7.14. 验证信任配置
您可以通过检查 Trustee pod 和 logs 来验证 Trustee 配置。
流程
运行以下命令来设置默认项目:
oc project trustee-operator-system
$ oc project trustee-operator-system
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 运行以下命令检查 Trustee pod:
oc get pods -n trustee-operator-system
$ oc get pods -n trustee-operator-system
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 输出示例
NAME READY STATUS RESTARTS AGE trustee-deployment-8585f98449-9bbgl 1/1 Running 0 22m trustee-operator-controller-manager-5fbd44cd97-55dlh 2/2 Running 0 59m
NAME READY STATUS RESTARTS AGE trustee-deployment-8585f98449-9bbgl 1/1 Running 0 22m trustee-operator-controller-manager-5fbd44cd97-55dlh 2/2 Running 0 59m
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 运行以下命令设置
POD_NAME
环境变量:POD_NAME=$(oc get pods -l app=kbs -o jsonpath='{.items[0].metadata.name}' -n trustee-operator-system)
$ POD_NAME=$(oc get pods -l app=kbs -o jsonpath='{.items[0].metadata.name}' -n trustee-operator-system)
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 运行以下命令检查 pod 日志:
oc logs -n trustee-operator-system $POD_NAME
$ oc logs -n trustee-operator-system $POD_NAME
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 输出示例
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 运行以下命令,验证
kbs-service
是否在节点端口上公开:oc get svc kbs-service -n trustee-operator-system
$ oc get svc kbs-service -n trustee-operator-system
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 输出示例
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE kbs-service NodePort 198.51.100.54 <none> 8080:31862/TCP 23h
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE kbs-service NodePort 198.51.100.54 <none> 8080:31862/TCP 23h
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 运行以下命令来获取 Trustee 部署 pod 名称:
oc get pods -n trustee-operator-system | grep -i trustee-deployment
$ oc get pods -n trustee-operator-system | grep -i trustee-deployment
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 输出示例
NAME READY STATUS RESTARTS AGE trustee-deployment-d746679cd-plq82 1/1 Running 0 2m32s
NAME READY STATUS RESTARTS AGE trustee-deployment-d746679cd-plq82 1/1 Running 0 2m32s
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 运行以下命令来获取 worker 节点 IP 地址:
oc get pod trustee-deployment-d746679cd-plq82 -o custom-columns="NODE-IP:.status.hostIP"
$ oc get pod trustee-deployment-d746679cd-plq82 -o custom-columns="NODE-IP:.status.hostIP"
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 输出示例
NODE-IP 192.168.122.36
NODE-IP 192.168.122.36
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 访问 Trustee 的 URL 是
http://<worker_node_ip>:<node_port
>,例如http://192.168.122.36:31862
。运行以下命令,验证
peer-pods-cm
配置映射中的AA_KBC_PARAMS
值是否与 Trustee URL 相同:oc get cm peer-pods-cm -n openshift-sandboxed-containers-operator -o yaml | grep AA_KBC_PARAMS
$ oc get cm peer-pods-cm -n openshift-sandboxed-containers-operator -o yaml | grep AA_KBC_PARAMS
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 输出示例
AA_KBC_PARAMS: cc_kbc::http://192.168.122.36:31862
AA_KBC_PARAMS: cc_kbc::http://192.168.122.36:31862
Copy to Clipboard Copied! Toggle word wrap Toggle overflow