You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Pod内运行Tekton CLI无法找到已存在Pipeline的问题排查

在Kubernetes Pod中执行tkn命令无法找到Pipeline的排查与解决

问题概况

在test命名空间部署的Pod中执行tkn启动Pipeline时,报错无法找到已存在的postsync-pipeline;简化场景下执行tkn pipeline ls时,直接提示缺少Kubernetes配置。但本地使用相同命令可正常操作Tekton资源。

关键报错

  1. Pipeline不存在报错:

Error: Pipeline name postsync-pipeline does not exist in namespace test.

  1. Kube配置缺失报错:

Error: Couldn't get kubeConfiguration namespace: invalid configuration: no configuration has been provided, try setting KUBERNETES_MASTER environment variable

原因分析

  1. Pod缺少Kubernetes API访问凭证:默认情况下,Pod使用的default ServiceAccount未被正确配置集群访问凭证,导致tkn无法连接K8s API服务器。
  2. ServiceAccount权限不足:即使能连接API,default ServiceAccount没有访问Tekton资源(Pipeline、Task、PipelineRun等)的RBAC权限,无法读取或操作这些资源。

解决方案

步骤1:创建具备Tekton资源权限的ServiceAccount与RBAC规则

创建以下RBAC配置文件(tekton-rbac.yaml),为Pod分配足够的Tekton资源操作权限:

apiVersion: v1
kind: ServiceAccount
metadata:
  name: tekton-cluster-access
  namespace: test

---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: tekton-pipeline-admin
  namespace: test
rules:
- apiGroups: ["tekton.dev"]
  resources: ["pipelines", "tasks", "pipelineruns", "taskruns"]
  verbs: ["get", "list", "create", "update", "delete", "watch"]

---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: tekton-pipeline-admin-binding
  namespace: test
subjects:
- kind: ServiceAccount
  name: tekton-cluster-access
  namespace: test
roleRef:
  kind: Role
  name: tekton-pipeline-admin
  apiGroup: rbac.authorization.k8s.io

步骤2:修改Deployment使用授权后的ServiceAccount

更新原Deployment配置,指定使用上述创建的ServiceAccount,并建议使用官方Tekton CLI镜像:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: tkncli
  namespace: test
spec:
  replicas: 1
  selector:
    matchLabels:
      app: tkncli
  template:
    metadata:
      labels:
        app: tkncli
    spec:
      serviceAccountName: tekton-cluster-access # 绑定授权后的ServiceAccount
      containers:
        - name: tkncli
          image: quay.io/tektoncd/cli:latest # 使用官方Tekton CLI镜像
          imagePullPolicy: IfNotPresent
          command:
            - tkn
          args:
            - -n
            - test
            - pipeline
            - start
            - postsync-pipeline
            - --param
            - pause-duration="2"

验证步骤

  1. 应用RBAC配置:
kubectl apply -f tekton-rbac.yaml -n test
  1. 更新Deployment:
kubectl apply -f updated-tkn-deployment.yaml -n test
  1. 进入Pod验证tkn命令是否正常:
# 查看Pod名称
kubectl get pods -n test
# 进入Pod执行命令
kubectl exec -it <tkncli-pod-name> -n test -- tkn pipeline list -n test

若能正常列出postsync-pipeline,说明配置生效。

额外排查点

  • 检查Pod是否正确挂载ServiceAccount凭证:
kubectl exec <tkncli-pod-name> -n test -- ls /var/run/secrets/kubernetes.io/serviceaccount/

应能看到token、ca.crt、namespace三个文件。

  • 验证ServiceAccount权限:
kubectl auth can-i get pipelines -n test --as=system:serviceaccount:test:tekton-cluster-access

返回yes表示权限配置正确。

内容的提问来源于stack exchange,提问作者tm1701

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 20:41:01