Difference between revisions of "Kubernetes service account"

From wikieduonline
Jump to navigation Jump to search
 
(5 intermediate revisions by the same user not shown)
Line 10: Line 10:
  
 
== Commands ==
 
== Commands ==
* <code>[[kubectl get serviceaccounts]], [[kubectl get sa]], [[kubectl get sa -n kube-system]]</code>
+
* <code>[[kubectl get serviceaccounts]], [[kubectl get sa]]</code>
 +
** <code>[[kubectl get sa -n kube-system]]</code>
 
* <code>[[kubectl create serviceaccount]], [[kubectl create sa]]</code>
 
* <code>[[kubectl create serviceaccount]], [[kubectl create sa]]</code>
 
* <code>[[kubectl describe sa]]</code>
 
* <code>[[kubectl describe sa]]</code>
Line 21: Line 22:
 
* <code>Error creating: pods "your_pod" [[is forbidden]]: [[error looking up service account]] default/your_service_account: serviceaccount "your_service_account" [[not found]]</code>
 
* <code>Error creating: pods "your_pod" [[is forbidden]]: [[error looking up service account]] default/your_service_account: serviceaccount "your_service_account" [[not found]]</code>
 
* {{impersonator}}
 
* {{impersonator}}
 +
 +
== Changelog ==
 +
* Conflicting issuers between [[JWT authenticators]] and service account config are now detected and fail on API server startup.
  
 
== Related ==
 
== Related ==
Line 32: Line 36:
 
* <code>[[system:]]</code>
 
* <code>[[system:]]</code>
 
* [[ServiceAccount admission controller]]: <code>[[/var/run/secrets/kubernetes.io/serviceaccount]]</code>
 
* [[ServiceAccount admission controller]]: <code>[[/var/run/secrets/kubernetes.io/serviceaccount]]</code>
* [[default]]
+
* <code>[[default]]</code>
 +
* [[kubectl describe clusterrolebindings]]
 +
* [[Kubernetes users]], [[Kubernetes groups]]
  
 
== Activities ==
 
== Activities ==
Line 42: Line 48:
 
* {{Kubernetes Authentication}}
 
* {{Kubernetes Authentication}}
 
* {{Kubernetes RBAC}}
 
* {{Kubernetes RBAC}}
 +
* {{Kubernetes users}}
  
 
[[Category:K8s]]
 
[[Category:K8s]]

Latest revision as of 14:01, 4 April 2024

system:serviceaccount: (singular) is the prefix for service account usernames.
system:serviceaccounts: (plural) is the prefix for service account groups.

Commands[edit]


Helm v2 (deprecated)

Errors[edit]

Changelog[edit]

  • Conflicting issuers between JWT authenticators and service account config are now detected and fail on API server startup.

Related[edit]

Activities[edit]

See also[edit]

Advertising: