Key takeaways
- Every node has to be prepared before
kubeadm:swapoff -aplus swap commented out in/etc/fstab(the scheduler needs exact memory metrics), theoverlayandbr_netfiltermodules, thennet.bridge.bridge-nf-call-iptables=1andnet.ipv4.ip_forward=1. Budget at least 2 vCPU and 2 GB of RAM per machine. - The containerd trap: after
containerd config default, you must flipSystemdCgroup = falsetotruein/etc/containerd/config.tomlso the runtime matches the systemd cgroup driver kubelet expects, then restart containerd. - After
kubeadm init --pod-network-cidr=10.244.0.0/16, nodes stayNotReadyuntil a CNI is deployed: Flannel to move fast, Calico when you need NetworkPolicies. Write down thekubeadm joincommand printed at the end of the init, it carries the worker token. - A Deployment updates without downtime through
strategy.rollingUpdate(maxUnavailable: 1,maxSurge: 1) combined with areadinessProbe:kubectl set image deployment/webapp webapp=nginx:1.27triggers the rollout,kubectl rollout statusfollows it andkubectl rollout undorolls it back. - Kubernetes Secrets are base64-encoded, not encrypted: turn on encryption at rest with
EncryptionConfiguration(or move to Vault / Sealed Secrets), and back it up with RBAC, deny-all NetworkPolicies and thepod-security.kubernetes.io/enforce: restrictedlabel on sensitive namespaces.
Kubernetes (K8s) is an open source container orchestration platform developed by Google. It automates the deployment, scaling and management of containerized applications across clusters of machines. This tutorial guides you from installation to production.
Prerequisites
- Machines: A minimum of 2 servers (1 control plane + 1 worker) with 2 CPUs and 2 GB of RAM each
- Operating system: Ubuntu 22.04 LTS or Debian 12 (recommended)
- Network: Full network connectivity between all machines in the cluster
- Container runtime: containerd or Docker Engine installed on each node
- Privileges: Root or sudo access on all machines
- Open ports: 6443 (API), 2379-2380 (etcd), 10250-10252 (kubelet/scheduler/controller)
Kubernetes Architecture
Understanding the architecture of Kubernetes is essential before starting the installation. A K8s cluster consists of two types of nodes.
Control Plane (Master node)
- kube-apiserver: The entry point for all REST requests. It is the central component that exposes the Kubernetes API.
- etcd: A distributed key-value database that stores the complete state of the cluster (configurations, secrets, pod state).
- kube-scheduler: Assigns pods to nodes based on available resources, constraints and affinities.
- kube-controller-manager: Runs the control loops that monitor the state of the cluster and make the necessary corrections.
Worker Nodes
- kubelet: The agent that runs on each worker node and ensures that the containers defined in the pods are running.
- kube-proxy: Manages the network rules on each node to route traffic to the correct pods.
- Container Runtime: The container execution engine (containerd, CRI-O).
In production, it is recommended to have at least 3 control plane nodes for the high availability of etcd and the API server.
Premium Content
This advanced tutorial is reserved for premium members.
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime