温馨提示×

centos k8s为什么起不来

小樊
51
2026-09-06 11:35:52
栏目: 智能运维

“CentOS 上 Kubernetes 起不来”原因非常多,需要结合具体现象来判断。下面我按最常见原因 → 排查思路 → 解决办法给你一个系统性的排查清单,你可以逐条对照。


一、最常被忽略的基础问题(占 80%)

1️⃣ 防火墙 / SELinux 没关

K8s 对网络要求很严格。

# 关闭防火墙
systemctl stop firewalld
systemctl disable firewalld

# 关闭 SELinux
setenforce 0
sed -i 's/^SELINUX=enforcing/SELINUX=disabled/' /etc/selinux/config

✅ 很多 kubeadm init 卡住、节点 NotReady 都是这个原因。


2️⃣ swap 没关(致命)

K8s 严禁 swap

swapoff -a
sed -i '/swap/s/^/#/' /etc/fstab

3️⃣ 时间不同步

节点时间差太大,etcd 会直接挂。

timedatectl status
# 同步时间
yum install -y chrony
systemctl enable --now chronyd

二、kubeadm init 起不来的常见原因

4️⃣ 容器运行时没装或没配置

CentOS 常见错误:docker 没配置 systemd

# 检查
docker info | grep Cgroup

# 如果不是 systemd
mkdir -p /etc/docker
cat > /etc/docker/daemon.json <<EOF
{
  "exec-opts": ["native.cgroupdriver=systemd"]
}
EOF
systemctl restart docker

5️⃣ cri 不匹配(containerd / docker)

CentOS 8+ 默认可能用 containerd

systemctl status containerd

如果是 containerd,却用 docker 初始化,会失败。


6️⃣ kubeadm init 报错(典型)

常见错误:

  • port 6443 already in use
  • /etc/kubernetes already exists
# 重置再来
kubeadm reset -f
rm -rf /etc/kubernetes /var/lib/etcd

三、节点 NotReady(master 起来了但 worker 不行)

7️⃣ 网络插件没装(最常见)

不装 CNI,节点永远 NotReady

kubectl get nodes
# STATUS = NotReady

解决(二选一):

# Calico
kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml

# 或 Flannel
kubectl apply -f https://github.com/flannel-io/flannel/releases/latest/download/kube-flannel.yml

8️⃣ 端口不通(CentOS 特有)

检查:

ss -lntup | grep 6443
ping <master-ip>

四、CentOS 版本相关坑

9️⃣ CentOS 7 + 新版本 K8s

  • CentOS 7 不支持 Kubernetes 1.28+
  • 建议:
    • CentOS 7 → K8s ≤ 1.24
    • CentOS 8/Stream → K8s 1.26+

五、快速自检脚本(建议你跑一下)

swapoff -a
getenforce
systemctl status firewalld
docker info | grep Cgroup
kubectl get nodes
journalctl -xeu kubelet

六、我可以直接帮你定位(最快方式)

你可以把下面信息发我:

  1. CentOS 版本(cat /etc/redhat-release)
  2. K8s 版本
  3. 容器运行时(docker / containerd)
  4. 具体报错(命令 + 输出)
  5. journalctl -u kubelet -n 50

我可以直接告诉你是哪一步挂了、怎么改。

0 踩