Failing pod

How to fix CreateContainerConfigError in Kubernetes

CreateContainerConfigError means the kubelet could not build the container’s configuration before starting it. The image is already pulled, but the container never runs, so there is no log: the answer is in the pod’s event.

1. Read the event message

kubectl describe pod <pod> -n <namespace>

What the message means

  • configmap "<name>" not found or secret "<name>" not found: the pod references a ConfigMap or Secret that does not exist in its namespace. Secrets and ConfigMaps are not visible from another namespace.
  • couldn't find key <key> in ConfigMap or in Secret: the object exists, but the key used in configMapKeyRef or secretKeyRef is missing. Check upper and lower case.
  • container has runAsNonRoot and image will run as root: the securityContext requires a non-root user and the image runs as root. Set runAsUser to a non-zero UID or use an image that runs as another user.

2. Check what exists in the namespace

Describing a Secret shows its keys and the size of each value, without showing the value:

kubectl get configmap,secret -n <namespace>
kubectl describe configmap <name> -n <namespace>
kubectl describe secret <name> -n <namespace>

3. Fix it

  • Create the missing ConfigMap or Secret in the pod’s namespace, with the right keys. The kubelet retries on its own and the container starts.
  • If the variable is optional, set optional: true in configMapKeyRef, secretKeyRef or envFrom.
  • In pipelines, create Secrets and ConfigMaps before the Deployment, or in the same apply.

Without a terminal, in Kubepier

In Kubepier, the pod status shows CreateContainerConfigError and the event with the message rises to the top of the warnings. ConfigMaps and Secrets show up in the resource list, Secrets by key only, without the values, from any cluster, in the browser or on your phone.

Start for free