排查 Debian 上 Kubernetes(k8s)部署故障,建议分层、由下至上进行。下面是一套实战型排查思路 + 常用命令,适用于 kubeadm 部署 的集群(最常见)。
# 系统版本
cat /etc/os-release
# 内核版本(建议 ≥ 4.15)
uname -r
# 时间同步(非常重要)
timedatectl status
✅ 时间不同步会导致证书、etcd、调度异常
# 防火墙(Debian 默认是 nftables/iptables)
iptables -L -n
nft list ruleset
# 临时关闭测试
systemctl stop nftables
systemctl stop ufw
✅ k8s 对 iptables 规则非常敏感
free -m
swapon -s
✅ kubelet 默认不允许 swap
永久关闭:
swapoff -a
sed -i '/swap/s/^/#/' /etc/fstab
systemctl status containerd
journalctl -u containerd -f
检查配置:
containerd config dump | grep -i sandbox
✅ 必须启用 SystemdCgroup
systemctl status docker
journalctl -u docker -f
systemctl status kubelet
journalctl -u kubelet -xe
常见错误:
failed to run kubeletcgroup driver mismatchnode not ready✅ cgroup 驱动必须一致(containerd / kubelet)
journalctl -u kubelet --since "10 min ago"
或查看初始化失败输出:
kubeadm init phase preflight
kubectl get nodes
kubectl describe node <node-name>
常见状态:
NotReadyNetworkUnavailablekubectl get componentstatuses
kubectl get pods -n kube-system
重点检查:
kube-apiserveretcdkube-controller-managerkube-schedulercorednskube-proxykubectl get pods -A
kubectl describe pod <pod> -n <ns>
常见状态含义:
| 状态 | 含义 |
|---|---|
| Pending | 调度失败 |
| CrashLoopBackOff | 容器反复崩溃 |
| ImagePullBackOff | 镜像拉取失败 |
| ErrImagePull | 镜像问题 |
kubectl logs <pod>
kubectl logs <pod> -c <container>
kubectl get events -n <ns> --sort-by=.metadata.creationTimestamp
✅ 90% 的问题都能在这里看到原因
kubectl get pods -n kube-system | grep -E "calico|flannel|cilium"
kubectl exec -it <pod> -- ping 8.8.8.8
kubectl exec -it <pod> -- nslookup kubernetes.default
ip route
ip a
kubectl get pods -n kube-system | grep etcd
journalctl -u etcd
或:
ETCDCTL_API=3 etcdctl endpoint health
openssl x509 -in /etc/kubernetes/pki/apiserver.crt -noout -dates
证书过期会导致:
| 现象 | 重点排查 |
|---|---|
| kubectl 连不上 | apiserver / 证书 |
| 节点 NotReady | kubelet / CNI |
| Pod 起不来 | 镜像 / 资源 / 调度 |
| 网络不通 | CNI / iptables |
| 集群初始化失败 | swap / 内核 / 系统组件 |
journalctl -u kubelet -xekubectl get nodeskubectl get pods -n kube-systemkubectl describe podkubectl get events如果你愿意,可以直接贴出:
kubectl get nodeskubectl get pods -n kube-systemjournalctl -u kubelet --no-pager | tail -50我可以直接帮你定位具体错误。