diff --git a/LICENSE b/LICENSE index 5ee2946660..06c608dcf4 100644 --- a/LICENSE +++ b/LICENSE @@ -1,201 +1,395 @@ -Apache License - Version 2.0, January 2004 - http://www.apache.org/licenses/ +Attribution 4.0 International - TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION +======================================================================= - 1. Definitions. +Creative Commons Corporation ("Creative Commons") is not a law firm and +does not provide legal services or legal advice. Distribution of +Creative Commons public licenses does not create a lawyer-client or +other relationship. Creative Commons makes its licenses and related +information available on an "as-is" basis. Creative Commons gives no +warranties regarding its licenses, any material licensed under their +terms and conditions, or any related information. Creative Commons +disclaims all liability for damages resulting from their use to the +fullest extent possible. - "License" shall mean the terms and conditions for use, reproduction, - and distribution as defined by Sections 1 through 9 of this document. +Using Creative Commons Public Licenses - "Licensor" shall mean the copyright owner or entity authorized by - the copyright owner that is granting the License. +Creative Commons public licenses provide a standard set of terms and +conditions that creators and other rights holders may use to share +original works of authorship and other material subject to copyright +and certain other rights specified in the public license below. The +following considerations are for informational purposes only, are not +exhaustive, and do not form part of our licenses. - "Legal Entity" shall mean the union of the acting entity and all - other entities that control, are controlled by, or are under common - control with that entity. For the purposes of this definition, - "control" means (i) the power, direct or indirect, to cause the - direction or management of such entity, whether by contract or - otherwise, or (ii) ownership of fifty percent (50%) or more of the - outstanding shares, or (iii) beneficial ownership of such entity. + Considerations for licensors: Our public licenses are + intended for use by those authorized to give the public + permission to use material in ways otherwise restricted by + copyright and certain other rights. Our licenses are + irrevocable. Licensors should read and understand the terms + and conditions of the license they choose before applying it. + Licensors should also secure all rights necessary before + applying our licenses so that the public can reuse the + material as expected. Licensors should clearly mark any + material not subject to the license. This includes other CC- + licensed material, or material used under an exception or + limitation to copyright. More considerations for licensors: + wiki.creativecommons.org/Considerations_for_licensors - "You" (or "Your") shall mean an individual or Legal Entity - exercising permissions granted by this License. + Considerations for the public: By using one of our public + licenses, a licensor grants the public permission to use the + licensed material under specified terms and conditions. If + the licensor's permission is not necessary for any reason--for + example, because of any applicable exception or limitation to + copyright--then that use is not regulated by the license. Our + licenses grant only permissions under copyright and certain + other rights that a licensor has authority to grant. Use of + the licensed material may still be restricted for other + reasons, including because others have copyright or other + rights in the material. A licensor may make special requests, + such as asking that all changes be marked or described. + Although not required by our licenses, you are encouraged to + respect those requests where reasonable. More_considerations + for the public: + wiki.creativecommons.org/Considerations_for_licensees - "Source" form shall mean the preferred form for making modifications, - including but not limited to software source code, documentation - source, and configuration files. +======================================================================= - "Object" form shall mean any form resulting from mechanical - transformation or translation of a Source form, including but - not limited to compiled object code, generated documentation, - and conversions to other media types. +Creative Commons Attribution 4.0 International Public License - "Work" shall mean the work of authorship, whether in Source or - Object form, made available under the License, as indicated by a - copyright notice that is included in or attached to the work - (an example is provided in the Appendix below). +By exercising the Licensed Rights (defined below), You accept and agree +to be bound by the terms and conditions of this Creative Commons +Attribution 4.0 International Public License ("Public License"). To the +extent this Public License may be interpreted as a contract, You are +granted the Licensed Rights in consideration of Your acceptance of +these terms and conditions, and the Licensor grants You such rights in +consideration of benefits the Licensor receives from making the +Licensed Material available under these terms and conditions. - "Derivative Works" shall mean any work, whether in Source or Object - form, that is based on (or derived from) the Work and for which the - editorial revisions, annotations, elaborations, or other modifications - represent, as a whole, an original work of authorship. For the purposes - of this License, Derivative Works shall not include works that remain - separable from, or merely link (or bind by name) to the interfaces of, - the Work and Derivative Works thereof. - "Contribution" shall mean any work of authorship, including - the original version of the Work and any modifications or additions - to that Work or Derivative Works thereof, that is intentionally - submitted to Licensor for inclusion in the Work by the copyright owner - or by an individual or Legal Entity authorized to submit on behalf of - the copyright owner. For the purposes of this definition, "submitted" - means any form of electronic, verbal, or written communication sent - to the Licensor or its representatives, including but not limited to - communication on electronic mailing lists, source code control systems, - and issue tracking systems that are managed by, or on behalf of, the - Licensor for the purpose of discussing and improving the Work, but - excluding communication that is conspicuously marked or otherwise - designated in writing by the copyright owner as "Not a Contribution." +Section 1 -- Definitions. - "Contributor" shall mean Licensor and any individual or Legal Entity - on behalf of whom a Contribution has been received by Licensor and - subsequently incorporated within the Work. + a. Adapted Material means material subject to Copyright and Similar + Rights that is derived from or based upon the Licensed Material + and in which the Licensed Material is translated, altered, + arranged, transformed, or otherwise modified in a manner requiring + permission under the Copyright and Similar Rights held by the + Licensor. For purposes of this Public License, where the Licensed + Material is a musical work, performance, or sound recording, + Adapted Material is always produced where the Licensed Material is + synched in timed relation with a moving image. - 2. Grant of Copyright License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - copyright license to reproduce, prepare Derivative Works of, - publicly display, publicly perform, sublicense, and distribute the - Work and such Derivative Works in Source or Object form. + b. Adapter's License means the license You apply to Your Copyright + and Similar Rights in Your contributions to Adapted Material in + accordance with the terms and conditions of this Public License. - 3. Grant of Patent License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - (except as stated in this section) patent license to make, have made, - use, offer to sell, sell, import, and otherwise transfer the Work, - where such license applies only to those patent claims licensable - by such Contributor that are necessarily infringed by their - Contribution(s) alone or by combination of their Contribution(s) - with the Work to which such Contribution(s) was submitted. If You - institute patent litigation against any entity (including a - cross-claim or counterclaim in a lawsuit) alleging that the Work - or a Contribution incorporated within the Work constitutes direct - or contributory patent infringement, then any patent licenses - granted to You under this License for that Work shall terminate - as of the date such litigation is filed. + c. Copyright and Similar Rights means copyright and/or similar rights + closely related to copyright including, without limitation, + performance, broadcast, sound recording, and Sui Generis Database + Rights, without regard to how the rights are labeled or + categorized. For purposes of this Public License, the rights + specified in Section 2(b)(1)-(2) are not Copyright and Similar + Rights. - 4. Redistribution. You may reproduce and distribute copies of the - Work or Derivative Works thereof in any medium, with or without - modifications, and in Source or Object form, provided that You - meet the following conditions: + d. Effective Technological Measures means those measures that, in the + absence of proper authority, may not be circumvented under laws + fulfilling obligations under Article 11 of the WIPO Copyright + Treaty adopted on December 20, 1996, and/or similar international + agreements. - (a) You must give any other recipients of the Work or - Derivative Works a copy of this License; and + e. Exceptions and Limitations means fair use, fair dealing, and/or + any other exception or limitation to Copyright and Similar Rights + that applies to Your use of the Licensed Material. - (b) You must cause any modified files to carry prominent notices - stating that You changed the files; and + f. Licensed Material means the artistic or literary work, database, + or other material to which the Licensor applied this Public + License. - (c) You must retain, in the Source form of any Derivative Works - that You distribute, all copyright, patent, trademark, and - attribution notices from the Source form of the Work, - excluding those notices that do not pertain to any part of - the Derivative Works; and + g. Licensed Rights means the rights granted to You subject to the + terms and conditions of this Public License, which are limited to + all Copyright and Similar Rights that apply to Your use of the + Licensed Material and that the Licensor has authority to license. - (d) If the Work includes a "NOTICE" text file as part of its - distribution, then any Derivative Works that You distribute must - include a readable copy of the attribution notices contained - within such NOTICE file, excluding those notices that do not - pertain to any part of the Derivative Works, in at least one - of the following places: within a NOTICE text file distributed - as part of the Derivative Works; within the Source form or - documentation, if provided along with the Derivative Works; or, - within a display generated by the Derivative Works, if and - wherever such third-party notices normally appear. The contents - of the NOTICE file are for informational purposes only and - do not modify the License. You may add Your own attribution - notices within Derivative Works that You distribute, alongside - or as an addendum to the NOTICE text from the Work, provided - that such additional attribution notices cannot be construed - as modifying the License. + h. Licensor means the individual(s) or entity(ies) granting rights + under this Public License. - You may add Your own copyright statement to Your modifications and - may provide additional or different license terms and conditions - for use, reproduction, or distribution of Your modifications, or - for any such Derivative Works as a whole, provided Your use, - reproduction, and distribution of the Work otherwise complies with - the conditions stated in this License. + i. Share means to provide material to the public by any means or + process that requires permission under the Licensed Rights, such + as reproduction, public display, public performance, distribution, + dissemination, communication, or importation, and to make material + available to the public including in ways that members of the + public may access the material from a place and at a time + individually chosen by them. - 5. Submission of Contributions. Unless You explicitly state otherwise, - any Contribution intentionally submitted for inclusion in the Work - by You to the Licensor shall be under the terms and conditions of - this License, without any additional terms or conditions. - Notwithstanding the above, nothing herein shall supersede or modify - the terms of any separate license agreement you may have executed - with Licensor regarding such Contributions. + j. Sui Generis Database Rights means rights other than copyright + resulting from Directive 96/9/EC of the European Parliament and of + the Council of 11 March 1996 on the legal protection of databases, + as amended and/or succeeded, as well as other essentially + equivalent rights anywhere in the world. - 6. Trademarks. This License does not grant permission to use the trade - names, trademarks, service marks, or product names of the Licensor, - except as required for reasonable and customary use in describing the - origin of the Work and reproducing the content of the NOTICE file. + k. You means the individual or entity exercising the Licensed Rights + under this Public License. Your has a corresponding meaning. - 7. Disclaimer of Warranty. Unless required by applicable law or - agreed to in writing, Licensor provides the Work (and each - Contributor provides its Contributions) on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or - implied, including, without limitation, any warranties or conditions - of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A - PARTICULAR PURPOSE. You are solely responsible for determining the - appropriateness of using or redistributing the Work and assume any - risks associated with Your exercise of permissions under this License. - 8. Limitation of Liability. In no event and under no legal theory, - whether in tort (including negligence), contract, or otherwise, - unless required by applicable law (such as deliberate and grossly - negligent acts) or agreed to in writing, shall any Contributor be - liable to You for damages, including any direct, indirect, special, - incidental, or consequential damages of any character arising as a - result of this License or out of the use or inability to use the - Work (including but not limited to damages for loss of goodwill, - work stoppage, computer failure or malfunction, or any and all - other commercial damages or losses), even if such Contributor - has been advised of the possibility of such damages. +Section 2 -- Scope. - 9. Accepting Warranty or Additional Liability. While redistributing - the Work or Derivative Works thereof, You may choose to offer, - and charge a fee for, acceptance of support, warranty, indemnity, - or other liability obligations and/or rights consistent with this - License. However, in accepting such obligations, You may act only - on Your own behalf and on Your sole responsibility, not on behalf - of any other Contributor, and only if You agree to indemnify, - defend, and hold each Contributor harmless for any liability - incurred by, or claims asserted against, such Contributor by reason - of your accepting any such warranty or additional liability. + a. License grant. - END OF TERMS AND CONDITIONS + 1. Subject to the terms and conditions of this Public License, + the Licensor hereby grants You a worldwide, royalty-free, + non-sublicensable, non-exclusive, irrevocable license to + exercise the Licensed Rights in the Licensed Material to: - APPENDIX: How to apply the Apache License to your work. + a. reproduce and Share the Licensed Material, in whole or + in part; and - To apply the Apache License to your work, attach the following - boilerplate notice, with the fields enclosed by brackets "{}" - replaced with your own identifying information. (Don't include - the brackets!) The text should be enclosed in the appropriate - comment syntax for the file format. We also recommend that a - file or class name and description of purpose be included on the - same "printed page" as the copyright notice for easier - identification within third-party archives. + b. produce, reproduce, and Share Adapted Material. - Copyright 2016 The Kubernetes Authors + 2. Exceptions and Limitations. For the avoidance of doubt, where + Exceptions and Limitations apply to Your use, this Public + License does not apply, and You do not need to comply with + its terms and conditions. - Licensed under the Apache License, Version 2.0 (the "License"); - you may not use this file except in compliance with the License. - You may obtain a copy of the License at + 3. Term. The term of this Public License is specified in Section + 6(a). - http://www.apache.org/licenses/LICENSE-2.0 + 4. Media and formats; technical modifications allowed. The + Licensor authorizes You to exercise the Licensed Rights in + all media and formats whether now known or hereafter created, + and to make technical modifications necessary to do so. The + Licensor waives and/or agrees not to assert any right or + authority to forbid You from making technical modifications + necessary to exercise the Licensed Rights, including + technical modifications necessary to circumvent Effective + Technological Measures. For purposes of this Public License, + simply making modifications authorized by this Section 2(a) + (4) never produces Adapted Material. - Unless required by applicable law or agreed to in writing, software - distributed under the License is distributed on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - See the License for the specific language governing permissions and - limitations under the License. + 5. Downstream recipients. + + a. Offer from the Licensor -- Licensed Material. Every + recipient of the Licensed Material automatically + receives an offer from the Licensor to exercise the + Licensed Rights under the terms and conditions of this + Public License. + + b. No downstream restrictions. You may not offer or impose + any additional or different terms or conditions on, or + apply any Effective Technological Measures to, the + Licensed Material if doing so restricts exercise of the + Licensed Rights by any recipient of the Licensed + Material. + + 6. No endorsement. Nothing in this Public License constitutes or + may be construed as permission to assert or imply that You + are, or that Your use of the Licensed Material is, connected + with, or sponsored, endorsed, or granted official status by, + the Licensor or others designated to receive attribution as + provided in Section 3(a)(1)(A)(i). + + b. Other rights. + + 1. Moral rights, such as the right of integrity, are not + licensed under this Public License, nor are publicity, + privacy, and/or other similar personality rights; however, to + the extent possible, the Licensor waives and/or agrees not to + assert any such rights held by the Licensor to the limited + extent necessary to allow You to exercise the Licensed + Rights, but not otherwise. + + 2. Patent and trademark rights are not licensed under this + Public License. + + 3. To the extent possible, the Licensor waives any right to + collect royalties from You for the exercise of the Licensed + Rights, whether directly or through a collecting society + under any voluntary or waivable statutory or compulsory + licensing scheme. In all other cases the Licensor expressly + reserves any right to collect such royalties. + + +Section 3 -- License Conditions. + +Your exercise of the Licensed Rights is expressly made subject to the +following conditions. + + a. Attribution. + + 1. If You Share the Licensed Material (including in modified + form), You must: + + a. retain the following if it is supplied by the Licensor + with the Licensed Material: + + i. identification of the creator(s) of the Licensed + Material and any others designated to receive + attribution, in any reasonable manner requested by + the Licensor (including by pseudonym if + designated); + + ii. a copyright notice; + + iii. a notice that refers to this Public License; + + iv. a notice that refers to the disclaimer of + warranties; + + v. a URI or hyperlink to the Licensed Material to the + extent reasonably practicable; + + b. indicate if You modified the Licensed Material and + retain an indication of any previous modifications; and + + c. indicate the Licensed Material is licensed under this + Public License, and include the text of, or the URI or + hyperlink to, this Public License. + + 2. You may satisfy the conditions in Section 3(a)(1) in any + reasonable manner based on the medium, means, and context in + which You Share the Licensed Material. For example, it may be + reasonable to satisfy the conditions by providing a URI or + hyperlink to a resource that includes the required + information. + + 3. If requested by the Licensor, You must remove any of the + information required by Section 3(a)(1)(A) to the extent + reasonably practicable. + + 4. If You Share Adapted Material You produce, the Adapter's + License You apply must not prevent recipients of the Adapted + Material from complying with this Public License. + + +Section 4 -- Sui Generis Database Rights. + +Where the Licensed Rights include Sui Generis Database Rights that +apply to Your use of the Licensed Material: + + a. for the avoidance of doubt, Section 2(a)(1) grants You the right + to extract, reuse, reproduce, and Share all or a substantial + portion of the contents of the database; + + b. if You include all or a substantial portion of the database + contents in a database in which You have Sui Generis Database + Rights, then the database in which You have Sui Generis Database + Rights (but not its individual contents) is Adapted Material; and + + c. You must comply with the conditions in Section 3(a) if You Share + all or a substantial portion of the contents of the database. + +For the avoidance of doubt, this Section 4 supplements and does not +replace Your obligations under this Public License where the Licensed +Rights include other Copyright and Similar Rights. + + +Section 5 -- Disclaimer of Warranties and Limitation of Liability. + + a. UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE + EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS + AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF + ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS, + IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION, + WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR + PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS, + ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT + KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT + ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU. + + b. TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE + TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION, + NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT, + INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES, + COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR + USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN + ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR + DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR + IN PART, THIS LIMITATION MAY NOT APPLY TO YOU. + + c. The disclaimer of warranties and limitation of liability provided + above shall be interpreted in a manner that, to the extent + possible, most closely approximates an absolute disclaimer and + waiver of all liability. + + +Section 6 -- Term and Termination. + + a. This Public License applies for the term of the Copyright and + Similar Rights licensed here. However, if You fail to comply with + this Public License, then Your rights under this Public License + terminate automatically. + + b. Where Your right to use the Licensed Material has terminated under + Section 6(a), it reinstates: + + 1. automatically as of the date the violation is cured, provided + it is cured within 30 days of Your discovery of the + violation; or + + 2. upon express reinstatement by the Licensor. + + For the avoidance of doubt, this Section 6(b) does not affect any + right the Licensor may have to seek remedies for Your violations + of this Public License. + + c. For the avoidance of doubt, the Licensor may also offer the + Licensed Material under separate terms or conditions or stop + distributing the Licensed Material at any time; however, doing so + will not terminate this Public License. + + d. Sections 1, 5, 6, 7, and 8 survive termination of this Public + License. + + +Section 7 -- Other Terms and Conditions. + + a. The Licensor shall not be bound by any additional or different + terms or conditions communicated by You unless expressly agreed. + + b. Any arrangements, understandings, or agreements regarding the + Licensed Material not stated herein are separate from and + independent of the terms and conditions of this Public License. + + +Section 8 -- Interpretation. + + a. For the avoidance of doubt, this Public License does not, and + shall not be interpreted to, reduce, limit, restrict, or impose + conditions on any use of the Licensed Material that could lawfully + be made without permission under this Public License. + + b. To the extent possible, if any provision of this Public License is + deemed unenforceable, it shall be automatically reformed to the + minimum extent necessary to make it enforceable. If the provision + cannot be reformed, it shall be severed from this Public License + without affecting the enforceability of the remaining terms and + conditions. + + c. No term or condition of this Public License will be waived and no + failure to comply consented to unless expressly agreed to by the + Licensor. + + d. Nothing in this Public License constitutes or may be interpreted + as a limitation upon, or waiver of, any privileges and immunities + that apply to the Licensor or You, including from the legal + processes of any jurisdiction or authority. + + +======================================================================= + +Creative Commons is not a party to its public +licenses. Notwithstanding, Creative Commons may elect to apply one of +its public licenses to material it publishes and in those instances +will be considered the “Licensor.” The text of the Creative Commons +public licenses is dedicated to the public domain under the CC0 Public +Domain Dedication. Except for the limited purpose of indicating that +material is shared under a Creative Commons public license or as +otherwise permitted by the Creative Commons policies published at +creativecommons.org/policies, Creative Commons does not authorize the +use of the trademark "Creative Commons" or any other trademark or logo +of Creative Commons without its prior written consent including, +without limitation, in connection with any unauthorized modifications +to any of its public licenses or any other arrangements, +understandings, or agreements concerning use of licensed material. For +the avoidance of doubt, this paragraph does not form part of the +public licenses. + +Creative Commons may be contacted at creativecommons.org. diff --git a/_data/support.yml b/_data/support.yml index 1b8e80699a..3e9ec08ee4 100644 --- a/_data/support.yml +++ b/_data/support.yml @@ -53,5 +53,3 @@ toc: path: https://github.com/kubernetes/kubernetes/milestones/ - title: Contributing to Kubernetes Documentation path: /editdocs/ - - title: New Template Instructions - path: /docs/templatedemos/ diff --git a/_includes/footer.html b/_includes/footer.html index e7fa36d26a..5e724f710c 100644 --- a/_includes/footer.html +++ b/_includes/footer.html @@ -24,6 +24,6 @@ Contribute to the K8s codebase -
© {{ 'now' | date: "%Y" }} Kubernetes
+
© {{ 'now' | date: "%Y" }} The Kubernetes Authors | Distributed under CC BY 4.0
diff --git a/_includes/head-header.html b/_includes/head-header.html index 0405f3699c..17a83fa31e 100644 --- a/_includes/head-header.html +++ b/_includes/head-header.html @@ -13,6 +13,7 @@ + Kubernetes - {{ title }} diff --git a/docs/admin/authentication.md b/docs/admin/authentication.md index 3d73f527bf..b0f1aa5cc1 100644 --- a/docs/admin/authentication.md +++ b/docs/admin/authentication.md @@ -35,8 +35,8 @@ or be treated as an anonymous user. ## Authentication strategies Kubernetes uses client certificates, bearer tokens, an authenticating proxy, or HTTP basic auth to -authenticate API requests through authentication plugins. As HTTP request are -made to the API server plugins attempts to associate the following attributes +authenticate API requests through authentication plugins. As HTTP requests are +made to the API server, plugins attempt to associate the following attributes with the request: * Username: a string which identifies the end user. Common values might be `kube-admin` or `jane@example.com`. @@ -420,7 +420,7 @@ enterprise directory, kerberos, etc.) ### Creating Certificates When using client certificate authentication, you can generate certificates -using an existing deployment script or manually through `easyrsa` or `openssl.`` +using an existing deployment script or manually through `easyrsa` or `openssl.` #### Using an Existing Deployment Script diff --git a/docs/admin/node.md b/docs/admin/node.md index 78ef3c4b2e..01e8f8bae7 100644 --- a/docs/admin/node.md +++ b/docs/admin/node.md @@ -11,44 +11,39 @@ assignees: ## What is a node? -`Node` is a worker machine in Kubernetes, previously known as `Minion`. Node +A `node` is a worker machine in Kubernetes, previously known as a `minion`. A node may be a VM or physical machine, depending on the cluster. Each node has -the services necessary to run [Pods](/docs/user-guide/pods) and is managed by the master -components. The services on a node include docker, kubelet and network proxy. See +the services necessary to run [pods](/docs/user-guide/pods) and is managed by the master +components. The services on a node include Docker, kubelet and kube-proxy. See [The Kubernetes Node](https://github.com/kubernetes/kubernetes/blob/{{page.githubbranch}}/docs/design/architecture.md#the-kubernetes-node) section in the architecture design doc for more details. ## Node Status -Node status describes current status of a node. For now, there are the following -pieces of information: +A node's status is comprised of the following information. -### Node Addresses +### Addresses The usage of these fields varies depending on your cloud provider or bare metal configuration. * HostName: The hostname as reported by the node's kernel. Can be overridden via the kubelet `--hostname-override` parameter. +* ExternalIP: Typically the IP address of the node that is externally routable (available from outside the cluster). +* InternalIP: Typically the IP address of the node that is routable only within the cluster. -* ExternalIP: Generally the IP address of the node that is externally routable (available from outside the cluster) +### Phase -* InternalIP: Generally the IP address of the node that is routable only within the cluster +Deprecated: node phase is no longer used. - -### Node Phase - -Deprecated: Node Phase is no longer used - -### Node Condition +### Condition The `conditions` field describes the status of all `Running` nodes. | Node Condition | Description | |----------------|-------------| -| `OutOfDisk` | `True` if insufficient free space on the node for adding new pods, otherwise `False` | -| `Ready` | `True` if the node is healthy ready to accept pods, `False` if the node is not healthy and is not accepting pods, and `Unknown` if the Node Controller has not heard from the node in the last 40 seconds | +| `OutOfDisk` | `True` if there is insufficient free space on the node for adding new pods, otherwise `False` | +| `Ready` | `True` if the node is healthy and ready to accept pods, `False` if the node is not healthy and is not accepting pods, and `Unknown` if the node controller has not heard from the node in the last 40 seconds | -Node condition is represented as a JSON object. For example, the following response describes a healthy node: -conditions mean the node is in sane state: +The node condition is represented as a JSON object. For example, the following response describes a healthy node. ```json "conditions": [ @@ -59,28 +54,31 @@ conditions mean the node is in sane state: ] ``` -If the Status of the Ready condition -is Unknown or False for more than five minutes, then all of the Pods on the node are terminated by the Node Controller. +If the Status of the Ready condition is Unknown or False for more than five +minutes, then all of the pods on the node are terminated by the node +controller. (The timeout length is configurable by the `--pod-eviction-timeout` +parameter on the controller manager.) -### Node Capacity +### Capacity -Describes the resources available on the node: CPUs, memory and the maximum +Describes the resources available on the node: CPU, memory and the maximum number of pods that can be scheduled onto the node. -### Node Info +### Info -General information about the node, for instance kernel version, Kubernetes version -(kubelet version, kube-proxy version), docker version (if used), OS name. +General information about the node, such as kernel version, Kubernetes version +(kubelet and kube-proxy version), Docker version (if used), OS name. The information is gathered by Kubelet from the node. -## Node Management +## Management -Unlike [Pods](/docs/user-guide/pods) and [Services](/docs/user-guide/services), a Node is not inherently -created by Kubernetes: it is either taken from cloud providers like Google Compute Engine, -or from your pool of physical or virtual machines. What this means is that when -Kubernetes creates a node, it is really just creating an object that represents the node in its internal state. -After creation, Kubernetes will check whether the node is valid or not. -For example, if you try to create a node from the following content: +Unlike [pods](/docs/user-guide/pods) and [services](/docs/user-guide/services), +a node is not inherently created by Kubernetes: it is created externally by cloud +providers like Google Compute Engine, or exists in your pool of physical or virtual +machines. What this means is that when Kubernetes creates a node, it is really +just creating an object that represents the node. After creation, Kubernetes +will check whether the node is valid or not. For example, if you try to create +a node from the following content: ```json { @@ -95,117 +93,127 @@ For example, if you try to create a node from the following content: } ``` -Kubernetes will create a Node object internally (the representation), and -validate the node by health checking based on the `metadata.name` field: we -assume `metadata.name` can be resolved. If the node is valid, i.e. all necessary -services are running, it is eligible to run a Pod; otherwise, it will be -ignored for any cluster activity, until it becomes valid. Note that Kubernetes -will keep the object for the invalid node unless it is explicitly deleted by the client, and it will keep -checking to see if it becomes valid. +Kubernetes will create a node object internally (the representation), and +validate the node by health checking based on the `metadata.name` field (we +assume `metadata.name` can be resolved). If the node is valid, i.e. all necessary +services are running, it is eligible to run a pod; otherwise, it will be +ignored for any cluster activity until it becomes valid. Note that Kubernetes +will keep the object for the invalid node unless it is explicitly deleted by +the client, and it will keep checking to see if it becomes valid. -Currently, there are three components that interact with the Kubernetes node interface: Node Controller, Kubelet, and kubectl. +Currently, there are three components that interact with the Kubernetes node +interface: node controller, kubelet, and kubectl. ### Node Controller -Node controller is a component in Kubernetes master which manages Node -objects. +The node controller is a Kubernetes master component which manages various +aspects of nodes. -Node controller has mutliple roles in Node's life. First is assigning a CIDR block to -the Node when it is registered (if CIDR assignment is turned on). Second is keeping the -node controller's list of nodes up to date with the cloud provider's list of available -machines. When running in cloud environment whenever a node is unhealthy node controller -asks cloud provider if the VM for that node is still available. If not, the node +The node controller has multiple roles in a node's life. The first is assigning a +CIDR block to the node when it is registered (if CIDR assignment is turned on). + +The second is keeping the node controller's internal list of nodes up to date with +the cloud provider's list of available machines. When running in a cloud +environment, whenever a node is unhealthy the node controller asks the cloud +provider if the VM for that node is still available. If not, the node controller deletes the node from its list of nodes. -Third responsibiliy is monitoring Node's health. Node controller is responsible for updating -the NodeReady condition of NodeStatus to ConditionUnknown when a node becomes unreachable -(i.e. node controller stops receiving heartbeats e.g. due to the node being down), and then -later evicting all the pods from the node (using graceful termination) if the node continues -to be unreachable (the current timeouts are 40s to start reporting ConditionUnknown and 5m -after that to start evicting pods). Node controller checks the state of each node every -`--node-monitor-period` seconds. +The third is monitoring the nodes' health. The node controller is +responsible for updating the NodeReady condition of NodeStatus to +ConditionUnknown when a node becomes unreachable (i.e. the node controller stops +receiving heartbeats for some reason, e.g. due to the node being down), and then later evicting +all the pods from the node (using graceful termination) if the node continues +to be unreachable. (The default timeouts are 40s to start reporting +ConditionUnknown and 5m after that to start evicting pods.) The node controller +checks the state of each node every `--node-monitor-period` seconds. -In 1.4 release we updated the logic of node controller to better handle cases when a -big number of Nodes have problems with reaching the master machine (e.g. because -master machine has networking problem). Starting with 1.4 node controller will look at the -state of all Nodes in the cluster when making a decision about pod eviction. +In Kubernetes 1.4, we updated the logic of the node controller to better handle +cases when a big number of nodes have problems with reaching the master +(e.g. because the master has networking problem). Starting with 1.4, the node +controller will look at the state of all nodes in the cluster when making a +decision about pod eviction. -In most cases, node controller limits the eviction rate to `--node-eviction-rate` (default 0.1) -per second, meaning it won't evict pods from more than 1 node per 10 seconds. +In most cases, node controller limits the eviction rate to +`--node-eviction-rate` (default 0.1) per second, meaning it won't evict pods +from more than 1 node per 10 seconds. -The node eviction behavior changes when a node in a given availability zone becomes unhealthy, -node controller checks what percentage of nodes in the zone are unhealthy (NodeReady condition -is ConditionUnknown or ConditionFalse) at the same time. If the fraction of unhealthy nodes is -at least `--unhealthy-zone-threshold` (default 0.55) then the eviction rate is reduced: if -the cluster is small (i.e. has less than or equal to `--large-cluster-size-threshold` -nodes - default 50) then evictions are stopped, otherwise the eviction rate is reduced to -`--secondary-node-eviction-rate` (default 0.01) per second. The reason these policies are -implemented per availability zone is because one availability zone might become partitioned -from the master while the others remain connected. If your cluster does not span multiple cloud -provider availability zones, then there is only one availability zone, namely the whole cluster. +The node eviction behavior changes when a node in a given availability zone +becomes unhealthy. The node controller checks what percentage of nodes in the zone +are unhealthy (NodeReady condition is ConditionUnknown or ConditionFalse) at +the same time. If the fraction of unhealthy nodes is at least +`--unhealthy-zone-threshold` (default 0.55) then the eviction rate is reduced: +if the cluster is small (i.e. has less than or equal to +`--large-cluster-size-threshold` nodes - default 50) then evictions are +stopped, otherwise the eviction rate is reduced to +`--secondary-node-eviction-rate` (default 0.01) per second. The reason these +policies are implemented per availability zone is because one availability zone +might become partitioned from the master while the others remain connected. If +your cluster does not span multiple cloud provider availability zones, then +there is only one availability zone (the whole cluster). -A key reason for spreading your nodes across availability zones is so that workload can be -shifted to healthy zones when one entire zone goes down. To enable this behavior, if all -nodes in a zone are unhealthy then node controller evicts at the normal rate `--node-eviction-rate`. -The corner case for that is when all zones are completely unhealthy (i.e. there's no healthy node in -the cluster). In such case node controller assumes that there's some problem with master machine -connectivity and stops all evictions until any connectivity is restored. +A key reason for spreading your nodes across availability zones is so that the +workload can be shifted to healthy zones when one entire zone goes down. +Therefore, if all nodes in a zone are unhealthy then node controller evicts at +the normal rate `--node-eviction-rate`. The corner case is when all zones are +completely unhealthy (i.e. there are no healthy nodes in the cluster). In such +case, the node controller assumes that there's some problem with master +connectivity and stops all evictions until some connectivity is restored. ### Self-Registration of Nodes -When kubelet flag `--register-node` is true (the default), the kubelet will attempt to +When the kubelet flag `--register-node` is true (the default), the kubelet will attempt to register itself with the API server. This is the preferred pattern, used by most distros. For self-registration, the kubelet is started with the following options: - - `--api-servers=` tells the kubelet the location of the apiserver. - - `--kubeconfig` tells kubelet where to find credentials to authenticate itself to the apiserver. - - `--cloud-provider=` tells the kubelet how to talk to a cloud provider to read metadata about itself. - - `--register-node` tells the kubelet to create its own node resource. + - `--api-servers=` - Location of the apiservers. + - `--kubeconfig=` - Path to credentials to authenticate itself to the apiserver. + - `--cloud-provider=` - How to talk to a cloud provider to read metadata about itself. + - `--register-node` - Automatically register with the API server. Currently, any kubelet is authorized to create/modify any node resource, but in practice it only creates/modifies -its own. (In the future, we plan to limit authorization to only allow a kubelet to modify its own Node resource.) +its own. (In the future, we plan to only allow a kubelet to modify its own node resource.) #### Manual Node Administration -A cluster administrator can create and modify Node objects. +A cluster administrator can create and modify node objects. -If the administrator wishes to create node objects manually, set kubelet flag +If the administrator wishes to create node objects manually, set the kubelet flag `--register-node=false`. -The administrator can modify Node resources (regardless of the setting of `--register-node`). -Modifications include setting labels on the Node, and marking it unschedulable. +The administrator can modify node resources (regardless of the setting of `--register-node`). +Modifications include setting labels on the node and marking it unschedulable. Labels on nodes can be used in conjunction with node selectors on pods to control scheduling, -e.g. to constrain a Pod to only be eligible to run on a subset of the nodes. +e.g. to constrain a pod to only be eligible to run on a subset of the nodes. -Making a node unscheduleable will prevent new pods from being scheduled to that -node, but will not affect any existing pods on the node. This is useful as a -preparatory step before a node reboot, etc. For example, to mark a node +Marking a node as unscheduleable will prevent new pods from being scheduled to that +node, but will not affect any existing pods on the node. This is useful as a +preparatory step before a node reboot, etc. For example, to mark a node unschedulable, run this command: ```shell -kubectl patch nodes $NODENAME -p '{"spec": {"unschedulable": true}}' +kubectl cordon $NODENAME ``` Note that pods which are created by a daemonSet controller bypass the Kubernetes scheduler, -and do not respect the unschedulable attribute on a node. The assumption is that daemons belong on +and do not respect the unschedulable attribute on a node. The assumption is that daemons belong on the machine even if it is being drained of applications in preparation for a reboot. ### Node capacity -The capacity of the node (number of cpus and amount of memory) is part of the node resource. -Normally, nodes register themselves and report their capacity when creating the node resource. If +The capacity of the node (number of cpus and amount of memory) is part of the node object. +Normally, nodes register themselves and report their capacity when creating the node object. If you are doing [manual node administration](#manual-node-administration), then you need to set node capacity when adding a node. The Kubernetes scheduler ensures that there are enough resources for all the pods on a node. It checks that the sum of the limits of containers on the node is no greater than the node capacity. It -includes all containers started by kubelet, but not containers started directly by docker, nor +includes all containers started by the kubelet, but not containers started directly by Docker nor processes not in containers. -If you want to explicitly reserve resources for non-Pod processes, you can create a placeholder -pod. Use the following template: +If you want to explicitly reserve resources for non-pod processes, you can create a placeholder +pod. Use the following template: ```yaml apiVersion: v1 diff --git a/docs/admin/rescheduler.md b/docs/admin/rescheduler.md index f32c185c81..e1a2cca5de 100644 --- a/docs/admin/rescheduler.md +++ b/docs/admin/rescheduler.md @@ -43,6 +43,7 @@ killed for this purpose. Rescheduler doesn't have any user facing configuration (component config) or API. It's enabled by default. It can be disabled: + * during cluster setup by setting `ENABLE_RESCHEDULER` flag to `false` * on running cluster by deleting its manifest from master node (default path `/etc/kubernetes/manifests/rescheduler.manifest`) @@ -51,6 +52,7 @@ It's enabled by default. It can be disabled: To be critical an add-on has to run in `kube-system` namespace (cofigurable via flag) and have the following annotations specified: + * `scheduler.alpha.kubernetes.io/critical-pod` set to empty string * `scheduler.alpha.kubernetes.io/tolerations` set to `[{"key":"CriticalAddonsOnly", "operator":"Exists"}]` diff --git a/docs/contribute/page-templates.md b/docs/contribute/page-templates.md index 5bea261e3c..4b19cde39b 100644 --- a/docs/contribute/page-templates.md +++ b/docs/contribute/page-templates.md @@ -1,4 +1,7 @@ --- +redirect_from: + - /docs/templatedemos/ + - /docs/templatedemos.html ---