You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenStack环境下Kubernetes LoadBalancer外部IP Pending问题求助

Troubleshooting LoadBalancer External IP Pending in OpenStack + Kubernetes (kubeadm + Calico)

Hey there! Let's work through this LoadBalancer pending issue you're facing. As someone who's debugged this exact scenario a few times, here's a step-by-step breakdown of the most common fixes:

1. First: Deploy the OpenStack Cloud Controller Manager (CCM)

This is the #1 reason for LoadBalancer pending in OpenStack setups with kubeadm. Kubernetes doesn't natively know how to talk to OpenStack's Neutron service—you need the OpenStack CCM to bridge that gap. It handles creating Neutron load balancers, assigning floating IPs, and syncing state between K8s and OpenStack.

  • Check if CCM is already running:
    kubectl get pods -n kube-system | grep openstack
    
    If you see no output, you need to deploy it:
    • Create a cloud.conf file with your OpenStack credentials (auth URL, username, password, project ID, region, etc.)
    • Store this as a Secret in the kube-system namespace:
      kubectl create secret generic cloud-config --from-file=cloud.conf -n kube-system
      
    • Deploy the CCM Deployment (make sure the YAML references the cloud-config Secret and matches your K8s version)

2. Verify Calico and OpenStack Network Compatibility

Calico's network setup needs to play nice with OpenStack's underlying network:

  • Check for CIDR conflicts: Ensure Calico's Pod CIDR doesn't overlap with your OpenStack subnets. Verify with:
    kubectl get configmap calico-config -n kube-system -o yaml | grep cidr
    
  • If using Calico in IPIP mode: Make sure OpenStack security groups allow IPIP traffic (protocol 4) between nodes.
  • If using BGP mode: Ensure TCP port 179 is open between K8s nodes for BGP peering.

3. Validate OpenStack User Permissions

The OpenStack user you're using for K8s needs enough permissions to manage load balancers and floating IPs:

  • Test with the OpenStack CLI to confirm:
    # Try creating a test load balancer
    openstack loadbalancer create --name test-lb --vip-subnet-id <your-subnet-id>
    # Try creating a floating IP
    openstack floating ip create <your-external-network-id>
    
    If these commands fail, your user lacks permissions. Assign roles like load-balancer_admin or ensure the member role has the necessary Neutron and Octavia permissions.

4. Check Your LoadBalancer Service Configuration

Double-check your Service YAML for common mistakes:

  • Ensure spec.type: LoadBalancer is set correctly
  • If you specified spec.loadBalancerIP, confirm that floating IP exists in OpenStack and isn't already in use
  • Verify the spec.ports match the NodeJS Pod's listening port
  • Avoid misconfiguring externalTrafficPolicy (unless you know what you're doing, leave it as the default Cluster)

5. Dig into CCM Logs (If Deployed)

If you already have CCM running, check its logs for error details:

kubectl logs -n kube-system <openstack-ccm-pod-name>

Look for errors like authentication failures, missing subnets, or permission denied messages—these will point you directly to the root cause.


内容的提问来源于stack exchange,提问作者Yummel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 07:42:50