生成集群admin token
在 K8s 中生成集群admin token需要创建一个admin用户并授予admin角色绑定,使用下面的yaml文件创建admin用户并赋予他管理员权限,然后可以通过token访问kubernetes:
kind: ClusterRoleBindingapiVersion: rbac.authorization.k8s.io/v1beta1metadata:name: adminannotations:rbac.authorization.kubernetes.io/autoupdate: "true"roleRef:kind: ClusterRolename: cluster-adminapiGroup: rbac.authorization.k8s.iosubjects:- kind: ServiceAccountname: adminnamespace: kube-system---apiVersion: v1kind: ServiceAccountmetadata:name: adminnamespace: kube-systemlabels:kubernetes.io/cluster-service: "true"addonmanager.kubernetes.io/mode: Reconcile
然后执行下面的命令创建 serviceaccount 和角色绑定:
kubectl create -f admin-role.yaml
创建完成后获取secret中token的值:
# 获取admin-token的secret名字$ kubectl -n kube-system get secret|grep admin-tokenadmin-token-nwphb kubernetes.io/service-account-token 3 6m# 获取token的值$ kubectl -n kube-system describe secret admin-token-nwphbName: admin-token-nwphbNamespace: kube-systemLabels: <none>Annotations: kubernetes.io/service-account.name=adminkubernetes.io/service-account.uid=f37bd044-bfb3-11e7-87c0-f4e9d49f8ed0Type: kubernetes.io/service-account-tokenData====namespace: 11 bytestoken: 非常长的字符串ca.crt: 1310 bytes
