Azure AKS Kubernetes Dashboard无法访问,误删pod后如何恢复?
Hey there, let's work through this issue step by step—losing access to the Kubernetes Dashboard after deleting the pod is a common gotcha with AKS, since the Dashboard is managed as an Azure add-on rather than a regular self-deployed app. Here are the actionable fixes you can try:
1. Force a Re-deployment via Azure Add-on Toggle
Since Azure manages the AKS Dashboard as an add-on, manually deleting the pod might not trigger an automatic rebuild right away. The simplest fix is to toggle the add-on off and on to force Azure to re-provision all Dashboard resources:
# First, disable the Dashboard add-on az aks disable-addons --addons kube-dashboard --resource-group <res_group> --name <cluster_name> # Wait 2-3 minutes for Azure to clean up old resources # Then re-enable the add-on az aks enable-addons --addons kube-dashboard --resource-group <res_group> --name <cluster_name>
After this, run kubectl get pods -n kube-system | grep dashboard to check if the pod is being created. Give it a minute or two to spin up, then try aks browse again.
2. Verify Dashboard Resources & Debug Deployment Issues
If toggling the add-on didn't work, let's dig into the underlying resources to find why the pod won't launch:
- Check if the Dashboard deployment exists in the
kube-systemnamespace:kubectl get deployment kubernetes-dashboard -n kube-system - If the deployment exists but no pod is running, inspect the deployment's events for errors (like image pull failures, resource limits, or permission issues):
Look at thekubectl describe deployment kubernetes-dashboard -n kube-systemEventssection at the bottom—common issues here areImagePullBackOff(node can't reach the Azure container registry) orCrashLoopBackOff(pod fails to start due to configuration errors).
3. Bypass aks browse to Test Dashboard Directly
Sometimes the issue is with the aks browse tool itself, not the Dashboard pod. Let's test accessing the Dashboard directly using port forwarding:
- First, confirm the Dashboard service exists:
kubectl get service kubernetes-dashboard -n kube-system - Forward a local port to the Dashboard service:
kubectl port-forward service/kubernetes-dashboard 8001:443 -n kube-system - Now open your browser and go to
https://localhost:8001—if the Dashboard loads, the problem was withaks browse(try restarting your terminal or updating the Azure CLI to fix this).
4. Fix Permission Issues (If Dashboard Loads but Shows Access Errors)
If you can reach the Dashboard but get permission denied errors, it might be because the default Dashboard service account lacks sufficient permissions. For testing purposes (not recommended for production clusters), you can grant it cluster-admin access:
kubectl create clusterrolebinding kubernetes-dashboard --clusterrole=cluster-admin --serviceaccount=kube-system:kubernetes-dashboard
After running this, refresh the Dashboard page—you should have full access. For production, create a more restricted role instead.
内容的提问来源于stack exchange,提问作者lvadim01

