Kubeadm: μ•Œ 수 μ—†λŠ” κΈ°κ΄€μ—μ„œ μ„œλͺ…ν•œ μΈμ¦μ„œ --κΈ°μ—… λ„€νŠΈμ›Œν¬ - ν”„λ‘μ‹œ

에 λ§Œλ“  2018λ…„ 06μ›” 22일  Β·  4μ½”λ©˜νŠΈ  Β·  좜처: kubernetes/kubeadm

도움 μš”μ²­μž…λ‹ˆκΉŒ?

λ„€

이 ν•­λͺ©μ„ μ œμΆœν•˜κΈ° 전에 kubeadm λ¬Έμ œμ—μ„œ μ–΄λ–€ ν‚€μ›Œλ“œλ₯Ό κ²€μƒ‰ν•˜μ…¨μŠ΅λ‹ˆκΉŒ?

x509: μ•Œ 수 μ—†λŠ” 기관이 μ„œλͺ…ν•œ μΈμ¦μ„œ -- κΈ°μ—… λ„€νŠΈμ›Œν¬ λ‚΄λΆ€

μ€‘λ³΅λ˜λŠ” ν•­λͺ©μ„ 찾으면 λŒ€μ‹  거기에 λ‹΅μž₯ν•˜κ³  이 νŽ˜μ΄μ§€λ₯Ό λ‹«μ•„μ•Ό ν•©λ‹ˆλ‹€.

쀑볡 ν•­λͺ©μ„ 찾지 λͺ»ν•œ 경우 이 μ„Ήμ…˜μ„ μ‚­μ œν•˜κ³  계속 μ§„ν–‰ν•˜μ‹­μ‹œμ˜€.

이것은 버그 λ³΄κ³ μ„œμž…λ‹ˆκΉŒ μ•„λ‹ˆλ©΄ κΈ°λŠ₯ μš”μ²­μž…λ‹ˆκΉŒ?

BUG REPORT λ˜λŠ” FEATURE REQUEST 쀑 ν•˜λ‚˜λ₯Ό μ„ νƒν•˜μ‹­μ‹œμ˜€.

버그 λ³΄κ³ μ„œ

버전

kubeadm 버전 ( kubeadm version ): --1.10.4
kubeadm 버전: &version.Info{μ£Όμš”:"1", λΆ€:"10", GitVersion:"v1.10.4", GitCommit:"5ca598b4ba5abb89bb773071ce452e33fb66339d", GitTreeState:"2016T0:"clean", BuildDate::0 59Z", GoVersion:"go1.9.3", 컴파일러:"gc", ν”Œλž«νΌ:"linux/amd64"}

ν™˜κ²½ :

  • Kubernetes 버전 ( kubectl version ):
  • ν΄λΌμš°λ“œ 제곡자 λ˜λŠ” ν•˜λ“œμ›¨μ–΄ ꡬ성 :
  • OS (예: /etc/os-release):
    NAME="μ„ΌνŠΈOS λ¦¬λˆ…μŠ€"
    버전="7(μ½”μ–΄)"
    아이디 = "μ„Όν† μŠ€"
    ID_LIKE="렐 νŽ˜λ„λΌ"
    VERSION_ID="7"
    PRETTY_NAME="CentOS Linux 7(μ½”μ–΄)"
    ANSI_COLOR="0;31"
    CPE_NAME="cpe:/o: centos:centos :7"
    HOME_URL=" https://www.centos.org/ "
    BUG_REPORT_URL=" https://bugs.centos.org/ "

CENTOS_MANTISBT_PROJECT="CentOS-7"
CENTOS_MANTISBT_PROJECT_VERSION="7"
REDHAT_SUPPORT_PRODUCT="μ„Όν† μŠ€"
REDHAT_SUPPORT_PRODUCT_VERSION="7"

  • 컀널 (예: uname -a ):
    λ¦¬λˆ…μŠ€ kubem13.10.0-123.el7.x86_64 #1 SMP μ›”μš”μΌ 6μ›” 30일 12:09:22 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux
  • 기타 :

무슨 μΌμ΄μ—μš”?

였λ₯˜ x509 λ°œμƒ: μ•Œ 수 μ—†λŠ” κΈ°κ΄€μ—μ„œ μ„œλͺ…ν•œ μΈμ¦μ„œ

무슨 일이 일어날 것이라고 μ˜ˆμƒν–ˆμŠ΅λ‹ˆκΉŒ?

였λ₯˜ 없이 kubeadm initλ₯Ό μ‹€ν–‰ν•΄μ•Ό ν•©λ‹ˆλ‹€.

그것을 μž¬ν˜„ν•˜λŠ” 방법(κ°€λŠ₯ν•œ ν•œ μ΅œμ†Œν•œμœΌλ‘œ 그리고 μ •ν™•ν•˜κ²Œ)?

μš°λ¦¬κ°€ μ•Œμ•„μ•Ό ν•  λ‹€λ₯Έ 것이 μžˆμŠ΅λ‹ˆκΉŒ?

μ—¬λŸ¬ νŒŒμΌμ— ν”„λ‘μ‹œλ₯Ό κ΅¬μ„±ν–ˆμŠ΅λ‹ˆλ‹€.

.bash_profile
/etc/ν™˜κ²½
/etc/systemd/system/docker.service.d/http-proxy.conf

/etc/systemd/system/docker.service.d/http-proxy.conf

[μ„œλΉ„μŠ€]
ν™˜κ²½="HTTP_PROXY=http://:@:8080"
ν™˜κ²½="HTTPS_PROXY=https://:@:8080"
ν™˜κ²½ = "NO_PROXY = 둜컬 호슀트, 127.0.0.1,10.169.150.123"

/etc/ν™˜κ²½

내보내기 http_proxy="http://:@:8080"
내보내기 https_proxy="https://:@:8080"
내보내기 HTTP_PROXY="http://:@:8080"
내보내기 HTTPS_PROXY="https://:@:8080"
내보내기 no_proxy="10.169.150.123,127.0.0.1,localhost"

IN 배쉬 ν”„λ‘œν•„

내보내기 KUBECONFIG=/etc/kubernetes/admin.conf
내보내기 http_proxy="http://:@:8080"
내보내기 https_proxy="https://:@:8080"
내보내기 HTTP_PROXY="http://:@:8080"
내보내기 HTTPS_PROXY="https://:@:8080"
내보내기 no_proxy="10.169.150.123,127.0.0.1,localhost"

ν•„μš”ν•œ 포트λ₯Ό μ—΄μ—ˆμŠ΅λ‹ˆλ‹€.

고양이 /etc/sysconfig/iptables

-A INPUT -p tcp -m state --state NEW -m tcp --dport 6443 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 2379-2380 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10250 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10251 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10252 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10255 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 8080 -j ACCEPT

방화벽을 λ‹€μ‹œ λ‘œλ“œν–ˆμŠ΅λ‹ˆλ‹€.

λ˜ν•œ 방화벽을 λΉ„ν™œμ„±ν™”ν•˜μ—¬ ν™•μΈν–ˆμŠ΅λ‹ˆλ‹€.

λΉ„ν™œμ„±ν™”λœ SELINUX

########KUBELET_NETWORK_ARGS에 λŒ“κΈ€μ„ λ‚¨κ²ΌμŠ΅λ‹ˆλ‹€.

/etc/systemd/system/kubelet.service.d/10-kubeadm.conf

[μ„œλΉ„μŠ€]
ν™˜κ²½="KUBELET_KUBECONFIG_ARGS=--bootstrap-kubeconfig=/etc/kubernetes/bootstrap-kubelet.conf --kubeconfig=/etc/kubernetes/kubelet.conf"
Environment="KUBELET_SYSTEM_PODS_ARGS=--pod-manifest-path=/etc/kubernetes/manifests --allow-privileged=true"

ν™˜κ²½="KUBELET_NETWORK_ARGS=--network-plugin=cni --cni-conf-dir=/etc/cni/net.d --cni-bin-dir=/opt/cni/bin"

ν™˜κ²½="KUBELET_DNS_ARGS=--cluster-dns=10.96.0.10 --cluster-domain=cluster.local"
Environment="KUBELET_AUTHZ_ARGS=--authorization-mode=Webhook --client-ca-file=/etc/kubernetes/pki/ca.crt"
ν™˜κ²½="KUBELET_CADVISOR_ARGS=--cadvisor-port=0"
ν™˜κ²½="KUBELET_CGROUP_ARGS=--cgroup-driver=systemd"
Environment="KUBELET_CERTIFICATE_ARGS=--rotate-certificates=true --cert-dir=/var/lib/kubelet/pki"
ν™˜κ²½="KUBELET_EXTRA_ARGS=--fail-swap-on=false"
μ‹€ν–‰ μ‹œμž‘=
ExecStart=/usr/bin/kubelet $KUBELET_KUBECONFIG_ARGS $KUBELET_SYSTEM_PODS_ARGS $KUBELET_DNS_ARGS $KUBELET_AUTHZ_ARGS $KUBELET_CADVISOR_ARGS $KUBELET_CGROUP_ARGS $FICATELEET_CERTI

버전을 μ „λ‹¬ν•˜μ—¬ μ‹€ν–‰ν•˜λ©΄

[ root@kubem1 ~]# kubeadm μ΄ˆκΈ°ν™” --kubernetes-version=v1.10.4
[μ΄ˆκΈ°ν™”] Kubernetes 버전 μ‚¬μš©: v1.10.4
[μ΄ˆκΈ°ν™”] κΆŒν•œ λΆ€μ—¬ λͺ¨λ“œ μ‚¬μš©: [λ…Έλ“œ RBAC]
[μ‹€ν–‰ μ „] μ‹€ν–‰ μ „ 검사λ₯Ό μ‹€ν–‰ν•©λ‹ˆλ‹€.
[κ²½κ³  HTTPProxyCIDR]: "10.96.0.0/12"에 λŒ€ν•œ 연결은 ν”„λ‘μ‹œ "https:// * * * * "λ₯Ό μ‚¬μš©ν•©λ‹ˆλ‹€. 이둜 인해 ν΄λŸ¬μŠ€ν„° 섀정이 μ œλŒ€λ‘œ μž‘λ™ν•˜μ§€ μ•Šμ„ 수 μžˆμŠ΅λ‹ˆλ‹€. ν¬λ“œ 및 μ„œλΉ„μŠ€ IP λ²”μœ„κ°€ ν”„λ‘μ‹œ κ΅¬μ„±μ—μ„œ μ˜ˆμ™Έλ‘œ μ˜¬λ°”λ₯΄κ²Œ μ§€μ •λ˜μ—ˆλŠ”μ§€ ν™•μΈν•©λ‹ˆλ‹€.
[μΈμ¦μ„œ] CA μΈμ¦μ„œ 및 ν‚€λ₯Ό μƒμ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μΈμ¦μ„œ] μƒμ„±λœ apiserver μΈμ¦μ„œ 및 ν‚€μž…λ‹ˆλ‹€.
[μΈμ¦μ„œ] apiserver μ„œλΉ™ μΈμ¦μ„œλŠ” DNS 이름 [kubem1]에 λŒ€ν•΄ μ„œλͺ…λ˜μ—ˆμŠ΅λ‹ˆλ‹€.kubernetes kubernetes.default kubernetes.default.svc kubernetes.default.svc.cluster.local] 및 IP [10.96.0.1 10.169.150.123]
[μΈμ¦μ„œ] apiserver-kubelet-client μΈμ¦μ„œ 및 ν‚€λ₯Ό μƒμ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μΈμ¦μ„œ] sa 킀와 곡개 ν‚€λ₯Ό μƒμ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μΈμ¦μ„œ] μƒμ„±λœ front-proxy-ca μΈμ¦μ„œ 및 ν‚€μž…λ‹ˆλ‹€.
[μΈμ¦μ„œ] μƒμ„±λœ ν”„λŸ°νŠΈ ν”„λ‘μ‹œ ν΄λΌμ΄μ–ΈνŠΈ μΈμ¦μ„œ 및 ν‚€μž…λ‹ˆλ‹€.
[μΈμ¦μ„œ] etcd/ca μΈμ¦μ„œ 및 ν‚€λ₯Ό μƒμ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μΈμ¦μ„œ] etcd/server μΈμ¦μ„œ 및 ν‚€λ₯Ό μƒμ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μΈμ¦μ„œ] etcd/server μ„œλΉ™ μΈμ¦μ„œλŠ” DNS 이름 [localhost] 및 IP [127.0.0.1]에 λŒ€ν•΄ μ„œλͺ…λ˜μ—ˆμŠ΅λ‹ˆλ‹€.
[μΈμ¦μ„œ] etcd/ν”Όμ–΄ μΈμ¦μ„œ 및 ν‚€λ₯Ό μƒμ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μΈμ¦μ„œ] etcd/ν”Όμ–΄ μ„œλΉ„μŠ€ μΈμ¦μ„œλŠ” DNS 이름 [kubem1. * * ** ] 및 IP [10.169.150.123]
[μΈμ¦μ„œ] etcd/healthcheck-client μΈμ¦μ„œ 및 ν‚€λ₯Ό μƒμ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μΈμ¦μ„œ] μƒμ„±λœ apiserver-etcd-client μΈμ¦μ„œ 및 ν‚€μž…λ‹ˆλ‹€.
[μΈμ¦μ„œ] μœ νš¨ν•œ μΈμ¦μ„œ 및 ν‚€κ°€ 이제 "/etc/kubernetes/pki"에 μžˆμŠ΅λ‹ˆλ‹€.
[kubeconfig] λ””μŠ€ν¬μ— KubeConfig 파일 μž‘μ„±: "/etc/kubernetes/admin.conf"
[kubeconfig] λ””μŠ€ν¬μ— KubeConfig 파일 μž‘μ„±: "/etc/kubernetes/kubelet.conf"
[kubeconfig] λ””μŠ€ν¬μ— KubeConfig 파일 μž‘μ„±: "/etc/kubernetes/controller-manager.conf"
[kubeconfig] λ””μŠ€ν¬μ— KubeConfig 파일 μž‘μ„±: "/etc/kubernetes/scheduler.conf"
[controlplane] ꡬ성 μš”μ†Œ kube-apiserver에 λŒ€ν•œ Static Pod λ§€λ‹ˆνŽ˜μŠ€νŠΈλ₯Ό "/etc/kubernetes/manifests/kube-apiserver.yaml"에 μž‘μ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[controlplane] ꡬ성 μš”μ†Œ kube-controller-manager에 λŒ€ν•œ Static Pod λ§€λ‹ˆνŽ˜μŠ€νŠΈλ₯Ό "/etc/kubernetes/manifests/kube-controller-manager.yaml"에 μž‘μ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μ œμ–΄νŒ] ꡬ성 μš”μ†Œ kube-scheduler에 λŒ€ν•œ 정적 ν¬λ“œ λ§€λ‹ˆνŽ˜μŠ€νŠΈλ₯Ό "/etc/kubernetes/manifests/kube-scheduler.yaml"에 μž‘μ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[etcd] 둜컬 etcd μΈμŠ€ν„΄μŠ€μ— λŒ€ν•œ Static Pod λ§€λ‹ˆνŽ˜μŠ€νŠΈλ₯Ό "/etc/kubernetes/manifests/etcd.yaml"에 μž‘μ„±ν–ˆμŠ΅λ‹ˆλ‹€.
[μ΄ˆκΈ°ν™”] kubelet이 "/etc/kubernetes/manifests" λ””λ ‰ν† λ¦¬μ—μ„œ Static Pod둜 컨트둀 ν”Œλ ˆμΈμ„ λΆ€νŒ…ν•˜κΈ°λ₯Ό κΈ°λ‹€λ¦½λ‹ˆλ‹€.
[μ΄ˆκΈ°ν™”] μ œμ–΄ 평면 이미지λ₯Ό 가져와야 ν•˜λŠ” 경우 1λΆ„ 이상 걸릴 수 μžˆμŠ΅λ‹ˆλ‹€.

#############IN 였λ₯˜ 둜그

6μ›” 22일 04:31:34 kubem1. * * * * kubelet[7275]: E0622 04:31:34.942572 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: λ‚˜μ—΄ μ‹€νŒ¨ *v1.Pod: https κ°€μ Έμ˜€κΈ° * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:35 kubem1. * * * * kubelet[7275]: E0622 04:31:35.888104 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:461: *v1.Nodeλ₯Ό λ‚˜μ—΄ν•˜μ§€ λͺ»ν–ˆμŠ΅λ‹ˆλ‹€ . /10.169.150.123 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkubem1. * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:35 kubem1. * * * * kubelet[7275]: E0622 04:31:35.888256 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:452: *v1.Service: https:/ λ₯Ό λ‚˜μ—΄ν•˜μ§€ λͺ»ν–ˆμŠ΅λ‹ˆλ‹€
6μ›” 22일 04:31:35 kubem1. * * * * kubelet[7275]: E0622 04:31:35.943992 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: v1.Pod λ‚˜μ—΄ μ‹€νŒ¨ * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:36 kubem1. * * * * kubelet[7275]: E0622 04:31:36.889648 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:461: λ‚˜μ—΄ν•˜μ§€ λͺ»ν–ˆμŠ΅λ‹ˆλ‹€. *v1.Node: Get https:/ /10.169.150.123 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkubem1. * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:36 kubem1. * * * * kubelet[7275]: E0622 04:31:36.891490 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:452: λ‚˜μ—΄ν•˜μ§€ λͺ»ν–ˆμŠ΅λ‹ˆλ‹€. *v1.Service: https:/ /10.169.150.123 :6443/api/v1/services?limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:36 kubem1. * * * * kubelet[7275]: E0622 04:31:36.945185 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: v1.Pod λ‚˜μ—΄ μ‹€νŒ¨ * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:37 kubem1. * * * * kubelet[7275]: E0622 04:31:37.890407 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:461: λ‚˜μ—΄μ— μ‹€νŒ¨ν–ˆμŠ΅λ‹ˆλ‹€. *v1.Node: Get https:/ /10.169.150.123 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkubem1. * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:37 kubem1. * * * * kubelet[7275]: E0622 04:31:37.891696 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:452: λ‚˜μ—΄ν•˜μ§€ λͺ»ν–ˆμŠ΅λ‹ˆλ‹€. *v1.Service: Get https:/ /10.169.150.123 :6443/api/v1/services?limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:37 kubem1. * * * * kubelet[7275]: E0622 04:31:37.946023 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: v1.Pod λ‚˜μ—΄ μ‹€νŒ¨ * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:38 kubem1. * * * * kubelet[7275]: E0622 04:31:38.121910 7275 eviction_manager.go:247] 퇴거 κ΄€λ¦¬μž: μš”μ•½ 톡계 κ°€μ Έμ˜€κΈ° μ‹€νŒ¨: λ…Έλ“œ 정보 κ°€μ Έμ˜€κΈ° μ‹€νŒ¨: λ…Έλ“œ "kubem1. * * * * "을(λ₯Ό) 찾을 수 μ—†μŒ
6μ›” 22일 04:31:38 kubem1. * * * * kubelet[7275]: E0622 04:31:38.892292 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:461: λ‚˜μ—΄μ— μ‹€νŒ¨ν–ˆμŠ΅λ‹ˆλ‹€. *v1.Node: Get https:/ /10.169.150.123 :6443/api/v1/nodes?fieldSelector=metadata.name%3Dkubem1. * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€
6μ›” 22일 04:31:38 kubem1. * * * * kubelet[7275]: E0622 04:31:38.894157 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/kubelet.go:452: λ‚˜μ—΄ν•˜μ§€ λͺ»ν–ˆμŠ΅λ‹ˆλ‹€. *v1.Service: https:/λ₯Ό κ°€μ Έμ˜΅λ‹ˆλ‹€.
6μ›” 22일 04:31:38 kubem1. * * * * kubelet[7275]: E0622 04:31:38.947002 7275 reflector.go:205] k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: v1.Pod λ‚˜μ—΄ μ‹€νŒ¨ * * * * &limit=500&resourceVersion=0: 닀이얼 tcp 10.169.150.123:6443: getsockopt: μ—°κ²° κ±°λΆ€

/etc/resolve.conf도 좔가됨

[ root@kubem1 ~]# 고양이 /etc/resolv.conf

NetworkManager에 μ˜ν•΄ 생성됨

도메인 <>

검색 <>

λ„€μž„μ„œλ²„ <>

λ„€μž„μ„œλ²„ <>

λ„€μž„μ„œλ²„ 8.8.8.8
λ„€μž„μ„œλ²„ 8.8.4.4

이 νŒŒμΌμ— ν•­λͺ©μ„ μΆ”κ°€ν•΄μ•Ό ν•©λ‹ˆκΉŒ?

μΈμ¦μ„œλ₯Ό 가져와야 ν•˜λ‚˜μš”??

λ‚˜λŠ” ν”„λ‘μ‹œ ν™˜κ²½μ— μžˆμŠ΅λ‹ˆλ‹€

λ˜ν•œ μ•„λž˜λ₯Ό μ‹œλ„ν–ˆμŠ΅λ‹ˆλ‹€.

kubeadm μž¬μ„€μ •
systemctl 데λͺ¬ λ‹€μ‹œ λ‘œλ“œ
systemctl docker.service λ‹€μ‹œ μ‹œμž‘
systemctl 쀑지 kubelet.service

μ•„λž˜ μ΄λ―Έμ§€λŠ” 도컀λ₯Ό 톡해 κ°€μ Έμ˜¬ 수 μ—†μŠ΅λ‹ˆλ‹€.

도컀 ν’€ k8s.gcr.io/kube-apiserver-amd64:v1.10.3
도컀 ν’€ k8s.gcr.io/kube-controller-manager-amd64:v1.10.3
도컀 ν’€ k8s.gcr.io/kube-scheduler-amd64:v1.10.3
도컀 ν’€ k8s.gcr.io/etcd-amd64:3.1.12

kinbug prioritimportant-longterm

κ°€μž₯ μœ μš©ν•œ λŒ“κΈ€

μ—¬κΈ°μ—μ„œ νŽΈμ§‘λœ FQDN으둜 λ³΄μ΄λŠ” spec.nodeName=kubem1.***************** λ₯Ό λ³Ό 수 μžˆμŠ΅λ‹ˆλ‹€. λ°˜λ©΄μ— DNS κ΅¬μ„±μ—λŠ” 도메인 및 검색 μ§€μ‹œλ¬Έμ΄ μ—†λŠ” 것 κ°™μŠ΅λ‹ˆλ‹€.

Google DNS μ„œλ²„κ°€ λ„€νŠΈμ›Œν¬μ—μ„œλ„ ν—ˆμš©λ©λ‹ˆκΉŒ? 이에 λŒ€ν•œ μΆ”κ°€ μ •λ³΄λŠ” 둜컬 λ„€νŠΈμ›Œν¬ κ΄€λ¦¬μžμ—κ²Œ λ¬Έμ˜ν•΄μ•Ό ν•  수 μžˆμŠ΅λ‹ˆλ‹€.

λ˜ν•œ docker pull κ°€ μ‹€νŒ¨ν•˜λ©΄ DNS 문제 λ•Œλ¬ΈμΌ 수 μžˆμŠ΅λ‹ˆλ‹€. docker pull 이(κ°€) μ‹€νŒ¨ν•˜λŠ” 였λ₯˜λŠ” λ¬΄μ—‡μž…λ‹ˆκΉŒ?

k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: Failed to list v1.Pod: Get https://10.169.150.123:6443/api/v1/pods?fieldSelector=spec.nodeName%3Dkubem1.*****************&limit=500&resourceVersion=0: dial tcp 10.169.150.123:6443: getsockopt: connection refused

λͺ¨λ“  4 λŒ“κΈ€

μ—¬κΈ°μ—μ„œ νŽΈμ§‘λœ FQDN으둜 λ³΄μ΄λŠ” spec.nodeName=kubem1.***************** λ₯Ό λ³Ό 수 μžˆμŠ΅λ‹ˆλ‹€. λ°˜λ©΄μ— DNS κ΅¬μ„±μ—λŠ” 도메인 및 검색 μ§€μ‹œλ¬Έμ΄ μ—†λŠ” 것 κ°™μŠ΅λ‹ˆλ‹€.

Google DNS μ„œλ²„κ°€ λ„€νŠΈμ›Œν¬μ—μ„œλ„ ν—ˆμš©λ©λ‹ˆκΉŒ? 이에 λŒ€ν•œ μΆ”κ°€ μ •λ³΄λŠ” 둜컬 λ„€νŠΈμ›Œν¬ κ΄€λ¦¬μžμ—κ²Œ λ¬Έμ˜ν•΄μ•Ό ν•  수 μžˆμŠ΅λ‹ˆλ‹€.

λ˜ν•œ docker pull κ°€ μ‹€νŒ¨ν•˜λ©΄ DNS 문제 λ•Œλ¬ΈμΌ 수 μžˆμŠ΅λ‹ˆλ‹€. docker pull 이(κ°€) μ‹€νŒ¨ν•˜λŠ” 였λ₯˜λŠ” λ¬΄μ—‡μž…λ‹ˆκΉŒ?

k8s.io/kubernetes/pkg/kubelet/config/apiserver.go:47: Failed to list v1.Pod: Get https://10.169.150.123:6443/api/v1/pods?fieldSelector=spec.nodeName%3Dkubem1.*****************&limit=500&resourceVersion=0: dial tcp 10.169.150.123:6443: getsockopt: connection refused

github 'spec.nodeName=kubem1.xml'에 κ²Œμ‹œν•˜κΈ° μœ„ν•΄ 이것을 νŽΈμ§‘ν–ˆμŠ΅λ‹ˆλ‹€. * * * * * '

Google DNSλŠ” 우리 λ„€νŠΈμ›Œν¬μ—μ„œ ν—ˆμš©λ˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€.

Docker pull은 λ‚˜λ¨Έμ§€ 이미지에 λŒ€ν•΄ μž‘λ™ν•˜μ§€λ§Œ "docker pull k8s.gcr.io/kube-apiserver-amd64:v1.10.3"을 λ‹ΉκΈ°λŠ” 것은 μž‘λ™ν•˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€.

ꡬ성 νŒŒμΌμ„ μˆ˜μ •ν•΄μ•Ό ν•˜λŠ” 경우 μ•Œλ €μ£Όμ‹­μ‹œμ˜€.

/ν• λ‹Ή @liztio

ν™•μ‹€ν•œ μž¬μƒμ‚° 지침이 μ—†κΈ° λ•Œλ¬Έμ— 이 문제λ₯Ό μ’…λ£Œν•©λ‹ˆλ‹€.
κ·Έλž˜λ„ λ¬Έμ œκ°€ 있으면 λ‹€μ‹œ μ—΄μ–΄μ£Όμ„Έμš”.

이 νŽ˜μ΄μ§€κ°€ 도움이 λ˜μ—ˆλ‚˜μš”?
0 / 5 - 0 λ“±κΈ‰