Kubeadm集群中tote-admin用户无法列出Pod的权限问题求助
解决Kubernetes tote-admin用户Pod访问403权限问题
问题根源是你仅创建了用户证书,但未通过RBAC为tote-admin分配任何资源访问权限。Kubernetes默认新用户没有任何操作权限,必须手动配置授权规则。
步骤1:创建集群级Pod读取角色
创建一个允许在集群范围列出Pod的ClusterRole,保存为pod-reader-clusterrole.yaml:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: pod-reader rules: - apiGroups: [""] # 空字符串对应核心API组 resources: ["pods"] verbs: ["list"] # 仅授予列出Pod的权限
执行命令应用配置:
kubectl apply -f pod-reader-clusterrole.yaml
步骤2:将角色绑定到tote-admin用户
创建ClusterRoleBinding,把上述角色绑定给tote-admin用户,保存为tote-pod-reader-binding.yaml:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: tote-pod-reader-binding subjects: - kind: User name: tote-admin apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: pod-reader apiGroup: rbac.authorization.k8s.io
执行命令应用配置:
kubectl apply -f tote-pod-reader-binding.yaml
步骤3:验证权限是否生效
重新执行你的curl命令:
curl https://172.31.127.100:6443/api/v1/pods --key tote.key --cert tote.crt --cacert /etc/kubernetes/pki/ca.crt
此时应该能正常返回集群中的Pod列表。
扩展:授予更全面的查看权限
如果需要让tote-admin能查看更多核心资源(比如Pod详情、Service等),可以直接使用Kubernetes内置的view ClusterRole,绑定配置如下:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: tote-view-binding subjects: - kind: User name: tote-admin apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: view apiGroup: rbac.authorization.k8s.io
内容的提问来源于stack exchange,提问作者Khaled
相关产品推荐
相关产品推荐

