使用eksctl创建Fargate型EKS集群时CoreDNS调度超时求助
问题描述
我按照AWS官方文档使用命令创建EKS集群:
eksctl create cluster --name my-cluster --region ap-south-1 --fargate
执行约30分钟后出现错误:
2023-08-21 01:05:46 [ℹ] waiting for CloudFormation stack "eksctl-eks-sample-cluster2-cluster" 2023-08-21 01:06:46 [ℹ] waiting for CloudFormation stack "eksctl-eks-sample-cluster2-cluster" 2023-08-21 01:08:49 [ℹ] creating Fargate profile "fp-default" on EKS cluster "eks-sample-cluster2" 2023-08-21 01:11:00 [ℹ] created Fargate profile "fp-default" on EKS cluster "eks-sample-cluster2" 2023-08-21 01:11:31 [ℹ] "coredns" is now schedulable onto Fargate 2023-08-21 01:36:33 [!] 1 error(s) occurred and cluster hasn't been created properly, you may wish to check CloudFormation console 2023-08-21 01:36:33 [ℹ] to cleanup resources, run 'eksctl delete cluster --region=ap-south-1 --name=eks-sample-cluster2' 2023-08-21 01:36:33 [✖] failed to schedule core-dns on fargate: timed out while waiting for "coredns" to be scheduled on Fargate
已尝试以下操作但未解决:
- 延长超时时间
- 去掉
--fargate参数 - 设置
--vpc-private-subnets选项
查看CloudFormation堆栈,CoreDNS部分显示No nodes setup to schedule pods,无节点创建。文档说明所有资源会自动创建配置,怀疑是否因使用root用户凭证配置eksctl导致,寻求解决方法。
排查与解决方法
排除root用户影响
root用户本身不会直接触发该问题,但建议切换到具备最小必要权限的IAM用户操作(需附加AmazonEKSClusterPolicy、AmazonEKSServicePolicy等核心权限),避免超权限引发的隐性冲突。检查Fargate配置细节
- 验证Fargate profile关联的子网:必须属于集群VPC,公有子网需开启
Auto-assign public IPv4 address,私有子网需配置NAT网关,确保Pod能访问AWS服务端点。 - 确认集群OIDC身份提供商:通过AWS控制台进入EKS集群配置页面,检查身份提供商是否已自动创建,这是Fargate Pod获取权限的关键。
- 验证Fargate profile关联的子网:必须属于集群VPC,公有子网需开启
CoreDNS调度问题定位
- 若集群部分资源保留,执行
kubectl get pods -n kube-system查看coredns Pod的事件日志,获取调度失败的具体原因(如资源配额不足、权限缺失)。 - 检查
eks-fargate-pod-execution-role角色:确认该角色存在且已关联到Fargate profile,Fargate Pod依赖此角色拉取镜像和访问服务。
- 若集群部分资源保留,执行
CloudFormation堆栈深度排查
- 查看堆栈事件日志,定位具体失败的资源步骤,比如是否存在子网创建失败、IAM角色权限不足等问题。
- 私有子网场景需检查VPC端点:确保已创建EKS、ECR、S3等服务的VPC端点,否则Fargate Pod无法拉取镜像。
区域资源配额检查
ap-south-1区域可能存在Fargate资源配额不足的情况,可通过AWS Support提交配额提升申请,或切换到其他区域测试验证。
内容的提问来源于stack exchange,提问作者Mahesh
相关产品推荐
相关产品推荐

