使用本地CLI连接EKS集群时遭遇认证错误求助
解决EKS本地CLI连接时的凭证验证错误
问题场景
已创建EKS集群,安装并配置AWS CLI凭证,且AWS账号具备EKS相关权限,但使用kubectl连接时出现以下凭证验证错误:
E0209 21:09:44.893284 2465691 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E0209 21:09:45.571635 2465691 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E0209 21:09:46.380542 2465691 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E0209 21:09:47.105407 2465691 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E0209 21:09:47.869614 2465691 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials error: You must be logged in to the server (the server has asked for the client to provide credentials)
解决方案
更新kubeconfig配置
运行以下命令生成/更新EKS集群的kubeconfig文件,该命令会自动将集群认证信息写入本地~/.kube/config:aws eks update-kubeconfig --region <你的集群所在区域> --name <EKS集群名称>若使用非默认AWS profile,需追加
--profile <profile名称>参数。确认kubeconfig上下文
查看当前kubectl使用的上下文是否为目标EKS集群:kubectl config get-contexts若上下文不符,切换到目标集群的上下文:
kubectl config use-context <EKS集群对应的上下文名称>验证AWS凭证有效性
确认当前使用的AWS账号正确:aws sts get-caller-identity检查返回的Account、UserId是否为拥有EKS权限的实体。
检查IAM权限与EKS授权
- 确保AWS账号/角色拥有
eks:DescribeCluster权限,这是update-kubeconfig命令获取集群信息的必要权限。 - 若使用自定义IAM用户/角色,需确认该实体已被添加到EKS的
aws-authConfigMap中,可通过以下命令查看:
若未添加,需编辑该ConfigMap将IAM实体映射到Kubernetes权限组。kubectl describe configmap aws-auth -n kube-system
- 确保AWS账号/角色拥有
清理旧配置缓存
若本地存在旧的kubeconfig配置导致冲突,可先备份~/.kube/config,删除原文件后重新运行aws eks update-kubeconfig生成全新配置。
内容的提问来源于stack exchange,提问作者dave vedant
相关产品推荐
相关产品推荐

