在 Debian 上使用 kubeadm 快速搭建单主集群
一 环境准备
sudo swapoff -a,并在 /etc/fstab 中注释 swap 行,避免重启后恢复。二 安装容器运行时 containerd
sudo apt update
sudo apt install -y apt-transport-https ca-certificates curl
curl -fsSL https://download.docker.com/linux/debian/gpg | sudo apt-key add -
echo "deb [arch=amd64] https://download.docker.com/linux/debian $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/containerd.list
sudo apt update
sudo apt install -y containerd
sudo systemctl enable --now containerd
sudo tee /etc/modules-load.d/containerd.conf <<EOF
overlay
br_netfilter
EOF
sudo modprobe overlay
sudo modprobe br_netfilter
sudo tee /etc/sysctl.d/99-kubernetes-k8s.conf <<EOF
net.bridge.bridge-nf-call-iptables = 1
net.ipv4.ip_forward = 1
EOF
sudo sysctl --system
三 安装 kubeadm kubelet kubectl
sudo apt update
sudo apt install -y apt-transport-https curl
curl -s https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo apt-key add -
echo "deb https://apt.kubernetes.io/ kubernetes-xenial main" | sudo tee /etc/apt/sources.list.d/kubernetes.list
sudo apt update
sudo apt install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
sudo systemctl enable --now kubelet
四 初始化 Master 并配置 kubectl
sudo kubeadm init --pod-network-cidr=10.244.0.0/16
--apiserver-advertise-address=<Master_IP>--image-repository=registry.aliyuncs.com/google_containers--service-cidr=10.1.0.0/16mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml
五 加入 Worker 与验证
kubeadm init 完成后输出的 kubeadm join 命令,例如:sudo kubeadm join <Master_IP>:6443 --token <token> --discovery-token-ca-cert-hash sha256:<hash>
若 token 过期,可在 Master 上执行 kubeadm token create --print-join-command 重新生成。kubectl get nodes
kubectl get pods --all-namespaces
等待片刻,所有节点状态应为 Ready。常见问题与提示
--image-repository=registry.aliyuncs.com/google_containers 加速;或提前在各节点 docker pull/crictl 拉取所需镜像。pod-network-cidr 与插件配置一致;检查 kubelet 日志 journalctl -u kubelet -f。sudo kubeadm reset -f,清理后重新 kubeadm init。