Jenkins Kubernetes插件连接EKS集群失败,测试连接报错求助
That error pops up because your Jenkins master is trying to use a local kubeconfig file to authenticate with EKS, but you're setting up authentication via a Kubernetes ServiceAccount (SA)—so you don't need that local config file at all. Let's walk through how to fix this step by step:
1. Adjust Kubernetes Plugin Configuration in Jenkins
Head to Manage Jenkins > Configure System, scroll down to the Kubernetes cloud section, and tweak these settings:
- Skip the "Kubeconfig" option: Instead, select "Kubernetes service account" as the authentication method. This tells Jenkins to use the ServiceAccount token you set up instead of hunting for a local config file.
- Paste your EKS API server URL (the same one from your error:
https://xxxxxxxx.us-east-1.eks.amazonaws.com). - Set the Namespace to the actual one you used for your ServiceAccount/Role/RoleBinding (not
default, as you noted). - Under Credentials, pick the "Secret text" credential you created—this should be the token linked to your
jenkins-adminServiceAccount.
2. Verify Your ServiceAccount Token is Correct
If you're unsure you grabbed the right token for your credential, fetch it directly from EKS with these commands (replace <your-namespace> with your actual namespace):
# Get the secret name tied to your ServiceAccount SECRET_NAME=$(kubectl get sa jenkins-admin -n <your-namespace> -o jsonpath='{.secrets[0].name}') # Decode the token from the secret kubectl get secret $SECRET_NAME -n <your-namespace> -o jsonpath='{.data.token}' | base64 --decode
Copy the output and update your Jenkins credential if needed.
3. Double-Check Your RBAC Configuration
You mentioned using a custom namespace instead of default—make sure your YAML files have the correct namespace in all metadata sections. For example, your ServiceAccount should look like this (swap <your-namespace> for your actual one):
apiVersion: v1 kind: ServiceAccount metadata: name: jenkins-admin namespace: <your-namespace> # Replace with your real namespace
Same rule applies to the Role and RoleBinding—their metadata.namespace must match where you deployed the ServiceAccount.
4. Confirm Network Access from EC2 to EKS
Make sure your Jenkins EC2 instance can reach the EKS API endpoint. Test this with curl (use the token you fetched earlier):
curl https://xxxxxxxx.us-east-1.eks.amazonaws.com --header "Authorization: Bearer <your-sa-token>"
You should get a valid JSON response with Kubernetes version details. If not, check your EC2 security group and EKS cluster endpoint access settings to ensure traffic is allowed.
Bonus: EKS-Specific IAM Authentication Alternative
Since you're using EKS, another option is to use IAM roles instead of ServiceAccount tokens. If your Jenkins EC2 instance has an IAM role with permissions to access EKS, you can configure the plugin to use AWS IAM Authenticator. This avoids manual token management—just select the "IAM role for service account" option in the plugin config and ensure your EC2 role has the right EKS permissions.
内容的提问来源于stack exchange,提问作者Abhilash Sandupatla

