You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubeadm集群中tote-admin用户无法列出Pod的权限问题求助

解决Kubernetes tote-admin用户Pod访问403权限问题

问题根源是你仅创建了用户证书,但未通过RBAC为tote-admin分配任何资源访问权限。Kubernetes默认新用户没有任何操作权限,必须手动配置授权规则。

步骤1:创建集群级Pod读取角色

创建一个允许在集群范围列出Pod的ClusterRole,保存为pod-reader-clusterrole.yaml:

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: pod-reader
rules:
- apiGroups: [""]  # 空字符串对应核心API组
  resources: ["pods"]
  verbs: ["list"]  # 仅授予列出Pod的权限

执行命令应用配置:

kubectl apply -f pod-reader-clusterrole.yaml

步骤2:将角色绑定到tote-admin用户

创建ClusterRoleBinding,把上述角色绑定给tote-admin用户,保存为tote-pod-reader-binding.yaml:

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: tote-pod-reader-binding
subjects:
- kind: User
  name: tote-admin
  apiGroup: rbac.authorization.k8s.io
roleRef:
  kind: ClusterRole
  name: pod-reader
  apiGroup: rbac.authorization.k8s.io

执行命令应用配置:

kubectl apply -f tote-pod-reader-binding.yaml

步骤3:验证权限是否生效

重新执行你的curl命令:

curl https://172.31.127.100:6443/api/v1/pods --key tote.key --cert tote.crt --cacert /etc/kubernetes/pki/ca.crt

此时应该能正常返回集群中的Pod列表。

扩展:授予更全面的查看权限

如果需要让tote-admin能查看更多核心资源(比如Pod详情、Service等),可以直接使用Kubernetes内置的view ClusterRole,绑定配置如下:

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: tote-view-binding
subjects:
- kind: User
  name: tote-admin
  apiGroup: rbac.authorization.k8s.io
roleRef:
  kind: ClusterRole
  name: view
  apiGroup: rbac.authorization.k8s.io

内容的提问来源于stack exchange,提问作者Khaled

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 12:28:09