CKS: kubeadm config still uses `kubeadm.k8s.io/v1beta3` — external-etcd clusters break on Kubernetes 1.37+
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- kubernetes
- Ambito
- infrastructure
Direzione di ricerca
Start with plugins/integrations/kubernetes-service/src/main/resources/conf/k8s-control-node.yml around lines 245-303, then read KubernetesClusterUpgradeWorker.java:75 and KubernetesClusterService.MIN_KUBERNETES_VERSION_HA_SUPPORT for supported-version handling. Reproduce the external-etcd path on Kubernetes 1.37 and verify the chosen compatibility approach also works with versions below 1.31. Done means external-etcd cluster creation succeeds across the supported Kubernetes range without changing the flag-only paths.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
problem
CKS writes a kubeadm configuration file into the control node's cloud-init, pinned to the v1beta3 API:
# plugins/integrations/kubernetes-service/src/main/resources/conf/k8s-control-node.yml:245
- path: /etc/kubernetes/kubeadm-config.yaml
...
apiVersion: kubeadm.k8s.io/v1beta3 # :249 (ClusterConfiguration)
...
apiVersion: kubeadm.k8s.io/v1beta3 # :260 (InitConfiguration)
kubeadm.k8s.io/v1beta3 was deprecated when v1beta4 was introduced in Kubernetes 1.31, with support to be "removed after a minimum of 3 Kubernetes minor releases"
(Kubernetes v1.31: kubeadm v1beta4).
It has since been reported removed as of Kubernetes 1.37
(kubernetes-sigs/image-builder#2151).
Once removed, kubeadm init --config rejects the file and cluster creation fails.
Scope — this affects external-etcd clusters only. That config file is passed to kubeadm on exactly one path:
# k8s-control-node.yml:299-303
if [[ ${EXTERNAL_ETCD_NODES} == true ]]; then
kubeadm init --config /etc/kubernetes/kubeadm-config.yaml --upload-certs
else
kubeadm init --token {{ ... }} --token-ttl 0 {{ k8s_control_node.cluster.initargs }} --cri-socket /run/containerd/containerd.sock
fi
So:
| Path | Uses kubeadm config file? | Affected on 1.37+ |
|---|---|---|
Control node, external etcd (:300) |
yes | yes |
Control node, stacked etcd (:302) |
no — flags only | no |
Additional control plane join (k8s-control-node-add.yml:239) |
no — flags only | no |
Worker join (k8s-node.yml:254) |
no — flags only | no |
grep -rn "kubeadm.k8s.io/v1beta" plugins/ systemvm/ returns only those two lines in the whole tree, so the fix is narrowly scoped.
Compounding this: CKS enforces no maximum supported Kubernetes version. addKubernetesSupportedVersion will happily accept 1.37.x, and the failure only surfaces part-way through cluster creation on the control node, which makes it hard to diagnose
versions
- Affects
main,4.20,4.21,4.22— the templatedv1beta3is identical on all of them. - Triggered by Kubernetes >= 1.37 (the release reported to have removed
v1beta3).
The steps to reproduce the bug
- Build a CKS binaries ISO for Kubernetes 1.37.x (
scripts/util/create-kubernetes-binaries-iso.sh). - Register it:
addKubernetesSupportedVersion semanticversion=1.37.0 url=... - Create a Kubernetes cluster with external etcd nodes (
etcdnodes=1or more), which selects the
kubeadm init --configpath. - On the control node,
kubeadm initfails because/etc/kubernetes/kubeadm-config.yamldeclares a
config API version that kubeadm no longer recognises. Cluster creation does not complete.
A cluster on the same version without external etcd should succeed, since that path passes flags only —
which is a useful way to confirm the diagnosis.
logs
root@test-cks-etcd-control-1a0a97ce958:/opt/bin# ./deploy-kube-system status
error: your configuration file uses an old API spec: "kubeadm.k8s.io/v1beta3" (kind: "ClusterConfiguration"). Please use kubeadm v1.36 instead and run 'kubeadm config migrate --old-config old-config-file --new-config new-config-file', which will write the new, similar spec using a newer API version.
To see the stack trace of this error execute with --v=5 or higher
error: your configuration file uses an old API spec: "kubeadm.k8s.io/v1beta3" (kind: "ClusterConfiguration"). Please use kubeadm v1.36 instead and run 'kubeadm config migrate --old-config old-config-file --new-config new-config-file', which will write the new, similar spec using a newer API version.
To see the stack trace of this error execute with --v=5 or higher
error: your configuration file uses an old API spec: "kubeadm.k8s.io/v1beta3" (kind: "ClusterConfiguration"). Please use kubeadm v1.36 instead and run 'kubeadm config migrate --old-config old-config-file --new-config new-config-file', which will write the new, similar spec using a newer API version.
To see the stack trace of this error execute with --v=5 or higher
Error: kubeadm init failed!
What to do about it?
Migrate the template to kubeadm.k8s.io/v1beta4 — but not unconditionally. v1beta4 requires
kubeadm >= 1.31, and CKS still supports much older Kubernetes versions (there are comparisons against
1.15.0 and 1.16.0 in KubernetesClusterUpgradeWorker.java:75 and
KubernetesClusterService.MIN_KUBERNETES_VERSION_HA_SUPPORT), with versions registered by the operator.
A straight bump would break clusters on anything below 1.31.
- Lingua principale
- Java
- Stelle
- 3.1k
- Fork
- 1.4k
- Merge medio
- 7g 5h
- PR unite (30g)
- 28
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di apache/cloudstack
-
create-kubernetes-binaries-iso.sh builds the ISO without setting a volume ID on EL8 based os's Apertabug component:kubernetes
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
apache/cloudstack#14180 ·
-
bug component:projects component:UI
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
apache/cloudstack#14070 · 5 commenti ·
-
component:backup
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
apache/cloudstack#14013 ·
-
KVM agent fails to connect to Ceph RBD storage pool after upgrading Ceph client to Tentacle 20.2.4 Apertabug component:ceph
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
apache/cloudstack#13989 · 3 commenti ·
-
component:UI
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
apache/cloudstack#13944 · 3 commenti ·
Tutte le issue di apache/cloudstack
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
infinispan/infinispan#18150 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
-
untriaged
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
opensearch-project/k-NN#3597 ·
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100