You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HCP Vault与AWS EKS连接失败求助(附操作步骤)

HCP Vault与AWS EKS连接失败排查

操作步骤

  • 已配置HVN并与K8s集群所在VPC建立对等连接
  • 在该HVN中创建HCP Vault集群
  • 通过Helm创建injector pod
  • 因Vault Cluster仅支持私有访问,使用堡垒机连接
  • 在堡垒机执行:vault auth enable kubernetes
  • 在admin-panel命名空间中创建名为admin-panel的服务账号
  • 导出相关环境变量:
    • export TOKEN_REVIEW_JWT=$(kubectl get secret $(kubectl get serviceaccount admin-panel -o jsonpath='{.secrets[0].name}') -o jsonpath='{ .data.token }' | base64 --decode)
    • export KUBE_CA_CERT=$(kubectl get secret $(kubectl get serviceaccount admin-panel -o jsonpath='{.secrets[0].name}') -o jsonpath='{ .data.ca\.crt }' | base64 --decode)
    • export KUBE_HOST=$(kubectl config view --raw --minify --flatten -o jsonpath='{.clusters[].cluster.server}')
  • 配置Kubernetes认证:vault write auth/kubernetes/config token_reviewer_jwt="$TOKEN_REVIEW_JWT" kubernetes_host="$KUBE_HOST" kubernetes_ca_cert="$KUBE_CA_CERT"
  • 启用KV-v2引擎并写入密钥:vault secrets enable -path=secret kv-v2 和 vault kv put secret/admin-panel/config username='user' password='password'
  • 创建策略:
vault policy write admin-panel - <<EOF
path "secret/data/admin-panel/config" {
  capabilities = ["read"]
}
EOF
  • 创建认证角色:vault write auth/kubernetes/role/admin-panel bound_service_account_names=admin-panel bound_service_account_namespaces=admin-panel policies=admin-panel ttl=24h
  • 测试Pod配置:
apiVersion: v1
kind: Pod
metadata:
  name: test
  labels:
    app: test
  annotations:
    vault.hashicorp.com/agent-inject: "true"
    vault.hashicorp.com/role: "admin-panel"
    vault.hashicorp.com/agent-inject-secret-credentials.txt: "secret/data/admin-panel/config"
spec:
  serviceAccountName: admin-panel
  containers:
    - name: test
      image: nginx

错误信息

2022-08-30T21:57:18.366Z [ERROR] auth.handler: error authenticating:
  error=
  | Error making API request.
  | 
  | URL: PUT https://vault-cluster-private-vault-dflosi.hfols.z1.hashicorp.cloud:8200/v1/auth/kubernetes/login
  | Code: 403. Errors:
  | 
  | * permission denied
   backoff=3m48.31s
2022-08-30T22:01:06.685Z [INFO]  auth.handler: authenticating
2022-08-30T22:01:06.703Z [ERROR] auth.handler: error authenticating:
  error=
  | Error making API request.

排查修复方向

  1. 补全TokenReview权限
    默认服务账号没有Kubernetes TokenReview权限,需创建ClusterRole并绑定到目标SA:

    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRole
    metadata:
      name: vault-token-reviewer
    rules:
    - apiGroups: ["authentication.k8s.io"]
      resources: ["tokenreviews"]
      verbs: ["create"]
    ---
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRoleBinding
    metadata:
      name: vault-token-reviewer-binding
    subjects:
    - kind: ServiceAccount
      name: admin-panel
      namespace: admin-panel
    roleRef:
      kind: ClusterRole
      name: vault-token-reviewer
      apiGroup: rbac.authorization.k8s.io
    

    绑定完成后,重新导出TOKEN_REVIEW_JWT并更新Vault的Kubernetes配置。

  2. 校验命名空间一致性
    操作步骤中提到命名空间为admin panel,但命令及角色配置中使用的是admin-panel,需确认实际命名空间名称完全匹配,避免因名称空格/连字符差异导致绑定失效。

  3. 验证VPC对等连接路由
    检查HVN与EKS VPC的对等连接路由表,确保双向路由配置正确,EKS集群Pod能访问Vault私有端点,堡垒机与Vault的连通性也需再次确认。

  4. 检查Injector配置
    通过helm get values vault-injector查看injector的Vault地址配置,确保vault.address指向Vault私有访问端点,而非公网地址。

  5. 验证Token权限有效性
    执行kubectl auth can-i create tokenreviews --as=system:serviceaccount:admin-panel:admin-panel,返回yes才表示服务账号拥有正确的TokenReview权限。


内容的提问来源于stack exchange,提问作者Murakami

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 15:51:31