RBAC Error in Kubernetes

2019-03-01 00:29发布

问题:

I have deployed kubernetes v1.8 in my workplace. I have created roles for admin and view access to namespaces 3months ago. In the initial phase RBAC is working as per the access given to the users. Now RBAC is not happening every who has access to the cluster is having clusteradmin access.

Can you suggest the errors/changes that had to be done?

回答1:

Ensure the RBAC authorization mode is still being used (--authorization-mode=…,RBAC is part of the apiserver arguments)

If it is, then check for a clusterrolebinding that is granting the cluster-admin role to all authenticated users:

kubectl get clusterrolebindings -o yaml | grep -C 20 system:authenticated