You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决EKS集群中IAM用户Kubernetes只读权限访问被拒问题

解决EKS集群IAM用户只读权限缺失问题

你尝试给特定IAM用户授予EKS集群全对象只读权限,创建了read-only-access-eks IAM角色并附加AWS托管策略ReadOnlyAccess后,用户登录时出现权限错误:

Error loading GenericResourceCollection/namespaces
namespaces is forbidden: User "xxxxx" cannot list resource "namespaces" in API group "" at the cluster scope

更新信息显示,你已通过aws-auth ConfigMap将用户user1加入view组,但问题仍存在。

核心原因

AWS IAM的ReadOnlyAccess策略仅控制AWS服务级别的只读权限,和Kubernetes集群内部的RBAC授权无关。而Kubernetes默认的view ClusterRole仅包含命名空间级别资源的只读权限,不覆盖集群级资源(如namespaces、nodes)的访问,这是报错的直接原因。

解决步骤

方案1:扩展默认view ClusterRole的权限

直接给默认view角色添加集群级资源的只读权限:

  1. 编辑view ClusterRole:
    kubectl edit clusterrole view
    
  2. 在rules数组中添加以下内容(按需补充其他API组):
    - apiGroups: [""]
      resources: ["namespaces", "nodes", "persistentvolumes"]
      verbs: ["get", "list", "watch"]
    - apiGroups: ["apps"]
      resources: ["daemonsets", "deployments", "replicasets", "statefulsets"]
      verbs: ["get", "list", "watch"]
    - apiGroups: ["networking.k8s.io"]
      resources: ["ingresses", "networkpolicies"]
      verbs: ["get", "list", "watch"]
    
  3. 保存退出后,权限会自动生效。

方案2:创建自定义全集群只读ClusterRole(推荐)

如果不想修改默认角色,可创建专属的全集群只读角色并绑定:

  1. 创建cluster-readonly.yaml文件:
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRole
    metadata:
      name: cluster-readonly
    rules:
    # 核心API组资源
    - apiGroups: [""]
      resources: ["*"]
      verbs: ["get", "list", "watch"]
    # Apps API组资源
    - apiGroups: ["apps"]
      resources: ["*"]
      verbs: ["get", "list", "watch"]
    # Batch API组资源(定时任务、Job)
    - apiGroups: ["batch"]
      resources: ["*"]
      verbs: ["get", "list", "watch"]
    # 网络相关API组
    - apiGroups: ["networking.k8s.io"]
      resources: ["*"]
      verbs: ["get", "list", "watch"]
    # 按需添加其他API组,如storage.k8s.io等
    
  2. 应用该ClusterRole:
    kubectl apply -f cluster-readonly.yaml
    
  3. 创建ClusterRoleBinding,将角色绑定到view组(或直接绑定到目标用户):
    创建cluster-readonly-binding.yaml:
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRoleBinding
    metadata:
      name: cluster-readonly-binding
    subjects:
    - kind: Group
      name: view
      apiGroup: rbac.authorization.k8s.io
    roleRef:
      kind: ClusterRole
      name: cluster-readonly
      apiGroup: rbac.authorization.k8s.io
    
  4. 应用绑定:
    kubectl apply -f cluster-readonly-binding.yaml
    

验证

让user1重新登录EKS集群,执行以下命令确认权限:

kubectl get namespaces
kubectl get nodes
kubectl get pods --all-namespaces
kubectl get daemonsets --all-namespaces

内容的提问来源于stack exchange,提问作者user2315104

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 19:27:06