k8s的 Node and Cluster实战

Node and Cluster

查看节点

bash 复制代码
# 查看节点清单
root@master30 ~ 14:58:52# kubectl get nodes 
NAME                 STATUS   ROLES           AGE   VERSION
master30.ggg.cloud   Ready    control-plane   95m   v1.30.2
worker31.ggg.cloud   Ready    <none>          28m   v1.30.2
worker32.ggg.cloud   Ready    <none>          28m   v1.30.2

# 查看特定节点详细信息
root@master30 ~ 15:21:38# kubectl describe node worker31.ggg.cloud
#重点关注Labels,Conditions,Non-terminated Pod,Allocated resources等

删除节点

以 worker31 节点为例。

bash 复制代码
# 设置节点为维护模式
root@master30 ~ 15:23:12# kubectl drain worker31.ggg.cloud --ignore-daemonsets
node/worker31.ggg.cloud already cordoned
Warning: ignoring DaemonSet-managed Pods: kube-system/calico-node-6bltt, kube-system/kube-proxy-kx6kn
node/worker31.ggg.cloud drained
root@master30 ~ 15:23:24# kubectl get nodes 
NAME                 STATUS                     ROLES           AGE   VERSION
master30.ggg.cloud   Ready                      control-plane   97m   v1.30.2
worker31.ggg.cloud   Ready,SchedulingDisabled   <none>          30m   v1.30.2
worker32.ggg.cloud   Ready                      <none>          30m   v1.30.2

# 删除 worker31 节点
root@master30 ~ 15:23:27# kubectl delete node worker31.ggg.cloud 
node "worker31.ggg.cloud" deleted
root@master30 ~ 15:23:50# kubectl get nodes 
NAME                 STATUS   ROLES           AGE   VERSION
master30.ggg.cloud   Ready    control-plane   97m   v1.30.2
worker32.ggg.cloud   Ready    <none>          31m   v1.30.2

# 重置删除的 worker31 节点
root@worker31 ~ 15:24:18# kubeadm reset -f
[preflight] Running pre-flight checks
W0805 15:24:26.048287   10253 removeetcdmember.go:106] [reset] No kubeadm config, using etcd pod spec to get data directory
[reset] Deleted contents of the etcd data directory: /var/lib/etcd
[reset] Stopping the kubelet service
[reset] Unmounting mounted directories in "/var/lib/kubelet"
[reset] Deleting contents of directories: [/etc/kubernetes/manifests /var/lib/kubelet /etc/kubernetes/pki]
[reset] Deleting files: [/etc/kubernetes/admin.conf /etc/kubernetes/super-admin.conf /etc/kubernetes/kubelet.conf /etc/kubernetes/bootstrap-kubelet.conf /etc/kubernetes/controller-manager.conf /etc/kubernetes/scheduler.conf]

The reset process does not clean CNI configuration. To do so, you must remove /etc/cni/net.d

The reset process does not reset or clean up iptables rules or IPVS tables.
If you wish to reset iptables, you must do so manually by using the "iptables" command.

If your cluster was setup to utilize IPVS, run ipvsadm --clear (or similar)
to reset your system's IPVS tables.

The reset process does not clean your kubeconfig files and you must remove them manually.
Please, check the contents of the $HOME/.kube/config file.


#重新加入 worker31 节点
root@worker31 ~ 15:24:26# kubeadm join 10.1.8.30:6443 --token cum331.6m74ji4yo7ffi5tw \
        --discovery-token-ca-cert-hash sha256:6f83aa8722974ef53128918a78da3fdcf931db14f779941343e11862cc39c1d8
[preflight] Running pre-flight checks
[preflight] Reading configuration from the cluster...
[preflight] FYI: You can look at this config file with 'kubectl -n kube-system get cm kubeadm-config -o yaml'
[kubelet-start] Writing kubelet configuration to file "/var/lib/kubelet/config.yaml"
[kubelet-start] Writing kubelet environment file with flags to file "/var/lib/kubelet/kubeadm-flags.env"
[kubelet-start] Starting the kubelet
[kubelet-check] Waiting for a healthy kubelet. This can take up to 4m0s
[kubelet-check] The kubelet is healthy after 501.227089ms
[kubelet-start] Waiting for the kubelet to perform the TLS Bootstrap

This node has joined the cluster:
* Certificate signing request was sent to apiserver and a response was received.
* The Kubelet was informed of the new secure connection details.

Run 'kubectl get nodes' on the control-plane to see this node join the cluster.

#验证
root@master30 ~ 15:24:43# kubectl get nodes 
NAME                 STATUS   ROLES           AGE   VERSION
master30.ggg.cloud   Ready    control-plane   99m   v1.30.2
worker31.ggg.cloud   Ready    <none>          22s   v1.30.2
worker32.ggg.cloud   Ready    <none>          32m   v1.30.2

删除集群

删除集群流程:

  1. 删除所有 node
  2. 删除所有 master

具体步骤:

  1. 删除所有node节点
bash 复制代码
root@master30 ~ 15:25:18#  kubectl drain worker31.ggg.cloud --ignore-daemonsets --force
root@master30 ~ 15:45:50# kubectl drain worker32.ggg.cloud --ignore-daemonsets --force
root@master30 ~ 15:46:01# kubectl delete node worker31.ggg.cloud worker32.ggg.cloud

# 重置节点,注意执行位置
root@worker31 ~ 15:24:18# kubeadm reset -f
root@worker32 ~ 14:58:56# kubeadm reset -f
  1. 删除master节点
bash 复制代码
# 删除集群前获取集群配置
root@master30 ~ 15:46:12# kubectl get cm kubeadm-config -n kube-system -o yaml > kubeadm.yml

# 修改kubeadm.yml内容如下:
root@master30 ~ 15:46:22# vim kubeadm.yml
# 删除1-3和22-28行,效果如下
apiServer:
  timeoutForControlPlane: 4m0s
apiVersion: kubeadm.k8s.io/v1beta3
certificatesDir: /etc/kubernetes/pki
clusterName: kubernetes
controllerManager: {}
dns: {}
etcd:
  local:
    dataDir: /var/lib/etcd
imageRepository: registry.k8s.io
kind: ClusterConfiguration
kubernetesVersion: v1.30.2
networking:
  dnsDomain: cluster.local
  podSubnet: 10.224.0.0/16
  serviceSubnet: 10.96.0.0/12
scheduler: {}

root@master30 ~ 15:46:44# kubectl delete node master30.ggg.cloud
root@master30 ~ 15:46:47# kubeadm reset -f
root@master30 ~ 15:46:53# rm -fr .kube/

重建集群

bash 复制代码
# 初始化集群
root@master30 ~ 15:53:44# kubeadm init --config kubeadm.yml

# 也可以使用之前的命令
root@master30 ~ 15:53:44# kubeadm init --kubernetes-version=v1.30.2 --pod-network-cidr=10.224.0.0/16

# 配置凭据
root@master30 ~ 15:54:17# mkdir -p $HOME/.kube
root@master30 ~ 15:54:17# sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
root@master30 ~ 15:54:17# sudo chown $(id -u):$(id -g) $HOME/.kube/config

# 配置网络
root@master30 ~ 15:53:59# kubectl apply -f calico.yaml

# 加入集群
root@worker31 ~ 15:46:24# kubeadm join 10.1.8.30:6443 --token quq3fd.z2cxskllch0gqo5i \
        --discovery-token-ca-cert-hash sha256:fc8f6417071df50562346fdfb79f4459ea8ba1c8f05031607ea75794ac593dfa
root@worker32 ~ 15:46:29# kubeadm join 10.1.8.30:6443 --token quq3fd.z2cxskllch0gqo5i \
        --discovery-token-ca-cert-hash sha256:fc8f6417071df50562346fdfb79f4459ea8ba1c8f05031607ea75794ac593dfa
相关推荐
吴声子夜歌11 小时前
Docker入门与实战——初识Docker与容器
docker·容器
MrSYJ13 小时前
Docker端口映射咋做的,模拟下。
docker·云原生·kubernetes
张小凡vip14 小时前
Kubernetes--k8s---了解和使用configmap挂载配置文件
云原生·容器·kubernetes
bluebonnet2715 小时前
【docker】容器内映射外部音频驱动
docker·容器·音视频
吴声子夜歌15 小时前
Docker入门与实战——核心概念与安装配置
运维·docker·容器
guo_wen_qiang1 天前
docker的备份与迁移
运维·docker·容器
小小龙学IT1 天前
Kubernetes 深度实践:架构、API 与避坑指南
容器·架构·kubernetes
MrSYJ1 天前
别人再问你路由表是啥,这篇文章摔它脸上
docker·云原生·kubernetes
羑悻2 天前
穿越Docker内核迷雾:揭秘镜像分层存储的叠加态与卷挂载的多维空间穿梭技术
后端·docker·容器
吴声子夜歌2 天前
Nginx应用与运维——Nginx在Kubernetes中的应用(一)
运维·nginx·kubernetes