【发布时间】:2021-11-30 17:31:50
【问题描述】:
我正在尝试在一个 k8s pod 中调用 k8s api。但遇到以下权限问题:
User "system:serviceaccount:default:flink" cannot list resource "nodes" in API group "" at the cluster scope.
在我的 yaml 文件中,我已经指定了 Role 和 RoleBinding。我在这里想念什么?
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: flink
---
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: zeppelin-server-role
rules:
- apiGroups: [""]
resources: ["pods", "services", "configmaps", "deployments", "nodes"]
verbs: ["create", "get", "update", "patch", "list", "delete", "watch"]
- apiGroups: ["rbac.authorization.k8s.io"]
resources: ["roles", "rolebindings"]
verbs: ["bind", "create", "get", "update", "patch", "list", "delete", "watch"]
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: zeppelin-server-role-binding
namespace: default
subjects:
- kind: ServiceAccount
name: flink
roleRef:
kind: ClusterRole
name: zeppelin-server-role
apiGroup: rbac.authorization.k8s.io
【问题讨论】:
-
您的 pod 是否使用给定的服务帐户?向我们展示您的部署 YAML
标签: kubernetes kubernetes-rbac