kubectl:无法识别“csr.yaml”:版本“certificates.k8s.io/v1”中的类型“CertificateSigningRequest”不匹配

use*_*898 4 kubernetes kubectl certificate-signing-request

我有这个模板,我尝试调用:查看此处的文档示例

--- 
apiVersion: certificates.k8s.io/v1
kind: CertificateSigningRequest
metadata: 
  name: vault-csr
spec: 
  groups: 
    - system: authenticated
  request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJRklEQ0NBd2dDQVFBd0lERWVNQndHQTFVRUF3d1ZkbUYxYkhRdWRtRjFiSFF0Y0dWeWMyOHVjM1pqTUlJQwpJakFOQmdrcWhraUc5dzBCQVFFRkFBT0NBZzhBTUlJQ0NnS0NBZ0VBdFJubkFQR2R4bG1xdjhMOW1Gc29YOXJuCk9JcTVGTnJMZmRDelZCVEVnUEV6TDgzSWFsT1cya2lrNWFRM282d2NSTmx1S3NzeUl1c0ZUSTFqR2djWjN0eXkKSDFqMlROMmNHMHp4MGVaYTJqK3JMVkkwSmVTdXFHNkdmY01rRzRudUhZSGJraDZUYmgyalc5S0RTUTVRekNzdwo0Rlg4bDZXVEVILzdSemgwNCt0RkdFamxVVktkakJYcnVqMnhBc0NqemJ2Sy9GaEhLRjJwRVpza1pSNWtCbC80Cm1KL2xHUTRUTysyVW5CbmsvalJJd3g5a0ZGWDhucEhGWxxxLS0K
  signerName: kubernetes.io/kubelet-serving
  usages:
  - digital signature
  - key encipherment
  - server auth
Run Code Online (Sandbox Code Playgroud)

kubectl 的版本:

$ kubectl version --short
Client Version: v1.20.0
Server Version: v1.18.9-eks-d1db3c
Run Code Online (Sandbox Code Playgroud)

我在使用 AWS EKS 时不断收到:

$ kubectl create -f csr.yaml
error: unable to recognize "csr.yaml": no matches for kind "CertificateSigningRequest" in version "certificates.k8s.io/v1"
Run Code Online (Sandbox Code Playgroud)

更改为 apiVersion 后更新:certificates.k8s.io/v1beta1

apiVersion: certificates.k8s.io/v1beta1
kind: CertificateSigningRequest
metadata: 
  name: vault-csr
spec: 
  groups: 
    - system: authenticated
  request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSB.....
  usages:
  - digital signature
  - key encipherment
  - server auth
Run Code Online (Sandbox Code Playgroud)

我现在收到这个错误:

$ kubectl create -f csr.yaml
error: error validating "tmp/csr.yaml": error validating data: ValidationError(CertificateSigningRequest.spec.groups[0]): invalid type for io.k8s.api.certificates.v1beta1.CertificateSigningRequestSpec.groups: got "map", expected "string"; if you choose to ignore these errors, turn validation off with --validate=false
Run Code Online (Sandbox Code Playgroud)

Kri*_*sia 7

根据K8s 变更文档,该API仅作为 K8s 版本的一部分CertificateSigningRequest进行升级。certificates.k8s.io/v11.19

在那之前它就在下面certificates.k8s.io/v1beta1

我怀疑这是一个问题,因为您的服务器版本是v1.18

apiVersion因此,尝试如下更改:

apiVersion: certificates.k8s.io/v1beta1