Update docs/reference/setup-tools/kubeadm/kubeadm.md (#11829)
* zh-trans:update docs/setup/independent/setup-ha-etcd-with-kubeadm.md * zh-trans:update docs/setup/independent/setup-ha-etcd-with-kubeadm.md
This commit is contained in:
committed by
Kubernetes Prow Robot
parent
361283e20d
commit
b697d945ef
@@ -33,10 +33,11 @@ when using kubeadm to set up a kubernetes cluster.
|
|||||||
* Three hosts that can talk to each other over ports 2379 and 2380. This document assumes these default ports. However, they are configurable through the kubeadm config file.
|
* Three hosts that can talk to each other over ports 2379 and 2380. This document assumes these default ports. However, they are configurable through the kubeadm config file.
|
||||||
-->
|
-->
|
||||||
* 三个可以通过 2379 和 2380 端口相互通信的主机。本文档使用这些作为默认端口。不过,它们可以通过 kubeadm 的配置文件进行自定义。
|
* 三个可以通过 2379 和 2380 端口相互通信的主机。本文档使用这些作为默认端口。不过,它们可以通过 kubeadm 的配置文件进行自定义。
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
* Each host must [have docker, kubelet, and kubeadm installed][toolbox].
|
* Each host must [have docker, kubelet, and kubeadm installed][toolbox].
|
||||||
-->
|
-->
|
||||||
* 每个主机必须 [安装有 docker, kubelet, 和 kubeadm][工具箱]
|
* 每个主机必须 [安装有 docker、kubelet 和 kubeadm][工具箱]。
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
* Some infrastructure to copy files between hosts. For example `ssh` and `scp` can satisfy this requirement.
|
* Some infrastructure to copy files between hosts. For example `ssh` and `scp` can satisfy this requirement.
|
||||||
@@ -62,7 +63,6 @@ The general approach is to generate all certs on one node and only distribute th
|
|||||||
-->
|
-->
|
||||||
一般来说,是在一个节点上生成所有证书并且只分发这些*必要*的文件到其它节点上。
|
一般来说,是在一个节点上生成所有证书并且只分发这些*必要*的文件到其它节点上。
|
||||||
|
|
||||||
|
|
||||||
{{< note >}}
|
{{< note >}}
|
||||||
<!--
|
<!--
|
||||||
kubeadm contains all the necessary crytographic machinery to generate the certificates described below; no other cryptographic tooling is required for this example.
|
kubeadm contains all the necessary crytographic machinery to generate the certificates described below; no other cryptographic tooling is required for this example.
|
||||||
@@ -70,7 +70,6 @@ kubeadm contains all the necessary crytographic machinery to generate the certif
|
|||||||
kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这个例子中,不需要其他加密工具。
|
kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这个例子中,不需要其他加密工具。
|
||||||
{{< /note >}}
|
{{< /note >}}
|
||||||
|
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
1. Configure the kubelet to be a service manager for etcd.
|
1. Configure the kubelet to be a service manager for etcd.
|
||||||
|
|
||||||
@@ -79,6 +78,7 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
precedence.
|
precedence.
|
||||||
-->
|
-->
|
||||||
1. 将 kubelet 配置为 etcd 的服务管理器。
|
1. 将 kubelet 配置为 etcd 的服务管理器。
|
||||||
|
|
||||||
运行 etcd 比运行 kubernetes 更简单,因此您必须通过创建具有更高优先级的新文件来覆盖 kubeadm 提供的 kubelet 单元文件。
|
运行 etcd 比运行 kubernetes 更简单,因此您必须通过创建具有更高优先级的新文件来覆盖 kubeadm 提供的 kubelet 单元文件。
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
@@ -93,17 +93,18 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
systemctl restart kubelet
|
systemctl restart kubelet
|
||||||
```
|
```
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
1. Create configuration files for kubeadm.
|
1.Create configuration files for kubeadm.
|
||||||
|
|
||||||
|
Generate one kubeadm configuration file for each host that will have an etcd
|
||||||
|
member running on it using the following script.
|
||||||
|
-->
|
||||||
|
|
||||||
Generate one kubeadm configuration file for each host that will have an etcd
|
|
||||||
member running on it using the following script.
|
|
||||||
-->
|
|
||||||
1. 为 kubeadm 创建配置文件。
|
1. 为 kubeadm 创建配置文件。
|
||||||
|
|
||||||
使用以下脚本为每个将要运行 etcd 成员的主机生成一个 kubeadm 配置文件。
|
使用以下脚本为每个将要运行 etcd 成员的主机生成一个 kubeadm 配置文件。
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
```sh
|
```sh
|
||||||
# Update HOST0, HOST1, and HOST2 with the IPs or resolvable names of your hosts
|
# Update HOST0, HOST1, and HOST2 with the IPs or resolvable names of your hosts
|
||||||
export HOST0=10.0.0.6
|
export HOST0=10.0.0.6
|
||||||
@@ -139,9 +140,9 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
EOF
|
EOF
|
||||||
done
|
done
|
||||||
```
|
```
|
||||||
-->
|
-->
|
||||||
```sh
|
```sh
|
||||||
# 使用 IP 或是可解析的主机名替换 HOST0, HOST1, 和 HOST2
|
# 使用 IP 或可解析的主机名替换 HOST0、HOST1 和 HOST2
|
||||||
export HOST0=10.0.0.6
|
export HOST0=10.0.0.6
|
||||||
export HOST1=10.0.0.7
|
export HOST1=10.0.0.7
|
||||||
export HOST2=10.0.0.8
|
export HOST2=10.0.0.8
|
||||||
@@ -175,17 +176,18 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
EOF
|
EOF
|
||||||
done
|
done
|
||||||
```
|
```
|
||||||
<!--
|
|
||||||
1. Generate the certificate authority
|
|
||||||
|
|
||||||
If you already have a CA then the only action that is copying the CA's `crt` and
|
<!--
|
||||||
`key` file to `/etc/kubernetes/pki/etcd/ca.crt` and
|
1.Generate the certificate authority
|
||||||
`/etc/kubernetes/pki/etcd/ca.key`. After those files have been copied,
|
|
||||||
proceed to the next step, "Create certificates for each member".
|
If you already have a CA then the only action that is copying the CA's `crt` and
|
||||||
-->
|
`key` file to `/etc/kubernetes/pki/etcd/ca.crt` and
|
||||||
|
`/etc/kubernetes/pki/etcd/ca.key`. After those files have been copied,
|
||||||
|
proceed to the next step, "Create certificates for each member".
|
||||||
|
-->
|
||||||
1. 生成证书颁发机构
|
1. 生成证书颁发机构
|
||||||
|
|
||||||
如果您已经拥有 CA,那么唯一的操作是复制 CA 的 `crt` 和 `key` 文件到 `etc/kubernetes/pki/etcd/ca.crt` 和 /etc/kubernetes/pki/etcd/ca.key`。复制完这些文件后继续下一步,“为每个成员创建证书”。
|
如果您已经拥有 CA,那么唯一的操作是复制 CA 的 `crt` 和 `key` 文件到 `etc/kubernetes/pki/etcd/ca.crt` 和 `/etc/kubernetes/pki/etcd/ca.key`。复制完这些文件后继续下一步,“为每个成员创建证书”。
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
If you do not already have a CA then run this command on `$HOST0` (where you generated the configuration files for kubeadm).
|
If you do not already have a CA then run this command on `$HOST0` (where you generated the configuration files for kubeadm).
|
||||||
@@ -207,7 +209,7 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
<!--
|
<!--
|
||||||
1. Create certificates for each member
|
1. Create certificates for each member
|
||||||
-->
|
-->
|
||||||
1. 为每个成员创建证书
|
1. 为每个成员创建证书
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
```sh
|
```sh
|
||||||
@@ -264,34 +266,34 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
find /tmp/${HOST1} -name ca.key -type f -delete
|
find /tmp/${HOST1} -name ca.key -type f -delete
|
||||||
```
|
```
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
1. Copy certificates and kubeadm configs
|
1.Copy certificates and kubeadm configs
|
||||||
|
|
||||||
The certificates have been generated and now they must be moved to their
|
The certificates have been generated and now they must be moved to their
|
||||||
respective hosts.
|
respective hosts.
|
||||||
-->
|
-->
|
||||||
1. 复制证书和 kubeadm 配置
|
1. 复制证书和 kubeadm 配置
|
||||||
|
|
||||||
证书已生成,现在必须将它们移动到对应的主机。
|
证书已生成,现在必须将它们移动到对应的主机。
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
USER=ubuntu
|
USER=ubuntu
|
||||||
HOST=${HOST1}
|
HOST=${HOST1}
|
||||||
scp -r /tmp/${HOST}/* ${USER}@${HOST}:
|
scp -r /tmp/${HOST}/* ${USER}@${HOST}:
|
||||||
ssh ${USER}@${HOST}
|
ssh ${USER}@${HOST}
|
||||||
USER@HOST $ sudo -Es
|
USER@HOST $ sudo -Es
|
||||||
root@HOST $ chown -R root:root pki
|
root@HOST $ chown -R root:root pki
|
||||||
root@HOST $ mv pki /etc/kubernetes/
|
root@HOST $ mv pki /etc/kubernetes/
|
||||||
```
|
```
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
1. Ensure all expected files exist
|
1.Ensure all expected files exist
|
||||||
|
|
||||||
The complete list of required files on `$HOST0` is:
|
The complete list of required files on `$HOST0` is:
|
||||||
-->
|
-->
|
||||||
1. 确保已经所有预期的文件都存在
|
1. 确保已经所有预期的文件都存在
|
||||||
|
|
||||||
`$HOST0` 所需文件的完整列表如下:
|
`$HOST0` 所需文件的完整列表如下:
|
||||||
|
|
||||||
```
|
```
|
||||||
/tmp/${HOST0}
|
/tmp/${HOST0}
|
||||||
@@ -311,9 +313,9 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
└── server.key
|
└── server.key
|
||||||
```
|
```
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
On `$HOST1`:
|
On `$HOST1`:
|
||||||
-->
|
-->
|
||||||
在 `$HOST1`:
|
在 `$HOST1`:
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -333,9 +335,9 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
└── server.key
|
└── server.key
|
||||||
```
|
```
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
On `$HOST2`
|
On `$HOST2`
|
||||||
-->
|
-->
|
||||||
在 `$HOST2`
|
在 `$HOST2`
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -355,12 +357,13 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
└── server.key
|
└── server.key
|
||||||
```
|
```
|
||||||
|
|
||||||
<!-- 1. Create the static pod manifests
|
<!--
|
||||||
|
1.Create the static pod manifests
|
||||||
|
|
||||||
Now that the certificates and configs are in place it's time to create the
|
Now that the certificates and configs are in place it's time to create the
|
||||||
manifests. On each host run the `kubeadm` command to generate a static manifest
|
manifests. On each host run the `kubeadm` command to generate a static manifest
|
||||||
for etcd.
|
for etcd.
|
||||||
-->
|
-->
|
||||||
1. 创建静态 Pod 清单
|
1. 创建静态 Pod 清单
|
||||||
|
|
||||||
既然证书和配置已经就绪,是时候去创建清单了。在每台主机上运行 `kubeadm` 命令来生成 etcd 使用的静态清单。
|
既然证书和配置已经就绪,是时候去创建清单了。在每台主机上运行 `kubeadm` 命令来生成 etcd 使用的静态清单。
|
||||||
@@ -371,9 +374,9 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
|
|||||||
root@HOST2 $ kubeadm alpha phase etcd local --config=/home/ubuntu/kubeadmcfg.yaml
|
root@HOST2 $ kubeadm alpha phase etcd local --config=/home/ubuntu/kubeadmcfg.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
1. Optional: Check the cluster health
|
1.Optional: Check the cluster health
|
||||||
-->
|
-->
|
||||||
1. 可选:检查群集运行状况
|
1. 可选:检查群集运行状况
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
|
|||||||
Reference in New Issue
Block a user