It's our wits that make us men.

_集群安装

Posted on By eatMelon-Masses

layout: post title: “k8s集群安装问题收集” date: 2021-3-28 17:21:52 +0800 categories: k8s tag: k8s

如何更换master节点ip

更换master节点ip,node节点需要重新加入

master节点需进行如下操作

  1. /etc/hosts 修改新ip
  2. 删除/etc/kubernetes/文件夹下的所有文件、删除$HOME/.kube文件夹、删除/var/lib/etcd文件夹
rm -rf /etc/kubernetes/*
rm -rf ~/.kube/*
rm -rf /var/lib/etcd/*
  1. 重置 kubeadm reset

  1. 初始化 Kubeadm init …
kubeadm config print init-defaults > kubeadm-config.yaml 
# 修改模版 advertiseAddress 为你master ip 
kubeadm init --config=kubeadm-config.yaml --experimental-upload-certs | tee kubeadm-init.log
  1. 加入子节点 kubeadm join …
  2. 安装Flannel
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube- flannel.yml

master节点 apiServer地址为公网ip 同时需要dns解析,如何设置?

在初始化 kubeadm-config.yaml脚本中添加dns相关设置

apiVersion: kubeadm.k8s.io/v1beta2
bootstrapTokens:
- groups:
  - system:bootstrappers:kubeadm:default-node-token
  token: abcdef.0123456789abcdef
  ttl: 24h0m0s
  usages:
  - signing
  - authentication
kind: InitConfiguration
localAPIEndpoint:
  advertiseAddress: x.x.x.x
  bindPort: 6443
nodeRegistration:
  criSocket: /var/run/dockershim.sock
  name: k8s-master01
  taints:
  - effect: NoSchedule
    key: node-role.kubernetes.io/master
---
apiServer:
  timeoutForControlPlane: 4m0s
  certSANs: 
  - apiserver.dns #此处dns用来生产证书配置
controlPlaneEndpoint: apiserver.dns #此处为dns地址为apiserver负载均衡器地址
apiVersion: kubeadm.k8s.io/v1beta2
certificatesDir: /etc/kubernetes/pki
clusterName: kubernetes
controllerManager: {}
dns:
  type: CoreDNS
etcd:
  local:
    dataDir: /var/lib/etcd
imageRepository: k8s.gcr.io
kind: ClusterConfiguration
kubernetesVersion: v1.15.1
networking:
  dnsDomain: cluster.local
  podSubnet: "10.244.0.0/16"
  serviceSubnet: 10.96.0.0/12
scheduler: {}
---
apiVersion: kubeproxy.config.k8s.io/v1alpha1 
kind: KubeProxyConfiguration
featureGates:
SupportIPVSProxyMode: true
mode: ipvs

kubeadm join操作时,如果无法提前知道ca hash可以忽略

kubeadm join xxxx:6443 --token abcdef.0123456789abcdef     --discovery-token-unsafe-skip-ca-verification

kubeadm master节点token过期,使用如下命令重新生成(24小时过期)

kubeadm token create --print-join-command