You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

指定启动模板ID时EKS节点组创建失败求助

EKS节点组创建失败:Instances failed to join the kubernetes cluster

报错信息

Resource handler returned message: "[Issue(Code=NodeCreationFailure, Message=Instances failed to join the kubernetes cluster, ResourceIds=[i-0ce4d16dfdaba673f])] (Service: null, Status Code: 0, Request ID: null)" (RequestToken: 26cdbc72-af9f-e2cd-3280-fa0e737b8d5f, HandlerErrorCode: GeneralServiceException)

已完成的验证

  • NAT网关位于公有子网中
  • 节点组创建在us-east-1b可用区,与NAT网关同AZ,私有子网路由表已指向NAT网关作为出口
  • 启动模板关联的安全组为EKS集群的安全组

启动模板代码

AWSTemplateFormatVersion: 2010-09-09
Description: Creates AWSCloudFormationStackSetAdministrationRole which will be used by stacks to provision resources.

Parameters:
  ImageID:
    Type: AWS::EC2::Image::Id
    Description: AWS Image Id of instance type.
    Default: "ami-0a3da8b47de1d87b8"
  accountname:
    Type: String
    Default: "sandboxdemo3"
  InstanceType:
    Type: String
    Default: t3.medium

Resources:
  MyLaunchTemplate:
   Type: AWS::EC2::LaunchTemplate
   Properties:
     LaunchTemplateName: eks-customlaunch-template
     LaunchTemplateData:
       UserData: 
         Fn::Base64: 
           !Sub |
            #!/bin/bash
            echo "Custom user data script"
            yum update -y 
            yum install -y awslogs
            cat > /etc/awslogs/awslogs.conf << EOF
            [general]
            state_file = /var/lib/awslogs/agent-state

            [syslog]
            datetime_format = %b %d %H:%M:%S
            file = /var/log/messages
            buffer_duration = 5000
            log_stream_name = {instance_id}
            initial_position = start_of_file
            log_group_name = /aws/k8/${accountname}-syslog

            [zio]
            datetime_format = %b %d %H:%M:%S
            file = /run/containerd/io.containerd.runtime.v2.task/k8s.io/*/rootfs/var/log/zio-testing.log
            buffer_duration = 5000
            log_stream_name = {instance_id}-${accountname}
            initial_position = start_of_file
            log_group_name = /aws/k8/${accountname}-zio"
            EOF
            systemctl start awslogsd
            systemctl enable awslogsd
       ImageId: !Ref ImageID
       InstanceType: !Ref InstanceType
       BlockDeviceMappings:
         - DeviceName: '/dev/sdh'
           Ebs:
             VolumeSize: 80
       SecurityGroupIds:
         - Fn::ImportValue:
            #  'Fn::Sub': 'eksctl-myeks-${AWS::AccountId}-cluster::ClusterSecurityGroupId'
             'Fn::Sub': 'eksctl-demov6-cluster::ClusterSecurityGroupId'
       TagSpecifications:
         - ResourceType: instance
           Tags:
             - Key: alpha.eksctl.io/cluster-name
               Value: demov6
             - Key: alpha.eksctl.io/nodegroup-name
               Value: demobasev6-2
             - Key: k8s.io/cluster-autoscaler/enabled
               Value: true
            #  - Key: !Sub k8s.io/cluster-autoscaler/myeks-${AWS::AccountId}
            #    Value: owned
            #  - Key: !Sub kubernetes.io/cluster/myeks-${AWS::AccountId}
            #    Value: owned
             - Key: k8s.io/cluster-autoscaler/demov6
               Value: owned
             - Key: kubernetes.io/cluster/demov6
               Value: owned

节点组YAML文件

apiVersion: eksctl.io/v1alpha5
kind: ClusterConfig
managedNodeGroups:
- amiFamily: AmazonLinux2
  desiredCapacity: 1
  launchTemplate:
    version: "1"
    id: lt-0a99b80de662a40be
  iam:
    withAddonPolicies:
      albIngress: false
      appMesh: false
      appMeshPreview: false
      autoScaler: true
      awsLoadBalancerController: true
      certManager: false
      cloudWatch: false
      ebs: false
      efs: false
      externalDNS: false
      fsx: false
      imageBuilder: false
      xRay: false
  labels:
    alpha.eksctl.io/cluster-name: demov6
    alpha.eksctl.io/nodegroup-name: demobasev6-2
  maxSize: 4
  minSize: 1
  name: demobasev6-2
  availabilityZones: ["us-east-1b"]
  privateNetworking: true
  releaseVersion: ""
  tags:
    alpha.eksctl.io/nodegroup-name: demobasev6-2
    alpha.eksctl.io/nodegroup-type: managed
  volumeThroughput: 125
  volumeType: gp3
metadata:
  name: demov6
  region: us-east-1
  version: "1.24"

问题排查与解决建议

1. 自定义UserData覆盖了EKS初始化逻辑

自定义UserData会完全替换EKS默认的节点初始化脚本,导致节点无法执行加入集群的核心步骤。需在自定义脚本开头添加默认初始化脚本调用:

#!/bin/bash
# 保留EKS节点加入集群的核心逻辑
/etc/eks/bootstrap.sh demov6 --kubelet-extra-args "--node-labels=alpha.eksctl.io/cluster-name=demov6,alpha.eksctl.io/nodegroup-name=demobasev6-2"

# 以下是你的自定义脚本内容
echo "Custom user data script"
yum update -y 
yum install -y awslogs
# ... 其余自定义代码

注意将demov6替换为你的集群名称,kubelet标签需与节点组配置保持一致。

2. UserData存在语法错误

检查到[zio]段的log_group_name末尾多了一个双引号:

log_group_name = /aws/k8/${accountname}-zio"

该错误会导致awslogs.conf格式失效,中断脚本执行。需删除多余的双引号。

3. 验证节点IAM角色权限

确认节点角色拥有以下核心权限(eksctl托管节点组默认会添加,但自定义启动模板需手动确认):

  • AmazonEKSWorkerNodePolicy
  • AmazonEC2ContainerRegistryReadOnly
  • AmazonEKS_CNI_Policy
    这些权限是节点连接EKS集群的必要条件。

4. 查看节点系统日志定位具体错误

通过AWS控制台进入EC2实例详情页,在「监控」选项卡中获取系统日志,重点排查:

  • EKS API服务器连接失败信息
  • IAM角色权限报错
  • bootstrap.sh脚本执行异常日志

内容的提问来源于stack exchange,提问作者user2051904

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 20:27:52