【发布时间】:2018-06-16 08:26:48
【问题描述】:
我在 kops 预置的 AWS 集群上测试了使用 EBS 卷挂载的 kubernetes 部署。这是部署 yml 文件:
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
name: helloworld-deployment-volume
spec:
replicas: 1
template:
metadata:
labels:
app: helloworld
spec:
containers:
- name: k8s-demo
image: wardviaene/k8s-demo
ports:
- name: nodejs-port
containerPort: 3000
volumeMounts:
- mountPath: /myvol
name: myvolume
volumes:
- name: myvolume
awsElasticBlockStore:
volumeID: <volume_id>
kubectl create -f <path_to_this_yml> 之后,我在 pod 描述中收到以下消息:
Attach failed for volume "myvolume" : Error attaching EBS volume "XXX" to instance "YYY": "UnauthorizedOperation: You are not authorized to perform this operation. status code: 403
看起来这只是一个权限问题。好的,我检查了节点角色 IAM -> Roles -> nodes.<my_domain> 的策略,发现没有允许操作卷的操作,默认情况下只有 ec2:DescribeInstances 操作。所以我添加了AttachVolume 和DetachVolume 操作:
{
"Sid": "kopsK8sEC2NodePerms",
"Effect": "Allow",
"Action": [
"ec2:DescribeInstances",
"ec2:AttachVolume",
"ec2:DetachVolume"
],
"Resource": [
"*"
]
},
这并没有帮助。我仍然收到该错误:
Attach failed for volume "myvolume" : Error attaching EBS volume "XXX" to instance "YYY": "UnauthorizedOperation: You are not authorized to perform this operation.
我错过了什么吗?
【问题讨论】:
标签: amazon-web-services amazon-ec2 kubernetes kubectl kops