You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS 1.21集群Nginx Ingress Controller Pod权限问题求助

问题根源分析
  1. ServiceAccount Token读取权限不足:Pod以runAsUser: 101运行,而Kubernetes默认挂载的ServiceAccount卷(kube-api-access-xxx)内的token文件权限为600,属主是root(0),非root用户无读取权限,导致Ingress Controller无法连接K8s API Server。
  2. 安全策略限制root运行:尝试修改runAsUser: 0失败,是因为EKS 1.21集群启用了PodSecurityPolicy(PSP) 或PodSecurityStandard(PSS),禁止Pod以root用户运行。
可行解决方案

方案1:调整Pod SecurityContext,通过fsGroup赋予读取权限

修改Ingress Controller的Pod模板,添加runAsGroup和fsGroup配置,让挂载的ServiceAccount卷文件组权限匹配运行用户组,从而允许101用户读取token:

securityContext:
  allowPrivilegeEscalation: true
  capabilities:
    add:
    - NET_BIND_SERVICE
    drop:
    - ALL
  runAsUser: 101
  runAsGroup: 101  # 添加此行
  fsGroup: 101      # 添加此行

fsGroup会让Kubernetes自动调整挂载卷的文件组权限为101,101用户作为组成员即可读取token文件。

方案2:检查并调整PodSecurityPolicy(PSP)

如果方案1无效,检查集群的PSP配置:

  1. 查看当前集群的PSP列表:
kubectl get psp
  1. 找到Ingress Controller使用的ServiceAccount对应的权限绑定,确保PSP允许runAsUser:101和fsGroup:101:
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: nginx-ingress-psp
spec:
  runAsUser:
    rule: "MustRunAs"
    ranges:
    - min: 101
      max: 101
  fsGroup:
    rule: "MustRunAs"
    ranges:
    - min: 101
      max: 101
  seLinux:
    rule: "RunAsAny"
  supplementalGroups:
    rule: "RunAsAny"
  volumes:
  - 'secret'
  - 'configMap'
  # 保留必要的权限,比如允许NET_BIND_SERVICE
  allowedCapabilities:
  - NET_BIND_SERVICE
  1. 将该PSP绑定到Ingress Controller的ServiceAccount:
kubectl create clusterrole nginx-ingress-psp-role --verb=use --resource=podsecuritypolicy --resource-name=nginx-ingress-psp
kubectl create clusterrolebinding nginx-ingress-psp-binding --clusterrole=nginx-ingress-psp-role --serviceaccount=<namespace>:<serviceaccount-name>

方案3:调整PodSecurityStandard(PSS)豁免

如果集群启用了PSS(EKS 1.21默认可能开启),检查Ingress Controller所在命名空间的PSS标签:

  1. 查看命名空间标签:
kubectl describe ns <nginx-ingress-namespace>
  1. 如果标签为pod-security.kubernetes.io/enforce: restricted,该模式禁止root运行且严格限制权限,可给该命名空间添加PSS豁免:
kubectl label ns <nginx-ingress-namespace> pod-security.kubernetes.io/enforce=privileged --overwrite

注意:privileged模式权限较高,若需更严格的安全策略,可配合方案1使用baseline模式:

kubectl label ns <nginx-ingress-namespace> pod-security.kubernetes.io/enforce=baseline --overwrite

额外建议

确认Ingress Controller版本与EKS 1.21兼容,建议使用ingress-nginx v1.0.0+版本,该版本对K8s 1.21+的安全策略支持更完善。

内容的提问来源于stack exchange,提问作者Nisarg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 15:11:12