ErrLookup › k3s-io/k3s
k3s-io/k3s
Lightweight Kubernetes · Go · 236 source files
Analyzed at 6ba341e396 on 2026-08-15. 202 documented errors.
| Code / Message | Type | Severity | Tags |
|---|---|---|---|
| insufficient PSK bytes | validation | error | security, psk, embedded-registry, spegel, config |
| nix-store not found in PATH: install nix (https://nixos.org/ | validation | error | containerd, snapshotter, nix, environment, path |
| cri-dockerd disabled at build time | exception | error | build-tags, cri-dockerd, docker, runtime, distribution |
| ipv4 mode requested but no ipv4 network provided | validation | error | flannel, cni, networking, ipv4, cluster-cidr |
| Flannel configuration not defined | validation | error | flannel, cni, config, internal-api |
| incorrect netMode for flannel tailscale backend | validation | error | flannel, tailscale, vpn, cluster-cidr, networking |
| Failed checking netMode | validation | error | flannel, cidr, validation, internal-api |
| all servers failed | exception | critical | load-balancer, connectivity, agent, supervisor, networking |
| Initial server URL host is not defined for load balancer | validation | error | load-balancer, url, config, validation |
| dual-stack or IPv6 are not supported on Windows node | validation | error | windows, ipv6, dual-stack, platform, cluster-cidr |
| embedded registry mirror requires embedded containerd | validation | error | embedded-registry, spegel, containerd, docker, config |
| invalid username/password combination | http | error | authentication, basic-auth, http, security, supervisor |
| unhandled cgroup mode | validation | critical | cgroups, linux, startup, container, host |
| failed to find memory cgroup, you may need to add "cgroup_me | validation | critical | cgroups, memory, raspberry-pi, kernel, cmdline |
| --token is required | validation | error | agent, token, bootstrap, authentication, cli |
| --server is required | validation | error | agent, cli, server, config, validation |
| service %s is not recognized | validation | error | certificates, cli, tls, validation, rotation |
| no snapshots given for removal | validation | error | etcd, snapshot, cli, validation, backup |
| invalid output format: | validation | error | etcd, snapshot, cli, output-format, validation |
| etcd-snapshot-reconcile-interval must be greater than 0s | validation | error | etcd, snapshot, server, config, validation |
| etcd-s3-timeout must be greater than 0s | validation | error | etcd, s3, backup, configuration, validation |
| invalid flag use; --cluster-reset required with --cluster-re | validation | error | cluster-reset, restore, etcd, backup, configuration |
| invalid flag use; --server is required with --disable-etcd | validation | error | etcd, cluster, ha, configuration |
| invalid flag use; cannot use --disable-apiserver with --data | validation | error | datastore, apiserver, configuration, ha |
| invalid flag use; cannot use --disable-etcd with --datastore | validation | error | datastore, etcd, configuration, ha |
| cannot perform cluster-reset while server URL is set - remov | validation | error | cluster-reset, recovery, etcd, configuration |
| does not exist, please pass --token to complete the restora | validation | error | cluster-reset, restore, token, recovery |
| tailscale does not provide an ipv6 address | exception | error | tailscale, vpn, ipv6, networking |
| tailscale does not provide an ipv4 address | exception | error | tailscale, vpn, ipv4, networking |
| missing argument; 'token delete' is missing token | validation | error | cli, token, usage |
| token must not be empty | validation | error | token, validation, api, clientaccess |
| invalid token CA hash length | validation | error | token, validation, format, clientaccess |
| invalid token format | validation | error | token, validation, format, clientaccess |
| only https:// URLs are supported, invalid scheme: | validation | error | token, url, tls, networking, clientaccess |
| all cloud-provider functionality disabled by config | validation | error | cloud-provider, servicelb, configuration, validation |
| toleration with empty key must have operator 'Exists' | validation | error | servicelb, tolerations, kubernetes, validation |
| toleration with operator 'Exists' must have an empty value | validation | error | servicelb, tolerations, kubernetes, validation |
| token is required to join a cluster | validation | critical | bootstrap, token, cluster-join, ha |
| missing %s directory from ${data-dir} | exception | critical | bootstrap, certificates, data-dir, recovery |
| %s directory is empty | exception | critical | bootstrap, certificates, data-dir, recovery |
| no bootstrap data found in datastore - check server token va | exception | critical | k3s, bootstrap, etcd, token, datastore |
| no bootstrap data is available to reconcile against | exception | critical | k3s, bootstrap, startup, join |
| critical configuration value mismatch between servers | exception | error | k3s, configuration, join, validation, deep-equal |
| invalid cipher text, not : delimited | exception | error | k3s, encryption, aes-gcm, bootstrap, corruption |
| etcd datastore disabled | http | warning | k3s, etcd, datastore, http, sqlite |
| no bootstrap data found | exception | critical | k3s, bootstrap, datastore, etcd, storage |
| found multiple bootstrap keys in storage | exception | critical | k3s, bootstrap, etcd, token, migration |
| bootstrap data already found and encrypted with different to | exception | critical | k3s, bootstrap, token, encryption, join |
| nix-store not found in PATH: install nix (https://nixos.org/ | exception | error | k3s, containerd, nix, snapshotter, linux |
| delegated cgroup v2 controllers are required for rootless | exception | critical | k3s, rootless, cgroups, cgroup-v2, linux, kubelet |
| pids cgroup controller not found | exception | critical | k3s, cgroups, kubelet, linux, container |
| hijacking not supported | http | error | k3s, http, hijack, proxy, tunnel, http2 |
| this server has not yet been promoted from learner to voting | exception | warning | k3s, etcd, learner, raft, join, transient |
| Managed etcd cluster membership has been reset, restart with | exception | info | k3s, etcd, cluster-reset, recovery, shutdown |
| cannot use S3 config secret when restoring snapshot; configu | validation | error | k3s, etcd, s3, cluster-reset, credentials |
| duplicate node name found, please use a unique name for this | validation | critical | k3s, etcd, node-name, join, duplicate |
| tombstone file has been detected but --server is empty: back | validation | critical | k3s, etcd, tombstone, join, recovery |
| server node name not set | validation | critical | k3s, etcd, node-name, hostname, startup |
| failed to get etcd MemberList: etcd not started | http | error | etcd, http, startup, cluster-join |
| etcd member has status errors: %s | exception | critical | etcd, storage, alarm, corruption |
| no etcd restore path was specified | validation | error | etcd, restore, configuration |
| s3 configuration was not set | validation | error | s3, etcd, configuration, backup |
| s3 bucket name was not set | validation | error | s3, configuration, validation |
| proxy URL must include scheme and host | validation | error | s3, proxy, configuration, url-parsing |
| no certificates loaded from etcd-s3-endpoint-ca | validation | error | s3, tls, certificates, configuration |
| unexpected compressed etcd snapshot contents | exception | error | etcd, snapshot, zip, restore |
| snapshot save already in progress | exception | warning | etcd, snapshot, concurrency |
| invalid snapshot operation | http | error | http, api, snapshot, validation |
| failed to read consistent index | exception | critical | etcd, bbolt, storage, corruption |
| invalid output format: {cfg.Output} | validation | error | cli, validation, token |
| password hash not found in node secret | http | error | authentication, kubernetes, secrets, node |
| header node name does not match auth node name | http | error | authentication, security, tls, node |
| auth user not set | http | error | authentication, http, middleware |
| node name not set | http | error | authentication, http-headers, node |
| node password not set | http | error | authentication, http-headers, node |
| host identifier bits must not be set in CIDR prefix | validation | error | networking, cidr, configuration, rootless |
| unsupported encryption keys found | validation | error | security, encryption, kubernetes, configuration |
| encryption reload time is incorrectly ahead of current time | exception | warning | encryption, metrics, clock-skew, time |
| not authorized | http | error | auth, http, k3s, middleware, startup, nil-safety |
| method not allowed | http | warning | http, k3s, method-not-allowed, certificates, ca-rotation |
| new CA bundle contains only a single certificate but should | validation | error | k3s, certificates, ca-rotation, pki, validation |
| old ServiceAccount signing key not in new ServiceAccount key | validation | error | k3s, certificates, service-account, key-rotation, validation |
| etcd disabled | http | warning | k3s, etcd, bootstrap, clustering, http |
| unable to enable/disable secrets encryption, unknown configu | http | error | k3s, secrets-encryption, configuration, security |
| method not allowed | http | warning | http, k3s, method-not-allowed, secrets-encryption |
| prepare does not support secretbox key type, use rotate-keys | http | warning | k3s, secrets-encryption, secretbox, key-rotation, unsupported-operation |
| rotate does not support secretbox key type, use rotate-keys | http | warning | k3s, secrets-encryption, secretbox, key-rotation, unsupported-operation |
| reencrypt does not support secretbox key type, use rotate-ke | http | warning | k3s, secrets-encryption, secretbox, key-rotation, unsupported-operation |
| method not allowed | http | warning | http, k3s, method-not-allowed, token, authentication |
| server token not found | http | error | k3s, token, credentials, file-corruption, authentication |
| apiserver not ready | http | warning | k3s, apiserver, startup, transient, http-503 |
| apiserver disabled | http | info | k3s, apiserver, configuration, http-503, ha |
| no IPv4 CIDRs found | validation | error | k3s, network, ipv4, cidr, configuration, dual-stack |
| no IPv4 address found | validation | error | k3s, network, ipv4, node-ip, configuration, dual-stack |
| no IPv6 address found | validation | error | k3s, network, ipv6, node-ip, configuration, dual-stack |
| no IPv6 CIDRs found | validation | error | network, ipv6, dual-stack, cidr, config |
| not running as root | console | error | permissions, root, linux, unix |
| not running as member of BUILTIN\Administrators group | console | error | permissions, windows, privileges, uac |
| failed to normalize server token; must be in format K10<CA-H | validation | error | auth, token, credentials, config |
| VPN Error. Tailscale requires a JoinKey | validation | error | vpn, tailscale, flannel, config, auth |
| Requested VPN: <name> is not supported. We currently only su | validation | error | vpn, config, validation |
| Node password rejected, duplicate hostname or contents of '% | console | error | auth, node, registration, cluster, hostname |
| %s: %s | console | error | http, connection, agent, status, server |
| invalid node-external-ip: %w | validation | error | config, ip, validation, agent, network |
| incompatible down-level server detected; servers must be upg | console | error | versioning, upgrade, network-policy, agent, server |
| invalid endpoint URL %s for %s: %v | validation | error | registry, containerd, config, url, parsing |
| default runtime %s was not found | validation | error | containerd, runtime, linux, config, gpu |
| failed to detect selinux: %w | console | error | selinux, linux, containerd, host, security |
| failed to determine MTU for %s interface | exception | error | flannel, network, mtu, interface, config |
| unsupported flannel backend '%s' for Windows | validation | error | flannel, windows, backend, config |
| Cannot configure unknown flannel backend '%s' | validation | error | flannel, config, backend, validation |
| unsupported proxy scheme: %s | validation | error | proxy, network, environment, loadbalancer, url |
| no server found for %s | exception | error | loadbalancer, internal, api, ordering |
| server %s is stopping | exception | warning | loadbalancer, lifecycle, transient, network, retry |
| cluster-cidr: %v and service-cidr: %v, must share the same I | validation | error | network, dual-stack, ipv6, config, agent, cidr |
| cluster-cidr: %v and node-ip: %v, must share the same IP ver | validation | error | |
| hash version %d does not match package version %d | exception | error | |
| password file '%s' must have at least 3 columns (password, u | validation | error | |
| failed to hash password for username '%s' in password file ' | exception | error | |
| %s/%s: certificate %s is not valid before %s | exception | error | |
| %s/%s: certificate %s expired at %s | exception | error | |
| %s/%s: certificate %s will expire within %d days at %s | exception | error | |
| failed to find %s cgroup (v2) | exception | error | |
| invalid output format %s | validation | error | |
| server time isn't set properly: %v | validation | error | |
| server panicked: %v | panic | error | |
| invalid cluster-dns address %s | validation | error | |
| invalid egress-selector-mode %s | validation | error | |
| a token with id %q already exists | validation | error | |
| given token didn't match pattern %q or %q | validation | error | |
| token CA hash does not match the Cluster CA certificate hash | validation | error | |
| %s: %s | http | error | |
| error updating LoadBalancer Status for %s: %v, requeueing | exception | error | |
| failed to parse tolerations from annotation %s: %v | validation | error | |
| validation failed for toleration %d: %v | validation | error | |
| Managed etcd cluster membership was previously reset, please | validation | error | etcd, k3s, cluster-reset, startup, operations |
| failed to parse config location %s: %w | validation | error | config, url-parsing, cli, shell |
| failed to read http config %s: %w | exception | error | network, http, tls, config, proxy |
| value required for kubelet-arg --%s | validation | error | kubelet, configuration, cli, agent, k3s |
| unsupported secrets-encryption-provider %s | validation | error | security, encryption, configuration, k3s |
| failed to verify directory %s | exception | critical | integrity, sha256, deployment, startup, airgap |
| no entries found in %s | exception | error | integrity, sha256, deployment, startup |
| failed %d hash verifications | exception | critical | integrity, sha256, corruption, deployment, startup |
| failed %d link verifications | exception | error | integrity, symlinks, deployment, filesystem |
| fields for file %s (%d) smaller than required index (key: %d | exception | error | integrity, parsing, sha256, manifest |
| invalid GVK format: %s | validation | warning | manifests, deploy, gvk, addon, parsing |
| etcd: snapshot path does not exist: %s | validation | critical | etcd, snapshot, restore, cluster-reset, k3s |
| etcd: snapshot path must be a file, not a directory: %s | validation | critical | etcd, snapshot, restore, cluster-reset, k3s |
| failed to migrate content from sqlite to etcd: %w | exception | critical | etcd, sqlite, migration, cluster-init, ha, k3s |
| etcd alarm list failed: %v | exception | error | etcd, alarms, nospace, disk, health |
| %s disarm failed: %v | exception | error | etcd, alarms, nospace, quota, disk |
| %s alarm must be disarmed manually | exception | critical | etcd, corruption, alarms, disaster-recovery, disk |
| failed to unmarshal apiserver addresses from etcd: %v | exception | error | etcd, json, apiserver, networking, k3s |
| node name annotation for node %s not found | exception | error | etcd, annotations, node-management, kubernetes, k3s |
| failed to get CRDs from %s: %v | exception | critical | kubernetes, crd, startup, embedded-assets |
| cannot use current data for %s; field is not settable | http | error | certificates, reflection, rotation, tls |
| invalid node IP address %s | http | error | network, kubelet, tls, agent |
| more than 3 providers (%d) found in secrets encryption | http | error | secrets-encryption, configuration, security |
| cannot enable secrets encryption with %s key type, no keys f | http | error | secrets-encryption, keys, configuration |
| unknown stage %s requested | http | warning | api, validation, secrets-encryption |
| failed to update secret: %v | http | error | kubernetes, secrets, re-encryption, apiserver |
| cannot manage secrets encryption on non control-plane node % | http | error | secrets-encryption, nodes, labels, rbac |
| invalid annotation %s found on node %s | http | error | annotations, secrets-encryption, cluster-sync |
| missing annotation on node %s | http | error | annotations, secrets-encryption, cluster-sync |
| failed to parse kubelet version %s: %v | http | error | versioning, nodes, secrets-encryption |
| node %s is running k3s version %s that does not support rota | http | error | upgrade, versioning, secrets-encryption |
| hash does not match between %s and %s | http | error | secrets-encryption, cluster-sync, annotations |
| incorrect stage: %s found on node %s | http | error | secrets-encryption, state-machine, validation |
| invalid hash: %s found on node %s | http | error | secrets-encryption, integrity, configuration |
| failed to remove %s file: %v | console | error | filesystem, kubeconfig, symlink, startup |
| failed to create path for symlink: %v | console | error | filesystem, permissions, startup, kubeconfig |
| failed to create symlink: %v | console | error | filesystem, symlink, kubeconfig, startup |
| error extracting zstd-compressed body: %v | exception | critical | zstd, tar, startup, integrity |
| tar error: %v | exception | critical | tar, startup, integrity, filesystem |
| tar contained invalid name error %q | validation | error | go, tar, security, path-traversal, archive |
| error writing to %s: %v | exception | error | go, tar, io, disk-full, filesystem |
| only wrote %d bytes to %s; expected %d | exception | error | go, tar, corruption, download, io |
| tar file entry %s contained unsupported file type %v | exception | error | go, tar, file-type, archive |
| %s error ID %05d | http | error | go, http, api, logging, correlation |
| invalid node-ip: %w | validation | error | go, network, configuration, ip, k3s |
| invalid ip format '%s' | validation | error | go, network, ip, parsing, configuration |
| ip: %v is not ipv4 or ipv6 | validation | error | go, network, ip, dual-stack |
| interface %s does not have a correct global unicast ip: %w | exception | error | go, network, interface, configuration, nic |
| the interface %s is not up | exception | error | go, network, interface, link-down |
| unable to parse CIDR for interface %s: %w | exception | error | go, network, interface, cidr, parsing |
| multiple global unicast addresses defined for %s, please set | validation | error | go, network, interface, multi-homed, configuration |
| can't find ip for interface %s | exception | error | go, network, interface, dhcp, address-missing |
| %s is not a recognized service | validation | error | go, certificates, services, configuration, k3s |
| Requested VPN: %s is not supported. We currently only suppor | validation | error | go, vpn, tailscale, configuration |
| VPN Error. The passed VPN auth info includes an unknown para | validation | error | go, vpn, configuration, parsing, tailscale |
| VPN Error. Invalid control server URL for Tailscale: %w | validation | error | go, vpn, url, validation, tailscale |
| failed to run tailscale status --json: %v | exception | error | go, vpn, tailscale, exec, cli |
| failed to unmarshal tailscale output: %v | exception | error | go, vpn, tailscale, json, parsing |
| failed to run tailscale debug prefs: %v | exception | error | go, vpn, tailscale, exec, routes |
| Failed to create image import watcher: | panic | critical | fsnotify, inotify, containerd, airgap, panic, k3s |
| failed to start etcd client | panic | critical | etcd, tls, panic, control-plane, leader-election, k3s |
| failed to start wrangler controllers | panic | critical | wrangler, informer, apiserver, etcd, panic, k3s |
| Rootless is not supported on windows | panic | error | rootless, windows, platform-unsupported, panic, k3s |
| Rootless is not supported on windows | panic | error | rootless, windows, port-forwarding, platform-unsupported, panic, k3s |
| failed to start %s leader controller | panic | critical | controllers, leader-election, panic, startup, k3s |
| failed to start wranger controllers | panic | critical | wrangler, informer, apiserver, panic, startup, k3s |
| no peer addresses available | http | warning | spegel, p2p, registry-mirror, networking, k3s |