k8s带授权时,生成访问k8s api的token
2019-04-30 本文已影响0人
yuluxs
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: k8s-authorize
namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: k8s-authorize
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: k8s-authorize
namespace: kube-system
上面创建k8s-authorize账户,绑定cluster-admin角色,拥有最高权限,会在该目录下自动创建k8s-authorize的secrets
$ kubectl describe secrets -n kube-system k8s-authorize-tok
如下图

参考:
https://segmentfault.com/a/1190000017865019?utm_source=tag-newest
https://www.jianshu.com/p/8d1188f106f4