kubeadm - bootstrap and operate a kubeadm cluster
kubeadm init | join | reset | token | certs | upgrade | version
Options you will use
init- set up a control plane: certificates in /etc/kubernetes/pki, kubeconfigs, static pod manifests, bootstrap token, addons
join HOST:6443 --token T --discovery-token-ca-cert-hash sha256:H- add a node (worker, or --control-plane)
token create --print-join-command [--ttl 2h]- a fresh join command (the init token expires after 24h)
certs check-expiration- every kubeadm certificate and how long it has left
certs renew all|NAME- renew leaf certificates - then restart the static pods and re-copy admin.conf
upgrade plan / apply vX.Y.Z- first control plane: plan, then apply (renews certificates too)
upgrade node- other control planes and workers: upgrade the local kubelet config (and static pods)
reset [-f]- undo init/join on this host (not CNI config, not iptables, not ~/.kube)
-o, --output FORMAT- Output format. One of: text|json|yaml|short (kubeadm version -o short).
-v, --v LEVEL- Number for the log level verbosity.
--config FILE- Path to a kubeadm configuration file (ClusterConfiguration / InitConfiguration / JoinConfiguration).
-h, --help- Help for the command (with the full flag list and examples).
Examples
$ sudo kubeadm token create --print-join-commandon cp-1: the line to run on a new node
$ sudo kubeadm certs check-expirationthe first command after an x509 "certificate has expired"
$ sudo kubeadm upgrade planwhat you can upgrade to and what must be upgraded by hand
Gotchas
- kubeadm reads /etc/kubernetes/admin.conf, so it needs sudo.
- Upgrades go one minor version at a time, control plane first; kubeadm itself is upgraded first (apt-mark unhold, install, hold).
- Leaf certificates last 1 year, CAs 10 years. Every upgrade apply renews the leaves - clusters that upgrade regularly never see expiry.
Try kubeadm in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.