一 下载对应插件的yaml
kubernetes 第三方对应插件都在对应版本的这个目录下
https://github.com/kubernetes/kubernetes/tree/master/cluster/addons
CoreDNS给出了标准的deployment配置, coredns.yaml.sed
vim coredns.yaml.sed
# Warning: This is a file generated from the base underscore template file: coredns.yaml.base
apiVersion: v1
kind: ServiceAccount
metadata:
name: coredns
namespace: kube-system
labels:
kubernetes.io/cluster-service: "true"
addonmanager.kubernetes.io/mode: Reconcile
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
kubernetes.io/bootstrapping: rbac-defaults
addonmanager.kubernetes.io/mode: Reconcile
name: system:coredns
rules:
- apiGroups:
- ""
resources:
- endpoints
- services
- pods
- namespaces
verbs:
- list
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
annotations:
rbac.authorization.kubernetes.io/autoupdate: "true"
labels:
kubernetes.io/bootstrapping: rbac-defaults
addonmanager.kubernetes.io/mode: EnsureExists
name: system:coredns
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: system:coredns
subjects:
- kind: ServiceAccount
name: coredns
namespace: kube-system
---
apiVersion: v1
kind: ConfigMap
metadata:
name: coredns
namespace: kube-system
labels:
addonmanager.kubernetes.io/mode: EnsureExists
data:
Corefile: |
.:53 {
errors
health
kubernetes cluster.local 10.254.0.0/16 { #着个前面domian变量需更改 和IP段
pods insecure
upstream
fallthrough in-addr.arpa ip6.arpa
}
prometheus :9153
proxy . /etc/resolv.conf
cache 30
}
---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
name: coredns
namespace: kube-system
labels:
k8s-app: coredns
kubernetes.io/cluster-service: "true"
addonmanager.kubernetes.io/mode: Reconcile
kubernetes.io/name: "CoreDNS"
spec:
replicas: 2
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 1
selector:
matchLabels:
k8s-app: coredns
template:
metadata:
labels:
k8s-app: coredns
spec:
serviceAccountName: coredns
tolerations:
- key: node-role.kubernetes.io/master
effect: NoSchedule
- key: "CriticalAddonsOnly"
operator: "Exists"
containers:
- name: coredns
image: coredns/coredns:1.0.6
imagePullPolicy: IfNotPresent
resources:
limits:
memory: 170Mi
requests:
cpu: 100m
memory: 70Mi
args: [ "-conf", "/etc/coredns/Corefile" ]
volumeMounts:
- name: config-volume
mountPath: /etc/coredns
ports:
- containerPort: 53
name: dns
protocol: UDP
- containerPort: 53
name: dns-tcp
protocol: TCP
livenessProbe:
httpGet:
path: /health
port: 8080
scheme: HTTP
initialDelaySeconds: 60
timeoutSeconds: 5
successThreshold: 1
failureThreshold: 5
dnsPolicy: Default
volumes:
- name: config-volume
configMap:
name: coredns
items:
- key: Corefile
path: Corefile
---
apiVersion: v1
kind: Service
metadata:
name: coredns
namespace: kube-system
labels:
k8s-app: coredns
kubernetes.io/cluster-service: "true"
addonmanager.kubernetes.io/mode: Reconcile
kubernetes.io/name: "CoreDNS"
spec:
selector:
k8s-app: coredns
clusterIP: 10.254.0.2 #clusterIP需要更改
ports:
- name: dns
port: 53
protocol: UDP
- name: dns-tcp
port: 53
protocol: TCP
配置文件中
kubernetes $DNS_DOMAIN in-addr.arpa ip6.arpa { 更改为:
kubernetes cluster.local 10.254.0.0/16 { #着个前面domian变量需更改 和IP段
clusterIP: $DNS_SERVER_IP 更改为:
clusterIP: 10.254.0.2
#这个地方需要改成和kubelet中配置的一样--cluster-dns=10.254.0.2
2 使用kubectl创建下
kubectl create -f coredns.yaml.sed
3 验证
kubectl get all --all-namespaces
NAMESPACE NAME READY STATUS RESTARTS AGE
kube-system pod/coredns-77c989547b-4jjn8 1/1 Running 0 27m
kube-system pod/coredns-77c989547b-p299x 1/1 Running 0 27m
NAMESPACE NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
default service/kubernetes ClusterIP 10.254.0.1 <none> 443/TCP 3d
kube-system service/coredns ClusterIP 10.254.0.2 <none> 53/UDP,53/TCP 27m
NAMESPACE NAME DESIRED CURRENT READY UP-TO-DATE AVAILABLE NODE SELECTOR AG
E
NAMESPACE NAME DESIRED CURRENT UP-TO-DATE AVAILABLE AGE
kube-system deployment.apps/coredns 2 2 2 2 27m
NAMESPACE NAME DESIRED CURRENT READY AGE
kube-system replicaset.apps/coredns-77c989547b 2 2 2 27m
4 dns解析验证
创建busybox.yaml
vim busybox.yaml
apiVersion: v1
kind: Pod
metadata:
name: busybox
namespace: default
spec:
containers:
- name: busybox
image: busybox #新的busybox有问题、使用下面的镜像
image: docker.io/azukiapp/dig
command:
- sleep
- "3600"
imagePullPolicy: IfNotPresent
restartPolicy: Always
创建service
kubectl create -f busybox.yaml
验证DNS解析
kubectl exec -it busybox -- nslookup kubernetes.default
Server: 10.254.0.2
Address 1: 10.254.0.2 coredns.kube-system.svc.cluster.local
Name: kubernetes.default
Address 1: 10.254.0.1 kubernetes.default.svc.cluster.local
kubectl exec -it busybox -- nslookup kubernetes-dashboard.kube-system 点后面指定kubernetes的namespace
Server: 10.254.0.2
Address 1: 10.254.0.2 coredns.kube-system.svc.cluster.local
Name: kubernetes-dashboard.kube-system
Address 1: 10.254.246.240 kubernetes-dashboard.kube-system.svc.cluster.local
coredns 配置自己内部dns
增加:upstream和下面域的配置文件
配置文件更改如下:
Corefile: |
.:53 {
errors
health
ready
kubernetes cluster.local 10.254.0.0/16 in-addr.arpa ip6.arpa {
pods insecure
upstream
fallthrough in-addr.arpa ip6.arpa
ttl 30
}
prometheus :9153
forward . /etc/resolv.conf
cache 30
loop
reload
loadbalance
}
docker.hc360.com:53 {
errors
\#kubernetes $DNS\_DOMAIN in-addr.arpa ip6.arpa {
forward . 10.7.3.22
cache 30
}
hc360.com:53 {
errors
\#kubernetes $DNS\_DOMAIN in-addr.arpa ip6.arpa {
forward . 10.7.3.22
cache 30
}