一、新增加Worker Node
### --- 拷贝已部署好的Node相关文件到新节点
~~~ 在master节点将Worker Node涉及文件拷贝到新节点10.10.10.12/13
[root@k8s-master ~]# scp -r /opt/kubernetes root@10.10.10.12:/opt/
[root@k8s-master ~]# scp -r /usr/lib/systemd/system/{kubelet,kube-proxy}.service root@10.10.10.12:/usr/lib/systemd/system
[root@k8s-master ~]# scp -r /opt/cni/ root@10.10.10.12:/opt/
[root@k8s-master ~]# scp /opt/kubernetes/ssl/ca.pem root@10.10.10.12:/opt/kubernetes/ssl
[root@k8s-master ~]# scp -r /opt/kubernetes root@10.10.10.13:/opt/
[root@k8s-master ~]# scp -r /usr/lib/systemd/system/{kubelet,kube-proxy}.service root@10.10.10.13:/usr/lib/systemd/system
[root@k8s-master ~]# scp -r /opt/cni/ root@10.10.10.13:/opt/
[root@k8s-master ~]# scp /opt/kubernetes/ssl/ca.pem root@10.10.10.13:/opt/kubernetes/ssl
### --- 删除kubelet证书和kubeconfig文件
~~~ 注:这几个文件是证书申请审批后自动生成的,每个Node不同,必须删除重新生成
[root@k8s-node1 ~]# rm -rf /opt/kubernetes/cfg/kubelet.kubeconfig
[root@k8s-node1 ~]# rm -f /opt/kubernetes/ssl/kubelet*
[root@k8s-node2 ~]# rm -rf /opt/kubernetes/cfg/kubelet.kubeconfig
[root@k8s-node2 ~]# rm -f /opt/kubernetes/ssl/kubelet*
### --- 修改主机名
[root@k8s-node1 ~]# vi /opt/kubernetes/cfg/kubelet.conf
--hostname-override=k8s-node1
[root@k8s-node1 ~]# vi /opt/kubernetes/cfg/kube-proxy-config.yml
hostnameOverride: k8s-node1
### --- 启动并设置开机启动
[root@k8s-node1 ~]# systemctl daemon-reload
[root@k8s-node1 ~]# systemctl start kubelet
[root@k8s-node1 ~]# systemctl enable kubelet
[root@k8s-node1 ~]# systemctl start kube-proxy
[root@k8s-node1 ~]# systemctl enable kube-proxy
### --- 在Master上批准新Node kubelet证书申请
[root@k8s-master ~]# kubectl get csr
NAME AGE SIGNERNAME REQUESTOR CONDITION
node-csr-4zTjsaVSrhuyhIGqsefxzVoZDCNKei-aE2jyTP81Uro 89s
kubernetes.io/kube-apiserver-client-kubelet kubelet-bootstrap Pending
[root@k8s-master ~]# kubectl certificate approve node-csr-4zTjsaVSrhuyhIGqsefxzVoZDCNKei-aE2jyTP81Uro
### --- 查看Node状态
~~~ Node2(10.10.10.13)节点同上,记得修改主机名:
[root@k8s-master ~]# kubectl get node
附录一:kubeadm和二进制部署总结