You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spinnaker指定K8s用户认证失败:仍使用system:anonymous

Fixing Spinnaker Kubernetes Authentication Issues

Let's work through both of your authentication problems with Spinnaker and Kubernetes step by step:

Issue 1: Spinnaker uses system:anonymous despite specifying user veeru

The root cause here is a mismatch between the user name in your kubeconfig and what you've configured in Halyard.

Looking at your first kubeconfig, the user entry has a full name of veeru/xx-xx-xx-220:8443, but in ~/.hal/config you've set user: veeru (only the prefix). Halyard needs the exact user name from the kubeconfig to pick the correct credentials.

Fix steps:

  1. Update your ~/.hal/config to use the full user name from kubeconfig:
    kubernetes:
      enabled: true
      accounts:
      - name: my-k8s-account
        requiredGroupMembership: []
        providerVersion: V1
        dockerRegistries:
        - accountName: my-docker-registry2
          namespaces: []
        configureImagePullSecrets: true
        namespaces: ["area-51"]
        user: veeru/xx-xx-xx-220:8443  # Use the full user name from kubeconfig
        omitNamespaces: []
        kubeconfigFile: /home/ubuntu/.kube/config
        oauthScopes: []
        oAuthScopes: []
      primaryAccount: my-k8s-account
    
  2. Verify that the veeru user has the necessary RBAC permissions in the area-51 namespace (e.g., permission to get services). You'll need a Role and RoleBinding like this:
    apiVersion: rbac.authorization.k8s.io/v1
    kind: Role
    metadata:
      namespace: area-51
      name: spinnaker-veeru-role
    rules:
    - apiGroups: [""]
      resources: ["services"]
      verbs: ["get", "list", "watch"]
    # Add other resources (pods, deployments, etc.) as needed for Spinnaker
    ---
    apiVersion: rbac.authorization.k8s.io/v1
    kind: RoleBinding
    metadata:
      name: spinnaker-veeru-binding
      namespace: area-51
    subjects:
    - kind: User
      name: veeru  # Match your Kubernetes user name
      apiGroup: rbac.authorization.k8s.io
    roleRef:
      kind: Role
      name: spinnaker-veeru-role
      apiGroup: rbac.authorization.k8s.io
    
  3. Redeploy Spinnaker:
    hal deploy apply
    

Issue 2: hal deploy fails with permission denied for spinnaker-service-account

When you run hal deploy, Halyard performs a cluster-wide validation step: it tries to list all namespaces to confirm connectivity. Your service account only has permissions for the webapp namespace, so this cluster-level request gets rejected (even though kubectl get namespace webapp works, since that's a namespace-scoped operation).

Fix steps:

  1. Grant the service account cluster-level permission to list namespaces (this is minimal and safe for validation):
    Create a file spinnaker-namespace-role.yaml with:
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRole
    metadata:
      name: spinnaker-namespace-reader
    rules:
    - apiGroups: [""]
      resources: ["namespaces"]
      verbs: ["list"]
    ---
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRoleBinding
    metadata:
      name: spinnaker-read-namespaces
    subjects:
    - kind: ServiceAccount
      name: spinnaker-service-account
      namespace: default
    roleRef:
      kind: ClusterRole
      name: spinnaker-namespace-reader
      apiGroup: rbac.authorization.k8s.io
    
    Apply it with:
    kubectl apply -f spinnaker-namespace-role.yaml
    
  2. Ensure the service account has full permissions in the webapp namespace for Spinnaker's operations (deployments, services, secrets, etc.). Example Role and RoleBinding:
    apiVersion: rbac.authorization.k8s.io/v1
    kind: Role
    metadata:
      namespace: webapp
      name: spinnaker-service-role
    rules:
    - apiGroups: ["", "apps", "extensions"]
      resources: ["deployments", "replicasets", "pods", "services", "secrets", "configmaps"]
      verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
    ---
    apiVersion: rbac.authorization.k8s.io/v1
    kind: RoleBinding
    metadata:
      name: spinnaker-service-binding
      namespace: webapp
    subjects:
    - kind: ServiceAccount
      name: spinnaker-service-account
      namespace: default
    roleRef:
      kind: Role
      name: spinnaker-service-role
      apiGroup: rbac.authorization.k8s.io
    
  3. Double-check that your ~/.hal/config specifies the correct namespaces and user:
    kubernetes:
      enabled: true
      accounts:
      - name: my-k8s-account
        # ... other config
        namespaces: ["webapp"]
        user: spinnaker-service-account  # Match the user name in your updated kubeconfig
        kubeconfigFile: /path/to/your/updated/kubeconfig
    
  4. Run the deploy again:
    hal deploy apply
    

内容的提问来源于stack exchange,提问作者veerendra2

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:05:03