Kubernetes上JupyterHub闲置Pod清理功能失效问题排查
JupyterHub闲置Pod清理功能失效(403 Forbidden错误排查与解决)
问题概述
在VMware虚拟机搭建的本地Kubernetes集群上,通过Helm Chart部署JupyterHub后,闲置用户Pod自动清理功能无法生效,Hub Pod日志中出现403权限错误。
错误日志
[W 2023-11-09 01:12:59.125 JupyterHub log:191] 403 GET /hub/api/users?state=[secret] (jupyterhub-idle-culler@127.0.0.1) 6.40ms [E 231109 01:12:59 ioloop:923] Exception in callback functools.partial(<function cull_idle at 0x7f8cc77975e0>, url='http://localhost:8081/hub/api', api_token='1b66576c8caa43a9ae64cb419f9bf1f0', inactive_limit=3600, cull_users=False, remove_named_servers=False, max_age=0, concurrency=10, ssl_enabled=False, internal_certs_location='internal-ssl', cull_admin_users=True, api_page_size=0) Traceback (most recent call last): File "/usr/local/lib/python3.9/site-packages/tornado/ioloop.py", line 921, in _run await val File "/usr/local/lib/python3.9/site-packages/jupyterhub_idle_culler/__init__.py", line 422, in cull_idle async for user in fetch_paginated(req): File "/usr/local/lib/python3.9/site-packages/jupyterhub_idle_culler/__init__.py", line 135, in fetch_paginated response = await resp_future File "/usr/local/lib/python3.9/site-packages/jupyterhub_idle_culler/__init__.py", line 117, in fetch return await client.fetch(req) tornado.httpclient.HTTPClientError: HTTP 403: Forbidden
环境版本
- Kubernetes版本:1.23
- Helm JupyterHub Chart版本:3.1.1
- JupyterHub版本:4.0.2
配置文件
singleuser: storage: capacity: 1Gi dynamic: storageClass: jhub-nas extraFiles: mountPath: /etc/jupyter/jupyter_notebook_config.json data: TerminalManager: cull_inactive_timeout: 300 cull_interval: 60 MappingKernelManager: cull_idle_timeout: 300 cull_interval: 60 cull_connected: true cull_busy: false hub: service: type: LoadBalancer db: type: sqlite-pvc pvc: storage: 10Gi storageClassName: jhub-nas cull: enabled: true timeout: 300 every: 60
解决步骤
1. 确认Cull配置是否正确加载
日志中显示inactive_limit=3600(默认值),但配置文件中设置的是cull.timeout=300,说明配置未正确生效。执行以下命令验证cull Pod的环境变量:
kubectl exec -n jhub-ns $(kubectl get pods -n jhub-ns -l app=jupyterhub,component=cull -o jsonpath='{.items[0].metadata.name}') -- env | grep INACTIVE_LIMIT
如果输出为3600,则重新执行Helm升级确保配置生效:
helm upgrade jhub jupyterhub/jupyterhub -n jhub-ns --values config.yaml
2. 修复403权限错误
403错误是因为idle-culler组件使用的API Token没有访问Hub /hub/api/users接口的权限,按以下步骤排查:
- 检查cull组件的ServiceAccount权限绑定:
确保ClusterRole包含访问Hub API的权限,ClusterRoleBinding正确绑定到cull的ServiceAccount。kubectl describe clusterrole jhub-cull -n jhub-ns kubectl describe clusterrolebinding jhub-cull -n jhub-ns - 检查Hub的配置是否包含cull服务的权限声明:
确认kubectl get configmap jhub-hub-config -n jhub-ns -o yamlservices字段下存在cull的配置且admin: true:
若缺失,重新部署Helm Chart即可自动生成该配置。services: cull: api_token: <你的token值> admin: true
3. 区分内核清理与Pod清理
注意:你在singleuser.extraFiles中配置的是内核/终端的闲置清理,仅会关闭闲置的内核或终端,不会删除用户Pod;而Pod级别的闲置清理由cull组件负责,对应配置文件中的cull字段,两者是独立功能,不要混淆。
内容的提问来源于stack exchange,提问作者Lyudmila Sun
相关产品推荐
相关产品推荐

