From 10bd7356a76e82606d68212479608c8365b67226 Mon Sep 17 00:00:00 2001 From: Jan Chaloupka Date: Thu, 12 Mar 2020 20:40:39 +0100 Subject: [PATCH] Taint based eviction promoted to GA in 1.18 (#19302) --- .../configuration/taint-and-toleration.md | 18 +++++++++--------- .../feature-gates.md | 5 +++-- 2 files changed, 12 insertions(+), 11 deletions(-) diff --git a/content/en/docs/concepts/configuration/taint-and-toleration.md b/content/en/docs/concepts/configuration/taint-and-toleration.md index eac6267e79..2026390eff 100644 --- a/content/en/docs/concepts/configuration/taint-and-toleration.md +++ b/content/en/docs/concepts/configuration/taint-and-toleration.md @@ -197,11 +197,13 @@ on the special hardware nodes. This will make sure that these special hardware nodes are dedicated for pods requesting such hardware and you don't have to manually add tolerations to your pods. -* **Taint based Evictions (beta feature)**: A per-pod-configurable eviction behavior +* **Taint based Evictions**: A per-pod-configurable eviction behavior when there are node problems, which is described in the next section. ## Taint based Evictions +{{< feature-state for_k8s_version="1.18" state="stable" >}} + Earlier we mentioned the `NoExecute` taint effect, which affects pods that are already running on the node as follows @@ -229,9 +231,9 @@ certain condition is true. The following taints are built in: as unusable. After a controller from the cloud-controller-manager initializes this node, the kubelet removes this taint. -In version 1.13, the `TaintBasedEvictions` feature is promoted to beta and enabled by default, hence the taints are automatically -added by the NodeController (or kubelet) and the normal logic for evicting pods from nodes -based on the Ready NodeCondition is disabled. +In case a node is to be evicted, the node controller or the kubelet adds relevant taints +with `NoExecute` effect. If the fault condition returns to normal the kubelet or node +controller can remove the relevant taint(s). {{< note >}} To maintain the existing [rate limiting](/docs/concepts/architecture/nodes/) @@ -240,7 +242,7 @@ in a rate-limited way. This prevents massive pod evictions in scenarios such as the master becoming partitioned from the nodes. {{< /note >}} -This beta feature, in combination with `tolerationSeconds`, allows a pod +The feature, in combination with `tolerationSeconds`, allows a pod to specify how long it should stay bound to a node that has one or both of these problems. For example, an application with a lot of local state might want to stay @@ -277,15 +279,13 @@ admission controller](https://git.k8s.io/kubernetes/plugin/pkg/admission/default * `node.kubernetes.io/unreachable` * `node.kubernetes.io/not-ready` -This ensures that DaemonSet pods are never evicted due to these problems, -which matches the behavior when this feature is disabled. +This ensures that DaemonSet pods are never evicted due to these problems. ## Taint Nodes by Condition The node lifecycle controller automatically creates taints corresponding to -Node conditions. +Node conditions with `NoSchedule` effect. Similarly the scheduler does not check Node conditions; instead the scheduler checks taints. This assures that Node conditions don't affect what's scheduled onto the Node. The user can choose to ignore some of the Node's problems (represented as Node conditions) by adding appropriate Pod tolerations. -Note that `TaintNodesByCondition` only taints nodes with `NoSchedule` effect. `NoExecute` effect is controlled by `TaintBasedEviction` which is a beta feature and enabled by default since version 1.13. Starting in Kubernetes 1.8, the DaemonSet controller automatically adds the following `NoSchedule` tolerations to all daemons, to prevent DaemonSets from diff --git a/content/en/docs/reference/command-line-tools-reference/feature-gates.md b/content/en/docs/reference/command-line-tools-reference/feature-gates.md index 2dc2a84b57..da3b73c143 100644 --- a/content/en/docs/reference/command-line-tools-reference/feature-gates.md +++ b/content/en/docs/reference/command-line-tools-reference/feature-gates.md @@ -139,8 +139,6 @@ different Kubernetes components. | `SupportPodPidsLimit` | `false` | Alpha | 1.10 | 1.13 | | `SupportPodPidsLimit` | `true` | Beta | 1.14 | | | `Sysctls` | `true` | Beta | 1.11 | | -| `TaintBasedEvictions` | `false` | Alpha | 1.6 | 1.12 | -| `TaintBasedEvictions` | `true` | Beta | 1.13 | | | `TokenRequest` | `false` | Alpha | 1.10 | 1.11 | | `TokenRequest` | `true` | Beta | 1.12 | | | `TokenRequestProjection` | `false` | Alpha | 1.11 | 1.11 | @@ -254,6 +252,9 @@ different Kubernetes components. | `SupportIPVSProxyMode` | `false` | Beta | 1.9 | 1.9 | | `SupportIPVSProxyMode` | `true` | Beta | 1.10 | 1.10 | | `SupportIPVSProxyMode` | `true` | GA | 1.11 | - | +| `TaintBasedEvictions` | `false` | Alpha | 1.6 | 1.12 | +| `TaintBasedEvictions` | `true` | Beta | 1.13 | 1.17 | +| `TaintBasedEvictions` | `true` | GA | 1.18 | - | | `TaintNodesByCondition` | `false` | Alpha | 1.8 | 1.11 | | `TaintNodesByCondition` | `true` | Beta | 1.12 | 1.16 | | `TaintNodesByCondition` | `true` | GA | 1.17 | - |