You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS EKS调用Core API报401未授权,需配置哪些权限?

问题描述

我已通过以下命令生成kubeconfig:

aws eks update-kubeconfig --name <cluster-name> --region <region> --kubeconfig /tmp/kubeconfig

但使用Kubernetes Python客户端调用API列出所有命名空间的Pod时,返回401 Unauthorized错误:

HTTP response headers: HTTPHeaderDict({'Audit-Id': 'xxxx-xxxx-xxxx-xxxx-xxxx', 'Cache-Control': 'no-cache, private', 'Content-Type': 'application/json', 'Date': 'Thu, 29 Sep 2022 17:41:09 GMT', 'Content-Length': '129'})
HTTP response body: {"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"Unauthorized","reason":"Unauthorized","code":401}

使用的Python客户端代码:

from kubernetes import client as k8s_client                                                                               
from kubernetes import config as k8s_config              
                                                                                                                              
k8s_api_client = k8s_client.ApiClient(k8s_config.load_kube_config('/tmp/kubeconfig'))                                      
core_v1_api = k8s_client.CoreV1Api(k8s_api_client)
pods_raw = core_v1_api.list_pod_for_all_namespaces(watch=False).to_dict()

完整报错栈:

19:41:09    File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api/core_v1_api.py", line 17309, in list_pod_for_all_namespaces
19:41:09      return self.list_pod_for_all_namespaces_with_http_info(**kwargs)  # noqa: E501
19:41:09    File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api/core_v1_api.py", line 17430, in list_pod_for_all_namespaces_with_http_info
19:41:09      collection_formats=collection_formats)
19:41:09    File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api_client.py", line 353, in call_api
19:41:09      _preload_content, _request_timeout, _host)
19:41:09    File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api_client.py", line 184, in __call_api
19:41:09      _request_timeout=_request_timeout)
19:41:09    File "/usr/local/lib/python3.7/site-packages/kubernetes/client/api_client.py", line 377, in request
19:41:09      headers=headers)
19:41:09    File "/usr/local/lib/python3.7/site-packages/kubernetes/client/rest.py", line 244, in GET
19:41:09      query_params=query_params)
19:41:09    File "/usr/local/lib/python3.7/site-packages/kubernetes/client/rest.py", line 234, in request
19:41:09      raise ApiException(http_resp=r)
19:41:09  kubernetes.client.exceptions.ApiException: (401)
19:41:09  Reason: Unauthorized

注:我仅作为客户端,无集群直接访问权限,暂时无法提供当前策略。

所需权限说明

要调用list_pod_for_all_namespaces这个Core API接口,你的身份需要被授予对所有命名空间下Pod资源的list权限。

具体需通过Kubernetes RBAC规则配置:

  • 定义一个ClusterRole,包含针对core/v1/pods资源的list权限(跨所有命名空间操作需用ClusterRole而非Role)
  • 通过ClusterRoleBinding将该ClusterRole绑定到你的身份(比如IAM用户对应的Kubernetes主体)

对应的ClusterRole示例:

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: pod-list-clusterrole
rules:
- apiGroups: [""] # core API组
  resources: ["pods"]
  verbs: ["list"]

ClusterRoleBinding示例(假设你的Kubernetes用户主体为arn:aws:iam::123456789012:user/your-iam-user):

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: pod-list-binding
subjects:
- kind: User
  name: arn:aws:iam::123456789012:user/your-iam-user
  apiGroup: rbac.authorization.k8s.io
roleRef:
  kind: ClusterRole
  name: pod-list-clusterrole
  apiGroup: rbac.authorization.k8s.io

若仅需访问特定命名空间的Pod,可将ClusterRole替换为Role,ClusterRoleBinding替换为RoleBinding,并指定目标命名空间。

内容的提问来源于stack exchange,提问作者Julen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 20:15:43