Skip to content

Multi-Node Setup

Multi-Node Cluster Setup

Deploying a multi-node Kubernetes cluster requires careful coordination between master (control plane) and worker nodes, along with secure TLS communication and a reliable etcd backend. This section guides you through the process using kubeadm, a tool designed for easy Kubernetes installation.


Prerequisites

Before starting, ensure all nodes meet these requirements: - Operating System: Ubuntu 22.04 or later (or compatible Linux distro). - Network: All nodes must have a stable network connection and can communicate with each other. - Static IPs: Assign static IP addresses to each node for consistent networking. - Tools: Install kubeadm, kubectl, and kubelet on all nodes:

sudo apt update && sudo apt install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl


Node Preparation

  1. Disable Swap:

    sudo swapoff -a
    
    Ensure swap is disabled in /etc/fstab to prevent unexpected behavior.

  2. Set Hostnames: Assign unique hostnames to each node (e.g., master, worker1, worker2).

  3. Configure Firewall: Allow necessary ports (e.g., 6443 for API server, 10250 for kubelet):

    sudo ufw allow 6443/tcp
    sudo ufw allow 10250/tcp
    sudo ufw enable
    


Setting Up etcd

For a production cluster, etcd should be deployed as a multi-node cluster for redundancy and high availability. Here’s how to set it up manually:

  1. Install etcd on each etcd node:

    sudo apt install -y etcd
    
    Configure etcd with a static peer list (e.g., in /etc/default/etcd):
    ETCD_INITIAL_CLUSTER="etcd0=http://<etcd0-ip>:2380,etcd1=http://<etcd1-ip>:2380,etcd2=http://<etcd2-ip>:2380"
    ETCD_INITIAL_ADVERTISE_PEER_URLS="http://<etcd0-ip>:2380"
    ETCD_LISTEN_PEER_URLS="http://0.0.0.0:2380"
    ETCD_LISTEN_CLIENT_URLS="http://0.0.0.0:2379"
    

  2. Start and Enable etcd:

    sudo systemctl enable --now etcd
    

  3. Verify etcd Cluster Health: Use etcdctl to check the etcd cluster:

    etcdctl --endpoints=<etcd0-ip>:2379,etcd1-ip:2379,etcd2-ip:2379 endpoint health
    


Initializing the Master Node

  1. Initialize the Control Plane: Use kubeadm init to set up the master node. Specify the etcd configuration if using a custom setup:
    sudo kubeadm init --control-plane-endpoint=<master-ip>:6443 --upload-certs
    
  2. --control-plane-endpoint: Public IP or DNS name of the master node.
  3. --upload-certs: Uploads certificates for easier worker node joins.

  4. Configure kubeconfig: After initialization, copy the kubeconfig file to your home directory:

    sudo cp /etc/kubernetes/admin.conf $HOME/
    sudo chown $(id -u):$(id -g) $HOME/admin.conf
    export KUBECONFIG=$HOME/admin.conf
    


Joining Worker Nodes

  1. Generate Join Token: Run the following on the master node to generate a token for worker nodes:

    sudo kubeadm token create --print-join-command
    
    This outputs a command like:
    sudo kubeadm join <master-ip>:6443 --token <token> --discovery-token-ca-cert-hash sha256:<hash>
    

  2. Join Worker Nodes: Execute the generated command on each worker node:

    sudo kubeadm join <master-ip>:6443 --token <token> --discovery-token-ca-cert-hash sha256:<hash>
    


Verifying the Cluster

  1. Check Node Status:

    kubectl get nodes
    
    All nodes should show Ready.

  2. Verify etcd Health: Use etcdctl to check the etcd cluster:

    etcdctl --endpoints=<etcd0-ip>:2379,etcd1-ip:2379,etcd2-ip:2379 endpoint health
    

  3. Test TLS Connectivity: Ensure the API server is reachable securely:

    curl -k https://<master-ip>:6443/api/v1/namespaces
    


Key takeaways

  • Multi-node clusters require careful network configuration and role separation between master and worker nodes.
  • etcd must be securely configured and either integrated with Kubernetes or run as a standalone cluster.
  • TLS is automatically handled by kubeadm, but manual configuration is possible for advanced scenarios.
  • Verification steps ensure the cluster is functional and secure.