在master中
openssl genrsa -out /etc/kubernetes/serviceaccount.key 2048
修改kube-apiserver.service添加参数
--service_account_key_file=/etc/kubernetes/serviceaccount.key \
修改kube-controller-manager.service 添加参数
--service_account_private_key_file=/etc/kubernetes/serviceaccount.key \
重启服务
systemctl restart kube-apiserver kube-controller-manager kube-scheduler