-
Notifications
You must be signed in to change notification settings - Fork 267
-
Notifications
You must be signed in to change notification settings - Fork 267
Unknown user error #225
Comments
Hey - this looks like your local RBAC rules are set up incorrectly. How have you configured RBAC for your kube-lego instance? Could you post your RoleBinding, Role, ServiceAccount and kube-lego Deployment spec? |
No I haven't configured RBAC for my kube-lego instance. I just followed the GCE example and adapted it to my application. https://github.com/jetstack/kube-lego/tree/master/examples/gce Is there a guide for setting up RBAC for kube-lego? I found this issue which has a rbac.yaml file. I also found this merge request that has an rbac.yaml: However when I attempt to use them I am getting this error: kubectl apply -f lego/rbac.yaml Turns out the error I was receiving in an known issue with GKE 1.6. I resolved by following this article: get current google identity$ gcloud info | grep Account grant cluster-admin to your current identity$ kubectl create clusterrolebinding myname-cluster-admin-binding --clusterrole=cluster-admin --user=myname@example.org https://coreos.com/operators/prometheus/docs/latest/troubleshooting.html |
The rbac in the PR mentioned above wasnt sufficient for our setup (we use GCE ingress). If needed I can make a PR with the required changes? |
Can you post what permissions you had to add for the endpoints resource? |
I have the same problem and I'm following the example of nginx, some idea of how to solve it?
|
To help people late to this party like me:
$ gcloud info | grep Account
Account: [myname@example.org] grant cluster-admin to your current identity $ kubectl create clusterrolebinding myname-cluster-admin-binding --clusterrole=cluster-admin --
user=myname@example.org
Clusterrolebinding "myname-cluster-admin-binding" created Good luck! |
To chime in further, the issue I ran into was case-sensitivity with my email! Running But, when I looked at the error @Isaac6702 (and I) was getting, I finally noticed that the first letter of my email was capitalized. When I created the Hope this helps folks like me banging their head against the wall! |
For anybody running into this issue, don't overlook @mike-engel recommendation above, its hard to catch but it happened to me as well. |
E0706 02:04:01.000444 1 reflector.go:201] github.com/jetstack/kube-lego/pkg/kubelego/watch.go:112: Failed to list *v1beta1.Ingress: User "system:serviceaccount:kube-lego:default" cannot list ingresses.extensions at the cluster scope.: "Unknown user "system:serviceaccount:kube-lego:default"" (get ingresses.extensions)
The text was updated successfully, but these errors were encountered: