Files
website/content/ja/docs/setup/independent/setup-ha-etcd-with-kubeadm.md
Takuya Tokuda edb233cac2 First Japanese l10n work for release-1.13 (#12998)
* [ja] add basic files for 1.13 (#11571)

* [ja] add basic files for 1.13

* [ja] add some base files

* Translate setup/independent/_index.md (#11573)

* Translate content/ja/docs/home/_index.md in Japanese (#11569)

* Translate content/ja/docs/setup/custom-cloud/_index.md in Japanese (#11572)

* Translate content/en/docs/setup/on-premises-vm/_index.md in Japanese (#11574)

* Translate content/ja/docs/setup/release/_index.md in Japanese (#11576)

* ja-trans: Translate content/ja/docs/tutorials/kubernetes-basics/explore/_index.md (#11580)

* Translate content/ja/docs/setup/turnkey/_index.md (#11582)

* Translate content/ja/docs/tutorials/kubernetes-basics/update/_index.m… (#11579)

* Translate content/ja/docs/tutorials/kubernetes-basics/update/_index.md in Japanese

* Fix title

* Translated Tutorials/Learn Kubenetes Basics/Deploy an App in Japanese. (#11583)

* translate tutorials/kubernetes-basics/expose/_index.md (#11584)

* Dev 1.13 ja.1 tutorials kubernetes basics scale (#11577)

* Translate content/ja/docs/tutorials/kubernetes-basics/scale/_index.md in Japanese

* Fix title

* translate deprecated state description (#11578)

*  Fix the build doesn't pass at dev-1.13-ja.1 (#11609)

* delete files not at minimum requirements to pass the build.

* copy necessary file for pass build from content/en

* translate content/ja/_index.html (#11585)

* ja-trans: add docs/_index.md (#11721)

* Remove copied docs/index.md by mistake. (#11735)

* Translate stable state description (#11642)

* translate stable state description

* Update content/ja/docs/templates/feature-state-stable.txt

Co-Authored-By: auifzysr <38824461+auifzysr@users.noreply.github.com>

* apply the suggestion directly

* Translate alpha state description (#11753)

* [ja] add ja section (#11581)

* [ja] translate case-studies (#12060)

* [ja] translate case-studies

* remove comment

* fix /ja/docs/ content (#12062)

* Translate content/ja/docs/tutorials/kubernetes-basics/create-cluster/_index.md in Japanese (#12059)

* [ja] translate supported doc versions (#12068)

* [ja] add ja.toml (#11595)

* Remove reviewers block from front matter. (#12092)

* Translate beta state description (#12023)

* [ja] translate setup (#12070)

* translate setup

* add translation

* Update _index.md

* Update _index.md

* 表記ゆれ

* 表記ゆれ

* [ja] translate what-is-kubernetes (#12065)

* translate what-is-kubernetes

* add more translation

* finish basic translation

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: d-kuro <34958495+d-kuro@users.noreply.github.com>

* Update what-is-kubernetes.md

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* fix new lines

* fix review

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update what-is-kubernetes.md

* Update what-is-kubernetes.md

* rephrase プラクティス to 知見

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* italic

* オーケストレーション

* [ja] tutorials/index (#12071)

* translate tutorial index

* fix page link

* add ja to path for kubernetes-basic  because it's already in progress of translation

* Update _index.md

* review

* remove typo

* Update content/ja/docs/tutorials/_index.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/_index.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* [ja] translate cri installation (#12095)

* [ja] translate cri installation

* Update content/ja/docs/setup/cri.md

Co-Authored-By: auifzysr <38824461+auifzysr@users.noreply.github.com>

* apply comments

* apply comments

* [ja]translate tutorials/kubernetes-basics (#12074)

* start translation

* translate index

* wording

* wording

* cluster-interactive

* cluster-intro

* update interactive

* update some data

* fix link

* deploy-intro

* japanize

* fix path for public data

* wording

* start translation of expose

* expose intro

* けーしょん

* scale-intro

* update-intro

* fix wrong word

* fix wording

* translate missing string

* Update content/ja/docs/tutorials/kubernetes-basics/_index.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/_index.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/scale/scale-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/expose/expose-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/_index.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* fix wording

* Update content/ja/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/scale/scale-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/expose/expose-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/explore/explore-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/deploy-app/deploy-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/create-cluster/cluster-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/explore/explore-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/scale/scale-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* lowercase for kubectl

* ja-trans: tutorials/hello-minikube.md (#11648)

* trns-ja: tutorials/hello-minikube.md

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update hello-minikube.md

大変、大変遅くなりました。丁寧に見ていただいて感謝です。いただいたコメントを反映しました。

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update hello-minikube.md

<修正点>
・10行目の「本チュートリアルでは」を削除
・クラスターをクラスタに統一

* Update hello-minikube.md

10行目の実践を手を動かすに修正

* Update hello-minikube.md

10行目を「手を動かす準備はできていますか?本チュートリアルでは、Node.jsを使った簡単な"Hello World"を実行するKubernetesクラスタをビルドします。」に差し替え。

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* ja-trans: setup/custom-cloud/coreos/ (#12731)

* ja-trans: setup/release/building-from-source/ (#12721)

* translate building-from-source

* improve translation

* ja-trans: translate setup/certificates/ (#12722)

* translate certificates.md

* change translation about Paths

* ja-trans: setup/custom-cloud/kubespray/ (#12733)

* ja-trans: setup/node-conformance/ (#12728)

* ja-trans: setup/node-conformance/

* Update content/ja/docs/setup/node-conformance.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/node-conformance.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/node-conformance.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* ja-trans: setup/cluster-large/ (#12723)

* ja-trans: setup/cluster-large/

* translate quota and addon

* ja-trans: setup/pick-right-solution/ (#12729)

* ja-trans: setup/pick-right-solution/

* revise translating solutions

* ending with a noun

* ja-trans: setup/custom-cloud/kops/ (#12732)

* ja-trans: setup/custom-cloud/kops/

* improve translation

* translate build

* translate explore and add-ons

* ja-trans: setup/independent/control-plane-flags/ (#12745)

* ja-trans: setup/minikube/ (#12724)

* ja-trans: setup/minikube/

* Update content/ja/docs/setup/minikube.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* translate features and add-ons

* improve translation

* improve translation

* fix translation style

* ja-trans: setup/multiple-zones/ (#12725)

* ja-trans: setup/multiple-zones/

* ja-trans: setup/multiple-zones/ (2)

* ending with a noun

* fix translation style

* ja-trans: setup/scratch/ (#12730)

* ja-trans: setup/scratch/

* revise translating connectivity

* improve translation

* Update content/ja/docs/setup/scratch.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/scratch.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/scratch.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/scratch.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* revise translation

* revert some words to English

* fix translation style

* fix title

* ja-trans: setup/independent/create-cluster-kubeadm/ (#12750)

* ja-trans: setup/independent/create-cluster-kubeadm/

* translate Instructions

* fix translation style

* ja-trans: setup/independent/kubelet-integration/ (#12754)

* ja-trans: setup/independent/kubelet-integration/

* fix translation style

* ja-trans: setup/independent/setup-ha-etcd-with-kubeadm/ (#12755)

* ja-trans: setup/independent/setup-ha-etcd-with-kubeadm/

* fix translation style

* ja-trans: setup/independent/troubleshooting-kubeadm/ (#12757)

* ja-trans: setup/independent/troubleshooting-kubeadm/

* pod -> Pod

* ja-trans: setup/on-premises-vm/cloudstack/ (#12772)

* ja-trans: setup/independent/high-availability/ (#12753)

* ja-trans: setup/independent/high-availability/

* fix translation style

* translate Stacked and worker node

* ja-trans: setup/on-premises-metal/krib/ (#12770)

* ja-trans: setup/on-premises-metal/krib/

* Update content/ja/docs/setup/on-premises-metal/krib.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* ja-trans: setup/on-premises-vm/ovirt/ (#12781)

* ja-trans: setup/on-premises-vm/dcos/ (#12780)

* ja-trans: setup/on-premises-vm/dcos/

* fix translation

* Update content/ja/docs/setup/on-premises-vm/dcos.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* ja-trans: setup/turnkey/alibaba-cloud/ (#12786)

* ja-trans: setup/turnkey/alibaba-cloud/

* tiny fix

* Update content/ja/docs/setup/turnkey/alibaba-cloud.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* fix translation

* ja-trans: setup/turnkey/aws/ (#12788)

* ja-trans: setup/turnkey/aws/

* translate production grade

* fix translation

* ja-trans: setup/release/notes/ (#12791)

* ja-trans: setup/independent/install-kubeadm.md (#12812)

* ja-trans: setup/independent/install-kubeadm.md

* ja-trans: fix internal links in setup/independent/install-kubeadm.md

* ja-trans: setup/turnkey/clc/ (#12824)

* ja-trans: setup/turnkey/clc/

* Update content/ja/docs/setup/turnkey/clc.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/turnkey/clc.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* ja-trans: setup/turnkey/stackpoint/ (#12853)

* ja-trans: concepts/ (#12820)

* ja-trans: concepts/

* fix translation

* ja: fix formatting in what is kubernetes (#12694)

* fix formatting in what is kubernetes

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* ?

* format (#12866)

* ja-trans: setup/turnkey/gce.md (#12813)

* ja-trans: setup/turnkey/gce.md

* Update content/ja/docs/setup/turnkey/gce.md

Co-Authored-By: auifzysr <38824461+auifzysr@users.noreply.github.com>

* Update content/ja/docs/setup/turnkey/gce.md

Co-Authored-By: auifzysr <38824461+auifzysr@users.noreply.github.com>

* ja-trans: modify a word in setup/turnkey/gce.md

* Translated docs/setup/turnkey/azure.md. (#12951)

* Translated docs/setup/turnkey/azure.md.

* Update content/ja/docs/setup/turnkey/azure.md

Applied a suggestion.

Co-Authored-By: dzeyelid <dzeyelid@gmail.com>

* Update content/ja/docs/setup/turnkey/azure.md

Applied a suggestion.

Co-Authored-By: dzeyelid <dzeyelid@gmail.com>

* Update content/ja/docs/setup/turnkey/azure.md

Applied suggestion.

Co-Authored-By: dzeyelid <dzeyelid@gmail.com>

* Applied review suggestions.

* Applied review suggestions.

* fix language setting order.
2019-03-07 10:17:41 -08:00

8.5 KiB

title, content_template, weight
title content_template weight
kubeadmを使用した高可用性etcdクラスターの作成 templates/task 70

{{% capture overview %}}

Kubeadm defaults to running a single member etcd cluster in a static pod managed by the kubelet on the control plane node. This is not a high availability setup as the etcd cluster contains only one member and cannot sustain any members becoming unavailable. This task walks through the process of creating a high availability etcd cluster of three members that can be used as an external etcd when using kubeadm to set up a kubernetes cluster.

{{% /capture %}}

{{% capture prerequisites %}}

  • Three hosts that can talk to each other over ports 2379 and 2380. This document assumes these default ports. However, they are configurable through the kubeadm config file.
  • Each host must have docker, kubelet, and kubeadm installed.
  • Some infrastructure to copy files between hosts. For example ssh and scp can satisfy this requirement.

{{% /capture %}}

{{% capture steps %}}

クラスターの構築

The general approach is to generate all certs on one node and only distribute the necessary files to the other nodes.

{{< note >}} kubeadm contains all the necessary crytographic machinery to generate the certificates described below; no other cryptographic tooling is required for this example. {{< /note >}}

  1. Configure the kubelet to be a service manager for etcd.

    Running etcd is simpler than running kubernetes so you must override the kubeadm-provided kubelet unit file by creating a new one with a higher precedence.

    cat << EOF > /etc/systemd/system/kubelet.service.d/20-etcd-service-manager.conf
    [Service]
    ExecStart=
    ExecStart=/usr/bin/kubelet --address=127.0.0.1 --pod-manifest-path=/etc/kubernetes/manifests --allow-privileged=true
    Restart=always
    EOF
    
    systemctl daemon-reload
    systemctl restart kubelet
    
  2. Create configuration files for kubeadm.

    Generate one kubeadm configuration file for each host that will have an etcd member running on it using the following script.

    # Update HOST0, HOST1, and HOST2 with the IPs or resolvable names of your hosts
    export HOST0=10.0.0.6
    export HOST1=10.0.0.7
    export HOST2=10.0.0.8
    
    # Create temp directories to store files that will end up on other hosts.
    mkdir -p /tmp/${HOST0}/ /tmp/${HOST1}/ /tmp/${HOST2}/
    
    ETCDHOSTS=(${HOST0} ${HOST1} ${HOST2})
    NAMES=("infra0" "infra1" "infra2")
    
    for i in "${!ETCDHOSTS[@]}"; do
    HOST=${ETCDHOSTS[$i]}
    NAME=${NAMES[$i]}
    cat << EOF > /tmp/${HOST}/kubeadmcfg.yaml
    apiVersion: "kubeadm.k8s.io/v1beta1"
    kind: ClusterConfiguration
    etcd:
        local:
            serverCertSANs:
            - "${HOST}"
            peerCertSANs:
            - "${HOST}"
            extraArgs:
                initial-cluster: infra0=https://${ETCDHOSTS[0]}:2380,infra1=https://${ETCDHOSTS[1]}:2380,infra2=https://${ETCDHOSTS[2]}:2380
                initial-cluster-state: new
                name: ${NAME}
                listen-peer-urls: https://${HOST}:2380
                listen-client-urls: https://${HOST}:2379
                advertise-client-urls: https://${HOST}:2379
                initial-advertise-peer-urls: https://${HOST}:2380
    EOF
    done
    
  3. Generate the certificate authority

    If you already have a CA then the only action that is copying the CA's crt and key file to /etc/kubernetes/pki/etcd/ca.crt and /etc/kubernetes/pki/etcd/ca.key. After those files have been copied, proceed to the next step, "Create certificates for each member".

    If you do not already have a CA then run this command on $HOST0 (where you generated the configuration files for kubeadm).

    kubeadm init phase certs etcd-ca
    

    This creates two files

    • /etc/kubernetes/pki/etcd/ca.crt
    • /etc/kubernetes/pki/etcd/ca.key
  4. Create certificates for each member

    kubeadm init phase certs etcd-server --config=/tmp/${HOST2}/kubeadmcfg.yaml
    kubeadm init phase certs etcd-peer --config=/tmp/${HOST2}/kubeadmcfg.yaml
    kubeadm init phase certs etcd-healthcheck-client --config=/tmp/${HOST2}/kubeadmcfg.yaml
    kubeadm init phase certs apiserver-etcd-client --config=/tmp/${HOST2}/kubeadmcfg.yaml
    cp -R /etc/kubernetes/pki /tmp/${HOST2}/
    # cleanup non-reusable certificates
    find /etc/kubernetes/pki -not -name ca.crt -not -name ca.key -type f -delete
    
    kubeadm init phase certs etcd-server --config=/tmp/${HOST1}/kubeadmcfg.yaml
    kubeadm init phase certs etcd-peer --config=/tmp/${HOST1}/kubeadmcfg.yaml
    kubeadm init phase certs etcd-healthcheck-client --config=/tmp/${HOST1}/kubeadmcfg.yaml
    kubeadm init phase certs apiserver-etcd-client --config=/tmp/${HOST1}/kubeadmcfg.yaml
    cp -R /etc/kubernetes/pki /tmp/${HOST1}/
    find /etc/kubernetes/pki -not -name ca.crt -not -name ca.key -type f -delete
    
    kubeadm init phase certs etcd-server --config=/tmp/${HOST0}/kubeadmcfg.yaml
    kubeadm init phase certs etcd-peer --config=/tmp/${HOST0}/kubeadmcfg.yaml
    kubeadm init phase certs etcd-healthcheck-client --config=/tmp/${HOST0}/kubeadmcfg.yaml
    kubeadm init phase certs apiserver-etcd-client --config=/tmp/${HOST0}/kubeadmcfg.yaml
    # No need to move the certs because they are for HOST0
    
    # clean up certs that should not be copied off this host
    find /tmp/${HOST2} -name ca.key -type f -delete
    find /tmp/${HOST1} -name ca.key -type f -delete
    
  5. Copy certificates and kubeadm configs

    The certificates have been generated and now they must be moved to their respective hosts.

    USER=ubuntu
    HOST=${HOST1}
    scp -r /tmp/${HOST}/* ${USER}@${HOST}:
    ssh ${USER}@${HOST}
    USER@HOST $ sudo -Es
    root@HOST $ chown -R root:root pki
    root@HOST $ mv pki /etc/kubernetes/
    
  6. Ensure all expected files exist

    The complete list of required files on $HOST0 is:

    /tmp/${HOST0}
    └── kubeadmcfg.yaml
    ---
    /etc/kubernetes/pki
    ├── apiserver-etcd-client.crt
    ├── apiserver-etcd-client.key
    └── etcd
        ├── ca.crt
        ├── ca.key
        ├── healthcheck-client.crt
        ├── healthcheck-client.key
        ├── peer.crt
        ├── peer.key
        ├── server.crt
        └── server.key
    

    On $HOST1:

    $HOME
    └── kubeadmcfg.yaml
    ---
    /etc/kubernetes/pki
    ├── apiserver-etcd-client.crt
    ├── apiserver-etcd-client.key
    └── etcd
        ├── ca.crt
        ├── healthcheck-client.crt
        ├── healthcheck-client.key
        ├── peer.crt
        ├── peer.key
        ├── server.crt
        └── server.key
    

    On $HOST2

    $HOME
    └── kubeadmcfg.yaml
    ---
    /etc/kubernetes/pki
    ├── apiserver-etcd-client.crt
    ├── apiserver-etcd-client.key
    └── etcd
        ├── ca.crt
        ├── healthcheck-client.crt
        ├── healthcheck-client.key
        ├── peer.crt
        ├── peer.key
        ├── server.crt
        └── server.key
    
  7. Create the static pod manifests

    Now that the certificates and configs are in place it's time to create the manifests. On each host run the kubeadm command to generate a static manifest for etcd.

    root@HOST0 $ kubeadm init phase etcd local --config=/tmp/${HOST0}/kubeadmcfg.yaml
    root@HOST1 $ kubeadm init phase etcd local --config=/home/ubuntu/kubeadmcfg.yaml
    root@HOST2 $ kubeadm init phase etcd local --config=/home/ubuntu/kubeadmcfg.yaml
    
  8. Optional: Check the cluster health

    docker run --rm -it \
    --net host \
    -v /etc/kubernetes:/etc/kubernetes quay.io/coreos/etcd:${ETCD_TAG} etcdctl \
    --cert-file /etc/kubernetes/pki/etcd/peer.crt \
    --key-file /etc/kubernetes/pki/etcd/peer.key \
    --ca-file /etc/kubernetes/pki/etcd/ca.crt \
    --endpoints https://${HOST0}:2379 cluster-health
    ...
    cluster is healthy
    
    • Set ${ETCD_TAG} to the version tag of your etcd image. For example v3.2.24.
    • Set ${HOST0}to the IP address of the host you are testing.

{{% /capture %}}

{{% capture whatsnext %}}

Once your have a working 3 member etcd cluster, you can continue setting up a highly available control plane using the external etcd method with kubeadm.

{{% /capture %}}