kubernetes学习笔记2

Posted

tags:

篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了kubernetes学习笔记2相关的知识,希望对你有一定的参考价值。


安装部署

ansible的role;

kubeadm,把所有组件能运行为容器的都运行为容器,仅kubelet需单独装在主机上,镜像托管在jcr上不能直接访问;

minikube,适合开发,在1个节点上运行;


kubernetes学习笔记2_k8s


节点网络172.20.0.0/16

pod网络10.244.0.0/16,flannel默认的;

service网络10.96.0.0/12


方式1,繁琐:

master上,api server|etcd|controller-manager|scheduler,可用yum或编译,在节点上安装,通过systemctl启动;

node上,kube-proxy|kubelet|docker,用yum或二进制包,在节点级启动;

这种方式缺点,守护进程如果宕了,还得手动启动;


方式2:

官方的kubeadm集群管理部署工具;

每一个节点,包括master,都要运行docker|kubelet|kubeadm并启动;

将一个节点初始化为master(上的etcd|controller-manager|scheduler|api-server都运行为pod容器),kubeadm init;

其它节点初始化为node(上的把kube-proxy运行为pod),kubeadm join;

自此,master上的api-server|etcd|controller-manager|scheduler和node上的kube-proxy均为static pod;

在master和node上再部flannel,这是k8s之上托管的,是k8s的附件,是动态pod;


/etc/hosts;

各节点间时间同步;

iptables或firewall服务禁用;


v1.11.1 #kubernetes

docker-ce #18.06.0.ce-3.el7


cd /etc/yum.repos.d/

wget ​https://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo​

vim kubernetes.repo

[kubernetes]

name=Kubernetes Repo

baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64/

enabled=1

gpgcheck=0

gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg #可以下载rpm-package-key.gpg,rpm --import rpm-package-key.gpg


注:阿里云上kubernetes帮助

cat <<EOF > /etc/yum.repos.d/kubernetes.repo

[kubernetes]

name=Kubernetes

baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64/

enabled=1

gpgcheck=1

repo_gpgcheck=1

gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg

EOF


yum repolist

yum install docker-ce kubelet kubeadm kubectl #kubectl为api server的命令行工具,node节点可以不安装


vim /usr/lib/systemd/system/docker.service

[Service]

Type=notify

#Envirnotallow="HTTPS_PROXY=http://www.ik8s.io:10080" #经测此地址失效,使用阿里云加速器

Envirnotallow="NO_PROXY=127.0.0.0/8,172.20.0.0/16"

systemctl daemon-reload

systemctl start docker

docker info


用阿里云加速器下载7个镜像,并改标签方便kubeadm使用

vim /etc/docker/daemon.json

"registry-mirrors": ["https://czekxvyt.mirror.aliyuncs.com"]

docker login --username=chaizaowen@163.com registry.cn-hangzhou.aliyuncs.com

docker pull mirrorgooglecontainers/kube-apiserver:v1.15.0

docker pull mirrorgooglecontainers/kube-controller-manager:v1.15.0

docker pull mirrorgooglecontainers/kube-scheduler:v1.15.0

docker pull mirrorgooglecontainers/kube-proxy:v1.15.0

docker pull mirrorgooglecontainers/pause:3.1

docker pull mirrorgooglecontainers/etcd:3.3.10

docker pull coredns/coredns:1.3.1

docker tag mirrorgooglecontainers/kube-apiserver:v1.15.0 k8s.gcr.io/kube-apiserver:v1.15.0

docker tag mirrorgooglecontainers/kube-controller-manager:v1.15.0 k8s.gcr.io/kube-controller-manager:v1.15.0

docker tag mirrorgooglecontainers/kube-scheduler:v1.15.0 k8s.gcr.io/kube-scheduler:v1.15.0

docker tag mirrorgooglecontainers/kube-proxy:v1.15.0 k8s.gcr.io/kube-proxy:v1.15.0

docker tag mirrorgooglecontainers/pause:3.1 k8s.gcr.io/pause:3.1

docker tag mirrorgooglecontainers/etcd:3.3.10 k8s.gcr.io/etcd:3.3.10

docker tag coredns/coredns:1.3.1 k8s.gcr.io/coredns:1.3.1


docker image ls


cat /proc/sys/net/bridge/bridge-nf-call-iptables #默认1

cat /proc/sys/net/bridge/bridge-nf-call-ip6tables #1

注:

vim /etc/sysctl.conf

net.bridge.bridge-nf-call-ip6tables = 1

net.bridge.bridge-nf-call-iptables = 1

sysctl -p


rpm -ql kubelet

cat /etc/sysconfig/kubelet #早期版本不允许开启swap,在KUBELET_EXTRA_ARGS="--fail-swap-notallow=false"上设置可忽略

systemctl enable kubelet #先设开机自启,配置还没完成不能启动

systemctl enable docker


kubeadm init --help

kubeadm config images pull #网速慢可以先拉镜像

kubeadm init --kubernetes-versinotallow=v1.11.1 --pod-network-cidr=10.244.0.0/16 --service-cidr=10.96.0.0/12 --ignore-preflight-errors=Swap #api server默认监听0.0.0.0:6443,可省;DNS在k8s上已进化到第3版,skyDNS-->kubeDNS-->CoreDNS,1.11版使用CoreDNS支持更多高级功能;1.11版用的kube-proxy是ipvs(指定使用ipvs,--feature-gates=SupportIPVSProxyMode=true),而之前版本是iptables

ss -tnl #6443port为apiserver


kubeadm init --kubernetes-versinotallow=v1.15.0 --pod-network-cidr=10.244.0.0/16 --service-cidr=10.96.0.0/12 --ignore-preflight-errors=Swap

注,init完成后,记录此段信息:

kubeadm join 10.10.104.31:6443 --token smdywe.i8o6udmhpo5ally7 \\

--discovery-token-ca-cert-hash sha256:24affe4059fb63716de88869702e3b1c3d9ffa2fb1a913fe05e2462124cd0943


mkdir -p $HOME/.kube

cp -i /etc/kubernetes/admin.conf $HOME/.kube/config #有证书等信息

chown `id -u`:`id -g` $HOME/.kube/config

kubectl get cs #或用componentstatus

kubectl get nodes #NotReady,待部署flannel

kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml #https://github.com/coreos/flannel找到Deploying flannel manually

kubectl get pods -n kube-system #要看到flannel正常运行才算部署成功

docker image ls #要有flannel镜像

kubectl get ns #namespace,default|kube-public|kube-system

kubectl get nodes

kubectl get pods -n kube-system -o wide #kube-proxy和kube-flannel启动了2个,master上和node01上




node上操作:

yum -y install docker-ce kubelet kubeadm #node上执行


/etc/docker/daemon.json #从master上拷贝

/usr/lib/systemd/system/docker.service

/etc/sysconfig/kubelet


systemctl start docker

systemctl enable docker kubelet

systemctl daemon-reload #更改了systemd的启动脚本要加载

echo 1 > /proc/sys/net/bridge/bridge-nf-call-iptables

echo 1 > /proc/sys/net/bridge/bridge-nf-call-ip6tables


docker info

kubeadm join 172.20.0.70:6443 --token vbja9f.egyl0av --discovery-token-ca-cert-hash sha256:f187f4784 --ignore-preflight-errors=Swap #在node节点中执行,此段命令是master上init后的提示,要单独保存,方便之后node加入master

docker image ls


注,实际操作要加--ignore-preflight-errors=Swap:

kubeadm join 10.10.104.31:6443 --token smdywe.i8o6udmhpo5ally7 --discovery-token-ca-cert-hash sha256:24affe4059fb63716de88869702e3b1c3d9ffa2fb1a913fe05e2462124cd0943 --ignore-preflight-errors=Swap


注:

node上addon,kube-proxy|CoreDNS|flannel,另ingress controller,监控的prometheus|heapster;


以上是关于kubernetes学习笔记2的主要内容,如果未能解决你的问题,请参考以下文章

云原生技术之kubernetes学习笔记

Kubernetes(k8s) 笔记总结

Kubernetes(k8s) 笔记总结

kubernetes学习笔记3资源清单

kubernetes(K8S) 容器管理“扫盲“ 学习笔记

Kubernetes(k8s) 笔记总结