使用Helm部署GitLab时Nginx-ingress Pod启动失败求助
解决GitLab Helm安装后的Nginx Ingress RBAC权限及Runner连接问题
一、修复Nginx Ingress的RBAC权限问题
从你的错误日志可以明确定位到问题:nginx-ingress命名空间下的default服务账号没有权限访问该命名空间内的Services资源:
services "default-http-backend" is forbidden: User "system:serviceaccount:nginx-ingress:default" cannot get services in the namespace "nginx-ingress"
按照以下步骤修复权限:
创建一个Role,赋予访问
nginx-ingress命名空间内Services的权限
新建nginx-ingress-role.yaml文件,内容如下:apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: nginx-ingress-services-access namespace: nginx-ingress rules: - apiGroups: [""] resources: ["services"] verbs: ["get", "list", "watch"]执行命令应用配置:
kubectl apply -f nginx-ingress-role.yaml将Role绑定到目标服务账号
新建nginx-ingress-rolebinding.yaml文件,内容如下:apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: nginx-ingress-services-binding namespace: nginx-ingress subjects: - kind: ServiceAccount name: default namespace: nginx-ingress roleRef: kind: Role name: nginx-ingress-services-access apiGroup: rbac.authorization.k8s.io执行命令应用配置:
kubectl apply -f nginx-ingress-rolebinding.yaml重启Nginx Ingress Pod让权限生效
kubectl delete pods -n nginx-ingress -l app=nginx等待Pod重启完成后,检查状态是否正常:
kubectl get pods -n nginx-ingress
二、解决GitLab Runner连接超时问题
Runner日志显示无法连接http://gitlab1-gitlab.default:8005/api/v4/runners并出现I/O超时,核心原因是你的GitLab主Pod(gitlab1-gitlab-75576c4589-lnf56)还处于0/1 Running状态,服务并未就绪。
等你修复完Nginx Ingress问题后,按照以下步骤排查:
- 检查GitLab主Pod的启动日志,确认是否有启动异常:
kubectl logs gitlab1-gitlab-75576c4589-lnf56 -n default - 验证资源使用情况,排查是否因内存/CPU不足导致启动失败:
kubectl top pod gitlab1-gitlab-75576c4589-lnf56 -n default - 确认PVC挂载状态(虽然你提到PVC正常,但可以再次验证):
kubectl describe pvc -n default
等GitLab主服务完全就绪后,重启Runner Pod即可:
kubectl delete pod gitlab1-gitlab-runner-55d458ccb7-g442z -n default
内容的提问来源于stack exchange,提问作者Ivan
相关产品推荐
相关产品推荐

