OpenStack环境下Kubernetes LoadBalancer外部IP Pending问题求助
Hey there! Let's work through this LoadBalancer pending issue you're facing. As someone who's debugged this exact scenario a few times, here's a step-by-step breakdown of the most common fixes:
1. First: Deploy the OpenStack Cloud Controller Manager (CCM)
This is the #1 reason for LoadBalancer pending in OpenStack setups with kubeadm. Kubernetes doesn't natively know how to talk to OpenStack's Neutron service—you need the OpenStack CCM to bridge that gap. It handles creating Neutron load balancers, assigning floating IPs, and syncing state between K8s and OpenStack.
- Check if CCM is already running:
If you see no output, you need to deploy it:kubectl get pods -n kube-system | grep openstack- Create a
cloud.conffile with your OpenStack credentials (auth URL, username, password, project ID, region, etc.) - Store this as a Secret in the
kube-systemnamespace:kubectl create secret generic cloud-config --from-file=cloud.conf -n kube-system - Deploy the CCM Deployment (make sure the YAML references the cloud-config Secret and matches your K8s version)
- Create a
2. Verify Calico and OpenStack Network Compatibility
Calico's network setup needs to play nice with OpenStack's underlying network:
- Check for CIDR conflicts: Ensure Calico's Pod CIDR doesn't overlap with your OpenStack subnets. Verify with:
kubectl get configmap calico-config -n kube-system -o yaml | grep cidr - If using Calico in IPIP mode: Make sure OpenStack security groups allow IPIP traffic (protocol 4) between nodes.
- If using BGP mode: Ensure TCP port 179 is open between K8s nodes for BGP peering.
3. Validate OpenStack User Permissions
The OpenStack user you're using for K8s needs enough permissions to manage load balancers and floating IPs:
- Test with the OpenStack CLI to confirm:
If these commands fail, your user lacks permissions. Assign roles like# Try creating a test load balancer openstack loadbalancer create --name test-lb --vip-subnet-id <your-subnet-id> # Try creating a floating IP openstack floating ip create <your-external-network-id>load-balancer_adminor ensure thememberrole has the necessary Neutron and Octavia permissions.
4. Check Your LoadBalancer Service Configuration
Double-check your Service YAML for common mistakes:
- Ensure
spec.type: LoadBalanceris set correctly - If you specified
spec.loadBalancerIP, confirm that floating IP exists in OpenStack and isn't already in use - Verify the
spec.portsmatch the NodeJS Pod's listening port - Avoid misconfiguring
externalTrafficPolicy(unless you know what you're doing, leave it as the defaultCluster)
5. Dig into CCM Logs (If Deployed)
If you already have CCM running, check its logs for error details:
kubectl logs -n kube-system <openstack-ccm-pod-name>
Look for errors like authentication failures, missing subnets, or permission denied messages—these will point you directly to the root cause.
内容的提问来源于stack exchange,提问作者Yummel

