etcd角色控制特定Key写入权限异常,请求排查原因
问题描述
我使用Go的etcd/clientv3启动etcd集群,参数如下:
"--name", "etcd-cluster" "--data-dir", "/var/lib/etcd", "--wal-dir", "/var/lib", "--listen-client-urls", "127.0.0.1:2379", "--listen-peer-urls", "127.0.0.1:2380", "--advertise-client-urls", "127.0.0.1:2379", "--initial-advertise-peer-urls", "127.0.0.1:2380", "--initial-cluster", "cluster", "--initial-cluster-state", "new", "--initial-cluster-token", "election", "--cert-file", "tls.pem", "--key-file", "tls.key", "--client-cert-auth", "--trusted-ca-file", "ca.pem", "--peer-client-cert-auth", "--peer-trusted-ca-file", "peer-ca.pem", "--peer-cert-file", "peer-cert.pem", "--peer-key-file", "peer.key",
随后执行了以下命令:
env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem user add root env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem role add root env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem user add myuser env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem role add myrole env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem put /events/1 value env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem role grant-permisson myrole read /events/1 env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem user grant-role root root env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem user grant-role myuser myrole env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem auth enable
根据etcd认证文档,客户端使用TLS证书时会提取证书CN作为用户,我的tls.pem证书CN为myuser,执行以下命令返回permission denied符合预期(myuser仅被授予读权限):
env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem put /events/1 value
但文档说明同时使用--user选项与TLS证书时,--user优先级高于CN,执行以下命令预期返回OK,实际仍返回permission denied:
env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem --user=root:mypass put /events/1 value
原因分析与解决
核心问题:root角色未配置任何权限
你创建了root角色并将root用户绑定到该角色,但etcd新建的角色默认没有任何操作权限。即使root用户身份验证通过,也会因角色无权限导致permission denied。
次要问题:命令拼写错误
你的role grant-permisson命令存在拼写错误,正确命令为role grant-permission(末尾为permission而非permisson),这条错误命令不会生效,不过你提到myuser的读权限符合预期,推测是输入时的笔误。
额外集群配置错误
--initial-cluster参数设置为"cluster"不符合格式要求,正确格式应为"etcd-cluster=http://127.0.0.1:2380"(与--name参数对应,格式为{name}={peer-url}),这个错误会影响集群初始化,但不直接导致认证问题。
解决步骤
- 先禁用认证(若还能通过现有证书操作):
env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem auth disable - 给
root角色授予所有路径的读写权限:env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem role grant-permission root --prefix=true readwrite / - 重新启用认证:
env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem auth enable - 再次测试put命令:
env ETCDCTL_API=3 etcdctl --endpoints=localhost:2379 --cert tls.pem --key tls.key --cacert ca.pem --user=root:mypass put /events/1 value
内容的提问来源于stack exchange,提问作者armaka
相关产品推荐
相关产品推荐

