You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes上JupyterHub闲置Pod清理功能失效问题排查

JupyterHub闲置Pod清理功能失效(403 Forbidden错误排查与解决)

问题概述

在VMware虚拟机搭建的本地Kubernetes集群上,通过Helm Chart部署JupyterHub后,闲置用户Pod自动清理功能无法生效,Hub Pod日志中出现403权限错误。

错误日志

[W 2023-11-09 01:12:59.125 JupyterHub log:191] 403 GET /hub/api/users?state=[secret] (jupyterhub-idle-culler@127.0.0.1) 6.40ms
[E 231109 01:12:59 ioloop:923] Exception in callback functools.partial(<function cull_idle at 0x7f8cc77975e0>, url='http://localhost:8081/hub/api', api_token='1b66576c8caa43a9ae64cb419f9bf1f0', inactive_limit=3600, cull_users=False, remove_named_servers=False, max_age=0, concurrency=10, ssl_enabled=False, internal_certs_location='internal-ssl', cull_admin_users=True, api_page_size=0)
    Traceback (most recent call last):
      File "/usr/local/lib/python3.9/site-packages/tornado/ioloop.py", line 921, in _run
        await val
      File "/usr/local/lib/python3.9/site-packages/jupyterhub_idle_culler/__init__.py", line 422, in cull_idle
        async for user in fetch_paginated(req):
      File "/usr/local/lib/python3.9/site-packages/jupyterhub_idle_culler/__init__.py", line 135, in fetch_paginated
        response = await resp_future
      File "/usr/local/lib/python3.9/site-packages/jupyterhub_idle_culler/__init__.py", line 117, in fetch
        return await client.fetch(req)
    tornado.httpclient.HTTPClientError: HTTP 403: Forbidden

环境版本

  • Kubernetes版本:1.23
  • Helm JupyterHub Chart版本:3.1.1
  • JupyterHub版本:4.0.2

配置文件

singleuser:
  storage:
    capacity: 1Gi
    dynamic:
      storageClass: jhub-nas
  extraFiles:
    mountPath: /etc/jupyter/jupyter_notebook_config.json
    data:
      TerminalManager:
        cull_inactive_timeout: 300
        cull_interval: 60
      MappingKernelManager:
        cull_idle_timeout: 300
        cull_interval: 60
        cull_connected: true
        cull_busy: false

hub:
  service:
    type: LoadBalancer
  db:
    type: sqlite-pvc
    pvc:
      storage: 10Gi
      storageClassName: jhub-nas
cull:
  enabled: true
  timeout: 300 
  every: 60

解决步骤

1. 确认Cull配置是否正确加载

日志中显示inactive_limit=3600(默认值),但配置文件中设置的是cull.timeout=300,说明配置未正确生效。执行以下命令验证cull Pod的环境变量:

kubectl exec -n jhub-ns $(kubectl get pods -n jhub-ns -l app=jupyterhub,component=cull -o jsonpath='{.items[0].metadata.name}') -- env | grep INACTIVE_LIMIT

如果输出为3600,则重新执行Helm升级确保配置生效:

helm upgrade jhub jupyterhub/jupyterhub -n jhub-ns --values config.yaml

2. 修复403权限错误

403错误是因为idle-culler组件使用的API Token没有访问Hub /hub/api/users接口的权限,按以下步骤排查:

  • 检查cull组件的ServiceAccount权限绑定:
    kubectl describe clusterrole jhub-cull -n jhub-ns
    kubectl describe clusterrolebinding jhub-cull -n jhub-ns
    
    确保ClusterRole包含访问Hub API的权限,ClusterRoleBinding正确绑定到cull的ServiceAccount。
  • 检查Hub的配置是否包含cull服务的权限声明:
    kubectl get configmap jhub-hub-config -n jhub-ns -o yaml
    
    确认services字段下存在cull的配置且admin: true:
    services:
      cull:
        api_token: <你的token值>
        admin: true
    
    若缺失,重新部署Helm Chart即可自动生成该配置。

3. 区分内核清理与Pod清理

注意:你在singleuser.extraFiles中配置的是内核/终端的闲置清理,仅会关闭闲置的内核或终端,不会删除用户Pod;而Pod级别的闲置清理由cull组件负责,对应配置文件中的cull字段,两者是独立功能,不要混淆。

内容的提问来源于stack exchange,提问作者Lyudmila Sun

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 16:58:22