kubernetes - 由于RBAC而无法在Kubernetes集群上部署厚皮动物

标签 kubernetes

我的目标是运行以下命令:

sudo pachctl deploy google ${BUCKET_NAME} ${STORAGE_SIZE} --dynamic-etcd-nodes=1

我遇到有关我拥有的权限的错误(最后发布)。因此,我想通过以下命令创建角色:
sudo kubectl create clusterrolebinding aviralsrivastava-cluster-admin-binding --clusterrole=cluster-admin --user=aviral@socialcops.com

但是,以上命令给我一个错误:
Error from server (Forbidden): clusterrolebindings.rbac.authorization.k8s.io is forbidden: User "aviral@socialcops.com" cannot create clusterrolebindings.rbac.authorization.k8s.io at the cluster scope: Required "container.clusterRoleBindings.create" permission.

最佳答案

您需要将以下RBAC权限作为cluster-admin应用,以向用户aviral@socialcops.com提供权限以创建clusterRole和clusterRoleBinding:

ClusterRole.yaml

apiVersion: rbac.authorization.k8s.io/v1beta1
kind: ClusterRole
metadata:
  name: prom-admin
rules:
# Just an example, feel free to change it
- apiGroups: [""]
  resources: ["clusterRole", "clusterRoleBinding"]
  verbs: ["get", "watch", "list", "create", "update", "patch", "delete"]

ClusterRoleBinding.yaml
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: ClusterRoleBinding
metadata:
  name: prom-rbac
subjects:
- kind: User
  name: aviral@socialcops.com
roleRef:
  kind: ClusterRole
  name: prom-admin
  apiGroup: rbac.authorization.k8s.io

关于kubernetes - 由于RBAC而无法在Kubernetes集群上部署厚皮动物,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/53956530/

相关文章:

kubernetes - 版本 "Deployment"中的种类 "extensions/v1beta1"没有匹配项

mysql - 并行运行 22 个 airflow worker pod 时 k8s 集群挂起

jenkins - Google Cloud Jenkins gcloud 推送访问被拒绝

kubernetes - 安装到多个Kubernetes Pod时如何写入gcePersistentDisk

kubernetes - kubespray部署无法在https://apt.dockerproject.org/gpg下载 key :HTTP错误404:未找到

ssl - openssl 提供 Kubernetes 入口 Controller 假证书

dns - Kubernetes 多集群服务发现

python - standard_init_linux.go :211: exec user process caused "exec format error"

azure - 如何更改 kubernetes api 服务器标志 [AKS] [Kubernetes 1.8]

docker - 收集 kubernetes 的 pods 日志