k8s-flannel

k8s网络通讯:

(1)容器间通信:同一个Pod内的多个容器间的通信,lo
(2)Pod通信:Pod IP <–> Pod IP
(3)Pod与service通信:PodIP <–> ClusterIP
(4)Service与集群外部客户端的通信;

CNI

CNI(Container Network Interface)是CNCF 旗下的一个项目,由一组用于配置Linux 容器的网络接口的规范和库组成,同时还包含了一些插件

k8s的CNI:
flannel(网络地址分配,网络管理,但没有网络策略(定义Pod之间能不能访问))
calico(既支持网络地址分配,又支持网络策略,但安装复杂)
canel
kube-router(k8s自带)

解决方案:
1)虚拟网桥
2)多路复用 MacVLAN
3)硬件交换 SR-IOV(单根IO序列化,一个网卡可以虚拟出多个物理接口,这种性能最好

kubelet,/etc/cni/net.d/ 放在这个目录下即可使用网络插件
在这里插入图片描述

ifconfig我们会查看到flannel和cni0(只有创建了Pod之后才会出现)
在这里插入图片描述

flannel支持多种后端:

  1. VxLAN:
    1)vxlan
    2)Drectrouting
    在这里插入图片描述
  2. host-gw: Host Gateway(主机网关,不允许跨网段)
    在这里插入图片描述
    如果在同一网络会用host-gw,不在同一网络会自动选择VxLAN
  3. UDP效果最差

flannel的配置参数

Network: flannel使用的CIDR格式的网络地址,用于Pod配置网络功能;
10.244.0.0/16->master:10.244.0.0/24;node01:10.244.1.0/24…node255:10.244.255.0/24

10.0.0.0/8->master:10.0.0.0/24;node01:10.0.1.0/24…node65536:10.2255.255.0/24

SubnetLen:把Network切分子网供各节点使用时,使用多长的亚麻进行切分,默认为24位
SubnetMin:10.244.10.0//24(使用最小IP段是10)
SubnetMax:10.244.100.0//24(使用最大IP段是100)

Backend:vxlan,host-gw,udp
vxlan:vxlan,drectrouting

添加flannel的directroute为true

kubectl edit cm -n kube-system kube-flannel-cfg

"Directrouting": true

在这里插入图片描述

查看是否生效ip route show发现没有生效
在这里插入图片描述
需要重启主机才会起作用:
在这里插入图片描述
在这里插入图片描述
使用抓包工具:tcpdump

tcpdump -i en0 -nn icmp
--- kind: Namespace apiVersion: v1 metadata: name: kube-flannel labels: k8s-app: flannel pod-security.kubernetes.io/enforce: privileged --- kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: labels: k8s-app: flannel name: flannel rules: - apiGroups: - "" resources: - pods verbs: - get - apiGroups: - "" resources: - nodes verbs: - get - list - watch - apiGroups: - "" resources: - nodes/status verbs: - patch --- kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: labels: k8s-app: flannel name: flannel roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: flannel subjects: - kind: ServiceAccount name: flannel namespace: kube-flannel --- apiVersion: v1 kind: ServiceAccount metadata: labels: k8s-app: flannel name: flannel namespace: kube-flannel --- kind: ConfigMap apiVersion: v1 metadata: name: kube-flannel-cfg namespace: kube-flannel labels: tier: node k8s-app: flannel app: flannel data: cni-conf.json: | { "name": "cbr0", "cniVersion": "0.3.1", "plugins": [ { "type": "flannel", "delegate": { "hairpinMode": true, "isDefaultGateway": true } }, { "type": "portmap", "capabilities": { "portMappings": true } } ] } net-conf.json: | { "Network": "10.244.0.0/16", "EnableNFTables": false, "Backend": { "Type": "vxlan" } } --- apiVersion: apps/v1 kind: DaemonSet metadata: name: kube-flannel-ds namespace: kube-flannel labels: tier: node app: flannel k8s-app: flannel spec: selector: matchLabels: app: flannel template: metadata: labels: tier: node app: flannel spec: affinity: nodeAffinity: requiredDuringSchedulingIgnoredDuringExecution: nodeSelectorTerms: - matchExpressions: - key: kubernetes.io/os operator: In values: - linux hostNetwork: true priorityClassName: system-node-critical tolerations: - operator: Exists effect: NoSchedule serviceAccountName: flannel initContainers: - name: install-cni-plugin image: ghcr.io/flannel-io/flannel-cni-plugin:v1.7.1-flannel1 command: - cp args: - -f - /flannel - /opt/cni/bin/flannel volumeMounts: - name: cni-plugin mountPath: /opt/cni/bin - name: install-cni image: ghcr.io/flannel-io/flannel:v0.27.0 command: - cp args: - -f - /etc/kube-flannel/cni-conf.json - /etc/cni/net.d/10-flannel.conflist volumeMounts: - name: cni mountPath: /etc/cni/net.d - name: flannel-cfg mountPath: /etc/kube-flannel/ containers: - name: kube-flannel image: ghcr.io/flannel-io/flannel:v0.27.0 command: - /opt/bin/flanneld args: - --ip-masq - --kube-subnet-mgr resources: requests: cpu: "100m" memory: "50Mi" securityContext: privileged: false capabilities: add: ["NET_ADMIN", "NET_RAW"] env: - name: POD_NAME valueFrom: fieldRef: fieldPath: metadata.name - name: POD_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace - name: EVENT_QUEUE_DEPTH value: "5000" - name: CONT_WHEN_CACHE_NOT_READY value: "false" volumeMounts: - name: run mountPath: /run/flannel - name: flannel-cfg mountPath: /etc/kube-flannel/ - name: xtables-lock mountPath: /run/xtables.lock volumes: - name: run hostPath: path: /run/flannel - name: cni-plugin hostPath: path: /opt/cni/bin - name: cni hostPath: path: /etc/cni/net.d - name: flannel-cfg configMap: name: kube-flannel-cfg - name: xtables-lock hostPath: path: /run/xtables.lock type: FileOrCreate
最新发布
07-01
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值