【问题标题】:Kube-apiserver unable to read from a custom volume added to ApiServer POD manifestKube-apiserver 无法从添加到 ApiServer POD 清单的自定义卷中读取
【发布时间】:2021-10-23 04:47:09
【问题描述】:

我想将准入控制器配置和审计策略 yaml 添加到 kube api 服务器。我将这两个文件保存在 /etc/kubernetes/configs 下的文件夹中,并将其作为卷/volumeMount 添加到 POD。

尽管没有收到任何错误,但 pod 无法从该位置获取配置文件。我做错了什么?

错误:无法初始化准入:无法读取插件配置:无法从“/etc/kubernetes/configs/admission-controller.yaml”读取准入控制配置[打开/etc/kubernetes/configs/admission-controller. yaml: 没有这样的文件或目录]

kube-apiserver.yaml

apiVersion: v1
kind: Pod
metadata:
  annotations:
    kubeadm.kubernetes.io/kube-apiserver.advertise-address.endpoint: 192.168.1.45:6443
  creationTimestamp: null
  labels:
    component: kube-apiserver
    tier: control-plane
  name: kube-apiserver
  namespace: kube-system
spec:
  containers:
  - command:
    - kube-apiserver
    - --service-account-lookup=true
    - --request-timeout=300s
    #- --audit-log-maxsize=100
    #- --audit-log-maxbackup=10
    #- --audit-log-maxage=30
    #- --audit-policy-file=/etc/kubernetes/pki/audit-policy.yaml
    #- --audit-log-path=/var/log/audit/audit.log
    - --profiling=false
    - --admission-control-config-file=/etc/kubernetes/configs/admission-controller.yaml
    - --kubelet-certificate-authority=/etc/kubernetes/pki/ca.crt 
    - --kubelet-https=true
    - --anonymous-auth=false
    - --advertise-address=192.168.1.45
    - --allow-privileged=true
    - --authorization-mode=Node,RBAC
    - --client-ca-file=/etc/kubernetes/pki/ca.crt
    - --enable-admission-plugins=NodeRestriction,EventRateLimit,AlwaysPullImages,PodSecurityPolicy
    - --enable-bootstrap-token-auth=true
    - --etcd-cafile=/etc/kubernetes/pki/etcd/ca.crt
    - --etcd-certfile=/etc/kubernetes/pki/apiserver-etcd-client.crt
    - --etcd-keyfile=/etc/kubernetes/pki/apiserver-etcd-client.key
    - --etcd-servers=https://127.0.0.1:2379
    - --insecure-port=0
    - --kubelet-client-certificate=/etc/kubernetes/pki/apiserver-kubelet-client.crt
    - --kubelet-client-key=/etc/kubernetes/pki/apiserver-kubelet-client.key
    - --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname
    - --proxy-client-cert-file=/etc/kubernetes/pki/front-proxy-client.crt
    - --proxy-client-key-file=/etc/kubernetes/pki/front-proxy-client.key
    - --requestheader-allowed-names=front-proxy-client
    - --requestheader-client-ca-file=/etc/kubernetes/pki/front-proxy-ca.crt
    - --requestheader-extra-headers-prefix=X-Remote-Extra-
    - --requestheader-group-headers=X-Remote-Group
    - --requestheader-username-headers=X-Remote-User
    - --secure-port=6443
    - --service-account-issuer=https://kubernetes.default.svc.cluster.local
    - --service-account-key-file=/etc/kubernetes/pki/sa.pub
    - --service-account-signing-key-file=/etc/kubernetes/pki/sa.key
    - --service-cluster-ip-range=10.96.0.0/12
    - --tls-cert-file=/etc/kubernetes/pki/apiserver.crt
    - --tls-private-key-file=/etc/kubernetes/pki/apiserver.key
    image: k8s.gcr.io/kube-apiserver:v1.21.4
    imagePullPolicy: IfNotPresent
    livenessProbe:
      failureThreshold: 8
      httpGet:
        host: 192.168.1.45
        path: /livez
        port: 6443
        scheme: HTTPS
      initialDelaySeconds: 10
      periodSeconds: 10
      timeoutSeconds: 15
    name: kube-apiserver
    readinessProbe:
      failureThreshold: 3
      httpGet:
        host: 192.168.1.45
        path: /readyz
        port: 6443
        scheme: HTTPS
      periodSeconds: 1
      timeoutSeconds: 15
    resources:
      requests:
        cpu: 250m
    startupProbe:
      failureThreshold: 24
      httpGet:
        host: 192.168.1.45
        path: /livez
        port: 6443
        scheme: HTTPS
      initialDelaySeconds: 10
      periodSeconds: 10
      timeoutSeconds: 15
    volumeMounts:
    - name: configfiles
      mountPath: /etc/kubernetes/configs
      readOnly: false
    - name: auditlog
      mountPath: /var/log/audit
      readOnly: false
    - mountPath: /etc/ssl/certs
      name: ca-certs
      readOnly: true
    - mountPath: /etc/pki
      name: etc-pki
      readOnly: true
    - mountPath: /etc/kubernetes/pki
      name: k8s-certs
      readOnly: true
  hostNetwork: true
  priorityClassName: system-node-critical
  volumes:
  - name: auditlog
    hostpath:
      path: /var/log/kubernetes
      type: DirectoryOrCreate
  - name: configfiles
    hostpath:
      path: /etc/kubernetes/configs
      type: DirectoryOrCreate
  - hostPath:
      path: /etc/ssl/certs
      type: DirectoryOrCreate
    name: ca-certs
  - hostPath:
      path: /etc/pki
      type: DirectoryOrCreate
    name: etc-pki
  - hostPath:
      path: /etc/kubernetes/pki
      type: DirectoryOrCreate
    name: k8s-certs
status: {}
[root@controlplane ~]# ls -lrt /etc/kubernetes/configs
total 16
-rw------- 1 root root  175 Aug 21 09:36 eventconfig.yaml
-rw------- 1 root root  125 Aug 21 09:36 admission-controller.yaml
-rw------- 1 root root 2219 Aug 21 16:15 audit-policy.yaml_back
-rw------- 1 root root 2219 Aug 21 16:39 audit-policy.yaml
[root@controlplane ~]#

【问题讨论】:

  • 主机路径应该在主节点中。您确定文件在主节点中吗?
  • 是的,它是一个单一的节点..
  • 能否从主机添加 ls -lrt /etc/kubernetes/configs

标签: kubernetes volumes kube-apiserver


【解决方案1】:

错误是由于hostPath不是驼峰式的,更改它以解决问题。

  - name: auditlog
    hostPath:
      path: /var/log/kubernetes
      type: DirectoryOrCreate
  - name: configfiles
    hostPath:
      path: /etc/kubernetes/configs
      type: DirectoryOrCreate

【讨论】:

  • 你没有任何错误吗?这不应该用不正确的语法来解析(我指的是你的原始帖子)
  • 不,它没有,不确定它是否在更高版本中被解析,但 1.20 没有捕捉到它,这就是为什么我无法轻易弄清楚。我检查了显示从容器图形位置安装的卷的容器
猜你喜欢
  • 1970-01-01
  • 2021-06-12
  • 2016-04-22
  • 2019-12-19
  • 2023-03-10
  • 1970-01-01
  • 2020-12-31
  • 2019-05-08
  • 1970-01-01
相关资源
最近更新 更多