You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform无法为AWS EKS添加节点组,请求排查

AWS EKS工作节点组创建失败问题

问题描述

我编写了如下main.tf Terraform配置文件:

provider "aws" {
    region = "ca-central-1"
    access_key = "***"
    secret_key = "***"
}

resource "aws_iam_account_alias" "alias" {
  account_alias = "***"
}


resource "aws_budgets_budget" "eks" {
  name              = "aws-eks"
  budget_type       = "COST"
  limit_amount      = "30"
  limit_unit        = "USD"
  time_period_end   = "2087-06-15_00:00"
  time_period_start = "2017-07-01_00:00"
  time_unit         = "MONTHLY"

  notification {
    comparison_operator        = "GREATER_THAN"
    threshold                  = 80
    threshold_type             = "PERCENTAGE"
    notification_type          = "FORECASTED"
    subscriber_email_addresses = ["amin.bamavadat@gmail.com"]
  }
}

resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
  tags = {
    Name = "main"
  }
}

variable "public_subnet_cidrs" {
 type        = list(string)
 description = "Public Subnet CIDR values"
 default     = ["10.0.1.0/24", "10.0.2.0/24", "10.0.3.0/24"]
}
variable "private_subnet_cidrs" {
 type        = list(string)
 description = "Private Subnet CIDR values"
 default     = ["10.0.4.0/24", "10.0.5.0/24", "10.0.6.0/24"]
}

variable "azs" {
 type        = list(string)
 description = "Availability Zones"
 default     = ["ca-central-1a", "ca-central-1b", "ca-central-1d"]
}
resource "aws_subnet" "public_subnets" {
 count      = length(var.public_subnet_cidrs)
 vpc_id     = aws_vpc.main.id
 cidr_block = element(var.public_subnet_cidrs, count.index)
 availability_zone = element(var.azs, count.index)
 tags = {
   Name = "Public Subnet ${count.index + 1}"
 }
}
resource "aws_subnet" "private_subnets" {
 count      = length(var.private_subnet_cidrs)
 vpc_id     = aws_vpc.main.id
 cidr_block = element(var.private_subnet_cidrs, count.index)
 availability_zone = element(var.azs, count.index)
 tags = {
   Name = "Private Subnet ${count.index + 1}"
 }
}

resource "aws_internet_gateway" "gw" {
 vpc_id = aws_vpc.main.id
 tags = {
   Name = "main VPC IG"
 }
}

resource "aws_route_table" "second_rt" {
 vpc_id = aws_vpc.main.id
 route {
   cidr_block = "0.0.0.0/0"
   gateway_id = aws_internet_gateway.gw.id
 }
 tags = {
   Name = "2nd Route Table"
 }
}

resource "aws_route_table_association" "public_subnet_asso" {
 count = length(var.public_subnet_cidrs)
 subnet_id      = element(aws_subnet.public_subnets[*].id, count.index)
 route_table_id = aws_route_table.second_rt.id
}

data "aws_iam_policy_document" "eks_assume_role_policy" {
  version = "2012-10-17"
  statement {
    actions = ["sts:AssumeRole"]
    effect = "Allow"
    principals {
      type        = "Service"
      identifiers = ["eks.amazonaws.com"]
    }
  }
}
resource "aws_iam_role" "eks-iam-role" {
 name = "eks-iam-role"
 path = "/"
 assume_role_policy = data.aws_iam_policy_document.eks_assume_role_policy.json
}

data "aws_iam_policy_document" "eks_workerodes_assume_role_policy" {
  version = "2012-10-17"
  statement {
    actions = ["sts:AssumeRole"]
    effect = "Allow"
    principals {
      type        = "Service"
      identifiers = ["ec2.amazonaws.com"]
    }
  }
}
resource "aws_iam_role" "eks-workernodes-iam-role" {
 name = "eks-workernodes-iam-role"
 path = "/"
 assume_role_policy = data.aws_iam_policy_document.eks_workerodes_assume_role_policy.json
}


resource "aws_iam_role_policy_attachment" "AmazonEKSClusterPolicy" {
 policy_arn = "arn:aws:iam::aws:policy/AmazonEKSClusterPolicy"
 role    = aws_iam_role.eks-iam-role.name
}
resource "aws_iam_role_policy_attachment" "AmazonEC2ContainerRegistryReadOnly-EKS" {
 policy_arn = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly"
 role    = aws_iam_role.eks-iam-role.name
}
resource "aws_iam_role_policy_attachment" "AmazonEKSWorkerNodePolicy" {
policy_arn = "arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy"
role    = aws_iam_role.eks-workernodes-iam-role.name
}
resource "aws_iam_role_policy_attachment" "AmazonEKS_CNI_Policy" {
policy_arn = "arn:aws:iam::aws:policy/AmazonEKS_CNI_Policy"
role    = aws_iam_role.eks-workernodes-iam-role.name
}
resource "aws_iam_role_policy_attachment" "EC2InstanceProfileForImageBuilderECRContainerBuilds" {
policy_arn = "arn:aws:iam::aws:policy/EC2InstanceProfileForImageBuilderECRContainerBuilds"
role    = aws_iam_role.eks-workernodes-iam-role.name
}
resource "aws_iam_role_policy_attachment" "AmazonEC2ContainerRegistryReadOnly" {
policy_arn = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly"
role    = aws_iam_role.eks-workernodes-iam-role.name
}

resource "aws_eks_cluster" "eks-cluster" {
 name = "eks-cluster"
 role_arn = aws_iam_role.eks-iam-role.arn

 vpc_config {
  subnet_ids = [ for subnet in aws_subnet.private_subnets: subnet.id ]
 }

 depends_on = [
  aws_iam_role.eks-iam-role
 ]
}

resource "aws_eks_node_group" "worker-node-group" {
  cluster_name  = aws_eks_cluster.eks-cluster.name
  node_group_name = "workernodes"
  node_role_arn  = aws_iam_role.eks-workernodes-iam-role.arn
  subnet_ids   = [ for subnet in aws_subnet.private_subnets: subnet.id ]
  instance_types = ["t3.small"]
 
  scaling_config {
   desired_size = 1
   max_size   = 1
   min_size   = 1
  }
 
  depends_on = [
   aws_iam_role_policy_attachment.AmazonEKSWorkerNodePolicy,
   aws_iam_role_policy_attachment.AmazonEKS_CNI_Policy,
  ]
 }

执行该配置后,所有资源均已创建完成,但工作节点组无法加入AWS EKS集群。

执行日志

aws_iam_account_alias.alias: Creation complete after 0s [id=aminbaa]
aws_iam_role.eks-iam-role: Creation complete after 0s [id=eks-iam-role]
aws_iam_role.eks-workernodes-iam-role: Creation complete after 0s [id=eks-workernodes-iam-role]
aws_iam_role_policy_attachment.AmazonEC2ContainerRegistryReadOnly-EKS: Creation complete after 0s [id=eks-iam-role-20231111115059381300000001]
aws_iam_role_policy_attachment.AmazonEKSWorkerNodePolicy: Creation complete after 1s [id=eks-workernodes-iam-role-20231111115059512800000003]
aws_iam_role_policy_attachment.AmazonEKSClusterPolicy: Creation complete after 1s [id=eks-iam-role-20231111115059452500000002]
aws_iam_role_policy_attachment.AmazonEC2ContainerRegistryReadOnly: Creation complete after 1s [id=eks-workernodes-iam-role-20231111115059556700000004]
aws_budgets_budget.eks: Creation complete after 1s [id=218169265088:aws-eks]
aws_iam_role_policy_attachment.AmazonEKS_CNI_Policy: Creation complete after 1s [id=eks-workernodes-iam-role-20231111115059616900000005]
aws_iam_role_policy_attachment.EC2InstanceProfileForImageBuilderECRContainerBuilds: Creation complete after 1s [id=eks-workernodes-iam-role-20231111115059660100000006]
aws_vpc.main: Creation complete after 1s [id=vpc-0efba82ca7a4ae813]
aws_internet_gateway.gw: Creation complete after 1s [id=igw-05440653f44ed7e5f]
aws_subnet.public_subnets[0]: Creation complete after 1s [id=subnet-06d7bbbc77f59954f]
aws_subnet.private_subnets[0]: Creation complete after 1s [id=subnet-09592afd45f49ca61]
aws_subnet.public_subnets[1]: Creation complete after 1s [id=subnet-031827712d9765202]
aws_subnet.public_subnets[2]: Creation complete after 1s [id=subnet-0e1a424a7f656c6ba]
aws_subnet.private_subnets[1]: Creation complete after 1s [id=subnet-0a386d8d241420598]
aws_subnet.private_subnets[2]: Creation complete after 1s [id=subnet-0626a52464d4ed26e]
aws_route_table.second_rt: Creation complete after 0s [id=rtb-09d079b731f773ccb]
aws_route_table_association.public_subnet_asso[1]: Creation complete after 1s [id=rtbassoc-0faa40c0eadfedbd2]
aws_route_table_association.public_subnet_asso[0]: Creation complete after 1s [id=rtbassoc-0b416eecd9c95200a]
aws_route_table_association.public_subnet_asso[2]: Creation complete after 1s [id=rtbassoc-083007a4aea0f99a2]
aws_eks_cluster.eks-cluster: Creation complete after 7m11s [id=eks-cluster]
aws_eks_node_group.worker-node-group: Creating...
        
aws_eks_node_group.worker-node-group: Still creating... [23m40s elapsed]
╷
│ Error: waiting for EKS Node Group (eks-cluster:workernodes) to create: unexpected state 'CREATE_FAILED', wanted target 'ACTIVE'. last error: 1 error occurred:
│       * i-089cdb74d5bd0b72d: NodeCreationFailure: Instances failed to join the kubernetes cluster
│
│
│
│   with aws_eks_node_group.worker-node-group,
│   on main.tf line 169, in resource "aws_eks_node_group" "worker-node-group":
│  169: resource "aws_eks_node_group" "worker-node-group" {

排查方向与解决方法

  • 私有子网无互联网访问路径:工作节点部署在私有子网,但当前配置中私有子网未关联带NAT网关的路由表,节点无法下载EKS所需镜像和配置文件。需创建NAT网关,并为私有子网配置包含NAT网关的路由表,让私有子网流量通过NAT网关访问互联网。
  • EKS集群端点访问配置问题:检查EKS集群的VPC配置,确认是否开启公共/私有端点访问。若仅启用私有端点,需确保节点能访问EKS集群端点地址,可配置VPC端点或调整安全组规则。
  • 安全组规则限制:默认EKS节点组会自动创建安全组,若自定义安全组,需确保节点安全组允许与EKS控制平面的443端口通信,以及节点间的必要通信。
  • IAM角色权限同步问题:虽然已附加必要策略,但需确认eks-workernodes-iam-role的信任策略正确,且策略已完全生效(策略附加后可能需要短暂同步时间)。

内容的提问来源于stack exchange,提问作者Amin Ba

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 21:07:02