You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从单点修改集群所有节点的Kubelet配置添加指定参数?

Great question—manually editing each node's config is definitely a pain. Here are a few reliable, scalable ways to update the kubelet config across all nodes from a single point:

1. Quick Batch Execution with kubectl debug

This is a fast, ad-hoc solution that leverages Kubernetes built-in tools to run commands directly on node hosts:

First, iterate over all nodes and use kubectl debug to spawn a privileged container that modifies the host's kubelet config, reloads systemd, and restarts kubelet:

for node in $(kubectl get nodes -o name | cut -d'/' -f2); do
  kubectl debug node/$node -it --image=busybox:1.36 -- sh << EOF
    # Append the flag to the KUBELET_AUTHZ_ARGS line
    sed -i '/KUBELET_AUTHZ_ARGS=/ s/$/ --authentication-token-webhook/' /host/etc/systemd/system/kubelet.service.d/10-kubeadm.conf
    # Reload systemd and restart kubelet on the host
    chroot /host systemctl daemon-reload
    chroot /host systemctl restart kubelet
    exit
EOF
done

Note: This requires your nodes to allow privileged pod execution, and the busybox image to be accessible. The command will automatically handle control plane nodes thanks to kubectl debug's node access.

2. DaemonSet for Scalable, Cluster-Wide Updates

For larger clusters, a DaemonSet ensures the config change runs on every node (including any new nodes you add later, if you leave it running temporarily):

Create a kubelet-config-updater.yaml file with this content:

apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: kubelet-config-updater
  namespace: kube-system
spec:
  selector:
    matchLabels:
      name: kubelet-config-updater
  template:
    metadata:
      labels:
        name: kubelet-config-updater
    spec:
      hostPID: true
      hostNetwork: true
      tolerations:
        # Ensure the pod runs on control plane nodes too
        - key: node-role.kubernetes.io/control-plane
          operator: Exists
          effect: NoSchedule
        - key: node-role.kubernetes.io/master
          operator: Exists
          effect: NoSchedule
      containers:
        - name: updater
          image: busybox:1.36
          command: ["/bin/sh", "-c"]
          args:
            - |
              # Modify the kubelet config file on the host
              sed -i '/KUBELET_AUTHZ_ARGS=/ s/$/ --authentication-token-webhook/' /host/etc/systemd/system/kubelet.service.d/10-kubeadm.conf
              # Reload systemd and restart kubelet
              chroot /host systemctl daemon-reload
              chroot /host systemctl restart kubelet
              sleep infinity  # Keep container running (optional; remove to exit after execution)
          volumeMounts:
            - name: host-root
              mountPath: /host
      volumes:
        - name: host-root
          hostPath:
            path: /

Apply the DaemonSet:

kubectl apply -f kubelet-config-updater.yaml

Once all pods have completed the update, you can delete the DaemonSet to clean up:

kubectl delete daemonset kubelet-config-updater -n kube-system

If your cluster was deployed with kubeadm, this method ensures the config change is managed centrally and persists across node upgrades or new node joins:

  1. Export your current kubeadm cluster configuration:
kubeadm config view > kubeadm-config.yaml
  1. Edit kubeadm-config.yaml to add the kubelet flag. Look for the kubeletConfiguration section and add either the structured config or direct command-line argument:
kubeletConfiguration:
  # Keep existing config fields...
  authentication:
    webhook:
      enabled: true
  # Alternatively, add as an extra argument:
  extraArgs:
    authentication-token-webhook: "true"
  1. Apply the updated config to the cluster:
kubeadm init phase kubelet-config write-to-disk --config kubeadm-config.yaml
  1. Finally, push the config to all nodes (use a loop to batch this command):
for node in $(kubectl get nodes -o name | cut -d'/' -f2); do
  kubectl debug node/$node -it --image=busybox:1.36 -- sh << EOF
    chroot /host kubeadm upgrade node phase kubelet-config
    exit
EOF
done

This will automatically update each node's kubelet config and restart the service, and any future nodes added with kubeadm join will inherit this setting.

Verification

To confirm the change worked on all nodes, run:

for node in $(kubectl get nodes -o name | cut -d'/' -f2); do
  echo "Checking node $node:"
  kubectl debug node/$node --image=busybox:1.36 -- sh -c "chroot /host ps aux | grep kubelet | grep authentication-token-webhook"
done

内容的提问来源于stack exchange,提问作者Ivan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:33:46