Skip to content

Commit

Permalink
MASTER_NODE -> MASTER_IP
Browse files Browse the repository at this point in the history
  • Loading branch information
Zhang Jun committed Jun 20, 2018
1 parent 84186a0 commit 401f59e
Show file tree
Hide file tree
Showing 5 changed files with 14 additions and 14 deletions.
4 changes: 2 additions & 2 deletions 01.系统初始化和全局变量.md
Original file line number Diff line number Diff line change
Expand Up @@ -173,10 +173,10 @@ export NODE_IPS=(172.27.129.105 172.27.129.111 172.27.129.112)
export NODE_NAMES=(kube-node1 kube-node2 kube-node3)

# kube-apiserver 节点 IP
export MASTER_NODE=172.27.129.105
export MASTER_IP=172.27.129.105

# kube-apiserver https 地址
export KUBE_APISERVER="https://${MASTER_NODE}:6443"
export KUBE_APISERVER="https://${MASTER_IP}:6443"

# etcd 集群服务地址列表
export ETCD_ENDPOINTS="https://172.27.129.105:2379,https://172.27.129.111:2379,https://172.27.129.112:2379"
Expand Down
16 changes: 8 additions & 8 deletions 06-1.api-server.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ cat > kubernetes-csr.json <<EOF
"CN": "kubernetes",
"hosts": [
"127.0.0.1",
"${MASTER_NODE}",
"${MASTER_IP}",
"${CLUSTER_KUBERNETES_SVC_IP}",
"kubernetes",
"kubernetes.default",
Expand Down Expand Up @@ -69,8 +69,8 @@ ls kubernetes*

``` bash
source /opt/k8s/bin/environment.sh
ssh root@${MASTER_NODE} "mkdir -p /etc/kubernetes/cert/ && sudo chown -R k8s /etc/kubernetes/cert/"
scp kubernetes*.pem k8s@${MASTER_NODE}:/etc/kubernetes/cert/
ssh root@${MASTER_IP} "mkdir -p /etc/kubernetes/cert/ && sudo chown -R k8s /etc/kubernetes/cert/"
scp kubernetes*.pem k8s@${MASTER_IP}:/etc/kubernetes/cert/
```
+ k8s 账户可以读写 /etc/kubernetes/cert/ 目录;

Expand All @@ -97,7 +97,7 @@ EOF

``` bash
source /opt/k8s/bin/environment.sh
scp encryption-config.yaml root@${MASTER_NODE}:/etc/kubernetes/
scp encryption-config.yaml root@${MASTER_IP}:/etc/kubernetes/
```

替换后的 encryption-config.yaml 文件:[encryption-config.yaml](https://github.com/opsnull/follow-me-install-kubernetes-cluster/blob/master/systemd/encryption-config.yaml)
Expand Down Expand Up @@ -128,7 +128,7 @@ ExecStart=/opt/k8s/bin/kube-apiserver \\
--tls-cert-file=/etc/kubernetes/cert/kubernetes.pem \\
--tls-private-key-file=/etc/kubernetes/cert/kubernetes-key.pem \\
--client-ca-file=/etc/kubernetes/cert/ca.pem \\
--kubelet-client-certificate=etc/kubernetes/ssl/kubernetes.pem \\
--kubelet-client-certificate=/etc/kubernetes/ssl/kubernetes.pem \\
--kubelet-client-key=/etc/kubernetes/cert/kubernetes-key.pem \\
--service-account-key-file=/etc/kubernetes/cert/ca-key.pem \\
--etcd-cafile=/etc/kubernetes/cert/ca.pem \\
Expand Down Expand Up @@ -175,7 +175,7 @@ EOF

``` bash
source /opt/k8s/bin/environment.sh
scp kube-apiserver.service root@${MASTER_NODE}:/etc/systemd/system/
scp kube-apiserver.service root@${MASTER_IP}:/etc/systemd/system/
```

## 授予 kubernetes 证书访问 kubelet API 的权限
Expand All @@ -190,13 +190,13 @@ $ kubectl create clusterrolebinding kube-apiserver:kubelet-apis --clusterrole=sy

``` bash
source /opt/k8s/bin/environment.sh
ssh root@{MASTER_NODE} "systemctl daemon-reload && systemctl enable kube-apiserver && systemctl start kube-apiserver"
ssh root@{MASTER_IP} "systemctl daemon-reload && systemctl enable kube-apiserver && systemctl start kube-apiserver"
```
## 检查 kube-apiserver 运行状态

``` bash
source /opt/k8s/bin/environment.sh
ssh root@{MASTER_NODE} "systemctl status kube-apiserver |grep 'Active:'"
ssh root@{MASTER_IP} "systemctl status kube-apiserver |grep 'Active:'"
```

确保状态为 `active (running)`,否则到 master 节点查看日志,确认原因:
Expand Down
2 changes: 1 addition & 1 deletion 07-2.kubelet.md
Original file line number Diff line number Diff line change
Expand Up @@ -562,7 +562,7 @@ cadvisor 统计所在节点各容器的资源(CPU、内存、磁盘、网卡)

``` bash
$ source /opt/k8s/bin/environment.sh
$ curl -sSL http://${MASTER_NODE}:8080/api/v1/nodes/kube-node1/proxy/configz | jq \
$ curl -sSL http://${MASTER_IP}:8080/api/v1/nodes/kube-node1/proxy/configz | jq \
'.kubeletconfig|.kind="KubeletConfiguration"|.apiVersion="kubelet.config.k8s.io/v1beta1"'
{
"syncFrequency": "1m0s",
Expand Down
2 changes: 1 addition & 1 deletion 09-4.metrics-server插件.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ cfssl gencert -ca=/etc/kubernetes/cert/ca.pem \

``` bash
source /opt/k8s/bin/environment.sh
scp metrics-server*.pem k8s@${MASTER_NODE}:/etc/kubernetes/cert/
scp metrics-server*.pem k8s@${MASTER_IP}:/etc/kubernetes/cert/
```

## 修改 kubernetes 控制平面组件的配置以支持 metrics-server
Expand Down
4 changes: 2 additions & 2 deletions manifests/environment.sh
Original file line number Diff line number Diff line change
Expand Up @@ -21,10 +21,10 @@ export NODE_IPS=(172.27.129.105 172.27.129.111 172.27.129.112)
export NODE_NAMES=(kube-node1 kube-node2 kube-node3)

# kube-apiserver 节点 IP
export MASTER_NODE=172.27.129.105
export MASTER_IP=172.27.129.105

# kube-apiserver https 地址
export KUBE_APISERVER="https://${MASTER_NODE}:6443"
export KUBE_APISERVER="https://${MASTER_IP}:6443"

# etcd 集群服务地址列表
export ETCD_ENDPOINTS="https://172.27.129.105:2379,https://172.27.129.111:2379,https://172.27.129.112:2379"
Expand Down

0 comments on commit 401f59e

Please sign in to comment.