You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否使用Vertical Pod Autoscaler监控Kubernetes API Server?实践遇阻求助

如何用VPA监控Kubernetes API Server的CPU和内存使用率?

问题背景

根据Vertical Pod Autoscaler(VPA)官方文档,VPA仅支持分析由Deployment、DaemonSet等高层控制器创建的Pod。而Kubernetes API-Server以静态Pod的形式运行,由控制平面节点上的kubelet直接管理。尝试将VPA与API-Server关联时,因API-Server无上层Deployment类控制器托管,出现「Pod not found」错误,具体报错信息如下:

kubectl describe vpa -n kube-system kube-apiserver-vpa
Name:         kube-apiserver-vpa
Namespace:    kube-system
Labels:       <none>
Annotations:  <none>
API Version:  autoscaling.k8s.io/v1
Kind:         VerticalPodAutoscaler
Metadata:
  Creation Timestamp:  2024-02-29T16:00:32Z
  Generation:          1
  Resource Version:    585285
  UID:                 fbbac82f-2ace-4021-aad1-75d8bb4b4454
Spec:
  Resource Policy:
    Container Policies:
      Container Name:  kube-apiserver
      Controlled Resources:
        cpu
        memory
      Max Allowed:
        Cpu:     2000m
        Memory:  2Gi
      Min Allowed:
        Cpu:     250m
        Memory:  250Mi
  Target Ref:
    API Version:  v1
    Kind:         Pod
    Name:         kube-apiserver-c0n0
  Update Policy:
    Update Mode:  Off
Status:
  Conditions:
    Last Transition Time:  2024-02-29T16:00:45Z
    Message:               Cannot read targetRef. Reason: Unhandled targetRef v1 / Pod / kube-apiserver-c0n0, last error the server could not find the requested resource
    Status:                True
    Type:                  ConfigUnsupported
    Last Transition Time:  2024-02-29T16:00:45Z
    Message:               No pods match this VPA object
    Reason:                NoPodsMatched
    Status:                True
    Type:                  NoPodsMatched
    Last Transition Time:  2024-02-29T16:00:45Z
    Message:               No pods match this VPA object
    Reason:                NoPodsMatched
    Status:                False
    Type:                  RecommendationProvided
  Recommendation:
Events:  <none>

核心疑问

是否有办法使用VPA监控Kubernetes API-Server的CPU和内存使用率?

解决方案

1. 利用VPA的Selector匹配静态Pod(支持监控与资源推荐)

VPA虽然不支持直接指定单个静态Pod作为targetRef,但可以通过spec.selector匹配带有特定标签的静态Pod,从而实现监控和资源使用分析。

步骤:

  • 给API Server静态Pod添加标签:
    登录控制平面节点,找到静态Pod配置文件(通常路径为/etc/kubernetes/manifests/kube-apiserver.yaml),在metadata.labels中添加自定义标签,示例:

    metadata:
      labels:
        component: kube-apiserver
        tier: control-plane
    

    修改保存后,kubelet会自动重启API Server Pod以应用标签。

  • 创建带Selector的VPA资源:
    替换原VPA的targetRef为selector,匹配刚添加的标签,示例YAML:

    apiVersion: autoscaling.k8s.io/v1
    kind: VerticalPodAutoscaler
    metadata:
      name: kube-apiserver-vpa
      namespace: kube-system
    spec:
      resourcePolicy:
        containerPolicies:
        - containerName: kube-apiserver
          controlledResources:
          - cpu
          - memory
          maxAllowed:
            cpu: 2000m
            memory: 2Gi
          minAllowed:
            cpu: 250m
            memory: 250Mi
      selector:
        matchLabels:
          component: kube-apiserver
          tier: control-plane
      updatePolicy:
        updateMode: Off
    

    应用配置:kubectl apply -f vpa-apiserver.yaml -n kube-system

    之后可以通过kubectl describe vpa kube-apiserver-vpa -n kube-system查看VPA生成的资源使用分析和推荐。

注意:VPA的自动更新功能(updateMode: Auto或Recreate)对静态Pod无效,因为静态Pod的资源配置由本地文件管理,VPA无法直接修改这些文件。

2. 用Prometheus+Grafana/Metrics Server替代(仅监控需求)

如果仅需要监控API Server的CPU和内存使用率,不需要VPA的资源推荐,可以直接用K8s生态工具实现:

  • Metrics Server:执行kubectl top pod kube-apiserver-<节点名> -n kube-system即可查看实时资源使用数据。
  • Prometheus+Grafana:通过采集kubelet或API Server暴露的metrics接口,在Grafana中配置可视化面板,实现长期监控和告警。

内容的提问来源于stack exchange,提问作者user2819943

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 15:57:08