安装环境
Ubuntu20.04LTS Server
安装准备
一、设置固定IP
sudo -s # 切换root权限
vim /etc/netplan/00-installer-config.yaml
# 修改如下内容
# This is the network config written by 'subiquity'
network:
ethernets:
ens33:
dhcp4: no #dhcp4关闭
addresses: [192.168.0.128/24] #设置本机IP及掩码
gateway4: 192.168.0.1 #设置网关
nameservers:
addresses: [114.114.114.114, 8.8.8.8] #设置DNS
version: 2
sudo netplan apply # 应用
二、创建root用户
passwd root
sed -i 's/#PermitRootLogin prohibit-password/PermitRootLogin yes/' /etc/ssh/sshd_config
systemctl restart sshd
三、修改hostname(需要可以修改)
# 修改主机名
vim /etc/hostname
# 修改对应主机名
vim /etc/hosts
# 需要重启
reboot
四、关闭防火墙
systemctl stop ufw
五、关闭swap分区
临时关闭
swapoff -a
永久关闭
vim /etc/fstab # 注释掉对应的一行,例如: #/swapfile none swap sw 0 0
echo "vm.swappiness = 0">> /etc/sysctl.conf
swapoff -a && swapon -a #刷新SWAP
sysctl -p #执行使其生效,不用重启系统
安装
切换root账号登陆
配置apt源
cp /etc/apt/sources.list /etc/apt/sources.list.bak
echo "" > /etc/apt/sources.list
cat << EOF >> /etc/apt/sources.list
deb http://mirrors.aliyun.com/ubuntu/ bionic main restricted universe multiverse
deb-src http://mirrors.aliyun.com/ubuntu/ bionic main restricted universe multiverse
deb http://mirrors.aliyun.com/ubuntu/ bionic-security main restricted universe multiverse
deb-src http://mirrors.aliyun.com/ubuntu/ bionic-security main restricted universe multiverse
deb http://mirrors.aliyun.com/ubuntu/ bionic-updates main restricted universe multiverse
deb-src http://mirrors.aliyun.com/ubuntu/ bionic-updates main restricted universe multiverse
deb http://mirrors.aliyun.com/ubuntu/ bionic-backports main restricted universe multiverse
deb-src http://mirrors.aliyun.com/ubuntu/ bionic-backports main restricted universe multiverse
deb http://mirrors.aliyun.com/ubuntu/ bionic-proposed main restricted universe multiverse
deb-src http://mirrors.aliyun.com/ubuntu/ bionic-proposed main restricted universe multiverse
deb https://mirrors.aliyun.com/kubernetes/apt kubernetes-xenial main
EOF
添加 Kubernetes 仓库的 GPG 密钥:
curl https://mirrors.aliyun.com/kubernetes/apt/doc/apt-key.gpg | sudo apt-key add -
更新apt源
apt update
安装依赖包
apt-get install -y apt-transport-https ca-certificates curl software-properties-common
安装kubeadm, kubelet 和 kubectl
apt install -y kubectl=1.26.3-00 kubelet=1.26.3-00 kubeadm=1.26.3-00
安装containerd
apt install -y containerd
mkdir -p /etc/containerd
containerd config default | sudo tee /etc/containerd/config.toml
systemctl restart containerd
apt-get install -y bridge-utils
modprobe br_netfilter
echo "net.ipv4.ip_forward = 1" | sudo tee -a /etc/sysctl.conf
sysctl -p
查看需要的镜像
kubeadm config images list # 执行这个命令,下面是结果
registry.k8s.io/kube-apiserver:v1.26.3
registry.k8s.io/kube-controller-manager:v1.26.3
registry.k8s.io/kube-scheduler:v1.26.3
registry.k8s.io/kube-proxy:v1.26.3
registry.k8s.io/pause:3.9
registry.k8s.io/etcd:3.5.6-0
registry.k8s.io/coredns/coredns:v1.9.3
这里有个坑是kubelet去启动的时候会去拉registry.k8s.io/pause:3.6的镜像,所以我在后面拉取镜像的时候把这个版本也拉了。
准备镜像
拉取
crictl -r unix:///run/containerd/containerd.sock pull registry.aliyuncs.com/google_containers/kube-apiserver:v1.26.3
crictl -r unix:///run/containerd/containerd.sock pull registry.aliyuncs.com/google_containers/kube-proxy:v1.26.3
crictl -r unix:///run/containerd/containerd.sock pull registry.aliyuncs.com/google_containers/kube-controller-manager:v1.26.3
crictl -r unix:///run/containerd/containerd.sock pull registry.aliyuncs.com/google_containers/kube-scheduler:v1.26.3
crictl -r unix:///run/containerd/containerd.sock pull registry.aliyuncs.com/google_containers/pause:3.9
crictl -r unix:///run/containerd/containerd.sock pull registry.aliyuncs.com/google_containers/pause:3.6
crictl -r unix:///run/containerd/containerd.sock pull registry.aliyuncs.com/google_containers/etcd:3.5.6-0
crictl -r unix:///run/containerd/containerd.sock pull registry.aliyuncs.com/google_containers/coredns:v1.9.3
tag镜像
ctr -n k8s.io images tag registry.aliyuncs.com/google_containers/kube-apiserver:v1.26.3 registry.k8s.io/kube-apiserver:v1.26.3
ctr -n k8s.io images tag registry.aliyuncs.com/google_containers/kube-proxy:v1.26.3 registry.k8s.io/kube-proxy:v1.26.3
ctr -n k8s.io images tag registry.aliyuncs.com/google_containers/kube-controller-manager:v1.26.3 registry.k8s.io/kube-controller-manager:v1.26.3
ctr -n k8s.io images tag registry.aliyuncs.com/google_containers/kube-scheduler:v1.26.3 registry.k8s.io/kube-scheduler:v1.26.3
ctr -n k8s.io images tag registry.aliyuncs.com/google_containers/pause:3.9 registry.k8s.io/pause:3.9
ctr -n k8s.io images tag registry.aliyuncs.com/google_containers/pause:3.6 registry.k8s.io/pause:3.6
ctr -n k8s.io images tag registry.aliyuncs.com/google_containers/etcd:3.5.6-0 registry.k8s.io/etcd:3.5.6-0
ctr -n k8s.io images tag registry.aliyuncs.com/google_containers/coredns:v1.9.3 registry.k8s.io/coredns/coredns:v1.9.3
查看镜像
crictl -r unix:///run/containerd/containerd.sock image
初始化 control-plane
kubeadm init --kubernetes-version=v1.26.3 --apiserver-advertise-address 192.168.0.128 --pod-network-cidr=10.244.0.0/16 --ignore-preflight-errors=Swap
记录下k8s join 的token,方便后续节点加入
kubeadm join 192.168.0.128:6443 --token {xxx}
加载环境变量
mkdir -p $HOME/.kube
cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
chown $(id -u):$(id -g) $HOME/.kube/config
export KUBECONFIG=/etc/kubernetes/admin.conf
echo "export KUBECONFIG=/etc/kubernetes/admin.conf" >> ~/.profile
source ~/.profile
部署网络插件
wget https://docs.projectcalico.org/v3.25/manifests/calico.yaml -O calico.yaml
kubectl apply -f calico.yaml
测试是否ok
kubectl get node
NAME STATUS ROLES AGE VERSION
master Ready control-plane 4m28s v1.26.3
kubectl get pods -A
NAMESPACE NAME READY STATUS RESTARTS AGE
kube-system calico-kube-controllers-57b57c56f-96sf7 1/1 Running 0 12m
kube-system calico-node-7mdrh 1/1 Running 0 12m
kube-system coredns-787d4945fb-2chlh 1/1 Running 0 16m
kube-system coredns-787d4945fb-lzdbt 1/1 Running 0 16m
kube-system etcd-master 1/1 Running 0 16m
kube-system kube-apiserver-master 1/1 Running 0 16m
kube-system kube-controller-manager-master 1/1 Running 0 16m
kube-system kube-proxy-8z2bx 1/1 Running 0 16m
kube-system kube-scheduler-master 1/1 Running 0 16m
设置kubectl自动补全命令
安装bash-completion
apt-get install bash-completion
重新启动你的 shell 会话或者运行 source /etc/profile 以应用更改
echo 'source <(kubectl completion bash)' >>~/.bashrc
source ~/.bashrc