# 在v1.17.3中版本通过测试 apiVersion: v1 kind: ServiceAccount metadata: name: default namespace: default --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: default rules: - apiGroups: - '*' resources: - '*' verbs: - '*' --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: cluster-reader roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: default subjects: - kind: ServiceAccount name: default namespace: default
2 获得name
kubectl get secret -n kube-system
3 获得token
kubectl describe secret 这里换成刚刚获得的name -n kube-system