Kubernetes部署Dashboard可视化插件

Kubernetes集群架构环境

主机名IP系统版本
k8s-master 172.21.3.20 CentOS7.8
k8s-node1 172.21.3.21 CentOS7.8
k8s-node2 172.21.3.22 CentOS7.8

在每台机器的hosts文件中添加所有角色名称及对应的ip

关闭所有主机防火墙

#停止firewall

systemctl stop firewalld.service

#禁止firewall开机启动

systemctl disable firewalld.service 

部署Dashboard

#在k8s-master执行yaml文件直接部署

kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.0/aio/deploy/recommended.yaml

#查看dashboard运行状态,以deployment方式部署,运行2个pod及2个service

[root@master ~]# kubectl -n kubernetes-dashboard get pods
NAME                                         READY   STATUS    RESTARTS   AGE
dashboard-metrics-scraper-694557449d-wfv4b   1/1     Running   0          4m50s
kubernetes-dashboard-9774cc786-v9ltx         1/1     Running   0          4m50s

[root@master ~]# kubectl -n kubernetes-dashboard get svc 
NAME                        TYPE        CLUSTER-IP       EXTERNAL-IP   PORT(S)    AGE
dashboard-metrics-scraper   ClusterIP   10.100.165.238           8000/TCP   4m52s
kubernetes-dashboard        ClusterIP   10.109.218.125           443/TCP    4m52s

访问dashboard

#这里作为演示,使用nodeport方式将dashboard服务暴露在集群外,指定使用30443端口,可自定义:

kubectl  patch svc kubernetes-dashboard -n kubernetes-dashboard \
-p '{"spec":{"type":"NodePort","ports":[{"port":443,"targetPort":8443,"nodePort":30443}]}}'

#查看暴露的service,已修改为nodeport类型:

kubectl -n kubernetes-dashboard get svc
NAME                        TYPE        CLUSTER-IP       EXTERNAL-IP   PORT(S)         AGE
dashboard-metrics-scraper   ClusterIP   10.102.18.37             8000/TCP        69s
kubernetes-dashboard        NodePort    10.110.118.188           443:30443/TCP   69s

#或者下载yaml文件手动修改service部分 

wget https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.0/aio/deploy/recommended.yaml

#修改servcie部分

$ more recommended.yaml
...
---

kind: Service
apiVersion: v1
metadata:
  labels:
    k8s-app: kubernetes-dashboard
  name: kubernetes-dashboard
  namespace: kubernetes-dashboard
spec:
  type: NodePort
  ports:
    - port: 443
      targetPort: 8443
      nodePort: 30443
  selector:
    k8s-app: kubernetes-dashboard

---
...

#更新配置

kubectl apply -f recommended.yaml

登录dashboard

#浏览器访问dashboard:
    
https://172.21.3.20:30443

创建dashboard认证方式

#Dashboard 支持 Kubeconfig 和 Token 两种认证方式,我们这里选择Token认证方式登录

cat > dashboard-adminuser.yaml << EOF
apiVersion: v1
kind: ServiceAccount
metadata:
  name: admin-user
  namespace: kubernetes-dashboard

---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: admin-user
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: cluster-admin
subjects:
- kind: ServiceAccount
  name: admin-user
  namespace: kubernetes-dashboard  
EOF

#创建登录用户
kubectl apply -f dashboard-adminuser.yaml

#说明:上面创建了一个叫admin-user的服务账号,并放在kubernetes-dashboard 命名空间下,并将cluster-admin角色绑定到admin-user账户,

#这样admin-user账户就有了管理员的权限。默认情况下,kubeadm创建集群时已经创建了cluster-admin角色,我们直接绑定即可。  

#查看admin-user账户的token

[root@k8s-master ~]# kubectl -n kubernetes-dashboard describe secret $(kubectl -n kubernetes-dashboard get secret | grep admin-user | awk '{print $1}')
Name:         admin-user-token-k5dxw
Namespace:    kubernetes-dashboard
Labels:       
Annotations:  kubernetes.io/service-account.name: admin-user
              kubernetes.io/service-account.uid: 4731fd19-db01-4517-bd64-e03fc7fb82be

Type:  kubernetes.io/service-account-token

Data
====
ca.crt:     1025 bytes
namespace:  20 bytes
token:      eyJhbGciOiJSUzI1NiIsImtpZCI6IlBEbzQ3b1dQRWI3M2diLVRFcmd4ZnpZMmtUV1BwV2pkNEZHZDFiWVBnSkEifQ.eyJpc3MiOiJrdWJlcm5ldGVzL3NlcnZpY2VhY2NvdW50Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9uYW1lc3BhY2UiOiJrdWJlcm5ldGVzLWRhc2hib2FyZCIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VjcmV0Lm5hbWUiOiJhZG1pbi11c2VyLXRva2VuLWs1ZHh3Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9zZXJ2aWNlLWFjY291bnQubmFtZSI6ImFkbWluLXVzZXIiLCJrdWJlcm5ldGVzLmlvL3NlcnZpY2VhY2NvdW50L3NlcnZpY2UtYWNjb3VudC51aWQiOiI0NzMxZmQxOS1kYjAxLTQ1MTctYmQ2NC1lMDNmYzdmYjgyYmUiLCJzdWIiOiJzeXN0ZW06c2VydmljZWFjY291bnQ6a3ViZXJuZXRlcy1kYXNoYm9hcmQ6YWRtaW4tdXNlciJ9.aGyFRbrput1RujzAVPMl1X7yTQ_OXRQQtw4NoUSr44kL-2DEU0wk78ms2BDIjTM63p9aUQ9JTgzDPJCFbjOf6DWbh7AOPDDrs-4ULiIIRNnhy_Qe-5nAED5CvgVXwH60jQn3YlMsnDWqDvyhjGTaUwWrl8IZVaFLrqoaNNvF_pL4jwDoc7MAX_BVgyiJQvJDDk9--QSfCIKIZe3AOTGgq1Q6rulUxyvygUWhN4znTUOM0wv-nVCG_E-9uLF7UaxoHZE32nSsb4gO1tbnOhuw3EeyhV7VATJtLUghWzZhg7Xl-dHHCr4rY1Pf0DKCVyQEv8bTv3065MumWJaB90SNxQ

#把获取到的Token复制到登录界面的token输入框中

至此到这k8s可视化插件搭建结束

posted @ 2020-09-25 09:35  浒多年以后  阅读(336)  评论(0)    收藏  举报