以下均为root用户登录
-
安装docker
- 更新yum包到最新
yum update - 安装需要的软件包, yum-util 提供yum-config-manager功能,另外两个是devicemapper驱动依赖的
yum install -y yum-utils device-mapper-persistent-data lvm2 - 设置yum源
yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo - yum install docker-ce
- 启动并加入开机启动
systemctl start docker systemctl enable docker - 查看版本
docker version -
安装kubeadm
- 允许 iptables 检查桥接流量
cat <<EOF | sudo tee /etc/modules-load.d/k8s.conf br_netfilter EOF
cat <<EOF | sudo tee /etc/sysctl.d/k8s.conf net.bridge.bridge-nf-call-ip6tables = 1 net.bridge.bridge-nf-call-iptables = 1 EOF sudo sysctl --system 2. 安装 kubeadm、kubelet 和 kubectl cat <<EOF | sudo tee /etc/yum.repos.d/kubernetes.repo [kubernetes] name=Kubernetes baseurl=https://packages.cloud.google.com/yum/repos/kubernetes-el7-$basearch enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://packages.cloud.google.com/yum/doc/yum-key.gpg https://packages.cloud.google.com/yum/doc/rpm-package-key.gpg exclude=kubelet kubeadm kubectl EOF
出现连接超时的情况更换阿里源: cat > /etc/yum.repos.d/kubernetes.repo <<EOF [kubernetes] name=Kubernetes baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64 enabled=1 gpgcheck=0 repo_gpgcheck=0 EOF
将 SELinux 设置为 permissive 模式(相当于将其禁用)
sudo setenforce 0 sudo sed -i ‘s/^SELINUX=enforcing$/SELINUX=permissive/’ /etc/selinux/config
sudo yum install -y kubelet kubeadm kubectl --disableexcludes=kubernetes
sudo systemctl enable --now kubelet
3. 使用kubeadm初始化集群(本处集群使用公网连接)
kubeadm init --pod-network-cidr 172.16.0.0/16 --image-repository registry.cn-hangzhou.aliyuncs.com/google_containers --apiserver-advertise-address xxx.xx.xxx.xx # xxx.xx.xxx.xx为master机器的公网ip地址 4. 报错了:It seems like the kubelet isn’t running or healthy,kubelet没起来 通过journalctl -xeu kubelet看到报错: failed to run Kubelet: misconfiguration: kubelet cgroup driver: “systemd” is different from docker cgroup driver: “cgroupfs”" 这是由于docker的驱动和k8s的驱动不一致导致的 解决方式: 替换docker的cgroup为systemd vim /etc/docker/daemon.json,如果有此文件新增一行"exec-opts": [“native.cgroupdriver=systemd”],否则直接复制 { “exec-opts”: [“native.cgroupdriver=systemd”] } 5. 如果中途出现报错,修复之后需要先执行kubeadm reset,再重新执行3的命令 6. 继续向下走,出现了卡住的问题: [wait-control-plane] Waiting for the kubelet to boot up the control plane as static Pods from directory “/etc/kubernetes/manifests”. This can take up to 4m0s [kubelet-check] Initial timeout of 40s passed. 解决方式: 另开一个终端, 打开/etc/kubernetes/manifests/etcd.yaml 要关注的是"–listen-client-urls"和"–listen-peer-urls"。需要把–listen-client-urls 和 --listen-peer-urls 都改成127.0.0.1:2379和127.0.0.1:2380 执行systemctl restart kubelet 7. 稍等一会可以看到已经安装成功了 安装成功之后将kubeadm join … --token ***** --discovery-token-ca-cert-hash sha256:***** 记录下来,新节点加入需要用到 9. 安装网络插件(这里使用的flannel) kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml 10. 安装完成之后执行kubectl get pod -n kube-system查看安装状态,发现不能执行,报错: The connection to the server localhost:8080 was refused - did you specify the right host or port? 执行如下命令(非root用户): mkdir -p $HOME/.kube sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config sudo chown
(
i
d
?
u
)
:
(id -u):
(id?u):(id -g) $HOME/.kube/config 执行命令(root用户): export KUBECONFIG=/etc/kubernetes/admin.conf
node节点的安装与加入 1. 执行安装k8s集群master的第1步,第2步的(1,2)小步 2. 加入节点,执行master节点init之后得到的那个join语句 kubeadm join … --token ***** --discovery-token-ca-cert-hash sha256:***** 3. 如果想要node节点也能够执行kubectl命令,需要将master的/etc/kubernetes/admin.conf移到node节点上,同时配置环境变量,同master
k8s官方安装文档
|