You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

执行kubectl get pods持续报错:服务器要求提供凭证

解决EKS集群kubectl认证失败问题

问题背景

执行命令更新EKS集群的kubeconfig:

aws eks update-kubeconfig --region eu-west-1  --name my-cluster

之后运行kubectl get pods时,持续抛出认证错误:

E1229 13:04:42.538976   82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
E1229 13:04:42.873405   82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
E1229 13:04:43.208848   82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
E1229 13:04:43.561855   82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
E1229 13:04:43.896372   82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials
error: You must be logged in to the server (the server has asked for the client to provide credentials)

注:本地AWS CLI配置已验证可用。

排查与解决步骤

1. 修复kubeconfig文件权限

kubeconfig文件(默认路径~/.kube/config)权限必须设为600,权限过高会被kubectl拒绝:

chmod 600 ~/.kube/config

2. 确认IAM实体的集群访问权限

即使AWS CLI能正常工作,也要确保当前使用的IAM用户/角色已被授权访问EKS集群:

  • 先查看当前身份:
aws sts get-caller-identity
  • 复制返回的ARN,检查是否在EKS集群的aws-auth ConfigMap中:
kubectl get configmap aws-auth -n kube-system -o yaml
  • 如果不在,编辑该ConfigMap添加授权:
kubectl edit configmap aws-auth -n kube-system

在mapUsers或mapRoles节点下添加对应配置,示例:

mapUsers:
- userarn: arn:aws:iam::123456789012:user/你的用户名
  username: 你的用户名
  groups:
  - system:masters

3. 重新生成kubeconfig

可能之前的kubeconfig生成有问题,重新执行命令并指定AWS配置文件(如果有多个):

aws eks update-kubeconfig --region eu-west-1 --name my-cluster --profile 你的AWS配置文件名称

4. 切换到正确的kubectl上下文

确认kubectl当前使用的是目标EKS集群的上下文:

kubectl config get-contexts

找到对应集群的上下文名称,切换过去:

kubectl config use-context my-cluster.eu-west-1.eksctl.io

5. 检查网络连通性

确保你的机器能访问EKS集群的API端点:

  • 如果集群是私有端点,需要在VPC内访问,或通过VPN/Direct Connect连接到VPC
  • 检查安全组是否允许你的IP访问集群API端口(443)

内容的提问来源于stack exchange,提问作者welu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 20:50:31