You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Helm Chart创建的ServiceAccount无法调用Grafana REST API

Kubernetes ServiceAccount 访问 Grafana API 问题及配置

我在Helm Chart中创建并配置了一个ServiceAccount(SA),该账号已在K8s命名空间中以Secret形式创建,但使用其token调用Grafana的REST API(例如获取文件夹接口)时,返回“invalid API key”错误。需求是在全新安装Grafana时自动预置该SA,并用其token访问REST API。

Chart.yaml

apiVersion: v2
name: kraken-observability-stack
version:  0.1.0
#We don't have a built-in-house app so we dont set 
#appVersion: 0.1.0
kubeVersion: "^1.20.0-0"
description: The kraken observability stack for collecting and visualizing metrics, logs and traces related to CI pipelines.
home: https://docs.net/
dependencies:
  - name: grafana
    repository: https://grafana.github.io/helm-charts
    version:  6.50.x
  - name: mimir-distributed
    repository: https://grafana.github.io/helm-charts
    version: 3.2.x
  - name: loki-distributed
    repository: https://grafana.github.io/helm-charts
    version:  0.68.x
  - name: tempo-distributed
    repository: https://grafana.github.io/helm-charts
    version: 1.0.x
  - name: opentelemetry-collector
    repository: https://open-telemetry.github.io/opentelemetry-helm-charts                                      
    version: 0.47.x

(部分) values.yaml

grafana:
  testFramework:
    enabled: false
  resources:
    limits:
      #maybe we shouldn't set cpu limits to avoid overbooking of resources.
      #cpu: 1000m
      memory: 1Gi
    requests:
      memory: 200Mi
      cpu: 200m

  grafana.ini:
    force_migration: true
    data_proxy:
      timeout: 60s
    #feature_toggles:
    #  enable: tempoServiceGraph,tempoSearch,tempoBackendSearch,tempoApmTable
    auth:
      login_cookie_name: "kraken_grafana_session"
    auth.anonymous:
      enabled: true
      org_name: 'CICDS Pipelines User'
      org_role: 'Viewer'
    analytics:
      reporting_enabled: false
      check_for_updates: false
      check_for_plugin_updates: false
      enable_feedback_links: false
    log:
      level: warn
      mode: console
    plugins:
      enable_alpha: true
      app_tls_skip_verify_insecure: true
      allow_loading_unsigned_plugins: true

  #podAnnotations for grafana to expose its own metrics
  podAnnotations:
    prometheus.io/scrape: "true"
    prometheus.io/schema: "http"
    prometheus.io/port: "http"
    prometheus.io/path: "/metrics"
  rbac:
    #disable Create and use RBAC resources
    create: false
    #disable Create PodSecurityPolicy (we don't have privileges for that)
    pspEnabled: false
    #disable to enforce AppArmor in created PodSecurityPolicy
    pspUseAppArmor: false
  serviceAccount:
    create: true
    name: grafana-init-sa
    labels: {kraken-init}

  replicas: 3

  image:
    #repository: docker-virtual.repository.net/grafana/grafana
    repository: grafana/grafana

  downloadDashboardsImage:
    repository: docker-virtual.repository.net/curlimages/curl
    tag: 7.85.0
    pullPolicy: IfNotPresent

  persistence:
    type: statefulset
    enabled: true

  initChownData:
    
    ## This allows the prometheus-server to be run with an arbitrary user
    ##
    enabled: false
    #image:
    #  repository: docker-virtual.repository.net/busybox

  # Administrator credentials when not using an existing secret (see below)
  adminUser: admin
  adminPassword: changeit

  # Use an existing secret for the admin user.
  # grafana-admin-credentials name is reserved by the operator and thus -creds
  admin:
    existingSecret: "grafana-admin-user"
    userKey: ADMIN_USER
    passwordKey: ADMIN_PASSWORD

  env:
    HTTP_PROXY: http://p985nst:p985nst@proxyvip-se.sbcore.net:8080/
    HTTPS_PROXY: http://p985nst:p985nst@proxyvip-se.sbcore.net:8080/
    NO_PROXY: .cluster.local,.net,.sbcore.net,.svc,10.0.0.0/8,172.30.0.0/16,localhost

#  ## Pass the plugins you want installed as a list.
#  ##
#  plugins:
#    - digrich-bubblechart-panel
#    - grafana-clock-panel
#    - grafana-piechart-panel
#    - natel-discrete-panel

  extraSecretMounts:
     - name: loki-credentials-secret-mount
       secretName: loki-credentials
       defaultMode: 0440
       mountPath: /etc/secrets/.loki_credentials
       readOnly: true

内容的提问来源于stack exchange,提问作者Kaliyug Antagonist

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 01:50:29