Update docs/reference/setup-tools/kubeadm/kubeadm.md (#11829)

* zh-trans:update docs/setup/independent/setup-ha-etcd-with-kubeadm.md

* zh-trans:update docs/setup/independent/setup-ha-etcd-with-kubeadm.md
This commit is contained in:
SataQiu
2018-12-21 22:37:21 +08:00
committed by Kubernetes Prow Robot
parent 361283e20d
commit b697d945ef
@@ -33,10 +33,11 @@ when using kubeadm to set up a kubernetes cluster.
* Three hosts that can talk to each other over ports 2379 and 2380. This document assumes these default ports. However, they are configurable through the kubeadm config file. * Three hosts that can talk to each other over ports 2379 and 2380. This document assumes these default ports. However, they are configurable through the kubeadm config file.
--> -->
* 三个可以通过 2379 和 2380 端口相互通信的主机。本文档使用这些作为默认端口。不过,它们可以通过 kubeadm 的配置文件进行自定义。 * 三个可以通过 2379 和 2380 端口相互通信的主机。本文档使用这些作为默认端口。不过,它们可以通过 kubeadm 的配置文件进行自定义。
<!-- <!--
* Each host must [have docker, kubelet, and kubeadm installed][toolbox]. * Each host must [have docker, kubelet, and kubeadm installed][toolbox].
--> -->
* 每个主机必须 [安装有 docker, kubelet, 和 kubeadm][工具箱] * 每个主机必须 [安装有 dockerkubelet 和 kubeadm][工具箱]
<!-- <!--
* Some infrastructure to copy files between hosts. For example `ssh` and `scp` can satisfy this requirement. * Some infrastructure to copy files between hosts. For example `ssh` and `scp` can satisfy this requirement.
@@ -62,7 +63,6 @@ The general approach is to generate all certs on one node and only distribute th
--> -->
一般来说,是在一个节点上生成所有证书并且只分发这些*必要*的文件到其它节点上。 一般来说,是在一个节点上生成所有证书并且只分发这些*必要*的文件到其它节点上。
{{< note >}} {{< note >}}
<!-- <!--
kubeadm contains all the necessary crytographic machinery to generate the certificates described below; no other cryptographic tooling is required for this example. kubeadm contains all the necessary crytographic machinery to generate the certificates described below; no other cryptographic tooling is required for this example.
@@ -70,7 +70,6 @@ kubeadm contains all the necessary crytographic machinery to generate the certif
kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这个例子中,不需要其他加密工具。 kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这个例子中,不需要其他加密工具。
{{< /note >}} {{< /note >}}
<!-- <!--
1. Configure the kubelet to be a service manager for etcd. 1. Configure the kubelet to be a service manager for etcd.
@@ -79,6 +78,7 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
precedence. precedence.
--> -->
1. 将 kubelet 配置为 etcd 的服务管理器。 1. 将 kubelet 配置为 etcd 的服务管理器。
运行 etcd 比运行 kubernetes 更简单,因此您必须通过创建具有更高优先级的新文件来覆盖 kubeadm 提供的 kubelet 单元文件。 运行 etcd 比运行 kubernetes 更简单,因此您必须通过创建具有更高优先级的新文件来覆盖 kubeadm 提供的 kubelet 单元文件。
```sh ```sh
@@ -93,17 +93,18 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
systemctl restart kubelet systemctl restart kubelet
``` ```
<!-- <!--
1. Create configuration files for kubeadm. 1.Create configuration files for kubeadm.
Generate one kubeadm configuration file for each host that will have an etcd
member running on it using the following script.
-->
Generate one kubeadm configuration file for each host that will have an etcd
member running on it using the following script.
-->
1. 为 kubeadm 创建配置文件。 1. 为 kubeadm 创建配置文件。
    使用以下脚本为每个将要运行 etcd 成员的主机生成一个 kubeadm 配置文件。 使用以下脚本为每个将要运行 etcd 成员的主机生成一个 kubeadm 配置文件。
<!-- <!--
```sh ```sh
# Update HOST0, HOST1, and HOST2 with the IPs or resolvable names of your hosts # Update HOST0, HOST1, and HOST2 with the IPs or resolvable names of your hosts
export HOST0=10.0.0.6 export HOST0=10.0.0.6
@@ -139,9 +140,9 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
EOF EOF
done done
``` ```
--> -->
```sh ```sh
# 使用 IP 或可解析的主机名替换 HOST0, HOST1, 和 HOST2 # 使用 IP 或可解析的主机名替换 HOST0HOST1 和 HOST2
export HOST0=10.0.0.6 export HOST0=10.0.0.6
export HOST1=10.0.0.7 export HOST1=10.0.0.7
export HOST2=10.0.0.8 export HOST2=10.0.0.8
@@ -175,17 +176,18 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
EOF EOF
done done
``` ```
<!--
1. Generate the certificate authority
If you already have a CA then the only action that is copying the CA's `crt` and <!--
`key` file to `/etc/kubernetes/pki/etcd/ca.crt` and 1.Generate the certificate authority
`/etc/kubernetes/pki/etcd/ca.key`. After those files have been copied,
proceed to the next step, "Create certificates for each member". If you already have a CA then the only action that is copying the CA's `crt` and
--> `key` file to `/etc/kubernetes/pki/etcd/ca.crt` and
`/etc/kubernetes/pki/etcd/ca.key`. After those files have been copied,
proceed to the next step, "Create certificates for each member".
-->
1. 生成证书颁发机构 1. 生成证书颁发机构
如果您已经拥有 CA,那么唯一的操作是复制 CA 的 `crt` 和 `key` 文件到 `etc/kubernetes/pki/etcd/ca.crt` 和 /etc/kubernetes/pki/etcd/ca.key`。复制完这些文件后继续下一步,“为每个成员创建证书”。 如果您已经拥有 CA,那么唯一的操作是复制 CA 的 `crt` 和 `key` 文件到 `etc/kubernetes/pki/etcd/ca.crt` 和 `/etc/kubernetes/pki/etcd/ca.key`。复制完这些文件后继续下一步,“为每个成员创建证书”。
<!-- <!--
If you do not already have a CA then run this command on `$HOST0` (where you generated the configuration files for kubeadm). If you do not already have a CA then run this command on `$HOST0` (where you generated the configuration files for kubeadm).
@@ -207,7 +209,7 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
<!-- <!--
1. Create certificates for each member 1. Create certificates for each member
--> -->
1. 为每个成员创建证书 1. 为每个成员创建证书
<!-- <!--
```sh ```sh
@@ -264,34 +266,34 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
find /tmp/${HOST1} -name ca.key -type f -delete find /tmp/${HOST1} -name ca.key -type f -delete
``` ```
<!-- <!--
1. Copy certificates and kubeadm configs 1.Copy certificates and kubeadm configs
The certificates have been generated and now they must be moved to their The certificates have been generated and now they must be moved to their
respective hosts. respective hosts.
--> -->
1. 复制证书和 kubeadm 配置 1. 复制证书和 kubeadm 配置
    证书已生成,现在必须将它们移动到对应的主机。 证书已生成,现在必须将它们移动到对应的主机。
```sh ```sh
USER=ubuntu USER=ubuntu
HOST=${HOST1} HOST=${HOST1}
scp -r /tmp/${HOST}/* ${USER}@${HOST}: scp -r /tmp/${HOST}/* ${USER}@${HOST}:
ssh ${USER}@${HOST} ssh ${USER}@${HOST}
USER@HOST $ sudo -Es USER@HOST $ sudo -Es
root@HOST $ chown -R root:root pki root@HOST $ chown -R root:root pki
root@HOST $ mv pki /etc/kubernetes/ root@HOST $ mv pki /etc/kubernetes/
``` ```
<!-- <!--
1. Ensure all expected files exist 1.Ensure all expected files exist
The complete list of required files on `$HOST0` is: The complete list of required files on `$HOST0` is:
--> -->
1. 确保已经所有预期的文件都存在 1. 确保已经所有预期的文件都存在
     `$HOST0` 所需文件的完整列表如下: `$HOST0` 所需文件的完整列表如下:
``` ```
/tmp/${HOST0} /tmp/${HOST0}
@@ -311,9 +313,9 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
└── server.key └── server.key
``` ```
<!-- <!--
On `$HOST1`: On `$HOST1`:
--> -->
在 `$HOST1`: 在 `$HOST1`:
``` ```
@@ -333,9 +335,9 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
└── server.key └── server.key
``` ```
<!-- <!--
On `$HOST2` On `$HOST2`
--> -->
在 `$HOST2` 在 `$HOST2`
``` ```
@@ -355,12 +357,13 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
└── server.key └── server.key
``` ```
<!-- 1. Create the static pod manifests <!--
1.Create the static pod manifests
Now that the certificates and configs are in place it's time to create the Now that the certificates and configs are in place it's time to create the
manifests. On each host run the `kubeadm` command to generate a static manifest manifests. On each host run the `kubeadm` command to generate a static manifest
for etcd. for etcd.
--> -->
1. 创建静态 Pod 清单 1. 创建静态 Pod 清单
既然证书和配置已经就绪,是时候去创建清单了。在每台主机上运行 `kubeadm` 命令来生成 etcd 使用的静态清单。 既然证书和配置已经就绪,是时候去创建清单了。在每台主机上运行 `kubeadm` 命令来生成 etcd 使用的静态清单。
@@ -371,9 +374,9 @@ kubeadm 包含生成下述证书所需的所有必要的密码学工具;在这
root@HOST2 $ kubeadm alpha phase etcd local --config=/home/ubuntu/kubeadmcfg.yaml root@HOST2 $ kubeadm alpha phase etcd local --config=/home/ubuntu/kubeadmcfg.yaml
``` ```
<!-- <!--
1. Optional: Check the cluster health 1.Optional: Check the cluster health
--> -->
1. 可选:检查群集运行状况 1. 可选:检查群集运行状况
```sh ```sh