{"id":5396,"date":"2021-07-14T16:26:21","date_gmt":"2021-07-14T08:26:21","guid":{"rendered":"https:\/\/damogame.cn\/wordpress\/?p=5396"},"modified":"2021-07-14T16:26:56","modified_gmt":"2021-07-14T08:26:56","slug":"etcd-etcd%e8%ae%bf%e9%97%ae%e6%8e%a7%e5%88%b6","status":"publish","type":"post","link":"https:\/\/i007.cc\/wordpress\/archives\/5396","title":{"rendered":"Etcd\u8bbf\u95ee\u63a7\u5236"},"content":{"rendered":"<header class=\"intro-header\">\n<div id=\"signature\">\n<div class=\"container\">\n<div class=\"row\">\n<div class=\"col-lg-8 col-lg-offset-2 col-md-10 col-md-offset-1\">\n<div class=\"post-heading\">\n<p id=\"etcd-etcd\"><a href=\"https:\/\/www.huweihuang.com\/article\/etcd\/etcd-auth&amp;security\/#1-etcd%E8%B5%84%E6%BA%90%E7%B1%BB%E5%9E%8B\">\u539f\u6587\u5730\u5740<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/header>\n<nav class=\"navbar navbar-default navbar-custom navbar-fixed-top is-fixed\">\n<div class=\"container-fluid\">\n<div id=\"huxblog_navbar\">\n<div class=\"navbar-collapse\">\n<p>&nbsp;<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/nav>\n<article>\n<div class=\"container\">\n<div class=\"row\">\n<div class=\" col-lg-8 col-lg-offset-2 col-md-10 col-md-offset-1 post-container\">\n<h2 id=\"1-etcd\u8d44\u6e90\u7c7b\u578b\">1. ETCD\u8d44\u6e90\u7c7b\u578b<\/h2>\n<p>There are three types of resources in etcd<\/p>\n<p>permission resources: users and roles in the user store<br \/>\nkey-value resources: key-value pairs in the key-value store<br \/>\nsettings resources: security settings, auth settings, and dynamic etcd cluster settings (election\/heartbeat)<\/p>\n<h2 id=\"2-\u6743\u9650\u8d44\u6e90\">2. \u6743\u9650\u8d44\u6e90<\/h2>\n<p><strong>Users<\/strong>\uff1auser\u7528\u6765\u8bbe\u7f6e\u8eab\u4efd\u8ba4\u8bc1\uff08user\uff1apasswd\uff09\uff0c\u4e00\u4e2a\u7528\u6237\u53ef\u4ee5\u62e5\u6709\u591a\u4e2a\u89d2\u8272\uff0c\u6bcf\u4e2a\u89d2\u8272\u88ab\u5206\u914d\u4e00\u5b9a\u7684\u6743\u9650\uff08\u53ea\u8bfb\u3001\u53ea\u5199\u3001\u53ef\u8bfb\u5199\uff09\uff0c\u7528\u6237\u5206\u4e3aroot\u7528\u6237\u548c\u975eroot\u7528\u6237\u3002<\/p>\n<p><strong>Roles<\/strong>\uff1a\u89d2\u8272\u7528\u6765\u5173\u8054\u6743\u9650\uff0c\u89d2\u8272\u4e3b\u8981\u4e09\u7c7b\uff1aroot\u89d2\u8272\u3002\u9ed8\u8ba4\u521b\u5efaroot\u7528\u6237\u65f6\u5373\u521b\u5efa\u4e86root\u89d2\u8272\uff0c\u8be5\u89d2\u8272\u62e5\u6709\u6240\u6709\u6743\u9650\uff1bguest\u89d2\u8272\uff0c\u9ed8\u8ba4\u81ea\u52a8\u521b\u5efa\uff0c\u4e3b\u8981\u7528\u4e8e\u975e\u8ba4\u8bc1\u4f7f\u7528\u3002\u666e\u901a\u89d2\u8272\uff0c\u7531root\u7528\u6237\u521b\u5efa\u89d2\u8272\uff0c\u5e76\u5206\u914d\u6307\u5b9a\u6743\u9650\u3002<\/p>\n<p>\u6ce8\u610f\uff1a\u5982\u679c\u6ca1\u6709\u6307\u5b9a\u4efb\u4f55\u9a8c\u8bc1\u65b9\u5f0f\uff0c\u5373\u6ca1\u663e\u793a\u6307\u5b9a\u4ee5\u4ec0\u4e48\u7528\u6237\u8fdb\u884c\u8bbf\u95ee\uff0c\u90a3\u4e48\u9ed8\u8ba4\u4f1a\u8bbe\u5b9a\u4e3a guest \u89d2\u8272\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b guest \u4e5f\u662f\u5177\u6709\u5168\u5c40\u8bbf\u95ee\u6743\u9650\u7684\u3002\u5982\u679c\u4e0d\u5e0c\u671b\u672a\u6388\u6743\u5c31\u83b7\u53d6\u6216\u4fee\u6539etcd\u7684\u6570\u636e\uff0c\u5219\u53ef\u6536\u56deguest\u89d2\u8272\u7684\u6743\u9650\u6216\u5220\u9664\u8be5\u89d2\u8272\uff0cetcdctl role revoke \u3002<\/p>\n<p><strong>Permissions<\/strong>:\u6743\u9650\u5206\u4e3a\u53ea\u8bfb\u3001\u53ea\u5199\u3001\u53ef\u8bfb\u5199\u4e09\u79cd\u6743\u9650\uff0c\u6743\u9650\u5373\u5bf9\u6307\u5b9a\u76ee\u5f55\u6216key\u7684\u8bfb\u5199\u6743\u9650\u3002<\/p>\n<h2 id=\"3-etcd\u8bbf\u95ee\u63a7\u5236\">3. ETCD\u8bbf\u95ee\u63a7\u5236<\/h2>\n<h3 id=\"31-\u8bbf\u95ee\u63a7\u5236\u76f8\u5173\u547d\u4ee4\">3.1. \u8bbf\u95ee\u63a7\u5236\u76f8\u5173\u547d\u4ee4<\/h3>\n<figure class=\"highlight shell\">\n<div class=\"table-responsive\">\n<table class=\"table\">\n<tbody>\n<tr>\n<td class=\"gutter\">\n<pre><span class=\"line\">1<\/span>\r\n<span class=\"line\">2<\/span>\r\n<span class=\"line\">3<\/span>\r\n<span class=\"line\">4<\/span>\r\n<span class=\"line\">5<\/span>\r\n<span class=\"line\">6<\/span>\r\n<span class=\"line\">7<\/span>\r\n<span class=\"line\">8<\/span>\r\n<span class=\"line\">9<\/span>\r\n<span class=\"line\">10<\/span>\r\n<span class=\"line\">11<\/span>\r\n<span class=\"line\">12<\/span>\r\n<span class=\"line\">13<\/span>\r\n<span class=\"line\">14<\/span>\r\n<span class=\"line\">15<\/span>\r\n<span class=\"line\">16<\/span>\r\n<span class=\"line\">17<\/span>\r\n<span class=\"line\">18<\/span><\/pre>\n<\/td>\n<td class=\"code\">\n<pre><span class=\"line\">NAME:<\/span>\r\n<span class=\"line\">   etcdctl - A simple command line client for etcd.<\/span>\r\n<span class=\"line\">USAGE:<\/span>\r\n<span class=\"line\">   etcdctl [global options] command [command options] [arguments...]<\/span>\r\n<span class=\"line\">VERSION:<\/span>\r\n<span class=\"line\">   2.2.0<\/span>\r\n<span class=\"line\">COMMANDS:<\/span>\r\n<span class=\"line\">   user         user add, grant and revoke subcommands<\/span>\r\n<span class=\"line\">   role         role add, grant and revoke subcommands<\/span>\r\n<span class=\"line\">   auth         overall auth controls  <\/span>\r\n<span class=\"line\">GLOBAL OPTIONS:<\/span>\r\n<span class=\"line\">   --peers, -C          a comma-delimited list of machine addresses in the cluster (default: \"http:\/\/127.0.0.1:4001,http:\/\/127.0.0.1:2379\")<\/span>\r\n<span class=\"line\">   --endpoint           a comma-delimited list of machine addresses in the cluster (default: \"http:\/\/127.0.0.1:4001,http:\/\/127.0.0.1:2379\")<\/span>\r\n<span class=\"line\">   --cert-file          identify HTTPS client using this SSL certificate file<\/span>\r\n<span class=\"line\">   --key-file           identify HTTPS client using this SSL key file<\/span>\r\n<span class=\"line\">   --ca-file            verify certificates of HTTPS-enabled servers using this CA bundle<\/span>\r\n<span class=\"line\">   --username, -u       provide username[:password] and prompt if password is not supplied.<\/span>\r\n<span class=\"line\">   --timeout '1s'       connection timeout per request<\/span><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/figure>\n<h3 id=\"32-user\u76f8\u5173\u547d\u4ee4\">3.2. user\u76f8\u5173\u547d\u4ee4<\/h3>\n<figure class=\"highlight shell\">\n<div class=\"table-responsive\">\n<table class=\"table\">\n<tbody>\n<tr>\n<td class=\"gutter\">\n<pre><span class=\"line\">1<\/span>\r\n<span class=\"line\">2<\/span>\r\n<span class=\"line\">3<\/span>\r\n<span class=\"line\">4<\/span>\r\n<span class=\"line\">5<\/span>\r\n<span class=\"line\">6<\/span>\r\n<span class=\"line\">7<\/span>\r\n<span class=\"line\">8<\/span>\r\n<span class=\"line\">9<\/span>\r\n<span class=\"line\">10<\/span>\r\n<span class=\"line\">11<\/span>\r\n<span class=\"line\">12<\/span>\r\n<span class=\"line\">13<\/span>\r\n<span class=\"line\">14<\/span>\r\n<span class=\"line\">15<\/span>\r\n<span class=\"line\">16<\/span>\r\n<span class=\"line\">17<\/span><\/pre>\n<\/td>\n<td class=\"code\">\n<pre><span class=\"line\">[root@localhost etcd]# etcdctl user --help<\/span>\r\n<span class=\"line\">NAME:<\/span>\r\n<span class=\"line\">   etcdctl user - user add, grant and revoke subcommands<\/span>\r\n<span class=\"line\">USAGE:<\/span>\r\n<span class=\"line\">   etcdctl user command [command options] [arguments...]<\/span>\r\n<span class=\"line\">COMMANDS:<\/span>\r\n<span class=\"line\">   add      add a new user for the etcd cluster<\/span>\r\n<span class=\"line\">   get      get details for a user<\/span>\r\n<span class=\"line\">   list     list all current users<\/span>\r\n<span class=\"line\">   remove   remove a user for the etcd cluster<\/span>\r\n<span class=\"line\">   grant    grant roles to an etcd user<\/span>\r\n<span class=\"line\">   revoke   revoke roles for an etcd user<\/span>\r\n<span class=\"line\">   passwd   change password for a user<\/span>\r\n<span class=\"line\">   help, h  Shows a list of commands or help for one command<\/span>\r\n    \r\n<span class=\"line\">OPTIONS:<\/span>\r\n<span class=\"line\">   --help, -h   show help<\/span><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/figure>\n<h4 id=\"321-\u6dfb\u52a0root\u7528\u6237\u5e76\u8bbe\u7f6e\u5bc6\u7801\">3.2.1. \u6dfb\u52a0root\u7528\u6237\u5e76\u8bbe\u7f6e\u5bc6\u7801<\/h4>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0user add root<\/p>\n<h4 id=\"322-\u6dfb\u52a0\u975eroot\u7528\u6237\u5e76\u8bbe\u7f6e\u5bc6\u7801\">3.2.2. \u6dfb\u52a0\u975eroot\u7528\u6237\u5e76\u8bbe\u7f6e\u5bc6\u7801<\/h4>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:123 user add huwh<\/p>\n<h4 id=\"323-\u67e5\u770b\u5f53\u524d\u6240\u6709\u7528\u6237\">3.2.3. \u67e5\u770b\u5f53\u524d\u6240\u6709\u7528\u6237<\/h4>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:123 user list<\/p>\n<h4 id=\"324-\u5c06\u7528\u6237\u6dfb\u52a0\u5230\u5bf9\u5e94\u89d2\u8272\">3.2.4. \u5c06\u7528\u6237\u6dfb\u52a0\u5230\u5bf9\u5e94\u89d2\u8272<\/h4>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:123 user grant &#8211;roles test1 phpor<\/p>\n<h4 id=\"325-\u67e5\u770b\u7528\u6237\u62e5\u6709\u54ea\u4e9b\u89d2\u8272\">3.2.5. \u67e5\u770b\u7528\u6237\u62e5\u6709\u54ea\u4e9b\u89d2\u8272<\/h4>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:123 user get phpor<\/p>\n<h3 id=\"33-role\u76f8\u5173\u547d\u4ee4\">3.3. role\u76f8\u5173\u547d\u4ee4<\/h3>\n<figure class=\"highlight shell\">\n<div class=\"table-responsive\">\n<table class=\"table\">\n<tbody>\n<tr>\n<td class=\"gutter\">\n<pre><span class=\"line\">1<\/span>\r\n<span class=\"line\">2<\/span>\r\n<span class=\"line\">3<\/span>\r\n<span class=\"line\">4<\/span>\r\n<span class=\"line\">5<\/span>\r\n<span class=\"line\">6<\/span>\r\n<span class=\"line\">7<\/span>\r\n<span class=\"line\">8<\/span>\r\n<span class=\"line\">9<\/span>\r\n<span class=\"line\">10<\/span>\r\n<span class=\"line\">11<\/span>\r\n<span class=\"line\">12<\/span>\r\n<span class=\"line\">13<\/span>\r\n<span class=\"line\">14<\/span>\r\n<span class=\"line\">15<\/span>\r\n<span class=\"line\">16<\/span><\/pre>\n<\/td>\n<td class=\"code\">\n<pre><span class=\"line\">[root@localhost etcd]# etcdctl role --help<\/span>\r\n<span class=\"line\">NAME:<\/span>\r\n<span class=\"line\">   etcdctl role - role add, grant and revoke subcommands<\/span>\r\n<span class=\"line\">USAGE:<\/span>\r\n<span class=\"line\">   etcdctl role command [command options] [arguments...]<\/span>\r\n<span class=\"line\">COMMANDS:<\/span>\r\n<span class=\"line\">   add      add a new role for the etcd cluster<\/span>\r\n<span class=\"line\">   get      get details for a role<\/span>\r\n<span class=\"line\">   list     list all roles<\/span>\r\n<span class=\"line\">   remove   remove a role from the etcd cluster<\/span>\r\n<span class=\"line\">   grant    grant path matches to an etcd role<\/span>\r\n<span class=\"line\">   revoke   revoke path matches for an etcd role<\/span>\r\n<span class=\"line\">   help, h  Shows a list of commands or help for one command<\/span>\r\n    \r\n<span class=\"line\">OPTIONS:<\/span>\r\n<span class=\"line\">   --help, -h   show help<\/span><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/figure>\n<h4 id=\"331-\u6dfb\u52a0\u89d2\u8272\">3.3.1. \u6dfb\u52a0\u89d2\u8272<\/h4>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:2379 role add test1<\/p>\n<h4 id=\"332-\u67e5\u770b\u6240\u6709\u89d2\u8272\">3.3.2. \u67e5\u770b\u6240\u6709\u89d2\u8272<\/h4>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:123 role list<\/p>\n<h4 id=\"333-\u7ed9\u89d2\u8272\u5206\u914d\u6743\u9650\">3.3.3. \u7ed9\u89d2\u8272\u5206\u914d\u6743\u9650<\/h4>\n<figure class=\"highlight shell\">\n<div class=\"table-responsive\">\n<table class=\"table\">\n<tbody>\n<tr>\n<td class=\"gutter\">\n<pre><span class=\"line\">1<\/span>\r\n<span class=\"line\">2<\/span>\r\n<span class=\"line\">3<\/span>\r\n<span class=\"line\">4<\/span>\r\n<span class=\"line\">5<\/span>\r\n<span class=\"line\">6<\/span>\r\n<span class=\"line\">7<\/span>\r\n<span class=\"line\">8<\/span>\r\n<span class=\"line\">9<\/span>\r\n<span class=\"line\">10<\/span><\/pre>\n<\/td>\n<td class=\"code\">\n<pre><span class=\"line\">[root@localhost etcd]# etcdctl role grant --help<\/span>\r\n<span class=\"line\">NAME:<\/span>\r\n<span class=\"line\">   grant - grant path matches to an etcd role<\/span>\r\n<span class=\"line\">USAGE:<\/span>\r\n<span class=\"line\">   command grant [command options] [arguments...]<\/span>\r\n<span class=\"line\">OPTIONS:<\/span>\r\n<span class=\"line\">   --path   Path granted for the role to access<\/span>\r\n<span class=\"line\">   --read   Grant read-only access<\/span>\r\n<span class=\"line\">   --write  Grant write-only access<\/span>\r\n<span class=\"line\">   --readwrite  Grant read-write access<\/span><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/figure>\n<p>1\u3001\u53ea\u5305\u542b\u76ee\u5f55<br \/>\netcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:123 role grant &#8211;readwrite &#8211;path \/test1 test1<\/p>\n<p>2\u3001\u5305\u62ec\u76ee\u5f55\u548c\u5b50\u76ee\u5f55\u6216\u6587\u4ef6<br \/>\netcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:123 role grant &#8211;readwrite &#8211;path \/test1\/* test1<\/p>\n<h3 id=\"334-\u67e5\u770b\u89d2\u8272\u6240\u62e5\u6709\u7684\u6743\u9650\">3.3.4. \u67e5\u770b\u89d2\u8272\u6240\u62e5\u6709\u7684\u6743\u9650<\/h3>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0&#8211;username root:2379 role get test1<\/p>\n<h3 id=\"34-auth\u76f8\u5173\u64cd\u4f5c\">3.4. auth\u76f8\u5173\u64cd\u4f5c<\/h3>\n<figure class=\"highlight shell\">\n<div class=\"table-responsive\">\n<table class=\"table\">\n<tbody>\n<tr>\n<td class=\"gutter\">\n<pre><span class=\"line\">1<\/span>\r\n<span class=\"line\">2<\/span>\r\n<span class=\"line\">3<\/span>\r\n<span class=\"line\">4<\/span>\r\n<span class=\"line\">5<\/span>\r\n<span class=\"line\">6<\/span>\r\n<span class=\"line\">7<\/span>\r\n<span class=\"line\">8<\/span>\r\n<span class=\"line\">9<\/span>\r\n<span class=\"line\">10<\/span>\r\n<span class=\"line\">11<\/span>\r\n<span class=\"line\">12<\/span><\/pre>\n<\/td>\n<td class=\"code\">\n<pre><span class=\"line\">[root@localhost etcd]# etcdctl auth --help<\/span>\r\n<span class=\"line\">NAME:<\/span>\r\n<span class=\"line\">   etcdctl auth - overall auth controls<\/span>\r\n<span class=\"line\">USAGE:<\/span>\r\n<span class=\"line\">   etcdctl auth command [command options] [arguments...]<\/span>\r\n<span class=\"line\">COMMANDS:<\/span>\r\n<span class=\"line\">   enable   enable auth access controls<\/span>\r\n<span class=\"line\">   disable  disable auth access controls<\/span>\r\n<span class=\"line\">   help, h  Shows a list of commands or help for one command<\/span>\r\n    \r\n<span class=\"line\">OPTIONS:<\/span>\r\n<span class=\"line\">   --help, -h   show help<\/span><\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/figure>\n<h4 id=\"341-\u5f00\u542f\u8ba4\u8bc1\">3.4.1. \u5f00\u542f\u8ba4\u8bc1<\/h4>\n<p>etcdctl &#8211;endpoints\u00a0<a href=\"http:\/\/172.16.22.36:2379\/\" target=\"_blank\" rel=\"noopener\">http:\/\/172.16.22.36:2379<\/a>\u00a0auth enable<\/p>\n<h2 id=\"4-\u8bbf\u95ee\u63a7\u5236\u8bbe\u7f6e\u6b65\u9aa4\">4. \u8bbf\u95ee\u63a7\u5236\u8bbe\u7f6e\u6b65\u9aa4<\/h2>\n<div class=\"table-responsive\">\n<table class=\"table\">\n<thead>\n<tr>\n<th>\u987a\u5e8f<\/th>\n<th>\u6b65\u9aa4<\/th>\n<th>\u547d\u4ee4<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>1<\/td>\n<td>\u6dfb\u52a0root\u7528\u6237<\/td>\n<td>etcdctl &#8211;endpoints http:\/\/:\u00a0user add root<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>\u5f00\u542f\u8ba4\u8bc1<\/td>\n<td>etcdctl &#8211;endpoints http:\/\/:\u00a0auth enable<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>\u6dfb\u52a0\u975eroot\u7528\u6237<\/td>\n<td>etcdctl &#8211;endpoints http:\/\/:\u00a0\u2013username root:\u00a0user add<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>\u6dfb\u52a0\u89d2\u8272<\/td>\n<td>etcdctl &#8211;endpoints http:\/\/:\u00a0\u2013username root:\u00a0role add<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>\u7ed9\u89d2\u8272\u6388\u6743\uff08\u53ea\u8bfb\u3001\u53ea\u5199\u3001\u53ef\u8bfb\u5199\uff09<\/td>\n<td>etcdctl &#8211;endpoints http:\/\/:\u00a0\u2013username root:\u00a0role grant &#8211;readwrite &#8211;path<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>\u7ed9\u7528\u6237\u5206\u914d\u89d2\u8272\uff08\u5373\u5206\u914d\u4e86\u89d2\u8272\u5bf9\u5e94\u7684\u6743\u9650\uff09<\/td>\n<td>etcdctl &#8211;endpoints http:\/\/:\u00a0\u2013username root:\u00a0user grant &#8211;roles<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2 id=\"5-\u8bbf\u95ee\u8ba4\u8bc1\u7684api\u8c03\u7528\">5. \u8bbf\u95ee\u8ba4\u8bc1\u7684API\u8c03\u7528<\/h2>\n<p>\u66f4\u591a\u53c2\u8003<\/p>\n<p><a href=\"https:\/\/coreos.com\/etcd\/docs\/latest\/v2\/auth_api.html\" target=\"_blank\" rel=\"noopener\">https:\/\/coreos.com\/etcd\/docs\/latest\/v2\/auth_api.html<\/a><\/p>\n<p><a href=\"https:\/\/coreos.com\/etcd\/docs\/latest\/v2\/authentication.html\" target=\"_blank\" rel=\"noopener\">https:\/\/coreos.com\/etcd\/docs\/latest\/v2\/authentication.html<\/a><\/p>\n<div>\n<h2 id=\"\u63a8\u8350\u6587\u7ae0\">\u63a8\u8350\u6587\u7ae0<\/h2>\n<ul>\n<li><a href=\"http:\/\/www.huweihuang.com\/article\/etcd\/etcd-introduction\/\">[Etcd] Etcd\u4ecb\u7ecd<\/a><\/li>\n<li><a href=\"http:\/\/www.huweihuang.com\/article\/etcd\/etcd-commands\/\">[Etcd] Etcd\u5e38\u7528\u547d\u4ee4<\/a><\/li>\n<\/ul>\n<\/div>\n<hr \/>\n<ul class=\"pager\">\n<li class=\"previous\"><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>\u539f\u6587\u5730\u5740 &nbsp; 1. ETCD\u8d44<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[],"tags":[118],"class_list":["post-5396","post","type-post","status-publish","format-standard","hentry","tag-02-"],"_links":{"self":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts\/5396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/comments?post=5396"}],"version-history":[{"count":0,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts\/5396\/revisions"}],"wp:attachment":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/media?parent=5396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/categories?post=5396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/tags?post=5396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}