生产环境部署 Kubernetes 1.13.1
环境检查 (Master Node and Worker Node)
环境检查参考 Kubernetes
- 支持以下系统:
- Ubuntu 16.04+
- CentOS 7
- 2 GB 内存以上
- 2 核以上
- 节点之间能相互访问
- 每个节点有独立的 MAC 地址 和 product uuid
- 特定的端口要开放
- 禁用Swap
检查唯一 MAC 地址 和 product uuid
MAC 地址
ifconfig -a
product uuid
sudo cat /sys/class/dmi/id/product_uuid
特定端口开放
Master node
TCP 6443* Kubernetes API server
TCP 2379-2380 etcd server client API
TCP 10250 Kubelet API
TCP 10251 kube-scheduler
TCP 10252 kube-controller-manager
Worker node
TCP 10250 Kubelet API
TCP 30000-32767 NodePort Services**
禁用Swap
临时
swapoff -a
永久
sudo vim /etc/fstab
#/swap.img none swap sw 0 0
安装 Docker (Master Node and Worker Node)
安装 Docker 参考 Docker 各个节点统一安装 docker-ce-18.06.0.ce
Ubuntu 安装 kubeadm, kubelet and kubectl (Master Node and Worker Node)
apt-get update && apt-get install -y apt-transport-https curl
curl -s https://mirrors.aliyun.com/kubernetes/apt/doc/apt-key.gpg | sudo apt-key add -
cat <<EOF >/etc/apt/sources.list.d/kubernetes.list
deb https://mirrors.aliyun.com/kubernetes/apt/ kubernetes-xenial main
EOF
apt-get update
apt-get install -y kubelet-1.13.1 kubeadm-1.13.1 kubectl-1.13.1
apt-mark hold kubelet kubeadm kubectl
Centos 安装 kubeadm, kubelet and kubectl (Master Node and Worker Node)
cat <<EOF > /etc/yum.repos.d/kubernetes.repo
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
exclude=kube*
EOF
setenforce 0
sed -i 's/^SELINUX=enforcing$/SELINUX=permissive/' /etc/selinux/config
yum install -y kubelet-1.13.1 kubeadm-1.13.1 kubectl-1.13.1 --disableexcludes=kubernetes
systemctl enable kubelet && systemctl start kubelet
cat <<EOF > /etc/sysctl.d/k8s.conf
net.bridge.bridge-nf-call-ip6tables = 1
net.bridge.bridge-nf-call-iptables = 1
EOF
sysctl --system
初始化 (Master Node)
kubeadm init --image-repository registry.aliyuncs.com/google_containers --kubernetes-version v1.13.1 --pod-network-cidr=192.168.0.0/16
普通用户
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
root
export KUBECONFIG=/etc/kubernetes/admin.conf
安装网络插件 (Master Node)
kubectl apply -f https://docs.projectcalico.org/v3.3/getting-started/kubernetes/installation/hosted/rbac-kdd.yaml
kubectl apply -f https://docs.projectcalico.org/v3.3/getting-started/kubernetes/installation/hosted/kubernetes-datastore/calico-networking/1.7/calico.yaml
添加 Node (Worker Node)
kubeadm join <master-ip>:<master-port> --token <token> --discovery-token-ca-cert-hash sha256:<hash>
获取 token 和 hash (Master Node)
获取 token
kubeadm token list
token 过期 (默认情况下,token的有效期是24小时)
kubeadm token create
获取 hash
openssl x509 -pubkey -in /etc/kubernetes/pki/ca.crt | openssl rsa -pubin -outform der 2>/dev/null | openssl dgst -sha256 -hex | sed 's/^.* //'
检查 Node (Master Node)
kubectl get pod --all-namespaces -o wide
kubectl get nodes
kubectl describe node <node name>
删除 Node (Master Node)
kubectl drain <node name> --delete-local-data --force --ignore-daemonsets
kubectl delete node <node name>
重置 Node (Master Node or Worker Node)
kubeadm reset
部署 (Master Node)
kubectl create deployment nginx --image=nginx:alpine # create deployment
kubectl scale deployment nginx --replicas=2 # scale deployment
kubectl expose deployment nginx --port=80 --type=NodePort # create services
查看服务
kubectl get deployments # 查看应用
kubectl get pods # 查看节点
kubectl get events
kubectl get services # 查看集群外可访问的服务端口
关闭应用
kubectl delete service nginx
kubectl delete deployment nginx