【问题标题】:Kubernetes/kops: error attaching EBS volume to instance. You are not authorized to perform this operation. Error 403Kubernetes/kops:将 EBS 卷附加到实例时出错。您无权执行此操作。错误 403
【发布时间】:2018-06-16 08:26:48
【问题描述】:

我在 kops 预置的 AWS 集群上测试了使用 EBS 卷挂载的 kubernetes 部署。这是部署 yml 文件:

apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: helloworld-deployment-volume
spec:
  replicas: 1
  template:
    metadata:
      labels:
        app: helloworld
    spec:
      containers:
      - name: k8s-demo
        image: wardviaene/k8s-demo
        ports:
        - name: nodejs-port
          containerPort: 3000
        volumeMounts:
        - mountPath: /myvol
          name: myvolume
      volumes:
      - name: myvolume
        awsElasticBlockStore:
          volumeID: <volume_id>

kubectl create -f &lt;path_to_this_yml&gt; 之后,我在 pod 描述中收到以下消息:

Attach failed for volume "myvolume" : Error attaching EBS volume "XXX" to instance "YYY": "UnauthorizedOperation: You are not authorized to perform this operation. status code: 403

看起来这只是一个权限问题。好的,我检查了节点角色 IAM -> Roles -> nodes.&lt;my_domain&gt; 的策略,发现没有允许操作卷的操作,默认情况下只有 ec2:DescribeInstances 操作。所以我添加了AttachVolume 和DetachVolume 操作:

    {
        "Sid": "kopsK8sEC2NodePerms",
        "Effect": "Allow",
        "Action": [
            "ec2:DescribeInstances",
            "ec2:AttachVolume",
            "ec2:DetachVolume"
        ],
        "Resource": [
            "*"
        ]
    },

这并没有帮助。我仍然收到该错误:

Attach failed for volume "myvolume" : Error attaching EBS volume "XXX" to instance "YYY": "UnauthorizedOperation: You are not authorized to perform this operation.

我错过了什么吗?

【问题讨论】:

    标签: amazon-web-services amazon-ec2 kubernetes kubectl kops


    【解决方案1】:

    我找到了解决方案。它被描述为here。

    在 kops 1.8.0-beta.1 中,主节点要求您标记 AWS 卷:

    KubernetesCluster:&lt;clustername-here&gt;

    因此有必要使用awscli创建带有该标签的EBS卷:

    aws ec2 create-volume --size 10 --region eu-central-1 --availability-zone eu-central-1a --volume-type gp2 --tag-specifications 'ResourceType=volume,Tags=[{Key=KubernetesCluster,Value=<clustername-here>}]'
    

    或者您可以在EC2 -> Volumes -> Your volume -> Tags 中手动标记它

    就是这样。

    编辑:

    可以在属于集群的 EC2 实例标签中找到正确的集群名称。密钥相同:KubernetesCluster。

    【讨论】:

    • 感谢您的解决方案。但我得到了新的错误。无法为 pod“XXX”挂载卷:等待卷为“XXX”/“XXX”附加/挂载的超时已过期。未附加/卸载的卷列表=[我的卷]。您是否遇到过同样的错误?
    • 有趣。不,我没有遇到过这样的问题,我什至不知道它与什么有关。
    • 我找到了解决方案。问题是由于 xfs FS。此错误与 kubernetes 问题有关。
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2018-12-29
    • 2021-03-06
    • 2021-03-09
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多