根据架构图,我们的apiserver部署在hdss7-21和hdss7-22上:
首先在hdss7-200上申请证书并拷贝到21和22上:
创建证书文件:
# cd /etc/certs # vi client-csr.json
{ "CN": "k8s-node", "hosts": [ ], "key": { "algo": "rsa", "size": 2048 }, "names": [ { "C": "CN", "ST": "beijing", "L": "beijing", "O": "od", "OU": "ops" } ] }
申请证书:
# cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=client client-csr.json |cfssl-json -bare client