Prepare Cluster (MicroOS)
4 minute read
Before you start with KubeOps Compliance, all cluster nodes must be prepared with a consistent baseline configuration. This Prepare Cluster guide walks you through the required system-level steps on both controlplane and worker nodes, as well as the admin node used to manage the cluster. With these preparations done, you will ensure that all nodes behave predictably, can communicate securely with each other, and meet the prerequisites for the subsequent cluster setup procedure.
1. Create a user to work with
A user
If no SSH keys have been set up for root, you can temporarily allow root login.
echo -e "PermitRootLogin yes\nPasswordAuthentication yes" > /etc/ssh/sshd_config.d/permit_root_login.conf
systemctl restart sshd
useradd myuser # You can choose your own username instead of myuser
passwd myuser # Set password for myuser
2. Hostnames of all nodes must be resolvable via DNS
If you do not run a DNS server, the easiest solution is to enter the IP-addresses and hostnames in etc/hosts
# IMPORTANT: The following command has to be adapted so that every admin, controlplane and worker node is included
sudo tee /etc/hosts <<EOL_ETC_HOSTS
127.0.0.1 localhost
<admin ip> <admin hostname>
<controlplane01 ip> <controlplane01 hostname>
<controlplane02 ip> <controlplane02 hostname>
<controlplane03 ip> <controlplane03 hostname>
...
<worker01 ip> <worker01 hostname>
<worker02 ip> <worker02 hostname>
<worker03 ip> <worker03 hostname>
...
EOL_ETC_HOSTS
Full Example
sudo tee /etc/hosts <<EOL_ETC_HOSTS
127.0.0.1 localhost
10.2.10.10 admin
10.2.10.110 node01
10.2.10.120 node02
10.2.10.130 node03
10.2.10.210 node04
10.2.10.220 node05
10.2.10.230 node06
EOL_ETC_HOSTS
3. Distribute ssh-keys on all nodes
Create ssh-keys on all nodes
ssh-keygen -q -t ed25519 -f ~/.ssh/id_ed25519 -N ""
Copy public ssh-key on all nodes
# IMPORTANT: The following command has to be adapted so that every admin, controlplane and worker node is included
ssh-copy-id -i ~/.ssh/id_ed25519 <admin hostname>
ssh-copy-id -i ~/.ssh/id_ed25519 <controlplane01 hostname>
ssh-copy-id -i ~/.ssh/id_ed25519 <controlplane02 hostname>
ssh-copy-id -i ~/.ssh/id_ed25519 <controlplane03 hostname>
...
ssh-copy-id -i ~/.ssh/id_ed25519 <worker01 hostname>
ssh-copy-id -i ~/.ssh/id_ed25519 <worker02 hostname>
ssh-copy-id -i ~/.ssh/id_ed25519 <worker03 hostname>
...
Full Example
ssh-copy-id -i ~/.ssh/id_ed25519 admin
ssh-copy-id -i ~/.ssh/id_ed25519 node01
ssh-copy-id -i ~/.ssh/id_ed25519 node02
ssh-copy-id -i ~/.ssh/id_ed25519 node03
ssh-copy-id -i ~/.ssh/id_ed25519 node04
ssh-copy-id -i ~/.ssh/id_ed25519 node05
ssh-copy-id -i ~/.ssh/id_ed25519 node06
Scan host-keys with name and IP-address on all nodes
# IMPORTANT: The following command has to be adapted so that every admin, controlplane and worker node is included
ssh-keyscan <admin hostname> >> ~/.ssh/known_hosts
ssh-keyscan <admin ip> >> ~/.ssh/known_hosts
ssh-keyscan <controlplane01 hostname> >> ~/.ssh/known_hosts
ssh-keyscan <controlplane01 ip> >> ~/.ssh/known_hosts
ssh-keyscan <controlplane02 hostname> >> ~/.ssh/known_hosts
ssh-keyscan <controlplane02 ip> >> ~/.ssh/known_hosts
ssh-keyscan <controlplane03 hostname> >> ~/.ssh/known_hosts
ssh-keyscan <controlplane03 ip> >> ~/.ssh/known_hosts
...
ssh-keyscan <worker01 hostname> >> ~/.ssh/known_hosts
ssh-keyscan <worker01 ip> >> ~/.ssh/known_hosts
ssh-keyscan <worker02 hostname> >> ~/.ssh/known_hosts
ssh-keyscan <worker02 ip> >> ~/.ssh/known_hosts
ssh-keyscan <worker03 hostname> >> ~/.ssh/known_hosts
ssh-keyscan <worker03 ip> >> ~/.ssh/known_hosts
...
Full Example
ssh-keyscan admin >> ~/.ssh/known_hosts
ssh-keyscan 10.2.10.10 >> ~/.ssh/known_hosts
ssh-keyscan node01 >> ~/.ssh/known_hosts
ssh-keyscan 10.2.10.110 >> ~/.ssh/known_hosts
ssh-keyscan node02 >> ~/.ssh/known_hosts
ssh-keyscan 10.2.10.120 >> ~/.ssh/known_hosts
ssh-keyscan node03 >> ~/.ssh/known_hosts
ssh-keyscan 10.2.10.130 >> ~/.ssh/known_hosts
ssh-keyscan node04 >> ~/.ssh/known_hosts
ssh-keyscan 10.2.10.210 >> ~/.ssh/known_hosts
ssh-keyscan node05 >> ~/.ssh/known_hosts
ssh-keyscan 10.2.10.220 >> ~/.ssh/known_hosts
ssh-keyscan node06 >> ~/.ssh/known_hosts
ssh-keyscan 10.2.10.230 >> ~/.ssh/known_hosts
Test ssh login without password.
Passwordless SSH login must work from each node to all other nodes.
# IMPORTANT: The following command has to be adapted so that every admin, controlplane and worker node is included
ssh <admin hostname> exit
ssh <admin ip> exit
ssh <controlplane01 hostname> exit
ssh <controlplane01 ip> exit
ssh <controlplane02 hostname> exit
ssh <controlplane02 ip> exit
ssh <controlplane03 hostname> exit
ssh <controlplane03 ip> exit
...
ssh <worker01 hostname> exit
ssh <worker01 ip> exit
ssh <worker02 hostname> exit
ssh <worker02 ip> exit
ssh <worker03 hostname> exit
ssh <worker03 ip> exit
...
Full Example
ssh admin exit
ssh 10.2.10.10 exit
ssh node01 exit
ssh 10.2.10.110 exit
ssh node02 exit
ssh 10.2.10.120 exit
ssh node03 exit
ssh 10.2.10.130 exit
ssh node04 exit
ssh 10.2.10.210 exit
ssh node05 exit
ssh 10.2.10.220 exit
ssh node06 exit
ssh 10.2.10.230 exit
4. Distribute SUDOERS on all nodes
Replace the username “myuser” with your username and copy the sudoers file to /etc/sudoers.d/<username> on all nodes.
myuser ALL=(ALL) NOPASSWD: ALL
Full Example
sudo tee /etc/sudoers.d/myuser <<EOL_SUDOERS
myuser ALL=(ALL) NOPASSWD: ALL
EOL_SUDOERS
Once all nodes are prepared, you can start setting up the cluster.