EKS集群nodeSelector不生效求助:Jenkins未按标签调度至指定节点
问题:EKS集群中NodeSelector无法按预期调度Jenkins Pod到指定节点
我正在创建一个EKS集群,期望Jenkins运行在Jenkins节点、Nexus运行在Nexus节点,因此尝试使用nodeSelector,但未达到预期效果,不清楚遗漏了哪部分配置。
我的配置文件
cluster.yaml(eksctl集群配置)
apiVersion: eksctl.io/v1alpha5 kind: ClusterConfig metadata: name: Devops-Test region: ap-south-1 vpc: id: vpc-xxxxxx cidr: "192.168.0.0/16" subnets: public: ap-south-1a: id: subnet-xxxx ap-south-1b: id: subnet-xxxx private: ap-south-1a: id: subnet-xxxx ap-south-1b: id: subnet-xxxx nodeGroups: - name: jenkins-public-node-group tags: { role: "jenkins" } instanceType: t2.medium desiredCapacity: 2 - name: jenkins-private-node-group tags: { role: "jenkins" } instanceType: t2.medium desiredCapacity: 2 privateNetworking: true - name: nexus-public-node-group tags: { role: "nexus" } instanceType: t2.medium desiredCapacity: 2 - name: nexus-private-node-group tags: { role: "nexus" } instanceType: t2.medium desiredCapacity: 2 privateNetworking: true
deployment.yaml(Jenkins部署配置)
apiVersion: apps/v1 kind: Deployment metadata: name: devops-tools namespace: devops spec: replicas: 2 selector: matchLabels: role: jenkins template: metadata: labels: role: jenkins spec: nodeSelector: role: jenkins containers: - name: jenkins image: jenkins:2.60.3 ports: - containerPort: 8080
service.yaml(Jenkins服务配置)
apiVersion: v1 kind: Service metadata: name: jenkins-service namespace: devops spec: type: NodePort selector: role: jenkins ports: - nodePort: 31429 port: 8080 targetPort: 8080
我期望Jenkins仅运行在标记有role:jenkins的节点上,但它也会运行在无该标签的节点上。我甚至尝试执行命令kubectl label nodes role=jenkins后重新应用deployment.yaml,但Jenkins仍会调度至无该标签的节点。
解决方案
1. 核心问题:eksctl的tags是EC2实例标签,而非Kubernetes节点标签
你在cluster.yaml中给nodeGroups设置的tags只会给EC2实例打上AWS资源标签,不会自动同步为Kubernetes节点的标签。Kubernetes调度器识别的是节点上的K8s原生标签,所以需要额外配置让eksctl直接设置K8s节点标签。
修改cluster.yaml,给每个nodeGroup添加labels字段(这才是Kubernetes节点标签),同时保留tags(可选,用于AWS资源识别):
nodeGroups: - name: jenkins-public-node-group tags: { role: "jenkins" } labels: { role: "jenkins" } # 添加该行,设置K8s节点标签 instanceType: t2.medium desiredCapacity: 2 - name: jenkins-private-node-group tags: { role: "jenkins" } labels: { role: "jenkins" } # 添加该行 instanceType: t2.medium desiredCapacity: 2 privateNetworking: true - name: nexus-public-node-group tags: { role: "nexus" } labels: { role: "nexus" } # 添加该行 instanceType: t2.medium desiredCapacity: 2 - name: nexus-private-node-group tags: { role: "nexus" } labels: { role: "nexus" } # 添加该行 instanceType: t2.medium desiredCapacity: 2 privateNetworking: true
2. 修复已存在节点的标签(无需重建集群)
如果已经创建了集群,不用重新部署,直接给现有节点打上正确的K8s标签:
- 查看所有节点:
kubectl get nodes - 给Jenkins节点打标签:
kubectl label nodes <jenkins-node-name> role=jenkins - 给Nexus节点打标签:
kubectl label nodes <nexus-node-name> role=nexus
3. 验证调度配置是否生效
- 确认节点标签正确:
kubectl get nodes --show-labels,检查目标节点是否包含role=jenkins标签 - 重新应用Deployment:
kubectl apply -f deployment.yaml -n devops - 查看Pod调度情况:
kubectl get pods -n devops -o wide,检查NODE列是否为标记了role=jenkins的节点
4. 额外排查点
- 检查Deployment是否存在其他调度规则(如
affinity、tolerations)可能覆盖nodeSelector - 确认节点状态为
Ready:kubectl get nodes,封锁或NotReady的节点不会被调度 - 检查节点资源是否充足:如果Jenkins节点CPU/内存不足,调度器会尝试其他节点,可通过
kubectl describe pod <pod-name> -n devops查看调度事件
内容的提问来源于stack exchange,提问作者Maheedhar Talluri
相关产品推荐
相关产品推荐

