1.查看ETCD集群中运行的ETCD pod
[root@master1 ~]# kubectl get pod -n kube-system | grep etcd
etcd-master1 1/1 Running 0 61m
etcd-master2 1/1 Running 0 58m
etcd-master3 1/1 Running 0 56m
2.进入ETCD pod容器
[root@master1 ~]# kubectl exec -it etcd-master1 -n kube-system -- /bin/sh
3.设置环境变量为v3
export ETCDCTL_API=3
4.查看ETCD中所有的key,输入以下命令:
etcdctl --cacert=/etc/kubernetes/pki/etcd/ca.crt --cert=/etc/kubernetes/pki/etcd/healthcheck-client.crt --key=/etc/kubernetes/pki/etcd/healthcheck-client.key get / --prefix --keys-only
5.得到以下结果:
/registry/clusterrolebindings/system:volume-scheduler
/registry/clusterroles/admin
/registry/clusterroles/cluster-admin
/registry/clusterroles/edit
/registry/clusterroles/flannel
/registry/clusterroles/ks-installer
/registry/clusterroles/kubeadm:get-nodes
/registry/clusterroles/nfs-client-provisioner-runner
/registry/clusterroles/system:aggregate-to-admin
/registry/clusterroles/system:aggregate-to-edit
/registry/clusterroles/system:aggregate-to-view
/registry/clusterroles/system:auth-delegator
/registry/clusterroles/system:basic-user
/registry/clusterroles/system:certificates.k8s.io:certificatesigningrequests:nodeclient
/registry/clusterroles/system:certificates.k8s.io:certificatesigningrequests:selfnodeclient
/registry/clusterroles/system:certificates.k8s.io:kube-apiserver-client-approver
/registry/clusterroles/system:certificates.k8s.io:kube-apiserver-client-kubelet-approver
/registry/clusterroles/system:certificates.k8s.io:kubelet-serving-approver
/registry/clusterroles/system:certificates.k8s.io:legacy-unknown-approver
/registry/clusterroles/system:controller:attachdetach-controller
/registry/clusterroles/system:controller:certificate-controller
/registry/clusterroles/system:controller:clusterrole-aggregation-controller
/registry/clusterroles/system:controller:cronjob-controller
/registry/clusterroles/system:controller:daemon-set-controller
/registry/clusterroles/system:controller:deployment-controller
/registry/clusterroles/system:controller:disruption-controller
/registry/clusterroles/system:controller:endpoint-controller
/registry/clusterroles/system:controller:endpointslice-controller
/registry/clusterroles/system:controller:expand-controller
/registry/clusterroles/system:controller:generic-garbage-collector
/registry/clusterroles/system:controller:horizontal-pod-autoscaler
/registry/clusterroles/system:controller:job-controller
/registry/clusterroles/system:controller:namespace-controller
/registry/clusterroles/system:controller:node-controller
/registry/clusterroles/system:controller:persistent-volume-binder
/registry/clusterroles/system:controller:pod-garbage-collector
/registry/clusterroles/system:controller:pv-protection-controller
/registry/clusterroles/system:controller:pvc-protection-controller
/registry/clusterroles/system:controller:replicaset-controller
/registry/clusterroles/system:controller:replication-controller
/registry/clusterroles/system:controller:resourcequota-controller
/registry/clusterroles/system:controller:route-controller
/registry/clusterroles/system:controller:service-account-controller
/registry/clusterroles/system:controller:service-controller
/registry/clusterroles/system:controller:statefulset-controller
/registry/clusterroles/system:controller:ttl-controller
/registry/clusterroles/system:coredns
/registry/clusterroles/system:discovery
/registry/clusterroles/system:heapster
/registry/clusterroles/system:kube-aggregator
/registry/clusterroles/system:kube-controller-manager
/registry/clusterroles/system:kube-dns
/registry/clusterroles/system:kube-scheduler
/registry/clusterroles/system:kubelet-api-admin
/registry/clusterroles/system:node
/registry/clusterroles/system:node-bootstrapper
/registry/clusterroles/system:node-problem-detector
/registry/clusterroles/system:node-proxier
/registry/clusterroles/system:persistent-volume-provisioner
/registry/clusterroles/system:public-info-viewer
/registry/clusterroles/system:volume-scheduler
/registry/clusterroles/view
/registry/configmaps/kube-public/cluster-info
/registry/configmaps/kube-system/coredns
/registry/configmaps/kube-system/extension-apiserver-authentication
/registry/configmaps/kube-system/kube-flannel-cfg
/registry/configmaps/kube-system/kube-proxy
/registry/configmaps/kube-system/kubeadm-config
/registry/configmaps/kube-system/kubelet-config-1.18
/registry/controllerrevisions/kube-system/kube-flannel-ds-6bd695f86f
/registry/controllerrevisions/kube-system/kube-proxy-5f7b7d4f89
/registry/csinodes/master1
/registry/csinodes/master2
/registry/csinodes/master3
/registry/csinodes/node1
/registry/daemonsets/kube-system/kube-flannel-ds
/registry/daemonsets/kube-system/kube-proxy
/registry/deployments/default/nfs-client-provisioner
/registry/deployments/kube-system/coredns
/registry/deployments/kubesphere-system/ks-installer
/registry/endpointslices/default/kubernetes
/registry/endpointslices/kube-system/kube-dns-6twcp
/registry/events/default/nfs-client-provisioner-6d4469b5b5-6vfcm.1656a941b15fb15f
/registry/events/default/nfs-client-provisioner-6d4469b5b5-6vfcm.1656a946889f01f3
/registry/events/default/nfs-client-provisioner-6d4469b5b5-6vfcm.1656a9468a94e69d
/registry/events/default/nfs-client-provisioner-6d4469b5b5-6vfcm.1656a9469349ce73
/registry/events/default/nfs-client-provisioner-6d4469b5b5-6vfcm.1656a9487875612f
/registry/events/default/nfs-client-provisioner-6d4469b5b5-6vfcm.1656a949d68288ef
/registry/events/default/nfs-client-provisioner-6d4469b5b5-6vfcm.1656a953c3f77d6a
/registry/events/default/nfs-client-provisioner-6d4469b5b5-m46z5.1656a96f739daadc
/registry/events/default/nfs-client-provisioner-6d4469b5b5-m46z5.1656a97063207f35
/registry/events/default/nfs-client-provisioner-6d4469b5b5-m46z5.1656a9706616fe92
/registry/events/default/nfs-client-provisioner-6d4469b5b5-m46z5.1656a9706cc35b5d
/registry/events/default/nfs-client-provisioner-6d4469b5b5-m46z5.1656a972065e2a40
/registry/events/default/nfs-client-provisioner-6d4469b5b5-m46z5.1656a9779f9559f4
/registry/events/default/nfs-client-provisioner-6d4469b5b5.1656a94770dfc0c7
/registry/events/default/nfs-client-provisioner-6d4469b5b5.1656a949d58bd081
/registry/events/default/nfs-client-provisioner-6d4469b5b5.1656a97538aa6b1d
/registry/events/default/nfs-client-provisioner-6d4469b5b5.1656a9779d8eb208
/registry/events/default/nfs-client-provisioner.1656a9476ffefbeb
/registry/events/default/nfs-client-provisioner.1656a97537bfee9e
/registry/events/kube-system/coredns-66bff467f8-5mnfr.1656a8dc8a1d7b89
/registry/events/kube-system/coredns-66bff467f8-5mnfr.1656a8e50bccb286
/registry/events/kube-system/coredns-66bff467f8-5mnfr.1656a90868ef48d8
/registry/events/kube-system/coredns-66bff467f8-zbt6q.1656a8dc8aac58c5
/registry/events/kube-system/coredns-66bff467f8-zbt6q.1656a8e50c886a7b
/registry/events/kube-system/coredns-66bff467f8-zbt6q.1656a907f1b988b0
/registry/events/kubesphere-system/ks-installer-7cb866bd-k8x62.1656aab854c6ef5d
/registry/events/kubesphere-system/ks-installer-7cb866bd-k8x62.1656aac086f21fad
/registry/events/kubesphere-system/ks-installer-7cb866bd-k8x62.1656ab5dcdcded0d
/registry/events/kubesphere-system/ks-installer-7cb866bd-k8x62.1656ab5dd26086ac
/registry/events/kubesphere-system/ks-installer-7cb866bd-k8x62.1656ab5ddafeacbc
/registry/events/kubesphere-system/ks-installer-7cb866bd-k8x62.1656ab6144db00ae
/registry/events/kubesphere-system/ks-installer-7cb866bd.1656aac0858e0433
/registry/events/kubesphere-system/ks-installer.1656aac08466d684
/registry/leases/kube-node-lease/master1
/registry/leases/kube-node-lease/master2
/registry/leases/kube-node-lease/master3
/registry/leases/kube-node-lease/node1
/registry/leases/kube-system/kube-controller-manager
/registry/leases/kube-system/kube-scheduler
/registry/masterleases/192.168.200.3
/registry/masterleases/192.168.200.4
/registry/masterleases/192.168.200.5
/registry/minions/master1
/registry/minions/master2
/registry/minions/master3
/registry/minions/node1
/registry/namespaces/default
/registry/namespaces/kube-node-lease
/registry/namespaces/kube-public
/registry/namespaces/kube-system
/registry/namespaces/kubesphere-system
/registry/pods/default/nfs-client-provisioner-6d4469b5b5-m46z5
/registry/pods/kube-system/coredns-66bff467f8-5mnfr
/registry/pods/kube-system/coredns-66bff467f8-zbt6q
/registry/pods/kube-system/etcd-master1
/registry/pods/kube-system/etcd-master2
/registry/pods/kube-system/etcd-master3
/registry/pods/kube-system/kube-apiserver-master1
/registry/pods/kube-system/kube-apiserver-master2
/registry/pods/kube-system/kube-apiserver-master3
/registry/pods/kube-system/kube-controller-manager-master1
/registry/pods/kube-system/kube-controller-manager-master2
/registry/pods/kube-system/kube-controller-manager-master3
/registry/pods/kube-system/kube-flannel-ds-4zdjs
/registry/pods/kube-system/kube-flannel-ds-7hvlk
/registry/pods/kube-system/kube-flannel-ds-hmtgx
/registry/pods/kube-system/kube-flannel-ds-z8fvs
/registry/pods/kube-system/kube-proxy-448fc
/registry/pods/kube-system/kube-proxy-8jjrs
/registry/pods/kube-system/kube-proxy-cjnt8
/registry/pods/kube-system/kube-proxy-pf4wb
/registry/pods/kube-system/kube-scheduler-master1
/registry/pods/kube-system/kube-scheduler-master2
/registry/pods/kube-system/kube-scheduler-master3
/registry/pods/kubesphere-system/ks-installer-7cb866bd-k8x62
/registry/podsecuritypolicy/psp.flannel.unprivileged
/registry/priorityclasses/system-cluster-critical
/registry/priorityclasses/system-node-critical
/registry/ranges/serviceips
/registry/ranges/servicenodeports
/registry/replicasets/default/nfs-client-provisioner-6d4469b5b5
/registry/replicasets/kube-system/coredns-66bff467f8
/registry/replicasets/kubesphere-system/ks-installer-7cb866bd
/registry/rolebindings/default/leader-locking-nfs-client-provisioner
/registry/rolebindings/kube-public/kubeadm:bootstrap-signer-clusterinfo
/registry/rolebindings/kube-public/system:controller:bootstrap-signer
/registry/rolebindings/kube-system/kube-proxy
/registry/rolebindings/kube-system/kubeadm:kubelet-config-1.18
/registry/rolebindings/kube-system/kubeadm:nodes-kubeadm-config
/registry/rolebindings/kube-system/system::extension-apiserver-authentication-reader
/registry/rolebindings/kube-system/system::leader-locking-kube-controller-manager
/registry/rolebindings/kube-system/system::leader-locking-kube-scheduler
/registry/rolebindings/kube-system/system:controller:bootstrap-signer
/registry/rolebindings/kube-system/system:controller:cloud-provider
/registry/rolebindings/kube-system/system:controller:token-cleaner
/registry/roles/default/leader-locking-nfs-client-provisioner
/registry/roles/kube-public/kubeadm:bootstrap-signer-clusterinfo
/registry/roles/kube-public/system:controller:bootstrap-signer
/registry/roles/kube-system/extension-apiserver-authentication-reader
/registry/roles/kube-system/kube-proxy
/registry/roles/kube-system/kubeadm:kubelet-config-1.18
/registry/roles/kube-system/kubeadm:nodes-kubeadm-config
/registry/roles/kube-system/system::leader-locking-kube-controller-manager
/registry/roles/kube-system/system::leader-locking-kube-scheduler
/registry/roles/kube-system/system:controller:bootstrap-signer
/registry/roles/kube-system/system:controller:cloud-provider
/registry/roles/kube-system/system:controller:token-cleaner
/registry/secrets/default/default-token-wxkdj
/registry/secrets/default/nfs-client-provisioner-token-qtdgc
/registry/secrets/kube-node-lease/default-token-7zmh4
/registry/secrets/kube-public/default-token-2tt47
/registry/secrets/kube-system/attachdetach-controller-token-jt8j7
/registry/secrets/kube-system/bootstrap-signer-token-6n4mt
/registry/secrets/kube-system/bootstrap-token-abcdef
/registry/secrets/kube-system/certificate-controller-token-n46v9
/registry/secrets/kube-system/clusterrole-aggregation-controller-token-ql46p
/registry/secrets/kube-system/coredns-token-jk5d4
/registry/secrets/kube-system/cronjob-controller-token-glvbw
/registry/secrets/kube-system/daemon-set-controller-token-fm7nq
/registry/secrets/kube-system/default-token-c2jsb
/registry/secrets/kube-system/deployment-controller-token-rmphl
/registry/secrets/kube-system/disruption-controller-token-9qnlq
/registry/secrets/kube-system/endpoint-controller-token-vqbjw
/registry/secrets/kube-system/endpointslice-controller-token-jl5jb
/registry/secrets/kube-system/expand-controller-token-mnbcr
/registry/secrets/kube-system/flannel-token-ksmc9
/registry/secrets/kube-system/generic-garbage-collector-token-r4t6z
/registry/secrets/kube-system/horizontal-pod-autoscaler-token-lrbq2
/registry/secrets/kube-system/job-controller-token-c6tnv
/registry/secrets/kube-system/kube-proxy-token-tqsxf
/registry/secrets/kube-system/namespace-controller-token-2gxqg
/registry/secrets/kube-system/node-controller-token-rmv4l
/registry/secrets/kube-system/persistent-volume-binder-token-tmsqx
/registry/secrets/kube-system/pod-garbage-collector-token-xdff7
/registry/secrets/kube-system/pv-protection-controller-token-xln2j
/registry/secrets/kube-system/pvc-protection-controller-token-2bh9w
/registry/secrets/kube-system/replicaset-controller-token-kbvww
/registry/secrets/kube-system/replication-controller-token-8j9w6
/registry/secrets/kube-system/resourcequota-controller-token-mk2j8
/registry/secrets/kube-system/service-account-controller-token-x4pln
/registry/secrets/kube-system/service-controller-token-cwsgw
/registry/secrets/kube-system/statefulset-controller-token-5gkzv
/registry/secrets/kube-system/token-cleaner-token-bwq7j
/registry/secrets/kube-system/ttl-controller-token-jqf5c
/registry/secrets/kubesphere-system/default-token-47z4j
/registry/secrets/kubesphere-system/ks-installer-token-zfh7b
/registry/serviceaccounts/default/default
/registry/serviceaccounts/default/nfs-client-provisioner
/registry/serviceaccounts/kube-node-lease/default
/registry/serviceaccounts/kube-public/default
/registry/serviceaccounts/kube-system/attachdetach-controller
/registry/serviceaccounts/kube-system/bootstrap-signer
/registry/serviceaccounts/kube-system/certificate-controller
/registry/serviceaccounts/kube-system/clusterrole-aggregation-controller
/registry/serviceaccounts/kube-system/coredns
/registry/serviceaccounts/kube-system/cronjob-controller
/registry/serviceaccounts/kube-system/daemon-set-controller
/registry/serviceaccounts/kube-system/default
/registry/serviceaccounts/kube-system/deployment-controller
/registry/serviceaccounts/kube-system/disruption-controller
/registry/serviceaccounts/kube-system/endpoint-controller
/registry/serviceaccounts/kube-system/endpointslice-controller
/registry/serviceaccounts/kube-system/expand-controller
/registry/serviceaccounts/kube-system/flannel
/registry/serviceaccounts/kube-system/generic-garbage-collector
/registry/serviceaccounts/kube-system/horizontal-pod-autoscaler
/registry/serviceaccounts/kube-system/job-controller
/registry/serviceaccounts/kube-system/kube-proxy
/registry/serviceaccounts/kube-system/namespace-controller
/registry/serviceaccounts/kube-system/node-controller
/registry/serviceaccounts/kube-system/persistent-volume-binder
/registry/serviceaccounts/kube-system/pod-garbage-collector
/registry/serviceaccounts/kube-system/pv-protection-controller
/registry/serviceaccounts/kube-system/pvc-protection-controller
/registry/serviceaccounts/kube-system/replicaset-controller
/registry/serviceaccounts/kube-system/replication-controller
/registry/serviceaccounts/kube-system/resourcequota-controller
/registry/serviceaccounts/kube-system/service-account-controller
/registry/serviceaccounts/kube-system/service-controller
/registry/serviceaccounts/kube-system/statefulset-controller
/registry/serviceaccounts/kube-system/token-cleaner
/registry/serviceaccounts/kube-system/ttl-controller
/registry/serviceaccounts/kubesphere-system/default
/registry/serviceaccounts/kubesphere-system/ks-installer
/registry/services/endpoints/default/kubernetes
/registry/services/endpoints/kube-system/kube-controller-manager
/registry/services/endpoints/kube-system/kube-dns
/registry/services/endpoints/kube-system/kube-scheduler
/registry/services/specs/default/kubernetes
/registry/services/specs/kube-system/kube-dns
/registry/storageclasses/managed-nfs-storage
标签:k8s,查看,system,controller,registry,etcd,kube,clusterroles,token
From: https://blog.51cto.com/u_14620403/8868251