Document changing the sandbox image in CR (#33660)

* Document changing the sandbox image in CR

* Update cri-dockerd section to be idiomatic
This commit is contained in:
Dom Goodwin
2022-06-17 05:52:33 +01:00
committed by GitHub
parent adced437e8
commit 1145cab87b
2 changed files with 46 additions and 0 deletions
@@ -242,6 +242,15 @@ where `config.yaml` contains the custom `imageRepository`, and/or `imageTag`
for etcd and CoreDNS.
* Pass the same `config.yaml` to `kubeadm init`.
#### Custom sandbox (pause) images {#custom-pause-image}
To set a custom image for these you need to configure this in your
{{< glossary_tooltip text="container runtime" term_id="container-runtime" >}}
to use the image.
Consult the documentation for your container runtime to find out how to change this setting;
for selected container runtimes, you can also find advice within the
[Container Runtimes]((/docs/setup/production-environment/container-runtimes/) topic.
### Uploading control-plane certificates to the cluster
By adding the flag `--upload-certs` to `kubeadm init` you can temporary upload
@@ -215,6 +215,18 @@ sudo systemctl restart containerd
When using kubeadm, manually configure the
[cgroup driver for kubelet](/docs/tasks/administer-cluster/kubeadm/configure-cgroup-driver/#configuring-the-kubelet-cgroup-driver).
#### Overriding the sandbox (pause) image {#override-pause-image-containerd}
In your [containerd config](https://github.com/containerd/cri/blob/master/docs/config.md) you can overwrite the
sandbox image by setting the following config:
```toml
[plugins."io.containerd.grpc.v1.cri"]
sandbox_image = "k8s.gcr.io/pause:3.2"
```
You might need to restart `containerd` as well once you've updated the config file: `systemctl restart containerd`.
### CRI-O
This section contains the necessary steps to install CRI-O as a container runtime.
@@ -241,6 +253,19 @@ in sync.
For CRI-O, the CRI socket is `/var/run/crio/crio.sock` by default.
#### Overriding the sandbox (pause) image {#override-pause-image-cri-o}
In your [CRI-O config](https://github.com/cri-o/cri-o/blob/main/docs/crio.conf.5.md) you can set the following
config value:
```toml
[crio.image]
pause_image="registry.k8s.io/pause:3.6"
```
This config option supports live configuration reload to apply this change: `systemctl reload crio` or by sending
`SIGHUP` to the `crio` process.
### Docker Engine {#docker}
{{< note >}}
@@ -257,6 +282,12 @@ Docker Engine with Kubernetes.
For `cri-dockerd`, the CRI socket is `/run/cri-dockerd.sock` by default.
#### Overriding the sandbox (pause) image {#override-pause-image-cri-dockerd}
The `cri-dockerd` adapter accepts a command line argument for
specifying which container image to use as the Pod infrastructure container (“pause image”).
The command line argument to use is `--pod-infra-container-image`.
### Mirantis Container Runtime {#mcr}
[Mirantis Container Runtime](https://docs.mirantis.com/mcr/20.10/overview.html) (MCR) is a commercially
@@ -271,6 +302,12 @@ visit [MCR Deployment Guide](https://docs.mirantis.com/mcr/20.10/install.html).
Check the systemd unit named `cri-docker.socket` to find out the path to the CRI
socket.
#### Overriding the sandbox (pause) image {#override-pause-image-cri-dockerd-mcr}
The `cri-dockerd` adapter accepts a command line argument for
specifying which container image to use as the Pod infrastructure container (“pause image”).
The command line argument to use is `--pod-infra-container-image`.
## {{% heading "whatsnext" %}}
As well as a container runtime, your cluster will need a working