无法关联Google服务账号与Kubernetes服务账号的问题排查
GCP Workload Identity配置权限问题排查
问题描述
我正按照GCP官方指南在GCP上配置带Workload Identity的Kubernetes集群,但在服务账号权限配置上遇到阻碍。
执行的操作步骤
gcloud container clusters create test-cluster \ --region=europe-west1 \ --workload-pool=my-project.svc.id.goog gcloud container clusters get-credentials test-cluster \ --region=europe-west1 kubectl create namespace test-kns kubectl create serviceaccount test-ksa \ --namespace test-kns gcloud iam service-accounts create test-gsa \ --project=my-project gcloud projects add-iam-policy-binding my-project \ --member "serviceAccount:test-gsa@my-project.iam.gserviceaccount.com" \ --role "roles/composer.worker" gcloud iam service-accounts add-iam-policy-binding test-gsa@my-project.iam.gserviceaccount.com \ --role roles/iam.workloadIdentityUser \ --member "serviceAccount:my-project.svc.id.goog[test-kns/test-ksa]" kubectl annotate serviceaccount test-ksa \ --namespace test-kns \ iam.gke.io/gcp-service-account=test-gsa@my-project.iam.gserviceaccount.com # 测试KSA权限,返回no kubectl auth can-i list pods --all-namespaces --as "system:serviceaccount:test-kns:test-ksa" # 输出:[no] # 模拟GSA后测试,返回yes gcloud config set auth/impersonate_service_account test-gsa@my-project.iam.gserviceaccount.com gcloud container clusters get-credentials test-cluster --location europe-west1 kubectl auth can-i list pods --all-namespaces # 输出:[yes]
已验证的配置
- 服务账号注释已正确配置:
kubectl describe serviceaccount -n test-kns test-ksa Name: test-ksa Namespace: test-kns Labels: <none> Annotations: iam.gke.io/gcp-service-account: test-gsa@my-project.iam.gserviceaccount.com Image pull secrets: <none> Mountable secrets: <none> Tokens: <none> Events: <none>
- Pod中能正确获取GSA邮箱:
root@workload-identity-test:/# curl -H "Metadata-Flavor: Google" http://169.254.169.254/computeMetadata/v1/instance/service-accounts/default/email test-gsa@my-project.iam.gserviceaccount.com
疑问
GSA与KSA之间是否缺少了什么配置?
解决方案
核心问题在于:kubectl auth can-i测试的是Kubernetes RBAC权限,而非GCP IAM权限。你已完成Workload Identity的身份映射(KSA可关联GSA获取GCP权限),但未给KSA配置对应的Kubernetes RBAC规则,使其拥有list pods --all-namespaces的权限。
权限体系区分
- 模拟GSA执行测试时,使用的是GSA绑定的GCP IAM角色(如
roles/container.admin这类可操作K8s集群的角色),因此返回yes。 - 通过
--as指定KSA测试时,验证的是该KSA在K8s集群内部的RBAC权限,由于未配置任何ClusterRole或RoleBinding,因此返回no。
具体修复步骤
若需让该KSA拥有集群级别的Pod查看权限,执行以下命令:
# 创建允许查看所有命名空间Pod的ClusterRole kubectl create clusterrole pod-reader --verb=list --resource=pods # 将ClusterRole绑定到test-kns命名空间下的test-ksa kubectl create clusterrolebinding test-ksa-pod-reader --clusterrole=pod-reader --serviceaccount=test-kns:test-ksa
执行完成后再次测试:
kubectl auth can-i list pods --all-namespaces --as "system:serviceaccount:test-kns:test-ksa"
此时会返回yes。
补充说明
Workload Identity仅负责让K8s Pod通过KSA获取GCP IAM权限(如访问GCS、BigQuery等GCP服务),而K8s内部的资源访问权限仍需通过Kubernetes RBAC单独配置,二者是独立的权限体系。
内容的提问来源于stack exchange,提问作者jimbofreedman
相关产品推荐
相关产品推荐

