{"id":7420,"date":"2021-12-22T17:37:18","date_gmt":"2021-12-22T09:37:18","guid":{"rendered":"https:\/\/nj.transwarp.cn:8180\/?p=7420"},"modified":"2025-11-17T18:23:52","modified_gmt":"2025-11-17T10:23:52","slug":"kubelet%e8%af%81%e4%b9%a6%e8%bf%87%e6%9c%9f%e9%97%ae%e9%a2%98","status":"publish","type":"post","link":"https:\/\/kbwp.transwarp.cn\/?p=7420","title":{"rendered":"kubelet\u8bc1\u4e66\u8fc7\u671f\u95ee\u9898"},"content":{"rendered":"<h3>\u6982\u8981\u63cf\u8ff0<\/h3>\n<p>\u95ee\u9898\u63cf\u8ff0<br \/>\nTDH6.x\u548cTOS1.9.x\u7248\u672c\u4e0akubelet\u76ee\u524d\u6ca1\u6709\u914d\u7f6e\u81ea\u52a8\u66f4\u65b0\u8bc1\u4e66\uff0c\u5bfc\u81f4\u4e00\u5e74\u65f6\u95f4\u8bc1\u4e66\u4f1a\u8fc7\u671f\uff0c\u8fdb\u800c\u5bfc\u81f4\u8282\u70b9\u72b6\u6001NotReady\uff08\u6b63\u5e38\u8282\u70b9\u6267\u884c<code>kubectl get nodes<\/code>\u67e5\u770b\uff09\uff0c\u670d\u52a1\u4e0d\u53ef\u7528\uff1b<\/p>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640079409260.png\" alt=\"file\" \/><\/p>\n<p>kubelet\u65e5\u5fd7\u62a5\u9519\u4fe1\u606f\uff1a<\/p>\n<pre><code class=\"language-shell\">12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: E1219 12:43:15.809165   90772 reflector.go:205] k8s.io\/kubernetes\/pkg\/kubelet\/kubelet.go:492: Failed to list *v1.Node: Unauthorized\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: I1219 12:43:15.809432   90772 reflector.go:240] Listing and watching *v1.ConfigMap from k8s.io\/kubernetes\/pkg\/kubelet\/kubelet.go:500\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: I1219 12:43:15.809937   90772 round_trippers.go:436] GET https:\/\/127.0.0.1:6443\/api\/v1\/pods?fieldSelector=spec.nodeName%3Dkm4-hcb-compute-01&amp;limit=500&amp;resourceVersion=0 401 Unauthorized in 1 milliseconds\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: E1219 12:43:15.810063   90772 reflector.go:205] k8s.io\/kubernetes\/pkg\/kubelet\/config\/apiserver.go:47: Failed to list *v1.Pod: Unauthorized\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: I1219 12:43:15.810517   90772 reflector.go:240] Listing and watching *v1.Service from k8s.io\/kubernetes\/pkg\/kubelet\/kubelet.go:483\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: I1219 12:43:15.810933   90772 round_trippers.go:436] GET https:\/\/127.0.0.1:6443\/api\/v1\/namespaces\/kube-system\/configmaps?limit=500&amp;resourceVersion=0 401 Unauthorized in 1 milliseconds\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: E1219 12:43:15.811035   90772 reflector.go:205] k8s.io\/kubernetes\/pkg\/kubelet\/kubelet.go:500: Failed to list *v1.ConfigMap: Unauthorized\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: I1219 12:43:15.811850   90772 round_trippers.go:436] GET https:\/\/127.0.0.1:6443\/api\/v1\/services?limit=500&amp;resourceVersion=0 401 Unauthorized in 1 milliseconds\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: E1219 12:43:15.812001   90772 reflector.go:205] k8s.io\/kubernetes\/pkg\/kubelet\/kubelet.go:483: Failed to list *v1.Service: Unauthorized\n12\u6708 19 12:43:15 km4-hcb-compute-01 hyperkube[90772]: I1219 12:43:15.822999   90772 volume_host.go:218] using default mounter\/exec for kubernetes.io\/secret<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640079365545.png\" alt=\"file\" \/><\/p>\n<p><strong>\u5f71\u54cd\u7248\u672c<\/strong><\/p>\n<p>TDH 6.X,TOS 1.9.X<\/p>\n<h3>\u8be6\u7ec6\u8bf4\u660e<\/h3>\n<h4>workround\u65b9\u6848<\/h4>\n<p><strong>\u91cd\u542fkubelet<\/strong><\/p>\n<p>\u6240\u6709\u8282\u70b9\u6267\u884c <code>systemctl restart kubelet<\/code>\u3002<\/p>\n<h4>\u6c38\u4e45\u89e3\u51b3\u65b9\u6848<\/h4>\n<pre><code>\u6ce8\u610f\uff1a \u4ee5\u4e0b\u6b65\u9aa4\u9700\u8981\u5728\u96c6\u7fa4\u4e2d\u6240\u6709\u8282\u70b9\uff08\u6b63\u5e38\u8282\u70b9\u64cd\u4f5c\u662f\u4e3a\u4e86\u9632\u6b62\u540e\u7eed\u51fa\u73b0\u8bc1\u4e66\u8fc7\u671f\u95ee\u9898\uff09\u6267\u884c\u3002<\/code><\/pre>\n<ol>\n<li>\u67e5\u770b\u8d77\u6b62\u65f6\u95f4<\/li>\n<\/ol>\n<pre><code class=\"language-shell\">[root@jiujiu-tdh-70 ~]# openssl x509 -in \/var\/lib\/kubelet\/pki\/kubelet.crt -noout -text | grep 'Not'\n            Not Before: Sep 29 16:36:48 2020 GMT\n            Not After : Sep 29 16:36:48 2021 GMT<\/code><\/pre>\n<ol start=\"2\">\n<li>\u505c\u6b62kubelet\uff1b<\/li>\n<\/ol>\n<pre><code class=\"language-shell\">systemctl stop kubelet<\/code><\/pre>\n<ol start=\"3\">\n<li>\u4fee\u6539 kubelet \u914d\u7f6e\u6587\u4ef6<\/li>\n<\/ol>\n<p>\u5728\u8282\u70b9\u4e0a\u627e\u5230 <code>\/usr\/lib\/systemd\/system\/kubelet.service <\/code>\u6587\u4ef6\uff0c\u5728\u6587\u4ef6\u91cc\u9762\u52a0\u4e0a<code>--rotate-certificates \\<\/code> \u548c <code>--feature-gates=<\/code> \u540e\u9762\u52a0\u4e0a <code>RotateKubeletClientCertificate=true,RotateKubeletServerCertificate=true,<\/code> \uff0c\u4f7f\u4e4b\u53ef\u4ee5<strong>\u81ea\u52a8\u66f4\u65b0\u8bc1\u4e66<\/strong>\uff1b<br \/>\n\u4fee\u6539\u7684\u5730\u65b9\uff0c\u5982\u4e0b\u56fe<br \/>\n<img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640081843892.png\" alt=\"file\"><\/p>\n<ol start=\"4\">\n<li>\u5907\u4efd\u548c\u5220\u9664<code>\/var\/lib\/kubelet\/pki<\/code><\/li>\n<\/ol>\n<pre><code class=\"language-shell\"># \u5907\u4efd\u5230tmp\u76ee\u5f55\u4e0b\uff1a\ncp -r \/var\/lib\/kubelet\/pki  \/tmp\/<\/code><\/pre>\n<pre><code class=\"language-shell\"># \u5220\u9664\nrm -rf \/var\/lib\/kubelet\/pki<\/code><\/pre>\n<ol start=\"5\">\n<li>\u91cd\u542fkubelet<\/li>\n<\/ol>\n<pre><code class=\"language-shell\">systemctl daemon-reload &amp;&amp; systemctl restart kubelet\uff08\u82e5\u542f\u52a8\u5931\u8d25\uff0c\u8df3\u5230\u6b65\u9aa47\uff09<\/code><\/pre>\n<ol start=\"6\">\n<li>\u9a8c\u8bc1<\/li>\n<\/ol>\n<pre><code class=\"language-shell\"># \u9a8c\u8bc1\u53c2\u6570\u662f\u5426\u6dfb\u52a0\u6210\u529f\nsystemctl status kubelet -l | grep rotate-certificates<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640142393498.png\" alt=\"file\"><\/p>\n<pre><code class=\"language-shell\"># \u5728\u672a\u4fee\u6539\u7684\u8282\u70b9\u6267\u884c\u4e0b\u9762\u547d\u4ee4\uff0c\u67e5\u770b\u4fee\u6539\u7684\u8282\u70b9\u72b6\u6001\u662f\u5426\u6b63\u5e38\uff08\u662f\u5426\u4e3aready\uff0c\u5982\u679c\u4e0d\u662f\u5219\u770b\u6b65\u9aa47\uff09\nkubectl get nodes -owide<\/code><\/pre>\n<pre><code class=\"language-shell\"># \u662f\u5426\u53ef\u4ee5\u67e5\u770b\u8bc1\u4e66\u8d77\u6b62\u65f6\u95f4\uff08\u5982\u679c\u62a5\u9519\uff0c\u8bf7\u53c2\u89c1\u540e\u9762\u6b65\u9aa47\uff09\nopenssl x509 -in \/var\/lib\/kubelet\/pki\/kubelet.crt -noout -text | grep 'Not'<\/code><\/pre>\n<ol start=\"7\">\n<li>\u5176\u4ed6\u60c5\u51b5<\/li>\n<\/ol>\n<p>\u5982\u679c\u8282\u70b9not ready \u5e76\u4e14\u4f7f\u7528\u6b65\u9aa41\u7684\u67e5\u770b\u8bc1\u4e66\u547d\u4ee4\u62a5\u9519 <code>No such file or directory<\/code><br \/>\n\u4f8b\u5982\uff0c \u4fee\u6539\u4e86 jiujiu-tdh-72\u7684\u914d\u7f6e\uff0c\u5728\u6b63\u5e38\u7684jiujiu-tdh-70\u8282\u70b9\u6267\u884c <code>kubectl get nodes<\/code>\u547d\u4ee4\u770b\u5230 72\u8282\u70b9 not ready\uff0c\u6267\u884c\u67e5\u770b\u8bc1\u4e66\u7684\u8d77\u6b62\u65f6\u95f4\u7684\u547d\u4ee4\uff0c\u62a5\u9519\u5982\u4e0b\u56fe\u3002<br \/>\n<img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640153123871.png\" alt=\"file\"><\/p>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640153086389.png\" alt=\"file\"><\/p>\n<p>\u6b64\u95ee\u9898\u89e3\u51b3\u65b9\u6848\uff1a<\/p>\n<ol>\n<li>\n<p>\u5728\u6545\u969c\u8282\u70b9\u83b7\u53d6<strong>Pending<\/strong>\u72b6\u6001\u7684csr name<\/p>\n<pre><code class=\"language-shell\">kubectl get csr<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640153383617.png\" alt=\"file\"><\/p>\n<\/li>\n<li>\n<p>\u624b\u52a8 approve CSR \u8bf7\u6c42<\/p>\n<pre><code class=\"language-shell\">kubectl certificate approve <\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640154031852.png\" alt=\"file\"><\/p>\n<\/li>\n<li>\n<p>\u83b7\u53d6node\u7684\u72b6\u6001<\/p>\n<pre><code class=\"language-shell\">kubectl get nodes<\/code><\/pre>\n<\/li>\n<li>\n<p>approve \u540e \u67e5\u770b\u8bc1\u4e66\u65f6\u95f4\uff08\u4e0e\u6b65\u9aa46\u7684\u4e0d\u540c\uff09<\/p>\n<pre><code class=\"language-shell\">openssl x509 -in \/var\/lib\/kubelet\/pki\/kubelet-server-current.pem -noout -text | grep 'Not'<\/code><\/pre>\n<\/li>\n<\/ol>\n<h3>\u5176\u4ed6\u95ee\u9898\u8bf4\u660e<\/h3>\n<hr \/>\n<h4>\u4e00. \u90e8\u5206TOS\u7248\u672c\u8fd8\u4f1a\u4e00\u76f4\u4ea7\u751fpending\u72b6\u6001\u7684csr<\/h4>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640157804062.png\" alt=\"file\"><\/p>\n<p><strong>\u95ee\u9898\u539f\u56e0<\/strong> <\/p>\n<p>\u5927\u6982\u7387\u662f\u96c6\u7fa4\u7684rcba\u6743\u9650\u7f3a\u5931\u5bfc\u81f4\u7684\u3002<\/p>\n<p><strong>\u89e3\u51b3\u65b9\u6848<\/strong><\/p>\n<ol>\n<li>\u5c06<a href=\"\/wp-content\/uploads\/2021\/12\/kubelet.tar.gz\" title=\"kubelet.tar\">kubelet.tar<\/a> \u653e\u5230\u8282\u70b9\u4e0a\u89e3\u538b\uff0c \u5728\u89e3\u538b\u7684\u76ee\u5f55\u4e0b\u6267\u884c\u4e0b\u97623\u4e2a\u547d\u4ee4\u5c06\u4e09\u4e2a\u914d\u7f6e\u6587\u4ef6apply\u5230kubelet\u91cc\u9762\u3002\u5728TOS1.9.X-TOS2.1.X\u90fd\u6709\u6548\u3002\n<pre><code class=\"language-shell\">kubectl apply -f  clusterrolebinding-rbac.yaml<\/code><\/pre>\n<pre><code class=\"language-shell\">kubectl apply -f  clusterrole-rbac.yaml<\/code><\/pre>\n<pre><code class=\"language-shell\">kubectl apply -f   system-node-proxier.yaml<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640158008148.png\" alt=\"file\"><\/p>\n<\/li>\n<li>\u91cd\u542fkubelet\n<pre><code class=\"language-shell\">systemctl daemon-reload &amp;&amp; systemctl restart kubelet<\/code><\/pre>\n<\/li>\n<li>\u6309\u7167 <strong>\u6c38\u4e45\u89e3\u51b3\u65b9\u6848<\/strong> \u4e2d\u7684\u6b65\u9aa47 \uff0c \u5c06pending\u7684csr \u5168\u90e8 approve\u6389\uff0c \u5e76\u901a\u8fc7<code>kubectl get nodes<\/code> \u547d\u4ee4\u68c0\u67e5\u8282\u70b9\u72b6\u6001\u3002<\/li>\n<li>\u68c0\u67e5  <code>\/var\/lib\/kubelet\/pki<\/code>\u4e0b\u6709\u6ca1\u6709\u751f\u6210<code>kubelet-server-<date>.pem<\/date><\/code> \u548c<code> kubelet-server-current.pem<\/code>\u4e24\u4e2a\u8bc1\u4e66\u6587\u4ef6\uff1b\u5982\u679c\u6ca1\u6709\uff0c \u591a\u5c1d\u8bd5\u51e0\u6b21\u672c\u95ee\u9898\u7684\u6b65\u9aa42\u548c3\u3002<\/li>\n<\/ol>\n<h4>\u4e8c.\u56de\u9000\u6b65\u9aa4<\/h4>\n<ol>\n<li>\n<p>\u505c\u6b62kubelet\uff1b<\/p>\n<pre><code class=\"language-shell\">systemctl stop kubelet<\/code><\/pre>\n<\/li>\n<li>\n<p>\u4fee\u6539 kubelet \u914d\u7f6e\u6587\u4ef6<br \/>\n\u5c06 <code>\/usr\/lib\/systemd\/system\/kubelet.service <\/code>\u6587\u4ef6\u4e2d\u7684<code>--rotate-certificates \\<\/code> \u548c <code>--feature-gates=<\/code> \u540e\u9762\u7684 <code>RotateKubeletClientCertificate=true,RotateKubeletServerCertificate=true,<\/code> \u5220\u6389\uff1b<br \/>\n\u9700\u8981\u5220\u6389\u7684\u5730\u65b9\uff0c\u5982\u4e0b\u56fe<br \/>\n<img decoding=\"async\" src=\"\/wp-content\/uploads\/2021\/12\/image-1640081843892.png\" alt=\"file\"><\/p>\n<\/li>\n<li>\n<p>\u5907\u4efd\u548c\u5220\u9664<code>\/var\/lib\/kubelet\/pki<\/code><\/p>\n<pre><code class=\"language-shell\"># \u5907\u4efd\u5230tmp\u76ee\u5f55\u4e0b\uff1a\ncp -ru \/var\/lib\/kubelet\/pki  \/tmp\/bak<\/code><\/pre>\n<pre><code class=\"language-shell\"># \u5220\u9664\nrm -rf \/var\/lib\/kubelet\/pki<\/code><\/pre>\n<\/li>\n<li>\n<p>\u91cd\u542fkubelet, \u91cd\u65b0\u751f\u6210\u8bc1\u4e66\u6587\u4ef6<\/p>\n<pre><code class=\"language-shell\">systemctl daemon-reload &amp;&amp; systemctl restart kubelet<\/code><\/pre>\n<\/li>\n<li>\n<p>\u67e5\u770bnode\u72b6\u6001<\/p>\n<pre><code class=\"language-shell\">kubectl get nodes<\/code><\/pre>\n<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981\u63cf\u8ff0 \u95ee\u9898\u63cf\u8ff0 TDH6.x\u548cTOS1.9.x\u7248\u672c\u4e0akubelet\u76ee\u524d\u6ca1\u6709\u914d\u7f6e\u81ea\u52a8\u66f4\u65b0\u8bc1\u4e66\uff0c\u5bfc\u81f4\u4e00\u5e74\u65f6\u95f4\u8bc1 ..<\/p>\n<div class=\"clear-fix\"><\/div>\n<p><a href=\"https:\/\/kbwp.transwarp.cn\/?p=7420\" title=\"read more...\">Read more<\/a><\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7420","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"_links":{"self":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/7420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7420"}],"version-history":[{"count":5,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/7420\/revisions"}],"predecessor-version":[{"id":17703,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/7420\/revisions\/17703"}],"wp:attachment":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7420"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7420"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}