Rocky Linux 9.0 完整安装 containerd(K8s 标准容器运行时)分步教程
Rocky9 系列官方弃用 Docker,K8s 1.24+ 强制使用 containerd,全程永久配置、重启不失效,适配 K8s 1.24~1.33。
前置准备(所有节点必须执行)
1. 关闭防火墙 / SELinux(生产可选放行端口,测试直接关闭)
|
bash
# 关闭防火墙开机自启并立即停止
systemctl stop firewalld
systemctl disable firewalld
# SELinux 永久关闭
sed -i 's/^SELINUX=enforcing/SELINUX=disabled/' /etc/selinux/config
# 临时生效
setenforce 0
|
2. 永久关闭 Swap(K8s 硬性要求)
|
bash
# 临时关闭
swapoff -a
# 永久注释 fstab 中的swap
sed -i '/swap/s/^/#/' /etc/fstab
|
3. 加载内核模块、开启 ip 转发(容器网络必需)
|
bash
# 加载overlay、br_netfilter内核模块
modprobe overlay
modprobe br_netfilter
# 永久内核参数配置
cat > /etc/sysctl.d/k8s.conf <<EOF
net.bridge.bridge-nf-call-iptables = 1
net.bridge.bridge-nf-call-ip6tables = 1
net.ipv4.ip_forward = 1
EOF
# 生效配置
sysctl --system
# 验证
sysctl net.ipv4.ip_forward
|
步骤 1:配置阿里云 containerd 软件源(国外源太慢)
|
bash
# 安装yum工具
dnf install -y dnf-utils
# 添加kubernetes阿里云yum源(同时附带containerd)
cat > /etc/yum.repos.d/kubernetes.repo <<EOF
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el9-x86_64/
enabled=1
gpgcheck=1
repo_gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF
# 刷新yum缓存
dnf clean all && dnf makecache
|
步骤 2:安装 containerd
|
bash
# 安装指定稳定版 1.7.20(适配K8s全版本)
dnf install -y containerd.io-1.7.20
|
步骤 3:生成默认配置文件(关键)
containerd 默认无配置文件,需要导出标准配置到 /etc/containerd/config.toml
|
bash
containerd config default > /etc/containerd/config.toml
|
步骤 4:修改配置文件(4 项核心修改,K8s 必改)
4.1 修改配置
|
bash
vim /etc/containerd/config.toml
|
执行以下替换命令(不用手动改文件,一键替换)
|
bash
# 1. cgroup驱动改为systemd(K8s强制要求)
sed -i 's/SystemdCgroup \= false/SystemdCgroup \= true/g' /etc/containerd/config.toml
# 2. 修改镜像加速器(阿里云镜像仓库,解决拉取k8s镜像超时)
sed -i 's#registry.k8s.io#registry.aliyuncs.com/google_containers#g' /etc/containerd/config.toml
# 3. 配置国内docker.io镜像加速(可选,加速业务镜像)
sed -i '/\[plugins."io.containerd.grpc.v1.cri".registry.mirrors\]/a \ [plugins."io.containerd.grpc.v1.cri".registry.mirrors."docker.io"]\n endpoint = ["https://docker.mirrors.ustc.edu.cn"]' /etc/containerd/config.toml
|
4.2 验证修改结果
|
bash
grep SystemdCgroup /etc/containerd/config.toml
# 输出 SystemdCgroup = true 代表修改成功
|
步骤 5:设置 containerd 开机自启 + 启动服务
|
bash
# 开机自启并立即启动
systemctl enable --now containerd
# 查看运行状态(显示 active (running) 正常)
systemctl status containerd
|
步骤 6:验证 containerd 功能
6.1 查看版本
6.2 测试拉取镜像
|
bash
# 拉取nginx测试镜像
ctr images pull docker.io/library/nginx:alpine
# 查看本地镜像
ctr images list
|
步骤 7:(可选)安装 crictl 工具(K8s 专用容器调试工具)
crictl 是 k8s 标准容器调试命令,替代 docker 命令
|
bash
# 安装
dnf install -y cri-tools
# 配置crictl连接containerd
cat > /etc/crictl.yaml <<EOF
runtime-endpoint: unix:///run/containerd/containerd.sock
image-endpoint: unix:///run/containerd/containerd.sock
timeout: 10
debug: false
EOF
# 验证连通性
crictl info
|
完整一键脚本(复制直接整条执行,Rocky9.0 通用)
|
bash
# 1. 基础环境优化
systemctl stop firewalld && systemctl disable firewalld
setenforce 0
sed -i 's/^SELINUX=enforcing/SELINUX=disabled/' /etc/selinux/config
swapoff -a
sed -i '/swap/s/^/#/' /etc/fstab
modprobe overlay && modprobe br_netfilter
cat > /etc/sysctl.d/k8s.conf <<EOF
net.bridge.bridge-nf-call-iptables = 1
net.bridge.bridge-nf-call-ip6tables = 1
net.ipv4.ip_forward = 1
EOF
sysctl --system
# 2. 配置yum源
dnf install -y dnf-utils
cat > /etc/yum.repos.d/kubernetes.repo <<EOF
[kubernetes]
name=Kubernetes
baseurl=https://mirrors.aliyun.com/kubernetes/yum/repos/kubernetes-el9-x86_64/
enabled=1
gpgcheck=1
repo_gpgkey=https://mirrors.aliyun.com/kubernetes/yum/doc/yum-key.gpg https://mirrors.aliyun.com/kubernetes/yum/doc/rpm-package-key.gpg
EOF
dnf clean all && dnf makecache
# 3. 安装并配置containerd
dnf install -y containerd.io-1.7.20 cri-tools
containerd config default > /etc/containerd/config.toml
sed -i 's/SystemdCgroup \= false/SystemdCgroup \= true/g' /etc/containerd/config.toml
sed -i 's#registry.k8s.io#registry.aliyuncs.com/google_containers#g' /etc/containerd/config.toml
sed -i '/\[plugins."io.containerd.grpc.v1.cri".registry.mirrors\]/a \ [plugins."io.containerd.grpc.v1.cri".registry.mirrors."docker.io"]\n endpoint = ["https://docker.mirrors.ustc.edu.cn"]' /etc/containerd/config.toml
# 4. 启动服务
systemctl enable --now containerd
cat > /etc/crictl.yaml <<EOF
runtime-endpoint: unix:///run/containerd/containerd.sock
image-endpoint: unix:///run/containerd/containerd.sock
timeout: 10
debug: false
EOF
# 5. 校验
systemctl status containerd
crictl info
|
常见故障排查
- containerd 启动失败:检查 /etc/containerd/config.toml 语法,不能有多余空格
- K8s node 初始化报错 cgroup:确认 SystemdCgroup = true
- 镜像拉取超时:检查镜像加速器配置,切换阿里云 / 中科大镜像源
- 重启后失效:确认 systemctl enable containerd 执行成功,swap、sysctl 配置写入永久文件
所有评论(0)