From fac7653113443338743afd95228dcd042d755e46 Mon Sep 17 00:00:00 2001 From: Jamie Hannaford Date: Thu, 22 Jun 2017 12:08:21 +0200 Subject: [PATCH 1/2] Document product_uuid and MAC reqs --- docs/setup/independent/install-kubeadm.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/setup/independent/install-kubeadm.md b/docs/setup/independent/install-kubeadm.md index d0c808e31e..612b52b3c1 100644 --- a/docs/setup/independent/install-kubeadm.md +++ b/docs/setup/independent/install-kubeadm.md @@ -13,6 +13,7 @@ This page shows how to use install kubeadm. * One or more machines running Ubuntu 16.04+, CentOS 7 or HypriotOS v1.0.1+ * 1GB or more of RAM per machine (any less will leave little room for your apps) * Full network connectivity between all machines in the cluster (public or private network is fine) +* Unique MAC address and product_uuid for every node {% endcapture %} @@ -26,7 +27,7 @@ Versions 1.13 and 17.03+ have not yet been tested and verified by the Kubernetes For installation instructions, see [Install Docker](https://docs.docker.com/engine/installation/). -## Installing kubectl +## Installing kubectl On each of your machines, [install kubectl](/docs/tasks/tools/install-kubectl/). From 686b7aef38909c7e2e36e72929c9ca5928b2ab3d Mon Sep 17 00:00:00 2001 From: Jamie Hannaford Date: Sun, 25 Jun 2017 20:44:44 +0200 Subject: [PATCH 2/2] Document how to use custom certs with kubeadm (#4113) --- docs/admin/kubeadm.md | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/docs/admin/kubeadm.md b/docs/admin/kubeadm.md index 7a295ab91d..2c1f33718c 100644 --- a/docs/admin/kubeadm.md +++ b/docs/admin/kubeadm.md @@ -23,7 +23,9 @@ following steps: 1. kubeadm generates a self-signed CA to provision identities for each component (including nodes) in the cluster. It also generates client certificates to - be used by various components. + be used by various components. If the user has provided their own CA by + dropping it in the cert directory (configured via `--cert-dir`, by default + `/etc/kubernetes/pki`), this step is skipped. 1. Outputting a kubeconfig file for the kubelet to use to connect to the API server, as well as an additional kubeconfig file for administration. @@ -459,6 +461,23 @@ EOF Now `kubelet` is ready to use the specified CRI runtime, and you can continue with `kubeadm init` and `kubeadm join` workflow to deploy Kubernetes cluster. +## Using custom certificates + +By default kubeadm will generate all the certificates needed for a cluster to run. +You can override this behaviour by providing your own certificates. + +To do so, you must place them in whatever directory is specified by the +`--cert-dir` flag or `CertificatesDir` configuration file key. By default this +is `/etc/kubernetes/pki`. + +If a given certificate and private key pair both exist, kubeadm will skip the +generation step and those files will be validated and used for the prescribed +use-case. + +This means you can, for example, prepopulate `/etc/kubernetes/pki/ca.crt` +and `/etc/kubernetes/pki/ca.key` with an existing CA, which then will be used +for signing the rest of the certs. + ## Releases and release notes If you already have kubeadm installed and want to upgrade, run `apt-get update