AWS EKS调用Core API报401未授权,需配置哪些权限?
问题描述
我已通过以下命令生成kubeconfig:
aws eks update-kubeconfig --name <cluster-name> --region <region> --kubeconfig /tmp/kubeconfig
但使用Kubernetes Python客户端调用API列出所有命名空间的Pod时,返回401 Unauthorized错误:
HTTP response headers: HTTPHeaderDict({'Audit-Id': 'xxxx-xxxx-xxxx-xxxx-xxxx', 'Cache-Control': 'no-cache, private', 'Content-Type': 'application/json', 'Date': 'Thu, 29 Sep 2022 17:41:09 GMT', 'Content-Length': '129'}) HTTP response body: {"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"Unauthorized","reason":"Unauthorized","code":401}
使用的Python客户端代码:
from kubernetes import client as k8s_client from kubernetes import config as k8s_config k8s_api_client = k8s_client.ApiClient(k8s_config.load_kube_config('/tmp/kubeconfig')) core_v1_api = k8s_client.CoreV1Api(k8s_api_client) pods_raw = core_v1_api.list_pod_for_all_namespaces(watch=False).to_dict()
完整报错栈:
19:41:09 File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api/core_v1_api.py", line 17309, in list_pod_for_all_namespaces 19:41:09 return self.list_pod_for_all_namespaces_with_http_info(**kwargs) # noqa: E501 19:41:09 File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api/core_v1_api.py", line 17430, in list_pod_for_all_namespaces_with_http_info 19:41:09 collection_formats=collection_formats) 19:41:09 File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api_client.py", line 353, in call_api 19:41:09 _preload_content, _request_timeout, _host) 19:41:09 File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api_client.py", line 184, in __call_api 19:41:09 _request_timeout=_request_timeout) 19:41:09 File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api_client.py", line 377, in request 19:41:09 headers=headers) 19:41:09 File "/usr/local/lib/python3.7/site-packages/kubernetes/client/rest.py", line 244, in GET 19:41:09 query_params=query_params) 19:41:09 File "/usr/local/lib/python3.7/site-packages/kubernetes/client/rest.py", line 234, in request 19:41:09 raise ApiException(http_resp=r) 19:41:09 kubernetes.client.exceptions.ApiException: (401) 19:41:09 Reason: Unauthorized
注:我仅作为客户端,无集群直接访问权限,暂时无法提供当前策略。
所需权限说明
要调用list_pod_for_all_namespaces这个Core API接口,你的身份需要被授予对所有命名空间下Pod资源的list权限。
具体需通过Kubernetes RBAC规则配置:
- 定义一个ClusterRole,包含针对
core/v1/pods资源的list权限(跨所有命名空间操作需用ClusterRole而非Role) - 通过ClusterRoleBinding将该ClusterRole绑定到你的身份(比如IAM用户对应的Kubernetes主体)
对应的ClusterRole示例:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: pod-list-clusterrole rules: - apiGroups: [""] # core API组 resources: ["pods"] verbs: ["list"]
ClusterRoleBinding示例(假设你的Kubernetes用户主体为arn:aws:iam::123456789012:user/your-iam-user):
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: pod-list-binding subjects: - kind: User name: arn:aws:iam::123456789012:user/your-iam-user apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: pod-list-clusterrole apiGroup: rbac.authorization.k8s.io
若仅需访问特定命名空间的Pod,可将ClusterRole替换为Role,ClusterRoleBinding替换为RoleBinding,并指定目标命名空间。
内容的提问来源于stack exchange,提问作者Julen
相关产品推荐
相关产品推荐

