You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

单节点集群安装Cilium遇pod反亲和性规则匹配失败问题

解决单节点K8s集群安装Cilium时的didn't match pod anti-affinity rules错误

问题原因

你遇到的调度失败是因为Cilium Operator默认配置了强制Pod反亲和性规则,要求所有io.cilium/app=operator的Pod不能调度到同一节点(通过topologyKey: kubernetes.io/hostname限制)。但你的集群是单节点架构,无法满足这个规则,导致Pod无法被调度。

解决方案

以下两种方法任选其一即可:

方法1:安装Cilium时直接禁用Operator的反亲和性

如果还未完成Cilium安装,在安装命令中添加参数跳过反亲和性检查:

  • 使用Cilium CLI安装:
cilium install --set operator.antiAffinity=None
  • 使用Helm安装:
helm install cilium cilium/cilium --version <你的Cilium版本> \
  --namespace kube-system \
  --set operator.antiAffinity=None

方法2:修改已部署的Cilium Operator Deployment

如果已经发起安装但Pod调度失败,直接编辑Operator的Deployment配置:

  1. 打开Deployment编辑界面:
kubectl edit deployment cilium-operator -n kube-system
  1. 找到affinity.podAntiAffinity配置块,将requiredDuringSchedulingIgnoredDuringExecution部分替换为软亲和性规则(或直接删除整个podAntiAffinity块):
    修改后的示例配置:
affinity:
  podAntiAffinity:
    preferredDuringSchedulingIgnoredDuringExecution:
    - weight: 100
      podAffinityTerm:
        labelSelector:
          matchLabels:
            io.cilium/app: operator
        topologyKey: kubernetes.io/hostname
  1. 保存退出后,Kubernetes会自动重建Operator Pod,此时Pod就能在单节点上正常调度。

内容的提问来源于stack exchange,提问作者Chris G.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 21:15:36