gbless 发表于 2018-1-4 11:16:04

Docker集群管理工具

1)首先部署nginx pod 和复制器---------------------------------------------------------------------  

  
# docker images

  
REPOSITORY          TAG               IMAGE>  
docker.io/nginx   latest            3448f27c273f      8 days ago          109.4 MB
  

  
通过下面命令发现apiVersion版本是v1
  
# curl -s -L http://182.48.115.237:8080/api/v1beta1/version | python -mjson.tool
  
{
  
"apiVersion": "v1",
  
.......
  
}
  

  
开始创建pod单元
  
# mkdir -p /home/kubermange && cd /home/kubermange
  
# vim nginx-rc.yaml
  
apiVersion: v1
  
kind: ReplicationController
  
metadata:
  
name: nginx-controller
  
spec:
  
replicas: 2                              #即2个备份
  
selector:
  
name: nginx
  
template:
  
metadata:
  
labels:
  
name: nginx
  
spec:
  
containers:
  
- name: nginx
  
image: docker.io/nginx
  
ports:
  
- containerPort: 80
  
# kubectl -s http://182.48.115.237:8080 create -f nginx-rc.yaml
  
replicationcontroller "nginx-controller" created
  

  
由于kubernetes要去gcr.io下载gcr.io/google_containers/pause镜像,然后下载nginx镜像,所以所创建的Pod需要等待一些时间才能处于running状态。
  
然后查看pods清单
  
# kubectl -s http://k8s-master:8080 get pods
  
NAME                     READY   STATUS            RESTARTS   AGE
  
nginx-controller-f0j9c   0/1       ContainerCreating   0          1m
  
nginx-controller-v219k   0/1       ContainerCreating   0          1m
  

  
可以使用describe 命令查看pod所分到的节点:
  
# kubectl -s http://182.48.115.237:8080 describe pod nginx-controller-f0j9c
  
Name:       nginx-controller-f0j9c
  
Namespace:default
  
Node:       k8s-node-1/182.48.115.238
  
.......
  

  
同理,查看另一个pod
  
# kubectl -s http://182.48.115.237:8080 describe pod nginx-controller-v219k
  
Name:       nginx-controller-v219k
  
Namespace:default
  
Node:       k8s-node-2/182.48.115.239
  
.......
  

  
由上可以看出,这个复制器启动了两个Pod,分别运行在182.48.115.238和182.48.115.239这两个节点上了。到这两个节点上查看,发现已经有nginx应用容器创建了。
  

  
2)部署节点内部可访问的nginx service------------------------------------------------------------------------
  
Service的type有ClusterIP和NodePort之分,缺省是ClusterIP,这种类型的Service只能在集群内部访问。配置文件如下:
  
# vim nginx-service-clusterip.yaml
  
apiVersion: v1
  
kind: Service
  
metadata:
  
name: nginx-service-clusterip
  
spec:
  
ports:
  
- port: 8001
  
targetPort: 80
  
protocol: TCP
  
selector:
  
name: nginx
  

  

  
然后执行下面的命令创建service:
  
# kubectl -s http://182.48.115.237:8080 create -f ./nginx-service-clusterip.yaml
  
service "nginx-service-clusterip" created
  
# kubectl -s http://182.48.115.237:8080 get service
  
NAME                      CLUSTER-IP       EXTERNAL-IP   PORT(S)    AGE
  
kubernetes                10.254.0.1       <none>      443/TCP    2h
  
nginx-service-clusterip   10.254.163.249   <none>      8001/TCP   24s
  

  
验证service的可访问性(访问节点):
  
上面的输出告诉我们这个Service的Cluster IP是10.254.163.249,端口是8001。那么我们就来验证这个PortalNet IP的工作情况:
  
ssh登录到节点机上验证(可以提前做ssh无密码登录的信任关系,当然也可以不做,这样验证时要手动输入登录密码)
  
# ssh 182.48.115.238 curl -s 10.254.163.249:8001            //或者直接到节点机上执行"curl -s 10.254.163.249:8001"
  
The authenticity of host '182.48.115.238 (182.48.115.238)' can't be established.
  
ECDSA key fingerprint is 4c:24:35:e0:35:00:86:05:94:a2:9e:f9:22:b0:90:b7.
  
Are you sure you want to continue connecting (yes/no)? yes
  
Warning: Permanently added '182.48.115.238' (ECDSA) to the list of known hosts.
  
root@182.48.115.238's password:
  
<!DOCTYPE html>
  
<html>
  
<head>
  
<title>Welcome to nginx!</title>
  
<style>
  
body {
  
width: 35em;
  
margin: 0 auto;
  
font-family: Tahoma, Verdana, Arial, sans-serif;
  
}
  
</style>
  
</head>
  
<body>
  
<h1>Welcome to nginx!</h1>
  
<p>If you see this page, the nginx web server is successfully installed and
  
working. Further configuration is required.</p>
  

  
<p>For online documentation and support please refer to
  
<a href="http://nginx.org/">nginx.org</a>.<br/>
  
Commercial support is available at
  
<a href="http://nginx.com/">nginx.com</a>.</p>
  

  
<p><em>Thank you for using nginx.</em></p>
  
</body>
  
</html>
  

  
同理验证到另外一个节点机上的service的可访问性也是ok的
  
# ssh 182.48.115.239 curl -s 10.254.163.249:8001
  

  
由此可见,从前面部署复制器的部分可以知道nginx Pod运行在182.48.115.238和182.48.115.239这两个节点上。
  
从这两个节点上访问我们的服务来体现Service Cluster IP在所有集群节点的可到达性。
  

  
3)部署外部可访问的nginx service-------------------------------------------------------------------
  
下面我们创建NodePort类型的Service,这种类型的Service在集群外部是可以访问。下表是本文用的配置文件:
  
# vim nginx-service-nodeport.yaml
  
apiVersion: v1
  
kind: Service
  
metadata:
  
name: nginx-service-nodeport
  
spec:
  
ports:
  
- port: 8000
  
targetPort: 80
  
protocol: TCP
  
type: NodePort
  
selector:
  
name: nginx
  

  

  
执行下面的命令创建service:
  
# kubectl -s http://182.48.115.237:8080 create -f ./nginx-service-nodeport.yaml
  
service "nginx-service-nodeport" created
  
# kubectl -s http://182.48.115.237:8080 get service
  
NAME                      CLUSTER-IP       EXTERNAL-IP   PORT(S)          AGE
  
kubernetes                10.254.0.1       <none>      443/TCP          2h
  
nginx-service-clusterip   10.254.163.249   <none>      8001/TCP         13m
  
nginx-service-nodeport    10.254.146.68    <nodes>       8000:31298/TCP   22s
  

  
使用下面的命令获得这个service的节点级别的端口:
  
# kubectl -s http://182.48.115.237:8080 describe service nginx-service-nodeport 2>/dev/null | grep NodePort
  
Type:         NodePort
  
NodePort:       <unset> 31298/TCP
  

  
验证service的可访问性(访问节点):
  
上面的输出告诉我们这个Service的节点级别端口是31298。下面我们验证这个Service的工作情况:
  
# curl 182.48.115.238:31298
  
<!DOCTYPE html>
  
<html>
  
<head>
  
<title>Welcome to nginx!</title>
  
<style>
  
body {
  
width: 35em;
  
margin: 0 auto;
  
font-family: Tahoma, Verdana, Arial, sans-serif;
  
}
  
</style>
  
</head>
  
<body>
  
<h1>Welcome to nginx!</h1>
  
<p>If you see this page, the nginx web server is successfully installed and
  
working. Further configuration is required.</p>
  

  
<p>For online documentation and support please refer to
  
<a href="http://nginx.org/">nginx.org</a>.<br/>
  
Commercial support is available at
  
<a href="http://nginx.com/">nginx.com</a>.</p>
  

  
<p><em>Thank you for using nginx.</em></p>
  
</body>
  
</html>
  

  
同理验证到另外一个节点机上的service的可访问性也是ok的
  
# curl 182.48.115.239:31298
  

  
----------------------------------------------------------
  
登录另外两个节点机上,发现已经创建了nginx应用容器
  
# docker ps

  
CONTAINER>  
620d9171a42c      docker.io/nginx                                              "nginx -g 'daemon off"   19 minutes ago      Up 19 minutes                           k8s_nginx.3d610115_nginx-controller-f0j9c_default_eaa0497b-3be5-11e7-a8a1-52540030ba6d_a6cde2e2
  
01facbbbe7cb      registry.access.redhat.com/rhel7/pod-infrastructure:latest   "/pod"                   19 minutes ago      Up 19 minutes                           k8s_POD.a8590b41_nginx-controller-f0j9c_default_eaa0497b-3be5-11e7-a8a1-52540030ba6d_d2dd947d
  

  
# docker ps

  
CONTAINER>  
308749352e55      docker.io/nginx                                              "nginx -g 'daemon off"   30 minutes ago      Up 30 minutes                           k8s_nginx.3d610115_nginx-controller-v219k_default_eaa02644-3be5-11e7-a8a1-52540030ba6d_7d54d433
  
cde94e406f9a      registry.access.redhat.com/rhel7/pod-infrastructure:latest   "/pod"                   30 minutes ago      Up 30 minutes
页: [1]
查看完整版本: Docker集群管理工具