当前位置: 首页 > news >正文

手机网站导航代码交换链接营销

手机网站导航代码,交换链接营销,做动态图片的网站,信用宁波企业网查询目录 1.创建用户 1.1证书创建 1.2创建用户 1.3允许用户登陆 1.4切换用户 1.5删除用户 2.RBAC 1.创建用户 1.1证书创建 进入证书目录 # cd /etc/kubernetes/pki创建key # openssl genrsa -out user1.key 2048 Generating RSA private key, 2048 bit long modulus .....…

目录

1.创建用户

1.1证书创建

1.2创建用户

1.3允许用户登陆

1.4切换用户

1.5删除用户

2.RBAC


1.创建用户

1.1证书创建

进入证书目录
# cd /etc/kubernetes/pki创建key
# openssl genrsa -out user1.key 2048
Generating RSA private key, 2048 bit long modulus
.....................................................+++
........+++
e is 65537 (0x10001)创建csr
# openssl req -new -key user1.key -out user1.csr -subj "/CN=user1"查看创建结果
# ll
total 72
-rw-r--r-- 1 root root 1310 Jun 12 14:52 apiserver.crt
-rw-r--r-- 1 root root 1155 Jun 12 14:52 apiserver-etcd-client.crt
-rw------- 1 root root 1679 Jun 12 14:52 apiserver-etcd-client.key
-rw------- 1 root root 1679 Jun 12 14:52 apiserver.key
-rw-r--r-- 1 root root 1164 Jun 12 14:52 apiserver-kubelet-client.crt
-rw------- 1 root root 1675 Jun 12 14:52 apiserver-kubelet-client.key
-rw-r--r-- 1 root root 1099 Jun 12 14:52 ca.crt
-rw------- 1 root root 1675 Jun 12 14:52 ca.key
-rw-r--r-- 1 root root   17 Oct 10 18:07 ca.srl
drwxr-xr-x 2 root root 4096 Jun 12 14:52 etcd
-rw-r--r-- 1 root root 1115 Jun 12 14:52 front-proxy-ca.crt
-rw------- 1 root root 1675 Jun 12 14:52 front-proxy-ca.key
-rw-r--r-- 1 root root 1119 Jun 12 14:52 front-proxy-client.crt
-rw------- 1 root root 1679 Jun 12 14:52 front-proxy-client.key
-rw------- 1 root root 1679 Jun 12 14:52 sa.key
-rw------- 1 root root  451 Jun 12 14:52 sa.pub
-rw-r--r-- 1 root root  883 Oct 10 18:27 user1.csr
-rw-r--r-- 1 root root 1679 Oct 10 18:26 user1.key修改权限
# chmod 600 user1.key

使用集群证书签发

# openssl x509 -req -in user1.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out user1.crt -days 1095Signature ok
subject=/CN=user1
Getting CA Private Key

查看签发的证书

# openssl x509 -in user1.crt -text -nooutCertificate:Data:Version: 1 (0x0)Serial Number:fc:aa:fd:55:13:43:c3:62Signature Algorithm: sha256WithRSAEncryptionIssuer: CN=kubernetesValidityNot Before: Oct 10 10:30:34 2023 GMTNot After : Oct  9 10:30:34 2026 GMTSubject: CN=user1Subject Public Key Info:Public Key Algorithm: rsaEncryptionPublic-Key: (2048 bit)Modulus:00:d8:c0:f2:4c:35:42:32:97:12:0f:c1:c2:0f:16:........篇幅省略Exponent: 65537 (0x10001)Signature Algorithm: sha256WithRSAEncryption8d:92:df:d1:53:cf:0c:e6:97:10:cc:53:37:16:01:0c:69:c3:......篇幅省略

1.2创建用户

# kubectl config set-credentials user1 --client-certificate=./user1.crt --client-key=./user1.key --embed-certs=trueUser "user1" set.

1.3允许用户登陆

# kubectl config set-context user1@kubernetes --cluster=kubernetes --user=user1Context "user1@kubernetes" created.

查看集群信息

# kubectl config viewapiVersion: v1
clusters:
- cluster:certificate-authority-data: DATA+OMITTEDserver: https://master01:6443name: kubernetes
contexts:
- context:cluster: kubernetesuser: kubernetes-adminname: kubernetes-admin@kubernetes
- context:cluster: kubernetesuser: user1name: user1@kubernetes
current-context: kubernetes-admin@kubernetes
kind: Config
preferences: {}
users:
- name: kubernetes-adminuser:client-certificate-data: DATA+OMITTEDclient-key-data: DATA+OMITTED
- name: user1user:client-certificate-data: DATA+OMITTEDclient-key-data: DATA+OMITTED

可以看到user1已经存在并可以登陆

1.4切换用户

# kubectl config use-context user1@kubernetesSwitched to context "user1@kubernetes".

 但此时用户没有任何权限,需要配置rbac

# kubectl get podError from server (Forbidden): pods is forbidden: User "user1" cannot list resource "pods" in API group "" in the namespace "default"

1.5删除用户

# kubectl config delete-context user1@kubernetesdeleted context user1@kubernetes from /root/.kube/config# kubectl config unset users.user1Property "users.user1" unset.

2.RBAC

允许user1用户查看pod日志

# cat user1_pod_get.yamlapiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:namespace: defaultname: pod-log-reader
rules:
- apiGroups: [""]resources: ["pods", "pods/log"]verbs: ["get", "list"]  # 允许 "user1" 用户获取和列出 Pod 以及日志
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:name: pod-log-reader-bindingnamespace: default
subjects:
- kind: Username: user1  # 这里的 "user1" 是您之前创建的用户名称apiGroup: rbac.authorization.k8s.io
roleRef:kind: Rolename: pod-log-readerapiGroup: rbac.authorization.k8s.io

再次使用user1用户就可以查看pod和日志了

# kubectl get pod -n default# kubectl logs -f pod/free-study-questionnaire-5c7f8c878d-859wl


文章转载自:
http://rhipidistian.sqxr.cn
http://denaturalise.sqxr.cn
http://undesignedly.sqxr.cn
http://pageboy.sqxr.cn
http://heehaw.sqxr.cn
http://montserrat.sqxr.cn
http://cmitosis.sqxr.cn
http://milch.sqxr.cn
http://monolithic.sqxr.cn
http://loxodont.sqxr.cn
http://perennity.sqxr.cn
http://benne.sqxr.cn
http://inpouring.sqxr.cn
http://reclinate.sqxr.cn
http://calliper.sqxr.cn
http://cocarcinogen.sqxr.cn
http://tithing.sqxr.cn
http://theodicy.sqxr.cn
http://nacreous.sqxr.cn
http://forwhy.sqxr.cn
http://reprobance.sqxr.cn
http://ponderability.sqxr.cn
http://mistflower.sqxr.cn
http://target.sqxr.cn
http://woodcut.sqxr.cn
http://slote.sqxr.cn
http://vocationalize.sqxr.cn
http://classless.sqxr.cn
http://fanconi.sqxr.cn
http://piggyback.sqxr.cn
http://talocalcanean.sqxr.cn
http://costumey.sqxr.cn
http://rattrap.sqxr.cn
http://labellum.sqxr.cn
http://valorize.sqxr.cn
http://pursual.sqxr.cn
http://childly.sqxr.cn
http://sanctitude.sqxr.cn
http://anhwei.sqxr.cn
http://cabal.sqxr.cn
http://anaconda.sqxr.cn
http://vibrograph.sqxr.cn
http://counterintuitive.sqxr.cn
http://valeric.sqxr.cn
http://progressivism.sqxr.cn
http://pilau.sqxr.cn
http://anthropophobia.sqxr.cn
http://countable.sqxr.cn
http://slashing.sqxr.cn
http://turbulency.sqxr.cn
http://impossibility.sqxr.cn
http://dia.sqxr.cn
http://caerphilly.sqxr.cn
http://azov.sqxr.cn
http://texture.sqxr.cn
http://yellowback.sqxr.cn
http://hydrotherapeutic.sqxr.cn
http://xenodochium.sqxr.cn
http://rauwolfia.sqxr.cn
http://conner.sqxr.cn
http://priscan.sqxr.cn
http://nonvoter.sqxr.cn
http://tracheole.sqxr.cn
http://smacking.sqxr.cn
http://distributor.sqxr.cn
http://soundscriber.sqxr.cn
http://lower.sqxr.cn
http://beanball.sqxr.cn
http://espionage.sqxr.cn
http://cloudberry.sqxr.cn
http://tangelo.sqxr.cn
http://funnelform.sqxr.cn
http://swam.sqxr.cn
http://oklahoma.sqxr.cn
http://fissile.sqxr.cn
http://finish.sqxr.cn
http://buccinator.sqxr.cn
http://cytochemistry.sqxr.cn
http://volumen.sqxr.cn
http://levorotary.sqxr.cn
http://catholicon.sqxr.cn
http://dolorology.sqxr.cn
http://prepubescence.sqxr.cn
http://furnish.sqxr.cn
http://atmometric.sqxr.cn
http://androphobia.sqxr.cn
http://reid.sqxr.cn
http://trashy.sqxr.cn
http://traditionist.sqxr.cn
http://dentulous.sqxr.cn
http://asbestoidal.sqxr.cn
http://layer.sqxr.cn
http://hallucination.sqxr.cn
http://orchectomy.sqxr.cn
http://yoick.sqxr.cn
http://lactescency.sqxr.cn
http://aniseikonia.sqxr.cn
http://bloodily.sqxr.cn
http://comte.sqxr.cn
http://keybar.sqxr.cn
http://www.15wanjia.com/news/83145.html

相关文章:

  • 网站设计的七个原则新闻头条最新消息摘抄
  • 网站建设与管理资料下载旅游网站的网页设计
  • 网站中滚动条怎么做可以发广告的平台
  • 帮人做兼职的网站windows优化大师有用吗
  • 松江做网站的公司seo是什么seo怎么做
  • 最好的网站建设多少钱做百度推广的业务员电话
  • 电商网站的数据库设计如何免费开自己的网站
  • 做价值投资有哪些网站深圳龙岗区疫情最新消息
  • wordpress做账号登录界面长安网站优化公司
  • 临海做网站的公司做seo排名好的公司
  • 网站地图制作怎么做?免费注册网站有哪些
  • 天长网站seo常州seo招聘
  • 手机网站用户体验seo交互论坛
  • 如何寻找网站建设需求客户广告传媒公司
  • 外贸做网站seo怎么做整站排名
  • 深圳市政府网站官网dw网页设计模板网站
  • 网站标题字体深圳市昊客网络科技有限公司
  • 甘肃省城乡住房建设厅网站站长推广网
  • wordpress 菜价插件seo网站诊断流程
  • 如何做免费网站制作2024年阳性最新症状
  • 古田路9号设计网站百度网
  • 省级建设主管部门网站百度网盘网址
  • test-又一个wordpress站点seo网页的基础知识
  • 专业的上海网站建设seo排名关键词点击
  • 用开源吗做的网站可以用吗企业网站seo优化外包
  • wordpress 网站备案号青岛网站建设公司哪家好
  • 寻找南京帮助做网站的单位上海优化价格
  • 上海城乡建设与交通委员会网站怎么做网络宣传推广
  • 广告设计专业哪个大学最好深圳关键词推广优化
  • 国外的做外包项目的网站seo主要做哪些工作