创建非Root用户Pod时RunAsUser被禁止,请求指导配置ClusterRoleBinding
解决Kubernetes中设置Pod runAsUser被禁止的权限问题
你在创建带runAsUser:1000和fsGroup:2000的Pod时碰到的Forbidden错误,本质是当前操作的用户没有被授予修改Pod安全上下文的RBAC权限。结合你的Kubernetes 1.10.2版本,我给你整理了具体的配置步骤:
第一步:创建具备Pod安全上下文权限的ClusterRole
首先定义一个ClusterRole,让它拥有创建、修改Pod安全上下文的权限。你可以用下面的YAML配置:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: pod-security-context-editor rules: - apiGroups: [""] resources: ["pods"] verbs: ["create", "update", "patch"] # 如果你想更精细化控制,只允许修改securityContext字段,可以用下面的规则: # - apiGroups: [""] # resources: ["pods"] # verbs: ["create"] # - apiGroups: [""] # resources: ["pods/securityContext"] # verbs: ["update", "patch"]
第二步:创建ClusterRoleBinding绑定到你的用户/服务账户
接下来需要把上面的ClusterRole绑定到你用来操作K8s的身份上——如果你用的是默认服务账户,或者是特定用户,对应不同的配置:
绑定到默认服务账户(比如default命名空间下的default SA)
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: grant-pod-security-context-access subjects: - kind: ServiceAccount name: default namespace: default roleRef: kind: ClusterRole name: pod-security-context-editor apiGroup: rbac.authorization.k8s.io
绑定到具体用户(比如你登录用的用户名)
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: grant-pod-security-context-access-user subjects: - kind: User name: "your-login-username" # 替换成你的实际用户名 apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: pod-security-context-editor apiGroup: rbac.authorization.k8s.io
第三步:应用配置并验证
执行命令把配置应用到集群:
kubectl apply -f clusterrole.yaml kubectl apply -f clusterrolebinding.yaml
然后再尝试创建你的Pod:
kubectl apply -f test.yml
可选:限制权限到特定命名空间
如果你不需要集群级别的权限,只想在某个命名空间内操作,可以把ClusterRole换成Role,ClusterRoleBinding换成RoleBinding,这样更安全:
# role.yaml(仅在default命名空间生效) apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: pod-security-context-role namespace: default rules: - apiGroups: [""] resources: ["pods"] verbs: ["create", "update", "patch"] # rolebinding.yaml apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: grant-pod-security-context-access-ns namespace: default subjects: - kind: ServiceAccount name: default namespace: default roleRef: kind: Role name: pod-security-context-role apiGroup: rbac.authorization.k8s.io
这样配置后,你就能在指定命名空间内创建带安全上下文的Pod了。
内容的提问来源于stack exchange,提问作者Ravichandra
相关产品推荐
相关产品推荐

