部署Couchbase集群时Webhook调用失败:找不到准入控制器服务
问题描述
在Kubernetes v1.28.1集群上已成功安装Couchbase Operator v2.7(包含自定义资源定义、Operator及准入控制器),但执行kubectl apply -f couchbase-cluster.yaml创建集群时,触发以下错误:
secret/cb-example-auth created Error from server (InternalError): error when creating "couchbase-cluster.yaml": Internal error occurred: failed calling webhook "release-1-couchbase-admission-controller.couchbase.svc": failed to call webhook: Post "https://release-1-couchbase-admission-controller.couchbase.svc:443/couchbaseclusters/validate?timeout=10s": service "release-1-couchbase-admission-controller" not found Error from server (InternalError): error when creating "couchbase-cluster.yaml": Internal error occurred: failed calling webhook "release-1-couchbase-admission-controller.couchbase.svc": failed to call webhook: Post "https://release-1-couchbase-admission-controller.couchbase.svc:443/couchbaseclusters/validate?timeout=10s": service "release-1-couchbase-admission-controller" not found
集群中实际存在的服务列表:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE couchbase-operator ClusterIP xx.xx.xx.xx <none> 8080/TCP,8383/TCP 19m couchbase-operator-admission ClusterIP xx.xx.xx.xx <none> 443/TCP 19m
核心问题:创建集群时,Couchbase调用的准入控制器服务名称release-1-couchbase-admission-controller与实际安装的couchbase-operator-admission不匹配,导致请求失败。
解决方案
1. 修改准入Webhook配置
准入Webhook的规则存储在ValidatingWebhookConfiguration资源中,需要将其指向正确的服务名称:
- 查看当前Couchbase相关的Webhook配置:
kubectl get validatingwebhookconfigurations | grep couchbase - 编辑该Webhook配置:
在编辑界面中,找到kubectl edit validatingwebhookconfigurations <webhook-config-name>clientConfig.url字段,将其中的服务名称从release-1-couchbase-admission-controller替换为实际存在的couchbase-operator-admission,保存退出。
2. 检查集群配置文件(可选)
如果你的couchbase-cluster.yaml中存在自定义的Operator服务名称或Webhook相关配置项,需要同步修改为实际的服务名称,确保集群资源与Operator服务的配置一致。
3. 验证修复效果
重新执行集群创建命令:
kubectl apply -f couchbase-cluster.yaml
若仍有异常,可查看Operator日志排查其他配置不一致问题:
kubectl logs -l app=couchbase-operator -n couchbase
内容的提问来源于stack exchange,提问作者Piyush Das
相关产品推荐
相关产品推荐

