我创建了一个群集角色“try-usr”
kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: name: try-usr rules: - apiGroups: - '*' resources: - '*' verbs: - get - list - watch
访问Web UI(仪表板)时,它会抛出如下错误:
{ "kind": "Status", "apiVersion": "v1", "metadata": { }, "status": "Failure", "message": "services \"https:kubernetes-dashboard:\" is forbidden: User \"xyz\" cannot get services/proxy in the namespace \"kube-system\"", "reason": "Forbidden", "details": { "name": "https:kubernetes-dashboard:", "kind": "services" }, "code": 403 }
答案 0 :(得分:0)
取决于kubernetes版本,the dashboard will require different permissions according to the docs
<强> V1.7 强>
<强> V1.8 强>