클러스터 인사이트 보기

클러스터 인사이트 보기

Amazon EKS가 제공하는 세 가지 인사이트 유형(구성, 업그레이드, 롤백 준비)을 보는 방법을 알아봐요. 콘솔과 AWS CLI로 수행되는 인사이트 검사 목록과 관련 문제를 확인할 수 있어요.

출처: 문서

본문

Amazon EKS는 세 가지 유형의 인사이트를 제공해요: 구성 인사이트(Configuration insights), 업그레이드 인사이트(Upgrade insights), 롤백 준비 인사이트(Rollback readiness insights). 구성 인사이트는 EKS Hybrid Nodes 설정에서 클러스터나 워크로드의 기능을 손상시킬 수 있는 잘못된 구성을 식별해요. 업그레이드 인사이트는 새 Kubernetes 버전으로 업그레이드하는 능력에 영향을 줄 수 있는 문제를 식별해요. 롤백 준비 인사이트는 업그레이드 후 이전 Kubernetes 버전으로 롤백하는 능력에 영향을 줄 수 있는 문제를 식별해요.

수행되는 인사이트 검사 목록과 Amazon EKS가 식별한 관련 문제를 보려면 AWS Management Console, AWS CLI, AWS SDKs, Amazon EKS ListInsights API 작업을 사용할 수 있어요.

구성 인사이트 보기 - 콘솔 (View configuration insights - Console)

  1. Amazon EKS 콘솔을 엽니다.
  2. 클러스터 목록에서 인사이트를 보려는 Amazon EKS 클러스터의 이름을 선택합니다.
  3. Monitor cluster를 선택합니다.
  4. Cluster health 탭을 선택합니다.
  5. Configuration insights 표에서 다음 열을 볼 수 있습니다:
    • Name — Amazon EKS가 클러스터에 대해 수행한 검사입니다.
    • Insight status — Error 상태의 인사이트는 클러스터 기능에 영향을 줄 가능성이 있는 잘못된 구성이 있음을 뜻합니다. Warning 상태는 구성이 문서화된 방식과 일치하지 않지만 의도적으로 구성했다면 클러스터 기능이 동작할 수 있음을 뜻합니다. Passing 상태는 Amazon EKS가 클러스터에서 이 인사이트 검사와 관련된 문제를 찾지 못했음을 뜻합니다.
    • Version — 해당 버전입니다.
    • Last refresh time — 이 클러스터에 대해 인사이트 상태가 마지막으로 갱신된 시간입니다.
    • Description — 경고와 해결을 위한 권장 작업을 포함한 인사이트 검사의 정보입니다.

업그레이드 인사이트 보기 - 콘솔 (View upgrade insights - Console)

  1. Amazon EKS 콘솔을 엽니다.
  2. 클러스터 목록에서 인사이트를 보려는 Amazon EKS 클러스터의 이름을 선택합니다.
  3. Monitor cluster를 선택합니다.
  4. Upgrade insights 탭을 선택합니다.
  5. 최신 데이터를 보려면 Refresh insights 버튼을 선택하고 갱신 작업이 완료될 때까지 기다립니다.
  6. Upgrade insights 표에서 다음 열을 볼 수 있습니다:
    • Name — Amazon EKS가 클러스터에 대해 수행한 검사입니다.
    • Insight status — "Error" 상태의 인사이트는 일반적으로 영향받는 Kubernetes 버전이 현재 클러스터 버전의 N+1임을 뜻하며, "Warning" 상태는 인사이트가 향후 Kubernetes 버전 N+2 이상에 적용됨을 뜻합니다. "Passing" 상태는 관련 문제를 찾지 못했음을, "Unknown" 상태는 클러스터가 이 인사이트 검사의 영향을 받는지 Amazon EKS가 판단할 수 없음을 뜻합니다.
    • Version — 인사이트가 가능한 문제를 검사한 Kubernetes 버전입니다.
    • Last refresh time — 이 클러스터에 대해 인사이트 상태가 마지막으로 갱신된 시간입니다.
    • Last transition time — 이 인사이트의 상태가 마지막으로 변경된 시간입니다.
    • Description — 경고와 해결을 위한 권장 작업을 포함한 인사이트 검사의 정보입니다.

참고: 롤백 준비 인사이트는 업그레이드를 수행한 후 같은 탭에 나타나며 7일 롤백 자격 창 동안 계속 표시됩니다.

클러스터 인사이트 보기 - AWS CLI (View cluster insights - AWS CLI)

최신 데이터를 보려면 지정한 클러스터의 인사이트를 갱신합니다. 필요에 따라 명령을 수정한 후 실행합니다.

  • region-code를 AWS 리전 코드로 바꿉니다.
  • my-cluster를 클러스터 이름으로 바꿉니다.
aws eks start-insights-refresh --region region-code --cluster-name my-cluster

인사이트 갱신 상태를 추적하려면 다음 명령을 실행합니다. my-cluster를 클러스터 이름으로 바꿉니다.

aws eks describe-insights-refresh --cluster-name my-cluster

예시 출력:

{
    "message": "Insights refresh is in progress",
    "status": "IN_PROGRESS",
    "startedAt": "2025-07-30T13:36:09-07:00"
}

지정한 클러스터의 인사이트를 나열합니다. 필요에 따라 명령을 수정한 후 실행합니다.

  • region-code를 AWS 리전 코드로 바꿉니다.
  • my-cluster를 클러스터 이름으로 바꿉니다.
aws eks list-insights --region region-code --cluster-name my-cluster

예시 출력:

{
"insights":
    [
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
            "name": "Deprecated APIs removed in Kubernetes vX.XX",
            "category": "UPGRADE_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557315.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks for usage of deprecated APIs that are scheduled for removal in Kubernetes vX.XX. Upgrading your cluster before migrating to the updated APIs supported by vX.XX could cause application impact.",
            "insightStatus":
            {
                "status": "PASSING",
                "reason": "No deprecated API usage detected within the last 30 days.",
            },
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLE22222",
            "name": "Kubelet version skew",
            "category": "UPGRADE_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557309.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks for kubelet versions of worker nodes in the cluster to see if upgrade would cause non compliance with supported Kubernetes kubelet version skew policy.",
            "insightStatus":
            {
                "status": "UNKNOWN",
                "reason": "Unable to determine status of node kubelet versions.",
            },
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLE33333",
            "name": "Deprecated APIs removed in Kubernetes vX.XX",
            "category": "UPGRADE_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557315.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks for usage of deprecated APIs that are scheduled for removal in Kubernetes vX.XX. Upgrading your cluster before migrating to the updated APIs supported by vX.XX could cause application impact.",
            "insightStatus":
            {
                "status": "PASSING",
                "reason": "No deprecated API usage detected within the last 30 days.",
            },
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLEaaaaa",
            "name": "Cluster health issues",
            "category": "UPGRADE_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557314.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks for any cluster health issues that prevent successful upgrade to the next Kubernetes version on EKS.",
            "insightStatus":
            {
                "status": "PASSING",
                "reason": "No cluster health issues detected.",
            },
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLEbbbbb",
            "name": "EKS add-on version compatibility",
            "category": "UPGRADE_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557314.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks version of installed EKS add-ons to ensure they are compatible with the next version of Kubernetes. ",
            "insightStatus": { "status": "PASSING", "reason": "All installed EKS add-on versions are compatible with next Kubernetes version."},
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLEccccc",
            "name": "kube-proxy version skew",
            "category": "UPGRADE_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557314.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks version of kube-proxy in cluster to see if upgrade would cause non compliance with supported Kubernetes kube-proxy version skew policy.",
            "insightStatus":
            {
                "status": "PASSING",
                "reason": "kube-proxy versions match the cluster control plane version.",
            },
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLEddddd",
            "name": "Deprecated APIs removed in Kubernetes vX.XX",
            "category": "UPGRADE_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557315.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks for usage of deprecated APIs that are scheduled for removal in Kubernetes vX.XX. Upgrading your cluster before migrating to the updated APIs supported by vX.XX could cause application impact.",
            "insightStatus":
            {
                "status": "PASSING",
                "reason": "No deprecated API usage detected within the last 30 days.",
            },
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLE44444",
            "name": "Incompatible API usage",
            "category": "ROLLBACK_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557315.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks for usage of APIs that are not compatible with the previous Kubernetes version. Rolling back your cluster before removing incompatible API usage could cause data loss or application impact.",
            "insightStatus":
            {
                "status": "ERROR",
                "reason": "Incompatible API usage detected.",
            },
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLE55555",
            "name": "Kubelet version rollback compatibility",
            "category": "ROLLBACK_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557309.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks for kubelet versions of worker nodes in the cluster to see if rollback would cause non compliance with supported Kubernetes kubelet version skew policy.",
            "insightStatus":
            {
                "status": "ERROR",
                "reason": "At least one node kubelet version matches the cluster control plane version.",
            },
        },
        {
            "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLE66666",
            "name": "EKS add-on version rollback compatibility",
            "category": "ROLLBACK_READINESS",
            "kubernetesVersion": "X.XX",
            "lastRefreshTime": 1734557314.000,
            "lastTransitionTime": 1734557309.000,
            "description": "Checks version of installed EKS add-ons to ensure they are compatible with the previous version of Kubernetes.",
            "insightStatus":
            {
                "status": "PASSING",
                "reason": "All installed EKS add-on versions are compatible with previous Kubernetes version.",
            },
        },
    ],
"nextToken": null,
}

인사이트에 대한 설명 정보를 보려면 다음 명령을 실행합니다. 필요에 따라 명령을 수정한 후 실행합니다.

  • region-code를 AWS 리전 코드로 바꿉니다.
  • a1b2c3d4-5678-90ab-cdef-EXAMPLE22222를 클러스터 인사이트 나열에서 얻은 인사이트 ID로 바꿉니다.
  • my-cluster를 클러스터 이름으로 바꿉니다.
aws eks describe-insight --region region-code --id a1b2c3d4-5678-90ab-cdef-EXAMPLE22222 --cluster-name my-cluster

예시 출력:

{
  "insight":
    {
      "id": "a1b2c3d4-5678-90ab-cdef-EXAMPLE22222",
      "name": "Kubelet version skew",
      "category": "UPGRADE_READINESS",
      "kubernetesVersion": "1.27",
      "lastRefreshTime": 1734557309.000,
      "lastTransitionTime": 1734557309.000,
      "description": "Checks for kubelet versions of worker nodes in the cluster to see if upgrade would cause non compliance with supported Kubernetes kubelet version skew policy.",
      "insightStatus":
        {
          "status": "UNKNOWN",
          "reason": "Unable to determine status of node kubelet versions.",
        },
      "recommendation": "Upgrade your worker nodes to match the Kubernetes version of your cluster control plane.",
      "additionalInfo":
        {
          "Kubelet version skew policy": "https://kubernetes.io/releases/version-skew-policy/#kubelet",
          "Updating a managed node group": "https://docs.aws.amazon.com/eks/latest/userguide/update-managed-node-group.html",
        },
      "resources": [],
      "categorySpecificSummary":
        { "deprecationDetails": [], "addonCompatibilityDetails": [] },
    },
}

위 출력은 UPGRADE_READINESS와 ROLLBACK_READINESS 인사이트를 모두 보여줘요. 롤백 준비 인사이트는 지난 7일 안에 업그레이드된 클러스터에만 존재해요.

카테고리로 인사이트 필터링하기 (Filter insights by category)

카테고리로 인사이트를 필터링해 특정 유형만 볼 수 있어요:

aws eks list-insights \
  --cluster-name my-cluster \
  --region region-code \
  --filter '{"categories": ["ROLLBACK_READINESS"]}'

상태로 필터링해 차단하는 문제만 볼 수도 있어요:

aws eks list-insights \
  --cluster-name my-cluster \
  --region region-code \
  --filter '{"categories": ["ROLLBACK_READINESS"], "statuses": ["ERROR"]}'

롤백 준비 인사이트 세부 정보 보기 (View rollback readiness insight details)

롤백 준비 인사이트의 경우 describe-insight 명령이 영향받은 리소스와 해결 단계에 대한 유사한 정보를 반환해요. 예:

{
    "clusterId": "73a0e91f-f016-4555-bb7c-177496c47c9d",
    "insight": {
        "category": "ROLLBACK_READINESS",
        "name": "API usage rollback compatibility",
        "kubernetesVersion": "1.32",
        "insightStatus": {
            "status": "ERROR",
            "reason": "Detected incompatible API objects with version rollback."
        },
        "resources": [
            {
                "kubernetesResourceUri": "/apis/networking.k8s.io/v1/servicecidrs/kubernetes",
                "status": {
                    "status": "ERROR",
                    "reason": "networking.k8s.io/v1 is not compatible with Kubernetes version 1.32"
                }
            }
        ]
    }
}

"status": "ERROR"인 롤백 준비 인사이트를 찾으면 롤백을 수행하기 전에 문제를 해결하거나 --force 플래그로 인사이트 검사를 우회해야 해요. 롤백 과정에 대한 자세한 내용은 Roll back a cluster to a previous Kubernetes version 참고.

인사이트가 UNKNOWN 상태를 표시하면 EKS가 인사이트를 평가할 수 없었던 거예요. 인사이트를 성공적으로 평가할 수 있을 때까지 롤백이 차단되거나 --force 플래그로 인사이트 검사를 우회해야 해요.

더 알아보기 (Learn more)