You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

N节点全互联网隔离集群:能否配置kubelet从代理下载镜像?

Absolutely! You can definitely set up an internet-isolated N-node Kubernetes cluster and configure kubelet to pull container images from a specified proxy server. Let’s walk through this step by step—there are a few key pieces to get right, but it’s totally doable.

1. Setting Up the Internet-Isolated Cluster

First, you need to lock down the network and get Kubernetes installed without relying on external internet access:

  • Enforce Network Isolation: Make sure all master and worker nodes are completely cut off from the public internet. Use firewall rules, dedicated VLANs, or physical network separation to block all outbound traffic—except for traffic to your specified proxy server (if it’s outside the cluster) and internal cluster communication between nodes.
  • Prep Offline Installation Packages: Since you can’t pull binaries from the internet, download all required Kubernetes and container runtime packages on a machine with internet access first, then copy them to each cluster node. This includes:
    • kubeadm, kubelet, and kubectl binaries/packages matching your target Kubernetes version
    • Container runtime packages (like containerd or Docker) and their dependencies
  • Preload Core Kubernetes Images: Kubeadm needs core images (e.g., kube-apiserver, kube-controller-manager) to initialize the cluster. On your internet-connected machine, pull these images, save them to a tar file, then import them into each node’s container runtime. For example:
    # On a connected machine, pull and save images
    kubeadm config images pull
    kubeadm config images save --output k8s-core-images.tar
    # Copy the tar to each cluster node, then import
    ctr images import k8s-core-images.tar
    
  • Initialize the Cluster Offline: When running kubeadm init, specify your proxy/local registry as the image source to avoid internet calls:
    kubeadm init --image-repository=your-proxy-registry:5000 --pod-network-cidr=10.244.0.0/16
    
  • Join Worker Nodes: For each worker, ensure the kubelet package is installed, core images are preloaded, then run the kubeadm join command provided by the master node (make sure nodes can communicate internally).
2. Configuring Kubelet to Pull from Your Proxy

This depends on whether your proxy is a container registry proxy (the most common setup for isolated environments) or a standard HTTP/HTTPS proxy.

A registry proxy (like Harbor, Nexus, or a simple Docker registry with caching) stores or mirrors all the images your cluster needs. Here’s how to set it up:

  • Populate the Registry: On an internet-connected machine, pull the images you need (business images, extra K8s add-ons), retag them to point to your proxy registry, then push them (you’ll need temporary network access between the connected machine and your isolated proxy). Example:
    docker pull nginx:latest
    docker tag nginx:latest your-proxy-registry:5000/nginx:latest
    docker push your-proxy-registry:5000/nginx:latest
    
  • Configure Kubelet to Use the Registry: You have a few options here:
    1. Edit the kubelet config file: Open /var/lib/kubelet/config.yaml and add the imageRepository field:
      imageRepository: "your-proxy-registry:5000"
      
      Restart kubelet afterward: systemctl restart kubelet
    2. Update the kubelet systemd service: Edit /etc/systemd/system/kubelet.service.d/10-kubeadm.conf and add --image-repository=your-proxy-registry:5000 to the KUBELET_EXTRA_ARGS line. Then run:
      systemctl daemon-reload
      systemctl restart kubelet
      
    3. Configure the container runtime: If using containerd, set up a mirror so all image pulls go through your proxy. Edit /etc/containerd/config.toml:
      [plugins."io.containerd.grpc.v1.cri".registry.mirrors]
        [plugins."io.containerd.grpc.v1.cri".registry.mirrors."docker.io"]
          endpoint = ["http://your-proxy-registry:5000"]
      
      Restart containerd: systemctl restart containerd

2.2 Using an HTTP/HTTPS Proxy (Less Common for Isolated Clusters)

If your proxy is a standard HTTP/HTTPS proxy that routes requests to external registries (and your cluster can reach this proxy, but not the public internet directly), configure kubelet to use it:

  • Add proxy environment variables to kubelet: Edit the kubelet systemd service file (e.g., /etc/systemd/system/kubelet.service.d/10-kubeadm.conf) and add these lines under the [Service] section:
    Environment="HTTP_PROXY=http://your-proxy-server:8080"
    Environment="HTTPS_PROXY=http://your-proxy-server:8080"
    Environment="NO_PROXY=localhost,127.0.0.1,cluster.local,10.244.0.0/16,10.96.0.0/12"
    
    The NO_PROXY list should include your cluster’s pod and service CIDRs to avoid proxying internal cluster traffic. Then reload and restart:
    systemctl daemon-reload
    systemctl restart kubelet
    
3. Verify Everything Works

To confirm your setup works, deploy a test pod using an image from your proxy:

apiVersion: v1
kind: Pod
metadata:
  name: test-proxy-pull
spec:
  containers:
  - name: nginx-test
    image: nginx:latest

Run kubectl apply -f test-pod.yaml, then check the pod status with kubectl get pods. If it shows Running, the image was pulled successfully. You can also check kubelet logs with journalctl -u kubelet -f to ensure no pull errors.

内容的提问来源于stack exchange,提问作者Nicola Ben

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:54:05