1.?????rancher、kubernetes-dashboard等應(yīng)用需要通過https方式訪問,所以此次部署將開啟traefik對https的支持。
寧津網(wǎng)站制作公司哪家好,找創(chuàng)新互聯(lián)!從網(wǎng)頁設(shè)計、網(wǎng)站建設(shè)、微信開發(fā)、APP開發(fā)、響應(yīng)式網(wǎng)站建設(shè)等網(wǎng)站項目制作,到程序開發(fā),運營維護。創(chuàng)新互聯(lián)2013年開創(chuàng)至今到現(xiàn)在10年的時間,我們擁有了豐富的建站經(jīng)驗和運維經(jīng)驗,來保證我們的工作的順利進行。專注于網(wǎng)站建設(shè)就選創(chuàng)新互聯(lián)。2.?????基于之前的rancher HA是部署在cattle-system命名空間下的,所以此次同樣將traefik部署在cattle-system命名空間下,并且使用同樣的tls證書。
RBAC清單文件traefik-rbac.yaml如下:
--- apiVersion:?v1 kind:?ServiceAccount metadata: ??name:?traefik-ingress-controller ??namespace:?cattle-system --- kind:?ClusterRole apiVersion:?rbac.authorization.k8s.io/v1 metadata: ??name:?traefik-ingress-controller rules: ??-?apiGroups: ??????-?"" ????resources: ??????-?services ??????-?endpoints ??????-?secrets ????verbs: ??????-?get ??????-?list ??????-?watch ??-?apiGroups: ??????-?extensions ????resources: ??????-?ingresses ????verbs: ??????-?get ??????-?list ??????-?watch --- kind:?ClusterRoleBinding apiVersion:?rbac.authorization.k8s.io/v1 metadata: ??name:?traefik-ingress-controller roleRef: ??apiGroup:?rbac.authorization.k8s.io ??kind:?ClusterRole ??name:?traefik-ingress-controller subjects: -?kind:?ServiceAccount ??name:?traefik-ingress-controller ??namespace:?cattle-system?應(yīng)用清單文件
[root@k8s-master03?traefik]#?kubectl?apply?-f?traefik-rbac.yaml serviceaccount/traefik-ingress-controller?created clusterrole.rbac.authorization.k8s.io/traefik-ingress-controller?created clusterrolebinding.rbac.authorization.k8s.io/traefik-ingress-controller?createddamonset清單文件traefik-ds.yaml如下:
--- kind:?ConfigMap apiVersion:?v1 metadata: ??name:?traefik-conf ??namespace:?cattle-system data: ??traefik.toml:?| ????insecureSkipVerify?=?true ????defaultEntryPoints?=?["http","https"] ????[entryPoints] ??????[entryPoints.http] ??????address?=?":80" ??????[entryPoints.https] ??????address?=?":443" ????????[entryPoints.https.tls] ??????????[[entryPoints.https.tls.certificates]] ??????????CertFile?=?"/ssl/tls.crt" ??????????KeyFile?=?"/ssl/tls.key" --- kind:?DaemonSet apiVersion:?extensions/v1beta1 metadata: ??name:?traefik-ingress-controller ??namespace:?cattle-system ??labels: ????k8s-app:?traefik-ingress-lb spec: ??template: ????metadata: ??????labels: ????????k8s-app:?traefik-ingress-lb ????????name:?traefik-ingress-lb ????spec: ??????serviceAccountName:?traefik-ingress-controller ??????terminationGracePeriodSeconds:?60 ??????hostNetwork:?true ??????volumes: ??????-?name:?ssl ????????secret: ??????????secretName:?tls-rancher-ingress ??????-?name:?config ????????configMap: ??????????name:?traefik-conf ??????containers: ??????-?image:?traefik ????????name:?traefik-ingress-lb ????????ports: ????????-?name:?http ??????????containerPort:?80 ??????????hostPort:?80 ????????-?name:?admin ??????????containerPort:?8080 ????????securityContext: ??????????privileged:?true ????????args: ????????-?--configfile=/config/traefik.toml ????????-?-d ????????-?--web ????????-?--kubernetes ????????volumeMounts: ????????-?mountPath:?"/ssl" ??????????name:?"ssl" ????????-?mountPath:?"/config" ??????????name:?"config" --- kind:?Service apiVersion:?v1 metadata: ??name:?traefik-ingress-service ??namespace:?cattle-system spec: ??selector: ????k8s-app:?traefik-ingress-lb ??ports: ????-?protocol:?TCP ??????port:?80 ??????name:?web ????-?protocol:?TCP ??????port:?8080 ??????name:?admin ????-?protocol:?TCP ??????port:?443 ??????name:?https ??#type:?NodePort應(yīng)用清單文件
[root@k8s-master03?traefik]#?kubectl?apply?-f?traefik-ds.yaml configmap/traefik-conf?created daemonset.extensions/traefik-ingress-controller?created service/traefik-ingress-service?createdingress清單文件traefik-ui.yaml如下:
apiVersion:?v1 kind:?Service metadata: ??name:?traefik-web-ui ??namespace:?cattle-system spec: ??selector: ????k8s-app:?traefik-ingress-lb ??ports: ??-?name:?web ????port:?80 ????targetPort:?8080 --- apiVersion:?extensions/v1beta1 kind:?Ingress metadata: ??name:?traefik-web-ui ??namespace:?cattle-system spec: ??rules: ??-?host:?traefik-ui.sumapay.com ????http: ??????paths: ??????-?path:?/ ????????backend: ??????????serviceName:?traefik-web-ui ??????????servicePort:?web應(yīng)用清單文件
[root@k8s-master03?traefik]#?kubectl?apply?-f?traefik-ui.yaml service/traefik-web-ui?created ingress.extensions/traefik-web-ui?created將域名映射到外部負載均衡IP后,就可以通過域名訪問traefik UI和rancher HA服務(wù)了。
另外有需要云服務(wù)器可以了解下創(chuàng)新互聯(lián)cdcxhl.cn,海內(nèi)外云服務(wù)器15元起步,三天無理由+7*72小時售后在線,公司持有idc許可證,提供“云服務(wù)器、裸金屬服務(wù)器、高防服務(wù)器、香港服務(wù)器、美國服務(wù)器、虛擬主機、免備案服務(wù)器”等云主機租用服務(wù)以及企業(yè)上云的綜合解決方案,具有“安全穩(wěn)定、簡單易用、服務(wù)可用性高、性價比高”等特點與優(yōu)勢,專為企業(yè)上云打造定制,能夠滿足用戶豐富、多元化的應(yīng)用場景需求。