You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SAML联邦AWS用户访问EKS Kubernetes集群凭证错误排查求助

缺失/错误配置项说明

以下是当前排查到的所有需要修正的配置点:

  • aws-auth ConfigMap配置错误
    EKS的aws-auth ConfigMap的mapRoles字段中,rolearn必须填写原始IAM角色的静态ARN,不能填写带会话后缀的STS临时角色ARN。
    修正后的mapRoles配置如下:
    mapRoles:
    ----
    - groups:
      - xx:developers
      rolearn: arn:aws:iam::123456789:role/CT/PUsers
      username: name@xxx.com
    
  • kubeconfig上下文与用户配置不匹配
    当前配置中context的user字段值为arn:aws:eks:us-east-1:123456789:cluster/cluster-name,但users列表中对应配置的name为arn:aws:eks:us-east-1:123456789:cluster/amp-eks18,二者不匹配导致无法找到正确的认证配置。只需将二者修改为一致即可,示例修正如下:
    contexts:
    - context:
        cluster: arn:aws:eks:us-east-1:123456789:cluster/cluster-name
        user: arn:aws:eks:us-east-1:123456789:cluster/amp-eks18
      name: stage18
    
  • kubeconfig未指定AWS凭证Profile
    用户通过gimme-aws-creds生成的凭证存储在名为ihm的AWS Profile中,但kubeconfig的exec配置中未指定该Profile,导致aws eks get-token命令默认读取default Profile的无效凭证。可以通过两种方式修正:
    1. 在exec的args中添加profile参数:
    args:
    - --region
    - us-east-1
    - --profile
    - ihm
    - eks
    - get-token
    - --cluster-name
    - cluster-name
    
    1. 执行kubectl/k9s前设置环境变量:export AWS_PROFILE=ihm
  • RBAC权限校验(可选,避免后续权限报错)
    需确认集群中已存在对应xx:developers组的ClusterRoleBinding/RoleBinding,绑定了符合只读要求的ClusterRole(如系统默认的view角色),示例配置如下:
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRoleBinding
    metadata:
      name: developers-view
    subjects:
    - kind: Group
      name: xx:developers
      apiGroup: rbac.authorization.k8s.io
    roleRef:
      kind: ClusterRole
      name: view
      apiGroup: rbac.authorization.k8s.io
    

内容的提问来源于stack exchange,提问作者user6826691

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 01:00:00