N节点全互联网隔离集群:能否配置kubelet从代理下载镜像?
Absolutely! You can definitely set up an internet-isolated N-node Kubernetes cluster and configure kubelet to pull container images from a specified proxy server. Let’s walk through this step by step—there are a few key pieces to get right, but it’s totally doable.
First, you need to lock down the network and get Kubernetes installed without relying on external internet access:
- Enforce Network Isolation: Make sure all master and worker nodes are completely cut off from the public internet. Use firewall rules, dedicated VLANs, or physical network separation to block all outbound traffic—except for traffic to your specified proxy server (if it’s outside the cluster) and internal cluster communication between nodes.
- Prep Offline Installation Packages: Since you can’t pull binaries from the internet, download all required Kubernetes and container runtime packages on a machine with internet access first, then copy them to each cluster node. This includes:
- kubeadm, kubelet, and kubectl binaries/packages matching your target Kubernetes version
- Container runtime packages (like containerd or Docker) and their dependencies
- Preload Core Kubernetes Images: Kubeadm needs core images (e.g., kube-apiserver, kube-controller-manager) to initialize the cluster. On your internet-connected machine, pull these images, save them to a tar file, then import them into each node’s container runtime. For example:
# On a connected machine, pull and save images kubeadm config images pull kubeadm config images save --output k8s-core-images.tar # Copy the tar to each cluster node, then import ctr images import k8s-core-images.tar - Initialize the Cluster Offline: When running
kubeadm init, specify your proxy/local registry as the image source to avoid internet calls:kubeadm init --image-repository=your-proxy-registry:5000 --pod-network-cidr=10.244.0.0/16 - Join Worker Nodes: For each worker, ensure the kubelet package is installed, core images are preloaded, then run the
kubeadm joincommand provided by the master node (make sure nodes can communicate internally).
This depends on whether your proxy is a container registry proxy (the most common setup for isolated environments) or a standard HTTP/HTTPS proxy.
2.1 Using a Container Registry Proxy (Recommended)
A registry proxy (like Harbor, Nexus, or a simple Docker registry with caching) stores or mirrors all the images your cluster needs. Here’s how to set it up:
- Populate the Registry: On an internet-connected machine, pull the images you need (business images, extra K8s add-ons), retag them to point to your proxy registry, then push them (you’ll need temporary network access between the connected machine and your isolated proxy). Example:
docker pull nginx:latest docker tag nginx:latest your-proxy-registry:5000/nginx:latest docker push your-proxy-registry:5000/nginx:latest - Configure Kubelet to Use the Registry: You have a few options here:
- Edit the kubelet config file: Open
/var/lib/kubelet/config.yamland add theimageRepositoryfield:
Restart kubelet afterward:imageRepository: "your-proxy-registry:5000"systemctl restart kubelet - Update the kubelet systemd service: Edit
/etc/systemd/system/kubelet.service.d/10-kubeadm.confand add--image-repository=your-proxy-registry:5000to theKUBELET_EXTRA_ARGSline. Then run:systemctl daemon-reload systemctl restart kubelet - Configure the container runtime: If using containerd, set up a mirror so all image pulls go through your proxy. Edit
/etc/containerd/config.toml:
Restart containerd:[plugins."io.containerd.grpc.v1.cri".registry.mirrors] [plugins."io.containerd.grpc.v1.cri".registry.mirrors."docker.io"] endpoint = ["http://your-proxy-registry:5000"]systemctl restart containerd
- Edit the kubelet config file: Open
2.2 Using an HTTP/HTTPS Proxy (Less Common for Isolated Clusters)
If your proxy is a standard HTTP/HTTPS proxy that routes requests to external registries (and your cluster can reach this proxy, but not the public internet directly), configure kubelet to use it:
- Add proxy environment variables to kubelet: Edit the kubelet systemd service file (e.g.,
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf) and add these lines under the[Service]section:
TheEnvironment="HTTP_PROXY=http://your-proxy-server:8080" Environment="HTTPS_PROXY=http://your-proxy-server:8080" Environment="NO_PROXY=localhost,127.0.0.1,cluster.local,10.244.0.0/16,10.96.0.0/12"NO_PROXYlist should include your cluster’s pod and service CIDRs to avoid proxying internal cluster traffic. Then reload and restart:systemctl daemon-reload systemctl restart kubelet
To confirm your setup works, deploy a test pod using an image from your proxy:
apiVersion: v1 kind: Pod metadata: name: test-proxy-pull spec: containers: - name: nginx-test image: nginx:latest
Run kubectl apply -f test-pod.yaml, then check the pod status with kubectl get pods. If it shows Running, the image was pulled successfully. You can also check kubelet logs with journalctl -u kubelet -f to ensure no pull errors.
内容的提问来源于stack exchange,提问作者Nicola Ben

