环境准备
卸载podman,可能与docker冲突sudo yum remove podman
关闭交换分区:sudo swapoff -a
,sudo sed -i 's/.*swap.*/#&/' /etc/fstab
禁用selinux:setenforce 0
,sed -i "s/^SELINUX=enforcing/SELINUX=disabled/g" /etc/selinux/config
关闭防火墙:sudo systemctl stop firewalld.service
,sudo systemctl disable firewalld.service
k8s安装
配置系统基本安装源
sudo curl -o /etc/yum.repos.d/CentOS-Base.repo curl -o /etc/yum.repos.d/CentOS-Base.repo https://mirrors.aliyun.com/repo/Centos-vault-8.5.2111.repo
安装k8s安装源
vim /etc/yum.repos.d/kubernetes.repo
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64/
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
安装docker加速
mkdir -p /etc/docker
vim /etc/docker/daemon.json
{
"registry-mirrors":["https://mj9kvemk.mirror.aliyuncs.com"]
}
安装kubectl,kubelet,kubeadm
kubeadm version
kubectl version --client
kubelet --version
修改docker,默认驱动是system,修改为systemd
vim /etc/docker/daemon.json
{
"exec-opts":["native.cgroupdriver=systemd"]
}
systemctl daemon-reload
systemctl restart docker
初始化kubernetes集群
kubeadm init --apiserver-advertise-address=0.0.0.0 \
--apiserver-cert-extra-sans=127.0.0.1 \
--image-repository=registry.aliyuncs.com/google_containers \
--ignore-preflight-errors=all \
--kubernetes-version=v1.22.0 \
--service-cidr=10.10.0.0/16 \
--pod-network-cidr=10.18.0.0/16
部署
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
获取节点信息
kubectl get node
kubectl get pod --all-namespaces
安装calico网络
kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml
安装kubernetes-dashboard,也就是web控制面板
下载recommended.yaml
wget https://raw.githubusercontent.com/kubernetes/dashboard/master/aio/deploy/recommended/yaml
注意:在文件中搜索k8s-app:kubernetes-dashboard,修改当前节点的信息
# 修改文件
vim recommended.yaml
kind: Service
apiVersion: v1
metadata:
labels:
k8s-app: kubernetes-dashboard
name: kubernetes-dashboard
namespace: kubernetes-dashboard
spec:
type: NodePort #添加这行
ports:
- port: 443
targetPort: 8443
nodePort: 30000 #添加这行
selector:
k8s-app: kubernetes-dashboard
创建pod:
kubectl create -f recommended.yaml
kubectl get svc -n kubenetes-dashboard
查看是否正确启动kubenetes-dashboard:kubectl get pod --all-namespaces
如果kubenetes-dashboard的status一直在creating container或者其他状态,运行下面的命令查看当前pod的日志:
kubectl describe pod dashboard-metrics-scraper-c45b7869d-2dhc4 -namespace=kubernetes-dashboard
运行命令删除:
kubectl delete -f recommended.yaml
使用docker拉去镜像
docker pull kubernetesui/metrics-scraper:v1.0.7
使用web管理
获取token
# 创建token
kubectl create sa dashboard-admin -n kube-system
# 授权Token访问权限
kubectl create clusterrolebinding dashboard-admin --clusterrole=cluster-admin --serviceaccount=kube-system:dashboard-admin
# 获取token
ADMIN_SECRET=$(kubectl get secrets -n kube-system | grep dashboard-admin | awk '{print $1}')
DASHBOARD_LOGIN_TOKEN=$(kubectl describe secret -n kube-system ${ADMIN_SECRET} | grep -E '^token' | awk '{print $2}')
echo ${DASHBOARD_LOGIN_TOKEN}
https://ip:30000/#/login 使用上面的token登录
使用config登录
vim /root/.kube/config
将上面生成的token放到文件最后一行,token前面需要和上面的client代码缩进,token后面有一个空格
允许master节点参与pod调度
kubectl taint nodes --all node-role.kubernetes.io/master-
参考: https://blog.csdn.net/qq_26897321/article/details/124127198