You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助解决Kube-apiserver的invalid bearer token认证错误

解决Kubernetes APIServer "invalid bearer token" 错误求助

各位好,请问有没有人有解决apiserver的"invalid bearer token"错误的经验?

我是Kubernetes集群新手,近期在办公局域网部署了一个测试集群,版本信息如下:

  • CentOS Linux release 7.9.2009 (Core)
  • GO version go1.20.4
  • Docker-CE 24.0.2
  • cri-dockerd 0.3.2: CRI Interface for Docker Application Container Engine
  • Containerd Containerd.io 1.6.21
  • kube-apiserver:v1.27.2
  • kube-controller-manager:v1.27.2
  • kube-scheduler:v1.27.2
  • kube-proxy:v1.27.2
  • pause:3.9/pause:3.6 (手动本地部署了3.6版本,不清楚为何需要)
  • etcd:3.5.7-0
  • coredns:v1.10.1
  • Flannel 0.22

集群运行环境信息如下:

# kubectl get service -A

NAMESPACE        NAME                                                TYPE        CLUSTER-IP     EXTERNAL-IP   PORT(S)                  AGE
chan-namespace   nodeport-service-chan-nginx-development             NodePort    10.6.228.232   <none>        80:32577/TCP             8d
chan-namespace   nodeport-service-chan-nginx-development-portbased   NodePort    10.6.111.58    <none>        8080:31529/TCP           8d
chan-namespace   service-nodeport-blog-access                        NodePort    10.6.100.85    <none>        888:31695/TCP            3d6h
chan-namespace   service-nodeport-blog-mysql                         NodePort    10.6.244.105    <none>        3308:30006/TCP           7h21m
chan-namespace   service-nodeport-expose                             NodePort    10.6.66.244    <none>        8081:30001/TCP           5h48m
default          kubernetes                                          ClusterIP   10.6.0.1       <none>        443/TCP                  9d
kube-system      kube-dns                                            ClusterIP   10.6.0.10      <none>        53/UDP,53/TCP,9153/TCP   9d
# kubectl get pod -A
NAMESPACE        NAME                                        READY   STATUS    RESTARTS         AGE
chan-namespace   blog-access-node-5d6b6b9584-dshzl           1/1     Running   6 (48m ago)      3d2h
chan-namespace   blog-mysql-76cd95c4c8-qvvph                 1/1     Running   0                3h55m
chan-namespace   busybox                                     1/1     Running   0                56m
chan-namespace   nginx-deployment-chan-57d84f57dc-88tr4      1/1     Running   2 (48m ago)      12h
chan-namespace   nginx-deployment-chan-57d84f57dc-dtffm      1/1     Running   2 (48m ago)      12h
chan-namespace   nginx-deployment-chan-57d84f57dc-tztpg      1/1     Running   7 (48m ago)      4d13h
kube-flannel     kube-flannel-ds-gg6dc                       1/1     Running   3 (5h14m ago)    2d2h
kube-flannel     kube-flannel-ds-nn4x5                       1/1     Running   17 (48m ago)     9d
kube-flannel     kube-flannel-ds-tdttg                       1/1     Running   3 (5h14m ago)    2d2h
kube-system      coredns-7c987b59d4-62b6d                    1/1     Running   1 (48m ago)      3h55m
kube-system      coredns-7c987b59d4-w9s7x                    1/1     Running   1 (48m ago)      3h55m
kube-system      etcd-controller-master                      1/1     Running   18 (48m ago)     9d
kube-system      kube-apiserver-controller-master            1/1     Running   18 (48m ago)     9d
kube-system      kube-controller-manager-controller-master   1/1     Running   18 (48m ago)     9d
kube-system      kube-proxy-2tsff                            1/1     Running   11 (5h14m ago)   9d
kube-system      kube-proxy-9268z                            1/1     Running   18 (48m ago)     9d
kube-system      kube-proxy-t57jz                            1/1     Running   3 (5h14m ago)    2d2h
kube-system      kube-scheduler-controller-master            1/1     Running   18 (48m ago)     9d
# kubectl get cs
Warning: v1 ComponentStatus is deprecated in v1.19+
NAME                 STATUS    MESSAGE                         ERROR
scheduler            Healthy   ok                              
controller-manager   Healthy   ok                              
etcd-0               Healthy   {"health":"true","reason":""}   
# kubectl get ns
NAME              STATUS   AGE
chan-namespace    Active   9d
default           Active   9d
kube-flannel      Active   9d
kube-node-lease   Active   9d
kube-public       Active   9d
kube-system       Active   9d

各集群节点的NTP定时任务信息如下:

# crontab -l
*/5 * * * * /usr/sbin/ntpdate -u time1.aliyun.com >>/var/log/ntp-udpate-chan.log  2>&1

API-Server Pod持续出现如下错误信息:

E0614 13:16:29.609061       1 authentication.go:70] "Unable to authenticate the request" err="[invalid bearer token, service account token is not valid yet]"
E0614 13:16:37.014138       1 authentication.go:70] "Unable to authenticate the request" err="[invalid bearer token, service account token is not valid yet]"

Flannel Pod持续出现如下错误信息:

0614 13:13:26.346353       1 reflector.go:140] github.com/flannel-io/flannel/pkg/subnet/kube/kube.go:487: Failed to watch *v1.Node: failed to list *v1.Node: Unauthorized
W0614 13:14:11.331341       1 reflector.go:424] github.com/flannel-io/flannel/pkg/subnet/kube/kube.go:487: failed to list *v1.Node: Unauthorized
E0614 13:14:11.331361       1 reflector.go:140] github.com/flannel-io/flannel/pkg/subnet/kube/kube.go:487: Failed to watch *v1.Node: failed to list *v1.Node: Unauthorized

CoreDNS持续出现如下错误信息:

[INFO] plugin/kubernetes: pkg/mod/k8s.io/client-go@v0.26.1/tools/cache/reflector.go:169: failed to list *v1.Namespace: Unauthorized
[ERROR] plugin/kubernetes: pkg/mod/k8s.io/client-go@v0.26.1/tools/cache/reflector.go:169: Failed to watch *v1.Namespace: failed to list *v1.Namespace: Unauthorized
[INFO] plugin/kubernetes: pkg/mod/k8s.io/client-go@v0.26.1/tools/cache/reflector.go:169: failed to list *v1.Service: Unauthorized
[ERROR] plugin/kubernetes: pkg/mod/k8s.io/client-go@v0.26.1/tools/cache/reflector.go:169: Failed to watch *v1.Service: failed to list *v1.Service: Unauthorized

恳请各位帮忙解决这些错误,任何提示都将不胜感激,提前感谢!


内容的提问来源于stack exchange,提问作者Tony C

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 00:07:05