生产环境部署 Kubernetes 1.13.1

环境检查 (Master Node and Worker Node)

环境检查参考 Kubernetes

检查唯一 MAC 地址 和 product uuid

MAC 地址

ifconfig -a

product uuid

sudo cat /sys/class/dmi/id/product_uuid
特定端口开放

Master node

TCP    6443*        Kubernetes API server
TCP    2379-2380    etcd server client API
TCP    10250        Kubelet API
TCP    10251        kube-scheduler
TCP    10252        kube-controller-manager

Worker node

TCP    10250    Kubelet API
TCP    30000-32767    NodePort Services**
禁用Swap

临时

swapoff -a

永久

sudo vim /etc/fstab

#/swap.img      none    swap    sw      0       0

安装 Docker (Master Node and Worker Node)

安装 Docker 参考 Docker 各个节点统一安装 docker-ce-18.06.0.ce

Ubuntu 安装 kubeadm, kubelet and kubectl (Master Node and Worker Node)

apt-get update && apt-get install -y apt-transport-https curl
curl -s https://mirrors.aliyun.com/kubernetes/apt/doc/apt-key.gpg | sudo apt-key add -
cat <<EOF >/etc/apt/sources.list.d/kubernetes.list
deb https://mirrors.aliyun.com/kubernetes/apt/ kubernetes-xenial main
EOF
apt-get update
apt-get install -y kubelet-1.13.1 kubeadm-1.13.1 kubectl-1.13.1
apt-mark hold kubelet kubeadm kubectl

Centos 安装 kubeadm, kubelet and kubectl (Master Node and Worker Node)


cat <<EOF > /etc/yum.repos.d/kubernetes.repo
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
exclude=kube*
EOF

setenforce 0
sed -i 's/^SELINUX=enforcing$/SELINUX=permissive/' /etc/selinux/config

yum install -y kubelet-1.13.1 kubeadm-1.13.1 kubectl-1.13.1 --disableexcludes=kubernetes

systemctl enable kubelet && systemctl start kubelet

cat <<EOF >  /etc/sysctl.d/k8s.conf
net.bridge.bridge-nf-call-ip6tables = 1
net.bridge.bridge-nf-call-iptables = 1
EOF
sysctl --system

初始化 (Master Node)

kubeadm init --image-repository registry.aliyuncs.com/google_containers --kubernetes-version v1.13.1 --pod-network-cidr=192.168.0.0/16

普通用户

mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config

root

export KUBECONFIG=/etc/kubernetes/admin.conf

安装网络插件 (Master Node)


kubectl apply -f https://docs.projectcalico.org/v3.3/getting-started/kubernetes/installation/hosted/rbac-kdd.yaml
kubectl apply -f https://docs.projectcalico.org/v3.3/getting-started/kubernetes/installation/hosted/kubernetes-datastore/calico-networking/1.7/calico.yaml

添加 Node (Worker Node)

kubeadm join <master-ip>:<master-port> --token <token> --discovery-token-ca-cert-hash sha256:<hash>

获取 token 和 hash (Master Node)

获取 token

kubeadm token list

token 过期 (默认情况下,token的有效期是24小时)

kubeadm token create

获取 hash

openssl x509 -pubkey -in /etc/kubernetes/pki/ca.crt | openssl rsa -pubin -outform der 2>/dev/null | openssl dgst -sha256 -hex | sed 's/^.* //'

检查 Node (Master Node)


kubectl get pod --all-namespaces -o wide
kubectl get nodes
kubectl describe node <node name>

删除 Node (Master Node)


kubectl drain <node name> --delete-local-data --force --ignore-daemonsets
kubectl delete node <node name>

重置 Node (Master Node or Worker Node)

kubeadm reset

部署 (Master Node)

kubectl create deployment nginx --image=nginx:alpine       # create deployment
kubectl scale deployment nginx --replicas=2                # scale deployment 
kubectl expose deployment nginx --port=80 --type=NodePort  # create services

查看服务

kubectl get deployments  # 查看应用
kubectl get pods         # 查看节点
kubectl get events
kubectl get services     # 查看集群外可访问的服务端口

关闭应用

kubectl delete service nginx 
kubectl delete deployment nginx