You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS挂载EFS作为持久存储时PVC报‘ValidationError: Request ARN is invalid’

EKS挂载EFS PVC失败:WebIdentityErr凭证获取错误

问题现象

尝试将EFS用作EKS Pod的持久化存储,已完成以下操作:

  • 安装AWS EFS CSI Driver
  • 创建EFS文件系统
  • 创建EKS存储类

但PVC创建失败,报错如下:

Type     Reason              Age   From                                                                           Message
----     ------              ----  ----                                                                           -------
Warning  ProvisioningFailed  19s   efs.csi.aws.com_ip-xxxx.xxx.com_7598289c-9f51-4b83-9a4e-02ff9942af9a  failed to provision volume with StorageClass "efs-sc": rpc error: code = Internal desc = Failed to fetch File System info: Describe File System failed: WebIdentityErr: failed to retrieve credentials
caused by: ValidationError: Request ARN is invalid
           status code: 400, request id: 2af47ad1-c5ce-4389-a716-8f0e241145a7

PVC始终未绑定,Pod处于Pending状态。

已完成的排查动作

  • 确认存储类中的fileSystemId与EFS控制台显示一致
  • 已按照官方文档配置CSI驱动及IRSA(IAM Roles for Service Accounts)
  • EFS CSI驱动控制器日志显示调用DescribeFileSystems时使用的fileSystemId正确:
I0729 06:59:09.646688       1 controller.go:61] CreateVolume: called with args {Name:pvc-649527dd-78bf-4aaa-9688-2496bb181d6c CapacityRange:required_bytes:68719476736  VolumeCapabilities:[mount:<mount_flags:"tls" > access_mode:<mode:MULTI_NODE_MULTI_WRITER > ] Parameters:map[basePath:/dynamic_provisioning csi.storage.k8s.io/pv/name:pvc-649527dd-78bf-4aaa-9688-2496bb181d6c csi.storage.k8s.io/pvc/name:prometheus-prometheus-kube-prometheus-prometheus-db-prometheus-prometheus-kube-prometheus-prometheus-2 csi.storage.k8s.io/pvc/namespace:monitoring directoryPerms:755 fileSystemId:fs-08121f8be9526a369 gidRangeEnd:70000 gidRangeStart:1000 provisioningMode:efs-ap] Secrets:map[] VolumeContentSource:<nil> AccessibilityRequirements:<nil> XXX_NoUnkeyedLiteral:{} XXX_unrecognized:[] XXX_sizecache:0}
I0729 06:59:09.646782       1 cloud.go:238] Calling DescribeFileSystems with input: {
  FileSystemId: "fs-08121f8be9526a369"
}

排查指导

1. 检查IRSA角色ARN的正确性

  • 确认EFS CSI Driver使用的ServiceAccount关联的IAM角色ARN格式为arn:aws:iam::[AWS账号ID]:role/[角色名称],无拼写错误、多余字符或缺失部分。
  • 查看kube-system命名空间下的efs-csi-controller-sa注解,确认eks.amazonaws.com/role-arn的值正确:
    kubectl describe serviceaccount efs-csi-controller-sa -n kube-system
    

2. 验证IAM角色的信任策略

  • 确保IAM角色的信任策略允许EKS集群的OIDC提供商扮演该角色,策略需包含以下核心内容(替换占位符为实际值):
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "Federated": "arn:aws:iam::[AWS账号ID]:oidc-provider/oidc.eks.[区域].amazonaws.com/id/[OIDC提供商ID]"
          },
          "Action": "sts:AssumeRoleWithWebIdentity",
          "Condition": {
            "StringEquals": {
              "oidc.eks.[区域].amazonaws.com/id/[OIDC提供商ID]:sub": "system:serviceaccount:kube-system:efs-csi-controller-sa"
            }
          }
        }
      ]
    }
    
  • 注意ServiceAccount的命名空间和名称需与策略中的sub字段完全匹配。

3. 确认IAM角色权限

  • 检查角色是否附加了AmazonEFSCSIDriverPolicy托管策略,若使用自定义策略,需包含以下权限:
    • elasticfilesystem:DescribeFileSystems
    • elasticfilesystem:CreateAccessPoint
    • elasticfilesystem:DeleteAccessPoint
    • elasticfilesystem:DescribeAccessPoints

4. 验证EKS OIDC提供商配置

  • 通过以下命令确认EKS集群已关联OIDC提供商:
    aws eks describe-cluster --name [集群名称] --query "cluster.identity.oidc.issuer"
    
  • 确保IAM控制台中存在对应ARN的OIDC提供商。

5. 检查EFS网络访问配置

  • 确认EFS文件系统的挂载目标位于EKS集群所在VPC的子网中。
  • 验证EFS安全组允许EKS节点安全组访问NFS端口(2049)。

内容的提问来源于stack exchange,提问作者Aakash Howlader

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 00:23:20