Ubuntu 16.04中kubeadm join命令持续超时问题求助
Hey there, I’ve run into this exact timeout issue when adding worker nodes to a Kubernetes cluster with kubeadm on Ubuntu 16.04 before. Let’s walk through the most likely fixes to get your node joined successfully:
1. Verify Network Connectivity Between Worker and Master
The i/o timeout error almost always points to a network block first. Here’s how to check:
- Ping the master IP: On your worker node, run
ping {{MASTER_IP}}to confirm basic connectivity. If this fails, fix your network routing, subnet rules, or cloud security groups first. - Check the K8s API port (6443): The kube-apiserver listens on port 6443 by default. Test if it’s reachable from the worker with:
If this times out, head to your master node and open the port in UFW (Ubuntu’s firewall):nc -zv {{MASTER_IP}} 6443
If you’re using a cloud provider (AWS, GCP, etc.), don’t forget to update your security group rules to allow inbound traffic on 6443 from your worker node’s IP/subnet.sudo ufw allow 6443/tcp sudo ufw reload
2. Ensure the Master’s Kube-APIServer is Running
If the network checks out, the master’s API server might be down or misconfigured. On the master node:
- List kube-system pods to check the apiserver status:
Look for a pod starting withkubectl get pods -n kube-systemkube-apiserver-—it should show aRunningstatus. - If it’s not running, check the logs for errors:
Common issues here include invalid TLS certificates or misconfiguredkubectl logs kube-apiserver-$(hostname) -n kube-systemkubeconfigfiles.
3. Use a Fresh Kubeadm Join Command
Kubeadm tokens expire after 24 hours by default. If you’re using an old join command, it’ll fail silently (or with timeouts). Generate a new command on the master:
kubeadm token create --print-join-command
Copy the full output of this command and run it directly on your worker node—this ensures you’re using a valid token and CA hash.
4. Check Worker Node Firewall Rules
Sometimes the worker node’s own firewall blocks outbound traffic to the master’s 6443 port. Test this by temporarily disabling UFW:
sudo ufw disable
Try the join command again. If it works, re-enable UFW and add a rule to allow outbound traffic to the master:
sudo ufw allow out to {{MASTER_IP}} port 6443 proto tcp sudo ufw enable
5. Validate DNS and Hostname Resolution
Even if you’re using the master’s IP directly, DNS issues on the worker can cause unexpected timeouts. Check if the master IP resolves correctly:
nslookup {{MASTER_IP}}
You can also add an entry for the master in the worker’s /etc/hosts file to eliminate DNS as a variable:
echo "{{MASTER_IP}} kubernetes-master" | sudo tee -a /etc/hosts
6. Confirm Worker Node Runtime and Kubelet Status
Make sure Docker (or your container runtime) and kubelet are running on the worker:
systemctl status docker systemctl status kubelet
If either is inactive, start and enable them:
sudo systemctl start docker && sudo systemctl enable docker sudo systemctl restart kubelet && sudo systemctl enable kubelet
Start with the network checks first—they’re the most common culprit. If none of these work, feel free to share more details about your cluster setup (like proxy usage or custom CNI plugins) and we can dig deeper!
内容的提问来源于stack exchange,提问作者Aryak Sengupta

