You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 16.04中kubeadm join命令持续超时问题求助

Fixing kubeadm Join Timeout on Ubuntu 16.04 (Xenial)

Hey there, I’ve run into this exact timeout issue when adding worker nodes to a Kubernetes cluster with kubeadm on Ubuntu 16.04 before. Let’s walk through the most likely fixes to get your node joined successfully:

1. Verify Network Connectivity Between Worker and Master

The i/o timeout error almost always points to a network block first. Here’s how to check:

  • Ping the master IP: On your worker node, run ping {{MASTER_IP}} to confirm basic connectivity. If this fails, fix your network routing, subnet rules, or cloud security groups first.
  • Check the K8s API port (6443): The kube-apiserver listens on port 6443 by default. Test if it’s reachable from the worker with:
    nc -zv {{MASTER_IP}} 6443
    
    If this times out, head to your master node and open the port in UFW (Ubuntu’s firewall):
    sudo ufw allow 6443/tcp
    sudo ufw reload
    
    If you’re using a cloud provider (AWS, GCP, etc.), don’t forget to update your security group rules to allow inbound traffic on 6443 from your worker node’s IP/subnet.

2. Ensure the Master’s Kube-APIServer is Running

If the network checks out, the master’s API server might be down or misconfigured. On the master node:

  • List kube-system pods to check the apiserver status:
    kubectl get pods -n kube-system
    
    Look for a pod starting with kube-apiserver-—it should show a Running status.
  • If it’s not running, check the logs for errors:
    kubectl logs kube-apiserver-$(hostname) -n kube-system
    
    Common issues here include invalid TLS certificates or misconfigured kubeconfig files.

3. Use a Fresh Kubeadm Join Command

Kubeadm tokens expire after 24 hours by default. If you’re using an old join command, it’ll fail silently (or with timeouts). Generate a new command on the master:

kubeadm token create --print-join-command

Copy the full output of this command and run it directly on your worker node—this ensures you’re using a valid token and CA hash.

4. Check Worker Node Firewall Rules

Sometimes the worker node’s own firewall blocks outbound traffic to the master’s 6443 port. Test this by temporarily disabling UFW:

sudo ufw disable

Try the join command again. If it works, re-enable UFW and add a rule to allow outbound traffic to the master:

sudo ufw allow out to {{MASTER_IP}} port 6443 proto tcp
sudo ufw enable

5. Validate DNS and Hostname Resolution

Even if you’re using the master’s IP directly, DNS issues on the worker can cause unexpected timeouts. Check if the master IP resolves correctly:

nslookup {{MASTER_IP}}

You can also add an entry for the master in the worker’s /etc/hosts file to eliminate DNS as a variable:

echo "{{MASTER_IP}} kubernetes-master" | sudo tee -a /etc/hosts

6. Confirm Worker Node Runtime and Kubelet Status

Make sure Docker (or your container runtime) and kubelet are running on the worker:

systemctl status docker
systemctl status kubelet

If either is inactive, start and enable them:

sudo systemctl start docker && sudo systemctl enable docker
sudo systemctl restart kubelet && sudo systemctl enable kubelet

Start with the network checks first—they’re the most common culprit. If none of these work, feel free to share more details about your cluster setup (like proxy usage or custom CNI plugins) and we can dig deeper!

内容的提问来源于stack exchange,提问作者Aryak Sengupta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:32:29