최초 Kubeadm init 시 생성되는 키는 24시간 이후 만료되므로 24시간 이후 노드를 추가할 경우 키를 확인해야 한다.
Master node에서 수행한다.
[haedong@haedongg.net:~]$ kubeadm token list
TOKEN TTL EXPIRES USAGES DESCRIPTION EXTRA GROUPS
xlykgo.y11bat3qc6h1abcd 2h 2021-11-16T04:25:15Z authentication,signing The default bootstrap token generated by 'kubeadm init'. system:bootstrappers:kubeadm:default-node-token
[haedong@haedongg.net:~]$ openssl x509 -pubkey -in /etc/kubernetes/pki/ca.crt | openssl rsa -pubin -outform der 2>/dev/null | openssl dgst -sha256 -hex | sed 's/^.* //'
be6b12345cd4ae6e90c7e7bcdbf148ba5fea222c11e43064878c05afe7fb1a11
kubeadm token create
kubeadm token create --print-join-command
Worker 노드에서 수행한다.
[haedong@haedongg.net:~]$ kubeadm join --token xlykgo.y11bat3qc6h1abcd 192.17.192.1:6443 --discovery-token-ca-cert-hash sha256:be6b12345cd4ae6e90c7e7bcdbf148ba5fea222c11e43064878c05afe7fb1a11
[preflight] Running pre-flight checks
[preflight] Reading configuration from the cluster...
[preflight] FYI: You can look at this config file with 'kubectl -n kube-system get cm kubeadm-config -o yaml'
[kubelet-start] Writing kubelet configuration to file "/var/lib/kubelet/config.yaml"
[kubelet-start] Writing kubelet environment file with flags to file "/var/lib/kubelet/kubeadm-flags.env"
[kubelet-start] Starting the kubelet
[kubelet-start] Waiting for the kubelet to perform the TLS Bootstrap...
This node has joined the cluster:
* Certificate signing request was sent to apiserver and a response was received.
* The Kubelet was informed of the new secure connection details.
Run 'kubectl get nodes' on the control-plane to see this node join the cluster.