Kubernetes 应用要求
集群填写的是 K8S 的集群地址
直接访问集群地址页面可以显示如下信息(如: https://172.16.8.8:8443),一般是 master 节点的 8443 端口
{"kind": "Status","apiVersion": "v1","metadata": {},"status": "Failure","message": "forbidden: User \"system:anonymous\" cannot get path \"/\"","reason": "Forbidden","details": {},"code": 403}
获取 TOKEN 方法
- 下面以 ko-admin 为例,如果你的系统中没有此账户可以使用其他有权限的账户或者新建
kubectl get secret -n kube-system
> kubectl get secret -n kube-systemNAME TYPE DATA AGEattachdetach-controller-token-qss79 kubernetes.io/service-account-token 3 44mbootstrap-signer-token-ftqb6 kubernetes.io/service-account-token 3 44mbootstrap-token-abcdef bootstrap.kubernetes.io/token 5 44mcertificate-controller-token-gm8mf kubernetes.io/service-account-token 3 44mclusterrole-aggregation-controller-token-92v9j kubernetes.io/service-account-token 3 44mcoredns-token-mjpwp kubernetes.io/service-account-token 3 44mcronjob-controller-token-bjdn5 kubernetes.io/service-account-token 3 44mdaemon-set-controller-token-6wljg kubernetes.io/service-account-token 3 44mdefault-token-9pl84 kubernetes.io/service-account-token 3 44mdeployment-controller-token-wbpq6 kubernetes.io/service-account-token 3 44mdisruption-controller-token-9mrbr kubernetes.io/service-account-token 3 44mendpoint-controller-token-hmgw5 kubernetes.io/service-account-token 3 44mendpointslice-controller-token-pbnkw kubernetes.io/service-account-token 3 44mendpointslicemirroring-controller-token-zkc6z kubernetes.io/service-account-token 3 44mexpand-controller-token-btlqv kubernetes.io/service-account-token 3 44mflannel-token-qc6kw kubernetes.io/service-account-token 3 42mgeneric-garbage-collector-token-j8c7c kubernetes.io/service-account-token 3 44mhorizontal-pod-autoscaler-token-v9d49 kubernetes.io/service-account-token 3 44mjob-controller-token-9pldd kubernetes.io/service-account-token 3 44mko-admin-token-kprl9 kubernetes.io/service-account-token 3 40mkube-proxy-token-9pfd2 kubernetes.io/service-account-token 3 44mmetrics-server-token-cmdpk kubernetes.io/service-account-token 3 41mnamespace-controller-token-k94nh kubernetes.io/service-account-token 3 44mnfs-client-provisioner-token-pb5qx kubernetes.io/service-account-token 3 28mnginx-ingress-serviceaccount-token-vk8tm kubernetes.io/service-account-token 3 41mnode-controller-token-v5k59 kubernetes.io/service-account-token 3 44mpersistent-volume-binder-token-jfgm7 kubernetes.io/service-account-token 3 44mpod-garbage-collector-token-7lptd kubernetes.io/service-account-token 3 44mpv-protection-controller-token-fpqqm kubernetes.io/service-account-token 3 44mpvc-protection-controller-token-wcrmp kubernetes.io/service-account-token 3 44mreplicaset-controller-token-9g9s7 kubernetes.io/service-account-token 3 44mreplication-controller-token-xg4fq kubernetes.io/service-account-token 3 44mresourcequota-controller-token-lskn4 kubernetes.io/service-account-token 3 44mroot-ca-cert-publisher-token-sdt67 kubernetes.io/service-account-token 3 44mservice-account-controller-token-2xr8k kubernetes.io/service-account-token 3 44mservice-controller-token-9dghl kubernetes.io/service-account-token 3 44mstatefulset-controller-token-wqm5v kubernetes.io/service-account-token 3 44mtoken-cleaner-token-gv552 kubernetes.io/service-account-token 3 44mttl-controller-token-cgqcd kubernetes.io/service-account-token 3 44m
kubectl describe secret ko-admin-token-kprl9 -n kube-system
> kubectl describe secret ko-admin-token-kprl9 -n kube-systemName: ko-admin-token-kprl9Namespace: kube-systemLabels: <none>Annotations: kubernetes.io/service-account.name: ko-adminkubernetes.io/service-account.uid: 8be05ad6-83ce-483b-9324-7c3f041c6da1Type: kubernetes.io/service-account-tokenData====ca.crt: 1038 bytesnamespace: 11 bytestoken: eyJhbGciOiJSUzI1NiIsImtpZCI6ImlCVkhHTlhHem9idXNtYmtsaVpDZXRESVFMSHRFNUdsOFJWOXc0MnRZTG8ifQ.eyJpc3MiOiJrdWJlcm5ldGVzL3NlcnZpY2VhY2NvsA50Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9uYW1lc3BhY2UiOiJrdWJlLXN5c3RlbSIsImt1YmAxbmV0ZXMuaW8vc6VydmljZWFjY291bnQvc2VjcmV0Lm5hbWUiOiJrby1hZG1pbi10b2tlbi1rcHJsOSIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2AxdmljZS1hY2NvdW50Lm5hbQAiOiJrby1hZG1pbiIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFiQ291bnQvc2VydmljZS1hY2NvdW50LnVpZCI6IjhiZTA1YWQ2LTgzY2UtNDgzYi05MzI0LTdjM2YwNDFjNmRhMSIsInN1YiI6InN5c3RlbTpzZXJ2aWNlYWNjb3VudDprdWJlLXN5c3RlbTprby1hZG1pbiJ9.qP04Yd6sTf5IDbQ_9lF_VdoyBEN5UCBmp1P7tvv9Fn9ibZFOGsupXjzbxCMhu3HhkGSE1pUuu1NNmcJUCUb_pFi5x5Bvo2xkF1_SfQACo40kzrUQ9ATTX8wuDzpiNw9sjf-_1l7rwnseOC4WJYNQIOs9i9FOeyRPYbKvkwsysJBVCq_XkoqvZt9xPp-LtsMUdWKHhLKUkBBM5F1NpVyahSrrsgH2lRuNsGALGb0FGIwYfMWN6KaHim2eeOaH4nqnVJ0WGCVJNx9-_PJQXfFWZtnceF_IiTUGwC7fqrA7T-5vOafPvG7c6PgjPzgMyEo4ade1bRV3fM98gHs_5v-oVw
上面 token: 后面的内容就是我们需要的 token,把这个内容填写到 JumpServer 系统用户里面即可
当前内容版权归 JumpServer 或其关联方所有,如需对内容或内容相关联开源项目进行关注与资助,请访问 JumpServer .