mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-25 12:38:05 +00:00
Organize RKE OS requirements
This commit is contained in:
committed by
Denise
parent
db4ca034e7
commit
900b63c3ee
@@ -10,19 +10,19 @@ aliases:
|
||||
|
||||
- [Operating System](#operating-system)
|
||||
|
||||
- [RedHat Enterprise Linux (RHEL) / Oracle Enterprise Linux (OEL) / CentOS](#redhat-enterprise-linux-rhel--oracle-enterprise-linux-oel--centos)
|
||||
|
||||
- [Red Hat Enterprise Linux (RHEL) / Oracle Enterprise Linux (OEL) / CentOS](#red-hat-enterprise-linux-rhel-oracle-enterprise-linux-oel-centos)
|
||||
|
||||
- [Using upstream Docker](#using-upstream-docker)
|
||||
- [Using RHEL/CentOS packaged Docker](#using-rhelcentos-packaged-docker)
|
||||
- [Using RHEL/CentOS packaged Docker](#using-rhel-centos-packaged-docker)
|
||||
- [Notes about Atomic Nodes](#red-hat-atomic)
|
||||
|
||||
- [OpenSSH version](#openssh-version)
|
||||
- [Creating a Docker Group](#creating-a-docker-group)
|
||||
- [Software](#software)
|
||||
- [Ports](#ports)
|
||||
- [Opening port TCP/6443 using `iptables``](#opening-port-tcp6443-using-iptables)
|
||||
- [Opening port TCP/6443 using `firewalld`](#opening-port-tcp6443-using-firewalld)
|
||||
- [Notes about Atomic Nodes](#notes-about-atomic-nodes)
|
||||
|
||||
- [Container Volumes](#container-volumes)
|
||||
- [OpenSSH version](#openssh-version)
|
||||
- [Creating a Docker Group](#creating-a-docker-group)
|
||||
- [Opening port TCP/6443 using `iptables`](#opening-port-tcp-6443-using-iptables)
|
||||
- [Opening port TCP/6443 using `firewalld`](#opening-port-tcp-6443-using-firewalld)
|
||||
|
||||
<!-- /TOC -->
|
||||
|
||||
@@ -82,9 +82,9 @@ xt_tcpudp |
|
||||
net.bridge.bridge-nf-call-iptables=1
|
||||
```
|
||||
|
||||
### RedHat Enterprise Linux (RHEL) / Oracle Enterprise Linux (OEL) / CentOS
|
||||
### Red Hat Enterprise Linux (RHEL) / Oracle Enterprise Linux (OEL) / CentOS
|
||||
|
||||
If using RedHat Enterprise Linux, Oracle Enterprise Linux or CentOS, you cannot use the `root` user as [SSH user]({{< baseurl >}}/rke/v0.1.x/en/config-options/nodes/#ssh-user) due to [Bugzilla 1527565](https://bugzilla.redhat.com/show_bug.cgi?id=1527565). Please follow the instructions below how to setup Docker correctly, based on the way you installed Docker on the node.
|
||||
If using Red Hat Enterprise Linux, Oracle Enterprise Linux or CentOS, you cannot use the `root` user as [SSH user]({{< baseurl >}}/rke/v0.1.x/en/config-options/nodes/#ssh-user) due to [Bugzilla 1527565](https://bugzilla.redhat.com/show_bug.cgi?id=1527565). Please follow the instructions below how to setup Docker correctly, based on the way you installed Docker on the node.
|
||||
|
||||
#### Using upstream Docker
|
||||
If you are using upstream Docker, the package name is `docker-ce` or `docker-ee`. You can check the installed package by executing:
|
||||
@@ -96,13 +96,13 @@ rpm -q docker-ce
|
||||
When using the upstream Docker packages, please follow [Manage Docker as a non-root user](https://docs.docker.com/install/linux/linux-postinstall/#manage-docker-as-a-non-root-user).
|
||||
|
||||
#### Using RHEL/CentOS packaged Docker
|
||||
If you are using the Docker Docker package supplied by RedHat / CentOS, the package name is `docker`. You can check the installed package by executing:
|
||||
If you are using the Docker Docker package supplied by Red Hat / CentOS, the package name is `docker`. You can check the installed package by executing:
|
||||
|
||||
```
|
||||
rpm -q docker
|
||||
```
|
||||
|
||||
If you are using the Docker package supplied by RedHat / CentOS, the `dockerroot` group is automatically added to the system. You will need to edit (or create) `/etc/docker/daemon.json` to include the following:
|
||||
If you are using the Docker package supplied by Red Hat / CentOS, the `dockerroot` group is automatically added to the system. You will need to edit (or create) `/etc/docker/daemon.json` to include the following:
|
||||
|
||||
```
|
||||
{
|
||||
@@ -130,15 +130,31 @@ $ docker ps
|
||||
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
|
||||
```
|
||||
|
||||
### Red Hat Atomic
|
||||
|
||||
Before trying to use RKE with Red Hat Atomic nodes, there are a couple of updates to the OS that need to occur in order to get RKE working.
|
||||
|
||||
#### OpenSSH version
|
||||
|
||||
By default, Atomic hosts ship with OpenSSH 6.4, which doesn't support SSH tunneling, which is a core RKE requirement. If you upgrade to the latest version of OpenSSH supported by Atomic, it will correct the SSH issue.
|
||||
|
||||
#### Creating a Docker Group
|
||||
|
||||
By default, Atomic hosts do not come with a Docker group. You can update the ownership of the Docker socket by enabling the specific user in order to launch RKE.
|
||||
|
||||
```
|
||||
# chown <user> /var/run/docker.sock
|
||||
```
|
||||
|
||||
## Software
|
||||
|
||||
- Docker - Each Kubernetes version supports different Docker versions.
|
||||
|
||||
Kubernetes Version | Docker 1.12.6 | Docker 1.13.1 | Docker 17.03.2 |
|
||||
----|----|----|----|
|
||||
v1.11.x | X | X | X |
|
||||
v1.10.x | X | X | X |
|
||||
v1.9.x | X | X | X |
|
||||
v1.8.x | X | X | X |
|
||||
|
||||
You can either follow the [Docker installation](https://docs.docker.com/install/) instructions or use one of Rancher's [install scripts](https://github.com/rancher/install-docker) to install Docker.
|
||||
|
||||
@@ -174,12 +190,13 @@ Server:
|
||||
|
||||
## Ports
|
||||
|
||||
{{< ports-rke-nodes >}}
|
||||
{{< requirements_ports_rke >}}
|
||||
|
||||
If you are using an external firewall, make sure you have this port opened between the machine you are using to run `rke` and the nodes that you are going to use in the cluster.
|
||||
|
||||
|
||||
### Opening port TCP/6443 using `iptables``
|
||||
### Opening port TCP/6443 using `iptables`
|
||||
|
||||
```
|
||||
# Open TCP/6443 for all
|
||||
@@ -203,31 +220,3 @@ firewall-cmd --permanent --zone=public --add-rich-rule='
|
||||
port protocol="tcp" port="6443" accept'
|
||||
firewall-cmd --reload
|
||||
```
|
||||
|
||||
## Notes about Atomic Nodes
|
||||
|
||||
Before trying to use RKE with Atomic nodes, there are a couple of updates to the OS that need to occur in order to get RKE working.
|
||||
|
||||
### Container Volumes
|
||||
|
||||
In RKE, most of the volumes are mounted with option `z`, but there are some container volumes that may have some issues in Atomic due to SELinux.
|
||||
|
||||
Before running RKE, users will need to run the following commands to make some additional directories:
|
||||
|
||||
```
|
||||
# mkdir /opt/cni /etc/cni
|
||||
# chcon -Rt svirt_sandbox_file_t /etc/cni
|
||||
# chcon -Rt svirt_sandbox_file_t /opt/cni
|
||||
```
|
||||
|
||||
### OpenSSH version
|
||||
|
||||
By default, Atomic hosts ship with OpenSSH 6.4, which doesn't support SSH tunneling, which is a core RKE requirement. If you upgrade to the latest version of OpenSSH supported by Atomic, it will correct the SSH issue.
|
||||
|
||||
### Creating a Docker Group
|
||||
|
||||
By default, Atomic hosts do not come with a Docker group. You can update the ownership of the Docker socket by enabling the specific user in order to launch RKE.
|
||||
|
||||
```
|
||||
# chown <user> /var/run/docker.sock
|
||||
```
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
<div>
|
||||
<p><strong>RKE node:</strong><br/>Node that runs the <code>rke</code> commands</p>
|
||||
<h3>RKE node - Outbound rules</h3>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Protocol</th>
|
||||
<th>Port</th>
|
||||
<th>Source</th>
|
||||
<th>Destination</th>
|
||||
<th>Description</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>TCP</td>
|
||||
<td>22</td>
|
||||
<td>RKE node</td>
|
||||
<td><ul><li>Any node configured in Cluster Configuration File</li></ul></td>
|
||||
<td>SSH provisioning of node by RKE</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>TCP</td>
|
||||
<td>6443</td>
|
||||
<td>RKE node</td>
|
||||
<td><ul><li>controlplane nodes</li></ul></td>
|
||||
<td>Kubernetes apiserver</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
Reference in New Issue
Block a user