­

二进制安装k8s集群(12)-安装kubelet

上一篇文章里我们主要介绍master组件kube-scheduler的安装,这里我们开始介绍安装worker组件kubelet,我们采用下载二进制binary制作linux systemd的方式安装。这个组件也在下载的kubenetes包里(1.15.1版本),在以前文章里已经下载过(要科学上网或者搭个梯子),这里就不再重复。另外kubelet与kube-apiserver交互我们开启ssl,所以请提前制作好相关ssl证书(可以参考以前文章里制作docker的证书),并copy到配置目录里。

copy二进制文件:

cp /opt/sw/kubernetes/install/kubernetes/server/bin/kubelet /usr/bin/  whereis kubelet

创建配置目录:

kubelet和kube-apiserver会相互通讯,相互作为client端与server端。这里kubelet作为server端的时候开启ssl,请提前制作好相应的ssl证书并copy到配置目录里。

mkdir -p /etc/kubernetes/kubelet  mkdir -p /etc/kubernetes/kubelet/cert  touch  /etc/kubernetes/kubelet/k8s-kubelet.conf

创建配置文件:

kubelet需要和kube-apiserver交互,这个交互可以利用kubeconfig文件做为配置文件。所以与kube-controller-manager一样,我们可以利用在kubectl安装过程中我们创建的kubeconfig文件。同时kubelet负责创建销毁pod,要为pod配置基础镜像,这里设置为私有repo的public项目中的

172.20.11.41:1034/infra-pub/registry.access.redhat.com-rhel7-pod-infrastructure:latest(已经在以前文章里我们push到private repo中)。

cat >  /etc/kubernetes/kubelet/k8s-kubelet.conf<<EOF  KUBELET_ADDRESS="--address=0.0.0.0 --port=10250"  KUBELET_TLS="--tls-cert-file=/etc/kubernetes/kubelet/cert/k8skubelet-server.crt --tls-private-key-file=/etc/kubernetes/kubelet/cert/k8skubelet-server.key"  KUBELET_POD_INFRA_CONTAINER="--pod-infra-container-image=172.20.11.41:1034/infra-pub/registry.access.redhat.com-rhel7-pod-infrastructure:latest"  KUBELET_KUBE_CONFIG="--kubeconfig=/etc/kubernetes/kubeconfig/config"  KUBELET_CLUSTER="--cluster-dns=10.254.10.2 --cluster-domain=cluster.local"  KUBELET_ARGS="--fail-swap-on=false --hostname-override=172.20.11.43"  EOF    source /etc/kubernetes/kubelet/k8s-kubelet.conf

创建systemd unit文件:

touch /usr/lib/systemd/system/kubelet.service    cat > /usr/lib/systemd/system/kubelet.service<<EOF  [Unit]  Description=Kubernetes Kubelet Service  After=network.target network-online.target docker.service  Wants=network-online.target docker.service    [Service]  Type=simple  EnvironmentFile=-/etc/kubernetes/kubelet/k8s-kubelet.conf  ExecStartPre=-source /etc/kubernetes/kubelet/k8s-kubelet.conf  ExecStart=/usr/bin/kubelet   ${KUBELET_ADDRESS}   ${KUBELET_TLS}   ${KUBELET_POD_INFRA_CONTAINER}   ${KUBELET_KUBE_CONFIG}   ${KUBELET_CLUSTER}   ${KUBELET_ARGS}    Restart=on-failure  LimitNOFILE=65536    [Install]  WantedBy=multi-user.target  EOF    source /etc/kubernetes/kubelet/k8s-kubelet.conf  cat /usr/lib/systemd/system/kubelet.service

reload服务并设置开机启动:

systemctl daemon-reload  systemctl enable kubelet

启动服务并检查状态:

systemctl start kubelet  systemctl status kubelet