无法通过kubectl认证访问AWS EKS的排查求助
EKS kubectl认证失败排查方案
验证aws-iam-authenticator可用性与配置
- 执行
aws-iam-authenticator token -i mynode --profile myprofile,检查是否能返回有效token。若报错,重新安装对应系统版本的authenticator,或确认其路径已加入环境变量PATH。 - 查看
~/.kube/config中对应集群的user段,确认exec命令为aws-iam-authenticator,args包含token -i mynode,且env正确指定AWS_PROFILE=myprofile(或通过其他方式传递凭证)。
- 执行
确认IAM用户权限边界
- 进入IAM控制台,检查myprofile用户的**权限边界(Permission Boundary)**配置,确保未限制
eks:DescribeCluster、sts:GetCallerIdentity等必要操作。 - 使用IAM策略模拟器,模拟myprofile用户执行
eks:DescribeCluster、eks:ListClusters、sts:GetCallerIdentity等操作,验证是否允许。
- 进入IAM控制台,检查myprofile用户的**权限边界(Permission Boundary)**配置,确保未限制
检查kubectl上下文与凭证传递
- 执行
kubectl config current-context,确认当前使用的是mynode集群对应的myprofile上下文。若不是,执行kubectl config use-context <上下文名称>切换。 - 直接指定凭证测试:执行
AWS_PROFILE=myprofile kubectl get nodes,绕开kubeconfig的exec配置,验证是否能正常访问。
- 执行
验证集群端点网络可达性
- 先通过
aws eks describe-cluster --name mynode --profile myprofile --query "cluster.endpoint"获取集群API端点,执行curl <端点URL>。若返回401则网络可达(需凭证),若超时或无法连接,排查本地防火墙、VPN连接或EKS VPC端点配置是否限制了访问。 - 若在EC2实例上操作,确认实例位于EKS集群的VPC内,且安全组允许出站访问集群端点。
- 先通过
检查aws-auth ConfigMap配置(若有其他权限用户协助)
- 让有权限的用户执行
kubectl get configmap aws-auth -n kube-system -o yaml,确认myprofile用户的ARN已添加到mapUsers段中。若未添加,即使IAM权限足够,K8s侧也会拒绝访问。
- 让有权限的用户执行
清理缓存并重新生成kubeconfig
- 删除kubectl缓存:
rm -rf ~/.kube/cache,避免旧缓存干扰。 - 重新生成kubeconfig:
aws eks update-kubeconfig --name mynode --profile myprofile --overwrite,覆盖原有配置。
- 删除kubectl缓存:
内容的提问来源于stack exchange,提问作者Chris B.
相关产品推荐
相关产品推荐

