Import Tencent Cloud TKE cluster
Integrate the deployed Tencent Cloud TKE standalone cluster or Tencent Cloud TKE managed cluster into the platform for unified management.
Tip: For the product introduction of TKE standalone cluster or Tencent Cloud TKE managed cluster, please refer to the official documentation .
Prerequisites
-
The Kubernetes version and parameters on the cluster meet the requirements of Access Standard Kubernetes Cluster Component Versions and Parameter Requirements .
-
The repository must support HTTPS access and provide a valid TLS certificate authenticated by a public certificate authority.
Get Image Registry Address
-
To use the repository for deploying the platform globally, execute the following command on the control node of the global deployment to obtain the address:
if [ "$(kubectl get productbase -o jsonpath='{.items[].spec.registry.preferPlatformURL}')" = 'false' ]; then REGISTRY=$(kubectl get cm -n kube-public global-info -o jsonpath='{.data.registryAddress}') else REGISTRY=$(kubectl get cm -n kube-public global-info -o jsonpath='{.data.platformURL}' | awk -F \// '{print $NF}') fi echo "repositoryAddress is:$REGISTRY" -
If you need to use an external repository, please manually set the REGISTRY variable.
REGISTRY=<externalrepositoryaddress> # valid examples such as:registry.example.cn:60080 or 192.168.134.43 echo "repositoryaddress is:$REGISTRY"
Determine if Additional Configuration Needed for Image Registry
-
Execute the following command to determine if the specified repository supports HTTPS access and uses a certificate issued by a trusted CA authority:
REGISTRY=<“GetrepositoryAddress”Obtained in SectionrepositoryAddress> if curl -s -o /dev/null --retry 5 --retry-delay 10 -- "https://${REGISTRY}/v2/"; then echo 'Passed the Check:repositoryUsing Trusted CA Certificate Issued by Certification Authority。No Need to Execute“Trust Non-Securerepository”Content of Section。' else echo 'Failed the Check:repositoryNot Supported HTTPS,Or Certificate is Not Trusted。Please Refer to“Trust Non-Securerepository”Configure in Section。' fi -
If the test fails, please refer to the common question How to trust an insecure repository? .
Get KubeConfig
-
Log in to the Tencent Cloud Container Service Management Platform.
-
In Cluster Details > Basic Information, check the information of Cluster APIServer.
-
Download the Kubeconfig file to your local machine based on the actual network configuration, either for external network access or internal network access.
Cluster of access
-
In the left navigation pane, click Clusters > Cluster of clusters.
-
Click on Cluster of access.
-
Configure the relevant parameters according to the following instructions.
Parameter Description repository The repository that stores the platform components images required by the cluster.
- Default repository: The repository configured when deploying global.
- Private repository: A pre-built repository that stores the platform components. You need to enter the private repository address, port, username, and password to access the repository.
- Public repository: Use a repository service located on the public network. Before using it, you need to refer to Updating public network repository cloud credentials to obtain repository authentication permissions.Cluster Information Note: You can manually fill in or upload the KubeConfig file for the platform to automatically parse and fill in.
Parse KubeConfig file: After uploading the obtained KubeConfig file, the platform will automatically parse and fill in the Cluster Information, and you can modify the automatically filled information.
Cluster Address: The access address of the cluster’s API Server exposed to the outside, used for the platform to access the cluster’s API Server.
CA Certificate: The CA certificate of the cluster.
Note: When manually entering, you need to enter the decoded certificate in Base64.
Authentication Method: The authentication method used to access the cluster, which requires using a token or certificate authentication (client certificate and key) with cluster management permissions. -
Click on Check Connectivity to verify the network connectivity with the connected cluster and automatically identify the type of the connected cluster. The cluster type will be displayed as a badge in the top right corner of the form.
-
After passing the connectivity check, click on Connect and confirm.
Tip:
-
Use the
kubectlcommand to interact with the Kubernetes cluster. -
The
kubectl getcommand is used to retrieve information about resources in the cluster. -
The
kubectl describecommand provides detailed information about a specific resource. -
The
kubectl createcommand is used to create new resources in the cluster. -
The
kubectl applycommand is used to apply changes to existing resources. -
The
kubectl deletecommand is used to delete resources from the cluster. -
The
kubectl editcommand is used to edit resources in the cluster. -
The
kubectl execcommand is used to execute commands in a running container. -
The
kubectl logscommand is used to view the logs of a container. -
The
kubectl port-forwardcommand is used to forward a local port to a port on a pod. -
The
kubectl scalecommand is used to scale the number of replicas of a resource. -
The
kubectl rolloutcommand is used to manage rollouts and rollbacks of deployments. -
The
kubectl labelcommand is used to add or modify labels on resources. -
The
kubectl annotatecommand is used to add or modify annotations on resources. -
The
kubectl get eventscommand is used to view events in the cluster. -
The
kubectl topcommand is used to view resource usage in the cluster. -
The
kubectl apply -fcommand is used to apply changes from a YAML file. -
The
kubectl explaincommand is used to view the documentation of a resource. -
The
kubectl configcommand is used to manage the Kubernetes configuration. -
The
kubectl cluster-infocommand is used to view information about the cluster. -
The
kubectl versioncommand is used to view the version of the Kubernetes client and server.-
Click on the
icon on the right side of the cluster in the In Progress state to view the execution progress of the cluster (status.conditions) in the popped-up Execution Progress dialog box. -
After successful cluster access, you can view key information about the cluster in the cluster list. The status of the cluster is displayed as normal, and you can perform cluster-related operations.
-
Network Configuration
To ensure global connectivity with the connected cluster network, please refer to the configuration related to accessing the cluster network .
What’s next
Deployment plugins
After successfully accessing the cluster, you can go to Plugin Management to select the necessary plugins for cluster deployment, including monitoring components, Log Agent, log storage components, etc.
Namespace under the tube cluster
After accessing the cluster, you can add the cluster to an existing project by creating a project based on the cluster or by adding a cluster associated with the project , thus associating the newly accessed cluster with the project.
Furthermore, by using the import namespace operation, existing Kubernetes namespaces within the cluster can be included and managed under the platform’s project.
FAQ
The Add node button is grayened after accessing the cluster. How to add nodes?
TKE Standalone Cluster and TKE Managed Cluster do not support adding nodes through the platform interface. Please add nodes in the background or contact the cluster provider to add them.
Which certificates are supported by the certificate management function of the access cluster?
-
Kubernetes certificate: All access to the cluster only supports viewing the APIServer certificate information in the platform’s certificate management interface. It does not support viewing other Kubernetes certificates and does not support automatic rotation.
-
Platform Component Certificate: All access to the cluster can view the platform component certificate information in the platform certificate management interface and support automatic rotation.
What other features do not support access to **TKE managed cluster ** and **TKE independent cluster **?
-
TKE Managed Cluster does not support retrieving audit data.
-
TKE Managed Cluster does not support monitoring information for ETCD, Scheduler, and Controller Manager, but it does support monitoring charts for APIServer.
-
Both TKE Managed Cluster and TKE Standalone Cluster do not support obtaining cluster certificate-related information other than the Kubernetes APIServer certificate.