kubeadm ๋ฒ์ ( kubeadm version
์ฌ์ฉ):
ํ๊ฒฝ :
kubectl version
์ฌ์ฉ):v1.9.2uname -a
):linux 4.4.0-62-generickubeadm init๋ฅผ ์คํํ๋ ค๊ณ ํ๋ฉด ๋ค์๊ณผ ๊ฐ์ด ์ค๋จ๋ฉ๋๋ค.
xx@xx :~$ sudo kubeadm ์ด๊ธฐํ --kubernetes-version=v1.9.2
[์ด๊ธฐํ] Kubernetes ๋ฒ์ ์ฌ์ฉ: v1.9.2
[์ด๊ธฐํ] ๊ถํ ๋ถ์ฌ ๋ชจ๋ ์ฌ์ฉ: [๋ ธ๋ RBAC]
[์คํ ์ ] ์คํ ์ ๊ฒ์ฌ๋ฅผ ์คํํฉ๋๋ค.
[๊ฒฝ๊ณ FileExisting-crictl]: ์์คํ ๊ฒฝ๋ก์์ crictl์ ์ฐพ์ ์ ์์ต๋๋ค.
[ํ๋ฆฌํ๋ผ์ดํธ] kubelet ์๋น์ค ์์
[์ธ์ฆ์] CA ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ apiserver ์ธ์ฆ์ ๋ฐ ํค์ ๋๋ค.
[์ธ์ฆ์] apiserver ์๋น ์ธ์ฆ์๋ DNS ์ด๋ฆ [kickseed kubernetes kubernetes.default kubernetes.default.svc kubernetes.default.svc.cluster.local] ๋ฐ IP [10.96.0.1 172.17.41.15]์ ๋ํด ์๋ช ๋์์ต๋๋ค.
[์ธ์ฆ์] apiserver-kubelet-client ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] sa ํค์ ๊ณต๊ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ front-proxy-ca ์ธ์ฆ์ ๋ฐ ํค์ ๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ ํ๋ฐํธ ํ๋ก์ ํด๋ผ์ด์ธํธ ์ธ์ฆ์ ๋ฐ ํค์ ๋๋ค.
[์ธ์ฆ์] ์ ํจํ ์ธ์ฆ์ ๋ฐ ํค๊ฐ ์ด์ "/etc/kubernetes/pki"์ ์์ต๋๋ค.
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "admin.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "kubelet.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "controller-manager.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "scheduler.conf"
[controlplane] ๊ตฌ์ฑ ์์ kube-apiserver์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-apiserver.yaml"์ ์์ฑํ์ต๋๋ค.
[controlplane] ๊ตฌ์ฑ ์์ kube-controller-manager์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-controller-manager.yaml"์ ์์ฑํ์ต๋๋ค.
[์ ์ดํ] ๊ตฌ์ฑ ์์ kube-scheduler์ ๋ํ ์ ์ ํฌ๋ ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-scheduler.yaml"์ ์์ฑํ์ต๋๋ค.
[etcd] ๋ก์ปฌ etcd ์ธ์คํด์ค์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/etcd.yaml"์ ์์ฑํ์ต๋๋ค.
[์ด๊ธฐํ] kubelet์ด "/etc/kubernetes/manifests" ๋๋ ํ ๋ฆฌ์์ Static Pod๋ก ์ปจํธ๋กค ํ๋ ์ธ์ ๋ถํ ํ๊ธฐ๋ฅผ ๊ธฐ๋ค๋ฆฝ๋๋ค.
[์ด๊ธฐํ] ์ ์ด ํ๋ฉด ์ด๋ฏธ์ง๋ฅผ ๊ฐ์ ธ์์ผ ํ๋ ๊ฒฝ์ฐ 1๋ถ ์ด์ ๊ฑธ๋ฆด ์ ์์ต๋๋ค.
๊ทธ๋ฐ ๋ค์ kubelet ๋ก๊ทธ๋ฅผ ํ์ธํฉ๋๋ค.
xx@xx :~$ sudo journalctl -xeu kubelet:
Jan 31 14:45:03 kickseed kubelet[28516]: E0131 14:45:03.280984 28516 remote_runtime.go:92] ๋ฐํ์ ์๋น์ค์ RunPodSandbox ์คํจ: rpc ์ค๋ฅ: ์ฝ๋ = ์ ์ ์๋ ์ค๋ช
= ์ด๋ฏธ์ง "gcr.io/google์ ๊ฐ์ ธ์ค์ง ๋ชปํ์ต๋๋ค. pause-amd64:3.0": ๋ฐ๋ชฌ์ ์ค๋ฅ ์๋ต: https://gcr.io/v1/_ping ๊ฐ์ ธ์ค๊ธฐ: ๋ค์ด์ผ tcp 172.217.6.127:443: i/o ์๊ฐ ์ด๊ณผ
1์ 31์ผ 14:45:03 kickseed kubelet[28516]: E0131 14:45:03.281317 28516 kuberuntime_sandbox.go:54] "kube-scheduler-kickseed_kube-system074์ ๋ํ CreatePodSandbox" = "gcr.io/google_containers/pause-amd64:3.0" ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ ์คํจ: ๋ฐ๋ชฌ์ ์ค๋ฅ ์๋ต: Get https://gcr.io/v1/_ping : ๋ค์ด์ผ tcp 172.217.6.127:443: i/o ์๊ฐ ์ด๊ณผ
1์ 31์ผ 14:45:03 kickseed kubelet[28516]: E0131 14:45:03.281580 28516 kuberuntime_manager.go:647] createPodcd60 codecdcd60 "kube-scheduler-kickseed_kube-system(6)์ ๋ํ codecdcd6b0 codecd60" = "gcr.io/google_containers/pause-amd64:3.0" ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ ์คํจ: ๋ฐ๋ชฌ์ ์ค๋ฅ ์๋ต: Get https://gcr.io/v1/_ping : ๋ค์ด์ผ tcp 172.217.6.127:443: i/o ์๊ฐ ์ด๊ณผ
1 ์ 31 ์ผ 14:45:03 [28516] : E0131 14 : 45 : 03.281875 28516 Pod_Workers.go : 186.281875 28516 Pod_Workers.go : 186 Pod Syncing Pod 69C12074E336B0DBD074E336B0DBBD0A1666CE05226A ( "Kube-Scheduler-kickseed_kube-system (69C12074E336B0DBBD0A166CE05226A ์์คํ
)"), ๊ฑด๋ ๋ฐ๊ธฐ : " \"kube-scheduler-kickseed_kube-system(69c12074e336b0dbbd0a1666ce05226a)"์ ๋ํ CreatePodSandbox ์คํจ: \"kube-scheduler-kickseed_c31-system(709)์ ๋ํ CreatePodSandbox = deknownsandboxError: "CreatePodSandbox\"code0bb ๊ฐ์ ธ์ค๊ธฐ "gcr.io/google_containers/pause-amd64:3.0\": ๋ฐ๋ชฌ์ ์ค๋ฅ ์๋ต: Get https://gcr.io/v1/_ping : ๋ค์ด์ผ tcp 172.217.6.127:443: i/o ์๊ฐ ์ด๊ณผ"
Jan 31 14:45:03 kickseed kubelet[28516]: E0131 14:45:03.380290 28516 event.go:209] ์ด๋ฒคํธ๋ฅผ ์ธ ์ ์์: 'ํจ์น https://172.17.41.15:6443/namesapi/v1 /events/kickseed.150ecf46afb098b7: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ๋จ'(์ ์๊ธฐ ํ ๋ค์ ์๋ํ ์ ์์)
1์ 31์ผ 14:45:03 kickseed kubelet[28516]: E0131 14:45:03.933783 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: *v๋ฅผ ๋์ดํ์ง ๋ชปํ์ต๋๋ค. ํฌ๋: ๊ฐ์ ธ์ค๊ธฐ https://172.17.41.15 :6443/api/v1/pods?fieldSelector=spec.nodeName%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
1์ 31์ผ 14:45:03 kickseed kubelet[28516]: E0131 14:45:03.934707 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:474: ๋
ธ๋ ๋์ด ์คํจ *v Get https://172.17.41.15 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
1์ 31์ผ 14:45:03 kickseed kubelet[28516]: E0131 14:45:03.935921 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:465: ์๋น์ค๋ฅผ ๋์ดํ์ง ๋ชปํ์ต๋๋ค. Get https://172.17.41.15 :6443/api/v1/services?limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:45:04 kickseed kubelet[28516]: E0131 14:45:04.281024 28516 remote_runtime.go:92] ๋ฐํ์ ์๋น์ค์ RunPodSandbox ์คํจ: rpc ์ค๋ฅ: ์ฝ๋ = ์ ์ ์๋ ์ค๋ช
= ์ด๋ฏธ์ง "gcr.io/google์ ๊ฐ์ ธ์ค์ง ๋ชปํ์ต๋๋ค. pause-amd64:3.0": ๋ฐ๋ชฌ์ ์ค๋ฅ ์๋ต: https://gcr.io/v1/_ping ๊ฐ์ ธ์ค๊ธฐ: ๋ค์ด์ผ tcp 172.217.6.127:443: i/o ์๊ฐ ์ด๊ณผ
Jan 31 14:45:04 kickseed kubelet[28516]: E0131 14:45:04.281352 28516 kuberuntime_sandbox.go:54] CreatePodSandbox for pod "kube-controller-manager-kickseed_kube-system(65516) ์ ์ ์๋ ์ค๋ช
= "gcr.io/google_containers/pause-amd64:3.0" ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ ์คํจ: ๋ฐ๋ชฌ์ ์ค๋ฅ ์๋ต: https://gcr.io/v1/_ping ๊ฐ์ ธ์ค๊ธฐ: ๋ค์ด์ผ tcp 172.217.6.127:443: i/o ์๊ฐ ์ด๊ณผ
1์ 31์ผ 14:45:04 kickseed kubelet[28516]: E0131 14:45:04.281634 28516 kuberuntime_manager.go:647] pod "kube-controller-manager-kickseed_kube-647"์ ๋ํ createPodcfcee6 error5dccfe6 error5dpcfee2004 ์ ์ ์๋ ์ค๋ช
= "gcr.io/google_containers/pause-amd64:3.0" ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ ์คํจ: ๋ฐ๋ชฌ์ ์ค๋ฅ ์๋ต: https://gcr.io/v1/_ping ๊ฐ์ ธ์ค๊ธฐ: ๋ค์ด์ผ tcp 172.217.6.127:443: i/o ์๊ฐ ์ด๊ณผ
1 ์ 31 ์ผ 14:45:04 kickeed kubelet [28516] : e0131 14 : 45 : 04.281938 28516 Pod_Workers.go : 186.Go.Go : 186.114 : 04.281938 28516 Pod_Workers.go : Pod 6546D6Faf0B50C9FC6712CE25EE9B6CB ( "Kube-Controller-Manager-Kickseed_Kube-system (6546D6FAF0B50C9FC6712CE25EE9B6CB)"), ๊ฑด๋ ๋ฐ๊ธฐ : ์คํจ = "kube-controller-manager-kickseed_kube-system(6546d6faf0b50c9fc6712ce25ee9b6cb)"์ ๋ํ "CreatePodSandbox"์ ์คํจ: CreatePodSandboxError: "CreatePodSandbox for pod \"kube-controller\manager-kickseed_kube6) desc = ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ ์คํจ \"gcr.io/google_containers/pause-amd64:3.0\": ๋ฐ๋ชฌ์ ์ค๋ฅ ์๋ต: https://gcr.io/v1/_ping ๊ฐ์ ธ์ค๊ธฐ: ๋ค์ด์ผ tcp 172.217.6.127:443: i/o ์๊ฐ ์ด๊ณผ"
Jan 31 14:45:04 kickseed kubelet[28516]: E0131 14:45:04.934694 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: *v ๋์ด์ ์คํจํ์ต๋๋ค. ํฌ๋: ๊ฐ์ ธ์ค๊ธฐ https://172.17.41.15 :6443/api/v1/pods?fieldSelector=spec.nodeName%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
1์ 31์ผ 14:45:04 kickseed kubelet[28516]: E0131 14:45:04.935613 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:471: ๋
ธ๋ ๋์ด ์คํจ *v Get https://172.17.41.15 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
1์ 31์ผ 14:45:04 kickseed kubelet[28516]: E0131 14:45:04.936669 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:465: ์๋น์ค๋ฅผ ๋์ดํ์ง ๋ชปํ์ต๋๋ค. Get https://172.17.41.15 :6443/api/v1/services?limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:45:05 kickseed kubelet[28516]: W0131 14:45:05.073692 28516 cni.go:171] cni ๊ตฌ์ฑ์ ์
๋ฐ์ดํธํ ์ ์์: /etc/cni/net.d์ ๋คํธ์ํฌ๊ฐ ์์ต๋๋ค.
Jan 31 14:45:05 kickseed kubelet[28516]: E0131 14:45:05.074106 28516 kubelet.go:2105] ์ปจํ
์ด๋ ๋ฐํ์ ๋คํธ์ํฌ๊ฐ ์ค๋น๋์ง ์์: NetworkReady=false ์ด์ :NetworkPluginNotReady ๋ฉ์์ง๊ฐ ์ค๋น๋์ง ์์:docker : ๋คํธ์ํฌ ํ๋ฌ๊ทธ์ธ ์ด๊ธฐํ๋์ง ์์
1์ 31์ผ 14:45:05 kickseed kubelet[28516]: E0131 14:45:05.935680 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: *v๋ฅผ ๋์ดํ์ง ๋ชปํ์ต๋๋ค. ํฌ๋: ๊ฐ์ ธ์ค๊ธฐ https://172.17.41.15 :6443/api/v1/pods?fieldSelector=spec.nodeName%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:45:05 kickseed kubelet[28516]: E0131 14:45:05.937423 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:474: ๋
ธ๋ ๋์ด ์คํจ *v Get https://172.17.41.15 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
1์ 31์ผ 14:45:05 kickseed kubelet[28516]: E0131 14:45:05.937963 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:465: ์๋น์ค๋ฅผ ๋์ดํ์ง ๋ชปํ์ต๋๋ค. Get https://172.17.41.15 :6443/api/v1/services?limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:45:05 kickseed kubelet[28516]: I0131 14:45:05.974034 28516 kubelet_node_status.go:273] ๋ณผ๋ฅจ ์ปจํธ๋กค๋ฌ ์ฐ๊ฒฐ/๋ถ๋ฆฌ๋ฅผ ํ์ฑํํ๊ธฐ ์ํ ๋
ธ๋ ์ฃผ์ ์ค์
Jan 31 14:45:06 kickseed kubelet[28516]: I0131 14:45:06.802447 28516 kubelet_node_status.go:273] ๋ณผ๋ฅจ ์ปจํธ๋กค๋ฌ ์ฐ๊ฒฐ/๋ถ๋ฆฌ๋ฅผ ํ์ฑํํ๊ธฐ ์ํ ๋
ธ๋ ์ฃผ์ ์ค์
Jan 31 14:45:06 kickseed kubelet[28516]: I0131 14:45:06.804242 28516 kubelet_node_status.go:82] ๋
ธ๋ ํฅ์๋ ๋ฑ๋ก ์๋
Jan 31 14:45:06 kickseed kubelet[28516]: E0131 14:45:06.804778 28516 kubelet_node_status.go:106] API ์๋ฒ์ "kickseed" ๋
ธ๋๋ฅผ ๋ฑ๋กํ ์ ์์: Post https ://1743.157.4 v1/๋
ธ๋: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: con
xx@xx :~$ sudo systemctl ์ํ kubelet:
kubelet.service - kubelet: Kubernetes ๋
ธ๋ ์์ด์ ํธ
๋ก๋๋จ: ๋ก๋๋จ(/lib/systemd/system/kubelet.service; ํ์ฑํ๋จ, ๊ณต๊ธ์
์ฒด ์ฌ์ ์ค์ : ํ์ฑํ๋จ)
๋๋กญ์ธ: /etc/systemd/system/kubelet.service.d
โโ11-kubeadm.conf, 10-kubeadm1.conf, 90-local-extras.conf
ํ์ฑ: ํ์ฑ(์คํ ์ค) ์ดํ Wed 2018-01-31 13:53:46 CST; 49๋ถ ์
๋ฌธ์: http://kubernetes.io/docs/
๋ฉ์ธ PID: 28516(kubelet)
์์
: 13
๋ฉ๋ชจ๋ฆฌ: 37.8M
CPU: 22.767์ด
C๊ทธ๋ฃน: /system.slice/kubelet.service
โโ28516 /usr/bin/kubelet --bootstrap-kubeconfig=/etc/kubernetes/bootstrap-kubelet.conf --kubeconfig=/etc/kubernetes/kubelet.conf --pod-manifest-path=/etc/kubernetes/ ๋งค๋ํ์คํธ --allow-privileged=true --cgroup-driver=cgroupfs --network-plugin=cni --cni-conf-dir=/etc/cni/net.d --cni-bin-dir=/opt/cni /bin --cluster-dns=10.96.0.10 --cluster-domain=cluster.local --authorization-mode=Webhook --client-ca-file=/etc/kubernetes/pki/ca.crt --cadvisor-port =0 --rotate-certificates=true --cert-dir=/var/lib/kubelet/pki --fail-swap-on=false
1์ 31์ผ 14:43:17 kickseed kubelet[28516]: E0131 14:43:17.862590 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:474: ๋
ธ๋ ๋์ด ์คํจ *v Get https://172.17.41.15 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
1์ 31์ผ 14:43:17 kickseed kubelet[28516]: E0131 14:43:17.863474 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:465: ์๋น์ค๋ฅผ ๋์ดํ์ง ๋ชปํ์ต๋๋ค. Get https://172.17.41.15 :6443/api/v1/services?limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:43:18 kickseed kubelet[28516]: E0131 14:43:18.621818 28516 event.go:209] ์ด๋ฒคํธ๋ฅผ ์ธ ์ ์์: 'ํจ์น https://172.17.41.15:6443/namesapi/v1 /events/kickseed.150ecf46afb098b7: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ๋จ'(์ ์๊ธฐ ํ ๋ค์ ์๋ํ ์ ์์)
Jan 31 14:43:18 kickseed kubelet[28516]: E0131 14:43:18.862440 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: *v๋ฅผ ๋์ดํ์ง ๋ชปํ์ต๋๋ค. ํฌ๋: ๊ฐ์ ธ์ค๊ธฐ https://172.17.41.15 :6443/api/v1/pods?fieldSelector=spec.nodeName%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:43:18 kickseed kubelet[28516]: E0131 14:43:18.863379 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:474: ๋
ธ๋ ๋์ด ์คํจ *v Get https://172.17.41.15 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:43:18 kickseed kubelet[28516]: E0131 14:43:18.864424 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:465: ์๋น์ค ๋์ด ์คํจ Get https://172.17.41.15 :6443/api/v1/services?limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:43:19 kickseed kubelet[28516]: E0131 14:43:19.255460 28516 eviction_manager.go:238] ํด๊ฑฐ ๊ด๋ฆฌ์: ์๊ธฐ์น ์์ ์ค๋ฅ: ๋
ธ๋ ์ ๋ณด๋ฅผ ๊ฐ์ ธ์ค์ง ๋ชปํ์ต๋๋ค: ๋
ธ๋ "kickseed"๋ฅผ ์ฐพ์ ์ ์์
1์ 31์ผ 14:43:19 kickseed kubelet[28516]: E0131 14:43:19.863266 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: *v๋ฅผ ๋์ดํ์ง ๋ชปํ์ต๋๋ค. ํฌ๋: ๊ฐ์ ธ์ค๊ธฐ https://172.17.41.15 :6443/api/v1/pods?fieldSelector=spec.nodeName%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
1์ 31์ผ 14:43:19 kickseed kubelet[28516]: E0131 14:43:19.864238 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:474: ๋
ธ๋ ๋์ด ์คํจ *v Get https://172.17.41.15 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkickseed&limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
Jan 31 14:43:19 kickseed kubelet[28516]: E0131 14:43:19.865262 28516 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:465: ์๋น์ค ๋์ด ์คํจ Get https://172.17.41.15 :6443/api/v1/services?limit=500&resourceVersion=0: ๋ค์ด์ผ tcp 172.17.41.15:6443: getsockopt: ์ฐ๊ฒฐ ๊ฑฐ๋ถ
์ผ๋ถ ๋์ปค ์ด๋ฏธ์ง๋ ๋ค์๊ณผ ๊ฐ์ด ๋์ด๋ฉ๋๋ค.
gcr.io/google_containers/kube-apiserver-amd64:v1.9.2
gcr.io/google_containers/kube-controller-manager-amd64:v1.9.2
gcr.io/google_containers/kube-scheduler-amd64:v1.9.2
gcr.io/google_containers/kube-proxy-amd64:v1.9.2
gcr.io/google_containers/etcd-amd64:3.2.14
gcr.io/google_containers/pause-amd64:3.1
gcr.io/google_containers/kube-dnsmasq-amd64:1.4.1
gcr.io/google_containers/kubernetes-dashboard-amd64:v1.8.2
gcr.io/google_containers/kubedns-amd64:1.9
gcr.io/google_containers/kube-discovery-amd64:1.0
gcr.io/google_containers/exechealthz-amd64:v1.2.0
gcr.io/google_containers/k8s-dns-kube-dns-amd64:1.14.8
gcr.io/google_containers/k8s-dns-dnsmasq-nanny-amd64:1.14.8
gcr.io/google_containers/k8s-dns-sidecar-amd64:1.14.8
gcr.io/google_containers/dnsmasq-metrics-amd64:1.0.1
kubeadm ์ด๊ธฐํ๊ฐ ์๋ฃ๋์ด์ผ ํฉ๋๋ค.
Ubuntu 16.04 ๋ฐ kubeadm 1.9.2๊ฐ ์๋ virtualbox
์์ ๋์ด๋ ์ด๋ฌํ ๋์ปค ์ด๋ฏธ์ง๋ "kubeadm init --kubernetes-version v1.9.2"๋ฅผ ์คํํ๊ธฐ ์ ์ ๋ด ๊ฐ์ธ ์ ์ฅ์์์ ๊ฐ์ ธ์์ต๋๋ค. GFW๋ก ์ธํด gcr.io/google-containers์ ์ง์ ์ก์ธ์คํ ์ ์์ต๋๋ค.
์ฌ๊ธฐ์๋ ๊ฐ์ ๋ฌธ์ !
CentOS 7์์ ๋์ผํ ๋ฌธ์ ๊ฐ ์์ต๋๋ค.
+1
+1
+1
+1
vultr์ ์๋ฒ๋ ์ฌ๊ธฐ์ ๋ถ์ด ์์ต๋๋ค.
+1
+1
+1
ํด๊ฒฐ ๋ฐฉ๋ฒ์ผ๋ก
1/ ์ฟ ๋ฒ๋คํฐ์ค ๋ง์คํฐ์ ๋์ปค ๋ ์ง์คํธ๋ฆฌ ์์ฑ
2/ /etc/hosts์์ kubernetes ๋ง์คํฐ๋ฅผ gcr.io๋ก ์ ์ธํฉ๋๋ค.
3/ ์ธํฐ๋ท์ ์ฐ๊ฒฐ๋ ์ปดํจํฐ์์ ggogle ํด๋ผ์ฐ๋์ ๋ก๊ทธ์จํ๊ณ ์ด๋ฏธ์ง๋ฅผ ๋ค์ด๋ก๋ํฉ๋๋ค.
์:
gloud docker -- pull gcrio/goole_container/pause-amd64:3.0
gloud docker -- save -o /tmp/pause-amd.tar gcrio/goole_container/pause-amd64:3.0
4/ docker repo ๋ ์ง์คํธ๋ฆฌ์ ์ด๋ฏธ์ง ์
๋ก๋
๋์ปค ๋ก๋ -i /tmp/pause-amd64.tar
๋์ปค ํ๊ทธ gcr.io/Google_containers/pause-amd64:3.0 yourdoke ๋ฑ๋ก:pause-amd64 :3.0
docker push yourdoke ๋ ์ง์คํธ๋ฆฌ:pause-amd64 :3.0
5/ kebernetes ๋ง์คํฐ์์ gcr.io ๋์ปค ๋ ์ง์คํธ๋ฆฌ๋ก
๋์ปค ๋ ์ง์คํธ๋ฆฌ ๋ฆฌํฌ์งํ ๋ฆฌ์์ ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ
docker pull yourdocke rregistry:pause-amd64 :3.0
๋ก์ปฌ gcr.io ๋์ปค ๋ ์ง์คํธ๋ฆฌ๋ก ๊ฐ์ ธ์ค๊ธฐ
๋์ปค ํ๊ทธ yourdocke rregistry:pause-amd64 :3.0 gcr.io/google_containers/pause-amd64:3.0
๋์ปค ํธ์ gcr.io/google_containers/pause-amd64:3.0
kubeadm init ์์ ์ฌ์ฉํ๋ ๋ชจ๋ ์ด๋ฏธ์ง๋ฅผ ๋ค์ด๋ก๋ํ์ญ์์ค. /etc/kubernetes/manifest/*.yaml์ ์ฐธ์กฐํ์ญ์์ค.
1.9.3์์ ์์ ๋์๋์?
+1
+1 - kubeadm init๋ฅผ ๋ ๋ฒ์งธ ์คํํ ๋๋ง ๋ํ๋ฉ๋๋ค. ์ฒ์์ ๊ทธ๋ฅ ์ ๋์ด๊ฐ๋๋ค. kubeadm reset์ผ๋ก ์ ๋๋ก ์ ๋ฆฌ๋์ง ์์ ์ฒซ ๋ฒ์งธ ์คํ์์ ์ฝ๊ฐ์ ์ํ๊ฐ ์๋์ง ํ์คํ์ง ์์ต๋๋ค.
+1
centos 7 ๋ฐ /etc/env์ ํ๋ก์๋ฅผ ์ค์ ํ ๋ค์ ๐๋ก ํ์ํฉ๋๋ค.
+1
๋์ผํ ๋ฌธ์ ๊ฐ ์์ต๋๋ค. Centos7, ์ต์ kube ์ค์น(1.9.3), hightower ๋ฌธ์ ๋ฐ ๋ชจ๋ kubernetes ๋ฌธ์๋ฅผ ์๋ํ์ต๋๋ค. etcd์ flannel์ ์๋ํ๊ณ ์ด์์์ต๋๋ค. NO_PROXY ํ๊ฒฝ ๋ณ์๋ฅผ ์ฌ์ฉํ์ฌ ๋ค๋ฅธ ์ฐ๊ฒฐ์ ๋ํ ํ๋ก์ ์ฐ๊ฒฐ์ ์๋ํ์ง ์๋๋ก ์ธ๋ถ IP๋ฅผ ์ ๋ ฅํ์ง๋ง ์ค์ ๋ก๋ ํด๋น ์ง์ ์ ๋๋ฌํ์ง ์๊ณ ์์ ๋ค๋ฅธ ๋ชจ๋ ์ฌ๋๊ณผ ๋์ผํ ์ค๋ฅ๊ฐ ๋ฐ์ํฉ๋๋ค.
+1
๋์ผํ ๋ฌธ์ ๊ฐ ์์ต๋๋ค. centos 7, kubelet v1.9.3;
ํ์ง๋ง ์ด๋ฏธ์ง๊ฐ ์ฑ๊ณต์ ์ผ๋ก ๋ค์ด๋ก๋ ๋ ๊ฒ ๊ฐ์ต๋๋ค.
docker images
gcr.io/google_containers/kube-apiserver-amd64 v1.9.3 360d55f91cbf 4 weeks ago 210.5 MB
gcr.io/google_containers/kube-controller-manager-amd64 v1.9.3 83dbda6ee810 4 weeks ago 137.8 MB
gcr.io/google_containers/kube-scheduler-amd64 v1.9.3 d3534b539b76 4 weeks ago 62.71 MB
gcr.io/google_containers/etcd-amd64 3.1.11 59d36f27cceb 3 months ago 193.9 MB
gcr.io/google_containers/pause-amd64 3.0 99e59f495ffa 22 months ago 746.9 kB
์ฌ๊ธฐ์ CentOS 7 vm์ด ์๊ณ ์ด๋ฏธ ํ๋ก์ ์๋ฒ๋ก ๊ตฌ์ฑํ์ต๋๋ค.
๋๋ ๊ฐ์ ์๊ฐ ์ด๊ณผ ๋ฉ์์ง๋ฅผ ๋ฐ์์ง๋ง ๋์ปค ์ด๋ฏธ์ง๋ฅผ ๊ฐ์ ธ์ ์คํ ์ค์
๋๋ค.
์ ๋ ๊ฐ์ ๋ฌธ์ ๋ฅผ ๊ฒช๊ณ ์์ต๋๋ค. ์์ธํ ๋ด์ฉ์ ์ถ๋ ฅ ๋ฐ ๋ก๊ทธ๋ฅผ ์ฐธ์กฐํ์ญ์์ค.
```[ root@kube01 ~]# kubeadm ์ด๊ธฐํ
[์ด๊ธฐํ] Kubernetes ๋ฒ์ ์ฌ์ฉ: v1.9.3
[์ด๊ธฐํ] ๊ถํ ๋ถ์ฌ ๋ชจ๋ ์ฌ์ฉ: [๋
ธ๋ RBAC]
[์คํ ์ ] ์คํ ์ ๊ฒ์ฌ๋ฅผ ์คํํฉ๋๋ค.
[๊ฒฝ๊ณ ํธ์คํธ ์ด๋ฆ]: ํธ์คํธ ์ด๋ฆ "kube01"์ ์ฐ๊ฒฐํ ์ ์์ต๋๋ค.
[๊ฒฝ๊ณ ํธ์คํธ ์ด๋ฆ]: ํธ์คํธ ์ด๋ฆ "kube01" ์กฐํ kube01 on 10.10.0.81:53: ์๋ฒ ์ค์๋
[๊ฒฝ๊ณ FileExisting-crictl]: ์์คํ
๊ฒฝ๋ก์์ crictl์ ์ฐพ์ ์ ์์ต๋๋ค.
[ํ๋ฆฌํ๋ผ์ดํธ] kubelet ์๋น์ค ์์
[์ธ์ฆ์] CA ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ apiserver ์ธ์ฆ์ ๋ฐ ํค์
๋๋ค.
[์ธ์ฆ์] apiserver ์๋น ์ธ์ฆ์๋ DNS ์ด๋ฆ [kube01 kubernetes kubernetes.default kubernetes.default.svc kubernetes.default.svc.cluster.local] ๋ฐ IP [10.96.0.1 10.25.123.11]์ ๋ํด ์๋ช
๋์์ต๋๋ค.
[์ธ์ฆ์] apiserver-kubelet-client ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] sa ํค์ ๊ณต๊ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ front-proxy-ca ์ธ์ฆ์ ๋ฐ ํค์
๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ ํ๋ฐํธ ํ๋ก์ ํด๋ผ์ด์ธํธ ์ธ์ฆ์ ๋ฐ ํค์
๋๋ค.
[์ธ์ฆ์] ์ ํจํ ์ธ์ฆ์ ๋ฐ ํค๊ฐ ์ด์ "/etc/kubernetes/pki"์ ์์ต๋๋ค.
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "admin.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "kubelet.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "controller-manager.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "scheduler.conf"
[controlplane] ๊ตฌ์ฑ ์์ kube-apiserver์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-apiserver.yaml"์ ์์ฑํ์ต๋๋ค.
[controlplane] ๊ตฌ์ฑ ์์ kube-controller-manager์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-controller-manager.yaml"์ ์์ฑํ์ต๋๋ค.
[์ ์ดํ] ๊ตฌ์ฑ ์์ kube-scheduler์ ๋ํ ์ ์ ํฌ๋ ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-scheduler.yaml"์ ์์ฑํ์ต๋๋ค.
[etcd] ๋ก์ปฌ etcd ์ธ์คํด์ค์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/etcd.yaml"์ ์์ฑํ์ต๋๋ค.
[์ด๊ธฐํ] kubelet์ด "/etc/kubernetes/manifests" ๋๋ ํ ๋ฆฌ์์ Static Pod๋ก ์ปจํธ๋กค ํ๋ ์ธ์ ๋ถํ
ํ๊ธฐ๋ฅผ ๊ธฐ๋ค๋ฆฝ๋๋ค.
[์ด๊ธฐํ] ์ ์ด ํ๋ฉด ์ด๋ฏธ์ง๋ฅผ ๊ฐ์ ธ์์ผ ํ๋ ๊ฒฝ์ฐ 1๋ถ ์ด์ ๊ฑธ๋ฆด ์ ์์ต๋๋ค.
In the meantime, while watching `docker ps` this is what I see:
***Note:*** Don't mind the length of time that the containers have been up โ this is my third attempt and it's always the same.
```CONTAINER ID IMAGE
COMMAND CREATED STATUS PORTS NAMES
c422b3fd67f9 gcr.io/google_containers/kube-apiserver-amd64<strong i="5">@sha256</strong>:a5382344aa373a90bc87d3baa4eda5402507e8df5b8bfbbad392c4fff715f0
43 "kube-apiserver --req" About a minute ago Up About a minute k8s_kube-apiserver_kube-apiserver-k
ube01_kube-system_3ff6faac27328cf290a026c08ae0ce75_1
4b30b98bcc24 gcr.io/google_containers/kube-controller-manager-amd64<strong i="6">@sha256</strong>:3ac295ae3e78af5c9f88164ae95097c2d7af03caddf067cb35599
769d0b7251e "kube-controller-mana" 2 minutes ago Up 2 minutes k8s_kube-controller-manager_kube-co
ntroller-manager-kube01_kube-system_d556d9b8ccdd523a5208b391ca206031_0
71c6505ed125 gcr.io/google_containers/kube-scheduler-amd64<strong i="7">@sha256</strong>:2c17e637c8e4f9202300bd5fc26bc98a7099f49559ca0a8921cf692ffd4a16
75 "kube-scheduler --add" 2 minutes ago Up 2 minutes k8s_kube-scheduler_kube-scheduler-k
ube01_kube-system_6502dddc08d519eb6bbacb5131ad90d0_0
9d01e2de4686 gcr.io/google_containers/pause-amd64:3.0
"/pause" 3 minutes ago Up 2 minutes k8s_POD_kube-controller-manager-kub
e01_kube-system_d556d9b8ccdd523a5208b391ca206031_0
7fdaabc7e2a7 gcr.io/google_containers/pause-amd64:3.0
"/pause" 3 minutes ago Up 2 minutes k8s_POD_kube-apiserver-kube01_kube-
system_3ff6faac27328cf290a026c08ae0ce75_0
a5a2736e6cd0 gcr.io/google_containers/pause-amd64:3.0
"/pause" 3 minutes ago Up 2 minutes k8s_POD_kube-scheduler-kube01_kube-
system_6502dddc08d519eb6bbacb5131ad90d0_0
ea82cd3a27da gcr.io/google_containers/pause-amd64:3.0
"/pause" 3 minutes ago Up 2 minutes k8s_POD_etcd-kube01_kube-system_727
8f85057e8bf5cb81c9f96d3b25320_0
I0309 19:59:29.570990 1 server.go:121] Version: v1.9.3
I0309 19:59:29.756611 1 feature_gate.go:190] feature gates: map[Initializers:true]
I0309 19:59:29.756680 1 initialization.go:90] enabled Initializers feature as part of admission plugin setup
I0309 19:59:29.760396 1 master.go:225] Using reconciler: master-count
W0309 19:59:29.789648 1 genericapiserver.go:342] Skipping API batch/v2alpha1 because it has no resources.
W0309 19:59:29.796731 1 genericapiserver.go:342] Skipping API rbac.authorization.k8s.io/v1alpha1 because it has no resources.
W0309 19:59:29.797445 1 genericapiserver.go:342] Skipping API storage.k8s.io/v1alpha1 because it has no resources.
W0309 19:59:29.804841 1 genericapiserver.go:342] Skipping API admissionregistration.k8s.io/v1alpha1 because it has no resources.
[restful] 2018/03/09 19:59:29 log.go:33: [restful/swagger] listing is available at https://10.25.123.11:6443/swaggerapi
[restful] 2018/03/09 19:59:29 log.go:33: [restful/swagger] https://10.25.123.11:6443/swaggerui/ is mapped to folder /swagger-ui/
[restful] 2018/03/09 19:59:30 log.go:33: [restful/swagger] listing is available at https://10.25.123.11:6443/swaggerapi
[restful] 2018/03/09 19:59:30 log.go:33: [restful/swagger] https://10.25.123.11:6443/swaggerui/ is mapped to folder /swagger-ui/
I0309 19:59:32.393800 1 serve.go:89] Serving securely on [::]:6443
I0309 19:59:32.393854 1 apiservice_controller.go:112] Starting APIServiceRegistrationController
I0309 19:59:32.393866 1 cache.go:32] Waiting for caches to sync for APIServiceRegistrationController controller
I0309 19:59:32.393965 1 controller.go:84] Starting OpenAPI AggregationController
I0309 19:59:32.393998 1 crdregistration_controller.go:110] Starting crd-autoregister controller
I0309 19:59:32.394012 1 controller_utils.go:1019] Waiting for caches to sync for crd-autoregister controller
I0309 19:59:32.394034 1 customresource_discovery_controller.go:152] Starting DiscoveryController
I0309 19:59:32.394057 1 naming_controller.go:274] Starting NamingConditionController
I0309 19:59:32.393855 1 crd_finalizer.go:242] Starting CRDFinalizer
I0309 19:59:32.394786 1 available_controller.go:262] Starting AvailableConditionController
I0309 19:59:32.394815 1 cache.go:32] Waiting for caches to sync for AvailableConditionController controller
I0309 20:00:06.434318 1 trace.go:76] Trace[12318713]: "Create /api/v1/nodes" (started: 2018-03-09 19:59:32.431463052 +0000 UTC m=+2.986431803) (total time: 34.002792758s):
Trace[12318713]: [4.00201898s] [4.001725343s] About to store object in database
Trace[12318713]: [34.002792758s] [30.000773778s] END
E0309 20:00:32.406206 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *core.LimitRange: the server was unable to return a response in the time allotted, but may still be processing the request (get limitranges)
E0309 20:00:32.406339 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *core.Secret: the server was unable to return a response in the time allotted, but may still be processing the request (get secrets)
E0309 20:00:32.406342 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/kube-aggregator/pkg/client/informers/internalversion/factory.go:73: Failed to list *apiregistration.APIService: the server was unable to return a response in the time allotted, but may still be processing the request (get apiservices.apiregistration.k8s.io)
E0309 20:00:32.408094 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *core.Pod: the server was unable to return a response in the time allotted, but may still be processing the request (get pods)
E0309 20:00:32.415692 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *core.PersistentVolume: the server was unable to return a response in the time allotted, but may still be processing the request (get persistentvolumes)
E0309 20:00:32.415818 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/apiextensions-apiserver/pkg/client/informers/internalversion/factory.go:73: Failed to list *apiextensions.CustomResourceDefinition: the server was unable to return a response in the time allotted, but may still be processing the request (get customresourcedefinitions.apiextensions.k8s.io)
E0309 20:00:32.415862 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *rbac.ClusterRoleBinding: the server was unable to return a response in the time allotted, but may still be processing the request (get clusterrolebindings.rbac.authorization.k8s.io)
E0309 20:00:32.415946 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Namespace: the server was unable to return a response in the time allotted, but may still be processing the request (get namespaces)
E0309 20:00:32.416029 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *core.ResourceQuota: the server was unable to return a response in the time allotted, but may still be processing the request (get resourcequotas)
E0309 20:00:32.416609 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *rbac.ClusterRole: the server was unable to return a response in the time allotted, but may still be processing the request (get clusterroles.rbac.authorization.k8s.io)
E0309 20:00:32.416684 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *rbac.RoleBinding: the server was unable to return a response in the time allotted, but may still be processing the request (get rolebindings.rbac.authorization.k8s.io)
E0309 20:00:32.420305 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Endpoints: the server was unable to return a response in the time allotted, but may still be processing the request (get endpoints)
E0309 20:00:32.440196 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *storage.StorageClass: the server was unable to return a response in the time allotted, but may still be processing the request (get storageclasses.storage.k8s.io)
E0309 20:00:32.440403 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: the server was unable to return a response in the time allotted, but may still be processing the request (get services)
E0309 20:00:32.448018 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *core.ServiceAccount: the server was unable to return a response in the time allotted, but may still be processing the request (get serviceaccounts)
E0309 20:00:32.448376 1 reflector.go:205] k8s.io/kubernetes/pkg/client/informers/informers_generated/internalversion/factory.go:85: Failed to list *rbac.Role: the server was unable to return a response in the time allotted, but may still be processing the request (get roles.rbac.authorization.k8s.io)
E0309 20:00:33.395988 1 storage_rbac.go:175] unable to initialize clusterroles: the server was unable to return a response in the time allotted, but may still be processing the request (get clusterroles.rbac.authorization.k8s.io)
I0309 20:00:43.455564 1 trace.go:76] Trace[375160879]: "Create /api/v1/nodes" (started: 2018-03-09 20:00:13.454506587 +0000 UTC m=+44.009475397) (total time: 30.001008377s):
Trace[375160879]: [30.001008377s] [30.000778516s] END
==================================================== =====================
I0309 19:51:35.248083 1 controllermanager.go:108] Version: v1.9.3
I0309 19:51:35.257251 1 leaderelection.go:174] attempting to acquire leader lease...
E0309 19:51:38.310839 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:51:41.766358 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:51:46.025824 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:51:49.622916 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:51:52.675648 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:51:55.697734 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:51:59.348765 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:01.508487 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:03.886473 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:06.120356 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:08.844772 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:12.083789 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:16.038882 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:18.555388 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:21.471034 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:24.236724 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:27.363968 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:30.045776 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:32.751626 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:36.383923 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:38.910958 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:41.400748 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:44.268909 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:47.640891 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:51.713420 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:54.419154 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:52:57.134430 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:00.942903 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:03.440586 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:07.518362 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:53:12.968927 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:16.228760 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:18.299005 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:20.681915 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:24.141874 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:28.484775 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:30.678092 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:34.107654 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:36.251647 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:39.914756 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:42.641017 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:45.058876 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:48.359511 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:51.667554 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:54.338101 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:53:57.357894 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:00.633504 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:03.244353 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:05.923510 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:09.817627 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:12.688349 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:16.803954 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:19.519269 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:23.668226 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:25.903217 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:54:30.248639 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:54:32.428029 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:54:34.962675 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:54:38.598370 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:54:41.179039 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:54:43.927574 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:54:48.190961 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:51.974141 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:55.898687 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:54:59.653210 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:02.094737 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:05.125275 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:09.280324 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:12.920886 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:17.272605 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:21.488182 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:23.708198 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:26.893696 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:31.121014 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:35.414628 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:38.252001 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:41.912479 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:45.621133 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:48.976244 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:52.537317 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:55.863737 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:55:59.682009 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:02.653432 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:04.968939 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:09.336478 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:56:13.488850 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:56:16.262967 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:56:22.685928 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:26.235497 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:28.442915 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:32.051827 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:35.547277 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:38.437120 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:41.007877 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:44.295081 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:46.746424 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:49.321870 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:52.831866 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:55.138333 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:56:57.815491 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:00.802112 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:03.848363 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:07.350593 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:10.672982 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:14.171660 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:17.923995 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:21.919624 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:23.923165 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:27.692006 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:30.654447 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:33.851703 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:57:37.302382 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:57:40.286552 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:57:42.358940 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:57:44.364982 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:57:46.372569 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:57:50.571683 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:57:53.988093 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:57:57.648006 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:01.607961 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:05.717138 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:08.819600 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:12.262314 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:14.327626 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:18.359683 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:20.961212 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:24.503457 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:27.099581 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:29.518623 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:32.943210 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:36.900236 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:40.567479 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:42.642410 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:45.938839 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:50.282483 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:54.086558 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:58:56.794469 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:00.604370 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:02.968978 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:05.825551 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:09.824458 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:12.383249 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:15.891164 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:59:19.088375 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:59:21.305063 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:59:23.366258 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:59:26.308481 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: Get https://10.25.123.11:6443/api/v1/namespaces/kube-system/endpoints/kube-controller-manager: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:59:32.440045 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:36.673744 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:40.049109 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:43.463730 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:46.454431 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:49.782639 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:52.964468 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 19:59:57.265527 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:01.181219 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:03.441468 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:07.324053 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:10.269835 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:12.584906 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:15.042928 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:18.820764 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:22.392476 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:24.630702 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:27.881904 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:30.123513 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:32.490088 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:34.675420 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:37.433904 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:39.819475 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
E0309 20:00:42.152164 1 leaderelection.go:224] error retrieving resource lock kube-system/kube-controller-manager: endpoints "kube-controller-manager" is forbidden: User "system:kube-controller-manager" cannot get endpoints in the namespace "kube-system"
==================================================== =====================
W0309 19:51:34.800737 1 server.go:159] WARNING: all flags than --config are deprecated. Please begin using a config file ASAP.
I0309 19:51:34.812848 1 server.go:551] Version: v1.9.3
I0309 19:51:34.817093 1 server.go:570] starting healthz server on 127.0.0.1:10251
E0309 19:51:34.818028 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: Get https://10.25.123.11:6443/apis/policy/v1beta1/poddisruptionbudgets?limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:34.818279 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: Get https://10.25.123.11:6443/api/v1/pods?fieldSelector=spec.schedulerName%3Ddefault-scheduler%2Cstatus.phase%21%3DFailed%2Cstatus.phase%21%3DSucceeded&limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:34.818346 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: Get https://10.25.123.11:6443/api/v1/persistentvolumeclaims?limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:34.818408 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.StatefulSet: Get https://10.25.123.11:6443/apis/apps/v1beta1/statefulsets?limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:34.819028 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: Get https://10.25.123.11:6443/api/v1/services?limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:34.819386 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: Get https://10.25.123.11:6443/api/v1/nodes?limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:34.820217 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: Get https://10.25.123.11:6443/apis/extensions/v1beta1/replicasets?limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:34.820659 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolume: Get https://10.25.123.11:6443/api/v1/persistentvolumes?limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:34.821783 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: Get https://10.25.123.11:6443/api/v1/replicationcontrollers?limit=500&resourceVersion=0: dial tcp 10.25.123.11:6443: getsockopt: connection refused
E0309 19:51:38.320455 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: poddisruptionbudgets.policy is forbidden: User "system:kube-scheduler" cannot list poddisruptionbudgets.policy at the cluster scope
E0309 19:51:38.329101 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: pods is forbidden: User "system:kube-scheduler" cannot list pods at the cluster scope
E0309 19:51:38.329733 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: replicationcontrollers is forbidden: User "system:kube-scheduler" cannot list replicationcontrollers at the cluster scope
E0309 19:51:38.332670 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: replicasets.extensions is forbidden: User "system:kube-scheduler" cannot list replicasets.extensions at the cluster scope
E0309 19:51:38.332707 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: nodes is forbidden: User "system:kube-scheduler" cannot list nodes at the cluster scope
E0309 19:51:38.332734 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: persistentvolumeclaims is forbidden: User "system:kube-scheduler" cannot list persistentvolumeclaims at the cluster scope
E0309 19:51:38.334248 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolume: persistentvolumes is forbidden: User "system:kube-scheduler" cannot list persistentvolumes at the cluster scope
E0309 19:51:38.334568 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.StatefulSet: statefulsets.apps is forbidden: User "system:kube-scheduler" cannot list statefulsets.apps at the cluster scope
E0309 19:51:38.334594 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: services is forbidden: User "system:kube-scheduler" cannot list services at the cluster scope
E0309 19:51:39.322884 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: poddisruptionbudgets.policy is forbidden: User "system:kube-scheduler" cannot list poddisruptionbudgets.policy at the cluster scope
E0309 19:51:39.331726 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: pods is forbidden: User "system:kube-scheduler" cannot list pods at the cluster scope
E0309 19:51:39.333093 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: replicationcontrollers is forbidden: User "system:kube-scheduler" cannot list replicationcontrollers at the cluster scope
E0309 19:51:39.335939 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: replicasets.extensions is forbidden: User "system:kube-scheduler" cannot list replicasets.extensions at the cluster scope
E0309 19:51:39.335988 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: nodes is forbidden: User "system:kube-scheduler" cannot list nodes at the cluster scope
E0309 19:51:39.336229 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: persistentvolumeclaims is forbidden: User "system:kube-scheduler" cannot list persistentvolumeclaims at the cluster scope
E0309 19:51:39.336514 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolume: persistentvolumes is forbidden: User "system:kube-scheduler" cannot list persistentvolumes at the cluster scope
E0309 19:51:39.337881 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.StatefulSet: statefulsets.apps is forbidden: User "system:kube-scheduler" cannot list statefulsets.apps at the cluster scope
E0309 19:51:39.338784 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: services is forbidden: User "system:kube-scheduler" cannot list services at the cluster scope
E0309 19:51:40.323869 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: poddisruptionbudgets.policy is forbidden: User "system:kube-scheduler" cannot list poddisruptionbudgets.policy at the cluster scope
E0309 19:51:40.332910 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: pods is forbidden: User "system:kube-scheduler" cannot list pods at the cluster scope
E0309 19:51:40.334120 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: replicationcontrollers is forbidden: User "system:kube-scheduler" cannot list replicationcontrollers at the cluster scope
E0309 19:51:40.337188 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: replicasets.extensions is forbidden: User "system:kube-scheduler" cannot list replicasets.extensions at the cluster scope
E0309 19:51:40.338218 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: nodes is forbidden: User "system:kube-scheduler" cannot list nodes at the cluster scope
E0309 19:51:40.339267 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: persistentvolumeclaims is forbidden: User "system:kube-scheduler" cannot list persistentvolumeclaims at the cluster scope
E0309 19:51:40.340635 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolume: persistentvolumes is forbidden: User "system:kube-scheduler" cannot list persistentvolumes at the cluster scope
E0309 19:51:40.342035 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.StatefulSet: statefulsets.apps is forbidden: User "system:kube-scheduler" cannot list statefulsets.apps at the cluster scope
E0309 19:51:40.343070 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: services is forbidden: User "system:kube-scheduler" cannot list services at the cluster scope
E0309 19:51:41.325987 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: poddisruptionbudgets.policy is forbidden: User "system:kube-scheduler" cannot list poddisruptionbudgets.policy at the cluster scope
E0309 19:51:41.334782 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: pods is forbidden: User "system:kube-scheduler" cannot list pods at the cluster scope
E0309 19:51:41.336320 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: replicationcontrollers is forbidden: User "system:kube-scheduler" cannot list replicationcontrollers at the cluster scope
E0309 19:51:41.338996 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: replicasets.extensions is forbidden: User "system:kube-scheduler" cannot list replicasets.extensions at the cluster scope
E0309 19:51:41.339923 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: nodes is forbidden: User "system:kube-scheduler" cannot list nodes at the cluster scope
E0309 19:51:41.340904 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: persistentvolumeclaims is forbidden: User "system:kube-scheduler" cannot list persistentvolumeclaims at the cluster scope
E0309 19:51:41.342304 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolume: persistentvolumes is forbidden: User "system:kube-scheduler" cannot list persistentvolumes at the cluster scope
E0309 19:51:41.343675 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.StatefulSet: statefulsets.apps is forbidden: User "system:kube-scheduler" cannot list statefulsets.apps at the cluster scope
E0309 19:51:41.344622 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: services is forbidden: User "system:kube-scheduler" cannot list services at the cluster scope
E0309 19:51:42.328038 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: poddisruptionbudgets.policy is forbidden: User "system:kube-scheduler" cannot list poddisruptionbudgets.policy at the cluster scope
E0309 19:51:42.336744 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: pods is forbidden: User "system:kube-scheduler" cannot list pods at the cluster scope
E0309 19:51:42.338239 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: replicationcontrollers is forbidden: User "system:kube-scheduler" cannot list replicationcontrollers at the cluster scope
E0309 19:51:42.340719 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: replicasets.extensions is forbidden: User "system:kube-scheduler" cannot list replicasets.extensions at the cluster scope
E0309 19:51:42.341878 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: nodes is forbidden: User "system:kube-scheduler" cannot list nodes at the cluster scope
E0309 19:51:42.342835 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: persistentvolumeclaims is forbidden: User "system:kube-scheduler" cannot list persistentvolumeclaims at the cluster scope
E0309 19:51:42.344100 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolume: persistentvolumes is forbidden: User "system:kube-scheduler" cannot list persistentvolumes at the cluster scope
E0309 19:51:42.345231 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.StatefulSet: statefulsets.apps is forbidden: User "system:kube-scheduler" cannot list statefulsets.apps at the cluster scope
E0309 19:51:42.346405 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: services is forbidden: User "system:kube-scheduler" cannot list services at the cluster scope
E0309 19:51:43.330230 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: poddisruptionbudgets.policy is forbidden: User "system:kube-scheduler" cannot list poddisruptionbudgets.policy at the cluster scope
E0309 19:51:43.338706 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: pods is forbidden: User "system:kube-scheduler" cannot list pods at the cluster scope
E0309 19:51:43.339941 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: replicationcontrollers is forbidden: User "system:kube-scheduler" cannot list replicationcontrollers at the cluster scope
E0309 19:51:43.342476 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: replicasets.extensions is forbidden: User "system:kube-scheduler" cannot list replicasets.extensions at the cluster scope
E0309 19:51:43.343584 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: nodes is forbidden: User "system:kube-scheduler" cannot list nodes at the cluster scope
E0309 19:51:43.344615 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: persistentvolumeclaims is forbidden: User "system:kube-scheduler" cannot list persistentvolumeclaims at the cluster scope
E0309 19:51:43.345792 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolume: persistentvolumes is forbidden: User "system:kube-scheduler" cannot list persistentvolumes at the cluster scope
E0309 19:51:43.346976 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.StatefulSet: statefulsets.apps is forbidden: User "system:kube-scheduler" cannot list statefulsets.apps at the cluster scope
E0309 19:51:43.348050 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: services is forbidden: User "system:kube-scheduler" cannot list services at the cluster scope
E0309 19:51:44.332307 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: poddisruptionbudgets.policy is forbidden: User "system:kube-scheduler" cannot list poddisruptionbudgets.policy at the cluster scope
E0309 19:51:44.340659 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: pods is forbidden: User "system:kube-scheduler" cannot list pods at the cluster scope
E0309 19:51:44.341607 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: replicationcontrollers is forbidden: User "system:kube-scheduler" cannot list replicationcontrollers at the cluster scope
E0309 19:51:44.344223 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: replicasets.extensions is forbidden: User "system:kube-scheduler" cannot list replicasets.extensions at the cluster scope
E0309 19:51:44.345380 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: nodes is forbidden: User "system:kube-scheduler" cannot list nodes at the cluster scope
E0309 19:51:44.346247 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: persistentvolumeclaims is forbidden: User "system:kube-scheduler" cannot list persistentvolumeclaims at the cluster scope
E0309 19:51:44.347536 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolume: persistentvolumes is forbidden: User "system:kube-scheduler" cannot list persistentvolumes at the cluster scope
E0309 19:51:44.348664 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.StatefulSet: statefulsets.apps is forbidden: User "system:kube-scheduler" cannot list statefulsets.apps at the cluster scope
E0309 19:51:44.349648 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Service: services is forbidden: User "system:kube-scheduler" cannot list services at the cluster scope
E0309 19:51:45.334228 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.PodDisruptionBudget: poddisruptionbudgets.policy is forbidden: User "system:kube-scheduler" cannot list poddisruptionbudgets.policy at the cluster scope
E0309 19:51:45.342638 1 reflector.go:205] k8s.io/kubernetes/plugin/cmd/kube-scheduler/app/server.go:590: Failed to list *v1.Pod: pods is forbidden: User "system:kube-scheduler" cannot list pods at the cluster scope
E0309 19:51:45.343460 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.ReplicationController: replicationcontrollers is forbidden: User "system:kube-scheduler" cannot list replicationcontrollers at the cluster scope
E0309 19:51:45.345969 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1beta1.ReplicaSet: replicasets.extensions is forbidden: User "system:kube-scheduler" cannot list replicasets.extensions at the cluster scope
E0309 19:51:45.347140 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.Node: nodes is forbidden: User "system:kube-scheduler" cannot list nodes at the cluster scope
E0309 19:51:45.348176 1 reflector.go:205] k8s.io/kubernetes/vendor/k8s.io/client-go/informers/factory.go:86: Failed to list *v1.PersistentVolumeClaim: persistentvolumeclaims is forbidden: User "system:kube-scheduler" cannot list persistentvolumeclaims at the cluster scope
==================================================== =====================
==================================================== =====================
==================================================== =====================
==================================================== =====================
==================================================== =====================
+1
์
๋ฐ์ดํธ:
๋ด๊ฐ ํ ์ ์๋ ๋ชจ๋ ๊ฒ์ ์ดํด๋ณธ ํ(์ ๋ k8s๋ฅผ ์ฒ์ ์ ํ์ต๋๋ค) ๋ง์นจ๋ด kubectl describe pod -n kube-system kube-dns-<sha>
์์ ๋ด๊ฐ ์ค์นํ๊ณ ์๋ ๊ฐ์ ์๋ฒ์ CPU๊ฐ 1๊ฐ๋ง ์๊ณ kube-dns๊ฐ ์์๋์ง ์๋๋ค๋ ๊ฒ์ ์์์ต๋๋ค. CPU๊ฐ ๋ถ์กฑํ๊ธฐ ๋๋ฌธ์
๋๋ค. ์ด์ํ๊ฒ๋ kubectl logs pod -n kube-system kube-dns-<sha>
๋ ์ด ์ ๋ณด๋ฅผ ํ์ํ์ง ์์์ต๋๋ค.
OS ์ฌ์ค์น ํ ์๋ํ์ต๋๋ค(kubeadm ์ค์น ํ ์ฌ๋ถํ
ํ๋ฉด k8s ๋ง์คํฐ๊ฐ ์ ๋๋ก ์์๋์ง ์์).
(์ถ๋ ฅ์ ์บก์ฒํ๋ ๊ฒ์ ์์ด ์ฃ์กํฉ๋๋ค)
+1
๋๋ ๊ฐ์ ๋ฌธ์ ๊ฐ ์์๊ณ ์ทจ์ํ๊ณ reset
๋ฅผ ์คํํ ๋ค์ ์ด์ ๊ณผ ๋์ผํ init
๋ฅผ ์คํํ์ง๋ง --apiserver-advertise-address=<my_host_public_ip_address>
-- ์๋ํ์ต๋๋ค.
https://github.com/kubernetes/kubernetes/issues/59680#issuecomment -364646304
selinux ๋นํ์ฑํ๊ฐ ๋์์ด๋์์ต๋๋ค.
1.8.10์ผ๋ก ๋ค์ด ๊ทธ๋ ์ด๋ํ๋ฉด ๋ฌธ์ ๊ฐ ํด๊ฒฐ๋์์ต๋๋ค.
+1
+1
Ubuntu 16.04์ v1.9.3๊ณผ ๋์ผํ ๋ฌธ์ (selinux ์์)
+1 ๊ฐ์ ๋ฌธ์
arm64์ Ubuntu 16.04์ ์๋ v1.10๊ณผ ๋์ผํ ๋ฌธ์ ์ ๋๋ค.
arm64์ ์ฐ๋ถํฌ 16.04์ v1.10๊ณผ ๋์ผํ ๋ฌธ์ (selinux ์์)
์ค์นํ ํ๋์จ์ด์ ์๋ CPU ์๋ฅผ ํ์ธํ์ญ์์ค. 3์ฃผ ์ ์ ์์์ ์ค๋ช ํ ๋๋ก ์ค์นํ๋ ค๋ฉด ๋ง์คํฐ์ 2๊ฐ๊ฐ ํ์ํฉ๋๋ค.
@bbruun ์ฌ์ฉ๋ ํ๋์จ์ด๋ https://www.pine64.org/?page_id=1491 ์ด๋ฏ๋ก 4๊ฐ์ ์ฝ์ด๋ก ์ ๋๋ก ๊ฐ์ง๋ฉ๋๋ค. ๊ทธ๋ฌ๋ฉด ํ๋์จ์ด๊ฐ ๋ฌธ์ ๊ฐ ๋์ด์๋ ์ ๋ฉ๋๋ค. ๊ทธ๋ฌ๋ ์ด์จ๋ ํ์ ์ฃผ์ ์ ๊ฐ์ฌํฉ๋๋ค. @qxing3 ์ ๋์ผํ ํ๋์จ์ด๋ฅผ ์ฌ์ฉํ์ง ์์ ์๋ ์์ง๋ง...
@farfeduc ๊ทธ๊ฒ์ ๋ด๊ฐ ๋ถ๋ชํ ์ฅ์ ๋ฌผ์ด์์ต๋๋ค. ์ค์น๋ฅผ ํ ์คํธํ๊ณ k8์ ์๊ธฐ ์ํด ๊ฐ์ ๋จธ์ ์ ๋ค์ ์ค์นํ๋ฉด์ ์ฌ๋ฌ ๋ฒ ์ฐ์ ์๋ํ์ง๋ง ์์คํ ์์ ์ฌ์ฉ ๊ฐ๋ฅํ ๋ก๊ทธ๋ฅผ ๊ฐ์ ธ์ค๋ ๊ฒ์ ์๋ฑํ ์ผ์ด๋ฉฐ ๊ฐ๋ฅํ ๋ชจ๋ ๊ณณ์์ ๊ฐ์ ธ์ค๋ ค๊ณ ํ์ต๋๋ค. ์ฌ์ฉ ๊ฐ๋ฅํ CPU๊ฐ ์ถฉ๋ถํ์ง ์๋ค๋ ๋ฉ์์ง๊ฐ ๋ํ๋ ๋๊น์ง. ์ด์ 3๊ฐ์ Udoo x86 Ultra๋ฅผ ๊ตฌ์ ํ์ฌ ์ง์์ ์ฝ๊ฐ ๋ ํฐ ์ธ์คํด์ค๋ฅผ ์ฌ์ฉํ๋ ์์ ๊ณผ ํจ๊ป ์์ ํด๋ฌ์คํฐ๋ฅผ ์คํํฉ๋๋ค :-)
@bbruun ์ด์จ๋ ํ ์ฃผ์ ์ ๊ฐ์ฌํฉ๋๋ค. ๊ฐ์ ๋จธ์ ์ 2๊ฐ์ CPU๋ฅผ ๊ตฌ์ฑํ์ต๋๋ค.
/ํ ๋น @liztio
+1
+1 v1.10.0
+1 v1.10.0 ๋ฐ 1.10.1
+1
ํฅ๋ฏธ๋กญ๊ฒ๋ ๋ฐฐํฌ ์์น์ ๋ฐ๋ผ ๋ธํ๋ฅผ ์ฐพ๊ณ ์์ต๋๋ค. ๋๋ ๋ ํ๊ตฌํ ์๊ฐ์ ์ฐพ๊ธฐ๋ฅผ ํฌ๋งํ์ง๋ง, ์ง๊ธ๊น์ง๋ ์ด๊ฒ์ ์๊ณ ์์ต๋๋ค. Mac/VMware Fusion์ ์ฌ์ฉํ๊ณ CentOS 7 VM์ ์คํํ๋ฉด kubeadm 1.8์ ์์ ํ ์ฌ์ฉํ ์ ์์ต๋๋ค. ๋ก์ปฌ์์ ์๋ํ๋ v1.9 ๋๋ v1.10์ด ์์ต๋๋ค. ๊ทธ๋ฌ๋ Digital Ocean์์ CentOS 7 ์ด๋ฏธ์ง๋ฅผ ์ฌ์ฉํ๋ฉด v1.8.x, v1.10.0 ๋ฐ v1.10.1์ ์ฑ๊ณต์ ์ผ๋ก ์คํํ ์ ์์ต๋๋ค. v1.9๋ ์ด๋ค ์ด์ ๋ก "๊ทธ๋ฅ ์์กด"ํ๋ ๊ฒ ๊ฐ์ต๋๋ค. ์ด์ ์ค์์น๋ฅผ ํธ๋ฆฝํ๋ ์์๋ฅผ ์ฐพ๊ธฐ ์ํด ๋ ํ๊ฒฝ ์ฌ์ด์ ๋ฏธ์ธํ ๋ธํ๋ฅผ ํํค์น๋ ๋ฌธ์ ์ ๋๋ค. ์ปค๋/ํจ์น ์์ค์ด ์ผ์นํ๊ณ Docker ์์ง ๋ฑ์ด ์ผ์นํ๋ค๋ ๊ฒ์ ์๊ณ ์์ต๋๋ค. DO๋ cloud-init ํญ๋ชฉ์ ์ค์นํ์ง๋ง ๋ด ๋ก์ปฌ VM์ ์ค์นํ์ง ์์ต๋๋ค. ๋ฌด์์ด ๋ค๋ฅธ์ง ์์๋ด๋ ๊ฒ์ ์ฝ์ง ์์ต๋๋ค. ๋๋ ๋์คํฌ ํฌ๊ธฐ๋ฅผ ๋ง์ถ๊ธฐ ์ํด ๋ ธ๋ ฅํ์ต๋๋ค(์์ ๋์คํฌ๊ฐ ์ด๋๊ฐ์ ์ค๋ฅ๋ฅผ ๊ฐ๋ฆด ์ ์๋ค๊ณ ์๊ฐํ์ง๋ง ๊ทธ๊ฒ๋ ์ ๊ฑฐํ์ต๋๋ค).
๋ชจ๋ ๊ฒฝ์ฐ์ ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ๋ ํญ์ ์๋ํ์ผ๋ฉฐ API ์๋น์ค๊ฐ ์๋ตํ๋๋ก ํ๊ณ ์คํจํ ๋ ๋ช ๋ถ๋ง๋ค ์ฌํ์ฉ์ ์ ์งํ์ง ์์ต๋๋ค.
์ธ์ฌ๋ง,
https://docs.docker.com/config/daemon/systemd/#httphttps -proxy๋ฅผ ์ฐธ์กฐํ์ฌ docker ๋ฐ๋ชฌ์ ๋ํ ํ๋ก์๋ฅผ ์ค์ ํ ์ ์์ต๋๋ค.
+1 Raspberry PI 3์ HypriotOS์์ ์คํ
๋ง์ง๋ง ๋ฒ์ ๋์ v1.9.6์ ์ค์นํ์ฌ ์๋ํ๊ฒ ๋ง๋ค ์ ์์์ต๋๋ค.
๋ฐ๋ผ์ v1.9.6์์๋ ์ ์์ ์ผ๋ก ์๋ํ์ง๋ง ์ํ์ธ ๋ณด๋์ arm64์์ ์ฐ๋ถํฌ 16.04์ v1.10.0 ๋ฐ v1.10.1์์๋ ์คํจํฉ๋๋ค.
Raspberry Pi 3, HypriotOS์์๋ ๋์ผํ ๋ฌธ์ ๊ฐ ์์ต๋๋ค. 1.9.7-00์ผ๋ก ๋ค์ด ๊ทธ๋ ์ด๋ํ๋ ๊ฒ๋ ์ ์๊ฒ ํจ๊ณผ์ ์ด์์ต๋๋ค.
+1, kubeadm v1.10.1, ๋ผ์ฆ๋ฒ ๋ฆฌ ํ์ด 3b, hypriotOS
์ ๊ฒฝ์ฐ์๋ etcd ์ปจํ
์ด๋๊ฐ ์์๋๊ณ ์ค๋ฅ์ ํจ๊ป ์ข
๋ฃ๋์์ผ๋ฉฐ ์ด๋ก ์ธํด kubeadm init
๊ฐ ์ค๋จ๋๊ณ ๊ฒฐ๊ตญ ์๊ฐ์ด ์ด๊ณผ๋์์ต๋๋ค.
์ด๊ฒ์ด ๋น์ ์ ๋ฌผ๊ณ ์๋์ง ํ์ธํ๋ ค๋ฉด docker ps -a
๋ฅผ ์คํํ๊ณ etcd ์ปจํ
์ด๋์ ์ํ๋ฅผ ํ์ธํ์ญ์์ค. ์คํ ์ค์ด ์๋๋ฉด etcd ์ปจํ
์ด๋( docker logs <container-id>
)์ ๋ํ ๋ก๊ทธ๋ฅผ ํ์ธํ๊ณ ์ฃผ์์ ๋ฐ์ธ๋ฉํ ์ ์๋ค๊ณ ๋ถํํ๋์ง ํ์ธํฉ๋๋ค. ์ด ๋ฌธ์ ๋ณด๊ณ ์๋ฅผ ์ฐธ์กฐํ์ญ์์ค: https://github.com/kubernetes/kubernetes/issues/57709
๋ฐฉ๊ธ ์ธ๊ธํ ๋ฌธ์ ์๋ ํด๊ฒฐ ๋ฐฉ๋ฒ์ด ์์ง๋ง ๊ทธ๊ฒ์ด ๋จผ์ ์คํ๋๊ณ ์๋์ง ํ์ธํ์ญ์์ค.
๋ฐฉํ๋ฒฝ์ด 6443
์ ๋ํ ์ธ๋ฐ์ด๋ ํธ๋ํฝ์ ํ์ฉํ๋์ง ํ์ธํ์ญ์์ค.
์๋ฅผ ๋ค์ด Ubuntu๋ฅผ ์ฌ์ฉํ๋ ๊ฒฝ์ฐ ufw status
๋ฅผ ์คํํ์ฌ ํ์ฑํ๋์ด ์๋์ง ํ์ธํฉ๋๋ค.
๊ทธ๋ฐ ๋ค์ ufw allow 6443
ํฌํธ๋ฅผ ์ฝ๋๋ค.
์๋ ์ด๋ฏธ์ง๋ฅผ ๋์ดํ๊ณ ํ๋ก์๋ฅผ ํตํด ์๋์ผ๋ก ๊ฐ์ ธ์จ ๋ค์ kubeadm์ ๋ค์ ์ด๊ธฐํํ๋ ๊ฒ์ด ๊ฐ๋ฅํฉ๋๊น?
์๋ํ ๊น์?
์ฌ์ด, ์ฐ๋ฆฌ๋ ์ค๊ตญ์ ์์ต๋๋ค, ๋น์ ์ ์๊ณ ์์ต๋๋ค, GFW.
๊ทธ๋ฆฌ๊ณ ์ ๋ k8์ ์ฒ์ ์ฌ์ฉํ๊ณ centos7์ ์ค์ ํ ๋ ์ฌ๊ธฐ์ ๋ฉ์ท์ต๋๋ค.
GREAT FIREWALL ๋ค์ ์๋ ์ค๊ตญ ์ฌ๋๋ค์ ์ํด
@thanch2n thx ๋ง์ด. ๋๋ ๊ทธ๊ฒ์ ์๋ ํ ๊ฑฐ์ผ.
์ด๊ฒ์ ์ฌ์ฉํ์ฌ ํ๋ก์๋ฅผ docker์ ์ถ๊ฐํ๋๋ฐ ์ด๋ฏธ์ง๊ฐ ๋ชจ๋ ์ด๋ฏธ ๋ค์ด๋ก๋๋ ๊ฒ ๊ฐ์ง๋ง ์ฌ์ ํ "[์ด๊ธฐํ] ์ ์ด ํ๋ฉด ์ด๋ฏธ์ง๋ฅผ ๊ฐ์ ธ์์ผ ํ๋ ๊ฒฝ์ฐ 1๋ถ ์ด์ ๊ฑธ๋ฆด ์ ์์ต๋๋ค."
์๋์ ์๋์ผ๋ก ๊ฐ์ ธ์จ ์ด๋ฏธ์ง๋ฅผ ๋์ดํฉ๋๋ค.
k8s.gcr.io/kube-apiserver-amd64 v1.10.2 e774f647e259 2์ฃผ ์ 225MB
k8s.gcr.io/kube-scheduler-amd64 v1.10.2 0dcb3dea0db1 2์ฃผ ์ 50.4MB
k8s.gcr.io/kube-controller-manager-amd64 v1.10.2 f3fcd0775c4e 2์ฃผ ์ 148MB
k8s.gcr.io/etcd-amd64 3.1.12 52920ad46f5b 2 ๊ฐ์ ์ 193 MB
k8s.gcr.io/pause-amd64 3.1 da86e6ba6ca1 4๊ฐ์ ์ 742 kB
๋๋ ์ด๊ฒ์ ์์๋ด๊ธฐ ์ํด ๋ง์ ์๊ฐ์ ๋ณด๋๋ค. ๋๋ ufw๋ฅผ ๋นํ์ฑํํ๊ณ selinux๋ฅผ ๋๊ณ ip ํฌ์๋ฉ์ด ์ผ์ ธ ์๊ณ /proc/sys/net/bridge/bridge-nf-call-iptables๋ 1๋ก ์ค์ ๋์ด ์๋์ง ํ์ธํ์ต๋๋ค. ์๋ฌด ๊ฒ๋ ๋ฌธ์ ๋ฅผ ํด๊ฒฐํ์ง ๋ชปํ๋ ๊ฒ ๊ฐ์์ต๋๋ค.
๊ฒฐ๊ตญ ๋ค์ด๊ทธ๋ ์ด๋ ํ ์ ๊ทธ๋ ์ด๋๋ฅผ ํ๊ธฐ๋ก ํ์ต๋๋ค.
sudo apt-get -y --allow-downgrades install kubectl=1.5.3-00 kubelet=1.5.3-00 kubernetes-cni=0.3.0.1-07a8a2-00
๋ฐ
curl -Lo /tmp/old-kubeadm.deb https://apt.k8s.io/pool/kubeadm_1.6.0-alpha.0.2074-a092d8e0f95f52-00_amd64_0206dba536f698b5777c7d210444a8ace18f48e045ab78687327631c6c694f42.deb
1.10์์ ๋ค์ด ๊ทธ๋ ์ด๋ ํ ๋ค์
sudo apt-get -y install kubectl kubelet kubernetes-cni kubeadm
Etcd๊ฐ ๋ค์ ์์๋๊ณ API ์๋ฒ๊ฐ ์๊ฐ ์ด๊ณผ๋์์ต๋๋ค. ์ ์ ํ api-server๊ฐ ์ฐ๊ฒฐํ ์ ์๋ค๋ ๋ถํ์ผ๋ก ๋ค์ ์์๋ฉ๋๋ค. DEBUG ๋ ๋ฒจ ๋ก๊น ์ ์ผค ์ ์๋ ๋ฐฉ๋ฒ์ด ์์ต๋๊น? ์ด์ ์์ธ์ด ๋ฌด์์ธ์ง ํ์ธํ์ญ์์ค. ํ์ง๋ง ์ง๊ธ ์๋ํฉ๋๋ค. ๋๋ ํ์คํ ์ด๊ฒ์ ์ฌํํ๊ณ ๋ฌธ์ ๋ฅผ ํด๊ฒฐํ๊ณ ์ถ์ต๋๋ค.
๋งํ ์ด์ ๋ฅผ ์์์ต๋๋ค.
vmware์์ ์คํ ์ค์ด๊ณ 1G RAM์ ์ฐพ์์ต๋๋ค. k8s์๋ ์ต์ 2G RAM์ด ํ์ํฉ๋๋ค.
์ด์ ๋ํ ์๋ฆผ์ ์ถ๊ฐํ ์ ์์ต๋๊น?
CentOS 7์์ +1 kubeadm 1.10.2
4GB RAM 2CPU
6GB RAM ๋ฐ 1 VCPU๊ฐ ์๋ HyperV VM์ Debian Stretch(go1.9.3)์์ +1 kubeadm 1.10.1...
ํด๋ฌ์คํฐ๋ฅผ ์ฌ๋ฌ ๋ฒ ์ฌ์์ฑํ์ ๋ ๊ณผ๊ฑฐ์๋ ์ ์๋ํ์ต๋๋ค ...
HyperV์์ 2๊ฐ์ VCPU๋ก ์ ํ์ ์๋ํ์ง๋ง ์๋ฌด ๊ฒ๋ ๋ณ๊ฒฝ๋์ง ์์์ต๋๋ค.
+1 !
+1. kubeadm 1.10.1, ๋ฐ๋น์ ์คํธ๋ ์น. ์ด์ ์ ์ผํจ
Centos 7์ docker 1.13.1์์ ์คํ ๋ฆฌ์ง ๋๋ผ์ด๋ฒ์ ๋ฌธ์ ๊ฐ ์์์ ๋ฐ๊ฒฌํ์ต๋๋ค. Docker ๋ก๊ทธ์ 'readlink /var/lib/docker/overlay2/l: ์๋ชป๋ ์ธ์'๊ฐ ํ์๋์์ต๋๋ค. docker 18.03.1-ce๋ก ์ด๋ํ๋ฉด ์ด ๋ฌธ์ ๊ฐ ํด๊ฒฐ๋๊ณ kubeadm init๊ฐ ๋ ์ด์ ์ค๋จ๋์ง ์์ต๋๋ค.
๋๋ ๊ฐ์ ๋ฌธ์ ๊ฐ ์์๋ค. etcd๊ฐ ๋ฆฌ๋ ์ค ๋จธ์ ์ ํธ์คํธ ์ด๋ฆ(somedomain.example.com)์ ๊ฐ์ ธ์์ DNS ์๋ฒ์์ ๊ฒ์ํ๊ณ ์์ผ๋์นด๋ ๋๋ฉ์ธ(*.example.com)์ ๋ํ ๋ต๋ณ์ ์ฐพ์ ๋ค์ ๋ฐํ๋ IP ์ฃผ์ ๋์ ๋ฐํ๋ IP ์ฃผ์์ ๋ฐ์ธ๋ฉ์ ์๋ํ ๊ฒ์ผ๋ก ๋ํ๋ฌ์ต๋๋ค. apiserver-advertise-address.
์ฌ์ ํ๋ง ๋ฐ ํผ๋ฒ ์๊ฐ ์ด๊ณผ ๊ฐ์ง์ ๋ํ ์ฌ๋ฌ ์์ ์ฌํญ์ด ์์ผ๋ฏ๋ก ์ด ๋ฌธ์ ๋ฅผ ์ข ๋ฃํฉ๋๋ค.
+1
k8sadmin์ด ์ด๋ฏธ์ง๋ฅผ ๋์ด๋ด๋ฆฌ๋๋ก ํ๋ ํ์ค ๋ฐฉ๋ฒ์ ์๋ํ๊ณ ์ฌ๋ฌ ๋ฒ ์๋ํ ๋ค์ ์ด๋ฏธ์ง๋ฅผ ๊ฐ์ ธ์ค๊ณ ์ฌ์ค์ ํ๊ณ ์ค๋ฅ๋ฅผ ๋ฌด์ํ๋ ค๊ณ ํ์ง๋ง ํญ์ ์คํจํ์ต๋๋ค.
pi@master-node-001 :~ $ sudo kubeadm ๋ฆฌ์
[์ฌ์ค์ ] ๊ฒฝ๊ณ : 'kubeadm init' ๋๋ 'kubeadm join'์ ์ํด ์ด ํธ์คํธ์ ์ ์ฉ๋ ๋ณ๊ฒฝ ์ฌํญ์ ๋๋๋ ค์ง๋๋ค.
[์คํ ์ ] ์คํ ์ ๊ฒ์ฌ ์คํ
[์ฌ์ค์ ] kubelet ์๋น์ค ์ค์ง
[์ฌ์ค์ ] "/var/lib/kubelet"์์ ๋ง์ดํธ๋ ๋๋ ํ ๋ฆฌ ๋ง์ดํธ ํด์
[์ฌ์ค์ ] ์ํ ์ ์ฅ ๋๋ ํ ๋ฆฌ ๋ด์ฉ ์ญ์ : [/var/lib/kubelet /etc/cni/net.d /var/lib/dockershim /var/run/kubernetes /var/lib/etcd]
[์ฌ์ค์ ] ๊ตฌ์ฑ ๋๋ ํ ๋ฆฌ์ ๋ด์ฉ ์ญ์ : [/etc/kubernetes/manifests /etc/kubernetes/pki]
[์ฌ์ค์ ] ํ์ผ ์ญ์ : [/etc/kubernetes/admin.conf /etc/kubernetes/kubelet.conf /etc/kubernetes/bootstrap-kubelet.conf /etc/kubernetes/controller-manager.conf /etc/kubernetes/scheduler. conf]
pi@master-node-001 :~ $ kubeadm ๊ตฌ์ฑ ์ด๋ฏธ์ง ํ
[config/images] ๊ฐ์ ธ ์ค๊ธฐ k8s.gcr.io/kube-apiserver:v1.12.2
[config/images] ๊ฐ์ ธ ์ค๊ธฐ k8s.gcr.io/kube-controller-manager:v1.12.2
[๊ตฌ์ฑ/์ด๋ฏธ์ง] ๊ฐ์ ธ์ค๊ธฐ k8s.gcr.io/kube- ์ค์ผ์ค๋ฌ:v1.12.2
[config/images] ๊ฐ์ ธ ์ค๊ธฐ k8s.gcr.io/kube-proxy:v1.12.2
[config/images] k8s.gcr.io/pause:3.1 ๊ฐ์ ธ์ค๊ธฐ
[๊ตฌ์ฑ/์ด๋ฏธ์ง] ๊ฐ์ ธ ์ค๊ธฐ k8s.gcr.io/etcd:3.2.24
[config/images] k8s.gcr.io/coredns:1.2.2 ๊ฐ์ ธ์ค๊ธฐ
pi@master-node-001 :~ $ sudo kubeadm init --token-ttl=0 --ignore-preflight-errors=all
[์ด๊ธฐ] Kubernetes ๋ฒ์ ์ฌ์ฉ: v1.12.2
[์คํ ์ ] ์คํ ์ ๊ฒ์ฌ ์คํ
[ํ๋ฆฌํ๋ผ์ดํธ/์ด๋ฏธ์ง] Kubernetes ํด๋ฌ์คํฐ ์ค์ ์ ํ์ํ ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ
[ํ๋ฆฌํ๋ผ์ดํธ/์ด๋ฏธ์ง] ์ธํฐ๋ท ์ฐ๊ฒฐ ์๋์ ๋ฐ๋ผ 1~2๋ถ ์ ๋ ์์๋ ์ ์์ต๋๋ค.
[ํ๋ฆฌํ๋ผ์ดํธ/์ด๋ฏธ์ง] 'kubeadm config images pull'์ ์ฌ์ฉํ์ฌ ๋ฏธ๋ฆฌ ์ด ์์
์ ์ํํ ์๋ ์์ต๋๋ค.
[kubelet] "/var/lib/kubelet/kubeadm-flags.env" ํ์ผ์ ํ๋๊ทธ๊ฐ ์๋ kubelet ํ๊ฒฝ ํ์ผ ์ฐ๊ธฐ
[kubelet] "/var/lib/kubelet/config.yaml" ํ์ผ์ kubelet ๊ตฌ์ฑ ์ฐ๊ธฐ
[ํ๋ฆฌํ๋ผ์ดํธ] kubelet ์๋น์ค ํ์ฑํ
[์ธ์ฆ์] etcd/ca ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ apiserver-etcd-client ์ธ์ฆ์ ๋ฐ ํค์
๋๋ค.
[์ธ์ฆ์] etcd/server ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] etcd/server ์๋น ์ธ์ฆ์๋ DNS ์ด๋ฆ [master-node-001 localhost] ๋ฐ IP [127.0.0.1 ::1]์ ๋ํด ์๋ช
๋์์ต๋๋ค.
[์ธ์ฆ์] etcd/ํผ์ด ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] etcd/peer ์๋น ์ธ์ฆ์๋ DNS ์ด๋ฆ [master-node-001 localhost] ๋ฐ IP [192.168.0.100 127.0.0.1 ::1]์ ๋ํด ์๋ช
๋์์ต๋๋ค.
[์ธ์ฆ์] etcd/healthcheck-client ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] CA ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ apiserver ์ธ์ฆ์ ๋ฐ ํค์
๋๋ค.
[์ธ์ฆ์] apiserver ์๋น ์ธ์ฆ์๋ DNS ์ด๋ฆ [master-node-001 kubernetes kubernetes.default kubernetes.default.svc kubernetes.default.svc.cluster.local] ๋ฐ IP [10.96.0.1 192.168.0.100]์ ๋ํด ์๋ช
๋์์ต๋๋ค.
[์ธ์ฆ์] apiserver-kubelet-client ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ front-proxy-ca ์ธ์ฆ์ ๋ฐ ํค์
๋๋ค.
[์ธ์ฆ์] ์์ฑ๋ ํ๋ฐํธ ํ๋ก์ ํด๋ผ์ด์ธํธ ์ธ์ฆ์ ๋ฐ ํค์
๋๋ค.
[์ธ์ฆ์] ์ ํจํ ์ธ์ฆ์ ๋ฐ ํค๊ฐ ์ด์ "/etc/kubernetes/pki"์ ์์ต๋๋ค.
[์ธ์ฆ์] sa ํค์ ๊ณต๊ฐ ํค๋ฅผ ์์ฑํ์ต๋๋ค.
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "/etc/kubernetes/admin.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "/etc/kubernetes/kubelet.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "/etc/kubernetes/controller-manager.conf"
[kubeconfig] ๋์คํฌ์ KubeConfig ํ์ผ ์์ฑ: "/etc/kubernetes/scheduler.conf"
[controlplane] ๊ตฌ์ฑ ์์ kube-apiserver์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-apiserver.yaml"์ ์์ฑํ์ต๋๋ค.
[controlplane] ๊ตฌ์ฑ ์์ kube-controller-manager์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-controller-manager.yaml"์ ์์ฑํ์ต๋๋ค.
[controlplane] ๊ตฌ์ฑ ์์ kube-scheduler์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-scheduler.yaml"์ ์์ฑํ์ต๋๋ค.
[etcd] ๋ก์ปฌ etcd ์ธ์คํด์ค์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/etcd.yaml"์ ์์ฑํ์ต๋๋ค.
[์ด๊ธฐํ] kubelet์ด "/etc/kubernetes/manifests" ๋๋ ํ ๋ฆฌ์์ Static Pod๋ก ์ ์ด ํ๋ฉด์ ๋ถํ
ํ๊ธฐ๋ฅผ ๊ธฐ๋ค๋ฆฝ๋๋ค.
[์ด๊ธฐํ] ์ ์ด ํ๋ฉด ์ด๋ฏธ์ง๋ฅผ ๊ฐ์ ธ์์ผ ํ๋ ๊ฒฝ์ฐ 1๋ถ ์ด์ ๊ฑธ๋ฆด ์ ์์ต๋๋ค.
์ ๊ฐ์ค๋ฝ๊ฒ๋ ๋ค์๊ณผ ๊ฐ์ ์ค๋ฅ๊ฐ ๋ฐ์ํ์ต๋๋ค.
์กฐ๊ฑด์ ๊ธฐ๋ค๋ฆฌ๋ ์๊ฐ์ด ์ด๊ณผ๋์์ต๋๋ค.
์ด ์ค๋ฅ๋ ๋ค์์ผ๋ก ์ธํด ๋ฐ์ํ ์ ์์ต๋๋ค.
- kubelet์ด ์คํ๋์ง ์์ต๋๋ค.
- ์ด๋ค ์์ผ๋ก๋ ๋
ธ๋์ ์๋ชป๋ ๊ตฌ์ฑ์ผ๋ก ์ธํด kubelet์ด ๋น์ ์์
๋๋ค(ํ์ํ cgroups ๋นํ์ฑํ๋จ).
์์คํ
์ ์ ๊ณต๊ธ ์์คํ
์ ์ฌ์ฉํ๋ ๊ฒฝ์ฐ ๋ค์ ๋ช
๋ น์ ์ฌ์ฉํ์ฌ ์ค๋ฅ ๋ฌธ์ ๋ฅผ ํด๊ฒฐํ ์ ์์ต๋๋ค.
- 'systemctl ์ํ kubelet'
- 'journalctl -xeu kubelet'
๋ํ ์ปจํ
์ด๋ ๋ฐํ์์์ ์์ํ ๋ ์ปจํธ๋กค ํ๋ ์ธ ๊ตฌ์ฑ ์์๊ฐ ์ถฉ๋ํ๊ฑฐ๋ ์ข
๋ฃ๋์์ ์ ์์ต๋๋ค.
๋ฌธ์ ๋ฅผ ํด๊ฒฐํ๋ ค๋ฉด ์ ํธํ๋ ์ปจํ
์ด๋ ๋ฐํ์ CLI(์: docker)๋ฅผ ์ฌ์ฉํ์ฌ ๋ชจ๋ ์ปจํ
์ด๋๋ฅผ ๋์ดํ์ญ์์ค.
๋ค์์ ๋์ปค์์ ์คํ๋๋ ๋ชจ๋ Kubernetes ์ปจํ
์ด๋๋ฅผ ๋์ดํ๋ ๋ฐฉ๋ฒ์ ํ ์์
๋๋ค.
- '๋์ปค PS -a | ๊ทธ๋ ํ๋ธ | grep -v ์ผ์ ์ค์ง'
์คํจํ ์ปจํ
์ด๋๋ฅผ ์ฐพ์ผ๋ฉด ๋ค์์ ์ฌ์ฉํ์ฌ ๋ก๊ทธ๋ฅผ ๊ฒ์ฌํ ์ ์์ต๋๋ค.
- '๋์ปค ๋ก๊ทธ CONTAINERID'
Kubernetes ํด๋ฌ์คํฐ๋ฅผ ์ด๊ธฐํํ ์ ์์ต๋๋ค.
pi@master-node-001 :~ $ ๋์ปค ์ด๋ฏธ์ง
์ ์ฅ์ ํ๊ทธ ์ด๋ฏธ์ง ID ์์ฑ๋ ํฌ๊ธฐ
k8s.gcr.io/kube-controller-manager v1.12.2 4bc6cae738d8 7์ผ ์ 146MB
k8s.gcr.io/kube-apiserver v1.12.2 8bfe044a05e1 7์ผ ์ 177MB
k8s.gcr.io/kube-scheduler v1.12.2 3abf5566fec1 7์ผ ์ 52MB
k8s.gcr.io/kube-proxy v1.12.2 328ef67ca54f 7์ผ ์ 84.5MB
k8s.gcr.io/kube-proxy v1.12.1 8c06fbe56458 3์ฃผ ์ 84.7MB
k8s.gcr.io/kube-controller-manager v1.12.1 5de943380295 3์ฃผ ์ 146MB
k8s.gcr.io/kube-scheduler v1.12.1 1fbc2e4cd378 3์ฃผ ์ 52MB
k8s.gcr.io/kube-apiserver v1.12.1 ab216fe6acf6 3์ฃผ ์ 177MB
k8s.gcr.io/etcd 3.2.24 e7a8884c8443 5์ฃผ ์ 222MB
k8s.gcr.io/coredns 1.2.2 ab0805b0de94 2๊ฐ์ ์ 33.4MB
k8s.gcr.io/kube-scheduler v1.11.0 0e4a34a3b0e6 4๊ฐ์ ์ 56.8MB
k8s.gcr.io/kube-controller-manager v1.11.0 55b70b420785 4 ๊ฐ์ ์ 155MB
k8s.gcr.io/etcd 3.2.18 b8df3b177be2 6 ๊ฐ์ ์ 219MB
k8s.gcr.io/pause 3.1 e11a8cbeda86 10 months ago 374kB
pi@master-node-001 :~ $ h | grep kubectl
-bash: h: ๋ช
๋ น์ ์ฐพ์ ์ ์์
pi@master-node-001 :~ $ ํ์คํ ๋ฆฌ | grep kubectl
9 kubectl ํฌ๋ ๋ชฉ๋ก
10 kubectl ๋ชฉ๋ก ํฌ๋
11 kubectl --help
12 kubectl get pod -o wide
14 kubectl get pod -o wide
32์๊ฐ | grep kubectl
33 ์ญ์ฌ | grep kubectl
pi@master-node-001 :~ $ !12
kubectl ํฌ๋ ๊ฐ์ ธ์ค๊ธฐ -o ์์ด๋
์๋ฒ์ ์ฐ๊ฒฐํ ์ ์์: net/http: TLS ํธ๋์
ฐ์ดํฌ ์๊ฐ ์ด๊ณผ
pi@master-node-001 :~ $ ํ์คํ ๋ฆฌ | ๊ทธ๋ ์ผ์ ์ค์ง
17 ๋์ปค PS -a | ๊ทธ๋ ํ๋ธ | grep -v ์ผ์ ์ค์ง
35 ์ญ์ฌ | ๊ทธ๋ ์ผ์ ์ค์ง
pi@master-node-001 :~ $ !17
๋์ปค PS -a | ๊ทธ๋ ํ๋ธ | grep -v ์ผ์ ์ค์ง
41623613679e 8bfe044a05e1 "kube-apiserver --auโฆ
0870760b9ea0 8bfe044a05e1 "kube-apiserver --auโฆ
c60d65fab8a7 3abf5566fec1 "kube-scheduler --adโฆ
26c58f6c68e9 e7a8884c8443 "etcd --advertise-clโฆ" 6๋ถ ์ ์ต๋ 5๋ถ k8s_etcd_etcd-master-node-001_kube-system_d01dcc7fc79b875a52f01e26432e6745
65546081ca77 4bc6cae738d8 "kube-controller-manโฆ
pi@master-node-001 :~ $ kubectl get pod -o wide
^C
pi@master-node-001 :~ $ sudo ์ฌ๋ถํ
192.168.0.100์ ๋ํ ์ฐ๊ฒฐ์ด ์๊ฒฉ ํธ์คํธ์ ์ํด ๋ซํ์ต๋๋ค.
192.168.0.100์ ๋ํ ์ฐ๊ฒฐ์ด ๋ซํ์ต๋๋ค.
karl@karl-PL62-7RC :~$ ํ 192.168.0.100
PING 192.168.0.100(192.168.0.100) 56(84) ๋ฐ์ดํธ ๋ฐ์ดํฐ.
^C
--- 192.168.0.100 ํ ํต๊ณ ---
2 ํจํท ์ ์ก, 0 ์์ , 100% ํจํท ์์ค, ์๊ฐ 1015ms
karl@karl-PL62-7RC :~$ ssh [email protected]
ssh_exchange_identification: ์ฝ๊ธฐ: ํผ์ด์ ์ํ ์ฐ๊ฒฐ ์ฌ์ค์
karl@karl-PL62-7RC :~$ ssh [email protected]
[email protected] ์ ๋น๋ฐ๋ฒํธ:
Linux master-node-001 4.14.71-v7+ #1145 SMP Fri Sep 21 15:38:35 BST 2018 armv7l
๋ฐ๋น์ GNU/๋ฆฌ๋
์ค ์์คํ
์ ํฌํจ๋ ํ๋ก๊ทธ๋จ์ ๋ฌด๋ฃ ์ํํธ์จ์ด์
๋๋ค.
๊ฐ ํ๋ก๊ทธ๋จ์ ์ ํํ ๋ฐฐํฌ ์กฐ๊ฑด์
/usr/share/doc/*/copyright์ ๊ฐ๋ณ ํ์ผ.
๋ฐ๋น์ GNU/๋ฆฌ๋
์ค๋ ์ด๋ ์ ๋๊น์ง ๋ณด์ฆ์ ํ์ง ์์ต๋๋ค.
ํด๋น ๋ฒ๋ฅ ์ ์ํด ํ์ฉ๋ฉ๋๋ค.
๋ง์ง๋ง ๋ก๊ทธ์ธ: 2018๋
10์ 31์ผ ์์์ผ 21:36:13
pi@master-node-001 :~ $ kubectl get pod -o wide
์๋ฒ 192.168.0.100:6443์ ๋ํ ์ฐ๊ฒฐ์ด ๊ฑฐ๋ถ๋์์ต๋๋ค. ์ฌ๋ฐ๋ฅธ ํธ์คํธ ๋๋ ํฌํธ๋ฅผ ์ง์ ํ์ต๋๊น?
pi@master-node-001 :~ $ sudo kubeadm init --token-ttl=0 --ignore-preflight-errors=all
[์ด๊ธฐ] Kubernetes ๋ฒ์ ์ฌ์ฉ: v1.12.2
[์คํ ์ ] ์คํ ์ ๊ฒ์ฌ ์คํ
[๊ฒฝ๊ณ FileAvailable--etc-kubernetes-manifests-kube-apiserver.yaml]: /etc/kubernetes/manifests/kube-apiserver.yaml์ด ์ด๋ฏธ ์กด์ฌํฉ๋๋ค.
[๊ฒฝ๊ณ FileAvailable--etc-kubernetes-manifests-kube-controller-manager.yaml]: /etc/kubernetes/manifests/kube-controller-manager.yaml์ด ์ด๋ฏธ ์กด์ฌํฉ๋๋ค.
[๊ฒฝ๊ณ FileAvailable--etc-kubernetes-manifests-kube-scheduler.yaml]: /etc/kubernetes/manifests/kube-scheduler.yaml์ด ์ด๋ฏธ ์กด์ฌํฉ๋๋ค.
[๊ฒฝ๊ณ FileAvailable--etc-kubernetes-manifests-etcd.yaml]: /etc/kubernetes/manifests/etcd.yaml์ด ์ด๋ฏธ ์กด์ฌํฉ๋๋ค.
[๊ฒฝ๊ณ ํฌํธ-10250]: ํฌํธ 10250์ด ์ฌ์ฉ ์ค์
๋๋ค.
[๊ฒฝ๊ณ DirAvailable--var-lib-etcd]: /var/lib/etcd๊ฐ ๋น์ด ์์ง ์์ต๋๋ค.
[ํ๋ฆฌํ๋ผ์ดํธ/์ด๋ฏธ์ง] Kubernetes ํด๋ฌ์คํฐ ์ค์ ์ ํ์ํ ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ
[ํ๋ฆฌํ๋ผ์ดํธ/์ด๋ฏธ์ง] ์ธํฐ๋ท ์ฐ๊ฒฐ ์๋์ ๋ฐ๋ผ 1~2๋ถ ์ ๋ ์์๋ ์ ์์ต๋๋ค.
[ํ๋ฆฌํ๋ผ์ดํธ/์ด๋ฏธ์ง] 'kubeadm config images pull'์ ์ฌ์ฉํ์ฌ ๋ฏธ๋ฆฌ ์ด ์์
์ ์ํํ ์๋ ์์ต๋๋ค.
[kubelet] "/var/lib/kubelet/kubeadm-flags.env" ํ์ผ์ ํ๋๊ทธ๊ฐ ์๋ kubelet ํ๊ฒฝ ํ์ผ ์ฐ๊ธฐ
[kubelet] "/var/lib/kubelet/config.yaml" ํ์ผ์ kubelet ๊ตฌ์ฑ ์ฐ๊ธฐ
[ํ๋ฆฌํ๋ผ์ดํธ] kubelet ์๋น์ค ํ์ฑํ
[์ธ์ฆ์] ๊ธฐ์กด etcd/peer ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์ฌ์ฉํฉ๋๋ค.
[์ธ์ฆ์] ๊ธฐ์กด apiserver-etcd-client ์ธ์ฆ์ ๋ฐ ํค ์ฌ์ฉ.
[์ธ์ฆ์] ๊ธฐ์กด etcd/server ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์ฌ์ฉํฉ๋๋ค.
[์ธ์ฆ์] ๊ธฐ์กด etcd/healthcheck-client ์ธ์ฆ์ ๋ฐ ํค ์ฌ์ฉ.
[์ธ์ฆ์] ๊ธฐ์กด apiserver ์ธ์ฆ์ ๋ฐ ํค ์ฌ์ฉ.
[์ธ์ฆ์] ๊ธฐ์กด apiserver-kubelet-client ์ธ์ฆ์ ๋ฐ ํค ์ฌ์ฉ.
[์ธ์ฆ์] ๊ธฐ์กด ํ๋ก ํธ ํ๋ก์ ํด๋ผ์ด์ธํธ ์ธ์ฆ์ ๋ฐ ํค๋ฅผ ์ฌ์ฉํฉ๋๋ค.
[์ธ์ฆ์] ์ ํจํ ์ธ์ฆ์ ๋ฐ ํค๊ฐ ์ด์ "/etc/kubernetes/pki"์ ์์ต๋๋ค.
[์ธ์ฆ์] ๊ธฐ์กด sa ํค ์ฌ์ฉ.
[kubeconfig] ๊ธฐ์กด ์ต์ KubeConfig ํ์ผ ์ฌ์ฉ: "/etc/kubernetes/admin.conf"
[kubeconfig] ๊ธฐ์กด ์ต์ KubeConfig ํ์ผ ์ฌ์ฉ: "/etc/kubernetes/kubelet.conf"
[kubeconfig] ๊ธฐ์กด ์ต์ KubeConfig ํ์ผ ์ฌ์ฉ: "/etc/kubernetes/controller-manager.conf"
[kubeconfig] ๊ธฐ์กด ์ต์ KubeConfig ํ์ผ ์ฌ์ฉ: "/etc/kubernetes/scheduler.conf"
[controlplane] ๊ตฌ์ฑ ์์ kube-apiserver์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-apiserver.yaml"์ ์์ฑํ์ต๋๋ค.
[controlplane] ๊ตฌ์ฑ ์์ kube-controller-manager์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-controller-manager.yaml"์ ์์ฑํ์ต๋๋ค.
[controlplane] ๊ตฌ์ฑ ์์ kube-scheduler์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/kube-scheduler.yaml"์ ์์ฑํ์ต๋๋ค.
[etcd] ๋ก์ปฌ etcd ์ธ์คํด์ค์ ๋ํ Static Pod ๋งค๋ํ์คํธ๋ฅผ "/etc/kubernetes/manifests/etcd.yaml"์ ์์ฑํ์ต๋๋ค.
[์ด๊ธฐํ] kubelet์ด "/etc/kubernetes/manifests" ๋๋ ํ ๋ฆฌ์์ Static Pod๋ก ์ ์ด ํ๋ฉด์ ๋ถํ
ํ๊ธฐ๋ฅผ ๊ธฐ๋ค๋ฆฝ๋๋ค.
[์ด๊ธฐํ] ์ ์ด ํ๋ฉด ์ด๋ฏธ์ง๋ฅผ ๊ฐ์ ธ์์ผ ํ๋ ๊ฒฝ์ฐ 1๋ถ ์ด์ ๊ฑธ๋ฆด ์ ์์ต๋๋ค.
์ ๊ฐ์ค๋ฝ๊ฒ๋ ๋ค์๊ณผ ๊ฐ์ ์ค๋ฅ๊ฐ ๋ฐ์ํ์ต๋๋ค.
์กฐ๊ฑด์ ๊ธฐ๋ค๋ฆฌ๋ ์๊ฐ์ด ์ด๊ณผ๋์์ต๋๋ค.
์ด ์ค๋ฅ๋ ๋ค์์ผ๋ก ์ธํด ๋ฐ์ํ ์ ์์ต๋๋ค.
- kubelet์ด ์คํ๋์ง ์์ต๋๋ค.
- ์ด๋ค ์์ผ๋ก๋ ๋
ธ๋์ ์๋ชป๋ ๊ตฌ์ฑ์ผ๋ก ์ธํด kubelet์ด ๋น์ ์์
๋๋ค(ํ์ํ cgroups ๋นํ์ฑํ๋จ).
์์คํ
์ ์ ๊ณต๊ธ ์์คํ
์ ์ฌ์ฉํ๋ ๊ฒฝ์ฐ ๋ค์ ๋ช
๋ น์ ์ฌ์ฉํ์ฌ ์ค๋ฅ ๋ฌธ์ ๋ฅผ ํด๊ฒฐํ ์ ์์ต๋๋ค.
- 'systemctl ์ํ kubelet'
- 'journalctl -xeu kubelet'
๋ํ ์ปจํ
์ด๋ ๋ฐํ์์์ ์์ํ ๋ ์ปจํธ๋กค ํ๋ ์ธ ๊ตฌ์ฑ ์์๊ฐ ์ถฉ๋ํ๊ฑฐ๋ ์ข
๋ฃ๋์์ ์ ์์ต๋๋ค.
๋ฌธ์ ๋ฅผ ํด๊ฒฐํ๋ ค๋ฉด ์ ํธํ๋ ์ปจํ
์ด๋ ๋ฐํ์ CLI(์: docker)๋ฅผ ์ฌ์ฉํ์ฌ ๋ชจ๋ ์ปจํ
์ด๋๋ฅผ ๋์ดํ์ญ์์ค.
๋ค์์ ๋์ปค์์ ์คํ๋๋ ๋ชจ๋ Kubernetes ์ปจํ
์ด๋๋ฅผ ๋์ดํ๋ ๋ฐฉ๋ฒ์ ํ ์์
๋๋ค.
- '๋์ปค PS -a | ๊ทธ๋ ํ๋ธ | grep -v ์ผ์ ์ค์ง'
์คํจํ ์ปจํ
์ด๋๋ฅผ ์ฐพ์ผ๋ฉด ๋ค์์ ์ฌ์ฉํ์ฌ ๋ก๊ทธ๋ฅผ ๊ฒ์ฌํ ์ ์์ต๋๋ค.
- '๋์ปค ๋ก๊ทธ CONTAINERID'
Kubernetes ํด๋ฌ์คํฐ๋ฅผ ์ด๊ธฐํํ ์ ์์ต๋๋ค.
13 sudo kubeadm ์ด๊ธฐํ --token-ttl=0
14 kubectl get pod -o wide
15 sudo kubeadm ์ฌ์ค์
16 sudo kubeadm ์ด๊ธฐํ --token-ttl=0
17 ๋์ปค PS -a | ๊ทธ๋ ํ๋ธ | grep -v ์ผ์ ์ค์ง
18๊ฐ์ kubeadm ๊ตฌ์ฑ ์ด๋ฏธ์ง pull --kubernetes-version=v1.11.0
19 sudo kubeadm ์ฌ์ค์
20 ์ญ์ฌ > notes.txt
21๊ฐ์ ์ถ๊ฐ notes.txt
22 sudo ์ฌ๋ถํ
23๊ฐ์ kubeadm ๊ตฌ์ฑ ์ด๋ฏธ์ง ๋ชฉ๋ก
24๊ฐ์ kubeadm ๊ตฌ์ฑ ์ด๋ฏธ์ง pull --kubernetes-version=v1.11.0
25 sudo kubeadm ์ด๊ธฐํ --token-ttl=0 --ignore-preflight-errors=all
26๊ฐ์ kubeadm ๊ตฌ์ฑ ์ด๋ฏธ์ง ๊ฐ์ ธ์ค๊ธฐ
27 sudo kubeadm ์ด๊ธฐํ --token-ttl=0 --ignore-preflight-errors=all
28๊ฐ์ kubeadm ๊ตฌ์ฑ ์ด๋ฏธ์ง ํ
29 sudo kubeadm ์ฌ์ค์
30๊ฐ์ kubeadm ๊ตฌ์ฑ ์ด๋ฏธ์ง ํ
31 sudo kubeadm ์ด๊ธฐํ --token-ttl=0 --ignore-preflight-errors=all
32๊ฐ์ ๋์ปค ์ด๋ฏธ์ง
33์๊ฐ | grep kubectl
34 ์ญ์ฌ | grep kubectl
35 kubectl get pod -o wide
36 ์ญ์ฌ | ๊ทธ๋ ์ผ์ ์ค์ง
37 ๋์ปค ps -a | ๊ทธ๋ ํ๋ธ | grep -v ์ผ์ ์ค์ง
38 kubectl get pod -o wide
39 sudo ์ฌ๋ถํ
40 kubectl get pod -o wide
41 sudo kubeadm ์ด๊ธฐํ --token-ttl=0 --ignore-preflight-errors=all
๊ฐ์ฅ ์ ์ฉํ ๋๊ธ
https://github.com/kubernetes/kubernetes/issues/59680#issuecomment -364646304
selinux ๋นํ์ฑํ๊ฐ ๋์์ด๋์์ต๋๋ค.