使用带MFA验证的AWS角色通过kubectl访问EKS集群遇阻求助
访问EKS集群的MFA认证与连接超时问题
问题背景
尝试访问由OwnerRole角色拥有的EKS集群,该角色要求授权用户必须完成MFA认证才能切换至该角色。
初始配置
.aws/config 配置
[profile AuthorizedUser] region = us-east-1 output = json mfa_serial = <ARN of the user's MFA device> [profile RoleProfileUsedByKubectl] source_profile = AuthorizedUser role_arn = <ARN of the OwnerRole role>
kubectl 配置片段
- name: <username in context> user: exec: apiVersion: client.authentication.k8s.io/v1beta1 args: - --region - us-east-1 - eks - get-token - --cluster-name - <name of the cluster> command: aws env: - name: AWS_PROFILE value: RoleProfileUsedByKubectl interactiveMode: IfAvailable provideClusterInfo: false
初始执行结果
切换上下文后执行kubectl get po -A报错:
$ kubectl config use-context <context name> Switched to context "<context name>" $ $ kubectl get po -A An error occurred (AccessDenied) when calling the AssumeRole operation: User: <user ARN> is not authorized to perform: sts:AssumeRole on resource: <role ARN> .... <repeat 4 more times> .... Unable to connect to the server: getting credentials: exec: executable aws failed with exit code 254
推测原因:切换上下文时未触发AuthorizedUser的MFA验证,直接以无MFA的用户身份尝试扮演OwnerRole被拒绝。
调整配置后的情况
将mfa_serial移至角色配置:
修改后的.aws/config
[profile AuthorizedUser] region = us-east-1 output = json [profile RoleProfileUsedByKubectl] source_profile = AuthorizedUser mfa_serial = <ARN of the user's MFA device> role_arn = <ARN of the OwnerRole role>
执行结果
AWS命令可正常执行:
$ aws eks list-nodegroups --cluster-name <cluster name> --region us-east-1 --profile RoleProfileUsedByKubectl Enter MFA code for <MFA ARN>: { "nodegroups": [ "<node group name list>" ] }
但kubectl仍报错:
$ kubectl get po -A Unable to connect to the server: dial tcp 172.16.88.123:443: i/o timeout
疑问
请问这是否是防火墙或安全组阻止了kubectl的访问?
内容的提问来源于stack exchange,提问作者King Bob
相关产品推荐
相关产品推荐

