You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform创建仅含私有子网EKS集群时节点组创建失败问题

错误成因

  • 你使用的terraform-aws-modules/vpc/aws模块中,map_public_ip_on_launch参数仅对公网子网生效,私有子网默认本身就关闭了自动分配公网IP的属性,你修改这个参数不会影响私有子网的行为。
  • AWS EKS托管节点组的aws_eks_node_group资源默认开启了associate_public_ip_address = true,默认要求加入节点组的EC2实例具备公网IP,当你把节点组部署在没有自动分配公网IP能力的私有子网时,就会触发配置不匹配错误。

解决方案

直接在你的aws_eks_node_group资源块里添加associate_public_ip_address = false参数即可,显式告知EKS不要给私有子网的节点关联公网IP,无需修改VPC侧现有配置。

修改后的eks-workers.tf节点组配置参考:

resource "aws_eks_node_group" "EKS_NG" {
  for_each = var.eks_node_groups
  cluster_name = aws_eks_cluster.ds-eks-airflow.name
  node_group_name =  each.key
  node_role_arn = var.create_role? aws_iam_role.ds-eks-airflow-node[0].arn : var.node_rolearn
  subnet_ids = local.private_subnet_ids
  instance_types = [each.value.instance_type]
  capacity_type =  each.value.capacity_type
  # 新增该行,关闭公网IP关联
  associate_public_ip_address = false

  scaling_config {
    desired_size = each.value.desired_size
    max_size     = each.value.max_size
    min_size     = each.value.min_size
  }
  
  remote_access {
     ec2_ssh_key = each.value.ec2_ssh_key
     source_security_group_ids = [ aws_security_group.ds-eks-airflow-node.id ]
  }
 
  tags = each.value.tags
  labels = each.value.labels

  depends_on = [
    aws_iam_role_policy_attachment.AmazonEKSWorkerNodePolicy,
    aws_iam_role_policy_attachment.AmazonEKS_CNI_Policy,
    aws_iam_role_policy_attachment.AmazonEC2ContainerRegistryReadOnly,
    aws_eks_cluster.ds-eks-airflow,
    aws_security_group.ds-eks-airflow-node
  ]
}

注意:请确保你的VPC私有子网路由表已经配置了NAT网关转发规则,保证节点可以访问EKS、ECR等必要的AWS服务,否则节点仍无法正常加入集群。

内容的提问来源于stack exchange,提问作者Karthik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.26 09:24:00