部署Busybox卡ContainerCreating,Kubelet报x509未知证书签名错误求助
Hey there, let's work through this x509 certificate issue that's keeping your busybox pod stuck in ContainerCreating. This is a super common problem when dealing with self-signed certificates or private image registries in Kubernetes, especially on CentOS 7.3 with K8s 1.9.0.
问题根源
The error x509: certificate signed by unknown authority means your kubelet doesn't trust the SSL certificate used by the image registry you're pulling from. This could be a private registry with a self-signed cert, or a registry whose CA cert isn't installed in your CentOS node's trusted root store.
解决方案步骤
1. 添加镜像仓库CA证书到系统信任根目录
This is the proper, production-safe fix:
- First, get hold of the CA certificate file (usually a
.crtfile) for your image registry. If you're using a self-signed cert from the kubernetes-the-hard-way setup, you should already have this file handy. - Copy the certificate to CentOS's trusted anchor directory:
sudo cp your-registry-ca.crt /etc/pki/ca-trust/source/anchors/ - Update the system's trusted certificate store:
sudo update-ca-trust extract - Restart kubelet to pick up the new trust settings:
sudo systemctl restart kubelet
2. 临时跳过证书验证(仅限测试环境)
If you're just testing and don't want to deal with cert setup right now, you can configure kubelet to skip registry certificate checks. Do NOT use this in production:
- Edit your kubelet service config file (usually located at
/etc/systemd/system/kubelet.service.d/10-kubeadm.confor similar):
Add the--insecure-registryflag pointing to your registry address, like:Environment="KUBELET_EXTRA_ARGS=--insecure-registry=your-registry-ip:port" - Reload systemd and restart kubelet:
sudo systemctl daemon-reload sudo systemctl restart kubelet
验证修复效果
After applying either fix, check if the pod starts up:
kubectl get pods
You can also tail the kubelet logs to confirm the certificate error is gone:
journalctl -u kubelet -f
额外注意事项
- Make sure you distribute the CA certificate to all worker nodes in your cluster if you have multiple nodes.
- CentOS 7 uses
update-ca-trust extractto refresh the trust store; other distros might use different commands likeupdate-ca-certificates. - Avoid using
--insecure-registryin production environments—it exposes your cluster to man-in-the-middle attacks.
内容的提问来源于stack exchange,提问作者Tony Iams

