执行kubectl get pods持续报错:服务器要求提供凭证
解决EKS集群kubectl认证失败问题
问题背景
执行命令更新EKS集群的kubeconfig:
aws eks update-kubeconfig --region eu-west-1 --name my-cluster
之后运行kubectl get pods时,持续抛出认证错误:
E1229 13:04:42.538976 82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E1229 13:04:42.873405 82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E1229 13:04:43.208848 82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E1229 13:04:43.561855 82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials E1229 13:04:43.896372 82870 memcache.go:238] couldn't get current server API group list: the server has asked for the client to provide credentials error: You must be logged in to the server (the server has asked for the client to provide credentials)
注:本地AWS CLI配置已验证可用。
排查与解决步骤
1. 修复kubeconfig文件权限
kubeconfig文件(默认路径~/.kube/config)权限必须设为600,权限过高会被kubectl拒绝:
chmod 600 ~/.kube/config
2. 确认IAM实体的集群访问权限
即使AWS CLI能正常工作,也要确保当前使用的IAM用户/角色已被授权访问EKS集群:
- 先查看当前身份:
aws sts get-caller-identity
- 复制返回的ARN,检查是否在EKS集群的
aws-authConfigMap中:
kubectl get configmap aws-auth -n kube-system -o yaml
- 如果不在,编辑该ConfigMap添加授权:
kubectl edit configmap aws-auth -n kube-system
在mapUsers或mapRoles节点下添加对应配置,示例:
mapUsers: - userarn: arn:aws:iam::123456789012:user/你的用户名 username: 你的用户名 groups: - system:masters
3. 重新生成kubeconfig
可能之前的kubeconfig生成有问题,重新执行命令并指定AWS配置文件(如果有多个):
aws eks update-kubeconfig --region eu-west-1 --name my-cluster --profile 你的AWS配置文件名称
4. 切换到正确的kubectl上下文
确认kubectl当前使用的是目标EKS集群的上下文:
kubectl config get-contexts
找到对应集群的上下文名称,切换过去:
kubectl config use-context my-cluster.eu-west-1.eksctl.io
5. 检查网络连通性
确保你的机器能访问EKS集群的API端点:
- 如果集群是私有端点,需要在VPC内访问,或通过VPN/Direct Connect连接到VPC
- 检查安全组是否允许你的IP访问集群API端口(443)
内容的提问来源于stack exchange,提问作者welu
相关产品推荐
相关产品推荐

