Kubernetes API服务安全防护

Kubernetes API服务安全防护

用户和组

  1. 创建ServiceAccount
    vim prometheus-service-account.yml

    apiVersion: v1
    kind: ServiceAccount
    metadata:
      name: prometheus
  1. 创建Cluster级别角色
    vim prometheus-clusterrole.yml

    apiVersion: rbac.authorization.k8s.io/v1beta1
    kind: ClusterRole
    metadata:
      name: prometheus
    rules:
    - apiGroups: ["","extensions","apps"]
      resources:
      - nodes
      - nodes/proxy
      - services
      - endpoints
      - pods
      - deployments
      verbs: ["get", "list", "watch"]
      - nonResourceURLs: ["/metrics"]
  1. 绑定角色及用户
    kubectl create clusterrolebinding prometheus-clusterrole-binding --clusterrole=prometheus --serviceaccount=default:prometheus
  1. 任意启动一个pod,serviceAccountName指定为如上的prometheus
    vim example.yml

    apiVersion: v1
    kind: Pod
    metadata:
      name: example
    spec:
      serviceAccountName: prometheus
      containers:
      - image: luksa/kubia
        name: kubia
        ports:
        - containerPort: 8080
          protocol: TCP
  1. 拷贝这个Pod的ca.crt/token/namespace
    kubectl describe pod example

    ---
    Mounts:
      /var/run/secrets/kubernetes.io/serviceaccount from prometheus-token-7vdmz (ro)
    ---

    kubectl cp default/example:/var/run/secrets/kubernetes.io/serviceaccount ./

    # 可能会报警告,无法成功,通过警告提示的命令执行即可
    kubectl exec -n "default" "example" -- tar cf - "/var/run/secrets/kubernetes.io/serviceaccount" | tar xf -
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值