在 Debian 上使用 kubeadm 安装 Kubernetes 的标准流程
一 环境准备
sudo hostnamectl set-hostname k8s-master01.test.localsudo hostnamectl set-hostname k8s-worker01.test.local192.168.1.100 k8s-master01.test.local k8s-master01
192.168.1.101 k8s-worker01.test.local k8s-worker01
192.168.1.102 k8s-worker02.test.local k8s-worker02
sudo swapoff -asudo sed -i '/ swap / s/^/#/g' /etc/fstabsudo apt install -y ntp),避免证书校验与组件异常。二 安装容器运行时 containerd
sudo apt update && sudo apt install -y containerdsudo tee /etc/modules-load.d/containerd.conf <<EOF
overlay
br_netfilter
EOF
sudo modprobe overlay
sudo modprobe br_netfilter
sudo tee /etc/sysctl.d/99-kubernetes-k8s.conf <<EOF
net.bridge.bridge-nf-call-iptables = 1
net.ipv4.ip_forward = 1
EOF
sudo sysctl --system
sudo containerd config default | sudo tee /etc/containerd/config.toml[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options] 下添加 SystemdCgroup = truesudo systemctl enable --now containerd三 安装 kubeadm kubelet kubectl
curl -s https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo apt-key add -
echo "deb https://apt.kubernetes.io/ kubernetes-xenial main" | sudo tee /etc/apt/sources.list.d/kubernetes.list
sudo apt update
sudo apt install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
sudo systemctl enable --now kubelet
sudo apt-get install -y kubelet=1.23.6-00 kubeadm=1.23.6-00 kubectl=1.23.6-00四 初始化控制平面并配置 kubectl
sudo kubeadm init --pod-network-cidr=10.244.0.0/16sudo kubeadm init --apiserver-advertise-address=<MASTER_IP> --image-repository registry.aliyuncs.com/google_containers --service-cidr=10.10.0.0/16 --pod-network-cidr=172.16.0.0/16mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.ymlkubectl apply -f https://docs.projectcalico.org/manifests/calico.yamlsudo kubeadm join <MASTER_IP>:6443 --token <TOKEN> --discovery-token-ca-cert-hash sha256:<HASH>kubectl cluster-infokubectl get nodes五 常见问题与排错要点
kubeadm init 中使用 --image-repository registry.aliyuncs.com/google_containers 加速;或提前在各节点 docker pull/crictl 拉取所需镜像。--pod-network-cidr 与插件配置一致;检查 10250 等端口连通性。