版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
Kubernetes高可用集群-高可用配置目录01任务高可用配置软件包准备02任务学习目标【知识目标】●了解kubeadm工具的使用方法;●
掌握Kubernetes集群的高可用配置。【技能目标】●
能够利用keepalived+nginx实现k8sapiserver节点高可用;●
能够基于搭建过程中出现的问题进行基础排错。1软件包准备1安装软件包三节点安装初始化Kubernetes需要的软件包,并启动kubelet服务,设置开机自启,以master节点为例,代码如下:[root@master1~]#yuminstall-ykubelet-1.20.6kubeadm-1.20.6kubectl-1.20.6[root@master1~]#systemctlenablekubelet[root@master1~]#systemctlstartkubelet软件包准备1安装软件包查看kubelet服务状态:[root@master1~]#systemctlstatuskubelet输出结果如下:软件包准备2高可用配置通过keepalived+nginx实现apiserver节点高可用把epel.repo上传到master1的/etc/yum.repos.d目录下,#并拷贝到远程主机master2和node1上[root@master1~]#scp/etc/yum.repos.d/epel.repomaster2:/etc/yum.repos.d/[root@master1~]#scp/etc/yum.repos.d/epel.reponode1:/etc/yum.repos.d/2配置epel源通过keepalived+nginx实现apiserver节点高可用在master1和master2上做nginx主备安装[root@master1~]#yuminstallnginxkeepalived-y[root@master2~]#yuminstallnginxkeepalived-y2安装nginx和keepalived通过keepalived+nginx实现apiserver节点高可用[root@master1~]#vim/etc/nginx/nginx.confusernginx;worker_processesauto;error_log/var/log/nginx/error.log;pid/run/nginx.pid;include/usr/share/nginx/modules/*.conf;events{worker_connections1024;}2修改nginx配置文件#四层负载均衡,为两台Masterapiserver组件提供负载均衡stream{log_formatmain'$remote_addr$upstream_addr-[$time_local]$status$upstream_bytes_sent';access_log/var/log/nginx/k8s-access.logmain;upstreamk8s-apiserver{server0:6443;#Master1APISERVERIP:PORTserver0:6443;#Master2APISERVERIP:PORT}
server{listen16443;#由于nginx与master节点复用,这个监听端口不能是6443,否则会冲突proxy_passk8s-apiserver;}}通过keepalived+nginx实现apiserver节点高可用http{log_formatmain'$remote_addr-$remote_user[$time_local]"$request"''$status$body_bytes_sent"$http_referer"''"$http_user_agent""$http_x_forwarded_for"';access_log/var/log/nginx/access.logmain;sendfile
on;tcp_nopush
on;tcp_nodelay
on;keepalive_timeout
65;types_hash_max_size
2048;2修改nginx配置文件include/etc/nginx/mime.types;default_typeapplication/octet-stream;server{listen80default_server;server_name_;location/{}}}通过keepalived+nginx实现apiserver节点高可用在master2节点[root@master2keepalived]#yuminstallnginx-mod-stream-y2nginx增加stream模块通过keepalived+nginx实现apiserver节点高可用[root@master2~]#vim/etc/nginx/nginx.confusernginx;worker_processesauto;error_log/var/log/nginx/error.log;pid/run/nginx.pid;include/usr/share/nginx/modules/*.conf;events{worker_connections1024;}2修改nginx配置文件#四层负载均衡,为两台Masterapiserver组件提供负载均衡stream{log_formatmain'$remote_addr$upstream_addr-[$time_local]$status$upstream_bytes_sent';access_log/var/log/nginx/k8s-access.logmain;upstreamk8s-apiserver{server0:6443;#Master1APISERVERIP:PORTserver0:6443;#Master2APISERVERIP:PORT}
server{listen16443;#由于nginx与master节点复用,这个监听端口不能是6443,否则会冲突proxy_passk8s-apiserver;}}通过keepalived+nginx实现apiserver节点高可用http{log_formatmain'$remote_addr-$remote_user[$time_local]"$request"''$status$body_bytes_sent"$http_referer"''"$http_user_agent""$http_x_forwarded_for"';access_log/var/log/nginx/access.logmain;sendfile
on;tcp_nopush
on;tcp_nodelay
on;keepalive_timeout
65;types_hash_max_size
2048;2修改nginx配置文件include/etc/nginx/mime.types;default_typeapplication/octet-stream;server{listen80default_server;server_name_;location/{}}}通过keepalived+nginx实现apiserver节点高可用[root@master1~]#vim/etc/keepalived/keepalived.confglobal_defs{notification_email{acassen@firewall.locfailover@firewall.locsysadmin@firewall.loc}notification_email_fromAlexandre.Cassen@firewall.locsmtp_serversmtp_connect_timeout30router_idNGINX_MASTER}vrrp_scriptcheck_nginx{script"/etc/keepalived/check_nginx.sh"}2主keepalived配置vrrp_instanceVI_1{stateMASTERinterfaceens33#修改为实际网卡名virtual_router_id51#VRRP路由ID实例,每个实例是唯一的priority100#优先级,备服务器设置90advert_int1#指定VRRP心跳包通告间隔时间,默认1秒authentication{auth_typePASSauth_pass1111}virtual_ipaddress{99/24
#虚拟IP}track_script{check_nginx}}通过keepalived+nginx实现apiserver节点高可用2主keepalived配置准备上述配置文件中检查Nginx运行状态的脚本[root@master1~]#vim/etc/keepalived/check_nginx.sh#!/bin/bashcount=$(ps-ef|grepnginx|grepsbin|egrep-cv"grep|$$")if["$count"-eq0];thensystemctlstopkeepalivedfi[root@master1~]#chmod+x/etc/keepalived/check_nginx.sh通过keepalived+nginx实现apiserver节点高可用[root@master2~]#vim/etc/keepalived/keepalived.confglobal_defs{notification_email{acassen@firewall.locfailover@firewall.locsysadmin@firewall.loc}notification_email_fromAlexandre.Cassen@firewall.locsmtp_serversmtp_connect_timeout30router_idNGINX_MASTER}vrrp_scriptcheck_nginx{script"/etc/keepalived/check_nginx.sh"}2备keepalived配置vrrp_instanceVI_1{stateBACKUPinterfaceens33virtual_router_id51#VRRP路由ID实例,每个实例是唯一的priority90advert_int1authentication{auth_typePASSauth_pass1111}virtual_ipaddress{99/24}track_script{check_nginx}}通过keepalived+nginx实现apiserver节点高可用2备keepalived配置准备上述配置文件中检查Nginx运行状态的脚本[root@master2~]#vim/etc/keepalived/check_nginx.sh#!/bin/bashcount=$(ps-ef|grepnginx|grepsbin|egrep-cv"grep|$$")if["$count"-eq0];thensystemctlstopkeepalivedfi[root@master2~]#chmod+x/etc/keepalived/check_nginx.sh通过keepalived+nginx实现apiserver节点高可用2启动服务master1和master2操作相同,以master1为例[root@master1~]#systemctldaemon-reload[root@master1~]#systemctlstartnginx[root@master1~]#systemctlstartkeepalived[root@master1~]#systemctlenablenginxkeepalived[root@master1
~]#systemctlstatuskeepalived通过keepalived+nginx实现apiserver节点高可用2测试vip是否绑定成功通过ipaddr查看master1节点vip[root@master1~]#ipaddr1:lo:<LOOPBACK,UP,LOWER_UP>mtu65536qdiscnoqueuestate。。。2:ens33:<BROADCAST,MULTICAST,UP,LOWER_UP>mtu1500qdiscpfifo_faststateUPgroupdefaultqlen1000link/ether00:0c:29:91:f9:12brdff:ff:ff:ff:ff:ffinet192.168.116.10/24brd55scopeglobalnoprefixrouteens33valid_lftforeverpreferred_lftforeverinet99/24scopeglobalsecondaryens33valid_lftforeverpreferred_lftforeverinet6fe80::5dc1:f326:2132:7365/64scopelinknoprefixroutevalid_lftforeverpreferred_lftforever通过keepalived+nginx实现apiserver节点高可用2测试keepalived停掉master1上的nginx。Vip会漂移到master2[root@master1
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026湖南长沙麓山国际昌济中学公开招聘物理校聘教师考试参考题库及答案解析
- 2026上海海事大学招聘59人(第一批)笔试模拟试题及答案解析
- 2026某企业劳务外包工作人员招聘笔试参考题库及答案解析
- 动脉血气分析仪器使用与维护
- 2026年哈尔滨市风华中学校招聘临时聘用教师4人笔试备考题库及答案解析
- 投行职业规划手册
- 2025年郑州工业安全职业学院单招职业适应性测试试题及答案解析
- 2026甘肃建设社区卫生服务中心(嘉峪关市老年病医院)招聘11人考试参考题库及答案解析
- 2025年六盘水幼儿师范高等专科学校单招职业技能考试题库及答案解析
- 2026新疆兵团第 三师法院系统聘用制书记员招聘(8人)笔试备考试题及答案解析
- 2025高二英语冲刺卷
- 血吸虫防治培训课件
- 留学行业分析和市场分析报告
- 《银行会计(第四版)》全套教学课件
- 2025-2030中国激光切割行业市场竞争力深度解析及行业未来发展方向与前景规划报告
- 周黑鸭合同协议书
- DB34∕T 5013-2025 工程建设项目招标代理规程
- 餐厅临时工作人员培训教材
- 2026年江西司法警官职业学院单招职业技能考试题库及答案1套
- 去极端化宣传课件
- 2025财政部部属单位招聘笔试历年参考题库附带答案详解
评论
0/150
提交评论