简体   繁体   English

EKS Anywhere 集群证书管理器 io 超时

[英]EKS Anywhere Cluster cert-manager io-timeout

First time trying EKS Anywhere docker provider deployment as given in below link https://anywhere.eks.amazonaws.com/docs/getting-started/local-environment/第一次尝试 EKS Anywhere docker 提供程序部署,如下链接https://anywhere.eks.amazonaws.com/docs/getting-started/local-environment/

It gets stuck at 'waiting for cert-manager'.它卡在“等待证书管理器”。 Working on CentOS 7.System is behind proxy.工作在 CentOS 7. 系统在代理后面。

Installing cert-manager Version="v1.5.3+66e1acc"
Using Override="cert-manager.yaml" Provider="cert-manager" Version="v1.5.3+66e1acc"
Waiting for cert-manager to be available...
Error: timed out waiting for the condition

Only cert-manager pods are not able to pull images只有 cert-manager pod 无法拉取镜像

   NAMESPACE            NAME                                                              READY   STATUS             RESTARTS   AGE
  cert-manager         cert-manager-7988d4fb6c-bjhsv                                     0/1     ImagePullBackOff   0          5m54s
  cert-manager         cert-manager-cainjector-6bc8dcdb64-hvdx5                          0/1     ImagePullBackOff   0          5m55s
  cert-manager         cert-manager-webhook-68979bfb95-q8ttt                             0/1     ImagePullBackOff   0          5m54s
  kube-system          coredns-745c7986c7-2wrx5                                          1/1     Running            0          5m57s
  kube-system          coredns-745c7986c7-kx594                                          1/1     Running            0          5m57s
  kube-system          etcd-dev-cluster-eks-a-cluster-control-plane                      1/1     Running            0          5m52s
  kube-system          kindnet-4jcvt                                                     1/1     Running            0          5m57s
  kube-system          kube-apiserver-dev-cluster-eks-a-cluster-control-plane            1/1     Running            0          5m52s
  kube-system          kube-controller-manager-dev-cluster-eks-a-cluster-control-plane   1/1     Running            0          5m52s
  kube-system          kube-proxy-4dk2r                                                  1/1     Running            0          5m57s
  kube-system          kube-scheduler-dev-cluster-eks-a-cluster-control-plane            1/1     Running            0          5m52s
  local-path-storage   local-path-provisioner-666bfc797f-nkhqf                           1/1     Running            0          5m57s

same images are getting pulled using docker pull使用 docker pull 拉取相同的图像

 public.ecr.aws/eks-anywhere/jetstack/cert-manager-webhook      v1.5.3-eks-a-6                 194bcfda671e   3 months ago    46MB
 public.ecr.aws/eks-anywhere/jetstack/cert-manager-controller   v1.5.3-eks-a-6                 1e6749016508   3 months ago    61.3MB
 public.ecr.aws/eks-anywhere/jetstack/cert-manager-cainjector   v1.5.3-eks-a-6                 45723d794a88   3 months ago    42.4MB

kubectl describe gives below (i/o timeout) error as well as 'server misbehaving' error kubectl describe 给出以下(i/o 超时)错误以及“服务器行为不当”错误

 Failed to pull image "public.ecr.aws/eks-anywhere/jetstack/cert-manager-controller:v1.5.3-eks-a-6": rpc error: code = Unknown desc = failed to pull and unpack image "public.ecr.aws/eks-anywhere/jetstack/cert-manager-controller:v1.5.3-eks-a-6": failed to resolve reference "public.ecr.aws/eks-anywhere/jetstack/cert-manager-controller:v1.5.3-eks-a-6": failed to do request: Head "https://public.ecr.aws/v2/eks-anywhere/jetstack/cert-manager-controller/manifests/v1.5.3-eks-a-6": dial tcp: lookup public.ecr.aws on 172.19.0.1:53: read udp 172.19.0.2:38941->172.19.0.1:53: i/o timeout

It was a proxy related issue.这是一个代理相关的问题。 Resolved by adding proxy config in containerd service of docker container of node and restarting containerd service.通过在node的docker容器的containerd服务中添加代理配置并重启containerd服务解决。

docker exec -it <container name> bash

Inside container内部容器

cd /etc/systemd/system/
mkdir containerd.service.d
touch http-proxy.conf
cat <<EOF >/etc/systemd/system/containerd.service.d/http-proxy.conf    
[Service]    
Environment="HTTP_PROXY=http://proxy ip:proxy port"    
Environment="HTTPS_PROXY=http://proxy ip:proxy port"    
Environment="NO_PROXY=${NO_PROXY:-localhost},${LOCAL_NETWORK}"    
EOF
systemctl daemon-reload
systemctl restart containerd

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM