You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Spring Boot应用获取Amazon EKS Kubernetes集群详情?

实现Spring Boot应用访问Amazon EKS集群信息的方案

要让部署在EKS上的Spring Boot应用获取集群命名空间、节点、Pod、服务等信息,并通过API触发控制台输出,可按以下步骤操作:

1. 引入依赖

推荐使用Kubernetes Java Client(官方维护,功能全面)或Spring Cloud Kubernetes(Spring生态集成更便捷),以下是两种方式的依赖配置:

方式1:Kubernetes Java Client

在pom.xml中添加:

<dependency>
    <groupId>io.kubernetes</groupId>
    <artifactId>client-java</artifactId>
    <version>19.0.0</version> <!-- 使用最新稳定版 -->
</dependency>

方式2:Spring Cloud Kubernetes

适合Spring Boot原生集成,自动配置客户端:

<dependency>
    <groupId>org.springframework.cloud</groupId>
    <artifactId>spring-cloud-starter-kubernetes-client</artifactId>
</dependency>

2. 配置EKS RBAC权限

EKS集群默认限制Pod访问K8s API,需通过RBAC为应用的服务账号赋予查询资源的权限:

创建ServiceAccount

apiVersion: v1
kind: ServiceAccount
metadata:
  name: spring-boot-k8s-sa
  namespace: your-app-namespace # 替换为你的应用命名空间

创建ClusterRole

定义允许查看集群资源的权限:

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: spring-boot-k8s-role
rules:
- apiGroups: [""] # 核心API组
  resources: ["namespaces", "nodes", "pods", "services"]
  verbs: ["get", "list"] # 仅授予查询权限,避免权限过大

绑定权限到ServiceAccount

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: spring-boot-k8s-binding
subjects:
- kind: ServiceAccount
  name: spring-boot-k8s-sa
  namespace: your-app-namespace
roleRef:
  kind: ClusterRole
  name: spring-boot-k8s-role
  apiGroup: rbac.authorization.k8s.io

部署应用时指定ServiceAccount

在应用的Deployment YAML中添加:

spec:
  serviceAccountName: spring-boot-k8s-sa

3. Spring Boot代码实现

初始化Kubernetes客户端

集群内部运行的应用可自动加载Pod的服务账号凭证;本地测试时需加载本地kubeconfig文件:

import io.kubernetes.client.openapi.ApiClient;
import io.kubernetes.client.openapi.apis.CoreV1Api;
import io.kubernetes.client.util.Config;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;

@Configuration
public class K8sClientConfig {
    @Bean
    public CoreV1Api coreV1Api() throws Exception {
        ApiClient client = Config.fromCluster(); // 集群内运行时使用
        // 本地测试替换为:ApiClient client = Config.fromKubeconfig("/path/to/your/kubeconfig");
        return new CoreV1Api(client);
    }
}

编写API接口触发信息输出

创建Controller,注入CoreV1Api实现资源查询并输出到控制台:

import io.kubernetes.client.openapi.apis.CoreV1Api;
import io.kubernetes.client.openapi.models.V1NamespaceList;
import io.kubernetes.client.openapi.models.V1NodeList;
import io.kubernetes.client.openapi.models.V1PodList;
import io.kubernetes.client.openapi.models.V1ServiceList;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class K8sInfoController {

    private final CoreV1Api coreV1Api;

    // 构造注入客户端
    public K8sInfoController(CoreV1Api coreV1Api) {
        this.coreV1Api = coreV1Api;
    }

    @GetMapping("/print-cluster-info")
    public String printClusterInfo() {
        try {
            // 输出命名空间信息
            V1NamespaceList namespaces = coreV1Api.listNamespace(null, null, null, null, null, null, null, null, null);
            System.out.println("=== 集群命名空间列表 ===");
            namespaces.getItems().forEach(ns -> 
                System.out.printf("命名空间: %s%n", ns.getMetadata().getName())
            );

            // 输出节点信息
            V1NodeList nodes = coreV1Api.listNode(null, null, null, null, null, null, null, null, null);
            System.out.println("\n=== 集群节点列表 ===");
            nodes.getItems().forEach(node -> 
                System.out.printf("节点名称: %s | 状态: %s%n", 
                    node.getMetadata().getName(),
                    node.getStatus().getConditions().getLast().getType())
            );

            // 输出所有Pod信息
            V1PodList pods = coreV1Api.listPodForAllNamespaces(null, null, null, null, null, null, null, null, null);
            System.out.println("\n=== 集群Pod列表 ===");
            pods.getItems().forEach(pod -> 
                System.out.printf("Pod名称: %s | 命名空间: %s | 状态: %s%n", 
                    pod.getMetadata().getName(),
                    pod.getMetadata().getNamespace(),
                    pod.getStatus().getPhase())
            );

            // 输出所有服务信息
            V1ServiceList services = coreV1Api.listServiceForAllNamespaces(null, null, null, null, null, null, null, null, null);
            System.out.println("\n=== 集群服务列表 ===");
            services.getItems().forEach(svc -> 
                System.out.printf("服务名称: %s | 命名空间: %s | 类型: %s%n", 
                    svc.getMetadata().getName(),
                    svc.getMetadata().getNamespace(),
                    svc.getSpec().getType())
            );

            return "集群信息已输出至应用控制台";
        } catch (Exception e) {
            e.printStackTrace();
            return "获取集群信息失败: " + e.getMessage();
        }
    }
}

4. 测试验证

  • 集群部署:将应用部署到EKS后,调用GET /print-cluster-info接口,通过kubectl logs <pod-name>查看Pod日志即可看到输出的集群信息。
  • 本地测试:确保本地kubeconfig已配置EKS集群访问权限,启动应用后调用接口,控制台会直接输出信息。

参考资源

  • Kubernetes Java Client:核心API操作、客户端配置详情
  • Spring Cloud Kubernetes:Spring Boot与K8s集成的最佳实践
  • Amazon EKS RBAC:集群权限配置、服务账号管理指南

内容的提问来源于stack exchange,提问作者KP Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 17:24:51