diff --git a/docs/concepts/cluster-administration/cloud-providers.md b/docs/concepts/cluster-administration/cloud-providers.md index 17b8ecadcc..d574d92658 100644 --- a/docs/concepts/cluster-administration/cloud-providers.md +++ b/docs/concepts/cluster-administration/cloud-providers.md @@ -64,20 +64,20 @@ the underlying cloud, where available: | Service | API Version(s) | Required | |--------------------------|----------------|----------| -| Block Storage (Cinder) | V1†, V2 | No | +| Block Storage (Cinder) | V1†, V2, V3 | No | | Compute (Nova) | V2 | No | | Identity (Keystone) | V2‡, V3 | Yes | | Load Balancing (Neutron) | V1§, V2 | No | +| Load Balancing (Octavia) | V2 | No | + +† Block Storage V1 API support is deprecated, Block Storage V3 API support was +added in Kubernetes 1.9. -† Block Storage V1 API support is deprecated, support for Block Storage V3 will -be added in the future. - ‡ Identity V2 API support is deprecated and will be removed from the provider in a future release. As of the "Queens" release, OpenStack will no longer expose the Identity V2 API. -§ Load Balancing V1 API support is deprecated and will be removed from the -provider in a future release. +§ Load Balancing V1 API support was removed in Kubernetes 1.9. Service discovery is achieved by listing the service catalog managed by OpenStack Identity (Keystone) using the `auth-url` provided in the provider diff --git a/docs/concepts/policy/pod-security-policy.md b/docs/concepts/policy/pod-security-policy.md index a1e219c146..884ad55fc6 100644 --- a/docs/concepts/policy/pod-security-policy.md +++ b/docs/concepts/policy/pod-security-policy.md @@ -21,25 +21,26 @@ actions that a pod can perform and what it has the ability to access. The run with in order to be accepted into the system. They allow an administrator to control the following: -| Control Aspect | Field Name | -| ---------------------------------------------------------------------- | ------------------------------------------- | -| Running of privileged containers | `privileged` | -| Default set of capabilities that will be added to a container | `defaultAddCapabilities` | -| Capabilities that will be dropped from a container | `requiredDropCapabilities` | -| Capabilities a container can request to be added | `allowedCapabilities` | -| Controlling the usage of volume types | [`volumes`](#controlling-volumes) | -| The use of host networking | [`hostNetwork`](#host-network) | -| The use of host ports | `hostPorts` | -| The use of host's PID namespace | `hostPID` | -| The use of host's IPC namespace | `hostIPC` | -| The SELinux context of the container | [`seLinux`](#selinux) | -| The user ID | [`runAsUser`](#runasuser) | -| Configuring allowable supplemental groups | [`supplementalGroups`](#supplementalgroups) | -| Allocating an FSGroup that owns the pod's volumes | [`fsGroup`](#fsgroup) | -| Requiring the use of a read only root file system | `readOnlyRootFilesystem` | -| Running of a container that allow privilege escalation from its parent | [`allowPrivilegeEscalation`](#allowprivilegeescalation) | +| Control Aspect | Field Name | +| ---------------------------------------------------------------------- | ------------------------------------------- | +| Running of privileged containers | `privileged` | +| Default set of capabilities that will be added to a container | `defaultAddCapabilities` | +| Capabilities that will be dropped from a container | `requiredDropCapabilities` | +| Capabilities a container can request to be added | `allowedCapabilities` | +| Controlling the usage of volume types | [`volumes`](#controlling-volumes) | +| The use of host networking | [`hostNetwork`](#host-network) | +| The use of host ports | `hostPorts` | +| The use of host's PID namespace | `hostPID` | +| The use of host's IPC namespace | `hostIPC` | +| The SELinux context of the container | [`seLinux`](#selinux) | +| The user ID | [`runAsUser`](#runasuser) | +| Configuring allowable supplemental groups | [`supplementalGroups`](#supplementalgroups) | +| Allocating an FSGroup that owns the pod's volumes | [`fsGroup`](#fsgroup) | +| Requiring the use of a read only root file system | `readOnlyRootFilesystem` | +| Running of a container that allow privilege escalation from its parent | [`allowPrivilegeEscalation`](#allowprivilegeescalation) | | Control whether a process can gain more privileges than its parent process | [`defaultAllowPrivilegeEscalation`](#defaultallowprivilegeescalation) | -| Whitelist of allowed host paths | [`allowedHostPaths`](#allowedhostpaths) | +| Whitelist of allowed host paths | [`allowedHostPaths`](#allowedhostpaths) | +| Whitelist of the flex volume drivers | [`allowedFlexVolumes`](#allowedflexvolumes) | _Pod Security Policies_ are comprised of settings and strategies that control the security features a pod has access to. These settings fall @@ -162,6 +163,26 @@ spec: - pathPrefix: "/foo" ``` +### AllowedFlexVolumes + +This specifies a whitelist of flex volume drivers that are allowed +to be used by flexVolume. An empty list means there is no restriction on the drivers. Please +make sure `volumes` contains the `flexVolume` volume type, no flex volume driver is allowed +otherwise. For example: + +```yaml +apiVersion: extensions/v1beta1 +kind: PodSecurityPolicy +metadata: + name: allow-flex-volumes +spec: + volumes: + - flexVolume + allowedFlexVolumes: + - driver: example/lvm + - driver: example/cifs +``` + ## Admission [_Admission control_ with `PodSecurityPolicy`](/docs/admin/admission-controllers/#podsecuritypolicy) diff --git a/docs/concepts/storage/volumes.md b/docs/concepts/storage/volumes.md index 9fb33064dd..247c593d75 100644 --- a/docs/concepts/storage/volumes.md +++ b/docs/concepts/storage/volumes.md @@ -939,7 +939,7 @@ achieved by using the `FlexVolume` plugin. `FlexVolume` enables users to mount vendor volumes into a pod. The vendor plugin is implemented using a driver, an executable supporting a list of volume commands defined by the `FlexVolume` API. Drivers must be installed in a pre-defined -volume plugin path on each node. This is an alpha feature and may change in future. +volume plugin path on each node. More details can be found [here](https://github.com/kubernetes/community/blob/master/contributors/devel/flexvolume.md).