CentOS 7 上稳定OpenShift-ansible(Origin)版本及多节点安装咨询
Hey there! Let me break this down for you clearly from my hands-on experience:
适用于CentOS 7的最新稳定版OpenShift Origin(OKD)及对应openshift-ansible版本
OpenShift Origin was officially renamed to OKD later on. The latest stable branch that fully supports CentOS 7 is OKD 3.11 — this is also the last major stable release with official CentOS 7 support (subsequent 4.x versions dropped CentOS 7 support and shifted to RHEL 8/Fedora-based distros). The matching latest stable openshift-ansible toolkit belongs to the 3.11.x series; you can grab its final release by cloning the official repo's release-3.11 branch:
git clone https://github.com/openshift/openshift-ansible.git cd openshift-ansible git checkout release-3.11
多节点安装实战经验 & 踩坑技巧
I've set up OKD 3.11 multi-node clusters multiple times, so here are some hard-earned tips to save you headaches:
Pre-install Must-Dos
- Hardware & System Checks: Each node needs at least 2 CPU cores and 8GB RAM (master nodes should have 4 cores + 16GB RAM for stability), plus a minimum 50GB disk space (container images and logs eat up space fast). Make sure your CentOS 7 is version 7.6 or newer; update first and reboot:
yum update -y && reboot - Disable Troublesome Services:
- Turn off
firewalld(it often causes compatibility issues; use iptables instead or configure rules manually):systemctl stop firewalld && systemctl disable firewalld - Disable SELinux (both temporarily and permanently — permission issues here will ruin your day):
setenforce 0 sed -i 's/^SELINUX=.*/SELINUX=disabled/' /etc/selinux/config - Turn off swap (Kubernetes/OKD requires this strictly):
swapoff -a sed -i '/swap/d' /etc/fstab
- Turn off
- Network & Hostname Setup: All nodes must resolve each other's hostnames reliably — editing
/etc/hostsis the most foolproof way (don't rely on flaky DNS). Also, sync system time across all nodes withchronyd(a time difference over 5 minutes will break the cluster):yum install chronyd -y systemctl start chronyd && systemctl enable chronyd
Ansible Configuration & Installation Phase
- Control Node Prep: Pick one node (can be a master or a dedicated control node) to install Ansible 2.7.x — OKD 3.11 only works with this version, don't install a newer one:
yum install ansible-2.7.* -y - Inventory File Tuning: This is the core of the setup! Double-check every entry. For small clusters, it's fine to reuse master nodes as etcd nodes. Here's a sample inventory snippet:
Key notes: Specify[OSEv3:children] masters nodes etcd [masters] master01.example.com ansible_user=root [nodes] master01.example.com openshift_node_group_name='node-config-master' node01.example.com openshift_node_group_name='node-config-compute' node02.example.com openshift_node_group_name='node-config-compute' [etcd] master01.example.comansible_useras root or a user with full sudo access, and make sureopenshift_node_group_namematches the correct node role. - Run Pre-check Playbook: Always run this before the actual installation to catch issues early:
It checks dependencies, open ports, and system configs — fix any errors before proceeding, don't force the installation.ansible-playbook playbooks/prerequisites.yml - Start Installation: Run the cluster deployment playbook with
-vto get detailed output, which helps with troubleshooting:
If it fails, don't just retry blindly. Check logs underansible-playbook playbooks/deploy_cluster.yml -v/var/log/openshift-ansible/first, then dig into specific node issues (e.g., usedocker logs <pod-name>on the problematic node if a container won't start).
Post-install Validation & Optimization
- Cluster Health Check: On the master node, run these commands to confirm everything is running:
Ensure all nodes showoc get nodes oc get pods --all-namespacesReadystatus and all core pods areRunning. - Common Issue Fixes:
- Image pull failures: Due to network restrictions, configure Docker image acceleration on all nodes beforehand or pull required images manually.
- Nodes can't join the cluster: Check if core ports (6443, 2379, 8443, etc.) are open between nodes, and verify hostname resolution works correctly.
- Permission errors: Make sure directories like
/var/lib/dockerand/var/lib/openshifthave the right permissions (owned by root and docker group).
Hope these tips help you get your cluster up and running smoothly! If you hit specific errors, feel free to share log snippets for further troubleshooting.
内容的提问来源于stack exchange,提问作者Adigun Gbenga

