This documentation is for a release that is no longer maintained
See documentation for the latest supported version 3 or the latest supported version 4.2.3.3. 禁用项目自助置备
您可以防止经过身份验证的用户组自助置备新项目。
流程
-
以具有
cluster-admin
特权的用户身份登录。 运行以下命令,以查看
self-provisioners
集群角色绑定用法:oc describe clusterrolebinding.rbac self-provisioners
$ oc describe clusterrolebinding.rbac self-provisioners
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 输出示例
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 检查
self-provisioners
部分中的主题。从
system:authenticated:oauth
组中移除self-provisioner
集群角色。如果
self-provisioners
集群角色绑定仅将self-provisioner
角色绑定至system:authenticated:oauth
组,请运行以下命令:oc patch clusterrolebinding.rbac self-provisioners -p '{"subjects": null}'
$ oc patch clusterrolebinding.rbac self-provisioners -p '{"subjects": null}'
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 如果
self-provisioners
集群角色将self-provisioner
角色绑定到system:authenticated:oauth
组以外的多个用户、组或服务帐户,请运行以下命令:oc adm policy \ remove-cluster-role-from-group self-provisioner \ system:authenticated:oauth
$ oc adm policy \ remove-cluster-role-from-group self-provisioner \ system:authenticated:oauth
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
编辑
self-provisioners
集群角色绑定,以防止自动更新角色。自动更新会使集群角色重置为默认状态。使用 CLI 更新角色绑定:
运行以下命令:
oc edit clusterrolebinding.rbac self-provisioners
$ oc edit clusterrolebinding.rbac self-provisioners
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 在显示的角色绑定中,将
rbac.authorization.kubernetes.io/autoupdate
参数值设置为false
,如下例所示:Copy to Clipboard Copied! Toggle word wrap Toggle overflow
使用单个命令更新角色绑定:
oc patch clusterrolebinding.rbac self-provisioners -p '{ "metadata": { "annotations": { "rbac.authorization.kubernetes.io/autoupdate": "false" } } }'
$ oc patch clusterrolebinding.rbac self-provisioners -p '{ "metadata": { "annotations": { "rbac.authorization.kubernetes.io/autoupdate": "false" } } }'
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
以通过身份验证的用户身份登陆,验证是否无法再自助置备项目:
oc new-project test
$ oc new-project test
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 输出示例
Error from server (Forbidden): You may not request a new project via this API.
Error from server (Forbidden): You may not request a new project via this API.
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 您可以对此项目请求消息进行自定义,以提供特定于您的组织的更多有用说明。