controller-manager 涉及的服务器:k8s-5-138,k8s-5-139 controller-manager 设置为只调用当前机器的 apiserver,走127.0.0.1网卡,因此不配制SSL证书
配置启动脚本
#] vim /etc/systemd/system/kube-controller-manager.service[Unit]Description=kube controller managerDocumentation=https://github.com/kubernetesConflicts=kube-controller-manager[Service]Type=notifyRestart=alwaysRestartSec=5sLimitNOFILE=40000TimeoutStartSec=0ExecStart=/opt/kubernetes/server/bin/kube-controller-manager \--cluster-cidr 192.168.0.0/16 \--leader-elect true \--log-dir /data/logs/kubernetes/kube-controller-manager \--master http://127.0.0.1:8080 \--service-account-private-key-file /opt/kubernetes/server/bin/certs/ca-key.pem \--service-cluster-ip-range 192.168.0.0/16 \--root-ca-file /opt/kubernetes/server/bin/certs/ca.pem \--v 2[Install]WantedBy=multi-user.target#] systemctl daemon-reload#] systemctl cat kube-controller-manager.service#] systemctl enable kube-controller-manager#] systemctl start kube-controller-manager# 查看是否已经正常启动#] netstat -unltp |grep kube-controller#查看是否已经正常启动的另一种方法#] systemctl status kube-controller-manager
