惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Privacy & Cybersecurity Law Blog
WordPress大学
WordPress大学
Last Week in AI
Last Week in AI
腾讯CDC
人人都是产品经理
人人都是产品经理
小众软件
小众软件
V
Visual Studio Blog
S
Secure Thoughts
J
Java Code Geeks
V
V2EX
量子位
The Hacker News
The Hacker News
酷 壳 – CoolShell
酷 壳 – CoolShell
Security Latest
Security Latest
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Spread Privacy
Spread Privacy
博客园 - 叶小钗
T
Threat Research - Cisco Blogs
Security Archives - TechRepublic
Security Archives - TechRepublic
T
Tailwind CSS Blog
Cloudbric
Cloudbric
S
SegmentFault 最新的问题
AI
AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Application and Cybersecurity Blog
Application and Cybersecurity Blog
IT之家
IT之家
T
Tenable Blog
S
Security @ Cisco Blogs
月光博客
月光博客
雷峰网
雷峰网
博客园 - 【当耐特】
Know Your Adversary
Know Your Adversary
C
Cybersecurity and Infrastructure Security Agency CISA
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
爱范儿
爱范儿
Attack and Defense Labs
Attack and Defense Labs
博客园 - 三生石上(FineUI控件)
Hacker News - Newest:
Hacker News - Newest: "LLM"
有赞技术团队
有赞技术团队
N
News and Events Feed by Topic
阮一峰的网络日志
阮一峰的网络日志
TaoSecurity Blog
TaoSecurity Blog
宝玉的分享
宝玉的分享
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Cloudflare Blog
K
Kaspersky official blog

打工人日志

2026-05-28 打工人日报 2026-05-27 打工人日报 2026-05-26 打工人日报 2026-05-25 打工人日报 2026-05-24 打工人日报 2026-05-23 打工人日报 2026-05-22 打工人日报 2026-05-21 打工人日报 2026-05-20 打工人日报 2026-05-19 打工人日报 2026-05-18 打工人日报 2026-05-17 打工人日报 2026-05-16 打工人日报 2026-05-15 打工人日报 2026-05-14 打工人日报 2026-05-13 打工人日报 2026-05-12 打工人日报 2026-05-11 打工人日报 2026-05-10 打工人日报 2026-05-09 打工人日报 2026-05-08 打工人日报 2026-05-07 打工人日报 2026-05-06 打工人日报 2026-05-05 打工人日报 2026-05-04 打工人日报 2026-05-03 打工人日报 2026-05-02 打工人日报 2026-05-01 打工人日报 2026-04-30 打工人日报 2026-04-29 打工人日报 2026-04-28 打工人日报 2026-04-27 打工人日报 2026-04-26 打工人日报 2026-04-25 打工人日报 2026-04-24 打工人日报 2026-04-23 打工人日报 2026-04-22 打工人日报 2026-04-21 打工人日报 2026-04-20 打工人日报 2026-04-19 打工人日报 2026-04-18 打工人日报 2026-04-17 打工人日报 2026-04-16 打工人日报 2026-04-15 打工人日报 2026-04-14 打工人日报 2026-04-13 打工人日报 2026-04-12 打工人日报 2026-04-11 打工人日报 2026-04-10 打工人日报 2026-04-09 打工人日报 2026-04-08 打工人日报 2026-04-07 打工人日报 2026-04-06 打工人日报 2026-04-05 打工人日报 2026-04-04 打工人日报 2026-04-03 打工人日报 2026-04-02 打工人日报 2026-04-01 打工人日报 2026-03-31 打工人日报 2026-03-30 打工人日报 2026-03-29 打工人日报 2026-03-28 打工人日报 2026-03-27 打工人日报 2026-03-26 打工人日报 2026-03-25 打工人日报 2026-03-24 打工人日报 2026-03-23 打工人日报 2026-03-22 打工人日报 2026-03-21 打工人日报 2026-03-20 打工人日报 2026-03-19 打工人日报 2026-03-18 打工人日报 2026-03-17 打工人日报 2026-03-16 打工人日报 2026-03-15 打工人日报 2026-03-14 打工人日报 2026-03-13 打工人日报 2026-03-12 打工人日报 2026-03-11 打工人日报 2026-03-10 打工人日报 2026-03-09 打工人日报 2026-03-08 打工人日报 2026-03-07 打工人日报 2026-03-06 打工人日报 2026-03-05 打工人日报 2026-03-04 打工人日报 2026-03-03 打工人日报 2026-03-02 打工人日报 2026-03-01 打工人日报 2026-02-28 打工人日报 2026-02-27 打工人日报 2026-02-26 打工人日报 2026-02-25 打工人日报 2026-02-24 打工人日报 2026-02-23 打工人日报 2026-02-22 打工人日报 2026-02-21 打工人日报 2026-02-20 打工人日报 2026-02-19 打工人日报 2026-02-18 打工人日报
Kubernetes — RKE2 + kube-vip + cilium 部署
2025-09-18 · via 打工人日志

准备工作

节点名称节点IP
k8s-master-110.10.10.151
k8s-master-210.10.10.152
k8s-master-310.10.10.153
kube-vip(虚拟IP)10.10.10.150

RKE 安装 rancher

在第一个 master 安装 RKE2 server

1# 安装 RKE2
2curl -sfL https://get.rke2.io | sh -

创建配置文件

1mkdir -p /etc/rancher/rke2/
1# 配置 server
2cat <<EOF >/etc/rancher/rke2/config.yaml
3write-kubeconfig-mode: "0644"
4tls-san:
5  - 10.10.10.150
6  - rancher.jobcher.com
7cni: cilium
8disable-kube-proxy: true
9EOF
1# 启动 server
2systemctl enable rke2-server --now
3systemctl status rke2-server
1ln -s /var/lib/rancher/rke2/bin/kubectl /usr/local/bin/kubectl
2echo 'export KUBECONFIG=/etc/rancher/rke2/rke2.yaml' >> ~/.bashrc
3source ~/.bashrc

kubectl 补全

1apt-get install -y bash-completion
1echo 'source <(kubectl completion bash)' >> ~/.bashrc
2source ~/.bashrc
3kubectl completion bash >/etc/bash_completion.d/kubectl
4source /etc/bash_completion.d/kubectl

cilium 安装

下载 Cilium CLI

1curl -L --remote-name https://github.com/cilium/cilium-cli/releases/latest/download/cilium-linux-amd64.tar.gz
2tar xzvf cilium-linux-amd64.tar.gz
3mv cilium /usr/local/bin/
4cilium version
1cilium status
2kubectl get pods -n kube-system -l k8s-app=cilium
3kubectl get nodes -o wide
1vim rke2-cilium-config.yml
 1# /var/lib/rancher/rke2/server/manifests/rke2-cilium-config.yml
 2apiVersion: helm.cattle.io/v1
 3kind: HelmChartConfig
 4metadata:
 5  name: rke2-cilium
 6  namespace: kube-system
 7spec:
 8  valuesContent: |-
 9    tunnelProtocol: geneve
10    kubeProxyReplacement: true
11    k8sServiceHost: localhost
12    k8sServicePort: 6443
13    hubble:
14      enabled: true
15      relay:
16        enabled: true
17      ui:
18        enabled: true    

配置 hubble-ui ,查看网络结构

1kubectl apply -f rke2-cilium-config.yml
2
3kubectl -n kube-system patch svc hubble-ui \
4  -p '{"spec": {"type": "NodePort"}}'

其他master 加入集群

获取token值

1cat /var/lib/rancher/rke2/server/node-token
1curl -sfL https://get.rke2.io | sh -
1mkdir -p /etc/rancher/rke2/
1cat <<EOF >/etc/rancher/rke2/config.yaml
2server: https://10.10.10.150:9345
3token: <token> # 输入token值
4tls-san:
5  - 10.10.10.150
6  - rancher.jobcher.com
7cni: cilium
8disable-kube-proxy: true
9EOF
1# 启动 server
2systemctl enable rke2-server --now
3systemctl status rke2-server

配置kubectl

1ln -s /var/lib/rancher/rke2/bin/kubectl /usr/local/bin/kubectl
2echo 'export KUBECONFIG=/etc/rancher/rke2/rke2.yaml' >> ~/.bashrc
3source ~/.bashrc
1kubectl get pod -n kube-system | grep kube-vip

kube-vip 安装

1KVVERSION=$(curl -sL https://api.github.com/repos/kube-vip/kube-vip/releases | jq -r ".[0].name")
1alias ctr="/var/lib/rancher/rke2/bin/ctr --address /run/k3s/containerd/containerd.sock"
1alias kube-vip="ctr image pull ghcr.io/kube-vip/kube-vip:$KVVERSION; ctr run --rm --net-host ghcr.io/kube-vip/kube-vip:$KVVERSION vip /kube-vip"
1wget https://kube-vip.io/manifests/rbac.yaml
2mv rbac.yaml kube-vip-rbac.yaml
3chmod +x kube-vip-rbac.yaml && kubectl apply -f kube-vip-rbac.yaml
 1# 运行
 2kube-vip manifest daemonset \
 3  --arp \
 4  --controlplane \
 5  --address 10.10.10.150\
 6  --interface eth0 \
 7  --leaderElection \
 8  --enableLoadBalancer \
 9  --inCluster \
10  --taint > kube-vip.yaml
1kubectl apply -f kube-vip.yaml

检测vip

1curl -k https://10.10.10.150:9345/v1-rke2/connect

rancher 安装

1curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
2
3helm repo add rancher-stable https://releases.rancher.com/server-charts/stable
4helm repo update
5
6kubectl create namespace cattle-system
7kubectl -n cattle-system create secret tls tls-rancher-ingress --cert=fullchain.pem --key=privkey.pem
1helm upgrade --install rancher rancher-stable/rancher \
2  --namespace cattle-system \
3  --set hostname="rancher.jobcher.com" \
4  --set ingress.tls.source="secret" \
5  --set bootstrapPassword="输入你的密码"