“CentOS 上 Kubernetes 起不来”原因非常多,需要结合具体现象来判断。下面我按最常见原因 → 排查思路 → 解决办法给你一个系统性的排查清单,你可以逐条对照。
K8s 对网络要求很严格。
# 关闭防火墙
systemctl stop firewalld
systemctl disable firewalld
# 关闭 SELinux
setenforce 0
sed -i 's/^SELINUX=enforcing/SELINUX=disabled/' /etc/selinux/config
✅ 很多 kubeadm init 卡住、节点 NotReady 都是这个原因。
K8s 严禁 swap
swapoff -a
sed -i '/swap/s/^/#/' /etc/fstab
节点时间差太大,etcd 会直接挂。
timedatectl status
# 同步时间
yum install -y chrony
systemctl enable --now chronyd
CentOS 常见错误:docker 没配置 systemd
# 检查
docker info | grep Cgroup
# 如果不是 systemd
mkdir -p /etc/docker
cat > /etc/docker/daemon.json <<EOF
{
"exec-opts": ["native.cgroupdriver=systemd"]
}
EOF
systemctl restart docker
CentOS 8+ 默认可能用 containerd
systemctl status containerd
如果是 containerd,却用 docker 初始化,会失败。
常见错误:
port 6443 already in use/etc/kubernetes already exists# 重置再来
kubeadm reset -f
rm -rf /etc/kubernetes /var/lib/etcd
不装 CNI,节点永远 NotReady
kubectl get nodes
# STATUS = NotReady
解决(二选一):
# Calico
kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml
# 或 Flannel
kubectl apply -f https://github.com/flannel-io/flannel/releases/latest/download/kube-flannel.yml
检查:
ss -lntup | grep 6443
ping <master-ip>
swapoff -a
getenforce
systemctl status firewalld
docker info | grep Cgroup
kubectl get nodes
journalctl -xeu kubelet
你可以把下面信息发我:
cat /etc/redhat-release)journalctl -u kubelet -n 50我可以直接告诉你是哪一步挂了、怎么改。