0
点赞
收藏
分享

微信扫一扫

k8s中安装Jenkins(Docker Desktop for Mac补充)

求索大伟 2022-04-04 阅读 64

原文:k8s中安装Jenkins

创建NFS共享目录用于Jenkins持久化

MacBook启用NFS服务

创建ServiceAccount

需要一个拥有相关权限的serviceAccount的Jenkins用户:vim jenkins-sa.yaml

apiVersion: v1
kind: ServiceAccount
metadata:
  name: jenkins-sa

执行创建ServiceAccount:kubectl create -f jenkins-sa.yaml
查看ServiceAccount:kubectl get sa
在这里插入图片描述

创建ClusterRole

创建角色:vim jenkins-clusterRole.yaml

kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  name: jenkins-clusterRole
rules:
  - apiGroups: ["extensions", "apps"]
    resources: ["deployments"]
    verbs: ["create", "delete", "get", "list", "watch", "patch", "update"]
  - apiGroups: [""]
    resources: ["services"]
    verbs: ["create", "delete", "get", "list", "watch", "patch", "update"]
  - apiGroups: [""]
    resources: ["pods"]
    verbs: ["create","delete","get","list","patch","update","watch"]
  - apiGroups: [""]
    resources: ["pods/exec"]
    verbs: ["create","delete","get","list","patch","update","watch"]
  - apiGroups: [""]
    resources: ["pods/log"]
    verbs: ["get","list","watch"]
  - apiGroups: [""]
    resources: ["secrets"]
    verbs: ["get"]

执行创建ClusterRole:kubectl create -f jenkins-clusterRole.yaml
查看ClusterRole:kubectl get clusterRole|grep jenkins
在这里插入图片描述

创建ClusterRoleBinding

创建角色绑定:vim jenkins-clusterRoleBinding.yaml

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: jenkins-clusterRoleBinding
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: jenkins-clusterRole
subjects:
  - kind: ServiceAccount
    name: jenkins-sa
    namespace: default # 默认命名空间下也需要添加此行

执行创建ClusterRoleBinding:kubectl create -f jenkins-clusterRoleBinding.yaml
查看ClusterRoleBinding:kubectl get clusterRoleBinding|grep jenkins
在这里插入图片描述

创建Deployment

创建Deployment定义vim jenkins-deploy.yaml

apiVersion: apps/v1
kind: Deployment
metadata:
  name: jenkins-deploy         #deployment名称
spec:
  replicas: 1
  selector:
    matchLabels:
      app: jenkins
  template:
    metadata:
      labels:
        app: jenkins
    spec:
      terminationGracePeriodSeconds: 10     #优雅停止pod
      serviceAccount: jenkins-sa            #后面还需要创建服务账户
      containers:
      - name: jenkins
        image: jenkins/jenkins:2.332.1 #镜像版本
        imagePullPolicy: IfNotPresent
        ports:
        - containerPort: 8080                #外部访问端口
          name: web
          protocol: TCP
        - containerPort: 50000              #jenkins save发现端口
          name: agent
          protocol: TCP
        resources:
          limits:
            cpu: 2
            memory: 1Gi
          requests:
            cpu: 1
            memory: 512Mi
        livenessProbe:
          httpGet:
            path: /login
            port: 8080
          initialDelaySeconds: 60          #容器初始化完成后,等待60秒进行探针检查
          timeoutSeconds: 5
          failureThreshold: 12          #当Pod成功启动且检查失败时,Kubernetes将在放弃之前尝试failureThreshold次。放弃生存检查意味着重新启动Pod。而放弃就绪检查,Pod将被标记为未就绪。默认为3.最小值为1
        readinessProbe:
          httpGet:
            path: /login
            port: 8080
          initialDelaySeconds: 60
          timeoutSeconds: 5
          failureThreshold: 12
        volumeMounts:                       #需要将jenkins_home目录挂载出来
        - name: jenkins-home
          mountPath: /var/jenkins_home
        env:
        - name: LIMITS_MEMORY
          valueFrom:
            resourceFieldRef:
              resource: limits.memory
              divisor: 1Mi
        - name: JAVA_OPTS # -Dhudson.model.DownloadService.noSignatureCheck=true 关闭源配置检查,否则换源后可能无法使用
          value: -Xmx$(LIMITS_MEMORY)m -XshowSettings:vm -Dhudson.slaves.NodeProvisioner.initialDelay=0 -Dhudson.slaves.NodeProvisioner.MARGIN=50 -Dhudson.slaves.NodeProvisioner.MARGIN0=0.85 -Duser.timezone=Asia/Shanghai -Dhudson.model.DownloadService.noSignatureCheck=true -Dhudson.model.UpdateCenter.updateCenterUrl=https://mirrors.tuna.tsinghua.edu.cn/jenkins/updates/
      securityContext:
        fsGroup: 1000
      volumes:
      - name: jenkins-home
        hostPath: #此处可自定义本地已存在的路径
          path: /opt/jenkins/data

执行创建Deployment:kubectl create -f jenkins-deploy.yaml
等待两分钟左右,执行以下指令确认jenkins已成功启动:
查看Deployment:kubectl get deploy
查看Pod:kubectl get po
在这里插入图片描述

创建集群访问入口

创建服务定义vim jenkins-svc.yaml

apiVersion: v1
kind: Service
metadata:
  name: jenkins-svc
spec:
  selector:
    app: jenkins
  type: NodePort
  ports:
  - name: web
    port: 8080
    targetPort: web
    nodePort: 30190
  - name: agent
    port: 50000
    targetPort: agent

执行创建服务:kubectl create -f jenkins-svc.yaml
查看服务:kubectl get svc
在这里插入图片描述

访问集群

浏览器访问:localhost:30190/login
在这里插入图片描述
获取密码,路径拼接持久化目录+上图中的url(/var/jenkins_home/secrets/initialAdminPassword),因/var/jenkins_home映射到subpath:jenkins,故此处替换下:
cat /Users/renzhengxin/IdeaProjects/k8s/jenkins/v2340/data/jenkins/secrets/initialAdminPassword
在这里插入图片描述
登录成功!
在这里插入图片描述
此处点击使用选择插件来安装,点击,暂不安装任何插件,点击安装进入下一步
在这里插入图片描述
如果无创建用户需求,点击使用admin账户继续即可。
在这里插入图片描述
实例配置使用默认值:
在这里插入图片描述
配置完成,点击开始使用Jenkins:
在这里插入图片描述
配置完成,跳转到主页:
在这里插入图片描述

参考文档

基于Kubernetes Jenkins CICD(项目实战)
Jenkins启动参数
jenkins安装提示Please wait while Jenkins is getting ready to work…(Jenkins访问资源慢的问题)
Docker Desktop for Mac ACL权限控制
Docker Desktop for Mac user manual

举报

相关推荐

0 条评论