Taint based eviction promoted to GA in 1.18 (#19302)

This commit is contained in:
Jan Chaloupka
2020-03-12 20:40:39 +01:00
committed by GitHub
parent 5372544d6f
commit 10bd7356a7
2 changed files with 12 additions and 11 deletions
@@ -197,11 +197,13 @@ on the special hardware nodes. This will make sure that these special hardware
nodes are dedicated for pods requesting such hardware and you don't have to nodes are dedicated for pods requesting such hardware and you don't have to
manually add tolerations to your pods. manually add tolerations to your pods.
* **Taint based Evictions (beta feature)**: A per-pod-configurable eviction behavior * **Taint based Evictions**: A per-pod-configurable eviction behavior
when there are node problems, which is described in the next section. when there are node problems, which is described in the next section.
## Taint based Evictions ## Taint based Evictions
{{< feature-state for_k8s_version="1.18" state="stable" >}}
Earlier we mentioned the `NoExecute` taint effect, which affects pods that are already Earlier we mentioned the `NoExecute` taint effect, which affects pods that are already
running on the node as follows running on the node as follows
@@ -229,9 +231,9 @@ certain condition is true. The following taints are built in:
as unusable. After a controller from the cloud-controller-manager initializes as unusable. After a controller from the cloud-controller-manager initializes
this node, the kubelet removes this taint. this node, the kubelet removes this taint.
In version 1.13, the `TaintBasedEvictions` feature is promoted to beta and enabled by default, hence the taints are automatically In case a node is to be evicted, the node controller or the kubelet adds relevant taints
added by the NodeController (or kubelet) and the normal logic for evicting pods from nodes with `NoExecute` effect. If the fault condition returns to normal the kubelet or node
based on the Ready NodeCondition is disabled. controller can remove the relevant taint(s).
{{< note >}} {{< note >}}
To maintain the existing [rate limiting](/docs/concepts/architecture/nodes/) To maintain the existing [rate limiting](/docs/concepts/architecture/nodes/)
@@ -240,7 +242,7 @@ in a rate-limited way. This prevents massive pod evictions in scenarios such
as the master becoming partitioned from the nodes. as the master becoming partitioned from the nodes.
{{< /note >}} {{< /note >}}
This beta feature, in combination with `tolerationSeconds`, allows a pod The feature, in combination with `tolerationSeconds`, allows a pod
to specify how long it should stay bound to a node that has one or both of these problems. to specify how long it should stay bound to a node that has one or both of these problems.
For example, an application with a lot of local state might want to stay For example, an application with a lot of local state might want to stay
@@ -277,15 +279,13 @@ admission controller](https://git.k8s.io/kubernetes/plugin/pkg/admission/default
* `node.kubernetes.io/unreachable` * `node.kubernetes.io/unreachable`
* `node.kubernetes.io/not-ready` * `node.kubernetes.io/not-ready`
This ensures that DaemonSet pods are never evicted due to these problems, This ensures that DaemonSet pods are never evicted due to these problems.
which matches the behavior when this feature is disabled.
## Taint Nodes by Condition ## Taint Nodes by Condition
The node lifecycle controller automatically creates taints corresponding to The node lifecycle controller automatically creates taints corresponding to
Node conditions. Node conditions with `NoSchedule` effect.
Similarly the scheduler does not check Node conditions; instead the scheduler checks taints. This assures that Node conditions don't affect what's scheduled onto the Node. The user can choose to ignore some of the Node's problems (represented as Node conditions) by adding appropriate Pod tolerations. Similarly the scheduler does not check Node conditions; instead the scheduler checks taints. This assures that Node conditions don't affect what's scheduled onto the Node. The user can choose to ignore some of the Node's problems (represented as Node conditions) by adding appropriate Pod tolerations.
Note that `TaintNodesByCondition` only taints nodes with `NoSchedule` effect. `NoExecute` effect is controlled by `TaintBasedEviction` which is a beta feature and enabled by default since version 1.13.
Starting in Kubernetes 1.8, the DaemonSet controller automatically adds the Starting in Kubernetes 1.8, the DaemonSet controller automatically adds the
following `NoSchedule` tolerations to all daemons, to prevent DaemonSets from following `NoSchedule` tolerations to all daemons, to prevent DaemonSets from
@@ -139,8 +139,6 @@ different Kubernetes components.
| `SupportPodPidsLimit` | `false` | Alpha | 1.10 | 1.13 | | `SupportPodPidsLimit` | `false` | Alpha | 1.10 | 1.13 |
| `SupportPodPidsLimit` | `true` | Beta | 1.14 | | | `SupportPodPidsLimit` | `true` | Beta | 1.14 | |
| `Sysctls` | `true` | Beta | 1.11 | | | `Sysctls` | `true` | Beta | 1.11 | |
| `TaintBasedEvictions` | `false` | Alpha | 1.6 | 1.12 |
| `TaintBasedEvictions` | `true` | Beta | 1.13 | |
| `TokenRequest` | `false` | Alpha | 1.10 | 1.11 | | `TokenRequest` | `false` | Alpha | 1.10 | 1.11 |
| `TokenRequest` | `true` | Beta | 1.12 | | | `TokenRequest` | `true` | Beta | 1.12 | |
| `TokenRequestProjection` | `false` | Alpha | 1.11 | 1.11 | | `TokenRequestProjection` | `false` | Alpha | 1.11 | 1.11 |
@@ -254,6 +252,9 @@ different Kubernetes components.
| `SupportIPVSProxyMode` | `false` | Beta | 1.9 | 1.9 | | `SupportIPVSProxyMode` | `false` | Beta | 1.9 | 1.9 |
| `SupportIPVSProxyMode` | `true` | Beta | 1.10 | 1.10 | | `SupportIPVSProxyMode` | `true` | Beta | 1.10 | 1.10 |
| `SupportIPVSProxyMode` | `true` | GA | 1.11 | - | | `SupportIPVSProxyMode` | `true` | GA | 1.11 | - |
| `TaintBasedEvictions` | `false` | Alpha | 1.6 | 1.12 |
| `TaintBasedEvictions` | `true` | Beta | 1.13 | 1.17 |
| `TaintBasedEvictions` | `true` | GA | 1.18 | - |
| `TaintNodesByCondition` | `false` | Alpha | 1.8 | 1.11 | | `TaintNodesByCondition` | `false` | Alpha | 1.8 | 1.11 |
| `TaintNodesByCondition` | `true` | Beta | 1.12 | 1.16 | | `TaintNodesByCondition` | `true` | Beta | 1.12 | 1.16 |
| `TaintNodesByCondition` | `true` | GA | 1.17 | - | | `TaintNodesByCondition` | `true` | GA | 1.17 | - |