Kubeadm: `kubeadm init --token-ttl 0`(ํ”Œ๋ž˜๊ทธ) ๋ฐ `tokenTTL: "0"`(๊ตฌ์„ฑ)์ด 1.8.0๋ถ€ํ„ฐ ์†์ƒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์— ๋งŒ๋“  2017๋…„ 10์›” 26์ผ  ยท  4์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: kubernetes/kubeadm

์ด๊ฒƒ์€ ๋ฒ„๊ทธ ๋ณด๊ณ ์„œ์ž…๋‹ˆ๊นŒ ์•„๋‹ˆ๋ฉด ๊ธฐ๋Šฅ ์š”์ฒญ์ž…๋‹ˆ๊นŒ?

๋ฒ„๊ทธ ๋ณด๊ณ ์„œ(https://github.com/kubernetes/kubernetes/issues/5363์— ์ œ์ถœ๋œ @rhuss ์˜ ๋ฌธ์ œ์—์„œ ๋ณต์‚ฌ)

๋ฒ„์ „

1.8.0 - ํ˜„์žฌ ๋งˆ์Šคํ„ฐ๊นŒ์ง€(2017-10-26)

๋ฌด์Šจ ์ผ์ด์—์š”?

kubeadm ํ† ํฐ ์ƒ์„ฑ์— ์˜ํ•ด ๋ฏธ๋ฆฌ ์ƒ์„ฑ๋œ ํ† ํฐ๊ณผ ํ•จ๊ป˜ kubeadm์„ ์‚ฌ์šฉํ•  ๋•Œ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ kubeadm์ด ํ† ํฐ์„ ์ƒ์„ฑํ•˜๋„๋ก ํ•˜๋Š” ๊ฒฝ์šฐ์—๋„ tokenTTL ๊ตฌ์„ฑ์ด ๋ฌด์‹œ๋ฉ๋‹ˆ๋‹ค. ๊ตฌ์„ฑ ํŒŒ์ผ์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  kubeadm init --token-ttl 0 ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ์—๋„ ๋งˆ์ฐฌ๊ฐ€์ง€์ž…๋‹ˆ๋‹ค.

๋ฌด์Šจ ์ผ์ด ์ผ์–ด๋‚  ๊ฒƒ์ด๋ผ๊ณ  ์˜ˆ์ƒํ–ˆ์Šต๋‹ˆ๊นŒ?

ํ† ํฐ์ด ๋งŒ๋ฃŒ๋˜์ง€ ์•Š๋Š” 0์˜ tokenTTL์„ ์ œ๊ณตํ•  ๋•Œ ์˜ˆ์ƒํ•ฉ๋‹ˆ๋‹ค.

์žฌํ˜„ํ•˜๋Š” ๋ฐฉ๋ฒ•(๊ฐ€๋Šฅํ•œ ํ•œ ์ตœ์†Œํ•œ์œผ๋กœ ์ •ํ™•ํ•˜๊ฒŒ)?

@rhuss๊ฐ€ ์ด๊ฒƒ์„ ๋ฉ‹์ง€๊ฒŒ ์„ค๋ช…ํ•œ https://github.com/kubernetes/kubernetes/issues/53637์„ ์ฐธ์กฐ

์šฐ๋ฆฌ๊ฐ€ ์•Œ์•„์•ผ ํ•  ๋‹ค๋ฅธ ๊ฒƒ์ด ์žˆ์Šต๋‹ˆ๊นŒ?

์ด ๋ฒ„๊ทธ๋Š” ๊ธฐ๋ณธ ํ† ํฐ TTL์ด ๋ณ€๊ฒฝ๋˜์—ˆ์„ ๋•Œ https://github.com/kubernetes/kubernetes/pull/48783 ์— ๋„์ž…๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

API ๊ธฐ๊ณ„ ๊ธฐ๋ณธ๊ฐ’ ์„ค์ • ๋ฉ”์ปค๋‹ˆ์ฆ˜์—๋Š” ์„ค์ •๋˜์ง€ ์•Š์€ ๊ฐ’๊ณผ ๋ช…์‹œ์ ์œผ๋กœ 0์œผ๋กœ ์„ค์ •๋œ ๊ฐ’์„ ๊ตฌ๋ณ„ํ•˜๋Š” ๋ฐฉ๋ฒ•์ด ์—†์Šต๋‹ˆ๋‹ค.

ํ•ด๋‹น ๋ณ€๊ฒฝ ์‚ฌํ•ญ์— ๋Œ€ํ•ด ์ˆ˜๋™ ํ…Œ์ŠคํŠธ๋ฅผ ์ผ๋ถ€ ์ˆ˜ํ–‰ํ–ˆ์ง€๋งŒ ๋ถ„๋ช…ํžˆ kubeadm token create --ttl 0 ๋Œ€ํ•ด์„œ๋งŒ MasterConfiguration ๊ธฐ๋ณธ๊ฐ’ ์„ค์ • ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ์ œ๋Œ€๋กœ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

kinbug prioritimportant-soon

๊ฐ€์žฅ ์œ ์šฉํ•œ ๋Œ“๊ธ€

ํ˜„์žฌ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์€ _after_ kubeadm init ์— ์ถ”๊ฐ€ ํ† ํฐ์„ ๋งŒ๋“œ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

kubeadm init --config /etc/kubernetes/kubeadm.yml
kubeadm token create --ttl 0 --groups system:bootstrappers:kubeadm:default-node-token --description "Bootstrap token which does not expire"

์ดํ›„ ํ† ํฐ์€ ๋…ธ๋“œ์—์„œ kubeadm join ์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋ชจ๋“  4 ๋Œ“๊ธ€

cc @kubernetes/sig-cluster-lifecycle-bugs
/์œ ํ˜• ๋ฒ„๊ทธ

ํ˜„์žฌ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์€ _after_ kubeadm init ์— ์ถ”๊ฐ€ ํ† ํฐ์„ ๋งŒ๋“œ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

kubeadm init --config /etc/kubernetes/kubeadm.yml
kubeadm token create --ttl 0 --groups system:bootstrappers:kubeadm:default-node-token --description "Bootstrap token which does not expire"

์ดํ›„ ํ† ํฐ์€ ๋…ธ๋“œ์—์„œ kubeadm join ์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋ฒ„๊ทธ ์ˆ˜์ •์— ๋Œ€ํ•ด @mattmoyer ์—๊ฒŒ ๊ฐ์‚ฌ๋“œ๋ฆฝ๋‹ˆ๋‹ค :๋ฐ•์ˆ˜:! ์Šน์ธ๋จ

์ด๊ฒƒ์€ master ์—์„œ ์ˆ˜์ •๋˜์—ˆ์œผ๋ฉฐ v1.8.3์— ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰