【发布时间】:2017-11-02 21:50:07
【问题描述】:
我正在运行启用了 RBAC 的 Kubernetes 1.6.2。我创建了一个用户kube-admin,它具有以下集群角色绑定
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1beta1
metadata:
name: k8s-admin
subjects:
- kind: User
name: kube-admin
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: ClusterRole
name: cluster-admin
apiGroup: rbac.authorization.k8s.io
当我尝试 kubectl exec 进入正在运行的 pod 时,我收到以下错误。
kubectl -n kube-system exec -it kubernetes-dashboard-2396447444-1t9jk -- /bin/bash
error: unable to upgrade connection: Forbidden (user=system:anonymous, verb=create, resource=nodes, subresource=proxy)
我猜我缺少ClusterRoleBinding ref,我缺少哪个角色?
【问题讨论】:
标签: kubernetes kubectl