You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

裸金属部署Kubernetes集群:能否不启用SSH将工作节点加入控制平面?

Can You Join Kubernetes Worker Nodes to Control Plane Without SSH?

Great question! When deploying a Kubernetes cluster on bare metal, SSH is the go-to method tools like kubeadm use to orchestrate node joining—but it’s not strictly mandatory. You can work around SSH if you have a specific need to avoid it, though it does add some manual overhead. Here’s how:

Ways to Skip SSH for Node Joining

1. Manually Transfer Cluster Credentials & Configs

The core of what SSH does during kubeadm join is securely copy critical cluster assets from the control plane to the worker node. You can replicate this manually:

  • On your control plane node, grab the necessary files from /etc/kubernetes/pki/ (like ca.crt, and ca.key—handle this private key with extreme care!) plus the kubelet configuration file (typically kubelet.conf or a dedicated node-specific config).
  • Transfer these files to the worker node’s corresponding directories (/etc/kubernetes/pki/ and /etc/kubernetes/ for the config). Use a secure, non-SSH method like encrypted file transfer software, a physical encrypted drive, or a secure internal vault.
  • Run the kubeadm join command on the worker node with the required flags (--token, --discovery-token-ca-cert-hash), and add --skip-phases=preflight/ssh to bypass SSH-related pre-checks if your kubeadm version supports it.

2. Pre-Configure Worker Node Images

If you’re provisioning multiple worker nodes, bake the cluster credentials and kubelet config directly into your node’s OS image (e.g., a custom Ubuntu/CentOS image). When the node boots up, it already has all the necessary files to run kubeadm join without needing to pull anything over SSH.

3. Use Alternative Bare Metal Provisioning Tools

Some bare metal infrastructure tools support non-SSH ways to inject files into nodes during deployment. For example, using iPXE with custom scripts to push Kubernetes assets to the node before it finishes booting, or using a provisioning system that can write files directly to the node’s disk over a dedicated management network.

Important Caveats

  • Security Risk: Manually handling cluster certificates and private keys drastically increases the chance of accidental exposure. SSH provides a built-in, encrypted channel for this transfer that’s hard to replicate safely with manual methods.
  • Increased Complexity: Skipping SSH means you lose the streamlined automation kubeadm provides. You’ll have to manage credential distribution, pre-flight checks, and consistency across nodes entirely by hand.
  • Version Compatibility: Not all kubeadm versions support skipping SSH phases. Double-check your Kubernetes version’s documentation to confirm the --skip-phases flag works for your setup.

Final Takeaway

While it’s technically possible to join worker nodes without SSH, it’s not the recommended approach. SSH key pairs are the simplest, most secure way to handle node joining in bare metal Kubernetes clusters. Only skip SSH if you have a strict, unavoidable requirement that prohibits it.

内容的提问来源于stack exchange,提问作者Sunil Gajula

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 03:44:16