第 6 章 Cluster Administrator 设置
认证
使用 AllowAll Authentication 方法设置身份验证。
AllowAll Authentication
设置允许所有密码的身份验证模型。编辑 OpenShift 主控机上的 /etc/origin/master/master-config.yaml,并将 DenyAllPasswordIdentityProvider 的值改为 AllowAllPasswordIdentityProvider。然后重新启动 OpenShift 主控机。
现在,验证模型已被设置,以一个用户身份登录,如 admin/admin:
# oc login openshift master e.g. https://1.1.1.1:8443 --username=admin --password=admin为 admin 用户帐户授予 cluster-admin 角色。
# oc login -u system:admin -n default Logged into "https:// <<openshift_master_fqdn>>:8443" as "system:admin" using existing credentials. You have access to the following projects and can switch between them with 'oc project <projectname>': *default glusterfs infra-storage kube-public kube-system management-infra openshift openshift-infra openshift-logging openshift-node openshift-sdn openshift-web-console Using project "default". # oc adm policy add-cluster-role-to-user cluster-admin admin cluster role "cluster-admin" added: "admin"
有关身份验证方法的详情请参考 https://access.redhat.com/documentation/en-us/openshift_container_platform/3.11/html-single/configuring_clusters/#identity-providers-configuring。