You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MLRun WebShell执行igztop命令权限不足问题求助

解决MLRun WebShell中igztop权限不足问题

问题重现

执行igztop及权限检查命令后返回:

xiong @ iguazio-system 13:26:39 ] ~ $ igztop
No resources found.
Does the Service Account running this service have sufficient permissions? Use 'igztop --check-permissions' to find out.
xiong @ iguazio-system 13:26:44 ] ~ $ igztop --check-permissions
List pods: no
Delete pods: no

已在管理端Identity/Account/Policies配置最高权限,但问题未解决。

解决方案

  • 确认WebShell关联的ServiceAccount
    MLRun WebShell并非直接使用用户权限,而是绑定特定的ServiceAccount。先找到WebShell的pod:
kubectl get pods -n <mlrun命名空间> | grep webshell

再查看该pod使用的ServiceAccount:

kubectl describe pod <webshell-pod名称> -n <mlrun命名空间> | grep ServiceAccount
  • 为ServiceAccount绑定K8s权限
    igztop需要pod的list和delete权限,可直接绑定集群管理员角色(或自定义权限):

    1. 绑定cluster-admin角色:
    kubectl create clusterrolebinding webshell-admin --clusterrole=cluster-admin --serviceaccount=<mlrun命名空间>:<webshell-sa名称>
    
    1. 自定义最小权限:
      创建igztop-access.yaml文件:
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRole
    metadata:
      name: igztop-access
    rules:
    - apiGroups: [""]
      resources: ["pods"]
      verbs: ["list", "delete"]
    

    应用配置并绑定:

    kubectl apply -f igztop-access.yaml
    kubectl create clusterrolebinding igztop-webshell --clusterrole=igztop-access --serviceaccount=<mlrun命名空间>:<webshell-sa名称>
    
  • 重启WebShell pod使权限生效

kubectl delete pod <webshell-pod名称> -n <mlrun命名空间>

重新进入WebShell后执行igztop --check-permissions验证权限是否正常。

  • 检查MLRun内部权限控制
    若K8s权限配置完成仍无效,需确认MLRun UI中用户角色是否包含集群资源访问权限,或检查MLRun配置是否限制了WebShell对K8s资源的访问。

内容的提问来源于stack exchange,提问作者XiongChan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 23:27:08