You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes获取system:unauthenticated授权列表及报错排查

问题背景

已为Kubernetes集群启用匿名认证,尝试列出未认证用户(system:unauthenticated)的权限时,执行命令后APIServer返回如下报错:

➜  ~ kubectl auth can-i --list --as=system:authenticated                                                                                                                                                                                                                                                                                                   
error: You must be logged in to the server (the server has asked for the client to provide credentials (post selfsubjectrulesreviews.authorization.k8s.io))

当前环境版本信息如下,执行版本查询时已经提示客户端与服务端版本差超出支持范围:

➜  ~ kubectl version                                                                                                                                                                                                                                                                                                                           
WARNING: This version information is deprecated and will be replaced with the output from kubectl version --short.  Use --output=yaml|json to get the full version.
Client Version: version.Info{Major:"1", Minor:"24", GitVersion:"v1.24.1", GitCommit:"3ddd0f45aa91e2f30c70734b175631bec5b5825a", GitTreeState:"clean", BuildDate:"2022-05-24T12:17:11Z", GoVersion:"go1.18.2", Compiler:"gc", Platform:"darwin/arm64"}
Kustomize Version: v4.5.4
Server Version: version.Info{Major:"1", Minor:"20", GitVersion:"v1.20.15", GitCommit:"8f1e5bf0b9729a899b8df86249b56e2c74aebc55", GitTreeState:"clean", BuildDate:"2022-01-19T17:23:01Z", GoVersion:"go1.15.15", Compiler:"gc", Platform:"linux/amd64"}
WARNING: version difference between client (1.24) and server (1.20) exceeds the supported minor version skew of +/-1
报错原因
  • 命令参数书写错误:你要查询的是未认证用户system:unauthenticated的权限,但实际执行的命令里传的是--as=system:authenticated,这是所有已通过认证的用户所属的默认用户组,和目标查询身份不符。不过这个笔误不是触发401报错的核心原因。
  • 接口鉴权逻辑限制:kubectl auth can-i --list 底层调用的是selfsubjectrulesreviews.authorization.k8s.io接口,这个接口的设计逻辑是仅返回请求发起方自身的权限规则。如果要通过--as参数模拟其他身份查询权限,前提是发起请求的客户端本身持有有效凭证、通过APIServer认证,且拥有调用该接口的权限。
    即使你开启了匿名认证,匿名身份system:unauthenticated默认没有调用SelfSubjectRulesReview接口的权限,APIServer收到无有效凭证的请求时,会直接返回401要求客户端提供认证信息,根本不会走到后续的--as身份模拟处理逻辑。
  • 版本兼容问题放大异常:当前kubectl客户端版本为v1.24.1,对接的APIServer版本为v1.20.15,版本差达到4个小版本,远超Kubernetes官方支持的客户端/服务端±1小版本的兼容范围,两个版本间鉴权接口的参数校验、请求处理逻辑存在差异,会进一步提升接口调用异常的概率。
正确查询未认证用户权限的方案

不要使用--list参数走SelfSubjectRulesReview接口,改用以下两种方式查询:

  • 单条权限校验:针对具体的资源操作做定向校验,比如校验匿名用户是否拥有列出Pod的权限,执行如下命令即可,返回yes代表有权限,返回no代表无权限:
    kubectl auth can-i list pods --as=system:unauthenticated
    
  • 全量权限枚举:直接拉取集群内所有RBAC绑定资源,筛选关联system:unauthenticated组的权限规则:
    # 查询集群范围绑定给匿名用户的权限
    kubectl get clusterrolebindings -o yaml | grep -B2 -A20 "system:unauthenticated"
    # 查询所有命名空间内绑定给匿名用户的权限
    kubectl get rolebindings --all-namespaces -o yaml | grep -B2 -A20 "system:unauthenticated"
    

内容的提问来源于stack exchange,提问作者Shuzheng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.29 15:12:21