[zh] Enhance format in rbac.md

This commit is contained in:
Skeet WU
2022-04-08 17:36:50 +08:00
committed by GitHub
parent f764ec7338
commit 40b3832fe0
@@ -2097,6 +2097,7 @@ This is not a recommended policy.
下面的策略允许 **所有** 服务帐户充当集群管理员。 下面的策略允许 **所有** 服务帐户充当集群管理员。
容器中运行的所有应用程序都会自动收到服务帐户的凭据,可以对 API 执行任何操作, 容器中运行的所有应用程序都会自动收到服务帐户的凭据,可以对 API 执行任何操作,
包括查看 Secrets 和修改权限。这一策略是不被推荐的。 包括查看 Secrets 和修改权限。这一策略是不被推荐的。
{{< /warning >}}
```shell ```shell
kubectl create clusterrolebinding permissive-binding \ kubectl create clusterrolebinding permissive-binding \
@@ -2105,12 +2106,10 @@ kubectl create clusterrolebinding permissive-binding \
--user=kubelet \ --user=kubelet \
--group=system:serviceaccounts --group=system:serviceaccounts
``` ```
{{< /warning >}}
<!-- <!--
After you have transitioned to use RBAC, you should adjust the access controls After you have transitioned to use RBAC, you should adjust the access controls
for your cluster to ensure that these meet your information security needs. for your cluster to ensure that these meet your information security needs.
--> -->
在你完成到 RBAC 的迁移后,应该调整集群的访问控制,确保相关的策略满足你的 在你完成到 RBAC 的迁移后,应该调整集群的访问控制,确保相关的策略满足你的信息安全需求。
信息安全需求。