1、生产一个永久的token(使用参数--ttl 0 )
[root@k8s-master ~]# kubeadm token create //默认有效期24小时,若想久一些可以结合--ttl参数,设为0则用不过期
kk0ee6.nhvz5p85avmzyof3
2、查看当前有效的token
[root@k8s-master ~]# kubeadm token list
TOKEN TTL EXPIRES USAGES DESCRIPTION EXTRA GROUPS
bgis60.aubeva3pjl9vf2qx 6h 2020-02-04T17:24:00+08:00 authentication,signing The default bootstrap token generated by 'kubeadm init'. system:bootstrappers:kubeadm:default-node-token
kk0ee6.nhvz5p85avmzyof3 23h 2020-02-05T11:02:44+08:00 authentication,signing <none> system:bootstrappers:kubeadm:default-node-token
3、获取ca证书sha256编码hash值
[root@k8s-master ~]# openssl x509 -pubkey -in /etc/kubernetes/pki/ca.crt | openssl rsa -pubin -outform der 2>/dev/null | openssl dgst -sha256 -hex | sed 's/^.* //'
9db128fe4c68b0e65c19bb49226fc717e64e790d23816c5615ad6e21fbe92020
即可使用 kubeadm join来将节点加入到集群中
[root@k8s-node1 ~]# kubeadm join 10.129.6.105:6443 --token 65dv57.r44t9rbfbg3j3g3h --discovery-token-ca-cert-hash sha256:b5b2b5d414694f1392a34e34ddb87497d8cc0192597819c0f08fffa305f63749