正确设置AWS k8s的kops权限

时间:2018-04-05 18:03:53

标签: amazon-web-services permissions kubernetes kops

installed Kubernetes on AWS using kops。部分原因是设置了IAM组和用户:

aws iam create-group --group-name kops

aws iam attach-group-policy --policy-arn arn:aws:iam::aws:policy/AmazonEC2FullAccess --group-name kops
aws iam attach-group-policy --policy-arn arn:aws:iam::aws:policy/AmazonRoute53FullAccess --group-name kops
aws iam attach-group-policy --policy-arn arn:aws:iam::aws:policy/AmazonS3FullAccess --group-name kops
aws iam attach-group-policy --policy-arn arn:aws:iam::aws:policy/IAMFullAccess --group-name kops
aws iam attach-group-policy --policy-arn arn:aws:iam::aws:policy/AmazonVPCFullAccess --group-name kops

aws iam create-user --user-name kops
aws iam add-user-to-group --user-name kops --group-name kops
aws iam create-access-key --user-name kops

我的kubernetes已经开始了,但我时不时会遇到奇怪的错误和失败(就像无法将EC2 EBS挂载到pod)。想法可能是它的许可事情。所以我去IAM看看:

enter image description here

kops用户和组从未访问任何内容!

这是正常的吗?

1 个答案:

答案 0 :(得分:0)

是的,这似乎是正常的。

问题是machine type of my workers

我的全功能群集显示了相同的行为。