kubeadm: Install & Upgrade (CKA)
Bootstrap a cluster, join nodes, and upgrade it one minor version at a time.
An interactive Kubernetes lesson: 24 steps, about 35 minutes, on a live simulation in your browser.
The shop is moving off a managed service. You have been given three fresh Linux machines, cp-1, node-a and node-b, and one task: turn them into a Kubernetes cluster running v1.34, then take it to v1.35.
The stage shows the first machine, cp-1. Every control-plane box is dark. There is no API server, so there is nothing for kubectl to talk to.
What you will learn
Prepare the machines
- Three empty machines: kubeadm bootstraps Kubernetes on machines you have prepared. The machine, the runtime and the network plugin are your job.
- Prepare the operating system
- Install a container runtime: The kubelet and the container runtime must use the same cgroup driver. On a systemd machine, that driver is systemd.
- Install kubeadm, kubelet, kubectl
kubeadm init
- kubeadm init: kubeadm init is a list of phases: certificates, kubeconfigs, static pod manifests, start the kubelet, then a token so others can join.
- What init left on disk
- Tell kubectl where the cluster is
- Why is the node NotReady?: A kubeadm cluster is not finished until a CNI plugin is installed. NotReady plus Pending CoreDNS right after init means: install the network.
Join the workers
- Join a worker: The token proves the node to the cluster. The CA hash proves the cluster to the node. After the join, neither is needed again.
- Yesterday's token
- The cluster does its job
Upgrade, one minor at a time
- Plan the upgrade: Upgrade order never changes: one minor at a time, control plane before workers, kubeadm before kubelet.
- Upgrade the control plane
- What version is cp-1 now?: kubeadm upgrades the control-plane pods. The kubelet is a package on each machine, upgraded by you, and it is what VERSION shows.
- Mixed versions on purpose: Nothing may be newer than the API server. The kubelet may lag it by up to three minors; kubectl may be one either side.
- Drain a worker: drain = cordon + evict. The node stays in the cluster, empty and unschedulable, until you uncordon it.
- Upgrade the worker's kubelet
- Break it: the forgotten uncordon
- Finish the upgrade
Certificates & drills
- Break it: a year without an upgrade
- Drill: a fresh join command
- Drill: empty a node safely
Recap & playground
- Cheat sheet
- Playground