You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Kubernetes中部署Apache Ignite时遭遇403错误求助

Kubernetes部署Apache Ignite时403错误的解决方法

这个403错误的核心原因是:Ignite Pod使用的服务账号没有权限访问Kubernetes API中的endpoints资源。Ignite的Kubernetes节点发现机制需要获取指定服务对应的端点列表,当前Pod的身份不具备执行该操作的权限。

解决步骤:

  1. 创建权限角色
    根据权限范围需求,选择创建集群级ClusterRole或命名空间级Role,赋予访问endpoints的权限:

    集群级角色(适用于跨命名空间的Ignite部署):

    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRole
    metadata:
      name: ignite-endpoints-reader
    rules:
    - apiGroups: [""]
      resources: ["endpoints"]
      verbs: ["get", "list", "watch"]
    

    命名空间级角色(仅在ignite-stack命名空间生效,更安全):

    apiVersion: rbac.authorization.k8s.io/v1
    kind: Role
    metadata:
      name: ignite-endpoints-reader
      namespace: ignite-stack
    rules:
    - apiGroups: [""]
      resources: ["endpoints"]
      verbs: ["get", "list", "watch"]
    
  2. 绑定角色到服务账号
    将上述角色绑定到Ignite Pod使用的服务账号(如果未指定服务账号,默认使用default):

    集群级绑定:

    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRoleBinding
    metadata:
      name: ignite-endpoints-binding
    subjects:
    - kind: ServiceAccount
      name: ignite-service-account
      namespace: ignite-stack
    roleRef:
      kind: ClusterRole
      name: ignite-endpoints-reader
      apiGroup: rbac.authorization.k8s.io
    

    命名空间级绑定:

    apiVersion: rbac.authorization.k8s.io/v1
    kind: RoleBinding
    metadata:
      name: ignite-endpoints-binding
      namespace: ignite-stack
    subjects:
    - kind: ServiceAccount
      name: ignite-service-account
      namespace: ignite-stack
    roleRef:
      kind: Role
      name: ignite-endpoints-reader
      apiGroup: rbac.authorization.k8s.io
    
  3. 配置Ignite Pod使用指定服务账号
    在Ignite的Deployment或StatefulSet的Pod模板中,明确指定服务账号:

    spec:
      serviceAccountName: ignite-service-account
      containers:
      - name: ignite
        image: apacheignite/ignite:latest
        # 其他容器配置
    

完成以上操作后,重启Ignite Pod,即可解决403权限问题。

内容的提问来源于stack exchange,提问作者Gursewak Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 18:55:40