userGroups: ["system:nodes"]
verbs: ["get"]
resources:
- group: "" # core
resources: ["nodes"]
- level: None
users:
- system:kube-controller-manager
- system:kube-scheduler
- system:serviceaccount:kube-system:endpoint-controller
verbs: ["get", "update"]
namespaces: ["kube-system"]
resources:
- group: "" # core
resources: ["endpoints","leases"]
А лог все равно есть
{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"Metadata","auditID":"05659cd3-e079-46f5-9311-e0bb4eb29d22","stage":"ResponseComplete","requestURI":"/apis/coordination.k8s.io/v1/namespaces/kube-system/leases/kube-scheduler?timeout=10s","verb":"update","user":{"username":"system:kube-scheduler","groups":["system:authenticated"]},"sourceIPs":["10.118.12.21"],"userAgent":"kube-scheduler/v1.19.2 (linux/amd64) kubernetes/f574309/leader-election","objectRef":{"resource":"leases","namespace":"kube-system","name":"kube-scheduler","uid":"0f28806f-f4d1-485f-a543-72be98c49042","apiGroup":"coordination.k8s.io","apiVersion":"v1","resourceVersion":"5652514"},"responseStatus":{"metadata":{},"code":200},"requestReceivedTimestamp":"2020-11-10T08:26:59.123758Z","stageTimestamp":"2020-11-10T08:26:59.127472Z","annotations":{"authorization.k8s.io/decision":"allow","authorization.k8s.io/reason":"RBAC: allowed by ClusterRoleBinding \"system:kube-scheduler\" of ClusterRole \"system:kube-scheduler\" to User \"system:kube-scheduler\""}}
А в чём собстревнно проблема? kube-scheduler сходил в coordination.k8s.io и взял себе lease
Так у меня закрыт lease
Обсуждают сегодня