Gke Node Notready

作者 google55b4e13eba6d無授權條款21K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Diagnoses GKE nodes reporting NotReady or Unknown status by inspecting node conditions, events, kubelet/containerd logs, and node metrics, then proposing safe remediations. Use when nodes show NotReady, when the kubelet stops posting node status, or when workloads are evicted or stuck Pending due to node health. Don't use for pod-level application failures (use gke-workload-troubleshooting), autoscaler scale-up/scale-down decisions (use gke-cluster-autoscaler), or non-GKE compute.

精選僅含說明DevOps & Cloud
AI 產生的概覽

診斷回報 NotReady 或 Unknown 狀態的 GKE 節點,並提出由人工套用的安全修復建議。

功能
以唯讀方式排查卡在 NotReady 或 Ready: Unknown 的 GKE 節點,先檢視節點狀況與事件,再檢查 kubelet 與序列埠主控台記錄、節點指標,以及網路與准入 Webhook 設定。它會把觀察到的特徵對應到可能的根因,例如 containerd 故障、系統 OOM、PLEG 停滯、CNI 問題或 kube-node-lease 抖動。最後產出附證據的根因說明,以及供人工套用的 kubectl、gcloud 或 GitOps 修復建議;當記錄不可用或原因仍無法確定時,會建議升級處理。
適用情境
適用於 GKE 節點顯示 NotReady 或 Unknown、kubelet 停止回報節點狀態,或因節點健康狀況導致工作負載被逐出或一直處於 Pending 的情況。不適用於 Pod 層級的應用程式故障、自動擴縮決策或非 GKE 運算資源。
執行需求
需要存取 GKE 叢集與 Google Cloud 專案,通常透過 kubectl 與 gcloud 憑證,並使用 Cloud Logging 和 Cloud Monitoring 查詢記錄與指標。此技能不含指令碼,只提出變更建議,不會更動叢集。

GKE Node NotReady Troubleshooting Skill

Use this skill to systematically diagnose why one or more GKE nodes report a NotReady (or Ready: Unknown) status and to propose safe remediations. A NotReady status means the node's kubelet is not reporting to the control plane correctly, so Kubernetes stops scheduling new Pods on the node, which can reduce application capacity and cause downtime.

This skill operates non-interactively and enforces a read-only diagnostics boundary: gather evidence first, then propose a fix (a kubectl/gcloud command or a GitOps manifest change) for a human to apply. Never mutate the cluster, drain, delete, or recreate nodes automatically.

[!IMPORTANT] First rule out an expected NotReady: a node that is newly provisioning, upgrading, being repaired, cordoned, or scaling down will transiently report NotReady. Only treat it as a fault if it persists beyond the expected window.

🔍 Diagnostic Workflow

Step 0: Context discovery & time window

  1. Parameter extraction — obtain project_id, cluster_name, cluster_location, and node_name non-interactively from the user prompt, active SETTINGS.md, or environment defaults (kubectl config current-context, gcloud config get-value project).
  2. Credentials & fallback — attempt gcloud container clusters get-credentials {cluster_name} --location {cluster_location} --project {project_id}. If the cluster is unreachable or commands fail (sandbox/dry-run/offline), present the exact diagnostic commands for a human to run and continue the analysis from the reported symptoms.
  3. Time window — determine {issue_time} (explicit, relative, or now) and center a 1-hour window around it (start = issue_time - 30m, end = issue_time + 30m) for all log/metric queries.

Step 1: Identify NotReady nodes and gather initial status

bash
# List nodes and spot NotReady status, node IPs, and container-runtime version.kubectl get nodes -o wide
# Inspect the affected node's Conditions and Events (the primary clues).kubectl describe node "{node_name}"

Equivalent via Cloud Logging (preferred when kubectl access is limited or for historical events). Open it as a Logs Explorer deep link — URL-encode the query and append the project and Step 0 time window: https://console.cloud.google.com/logs/query;query={URL_ENCODED_QUERY};timeRange={start}%2F{end}?project={project_id} (encode / as %2F, or use ;duration=PT1H for a rolling hour):

resource.type="k8s_node"log_id("events")resource.labels.node_name="{node_name}"resource.labels.cluster_name="{cluster_name}"resource.labels.location="{cluster_location}"

Interpret the Conditions table:

  • Ready: False / Ready: Unknown with reason KubeletNotReady / NodeStatusUnknown ("Kubelet stopped posting node status") → kubelet or runtime problem; continue to Step 2.
  • MemoryPressure: True, DiskPressure: True, PIDPressure: True → resource exhaustion; go to Step 4b.
  • NetworkUnavailable: True → networking/CNI problem; go to Step 4d.

Step 2: Scan kubelet logs for error signatures

Open these kubelet logs as a Logs Explorer deep link using the same logs/query;query={URL_ENCODED_QUERY};timeRange=...?project=... pattern as Step 1.

resource.type="k8s_node"resource.labels.node_name="{node_name}"resource.labels.cluster_name="{cluster_name}"resource.labels.location="{cluster_location}"log_id("kubelet")severity>=WARNING

Also review the node's serial-console logs (log_id("serialconsole.googleapis.com/serial_port_1_output") or the resource.type="gce_instance" serial logs) for kernel TaskHung, OOM-killer, or disk I/O errors that correlate with the kubelet failures.


Step 3: Map the signature to a root cause (decision table)

Kubelet / event signatureLikely root causeGo to
runtime is down, Container runtime not ready, errors on /run/containerd/containerd.sock (connection refused / DeadlineExceeded)Container runtime (containerd) down or unresponsiveStep 4a
Got sys oom event from cadvisor / kernel OOM-killer in serial logsSystem (node-level) OOM killed critical processesStep 4b
PLEG is not healthyPLEG stalled, usually node overload (CPU/disk)Step 4c
TaskHung for containerd/kubelet, high disk latencyDisk throttling / I/O starvationStep 4b
failed to ensure lease, leases.coordination.k8s.io ... namespace kube-node-lease ... terminatingkube-node-lease termination → NotReady flappingStep 4f
Kubelet cannot reach API server, TLS/dial timeoutsKubelet ↔ control-plane connectivityStep 4d
NetworkPluginNotReady, cni plugin not initialized, NetworkUnavailableCNI plugin failureStep 4d
Node-critical DaemonSet Pods (CNI, kube-proxy, metadata) blocked from admissionAdmission webhook interferenceStep 4e
Only generic NodeNotReady, no other signatureCause unclear — widen to Step 4d, then escalateEscalation

Step 4: Branch investigations

4a. Container runtime (containerd) down

Confirm the kubelet cannot talk to containerd (socket errors above). Check for containerd restarts/crashes in serial logs. Remediation (propose, don't run): recreate/repair the node (kubectl drain then let the node pool recreate it, or gcloud container clusters upgrade/node auto-repair); if it recurs across nodes, suspect a node image or custom DaemonSet interfering with containerd.

4b. Resource pressure & OOM
bash
# Node allocatable vs. usage.kubectl describe node "{node_name}" | sed -n '/Allocated resources/,/Events/p'

Cloud Monitoring metrics to inspect (read-only): kubernetes.io/node/memory/used_bytes, kubernetes.io/node/cpu/core_usage_time, kubernetes.io/node/ephemeral_storage/used_bytes.

  • DiskPressure / disk throttling: full boot disk or slow PD → increase disk size / use a faster PD type; reduce image/log churn.
  • System OOM: node memory exhausted → set/raise Pod memory requests/limits, reduce over-commit, or use larger machine types. Distinguish system OOM (node-wide, kills kubelet/runtime) from cgroup OOM (single container).
  • PIDPressure: too many processes → cap Pod PIDs / reduce workload density.
4c. PLEG is not healthy

PLEG is not healthy almost always means the node is overloaded (CPU saturation, disk latency, or too many Pods/containers per node) so the runtime can't relist in time. Correlate with 4b metrics. Remediation: reduce node density, add CPU/disk headroom, or spread workloads.

4d. Networking
bash
# Are node-critical networking Pods healthy on this node?kubectl get pods -n kube-system -o wide --field-selector spec.nodeName={node_name}
  • Kubelet ↔ control-plane: dial/TLS timeouts to the API server → check firewall rules, Private Google Access, authorized networks, and route/NAT changes.
  • CNI failure (NetworkPluginNotReady): the CNI DaemonSet (netd/calico/dataplane) is not running on the node → inspect those Pods' logs/events.
4e. Admission webhook interference

A misconfigured/failing validating or mutating webhook with a broad scope can block node-critical system Pods from being admitted, keeping the node NotReady.

bash
kubectl get validatingwebhookconfigurations,mutatingwebhookconfigurations

Look for webhooks that intercept kube-system / node-critical objects with failurePolicy: Fail. Remediation (propose): scope the webhook out of kube-system/node-critical namespaces or set an appropriate namespaceSelector.

4f. kube-node-lease termination flapping

If the node flaps NotReady with leases.coordination.k8s.io ... namespace kube-node-lease ... is being terminated, the kube-node-lease namespace was deleted/terminating. Remediation (propose): do not delete the kube-node-lease namespace; if terminating, identify the finalizer/actor holding it and restore the namespace.


Step 5: Remediation boundary & escalation

  • Present the root cause + evidence (the exact conditions, events, log lines, or metrics observed). Provide Cloud Logging deep links (and Cloud Monitoring links for the Step 4b metrics) to the supporting entries — using the deep-link pattern from Steps 1-2 — so a human can open the evidence directly.
  • Propose the fix as a command or GitOps manifest change for a human to apply — never apply, drain, or recreate nodes automatically. When to escalate (do this instead of proposing more self-service diagnostics):

Escalate when either:

  • the relevant logs are unavailable — excluded by a logging filter, or older than the log bucket's retention (the _Default bucket defaults to 30 days, so incidents older than that are permanently deleted); or
  • the kubelet/event signature is not in the Step 3 table and the root cause remains undetermined after the branch investigations.

In those cases, do all three:

  1. State the limitation plainly (for example, "kubelet logs for that date are past the 30-day _Default retention window and are permanently deleted").
  2. Summarize the findings you did gather (node conditions, events, metrics, and any Admin Activity audit logs still in the _Required bucket, default 400-day retention).
  3. Route to GKE support / engineering escalation with those findings. Do not keep proposing further self-service investigation, and do not fabricate a diagnosis when the evidence is missing.

References

This skill is derived from public Google Cloud documentation:

來源與署名

來源:google/skills位於skills/cloud/gke-node-notready提交55b4e13

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 google/skills 的技能

Dpop Adoption

google

精選

指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Security21K今天更新

Finding Google Skills

google

精選

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

待分類21K今天更新

Spanner Basics

google

精選

指導 Google Cloud Spanner 的執行個體與資料庫管理、結構定義設計、查詢與效能診斷。

Data & Analytics21K今天更新

Secops Triage

google

精選

引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Security21K今天更新

Secops Investigate

google

精選

指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Security21K今天更新

Secops Hunt

google

精選

指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Security21K今天更新