You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MicroK8s安装OpenWhisk报错:serviceaccount 'default'未找到求助

问题排查:MicroK8s中Helm安装OpenWhisk报错"serviceaccount 'default' not found"

环境信息

  • 系统:Linuxmint(Ubuntu衍生版)
  • MicroK8s:1.26/stable(snap安装,单节点集群)
  • Helm:3.7/stable(snap安装)

执行的安装命令

helm install owdev openwhisk/openwhisk -n openwhisk --create-namespace -f whisk.yaml

自定义配置文件whisk.yaml

whisk:
  ingress:
    type: NodePort
    apiHostName: localhost
    apiHostPort: 31001
    useInternally: false

nginx:
  httpsNodePort: 31001

# disable affinity
affinity:
  enabled: false
toleration:
  enabled: false
invoker:
  options: "-Dwhisk.kubernetes.user-pod-node-affinity.enabled=false"
  # must use KCF as kind uses containerd as its container runtime
  containerFactory:
    impl: "kubernetes"

报错信息

Error: INSTALLATION FAILED: pods "owdev-wskadmin" is forbidden: error looking up service account openwhisk/default: serviceaccount "default" not found

已执行的排查命令结果

执行microk8s kubectl get secrets --all-namespaces得到:

NAMESPACE     NAME                              TYPE                                  DATA   AGE
kube-system   kubernetes-dashboard-certs        Opaque                                0      24h
kube-system   microk8s-dashboard-token          kubernetes.io/service-account-token   3      24h
kube-system   kubernetes-dashboard-csrf         Opaque                                1      24h
kube-system   kubernetes-dashboard-key-holder   Opaque                                2      24h
default       lithops-regcred                   kubernetes.io/dockerconfigjson        1      18h
openwhisk     owdev-whisk.auth                  Opaque                                2      17m
openwhisk     owdev-db.auth                     Opaque                                2      24h
openwhisk     sh.helm.release.v1.owdev.v1       helm.sh/release.v1                    1      17m

问题原因与解决方法

问题原因

使用--create-namespace参数创建新命名空间时,MicroK8s默认不会自动生成default服务账号。而OpenWhisk的owdev-wskadmin Pod默认依赖openwhisk命名空间下的default服务账号,因此触发找不到账号的权限错误。

解决步骤

  1. 手动创建openwhisk命名空间及对应的default服务账号:
# 创建命名空间
microk8s kubectl create namespace openwhisk

# 在openwhisk命名空间下创建default服务账号
microk8s kubectl create serviceaccount default -n openwhisk
  1. 重新执行Helm安装命令:
helm install owdev openwhisk/openwhisk -n openwhisk -f whisk.yaml

内容的提问来源于stack exchange,提问作者joe2310

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 13:40:36