環境準備
在VMWare 中安裝Centos7做爲master 節點
Master 節點操作
關閉圖形界面
systemctl set-default multi-user.target
配置yum源
wget -O /etc/yum.repos.d/CentOS-Base.repo http://mirrors.aliyun.com/repo/Centos-7.repo
yum makecache
關閉防火牆
systemctl stop firewalld & systemctl disable firewalld
關閉Swap
swapoff -a && sed -i '/ swap / s/^/#/' /etc/fstab
SELINUX
setenforce 0 && sed -i 's/^SELINUX=enforcing$/SELINUX=permissive/' /etc/selinux/config
安裝Docker
yum-config-manager --add-repo http://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo
yum makecache
yum install docker-ce -y
systemctl start docker & systemctl enable docker
安裝k8s 組件
cat <<EOF > /etc/yum.repos.d/kubernetes.repo
[kubernetes]
name=Kubernetes
baseurl=http://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64
enabled=1
gpgcheck=0
repo_gpgcheck=0
gpgkey=http://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg
http://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF
yum install -y kubelet kubeadm kubectl --disableexcludes=kubernetes
systemctl enable --now kubelet
設置 ensure net.bridge.bridge-nf-call-iptables
cat <<EOF > /etc/sysctl.d/k8s.conf
net.bridge.bridge-nf-call-ip6tables = 1
net.bridge.bridge-nf-call-iptables = 1
EOF
sysctl --system
配置kubelet使用的cgroup驅動程序
確保docker 的cgroup drive 和kubelet的cgroup drive一樣:systemd
添加 /etc/docker/daemon.json 內容爲
{
"exec-opts":["native.cgroupdriver=systemd"]
}
/etc/sysconfig/kubelet
KUBELET_EXTRA_ARGS=--cgroup-driver=systemd
systemctl daemon-reload
systemctl enable kubelet && systemctl restart kubelet
安裝k8s docker鏡像
參考https://github.com/xuxinkun/littleTools#azk8spull 國內安裝k8s 鏡像
k8s.gcr.io/kube-apiserver:v1.17.3
k8s.gcr.io/kube-controller-manager:v1.17.3
k8s.gcr.io/kube-scheduler:v1.17.3
k8s.gcr.io/kube-proxy:v1.17.3
k8s.gcr.io/pause:3.1
k8s.gcr.io/etcd:3.4.3-0
k8s.gcr.io/coredns:1.6.5
./azk8spull k8s.gcr.io/kube-apiserver:v1.17.3
......
克隆master 節點
克隆後修改主機名字
hostnamectl set-hostname k8s-work1
hostnamectl set-hostname k8s-work2
hostnamectl set-hostname k8s-work3
創建集羣
在master 上運行一下命令
kubeadm init --pod-network-cidr=192.168.0.0/16 --kubernetes-version=v1.17.3 --apiserver-advertise-address=192.168.119.128 --image-repository registry.aliyuncs.com/google_containers --control-plane-endpoint=192.168.119.128:6443
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
安裝pod 網絡
wget https://docs.projectcalico.org/v3.11/manifests/calico.yaml
kubectl apply -f calico.yaml
運行命令
kubectl get pod -n kube-system
所有status 爲running 則正常
把其他節點加入集羣
運行一下命令在其他兩個節點k8s-work2和k8s-work3上
kubeadm join 192.168.119.128:6443 --token s0gn88.prqj9fkxazzc0r83 \
--discovery-token-ca-cert-hash sha256:bb6909d8b52a288a186014f0a88e3b51765394e2d715a9d58fb9a5bc016731ef
在master上查看結果
kubectl get nodes
- 注意:在node節點刪除是無法重新jion 需要運行
kubeadm reset