GKE部署Kubernetes时kube-dns无法连接api-server求助
Got it, let's break down what's happening here. The 10.32.0.1 address is the default ClusterIP for the Kubernetes API server in Kelsey Hightower's guide, but GKE assigns its own unique ClusterIP to the internal kubernetes service by default. That mismatch is why kube-dns can't reach the API server and keeps crashing. Here's how to fix it step by step:
1. Find GKE's Actual Kubernetes Service ClusterIP
First, let's get the correct address that kube-dns should be using:
# Check your cluster's API server details kubectl cluster-info # Get the ClusterIP of the default kubernetes service kubectl get service kubernetes -n default
You'll see the ClusterIP here is something like 10.0.0.1 (not 10.32.0.1). Jot that down—we'll need it in the next step.
2. Download and Modify the kube-dns YAML
Grab the official YAML file from the guide to edit locally:
curl -O https://storage.googleapis.com/kubernetes-the-hard-way/kube-dns.yaml
Open the file in your favorite editor, then find the args section for the kube-dns container. Add a --server flag pointing to the ClusterIP you just found, formatted as https://<your-cluster-ip>:443.
Your modified args should look something like this:
args: - --domain=cluster.local. - --dns-port=10053 - --config-dir=/kube-dns-config - --v=2 - --server=https://10.0.0.1:443 # Replace with your actual ClusterIP
Double-check the rest of the YAML for any other references to 10.32.0.1 (like in configmaps or kubeconfig volumes) and replace those too if you find them.
3. Redeploy kube-dns
First, clean up the broken deployment:
kubectl delete -f https://storage.googleapis.com/kubernetes-the-hard-way/kube-dns.yaml
Then deploy your modified local file:
kubectl create -f ./kube-dns.yaml
4. Verify the Fix
Wait a minute or two, then check the pod status to see if it's running:
kubectl get pods -n kube-system -l k8s-app=kube-dns
You should see it show Running with 3/3 containers ready. To be extra sure, check the logs to confirm no more timeout errors:
kubectl logs -n kube-system <kube-dns-pod-name> kube-dns
Extra Checks If It's Still Broken
If you're still having issues, here a couple more things to verify:
- Make sure the kube-dns service account has the necessary permissions to list services and endpoints (the default setup should handle this, but it's worth checking)
- Confirm there are no network policies in the
kube-systemnamespace blocking traffic to the Kubernetes service - Test if the pod can resolve
kubernetes.default.svc.cluster.local(you can exec into the pod and runnslookup kubernetesto check)
内容的提问来源于stack exchange,提问作者christian

