在 CentOS 上用 kubeadm 部署 Kubernetes 的可复现步骤
一 环境准备与系统初始化
swapoff -ased -ri 's/.*swap.*/#&/' /etc/fstabsetenforce 0sed -i 's/^SELINUX=.*/SELINUX=disabled/' /etc/selinux/configsystemctl stop firewalld && systemctl disable firewalldcat > /etc/sysctl.d/k8s.conf << EOFnet.bridge.bridge-nf-call-ip6tables = 1net.bridge.bridge-nf-call-iptables = 1net.ipv4.ip_forward = 1EOFsysctl --systemhostnamectl set-hostname k8s-master(Node 改为 k8s-node1/2)cat >> /etc/hosts << EOF192.168.0.10 k8s-master192.168.0.11 k8s-node1192.168.0.12 k8s-node2EOFyum install -y ntpdate && ntpdate time.windows.com(或内网 NTP)yum install -y yum-utils && yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repoyum install -y docker-ce docker-ce-cli containerd.iosystemctl start docker && systemctl enable dockermkdir -p /etc/dockercat > /etc/docker/daemon.json << EOF{ "exec-opts": ["native.cgroupdriver=systemd"] }EOFsystemctl restart docker二 安装 kubeadm kubelet kubectl
cat > /etc/yum.repos.d/kubernetes.repo << EOF[kubernetes]name=Kubernetesbaseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el7-x86_64/enabled=1gpgcheck=1repo_gpgcheck=1gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpgEOFyum install -y kubelet kubeadm kubectlsystemctl enable --now kubelet(此时 kubelet 可能反复重启,属正常,待 init 后恢复)kubeadm config images list 查看所需镜像三 初始化 Master 与加入 Node
kubeadm init --apiserver-advertise-address=<MASTER_IP> --pod-network-cidr=10.244.0.0/16mkdir -p $HOME/.kubecp -i /etc/kubernetes/admin.conf $HOME/.kube/configchown $(id -u):$(id -g) $HOME/.kube/configkubeadm token create --print-join-commandkubeadm token list(配合 openssl x509 -pubkey -in /etc/kubernetes/pki/ca.crt | openssl rsa -pubin -outform der 2>/dev/null | openssl dgst -sha256 -hex | sed 's/^.* //' 获取哈希)kubeadm join <MASTER_IP>:6443 --token <TOKEN> --discovery-token-ca-cert-hash sha256:<HASH>--pod-network-cidr 必须与所选网络插件一致(Flannel 用 10.244.0.0/16,Calico 常用 192.168.0.0/16)四 部署网络插件
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.ymlkubectl apply -f https://docs.projectcalico.org/manifests/calico.yamlkubectl get pods -n kube-system 确认 kube-flannel 或 calico Pod 均为 Runningkubectl get nodes 确认节点 Ready五 验证与常见问题处理
kubectl cluster-infokubectl get nodes -o widekubectl get pods --all-namespacesdocker load 所需镜像。kubeadm token create --print-join-command 重新生成加入命令。