You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在minikube与Kind中运行Krustlet遇连接拒绝错误求助

解决Krustlet在Minikube/Kind中启动时的TCP连接拒绝问题

问题重现

Minikube环境操作及错误

尝试按照官方教程部署Krustlet,Minikube集群启动正常,但启动Krustlet时出现TCP连接拒绝错误:

julen@julen-HP-ZBook:~/Cloudlab/krustlet$ minikube start --driver=virtualbox
😄  minikube v1.29.0 on Ubuntu 22.04
✨  Using the virtualbox driver based on user configuration
👍  Starting control plane node minikube in cluster minikube
🔥  Creating virtualbox VM (CPUs=2, Memory=6000MB, Disk=20000MB) ...
🐳  Preparing Kubernetes v1.26.1 on Docker 20.10.23 ...
    ▪ Generating certificates and keys ...
    ▪ Booting up control plane ...
    ▪ Configuring RBAC rules ...
🔗  Configuring bridge CNI (Container Networking Interface) ...
    ▪ Using image gcr.io/k8s-minikube/storage-provisioner:v5
🔎  Verifying Kubernetes components...
🌟  Enabled addons: storage-provisioner, default-storageclass
🏄  Done! kubectl is now configured to use "minikube" cluster and "default" namespace by default
julen@julen-HP-ZBook:~/Cloudlab/krustlet$ kubectl get nodes
NAME       STATUS   ROLES           AGE   VERSION
minikube   Ready    control-plane   83s   v1.26.1
julen@julen-HP-ZBook:~/Cloudlab/krustlet$ bash <(curl https://raw.githubusercontent.com/krustlet/krustlet/main/scripts/bootstrap.sh)
100  2456  100  2456    0     0   5652      0 --:--:-- --:--:-- --:--:--  5645
secret/bootstrap-token-5k3c0g created
Switched to context "minikube".
Context "minikube" renamed to "tls-bootstrap-token-user@kubernetes".
User "tls-bootstrap-token-user" set.
Context "tls-bootstrap-token-user@kubernetes" modified.
Context "tls-bootstrap-token-user@kubernetes" modified.
julen@julen-HP-ZBook:~/Cloudlab/krustlet$ KUBECONFIG=~/.krustlet/config/kubeconfig \
  krustlet-wasi \
  --node-ip 10.0.2.2 \
  --node-name=krustlet \
  --bootstrap-file=${HOME}/.krustlet/config/bootstrap.conf
Mar 24 17:04:26.750 ERROR kube::client: failed with error error trying to connect: tcp connect error: Connection refused (os error 111)
Error: HyperError: error trying to connect: tcp connect error: Connection refused (os error 111)

Caused by:
    0: error trying to connect: tcp connect error: Connection refused (os error 111)
    1: tcp connect error: Connection refused (os error 111)
    2: Connection refused (os error 111)

已尝试官方指定IP及其他可能IP,均未解决问题。

Kind环境操作及错误

切换到Kind环境尝试,同样出现连接拒绝错误,且Kind节点处于NotReady状态:

julen@julen-HP-ZBook:~/Cloudlab/krustlet$ kind create cluster
Creating cluster "kind" ...
 ✓ Ensuring node image (kindest/node:v1.20.2) 🖼
 ✓ Preparing nodes 📦  
 ✓ Writing configuration 📜 
 ✓ Starting control-plane 🕹️ 
 ✓ Installing CNI 🔌 
 ✓ Installing StorageClass 💾 
Set kubectl context to "kind-kind"
You can now use your cluster with:

kubectl cluster-info --context kind-kind

Have a nice day! 👋
julen@julen-HP-ZBook:~/Cloudlab/krustlet$ curl https://raw.githubusercontent.com/krustlet/krustlet/main/scripts/bootstrap.sh | /bin/bash
100  2456  100  2456    0     0   6854      0 --:--:-- --:--:-- --:--:--  6860
secret/bootstrap-token-p83li5 created
Switched to context "kind-kind".
Context "kind-kind" renamed to "tls-bootstrap-token-user@kubernetes".
User "tls-bootstrap-token-user" set.
Context "tls-bootstrap-token-user@kubernetes" modified.
Context "tls-bootstrap-token-user@kubernetes" modified.
julen@julen-HP-ZBook:~/Cloudlab/krustlet$ KUBECONFIG=~/.krustlet/config/kubeconfig \
  krustlet-wasi \
  --node-ip=172.17.0.1 \
  --node-name=krustlet \
  --bootstrap-file=${HOME}/.krustlet/config/bootstrap.conf
Mar 24 17:13:36.504 ERROR kube::client: failed with error error trying to connect: tcp connect error: Connection refused (os error 111)
Error: HyperError: error trying to connect: tcp connect error: Connection refused (os error 111)

Caused by:
    0: error trying to connect: tcp connect error: Connection refused (os error 111)
    1: tcp connect error: Connection refused (os error 111)
    2: Connection refused (os error 111)
julen@julen-HP-ZBook:~/Cloudlab/krustlet$ kubectl get nodes
NAME                 STATUS     ROLES                  AGE   VERSION
kind-control-plane   NotReady   control-plane,master   37s   v1.20.2

解决步骤

1. 确认Kubernetes API Server的可访问性

  • 执行kubectl cluster-info获取API Server的实际地址,示例输出类似:Kubernetes control plane is running at https://192.168.99.100:6443
  • 在主机上测试连通性:curl -v <API_SERVER_ADDRESS>,若返回SSL相关响应则连通正常,否则排查集群网络问题

2. 修正Krustlet的KubeConfig配置

  • 查看生成的Krustlet配置文件:cat ~/.krustlet/config/kubeconfig
  • 检查server字段是否与kubectl cluster-info中的API Server地址一致,若不一致手动修改该字段

3. 调整Krustlet启动参数

Minikube环境

  • 获取Minikube节点IP:minikube ip
  • 使用正确的上下文和节点IP启动Krustlet:
KUBECONFIG=~/.krustlet/config/kubeconfig \
krustlet-wasi \
--node-ip $(minikube ip) \
--node-name=krustlet \
--bootstrap-file=${HOME}/.krustlet/config/bootstrap.conf \
--kubeconfig-context=minikube

Kind环境

  • 先等待Kind节点进入Ready状态:kubectl wait --for=condition=ready node/kind-control-plane --timeout=5m
  • 使用Kind集群上下文启动Krustlet:
KUBECONFIG=~/.krustlet/config/kubeconfig \
krustlet-wasi \
--node-ip=172.17.0.1 \
--node-name=krustlet \
--bootstrap-file=${HOME}/.krustlet/config/bootstrap.conf \
--kubeconfig-context=kind-kind

4. 检查防火墙与端口占用

  • 检查主机6443端口(Kubernetes API默认端口)是否被占用:sudo lsof -i :6443
  • 临时关闭主机防火墙(如UFW)测试:sudo ufw disable,若问题解决则添加允许6443端口的规则:sudo ufw allow 6443

5. 重新生成Bootstrap配置(可选)

若之前的Bootstrap脚本生成的配置存在问题,删除旧配置后重新执行:

rm -rf ~/.krustlet/config
bash <(curl https://raw.githubusercontent.com/krustlet/krustlet/main/scripts/bootstrap.sh)

内容的提问来源于stack exchange,提问作者julenbhy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 13:38:13