Skip to content

NimTechnology

Trình bày các công nghệ CLOUD một cách dễ hiểu.

  • Kubernetes & Container
    • Docker
    • Kubernetes
      • Ingress
      • Pod
    • Helm Chart
    • OAuth2 Proxy
    • Isito-EnvoyFilter
    • Apache Kafka
      • Kafka
      • Kafka Connect
      • Lenses
    • Vault
    • Longhorn – Storage
    • VictoriaMetrics
    • MetalLB
    • Kong Gateway
  • CI/CD
    • ArgoCD
    • ArgoWorkflows
    • Argo Events
    • Spinnaker
    • Jenkins
    • Harbor
    • TeamCity
    • Git
      • Bitbucket
  • Coding
    • DevSecOps
    • Terraform
      • GCP – Google Cloud
      • AWS – Amazon Web Service
      • Azure Cloud
    • Golang
    • Laravel
    • Python
    • Jquery & JavaScript
    • Selenium
  • Log, Monitor & Tracing
    • DataDog
    • Prometheus
    • Grafana
    • ELK
      • Kibana
      • Logstash
  • BareMetal
    • NextCloud
  • Toggle search form

[Cilium] Cilium Pods crash when upgraded to K8S 1.30

Posted on January 16, 2025January 16, 2025 By nim No Comments on [Cilium] Cilium Pods crash when upgraded to K8S 1.30

Khi Upgrade K8s lên 1.30 khả năng cao bạn sẽ gặp lỗi này
Cilium pod crashes cause the mount-group container to constantly restart.

trong log có nhả 1 lỗi:

$ kubectl -n kube-system logs cilium-2bgp7 -c mount-cgroup
nsenter: cannot open /hostproc/1/ns/cgroup: Permission denied

Nếu bạn sử dụng helm để install cilium thì add thêm pod annotations:

...
...

podAnnotations:
  container.apparmor.security.beta.kubernetes.io/cilium-agent: "unconfined"
  container.apparmor.security.beta.kubernetes.io/clean-cilium-state: "unconfined"
  container.apparmor.security.beta.kubernetes.io/mount-cgroup: "unconfined"
  container.apparmor.security.beta.kubernetes.io/apply-sysctl-overwrites: "unconfined"


...
...

Nó sẽ add thêm SecurityContext:

add thêm annotations:

Refer to:
https://hackmd.io/@7vxmAdNPTmmlYGSRMuvbmw/H1cxr_yGkg

Kubernetes

Post navigation

Previous Post: [Terminal/Huh] Build Terminal Form By golang.
Next Post: [CoreDNS] How to improve the Coredns performance.

More Related Articles

[Metallb] Create LoadBalancer Service on K8S (on-premise) so easily Ingress
[Network/Kubernetes] Latency is too hight Kubernetes
[AWS] Pull images from ECR AWS - Amazon Web Service
[Kubernetes] How to Protect Your K8S. Kubernetes
[Kubernetes] RBAC Demo Kubernetes
[Sidecar/Kubernestes] Inject sidecar into a Pod automatically Kubernetes

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Tham Gia Group DevOps nhé!
Để Nim có nhiều động lực ra nhiều bài viết.
Để nhận được những thông báo mới nhất.

Recent Posts

  • [AWS/EKS] Cache Docker image to accelerate EKS container deployment. July 10, 2025
  • [Laravel] Laravel Helpful June 26, 2025
  • [VScode] Hướng dẫn điều chỉnh font cho terminal June 20, 2025
  • [WordPress] Hướng dấn gửi mail trên WordPress thông qua gmail. June 15, 2025
  • [Bitbucket] Git Clone/Pull/Push with Bitbucket through API Token. June 12, 2025

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021

Categories

  • BareMetal
    • NextCloud
  • CI/CD
    • Argo Events
    • ArgoCD
    • ArgoWorkflows
    • Git
      • Bitbucket
    • Harbor
    • Jenkins
    • Spinnaker
    • TeamCity
  • Coding
    • DevSecOps
    • Golang
    • Jquery & JavaScript
    • Laravel
    • NextJS 14 & ReactJS & Type Script
    • Python
    • Selenium
    • Terraform
      • AWS – Amazon Web Service
      • Azure Cloud
      • GCP – Google Cloud
  • Kubernetes & Container
    • Apache Kafka
      • Kafka
      • Kafka Connect
      • Lenses
    • Docker
    • Helm Chart
    • Isito-EnvoyFilter
    • Kong Gateway
    • Kubernetes
      • Ingress
      • Pod
    • Longhorn – Storage
    • MetalLB
    • OAuth2 Proxy
    • Vault
    • VictoriaMetrics
  • Log, Monitor & Tracing
    • DataDog
    • ELK
      • Kibana
      • Logstash
    • Fluent
    • Grafana
    • Prometheus
  • Uncategorized
  • Admin

Copyright © 2025 NimTechnology.