You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS集群Role与RoleBinding配置异常:组用户仍可编辑Secrets

问题排查与解决方案

核心问题点

1. RoleBinding中Group的namespace字段无效且错误

Group是集群级身份标识,不需要指定namespace,你当前配置中给Group添加的namespace字段会导致RoleBinding无法正确关联到目标组,这是权限未生效的关键原因之一。

2. 目标组可能存在其他高权限绑定

该组用户能编辑Secrets,说明他们还拥有其他权限来源:

  • 检查是否存在集群级的ClusterRoleBinding,给该组授予了edit、admin或包含Secrets编辑权限的角色
  • 检查devtest命名空间内是否有其他RoleBinding,给该组分配了超过list的权限

3. 补充:当前Role仅支持列出Secrets,无法查看单个Secret详情

如果你的需求是允许用户查看单个Secret内容,需要在Role的verbs中添加get,但这和编辑权限无关,仅做补充说明。

修正后的配置

RoleBinding(删除Group的namespace字段)

apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: listOnlysecretBinding
  namespace: devtest
roleRef:
  kind: Role
  name: listOnlysecret
  apiGroup: rbac.authorization.k8s.io
subjects:
  - kind: Group
    name: "9ijk008-330k-900g-800a-7567678ccaa"

Role(如需查看单个Secret可添加get)

apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: listOnlysecret
  namespace: devtest
rules:
  - apiGroups: [""]
    resources: ["secrets"]
    verbs: ["list", "get"] # 仅当需要查看单个Secret时添加get

验证步骤

  1. 应用修正后的配置:
    kubectl apply -f <your-config-file>.yaml
    
  2. 验证该组是否无法编辑Secrets:
    kubectl auth can-i update secrets -n devtest --as-group=9ijk008-330k-900g-800a-7567678ccaa
    
    正常返回应为no
  3. 排查是否存在其他权限绑定:
    kubectl get clusterrolebindings -o json | jq '.items[] | select(.subjects[]?.name == "9ijk008-330k-900g-800a-7567678ccaa")'
    
    若输出结果,说明该组存在额外的集群级权限绑定,需根据需求调整或删除。

内容的提问来源于stack exchange,提问作者sysadmincrispy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 11:55:24