Spinnaker指定K8s用户认证失败:仍使用system:anonymous
Let's work through both of your authentication problems with Spinnaker and Kubernetes step by step:
Issue 1: Spinnaker uses system:anonymous despite specifying user veeru
The root cause here is a mismatch between the user name in your kubeconfig and what you've configured in Halyard.
Looking at your first kubeconfig, the user entry has a full name of veeru/xx-xx-xx-220:8443, but in ~/.hal/config you've set user: veeru (only the prefix). Halyard needs the exact user name from the kubeconfig to pick the correct credentials.
Fix steps:
- Update your
~/.hal/configto use the full user name fromkubeconfig:kubernetes: enabled: true accounts: - name: my-k8s-account requiredGroupMembership: [] providerVersion: V1 dockerRegistries: - accountName: my-docker-registry2 namespaces: [] configureImagePullSecrets: true namespaces: ["area-51"] user: veeru/xx-xx-xx-220:8443 # Use the full user name from kubeconfig omitNamespaces: [] kubeconfigFile: /home/ubuntu/.kube/config oauthScopes: [] oAuthScopes: [] primaryAccount: my-k8s-account - Verify that the
veeruuser has the necessary RBAC permissions in thearea-51namespace (e.g., permission to get services). You'll need aRoleandRoleBindinglike this:apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: namespace: area-51 name: spinnaker-veeru-role rules: - apiGroups: [""] resources: ["services"] verbs: ["get", "list", "watch"] # Add other resources (pods, deployments, etc.) as needed for Spinnaker --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: spinnaker-veeru-binding namespace: area-51 subjects: - kind: User name: veeru # Match your Kubernetes user name apiGroup: rbac.authorization.k8s.io roleRef: kind: Role name: spinnaker-veeru-role apiGroup: rbac.authorization.k8s.io - Redeploy Spinnaker:
hal deploy apply
Issue 2: hal deploy fails with permission denied for spinnaker-service-account
When you run hal deploy, Halyard performs a cluster-wide validation step: it tries to list all namespaces to confirm connectivity. Your service account only has permissions for the webapp namespace, so this cluster-level request gets rejected (even though kubectl get namespace webapp works, since that's a namespace-scoped operation).
Fix steps:
- Grant the service account cluster-level permission to list namespaces (this is minimal and safe for validation):
Create a filespinnaker-namespace-role.yamlwith:
Apply it with:apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: spinnaker-namespace-reader rules: - apiGroups: [""] resources: ["namespaces"] verbs: ["list"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: spinnaker-read-namespaces subjects: - kind: ServiceAccount name: spinnaker-service-account namespace: default roleRef: kind: ClusterRole name: spinnaker-namespace-reader apiGroup: rbac.authorization.k8s.iokubectl apply -f spinnaker-namespace-role.yaml - Ensure the service account has full permissions in the
webappnamespace for Spinnaker's operations (deployments, services, secrets, etc.). ExampleRoleandRoleBinding:apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: namespace: webapp name: spinnaker-service-role rules: - apiGroups: ["", "apps", "extensions"] resources: ["deployments", "replicasets", "pods", "services", "secrets", "configmaps"] verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: spinnaker-service-binding namespace: webapp subjects: - kind: ServiceAccount name: spinnaker-service-account namespace: default roleRef: kind: Role name: spinnaker-service-role apiGroup: rbac.authorization.k8s.io - Double-check that your
~/.hal/configspecifies the correct namespaces and user:kubernetes: enabled: true accounts: - name: my-k8s-account # ... other config namespaces: ["webapp"] user: spinnaker-service-account # Match the user name in your updated kubeconfig kubeconfigFile: /path/to/your/updated/kubeconfig - Run the deploy again:
hal deploy apply
内容的提问来源于stack exchange,提问作者veerendra2

