zh-trans: merge zh content from release-1.16-temporary into release-1.16 (#18216)
* Update http-proxy-access-api.md (#16932) * Update coredns.md (#16930) * zh-trans:/docs/docs/concepts/workloads/pods/ephemeral-containers.md (#16948) * update zh-trans of define-environment-variable-container.md (#16999) Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> * update chinese docs (#16985) * Fix ordered list (#16988) Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> * zh-trans:/docs/reference/setup-tools/kubeadm/kubeadm-upgrade-phase.md (#16951) Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> * Remove redundant symbol and fix some ordered list (#17000) Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> * update-zh-translation/docs/reference/setup-tools/kubeadm/kubeadm-init.md (#16997) * update zh translation kubeadm-reset.md kubeadm-upgrade.md (#16992) * Create kubeadm_join_phase_control-plane-join_all.md (#16987) * Update web-ui-dashboard.md (#16976) * update format problem (#16956) Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> * zh-trans:/docs/docs/concepts/storage/volume-pvc-datasource.md (#17021) * update zh translation /docs/reference/access-authn-authz/webhook.md (#16860) * fix confict update zh translation (#16863) * zh-trans:/docs/concepts/workloads/pods/disruptions.md (#16983) * zh-trans:/docs/concepts/workloads/pods/disruptions.md * Update content/zh/docs/concepts/workloads/pods/disruptions.md Co-Authored-By: Qiming <tengqim@cn.ibm.com> * update zh translation content/zh/docs/reference/command-line-tools-reference/kube-scheduler.md (#17006) * Update RC's link (#16935) Signed-off-by: PingWang <wang.ping5@zte.com.cn> Update Signed-off-by: PingWang <wang.ping5@zte.com.cn> update the style Signed-off-by: PingWang <wang.ping5@zte.com.cn> * Update the links for /zh/docs/setup (#16938) Signed-off-by: PingWang <wang.ping5@zte.com.cn> * zh-trans:/docs/docs/concepts/services-networking/dual-stack.md (#17024) * update zh translation /reference/setup-tools/kubeadm/generated/kubeadm.md (#17036) * update zh tanslation /reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubelet_config_download.md (#17037) * update zh translation -/reference/setup-tools/kubeadm/generated/kubeadm_alpha.md (#17038) * update zh translation /docs/contribute/participating.md (#17040) * Fix cri-o's links to match English docs (#16936) Signed-off-by: PingWang <wang.ping5@zte.com.cn> * update zh translation content/zh/docs/reference/kubectl/jsonpath.md (#16862) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_token_generate.md (#17049) * update Unkown -> Unknown (#17062) * zh-translation:high-availability.md (#16960) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update Runnning -> Running (#17061) * zh-trans:/docs/docs/concepts/storage/volume-snapshots.md (#17054) * update zh transation /docs/reference/setup-tools/kubeadm/generated/kubeadm_reset.md (#17060) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_token_create.md (#17052) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_token.md (#17055) * update zh translation update-zh-translation-/docs/reference/setup-tools/kubeadm/generated/kubeadm_token_list.md (#17048) * update zh-translation:ha-topology.md (#17099) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-trans /reference/setup-tools/kubeadm/generated/kubeadm_config_images_list.md (#17093) * update zh translation /reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_all.md (#17083) * Add Chinese translation for scheduler-perf-tuning (#17087) Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for scheduler-perf-tuning Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for scheduler-perf-tuning Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for scheduler-perf-tuning Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> * zh trans content/zh/docs/setup/production-environment/tools/kubeadm/control-plane-flags.md (#17121) * update zh trans content/zh/docs/tasks/access-application-cluster/service-access-application-cluster.md (#17122) * zh-translation:content/zh/docs/tasks/administer-cluster/namespaces-walkthrough.md (#17105) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update-zh-translation-/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_migrate.md (#17091) * update zh trans /docs/setup/learning-environment/minikube.md (#17143) * update zh trans /zh/docs/reference/_index.md (#17146) * update zh trans /docs/tasks/access-application-cluster/port-forward-access-application-cluster.md (#17134) * update zh translation 20191020-update-zh-translation-/docs/contribute/localization.md (#17046) * update zh trans /docs/reference/using-api/client-libraries.md (#17144) * update zh trans /docs/reference/setup-tools/kubeadm/generated/kubeadm_version.md (#17145) * update zh /docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade_node.md (#17131) * update zh translation /reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_front-proxy-client.md (#17081) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig.md (#17078) * add zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-join_update-status.md (#17076) * update zh trans content/zh/docs/contribute/generate-ref-docs/kubectl.md (#17165) * update zh translation /reference/command-line-tools-reference/kube-proxy.md (#17107) * zh-trans:/docs/docs/concepts/workloads/pods/pod-topology-spread-const… (#16955) * zh-trans:/docs/docs/concepts/workloads/pods/pod-topology-spread-constraints.md * Update pod-topology-spread-constraints.md * zh-trans:/docs/concepts/configuration/scheduling-framework.md (#17088) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_upload-config_kubelet.md (#17079) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane_apiserver.md (#17077) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-join.md (#17075) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_token_delete.md (#17050) * update zh trans /docs/concepts/overview/working-with-objects/namespaces.md (#17205) * update zh trans /docs/concepts/overview/what-is-kubernetes.md (#17203) * pr_release-1.16_crictl (#17201) * update zh docs/tasks/administer-cluster/dns-debugging-resolution.md (#17186) * update zh trans content/zh/docs/concepts/overview/working-with-objects/field-selectors.md (#17191) * translate configure_upgrade_etcd (#17160) * translate kubeadm_upgrade_apply (#17159) * update zh /docs/tasks/job/coarse-parallel-processing-work-queue.md (#17155) * translate docs/setup/release/version-skew-policy.md to Chinese (#17142) * update zh trans content/zh/docs/tasks/access-application-cluster/create-external-load-balancer.md (#17124) * zh-trans replace the wrong translation (#17103) zh-trans replace the wrong translation * Merged 1.14~1.16 changes (#17117) * zh-trans:/docs/concepts/configuration/assign-pod-node.md (#17129) * update zh trans /docs/contribute/generate-ref-docs/kubernetes-api.md (#17161) * pr_release-1.16_basic-ss (#17169) * Add zh-trans of assign-cpu-resource.md (#17063) Signed-off-by: heqg <he.qingguo@zte.com.cn> Add zh-trans of assign-cpu-resource.md Signed-off-by: heqg <he.qingguo@zte.com.cn> Add zh-trans of assign-cpu-resource.md Signed-off-by: heqg <he.qingguo@zte.com.cn> Add zh-trans of assign-cpu-resource.md Signed-off-by: heqg <he.qingguo@zte.com.cn> Add zh-trans of assign-cpu-resource.md Signed-off-by: heqg <he.qingguo@zte.com.cn> * update zh trans content/zh/docs/concepts/overview/working-with-objects/common-labels.md (#17193) * update zh translation /docs/contribute/intermediate.md (#17041) * zh-trans:docs/setup/production-environment/turnkey/tencent.md (#17207) * pr_release-1.16_mysql-wordpress-pv (#17202) * pr_release-1.16_reconfig-kubelet (#17200) * zh-trans:/docs/docs/concepts/workloads/controllers/jobs-run-completio… (#17020) * zh-trans:/docs/docs/concepts/workloads/controllers/jobs-run-completion.md * Update jobs-run-completion.md * Update jobs-run-completion.md * update zh trans content/zh/docs/concepts/extend-kubernetes/extend-cluster.md (#17212) * update zh trans content/zh/docs/concepts/extend-kubernetes/api-extension/apiserver-aggregation.md (#17213) * add zh trans /docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare_kubeconfig.md (#17220) kubeadm_join_phase_control-plane-prepare_download-certs.md * add zh trans /reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs.md and /reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare.md (#17219) * update zh trans content/zh/docs/concepts/containers/images.md (#17216) * ZH-trans: add _index.md (#17214) * ZH-trans: add _index.md * add _index.md file * add _index.md files * pr_release-1.16_crd-versions (#17198) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_config_images_pull.md (#17092) * zh-trans /reference/setup-tools/kubeadm/generated/kubeadm_config_images.md (#17094) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_addon_kube-proxy.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_sa.md (#17222) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare_all.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare_certs.md (#17221) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_addon_all.md (#17223) * 013 /docs/concepts/services networking/ingress.md (#17185) * x * update zh trans content/zh/docs/concepts/services-networking/ingress.md * zh-trans:/reference/setup-tools/kubeadm/generated/kubeadm_completion.md and kubeadm_config.md (#17097) * add zh trans reference/glossary/pod-lifecycle (#17226) * update zh-translation document (#17096) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update zh-translation:setup-ha-etcd-with-kubeadm.md (#17098) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * add zh trans /docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_selfhosting.md and /docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubelet_config_enable-dynamic.md (#17227) * add zh trans /docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubeconfig_user.md and /docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_upload-config_kubeadm.md (#17228) * zh-translation:content/zh/docs/tasks/extend-kubectl/kubectl-plugins.md (#17089) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_join.md (#17080) * update zh translation /reference/setup-tools/kubeadm/generated/kubeadm_config_view.md (#17085) * zh-translation:troubleshooting-kubeadm.md (#17069) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-trans: docs/concepts/scheduling/kube-scheduler.md (#17067) * Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> * Update kube-scheduler.md * Add Chinese translation for kube-scheduler * Update kube-scheduler.md * Update kube-scheduler.md * Update kube-scheduler.md * translate pods.md and init-containers.md for branch release-1.16 (#17208) * update zh translation /docs/contribute/start.md (#17039) * zh-translation:2017-10-00-Five-Days-Of-Kubernetes-18.md (#17229) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * translate kubeadm-certs.md (#17090) * update the Illegal comment such as : (<!--、<--) (#17266) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_etcd-ca.md (#17268) * update zh /docs/concepts/architecture/cloud-controller.md (#17263) * update zh /docs/concepts/cluster-administration/logging.md (#17247) * modify the show of zh translation /concepts/overview/what-is-kubernetes.md /reference/setup-tools/kubeadm/generated/kubeadm_init.md /reference/setup-tools/kubeadm/kubeadm-init.md (#17246) * zh-translation:kubeadm_init_phase_control-plane_all.md (#17243) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-translation:kubeadm_join_phase_control-plane-join_etcd.md (#17236) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubelet-start.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_upload-certs.md (#17230) * add content/zh/docs/reference/glossary/container-runtime.md file fix-up to pass the ci and trans content/zh/docs/reference/glossary/container-runtime.md、content/zh/docs/concepts/overview/components.md (#17211) * zh-translation:mirror-pod.md (#17231) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-translation:kubeadm_init_phase_upload-config.md (#17238) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update zh /docs/concepts/workloads/pods/pod-overview.md (#17239) * update the format of zh translation content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade_apply.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade_plan.md content/zh/docs/reference/setup-tools/kubeadm/kubeadm-config.md content/zh/docs/reference/setup-tools/kubeadm/kubeadm-reset.md content/zh/docs/reference/setup-tools/kubeadm/kubeadm-token.md content/zh/docs/reference/setup-tools/kubeadm/kubeadm-upgrade.md (#17248) * Create advanced.md (#17256) * Create advanced.md * trans the advanced.md and fix the build bugs * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane_scheduler.md (#17269) * zh-translation:kubelet-integration.md (#17272) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * pr_release-1.16_out-of-resource (#17199) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_front-proxy-ca.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane_controller-manager.md (#17267) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_etcd-peer.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_admin.md (#17271) * pr_release-1.16_ext-admission-ctl (#17196) * update zh translation /docs/contribute/advanced.md (#17042) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_apiserver-etcd-client.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_ca.md (#17275) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_print.md update zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_print_init-defaults.md (#17282) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated… (#17287) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_etcd.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_upload-config_all.md update zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane.md * Update kubeadm_init_phase_etcd.md * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/… (#17285) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_etcd-server.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubelet.md update zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_apiserver.md * Update kubeadm_alpha_kubelet.md * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_all.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_addon.md fix-up bad comment kubeadm_alpha_certs_renew.md、kubeadm_alpha_certs_renew_apiserver-etcd-client.md、kubeadm_init_phase_addon_all.md (#17276) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/… (#17281) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_etcd_local.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_print_join-defaults.md * Update kubeadm_init_phase_etcd_local.md * zh trans update-daemon-set.md (#16872) * zh trans update-daemon-set.md * Update update-daemon-set.md * managing-tls-in-a-cluster.md (#16874) * update-api-object-kubectl-patch.md (#16875) * improve the zh trans /kubeadm/generated/kubeadm_init_phase_.* 1 (#17295) * improve the zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_.* (#17294) * modify the zh translation content/zh/docs/reference/setup-tools/kubea… (#17293) * modify the zh translation content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_.* * Update kubeadm_alpha.md * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_all.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_preflight.md (#17280) * add zh /docs/reference/glossary/cgroup.md (#17291) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubelet_config.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_apiserver-kubelet-client.md (#17288) * improve zh trans of command in /kubeadm/generated/kubeadm_init_phase_.* files (#17297) * improve zh command translation /kubeadm/generated/kubeadm_init_.* files (#17298) * update zh trans in /kubeadm/generated/kubeadm_.* files (#17306) * add zh trans /reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_etcd-healthcheck-client.md、/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_etcd-peer.md、/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubeconfig.md (#17308) * Improve previously translated documents (#17327) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-trans: docs/setup/production-environment/turnkey/aws.md (#17320) * Update zh.toml * update zh trans /generated/kubeadm_join_phase_.* files (#17301) * Update zh.toml * add zh /docs/reference/glossary/pod-disruption-budget.md (#17344) * pr_release-1.16_config-aggregation-layer (#17197) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_controller-manager.conf.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_scheduler.conf.md (#17390) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_scheduler.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare_control-plane.md (#17381) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_apiserver-kubelet-client.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-join_mark-control-plane.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_kubelet-start.md (#17380) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_addon_coredns.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_bootstrap-token.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_apiserver.md (#17383) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_certificate-key.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset_phase_preflight.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset_phase_update-cluster-status.md (#17385) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_admin.conf.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset_phase.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset_phase_cleanup-node.md (#17387) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_apiserver-kubelet-client.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_front-proxy-client.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_selfhosting_pivot.md (#17384) * add zh /docs/reference/glossary/limitrange.md (#17324) * add zh trans content/zh/docs/setup/best-practices/cluster-large.md (#17321) * add zh trans content/zh/docs/setup/best-practices/cluster-large.md * Update cluster-large.md * add zh trans /docs/reference/setup-tools/kubeadm/kubeadm-alpha.md、/do… (#17403) * add zh trans /docs/reference/setup-tools/kubeadm/kubeadm-alpha.md、/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_preflight.md、/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_etcd-server.md * Update kubeadm_init_phase_certs_etcd-server.md * add zh /docs/reference/glossary/cluster-operations.md (#17300) * add zh /docs/reference/glossary/applications.md (#17419) * update zh trans kubelet (#17379) * update zh trans kubelet * update the file according to feedback from reviewer tengqm * update 1000-1757 lines * update the advice zh trans * add zh /docs/reference/glossary/static-pod.md (#17418) * add zh /docs/reference/glossary/preemption.md (#17423) * add zh /docs/reference/glossary/pod-priority.md (#17421) * add zh /docs/reference/glossary/control-plane.md (#17425) * add zh /docs/reference/glossary/cluster-infrastructure.md (#17424) * pr_release-1.16_api-overview (#17444) * pr_release-1.16_daemonset (#17435) * pr_release-1.16_gc (#17445) * pr_release-1.16_qos-class (#17442) * fix QoS Class to QoS 类 (#17464) * pr_release-1.16-abac (#17427) * zh-trans:docs/setup/production-environment/turnkey/alibaba-cloud.md (#17345) * pr_release-1.16_endpoint-slice (#17468) * pr_release-1.16_taint (#17469) * pr_release-1.16_operator-pattern (#17467) * pr_release-1.16_ss (#17433) * pr_release-1.16_admission-controller (#17440) * pr_release-1.16_containerd (#17441) * pr_release-1.16_app-container (#17466) * add zh-trans content/zh/docs/setup/_index.md、content/zh/docs/setup/release/_index.md (#17503) * pr-release-1.16_enabling-endpoint-slices (#17504) * update zh trans content/zh/docs/reference/setup-tools/kubeadm/kubeadm… (#17495) * update zh trans content/zh/docs/reference/setup-tools/kubeadm/kubeadm-upgrade-phase.md、content/zh/docs/reference/setup-tools/kubeadm/kubeadm-init-phase.md * add content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_kubelet.md * pr-release-1.16_logging (#17491) * pr-release-1.16_cri (#17486) * add zh-trans:docs/setup/production-environment/turnkey/azure.md (#17482) * pattern translate into 模式 (#17485) * fix zk affinity description in zh trans (#17393) * pr-release-1.16_ephemeral-container (#17487) * pr-release-1.16_data-plane (#17489) * pr-release-1.16_cncf (#17490) * zh-trans add content\zh\docs\tools\install-minikube.md (#16920) * zh-trans add content\zh\docs\tools\install-minikube.md * zh-trans update content\zh\docs\tools\install-minikube.md * zh-trans update content\zh\docs\tools\install-minikube.md * update \docs\tasks\tools\install-minikube.md * update docs\concepts\workloads\controllers\deployment.md * update deployment.md * pr-release-1.16_extensions (#17492) * pr-release-1.16_toleration (#17493) * Revert "update zh trans content/zh/docs/reference/setup-tools/kubeadm/kubeadm… (#17495)" (#17521) This reverts commit 1134c14e0a39bdc3d1a920ac9797139a6dcccf4b. * motidy extensions in content/zh/docs/reference/glossary/extensions (#17524) * motidy toleration in content/zh/docs/reference/glossary/toleration.md (#17523) * motidy toleration in content/zh/docs/reference/glossary/toleration.md * Update toleration.md * improve zh-trans in content/zh/docs/setup/_index.md (#17526) * add zh-trans /zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_kubelet.md (#17527) * Broken Link (#17546) Issue available at https://kubernetes.io/zh/docs/concepts/containers/runtime-class/ and introduced by original English documentation (see #17543) * Update trans kubeadm_upgrade_plan.md (#17395) * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * update zh-trans of define-command-argument-container.md (#17022) Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> update zh-trans of define-command-argument-container.md Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> Add back the Original English Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> update title of define-command-argument-container.md Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> update table title and reference Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> update reference of define-command-argument-container.md Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> * ZH-trans: fix multiple jump links and update files (#17603) * ZH-trans: fix multiple jump links and update files * Update _index.html * update zh trans content/zh/docs/reference/setup-tools/kubeadm/kubeadm-init-phase.md (#17528) * update zh trans /doc/concepts/architecture/nodes.md (#17617) * update zh trans content/zh/docs/concepts/architecture/nodes.md * fix-up content/zh/docs/concepts/architecture/nodes.md * add zh-trans /docs/setup/release/notes.md (#17519) * add zh-trans /docs/setup/release/notes.md update-750 * fix-up 1575 line and udpate 2483 line * update to line 2980 * update to the last line 3160 * add zh-trans:docs/setup/production-environment/turnkey/icp.md (#17568) * zh-trans: /docs/setup/production-environment/container-runtimes.md (#17646) * zh-trs:container-runtimes.md Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * Update container-runtimes.md * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese (#17791) * Translate /docs/concepts/cluster-administration/cloud-providers.md into Chinese * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese * Sorry, wrong commit, roll back... * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese * Create trans kubeadm_upgrade_diff.md (#17392) * Update kubeadm_upgrade_diff.md * Update kubeadm_upgrade_diff.md * Update kubeadm_upgrade_diff.md * Create _index.md (#17831) * zh-trans zh-trans-/docs/reference/command-line-tools-reference/feature-gates.md (#17658) * Update volume-snapshots.md (#17829) * Update volume-snapshots.md * Update volume-snapshots.md * Update volume-snapshots.md * Create ovirt.md (#17849) * Create ovirt.md * Update ovirt.md * Translate /docs/concepts/cluster-administration/cloud-providers.md into Chinese (#17761) * Translate /docs/concepts/cluster-administration/cloud-providers.md into Chinese * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese * Sorry, wrong commit, roll back... * Update translation after tengqm's review. * Update cloud-providers.md * Update dual-stack.md (#17836) * Update dual-stack.md * Update dual-stack.md * Update dual-stack.md * Update dual-stack.md * Create validate-dual-stack.md (#17833) * Create validate-dual-stack.md * Update validate-dual-stack.md * translation content/zh/docs/reference/setup-tools/kubeadm/ kubeadm-join-phase、kubeadm-reset-phase (#17881) * zh-trans content/zh/docs/contribute/generate-ref-docs/contribute-upstream.md (#17882) * Chinese translation /docs/tasks/administer-cluster/highly-available-master.md (#17884) * Chinese translation /docs/tasks/administer-cluster/highly-available-master.md * Apply suggestions from code review Co-Authored-By: Qiming <tengqim@cn.ibm.com> * Fix format issue (#17921) * Create topology-manager.md (#17901) * Create topology-manager.md * Update topology-manager.md * add zh-trans:docs/setup/production-environment/windows/user-guide-windows-containers.md (#17876) * Update pod-overhead.md (#17931) * Update scheduler-perf-tuning.md (#17934) * Create dcos.md (#17932) * Create dcos.md * Update dcos.md * Update object-management.md (#17937) * zh-translation content/zh/docs/setup/production-environment/tools/kops.md (#17991) * Create imperative-config.md (#17956) * Create imperative-config.md * Update imperative-config.md * Create self-hosting.md (#17950) * Create resource-bin-packing.md (#17935) * Create nodelocaldns.md (#17938) * Update config.toml(release-1.16) for 1.17 (#18025) * Update config.toml(release-1.16) for 1.17 * Update config.toml * Remove ru language * fix shotcode mismatch Co-authored-by: zhangx501 <zhang0000xun@gmail.com> Co-authored-by: ZhongliangXiong <xiong.zhongliang@zte.com.cn> Co-authored-by: Yixiang Wang <wang.yixiang@zte.com.cn> Co-authored-by: li mengyang <hwdef97@gmail.com> Co-authored-by: PingWang <wang.ping5@zte.com.cn> Co-authored-by: chentanjun <tanjunchen20@gmail.com> Co-authored-by: Sophy417 <53026875+Sophy417@users.noreply.github.com> Co-authored-by: Qiming <tengqim@cn.ibm.com> Co-authored-by: yuxiaobo96 <41496192+yuxiaobo96@users.noreply.github.com> Co-authored-by: senwang <wang.sen2@zte.com.cn> Co-authored-by: lichuqiang <lichuqiang@huawei.com> Co-authored-by: lpf7551321 <liupengfei20@huawei.com> Co-authored-by: Hongcai Ren <renhongcai@huawei.com> Co-authored-by: jiajie <jiaj12@chinaunicom.cn> Co-authored-by: heqg <56527988+heqg@users.noreply.github.com> Co-authored-by: IreneByron <zhangbingqing7@huawei.com> Co-authored-by: LiuDui <1693291525@qq.com> Co-authored-by: Wang Bing <wangbing.adam@gmail.com> Co-authored-by: Damini Satya <daminisatya@gmail.com> Co-authored-by: liufangwai <liufangwai@huawei.com> Co-authored-by: wangcong <congfairy2536@gmail.com> Co-authored-by: XuefeiWang2 <wangxuefei2@huawei.com> Co-authored-by: Kubernetes Prow Robot <k8s-ci-robot@users.noreply.github.com> Co-authored-by: Ziqiu Zhu <zzqshu@126.com> Co-authored-by: ten2ton <50288981+ten2ton@users.noreply.github.com> Co-authored-by: Oleg Butuzov <butuzov@users.noreply.github.com> Co-authored-by: jiazxjason <52809535+jiazxjason@users.noreply.github.com> Co-authored-by: Coffey Gao <coffiney@qq.com> Co-authored-by: Bingshen Wang <bingshen.wbs@alibaba-inc.com>
This commit is contained in:
committed by
Kubernetes Prow Robot
parent
6be3e1414d
commit
0f2bd2871b
@@ -1,4 +1,11 @@
|
||||
---
|
||||
title: "容器"
|
||||
weight: 50
|
||||
---
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: "Containers"
|
||||
weight: 50
|
||||
---
|
||||
-->
|
||||
|
||||
@@ -1,9 +1,22 @@
|
||||
---
|
||||
reviewers:
|
||||
- mikedanese
|
||||
- thockin
|
||||
title: 容器生命周期钩子
|
||||
content_template: templates/concept
|
||||
weight: 30
|
||||
---
|
||||
|
||||
<!--
|
||||
reviewers:
|
||||
- mikedanese
|
||||
- thockin
|
||||
title: Container Lifecycle Hooks
|
||||
content_template: templates/concept
|
||||
weight: 30
|
||||
-->
|
||||
|
||||
|
||||
{{% capture overview %}}
|
||||
|
||||
<!--
|
||||
|
||||
@@ -1,73 +1,219 @@
|
||||
---
|
||||
approvers:
|
||||
- erictune
|
||||
- thockin
|
||||
title: 镜像
|
||||
content_template: templates/concept
|
||||
weight: 10
|
||||
---
|
||||
<!--
|
||||
---
|
||||
reviewers:
|
||||
- erictune
|
||||
- thockin
|
||||
title: Images
|
||||
content_template: templates/concept
|
||||
weight: 10
|
||||
---
|
||||
-->
|
||||
|
||||
{{% capture overview %}}
|
||||
|
||||
在Kubernetes pod中引用镜像前,请创建Docker镜像,并将之推送到镜像仓库中。
|
||||
容器的“image”属性支持和Docker命令行相同的语法,包括私有仓库和标签。
|
||||
<!--
|
||||
You create your Docker image and push it to a registry before referring to it in a Kubernetes pod.
|
||||
|
||||
The `image` property of a container supports the same syntax as the `docker` command does, including private registries and tags.
|
||||
-->
|
||||
创建 Docker 镜像并将其推送到仓库,然后在 Kubernetes pod 中引用它。
|
||||
|
||||
容器的 `image` 属性支持与 `docker` 命令相同的语法,包括私有仓库和标签。
|
||||
|
||||
{{% /capture %}}
|
||||
|
||||
{{< toc >}}
|
||||
|
||||
{{% capture body %}}
|
||||
|
||||
<!--
|
||||
## Updating Images
|
||||
-->
|
||||
## 升级镜像
|
||||
默认的镜像拉取策略是“IfNotPresent”,在镜像已经存在的情况下,kubelet将不在去拉取镜像。
|
||||
如果总是想要拉取镜像,必须设置拉取策略为“Always”或者设置镜像标签为“:latest”。
|
||||
|
||||
如果没有指定镜像的标签,它会被假定为“:latest”,同时拉取策略为“Always”。
|
||||
<!--
|
||||
The default pull policy is `IfNotPresent` which causes the Kubelet to skip
|
||||
pulling an image if it already exists. If you would like to always force a pull,
|
||||
you can do one of the following:
|
||||
-->
|
||||
默认的镜像拉取策略是 `IfNotPresent`,在镜像已经存在的情况下,kubelet 将不再去拉取镜像。如果总是想要拉取镜像,您可以执行以下操作:
|
||||
|
||||
注意应避免使用“:latest”标签,参见 [Best Practices for Configuration](/docs/concepts/configuration/overview/#container-images) 获取更多信息。
|
||||
<!--
|
||||
- set the `imagePullPolicy` of the container to `Always`.
|
||||
- omit the `imagePullPolicy` and use `:latest` as the tag for the image to use.
|
||||
- omit the `imagePullPolicy` and the tag for the image to use.
|
||||
- enable the [AlwaysPullImages](/docs/reference/access-authn-authz/admission-controllers/#alwayspullimages) admission controller.
|
||||
-->
|
||||
- 设置容器的 `imagePullPolicy` 为 `Always`。
|
||||
- 省略 `imagePullPolicy`,并使用 `:latest` 作为要使用的镜像的标签。
|
||||
- 省略 `imagePullPolicy` 和要使用的镜像标签。
|
||||
- 启用 [AlwaysPullImages](/docs/reference/access-authn-authz/admission-controllers/#alwayspullimages) 准入控制器(admission controller)。
|
||||
|
||||
<!--
|
||||
Note that you should avoid using `:latest` tag, see [Best Practices for Configuration](/docs/concepts/configuration/overview/#container-images) for more information.
|
||||
-->
|
||||
注意应避免使用 `:latest` 标签,参见[配置镜像最佳实践](/docs/concepts/configuration/overview/#container-images) 获取更多信息。
|
||||
|
||||
<!--
|
||||
## Building Multi-architecture Images with Manifests
|
||||
-->
|
||||
## 使用清单(manifest)构建多架构镜像
|
||||
|
||||
<!--
|
||||
Docker CLI now supports the following command `docker manifest` with sub commands like `create`, `annotate` and `push`. These commands can be used to build and push the manifests. You can use `docker manifest inspect` to view the manifest.
|
||||
-->
|
||||
Docker CLI 现在支持以下命令 `docker manifest` 以及 `create`、`annotate`、`push` 等子命令。这些命令可用于构建和推送清单。您可以使用 `docker manifest inspect` 来查看清单。
|
||||
|
||||
<!--
|
||||
Please see docker documentation here:
|
||||
https://docs.docker.com/edge/engine/reference/commandline/manifest/
|
||||
-->
|
||||
请在此处查看 docker 清单文档:
|
||||
https://docs.docker.com/edge/engine/reference/commandline/manifest/
|
||||
|
||||
<!--
|
||||
See examples on how we use this in our build harness:
|
||||
https://cs.k8s.io/?q=docker%20manifest%20(create%7Cpush%7Cannotate)&i=nope&files=&repos=
|
||||
-->
|
||||
查看有关如何在构建工具中使用清单的示例:
|
||||
https://cs.k8s.io/?q=docker%20manifest%20(create%7Cpush%7Cannotate)&i=nope&files=&repos=
|
||||
|
||||
<!--
|
||||
These commands rely on and are implemented purely on the Docker CLI. You will need to either edit the `$HOME/.docker/config.json` and set `experimental` key to `enabled` or you can just set `DOCKER_CLI_EXPERIMENTAL` environment variable to `enabled` when you call the CLI commands.
|
||||
-->
|
||||
这些命令依赖于 Docker CLI 并仅在 Docker CLI 上实现。需要编辑 `$HOME/.docker/config.json` 并将 `experimental` 设置为 `enabled`,或者仅在调用 CLI 命令时将 `DOCKER_CLI_EXPERIMENTAL` 环境变量设置为 `enabled`。
|
||||
|
||||
{{< note >}}
|
||||
<!--
|
||||
Please use Docker *18.06 or above*, versions below that either have bugs or do not support the experimental command line option. Example https://github.com/docker/cli/issues/1135 causes problems under containerd.
|
||||
-->
|
||||
请使用 Docker *18.06 或更高版本*,低版本存在错误或不支持实验性命令行选项。导致容器问题示例 https://github.com/docker/cli/issues/1135。
|
||||
{{< /note >}}
|
||||
|
||||
<!--
|
||||
If you run into trouble with uploading stale manifests, just clean up the older manifests in `$HOME/.docker/manifests` to start fresh.
|
||||
-->
|
||||
如果在上传旧清单时遇到麻烦,只需删除 `$HOME/.docker/manifests` 中旧的清单即可重新开始。
|
||||
|
||||
<!--
|
||||
For Kubernetes, we have typically used images with suffix `-$(ARCH)`. For backward compatibility, please generate the older images with suffixes. The idea is to generate say `pause` image which has the manifest for all the arch(es) and say `pause-amd64` which is backwards compatible for older configurations or YAML files which may have hard coded the images with suffixes.
|
||||
-->
|
||||
对于 Kubernetes,通常使用带有后缀 `-$(ARCH)` 的镜像。为了向后兼容,请生成带有后缀的旧镜像。想法是生成具有所有 arch(es) 清单的 `pause` 镜像,并生成 `pause-amd64` 镜像,该镜像向后兼容较早的配置或者可能已对带有后缀的镜像进行硬编码的 YAML 文件。
|
||||
|
||||
<!--
|
||||
## Using a Private Registry
|
||||
-->
|
||||
## 使用私有仓库
|
||||
|
||||
<!--
|
||||
Private registries may require keys to read images from them.
|
||||
Credentials can be provided in several ways:
|
||||
-->
|
||||
从私有仓库读取镜像时可能需要密钥。
|
||||
凭证可以用以下方式提供:
|
||||
|
||||
- 使用Google Container Registry
|
||||
- 每个集群分别配置
|
||||
- 在Google Compute Engine 或者 Google Kubernetes Engine上自动配置
|
||||
- 所有的pod都能读取项目的私有仓库
|
||||
- 使用 AWS EC2 Container Registry (ECR)
|
||||
- 使用IAM角色和策略来控制对ECR仓库的访问
|
||||
- 自动刷新ECR的登录凭证
|
||||
<!--
|
||||
- Using Google Container Registry
|
||||
- Per-cluster
|
||||
- automatically configured on Google Compute Engine or Google Kubernetes Engine
|
||||
- all pods can read the project's private registry
|
||||
- Using Amazon Elastic Container Registry (ECR)
|
||||
- use IAM roles and policies to control access to ECR repositories
|
||||
- automatically refreshes ECR login credentials
|
||||
- Using Oracle Cloud Infrastructure Registry (OCIR)
|
||||
- use IAM roles and policies to control access to OCIR repositories
|
||||
- Using Azure Container Registry (ACR)
|
||||
- Using IBM Cloud Container Registry
|
||||
- Configuring Nodes to Authenticate to a Private Registry
|
||||
- all pods can read any configured private registries
|
||||
- requires node configuration by cluster administrator
|
||||
- Pre-pulled Images
|
||||
- all pods can use any images cached on a node
|
||||
- requires root access to all nodes to setup
|
||||
- Specifying ImagePullSecrets on a Pod
|
||||
- only pods which provide own keys can access the private registry
|
||||
-->
|
||||
- 使用 Google Container Registry
|
||||
- 每个集群
|
||||
- 在 Google Compute Engine 或 Google Kubernetes Engine 上自动配置
|
||||
- 所有 Pod 均可读取项目的私有仓库
|
||||
- 使用 Amazon Elastic Container Registry(ECR)
|
||||
- 使用 IAM 角色和策略来控制对 ECR 仓库的访问
|
||||
- 自动刷新 ECR 登录凭据
|
||||
- 使用 Oracle Cloud Infrastructure Registry(OCIR)
|
||||
- 使用 IAM 角色和策略来控制对 OCIR 仓库的访问
|
||||
- 使用 Azure Container Registry (ACR)
|
||||
- 配置节点对私有仓库认证
|
||||
- 所有的pod都可以读取已配置的私有仓库
|
||||
- 需要集群管理员提供node的配置
|
||||
- 提前拉取镜像
|
||||
- 所有的pod都可以使用node上缓存的镜像
|
||||
- 需要以root进入node操作
|
||||
- pod上指定 ImagePullSecrets
|
||||
- 只有提供了密钥的pod才能接入私有仓库
|
||||
下面将详细描述每一项
|
||||
- 使用 IBM Cloud Container Registry
|
||||
- 配置节点用于私有仓库进行身份验证
|
||||
- 所有 Pod 均可读取任何已配置的私有仓库
|
||||
- 需要集群管理员配置节点
|
||||
- 预拉镜像
|
||||
- 所有 Pod 都可以使用节点上缓存的任何镜像
|
||||
- 需要所有节点的 root 访问权限才能进行设置
|
||||
- 在 Pod 上指定 ImagePullSecrets
|
||||
- 只有提供自己密钥的 Pod 才能访问私有仓库
|
||||
|
||||
<!--
|
||||
Each option is described in more detail below.
|
||||
-->
|
||||
下面将详细描述每一项。
|
||||
|
||||
|
||||
<!--
|
||||
### Using Google Container Registry
|
||||
-->
|
||||
### 使用 Google Container Registry
|
||||
Kuberetes运行在Google Compute Engine (GCE)时原生支持[Google ContainerRegistry (GCR)]
|
||||
(https://cloud.google.com/tools/container-registry/)。如果kubernetes集群运行在GCE
|
||||
或者Google Kubernetes Engine 上,使用镜像全名(e.g. gcr.io/my_project/image:tag)即可。
|
||||
|
||||
集群中的所有pod都会有读取这个仓库中镜像的权限。
|
||||
<!--
|
||||
Kubernetes has native support for the [Google Container
|
||||
Registry (GCR)](https://cloud.google.com/tools/container-registry/), when running on Google Compute
|
||||
Engine (GCE). If you are running your cluster on GCE or Google Kubernetes Engine, simply
|
||||
use the full image name (e.g. gcr.io/my_project/image:tag).
|
||||
-->
|
||||
Kuberetes 运行在 Google Compute Engine (GCE) 时原生支持 [Google Container
|
||||
Registry (GCR)](https://cloud.google.com/tools/container-registry/)。如果 kubernetes 集群运行在 GCE 或者 Google Kubernetes Engine,使用镜像全名(例如 gcr.io/my_project/image:tag) 即可。
|
||||
|
||||
Kubelet将使用实例的Google service account向GCR认证。实例的service account拥有
|
||||
`https://www.googleapis.com/auth/devstorage.read_only`,所以它可以从项目的GCR拉取,但不能推送。
|
||||
|
||||
### 使用 AWS EC2 Container Registry
|
||||
<!--
|
||||
All pods in a cluster will have read access to images in this registry.
|
||||
-->
|
||||
集群中所有 pod 都会有读取这个仓库镜像的权限。
|
||||
|
||||
当Node是AWS EC2实例时,Kubernetes原生支持[AWS EC2 ContainerRegistry](https://aws.amazon.com/ecr/)。
|
||||
<!--
|
||||
The kubelet will authenticate to GCR using the instance's
|
||||
Google service account. The service account on the instance
|
||||
will have a `https://www.googleapis.com/auth/devstorage.read_only`,
|
||||
so it can pull from the project's GCR, but not push.
|
||||
-->
|
||||
kubelet 将使用实例的 Google service account 向 GCR 认证。实例的 Google service account 拥有 `https://www.googleapis.com/auth/devstorage.read_only`,所以它可以从项目的 GCR 拉取,但不能推送。
|
||||
|
||||
在pod定义中,使用镜像全名即可 (例如 `ACCOUNT.dkr.ecr.REGION.amazonaws.com/imagename:tag`)
|
||||
<!--
|
||||
### Using Amazon Elastic Container Registry
|
||||
-->
|
||||
### 使用 Amazon Elastic Container Registry
|
||||
|
||||
集群中可以创建pod的用户都可以使用ECR中的任意镜像运行pod。
|
||||
<!--
|
||||
Kubernetes has native support for the [Amazon Elastic Container Registry](https://aws.amazon.com/ecr/), when nodes are AWS EC2 instances.
|
||||
|
||||
Kubelet会获取并且定期刷新ECR的凭证。它需要以下权限
|
||||
Simply use the full image name (e.g. `ACCOUNT.dkr.ecr.REGION.amazonaws.com/imagename:tag`)
|
||||
in the Pod definition.
|
||||
-->
|
||||
当 Node 是 AWS EC2 实例时,Kubernetes 原生支持 [Amazon Elastic Container Registry](https://aws.amazon.com/ecr/)。
|
||||
|
||||
在 pod 定义中,使用镜像全名即可 (例如 `ACCOUNT.dkr.ecr.REGION.amazonaws.com/imagename:tag`)
|
||||
|
||||
<!--
|
||||
All users of the cluster who can create pods will be able to run pods that use any of the
|
||||
images in the ECR registry.
|
||||
|
||||
The kubelet will fetch and periodically refresh ECR credentials. It needs the following permissions to do this:
|
||||
-->
|
||||
集群中所有可以创建 Pod 的用户都将能够运行使用 ECR 仓库中任何镜像的 Pod。
|
||||
|
||||
kubelet 将获取并定期刷新 ECR 凭据。它需要以下权限才能执行此操作:
|
||||
|
||||
- `ecr:GetAuthorizationToken`
|
||||
- `ecr:BatchCheckLayerAvailability`
|
||||
@@ -77,65 +223,192 @@ Kubelet会获取并且定期刷新ECR的凭证。它需要以下权限
|
||||
- `ecr:ListImages`
|
||||
- `ecr:BatchGetImage`
|
||||
|
||||
<!--
|
||||
Requirements:
|
||||
|
||||
- You must be using kubelet version `v1.2.0` or newer. (e.g. run `/usr/bin/kubelet --version=true`).
|
||||
- If your nodes are in region A and your registry is in a different region B, you need version `v1.3.0` or newer.
|
||||
- ECR must be offered in your region
|
||||
-->
|
||||
要求:
|
||||
|
||||
- 必须使用kubelet 1.2.0及以上版本
|
||||
- 如果node在区域A,而镜像仓库在另一个区域B,需要1.3.0及以上版本
|
||||
- 区域中必须提供ECR
|
||||
- 必须使用 kubelet `v1.2.0` 及以上版本。(例如 运行 `/usr/bin/kubelet --version=true`)。
|
||||
- 如果 Node 在区域 A,而镜像仓库在另一个区域 B,需要 `v1.3.0` 及以上版本。
|
||||
- 区域中必须提供 ECR。
|
||||
|
||||
诊断
|
||||
<!--
|
||||
Troubleshooting:
|
||||
|
||||
- 验证是否满足以上要求
|
||||
- 获取工作站的$REGION (例如 `us-west-2`)凭证,使用凭证SSH到主机手动运行docker,检查是否运行
|
||||
- 验证kubelet是否使用参数`--cloud-provider=aws`运行
|
||||
- 检查kubelet日志(例如 `journalctl -u kubelet`),是否有类似的行
|
||||
- Verify all requirements above.
|
||||
- Get $REGION (e.g. `us-west-2`) credentials on your workstation. SSH into the host and run Docker manually with those creds. Does it work?
|
||||
- Verify kubelet is running with `--cloud-provider=aws`.
|
||||
- Check kubelet logs (e.g. `journalctl -u kubelet`) for log lines like:
|
||||
- `plugins.go:56] Registering credential provider: aws-ecr-key`
|
||||
- `provider.go:91] Refreshing cache for provider: *aws_credentials.ecrProvider`
|
||||
-->
|
||||
故障排除:
|
||||
|
||||
- 验证是否满足以上要求。
|
||||
- 获取工作站的 $REGION (例如 `us-west-2`) 凭证,使用凭证 SSH 到主机手动运行 Docker。它行得通吗?
|
||||
- 验证 kubelet 是否使用参数 `--cloud-provider=aws` 运行。
|
||||
- 检查 kubelet 日志(例如 `journalctl -u kubelet`)是否有类似的行:
|
||||
- `plugins.go:56] Registering credential provider: aws-ecr-key`
|
||||
- `provider.go:91] Refreshing cache for provider: *aws_credentials.ecrProvider`
|
||||
|
||||
<!--
|
||||
### Using Azure Container Registry (ACR)
|
||||
-->
|
||||
### 使用 Azure Container Registry (ACR)
|
||||
当使用[Azure Container Registry](https://azure.microsoft.com/en-us/services/container-registry/)时,可以使用admin user或者service principal认证。
|
||||
任何一种情况,认证都通过标准的Docker authentication完成。本指南假设使用[azure-cli](https://github.com/azure/azure-cli)
|
||||
命令行工具。
|
||||
|
||||
首先,需要创建仓库并获取凭证,完整的文档请参考
|
||||
[Azure container registry documentation](https://docs.microsoft.com/en-us/azure/container-registry/container-registry-get-started-azure-cli)。
|
||||
<!--
|
||||
When using [Azure Container Registry](https://azure.microsoft.com/en-us/services/container-registry/)
|
||||
you can authenticate using either an admin user or a service principal.
|
||||
In either case, authentication is done via standard Docker authentication. These instructions assume the
|
||||
[azure-cli](https://github.com/azure/azure-cli) command line tool.
|
||||
-->
|
||||
当使用 [Azure Container Registry](https://azure.microsoft.com/en-us/services/container-registry/) 时,可以使用管理员用户或者 service principal 进行身份验证。任何一种情况,认证都通过标准的 Docker 授权完成。本指南假设使用 [azure-cli](https://github.com/azure/azure-cli) 命令行工具。
|
||||
|
||||
创建好容器仓库后,可以使用以下凭证登录:
|
||||
<!--
|
||||
You first need to create a registry and generate credentials, complete documentation for this can be found in
|
||||
the [Azure container registry documentation](https://docs.microsoft.com/en-us/azure/container-registry/container-registry-get-started-azure-cli).
|
||||
-->
|
||||
首先,需要创建仓库并获取凭证,完整的文档请参考 [Azure container registry 文档](https://docs.microsoft.com/en-us/azure/container-registry/container-registry-get-started-azure-cli)。
|
||||
|
||||
<!--
|
||||
Once you have created your container registry, you will use the following credentials to login:
|
||||
|
||||
* `DOCKER_USER` : service principal, or admin username
|
||||
* `DOCKER_PASSWORD`: service principal password, or admin user password
|
||||
* `DOCKER_REGISTRY_SERVER`: `${some-registry-name}.azurecr.io`
|
||||
* `DOCKER_EMAIL`: `${some-email-address}`
|
||||
-->
|
||||
创建好容器仓库后,可以使用以下凭证登录:
|
||||
|
||||
* `DOCKER_USER` : service principal,或管理员用户名称
|
||||
* `DOCKER_PASSWORD`: service principal 密码,或管理员用户密码
|
||||
* `DOCKER_REGISTRY_SERVER`: `${some-registry-name}.azurecr.io`
|
||||
* `DOCKER_EMAIL`: `${some-email-address}`
|
||||
|
||||
<!--
|
||||
Once you have those variables filled in you can
|
||||
[configure a Kubernetes Secret and use it to deploy a Pod](/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod).
|
||||
-->
|
||||
填写以上变量后,就可以
|
||||
[configure a Kubernetes Secret and use it to deploy a Pod](/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod)。
|
||||
[配置 Kubernetes Secret 并使用它来部署 Pod](/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod)。
|
||||
|
||||
<!--
|
||||
### Using IBM Cloud Container Registry
|
||||
IBM Cloud Container Registry provides a multi-tenant private image registry that you can use to safely store and share your Docker images. By default, images in your private registry are scanned by the integrated Vulnerability Advisor to detect security issues and potential vulnerabilities. Users in your IBM Cloud account can access your images, or you can create a token to grant access to registry namespaces.
|
||||
-->
|
||||
### 使用 IBM Cloud Container Registry
|
||||
IBM Cloud Container Registry 提供了一个多租户私有镜像仓库,可以使用它来安全地存储和共享 Docker 仓库。默认情况下,集成的 Vulnerability Advisor 会扫描私有仓库中的镜像,以检测安全问题和潜在的漏洞。IBM Cloud 帐户中的用户可以访问您的镜像,也可以创建令牌来授予对仓库命名空间的访问权限。
|
||||
|
||||
### 配置Nodes对私有仓库认证
|
||||
<!--
|
||||
To install the IBM Cloud Container Registry CLI plug-in and create a namespace for your images, see [Getting started with IBM Cloud Container Registry](https://cloud.ibm.com/docs/services/Registry?topic=registry-index#index).
|
||||
-->
|
||||
要安装 IBM Cloud Container Registry CLI 插件并为镜像创建命名空间,请参阅 [IBM Cloud Container Registry 入门](https://cloud.ibm.com/docs/services/Registry?topic=registry-index#index)。
|
||||
|
||||
**注意:** 如果在Google Kubernetes Engine 上运行集群,每个节点上都会有`.dockercfg`文件,它包含对Google Container Registry的凭证。
|
||||
不需要使用以下方法。
|
||||
<!--
|
||||
You can use the IBM Cloud Container Registry to deploy containers from [IBM Cloud public images](https://cloud.ibm.com/docs/services/Registry?topic=registry-public_images#public_images) and your private images into the `default` namespace of your IBM Cloud Kubernetes Service cluster. To deploy a container into other namespaces, or to use an image from a different IBM Cloud Container Registry region or IBM Cloud account, create a Kubernetes `imagePullSecret`. For more information, see [Building containers from images](https://cloud.ibm.com/docs/containers?topic=containers-images#images).
|
||||
-->
|
||||
可以使用 IBM Cloud Container Registry 将容器从 [IBM Cloud 公共镜像](https://cloud.ibm.com/docs/services/Registry?topic=registry-public_images#public_images) 和私有镜像部署到 IBM Cloud Kubernetes Service 集群的默认命名空间。要将容器部署到其他命名空间,或使用来自其他 IBM Cloud Container 的仓库区域或 IBM Cloud 帐户的镜像,请创建 Kubernetes `imagePullSecret`。有关更多信息,请参阅[从镜像构建容器](https://cloud.ibm.com/docs/containers?topic=containers-images#images)。
|
||||
|
||||
**注意:** 如果在AWS EC2上运行集群且准备使用EC2 Container Registry (ECR),每个node上的kubelet会管理和更新ECR的登录凭证。不需要使用以下方法。
|
||||
<!--
|
||||
### Configuring Nodes to Authenticate to a Private Registry
|
||||
-->
|
||||
### 配置 Node 对私有仓库认证
|
||||
|
||||
**注意:** 该方法适用于能够对节点进行配置的情况。该方法在GCE及在其它能自动配置节点的云平台上并不适合。
|
||||
{{< note >}}
|
||||
<!--
|
||||
If you are running on Google Kubernetes Engine, there will already be a `.dockercfg` on each node with credentials for Google Container Registry. You cannot use this approach.
|
||||
-->
|
||||
如果在 Google Kubernetes Engine 上运行集群,每个节点上都会有 `.dockercfg` 文件,它包含 Google Container Registry 的凭证。不需要使用以下方法。
|
||||
{{< /note >}}
|
||||
|
||||
Docker将私有仓库的密钥存放在`$HOME/.dockercfg`或`$HOME/.docker/config.json`文件中。Kubelet上,docker会使用root用户`$HOME`路径下的密钥。
|
||||
{{< note >}}
|
||||
<!--
|
||||
If you are running on AWS EC2 and are using the EC2 Container Registry (ECR), the kubelet on each node will
|
||||
manage and update the ECR login credentials. You cannot use this approach.
|
||||
-->
|
||||
如果在 AWS EC2 上运行集群且准备使用 EC2 Container Registry (ECR),每个 node 上的 kubelet 会管理和更新 ECR 的登录凭证。不需要使用以下方法。
|
||||
{{< /note >}}
|
||||
|
||||
推荐如下步骤来为node配置私有仓库。以下示例在PC或笔记本电脑中操作
|
||||
{{< note >}}
|
||||
<!--
|
||||
This approach is suitable if you can control node configuration. It
|
||||
will not work reliably on GCE, and any other cloud provider that does automatic
|
||||
node replacement.
|
||||
-->
|
||||
该方法适用于能够对节点进行配置的情况。该方法在 GCE 及在其它能自动配置节点的云平台上并不适合。
|
||||
{{< /note >}}
|
||||
|
||||
1.对于想要使用的每一种凭证,运行 `docker login [server]`,它会更新`$HOME/.docker/config.json`。
|
||||
1.使用编辑器查看`$HOME/.docker/config.json`,保证文件中包含了想要使用的凭证
|
||||
1.获取node列表,例如
|
||||
- 如果使用node名称,`nodes=$(kubectl get nodes -o jsonpath='{range.items[*].metadata}{.name} {end}')`
|
||||
- 如果使用node IP ,`nodes=$(kubectl get nodes -o jsonpath='{range .items[*].status.addresses[?(@.type=="ExternalIP")]}{.address} {end}')`
|
||||
1.将本地的`.docker/config.json`拷贝到每个节点root用户目录下
|
||||
- 例如: `for n in $nodes; do scp ~/.docker/config.json root@$n:/root/.docker/config.json; done`
|
||||
|
||||
创建使用私有仓库的pod来验证,例如:
|
||||
{{< note >}}
|
||||
<!--
|
||||
Kubernetes as of now only supports the `auths` and `HttpHeaders` section of docker config. This means credential helpers (`credHelpers` or `credsStore`) are not supported.
|
||||
-->
|
||||
截至目前,Kubernetes 仅支持 docker config 的 `auths` 和 `HttpHeaders` 部分。这意味着不支持凭据助手(`credHelpers` 或 `credsStore`)。
|
||||
{{< /note >}}
|
||||
|
||||
<!--
|
||||
Docker stores keys for private registries in the `$HOME/.dockercfg` or `$HOME/.docker/config.json` file. If you put the same file
|
||||
in the search paths list below, kubelet uses it as the credential provider when pulling images.
|
||||
|
||||
* `{--root-dir:-/var/lib/kubelet}/config.json`
|
||||
* `{cwd of kubelet}/config.json`
|
||||
* `${HOME}/.docker/config.json`
|
||||
* `/.docker/config.json`
|
||||
* `{--root-dir:-/var/lib/kubelet}/.dockercfg`
|
||||
* `{cwd of kubelet}/.dockercfg`
|
||||
* `${HOME}/.dockercfg`
|
||||
* `/.dockercfg`
|
||||
-->
|
||||
Docker 将私有仓库的密钥存放在 `$HOME/.dockercfg` 或 `$HOME/.docker/config.json` 文件中。Kubelet 上,docker 会使用 root 用户 `$HOME` 路径下的密钥。
|
||||
|
||||
* `{--root-dir:-/var/lib/kubelet}/config.json`
|
||||
* `{cwd of kubelet}/config.json`
|
||||
* `${HOME}/.docker/config.json`
|
||||
* `/.docker/config.json`
|
||||
* `{--root-dir:-/var/lib/kubelet}/.dockercfg`
|
||||
* `{cwd of kubelet}/.dockercfg`
|
||||
* `${HOME}/.dockercfg`
|
||||
* `/.dockercfg`
|
||||
|
||||
{{< note >}}
|
||||
<!--
|
||||
You may have to set `HOME=/root` explicitly in your environment file for kubelet.
|
||||
-->
|
||||
可能必须在环境变量文件中为 kubelet 显式设置 `HOME=/root`。
|
||||
{{< /note >}}
|
||||
|
||||
<!--
|
||||
Here are the recommended steps to configuring your nodes to use a private registry. In this
|
||||
example, run these on your desktop/laptop:
|
||||
|
||||
1. Run `docker login [server]` for each set of credentials you want to use. This updates `$HOME/.docker/config.json`.
|
||||
1. View `$HOME/.docker/config.json` in an editor to ensure it contains just the credentials you want to use.
|
||||
1. Get a list of your nodes, for example:
|
||||
- if you want the names: `nodes=$(kubectl get nodes -o jsonpath='{range.items[*].metadata}{.name} {end}')`
|
||||
- if you want to get the IPs: `nodes=$(kubectl get nodes -o jsonpath='{range .items[*].status.addresses[?(@.type=="ExternalIP")]}{.address} {end}')`
|
||||
1. Copy your local `.docker/config.json` to one of the search paths list above.
|
||||
- for example: `for n in $nodes; do scp ~/.docker/config.json root@$n:/var/lib/kubelet/config.json; done`
|
||||
-->
|
||||
推荐如下步骤来为 node 配置私有仓库。以下示例在 PC 或笔记本电脑中操作:
|
||||
|
||||
1. 对于想要使用的每一种凭证,运行 `docker login [server]`,它会更新 `$HOME/.docker/config.json`。
|
||||
2. 使用编辑器查看 `$HOME/.docker/config.json`,保证文件中包含了想要使用的凭证。
|
||||
3. 获取 node 列表,例如
|
||||
- 如果想要 node 名称,`nodes=$(kubectl get nodes -o jsonpath='{range.items[*].metadata}{.name} {end}')`
|
||||
- 如果想要 node IP ,`nodes=$(kubectl get nodes -o jsonpath='{range .items[*].status.addresses[?(@.type=="ExternalIP")]}{.address} {end}')`
|
||||
4. 将本地的 `.docker/config.json` 拷贝到每个节点 root 用户目录下
|
||||
- 例如: `for n in $nodes; do scp ~/.docker/config.json root@$n:/root/.docker/config.json; done`
|
||||
|
||||
<!--
|
||||
Verify by creating a pod that uses a private image, e.g.:
|
||||
-->
|
||||
创建使用私有仓库的 pod 来验证,例如:
|
||||
|
||||
```yaml
|
||||
$ cat <<EOF > /tmp/private-image-test-1.yaml
|
||||
kubectl apply -f - <<EOF
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
@@ -147,105 +420,147 @@ spec:
|
||||
imagePullPolicy: Always
|
||||
command: [ "echo", "SUCCESS" ]
|
||||
EOF
|
||||
$ kubectl create -f /tmp/private-image-test-1.yaml
|
||||
pod "private-image-test-1" created
|
||||
$
|
||||
pod/private-image-test-1 created
|
||||
```
|
||||
|
||||
<!--
|
||||
If everything is working, then, after a few moments, you should see:
|
||||
-->
|
||||
如果一切正常,一段时间后,可以看到:
|
||||
|
||||
```shell
|
||||
$ kubectl logs private-image-test-1
|
||||
kubectl logs private-image-test-1
|
||||
SUCCESS
|
||||
```
|
||||
|
||||
<!--
|
||||
If it failed, then you will see:
|
||||
-->
|
||||
如果失败,则可以看到:
|
||||
|
||||
```shell
|
||||
$ kubectl describe pods/private-image-test-1 | grep "Failed"
|
||||
kubectl describe pods/private-image-test-1 | grep "Failed"
|
||||
Fri, 26 Jun 2015 15:36:13 -0700 Fri, 26 Jun 2015 15:39:13 -0700 19 {kubelet node-i2hq} spec.containers{uses-private-image} failed Failed to pull image "user/privaterepo:v1": Error: image user/privaterepo:v1 not found
|
||||
```
|
||||
|
||||
<!--
|
||||
You must ensure all nodes in the cluster have the same `.docker/config.json`. Otherwise, pods will run on
|
||||
some nodes and fail to run on others. For example, if you use node autoscaling, then each instance
|
||||
template needs to include the `.docker/config.json` or mount a drive that contains it.
|
||||
-->
|
||||
必须保证集群中所有的节点都有相同的 `.docker/config.json` 文件。否则, pod 会在一些节点上正常运行而在另一些节点上无法启动。例如,如果使用 node 自动缩放,那么每个实例模板都需要包含 `.docker/config.json`,或者挂载一个包含这个文件的驱动器。
|
||||
|
||||
必须保证集群中所有的节点都有相同的`.docker/config.json`文件。否则,pod会在一些节点上正常运行而在另一些节点上无法启动
|
||||
例如,如果使用node自动弹缩,那么每个实例模板都需要包含`.docker/config.json`,或者挂载一个包含这个文件的驱动器。
|
||||
|
||||
在`.docker/config.json`中配置了私有仓库密钥后,所有pod都会能读取私有仓库中的镜像。
|
||||
|
||||
**该方法已在6月26日的docker私有仓库和kubernetes v0.19.3上测试通过,其他私有仓库,如quay.io应该也可以运行,但未测试过。**
|
||||
<!--
|
||||
All pods will have read access to images in any private registry once private
|
||||
registry keys are added to the `.docker/config.json`.
|
||||
-->
|
||||
在 `.docker/config.json` 中配置了私有仓库密钥后,所有 pod 都会能读取私有仓库中的镜像。
|
||||
|
||||
<!--
|
||||
### Pre-pulled Images
|
||||
-->
|
||||
### 提前拉取镜像
|
||||
|
||||
**注意:** 如果在Google Kubernetes Engine 上运行集群,每个节点上都会有`.dockercfg`文件,它包含对Google Container Registry的凭证。
|
||||
不需要使用以下方法。
|
||||
{{< note >}}
|
||||
<!--
|
||||
If you are running on Google Kubernetes Engine, there will already be a `.dockercfg` on each node with credentials for Google Container Registry. You cannot use this approach.
|
||||
-->
|
||||
如果在 Google Kubernetes Engine 上运行集群,每个节点上都会有 `.dockercfg` 文件,它包含 Google Container Registry 的凭证。不需要使用以下方法。
|
||||
{{< /note >}}
|
||||
|
||||
**注意:** 该方法适用于能够对节点进行配置的情况。该方法在GCE及在其它能自动配置节点的云平台上并不适合。
|
||||
{{< note >}}
|
||||
<!--
|
||||
This approach is suitable if you can control node configuration. It
|
||||
will not work reliably on GCE, and any other cloud provider that does automatic
|
||||
node replacement.
|
||||
-->
|
||||
该方法适用于能够对节点进行配置的情况。该方法在 GCE 及在其它能自动配置节点的云平台上并不适合。
|
||||
{{< /note >}}
|
||||
|
||||
默认情况下,kubelet会尝试从指定的仓库拉取每一个镜像
|
||||
但是,如果容器属性`imagePullPolicy`设置为`IfNotPresent`或者`Never`,
|
||||
则会使用本地镜像(优先、唯一、分别)。
|
||||
<!--
|
||||
By default, the kubelet will try to pull each image from the specified registry.
|
||||
However, if the `imagePullPolicy` property of the container is set to `IfNotPresent` or `Never`,
|
||||
then a local image is used (preferentially or exclusively, respectively).
|
||||
-->
|
||||
默认情况下,kubelet 会尝试从指定的仓库拉取每一个镜像。但是,如果容器属性 `imagePullPolicy` 设置为 `IfNotPresent `或者 `Never`,则会使用本地镜像(优先、唯一、分别)。
|
||||
|
||||
如果依赖提前拉取镜像代替仓库认证,
|
||||
必须保证集群所有的节点提前拉取的镜像是相同的。
|
||||
<!--
|
||||
If you want to rely on pre-pulled images as a substitute for registry authentication,
|
||||
you must ensure all nodes in the cluster have the same pre-pulled images.
|
||||
|
||||
可以用于提前载入指定的镜像以提高速度,或者作为私有仓库认证的一种替代方案
|
||||
This can be used to preload certain images for speed or as an alternative to authenticating to a private registry.
|
||||
|
||||
所有的pod都可以使用node上缓存的镜像
|
||||
All pods will have read access to any pre-pulled images.
|
||||
-->
|
||||
如果依赖提前拉取镜像代替仓库认证,必须保证集群所有的节点提前拉取的镜像是相同的。
|
||||
|
||||
### 在pod上指定ImagePullSecrets
|
||||
可以用于提前载入指定的镜像以提高速度,或者作为私有仓库认证的一种替代方案。
|
||||
|
||||
**注意:** Google Kubernetes Engine,GCE及其他自动创建node的云平台上,推荐使用本方法。
|
||||
所有的 pod 都可以使用 node 上缓存的镜像。
|
||||
|
||||
Kubernetes支持在pod中指定仓库密钥。
|
||||
<!--
|
||||
### Specifying ImagePullSecrets on a Pod
|
||||
-->
|
||||
### 在 pod 上指定 ImagePullSecrets
|
||||
|
||||
#### 使用Docker Config创建Secret
|
||||
{{< note >}}
|
||||
<!--
|
||||
This approach is currently the recommended approach for Google Kubernetes Engine, GCE, and any cloud-providers
|
||||
where node creation is automated.
|
||||
-->
|
||||
Google Kubernetes Engine、GCE 及其他自动创建 node 的云平台上,推荐使用本方法。
|
||||
{{< /note >}}
|
||||
|
||||
运行以下命令,将大写字母代替为合适的值
|
||||
<!--
|
||||
Kubernetes supports specifying registry keys on a pod.
|
||||
-->
|
||||
Kubernetes 支持在 pod 中指定仓库密钥。
|
||||
|
||||
<!--
|
||||
#### Creating a Secret with a Docker Config
|
||||
-->
|
||||
#### 使用 Docker Config 创建 Secret
|
||||
|
||||
<!--
|
||||
Run the following command, substituting the appropriate uppercase values:
|
||||
-->
|
||||
运行以下命令,将大写字母代替为合适的值:
|
||||
|
||||
```shell
|
||||
$ kubectl create secret docker-registry myregistrykey --docker-server=DOCKER_REGISTRY_SERVER --docker-username=DOCKER_USER --docker-password=DOCKER_PASSWORD --docker-email=DOCKER_EMAIL
|
||||
secret "myregistrykey" created.
|
||||
kubectl create secret docker-registry <name> --docker-server=DOCKER_REGISTRY_SERVER --docker-username=DOCKER_USER --docker-password=DOCKER_PASSWORD --docker-email=DOCKER_EMAIL
|
||||
```
|
||||
|
||||
如果需要接入多个仓库,可以为每个仓库创建一个secret。
|
||||
当为pod拉取镜像时,kubelet会将`imagePullSecrets`合入一个独立虚拟的`.docker/config.json`。
|
||||
<!--
|
||||
If you already have a Docker credentials file then, rather than using the above
|
||||
command, you can import the credentials file as a Kubernetes secret.
|
||||
[Create a Secret based on existing Docker credentials](/docs/tasks/configure-pod-container/pull-image-private-registry/#registry-secret-existing-credentials) explains how to set this up.
|
||||
This is particularly useful if you are using multiple private container
|
||||
registries, as `kubectl create secret docker-registry` creates a Secret that will
|
||||
only work with a single private registry.
|
||||
-->
|
||||
如果已经有 Docker 凭证文件,则可以将凭证文件作为 Kubernetes secret 导入而不是使用上面的命令。[根据现有 Docker 凭证创建 Secret](/docs/tasks/configure-pod-container/pull-image-private-registry/#registry-secret-existing-credentials) 解释了如何安装。如果使用多个私有容器仓库,这将特别有用,因为 `kubectl create secret docker-registry` 创建了一个仅适用于单个私有仓库的 Secret。
|
||||
|
||||
Pod只能引用和它相同namespace的ImagePullSecrets,
|
||||
所以需要为每一个namespace做配置
|
||||
{{< note >}}
|
||||
<!--
|
||||
Pods can only reference image pull secrets in their own namespace,
|
||||
so this process needs to be done one time per namespace.
|
||||
-->
|
||||
Pod 只能引用和它相同命名空间的 ImagePullSecrets,所以需要为每一个命名空间做配置。
|
||||
{{< /note >}}
|
||||
|
||||
#### 通过kubectl创建secret
|
||||
<!--
|
||||
#### Referring to an imagePullSecrets on a Pod
|
||||
-->
|
||||
#### 引用 Pod 上的 imagePullSecrets
|
||||
|
||||
由于某种原因在一个`.docker/config.json`中需要多个项或者需要非上述命令给出的secret,可以[create a secret using
|
||||
json or yaml](/docs/user-guide/secrets/#creating-a-secret-manually)。
|
||||
<!--
|
||||
Now, you can create pods which reference that secret by adding an `imagePullSecrets`
|
||||
section to a pod definition.
|
||||
-->
|
||||
现在,在创建 pod 时,可以在 pod 定义中增加 `imagePullSecrets` 部分来引用 secret。
|
||||
|
||||
请保证:
|
||||
|
||||
- 设置data项的名称为`.dockerconfigjson`
|
||||
- 使用base64对docker文件编码,并将字符准确黏贴到`data[".dockerconfigjson"]`里
|
||||
- 设置`type`为`kubernetes.io/dockerconfigjson`
|
||||
|
||||
示例:
|
||||
|
||||
```yaml
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: myregistrykey
|
||||
namespace: awesomeapps
|
||||
data:
|
||||
.dockerconfigjson: UmVhbGx5IHJlYWxseSByZWVlZWVlZWVlZWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGxsbGx5eXl5eXl5eXl5eXl5eXl5eXl5eSBsbGxsbGxsbGxsbGxsbG9vb29vb29vb29vb29vb29vb29vb29vb29vb25ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubmdnZ2dnZ2dnZ2dnZ2dnZ2dnZ2cgYXV0aCBrZXlzCg==
|
||||
type: kubernetes.io/dockerconfigjson
|
||||
```
|
||||
|
||||
如果收到错误消息`error: no objects passed to create`,可能是 base64 编码后的字符串非法。
|
||||
如果收到错误消息类似`Secret "myregistrykey" is invalid: data[.dockerconfigjson]: invalid value ...`,
|
||||
说明数据已经解码成功,但是不满足`.docker/config.json`文件的语法。
|
||||
|
||||
#### 在pod中引用imagePullSecrets
|
||||
|
||||
现在,在创建pod时,可以在pod定义中增加`imagePullSecrets`小节来引用secret
|
||||
|
||||
```yaml
|
||||
```shell
|
||||
cat <<EOF > pod.yaml
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
@@ -257,41 +572,98 @@ spec:
|
||||
image: janedoe/awesomeapp:v1
|
||||
imagePullSecrets:
|
||||
- name: myregistrykey
|
||||
EOF
|
||||
|
||||
cat <<EOF >> ./kustomization.yaml
|
||||
resources:
|
||||
- pod.yaml
|
||||
EOF
|
||||
```
|
||||
|
||||
对每一个使用私有仓库的pod,都需要做以上操作。
|
||||
<!--
|
||||
This needs to be done for each pod that is using a private registry.
|
||||
|
||||
也可以在[serviceAccount](/docs/user-guide/service-accounts) 资源中设置imagePullSecrets自动设置`imagePullSecrets`
|
||||
However, setting of this field can be automated by setting the imagePullSecrets
|
||||
in a [serviceAccount](/docs/user-guide/service-accounts) resource.
|
||||
Check [Add ImagePullSecrets to a Service Account](/docs/tasks/configure-pod-container/configure-service-account/#add-imagepullsecrets-to-a-service-account) for detailed instructions.
|
||||
-->
|
||||
对每一个使用私有仓库的 pod,都需要做以上操作。
|
||||
|
||||
`imagePullSecrets`可以和每个node上的`.docker/config.json`一起使用,他们将共同生效。本方法在Google Kubernetes Engine
|
||||
也能正常工作。
|
||||
但是,可以通过在 [serviceAccount](/docs/user-guide/service-accounts) 资源中设置 imagePullSecrets 来自动设置 `imagePullSecrets`。检查 [将 ImagePullSecrets 添加 Service Account](/docs/tasks/configure-pod-container/configure-service-account/#add-imagepullsecrets-to-a-service-account) 以获取详细说明。
|
||||
|
||||
<!--
|
||||
You can use this in conjunction with a per-node `.docker/config.json`. The credentials
|
||||
will be merged. This approach will work on Google Kubernetes Engine.
|
||||
-->
|
||||
可以将其与每个节点 `.docker/config.json` 结合使用。凭据将被合并。这种方法适用于 Google Kubernetes Engine。
|
||||
|
||||
<!--
|
||||
### Use Cases
|
||||
-->
|
||||
### 使用场景
|
||||
|
||||
<!--
|
||||
There are a number of solutions for configuring private registries. Here are some
|
||||
common use cases and suggested solutions.
|
||||
-->
|
||||
配置私有仓库有多种方案,以下是一些常用场景和建议的解决方案。
|
||||
|
||||
<!--
|
||||
1. Cluster running only non-proprietary (e.g. open-source) images. No need to hide images.
|
||||
- Use public images on the Docker hub.
|
||||
- No configuration required.
|
||||
- On GCE/Google Kubernetes Engine, a local mirror is automatically used for improved speed and availability.
|
||||
-->
|
||||
1. 集群运行非专有(例如 开源镜像)镜像。镜像不需要隐藏。
|
||||
- 使用Docker hub上的公有镜像
|
||||
- 使用 Docker hub 上的公有镜像
|
||||
- 无需配置
|
||||
- 在GCE/GKE上会自动使用高稳定性和高速的Docker hub的本地mirror
|
||||
1. 集群运行一些专有镜像,这些镜像对外部公司需要隐藏,对集群用户可见
|
||||
- 使用自主的私有[Docker registry](https://docs.docker.com/registry/).
|
||||
- 可以放置在[Docker Hub](https://hub.docker.com/account/signup/),或者其他地方。
|
||||
- 按照上面的描述,在每个节点手动配置.docker/config.json
|
||||
- 或者,在防火墙内运行一个内置的私有仓库,并开放读取权限
|
||||
- 不需要配置Kubenretes
|
||||
- 或者,在GCE/GKE上时,使用项目的Google Container Registry
|
||||
- 使用集群自动伸缩比手动配置node工作的更好
|
||||
- 或者,在更改集群node配置不方便时,使用`imagePullSecrets`
|
||||
1. 使用专有镜像的集群,有更严格的访问控制
|
||||
- 保证[AlwaysPullImages admission controller](/docs/admin/admission-controllers/#alwayspullimages)开启。否则,所有的pod都可以使用镜像
|
||||
- 将敏感数据存储在"Secret"资源中,而不是打包在镜像里
|
||||
1. 多租户集群下,每个租户需要自己的私有仓库
|
||||
- 保证[AlwaysPullImages admission controller](/docs/admin/admission-controllers/#alwayspullimages)开启。否则,所有租户的所有的pod都可以使用镜像
|
||||
- 私有仓库开启认证
|
||||
- 为每个租户获取仓库凭证,放置在secret中,并发布到每个租户的namespace下
|
||||
- 租户将secret增加到每个namespace下的imagePullSecrets中
|
||||
- 在 GCE/GKE 上会自动使用高稳定性和高速的 Docker hub 的本地 mirror
|
||||
<!--
|
||||
1. Cluster running some proprietary images which should be hidden to those outside the company, but
|
||||
visible to all cluster users.
|
||||
- Use a hosted private [Docker registry](https://docs.docker.com/registry/).
|
||||
- It may be hosted on the [Docker Hub](https://hub.docker.com/signup), or elsewhere.
|
||||
- Manually configure .docker/config.json on each node as described above.
|
||||
- Or, run an internal private registry behind your firewall with open read access.
|
||||
- No Kubernetes configuration is required.
|
||||
- Or, when on GCE/Google Kubernetes Engine, use the project's Google Container Registry.
|
||||
- It will work better with cluster autoscaling than manual node configuration.
|
||||
- Or, on a cluster where changing the node configuration is inconvenient, use `imagePullSecrets`.
|
||||
-->
|
||||
2. 集群运行一些专有镜像,这些镜像对外部公司需要隐藏,对集群用户可见
|
||||
- 使用自主的私有 [Docker registry](https://docs.docker.com/registry/)。
|
||||
- 可以放置在 [Docker Hub](https://hub.docker.com/account/signup/),或者其他地方。
|
||||
- 按照上面的描述,在每个节点手动配置 .docker/config.json。
|
||||
- 或者,在防火墙内运行一个内置的私有仓库,并开放读取权限。
|
||||
- 不需要配置 Kubenretes。
|
||||
- 或者,在 GCE/GKE 上时,使用项目的 Google Container Registry。
|
||||
- 使用集群自动伸缩比手动配置 node 工作的更好。
|
||||
- 或者,在更改集群 node 配置不方便时,使用 `imagePullSecrets`。
|
||||
<!--
|
||||
3. Cluster with proprietary images, a few of which require stricter access control.
|
||||
- Ensure [AlwaysPullImages admission controller](/docs/reference/access-authn-authz/admission-controllers/#alwayspullimages) is active. Otherwise, all Pods potentially have access to all images.
|
||||
- Move sensitive data into a "Secret" resource, instead of packaging it in an image.
|
||||
-->
|
||||
3. 使用专有镜像的集群,有更严格的访问控制。
|
||||
- 保证开启 [AlwaysPullImages admission controller](/docs/reference/access-authn-authz/admission-controllers/#alwayspullimages)。否则,所有的 pod 都可以使用镜像。
|
||||
- 将敏感数据存储在 "Secret" 资源中,而不是打包在镜像里。
|
||||
<!--
|
||||
4. A multi-tenant cluster where each tenant needs own private registry.
|
||||
- Ensure [AlwaysPullImages admission controller](/docs/reference/access-authn-authz/admission-controllers/#alwayspullimages) is active. Otherwise, all Pods of all tenants potentially have access to all images.
|
||||
- Run a private registry with authorization required.
|
||||
- Generate registry credential for each tenant, put into secret, and populate secret to each tenant namespace.
|
||||
- The tenant adds that secret to imagePullSecrets of each namespace.
|
||||
-->
|
||||
4. 多租户集群下,每个租户需要自己的私有仓库。
|
||||
- 开启保证 [AlwaysPullImages admission controller](/docs/reference/access-authn-authz/admission-controllers/#alwayspullimages)。否则,所有租户的所有的 pod 都可以使用镜像。
|
||||
- 私有仓库开启认证。
|
||||
- 为每个租户获取仓库凭证,放置在 secret 中,并发布到每个租户的命名空间下。
|
||||
- 租户将 secret 增加到每个命名空间下的 imagePullSecrets 中。
|
||||
|
||||
{{% /capture %}}
|
||||
|
||||
|
||||
<!--
|
||||
If you need access to multiple registries, you can create one secret for each registry.
|
||||
Kubelet will merge any `imagePullSecrets` into a single virtual `.docker/config.json`
|
||||
-->
|
||||
如果需要访问多个仓库,则可以为每个仓库创建一个 secret。Kubelet 将任何 `imagePullSecrets` 合并为单个虚拟 `.docker/config.json` 文件。
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
---
|
||||
reviewers:
|
||||
- tallclair
|
||||
- dchen1107
|
||||
title: 容器运行时类(Runtime Class)
|
||||
content_template: templates/concept
|
||||
weight: 20
|
||||
@@ -8,22 +11,19 @@ weight: 20
|
||||
|
||||
{{< feature-state for_k8s_version="v1.14" state="beta" >}}
|
||||
|
||||
<!--
|
||||
<!--
|
||||
This page describes the RuntimeClass resource and runtime selection mechanism.
|
||||
-->
|
||||
|
||||
这个文档主要说明了 RuntimeClass 资源和 kubernetes 指定容器运行时的功能。
|
||||
本页面描述了 RuntimeClass 资源和运行时的选择机制。
|
||||
|
||||
{{< warning >}}
|
||||
<!--
|
||||
RuntimeClass includes *breaking* changes in the beta upgrade in v1.14. If you were using
|
||||
RuntimeClass prior to v1.14, see [Upgrading RuntimeClass from Alpha to
|
||||
Beta](#upgrading-runtimeclass-from-alpha-to-beta).
|
||||
-->
|
||||
|
||||
Kubernetes1.14 的 β 版的升级包含了 RuntimeClass 的 *破坏性* 的变更。
|
||||
如果用户在使用 Kubernetes1.14 以前的 RuntimeClass 版本,
|
||||
请参考文档[从 RuntimeClass 的 α 版升级到β版](#upgrading-runtimeclass-from-alpha-to-beta)。
|
||||
-->RuntimeClass 特性在 v1.14 版本升级为 beta 特性时引入了不兼容的改变。
|
||||
如果你在 v1.14 以前的版本中使用 RuntimeClass,请查阅
|
||||
[Upgrading RuntimeClass from Alpha to Beta](#upgrading-runtimeclass-from-alpha-to-beta)。
|
||||
{{< /warning >}}
|
||||
|
||||
{{% /capture %}}
|
||||
@@ -31,101 +31,105 @@ Kubernetes1.14 的 β 版的升级包含了 RuntimeClass 的 *破坏性* 的变
|
||||
|
||||
{{% capture body %}}
|
||||
|
||||
<!--
|
||||
## Runtime Class
|
||||
|
||||
<!--
|
||||
RuntimeClass is a feature for selecting the container runtime configuration. The container runtime
|
||||
configuration is used to run a Pod's containers.
|
||||
-->
|
||||
RuntimeClass 是用于选择容器运行时配置的特性,容器运行时配置用于运行 Pod 中的容器。
|
||||
|
||||
## 关于RuntimeClass
|
||||
|
||||
RuntimeClass 是可以让用户选择容器运行时的功能。用户通过设定容器运行时可以选择 Pod 的容器运行在那种容器运行时之上。
|
||||
|
||||
<!--
|
||||
## Motivation
|
||||
|
||||
<!--
|
||||
You can set a different RuntimeClass between different Pods to provide a balance of
|
||||
performance versus security. For example, if part of your workload deserves a high
|
||||
level of information security assurance, you might choose to schedule those Pods so
|
||||
that they run in a container runtime that uses hardware virtualization. You'd then
|
||||
benefit from the extra isolation of the alternative runtime, at the expense of some
|
||||
additional overhead.
|
||||
-->
|
||||
您可以在不同的 pod 之间设置不同的 RuntimeClass,以提供性能与安全性之间的平衡。
|
||||
例如,如果您的部分工作负载需要高级别的信息安全保证,那么您可以选择性地调度这些 pod,
|
||||
使它们在使用硬件虚拟化的容器运行时中运行。
|
||||
然后,您将从可选运行时的额外隔离中获益,代价是一些额外的开销。
|
||||
|
||||
<!--
|
||||
You can also use RuntimeClass to run different Pods with the same container runtime
|
||||
but with different settings.
|
||||
-->
|
||||
## 使用场景
|
||||
用户可以为不同的 Pod 设定不同的 RuntimeClass ,以达到动态调整容器安全和容器性能间的平衡的目的。例如,
|
||||
如果用户的一部分工作需要确保高安全性,那么可以选择调度Pod使用到硬件虚拟化的容器运行时。
|
||||
受益于硬件虚拟化带来的附加的容器隔离特性的同时,也会带来性能上的额外开销。
|
||||
您还可以使用 RuntimeClass 运行具有相同容器运行时但具有不同设置的pod。
|
||||
|
||||
用户也可以通过这种方式,为Pod提供不同设定的同一种容器运行时。
|
||||
<!--
|
||||
### Set Up
|
||||
-->
|
||||
### 设置
|
||||
|
||||
<!--
|
||||
### Set Up
|
||||
|
||||
Ensure the RuntimeClass feature gate is enabled (it is by default). See [Feature
|
||||
Gates](/docs/reference/command-line-tools-reference/feature-gates/) for an explanation of enabling
|
||||
feature gates. The `RuntimeClass` feature gate must be enabled on apiservers _and_ kubelets.
|
||||
-->
|
||||
确保 RuntimeClass 特性开关处于开启状态(默认为开启状态)。
|
||||
关于特性开关的详细介绍,请查阅
|
||||
[Feature Gates](/docs/reference/command-line-tools-reference/feature-gates/)。
|
||||
`RuntimeClass` 特性开关必须在 apiservers 和 kubelets 同时开启。
|
||||
|
||||
<!--
|
||||
1. Configure the CRI implementation on nodes (runtime dependent)
|
||||
2. Create the corresponding RuntimeClass resources
|
||||
-->
|
||||
|
||||
### 设定
|
||||
|
||||
首先要先确认 RuntimeClass 功能的 Feature Gate 被设定为开启(默认是有效状态)。设定 Feature Gate 为有效的文档请参考[Feature Gates](/docs/reference/command-line-tools-reference/feature-gates/)。
|
||||
`RuntimeClass`的 Feature Gate 开启需要 ApiServer 和 kubelet 同时将相关配置开启。
|
||||
|
||||
1. 配置节点的 CRI。(依赖于容器运行时)
|
||||
2. 创建相应的 RuntimeClass 资源。
|
||||
1. 在节点上配置 CRI 的实现(取决于所选用的运行时)
|
||||
2. 创建相应的 RuntimeClass 资源
|
||||
|
||||
<!--
|
||||
#### 1. Configure the CRI implementation on nodes
|
||||
-->
|
||||
#### 1. 在节点上配置 CRI 实现
|
||||
|
||||
<!--
|
||||
The configurations available through RuntimeClass are Container Runtime Interface (CRI)
|
||||
implementation dependent. See the corresponding documentation ([below](#cri-configuration)) for your
|
||||
CRI implementation for how to configure.
|
||||
-->
|
||||
#### 1. 实现节点上的CRI设定。
|
||||
|
||||
通过 RuntimeClass 进行设定的有效化,依赖于 Container Runtime Interface (CRI) 组件。
|
||||
在用户环境中,CRI 的设定方法请参考([见下面](#cri-configuration))文档。
|
||||
RuntimeClass 的配置依赖于 运行时接口(CRI)的实现。
|
||||
根据你使用的 CRI 实现,查阅相关的文档([下方](#cri-configuration))来了解如何配置。
|
||||
|
||||
{{< note >}}
|
||||
<!--
|
||||
<!--
|
||||
RuntimeClass assumes a homogeneous node configuration across the cluster by default (which means
|
||||
that all nodes are configured the same way with respect to container runtimes). To support
|
||||
heterogenous node configurations, see [Scheduling](#scheduling) below.
|
||||
-->
|
||||
|
||||
默认情况下,RuntimeClass 被假设为所有节点上的配置均为一致。(这意味着所有的 Node 节点的容器运行时必须以相同的方式进行设定)。
|
||||
要支持不同配置构节点配置,请参见下面的[Scheduling](#scheduling)。
|
||||
|
||||
heterogenous node configurations, see [Scheduling](#scheduling) below.-->RuntimeClass 假设集群中的节点配置是同构的
|
||||
(换言之,所有的节点在容器运行时方面的配置是相同的)。
|
||||
如果需要支持异构节点,配置方法请参阅下面的 [Scheduling](#scheduling)。
|
||||
{{< /note >}}
|
||||
|
||||
<!--
|
||||
The configurations have a corresponding `handler` name, referenced by the RuntimeClass. The
|
||||
handler must be a valid DNS 1123 label (alpha-numeric + `-` characters).
|
||||
-->
|
||||
配置需要具有相应的 `handler` 名称,被用于 RuntimeClass 的设定。
|
||||
被定义的 Handler 名称必须是有效的 DNS-1123 标准。(只能使用英文字母,数字 和 `-`)。
|
||||
所有这些配置都具有相应的 `handler` 名,并被 RuntimeClass 引用。
|
||||
handler 必须符合 DNS-1123 命名规范(字母、数字、或 `-`)。
|
||||
|
||||
<!--
|
||||
#### 2. Create the corresponding RuntimeClass resources
|
||||
-->
|
||||
#### 2. 创建相应的 RuntimeClass 资源
|
||||
|
||||
<!--
|
||||
The configurations setup in step 1 should each have an associated `handler` name, which identifies
|
||||
the configuration. For each handler, create a corresponding RuntimeClass object.
|
||||
-->
|
||||
在上面步骤 1 中,每个配置都需要有一个用于标识配置的 `handler`。
|
||||
针对每个 handler 需要创建一个 RuntimeClass 对象。
|
||||
|
||||
<!--
|
||||
The RuntimeClass resource currently only has 2 significant fields: the RuntimeClass name
|
||||
(`metadata.name`) and the handler (`handler`). The object definition looks like this:
|
||||
-->
|
||||
#### 2. 创建对应的RuntimeClass资源
|
||||
|
||||
为了便于识别各个项目,安装配置的第一步需要每个项目有一个关联的 `handler` 名称。这样就可以为每个 `handler` 创建对应的 RuntimeClass 资源了。
|
||||
|
||||
所以当前 RuntimeClass 资源有两个重要的设定项。一个是 RuntimeClass 的名称( `metadata.name` )和 Handler (`handler`)。RuntimeClass 的资源定义可以参考下面的内容。
|
||||
RuntimeClass 资源当前只有两个重要的字段:RuntimeClass 名 (`metadata.name`) 和 handler (`handler`)。
|
||||
对象定义如下所示:
|
||||
|
||||
```yaml
|
||||
apiVersion: node.k8s.io/v1beta1 # RuntimeClass is defined in the node.k8s.io API group
|
||||
@@ -140,22 +144,21 @@ handler: myconfiguration # The name of the corresponding CRI configuration
|
||||
<!--
|
||||
It is recommended that RuntimeClass write operations (create/update/patch/delete) be
|
||||
restricted to the cluster administrator. This is typically the default. See [Authorization
|
||||
Overview](/docs/reference/access-authn-authz/authorization/) for more details.
|
||||
-->
|
||||
推荐只有集群管理员具有针对 RuntimeClass 的各项操作权限(create/update/patch/delete)。
|
||||
这通常是默认值。具体内容可以[授权概况](/docs/reference/access-authn-authz/authorization/)文档了解详细信息。
|
||||
Overview](/docs/reference/access-authn-authz/authorization/) for more details.-->建议将 RuntimeClass 写操作(create、update、patch 和 delete)限定于集群管理员使用。
|
||||
通常这是默认配置。参阅[授权概述](/docs/reference/access-authn-authz/authorization/)了解更多信息。
|
||||
{{< /note >}}
|
||||
|
||||
<!--
|
||||
### Usage
|
||||
-->
|
||||
### 使用说明
|
||||
|
||||
<!--
|
||||
Once RuntimeClasses are configured for the cluster, using them is very simple. Specify a
|
||||
`runtimeClassName` in the Pod spec. For example:
|
||||
-->
|
||||
### 使用方法
|
||||
|
||||
一旦集群中的 RuntimeClass 的设定完成,接下来的使用就变得非常简单了。只需要设定 PodSpec 的 `runtimeClassName` 设定项。
|
||||
例如:
|
||||
一旦完成集群中 RuntimeClasses 的配置,使用起来非常方便。
|
||||
在 Pod spec 中指定 `runtimeClassName` 即可。例如:
|
||||
|
||||
```yaml
|
||||
apiVersion: v1
|
||||
@@ -173,44 +176,39 @@ RuntimeClass does not exist, or the CRI cannot run the corresponding handler, th
|
||||
`Failed` terminal [phase](/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase). Look for a
|
||||
corresponding [event](/docs/tasks/debug-application-cluster/debug-application-introspection/) for an
|
||||
error message.
|
||||
-->
|
||||
这一设置会告诉 Kubelet 使用所指的 RuntimeClass 来运行该 pod。
|
||||
如果所指的 RuntimeClass 不存在或者 CRI 无法运行相应的 handler,那么 pod 将会进入 `Failed` 终止[阶段](/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase)。
|
||||
你可以查看相应的[事件](/docs/tasks/debug-application-cluster/debug-application-introspection/),获取出错信息。
|
||||
|
||||
<!--
|
||||
If no `runtimeClassName` is specified, the default RuntimeHandler will be used, which is equivalent
|
||||
to the behavior when the RuntimeClass feature is disabled.
|
||||
-->
|
||||
如果未指定 `runtimeClassName` ,则将使用默认的 RuntimeHandler,相当于禁用 RuntimeClass 功能特性。
|
||||
|
||||
这个设定将让Kubelet使用指定的 RuntimeClass 来运行 Pod。如果 RuntimeClass 不存在, 或者 CRI 不能执行相应的 Handler,Pod 将会变成`Failed`[状态](/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase)。
|
||||
请参考对应的相关[事件](/docs/tasks/debug-application-cluster/debug-application-introspection/)文档,确定错误信息。
|
||||
|
||||
如果 `runtimeClassName` 没有被设定的情况下,将会使用默认的 RuntimeHandler,这里的运行效果和 RuntimeClass 功能被禁止的情况下是一样的。
|
||||
|
||||
<!--
|
||||
### CRI Configuration
|
||||
|
||||
<!--
|
||||
For more details on setting up CRI runtimes, see [CRI installation](/docs/setup/production-environment/container-runtimes/).
|
||||
-->
|
||||
### CRI的设定
|
||||
关于如何安装 CRI 运行时,请查阅[CRI installation](/docs/setup/production-environment/container-runtimes/)。
|
||||
|
||||
CRI 运行时的相关设定详细内容请参考[CRI的安装](/docs/setup/cri/)。
|
||||
|
||||
<!--
|
||||
#### dockershim
|
||||
|
||||
<!--
|
||||
Kubernetes built-in dockershim CRI does not support runtime handlers.
|
||||
-->
|
||||
#### dockershim
|
||||
Kubernetes 内置 dockershim CRI 不支持配置运行时 handler。
|
||||
|
||||
Kubernetes 的内置 dockershim CRI 不支持容器运行时 handlers。
|
||||
|
||||
<!--
|
||||
#### [containerd](https://containerd.io/)
|
||||
|
||||
<!--
|
||||
Runtime handlers are configured through containerd's configuration at
|
||||
`/etc/containerd/config.toml`. Valid handlers are configured under the runtimes section:
|
||||
-->
|
||||
#### [containerd](https://containerd.io/)
|
||||
|
||||
运行时 handler 可以通过 containerd 的配置文件 `/etc/containerd/config.toml` 进行设定。
|
||||
有效的 handlers 被设定在 runtimes 部分的下一层级。
|
||||
通过 containerd 的 `/etc/containerd/config.toml` 配置文件来配置运行时 handler。
|
||||
handler 需要配置在 runtimes 块中:
|
||||
|
||||
```
|
||||
[plugins.cri.containerd.runtimes.${HANDLER_NAME}]
|
||||
@@ -220,7 +218,7 @@ Runtime handlers are configured through containerd's configuration at
|
||||
See containerd's config documentation for more details:
|
||||
https://github.com/containerd/cri/blob/master/docs/config.md
|
||||
-->
|
||||
`containerd` 的具体设定请参考下面的文档信息。
|
||||
更详细信息,请查阅 containerd 配置文档:
|
||||
https://github.com/containerd/cri/blob/master/docs/config.md
|
||||
|
||||
#### [cri-o](https://cri-o.io/)
|
||||
@@ -230,8 +228,9 @@ Runtime handlers are configured through cri-o's configuration at `/etc/crio/crio
|
||||
handlers are configured under the [crio.runtime
|
||||
table](https://github.com/kubernetes-sigs/cri-o/blob/master/docs/crio.conf.5.md#crioruntime-table):
|
||||
-->
|
||||
运行时处理程序通过cri-o的配置在 `/etc/crio/crio.conf` 中进行配置。
|
||||
有效的处理程序在[crio.runtime表](https://github.com/kubernetes-sigs/cri-o/blob/master/docs/crio.conf.5.md#crioruntime-table)下配置。
|
||||
通过 cri-o 的 `/etc/crio/crio.conf` 配置文件来配置运行时 handler。
|
||||
handler 需要配置在[crio.runtime 表](https://github.com/kubernetes-sigs/cri-o/blob/master/docs/crio.conf.5.md#crioruntime-table)
|
||||
下方:
|
||||
|
||||
```
|
||||
[crio.runtime.runtimes.${HANDLER_NAME}]
|
||||
@@ -242,14 +241,10 @@ table](https://github.com/kubernetes-sigs/cri-o/blob/master/docs/crio.conf.5.md#
|
||||
See cri-o's config documentation for more details:
|
||||
https://github.com/kubernetes-sigs/cri-o/blob/master/cmd/crio/config.go
|
||||
-->
|
||||
有关更多详细信息,请参见cri-o的配置文档:
|
||||
更详细信息,请查阅 containerd 配置文档:
|
||||
https://github.com/kubernetes-sigs/cri-o/blob/master/cmd/crio/config.go
|
||||
|
||||
<!--
|
||||
### Scheduling
|
||||
-->
|
||||
|
||||
### 调度
|
||||
|
||||
{{< feature-state for_k8s_version="v1.16" state="beta" >}}
|
||||
|
||||
@@ -258,75 +253,69 @@ As of Kubernetes v1.16, RuntimeClass includes support for heterogenous clusters
|
||||
`scheduling` fields. Through the use of these fields, you can ensure that pods running with this
|
||||
RuntimeClass are scheduled to nodes that support it. To use the scheduling support, you must have
|
||||
the RuntimeClass [admission controller][] enabled (the default, as of 1.16).
|
||||
-->
|
||||
在 Kubernetes v1.16 版本里,RuntimeClass 特性引入了 `scheduling` 字段来支持异构集群。
|
||||
通过该字段,可以确保 pod 被调度到支持指定运行时的节点上。
|
||||
该调度支持,需要确保 RuntimeClass [admission controller][] 处于开启状态(1.16 版本默认开启)。
|
||||
|
||||
<!--
|
||||
To ensure pods land on nodes supporting a specific RuntimeClass, that set of nodes should have a
|
||||
common label which is then selected by the `runtimeclass.scheduling.nodeSelector` field. The
|
||||
RuntimeClass's nodeSelector is merged with the pod's nodeSelector in admission, effectively taking
|
||||
the intersection of the set of nodes selected by each. If there is a conflict, the pod will be
|
||||
rejected.
|
||||
-->
|
||||
|
||||
从Kubernetes v1.16开始,RuntimeClass 通过 `scheduling` 字段添加了对异构集群的支持。
|
||||
通过使用这些字段,可以确保将与此 RuntimeClass一 起运行的 Pod 调度到支持它的节点上。
|
||||
要使用计划支持,您必须启用 RuntimeClass [admission controller] [](默认值,自1.16开始)。
|
||||
|
||||
为了确保 Pod 被调度到支持特定 RuntimeClass 的节点上,
|
||||
那组节点应该具有一个公共标签,然后由 `runtimeclass.scheduling.nodeSelector` 字段选择该标签。
|
||||
RuntimeClass 的 nodeSelector 在调度时与 Pod 的 nodeSelector 合并,有效地进行节点选择,并且调度到相应节点。
|
||||
如果有冲突,则将拒绝该 Pod 被调度。
|
||||
为了确保 pod 会被调度到支持指定运行时的 node 上,每个 node 需要设置一个通用的 label 用于被
|
||||
`runtimeclass.scheduling.nodeSelector` 挑选。在 admission 阶段,RuntimeClass 的 nodeSelector 将会于
|
||||
pod 的 nodeSelector 合并,取二者的交集。如果有冲突,pod 将会被拒绝。
|
||||
|
||||
<!--
|
||||
|
||||
If the supported nodes are tainted to prevent other RuntimeClass pods from running on the node, you
|
||||
can add `tolerations` to the RuntimeClass. As with the `nodeSelector`, the tolerations are merged
|
||||
with the pod's tolerations in admission, effectively taking the union of the set of nodes tolerated
|
||||
by each.
|
||||
|
||||
To learn more about configuring the node selector and tolerations, see [Assigning Pods to
|
||||
Nodes](/docs/concepts/configuration/assign-pod-node/).
|
||||
|
||||
[admission controller]: /docs/reference/access-authn-authz/admission-controllers/
|
||||
-->
|
||||
|
||||
如果受支持的节点被污染以防止其他 RuntimeClass 容器在该节点上运行,则可以向RuntimeClass添加 `tolerations` 设定。
|
||||
与 `nodeSelector` 一样,容忍度在接纳时与容器的容忍度合并,从而有效地吸收了每个容忍度的节点集的并集。
|
||||
|
||||
要了解有关配置节点选择器和容差的更多信息,请参阅[分配 Pod 到节点](/docs/concepts/configuration/assign-pod-node/)。
|
||||
|
||||
[准入控制器]: /docs/reference/access-authn-authz/admission-controllers/
|
||||
如果 node 需要阻止某些需要特定 RuntimeClass 的 pod,可以在 `tolerations` 中指定。
|
||||
与 `nodeSelector` 一样,tolerations 也在 admission 阶段与 pod 的 tolerations 合并,取二者的并集。
|
||||
|
||||
<!--
|
||||
### Pod Overhead
|
||||
To learn more about configuring the node selector and tolerations, see [Assigning Pods to
|
||||
Nodes](/docs/concepts/configuration/assign-pod-node/).
|
||||
-->
|
||||
更多有关 node selector 和 tolerations 的配置信息,请查阅
|
||||
[Assigning Pods to Nodes](/docs/concepts/configuration/assign-pod-node/)。
|
||||
|
||||
### Pod 开销
|
||||
[admission controller]: /docs/reference/access-authn-authz/admission-controllers/
|
||||
|
||||
### Pod Overhead
|
||||
|
||||
{{< feature-state for_k8s_version="v1.16" state="alpha" >}}
|
||||
|
||||
<!--
|
||||
As of Kubernetes v1.16, RuntimeClass includes support for specifying overhead associated with
|
||||
running a pod, as part of the [`PodOverhead`](/docs/concepts/configuration/pod-overhead.md) feature.
|
||||
running a pod, as part of the [`PodOverhead`](/docs/concepts/configuration/pod-overhead) feature.
|
||||
To use `PodOverhead`, you must have the PodOverhead [feature gate](/docs/reference/command-line-tools-reference/feature-gates/)
|
||||
enabled (it is off by default).
|
||||
-->
|
||||
在 Kubernetes v1.16 版本中,RuntimeClass 开始支持 pod 的 overhead,作为 [`PodOverhead`](/docs/concepts/configuration/pod-overhead)
|
||||
特性的一部分。
|
||||
若要使用 `PodOverhead` 特性,你需要确保 PodOverhead 特性开关处于开启状态(默认为关闭状态)。
|
||||
|
||||
|
||||
<!--
|
||||
Pod overhead is defined in RuntimeClass through the `Overhead` fields. Through the use of these fields,
|
||||
you can specify the overhead of running pods utilizing this RuntimeClass and ensure these overheads
|
||||
are accounted for in Kubernetes.
|
||||
-->
|
||||
Pod 的 overhead 在 RuntimeClass 的 `Overhead` 字段定义,该字段用于指定使用 RuntimeClass 特性时带来的 overhead。
|
||||
|
||||
从 Kubernetes v1.16 开始,RuntimeClass 包含了对指定与运行 Pod 相关的开销的支持,
|
||||
这是[`Pod 开销`](/docs/concepts/configuration/pod-overhead.md)功能的一部分。
|
||||
要使用 `PodOverhead` ,您必须确保 PodOverhead [功能](/docs/reference/command-line-tools-reference/feature-gates/) 已启用(默认情况下处于关闭状态)。
|
||||
|
||||
Pod 的开销是在 RuntimeClass 中通过 `Overhead` 字段定义的。 通过使用这些字段,
|
||||
您可以使用此 RuntimeClass 指定运行 Pod 的开销,并确保在Kubernetes中考虑了这些开销。
|
||||
|
||||
<!--
|
||||
### Upgrading RuntimeClass from Alpha to Beta
|
||||
|
||||
<!--
|
||||
The RuntimeClass Beta feature includes the following changes:
|
||||
-->
|
||||
RuntimeClass Beta 特性包含如下几个改变:
|
||||
|
||||
<!--
|
||||
- The `node.k8s.io` API group and `runtimeclasses.node.k8s.io` resource have been migrated to a
|
||||
built-in API from a CustomResourceDefinition.
|
||||
- The `spec` has been inlined in the RuntimeClass definition (i.e. there is no more
|
||||
@@ -338,22 +327,20 @@ The RuntimeClass Beta feature includes the following changes:
|
||||
meaning it can no longer contain `.` characters (in all versions). Valid handlers match the
|
||||
following regular expression: `^[a-z0-9]([-a-z0-9]*[a-z0-9])?$`.
|
||||
-->
|
||||
|
||||
### 将 RuntimeClass 从 Alpha 升级到 Beta
|
||||
|
||||
RuntimeClass Beta 功能包括以下更改:
|
||||
|
||||
- `node.k8s.io` API 组和 `runtimeclasses.node.k8s.io` 资源已从 `CustomResourceDefinition` 迁移到内置API。
|
||||
- 已在 RuntimeClass 定义中内联了 `spec`(即不再有RuntimeClassSpec)。
|
||||
- `runtimeHandler` 字段已重命名为 `handler`。
|
||||
- 所有 API 版本中现在都需要 `handler` 字段。 这意味着 Alpha API 中的 `runtimeHandler` 字段也是必须设定项。
|
||||
- `handler`字段必须是有效的DNS标签([RFC 1123](https://tools.ietf.org/html/rfc1123)),这意味着它不再包含 `.` 字符(在所有版本中)。
|
||||
有效的处理程序匹配以下正则表达式:`^ [a-z0-9]([-a-z0-9] * [a-z0-9])?$`。
|
||||
- `node.k8s.io` API 组和 `runtimeclasses.node.k8s.io` 资源已从 CRD 中迁移到内置的 API 中;
|
||||
- `spec` 被放置到 RuntimeClass 中(例如,没有 RuntimeClassSpec 了);
|
||||
- `runtimeHandler` 字段重命名为 `handler`;
|
||||
- `handler` 字段需要在所有版本的 API 提供,这意味着 `runtimeHandler` 字段在 Alpha API 中也需要提供;
|
||||
- `handler` 字段必须是一个合法的 DNS 标识([RFC 1123](https://tools.ietf.org/html/rfc1123)),
|
||||
这意味着不可以包含 `.` 字符。合法的 handler 必须满足如下规则:`^[a-z0-9]([-a-z0-9]*[a-z0-9])?$`。
|
||||
|
||||
<!--
|
||||
**Action Required:** The following actions are required to upgrade from the alpha version of the
|
||||
RuntimeClass feature to the beta version:
|
||||
-->
|
||||
**Action Required:** RuntimeClass 特性从 alpha 版本升级到 beta 版本,需要做如下动作:
|
||||
|
||||
<!--
|
||||
- RuntimeClass resources must be recreated *after* upgrading to v1.14, and the
|
||||
`runtimeclasses.node.k8s.io` CRD should be manually deleted:
|
||||
```
|
||||
@@ -363,30 +350,18 @@ RuntimeClass feature to the beta version:
|
||||
in the handler are no longer valid, and must be migrated to a valid handler configuration (see
|
||||
above).
|
||||
-->
|
||||
|
||||
**需要采取的措施:** 要从 RuntimeClass 功能的 Alpha 版本升级到 Beta 版本,需要执行以下操作:
|
||||
|
||||
- 在升级到v1.14之后,必须重新创建 RuntimeClass 资源,并且应该手动删除 runtimeclasses.node.k8s.io 的 CRD:
|
||||
- RuntimeClass 资源必须在升级到 v1.14 *之后* 再创建,并且 CRD 资源 `runtimeclasses.node.k8s.io` 必须要手动删除:
|
||||
```
|
||||
kubectl delete customresourcedefinitions.apiextensions.k8s.io runtimeclasses.node.k8s.io
|
||||
```
|
||||
- 在处理程序中具有未指定或为空的 `runtimeHandler` 字段或使用 `.` 字符的 Alpha RuntimeClass 不再有效,
|
||||
必须将其迁移到有效的处理程序配置中(请参见上文)。
|
||||
|
||||
<!--
|
||||
- RuntimeClasses 中未指定或为空的 `runtimeHandler` 和 使用包含 `.` 符号的 handler 将不再合法,
|
||||
必须迁移成合法的 handler 配置(见上)。
|
||||
|
||||
### Further Reading
|
||||
|
||||
- [RuntimeClass Design](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/runtime-class.md)
|
||||
- [RuntimeClass Scheduling Design](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/runtime-class-scheduling.md)
|
||||
- Read about the [Pod Overhead](/docs/concepts/configuration/pod-overhead/) concept
|
||||
- [PodOverhead Feature Design](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/20190226-pod-overhead.md)
|
||||
-->
|
||||
|
||||
### 进一步阅读
|
||||
|
||||
- [运行时类设计](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/runtime-class.md)
|
||||
- [RuntimeClass 计划设计](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/runtime-class-scheduling.md)
|
||||
- 了解有关 [Pod 开销](/docs/concepts/configuration/pod-overhead/) 概念
|
||||
- [Pod 开销功能设计](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/20190226-pod-overhead.md)
|
||||
|
||||
{{% /capture %}}
|
||||
|
||||
Reference in New Issue
Block a user