持久化存储-NFS
NFS配置
安装NFS
yum install nfs-utils -y
配置NFS
cat > /etc/exports << EOF
/data/NFS/ifs *(rw,sync,no_root_squash)
EOF
启动NFS
systemctl start nfs
挂载验证
# 列出NFS共享目录
showmount -e 192.168.104.200
Export list for 192.168.104.200:
/data/NFS/ifs *
# 挂载共享目录
mount -t nfs 192.168.104.200:/data/NFS/ifs /mnt/ifs/
挂载节点也需要安装nfs-utils
创建动态PV
nfs-client插件部署,插件地址:
https://github.com/kubernetes-retired/external-storage/tree/master/nfs-client/deploy
下载deploy下的class.yaml deployment.yaml rbac.yaml
- 修改deployment.yaml的image地址为lizhenliang/nfs-client-provisioner:latest
- 修改NFS地址和共享路径
查看
kubectl get sc
NAME PROVISIONER RECLAIMPOLICY VOLUMEBINDINGMODE ALLOWVOLUMEEXPANSION AGE
managed-nfs-storage fuseim.pri/ifs Delete Immediate false 16m
YAML配置文件
RBAC配置
rbac.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: jenkins-sa
namespace: kube-devops
---
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: ClusterRole
metadata:
name: jenkins-cr
rules:
- apiGroups: ["extensions", "apps"]
resources: ["deployments"]
verbs: ["create", "delete", "get", "list", "watch", "patch", "update"]
- apiGroups: [""]
resources: ["services"]
verbs: ["create", "delete", "get", "list", "watch", "patch", "update"]
- apiGroups: [""]
resources: ["pods"]
verbs: ["create","delete","get","list","patch","update","watch"]
- apiGroups: [""]
resources: ["pods/exec"]
verbs: ["create","delete","get","list","patch","update","watch"]
- apiGroups: [""]
resources: ["pods/log"]
verbs: ["get","list","watch"]
- apiGroups: [""]
resources: ["secrets"]
verbs: ["get"]
---
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: ClusterRoleBinding
metadata:
name: jenkins-crd
roleRef:
kind: ClusterRole
name: jenkins-cr
apiGroup: rbac.authorization.k8s.io
subjects:
- kind: ServiceAccount
name: jenkins-sa
namespace: kube-devops
Deployment配置
deployment.yaml
apiVersion: v1
kind: Namespace
metadata:
name: kube-devops
---
apiVersion: apps/v1
kind: Deployment
metadata:
labels:
app: jenkins
name: jenkins
namespace: kube-devops
spec:
replicas: 1
selector:
matchLabels:
app: jenkins
template:
metadata:
labels:
app: jenkins
spec:
terminationGracePeriodSeconds: 10
serviceAccount: jenkins-sa
containers:
- name: jenkins
image: jenkins/jenkins:lts
imagePullPolicy: IfNotPresent
env:
- name: JAVA_OPTS
value: -XshowSettings:vm -Dhudson.slaves.NodeProvisioner.initialDelay=0 -Dhudson.slaves.NodeProvisioner.MARGIN=50 -Dhudson.slaves.NodeProvisioner.MARGIN0=0.85 -Duser.timezone=Asia/Shanghai
ports:
- containerPort: 8080
name: web
protocol: TCP
- containerPort: 50000
name: agent
protocol: TCP
resources:
limits:
cpu: 4000m
memory: 16Gi
requests:
cpu: 1000m
memory: 4096Mi
# 等容器全部启动正常才开启健康检查,避免由于配置低气动慢造成的循环重启
# livenessProbe:
# httpGet:
# path: /login
# port: 8080
# initialDelaySeconds: 60
# timeoutSeconds: 5
# failureThreshold: 12
# readinessProbe:
# httpGet:
# path: /login
# port: 8080
# initialDelaySeconds: 60
# timeoutSeconds: 5
# failureThreshold: 12
#
volumeMounts:
- name: jenkins-data
mountPath: /var/jenkins_home
securityContext:
fsGroup: 1000
volumes:
- name: jenkins-data
persistentVolumeClaim:
claimName: pvc-jenkins
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: pvc-jenkins
namespace: kube-devops
spec:
storageClassName: managed-nfs-storage
accessModes:
- ReadWriteMany
resources:
requests:
storage: 10Gi
Service配置
service.yaml
apiVersion: v1
kind: Service
metadata:
name: jenkins-service
namespace: kube-devops
labels:
app: jenkins
spec:
selector:
app: jenkins
type: NodePort
ports:
- name: web
port: 8080
targetPort: web
nodePort: 30005
- name: agent
port: 50000
targetPort: agent
Ingress配置
ingress部署参考
https://blog.csdn.net/wangshui898/article/details/110292504
ingress.yaml
apiVersion: networking.k8s.io/v1beta1
kind: Ingress
metadata:
name: ingress-jenkins
namespace: kube-devops
spec:
rules:
- host: jenkins.abc.com
http:
paths:
- path: /
backend:
serviceName: jenkins-service
servicePort: 8080
部署
kubectl apply -f .
绑定hosts
将域名绑定到部署ingress的节点
通过域名访问登录即可