当前位置:网站首页>Kubernetes加入集群的TOKEN值过期
Kubernetes加入集群的TOKEN值过期
2022-07-31 05:09:00 【hunheidaode】
当Kubernetes集群的master节点init完成后,会输出join命令,以便用户用来将其他节点加入,如下
COPYkubeadm join 192.168.1.11:6443 --token abcdef.0123456789abcdef \
--discovery-token-ca-cert-hash sha256:063cf8ade66033addf58f5d1a453aab0b1ec5ff023327bc10156935875baa7ad
而如上命令的token值的有效期只有24小时,通过以下命令查看,TTL就是token的有效时长
COPY$ kubeadm token list
TOKEN TTL EXPIRES USAGES DESCRIPTION EXTRA GROUPS
2tmuf8.gi... 23h 2021-01-25T1... authentication,signing The default bootstrap... system:bootstrappers:...
当init后的这个token过期之后应该怎么让新的节点重新加入集群
加入新的master节点
这里有一点需要注意,如果部署集群进行init时未指定
controlPlaneEndpoint
,则不能加入新的master,一般该项的值为Keepalived VIP
,或者某一台master的ip:6443
也就是集群的api地址即可,否则在加入新的master时会报错。
添加controlPlaneEndpoint
如果集群中只有一个master节点,可以在kube-apiserver中添加
controlPlaneEndpoint
参数,该参数的值为master节点ip。如果是多master则跳过
COPY$ kubectl edit cm -n kube-system kubeadm-config
apiVersion: v1
data:
ClusterConfiguration: |
apiServer:
extraArgs:
authorization-mode: Node,RBAC
timeoutForControlPlane: 4m0s
apiVersion: kubeadm.k8s.io/v1beta2
certificatesDir: /etc/kubernetes/pki
clusterName: kubernetes
controllerManager: {}
dns:
type: CoreDNS
etcd:
local:
dataDir: /var/lib/etcd
imageRepository: registry.aliyuncs.com/google_containers
kind: ClusterConfiguration
kubernetesVersion: v1.18.1
# 这个位置添加apiserver的地址即可
controlPlaneEndpoint: "192.168.1.11:6443"
...
生成添加master命令
COPY# 要用到certificate-key,所以先生成certificate-key
$ kubeadm init phase upload-certs --upload-certs
I0217 01:23:50.056394 19222 version.go:252] remote version is much newer: v1.20.2; falling back to: stable-1.18
W0217 01:23:52.864011 19222 configset.go:202] WARNING: kubeadm cannot validate component configs for API groups [kubelet.config.k8s.io kubeproxy.config.k8s.io]
[upload-certs] Storing the certificates in Secret "kubeadm-certs" in the "kube-system" Namespace
[upload-certs] Using certificate key:
0787d9b7f5abf63dd94570b1a8c6a2aa73421019bb45bd9a7ea24893f48e4ef9
$ kubeadm token create --print-join-command --certificate-key=0787d9b7f5abf63dd94570b1a8c6a2aa73421019bb45bd9a7ea24893f48e4ef9
W0217 01:24:22.855390 23471 configset.go:202] WARNING: kubeadm cannot validate component configs for API groups [kubelet.config.k8s.io kubeproxy.config.k8s.io]
# 在待加入节点执行以下这条命令即可加入集群成为master
kubeadm join 192.168.1.11:6443 --token 0ysckj.3vtjwoa28dw1z8xz --discovery-token-ca-cert-hash sha256:c31906addf05434a967d68eb04a81fad38e90c04f2a86b899b5e41b1f919d3ae --control-plane --certificate-key 0787d9b7f5abf63dd94570b1a8c6a2aa73421019bb45bd9a7ea24893f48e4ef9
加入新的node节点
COPY$ kubeadm token create --print-join-command
W0217 01:11:55.754155 73469 configset.go:202] WARNING: kubeadm cannot validate component configs for API groups [kubelet.config.k8s.io kubeproxy.config.k8s.io]
# 在待加入节点执行以下这条命令,将会以node的身份加入集群
kubeadm join 192.168.1.11:6443 --token 67v2qk.vhylz26xsgwk5f2h --discovery-token-ca-cert-hash sha256:c31906addf05434a967d68eb04a81fad38e90c04f2a86b899b5e41b1f919d3ae
当然也可以使用加入新master的方法生成的命令加入新node,只要不加--control-plane --certificate-key 0787d9b7f5abf63dd94570b1a8c6a2aa73421019bb45bd9a7ea24893f48e4ef9
这部分即可。
建议
无论是搭建单master集群还是多master集群,都加上controlPlaneEndpoint参数
边栏推荐
猜你喜欢
110 MySQL interview questions and answers (continuously updated)
【MQ我可以讲一个小时】
Mysql application cannot find my.ini file after installation
Linux系统安装mysql(rpm方式安装)
Interviewer: If the order is not paid within 30 minutes, it will be automatically canceled. How to do this?
On-line monitoring system for urban waterlogging and water accumulation in bridges and tunnels
MySQL database installation (detailed)
Multiple table query of sql statement
【MySQL8入门到精通】基础篇- Linux系统静默安装MySQL,跨版本升级
再见了繁琐的Excel,掌握数据分析处理技术就靠它了
随机推荐
Distributed Transactions - Introduction to Distributed Transactions, Distributed Transaction Framework Seata (AT Mode, Tcc Mode, Tcc Vs AT), Distributed Transactions - MQ
2022-07-30:以下go语言代码输出什么?A:[]byte{} []byte;B:[]byte{} []uint8;C:[]uint8{} []byte;D:[]uin8{} []uint8。
Linux的mysql报ERROR 1045 (28000) Access denied for user ‘root‘@‘localhost‘ (using password NOYSE)
Pytorch教程Introduction中的神经网络实现示例
sql语句-如何以一个表中的数据为条件据查询另一个表中的数据
Unity手机游戏性能优化系列:针对CPU端的性能调优
工作流编排引擎-Temporal
信息系统项目管理师核心考点(五十五)配置管理员(CMO)的工作
DVWA安装教程(懂你的不懂·详细)
1. 获取数据-requests.get()
【MQ我可以讲一个小时】
Simple read operation of EasyExcel
.NET-9.乱七八糟的理论笔记(概念,思想)
ERROR 1819 (HY000) Your password does not satisfy the current policy requirements
<urlopen error [Errno 11001] getaddrinfo failed>的解决、isinstance()函数初略介绍
Apache DButils使用注意事项--with modifiers “public“
Interview | Cheng Li, CTO of Alibaba: Cloud + open source together form a credible foundation for the digital world
【mysql 提高查询效率】Mysql 数据库查询好慢问题解决
质量小议12 -- 以测代评
Typec手机有线网卡网线转网口转接口快充方案