环境
系统:CentOS 7.8
准备
-
关闭swap
-
修改内核运行参数
cat << EOF | tee /etc/sysctl.d/99-kubernetes-cri.conf
net.bridge.bridge-nf-call-iptables = 1
net.bridge.bridge-nf-call-ip6tables = 1
net.ipv4.ip_forward = 1
EOF
sysctl --system
- 添加K8S Yum源
cat << EOF | tee /etc/yum.repos.d/kubernetes.repo
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64/
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF
- 安装K8S
yum install -y kubelet kubeadm kubectl
systemctl enable kubelet
Master节点
- 初始化K8S集群
kubeadm init --pod-network-cidr 10.244.0.0/16 --kubernetes-version latest
# 如官方源太慢导致初始化卡住,可更换阿里云源(非必需)
kubeadm init --image-repository=registry.aliyuncs.com/google_containers --pod-network-cidr 10.244.0.0/16 --kubernetes-version latest
--pod-network-cidr
与CNI插件有关,此处使用Flannel
--kubernetes-version
为K8S指定版本,如 stable-1.21
--control-plane-endpoint
为control-plane指定 IP 或 DNS
如出现错误:error: failed to run Kubelet: failed to create kubelet: misconfiguration: kubelet cgroup driver: "cgroupfs" is different from docker cgroup driver: "systemd"
解决方法:更换docker cgroup driver为systemd
成功后会输出
Your Kubernetes control-plane has initialized successfully!
To start using your cluster, you need to run the following as a regular user:
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
Alternatively, if you are the root user, you can run:
export KUBECONFIG=/etc/kubernetes/admin.conf
You should now deploy a pod network to the cluster.
Run "kubectl apply -f [podnetwork].yaml" with one of the options listed at:
https://kubernetes.io/docs/concepts/cluster-administration/addons/
Then you can join any number of worker nodes by running the following on each as root:
kubeadm join 192.168.10.10:6443 --token r4ui2y.ord9liberrbz7qhm \
--discovery-token-ca-cert-hash sha256:b2338948674f696f03bc409d13f940938e17eb04800e605e3a8226597d564263
- 配置集群访问认证
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
- 安装CNI插件
此处使用Flannel
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml
Worker节点
- 加入集群
kubeadm join 192.168.10.10:6443 --token r4ui2y.ord9liberrbz7qhm \
--discovery-token-ca-cert-hash sha256:b2338948674f696f03bc409d13f940938e17eb04800e605e3a8226597d564263
其它
- 允许Master节点运行pod
# 解除限制
kubectl taint nodes --all node-role.kubernetes.io/master-
# 恢复默认
kubectl taint nodes NODE_NAME node-role.kubernetes.io/master=true:NoSchedule
- 使用HPA时,需安装插件Metrics Server
网友评论