You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署Busybox卡ContainerCreating,Kubelet报x509未知证书签名错误求助

解决Kubernetes拉取镜像时x509证书认证失败的问题

Hey there, let's work through this x509 certificate issue that's keeping your busybox pod stuck in ContainerCreating. This is a super common problem when dealing with self-signed certificates or private image registries in Kubernetes, especially on CentOS 7.3 with K8s 1.9.0.

问题根源

The error x509: certificate signed by unknown authority means your kubelet doesn't trust the SSL certificate used by the image registry you're pulling from. This could be a private registry with a self-signed cert, or a registry whose CA cert isn't installed in your CentOS node's trusted root store.

解决方案步骤

1. 添加镜像仓库CA证书到系统信任根目录

This is the proper, production-safe fix:

  • First, get hold of the CA certificate file (usually a .crt file) for your image registry. If you're using a self-signed cert from the kubernetes-the-hard-way setup, you should already have this file handy.
  • Copy the certificate to CentOS's trusted anchor directory:
    sudo cp your-registry-ca.crt /etc/pki/ca-trust/source/anchors/
    
  • Update the system's trusted certificate store:
    sudo update-ca-trust extract
    
  • Restart kubelet to pick up the new trust settings:
    sudo systemctl restart kubelet
    

2. 临时跳过证书验证(仅限测试环境)

If you're just testing and don't want to deal with cert setup right now, you can configure kubelet to skip registry certificate checks. Do NOT use this in production:

  • Edit your kubelet service config file (usually located at /etc/systemd/system/kubelet.service.d/10-kubeadm.conf or similar):
    Add the --insecure-registry flag pointing to your registry address, like:
    Environment="KUBELET_EXTRA_ARGS=--insecure-registry=your-registry-ip:port"
    
  • Reload systemd and restart kubelet:
    sudo systemctl daemon-reload
    sudo systemctl restart kubelet
    

验证修复效果

After applying either fix, check if the pod starts up:

kubectl get pods

You can also tail the kubelet logs to confirm the certificate error is gone:

journalctl -u kubelet -f

额外注意事项

  • Make sure you distribute the CA certificate to all worker nodes in your cluster if you have multiple nodes.
  • CentOS 7 uses update-ca-trust extract to refresh the trust store; other distros might use different commands like update-ca-certificates.
  • Avoid using --insecure-registry in production environments—it exposes your cluster to man-in-the-middle attacks.

内容的提问来源于stack exchange,提问作者Tony Iams

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:30:51