master-node、worker-node1),并更新/etc/hosts文件(将节点IP与主机名映射)。sudo swapoff -a # 临时关闭
sudo sed -i '/ swap / s/^\(.*\)$/#\1/g' /etc/fstab # 永久关闭
sudo apt install ntp),确保所有节点时间一致。sudo apt update && sudo apt upgrade -y
sudo apt install -y apt-transport-https ca-certificates curl software-properties-common
curl -fsSL https://download.docker.com/linux/debian/gpg | sudo apt-key add -
echo "deb [arch=amd64] https://download.docker.com/linux/debian $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list
sudo apt update
sudo apt install -y docker-ce docker-ce-cli containerd.io
sudo systemctl start docker
sudo systemctl enable docker
curl -s https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo apt-key add -
echo "deb https://apt.kubernetes.io/ kubernetes-xenial main" | sudo tee /etc/apt/sources.list.d/kubernetes.list
sudo apt update
sudo apt install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
执行初始化命令(指定Pod网络CIDR,如Flannel需10.244.0.0/16):
sudo kubeadm init --pod-network-cidr=10.244.0.0/16
1.28.2),可添加--kubernetes-version=v1.28.2参数。kubeadm join命令(用于Worker节点加入),请保存该命令。配置kubectl(允许当前用户访问集群):
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
Kubernetes需要网络插件实现Pod间通信,常用Flannel:
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml
等待插件部署完成(可通过kubectl get pods -n kube-system查看插件状态)。
在Worker节点上执行Master节点初始化时输出的kubeadm join命令(格式如下):
sudo kubeadm join <Master-IP>:6443 --token <Token> --discovery-token-ca-cert-hash sha256:<Hash>
<Master-IP>:Master节点的IP地址。<Token>:初始化Master时生成的临时令牌(有效期24小时,过期需重新生成)。<Hash>:Master节点的CA证书哈希值。kubectl get nodes
Ready,则说明安装成功。kubectl create deployment nginx-app --image=nginx --replicas=2
kubectl expose deployment nginx-app --name=nginx-web-svc --type=NodePort --port=80 --target-port=80
curl http://<Node-IP>:<NodePort>
<Node-Port>可通过kubectl get svc nginx-web-svc查看(通常为30000-32767之间的端口)。6443端口,用于Kubernetes API通信)。apt update && apt upgrade),修复安全漏洞。