能否在GDCE本地集群安装Anthos Service Mesh?安装失败求助
能否在Google本地云边缘集群(GDCE)上安装Anthos Service Mesh(ASM)?
问题背景
尝试在本地GDCE服务器上通过asmcli安装ASM,重试5次均失败,Istiod Pod处于CrashLoopBackOff状态。
安装命令及失败输出
/usr/local/bin/asmcli install --fleet_id grv-xyz --kubeconfig xxx/xxx/.kube/config --output_dir /home/piyush/testasm --platform multicloud --enable_all set 2 field(s) of setter "anthos.servicemesh.trustDomainAliases" to value "grv-1162.svc.id.goog" namespace/istio-system labeled asmcli: Installing validation webhook fix... service/istiod created asmcli: Installing ASM control plane... asmcli: [WARNING]: Failed, retrying...(1 of 5)
Istiod Pod状态及错误日志
Pod状态:
kubectl get pods -n istio-system NAME READY STATUS RESTARTS AGE istiod-asm-1157-23-586f6658b-g4zkh 0/1 CrashLoopBackOff 6 (73s ago) 7m10s istiod-asm-1157-23-586f6658b-vgxvn 0/1 CrashLoopBackOff 6 (86s ago) 7m25s
关键错误日志:
2024-01-08T19:38:24.032740Z info done initializing workload trustBundle 2024-01-08T19:38:24.032754Z info initializing Istiod DNS certificates host: istiod-asm-1157-23.istio-system.svc, custom host: 2024-01-08T19:38:24.032762Z info Generating K8S-signed cert for [istiod-asm-1157-23.istio-system.svc istiod.istio-system.svc istiod-remote.istio-system.svc istio-pilot.istio-system.svc] 2024-01-08T19:38:24.333489Z error retry attempts exceeded when creating csr request csr-workload-r9z598s2kgzg9m87kw Error: failed to create discovery service: failed generating key and cert by kubernetes: unable to submit CSR request (). Error: admission webhook "gkepolicy.common-webhooks.networking.gke.io" denied the request: GKE Policy Controller rejected the request because it violates one or more policies: {"[denied by autogke-csr-limitation]":["CSR 'csr-workload-r9z598s2kgzg9m87kw' disallowed in Autopilot."]} 2024-01-08T19:38:24.333534Z error failed to create discovery service: failed generating key and cert by kubernetes: unable to submit CSR request (). Error: admission webhook "gkepolicy.common-webhooks.networking.gke.io" denied the request: GKE Policy Controller rejected the request because it violates one or more policies: {"[denied by autogke-csr-limitation]":["CSR 'csr-workload-r9z598s2kgzg9m87kw' disallowed in Autopilot."]}
核心结论与解决方案
GDCE对ASM的支持性
GDCE集群支持安装ASM,当前失败并非源于平台不兼容,而是集群的GKE Policy Controller策略拦截了CSR请求。错误原因分析
日志中autogke-csr-limitation策略拒绝了Istiod生成的CSR,该策略专为GKE Autopilot集群设计,不适用于GDCE本地边缘集群,导致证书生成失败,Istiod无法正常启动。修复步骤
禁用不适用的Policy Controller策略
查看集群中已启用的约束策略,找到autogke-csr-limitation相关约束并删除:kubectl get constraints -n gke-system kubectl delete constraint <autogke-csr-limitation-constraint-name> -n gke-system也可通过修改Policy Controller配置,排除该策略在GDCE集群上的应用。
调整ASM安装参数
将安装命令中的--platform multicloud替换为--platform other,更贴合GDCE本地边缘集群的类型:/usr/local/bin/asmcli install --fleet_id grv-xyz --kubeconfig xxx/xxx/.kube/config --output_dir /home/piyush/testasm --platform other --enable_all验证权限
确保执行安装操作的账号拥有以下权限:- 创建和批准CSR的权限
- 在
istio-system命名空间下管理资源的权限
手动批准CSR(临时方案)
若策略调整后仍有问题,可手动批准Istiod生成的CSR:kubectl certificate approve csr-workload-r9z598s2kgzg9m87kw
内容的提问来源于stack exchange,提问作者user23215058
相关产品推荐
相关产品推荐

