Kubernetes Dashboard 的安装、配置和使用

一、实验环境版本信息

1. 操作系统的版本信息

CentOS Linux release 7.6.1810 (Core)

2. 各组件的版本信息

kubernetes cluster v1.17.0,推荐使用kubeadm v1.17.0 进行试验

etcd v3.4.3
kube-apiserver v1.17.0
kube-controller-manager v1.17.0
kube-scheduler v1.17.0
kubectl v1.17.0

docker 18.09.9
kubelet v1.17.0
calico v3.11.1

kubernetes dashborad,使用容器化的方式部署

kubernetes dashboard v2.0.0-rc5

二、准备Docker镜像与Kubernetes YAML部署文件

1. 准备相关的 Docker 镜像

1
2
3
docker pull kubernetesui/dashboard:v2.0.0-rc5
docker pull kubernetesui/metrics-scraper:v1.0.3
docker pull registry.cn-hangzhou.aliyuncs.com/google_containers/metrics-server-amd64:v0.3.6

2. 准备相关的 Kubernetes YAML 部署文件

1
2
3
# git clone https://github.com/kubernetes/dashboard.git
# cd dashboard/
# git checkout -b v2.0.0-rc5.tag v2.0.0-rc5

三、在 Kubernetes Cluster 上安装 Kubernetes Dashboard

1
2
## 接上一步,在 dashboard/ 目录下操作,直接使用 kubectl 创建资源即可
# kubectl create -f aio/deploy/recommended.yaml

四、安装 Kubernetes 监控组件 Metric Server

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
# git clone https://github.com/kubernetes-sigs/metrics-server.git
# cd metrics-server/
# git checkout -b v0.3.6.tag v0.3.6
# git branch
master
* v0.3.6.tag

# git diff deploy/1.8+/metrics-server-deployment.yaml
diff --git a/deploy/1.8+/metrics-server-deployment.yaml b/deploy/1.8+/metrics-server-deployment.yaml
index 2393e75..86f4219 100644
--- a/deploy/1.8+/metrics-server-deployment.yaml
+++ b/deploy/1.8+/metrics-server-deployment.yaml
@@ -29,8 +29,12 @@ spec:
emptyDir: {}
containers:
- name: metrics-server
- image: k8s.gcr.io/metrics-server-amd64:v0.3.6
- imagePullPolicy: Always
+ image: registry.cn-hangzhou.aliyuncs.com/google_containers/metrics-server-amd64:v0.3.6
+ imagePullPolicy: IfNotPresent
+ command:
+ - /metrics-server
+ - --kubelet-preferred-address-types=InternalIP
+ - --kubelet-insecure-tls
volumeMounts:
- name: tmp-dir
mountPath: /tmp
## 按照上述git对比出来的变化进行修改

# kubectl create -f deploy/1.8+/

# kubectl get pod -n kube-system -o wide
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES
。。。
metrics-server-c6774ddf4-nnktl 1/1 Running 0 30h 10.211.196.130 node01 <none> <none>
。。。

## 验证metric server的可用性
# kubectl get --raw "/apis/metrics.k8s.io/v1beta1/nodes" | jq .
{
"kind": "NodeMetricsList",
"apiVersion": "metrics.k8s.io/v1beta1",
"metadata": {
"selfLink": "/apis/metrics.k8s.io/v1beta1/nodes"
},
"items": [
{
"metadata": {
"name": "node02",
"selfLink": "/apis/metrics.k8s.io/v1beta1/nodes/node02",
"creationTimestamp": "2020-02-22T05:32:50Z"
},
"timestamp": "2020-02-22T05:32:13Z",
"window": "30s",
"usage": {
"cpu": "88057337n",
"memory": "822040Ki"
}
},
{
"metadata": {
"name": "master",
"selfLink": "/apis/metrics.k8s.io/v1beta1/nodes/master",
"creationTimestamp": "2020-02-22T05:32:50Z"
},
"timestamp": "2020-02-22T05:32:21Z",
"window": "30s",
"usage": {
"cpu": "184970966n",
"memory": "1045388Ki"
}
},
{
"metadata": {
"name": "node01",
"selfLink": "/apis/metrics.k8s.io/v1beta1/nodes/node01",
"creationTimestamp": "2020-02-22T05:32:50Z"
},
"timestamp": "2020-02-22T05:32:18Z",
"window": "30s",
"usage": {
"cpu": "92128619n",
"memory": "833480Ki"
}
}
]
}


# kubectl get --raw "/apis/metrics.k8s.io/v1beta1/pods" | jq .
{
"kind": "PodMetricsList",
"apiVersion": "metrics.k8s.io/v1beta1",
"metadata": {
"selfLink": "/apis/metrics.k8s.io/v1beta1/pods"
},
"items": [
{
"metadata": {
"name": "calico-node-vp2mk",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/calico-node-vp2mk",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:13Z",
"window": "30s",
"containers": [
{
"name": "calico-node",
"usage": {
"cpu": "23828482n",
"memory": "29852Ki"
}
}
]
},
{
"metadata": {
"name": "coredns-7f9c544f75-nbtt9",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/coredns-7f9c544f75-nbtt9",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:12Z",
"window": "30s",
"containers": [
{
"name": "coredns",
"usage": {
"cpu": "2739715n",
"memory": "8372Ki"
}
}
]
},
{
"metadata": {
"name": "kube-controller-manager-master",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/kube-controller-manager-master",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:22Z",
"window": "30s",
"containers": [
{
"name": "kube-controller-manager",
"usage": {
"cpu": "11899093n",
"memory": "61688Ki"
}
}
]
},
{
"metadata": {
"name": "etcd-master",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/etcd-master",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:15Z",
"window": "30s",
"containers": [
{
"name": "etcd",
"usage": {
"cpu": "15906661n",
"memory": "46120Ki"
}
}
]
},
{
"metadata": {
"name": "coredns-7f9c544f75-bk25k",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/coredns-7f9c544f75-bk25k",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:07Z",
"window": "30s",
"containers": [
{
"name": "coredns",
"usage": {
"cpu": "2311367n",
"memory": "11300Ki"
}
}
]
},
{
"metadata": {
"name": "dashboard-metrics-scraper-7b8b58dc8b-nnktl",
"namespace": "kubernetes-dashboard",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kubernetes-dashboard/pods/dashboard-metrics-scraper-7b8b58dc8b-nnktl",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:12Z",
"window": "30s",
"containers": [
{
"name": "dashboard-metrics-scraper",
"usage": {
"cpu": "487926n",
"memory": "3932Ki"
}
}
]
},
{
"metadata": {
"name": "kube-proxy-v6vtg",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/kube-proxy-v6vtg",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:11Z",
"window": "30s",
"containers": [
{
"name": "kube-proxy",
"usage": {
"cpu": "414352n",
"memory": "23932Ki"
}
}
]
},
{
"metadata": {
"name": "network-pz6st",
"namespace": "default",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/default/pods/network-pz6st",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:18Z",
"window": "30s",
"containers": [
{
"name": "network",
"usage": {
"cpu": "0",
"memory": "44Ki"
}
}
]
},
{
"metadata": {
"name": "kube-apiserver-master",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/kube-apiserver-master",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:17Z",
"window": "30s",
"containers": [
{
"name": "kube-apiserver",
"usage": {
"cpu": "35264598n",
"memory": "300208Ki"
}
}
]
},
{
"metadata": {
"name": "calico-kube-controllers-648f4868b8-844cd",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/calico-kube-controllers-648f4868b8-844cd",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:19Z",
"window": "30s",
"containers": [
{
"name": "calico-kube-controllers",
"usage": {
"cpu": "1185857n",
"memory": "8716Ki"
}
}
]
},
{
"metadata": {
"name": "metrics-server-c6774ddf4-f6lg2",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/metrics-server-c6774ddf4-f6lg2",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:17Z",
"window": "30s",
"containers": [
{
"name": "metrics-server",
"usage": {
"cpu": "1059092n",
"memory": "11748Ki"
}
}
]
},
{
"metadata": {
"name": "kube-scheduler-master",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/kube-scheduler-master",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:20Z",
"window": "30s",
"containers": [
{
"name": "kube-scheduler",
"usage": {
"cpu": "2369907n",
"memory": "24184Ki"
}
}
]
},
{
"metadata": {
"name": "calico-node-2qjtg",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/calico-node-2qjtg",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:21Z",
"window": "30s",
"containers": [
{
"name": "calico-node",
"usage": {
"cpu": "25966443n",
"memory": "25984Ki"
}
}
]
},
{
"metadata": {
"name": "kube-proxy-pwh6h",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/kube-proxy-pwh6h",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:15Z",
"window": "30s",
"containers": [
{
"name": "kube-proxy",
"usage": {
"cpu": "216986n",
"memory": "25156Ki"
}
}
]
},
{
"metadata": {
"name": "calico-node-gq9r9",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/calico-node-gq9r9",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:04Z",
"window": "30s",
"containers": [
{
"name": "calico-node",
"usage": {
"cpu": "25302709n",
"memory": "26760Ki"
}
}
]
},
{
"metadata": {
"name": "network-s5tjd",
"namespace": "default",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/default/pods/network-s5tjd",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:10Z",
"window": "30s",
"containers": [
{
"name": "network",
"usage": {
"cpu": "0",
"memory": "48Ki"
}
}
]
},
{
"metadata": {
"name": "kubernetes-dashboard-866f987876-5npr9",
"namespace": "kubernetes-dashboard",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kubernetes-dashboard/pods/kubernetes-dashboard-866f987876-5npr9",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:18Z",
"window": "30s",
"containers": [
{
"name": "kubernetes-dashboard",
"usage": {
"cpu": "281233n",
"memory": "9512Ki"
}
}
]
},
{
"metadata": {
"name": "kube-proxy-knt4j",
"namespace": "kube-system",
"selfLink": "/apis/metrics.k8s.io/v1beta1/namespaces/kube-system/pods/kube-proxy-knt4j",
"creationTimestamp": "2020-02-22T05:33:20Z"
},
"timestamp": "2020-02-22T05:32:05Z",
"window": "30s",
"containers": [
{
"name": "kube-proxy",
"usage": {
"cpu": "485574n",
"memory": "15496Ki"
}
}
]
}
]
}

五、配置以https的方式访问 Kubernetes Dashboard

  1. 决定了 Kubernetes Dashboard 以 https 的形式对外提供服务的关键参数

    1
    2
    3
    4
    5
    6
    7
    8
    9
    ## 以 https 对外提供服务时,Kubernetes Dashboard 默认是启用登录模式的
    ## 特别注意:该参数启用后,Kubernetes Dashboard 会监听 8443 端口对外提供 https 服务,并且不会监听 9090 端口提供 http 服务
    --auto-generate-certificates

    ## 设置 https 监听端口,默认值为 8443
    --port

    ## 设置 https 监听地址,默认值为 0.0.0.0
    --bind-address
  2. 决定了 Kubernetes Dashboard 能够启动成功的关键参数

    1
    2
    ## 证书相关的secret对象放在哪个namespace下,通常情况下与 Kubernetes Dashboard 的 pod 所在的 namespace 相同,默认值为 kube-system
    --namespace
  3. 如何访问 Kubernetes Dashboard 的登录页

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    ## 修改 service 类型为 NodePort 类型
    # kubectl edit service kubernetes-dashboard -n kubernetes-dashboard
    。。。。。。
    spec:
    clusterIP: 10.96.56.103
    externalTrafficPolicy: Cluster
    ports:
    - nodePort: 32027
    port: 443
    protocol: TCP
    targetPort: 8443
    selector:
    k8s-app: kubernetes-dashboard
    sessionAffinity: None
    type: NodePort
    。。。。。。

    ## 通过 https://<node-ip>:<node-port> 的形式访问 Kubernetes Dashboard 的登录页,例如 https://192.168.112.129:32027/

login_01

六、使用说明

  1. 创建访问用户并授权

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    mkdir -p access/
    cat <<EOF > access/01-serviceaccount.yaml
    apiVersion: v1
    kind: ServiceAccount
    metadata:
    name: admin-user
    namespace: kubernetes-dashboard
    EOF

    cat <<EOF > access/02-clusterrolebinding.yaml
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRoleBinding
    metadata:
    name: admin-user
    roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: ClusterRole
    name: cluster-admin
    subjects:
    - kind: ServiceAccount
    name: admin-user
    namespace: kubernetes-dashboard
    EOF

    kubectl create -f access/
  2. 获取用户的 Token, 并在登录页面上输入, 然后登录 Kubernetes Dashboard

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    ## 获取上一步授权的用户 Token,用于登录 Kubernetes Dashboard 
    # kubectl -n kubernetes-dashboard describe secret $(kubectl -n kubernetes-dashboard get secret | grep admin-user | awk '{print $1}')
    Name: admin-user-token-bhp84
    Namespace: kubernetes-dashboard
    Labels: <none>
    Annotations: kubernetes.io/service-account.name: admin-user
    kubernetes.io/service-account.uid: 4c67c8da-0694-4de9-b978-eff7a1075bea

    Type: kubernetes.io/service-account-token

    Data
    ====
    ca.crt: 1025 bytes
    namespace: 20 bytes
    token: eyJhbGciOiJSUzI1NiIsImtpZCI6IkpWcTFvc0Rza0xYZVVhVnlkRkhUX2VDM1RBR1hUNXpKVkdna3kyRTAyVlEifQ.eyJpc3MiOiJrdWJlcm5ldGVzL3NlcnZpY2VhY2NvdW50Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9uYW1lc3BhY2UiOiJrdWJlcm5ldGVzLWRhc2hib2FyZCIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VjcmV0Lm5hbWUiOiJhZG1pbi11c2VyLXRva2VuLWJocDg0Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9zZXJ2aWNlLWFjY291bnQubmFtZSI6ImFkbWluLXVzZXIiLCJrdWJlcm5ldGVzLmlvL3NlcnZpY2VhY2NvdW50L3NlcnZpY2UtYWNjb3VudC51aWQiOiI0YzY3YzhkYS0wNjk0LTRkZTktYjk3OC1lZmY3YTEwNzViZWEiLCJzdWIiOiJzeXN0ZW06c2VydmljZWFjY291bnQ6a3ViZXJuZXRlcy1kYXNoYm9hcmQ6YWRtaW4tdXNlciJ9.aF2iWV--nNTdcrOTSQiQLEWi9QQnonjqk4EZNQSxcgqjZjUIaK1ezXBDrm9_bT5M9ddsMXKuE7E4PuTqk2IMTC_8m9DlinRrHHERAneI5OVO8aoAGqRo-pMyatEF7n9YfNoZMR0pLCWgrwrm1ttADHWtsTYsjrj4uT42Gt_h7J4i47VxF5g9qtqv8Jt_yoQNemje_XhWoGK4p9F_jPt3H8OrQ7CKYx1SwTGfw8t7P_mt9XY9AsWuUO4r4AixnZhWOLBtxa0QibM-mK7X4iREN3Ib8nmezVGkdiVt1epd_zmWAAWMHxEgh1D48wSro2Gb0e2p5AQQV2FAHJrfra4qUA

    ## 登录页面上输入 Token 后,点击对应按钮即可实现登录

login_02
login_03

七、参考资料

1. Kubernetes Dashboard 的官方资料

https://github.com/kubernetes/dashboard/blob/v2.0.0-rc5/src/app/backend/dashboard.go
https://github.com/kubernetes/dashboard/blob/v2.0.0-rc5/docs/user/accessing-dashboard/1.7.x-and-above.md
https://github.com/kubernetes/dashboard/blob/v2.0.0-rc5/docs/user/access-control/creating-sample-user.md
https://github.com/kubernetes/dashboard/blob/v2.0.0-rc5/docs/user/integrations.md
https://github.com/kubernetes/dashboard/blob/v2.0.0-rc5/docs/user/certificate-management.md

2. Kubernetes Metric Server

https://www.cnblogs.com/ding2016/p/10786252.html
https://github.com/singhwang/k8s-prom-hpa

3. 关于 Chrome 无法访问 Kubernetes Dashboard 的问题解决

http://team.jiunile.com/blog/2018/12/k8s-dashboard-chrome-err.html
https://superuser.com/questions/27268/how-do-i-disable-the-warning-chrome-gives-if-a-security-certificate-is-not-trust
https://www.jianshu.com/p/a8cc2c04ee7c
https://blog.gxxsite.com/wei-mac-osxde-cheng-xu-tian-jia-yong-jiu-qi-dong-can-shu/