Cleanup k3s docs

This commit is contained in:
Erik Wilson
2019-07-15 15:32:37 -07:00
committed by Denise Schannon
parent 70a849d102
commit 92325bcbd7
3 changed files with 54 additions and 53 deletions
+17 -30
View File
@@ -79,9 +79,7 @@ Containerd and Docker
k3s includes and defaults to containerd. Why? Because it's just plain better. If you want to k3s includes and defaults to containerd. Why? Because it's just plain better. If you want to
run with Docker first stop and think, "Really? Do I really want more headache?" If still run with Docker first stop and think, "Really? Do I really want more headache?" If still
yes then you just need to run the agent with the `--docker` flag yes then you just need to run the agent with the `--docker` flag.
k3s agent -s ${SERVER_URL} -t ${NODE_TOKEN} --docker &
k3s will generate config.toml for containerd in `/var/lib/rancher/k3s/agent/etc/containerd/config.toml`, for advanced customization for this file you can create another file called `config.toml.tmpl` in the same directory and it will be used instead. k3s will generate config.toml for containerd in `/var/lib/rancher/k3s/agent/etc/containerd/config.toml`, for advanced customization for this file you can create another file called `config.toml.tmpl` in the same directory and it will be used instead.
@@ -132,9 +130,8 @@ mount namespace.
Node Labels and Taints Node Labels and Taints
---------------------- ----------------------
k3s server and agent can be configured with options `--node-label` and `--node-taint` which adds set of Labels and Taints to kubelet, the two options only adds labels/taints at registration time, so they can only be added once and not changed after that, an example to add new label is: k3s agents can be configured with options `--node-label` and `--node-taint` which adds set of Labels and Taints to kubelet, the two options only adds labels/taints at registration time, so they can only be added once and not changed after that, an example of options to add new label is:
``` ```
k3s server \
--node-label foo=bar \ --node-label foo=bar \
--node-label hello=world \ --node-label hello=world \
--node-taint key1=value1:NoExecute --node-taint key1=value1:NoExecute
@@ -143,27 +140,21 @@ k3s server \
Flannel Flannel
------- -------
Flannel is included by default, if you don't want flannel then run the agent with `--no-flannel` as follows Flannel is included by default, if you don't want flannel then run the agent with `--no-flannel` option.
k3s agent -u ${SERVER_URL} -t ${NODE_TOKEN} --no-flannel &
In this setup you will still be required to install your own CNI driver. More info [here](https://kubernetes.io/docs/setup/independent/create-cluster-kubeadm/#pod-network) In this setup you will still be required to install your own CNI driver. More info [here](https://kubernetes.io/docs/setup/independent/create-cluster-kubeadm/#pod-network)
CoreDNS CoreDNS
------- -------
CoreDNS is deployed on start of the agent, to disable add `--no-deploy coredns` to the server CoreDNS is deployed on start of the agent, to disable run the server with the `--no-deploy coredns` option.
k3s server --no-deploy coredns
If you don't install CoreDNS you will need to install a cluster DNS provider yourself. If you don't install CoreDNS you will need to install a cluster DNS provider yourself.
Traefik Traefik
------- -------
Traefik is deployed by default when starting the server; to disable it, start the server with `--no-deploy traefik` like this Traefik is deployed by default when starting the server; to disable it, start the server with the `--no-deploy traefik` option.
k3s server --no-deploy traefik
Service Load Balancer Service Load Balancer
--------------------- ---------------------
@@ -172,16 +163,15 @@ k3s includes a basic service load balancer that uses available host ports. If y
a load balancer that listens on port 80, for example, it will try to find a free host in the cluster a load balancer that listens on port 80, for example, it will try to find a free host in the cluster
for port 80. If no port is available the load balancer will stay in Pending. for port 80. If no port is available the load balancer will stay in Pending.
To disable the embedded service load balancer (if you wish to use a different implementation like To disable the embedded load balancer run the server with the `--no-deploy servicelb` option. This is necessary if you wish to run a different load balancer, such as MetalLB.
MetalLB) just add `--no-deploy=servicelb` to the server on startup.
Metrics Server Metrics Server
-------------- --------------
To add functionality for commands such as `k3s kubectl top node` metrics-server must be installed, To add functionality for commands such as `k3s kubectl top nodes` metrics-server must be installed,
to install see the instructions located at https://github.com/kubernetes-incubator/metrics-server/. to install see the instructions located at https://github.com/kubernetes-incubator/metrics-server/.
NOTE: By default the image used in `metrics-server-deployment.yaml` is valid only for amd64 devices, **NOTE** : By default the image used in `metrics-server-deployment.yaml` is valid only for **amd64** devices,
this should be edited as appropriate for your architecture. As of this writing metrics-server provides this should be edited as appropriate for your architecture. As of this writing metrics-server provides
the following images relevant to k3s: `amd64:v0.3.3`, `arm64:v0.3.2`, and `arm:v0.3.2`. Further information the following images relevant to k3s: `amd64:v0.3.3`, `arm64:v0.3.2`, and `arm:v0.3.2`. Further information
on the images provided through gcr.io can be found at https://console.cloud.google.com/gcr/images/google-containers/GLOBAL. on the images provided through gcr.io can be found at https://console.cloud.google.com/gcr/images/google-containers/GLOBAL.
@@ -189,7 +179,7 @@ on the images provided through gcr.io can be found at https://console.cloud.goog
Storage Backends Storage Backends
---------------- ----------------
As of version 0.6.0, k3s can support various storage backends including: SQLite (default), MySQL, Postgres, and etcd, this enahancement depends on the following arguments that can be passed to k3s server: As of version 0.6.0, k3s can support various storage backends including: SQLite (default), MySQL, Postgres, and etcd, this enhancement depends on the following arguments that can be passed to k3s server:
* `--storage-backend` _value_ * `--storage-backend` _value_
@@ -216,14 +206,13 @@ As of version 0.6.0, k3s can support various storage backends including: SQLite
To use k3s with MySQL storage backend, you can specify the following for insecure connection: To use k3s with MySQL storage backend, you can specify the following for insecure connection:
``` ```
k3s server --storage-endpoint="mysql://" --storage-endpoint="mysql://"
``` ```
By default the server will attempt to connect to mysql using the mysql socket at `/var/run/mysqld/mysqld.sock` using the root user and with no password, k3s will also create a database with the name `kubernetes` if the database is not specified in the DSN. By default the server will attempt to connect to mysql using the mysql socket at `/var/run/mysqld/mysqld.sock` using the root user and with no password, k3s will also create a database with the name `kubernetes` if the database is not specified in the DSN.
To override the method of connection, user/pass, and database name, you can provide a custom DSN, for example: To override the method of connection, user/pass, and database name, you can provide a custom DSN, for example:
``` ```
k3s server \
--storage-endpoint="mysql://k3suser:k3spass@tcp(192.168.1.100:3306)/k3stest" --storage-endpoint="mysql://k3suser:k3spass@tcp(192.168.1.100:3306)/k3stest"
``` ```
@@ -231,7 +220,6 @@ This command will attempt to connect to MySQL on host `192.168.1.100` on port `3
To connect to MySQL securely, you can use the following example: To connect to MySQL securely, you can use the following example:
``` ```
k3s server \
--storage-endpoint="mysql://k3suser:k3spass@tcp(192.168.1.100:3306)/k3stest" \ --storage-endpoint="mysql://k3suser:k3spass@tcp(192.168.1.100:3306)/k3stest" \
--storage-cafile ca.crt \ --storage-cafile ca.crt \
--storage-certfile mysql.crt \ --storage-certfile mysql.crt \
@@ -245,7 +233,7 @@ The above command will use these certificates to generate the tls config to comm
Connection to postgres can be established using the following command: Connection to postgres can be established using the following command:
``` ```
k3s server --storage-endpoint="postgres://" --storage-endpoint="postgres://"
``` ```
By default the server will attempt to connect to postgres on localhost with using the `postgres` user and with `postgres` password, k3s will also create a database with the name `kubernetes` if the database is not specified in the DSN. By default the server will attempt to connect to postgres on localhost with using the `postgres` user and with `postgres` password, k3s will also create a database with the name `kubernetes` if the database is not specified in the DSN.
@@ -253,7 +241,6 @@ By default the server will attempt to connect to postgres on localhost with usin
To override the method of connection, user/pass, and database name, you can provide a custom DSN, for example: To override the method of connection, user/pass, and database name, you can provide a custom DSN, for example:
``` ```
k3s server \
--storage-endpoint="postgres://k3suser:k3spass@192.168.1.100:5432/k3stest" --storage-endpoint="postgres://k3suser:k3spass@192.168.1.100:5432/k3stest"
``` ```
@@ -262,30 +249,30 @@ This command will attempt to connect to Postgres on host `192.168.1.100` on port
To connect to Postgres securely, you can use the following example: To connect to Postgres securely, you can use the following example:
``` ```
k3s server \ --storage-endpoint="postgres://k3suser:k3spass@192.168.1.100:5432/k3stest" \
--storage-endpoint="postgres://k3suser:k3spass@192.168.1.100:5432/k3stest?sslmode=verify-full" \
--storage-certfile postgres.crt \ --storage-certfile postgres.crt \
--storage-keyfile postgres.key \ --storage-keyfile postgres.key \
--storage-cafile ca.crt --storage-cafile ca.crt
``` ```
The above command will use these certificates to generate the tls config to communicate with postgres securely, note that the `sslmode` in the example is `verify-full` which verify that the certification presented by the server was signed by a trusted CA and the server host name matches the one in the certificate. The above command will use these certificates to generate the tls config to communicate with postgres securely.
### etcd ### etcd
Connection to etcd3 can be established using the following command: Connection to etcd3 can be established using the following command:
``` ```
k3s server --storage-backend=etcd3 \ --storage-backend=etcd3 \
--storage-endpoint="https://127.0.0.1:2379" --storage-endpoint="https://127.0.0.1:2379"
``` ```
The above command will attempt to connect insecurely to etcd on localhost with port `2379`, you can connect securely to etcd using the following command: The above command will attempt to connect insecurely to etcd on localhost with port `2379`, you can connect securely to etcd using the following command:
``` ```
k3s server \
--storage-backend=etcd3 \ --storage-backend=etcd3 \
--storage-endpoint="https://127.0.0.1:2379" \ --storage-endpoint="https://127.0.0.1:2379" \
--storage-cafile ca.crt \ --storage-cafile ca.crt \
--storage-certfile etcd.crt \ --storage-certfile etcd.crt \
--storage-keyfile etcd.key --storage-keyfile etcd.key
``` ```
The above command will use these certificates to generate the tls config to communicate with etcd securely.
+29 -16
View File
@@ -86,7 +86,10 @@ The full help text for the install script environment variables are as follows:
if not specified. if not specified.
Server Options Server Options
------------------ --------------
The following information on server options is also available through `k3s server --help` :
* `--bind-address` _value_ * `--bind-address` _value_
k3s bind address (default: localhost) k3s bind address (default: localhost)
@@ -234,6 +237,8 @@ Server Options
Agent Options Agent Options
------------------ ------------------
The following information on agent options is also available through `k3s agent --help` :
* `--token` _value_, `-t` _value_ * `--token` _value_, `-t` _value_
Token to use for authentication [$`K3S_TOKEN`] Token to use for authentication [$`K3S_TOKEN`]
@@ -311,21 +316,29 @@ Customizing components
As of v0.3.0 any of the following processes can be customized with extra flags: As of v0.3.0 any of the following processes can be customized with extra flags:
- [kube-apiserver](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-apiserver/) (server) * `--kube-apiserver-arg` _value_
- [kube-controller-manager](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/) (server)
- [kube-scheduler](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-scheduler/) (server) (server) [kube-apiserver options](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-apiserver/)
- [kubelet](https://kubernetes.io/docs/reference/command-line-tools-reference/kubelet/) (agent)
- [kube-proxy](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-proxy/) (agent) * `--kube-controller-arg` _value_
(server) [kube-controller-manager options](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/)
* `--kube-scheduler-arg` _value_
(server) [kube-scheduler options](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-scheduler/)
* `--kubelet-arg` _value_
(agent) [kubelet options](https://kubernetes.io/docs/reference/command-line-tools-reference/kubelet/)
* `--kube-proxy-arg` _value_
(agent) [kube-proxy options](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-proxy/)
Adding extra arguments can be done by passing the following flags to server or agent.
For example to add the following arguments `-v=9` and `log-file=/tmp/kubeapi.log` to the kube-apiserver, you should add the following options to k3s server:
Adding extra argument can be done by passing the following flags to server or agent:
``` ```
--kube-apiserver-arg value --kube-apiserver-arg v=9 --kube-apiserver-arg log-file=/tmp/kubeapi.log
--kube-scheduler-arg value
--kube-controller-arg value
--kubelet-arg value
--kube-proxy-arg value
```
For example to add the following arguments `-v=9` and `log-file=/tmp/kubeapi.log` to the kube-apiserver, you should pass the following:
```
k3s server --kube-apiserver-arg v=9 --kube-apiserver-arg log-file=/tmp/kubeapi.log
``` ```
+8 -7
View File
@@ -8,7 +8,7 @@ This section contains information for running k3s in various environments.
Starting the Server Starting the Server
------------------ ------------------
The installation script will auto-detect if your OS is using systemd or openrc. The installation script will auto-detect if your OS is using systemd or openrc and start the service.
When running with openrc logs will be created at `/var/log/k3s.log`, or with systemd in `/var/log/syslog` and viewed using `journalctl -u k3s`. When running with openrc logs will be created at `/var/log/k3s.log`, or with systemd in `/var/log/syslog` and viewed using `journalctl -u k3s`.
When running the server manually you should get an output similar to: When running the server manually you should get an output similar to:
@@ -39,15 +39,16 @@ Joining Nodes
------------- -------------
When the server starts it creates a file `/var/lib/rancher/k3s/server/node-token`. When the server starts it creates a file `/var/lib/rancher/k3s/server/node-token`.
Use the contents of that file as `NODE_TOKEN` and then running the agent manually: Using the contents of that file as `K3S_TOKEN` and setting `K3S_URL` allows the node
to join as an agent using the install script:
k3s agent --server https://myserver:6443 --token ${NODE_TOKEN}
Or as a `K3S_TOKEN` environment variable using the install script:
curl -sfL https://get.k3s.io | K3S_URL=https://myserver:6443 K3S_TOKEN=XXX sh - curl -sfL https://get.k3s.io | K3S_URL=https://myserver:6443 K3S_TOKEN=XXX sh -
When running with openrc logs will be created at `/var/log/k3s-agent.log`, or with systemd in `/var/log/syslog` and viewed using `journalctl -u k3s-agent`. When using the install script openrc logs will be created at `/var/log/k3s-agent.log`, or with systemd in `/var/log/syslog` and viewed using `journalctl -u k3s-agent`.
Or running k3s manually with the token as `NODE_TOKEN`:
k3s agent --server https://myserver:6443 --token ${NODE_TOKEN}
SystemD SystemD
------- -------