You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes客户端证书认证请求被识别为system:anonymous报403错误

问题根因排查&修复方案

你遇到的问题是两个独立错误叠加导致的,分别是身份未被API server正确识别、RBAC配置存在多处规则不匹配/绑定方式错误,对应修复步骤如下:


1. 先解决身份识别为system:anonymous的问题

报错明确显示请求被识别为匿名用户,说明API server根本没有拿到你提交的客户端证书信息,优先排查以下几点:

  • 检查客户端证书的CN是否正确:
    执行命令查看证书subject字段:
    openssl x509 -in ./userone.crt -text -noout | grep "Subject: CN ="
    
    确认输出的CN值为userone,无拼写错误。
  • 检查证书签发CA是否合法:
    确认你签发userone.crt使用的根CA,和API server--client-ca-file参数指定的CA文件一致,否则API server会直接不信任你的客户端证书,默认判定为匿名用户。
  • 检查反向代理配置(最可能的原因):
    你的报错响应头返回Server: nginx/1.12.2,说明API server前面加了Nginx反向代理。需要确认Nginx已配置以下规则:
    • 开启客户端证书校验:ssl_verify_client on
    • 配置将客户端证书信息透传给上游API server,否则代理层会直接丢弃证书信息,API server永远拿不到客户端证书。
  • 检查curl请求的证书路径是否正确:
    确认当前目录下存在userone.crt和userone.key文件,且当前用户有读取权限,否则curl会静默跳过客户端证书提交。

2. 修复RBAC配置错误

你当前的RBAC配置存在3处明显错误,导致非资源路径权限不生效:

错误1:ClusterRole名称引用错误

你定义的ClusterRole名称是read-only-role,但RoleBinding中roleRef.name写的是read-only,名称不匹配,导致根本没有绑定到你定义的带非资源路径规则的ClusterRole。

错误2:非资源路径匹配规则不完整

你配置的nonResourceURLs只有/apis/*,只能匹配/apis/xxx这类带后缀的路径,你请求的/apis根路径无法匹配,需要补充/apis规则。

错误3:非资源路径权限用RoleBinding绑定不生效

nonResourceURLs属于集群级非资源路径,命名空间级别的RoleBinding绑定的ClusterRole规则仅在对应命名空间内生效,对集群级非资源路径完全不生效,必须用ClusterRoleBinding绑定。


修复后的RBAC配置参考

  1. 修正后的ClusterRole:
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: read-only-role
rules:
- apiGroups: [""]
  resources: ["*"]
  verbs: ["get", "list", "watch"]
- nonResourceURLs:
  - /metrics
  - /api/*
  - /apis
  - /apis/*
  verbs: ["get"]
  1. 修正名称后的RoleBinding(保留xyz命名空间的资源访问权限):
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: read-only-binding
  namespace: xyz
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: read-only-role # 修正为正确的ClusterRole名称
subjects:
- apiGroup: rbac.authorization.k8s.io
  kind: User
  name: userone
  1. 新增ClusterRoleBinding绑定非资源路径权限:
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: read-only-non-resource-binding
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: read-only-role
subjects:
- apiGroup: rbac.authorization.k8s.io
  kind: User
  name: userone

所有配置生效后,重新发起curl请求即可正常访问/apis端点。

内容的提问来源于stack exchange,提问作者Venu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 17:15:08