使用kubeadm部署k8s

1.Docker 安裝

1.1CentOS Docker安裝

https://www.runoob.com/docker/centos-docker-install.html

1.2Docker 鏡像加速

https://www.runoob.com/docker/docker-mirror-acceleration.html

1.3Docker Cgroup Driver改為systemd

命令:sudo vi /etc/docker/daemon.json

配置如下:

{
  "exec-opts": ["native.cgroupdriver=systemd"]
}

# 如果使用了加速器配置格式如下
{
  "registry-mirrors": ["https://sv2jerob.mirror.aliyuncs.com"],
  "exec-opts": ["native.cgroupdriver=systemd"]
}

1.4啟動(dòng)Docker

sudo systemctl restart docker

可以查看docker的Cgroup Driver已修改為systemd煤裙,未修改前的值為cgroupfs,命令:sudo docker info

2.kubeadm 安裝

2.1使用阿里鏡像安裝

# 配置源
cat <<EOF > /etc/yum.repos.d/kubernetes.repo
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF

# 安裝
yum install -y kubeadm

3.k8s master init

sudo kubeadm init

如果沒有翻墻,上面的命令會(huì)報(bào)錯(cuò):

[preflight] Some fatal errors occurred:
    [ERROR ImagePull]: failed to pull image [k8s.gcr.io/kube-apiserver:v1.18.1]: exit status 1
    [ERROR ImagePull]: failed to pull image [k8s.gcr.io/kube-controller-manager:v1.18.1]: exit status 1
    [ERROR ImagePull]: failed to pull image [k8s.gcr.io/kube-scheduler:v1.18.1]: exit status 1
    [ERROR ImagePull]: failed to pull image [k8s.gcr.io/kube-proxy:v1.18.1]: exit status 1
    [ERROR ImagePull]: failed to pull image [k8s.gcr.io/pause:3.2]: exit status 1
    [ERROR ImagePull]: failed to pull image [k8s.gcr.io/etcd:3.4.3-0]: exit status 1
    [ERROR ImagePull]: failed to pull image [k8s.gcr.io/coredns:1.6.7]: exit status 1

如果不能翻墻,可以手動(dòng)下載這些鏡像:

curl -s https://www.zhangguanzhang.com/pull | bash -s k8s.gcr.io/kube-apiserver:v1.18.1
curl -s https://www.zhangguanzhang.com/pull | bash -s k8s.gcr.io/kube-controller-manager:v1.18.1
curl -s https://www.zhangguanzhang.com/pull | bash -s k8s.gcr.io/kube-scheduler:v1.18.1
curl -s https://www.zhangguanzhang.com/pull | bash -s k8s.gcr.io/kube-proxy:v1.18.1
curl -s https://www.zhangguanzhang.com/pull | bash -s k8s.gcr.io/pause:3.2
curl -s https://www.zhangguanzhang.com/pull | bash -s k8s.gcr.io/etcd:3.4.3-0
curl -s https://www.zhangguanzhang.com/pull | bash -s k8s.gcr.io/coredns:1.6.7

4.k8s node join

重復(fù)1组去、2兩步,安裝好Docker、kubeadm后,執(zhí)行命令:

sudo kubeadm join 10.0.0.6:6443 --token sh3723.182lsru545rta8qc --discovery-token-ca-cert-hash sha256:d079daadd145a5f5badfcfc8cfed0cb1fa47f734f7e05edb985243aeda202b75

5.第一次使用 Kubernetes 集群所需要的配置命令

mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config

將剛剛部署生成的 Kubernetes 集群的安全配置文件暑塑,保存到當(dāng)前用戶的.kube 目錄下,kubectl 默認(rèn)會(huì)使用這個(gè)目錄下的授權(quán)信息訪問 Kubernetes 集群锅必。

如果不這么做的話事格,我們每次都需要通過 export KUBECONFIG 環(huán)境變量告訴 kubectl 這個(gè)安全配置文件的位置。

6.部署網(wǎng)絡(luò)插件

以Weave Net為例:

export kubever=$(kubectl version | base64 | tr -d '\n')
kubectl apply -f "https://cloud.weave.works/k8s/net?k8s-version=$kubever"

7.部署 Dashboard 可視化插件

7.1安裝

還是墻的問題况毅,使用私人的鏡像image: kubernetesui/dashboard:v2.0.0-rc7
sudo vi dashboard.yaml

# Copyright 2017 The Kubernetes Authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

apiVersion: v1
kind: Namespace
metadata:
  name: kubernetes-dashboard

---

apiVersion: v1
kind: ServiceAccount
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard
  namespace: kubernetes-dashboard

---

kind: Service
apiVersion: v1
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard
  namespace: kubernetes-dashboard
spec:
  type: NodePort
  ports:
    - port: 443
      targetPort: 8443
      nodePort: 30001
  selector:
    k8s-app: kubernetes-dashboard

---

apiVersion: v1
kind: Secret
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard-certs
  namespace: kubernetes-dashboard
type: Opaque

---

apiVersion: v1
kind: Secret
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard-csrf
  namespace: kubernetes-dashboard
type: Opaque
data:
  csrf: ""

---

apiVersion: v1
kind: Secret
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard-key-holder
  namespace: kubernetes-dashboard
type: Opaque

---

kind: ConfigMap
apiVersion: v1
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard-settings
  namespace: kubernetes-dashboard

---

kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard
  namespace: kubernetes-dashboard
rules:
  # Allow Dashboard to get, update and delete Dashboard exclusive secrets.
  - apiGroups: [""]
    resources: ["secrets"]
    resourceNames: ["kubernetes-dashboard-key-holder", "kubernetes-dashboard-certs", "kubernetes-dashboard-csrf"]
    verbs: ["get", "update", "delete"]
    # Allow Dashboard to get and update 'kubernetes-dashboard-settings' config map.
  - apiGroups: [""]
    resources: ["configmaps"]
    resourceNames: ["kubernetes-dashboard-settings"]
    verbs: ["get", "update"]
    # Allow Dashboard to get metrics.
  - apiGroups: [""]
    resources: ["services"]
    resourceNames: ["heapster", "dashboard-metrics-scraper"]
    verbs: ["proxy"]
  - apiGroups: [""]
    resources: ["services/proxy"]
    resourceNames: ["heapster", "http:heapster:", "https:heapster:", "dashboard-metrics-scraper", "http:dashboard-metrics-scraper"]
    verbs: ["get"]

---

kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard
rules:
  # Allow Metrics Scraper to get metrics from the Metrics server
  - apiGroups: ["metrics.k8s.io"]
    resources: ["pods", "nodes"]
    verbs: ["get", "list", "watch"]

---

apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard
  namespace: kubernetes-dashboard
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: Role
  name: kubernetes-dashboard
subjects:
  - kind: ServiceAccount
    name: kubernetes-dashboard
    namespace: kubernetes-dashboard

---

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: kubernetes-dashboard
  namespace: kubernetes-dashboard
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: kubernetes-dashboard
subjects:
  - kind: ServiceAccount
    name: kubernetes-dashboard
    namespace: kubernetes-dashboard

---

kind: Deployment
apiVersion: apps/v1
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard
  namespace: kubernetes-dashboard
spec:
  replicas: 1
  revisionHistoryLimit: 10
  selector:
    matchLabels:
      k8s-app: kubernetes-dashboard
  template:
    metadata:
      labels:
        k8s-app: kubernetes-dashboard
    spec:
      containers:
        - name: kubernetes-dashboard
          image: kubernetesui/dashboard:v2.0.0-rc7
          imagePullPolicy: Always
          ports:
            - containerPort: 8443
              protocol: TCP
          args:
            - --auto-generate-certificates
            - --namespace=kubernetes-dashboard
            # Uncomment the following line to manually specify Kubernetes API server Host
            # If not specified, Dashboard will attempt to auto discover the API server and connect
            # to it. Uncomment only if the default does not work.
            # - --apiserver-host=http://my-address:port
          volumeMounts:
            - name: kubernetes-dashboard-certs
              mountPath: /certs
              # Create on-disk volume to store exec logs
            - mountPath: /tmp
              name: tmp-volume
          livenessProbe:
            httpGet:
              scheme: HTTPS
              path: /
              port: 8443
            initialDelaySeconds: 30
            timeoutSeconds: 30
      volumes:
        - name: kubernetes-dashboard-certs
          secret:
            secretName: kubernetes-dashboard-certs
        - name: tmp-volume
          emptyDir: {}
      serviceAccountName: kubernetes-dashboard
      # Comment the following tolerations if Dashboard must not be deployed on master
      tolerations:
        - key: node-role.kubernetes.io/master
          effect: NoSchedule

---

kind: Service
apiVersion: v1
metadata:
  labels:
    k8s-app: dashboard-metrics-scraper
  name: dashboard-metrics-scraper
  namespace: kubernetes-dashboard
spec:
  ports:
    - port: 8000
      targetPort: 8000
  selector:
    k8s-app: dashboard-metrics-scraper

---

kind: Deployment
apiVersion: apps/v1
metadata:
  labels:
    k8s-app: dashboard-metrics-scraper
  name: dashboard-metrics-scraper
  namespace: kubernetes-dashboard
spec:
  replicas: 1
  revisionHistoryLimit: 10
  selector:
    matchLabels:
      k8s-app: dashboard-metrics-scraper
  template:
    metadata:
      labels:
        k8s-app: dashboard-metrics-scraper
    spec:
      containers:
        - name: dashboard-metrics-scraper
          image: kubernetesui/metrics-scraper:v1.0.4
          ports:
            - containerPort: 8000
              protocol: TCP
          livenessProbe:
            httpGet:
              scheme: HTTP
              path: /
              port: 8000
            initialDelaySeconds: 30
            timeoutSeconds: 30
          volumeMounts:
          - mountPath: /tmp
            name: tmp-volume
      serviceAccountName: kubernetes-dashboard
      # Comment the following tolerations if Dashboard must not be deployed on master
      tolerations:
        - key: node-role.kubernetes.io/master
          effect: NoSchedule
      volumes:
        - name: tmp-volume
          emptyDir: {}

運(yùn)行pod

kubectl apply -f dashboard.yaml

查看pod的運(yùn)行情況

kubectl get pods -n kubernetes-dashboard

如果處于running狀態(tài)分蓖,查看一下dashboard的log日志

kubectl logs  -f  kubernetes-dashboard-cdbc9547c-7sb2n -n kubernetes-dashboard

kubectl logs  -f  dashboard-metrics-scraper-fb986f88d-nd9d6  -n kubernetes-dashboard

7.2允許外部訪問

kubectl proxy --address='0.0.0.0' --accept-hosts='^*$'

7.3瀏覽器中訪問

瀏覽器輸入https://IP:30001,通過token訪問

7.3獲取token

Dashboard支持Kubeconfig和Token兩種認(rèn)證方式尔许,為了簡(jiǎn)化配置,我們通過配置文件 dashboard-admin.yaml為Dashboard默認(rèn)用戶賦予admin權(quán)限

sudo vi dashboard-admin.yaml

文件內(nèi)容:

apiVersion: v1
kind: ServiceAccount
metadata:
  name: dashboard-admin
  namespace: kube-system
---
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1beta1
metadata:
  name: dashboard-admin
subjects:
  - kind: ServiceAccount
    name: dashboard-admin
    namespace: kube-system
roleRef:
  kind: ClusterRole
  name: cluster-admin
  apiGroup: rbac.authorization.k8s.io

執(zhí)行kubectl apply使之生效

kubectl apply -f dashboard-admin.yaml

獲取token终娃,其中dashboard-admin-token-nhrx9通過命令kubectl get secret -n kube-system |grep dashboard-admin獲取

kubectl get secret -n kube-system |grep dashboard-admin
kubectl describe secret dashboard-admin-token-nhrx9 -n kube-system

8.安裝存儲(chǔ)插件

cd /usr/local/src
yum -y install git
git clone https://github.com/rook/rook.git
cd /usr/local/src/rook/cluster/examples/kubernetes/ceph
kubectl apply -f common.yaml
kubectl apply -f operator.yaml
kubectl apply -f cluster.yaml 

配置系統(tǒng)相關(guān)參數(shù)

# 臨時(shí)禁用selinux
# 永久關(guān)閉 修改/etc/sysconfig/selinux文件設(shè)置
sed -i 's/SELINUX=permissive/SELINUX=disabled/' /etc/sysconfig/selinux
setenforce 0

# 臨時(shí)關(guān)閉swap
# 永久關(guān)閉 注釋/etc/fstab文件里swap相關(guān)的行
swapoff -a



# 開啟forward
# Docker從1.13版本開始調(diào)整了默認(rèn)的防火墻規(guī)則
# 禁用了iptables filter表中FOWARD鏈
# 這樣會(huì)引起Kubernetes集群中跨Node的Pod無法通信

iptables -P FORWARD ACCEPT

# 配置轉(zhuǎn)發(fā)相關(guān)參數(shù)味廊,否則可能會(huì)出錯(cuò)
cat <<EOF >  /etc/sysctl.d/k8s.conf
net.bridge.bridge-nf-call-ip6tables = 1
net.bridge.bridge-nf-call-iptables = 1
vm.swappiness=0
EOF
sysctl --system
最后編輯于
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
  • 序言:七十年代末,一起剝皮案震驚了整個(gè)濱河市棠耕,隨后出現(xiàn)的幾起案子余佛,更是在濱河造成了極大的恐慌,老刑警劉巖窍荧,帶你破解...
    沈念sama閱讀 217,509評(píng)論 6 504
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件辉巡,死亡現(xiàn)場(chǎng)離奇詭異,居然都是意外死亡蕊退,警方通過查閱死者的電腦和手機(jī)郊楣,發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 92,806評(píng)論 3 394
  • 文/潘曉璐 我一進(jìn)店門憔恳,熙熙樓的掌柜王于貴愁眉苦臉地迎上來,“玉大人净蚤,你說我怎么就攤上這事钥组。” “怎么了今瀑?”我有些...
    開封第一講書人閱讀 163,875評(píng)論 0 354
  • 文/不壞的土叔 我叫張陵程梦,是天一觀的道長(zhǎng)。 經(jīng)常有香客問我橘荠,道長(zhǎng)屿附,這世上最難降的妖魔是什么? 我笑而不...
    開封第一講書人閱讀 58,441評(píng)論 1 293
  • 正文 為了忘掉前任哥童,我火速辦了婚禮挺份,結(jié)果婚禮上,老公的妹妹穿的比我還像新娘如蚜。我一直安慰自己压恒,他們只是感情好,可當(dāng)我...
    茶點(diǎn)故事閱讀 67,488評(píng)論 6 392
  • 文/花漫 我一把揭開白布错邦。 她就那樣靜靜地躺著探赫,像睡著了一般。 火紅的嫁衣襯著肌膚如雪撬呢。 梳的紋絲不亂的頭發(fā)上伦吠,一...
    開封第一講書人閱讀 51,365評(píng)論 1 302
  • 那天,我揣著相機(jī)與錄音魂拦,去河邊找鬼毛仪。 笑死,一個(gè)胖子當(dāng)著我的面吹牛芯勘,可吹牛的內(nèi)容都是我干的箱靴。 我是一名探鬼主播,決...
    沈念sama閱讀 40,190評(píng)論 3 418
  • 文/蒼蘭香墨 我猛地睜開眼荷愕,長(zhǎng)吁一口氣:“原來是場(chǎng)噩夢(mèng)啊……” “哼衡怀!你這毒婦竟也來了?” 一聲冷哼從身側(cè)響起安疗,我...
    開封第一講書人閱讀 39,062評(píng)論 0 276
  • 序言:老撾萬榮一對(duì)情侶失蹤抛杨,失蹤者是張志新(化名)和其女友劉穎,沒想到半個(gè)月后荐类,有當(dāng)?shù)厝嗽跇淞掷锇l(fā)現(xiàn)了一具尸體怖现,經(jīng)...
    沈念sama閱讀 45,500評(píng)論 1 314
  • 正文 獨(dú)居荒郊野嶺守林人離奇死亡,尸身上長(zhǎng)有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點(diǎn)故事閱讀 37,706評(píng)論 3 335
  • 正文 我和宋清朗相戀三年玉罐,在試婚紗的時(shí)候發(fā)現(xiàn)自己被綠了屈嗤。 大學(xué)時(shí)的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片潘拨。...
    茶點(diǎn)故事閱讀 39,834評(píng)論 1 347
  • 序言:一個(gè)原本活蹦亂跳的男人離奇死亡,死狀恐怖恢共,靈堂內(nèi)的尸體忽然破棺而出战秋,到底是詐尸還是另有隱情,我是刑警寧澤讨韭,帶...
    沈念sama閱讀 35,559評(píng)論 5 345
  • 正文 年R本政府宣布脂信,位于F島的核電站,受9級(jí)特大地震影響透硝,放射性物質(zhì)發(fā)生泄漏狰闪。R本人自食惡果不足惜,卻給世界環(huán)境...
    茶點(diǎn)故事閱讀 41,167評(píng)論 3 328
  • 文/蒙蒙 一濒生、第九天 我趴在偏房一處隱蔽的房頂上張望埋泵。 院中可真熱鬧,春花似錦罪治、人聲如沸丽声。這莊子的主人今日做“春日...
    開封第一講書人閱讀 31,779評(píng)論 0 22
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽。三九已至久脯,卻和暖如春晒骇,著一層夾襖步出監(jiān)牢的瞬間霉撵,已是汗流浹背。 一陣腳步聲響...
    開封第一講書人閱讀 32,912評(píng)論 1 269
  • 我被黑心中介騙來泰國打工洪囤, 沒想到剛下飛機(jī)就差點(diǎn)兒被人妖公主榨干…… 1. 我叫王不留徒坡,地道東北人。 一個(gè)月前我還...
    沈念sama閱讀 47,958評(píng)論 2 370
  • 正文 我出身青樓瘤缩,卻偏偏與公主長(zhǎng)得像喇完,于是被迫代替她去往敵國和親。 傳聞我的和親對(duì)象是個(gè)殘疾皇子剥啤,可洞房花燭夜當(dāng)晚...
    茶點(diǎn)故事閱讀 44,779評(píng)論 2 354

推薦閱讀更多精彩內(nèi)容