如何通过Spring Boot应用获取Amazon EKS Kubernetes集群详情?
实现Spring Boot应用访问Amazon EKS集群信息的方案
要让部署在EKS上的Spring Boot应用获取集群命名空间、节点、Pod、服务等信息,并通过API触发控制台输出,可按以下步骤操作:
1. 引入依赖
推荐使用Kubernetes Java Client(官方维护,功能全面)或Spring Cloud Kubernetes(Spring生态集成更便捷),以下是两种方式的依赖配置:
方式1:Kubernetes Java Client
在pom.xml中添加:
<dependency> <groupId>io.kubernetes</groupId> <artifactId>client-java</artifactId> <version>19.0.0</version> <!-- 使用最新稳定版 --> </dependency>
方式2:Spring Cloud Kubernetes
适合Spring Boot原生集成,自动配置客户端:
<dependency> <groupId>org.springframework.cloud</groupId> <artifactId>spring-cloud-starter-kubernetes-client</artifactId> </dependency>
2. 配置EKS RBAC权限
EKS集群默认限制Pod访问K8s API,需通过RBAC为应用的服务账号赋予查询资源的权限:
创建ServiceAccount
apiVersion: v1 kind: ServiceAccount metadata: name: spring-boot-k8s-sa namespace: your-app-namespace # 替换为你的应用命名空间
创建ClusterRole
定义允许查看集群资源的权限:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: spring-boot-k8s-role rules: - apiGroups: [""] # 核心API组 resources: ["namespaces", "nodes", "pods", "services"] verbs: ["get", "list"] # 仅授予查询权限,避免权限过大
绑定权限到ServiceAccount
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: spring-boot-k8s-binding subjects: - kind: ServiceAccount name: spring-boot-k8s-sa namespace: your-app-namespace roleRef: kind: ClusterRole name: spring-boot-k8s-role apiGroup: rbac.authorization.k8s.io
部署应用时指定ServiceAccount
在应用的Deployment YAML中添加:
spec: serviceAccountName: spring-boot-k8s-sa
3. Spring Boot代码实现
初始化Kubernetes客户端
集群内部运行的应用可自动加载Pod的服务账号凭证;本地测试时需加载本地kubeconfig文件:
import io.kubernetes.client.openapi.ApiClient; import io.kubernetes.client.openapi.apis.CoreV1Api; import io.kubernetes.client.util.Config; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; @Configuration public class K8sClientConfig { @Bean public CoreV1Api coreV1Api() throws Exception { ApiClient client = Config.fromCluster(); // 集群内运行时使用 // 本地测试替换为:ApiClient client = Config.fromKubeconfig("/path/to/your/kubeconfig"); return new CoreV1Api(client); } }
编写API接口触发信息输出
创建Controller,注入CoreV1Api实现资源查询并输出到控制台:
import io.kubernetes.client.openapi.apis.CoreV1Api; import io.kubernetes.client.openapi.models.V1NamespaceList; import io.kubernetes.client.openapi.models.V1NodeList; import io.kubernetes.client.openapi.models.V1PodList; import io.kubernetes.client.openapi.models.V1ServiceList; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.RestController; @RestController public class K8sInfoController { private final CoreV1Api coreV1Api; // 构造注入客户端 public K8sInfoController(CoreV1Api coreV1Api) { this.coreV1Api = coreV1Api; } @GetMapping("/print-cluster-info") public String printClusterInfo() { try { // 输出命名空间信息 V1NamespaceList namespaces = coreV1Api.listNamespace(null, null, null, null, null, null, null, null, null); System.out.println("=== 集群命名空间列表 ==="); namespaces.getItems().forEach(ns -> System.out.printf("命名空间: %s%n", ns.getMetadata().getName()) ); // 输出节点信息 V1NodeList nodes = coreV1Api.listNode(null, null, null, null, null, null, null, null, null); System.out.println("\n=== 集群节点列表 ==="); nodes.getItems().forEach(node -> System.out.printf("节点名称: %s | 状态: %s%n", node.getMetadata().getName(), node.getStatus().getConditions().getLast().getType()) ); // 输出所有Pod信息 V1PodList pods = coreV1Api.listPodForAllNamespaces(null, null, null, null, null, null, null, null, null); System.out.println("\n=== 集群Pod列表 ==="); pods.getItems().forEach(pod -> System.out.printf("Pod名称: %s | 命名空间: %s | 状态: %s%n", pod.getMetadata().getName(), pod.getMetadata().getNamespace(), pod.getStatus().getPhase()) ); // 输出所有服务信息 V1ServiceList services = coreV1Api.listServiceForAllNamespaces(null, null, null, null, null, null, null, null, null); System.out.println("\n=== 集群服务列表 ==="); services.getItems().forEach(svc -> System.out.printf("服务名称: %s | 命名空间: %s | 类型: %s%n", svc.getMetadata().getName(), svc.getMetadata().getNamespace(), svc.getSpec().getType()) ); return "集群信息已输出至应用控制台"; } catch (Exception e) { e.printStackTrace(); return "获取集群信息失败: " + e.getMessage(); } } }
4. 测试验证
- 集群部署:将应用部署到EKS后,调用
GET /print-cluster-info接口,通过kubectl logs <pod-name>查看Pod日志即可看到输出的集群信息。 - 本地测试:确保本地kubeconfig已配置EKS集群访问权限,启动应用后调用接口,控制台会直接输出信息。
参考资源
- Kubernetes Java Client:核心API操作、客户端配置详情
- Spring Cloud Kubernetes:Spring Boot与K8s集成的最佳实践
- Amazon EKS RBAC:集群权限配置、服务账号管理指南
内容的提问来源于stack exchange,提问作者KP Singh
相关产品推荐
相关产品推荐

