Kubernetes创建Job权限不足,Role配置正确性及生效方法咨询
问题描述
在Windows环境下执行kubectl apply -f file-download.yaml部署一个将文件下载至已创建PVC的Job时,出现权限禁止错误:
Error from server (Forbidden): error when creating "file-download.yaml": jobs.batch is forbidden: User "token-{my user token}" cannot create resource "jobs" in API group "batch" in the namespace "{my context}"
为解决该问题,编写了以下RBAC配置文件:
role.yaml
kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata: namespace: mycontext name: example-role rules: - apiGroups: ["batch", "extensions"] resources: ["jobs"] verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
binding.yaml
kind: RoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: example-rolebinding namespace: mycontext subjects: - kind: User name: token-mytoken apiGroup: rbac.authorization.k8s.io roleRef: kind: Role name: example-role apiGroup: rbac.authorization.k8s.io
现咨询:上述配置是否正确?如何使这些规则生效?仅将文件放在工作目录即可,还是需要执行kubectl命令应用,或是需在file-download.yaml中引用这些文件?
解决方案
配置正确性
你的Role和RoleBinding配置大体正确,但有两个细节需要调整:
- API组优化:
extensionsAPI组已被Kubernetes弃用,Job资源当前仅属于batchAPI组,所以Role的apiGroups可以只保留["batch"],去掉extensions。 - 用户名称匹配:RoleBinding中
subjects里的name必须和错误提示里的用户名称token-{my user token}完全一致,比如错误里显示的是token-abc123,这里就不能写成token-mytoken,必须精准匹配。
规则生效方式
这些配置文件不能仅放在工作目录,也不需要在file-download.yaml中引用,必须通过kubectl命令提交到Kubernetes集群才能生效,步骤如下:
- 先创建Role:执行
kubectl apply -f role.yaml - 再创建RoleBinding:执行
kubectl apply -f binding.yaml - 或者一次性执行两个文件:
kubectl apply -f role.yaml -f binding.yaml
执行完以上命令后,等待RBAC规则同步(通常几秒内完成),再重新执行kubectl apply -f file-download.yaml即可创建Job。
内容的提问来源于stack exchange,提问作者user1088793
相关产品推荐
相关产品推荐

