[k8s] kubeadm: node ์ถ”๊ฐ€

kubeadm ๊ธฐ๋ฐ˜ ํด๋Ÿฌ์Šคํ„ฐ์— ๋…ธ๋“œ๋ฅผ ์ถ”๊ฐ€ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๊ฐ„๋‹จํ•˜๊ฒŒ ์ •๋ฆฌํ•œ๋‹ค.
k8s๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ๋‚ด๋ถ€๋ง์— ๋Œ€ํ•ด์„œ๋งŒ ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ์ด ๊ฐ€๋Šฅํ•˜๊ฒŒ๋” ์ธ์ฆ์„œ ์„ค์ •์ด ๋œ๋‹ค.

๊ทธ๋ž˜์„œ ํŠน๋ณ„ํ•œ ์ƒํ™ฉ์ด ์•„๋‹ˆ๋ผ๋ฉด ์„œ๋กœ๋ฅผ private IP๋กœ๋งŒ ๊ฐ€๋ฆฌํ‚ค๊ฒŒ๋” ๊ตฌ์„ฑ์„ ํ•˜๋Š”๋ฐ, ๋งŒ์•ฝ ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ์—์„œ public IP๋กœ ์—ฐ๊ฒฐํ•˜๋ ค๋ฉด ๋งˆ์Šคํ„ฐ๋…ธ๋“œ๋ฅผ ์ดˆ๊ธฐํ™”ํ• ๋•Œ๋ถ€ํ„ฐ public IP๋ฅผ ๋„ฃ์–ด์คฌ์–ด์•ผ ํ•œ๋‹ค.

kubeadm init --apiserver-cert-extra-sans=PUBLIC_IP_MASTER_NODE

์•„๋ฌดํŠผ ๋‚ด ๊ฒฝ์šฐ์—๋Š” ๋จธ์‹ ์„ ํ•˜๋‚˜ ๋” ๋„์šฐ๊ณ  ๋…ธ๋“œ๋กœ ๋งŒ๋“ค์—ˆ๋‹ค.

๊ธฐ์กด ๋งˆ์Šคํ„ฐ ๋…ธ๋“œ์˜ ์ฟ ๋ฒ„ ๋ฒ„์ „์„ ํ™•์ธํ•˜๊ณ , kubelet, ์ปจํ…Œ์ด๋„ˆ, kubeadm ์„ธํŠธ๋ฅผ ์„ค์น˜ํ•ด์ค€๋‹ค.

https://blog.naver.com/sssang97/222456216151
์ž์„ธํ•œ ๋ฐฉ๋ฒ•์€ ๋ณ„๋„ ํฌ์ŠคํŠธ๋ฅผ ์ฐธ์กฐํ•œ๋‹ค.




ํ† ํฐ ์ƒ์„ฑ

์ƒˆ๋กœ์šด ๋…ธ๋“œ๊ฐ€ ํด๋Ÿฌ์Šคํ„ฐ์— ์ฐธ์—ฌํ•˜๋ ค๋ฉด ์ธ์ฆ ํ† ํฐ์„ ํ†ตํ•ด์„œ ์„œ๋กœ๋ฅผ ์•Œ์•„๊ฐ€์•ผ ํ•œ๋‹ค.

kubeadm token create
kubeadm token list

๋งŒ๋“ค๊ณ 


openssl x509 -pubkey -in /etc/kubernetes/pki/ca.crt | openssl rsa -pubin -outform der 2>/dev/null | openssl dgst -sha256 -hex | sed 's/^.* //'

ํ•ด์‹œ๋„ ํ•˜๋‚˜ ๋งŒ๋“ค์–ด์ค€๋‹ค.




join

์ƒˆ๋กœ์šด ๋…ธ๋“œ๊ฐ€ ํด๋Ÿฌ์Šคํ„ฐ์— ์ฐธ์—ฌํ•˜๋Š” ๊ฒƒ์„ join์ด๋ผ๊ณ  ํ•œ๋‹ค.
๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ช…๋ น์„ ์‚ฌ์šฉํ•ด์„œ ๋งˆ์Šคํ„ฐ ๋…ธ๋“œ์— ์ฐธ์—ฌ์‹œํ‚จ๋‹ค.

kubeadm join IP:6443 --token ํ† ํฐ๊ฐ’ --discovery-token-ca-cert-hash sha256:ํ•ด์‹œ๊ฐ’ --ignore-preflight-errors=FileExisting-conntrack



์ฐธ์กฐ
https://stackoverflow.com/questions/60173541/is-it-possible-to-join-a-worker-node-that-is-in-a-different-network
https://kubernetes.io/docs/reference/setup-tools/kubeadm/kubeadm-join/