注意:本人使用centos7系统进行搭建
一、基本环境准备
#禁用**iptables**和**firewalld**服务
#关闭firewalld服务
systemctl stop firewalld
systemctl disable firewalld
#关闭iptables服务
systemctl stop iptables
systemctl disable iptables
#禁用**selinux**
sed -i 's/enforcing/disabled/' /etc/selinux/config
# 将桥接的IPv4流量传递到iptables的链
vim /etc/sysctl.d/k8s.conf
#增加如下内容
net.bridge.bridge-nf-call-ip6tables = 1
net.bridge.bridge-nf-call-iptables = 1
net.ipv4.ip_forward = 1
# 生效命令
sysctl --system
复制代码
二、docker环境准备
wget https://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo -O /etc/yum.repos.d/docker-ce.repo
yum list docker-ce --showduplicates | sort -r
#安装指定版本
yum install docker-ce-20.10.7
# 添加阿里云 yum 源, 可从阿里云容器镜像管理中复制镜像加速地址
cat <<EOF > /etc/docker/daemon.json
{
"registry-mirrors": ["https://xxxx.mirror.aliyuncs.com"]
}
EOF
#启动docker
systemctl enable docker && systemctl start docker
复制代码
三、安装 kubeadm、kubelet 和 kubectl
cat > /etc/yum.repos.d/kubernetes.repo << EOF
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64
enabled=1
gpgcheck=0
repo_gpgcheck=0
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF
yum install -y kubelet-1.21.3 kubeadm-1.21.3 kubectl-1.21.3
systemctl enable kubelet
复制代码
四、单机部署
# 设置hostname
hostnamectl set-hostname master
cat >> /etc/hosts << EOF
192.168.137.200 master
EOF
# 初始化 Master
kubeadm init \
--apiserver-advertise-address=192.168.137.200 \
--image-repository registry.aliyuncs.com/google_containers \
--kubernetes-version v1.21.3 \
--service-cidr=10.96.0.0/12 \
--pod-network-cidr=10.244.0.0/16
#可能遇到coredns镜像下载失败 用下面方式解决
docker pull registry.aliyuncs.com/google_containers/coredns:1.8.0
docker tag registry.aliyuncs.com/google_containers/coredns:1.8.0 registry.aliyuncs.com/google_containers/coredns:v1.8.0
docker rmi registry.aliyuncs.com/google_containers/coredns:1.8.0
# 为其他非root用户创建执行权限
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
#root 用户,则可以运行:
export KUBECONFIG=/etc/kubernetes/admin.conf
# 去除污点
kubectl describe node master | grep Taints
kubectl taint nodes master node-role.kubernetes.io/master-
# 部署CNI网络插件
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml
# 查看运行状态
kubectl get pods -n kube-system
复制代码
五、集群部署
设置 hosts
# 设置主机名
hostnamectl set-hostname master # node1 / node2
hostname
# 配置 hosts(只在master执行)
cat >> /etc/hosts << EOF
192.168.137.200 master
192.168.137.201 node1
192.168.137.202 node2
EOF
#初始化 Master
kubeadm init \
--apiserver-advertise-address=192.168.137.200 \
--image-repository registry.aliyuncs.com/google_containers \
--kubernetes-version v1.21.3 \
--service-cidr=10.96.0.0/12 \
--pod-network-cidr=10.244.0.0/16
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
#root 用户,则可以运行:
export KUBECONFIG=/etc/kubernetes/admin.conf
kubectl get nodes
#初始化 Node
kubeadm join 192.168.137.200:6443 --token 0bgtnj.6xl01261s02wqc7z \
--discovery-token-ca-cert-hash sha256:6553e9758f5eb18d81e793e936fffb7a168c943a6429de0834e1946033ce6f80
#可能出现的错误
[ERROR FileContent--proc-sys-net-ipv4-ip_forward]: /proc/sys/net/ipv4/ip_forward contents are not set to 1
kubeadm reset
echo 1 > /proc/sys/net/ipv4/ip_forward
#部署 CNI 网络插件(Master)
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml
# 查看运行状态
kubectl get pods -n kube-system
复制代码
dashboard UI监控使用
github地址 github.com/kubernetes/…
#下载
wget https://raw.githubusercontent.com/kubernetes/dashboard/v2.3.1/aio/deploy/recommended.yaml
#编辑文件开放端口进行访问
kind: Service
apiVersion: v1
metadata:
labels:
k8s-app: kubernetes-dashboard
name: kubernetes-dashboard
namespace: kubernetes-dashboard
spec:
type: NodePort
ports:
- port: 443
targetPort: 8443
nodePort: 31443
selector:
k8s-app: kubernetes-dashboard
#设置超级用户 roleRef 按照如下修改
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: kubernetes-dashboard-minimal
namespace: kube-system
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: kubernetes-dashboard
namespace: kube-system
---
#启动
kubectl apply -f recommended.yaml
#获取token
kubectl -n kubernetes-dashboard describe secret $(kubectl -n kubernetes-dashboard get secret | grep admin-user | awk '{print $1}')
#会显示token字符串然后进行登陆
复制代码
简单springboot应用部署
vim k8s-springboot.yaml
apiVersion: v1
kind: Namespace
metadata:
name: k8s-springboot
---
apiVersion: v1
kind: Service
metadata:
name: springboot-demo-nodeport
namespace: k8s-springboot
spec:
type: NodePort
ports:
- port: 8080
targetPort: 8080
nodePort: 30001
selector:
app: springboot-demo
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: springboot-demo
namespace: k8s-springboot
spec:
selector:
matchLabels:
app: springboot-demo
replicas: 1
template:
metadata:
labels:
app: springboot-demo
spec:
containers:
- name: springboot-demo
image: huzhihui/springboot:1.0.0
ports:
- containerPort: 8080
# 部署
kubectl apply -f k8s-springboot.yaml
#查看部署pod状态
kubectl get pods --all-namespaces
复制代码
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END