SAML联邦AWS用户访问EKS Kubernetes集群凭证错误排查求助
缺失/错误配置项说明
以下是当前排查到的所有需要修正的配置点:
- aws-auth ConfigMap配置错误
EKS的aws-auth ConfigMap的mapRoles字段中,rolearn必须填写原始IAM角色的静态ARN,不能填写带会话后缀的STS临时角色ARN。
修正后的mapRoles配置如下:mapRoles: ---- - groups: - xx:developers rolearn: arn:aws:iam::123456789:role/CT/PUsers username: name@xxx.com - kubeconfig上下文与用户配置不匹配
当前配置中context的user字段值为arn:aws:eks:us-east-1:123456789:cluster/cluster-name,但users列表中对应配置的name为arn:aws:eks:us-east-1:123456789:cluster/amp-eks18,二者不匹配导致无法找到正确的认证配置。只需将二者修改为一致即可,示例修正如下:contexts: - context: cluster: arn:aws:eks:us-east-1:123456789:cluster/cluster-name user: arn:aws:eks:us-east-1:123456789:cluster/amp-eks18 name: stage18 - kubeconfig未指定AWS凭证Profile
用户通过gimme-aws-creds生成的凭证存储在名为ihm的AWS Profile中,但kubeconfig的exec配置中未指定该Profile,导致aws eks get-token命令默认读取default Profile的无效凭证。可以通过两种方式修正:- 在exec的args中添加profile参数:
args: - --region - us-east-1 - --profile - ihm - eks - get-token - --cluster-name - cluster-name- 执行kubectl/k9s前设置环境变量:
export AWS_PROFILE=ihm
- RBAC权限校验(可选,避免后续权限报错)
需确认集群中已存在对应xx:developers组的ClusterRoleBinding/RoleBinding,绑定了符合只读要求的ClusterRole(如系统默认的view角色),示例配置如下:apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: developers-view subjects: - kind: Group name: xx:developers apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: view apiGroup: rbac.authorization.k8s.io
内容的提问来源于stack exchange,提问作者user6826691
相关产品推荐
相关产品推荐

