kubernetes-handbook/guide/kubectl-user-authentication...

1657 lines
73 KiB
HTML
Raw Blame History

This file contains ambiguous Unicode characters!

This file contains ambiguous Unicode characters that may be confused with others in your current locale. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to highlight these characters.

<!DOCTYPE HTML>
<html lang="zh-cn" >
<head>
<meta charset="UTF-8">
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
<title>3.3.4 kubectl的用户认证授权 · Kubernetes Handbook</title>
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta name="description" content="">
<meta name="generator" content="GitBook 3.2.2">
<meta name="author" content="Jimmy Song">
<link rel="stylesheet" href="../gitbook/style.css">
<link rel="stylesheet" href="../gitbook/gitbook-plugin-splitter/splitter.css">
<link rel="stylesheet" href="../gitbook/gitbook-plugin-page-toc-button/plugin.css">
<link rel="stylesheet" href="../gitbook/gitbook-plugin-image-captions/image-captions.css">
<link rel="stylesheet" href="../gitbook/gitbook-plugin-page-footer-ex/style/plugin.css">
<link rel="stylesheet" href="../gitbook/gitbook-plugin-search-plus/search.css">
<link rel="stylesheet" href="../gitbook/gitbook-plugin-highlight/website.css">
<link rel="stylesheet" href="../gitbook/gitbook-plugin-fontsettings/website.css">
<meta name="HandheldFriendly" content="true"/>
<meta name="viewport" content="width=device-width, initial-scale=1, user-scalable=no">
<meta name="apple-mobile-web-app-capable" content="yes">
<meta name="apple-mobile-web-app-status-bar-style" content="black">
<link rel="apple-touch-icon-precomposed" sizes="152x152" href="../gitbook/images/apple-touch-icon-precomposed-152.png">
<link rel="shortcut icon" href="../gitbook/images/favicon.ico" type="image/x-icon">
<link rel="next" href="rbac.html" />
<link rel="prev" href="tls-bootstrapping.html" />
</head>
<body>
<div class="book">
<div class="book-summary">
<div id="book-search-input" role="search">
<input type="text" placeholder="輸入並搜尋" />
</div>
<nav role="navigation">
<ul class="summary">
<li class="chapter " data-level="1.1" data-path="../">
<a href="../">
1. 前言
</a>
</li>
<li class="chapter " data-level="1.2" data-path="../concepts/">
<a href="../concepts/">
2. 概念原理
</a>
<ul class="articles">
<li class="chapter " data-level="1.2.1" data-path="../concepts/concepts.html">
<a href="../concepts/concepts.html">
2.1 设计理念
</a>
</li>
<li class="chapter " data-level="1.2.2" data-path="../concepts/objects.html">
<a href="../concepts/objects.html">
2.2 主要概念
</a>
<ul class="articles">
<li class="chapter " data-level="1.2.2.1" data-path="../concepts/pod-overview.html">
<a href="../concepts/pod-overview.html">
2.2.1 Pod
</a>
<ul class="articles">
<li class="chapter " data-level="1.2.2.1.1" data-path="../concepts/pod.html">
<a href="../concepts/pod.html">
2.2.1.1 Pod解析
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.2.2.2" data-path="../concepts/node.html">
<a href="../concepts/node.html">
2.2.2 Node
</a>
</li>
<li class="chapter " data-level="1.2.2.3" data-path="../concepts/namespace.html">
<a href="../concepts/namespace.html">
2.2.3 Namespace
</a>
</li>
<li class="chapter " data-level="1.2.2.4" data-path="../concepts/service.html">
<a href="../concepts/service.html">
2.2.4 Service
</a>
</li>
<li class="chapter " data-level="1.2.2.5" data-path="../concepts/volume.html">
<a href="../concepts/volume.html">
2.2.5 Volume和Persistent Volume
</a>
</li>
<li class="chapter " data-level="1.2.2.6" data-path="../concepts/deployment.html">
<a href="../concepts/deployment.html">
2.2.6 Deployment
</a>
</li>
<li class="chapter " data-level="1.2.2.7" data-path="../concepts/secret.html">
<a href="../concepts/secret.html">
2.2.7 Secret
</a>
</li>
<li class="chapter " data-level="1.2.2.8" data-path="../concepts/statefulset.html">
<a href="../concepts/statefulset.html">
2.2.8 StatefulSet
</a>
</li>
<li class="chapter " data-level="1.2.2.9" data-path="../concepts/daemonset.html">
<a href="../concepts/daemonset.html">
2.2.9 DaemonSet
</a>
</li>
<li class="chapter " data-level="1.2.2.10" data-path="../concepts/serviceaccount.html">
<a href="../concepts/serviceaccount.html">
2.2.10 ServiceAccount
</a>
</li>
<li class="chapter " data-level="1.2.2.11" data-path="../concepts/replicaset.html">
<a href="../concepts/replicaset.html">
2.2.11 ReplicationController和ReplicaSet
</a>
</li>
<li class="chapter " data-level="1.2.2.12" data-path="../concepts/job.html">
<a href="../concepts/job.html">
2.2.12 Job
</a>
</li>
<li class="chapter " data-level="1.2.2.13" data-path="../concepts/cronjob.html">
<a href="../concepts/cronjob.html">
2.2.13 CronJob
</a>
</li>
<li class="chapter " data-level="1.2.2.14" data-path="../concepts/ingress.html">
<a href="../concepts/ingress.html">
2.2.14 Ingress
</a>
</li>
<li class="chapter " data-level="1.2.2.15" data-path="../concepts/configmap.html">
<a href="../concepts/configmap.html">
2.2.15 ConfigMap
</a>
</li>
<li class="chapter " data-level="1.2.2.16" data-path="../concepts/horizontal-pod-autoscaling.html">
<a href="../concepts/horizontal-pod-autoscaling.html">
2.2.16 Horizontal Pod Autoscaling
</a>
</li>
<li class="chapter " data-level="1.2.2.17" data-path="../concepts/label.html">
<a href="../concepts/label.html">
2.2.17 Label
</a>
</li>
</ul>
</li>
</ul>
</li>
<li class="chapter " data-level="1.3" data-path="./">
<a href="./">
3. 用户指南
</a>
<ul class="articles">
<li class="chapter " data-level="1.3.1" data-path="resource-configuration.html">
<a href="resource-configuration.html">
3.1 资源配置
</a>
<ul class="articles">
<li class="chapter " data-level="1.3.1.1" data-path="configure-liveness-readiness-probes.html">
<a href="configure-liveness-readiness-probes.html">
3.1.1 配置Pod的liveness和readiness探针
</a>
</li>
<li class="chapter " data-level="1.3.1.2" data-path="configure-pod-service-account.html">
<a href="configure-pod-service-account.html">
3.1.2 配置Pod的Service Account
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.3.2" data-path="command-usage.html">
<a href="command-usage.html">
3.2 命令使用
</a>
<ul class="articles">
<li class="chapter " data-level="1.3.2.1" data-path="using-kubectl.html">
<a href="using-kubectl.html">
3.2.1 使用kubectl
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.3.3" data-path="cluster-management.html">
<a href="cluster-management.html">
3.3 集群管理
</a>
<ul class="articles">
<li class="chapter " data-level="1.3.3.1" data-path="managing-tls-in-a-cluster.html">
<a href="managing-tls-in-a-cluster.html">
3.3.1 管理集群中的TLS
</a>
</li>
<li class="chapter " data-level="1.3.3.2" data-path="kubelet-authentication-authorization.html">
<a href="kubelet-authentication-authorization.html">
3.3.2 kubelet的认证授权
</a>
</li>
<li class="chapter " data-level="1.3.3.3" data-path="tls-bootstrapping.html">
<a href="tls-bootstrapping.html">
3.3.3 TLS bootstrap
</a>
</li>
<li class="chapter active" data-level="1.3.3.4" data-path="kubectl-user-authentication-authorization.html">
<a href="kubectl-user-authentication-authorization.html">
3.3.4 kubectl的用户认证授权
</a>
</li>
<li class="chapter " data-level="1.3.3.5" data-path="rbac.html">
<a href="rbac.html">
3.3.5 RBAC——基于角色的访问控制
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.3.4" data-path="access-kubernetes-cluster.html">
<a href="access-kubernetes-cluster.html">
3.4 访问 Kubernetes 集群
</a>
<ul class="articles">
<li class="chapter " data-level="1.3.4.1" data-path="access-cluster.html">
<a href="access-cluster.html">
3.4.1 访问集群
</a>
</li>
<li class="chapter " data-level="1.3.4.2" data-path="authenticate-across-clusters-kubeconfig.html">
<a href="authenticate-across-clusters-kubeconfig.html">
3.4.2 使用 kubeconfig 文件配置跨集群认证
</a>
</li>
<li class="chapter " data-level="1.3.4.3" data-path="connecting-to-applications-port-forward.html">
<a href="connecting-to-applications-port-forward.html">
3.4.3 通过端口转发访问集群中的应用程序
</a>
</li>
<li class="chapter " data-level="1.3.4.4" data-path="service-access-application-cluster.html">
<a href="service-access-application-cluster.html">
3.4.4 使用 service 访问群集中的应用程序
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.3.5" data-path="application-development-deployment-flow.html">
<a href="application-development-deployment-flow.html">
3.5 在kubernetes中开发部署应用
</a>
<ul class="articles">
<li class="chapter " data-level="1.3.5.1" data-path="deploy-applications-in-kubernetes.html">
<a href="deploy-applications-in-kubernetes.html">
3.5.1 适用于kubernetes的应用开发部署流程
</a>
</li>
<li class="chapter " data-level="1.3.5.2" data-path="migrating-hadoop-yarn-to-kubernetes.html">
<a href="migrating-hadoop-yarn-to-kubernetes.html">
3.5.2 迁移传统应用到kubernetes中——以Hadoop YARN为例
</a>
</li>
</ul>
</li>
</ul>
</li>
<li class="chapter " data-level="1.4" data-path="../practice/">
<a href="../practice/">
4. 最佳实践
</a>
<ul class="articles">
<li class="chapter " data-level="1.4.1" data-path="../practice/install-kbernetes1.6-on-centos.html">
<a href="../practice/install-kbernetes1.6-on-centos.html">
4.1 在CentOS上部署kubernetes1.6集群
</a>
<ul class="articles">
<li class="chapter " data-level="1.4.1.1" data-path="../practice/create-tls-and-secret-key.html">
<a href="../practice/create-tls-and-secret-key.html">
4.1.1 创建TLS证书和秘钥
</a>
</li>
<li class="chapter " data-level="1.4.1.2" data-path="../practice/create-kubeconfig.html">
<a href="../practice/create-kubeconfig.html">
4.1.2 创建kubeconfig文件
</a>
</li>
<li class="chapter " data-level="1.4.1.3" data-path="../practice/etcd-cluster-installation.html">
<a href="../practice/etcd-cluster-installation.html">
4.1.3 创建高可用etcd集群
</a>
</li>
<li class="chapter " data-level="1.4.1.4" data-path="../practice/kubectl-installation.html">
<a href="../practice/kubectl-installation.html">
4.1.4 安装kubectl命令行工具
</a>
</li>
<li class="chapter " data-level="1.4.1.5" data-path="../practice/master-installation.html">
<a href="../practice/master-installation.html">
4.1.5 部署master节点
</a>
</li>
<li class="chapter " data-level="1.4.1.6" data-path="../practice/node-installation.html">
<a href="../practice/node-installation.html">
4.1.6 部署node节点
</a>
</li>
<li class="chapter " data-level="1.4.1.7" data-path="../practice/kubedns-addon-installation.html">
<a href="../practice/kubedns-addon-installation.html">
4.1.7 安装kubedns插件
</a>
</li>
<li class="chapter " data-level="1.4.1.8" data-path="../practice/dashboard-addon-installation.html">
<a href="../practice/dashboard-addon-installation.html">
4.1.8 安装dashboard插件
</a>
</li>
<li class="chapter " data-level="1.4.1.9" data-path="../practice/heapster-addon-installation.html">
<a href="../practice/heapster-addon-installation.html">
4.1.9 安装heapster插件
</a>
</li>
<li class="chapter " data-level="1.4.1.10" data-path="../practice/efk-addon-installation.html">
<a href="../practice/efk-addon-installation.html">
4.1.10 安装EFK插件
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.4.2" data-path="../practice/service-discovery-and-loadbalancing.html">
<a href="../practice/service-discovery-and-loadbalancing.html">
4.2 服务发现与负载均衡
</a>
<ul class="articles">
<li class="chapter " data-level="1.4.2.1" data-path="../practice/traefik-ingress-installation.html">
<a href="../practice/traefik-ingress-installation.html">
4.2.1 安装Traefik ingress
</a>
</li>
<li class="chapter " data-level="1.4.2.2" data-path="../practice/distributed-load-test.html">
<a href="../practice/distributed-load-test.html">
4.2.2 分布式负载测试
</a>
</li>
<li class="chapter " data-level="1.4.2.3" data-path="../practice/network-and-cluster-perfermance-test.html">
<a href="../practice/network-and-cluster-perfermance-test.html">
4.2.3 网络和集群性能测试
</a>
</li>
<li class="chapter " data-level="1.4.2.4" data-path="../practice/edge-node-configuration.html">
<a href="../practice/edge-node-configuration.html">
4.2.4 边缘节点配置
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.4.3" data-path="../practice/operation.html">
<a href="../practice/operation.html">
4.3 运维管理
</a>
<ul class="articles">
<li class="chapter " data-level="1.4.3.1" data-path="../practice/service-rolling-update.html">
<a href="../practice/service-rolling-update.html">
4.3.1 服务滚动升级
</a>
</li>
<li class="chapter " data-level="1.4.3.2" data-path="../practice/app-log-collection.html">
<a href="../practice/app-log-collection.html">
4.3.2 应用日志收集
</a>
</li>
<li class="chapter " data-level="1.4.3.3" data-path="../practice/configuration-best-practice.html">
<a href="../practice/configuration-best-practice.html">
4.3.3 配置最佳实践
</a>
</li>
<li class="chapter " data-level="1.4.3.4" data-path="../practice/monitor.html">
<a href="../practice/monitor.html">
4.3.4 集群及应用监控
</a>
</li>
<li class="chapter " data-level="1.4.3.5" data-path="../practice/jenkins-ci-cd.html">
<a href="../practice/jenkins-ci-cd.html">
4.3.5 使用Jenkins进行持续构建与发布
</a>
</li>
<li class="chapter " data-level="1.4.3.6" data-path="../practice/data-persistence-problem.html">
<a href="../practice/data-persistence-problem.html">
4.3.6 数据持久化问题
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.4.4" data-path="../practice/storage.html">
<a href="../practice/storage.html">
4.4 存储管理
</a>
<ul class="articles">
<li class="chapter " data-level="1.4.4.1" data-path="../practice/glusterfs.html">
<a href="../practice/glusterfs.html">
4.4.1 GlusterFS
</a>
<ul class="articles">
<li class="chapter " data-level="1.4.4.1.1" data-path="../practice/using-glusterfs-for-persistent-storage.html">
<a href="../practice/using-glusterfs-for-persistent-storage.html">
4.4.1.1 使用GlusterFS做持久化存储
</a>
</li>
<li class="chapter " data-level="1.4.4.1.2" data-path="../practice/storage-for-containers-using-glusterfs-with-openshift.html">
<a href="../practice/storage-for-containers-using-glusterfs-with-openshift.html">
4.4.1.2 在OpenShift中使用GlusterFS做持久化存储
</a>
</li>
</ul>
</li>
</ul>
</li>
</ul>
</li>
<li class="chapter " data-level="1.5" data-path="../usecases/">
<a href="../usecases/">
5. 领域应用
</a>
<ul class="articles">
<li class="chapter " data-level="1.5.1" data-path="../usecases/microservices.html">
<a href="../usecases/microservices.html">
5.1 微服务架构
</a>
<ul class="articles">
<li class="chapter " data-level="1.5.1.1" data-path="../usecases/istio.html">
<a href="../usecases/istio.html">
5.1.1 Istio
</a>
<ul class="articles">
<li class="chapter " data-level="1.5.1.1.1" data-path="../usecases/istio-installation.html">
<a href="../usecases/istio-installation.html">
5.1.1.1 安装istio
</a>
</li>
<li class="chapter " data-level="1.5.1.1.2" data-path="../usecases/configuring-request-routing.html">
<a href="../usecases/configuring-request-routing.html">
5.1.1.2 配置请求的路由规则
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.5.1.2" data-path="../usecases/linkerd.html">
<a href="../usecases/linkerd.html">
5.1.2 Linkerd
</a>
<ul class="articles">
<li class="chapter " data-level="1.5.1.2.1" data-path="../usecases/linkerd-user-guide.html">
<a href="../usecases/linkerd-user-guide.html">
5.1.2.1 Linkerd 使用指南
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.5.1.3" data-path="../usecases/service-discovery-in-microservices.html">
<a href="../usecases/service-discovery-in-microservices.html">
5.1.3 微服务中的服务发现
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.5.2" data-path="../usecases/big-data.html">
<a href="../usecases/big-data.html">
5.2 大数据
</a>
<ul class="articles">
<li class="chapter " data-level="1.5.2.1" data-path="../usecases/spark-standalone-on-kubernetes.html">
<a href="../usecases/spark-standalone-on-kubernetes.html">
5.2.1 Spark standalone on Kubernetes
</a>
</li>
<li class="chapter " data-level="1.5.2.2" data-path="../usecases/support-spark-natively-in-kubernetes.html">
<a href="../usecases/support-spark-natively-in-kubernetes.html">
5.2.2 运行支持kubernetes原生调度的Spark程序
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.5.3" data-path="../usecases/serverless.html">
<a href="../usecases/serverless.html">
5.3 Serverless架构
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.6" data-path="../develop/">
<a href="../develop/">
6. 开发指南
</a>
<ul class="articles">
<li class="chapter " data-level="1.6.1" data-path="../develop/developing-environment.html">
<a href="../develop/developing-environment.html">
6.1 开发环境搭建
</a>
</li>
<li class="chapter " data-level="1.6.2" data-path="../develop/testing.html">
<a href="../develop/testing.html">
6.2 单元测试和集成测试
</a>
</li>
<li class="chapter " data-level="1.6.3" data-path="../develop/client-go-sample.html">
<a href="../develop/client-go-sample.html">
6.3 client-go示例
</a>
</li>
<li class="chapter " data-level="1.6.4" data-path="../develop/contribute.html">
<a href="../develop/contribute.html">
6.4 社区贡献
</a>
</li>
</ul>
</li>
<li class="chapter " data-level="1.7" data-path="../appendix/">
<a href="../appendix/">
7. 附录
</a>
<ul class="articles">
<li class="chapter " data-level="1.7.1" data-path="../appendix/docker-best-practice.html">
<a href="../appendix/docker-best-practice.html">
7.1 Docker最佳实践
</a>
</li>
<li class="chapter " data-level="1.7.2" data-path="../appendix/issues.html">
<a href="../appendix/issues.html">
7.2 问题记录
</a>
</li>
<li class="chapter " data-level="1.7.3" data-path="../appendix/tricks.html">
<a href="../appendix/tricks.html">
7.3 使用技巧
</a>
</li>
</ul>
</li>
<li class="divider"></li>
<li>
<a href="https://www.gitbook.com" target="blank" class="gitbook-link">
本書使用 GitBook 釋出
</a>
</li>
</ul>
</nav>
</div>
<div class="book-body">
<div class="body-inner">
<div class="book-header" role="navigation">
<!-- Title -->
<h1>
<i class="fa fa-circle-o-notch fa-spin"></i>
<a href=".." >3.3.4 kubectl的用户认证授权</a>
</h1>
</div>
<div class="page-wrapper" tabindex="-1" role="main">
<div class="page-inner">
<div class="search-plus" id="book-search-results">
<div class="search-noresults">
<section class="normal markdown-section">
<h1 id="kubectl-&#x7684;&#x7528;&#x6237;&#x8BA4;&#x8BC1;&#x6388;&#x6743;">kubectl &#x7684;&#x7528;&#x6237;&#x8BA4;&#x8BC1;&#x6388;&#x6743;</h1>
<p>&#x5F53;&#x6211;&#x4EEC;&#x5B89;&#x88C5;&#x597D;&#x96C6;&#x7FA4;&#x540E;&#xFF0C;&#x5982;&#x679C;&#x60F3;&#x8981;&#x628A; kubectl &#x547D;&#x4EE4;&#x4EA4;&#x7ED9;&#x7528;&#x6237;&#x4F7F;&#x7528;&#xFF0C;&#x5C31;&#x4E0D;&#x5F97;&#x4E0D;&#x5BF9;&#x7528;&#x6237;&#x7684;&#x8EAB;&#x4EFD;&#x8FDB;&#x884C;&#x8BA4;&#x8BC1;&#x548C;&#x5BF9;&#x5176;&#x6743;&#x9650;&#x505A;&#x51FA;&#x9650;&#x5236;&#x3002;</p>
<p>&#x4E0B;&#x9762;&#x4EE5;&#x521B;&#x5EFA;&#x4E00;&#x4E2A; devuser &#x7528;&#x6237;&#x5E76;&#x5C06;&#x5176;&#x7ED1;&#x5B9A;&#x5230; dev &#x548C; test &#x4E24;&#x4E2A; namespace &#x4E3A;&#x4F8B;&#x8BF4;&#x660E;&#x3002;</p>
<h2 id="&#x521B;&#x5EFA;-ca-&#x8BC1;&#x4E66;&#x548C;&#x79D8;&#x94A5;">&#x521B;&#x5EFA; CA &#x8BC1;&#x4E66;&#x548C;&#x79D8;&#x94A5;</h2>
<p><strong>&#x521B;&#x5EFA; <code>devuser-csr.json</code> &#x6587;&#x4EF6;</strong></p>
<pre><code class="lang-json">{
<span class="hljs-string">&quot;CN&quot;</span>: <span class="hljs-string">&quot;devuser&quot;</span>,
<span class="hljs-string">&quot;hosts&quot;</span>: [],
<span class="hljs-string">&quot;key&quot;</span>: {
<span class="hljs-string">&quot;algo&quot;</span>: <span class="hljs-string">&quot;rsa&quot;</span>,
<span class="hljs-string">&quot;size&quot;</span>: <span class="hljs-number">2048</span>
},
<span class="hljs-string">&quot;names&quot;</span>: [
{
<span class="hljs-string">&quot;C&quot;</span>: <span class="hljs-string">&quot;CN&quot;</span>,
<span class="hljs-string">&quot;ST&quot;</span>: <span class="hljs-string">&quot;BeiJing&quot;</span>,
<span class="hljs-string">&quot;L&quot;</span>: <span class="hljs-string">&quot;BeiJing&quot;</span>,
<span class="hljs-string">&quot;O&quot;</span>: <span class="hljs-string">&quot;k8s&quot;</span>,
<span class="hljs-string">&quot;OU&quot;</span>: <span class="hljs-string">&quot;System&quot;</span>
}
]
}
</code></pre>
<p><strong>&#x751F;&#x6210; CA &#x8BC1;&#x4E66;&#x548C;&#x79C1;&#x94A5;</strong></p>
<p>&#x5728; <a href="../practice/create-tls-and-secret-key.html">&#x521B;&#x5EFA; TLS &#x8BC1;&#x4E66;&#x548C;&#x79D8;&#x94A5;</a> &#x4E00;&#x8282;&#x4E2D;&#x6211;&#x4EEC;&#x5C06;&#x751F;&#x6210;&#x7684;&#x8BC1;&#x4E66;&#x548C;&#x79D8;&#x94A5;&#x653E;&#x5728;&#x4E86;&#x6240;&#x6709;&#x8282;&#x70B9;&#x7684; <code>/etc/kubernetes/ssl</code> &#x76EE;&#x5F55;&#x4E0B;&#xFF0C;&#x4E0B;&#x9762;&#x6211;&#x4EEC;&#x518D;&#x5728; master &#x8282;&#x70B9;&#x4E0A;&#x4E3A; devuser &#x521B;&#x5EFA;&#x8BC1;&#x4E66;&#x548C;&#x79D8;&#x94A5;&#xFF0C;&#x5728; <code>/etc/kubernetes/ssl</code> &#x76EE;&#x5F55;&#x4E0B;&#x6267;&#x884C;&#x4EE5;&#x4E0B;&#x547D;&#x4EE4;&#xFF1A;</p>
<p>&#x6267;&#x884C;&#x8BE5;&#x547D;&#x4EE4;&#x524D;&#x8BF7;&#x5148;&#x786E;&#x4FDD;&#x8BE5;&#x76EE;&#x5F55;&#x4E0B;&#x5DF2;&#x7ECF;&#x5305;&#x542B;&#x5982;&#x4E0B;&#x6587;&#x4EF6;&#xFF1A;</p>
<pre><code>ca-key.pem ca.pem ca-config.json devuser-csr.json
</code></pre><pre><code class="lang-bash">$ cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=kubernetes devuser-csr.json | cfssljson -bare devuser
2017/08/31 13:31:54 [INFO] generate received request
2017/08/31 13:31:54 [INFO] received CSR
2017/08/31 13:31:54 [INFO] generating key: rsa-2048
2017/08/31 13:31:55 [INFO] encoded CSR
2017/08/31 13:31:55 [INFO] signed certificate with serial number 43372632012323103879829229080989286813242051309
2017/08/31 13:31:55 [WARNING] This certificate lacks a <span class="hljs-string">&quot;hosts&quot;</span> field. This makes it unsuitable <span class="hljs-keyword">for</span>
websites. For more information see the Baseline Requirements <span class="hljs-keyword">for</span> the Issuance and Management
of Publicly-Trusted Certificates, v.1.1.6, from the CA/Browser Forum (https://cabforum.org);
specifically, section 10.2.3 (<span class="hljs-string">&quot;Information Requirements&quot;</span>).
</code></pre>
<p>&#x8FD9;&#x5C06;&#x751F;&#x6210;&#x5982;&#x4E0B;&#x6587;&#x4EF6;&#xFF1A;</p>
<pre><code>devuser.csr devuser-key.pem devuser.pem
</code></pre><h2 id="&#x521B;&#x5EFA;-kubeconfig-&#x6587;&#x4EF6;">&#x521B;&#x5EFA; kubeconfig &#x6587;&#x4EF6;</h2>
<pre><code class="lang-bash"><span class="hljs-comment"># &#x8BBE;&#x7F6E;&#x96C6;&#x7FA4;&#x53C2;&#x6570;</span>
<span class="hljs-built_in">export</span> KUBE_APISERVER=<span class="hljs-string">&quot;https://172.20.0.113:6443&quot;</span>
kubectl config <span class="hljs-built_in">set</span>-cluster kubernetes \
--certificate-authority=/etc/kubernetes/ssl/ca.pem \
--embed-certs=<span class="hljs-literal">true</span> \
--server=<span class="hljs-variable">${KUBE_APISERVER}</span> \
--kubeconfig=devuser.kubeconfig
<span class="hljs-comment"># &#x8BBE;&#x7F6E;&#x5BA2;&#x6237;&#x7AEF;&#x8BA4;&#x8BC1;&#x53C2;&#x6570;</span>
kubectl config <span class="hljs-built_in">set</span>-credentials devuser \
--client-certificate=/etc/kubernetes/ssl/devuser.pem \
--client-key=/etc/kubernetes/ssl/devuser-key.pem \
--embed-certs=<span class="hljs-literal">true</span> \
--kubeconfig=devuser.kubeconfig
<span class="hljs-comment"># &#x8BBE;&#x7F6E;&#x4E0A;&#x4E0B;&#x6587;&#x53C2;&#x6570;</span>
kubectl config <span class="hljs-built_in">set</span>-context kubernetes \
--cluster=kubernetes \
--user=devuser \
--namespace=dev \
--kubeconfig=devuser.kubeconfig
<span class="hljs-comment"># &#x8BBE;&#x7F6E;&#x9ED8;&#x8BA4;&#x4E0A;&#x4E0B;&#x6587;</span>
kubectl config use-context kubernetes --kubeconfig=devuser.kubeconfig
</code></pre>
<p>&#x6211;&#x4EEC;&#x73B0;&#x5728;&#x67E5;&#x770B; kubectl &#x7684; context&#xFF1A;</p>
<pre><code class="lang-bash">kubectl config get-contexts
CURRENT NAME CLUSTER AUTHINFO NAMESPACE
* kubernetes kubernetes admin
default-context default-cluster default-admin
</code></pre>
<p>&#x663E;&#x793A;&#x7684;&#x7528;&#x6237;&#x4ECD;&#x7136;&#x662F; admin&#xFF0C;&#x8FD9;&#x662F;&#x56E0;&#x4E3A; kubectl &#x4F7F;&#x7528;&#x4E86; <code>$HOME/.kube/config</code> &#x6587;&#x4EF6;&#x4F5C;&#x4E3A;&#x4E86;&#x9ED8;&#x8BA4;&#x7684; context &#x914D;&#x7F6E;&#xFF0C;&#x6211;&#x4EEC;&#x53EA;&#x9700;&#x8981;&#x5C06;&#x5176;&#x7528;&#x521A;&#x751F;&#x6210;&#x7684; <code>devuser.kubeconfig</code> &#x6587;&#x4EF6;&#x66FF;&#x6362;&#x5373;&#x53EF;&#x3002;</p>
<pre><code class="lang-bash">cp <span class="hljs-_">-f</span> ./devuser.kubeconfig /root/.kube/config
</code></pre>
<p>&#x5173;&#x4E8E; kubeconfig &#x6587;&#x4EF6;&#x7684;&#x66F4;&#x591A;&#x4FE1;&#x606F;&#x8BF7;&#x53C2;&#x8003; <a href="authenticate-across-clusters-kubeconfig.html">&#x4F7F;&#x7528; kubeconfig &#x6587;&#x4EF6;&#x914D;&#x7F6E;&#x8DE8;&#x96C6;&#x7FA4;&#x8BA4;&#x8BC1;</a>&#x3002;</p>
<h2 id="clusterrolebinding">ClusterRoleBinding</h2>
<p>&#x5982;&#x679C;&#x6211;&#x4EEC;&#x60F3;&#x9650;&#x5236; devuser &#x7528;&#x6237;&#x7684;&#x884C;&#x4E3A;&#xFF0C;&#x9700;&#x8981;&#x4F7F;&#x7528; RBAC &#x5C06;&#x8BE5;&#x7528;&#x6237;&#x7684;&#x884C;&#x4E3A;&#x9650;&#x5236;&#x5728;&#x67D0;&#x4E2A;&#x6216;&#x67D0;&#x51E0;&#x4E2A; namespace &#x7A7A;&#x95F4;&#x8303;&#x56F4;&#x5185;&#xFF0C;&#x4F8B;&#x5982;&#xFF1A;</p>
<pre><code class="lang-bash">kubectl create rolebinding devuser-admin-binding --clusterrole=admin --user=devuser --namespace=dev
kubectl create rolebinding devuser-admin-binding --clusterrole=admin --user=devuser --namespace=<span class="hljs-built_in">test</span>
</code></pre>
<p>&#x8FD9;&#x6837; devuser &#x7528;&#x6237;&#x5BF9; dev &#x548C; test &#x4E24;&#x4E2A; namespace &#x5177;&#x6709;&#x5B8C;&#x5168;&#x8BBF;&#x95EE;&#x6743;&#x9650;&#x3002;</p>
<p>&#x8BA9;&#x6211;&#x4EEC;&#x6765;&#x9A8C;&#x8BC1;&#x4EE5;&#x4E0B;&#xFF0C;&#x73B0;&#x5728;&#x6211;&#x4EEC;&#x5728;&#x6267;&#x884C;&#xFF1A;</p>
<pre><code class="lang-bash"><span class="hljs-comment"># &#x83B7;&#x53D6;&#x5F53;&#x524D;&#x7684; context</span>
kubectl config get-contexts
CURRENT NAME CLUSTER AUTHINFO NAMESPACE
* kubernetes kubernetes devuser dev
* kubernetes kubernetes devuser <span class="hljs-built_in">test</span>
<span class="hljs-comment"># &#x65E0;&#x6CD5;&#x8BBF;&#x95EE; default namespace</span>
kubectl get pods --namespace default
Error from server (Forbidden): User <span class="hljs-string">&quot;devuser&quot;</span> cannot list pods <span class="hljs-keyword">in</span> the namespace <span class="hljs-string">&quot;default&quot;</span>. (get pods)
<span class="hljs-comment"># &#x9ED8;&#x8BA4;&#x8BBF;&#x95EE;&#x7684;&#x662F; dev namespace&#xFF0C;&#x60A8;&#x4E5F;&#x53EF;&#x4EE5;&#x91CD;&#x65B0;&#x8BBE;&#x7F6E; context &#x8BA9;&#x5176;&#x9ED8;&#x8BA4;&#x8BBF;&#x95EE; test namespace</span>
kubectl get pods
No resources found.
</code></pre>
<p>&#x73B0;&#x5728; kubectl &#x547D;&#x4EE4;&#x9ED8;&#x8BA4;&#x4F7F;&#x7528;&#x7684; context &#x5C31;&#x662F; devuser &#x4E86;&#xFF0C;&#x4E14;&#x8BE5;&#x7528;&#x6237;&#x53EA;&#x80FD;&#x64CD;&#x4F5C; dev &#x548C; test &#x8FD9;&#x4E24;&#x4E2A; namespace&#xFF0C;&#x5E76;&#x62E5;&#x6709;&#x5B8C;&#x5168;&#x7684;&#x8BBF;&#x95EE;&#x6743;&#x9650;&#x3002;</p>
<p>&#x5173;&#x4E8E;&#x89D2;&#x8272;&#x7ED1;&#x5B9A;&#x7684;&#x66F4;&#x591A;&#x4FE1;&#x606F;&#x8BF7;&#x53C2;&#x8003; <a href="rbac.html">RBAC&#x2014;&#x2014;&#x57FA;&#x4E8E;&#x89D2;&#x8272;&#x7684;&#x8BBF;&#x95EE;&#x63A7;&#x5236;</a>&#x3002; </p>
<footer class="page-footer-ex"> <span class="page-footer-ex-copyright">for GitBook</span>&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;<span class="page-footer-ex-footer-update">update
2017-08-31 14:17:46
</span></footer>
</section>
</div>
<div class="search-results">
<div class="has-results">
<h1 class="search-results-title"><span class='search-results-count'></span> results matching "<span class='search-query'></span>"</h1>
<ul class="search-results-list"></ul>
</div>
<div class="no-results">
<h1 class="search-results-title">No results matching "<span class='search-query'></span>"</h1>
</div>
</div>
</div>
</div>
</div>
</div>
<a href="tls-bootstrapping.html" class="navigation navigation-prev " aria-label="Previous page: 3.3.3 TLS bootstrap">
<i class="fa fa-angle-left"></i>
</a>
<a href="rbac.html" class="navigation navigation-next " aria-label="Next page: 3.3.5 RBAC——基于角色的访问控制">
<i class="fa fa-angle-right"></i>
</a>
</div>
<script>
var gitbook = gitbook || [];
gitbook.push(function() {
gitbook.page.hasChanged({"page":{"title":"3.3.4 kubectl的用户认证授权","level":"1.3.3.4","depth":3,"next":{"title":"3.3.5 RBAC——基于角色的访问控制","level":"1.3.3.5","depth":3,"path":"guide/rbac.md","ref":"guide/rbac.md","articles":[]},"previous":{"title":"3.3.3 TLS bootstrap","level":"1.3.3.3","depth":3,"path":"guide/tls-bootstrapping.md","ref":"guide/tls-bootstrapping.md","articles":[]},"dir":"ltr"},"config":{"plugins":["github","codesnippet","splitter","page-toc-button","image-captions","page-footer-ex","editlink","-lunr","-search","search-plus"],"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"pluginsConfig":{"github":{"url":"https://github.com/rootsongjc/kubernetes-handbook"},"editlink":{"label":"编辑本页","multilingual":false,"base":"https://github.com/rootsongjc/kubernetes-handbook/blob/master/"},"page-footer-ex":{"copyright":"for GitBook","update_format":"YYYY-MM-DD HH:mm:ss","update_label":"update"},"splitter":{},"codesnippet":{},"fontsettings":{"theme":"white","family":"sans","size":2},"highlight":{},"page-toc-button":{},"sharing":{"facebook":true,"twitter":true,"google":false,"weibo":false,"instapaper":false,"vk":false,"all":["facebook","google","twitter","weibo","instapaper"]},"theme-default":{"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"showLevel":false},"search-plus":{},"image-captions":{"variable_name":"_pictures"}},"page-footer-ex":{"copyright":"Jimmy Song","update_label":"最后更新:","update_format":"YYYY-MM-DD HH:mm:ss"},"theme":"default","author":"Jimmy Song","pdf":{"pageNumbers":true,"fontSize":12,"fontFamily":"Arial","paperSize":"a4","chapterMark":"pagebreak","pageBreaksBefore":"/","margin":{"right":62,"left":62,"top":56,"bottom":56}},"structure":{"langs":"LANGS.md","readme":"README.md","glossary":"GLOSSARY.md","summary":"SUMMARY.md"},"variables":{"_pictures":[{"backlink":"concepts/index.html#fig1.2.1","level":"1.2","list_caption":"Figure: Borg架构","alt":"Borg架构","nro":1,"url":"../images/borg.png","index":1,"caption_template":"Figure: _CAPTION_","label":"Borg架构","attributes":{},"skip":false,"key":"1.2.1"},{"backlink":"concepts/index.html#fig1.2.2","level":"1.2","list_caption":"Figure: Kubernetes架构","alt":"Kubernetes架构","nro":2,"url":"../images/architecture.png","index":2,"caption_template":"Figure: _CAPTION_","label":"Kubernetes架构","attributes":{},"skip":false,"key":"1.2.2"},{"backlink":"concepts/index.html#fig1.2.3","level":"1.2","list_caption":"Figure: kubernetes整体架构示意图","alt":"kubernetes整体架构示意图","nro":3,"url":"../images/kubernetes-whole-arch.png","index":3,"caption_template":"Figure: _CAPTION_","label":"kubernetes整体架构示意图","attributes":{},"skip":false,"key":"1.2.3"},{"backlink":"concepts/index.html#fig1.2.4","level":"1.2","list_caption":"Figure: Kubernetes master架构示意图","alt":"Kubernetes master架构示意图","nro":4,"url":"../images/kubernetes-master-arch.png","index":4,"caption_template":"Figure: _CAPTION_","label":"Kubernetes master架构示意图","attributes":{},"skip":false,"key":"1.2.4"},{"backlink":"concepts/index.html#fig1.2.5","level":"1.2","list_caption":"Figure: kubernetes node架构示意图","alt":"kubernetes node架构示意图","nro":5,"url":"../images/kubernetes-node-arch.png","index":5,"caption_template":"Figure: _CAPTION_","label":"kubernetes node架构示意图","attributes":{},"skip":false,"key":"1.2.5"},{"backlink":"concepts/index.html#fig1.2.6","level":"1.2","list_caption":"Figure: Kubernetes分层架构示意图","alt":"Kubernetes分层架构示意图","nro":6,"url":"../images/kubernetes-layers-arch.jpg","index":6,"caption_template":"Figure: _CAPTION_","label":"Kubernetes分层架构示意图","attributes":{},"skip":false,"key":"1.2.6"},{"backlink":"concepts/concepts.html#fig1.2.1.1","level":"1.2.1","list_caption":"Figure: 分层架构示意图","alt":"分层架构示意图","nro":7,"url":"../images/kubernetes-layers-arch.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"分层架构示意图","attributes":{},"skip":false,"key":"1.2.1.1"},{"backlink":"concepts/pod-overview.html#fig1.2.2.1.1","level":"1.2.2.1","list_caption":"Figure: pod diagram","alt":"pod diagram","nro":8,"url":"../images/pod-overview.png","index":1,"caption_template":"Figure: _CAPTION_","label":"pod diagram","attributes":{},"skip":false,"key":"1.2.2.1.1"},{"backlink":"concepts/pod.html#fig1.2.2.1.1.1","level":"1.2.2.1.1","list_caption":"Figure: Pod示意图","alt":"Pod示意图","nro":9,"url":"../images/pod-overview.png","index":1,"caption_template":"Figure: _CAPTION_","label":"Pod示意图","attributes":{},"skip":false,"key":"1.2.2.1.1.1"},{"backlink":"concepts/pod.html#fig1.2.2.1.1.2","level":"1.2.2.1.1","list_caption":"Figure: Pod Cheatsheet","alt":"Pod Cheatsheet","nro":10,"url":"../images/kubernetes-pod-cheatsheet.png","index":2,"caption_template":"Figure: _CAPTION_","label":"Pod Cheatsheet","attributes":{},"skip":false,"key":"1.2.2.1.1.2"},{"backlink":"concepts/service.html#fig1.2.2.4.1","level":"1.2.2.4","list_caption":"Figure: userspace代理模式下Service概览图","alt":"userspace代理模式下Service概览图","nro":11,"url":"https://d33wubrfki0l68.cloudfront.net/b8e1022c2dd815d8dd36b1bc4f0cc3ad870a924f/1dd12/images/docs/services-userspace-overview.svg","index":1,"caption_template":"Figure: _CAPTION_","label":"userspace代理模式下Service概览图","attributes":{},"skip":false,"key":"1.2.2.4.1"},{"backlink":"concepts/service.html#fig1.2.2.4.2","level":"1.2.2.4","list_caption":"Figure: iptables代理模式下Service概览图","alt":"iptables代理模式下Service概览图","nro":12,"url":"https://d33wubrfki0l68.cloudfront.net/837afa5715eb31fb9ca6516ec6863e810f437264/42951/images/docs/services-iptables-overview.svg","index":2,"caption_template":"Figure: _CAPTION_","label":"iptables代理模式下Service概览图","attributes":{},"skip":false,"key":"1.2.2.4.2"},{"backlink":"concepts/deployment.html#fig1.2.2.6.1","level":"1.2.2.6","list_caption":"Figure: kubernetes deployment cheatsheet","alt":"kubernetes deployment cheatsheet","nro":13,"url":"../images/deployment-cheatsheet.png","index":1,"caption_template":"Figure: _CAPTION_","label":"kubernetes deployment cheatsheet","attributes":{},"skip":false,"key":"1.2.2.6.1"},{"backlink":"concepts/horizontal-pod-autoscaling.html#fig1.2.2.16.1","level":"1.2.2.16","list_caption":"Figure: horizontal-pod-autoscaler","alt":"horizontal-pod-autoscaler","nro":14,"url":"../images/horizontal-pod-autoscaler.png","index":1,"caption_template":"Figure: _CAPTION_","label":"horizontal-pod-autoscaler","attributes":{},"skip":false,"key":"1.2.2.16.1"},{"backlink":"concepts/label.html#fig1.2.2.17.1","level":"1.2.2.17","list_caption":"Figure: label示意图","alt":"label示意图","nro":15,"url":"../images/labels.png","index":1,"caption_template":"Figure: _CAPTION_","label":"label示意图","attributes":{},"skip":false,"key":"1.2.2.17.1"},{"backlink":"guide/using-kubectl.html#fig1.3.2.1.1","level":"1.3.2.1","list_caption":"Figure: kubectl cheatsheet","alt":"kubectl cheatsheet","nro":16,"url":"../images/kubernetes-kubectl-cheatsheet.png","index":1,"caption_template":"Figure: _CAPTION_","label":"kubectl cheatsheet","attributes":{},"skip":false,"key":"1.3.2.1.1"},{"backlink":"guide/using-kubectl.html#fig1.3.2.1.2","level":"1.3.2.1","list_caption":"Figure: kube-shell页面","alt":"kube-shell页面","nro":17,"url":"../images/kube-shell.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"kube-shell页面","attributes":{},"skip":false,"key":"1.3.2.1.2"},{"backlink":"guide/deploy-applications-in-kubernetes.html#fig1.3.5.1.1","level":"1.3.5.1","list_caption":"Figure: API","alt":"API","nro":18,"url":"../images/k8s-app-monitor-test-api-doc.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"API","attributes":{},"skip":false,"key":"1.3.5.1.1"},{"backlink":"guide/deploy-applications-in-kubernetes.html#fig1.3.5.1.2","level":"1.3.5.1","list_caption":"Figure: wercker","alt":"wercker","nro":19,"url":"../images/k8s-app-monitor-agent-wercker.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"wercker","attributes":{},"skip":false,"key":"1.3.5.1.2"},{"backlink":"guide/deploy-applications-in-kubernetes.html#fig1.3.5.1.3","level":"1.3.5.1","list_caption":"Figure: 图表","alt":"图表","nro":20,"url":"../images/k8s-app-monitor-agent.jpg","index":3,"caption_template":"Figure: _CAPTION_","label":"图表","attributes":{},"skip":false,"key":"1.3.5.1.3"},{"backlink":"guide/migrating-hadoop-yarn-to-kubernetes.html#fig1.3.5.2.1","level":"1.3.5.2","list_caption":"Figure: spark on yarn with kubernetes","alt":"spark on yarn with kubernetes","nro":21,"url":"../images/spark-on-yarn-with-kubernetes.png","index":1,"caption_template":"Figure: _CAPTION_","label":"spark on yarn with kubernetes","attributes":{},"skip":false,"key":"1.3.5.2.1"},{"backlink":"guide/migrating-hadoop-yarn-to-kubernetes.html#fig1.3.5.2.2","level":"1.3.5.2","list_caption":"Figure: Terms","alt":"Terms","nro":22,"url":"../images/terms-in-kubernetes-app-deployment.png","index":2,"caption_template":"Figure: _CAPTION_","label":"Terms","attributes":{},"skip":false,"key":"1.3.5.2.2"},{"backlink":"guide/migrating-hadoop-yarn-to-kubernetes.html#fig1.3.5.2.3","level":"1.3.5.2","list_caption":"Figure: 分解步骤解析","alt":"分解步骤解析","nro":23,"url":"../images/migrating-hadoop-yarn-to-kubernetes.png","index":3,"caption_template":"Figure: _CAPTION_","label":"分解步骤解析","attributes":{},"skip":false,"key":"1.3.5.2.3"},{"backlink":"practice/node-installation.html#fig1.4.1.6.1","level":"1.4.1.6","list_caption":"Figure: welcome-nginx","alt":"welcome-nginx","nro":24,"url":"http://olz1di9xf.bkt.clouddn.com/kubernetes-installation-test-nginx.png","index":1,"caption_template":"Figure: _CAPTION_","label":"welcome-nginx","attributes":{},"skip":false,"key":"1.4.1.6.1"},{"backlink":"practice/dashboard-addon-installation.html#fig1.4.1.8.1","level":"1.4.1.8","list_caption":"Figure: kubernetes-dashboard","alt":"kubernetes-dashboard","nro":25,"url":"http://olz1di9xf.bkt.clouddn.com/kubernetes-dashboard-raw.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"kubernetes-dashboard","attributes":{},"skip":false,"key":"1.4.1.8.1"},{"backlink":"practice/heapster-addon-installation.html#fig1.4.1.9.1","level":"1.4.1.9","list_caption":"Figure: dashboard-heapster","alt":"dashboard-heapster","nro":26,"url":"../images/kubernetes-dashboard-with-heapster.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"dashboard-heapster","attributes":{},"skip":false,"key":"1.4.1.9.1"},{"backlink":"practice/heapster-addon-installation.html#fig1.4.1.9.2","level":"1.4.1.9","list_caption":"Figure: grafana","alt":"grafana","nro":27,"url":"../images/kubernetes-heapster-grafana.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"grafana","attributes":{},"skip":false,"key":"1.4.1.9.2"},{"backlink":"practice/heapster-addon-installation.html#fig1.4.1.9.3","level":"1.4.1.9","list_caption":"Figure: kubernetes-influxdb-heapster","alt":"kubernetes-influxdb-heapster","nro":28,"url":"../images/kubernetes-influxdb-heapster.jpg","index":3,"caption_template":"Figure: _CAPTION_","label":"kubernetes-influxdb-heapster","attributes":{},"skip":false,"key":"1.4.1.9.3"},{"backlink":"practice/efk-addon-installation.html#fig1.4.1.10.1","level":"1.4.1.10","list_caption":"Figure: es-setting","alt":"es-setting","nro":29,"url":"../images/es-setting.png","index":1,"caption_template":"Figure: _CAPTION_","label":"es-setting","attributes":{},"skip":false,"key":"1.4.1.10.1"},{"backlink":"practice/efk-addon-installation.html#fig1.4.1.10.2","level":"1.4.1.10","list_caption":"Figure: es-home","alt":"es-home","nro":30,"url":"../images/kubernetes-efk-kibana.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"es-home","attributes":{},"skip":false,"key":"1.4.1.10.2"},{"backlink":"practice/traefik-ingress-installation.html#fig1.4.2.1.1","level":"1.4.2.1","list_caption":"Figure: kubernetes-dashboard","alt":"kubernetes-dashboard","nro":31,"url":"../images/traefik-dashboard.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"kubernetes-dashboard","attributes":{},"skip":false,"key":"1.4.2.1.1"},{"backlink":"practice/traefik-ingress-installation.html#fig1.4.2.1.2","level":"1.4.2.1","list_caption":"Figure: traefik-nginx","alt":"traefik-nginx","nro":32,"url":"../images/traefik-nginx.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"traefik-nginx","attributes":{},"skip":false,"key":"1.4.2.1.2"},{"backlink":"practice/traefik-ingress-installation.html#fig1.4.2.1.3","level":"1.4.2.1","list_caption":"Figure: traefik-guestbook","alt":"traefik-guestbook","nro":33,"url":"../images/traefik-guestbook.jpg","index":3,"caption_template":"Figure: _CAPTION_","label":"traefik-guestbook","attributes":{},"skip":false,"key":"1.4.2.1.3"},{"backlink":"practice/distributed-load-test.html#fig1.4.2.2.1","level":"1.4.2.2","list_caption":"Figure: traefik-dashboard-locust","alt":"traefik-dashboard-locust","nro":34,"url":"../images/traefik-dashboard-locust.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"traefik-dashboard-locust","attributes":{},"skip":false,"key":"1.4.2.2.1"},{"backlink":"practice/distributed-load-test.html#fig1.4.2.2.2","level":"1.4.2.2","list_caption":"Figure: locust-start-swarming","alt":"locust-start-swarming","nro":35,"url":"../images/locust-start-swarming.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"locust-start-swarming","attributes":{},"skip":false,"key":"1.4.2.2.2"},{"backlink":"practice/distributed-load-test.html#fig1.4.2.2.3","level":"1.4.2.2","list_caption":"Figure: sample-webapp-rc","alt":"sample-webapp-rc","nro":36,"url":"../images/sample-webapp-rc.jpg","index":3,"caption_template":"Figure: _CAPTION_","label":"sample-webapp-rc","attributes":{},"skip":false,"key":"1.4.2.2.3"},{"backlink":"practice/distributed-load-test.html#fig1.4.2.2.4","level":"1.4.2.2","list_caption":"Figure: locust-dashboard","alt":"locust-dashboard","nro":37,"url":"../images/locust-dashboard.jpg","index":4,"caption_template":"Figure: _CAPTION_","label":"locust-dashboard","attributes":{},"skip":false,"key":"1.4.2.2.4"},{"backlink":"practice/network-and-cluster-perfermance-test.html#fig1.4.2.3.1","level":"1.4.2.3","list_caption":"Figure: kubernetes-dashboard","alt":"kubernetes-dashboard","nro":38,"url":"http://olz1di9xf.bkt.clouddn.com/kubenetes-e2e-test.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"kubernetes-dashboard","attributes":{},"skip":false,"key":"1.4.2.3.1"},{"backlink":"practice/network-and-cluster-perfermance-test.html#fig1.4.2.3.2","level":"1.4.2.3","list_caption":"Figure: locust-test","alt":"locust-test","nro":39,"url":"http://olz1di9xf.bkt.clouddn.com/kubernetes-locust-test.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"locust-test","attributes":{},"skip":false,"key":"1.4.2.3.2"},{"backlink":"practice/edge-node-configuration.html#fig1.4.2.4.1","level":"1.4.2.4","list_caption":"Figure: 边缘节点架构","alt":"边缘节点架构","nro":40,"url":"../images/kubernetes-edge-node-architecture.png","index":1,"caption_template":"Figure: _CAPTION_","label":"边缘节点架构","attributes":{},"skip":false,"key":"1.4.2.4.1"},{"backlink":"practice/app-log-collection.html#fig1.4.3.2.1","level":"1.4.3.2","list_caption":"Figure: logstash日志收集架构图","alt":"logstash日志收集架构图","nro":41,"url":"../images/filebeat-log-collector.png","index":1,"caption_template":"Figure: _CAPTION_","label":"logstash日志收集架构图","attributes":{},"skip":false,"key":"1.4.3.2.1"},{"backlink":"practice/app-log-collection.html#fig1.4.3.2.2","level":"1.4.3.2","list_caption":"Figure: Kibana页面","alt":"Kibana页面","nro":42,"url":"../images/filebeat-docker-test.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"Kibana页面","attributes":{},"skip":false,"key":"1.4.3.2.2"},{"backlink":"practice/app-log-collection.html#fig1.4.3.2.3","level":"1.4.3.2","list_caption":"Figure: filebeat收集的日志详细信息","alt":"filebeat收集的日志详细信息","nro":43,"url":"../images/kubernetes-filebeat-detail.png","index":3,"caption_template":"Figure: _CAPTION_","label":"filebeat收集的日志详细信息","attributes":{},"skip":false,"key":"1.4.3.2.3"},{"backlink":"practice/monitor.html#fig1.4.3.4.1","level":"1.4.3.4","list_caption":"Figure: Kubernetes集群中的监控","alt":"Kubernetes集群中的监控","nro":44,"url":"../images/monitoring-in-kubernetes.png","index":1,"caption_template":"Figure: _CAPTION_","label":"Kubernetes集群中的监控","attributes":{},"skip":false,"key":"1.4.3.4.1"},{"backlink":"practice/monitor.html#fig1.4.3.4.2","level":"1.4.3.4","list_caption":"Figure: kubernetes的容器命名规则示意图","alt":"kubernetes的容器命名规则示意图","nro":45,"url":"../images/kubernetes-container-naming-rule.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"kubernetes的容器命名规则示意图","attributes":{},"skip":false,"key":"1.4.3.4.2"},{"backlink":"practice/monitor.html#fig1.4.3.4.3","level":"1.4.3.4","list_caption":"Figure: Heapster架构图改进版","alt":"Heapster架构图改进版","nro":46,"url":"../images/kubernetes-heapster-monitoring.png","index":3,"caption_template":"Figure: _CAPTION_","label":"Heapster架构图改进版","attributes":{},"skip":false,"key":"1.4.3.4.3"},{"backlink":"practice/monitor.html#fig1.4.3.4.4","level":"1.4.3.4","list_caption":"Figure: 应用监控架构图","alt":"应用监控架构图","nro":47,"url":"../images/kubernetes-app-monitoring.png","index":4,"caption_template":"Figure: _CAPTION_","label":"应用监控架构图","attributes":{},"skip":false,"key":"1.4.3.4.4"},{"backlink":"practice/monitor.html#fig1.4.3.4.5","level":"1.4.3.4","list_caption":"Figure: 应用拓扑图","alt":"应用拓扑图","nro":48,"url":"../images/weave-scope-service-topology.jpg","index":5,"caption_template":"Figure: _CAPTION_","label":"应用拓扑图","attributes":{},"skip":false,"key":"1.4.3.4.5"},{"backlink":"practice/jenkins-ci-cd.html#fig1.4.3.5.1","level":"1.4.3.5","list_caption":"Figure: 基于Jenkins的持续集成与发布","alt":"基于Jenkins的持续集成与发布","nro":49,"url":"../images/kubernetes-jenkins-ci-cd.png","index":1,"caption_template":"Figure: _CAPTION_","label":"基于Jenkins的持续集成与发布","attributes":{},"skip":false,"key":"1.4.3.5.1"},{"backlink":"practice/data-persistence-problem.html#fig1.4.3.6.1","level":"1.4.3.6","list_caption":"Figure: 日志持久化收集解决方案示意图","alt":"日志持久化收集解决方案示意图","nro":50,"url":"../images/log-persistence-logstash.png","index":1,"caption_template":"Figure: _CAPTION_","label":"日志持久化收集解决方案示意图","attributes":{},"skip":false,"key":"1.4.3.6.1"},{"backlink":"practice/storage-for-containers-using-glusterfs-with-openshift.html#fig1.4.4.1.2.1","level":"1.4.4.1.2","list_caption":"Figure: Screen Shot 2017-03-23 at 21.50.34","alt":"Screen Shot 2017-03-23 at 21.50.34","nro":51,"url":"https://keithtenzer.files.wordpress.com/2017/03/screen-shot-2017-03-23-at-21-50-34.png?w=440","index":1,"caption_template":"Figure: _CAPTION_","label":"Screen Shot 2017-03-23 at 21.50.34","attributes":{},"skip":false,"key":"1.4.4.1.2.1"},{"backlink":"practice/storage-for-containers-using-glusterfs-with-openshift.html#fig1.4.4.1.2.2","level":"1.4.4.1.2","list_caption":"Figure: Screen Shot 2017-03-24 at 11.09.34.png","alt":"Screen Shot 2017-03-24 at 11.09.34.png","nro":52,"url":"https://keithtenzer.files.wordpress.com/2017/03/screen-shot-2017-03-24-at-11-09-341.png?w=440","index":2,"caption_template":"Figure: _CAPTION_","label":"Screen Shot 2017-03-24 at 11.09.34.png","attributes":{},"skip":false,"key":"1.4.4.1.2.2"},{"backlink":"usecases/istio.html#fig1.5.1.1.1","level":"1.5.1.1","list_caption":"Figure: Istio架构图","alt":"Istio架构图","nro":53,"url":"../images/istio-arch.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"Istio架构图","attributes":{},"skip":false,"key":"1.5.1.1.1"},{"backlink":"usecases/istio-installation.html#fig1.5.1.1.1.1","level":"1.5.1.1.1","list_caption":"Figure: BookInfo Sample应用架构图","alt":"BookInfo Sample应用架构图","nro":54,"url":"../images/bookinfo-sample-arch.png","index":1,"caption_template":"Figure: _CAPTION_","label":"BookInfo Sample应用架构图","attributes":{},"skip":false,"key":"1.5.1.1.1.1"},{"backlink":"usecases/istio-installation.html#fig1.5.1.1.1.2","level":"1.5.1.1.1","list_caption":"Figure: BookInfo Sample页面","alt":"BookInfo Sample页面","nro":55,"url":"../images/bookinfo-sample.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"BookInfo Sample页面","attributes":{},"skip":false,"key":"1.5.1.1.1.2"},{"backlink":"usecases/istio-installation.html#fig1.5.1.1.1.3","level":"1.5.1.1.1","list_caption":"Figure: Istio Grafana界面","alt":"Istio Grafana界面","nro":56,"url":"../images/istio-grafana.jpg","index":3,"caption_template":"Figure: _CAPTION_","label":"Istio Grafana界面","attributes":{},"skip":false,"key":"1.5.1.1.1.3"},{"backlink":"usecases/istio-installation.html#fig1.5.1.1.1.4","level":"1.5.1.1.1","list_caption":"Figure: Prometheus页面","alt":"Prometheus页面","nro":57,"url":"../images/istio-prometheus.jpg","index":4,"caption_template":"Figure: _CAPTION_","label":"Prometheus页面","attributes":{},"skip":false,"key":"1.5.1.1.1.4"},{"backlink":"usecases/istio-installation.html#fig1.5.1.1.1.5","level":"1.5.1.1.1","list_caption":"Figure: Zipkin页面","alt":"Zipkin页面","nro":58,"url":"../images/istio-zipkin.jpg","index":5,"caption_template":"Figure: _CAPTION_","label":"Zipkin页面","attributes":{},"skip":false,"key":"1.5.1.1.1.5"},{"backlink":"usecases/istio-installation.html#fig1.5.1.1.1.6","level":"1.5.1.1.1","list_caption":"Figure: ServiceGraph页面","alt":"ServiceGraph页面","nro":59,"url":"../images/istio-servicegraph.jpg","index":6,"caption_template":"Figure: _CAPTION_","label":"ServiceGraph页面","attributes":{},"skip":false,"key":"1.5.1.1.1.6"},{"backlink":"usecases/linkerd.html#fig1.5.1.2.1","level":"1.5.1.2","list_caption":"Figure: source https://linkerd.io","alt":"source https://linkerd.io","nro":60,"url":"https://linkerd.io/images/diagram-individual-instance.png","index":1,"caption_template":"Figure: _CAPTION_","label":"source https://linkerd.io","attributes":{},"skip":false,"key":"1.5.1.2.1"},{"backlink":"usecases/linkerd-user-guide.html#fig1.5.1.2.1.1","level":"1.5.1.2.1","list_caption":"Figure: Jenkins pipeline","alt":"Jenkins pipeline","nro":61,"url":"../images/linkerd-jenkins-pipeline.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"Jenkins pipeline","attributes":{},"skip":false,"key":"1.5.1.2.1.1"},{"backlink":"usecases/linkerd-user-guide.html#fig1.5.1.2.1.2","level":"1.5.1.2.1","list_caption":"Figure: Jenkins config","alt":"Jenkins config","nro":62,"url":"../images/linkerd-jenkins.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"Jenkins config","attributes":{},"skip":false,"key":"1.5.1.2.1.2"},{"backlink":"usecases/linkerd-user-guide.html#fig1.5.1.2.1.3","level":"1.5.1.2.1","list_caption":"Figure: namerd","alt":"namerd","nro":63,"url":"../images/namerd-internal.jpg","index":3,"caption_template":"Figure: _CAPTION_","label":"namerd","attributes":{},"skip":false,"key":"1.5.1.2.1.3"},{"backlink":"usecases/linkerd-user-guide.html#fig1.5.1.2.1.4","level":"1.5.1.2.1","list_caption":"Figure: linkerd监控","alt":"linkerd监控","nro":64,"url":"../images/linkerd-helloworld-outgoing.jpg","index":4,"caption_template":"Figure: _CAPTION_","label":"linkerd监控","attributes":{},"skip":false,"key":"1.5.1.2.1.4"},{"backlink":"usecases/linkerd-user-guide.html#fig1.5.1.2.1.5","level":"1.5.1.2.1","list_caption":"Figure: linkerd监控","alt":"linkerd监控","nro":65,"url":"../images/linkerd-helloworld-incoming.jpg","index":5,"caption_template":"Figure: _CAPTION_","label":"linkerd监控","attributes":{},"skip":false,"key":"1.5.1.2.1.5"},{"backlink":"usecases/linkerd-user-guide.html#fig1.5.1.2.1.6","level":"1.5.1.2.1","list_caption":"Figure: linkerd性能监控","alt":"linkerd性能监控","nro":66,"url":"../images/linkerd-grafana.png","index":6,"caption_template":"Figure: _CAPTION_","label":"linkerd性能监控","attributes":{},"skip":false,"key":"1.5.1.2.1.6"},{"backlink":"usecases/linkerd-user-guide.html#fig1.5.1.2.1.7","level":"1.5.1.2.1","list_caption":"Figure: Linkerd ingress controller","alt":"Linkerd ingress controller","nro":67,"url":"../images/linkerd-ingress-controller.jpg","index":7,"caption_template":"Figure: _CAPTION_","label":"Linkerd ingress controller","attributes":{},"skip":false,"key":"1.5.1.2.1.7"},{"backlink":"usecases/service-discovery-in-microservices.html#fig1.5.1.3.1","level":"1.5.1.3","list_caption":"Figure: 微服务中的服务发现","alt":"微服务中的服务发现","nro":68,"url":"../images/service-discovery-in-microservices.png","index":1,"caption_template":"Figure: _CAPTION_","label":"微服务中的服务发现","attributes":{},"skip":false,"key":"1.5.1.3.1"},{"backlink":"usecases/spark-standalone-on-kubernetes.html#fig1.5.2.1.1","level":"1.5.2.1","list_caption":"Figure: spark master ui","alt":"spark master ui","nro":69,"url":"../images/spark-ui.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"spark master ui","attributes":{},"skip":false,"key":"1.5.2.1.1"},{"backlink":"usecases/spark-standalone-on-kubernetes.html#fig1.5.2.1.2","level":"1.5.2.1","list_caption":"Figure: zeppelin ui","alt":"zeppelin ui","nro":70,"url":"../images/zeppelin-ui.jpg","index":2,"caption_template":"Figure: _CAPTION_","label":"zeppelin ui","attributes":{},"skip":false,"key":"1.5.2.1.2"},{"backlink":"develop/client-go-sample.html#fig1.6.3.1","level":"1.6.3","list_caption":"Figure: 使用kubernetes dashboard进行故障排查","alt":"使用kubernetes dashboard进行故障排查","nro":71,"url":"../images/kubernetes-client-go-sample-update.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"使用kubernetes dashboard进行故障排查","attributes":{},"skip":false,"key":"1.6.3.1"},{"backlink":"appendix/issues.html#fig1.7.2.1","level":"1.7.2","list_caption":"Figure: pvc-storage-limit","alt":"pvc-storage-limit","nro":72,"url":"../images/pvc-storage-limit.jpg","index":1,"caption_template":"Figure: _CAPTION_","label":"pvc-storage-limit","attributes":{},"skip":false,"key":"1.7.2.1"}]},"title":"Kubernetes Handbook","language":"zh-cn","gitbook":"*","description":"Let's play fun with kubernetes!","image-captions":{"caption":"图片 - _CAPTION_"}},"file":{"path":"guide/kubectl-user-authentication-authorization.md","mtime":"2017-08-31T06:17:46.000Z","type":"markdown"},"gitbook":{"version":"3.2.2","time":"2017-08-31T10:20:14.022Z"},"basePath":"..","book":{"language":""}});
});
</script>
</div>
<script src="../gitbook/gitbook.js"></script>
<script src="../gitbook/theme.js"></script>
<script src="../gitbook/gitbook-plugin-github/plugin.js"></script>
<script src="../gitbook/gitbook-plugin-splitter/splitter.js"></script>
<script src="../gitbook/gitbook-plugin-page-toc-button/plugin.js"></script>
<script src="../gitbook/gitbook-plugin-editlink/plugin.js"></script>
<script src="../gitbook/gitbook-plugin-search-plus/jquery.mark.min.js"></script>
<script src="../gitbook/gitbook-plugin-search-plus/search.js"></script>
<script src="../gitbook/gitbook-plugin-sharing/buttons.js"></script>
<script src="../gitbook/gitbook-plugin-fontsettings/fontsettings.js"></script>
</body>
</html>