单节点虚拟机指定公网主机名启动OpenShift Origin 3.11失败
I1021 16:48:50.515745 21486 run_self_hosted.go:557] Server isn't healthy yet. Waiting a little while. Get https://103.231.8.164:8443/healthz?timeout=32s: dial tcp 103.231.8.164:8443: connect: connection refused
I1021 16:48:51.516680 21486 run_self_hosted.go:557] Server isn't healthy yet. Waiting a little while. Get https://103.231.8.164:8443/healthz?timeout=32s: dial tcp 103.231.8.164:8443: connect: connection refused
I1021 16:48:51.517328 21486 run_self_hosted.go:557] Server isn't healthy yet. Waiting a little while. Get https://103.231.8.164:8443/healthz?timeout=32s: dial tcp 103.231.8.164:8443: connect: connection refused
E1021 16:48:51.517364 21486 run_self_hosted.go:571] API server error: Get https://103.231.8.164:8443/healthz?timeout=32s: dial tcp 103.231.8.164:8443: connect: connection refused ()
Error: timed out waiting for the condition
- 指定的公网IP
103.231.8.164未正确绑定到CentOS 8主机的网卡上,API Server无法在对应IP上监听端口 - 主机防火墙未放行8443、80、443等OKD集群必需的服务端口,访问请求被拦截
- OKD 3.11与CentOS 8的兼容性适配不足,指定公网IP时未自动配置对应的网卡IP别名
- SELinux默认策略拦截了API Server绑定非本机默认IP端口的请求
1. 确认IP绑定配置
执行ip addr命令检查103.231.8.164是否在主机网卡的地址列表中,若不存在执行以下命令临时绑定:
ip addr add 103.231.8.164/32 dev 你的网卡名称(如eth0、ens33等)
如需永久生效,修改/etc/sysconfig/network-scripts/ifcfg-你的网卡名配置文件添加对应的IP配置项。
2. 放行防火墙端口
依次执行以下命令放开OKD集群所需的端口规则:
firewall-cmd --add-port=8443/tcp --permanent firewall-cmd --add-port=80/tcp --permanent firewall-cmd --add-port=443/tcp --permanent firewall-cmd --add-port=53/udp --permanent firewall-cmd --add-port=4789/udp --permanent firewall-cmd --reload
3. 临时关闭SELinux验证
执行setenforce 0临时关闭SELinux,避免策略拦截服务启动,后续可按需配置对应的SELinux放行规则。
4. 重置集群状态后重新启动
先关闭残留的集群进程并删除本地缓存文件:
oc cluster down rm -rf ~/.kube/ /var/lib/origin/openshift.local.clusterup/
再执行带公网主机名参数的启动命令:
oc cluster up --public-hostname=103.231.8.164
可选兼容性适配
如果上述操作后仍启动失败,可在启动命令中额外添加兼容性参数:
oc cluster up --public-hostname=103.231.8.164 --skip-registry-check=true --enable-excluded-versions=true
内容的提问来源于stack exchange,提问作者D Developer

