有时候我们操作不规范,或者删除的先后顺序有问题,或者某项关键服务没有启动,导致 Kubernetes 经常会出现无法删除 NameSpace 的情况。这种情况下我们应该怎么办?
其实,很多时候出现这种情况,主要是因为我们的删除操作不规范,典型的有下面几种情况:
…
综上,根源上,大部分情况下 NameSpace 无法删除,都是我们操作有错在先。
为了避免此类错误再犯,推荐搭建删除按照如下流程:
get-all
来真正地获取该 NameSpace 下的所有资源,如后面的代码块所示:第 2 步的代码块:(有如此多的 CRD)
❯ kubectl get-all -n cert-manager NAME NAMESPACE AGE configmap/cert-manager-webhook cert-manager 277d configmap/kube-root-ca.crt cert-manager 277d endpoints/cert-manager cert-manager 277d endpoints/cert-manager-webhook cert-manager 277d endpoints/cert-manager-webhook-dnspod cert-manager 277d pod/cert-manager-6d6bb4f487-hkwpn cert-manager 85d pod/cert-manager-6d6bb4f487-wgtd8 cert-manager 85d pod/cert-manager-cainjector-7d55bf8f78-5797c cert-manager 277d pod/cert-manager-webhook-577f77586f-txlcx cert-manager 85d pod/cert-manager-webhook-577f77586f-xh4st cert-manager 85d pod/cert-manager-webhook-dnspod-5d5566c7bc-5cj4s cert-manager 211d secret/cert-manager-cainjector-token-h8cqq cert-manager 277d secret/cert-manager-token-28knj cert-manager 277d secret/cert-manager-webhook-ca cert-manager 277d secret/cert-manager-webhook-dnspod-ca cert-manager 277d secret/cert-manager-webhook-dnspod-letsencrypt cert-manager 277d secret/cert-manager-webhook-dnspod-secret cert-manager 277d secret/cert-manager-webhook-dnspod-token-jsjrn cert-manager 277d secret/cert-manager-webhook-dnspod-webhook-tls cert-manager 277d secret/cert-manager-webhook-token-qxq44 cert-manager 277d secret/default-token-mkpmt cert-manager 277d secret/ewhisper-crt-secret cert-manager 277d secret/sh.helm.release.v1.cert-manager-webhook-dnspod.v1 cert-manager 277d secret/sh.helm.release.v1.cert-manager.v1 cert-manager 277d serviceaccount/cert-manager cert-manager 277d serviceaccount/cert-manager-cainjector cert-manager 277d serviceaccount/cert-manager-webhook cert-manager 277d serviceaccount/cert-manager-webhook-dnspod cert-manager 277d serviceaccount/default cert-manager 277d service/cert-manager cert-manager 277d service/cert-manager-webhook cert-manager 277d service/cert-manager-webhook-dnspod cert-manager 277d order.acme.cert-manager.io/ewhisper-crt-6v6s4-2449993249 cert-manager 209d order.acme.cert-manager.io/ewhisper-crt-89n7g-2449993249 cert-manager 23d order.acme.cert-manager.io/ewhisper-crt-8g496-2449993249 cert-manager 277d order.acme.cert-manager.io/ewhisper-crt-jj24l-2449993249 cert-manager 83d order.acme.cert-manager.io/ewhisper-crt-q8pvw-2449993249 cert-manager 149d deployment.apps/cert-manager cert-manager 277d deployment.apps/cert-manager-cainjector cert-manager 277d deployment.apps/cert-manager-webhook cert-manager 277d deployment.apps/cert-manager-webhook-dnspod cert-manager 277d replicaset.apps/cert-manager-6d6bb4f487 cert-manager 277d replicaset.apps/cert-manager-cainjector-7d55bf8f78 cert-manager 277d replicaset.apps/cert-manager-webhook-577f77586f cert-manager 277d replicaset.apps/cert-manager-webhook-dnspod-5d5566c7bc cert-manager 211d replicaset.apps/cert-manager-webhook-dnspod-5d78f9bfcb cert-manager 217d replicaset.apps/cert-manager-webhook-dnspod-7c5cd575fc cert-manager 277d app.catalog.cattle.io/cert-manager cert-manager 270d app.catalog.cattle.io/cert-manager-webhook-dnspod cert-manager 270d certificaterequest.cert-manager.io/cert-manager-webhook-dnspod-ca-l57hl cert-manager 277d certificaterequest.cert-manager.io/cert-manager-webhook-dnspod-webhook-tls-7zwdh cert-manager 277d certificaterequest.cert-manager.io/cert-manager-webhook-dnspod-webhook-tls-gs57f cert-manager 34d certificaterequest.cert-manager.io/ewhisper-crt-6v6s4 cert-manager 209d certificaterequest.cert-manager.io/ewhisper-crt-89n7g cert-manager 23d certificaterequest.cert-manager.io/ewhisper-crt-8g496 cert-manager 277d certificaterequest.cert-manager.io/ewhisper-crt-jj24l cert-manager 83d certificaterequest.cert-manager.io/ewhisper-crt-q8pvw cert-manager 149d certificate.cert-manager.io/cert-manager-webhook-dnspod-ca cert-manager 277d certificate.cert-manager.io/cert-manager-webhook-dnspod-webhook-tls cert-manager 277d certificate.cert-manager.io/ewhisper-crt cert-manager 277d issuer.cert-manager.io/cert-manager-webhook-dnspod-ca cert-manager 277d issuer.cert-manager.io/cert-manager-webhook-dnspod-selfsign cert-manager 277d endpointslice.discovery.k8s.io/cert-manager-9lm6j cert-manager 277d endpointslice.discovery.k8s.io/cert-manager-webhook-dnspod-q7f8n cert-manager 277d endpointslice.discovery.k8s.io/cert-manager-webhook-z6qdd cert-manager 277d rolebinding.rbac.authorization.k8s.io/cert-manager-webhook:dynamic-serving cert-manager 277d role.rbac.authorization.k8s.io/cert-manager-webhook:dynamic-serving cert-manager 277d ingressroute.traefik.containo.us/alertmanager cert-manager 244d ingressroute.traefik.containo.us/grafana cert-manager 255d ingressroute.traefik.containo.us/grafana-rancher cert-manager 238d ingressroute.traefik.containo.us/prometheus cert-manager 244d ingressroute.traefik.containo.us/rsshub cert-manager 268d ingressroute.traefik.containo.us/ttrss cert-manager 257d tlsstore.traefik.containo.us/default cert-manager 268d
如果 NameSpace 已经处于 terminating
的状态,且久久无法删除,可以试试加上这 2 个参数强制删除:
--force
--grace-period=0
kubectl delete ns ${NAMESPACE} --force --grace-period=0
强制删除失败?再来试试这种办法:调用 Kubernetes API 删除
首先,获取要删除 NameSpace 的 JSON 文件:
NAMESPACE=cert-manager kubectl get ns ${NAMESPACE} -o json > namespace.json
然后,编辑 namespace.json
, 从 finalizers
字段中删除 kubernetes
的值并保存,示例如下:
{ "apiVersion": "v1", "kind": "Namespace", "metadata": { ...: ... }, "spec": { "finalizers": [] }, "status": { "phase": "Terminating" } }
之后,可以通过 kubectl proxy
设置 APIServer 的临时 IP 和端口
kubectl proxy --port=6880 &
最后,进行 API 调用来强制删除:
curl -k -H "Content-Type: application/json" -X PUT --data-binary @namespace.json http://127.0.0.1:6880/api/v1/namespaces/${NAMESPACE}/finalize
验证是否已经成功删除:
kubectl get ns ${NAMESPACE}
📝Notes:
依赖组件:
- kubectl
- jq
- curl
force-delete-ns.sh
#!/bin/bash set -ex PATH=$PATH:. NAMESPACE=$1 # 读取命令行第一个参数 kill -9 $(ps -ef|grep proxy|grep -v grep |awk '{print $2}') kubectl proxy --port=6880 & kubectl get namespace ${NAMESPACE} -o json |jq '.spec = {"finalizers":[]}' > namespace.json curl -k -H "Content-Type: application/json" -X PUT --data-binary @namespace.json 127.0.0.1:6880/api/v1/namespaces/${NAMESPACE}/finalize
使用方式示例:
bash force-delete-ns.sh cert-manager
🎉🎉🎉
经常会碰到 Kubernetes 的 NameSpace 无法删除的情况,这时候应该如何解决?这里提供了 3 种方案:
--force
flag 强制删除但是,真到了需要强制删除的阶段,2/3 部是无法保证 100% 成功的。
所以第一步才是正道 …(呆,但是有用)
EOF