Microk8s启用DNS后Pod卡在ContainerCreating状态求助
Looking at the logs you shared, the core issue is obvious: your kubelet can’t sync the secret and ConfigMap caches, which leads to volume mounting timeouts for the CoreDNS pod. Let’s walk through practical, actionable steps to diagnose and fix this:
Step 1: Check Health of Core MicroK8s Components
First, make sure the foundational services are running properly:
- Verify the kubelet status:
systemctl status snap.microk8s.daemon-kubelet - Check containerd (the container runtime MicroK8s uses):
systemctl status snap.microk8s.daemon-containerd
If either service is stopped or throwing errors, restart them with:
sudo systemctl restart snap.microk8s.daemon-kubelet sudo systemctl restart snap.microk8s.daemon-containerd
Step 2: Test API Server Connectivity
The kubelet relies on the Kubernetes API Server to fetch secrets and ConfigMaps. Test if your node can reach the API Server:
- Use the cluster IP from your
kubectl get servicesoutput (10.152.183.1):curl -k https://10.152.183.1:443
A successful response will return JSON listing API versions. If this fails, check the API Server logs for issues:
microk8s.kubectl logs -n kube-system pod/kube-apiserver-peza-ubuntu-19
Step 3: Clear Corrupted Kubelet Cache
Corrupted cache is a frequent cause of volume mounting failures. Let’s clean it up:
- Stop MicroK8s:
microk8s stop - Delete the kubelet cache directory:
sudo rm -rf /var/snap/microk8s/current/var/lib/kubelet/cache - Restart MicroK8s:
microk8s start
Wait 1-2 minutes, then check if CoreDNS starts:
microk8s.kubectl get pods -n kube-system
Step 4: Recreate CoreDNS Resources
If the issue persists, the CoreDNS service account or associated secrets/ConfigMaps might be corrupted. Reset the DNS add-on:
- Disable DNS:
microk8s.disable dns - Delete the CoreDNS service account (forces a new token secret to be created):
microk8s.kubectl delete serviceaccount coredns -n kube-system - Re-enable DNS:
microk8s.enable dns
Step 5: Troubleshoot VirtualBox Network
Since you’re running Ubuntu in VirtualBox, network glitches between the node and API Server could be blocking communication:
- Confirm the node’s IP (10.0.2.15) is reachable and not conflicting with other devices.
- Temporarily disable Ubuntu’s firewall to rule out blocking:
sudo ufw disable - Check if iptables rules are interfering with Kubernetes traffic:
iptables -L -n | grep -E "kube|coredns"
If you see unexpected block rules, reset iptables (note: this clears all custom rules):
sudo iptables -F && sudo iptables -t nat -F && sudo iptables -t mangle -F && sudo iptables -X
After trying these steps, your CoreDNS pod should transition to a Running state. If it still doesn’t work, share the updated kubectl describe pod output and we can dig deeper.
内容的提问来源于stack exchange,提问作者Peter Zandbergen

