You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS集群访问授权相关问题:证书获取及kubectl配置咨询

EKS集群访问授权相关问题:证书获取及kubectl配置咨询

嘿,我来帮你解决这两个EKS集群访问的问题哈,先理下你的现状,再一步步给你说解决方案:

你的操作现状回顾

你已经按照证书签发相关文档完成了证书申请流程,还创建了ClusterRole和RoleBinding做权限测试,测试结果如下:

$ kubectl auth can-i create pods --as=myserver
yes
$ kubectl auth can-i list pods --as=myserver
no
$ kubectl auth can-i delete secrets --as=myserver
no

但当你用--user=myserver直接测试时,出现了未授权错误:

error: You must be logged in to the server (Unauthorized)


一、如何获取EKS集群的certificate-authority?

有两种简单的方式可以获取:

  • 从现有kubectl配置提取:
    执行以下命令,会把集群CA证书解码后保存到本地ca.crt文件中:
    kubectl config view --raw --minify --output 'jsonpath={.clusters[*].cluster.certificate-authority-data}' | base64 --decode > ca.crt
    
  • 从AWS控制台获取:
    登录AWS控制台进入你的EKS集群详情页,找到「配置」→「认证」标签,在「集群证书颁发机构」区域可以直接复制证书内容,或者下载对应的证书文件。

二、如何配置kubectl使用.key和.crt文件访问集群?

你可以通过以下步骤把你的证书和密钥添加到kubectl配置中:

  1. 确认集群配置(如果kubeconfig里已有集群信息可跳过这步):
    kubectl config set-cluster <你的EKS集群名称> \
      --server=<集群API服务器地址> \
      --certificate-authority=ca.crt \
      --embed-certs=true
    
  2. 添加用户配置,关联你的.key和.crt文件:
    kubectl config set-credentials myserver \
      --client-key=myserver.key \
      --client-certificate=myserver.crt \
      --embed-certs=true
    
  3. 创建上下文,绑定用户和集群:
    kubectl config set-context myserver-context \
      --cluster=<你的EKS集群名称> \
      --user=myserver
    
  4. 切换到新上下文:
    kubectl config use-context myserver-context
    

完成以上步骤后,再执行kubectl auth can-i create pods --user=myserver就能正常验证权限啦。

备注:内容来源于stack exchange,提问作者Alexy Pulivelil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.16 12:04:41