Skip to content

Commit f518516

Browse files
committed
kubernetes 1.9 annotation
1 parent f124e11 commit f518516

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

practice/master-installation.md

+4
Original file line numberDiff line numberDiff line change
@@ -169,6 +169,10 @@ KUBE_API_ARGS="--authorization-mode=RBAC --runtime-config=rbac.authorization.k8s
169169
+ 缺省情况下 kubernetes 对象保存在 etcd `/registry` 路径下,可以通过 `--etcd-prefix` 参数进行调整;
170170
+ 如果需要开通http的无认证的接口,则可以增加以下两个参数:`--insecure-port=8080 --insecure-bind-address=127.0.0.1`。注意,生产上不要绑定到非127.0.0.1的地址上
171171

172+
**Kubernetes 1.9**
173+
174+
对于Kubernetes1.9集群,需要注意配置`KUBE_API_ARGS`环境变量中的`--authorization-mode=Node,RBAC`,增加对`Node`授权的模式,否则将无法注册node。
175+
172176
完整 unit 见 [kube-apiserver.service](../systemd/kube-apiserver.service)
173177

174178
**启动kube-apiserver**

0 commit comments

Comments
 (0)