⎈ k8s knowledge compiler

Adding Windows worker nodes [page]deterministic

tasks

This page explains how to add Windows worker nodes to a kubeadm cluster.

##

* A running [Windows Server 2022](https://www.microsoft.com/cloud-platform/windows-server-pricing) (or higher) instance with administrative access. * A running kubeadm cluster created by `kubeadm init` and following the steps in the document [Creating a cluster with kubeadm](/docs/setup/production-environment/tools/kubeadm/create-cluster-kubeadm/).

## Adding Windows worker nodes

> Note: To facilitate the addition of Windows worker nodes to a cluster, PowerShell scripts from the repository https://sigs.k8s.io/sig-windows-tools are used.

Do the following for each machine:

1. Open a PowerShell session on the machine. 1. Make sure you are Administrator or a privileged user.

Then proceed with the steps outlined below.

### Install containerd

To install containerd, first run the following command:

```PowerShell curl.exe -LO https://raw.githubusercontent.com/kubernetes-sigs/sig-windows-tools/master/hostprocess/Install-Containerd.ps1 ```

Then run the following command, but first replace `CONTAINERD_VERSION` with a recent release from the [containerd repository](https://github.com/containerd/containerd/releases). The version must not have a `v` prefix. For example, use `1.7.22` instead of `v1.7.22`:

```PowerShell .\Install-Containerd.ps1 -ContainerDVersion CONTAINERD_VERSION ```

* Adjust any other parameters for `Install-Containerd.ps1` such as `netAdapterName` as you need them. * Set `skipHypervisorSupportCheck` if your machine does not support Hyper-V and cannot host Hyper-V isolated containers. * If you change the `Install-Containerd.ps1` optional parameters `CNIBinPath` and/or `CNIConfigPath` you will need to configure the installed Windows CNI plugin with matching values.

### Install kubeadm and kubelet

Run the following commands to install kubeadm and the kubelet:

```PowerShell curl.exe -LO https://raw.githubusercontent.com/kubernetes-sigs/sig-windows-tools/master/hostprocess/PrepareNode.ps1 .\PrepareNode.ps1 -KubernetesVersion v ```

* Adjust the parameter `KubernetesVersion` of `PrepareNode.ps1` if needed.

### Run `kubeadm join`

Run the command that was output by `kubeadm init`. For example:

```bash kubeadm join --token <token> <control-plane-host>:<control-plane-port> --discovery-token-ca-cert-hash sha256:<hash> ```

#### Additional information about kubeadm join

> Note: To specify an IPv6 tuple for `<control-plane-host>:<control-plane-port>`, IPv6 address must be enclosed in square brackets, for example: `[2001:db8::101]:2073`.

If you do not have the token, you can get it by running the following command on the control plane node:

```bash # Run this on a control plane node sudo kubeadm token list ```

The output is similar to this:

```console TOKEN TTL EXPIRES USAGES DESCRIPTION EXTRA GROUPS 8ewj1p.9r9hcjoqgajrj4gi 23h 2018-06-12T02:51:28Z authentication, The default bootstrap system: signing token generated by bootstrappers: 'kubeadm init'. kubeadm: default-node-token ```

By default, node join tokens expire after 24 hours. If you are joining a node to the cluster after the current token has expired, you can create a new token by running the following command on the control plane node:

```bash # Run this on a control plane node sudo kubeadm token create ```

The output is similar to this:

```console 5didvk.d09sbcov8ph2amjw ```

If you don't have the value of `--discovery-token-ca-cert-hash`, you can get it by running the following commands on the control plane node:

```bash sudo cat /etc/kubernetes/pki/ca.crt | openssl x509 -pubkey | openssl rsa -pubin -outform der 2>/dev/null | \ openssl dgst …(trimmed)

Sources

tasks/administer-cluster/kubeadm/adding-windows-nodes.md · docAdding Windows worker nodes

Related (9)

part_of {{% heading "prerequisites" %}}describes conf=1
part_of Adding Windows worker nodesdescribes conf=1
part_of {{% heading "whatsnext" %}}describes conf=1
part_of Install Containerddescribes conf=1
part_of Install kubeadm and kubeletdescribes conf=1
part_of Run `kubeadm join`describes conf=1
part_of Network configurationdescribes conf=1
api_for Nodedocuments API object conf=1

← all Docs