ClusterRole 和 ClusterRoleBinding 的 YAML 模板与 CKAD 常考字段解析 ClusterRole 定义集群级权限,ClusterRoleBinding 把权限绑定到整个集群范围。CKAD 常考允许某用户读取所有 Pod。
YAML 模板 1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRole
metadata :
name : pod-reader
rules :
- apiGroups : [ "" ]
resources : [ "pods" ]
verbs : [ "get" , "list" , "watch" ]
---
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRoleBinding
metadata :
name : read-pods
subjects :
- kind : User
name : jane
apiGroup : rbac.authorization.k8s.io
roleRef :
kind : ClusterRole
name : pod-reader
apiGroup : rbac.authorization.k8s.io
常考字段解析 ClusterRole.metadata.namespace:不能写,ClusterRole 是集群级资源。ClusterRoleBinding.metadata.namespace:不能写,ClusterRoleBinding 也是集群级资源。subjects[].kind:用户用 User,服务账号用 ServiceAccount。roleRef.kind:这里通常是 ClusterRole。常用命令 1
2
3
k create clusterrole pod-reader --verb= get,list,watch --resource= pods
k create clusterrolebinding read-pods --clusterrole= pod-reader --user= jane
k auth can-i list pods --as= jane
易错点 只想授权某个 namespace 时,用 RoleBinding 绑定 ClusterRole 也可以限制范围。 集群级资源不要加 -n。 Licensed under CC BY-NC-SA 4.0