[vagrant@master01 ~]$ kubectl create -f example-nad-pod.yml pod/example-nad-pod created
[vagrant@master01 ~]$ k get pod -n example-multus NAME READY STATUS RESTARTS AGE example-nad-pod 1/1 Running 0 10s
[vagrant@master01 ~]$ kubectl describe pod example-nad-pod -n example-multus Name: example-nad-pod Namespace: example-multus Priority: 0 Service Account: default Node: worker01.example.com/192.168.121.27 Start Time: Sun, 05 May 2024 13:05:38 +0000 Labels: <none> Annotations: cni.projectcalico.org/containerID: 81dcd5467f0d8be6275f61c0b22329086c5bc18a7fa595031696bd200b6708a0 cni.projectcalico.org/podIP: 10.42.95.152/32 cni.projectcalico.org/podIPs: 10.42.95.152/32 k8s.v1.cni.cncf.io/network-status: [{ "name": "k8s-pod-network", "ips": [ "10.42.95.152" ], "default": true, "dns": {} },{ "name": "example-multus/example-nad", "interface": "net1", "ips": [ "192.168.122.188" ], "mac": "52:54:00:26:5a:9f", "dns": {} }] k8s.v1.cni.cncf.io/networks: [{ "name": "example-nad", "namespace": "example-multus", "ips": ["192.168.122.188/24"] }] Status: Running IP: 10.42.95.152 IPs: IP: 10.42.95.152 Containers: samplepod: Container ID: containerd://ff28ad8ac418342ca212763184600e313b287bc8e92b386ef3e81de52f6f953c Image: alpine Image ID: docker.io/library/alpine@sha256:c5b1261d6d3e43071626931fc004f70149baeba2c8ec672bd4f27761f8e1ad6b Port: <none> Host Port: <none> Command: /bin/ash -c trap : TERM INT; sleep infinity & wait State: Running Started: Sun, 05 May 2024 13:05:41 +0000 Ready: True Restart Count: 0 Environment: <none> Mounts: /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-d44h6 (ro) Conditions: Type Status Initialized True Ready True ContainersReady True PodScheduled True Volumes: kube-api-access-d44h6: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3607 ConfigMapName: kube-root-ca.crt ConfigMapOptional: <nil> DownwardAPI: true QoS Class: BestEffort Node-Selectors: <none> Tolerations: node.kubernetes.io/not-ready:NoExecute op=Exists for 300s node.kubernetes.io/unreachable:NoExecute op=Exists for 300s Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal Scheduled 76s default-scheduler Successfully assigned example-multus/example-nad-pod to worker01.example.com Normal AddedInterface 75s multus Add eth0 [10.42.95.152/32] from k8s-pod-network Normal AddedInterface 75s multus Add net1 [192.168.122.188/24] from example-multus/example-nad Normal Pulling 75s kubelet Pulling image "alpine" Normal Pulled 73s kubelet Successfully pulled image "alpine"in 2.218s (2.218s including waiting) Normal Created 73s kubelet Created container samplepod Normal Started 73s kubelet Started container samplepod
在 Events 中可以看到已经将 192.168.122.188 分配给 Pod 。
在 Pod 中查看网络信息:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
[vagrant@master01 ~]$ kubectl -n example-multus exec example-nad-pod -- ip a 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0@if24: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1450 qdisc noqueue state UP qlen 1000 link/ether 96:fa:00:7d:38:8a brd ff:ff:ff:ff:ff:ff inet 10.42.95.152/32 scope global eth0 valid_lft forever preferred_lft forever inet6 fe80::94fa:ff:fe7d:388a/64 scope link valid_lft forever preferred_lft forever 3: net1@net1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN link/ether 52:54:00:26:5a:9f brd ff:ff:ff:ff:ff:ff inet 192.168.122.188/24 brd 192.168.122.255 scope global net1 valid_lft forever preferred_lft forever inet6 fe80::5254:0:126:5a9f/64 scope link valid_lft forever preferred_lft forever
其中 eth0 是默认的 Pod 网络,net1 是通过 Multus 添加的附加网络。 此时可以从集群外部与 Pod 进行通信:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
hcai@P1-Gen4:~$ ip a s virbr0 5: virbr0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000 link/ether 52:54:00:e8:39:b6 brd ff:ff:ff:ff:ff:ff inet 192.168.122.1/24 brd 192.168.122.255 scope global virbr0 valid_lft forever preferred_lft forever hcai@P1-Gen4:~$ ping -c 4 192.168.122.188 PING 192.168.122.188 (192.168.122.188) 56(84) bytes of data. 64 bytes from 192.168.122.188: icmp_seq=1 ttl=64 time=0.244 ms 64 bytes from 192.168.122.188: icmp_seq=2 ttl=64 time=0.242 ms 64 bytes from 192.168.122.188: icmp_seq=3 ttl=64 time=0.175 ms 64 bytes from 192.168.122.188: icmp_seq=4 ttl=64 time=0.144 ms
--- 192.168.122.188 ping statistics --- 4 packets transmitted, 4 received, 0% packet loss, time 3049ms rtt min/avg/max/mdev = 0.144/0.201/0.244/0.043 ms
NetworkAttachDefiniton 类型
可以创建以下 NAD 类型:
host-device :将网络接口附加到单个 Pod
bridge:在节点上使用现有的网络接口,或者配置一个新的网桥,连接到该网络的 Pod 可以通过 bridge 相互通信,也可以与连接到该 bridge 的任何其它网络通信
IPVLAN:创建基于 IPVLAN 并附加到网络接口的网络
MACVLAN: 创建基于 MACVLAN 并附加网络接口的网络
其中 bridge 非常适合虚拟化环境,IPVLAN 和 MACVLAN 是专为容器环境设计的 Linux 网络驱动程序。
IPVLAN 和 MACVLAN 是两种不同的虚拟网络技术它们的主要区别在于 MAC 地址和 IP 地址的分配以及数据包的路由方式
评论· · · · · ·