controller-manager 涉及的服务器:k8s-5-138,k8s-5-139 controller-manager 设置为只调用当前机器的 apiserver,走127.0.0.1网卡,因此不配制SSL证书
配置启动脚本
#] vim /etc/systemd/system/kube-controller-manager.service
[Unit]
Description=kube controller manager
Documentation=https://github.com/kubernetes
Conflicts=kube-controller-manager
[Service]
Type=notify
Restart=always
RestartSec=5s
LimitNOFILE=40000
TimeoutStartSec=0
ExecStart=/opt/kubernetes/server/bin/kube-controller-manager \
--cluster-cidr 192.168.0.0/16 \
--leader-elect true \
--log-dir /data/logs/kubernetes/kube-controller-manager \
--master http://127.0.0.1:8080 \
--service-account-private-key-file /opt/kubernetes/server/bin/certs/ca-key.pem \
--service-cluster-ip-range 192.168.0.0/16 \
--root-ca-file /opt/kubernetes/server/bin/certs/ca.pem \
--v 2
[Install]
WantedBy=multi-user.target
#] systemctl daemon-reload
#] systemctl cat kube-controller-manager.service
#] systemctl enable kube-controller-manager
#] systemctl start kube-controller-manager
# 查看是否已经正常启动
#] netstat -unltp |grep kube-controller
#查看是否已经正常启动的另一种方法
#] systemctl status kube-controller-manager