Linkerd 체크
Linkerd 체크 (linkerd check)
linkerd check 명령에서 보고되는 흔한 문제들에 대한 해결 단계를 정리한 문서예요. 체크 항목이 실패하면 어떤 리소스가 빠졌거나 잘못 구성되었는지 단계별로 확인하고 바로잡는 방법을 설명해 줘요.
출처: Linkerd Checks
본문
이 문서는 linkerd check 명령에서 보고되는 흔한 문제들에 대한 해결 단계를 제공해요.
"pre-kubernetes-cluster-setup" 체크
이 체크들은 --pre 플래그를 설정했을 때만 실행돼요. 이 플래그는 linkerd install을 실행하기 전에 클러스터가 설치 준비가 되었는지 확인하기 위한 용도예요.
√ control plane namespace does not already exist
실패 예시:
× control plane namespace does not already exist
The "linkerd" namespace already exists
기본적으로 linkerd install은 linkerd 네임스페이스를 만들어요. 설치 전에는 그 네임스페이스가 없어야 해요. 다른 네임스페이스로 확인하려면 다음을 실행하세요:
linkerd check --pre --linkerd-namespace linkerd-test
√ can create Kubernetes resources
이 섹션의 후속 체크들은 Linkerd 설치에 필요한 Kubernetes 리소스를 만들 권한이 있는지 검증해요. 구체적으로는:
√ can create Namespaces
√ can create ClusterRoles
√ can create ClusterRoleBindings
√ can create CustomResourceDefinitions
"pre-kubernetes-setup" 체크
이 체크들은 --pre 플래그를 설정했을 때만 실행돼요. 이 플래그는 linkerd install을 실행하기 전에 Linkerd를 설치할 올바른 RBAC 권한이 있는지 확인하기 위한 용도예요.
√ can create Namespaces
√ can create ClusterRoles
√ can create ClusterRoleBindings
√ can create CustomResourceDefinitions
√ can create PodSecurityPolicies
√ can create ServiceAccounts
√ can create Services
√ can create Deployments
√ can create ConfigMaps
√ no clock skew detected
이 체크는 linkerd install 명령을 실행하는 시스템과 Kubernetes 노드 사이의 차이(시계 오프셋, clock skew)를 감지해요. 시계 오프셋이 크면 TLS 검증 문제가 발생할 수 있어요. 노드가 TLS 인증서가 만료되지 않았는데 만료된 것으로 판단하거나, 그 반대가 될 수 있기 때문이에요.
Linkerd edge-20.3.4 이상 버전은 최대 5분의 차이를 확인하고, 이전 버전의 Linkerd(stable-2.7 포함)는 최대 1분의 차이를 확인해요. Kubernetes 노드 하트비트 간격이 이 차이보다 길면 이 체크의 오탐(false positive)을 경험할 수 있어요. 기본 노드 하트비트 간격은 Kubernetes 1.17에서 5분으로 늘어났으므로, Kubernetes 1.17 이상에서 edge-20.3.4 이전 버전의 Linkerd를 실행하는 사용자는 이 오탐을 경험할 가능성이 높아요. 이런 경우 edge-20.3.4 이상으로 업그레이드할 수 있어요. 이 오류를 무시하기로 했다면 시스템 시계가 일관적인지 확인할 것을 강력히 권장해요.
"pre-kubernetes-capability" 체크
이 체크들은 --pre 플래그를 설정했을 때만 실행돼요. 이 플래그는 linkerd install을 실행하기 전에 Linkerd를 설치할 올바른 Kubernetes capability 권한이 있는지 확인하기 위한 용도예요.
"pre-linkerd-global-resources" 체크
이 체크들은 --pre 플래그를 설정했을 때만 실행돼요. 이 플래그는 linkerd install을 실행하기 전에 Linkerd 컨트롤 플레인을 아직 설치하지 않았는지 확인하기 위한 용도예요.
√ no ClusterRoles exist
√ no ClusterRoleBindings exist
√ no CustomResourceDefinitions exist
√ no MutatingWebhookConfigurations exist
√ no ValidatingWebhookConfigurations exist
√ no PodSecurityPolicies exist
"pre-kubernetes-single-namespace-setup" 체크
전체 클러스터 설치 권한이 없을 것으로 예상된다면 --single-namespace 플래그를 시도해 보세요. 제한된 클러스터 접근으로 단일 네임스페이스에 Linkerd를 설치할 수 있는지 검증해 줘요:
linkerd check --pre --single-namespace
"kubernetes-api" 체크
실패 예시:
× can initialize the client
error configuring Kubernetes API client: stat badconfig: no such file or directory
× can query the Kubernetes API
Get https://8.8.8.8/version: dial tcp 8.8.8.8:443: i/o timeout
시스템이 Kubernetes 클러스터에 연결하도록 구성되어 있는지 확인하세요. KUBECONFIG 환경 변수가 올바르게 설정되었는지, 그리고/또는 ~/.kube/config가 유효한 클러스터를 가리키는지 검증하세요.
자세한 내용은 Kubernetes 문서의 다음 페이지들을 참고하세요:
- Accessing Clusters
- Configure Access to Multiple Clusters
또한 다음 명령들이 동작하는지 확인하세요:
kubectl config view
kubectl cluster-info
kubectl version
또 다른 실패 예시:
× can query the Kubernetes API
Get REDACTED/version: x509: certificate signed by unknown authority
이에 대한 (안전하지 않은) 임시 해결책으로 다음을 시도할 수 있어요:
kubectl config set-cluster ${KUBE_CONTEXT} --insecure-skip-tls-verify=true \
--server=${KUBE_CONTEXT}
"kubernetes-version" 체크
√ is running the minimum Kubernetes API version
실패 예시:
× is running the minimum Kubernetes API version
Kubernetes is on version [1.7.16], but version [1.13.0] or more recent is required
Linkerd는 최소 1.13.0 버전을 요구해요. 클러스터 버전을 확인하세요:
kubectl version
√ is running the minimum kubectl version
실패 예시:
× is running the minimum kubectl version
kubectl is on version [1.9.1], but version [1.13.0] or more recent is required
see https://linkerd.io/2/checks/#kubectl-version for hints
Linkerd는 최소 1.13.0 버전을 요구해요. kubectl 버전을 확인하세요:
kubectl version --client --short
이를 해결하려면 kubectl 버전을 업데이트하세요.
Kubernetes 업그레이드에 대한 자세한 내용은 Kubernetes 문서의 페이지를 참고하세요.
"linkerd-config" 체크
이 체크 범주는 Linkerd의 클러스터 전반 RBAC 및 관련 리소스가 설치되었는지 검증해요.
√ control plane Namespace exists
실패 예시:
× control plane Namespace exists
The "foo" namespace does not exist
see https://linkerd.io/2/checks/#l5d-existence-ns for hints
Linkerd 컨트롤 플레인 네임스페이스가 존재하는지 확인하세요:
kubectl get ns
기본 컨트롤 플레인 네임스페이스는 linkerd예요. Linkerd를 다른 네임스페이스에 설치했다면 체크 명령에서 이를 지정하세요:
linkerd check --linkerd-namespace linkerdtest
√ control plane ClusterRoles exist
실패 예시:
× control plane ClusterRoles exist
missing ClusterRoles: linkerd-linkerd-identity
see https://linkerd.io/2/checks/#l5d-existence-cr for hints
Linkerd ClusterRole이 존재하는지 확인하세요:
kubectl get clusterroles | grep linkerd
대략 다음과 같은 출력이 보여야 해요:
linkerd-linkerd-destination 9d
linkerd-linkerd-identity 9d
linkerd-linkerd-proxy-injector 9d
linkerd-policy 9d
또한 ClusterRole을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create clusterroles
다음과 같은 출력이 보여야 해요:
yes
√ control plane ClusterRoleBindings exist
실패 예시:
× control plane ClusterRoleBindings exist
missing ClusterRoleBindings: linkerd-linkerd-identity
see https://linkerd.io/2/checks/#l5d-existence-crb for hints
Linkerd ClusterRoleBinding이 존재하는지 확인하세요:
kubectl get clusterrolebindings | grep linkerd
대략 다음과 같은 출력이 보여야 해요:
linkerd-linkerd-destination 9d
linkerd-linkerd-identity 9d
linkerd-linkerd-proxy-injector 9d
linkerd-destination-policy 9d
또한 ClusterRoleBinding을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create clusterrolebindings
다음과 같은 출력이 보여야 해요:
yes
√ control plane ServiceAccounts exist
실패 예시:
× control plane ServiceAccounts exist
missing ServiceAccounts: linkerd-identity
see https://linkerd.io/2/checks/#l5d-existence-sa for hints
Linkerd ServiceAccount가 존재하는지 확인하세요:
kubectl -n linkerd get serviceaccounts
대략 다음과 같은 출력이 보여야 해요:
NAME SECRETS AGE
default 1 14m
linkerd-destination 1 14m
linkerd-heartbeat 1 14m
linkerd-identity 1 14m
linkerd-proxy-injector 1 14m
또한 Linkerd 네임스페이스에서 ServiceAccount를 생성할 권한이 있는지 확인하세요:
kubectl -n linkerd auth can-i create serviceaccounts
다음과 같은 출력이 보여야 해요:
yes
√ control plane CustomResourceDefinitions exist
실패 예시:
× control plane CustomResourceDefinitions exist
missing CustomResourceDefinitions: serviceprofiles.linkerd.io
see https://linkerd.io/2/checks/#l5d-existence-crd for hints
Linkerd CRD가 존재하는지 확인하세요:
kubectl get customresourcedefinitions
대략 다음과 같은 출력이 보여야 해요:
NAME CREATED AT
serviceprofiles.linkerd.io 2019-04-25T21:47:31Z
또한 CRD를 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create customresourcedefinitions
다음과 같은 출력이 보여야 해요:
yes
√ control plane MutatingWebhookConfigurations exist
실패 예시:
× control plane MutatingWebhookConfigurations exist
missing MutatingWebhookConfigurations: linkerd-proxy-injector-webhook-config
see https://linkerd.io/2/checks/#l5d-existence-mwc for hints
Linkerd MutatingWebhookConfigurations가 존재하는지 확인하세요:
kubectl get mutatingwebhookconfigurations | grep linkerd
대략 다음과 같은 출력이 보여야 해요:
linkerd-proxy-injector-webhook-config 2019-07-01T13:13:26Z
또한 MutatingWebhookConfigurations를 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create mutatingwebhookconfigurations
다음과 같은 출력이 보여야 해요:
yes
√ control plane ValidatingWebhookConfigurations exist
실패 예시:
× control plane ValidatingWebhookConfigurations exist
missing ValidatingWebhookConfigurations: linkerd-sp-validator-webhook-config
see https://linkerd.io/2/checks/#l5d-existence-vwc for hints
Linkerd ValidatingWebhookConfiguration이 존재하는지 확인하세요:
kubectl get validatingwebhookconfigurations | grep linkerd
대략 다음과 같은 출력이 보여야 해요:
linkerd-sp-validator-webhook-config 2019-07-01T13:13:26Z
또한 ValidatingWebhookConfigurations를 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create validatingwebhookconfigurations
다음과 같은 출력이 보여야 해요:
yes
√ proxy-init container runs as root if docker container runtime is used
실패 예시:
× proxy-init container runs as root user if docker container runtime is used
there are nodes using the docker container runtime and proxy-init container must run as root user.
try installing linkerd via --set proxyInit.runAsRoot=true
see https://linkerd.io/2/checks/#l5d-proxy-init-run-as-root for hints
docker를 컨테이너 런타임(CRI)으로 실행하는 Kubernetes 노드는 iptables를 위해 init 컨테이너가 root로 실행되어야 해요.
관리형 k8s의 최신 배포판은 containerd를 사용하므로 이런 문제가 없어요.
init 컨테이너에 root가 없으면 다음과 같은 오류가 발생할 수 있어요:
time="2021-11-15T04:41:31Z" level=info msg="iptables-save -t nat"
Error: exit status 1
time="2021-11-15T04:41:31Z" level=info msg="iptables-save v1.8.7 (legacy): Cannot initialize: Permission denied (you must be root)\n\n"
자세한 내용은 linkerd/linkerd2#7283 및 linkerd/linkerd2#7308을 참고하세요.
"linkerd-existence" 체크
√ 'linkerd-config' config map exists
실패 예시:
× 'linkerd-config' config map exists
missing ConfigMaps: linkerd-config
see https://linkerd.io/2/checks/#l5d-existence-linkerd-config for hints
Linkerd ConfigMap이 존재하는지 확인하세요:
kubectl -n linkerd get configmap/linkerd-config
대략 다음과 같은 출력이 보여야 해요:
NAME DATA AGE
linkerd-config 3 61m
또한 ConfigMap을 생성할 권한이 있는지 확인하세요:
kubectl -n linkerd auth can-i create configmap
다음과 같은 출력이 보여야 해요:
yes
√ control plane replica sets are ready
이 실패는 Linkerd의 ReplicaSet 중 하나가 파드를 스케줄하는 데 실패할 때 발생해요.
자세한 내용은 Kubernetes 문서의 Failed Deployments를 참고하세요.
√ no unschedulable pods
실패 예시:
× no unschedulable pods
linkerd-prometheus-6b668f774d-j8ncr: 0/1 nodes are available: 1 Insufficient cpu.
see https://linkerd.io/2/checks/#l5d-existence-unschedulable-pods for hints
자세한 내용은 Kubernetes 문서의 Unschedulable Pod Condition을 참고하세요.
"linkerd-identity" 체크
√ certificate config is valid
실패 예시:
× certificate config is valid
key ca.crt containing the trust anchors needs to exist in secret linkerd-identity-issuer if --identity-external-issuer=true
see https://linkerd.io/2/checks/#l5d-identity-cert-config-valid
× certificate config is valid
key crt.pem containing the issuer certificate needs to exist in secret linkerd-identity-issuer if --identity-external-issuer=false
see https://linkerd.io/2/checks/#l5d-identity-cert-config-valid
linkerd-identity-issuer secret이 Linkerd가 구성된 scheme에 맞는 올바른 키를 포함하고 있는지 확인하세요. scheme이 kubernetes.io/tls라면 secret은 tls.crt, tls.key, ca.crt 키를 포함해야 해요. 반면 scheme이 linkerd.io/tls라면 필요한 키는 crt.pem과 key.pem이에요.
√ trust roots are using supported crypto algorithm
실패 예시:
× trust roots are using supported crypto algorithm
Invalid roots:
* 165223702412626077778653586125774349756 identity.linkerd.cluster.local must use P-256 curve for public key, instead P-521 was used
see https://linkerd.io/2/checks/#l5d-identity-trustAnchors-use-supported-crypto
모든 root가 공개 키 알고리즘으로 ECDSA P-256을 사용해야 해요.
√ trust roots are within their validity period
실패 예시:
× trust roots are within their validity period
Invalid roots:
* 199607941798581518463476688845828639279 identity.linkerd.cluster.local not valid anymore. Expired on 2019-12-19T13:08:18Z
see https://linkerd.io/2/checks/#l5d-identity-trustAnchors-are-time-valid for hints
이런 성격의 실패는 root가 만료되었음을 나타내요. 이 경우 root와 issuer 인증서를 동시에 업데이트해야 해요. Replacing Expired Certificates 문서에 설명된 절차를 따라 클러스터를 안정적인 상태로 되돌릴 수 있어요.
√ trust roots are valid for at least 60 days
경고 예시:
‼ trust roots are valid for at least 60 days
Roots expiring soon:
* 66509928892441932260491975092256847205 identity.linkerd.cluster.local will expire on 2019-12-19T13:30:57Z
see https://linkerd.io/2/checks/#l5d-identity-trustAnchors-not-expiring-soon for hints
이 경고는 일부 root의 만료가 다가오고 있음을 나타내요. 가동 중단 없이 이 문제를 해결하려면 Rotating your identity certificates 문서에 설명된 절차를 따를 수 있어요.
√ issuer cert is using supported crypto algorithm
실패 예시:
× issuer cert is using supported crypto algorithm
issuer certificate must use P-256 curve for public key, instead P-521 was used
see https://linkerd.io/2/checks/#5d-identity-issuer-cert-uses-supported-crypto for hints
issuer 인증서가 공개 키 알고리즘으로 ECDSA P-256을 사용해야 해요. Generating your own mTLS root certificates 문서를 참고해 Linkerd와 함께 동작하는 인증서를 생성하는 방법을 확인할 수 있어요.
√ issuer cert is within its validity period
실패 예시:
× issuer cert is within its validity period
issuer certificate is not valid anymore. Expired on 2019-12-19T13:35:49Z
see https://linkerd.io/2/checks/#l5d-identity-issuer-cert-is-time-valid
이 실패는 issuer 인증서가 만료되었음을 나타내요. 클러스터를 유효한 상태로 되돌리려면 Replacing Expired Certificates 문서에 설명된 절차를 따르세요.
√ issuer cert is valid for at least 60 days
경고 예시:
‼ issuer cert is valid for at least 60 days
issuer certificate will expire on 2019-12-19T13:35:49Z
see https://linkerd.io/2/checks/#l5d-identity-issuer-cert-not-expiring-soon for hints
이 경고는 issuer 인증서가 곧 만료된다는 뜻이에요. cert-manager 같은 외부 인증서 관리 솔루션에 의존하지 않는다면 Rotating your identity certificates 문서에 설명된 절차를 따를 수 있어요.
√ issuer cert is issued by the trust root
오류 예시:
× issuer cert is issued by the trust root
x509: certificate signed by unknown authority (possibly because of "x509: ECDSA verification failure" while trying to verify candidate authority certificate "identity.linkerd.cluster.local")
see https://linkerd.io/2/checks/#l5d-identity-issuer-cert-issued-by-trust-anchor for hints
이 오류는 linkerd-identity-issuer secret에 있는 issuer 인증서를 Linkerd가 구성된 어떤 root로도 검증할 수 없음을 나타내요. CLI 설치 절차를 사용했다면 이런 일이 발생하지 않아야 해요. Helm으로 설치했거나 issuer 인증서를 오작동하는 인증서 관리 솔루션이 관리한다면 클러스터가 이런 잘못된 상태에 빠질 수 있어요. 이 경우 가장 좋은 방법은 upgrade 명령으로 인증서를 업데이트하는 것이에요:
linkerd upgrade \
--identity-issuer-certificate-file=./your-new-issuer.crt \
--identity-issuer-key-file=./your-new-issuer.key \
--identity-trust-anchors-file=./your-new-roots.crt \
--force | kubectl apply -f -
업그레이드 프로세스가 끝나면 linkerd check --proxy의 출력은 다음과 같아야 해요:
linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
√ issuer cert is within its validity period
√ issuer cert is valid for at least 60 days
√ issuer cert is issued by the trust root
linkerd-identity-data-plane
---------------------------
√ data plane proxies certificate match CA
"linkerd-webhooks-and-apisvc-tls" 체크
√ proxy-injector webhook has valid cert
실패 예시:
× proxy-injector webhook has valid cert
secrets "linkerd-proxy-injector-tls" not found
see https://linkerd.io/2/checks/#l5d-proxy-injector-webhook-cert-valid for hints
linkerd-proxy-injector-k8s-tls secret이 존재하고 적절한 tls.crt와 tls.key 데이터 항목을 포함하는지 확인하세요. 2.9 이전 버전의 경우 secret 이름은 linkerd-proxy-injector-tls이고 crt.pem과 key.pem 데이터 항목을 포함해야 해요.
× proxy-injector webhook has valid cert
cert is not issued by the trust anchor: x509: certificate is valid for xxxxxx, not linkerd-proxy-injector.linkerd.svc
see https://linkerd.io/2/checks/#l5d-proxy-injector-webhook-cert-valid for hints
여기서는 인증서가 특별히 linkerd-proxy-injector.linkerd.svc용으로 발급되었는지 확인해야 해요.
√ proxy-injector cert is valid for at least 60 days
실패 예시:
‼ proxy-injector cert is valid for at least 60 days
certificate will expire on 2020-11-07T17:00:07Z
see https://linkerd.io/2/checks/#l5d-proxy-injector-webhook-cert-not-expiring-soon for hints
이 경고는 proxy-injector webhook 인증서의 만료가 다가오고 있음을 나타내요. 가동 중단 없이 이 문제를 해결하려면 Automatically Rotating your webhook TLS Credentials 문서에 설명된 절차를 따를 수 있어요.
√ sp-validator webhook has valid cert
실패 예시:
× sp-validator webhook has valid cert
secrets "linkerd-sp-validator-tls" not found
see https://linkerd.io/2/checks/#l5d-sp-validator-webhook-cert-valid for hints
linkerd-sp-validator-k8s-tls secret이 존재하고 적절한 tls.crt와 tls.key 데이터 항목을 포함하는지 확인하세요. 2.9 이전 버전의 경우 secret 이름은 linkerd-sp-validator-tls이고 crt.pem과 key.pem 데이터 항목을 포함해야 해요.
× sp-validator webhook has valid cert
cert is not issued by the trust anchor: x509: certificate is valid for xxxxxx, not linkerd-sp-validator.linkerd.svc
see https://linkerd.io/2/checks/#l5d-sp-validator-webhook-cert-valid for hints
여기서는 인증서가 특별히 linkerd-sp-validator.linkerd.svc용으로 발급되었는지 확인해야 해요.
√ sp-validator cert is valid for at least 60 days
실패 예시:
‼ sp-validator cert is valid for at least 60 days
certificate will expire on 2020-11-07T17:00:07Z
see https://linkerd.io/2/checks/#l5d-sp-validator-webhook-cert-not-expiring-soon for hints
이 경고는 sp-validator webhook 인증서의 만료가 다가오고 있음을 나타내요. 가동 중단 없이 이 문제를 해결하려면 Automatically Rotating your webhook TLS Credentials 문서에 설명된 절차를 따를 수 있어요.
√ policy-validator webhook has valid cert
실패 예시:
× policy-validator webhook has valid cert
secrets "linkerd-policy-validator-tls" not found
see https://linkerd.io/2/checks/#l5d-policy-validator-webhook-cert-valid for hints
linkerd-policy-validator-k8s-tls secret이 존재하고 적절한 tls.crt와 tls.key 데이터 항목을 포함하는지 확인하세요.
× policy-validator webhook has valid cert
cert is not issued by the trust anchor: x509: certificate is valid for xxxxxx, not linkerd-policy-validator.linkerd.svc
see https://linkerd.io/2/checks/#l5d-policy-validator-webhook-cert-valid for hints
여기서는 인증서가 특별히 linkerd-policy-validator.linkerd.svc용으로 발급되었는지 확인해야 해요.
√ policy-validator cert is valid for at least 60 days
실패 예시:
‼ policy-validator cert is valid for at least 60 days
certificate will expire on 2020-11-07T17:00:07Z
see https://linkerd.io/2/checks/#l5d-policy-validator-webhook-cert-not-expiring-soon for hints
이 경고는 policy-validator webhook 인증서의 만료가 다가오고 있음을 나타내요. 가동 중단 없이 이 문제를 해결하려면 Automatically Rotating your webhook TLS Credentials 문서에 설명된 절차를 따를 수 있어요.
"linkerd-identity-data-plane" 체크
√ data plane proxies certificate match CA
경고 예시:
‼ data plane proxies certificate match CA
Some pods do not have the current trust bundle and must be restarted:
* emojivoto/emoji-d8d7d9c6b-8qwfx
* emojivoto/vote-bot-588499c9f6-zpwz6
* emojivoto/voting-8599548fdc-6v64k
see https://linkerd.io/2/checks/#l5d-identity-data-plane-proxies-certs-match-ca for hints
이 경고를 보는 것은 일부 메시된 파드의 프록시에 만료된 인증서가 있음을 나타내요. 이는 인증서 회전을 다루는 upgrade 작업 중에 가장 흔하게 발생해요. 이 문제를 해결하려면 rollout restart를 사용해 해당 파드를 재시작할 수 있어요. 그러면 파드들이 linkerd-config configmap에서 올바른 인증서를 가져오게 돼요. --identity-trust-anchors-file 플래그로 root를 수정하면서 upgrade를 수행하면 Linkerd 구성요소가 재시작돼요. 이 작업이 진행되는 동안 check --proxy 명령이 Linkerd 구성요소에 관한 경고를 출력할 수 있어요:
‼ data plane proxies certificate match CA
Some pods do not have the current trust bundle and must be restarted:
* linkerd/linkerd-sp-validator-75f9d96dc-rch4x
* linkerd-viz/tap-68d8bbf64-mpzgb
* linkerd-viz/web-849f74b7c6-qlhwc
see https://linkerd.io/2/checks/#l5d-identity-data-plane-proxies-certs-match-ca for hints
이런 경우에는 upgrade 작업이 완료될 때까지 기다리세요. 만료된 파드가 종료되고 올바른 인증서로 구성된 새 파드로 교체될 거예요.
"linkerd-api" 체크
√ control plane pods are ready
실패 예시:
× control plane pods are ready
No running pods for "linkerd-sp-validator"
다음으로 컨트롤 플레인 파드의 상태를 확인하세요:
kubectl -n linkerd get po
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
linkerd-destination-5fd7b5d466-szgqm 2/2 Running 1 12m
linkerd-identity-54df78c479-hbh5m 2/2 Running 0 12m
linkerd-proxy-injector-67f8cf65f7-4tvt5 2/2 Running 1 12m
√ cluster networks can be verified
실패 예시:
‼ cluster networks can be verified
the following nodes do not expose a podCIDR:
node-0
see https://linkerd.io/2/checks/#l5d-cluster-networks-verified for hints
Linkerd에는 클러스터 내 트래픽과 이그레스 트래픽을 구분할 수 있게 해 주는 clusterNetworks 설정이 있어요. 각 노드의 podCIDR 필드를 통해 Linkerd는 가능한 모든 파드 IP가 clusterNetworks 설정에 포함되는지 검증할 수 있어요. 노드에 podCIDR 필드가 없으면 Linkerd가 이를 검증할 수 없고, 그 노드가 clusterNetworks 밖의 IP로 파드를 만들 수 있어요. 그러면 메시가 제대로 되지 않을 수 있어요.
노드는 podCIDR 필드를 노출할 의무가 없기 때문에 이는 경고로 이어져요. 노드가 이 필드를 노출하게 하는 방법은 사용하는 특정 배포판에 따라 달라요.
√ cluster networks contains all node podCIDRs
실패 예시:
× cluster networks contains all node podCIDRs
node has podCIDR(s) [10.244.0.0/24] which are not contained in the Linkerd clusterNetworks.
Try installing linkerd via --set clusterNetworks=10.244.0.0/24
see https://linkerd.io/2/checks/#l5d-cluster-networks-cidr for hints
Linkerd에는 클러스터 내 트래픽과 이그레스 트래픽을 구분할 수 있게 해 주는 clusterNetworks 설정이 있어요. 이 경고는 클러스터에 Linkerd의 clusterNetworks에 포함되지 않은 podCIDR이 있음을 나타내요. 이 네트워크의 파드로 가는 트래픽은 메시가 제대로 되지 않을 수 있어요. 이를 해결하려면 clusterNetworks 설정을 업데이트해서 클러스터의 모든 파드 네트워크를 포함시키세요.
√ cluster networks contains all pods
실패 예시:
× the Linkerd clusterNetworks [10.244.0.0/24] do not include pod default/foo (104.21.63.202)
see https://linkerd.io/2/checks/#l5d-cluster-networks-pods for hints
× the Linkerd clusterNetworks [10.244.0.0/24] do not include svc default/bar (10.96.217.194)
see https://linkerd.io/2/checks/#l5d-cluster-networks-pods for hints
Linkerd에는 클러스터 내 트래픽과 이그레스 트래픽을 구분할 수 있게 해 주는 clusterNetworks 설정이 있어요. 이 경고는 클러스터에 Linkerd의 clusterNetworks에 포함되지 않은 파드 또는 ClusterIP 서비스가 있음을 나타내요. 이 네트워크의 파드나 서비스로 가는 트래픽은 메시가 제대로 되지 않을 수 있어요. 이를 해결하려면 clusterNetworks 설정을 업데이트해서 클러스터의 모든 파드 및 서비스 네트워크를 포함시키세요.
"linkerd-version" 체크
√ can determine the latest version
실패 예시:
× can determine the latest version
Get https://versioncheck.linkerd.io/version.json?version=edge-19.1.2&uuid=test-uuid&source=cli: context deadline exceeded
linkerd cli가 실행되는 환경에서 Linkerd 버전 체크 엔드포인트에 연결할 수 있는지 확인하세요:
curl "https://versioncheck.linkerd.io/version.json?version=edge-19.1.2&uuid=test-uuid&source=cli"
대략 다음과 같은 출력이 보여야 해요:
{"stable":"stable-2.1.0","edge":"edge-19.1.2"}
√ cli is up-to-date
실패 예시:
unsupported version channel
‼ cli is up-to-date
unsupported version channel: stable-2.14.10
2024년 2월부터 Linkerd 프로젝트 자체는 edge 릴리스 아티팩트만 만들어요. 자세한 내용은 Releases and Versions 페이지를 읽어보세요.
is running version X but the latest version is Y
‼ cli is up-to-date
is running version 19.1.1 but the latest edge version is 19.1.2
linkerd cli의 더 새로운 버전이 있어요. Upgrading Linkerd 페이지를 참고하세요.
"control-plane-version" 체크
√ control plane is up-to-date
실패 예시:
unsupported version channel
‼ control plane is up-to-date
unsupported version channel: stable-2.14.10
2024년 2월부터 Linkerd 프로젝트 자체는 edge 릴리스 아티팩트만 만들어요. 자세한 내용은 Releases and Versions 페이지를 읽어보세요.
is running version X but the latest version is Y
‼ control plane is up-to-date
is running version 19.1.1 but the latest edge version is 19.1.2
컨트롤 플레인의 더 새로운 버전이 있어요. Upgrading Linkerd 페이지를 참고하세요.
√ control plane and cli versions match
실패 예시:
‼ control plane and cli versions match
mismatched channels: running stable-2.1.0 but retrieved edge-19.1.2
CLI와 컨트롤 플레인이 서로 다른 유형의 릴리스를 실행하고 있어요. 이는 문제를 일으킬 수 있어요.
"linkerd-control-plane-proxy" 체크
√ control plane proxies are healthy
이 오류는 Linkerd 컨트롤 플레인에서 실행되는 프록시가 건강하지 않음을 나타내요. Linkerd가 올바른 설정으로 설치되었는지 확인하거나 필요에 따라 Linkerd를 다시 설치하세요.
√ control plane proxies are up-to-date
이 경고는 Linkerd 컨트롤 플레인에서 실행되는 프록시가 오래된 버전을 실행 중임을 나타내요. 최신 Linkerd 릴리스를 다운로드하고 Upgrading Linkerd하기를 권장해요.
√ control plane proxies and cli versions match
이 경고는 Linkerd 컨트롤 플레인에서 실행되는 프록시가 Linkerd CLI와 다른 버전을 실행 중임을 나타내요. 필요에 따라 CLI나 컨트롤 플레인 중 하나를 업데이트해서 버전을 동기화해 두길 권장해요.
"linkerd-data-plane" 체크
이 체크들은 --proxy 플래그를 설정했을 때만 실행돼요. 이 플래그는 linkerd inject를 실행한 후 주입된 프록시가 정상적으로 동작하는지 확인하기 위한 용도예요.
√ data plane namespace exists
실패 예시:
linkerd check --proxy --namespace foo
× data plane namespace exists
The "foo" namespace does not exist
지정한 --namespace가 존재하는지 확인하거나, 모든 네임스페이스를 확인하려면 파라미터를 생략하세요.
√ data plane proxies are ready
실패 예시:
× data plane proxies are ready
No "linkerd-proxy" containers found
linkerd inject 명령으로 Linkerd 프록시를 애플리케이션에 주입했는지 확인하세요.
linkerd inject에 대한 자세한 내용은 Getting Started 가이드의 Step 5: Install the demo app을 참고하세요.
√ data plane is up-to-date
실패 예시:
‼ data plane is up-to-date
linkerd/linkerd-prometheus-74d66f86f6-6t6dh: is running version 19.1.2 but the latest edge version is 19.1.3
Upgrading Linkerd 페이지를 참고하세요.
√ data plane and cli versions match
‼ data plane and cli versions match
linkerd/linkerd-identity-5f6c45d6d9-9hd9j: is running version 19.1.2 but the latest edge version is 19.1.3
Upgrading Linkerd 페이지를 참고하세요.
√ data plane pod labels are configured correctly
실패 예시:
‼ data plane pod labels are configured correctly
Some labels on data plane pods should be annotations:
* emojivoto/voting-ff4c54b8d-tv9pp
linkerd.io/inject
linkerd.io/inject, config.linkerd.io/* 또는 config.alpha.linkerd.io/*는 효과를 보려면 어노테이션이어야 해요.
√ data plane service labels are configured correctly
실패 예시:
‼ data plane service labels and annotations are configured correctly
Some labels on data plane services should be annotations:
* emojivoto/emoji-svc
config.linkerd.io/control-port
config.linkerd.io/* 또는 config.alpha.linkerd.io/*는 효과를 보려면 어노테이션이어야 해요.
√ data plane service annotations are configured correctly
실패 예시:
‼ data plane service annotations are configured correctly
Some annotations on data plane services should be labels:
* emojivoto/emoji-svc
mirror.linkerd.io/exported
mirror.linkerd.io/exported는 효과를 보려면 레이블이어야 해요.
√ opaque ports are properly annotated
실패 예시:
× opaque ports are properly annotated
* service emoji-svc targets the opaque port 8080 through 8080; add 8080 to its config.linkerd.io/opaque-ports annotation
see https://linkerd.io/2/checks/#linkerd-opaque-ports-definition for hints
파드가 config.linkerd.io/opaque-ports 어노테이션으로 포트를 opaque로 표시하면, 해당 포트를 대상으로 하는 모든 Service도 config.linkerd.io/opaque-ports 어노테이션으로 그 포트를 opaque로 표시해야 해요. 포트가 파드에서는 opaque로 표시되었지만 Service에서는 그렇지 않으면(또는 그 반대), 트래픽이 파드로 직접 보내지는지(예: headless Service) ClusterIP Service를 통해 보내지는지에 따라 일관성 없는 동작이 발생할 수 있어요. 이 오류는 Pod와 Service 양쪽에 config.linkerd.io/opaque-ports 어노테이션을 추가하면 해결돼요. 자세한 내용은 Protocol Detection을 참고하세요.
"linkerd-ha-checks" 체크
이 체크들은 Linkerd가 HA 모드로 설치된 경우 실행돼요.
√ multiple replicas of control plane pods
경고 예시:
‼ multiple replicas of control plane pods
not enough replicas available for [linkerd-identity]
see https://linkerd.io/2/checks/#l5d-control-plane-replicas for hints
이것은 컨트롤 플레인 파드 중 하나가 최소 두 개의 복제본을 실행하고 있지 않을 때 발생해요. 이는 보통 노드 리소스 부족으로 인해 발생해요.
확장 (Extensions)
√ namespace configuration for extensions
Linkerd의 확장 모델은 각 확장을 "소유"하는 네임스페이스에 확장 이름이 레이블로 표시되어야 한다고 요구해요. 예를 들어 viz가 설치되는 네임스페이스에는 linkerd.io/extension=viz 레이블이 붙어요. 이 경고는 클러스터 전반에서 확장 값이 레이블 키에 두 번 이상 사용되면 발생해요.
이 경고를 해결하려면 linkerd.io/extension 네임스페이스 레이블에 중복 값이 없는지 확인하세요. 중복 값은 확장이 서로 다른 네임스페이스에 두 번 이상 설치되었음을 나타내요.
Extensions 체크
확장이 설치되면 Linkerd 바이너리는 확장 바이너리에서 check --output json을 호출하려고 해요. 확장 바이너리가 이를 구현하는 것이 중요해요. 자세한 내용은 Extension developer docs를 참고하세요.
오류 예시:
invalid extension check output from "viz" (JSON object expected)
확장 바이너리가 예상되는 json 형식으로 헬스체크를 반환하는 check --output json을 구현하는지 확인하세요.
오류 예시:
× Linkerd command viz exists
관련 바이너리가 $PATH에 존재하는지 확인하세요.
Linkerd 확장에 대한 자세한 내용은 Extension developer docs를 참고하세요.
"linkerd-cni-plugin" 체크
이 체크들은 Linkerd가 --linkerd-cni-enabled 플래그로 설치된 경우 실행돼요. 또는 --linkerd-cni-enabled 플래그를 제공해 pre-check의 일부로 실행할 수도 있어요. 이 체크 대부분은 필요한 리소스가 제자리에 있는지 검증해요. 누락된 것이 있으면 linkerd install-cni | kubectl apply -f -로 다시 설치할 수 있어요.
√ cni plugin ConfigMap exists
오류 예시:
× cni plugin ConfigMap exists
configmaps "linkerd-cni-config" not found
see https://linkerd.io/2/checks/#cni-plugin-cm-exists for hints
linkerd-cni-config ConfigMap이 CNI 네임스페이스에 존재하는지 확인하세요:
kubectl get cm linkerd-cni-config -n linkerd-cni
대략 다음과 같은 출력이 보여야 해요:
NAME PRIV CAPS SELINUX RUNASUSER FSGROUP SUPGROUP READONLYROOTFS VOLUMES
linkerd-linkerd-cni-cni false RunAsAny RunAsAny RunAsAny RunAsAny false hostPath,secret
또한 ConfigMap을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create ConfigMaps
다음과 같은 출력이 보여야 해요:
yes
√ cni plugin ClusterRole exist
오류 예시:
× cni plugin ClusterRole exists
missing ClusterRole: linkerd-cni
see https://linkerd.io/2/checks/#cni-plugin-cr-exists for hints
클러스터 역할이 존재하는지 확인하세요:
kubectl get clusterrole linkerd-cni
대략 다음과 같은 출력이 보여야 해요:
NAME AGE
linkerd-cni 54m
또한 ClusterRole을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create ClusterRoles
다음과 같은 출력이 보여야 해요:
yes
√ cni plugin ClusterRoleBinding exist
오류 예시:
× cni plugin ClusterRoleBinding exists
missing ClusterRoleBinding: linkerd-cni
see https://linkerd.io/2/checks/#cni-plugin-crb-exists for hints
클러스터 역할 바인딩이 존재하는지 확인하세요:
kubectl get clusterrolebinding linkerd-cni
대략 다음과 같은 출력이 보여야 해요:
NAME AGE
linkerd-cni 54m
또한 ClusterRoleBinding을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create ClusterRoleBindings
다음과 같은 출력이 보여야 해요:
yes
√ cni plugin ServiceAccount exists
오류 예시:
× cni plugin ServiceAccount exists
missing ServiceAccount: linkerd-cni
see https://linkerd.io/2/checks/#cni-plugin-sa-exists for hints
CNI 서비스 어카운트가 CNI 네임스페이스에 존재하는지 확인하세요:
kubectl get ServiceAccount linkerd-cni -n linkerd-cni
대략 다음과 같은 출력이 보여야 해요:
NAME SECRETS AGE
linkerd-cni 1 45m
또한 ServiceAccount를 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create ServiceAccounts -n linkerd-cni
다음과 같은 출력이 보여야 해요:
yes
√ cni plugin DaemonSet exists
오류 예시:
× cni plugin DaemonSet exists
missing DaemonSet: linkerd-cni
see https://linkerd.io/2/checks/#cni-plugin-ds-exists for hints
CNI 데몬셋이 CNI 네임스페이스에 존재하는지 확인하세요:
kubectl get ds -n linkerd-cni
대략 다음과 같은 출력이 보여야 해요:
NAME DESIRED CURRENT READY UP-TO-DATE AVAILABLE NODE SELECTOR AGE
linkerd-cni 1 1 1 1 1 beta.kubernetes.io/os=linux 14m
또한 DaemonSet을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create DaemonSets -n linkerd-cni
다음과 같은 출력이 보여야 해요:
yes
√ cni plugin pod is running on all nodes
실패 예시:
‼ cni plugin pod is running on all nodes
number ready: 2, number scheduled: 3
see https://linkerd.io/2/checks/#cni-plugin-ready
모든 CNI 파드가 실행 중인지 확인하세요:
kubectl get po -n linkerd-cni
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
linkerd-cni-rzp2q 1/1 Running 0 9m20s
linkerd-cni-mf564 1/1 Running 0 9m22s
linkerd-cni-p5670 1/1 Running 0 9m25s
모든 파드가 CNI 구성과 바이너리 배포를 끝냈는지 확인하세요:
kubectl logs linkerd-cni-rzp2q -n linkerd-cni
대략 다음과 같은 출력이 보여야 해요:
Wrote linkerd CNI binaries to /host/opt/cni/bin
Created CNI config /host/etc/cni/net.d/10-kindnet.conflist
Done configuring CNI. Sleep=true
"linkerd-multicluster" 체크
이 체크들은 서비스 미러링 컨트롤러가 설치된 경우 실행돼요. 또한 linkerd multicluster check로 실행할 수 있어요. 이 체크 대부분은 서비스 미러링 컨트롤러가 원격 게이트웨이와 함께 올바르게 동작하는지 검증해요. 또한 체크는 쌍을 이룬 클러스터 간 end-to-end TLS가 가능한지 보장해요.
√ Link CRD exists
오류 예시:
× Link CRD exists
multicluster.linkerd.io/Link CRD is missing
see https://linkerd.io/2/checks/#l5d-multicluster-link-crd-exists for hints
multicluster 확장이 올바르게 설치되었고 links.multicluster.linkerd.io CRD가 존재하는지 확인하세요.
kubectl get crds | grep multicluster
대략 다음과 같은 출력이 보여야 해요:
NAME CREATED AT
links.multicluster.linkerd.io 2021-03-10T09:58:10Z
√ Link resources are valid
오류 예시:
× Link resources are valid
failed to parse Link east
see https://linkerd.io/2/checks/#l5d-multicluster-links-are-valid for hints
모든 link 객체가 예상된 형식으로 지정되어 있는지 확인하세요.
√ Link and CLI versions match
이 경고는 CLI 버전과 일치하지 않는 Link 리소스가 있음을 나타내요. 이는 보통 CLI는 업그레이드되었지만 Link 리소스는 업그레이드되지 않았음을 의미하며, 해당 Link들이 업그레이드될 때까지 일부 기능이 지원되지 않을 수 있어요.
Link를 업그레이드하려면 다시 생성하세요. 방법은 multicluster 문서를 참고하세요.
√ remote cluster access credentials are valid
오류 예시:
× remote cluster access credentials are valid
* secret [east/east-config]: could not find east-config secret
see https://linkerd.io/2/checks/#l5d-smc-target-clusters-access for hints
특정 대상 클러스터에 대한 관련 권한이 있는 kube-config가 secret으로 올바르게 존재하는지 확인하세요.
√ clusters share trust anchors
오류 예시:
× clusters share trust anchors
Problematic clusters:
* remote
see https://linkerd.io/2/checks/#l5d-multicluster-clusters-share-anchors for hints
위 오류는 trust anchor가 호환되지 않음을 나타내요. 이를 해결하려면 두 anchor가 동일한 인증서 집합을 포함하도록 해야 해요.
× clusters share trust anchors
Problematic clusters:
* remote: cannot parse trust anchors
see https://linkerd.io/2/checks/#l5d-multicluster-clusters-share-anchors for hints
이런 오류는 remote라는 클러스터의 anchor에 문제가 있음을 나타내요. remote 클러스터의 Linkerd 설치에서 identity config 측면이 올바른지 확인해야 해요. 원격 클러스터에 대해 check를 실행해 이를 검증할 수 있어요:
linkerd --context=remote check
√ service mirror controller has required permissions
오류 예시:
× service mirror controller has required permissions
missing Service mirror ClusterRole linkerd-service-mirror-access-local-resources: unexpected verbs expected create,delete,get,list,update,watch, got create,delete,get,update,watch
see https://linkerd.io/2/checks/#l5d-multicluster-source-rbac-correct for hints
이 오류는 서비스 미러 서비스 어카운트의 로컬 RBAC 권한이 올바르지 않음을 나타내요. 올바른 동사와 리소스가 있는지 확인하려면 ClusterRole과 Role 객체를 검사하고 rules 섹션을 살펴보세요.
linkerd-service-mirror-access-local-resources 클러스터 역할의 예상 규칙:
kubectl --context=local get clusterrole linkerd-service-mirror-access-local-resources -o yaml
다음과 같은 출력이 보여야 해요:
kind: ClusterRole
metadata:
labels:
linkerd.io/control-plane-component: linkerd-service-mirror
name: linkerd-service-mirror-access-local-resources
rules:
- apiGroups:
- ""
resources:
- endpoints
- services
verbs:
- list
- get
- watch
- create
- delete
- update
- apiGroups:
- ""
resources:
- namespaces
verbs:
- create
- list
- get
- watch
linkerd-service-mirror-read-remote-creds 역할의 예상 규칙:
kubectl --context=local get role linkerd-service-mirror-read-remote-creds -n linkerd-multicluster -o yaml
다음과 같은 출력이 보여야 해요:
kind: Role
metadata:
labels:
linkerd.io/control-plane-component: linkerd-service-mirror
name: linkerd-service-mirror-read-remote-creds
namespace: linkerd-multicluster
rules:
- apiGroups:
- ""
resources:
- secrets
verbs:
- list
- get
- watch
√ service mirror controllers are running
오류 예시:
× service mirror controllers are running
Service mirror controller is not present
see https://linkerd.io/2/checks/#l5d-multicluster-service-mirror-running for hints
파드가 스케줄링되고 이미지가 pull되며 모든 것이 시작되는 데에는 시간이 조금 걸린다는 점에 유의하세요. 이것이 영구적인 오류라면 컨트롤러 파드의 상태를 검증해 보세요:
kubectl --all-namespaces get po --selector linkerd.io/control-plane-component=linkerd-service-mirror
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
linkerd-service-mirror-7bb8ff5967-zg265 2/2 Running 0 50m
√ extension is managing controllers
오류 예시:
‼ extension is managing controllers
* using legacy service mirror controller for Link: target
see https://linkerd.io/2/checks/#l5d-multicluster-managed-controllers for hints
Linkerd 2.18에서 멀티클러스터 link를 설정하는 선언적이고 GitOps 호환이 가능한 접근 방식을 도입했어요. 이 방법에서는 컨트롤러가 멀티클러스터 확장에 통합되어, 반드시 linkerd multicluster link 명령에 의존하지 않고 Link CR과 kubeconfig secret 매니페스트를 직접 제공할 수 있어요. 이는 이전 버전의 Linkerd(v2.18 이전)와 다르며, 거기서는 (Link CR 및 secret 외에) 새 link를 만들 때마다 컨트롤러 매니페스트를 제공해야 했고 linkerd multicluster link 명령을 사용해야 했어요. 이 절차는 GitOps 워크플로우에 적합하지 않았죠.
이 체크는 연결된 클러스터가 새 모델을 사용하고 있는지 확인해요. 이전 모델에서 마이그레이션하려면, installing multicluster 문서에 자세히 설명된 대로 링크를 새 controllers 항목으로 옮기면서 멀티클러스터 확장을 업데이트하세요. 새 컨트롤러가 배포되지만, 이전 컨트롤러가 삭제될 때까지 링크를 관리하지는 않아요. 이전 컨트롤러가 제거되면 새 컨트롤러가 Lease 객체를 확보해 서비스 미러링을 인계받아요.
√ all gateway mirrors are healthy
오류 예시:
‼ all gateway mirrors are healthy
Some gateway mirrors do not have endpoints:
linkerd-gateway-gke.linkerd-multicluster mirrored from cluster [gke]
see https://linkerd.io/2/checks/#l5d-multicluster-gateways-endpoints for hints
위 오류는 소스 클러스터의 일부 게이트웨이 미러 서비스에 연결된 endpoints 리소스가 없음을 나타내요. 이러한 endpoints는 대상 클러스터와 link가 설정될 때마다 소스 클러스터의 Linkerd 서비스 미러 컨트롤러가 만들어요.
이런 오류는 서비스 미러 컨트롤러의 리소스 생성에 문제가 있거나, 대상 클러스터의 게이트웨이 서비스의 외부 IP에 문제가 있을 수 있음을 나타내요.
√ all mirror services have endpoints
오류 예시:
‼ all mirror services have endpoints
Some mirror services do not have endpoints:
voting-svc-gke.emojivoto mirrored from cluster [gke] (gateway: [linkerd-multicluster/linkerd-gateway])
see https://linkerd.io/2/checks/#l5d-multicluster-services-endpoints for hints
위 오류는 소스 클러스터의 일부 미러 서비스에 연결된 endpoints 리소스가 없음을 나타내요. 이러한 endpoints는 서비스 미러 컨트롤러가 endpoints 값을 원격 게이트웨이의 외부 IP로 하여 미러 서비스를 만들 때 생성해요.
이런 오류는 서비스 미러 컨트롤러의 미러 리소스 생성에 문제가 있거나, 소스 클러스터의 미러 게이트웨이 서비스나 대상 클러스터의 게이트웨이 서비스 외부 IP에 문제가 있을 수 있음을 나타내요.
√ all mirror services are part of a Link
오류 예시:
‼ all mirror services are part of a Link
mirror service voting-east.emojivoto is not part of any Link
see https://linkerd.io/2/checks/#l5d-multicluster-orphaned-services for hints
위 오류는 소스 클러스터의 일부 미러 서비스에 연결된 link가 없음을 나타내요. 이 미러 서비스들은 원격 서비스가 미러링되도록 표시될 때 Linkerd 서비스 미러 컨트롤러가 만들어요.
서비스가 원격에서 올바르게 미러링되도록 표시되었는지 확인하고, 불필요한 것이 있으면 삭제하세요.
√ multicluster extension proxies are healthy
이 오류는 멀티클러스터 확장에서 실행되는 프록시가 건강하지 않음을 나타내요. linkerd-multicluster가 올바른 설정으로 설치되었는지 확인하거나 필요에 따라 다시 설치하세요.
√ multicluster extension proxies are up-to-date
이 경고는 멀티클러스터 확장에서 실행되는 프록시가 오래된 버전을 실행 중임을 나타내요. 최신 linkerd-multicluster를 다운로드하고 업그레이드하기를 권장해요.
√ multicluster extension proxies and cli versions match
이 경고는 멀티클러스터 확장에서 실행되는 프록시가 Linkerd CLI와 다른 버전을 실행 중임을 나타내요. 필요에 따라 CLI나 linkerd-multicluster 중 하나를 업데이트해서 버전을 동기화해 두길 권장해요.
"linkerd-viz" 체크
이 체크들은 linkerd-viz 확장이 설치된 경우에만 실행돼요. 이 체크는 tap, web, metrics-api, 선택적 grafana와 prometheus 인스턴스, 그리고 프록시에 특정 tap 구성을 주입하는 tap-injector로 구성된 linkerd-viz 확장의 설치를 검증하기 위한 용도예요.
√ linkerd-viz Namespace exists
이것은 linkerd-viz 확장 네임스페이스가 설치되었는지 검증하는 기본 체크예요. 확장은 다음 명령을 실행해 설치할 수 있어요:
linkerd viz install | kubectl apply -f -
설치는 --set, --values, --set-string, --set-file 플래그로 구성할 수 있어요. 구성 가능한 필드의 전체 목록은 Linkerd Viz Readme를 참고하세요.
√ linkerd-viz ClusterRoles exist
실패 예시:
× linkerd-viz ClusterRoles exist
missing ClusterRoles: linkerd-linkerd-viz-metrics-api
see https://linkerd.io/2/checks/#l5d-viz-cr-exists for hints
linkerd-viz 확장 ClusterRole이 존재하는지 확인하세요:
kubectl get clusterroles | grep linkerd-viz
대략 다음과 같은 출력이 보여야 해요:
linkerd-linkerd-viz-metrics-api 2021-01-26T18:02:17Z
linkerd-linkerd-viz-prometheus 2021-01-26T18:02:17Z
linkerd-linkerd-viz-tap 2021-01-26T18:02:17Z
linkerd-linkerd-viz-tap-admin 2021-01-26T18:02:17Z
linkerd-linkerd-viz-web-check 2021-01-26T18:02:18Z
또한 ClusterRole을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create clusterroles
다음과 같은 출력이 보여야 해요:
yes
√ linkerd-viz ClusterRoleBindings exist
실패 예시:
× linkerd-viz ClusterRoleBindings exist
missing ClusterRoleBindings: linkerd-linkerd-viz-metrics-api
see https://linkerd.io/2/checks/#l5d-viz-crb-exists for hints
linkerd-viz 확장 ClusterRoleBinding이 존재하는지 확인하세요:
kubectl get clusterrolebindings | grep linkerd-viz
대략 다음과 같은 출력이 보여야 해요:
linkerd-linkerd-viz-metrics-api ClusterRole/linkerd-linkerd-viz-metrics-api 18h
linkerd-linkerd-viz-prometheus ClusterRole/linkerd-linkerd-viz-prometheus 18h
linkerd-linkerd-viz-tap ClusterRole/linkerd-linkerd-viz-tap 18h
linkerd-linkerd-viz-tap-auth-delegator ClusterRole/system:auth-delegator 18h
linkerd-linkerd-viz-web-admin ClusterRole/linkerd-linkerd-viz-tap-admin 18h
linkerd-linkerd-viz-web-check ClusterRole/linkerd-linkerd-viz-web-check 18h
또한 ClusterRoleBinding을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create clusterrolebindings
다음과 같은 출력이 보여야 해요:
yes
√ viz extension proxies are healthy
이 오류는 viz 확장에서 실행되는 프록시가 건강하지 않음을 나타내요. linkerd-viz가 올바른 설정으로 설치되었는지 확인하거나 필요에 따라 다시 설치하세요.
√ viz extension proxies are up-to-date
이 경고는 viz 확장에서 실행되는 프록시가 오래된 버전을 실행 중임을 나타내요. 최신 linkerd-viz를 다운로드하고 업그레이드하기를 권장해요.
√ viz extension proxies and cli versions match
이 경고는 viz 확장에서 실행되는 프록시가 Linkerd CLI와 다른 버전을 실행 중임을 나타내요. 필요에 따라 CLI나 linkerd-viz 중 하나를 업데이트해서 버전을 동기화해 두길 권장해요.
√ tap API server has valid cert
실패 예시:
× tap API server has valid cert
secrets "tap-k8s-tls" not found
see https://linkerd.io/2/checks/#l5d-tap-cert-valid for hints
tap-k8s-tls secret이 존재하고 적절한 tls.crt와 tls.key 데이터 항목을 포함하는지 확인하세요. 2.9 이전 버전의 경우 secret 이름은 linkerd-tap-tls이고 crt.pem과 key.pem 데이터 항목을 포함해야 해요.
× tap API server has valid cert
cert is not issued by the trust anchor: x509: certificate is valid for xxxxxx, not tap.linkerd-viz.svc
see https://linkerd.io/2/checks/#l5d-tap-cert-valid for hints
여기서는 인증서가 특별히 tap.linkerd-viz.svc용으로 발급되었는지 확인해야 해요.
√ tap API server cert is valid for at least 60 days
실패 예시:
‼ tap API server cert is valid for at least 60 days
certificate will expire on 2020-11-07T17:00:07Z
see https://linkerd.io/2/checks/#l5d-webhook-cert-not-expiring-soon for hints
이 경고는 tap API Server webhook 인증서의 만료가 다가오고 있음을 나타내요. 가동 중단 없이 이 문제를 해결하려면 Automatically Rotating your webhook TLS Credentials 문서에 설명된 절차를 따를 수 있어요.
√ tap api service is running
실패 예시:
× FailedDiscoveryCheck: no response from https://10.233.31.133:443: Get https://10.233.31.133:443: net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)
tap은 kubernetes Aggregated Api-Server 모델을 사용해 사용자가 그 위에 k8s RBAC를 가질 수 있게 해요. 이 모델은 클러스터에서 다음과 같은 특정 요구사항이 있어요:
- tap Server가 kube-apiserver에서 도달 가능해야 함
- kube-apiserver가 aggregation layer를 활성화하도록 올바르게 구성되어야 함
√ linkerd-viz pods are injected
× linkerd-viz extension pods are injected
could not find proxy container for tap-59f5595fc7-ttndp pod
see https://linkerd.io/2/checks/#l5d-viz-pods-injection for hints
모든 linkerd-viz 파드가 주입되었는지 확인하세요.
kubectl -n linkerd-viz get pods
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
grafana-68cddd7cc8-nrv4h 2/2 Running 3 18h
metrics-api-77f684f7c7-hnw8r 2/2 Running 2 18h
prometheus-5f6898ff8b-s6rjc 2/2 Running 2 18h
tap-59f5595fc7-ttndp 2/2 Running 2 18h
web-78d6588d4-pn299 2/2 Running 2 18h
tap-injector-566f7ff8df-vpcwc 2/2 Running 2 18h
linkerd check를 실행해 proxy-injector가 올바르게 동작하는지 확인하세요.
√ viz extension pods are running
× viz extension pods are running
container linkerd-proxy in pod tap-59f5595fc7-ttndp is not ready
see https://linkerd.io/2/checks/#l5d-viz-pods-running for hints
모든 linkerd-viz 파드가 2/2로 실행 중인지 확인하세요.
kubectl -n linkerd-viz get pods
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
grafana-68cddd7cc8-nrv4h 2/2 Running 3 18h
metrics-api-77f684f7c7-hnw8r 2/2 Running 2 18h
prometheus-5f6898ff8b-s6rjc 2/2 Running 2 18h
tap-59f5595fc7-ttndp 2/2 Running 2 18h
web-78d6588d4-pn299 2/2 Running 2 18h
tap-injector-566f7ff8df-vpcwc 2/2 Running 2 18h
linkerd check를 실행해 proxy-injector가 올바르게 동작하는지 확인하세요.
√ prometheus is installed and configured correctly
× prometheus is installed and configured correctly
missing ClusterRoles: linkerd-linkerd-viz-prometheus
see https://linkerd.io/2/checks/#l5d-viz-cr-exists for hints
prometheus 관련 리소스가 모두 존재하고 올바르게 실행 중인지 확인하세요.
kubectl -n linkerd-viz get deploy,cm | grep prometheus
대략 다음과 같은 출력이 보여야 해요:
deployment.apps/prometheus 1/1 1 1 3m18s
configmap/prometheus-config 1 3m18s
kubectl get clusterRoleBindings | grep prometheus
대략 다음과 같은 출력이 보여야 해요:
linkerd-linkerd-viz-prometheus ClusterRole/linkerd-linkerd-viz-prometheus 3m37s
kubectl get clusterRoles | grep prometheus
대략 다음과 같은 출력이 보여야 해요:
linkerd-linkerd-viz-prometheus 2021-02-26T06:03:11Zh
√ can initialize the client
실패 예시:
× can initialize the client
Failed to get deploy for pod metrics-api-77f684f7c7-hnw8r: not running
metrics API 파드가 올바르게 실행 중인지 확인하세요.
kubectl -n linkerd-viz get pods
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
metrics-api-7bb8cb8489-cbq4m 2/2 Running 0 4m58s
tap-injector-6b9bc6fc4-cgbr4 2/2 Running 0 4m56s
tap-5f6ddcc684-k2fd6 2/2 Running 0 4m57s
web-cbb846484-d987n 2/2 Running 0 4m56s
grafana-76fd8765f4-9rg8q 2/2 Running 0 4m58s
prometheus-7c5c48c466-jc27g 2/2 Running 0 4m58s
√ viz extension self-check
실패 예시:
× viz extension self-check
No results returned
viz 확장의 metrics API에서 로그를 확인하세요:
kubectl -n linkerd-viz logs deploy/metrics-api metrics-api
√ prometheus is authorized to scrape data plane pods
실패 예시:
‼ prometheus is authorized to scrape data plane pods
prometheus may not be authorized to scrape the following pods:
* emojivoto/voting-5f46cbcdc6-p5dhn
* emojivoto/emoji-54f8786975-6qc8s
* emojivoto/vote-bot-85dfbf8996-86c44
* emojivoto/web-79db6f4548-4mzkg
consider running `linkerd viz allow-scrapes` to authorize prometheus scrapes
see https://linkerd.io/2/checks/#l5d-viz-data-plane-prom-authz for hints
이 경고는 나열된 파드가 deny 기본 인바운드 정책을 갖고 있어서 linkerd-viz Prometheus 인스턴스가 그 파드의 데이터 플레인 프록시를 스크랩하지 못할 수 있음을 나타내요. Prometheus가 데이터 플레인 파드를 스크랩할 수 없으면 그 파드를 대상으로 하는 linkerd viz 명령이 데이터를 반환하지 않아요.
이것은 네임스페이스의 데이터 플레인 프록시를 스크랩하도록 Prometheus를 인가하는 정책 리소스를 생성하는 linkerd viz allow-scrapes 명령을 실행해 해결할 수 있어요:
linkerd viz allow-scrapes --namespace emojivoto | kubectl apply -f -
이 경고는 deny 기본 인바운드 정책이 있는 파드를 포함하는 네임스페이스에서 linkerd viz allow-scrapes로 생성된 정책 리소스의 존재만 확인한다는 점에 유의하세요. 어떤 경우에는 Prometheus 스크랩이 다른 사용자 생성 인가 정책으로도 인가될 수 있어요. 나열된 파드의 메트릭이 Prometheus에 있다면 이 경고는 오탐이므로 안전하게 무시할 수 있어요.
√ data plane proxy metrics are present in Prometheus
실패 예시:
× data plane proxy metrics are present in Prometheus
Data plane metrics not found for linkerd/linkerd-identity-b8c4c48c8-pflc9.
Prometheus 대시보드를 통해 Prometheus가 각 linkerd-proxy에 연결할 수 있는지 확인하세요:
kubectl -n linkerd-viz port-forward svc/prometheus 9090
그런 다음 http://localhost:9090/targets 를 열어 linkerd-proxy 섹션을 검증하세요.
모든 파드가 여기에 표시되어야 해요. 그렇지 않다면:
- Prometheus가 k8s api 서버와 연결 문제를 겪고 있을 수 있어요. 로그를 확인하고 파드를 삭제해 일시적인 오류를 없애 보세요.
"linkerd-buoyant" 체크
이 체크들은 linkerd-buoyant 확장이 설치된 경우에만 실행돼요. 이 체크는 linkerd-buoyant CLI, buoyant-cloud-agent Deployment, buoyant-cloud-metrics DaemonSet으로 구성된 linkerd-buoyant 확장의 설치를 검증하기 위한 용도예요.
√ Linkerd extension command linkerd-buoyant exists
‼ Linkerd extension command linkerd-buoyant exists
exec: "linkerd-buoyant": executable file not found in $PATH
see https://linkerd.io/2/checks/#extensions for hints
linkerd-buoyant cli가 설치되어 있는지 확인하세요:
linkerd-buoyant check
CLI를 설치하려면:
curl https://buoyant.cloud/install | sh
√ linkerd-buoyant can determine the latest version
‼ linkerd-buoyant can determine the latest version
Get "https://buoyant.cloud/version.json": dial tcp: lookup buoyant.cloud: no such host
see https://linkerd.io/checks#l5d-buoyant for hints
linkerd cli가 실행되는 환경에서 Linkerd Buoyant 버전 체크 엔드포인트에 연결할 수 있는지 확인하세요:
curl https://buoyant.cloud/version.json
대략 다음과 같은 출력이 보여야 해요:
{"linkerd-buoyant":"v0.4.4"}
√ linkerd-buoyant cli is up-to-date
‼ linkerd-buoyant cli is up-to-date
CLI version is v0.4.3 but the latest is v0.4.4
see https://linkerd.io/checks#l5d-buoyant for hints
linkerd-buoyant CLI의 최신 버전으로 업데이트하려면:
curl https://buoyant.cloud/install | sh
√ buoyant-cloud Namespace exists
× buoyant-cloud Namespace exists
namespaces "buoyant-cloud" not found
see https://linkerd.io/checks#l5d-buoyant for hints
buoyant-cloud 네임스페이스가 존재하는지 확인하세요:
kubectl get ns/buoyant-cloud
네임스페이스가 없으면 linkerd-buoyant 설치가 누락되었거나 불완전할 수 있어요. 확장을 설치하려면:
linkerd-buoyant install | kubectl apply -f -
√ buoyant-cloud Namespace has correct labels
× buoyant-cloud Namespace has correct labels
missing app.kubernetes.io/part-of label
see https://linkerd.io/checks#l5d-buoyant for hints
linkerd-buoyant 설치가 누락되었거나 불완전할 수 있어요. 확장을 설치하려면:
linkerd-buoyant install | kubectl apply -f -
√ buoyant-cloud-agent ClusterRole exists
× buoyant-cloud-agent ClusterRole exists
missing ClusterRole: buoyant-cloud-agent
see https://linkerd.io/checks#l5d-buoyant for hints
클러스터 역할이 존재하는지 확인하세요:
kubectl get clusterrole buoyant-cloud-agent
대략 다음과 같은 출력이 보여야 해요:
NAME CREATED AT
buoyant-cloud-agent 2020-11-13T00:59:50Z
또한 ClusterRole을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create ClusterRoles
다음과 같은 출력이 보여야 해요:
yes
√ buoyant-cloud-agent ClusterRoleBinding exists
× buoyant-cloud-agent ClusterRoleBinding exists
missing ClusterRoleBinding: buoyant-cloud-agent
see https://linkerd.io/checks#l5d-buoyant for hints
클러스터 역할 바인딩이 존재하는지 확인하세요:
kubectl get clusterrolebinding buoyant-cloud-agent
대략 다음과 같은 출력이 보여야 해요:
NAME ROLE AGE
buoyant-cloud-agent ClusterRole/buoyant-cloud-agent 301d
또한 ClusterRoleBinding을 생성할 권한이 있는지 확인하세요:
kubectl auth can-i create ClusterRoleBindings
다음과 같은 출력이 보여야 해요:
yes
√ buoyant-cloud-agent ServiceAccount exists
× buoyant-cloud-agent ServiceAccount exists
missing ServiceAccount: buoyant-cloud-agent
see https://linkerd.io/checks#l5d-buoyant for hints
서비스 어카운트가 존재하는지 확인하세요:
kubectl -n buoyant-cloud get serviceaccount buoyant-cloud-agent
대략 다음과 같은 출력이 보여야 해요:
NAME SECRETS AGE
buoyant-cloud-agent 1 301d
또한 ServiceAccount를 생성할 권한이 있는지 확인하세요:
kubectl -n buoyant-cloud auth can-i create ServiceAccount
다음과 같은 출력이 보여야 해요:
yes
√ buoyant-cloud-id Secret exists
× buoyant-cloud-id Secret exists
missing Secret: buoyant-cloud-id
see https://linkerd.io/checks#l5d-buoyant for hints
secret이 존재하는지 확인하세요:
kubectl -n buoyant-cloud get secret buoyant-cloud-id
대략 다음과 같은 출력이 보여야 해요:
NAME TYPE DATA AGE
buoyant-cloud-id Opaque 4 301d
또한 ServiceAccount를 생성할 권한이 있는지 확인하세요:
kubectl -n buoyant-cloud auth can-i create ServiceAccount
다음과 같은 출력이 보여야 해요:
yes
√ buoyant-cloud-agent Deployment exists
× buoyant-cloud-agent Deployment exists
deployments.apps "buoyant-cloud-agent" not found
see https://linkerd.io/checks#l5d-buoyant for hints
buoyant-cloud-agent Deployment가 존재하는지 확인하세요:
kubectl -n buoyant-cloud get deploy/buoyant-cloud-agent
Deployment가 없으면 linkerd-buoyant 설치가 누락되었거나 불완전할 수 있어요. 확장을 다시 설치하려면:
linkerd-buoyant install | kubectl apply -f -
√ buoyant-cloud-agent Deployment is running
× buoyant-cloud-agent Deployment is running
no running pods for buoyant-cloud-agent Deployment
see https://linkerd.io/checks#l5d-buoyant for hints
파드가 스케줄링되고 이미지가 pull되며 모든 것이 시작되는 데에는 시간이 조금 걸린다는 점에 유의하세요. 이것이 영구적인 오류라면 buoyant-cloud-agent Deployment의 상태를 검증해 보세요:
kubectl -n buoyant-cloud get po --selector app=buoyant-cloud-agent
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
buoyant-cloud-agent-6b8c6888d7-htr7d 2/2 Running 0 156m
에이전트의 로그를 확인하세요:
kubectl logs -n buoyant-cloud buoyant-cloud-agent-6b8c6888d7-htr7d buoyant-cloud-agent
√ buoyant-cloud-agent Deployment is injected
× buoyant-cloud-agent Deployment is injected
could not find proxy container for buoyant-cloud-agent-6b8c6888d7-htr7d pod
see https://linkerd.io/checks#l5d-buoyant for hints
buoyant-cloud-agent 파드가 주입되었는지 확인하세요. READY 열에 2/2가 표시되어야 해요:
kubectl -n buoyant-cloud get pods --selector app=buoyant-cloud-agent
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
buoyant-cloud-agent-6b8c6888d7-htr7d 2/2 Running 0 161m
linkerd check를 실행해 proxy-injector가 올바르게 동작하는지 확인하세요.
√ buoyant-cloud-agent Deployment is up-to-date
‼ buoyant-cloud-agent Deployment is up-to-date
incorrect app.kubernetes.io/version label: v0.4.3, expected: v0.4.4
see https://linkerd.io/checks#l5d-buoyant for hints
버전을 확인하세요:
linkerd-buoyant version
대략 다음과 같은 출력이 보여야 해요:
CLI version: v0.4.4
Agent version: v0.4.4
최신 버전으로 업데이트하려면:
linkerd-buoyant install | kubectl apply -f -
√ buoyant-cloud-agent Deployment is running a single pod
× buoyant-cloud-agent Deployment is running a single pod
expected 1 buoyant-cloud-agent pod, found 2
see https://linkerd.io/checks#l5d-buoyant for hints
buoyant-cloud-agent는 singleton으로 실행되어야 해요. 다른 파드가 있는지 확인하세요:
kubectl get po -A --selector app=buoyant-cloud-agent
√ buoyant-cloud-metrics DaemonSet exists
× buoyant-cloud-metrics DaemonSet exists
deployments.apps "buoyant-cloud-metrics" not found
see https://linkerd.io/checks#l5d-buoyant for hints
buoyant-cloud-metrics DaemonSet이 존재하는지 확인하세요:
kubectl -n buoyant-cloud get daemonset/buoyant-cloud-metrics
DaemonSet이 없으면 linkerd-buoyant 설치가 누락되었거나 불완전할 수 있어요. 확장을 다시 설치하려면:
linkerd-buoyant install | kubectl apply -f -
√ buoyant-cloud-metrics DaemonSet is running
× buoyant-cloud-metrics DaemonSet is running
no running pods for buoyant-cloud-metrics DaemonSet
see https://linkerd.io/checks#l5d-buoyant for hints
파드가 스케줄링되고 이미지가 pull되며 모든 것이 시작되는 데에는 시간이 조금 걸린다는 점에 유의하세요. 이것이 영구적인 오류라면 buoyant-cloud-metrics DaemonSet의 상태를 검증해 보세요:
kubectl -n buoyant-cloud get po --selector app=buoyant-cloud-metrics
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
buoyant-cloud-metrics-kt9mv 2/2 Running 0 163m
buoyant-cloud-metrics-q8jhj 2/2 Running 0 163m
buoyant-cloud-metrics-qtflh 2/2 Running 0 164m
buoyant-cloud-metrics-wqs4k 2/2 Running 0 163m
에이전트의 로그를 확인하세요:
kubectl logs -n buoyant-cloud buoyant-cloud-metrics-kt9mv buoyant-cloud-metrics
√ buoyant-cloud-metrics DaemonSet is injected
× buoyant-cloud-metrics DaemonSet is injected
could not find proxy container for buoyant-cloud-agent-6b8c6888d7-htr7d pod
see https://linkerd.io/checks#l5d-buoyant for hints
buoyant-cloud-metrics 파드가 주입되었는지 확인하세요. READY 열에 2/2가 표시되어야 해요:
kubectl -n buoyant-cloud get pods --selector app=buoyant-cloud-metrics
대략 다음과 같은 출력이 보여야 해요:
NAME READY STATUS RESTARTS AGE
buoyant-cloud-metrics-kt9mv 2/2 Running 0 166m
buoyant-cloud-metrics-q8jhj 2/2 Running 0 166m
buoyant-cloud-metrics-qtflh 2/2 Running 0 166m
buoyant-cloud-metrics-wqs4k 2/2 Running 0 166m
linkerd check를 실행해 proxy-injector가 올바르게 동작하는지 확인하세요.
√ buoyant-cloud-metrics DaemonSet is up-to-date
‼ buoyant-cloud-metrics DaemonSet is up-to-date
incorrect app.kubernetes.io/version label: v0.4.3, expected: v0.4.4
see https://linkerd.io/checks#l5d-buoyant for hints
버전을 확인하세요:
kubectl -n buoyant-cloud get daemonset/buoyant-cloud-metrics -o jsonpath='{.metadata.labels}'
대략 다음과 같은 출력이 보여야 해요:
{"app.kubernetes.io/name":"metrics","app.kubernetes.io/part-of":"buoyant-cloud","app.kubernetes.io/version":"v0.4.4"}
최신 버전으로 업데이트하려면:
linkerd-buoyant install | kubectl apply -f -