While I was setting up my homelab K8s cluster, I faced a few networking, DNS and connectivity issues, while setting up a lot of stuff in my cluster. To ensure you don’t have to go through the same misery as I did, let’s get these out of the way:
- Allow
iptablesto accept forward requests on each of the nodes, otherwise networking won’t work -sudo iptables -P FORWARD ACCEPT. Once that’s done, we’ll need to ensure that this is persisted and isn’t wiped out on reboots. I had to do these in my Intel installation, but not on the cloud-init based installs on the Raspberry PIs. If you know why, lemme know.sudo apt install iptables-persistent- Answer
yesto saving the configs. sudo service netfilter-persistent restart
- If you have
ufwrunning, and you can verify if it is withsudo ufw status, you’ll need it to allow routed packets on the calico interfaces (assuming we’ll be running a cluster which uses calico for CNI):sudo ufw default allow routedsudo ufw allow in on vxlan.calicosudo ufw allow out on vxlan.calico
- I had a Bind9 DNS server installed for resolving my LAN-only Domain. If you have the same.
- use 127.0.0.1 (bind9) for DNS resolution in the PKI CA Node, so that it can resolve itself -
sudo resolvectl dns eth0 127.0.0.1 1.1.1.1 8.8.8.8 - Verify the DNS Servers -
resolvectl dns eth0(change the interface to the one you’re going to use for your cluster communications) - For me step 1 here didn’t work. It was temporary and would get replaced in a while, leading to certificate renewal failures. So to address that, I had to:
sudo vim /etc/systemd/resolved.conf- Add this line in there:
DNS=127.0.0.1after the line that says[Resolve]. - Restart the systemd-resolve service -
sudo service systemd-resolved restart
- use 127.0.0.1 (bind9) for DNS resolution in the PKI CA Node, so that it can resolve itself -
- Update /etc/hosts on each of your nodes, to have entries for each of your other nodes. Mine looks like this:
... 127.0.1.1 k0r0ptserver0 127.0.0.1 localhost 192.168.1.230 k0r0ptnas 192.168.1.232 k0r0ptserver1 ... - If you’re using a cloud-init image (I was, with Ubuntu), you need to ensure that /etc/hosts is not regenerated upon restart, as that will wipe out your changes.
- Open the cloud-init config for editing
vim /etc/cloud/cloud.cfg - Comment out the line which says
update_etc_hoststo -# - update_etc_hosts - Save and Quit
- Open the cloud-init config for editing