Files

33 lines
35 KiB
HTML
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!doctype html>
<html lang="zh" dir="ltr" class="docs-wrapper docs-doc-page docs-version-2.6 plugin-docs plugin-id-default docs-doc-id-reference-guides/about-the-api/api-tokens" data-has-hydrated="false">
<head>
<meta charset="UTF-8">
<meta name="generator" content="Docusaurus v2.4.3">
<title data-rh="true">API 令牌 | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://ranchermanager.docs.rancher.com/zh/v2.6/reference-guides/about-the-api/api-tokens"><meta data-rh="true" name="docusaurus_locale" content="zh"><meta data-rh="true" name="docsearch:language" content="zh"><meta data-rh="true" name="docusaurus_version" content="2.6"><meta data-rh="true" name="docusaurus_tag" content="docs-default-2.6"><meta data-rh="true" name="docsearch:version" content="2.6"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-2.6"><meta data-rh="true" property="og:title" content="API 令牌 | Rancher"><meta data-rh="true" name="description" content="默认情况下,某些集群级别的 API 令牌是使用无限期 TTL(ttl=0)生成的。换言之,除非你让令牌失效,否则 ttl=0 的 API 令牌永远不会过期。令牌不会因为更改密码而失效。"><meta data-rh="true" property="og:description" content="默认情况下,某些集群级别的 API 令牌是使用无限期 TTL(ttl=0)生成的。换言之,除非你让令牌失效,否则 ttl=0 的 API 令牌永远不会过期。令牌不会因为更改密码而失效。"><link data-rh="true" rel="icon" href="/zh/img/favicon.png"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/v2.6/reference-guides/about-the-api/api-tokens" hreflang="en"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/zh/v2.6/reference-guides/about-the-api/api-tokens" hreflang="zh"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/v2.6/reference-guides/about-the-api/api-tokens" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link data-rh="true" rel="canonical" href="https://ranchermanager.docs.rancher.com/zh/reference-guides/about-the-api/api-tokens"><link rel="preconnect" href="https://www.googletagmanager.com">
<script>window.dataLayer=window.dataLayer||[]</script>
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/zh/opensearch.xml">
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/zh/assets/css/styles.29ec6351.css">
<link rel="preload" href="/zh/assets/js/runtime~main.7955d3d3.js" as="script">
<link rel="preload" href="/zh/assets/js/main.129d8862.js" as="script">
</head>
<body class="navigation-with-keyboard">
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}return t}()||function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
<div role="region" aria-label="跳到主要内容"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">跳到主要内容</a></div><nav aria-label="主导航" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="切换导航栏" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/zh/"><div class="navbar__logo"><img src="/zh/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/zh/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/zh/v2.6">v2.6</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/zh/">Latest</a></li><li><a class="dropdown__link" href="/zh/v2.9">v2.9 (Preview)</a></li><li><a class="dropdown__link" href="/zh/v2.8">v2.8</a></li><li><a class="dropdown__link" href="/zh/v2.7/reference-guides/about-the-api/api-tokens">v2.7</a></li><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/zh/v2.6/reference-guides/about-the-api/api-tokens">v2.6</a></li><li><a class="dropdown__link" href="/zh/v2.5/reference-guides/about-the-api/api-tokens">v2.5</a></li><li><a class="dropdown__link" href="/zh/v2.0-v2.4/reference-guides/about-the-api/api-tokens">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/zh/versions">All versions</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>简体中文</a><ul class="dropdown__menu"><li><a href="/v2.6/reference-guides/about-the-api/api-tokens" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="en">English</a></li><li><a href="/zh/v2.6/reference-guides/about-the-api/api-tokens" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="zh">简体中文</a></li></ul></div><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="搜索"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">搜索</span></span><span class="DocSearch-Button-Keys"></span></button></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Quick Links</a><ul class="dropdown__menu"><li><a href="https://github.com/rancher/rancher" target="_blank" rel="noopener noreferrer" class="dropdown__link">GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="dropdown__link">Docs GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">More from SUSE</a><ul class="dropdown__menu"><li><a href="https://www.rancher.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher">Rancher<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://elemental.docs.rancher.com/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__elemental">Elemental<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://fleet.rancher.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__fleet">Fleet<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://harvesterhci.io" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__harvester">Harvester<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://rancherdesktop.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher__desktop">Rancher Desktop<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://opensource.suse.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__suse">More Projects...<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="回到顶部" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="文档侧边栏" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/zh/v2.6">什么是 Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/v2.6/getting-started/overview">开始使用</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/v2.6/how-to-guides/new-user-guides">操作指南</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/zh/v2.6/reference-guides/best-practices">参考指南</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/best-practices">最佳实践</a><button aria-label="打开/收起侧边栏菜单「最佳实践」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/rancher-manager-architecture">Rancher 架构</a><button aria-label="打开/收起侧边栏菜单「Rancher 架构」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/cluster-configuration">集群配置</a><button aria-label="打开/收起侧边栏菜单「集群配置」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/single-node-rancher-in-docker">Docker 中的单节点 Rancher</a><button aria-label="打开/收起侧边栏菜单「Docker 中的单节点 Rancher」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/backup-restore-configuration">备份和恢复配置</a><button aria-label="打开/收起侧边栏菜单「备份和恢复配置」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/v2.6/reference-guides/kubernetes-concepts">Kubernetes 概念</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/monitoring-v2-configuration">Monitoring 配置</a><button aria-label="打开/收起侧边栏菜单「Monitoring 配置」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/prometheus-federator">Prometheus Federator</a><button aria-label="打开/收起侧边栏菜单「Prometheus Federator」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/user-settings">用户设置</a><button aria-label="打开/收起侧边栏菜单「用户设置」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/cli-with-rancher">Rancher CLI</a><button aria-label="打开/收起侧边栏菜单「Rancher CLI」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--active" aria-expanded="true" tabindex="0" href="/zh/v2.6/reference-guides/about-the-api">关于 API</a><button aria-label="打开/收起侧边栏菜单「关于 API」" type="button" class="clean-btn menu__caret"></button></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/zh/v2.6/reference-guides/about-the-api/api-tokens">API 令牌</a></li></ul></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/v2.6/reference-guides/rancher-cluster-tools">集群工具:Logging,Monitoring 和可视化</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/v2.6/reference-guides/rancher-project-tools">项目工具:Logging,Monitoring 和可视化</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/v2.6/reference-guides/system-tools">系统工具</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/v2.6/reference-guides/rke1-template-example-yaml">RKE1 示例 YAML</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/pipelines">流水线</a><button aria-label="打开/收起侧边栏菜单「流水线」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/v2.6/reference-guides/rancher-security">Rancher 安全指南</a><button aria-label="打开/收起侧边栏菜单「Rancher 安全指南」" type="button" class="clean-btn menu__caret"></button></div></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/v2.6/integrations-in-rancher/cloud-marketplace">Rancher 中的集成</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/v2.6/faq/general-faq">常见问题</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/v2.6/troubleshooting/general-troubleshooting">故障排除</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/zh/v2.6/contribute-to-rancher">参与 Rancher 社区贡献</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="页面路径"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="主页面" class="breadcrumbs__link" href="/zh/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">参考指南</span><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item"><a class="breadcrumbs__link" itemprop="item" href="/zh/v2.6/reference-guides/about-the-api"><span itemprop="name">关于 API</span></a><meta itemprop="position" content="2"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">API 令牌</span><meta itemprop="position" content="3"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">版本:v2.6</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">本页总览</button></div><div class="theme-doc-markdown markdown"><header><h1>API 令牌</h1></header><p>默认情况下,某些集群级别的 API 令牌是使用无限期 TTL(<code>ttl=0</code>)生成的。换言之,除非你让令牌失效,否则 <code>ttl=0</code> 的 API 令牌永远不会过期。令牌不会因为更改密码而失效。</p><p>要停用 API 令牌,你可以删除令牌或停用用户账号。</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="删除令牌">删除令牌<a href="#删除令牌" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h3><p>要删除令牌:</p><ol><li><p>转到 <code>https://&lt;Rancher-Server-IP&gt;/v3/tokens</code>,在 Rancher API 视图中查看包含所有令牌的列表。</p></li><li><p>通过 ID 访问要删除的令牌。例如,<code>https://&lt;Rancher-Server-IP&gt;/v3/tokens/kubectl-shell-user-vqkqt</code>。</p></li><li><p>单击<strong>删除</strong>。</p></li></ol><p>以下是使用 <code>ttl=0</code> 生成的完整令牌列表:</p><table><thead><tr><th>令牌</th><th>描述</th></tr></thead><tbody><tr><td><code>kubeconfig-*</code></td><td>Kubeconfig 令牌</td></tr><tr><td><code>kubectl-shell-*</code></td><td>在浏览器中访问 <code>kubectl</code> shell</td></tr><tr><td><code>agent-*</code></td><td>Agent deployment 令牌</td></tr><tr><td><code>compose-token-*</code></td><td>compose 令牌</td></tr><tr><td><code>helm-token-*</code></td><td>Helm Chart deployment 令牌</td></tr><tr><td><code>*-pipeline*</code></td><td>项目流水线令牌</td></tr><tr><td><code>telemetry-*</code></td><td>遥测令牌</td></tr><tr><td><code>drain-node-*</code></td><td>用于清空的令牌(由于没有原生 Kubernetes API,我们使用 <code>kubectl</code> 来清空)</td></tr></tbody></table><h3 class="anchor anchorWithStickyNavbar_LWe7" id="在-kubeconfig-令牌上设置-ttl">在 Kubeconfig 令牌上设置 TTL<a href="#在-kubeconfig-令牌上设置-ttl" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h3><p>管理员可以在 Kubeconfig 令牌上设置全局存活时间 (time-to-live,TTL)。如需更改默认 kubeconfig TTL,你可以导航到全局设置并将 <a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-ttl-minutes</code></a> 设置为所需的持续时间(单位:分钟)。<a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-ttl-minutes</code></a> 的默认值为 0,表示令牌永不过期。</p><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>备注</div><div class="admonitionContent_S0QG"><p>除了由 CLI 创建的用于<a href="#%E5%9C%A8%E7%94%9F%E6%88%90%E7%9A%84-kubeconfig-%E4%B8%AD%E7%A6%81%E7%94%A8%E4%BB%A4%E7%89%8C">生成 kubeconfig 令牌</a>的令牌之外,所有 kubeconfig 令牌都使用此设置。</p></div></div><h3 class="anchor anchorWithStickyNavbar_LWe7" id="在生成的-kubeconfig-中禁用令牌">在生成的 Kubeconfig 中禁用令牌<a href="#在生成的-kubeconfig-中禁用令牌" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h3><ol><li><p>将 <code>kubeconfig-generate-token</code> 设置为 <code>false</code>。此设置让 Rancher 不再在用户单击下载 kubeconfig 文件时自动生成令牌。如果停用此设置,生成的 kubeconfig 将引用 <a href="/zh/v2.6/reference-guides/cli-with-rancher/kubectl-utility#%E4%BD%BF%E7%94%A8-kubectl-%E5%92%8C-kubeconfig-%E4%BB%A4%E7%89%8C%E8%BF%9B%E8%A1%8C-ttl-%E8%AE%A4%E8%AF%81">Rancher CLI</a> 来检索集群的短期令牌。当这个 kubeconfig 在客户端(例如 <code>kubectl</code>)中使用时,你需要安装 Rancher CLI 来完成登录请求。</p></li><li><p>将 <code>kubeconfig-token-ttl-minutes</code> 设置为所需的时长(单位:分钟)。<code>kubeconfig-token-ttl-minutes</code> 默认设置为 960(即 16 小时)。</p></li></ol><h3 class="anchor anchorWithStickyNavbar_LWe7" id="令牌哈希">令牌哈希<a href="#令牌哈希" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h3><p>你可以启用令牌哈希,令牌将使用 SHA256 算法进行单向哈希。这是一个不可逆的操作,一旦启用,此功能将无法禁用。在启用功能或在测试环境中评估之前,建议你先进行备份。</p><p>要启用令牌哈希,请参阅<a href="/zh/v2.6/pages-for-subheaders/enable-experimental-features.md">本节</a>。</p><p>此功能将影响所有令牌,包括但不限于以下内容:</p><ul><li>Kubeconfig 令牌</li><li>持有者令牌 API 密钥/调用</li><li>内部操作使用的令牌</li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="令牌设置">令牌设置<a href="#令牌设置" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h3><p>以下全局设置会影响 Rancher 令牌的行为:</p><table><thead><tr><th>设置</th><th>描述</th></tr></thead><tbody><tr><td><a href="#auth-user-session-ttl-minutes"><code>auth-user-session-ttl-minutes</code></a></td><td>用户认证会话令牌的 TTL(单位:分钟)。</td></tr><tr><td><a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-TTL-minutes</code></a></td><td>默认 TTL,应用于所有 kubeconfig 令牌(除了<a href="#%E5%9C%A8%E7%94%9F%E6%88%90%E7%9A%84-kubeconfig-%E4%B8%AD%E7%A6%81%E7%94%A8%E4%BB%A4%E7%89%8C">由 Rancher CLI 生成的令牌</a>)。<strong>此设置从 2.6.6 版本开始引入。</strong></td></tr><tr><td><a href="#kubeconfig-token-ttl-minutes"><code>kubeconfig-token-ttl-minutes</code></a></td><td>在 CLI 中生成的令牌 TTL。<strong>自 2.6.6 起已弃用,并将在 2.8.0 中删除</strong>。请知悉,<code>kubeconfig-default-token-TTL-minutes</code> 将用于所有 kubeconfig 令牌。</td></tr><tr><td><a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a></td><td>除了由 <a href="#auth-user-session-ttl-minutes"><code>auth-user-session-ttl-minutes</code></a> 控制的令牌外,所有令牌的最大 TTL。</td></tr><tr><td><a href="#kubeconfig-generate-token"><code>kubeconfig-generate-token</code></a></td><td>如果为 true,则在用户下载 kubeconfig 时自动生成令牌。</td></tr></tbody></table><h4 class="anchor anchorWithStickyNavbar_LWe7" id="auth-user-session-ttl-minutes">auth-user-session-ttl-minutes<a href="#auth-user-session-ttl-minutes" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h4><p>存活时间(TTL)(单位:分钟),用于确定用户身份验证会话令牌的到期时间。过期后,用户将需要登录并获取新令牌。此设置不受 <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a> 的影响。会话令牌是在用户登录 Rancher 时创建的。</p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-default-token-ttl-minutes">kubeconfig-default-token-TTL-minutes<a href="#kubeconfig-default-token-ttl-minutes" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h4><p>存活时间(TTL)(单位:分钟),用于确定 kubeconfig 令牌的到期时间。令牌过期后,API 将拒绝令牌。此设置的值不能大于 <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a> 的值。此设置适用于在请求的 kubeconfig 文件中生成的令牌,不包括<a href="#%E5%9C%A8%E7%94%9F%E6%88%90%E7%9A%84-kubeconfig-%E4%B8%AD%E7%A6%81%E7%94%A8%E4%BB%A4%E7%89%8C">由 Rancher CLI 生成的</a>令牌。
<strong>此设置从 2.6.6 版本开始引入</strong>。</p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-token-ttl-minutes">kubeconfig-token-ttl-minutes<a href="#kubeconfig-token-ttl-minutes" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h4><p>存活时间(TTL)(单位:分钟),用于确定由 CLI 生成的 kubeconfig 令牌的到期时间。当 <a href="#kubeconfig-generate-token"><code>kubeconfig-generate-token</code></a> 设为 false 时,则由 CLI 生成令牌。令牌过期后,API 将拒绝令牌。此设置的值不能大于 <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a> 的值。
<strong>自版本 2.6.6 起已弃用,并将在 2.8.0 中删除。请知悉,此设置将被 <a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-TTL-minutes</code></a> 的值替换</strong>。</p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="auth-token-max-ttl-minutes">auth-token-max-ttl-minutes<a href="#auth-token-max-ttl-minutes" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h4><p>身份验证令牌的最大生存时间 (TTL)(单位:分钟)。如果用户尝试创建一个 TTL 大于 <code>auth-token-max-ttl-minutes</code> 的令牌,Rancher 会将令牌 TTL 设置为 <code>auth-token-max-ttl-minutes</code> 的值。身份验证令牌是为验证 API 请求而创建的。
<strong>2.6.6 版本更改:适用于所有 kubeconfig 令牌和 API 令牌。</strong></p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-generate-token">kubeconfig-generate-token<a href="#kubeconfig-generate-token" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接">​</a></h4><p>如果设置为 true,则通过 UI 请求的 kubeconfig 将包含一个有效的令牌。如果设置为 false,kubeconfig 将包含一个使用 Rancher CLI 提示用户登录的命令。然后,<a href="/zh/v2.6/reference-guides/cli-with-rancher/kubectl-utility#%E4%BD%BF%E7%94%A8-kubectl-%E5%92%8C-kubeconfig-%E4%BB%A4%E7%89%8C%E8%BF%9B%E8%A1%8C-ttl-%E8%AE%A4%E8%AF%81">CLI 将为用户检索和缓存令牌</a>。</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.6/reference-guides/about-the-api/api-tokens.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>编辑此页</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">最后<!-- -->于 <b><time datetime="2024-05-06T07:06:07.000Z">2024年5月6日</time></b> <!-- -->更新</span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="文档分页导航"><a class="pagination-nav__link pagination-nav__link--prev" href="/zh/v2.6/reference-guides/about-the-api"><div class="pagination-nav__sublabel">上一页</div><div class="pagination-nav__label">API</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/zh/v2.6/reference-guides/rancher-cluster-tools"><div class="pagination-nav__sublabel">下一页</div><div class="pagination-nav__label">集群工具:Logging,Monitoring 和可视化</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#删除令牌" class="table-of-contents__link toc-highlight">删除令牌</a></li><li><a href="#在-kubeconfig-令牌上设置-ttl" class="table-of-contents__link toc-highlight">在 Kubeconfig 令牌上设置 TTL</a></li><li><a href="#在生成的-kubeconfig-中禁用令牌" class="table-of-contents__link toc-highlight">在生成的 Kubeconfig 中禁用令牌</a></li><li><a href="#令牌哈希" class="table-of-contents__link toc-highlight">令牌哈希</a></li><li><a href="#令牌设置" class="table-of-contents__link toc-highlight">令牌设置</a></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2024 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
<script src="/zh/assets/js/runtime~main.7955d3d3.js"></script>
<script src="/zh/assets/js/main.129d8862.js"></script>
</body>
</html>