MicroK8s安装OpenWhisk报错:serviceaccount 'default'未找到求助
问题排查:MicroK8s中Helm安装OpenWhisk报错"serviceaccount 'default' not found"
环境信息
- 系统:Linuxmint(Ubuntu衍生版)
- MicroK8s:1.26/stable(snap安装,单节点集群)
- Helm:3.7/stable(snap安装)
执行的安装命令
helm install owdev openwhisk/openwhisk -n openwhisk --create-namespace -f whisk.yaml
自定义配置文件whisk.yaml
whisk: ingress: type: NodePort apiHostName: localhost apiHostPort: 31001 useInternally: false nginx: httpsNodePort: 31001 # disable affinity affinity: enabled: false toleration: enabled: false invoker: options: "-Dwhisk.kubernetes.user-pod-node-affinity.enabled=false" # must use KCF as kind uses containerd as its container runtime containerFactory: impl: "kubernetes"
报错信息
Error: INSTALLATION FAILED: pods "owdev-wskadmin" is forbidden: error looking up service account openwhisk/default: serviceaccount "default" not found
已执行的排查命令结果
执行microk8s kubectl get secrets --all-namespaces得到:
NAMESPACE NAME TYPE DATA AGE kube-system kubernetes-dashboard-certs Opaque 0 24h kube-system microk8s-dashboard-token kubernetes.io/service-account-token 3 24h kube-system kubernetes-dashboard-csrf Opaque 1 24h kube-system kubernetes-dashboard-key-holder Opaque 2 24h default lithops-regcred kubernetes.io/dockerconfigjson 1 18h openwhisk owdev-whisk.auth Opaque 2 17m openwhisk owdev-db.auth Opaque 2 24h openwhisk sh.helm.release.v1.owdev.v1 helm.sh/release.v1 1 17m
问题原因与解决方法
问题原因
使用--create-namespace参数创建新命名空间时,MicroK8s默认不会自动生成default服务账号。而OpenWhisk的owdev-wskadmin Pod默认依赖openwhisk命名空间下的default服务账号,因此触发找不到账号的权限错误。
解决步骤
- 手动创建
openwhisk命名空间及对应的default服务账号:
# 创建命名空间 microk8s kubectl create namespace openwhisk # 在openwhisk命名空间下创建default服务账号 microk8s kubectl create serviceaccount default -n openwhisk
- 重新执行Helm安装命令:
helm install owdev openwhisk/openwhisk -n openwhisk -f whisk.yaml
内容的提问来源于stack exchange,提问作者joe2310
相关产品推荐
相关产品推荐

