[Kubernetes] Role, Clusterrole, Binding
๐ ๋ค์ด๊ฐ๋ฉฐ
์ด๋ฒ ๊ธ์์๋ ์ฟ ๋ฒ๋คํฐ์ค์ ๋ณด์ 3์์๋ฅผ ์ ๋ฆฌํ๋ค. RBAC(๋๊ฐ ๋ฌด์์ ํ ์ ์๋๊ฐ), ServiceAccount(ํ๋์ ์ ์), NetworkPolicy(ํ๋ ๊ฐ ํต์ ํต์ )๋ฅผ ํตํด ํด๋ฌ์คํฐ์ ์ ํ๋ฆฌ์ผ์ด์ ์ ๋ณดํธํ๋ค.
๋ณด์์ ๋ ์ถ โ RBAC๋ โ๋๊ฐ ์ด๋ค ๋ฆฌ์์ค์ ๋ฌด์จ ์์ ์ ํ ์ ์๋๊ฐโ(์ ๊ทผ ์ ์ด)๋ฅผ, NetworkPolicy๋ โ์ด๋ค ํ๋๊ฐ ์ด๋ค ํ๋์ ํต์ ํ ์ ์๋๊ฐโ(๋คํธ์ํฌ ์ ์ด)๋ฅผ ๋ด๋นํ๋ค. ๋์ ์๋ก ๋ค๋ฅธ ๊ณ์ธต์ ์งํจ๋ค.
1. RBAC โ Role & Binding
RBAC(Role-Based Access Control)๋ ์ญํ (Role/ClusterRole)์ ์ ์ํ๊ณ ๋ฐ์ธ๋ฉ(RoleBinding/ClusterRoleBinding)์ผ๋ก ์ฌ์ฉ์์๊ฒ ๋ถ์ฌํ๋ค.
flowchart LR
Role["๐ Role<br/>(๊ถํ ์ ์)"]
Binding["๐ RoleBinding"]
User["๐ค User / SA"]
Role --> Binding --> User
| ์ค๋ธ์ ํธ | ๋ฒ์ |
|---|---|
| Role / RoleBinding | ํน์ ๋ค์์คํ์ด์ค |
| ClusterRole / ClusterRoleBinding | ํด๋ฌ์คํฐ ์ ์ฒด |
Role & RoleBinding (๋ค์์คํ์ด์ค ๋ฒ์)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
# Role โ dev-ns์์ ํ๋ ์กฐํ ๊ถํ
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
namespace: dev-ns
name: pod-reader
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list", "watch"]
---
# RoleBinding โ dev-user์๊ฒ ๋ถ์ฌ
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-pods
namespace: dev-ns
subjects:
- kind: User
name: "dev-user"
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: Role
name: pod-reader
apiGroup: rbac.authorization.k8s.io
ClusterRole & ClusterRoleBinding (ํด๋ฌ์คํฐ ๋ฒ์)
1
2
3
4
5
6
7
8
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: cluster-admin-role
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list", "watch", "delete"]
๐ก Role์ โ๊ถํ์ ์ ์โ, Binding์ โ๊ถํ์ ๋ถ์ฌโ๋ก ๋ถ๋ฆฌ๋์ด ์๋ค. ์ด ๋ถ๋ฆฌ ๋๋ถ์ ํ๋์ Role์ ์ฌ๋ฌ ์ฌ์ฉ์์๊ฒ ์ฌ์ฌ์ฉํ ์ ์๋ค.
verbs(get/list/delete ๋ฑ)์resources(pods ๋ฑ)์ ์กฐํฉ์ผ๋ก ์ธ๋ฐํ๊ฒ ๊ถํ์ ์ ํ๋ค.
2. ServiceAccount โ ํ๋์ ์ ์
ServiceAccount(SA)๋ ํ๋๊ฐ API ์๋ฒ์ ์ํธ์์ฉํ ๋ ์ฐ๋ ๊ณ์ ์ด๋ค. ์ฌ๋์ด ์๋๋ผ ์ ํ๋ฆฌ์ผ์ด์ (ํ๋)์ ์ ์์ด๋ค.
1
kubectl create serviceaccount dev-sa -n dev-ns
1
2
3
4
5
6
7
8
9
10
11
12
apiVersion: v1
kind: Pod
metadata:
name: sa-pod
namespace: dev-ns
spec:
serviceAccountName: dev-sa # ์ด SA์ ๊ถํ์ผ๋ก API ์ ๊ทผ
containers:
- name: nginx
image: nginx
ports:
- containerPort: 80
๐ก User๋ ์ฌ๋, ServiceAccount๋ ํ๋(์ฑ)์ ๊ณ์ ์ด๋ค. ํ๋๊ฐ API ์๋ฒ์ ์์ฒญํ ๋ SA์ ๊ถํ์ ๋ฐ๋ฅด๋ฏ๋ก, SA์ RBAC๋ฅผ ๋ฐ์ธ๋ฉํด ํ๋๊ฐ ํ ์ ์๋ ์ผ์ ์ ํํ๋ค.
3. NetworkPolicy โ ํ๋ ํต์ ํต์
NetworkPolicy๋ ํ๋ ๊ฐยท์ธ๋ถ์์ ํธ๋ํฝ์ ์ ์ดํ๋ค.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# ๋ชจ๋ ํธ๋ํฝ ์ฐจ๋จ (myapp ํ๋)
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: deny-all-traffic
namespace: default
spec:
podSelector:
matchLabels:
app: myapp
policyTypes:
- Ingress
- Egress
ingress: []
egress: []
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
# ํน์ ๋์ญยทํฌํธ๋ง ํ์ฉ
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-specific-traffic
namespace: default
spec:
podSelector:
matchLabels:
app: myapp
policyTypes:
- Ingress
ingress:
- from:
- ipBlock:
cidr: 192.168.1.0/24
ports:
- protocol: TCP
port: 80
โ ๏ธ NetworkPolicy๋ CNI๊ฐ ์ง์ํด์ผ ๋์ํ๋ค. Calico ๊ฐ์ ์ ์ฑ ์ง์ CNI๊ฐ ์์ผ๋ฉด ์ ์ฑ ์ ๋ง๋ค์ด๋ ๋ฌด์๋๋ค. ๋ ๊ธฐ๋ณธ๊ฐ์ โ๋ชจ๋ ํ์ฉโ์ด๋ผ, ํ ๋ฒ์ด๋ผ๋ ์ ์ฑ ์ด ๋ถ์ ํ๋๋ ๋ช ์์ ์ผ๋ก ํ์ฉํ ํธ๋ํฝ๋ง ํต๊ณผ์ํค๋ ํ์ดํธ๋ฆฌ์คํธ ๋ฐฉ์์ด ๋๋ค.
4. Dashboard ๋ณด์ ๊ตฌ์ฑ ์์
Dashboard์ ๊ด๋ฆฌ์ ๊ถํ์ ์ฃผ๋ ค๋ฉด SA๋ฅผ ๋ง๋ค๊ณ cluster-admin์ ๋ฐ์ธ๋ฉํ๋ค.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
apiVersion: v1
kind: ServiceAccount
metadata:
name: admin-user
namespace: kubernetes-dashboard
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: admin-user
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: admin-user
namespace: kubernetes-dashboard
โ ๏ธ
cluster-admin์ ๋ชจ๋ ๊ถํ์ ๊ฐ์ง ์ต๊ฐ ์ญํ ์ด๋ค. ํธ์์ Dashboard ์ค์ต์ ์ฐ์ง๋ง, ์ค๋ฌด์์๋ ํ์ํ ๊ถํ๋ง ๋ด์ ์ปค์คํ ClusterRole์ ๋ง๋ค์ด ์ต์ ๊ถํ ์์น์ ์ง์ผ์ผ ํ๋ค.
๐ ์ ๋ฆฌ
1
2
3
4
5
์ฟ ๋ฒ๋คํฐ์ค ๋ณด์
โโ RBAC Role(์ ์) + Binding(๋ถ์ฌ), NS/ํด๋ฌ์คํฐ ๋ฒ์
โโ ServiceAccount ํ๋์ ์ ์(์ฑ์ API ์ ๊ทผ ๊ถํ)
โโ NetworkPolicy ํ๋ ๊ฐ ํต์ ํ์ดํธ๋ฆฌ์คํธ(CNI ํ์)
โโ ์์น ์ต์ ๊ถํ(cluster-admin ๋จ์ฉ X)
| ๊ฐ๋ | ํ ์ค ์ ์ |
|---|---|
| RBAC | ๋๊ฐยท๋ฌด์์ยทํ ์ ์๋๊ฐ |
| ServiceAccount | ํ๋(์ฑ)์ ๊ณ์ |
| NetworkPolicy | ํ๋ ํต์ ๋ฐฉํ๋ฒฝ |
์ฟ ๋ฒ๋คํฐ์ค ๋ณด์์ ํต์ฌ์ RBAC๋ก ์ ๊ทผ์, NetworkPolicy๋ก ํต์ ์ ํต์ ํ๋ ๊ฒ์ด๋ค. ํ๋์๋ ServiceAccount๋ก ์ ์์ ๋ถ์ฌํ๊ณ , ๋ชจ๋ ๊ถํ์ ์ต์ ๊ถํ ์์น์ผ๋ก ์ข๊ฒ ์ฃผ๋ ๊ฒ์ด ์์ ํ๋ค.
Comments powered by Disqus.