能否使用Vertical Pod Autoscaler监控Kubernetes API Server?实践遇阻求助
问题背景
根据Vertical Pod Autoscaler(VPA)官方文档,VPA仅支持分析由Deployment、DaemonSet等高层控制器创建的Pod。而Kubernetes API-Server以静态Pod的形式运行,由控制平面节点上的kubelet直接管理。尝试将VPA与API-Server关联时,因API-Server无上层Deployment类控制器托管,出现「Pod not found」错误,具体报错信息如下:
kubectl describe vpa -n kube-system kube-apiserver-vpa Name: kube-apiserver-vpa Namespace: kube-system Labels: <none> Annotations: <none> API Version: autoscaling.k8s.io/v1 Kind: VerticalPodAutoscaler Metadata: Creation Timestamp: 2024-02-29T16:00:32Z Generation: 1 Resource Version: 585285 UID: fbbac82f-2ace-4021-aad1-75d8bb4b4454 Spec: Resource Policy: Container Policies: Container Name: kube-apiserver Controlled Resources: cpu memory Max Allowed: Cpu: 2000m Memory: 2Gi Min Allowed: Cpu: 250m Memory: 250Mi Target Ref: API Version: v1 Kind: Pod Name: kube-apiserver-c0n0 Update Policy: Update Mode: Off Status: Conditions: Last Transition Time: 2024-02-29T16:00:45Z Message: Cannot read targetRef. Reason: Unhandled targetRef v1 / Pod / kube-apiserver-c0n0, last error the server could not find the requested resource Status: True Type: ConfigUnsupported Last Transition Time: 2024-02-29T16:00:45Z Message: No pods match this VPA object Reason: NoPodsMatched Status: True Type: NoPodsMatched Last Transition Time: 2024-02-29T16:00:45Z Message: No pods match this VPA object Reason: NoPodsMatched Status: False Type: RecommendationProvided Recommendation: Events: <none>
核心疑问
是否有办法使用VPA监控Kubernetes API-Server的CPU和内存使用率?
解决方案
1. 利用VPA的Selector匹配静态Pod(支持监控与资源推荐)
VPA虽然不支持直接指定单个静态Pod作为targetRef,但可以通过spec.selector匹配带有特定标签的静态Pod,从而实现监控和资源使用分析。
步骤:
给API Server静态Pod添加标签:
登录控制平面节点,找到静态Pod配置文件(通常路径为/etc/kubernetes/manifests/kube-apiserver.yaml),在metadata.labels中添加自定义标签,示例:metadata: labels: component: kube-apiserver tier: control-plane修改保存后,kubelet会自动重启API Server Pod以应用标签。
创建带Selector的VPA资源:
替换原VPA的targetRef为selector,匹配刚添加的标签,示例YAML:apiVersion: autoscaling.k8s.io/v1 kind: VerticalPodAutoscaler metadata: name: kube-apiserver-vpa namespace: kube-system spec: resourcePolicy: containerPolicies: - containerName: kube-apiserver controlledResources: - cpu - memory maxAllowed: cpu: 2000m memory: 2Gi minAllowed: cpu: 250m memory: 250Mi selector: matchLabels: component: kube-apiserver tier: control-plane updatePolicy: updateMode: Off应用配置:
kubectl apply -f vpa-apiserver.yaml -n kube-system之后可以通过
kubectl describe vpa kube-apiserver-vpa -n kube-system查看VPA生成的资源使用分析和推荐。
注意:VPA的自动更新功能(
updateMode: Auto或Recreate)对静态Pod无效,因为静态Pod的资源配置由本地文件管理,VPA无法直接修改这些文件。
2. 用Prometheus+Grafana/Metrics Server替代(仅监控需求)
如果仅需要监控API Server的CPU和内存使用率,不需要VPA的资源推荐,可以直接用K8s生态工具实现:
- Metrics Server:执行
kubectl top pod kube-apiserver-<节点名> -n kube-system即可查看实时资源使用数据。 - Prometheus+Grafana:通过采集kubelet或API Server暴露的metrics接口,在Grafana中配置可视化面板,实现长期监控和告警。
内容的提问来源于stack exchange,提问作者user2819943

