You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用GitHub Actions部署EKS集群后无法访问的问题求助

EKS集群部署后GitHub Actions中kubectl无凭证访问问题排查与解决

问题场景

本地通过Terraform部署带工作节点的EKS集群后,执行kubectl get nodes可正常返回结果;但通过GitHub Actions推送部署时,集群虽部署成功,执行kubectl get nodes却抛出凭证缺失错误。已将OIDC配置的GitHubActionsTerraformIAMrole的ARN作为环境密钥存入GitHub仓库,本地与Actions使用相同tfvars文件,暂无法定位具体凭证问题,相关报错与Workflow文件如下:

报错信息

E0505 22:34:58.473467   28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials
E0505 22:34:59.011805   28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials
E0505 22:34:59.764169   28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials
E0505 22:35:00.350556   28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials
E0505 22:35:01.067397   28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials
error: You must be logged in to the server (the server has asked for the client to provide credentials)

GitHub Actions Workflow文件

name: Terraform Deployment Workflow
on:
  push:
    branches:
      - main
      - dev
permissions:
  id-token: write
  contents: read
jobs:
  terraform:
    runs-on: ubuntu-latest
    environment: ${{ (github.ref == 'refs/heads/main' && 'production') || (github.ref == 'refs/heads/staging' && 'staging') || 'dev' }}
    steps:
      - name: Checkout repository
        uses: actions/checkout@v2

      - name: Configure AWS credentials
        uses: aws-actions/configure-aws-credentials@v1.7.0
        with:
          aws-region: us-east-1
          role-to-assume: ${{ secrets.IAM_ROLE }}
          audience: sts.amazonaws.com

      - name: Terraform Initialize
        run: terraform init -reconfigure -backend-config="bucket=project-x" -backend-config="key=terraform.tfstate" -backend-config="region=us-east-1"
        working-directory: ./roots/main-eks-root/

      - name: Terraform Plan
        run: terraform plan -var-file="project.tfvars" -out=tfplan
        working-directory: ./roots/main-eks-root/

      - name: Terraform Apply
        run: terraform apply -auto-approve "tfplan"
        working-directory: ./roots/main-eks-root/

问题根源

GitHub Actions中配置的IAM角色仅具备Terraform部署EKS的权限,未被授权获取EKS集群kubeconfig,也未加入EKS的RBAC授权体系,导致kubectl无法完成身份验证。

解决步骤

1. 为IAM角色添加EKS访问权限

修改该IAM角色的权限策略,加入以下内容,允许角色获取EKS集群信息:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "eks:DescribeCluster"
            ],
            "Resource": "arn:aws:eks:us-east-1:你的AWS账号ID:cluster/你的EKS集群名称"
        }
    ]
}

2. 将IAM角色纳入EKS RBAC授权

通过以下两种方式之一,为IAM角色分配EKS集群访问权限(示例为管理员权限,可根据需求调整):

方式一:Terraform代码配置

在EKS集群的Terraform代码中添加资源:

# 获取EKS集群认证信息
resource "aws_eks_cluster_auth" "main" {
  name = aws_eks_cluster.main.name
}

# 绑定集群管理员权限到GitHub Actions角色
resource "kubernetes_cluster_role_binding" "github_actions_admin" {
  metadata {
    name = "github-actions-admin-binding"
  }
  role_ref {
    api_group = "rbac.authorization.k8s.io"
    kind      = "ClusterRole"
    name      = "cluster-admin"
  }
  subject {
    api_group = "rbac.authorization.k8s.io"
    kind      = "User"
    name      = "arn:aws:iam::你的AWS账号ID:role/GitHubActionsTerraformIAMrole"
  }
}

方式二:手动绑定(临时验证用)

若不想修改Terraform代码,可在本地执行命令完成绑定(需本地已有集群访问权限):

kubectl create clusterrolebinding github-actions-admin --clusterrole=cluster-admin --user=arn:aws:iam::你的AWS账号ID:role/GitHubActionsTerraformIAMrole

3. 在Workflow中添加kubectl配置步骤

在Terraform Apply步骤之后,添加获取kubeconfig并验证节点状态的步骤:

- name: Configure kubectl
  run: |
    aws eks update-kubeconfig --region us-east-1 --name 你的EKS集群名称
  working-directory: ./roots/main-eks-root/

- name: Verify node status
  run: kubectl get nodes
  working-directory: ./roots/main-eks-root/

4. 验证IAM角色信任策略

确保OIDC信任策略正确,允许GitHub Actions身份提供商扮演该角色,示例策略:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Federated": "arn:aws:iam::你的AWS账号ID:oidc-provider/token.actions.githubusercontent.com"
            },
            "Action": "sts:AssumeRoleWithWebIdentity",
            "Condition": {
                "StringEquals": {
                    "token.actions.githubusercontent.com:sub": "repo:你的GitHub用户名/仓库名:ref:refs/heads/main",
                    "token.actions.githubusercontent.com:aud": "sts.amazonaws.com"
                }
            }
        }
    ]
}

若需支持多个分支,可调整Condition中的sub值,例如添加多个条目或使用通配符。

关键提示

本地能正常访问是因为本地AWS凭证对应的IAM用户/角色已被授权访问EKS,而GitHub Actions使用的角色未加入EKS的RBAC体系。确保Terraform部署完成后,aws eks update-kubeconfig能通过当前AWS凭证正确生成并加载kubeconfig。

内容的提问来源于stack exchange,提问作者user24886951

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 09:17:10