GitHub Actions无法连接EKS集群问题求助
GitHub Actions无法连接EKS集群,报错executable aws failed with exit code 255
问题描述
GitHub Actions执行Terraform Apply时无法连接EKS集群,报错如下:
Error: Kubernetes cluster unreachable: Get "https://test.ukk.us-east-2.eks.amazonaws.com/version": getting credentials: exec: executable aws failed with exit code 255. Error: failed to create kubernetes rest client for read of resource: Get "https://test.ukk.us-east-2.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 255本地可正常连接该公开EKS集群,GitHub Action配置文件如下:
name: "Terraform Provisioning" on: push: paths: - 'terraform/scripts/test-tech-stack/**' branches: - main pull_request: paths: - 'terraform/scripts/test-tech-stack/**' branches: - main jobs: terraform: env: AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }} AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }} name: "Terraform" runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v3 - name: Setup Terraform uses: hashicorp/setup-terraform@v2 with: terraform_version: 1.1.7 - name: Terraform Init id: init run: terraform init working-directory: terraform/scripts/test-tech-stack - name: Terraform Apply if: github.ref == 'refs/heads/main' && github.event_name == 'push' run: aws --version; terraform apply -auto-approve -input=false working-directory: terraform/scripts/test-tech-stack
排查与解决步骤
1. 确保AWS CLI安装并配置正确
GitHub Actions的ubuntu-latest runner默认AWS CLI版本可能存在兼容性问题,建议明确安装指定版本:
在Setup Terraform步骤后添加:
- name: Install AWS CLI run: | curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" unzip awscliv2.zip sudo ./aws/install
2. 配置AWS区域与EKS认证凭证
需要指定AWS区域并生成EKS的kubeconfig,在Terraform Apply步骤前添加:
- name: Configure AWS and EKS Kubeconfig run: | aws configure set region us-east-2 aws eks update-kubeconfig --name test
注意将test替换为你的EKS集群名称,同时确保IAM凭证拥有eks:DescribeCluster权限。
3. 检查Terraform Kubernetes Provider配置
确保Terraform的Kubernetes provider正确通过AWS获取EKS访问权限,示例配置:
provider "kubernetes" { host = data.aws_eks_cluster.cluster.endpoint cluster_ca_certificate = base64decode(data.aws_eks_cluster.cluster.certificate_authority.0.data) exec { api_version = "client.authentication.k8s.io/v1beta1" command = "aws" args = [ "eks", "get-token", "--cluster-name", data.aws_eks_cluster.cluster.name, ] } } data "aws_eks_cluster" "cluster" { name = "test" }
4. 验证GitHub Secrets对应的IAM权限
确认AWS_ACCESS_KEY_ID和AWS_SECRET_ACCESS_KEY关联的IAM用户拥有:
eks:DescribeCluster权限- EKS集群的RBAC访问权限(需在集群中配置对应IAM用户的权限绑定)
5. 检查EKS安全组网络规则
即使集群是公开的,也要确认GitHub Actions runner的IP范围被允许访问EKS集群的API端点。可临时开放0.0.0.0/0测试,或查询GitHub Actions官方IP范围添加到安全组的入站规则中。
内容的提问来源于stack exchange,提问作者Pavan
相关产品推荐
相关产品推荐

