You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K3s上GitLab Runner报错ContainersNotInitialized:init-permissions容器未初始化

K3s上GitLab Runner配置导致Pod初始化失败的排查方向

问题描述

已创建好Pod,但构建日志出现报错,具体日志信息如下:

Running with gitlab-runner 16.3.0 (8ec04662)
  on gitlab-runner-679d6544d7-2cnnp -cU7jBwtk, system ID: r_FmvSLQ5mgJMU

Preparing the "kubernetes" executor
00:00
Using Kubernetes namespace: gitlab-runner
Using Kubernetes executor with image ubuntu:22.04 ...
Using attach strategy to execute scripts...

Preparing environment
00:06
Waiting for pod gitlab-runner/runner--cu7jbwtk-project-1-concurrent-0-qv72z26e to be running, status is Pending
Waiting for pod gitlab-runner/runner--cu7jbwtk-project-1-concurrent-0-qv72z26e to be running, status is Pending
    ContainersNotInitialized: "containers with incomplete status: [init-permissions]"
    PodFailed: ""
    PodFailed: ""
ERROR: Job failed (system failure): prepare environment: waiting for pod running: pod status is failed. Check https://docs.gitlab.com/runner/shells/index.html#shell-profile-loading for more information

请问在K3s上配置GitLab Runner时,该错误可能由哪些配置问题导致?

可能的配置问题

  • 权限初始化容器异常:GitLab Runner的Kubernetes executor默认会启动init-permissions初始化容器来调整文件权限,若该容器镜像拉取失败、资源配额不足或镜像版本与Runner不兼容,都会导致初始化失败。比如K3s的镜像仓库无法拉取该容器依赖的镜像,或者镜像的权限逻辑有问题。
  • Runner服务账号权限不足:运行GitLab Runner的ServiceAccount缺少必要权限,比如无法操作Pod内的文件权限、无法访问Kubernetes API完成初始化流程。需要检查该账号是否拥有pods、pods/exec等核心权限。
  • K3s安全策略限制:K3s默认启用的安全机制(如SELinux、AppArmor)或节点的PodSecurityPolicy、SecurityContextConstraint,可能禁止init-permissions容器以root用户运行,或者限制了容器的文件系统操作权限,导致初始化失败。
  • 存储卷权限配置错误:如果Runner配置了持久化存储卷(PVC),存储卷的所属用户、组或读写权限不符合要求,会导致init-permissions容器无法修改卷内文件权限,进而初始化失败。
  • 版本兼容性问题:GitLab Runner 16.3.0与当前K3s版本不兼容,导致初始化容器的逻辑无法正常执行。需确认两者的版本适配范围,比如GitLab官方支持的Kubernetes版本是否包含当前K3s版本。

内容的提问来源于stack exchange,提问作者Leslie Wang

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 09:12:19