首页   注册   登录
V2EX = way to explore
V2EX 是一个关于分享和探索的地方
现在注册
已注册用户请  登录
Coding
V2EX  ›  Docker

k8s 节点启动 kubelet 问题请教

  •  
  •   fanne · 317 天前 · 1670 次点击
    这是一个创建于 317 天前的主题,其中的信息可能已经有所发展或是发生改变。
    [[email protected] cfg]# /opt/kubernetes/bin/kubelet  --logtostderr=true --v=4 --address=192.168.248.129 --hostname-override=192.168.248.129 --kubeconfig=/opt/kubernetes/cfg/kubelet.kubeconfig --experimental-bootstrap-kubeconfig=/opt/kubernetes/cfg/bootstrap.kubeconfig --cert-dir=/opt/kubernetes/ssl --allow-privileged=true --fail-swap-on=false --cluster-dns=10.10.10.2 --cluster-domain=cluster.local --pod-infra-container-image=registry.cn-hangzhou.aliyuncs/google_containers/pause-amd64:3.0
    

    报错信息

    I0129 05:41:06.946579    6235 bootstrap.go:58] Using bootstrap kubeconfig to generate TLS client cert, key and kubeconfig file
    error: failed to run Kubelet: cannot create certificate signing request: certificatesigningrequests.certificates.k8s.io is forbidden: User "kubelet-bootstrap" cannot create certificatesigningrequests.certificates.k8s.io at the cluster scope: clusterrole.rbac.authorization.k8s.io "system:node-bootstrap" not found
    

    master 上创建角色权限

    [[email protected] .kube]# kubectl create clusterrolebinding kubelet-bootstrap --clusterrole=system:node-bootstrapper --user=kubelet-bootstrap
    Error from server (AlreadyExists): clusterrolebindings.rbac.authorization.k8s.io "kubelet-bootstrap" already exists
    [[email protected] .kube]# kubectl describe clusterrolebinding kubelet-bootstrap                                                              
    Name:           kubelet-bootstrap
    Namespace:
    Labels:         <none>
    Events:         <none>
    

    这个权限之前估计创建有误,但kubelet-bootstrap已占用,不知怎么修改的clusterrole这个值。

    目前尚无回复
    关于   ·   FAQ   ·   API   ·   我们的愿景   ·   广告投放   ·   感谢   ·   实用小工具   ·   3648 人在线   最高记录 5043   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.3 · 22ms · UTC 01:13 · PVG 09:13 · LAX 17:13 · JFK 20:13
    ♥ Do have faith in what you're doing.