【发布时间】:2019-04-23 01:41:44
【问题描述】:
我正在尝试实施审核政策 我的yaml
~/.minikube/addons$ cat audit-policy.yaml
# Log all requests at the Metadata level.
apiVersion: audit.k8s.io/v1beta1
kind: Policy
rules:
- level: Metadata
Pod 卡住了
minikube start --extra-config=apiserver.Authorization.Mode=RBAC --extra-config=apiserver.Audit.LogOptions.Path=/var/logs/audit.log --extra-config=apiserver.Audit.PolicyFile=/etc/kubernetes/addons/audit-policy.yaml
???? minikube v0.35.0 on linux (amd64)
???? Tip: Use 'minikube start -p <name>' to create a new cluster, or 'minikube delete' to delete this one.
???? Restarting existing virtualbox VM for "minikube" ...
⌛ Waiting for SSH access ...
???? "minikube" IP address is 192.168.99.101
???? Configuring Docker as the container runtime ...
✨ Preparing Kubernetes environment ...
▪ apiserver.Authorization.Mode=RBAC
▪ apiserver.Audit.LogOptions.Path=/var/logs/audit.log
▪ apiserver.Audit.PolicyFile=/etc/kubernetes/addons/audit-policy.yaml
???? Pulling images required by Kubernetes v1.13.4 ...
???? Relaunching Kubernetes v1.13.4 using kubeadm ...
⌛ Waiting for pods: apiserver
为什么?
我能做到
minkub start
然后我去 minikube ssh
$ sudo bash
$ cd /var/logs
bash: cd: /var/logs: No such file or directory
ls
cache empty lib lock log run spool tmp
如何应用额外配置?
【问题讨论】:
-
cd /var/logs应该是cd /var/log -
我同意,我里面有容器、pods和vmware-vmsvc.log。
标签: kubernetes