在Kubernetes中部署Apache Ignite时遭遇403错误求助
Kubernetes部署Apache Ignite时403错误的解决方法
这个403错误的核心原因是:Ignite Pod使用的服务账号没有权限访问Kubernetes API中的endpoints资源。Ignite的Kubernetes节点发现机制需要获取指定服务对应的端点列表,当前Pod的身份不具备执行该操作的权限。
解决步骤:
创建权限角色
根据权限范围需求,选择创建集群级ClusterRole或命名空间级Role,赋予访问endpoints的权限:集群级角色(适用于跨命名空间的Ignite部署):
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: ignite-endpoints-reader rules: - apiGroups: [""] resources: ["endpoints"] verbs: ["get", "list", "watch"]命名空间级角色(仅在
ignite-stack命名空间生效,更安全):apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: ignite-endpoints-reader namespace: ignite-stack rules: - apiGroups: [""] resources: ["endpoints"] verbs: ["get", "list", "watch"]绑定角色到服务账号
将上述角色绑定到Ignite Pod使用的服务账号(如果未指定服务账号,默认使用default):集群级绑定:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: ignite-endpoints-binding subjects: - kind: ServiceAccount name: ignite-service-account namespace: ignite-stack roleRef: kind: ClusterRole name: ignite-endpoints-reader apiGroup: rbac.authorization.k8s.io命名空间级绑定:
apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: ignite-endpoints-binding namespace: ignite-stack subjects: - kind: ServiceAccount name: ignite-service-account namespace: ignite-stack roleRef: kind: Role name: ignite-endpoints-reader apiGroup: rbac.authorization.k8s.io配置Ignite Pod使用指定服务账号
在Ignite的Deployment或StatefulSet的Pod模板中,明确指定服务账号:spec: serviceAccountName: ignite-service-account containers: - name: ignite image: apacheignite/ignite:latest # 其他容器配置
完成以上操作后,重启Ignite Pod,即可解决403权限问题。
内容的提问来源于stack exchange,提问作者Gursewak Singh
相关产品推荐
相关产品推荐

