You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions无法连接EKS集群问题求助

GitHub Actions无法连接EKS集群,报错executable aws failed with exit code 255

问题描述

GitHub Actions执行Terraform Apply时无法连接EKS集群,报错如下:

Error: Kubernetes cluster unreachable: Get "https://test.ukk.us-east-2.eks.amazonaws.com/version": getting credentials: exec: executable aws failed with exit code 255. Error: failed to create kubernetes rest client for read of resource: Get "https://test.ukk.us-east-2.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 255

本地可正常连接该公开EKS集群,GitHub Action配置文件如下:

name: "Terraform Provisioning"

on:
  push:
    paths:
      - 'terraform/scripts/test-tech-stack/**'
    branches:
      - main
  pull_request:
    paths:
      - 'terraform/scripts/test-tech-stack/**'
    branches:
      - main
      
jobs:
  terraform:
    env:
      AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
      AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
    name: "Terraform"
    runs-on: ubuntu-latest
    steps:
      - name: Checkout
        uses: actions/checkout@v3

      - name: Setup Terraform
        uses: hashicorp/setup-terraform@v2
        with:
          terraform_version: 1.1.7

      - name: Terraform Init
        id: init
        run: terraform init
        working-directory: terraform/scripts/test-tech-stack

      - name: Terraform Apply
        if: github.ref == 'refs/heads/main' && github.event_name == 'push'
        run: aws --version; terraform apply -auto-approve -input=false
        working-directory: terraform/scripts/test-tech-stack

排查与解决步骤

1. 确保AWS CLI安装并配置正确

GitHub Actions的ubuntu-latest runner默认AWS CLI版本可能存在兼容性问题,建议明确安装指定版本:
在Setup Terraform步骤后添加:

- name: Install AWS CLI
  run: |
    curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
    unzip awscliv2.zip
    sudo ./aws/install

2. 配置AWS区域与EKS认证凭证

需要指定AWS区域并生成EKS的kubeconfig,在Terraform Apply步骤前添加:

- name: Configure AWS and EKS Kubeconfig
  run: |
    aws configure set region us-east-2
    aws eks update-kubeconfig --name test

注意将test替换为你的EKS集群名称,同时确保IAM凭证拥有eks:DescribeCluster权限。

3. 检查Terraform Kubernetes Provider配置

确保Terraform的Kubernetes provider正确通过AWS获取EKS访问权限,示例配置:

provider "kubernetes" {
  host                   = data.aws_eks_cluster.cluster.endpoint
  cluster_ca_certificate = base64decode(data.aws_eks_cluster.cluster.certificate_authority.0.data)
  exec {
    api_version = "client.authentication.k8s.io/v1beta1"
    command     = "aws"
    args = [
      "eks",
      "get-token",
      "--cluster-name",
      data.aws_eks_cluster.cluster.name,
    ]
  }
}

data "aws_eks_cluster" "cluster" {
  name = "test"
}

4. 验证GitHub Secrets对应的IAM权限

确认AWS_ACCESS_KEY_ID和AWS_SECRET_ACCESS_KEY关联的IAM用户拥有:

  • eks:DescribeCluster权限
  • EKS集群的RBAC访问权限(需在集群中配置对应IAM用户的权限绑定)

5. 检查EKS安全组网络规则

即使集群是公开的,也要确认GitHub Actions runner的IP范围被允许访问EKS集群的API端点。可临时开放0.0.0.0/0测试,或查询GitHub Actions官方IP范围添加到安全组的入站规则中。

内容的提问来源于stack exchange,提问作者Pavan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 12:03:29