Azure AKS上ARC自托管作业持续排队的排查求助
问题描述
我在Azure AKS集群上部署了Actions Runner Controller(ARC)及运行器,但作业始终处于排队状态,显示:
Requested labels: arc-runners
Job defined at: SH-Proptech/k8s/.github/workflows/arc.yaml@refs/heads/main
Waiting for a runner to pick up this job...
所有日志均未报错,以下是我的相关配置信息,请问哪里遗漏了?
作业配置
name: Actions Runner Controller Test on: # 手动触发工作流 workflow_dispatch: jobs: Test-Arc-Runners: runs-on: labels: arc-runners # 确保与自托管运行器的标签匹配 steps: - run: echo "🎉 This job uses runner scale set runners!"
Helm部署命令
helm upgrade --install arc \ --namespace arc \ --create-namespace \ oci://ghcr.io/actions/actions-runner-controller-charts/gha-runner-scale-set-controller helm upgrade --install arc-runners \ --namespace arc-runners \ --create-namespace \ --values ./values/arc.yaml \ oci://ghcr.io/actions/actions-runner-controller-charts/gha-runner-scale-set
values.yaml配置(使用个人PAT访问组织,可能存在问题)
githubConfigUrl: "https://github.com/<my-org>" githubConfigSecret: "arc" maxRunners: 5 minRunners: 1
运行器集信息
kubectl describe autoscalingrunnersets -n arc-runners Name: arc-runners Namespace: arc-runners Labels: actions.github.com/organization=<my-org> actions.github.com/scale-set-name=arc-runners actions.github.com/scale-set-namespace=arc-runners app.kubernetes.io/component=autoscaling-runner-set app.kubernetes.io/instance=arc-runners app.kubernetes.io/managed-by=Helm app.kubernetes.io/name=arc-runners app.kubernetes.io/part-of=gha-rs app.kubernetes.io/version=0.10.1 helm.sh/chart=gha-rs-0.10.1 Annotations: actions.github.com/cleanup-manager-role-binding: arc-runners-gha-rs-manager actions.github.com/cleanup-manager-role-name: arc-runners-gha-rs-manager actions.github.com/cleanup-no-permission-service-account-name: arc-runners-gha-rs-no-permission actions.github.com/runner-group-name: Default actions.github.com/runner-scale-set-name: arc-runners API Version: actions.github.com/v1alpha1 Kind: AutoscalingRunnerSet Metadata: Creation Timestamp: 2025-02-16T18:01:33Z Finalizers: autoscalingrunnerset.actions.github.com/finalizer Generation: 2 ... Spec: Github Config Secret: arc Github Config URL: https://github.com/<my-org> Max Runners: 5 Min Runners: 1 Template: Spec: Containers: Command: /home/runner/run.sh Image: ghcr.io/actions/actions-runner:latest Name: runner Restart Policy: Never Service Account Name: arc-runners-gha-rs-no-permission Status: Current Runners: 1 Pending Ephemeral Runners: 1 Events: <none>
Secret信息
kubectl describe secret -n arc-runners arc Name: arc Namespace: arc-runners Labels: app.kubernetes.io/managed-by=Helm Annotations: operator.1password.io/auto-restart: true operator.1password.io/item-path: vaults/<vault> operator.1password.io/item-version: 10 Type: Opaque Data ==== github_token: <masked>
相关截图


排查关键点
PAT权限验证
- 确认个人PAT拥有
repo、admin:org(组织级运行器需要)、workflow权限,且未过期。 - 可通过
kubectl get secret arc -n arc-runners -o jsonpath='{.data.github_token}' | base64 -d验证Secret中的PAT内容是否正确(注意保密)。
- 确认个人PAT拥有
运行器标签匹配
- 在GitHub组织设置的「运行器」页面,查看对应运行器集的实际标签,确保和作业中
runs-on.labels完全一致(大小写敏感)。
- 在GitHub组织设置的「运行器」页面,查看对应运行器集的实际标签,确保和作业中
运行器组权限
- 检查运行器所在的「Default」组是否允许目标仓库(SH-Proptech/k8s)使用:在GitHub组织的运行器组设置中,确认仓库已添加到允许列表,或设置为「所有仓库都可以使用」。
ARC组件日志排查
- 查看ARC控制器日志:
kubectl logs -n arc deployment/arc-gha-runner-scale-set-controller,确认是否存在GitHub API通信异常(如认证失败、权限不足)。 - 查看运行器Pod日志:若有Pending状态的Pod,先排查启动失败原因(如镜像拉取失败、资源不足);若Pod已启动,执行
kubectl logs -n arc-runners <runner-pod-name>,确认运行器是否成功注册到GitHub。
- 查看ARC控制器日志:
命名空间与Secret关联检查
- 确认
arc-runners命名空间下的arcSecret确实包含github_token字段,且ARC控制器拥有访问该Secret的RBAC权限。
- 确认
内容的提问来源于stack exchange,提问作者Brenwell
相关产品推荐
相关产品推荐

