将AWS集群接入GCP Anthos时遇代理不可达及401认证错误技术求助
Let’s tackle your two key problems step by step—first the authentication error blocking your cluster creation command, then the unreachable GKE Connect Agent status.
1. Fixing the 401 "UNAUTHENTICATED" Error on cloud container aws cluster create
This error means your gcloud session lacks valid credentials to interact with the Anthos Multi-Cloud API. Try these actionable steps:
Verify active gcloud authentication
Rungcloud auth listto check if you have an active authenticated account linked to your Anthos project. If no account is listed or the active one is incorrect, re-authenticate with:gcloud auth loginFor service account-based workflows (common in automation), ensure you’ve set the environment variable pointing to your service account key file:
export GOOGLE_APPLICATION_CREDENTIALS="/path/to/your/service-account-key.json"Confirm your target GCP project is set correctly
Make sure you’re operating in the project where Anthos is enabled:gcloud config get-value projectIf it’s wrong, update it with:
gcloud config set project YOUR_PROJECT_IDCheck IAM permissions
Ensure your account (or service account) has the necessary roles for Anthos Multi-Cloud, such as:roles/gkemulticloud.admin(full admin access)- Or granular roles like
roles/gkemulticloud.clusterCreatorif you don’t need full admin rights
2. Resolving the "Unreachable Agent" Status in GCP
Once you fix the authentication issue and create the cluster successfully, if the agent still shows as unreachable, diagnose with these steps:
Check if the GKE Connect Agent is deployed and running
Use kubectl to access your AWS cluster (ensure your kubeconfig is configured for the AWS cluster) and run:kubectl get pods -n gke-connectYou should see at least one pod in
Runningstate. If pods are missing or inCrashLoopBackOff, inspect their logs for root causes:kubectl logs <pod-name> -n gke-connectValidate the Connect registration key
The agent relies on a registration key linked to your Anthos Hub membership. If you registered the cluster manually, confirm the key isn’t expired and was applied correctly. You can re-register the membership if needed (replace placeholders):gcloud container hub memberships register YOUR_MEMBERSHIP_NAME \ --gke-cluster=aws://YOUR_AWS_REGION/YOUR_AWS_CLUSTER_NAME \ --service-account-key-file=/path/to/connect-sa-key.jsonVerify network connectivity from AWS nodes
Your AWS cluster nodes need outbound HTTPS (443) access to critical GCP endpoints including:gkeconnect.googleapis.comoauth2.googleapis.comcontainer.googleapis.com
Check your AWS security groups and network ACLs to ensure these connections aren’t blocked. Test connectivity directly from a node with:
curl -v https://gkeconnect.googleapis.comConfirm all required APIs are enabled
Double-check that essential GCP services are active:gcloud services list --enabled | grep -E "gkemulticloud|gkeconnect|container"If any are missing, enable them with:
gcloud services enable gkemulticloud.googleapis.com gkeconnect.googleapis.com container.googleapis.com
内容的提问来源于stack exchange,提问作者RaSta83

