{"id":35864,"date":"2022-11-29T00:53:58","date_gmt":"2023-05-13T13:26:55","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/"},"modified":"2024-04-29T02:54:46","modified_gmt":"2024-04-28T18:54:46","slug":"%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/","title":{"rendered":"\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1"},"content":{"rendered":"<h2>\u9996\u5148<\/h2>\n<p>\u901a\u5e38\u60c5\u51b5\u4e0b\uff0cKubernetes\u5e76\u6ca1\u6709\u7528\u6237\u7ba1\u7406\u673a\u5236\uff0c\u9700\u8981\u501f\u52a9\u5916\u90e8\u673a\u5236\u6765\u8fdb\u884c\u7528\u6237\u8ba4\u8bc1\u3002\u5982\u679c\u4f7f\u7528kubeadm\u6216minikube\u7b49\u5de5\u5177\u6784\u5efa\u539f\u751f\u7684Kubernetes\u96c6\u7fa4\uff0c\u901a\u5e38\u4f1a\u4f7f\u7528x509\u8bc1\u4e66\u8fdb\u884c\u7528\u6237\u8ba4\u8bc1\uff08admin\u8bc1\u4e66\u53ef\u7528\u4e8e\u8ba4\u8bc1\uff09\u3002<\/p>\n<p>\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u5c06\u4f7f\u7528Keycloak\u4f5c\u4e3aOIDC\uff08OpenID Connect\uff09ID\u63d0\u4f9b\u8005\u4e4b\u4e00\u6765\u7ba1\u7406\u7528\u6237\u4fe1\u606f\u5e76\u8fdb\u884cOIDC\u8ba4\u8bc1\uff0c\u7136\u540e\u4f7f\u7528\u8be5\u8ba4\u8bc1\u4fe1\u606f\uff08id_token\uff09\u6765\u8fdb\u884cKubernetes\uff08API\uff09\u7684\u8ba4\u8bc1\u3002<\/p>\n<p>Keycloak\u662f\u4e00\u4e2a\u7f51\u7ad9\uff0c\u5176\u7f51\u5740\u662fhttps:\/\/www.keycloak.org\/\u3002<\/p>\n<p>\u53e6\u5916\uff0cKubernetes\u4e2d\u7684OIDC\u8ba4\u8bc1\u987a\u5e8f\u53ef\u4ee5\u53c2\u8003\u5b98\u65b9\u6587\u6863\u4e2d\u5982\u4e0b\u8bf4\u660e\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/5-0.png\" alt=\"pic0.png\" \/><\/div>\n<p>OpenID Connect\u4ee4\u724c<\/p>\n<p>https:\/\/kubernetes.io\/zh\/docs\/reference\/access-authn-authz\/authentication\/#openid-connect-tokens<\/p>\n<h2>\u524d\u63d0\u610f\u5473\u7740\u4e00\u4e2a\u524d\u9762\u7684\u6761\u4ef6\u6216\u5047\u8bbe\u3002 (The premise implies a previously stated condition or assumption.)<\/h2>\n<p>minikube v1.25.2(Kubernetes v1.23.3)\u306e\u30b7\u30f3\u30b0\u30ebNode\u69cb\u6210\u3067\u691c\u8a3c\u3057\u305f<\/p>\n<p>Keycloak\u306f\u73fe\u6642\u70b9\u306e\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u3042\u308bv18.0.0\u3092\u7528\u3044\u308b\u3053\u3068\u3068\u3057\u3001Kubernetes(minikube)\u30af\u30e9\u30b9\u30bf\u30fc\u4e0a\u306b\u69cb\u7bc9\u3057\u305f\uff08\u4e00\u822c\u7684\u306aKubernetes\u30af\u30e9\u30b9\u30bf\u30fc\u4e0a\u306b\u69cb\u7bc9\u3059\u308b\u30b1\u30fc\u30b9\u3067\u3082\u305d\u3093\u306a\u306b\u5927\u5dee\u306f\u306a\u3044\u60f3\u5b9a\uff09<br \/>\n\u691c\u8a3c\u7528\u306a\u306e\u3067Keycloak\u306f\u4ee5\u4e0b\u306e\u6761\u4ef6\u3067\u8d77\u52d5\u3057\u305f<\/p>\n<p>dev mode\uff08\u672c\u6765\u3067\u3042\u308c\u3070prod mode\u3067\u8d77\u52d5\u3059\u3079\u304d\uff09<\/p>\n<p>Keycloak\u306e\u30c7\u30fc\u30bf\u30b9\u30c8\u30a2\u306fInternal DB\uff08H2\uff09\u3092\u6c38\u7d9a\u5316\u3057\u3066\u5229\u7528\uff08\u672c\u6765\u3067\u3042\u308c\u3070PostgreSQL\u306a\u3069\u5916\u90e8DB\u3092\u5229\u7528\u3059\u3079\u304d\uff09<br \/>\n\u8a3c\u660e\u66f8\u306f\u81ea\u5df1\u8a3c\u660e\u66f8\u3092\u5229\u7528\u3057\u305f\uff08\u672c\u6765\u3067\u3042\u308c\u3070\u4fe1\u983c\u3067\u304d\u308bCA\u3067\u7f72\u540d\u3055\u308c\u305f\u3082\u306e\u3092\u5229\u7528\u3059\u3079\u304d\uff09<\/p>\n<p>Keycloak\u306e\u540d\u524d\u89e3\u6c7a\u306b\u306fDNS\u3067\u306f\u306a\u304fhosts\u30d5\u30a1\u30a4\u30eb\u3092\u4f7f\u7528\u3057\u305f<\/p>\n<p>Keycloak\u306b\u306f\u305d\u308c\u305e\u308ckube-apiserver\u3068\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u304c\u540c\u3058\u30db\u30b9\u30c8\u540d\u3067\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u5fc5\u8981\u304c\u3042\u308b\u305f\u3081\u66ab\u5b9a\u5bfe\u51e6<br \/>\n\u672c\u6765\u306fDNS\u306e\u540d\u524d\u89e3\u6c7a\u3067\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u306e\u304c\u671b\u307e\u3057\u3044<\/p>\n<p>Keycloak\u306e\u30a2\u30af\u30bb\u30b9\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\uff08HTTP\/HTTPS\uff09\u306fNodePort\u3068\u3057\u305f<\/p>\n<p>Keycloak\u306b\u306f\u305d\u308c\u305e\u308ckube-apiserver\u3068\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u304c\u540c\u3058\u30dd\u30fc\u30c8\u3067\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u5fc5\u8981\u304c\u3042\u308b\u305f\u3081\u66ab\u5b9a\u5bfe\u51e6<br \/>\n\u672c\u6765\u306fingress\u3084LB\u306b\u8a3c\u660e\u66f8\u306e\u30a4\u30f3\u30dd\u30fc\u30c8\u3092\u884c\u3044TLS\u7d42\u7aef\u3059\u3079\u304d<\/p>\n<p>\u57fa\u672c\u7684\u306bKeycloak\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u6cbf\u3063\u3066\u3044\u308b\u304c\u3001\u5fc5\u8981\u306b\u5fdc\u3058\u3066\u8a2d\u5b9a\u3092\u5909\u66f4\u3057\u3066\u3044\u308b<br \/>\nGetting started\/Kubernetes<br \/>\nhttps:\/\/www.keycloak.org\/getting-started\/getting-started-kube<\/p>\n<h2>3. \u521b\u5efaKeycloak\u7684\u8bc1\u4e66<\/h2>\n<p>\u9996\u5148\uff0c\u521b\u5efaKeycloak\u5c06\u7528\u4e8eTLS\u7684\u5bc6\u94a5\u5bf9\u3002<br \/>\n\u7136\u540e\uff0c\u5728Kubernetes\u96c6\u7fa4\u4e0a\uff0c\u901a\u8fc7hostPath\u5c06\u5bc6\u94a5\u5bf9\u6302\u8f7d\u5230\u90e8\u7f72Keycloak\u7684Pod\u4e0a\uff0c\u5728minikube\u865a\u62df\u673a\u4e0a\u6267\u884c\u521b\u5efa\u64cd\u4f5c\u3002<\/p>\n<p>\u8fde\u63a5\u5230minikube\u7684SSH\u3002<\/p>\n<pre class=\"post-pre\"><code>minikube ssh\r\n<\/code><\/pre>\n<p>\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u4f5c\u6210<\/p>\n<pre class=\"post-pre\"><code>sudo su -\r\nmkdir \/srv\/keycloak-ssl\r\ncd \/srv\/keycloak-ssl \r\n<\/code><\/pre>\n<p>\u521b\u5efa\u8bc1\u4e66\u8bbe\u7f6e\u6587\u4ef6<\/p>\n<p>sslcert.conf\uff1assl\u8bc1\u4e66\u914d\u7f6e\u6587\u4ef6<\/p>\n<pre class=\"post-pre\"><code>[req]\r\ndistinguished_name = req_distinguished_name\r\nx509_extensions = v3_req\r\nprompt = no\r\n[req_distinguished_name]\r\nCN = keycloak \r\n[v3_req]      \r\nkeyUsage = keyEncipherment, dataEncipherment\r\nextendedKeyUsage = serverAuth, clientAuth   \r\nsubjectAltName = @alt_names                 \r\n[alt_names]\r\nDNS.1 = keycloak                            \r\nDNS.2 = keycloak.example.com\r\n<\/code><\/pre>\n<p>\u521b\u5efa\u5bc6\u94a5\u5bf9<\/p>\n<pre class=\"post-pre\"><code># openssl req -x509 -nodes -days 730 -newkey rsa:2048 -keyout tls.key -out tls.crt -config sslcert.conf -extensions 'v3_req'\r\n\r\nls\r\nsslcert.conf  tls.crt  tls.key \r\n<\/code><\/pre>\n<p>\u53ef\u4ee5\u786e\u5b9a\u516c\u94a5\u7684\u7b7e\u53d1\u8005\u548c\u4e3b\u9898\u90fd\u662f\u540c\u4e00\u4e2a\u81ea\u7b7e\u540d\u8bc1\u4e66\uff08\u5373\u6240\u8c13\u7684\u81ea\u5236\u8bc1\u4e66\uff09\u3002<\/p>\n<pre class=\"post-pre\"><code># openssl x509 -in tls.crt --text --noout\r\nCertificate:\r\n    Data:\r\n        Version: 3 (0x2)\r\n        Serial Number:\r\n            53:e8:c5:1e:e4:6c:dd:13:59:f8:4d:81:0d:6f:56:97:06:e3:4f:f3\r\n        Signature Algorithm: sha256WithRSAEncryption\r\n        Issuer: CN = keycloak\r\n        Validity\r\n            Not Before: May  8 06:27:59 2022 GMT\r\n            Not After : May  7 06:27:59 2024 GMT\r\n        Subject: CN = keycloak\r\n        Subject Public Key Info:\r\n            Public Key Algorithm: rsaEncryption\r\n                RSA Public-Key: (2048 bit)\r\n                Modulus:\r\n                \u30fb\u30fb\u30fb\r\n<\/code><\/pre>\n<p>\u4eca\u56deKeycloak\u306ePod\u306fhostPath\u3092\u7528\u3044\u3066\u30ad\u30fc\u30da\u30a2\u683c\u7d0d\u30d5\u30a9\u30eb\u30c0\u3092\u30de\u30a6\u30f3\u30c8\u3059\u308b\u305f\u3081\u6a29\u9650\u3092\u5909\u66f4\u3057\u3066\u304a\u304f\u3002<br \/>\n\u203b\u53b3\u5bc6\u306b\u306ftls.key\u306bRead\u6a29\u9650\u3092\u4ed8\u4e0e\u3057\u3066\u304a\u3051\u3070\u826f\u3044\u306f\u305a\u3002<\/p>\n<pre class=\"post-pre\"><code># chmod -R 777 \/srv\/keycloak-ssl \r\n<\/code><\/pre>\n<p>\u5c06\u516c\u5f00\u5bc6\u94a5\u914d\u7f6e\u5230\u4e3b\u8282\u70b9\u4e0a\u3002<\/p>\n<pre class=\"post-pre\"><code># mkdir -p \/etc\/kubernetes\/ssl\/\r\n# cp tls.crt \/etc\/kubernetes\/ssl\/kc-ca.crt\r\n# ls \/etc\/kubernetes\/ssl\/\r\nkc-ca.crt\r\n<\/code><\/pre>\n<h2>\u521b\u5efaKeycloak\u6301\u4e45\u5316\u76ee\u5f55\u3002<\/h2>\n<p>\u5f53\u5c06Keycloak\u90e8\u7f72\u4e3aPod\u65f6\uff0c\u901a\u5e38\u60c5\u51b5\u4e0b\u4fe1\u606f\u5c06\u4fdd\u5b58\u5728Keycloak\u5185\u90e8\u7684\u672c\u5730\u6570\u636e\u5e93\uff08H2\uff09\u4e2d\u3002\u7136\u800c\uff0c\u5f53\u5bb9\u5668\u91cd\u65b0\u542f\u52a8\u65f6\uff0c\u8fd9\u4e9b\u6570\u636e\u5c06\u4f1a\u4e22\u5931\u3002<br \/>\n\u7406\u60f3\u60c5\u51b5\u4e0b\uff0c\u5e94\u8be5\u6307\u5b9a\u5916\u90e8\u6570\u636e\u5e93\uff08\u5982PostgreSQL\uff09\u4f5c\u4e3a\u4fdd\u5b58\u4f4d\u7f6e\u3002\u4f46\u662f\uff0c\u672c\u6b21\u6211\u4eec\u5c06\u6570\u636e\u4fdd\u5b58\u5230minikube\u865a\u62df\u673a\u4e0a\u7684\u76ee\u5f55\uff0c\u5e76\u901a\u8fc7\u5c06\u5176\u4f5c\u4e3ahostPath\u7684volumeMounts\u6302\u8f7d\u5230Pod\u4e0a\u6765\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\u3002<\/p>\n<p>\u5728minikube\u865a\u62df\u673a\u4e0a\u521b\u5efa\u5b58\u50a8\u76ee\u5f55\u3002<\/p>\n<pre class=\"post-pre\"><code># mkdir -p \/srv\/keycloak\r\n# chmod -R 777 \/srv\/keycloak\r\n# ls -la \/srv\r\ntotal 0\r\ndrwxr-xr-x  4 root root  80 May  8 06:46 .\r\ndrwxr-xr-x 19 root root 500 May  8 06:24 ..\r\ndrwxrwxrwx  2 root root  40 May  8 06:46 keycloak\r\ndrwxrwxrwx  2 root root 100 May  8 06:27 keycloak-ssl\r\n<\/code><\/pre>\n<h2>5. Keycloak\u5efa\u7acb<\/h2>\n<p>\u901a\u8fc7\u5177\u6709minikube\u64cd\u4f5c\u6743\u9650\u7684\u5ba2\u6237\u7aef\uff0c\u5728Kubernetes\u96c6\u7fa4\u4e0a\u5c06Keycloak\u90e8\u7f72\u4e3aPod\u3002<\/p>\n<h3>Keycloak\u7684\u90e8\u7f72<\/h3>\n<p>\u6211\u4f7f\u7528\u4e86\u4e00\u90e8\u5206Keycloak\u5b98\u65b9\u6587\u6863\u4f5c\u4e3a\u53c2\u8003\uff0c\u5e76\u4fee\u6539\u4e86\u4e00\u4e9bmanifest\u3002\u7136\u540e\u4f7f\u7528\u4ee5\u4e0bmanifest\u8fdb\u884c\u90e8\u7f72\u3002<\/p>\n<p>Keycloak\u542f\u52a8\u914d\u7f6e\u7684\u6ce8\u610f\u4e8b\u9879\u3002<\/p>\n<p>dev mode\u3067\u8d77\u52d5<\/p>\n<p>HTTPS\u30dd\u30fc\u30c8\u306e\u6307\u5b9a\uff08\u30c7\u30d5\u30a9\u30eb\u30c88443\uff09<\/p>\n<p>NodePort\u3067\u30b5\u30fc\u30d3\u30b9\u3092\u516c\u958b<\/p>\n<p>TLS\u30ad\u30fc\u30da\u30a2\u306e\u6307\u5b9a\u3068\u683c\u7d0d\u5148\u3092hostPath\u3068\u3057\u3066\u30de\u30a6\u30f3\u30c8<\/p>\n<p>keycloak.yaml \u6587\u4ef6<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">v1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Namespace<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n<span class=\"nn\">---<\/span>\r\n<span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">v1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Service<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n  <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n  <span class=\"na\">labels<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">http<\/span>\r\n    <span class=\"na\">port<\/span><span class=\"pi\">:<\/span> <span class=\"m\">8080<\/span>\r\n    <span class=\"na\">targetPort<\/span><span class=\"pi\">:<\/span> <span class=\"m\">8080<\/span>\r\n    <span class=\"na\">nodePort<\/span><span class=\"pi\">:<\/span> <span class=\"m\">31008<\/span> <span class=\"c1\"># NodePort\u3092\u660e\u793a<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">https<\/span> <span class=\"c1\"># HTTP\u30a2\u30af\u30bb\u30b9\u7528\u306b8443\u30dd\u30fc\u30c8\u3092\u516c\u958b<\/span>\r\n    <span class=\"na\">port<\/span><span class=\"pi\">:<\/span> <span class=\"m\">8443<\/span>\r\n    <span class=\"na\">targetPort<\/span><span class=\"pi\">:<\/span> <span class=\"m\">8443<\/span>\r\n    <span class=\"na\">nodePort<\/span><span class=\"pi\">:<\/span> <span class=\"m\">32084<\/span> <span class=\"c1\"># NodePort\u3092\u660e\u793a<\/span>\r\n  <span class=\"na\">selector<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n  <span class=\"na\">type<\/span><span class=\"pi\">:<\/span> <span class=\"s\">NodePort<\/span>\r\n<span class=\"nn\">---<\/span>\r\n<span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">apps\/v1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Deployment<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n  <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n  <span class=\"na\">labels<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">replicas<\/span><span class=\"pi\">:<\/span> <span class=\"m\">1<\/span>\r\n  <span class=\"na\">selector<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n  <span class=\"na\">template<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">labels<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n    <span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">containers<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak<\/span>\r\n        <span class=\"na\">image<\/span><span class=\"pi\">:<\/span> <span class=\"s\">quay.io\/keycloak\/keycloak:18.0.0<\/span>\r\n        <span class=\"na\">args<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">start-dev\"<\/span><span class=\"pi\">]<\/span> <span class=\"c1\"># dev mode\u3067\u8d77\u52d5<\/span>\r\n        <span class=\"na\">env<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">KEYCLOAK_ADMIN<\/span>\r\n          <span class=\"na\">value<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">admin\"<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">KEYCLOAK_ADMIN_PASSWORD<\/span>\r\n          <span class=\"na\">value<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">admin\"<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">KC_PROXY<\/span>\r\n          <span class=\"na\">value<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">edge\"<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">KC_HTTP_ENABLED\"<\/span> <span class=\"c1\"># HTTP\u63a5\u7d9a\u6709\u52b9\u5316\uff08\u30d6\u30e9\u30a6\u30b6\u30a2\u30af\u30bb\u30b9\u7528\uff09<\/span>\r\n          <span class=\"na\">value<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">true\"<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">KC_HTTPS_PORT\"<\/span> <span class=\"c1\"># HTTPS\u30dd\u30fc\u30c8<\/span>\r\n          <span class=\"na\">value<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">8443\"<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">KC_HTTPS_CERTIFICATE_FILE<\/span> <span class=\"c1\"># \u516c\u958b\u9375\u306e\u30d1\u30b9<\/span>\r\n          <span class=\"na\">value<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">\/opt\/keycloak\/tls\/tls.crt\"<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">KC_HTTPS_CERTIFICATE_KEY_FILE<\/span> <span class=\"c1\"># \u79d8\u5bc6\u9375\u306e\u30d1\u30b9<\/span>\r\n          <span class=\"na\">value<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">\/opt\/keycloak\/tls\/tls.key\"<\/span>\r\n        <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">http<\/span>\r\n          <span class=\"na\">containerPort<\/span><span class=\"pi\">:<\/span> <span class=\"m\">8080<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">https<\/span> <span class=\"c1\"># TLS\u7528\u306b8443\u30dd\u30fc\u30c8\u3092\u516c\u958b<\/span>\r\n          <span class=\"na\">containerPort<\/span><span class=\"pi\">:<\/span> <span class=\"m\">8443<\/span>\r\n        <span class=\"na\">readinessProbe<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">httpGet<\/span><span class=\"pi\">:<\/span>\r\n            <span class=\"na\">path<\/span><span class=\"pi\">:<\/span> <span class=\"s\">\/realms\/master<\/span>\r\n            <span class=\"na\">port<\/span><span class=\"pi\">:<\/span> <span class=\"m\">8080<\/span>\r\n        <span class=\"na\">volumeMounts<\/span><span class=\"pi\">:<\/span> <span class=\"c1\"># \u518d\u8d77\u52d5\u3057\u3066\u3082\u30c7\u30fc\u30bf\u304c\u63ee\u767a\u3057\u306a\u3044\u3088\u3046\u66ab\u5b9a\u3067hostPath\u306b\u30de\u30a6\u30f3\u30c8<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">keycloak-persistent-storage\"<\/span>\r\n          <span class=\"na\">mountPath<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">\/opt\/keycloak\/data\"<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">keycloak-ssl\"<\/span> <span class=\"c1\"># \u30ad\u30fc\u30da\u30a2\u683c\u7d0d\u5148<\/span>\r\n          <span class=\"na\">mountPath<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">\/opt\/keycloak\/tls\"<\/span>\r\n      <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak-persistent-storage<\/span>\r\n        <span class=\"na\">hostPath<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">path<\/span><span class=\"pi\">:<\/span> <span class=\"s\">\/srv\/keycloak<\/span>\r\n          <span class=\"na\">type<\/span><span class=\"pi\">:<\/span> <span class=\"s\">DirectoryOrCreate<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak-ssl<\/span> <span class=\"c1\"># \u8a3c\u660e\u66f8\u683c\u7d0d\u5148<\/span>\r\n        <span class=\"na\">hostPath<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">path<\/span><span class=\"pi\">:<\/span> <span class=\"s\">\/srv\/keycloak-ssl<\/span>     \r\n          <span class=\"na\">type<\/span><span class=\"pi\">:<\/span>  <span class=\"s\">DirectoryOrCreate<\/span>\r\n<\/code><\/pre>\n<p>\u90e8\u7f72\u6267\u884c<\/p>\n<pre class=\"post-pre\"><code># kubectl apply -f keycloak.yaml\r\nnamespace\/keycloak created\r\nservice\/keycloak created\r\ndeployment.apps\/keycloak created\r\n\r\n# kubectl -n keycloak get all\r\nNAME                            READY   STATUS    RESTARTS   AGE\r\npod\/keycloak-679b66bbd8-l2n9g   1\/1     Running   0          5m16s\r\n\r\nNAME               TYPE       CLUSTER-IP     EXTERNAL-IP   PORT(S)                         AGE\r\nservice\/keycloak   NodePort   10.102.40.27   &lt;none&gt;        8080:31008\/TCP,8443:32084\/TCP   5m16s\r\n\r\nNAME                       READY   UP-TO-DATE   AVAILABLE   AGE\r\ndeployment.apps\/keycloak   1\/1     1            1           5m16s\r\n\r\nNAME                                  DESIRED   CURRENT   READY   AGE\r\nreplicaset.apps\/keycloak-679b66bbd8   1         1         1       5m16s\r\n<\/code><\/pre>\n<h3>Keycloak\u540d\u524d\u89e3\u6c7a\u8a2d\u5b9a<\/h3>\n<p>\u7531\u4e8e\u8fd9\u6b21\u662f\u9a8c\u8bc1\uff0c\u8bf7\u5728\/etc\/hosts\u6587\u4ef6\u4e2d\u6dfb\u52a0\u8bb0\u5f55\u5e76\u8fdb\u884c\u76f8\u5e94\u7684\u5904\u7406\u3002<br \/>\n*\u5728Keycloak\u7684\u6d4f\u89c8\u5668\u8bbf\u95ee\u8bbe\u5907\u548cminikube\u865a\u62df\u673a\u4e0a\u5206\u522b\u8fdb\u884c\u6dfb\u52a0\u3002<\/p>\n<p>\u786e\u8ba4 minikube \u865a\u62df\u673a\u7684 IP \u5730\u5740\u3002<\/p>\n<pre class=\"post-pre\"><code># minikube ip\r\n192.168.59.101\r\n<\/code><\/pre>\n<p>\/etc\/hosts \u8bf7\u5c06\u4ee5\u4e0b\u5185\u5bb9\u7528\u4e2d\u6587\u672c\u5730\u5316\uff1a<\/p>\n<pre class=\"post-pre\"><code>\u30fb\u30fb\u30fb\r\n&lt;minikube VM IP&gt;\tkeycloak.example.com\r\n\u30fb\u30fb\u30fb\r\n<\/code><\/pre>\n<h2>6. Keycloak\u8bbf\u95ee\u786e\u8ba4<\/h2>\n<p>\u8fdb\u884c\u5bf9Keycloak\u7684\u8bbf\u95ee\u786e\u8ba4\u3002<\/p>\n<h3>\u68c0\u67e5curl\u8bbf\u95ee\uff08HTTPS\uff09<\/h3>\n<p>\u4f7f\u7528curl\u547d\u4ee4\u4eceminikube\u865a\u62df\u673a\u9a8c\u8bc1\u662f\u5426\u53ef\u4ee5\u8fdb\u884cHTTPS\u8bbf\u95ee\u3002<br \/>\n\u7531\u4e8eKeycloak\u4f7f\u7528\u81ea\u7b7e\u540d\u8bc1\u4e66\uff0c\u56e0\u6b64\u4f7f\u7528\u516c\u94a5\u5bf9\u5176\u8fdb\u884cCA\u7b7e\u540d\u3002<br \/>\n\u56e0\u6b64\uff0c\u5728\u8fdb\u884cTLS\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u9700\u8981\u4fe1\u4efbKeycloak\u7684CA\u8bc1\u4e66\uff08\u5373\u516c\u94a5\uff09\uff0c\u4ee5\u5b9e\u73b0\u8bbf\u95ee\u3002<\/p>\n<pre class=\"post-pre\"><code># curl -v --cacert \/etc\/kubernetes\/ssl\/kc-ca.crt https:\/\/keycloak.example.com:32084\r\n<\/code><\/pre>\n<h3>\u6d4f\u89c8\u5668\u8bbf\u95ee\u786e\u8ba4\uff08HTTP\uff09<\/h3>\n<p>\u4f7f\u7528\u6d4f\u89c8\u5668\u8bbf\u95ee\u4ee5\u4e0b\u7f51\u5740\u3002<br \/>\n* \u7531\u4e8e\u76f4\u63a5\u4f7f\u7528\u6d4f\u89c8\u5668\u901a\u8fc7HTTPS\u8bbf\u95ee\u65e0\u6cd5\u663e\u793a\u9875\u9762\uff08ERR_SSL_KEY_USAGE_INCOMPATIBLE\uff09\uff0c\u6545\u6539\u4e3a\u4f7f\u7528HTTP\u8bbf\u95ee\u3002<\/p>\n<pre class=\"post-pre\"><code>http:\/\/keycloak.example.com:31008\r\n<\/code><\/pre>\n<h2>7. Keycloak\u7684\u914d\u7f6e\u3002<\/h2>\n<p>\u901a\u8fc7\u6d4f\u89c8\u5668\u8bbf\u95eeKeycloak\u5e76\u8fdb\u884c\u4ee5\u4e0b\u914d\u7f6e\u3002<\/p>\n<h3>\u8bbf\u95ee\u7ba1\u7406\u754c\u9762<\/h3>\n<p>\u4f7f\u7528ID\/Password=admin\u767b\u5f55\u5230\u7ba1\u7406\u63a7\u5236\u53f0\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/59-1.png\" alt=\"pic2.png\" \/><\/div>\n<h3>\u521b\u5efa\u9886\u57df<\/h3>\n<p>\u5728Keycloak\u4e2d\u521b\u5efa\u4e0e\u79df\u6237\u6982\u5ff5\u76f8\u5bf9\u5e94\u7684Realm\u3002\u672c\u6b21\u521b\u5efa\u7684Realm\u540d\u79f0\u4e3a&#8221;kubernetes&#8221;\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/62-2.png\" alt=\"pic5.png\" \/><\/div>\n<h3>\u521b\u5efaClients\u548cClientScopes\u3002<\/h3>\n<p>\u521b\u5efa\u4e00\u4e2a\u5ba2\u6237\u7aef\u5e76\u8bbe\u7f6e\u76f8\u5e94\u7684\u5ba2\u6237\u7aef\u8303\u56f4\uff0c\u4f5c\u4e3aKeycloak\u7684\u8eab\u4efd\u9a8c\u8bc1\u63a5\u6536\u7aef\u3002<\/p>\n<p>\u5236\u4f5c\u5ba2\u6237\u7aef<\/p>\n<p>Client ID: kubernetes<\/p>\n<p>Access Type: confidential<\/p>\n<p>Valid Redirect URIs: http:\/\/* https:\/\/*<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/67-3.png\" alt=\"pic9.png\" \/><\/div>\n<p>\u521b\u5efa\u5ba2\u6237\u8303\u56f4<\/p>\n<p>Client Scope: groups<\/p>\n<p>Mappers: name groups\u3092\u8ffd\u52a0<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/70-7.png\" alt=\"pic17.png\" \/><\/div>\n<p>\u5411\u5ba2\u6237\u7aef\u7684\u5ba2\u6237\u7aef\u8303\u56f4\u6dfb\u52a0groups\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/72-2.png\" alt=\"pic20.png\" \/><\/div>\n<p>\u4ece\u5ba2\u6237\u7aef\u51ed\u636e\u4e2d\u83b7\u53d6\u5bc6\u94a5<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/74-0.png\" alt=\"pic21.png\" \/><\/div>\n<h3>\u521b\u5efa\u7528\u6237\u548c\u7ec4<\/h3>\n<p>\u521b\u5efa\u7528\u4e8e\u8ba4\u8bc1\u7684\u7528\u6237\u548c\u7ec4\u3002<\/p>\n<p>administrators\u3001developers\u3068\u3044\u3046\u30b0\u30eb\u30fc\u30d7\u3092\u4f5c\u6210\u3002<br \/>\n\u3053\u308c\u3089\u306e\u30b0\u30eb\u30fc\u30d7\u306b\u5bfe\u3057\u3066\u5f8c\u7a0bRBAC\u306b\u3088\u308aKubernetes\u30af\u30e9\u30b9\u30bf\u30fc\u306b\u5bfe\u3059\u308b\u6a29\u9650\u3092\u4ed8\u4e0e\u3059\u308b<\/p>\n<p>administrators: Kubernetes\u30af\u30e9\u30b9\u30bf\u30fc\u306e\u7ba1\u7406\u8005\u6a29\u9650\u3092\u6301\u3064\u30b0\u30eb\u30fc\u30d7<\/p>\n<p>developers: Kubernetes\u30af\u30e9\u30b9\u30bf\u30fc\u306b\u5bfe\u3057\u3066\u7279\u5b9a\u306e\u6a29\u9650\u306e\u307f\u3057\u304b\u6301\u305f\u306a\u3044\u30b0\u30eb\u30fc\u30d7<\/p>\n<p>\u5c3d\u7ba1\u622a\u56fe\u53ea\u663e\u793a\u4e86\u7ba1\u7406\u5458\u7684\u521b\u5efa\uff0c\u4f46\u4e5f\u8981\u540c\u6837\u521b\u5efa\u5f00\u53d1\u4eba\u5458\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/80-2.png\" alt=\"pic24.png\" \/><\/div>\n<p>\u521b\u5efa\u540d\u4e3aadmin-user\u548cdev-user\u7684\u7528\u6237\u3002<\/p>\n<p>admin-user: administrators\u30b0\u30eb\u30fc\u30d7\u306b\u6240\u5c5e<\/p>\n<p>dev-user: developers\u30b0\u30eb\u30fc\u30d7\u306b\u6240\u5c5e<\/p>\n<p>\u53ea\u663e\u793a\u4e86\u521b\u5efaadmin-user\uff0c\u4f46\u662f\u9700\u8981\u540c\u6837\u521b\u5efadev-user\u3002<br \/>\n\u5bc6\u7801\u53ef\u4ee5\u8bbe\u7f6e\u4e3a\u4efb\u610f\u503c\uff08\u5728\u6b64\u8bbe\u7f6e\u4e3aP@ssw0rd\uff09\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/84-2.png\" alt=\"pic27.png\" \/><\/div>\n<h3>\u78ba\u8a8d<\/h3>\n<p>\u786e\u8ba4\u53ef\u4ee5\u901a\u8fc7\u4ee5\u4e0b\u547d\u4ee4\u5728Keycloak\u4e0a\u8fdb\u884c\u8ba4\u8bc1\uff0c\u5e76\u83b7\u53d6id-token\u548crefresh-token\u3002<\/p>\n<pre class=\"post-pre\"><code># curl -k -d \"grant_type=password\" -d \"scope=openid\" -d \"client_id=kubernetes\" -d \"client_secret=&lt;client=kubernetes\u306eSecret&gt;\" -d \"username=&lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u540d&gt;\" -d \"password=&lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u30d1\u30b9\u30ef\u30fc\u30c9&gt;\" https:\/\/keycloak.example.com:32084\/realms\/kubernetes\/protocol\/openid-connect\/token | jq .\r\n\r\n\u30fb\u30fb\u30fb\r\n{\r\n  \"access_token\": \u30fb\u30fb\u30fb,\r\n  \"expires_in\": 300,\r\n  \"refresh_expires_in\": 1800,\r\n  \"refresh_token\": \u30fb\u30fb\u30fb\r\n  \"id_token\": \u30fb\u30fb\u30fb,\r\n  \"not-before-policy\": 0,\r\n  \"session_state\": \u30fb\u30fb\u30fb,\r\n  \"scope\": \"openid profile email groups\"\r\n}\r\n<\/code><\/pre>\n<p>\u53ef\u4ee5\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u5bf9\u6bcf\u4e2a\u4ee4\u724c\u8fdb\u884c\u9a8c\u8bc1\u3002<\/p>\n<p>exp: token\u6709\u52b9\u671f\u9650\uff08UNIX\u6642\u9593\uff09<\/p>\n<p>iat: token\u767a\u884c\u6642\u9593\uff08UNIX\u6642\u9593\uff09<\/p>\n<p>active: token\u306e\u6709\u52b9\u6709\u7121<\/p>\n<pre class=\"post-pre\"><code># curl -k --user \"kubernetes:&lt;client=kubernetes\u306esecret&gt;\" -d \"token=&lt;token&gt;\" https:\/\/keycloak.example.com:32084\/realms\/kubernetes\/protocol\/openid-connect\/token\/introspect | jq .\r\n\r\n\u30fb\u30fb\u30fb\r\n{\r\n  \"exp\": 1651997178,\r\n  \"iat\": 1651996878,\r\n  \u30fb\u30fb\u30fb\r\n  \"active\": true\r\n}\r\n<\/code><\/pre>\n<h2>8. Kubernetes\u7684API\u670d\u52a1\u5668\u914d\u7f6e<\/h2>\n<p>kube-apiserver\u304cKeycloak\u3092\u7528\u3044\u3066OIDC\u8a8d\u8a3c\u3092\u884c\u3046\u305f\u3081\u306e\u8a2d\u5b9a\u3092\u884c\u3046\u3002<br \/>\nminikube VM\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3001kube-apiserver\u306emanifest\u306b\u8d77\u52d5OP\u304a\u3088\u3073KeycloakCA\u8a3c\u660e\u66f8\uff08=\u516c\u958b\u9375)\u683c\u7d0d\u5148\u3092volumeMounts\u3059\u308b\u3002<br \/>\n\u306a\u304a\u3001kube-apiserver\u306fStatic Pod\u3068\u3057\u3066\u8d77\u52d5\u3057\u3066\u3044\u308b\u305f\u3081manifest\u5909\u66f4\u5f8c\u306b\u81ea\u52d5\u7684\u306b\u518d\u30c7\u30d7\u30ed\u30a4\u3055\u308c\u308b\u3002<\/p>\n<p>\/etc\/kubernetes\/manifests\/kube-apiserver.yaml<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">\u30fb\u30fb\u30fb<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">containers<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">command<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">kube-apiserver<\/span>\r\n    <span class=\"s\">\u30fb\u30fb\u30fb<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">--oidc-issuer-url=https:\/\/keycloak.example.com:32084\/realms\/kubernetes<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">--oidc-client-id=kubernetes<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">--oidc-username-claim=name<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">--oidc-groups-claim=groups<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"s\">--oidc-ca-file=\/etc\/kubernetes\/ssl\/kc-ca.crt<\/span>\r\n    <span class=\"s\">\u30fb\u30fb\u30fb<\/span>\r\n    <span class=\"na\">volumeMounts<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s\">\u30fb\u30fb\u30fb<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">mountPath<\/span><span class=\"pi\">:<\/span> <span class=\"s\">\/etc\/kubernetes\/ssl<\/span>\r\n      <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak-ca-certificates<\/span>\r\n      <span class=\"na\">readOnly<\/span><span class=\"pi\">:<\/span> <span class=\"kc\">true<\/span>\r\n  <span class=\"s\">\u30fb\u30fb\u30fb<\/span>\r\n  <span class=\"na\">volumes<\/span><span class=\"pi\">:<\/span> \r\n  <span class=\"s\">\u30fb\u30fb\u30fb<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">hostPath<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">path<\/span><span class=\"pi\">:<\/span> <span class=\"s\">\/etc\/kubernetes\/ssl<\/span>\r\n      <span class=\"na\">type<\/span><span class=\"pi\">:<\/span> <span class=\"s\">DirectoryOrCreate<\/span>\r\n    <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">keycloak-ca-certificates<\/span>\r\n<span class=\"na\">status<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">{}<\/span> \r\n<\/code><\/pre>\n<h2>9. \u5236\u5b9aRBAC\u7cfb\u7edf<\/h2>\n<p>Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30b0\u30eb\u30fc\u30d7\u306b\u5bfe\u3057\u3066RBAC\u306e\u8a2d\u5b9a\u3092\u884c\u3046\u3002<br \/>\n\u4eca\u56de\u306f\u305d\u308c\u305e\u308c\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u6a29\u9650\u8a2d\u5b9a\u3068\u3059\u308b\u3002<\/p>\n<p>administrators: \u30af\u30e9\u30b9\u30bf\u30fc\u306b\u5bfe\u3059\u308b\u5168\u3066\u306e\u6a29\u9650\u3092\u4ed8\u4e0e\uff08\u30d3\u30eb\u30c9\u30a4\u30f3\u306eClusterRole=cluster-admin\u3092\u30d0\u30a4\u30f3\u30c9\uff09<\/p>\n<p>developers: Namespace\u3068Pod\u306e\u53c2\u7167\u6a29\u9650\u306e\u307f\u3092\u4ed8\u4e0e\uff08\u72ec\u81ea\u3067ClusterRole=developer-role\u3092\u4f5c\u6210\u3057\u3066\u30d0\u30a4\u30f3\u30c9\uff09<\/p>\n<p>\u7ba1\u7406\u5458\u89d2\u8272\u914d\u7f6e\u6587\u4ef6.yaml<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterRoleBinding<\/span>\r\n<span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io\/v1<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">administrator-crb<\/span>\r\n<span class=\"na\">roleRef<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">apiGroup<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io<\/span>\r\n  <span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterRole<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">cluster-admin<\/span>\r\n<span class=\"na\">subjects<\/span><span class=\"pi\">:<\/span>\r\n<span class=\"pi\">-<\/span> <span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Group<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">administrators\"<\/span>\r\n  <span class=\"na\">apiGroup<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io<\/span>\r\n<\/code><\/pre>\n<p>devrole.yaml-\u8bf7\u5c06devrole.yaml\u8fdb\u884c\u91ca\u4e49\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterRole<\/span>\r\n<span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io\/v1<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">developer-role<\/span>\r\n<span class=\"na\">rules<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">apiGroups<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">\"<\/span><span class=\"pi\">]<\/span>\r\n    <span class=\"na\">resources<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">namespaces\"<\/span><span class=\"pi\">,<\/span><span class=\"s2\">\"<\/span><span class=\"s\">pods\"<\/span><span class=\"pi\">]<\/span>\r\n    <span class=\"na\">verbs<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">get\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">watch\"<\/span><span class=\"pi\">,<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">list\"<\/span><span class=\"pi\">]<\/span>\r\n<span class=\"nn\">---<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterRoleBinding<\/span>\r\n<span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io\/v1<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">developer-crb<\/span>\r\n<span class=\"na\">roleRef<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">apiGroup<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io<\/span>\r\n  <span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterRole<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">developer-role<\/span>\r\n<span class=\"na\">subjects<\/span><span class=\"pi\">:<\/span>\r\n<span class=\"pi\">-<\/span> <span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Group<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">developers\"<\/span>\r\n  <span class=\"na\">apiGroup<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io<\/span>\r\n<\/code><\/pre>\n<p>\u30af\u30e9\u30b9\u30bf\u30fc\u306b\u9069\u7528<\/p>\n<pre class=\"post-pre\"><code># kubectl apply -f adminrole.yaml\r\nclusterrolebinding.rbac.authorization.k8s.io\/administrator-crb created\r\n\r\n# kubectl apply -f devrole.yaml\r\nclusterrole.rbac.authorization.k8s.io\/developer-role created\r\nclusterrolebinding.rbac.authorization.k8s.io\/developer-crb created\r\n<\/code><\/pre>\n<h2>10.kubectl\u306e\u8a2d\u5b9a<\/h2>\n<p>kubectl\u306b\u306fOIDC ID \u30d7\u30ed\u30d0\u30a4\u30c0\u30fc\u306b\u30ed\u30b0\u30a4\u30f3\u3059\u308b\u4ed5\u7d44\u307f\u304c\u7528\u610f\u3055\u308c\u3066\u3044\u306a\u3044\u305f\u3081\u3001<br \/>\n\u624b\u52d5\u3067\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073kubeconfig\u3078\u306etoken\u8a2d\u5b9a\u3092\u884c\u3046\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/106-0.png\" alt=\"pic28.png\" \/><\/div>\n<p>\u4f3c\u4e4e\u5b58\u5728\u4e00\u79cd\u53ef\u4ee5\u901a\u8fc7kubectl\u8fdb\u884c\u767b\u5f55\u7684\u63d2\u4ef6\u3002kubelogin \u53ef\u5728 GitHub \u4e0a\u627e\u5230\uff1ahttps:\/\/github.com\/int128\/kubelogin\u3002<\/p>\n<h3>\u6b65\u9aa41\uff1a\u767b\u5f55Keycloak<\/h3>\n<p>\u53ef\u4ee5\u901a\u8fc7\u4ee5\u4e0b\u547d\u4ee4\u5728Keycloak\u4e0a\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\uff0c\u83b7\u53d6id-token\u548crefresh-token\u3002<\/p>\n<pre class=\"post-pre\"><code># curl -k -d \"grant_type=password\" -d \"scope=openid\" -d \"client_id=kubernetes\" -d \"client_secret=&lt;client=kubernetes\u306esecret&gt;\" -d \"username=&lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u540d&gt;\" -d \"password=&lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u30d1\u30b9\u30ef\u30fc\u30c9&gt;\" https:\/\/keycloak.example.com:32084\/realms\/kubernetes\/protocol\/openid-connect\/token | jq .\r\n<\/code><\/pre>\n<h3>\u6b65\u9aa42\uff1a\u8bbe\u7f6ekubeconfig\u914d\u7f6e\u6587\u4ef6<\/h3>\n<p>\u4f7f\u7528\u83b7\u5f97\u7684id-token\u548crefresh-token\u6765\u914d\u7f6ekubeconfig\u3002<\/p>\n<pre class=\"post-pre\"><code># kubectl config set-credentials &lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u540d&gt; \\\r\n    \"--auth-provider=oidc\" \\\r\n    \"--auth-provider-arg=idp-issuer-url=https:\/\/keycloak.example.com:32084\/realms\/kubernetes\" \\\r\n    \"--auth-provider-arg=client-id=kubernetes\" \\\r\n    \"--auth-provider-arg=idp-certificate-authority=&lt;keycloak\u516c\u958b\u9375\u306e\u30d1\u30b9&gt;\" \\\r\n    \"--auth-provider-arg=client-secret=&lt;client=kubernetes\u306esecret&gt;\" \\\r\n    \"--auth-provider-arg=id-token=&lt;id-token&gt;\" \\\r\n    \"--auth-provider-arg=refresh-token=&lt;refresh-token&gt;\"\r\n    \r\n# kubectl config set-context &lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u540d&gt;@&lt;kubeconfig\u3067\u5b9a\u7fa9\u3055\u308c\u3066\u3044\u308bk8s\u30af\u30e9\u30b9\u30bf\u540d&gt; --cluster=&lt;kubeconfig\u3067\u5b9a\u7fa9\u3055\u308c\u3066\u3044\u308bk8s\u30af\u30e9\u30b9\u30bf\u540d&gt; --user=&lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u540d&gt;\r\n\r\n# kubectl config use-context &lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u540d&gt;@&lt;kubeconfig\u3067\u5b9a\u7fa9\u3055\u308c\u3066\u3044\u308bk8s\u30af\u30e9\u30b9\u30bf\u540d&gt;\r\nSwitched to context \"&lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u540d&gt;@&lt;kubeconfig\u3067\u5b9a\u7fa9\u3055\u308c\u3066\u3044\u308bk8s\u30af\u30e9\u30b9\u30bf\u540d&gt;\".\r\n<\/code><\/pre>\n<p>\u4f7f\u7528shell\u811a\u672c\u4e00\u6b21\u6027\u6267\u884c\u4e0a\u8ff0\u64cd\u4f5c<\/p>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n\r\n<span class=\"nv\">scope<\/span><span class=\"o\">=<\/span>openid\r\n<span class=\"nv\">client_id<\/span><span class=\"o\">=<\/span>kubernetes\r\n<span class=\"nv\">client_secret<\/span><span class=\"o\">=<\/span>&lt;<span class=\"nv\">client<\/span><span class=\"o\">=<\/span>kubernetes\u306esecret&gt;\r\n<span class=\"nv\">username<\/span><span class=\"o\">=<\/span>&lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u540d&gt;\r\n<span class=\"nv\">password<\/span><span class=\"o\">=<\/span>&lt;Keycloak\u3067\u4f5c\u6210\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u30d1\u30b9\u30ef\u30fc\u30c9&gt;\r\n<span class=\"nv\">oidc_url<\/span><span class=\"o\">=<\/span>https:\/\/keycloak.example.com:32084\/realms\/kubernetes\/protocol\/openid-connect\/token\r\n<span class=\"nv\">realm_url<\/span><span class=\"o\">=<\/span>https:\/\/keycloak.example.com:32084\/realms\/kubernetes\r\n<span class=\"nv\">certificate<\/span><span class=\"o\">=<\/span>&lt;keycloak\u516c\u958b\u9375\u306e\u30d1\u30b9&gt;\r\n<span class=\"nv\">cluster<\/span><span class=\"o\">=<\/span>&lt;kubeconfig\u3067\u5b9a\u7fa9\u3055\u308c\u3066\u3044\u308bk8s\u30af\u30e9\u30b9\u30bf\u540d&gt;\r\n\r\n<span class=\"c\">### Generate Authentication token<\/span>\r\n\r\n<span class=\"nv\">json_data<\/span><span class=\"o\">=<\/span><span class=\"sb\">`<\/span>curl <span class=\"nt\">-k<\/span> <span class=\"nt\">-d<\/span> <span class=\"s2\">\"grant_type=password\"<\/span> <span class=\"nt\">-d<\/span> <span class=\"s2\">\"scope=<\/span><span class=\"k\">${<\/span><span class=\"nv\">scope<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"nt\">-d<\/span> <span class=\"s2\">\"client_id=<\/span><span class=\"k\">${<\/span><span class=\"nv\">client_id<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"nt\">-d<\/span> <span class=\"s2\">\"client_secret=<\/span><span class=\"k\">${<\/span><span class=\"nv\">client_secret<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"nt\">-d<\/span> <span class=\"s2\">\"username=<\/span><span class=\"k\">${<\/span><span class=\"nv\">username<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"nt\">-d<\/span> <span class=\"s2\">\"password=<\/span><span class=\"k\">${<\/span><span class=\"nv\">password<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"k\">${<\/span><span class=\"nv\">oidc_url<\/span><span class=\"k\">}<\/span><span class=\"sb\">`<\/span>\r\n\r\n<span class=\"nv\">id_token<\/span><span class=\"o\">=<\/span><span class=\"sb\">`<\/span><span class=\"nb\">echo<\/span> <span class=\"nv\">$json_data<\/span> | jq <span class=\"s1\">'.id_token'<\/span> | <span class=\"nb\">tr<\/span> <span class=\"nt\">-d<\/span> <span class=\"s1\">'\"'<\/span><span class=\"sb\">`<\/span>\r\n<span class=\"nv\">refresh_token<\/span><span class=\"o\">=<\/span><span class=\"sb\">`<\/span><span class=\"nb\">echo<\/span> <span class=\"nv\">$json_data<\/span> | jq <span class=\"s1\">'.refresh_token'<\/span> | <span class=\"nb\">tr<\/span> <span class=\"nt\">-d<\/span> <span class=\"s1\">'\"'<\/span><span class=\"sb\">`<\/span>\r\n<span class=\"nv\">access_token<\/span><span class=\"o\">=<\/span><span class=\"sb\">`<\/span><span class=\"nb\">echo<\/span> <span class=\"nv\">$json_data<\/span> | jq <span class=\"s1\">'.access_token'<\/span> | <span class=\"nb\">tr<\/span> <span class=\"nt\">-d<\/span> <span class=\"s1\">'\"'<\/span><span class=\"sb\">`<\/span>\r\n\r\n<span class=\"c\">### Print tokens<\/span>\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s2\">\"ID_TOKEN=<\/span><span class=\"nv\">$id_token<\/span><span class=\"s2\">\"<\/span><span class=\"p\">;<\/span> <span class=\"nb\">echo\r\necho<\/span> <span class=\"s2\">\"REFRESH_TOKEN=<\/span><span class=\"nv\">$refresh_token<\/span><span class=\"s2\">\"<\/span><span class=\"p\">;<\/span> <span class=\"nb\">echo\r\necho<\/span> <span class=\"s2\">\"ACCESS_TOKEN=<\/span><span class=\"nv\">$access_token<\/span><span class=\"s2\">\"<\/span><span class=\"p\">;<\/span> <span class=\"nb\">echo<\/span>\r\n\r\n<span class=\"c\">### Introspect the id token<\/span>\r\n\r\n<span class=\"nv\">token<\/span><span class=\"o\">=<\/span><span class=\"sb\">`<\/span>curl <span class=\"nt\">-k<\/span> <span class=\"nt\">--user<\/span> <span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"nv\">client_id<\/span><span class=\"k\">}<\/span><span class=\"s2\">:<\/span><span class=\"k\">${<\/span><span class=\"nv\">client_secret<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"nt\">-d<\/span> <span class=\"s2\">\"token=<\/span><span class=\"k\">${<\/span><span class=\"nv\">id_token<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"k\">${<\/span><span class=\"nv\">oidc_url<\/span><span class=\"k\">}<\/span>\/introspect<span class=\"sb\">`<\/span>\r\n<span class=\"nv\">token_details<\/span><span class=\"o\">=<\/span><span class=\"sb\">`<\/span><span class=\"nb\">echo<\/span> <span class=\"nv\">$token<\/span> | jq .<span class=\"sb\">`<\/span>\r\n<span class=\"nb\">echo<\/span> <span class=\"nv\">$token_details<\/span>\r\n\r\n<span class=\"c\">### Update kubectl config<\/span>\r\n\r\nkubectl config set-credentials <span class=\"k\">${<\/span><span class=\"nv\">username<\/span><span class=\"k\">}<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"s2\">\"--auth-provider=oidc\"<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"s2\">\"--auth-provider-arg=idp-issuer-url=<\/span><span class=\"k\">${<\/span><span class=\"nv\">realm_url<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"s2\">\"--auth-provider-arg=client-id=<\/span><span class=\"k\">${<\/span><span class=\"nv\">client_id<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"s2\">\"--auth-provider-arg=client-secret=<\/span><span class=\"k\">${<\/span><span class=\"nv\">client_secret<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"s2\">\"--auth-provider-arg=refresh-token=<\/span><span class=\"k\">${<\/span><span class=\"nv\">refresh_token<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"s2\">\"--auth-provider-arg=idp-certificate-authority=<\/span><span class=\"k\">${<\/span><span class=\"nv\">certificate<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"s2\">\"--auth-provider-arg=id-token=<\/span><span class=\"k\">${<\/span><span class=\"nv\">id_token<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span>\r\n\r\n<span class=\"c\">### Create new context<\/span>\r\n\r\nkubectl config set-context <span class=\"k\">${<\/span><span class=\"nv\">username<\/span><span class=\"k\">}<\/span>@<span class=\"k\">${<\/span><span class=\"nv\">cluster<\/span><span class=\"k\">}<\/span> <span class=\"nt\">--cluster<\/span><span class=\"o\">=<\/span><span class=\"k\">${<\/span><span class=\"nv\">cluster<\/span><span class=\"k\">}<\/span> <span class=\"nt\">--user<\/span><span class=\"o\">=<\/span><span class=\"k\">${<\/span><span class=\"nv\">username<\/span><span class=\"k\">}<\/span>\r\n\r\n<span class=\"c\">### Set current context<\/span>\r\nkubectl config use-context <span class=\"k\">${<\/span><span class=\"nv\">username<\/span><span class=\"k\">}<\/span>@<span class=\"k\">${<\/span><span class=\"nv\">cluster<\/span><span class=\"k\">}<\/span> \r\n\r\n<span class=\"c\">### Validate access with new context<\/span>\r\n\r\nkubectl get pods\r\n\r\n<\/code><\/pre>\n<h2>11. \u78ba\u8a8d\u884c\u52d5<\/h2>\n<p>\u4f7f\u7528\u5728Keycloak\u4e0a\u521b\u5efa\u7684\u7528\u6237\u6765\u9a8c\u8bc1\u5bf9Kubernetes\u96c6\u7fa4\u7684\u8bbf\u95ee\u6743\u9650\u3002<\/p>\n<h3>\u7ba1\u7406\u5458 &#8211; \u7528\u6237<\/h3>\n<p>\u5bf9\u4e8e\u96c6\u7fa4\uff0c\u53ef\u4ee5\u6267\u884c\u6240\u6709\u64cd\u4f5c\u3002<\/p>\n<pre class=\"post-pre\"><code># kubectl -n kube-system get all\r\nNAME                                   READY   STATUS    RESTARTS      AGE\r\npod\/coredns-64897985d-dn9c4            1\/1     Running   0             125m\r\npod\/etcd-minikube                      1\/1     Running   0             125m\r\npod\/kube-apiserver-minikube            1\/1     Running   0             15m\r\npod\/kube-controller-manager-minikube   1\/1     Running   0             125m\r\npod\/kube-proxy-gbw5v                   1\/1     Running   0             125m\r\npod\/kube-scheduler-minikube            1\/1     Running   0             125m\r\npod\/storage-provisioner                1\/1     Running   4 (15m ago)   125m\r\n\r\nNAME               TYPE        CLUSTER-IP   EXTERNAL-IP   PORT(S)                  AGE\r\nservice\/kube-dns   ClusterIP   10.96.0.10   &lt;none&gt;        53\/UDP,53\/TCP,9153\/TCP   125m\r\n\r\nNAME                        DESIRED   CURRENT   READY   UP-TO-DATE   AVAILABLE   NODE SELECTOR            AGE\r\ndaemonset.apps\/kube-proxy   1         1         1       1            1           kubernetes.io\/os=linux   125m\r\n\r\nNAME                      READY   UP-TO-DATE   AVAILABLE   AGE\r\ndeployment.apps\/coredns   1\/1     1            1           125m\r\n\r\nNAME                                DESIRED   CURRENT   READY   AGE\r\nreplicaset.apps\/coredns-64897985d   1         1         1       125m\r\n<\/code><\/pre>\n<h3>\u4eb2\u7231\u7684\u7528\u6237<\/h3>\n<p>\u53c2\u7167\u672a\u7ecf\u8bb8\u53ef\u7684\u8d44\u6e90\u4f1a\u5bfc\u81f4\u9519\u8bef\u3002<\/p>\n<pre class=\"post-pre\"><code># kubectl -n kube-system get all\r\nNAME                               READY   STATUS    RESTARTS      AGE\r\ncoredns-64897985d-dn9c4            1\/1     Running   0             128m\r\netcd-minikube                      1\/1     Running   0             128m\r\nkube-apiserver-minikube            1\/1     Running   0             17m\r\nkube-controller-manager-minikube   1\/1     Running   0             128m\r\nkube-proxy-gbw5v                   1\/1     Running   0             128m\r\nkube-scheduler-minikube            1\/1     Running   0             128m\r\nstorage-provisioner                1\/1     Running   4 (18m ago)   128m\r\nError from server (Forbidden): replicationcontrollers is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"replicationcontrollers\" in API group \"\" in the namespace \"kube-system\"\r\nError from server (Forbidden): services is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"services\" in API group \"\" in the namespace \"kube-system\"\r\nError from server (Forbidden): daemonsets.apps is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"daemonsets\" in API group \"apps\" in the namespace \"kube-system\"\r\nError from server (Forbidden): deployments.apps is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"deployments\" in API group \"apps\" in the namespace \"kube-system\"\r\nError from server (Forbidden): replicasets.apps is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"replicasets\" in API group \"apps\" in the namespace \"kube-system\"\r\nError from server (Forbidden): statefulsets.apps is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"statefulsets\" in API group \"apps\" in the namespace \"kube-system\"\r\nError from server (Forbidden): horizontalpodautoscalers.autoscaling is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"horizontalpodautoscalers\" in API group \"autoscaling\" in the namespace \"kube-system\"\r\nError from server (Forbidden): cronjobs.batch is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"cronjobs\" in API group \"batch\" in the namespace \"kube-system\"\r\nError from server (Forbidden): jobs.batch is forbidden: User \"https:\/\/keycloak.example.com:32084\/realms\/kubernetes#user dev\" cannot list resource \"jobs\" in API group \"batch\" in the namespace \"kube-system\"\r\n<\/code><\/pre>\n<h2>\u7ee7\u7eed<\/h2>\n<p>\u4f7f\u7528Keycloak\u7684OIDC\u8eab\u4efd\u9a8c\u8bc1\u5728Kubernetes\u4e0a\u8fdb\u884c\u79df\u6237\u63a7\u5236\u3002<\/p>\n<h2>\u8bf7\u9605\u8bfb\u4ee5\u4e0b\u5185\u5bb9\u3002<\/h2>\n<p>Keycloak\/\u5165\u95e8\/Kubernetes<br \/>\nhttps:\/\/www.keycloak.org\/\u5165\u95e8\/\u5165\u95e8-kube<\/p>\n<p>Kubernetes\/\u8eab\u4efd\u9a8c\u8bc1<br \/>\nhttps:\/\/kubernetes.io\/zh\/docs\/reference\/access-authn-authz\/authentication\/#openid-connect-tokens<\/p>\n<p>\u5982\u4f55\u5728Kubernetes\u4e2d\u4f7f\u7528Keycloak OIDC\u63d0\u4f9b\u8005\u5bf9\u7528\u6237\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"fri7rFT9SR\"><p><a href=\"https:\/\/middlewaretechnologies.in\/2022\/01\/how-to-authenticate-user-with-keycloak-oidc-provider-in-kubernetes.html\">How to authenticate user with Keycloak OIDC Provider in Kubernetes<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;How to authenticate user with Keycloak OIDC Provider in Kubernetes&#8221; &#8212; Middleware|Technologies\" src=\"https:\/\/middlewaretechnologies.in\/2022\/01\/how-to-authenticate-user-with-keycloak-oidc-provider-in-kubernetes.html\/embed#?secret=ZNo3YlpEc7#?secret=fri7rFT9SR\" data-secret=\"fri7rFT9SR\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<hr \/>\n<h2>\u5e7f\u544a<\/h2>\n<p>\u6211\u5728\u4f7f\u7528Twitter\u3002<br \/>\n\u5982\u679c\u4f60\u80fd\u5173\u6ce8\u6211\uff0c\u6211\u4f1a\u5f88\u9ad8\u5174\u3002<\/p>\n<p>@mochizuki875<br \/>\n\u6211\u5e0c\u671b\u6210\u4e3a\u4e00\u540d\u4e13\u4e1a\u7684IT\u5de5\u7a0b\u5e08\uff0c\u6211\u559c\u6b22Kubernetes\u3002<br \/>\n\u4e00\u53ea\u72d0\u72f8\uff0c\u800c\u4e0d\u662f\u72f8\u732b\u3002<br \/>\n<a class=\"twitter-timeline\" data-width=\"500\" data-height=\"750\" data-dnt=\"true\" href=\"https:\/\/twitter.com\/mochizuki875?ref_src=twsrc%5Etfw\">Tweets by mochizuki875<\/a><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u9996\u5148 \u901a\u5e38\u60c5\u51b5\u4e0b\uff0cKubernetes\u5e76\u6ca1\u6709\u7528\u6237\u7ba1\u7406\u673a\u5236\uff0c\u9700\u8981\u501f\u52a9\u5916\u90e8\u673a\u5236\u6765\u8fdb\u884c\u7528\u6237\u8ba4\u8bc1\u3002\u5982\u679c\u4f7f\u7528kubead [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-35864","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5c1d\u8bd5\u4f7f\u7528keycloak\u6765\u8fdb\u884ckubernetes\u7684oidc\u8ba4\u8bc1\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1\" \/>\n<meta property=\"og:description\" content=\"\u9996\u5148 \u901a\u5e38\u60c5\u51b5\u4e0b\uff0cKubernetes\u5e76\u6ca1\u6709\u7528\u6237\u7ba1\u7406\u673a\u5236\uff0c\u9700\u8981\u501f\u52a9\u5916\u90e8\u673a\u5236\u6765\u8fdb\u884c\u7528\u6237\u8ba4\u8bc1\u3002\u5982\u679c\u4f7f\u7528kubead [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5c1d\u8bd5\u4f7f\u7528keycloak\u6765\u8fdb\u884ckubernetes\u7684oidc\u8ba4\u8bc1\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-05-13T13:26:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-28T18:54:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/5-0.png\" \/>\n<meta name=\"author\" content=\"\u9038, \u79d1\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u9038, \u79d1\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/\",\"name\":\"\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-05-13T13:26:55+00:00\",\"dateModified\":\"2024-04-28T18:54:46+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/85c1dae56e6ea1e695c73d33c684d487\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/85c1dae56e6ea1e695c73d33c684d487\",\"name\":\"\u9038, \u79d1\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/c94f6d9cbbfbca863fab309840bd690c153c95f8490c290ad2ed54dd693dad16?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/c94f6d9cbbfbca863fab309840bd690c153c95f8490c290ad2ed54dd693dad16?s=96&d=mm&r=g\",\"caption\":\"\u9038, \u79d1\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/keyi\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u5c1d\u8bd5\u4f7f\u7528keycloak\u6765\u8fdb\u884ckubernetes\u7684oidc\u8ba4\u8bc1\/","og_locale":"zh_CN","og_type":"article","og_title":"\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1","og_description":"\u9996\u5148 \u901a\u5e38\u60c5\u51b5\u4e0b\uff0cKubernetes\u5e76\u6ca1\u6709\u7528\u6237\u7ba1\u7406\u673a\u5236\uff0c\u9700\u8981\u501f\u52a9\u5916\u90e8\u673a\u5236\u6765\u8fdb\u884c\u7528\u6237\u8ba4\u8bc1\u3002\u5982\u679c\u4f7f\u7528kubead [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u5c1d\u8bd5\u4f7f\u7528keycloak\u6765\u8fdb\u884ckubernetes\u7684oidc\u8ba4\u8bc1\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-05-13T13:26:55+00:00","article_modified_time":"2024-04-28T18:54:46+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d25b737434c4406c3479f\/5-0.png"}],"author":"\u9038, \u79d1","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u9038, \u79d1","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"9 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/","name":"\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-05-13T13:26:55+00:00","dateModified":"2024-04-28T18:54:46+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/85c1dae56e6ea1e695c73d33c684d487"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u5c1d\u8bd5\u4f7f\u7528Keycloak\u6765\u8fdb\u884cKubernetes\u7684OIDC\u8ba4\u8bc1"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/85c1dae56e6ea1e695c73d33c684d487","name":"\u9038, \u79d1","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/c94f6d9cbbfbca863fab309840bd690c153c95f8490c290ad2ed54dd693dad16?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c94f6d9cbbfbca863fab309840bd690c153c95f8490c290ad2ed54dd693dad16?s=96&d=mm&r=g","caption":"\u9038, \u79d1"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/keyi\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%9d%e8%af%95%e4%bd%bf%e7%94%a8keycloak%e6%9d%a5%e8%bf%9b%e8%a1%8ckubernetes%e7%9a%84oidc%e8%ae%a4%e8%af%81\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/35864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=35864"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/35864\/revisions"}],"predecessor-version":[{"id":76535,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/35864\/revisions\/76535"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=35864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=35864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=35864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}