{"id":95581,"date":"2026-08-26T16:40:31","date_gmt":"2026-08-26T08:40:31","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/95581.html"},"modified":"2026-08-26T16:40:31","modified_gmt":"2026-08-26T08:40:31","slug":"%e5%90%83%e9%80%8f-k8s-%e8%b5%84%e6%ba%90%e7%ae%a1%e6%8e%a7-%e5%81%a5%e5%ba%b7%e6%8e%a2%e9%92%88-rbac-%e6%9d%83%e9%99%90%ef%bc%8c%e9%9d%a2%e8%af%95-80-%e8%80%83%e7%82%b9%e5%85%a8%e5%9c%a8%e8%bf%99","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/95581.html","title":{"rendered":"\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01"},"content":{"rendered":"<h2>&#x1f4dd;\u6458\u8981<\/h2>\n<p>\u672c\u6587\u5b8c\u6574\u8bb2\u89e3 K8s \u547d\u540d\u7a7a\u95f4\u8d44\u6e90\u914d\u989d ResourceQuota\u3001LimitRange \u8303\u56f4\u9650\u5236&#xff0c;\u8be6\u89e3 request\/limits \u539f\u7406&#xff0c;CPU \u5185\u5b58 OOM \u73b0\u8c61&#xff1b;\u8be6\u89e3 Pod \u4e09\u5927\u63a2\u9488 liveness\/readiness\/startupProbe&#xff0c;httpGet\/exec\/tcpSocket \u63a2\u6d4b\u65b9\u5f0f&#xff1b;\u68b3\u7406 K8s API \u8bbf\u95ee\u94fe\u8def&#xff1a;\u8ba4\u8bc1\u3001\u9274\u6743\u3001\u51c6\u5165\u63a7\u5236&#xff0c;\u5b9e\u6218 X509 \u8bc1\u4e66\u7528\u6237\u3001RBAC \u89d2\u8272\u4e0e\u89d2\u8272\u7ed1\u5b9a\u3002\u5168\u90e8 YAML\u3001\u547d\u4ee4\u96c6\u7fa4\u5b9e\u6d4b&#xff0c;\u8986\u76d6\u5927\u91cf CKA\u3001\u4e91\u539f\u751f\u9762\u8bd5\u9ad8\u9891\u8003\u70b9\u3002<\/p>\n<h2>&#x1f4d6;\u524d\u8a00<\/h2>\n<p>\u5728 K8s \u751f\u4ea7\u73af\u5883\u4e2d&#xff0c;\u8d44\u6e90\u5931\u63a7\u5bfc\u81f4\u8282\u70b9\u96ea\u5d29\u3001\u5bb9\u5668\u5f02\u5e38\u50f5\u6b7b\u4e0d\u91cd\u542f\u3001\u6743\u9650\u8d8a\u6743\u662f\u6700\u5e38\u89c1\u4e09\u5927\u6545\u969c\u3002 \u672c\u7bc7\u8986\u76d6\u4e09\u5927\u6a21\u5757&#xff1a; 1.\u8d44\u6e90\u7ba1\u63a7&#xff1a;ResourceQuota \u547d\u540d\u7a7a\u95f4\u603b\u914d\u989d&#xff0c;LimitRange \u5355\u5bb9\u5668\u8d44\u6e90\u7ea6\u675f&#xff0c;\u641e\u61c2 request \u8c03\u5ea6\u3001limits \u786c\u9650\u5236&#xff0c;\u7406\u89e3 CPU \u53ef\u538b\u7f29\u3001\u5185\u5b58 OOM \u88ab\u6740\u5e95\u5c42\u903b\u8f91&#xff1b; 2.Pod \u5065\u5eb7\u68c0\u67e5&#xff1a;\u5b58\u6d3b\u63a2\u9488\u3001\u5c31\u7eea\u63a2\u9488\u5b9e\u6218&#xff0c;\u641e\u61c2\u63a2\u9488\u5728\u6269\u7f29\u5bb9\u3001\u6eda\u52a8\u66f4\u65b0\u4e2d\u7684\u751f\u4ea7\u4ef7\u503c&#xff1b; 3.K8s \u5b89\u5168\u4f53\u7cfb&#xff1a;API \u8bbf\u95ee\u5b8c\u6574\u94fe\u8def&#xff0c;\u8eab\u4efd\u8ba4\u8bc1\u3001\u9274\u6743\u3001\u51c6\u5165\u63a7\u5236&#xff0c;X509 \u81ea\u5b9a\u4e49\u7528\u6237\u3001RBAC \u89d2\u8272 \/ \u96c6\u7fa4\u89d2\u8272\u5168\u5957\u5b9e\u64cd\u3002<\/p>\n<h2>&#x1f4c2;\u76ee\u5f55<\/h2>\n<h3>Quota and Limits<\/h3>\n<h3>Kubernetes Health Check<\/h3>\n<h3>Kubernetes \u8ba4\u8bc1\u548c\u6388\u6743<\/h3>\n<h2>Quota and Limits<\/h2>\n<p>\u5b66\u4e60\u53c2\u8003&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u8d44\u6e90\u914d\u989d<\/p>\n<\/li>\n<li>\n<p>\u9650\u5236\u8303\u56f4<\/p>\n<\/li>\n<li>\n<p>\u4e3a Pod \u548c\u5bb9\u5668\u7ba1\u7406\u8d44\u6e90<\/p>\n<\/li>\n<\/ul>\n<h3>\u73af\u5883\u51c6\u5907<\/h3>\n<li>\n<p>\u521b\u5efa\u4e00\u4e2a\u72ec\u7acb\u7684\u540d\u5b57\u7a7a\u95f4quota&#xff0c;\u5e76\u5207\u6362\u5230\u8be5ns<\/p>\n<p> root&#064;master30:~<span class=\"token comment\"># kubectl create ns quota<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl config set-context &#8211;current &#8211;namespace quota<\/span>\n <\/li>\n<li>\n<p>\u63d0\u524d\u90e8\u7f72\u597d Metric Server<\/p>\n<\/li>\n<h3>ResourceQuota<\/h3>\n<p>**\u95ee\u9898&#xff1a;**\u5f53\u591a\u4e2a\u7528\u6237\u6216\u56e2\u961f\u5171\u4eabKubernetes\u96c6\u7fa4\u65f6&#xff0c;\u6709\u4eba\u4f1a\u4f7f\u7528\u8d85\u8fc7\u5176\u57fa\u4e8e\u516c\u5e73\u539f\u5219\u6240\u5206\u914d\u5230\u7684\u8d44\u6e90\u91cf\u3002<\/p>\n<p>**\u89e3\u51b3&#xff1a;**\u53ef\u4ee5\u4f7f\u7528\u8d44\u6e90\u914d\u989d\u9650\u5236 Namespace \u4f7f\u7528\u7684\u8d44\u6e90\u3002<\/p>\n<p>\u8d44\u6e90\u914d\u989d&#xff0c;\u901a\u8fc7 ResourceQuota \u5bf9\u8c61\u6765\u5b9a\u4e49&#xff0c;\u5bf9\u6bcf\u4e2a\u547d\u540d\u7a7a\u95f4\u7684\u8d44\u6e90\u6d88\u8017\u603b\u91cf\u63d0\u4f9b\u9650\u5236\u3002<\/p>\n<p>\u8d44\u6e90\u914d\u989d\u7684\u5de5\u4f5c\u65b9\u5f0f\u5982\u4e0b&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u4e0d\u540c\u7684\u56e2\u961f\u5728\u4e0d\u540c\u7684\u547d\u540d\u7a7a\u95f4\u4e0b\u5de5\u4f5c\u3002\u8fd9\u53ef\u4ee5\u901a\u8fc7 RBAC \u5f3a\u5236\u6267\u884c\u3002<\/p>\n<\/li>\n<li>\n<p>\u96c6\u7fa4\u7ba1\u7406\u5458\u53ef\u4ee5\u4e3a\u6bcf\u4e2a\u547d\u540d\u7a7a\u95f4\u521b\u5efa\u4e00\u4e2a\u6216\u591a\u4e2a ResourceQuota \u5bf9\u8c61\u3002<\/p>\n<\/li>\n<li>\n<p>\u5f53\u7528\u6237\u5728\u547d\u540d\u7a7a\u95f4\u4e0b\u521b\u5efa\u8d44\u6e90&#xff08;\u5982 Pod\u3001Service \u7b49&#xff09;\u65f6&#xff0c;Kubernetes \u7684\u914d\u989d\u7cfb\u7edf\u4f1a\u8ddf\u8e2a\u96c6\u7fa4\u7684\u8d44\u6e90\u4f7f\u7528\u60c5\u51b5&#xff0c; \u4ee5\u786e\u4fdd\u4f7f\u7528\u7684\u8d44\u6e90\u7528\u91cf\u4e0d\u8d85\u8fc7 ResourceQuota \u4e2d\u5b9a\u4e49\u7684\u786c\u6027\u8d44\u6e90\u9650\u989d\u3002<\/p>\n<\/li>\n<li>\n<p>\u5982\u679c\u8d44\u6e90\u521b\u5efa\u6216\u8005\u66f4\u65b0\u8bf7\u6c42\u8fdd\u53cd\u4e86\u914d\u989d\u7ea6\u675f&#xff0c;\u90a3\u4e48\u8be5\u8bf7\u6c42\u4f1a\u62a5\u9519&#xff08;HTTP 403 FORBIDDEN&#xff09;&#xff0c; \u5e76\u5728\u6d88\u606f\u4e2d\u7ed9\u51fa\u6709\u53ef\u80fd\u8fdd\u53cd\u7684\u7ea6\u675f\u3002<\/p>\n<\/li>\n<li>\n<p>\u5982\u679c\u547d\u540d\u7a7a\u95f4\u4e0b\u7684\u8ba1\u7b97\u8d44\u6e90 &#xff08;\u5982 cpu \u548c memory&#xff09;\u7684\u914d\u989d\u88ab\u542f\u7528&#xff0c; \u5219\u7528\u6237\u5fc5\u987b\u4e3a\u8fd9\u4e9b\u8d44\u6e90\u8bbe\u5b9a\u8bf7\u6c42\u503c&#xff08;request&#xff09;\u548c\u7ea6\u675f\u503c&#xff08;limit&#xff09;&#xff0c;\u5426\u5219\u914d\u989d\u7cfb\u7edf\u5c06\u62d2\u7edd Pod \u7684\u521b\u5efa\u3002<\/p>\n<p>\u63d0\u793a: \u53ef\u4f7f\u7528 LimitRanger \u51c6\u5165\u63a7\u5236\u5668\u6765\u4e3a\u6ca1\u6709\u8bbe\u7f6e\u8ba1\u7b97\u8d44\u6e90\u9700\u6c42\u7684 Pod \u8bbe\u7f6e\u9ed8\u8ba4\u503c\u3002<\/p>\n<\/li>\n<\/ul>\n<h4>\u542f\u7528\u8d44\u6e90\u914d\u989d<\/h4>\n<p>Kubernetes \u9ed8\u8ba4\u542f\u7528\u4e86\u8d44\u6e90\u914d\u989d\u529f\u80fd \u3002 \u5f53 API \u670d\u52a1\u5668 \u7684\u547d\u4ee4\u884c\u6807\u5fd7 &#8211;enable-admission-plugins&#061; \u4e2d\u5305\u542b ResourceQuota \u65f6&#xff0c; \u8d44\u6e90\u914d\u989d\u4f1a\u88ab\u542f\u7528\u3002<\/p>\n<p>\u5f53\u547d\u540d\u7a7a\u95f4\u4e2d\u5b58\u5728\u4e00\u4e2a ResourceQuota \u5bf9\u8c61\u65f6&#xff0c;\u5bf9\u4e8e\u8be5\u547d\u540d\u7a7a\u95f4\u800c\u8a00&#xff0c;\u8d44\u6e90\u914d\u989d\u5c31\u662f\u5f00\u542f\u7684\u3002<\/p>\n<h4>\u914d\u989d\u7c7b\u578b<\/h4>\n<p>Kubernetes\u53ef\u4ee5\u9650\u5236\u4e24\u79cd\u7c7b\u578b\u8d44\u6e90&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u5bf9\u8c61\u6570\u91cf&#xff1a;Kubernetes \u8d44\u6e90\u6570\u91cf&#xff0c;\u4f8b\u5982pods&#xff0c;services\u7b49\u3002<\/p>\n<p>\u5b9e\u65bd\u8d44\u6e90\u6570\u91cf\u914d\u989d\u53ef\u4ee5\u63d0\u9ad8kubernetes\u7a33\u5b9a\u6027&#xff0c;\u907f\u514dEtcd\u6570\u636e\u5e93\u65e0\u9650\u589e\u957f&#xff0c;\u8fd8\u53ef\u4ee5\u907f\u514d\u5360\u7528node\u4e2d\u5176\u4ed6\u529f\u80fd\u8d44\u6e90&#xff08;\u4f8b\u5982ip\u5730\u5740\u670d\u52a1&#xff09;\u3002<\/p>\n<\/li>\n<li>\n<p>\u8ba1\u7b97\u8d44\u6e90&#xff1a;\u7269\u7406\u6216\u8005\u865a\u62df\u8d44\u6e90\u5bb9\u91cf&#xff0c;\u4f8b\u5982 CPU&#xff0c;memory \u548c\u5b58\u50a8\u5bb9\u91cf\u3002<\/p>\n<p>\u5b9e\u65bd\u8ba1\u7b97\u8d44\u6e90\u914d\u989d\u53ef\u4ee5\u907f\u514d\u6d88\u8017 kubernetes \u96c6\u7fa4\u4e2d\u5355\u4e2anode\u6240\u6709\u8ba1\u7b97\u8d44\u6e90&#xff0c;\u907f\u514d\u5355\u4e2anamespace\u4e2d\u5e94\u7528\u6d88\u8017\u6240\u6709\u96c6\u7fa4\u8d44\u6e90&#xff0c;\u5bfc\u81f4\u5176\u4ed6namespace\u4e2d\u5e94\u7528\u65e0\u6cd5\u6b63\u5e38\u8fd0\u884c\u3002<\/p>\n<\/li>\n<\/ul>\n<p>**kubernetes \u901a\u8fc7 ResourceQuota \u7c7b\u578b\u8d44\u6e90\u5b9e\u65bd\u914d\u989d\u3002**\u4e00\u4e2anamespace\u53ef\u4ee5\u5305\u542b\u591a\u4e2aResourceQuota\u5bf9\u8c61&#xff0c;\u8fd9\u4e9b\u9650\u5236\u662f\u7d2f\u52a0\u7684&#xff0c;\u4e00\u822c\u60c5\u51b5&#xff0c;\u591a\u4e2aResourceQuota\u5bf9\u8c61\u4e0d\u4f1a\u9650\u5b9a\u540c\u4e00\u4e2a\u8d44\u6e90\u3002<\/p>\n<ul>\n<li>\n<p>\u5bf9\u8c61\u6570\u91cf&#xff1a;<\/p>\n<ul>\n<li>persistentvolumeclaims<\/li>\n<li>services<\/li>\n<li>secrets<\/li>\n<li>configmaps<\/li>\n<li>replicationcontrollers<\/li>\n<li>deployments.apps<\/li>\n<li>replicasets.apps<\/li>\n<li>statefulsets.apps<\/li>\n<li>jobs.batch<\/li>\n<li>cronjobs.batch<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>\u8ba1\u7b97\u8d44\u6e90<\/p>\n<table>\n<tr>\u8d44\u6e90\u540d\u79f0\u63cf\u8ff0<\/tr>\n<tbody>\n<tr>\n<td>limits.cpu<\/td>\n<td>\u5728\u6240\u6709\u5904\u4e8e\u975e\u7ec8\u6b62\u72b6\u6001\u7684 Pod \u4e2d&#xff0c;CPU \u9650\u5236\u7684\u603b\u548c\u4e0d\u80fd\u8d85\u8fc7\u6b64\u503c\u3002<\/td>\n<\/tr>\n<tr>\n<td>limits.memory<\/td>\n<td>\u5728\u6240\u6709\u5904\u4e8e\u975e\u7ec8\u6b62\u72b6\u6001\u7684 Pod \u4e2d&#xff0c;\u5185\u5b58\u9650\u5236\u7684\u603b\u548c\u4e0d\u80fd\u8d85\u8fc7\u8fd9\u4e2a\u503c\u3002<\/td>\n<\/tr>\n<tr>\n<td>requests.cpu<\/td>\n<td>\u5728\u6240\u6709\u5904\u4e8e\u975e\u7ec8\u6b62\u72b6\u6001\u7684 Pod \u4e2d&#xff0c;CPU \u8bf7\u6c42\u7684\u603b\u548c\u4e0d\u80fd\u8d85\u8fc7\u6b64\u503c\u3002<\/td>\n<\/tr>\n<tr>\n<td>requests.memory<\/td>\n<td>\u5728\u6240\u6709\u5904\u4e8e\u975e\u7ec8\u6b62\u72b6\u6001\u7684 Pod \u4e2d&#xff0c;\u5185\u5b58\u8bf7\u6c42\u7684\u603b\u548c\u4e0d\u80fd\u8d85\u8fc7\u8fd9\u4e2a\u503c\u3002<\/td>\n<\/tr>\n<tr>\n<td>requests.storage<\/td>\n<td>\u5728\u6240\u6709\u6301\u4e45\u5377\u58f0\u660e\u4e2d&#xff0c;\u5b58\u50a8\u8bf7\u6c42\u7684\u603b\u548c\u4e0d\u80fd\u8d85\u8fc7\u6b64\u503c\u3002<\/td>\n<\/tr>\n<tr>\n<td>cpu<\/td>\n<td>\u4e0e requests.cpu\u4e00\u6837<\/td>\n<\/tr>\n<tr>\n<td>memory<\/td>\n<td>\u4e0e requests.memory\u4e00\u6837<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/li>\n<\/ul>\n<p>\u5355\u4f4d\u8bf4\u660e&#xff1a;<\/p>\n<ul>\n<li>CPU&#xff1a;1 cpu \u7b49\u4e8e1000 m&#xff0c;\u9ed8\u8ba4\u5355\u4f4d\u662f cpu\u6838\u5fc3\u6570\u91cf\u3002<\/li>\n<li>memory&#xff1a;\u652f\u6301\u4e24\u79cd\u683c\u5f0f\u3002\n<ul>\n<li>Ki | Mi | Gi | Ti | Pi | Ei&#xff0c;\u8fdb\u5236\u662f1024&#xff0c;\u4f8b\u59821024 &#061; 1Ki<\/li>\n<li>k | M | G | T | P | E&#xff0c;\u8fdb\u5236\u662f1000&#xff0c;\u4f8b\u59821000 &#061; 1k<\/li>\n<li>\u9ed8\u8ba4\u5355\u4f4d\u662f G&#xff0c;\u4f8b\u59821.5&#xff0c;\u4ee3\u88681500M\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h4>\u914d\u989d\u7ba1\u7406<\/h4>\n<p>\u91cd\u8981\u8bf4\u660e&#xff1a; \u5982\u679c\u9879\u76ee\u7ea7\u522b\u914d\u989d\u9650\u5b9a\u4e86 request \u548c limit&#xff0c;\u90a3\u4e48\u521b\u5efapod\u7684\u65f6\u5019\u5fc5\u987b\u6307\u5b9a request \u548c limit\u3002<\/p>\n<p>\u521b\u5efa ResourceQuota \u5bf9\u8c61<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create quota myquota &#8211;hard&#061;pods&#061;2,services&#061;3,secrets&#061;5,persistentvolumeclaims&#061;10<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl get resourcequotas <\/span><br \/>\nNAME       AGE   REQUEST                                                                LIMIT<br \/>\nmy-quota   10s   persistentvolumeclaims: <span class=\"token number\">0<\/span>\/10, pods: <span class=\"token number\">0<\/span>\/2, secrets: <span class=\"token number\">1<\/span>\/5, services: <span class=\"token number\">0<\/span>\/3<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl describe quota myquota <\/span><br \/>\nName:                   myquota<br \/>\nNamespace:              <span class=\"token function\">quota<\/span><br \/>\nResource                Used  Hard<br \/>\n&#8212;&#8212;&#8211;                &#8212;-  &#8212;-<br \/>\npersistentvolumeclaims  <span class=\"token number\">0<\/span>     <span class=\"token number\">10<\/span><br \/>\npods                    <span class=\"token number\">0<\/span>     <span class=\"token number\">2<\/span><br \/>\nsecrets                 <span class=\"token number\">1<\/span>     <span class=\"token number\">5<\/span><br \/>\nservices                <span class=\"token number\">0<\/span>     <span class=\"token number\">3<\/span><\/p>\n<p>\u901a\u8fc7 yaml \u6587\u4ef6\u521b\u5efa<\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> ResourceQuota<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> myquota<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">hard<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">persistentvolumeclaims<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;10&#034;<\/span><br \/>\n    <span class=\"token key atrule\">pods<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;2&#034;<\/span><br \/>\n    <span class=\"token key atrule\">secrets<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;5&#034;<\/span><br \/>\n    <span class=\"token key atrule\">services<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;3&#034;<\/span><\/p>\n<p>\u6d4b\u8bd5\u914d\u989d<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create deployment web &#8211;image&#061;hub.laoma.cloud\/library\/nginx &#8211;replicas&#061;3 <\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get all<\/span><br \/>\nNAME                      READY   STATUS    RESTARTS   AGE<br \/>\npod\/web-96d5df5c8-dl7qk   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          40s<br \/>\npod\/web-96d5df5c8-j7fhh   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          40s<\/p>\n<p>NAME                  READY   UP-TO-DATE   AVAILABLE   AGE<br \/>\ndeployment.apps\/web   <span class=\"token number\">2<\/span>\/3     <span class=\"token number\">2<\/span>            <span class=\"token number\">2<\/span>           40s<\/p>\n<p>NAME                            DESIRED   CURRENT   READY   AGE<br \/>\nreplicaset.apps\/web-96d5df5c8   <span class=\"token number\">3<\/span>         <span class=\"token number\">2<\/span>         <span class=\"token number\">2<\/span>       40s<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl describe rs web-96d5df5c8<\/span><br \/>\nLAST SEEN   TYPE      REASON              OBJECT                     MESSAGE<br \/>\n<span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><br \/>\n33s         Warning   FailedCreate        replicaset\/web-96d5df5c8   Error creating: pods <span class=\"token string\">&#034;web-96d5df5c8-xg6c9&#034;<\/span> is forbidden: exceeded quota: myquota, requested: <span class=\"token assign-left variable\">pods<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">1<\/span>, used: <span class=\"token assign-left variable\">pods<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">2<\/span>, limited: <span class=\"token assign-left variable\">pods<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">2<\/span><br \/>\n2s          Warning   FailedCreate        replicaset\/web-96d5df5c8   <span class=\"token punctuation\">(<\/span>combined from similar events<span class=\"token punctuation\">)<\/span>: Error creating: pods <span class=\"token string\">&#034;web-96d5df5c8-89p7j&#034;<\/span> is forbidden: exceeded quota: myquota, requested: <span class=\"token assign-left variable\">pods<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">1<\/span>, used: <span class=\"token assign-left variable\">pods<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">2<\/span>, limited: <span class=\"token assign-left variable\">pods<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">2<\/span><br \/>\n25s         Normal    SuccessfulCreate    replicaset\/web-96d5df5c8   Created pod: web-96d5df5c8-bkzmd<br \/>\n34s         Normal    ScalingReplicaSet   deployment\/web             Scaled up replica <span class=\"token builtin class-name\">set<\/span> web-96d5df5c8 to <span class=\"token number\">3<\/span><\/p>\n<p><span class=\"token comment\"># \u8d85\u8fc7\u914d\u989d&#xff0c;\u521b\u5efa\u5931\u8d25<\/span><\/p>\n<p><span class=\"token comment\"># \u4fee\u6539\u914d\u989d pod\u6570\u91cf\u4e3a10<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl patch resourcequotas myquota -p &#039;{&#034;spec&#034;:{&#034;hard&#034;:{&#034;pods&#034;:10}}}&#039;<\/span><\/p>\n<p><span class=\"token comment\"># \u6b64\u65f6\u91cd\u65b0\u6269\u5c55rs<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl scale rs web-96d5df5c8 &#8211;replicas 3<\/span><\/p>\n<p><span class=\"token comment\"># \u518d\u6b21\u9a8c\u8bc1pod\u6570\u91cf<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pods<\/span><br \/>\nNAME                      READY   STATUS    RESTARTS   AGE<br \/>\npod\/web-96d5df5c8-ajcz2   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          2s<br \/>\npod\/web-96d5df5c8-dl7qk   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          60s<br \/>\npod\/web-96d5df5c8-j7fhh   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          60s<\/p>\n<p><span class=\"token comment\"># \u6e05\u7406\u73af\u5883<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete deployments.apps web<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete resourcequotas myquota<\/span><\/p>\n<p>\u601d\u8003&#xff1a; \u5982\u679c\u4e00\u4e2a\u7528\u6237\u53ef\u4ee5\u7ba1\u7406\u591a\u4e2a namespace&#xff0c;\u80fd\u5426\u9650\u5b9a\u8be5\u7528\u6237\u914d\u989d\u5462&#xff1f;<\/p>\n<h3>Request \u548c Limits<\/h3>\n<p>\u5982\u679c\u547d\u540d\u7a7a\u95f4\u4e0b\u7684\u8ba1\u7b97\u8d44\u6e90 &#xff08;\u5982 cpu \u548c memory&#xff09;\u7684\u914d\u989d\u88ab\u542f\u7528&#xff0c; \u5219\u7528\u6237\u5fc5\u987b\u4e3a\u8fd9\u4e9b\u8d44\u6e90\u8bbe\u5b9a\u8bf7\u6c42\u503c&#xff08;request&#xff09;\u548c\u7ea6\u675f\u503c&#xff08;limit&#xff09;&#xff0c;\u5426\u5219\u914d\u989d\u7cfb\u7edf\u5c06\u62d2\u7edd Pod \u7684\u521b\u5efa\u3002<\/p>\n<p>pod.containers.resources \u5b9a\u4e49\u5305\u542b\u4e24\u90e8\u5206&#xff1a;<\/p>\n<ul>\n<li>\n<p>requests&#xff0c;\u6307\u660epod\u8fd0\u884c\u9700\u8981\u7684\u6700\u5c11\u8ba1\u7b97\u8d44\u6e90&#xff0c;\u8c03\u5ea6\u5668\u67e5\u627e\u5177\u6709\u5145\u8db3\u8ba1\u7b97\u8d44\u6e90\u7684nodes\u3002<\/p>\n<\/li>\n<li>\n<p>limits&#xff0c;\u6307\u660epod\u8fd0\u884c\u53ef\u4ee5\u83b7\u5f97\u8282\u70b9\u6700\u591a\u8ba1\u7b97\u8d44\u6e90&#xff0c;\u7528\u4e8e\u963b\u6b62pod\u5360\u7528node\u592a\u591a\u8ba1\u7b97\u8d44\u6e90\u3002node\u4f7f\u7528Linux\u5185\u6838\u529f\u80fdcgroup&#xff0c;\u9650\u5236pod\u8d44\u6e90\u4f7f\u7528\u3002<\/p>\n<\/li>\n<\/ul>\n<h4>\u6d4b\u8bd5-\u4e0d\u6307\u5b9a\u8ba1\u7b97\u8d44\u6e90<\/h4>\n<p>\u914d\u989d\u793a\u4f8b<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim resourcequota.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> ResourceQuota<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> myquota<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">hard<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">persistentvolumeclaims<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;10&#034;<\/span><br \/>\n    <span class=\"token key atrule\">pods<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;2&#034;<\/span><br \/>\n    <span class=\"token key atrule\">secrets<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;5&#034;<\/span><br \/>\n    <span class=\"token key atrule\">services<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;3&#034;<\/span><br \/>\n    <span class=\"token key atrule\">requests.cpu<\/span><span class=\"token punctuation\">:<\/span> 1000m<br \/>\n    <span class=\"token key atrule\">requests.memory<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;2048Mi&#034;<\/span><br \/>\n    <span class=\"token key atrule\">limits.cpu<\/span><span class=\"token punctuation\">:<\/span> 1000m<br \/>\n    <span class=\"token key atrule\">limits.memory<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;2048Mi&#034;<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f resourcequota.yaml<\/span><\/p>\n<p>pod \u793a\u4f8b<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim pod-without-quota.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/httpd<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">ports<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n      <span class=\"token key atrule\">containerPort<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">80<\/span><br \/>\n      <span class=\"token key atrule\">protocol<\/span><span class=\"token punctuation\">:<\/span> TCP<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f pod-without-quota.yaml<\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: error when creating <span class=\"token string\">&#034;pod-without-quota.yaml&#034;<\/span><span class=\"token builtin class-name\">:<\/span> pods <span class=\"token string\">&#034;web&#034;<\/span> is forbidden: failed quota: myquota: must specify limits.cpu for: web<span class=\"token punctuation\">;<\/span> limits.memory for: web<span class=\"token punctuation\">;<\/span> requests.cpu for: web<span class=\"token punctuation\">;<\/span> requests.memory for: web<\/p>\n<p><span class=\"token comment\"># \u6e05\u7406\u73af\u5883<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete resourcequotas myquota<\/span><\/p>\n<h4>\u6d4b\u8bd5-Request<\/h4>\n<p>\u914d\u989d\u793a\u4f8b<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim resourcequota.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> ResourceQuota<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> myquota<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">hard<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">requests.cpu<\/span><span class=\"token punctuation\">:<\/span> 1000m<br \/>\n    <span class=\"token key atrule\">requests.memory<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;2048Mi&#034;<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f resourcequota.yaml<\/span><\/p>\n<p>pod \u793a\u4f8b1&#xff1a;\u8d85\u4e0a\u9650<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim pod-request-1.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/httpd<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">requests<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 2000m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 4096Mi<br \/>\n    <span class=\"token key atrule\">ports<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n      <span class=\"token key atrule\">containerPort<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">80<\/span><br \/>\n      <span class=\"token key atrule\">protocol<\/span><span class=\"token punctuation\">:<\/span> TCP<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f pod-request-1.yaml<\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: error when creating <span class=\"token string\">&#034;pod-request-1.yaml&#034;<\/span><span class=\"token builtin class-name\">:<\/span> pods <span class=\"token string\">&#034;web&#034;<\/span> is forbidden: exceeded quota: myquota, requested: <span class=\"token assign-left variable\">requests.cpu<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">2<\/span>,requests.memory<span class=\"token operator\">&#061;<\/span>4Gi, used: <span class=\"token assign-left variable\">requests.cpu<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">0<\/span>,requests.memory<span class=\"token operator\">&#061;<\/span><span class=\"token number\">0<\/span>, limited: <span class=\"token assign-left variable\">requests.cpu<\/span><span class=\"token operator\">&#061;<\/span><span class=\"token number\">1<\/span>,requests.memory<span class=\"token operator\">&#061;<\/span>2Gi<\/p>\n<p>pod \u793a\u4f8b2&#xff1a;\u672a\u8d85\u4e0a\u9650<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim pod-request-2.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/httpd<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">requests<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 200m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 1024Mi<br \/>\n    <span class=\"token key atrule\">ports<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n      <span class=\"token key atrule\">containerPort<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">80<\/span><br \/>\n      <span class=\"token key atrule\">protocol<\/span><span class=\"token punctuation\">:<\/span> TCP<\/p>\n<p>root&#064;master30 ~<span class=\"token comment\"># kubectl apply -f pod-request-2.yaml<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pod<\/span><br \/>\nNAME   READY   STATUS    RESTARTS   AGE<br \/>\nweb    <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          43s<\/p>\n<p><span class=\"token comment\"># \u9a8c\u8bc1\u4f7f\u7528\u60c5\u51b5<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl describe resourcequotas myquota <\/span><br \/>\nName:            myquota<br \/>\nNamespace:       <span class=\"token function\">quota<\/span><br \/>\nResource         Used  Hard<br \/>\n&#8212;&#8212;&#8211;         &#8212;-  &#8212;-<br \/>\nrequests.cpu     200m  <span class=\"token number\">1<\/span><br \/>\nrequests.memory  1Gi   2Gi<\/p>\n<p><span class=\"token comment\"># \u5220\u9664pod\u548cquota<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete pod web<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete resourcequotas myquota<\/span><\/p>\n<h4>\u6d4b\u8bd5-Limits<\/h4>\n<h5>\u538b\u529b\u6d4b\u8bd5\u955c\u50cf<\/h5>\n<p>\u53ef\u4ee5\u76f4\u63a5\u4f7f\u7528\u955c\u50cf hub.laoma.cloud\/progrium\/stress \u8fdb\u884c\u538b\u529b\u6d4b\u8bd5&#xff0c;\u8be5\u955c\u50cf\u4e2d\u8fd0\u884cstress\u547d\u4ee4\u3002<\/p>\n<p>\u627e\u8bb2\u5e08\u7d22\u53d6\u955c\u50cf\u3002<\/p>\n<p>Usage: stress <span class=\"token punctuation\">[<\/span>OPTION <span class=\"token punctuation\">[<\/span>ARG<span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">]<\/span> <span class=\"token punctuation\">..<\/span>.<br \/>\n -?, <span class=\"token parameter variable\">&#8211;help<\/span>         show this <span class=\"token builtin class-name\">help<\/span> statement<br \/>\n     <span class=\"token parameter variable\">&#8211;version<\/span>      show version statement<br \/>\n -v, <span class=\"token parameter variable\">&#8211;verbose<\/span>      be verbose<br \/>\n -q, <span class=\"token parameter variable\">&#8211;quiet<\/span>        be quiet<br \/>\n -n, &#8211;dry-run      show what would have been <span class=\"token keyword\">done<\/span><br \/>\n -t, <span class=\"token parameter variable\">&#8211;timeout<\/span> N    <span class=\"token function\">timeout<\/span> after N seconds<br \/>\n     <span class=\"token parameter variable\">&#8211;backoff<\/span> N    <span class=\"token function\">wait<\/span> factor of N microseconds before work starts<br \/>\n -c, <span class=\"token parameter variable\">&#8211;cpu<\/span> N        spawn N workers spinning on sqrt<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n -i, <span class=\"token parameter variable\">&#8211;io<\/span> N         spawn N workers spinning on sync<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n -m, <span class=\"token parameter variable\">&#8211;vm<\/span> N         spawn N workers spinning on malloc<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span>\/free<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n     &#8211;vm-bytes B   malloc B bytes per vm worker <span class=\"token punctuation\">(<\/span>default is 256MB<span class=\"token punctuation\">)<\/span><br \/>\n     &#8211;vm-stride B  <span class=\"token function\">touch<\/span> a byte every B bytes <span class=\"token punctuation\">(<\/span>default is <span class=\"token number\">4096<\/span><span class=\"token punctuation\">)<\/span><br \/>\n     &#8211;vm-hang N    <span class=\"token function\">sleep<\/span> N secs before <span class=\"token function\">free<\/span> <span class=\"token punctuation\">(<\/span>default none, <span class=\"token number\">0<\/span> is inf<span class=\"token punctuation\">)<\/span><br \/>\n     &#8211;vm-keep      redirty memory instead of freeing and reallocating<br \/>\n -d, <span class=\"token parameter variable\">&#8211;hdd<\/span> N        spawn N workers spinning on write<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span>\/unlink<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n     &#8211;hdd-bytes B  <span class=\"token function\">write<\/span> B bytes per hdd worker <span class=\"token punctuation\">(<\/span>default is 1GB<span class=\"token punctuation\">)<\/span><\/p>\n<p>Example: stress <span class=\"token parameter variable\">&#8211;cpu<\/span> <span class=\"token number\">8<\/span> <span class=\"token parameter variable\">&#8211;io<\/span> <span class=\"token number\">4<\/span> <span class=\"token parameter variable\">&#8211;vm<\/span> <span class=\"token number\">2<\/span> &#8211;vm-bytes 128M <span class=\"token parameter variable\">&#8211;timeout<\/span> 10s<\/p>\n<p>Note: Numbers may be suffixed with s,m,h,d,y <span class=\"token punctuation\">(<\/span>time<span class=\"token punctuation\">)<\/span> or B,K,M,G <span class=\"token punctuation\">(<\/span>size<span class=\"token punctuation\">)<\/span>.<\/p>\n<p>\u5e38\u7528\u9009\u9879&#xff1a;<\/p>\n<ul>\n<li>\n<p>-c, &#8211;cpu N spawn N workers spinning on sqrt()<\/p>\n<\/li>\n<li>\n<p>-m, &#8211;vm N spawn N workers spinning on malloc()\/free()<\/p>\n<p>\u200b &#8211;vm-bytes B malloc B bytes per vm worker (default is 256MB)<\/p>\n<\/li>\n<li>\n<p>-d, &#8211;hdd N spawn N workers spinning on write()\/unlink() \u2013hdd-bytes B write B bytes per hdd worker (default is 1GB)<\/p>\n<\/li>\n<\/ul>\n<p>\u793a\u4f8b&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u538b\u529b\u6d4b\u8bd5\u5185\u5b58<\/span><br \/>\n$ <span class=\"token function\">docker<\/span> run <span class=\"token parameter variable\">&#8211;name<\/span> stress hub.laoma.cloud\/progrium\/stress <span class=\"token parameter variable\">-m<\/span> <span class=\"token number\">1<\/span> &#8211;vm-bytes 512M<\/p>\n<p><span class=\"token comment\"># \u538b\u529b\u6d4b\u8bd5CPU<\/span><br \/>\n$ <span class=\"token function\">docker<\/span> run <span class=\"token parameter variable\">&#8211;name<\/span> stress hub.laoma.cloud\/progrium\/stress <span class=\"token parameter variable\">-c<\/span> <span class=\"token number\">1<\/span><\/p>\n<p><span class=\"token comment\"># \u538b\u529b\u6d4b\u8bd5IO<\/span><br \/>\n$ <span class=\"token function\">docker<\/span> run <span class=\"token parameter variable\">&#8211;name<\/span> stress hub.laoma.cloud\/progrium\/stress \u2013d <span class=\"token number\">1<\/span> &#8211;hdd-bytes 3G<\/p>\n<p>\u5bf9\u4e8e pod&#xff1a;<\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/progrium\/stress<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">command<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token punctuation\">[<\/span><span class=\"token string\">&#039;sh&#039;<\/span><span class=\"token punctuation\">,<\/span><span class=\"token string\">&#039;-c&#039;<\/span><span class=\"token punctuation\">,<\/span><span class=\"token string\">&#039;sleep 3600&#039;<\/span><span class=\"token punctuation\">]<\/span><br \/>\n    <span class=\"token comment\"># \u6216\u8005\u4e0d\u7528command&#xff0c;\u800c\u662f\u4f7f\u7528args\u4f5c\u4e3a\u53c2\u6570\u4f20\u9012\u7ed9\u955c\u50cf\u7684Entrypoint\u3002<\/span><br \/>\n    <span class=\"token comment\">#args: [&#039;-m&#039;,&#039;1&#039;,&#039;&#8211;vm-bytes&#039;,&#039;512M&#039;]<\/span><br \/>\n    <span class=\"token comment\">#args: [&#039;-c&#039;,&#039;1&#039;]<\/span><br \/>\n    <span class=\"token comment\">#args: [&#039;-d&#039;,&#039;1&#039;,&#039;&#8211;hdd-bytes&#039;,&#039;3G&#039;]<\/span><\/p>\n<h5>\u914d\u989d\u793a\u4f8b<\/h5>\n<p>root&#064;master30:~<span class=\"token comment\"># vim resourcequota.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> ResourceQuota<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> myquota<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">hard<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">limits.cpu<\/span><span class=\"token punctuation\">:<\/span> 1000m<br \/>\n    <span class=\"token key atrule\">limits.memory<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;2048Mi&#034;<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f resourcequota.yaml<\/span><\/p>\n<h5>\u6d4b\u8bd5 CPU \u8d44\u6e90<\/h5>\n<p>pod\u793a\u4f8b&#xff1a;<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim pod-limit-cpu.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/progrium\/stress<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">args<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token punctuation\">[<\/span><span class=\"token string\">&#039;-c&#039;<\/span><span class=\"token punctuation\">,<\/span><span class=\"token string\">&#039;1&#039;<\/span><span class=\"token punctuation\">]<\/span><br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 200m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;256Mi&#034;<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f pod-limit-cpu.yaml<\/span><\/p>\n<p>\u6253\u5f00\u4e00\u4e2a\u7ec8\u7aef\u76d1\u63a7<\/p>\n<p>kubectl top \u547d\u4ee4\u9700\u8981\u63d0\u524d\u90e8\u7f72Metrics-Server<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl top pods<\/span><br \/>\nNAME     CPU<span class=\"token punctuation\">(<\/span>cores<span class=\"token punctuation\">)<\/span>   MEMORY<span class=\"token punctuation\">(<\/span>bytes<span class=\"token punctuation\">)<\/span><br \/>\nstress   201m         0Mi<\/p>\n<p>**\u53ef\u4ee5\u53d1\u73b0&#xff1a;**CPU \u4f7f\u7528\u7387\u7ef4\u6301\u5728 200m \u5de6\u53f3\u3002<\/p>\n<p><span class=\"token comment\"># \u5220\u9664 pod<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete pod stress &#8211;force<\/span><\/p>\n<h5>\u6d4b\u8bd5 MEMORY \u8d44\u6e90<\/h5>\n<p>pod\u793a\u4f8b&#xff1a;<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim pod-limit-memory.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/progrium\/stress<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">args<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token punctuation\">[<\/span><span class=\"token string\">&#039;-m&#039;<\/span><span class=\"token punctuation\">,<\/span><span class=\"token string\">&#039;1&#039;<\/span><span class=\"token punctuation\">,<\/span><span class=\"token string\">&#039;&#8211;vm-bytes&#039;<\/span><span class=\"token punctuation\">,<\/span><span class=\"token string\">&#039;512M&#039;<\/span><span class=\"token punctuation\">]<\/span><br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 200m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;256Mi&#034;<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f pod-limit-memory.yaml<\/span><\/p>\n<p>\u6253\u5f00\u4e00\u4e2a\u7ec8\u7aef\u76d1\u63a7<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl get pods -w<\/span><br \/>\nNAME     READY   STATUS      RESTARTS     AGE<br \/>\nstress   <span class=\"token number\">0<\/span>\/1     OOMKilled   <span class=\"token number\">1<\/span> <span class=\"token punctuation\">(<\/span>2s ago<span class=\"token punctuation\">)<\/span>   3s<br \/>\nstress   <span class=\"token number\">0<\/span>\/1     CrashLoopBackOff   <span class=\"token number\">1<\/span> <span class=\"token punctuation\">(<\/span>2s ago<span class=\"token punctuation\">)<\/span>   4s<\/p>\n<p>\u53ef\u4ee5\u53d1\u73b0&#xff1a; Pod \u72b6\u6001\u4e3a OOMKilled&#xff0c;\u5e76\u8fdb\u884crestart\u3002<\/p>\n<p><span class=\"token comment\"># \u5220\u9664 pod he <\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete pod stress &#8211;force<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete resourcequotas myquota<\/span><\/p>\n<h5>\u603b\u7ed3<\/h5>\n<li>\n<p>\u8ba1\u7b97\u8d44\u6e90\u7684 limits \u603b\u548c\u662f\u5426\u4f1a\u8d85\u8fc7\u8282\u70b9\u4e0a\u8d44\u6e90\u603b\u548c&#xff1f;<\/p>\n<p>\u7b54\u6848&#xff1a;\u53ef\u80fd\u4f1a\u3002 \u5047\u8bbe node\u53ef\u7528MEMORY\u4e3a1G\u3002<\/p>\n<p>\u6bcf\u4e2apod\u5185\u5b58 requests\u662f256M&#xff0c;limit\u662f512M\u3002\u521b\u5efa5\u4e2apod&#xff0c;pod\u5b9e\u9645\u5360\u7528\u5185\u5b58\u4e5f\u4e3a256M&#xff08;\u6709\u53ef\u80fd\u5c0f\u4e8e256M&#xff09;\u3002<\/p>\n<p>node\u4e0a\u5927\u6982\u53ef\u4ee5\u521b\u5efa4\u4e2apod&#xff0c;\u800c\u6b64\u65f6\u7684limits\u603b\u548c\u662f2G\u3002<\/p>\n<\/li>\n<li>\n<p>\u5f53\u8ba1\u7b97\u8d44\u6e90\u7684limits\u603b\u548c\u8d85\u8fc7\u8282\u70b9\u4e0a\u8d44\u6e90\u603b\u548c\u65f6&#xff0c;kubernetes\u5982\u4f55\u5904\u7406&#xff1f;<\/p>\n<ul>\n<li>\u5bf9\u4e8e cpu&#xff0c;kubernetes \u8ba4\u4e3a cpu \u662f\u53ef\u88ab\u538b\u7f29\u7684\u8d44\u6e90&#xff0c;\u5728\u5e94\u7528\u8fbe\u5230limits\u65f6&#xff0c;\u51cf\u5c11\u8be5\u5bb9\u5668\u7684\u8c03\u5ea6\u65f6\u95f4&#xff0c;\u5e76\u4e0d\u4f1a\u6740\u6b7b\u5e94\u7528\u3002<\/li>\n<li>\u5bf9\u4e8e memory&#xff0c;kubernetes \u8ba4\u4e3a memory \u662f\u65e0\u6cd5\u88ab\u538b\u7f29\u7684\u8d44\u6e90&#xff0c;\u6b64\u65f6k8s\u4f1a\u6740\u6b7b\u5360\u7528\u8d44\u6e90\u8d85\u8fc7\u5176request\u7684\u5e94\u7528&#xff08;1.9\u7248\u672c\u4e4b\u540e\u7684\u7248\u672c&#xff09;\u3002\u9996\u5f53\u5176\u51b2\u7684\u662f\u6ca1\u6709\u6307\u5b9arequest\u7684container&#xff0c;\u7136\u540e\u662f\u4f7f\u7528\u8d44\u6e90\u8d85\u8fc7\u5176request\u66f4\u591a\u7684container\u3002\u540c\u7b49\u60c5\u51b5\u4e0b\u4f18\u5148\u7ea7\u66f4\u4f4e\u7684container\u66f4\u5bb9\u6613\u88ab\u6740\u6b7b\u3002<\/li>\n<\/ul>\n<\/li>\n<h3>LimitRange<\/h3>\n<p>kubernetes\u521b\u5efapod\u65f6&#xff0c;\u9ed8\u8ba4\u4e0d\u6307\u5b9a\u8d44\u6e90\u8bf7\u6c42\u548c\u9650\u5236\u3002\u5982\u679cnamespace\u8bbe\u7f6e\u4e86\u914d\u989d&#xff0c;\u90a3\u4e48\u521b\u5efa\u4e0d\u6307\u5b9a\u8d44\u6e90\u8bf7\u6c42\u548c\u8d44\u6e90\u9650\u5236\u7684pod\u662f\u4e0d\u5141\u8bb8\u7684\u3002\u4e3a\u4e86\u5728\u8bbe\u5b9a\u914d\u989d\u7684namespace\u4e2d\u4f7f\u7528pod&#xff0c;namespace\u8fd8\u9700\u8981\u4e3apod\u8d44\u6e90\u8bf7\u6c42\u8bbe\u5b9a\u9ed8\u8ba4\u8303\u56f4\u3002<\/p>\n<p>LimitRange \u8d44\u6e90&#xff0c;\u4e5f\u79f0\u4e3alimits&#xff0c;\u5b9a\u4e49\u4e86\u5355\u4e2apod\u7684\u8d44\u6e90\u8bf7\u6c42\u548c\u8d44\u6e90\u9650\u5236default\u3001minimum\u3001maximum\u503c\u3002pod\u7684\u8d44\u6e90\u8bf7\u6c42\u662f\u5176\u4e2d\u6240\u6709\u5bb9\u5668\u8bf7\u6c42\u7684\u603b\u548c\u3002<\/p>\n<p>LimitRange \u8d44\u6e90\u7528\u4e8e\u9650\u5b9a\u7279\u5b9a namespace\u3002<\/p>\n<p>namespace\u8bbe\u5b9a\u4e86LimitRange&#xff0c;\u521b\u5efa\u8d44\u6e90\u89c4\u5219&#xff1a;<\/p>\n<ul>\n<li>\u5982\u679c\u9879\u76ee\u4e2d\u8bf7\u6c42\u4e00\u4e2a\u672a\u63d0\u4f9b\u8ba1\u7b97\u8d44\u6e90\u7684\u5bf9\u8c61&#xff0c;\u90a3\u4e48\u6b64\u65f6namespace\u5c06\u4f7f\u7528limit\u8303\u56f4default\u503c\u521b\u5efa\u8be5\u5bf9\u8c61\u3002<\/li>\n<li>\u5982\u679c\u9879\u76ee\u4e2d\u8bf7\u6c42\u4e00\u4e2a\u8ba1\u7b97\u8d44\u6e90\u7684\u5bf9\u8c61&#xff0c;\u8bf7\u6c42\u7684\u8d44\u6e90\u5c0f\u4e8elimit\u6700\u5c0f\u503c&#xff0c;\u90a3\u4e48\u8be5\u8d44\u6e90**\u65e0\u6cd5\u521b\u5efa**\u3002<\/li>\n<li>\u5982\u679c\u9879\u76ee\u4e2d\u8bf7\u6c42\u4e00\u4e2a\u8ba1\u7b97\u8d44\u6e90\u7684\u5bf9\u8c61&#xff0c;\u8bf7\u6c42\u7684\u8d44\u6e90\u5927\u4e8elimit\u6700\u5927\u503c&#xff0c;\u90a3\u4e48\u8be5\u8d44\u6e90**\u65e0\u6cd5\u521b\u5efa**\u3002<\/li>\n<\/ul>\n<p>LimitRange \u793a\u4f8b<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim limits.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> LimitRange<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> mylimit<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">type<\/span><span class=\"token punctuation\">:<\/span> Container<br \/>\n      <span class=\"token key atrule\">max<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 1024Mi<br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n      <span class=\"token key atrule\">min<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 128Mi<br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 100m<br \/>\n      <span class=\"token key atrule\">default<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 512Mi<br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 500m<br \/>\n      <span class=\"token key atrule\">defaultRequest<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 256Mi<br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 200m<\/p>\n<p>\u8bf4\u660e&#xff1a;<\/p>\n<ul>\n<li>name&#xff1a;\u53ea\u80fd\u4f7f\u7528\u5c0f\u5199\u5b57\u6bcd&#xff0c;\u6570\u5b57&#xff0c; \u2018-\u2019 \u548c \u2018.\u2019&#xff0c;\u800c\u4e14\u53ea\u80fd\u662f\u6570\u5b57\u6216\u5b57\u6bcd\u5f00\u5934\u548c\u7ed3\u5c3e\u3002<\/li>\n<li>default&#xff1a;\u5373\u8be5namespace\u914d\u7f6eresourceQuota\u65f6&#xff0c;\u521b\u5efacontainer\u7684\u9ed8\u8ba4limit\u4e0a\u9650<\/li>\n<li>defaultRequest&#xff1a;\u5373\u8be5namespace\u914d\u7f6eresourceQuota\u65f6&#xff0c;\u521b\u5efacontainer\u7684\u9ed8\u8ba4request\u4e0a\u9650<\/li>\n<li>max&#xff1a;\u5373\u8be5namespace\u4e0b\u521b\u5efacontainer\u7684\u8d44\u6e90\u6700\u5927\u503c<\/li>\n<li>min&#xff1a;\u5373\u8be5namespace\u4e0b\u521b\u5efacontainer\u7684\u8d44\u6e90\u6700\u5c0f\u503c<\/li>\n<\/ul>\n<p>\u5176\u4e2d&#xff1a; min &lt;&#061; defaultRequest &lt;&#061; default &lt;&#061; max<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f limits.yaml<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get limitranges <\/span><br \/>\nNAME      CREATED AT<br \/>\nmylimit   <span class=\"token number\">2021<\/span>-09-09T04:09:15Z<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl describe limitranges mylimit <\/span><br \/>\nName:       mylimit<br \/>\nNamespace:  <span class=\"token function\">quota<\/span><br \/>\nType        Resource  Min    Max  Default Request  Default Limit  Max Limit\/Request Ratio<br \/>\n&#8212;-        &#8212;&#8212;&#8211;  &#8212;    &#8212;  &#8212;&#8212;&#8212;&#8212;&#8212;  &#8212;&#8212;&#8212;&#8212;-  &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\nContainer   cpu       100m   <span class=\"token number\">1<\/span>    200m             500m           &#8211;<br \/>\nContainer   memory    128Mi  1Gi  256Mi            512Mi          &#8211;<\/p>\n<h4>\u672a\u6307\u5b9a resources<\/h4>\n<p>\u793a\u4f8b1&#xff1a;<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim pod-without-limits.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/progrium\/stress<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">args<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token punctuation\">[<\/span><span class=\"token string\">&#039;-c&#039;<\/span><span class=\"token punctuation\">,<\/span><span class=\"token string\">&#039;1&#039;<\/span><span class=\"token punctuation\">]<\/span><\/p>\n<p>**\u7ed3\u8bba&#xff1a;**\u521b\u5efa\u51fa\u6765\u7684pod\u7684resources \u4e0e limitranage \u6307\u5b9a\u7684\u76f8\u5173\u9ed8\u8ba4\u503c\u4e00\u81f4\u3002<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f pod-without-limits.yaml<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl top pods<\/span><br \/>\nNAME     CPU<span class=\"token punctuation\">(<\/span>cores<span class=\"token punctuation\">)<\/span>   MEMORY<span class=\"token punctuation\">(<\/span>bytes<span class=\"token punctuation\">)<\/span><br \/>\nstress   501m         0Mi<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl get pod stress -o yaml<\/span><\/p>\n<p><span class=\"token punctuation\">&#8230;<\/span><span class=\"token punctuation\">&#8230;<\/span><br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/progrium\/stress<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> stress<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 500m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 512Mi<br \/>\n      <span class=\"token key atrule\">requests<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 200m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 256Mi<br \/>\n<span class=\"token punctuation\">&#8230;<\/span><span class=\"token punctuation\">&#8230;<\/span><\/p>\n<p><span class=\"token comment\"># \u6e05\u7406\u8d44\u6e90<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete limitranges mylimit <\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete pod web &#8211;force <\/span><\/p>\n<h4>\u53ea\u6307\u5b9a limit \u503c<\/h4>\n<h5>\u793a\u4f8b 2-1&#xff1a;limit \u503c\u5927\u4e8e max \u503c<\/h5>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/nginx<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1.1<\/span><br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 1100Mi<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f limit.yml<\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: error when creating <span class=\"token string\">&#034;limit.yml&#034;<\/span><span class=\"token builtin class-name\">:<\/span> pods <span class=\"token string\">&#034;web&#034;<\/span> is forbidden: <span class=\"token punctuation\">[<\/span>maximum cpu usage per Container is <span class=\"token number\">1<\/span>, but limit is 1100m, maximum memory usage per Container is 1Gi, but limit is 1181116006400m<span class=\"token punctuation\">]<\/span><\/p>\n<h5>\u793a\u4f8b 2-2&#xff1a;limit \u503c\u5c0f\u4e8e min \u503c<\/h5>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/nginx<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 60m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 60Mi<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f limit.yml<\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: error when creating <span class=\"token string\">&#034;limit.yml&#034;<\/span><span class=\"token builtin class-name\">:<\/span> pods <span class=\"token string\">&#034;web&#034;<\/span> is forbidden: <span class=\"token punctuation\">[<\/span>minimum cpu usage per Container is 100m, but request is 60m, minimum memory usage per Container is 128Mi, but request is 60Mi<span class=\"token punctuation\">]<\/span><\/p>\n<h5>\u793a\u4f8b 2-3&#xff1a;min \u503c&lt; limit \u503c&lt; max \u503c<\/h5>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/nginx<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 600m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 600Mi<\/p>\n<p>\u7ed3\u8bba&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u521b\u5efa\u7684\u5bb9\u5668limits\u503c\u5fc5\u987b\u6ee1\u8db3\u6761\u4ef6&#xff1a;min\u503c&lt;\u6307\u5b9a\u7684limit\u503c&lt;max\u503c<\/p>\n<\/li>\n<li>\n<p>\u5f53\u53ea\u6307\u5b9alimits\u503c\u65f6&#xff0c;requests\u503c\u4e0elimits\u503c\u4fdd\u6301\u4e00\u81f4&#xff0c;\u800c\u4e0d\u662fdefault request\u3002<\/p>\n<p> root&#064;master30<span class=\"token punctuation\">:<\/span><span class=\"token null important\">~<\/span><span class=\"token comment\"># kubectl get pod web -o yaml<\/span><br \/>\n<span class=\"token punctuation\">&#8230;<\/span><span class=\"token punctuation\">&#8230;<\/span><br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/nginx<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> Always<br \/>\n    <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 600m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 600Mi<br \/>\n      <span class=\"token key atrule\">requests<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 600m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 600Mi<br \/>\n<span class=\"token punctuation\">&#8230;<\/span><span class=\"token punctuation\">&#8230;<\/span>\n <\/li>\n<\/ul>\n<h4>\u53ea\u6307\u5b9a requests<\/h4>\n<h5>\u793a\u4f8b 3-1&#xff1a;requests \u5927\u4e8e max \u503c<\/h5>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/nginx<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">requests<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 1600m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 600Mi<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f limit4.yml <\/span><br \/>\nThe Pod <span class=\"token string\">&#034;web&#034;<\/span> is invalid:<br \/>\n* spec.containers<span class=\"token punctuation\">[<\/span><span class=\"token number\">0<\/span><span class=\"token punctuation\">]<\/span>.resources.requests: Invalid value: <span class=\"token string\">&#034;1600m&#034;<\/span><span class=\"token builtin class-name\">:<\/span> must be <span class=\"token function\">less<\/span> than or equal to cpu limit<br \/>\n* spec.containers<span class=\"token punctuation\">[<\/span><span class=\"token number\">0<\/span><span class=\"token punctuation\">]<\/span>.resources.requests: Invalid value: <span class=\"token string\">&#034;1600Mi&#034;<\/span><span class=\"token builtin class-name\">:<\/span> must be <span class=\"token function\">less<\/span> than or equal to memory limit<\/p>\n<h5>\u793a\u4f8b 3-2&#xff1a;requests \u5c0f\u4e8e min \u503c<\/h5>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/nginx<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">requests<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 60m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 60Mi<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f limit.yml <\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: error when creating <span class=\"token string\">&#034;limit.yml&#034;<\/span><span class=\"token builtin class-name\">:<\/span> pods <span class=\"token string\">&#034;web&#034;<\/span> is forbidden: <span class=\"token punctuation\">[<\/span>minimum cpu usage per Container is 100m, but request is 60m, minimum memory usage per Container is 128Mi, but request is 60Mi<span class=\"token punctuation\">]<\/span><\/p>\n<h5>\u793a\u4f8b 3-3&#xff1a;min \u503c&lt; request \u503c&lt; max \u503c<\/h5>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/nginx<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">requests<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 400m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 400Mi<\/p>\n<p>\u7ed3\u8bba&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u521b\u5efa\u7684\u5bb9\u5668requests\u503c\u5fc5\u987b\u6ee1\u8db3\u6761\u4ef6&#xff1a;min\u503c&lt;requests\u503c&lt;limits\u503c<\/p>\n<\/li>\n<li>\n<p>\u5f53\u53ea\u6307\u5b9arequests\u503c\u65f6&#xff0c;limits\u503c\u4e0edefault\u503c\u4fdd\u6301\u4e00\u81f4\u3002<\/p>\n<p> root&#064;master30<span class=\"token punctuation\">:<\/span><span class=\"token null important\">~<\/span><span class=\"token comment\"># kubectl get pod web -o yaml<\/span><br \/>\n<span class=\"token punctuation\">&#8230;<\/span><span class=\"token punctuation\">&#8230;<\/span><br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/nginx<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> Always<br \/>\n    <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 500m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 512Mi<br \/>\n      <span class=\"token key atrule\">requests<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">cpu<\/span><span class=\"token punctuation\">:<\/span> 400m<br \/>\n        <span class=\"token key atrule\">memory<\/span><span class=\"token punctuation\">:<\/span> 400Mi<br \/>\n<span class=\"token punctuation\">&#8230;<\/span><span class=\"token punctuation\">&#8230;<\/span>\n <\/li>\n<\/ul>\n<h4>\u9650\u5b9a\u8d44\u6e90\u7c7b\u578b<\/h4>\n<p>LimitRange \u8d44\u6e90\u53ef\u4ee5\u9650\u5b9a\u5982\u4e0b\u8d44\u6e90&#xff1a;<\/p>\n<table>\n<tr>TypeResource NameDescription<\/tr>\n<tbody>\n<tr>\n<td>container<\/td>\n<td>cpu\u3001memory<\/td>\n<td>\u9650\u5b9a\u5bb9\u5668 cpu\u3001memroy<\/td>\n<\/tr>\n<tr>\n<td>Pod<\/td>\n<td>cpu\u3001memory<\/td>\n<td>\u9650\u5b9a Pod \u4e2d\u6240\u6709\u5bb9\u5668cpu\u3001memroy\u7684\u603b\u548c<\/td>\n<\/tr>\n<tr>\n<td>PVC<\/td>\n<td>storage<\/td>\n<td>\u9650\u5b9aPVC\u7533\u8bf7\u7684\u5b58\u50a8\u7a7a\u95f4\u5927\u5c0f<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>LimitRange for PVC \u793a\u4f8b&#xff1a;<\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> LimitRange<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> storagelimits<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">limits<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">type<\/span><span class=\"token punctuation\">:<\/span> PersistentVolumeClaim<br \/>\n    <span class=\"token key atrule\">max<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">storage<\/span><span class=\"token punctuation\">:<\/span> 2Gi<br \/>\n    <span class=\"token key atrule\">min<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">storage<\/span><span class=\"token punctuation\">:<\/span> 1Gi<\/p>\n<h3>\u73af\u5883\u6e05\u7406<\/h3>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl delete ns quota<\/span><\/p>\n<h2>Kubernetes Health Check<\/h2>\n<p>\u5b66\u4e60\u53c2\u8003&#xff1a;\u914d\u7f6e\u5b58\u6d3b\u3001\u5c31\u7eea\u548c\u542f\u52a8\u63a2\u9488<\/p>\n<h3>\u73af\u5883\u51c6\u5907<\/h3>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create ns health<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl config set-context &#8211;current &#8211;namespace health<\/span><\/p>\n<h3>Health Check<\/h3>\n<p>\u5e94\u7528\u53ef\u80fd\u4f1a\u56e0\u4e3a\u5404\u79cd\u95ee\u9898&#xff0c;\u53d8\u7684 unhealthy&#xff0c;\u4f8b\u5982\u4e34\u65f6\u8fde\u63a5\u65ad\u5f00&#xff0c;\u914d\u7f6e\u9519\u8bef&#xff0c;\u5e94\u7528\u672c\u8eab\u9519\u8bef\u3002<\/p>\n<p>kubelet \u4f7f\u7528 probes&#xff08;\u63a2\u9488&#xff09;&#xff0c;\u5468\u671f\u6027\u5730\u76d1\u63a7\u5bb9\u5668\u4e2d\u5e94\u7528\u662f\u5426\u4e3ahealthy\u72b6\u6001&#xff0c;\u8fdb\u4e00\u6b65\u51b3\u5b9a\u4ec0\u4e48\u65f6\u5019\u8981\u91cd\u542f\u5bb9\u5668\u3002 \u4f8b\u5982&#xff0c;\u5f53\u5b58\u6d3b\u63a2\u9488\u53ef\u4ee5\u63a2\u6d4b\u5230\u5e94\u7528\u6b7b\u9501&#xff08;\u5e94\u7528\u5728\u8fd0\u884c&#xff0c;\u4f46\u662f\u65e0\u6cd5\u7ee7\u7eed\u6267\u884c\u540e\u9762\u7684\u6b65\u9aa4&#xff09;\u60c5\u51b5&#xff0c;\u8fdb\u800c\u91cd\u542fpod&#xff0c;\u6709\u52a9\u4e8e\u63d0\u9ad8\u5e94\u7528\u7684\u53ef\u7528\u6027&#xff0c;\u5373\u4f7f\u5176\u4e2d\u5b58\u5728\u7f3a\u9677\u3002<\/p>\n<p>\u6ca1\u6709\u63a2\u6d4b\u7684\u60c5\u51b5&#xff0c;\u770b\u4e00\u4e2a\u4f8b\u5b50&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u521b\u5efa\u4e00\u4e2a\u666e\u901a pod<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl run web &#8211;image&#061;hub.laoma.cloud\/library\/httpd &#8211;image-pull-policy&#061;IfNotPresent<\/span><br \/>\n<span class=\"token punctuation\">[<\/span>root&#064;laoma20 health<span class=\"token punctuation\">]<\/span><span class=\"token comment\"># kubectl describe pod web|grep &#039;^IP:&#039;<\/span><br \/>\nIP:           <span class=\"token number\">10.224<\/span>.73.16<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># curl 10.224.73.16<\/span><br \/>\n<span class=\"token operator\">&lt;<\/span>html<span class=\"token operator\">&gt;<\/span><span class=\"token operator\">&lt;<\/span>body<span class=\"token operator\">&gt;<\/span><span class=\"token operator\">&lt;<\/span>h<span class=\"token operator\"><span class=\"token file-descriptor important\">1<\/span>&gt;<\/span>It works<span class=\"token operator\">!<\/span><span class=\"token operator\">&lt;<\/span>\/h<span class=\"token operator\"><span class=\"token file-descriptor important\">1<\/span>&gt;<\/span><span class=\"token operator\">&lt;<\/span>\/body<span class=\"token operator\">&gt;<\/span><span class=\"token operator\">&lt;<\/span>\/html<span class=\"token operator\">&gt;<\/span><\/p>\n<p><span class=\"token comment\"># \u5220\u9664\u4e3b\u9875\u6587\u4ef6&#xff0c;\u5373\u4f7fpod\u4e2d\u5e94\u7528\u6570\u636e\u4e22\u5931&#xff0c;pod\u72b6\u6001\u4f9d\u7136\u4e3aRunning<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl exec web &#8212; rm -f htdocs\/index.html<\/span><\/p>\n<p><span class=\"token comment\"># \u67e5\u770b\u4e3b\u9875\u5185\u5bb9<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># curl 10.224.73.16<\/span><br \/>\n<span class=\"token operator\">&lt;<\/span><span class=\"token operator\">!<\/span>DOCTYPE HTML PUBLIC <span class=\"token string\">&#034;-\/\/W3C\/\/DTD HTML 3.2 Final\/\/EN&#034;<\/span><span class=\"token operator\">&gt;<\/span><br \/>\n<span class=\"token operator\">&lt;<\/span>html<span class=\"token operator\">&gt;<\/span><br \/>\n <span class=\"token operator\">&lt;<\/span>head<span class=\"token operator\">&gt;<\/span><br \/>\n  <span class=\"token operator\">&lt;<\/span>title<span class=\"token operator\">&gt;<\/span>Index of \/<span class=\"token operator\">&lt;<\/span>\/title<span class=\"token operator\">&gt;<\/span><br \/>\n <span class=\"token operator\">&lt;<\/span>\/head<span class=\"token operator\">&gt;<\/span><br \/>\n <span class=\"token operator\">&lt;<\/span>body<span class=\"token operator\">&gt;<\/span><br \/>\n<span class=\"token operator\">&lt;<\/span>h<span class=\"token operator\"><span class=\"token file-descriptor important\">1<\/span>&gt;<\/span>Index of \/<span class=\"token operator\">&lt;<\/span>\/h<span class=\"token operator\"><span class=\"token file-descriptor important\">1<\/span>&gt;<\/span><br \/>\n<span class=\"token operator\">&lt;<\/span>ul<span class=\"token operator\">&gt;<\/span><span class=\"token operator\">&lt;<\/span>\/ul<span class=\"token operator\">&gt;<\/span><br \/>\n<span class=\"token operator\">&lt;<\/span>\/body<span class=\"token operator\">&gt;<\/span><span class=\"token operator\">&lt;<\/span>\/html<span class=\"token operator\">&gt;<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pod<\/span><br \/>\nNAME   READY   STATUS    RESTARTS   AGE<br \/>\nweb    <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          51s<\/p>\n<p><span class=\"token comment\"># \u6e05\u7406\u73af\u5883<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete pod web &#8211;force<\/span><\/p>\n<h3>Probe Type<\/h3>\n<p>kubelet \u4f7f\u7528\u542f\u52a8\u63a2\u9488\u6765\u4e86\u89e3\u5e94\u7528\u5bb9\u5668\u4f55\u65f6\u542f\u52a8\u3002 \u5982\u679c\u914d\u7f6e\u4e86\u8fd9\u7c7b\u63a2\u9488&#xff0c;\u5b58\u6d3b\u63a2\u9488\u548c\u5c31\u7eea\u63a2\u9488\u6210\u529f\u4e4b\u524d\u4e0d\u4f1a\u91cd\u542f&#xff0c;\u786e\u4fdd\u8fd9\u4e9b\u63a2\u9488\u4e0d\u4f1a\u5f71\u54cd\u5e94\u7528\u7684\u542f\u52a8\u3002 \u542f\u52a8\u63a2\u9488\u53ef\u4ee5\u7528\u4e8e\u5bf9\u6162\u542f\u52a8\u5bb9\u5668\u8fdb\u884c\u5b58\u6d3b\u6027\u68c0\u6d4b&#xff0c;\u907f\u514d\u5b83\u4eec\u5728\u542f\u52a8\u8fd0\u884c\u4e4b\u524d\u5c31\u88ab\u6740\u6389\u3002<\/p>\n<ul>\n<li>\n<p>LivenessProbe&#xff1a;\u7528\u4e8e\u786e\u5b9apod\u4e2d\u5e94\u7528\u662f\u5426\u5904\u4e8ehealthy\u72b6\u6001\u3002\u5982\u679cliveness probe\u68c0\u6d4b\u7684\u72b6\u6001\u4e3aunhealthy&#xff0c;\u5219\u63a7\u5236\u5668\u5c06\u91cd\u65b0\u542f\u52a8pod\u3002<\/p>\n<\/li>\n<li>\n<p>ReadinessProbe&#xff1a;\u7528\u4e8e\u786e\u5b9apod\u4e2d\u5e94\u7528\u662f\u5426\u53ef\u4ee5\u63d0\u4f9b\u670d\u52a1\u3002\u5982\u679c\u8fd4\u56de\u5931\u8d25\u72b6\u6001&#xff0c;\u5219**\u670d\u52a1\u5c06\u4eceendpoints \u4e2d\u5220\u9664\u5bb9\u5668ip\u5730\u5740\u3002**\u5373\u4f7f\u5bb9\u5668\u5904\u4e8e\u8fd0\u884c\u72b6\u6001&#xff0c;\u4e5f\u4e0d\u63a5\u53d7\u4ee3\u7406\u53d1\u8fc7\u6765\u7684\u8bf7\u6c42\u3002<\/p>\n<\/li>\n<li>\n<p>StartupProbe&#xff1a;\u7528\u4e8e\u786e\u5b9apod\u662f\u5426\u6210\u529f\u521d\u59cb\u5316\u3002 \u5982\u679c\u6307\u5b9a&#xff0c;\u5219\u5728\u6210\u529f\u5b8c\u6210\u4e4b\u524d\u4e0d\u4f1a\u6267\u884c\u5176\u4ed6\u63a2\u6d4b\u3002\u5982\u679c\u6b64\u63a2\u6d4b\u5931\u8d25&#xff0c;Pod \u5c06\u91cd\u65b0\u542f\u52a8&#xff0c;\u5c31\u50cf livenessProbe \u5931\u8d25\u4e00\u6837\u3002 \u8fd9\u53ef\u7528\u4e8e\u5728 Pod \u751f\u547d\u5468\u671f\u5f00\u59cb\u65f6\u63d0\u4f9b\u4e0d\u540c\u7684\u63a2\u6d4b\u53c2\u6570&#xff0c;\u6b64\u65f6\u52a0\u8f7d\u6570\u636e\u6216\u9884\u70ed\u7f13\u5b58\u53ef\u80fd\u9700\u8981\u6bd4\u7a33\u6001\u64cd\u4f5c\u671f\u95f4\u66f4\u957f\u7684\u65f6\u95f4\u3002 \u8fd9\u65e0\u6cd5\u66f4\u65b0\u3002<\/p>\n<\/li>\n<\/ul>\n<p>\u6211\u4eec\u8fd9\u91cc\u4e0d\u6df1\u5165\u8ba8\u8bbaStartupProbe\u3002<\/p>\n<h3>Checking Methods<\/h3>\n<p>\u63a2\u9488\u68c0\u67e5\u5bb9\u5668\u6709\u56db\u79cd\u4e0d\u540c\u7684\u65b9\u6cd5&#xff1a;<\/p>\n<ul>\n<li>httpGet&#xff0c;\u5bf9\u5bb9\u5668\u7684 IP \u5730\u5740\u4e0a\u6307\u5b9a\u7aef\u53e3\u548c\u8def\u5f84\u6267\u884c HTTP GET \u8bf7\u6c42\u3002\u5982\u679c\u54cd\u5e94\u7684\u72b6\u6001\u7801\u5927\u4e8e\u7b49\u4e8e 200 \u4e14\u5c0f\u4e8e 400&#xff0c;\u5219\u8bca\u65ad\u88ab\u8ba4\u4e3a\u662f\u6210\u529f\u7684\u3002<\/li>\n<li>exec&#xff0c;\u5728\u5bb9\u5668\u5185\u6267\u884c\u6307\u5b9a\u547d\u4ee4\u3002\u5982\u679c\u547d\u4ee4\u9000\u51fa\u65f6\u8fd4\u56de\u7801\u4e3a 0&#xff0c;\u5219\u8ba4\u4e3a\u8bca\u65ad\u6210\u529f\u3002<\/li>\n<li>tcpSocket&#xff0c;\u5bf9\u5bb9\u5668\u7684 IP \u5730\u5740\u4e0a\u7684\u6307\u5b9a\u7aef\u53e3\u6267\u884c TCP \u68c0\u67e5\u3002\u5982\u679c\u7aef\u53e3\u6253\u5f00&#xff0c;\u5219\u8bca\u65ad\u88ab\u8ba4\u4e3a\u662f\u6210\u529f\u7684\u3002 \u5982\u679c\u8fdc\u7a0b\u7cfb\u7edf&#xff08;\u5bb9\u5668&#xff09;\u5728\u6253\u5f00\u8fde\u63a5\u540e\u7acb\u5373\u5c06\u5176\u5173\u95ed&#xff0c;\u8fd9\u7b97\u4f5c\u662f\u5065\u5eb7\u7684\u3002<\/li>\n<li>grpc&#xff0c;\u4f7f\u7528 gRPC \u6267\u884c\u4e00\u4e2a\u8fdc\u7a0b\u8fc7\u7a0b\u8c03\u7528\u3002 \u76ee\u6807\u5e94\u8be5\u5b9e\u73b0 gRPC \u5065\u5eb7\u68c0\u67e5\u3002 \u5982\u679c\u54cd\u5e94\u7684\u72b6\u6001\u662f \u201cSERVING\u201d&#xff0c;\u5219\u8ba4\u4e3a\u8bca\u65ad\u6210\u529f\u3002<\/li>\n<\/ul>\n<p>\u6211\u4eec\u8fd9\u91cc\u4e0d\u8ba8\u8bba grpc \u65b9\u6cd5\u3002<\/p>\n<h4>HTTP Checks-httpGet<\/h4>\n<p>\u5f53\u4f7f\u7528HTTP Checks&#xff0c;\u63a7\u5236\u5668\u4f7f\u7528webhoook\u5224\u5b9a\u5bb9\u5668\u5065\u5eb7\u60c5\u51b5\u3002\u5982\u679cHTTP\u7684\u54cd\u5e94\u7801\u5728200-399\u4e4b\u95f4&#xff0c;\u5224\u5b9acheck\u6210\u529f\u3002\u9002\u5e94\u8303\u56f4&#xff1a;\u53ef\u4ee5\u8fd4\u56deHTTP\u72b6\u6001\u7801\u5e94\u7528\u3002<\/p>\n<h5>livenessProbe<\/h5>\n<p>root&#064;master30:~<span class=\"token comment\"># vim deploy-httpGet-liveness.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> apps\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Deployment<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">replicas<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n  <span class=\"token key atrule\">selector<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">matchLabels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">template<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/httpd<br \/>\n        <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n        <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> httpd<br \/>\n        <span class=\"token comment\"># \u6dfb\u52a0livenessProbe\u90e8\u5206<\/span><br \/>\n        <span class=\"token key atrule\">livenessProbe<\/span><span class=\"token punctuation\">:<\/span><br \/>\n          <span class=\"token key atrule\">failureThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">3<\/span><br \/>\n          <span class=\"token key atrule\">initialDelaySeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n          <span class=\"token key atrule\">periodSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n          <span class=\"token key atrule\">successThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n          <span class=\"token key atrule\">timeoutSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">10<\/span><br \/>\n          <span class=\"token key atrule\">httpGet<\/span><span class=\"token punctuation\">:<\/span><br \/>\n            <span class=\"token key atrule\">path<\/span><span class=\"token punctuation\">:<\/span> \/index.html<br \/>\n            <span class=\"token comment\"># port\u586b\u5199\u65f6\u95f4web\u7aef\u53e3<\/span><br \/>\n            <span class=\"token key atrule\">port<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">80<\/span><br \/>\n            <span class=\"token comment\"># scheme\u6307\u5b9a\u534f\u8bae&#xff0c;HTTP\u6216\u8005HTTPS<\/span><br \/>\n            <span class=\"token key atrule\">scheme<\/span><span class=\"token punctuation\">:<\/span> HTTP<\/p>\n<p>probe\u9009\u9879\u8bf4\u660e&#xff1a;<\/p>\n<ul>\n<li>initialDelaySeconds&#xff1a;\u5fc5\u9009\u3002\u5bb9\u5668\u542f\u52a8\u540e\u591a\u957f\u65f6\u95f4&#xff0c;probe\u5f00\u59cb\u751f\u6548\u3002<\/li>\n<li>timeoutSeconds&#xff1a;\u5fc5\u9009\u3002probe\u9700\u8981\u591a\u957f\u65f6\u95f4\u5b8c\u6210\u3002\u5982\u679c\u8d85\u8fc7\u8be5\u503c&#xff0c;\u63a7\u5236\u5668\u5224\u5b9aprobe\u5931\u8d25\u3002\u9ed8\u8ba4\u503c1s&#xff0c;\u6700\u5c0f\u503c\u662f1\u79d2\u3002<\/li>\n<li>periodSeconds&#xff1a;\u53ef\u9009\u3002\u68c0\u67e5\u9891\u7387\u3002\u9ed8\u8ba4\u503c10s&#xff0c;\u6700\u5c0f\u503c\u662f1\u79d2\u3002<\/li>\n<li>successThreshold&#xff1a;\u53ef\u9009&#xff0c;\u8fde\u7eed\u6210\u529f\u6700\u5c11\u6b21\u6570\u540e\u5224\u5b9aprobe\u6210\u529f\u3002\u9ed8\u8ba4\u503c1&#xff0c;\u6700\u5c0f\u503c\u662f1\u3002<\/li>\n<li>failureThreshold&#xff1a;\u53ef\u9009\u3002\u8fde\u7eed\u5931\u8d25\u6700\u5c11\u6b21\u6570\u540e\u5224\u5b9aprobe\u5931\u8d25\u3002\u9ed8\u8ba4\u503c3&#xff0c;\u6700\u5c0f\u503c\u662f1\u3002<\/li>\n<\/ul>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl apply -f deploy-httpGet-liveness.yaml<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pod<\/span><br \/>\nNAME                   READY   STATUS    RESTARTS   AGE<br \/>\nweb-85c6ff748f-qwszz   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          12m<br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl describe pod web-85c6ff748f-j92jn|grep &#039;^IP:&#039;<\/span><br \/>\nIP:           <span class=\"token number\">10.98<\/span>.146.216<\/p>\n<p><span class=\"token comment\"># \u5220\u9664\u4e3b\u9875\u6587\u4ef6<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl exec web-85c6ff748f-qwszz &#8212; bash -c &#039;rm htdocs\/index.html&#039;<\/span><\/p>\n<p><span class=\"token comment\"># \u89c2\u5bdfpod\u72b6\u6001&#xff0c;RESTARTS\u6b21\u6570\u53d8\u4f4d1&#xff0c;\u518d\u6b21\u8bbf\u95ee<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pod<\/span><br \/>\nNAME                   READY   STATUS    RESTARTS   AGE<br \/>\nweb-85c6ff748f-qwszz   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">1<\/span>          13m<\/p>\n<p><span class=\"token comment\"># \u5bb9\u5668\u5220\u9664\u9700\u8981\u4e00\u4e9b\u65f6\u95f4&#xff0c;\u7531\u53c2\u6570terminationGracePeriodSeconds\u8bbe\u5b9a&#xff0c;\u9ed8\u8ba4\u503c\u4e3a30s\u3002<\/span><br \/>\n<span class=\"token comment\"># \u53ea\u6709\u7b49\u5bb9\u5668\u5220\u9664&#xff0c;\u5e76\u521b\u5efa\u5b8c\u6210\u540e\u624d\u4f1a\u7ee7\u7eed\u68c0\u6d4b<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># curl 10.98.146.216<\/span><br \/>\n<span class=\"token operator\">&lt;<\/span>html<span class=\"token operator\">&gt;<\/span><span class=\"token operator\">&lt;<\/span>body<span class=\"token operator\">&gt;<\/span><span class=\"token operator\">&lt;<\/span>h<span class=\"token operator\"><span class=\"token file-descriptor important\">1<\/span>&gt;<\/span>It works<span class=\"token operator\">!<\/span><span class=\"token operator\">&lt;<\/span>\/h<span class=\"token operator\"><span class=\"token file-descriptor important\">1<\/span>&gt;<\/span><span class=\"token operator\">&lt;<\/span>\/body<span class=\"token operator\">&gt;<\/span><span class=\"token operator\">&lt;<\/span>\/html<span class=\"token operator\">&gt;<\/span><\/p>\n<p><span class=\"token comment\"># \u6e05\u7406\u73af\u5883<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete deployments.apps web<\/span><\/p>\n<h5>readinessProbe<\/h5>\n<p>root&#064;master30:~<span class=\"token comment\"># vim deploy-httpGet-readiness.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> apps\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Deployment<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">replicas<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">3<\/span><br \/>\n  <span class=\"token key atrule\">selector<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">matchLabels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">template<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/httpd<br \/>\n        <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n        <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> httpd<br \/>\n        <span class=\"token comment\"># \u6dfb\u52a0readinessProbe\u90e8\u5206<\/span><br \/>\n        <span class=\"token key atrule\">readinessProbe<\/span><span class=\"token punctuation\">:<\/span><br \/>\n          <span class=\"token key atrule\">failureThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">3<\/span><br \/>\n          <span class=\"token key atrule\">initialDelaySeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n          <span class=\"token key atrule\">periodSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n          <span class=\"token key atrule\">successThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n          <span class=\"token key atrule\">timeoutSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">10<\/span><br \/>\n          <span class=\"token key atrule\">httpGet<\/span><span class=\"token punctuation\">:<\/span><br \/>\n            <span class=\"token key atrule\">path<\/span><span class=\"token punctuation\">:<\/span> \/index.html<br \/>\n            <span class=\"token key atrule\">port<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">80<\/span><br \/>\n            <span class=\"token key atrule\">scheme<\/span><span class=\"token punctuation\">:<\/span> HTTP<\/p>\n<p><span class=\"token comment\"># \u521b\u5efa\u5e94\u7528<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl apply -f deploy-httpGet-readiness.yaml<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl expose deployment web &#8211;port&#061;80 &#8211;target-port&#061;80<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get svc<\/span><br \/>\nNAME   TYPE        CLUSTER-IP     EXTERNAL-IP   PORT<span class=\"token punctuation\">(<\/span>S<span class=\"token punctuation\">)<\/span>   AGE<br \/>\nweb    ClusterIP   <span class=\"token number\">10.98<\/span>.146.216   <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span>        <span class=\"token number\">80<\/span>\/TCP    4m5s<br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pod<\/span><br \/>\nNAME                  READY   STATUS    RESTARTS   AGE<br \/>\nweb-9479dc55c-6bpg7   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          2m34s<br \/>\nweb-9479dc55c-d2gbn   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          2m34s<br \/>\nweb-9479dc55c-hqh8q   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          2m34s<\/p>\n<p><span class=\"token comment\"># \u51c6\u59073\u4e2apod\u4e3b\u9875\u6587\u4ef6<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># for pod in $(kubectl get pods -o name|awk -F \/ &#039;{print $2}&#039;); do kubectl exec $pod &#8212; bash -c &#034;echo $pod &gt; htdocs\/index.html&#034;; done<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># for i in {1..90};do curl -s 10.96.180.30;done|sort |uniq -c<\/span><br \/>\n     <span class=\"token number\">24<\/span> web-9479dc55c-6bpg7<br \/>\n     <span class=\"token number\">33<\/span> web-9479dc55c-d2gbn<br \/>\n     <span class=\"token number\">33<\/span> web-9479dc55c-hqh8q<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl get endpoints web<\/span><br \/>\nNAME   ENDPOINTS                                         AGE<br \/>\nweb    <span class=\"token number\">10.224<\/span>.73.15:80,10.224.73.34:80,10.224.73.35:80   21m<\/p>\n<p><span class=\"token comment\"># \u5220\u9664 web-9479dc55c-6bpg7\u4e3b\u9875\u6587\u4ef6<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl exec -it web-9479dc55c-6bpg7 &#8212; rm -f htdocs\/index.html<\/span><\/p>\n<p><span class=\"token comment\"># web \u670d\u52a1\u7684\u540e\u7aef\u6ca1\u6709pod\u7684ip<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get endpoints web<\/span><br \/>\nNAME   ENDPOINTS                         AGE<br \/>\nweb    <span class=\"token number\">10.224<\/span>.73.15:80,10.224.73.34:80   23m<\/p>\n<p><span class=\"token comment\"># \u8bbf\u95eesvc&#xff0c;\u540e\u7aef\u65e0\u6cd5\u770b\u5230 web-9479dc55c-6bpg7<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># for i in {1..90};do curl -s 10.96.180.30;done|sort |uniq -c<\/span><br \/>\n     <span class=\"token number\">50<\/span> web2<br \/>\n     <span class=\"token number\">40<\/span> web3<\/p>\n<p><span class=\"token comment\"># \u89c2\u5bdfweb1\u72b6\u6001&#xff0c;READY\u4e3a0&#xff0c;RESTARTS\u6570\u91cf\u4e3a0<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pod<\/span><br \/>\nNAME                  READY   STATUS    RESTARTS   AGE<br \/>\nweb-9479dc55c-6bpg7   <span class=\"token number\">0<\/span>\/1     Running   <span class=\"token number\">0<\/span>          8m49s<br \/>\nweb-9479dc55c-d2gbn   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          8m49s<br \/>\nweb-9479dc55c-hqh8q   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          8m49s<\/p>\n<p><span class=\"token comment\"># \u6e05\u7406\u73af\u5883<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete deployments.apps web<\/span><\/p>\n<h4>Execution Checks-exec<\/h4>\n<p>\u5f53\u4f7f\u7528\u5bb9\u5668\u6267\u884c\u68c0\u6d4b&#xff0c;kubelet\u4ee3\u7406\u5c06\u5728\u5bb9\u5668\u5185\u6267\u884c\u547d\u4ee4\u3002\u8fd4\u56de\u503c\u662f0&#xff0c;\u4ee3\u8868check\u6210\u529f\u3002<\/p>\n<p>\u793a\u4f8b1&#xff1a;\u68c0\u6d4b\u5bb9\u5668\u81ea\u5e26\u6587\u4ef6<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim deploy-exec-liveness.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> apps\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Deployment<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">replicas<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n  <span class=\"token key atrule\">selector<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">matchLabels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">template<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/httpd<br \/>\n        <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n        <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> httpd<br \/>\n        <span class=\"token comment\"># \u6dfb\u52a0livenessProbe\u90e8\u5206<\/span><br \/>\n        <span class=\"token key atrule\">livenessProbe<\/span><span class=\"token punctuation\">:<\/span><br \/>\n          <span class=\"token key atrule\">failureThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">3<\/span><br \/>\n          <span class=\"token key atrule\">initialDelaySeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n          <span class=\"token key atrule\">periodSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n          <span class=\"token key atrule\">successThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n          <span class=\"token key atrule\">timeoutSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">10<\/span><br \/>\n          <span class=\"token key atrule\">exec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n            <span class=\"token key atrule\">command<\/span><span class=\"token punctuation\">:<\/span><br \/>\n            <span class=\"token punctuation\">&#8211;<\/span> cat<br \/>\n            <span class=\"token punctuation\">&#8211;<\/span> \/usr\/local\/apache2\/htdocs\/index.html<\/p>\n<p><span class=\"token comment\"># \u521b\u5efa\u5e94\u7528<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl apply -f deploy-exec-liveness.yaml<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pods<\/span><br \/>\nNAME                  READY   STATUS    RESTARTS     AGE<br \/>\nweb-8c9ff9b76-nm6s2   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">1<\/span> <span class=\"token punctuation\">(<\/span>2s ago<span class=\"token punctuation\">)<\/span>   18s<\/p>\n<p><span class=\"token comment\"># \u5220\u9664\u4e3b\u9875\u6587\u4ef6<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl exec web-8c9ff9b76-nm6s2 &#8212; bash -c &#039;rm htdocs\/index.html&#039;<\/span><\/p>\n<p><span class=\"token comment\"># \u89c2\u5bdfpod\u72b6\u6001&#xff0c;RESTARTS\u6b21\u6570\u53d8\u4f4d1<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl get pod<\/span><br \/>\nNAME   READY   STATUS    RESTARTS   AGE<br \/>\nweb    <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">1<\/span>          4m5s<\/p>\n<p>\u793a\u4f8b2&#xff1a;\u68c0\u6d4b\u81ea\u5b9a\u4e49\u6587\u4ef6<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl run busybox &#8211;image&#061;busybox &#8211;image-pull-policy&#061;IfNotPresent -o yaml &#8211;dry-run&#061;client &gt; busybox.yml<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># vim deploy-exec-busybox.yml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Pod<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">creationTimestamp<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token null important\">null<\/span><br \/>\n  <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">run<\/span><span class=\"token punctuation\">:<\/span> busybox<br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> busybox<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> busybox<br \/>\n    <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n    <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> busybox<\/p>\n<p>    <span class=\"token comment\"># \u6dfb\u52a0args\u53c2\u6570<\/span><br \/>\n    <span class=\"token key atrule\">args<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token punctuation\">&#8211;<\/span> \/bin\/sh<br \/>\n    <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token punctuation\">&#8211;<\/span>c<br \/>\n    <span class=\"token punctuation\">&#8211;<\/span> touch \/tmp\/healthy; sleep 10; rm <span class=\"token punctuation\">&#8211;<\/span>rf \/tmp\/healthy; sleep 100<\/p>\n<p>    <span class=\"token comment\">#\u6dfb\u52a0livenessProbe\u53c2\u6570<\/span><br \/>\n    <span class=\"token key atrule\">livenessProbe<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">failureThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">3<\/span><br \/>\n      <span class=\"token key atrule\">initialDelaySeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n      <span class=\"token key atrule\">periodSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n      <span class=\"token key atrule\">successThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n      <span class=\"token key atrule\">timeoutSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">10<\/span><br \/>\n      <span class=\"token key atrule\">exec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">command<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token punctuation\">&#8211;<\/span> ls<br \/>\n        <span class=\"token punctuation\">&#8211;<\/span> \/tmp\/healthy<br \/>\n  <span class=\"token key atrule\">dnsPolicy<\/span><span class=\"token punctuation\">:<\/span> ClusterFirst<br \/>\n  <span class=\"token key atrule\">restartPolicy<\/span><span class=\"token punctuation\">:<\/span> Always<\/p>\n<h4>TCP Socket Checks-tcpSocket<\/h4>\n<p>\u5f53\u4f7f\u7528TCP socket checks&#xff0c;kubelet\u4ee3\u7406\u5c1d\u8bd5\u6253\u5f00\u5bb9\u5668socket\u3002\u5982\u679ccheck\u53ef\u4ee5\u5efa\u7acb\u8fde\u63a5&#xff0c;\u5224\u5b9acheck\u6210\u529f\u3002<\/p>\n<p>\u793a\u4f8b&#xff1a;liveness probe\u4f7f\u7528TCP Socket check<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># vim deploy-tcpSocket-liveness.yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> apps\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Deployment<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n<span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">replicas<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n  <span class=\"token key atrule\">selector<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">matchLabels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n  <span class=\"token key atrule\">template<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">labels<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token key atrule\">app<\/span><span class=\"token punctuation\">:<\/span> web<br \/>\n    <span class=\"token key atrule\">spec<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token key atrule\">containers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> hub.laoma.cloud\/library\/httpd<br \/>\n        <span class=\"token key atrule\">imagePullPolicy<\/span><span class=\"token punctuation\">:<\/span> IfNotPresent<br \/>\n        <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> httpd<br \/>\n        <span class=\"token comment\"># \u6dfb\u52a0livenessProbe\u90e8\u5206<\/span><br \/>\n        <span class=\"token key atrule\">livenessProbe<\/span><span class=\"token punctuation\">:<\/span><br \/>\n          <span class=\"token key atrule\">failureThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">3<\/span><br \/>\n          <span class=\"token key atrule\">initialDelaySeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n          <span class=\"token key atrule\">periodSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5<\/span><br \/>\n          <span class=\"token key atrule\">successThreshold<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">1<\/span><br \/>\n          <span class=\"token key atrule\">timeoutSeconds<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">10<\/span><br \/>\n          <span class=\"token key atrule\">tcpSocket<\/span><span class=\"token punctuation\">:<\/span><br \/>\n            <span class=\"token key atrule\">port<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">80<\/span><\/p>\n<h3>Health Check Case<\/h3>\n<h4>Health Check \u5728 Scale Up \u4e2d\u7684\u5e94\u7528<\/h4>\n<p>\u5bf9\u4e8e\u591a\u526f\u672c\u5e94\u7528&#xff0c; \u5f53\u6267\u884cScale Up\u64cd\u4f5c\u65f6&#xff0c; \u65b0\u526f\u672c\u4f1a\u4f5c\u4e3abackend\u88ab\u6dfb\u52a0\u5230Service\u7684\u8d1f\u8f7d\u5747\u8861\u4e2d&#xff0c; \u4e0e\u5df2\u6709\u526f\u672c\u4e00\u8d77\u5904\u7406\u5ba2\u6237\u7684\u8bf7\u6c42\u3002\u8003\u8651\u5230\u5e94\u7528\u542f\u52a8\u901a\u5e38\u90fd\u9700\u8981\u4e00\u4e2a\u51c6\u5907\u9636\u6bb5&#xff0c; \u6bd4\u5982\u52a0\u8f7d\u7f13\u5b58\u6570\u636e\u3001 \u8fde\u63a5\u6570\u636e\u5e93\u7b49&#xff0c; \u4ece\u5bb9\u5668\u542f\u52a8\u5230\u771f\u6b63\u80fd\u591f\u63d0\u4f9b\u670d\u52a1\u662f\u9700\u8981\u4e00\u6bb5\u65f6\u95f4\u7684\u3002 \u6211\u4eec\u53ef\u4ee5\u901a\u8fc7Readiness\u63a2\u6d4b\u5224\u65ad\u5bb9\u5668\u662f\u5426\u5c31\u7eea&#xff0c; \u907f\u514d\u5c06\u8bf7\u6c42\u53d1\u9001\u5230\u8fd8\u6ca1\u6709\u51c6\u5907\u597d\u7684backend\u3002<\/p>\n<h4>Health Check \u5728\u6eda\u52a8\u66f4\u65b0\u4e2d\u7684\u5e94\u7528<\/h4>\n<p>Health Check\u53e6\u4e00\u4e2a\u91cd\u8981\u7684\u5e94\u7528\u573a\u666f\u662fRolling Update\u3002 \u8bd5\u60f3\u4e00\u4e0b&#xff0c; \u73b0\u6709\u4e00\u4e2a\u6b63\u5e38\u8fd0\u884c\u7684\u591a\u526f\u672c\u5e94\u7528&#xff0c; \u63a5\u4e0b\u6765\u5bf9\u5e94\u7528\u8fdb\u884c\u66f4\u65b0&#xff08;\u6bd4\u5982\u4f7f\u7528\u66f4\u9ad8\u7248\u672c\u7684image&#xff09; &#xff0c; Kubernetes\u4f1a\u542f\u52a8\u65b0\u526f\u672c&#xff0c; \u7136\u540e\u53d1\u751f\u4e86\u5982\u4e0b\u4e8b\u4ef6&#xff1a;<\/p>\n<li>\u6b63\u5e38\u60c5\u51b5\u4e0b\u65b0\u526f\u672c\u9700\u898110\u79d2\u949f\u5b8c\u6210\u51c6\u5907\u5de5\u4f5c&#xff0c; \u5728\u6b64\u4e4b\u524d\u65e0\u6cd5\u54cd\u5e94\u4e1a\u52a1\u8bf7\u6c42\u3002<\/li>\n<li>\u7531\u4e8e\u4eba\u4e3a\u914d\u7f6e\u9519\u8bef&#xff0c; \u526f\u672c\u59cb\u7ec8\u65e0\u6cd5\u5b8c\u6210\u51c6\u5907\u5de5\u4f5c&#xff08;\u6bd4\u5982\u65e0\u6cd5\u8fde\u63a5\u540e\u7aef\u6570\u636e\u5e93&#xff09;\u3002<\/li>\n<h4>\u5982\u679c\u6ca1\u6709\u914d\u7f6eHealth Check&#xff0c; \u4f1a\u51fa\u73b0\u600e\u6837\u7684\u60c5\u51b5&#xff1f;<\/h4>\n<p>\u56e0\u4e3a\u65b0\u526f\u672c\u672c\u8eab\u6ca1\u6709\u5f02\u5e38\u9000\u51fa&#xff0c; \u9ed8\u8ba4\u7684Health Check\u673a\u5236\u4f1a\u8ba4\u4e3a\u5bb9\u5668\u5df2\u7ecf\u5c31\u7eea&#xff0c; \u8fdb\u800c\u4f1a\u9010\u6b65\u7528\u65b0\u526f\u672c\u66ff\u6362\u73b0\u6709\u526f\u672c&#xff0c; \u5176\u7ed3\u679c\u5c31\u662f&#xff1a; \u5f53\u6240\u6709\u65e7\u526f\u672c\u90fd\u88ab\u66ff\u6362\u540e&#xff0c; \u6574\u4e2a\u5e94\u7528\u5c06\u65e0\u6cd5\u5904\u7406\u8bf7\u6c42&#xff0c; \u65e0\u6cd5\u5bf9\u5916\u63d0\u4f9b\u670d\u52a1\u3002 \u5982\u679c\u8fd9\u662f\u53d1\u751f\u5728\u91cd\u8981\u7684\u751f\u4ea7\u7cfb\u7edf\u4e0a&#xff0c; \u540e\u679c\u4f1a\u975e\u5e38\u4e25\u91cd\u3002<\/p>\n<p>\u5982\u679c\u6b63\u786e\u914d\u7f6e\u4e86Health Check&#xff0c; \u65b0\u526f\u672c\u53ea\u6709\u901a\u8fc7\u4e86\u63a2\u6d4b\u624d\u4f1a\u88ab\u6dfb\u52a0\u5230Service&#xff1b; \u5982\u679c\u6ca1\u6709\u901a\u8fc7\u63a2\u6d4b&#xff0c; \u73b0\u6709\u526f\u672c\u4e0d\u4f1a\u88ab\u5168\u90e8\u66ff\u6362&#xff0c; \u4e1a\u52a1\u4ecd\u7136\u6b63\u5e38\u8fdb\u884c\u3002<\/p>\n<h3>\u73af\u5883\u6e05\u7406<\/h3>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl delete ns health<\/span><\/p>\n<h2>Kubernetes \u8ba4\u8bc1\u548c\u6388\u6743<\/h2>\n<p>\u5b66\u4e60\u53c2\u8003&#xff1a;API \u8bbf\u95ee\u63a7\u5236<\/p>\n<h3>\u73af\u5883\u51c6\u5907<\/h3>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create ns auth<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl config set-context &#8211;current &#8211;namespace auth<\/span><\/p>\n<h3>Kubernetes API \u8bbf\u95ee\u63a7\u5236<\/h3>\n<p>\u5b66\u4e60\u53c2\u8003&#xff1a;Kubernetes API \u8bbf\u95ee\u63a7\u5236<\/p>\n<p>\u5f53\u7528\u6237\u4f7f\u7528User \u6216 \u670d\u52a1\u8d26\u53f7\u8bbf\u95eeKubernetes API\u65f6&#xff0c;\u6bcf\u4e2a\u8bf7\u6c42\u90fd\u4f1a\u7ecf\u8fc7\u591a\u9636\u6bb5\u7684\u8bbf\u95ee\u63a7\u5236\u4e4b\u540e\u624d\u4f1a\u88ab\u63a5\u53d7&#xff0c;\u5305\u62ec\u8eab\u4efd\u8ba4\u8bc1\u3001\u9274\u6743\u4ee5\u53ca\u51c6\u5165\u63a7\u5236&#xff08;Admission Control&#xff09;\u3002<\/p>\n<p>\u5982\u4e0b\u56fe\u6240\u793a&#xff1a;<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260826084030-6a8ea67e04d06.svg\" \/> <\/p>\n<h4>\u4f20\u8f93\u5b89\u5168<\/h4>\n<p>\u9ed8\u8ba4\u60c5\u51b5\u4e0b&#xff0c;Kubernetes API \u670d\u52a1\u5668\u5728\u7b2c\u4e00\u4e2a\u975e localhost \u7f51\u7edc\u63a5\u53e3\u7684 6443 \u7aef\u53e3\u4e0a\u8fdb\u884c\u76d1\u542c&#xff0c; \u53d7 TLS \u4fdd\u62a4\u3002\u5728\u4e00\u4e2a\u5178\u578b\u7684 Kubernetes \u751f\u4ea7\u96c6\u7fa4\u4e2d&#xff0c;API \u4f7f\u7528 443 \u7aef\u53e3\u3002 \u8be5\u7aef\u53e3\u53ef\u4ee5\u901a\u8fc7 &#8211;secure-port \u8fdb\u884c\u53d8\u66f4&#xff0c;\u76d1\u542c IP \u5730\u5740\u53ef\u4ee5\u901a\u8fc7 &#8211;bind-address \u6807\u5fd7\u8fdb\u884c\u53d8\u66f4\u3002<\/p>\n<p>\u5ba2\u6237\u7aef\u5411 Kubernetes API \u670d\u52a1\u5668\u53d1\u8d77\u8bf7\u6c42\u65f6&#xff0c;**API \u670d\u52a1\u5668\u51fa\u793a\u8bc1\u4e66\u3002**\u8be5\u8bc1\u4e66\u53ef\u4ee5\u4f7f\u7528\u79c1\u6709\u8bc1\u4e66\u9881\u53d1\u673a\u6784&#xff08;CA&#xff09;\u7b7e\u540d&#xff0c;\u4e5f\u53ef\u4ee5\u57fa\u4e8e\u94fe\u63a5\u5230\u516c\u8ba4\u7684 CA \u7684\u516c\u94a5\u57fa\u7840\u67b6\u6784\u7b7e\u540d\u3002 \u8be5\u8bc1\u4e66\u548c\u76f8\u5e94\u7684\u79c1\u94a5\u53ef\u4ee5\u901a\u8fc7\u4f7f\u7528 &#8211;tls-cert-file \u548c &#8211;tls-private-key-file \u6807\u5fd7\u8fdb\u884c\u8bbe\u7f6e\u3002<\/p>\n<p>\u5982\u679c\u4f60\u7684\u96c6\u7fa4\u4f7f\u7528\u79c1\u6709\u8bc1\u4e66\u9881\u53d1\u673a\u6784&#xff0c;\u4f60\u9700\u8981\u5728\u5ba2\u6237\u7aef\u7684 ~\/.kube\/config \u6587\u4ef6\u4e2d\u63d0\u4f9b\u8be5 CA \u8bc1\u4e66\u7684\u526f\u672c&#xff0c; \u4ee5\u4fbf\u4f60\u53ef\u4ee5\u4fe1\u4efb\u8be5\u8fde\u63a5\u5e76\u786e\u8ba4\u8be5\u8fde\u63a5\u6ca1\u6709\u88ab\u62e6\u622a\u3002<\/p>\n<h4>\u8eab\u4efd\u8ba4\u8bc1<\/h4>\n<p>\u5982\u4e0a\u56fe\u6b65\u9aa4 \u2460 \u6240\u793a&#xff1a;Kubernetes \u64cd\u4f5c\u524d\u9996\u5148\u8fdb\u884c\u8eab\u4efd\u8ba4\u8bc1&#xff08;Authentication&#xff09;\u3002<\/p>\n<p>Kubernetes \u4f7f\u7528\u8ba4\u8bc1\u6a21\u5757\u8fdb\u884c\u8ba4\u8bc1&#xff0c;\u8ba4\u8bc1\u6a21\u5757\u5305\u542b\u5ba2\u6237\u7aef\u8bc1\u4e66\u3001\u5bc6\u7801\u3001\u666e\u901a\u4ee4\u724c\u3001\u5f15\u5bfc\u4ee4\u724c\u548c JSON Web \u4ee4\u724c&#xff08;JWT&#xff0c;\u7528\u4e8e\u670d\u52a1\u8d26\u53f7&#xff09;\u7b49\u3002\u5982\u679c Kubernetes \u6307\u5b9a\u591a\u4e2a\u8ba4\u8bc1\u6a21\u5757&#xff0c;\u670d\u52a1\u5668\u4f9d\u6b21\u5c1d\u8bd5\u6bcf\u4e2a\u9a8c\u8bc1\u6a21\u5757&#xff0c;\u76f4\u5230\u5176\u4e2d\u4e00\u4e2a\u6210\u529f\u3002<\/p>\n<ul>\n<li>\u5982\u679c\u8bf7\u6c42\u8ba4\u8bc1\u901a\u8fc7&#xff0c;\u4e0b\u4e00\u6b65\u5bf9\u8be5\u7528\u6237\u540d\u8fdb\u884c\u9274\u6743\u3002<\/li>\n<li>\u5982\u679c\u8bf7\u6c42\u8ba4\u8bc1\u4e0d\u901a\u8fc7&#xff0c;\u670d\u52a1\u5668\u5c06\u4ee5 HTTP \u72b6\u6001\u7801 401 \u62d2\u7edd\u8be5\u8bf7\u6c42\u3002<\/li>\n<\/ul>\n<p>\u8eab\u4efd\u8ba4\u8bc1\u7ec4\u4ef6\u5728\u8ba4\u8bc1\u8282\u4e2d\u6709\u66f4\u8be6\u7ec6\u7684\u63cf\u8ff0\u3002<\/p>\n<h4>\u9274\u6743<\/h4>\n<p>\u5982\u4e0a\u56fe\u7684\u6b65\u9aa4 \u2461 \u6240\u793a&#xff0c;\u5c06\u8bf7\u6c42\u9a8c\u8bc1\u4e3a\u6765\u81ea\u7279\u5b9a\u7684\u7528\u6237\u540e&#xff0c;\u8bf7\u6c42\u5fc5\u987b\u88ab\u9274\u6743&#xff08;Authorization&#xff09;\u3002\u8bf7\u6c42\u5fc5\u987b\u5305\u542b\u8bf7\u6c42\u8005\u7684\u7528\u6237\u540d\u3001\u8bf7\u6c42\u7684\u884c\u4e3a\u4ee5\u53ca\u53d7\u8be5\u64cd\u4f5c\u5f71\u54cd\u7684\u5bf9\u8c61\u3002 \u5982\u679c\u73b0\u6709\u7b56\u7565\u58f0\u660e\u7528\u6237\u6709\u6743\u5b8c\u6210\u8bf7\u6c42\u7684\u64cd\u4f5c&#xff0c;\u90a3\u4e48\u8be5\u8bf7\u6c42\u88ab\u9274\u6743\u901a\u8fc7\u3002<\/p>\n<p>\u793a\u4f8b&#xff1a; \u4ee5\u4e0b\u7b56\u7565&#xff0c;Bob \u53ea\u80fd\u5728 projectCaribou \u540d\u79f0\u7a7a\u95f4\u4e2d\u8bfb\u53d6 Pod\u3002<\/p>\n<p><span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token string-property property\">&#034;apiVersion&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;abac.authorization.kubernetes.io\/v1beta1&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n    <span class=\"token string-property property\">&#034;kind&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;Policy&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n    <span class=\"token string-property property\">&#034;spec&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token string-property property\">&#034;user&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;bob&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n        <span class=\"token string-property property\">&#034;namespace&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;projectCaribou&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n        <span class=\"token string-property property\">&#034;resource&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;pods&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n        <span class=\"token string-property property\">&#034;readonly&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token boolean\">true<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<ul>\n<li>\u5982\u679c Bob \u6267\u884c\u4ee5\u4e0b\u8bf7\u6c42&#xff1a;\u8bfb\u53d6 projectCaribou \u540d\u79f0\u7a7a\u95f4\u4e2d\u7684\u5bf9\u8c61\u6e05\u5355&#xff0c;\u5176\u9274\u6743\u8bf7\u6c42\u5c06\u88ab\u5141\u8bb8\u3002<\/li>\n<\/ul>\n<p><span class=\"token punctuation\">{<\/span><br \/>\n  <span class=\"token string-property property\">&#034;apiVersion&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;authorization.k8s.io\/v1beta1&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n  <span class=\"token string-property property\">&#034;kind&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;SubjectAccessReview&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n  <span class=\"token string-property property\">&#034;spec&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token string-property property\">&#034;resourceAttributes&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n      <span class=\"token string-property property\">&#034;namespace&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;projectCaribou&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n      <span class=\"token string-property property\">&#034;verb&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;get&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n      <span class=\"token string-property property\">&#034;group&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;unicorn.example.org&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n      <span class=\"token string-property property\">&#034;resource&#034;<\/span><span class=\"token operator\">:<\/span> <span class=\"token string\">&#034;pods&#034;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n  <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<ul>\n<li>\u5982\u679c Bob \u5728 projectCaribou \u540d\u5b57\u7a7a\u95f4\u4e2d\u8bf7\u6c42\u5199&#xff08;create \u6216 update&#xff09;\u5bf9\u8c61\u6216\u5728\u5176\u5b83\u540d\u5b57\u7a7a\u95f4\u4e2d\u8bf7\u6c42\u8bfb\u53d6&#xff08;get&#xff09;\u5bf9\u8c61&#xff0c;\u5176\u9274\u6743\u8bf7\u6c42\u4f1a\u88ab\u62d2\u7edd\u3002<\/li>\n<\/ul>\n<p>**\u6ce8\u610f&#xff1a;**Kubernetes \u9274\u6743\u8981\u6c42\u4f7f\u7528\u516c\u5171 REST \u5c5e\u6027\u4e0e\u73b0\u6709\u7684\u7ec4\u7ec7\u8303\u56f4\u6216\u4e91\u63d0\u4f9b\u5546\u8303\u56f4\u7684\u8bbf\u95ee\u63a7\u5236\u7cfb\u7edf\u8fdb\u884c\u4ea4\u4e92\u3002 \u4f7f\u7528 REST \u683c\u5f0f\u5f88\u91cd\u8981&#xff0c;\u56e0\u4e3a\u8fd9\u4e9b\u63a7\u5236\u7cfb\u7edf\u53ef\u80fd\u4f1a\u4e0e Kubernetes API \u4e4b\u5916\u7684 API \u4ea4\u4e92\u3002<\/p>\n<p>Kubernetes \u652f\u6301\u591a\u79cd\u9274\u6743\u6a21\u5757&#xff0c;\u4f8b\u5982 ABAC \u6a21\u5f0f\u3001RBAC \u6a21\u5f0f\u548c Webhook \u6a21\u5f0f\u7b49\u3002 \u7ba1\u7406\u5458\u521b\u5efa\u96c6\u7fa4\u65f6&#xff0c;\u4ed6\u4eec\u914d\u7f6e\u5e94\u5728 API \u670d\u52a1\u5668\u4e2d\u4f7f\u7528\u7684\u9274\u6743\u6a21\u5757\u3002 \u5982\u679c\u914d\u7f6e\u4e86\u591a\u4e2a\u9274\u6743\u6a21\u5757&#xff0c;\u5219 Kubernetes \u4f1a\u68c0\u67e5\u6bcf\u4e2a\u6a21\u5757&#xff0c;\u4efb\u610f\u4e00\u4e2a\u6a21\u5757\u9274\u6743\u8be5\u8bf7\u6c42&#xff0c;\u8bf7\u6c42\u5373\u53ef\u7ee7\u7eed&#xff1b; \u5982\u679c\u6240\u6709\u6a21\u5757\u62d2\u7edd\u4e86\u8be5\u8bf7\u6c42&#xff0c;\u8bf7\u6c42\u5c06\u4f1a\u88ab\u62d2\u7edd&#xff08;HTTP \u72b6\u6001\u7801 403&#xff09;\u3002<\/p>\n<p>\u8981\u4e86\u89e3\u66f4\u591a\u6709\u5173 Kubernetes \u9274\u6743\u7684\u66f4\u591a\u4fe1\u606f&#xff0c;\u5305\u62ec\u6709\u5173\u4f7f\u7528\u652f\u6301\u9274\u6743\u6a21\u5757\u521b\u5efa\u7b56\u7565\u7684\u8be6\u7ec6\u4fe1\u606f&#xff0c; \u8bf7\u53c2\u9605\u9274\u6743\u3002<\/p>\n<h4>\u51c6\u5165\u63a7\u5236<\/h4>\n<p>\u8fd9\u4e00\u64cd\u4f5c\u5982\u4e0a\u56fe\u7684\u6b65\u9aa4 \u2462 \u6240\u793a\u3002<\/p>\n<ul>\n<li>\n<p>\u51c6\u5165\u63a7\u5236\u5668\u5bf9\u521b\u5efa\u3001\u4fee\u6539\u3001\u5220\u9664\u6216&#xff08;\u901a\u8fc7\u4ee3\u7406&#xff09;\u8fde\u63a5\u5bf9\u8c61\u7684\u8bf7\u6c42\u8fdb\u884c\u64cd\u4f5c\u3002 \u5f53\u6709\u591a\u4e2a\u51c6\u5165\u63a7\u5236\u5668\u88ab\u914d\u7f6e\u65f6&#xff0c;\u670d\u52a1\u5668\u5c06\u4f9d\u6b21\u8c03\u7528\u5b83\u4eec\u3002\u51c6\u5165\u63a7\u5236\u5668\u4e0d\u4f1a\u5bf9\u4ec5\u8bfb\u53d6\u5bf9\u8c61\u7684\u8bf7\u6c42\u8d77\u4f5c\u7528\u3002\u51c6\u5165\u63a7\u5236\u6a21\u5757\u662f\u53ef\u4ee5\u4fee\u6539\u6216\u62d2\u7edd\u8bf7\u6c42\u7684\u8f6f\u4ef6\u6a21\u5757\u3002 \u9664\u9274\u6743\u6a21\u5757\u53ef\u7528\u7684\u5c5e\u6027\u5916&#xff0c;\u51c6\u5165\u63a7\u5236\u6a21\u5757\u8fd8\u53ef\u4ee5\u8bbf\u95ee\u6b63\u5728\u521b\u5efa\u6216\u4fee\u6539\u7684\u5bf9\u8c61\u7684\u5185\u5bb9\u3002<\/p>\n<\/li>\n<li>\n<p>\u4e0e\u8eab\u4efd\u8ba4\u8bc1\u548c\u9274\u6743\u6a21\u5757\u4e0d\u540c&#xff0c;\u5982\u679c\u4efb\u4f55\u51c6\u5165\u63a7\u5236\u5668\u6a21\u5757\u62d2\u7edd\u67d0\u8bf7\u6c42&#xff0c;\u5219\u8be5\u8bf7\u6c42\u5c06\u7acb\u5373\u88ab\u62d2\u7edd\u3002\u9664\u4e86\u62d2\u7edd\u5bf9\u8c61\u4e4b\u5916&#xff0c;\u51c6\u5165\u63a7\u5236\u5668\u8fd8\u53ef\u4ee5\u4e3a\u5b57\u6bb5\u8bbe\u7f6e\u590d\u6742\u7684\u9ed8\u8ba4\u503c\u3002<\/p>\n<\/li>\n<li>\n<p>\u8bf7\u6c42\u901a\u8fc7\u6240\u6709\u51c6\u5165\u63a7\u5236\u5668\u540e&#xff0c;\u5c06\u4f7f\u7528\u68c0\u9a8c\u4f8b\u7a0b\u68c0\u67e5\u5bf9\u5e94\u7684 API \u5bf9\u8c61&#xff0c;\u7136\u540e\u5c06\u5176\u5199\u5165\u5bf9\u8c61\u5b58\u50a8&#xff08;\u5982\u6b65\u9aa4 4 \u6240\u793a&#xff09;\u3002<\/p>\n<\/li>\n<\/ul>\n<p>\u53ef\u7528\u7684\u51c6\u5165\u63a7\u5236\u6a21\u5757\u53c2\u8003 \u51c6\u5165\u63a7\u5236\u5668\u3002<\/p>\n<h4>\u5ba1\u8ba1<\/h4>\n<p>Kubernetes \u5ba1\u8ba1\u63d0\u4f9b\u4e86\u4e00\u5957\u4e0e\u5b89\u5168\u76f8\u5173\u7684\u3001\u6309\u65f6\u95f4\u987a\u5e8f\u6392\u5217\u7684\u8bb0\u5f55&#xff0c;\u5176\u4e2d\u8bb0\u5f55\u4e86\u96c6\u7fa4\u4e2d\u7684\u64cd\u4f5c\u5e8f\u5217\u3002 \u96c6\u7fa4\u5bf9\u7528\u6237\u3001\u4f7f\u7528 Kubernetes API \u7684\u5e94\u7528\u7a0b\u5e8f\u4ee5\u53ca\u63a7\u5236\u5e73\u9762\u672c\u8eab\u4ea7\u751f\u7684\u6d3b\u52a8\u8fdb\u884c\u5ba1\u8ba1\u3002<\/p>\n<p>\u66f4\u591a\u4fe1\u606f\u8bf7\u53c2\u8003 \u5ba1\u8ba1\u3002<\/p>\n<h3>\u8ba4\u8bc1\u7ba1\u7406<\/h3>\n<p>\u5b66\u4e60\u53c2\u8003&#xff1a;\u8ba4\u8bc1<\/p>\n<h4>Kubernetes \u4e2d\u7684\u7528\u6237<\/h4>\n<p>Kubernetes \u96c6\u7fa4\u6709\u4e24\u7c7b\u7528\u6237&#xff1a;<\/p>\n<ul>\n<li>\u666e\u901a\u7528\u6237&#xff0c;Kubernetes \u4e2d\u666e\u901a\u7528\u6237\u4e0d\u662f\u7531 kubernetes \u76f4\u63a5\u63d0\u4f9b&#xff0c;\u800c\u662f\u8eab\u4efd\u8ba4\u8bc1\u63d2\u4ef6\u63d0\u4f9b&#xff0c;Kubernetes \u5e76\u4e0d\u5305\u542b\u7528\u6765\u4ee3\u8868\u666e\u901a\u7528\u6237\u8d26\u53f7\u7684\u5bf9\u8c61\u3002 \u666e\u901a\u7528\u6237\u7684\u4fe1\u606f\u65e0\u6cd5\u901a\u8fc7 API \u8c03\u7528\u6dfb\u52a0\u5230\u96c6\u7fa4\u4e2d&#xff0c;Kubernetes \u8ba4\u4e3a&#xff1a;\u80fd\u591f\u63d0\u4f9b\u7531\u96c6\u7fa4\u7684\u8bc1\u4e66\u673a\u6784\u7b7e\u540d\u7684\u5408\u6cd5\u8bc1\u4e66\u7684\u7528\u6237\u662f\u901a\u8fc7\u8eab\u4efd\u8ba4\u8bc1\u7684\u7528\u6237\u3002 \u57fa\u4e8e\u8fd9\u6837\u7684\u673a\u5236&#xff0c;Kubernetes \u4f7f\u7528\u8bc1\u4e66\u4e2d\u7684 \u2018subject\u2019 \u7684\u901a\u7528\u540d\u79f0&#xff08;Common Name&#xff09;\u5b57\u6bb5 &#xff08;\u4f8b\u5982&#xff0c;\u201c\/CN&#061;bob\u201d&#xff09;\u6765\u786e\u5b9a\u7528\u6237\u540d\u3002 \u63a5\u4e0b\u6765&#xff0c;\u57fa\u4e8e\u89d2\u8272\u8bbf\u95ee\u63a7\u5236&#xff08;RBAC&#xff09;\u5b50\u7cfb\u7edf\u4f1a\u786e\u5b9a\u7528\u6237\u662f\u5426\u6709\u6743\u9488\u5bf9\u67d0\u8d44\u6e90\u6267\u884c\u7279\u5b9a\u7684\u64cd\u4f5c\u3002<\/li>\n<li>\u670d\u52a1\u8d26\u53f7&#xff0c;Kubernetes \u4e2d\u670d\u52a1\u8d26\u53f7\u662f Kubernetes API \u6240\u7ba1\u7406\u7684\u7528\u6237\u3002\u5b83\u4eec\u88ab\u7ed1\u5b9a\u5230\u7279\u5b9a\u7684\u540d\u5b57\u7a7a\u95f4&#xff0c; \u6216\u8005\u7531 API \u670d\u52a1\u5668\u81ea\u52a8\u521b\u5efa&#xff0c;\u6216\u8005\u901a\u8fc7 API \u8c03\u7528\u521b\u5efa\u3002\u670d\u52a1\u8d26\u53f7\u4e0e\u4e00\u7ec4\u4ee5 Secret \u4fdd\u5b58\u7684\u51ed\u636e\u76f8\u5173&#xff0c;\u8fd9\u4e9b\u51ed\u636e\u4f1a\u88ab\u6302\u8f7d\u5230 Pod \u4e2d&#xff0c;\u4ece\u800c\u5141\u8bb8\u96c6\u7fa4\u5185\u7684\u8fdb\u7a0b\u8bbf\u95ee Kubernetes API\u3002<\/li>\n<\/ul>\n<p>\u6bcf\u4e2a API \u8bf7\u6c42\u5fc5\u987b\u5305\u542b\u4e00\u4e2a\u7528\u6237&#xff1a;\u666e\u901a\u7528\u6237\u76f8\u5173\u6216\u8005\u670d\u52a1\u8d26\u53f7&#xff0c;\u5ba2\u6237\u7aef\u4e5f\u53ef\u4ee5\u53d1\u8d77\u533f\u540d\u8bf7\u6c42\u3002\u8fd9\u610f\u5473\u7740\u96c6\u7fa4\u5185\u5916\u7684\u6bcf\u4e2a\u8fdb\u7a0b\u5728\u5411 API \u670d\u52a1\u5668\u53d1\u8d77\u8bf7\u6c42\u65f6\u90fd\u5fc5\u987b\u901a\u8fc7\u8eab\u4efd\u8ba4\u8bc1&#xff0c;\u5426\u5219\u4f1a\u88ab\u89c6\u4f5c\u533f\u540d\u7528\u6237\u3002<\/p>\n<h4>\u8eab\u4efd\u8ba4\u8bc1\u7b56\u7565<\/h4>\n<p>Kubernetes \u901a\u8fc7\u8eab\u4efd\u8ba4\u8bc1\u63d2\u4ef6\u8ba4\u8bc1 API \u8bf7\u6c42\u7684\u8eab\u4efd\u3002HTTP \u8bf7\u6c42\u53d1\u7ed9 API \u670d\u52a1\u5668\u65f6&#xff0c;\u63d2\u4ef6\u4f1a\u5c06\u4ee5\u4e0b\u5c5e\u6027\u5173\u8054\u5230\u8bf7\u6c42\u672c\u8eab&#xff1a;<\/p>\n<ul>\n<li>\u7528\u6237\u540d&#xff1a;\u7528\u6765\u8fa9\u8bc6\u6700\u7ec8\u7528\u6237\u7684\u5b57\u7b26\u4e32\u3002\u5e38\u89c1\u7684\u503c\u53ef\u4ee5\u662f kube-admin \u6216 jane&#064;example.com\u3002<\/li>\n<li>\u7528\u6237 ID&#xff1a;\u7528\u6765\u8fa9\u8bc6\u6700\u7ec8\u7528\u6237\u7684\u5b57\u7b26\u4e32&#xff0c;\u65e8\u5728\u6bd4\u7528\u6237\u540d\u6709\u66f4\u597d\u7684\u4e00\u81f4\u6027\u548c\u552f\u4e00\u6027\u3002<\/li>\n<li>\u7528\u6237\u7ec4&#xff1a;\u53d6\u503c\u4e3a\u4e00\u7ec4\u5b57\u7b26\u4e32&#xff0c;\u5176\u4e2d\u5404\u4e2a\u5b57\u7b26\u4e32\u7528\u6765\u6807\u660e\u7528\u6237\u662f\u67d0\u4e2a\u547d\u540d\u7684\u7528\u6237\u903b\u8f91\u96c6\u5408\u7684\u6210\u5458\u3002 \u5e38\u89c1\u7684\u503c\u53ef\u80fd\u662f system:masters \u6216\u8005 devops-team \u7b49\u3002<\/li>\n<li>\u9644\u52a0\u5b57\u6bb5&#xff1a;\u4e00\u7ec4\u989d\u5916\u7684\u952e-\u503c\u6620\u5c04&#xff0c;\u952e\u662f\u5b57\u7b26\u4e32&#xff0c;\u503c\u662f\u4e00\u7ec4\u5b57\u7b26\u4e32&#xff1b; \u7528\u6765\u4fdd\u5b58\u4e00\u4e9b\u9274\u6743\u7ec4\u4ef6\u53ef\u80fd\u89c9\u5f97\u6709\u7528\u7684\u989d\u5916\u4fe1\u606f\u3002<\/li>\n<\/ul>\n<p>\u6240\u6709&#xff08;\u5c5e\u6027&#xff09;\u503c\u5bf9\u4e8e\u8eab\u4efd\u8ba4\u8bc1\u7cfb\u7edf\u800c\u8a00\u90fd\u662f\u4e0d\u900f\u660e\u7684&#xff0c; \u53ea\u6709\u88ab\u9274\u6743\u7ec4\u4ef6\u89e3\u91ca\u8fc7\u4e4b\u540e\u624d\u6709\u610f\u4e49\u3002<\/p>\n<p>\u53ef\u4ee5\u540c\u65f6\u542f\u7528\u591a\u79cd\u8eab\u4efd\u8ba4\u8bc1\u65b9\u6cd5&#xff0c;\u901a\u5e38\u81f3\u5c11\u4f7f\u7528\u4e24\u79cd\u65b9\u6cd5&#xff1a;<\/p>\n<ul>\n<li>\u9488\u5bf9\u670d\u52a1\u8d26\u53f7\u4f7f\u7528\u670d\u52a1\u8d26\u53f7\u4ee4\u724c\u3002<\/li>\n<li>\u81f3\u5c11\u53e6\u5916\u4e00\u79cd\u65b9\u6cd5\u5bf9\u7528\u6237\u7684\u8eab\u4efd\u8fdb\u884c\u8ba4\u8bc1&#xff0c;\u4f8b\u5982X509\u5ba2\u6237\u8bc1\u4e66\u3002<\/li>\n<\/ul>\n<p>Kubernetes \u9ed8\u8ba4\u4f7f\u7528\u7684\u662f\u670d\u52a1\u8d26\u53f7\u548cX509\u5ba2\u6237\u8bc1\u4e66\u3002\u672c\u8bfe\u7a0b\u6df1\u5165\u63a2\u8ba8\u4ee5\u4e0a\u4e24\u79cd\u65b9\u6cd5\u3002<\/p>\n<h4>\u8ba4\u8bc1\u63d2\u4ef6<\/h4>\n<p>Kubernetes\u652f\u6301\u540c\u65f6\u5f00\u542f\u591a\u4e2a\u8ba4\u8bc1\u63d2\u4ef6&#xff0c;\u53ea\u8981\u6709\u4e00\u4e2a\u8ba4\u8bc1\u901a\u8fc7\u5373\u53ef\u3002\u5982\u679c\u8ba4\u8bc1\u6210\u529f&#xff0c;\u5219\u7528\u6237\u7684username\u4f1a\u88ab\u4f20\u5165\u9274\u6743\u6a21\u5757\u505a\u8fdb\u4e00\u6b65\u9274\u6743\u9a8c\u8bc1&#xff1b;\u800c\u5bf9\u4e8e\u8ba4\u8bc1\u5931\u8d25\u7684\u8bf7\u6c42\u5219\u8fd4\u56deHTTP 401\u3002<\/p>\n<p>\u5e38\u7528\u8ba4\u8bc1\u63d2\u4ef6&#xff1a;<\/p>\n<ul>\n<li>\n<p>X509 \u5ba2\u6237\u8bc1\u4e66<\/p>\n<ul>\n<li>\n<p>\u5ba2\u6237\u7aef\u7528\u6237\u4e0eKubernetes\u4ea4\u4e92\u65f6\u5019&#xff0c;\u4f7f\u7528\u7684\u8ba4\u8bc1\u51ed\u636e\u6587\u4ef6.kube\/config\u5c31\u662f\u4f7f\u7528X509\u8bc1\u4e66\u3002<\/p>\n<\/li>\n<li>\n<p>API Server\u542f\u52a8\u65f6\u914d\u7f6e \u2013client-ca-file&#061;SOMEFILE \u53c2\u6570\u3002<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>root&#064;master30:~<span class=\"token comment\"># cat \/etc\/kubernetes\/manifests\/kube-apiserver.yaml |\\\\<\/span><br \/>\n<span class=\"token function\">grep<\/span> &#8212; &#8211;client-ca-file<br \/>\n    &#8211; &#8211;client-ca-file<span class=\"token operator\">&#061;<\/span>\/etc\/kubernetes\/pki\/ca.crt<\/p>\n<ul>\n<li>\n<p>\u9759\u6001\u4ee4\u724c\u6587\u4ef6<\/p>\n<ul>\n<li>API Server\u542f\u52a8\u65f6\u914d\u7f6e \u2013token-auth-file&#061;SOMEFILE \u53c2\u6570\u3002\u9ed8\u8ba4\u672a\u542f\u7528\u3002<\/li>\n<li>\u6587\u4ef6\u4e3a csv\u683c\u5f0f&#xff0c;\u6bcf\u884c\u81f3\u5c11\u5305\u62ec\u4e09\u5217 token,username,user id\u3002\u7b2c\u56db\u5217\u4e3a\u53ef\u9009group \u540d\u9879\u3002\u5982\u679c\u6709\u591a\u4e2agroup\u540d&#xff0c;\u5217\u5fc5\u987b\u7528\u201d\u201d\u53cc\u5f15\u53f7\u5305\u542b\u5176\u4e2d&#xff0c;\u4f8b\u5982&#xff1a;token,user,uid,&#034;group1,group2,group3&#034;<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>\u542f\u52a8\u5f15\u5bfc\u4ee4\u724c<\/p>\n<ul>\n<li>\u4e3a\u4e86\u652f\u6301\u5e73\u6ed1\u5730\u542f\u52a8\u5f15\u5bfc\u65b0\u7684\u96c6\u7fa4&#xff0c;Kubernetes \u5305\u542b\u4e86\u4e00\u79cd\u52a8\u6001\u7ba1\u7406\u7684\u6301\u6709\u8005\u4ee4\u724c\u7c7b\u578b&#xff0c; \u79f0\u4f5c \u542f\u52a8\u5f15\u5bfc\u4ee4\u724c&#xff08;Bootstrap Token&#xff09;\u3002 \u8fd9\u4e9b\u4ee4\u724c\u4ee5 Secret \u7684\u5f62\u5f0f\u4fdd\u5b58\u5728 kube-system \u540d\u5b57\u7a7a\u95f4\u4e2d&#xff0c;\u53ef\u4ee5\u88ab\u52a8\u6001\u7ba1\u7406\u548c\u521b\u5efa\u3002 \u4f7f\u7528 kubeadm \u5f15\u5bfc\u548c\u7ba1\u7406\u96c6\u7fa4\u65f6&#xff0c;kubeadm \u4f1a\u81ea\u52a8\u5b8c\u6210\u8fd9\u4e9b\u8bbe\u7f6e\u3002<\/li>\n<li>\u4f60\u5fc5\u987b\u5728 API \u670d\u52a1\u5668\u4e0a\u8bbe\u7f6e &#8211;enable-bootstrap-token-auth \u6807\u5fd7\u6765\u542f\u7528\u57fa\u4e8e\u542f\u52a8\u5f15\u5bfc\u4ee4\u724c\u7684\u8eab\u4efd\u8ba4\u8bc1\u7ec4\u4ef6\u3002<\/li>\n<li>\u8bf7\u53c2\u9605\u542f\u52a8\u5f15\u5bfc\u4ee4\u724c&#xff0c; \u4ee5\u4e86\u89e3\u5173\u4e8e\u542f\u52a8\u5f15\u5bfc\u4ee4\u724c\u8eab\u4efd\u8ba4\u8bc1\u7ec4\u4ef6\u8be6\u7ec6\u4fe1\u606f\u3002<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>\u670d\u52a1\u8d26\u53f7\u4ee4\u724c<\/p>\n<ul>\n<li>\n<p>\u670d\u52a1\u8d26\u53f7&#xff08;Service Account&#xff09;\u662f\u4e00\u79cd\u81ea\u52a8\u88ab\u542f\u7528\u7684\u7528\u6237\u8ba4\u8bc1\u673a\u5236&#xff0c;\u4f7f\u7528\u7ecf\u8fc7\u7b7e\u540d\u7684\u6301\u6709\u8005\u4ee4\u724c\u6765\u9a8c\u8bc1\u8bf7\u6c42\u3002<\/p>\n<\/li>\n<li>\n<p>\u670d\u52a1\u8d26\u53f7\u901a\u5e38\u7531 API \u670d\u52a1\u5668\u81ea\u52a8\u521b\u5efa\u5e76\u901a\u8fc7 ServiceAccount \u51c6\u5165\u63a7\u5236\u5668\u5173\u8054\u5230\u96c6\u7fa4\u4e2d\u8fd0\u884c\u7684 Pod \u4e0a\u3002 \u6301\u6709\u8005\u4ee4\u724c\u4f1a\u6302\u8f7d\u5230 Pod \u4e2d\u53ef\u9884\u77e5\u7684\u4f4d\u7f6e&#xff0c;\u5141\u8bb8\u96c6\u7fa4\u5185\u8fdb\u7a0b\u4e0e API \u670d\u52a1\u5668\u901a\u4fe1\u3002<\/p>\n<\/li>\n<li>\n<p>\u670d\u52a1\u8d26\u53f7\u4e5f\u53ef\u4ee5\u4f7f\u7528 Pod \u89c4\u7ea6\u7684 serviceAccountName \u5b57\u6bb5\u663e\u5f0f\u5730\u5173\u8054\u5230 Pod \u4e0a\u3002<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>Webhook \u4ee4\u724c\u8eab\u4efd\u8ba4\u8bc1<\/p>\n<p>Webhook \u8eab\u4efd\u8ba4\u8bc1\u662f\u4e00\u79cd\u7528\u6765\u9a8c\u8bc1\u6301\u6709\u8005\u4ee4\u724c\u7684\u56de\u8c03\u673a\u5236\u3002<\/p>\n<\/li>\n<li>\n<p>\u8eab\u4efd\u8ba4\u8bc1\u4ee3\u7406<\/p>\n<p>API \u670d\u52a1\u5668\u53ef\u4ee5\u914d\u7f6e\u6210\u4ece\u8bf7\u6c42\u7684\u5934\u90e8\u5b57\u6bb5\u503c&#xff08;\u5982 X-Remote-User&#xff09;\u4e2d\u8fa9\u8bc6\u7528\u6237\u3002 \u8fd9\u4e00\u8bbe\u8ba1\u662f\u7528\u6765\u4e0e\u67d0\u8eab\u4efd\u8ba4\u8bc1\u4ee3\u7406\u4e00\u8d77\u4f7f\u7528 API \u670d\u52a1\u5668&#xff0c;\u4ee3\u7406\u8d1f\u8d23\u8bbe\u7f6e\u8bf7\u6c42\u7684\u5934\u90e8\u5b57\u6bb5\u503c\u3002<\/p>\n<\/li>\n<li>\n<p>basic-auth-file\u8ba4\u8bc1<\/p>\n<p>\u5728kubernetes 1.19\u53ca\u4e4b\u540e\u7684\u7248\u672c\u4e2d&#xff0c;kubernetes\u653e\u5f03\u4e86 basic-auth-file \u8ba4\u8bc1\u65b9\u5f0f\u3002<\/p>\n<\/li>\n<\/ul>\n<h4>\u533f\u540d\u8bf7\u6c42<\/h4>\n<p>\u5982\u679c\u8bf7\u6c42\u6ca1\u6709\u88ab\u5df2\u914d\u7f6e\u7684\u8eab\u4efd\u8ba4\u8bc1\u65b9\u6cd5\u62d2\u7edd&#xff0c; \u5219\u88ab\u89c6\u4f5c\u533f\u540d\u8bf7\u6c42&#xff08;Anonymous Requests&#xff09;\u3002\u8fd9\u7c7b\u8bf7\u6c42\u83b7\u5f97\u7528\u6237\u540d system:anonymous \u548c\u5bf9\u5e94\u7684\u7528\u6237\u7ec4 system:unauthenticated\u3002<\/p>\n<ul>\n<li>\n<p>\u5728 1.5.1-1.5.x \u7248\u672c\u4e2d&#xff0c;\u533f\u540d\u8bbf\u95ee\u9ed8\u8ba4\u60c5\u51b5\u4e0b\u662f\u88ab\u7981\u7528\u7684&#xff0c;\u53ef\u4ee5\u901a\u8fc7\u4e3a API \u670d\u52a1\u5668\u8bbe\u5b9a &#8211;anonymous-auth&#061;true \u6765\u542f\u7528\u3002<\/p>\n<\/li>\n<li>\n<p>\u5728 1.6 \u53ca\u4e4b\u540e\u7248\u672c\u4e2d&#xff0c;\u5982\u679c\u6240\u4f7f\u7528\u7684\u9274\u6743\u6a21\u5f0f\u4e0d\u662f AlwaysAllow&#xff0c;\u5219\u533f\u540d\u8bbf\u95ee\u9ed8\u8ba4\u662f\u88ab\u542f\u7528\u7684\u3002 \u4ece 1.6 \u7248\u672c\u5f00\u59cb&#xff0c;ABAC \u548c RBAC \u9274\u6743\u6a21\u5757\u8981\u6c42\u5bf9 system:anonymous \u7528\u6237\u6216\u8005 system:unauthenticated \u7528\u6237\u7ec4\u6267\u884c\u663e\u5f0f\u7684\u6743\u9650\u5224\u5b9a&#xff0c;\u6240\u4ee5\u4e4b\u524d\u7684\u4e3a\u7528\u6237 * \u6216\u7528\u6237\u7ec4 * \u8d4b\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7b56\u7565\u89c4\u5219\u90fd\u4e0d\u518d\u5305\u542b\u533f\u540d\u7528\u6237\u3002<\/p>\n<\/li>\n<\/ul>\n<p>**\u4f8b\u5982&#xff0c;**\u5728\u4e00\u4e2a\u914d\u7f6e\u4e86\u4ee4\u724c\u8eab\u4efd\u8ba4\u8bc1\u4e14\u542f\u7528\u4e86\u533f\u540d\u8bbf\u95ee\u7684\u670d\u52a1\u5668\u4e0a&#xff0c;\u5982\u679c\u8bf7\u6c42\u63d0\u4f9b\u4e86\u975e\u6cd5\u7684\u6301\u6709\u8005\u4ee4\u724c&#xff0c; \u5219\u4f1a\u8fd4\u56de 401 Unauthorized \u9519\u8bef\u3002\u5982\u679c\u8bf7\u6c42\u6ca1\u6709\u63d0\u4f9b\u6301\u6709\u8005\u4ee4\u724c&#xff0c;\u5219\u88ab\u89c6\u4e3a\u533f\u540d\u8bf7\u6c42\u3002<\/p>\n<h4>\u521b\u5efa\u8d26\u6237<\/h4>\n<p>\u4ee5\u4e0b\u63a2\u8ba8\u4f7f\u7528 **X509\u5ba2\u6237\u8bc1\u4e66 **\u63d2\u4ef6\u7ba1\u7406\u7528\u6237\u3002<\/p>\n<h5>\u5ba2\u6237\u7aef\u51c6\u5907<\/h5>\n<p>\u5ba2\u6237\u7aef\u8981\u60f3\u8bbf\u95ee\u96c6\u7fa4&#xff0c;\u5fc5\u987b\u5b89\u88c5\u4e0e\u96c6\u7fa4\u7248\u672c\u4e00\u81f4\u7684kubectl\u5de5\u5177\u3002<\/p>\n<p>root&#064;client:~<span class=\"token comment\"># apt install -y kubectl&#061;1.30.2-1.1<\/span><\/p>\n<p>\u51c6\u5907\u7533\u8bf7\u6750\u6599<\/p>\n<p><span class=\"token comment\"># \u521b\u5efa\u79c1\u94a5<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># openssl genrsa -out laoma.key 2048<\/span><\/p>\n<p><span class=\"token comment\"># \u6839\u636e\u79c1\u94a5&#xff0c;\u521b\u5efa\u8bf7\u6c42\u8bc1\u4e66<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># openssl req -new -key laoma.key -out laoma.csr -subj &#039;\/CN&#061;laoma\/O&#061;kubernets&#039;<\/span><br \/>\n<span class=\"token comment\"># \u53c2\u6570\u8bf4\u660e&#xff1a;<\/span><br \/>\n<span class=\"token comment\">## C&#xff0c;Country&#xff0c;\u4ee3\u8868\u56fd\u5bb6<\/span><br \/>\n<span class=\"token comment\">## ST&#xff0c;STate&#xff0c;\u4ee3\u8868\u7701\u4efd<\/span><br \/>\n<span class=\"token comment\">## L&#xff0c;Location&#xff0c;\u4ee3\u8868\u57ce\u5e02<\/span><br \/>\n<span class=\"token comment\">## O&#xff0c;Organization&#xff0c;\u4ee3\u8868\u7ec4\u7ec7&#xff0c;\u516c\u53f8<\/span><br \/>\n<span class=\"token comment\">## OU&#xff0c;Organization Unit&#xff0c;\u4ee3\u8868\u90e8\u95e8<\/span><br \/>\n<span class=\"token comment\">## CN&#xff0c;Common Name&#xff0c;\u4ee3\u8868\u670d\u52a1\u5668\u57df\u540d<\/span><br \/>\n<span class=\"token comment\">## emailAddress&#xff0c;\u4ee3\u8868\u8054\u7cfb\u4eba\u90ae\u7bb1\u5730\u5740\u3002<\/span><\/p>\n<p><span class=\"token comment\"># \u5176\u4ed6\u793a\u4f8b&#xff1a;<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># openssl req -new -key servera.key -out servera.csr -subj &#034;\/C&#061;CHINA\/ST&#061;JS\/L&#061;NJ\/O&#061;LM\/OU&#061;DEVOPS\/CN&#061;servera.lab.example.com\/emailAddress&#061;laoma&#064;lab.example.com&#034;<\/span><\/p>\n<p><span class=\"token comment\"># \u5ba2\u6237\u7aef\u5c06\u81ea\u5df1\u8bf7\u6c42\u8bc1\u4e66\u53d1\u7ed9kubernetes\u7ba1\u7406\u5458<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># scp laoma.csr root&#064;master30:<\/span><\/p>\n<h5>\u521b\u5efa\u7528\u6237\u51ed\u636e<\/h5>\n<p>\u7ba1\u7406\u5458\u4f7f\u7528\u4ee5\u4e0b\u8d44\u6e90\u6587\u4ef6\u521b\u5efa\u7528\u6237\u7684kubeconfig\u3002<\/p>\n<p><span class=\"token comment\"># \u4f7f\u7528ca.crt\u548cca.key\u7b7e\u540dlaoma.csr&#xff0c;\u5f97\u5230laoma.crt\u8bc1\u4e66<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># openssl x509 -req -in laoma.csr -CA \/etc\/kubernetes\/pki\/ca.crt -CAkey \/etc\/kubernetes\/pki\/ca.key -CAcreateserial -out laoma.crt -days 1095<\/span><\/p>\n<p><span class=\"token comment\"># \u5bfc\u51fakubeconfig\u6a21\u7248<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl config view &gt; config.tpl<\/span><\/p>\n<p><span class=\"token comment\"># \u5c06kubeconfig\u6a21\u677f\u3001laoma.crt\u548ckubernetes\u7684ca\u8bc1\u4e66\u53d1\u7ed9\u5ba2\u6237\u7aef<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># scp config.tpl laoma.crt \/etc\/kubernetes\/pki\/ca.crt root&#064;client:~<\/span><\/p>\n<h5>\u521b\u5efa kubeconfig<\/h5>\n<p>kubeconfig\u521b\u5efa\u65b9\u6cd5&#xff1a;<\/p>\n<ul>\n<li>**\u65b9\u6cd5\u4e00&#xff1a;**\u4f7f\u7528kubectl config\u547d\u4ee4\u521b\u5efa\u3002<\/li>\n<\/ul>\n<p>\u4fee\u6539\u6a21\u7248config.tpl&#xff0c;\u7ed3\u679c\u5982\u4e0b&#xff1a;<\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> v1<br \/>\n<span class=\"token key atrule\">clusters<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">cluster<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">server<\/span><span class=\"token punctuation\">:<\/span> https<span class=\"token punctuation\">:<\/span>\/\/10.1.8.30<span class=\"token punctuation\">:<\/span><span class=\"token number\">6443<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> kubernetes<br \/>\n<span class=\"token key atrule\">contexts<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">context<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">cluster<\/span><span class=\"token punctuation\">:<\/span> kubernetes<br \/>\n    <span class=\"token key atrule\">namespace<\/span><span class=\"token punctuation\">:<\/span> default<br \/>\n    <span class=\"token key atrule\">user<\/span><span class=\"token punctuation\">:<\/span> laoma<br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> laoma&#064;kubernetes<br \/>\n<span class=\"token key atrule\">current-context<\/span><span class=\"token punctuation\">:<\/span> laoma&#064;kubernetes<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Config<br \/>\n<span class=\"token key atrule\">users<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> laoma<\/p>\n<p><span class=\"token comment\"># \u8bbe\u7f6e cluster<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># mv config.tpl config<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># kubectl config set-cluster kubernetes &#8211;kubeconfig&#061;config &#8211;certificate-authority&#061;ca.crt &#8211;embed-certs <\/span><\/p>\n<p><span class=\"token comment\"># &#8211;kubeconfig\u6307\u5b9akubeconfig\u6587\u4ef6<\/span><br \/>\n<span class=\"token comment\"># &#8211;server\u6307\u5b9akubernetes\u670d\u52a1\u5668\u8ba4\u8bc1\u5730\u5740<\/span><br \/>\n<span class=\"token comment\"># &#8211;certificate-authority\u9009\u9879\u6307\u5b9aca\u8bc1\u4e66<\/span><br \/>\n<span class=\"token comment\"># &#8211;embed-certs\u9009\u9879\u4f5c\u7528\u662f\u5c06ca.crt\u7684\u5185\u5bb9\u6dfb\u52a0\u5230config\u6587\u4ef6\u4e2d&#xff0c;<\/span><br \/>\n<span class=\"token comment\"># \u5982\u679c\u6ca1\u6709\u8be5\u9009\u9879&#xff0c;\u5219\u6dfb\u52a0 &#8211;certificate-authority \u9009\u9879\u6307\u5b9a\u7684\u8def\u5f84&#xff0c;\u4e5f\u5c31\u662fca.crt<\/span><\/p>\n<p><span class=\"token comment\"># \u8bbe\u7f6ecredentials<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># kubectl config set-credentials laoma &#8211;kubeconfig&#061;config &#8211;client-key&#061;laoma.key &#8211;client-certificate&#061;laoma.crt &#8211;embed-certs<\/span><\/p>\n<p><span class=\"token comment\"># &#8211;client-key \u6307\u5b9a\u7528\u6237\u79c1\u94a5<\/span><br \/>\n<span class=\"token comment\"># &#8211;client-certificate \u6307\u5b9a\u670d\u52a1\u5668\u4e3a\u7528\u6237\u751f\u6210\u7684\u8bc1\u4e66<\/span><\/p>\n<p><span class=\"token comment\"># \u8bbe\u7f6econtext<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># kubectl config set-context laoma &#8211;kubeconfig&#061;config &#8211;namespace&#061;default &#8211;cluster&#061;kubernetes &#8211;user&#061;laoma<\/span><br \/>\n<span class=\"token comment\"># &#8211;namespace\u6307\u5b9aNamespace<\/span><br \/>\n<span class=\"token comment\"># &#8211;cluster\u6307\u5b9a\u96c6\u7fa4<\/span><br \/>\n<span class=\"token comment\"># &#8211;user\u6307\u5b9a\u7528\u6237<\/span><\/p>\n<p><span class=\"token comment\"># \u6388\u6743\u7528\u6237laoma\u96c6\u7fa4\u7ba1\u7406\u5458\u89d2\u8272&#xff0c;\u540e\u7eed\u8be6\u7ec6\u8bb2\u89e3\u89d2\u8272\u7ba1\u7406<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl create clusterrolebinding laoma-admin &#8211;clusterrole&#061;cluster-admin &#8211;user&#061;laoma<\/span><\/p>\n<p><span class=\"token comment\"># \u9a8c\u8bc1\u7ed3\u679c<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># kubectl get nodes &#8211;kubeconfig&#061;config <\/span><br \/>\nNAME                  STATUS   ROLES           AGE   VERSION<br \/>\nmaster30.cai.cloud   Ready    control-plane   40h   v1.30.2<br \/>\nworker31.cai.cloud   Ready    <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span>          40h   v1.30.2<br \/>\nworker32.cai.cloud   Ready    <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span>          40h   v1.30.2<\/p>\n<ul>\n<li>**\u65b9\u6cd5\u4e8c&#xff1a;**\u4f7f\u7528\u6587\u672c\u7f16\u8f91\u5668\u521b\u5efa&#xff08;\u4e0d\u63a8\u8350&#xff09;\u3002<\/li>\n<\/ul>\n<p><span class=\"token comment\"># \u83b7\u53d6\u6587\u4ef6ca.crt base64\u7f16\u7801&#xff0c;\u586b\u5145\u5230certificate-authority-data<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># cat ca.crt | base64 | tr -d &#039;\\\\n&#039;<\/span><\/p>\n<p><span class=\"token comment\"># \u83b7\u53d6\u6587\u4ef6laoma.key base64\u7f16\u7801&#xff0c;\u586b\u5145\u5230client-key-data<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># cat laoma.key | base64 | tr -d &#039;\\\\n&#039;<\/span><\/p>\n<p><span class=\"token comment\"># \u83b7\u53d6\u6587\u4ef6laoma.crt base64\u7f16\u7801&#xff0c;\u586b\u5145\u5230client-certificate-data<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># cat laoma.crt | base64 | tr -d &#039;\\\\n&#039;<\/span><\/p>\n<p><span class=\"token comment\"># \u4f7f\u7528\u4e0a\u9762\u7684base64\u7f16\u7801\u4fee\u6539\u914d\u7f6e\u6587\u4ef6\u5bf9\u5e94\u503c<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl config view<\/span><br \/>\napiVersion: v1<br \/>\nclusters:<br \/>\n&#8211; cluster:<br \/>\n    certificate-authority-data: DATA&#043;OMITTED<br \/>\n    server: https:\/\/10.1.8.30:6443<br \/>\n  name: kubernetes<br \/>\ncontexts:<br \/>\n&#8211; context:<br \/>\n    cluster: kubernetes<br \/>\n    user: kubernetes-laoma<br \/>\n  name: kubernetes-laoma&#064;kubernetes<br \/>\ncurrent-context: kubernetes-admin&#064;kubernetes<br \/>\nkind: Config<br \/>\npreferences: <span class=\"token punctuation\">{<\/span><span class=\"token punctuation\">}<\/span><br \/>\nusers:<br \/>\n&#8211; name: kubernetes-laoma<br \/>\n  user:<br \/>\n    client-certificate-data: REDACTED<br \/>\n    client-key-data: REDACTED<\/p>\n<h4>\u5220\u9664\u8d26\u6237<\/h4>\n<p><span class=\"token comment\"># \u901a\u8fc7\u5220\u9664\u8bc1\u4e66\u8fdb\u884c\u5220\u9664\u8d26\u6237\u5373\u53ef&#xff0c;\u4e3a\u4e86\u540e\u7eed\u64cd\u4f5c\u65b9\u4fbf&#xff0c;\u8be5\u8d26\u6237\u4e0d\u5220\u9664<\/span><\/p>\n<p><span class=\"token comment\"># k8s\u5220\u9664\u7528\u6237csr\u8d44\u6e90\u540e&#xff0c;\u5ba2\u6237\u7aef\u7528\u6237\u4ecd\u53ef\u4ee5\u8bbf\u95ee\u96c6\u7fa4\u3002<\/span><br \/>\n<span class=\"token comment\"># \u89e3\u91ca&#xff1a;\u7528\u6237\u8ba4\u8bc1\u529f\u80fd\u7531x509\u63d0\u4f9b&#xff0c;\u4e0ek8s\u65e0\u5173\u3002<\/span><br \/>\n<span class=\"token comment\"># \u5982\u679c\u4e0d\u4e88\u8bb8\u7528\u6237\u767b\u5f55&#xff0c;\u5e94\u8be5\u4ecex509\u8ba4\u8bc1\u673a\u5236\u65b9\u9762\u4e0b\u624b&#xff0c;\u4f8b\u5982ca.crt\u5c06\u76f8\u5e94\u5ba2\u6237\u7aefcsr\u52a0\u5165\u9ed1\u540d\u5355\u3002<\/span><\/p>\n<p><span class=\"token comment\"># \u5220\u9664\u6743\u9650<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl delete clusterrolebindings.rbac.authorization.k8s.io laoma-admin<\/span><\/p>\n<p><span class=\"token comment\"># \u9a8c\u8bc1\u6743\u9650<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># kubectl get nodes<\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: nodes is forbidden: User <span class=\"token string\">&#034;laoma&#034;<\/span> cannot list resource <span class=\"token string\">&#034;nodes&#034;<\/span> <span class=\"token keyword\">in<\/span> API group <span class=\"token string\">&#034;&#034;<\/span> at the cluster scope<\/p>\n<h3>\u6388\u6743\u7ba1\u7406<\/h3>\n<p>\u5b66\u4e60\u53c2\u8003&#xff1a;\u9274\u6743\u3001\u4f7f\u7528 RBAC \u9274\u6743<\/p>\n<h4>\u9274\u6743\u6982\u8ff0<\/h4>\n<p>Kubernetes API \u670d\u52a1\u5668\u5bf9 API \u8bf7\u6c42\u8fdb\u884c\u9274\u6743\u3002 \u5b83\u6839\u636e\u6240\u6709\u7b56\u7565\u8bc4\u4f30\u6240\u6709\u8bf7\u6c42\u5c5e\u6027\u6765\u51b3\u5b9a\u5141\u8bb8\u6216\u62d2\u7edd\u8bf7\u6c42\u3002 \u4e00\u4e2a API \u8bf7\u6c42\u7684\u6240\u6709\u90e8\u5206\u90fd\u5fc5\u987b\u88ab\u67d0\u4e9b\u7b56\u7565\u5141\u8bb8\u624d\u80fd\u7ee7\u7eed\u3002 \u8fd9\u610f\u5473\u7740\u9ed8\u8ba4\u60c5\u51b5\u4e0b\u62d2\u7edd\u6743\u9650\u3002<\/p>\n<p>\u5f53\u7cfb\u7edf\u914d\u7f6e\u4e86\u591a\u4e2a\u9274\u6743\u6a21\u5757\u65f6&#xff0c;Kubernetes \u5c06\u6309\u987a\u5e8f\u4f7f\u7528\u6bcf\u4e2a\u6a21\u5757\u3002<\/p>\n<ul>\n<li>\u5982\u679c\u4efb\u4f55\u9274\u6743\u6a21\u5757\u6279\u51c6\u6216\u62d2\u7edd\u8bf7\u6c42&#xff0c;\u5219\u7acb\u5373\u8fd4\u56de\u8be5\u51b3\u5b9a&#xff0c;\u5e76\u4e14\u4e0d\u4f1a\u4e0e\u5176\u4ed6\u9274\u6743\u6a21\u5757\u534f\u5546\u3002<\/li>\n<li>\u5982\u679c\u6240\u6709\u6a21\u5757\u5bf9\u8bf7\u6c42\u6ca1\u6709\u610f\u89c1&#xff0c;\u5219\u62d2\u7edd\u8be5\u8bf7\u6c42\u3002 \u88ab\u62d2\u7edd\u54cd\u5e94\u8fd4\u56de HTTP \u72b6\u6001\u4ee3\u7801 403\u3002<\/li>\n<\/ul>\n<h4>\u9274\u6743\u6a21\u5f0f<\/h4>\n<p>\u9274\u6743\u6a21\u5f0f\u5b9a\u4e49\u8ba4\u8bc1\u6210\u529f\u7684\u7528\u6237\u5bf9\u96c6\u7fa4\u7684\u64cd\u4f5c\u6743\u9650&#xff0c;\u7531kube-apiserver\u914d\u7f6e\u6587\u4ef6\u6307\u5b9a&#xff1a;<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># cat \/etc\/kubernetes\/manifests\/kube-apiserver.yaml |grep mode<\/span><br \/>\n    &#8211; &#8211;authorization-mode<span class=\"token operator\">&#061;<\/span>Node,RBAC<\/p>\n<p>\u6211\u4eec\u8fd9\u91cc\u4f7f\u7528RBAC\u548cNode\u6a21\u5f0f\u3002<\/p>\n<p>\u652f\u6301\u7684\u6a21\u5f0f&#xff1a;<\/p>\n<ul>\n<li>\n<p>Node&#xff0c;\u662f\u8282\u70b9\u4e13\u7528\u7684\u9274\u6743\u6a21\u5f0f&#xff0c;\u6839\u636e\u8c03\u5ea6\u5230 kubelet \u4e0a\u8fd0\u884c\u7684 Pod \u4e3a kubelet \u6388\u4e88\u6743\u9650\u3002 \u8981\u4e86\u89e3\u6709\u5173\u4f7f\u7528\u8282\u70b9\u9274\u6743\u6a21\u5f0f\u7684\u66f4\u591a\u4fe1\u606f&#xff0c;\u8bf7\u53c2\u9605\u8282\u70b9\u9274\u6743\u3002<\/p>\n<\/li>\n<li>\n<p>ABAC&#xff0c;\u57fa\u4e8e\u5c5e\u6027\u7684\u8bbf\u95ee\u63a7\u5236&#xff08;ABAC&#xff09;\u5b9a\u4e49\u4e86\u4e00\u79cd\u8bbf\u95ee\u63a7\u5236\u8303\u578b&#xff0c;\u901a\u8fc7\u4f7f\u7528\u5c06\u5c5e\u6027\u7ec4\u5408\u5728\u4e00\u8d77\u7684\u7b56\u7565&#xff0c; \u5c06\u8bbf\u95ee\u6743\u9650\u6388\u4e88\u7528\u6237\u3002\u7b56\u7565\u53ef\u4ee5\u4f7f\u7528\u4efb\u4f55\u7c7b\u578b\u7684\u5c5e\u6027&#xff08;\u7528\u6237\u5c5e\u6027\u3001\u8d44\u6e90\u5c5e\u6027\u3001\u5bf9\u8c61&#xff0c;\u73af\u5883\u5c5e\u6027\u7b49&#xff09;\u3002 \u8981\u4e86\u89e3\u6709\u5173\u4f7f\u7528 ABAC \u6a21\u5f0f\u7684\u66f4\u591a\u4fe1\u606f&#xff0c;\u8bf7\u53c2\u9605 ABAC \u6a21\u5f0f\u3002<\/p>\n<\/li>\n<li>\n<p>RBAC&#xff0c;\u57fa\u4e8e\u89d2\u8272\u7684\u8bbf\u95ee\u63a7\u5236&#xff08;RBAC&#xff09; \u662f\u4e00\u79cd\u57fa\u4e8e\u4f01\u4e1a\u5185\u4e2a\u4eba\u7528\u6237\u7684\u89d2\u8272\u6765\u7ba1\u7406\u5bf9\u8ba1\u7b97\u673a\u6216\u7f51\u7edc\u8d44\u6e90\u7684\u8bbf\u95ee\u7684\u65b9\u6cd5\u3002\u8981\u4e86\u89e3\u6709\u5173\u4f7f\u7528 RBAC \u6a21\u5f0f\u7684\u66f4\u591a\u4fe1\u606f&#xff0c;\u8bf7\u53c2\u9605 RBAC \u6a21\u5f0f\u3002<\/p>\n<ul>\n<li>\u88ab\u542f\u7528\u4e4b\u540e&#xff0c;RBAC&#xff08;\u57fa\u4e8e\u89d2\u8272\u7684\u8bbf\u95ee\u63a7\u5236&#xff09;\u4f7f\u7528 rbac.authorization.k8s.io API \u7ec4\u6765\u9a71\u52a8\u9274\u6743\u51b3\u7b56&#xff0c;\u4ece\u800c\u5141\u8bb8\u7ba1\u7406\u5458\u901a\u8fc7 Kubernetes API \u52a8\u6001\u914d\u7f6e\u6743\u9650\u7b56\u7565\u3002<\/li>\n<li>\u8981\u542f\u7528 RBAC&#xff0c;\u8bf7\u4f7f\u7528 &#8211;authorization-mode &#061; RBAC \u542f\u52a8 API \u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>Webhook \u2014\u2014 WebHook \u662f\u4e00\u4e2a HTTP \u56de\u8c03&#xff1a;\u53d1\u751f\u67d0\u4e9b\u4e8b\u60c5\u65f6\u8c03\u7528\u7684 HTTP POST&#xff1b; \u901a\u8fc7 HTTP POST \u8fdb\u884c\u7b80\u5355\u7684\u4e8b\u4ef6\u901a\u77e5\u3002 \u5b9e\u73b0 WebHook \u7684 Web \u5e94\u7528\u7a0b\u5e8f\u4f1a\u5728\u53d1\u751f\u67d0\u4e9b\u4e8b\u60c5\u65f6\u5c06\u6d88\u606f\u53d1\u5e03\u5230 URL\u3002 \u8981\u4e86\u89e3\u6709\u5173\u4f7f\u7528 Webhook \u6a21\u5f0f\u7684\u66f4\u591a\u4fe1\u606f&#xff0c;\u8bf7\u53c2\u9605 Webhook \u6a21\u5f0f\u3002<\/p>\n<\/li>\n<li>\n<p>AlwaysAllow&#xff0c;\u5141\u8bb8\u7528\u6237\u6240\u6709\u8bf7\u6c42\u3002<\/p>\n<p> <span class=\"token comment\"># \u524d\u9762\u6211\u4eec\u5220\u9664\u4e86\u7528\u6237laoma\u6743\u9650&#xff0c;\u66f4\u6539\u4e3aAlwaysAllow\u6a21\u5f0f&#xff0c;\u6d4b\u8bd5laoma\u7528\u6237\u6743\u9650\u3002<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># vim \/etc\/kubernetes\/manifests\/kube-apiserver.yaml<\/span><br \/>\n<span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><br \/>\n<span class=\"token comment\"># \u5728spec.containers\u4e0b\u7684command\u4e2d\u6dfb\u52a0\u53c2\u6570- &#8211;basic-auth-file&#061;\/etc\/kubernets\/pki\/aa.csv<\/span><br \/>\nspec:<br \/>\n  containers:<br \/>\n  &#8211; command:<br \/>\n    &#8211; &#8211;authorization-mode<span class=\"token operator\">&#061;<\/span>AlwaysAllow<br \/>\n<span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><\/p>\n<p><span class=\"token comment\"># \u66f4\u6539\u5b8c\u6210\u540e&#xff0c;kubernetes\u4f1a\u81ea\u52a8\u91cd\u542fpod\/kube-apiserver&#xff0c;\u7b49\u8be5pod\u72b6\u6001\u4e3arunning\u518d\u6b21\u9a8c\u8bc1\u3002<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># kubectl get nodes<\/span><br \/>\nNAME                   STATUS   ROLES           AGE   VERSION<br \/>\nmaster30.cai.cloud   Ready    control-plane   12d   v1.30.2<br \/>\nworker31.cai.cloud   Ready    <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span>          12d   v1.30.2<br \/>\nworker32.cai.cloud   Ready    <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span>          12d   v1.30.2\n <\/li>\n<li>\n<p>AlwaysDeny&#xff0c;\u62d2\u7edd\u7528\u6237\u6240\u6709\u8bf7\u6c42&#xff0c;\u4e0d\u7ba1\u7528\u6237\u662f\u5426\u5177\u6709\u6743\u9650&#xff0c;\u4f46\u4e0d\u9650\u5236admin\u7528\u6237\u3002<\/p>\n<\/li>\n<\/ul>\n<h4>role \u7ba1\u7406<\/h4>\n<p>kubernetes \u65b9\u4fbf\u7ba1\u7406\u6743\u9650&#xff0c;\u5c06\u4e00\u7ec4\u7279\u5b9a\u6743\u9650\u8d4b\u4e88\u89d2\u8272&#xff0c;\u7136\u540e\u5c06\u89d2\u8272\u8d4b\u4e88\u7528\u6237&#xff0c;\u90a3\u4e48\u7528\u6237\u5c06\u7ee7\u627f\u8be5\u89d2\u8272\u5177\u6709\u7684\u6743\u9650\u3002<\/p>\n<h5>\u89d2\u8272\u5206\u7c7b<\/h5>\n<ul>\n<li>\n<p>role&#xff0c;namespace \u89d2\u8272&#xff0c;\u9650\u5b9a\u7528\u6237\u8bbf\u95ee\u7279\u5b9anamespace\u3002role\u7ed1\u5b9a\u7ed9\u7528\u6237&#xff0c;\u79f0\u4e4b\u4e3arolebinding\u3002<\/p>\n<\/li>\n<li>\n<p>clusterrole&#xff0c;cluster \u89d2\u8272&#xff0c;\u53ef\u4ee5\u7ba1\u7406\u96c6\u7fa4&#xff0c;\u5305\u62ec\u6240\u6709namespace\u4e2d\u8d44\u6e90\u3002clusterrole\u7ed1\u5b9a\u7ed9\u7528\u6237&#xff0c;\u79f0\u4e4b\u4e3aclusterrolebinding\u3002<\/p>\n<\/li>\n<\/ul>\n<p>\u6743\u9650\u7531kubernetes\u7cfb\u7edf\u9884\u5b9a\u4e49\u7684&#xff0c;clusterroles\/admin\u4e2d\u5305\u6db5\u7cfb\u7edf\u4e2d\u5168\u90e8\u6743\u9650\u5217\u8868\u3002<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl describe clusterroles admin<\/span><br \/>\nName:         admin<br \/>\nLabels:       kubernetes.io\/bootstrapping<span class=\"token operator\">&#061;<\/span>rbac-defaults<br \/>\nAnnotations:  rbac.authorization.kubernetes.io\/autoupdate: <span class=\"token boolean\">true<\/span><br \/>\nPolicyRule:<br \/>\n  Resources                                       Non-Resource URLs  Resource Names  Verbs<br \/>\n  &#8212;&#8212;&#8212;                                       &#8212;&#8212;&#8212;&#8212;&#8212;&#8211;  &#8212;&#8212;&#8212;&#8212;&#8211;  &#8212;&#8211;<br \/>\n  rolebindings.rbac.authorization.k8s.io          <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>                 <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>              <span class=\"token punctuation\">[<\/span>create delete deletecollection get list patch update watch<span class=\"token punctuation\">]<\/span><br \/>\n  roles.rbac.authorization.k8s.io                 <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>                 <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>              <span class=\"token punctuation\">[<\/span>create delete deletecollection get list patch update watch<span class=\"token punctuation\">]<\/span><br \/>\n  configmaps                                      <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>                 <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>              <span class=\"token punctuation\">[<\/span>create delete deletecollection patch update get list watch<span class=\"token punctuation\">]<\/span><br \/>\n  endpoints                                       <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>                 <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>              <span class=\"token punctuation\">[<\/span>create delete deletecollection patch update get list watch<span class=\"token punctuation\">]<\/span><br \/>\n<span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><\/p>\n<p>\u8f93\u51fa\u8bf4\u660e&#xff1a;<\/p>\n<ul>\n<li>\n<p>Resources&#xff1a;\u4ee3\u8868\u7cfb\u7edf\u4e2d\u8d44\u6e90\u7c7b\u578b&#xff0c;\u4f8b\u5982Secret&#xff0c;Configmap\u7b49\u3002<\/p>\n<\/li>\n<li>\n<p>Resource Names&#xff1a;\u4ee3\u8868\u7279\u5b9a\u8d44\u6e90\u3002\u5982\u679cResources\u662fSecret&#xff0c;\u90a3\u4e48\u8fd9\u91cc\u5c31\u6307\u7279\u5b9aSecret\u3002<\/p>\n<\/li>\n<li>\n<p>Non-Resource URLs&#xff1a; \u88ab\u79f0\u4e3a\u975e\u8d44\u6e90URL\u6216\u865a\u62dfURL\u5bf9\u8c61&#xff0c;\u662fk8s\u4e2d\u6240\u9700\u8981\u7684\u7279\u6b8a\u52a8\u4f5c&#xff08;\u4e0d\u9700\u8981\u5173\u6ce8&#xff09;\u3002<\/p>\n<\/li>\n<li>\n<p>Verbs&#xff1a;\u4ee3\u8868\u9488\u5bf9\u8d44\u6e90\u6267\u884c\u7684\u52a8\u4f5c&#xff0c;\u5305\u62ec\u64cd\u4f5cget\u3001list\u3001create\u3001delete\u3001update\u3001edit\u3001watch\u3001exec\u3002<\/p>\n<ul>\n<li>get&#xff0c;\u7528\u4e8e\u83b7\u5f97\u7279\u5b9a\u8d44\u6e90\u4fe1\u606f&#xff0c;\u4f8b\u5982&#xff0c;\u9488\u5bf9pod&#xff0c;\u53ef\u4ee5\u6267\u884cGET \/api\/v1\/namespaces\/{namespace}\/pods\/{podname}\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>root&#064;client:~<span class=\"token comment\"># kubectl get pod -n kube-system <\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: pods is forbidden: User <span class=\"token string\">&#034;laoma&#034;<\/span> cannot list resource <span class=\"token string\">&#034;pods&#034;<\/span> <span class=\"token keyword\">in<\/span> API group <span class=\"token string\">&#034;&#034;<\/span> <span class=\"token keyword\">in<\/span> the namespace <span class=\"token string\">&#034;kube-system&#034;<\/span><\/p>\n<p>root&#064;client:~<span class=\"token comment\"># kubectl get pod kube-proxy-8kp8w -n kube-system <\/span><br \/>\nNAME               READY   STATUS    RESTARTS   AGE<br \/>\nkube-proxy-8kp8w   <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">4<\/span>          52d<\/p>\n<ul>\n<li>list&#xff0c;\u7528\u6237\u67e5\u770b\u67d0\u4e00\u7c7b\u578b\u8d44\u6e90\u6e05\u5355&#xff0c;\u4f8b\u5982\u9488\u5bf9pod&#xff0c;\u53ef\u4ee5\u6267\u884cGET \/api\/v1\/namespaces\/{namespace}\/pods\u3002<\/li>\n<\/ul>\n<p>root&#064;client:~<span class=\"token comment\"># kubectl get pod -n kube-system <\/span><br \/>\nNAME                                        READY   STATUS    RESTARTS   AGE<br \/>\ncalico-kube-controllers-6dfcd885bf-lq4n5    <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">4<\/span>          52d<br \/>\ncalico-node-44cf4                           <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">4<\/span>          52d<br \/>\ncalico-node-48sm4                           <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">4<\/span>          52d<br \/>\n<span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span>.<\/p>\n<p>root&#064;client:~<span class=\"token comment\"># kubectl get pod kube-proxy-8kp8w -n kube-system <\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: pods <span class=\"token string\">&#034;kube-proxy-8kp8w&#034;<\/span> is forbidden: User <span class=\"token string\">&#034;laoma&#034;<\/span> cannot get resource <span class=\"token string\">&#034;pods&#034;<\/span> <span class=\"token keyword\">in<\/span> API group <span class=\"token string\">&#034;&#034;<\/span> <span class=\"token keyword\">in<\/span> the namespace <span class=\"token string\">&#034;kube-system&#034;<\/span><\/p>\n<p>\u66f4\u591aAPI\u4fe1\u606f\u53c2\u8003&#xff1a;https:\/\/kubernetes.io\/docs\/reference\/kubernetes-api\/<\/p>\n<h5>\u521b\u5efa role<\/h5>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create role -h<\/span><br \/>\nCreate a role with single rule.<\/p>\n<p>Usage:<br \/>\n  kubectl create role NAME <span class=\"token parameter variable\">&#8211;verb<\/span><span class=\"token operator\">&#061;<\/span>verb <span class=\"token parameter variable\">&#8211;resource<\/span><span class=\"token operator\">&#061;<\/span>resource.group\/subresource<br \/>\n<span class=\"token punctuation\">[<\/span>&#8211;resource-name<span class=\"token operator\">&#061;<\/span>resourcename<span class=\"token punctuation\">]<\/span> <span class=\"token punctuation\">[<\/span>&#8211;dry-run<span class=\"token operator\">&#061;<\/span>server<span class=\"token operator\">|<\/span>client<span class=\"token operator\">|<\/span>none<span class=\"token punctuation\">]<\/span> <span class=\"token punctuation\">[<\/span>options<span class=\"token punctuation\">]<\/span><\/p>\n<p>\u793a\u4f8b1&#xff1a;\u53ef\u4ee5\u5bf9\u9879\u76ee\u4e2d\u6240\u6709pods\u6267\u884cget\u3001list\u3001watch\u64cd\u4f5c<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create role pod-role &#8211;verb&#061;get,list,watch &#8211;resource&#061;pods -n default &#8211;dry-run&#061;client -o yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> rbac.authorization.k8s.io\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Role<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">creationTimestamp<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token null important\">null<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> pod<span class=\"token punctuation\">&#8211;<\/span>role<br \/>\n  <span class=\"token key atrule\">namespace<\/span><span class=\"token punctuation\">:<\/span> default<br \/>\n<span class=\"token key atrule\">rules<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">apiGroups<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token string\">&#034;&#034;<\/span><br \/>\n  <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> pods<br \/>\n  <span class=\"token key atrule\">verbs<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> get<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> list<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> watch<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create role pod-role &#8211;verb&#061;get,list,watch &#8211;resource&#061;pods -n default<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl get roles pod-role -n default<\/span><br \/>\nNAME         CREATED AT<br \/>\npod-role   <span class=\"token number\">2021<\/span>-08-24T10:24:36Z<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl describe roles pod-role -n default<\/span><br \/>\nName:         pod-role<br \/>\nLabels:       <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span><br \/>\nAnnotations:  <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span><br \/>\nPolicyRule:<br \/>\n  Resources  Non-Resource URLs  Resource Names  Verbs<br \/>\n  &#8212;&#8212;&#8212;  &#8212;&#8212;&#8212;&#8212;&#8212;&#8211;  &#8212;&#8212;&#8212;&#8212;&#8211;  &#8212;&#8211;<br \/>\n  pods       <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>                 <span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span>              <span class=\"token punctuation\">[<\/span>get list watch<span class=\"token punctuation\">]<\/span><\/p>\n<p>\u793a\u4f8b2&#xff1a;\u8bbf\u95ee\u7279\u5b9a\u8d44\u6e90pods\/readablepod<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create role pod-role &#8211;verb&#061;get &#8211;resource&#061;pods \\\\<\/span><br \/>\n&#8211;resource-name<span class=\"token operator\">&#061;<\/span>readablepod &#8211;resource-name<span class=\"token operator\">&#061;<\/span>anotherpod<\/p>\n<p>\u793a\u4f8b3&#xff1a;\u53ef\u4ee5\u5bf9\u9879\u76ee\u4e2d\u6240\u6709replicasets\u6267\u884cget list watch\u64cd\u4f5c<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create role foo &#8211;verb&#061;get,list,watch &#8211;resource&#061;replicasets<\/span><\/p>\n<h5>\u4fee\u6539 role<\/h5>\n<p><span class=\"token comment\"># \u589e\u52a0create\u6743\u9650<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl edit roles -n default pod-role<\/span><br \/>\n<span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><span class=\"token punctuation\">..<\/span><br \/>\nrules:<br \/>\n&#8211; apiGroups:<br \/>\n  &#8211; <span class=\"token string\">&#034;&#034;<\/span><br \/>\n  resources:<br \/>\n  &#8211; pods<br \/>\n  verbs:<br \/>\n<span class=\"token comment\"># \u5728verbs\u4e0b\u6dfb\u52a0\u76f8\u5e94\u6743\u9650<\/span><br \/>\n  &#8211; list<br \/>\n  &#8211; get<br \/>\n  &#8211; <span class=\"token function\">watch<\/span><br \/>\n  &#8211; create<\/p>\n<h5>apiGroups<\/h5>\n<ul>\n<li>\n<p>\u89d2\u8272\u7684 rules \u5c5e\u6027\u4e2d apiGroups \u9ed8\u8ba4\u4e3a\u7a7a\u3002<\/p>\n<\/li>\n<li>\n<p>pod\u3001service \u8d44\u6e90\u7684 apiVersion \u662fv1&#xff0c;apiGroups\u4e3a&#034;&#034;\u3002<\/p>\n<\/li>\n<li>\n<p>Deployment\u3001DaemonSet \u8d44\u6e90\u7684 apiVersion \u662fapps\/v1&#xff0c;apiGroups\u4e3a&#034;apps&#034;\u3002\u5982\u4e0b&#xff1a;<\/p>\n<\/li>\n<\/ul>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> rbac.authorization.k8s.io\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Role<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">creationTimestamp<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token null important\">null<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> deployments<span class=\"token punctuation\">&#8211;<\/span>role<br \/>\n  <span class=\"token key atrule\">namespace<\/span><span class=\"token punctuation\">:<\/span> default<br \/>\n<span class=\"token key atrule\">rules<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">apiGroups<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token string\">&#034;apps&#034;<\/span><br \/>\n  <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> deployments<br \/>\n  <span class=\"token key atrule\">verbs<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> get<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> list<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> watch<\/p>\n<p>**\u793a\u4f8b1&#xff1a;**\u5b9a\u4e49\u89d2\u8272&#xff0c;\u65e0\u6cd5\u64cd\u4f5cdeployments&#xff0c;\u56e0\u4e3aapiGroups\u672a\u6307\u5b9aapps\u3002<\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> rbac.authorization.k8s.io\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Role<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">creationTimestamp<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token null important\">null<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> deployments<span class=\"token punctuation\">&#8211;<\/span>role<br \/>\n  <span class=\"token key atrule\">namespace<\/span><span class=\"token punctuation\">:<\/span> default<br \/>\n<span class=\"token key atrule\">rules<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">apiGroups<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token string\">&#034;&#034;<\/span><br \/>\n  <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> deployments<br \/>\n  <span class=\"token key atrule\">verbs<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> get<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> list<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> watch<\/p>\n<p>**\u793a\u4f8b2&#xff1a;**\u5b9a\u4e49\u4e00\u4e2a\u53ef\u4ee5 scale deployments \u7684\u89d2\u8272\u3002<\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> rbac.authorization.k8s.io\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Role<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">creationTimestamp<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token null important\">null<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> deployments<span class=\"token punctuation\">&#8211;<\/span>role<br \/>\n  <span class=\"token key atrule\">namespace<\/span><span class=\"token punctuation\">:<\/span> default<br \/>\n<span class=\"token key atrule\">rules<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">apiGroups<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token string\">&#034;apps&#034;<\/span><br \/>\n  <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> deployments<br \/>\n  <span class=\"token comment\"># \u989d\u5916\u6dfb\u52a0\u4ee5\u4e0b\u8d44\u6e90<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> deployments\/scale<br \/>\n  <span class=\"token key atrule\">verbs<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> get<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> list<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> watch<br \/>\n  <span class=\"token comment\"># \u989d\u5916\u6dfb\u52a0\u4ee5\u4e0b\u6743\u9650<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> patch<\/p>\n<p>**\u793a\u4f8b3&#xff1a;**\u5b9a\u4e49\u4e00\u4e2a\u5bf9\u4e0d\u540c\u7c7b\u578b\u8d44\u6e90\u8d4b\u4e88\u4e0d\u540c\u6743\u9650\u7684\u89d2\u8272\u3002<\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> rbac.authorization.k8s.io\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Role<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">creationTimestamp<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token null important\">null<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> all<span class=\"token punctuation\">&#8211;<\/span>role<br \/>\n  <span class=\"token key atrule\">namespace<\/span><span class=\"token punctuation\">:<\/span> default<br \/>\n<span class=\"token key atrule\">rules<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">apiGroups<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token string\">&#034;&#034;<\/span><br \/>\n  <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> pods<br \/>\n  <span class=\"token key atrule\">verbs<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> get<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> list<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> watch<br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">apiGroups<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token string\">&#034;apps&#034;<\/span><br \/>\n  <span class=\"token key atrule\">resources<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> deployments<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> deployments\/scale<br \/>\n  <span class=\"token key atrule\">verbs<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> get<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> list<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> watch<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> patch<\/p>\n<p>\u5e38\u89c1apiGroups<\/p>\n<table>\n<tr>TypeapiVersionapiGroups<\/tr>\n<tbody>\n<tr>\n<td>Pod\u3001Service\u3001PersistentVolume\u3001PersistentVolumeClaim<\/td>\n<td>v1<\/td>\n<td>\u201c\u201d<\/td>\n<\/tr>\n<tr>\n<td>Deployment\u3001DaemonSet\u3001StatefulSets<\/td>\n<td>apps\/v1<\/td>\n<td>apps<\/td>\n<\/tr>\n<tr>\n<td>Job<\/td>\n<td>batch\/v1<\/td>\n<td>batch<\/td>\n<\/tr>\n<tr>\n<td>CronJob<\/td>\n<td>batch\/v1beta1<\/td>\n<td>batch<\/td>\n<\/tr>\n<tr>\n<td>Role RoleBinding \u3001ClusterRole ClusterRoleBinding<\/td>\n<td>rbac.authorization.k8s.io\/v1<\/td>\n<td>rbac.authorization.k8s.io<\/td>\n<\/tr>\n<tr>\n<td>NetworkPolicy<\/td>\n<td>networking.k8s.io\/v1<\/td>\n<td>networking.k8s.io<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u6bcf\u79cd\u7c7b\u578b\u8d44\u6e90\u7684 apiVersion \u90fd\u53ef\u4ee5\u901a\u8fc7\u4ee5\u4e0b\u547d\u4ee4\u67e5\u8be2&#xff1a;<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl explain deployment|grep VERSION<\/span><br \/>\nVERSION:  apps\/v1<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl explain networkpolicy|grep VERSION<\/span><br \/>\nVERSION:  networking.k8s.io\/v1<br \/>\n<span class=\"token comment\"># \u6216\u8005<\/span><br \/>\nroot&#064;master30:~\/auth<span class=\"token comment\"># kubectl api-resources |grep -i deploy<\/span><br \/>\ndeployments                       deploy       apps\/v1                                <span class=\"token boolean\">true<\/span>         Deployment<\/p>\n<h5>role \u7ed1\u5b9a<\/h5>\n<p>\u5c06 role \u7ed1\u5b9a\u7ed9\u7528\u6237\u3002<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl create rolebinding default-pod-laoma -n default &#8211;role&#061;pod-role &#8211;user&#061;laoma &#8211;dry-run&#061;client -o yaml<\/span><\/p>\n<p><span class=\"token key atrule\">apiVersion<\/span><span class=\"token punctuation\">:<\/span> rbac.authorization.k8s.io\/v1<br \/>\n<span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> RoleBinding<br \/>\n<span class=\"token key atrule\">metadata<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">creationTimestamp<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token null important\">null<\/span><br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> default<span class=\"token punctuation\">&#8211;<\/span>pod<span class=\"token punctuation\">&#8211;<\/span>laoma<br \/>\n  <span class=\"token key atrule\">namespace<\/span><span class=\"token punctuation\">:<\/span> default<br \/>\n<span class=\"token key atrule\">roleRef<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">apiGroup<\/span><span class=\"token punctuation\">:<\/span> rbac.authorization.k8s.io<br \/>\n  <span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> Role<br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> pod<span class=\"token punctuation\">&#8211;<\/span>role<br \/>\n<span class=\"token key atrule\">subjects<\/span><span class=\"token punctuation\">:<\/span><br \/>\n<span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">apiGroup<\/span><span class=\"token punctuation\">:<\/span> rbac.authorization.k8s.io<br \/>\n  <span class=\"token key atrule\">kind<\/span><span class=\"token punctuation\">:<\/span> User<br \/>\n  <span class=\"token key atrule\">name<\/span><span class=\"token punctuation\">:<\/span> laoma<\/p>\n<p><span class=\"token comment\"># \u7ed1\u5b9a ns\/default \u4e2d\u89d2\u8272 pod-role \u7ed9 laoma<\/span><br \/>\nroot&#064;master30:~<span class=\"token comment\"># kubectl create rolebinding default-pod-laoma -n default &#8211;role&#061;pod-role &#8211;user&#061;laoma<\/span><br \/>\n<span class=\"token comment\"># \u89d2\u8272\u7ed1\u5b9a\u5b8c\u6210\u540e&#xff0c;\u89d2\u8272\u7684\u6743\u9650\u53d1\u751f\u53d8\u5316&#xff0c;\u7528\u6237\u83b7\u5f97\u7684\u6743\u9650\u4e5f\u4f1a\u8ddf\u7740\u52a8\u6001\u53d8\u5316\u3002<\/span><\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl get rolebindings -n default default-pod-laoma <\/span><br \/>\nNAME                    ROLE              AGE<br \/>\ndefault-pod-laoma       Role\/pod-role   2m15s<\/p>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl describe rolebindings -n default default-pod-laoma <\/span><br \/>\nName:         default-pod-laoma<br \/>\nLabels:       <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span><br \/>\nAnnotations:  <span class=\"token operator\">&lt;<\/span>none<span class=\"token operator\">&gt;<\/span><br \/>\nRole:<br \/>\n  Kind:  Role<br \/>\n  Name:  pod-role<br \/>\nSubjects:<br \/>\n  Kind  Name   Namespace<br \/>\n  &#8212;-  &#8212;-   &#8212;&#8212;&#8212;<br \/>\n  User  laoma <\/p>\n<p><span class=\"token comment\"># \u9a8c\u8bc1<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># kubectl run web &#8211;image&#061;hub.laoma.cloud\/library\/httpd &#8211;image-pull-policy&#061;IfNotPresent -n default<\/span><\/p>\n<p>root&#064;client:~<span class=\"token comment\"># kubectl get pod -n default<\/span><br \/>\nNAME   READY   STATUS    RESTARTS   AGE<br \/>\nweb    <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          2m30s<\/p>\n<p>root&#064;client:~<span class=\"token comment\"># kubectl get pod -n default -w<\/span><br \/>\nNAME   READY   STATUS    RESTARTS   AGE<br \/>\nweb    <span class=\"token number\">1<\/span>\/1     Running   <span class=\"token number\">0<\/span>          2m42s<\/p>\n<h5>role \u56de\u6536<\/h5>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl delete rolebindings default-pod-laoma -n default<\/span><br \/>\nrolebinding.rbac.authorization.k8s.io <span class=\"token string\">&#034;default-pod-laoma&#034;<\/span> deleted<\/p>\n<p><span class=\"token comment\"># \u518d\u6b21\u9a8c\u8bc1<\/span><br \/>\nroot&#064;client:~<span class=\"token comment\"># kubectl get pod -n default<\/span><br \/>\nError from server <span class=\"token punctuation\">(<\/span>Forbidden<span class=\"token punctuation\">)<\/span>: pods is forbidden: User <span class=\"token string\">&#034;laoma&#034;<\/span> cannot list resource <span class=\"token string\">&#034;pods&#034;<\/span> <span class=\"token keyword\">in<\/span> API group <span class=\"token string\">&#034;&#034;<\/span> <span class=\"token keyword\">in<\/span> the namespace <span class=\"token string\">&#034;default&#034;<\/span><\/p>\n<h5>role \u5220\u9664<\/h5>\n<p>root&#064;master30:~<span class=\"token comment\"># kubectl delete roles pod-role -n default<\/span><\/p>\n<h2>&#x1f4dd;\u5168\u6587\u603b\u7ed3<\/h2>\n<li>\u8d44\u6e90\u7ba1\u63a7&#xff1a;ResourceQuota \u7ba1\u63a7\u547d\u540d\u7a7a\u95f4\u603b\u8d44\u6e90\u4e0a\u9650&#xff0c;LimitRange \u7ba1\u63a7\u5355\u4e2a\u5bb9\u5668\u8d44\u6e90\u8303\u56f4&#xff0c;\u586b\u5145\u9ed8\u8ba4 request\/limits&#xff1b;request \u7528\u4e8e\u8c03\u5ea6&#xff0c;limits \u901a\u8fc7 cgroup \u786c\u9650\u5236\u8d44\u6e90&#xff1b;CPU \u53ef\u538b\u7f29\u8282\u6d41&#xff0c;\u5185\u5b58\u8d85\u9650 OOMKilled\u3002<\/li>\n<li>Pod \u63a2\u9488&#xff1a;Liveness \u5f02\u5e38\u91cd\u542f\u5bb9\u5668&#xff1b;Readiness \u5931\u8d25\u6458\u9664 Service \u540e\u7aef\u7aef\u70b9&#xff0c;\u4fdd\u969c\u6269\u7f29\u5bb9\u3001\u6eda\u52a8\u66f4\u65b0\u4e1a\u52a1\u7a33\u5b9a\u6027&#xff0c;web \u4e1a\u52a1\u751f\u4ea7\u5fc5\u987b\u914d\u7f6e\u3002<\/li>\n<li>K8s \u5b89\u5168\u4f53\u7cfb&#xff1a;API \u8bbf\u95ee\u7ecf\u8fc7 TLS\u3001\u8ba4\u8bc1\u3001\u9274\u6743\u3001\u51c6\u5165\u63a7\u5236&#xff1b;X509 \u8bc1\u4e66\u5b9e\u73b0\u5916\u90e8\u7528\u6237&#xff1b;RBAC \u5b9e\u73b0\u7ec6\u7c92\u5ea6\u6743\u9650&#xff0c;\u533a\u5206\u547d\u540d\u7a7a\u95f4 Role \u548c\u96c6\u7fa4 ClusterRole\u3002<\/li>\n","protected":false},"excerpt":{"rendered":"<p>&#x1f4dd;\u6458\u8981<br \/>\n\u672c\u6587\u5b8c\u6574\u8bb2\u89e3 K8s \u547d\u540d\u7a7a\u95f4\u8d44\u6e90\u914d\u989d ResourceQuota\u3001LimitRange \u8303\u56f4\u9650\u5236&#xff0c;\u8be6\u89e3 request\/limits \u539f\u7406&#xff0c;CPU \u5185\u5b58 OOM \u73b0\u8c61&#xff1b;\u8be6\u89e3 Pod \u4e09\u5927\u63a2\u9488 liveness\/readiness\/startupProbe&#xff0c;httpGet\/exec\/tcpSocket \u63a2\u6d4b\u65b9\u5f0f&#xff1b;\u68b3\u7406 K8s API \u8bbf\u95ee\u94fe\u8def&#xff1a;\u8ba4\u8bc1\u3001\u9274\u6743\u3001\u51c6\u5165\u63a7\u5236&amp;#<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[120,44],"topic":[],"class_list":["post-95581","post","type-post","status-publish","format-standard","hentry","category-server","tag-kubernetes","tag-44"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/95581.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"&#x1f4dd;\u6458\u8981 \u672c\u6587\u5b8c\u6574\u8bb2\u89e3 K8s \u547d\u540d\u7a7a\u95f4\u8d44\u6e90\u914d\u989d ResourceQuota\u3001LimitRange \u8303\u56f4\u9650\u5236&#xff0c;\u8be6\u89e3 request\/limits \u539f\u7406&#xff0c;CPU \u5185\u5b58 OOM \u73b0\u8c61&#xff1b;\u8be6\u89e3 Pod \u4e09\u5927\u63a2\u9488 liveness\/readiness\/startupProbe&#xff0c;httpGet\/exec\/tcpSocket \u63a2\u6d4b\u65b9\u5f0f&#xff1b;\u68b3\u7406 K8s API \u8bbf\u95ee\u94fe\u8def&#xff1a;\u8ba4\u8bc1\u3001\u9274\u6743\u3001\u51c6\u5165\u63a7\u5236&amp;#\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/95581.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-26T08:40:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260826084030-6a8ea67e04d06.svg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"29 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/95581.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/95581.html\",\"name\":\"\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-08-26T08:40:31+00:00\",\"dateModified\":\"2026-08-26T08:40:31+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/95581.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/95581.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/95581.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/95581.html","og_locale":"zh_CN","og_type":"article","og_title":"\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"&#x1f4dd;\u6458\u8981 \u672c\u6587\u5b8c\u6574\u8bb2\u89e3 K8s \u547d\u540d\u7a7a\u95f4\u8d44\u6e90\u914d\u989d ResourceQuota\u3001LimitRange \u8303\u56f4\u9650\u5236&#xff0c;\u8be6\u89e3 request\/limits \u539f\u7406&#xff0c;CPU \u5185\u5b58 OOM \u73b0\u8c61&#xff1b;\u8be6\u89e3 Pod \u4e09\u5927\u63a2\u9488 liveness\/readiness\/startupProbe&#xff0c;httpGet\/exec\/tcpSocket \u63a2\u6d4b\u65b9\u5f0f&#xff1b;\u68b3\u7406 K8s API \u8bbf\u95ee\u94fe\u8def&#xff1a;\u8ba4\u8bc1\u3001\u9274\u6743\u3001\u51c6\u5165\u63a7\u5236&amp;#","og_url":"https:\/\/www.wsisp.com\/helps\/95581.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-08-26T08:40:31+00:00","og_image":[{"url":"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260826084030-6a8ea67e04d06.svg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"29 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/95581.html","url":"https:\/\/www.wsisp.com\/helps\/95581.html","name":"\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-08-26T08:40:31+00:00","dateModified":"2026-08-26T08:40:31+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/95581.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/95581.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/95581.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"\u5403\u900f K8s \u8d44\u6e90\u7ba1\u63a7 + \u5065\u5eb7\u63a2\u9488 + RBAC \u6743\u9650\uff0c\u9762\u8bd5 80% \u8003\u70b9\u5168\u5728\u8fd9\u91cc\uff01"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/95581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=95581"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/95581\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=95581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=95581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=95581"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=95581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}