You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS升级因已弃用API受阻,但未检测到该API的使用

AKS升级检测到弃用API autoscaling.horizontalpodautoscalers.v2beta2.watch 但未找到使用痕迹的原因

我在Azure Portal中将AKS集群从1.25.6版本升级至1.26.12版本时失败,提示检测到已弃用API autoscaling.horizontalpodautoscalers.v2beta2.watch 的使用,但我并未在集群中找到该API的使用痕迹。我知道可以强制升级,但希望先解决问题而非承担风险。

完整错误日志

Failed to save Kubernetes service 'devtest-us1'. Error: Control Plane upgrade is blocked due to recent usage of a Kubernetes API deprecated in the specified version. Please refer to https://kubernetes.io/docs/reference/using-api/deprecation-guide to migrate the usage. To bypass this error, set forceUpgrade in upgradeSettings.overrideSettings. Bypassing this error without migrating usage will result in the deprecated Kubernetes API calls failing. See details in https://aka.ms/aks/UpgradeAndDeprecatedAPIs. Usage details: 1 error occurred:
    * usage has been detected on API autoscaling.horizontalpodautoscalers.v2beta2.watch, and was recently seen at: 2024-03-07 15:46:48 +0000 UTC, which will be removed in 1.26

我的排查步骤

~ using ☁️ Production devtest-us1
➜ kubectl get horizontalpodautoscalers -A -o custom-columns='NAMESPACE:.metadata.namespace,NAME:.metadata.name,API_VERSION:.apiVersion'
NAMESPACE            NAME                    API_VERSION
datadog-operator     datadog-cluster-agent   autoscaling/v2
kube-state-metrics   kube-state-metrics      autoscaling/v2
kube-system          osm-controller-hpa      autoscaling/v2
kube-system          osm-injector-hpa        autoscaling/v2

➜ kubectl api-resources | grep autoscaling
horizontalpodautoscalers                   hpa                      autoscaling/v2                                         true         HorizontalPodAutoscaler

我原以为如果该API被使用,会在上述检查结果中显示,但实际并未发现,请问这是为什么?


原因分析

  • 你检查的是HPA资源的定义版本,而非watch操作的API版本
    kubectl get horizontalpodautoscalers仅返回现有HPA对象创建/更新时使用的API版本,但AKS检测到的是watch请求调用的API版本。watch是监听资源变化的操作,客户端(监控工具、控制器、甚至kubectl的watch命令)可能用旧版本API发起请求,这类操作不会体现在已创建的HPA对象的API版本上。

  • 第三方组件或控制器可能在后台调用旧API
    集群中的Datadog Operator、kube-state-metrics、OSM相关组件等,可能内部逻辑仍使用autoscaling/v2beta2版本发起HPA的watch请求。如果这些组件的版本未及时更新,就会持续触发旧API调用。

  • 检测基于API服务器的历史访问日志
    AKS的升级检查是通过分析API服务器的近期访问日志识别弃用API调用的。即使当前没有持续调用,只要检测窗口期内有过一次v2beta2.watch请求,就会触发阻止提示。可能之前临时运行的脚本、旧版本组件发起过该请求,现在已停止但日志仍被记录。

  • 客户端工具版本不匹配
    若你使用的kubectl版本低于目标集群版本(1.26),执行kubectl get hpa --watch这类命令时,可能默认用旧版本API发起watch请求。即使当前执行的返回v2版本,之前的watch操作可能由低版本客户端触发。

进一步排查建议

  • 检查集群内所有控制器、监控工具的版本,确认它们是否支持用autoscaling/v2版本进行watch操作,比如Datadog Operator、kube-state-metrics、OSM是否已更新至兼容Kubernetes 1.26的版本。
  • 收集并分析API服务器的访问日志,定位发起autoscaling.horizontalpodautoscalers.v2beta2.watch请求的客户端IP或用户代理,找到调用来源。
  • 确认本地及集群内使用的kubectl版本与目标集群版本匹配,避免因客户端版本过低导致旧API调用。

内容的提问来源于stack exchange,提问作者Emily Zall

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 10:13:12