GKE集群升级至1.8/1.9后Nginx Ingress Controller部署报错求助
GKE集群升级后Nginx Ingress Controller部署问题解决
我来帮你梳理下这两个问题的原因和解决办法,都是升级到1.8/1.9版本后常见的兼容性问题:
问题1:使用旧镜像gcr.io/google_containers/nginx-ingress-controller:0.8.3的报错
Using build: https://github.com/bprashanth/contrib.git - git-92b2bac
这个报错本质是镜像版本太老,和K8s 1.8+的API及生态不兼容:
- 这个镜像基于的是旧的contrib仓库分支,现在Nginx Ingress Controller的官方代码已经迁移到kubernetes/ingress-nginx项目,旧镜像对新版本K8s的API支持不足
- 你的配置里用的是
ReplicationController(RC),而K8s 1.8+推荐用Deployment来管理Pod副本,RC的功能已被Deployment替代,旧镜像对Deployment的适配性较差
问题2:使用quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.9.0的RBAC权限报错
It seems the cluster it is running with Authorization enabled (like RBAC) and there is no permissions for the ingress controller. Please check the configuration
GKE从1.8版本开始默认启用RBAC权限控制,而你的配置里没有给Ingress Controller分配必要的API访问权限,导致它无法获取Ingress、Service等集群资源信息,进而启动失败。
完整的修正配置方案
我调整了你的配置,解决了上面两个问题,你可以直接使用:
1. 先创建RBAC权限资源(必须,解决权限问题)
apiVersion: v1 kind: ServiceAccount metadata: name: nginx-ingress-serviceaccount namespace: production # 和Ingress Controller的--watch-namespace保持一致 --- apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRole metadata: name: nginx-ingress-clusterrole rules: - apiGroups: [""] resources: ["configmaps", "endpoints", "nodes", "pods", "secrets"] verbs: ["list", "watch"] - apiGroups: [""] resources: ["services"] verbs: ["get", "list", "watch"] - apiGroups: ["extensions"] resources: ["ingresses"] verbs: ["get", "list", "watch"] - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] - apiGroups: ["extensions"] resources: ["ingresses/status"] verbs: ["update"] --- apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRoleBinding metadata: name: nginx-ingress-clusterrole-binding roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: nginx-ingress-clusterrole subjects: - kind: ServiceAccount name: nginx-ingress-serviceaccount namespace: production
2. 替换默认后端和Ingress Controller为Deployment(替代旧的RC)
# 默认后端服务 apiVersion: v1 kind: Service metadata: name: default-http-backend namespace: production labels: k8s-app: default-http-backend spec: ports: - port: 80 targetPort: 8080 protocol: TCP name: http selector: k8s-app: default-http-backend --- # 默认后端Deployment(替代RC) apiVersion: apps/v1 kind: Deployment metadata: name: default-http-backend namespace: production spec: replicas: 1 selector: matchLabels: k8s-app: default-http-backend template: metadata: labels: k8s-app: default-http-backend spec: terminationGracePeriodSeconds: 60 containers: - name: default-http-backend image: gcr.io/google_containers/defaultbackend:1.0 livenessProbe: httpGet: path: /healthz port: 8080 scheme: HTTP initialDelaySeconds: 30 timeoutSeconds: 5 ports: - containerPort: 8080 resources: limits: cpu: 10m memory: 20Mi requests: cpu: 10m memory: 20Mi --- # Nginx Ingress Controller服务(可根据需求调整为LoadBalancer) apiVersion: v1 kind: Service metadata: name: nginx-ingress-controller namespace: production labels: k8s-app: nginx-ingress-lb spec: type: NodePort ports: - port: 80 targetPort: 80 protocol: TCP name: http - port: 443 targetPort: 443 protocol: TCP name: https selector: k8s-app: nginx-ingress-lb --- # Nginx Ingress Controller Deployment(替代RC) apiVersion: apps/v1 kind: Deployment metadata: name: nginx-ingress-controller namespace: production labels: k8s-app: nginx-ingress-lb spec: replicas: 1 selector: matchLabels: k8s-app: nginx-ingress-lb template: metadata: labels: k8s-app: nginx-ingress-lb name: nginx-ingress-lb spec: terminationGracePeriodSeconds: 60 serviceAccountName: nginx-ingress-serviceaccount # 关联RBAC的ServiceAccount containers: - image: quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.20.0 # 兼容1.8/1.9的稳定版本 name: nginx-ingress-lb imagePullPolicy: Always readinessProbe: httpGet: path: /healthz port: 10254 scheme: HTTP livenessProbe: httpGet: path: /healthz port: 10254 scheme: HTTP initialDelaySeconds: 10 timeoutSeconds: 1 env: - name: POD_NAME valueFrom: fieldRef: fieldPath: metadata.name - name: POD_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace ports: - containerPort: 80 - containerPort: 443 - containerPort: 18080 # 用于nginx状态监控 args: - /nginx-ingress-controller - --default-backend-service=$(POD_NAMESPACE)/default-http-backend - --nginx-configmap=$(POD_NAMESPACE)/nginx-ingress-cfg - --watch-namespace=production
额外注意事项
- 我选择了
0.20.0版本的镜像,这个版本对K8s 1.8/1.9兼容性较好,你也可以选择官方推荐的同系列稳定版本 - 所有资源都指定了
namespace: production,和Ingress Controller的--watch-namespace保持一致,避免权限范围冲突 - 如果你的集群未启用RBAC(GKE 1.8+默认启用),可以跳过RBAC相关配置,但建议保留RBAC以提升集群安全性
内容的提问来源于stack exchange,提问作者montatich
相关产品推荐
相关产品推荐

