mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-25 12:38:05 +00:00
Merge pull request #3743 from manuelbuil/tokens
More info about K3S_TOKEN and K3S_AGENT_TOKEN
This commit is contained in:
@@ -24,6 +24,7 @@ This section contains advanced information describing the different ways you can
|
||||
- [Additional preparation for (Red Hat/CentOS) Enterprise Linux](#additional-preparation-for-red-hat-centos-enterprise-linux)
|
||||
- [Enabling Lazy Pulling of eStargz (Experimental)](#enabling-lazy-pulling-of-estargz-experimental)
|
||||
- [Additional Logging Sources](#additional-logging-sources)
|
||||
- [Server and agent tokens](#server-and-agent-tokens)
|
||||
|
||||
# Certificate Rotation
|
||||
|
||||
@@ -440,4 +441,14 @@ helm repo add rancher-charts https://charts.rancher.io
|
||||
helm repo update
|
||||
helm install --create-namespace -n cattle-logging-system rancher-logging-crd rancher-charts/rancher-logging-crd
|
||||
helm install --create-namespace -n cattle-logging-system rancher-logging --set additionalLoggingSources.k3s.enabled=true rancher-charts/rancher-logging
|
||||
```
|
||||
```
|
||||
|
||||
# Server and agent tokens
|
||||
|
||||
In K3s, there are two types of tokens: K3S_TOKEN and K3S_AGENT_TOKEN.
|
||||
|
||||
K3S_TOKEN: Defines the key required by the server to offer the HTTP config resources. These resources are requested by the other servers before joining the K3s HA cluster. If the K3S_AGENT_TOKEN is not defined, the agents use this token as well to access the required HTTP resources to join the cluster. Note that this token is also used to generate the encryption key for important content in the database (e.g., bootstrap data).
|
||||
|
||||
K3S_AGENT_TOKEN: Optional. Defines the key required by the server to offer HTTP config resources to the agents. If not defined, agents will require K3S_TOKEN. Defining K3S_AGENT_TOKEN is encouraged to avoid agents having to know K3S_TOKEN, which is also used to encrypt data.
|
||||
|
||||
If no K3S_TOKEN is defined, the first K3s server will generate a random one. The result is part of the content in `/var/lib/rancher/k3s/server/token`. For example, `K1070878408e06a827960208f84ed18b65fa10f27864e71a57d9e053c4caff8504b::server:df54383b5659b9280aa1e73e60ef78fc`, where `df54383b5659b9280aa1e73e60ef78fc` is the K3S_TOKEN.
|
||||
|
||||
Reference in New Issue
Block a user