使用runsc挂起的Kubernetes中不受信任的工作负载?

使用runsc挂起的Kubernetes中不受信任的工作负载?,kubernetes,containerd,gvisor,Kubernetes,Containerd,Gvisor,我一直在学习本教程,并且能够在aws环境中创建K8S集群,直到这一步。一切正常,但工作负载不可信。不受信任的工作负载容器挂起在其pendind状态 $ k get pods -o wide NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES untrusted 0/1 Pending 0 3m38

我一直在学习本教程,并且能够在aws环境中创建K8S集群,直到这一步。一切正常,但工作负载不可信。不受信任的工作负载容器挂起在其pendind状态

$ k get pods -o wide
NAME        READY   STATUS    RESTARTS   AGE     IP           NODE           NOMINATED NODE   READINESS GATES
untrusted   0/1     Pending   0          3m38s   10.200.1.7   ip-10-0-1-21   <none>           <none>
我可以通过启动以下命令查看正在运行的容器:

ubuntu@ip-10-0-1-21:~$ sudo runsc --root  /run/containerd/runsc/k8s.io list
ID                                                                 PID         STATUS      BUNDLE                                                                                                                   CREATED                          OWNER
810812c901c432ef406bebe4730a925a73976e0f057a724cfd84ef8e5d9cefc4   1077        running     /run/containerd/io.containerd.runtime.v1.linux/k8s.io/810812c901c432ef406bebe4730a925a73976e0f057a724cfd84ef8e5d9cefc4   2021-04-18T15:35:46.15756454Z    
e1241cc457631f60ab8560317235fbe97bf8b0a89b86336c8dd59d5dc0a27654   1077        running     /run/containerd/io.containerd.runtime.v1.linux/k8s.io/e1241cc457631f60ab8560317235fbe97bf8b0a89b86336c8dd59d5dc0a27654   2021-04-18T15:35:48.208150407Z 

ubuntu@ip-10-0-1-21:~$ sudo ctr -n k8s.io containers list
CONTAINER                                                           IMAGE                                                                      RUNTIME                           
810812c901c432ef406bebe4730a925a73976e0f057a724cfd84ef8e5d9cefc4    sha256:da86e6ba6ca197bf6bc5e9d900febd906b133eaa4750e6bed647b0fbe50ed43e    io.containerd.runtime.v1.linux    
e1241cc457631f60ab8560317235fbe97bf8b0a89b86336c8dd59d5dc0a27654    sha256:f4dc9e2ce94362f78a358cbf0ffc71ffe2fc11224c94857f21a1f7e1df5997ef    io.containerd.runtime.v1.linux   


能否提供
kubectl descripe pod untrusted
命令的输出?$kubectl descripe pod nginx untrusted Containers:nginx:Container ID:Image:nginx Image ID:Port:Host Port:State:等待原因:Container创建就绪:False重新启动计数:0环境:从默认令牌fgsbl(ro)装载:/var/run/secrets/kubernetes.io/serviceaccount条件:类型状态已初始化True Ready False Containers就绪False PodScheduled TrueQoS类:BestWork节点选择器:容差:节点.kubernetes.io/未就绪:不执行300s节点.kubernetes.io/不可访问:不执行300s事件:类型原因消息正常调度57s默认调度程序成功将默认/nginx不受信任分配给ip-10-0-1-22正常拉取56s kubelet,ip-10-0-1-22拉取映像“nginx”正常拉取55s kubelet,ip-10-0-1-22成功拉取映像“nginx”正常创建55s kubelet,ip-10-0-1-22已创建容器nginx
ubuntu@ip-10-0-1-21:~$ sudo runsc --root  /run/containerd/runsc/k8s.io list
ID                                                                 PID         STATUS      BUNDLE                                                                                                                   CREATED                          OWNER
810812c901c432ef406bebe4730a925a73976e0f057a724cfd84ef8e5d9cefc4   1077        running     /run/containerd/io.containerd.runtime.v1.linux/k8s.io/810812c901c432ef406bebe4730a925a73976e0f057a724cfd84ef8e5d9cefc4   2021-04-18T15:35:46.15756454Z    
e1241cc457631f60ab8560317235fbe97bf8b0a89b86336c8dd59d5dc0a27654   1077        running     /run/containerd/io.containerd.runtime.v1.linux/k8s.io/e1241cc457631f60ab8560317235fbe97bf8b0a89b86336c8dd59d5dc0a27654   2021-04-18T15:35:48.208150407Z 

ubuntu@ip-10-0-1-21:~$ sudo ctr -n k8s.io containers list
CONTAINER                                                           IMAGE                                                                      RUNTIME                           
810812c901c432ef406bebe4730a925a73976e0f057a724cfd84ef8e5d9cefc4    sha256:da86e6ba6ca197bf6bc5e9d900febd906b133eaa4750e6bed647b0fbe50ed43e    io.containerd.runtime.v1.linux    
e1241cc457631f60ab8560317235fbe97bf8b0a89b86336c8dd59d5dc0a27654    sha256:f4dc9e2ce94362f78a358cbf0ffc71ffe2fc11224c94857f21a1f7e1df5997ef    io.containerd.runtime.v1.linux