Three CentOS 7.4 servers: kube1, kube2, kube3, configuration: 2 cores 16G
Turn off and disable the firewall:
systemctl stop firewalld
systemctl disable firewalld
Disable SELINUX:
setenforce 0
Create the /etc/sysctl.d/k8s.conf file and add the following content:
net.bridge.bridge-nf-call-ip6tables =1
net.bridge.bridge-nf-call-iptables =1
net.ipv4.ip_forward =1
Execute the following command to make the modification effective:
modprobe br_netfilter
sysctl -p /etc/sysctl.d/k8s.conf
# step 1:Install some necessary system tools
sudo yum install -y yum-utils device-mapper-persistent-data lvm2
# Step 2:Add software source information
sudo yum-config-manager --add-repo http://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo
# Step 3:Update and install Docker-CE
sudo yum makecache fast
sudo yum -y install docker-ce
# Step 4:Start Docker service
sudo service docker start
# Step 5:Set boot up
sudo systemctl enable docker
Configure Alibaba Cloud Image Accelerator:
mkdir -p /etc/docker
tee /etc/docker/daemon.json <<-'EOF'{"registry-mirrors":["https://obww7jh1.mirror.aliyuncs.com"]}
EOF
systemctl daemon-reload
systemctl restart docker
Mirror required for Pull (Master node kube1)
export image=pause-amd64:3.1
docker pull registry.cn-hangzhou.aliyuncs.com/anoy/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/anoy/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/anoy/${image}export image=kube-apiserver-amd64:v1.10.4
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}export image=kube-scheduler-amd64:v1.10.4
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}export image=kube-controller-manager-amd64:v1.10.4
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}export image=kube-proxy-amd64:v1.10.4
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}export image=k8s-dns-kube-dns-amd64:1.14.8
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}export image=k8s-dns-dnsmasq-nanny-amd64:1.14.8
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}export image=k8s-dns-sidecar-amd64:1.14.8
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}export image=etcd-amd64:3.1.12
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
Node node kube2 / kube3
export image=pause-amd64:3.1
docker pull registry.cn-hangzhou.aliyuncs.com/anoy/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/anoy/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/anoy/${image}export image=kube-proxy-amd64:v1.10.4
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
docker tag registry.cn-hangzhou.aliyuncs.com/google_containers/${image} k8s.gcr.io/${image}
docker rmi registry.cn-hangzhou.aliyuncs.com/google_containers/${image}
cat <<EOF >/etc/yum.repos.d/kubernetes.repo
[ kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64/
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF
yum install -y kubelet kubeadm kubectl
systemctl enable kubelet && systemctl start kubelet
Configure kubelet
After the installation is complete, we also need to configure the kubelet, because the configuration file generated by the kubelet installed by the yum source has the parameter --cgroup-driver changed to systemd, and docker's cgroup-driver is cgroupfs, the two must be the same, we can view it through the docker info command:
$ docker info | grep Cgroup
Cgroup Driver: cgroupfs
Modify the kubelet configuration file /etc/systemd/system/kubelet.service.d/10-kubeadm.conf, and change the KUBELET_CGROUP_ARGS parameter to cgroupfs:
Environment="KUBELET_CGROUP_ARGS=--cgroup-driver=cgroupfs"
There is another question about the swap partition. Kubernetes requires the system's Swap to be shut down since 1.8. If it is not shut down, the default configuration of kubelet will not start:
swapoff -a
After the modification is complete, reload our configuration file:
systemctl daemon-reload
1、 Initialize the Master node kube1
kubeadm init --pod-network-cidr=10.244.0.0/16--apiserver-advertise-address=172.17.58.201--kubernetes-version=v1.10.4
flannel, and the value is 10.244.0.0/16, ReferenceOutput log:
.....[ addons] Applied essential addon: kube-dns
[ addons] Applied essential addon: kube-proxy
Your Kubernetes master has initialized successfully!
To start using your cluster, you need to run the following as a regular user:
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
You should now deploy a pod network to the cluster.
Run "kubectl apply -f [podnetwork].yaml"with one of the options listed at:
https://kubernetes.io/docs/concepts/cluster-administration/addons/
You can now join any number of machines by running the following on each node
as root:
kubeadm join 172.17.58.201:6443--token 831rfg.dw0vyb1h3beab5as --discovery-token-ca-cert-hash sha256:623681fde5b2bf564a8631942f31797f9bef75f40b14a86ef75e1d31b43709f1
From the log, you can see that to use the cluster, you need to execute the following commands:
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
You also need to deploy a Pod Network to the cluster, here select flannel:
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/v0.10.0/Documentation/kube-flannel.yml
At this point, the Master node is initialized, check the cluster related information:
# View cluster information
$ kubectl cluster-info
Kubernetes master is running at https://172.17.58.201:6443
KubeDNS is running at https://172.17.58.201:6443/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy
To further debug and diagnose cluster problems, use 'kubectl cluster-info dump'.
# View node information
$ kubectl get nodes
NAME STATUS ROLES AGE VERSION
lab-backend1 Ready master 1m v1.10.4
# View Pods information
$ kubectl get pods --all-namespaces
NAMESPACE NAME READY STATUS RESTARTS AGE
kube-system etcd-lab-backend1 1/1 Running 0 2m
kube-system kube-apiserver-lab-backend1 1/1 Running 0 1m
kube-system kube-controller-manager-lab-backend1 1/1 Running 0 2m
kube-system kube-dns-86f4d74b45-zbnz6 3/3 Running 0 3m
kube-system kube-flannel-ds-n67zn 1/1 Running 0 1m
kube-system kube-proxy-qdmqq 1/1 Running 0 3m
kube-system kube-scheduler-lab-backend1 1/1 Running 0 2m
If there is a problem with the initialization process, use the following command to reset:
kubeadm reset
rm -rf /var/lib/cni/
rm -f $HOME/.kube/config
2、 Add Worker node
Method ① The information returned when using kubeadm init joins the cluster kube2 / kube3
kubeadm join 172.17.58.201:6443--token 831rfg.dw0vyb1h3beab5as --discovery-token-ca-cert-hash sha256:623681fde5b2bf564a8631942f31797f9bef75f40b14a86ef75e1d31b43709f1
Method ② Regenerate token kube1
kubeadm token generate
kubeadm token create <generated-token>--print-join-command --ttl=24h
Join the cluster kube2 / kube3
kubeadm join 172.17.58.201:6443--token 41ts3r.n2vw06xbniouo6u5 --discovery-token-ca-cert-hash sha256:f958e234e8554c2352127f356a7eb7dad422c10df9a749156df36e5972cba38b
Look again at the cluster node kube1
$ kubectl get nodes
NAME STATUS ROLES AGE VERSION
lab-backend1 Ready master 6m v1.10.4
lab-backend2 Ready <none> 56s v1.10.3
lab-backend3 Ready <none> 14s v1.10.3
At this point, the kubernetes cluster of 1 Master + 2 Worker has been created successfully.
Recommended Posts