You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins Kubernetes插件无法创建jnlp-slave Pod问题求助

Jenkins Kubernetes Plugin 1.5 Won’t Create JNLP Slave Pods (Jenkins Master Outside Kubernetes)

Environment Overview

From your setup details, here’s the context we’re working with:

  • Jenkins 2.107.1 running outside your Kubernetes cluster (no plans to migrate it into K8s short-term)
  • Kubernetes Plugin 1.5 installed in Jenkins
  • Kubernetes 1.10.0 cluster on Ubuntu 17.04 VMs (4 nodes total, master node has no taints)
  • Docker 17.03.2-ce on all nodes
  • Kubernetes cluster is fully functional: nginx services deploy successfully, dashboard is accessible without restrictions

Troubleshooting Steps & Fixes

Let’s walk through the most common issues and how to resolve them:

1. Confirm Jenkins Can Connect to Kubernetes

First, make sure the plugin can reach your K8s API server and has proper permissions:

  • Head to Manage Jenkins > Configure System > Cloud > Kubernetes
    • Double-check the Kubernetes URL (use your master node’s API endpoint, e.g., https://<master-ip>:6443)
    • Verify the Kubernetes Namespace (default is default—use the one you intend for slave pods)
    • Click Test Connection—if it fails:
      • Check network rules: Ensure your Jenkins master can reach port 6443 on the K8s master (firewalls, security groups, etc.)
      • Fix RBAC permissions: The service account Jenkins uses needs permissions to create pods, services, and other resources. For testing, assign the cluster-admin role (lock this down later for production):
        kubectl create clusterrolebinding jenkins-cluster-admin --clusterrole=cluster-admin --serviceaccount=<your-namespace>:jenkins
        

2. Fix JNLP Slave Image Mismatches

The default image might not play nice with your Jenkins/K8s version combo:

  • In the plugin’s Pod Templates section, update the Docker image to a compatible tag. For Jenkins 2.107.1 and K8s 1.10.0, jenkins/jnlp-slave:3.27-1 is a safe bet (match the image’s Jenkins version to your master where possible)
  • Confirm your cluster nodes can pull the image: Run docker pull jenkins/jnlp-slave:3.27-1 on a node to test; if it fails, use a local registry or check network access to Docker Hub

3. Dig Into Jenkins Logs for Specific Errors

Logs will tell you exactly what’s breaking:

  • Go to Manage Jenkins > System Log
  • Filter for entries containing "Kubernetes" or "jnlp"—look for:
    • Permission denied messages (RBAC issues)
    • Image pull failures
    • Pod creation timeouts or forbidden errors
  • Example red flag: Failed to create pod: pods "jenkins-slave-xxxx" is forbidden: User "system:serviceaccount:default:jenkins" cannot create pods in the namespace "default"

4. Validate Pod Template Configuration

A misconfigured template is a common culprit:

  • In Pod Templates, ensure:
    • The template has a name (e.g., jnlp-slave)
    • The container template is named jnlp
    • The Command field is blank (the plugin handles the JNLP command automatically)
    • The Arguments are set to ${computer.jnlpmac} ${computer.name}
    • If using node selectors, confirm they match labels on your cluster nodes (leave blank if you want pods to schedule anywhere)

5. Check Node Taints & Tolerations

Even though your master node has no taints, other nodes might block slave pods:

  • Run kubectl describe nodes on all nodes to check for taints
  • If you find taints, add matching tolerations in the Jenkins pod template’s Tolerations section

6. Verify Docker Health on Cluster Nodes

Kubernetes relies on Docker, so make sure it’s running smoothly:

  • On each node, run systemctl status docker to confirm the service is active
  • Check that Docker has the correct permissions (avoid using host sockets in production, but if you are, ensure the socket is accessible to the K8s service account)

内容的提问来源于stack exchange,提问作者Steve Maring

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:23:21