这套配置版本比较新,在k8s.1.25.2中,多了一个cri-dockerd,这货不安装跑不起来
具体执行的linux命令还有这个的安装包集成了一个简单的包,里面没做有兴趣的可以去看看,也可以直接拿来用,但是不包好,仅供参考
https://gitee.com/www.topwhere.cn/centos8.2-k8s-init
2vCPUs | 4 GiB | s3.large.2 CentOS8.2 64位的机器
首先,购置了3台服务器
59.36.165.83(192.168.1.73) master
59.36.140.180(192.168.1.152) work1
59.36.83.118(192.168.1.245) work2
选择了三台
2vCPUs | 4 GiB | s3.large.2 CentOS8.2 64位的机器
hostnamectl set-hostname k8s-master
hostnamectl set-hostname k8s-node1
hostnamectl set-hostname k8s-node2
cat >> /etc/hosts << EOF
192.168.1.73 k8s-master
192.168.1.152 k8s-node1
192.168.1.245 k8s-node2
EOF
bash
yum update -y
sed -i 's/mirrorlist/#mirrorlist/g' /etc/yum.repos.d/CentOS-*
sed -i 's|#baseurl=http://mirror.centos.org|baseurl=http://vault.centos.org|g' /etc/yum.repos.d/CentOS-*
yum update -y
yum -y install vim
yum -y install chrony
systemctl start chronyd && systemctl enable chronyd
date
service firewalld stop && systemctl disable firewalld
#临时关闭selinux,永久关闭请修改/etc/selinux/config配置文件
setenforce 0
# 临时关闭
swapoff -a
# getenforce查看状态
#永久关闭
sed -i '/ swap / s/^\(.*\)$/#\1/g' /etc/fstab
modprobe br_netfilter
cat < /etc/sysctl.d/k8s.conf
net.ipv4.ip_forward = 1
net.bridge.bridge-nf-call-ip6tables = 1
net.bridge.bridge-nf-call-iptables = 1
EOF
cat > /etc/sysconfig/modules/ipvs.modules << EOF
#!/bin/sh
modprobe -- ip_vs
modprobe -- ip_vs_rr
modprobe -- ip_vs_wrr
modprobe -- ip_vs_sh
modprobe -- nf_conntrack_ipv4
EOF
sysctl -p /etc/sysctl.d/k8s.conf
chmod 755 /etc/sysconfig/modules/ipvs.modules && bash /etc/sysconfig/modules/ipvs.modules && lsmod | grep -e ip_vs -e nf_conntrack_ipv4
yum install -y yum-utils device-mapper-persistent-data lvm2
yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo
yum-config-manager --add-repo http://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo
yum -y install docker-ce docker-ce-cli containerd.io docker-compose-plugin --allowerasing
containerd config default > /etc/containerd/config.toml
systemctl restart containerd && systemctl enable containerd
#启动 / #设置开机启动
systemctl start docker && systemctl enable docker.service
cat < /etc/docker/daemon.json
{
"registry-mirrors": ["https://y0753cg2.mirror.aliyuncs.com"],
"exec-opts": ["native.cgroupdriver=systemd"]
}
EOF
systemctl restart docker
cat < /etc/yum.repos.d/kubernetes.repo
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64/
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF
yum -y install kubectl kubelet kubeadm
systemctl enable kubelet
cd /home
git clone https://gitee.com/www.topwhere.cn/centos8.2-k8s-init.git
cd centos8.2-k8s-init/
chomd -R 777 ./*
cp cri-dockerd /usr/bin/
cat < /usr/lib/systemd/system/cri-docker.service
[Unit]
Description=CRI Interface for Docker Application Container Engine
Documentation=https://docs.mirantis.com
After=network-online.target firewalld.service docker.service
Wants=network-online.target
Requires=cri-docker.socket
[Service]
Type=notify
ExecStart=/usr/bin/cri-dockerd --network-plugin=cni --pod-infra-container-image=registry.aliyuncs.com/google_containers/pause:3.8
ExecReload=/bin/kill -s HUP $MAINPID
TimeoutSec=0
RestartSec=2
Restart=always
StartLimitBurst=3
StartLimitInterval=60s
LimitNOFILE=infinity
LimitNPROC=infinity
LimitCORE=infinity
TasksMax=infinity
Delegate=yes
KillMode=process
[Install]
WantedBy=multi-user.target
EOF
cat < /usr/lib/systemd/system/cri-docker.socket
[Unit]
Description=CRI Docker Socket for the API
PartOf=cri-docker.service
[Socket]
ListenStream=%t/cri-dockerd.sock
SocketMode=0660
SocketUser=root
SocketGroup=docker
[Install]
WantedBy=sockets.target
EOF
systemctl daemon-reload ; systemctl enable cri-docker --now
kubeadm init \
--control-plane-endpoint="k8s-master" \
--apiserver-advertise-address=192.168.1.73 \
--image-repository registry.aliyuncs.com/google_containers \
--kubernetes-version v1.25.2 \
--service-cidr=10.1.0.0/16 \
--pod-network-cidr=10.244.0.0/16 \
--cri-socket=unix:///var/run/cri-dockerd.sock \
--upload-certs \
--v=5
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
kubeadm join k8s-master:6443 --token 1vpqda.t0ws57wiiogadc58 \
--discovery-token-ca-cert-hash sha256:6e4e100441f40a42b57829f738633f2c136fa2e67d6476b1d2891552abfd1461 --cri-socket=unix:///var/run/cri-dockerd.sock
之后需要把 master节点的/etc/kubernetes/admin.conf 文件复制到node节点的同位置,之后执行 第十步
可以支持网络策略。
kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml
可以支持网络策略。
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml