这是一个 RBAC 限制,您可以在Kubernetes - Using RBAC Authorization文档上阅读。
您想创建自己的ServiceAccount
然后Role
使用RoleBinding
.
服务帐户示例
apiVersion: v1
kind: ServiceAccount
metadata:
name: some-name
namespace: my-name
角色示例
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: Role
metadata:
name: some-name
namespace: my-name
rules:
- apiGroups: ["extensions"]
resources: ["deployments"]
verbs: ["get","list","patch","update"]
角色绑定示例
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: RoleBinding
metadata:
name: some-name
namespace: my-name
subjects:
- kind: ServiceAccount
name: some-name
namespace: my-name
roleRef:
kind: Role
name: some-name
apiGroup: rbac.authorization.k8s.io
网上有例子,你可以找到。