真题解析
题目


解析
修改 kube-apiserver 配置(CP 节点执行)
vim /etc/kubernetes/manifests/kube-apiserver.yaml
- --authorization-mode=Node,RBAC
- --enable-bootstrap-token-auth=true修改 kubelet 配置(所有节点执行)
vim /var/lib/kubelet/config.yaml
authentication:
anonymous:
enabled: false
authorization:
mode: Webhook# 重启 kubelet 服务
systemctl daemon-reload
systemctl restart kubelet修改 etcd 配置(CP 节点执行)
vim /etc/kubernetes/manifests/etcd.yaml
- --client-cert-auth=trueLast updated