美文网首页
pod内curl访问apiserver

pod内curl访问apiserver

作者: wwq2020 | 来源:发表于2023-04-24 18:54 被阅读0次

创建testpod.yaml,内容如下

kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  name: demo
rules:
  - apiGroups:
      - ""
    resources:
      - pods
    verbs:
      - list
---
apiVersion: v1
kind: ServiceAccount
metadata:
  name: demo
---
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  name: demo
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: demo
subjects:
  - kind: ServiceAccount
    name: demo
---
apiVersion: v1
kind: Pod
metadata:
  name: demo
spec:
  serviceAccount: demo
  terminationGracePeriodSeconds: 1
  containers:
  - image: alpine
    imagePullPolicy: IfNotPresent
    command:
      - sleep
      - "3600"
    name: app
  restartPolicy: Always

进入pod

kubectl exec -it -n default demo -- sh

安装curl

sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories
apk add curl

测试访问apiserver

token=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
curl  --cacert  /var/run/secrets/kubernetes.io/serviceaccount/ca.crt -H "Authorization: Bearer $token" https://${KUBERNETES_SERVICE_HOST}:443/api/v1/namespaces/default/pods

相关文章

网友评论

      本文标题:pod内curl访问apiserver

      本文链接:https://www.haomeiwen.com/subject/kykjrdtx.html