View a markdown version of this page

AWSSupport-TroubleshootEKSNetwork - AWS Systems Manager 自动化运行手册参考

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

AWSSupport-TroubleshootEKSNetwork

说明

该AWSSupport-TroubleshootEKSNetwork运行手册可帮助您解决在亚马逊弹性 Kubernetes 服务(亚马逊 EKS)集群中运行的容器中的网络连接问题。运行手册根据目标类型从流量来源和目的地收集计算和网络统计信息。

工作原理

使用此运行手册对与以下目标类型的连接进行故障排除:

  • POD:另一个Kubernetes吊舱。

  • 服务:一项Kubernetes服务。

  • IP:集群或亚马逊 VPC 的内部或外部 IPv4/IPv6 地址。

  • DNS:集群或亚马逊 VPC 内部或外部的域名。

重要

除了以下 IAM 权限外,他们还 AutomationAssumeRole 必须能够使用支持的亚马逊 EKS API 访问方法访问亚马逊 EKS 集群。对于使用访问条目的集群,AmazonEKSViewPolicy访问策略是最低要求的策略。

运行此自动化(控制台)

所需的 IAM 权限

AutomationAssumeRole 参数需要执行以下操作才能成功使用运行手册。

该运行手册以相同的角色运行AWSSupport-SetupK8sApiProxyForEKS和AWSSupport-CollectEKSLinuxNodeStatistics子运行手册。AutomationAssumeRole必须允许对父级和子级运行手册执行以下操作:

  • cloudformation:CreateStack

  • cloudformation:DeleteStack

  • cloudformation:DescribeStackResources

  • cloudformation:DescribeStacks

  • cloudformation:UpdateStack

  • ec2:CreateNetworkInterface

  • ec2:DeleteNetworkInterface

  • ec2:DescribeInstances

  • ec2:DescribeNetworkInterfaces

  • ec2:DescribeRegions

  • ec2:DescribeRouteTables

  • ec2:DescribeSecurityGroups

  • ec2:DescribeSubnets

  • ec2:DescribeVpcPeeringConnections

  • ec2:DescribeVpcs

  • eks:DescribeCluster

  • eks:DescribeFargateProfile

  • iam:AttachRolePolicy

  • iam:CreateRole

  • iam:DeleteRole

  • iam:DeleteRolePolicy

  • iam:DetachRolePolicy

  • iam:GetRole

  • iam:PassRole

  • iam:PutRolePolicy

  • iam:TagRole

  • iam:UntagRole

  • lambda:CreateFunction

  • lambda:DeleteFunction

  • lambda:GetFunction

  • lambda:InvokeFunction

  • lambda:ListTags

  • lambda:TagResource

  • lambda:UntagResource

  • lambda:UpdateFunctionCode

  • lambda:UpdateFunctionConfiguration

  • logs:CreateLogGroup

  • logs:CreateLogStream

  • logs:DeleteLogGroup

  • logs:DescribeLogGroups

  • logs:DescribeLogStreams

  • logs:ListTagsForResource

  • logs:PutLogEvents

  • logs:PutRetentionPolicy

  • logs:TagResource

  • logs:UntagResource

  • s3:GetBucketLocation

  • s3:GetObject

  • s3:PutObject

  • ssm:DescribeAutomationExecutions

  • ssm:DescribeAutomationStepExecutions

  • ssm:DescribeDocument

  • ssm:DescribeInstanceInformation

  • ssm:GetAutomationExecution

  • ssm:GetCommandInvocation

  • ssm:GetDocument

  • ssm:ListCommands

  • ssm:SendCommand

  • ssm:StartAutomationExecution

  • sts:GetCallerIdentity

  • tag:GetResources

  • tag:TagResources

以下示例策略显示了所需的最低权限权限。AutomationAssumeRole用你自己的值替换REGIONACCOUNTIDSOURCE_CLUSTER_NAMEDESTINATION_CLUSTER_NAME、、、和S3_BUCKET_NAME:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "EKSClusterAccess", "Effect": "Allow", "Action": "eks:DescribeCluster", "Resource": [ "arn:aws:eks:REGION:ACCOUNTID:cluster/SOURCE_CLUSTER_NAME", "arn:aws:eks:REGION:ACCOUNTID:cluster/DESTINATION_CLUSTER_NAME" ] }, { "Sid": "EKSFargateProfileAccess", "Effect": "Allow", "Action": "eks:DescribeFargateProfile", "Resource": [ "arn:aws:eks:REGION:ACCOUNTID:fargateprofile/SOURCE_CLUSTER_NAME/*", "arn:aws:eks:REGION:ACCOUNTID:fargateprofile/DESTINATION_CLUSTER_NAME/*" ] }, { "Sid": "EC2DescribePermissions", "Effect": "Allow", "Action": [ "ec2:DescribeInstances", "ec2:DescribeRegions", "ec2:DescribeRouteTables", "ec2:DescribeVpcs", "ec2:DescribeVpcPeeringConnections", "ec2:DescribeSubnets" ], "Resource": "*", "Condition": { "StringEquals": { "aws:RequestedRegion": "REGION" } } }, { "Sid": "SSMAutomationExecution", "Effect": "Allow", "Action": [ "ssm:StartAutomationExecution", "ssm:GetAutomationExecution", "ssm:DescribeAutomationExecutions", "ssm:DescribeAutomationStepExecutions" ], "Resource": "arn:aws:ssm:REGION:ACCOUNTID:automation-execution/*" }, { "Sid": "SSMDocumentAccess", "Effect": "Allow", "Action": [ "ssm:DescribeDocument", "ssm:GetDocument" ], "Resource": [ "arn:aws:ssm:REGION:ACCOUNTID:document/AWSSupport-TroubleshootEKSNetwork", "arn:aws:ssm:REGION:ACCOUNTID:document/AWSSupport-SetupK8sApiProxyForEKS", "arn:aws:ssm:REGION:ACCOUNTID:document/AWSSupport-CollectEKSLinuxNodeStatistics", "arn:aws:ssm:REGION:*:document/AWS-RunShellScript" ] }, { "Sid": "SSMRunCommandOnNodes", "Effect": "Allow", "Action": [ "ssm:SendCommand", "ssm:GetCommandInvocation" ], "Resource": [ "arn:aws:ec2:REGION:ACCOUNTID:instance/*", "arn:aws:ssm:REGION:*:document/AWS-RunShellScript" ], "Condition": { "StringEquals": { "aws:ResourceTag/eks:cluster-name": [ "SOURCE_CLUSTER_NAME", "DESTINATION_CLUSTER_NAME" ] } } }, { "Sid": "S3TroubleshootingAssets", "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject" ], "Resource": "arn:aws:s3:::S3_BUCKET_NAME/AWSSupport-CollectEKSLinuxNodeStatistics/*" }, { "Sid": "S3BucketLocation", "Effect": "Allow", "Action": "s3:GetBucketLocation", "Resource": "arn:aws:s3:::S3_BUCKET_NAME" }, { "Sid": "LambdaK8sProxyManagement", "Effect": "Allow", "Action": [ "lambda:CreateFunction", "lambda:DeleteFunction", "lambda:GetFunction", "lambda:InvokeFunction", "lambda:UpdateFunctionCode", "lambda:UpdateFunctionConfiguration" ], "Resource": "arn:aws:lambda:REGION:ACCOUNTID:function:Automation-K8sProxy-*" }, { "Sid": "CloudFormationK8sProxyStack", "Effect": "Allow", "Action": [ "cloudformation:CreateStack", "cloudformation:DeleteStack", "cloudformation:DescribeStacks", "cloudformation:DescribeStackResources" ], "Resource": "arn:aws:cloudformation:REGION:ACCOUNTID:stack/AWSSupport-SetupK8sApiProxyForEKS-*/*" }, { "Sid": "IAMForK8sProxyLambdaRole", "Effect": "Allow", "Action": [ "iam:CreateRole", "iam:DeleteRole", "iam:GetRole", "iam:AttachRolePolicy", "iam:DetachRolePolicy", "iam:PutRolePolicy", "iam:DeleteRolePolicy" ], "Resource": "arn:aws:iam::ACCOUNTID:role/Automation-K8sProxy-Role-*" }, { "Sid": "IAMPassRoleToLambda", "Effect": "Allow", "Action": "iam:PassRole", "Resource": "arn:aws:iam::ACCOUNTID:role/Automation-K8sProxy-Role-*", "Condition": { "StringEquals": { "iam:PassedToService": "lambda.amazonaws.com" } } }, { "Sid": "CloudWatchLogsForK8sProxy", "Effect": "Allow", "Action": [ "logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents", "logs:DeleteLogGroup" ], "Resource": "arn:aws:logs:REGION:ACCOUNTID:log-group:/aws/lambda/Automation-K8sProxy-*" }, { "Sid": "ResourceTaggingForStackLookup", "Effect": "Allow", "Action": "tag:GetResources", "Resource": "*", "Condition": { "StringEquals": { "aws:RequestedRegion": "REGION" } } }, { "Sid": "STSCallerIdentity", "Effect": "Allow", "Action": "sts:GetCallerIdentity", "Resource": "*" } ] }

除了前面的示例策略(AWSSupport-TroubleshootEKSNetwork仅提供权限)外,您还需要其他策略来执行AWSSupport-SetupK8sApiProxyForEKS和AWSSupport-CollectEKSLinuxNodeStatistics的子运行手册。以下示例策略适用于这些文档:

需要AWSSupport-SetupK8sApiProxyForEKS以下权限:

{ "Version":"2012-10-17", "Statement": [ { "Action": [ "tag:GetResources", "tag:TagResources", "ec2:CreateNetworkInterface", "ec2:DescribeNetworkInterfaces", "ec2:DescribeRouteTables", "ec2:DescribeSecurityGroups", "ec2:DescribeSubnets", "ec2:DescribeVpcs", "ec2:DeleteNetworkInterface", "eks:DescribeCluster", "iam:GetRole", "cloudformation:DescribeStacks", "logs:DescribeLogGroups", "logs:DescribeLogStreams", "lambda:GetFunction", "lambda:ListTags", "logs:ListTagsForResource" ], "Resource": "*", "Effect": "Allow", "Sid": "AllowActionsWithoutConditions" }, { "Condition": { "StringEquals": { "aws:RequestTag/AWSSupport-SetupK8sApiProxyForEKS": "true" } }, "Action": "iam:CreateRole", "Resource": [ "arn:aws:iam::ACCOUNTID:role/Automation-K8sProxy*" ], "Effect": "Allow", "Sid": "AllowCreateRoleWithRequiredTag" }, { "Condition": { "StringEquals": { "aws:ResourceTag/AWSSupport-SetupK8sApiProxyForEKS": "true" } }, "Action": [ "iam:DeleteRole", "iam:TagRole", "iam:UntagRole" ], "Resource": [ "arn:aws:iam::ACCOUNTID:role/Automation-K8sProxy*" ], "Effect": "Allow", "Sid": "IAMActions" }, { "Condition": { "StringEquals": { "aws:ResourceTag/AWSSupport-SetupK8sApiProxyForEKS": "true" }, "StringLike": { "iam:PolicyARN": [ "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole", "arn:aws:iam::aws:policy/service-role/AWSLambdaVPCAccessExecutionRole" ] } }, "Action": [ "iam:AttachRolePolicy", "iam:DetachRolePolicy" ], "Resource": [ "arn:aws:iam::ACCOUNTID:role/Automation-K8sProxy*" ], "Effect": "Allow", "Sid": "AttachRolePolicy" }, { "Condition": { "StringEquals": { "aws:ResourceTag/AWSSupport-SetupK8sApiProxyForEKS": "true" } }, "Action": [ "lambda:CreateFunction", "lambda:DeleteFunction", "lambda:TagResource", "lambda:UntagResource", "lambda:UpdateFunctionCode" ], "Resource": "arn:aws:lambda:REGION:ACCOUNTID:function:Automation-K8sProxy*", "Effect": "Allow", "Sid": "LambdaActions" }, { "Condition": { "StringEquals": { "aws:ResourceTag/AWSSupport-SetupK8sApiProxyForEKS": "true" } }, "Action": [ "cloudformation:CreateStack", "cloudformation:DeleteStack", "cloudformation:UpdateStack" ], "Resource": "arn:aws:cloudformation:REGION:ACCOUNTID:stack/AWSSupport-SetupK8sApiProxyForEKS*", "Effect": "Allow", "Sid": "CloudFormationActions" }, { "Condition": { "StringEquals": { "aws:ResourceTag/AWSSupport-SetupK8sApiProxyForEKS": "true" } }, "Action": [ "logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents", "logs:PutRetentionPolicy", "logs:TagResource", "logs:UntagResource" ], "Resource": [ "arn:aws:logs:REGION:ACCOUNTID:log-group:/aws/lambda/Automation-K8sProxy*", "arn:aws:logs:REGION:ACCOUNTID:log-group:/aws/lambda/Automation-K8sProxy*:*" ], "Effect": "Allow", "Sid": "LogsActions" }, { "Condition": { "StringLikeIfExists": { "iam:PassedToService": "lambda.amazonaws.com" } }, "Action": [ "iam:PassRole" ], "Resource": [ "arn:aws:iam::ACCOUNTID:role/Automation-K8sProxy-Role*" ], "Effect": "Allow", "Sid": "PassRoleToLambda" } ] }

需要AWSSupport-CollectEKSLinuxNodeStatistics以下权限:

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetAccountPublicAccessBlock" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "s3:GetBucketPublicAccessBlock", "s3:GetBucketAcl", "s3:GetBucketPolicyStatus", "s3:GetBucketLocation", "s3:GetEncryptionConfiguration" ], "Resource": "arn:aws:s3:::S3_BUCKET_NAME" }, { "Effect": "Allow", "Action": [ "s3:PutObject" ], "Resource": "arn:aws:s3:::S3_BUCKET_NAME/*" }, { "Effect": "Allow", "Action": [ "ssm:DescribeInstanceInformation" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "ssm:SendCommand" ], "Resource": [ "arn:aws:ssm:*:*:document/AWS-RunShellScript", "arn:aws:ec2:*:ACCOUNTID:instance/*" ] }, { "Effect": "Allow", "Action": [ "ssm:GetCommandInvocation" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "ec2:DescribeInstances" ], "Resource": "*" } ] }

说明

  1. 在 “系统管理器” AWSSupport-TroubleshootEKSNetwork 中的 “文档” 下打开。

  2. 选择执行自动化。

  3. 对于输入参数,输入以下内容:

    • AutomationAssumeRole (可选):

      允许系统管理员自动化代表您执行操作的 IAM 角色的 ARN。如果未指定任何角色,系统管理员自动化将使用您的权限来运行此运行手册。

    • S3BucketName (必填):

      用于上传故障排除资产的 Amazon S3 存储桶名称。

    • SourceClusterName (必填):

      要进行故障排除的源亚马逊 EKS 集群的名称。

    • SourcePodName (必填):

      启动网络连接的源 Kubernetes Pod 的名称。

    • SourcePodNamespace (必填):

      源 p Kubernetes od 所在的命名空间。

    • DestinationType (必填):

      网络连接目标的类型。有效值:POD、SERVICE、IP 或 DNS。

    • ConnectionProtocol (必填):

      网络连接协议。有效值:tcp、udp 或 sctp。

    • DestinationPort (必填):

      网络连接目标端口。

    • DestinationClusterName (可选):

      目标亚马逊 EKS 集群名称(POD 和服务目标类型为必填项)。

    • DestinationPodName (可选):

      目标 POD 的名称(KubernetesPOD 目标类型为必填项)。

    • DestinationPodNamespace (可选):

      目标 Kubernetes Pod 所在的命名空间(POD 目标类型为必填项)。

    • DestinationServiceName (可选):

      目标服务的名称(Kubernetes服务目标类型为必填项)。

    • DestinationServiceNamespace (可选):

      目标Kubernetes服务所在的命名空间(服务目标类型为必填项)。

    • DestinationIpAddress (可选):

      目标 IPv4 或 IPv6 地址(IP 目标类型为必填项)。

    • DestinationDnsName (可选):

      目标 DNS 名称(DNS 目标类型为必填项)。

  4. 选择执行。

  5. 自动化开始。在 “执行” 选项卡上监控执行状态。

  6. 该文档自动执行以下步骤:

    • ValidateTroubleshootingParameters:

      验证故障排除所需的输入参数,例如集群是否存在。

    • SetupAuthProxyForSourceEKSCluster:

      运行该AWSSupport-SetupK8sApiProxyForEKS文档以设置 Lambda 函数,以便在源亚马逊 EKS 集群上进行亚马逊 EKS API 调用。

    • BranchOnDestinationProxySetupRequired:

      根据目标类型确定是否SetupK8sApiProxyForEKS为目标集群运行。

    • SetupAuthProxyForDestinationEKSCluster:

      如果需要,运行该AWSSupport-SetupK8sApiProxyForEKS文档为目标 Amazon EKS 集群设置 Lambda 函数。

    • CollectSourcePodData:

      收集和验证源 pod 的信息。

    • BranchOnSourcePodComputeEngine:

      分支说明源Kubernetes容器是否在 Amazon EC2 上运行以收集该节点的 Linux 统计数据。

    • CollectSourceLinuxNodeStatistics:

      如果源容器在 Amazon EC2 上运行,则运行该AWSSupport-CollectEKSLinuxNodeStatistics文档以从源Kubernetes容器的节点获取 Linux 统计数据。

    • CollectDestinationData:

      收集和验证目的地信息。

    • BranchOnDestinationResults:

      分支说明目标Kubernetes容器是否在 Amazon EC2 上运行,以收集该节点的 Linux 统计数据。

    • CollectDestinationLinuxNodeStatistics:

      如果目标容器在亚马逊 EC2 上运行,则运行该AWSSupport-CollectEKSLinuxNodeStatistics文档以从目标亚马逊 EKS 节点获取 Linux 统计数据。

    • CleanupAuthProxyForSourceEKSCluster:

      使用 Cleanup 操作运行AWSSupport-SetupK8sApiProxyForEKS文档,以清理为源集群创建的资源。

    • CleanupAuthProxyForDestinationEKSCluster:

      如果适用,使用 Cleanup 操作运行AWSSupport-SetupK8sApiProxyForEKS文档,以清理为目标群集创建的资源。

    • GenerateReport:

      为故障排除流程生成报告。

  7. 自动化完成后,查看 “输出” 部分以了解执行结果。

参考

Systems Manager Automation