You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K8s创建PodSandBox失败:PF设备未找到问题求助

问题描述

K8s新手,本地搭建2节点minikube集群,从一个PF创建2个VF,希望为Pod配置多网卡并绑定单个VF。已部署SRIOV-CNI、sriov-network-device-plugin(节点已识别到2个可分配VF)及multus组件,但Pod启动失败,事件提示FailedCreatePodSandBox,具体错误为SRIOV-CNI加载配置失败,无法获取VF信息,提示**"PF network device not found"**。

环境配置

1. minikube集群信息

minikube profile list
|----------|-----------|---------|--------------|------|---------|---------|-------|--------|
| Profile  | VM Driver | Runtime |      IP      | Port | Version | Status  | Nodes | Active |
|----------|-----------|---------|--------------|------|---------|---------|-------|--------|
| minikube | docker    | docker  | 192.168.76.2 | 8443 | v1.27.4 | Running |     2 | *      |
|----------|-----------|---------|--------------|------|---------|---------|-------|--------|

2. VF配置信息

eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
    link/ether 0c:c4:7a:77:f9:80 brd ff:ff:ff:ff:ff:ff
    vf 0     link/ether 1e:4c:7c:6b:7d:0f brd ff:ff:ff:ff:ff:ff, spoof checking on, link-state auto, trust off, query_rss off
    vf 1     link/ether 9e:52:6e:e0:e9:07 brd ff:ff:ff:ff:ff:ff, spoof checking on, link-state auto, trust off, query_rss off

3. SRIOV设备插件ConfigMap配置片段

apiVersion: v1
kind: ConfigMap
metadata:
  name: sriovdp-config
  namespace: kube-system
data:
  config.json: |
    {
        "resourceList": [{
                "resourceName": "intel_sriov_netdevice",
                "selectors": {
                    "vendors": ["8086"],
                    "devices": ["15a8"],
                    "drivers": ["ixgbevf"]
                }
            }
    }

4. 组件运行状态

SRIOV设备插件Pod运行状态

k -n kube-system get pod -l app=sriovdp -o wide
NAME                                   READY   STATUS    RESTARTS   AGE     IP             NODE           NOMINATED NODE   READINESS GATES
kube-sriov-device-plugin-amd64-64bf7   1/1     Running   0          5h41m   192.168.76.2   minikube       <none>           <none>
kube-sriov-device-plugin-amd64-7knxh   1/1     Running   0          5h41m   192.168.76.3   minikube-m02   <none>           <none>

节点可分配VF数量

kubectl get node  minikube -o jsonpath='{.status.allocatable}' |jq -r '."intel.com/intel_sriov_netdevice"'
2

Multus组件运行状态

k get pod -l app=multus -A -o wide
NAMESPACE     NAME                   READY   STATUS    RESTARTS   AGE     IP             NODE           NOMINATED NODE   READINESS GATES
kube-system   kube-multus-ds-47zg5   1/1     Running   0          5h38m   192.168.76.2   minikube       <none>           <none>
kube-system   kube-multus-ds-rjrzn   1/1     Running   0          5h38m   192.168.76.3   minikube-m02   <none>           <none>
Pod错误日志
Events:
  Type     Reason                  Age                From               Message
  ----     ------                  ----               ----               -------
  Normal   Scheduled               15s                default-scheduler  Successfully assigned default/testpod1 to minikube-m02
  Normal   AddedInterface          14s                multus             Add eth0 [10.244.1.32/24] from kindnet
  Warning  FailedCreatePodSandBox  14s                kubelet            Failed to create pod sandbox: rpc error: code = Unknown desc = failed to set up sandbox container "0f5d4259dfaa0087fba50ee5c656050fc6af6c01430bdd820e0642fba9d384de" network for pod "testpod1": networkPlugin cni failed to set up pod "testpod1_default" network: plugin type="multus" name="multus-cni-network" failed (add): [default/testpod1/:sriov-network]: error adding container to network "sriov-network": SRIOV-CNI failed to load netconf: LoadConf(): failed to get VF information: "PF network device not found"
  Normal   AddedInterface          13s                multus             Add eth0 [10.244.1.33/24] from kindnet
  Warning  FailedCreatePodSandBox  12s                kubelet            Failed to create pod sandbox: rpc error: code = Unknown desc = failed to set up sandbox container "39c2cc9ceff18eb34fbd4f7b0746fd0807a3999fdcef6f8dd8487b43f812a31a" network for pod "testpod1": networkPlugin cni failed to set up pod "testpod1_default" network: plugin type="multus" name="multus-cni-network" failed (add): [default/testpod1/:sriov-network]: error adding container to network "sriov-network": SRIOV-CNI failed to load netconf: LoadConf(): failed to get VF information: "PF network device not found"
  Normal   AddedInterface          12s                multus             Add eth0 [10.244.1.34/24] from kindnet
  Warning  FailedCreatePodSandBox  11s                kubelet            Failed to create pod sandbox: rpc error: code = Unknown desc = failed to set up sandbox container "20fb94f524db27d3b1bcb0e743c925ddb6af038c9220de28cd84ec92215b0ab3" network for pod "testpod1": networkPlugin cni failed to set up pod "testpod1_default" network: plugin type="multus" name="multus-cni-network" failed (add): [default/testpod1/:sriov-network]: error adding container to network "sriov-network": SRIOV-CNI failed to load netconf: LoadConf(): failed to get VF information: "PF network device not found"
排查与解决方案

1. 修正SRIOV NetworkAttachmentDefinition配置

确保Multus引用的NetworkAttachmentDefinition正确指定PF设备及匹配参数,示例配置如下:

apiVersion: k8s.cni.cncf.io/v1
kind: NetworkAttachmentDefinition
metadata:
  name: sriov-network
spec:
  config: |-
    {
      "cniVersion": "0.3.1",
      "type": "sriov",
      "name": "sriov-network",
      "ipam": {
        "type": "host-local",
        "subnet": "10.56.217.0/24",
        "routes": [
          {
            "dst": "0.0.0.0/0"
          }
        ],
        "gateway": "10.56.217.1"
      },
      "pf": "eth0",
      "vendor": "8086",
      "deviceID": "15a8"
    }
  • 重点检查pf字段是否为节点上实际的PF设备名(此处为eth0),vendor和deviceID需与PF的PCI信息一致。

2. 完善SRIOV设备插件ConfigMap

在ConfigMap的selectors中添加pfNames字段,明确指定PF设备,帮助插件精准识别目标VF:

{
    "resourceList": [{
            "resourceName": "intel_sriov_netdevice",
            "selectors": {
                "vendors": ["8086"],
                "devices": ["15a8"],
                "drivers": ["ixgbevf"],
                "pfNames": ["eth0"]
            }
        }]
}

更新ConfigMap后,重启SRIOV设备插件Pod:

kubectl rollout restart daemonset kube-sriov-device-plugin-amd64 -n kube-system

3. 验证节点PF设备状态

在Pod调度的目标节点(minikube-m02)上执行以下命令:

  • 确认PF设备存在:ip link show eth0
  • 查看PF的PCI信息:lspci -nn | grep Ethernet,验证vendor ID为8086、device ID为15a8
  • 确认VF驱动绑定:ethtool -i eth0,PF驱动应为ixgbe(对应VF驱动ixgbevf)

4. 检查SRIOV-CNI权限配置

确保SRIOV-CNI的DaemonSet挂载了必要的节点目录(如/sys、/dev),并拥有CAP_NET_ADMIN等权限,典型的DaemonSet权限配置片段:

securityContext:
  capabilities:
    add: ["NET_ADMIN"]
  privileged: true
volumeMounts:
- name: host-sys
  mountPath: /sys
- name: host-dev
  mountPath: /dev
- name: host-etc
  mountPath: /etc/cni/net.d

内容的提问来源于stack exchange,提问作者Verma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 02:19:52