{"id":1892,"date":"2025-12-25T16:05:41","date_gmt":"2025-12-25T08:05:41","guid":{"rendered":"http:\/\/www.huerpu.cc:7000\/?p=1892"},"modified":"2025-12-25T16:15:40","modified_gmt":"2025-12-25T08:15:40","slug":"centos-stream-10%e5%ae%89%e8%a3%85kubernetesk8s-v1-35-0%e9%ab%98%e5%8f%af%e7%94%a8%e9%9b%86%e7%be%a4","status":"publish","type":"post","link":"http:\/\/www.huerpu.cc:7000\/?p=1892","title":{"rendered":"CentOS Stream 10\u5b89\u88c5Kubernetes(k8s v1.35.0)\u9ad8\u53ef\u7528\u96c6\u7fa4"},"content":{"rendered":"<h1>CentOS Stream 10\u5b89\u88c5Kubernetes(k8s v1.35.0)\u9ad8\u53ef\u7528\u96c6\u7fa4<\/h1>\n<p>\u672c\u7740\u5b66\u4e60\u65b0\u6280\u672f\u548c\u4f7f\u7528\u65b0\u7248\u672c\u7684\u539f\u5219\uff0c\u672cK8S\u96c6\u7fa4\u9009\u7528\u521a\u521a\u53d1\u5e03\u7684k8s v1.35.0\uff0c\u7cfb\u7edf\u7248\u672c\u9009\u7528\u4e86CentOS Stream 10\u4e5f\u662f\u6700\u65b0\u7248\u672c\u7684LST\u7cfb\u7edf\u3002<\/p>\n<p>3\u53f0master\u4e3b\u8282\u70b9(2C4G)\u30014\u53f0(2C4G)worker node\uff0c\u5982\u679cCPU\u4f4e\u4e8e2\u6838\u5fc3\u662f\u6ca1\u6cd5\u521d\u59cb\u5316K8S\u7684\uff0c\u6839\u636e\u4e2a\u4eba\u786c\u4ef6\u914d\u7f6e\u5efa\u8bae\u5c3d\u53ef\u80fd\u591a\u6838\u5fc3\u5927\u5185\u5b58\uff0c\u5bf9\u5e94\u7684 IP\u5982\u4e0b\uff1a<\/p>\n<h2>\u4e00\u3001 \u96c6\u7fa4\u6982\u89c8<\/h2>\n<p>\u672c\u6b21\u90e8\u7f72\u91c7\u7528 <strong>3 Master + 4 Worker<\/strong> \u65b9\u6848\uff0c\u901a\u8fc7 <strong>kube-vip<\/strong> \u5b9e\u73b0\u63a7\u5236\u5e73\u9762\u9ad8\u53ef\u7528\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th><strong>Hostname<\/strong><\/th>\n<th><strong>IP<\/strong><\/th>\n<th><strong>Function<\/strong><\/th>\n<th><strong>OS<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>VIP<\/strong><\/td>\n<td>192.168.31.220<\/td>\n<td>lb.k8s.hep.com<\/td>\n<td>&#8212;<\/td>\n<\/tr>\n<tr>\n<td>hep-k8s-master-01<\/td>\n<td>192.168.31.221<\/td>\n<td>Control plane<\/td>\n<td>CentOS Stream 10<\/td>\n<\/tr>\n<tr>\n<td>hep-k8s-master-02<\/td>\n<td>192.168.31.222<\/td>\n<td>Control plane<\/td>\n<td>CentOS Stream 10<\/td>\n<\/tr>\n<tr>\n<td>hep-k8s-master-03<\/td>\n<td>192.168.31.223<\/td>\n<td>Control plane<\/td>\n<td>CentOS Stream 10<\/td>\n<\/tr>\n<tr>\n<td>hep-k8s-worker-01<\/td>\n<td>192.168.31.224<\/td>\n<td>Worker node<\/td>\n<td>CentOS Stream 10<\/td>\n<\/tr>\n<tr>\n<td>hep-k8s-worker-02<\/td>\n<td>192.168.31.225<\/td>\n<td>Worker node<\/td>\n<td>CentOS Stream 10<\/td>\n<\/tr>\n<tr>\n<td>hep-k8s-worker-03<\/td>\n<td>192.168.31.226<\/td>\n<td>Worker node<\/td>\n<td>CentOS Stream 10<\/td>\n<\/tr>\n<tr>\n<td>hep-k8s-worker-04<\/td>\n<td>192.168.31.227<\/td>\n<td>Worker node<\/td>\n<td>CentOS Stream 10<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<h2>\u4e8c\u3001 \u524d\u7f6e\u5de5\u4f5c<\/h2>\n<p>\u6211\u7684K8S\u96c6\u7fa4\u8282\u70b9\u90fd\u5728PVE\u4e0a\uff0c\u4e3a\u4e86\u66f4\u65b9\u4fbf\uff0c\u90a3\u4e9b\u91cd\u590d\u6027\u7684\u5de5\u4f5c\u6211\u5c31\u653e\u5728\u4e00\u53f0\u673a\u5668hep-k8s-master-worker-temp\u4e0a\u6267\u884c\uff0c\u5b83\u662f\u4e00\u53f0centOS Server\u673a\u5668\uff0c\u7136\u540e\u76f4\u63a5\u590d\u5236\u865a\u62df\u673a\uff0c\u5927\u5927\u63d0\u9ad8\u6548\u7387\u3002\u5982\u679c\u4f60\u662f\u5355\u72ec\u7684\u673a\u5668\uff0c\u53ef\u4ee5\u5728\u673a\u5668\u4e0a\u91cd\u590d\u6267\u884c\u8fd9\u4e9b\u547d\u4ee4\u5373\u53ef\uff0c\u4ece\u800c\u8fbe\u5230\u673a\u5668\u914d\u7f6e\u7684\u4e00\u81f4\u6027\u3002<\/p>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2025\/12\/24\/Screenshot-2025-12-24-113007.png\" alt=\"Screenshot 2025-12-24 113007\" \/><\/p>\n<h3>2.1 \u57fa\u7840\u73af\u5883\u914d\u7f6e<\/h3>\n<pre><code class=\"language-shell\"># \u5207\u6362\u81f3 root\nsudo -i\n\n# \u66f4\u65b0\u7cfb\u7edf\ndnf update -y\n\n#\u8bbe\u7f6ehostname\nhostnamectl set-hostname hep-k8s-master-01\n\n#\u56fa\u5b9aIP\nnmcli connection modify ens18 ipv4.addresses 192.168.31.221\/24\n\n# \u914d\u7f6e hosts\ncat >> \/etc\/hosts << EOF\n192.168.31.220  lb.k8s.hep.com\n192.168.31.221  hep-k8s-master-01\n192.168.31.222  hep-k8s-master-02\n192.168.31.223  hep-k8s-master-03\n192.168.31.224  hep-k8s-worker-01\n192.168.31.225  hep-k8s-worker-02\n192.168.31.226  hep-k8s-worker-03\n192.168.31.227  hep-k8s-worker-04\nEOF\n\n# \u5173\u95ed SELinux\nsetenforce 0\nsed -i 's\/^SELINUX=enforcing$\/SELINUX=permissive\/' \/etc\/selinux\/config\n\n# \u65f6\u95f4\u540c\u6b65 (CentOS 10 \u4f7f\u7528 chrony)\ndnf install chrony -y\nsystemctl enable --now chronyd\n\n# \u7981\u7528 Swap\nswapoff -a\nsed -i '\/swap\/s\/^\/#\/' \/etc\/fstab\n\n# \u52a0\u8f7d\u5185\u6838\u6a21\u5757\ncat << EOF | tee \/etc\/modules-load.d\/k8s.conf\noverlay\nbr_netfilter\nip_vs\nip_vs_rr\nip_vs_wrr\nip_vs_sh\nnf_conntrack\nEOF\n\nmodprobe overlay\nmodprobe br_netfilter\nmodprobe ip_vs\nmodprobe ip_vs_rr\nmodprobe ip_vs_wrr\nmodprobe ip_vs_sh\nmodprobe nf_conntrack\n\n# \u5185\u6838\u53c2\u6570\u8c03\u4f18\ncat << EOF | tee \/etc\/sysctl.d\/k8s.conf\nnet.bridge.bridge-nf-call-iptables  = 1\nnet.bridge.bridge-nf-call-ip6tables = 1\nnet.ipv4.ip_forward                 = 1\nEOF\nsysctl --system<\/code><\/pre>\n<h3>2.2 \u5b89\u88c5\u5bb9\u5668\u8fd0\u884c\u65f6 (Docker &amp; cri-dockerd)<\/h3>\n<pre><code class=\"language-shell\"># \u5b89\u88c5 Docker \u4ed3\u5e93\ndnf config-manager --add-repo https:\/\/download.docker.com\/linux\/centos\/docker-ce.repo\ndnf install docker-ce docker-ce-cli containerd.io -y\nsystemctl enable --now docker\n\n# \u5b89\u88c5 cri-dockerd\n# \u6ce8\u610f\uff1aCentOS 10 \u5efa\u8bae\u4e0b\u8f7d\u9002\u7528\u4e8e CentOS \u7684 rpm \u6216 \u4e8c\u8fdb\u5236\nwget https:\/\/github.com\/Mirantis\/cri-dockerd\/releases\/download\/v0.3.21\/cri-dockerd-0.3.21.amd64.tgz\ntar xf cri-dockerd-0.3.21.amd64.tgz\ninstall -o root -g root -m 0755 cri-dockerd\/cri-dockerd \/usr\/local\/bin\/cri-dockerd\n\n# \u83b7\u53d6\u670d\u52a1\u6587\u4ef6\ncd cri-dockerd\nwget https:\/\/raw.githubusercontent.com\/Mirantis\/cri-dockerd\/master\/packaging\/systemd\/cri-docker.service\nwget https:\/\/raw.githubusercontent.com\/Mirantis\/cri-dockerd\/master\/packaging\/systemd\/cri-docker.socket\ncp cri-docker.service cri-docker.socket \/etc\/systemd\/system\/\nsed -i -e 's,\/usr\/bin\/cri-dockerd,\/usr\/local\/bin\/cri-dockerd,' \/etc\/systemd\/system\/cri-docker.service\n\n# \u6307\u5b9a pause \u955c\u50cf (k8s 1.35 \u63a8\u8350 3.10)\nsed -i 's|ExecStart=.*|ExecStart=\/usr\/local\/bin\/cri-dockerd --container-runtime-endpoint fd:\/\/ --pod-infra-container-image=registry.k8s.io\/pause:3.10|' \/etc\/systemd\/system\/cri-docker.service\n\nsystemctl daemon-reload\nsystemctl enable --now cri-docker.socket cri-docker<\/code><\/pre>\n<h3>2.3 \u914d\u7f6e Kubernetes \u4ed3\u5e93<\/h3>\n<pre><code class=\"language-shell\">cat << EOF | tee \/etc\/yum.repos.d\/kubernetes.repo\n[kubernetes]\nname=Kubernetes\nbaseurl=https:\/\/pkgs.k8s.io\/core:\/stable:\/v1.35\/rpm\/\nenabled=1\ngpgcheck=1\ngpgkey=https:\/\/pkgs.k8s.io\/core:\/stable:\/v1.35\/rpm\/repodata\/repomd.xml.key\nEOF<\/code><\/pre>\n<h2>\u4e09\u3001\u51c6\u5907Master&amp;Worker\u8282\u70b9<\/h2>\n<p>\u590d\u5236hep-k8s-master-worker-temp\u865a\u62df\u673a\uff0c\u53f3\u952eclone\u5373\u53ef\uff0c\u7136\u540e\u4fee\u6539\u4e3b\u673a\u540d\u3001IP\u5730\u5740\u3002\u4e00\u5171\u590d\u5236\u51fa\u4e09\u53f0Master\u56db\u53f0Worker\u5373\u53ef\uff0c\u8fd9\u4e9b\u8282\u70b9\u90fd\u6709\u4e0a\u9762\u914d\u7f6e\u597d\u7684\u5185\u5bb9\u3002\u5982\u679c\u4f60\u662f\u72ec\u7acb\u7684Linux\uff0c\u53ef\u4ee5\u5728\u6bcf\u53f0\u673a\u5668\u4e0a\u90fd\u6267\u884c\u4e00\u4e0b\u6b65\u9aa4\u4e8c\u7684\u6240\u7528\u5185\u5bb9\u3002<\/p>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2025\/12\/25\/image-20251225153733816.png\" alt=\"image-20251225153733816\" \/><\/p>\n<h3>3.1 \u8bbe\u7f6e\u4e3b\u673a\u540d&amp;\u56fa\u5b9aIP\u5730\u5740<\/h3>\n<pre><code class=\"language-shell\"># hep-k8s-master-01\u8282\u70b9\n# \u8bbe\u7f6e\u4e3b\u673a\u540d\nhostnamectl set-hostname hep-k8s-master-01\n#\u56fa\u5b9aIP\nnmcli connection modify ens18 ipv4.addresses 192.168.31.221\/24\n# \u91cd\u542f\u751f\u6548\nreboot\n\n# hep-k8s-master-02\u8282\u70b9\n# \u8bbe\u7f6e\u4e3b\u673a\u540d\nhostnamectl set-hostname hep-k8s-master-02\n#\u56fa\u5b9aIP\nnmcli connection modify ens18 ipv4.addresses 192.168.31.222\/24\n# \u91cd\u542f\u751f\u6548\nreboot\n\n# hep-k8s-master-03\u8282\u70b9\n# \u8bbe\u7f6e\u4e3b\u673a\u540d\nhostnamectl set-hostname hep-k8s-master-03\n#\u56fa\u5b9aIP\nnmcli connection modify ens18 ipv4.addresses 192.168.31.223\/24\n# \u91cd\u542f\u751f\u6548\nreboot\n\n# hep-k8s-worker-01\u8282\u70b9\n# \u8bbe\u7f6e\u4e3b\u673a\u540d\nhostnamectl set-hostname hep-k8s-worker-01\n#\u56fa\u5b9aIP\nnmcli connection modify ens18 ipv4.addresses 192.168.31.224\/24\n# \u91cd\u542f\u751f\u6548\nreboot\n\n# hep-k8s-worker-02\u8282\u70b9\n# \u8bbe\u7f6e\u4e3b\u673a\u540d\nhostnamectl set-hostname hep-k8s-worker-02\n#\u56fa\u5b9aIP\nnmcli connection modify ens18 ipv4.addresses 192.168.31.225\/24\n# \u91cd\u542f\u751f\u6548\nreboot\n\n# hep-k8s-worker-03\u8282\u70b9\n# \u8bbe\u7f6e\u4e3b\u673a\u540d\nhostnamectl set-hostname hep-k8s-worker-03\n#\u56fa\u5b9aIP\nnmcli connection modify ens18 ipv4.addresses 192.168.31.226\/24\n# \u91cd\u542f\u751f\u6548\nreboot\n\n# hep-k8s-worker-04\u8282\u70b9\n# \u8bbe\u7f6e\u4e3b\u673a\u540d\nhostnamectl set-hostname hep-k8s-worker-04\n#\u56fa\u5b9aIP\nnmcli connection modify ens18 ipv4.addresses 192.168.31.227\/24\n# \u91cd\u542f\u751f\u6548\nreboot<\/code><\/pre>\n<h3>3.2 \u5f00\u653e\u7aef\u53e3\u53f7<\/h3>\n<p>\u4e3a\u4e86\u96c6\u7fa4\u7684\u5b89\u5168\u6027\u8003\u8651\uff0c\u6211\u8fd9\u91cc\u5e76\u6ca1\u6709\u5b8c\u5168\u5173\u95ed\u9632\u706b\u5899\uff0c\u800c\u662f\u91c7\u7528\u9700\u8981\u54ea\u4e2a\u7aef\u53e3\u5c31\u6253\u5f00\u54ea\u4e2a\u7aef\u53e3\uff0c\u8fd9\u6837\u4e5f\u66f4\u7b26\u5408\u4f01\u4e1a\u4f7f\u7528\u4e60\u60ef\uff0c\u4e5f\u4f1a\u5177\u6709\u66f4\u9ad8\u7684\u53ef\u9760\u6027\u5b89\u5168\u6027\u3002<\/p>\n<h4>3.2.1 Master\u8282\u70b9<\/h4>\n<pre><code class=\"language-shell\"># \u6838\u5fc3\u8f6c\u53d1\u4e0e\u7f51\u6bb5\u4fe1\u4efb (\u5fc5\u987b\u5148\u6267\u884c) \nfirewall-cmd --permanent --direct --add-rule ipv4 filter FORWARD 0 -j ACCEPT\nfirewall-cmd --permanent --add-masquerade\nfirewall-cmd --permanent --zone=public --add-source=192.168.0.0\/12\nfirewall-cmd --permanent --zone=public --add-source=10.96.0.0\/12\nfirewall-cmd --permanent --add-rich-rule='rule family=\"ipv4\" source address=\"192.168.0.0\/12\" accept'\nfirewall-cmd --permanent --add-rich-rule='rule family=\"ipv4\" source address=\"10.96.0.0\/12\" accept'\n\n#  Kubernetes \u6838\u5fc3\u7ec4\u4ef6\u7aef\u53e3 \nfirewall-cmd --permanent --add-port=6443\/tcp      # API Server\nfirewall-cmd --permanent --add-port=2379-2380\/tcp # Etcd\nfirewall-cmd --permanent --add-port=10250\/tcp     # Kubelet API\nfirewall-cmd --permanent --add-port=10257\/tcp     # Kube-controller-manager\nfirewall-cmd --permanent --add-port=10259\/tcp     # Kube-scheduler\nfirewall-cmd --permanent --add-port=9100\/tcp      # Node Exporter (\u76d1\u63a7\u5e38\u7528)\n\n# \u7f51\u7edc\u63d2\u4ef6 (Calico & kube-vip) \nfirewall-cmd --permanent --add-port=179\/tcp       # BGP\nfirewall-cmd --permanent --add-port=5473\/tcp      # Typha\nfirewall-cmd --permanent --add-port=4789\/udp      # VXLAN\nfirewall-cmd --permanent --add-port=8472\/udp      # Flannel\/Other VXLAN (\u5907\u7528)\n\n# \u670d\u52a1\u53d1\u73b0 (DNS) \nfirewall-cmd --permanent --add-port=53\/tcp\nfirewall-cmd --permanent --add-port=53\/udp\nfirewall-cmd --permanent --add-port=9153\/tcp     # CoreDNS Metrics\n\n#  \u4e1a\u52a1\u7aef\u53e3 \nfirewall-cmd --permanent --add-port=30000-32767\/tcp # NodePort\n\n# \u8865\u5168 Controller \u548c Scheduler \u7aef\u53e3\uff08\u867d\u7136 10250-10259 \u5305\u542b\u4e86\uff0c\u4f46\u5efa\u8bae\u663e\u5f0f\u786e\u8ba4\uff09\nfirewall-cmd --permanent --add-port=10257\/tcp\nfirewall-cmd --permanent --add-port=10259\/tcp\nfirewall-cmd --permanent --add-port=10256\/tcp\n\n# \u7acb\u5373\u751f\u6548\nfirewall-cmd --reload<\/code><\/pre>\n<h4>3.2.2 worker\u8282\u70b9<\/h4>\n<pre><code class=\"language-shell\"># \u6838\u5fc3\u8f6c\u53d1\u4e0e\u7f51\u6bb5\u4fe1\u4efb\nfirewall-cmd --permanent --direct --add-rule ipv4 filter FORWARD 0 -j ACCEPT\nfirewall-cmd --permanent --add-masquerade\nfirewall-cmd --permanent --zone=public --add-source=192.168.0.0\/12\nfirewall-cmd --permanent --zone=public --add-source=10.96.0.0\/12\nfirewall-cmd --permanent --add-rich-rule='rule family=\"ipv4\" source address=\"192.168.0.0\/12\" accept'\nfirewall-cmd --permanent --add-rich-rule='rule family=\"ipv4\" source address=\"10.96.0.0\/12\" accept'\n\n# Kubernetes \u7ec4\u4ef6\u4e0e\u76d1\u63a7\nfirewall-cmd --permanent --add-port=10250\/tcp     # Kubelet API\nfirewall-cmd --permanent --add-port=10256\/tcp     # Kube-Proxy (Health check)\nfirewall-cmd --permanent --add-port=9100\/tcp      # Node Exporter\n\n# \u7f51\u7edc\u63d2\u4ef6 (Calico) \nfirewall-cmd --permanent --add-port=179\/tcp       # BGP\nfirewall-cmd --permanent --add-port=5473\/tcp      # Typha\nfirewall-cmd --permanent --add-port=4789\/udp      # VXLAN\n\n#  \u670d\u52a1\u53d1\u73b0\u4e0e\u4e1a\u52a1 \nfirewall-cmd --permanent --add-port=53\/tcp\nfirewall-cmd --permanent --add-port=53\/udp\nfirewall-cmd --permanent --add-port=30000-32767\/tcp # NodePort\n\n# \u8865\u5168 Node Exporter \u76d1\u63a7\nfirewall-cmd --permanent --add-port=9100\/tcp\n# \u8865\u5168 Kube-Proxy \u5065\u5eb7\u68c0\u67e5\nfirewall-cmd --permanent --add-port=10256\/tcp\n\n# \u7acb\u5373\u751f\u6548\nfirewall-cmd --reload<\/code><\/pre>\n<h2>\u56db\u3001 \u96c6\u7fa4\u521d\u59cb\u5316\u51c6\u5907<\/h2>\n<h3>4.1 K8S\u96c6\u7fa4\u8f6f\u4ef6&amp;\u5bb9\u5668\u955c\u50cf<\/h3>\n<pre><code class=\"language-shell\"># \u5b89\u88c5\u6307\u5b9a\u7248\u672c\u7684 K8s \u6838\u5fc3\u7ec4\u4ef6\n# Master\u8282\u70b9\u5b89\u88c5kubelet\u3001kubeadm\u3001kubectl\uff0cWorker\u8282\u70b9\u5b89\u88c5kubelet\u3001kubeadm\n# dnf install -y kubelet kubeadm --disableexcludes=kubernetes\ndnf install -y kubelet kubeadm kubectl --disableexcludes=kubernetes\n\n# \u8bbe\u7f6e kubelet \u5f00\u673a\u81ea\u542f\nsystemctl enable --now kubelet\n\n# \u67e5\u770b K8s 1.35.0 \u6240\u9700\u7684\u955c\u50cf\u5217\u8868\nkubeadm config images list\nkubeadm config images list --kubernetes-version=v1.35.0\n\n# \u62c9\u53d6 K8s 1.35.0 \u955c\u50cf(\u6307\u5b9a cri-dockerd \u5bb9\u5668\u8fd0\u884c\u65f6\uff09\n# \u8fd9\u4e2a\u65f6\u5019\uff0c\u4f60\u6ca1\u6709\u79d1\u5b66\u4e0a\u7f51\u5e94\u8be5\u662f\u62c9\u53d6\u4e0d\u4e86\u7684\uff0c\u60f3\u77e5\u9053\u600e\u4e48\u914d\u7f6e\u53ef\u4ee5\u8f6c\u5230\u6587\u7ae0\u540e\u9762\u90e8\u5206\uff0c\u4e86\u89e3\u4e00\u4e0b\u3002\nkubeadm config images pull --cri-socket unix:\/\/\/var\/run\/cri-dockerd.sock<\/code><\/pre>\n<h3>4.2 \u4e91\u539f\u751f\u8d1f\u8f7d\u5747\u8861\u5668kube-vip\u51c6\u5907<\/h3>\n<pre><code class=\"language-shell\"># \u5728Master01\u4e0a\u6267\u884c\n# \u5b9a\u4e49kube-vip\u6240\u9700\u73af\u5883\u53d8\u91cf\nexport VIP=192.168.31.220\nexport INTERFACE=ens18 # \u6ce8\u610f\u67e5\u770b\u4f60\u7684\u7f51\u5361\u540d\uff0cCentOS\u53ef\u80fd\u662f ens18 \u6216 eth0\nexport KVVERSION=v1.0.3\n\ndocker run -it --rm --net=host ghcr.io\/kube-vip\/kube-vip:$KVVERSION manifest pod \\\n--interface $INTERFACE \\\n--address $VIP \\\n--controlplane \\\n--services \\\n--arp \\\n--enableLoadBalancer \\\n--leaderElection | tee \/etc\/kubernetes\/manifests\/kube-vip.yaml\n\n# \u540c\u6837\u5c06\u6b64\u6587\u4ef6\u5206\u53d1\u5230 master-02, master-03 \u7684\u5bf9\u5e94\u76ee\u5f55\n# \u5c06kube-vip.yaml\u6587\u4ef6\u590d\u5236\u5230hep-k8s-master-02\u8282\u70b9\u7684\u5bf9\u5e94\u76ee\u5f55\nscp \/etc\/kubernetes\/manifests\/kube-vip.yaml hep-k8s-master-02:\/etc\/kubernetes\/manifests\/\n\n# \u5c06kube-vip.yaml\u6587\u4ef6\u590d\u5236\u5230hep-k8s-master-03\u8282\u70b9\u7684\u5bf9\u5e94\u76ee\u5f55\nscp \/etc\/kubernetes\/manifests\/kube-vip.yaml hep-k8s-master-03:\/etc\/kubernetes\/manifests\/<\/code><\/pre>\n<h2>\u4e94\u3001K8S\u96c6\u7fa4\u521d\u59cb\u5316<\/h2>\n<h3>5.1 kubeadm-config.yaml\u914d\u7f6e<\/h3>\n<p>kubeadm-config.yaml\u6587\u4ef6\u7684\u4fee\u6539\u662f\u91cd\u70b9\uff0c\u8fd9\u4e2a\u641e\u597d\u4e86\u5c31\u6210\u529f\u4e86\u4e00\u534a\u4e86\u3002<\/p>\n<pre><code class=\"language-yaml\"># \u751f\u6210\u914d\u7f6e\u6587\u4ef6\u6837\u4f8b kubeadm-config.yaml\nkubeadm config print init-defaults --component-configs KubeProxyConfiguration > kubeadm-config.yaml\n\n# \u4fee\u6539\u8fd9\u4e2a\u914d\u7f6e\u6587\u4ef6\u4ee5\u4e0b\u5185\u5bb9\n# advertiseAddress: 192.168.31.221\uff0c\u6539\u6210\u81ea\u5df1\u7684\u4e3b\u673a\u5730\u5740\n# criSocket: unix:\/\/\/var\/run\/cri-dockerd.sock \u4f7f\u7528cri-dockerd\n# name: hep-k8s-master-01\uff0c\u81ea\u5df1\u7684\u4e3b\u673a\u540d\n# \u589e\u52a0 certSANs: \u8ba4\u8bc1\u8bc1\u4e66\u914d\u7f6e\uff0cMaster\u8282\u70b9\u7684\u4e3b\u673a\u540d\u548cIP\u90fd\u5199\u4e0a\u5566\n  #- lb.k8s.hep.com\n  #- hep-k8s-master-01\n  #- hep-k8s-master-02\n  #- hep-k8s-master-03\n  #- 192.168.31.221\n  #- 192.168.31.222\n  #- 192.168.31.223\n# \u589e\u52a0 controlPlaneEndpoint: \"lb.k8s.hep.com:6443\"\uff0cVIP\u5730\u5740\u548c\u7aef\u53e3\n# \u589e\u52a0 podSubnet: 192.168.0.0\/12\uff0c\u548cCalico \u9ed8\u8ba4 Pod \u5b50\u7f51\u5339\u914d\uff0c\u5f53\u7136\u4e5f\u53ef\u4ee5\u9ed8\u8ba4\u3002\u6211\u8fd9\u91cc\u5c31\u6ca1\u4fee\u6539\uff0c\u91c7\u7528\u9ed8\u8ba4\u7684\n# strictARP: true\n# mode: \"ipvs\"\napiVersion: kubeadm.k8s.io\/v1beta4\nkind: InitConfiguration\nlocalAPIEndpoint:\n  advertiseAddress: 192.168.31.221\nnodeRegistration:\n  criSocket: unix:\/\/\/var\/run\/cri-dockerd.sock\n  name: hep-k8s-master-01\n---\napiVersion: kubeadm.k8s.io\/v1beta4\nkind: ClusterConfiguration\nkubernetesVersion: v1.35.0\ncontrolPlaneEndpoint: \"lb.k8s.hep.com:6443\"\napiServer:\n  certSANs:\n  - lb.k8s.hep.com\n  - 192.168.31.220\n  - 192.168.31.221\n  - 192.168.31.222\n  - 192.168.31.223\nnetworking:\n  podSubnet: 192.168.0.0\/16\n---\napiVersion: kubeproxy.config.k8s.io\/v1alpha1\nkind: KubeProxyConfiguration\nmode: \"ipvs\"<\/code><\/pre>\n<h3>5.2 master\u8282\u70b9\u914d\u7f6e<\/h3>\n<pre><code class=\"language-shell\"># kubeadm \u521d\u59cb\u5316\u524d\u4fee\u6539 kube-vip.yaml\nsed -i 's#path: \/etc\/kubernetes\/admin.conf#path: \/etc\/kubernetes\/super-admin.conf#' \/etc\/kubernetes\/manifests\/kube-vip.yaml\n\n# \u9884\u62c9\u53d6\u955c\u50cf\nkubeadm config images pull --cri-socket unix:\/\/\/var\/run\/cri-dockerd.sock\n\n# \u6267\u884c\u521d\u59cb\u5316\nkubeadm init --config kubeadm-config.yaml --upload-certs\n\n[addons] Applied essential addon: CoreDNS\n[addons] Applied essential addon: kube-proxy\n\nYour Kubernetes control-plane has initialized successfully!\n\nTo start using your cluster, you need to run the following as a regular user:\n\n  mkdir -p $HOME\/.kube\n  sudo cp -i \/etc\/kubernetes\/admin.conf $HOME\/.kube\/config\n  sudo chown $(id -u):$(id -g) $HOME\/.kube\/config\n\nAlternatively, if you are the root user, you can run:\n\n  export KUBECONFIG=\/etc\/kubernetes\/admin.conf\n\nYou should now deploy a pod network to the cluster.\nRun \"kubectl apply -f [podnetwork].yaml\" with one of the options listed at:\n  https:\/\/kubernetes.io\/docs\/concepts\/cluster-administration\/addons\/\n\nYou can now join any number of control-plane nodes running the following command on each as root:\n\n  kubeadm join lb.k8s.hep.com:6443 --token abcdef.0123456789abcdef \\\n        --discovery-token-ca-cert-hash sha256:4e83465atcbd1eb05aa8e9f7244a760565b0fa27c9db8cf5a41ea283856d715 \\\n        --control-plane --certificate-key 056c3140d0a4c1d06501bb040bb6dc959569fdfa49888ef0cd3efc6dd7edc60f\n\nPlease note that the certificate-key gives access to cluster sensitive data, keep it secret!\nAs a safeguard, uploaded-certs will be deleted in two hours; If necessary, you can use\n\"kubeadm init phase upload-certs --upload-certs\" to reload certs afterward.\n\nThen you can join any number of worker nodes by running the following on each as root:\n\nkubeadm join lb.k8s.hep.com:6443 --token abcdef.0123456789abcdef \\\n        --discovery-token-ca-cert-hash sha256:4e83465atcbd1eb05aa8e9f7244a760565b0fa27c9db8cf5a41ea283856d715\n[root@hep-k8s-master-01 kelsen]#\n\n# \u5b8c\u6210\u540e\u914d\u7f6e kubectl\nmkdir -p $HOME\/.kube\ncp -i \/etc\/kubernetes\/admin.conf $HOME\/.kube\/config\nchown $(id -u):$(id -g) $HOME\/.kube\/config\n\n# hep-k8s-master-02\u3001hep-k8s-master-03\u52a0\u5165\u63a7\u5236\u8282\u70b9\uff0c\u4e00\u5b9a\u5e26\u4e0a--cri-socket unix:\/\/\/var\/run\/cri-dockerd.sock\u53c2\u6570\nkubeadm join lb.k8s.hep.com:6443 --token abcdef.0123456789abcdef \\\n        --discovery-token-ca-cert-hash sha256:4e83465atcbd1eb05aa8e9f7244a760565b0fa27c9db8cf5a41ea283856d715 \\\n        --control-plane --certificate-key 056c3140d0a4c1d06501bb040bb6dc959569fdfa49888ef0cd3efc6dd7edc60f  --cri-socket unix:\/\/\/var\/run\/cri-dockerd.sock\n\n# hep-k8s-master-02\u3001hep-k8s-master-03\u6210\u529f\u52a0\u5165\u63a7\u5236\u8282\u70b9\u540e\uff0c\u914d\u7f6ekubectl\u73af\u5883\nmkdir -p $HOME\/.kube\nsudo cp -i \/etc\/kubernetes\/admin.conf $HOME\/.kube\/config\nsudo chown $(id -u):$(id -g) $HOME\/.kube\/config<\/code><\/pre>\n<h3>5.3 worker\u8282\u70b9\u914d\u7f6e<\/h3>\n<pre><code class=\"language-shell\"># hep-k8s-worker-01\u3001hep-k8s-worker-02\u3001hep-k8s-worker-03\u3001hep-k8s-worker-04\u52a0\u5165\u96c6\u7fa4\uff0c\u4e00\u5b9a\u5e26\u4e0a--cri-socket unix:\/\/\/var\/run\/cri-dockerd.sock\u53c2\u6570\nkubeadm join lb.k8s.hep.com:6443 --token abcdef.0123456789abcdef \\\n        --discovery-token-ca-cert-hash sha256:4e83465atcbd1eb05aa8e9f7244a760565b0fa27c9db8cf5a41ea283856d715  --cri-socket unix:\/\/\/var\/run\/cri-dockerd.sock<\/code><\/pre>\n<h3>5.4 \u5b89\u88c5\u7f51\u7edc\u63d2\u4ef6 (Calico)<\/h3>\n<pre><code class=\"language-shell\"># \u5e94\u7528Calico Operator\u8d44\u6e90\u6e05\u5355(\u90e8\u7f72Calico\u63a7\u5236\u5668\uff09\nkubectl create -f https:\/\/raw.githubusercontent.com\/projectcalico\/calico\/v3.29.1\/manifests\/tigera-operator.yaml\n# \u67e5\u770btigera-operator\u662f\u5426\u4e3aRunning\nkubectl get ns\nkubectl get pods -n tigera-operator\n\n# \u4e0b\u8f7dCalico\u81ea\u5b9a\u4e49\u8d44\u6e90\u914d\u7f6e\u6587\u4ef6\nwget https:\/\/raw.githubusercontent.com\/projectcalico\/calico\/v3.29.1\/manifests\/custom-resources.yaml\n\n# \u4fee\u6539\u81ea\u5b9a\u4e49\u8d44\u6e90\u6587\u4ef6(\u5339\u914dkubeadm\u521d\u59cb\u5316\u7684Pod\u7f51\u7edcCIDR\uff09\uff0c\u6211\u8fd9\u91cc\u6ca1\u4fee\u6539\uff0c\u7528\u7684\u9ed8\u8ba4192.168.0.0\nvim custom-resources.yaml\n# (\u4fee\u6539\u7b2c13\u884c\u7684cidr\u4e3akubeadm init --pod-network-cidr\u6307\u5b9a\u7684\u5730\u5740\uff0c\u9ed8\u8ba4\u4e3a192.168.0.0\/16\uff09\n\n# \u5e94\u7528Calico\u81ea\u5b9a\u4e49\u8d44\u6e90\u914d\u7f6e(\u5b8c\u6210Calico\u90e8\u7f72\uff09\uff0c\u5927\u6982\u8fc7\u4e2a\u4e94\u5206\u949f\uff0c\u5c31\u90fdRunning\u72b6\u6001\u4e86\nkubectl create -f custom-resources.yaml\n\nkubectl get ns\nkubectl get pods -n calico-system\nkubectl get nodes\n\n# \u4fee\u6539 Worker \u8282\u70b9 ROLES\u4e3aworker\nkubectl label node hep-k8s-worker-01 node-role.kubernetes.io\/worker=worker\nkubectl label node hep-k8s-worker-02 node-role.kubernetes.io\/worker=worker\nkubectl label node hep-k8s-worker-03 node-role.kubernetes.io\/worker=worker\nkubectl label node hep-k8s-worker-04 node-role.kubernetes.io\/worker=worker\n# worker\u7684ROLES\u88ab\u6253\u4e0aworker\u7684label\u4e86\nkubectl get nodes<\/code><\/pre>\n<hr \/>\n<h2>\u516d\u3001\u90e8\u7f72Nginx\u9a8c\u8bc1\u96c6\u7fa4\u53ef\u7528\u6027<\/h2>\n<pre><code class=\"language-shell\">[root@hep-k8s-master-01 kelsen]# kubectl get service -n kube-system\nNAME       TYPE        CLUSTER-IP   EXTERNAL-IP   PORT(S)                  AGE\nkube-dns   ClusterIP   10.96.0.10   <none>        53\/UDP,53\/TCP,9153\/TCP   16h\n[root@hep-k8s-master-01 kelsen]# dig -t a www.baidu.com @10.96.0.10\n\n; <<>> DiG 9.18.33 <<>> -t a www.baidu.com @10.96.0.10\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6108\n;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 1232\n; COOKIE: 8d225c06f081a7e7 (echoed)\n;; QUESTION SECTION:\n;www.baidu.com.                 IN      A\n\n;; ANSWER SECTION:\nwww.baidu.com.          5       IN      CNAME   www.a.shifen.com.\nwww.a.shifen.com.       5       IN      CNAME   www.wshifen.com.\nwww.wshifen.com.        5       IN      A       103.235.46.102\nwww.wshifen.com.        5       IN      A       103.235.46.115\n\n;; Query time: 250 msec\n;; SERVER: 10.96.0.10#53(10.96.0.10) (UDP)\n;; WHEN: Thu Dec 25 15:53:05 CST 2025\n;; MSG SIZE  rcvd: 204\n\n[root@hep-k8s-master-01 kelsen]#<\/code><\/pre>\n<h3>6.2 \u5229\u7528K8S\u90e8\u7f72Nginx<\/h3>\n<pre><code class=\"language-yaml\"># \u521b\u5efa\u4e00\u4e2anginx.yaml\u6587\u4ef6\uff0c\u5176\u5185\u5bb9\u5982\u4e0b\nvim nginx.yaml\n\n---\napiVersion: apps\/v1\nkind: Deployment\nmetadata:\n  name: nginxweb\nspec:\n  selector:\n    matchLabels:\n      app: nginxweb1\n  replicas: 2\n  template:\n    metadata:\n      labels:\n        app: nginxweb1\n    spec:\n      containers:\n      - name: nginxwebc\n        image: nginx:latest\n        imagePullPolicy: IfNotPresent\n        ports:\n        - containerPort: 80\n---\napiVersion: v1\nkind: Service\nmetadata:\n  name: nginxweb-service\nspec:\n  externalTrafficPolicy: Cluster\n  selector:\n    app: nginxweb1\n  ports:\n  - protocol: TCP\n    port: 80\n    targetPort: 80\n    nodePort: 30080\n  type: NodePort<\/code><\/pre>\n<p>\u521b\u5efaNginx\u5e94\u7528<\/p>\n<pre><code class=\"language-shell\">kubectl apply -f nginx.yaml\n\nkubectl get pods\n\nkubectl get service<\/code><\/pre>\n<h3>6.3 \u9a8c\u8bc1Nginx<\/h3>\n<pre><code class=\"language-shell\"># \u5728Master\u548cworker\u6240\u6709\u673a\u5668\u4e0a\u5f00\u901a30080\u7aef\u53e3\nfirewall-cmd --permanent --add-port=30080\/tcp\n# \u5728\u5c40\u57df\u7f51\u6d4f\u89c8\u5668\u4e2d\u8bbf\u95eehttp:\/\/192.168.31.224:30080\/\u5373\u53ef\u770b\u5230Nginx\u4e3b\u9875\n# \u4e09\u53f0Master+30080\u4ee5\u53ca\u56db\u53f0worker+30080\u90fd\u53ef\u4ee5\u8bbf\u95eeNginx<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2025\/12\/25\/image-20251225155810077.png\" alt=\"image-20251225155810077\" \/><\/p>\n<h2>\u4e03\u3001CentOS Stream 10 \u914d\u7f6e\u955c\u50cf\u52a0\u901f<\/h2>\n<pre><code class=\"language-shell\"># \u8fdb\u5165\u5b58\u653e\u76ee\u5f55\ncd \/home\/kelsen\n\n# \u4e0b\u8f7d\u517c\u5bb9\u7248\u6838\u5fc3\nwget https:\/\/github.com\/MetaCubeX\/mihomo\/releases\/download\/v1.18.9\/mihomo-linux-amd64-compatible-v1.18.9.gz\n\n# \u89e3\u538b\u5e76\u79fb\u52a8\ngunzip -f mihomo-linux-amd64-compatible-v1.18.9.gz\nchmod +x mihomo-linux-amd64-compatible-v1.18.9\nmv -f mihomo-linux-amd64-compatible-v1.18.9 \/usr\/local\/bin\/mihomo\n\n# \u521b\u5efa\u914d\u7f6e\u6587\u4ef6\u5939\u5e76\u4e0b\u8f7d\u8d44\u6e90\nmkdir -p \/root\/.config\/mihomo\n# \u8bf7\u5c06\u4e0b\u65b9\u94fe\u63a5\u66ff\u6362\u4e3a\u4f60\u771f\u5b9e\u7684\u8ba2\u9605\u5730\u5740\ncurl -L -o \/root\/.config\/mihomo\/config.yaml \"\u4f60\u7684Mihomo\u8ba2\u9605\u94fe\u63a5\"\n# \u4e0b\u8f7d\u5730\u7406\u4f4d\u7f6e\u5e93\ncurl -L -o \/root\/.config\/mihomo\/Country.mmdb https:\/\/testingcf.jsdelivr.net\/gh\/MetaCubeX\/meta-rules-dat@release\/geoip.metadb\n\n# \u518d\u6b21\u5c1d\u8bd5\u624b\u52a8\u8fd0\u884c\n\/usr\/local\/bin\/mihomo -d \/root\/.config\/mihomo\n# \u6e05\u7406\u65e7\u8fdb\u7a0b\u5e76\u521b\u5efa Systemd \u670d\u52a1\nsudo pkill -9 mihomo || true\n\ncat <<EOF | sudo tee \/etc\/systemd\/system\/mihomo.service\n[Unit]\nDescription=Mihomo Daemon - Specialized for K8S Proxy\nAfter=network.target\n\n[Service]\nType=simple\nUser=root\nExecStart=\/usr\/local\/bin\/mihomo -d \/root\/.config\/mihomo\nRestart=always\nRestartSec=5\n\n[Install]\nWantedBy=multi-user.target\nEOF\n\n# \u542f\u52a8\u670d\u52a1\nsystemctl daemon-reload\nsystemctl enable --now mihomo\n\n# \u914d\u7f6e DNF \u6c38\u4e45\u4ee3\u7406 (CentOS \u66ff\u4ee3 APT \u7684\u914d\u7f6e)\n# \u6ce8\u610f\uff1aCentOS Stream 10 \u4f7f\u7528 dnf.conf\nif ! grep -q \"proxy=http:\/\/127.0.0.1:9981\" \/etc\/dnf\/dnf.conf; then\n    echo \"proxy=http:\/\/127.0.0.1:9981\" | sudo tee -a \/etc\/dnf\/dnf.conf\nfi\n\n# \u914d\u7f6e\u7528\u6237\u73af\u5883\u53d8\u91cf (\u5199\u5165 .bashrc)\ncat >> ~\/.bashrc << 'EOF'\n\n# Mihomo Proxy Settings\nexport http_proxy=\"http:\/\/127.0.0.1:9981\"\nexport https_proxy=\"http:\/\/127.0.0.1:9981\"\n# K8S \u91cd\u8981\u6392\u9664\u9879\nexport no_proxy=\"localhost,127.0.0.1,192.168.31.0\/24,10.96.0.0\/12,192.168.0.0\/16,lb.k8s.hep.com,.svc,.cluster.local\"\nEOF\n\n# .bashrc\u751f\u6548\nsource ~\/.bashrc\n\n# \u914d\u7f6e Docker \u4ee3\u7406\nmkdir -p \/etc\/systemd\/system\/docker.service.d\ncat << EOF | sudo tee \/etc\/systemd\/system\/docker.service.d\/http-proxy.conf\n[Service]\nEnvironment=\"HTTP_PROXY=http:\/\/127.0.0.1:9981\"\nEnvironment=\"HTTPS_PROXY=http:\/\/127.0.0.1:9981\"\nEnvironment=\"NO_PROXY=localhost,127.0.0.1,192.168.31.0\/24,lb.k8s.hep.com,.cluster.local\"\nEOF\n\nsystemctl daemon-reload\nsystemctl restart docker || echo \"Docker \u672a\u5b89\u88c5\uff0c\u8df3\u8fc7\u91cd\u542f\"\n\n#  \u9a8c\u8bc1\necho \"\u6b63\u5728\u6d4b\u8bd5\u4ee3\u7406\u8fde\u901a\u6027...\"\ncurl -I https:\/\/www.google.com\n\n# \u9884\u62c9\u53d6 K8S \u955c\u50cf\necho \"\u6b63\u5728\u9884\u62c9\u53d6 Kubernetes v1.35.0 \u955c\u50cf...\"\n# \u6ce8\u610f\uff1a\u786e\u4fdd cri-dockerd \u5df2\u5b89\u88c5\u5e76\u8fd0\u884c\nkubeadm config images pull --cri-socket unix:\/\/\/var\/run\/cri-dockerd.sock<\/code><\/pre>\n<h2>\u516b\u3001\u96c6\u7fa4\u4f18\u96c5\u5f00\u5173\u673a<\/h2>\n<h3>8.1 K8S\u96c6\u7fa4\u5173\u673a<\/h3>\n<pre><code class=\"language-shell\"># \u5982\u679c\u662f\u4e3a\u4e86\u957f\u671f\u505c\u673a\u6216\u7ef4\u62a4\uff0c\u5efa\u8bae\u5148\u6e05\u7a7a\u8282\u70b9\u3002\u5982\u679c\u53ea\u662f\u4e34\u65f6\u91cd\u542f\uff0c\u53ef\u8df3\u8fc7\u6b64\u6b65\u3002\n# \u5728 master01 \u6267\u884c\uff0c\u5faa\u73af\u5904\u7406 worker \u8282\u70b9\nkubectl drain hep-k8s-worker-01 --ignore-daemonsets --delete-emptydir-data\n# \u5bf9\u5176\u4ed6 worker02-04 \u91cd\u590d\u6b64\u64cd\u4f5c\nkubectl drain hep-k8s-worker-02 --ignore-daemonsets --delete-emptydir-data\nkubectl drain hep-k8s-worker-03 --ignore-daemonsets --delete-emptydir-data\nkubectl drain hep-k8s-worker-04 --ignore-daemonsets --delete-emptydir-data\n# \u5173\u95ed\u6240\u6709 Worker Nodes\n# \u4f9d\u6b21\u767b\u5f55\u5230\u56db\u53f0 Worker \u8282\u70b9\uff0801-04\uff09\uff0c\u6267\u884c\u5173\u673a\n# \u505c\u6b62 kubelet\uff0c\u9632\u6b62\u5b83\u5728\u5173\u673a\u8fc7\u7a0b\u4e2d\u5c1d\u8bd5\u62c9\u8d77\u5bb9\u5668\nsudo systemctl stop kubelet\nsudo systemctl stop containerd\nsudo shutdown -h now\n# \u9010\u4e2a\u5173\u95ed Master \u8282\u70b9 (\u5173\u952e)\n# \u5148\u5173 Master 02 \u548c Master 03\nsudo systemctl stop kubelet\nsudo systemctl stop containerd\nsudo shutdown -h now\n# \u6700\u540e\u5173 Master 01 (VIP \u627f\u8f7d\u8005)\uff1a \u6700\u540e\u5173\u95ed\u6301\u6709 VIP \u7684\u8282\u70b9\uff0c\u786e\u4fdd\u63a7\u5236\u5e73\u9762\u5728\u5173\u673a\u6700\u540e\u4e00\u523b\u4f9d\u7136\u53ef\u7528\u3002<\/code><\/pre>\n<h3>8.2 K8S\u96c6\u7fa4\u5f00\u673a<\/h3>\n<pre><code class=\"language-shell\"># \u540c\u65f6\u5f00\u542f Master 01, 02, 03\n# \u68c0\u67e5 kube-vip\uff1a \u7531\u4e8e\u4f7f\u7528\u4e86 kube-vip\uff0c\u5b83\u901a\u5e38\u4f5c\u4e3a\u9759\u6001 Pod \u8fd0\u884c\u3002Master \u8282\u70b9\u542f\u52a8\u540e\uff0c\u68c0\u67e5 VIP \u662f\u5426\u80fd\u591f Ping \u901a\nping 192.168.31.200\n# \u68c0\u67e5\u63a7\u5236\u5e73\u9762\u72b6\u6001\uff1a \u767b\u5f55\u5230 Master 01\uff0c\u89c2\u5bdf\u6838\u5fc3\u7ec4\u4ef6\u548c etcd \u72b6\u6001\nkubectl get nodes\nkubectl get pods -n kube-system\n# \u542f\u52a8 Worker \u8282\u70b9\n# \u4e00\u65e6 kubectl get nodes \u663e\u793a Master \u8282\u70b9\u4e3a Ready \u72b6\u6001\uff0c\u5373\u53ef\u542f\u52a8\u6240\u6709 Worker \u8282\u70b9\nkubectl uncordon hep-k8s-worker-01\nkubectl uncordon hep-k8s-worker-02\nkubectl uncordon hep-k8s-worker-03\nkubectl uncordon hep-k8s-worker-04<\/code><\/pre>\n<h2>\u4e5d\u3001Helm<\/h2>\n<blockquote>\n<p>Reference:<\/p>\n<p>\u5b98\u65b9\u6587\u6863k8s1.30\u5b89\u88c5\u90e8\u7f72\u9ad8\u53ef\u7528\u96c6\u7fa4\uff0ckubeadm\u5b89\u88c5Kubernetes1.30\u6700\u65b0\u7248\u672c:<a href=\"https:\/\/blog.csdn.net\/weixin_45652150\/article\/details\/138492600\">https:\/\/blog.csdn.net\/weixin_45652150\/article\/details\/138492600<\/a><\/p>\n<p>ubuntu22.04\u5b89\u88c5Kubernetes1.25.0(k8s1.25.0)\u9ad8\u53ef\u7528\u96c6\u7fa4\uff1a<a href=\"http:\/\/www.huerpu.cc:7000\/?p=432\">http:\/\/www.huerpu.cc:7000\/?p=432<\/a><\/p>\n<p>60\u5206\u949f\u6781\u901f\u90e8\u7f72\u4f01\u4e1a\u7ea7kubernetes k8s 1.35\u96c6\u7fa4:<a href=\"https:\/\/www.bilibili.com\/video\/BV1oNqkBzEuy\/\">https:\/\/www.bilibili.com\/video\/BV1oNqkBzEuy\/<\/a><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>CentOS Stream 10\u5b89\u88c5Kubernetes(k8s v1.35.0)\u9ad8\u53ef\u7528\u96c6\u7fa4 \u672c\u7740\u5b66\u4e60\u65b0\u6280\u672f\u548c [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[],"class_list":["post-1892","post","type-post","status-publish","format-standard","hentry","category-18"],"_links":{"self":[{"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=\/wp\/v2\/posts\/1892","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1892"}],"version-history":[{"count":10,"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=\/wp\/v2\/posts\/1892\/revisions"}],"predecessor-version":[{"id":1902,"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=\/wp\/v2\/posts\/1892\/revisions\/1902"}],"wp:attachment":[{"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1892"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.huerpu.cc:7000\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}