直接上yaml文件
#etcd-cluster-cm.yaml
apiVersion: v1
kind: ConfigMap
metadata:
name: etcd-cm
namespace: merry
data:
#3.5以下版本即使设置该环境变量也不会生效,需要手动处理用户权限
ETCD_ROOT_PASSWORD: "admin123"
#etcd-cluster-deploy.yaml
apiVersion: apps/v1
kind: StatefulSet
metadata:
labels:
app: etcd
name: etcd
namespace: merry
spec:
replicas: 3
selector:
matchLabels:
app: etcd
serviceName: etcd-headless
template:
metadata:
labels:
app: etcd
name: etcd
spec:
containers:
- env:
- name: MY_POD_NAME #当前pod名
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: CLUSTER_NAMESPACE #名称空间
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: SERVICE_NAME #内部通信的无头服务名称
value: "etcd-headless"
#arm架构下部署需要设置该环境变量
#- name: ETCD_UNSUPPORTED_ARCH
# value: arm64
- name: TZ
value: Asia/Shanghai
#- name: ETCD_ROOT_PASSWORD
# value: "admin123"
- name: INITIAL_CLUSTER #initial-cluster的值
value: "etcd-0=http://etcd-0.etcd-headless.merry:2380,etcd-1=http://etcd-1.etcd-headless.merry:2380,etcd-2=http://etcd-2.etcd-headless.merry:2380"
image: etcd:3.4.18
imagePullPolicy: Always
name: etcd
envFrom:
- configMapRef:
name: etcd-cm
ports:
- containerPort: 2380
name: peer
protocol: TCP
- containerPort: 2379
name: client
protocol: TCP
resources:
requests:
memory: "128Mi"
cpu: "100m"
limits:
memory: "4Gi"
cpu: "1000m"
volumeMounts:
- mountPath: /var/lib/etcd
name: etcd-data
affinity:
podAntiAffinity:
#绝对不要在一个node
requiredDuringSchedulingIgnoredDuringExecution: # 硬策略
- topologyKey: "kubernetes.io/hostname"
labelSelector:
matchExpressions:
- key: "app"
operator: In
values:
- etcd
updateStrategy:
type: OnDelete
volumeClaimTemplates:
- metadata:
name: etcd-data
spec:
accessModes: [ "ReadWriteMany" ]
storageClassName: managed-nfs-storage
resources:
requests:
storage: 100Gi
#etcd-cluster-svc.yaml
apiVersion: v1
kind: Service
metadata:
name: etcd-headless
namespace: merry
labels:
app: etcd
spec:
ports:
- port: 2380
name: etcd-server
- port: 2379
name: etcd-client
clusterIP: None
selector:
app: etcd
publishNotReadyAddresses: true
---
apiVersion: v1
kind: Service
metadata:
labels:
app: etcd
name: etcd-svc
namespace: merry
spec:
ports:
- name: etcd-cluster
port: 2379
targetPort: 2379
#nodePort: 12379
- name: port2380
port: 2380
targetPort: 2380
#nodePort: 12380
selector:
app: etcd
sessionAffinity: None
type: NodePort
#etcd-cluster-pdb.yaml
apiVersion: policy/v1beta1
kind: PodDisruptionBudget
metadata:
name: etcd-pdb
namespace: merry
labels:
pdb: etcd
spec:
minAvailable: 2
selector:
matchLabels:
app: etcd
Dockerfile文件内容:
FROM centos:centos7.9.2009
USER root
ADD etcd-3.4.18/etcd* /usr/bin/
COPY etcd.sh /
RUN chmod +x /etcd.sh && yum makecache fast && yum install -y vim curl && yum clean all
EXPOSE 2379 2380
CMD ["/etcd.sh"]
#脚本etcd.sh
#!/bin/bash
/usr/bin/etcd --data-dir=/var/lib/etcd --name=${MY_POD_NAME} --listen-peer-urls=http://0.0.0.0:2380 --listen-client-urls=http://0.0.0.0:2379 --advertise-client-urls=http://${MY_POD_NAME}.${SERVICE_NAME}.${CLUSTER_NAMESPACE}:2379 --initial-advertise-peer-urls=http://${MY_POD_NAME}.${SERVICE_NAME}.${CLUSTER_NAMESPACE}:2380 --initial-cluster-state='new' --initial-cluster-token='etcd-cluster-token' --initial-cluster=${INITIAL_CLUSTER}
#节点健康检查
etcdctl --user=root:'admin123' --write-out=table --endpoints=http://etcd-0.etcd-headless.merry:2379,http://etcd-1.etcd-headless.merry:2379,http://etcd-2.etcd-headless.merry:2379 endpoint health
#查看哪个节点为leader
etcdctl -w table endpoint status --cluster #无加密方式
etcdctl --user=root:'admin123' --write-out=table --endpoints=http://etcd-0.etcd-headless.merry:2379,http://etcd-1.etcd-headless.merry:2379,http://etcd-2.etcd-headless.merry:2379 endpoint status --cluster #加密方式
#一条命令开启认证
etcdctl user add 'root:admin123' && etcdctl user grant-role root root && etcdctl auth enable && echo "成功开启etcd认证"
# 构建多架构的脚本
#!/bin/bash
#构建etcd多架构镜像脚本
#etcd版本号
etcd_version=3.4.18
#支持多架构
docker run --privileged --rm harbor.codemiracle.com.cn/baseapp/binfmt:latest --install all
#创建builder
docker buildx create --use --name=mybuilder-cn-etcd --driver docker-container --driver-opt image=harbor.codemiracle.com.cn/baseapp/buildkit:master
#构建x86架构下的镜像
mkdir etcd-$etcd_version
tar -zxvf ../etcd-v$etcd_version-linux-amd64.tar.gz -C etcd-$etcd_version
docker buildx build --platform=linux/amd64 -t harbor.codemiracle.com.cn/baseapp/etcd:$etcd_version-amd64 -f Dockerfile . --push
rm -rf etcd-$etcd_version/*
#构建arm架构下的镜像
tar -zxvf ../etcd-v$etcd_version-linux-amd64.tar.gz -C etcd-$etcd_version
docker buildx build --platform=linux/arm64 -t harbor.codemiracle.com.cn/baseapp/etcd:$etcd_version-arm64 -f Dockerfile . --push
#聚合镜像
docker manifest create harbor.codemiracle.com.cn/baseapp/etcd:$etcd_version harbor.codemiracle.com.cn/baseapp/etcd:$etcd_version-amd64 harbor.codemiracle.com.cn/baseapp/etcd:$etcd_version-arm64
docker manifest push harbor.codemiracle.com.cn/baseapp/etcd:$etcd_version
docker buildx rm mybuilder-cn-etcd
二进制文件包下载地址:
二进制包etcd-v3.4.18-linux-amd64.tar.gz-Linux文档类资源-优快云下载
制作好的docker镜像下载:
docker镜像etcd-3.4.18-Linux文档类资源-优快云下载
arm架构下离线镜像包: