錯誤訊息疑難排解參考指南
本參考資料列出了《 Red Hat OpenShift on IBM Cloud 》各疑難排解主題中所有已記錄的錯誤訊息與錯誤代碼。 各項條目依元件分類,並附有連結可導向完整的疑難排解主題。
叢集與主節點
| 錯誤訊息 | 疑難排解主題 |
|---|---|
Cannot complete cluster master operations because the cluster has a broken webhook application. |
為什麼叢集主節點的操作會因 webhook 損壞而失敗? |
Cannot complete cluster master upgrade because the Upgradeable status condition is set to False. |
為什麼我會看到「Cannot complete cluster master upgrade」的訊息? |
The master is approaching its allotted memory resource limit (93%). |
為什麼我的叢集主節點狀態顯示其資源即將達到上限? |
etcd database size is approaching the maximum |
為什麼我會看到「etcd database size is approaching the maximum」錯誤? |
The 'configuration' field is not a valid Kubernetes PodSecurityConfiguration setting. |
為什麼會出現錯誤訊息,指出我的 PodSecurityConfiguration 無效? |
No VPC is available. Create a VPC. |
VPC:為何我在控制台建立叢集時,沒有可用的 VPC? |
Your cluster can't pull images from the 'icr.io' domains because an IAM access policy could not be created. |
為什麼叢集在建立過程中無法從 IBM Cloud Container Registry 拉取映像檔? |
Image security enforcement update canceled. CAE008: can't enable Portieris image security enforcement because the cluster already has a conflicting image admission controller installed. |
為什麼我的 Portieris 叢集映像的安全性強制執行安裝被取消了? |
incorrect account for worker, Worker deploy failed due to network communications failing, Unable to connect to the IBM Cloud account. |
為什麼我無法建立或刪除叢集或工作節點? |
Unable to create cluster. The 'vpc-gen2' infrastructure operation failed with the message: the provided token is not authorized to view the specified subnet |
為何在建立 VPC 叢集時會出現「infrastructure operation failed」錯誤? |
No resources found., connection timed out, dial tcp: connect: connection timed out |
排除叢集中的常見 CLI 問題 |
Encrypted storage cannot be configured. Review the customer root key configuration for the worker pool. |
為什麼我無法建立具有加密工作節點的 VPC 叢集? |
Pending security group creation |
當我建立 VPC 叢集時,我的工作節點會卡在 Pending security group creation |
Infrastructure instance status is 'failed': Can't start instance because provisioning failed. |
為何在新增自訂 DNS 解析器後,會出現 DNS 錯誤? |
Could not store the cloud object storage bucket and IAM service key. |
為什麼我在建立叢集時會出現關於雲端物件儲存桶的錯誤訊息? |
Could not find user. |
為什麼我在嘗試存取網頁控制台時,會看到「Could not find user」錯誤? |
No resources found. |
登入我的叢集後,為什麼會看到「未找到資源」的訊息? |
VPN server configuration update failed. |
為什麼叢集主節點會回傳 VPN 伺服器錯誤? |
在 oc get clusterversion 的輸出結果中,版本顯示為未更新 |
為什麼 OpenShift 顯示叢集版本已過時? |
| 在預設為安全的叢集中,影像串流未被填入 | 為什麼在預設為安全的叢集中,影像串流無法顯示? |
sysdig-agent 在僅限私有存取的 RHCOS 叢集上,位於 CrashLoopBackOff 的 Pod |
為什麼位於 CrashLoopBackOff 的 sysdig-agent Pods 會出現在僅限私有存取的 RHCOS 叢集中? |
工作者節點
| 錯誤訊息 | 疑難排解主題 |
|---|---|
The worker node instance ID changed. Reload the worker node if bare metal hardware was serviced. |
經典問題:為何裸機實例 ID 與工作節點記錄不一致? |
The dedicated hosts for the zone 'eu-de-2' are not ready. |
VPC:為什麼我無法在專用主機上建立工作節點? |
SoftLayerAPIError(SoftLayer_Exception_Public): Could not obtain network VLAN with id #123456. |
經典問題:為何無法新增 VLAN ID 無效的工作節點? |
Registration failed – The plan containers.kubernetes.vpc.gen2.roks is not available in <region>. |
為何我在嘗試配置或重新載入工作節點時,會看到「Registration failed」錯誤? |
A VSI with this profile will put user over quota. |
VPC 工作節點因配額限制而無法進行配置 |
warning: Container container-00 is unable to start due to an error: Back-off pulling image "registry.redhat.io/rhel8/support-tools" |
建立 4.15 版本的叢集後,我的應用程式就無法運作 |
網路狀態檢查 (NHC) 錯誤
在「ibmcloud oc cluster health issues」指令的輸出中出現了以下錯誤代碼。
| 錯誤碼 | 嚴重性 | 說明 | 疑難排解主題 |
|---|---|---|---|
NHC001 |
警告 | Tigera 操作員已通報,Calico 已處於「進行中」狀態超過一小時。 | 為什麼「網路狀態」會顯示「NHC001」錯誤? |
NHC003 |
警告 | 叢集中的部分工作節點無法連線至容器映像庫以拉取映像。 | 為什麼「網路狀態」會顯示「NHC003」錯誤? |
NHC004 |
警告 | 叢集中的部分工作節點無法解析 VPE 閘道的主機名稱。 | 為什麼「網路狀態」會顯示「NHC004」錯誤? |
NHC005 |
警告 | Tigera 操作員報告指出,Calico 處於「功能受限」狀態。 | 為什麼「網路狀態」會顯示「NHC005」錯誤? |
NHC006 |
警告 | 從某些工作節點無法連通一個或多個 DNS 解析器。 | 為什麼「網路狀態」會顯示「NHC006」錯誤? |
NHC007 |
警告 | 從某些工作節點無法連通一個或多個 DNS 解析器。 | 為什麼「網路狀態」會顯示「NHC007」錯誤? |
NHC009 |
錯誤 | IAM 代幣兌換請求失敗。 | 為什麼「網路狀態」會顯示「NHC009」錯誤? |
NHC010 |
錯誤 | 已超過安全群組規則所訂定的配額。 | 為什麼「網路狀態」會顯示「NHC010」錯誤? |
NHC011 |
錯誤 | 超出與安全群組相關的配額。 | 為什麼「網路狀態」會顯示「NHC011」錯誤? |
Ingress 狀態錯誤(ERR 和 ESS 代碼)
在「ibmcloud oc ingress status-report get」指令的輸出中出現了以下錯誤代碼。 共享的程式碼同時出現在 IBM Cloud Kubernetes Service 和 Red Hat OpenShift on IBM Cloud 這兩處。
| 錯誤碼 | 錯誤訊息 | 疑難排解主題 |
|---|---|---|
ERRDSIA |
該子網域註冊的地址有誤。 | 輸入錯誤:ERRDSIA |
ERRDRISS |
該子網域存在 DNS 解析問題。 | 輸入錯誤:ERRDRISS |
ERRDSAISS |
該子網域的外部服務供應商存在授權問題。 | 輸入錯誤:ERRDSAISS |
ERRDSISS |
該子網域存在 TLS 中的隱藏問題。 | 輸入錯誤:ERRDSISS |
ERRSAM |
缺少負載平衡服務的位址。 | 輸入錯誤:ERRSAM |
ESSDNE |
該密鑰不在叢集中,或位於錯誤的名稱空間中。 | Ingress 錯誤:ESSDNE |
ESSEC |
TLS 的憑證已過期或即將過期。 | 輸入錯誤:ESSEC |
ESSEF |
「Opaque」秘密欄位的有效期已過或即將到期。 | 輸入錯誤:ESSEF |
ESSSMG |
找不到該秘密群組。 | 輸入錯誤:ESSSMG |
ESSSMI |
無法存取 Secrets Manager 實例。 | 輸入錯誤:ESSSMI |
ESSSMINF |
找不到 Secrets Manager 這個實例。 | 輸入錯誤:ESSSMINF |
ESSVC |
CRN 無法與同一網域的預設密鑰配對。 | 輸入錯誤:ESSVC |
ESSWS |
該秘密狀態顯示一則警告。 | 輸入錯誤:ESSWS |
ERRESNF |
缺少外部服務。 | 輸入錯誤:ERRESNF |
ERRIODEG |
Ingress 操作員目前處於功能受限狀態。 | 輸入錯誤:ERRIODEG |
ERRIONF |
叢集中缺少 Ingress 操作員。 | 輸入錯誤:ERRIONF |
ERRRNA |
有一條或多條路由未被接受。 | 輸入錯誤:ERRRNA |
ERRSAMO |
缺少負載平衡服務的位址。 | 輸入錯誤:ERRSAMO |
ERRSEIPM |
該服務缺少一個或多個工作節點的 IP 位址。 | Ingress 錯誤:ERRSEIPM |
XXX.us-south.containers.appdomain.cloud: dial tcp: ... can't marshal DNS message |
為什麼 DNS 操作員會顯示「RouteHealthDegraded」或「can't marshal DNS message」的錯誤訊息? |
負載平衡器
| 錯誤訊息 | 疑難排解主題 |
|---|---|
The VPC load balancer that routes requests to this Kubernetes LoadBalancer service is offline. |
VPC 叢集:為什麼我的應用程式無法透過負載平衡器連線? |
The subnet with ID(s) '<subnet_id>' has insufficient available ipv4 addresses. |
VPC 叢集:為何 Kubernetes LoadBalancer 服務會因沒有 IP 位址而失敗? |
The load balancer was created in zone <zone>. This setting cannot be changed. |
VPC 叢集:我的 VPC NLB 出現區域錯誤且無法更新 |
Warning CreatingCloudLoadBalancerFailed ... Failed ensuring LoadBalancer: FindLoadBalancer failed ... 401 Unauthorized ... BXNIM0430E |
為何在建立 VPC 叢集時會出現 SyncLoadBalancerFailed 錯誤? |
| 在建立或更新負載平衡器時發生安全群組協定不匹配事件 | VPC 叢集:建立或更新時發生安全群組協定錯誤 LoadBalancer |
CAE003: Unable to determine the ingress IP address for the network load balancer. |
經典叢集:為何主節點狀態會顯示 NLB 錯誤的入口 IP 位址? |
| VPC 負載平衡器的健康狀態顯示,N 個執行個體中僅有 2 個通過檢查 | VPC 叢集:為什麼我會看到 VPC 負載平衡器的健康狀態顯示為失敗? |
Error on cloud load balancer ... Service and associated VPC load balancer do not match ... hostname.invalid |
為什麼我的「私有路徑 NLB」會出現「hostname.invalid」錯誤? |
| Ingress 子網域 DNS 問題 | 為什麼我的 Ingress 子網域會出現 DNS 問題? |
應用程式與服務
| 錯誤訊息 | 疑難排解主題 |
|---|---|
Failed to create pod sandbox: rpc error: ... failed to request 1 IPv4 addresses. IPAM allocated only 0 |
為什麼我的容器無法啟動? |
ImagePullBackOff 或圖片擷取授權錯誤 |
為何無法透過 ImagePullBackOff 從登錄檔載入映像檔,或是出現授權錯誤? |
pull QPS exceeded 擷取影像時的錯誤 |
為什麼 Pod 在拉取映像檔時會顯示「pull QPS exceeded」錯誤? |
Error: failed to download "<helm_repo>/<chart_name>" |
Helm Chart 安裝疑難排解:更新設定值 |
This service doesn't support creation of keys |
解決 IBM Cloud 叢集中的服務綁定錯誤 |
Pod 仍處於「Pending」狀態 |
為什麼 Pod 會一直處於「待處理」狀態? |
| Pod 屢次無法重新啟動,或被意外移除 | 為什麼 Pod 會反覆無法重新啟動,或是被意外移除? |
error: build error: After retrying 2 times, Pull image still failed due to error: unauthorized: authentication required |
為什麼我的建置會因為拉取映像檔的驗證問題而發生錯誤? |
received unexpected HTTP status: 504 Gateway Time-out |
為什麼將資料推送到內部登錄檔時會超時? |
error: build error: Failed to push image: error copying layers and metadata |
為什麼我的 Pod 會因安全上下文限制(SCC)而出現「權限被拒絕」的錯誤,導致無法進行建置? |
dial tcp 161.26.0.28:443: connect: network is unreachable |
為什麼我無法從 VPC 網路外部將映像檔推送至內部註冊表? |
Pod 目前處於「CrashLoopBackOff」狀態 |
為什麼我的 Pod 處於「CrashLoopBackOff」狀態? |
oc debug 執行時發生錯誤,錯誤訊息為 container is unable to start error |
為什麼執行 oc debug 指令時會出現 container is unable to start error`` 錯誤? |
The entitlement 'ocp_entitled' was not found. |
為何在建立工作執行程序池時會出現授權或使用權錯誤? |
Error: Unable to find a match: kernel-headers-VERSION kernel-devel-VERSION |
為什麼我的 NVIDIA GPU 驅動程式在 RHEL 9 工作節點上安裝失敗? |
Failed to get StorageCluster","error":"no matches for kind "StorageCluster" in version "ocs.openshift.io/v1" |
為什麼在 openshift-storage 命名空間中沒有列出任何 Pod? |
位於 openshift-marketplace 命名空間中的 Pod ImagePullBackOff |
位於 openshift-marketplace 命名空間中的 Pod 位於 ImagePullBackOff |
failed to set feature gates 工作節點升級時發生錯誤 |
為何在升級工作節點時會出現「failed to set feature gates」錯誤? |
機密容器排程失敗:Insufficient kata.peerpods.io/vm |
如何排除機密容器的故障? |
權限與憑證
| 錯誤訊息 | 疑難排解主題 |
|---|---|
User doesn't have permissions to create or manage Storage |
我需要哪些權限才能管理儲存空間並建立 PVC? |
預設安全 (SBD)
| 錯誤訊息 | 疑難排解主題 |
|---|---|
warning: Container container-00 is unable to start due to an error: Back-off pulling image "registry.redhat.io/rhel8/support-tools" |
建立 4.15 版本的叢集後,我的應用程式就無法運作 |
Pending security group creation |
當我建立 VPC 叢集時,我的工作節點會卡在 Pending security group creation |
Infrastructure instance status is 'failed': Can't start instance because provisioning failed. |
為何在新增自訂 DNS 解析器後,會出現 DNS 錯誤? |
| 更新至該版本後,Nodeport 應用程式無法運作 4.15 | 在更新叢集版本至 4.15 或更高版本後,修復 NodePort 應用程式 |
| 在建立 4.15 版本後,VPC 中的其他叢集發生故障 | 建立版本 4.15 叢集後,在我 VPC 中其他叢集中運行的應用程式出現錯誤 |
| VSIs 無法存取 VPE 閘道 | 為什麼我的 VSI 無法存取 VPE 閘道? |
File Storage
| 錯誤訊息 | 疑難排解主題 |
|---|---|
MountVolume.SetUp failed for volume ... mount.nfs: access denied by server while mounting |
經典問題:為何在將磁碟區掛載至工作節點時,會被拒絕存取伺服器? |
write-permission 或 NFS 掛載路徑上出現非 root 使用者所有權錯誤 |
當 NFS 檔案儲存區的掛載路徑由非 root 使用者擁有時,為什麼我的應用程式會失敗? |
| 套用 NFS 檔案儲存權限時發生群組 ID 錯誤 | 為什麼我的應用程式會因 NFS 檔案儲存權限的群組 ID 錯誤而失敗? |
| 非 root 使用者無法為持久性儲存裝置新增存取權限 | 為什麼我無法為非 root 使用者新增對持久儲存空間的存取權限? |
| 工作節點的檔案系統已變更為唯讀模式 | 為什麼工作節點的檔案系統被改為唯讀模式? |
| PVC 仍處於待處理狀態(檔案儲存) | 為什麼我的檔案儲存 PVC 始終處於待處理狀態? |
MetadataServiceNotEnabled |
為什麼我在瀏覽 File Storage for VPC 時會看到「MetadataServiceNotEnabled」錯誤? |
MountingTargetFailed 或 rpc error: code = DeadlineExceeded desc = context deadline exceeded |
為什麼我在瀏覽 File Storage for VPC 時會看到「MountingTargetFailed」錯誤? |
SubnetFindFailed 或參閱 rpc error: code = FailedPrecondition 了解 PVC 的建立方式 |
為什麼在 File Storage for VPC 中建立 PVC 會失敗? |
UnresponsiveMountHelperContainerUtility |
為什麼在 File Storage for VPC 上會出現「UnresponsiveMountHelperContainerUtility」錯誤? |
shares_snapshot_operation_not_allowed |
為什麼我無法建立「File Storage for VPC」快照? |
shares_snapshot_not_found 關於 PVC 修復 |
為什麼我無法將我的 File Storage for VPC 快照還原至 PVC? |
| 無法刪除 VPC File Storage 的快照 | 為什麼我無法刪除我的 File Storage for VPC 快照? |
'rfs' profile is not accessible 或 stunnel manager is not initialized |
File Storage 區域傳輸中加密功能的疑難排解 |
VPC File Storage PVC 仍位於 Pending,且容量數值經四捨五入 |
為何在使用容量四捨五入時,我的 PVC 會一直處於「待處理」狀態? |
| VPC File Storage 部署權限錯誤 | 為什麼我的 File Storage for VPC 部署會因權限錯誤而失敗? |
在掛載 VPC 時,App pod 卡在「Container creating」狀態 File Storage |
為什麼我的 AppPod 在嘗試掛載 File Storage for VPC 時,會卡在 Container creating 這個狀態? |
File Storage Critical 狀態下的附加元件 |
為什麼「File Storage for VPC」擴充功能處於「Critical」狀態? |
Block Storage
| 錯誤訊息 | 疑難排解主題 |
|---|---|
failed to mount the volume as "ext4", it already contains xfs. Mount error: mount failed: exit status 32 |
為何將現有的區塊儲存掛載到 Pod 時,會因檔案系統不符而失敗? |
Volume not attached |
為何在嘗試擴展 Block Storage for VPC 磁碟區時,會出現「Volume not attached」錯誤? |
| 將區塊儲存變更為唯讀 | 為什麼區塊儲存會變成唯讀? |
Message: 50% throttling of CPU in namespace kube-system for container ibmcloud-block-storage-driver-container |
為什麼「區塊儲存」外掛程式 Helm 的圖表會顯示 CPU 限速警告? |
| PVC 區塊儲存仍處於待處理狀態 | 為什麼我的區塊儲存 PVC 始終處於「待處理」狀態? |
| 應用程式無法存取或寫入 PVC(阻塞) | 為什麼我的應用程式無法存取或寫入 PVC? |
Labels: ibm.io/pv-connectivity-status: limited |
為什麼我的 Block Storage 持久卷顯示連接狀態為「limited」? |
| Block Storage API 金鑰重設導致資源配置失敗 | Block Storage for VPC 重設 API 金鑰後,PVC 建立失敗 |
UNEXPECTED INCONSISTENCY; RUN fsck MANUALLY. |
為何掛載 Block Storage for Classic 時會因檔案系統檢查錯誤而失敗? |
| 無法刪除區塊儲存卷的快照 | 為什麼我無法刪除我的 Block Storage for VPC 卷本快照資源? |
| 區塊儲存快照建立失敗 | 為什麼我無法建立「Block Storage for VPC」快照? |
| 刪除叢集後,區塊儲存裝置的費用仍會顯示 | 為什麼在刪除叢集後,我仍然看到針對區塊儲存裝置的費用? |
Object Storage
| 錯誤訊息 | 疑難排解主題 |
|---|---|
pvc:...:can't access bucket <bucket_name>: NotFound: Not Found |
為什麼我的 PVC 無法存取現有的「桶」? |
Error: symlink ... helm-ibmc: file exists |
為何安裝物件儲存 Helm 外掛程式會失敗? |
d--------- 1 root root 0 Jan 1 1970 <file_name> (非 root 使用者無法存取檔案) |
解決非 root 使用者存取 中的檔案時所遇到的問題 IBM Cloud |
EPERM: operation not permitted |
為什麼我的應用程式 Pod 會出現「Operation not permitted」錯誤而失敗? |
chown: changing ownership of '<volume_mount_path>': Input/output error |
為什麼無法變更掛載路徑的所有權? |
Error: rendered manifest contains a resource that already exists. ... existing_kind: storageClass |
為什麼安裝「IBM Cloud Object Storage」外掛程式會失敗? |
Bad value for ibm.io/object-store-endpoint ... scheme is missing. |
為何我在建立 PVC 時,會看到錯誤的 s3fs 或 IAM API 端點? |
SignatureDoesNotMatch: The request signature we calculated does not match the signature you provided. |
為何我在建立 PVC 時會看到「憑證錯誤」或「存取遭拒」的訊息? |
| Object Storage PVC 仍處於待定狀態 | 為什麼我的 PVC 始終處於待處理狀態? |
can't get credentials: can't get secret tsecret-key: secrets "secret-key" not found |
為什麼會因為找不到「Kubernetes」這個密鑰,導致 PVC 或 pod 的建立失敗? |
Transport endpoint is not connected. |
為什麼傳輸端點未連線? |
Error mounting volume: s3fs mount failed: s3fs: error while loading shared libraries: libfuse.so.2 |
為何在使用「IBM Cloud Object Storage」外掛程式時,會出現磁碟掛載錯誤? |
| 使用 COS 叢集附加元件時發生「傳輸終點未連線」錯誤 | 為何在使用「IBM Cloud Object Storage」叢集附加元件時,會看到「傳輸終端未連線」的錯誤訊息? |
Portworx 儲存空間
| 錯誤訊息 | 疑難排解主題 |
|---|---|
kp.Error: ... msg='Unauthorized: The user does not have access to the specified resource' |
為何在 KMS 端點無效時,加密會失敗? |
Red Hat OpenShift on IBM Cloud 資料基礎架構 (ODF)
| 錯誤訊息 | 疑難排解主題 |
|---|---|
Failed to get StorageCluster","error":"no matches for kind "StorageCluster" in version "ocs.openshift.io/v1" |
為什麼在 openshift-storage 命名空間中沒有列出任何 Pod? |
ODF 莢莢卡在 Pending |
為什麼 OpenShift Data Foundation 的 Pod 會卡在「Pending」這一步? |
ODF 儲存叢集卡在 Progressing |
為什麼我的 OpenShift Data Foundation 儲存叢集的狀態會卡在「Progressing」? |
ceph-cluster-controller: failed to reconcile ... must be no more than 63 characters |
為什麼我的 OpenShift Data Foundation 儲存叢集的狀態會卡在「Failed to reconcile」? |
OpenShift 虛擬化
| 錯誤訊息 | 疑難排解主題 |
|---|---|
| OpenShift Virtualization Operator 安裝失敗 | 為什麼 OpenShift 虛擬化操作員的安裝會失敗? |
| HyperConverged 資源部署失敗 | 為什麼 HyperConverged 的資源部署會失敗? |
| VM 無法為磁碟進行配置 | 為什麼 VM 磁碟無法完成配置? |
PVCs 仍處於 Pending 狀態 |
為何在「OpenShift 虛擬化」中,持久化卷的索取會持續保留在「Pending」中? |
| OpenShift 虛擬化環境中,ODF安裝失敗 | 為何在「OpenShift 虛擬化」環境中安裝「OpenShift Data Foundation」會失敗? |
| 虛擬機器無法啟動 | 為什麼虛擬機器無法啟動? |
| 即時遷移失敗 | 為什麼虛擬機器的即時遷移會失敗? |
| 虛擬機器無法連線至網路 | 為什麼虛擬機器無法連上網路? |
| VNI 連接失敗 | 為什麼 VNI 連接會失敗? |
| Localnet 使用者自訂網路無法運作 | 為什麼「localnet」這個自訂網路無法運作? |
| 附有 VNI 的虛擬機器無法進行通訊 | 為何附有 VNI 連接的虛擬機器無法進行通訊? |
| 虛擬機器的效能不佳 | 為什麼虛擬機器的效能不佳? |
| 即時遷移速度很慢 | 為什麼即時遷移速度很慢? |