OnCallReady

Commands

kubeadm - bootstrap and operate a kubeadm cluster

kubeadm init | join | reset | token | certs | upgrade | version

Options you will use

init
set up a control plane: certificates in /etc/kubernetes/pki, kubeconfigs, static pod manifests, bootstrap token, addons
join HOST:6443 --token T --discovery-token-ca-cert-hash sha256:H
add a node (worker, or --control-plane)
token create --print-join-command [--ttl 2h]
a fresh join command (the init token expires after 24h)
certs check-expiration
every kubeadm certificate and how long it has left
certs renew all|NAME
renew leaf certificates - then restart the static pods and re-copy admin.conf
upgrade plan / apply vX.Y.Z
first control plane: plan, then apply (renews certificates too)
upgrade node
other control planes and workers: upgrade the local kubelet config (and static pods)
reset [-f]
undo init/join on this host (not CNI config, not iptables, not ~/.kube)
-o, --output FORMAT
Output format. One of: text|json|yaml|short (kubeadm version -o short).
-v, --v LEVEL
Number for the log level verbosity.
--config FILE
Path to a kubeadm configuration file (ClusterConfiguration / InitConfiguration / JoinConfiguration).
-h, --help
Help for the command (with the full flag list and examples).

Examples

$ sudo kubeadm token create --print-join-command

on cp-1: the line to run on a new node

$ sudo kubeadm certs check-expiration

the first command after an x509 "certificate has expired"

$ sudo kubeadm upgrade plan

what you can upgrade to and what must be upgraded by hand

Gotchas

Try kubeadm in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.