使用Terraform无法为AWS EKS添加节点组,请求排查
AWS EKS工作节点组创建失败问题
问题描述
我编写了如下main.tf Terraform配置文件:
provider "aws" { region = "ca-central-1" access_key = "***" secret_key = "***" } resource "aws_iam_account_alias" "alias" { account_alias = "***" } resource "aws_budgets_budget" "eks" { name = "aws-eks" budget_type = "COST" limit_amount = "30" limit_unit = "USD" time_period_end = "2087-06-15_00:00" time_period_start = "2017-07-01_00:00" time_unit = "MONTHLY" notification { comparison_operator = "GREATER_THAN" threshold = 80 threshold_type = "PERCENTAGE" notification_type = "FORECASTED" subscriber_email_addresses = ["amin.bamavadat@gmail.com"] } } resource "aws_vpc" "main" { cidr_block = "10.0.0.0/16" tags = { Name = "main" } } variable "public_subnet_cidrs" { type = list(string) description = "Public Subnet CIDR values" default = ["10.0.1.0/24", "10.0.2.0/24", "10.0.3.0/24"] } variable "private_subnet_cidrs" { type = list(string) description = "Private Subnet CIDR values" default = ["10.0.4.0/24", "10.0.5.0/24", "10.0.6.0/24"] } variable "azs" { type = list(string) description = "Availability Zones" default = ["ca-central-1a", "ca-central-1b", "ca-central-1d"] } resource "aws_subnet" "public_subnets" { count = length(var.public_subnet_cidrs) vpc_id = aws_vpc.main.id cidr_block = element(var.public_subnet_cidrs, count.index) availability_zone = element(var.azs, count.index) tags = { Name = "Public Subnet ${count.index + 1}" } } resource "aws_subnet" "private_subnets" { count = length(var.private_subnet_cidrs) vpc_id = aws_vpc.main.id cidr_block = element(var.private_subnet_cidrs, count.index) availability_zone = element(var.azs, count.index) tags = { Name = "Private Subnet ${count.index + 1}" } } resource "aws_internet_gateway" "gw" { vpc_id = aws_vpc.main.id tags = { Name = "main VPC IG" } } resource "aws_route_table" "second_rt" { vpc_id = aws_vpc.main.id route { cidr_block = "0.0.0.0/0" gateway_id = aws_internet_gateway.gw.id } tags = { Name = "2nd Route Table" } } resource "aws_route_table_association" "public_subnet_asso" { count = length(var.public_subnet_cidrs) subnet_id = element(aws_subnet.public_subnets[*].id, count.index) route_table_id = aws_route_table.second_rt.id } data "aws_iam_policy_document" "eks_assume_role_policy" { version = "2012-10-17" statement { actions = ["sts:AssumeRole"] effect = "Allow" principals { type = "Service" identifiers = ["eks.amazonaws.com"] } } } resource "aws_iam_role" "eks-iam-role" { name = "eks-iam-role" path = "/" assume_role_policy = data.aws_iam_policy_document.eks_assume_role_policy.json } data "aws_iam_policy_document" "eks_workerodes_assume_role_policy" { version = "2012-10-17" statement { actions = ["sts:AssumeRole"] effect = "Allow" principals { type = "Service" identifiers = ["ec2.amazonaws.com"] } } } resource "aws_iam_role" "eks-workernodes-iam-role" { name = "eks-workernodes-iam-role" path = "/" assume_role_policy = data.aws_iam_policy_document.eks_workerodes_assume_role_policy.json } resource "aws_iam_role_policy_attachment" "AmazonEKSClusterPolicy" { policy_arn = "arn:aws:iam::aws:policy/AmazonEKSClusterPolicy" role = aws_iam_role.eks-iam-role.name } resource "aws_iam_role_policy_attachment" "AmazonEC2ContainerRegistryReadOnly-EKS" { policy_arn = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly" role = aws_iam_role.eks-iam-role.name } resource "aws_iam_role_policy_attachment" "AmazonEKSWorkerNodePolicy" { policy_arn = "arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy" role = aws_iam_role.eks-workernodes-iam-role.name } resource "aws_iam_role_policy_attachment" "AmazonEKS_CNI_Policy" { policy_arn = "arn:aws:iam::aws:policy/AmazonEKS_CNI_Policy" role = aws_iam_role.eks-workernodes-iam-role.name } resource "aws_iam_role_policy_attachment" "EC2InstanceProfileForImageBuilderECRContainerBuilds" { policy_arn = "arn:aws:iam::aws:policy/EC2InstanceProfileForImageBuilderECRContainerBuilds" role = aws_iam_role.eks-workernodes-iam-role.name } resource "aws_iam_role_policy_attachment" "AmazonEC2ContainerRegistryReadOnly" { policy_arn = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly" role = aws_iam_role.eks-workernodes-iam-role.name } resource "aws_eks_cluster" "eks-cluster" { name = "eks-cluster" role_arn = aws_iam_role.eks-iam-role.arn vpc_config { subnet_ids = [ for subnet in aws_subnet.private_subnets: subnet.id ] } depends_on = [ aws_iam_role.eks-iam-role ] } resource "aws_eks_node_group" "worker-node-group" { cluster_name = aws_eks_cluster.eks-cluster.name node_group_name = "workernodes" node_role_arn = aws_iam_role.eks-workernodes-iam-role.arn subnet_ids = [ for subnet in aws_subnet.private_subnets: subnet.id ] instance_types = ["t3.small"] scaling_config { desired_size = 1 max_size = 1 min_size = 1 } depends_on = [ aws_iam_role_policy_attachment.AmazonEKSWorkerNodePolicy, aws_iam_role_policy_attachment.AmazonEKS_CNI_Policy, ] }
执行该配置后,所有资源均已创建完成,但工作节点组无法加入AWS EKS集群。
执行日志
aws_iam_account_alias.alias: Creation complete after 0s [id=aminbaa] aws_iam_role.eks-iam-role: Creation complete after 0s [id=eks-iam-role] aws_iam_role.eks-workernodes-iam-role: Creation complete after 0s [id=eks-workernodes-iam-role] aws_iam_role_policy_attachment.AmazonEC2ContainerRegistryReadOnly-EKS: Creation complete after 0s [id=eks-iam-role-20231111115059381300000001] aws_iam_role_policy_attachment.AmazonEKSWorkerNodePolicy: Creation complete after 1s [id=eks-workernodes-iam-role-20231111115059512800000003] aws_iam_role_policy_attachment.AmazonEKSClusterPolicy: Creation complete after 1s [id=eks-iam-role-20231111115059452500000002] aws_iam_role_policy_attachment.AmazonEC2ContainerRegistryReadOnly: Creation complete after 1s [id=eks-workernodes-iam-role-20231111115059556700000004] aws_budgets_budget.eks: Creation complete after 1s [id=218169265088:aws-eks] aws_iam_role_policy_attachment.AmazonEKS_CNI_Policy: Creation complete after 1s [id=eks-workernodes-iam-role-20231111115059616900000005] aws_iam_role_policy_attachment.EC2InstanceProfileForImageBuilderECRContainerBuilds: Creation complete after 1s [id=eks-workernodes-iam-role-20231111115059660100000006] aws_vpc.main: Creation complete after 1s [id=vpc-0efba82ca7a4ae813] aws_internet_gateway.gw: Creation complete after 1s [id=igw-05440653f44ed7e5f] aws_subnet.public_subnets[0]: Creation complete after 1s [id=subnet-06d7bbbc77f59954f] aws_subnet.private_subnets[0]: Creation complete after 1s [id=subnet-09592afd45f49ca61] aws_subnet.public_subnets[1]: Creation complete after 1s [id=subnet-031827712d9765202] aws_subnet.public_subnets[2]: Creation complete after 1s [id=subnet-0e1a424a7f656c6ba] aws_subnet.private_subnets[1]: Creation complete after 1s [id=subnet-0a386d8d241420598] aws_subnet.private_subnets[2]: Creation complete after 1s [id=subnet-0626a52464d4ed26e] aws_route_table.second_rt: Creation complete after 0s [id=rtb-09d079b731f773ccb] aws_route_table_association.public_subnet_asso[1]: Creation complete after 1s [id=rtbassoc-0faa40c0eadfedbd2] aws_route_table_association.public_subnet_asso[0]: Creation complete after 1s [id=rtbassoc-0b416eecd9c95200a] aws_route_table_association.public_subnet_asso[2]: Creation complete after 1s [id=rtbassoc-083007a4aea0f99a2] aws_eks_cluster.eks-cluster: Creation complete after 7m11s [id=eks-cluster] aws_eks_node_group.worker-node-group: Creating... aws_eks_node_group.worker-node-group: Still creating... [23m40s elapsed] ╷ │ Error: waiting for EKS Node Group (eks-cluster:workernodes) to create: unexpected state 'CREATE_FAILED', wanted target 'ACTIVE'. last error: 1 error occurred: │ * i-089cdb74d5bd0b72d: NodeCreationFailure: Instances failed to join the kubernetes cluster │ │ │ │ with aws_eks_node_group.worker-node-group, │ on main.tf line 169, in resource "aws_eks_node_group" "worker-node-group": │ 169: resource "aws_eks_node_group" "worker-node-group" {
排查方向与解决方法
- 私有子网无互联网访问路径:工作节点部署在私有子网,但当前配置中私有子网未关联带NAT网关的路由表,节点无法下载EKS所需镜像和配置文件。需创建NAT网关,并为私有子网配置包含NAT网关的路由表,让私有子网流量通过NAT网关访问互联网。
- EKS集群端点访问配置问题:检查EKS集群的VPC配置,确认是否开启公共/私有端点访问。若仅启用私有端点,需确保节点能访问EKS集群端点地址,可配置VPC端点或调整安全组规则。
- 安全组规则限制:默认EKS节点组会自动创建安全组,若自定义安全组,需确保节点安全组允许与EKS控制平面的443端口通信,以及节点间的必要通信。
- IAM角色权限同步问题:虽然已附加必要策略,但需确认
eks-workernodes-iam-role的信任策略正确,且策略已完全生效(策略附加后可能需要短暂同步时间)。
内容的提问来源于stack exchange,提问作者Amin Ba
相关产品推荐
相关产品推荐

