Customizing components with the kubeadm API [page]deterministic
This page covers how to customize the components that kubeadm deploys. For control plane components you can use flags in the `ClusterConfiguration` structure or patches per-node. For the kubelet and kube-proxy you can use `KubeletConfiguration` and `KubeProxyConfiguration`, accordingly.
All of these options are possible via the kubeadm configuration API. For more details on each field in the configuration you can navigate to our [API reference pages](/docs/reference/config-api/kubeadm-config.v1beta4/).
> Note: To reconfigure a cluster that has already been created see [Reconfiguring a kubeadm cluster](/docs/tasks/administer-cluster/kubeadm/kubeadm-reconfigure).
## Customizing the control plane with flags in `ClusterConfiguration`
The kubeadm `ClusterConfiguration` object exposes a way for users to override the default flags passed to control plane components such as the APIServer, ControllerManager, Scheduler and Etcd. The components are defined using the following structures:
- `apiServer`
- `controllerManager`
- `scheduler`
- `etcd`
These structures contain a common `extraArgs` field, that consists of `name` / `value` pairs. To override a flag for a control plane component:
1. Add the appropriate `extraArgs` to your configuration. 2. Add flags to the `extraArgs` field. 3. Run `kubeadm init` with `--config <YOUR CONFIG YAML>`.
> Note: You can generate a `ClusterConfiguration` object with default values by running `kubeadm config print init-defaults` and saving the output to a file of your choice.
> Note: The `ClusterConfiguration` object is currently global in kubeadm clusters. This means that any flags that you add, will apply to all instances of the same component on different nodes. To apply individual configuration per component on different nodes you can use [patches](#patches).
> Note: Duplicate flags (keys), or passing the same flag `--foo` multiple times, is currently not supported. To workaround that you must use [patches](#patches).
### APIServer flags
For details, see the [reference documentation for kube-apiserver](/docs/reference/command-line-tools-reference/kube-apiserver/).
Example usage:
```yaml apiVersion: kubeadm.k8s.io/v1beta4 kind: ClusterConfiguration kubernetesVersion: v1.16.0 apiServer: extraArgs: - name: "enable-admission-plugins" value: "AlwaysPullImages,DefaultStorageClass" - name: "audit-log-path" value: "/home/johndoe/audit.log" ```
### ControllerManager flags
For details, see the [reference documentation for kube-controller-manager](/docs/reference/command-line-tools-reference/kube-controller-manager/).
Example usage:
```yaml apiVersion: kubeadm.k8s.io/v1beta4 kind: ClusterConfiguration kubernetesVersion: v1.16.0 controllerManager: extraArgs: - name: "cluster-signing-key-file" value: "/home/johndoe/keys/ca.key" - name: "deployment-controller-sync-period" value: "50" ```
### Scheduler flags
For details, see the [reference documentation for kube-scheduler](/docs/reference/command-line-tools-reference/kube-scheduler/).
Example usage:
```yaml apiVersion: kubeadm.k8s.io/v1beta4 kind: ClusterConfiguration kubernetesVersion: v1.16.0 scheduler: extraArgs: - name: "config" value: "/etc/kubernetes/scheduler-config.yaml" extraVolumes: - name: schedulerconfig hostPath: /home/johndoe/schedconfig.yaml mountPath: /etc/kubernetes/scheduler-config.yaml readOnly: true pathType: "File" ```
### Etcd flags
For details, see the [etcd server documentation](https://etcd.io/docs/).
Example usage:
```yaml apiVersion: kubeadm.k8s.io/v1beta4 kind: ClusterConfiguration etcd: local: extraArgs: - name: "election-timeout" value: 1000 ```
## Customizing with patches {#patches}
Kubeadm allows you to pass a directory with patch files to `InitConfiguration`, `JoinConfiguration` and `UpgradeConfiguration`. on individual nodes. These patches can be used as the last customization step before com …(trimmed)