默認(rèn)token的有效期為24小時(shí),當(dāng)過期之后陷虎,該token就不可用了。
產(chǎn)生token:
kubeadm token create
oapcal.mlearjiaijljtyeq
取ca證書sha256編碼hash值:
openssl x509 -pubkey -in /etc/kubernetes/pki/ca.crt | openssl rsa -pubin -outform der 2>/dev/null | openssl dgst -sha256 -hex | sed 's/^.* //'
8832ca46fa644aa8d4864119430985875f27f29bc68dd86797e0b0fa4db60fb4
kubeadm join 192.168.1.130:6443 --token oapcal.mlearjiaijljtyeq --discovery-token-ca-cert-hash sha256:8832ca46fa644aa8d4864119430985875f27f29bc68dd86797e0b0fa4db60fb4