You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否在GDCE本地集群安装Anthos Service Mesh?安装失败求助

能否在Google本地云边缘集群(GDCE)上安装Anthos Service Mesh(ASM)?

问题背景

尝试在本地GDCE服务器上通过asmcli安装ASM,重试5次均失败,Istiod Pod处于CrashLoopBackOff状态。

安装命令及失败输出

/usr/local/bin/asmcli install --fleet_id grv-xyz  --kubeconfig xxx/xxx/.kube/config  --output_dir /home/piyush/testasm   --platform multicloud   --enable_all 
set 2 field(s) of setter "anthos.servicemesh.trustDomainAliases" to value "grv-1162.svc.id.goog"
namespace/istio-system labeled
asmcli: Installing validation webhook fix...
service/istiod created
asmcli: Installing ASM control plane...
asmcli: [WARNING]: Failed, retrying...(1 of 5)

Istiod Pod状态及错误日志

Pod状态:

kubectl get pods -n istio-system
NAME                                 READY   STATUS             RESTARTS      AGE
istiod-asm-1157-23-586f6658b-g4zkh   0/1     CrashLoopBackOff   6 (73s ago)   7m10s
istiod-asm-1157-23-586f6658b-vgxvn   0/1     CrashLoopBackOff   6 (86s ago)   7m25s

关键错误日志:

2024-01-08T19:38:24.032740Z info    done initializing workload trustBundle
2024-01-08T19:38:24.032754Z info    initializing Istiod DNS certificates host: istiod-asm-1157-23.istio-system.svc, custom host:
2024-01-08T19:38:24.032762Z info    Generating K8S-signed cert for [istiod-asm-1157-23.istio-system.svc istiod.istio-system.svc istiod-remote.istio-system.svc istio-pilot.istio-system.svc]
2024-01-08T19:38:24.333489Z error   retry attempts exceeded when creating csr request csr-workload-r9z598s2kgzg9m87kw
Error: failed to create discovery service: failed generating key and cert by kubernetes: unable to submit CSR request (). Error: admission webhook "gkepolicy.common-webhooks.networking.gke.io" denied the request: GKE Policy Controller rejected the request because it violates one or more policies: {"[denied by autogke-csr-limitation]":["CSR 'csr-workload-r9z598s2kgzg9m87kw' disallowed in Autopilot."]}
2024-01-08T19:38:24.333534Z error   failed to create discovery service: failed generating key and cert by kubernetes: unable to submit CSR request (). Error: admission webhook "gkepolicy.common-webhooks.networking.gke.io" denied the request: GKE Policy Controller rejected the request because it violates one or more policies: {"[denied by autogke-csr-limitation]":["CSR 'csr-workload-r9z598s2kgzg9m87kw' disallowed in Autopilot."]}

核心结论与解决方案

  1. GDCE对ASM的支持性
    GDCE集群支持安装ASM,当前失败并非源于平台不兼容,而是集群的GKE Policy Controller策略拦截了CSR请求。

  2. 错误原因分析
    日志中autogke-csr-limitation策略拒绝了Istiod生成的CSR,该策略专为GKE Autopilot集群设计,不适用于GDCE本地边缘集群,导致证书生成失败,Istiod无法正常启动。

  3. 修复步骤

  • 禁用不适用的Policy Controller策略
    查看集群中已启用的约束策略,找到autogke-csr-limitation相关约束并删除:

    kubectl get constraints -n gke-system
    kubectl delete constraint <autogke-csr-limitation-constraint-name> -n gke-system
    

    也可通过修改Policy Controller配置,排除该策略在GDCE集群上的应用。

  • 调整ASM安装参数
    将安装命令中的--platform multicloud替换为--platform other,更贴合GDCE本地边缘集群的类型:

    /usr/local/bin/asmcli install --fleet_id grv-xyz  --kubeconfig xxx/xxx/.kube/config  --output_dir /home/piyush/testasm   --platform other   --enable_all 
    
  • 验证权限
    确保执行安装操作的账号拥有以下权限:

    • 创建和批准CSR的权限
    • 在istio-system命名空间下管理资源的权限
  • 手动批准CSR(临时方案)
    若策略调整后仍有问题,可手动批准Istiod生成的CSR:

    kubectl certificate approve csr-workload-r9z598s2kgzg9m87kw
    

内容的提问来源于stack exchange,提问作者user23215058

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 17:10:23