在 CentOS 上部署 Kubernetes(k8s)失败 是非常常见的问题,原因通常集中在系统环境、网络、版本兼容性和配置步骤几个方面。下面我按最常见失败原因 → 排查思路 → 解决建议来系统说明。
Kubernetes 对 CentOS 版本有明确要求:
| Kubernetes 版本 | 推荐 CentOS |
|---|---|
| 1.24+ | CentOS 7.9 / 8 Stream / Rocky / Alma |
| 1.28+ | 不建议 CentOS 7(已接近 EOL) |
✅ 检查:
cat /etc/centos-release
uname -a
❌ 常见错误:
这是部署失败第一杀手。
✅ 正确做法:
systemctl stop firewalld
systemctl disable firewalld
setenforce 0
sed -i 's/SELINUX=enforcing/SELINUX=disabled/' /etc/selinux/config
❌ 错误现象:
Kubernetes 严格要求关闭 swap
swapoff -a
sed -i '/swap/d' /etc/fstab
❌ 报错示例:
running with swap on is not supported
从 K8s 1.24 起已移除 dockershim
❌ 常见错误:
✅ 推荐方案(2024+):
检查:
systemctl status containerd
crictl info
在国内部署 几乎必踩
❌ 典型错误:
failed to pull image k8s.gcr.io/...
✅ 解决方案:
kubeadm init --image-repository registry.aliyuncs.com/google_containers
或提前拉镜像:
docker pull registry.aliyuncs.com/google_containers/...
常见错误:
--pod-network-cidr--apiserver-advertise-address✅ 示例(Calico):
kubeadm init \
--pod-network-cidr=192.168.0.0/16 \
--image-repository registry.aliyuncs.com/google_containers
没有 CNI → Node 永远 NotReady
✅ 常见选择:
示例(Calico):
kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml
节点时间差 > 5 分钟 → etcd / TLS 失败
✅ 解决:
timedatectl set-timezone Asia/Shanghai
systemctl enable --now chronyd
✅ CentOS 版本支持
✅ 关闭防火墙
✅ 关闭 SELinux
✅ 关闭 Swap
✅ 容器运行时正常
✅ 时间同步
✅ 镜像可拉取
✅ CNI 已安装
你可以直接贴出:
我可以一步一步帮你找出 具体是哪一步失败。