You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AKS中K8s Dashboard登录遇MSG_LOGIN_UNAUTHORIZED_ERROR求助

问题描述

我在Azure Kubernetes集群(AKS)中部署了Kubernetes Dashboard v2.2.0,部署命令:

kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.2.0/aio/deploy/recommended.yaml

同时为Azure AD用户配置了ClusterRole和ClusterRoleBinding:

ClusterRole.yml

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: admin-user-testing
rules:
  - apiGroups:
      ["*"]
    resources: ["*"]
    verbs: ["*"]

ClusterRoleBinding.yaml

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: admin-user-testing
subjects:
- kind: User
  name: <azure user object id>
  apiGroup: rbac.authorization.k8s.io
roleRef:
  kind: ClusterRole
  name: admin-user-testing
  apiGroup: rbac.authorization.k8s.io

登录Dashboard时,通过以下命令生成token:

kubelogin get-token --login azurecli --server-id xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxx

命令返回包含token的ExecCredential结果。执行kubectl proxy后,点击登录页面的Sign In按钮无响应,网络请求返回401错误:

{
 "status": 401,
 "plugins": [],
 "errors": [
  {
   "ErrStatus": {
    "metadata": {},
    "status": "Failure",
    "message": "MSG_LOGIN_UNAUTHORIZED_ERROR",
    "reason": "Unauthorized",
    "code": 401
   }
  }
 ]
}
排查与解决方案

1. 确认Azure AD用户对象ID正确性

  • 执行az ad user show --id <你的Azure AD用户邮箱> --query id -o tsv,获取正确的用户对象ID,替换ClusterRoleBinding中的<azure user object id>,然后重新应用绑定:
    kubectl apply -f ClusterRoleBinding.yaml
    

2. 调整Dashboard认证配置

Kubernetes Dashboard v2.2.0默认未适配Azure AD认证,需修改Deployment参数:

  • 编辑Dashboard Deployment:
    kubectl edit deployment kubernetes-dashboard -n kubernetes-dashboard
    
  • 在spec.template.spec.containers[0].args中添加:
    --authentication-mode=token
    --token-auth-file=/dev/null
    
    若需启用OIDC模式对接Azure AD,需额外添加--oidc-issuer-url(对应Azure AD租户的OIDC地址)、--oidc-client-id(对应你创建的Azure AD应用注册ID)等参数。

3. 验证token本身有效性

用生成的token直接调用K8s API,确认权限配置是否生效:

curl -H "Authorization: Bearer <你的token>" http://localhost:8001/api/v1/pods

如果此请求返回401,说明token或RBAC配置存在问题;如果返回正常,问题则聚焦在Dashboard的配置上。

4. 检查Dashboard访问路径

确保访问路径为http://localhost:8001/api/v1/namespaces/kubernetes-dashboard/services/https:kubernetes-dashboard:/proxy/,路径错误会导致认证请求无法正确转发。

5. 确认Azure AD应用注册与AKS集成配置

  • 检查--server-id对应的Azure AD应用注册:确保已添加Kubernetes相关权限,且重定向URI包含Dashboard访问路径(OIDC模式下)。
  • 确认AKS集群已启用Azure AD集成:
    az aks show --name <集群名称> --resource-group <资源组> --query aadProfile
    
    若未启用,需重新配置AKS的Azure AD集成。

6. 查看Dashboard日志定位细节

获取Dashboard Pod日志,查看具体认证失败原因:

kubectl logs -n kubernetes-dashboard $(kubectl get pods -n kubernetes-dashboard -l k8s-app=kubernetes-dashboard -o name)

日志中会包含token解析、RBAC匹配等环节的具体错误信息,帮助精准定位问题。

内容的提问来源于stack exchange,提问作者akhil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 21:49:52