使用GitHub Actions部署EKS集群后无法访问的问题求助
问题场景
本地通过Terraform部署带工作节点的EKS集群后,执行kubectl get nodes可正常返回结果;但通过GitHub Actions推送部署时,集群虽部署成功,执行kubectl get nodes却抛出凭证缺失错误。已将OIDC配置的GitHubActionsTerraformIAMrole的ARN作为环境密钥存入GitHub仓库,本地与Actions使用相同tfvars文件,暂无法定位具体凭证问题,相关报错与Workflow文件如下:
报错信息
E0505 22:34:58.473467 28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials E0505 22:34:59.011805 28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials E0505 22:34:59.764169 28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials E0505 22:35:00.350556 28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials E0505 22:35:01.067397 28812 memcache.go:265] couldn't get current server API group list: the server has asked for the client to provide credentials error: You must be logged in to the server (the server has asked for the client to provide credentials)
GitHub Actions Workflow文件
name: Terraform Deployment Workflow on: push: branches: - main - dev permissions: id-token: write contents: read jobs: terraform: runs-on: ubuntu-latest environment: ${{ (github.ref == 'refs/heads/main' && 'production') || (github.ref == 'refs/heads/staging' && 'staging') || 'dev' }} steps: - name: Checkout repository uses: actions/checkout@v2 - name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@v1.7.0 with: aws-region: us-east-1 role-to-assume: ${{ secrets.IAM_ROLE }} audience: sts.amazonaws.com - name: Terraform Initialize run: terraform init -reconfigure -backend-config="bucket=project-x" -backend-config="key=terraform.tfstate" -backend-config="region=us-east-1" working-directory: ./roots/main-eks-root/ - name: Terraform Plan run: terraform plan -var-file="project.tfvars" -out=tfplan working-directory: ./roots/main-eks-root/ - name: Terraform Apply run: terraform apply -auto-approve "tfplan" working-directory: ./roots/main-eks-root/
问题根源
GitHub Actions中配置的IAM角色仅具备Terraform部署EKS的权限,未被授权获取EKS集群kubeconfig,也未加入EKS的RBAC授权体系,导致kubectl无法完成身份验证。
解决步骤
1. 为IAM角色添加EKS访问权限
修改该IAM角色的权限策略,加入以下内容,允许角色获取EKS集群信息:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "eks:DescribeCluster" ], "Resource": "arn:aws:eks:us-east-1:你的AWS账号ID:cluster/你的EKS集群名称" } ] }
2. 将IAM角色纳入EKS RBAC授权
通过以下两种方式之一,为IAM角色分配EKS集群访问权限(示例为管理员权限,可根据需求调整):
方式一:Terraform代码配置
在EKS集群的Terraform代码中添加资源:
# 获取EKS集群认证信息 resource "aws_eks_cluster_auth" "main" { name = aws_eks_cluster.main.name } # 绑定集群管理员权限到GitHub Actions角色 resource "kubernetes_cluster_role_binding" "github_actions_admin" { metadata { name = "github-actions-admin-binding" } role_ref { api_group = "rbac.authorization.k8s.io" kind = "ClusterRole" name = "cluster-admin" } subject { api_group = "rbac.authorization.k8s.io" kind = "User" name = "arn:aws:iam::你的AWS账号ID:role/GitHubActionsTerraformIAMrole" } }
方式二:手动绑定(临时验证用)
若不想修改Terraform代码,可在本地执行命令完成绑定(需本地已有集群访问权限):
kubectl create clusterrolebinding github-actions-admin --clusterrole=cluster-admin --user=arn:aws:iam::你的AWS账号ID:role/GitHubActionsTerraformIAMrole
3. 在Workflow中添加kubectl配置步骤
在Terraform Apply步骤之后,添加获取kubeconfig并验证节点状态的步骤:
- name: Configure kubectl run: | aws eks update-kubeconfig --region us-east-1 --name 你的EKS集群名称 working-directory: ./roots/main-eks-root/ - name: Verify node status run: kubectl get nodes working-directory: ./roots/main-eks-root/
4. 验证IAM角色信任策略
确保OIDC信任策略正确,允许GitHub Actions身份提供商扮演该角色,示例策略:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Federated": "arn:aws:iam::你的AWS账号ID:oidc-provider/token.actions.githubusercontent.com" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringEquals": { "token.actions.githubusercontent.com:sub": "repo:你的GitHub用户名/仓库名:ref:refs/heads/main", "token.actions.githubusercontent.com:aud": "sts.amazonaws.com" } } } ] }
若需支持多个分支,可调整Condition中的sub值,例如添加多个条目或使用通配符。
关键提示
本地能正常访问是因为本地AWS凭证对应的IAM用户/角色已被授权访问EKS,而GitHub Actions使用的角色未加入EKS的RBAC体系。确保Terraform部署完成后,aws eks update-kubeconfig能通过当前AWS凭证正确生成并加载kubeconfig。
内容的提问来源于stack exchange,提问作者user24886951

