Kubeadm搭建K8s集群中Metallb Webhook调用失败求助
集群环境
本地通过kubeadm搭建的Kubernetes集群,版本信息如下:
clientVersion: buildDate: "2022-10-12T10:57:26Z" compiler: gc gitCommit: 434bfd82814af038ad94d62ebe59b133fcb50506 gitTreeState: clean gitVersion: v1.25.3 goVersion: go1.19.2 major: "1" minor: "25" platform: linux/amd64 kustomizeVersion: v4.5.7 serverVersion: buildDate: "2022-10-12T10:49:09Z" compiler: gc gitCommit: 434bfd82814af038ad94d62ebe59b133fcb50506 gitTreeState: clean gitVersion: v1.25.3 goVersion: go1.19.2 major: "1" minor: "25" platform: linux/amd64
MetalLB安装情况
安装版本为MetalLB v0.13.7,安装命令:
kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/v0.13.7/config/manifests/metallb-native.yaml
安装完成后,metallb-system命名空间下所有资源运行正常:
$ kubectl get all -n metallb-system NAME READY STATUS RESTARTS AGE pod/controller-84d6d4db45-l2r55 1/1 Running 0 35s pod/speaker-48qn4 1/1 Running 0 35s pod/speaker-ds8hh 1/1 Running 0 35s pod/speaker-pfbcp 1/1 Running 0 35s pod/speaker-st7n2 1/1 Running 0 35s NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE service/webhook-service ClusterIP 10.104.14.119 <none> 443/TCP 35s NAME DESIRED CURRENT READY UP-TO-DATE AVAILABLE NODE SELECTOR AGE daemonset.apps/speaker 4 4 4 4 4 kubernetes.io/os=linux 35s NAME READY UP-TO-DATE AVAILABLE AGE deployment.apps/controller 1/1 1 1 35s NAME DESIRED CURRENT READY AGE replicaset.apps/controller-84d6d4db45 1 1 1 35s
错误现象
应用IPAddressPool CRD配置文件(命令:kubectl apply -f ipaddresspool.yaml)时触发错误。
ipaddresspool.yaml内容:
apiVersion: metallb.io/v1beta1 kind: IPAddressPool metadata: name: first-pool namespace: metallb-system spec: addresses: - 192.168.2.100-192.168.2.199
错误信息:
Error from server (InternalError): error when creating "ipaddresspool.yaml": Internal error occurred: failed calling webhook "ipaddresspoolvalidationwebhook.metallb.io": failed to call webhook: Post "https://webhook-service.metallb-system.svc:443/validate-metallb-io-v1beta1-ipaddresspool?timeout=10s": dial tcp 10.104.14.119:443: connect: no route to host
换行后清晰版错误:
Error from server (InternalError): error when creating "ipaddresspool.yaml": Internal error occurred: failed calling webhook "ipaddresspoolvalidationwebhook.metallb.io": failed to call webhook: Post "https://webhook-service.metallb-system.svc:443/validate-metallb-io-v1beta1-ipaddresspool?timeout=10s": dial tcp 10.104.14.119:443: connect: no route to host
已确认webhook-service的ClusterIP正确:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE webhook-service ClusterIP 10.104.14.119 <none> 443/TCP 18m
尝试过Helm安装MetalLB v0.13.7,问题复现。另一套同问题集群的webhook-service描述:
$ kubectl describe svc webhook-service -n metallb-system Name: webhook-service Namespace: metallb-system Labels: <none> Annotations: <none> Selector: component=controller Type: ClusterIP IP Family Policy: SingleStack IP Families: IPv4 IP: 10.105.157.72 IPs: 10.105.157.72 Port: <unset> 443/TCP TargetPort: 9443/TCP Endpoints: 172.17.0.3:9443 Session Affinity: None Events: <none>
排查与解决方案
1. 验证ClusterIP与Pod的连通性
- 在集群任意节点或运行中的Pod内,执行
ping 10.104.14.119测试webhook-service的ClusterIP可达性。若无法ping通,说明集群网络插件(如Calico、Flannel)存在异常,需检查网络插件Pod状态及节点间网络是否正常。 - 直接访问controller Pod的端点(如另一集群中的
172.17.0.3:9443):curl -k https://<controller-pod-ip>:9443/validate-metallb-io-v1beta1-ipaddresspool。若能正常返回,说明ClusterIP到Pod的路由存在问题,需排查kube-proxy状态或iptables规则。
2. 检查kube-apiserver节点的网络权限
kube-apiserver所在节点必须能访问ClusterIP网段(默认是10.96.0.0/12或自定义Service CIDR)。检查节点防火墙、iptables规则是否拦截了ClusterIP的443端口流量,必要时临时关闭防火墙测试。
3. 临时禁用Webhook验证(仅用于排查)
若需快速验证IPAddressPool配置本身是否有效,可临时删除MetalLB的验证webhook:
kubectl delete validatingwebhookconfiguration metallb-webhook-configuration
之后重新应用IPAddressPool配置,若成功则说明问题集中在webhook的证书或连通性环节。
4. 检查Webhook证书状态
MetalLB的webhook依赖自签名证书,确认证书Secret是否正常存在:
kubectl get secrets -n metallb-system webhook-server-cert
若证书缺失或过期,删除该Secret并重启controller Pod,让系统重新生成证书:
kubectl delete secret webhook-server-cert -n metallb-system kubectl rollout restart deployment controller -n metallb-system
5. 确认kube-apiserver的Webhook支持
检查kube-apiserver的启动参数是否包含--enable-admission-plugins=ValidatingAdmissionWebhook,若未启用需修改kube-apiserver配置文件并重启服务。
内容的提问来源于stack exchange,提问作者AxdorphCoder

