在CentOS上配置Kubernetes(k8s)網絡通常涉及以下幾個步驟:
關閉防火墻:
systemctl stop firewalld
systemctl disable firewalld
關閉SELinux:
setenforce 0
sed -i 's/^SELINUX=.*/SELINUX=disabled/' /etc/selinux/config
關閉swap:
swapoff -a
sed -i '/swap/s///#/g' /etc/fstab
設置主機名:
hostnamectl set-hostname k8s-master
配置hosts文件(只在master節點執行):
cat >> /etc/hosts << EOF
192.168.0.51 k8s-master
192.168.0.52 k8s-node1
192.168.0.53 k8s-node2
EOF
配置網絡參數:
cat > /etc/sysctl.d/k8s.conf << EOF
net.bridge.bridge-nf-call-ip6tables = 1
net.bridge.bridge-nf-call-iptables = 1
net.ipv4.ip_forward = 1
EOF
sysctl --system
時間同步:
yum install ntpdate -y
ntpdate time.windows.com
添加鏡像源:
curl https://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo -o /etc/yum.repos.d/docker-ce.repo
安裝Docker:
yum install -y docker-ce
systemctl start docker
systemctl enable docker
添加鏡像源:
cat > /etc/yum.repos.d/kubernetes.repo << EOF
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64
enabled=1
gpgcheck=0
repo_gpgcheck=0
gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF
安裝:
yum install -y kubelet kubeadm kubectl
systemctl enable kubelet
systemctl start kubelet
初始化Master節點:
kubeadm init --apiserver-advertise-address 192.168.0.51 --image-repository registry.aliyuncs.com/google_containers --kubernetes-version 1.22.15 --service-cidr 10.96.0.0/12 --pod-network-cidr 10.244.0.0/16
拷貝Kubernetes認證文件:
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
添加工作節點:
在Master節點執行kubeadm join命令,輸出如下:
kubeadm join 192.168.0.51:6443 --token abcdef.0123456789abcdef0123456789abcdef012345678 --discovery-token-ca-cert-hash sha256:abcdef123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
安裝網絡插件(如Calico):
kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml
查看節點狀態:
kubectl get nodes
查看Pod狀態:
kubectl get pods --all-namespaces
以上步驟是在CentOS上配置Kubernetes網絡的基本流程。根據具體需求,可能還需要進行其他配置,如設置靜態IP地址、配置網絡策略等。