【问题标题】:HPA cannot get metrics due to 403 errors由于 403 错误,HPA 无法获取指标
【发布时间】:2020-07-22 08:15:53
【问题描述】:

我在 hpa 中使用了以下指标

apiVersion: autoscaling/v2beta2
kind: HorizontalPodAutoscaler
metadata:
  name: app-svc-hpa
  namespace: default
spec:
  scaleTargetRef:
    apiVersion: extensions/v1beta1
    kind: Deployment
    name: app-svc
  minReplicas: 1
  maxReplicas: 1000
  metrics:
  - type: Resource
    resource:
      name: cpu
      target:
        type: Utilization
        averageUtilization: 50
  - type: Pods
    pods:
      metric:
        name: packets-per-second
      target:
        type: AverageValue
        averageValue: 1k

但 hpa 无法获取指标

Warning FailedGetPodsMetric 14s (x6 over 1m) horizontal-pod-autoscaler unable to get metric packets-per-second: unable to fetch metrics from custom metrics API: the server could not find the descriptor for metric custom.googleapis.com/packets-per-second: googleapi: Error 403: Permission monitoring.metricDescriptors.get denied (or the resource may not exist)., forbidden

我在专用节点池上运行 pod,每个节点都在服务帐户下运行。

服务帐户确实具有这些 iam 角色

监控查看器, 监控指标编写器

不确定如何解决此错误。非常感谢任何指针。谢谢。

【问题讨论】:

  • 您提到了 IAM 角色,它是否在 EKS 上运行?您是否尝试在没有服务帐户的情况下进行部署?您是否向度量服务器添加了正确的权限?
  • 它在 Google Cloud Kubernetes Engine 上运行
  • 您是否在当前配置中使用 RBAC?
  • 不,我没有使用 RBAC
  • 您遇到的错误指向权限被拒绝或缺少名为 packets-per-second 的指标。有一个与您的配置非常相似的 GCP 指南:Cloud.google.com: HPA。它提到packets-per-second 是一个需要创建的自定义指标。您是否创建了此指标?你能在GCP->Monitoring->Metrics Explorer 中看到这个指标吗?

标签: kubernetes google-kubernetes-engine horizontal-pod-autoscaling


【解决方案1】:

我有一个启用了workload identity 的集群。显然,当集群启用了工作负载身份时,指标获取失败。

1) 我必须安装自定义堆栈驱动程序适配器并创建 David Kruk 在他的 cmets 中指出的自定义指标

2) 我必须在自定义堆栈驱动程序适配器部署 pod 规范中添加 hostNetwork:true。这个问题在 csa 的 github 存储库中提到了 here

通过这两个更新,自动缩放器按预期工作。

【讨论】:

    猜你喜欢
    • 2019-08-09
    • 2021-07-12
    • 1970-01-01
    • 2020-07-03
    • 1970-01-01
    • 2020-04-27
    • 2019-09-07
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多