@@ -45,8 +45,7 @@ For highly available setups, you will need to decide how to host your etcd clust
|
|||||||
|
|
||||||
While the first option provides more performance and better hardware isolation, it is also more expensive and requires an additional support burden.
|
While the first option provides more performance and better hardware isolation, it is also more expensive and requires an additional support burden.
|
||||||
|
|
||||||
For **Option 1**: create 3 virtual machines that follow [CoreOS's hardware recommendations](https://coreos.com/etcd/docs/latest/op-guide/hardware.html). For the sake of simplicity, we
|
For **Option 1**: create 3 virtual machines that follow [CoreOS's hardware recommendations](https://coreos.com/etcd/docs/latest/op-guide/hardware.html). For the sake of simplicity, we will refer to them as `etcd0`, `etcd1` and `etcd2`.
|
||||||
will refer to them as `etcd0`, `etcd1` and `etcd2`.
|
|
||||||
|
|
||||||
For **Option 2**: you can skip to the next step. Any reference to `etcd0`, `etcd1` and `etcd2` throughout this guide should be replaced with `master0`, `master1` and `master2` accordingly, since your master nodes host etcd.
|
For **Option 2**: you can skip to the next step. Any reference to `etcd0`, `etcd1` and `etcd2` throughout this guide should be replaced with `master0`, `master1` and `master2` accordingly, since your master nodes host etcd.
|
||||||
|
|
||||||
@@ -201,7 +200,7 @@ In order to copy certs between machines, you must enable SSH access for `scp`.
|
|||||||
cfssl print-defaults csr > config.json
|
cfssl print-defaults csr > config.json
|
||||||
sed -i '0,/CN/{s/example\.net/'"$PEER_NAME"'/}' config.json
|
sed -i '0,/CN/{s/example\.net/'"$PEER_NAME"'/}' config.json
|
||||||
sed -i 's/www\.example\.net/'"$PRIVATE_IP"'/' config.json
|
sed -i 's/www\.example\.net/'"$PRIVATE_IP"'/' config.json
|
||||||
sed -i 's/example\.net/'"$PUBLIC_IP"'/' config.json
|
sed -i 's/example\.net/'"$PEER_NAME"'/' config.json
|
||||||
|
|
||||||
cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=server config.json | cfssljson -bare server
|
cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=server config.json | cfssljson -bare server
|
||||||
cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=peer config.json | cfssljson -bare peer
|
cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=peer config.json | cfssljson -bare peer
|
||||||
@@ -445,7 +444,7 @@ Only follow this step if your etcd is hosted on dedicated nodes (**Option 1**).
|
|||||||
- `<etcd0-ip>`, `<etcd1-ip>` and `<etcd2-ip>` with the IP addresses of your three etcd nodes
|
- `<etcd0-ip>`, `<etcd1-ip>` and `<etcd2-ip>` with the IP addresses of your three etcd nodes
|
||||||
- `<podCIDR>` with your Pod CIDR. Please read the [CNI network section](https://kubernetes.io/docs/setup/independent/create-cluster-kubeadm/#pod-network) of the docs for more information. Some CNI providers do not require a value to be set.
|
- `<podCIDR>` with your Pod CIDR. Please read the [CNI network section](https://kubernetes.io/docs/setup/independent/create-cluster-kubeadm/#pod-network) of the docs for more information. Some CNI providers do not require a value to be set.
|
||||||
|
|
||||||
**Note:** If you are using Kubernetes 1.9+, you can replace the `apiserver-count: 3` extra argument with `endpoint-reconciler-type=lease`. For more information, see [the documentation](https://kubernetes.io/docs/admin/high-availability/#endpoint-reconciler).
|
**Note:** If you are using Kubernetes 1.9+, you can replace the `apiserver-count: 3` extra argument with `endpoint-reconciler-type: lease`. For more information, see [the documentation](https://kubernetes.io/docs/admin/high-availability/#endpoint-reconciler).
|
||||||
|
|
||||||
1. When this is done, run kubeadm like so:
|
1. When this is done, run kubeadm like so:
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user