TkeAuthenticator is a Kubernetes Authentication Webhook and Authorization Webhook service that provides CAM-based Identity Authentication and access control for TKE clusters.Capability | Description | Corresponding Kubernetes Stage |
CAM identity authentication (CAM Identity Authentication) | Authenticate users through CAM identities and map CAM users/roles to Kubernetes RBAC users and user groups. Use with tke-cam-tool to build a bridge from CAM identities to Kubernetes RBAC users/groups. | |
CAM user group authorization (CAM User Group Authorization) | Perform Kubernetes RBAC authorization based on CAM user groups, and support batch management of cluster permissions by user group. A CAM user group is a collection of users (sub-accounts) with the same responsibilities, and is suitable for quickly granting the same Kubernetes object access permissions to sub-accounts with the same responsibilities. |
UserGroupAccessControl (CAM user group authentication) was originally a standalone component and has now been merged into TkeAuthenticator for unified deployment.TkeAuthenticator is installed, both features are enabled by default and require no additional configuration. You can also use either feature independently.TkeAuthenticator component version must be 1.0.0 or later.
TKE_QCSRole to associate with the preset policy QcloudAccessForTKERoleInGroupsForUser during component installation. as shown in the following figure:

TkeAuthenticator is implemented through the Authentication Webhook, which maps Tencent Cloud CAM identities to Kubernetes RBAC users and user groups. When used together with tke-cam-tool, TkeAuthenticator builds a bridge from CAM identities to Kubernetes RBAC users/groups, eliminating the need to store any static cluster credentials locally, such as x509 client certificates or static tokens.
TkeAuthenticator.TkeAuthenticator sends the request in the token to the Tencent Cloud Security Token Service (STS) and calls GetCallerIdentity to obtain the user's CAM identity information (ARN).TkeAuthenticator searches all CAMIdentityMapping resources for a mapping rule that matches the ARN, and returns the corresponding Kubernetes RBAC username and user groups to the API Server.CAMIdentityMapping, TkeAuthenticator returns a "Not Authenticated" decision, and the user sees an "Unauthorized" error.TkeAuthenticator to the STS service to obtain the user's CAM identity. The Tencent Cloud credentials used to sign the request, which generate the signature in the Authorization header, represent the CAM identity that the user wants to be authenticated as. For example, if a token is signed with the Secret ID and Secret Key of a sub-account, the token will be authenticated as that sub-account.k8s-tke-v1. and a base64-encoded JSON object:k8s-tke-v1.<base64-encoded JSON>
{"clusterId": "cls-*****","header": {"Authorization": ["TC3-HMAC-SHA256 Credential=AKID*****/2024-09-03/sts/tc3_request, SignedHeaders=content-type;host;x-tc-action;x-tc-tke-clusterid, Signature=*****"],"Content-Type": ["application/json; charset=utf-8"],"Host": ["sts.internal.tencentcloudapi.com"],"X-TC-Action": ["GetCallerIdentity"],"X-TC-TKE-ClusterID": ["cls-*****"],"X-TC-Timestamp": ["1725332268"],"X-TC-Token": ["*****"],"X-TC-Version": ["2018-08-13"]}}
Field | Description |
Authorization | |
Content-Type | Request content type. |
Host | STS service endpoint address. |
X-TC-Action | Fixed to GetCallerIdentity. |
X-TC-TKE-ClusterID | Cluster ID accessible by the token. |
content-typehostx-tc-actionx-tc-tke-clusterid (ensures that the token can only be used to access the specified cluster)tke-cam-tool is a CLI tool that helps users generate the kubeconfig file and token required to access the Kubernetes API Server.
tke-cam-tool generates a token by using the Tencent Cloud credentials provided by the user:tke-cam-tool exec-cred token --cluster-id <CLUSTER_ID> [FLAGS...]
{"kind": "ExecCredential","apiVersion": "client.authentication.k8s.io/v1beta1","spec": { "interactive": false },"status": {"expirationTimestamp": "2024-10-12T09:18:05Z","token": "k8s-tke-v1.<base64-encoded content>"}}
expirationTimestamp in ExecCredential indicates the expiration time of the token, and tke-cam-tool reuses cached tokens that have not expired.--no-cache flag to disable caching and force a new token to be generated each time.--role, a cached token is reused only if the same role ARN, external ID, and session name are used.tke-cam-tool exec-cred kubeconfig --cluster-id <CLUSTER_ID> --region <REGION> [FLAGS...]
k8s.io/client-go to dynamically run the tke-cam-tool exec-cred token command to generate a token for each kubectl request. Example:apiVersion: v1clusters:- cluster:certificate-authority-data: BASE64_PEM_ENCODED_CA_CERTIFICATEserver: API_SERVER_ADDRESSname: <CLUSTER_ID> # Automatically generated. The value is the cluster ID.contexts:- context:cluster: <CLUSTER_ID>user: <CLUSTER_ID>-exec-cred-pluginname: <CLUSTER_ID>-exec-cred-plugin-context # Automatically generated.current-context: <CLUSTER_ID>-exec-cred-plugin-contextkind: Configpreferences: {}users:- name: <CLUSTER_ID>-exec-cred-plugin # Automatically generated.user:exec:apiVersion: client.authentication.k8s.io/v1beta1args:- exec-cred- token- --cluster-id- <CLUSTER_ID>- --profile- defaultcommand: tke-cam-toolenv: nullinteractiveMode: NeverprovideClusterInfo: false
TkeAuthenticator needs to convert CAM identities to Kubernetes users through mapping rules. The mapping rule is CAMIdentityMapping, a Kubernetes CRD (Custom Resource) that defines the mapping from a CAM identity ARN to Kubernetes RBAC users and user groups.TkeAuthenticator, the component searches all CAMIdentityMapping resources for a rule that matches the user's ARN, and returns the corresponding Kubernetes username and user groups to the API Server.apiVersion: authenticator.tke.cloud.tencent.com/v1kind: CAMIdentityMappingmetadata:name: <MAPPING_NAME> # Custom resource name, for example: my-sub-account-mappingspec:arn: <CAM_IDENTITY_ARN> # CAM identity ARN, for example: qcs::cam::uin/100000000001:uin/100000000002username: <K8S_USERNAME> # Custom Kubernetes username, for example: my-usergroups: # Mapped Kubernetes user groups (optional)- <GROUP_1> # Custom user group name, for example: dev-team- <GROUP_2> # Custom user group name, for example: read-only
Field | Required | Description |
metadata.name | Yes | Resource name. You can customize it. It must be unique within the cluster. |
spec.arn | Yes | ARN of the CAM identity, used to match authenticated users. Exact match and wildcards are supported. |
spec.username | Yes | Kubernetes username returned to the API Server after successful authentication. |
spec.groups | No | List of Kubernetes groups returned to the API Server after successful authentication. |
apiVersion: authenticator.tke.cloud.tencent.com/v1kind: CAMIdentityMappingmetadata:name: <MAPPING_NAME> # Custom resource name, for example: my-sub-account-mappingspec:arn: qcs::cam::uin/<ROOT_ACCOUNT_ID>:uin/<SUB_ACCOUNT_ID>username: <K8S_USERNAME> # Custom Kubernetes username, for example: my-usergroups:- read-group # Custom user group name- write-group # Custom user group name- {{CAMUserGroupIDs}}
qcs::SERVICE:(REGION:)ACCOUNT:RESOURCE.Type | ARN Format | Example |
Root Account | qcs::cam::uin/<ROOT_ACCOUNT_ID>:root | qcs::cam::uin/100000000001:root |
Sub-account. | qcs::cam::uin/<ROOT_ACCOUNT_ID>:uin/<SUB_ACCOUNT_ID> | qcs::cam::uin/100000000001:uin/100000000002 |
CAM Role | qcs::cam::uin/<ROOT_ACCOUNT_ID>:role/<ROLE_ID> | qcs::cam::uin/100000000001:role/4611686018427000001 |
Associating Accounts | qcs::sts::uin/<ROOT_ACCOUNT_ID>:federated-user/<UIN> | qcs::sts::uin/100000000001:federated-user/100000000002 |
Wildcard | qcs::cam::uin/<ROOT_ACCOUNT_ID>:uin/* | Matches all sub-accounts under this root account. |
username and groups. They will be automatically replaced with actual values after successful authentication. All placeholders are enclosed in double curly braces {{}}.Placeholder | Description |
{{AccountID}} | Root account ID to which the CAM identity belongs |
{{SessionName}} | Session name of the CAM identity (valid only for CAM roles) |
{{SecretID}} | Tencent Cloud Secret ID used for Token signing |
{{AccountID}} as the username:apiVersion: authenticator.tke.cloud.tencent.com/v1kind: CAMIdentityMappingmetadata:name: <MAPPING_NAME> # Custom resource name, for example: account-id-mappingspec:arn: qcs::cam::uin/<ROOT_ACCOUNT_ID>:uin/<SUB_ACCOUNT_ID>username: {{AccountID}}
Placeholder | Description |
{{CAMUserGroupIDs}} | IDs of all CAM user groups to which the sub-account belongs (valid only for sub-accounts) |
{{CAMUserGroupIDs}} is automatically expanded to all CAM user group IDs that the sub-account belongs to during authentication. You can add custom prefixes or suffixes before and after the placeholder to control the format of the returned user groups.{{CAMUserGroupIDs}} to associate user groups:apiVersion: authenticator.tke.cloud.tencent.com/v1kind: CAMIdentityMappingmetadata:name: <MAPPING_NAME> # Custom resource name, for example: cam-group-mappingspec:arn: qcs::cam::uin/<ROOT_ACCOUNT_ID>:uin/<SUB_ACCOUNT_ID>username: <K8S_USERNAME> # Custom Kubernetes username, for example: my-usergroups:- cam-group-{{CAMUserGroupIDs}}
56789 and 67890. The user groups returned after authentication are:cam-group-56789cam-group-67890{{CAMUserGroupIDs}} is valid only when the CAM identity is a sub-account. If the CAM identity is a role or federated account, the placeholder does not produce any user groups.kubectl is installed locally.Method | Scenario | Credential Type |
Existing sub-account Secret ID / Secret Key | Permanent Keys | |
Log in through enterprise SSO or Tencent Cloud account OAuth. | Temporary Keys |
export TENCENTCLOUD_SECRET_ID=<YOUR_SECRET_ID>export TENCENTCLOUD_SECRET_KEY=<YOUR_SECRET_KEY>
# Configure the SSO Login URL# Replace <YOUR_SSO_ID> with the enterprise SSO configuration ID (obtain it from the enterprise IdP administrator)tccli sso configure --url https://tencentcloudsso.com/<YOUR_SSO_ID>/login# Perform Logintccli sso login
tccli auth login
~/.tccli/default.credential.CAMIdentityMapping to map CAM identities to Kubernetes users. The way to fill in the arn field varies depending on the method selected in step 2:arn:apiVersion: authenticator.tke.cloud.tencent.com/v1kind: CAMIdentityMappingmetadata:name: <MAPPING_NAME> # Custom resource name, for example: my-cam-mappingspec:arn: qcs::cam::uin/<ROOT_ACCOUNT_ID>:uin/<SUB_ACCOUNT_ID>username: <K8S_USERNAME> # Custom Kubernetes username, for example: my-user. Subsequent RBAC bindings must match this username.
--role, and fill in the ARN of that role in arn:apiVersion: authenticator.tke.cloud.tencent.com/v1kind: CAMIdentityMappingmetadata:name: <MAPPING_NAME> # Custom resource name, for example: my-cam-mappingspec:arn: qcs::cam::uin/<ROOT_ACCOUNT_ID>:role/<ROLE_ID>username: <K8S_USERNAME> # Custom Kubernetes username, for example: my-user. Subsequent RBAC bindings must match this username.
<K8S_USERNAME> must match the username in the CAMIdentityMapping above):apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata:name: <CLUSTER_ROLE_NAME> # Custom ClusterRole name, for example: pod-readerrules:- apiGroups: [""]resources: ["pods"]verbs: ["get", "list"]---apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:name: <BINDING_NAME> # Custom ClusterRoleBinding name, for example: my-bindingroleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: <CLUSTER_ROLE_NAME> # References the name of the ClusterRole created abovesubjects:- kind: UserapiGroup: rbac.authorization.k8s.ioname: <K8S_USERNAME> # Must match the username in CAMIdentityMapping, for example: my-user
export CLUSTER_ID=<YOUR_CLUSTER_ID> # For example: cls-xxxxxxxxexport REGION=<YOUR_REGION> # For example: ap-guangzhou
tke-cam-tool exec-cred kubeconfig \\--cluster-id ${CLUSTER_ID} \\--region ${REGION} \\-o ${CLUSTER_ID}.kubeconfig
--role:tke-cam-tool exec-cred kubeconfig \\--cluster-id ${CLUSTER_ID} \\--region ${REGION} \\--profile default \\--token-profile default \\--role qcs::cam::uin/<ROOT_ACCOUNT_ID>:roleName/<ROLE_NAME> \\ # Replace with the actual root account ID and role name-o ${CLUSTER_ID}.kubeconfig
Parameter | Description |
--profile default | Use the credentials written during SSO login to call TKE APIs to obtain cluster information. |
--token-profile default | Credentials used when kubectl in kubeconfig calls tke-cam-tool |
--role | Assume a CAM role to obtain new temporary credentials in the format qcs::cam::uin/<ROOT_ACCOUNT_ID>:roleName/<ROLE_NAME>. Replace <ROOT_ACCOUNT_ID> with the root account ID (for example, 100000000001) and <ROLE_NAME> with the CAM role name (for example, TKE_QCSRole). |
# Can read pods (authorized)kubectl --kubeconfig ${CLUSTER_ID}.kubeconfig get pod# Cannot read deployments (unauthorized)kubectl --kubeconfig ${CLUSTER_ID}.kubeconfig get deployment# Error from server (Forbidden): deployments.apps is forbidden: User "<K8S_USERNAME>" cannot list resource "deployments" in API group "apps" in the namespace "default"
TkeAuthenticator has a built-in authentication feature based on CAM user groups (Authorization Webhook), which integrates the Kubernetes RBAC permission management mechanism with Tencent Cloud CAM user groups to facilitate fine-grained access control over sub-accounts. After the component is installed, this feature is enabled by default.SubjectAccessReview and forwards it to the /authorize endpoint of TkeAuthenticator.NoOpinion is returned, and the API Server continues to use other authorizers (such as the built-in RBAC) for authentication.Method | Scenario |
Operate through the visual page, suitable for users unfamiliar with YAML. | |
Create resources through YAML files, suitable for users familiar with Kubernetes. |

<CAM_USER_GROUP_ID> (for example, 12345), create the following RBAC rule to allow members of this user group to read all Pods:apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata:name: <CLUSTER_ROLE_NAME> # Custom ClusterRole name, for example: pod-readerrules:- apiGroups: [""]resources: ["pods"]verbs: ["get", "list", "watch"]---apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:name: <BINDING_NAME> # Custom ClusterRoleBinding name, for example: cam-group-bindingroleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: <CLUSTER_ROLE_NAME> # References the name of the ClusterRole created abovesubjects:- kind: GroupapiGroup: rbac.authorization.k8s.ioname: <CAM_USER_GROUP_ID> # Replace with the CAM user group ID, for example: 12345
# Replace ${KUBECONFIG_PATH} with the actual kubeconfig file path# Verify that pods can be read (the user group is authorized)kubectl --kubeconfig ${KUBECONFIG_PATH} get pods# Verify that unauthorized operations cannot be performedkubectl --kubeconfig ${KUBECONFIG_PATH} delete pod some-pod# Expected: A Forbidden error is returned
# Development team - Can read and write the dev namespaceapiVersion: rbac.authorization.k8s.io/v1kind: RoleBindingmetadata:name: <BINDING_NAME> # Custom RoleBinding name, for example: dev-team-bindingnamespace: devroleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: edit # Built-in ClusterRole of Kubernetessubjects:- kind: GroupapiGroup: rbac.authorization.k8s.ioname: <DEV_GROUP_ID> # Replace with the CAM user group ID of the development team, for example: 56789---# Ops team - Cluster administrator permissionsapiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:name: <BINDING_NAME> # Custom ClusterRoleBinding name, for example: ops-team-adminroleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: cluster-admin # Built-in ClusterRole of Kubernetessubjects:- kind: GroupapiGroup: rbac.authorization.k8s.ioname: <OPS_GROUP_ID> # Replace with the CAM user group ID of the Ops team, for example: 67890
TkeAuthenticator has a built-in user group cache mechanism to reduce the frequency of calls to the CAM API.UserGroupAccessControl component, migrate by following these steps:UserGroupAccessControl component on the component management page.TkeAuthenticator version installed in the cluster is 1.0.0 or later.TkeAuthenticator is installed, all features (authentication + authorization) are enabled by default and require no additional configuration.NoOpinion (no decision), and the API Server then continues to use other authorizers (such as the built-in RBAC) for authentication.TkeAuthenticator, but they are two completely independent feature modules with no functional dependency on each other:/authenticate): Responsible for CAM identity authentication, verifying the user's CAM identity and mapping it to Kubernetes users/groups./authorize): Responsible for authorization, determining whether a user has permission to perform an operation based on CAM user groups and RBAC rules.TkeAuthenticator component, authentication and authorization are implemented independently and are merely deployed together in the same service. You can use either feature alone or both at the same time.{{CAMUserGroupIDs}} Placeholder Valid for Non-Sub-Account Identities?{{CAMUserGroupIDs}} is valid only when the CAM identity is a sub-account. If the CAM identity is a role or federated account, the placeholder does not produce any user groups.Esta página foi útil?
Você também pode entrar em contato com a Equipe de vendas ou Enviar um tíquete em caso de ajuda.
comentários