【问题标题】:How to control which cluster kubectl talks to?如何控制 kubectl 与哪个集群通信?
【发布时间】:2023-03-08 22:38:01
【问题描述】:

我正在使用 kubectl 来控制本地 microk8s 安装。我配置了一个本地 Google 云 shell 连接,以避免通过 GKE 仪表板对可用的机器进行荒谬的配置。

现在,kubectl 命令似乎在 microk8s 和 GKE 上随机执行。我不仅要解决这个问题,还要在未来禁止这种情况。

kubectl 可以引用不同环境的可能性显然是建立在kubectl CLI 的概念中的一个可怕的想法,它无法指定远程集群。它可能导致生产系统发生意外更改。即使是铁杆 12 因素的布道者也会安装一个本地集群进行开发。

【问题讨论】:

    标签: kubernetes google-kubernetes-engine kubectl microk8s


    【解决方案1】:

    kubectl config use-context 命令可用于修改 kubectl 与谁对话。

    使用配置文件配置对多个集群的访问。在一个或多个配置文件中定义好您的集群、用户和上下文后,您可以使用 . configure-access-multiple-clusters/

    【讨论】:

    • 使用kubectl config get-contexts列出已配置的集群
    • 检查k,如果您正在寻找一种简写方式来切换集群上下文,如下所述:stackoverflow.com/a/57860864/544463
    【解决方案2】:

    您可以向您的kubectl 命令提供/添加--context--namespace 选项,以针对任何集群运行kubectl。如果您同时来回处理多个集群,这很方便。

    kubectl --cluster=my_cluster --namespace=my_namespace get pods
    

    注意:请为您的环境更改集群和命名空间名称。

    这里有更多 kubectl 选项:

    ~/git/kubernetes (master) $ kubectl options
    The following options can be passed to any command:
    
      --alsologtostderr=false: log to standard error as well as files
      --as='': Username to impersonate for the operation
      --as-group=[]: Group to impersonate for the operation, this flag can be repeated to specify multiple groups.
      --cache-dir='/Users/robertrt/.kube/http-cache': Default HTTP cache directory
      --certificate-authority='': Path to a cert file for the certificate authority
      --client-certificate='': Path to a client certificate file for TLS
      --client-key='': Path to a client key file for TLS
      --cluster='': The name of the kubeconfig cluster to use
      --context='': The name of the kubeconfig context to use
      --insecure-skip-tls-verify=false: If true, the server's certificate will not be checked for validity. This will make your HTTPS connections insecure
      --kubeconfig='': Path to the kubeconfig file to use for CLI requests.
      --log-backtrace-at=:0: when logging hits line file:N, emit a stack trace
      --log-dir='': If non-empty, write log files in this directory
      --log-flush-frequency=5s: Maximum number of seconds between log flushes
      --logtostderr=true: log to standard error instead of files
      --match-server-version=false: Require server version to match client version
    -n, --namespace='': If present, the namespace scope for this CLI request
      --request-timeout='0': The length of time to wait before giving up on a single server request. Non-zero values should contain a corresponding time unit (e.g. 1s, 2m, 3h). A value of zero means don't timeout requests.
    -s, --server='': The address and port of the Kubernetes API server
      --stderrthreshold=2: logs at or above this threshold go to stderr
      --token='': Bearer token for authentication to the API server
      --user='': The name of the kubeconfig user to use
    -v, --v=0: log level for V logs
      --vmodule=: comma-separated list of pattern=N settings for file-filtered logging
    

    【讨论】:

      猜你喜欢
      • 2022-08-23
      • 2019-10-11
      • 1970-01-01
      • 2021-05-26
      • 2017-07-16
      • 1970-01-01
      • 2019-12-07
      • 2019-04-15
      • 2023-01-24
      相关资源
      最近更新 更多