k8s集群安装
<p>关于kubernetes组件的详解介绍,请阅读上一篇文章《k8s入门系列之介绍篇》</p>
<p>Kubernetes集群安装部署</p>
<p><strong>•Kubernetes集群组件:</strong>
- etcd 一个高可用的K/V键值对存储和服务发现系统
- flannel 实现夸主机的容器网络的通信
- kube-apiserver 提供kubernetes集群的API调用
- kube-controller-manager 确保集群服务
- kube-scheduler 调度容器,分配到Node
- kubelet 在Node节点上按照配置文件中定义的容器规格启动容器
- kube-proxy 提供网络代理服务</p>
<p><strong>•集群示意图</strong>
Kubernetes工作模式server-client,Kubenetes Master提供集中化管理Minions。部署1台Kubernetes Master节点和4台Minion节点,
示意图如下:
<img src="https://www.showdoc.cc/server/api/common/visitfile/sign/53858ff2568dee90cf655113cfff7f03?showdoc=.jpg" alt="" /></p>
<p><strong>•先决条件</strong></p>
<p>如下操作在所有机器执行</p>
<p>1.确保系统已经安装epel-release源</p>
<pre><code>yum -y install epel-release</code></pre>
<p>2.关闭防火墙服务和selinx,避免与docker容器的防火墙规则冲突。</p>
<pre><code>systemctl stop firewalld
systemctl disable firewalld
setenforce 0 </code></pre>
<p><strong>•安装配置Kubernetes Master</strong>
如下操作在master上执行
1.使用yum安装etcd,docker,flannel和kubernetes-master</p>
<pre><code>yum -y install etcd kubernetes-master flannel docker</code></pre>
<p>2.编辑/etc/etcd/etcd.conf文件</p>
<pre><code>ETCD_NAME=default
ETCD_DATA_DIR="/var/lib/etcd/default.etcd"
ETCD_LISTEN_CLIENT_URLS="http://0.0.0.0:2379"
ETCD_ADVERTISE_CLIENT_URLS="http://localhost:2379"</code></pre>
<p>3.编辑/etc/kubernetes/apiserver文件</p>
<pre><code>KUBE_API_ADDRESS="--insecure-bind-address=0.0.0.0"
KUBE_API_PORT="--port=8080"
KUBELET_PORT="--kubelet-port=10250"
KUBE_ETCD_SERVERS="--etcd-servers=http://127.0.0.1:2379"
KUBE_SERVICE_ADDRESSES="--service-cluster-ip-range=10.254.0.0/16"
KUBE_ADMISSION_CONTROL="--admission-control=NamespaceLifecycle,NamespaceExists,LimitRanger,SecurityContextDeny,ResourceQuota"
KUBE_API_ARGS=""</code></pre>
<p>4、防火墙放行</p>
<pre><code>vim /usr/lib/systemd/system/docker.service</code></pre>
<p>修改ExecStartPost行为下面内容</p>
<pre><code>ExecStartPost=/sbin/iptables -I FORWARD -s 0.0.0.0/0 -j ACCEPT</code></pre>
<p>5.在etcd中定义flannel网络</p>
<pre><code> etcdctl mk /atomic.io/network/config '{"Network":"172.17.0.0/16"}'</code></pre>
<p>6.为flannel网络指定etcd服务,修改/etc/sysconfig/flanneld文件</p>
<pre><code>FLANNEL_ETCD="http://192.168.30.20:2379"
FLANNEL_ETCD_KEY="/atomic.io/network" </code></pre>
<p>7.启动etcd、kube-apiserver、kube-controller-manager、kube-scheduler等服务,并设置开机启动。</p>
<pre><code>for SERVICES in etcd kube-apiserver kube-controller-manager kube-scheduler;
do systemctl restart $SERVICES;systemctl enable $SERVICES;systemctl status $SERVICES ; done</code></pre>
<p><strong>•安装配置Kubernetes Node</strong>
如下操作在node1、node2、node3、node4上执行
1.使用yum安装flannel和kubernetes-node</p>
<pre><code>yum -y install flannel kubernetes-node docker</code></pre>
<p>2.为flannel网络指定etcd服务,修改/etc/sysconfig/flanneld文件</p>
<pre><code>FLANNEL_ETCD="http://192.168.30.20:2379"
FLANNEL_ETCD_KEY="/atomic.io/network"</code></pre>
<p>3.修改/etc/kubernetes/config文件</p>
<pre><code>KUBE_LOGTOSTDERR="--logtostderr=true"
KUBE_LOG_LEVEL="--v=0"
KUBE_ALLOW_PRIV="--allow-privileged=false"
KUBE_MASTER="--master=http://192.168.30.20:8080"</code></pre>
<p>4、防火墙放行</p>
<pre><code>vim /usr/lib/systemd/system/docker.service</code></pre>
<p>修改ExecStartPost行为下面内容</p>
<pre><code>ExecStartPost=/sbin/iptables -I FORWARD -s 0.0.0.0/0 -j ACCEPT</code></pre>
<p>5.按照如下内容修改对应node的配置文件/etc/kubernetes/kubelet</p>
<p>node1:</p>
<pre><code>KUBELET_ADDRESS="--address=0.0.0.0"
KUBELET_PORT="--port=10250"
KUBELET_HOSTNAME="--hostname-override=192.168.30.21" #修改成对应Node的IP
KUBELET_API_SERVER="--api-servers=http://192.168.30.20:8080" #指定Master节点的API Server
KUBELET_POD_INFRA_CONTAINER="--pod-infra-container-image=registry.access.redhat.com/rhel7/pod-infrastructure:latest"
KUBELET_ARGS=""</code></pre>
<p>node2:</p>
<pre><code>KUBELET_ADDRESS="--address=0.0.0.0"
KUBELET_PORT="--port=10250"
KUBELET_HOSTNAME="--hostname-override=192.168.30.22"
KUBELET_API_SERVER="--api-servers=http://192.168.30.20:8080"
KUBELET_POD_INFRA_CONTAINER="--pod-infra-container-image=registry.access.redhat.com/rhel7/pod-infrastructure:latest"
KUBELET_ARGS=""</code></pre>
<p>node3:</p>
<pre><code>KUBELET_ADDRESS="--address=0.0.0.0"
KUBELET_PORT="--port=10250"
KUBELET_HOSTNAME="--hostname-override=192.168.30.23"
KUBELET_API_SERVER="--api-servers=http://192.168.30.20:8080"
KUBELET_POD_INFRA_CONTAINER="--pod-infra-container-image=registry.access.redhat.com/rhel7/pod-infrastructure:latest"
KUBELET_ARGS=""</code></pre>
<p>node4:</p>
<pre><code>KUBELET_ADDRESS="--address=0.0.0.0"
KUBELET_PORT="--port=10250"
KUBELET_HOSTNAME="--hostname-override=192.168.30.24"
KUBELET_API_SERVER="--api-servers=http://192.168.30.20:8080"
KUBELET_POD_INFRA_CONTAINER="--pod-infra-container-image=registry.access.redhat.com/rhel7/pod-infrastructure:latest"
KUBELET_ARGS=""</code></pre>
<p>6.在所有Node节点上启动kube-proxy,kubelet,docker,flanneld等服务,并设置开机启动。</p>
<pre><code>for SERVICES in kube-proxy kubelet docker flanneld;
do systemctl restart $SERVICES;systemctl enable $SERVICES;systemctl status $SERVICES; done</code></pre>
<p><strong>•验证集群是否安装成功</strong>
在master上执行如下命令</p>
<pre><code>kubectl get node
NAME STATUS AGE
192.168.30.21 Ready 1m
192.168.30.22 Ready 1m
192.168.30.23 Ready 1m
192.168.30.24 Ready 1m</code></pre>