You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

受限网络下为Kubernetes集群安装Weave Net插件遇超时问题求助

解决受限网络环境下Kubectl连接超时问题(Weave Net安装失败)

问题核心分析

你遇到的超时错误,本质是kubectl无法和Kubernetes API Server建立稳定连接,或者容器运行时无法拉取Weave镜像——哪怕用本地YAML,镜像拉取环节仍依赖外网/代理配置。下面是针对性的解决步骤:


1. 给kubectl配置代理环境变量

集群安装时的代理是给组件用的,kubectl作为客户端需要单独配置:

  • 临时生效(当前shell会话):
    export HTTP_PROXY=http://你的代理IP:端口
    export HTTPS_PROXY=http://你的代理IP:端口
    # 注意:NO_PROXY必须包含集群内部IP段,避免代理本地/集群内部请求
    export NO_PROXY=127.0.0.1,localhost,10.96.0.0/12,192.168.0.0/16
    
  • 永久生效:把上面三行追加到~/.bashrc或~/.zshrc,执行source ~/.bashrc重载配置。

2. 给容器运行时配置代理(关键!)

Weave的DaemonSet需要拉取weaveworks/weave-kube和weaveworks/weave-npc镜像,容器运行时(Docker/containerd)必须配置代理才能拉取:

针对Docker:

  1. 创建/修改/etc/docker/daemon.json:
    {
      "proxies": {
        "default": {
          "httpProxy": "http://你的代理IP:端口",
          "httpsProxy": "http://你的代理IP:端口",
          "noProxy": "localhost,127.0.0.1,集群内部IP段"
        }
      }
    }
    
  2. 重启Docker服务:
    systemctl restart docker
    

针对containerd:

  1. 编辑/etc/containerd/config.toml,找到[plugins."io.containerd.grpc.v1.cri".registry.mirrors]下方的代理配置段,填入:
    [plugins."io.containerd.grpc.v1.cri".registry.configs]
      [plugins."io.containerd.grpc.v1.cri".registry.configs."docker.io".auth]
      [plugins."io.containerd.grpc.v1.cri".registry.configs."docker.io".proxy]
        http_proxy = "http://你的代理IP:端口"
        https_proxy = "http://你的代理IP:端口"
        no_proxy = "localhost,127.0.0.1,集群内部IP段"
    
  2. 重启containerd服务:
    systemctl restart containerd
    

3. 离线导入镜像(代理失效时的终极方案)

如果代理配置后还是无法拉取镜像,直接在联网机器上打包镜像,传到集群节点离线导入:

  1. 联网机器上拉取镜像:
    docker pull weaveworks/weave-kube:2.8.1
    docker pull weaveworks/weave-npc:2.8.1
    
  2. 打包成tar文件:
    docker save -o weave-images.tar weaveworks/weave-kube:2.8.1 weaveworks/weave-npc:2.8.1
    
  3. 把tar文件传到集群所有节点,加载镜像:
    docker load -i weave-images.tar
    
  4. 再执行本地YAML安装:
    kubectl apply -f weave-daemonset-k8s.yaml
    

4. 检查kubeconfig的API Server地址

确认~/.kube/config里的server字段是集群内部可访问的IP,比如如果之前填了公网IP但受限网络无法访问,改成API Server的内网IP(示例:https://192.168.0.100:6443)。


内容的提问来源于stack exchange,提问作者kaushal47

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 22:31:18