master-node、worker-node1),并更新/etc/hosts文件(將節點IP與主機名映射)。sudo swapoff -a # 臨時關閉
sudo sed -i '/ swap / s/^\(.*\)$/#\1/g' /etc/fstab # 永久關閉
sudo apt install ntp),確保所有節點時間一致。sudo apt update && sudo apt upgrade -y
sudo apt install -y apt-transport-https ca-certificates curl software-properties-common
curl -fsSL https://download.docker.com/linux/debian/gpg | sudo apt-key add -
echo "deb [arch=amd64] https://download.docker.com/linux/debian $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list
sudo apt update
sudo apt install -y docker-ce docker-ce-cli containerd.io
sudo systemctl start docker
sudo systemctl enable docker
curl -s https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo apt-key add -
echo "deb https://apt.kubernetes.io/ kubernetes-xenial main" | sudo tee /etc/apt/sources.list.d/kubernetes.list
sudo apt update
sudo apt install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
執行初始化命令(指定Pod網絡CIDR,如Flannel需10.244.0.0/16):
sudo kubeadm init --pod-network-cidr=10.244.0.0/16
1.28.2),可添加--kubernetes-version=v1.28.2參數。kubeadm join命令(用于Worker節點加入),請保存該命令。配置kubectl(允許當前用戶訪問集群):
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
Kubernetes需要網絡插件實現Pod間通信,常用Flannel:
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml
等待插件部署完成(可通過kubectl get pods -n kube-system查看插件狀態)。
在Worker節點上執行Master節點初始化時輸出的kubeadm join命令(格式如下):
sudo kubeadm join <Master-IP>:6443 --token <Token> --discovery-token-ca-cert-hash sha256:<Hash>
<Master-IP>:Master節點的IP地址。<Token>:初始化Master時生成的臨時令牌(有效期24小時,過期需重新生成)。<Hash>:Master節點的CA證書哈希值。kubectl get nodes
Ready,則說明安裝成功。kubectl create deployment nginx-app --image=nginx --replicas=2
kubectl expose deployment nginx-app --name=nginx-web-svc --type=NodePort --port=80 --target-port=80
curl http://<Node-IP>:<NodePort>
<Node-Port>可通過kubectl get svc nginx-web-svc查看(通常為30000-32767之間的端口)。6443端口,用于Kubernetes API通信)。apt update && apt upgrade),修復安全漏洞。