login as: root
root@111.17.169.203's password:
Last failed login: Sat Jul 11 21:32:55 CST 2020 from 49.95.252.151 on ssh:notty
There was 1 failed login attempt since the last successful login.
Last login: Sat Jul 11 21:30:31 2020 from 49.95.252.151
Welcome to Huawei Cloud Service
[root@hecs-x-medium-2-linux-20200711102537 ~]# curl https://127.0.0.1:10443
curl: (60) Issuer certificate is invalid.
More details here: http://curl.haxx.se/docs/sslcerts.html
curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
the -k (or --insecure) option.
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s status --wait-ready
microk8s is running
addons:
dashboard: enabled
dns: enabled
helm: enabled
metrics-server: enabled
registry: enabled
storage: enabled
cilium: disabled
fluentd: disabled
gpu: disabled
helm3: disabled
host-access: disabled
ingress: disabled
istio: disabled
jaeger: disabled
knative: disabled
kubeflow: disabled
linkerd: disabled
metallb: disabled
prometheus: disabled
rbac: disabled
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl get all --all-na mespaces
NAMESPACE NAME READY STA TUS RESTARTS AGE
container-registry pod/registry-7cf58dcdcc-9x8x8 1/1 Run ning 2 6h19m
kube-system pod/coredns-588fd544bf-9qgv6 1/1 Run ning 2 6h19m
kube-system pod/dashboard-metrics-scraper-59f5574d4-b7b4b 1/1 Run ning 2 6h19m
kube-system pod/hostpath-provisioner-75fdc8fccd-m89wz 1/1 Run ning 2 6h19m
kube-system pod/kubernetes-dashboard-6d97855997-8bnsq 1/1 Run ning 2 6h19m
kube-system pod/metrics-server-c65c9d66-lkkck 1/1 Run ning 0 6h19m
NAMESPACE NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
container-registry service/registry NodePort 10.152.183. 130 <none> 5000:32000/TCP 6h19m
default service/kubernetes ClusterIP 10.152.183. 1 <none> 443/TCP 6h21m
kube-system service/dashboard-metrics-scraper ClusterIP 10.152.183. 173 <none> 8000/TCP 6h19m
kube-system service/kube-dns ClusterIP 10.152.183. 10 <none> 53/UDP,53/TCP,9153/TCP 6h19m
kube-system service/kubernetes-dashboard ClusterIP 10.152.183. 101 <none> 443/TCP 6h19m
kube-system service/metrics-server ClusterIP 10.152.183. 210 <none> 443/TCP 6h19m
NAMESPACE NAME READY UP-TO-D ATE AVAILABLE AGE
container-registry deployment.apps/registry 1/1 1 1 6h19m
kube-system deployment.apps/coredns 1/1 1 1 6h19m
kube-system deployment.apps/dashboard-metrics-scraper 1/1 1 1 6h19m
kube-system deployment.apps/hostpath-provisioner 1/1 1 1 6h19m
kube-system deployment.apps/kubernetes-dashboard 1/1 1 1 6h19m
kube-system deployment.apps/metrics-server 1/1 1 1 6h19m
NAMESPACE NAME DESIR ED CURRENT READY AGE
container-registry replicaset.apps/registry-7cf58dcdcc 1 1 1 6h19m
kube-system replicaset.apps/coredns-588fd544bf 1 1 1 6h19m
kube-system replicaset.apps/dashboard-metrics-scraper-59f5574d4 1 1 1 6h19m
kube-system replicaset.apps/hostpath-provisioner-75fdc8fccd 1 1 1 6h19m
kube-system replicaset.apps/kubernetes-dashboard-6d97855997 1 1 1 6h19m
kube-system replicaset.apps/metrics-server-c65c9d66 1 1 1 6h19m
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl get all --all-namespaces
NAMESPACE NAME READY STATUS RESTARTS AGE
container-registry pod/registry-7cf58dcdcc-9x8x8 1/1 Running 2 6h19 m
kube-system pod/coredns-588fd544bf-9qgv6 1/1 Running 2 6h20 m
kube-system pod/dashboard-metrics-scraper-59f5574d4-b7b4b 1/1 Running 2 6h20 m
kube-system pod/hostpath-provisioner-75fdc8fccd-m89wz 1/1 Running 2 6h19 m
kube-system pod/kubernetes-dashboard-6d97855997-8bnsq 1/1 Running 2 6h20 m
kube-system pod/metrics-server-c65c9d66-lkkck 1/1 Running 0 6h20 m
NAMESPACE NAME TYPE CLUSTER-IP EXTERNAL-IP PO RT(S) AGE
container-registry service/registry NodePort 10.152.183.130 <none> 50 00:32000/TCP 6h19m
default service/kubernetes ClusterIP 10.152.183.1 <none> 44 3/TCP 6h21m
kube-system service/dashboard-metrics-scraper ClusterIP 10.152.183.173 <none> 80 00/TCP 6h20m
kube-system service/kube-dns ClusterIP 10.152.183.10 <none> 53 /UDP,53/TCP,9153/TCP 6h20m
kube-system service/kubernetes-dashboard ClusterIP 10.152.183.101 <none> 44 3/TCP 6h20m
kube-system service/metrics-server ClusterIP 10.152.183.210 <none> 44 3/TCP 6h20m
NAMESPACE NAME READY UP-TO-DATE AVAILABLE AGE
container-registry deployment.apps/registry 1/1 1 1 6h19 m
kube-system deployment.apps/coredns 1/1 1 1 6h20 m
kube-system deployment.apps/dashboard-metrics-scraper 1/1 1 1 6h20 m
kube-system deployment.apps/hostpath-provisioner 1/1 1 1 6h19 m
kube-system deployment.apps/kubernetes-dashboard 1/1 1 1 6h20 m
kube-system deployment.apps/metrics-server 1/1 1 1 6h20 m
NAMESPACE NAME DESIRED CURRENT READY AGE
container-registry replicaset.apps/registry-7cf58dcdcc 1 1 1 6h19m
kube-system replicaset.apps/coredns-588fd544bf 1 1 1 6h20m
kube-system replicaset.apps/dashboard-metrics-scraper-59f5574d4 1 1 1 6h20m
kube-system replicaset.apps/hostpath-provisioner-75fdc8fccd 1 1 1 6h19m
kube-system replicaset.apps/kubernetes-dashboard-6d97855997 1 1 1 6h20m
kube-system replicaset.apps/metrics-server-c65c9d66 1 1 1 6h20m
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl get secrets --all-namespaces|grep dash board-token
kube-system kubernetes-dashboard-token-zwxvg kubernetes.io/service-account-to ken 3 6h23m
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl describe --namespace kube-system secrets kubernetes-dashboard-token-zwxvg
Name: kubernetes-dashboard-token-zwxvg
Namespace: kube-system
Labels: <none>
Annotations: kubernetes.io/service-account.name: kubernetes-dashboard
kubernetes.io/service-account.uid: d3940950-0251-4db4-b9f7-d448ec3b7992
Type: kubernetes.io/service-account-token
Data
====
ca.crt: 1103 bytes
namespace: 11 bytes
token: eyJhbGciOiJSUzI1NiIsImtpZCI6InpLNTBYaVdEY2FNbUxQeDQ3bExtenkyMm5qS0VUMm9wVGtGWFJYdllhLWcifQ.eyJpc3MiOiJrdWJlcm5ldGVzL3NlcnZpY2VhY2NvdW50Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9uYW1lc3BhY2UiOiJrdWJlLXN5c3RlbSIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VjcmV0Lm5hbWUiOiJrdWJlcm5ldGVzLWRhc2hib2FyZC10b2tlbi16d3h2ZyIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VydmljZS1hY2NvdW50Lm5hbWUiOiJrdWJlcm5ldGVzLWRhc2hib2FyZCIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VydmljZS1hY2NvdW50LnVpZCI6ImQzOTQwOTUwLTAyNTEtNGRiNC1iOWY3LWQ0NDhlYzNiNzk5MiIsInN1YiI6InN5c3RlbTpzZXJ2aWNlYWNjb3VudDprdWJlLXN5c3RlbTprdWJlcm5ldGVzLWRhc2hib2FyZCJ9.Gcly56i7IPpTd6VUWFZZjjQmRE4rCgvKD9jlTrHxrE5bG_M2x91GzzPNzHbMZpZX6-cJSC0h8u3Ncg79QoGAIMHVApSRVdZ_Xqt7T6s-vFwwwBB0SRvuLTwTMVzhVyJ7rpdluwoGlljKT3Sek2OoyuHko2yYdCI9zMUJnx4TmMI7F5X-M6vD3j05LgjFg4BFFb53el0F9jXRxH4RHpa9ozHBwCmTh_g_j0mdWXiW2dNLr0S5iCLU10Y87YNlLR-nJCwWO9oZNYdKrVL_PCuK1XsbazVWdbIM6aui8ML23ZIa1EWQOcM7cIQQil6hsCHdylZkA8ctjPmsJhwmFJzFWw
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl get pods --all-namespaces|grep dashboard
kube-system dashboard-metrics-scraper-59f5574d4-b7b4b 1/1 Running 2 6h37m
kube-system kubernetes-dashboard-6d97855997-8bnsq 1/1 Running 2 6h37m
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl describe --namespace kube-system pod/kubernetes-dashboard-6d97855997-8bnsq
Name: kubernetes-dashboard-6d97855997-8bnsq
Namespace: kube-system
Priority: 0
Node: hecs-x-medium-2-linux-20200711102537/192.168.0.192
Start Time: Sat, 11 Jul 2020 15:17:27 +0800
Labels: k8s-app=kubernetes-dashboard
pod-template-hash=6d97855997
Annotations: <none>
Status: Running
IP: 10.1.86.17
IPs:
IP: 10.1.86.17
Controlled By: ReplicaSet/kubernetes-dashboard-6d97855997
Containers:
kubernetes-dashboard:
Container ID: containerd://0b24cf77ea2d3881bcabfda1c6c5eb70aa021f6abb7c0ee6118a57816783595b
Image: kubernetesui/dashboard:v2.0.0
Image ID: docker.io/kubernetesui/dashboard@sha256:06868692fb9a7f2ede1a06de1b7b32afabc40ec739c1181d83b5ed3eb147ec6e
Port: 8443/TCP
Host Port: 0/TCP
Args:
--auto-generate-certificates
--namespace=kube-system
State: Running
Started: Sat, 11 Jul 2020 20:16:04 +0800
Last State: Terminated
Reason: Unknown
Exit Code: 255
Started: Sat, 11 Jul 2020 18:54:24 +0800
Finished: Sat, 11 Jul 2020 20:15:55 +0800
Ready: True
Restart Count: 2
Liveness: http-get https://:8443/ delay=30s timeout=30s period=10s #success=1 #failure=3
Environment: <none>
Mounts:
/certs from kubernetes-dashboard-certs (rw)
/tmp from tmp-volume (rw)
/var/run/secrets/kubernetes.io/serviceaccount from kubernetes-dashboard-token-zwxvg (ro)
Conditions:
Type Status
Initialized True
Ready True
ContainersReady True
PodScheduled True
Volumes:
kubernetes-dashboard-certs:
Type: Secret (a volume populated by a Secret)
SecretName: kubernetes-dashboard-certs
Optional: false
tmp-volume:
Type: EmptyDir (a temporary directory that shares a pod's lifetime)
Medium:
SizeLimit: <unset>
kubernetes-dashboard-token-zwxvg:
Type: Secret (a volume populated by a Secret)
SecretName: kubernetes-dashboard-token-zwxvg
Optional: false
QoS Class: BestEffort
Node-Selectors: <none>
Tolerations: node-role.kubernetes.io/master:NoSchedule
node.kubernetes.io/not-ready:NoExecute for 300s
node.kubernetes.io/unreachable:NoExecute for 300s
Events: <none>
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl port-forward --namespace=kube-system --address=0.0.0.0 pod/kubernetes-dashboard-59f5574d4-b7b4b 9443:8443
Error from server (NotFound): pods "kubernetes-dashboard-59f5574d4-b7b4b" not found
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl port-forward --namespace=kube-system --address=0.0.0.0 pod/kubernetes-dashboard-6d97855997-8bnsq 9443:8443
Forwarding from 0.0.0.0:9443 -> 8443
Handling connection for 9443
E0711 22:05:43.366887 26062 portforward.go:385] error copying from local connection to remote stream: read tcp4 127.0.0.1:9443->127.0.0.1:52624: read: connection reset by peer
login as: root
root@111.17.169.203's password:
Last login: Sat Jul 11 22:05:24 2020 from 49.95.252.151
Welcome to Huawei Cloud Service
[root@hecs-x-medium-2-linux-20200711102537 ~]# netstat -ntlp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:44439 0.0.0.0:* LISTEN 594/containerd
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 1457/master
tcp 0 0 127.0.0.1:1338 0.0.0.0:* LISTEN 594/containerd
tcp 0 0 0.0.0.0:32000 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:9443 0.0.0.0:* LISTEN 26062/kubectl
tcp 0 0 127.0.0.1:10248 0.0.0.0:* LISTEN 595/kubelet
tcp 0 0 0.0.0.0:25000 0.0.0.0:* LISTEN 801/python3
tcp 0 0 127.0.0.1:10249 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:10443 0.0.0.0:* LISTEN 24260/kubectl
tcp 0 0 127.0.0.1:10251 0.0.0.0:* LISTEN 598/kube-scheduler
tcp 0 0 127.0.0.1:10252 0.0.0.0:* LISTEN 603/kube-controller
tcp 0 0 127.0.0.1:2380 0.0.0.0:* LISTEN 597/etcd
tcp 0 0 127.0.0.1:10256 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1706/sshd
tcp6 0 0 ::1:25 :::* LISTEN 1457/master
tcp6 0 0 :::16443 :::* LISTEN 608/kube-apiserver
tcp6 0 0 :::12379 :::* LISTEN 597/etcd
tcp6 0 0 :::10250 :::* LISTEN 595/kubelet
tcp6 0 0 :::10255 :::* LISTEN 595/kubelet
tcp6 0 0 :::10257 :::* LISTEN 603/kube-controller
tcp6 0 0 :::10259 :::* LISTEN 598/kube-scheduler
tcp6 0 0 :::22 :::* LISTEN 1706/sshd
[root@hecs-x-medium-2-linux-20200711102537 ~]# systemctl status firewalld
● firewalld.service - firewalld - dynamic firewall daemon
Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled)
Active: inactive (dead)
Docs: man:firewalld(1)
[root@hecs-x-medium-2-linux-20200711102537 ~]#
login as: root
root@111.17.169.203's password:
Last login: Sat Jul 11 22:20:05 2020 from 183.210.229.153
Welcome to Huawei Cloud Service
[root@hecs-x-medium-2-linux-20200711102537 ~]# netstat -ntlp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:44439 0.0.0.0:* LISTEN 594/containerd
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 1457/master
tcp 0 0 127.0.0.1:1338 0.0.0.0:* LISTEN 594/containerd
tcp 0 0 0.0.0.0:32000 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:9443 0.0.0.0:* LISTEN 26062/kubectl
tcp 0 0 127.0.0.1:10248 0.0.0.0:* LISTEN 595/kubelet
tcp 0 0 0.0.0.0:25000 0.0.0.0:* LISTEN 801/python3
tcp 0 0 127.0.0.1:10249 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:10443 0.0.0.0:* LISTEN 24260/kubectl
tcp 0 0 127.0.0.1:10251 0.0.0.0:* LISTEN 598/kube-scheduler
tcp 0 0 127.0.0.1:10252 0.0.0.0:* LISTEN 603/kube-controller
tcp 0 0 127.0.0.1:2380 0.0.0.0:* LISTEN 597/etcd
tcp 0 0 127.0.0.1:10256 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1706/sshd
tcp6 0 0 ::1:25 :::* LISTEN 1457/master
tcp6 0 0 :::16443 :::* LISTEN 608/kube-apiserver
tcp6 0 0 :::12379 :::* LISTEN 597/etcd
tcp6 0 0 :::10250 :::* LISTEN 595/kubelet
tcp6 0 0 :::10255 :::* LISTEN 595/kubelet
tcp6 0 0 :::10257 :::* LISTEN 603/kube-controller
tcp6 0 0 :::10259 :::* LISTEN 598/kube-scheduler
tcp6 0 0 :::22 :::* LISTEN 1706/sshd
[root@hecs-x-medium-2-linux-20200711102537 ~]# kill -9 26062
[root@hecs-x-medium-2-linux-20200711102537 ~]# netstat -ntlp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:44439 0.0.0.0:* LISTEN 594/containerd
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 1457/master
tcp 0 0 127.0.0.1:1338 0.0.0.0:* LISTEN 594/containerd
tcp 0 0 0.0.0.0:32000 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 127.0.0.1:10248 0.0.0.0:* LISTEN 595/kubelet
tcp 0 0 0.0.0.0:25000 0.0.0.0:* LISTEN 801/python3
tcp 0 0 127.0.0.1:10249 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:10443 0.0.0.0:* LISTEN 24260/kubectl
tcp 0 0 127.0.0.1:10251 0.0.0.0:* LISTEN 598/kube-scheduler
tcp 0 0 127.0.0.1:10252 0.0.0.0:* LISTEN 603/kube-controller
tcp 0 0 127.0.0.1:2380 0.0.0.0:* LISTEN 597/etcd
tcp 0 0 127.0.0.1:10256 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1706/sshd
tcp6 0 0 ::1:25 :::* LISTEN 1457/master
tcp6 0 0 :::16443 :::* LISTEN 608/kube-apiserver
tcp6 0 0 :::12379 :::* LISTEN 597/etcd
tcp6 0 0 :::10250 :::* LISTEN 595/kubelet
tcp6 0 0 :::10255 :::* LISTEN 595/kubelet
tcp6 0 0 :::10257 :::* LISTEN 603/kube-controller
tcp6 0 0 :::10259 :::* LISTEN 598/kube-scheduler
tcp6 0 0 :::22 :::* LISTEN 1706/sshd
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl port-forward --namespace=kube-system --address=0.0.0.0 pod/kubernetes-dashboard-6d97855997-8bnsq 8443:8443
Forwarding from 0.0.0.0:8443 -> 8443
^C[root@hecs-x-medium-2-linux-20200711102537 ~]netstat -ntlp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:44439 0.0.0.0:* LISTEN 594/containerd
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 1457/master
tcp 0 0 127.0.0.1:1338 0.0.0.0:* LISTEN 594/containerd
tcp 0 0 0.0.0.0:32000 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 127.0.0.1:10248 0.0.0.0:* LISTEN 595/kubelet
tcp 0 0 0.0.0.0:25000 0.0.0.0:* LISTEN 801/python3
tcp 0 0 127.0.0.1:10249 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:10443 0.0.0.0:* LISTEN 24260/kubectl
tcp 0 0 127.0.0.1:10251 0.0.0.0:* LISTEN 598/kube-scheduler
tcp 0 0 127.0.0.1:10252 0.0.0.0:* LISTEN 603/kube-controller
tcp 0 0 127.0.0.1:2380 0.0.0.0:* LISTEN 597/etcd
tcp 0 0 127.0.0.1:10256 0.0.0.0:* LISTEN 596/kube-proxy
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1706/sshd
tcp6 0 0 ::1:25 :::* LISTEN 1457/master
tcp6 0 0 :::16443 :::* LISTEN 608/kube-apiserver
tcp6 0 0 :::12379 :::* LISTEN 597/etcd
tcp6 0 0 :::10250 :::* LISTEN 595/kubelet
tcp6 0 0 :::10255 :::* LISTEN 595/kubelet
tcp6 0 0 :::10257 :::* LISTEN 603/kube-controller
tcp6 0 0 :::10259 :::* LISTEN 598/kube-scheduler
tcp6 0 0 :::22 :::* LISTEN 1706/sshd
[root@hecs-x-medium-2-linux-20200711102537 ~]# microk8s kubectl port-forward --namespace=kube-system --address=0.0.0.0 pod/kubernetes-dashboard-6d97855997-8bnsq 8443:8443
Forwarding from 0.0.0.0:8443 -> 8443