Created
July 1, 2019 19:37
-
-
Save rkamudhan/6438a4d4fe63165ec4ca39b7a435c5ca to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Create the `system:kube-apiserver-to-kubelet` [ClusterRole](https://kubernetes.io/docs/admin/authorization/rbac/#role-and-clusterrole) with permissions to access the Kubelet API and perform most common tasks associated with managing pods: | |
| ``` | |
| cat <<EOF | kubectl apply --kubeconfig admin.kubeconfig -f - | |
| apiVersion: rbac.authorization.k8s.io/v1beta1 | |
| kind: ClusterRole | |
| metadata: | |
| annotations: | |
| rbac.authorization.kubernetes.io/autoupdate: "true" | |
| labels: | |
| kubernetes.io/bootstrapping: rbac-defaults | |
| name: system:kube-apiserver-to-kubelet | |
| rules: | |
| - apiGroups: | |
| - "" | |
| resources: | |
| - nodes/proxy | |
| - nodes/stats | |
| - nodes/log | |
| - nodes/spec | |
| - nodes/metrics | |
| verbs: | |
| - "*" | |
| EOF | |
| ``` | |
| The Kubernetes API Server authenticates to the Kubelet as the `kubernetes` user using the client certificate as defined by the `--kubelet-client-certificate` flag. | |
| Bind the `system:kube-apiserver-to-kubelet` ClusterRole to the `kubernetes` user: | |
| ``` | |
| cat <<EOF | kubectl apply --kubeconfig admin.kubeconfig -f - | |
| apiVersion: rbac.authorization.k8s.io/v1beta1 | |
| kind: ClusterRoleBinding | |
| metadata: | |
| name: system:kube-apiserver | |
| namespace: "" | |
| roleRef: | |
| apiGroup: rbac.authorization.k8s.io | |
| kind: ClusterRole | |
| name: system:kube-apiserver-to-kubelet | |
| subjects: | |
| - apiGroup: rbac.authorization.k8s.io | |
| kind: User | |
| name: kube-apiserver | |
| EOF | |
| ``` |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment