vi admin-sa.yaml
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: admin
annotations:
rbac.authorization.kubernetes.io/autoupdate: "true"
roleRef:
kind: ClusterRole
name: cluster-admin
apiGroup: rbac.authorization.k8s.io
subjects:
- kind: ServiceAccount
name: admin
namespace: kube-system
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: admin
namespace: kube-system
labels:
kubernetes.io/cluster-service: "true"
addonmanager.kubernetes.io/mode: Reconcile
创建admin用户
kubectl create -f admin-sa.yaml
clusterrolebinding.rbac.authorization.k8s.io/admin created
serviceaccount/admin created
查看admin用户
kubectl get secret -n kube-system|grep admin
admin-token-plkmt kubernetes.io/service-account-token 3 82s
获取admin用户token
kubectl describe secret -n kube-system admin-token-plkmt