基于RBAC实现dashboard只读——view权限

基于RBAC实现dashboard只读——view权限

只是简单利用默认的clusterrole - view实现了只读所有namespace下的对象(除去secret、role、rolebinding),不支持读取集群信息,后期深入了解resource后再重新梳理role和rule

kind: ServiceAccount
apiVersion: v1
metadata: 
    name: view 
    namespace: kube-system 

---

kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1beta1
metadata:
    name: dashboard-dev-rolebinding
subjects:
  - kind: ServiceAccount 
    name: view
    namespace: kube-system
roleRef:
    kind: ClusterRole
    name: view 
    apiGroup: rbac.authorization.k8s.io 

使用默认的clusterrole:view(Allows read-only access to see most objects in a namespace. It does not allow viewing roles or rolebindings. It does not allow viewing secrets, since those are escalating. )

https://kubernetes.io/docs/reference/access-authn-authz/rbac/

拿token

 kubectl describe secret -n kube-system `kubectl describe sa view  -n kube-system |  grep "Mountable secrets" | awk '{print $3}'`  | grep -E ^token | awk '{print $2}' 

登录dashboard即可

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值