内网使用代理创建rancher,报错error loading CA cert for probe (kube-controller-manager)

Rancher Server 设置

  • Rancher 版本:2.8
  • 安装选项 (Docker install/Helm Chart): Docker install
    • 如果是 Helm Chart 安装,需要提供 Local 集群的类型(RKE1, RKE2, k3s, EKS, 等)和版本:
  • 在线或离线部署:内网代理,在线

下游集群信息

  • Kubernetes 版本: v1.27.7+rke2r2
  • Cluster Type (Local/Downstream):
    • 如果 Downstream,是什么类型的集群?(自定义/导入或为托管 等):

用户信息

  • 登录用户的角色是什么? (管理员/集群所有者/集群成员/项目所有者/项目成员/自定义):
    • 如果自定义,自定义权限集:

**主机操作系统:**ctyunos 可认为是openEuler

问题描述:
创建全部权限节点超时,详细错误见截图和日志,请问是否需要安装证书,在有外网的环境也部署了一套rancher,不需要安装相关证书,也未报这个错误。
另外有个额外的问题想咨询,部署好的rancher,内网服务器工作负载pod里面报Containers with unready status: [container-0]错误,请问是需要使用harbor来解决吗?
上面两个问题总结一下,有使用代理部署rancher的相关技术指导吗?
重现步骤:

结果:

预期结果:

截图:


其他上下文信息:

日志
Dec 19 09:51:53 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:51:53+08:00" level=error msg="error while appending ca cert to pool for probe kube-scheduler"
Dec 19 09:51:53 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:51:53+08:00" level=error msg="error loading CA cert for probe (kube-controller-manager) /var/lib/rancher/rke2/server/tls/kube-controller-manager/kube-controller-manager.crt: open /var/lib/rancher/rke2/server/tls/kube-controller-manager/kube-controller-manager.crt: no such file or directory"
Dec 19 09:51:53 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:51:53+08:00" level=error msg="error while appending ca cert to pool for probe kube-controller-manager"
Dec 19 09:51:53 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:51:53+08:00" level=info msg="[K8s] updated plan secret fleet-default/custom-6317573ff508-machine-plan with feedback"
Dec 19 09:51:53 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:51:53+08:00" level=error msg="error loading CA cert for probe (kube-controller-manager) /var/lib/rancher/rke2/server/tls/kube-controller-manager/kube-controller-manager.crt: open /var/lib/rancher/rke2/server/tls/kube-controller-manager/kube-controller-manager.crt: no such file or directory"
Dec 19 09:51:53 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:51:53+08:00" level=error msg="error while appending ca cert to pool for probe kube-controller-manager"
Dec 19 09:51:53 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:51:53+08:00" level=info msg="[K8s] updated plan secret fleet-default/custom-6317573ff508-machine-plan with feedback"
Dec 19 09:51:53 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:51:53+08:00" level=info msg="[K8s] updated plan secret fleet-default/custom-6317573ff508-machine-plan with feedback"
Dec 19 09:53:24 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:53:24+08:00" level=info msg="[K8s] updated plan secret fleet-default/custom-6317573ff508-machine-plan with feedback"
Dec 19 09:58:02 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:58:02+08:00" level=info msg="[Applyinator] No image provided, creating empty working directory /var/lib/rancher/agent/work/20231219-095802/e390e51d08c39de02e46b1288cab0958139d9406abb98f3dba5dcf770d6c8884_0"
Dec 19 09:58:02 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:58:02+08:00" level=info msg="[Applyinator] Running command: sh [-c rke2 etcd-snapshot list --etcd-s3=false 2>/dev/null]"
Dec 19 09:58:02 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:58:02+08:00" level=info msg="[e390e51d08c39de02e46b1288cab0958139d9406abb98f3dba5dcf770d6c8884_0:stdout]: Name Location Size Created"
Dec 19 09:58:02 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:58:02+08:00" level=info msg="[Applyinator] Command sh [-c rke2 etcd-snapshot list --etcd-s3=false 2>/dev/null] finished with err: <nil> and exit code: 0"
Dec 19 09:58:02 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T09:58:02+08:00" level=info msg="[K8s] updated plan secret fleet-default/custom-6317573ff508-machine-plan with feedback"
Dec 19 10:08:03 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T10:08:03+08:00" level=info msg="[Applyinator] No image provided, creating empty working directory /var/lib/rancher/agent/work/20231219-100803/e390e51d08c39de02e46b1288cab0958139d9406abb98f3dba5dcf770d6c8884_0"
Dec 19 10:08:03 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T10:08:03+08:00" level=info msg="[Applyinator] Running command: sh [-c rke2 etcd-snapshot list --etcd-s3=false 2>/dev/null]"
Dec 19 10:08:03 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T10:08:03+08:00" level=info msg="[e390e51d08c39de02e46b1288cab0958139d9406abb98f3dba5dcf770d6c8884_0:stdout]: Name                                         Location                                                                                      Size     Created"
Dec 19 10:08:03 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T10:08:03+08:00" level=info msg="[e390e51d08c39de02e46b1288cab0958139d9406abb98f3dba5dcf770d6c8884_0:stdout]: etcd-snapshot-szxc-12-1.novalocal-1702951204 file:///var/lib/rancher/rke2/server/db/snapshots/etcd-snapshot-szxc-12-1.novalocal-1702951204 14012448 2023-12-19T10:00:04+08:00"
Dec 19 10:08:03 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T10:08:03+08:00" level=info msg="[Applyinator] Command sh [-c rke2 etcd-snapshot list --etcd-s3=false 2>/dev/null] finished with err: <nil> and exit code: 0"
Dec 19 10:08:03 szxc-12-1.novalocal rancher-system-agent[2325979]: time="2023-12-19T10:08:03+08:00" level=info msg="[K8s] updated plan secret fleet-default/custom-6317573ff508-machine-plan with feedback"

这个错误,大概率是拉不下来镜像导致某些服务没启动导致的,你可以参考:RKE2 commands 来排查下其他的日志

好的,谢谢帮助