【问题标题】:Getting kubernetes config file using google-cloud API使用 google-cloud API 获取 kubernetes 配置文件
【发布时间】:2020-04-17 17:14:20
【问题描述】:

我可以像这样使用谷歌云的 kubernetes API:

import os
import time
import json
from pprint import pprint

from google.oauth2 import service_account
import googleapiclient.discovery
from six.moves import input

# https://developers.google.com/identity/protocols/oauth2/scopes
scopes = [
    'https://www.googleapis.com/auth/cloud-platform',
    'https://www.googleapis.com/auth/compute'
]
credentials = service_account.Credentials.from_service_account_file(
    'service_account.json',
    scopes = scopes
)


container = googleapiclient.discovery.build('container', 'v1', credentials = credentials)
loc = container.projects().locations()
client = loc.getServerConfig(name="projects/MY_PROJECT/locations/europe-west1-b")
client.execute()

但是,我想实现相当于

gcloud container clusters get-credentials MY_CLUSTER --zone=europe-west1-b --project MY_PROJECT

即获取完整的 kubernetes config+autorization 文件(然后我可以将其与 kubernetes python 模块一起使用)

查看 API 时

https://cloud.google.com/kubernetes-engine/docs/reference/rest

似乎缺少 get-credentials 调用?还是我使用了错误的 API?

【问题讨论】:

    标签: kubernetes google-kubernetes-engine


    【解决方案1】:

    Google Cloud 使用短暂的令牌(大约 10 秒)并使用 gcloud 工具刷新/获取令牌。

    如果您想创建一个长期存在的令牌,您可以在这里创建一个服务帐户https://console.cloud.google.com/iam-admin/serviceaccounts,角色为“Kubernetes 引擎开发人员”并下载 JSON 文件。例如,将 kubeconfig 配置为使用 gcp auth 提供程序

     [{name: user-1, user: {auth-provider: {name: gcp}}}]
    

    将环境变量 GOOGLE_APPLICATION_CREDENTIALS 设置为为服务帐号下载的 JSON 文件的绝对路径。与 kubectl 一起工作,因为它有特殊的支持。

    如果你想将它与 f.e. 一起使用。 python 你需要从serviceaccount获取token

    kubectl describe serviceaccount myserviceaccount
    kubectl describe secrets [secret-name]
    

    这个可以在库中使用

    config.load_kube_config()
    client.configuration.api_key['authorization'] = 'your token goes here'
    client.configuration.api_key_prefix['authorization'] = 'Bearer'
    

    请注意,长期使用的凭据必须得到特别好的保护。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2015-08-20
      • 1970-01-01
      • 1970-01-01
      • 2020-08-04
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2019-08-22
      相关资源
      最近更新 更多