rke2 version v1.30.6+rke2r1 (2959cd2193af9ed18d0fc2912fc5c11d6462103d)
rancher2.9.3
节点 CPU 架构,操作系统和版本:
Linux k8s-worker-1-19 5.14.0-427.40.1.el9_4.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Oct 16 14:57:47 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux
集群配置:
上游3rancher
下游集群
3master
4worker 问题描述:
我用的自签名的证书安装集群,上游集群安装成功,rancher安装也没有问题,
安装下游集群,集群已经启动,但是fleet-agent报tls: failed to verify certificate: x509: certificate signed by unknown authority" 重现步骤:
安装 RKE2 的命令:
cd /root/rke2-artifacts/
INSTALL_RKE2_ARTIFACT_PATH=/root/rke2-artifacts sh install.sh
Fri, Dec 6 2024 9:51:13 amtime=“2024-12-06T01:51:13Z” level=info msg=“Creating clusterregistration with id ‘cgjwwr44brns7hrhsjc59xqz46vvbvtgxqxqs6wllf6jk5lx6k85cq’ for new token”
Fri, Dec 6 2024 9:51:13 amtime=“2024-12-06T01:51:13Z” level=error msg=“Failed to register agent: registration failed: cannot create clusterregistration on management cluster for cluster id ‘cgjwwr44brns7hrhsjc59xqz46vvbvtgxqxqs6wllf6jk5lx6k85cq’: Post "https://rancher.xxxxx.com/apis/fleet.cattle.io/v1alpha1/namespaces/fleet-default/clusterregistrations\”: tls: failed to verify certificate: x509: certificate signed by unknown authority"
Mon, Dec 9 2024 2:26:23 pmtime=“2024-12-09T06:26:23Z” level=info msg=“Creating clusterregistration with id ‘cgjwwr44brns7hrhsjc59xqz46vvbvtgxqxqs6wllf6jk5lx6k85cq’ for new token”
Mon, Dec 9 2024 2:26:23 pmtime=“2024-12-09T06:26:23Z” level=error msg=“Failed to register agent: registration failed: cannot create clusterregistration on management cluster for cluster id ‘cgjwwr44brns7hrhsjc59xqz46vvbvtgxqxqs6wllf6jk5lx6k85cq’: Post "https://rancher.wakedata.com/apis/fleet.cattle.io/v1alpha1/namespaces/fleet-default/clusterregistrations\”: tls: failed to verify certificate: x509: certificate signed by unknown authority"