Juju部署Kubeflow失败:TLS握手错误排查求助
问题描述
我是Juju新手,在Ubuntu 20.04.6虚拟机中部署Charmed Kubeflow,Juju控制器已安装成功,但执行juju deploy kubeflow相关命令时,始终抛出TLS握手失败错误,相关命令输出及调试日志如下:
$ juju controllers Use --refresh option with this command to see the latest information. Controller Model User Access Cloud/Region Models Nodes HA Version microk8s-localhost* kubeflow admin superuser microk8s/localhost 2 - - 2.9.42 $ juju deploy kubeflow --trust --channel=1.7/stable ERROR resolving with preferred channel: Post "https://api.charmhub.io/v2/charms/refresh": remote error: tls: handshake failure $ juju deploy kubeflow ERROR resolving with preferred channel: Post "https://api.charmhub.io/v2/charms/refresh": remote error: tls: handshake failure $ juju version 2.9.42-ubuntu-amd64
调试日志:
$ juju deploy kubeflow --trust --channel=1.7/stable --debug 20:24:25 INFO juju.cmd supercommand.go:56 running juju [2.9.42 7b871e782195bdac9c90f8a8f01723cc3e08ab92 gc go1.18.10] 20:24:25 DEBUG juju.cmd supercommand.go:57 args: []string{"/snap/juju/22345/bin/juju", "deploy", "kubeflow", "--trust", "--channel=1.7/stable", "--debug"} 20:24:25 DEBUG juju.jujuclient proxy.go:65 unmarshalled proxy config for "kubernetes-port-forward" 20:24:25 INFO juju.juju api.go:86 connecting to API addresses: [10.152.183.138:17070] 20:24:25 DEBUG juju.api apiclient.go:625 starting proxier for connection 20:24:25 DEBUG juju.api apiclient.go:629 tunnel proxy in use at localhost on port 43975 20:24:25 DEBUG juju.api apiclient.go:1152 successfully dialed "wss://localhost:43975/api" 20:24:25 INFO juju.api apiclient.go:1054 cannot resolve "localhost": lookup localhost: operation was canceled 20:24:25 INFO juju.api apiclient.go:687 connection established to "wss://localhost:43975/api" 20:24:25 DEBUG juju.jujuclient proxy.go:65 unmarshalled proxy config for "kubernetes-port-forward" 20:24:25 INFO juju.juju api.go:86 connecting to API addresses: [10.152.183.138:17070] 20:24:25 DEBUG juju.api apiclient.go:625 starting proxier for connection 20:24:25 DEBUG juju.api apiclient.go:629 tunnel proxy in use at localhost on port 38075 20:24:25 DEBUG juju.api apiclient.go:1152 successfully dialed "wss://localhost:38075/model/4a2ce290-1cdb-489c-800b-bf0414c8cbef/api" 20:24:25 INFO juju.api apiclient.go:1054 cannot resolve "localhost": lookup localhost: operation was canceled 20:24:25 INFO juju.api apiclient.go:687 connection established to "wss://localhost:38075/model/4a2ce290-1cdb-489c-800b-bf0414c8cbef/api" 20:24:25 DEBUG juju.cmd.juju.application.deployer deployer.go:396 cannot interpret as local charm: file does not exist 20:24:25 DEBUG juju.cmd.juju.application.deployer deployer.go:208 cannot interpret as a redeployment of a local charm from the controller 20:24:26 DEBUG juju.api monitor.go:35 RPC connection died 20:24:26 DEBUG juju.api monitor.go:35 RPC connection died ERROR resolving with preferred channel: Post "https://api.charmhub.io/v2/charms/refresh": remote error: tls: handshake failure 20:24:26 DEBUG cmd supercommand.go:537 error stack: resolving with preferred channel: Post "https://api.charmhub.io/v2/charms/refresh": remote error: tls: handshake failure github.com/juju/juju/cmd/juju/application/store.(*CharmAdaptor).ResolveCharm:100: github.com/juju/juju/cmd/juju/application/store.(*CharmAdaptor).ResolveBundleURL:135: github.com/juju/juju/cmd/juju/application/deployer.(*factory).maybeReadRepositoryBundle:464: github.com/juju/juju/cmd/juju/application/deployer.(*factory).GetDeployer:71: github.com/juju/juju/cmd/juju/application.(*DeployCommand).Run:909:
解决方案
1. 同步系统时间
TLS握手失败最常见原因之一是系统时间与服务器时间偏差过大,执行以下命令同步时间:
sudo timedatectl set-ntp on timedatectl status
确认输出中NTP service显示active,System clock synchronized显示yes。
2. 验证网络连通性与代理设置
- 测试虚拟机能否正常访问Charmhub API:
curl -v https://api.charmhub.io/v2/charms/refresh
如果返回正常JSON数据,说明网络无问题;若出现TLS错误,检查是否有代理拦截,尝试关闭系统代理或配置Juju使用正确代理:
# 查看当前代理设置 echo $HTTP_PROXY $HTTPS_PROXY # 若有代理,配置Juju使用该代理 juju model-config http-proxy=$HTTP_PROXY https-proxy=$HTTPS_PROXY no-proxy=localhost,127.0.0.1,10.152.183.0/24
3. 更新Juju版本
当前使用的Juju 2.9.42可能存在TLS相关bug,更新到最新稳定版:
sudo snap refresh juju --stable juju version
4. 重置系统CA证书
系统根证书缺失或损坏也会导致TLS握手失败,重新安装并更新证书:
sudo apt update && sudo apt install --reinstall ca-certificates sudo update-ca-certificates -f
5. 直接指定Bundle URL部署
跳过Charmhub的自动解析步骤,直接使用Kubeflow Bundle的具体URL部署:
juju deploy https://github.com/canonical/bundle-kubeflow/releases/download/1.7.0/kubeflow.yaml --trust
内容的提问来源于stack exchange,提问作者codingfreak
相关产品推荐
相关产品推荐

