Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

forbidden: User "system:anonymous" cannot #1

Open
zalmanzhao opened this issue Jul 3, 2019 · 0 comments
Open

forbidden: User "system:anonymous" cannot #1

zalmanzhao opened this issue Jul 3, 2019 · 0 comments

Comments

@zalmanzhao
Copy link

of Publicly-Trusted Certificates, v.1.1.6, from the CA/Browser Forum (https://cabforum.org);
specifically, section 10.2.3 ("Information Requirements").
secret/kube-apiserver created
secret/admin-kubeconfig created
secret/kube-controller-manager created
secret/kube-scheduler created
secret/kube-apiserver-ingress created
deployment.extensions/etcd created
service/etcd0 created
deployment.extensions/kube-apiserver created
ingress.extensions/k8s-on-k8s created
service/apiserver created
deployment.extensions/kube-controller-manager created
deployment.extensions/kube-scheduler created
Giving a 10 seconds for the API server to start...
Trying to connect to the hosted control plane...
.......AVAILABLE !
Client Version: version.Info{Major:"1", Minor:"9", GitVersion:"v1.9.0", GitCommit:"925c127ec6b946659ad0fd596fa959be43f0cc05", GitTreeState:"clean", BuildDate:"2018-09-09T18:02:47Z", GoVersion:"go1.9.2", Compiler:"gc", Platform:"linux/amd64"}
Server Version: version.Info{Major:"1", Minor:"9", GitVersion:"v1.9.0", GitCommit:"925c127ec6b946659ad0fd596fa959be43f0cc05", GitTreeState:"clean", BuildDate:"2017-12-15T20:55:30Z", GoVersion:"go1.9.2", Compiler:"gc", Platform:"linux/amd64"}
Deploying child cluster assets
Error from server (Forbidden): secrets is forbidden: User "system:anonymous" cannot create secrets in the namespace "kube-system"
Error from server (Forbidden): error when retrieving current configuration of:
Resource: "extensions/v1beta1, Resource=daemonsets", GroupVersionKind: "extensions/v1beta1, Kind=DaemonSet"
Name: "kube-proxy", Namespace: "kube-system"
Object: &{map["kind":"DaemonSet" "metadata":map["labels":map["k8s-app":"kube-proxy" "tier":"node"] "name":"kube-proxy" "namespace":"kube-system" "annotations":map["kubectl.kubernetes.io/last-applied-configuration":""]] "spec":map["template":map["metadata":map["annotations":map["scheduler.alpha.kubernetes.io/critical-pod":""] "creationTimestamp": "labels":map["k8s-app":"kube-proxy" "tier":"node"]] "spec":map["schedulerName":"default-scheduler" "securityContext":map[] "terminationGracePeriodSeconds":'\x1e' "volumes":[map["hostPath":map["path":"/usr/share/ca-certificates"] "name":"ssl-certs-host"] map["name":"secrets" "secret":map["defaultMode":'\u01a4' "secretName":"kubeconfig-proxy"]]] "containers":[map["command":["./hyperkube" "proxy" "--kubeconfig=/etc/kubernetes/secrets/kubeconfig-proxy" "--proxy-mode=iptables" "--hostname-override=$(NODE_NAME)" "--cluster-cidr=10.2.0.0/16"] "name":"kube-proxy" "terminationMessagePolicy":"File" "volumeMounts":[map["readOnly":%!q(bool=true) "mountPath":"/etc/ssl/certs" "name":"ssl-certs-host"] map["mountPath":"/etc/kubernetes/secrets" "name":"secrets" "readOnly":%!q(bool=true)]] "securityContext":map["privileged":%!q(bool=true)] "terminationMessagePath":"/dev/termination-log" "env":[map["name":"NODE_NAME" "valueFrom":map["fieldRef":map["apiVersion":"v1" "fieldPath":"spec.nodeName"]]]] "image":"gcr.io/google_containers/hyperkube:v1.7.2" "imagePullPolicy":"IfNotPresent" "resources":map[]]] "dnsPolicy":"ClusterFirst" "hostNetwork":%!q(bool=true) "restartPolicy":"Always"]] "templateGeneration":'\x01' "updateStrategy":map["rollingUpdate":map["maxUnavailable":'\x01'] "type":"RollingUpdate"] "selector":map["matchLabels":map["k8s-app":"kube-proxy" "tier":"node"]]] "apiVersion":"extensions/v1beta1"]}
from server for: "manifests/on-k8s/kube-proxy/kube-proxy.yaml": daemonsets.extensions "kube-proxy" is forbidden: User "system:anonymous" cannot get daemonsets.extensions in the namespace "kube-system"
Error from server (Forbidden): error when retrieving current configuration of:
Resource: "rbac.authorization.k8s.io/v1beta1, Resource=clusterroles", GroupVersionKind: "rbac.authorization.k8s.io/v1beta1, Kind=ClusterRole"
Name: "flannel", Namespace: ""

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant