mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-27 21:50:21 +00:00
Add helm init troubleshooting
This commit is contained in:
committed by
Denise
parent
5659946adf
commit
d9da8b5ef8
@@ -30,4 +30,8 @@ helm init --service-account tiller
|
|||||||
|
|
||||||
> **Note:** This `tiller` install has full cluster access, which should be acceptable if the cluster is dedicated to Rancher server. Check out the [helm docs](https://docs.helm.sh/using_helm/#role-based-access-control) for restricting `tiller` access to suit your security requirements.
|
> **Note:** This `tiller` install has full cluster access, which should be acceptable if the cluster is dedicated to Rancher server. Check out the [helm docs](https://docs.helm.sh/using_helm/#role-based-access-control) for restricting `tiller` access to suit your security requirements.
|
||||||
|
|
||||||
### [Next: Install Rancher]({{< baseurl >}}/rancher/v2.x/en/installation/ha//helm-rancher/)
|
### Issues or errors?
|
||||||
|
|
||||||
|
See the [Troubleshooting]({{< baseurl >}}/rancher/v2.x/en/installation/ha/helm-init/troubleshooting/) page.
|
||||||
|
|
||||||
|
### [Next: Install Rancher]({{< baseurl >}}/rancher/v2.x/en/installation/ha/helm-rancher/)
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
---
|
||||||
|
title: Troubleshooting
|
||||||
|
weight: 276
|
||||||
|
---
|
||||||
|
|
||||||
|
### Helm commands show forbidden
|
||||||
|
|
||||||
|
When Helm is initiated in the cluster without specifying the correct `ServiceAccount`, the command `helm init` will succeed but you won't be able to execute most of the other `helm` commands. The following error will be shown:
|
||||||
|
|
||||||
|
```
|
||||||
|
Error: configmaps is forbidden: User "system:serviceaccount:kube-system:default" cannot list configmaps in the namespace "kube-system"
|
||||||
|
```
|
||||||
|
|
||||||
|
To resolve this, the server component (`tiller`) needs to be removed and added with the correct `ServiceAccount`. You can use `helm reset --force` to remove the `tiller` from the cluster. Please check if it is removed using `helm version --server`.
|
||||||
|
|
||||||
|
```
|
||||||
|
helm reset --force
|
||||||
|
Tiller (the Helm server-side component) has been uninstalled from your Kubernetes Cluster.
|
||||||
|
helm version --server
|
||||||
|
Error: could not find tiller
|
||||||
|
```
|
||||||
|
|
||||||
|
When you have confirmed that `tiller` has been removed, please follow the steps provided in [Initialize Helm on the cluster]({{< baseurl >}}/rancher/v2.x/en/installation/ha/helm-init/#initialize-helm-on-the-cluster) to install `tiller` with the correct `ServiceAccount`.
|
||||||
@@ -3,19 +3,19 @@ title: Troubleshooting
|
|||||||
weight: 276
|
weight: 276
|
||||||
---
|
---
|
||||||
|
|
||||||
#### canal Pods show READY 2/3
|
### canal Pods show READY 2/3
|
||||||
|
|
||||||
The most common cause of this issue is port 8472/UDP is not open between the nodes. Check your local firewall, network routing or security groups.
|
The most common cause of this issue is port 8472/UDP is not open between the nodes. Check your local firewall, network routing or security groups.
|
||||||
|
|
||||||
Once the network issue is resolved, the `canal` pods should timeout and restart to establish their connections.
|
Once the network issue is resolved, the `canal` pods should timeout and restart to establish their connections.
|
||||||
|
|
||||||
#### nginx-ingress-controller Pods show RESTARTS
|
### nginx-ingress-controller Pods show RESTARTS
|
||||||
|
|
||||||
The most common cause of this issue is the `canal` pods have failed to establish the overlay network. See [canal Pods show READY `2/3`](#canal-pods-show-ready-2-3) for troubleshooting.
|
The most common cause of this issue is the `canal` pods have failed to establish the overlay network. See [canal Pods show READY `2/3`](#canal-pods-show-ready-2-3) for troubleshooting.
|
||||||
|
|
||||||
#### Failed to set up SSH tunneling for host [xxx.xxx.xxx.xxx]: Can't retrieve Docker Info
|
### Failed to set up SSH tunneling for host [xxx.xxx.xxx.xxx]: Can't retrieve Docker Info
|
||||||
|
|
||||||
##### Failed to dial to /var/run/docker.sock: ssh: rejected: administratively prohibited (open failed)
|
#### Failed to dial to /var/run/docker.sock: ssh: rejected: administratively prohibited (open failed)
|
||||||
|
|
||||||
* User specified to connect with does not have permission to access the Docker socket. This can be checked by logging into the host and running the command `docker ps`:
|
* User specified to connect with does not have permission to access the Docker socket. This can be checked by logging into the host and running the command `docker ps`:
|
||||||
|
|
||||||
@@ -35,18 +35,18 @@ $ nc xxx.xxx.xxx.xxx 22
|
|||||||
SSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.10
|
SSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.10
|
||||||
```
|
```
|
||||||
|
|
||||||
##### Failed to dial ssh using address [xxx.xxx.xxx.xxx:xx]: Error configuring SSH: ssh: no key found
|
#### Failed to dial ssh using address [xxx.xxx.xxx.xxx:xx]: Error configuring SSH: ssh: no key found
|
||||||
|
|
||||||
* The key file specified as `ssh_key_path` cannot be accessed. Make sure that you specified the private key file (not the public key, `.pub`), and that the user that is running the `rke` command can access the private key file.
|
* The key file specified as `ssh_key_path` cannot be accessed. Make sure that you specified the private key file (not the public key, `.pub`), and that the user that is running the `rke` command can access the private key file.
|
||||||
|
|
||||||
##### Failed to dial ssh using address [xxx.xxx.xxx.xxx:xx]: ssh: handshake failed: ssh: unable to authenticate, attempted methods [none publickey], no supported methods remain
|
#### Failed to dial ssh using address [xxx.xxx.xxx.xxx:xx]: ssh: handshake failed: ssh: unable to authenticate, attempted methods [none publickey], no supported methods remain
|
||||||
|
|
||||||
* The key file specified as `ssh_key_path` is not correct for accessing the node. Double-check if you specified the correct `ssh_key_path` for the node and if you specified the correct user to connect with.
|
* The key file specified as `ssh_key_path` is not correct for accessing the node. Double-check if you specified the correct `ssh_key_path` for the node and if you specified the correct user to connect with.
|
||||||
|
|
||||||
##### Failed to dial ssh using address [xxx.xxx.xxx.xxx:xx]: Error configuring SSH: ssh: cannot decode encrypted private keys
|
#### Failed to dial ssh using address [xxx.xxx.xxx.xxx:xx]: Error configuring SSH: ssh: cannot decode encrypted private keys
|
||||||
|
|
||||||
* If you want to use encrypted private keys, you should use `ssh-agent` to load your keys with your passphrase. If the `SSH_AUTH_SOCK` environment variable is found in the environment where the `rke` command is run, it will be used automatically to connect to the node.
|
* If you want to use encrypted private keys, you should use `ssh-agent` to load your keys with your passphrase. If the `SSH_AUTH_SOCK` environment variable is found in the environment where the `rke` command is run, it will be used automatically to connect to the node.
|
||||||
|
|
||||||
##### Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
#### Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||||
|
|
||||||
* The node is not reachable on the configured `address` and `port`.
|
* The node is not reachable on the configured `address` and `port`.
|
||||||
|
|||||||
Reference in New Issue
Block a user