当前位置: 首页 > news >正文

猪八戒网站做私活赚钱吗中山做网站的公司哪家好

猪八戒网站做私活赚钱吗,中山做网站的公司哪家好,福建省住房与城乡建设厅网站,万网域名绑定到其它网站1.查看当前证书时间 # kubeadm alpha certs renew kubelet Kubeadm experimental sub-commands kubeadm是一个用于引导Kubernetes集群的工具#xff0c;它提供了许多命令和子命令来管理集群的一生周期。过去#xff0c;某些功能被标记为实验性的#xff0c;并通过kubeadm a…1.查看当前证书时间 # kubeadm alpha certs renew kubelet Kubeadm experimental sub-commands kubeadm是一个用于引导Kubernetes集群的工具它提供了许多命令和子命令来管理集群的一生周期。过去某些功能被标记为实验性的并通过kubeadm alpha子命令进行访问。然而从Kubernetes 1.15版本开始kubeadm将这些功能从alpha子命令迁移到了稳定的命令中。 在新版本中使用kubeadm certs renew kubelet即可 检查 # kubeadm certs check-expiration [check-expiration] Reading configuration from the cluster... [check-expiration] FYI: You can look at this config file with kubectl -n kube-system get cm kubeadm-config -o yamlCERTIFICATE EXPIRES RESIDUAL TIME CERTIFICATE AUTHORITY EXTERNALLY MANAGED admin.conf Mar 26, 2025 08:52 UTC 286d ca no apiserver Mar 26, 2025 08:52 UTC 286d ca no apiserver-etcd-client Mar 26, 2025 08:52 UTC 286d etcd-ca no apiserver-kubelet-client Mar 26, 2025 08:52 UTC 286d ca no controller-manager.conf Mar 26, 2025 08:52 UTC 286d ca no etcd-healthcheck-client Mar 26, 2025 08:52 UTC 286d etcd-ca no etcd-peer Mar 26, 2025 08:52 UTC 286d etcd-ca no etcd-server Mar 26, 2025 08:52 UTC 286d etcd-ca no front-proxy-client Mar 26, 2025 08:52 UTC 286d front-proxy-ca no scheduler.conf Mar 26, 2025 08:52 UTC 286d ca no CERTIFICATE AUTHORITY EXPIRES RESIDUAL TIME EXTERNALLY MANAGED ca Mar 24, 2034 08:52 UTC 9y no etcd-ca Mar 24, 2034 08:52 UTC 9y no front-proxy-ca Mar 24, 2034 08:52 UTC 9y no kubelet证书时间只有1年有效期。  # openssl x509 -in kubelet.crt -noout -text | grep NotNot Before: Mar 26 07:52:16 2024 GMTNot After : Mar 26 07:52:16 2025 GMT 备份原证书 # mkdir backup_certs # cd backup_certs/# cp /usr/bin/kube* . # ll total 211260 -rwxr-x--- 1 root root 45210392 Jun 13 15:15 kubeadm -rwxr-x--- 1 root root 46592216 Jun 13 15:15 kubectl -rwxr-x--- 1 root root 124521288 Jun 13 15:15 kubelet# cp -r /etc/kubernetes/pki . ]# ll total 211264 -rwxr-x--- 1 root root 45210392 Jun 13 15:15 kubeadm -rwxr-x--- 1 root root 46592216 Jun 13 15:15 kubectl -rwxr-x--- 1 root root 124521288 Jun 13 15:15 kubelet drwxr-x--- 3 root root 4096 Jun 13 15:18 pki 删除旧证书 # rm -rf /etc/kubernetes/pki/* 生成新证书 # kubeadm certs renew -h This command is not meant to be run on its own. See list of available subcommands.Usage:kubeadm certs renew [flags]kubeadm certs renew [command]Available Commands:admin.conf Renew the certificate embedded in the kubeconfig file for the admin to use and for kubeadm itselfall Renew all available certificatesapiserver Renew the certificate for serving the Kubernetes APIapiserver-etcd-client Renew the certificate the apiserver uses to access etcdapiserver-kubelet-client Renew the certificate for the API server to connect to kubeletcontroller-manager.conf Renew the certificate embedded in the kubeconfig file for the controller manager to useetcd-healthcheck-client Renew the certificate for liveness probes to healthcheck etcdetcd-peer Renew the certificate for etcd nodes to communicate with each otheretcd-server Renew the certificate for serving etcdfront-proxy-client Renew the certificate for the front proxy clientscheduler.conf Renew the certificate embedded in the kubeconfig file for the scheduler manager to useFlags:-h, --help help for renewGlobal Flags:--add-dir-header If true, adds the file directory to the header of the log messages--log-file string If non-empty, use this log file--log-file-max-size uint Defines the maximum size a log file can grow to. Unit is megabytes. If the value is 0, the maximum file size is unlimited. (default 1800)--one-output If true, only write logs to their native severity level (vs also writing to each lower severity level)--rootfs string [EXPERIMENTAL] The path to the real host root filesystem.--skip-headers If true, avoid header prefixes in the log messages--skip-log-headers If true, avoid headers when opening log files-v, --v Level number for the log level verbosityUse kubeadm certs renew [command] --help for more information about a command. 生成某个证书 升级哪个证书就生成哪个组件的证书保险就生成所有证书 # kubeadm certs renew apiserver-kubelet-client [renew] Reading configuration from the cluster... [renew] FYI: You can look at this config file with kubectl -n kube-system get cm kubeadm-config -o yamlcertificate for the API server to connect to kubelet renewed 生成所有证书 # kubeadm certs renew all [renew] Reading configuration from the cluster... [renew] FYI: You can look at this config file with kubectl -n kube-system get cm kubeadm-config -o yamlcertificate embedded in the kubeconfig file for the admin to use and for kubeadm itself renewed certificate for serving the Kubernetes API renewed certificate the apiserver uses to access etcd renewed certificate for the API server to connect to kubelet renewed certificate embedded in the kubeconfig file for the controller manager to use renewed certificate for liveness probes to healthcheck etcd renewed certificate for etcd nodes to communicate with each other renewed certificate for serving etcd renewed certificate for the front proxy client renewed certificate embedded in the kubeconfig file for the scheduler manager to use renewedDone renewing certificates. You must restart the kube-apiserver, kube-controller-manager, kube-scheduler and etcd, so that they can use the new certificates. 查看配置已经更新 # ll /etc/kubernetes/ total 32 -rwxrwxrwx 1 root root 5640 Jun 13 15:26 admin.conf -rw------- 1 root root 5668 Jun 13 15:26 controller-manager.conf -rw------- 1 root root 2004 Mar 26 16:52 kubelet.conf drwxr-xr-x 2 root root 113 May 29 17:12 manifests drwxr-x--- 3 root root 4096 Mar 26 16:52 pki -rw------- 1 root root 5620 Jun 13 15:26 scheduler.conf 生成新配置 查看帮助 # kubeadm init phase kubeconfig -h This command is not meant to be run on its own. See list of available subcommands.Usage:kubeadm init phase kubeconfig [flags]kubeadm init phase kubeconfig [command]Available Commands:admin Generate a kubeconfig file for the admin to use and for kubeadm itselfall Generate all kubeconfig filescontroller-manager Generate a kubeconfig file for the controller manager to usekubelet Generate a kubeconfig file for the kubelet to use *only* for cluster bootstrapping purposesscheduler Generate a kubeconfig file for the scheduler to useFlags:-h, --help help for kubeconfigGlobal Flags:--add-dir-header If true, adds the file directory to the header of the log messages--log-file string If non-empty, use this log file--log-file-max-size uint Defines the maximum size a log file can grow to. Unit is megabytes. If the value is 0, the maximum file size is unlimited. (default 1800)--one-output If true, only write logs to their native severity level (vs also writing to each lower severity level)--rootfs string [EXPERIMENTAL] The path to the real host root filesystem.--skip-headers If true, avoid header prefixes in the log messages--skip-log-headers If true, avoid headers when opening log files-v, --v Level number for the log level verbosityUse kubeadm init phase kubeconfig [command] --help for more information about a command. 生成某个配置 失败是正常版本垮裤较大而且也只更新证书有效期 # kubeadm init phase kubeconfig admin I0613 15:31:07.518079 30859 version.go:255] remote version is much newer: v1.30.2; falling back to: stable-1.23 W0613 15:31:17.521449 30859 version.go:103] could not fetch a Kubernetes version from the internet: unable to get URL https://dl.k8s.io/release/stable-1.23.txt: Get https://cdn.dl.k8s.io/release/stable-1.23.txt: context deadline exceeded (Client.Timeout exceeded while awaiting headers) W0613 15:31:17.521573 30859 version.go:104] falling back to the local client version: v1.23.4 生成所有配置 # kubeadm init phase kubeconfig all W0613 15:45:39.731181 7842 version.go:103] could not fetch a Kubernetes version from the internet: unable to get URL https://dl.k8s.io/release/stable-1.txt: Get https://cdn.dl.k8s.io/release/stable-1.txt: context deadline exceeded (Client.Timeout exceeded while awaiting headers) W0613 15:45:39.731479 7842 version.go:104] falling back to the local client version: v1.23.4 [kubeconfig] Using kubeconfig folder /etc/kubernetes [kubeconfig] Using existing kubeconfig file: /etc/kubernetes/admin.conf [kubeconfig] Using existing kubeconfig file: /etc/kubernetes/kubelet.conf [kubeconfig] Using existing kubeconfig file: /etc/kubernetes/controller-manager.conf [kubeconfig] Using existing kubeconfig file: /etc/kubernetes/scheduler.conf 重启kubelet # systemctl status kubelet.service | grep ActiveActive: active (running) since Tue 2024-03-26 16:52:52 CST; 2 months 18 days ago# systemctl restart kubelet.service # systemctl status kubelet.service | grep ActiveActive: active (running) since Thu 2024-06-13 15:47:19 CST; 3s ago 更新admin.conf文件 # cp /etc/kubernetes/admin.conf ~/.kube/config cp: overwrite ‘/root/.kube/config’? y 2.检查证书有效期 # kubeadm certs check-expiration [check-expiration] Reading configuration from the cluster... [check-expiration] FYI: You can look at this config file with kubectl -n kube-system get cm kubeadm-config -o yamlCERTIFICATE EXPIRES RESIDUAL TIME CERTIFICATE AUTHORITY EXTERNALLY MANAGED admin.conf Jun 13, 2025 07:26 UTC 364d ca no apiserver Jun 13, 2025 07:26 UTC 364d ca no apiserver-etcd-client Jun 13, 2025 07:26 UTC 364d etcd-ca no apiserver-kubelet-client Jun 13, 2025 07:26 UTC 364d ca no controller-manager.conf Jun 13, 2025 07:26 UTC 364d ca no etcd-healthcheck-client Jun 13, 2025 07:26 UTC 364d etcd-ca no etcd-peer Jun 13, 2025 07:26 UTC 364d etcd-ca no etcd-server Jun 13, 2025 07:26 UTC 364d etcd-ca no front-proxy-client Jun 13, 2025 07:26 UTC 364d front-proxy-ca no scheduler.conf Jun 13, 2025 07:26 UTC 364d ca no CERTIFICATE AUTHORITY EXPIRES RESIDUAL TIME EXTERNALLY MANAGED ca Mar 24, 2034 08:52 UTC 9y no etcd-ca Mar 24, 2034 08:52 UTC 9y no front-proxy-ca Mar 24, 2034 08:52 UTC 9y no 查看各证书时间 # openssl x509 -in /etc/kubernetes/pki/apiserver.crt -noout -textNot Before: Mar 26 08:52:10 2024 GMTNot After : Jun 13 07:26:54 2025 GMT # openssl x509 -in /etc/kubernetes/pki/apiserver-etcd-client.crt -noout -textNot Before: Mar 26 08:52:11 2024 GMTNot After : Jun 13 07:26:55 2025 GMT # openssl x509 -in /etc/kubernetes/pki/apiserver-kubelet-client.crt -noout -textNot Before: Mar 26 08:52:10 2024 GMTNot After : Jun 13 07:26:55 2025 GMT # openssl x509 -in /etc/kubernetes/pki/ca.crt -noout -textNot Before: Mar 26 08:52:10 2024 GMTNot After : Mar 24 08:52:10 2034 GMT # openssl x509 -in /etc/kubernetes/pki/front-proxy-ca.crt -noout -textNot Before: Mar 26 08:52:10 2024 GMTNot After : Mar 24 08:52:10 2034 GMT # openssl x509 -in /etc/kubernetes/pki/front-proxy-client.crt -noout -textNot Before: Mar 26 08:52:10 2024 GMTNot After : Jun 13 07:26:57 2025 GMT 查看k8s环境
http://www.dnsts.com.cn/news/36877.html

相关文章:

  • 网站建设河南公司如何在服务器上搭建网站
  • 电脑可以做网站主机么来个网站奖励自己
  • 珠海企业网站建设费用如何创建网络
  • 网站做seowordpress对接公众号
  • my网站域名宁波网站推广宣传
  • 在什么网站可以接活做注册网站登录
  • 谁专门做网站安全维护做公司网站要学会什么
  • 建设网站时vs2010网站开发登录代码
  • 免费的海报设计网站做网站需要几个岗位
  • 一般网站做响应式吗黄金网站下载免费
  • 北京网站设计公司新网站建设论文选题表
  • word如何做网站网站建设工作会议召开
  • 秦都区建设局网站湖州网
  • sem和seo是什么职业湖南网站建设方案优化
  • 网站服务公司有哪些万网虚拟主机做网站教程
  • 保定seo网站排名中国做w7的网站
  • 网站建设岗位绩效网站怎么做301
  • 兰州网站seo服务如何做内网网站
  • 如何免费建网站微信商城怎么找
  • 浙江省邮电工程建设有限公司 网站网站建设观点
  • 网络推广与传统推广的区别如何优化关键词提升相关度
  • 沈阳市建设局网站首页wordpress首页调用分类及描述
  • 成品网站软件wordpress开发 文档
  • wap网站部署网站代理协议
  • 临沂网站建设方案书cantos wordpress
  • 建筑设计怎么学 从零开始上海网络公司seo
  • 标准论坛网站建设wordpress 转换 织梦
  • 如何判断网站是响应式的还是百度信息
  • 制作网站支付方式企业网站排名运营
  • 网站管理助手婚庆网站建设目的