You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS集群nodeSelector不生效求助:Jenkins未按标签调度至指定节点

问题:EKS集群中NodeSelector无法按预期调度Jenkins Pod到指定节点

我正在创建一个EKS集群,期望Jenkins运行在Jenkins节点、Nexus运行在Nexus节点,因此尝试使用nodeSelector,但未达到预期效果,不清楚遗漏了哪部分配置。

我的配置文件

cluster.yaml(eksctl集群配置)

apiVersion: eksctl.io/v1alpha5
kind: ClusterConfig
metadata:
  name: Devops-Test
  region: ap-south-1

vpc:
  id: vpc-xxxxxx
  cidr: "192.168.0.0/16"
  subnets:
    public:
      ap-south-1a:
        id: subnet-xxxx
      ap-south-1b:
        id: subnet-xxxx
    private:
      ap-south-1a:
        id: subnet-xxxx
      ap-south-1b:
        id: subnet-xxxx

nodeGroups:
  - name: jenkins-public-node-group
    tags: { role: "jenkins" }
    instanceType: t2.medium
    desiredCapacity: 2
  - name: jenkins-private-node-group
    tags: { role: "jenkins" }
    instanceType: t2.medium
    desiredCapacity: 2
    privateNetworking: true
  - name: nexus-public-node-group
    tags: { role: "nexus" }
    instanceType: t2.medium
    desiredCapacity: 2
  - name: nexus-private-node-group
    tags: { role: "nexus" }
    instanceType: t2.medium
    desiredCapacity: 2
    privateNetworking: true

deployment.yaml(Jenkins部署配置)

apiVersion: apps/v1
kind: Deployment
metadata:
  name: devops-tools
  namespace: devops
spec:
  replicas: 2
  selector:
    matchLabels:
      role: jenkins 
  template:
    metadata:
      labels:
        role: jenkins
    spec:
      nodeSelector:
        role: jenkins
      containers:
        - name: jenkins
          image: jenkins:2.60.3
          ports:
            - containerPort: 8080

service.yaml(Jenkins服务配置)

apiVersion: v1
kind: Service
metadata:
  name: jenkins-service
  namespace: devops
spec:
  type: NodePort
  selector:
    role: jenkins
  ports:
    - nodePort: 31429
      port: 8080
      targetPort: 8080

我期望Jenkins仅运行在标记有role:jenkins的节点上,但它也会运行在无该标签的节点上。我甚至尝试执行命令kubectl label nodes role=jenkins后重新应用deployment.yaml,但Jenkins仍会调度至无该标签的节点。


解决方案

1. 核心问题:eksctl的tags是EC2实例标签,而非Kubernetes节点标签

你在cluster.yaml中给nodeGroups设置的tags只会给EC2实例打上AWS资源标签,不会自动同步为Kubernetes节点的标签。Kubernetes调度器识别的是节点上的K8s原生标签,所以需要额外配置让eksctl直接设置K8s节点标签。

修改cluster.yaml,给每个nodeGroup添加labels字段(这才是Kubernetes节点标签),同时保留tags(可选,用于AWS资源识别):

nodeGroups:
  - name: jenkins-public-node-group
    tags: { role: "jenkins" }
    labels: { role: "jenkins" }  # 添加该行,设置K8s节点标签
    instanceType: t2.medium
    desiredCapacity: 2
  - name: jenkins-private-node-group
    tags: { role: "jenkins" }
    labels: { role: "jenkins" }  # 添加该行
    instanceType: t2.medium
    desiredCapacity: 2
    privateNetworking: true
  - name: nexus-public-node-group
    tags: { role: "nexus" }
    labels: { role: "nexus" }  # 添加该行
    instanceType: t2.medium
    desiredCapacity: 2
  - name: nexus-private-node-group
    tags: { role: "nexus" }
    labels: { role: "nexus" }  # 添加该行
    instanceType: t2.medium
    desiredCapacity: 2
    privateNetworking: true

2. 修复已存在节点的标签(无需重建集群)

如果已经创建了集群,不用重新部署,直接给现有节点打上正确的K8s标签:

  • 查看所有节点:kubectl get nodes
  • 给Jenkins节点打标签:kubectl label nodes <jenkins-node-name> role=jenkins
  • 给Nexus节点打标签:kubectl label nodes <nexus-node-name> role=nexus

3. 验证调度配置是否生效

  • 确认节点标签正确:kubectl get nodes --show-labels,检查目标节点是否包含role=jenkins标签
  • 重新应用Deployment:kubectl apply -f deployment.yaml -n devops
  • 查看Pod调度情况:kubectl get pods -n devops -o wide,检查NODE列是否为标记了role=jenkins的节点

4. 额外排查点

  • 检查Deployment是否存在其他调度规则(如affinity、tolerations)可能覆盖nodeSelector
  • 确认节点状态为Ready:kubectl get nodes,封锁或NotReady的节点不会被调度
  • 检查节点资源是否充足:如果Jenkins节点CPU/内存不足,调度器会尝试其他节点,可通过kubectl describe pod <pod-name> -n devops查看调度事件

内容的提问来源于stack exchange,提问作者Maheedhar Talluri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 22:05:26