You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubeadm搭建K8s集群中Metallb Webhook调用失败求助

问题描述

集群环境

本地通过kubeadm搭建的Kubernetes集群,版本信息如下:

clientVersion:
  buildDate: "2022-10-12T10:57:26Z"
  compiler: gc
  gitCommit: 434bfd82814af038ad94d62ebe59b133fcb50506
  gitTreeState: clean
  gitVersion: v1.25.3
  goVersion: go1.19.2
  major: "1"
  minor: "25"
  platform: linux/amd64
kustomizeVersion: v4.5.7
serverVersion:
  buildDate: "2022-10-12T10:49:09Z"
  compiler: gc
  gitCommit: 434bfd82814af038ad94d62ebe59b133fcb50506
  gitTreeState: clean
  gitVersion: v1.25.3
  goVersion: go1.19.2
  major: "1"
  minor: "25"
  platform: linux/amd64

MetalLB安装情况

安装版本为MetalLB v0.13.7,安装命令:

kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/v0.13.7/config/manifests/metallb-native.yaml

安装完成后,metallb-system命名空间下所有资源运行正常:

$ kubectl get all -n metallb-system
 
NAME                              READY   STATUS    RESTARTS   AGE
pod/controller-84d6d4db45-l2r55   1/1     Running   0          35s
pod/speaker-48qn4                 1/1     Running   0          35s
pod/speaker-ds8hh                 1/1     Running   0          35s
pod/speaker-pfbcp                 1/1     Running   0          35s
pod/speaker-st7n2                 1/1     Running   0          35s

NAME                      TYPE        CLUSTER-IP      EXTERNAL-IP   PORT(S)   AGE
service/webhook-service   ClusterIP   10.104.14.119   <none>        443/TCP   35s

NAME                     DESIRED   CURRENT   READY   UP-TO-DATE   AVAILABLE   NODE SELECTOR            AGE
daemonset.apps/speaker   4         4         4       4            4           kubernetes.io/os=linux   35s

NAME                         READY   UP-TO-DATE   AVAILABLE   AGE
deployment.apps/controller   1/1     1            1           35s

NAME                                    DESIRED   CURRENT   READY   AGE
replicaset.apps/controller-84d6d4db45   1         1         1       35s

错误现象

应用IPAddressPool CRD配置文件(命令:kubectl apply -f ipaddresspool.yaml)时触发错误。
ipaddresspool.yaml内容:

apiVersion: metallb.io/v1beta1
kind: IPAddressPool
metadata:
  name: first-pool
  namespace: metallb-system
spec:
  addresses:
  - 192.168.2.100-192.168.2.199

错误信息:

Error from server (InternalError): error when creating "ipaddresspool.yaml": Internal error occurred: failed calling webhook "ipaddresspoolvalidationwebhook.metallb.io": failed to call webhook: Post "https://webhook-service.metallb-system.svc:443/validate-metallb-io-v1beta1-ipaddresspool?timeout=10s": dial tcp 10.104.14.119:443: connect: no route to host

换行后清晰版错误:

Error from server (InternalError): 
error when creating "ipaddresspool.yaml": 
Internal error occurred: failed calling webhook "ipaddresspoolvalidationwebhook.metallb.io": 
failed to call webhook: 
Post "https://webhook-service.metallb-system.svc:443/validate-metallb-io-v1beta1-ipaddresspool?timeout=10s": 
dial tcp 10.104.14.119:443: connect: no route to host

已确认webhook-service的ClusterIP正确:

NAME              TYPE        CLUSTER-IP      EXTERNAL-IP   PORT(S)   AGE
webhook-service   ClusterIP   10.104.14.119   <none>        443/TCP   18m

尝试过Helm安装MetalLB v0.13.7,问题复现。另一套同问题集群的webhook-service描述:

$ kubectl describe svc webhook-service -n metallb-system

Name:              webhook-service
Namespace:         metallb-system
Labels:            <none>
Annotations:       <none>
Selector:          component=controller
Type:              ClusterIP
IP Family Policy:  SingleStack
IP Families:       IPv4
IP:                10.105.157.72
IPs:               10.105.157.72
Port:              <unset>  443/TCP
TargetPort:        9443/TCP
Endpoints:         172.17.0.3:9443
Session Affinity:  None
Events:            <none>

排查与解决方案

1. 验证ClusterIP与Pod的连通性

  • 在集群任意节点或运行中的Pod内,执行ping 10.104.14.119测试webhook-service的ClusterIP可达性。若无法ping通,说明集群网络插件(如Calico、Flannel)存在异常,需检查网络插件Pod状态及节点间网络是否正常。
  • 直接访问controller Pod的端点(如另一集群中的172.17.0.3:9443):curl -k https://<controller-pod-ip>:9443/validate-metallb-io-v1beta1-ipaddresspool。若能正常返回,说明ClusterIP到Pod的路由存在问题,需排查kube-proxy状态或iptables规则。

2. 检查kube-apiserver节点的网络权限

kube-apiserver所在节点必须能访问ClusterIP网段(默认是10.96.0.0/12或自定义Service CIDR)。检查节点防火墙、iptables规则是否拦截了ClusterIP的443端口流量,必要时临时关闭防火墙测试。

3. 临时禁用Webhook验证(仅用于排查)

若需快速验证IPAddressPool配置本身是否有效,可临时删除MetalLB的验证webhook:

kubectl delete validatingwebhookconfiguration metallb-webhook-configuration

之后重新应用IPAddressPool配置,若成功则说明问题集中在webhook的证书或连通性环节。

4. 检查Webhook证书状态

MetalLB的webhook依赖自签名证书,确认证书Secret是否正常存在:

kubectl get secrets -n metallb-system webhook-server-cert

若证书缺失或过期,删除该Secret并重启controller Pod,让系统重新生成证书:

kubectl delete secret webhook-server-cert -n metallb-system
kubectl rollout restart deployment controller -n metallb-system

5. 确认kube-apiserver的Webhook支持

检查kube-apiserver的启动参数是否包含--enable-admission-plugins=ValidatingAdmissionWebhook,若未启用需修改kube-apiserver配置文件并重启服务。


内容的提问来源于stack exchange,提问作者AxdorphCoder

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 21:21:02