Multi-Node Setup
Multi-Node Cluster Setup¶
Deploying a multi-node Kubernetes cluster requires careful coordination between master (control plane) and worker nodes, along with secure TLS communication and a reliable etcd backend. This section guides you through the process using kubeadm, a tool designed for easy Kubernetes installation.
Prerequisites¶
Before starting, ensure all nodes meet these requirements:
- Operating System: Ubuntu 22.04 or later (or compatible Linux distro).
- Network: All nodes must have a stable network connection and can communicate with each other.
- Static IPs: Assign static IP addresses to each node for consistent networking.
- Tools: Install kubeadm, kubectl, and kubelet on all nodes:
sudo apt update && sudo apt install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
Node Preparation¶
-
Disable Swap:
Ensure swap is disabled in/etc/fstabto prevent unexpected behavior. -
Set Hostnames: Assign unique hostnames to each node (e.g.,
master,worker1,worker2). -
Configure Firewall: Allow necessary ports (e.g., 6443 for API server, 10250 for kubelet):
Setting Up etcd¶
For a production cluster, etcd should be deployed as a multi-node cluster for redundancy and high availability. Here’s how to set it up manually:
-
Install etcd on each etcd node:
Configure etcd with a static peer list (e.g., in/etc/default/etcd): -
Start and Enable etcd:
-
Verify etcd Cluster Health: Use
etcdctlto check the etcd cluster:
Initializing the Master Node¶
- Initialize the Control Plane:
Use
kubeadm initto set up the master node. Specify the etcd configuration if using a custom setup: --control-plane-endpoint: Public IP or DNS name of the master node.-
--upload-certs: Uploads certificates for easier worker node joins. -
Configure kubeconfig: After initialization, copy the kubeconfig file to your home directory:
Joining Worker Nodes¶
-
Generate Join Token: Run the following on the master node to generate a token for worker nodes:
This outputs a command like: -
Join Worker Nodes: Execute the generated command on each worker node:
Verifying the Cluster¶
-
Check Node Status:
All nodes should showReady. -
Verify etcd Health: Use
etcdctlto check the etcd cluster: -
Test TLS Connectivity: Ensure the API server is reachable securely:
Key takeaways¶
- Multi-node clusters require careful network configuration and role separation between master and worker nodes.
- etcd must be securely configured and either integrated with Kubernetes or run as a standalone cluster.
- TLS is automatically handled by
kubeadm, but manual configuration is possible for advanced scenarios. - Verification steps ensure the cluster is functional and secure.