RBAC
开启 RBAC
kubeadm 安装的开启方式
vim /etc/kubernetes/manifests/kube-apiserver.yaml
spec:
containers:
- command:
- --authorization-mode=Node,RBAC二进制安装的开启方式
vim /usr/lib/systemd/system/kube-apiserver.service
# 添加如下选项
--authorization-mode=Node,RBAC \Role 示例
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
namespace: default
name: pod-reader
rules:
- apiGroups: [""] # "" 标明 core API 组
resources: ["pods"]
verbs: ["get", "watch", "list"]ClusterRole 示例
RoleBinding 示例
ClusterRoleBinding 示例
Last updated