æ©èœãªã¯ãšã¹ã
kubeadmããŒãžã§ã³v1.12.5
ç°å¢ïŒ
uname -a
ïŒïŒLinux node1 4.4.0-141-genericïŒ167-Ubuntu SMP Wed Dec 5 10:40:15 UTC 2018 x86_64 x86_64 x86_64 GNU / Linuxç§ã®ã¯ã©ã¹ã¿ãŒã®ãã¡3ã€ã¯çŸåš1æ³ã§ãã äžéšã®èšŒææžã¯1幎ã®æå¹æéã§çºè¡ããããããã¯ã©ã¹ã¿ãŒã¯æ£åžžã«æ©èœããªããªããŸããã 蚌ææžãæå¹æéã«éããåã«ãã¯ã©ã¹ã¿ãŒã1.10.12ãã1.11.6ããã³1.12.5
ç§ã¯ããã€ãã®åé¡ãçµéšããŸããïŒ
/var/lib/kubelet/pki/kubelet-client-current.pem
ã¯æ£ããããŒããŒã·ã§ã³ãããŸããããclient-certificate
ãšclient-key
ã§/etc/kubernetes/kubelet.conf
ãŸã æã/var/lib/kubelet/pki/kubelet-client.*
client-certificate-data
ãšclient-key-data
ã§/etc/kubernetes/kubelet.conf
ãŸã ããã«å£ããŸã蚌ææžãå«ãŸããŠããŸãããclient-certificate-data
ãšclient-key-data
ãæåã§æŽæ°ããå¿
èŠããããŸããsudo kubeadm alpha phase kubeconfig kubelet
ã䜿çšããŠããã¹ã¿ãŒãšãã¹ãŠã®ããŒãã§ãã®ãã¡ã€ã«ãåçæããããšãã§ããŸããkubeadm alpha phase certs renew all
ã¯KubeConfigãã¡ã€ã«ãæŽæ°ããŸããsudo kubeadm alpha phase certs renew all
ã®ãã¹ãŠã®æéåãã®æ¬åœæŽæ°ããããã¹ã¿ã«/etc/kubernetes/pki
眰éã§ããã/etc/kubernetes/admin.conf
/etc/kubernetes/controller-manager.conf
/etc/kubernetes/scheduler.conf
sudo kubeadm alpha phase kubeconfig all --apiserver-advertise-address=x.x.x.x
ã䜿çšããå¿
èŠããããŸããkubectl -n kube-system delete pod kube-apiserver-mater
ã¯æ©èœããŠããããã«èŠããŸãããå®éã«ã¯ããããåèµ·åãããããšã¯ãããŸããã§ãããdockerstop/ startã䜿çšããŠã³ã³ãããŒãåæ¢ããã³éå§ããå¿
èŠããããŸãããkubeadm alpha phase kubeconfig
ã¯ãæ§æãæžã蟌ãŸããåŸã«éçããããåèµ·åãããããŠãŒã¶ãŒã«åèµ·åããããã«éç¥ããå¿
èŠããããŸããå®ãããé¡ãããŸã
ã¢ã³ãã¬ã¢ã¹
@MalloZup
ãã¡ããã§ãããçµåãã§ãŒãºã¯åªå
床ãé«ãããšã«æ³šæããŠãã ããã
ããã§ããïŒ ã©ããããããšãã
ããã«ã¡ã¯ã
ãã®ãããã¯ã«é¢ããŠãã1ã€ãããŸãã
kubeadm alpha phase kubeconfig all
ã¯ãã³ãã³ãã®çºè¡æã«confãã¡ã€ã«ãé
眮ãããŠããå Žåã次ã®ã¡ãã»ãŒãžã衚瀺ããŸãã
[kubeconfig] Using existing up-to-date KubeConfig file: "/etc/kubernetes/admin.conf"
[kubeconfig] Using existing up-to-date KubeConfig file: "/etc/kubernetes/kubelet.conf"
[kubeconfig] Using existing up-to-date KubeConfig file: "/etc/kubernetes/controller-manager.conf"
[kubeconfig] Using existing up-to-date KubeConfig file: "/etc/kubernetes/scheduler.conf"
蚌ææžã®æå¹æéãåããŠãããã©ããã¯ãã§ãã¯ãããªããããç§ã®æèŠã§ã¯up-to-date
ã¯èª€è§£ãæãæãããããŸãã
æŽæ°ããã蚌ææžããã¡ã€ã«ã«åã蟌ãã«ã¯ããã°ã次ã®ããã«ãªããããããã¡ã€ã«ãäºåã«åé€ããå¿ èŠããããŸãã
[kubeconfig] Wrote KubeConfig file to disk: "/etc/kubernetes/admin.conf"
[kubeconfig] Wrote KubeConfig file to disk: "/etc/kubernetes/kubelet.conf"
[kubeconfig] Wrote KubeConfig file to disk: "/etc/kubernetes/controller-manager.conf"
[kubeconfig] Wrote KubeConfig file to disk: "/etc/kubernetes/scheduler.conf"
ç§ã®å Žåã¯å€§äžå€«ã§ãããæ°æ¥åŸã蚌ææžãå€ããªã£ããããéçããããšéä¿¡ã§ããŸããã§ããã
å®ãããé¡ãããŸã
ã¢ã³ãã¬ã¢ã¹
@MalloZupã«å²ãåœãŠãããŠã
@MalloZup ïŒGitHubã§ã¯ã次ã®ãŠãŒã¶ãŒãå²ãåœãŠãããšãã§ããŸããã§ããïŒMalloZupã
å²ãåœãŠã§ããã®ã¯kubernetesã¡ã³ããŒãšã¬ãã³ã©ãã¬ãŒã¿ãŒã®ã¿ã§ããã課é¡/ PRã«ã¯åæã«10人ã®å²ãåœãŠè
ããå²ãåœãŠãããªãããšã«æ³šæããŠãã ããã
詳现ã«ã€ããŠã¯ãå¯çš¿è
ã¬ã€ããåç
§
察å¿ããŠããã®ïŒ
/å²åœ
PRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ããã¡ãããå
¥æã§ãkubernetes / test-infraãªããžããªã«å¯ŸããŠåé¡ã
ããã«ã¡ã¯@adoerlerthxã®åé¡ã§ãã 誀解ãæãæ å ±ã«é¢ããŠãç§ã¯PRhttps ïŒ//github.com/kubernetes/kubernetes/pull/73798ãéä¿¡ããŸãã
æéãããã°ãæ®ãã®åé¡ã«ã€ããŠèŠãŠãããŸãã åé¡ã®æéãšç²ŸåºŠã®ããã®Thx
@adoerlerç§ã¯ããªãã®ææ¡ã®ããã«DOCåºå ±ãéããŸããã ãæ°è»œã«tiaïŒrocketïŒãã芧ãã ããã
ïŒhttps://github.com/kubernetes/website/pull/12579ïŒ
ããã«ã¡ã¯@MalloZup ã
PRããããšãïŒ
certs renew
ã¯ã²ãŒã ã®äžéšã«ãããªããããkubeconfigãã¡ã€ã«ã«é¢ããæããããŸããã
äœãã®ãããªãã®ïŒ
蚌ææžãæŽæ°ããããã
kubeadm alpha phase kubeconfig ...
ã䜿çšããŠKubeConfigãã¡ã€ã«ãåäœæããããšãå¿ããªãã§ãã ãã
THXã å®éã«kubeconfigãã¡ã€ã«ãæŽæ°ã§ãããšæã£ãŠããã®ã§ãããã¥ã¡ã³ããè¿œå ããŸããã§ããã æ®ãã®åèµ·åãããã¯ããŠãŒã¶ãŒã«å§ä»»ããŠæå°éã®ããã¥ã¡ã³ããäœæã§ããŸãã @fabriziopandini @lubomir @ereslibreãã®å®è£ ã§äœãã足ããŸãããïŒ ãã£ã¢
@MalloZup蚌ææžã®æŽæ°ãã©ã®ããã«æ©èœãããã«ã€ããŠã®æ·±ãç¥èããããŸããã
å人çã«ã¯ãè¡åãèµ·ããåã«ãå šäœçãªæŽå²ãå°ãæããã«ããããšæããŸã-äžèšã§ææ¡ããããã®ãå«ã¿ãŸã-ïŒ
kubeadm alpha phase certs renew
ã§ç®¡çããå¿
èŠããããã®kubeadm upgrade
éã«èªåçã«ç®¡çãããã¹ããã®ããããç§ã¯ãã®åéã§ç§ãããçç·Žãã人ã ã«æåŸã®èšèãæ®ããŸã
æšå¥šããã蚌ææžã®æŽæ°ããªã·ãŒã«ã€ããŠè©±ãåãããã«ãäŒè°ã«æéãå²ãå¿
èŠããããšæããŸãã 蚌ææžç®¡çã«é¢ããããŒãžã§ã¯ãããã«è©³çŽ°ãå¿
èŠã«ãªãå ŽåããããŸãã
https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs
å°ãªããšãéå§ç¹ãšããŠãåäžã®ã³ã³ãããŒã«ãã¬ãŒã³ã¯ã©ã¹ã¿ãŒçšã®å°ããªã¬ã€ããäœæããå¿ èŠããããŸãã
ãŠãŒã¶ãŒãè¡ã£ãŠããããšã¯ãèªåã§ç©äºãç解ããããšã§ãã
https://github.com/kubernetes/kubeadm/issues/581#issuecomment -421477139
^ãã®ã³ã¡ã³ããšäžèšã®ã³ã¡ã³ãã«ã¯ããŠãŒã¶ãŒãäœæããã¬ã€ããå«ãŸããŠããŸãã
ããã¯ãå
¬åŒã¬ã€ããè¿œå ããå¿
èŠãããããšã瀺ããŠããŸãã
cc @timothysc @liztio
/ assign @ereslibre
çŸåšãæ°çŸäººã®ãŠãŒã¶ãŒãããã¯ã©ã¹ã¿ãŒã¯ã¹ã¿ãã¯ããŠããŸãã æéåãã®èšŒææžãã©ããããã«ã€ããŠã®éåžžã«ç°¡åãªã¬ã€ããæããŠããããŸããïŒ
@ dimm0
ãŠãŒã¶ãŒãè¡ã£ãŠããããšã¯ãèªåã§ç©äºãç解ããããšã§ãã
ïŒ581ïŒã³ã¡ã³ãïŒ
^ãã®ã³ã¡ã³ããšäžèšã®ã³ã¡ã³ãã«ã¯ããŠãŒã¶ãŒãäœæããã¬ã€ããå«ãŸããŠããŸãã
ãããã¯ç§ãã¡ãATMãæã£ãŠããå¯äžã®ã¬ã€ãã§ãã
[root<strong i="5">@controller0</strong> ~]# kubeadm alpha phase certs apiserver --apiserver-advertise-address 1.2.3.4
Error: unknown flag: --apiserver-advertise-address
Usage:
Flags:
-h, --help help for phase
Global Flags:
--log-file string If non-empty, use this log file
--rootfs string [EXPERIMENTAL] The path to the 'real' host root filesystem.
--skip-headers If true, avoid header prefixes in the log messages
-v, --v Level log level for V logs
error: unknown flag: --apiserver-advertise-address
[root<strong i="6">@controller0</strong> ~]# kubeadm alpha phase certs apiserver
This command is not meant to be run on its own. See list of available subcommands.
1.13ã§ã¯ãinitãã§ãŒãºã¯èŠªã®initã³ãã³ãã«ç§»è¡ããŸããã
https://kubernetes.io/docs/reference/setup-tools/kubeadm/kubeadm-init-phase/#cmd -phase-certs
1.12ã§ã¯ããã©ã°ã¯ããã«ããã¯ãã§ãã
https://v1-12.docs.kubernetes.io/docs/reference/setup-tools/kubeadm/kubeadm-alpha/#cmd -phase-certs
1.11ã¯ãŸããªããµããŒããçµäºããŸãã
ã©ã€ããµã€ã¯ã«/ã¢ã¯ãã£ãã©ãã«ãåé€ããŸãã
1.15ã«ç§»åããŸãã
å¯èœãªããã¥ã¡ã³ãã¯ããã§ã¢ã€ãã¢ãæŽæ°ããŸãïŒ
https://github.com/kubernetes/kubeadm/issues/1361#issuecomment -463192631
@ neolit123
質åïŒ1.14ã§ãã¹ã¿ãŒHAã䜿çšããå Žåãåäžã®ãã¹ã¿ãŒã§https://github.com/kubernetes/kubeadm/issues/581#issuecomment -421477139ããã©ããŒããã ãã§ååã§ããããããšãã»ã«ã³ããªãã¹ã¿ãŒã«å床åå ããå¿
èŠããããŸãã蚌ææžãåãã§ããããŸããïŒ
ã»ã«ã³ããªã³ã³ãããŒã«ãã¬ãŒã³ããŒãã«åçµåããããšã¯ã1,14ã®è¿
éã§å®è¡å¯èœãªãªãã·ã§ã³ã®ããã§ãã
HA蚌ææžã®ããŒããŒã·ã§ã³ã«é¢ããããã¥ã¡ã³ãã¯ãŸã ãããŸããã
ïŒèšããŸã§ããªããhttpsïŒ//github.com/kubernetes/kubeadm/issues/581#issuecomment-421477139ã®ãããªé©åãªæé ã¯ãŸã è¿œå ãããŠããŸããïŒã
--experimental-upload-certsã¯ãHAã§ã®èšŒææžããŒããŒã·ã§ã³ã®ããç°¡åãªãœãªã¥ãŒã·ã§ã³ã®åºç€ãæäŸããŸãããïŒ
HA蚌ææžããŒããŒã·ã§ã³ãè¡ã1ã€ã®æ¹æ³ã¯æ¬¡ã®ãšããã§ãã
kubeadm init phase upload-certs --experimental-upload-certs
蚌ææžããŒãä¿åããŸãã
kubeadm token create --print-join-command
ããŒã¯ã³ãšãšãã«joinã³ãã³ããä¿åããŸãã
ããŒã¯ã³ãšèšŒææžããŒã䜿çšããŠãæ®ãã®ã³ã³ãããŒã«ãã¬ãŒã³ããŒãã«--certs-key .... --experimental-control-plane-join
ã䜿çšããŠ1ã€ãã€åçµåããŸãã
åŽåè ã®ããã«ïŒææ°Žããæ°ããããŒã¯ã³ã䜿çšããŠååå ããã³ãŒãã³ã1ã€ãã€äœ¿çšããŸãã
ãªãã·ã§ã³ã§ãçµæã®ããŒã¯ã³ãåé€ããŸãã
@ neolit123
3ã€ã®ãã¹ã¿ãŒã¯ã©ã¹ã¿ãŒã§ã¯ãããã©ã€ããªããã¹ã¿ãŒã®èšŒææžãå€æŽãããšã蚌ææžãå€æŽããããããetcdã¯æ©èœããªããªããŸãïŒã¯ã©ãŒã©ã ã¯æå°51ïŒ
ã§ããå¿
èŠããããŸãïŒã ãããããªããå€åç§ãã¡ã¯ã©ãããããã2ã€ã®ã»ã«ã³ããªãã¹ã¿ãŒãã³ãŒãã³ããŠãã蚌ææžãå€æŽããå¿
èŠããããŸããïŒ ãã³ãŒãã³ãã¹ã¿ãŒãã¯å¯èœã§ããïŒ
ç§ã¯ããã®å°é家ã§ã¯ãããŸããããèªå蚌ææžã³ããŒããã®åçã«å«ãŸããã¹ãã§ã¯ãªããšæããŸã
èªåã³ããŒèšŒææžã¯ãCAãfront-proxy-CAãªã©ãåŠçããŸã-CAïŒ10幎TTLããïŒããã³SAããŒïŒTTLãªãïŒ
Cert renewã³ãã³ãã¯ããã¹ã¿ãŒéã§ç°ãªãä»ã®ãã¹ãŠã®èšŒææžïŒ1幎TTLïŒã«ã¿ããããŸãã
AFAIKãçŸåšãkubeconfigãã¡ã€ã«ã®èšŒææžã®æŽæ°ãåŠçãããã®ã¯ãããŸãã
ããããŸãããç§ã¯ã蚌ææžã®ã³ããŒããå®éã«ããã§äœãããããèæ
®ããŸããã§ããã
ã©ã¡ãã®æ¹æ³ã§ããé©åãªèšŒææžããŒããŒã·ã§ã³ããã¥ã¡ã³ããäœæããå¿
èŠããããŸãã
/å²åœ
/ã©ã€ããµã€ã¯ã«ã¢ã¯ãã£ã
ç§ã¯ãã®åé¡ã«åãçµã¿å§ããŠããŸãã
察åŠãã¹ãããŸããŸãªãã€ã³ãããããŸãïŒ_ 2019幎5æ14æ¥æŽæ°_ïŒ
ãããŠãç§ã¯ããããã¹ãŠã«å¥ã ã®PRã§åãçµã¿ãŸã
@ neolit123 @fabriziopandini
CA蚌ææžãããŒããŒã·ã§ã³ããããã«ãèšåããæé ã¯ãããŸããïŒ ãããææžåã§ããŸããïŒ CAçšã®ãã®ãå«ãç§å¯éµãããŒããŒã·ã§ã³ããã®ã¯ã©ãã§ããïŒ
@ tushar00jainã®CA蚌ææžã®ããŒããŒã·ã§ã³ã¯å¥ã®åé¡ã§è¿œè·¡ãããŠããŸãhttps://github.com/kubernetes/kubeadm/issues/1350
ãã®åé¡ã¯ã眲åããã蚌ææžã®ã¿ã«çŠç¹ãåœãŠãŠããŸã
@fabriziopandiniæŽæ°ããŒãã®PRãéä¿¡ã§ããã®ã§ãä»æ¥ãã®ãã±ãããéããããšãæ€èšããŠããŸããã ãã±ãããéããå¿ èŠããããŸããïŒ
蚌ææžããŒããŒã·ã§ã³ãæå¹ã«ãªã£ãŠããå Žåã§ããkubelet.confã¯å€ã蚌ææžãæããŸãïŒãã§ã«ïŒ1317ã§è¿œè·¡ãããŠããŸãïŒ
ã¯ããããã¯å¥ã®åé¡ã§è¿œè·¡ãããŸããæäŸããå¿ èŠã®ããåé¿çã«é¢ããŠããã£ã¹ã«ãã·ã§ã³/ããã¥ã¡ã³ããå¿ èŠã«ãªãå¯èœæ§ããããŸãã
蚌ææžããŒããŒã·ã§ã³ã¯apiserver / etcd / front-proxy-client蚌ææžãæŽæ°ããŸããïŒkubernetes / kubernetesïŒ76862ã§ä¿®æ£ïŒ
ã³ãã³ãkubeadmalpha phase certs renew allã¯ãKubeConfigãã¡ã€ã«ãæŽæ°ããŸããïŒkubernetes / kubernetesïŒ77180ã§ä¿®æ£ïŒ
蚌ææžã®æŽæ°ã«é¢ããããã¥ã¡ã³ãïŒã³ãã³ããå®è¡ããå ŽæãwhenãkubeconfigãHAã®è©³çŽ°ïŒ
äžèšã®3ãå®è¡ããå¿ èŠããããŸãã
/éãã
äžèšã®ã³ã¡ã³ãã«ãããšãã»ãšãã©ã®äœæ¥ã¯ãã§ã«å®äºããŠããŸãã æ¬ èœããŠãããããã¯ãå¥ã®/å°çšã®åé¡ã§è¿œè·¡ãããŸã
@fabriziopandini ïŒãã®åé¡ã解決ããŸãã
察å¿ããŠããã®ïŒ
/éãã
äžèšã®ã³ã¡ã³ãã«ãããšãã»ãšãã©ã®äœæ¥ã¯ãã§ã«å®äºããŠããŸãã æ¬ èœããŠãããããã¯ãå¥ã®/å°çšã®åé¡ã§è¿œè·¡ãããŸã
PRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ããã¡ãããå
¥æã§ãkubernetes / test-infraãªããžããªã«å¯ŸããŠåé¡ã
ã蚌ææžããŒããŒã·ã§ã³ãæå¹ã«ãªã£ãŠããå Žåã§ããkubelet.confãå€ã蚌ææžãæããŠãããéšåãã©ã®ããã«å¯ŸåŠããããã誰ãã«èª¬æããŠããããŸããïŒ ããã«èšåããŠããå¯äžã®ãªã³ã¯ãããåé¡ã¯ãããããåé¡ã§ãããã©ããããããªãã®ã§ãæ°ãããã±ãããéããã§éããããå¥ã®åé¡ãæ¯æããŠãæ瀺çã«éããããŸããã
ç§ã¯1.16ã䜿çšããŠããŸããã kubelet.conf
ã§sudo kubeadm alpha certs renew all
æŽæ°ãè¡ãããŠããŸããã äœãæ¬ ããŠããŸããïŒ @ neolit123
éåžžã«é·ãè°è«ã®ç°¡åãªèŠçŽã
ä»æ¥ã®æç¹ã§ãã§ã«ãã®2çªç®ã®ãã€ã³ãã¯ãkubeadminitãå®è¡ããããŒããé€ããã¹ãŠã®ããŒãã§æ©èœããŸãã https://github.com/kubernetes/kubernetes/pull/84118ã¯ãããä¿®æ£ããäºå®ã§ã
@fabriziopandiniãããããããšããããã¯çã«ããªã£ãŠããŸãã
kubelte.confã®èšŒææžãçŸåšããäžèšã®ä¿®æ£ãŸã§ã®éã«å€ããªã£ãŠãããšããåé¡ã«çŽé¢ããŠããä»ã®äººã«ãšã£ãŠããã®èšäºã¯åœ¹ã«ç«ã¡ãŸããã
https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#check -certificate-expiration
kubeadm initã§äœæãããããŒãã§ã¯ãkubeadmããŒãžã§ã³1.17ããåã§ã¯ãkubelet.confã®å 容ãæåã§å€æŽããå¿ èŠããããšãããã°ããããŸãã kubeadm initãçµäºããããclient-certificate-dataãšclient-key-dataã次ã®ããã«çœ®ãæããŠãããŒããŒã·ã§ã³ãããkubeletã¯ã©ã€ã¢ã³ã蚌ææžãæãããã«kubelet.confãæŽæ°ããå¿ èŠããããŸãã
client-certificate: /var/lib/kubelet/pki/kubelet-client-current.pem
client-key: /var/lib/kubelet/pki/kubelet-client-current.pem
@AndrewSavããããšãããããŸãã ç§ã¯promethesæŒç®åã䜿çšããŠã¯ã©ã¹ã¿ãŒãç£èŠããŸããã æè¿ããKubernetes API蚌ææžã®æå¹æéã7æ¥ä»¥å ã§ãããšããã¢ã©ãŒããåãåããŸããããããã¯ãã®åé¡ã«é¢é£ããŠãããšæããŸãã ãã¹ã¿ãŒããŒãã®kubelet.confã®ã³ã³ãã³ããæŽæ°ããŸããã ããããç§ã¯ãŸã ã¢ã©ãŒããåãåããŸãã äœãææ¡ã¯ãããŸããïŒ Tksã
@tannh kubeadmã䜿çšããŠã¯ã©ã¹ã¿ãŒãã€ã³ã¹ããŒã«ããå Žåã¯ãkubeadmã䜿çšããŠèšŒææžã®æå¹æéã確èªããŠãã ããã ããã§ãªããã°ãããªãã®åé¡ã¯ããããé¢é£ããŠããŸããã
kubeadm initã§äœæãããããŒãã§ã¯ãkubeadmããŒãžã§ã³1.17ããåã§ã¯ãkubelet.confã®å 容ãæåã§å€æŽããå¿ èŠããããšãããã°ããããŸãã kubeadm initãçµäºããããclient-certificate-dataãšclient-key-dataã次ã®ããã«çœ®ãæããŠãããŒããŒã·ã§ã³ãããkubeletã¯ã©ã€ã¢ã³ã蚌ææžãæãããã«kubelet.confãæŽæ°ããå¿ èŠããããŸãã
ããã¯ã1.17ã®ãªãªãŒã¹ããŒãã«ãèšèŒãããŠããŸãã
@adoerlerå€ãããŒãžã§ã³ã®kubeadmããŸã å®è¡ããŠããŸããã蚌ææžã®æŽæ°åŸã«kubelet.confãadmin.conãªã©ãæŽæ°ããã«ã¯ã©ãããã°ããã§ããïŒ
æ°ãã蚌ææžãçæãããkubeadmalphacerts renew allããå®è¡ããåŸã/ etc / kubernetesã®äžã«ãããã¹ãŠã®.confãç·šéããå¿
èŠããããŸããã©ãããã°ããã§ããïŒ æ£ç¢ºã«ã©ããæãå¿
èŠããããŸããïŒ
ãã«ããã¹ã¿ãŒããŒãã®å Žåããã¹ãŠã®ãã¹ã¿ãŒã§ã³ãã³ããå®è¡ããå¿
èŠããããŸããïŒ
ããã«ã¡ã¯@SuleimanWA ã
ãã«ããã¹ã¿ãŒç°å¢ã§äœããã¹ããããããŸãããã»ããã¢ããã«ã¯åäžã®ãã¹ã¿ãŒãããããŸããã§ããã
ããã¯ç§ãããããšã§ãïŒ
ãŸããæ¢åã®ãã¡ã€ã«ã¯äžæžããããªããããæ¢åã®confãã¡ã€ã«ãéªéã«ãªããªãå Žæã«ç§»åããŠãã ããã
mv /etc/kubernetes/admin.conf /backup
mv /etc/kubernetes/kubelet.conf /backup
mv /etc/kubernetes/controller-manager.conf /backup
mv /etc/kubernetes/scheduler.conf /backup
次ã«ããããã®ãã¡ã€ã«ãæŽæ°ããŸãã
user<strong i="13">@master</strong>:~$ sudo kubeadm alpha phase kubeconfig all --apiserver-advertise-address=<INSERT-YOUR-APISERVER-IP-HERE>
I0124 21:56:14.253641 15040 version.go:236] remote version is much newer: v1.13.2; falling back to: stable-1.12
[kubeconfig] Wrote KubeConfig file to disk: "/etc/kubernetes/admin.conf"
[kubeconfig] Wrote KubeConfig file to disk: "/etc/kubernetes/kubelet.conf"
[kubeconfig] Wrote KubeConfig file to disk: "/etc/kubernetes/controller-manager.conf"
[kubeconfig] Wrote KubeConfig file to disk: "/etc/kubernetes/scheduler.conf"
éçã·ã¹ãã ãããã«æ°ãã蚌ææžãé©çšããæãç°¡åãªæ¹æ³ã¯ããã¹ã¿ãŒãµãŒããŒãåèµ·åããããšã§ããã
client-certificate-data
ãšclient-key-data
ã/etc/kubernetes/admin.conf
ããããŒã«ã«ã®.kube/config
ã³ããŒããããšãå¿ããªãã§ãã ããã
ã圹ã«ç«ãŠãã°
ã¢ã³ãã¬ã¢ã¹
1.14.10ã§ãã®ã³ãã³ããå®è¡ããæ¹æ³ã¯ãããŸããïŒ ç§ãåŸãã®ã¯ïŒ
kubeadm alpha phase kubeconfig all --apiserver-advertise-address=192.168.102.170
Error: unknown flag: --apiserver-advertise-address
次ã«ãããã¥ã¡ã³ãã¯æ¬¡ã®ããã«è¿°ã¹ãŠããŸãã
kubeadm alpha phase kubeconfig all
ãããŠç§ã¯åŸãïŒ
This command is not meant to be run on its own. See list of available subcommands.
ããããšã
ããã«ã¡ã¯@provgregoryabdo ã
kubeadm version
åºåã¯äœã§ããïŒ
BRã¢ã³ãã¬ã¢ã¹
@provgregoryabdo phase
ã³ãã³ãã¯ã¢ã«ãã¡çãã移åããæ°ããããŒãžã§ã³ã§åæåããããã次ã®ãããªãã®ã䜿çšã§ããŸãã
kubeadm init phase kubeconfig all --apiserver-advertise-address=<your_address>
@adoerlerå©ããŠãããŠããããšãïŒ
æãåèã«ãªãã³ã¡ã³ã
/å²åœ
/ã©ã€ããµã€ã¯ã«ã¢ã¯ãã£ã
ç§ã¯ãã®åé¡ã«åãçµã¿å§ããŠããŸãã
察åŠãã¹ãããŸããŸãªãã€ã³ãããããŸãïŒ_ 2019幎5æ14æ¥æŽæ°_ïŒ
ãããŠãç§ã¯ããããã¹ãŠã«å¥ã ã®PRã§åãçµã¿ãŸã