CKAD 常用资源:Role 与 RoleBinding

Role 和 RoleBinding 的 YAML 模板与 CKAD 常考字段解析

Role 定义命名空间内权限,RoleBinding 把权限绑定给用户、组或 ServiceAccount。公式:先写权限,再写绑定。

YAML 模板

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: pod-reader
  namespace: security
rules:
- apiGroups: [""]
  resources: ["pods"]
  verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: read-pods
  namespace: security
subjects:
- kind: ServiceAccount
  name: app-sa
  namespace: security
roleRef:
  kind: Role
  name: pod-reader
  apiGroup: rbac.authorization.k8s.io

常考字段解析

  • rules[].apiGroups:核心资源如 Pod、Service 写空字符串 ""
  • rules[].resources:资源复数名,如 podsservices
  • rules[].verbs:动作,如 getlistwatchcreatedelete
  • subjects[].kindUserGroupServiceAccount
  • roleRef:绑定到哪个 Role,创建后不能直接修改。

常用命令

1
2
3
k create role pod-reader -n security --verb=get,list,watch --resource=pods
k create rolebinding read-pods -n security --role=pod-reader --serviceaccount=security:app-sa
k auth can-i list pods -n security --as=system:serviceaccount:security:app-sa

易错点

  • Role 只在自己的 namespace 生效。
  • ServiceAccount subject 需要写 namespace。
comments powered by Disqus