diff --git a/_data/guides.yml b/_data/guides.yml
index 40d47b08d6..e31411ea48 100644
--- a/_data/guides.yml
+++ b/_data/guides.yml
@@ -10,6 +10,8 @@ toc:
path: /docs/whatisk8s/
- title: Installing Kubernetes on Linux with kubeadm
path: /docs/getting-started-guides/kubeadm/
+ - title: Installing Kubernetes on AWS with kops
+ path: /docs/getting-started-guides/kops/
- title: Hello World on Google Container Engine
path: /docs/hellonode/
- title: Downloading or Building Kubernetes
@@ -68,6 +70,8 @@ toc:
path: /docs/getting-started-guides/network-policy/walkthrough/
- title: Using Calico for NetworkPolicy
path: /docs/getting-started-guides/network-policy/calico/
+ - title: Using Romana for NetworkPolicy
+ path: /docs/getting-started-guides/network-policy/romana/
- title: Batch Jobs
section:
diff --git a/_data/tasks.yml b/_data/tasks.yml
index 86209a52aa..90c1f3b8b2 100644
--- a/_data/tasks.yml
+++ b/_data/tasks.yml
@@ -2,6 +2,12 @@ bigheader: "Tasks"
toc:
- title: Tasks
path: /docs/tasks/
+- title: Configuring Pods and Containers
+ section:
+ - title: Defining Environment Variables for a Container
+ path: /docs/tasks/configure-pod-container/define-environment-variable-container/
+ - title: Defining a Command and Arguments for a Container
+ path: /docs/tasks/configure-pod-container/define-command-argument-container/
- title: Accessing Applications in a Cluster
section:
- title: Using Port Forwarding to Access Applications in a Cluster
diff --git a/_includes/footer.html b/_includes/footer.html
index f98dde06b5..15dacb72e0 100644
--- a/_includes/footer.html
+++ b/_includes/footer.html
@@ -4,6 +4,7 @@
Get Started
Documentation
Blog
+ Partners
Community
Case Studies
diff --git a/_includes/partner-script.js b/_includes/partner-script.js
new file mode 100644
index 0000000000..00dc9f1ee1
--- /dev/null
+++ b/_includes/partner-script.js
@@ -0,0 +1,229 @@
+;(function () {
+ var partners = [
+ {
+ type: 0,
+ name: 'CoreOS',
+ logo: 'core_os',
+ link: 'https://tectonic.com/',
+ blurb: 'Tectonic is the enterprise-ready Kubernetes product, by CoreOS. It adds key features to allow you to manage, update, and control clusters in production.'
+ },
+ {
+ type: 0,
+ name: 'Deis',
+ logo: 'deis',
+ link: 'https://deis.com',
+ blurb: 'Deis the creators of Helm, Workflow, and Steward, helps developers and operators build, deploy, manage and scale their applications on top of Kubernetes.'
+ },
+ {
+ type: 0,
+ name: 'Sysdig Cloud',
+ logo: 'sys_dig',
+ link: 'https://sysdig.com/blog/monitoring-kubernetes-with-sysdig-cloud/',
+ blurb: 'Container native monitoring with deep support for Kubernetes.'
+ },
+ {
+ type: 0,
+ name: 'Puppet',
+ logo: 'puppet',
+ link: 'https://puppet.com/blog/managing-kubernetes-configuration-puppet',
+ blurb: 'The Puppet module for Kubernetes makes it easy to manage Pods, Replication Controllers, Services and more in Kubernetes, and to build domain-specific interfaces to one\'s Kubernetes configuration.'
+ },
+ {
+ type: 0,
+ name: 'Citrix',
+ logo: 'citrix',
+ link: 'http://wercker.com/workflows/partners/kubernetes/',
+ blurb: 'Netscaler CPX gives app developers all the features they need to load balance their microservices and containerized apps with Kubernetes.'
+ },
+ {
+ type: 0,
+ name: 'Wercker',
+ logo: 'wercker',
+ link: 'http://wercker.com/workflows/partners/kubernetes/',
+ blurb: 'Wercker automates your build, test and deploy pipelines for launching containers and triggering rolling updates on your Kubernetes cluster. '
+ },
+ {
+ type: 0,
+ name: 'Rancher',
+ logo: 'rancher',
+ link: 'http://rancher.com/kubernetes/',
+ blurb: 'Rancher is an open-source, production-ready container management platform that makes it easy to deploy and leverage Kubernetes in the enterprise.'
+ },
+ {
+ type: 0,
+ name: 'Red Hat',
+ logo: 'redhat',
+ link: 'https://www.openshift.com/',
+ blurb: 'Leverage an enterprise Kubernetes platform to orchestrate complex, multi-container apps.'
+ },
+ {
+ type: 0,
+ name: 'Intel',
+ logo: 'intel',
+ link: 'https://tectonic.com/press/intel-coreos-collaborate-on-openstack-with-kubernetes.html',
+ blurb: 'Powering the GIFEE (Google’s Infrastructure for Everyone Else), to run OpenStack deployments on Kubernetes.'
+ },
+ {
+ type: 0,
+ name: 'ElasticKube',
+ logo: 'elastickube',
+ link: 'https://www.ctl.io/elastickube-kubernetes/',
+ blurb: 'Self-service container management for Kubernetes.'
+ },
+ {
+ type: 0,
+ name: 'Platform9',
+ logo: 'platform9',
+ link: 'https://platform9.com/products/kubernetes/',
+ blurb: 'Platform9 is the open source-as-a-service company that takes all of the goodness of Kubernetes and delivers it as a managed service.'
+ },
+ {
+ type: 0,
+ name: 'Datadog',
+ logo: 'datadog',
+ link: 'http://docs.datadoghq.com/integrations/kubernetes/',
+ blurb: 'Full-stack observability for dynamic infrastructure & applications. Includes precision alerting, analytics and deep Kubernetes integrations. '
+ },
+ {
+ type: 0,
+ name: 'AppFormix',
+ logo: 'appformix',
+ link: 'http://www.appformix.com/solutions/appformix-for-kubernetes/',
+ blurb: 'AppFormix is a cloud infrastructure performance optimization service helping enterprise operators streamline their cloud operations on any Kubernetes cloud. '
+ },
+ {
+ type: 0,
+ name: 'Crunchy',
+ logo: 'crunchy',
+ link: 'http://info.crunchydata.com/blog/advanced-crunchy-containers-for-postgresql',
+ blurb: 'Crunchy PostgreSQL Container Suite is a set of containers for managing PostgreSQL with DBA microservices leveraging Kubernetes and Helm.'
+ },
+ {
+ type: 0,
+ name: 'Aqua',
+ logo: 'aqua',
+ link: 'http://blog.aquasec.com/security-best-practices-for-kubernetes-deployment',
+ blurb: 'Deep, automated security for your containers running on Kubernetes.'
+ },
+ {
+ type: 0,
+ name: 'Canonical',
+ logo: 'canonical',
+ link: 'https://jujucharms.com/canonical-kubernetes/',
+ blurb: 'The Canonical Distribution of Kubernetes enables you to operate Kubernetes clusters on demand on any major public cloud and private infrastructure.'
+ },
+ {
+ type: 0,
+ name: 'Distelli',
+ logo: 'distelli',
+ link: 'https://www.distelli.com/',
+ blurb: 'Pipelines from your source repositories to your Kubernetes Clusters on any cloud.'
+ },
+ {
+ type: 0,
+ name: 'Nuage networks',
+ logo: 'nuagenetworks',
+ link: 'https://github.com/nuagenetworks/nuage-kubernetes',
+ blurb: 'The Nuage SDN platform provides policy-based networking between Kubernetes Pods and non-Kubernetes environments with visibility and security monitoring.'
+ },
+ {
+ type: 0,
+ name: 'Sematext',
+ logo: 'sematext',
+ link: 'https://sematext.com/kubernetes/',
+ blurb: 'Logging & Monitoring: Automatic collection and processing of Metrics, Events and Logs for auto-discovered pods and Kubernetes nodes.'
+ },
+ {
+ type: 0,
+ name: 'Diamanti',
+ logo: 'diamanti',
+ link: 'https://www.diamanti.com/products/',
+ blurb: 'Diamanti deploys containers with guaranteed performance using Kubernetes in the first hyperconverged appliance purpose built for containerized applications.'
+ },
+ {
+ type: 1,
+ name: 'Apprenda',
+ logo: 'apprenda',
+ link: 'https://apprenda.com/kubernetes-support/',
+ blurb: 'Apprenda offers flexible and wide range of support plans for pure play Kubernetes on your choice of infrastructure, cloud provider and operating system.'
+ },
+ {
+ type: 1,
+ name: 'Reactive Ops',
+ logo: 'reactive_ops',
+ link: 'https://www.reactiveops.com/kubernetes/',
+ blurb: 'ReactiveOps has written automation on best practices for infrastructure as code on GCP & AWS using Kubernetes, helping you build and maintain a world-class infrastructure at a fraction of the price of an internal hire.'
+ },
+ {
+ type: 1,
+ name: 'Livewyer',
+ logo: 'livewyer',
+ link: 'https://livewyer.io/services/kubernetes-experts/',
+ blurb: 'Kubernetes experts that on-board applications and empower IT teams to get the most out of containerised technology.'
+ },
+ {
+ type: 1,
+ name: 'Deis',
+ logo: 'deis',
+ link: 'https://deis.com/services/',
+ blurb: 'Deis provides professional services and 24x7 operational support for any Kubernetes cluster managed by our global cluster operations team.'
+ },
+ {
+ type: 1,
+ name: 'Samsung SDS',
+ logo: 'samsung_sds',
+ link: 'http://www.samsungsdsa.com/cloud-infrastructure_kubernetes',
+ blurb: 'Samsung SDS’s Cloud Native Computing Team offers expert consulting across the range of technical aspects involved in building services targeted at a Kubernetes cluster.'
+ },
+ {
+ type: 1,
+ name: 'Container Solutions',
+ logo: 'container_solutions',
+ link: 'http://container-solutions.com/resources/kubernetes/',
+ blurb: 'Container Solutions is a premium software consultancy that focuses on programmable infrastructure, offering our expertise in software development, strategy and operations to help you innovate at speed and scale.'
+ },
+ {
+ type: 1,
+ name: 'Jetstack',
+ logo: 'jetstack',
+ link: 'https://www.jetstack.io/',
+ blurb: 'Jetstack is an organisation focused entirely on Kubernetes. They will help you to get the most out of Kubernetes through expert professional services and open source tooling. Get in touch, and accelerate your project.'
+ }
+ ]
+
+ var isvContainer = document.getElementById('isvContainer')
+ var servContainer = document.getElementById('servContainer')
+
+ var sorted = partners.sort(function (a, b) {
+ if (a.name > b.name) return 1
+ if (a.name < b.name) return -1
+ return 0
+ })
+
+ sorted.forEach(function (obj) {
+ var box = document.createElement('div')
+ box.className = 'partner-box'
+
+ var img = document.createElement('img')
+ img.src = '/images/square-logos/' + obj.logo + '.png'
+
+ var div = document.createElement('div')
+
+ var p = document.createElement('p')
+ p.textContent = obj.blurb
+
+ var link = document.createElement('a')
+ link.href = obj.link
+ link.target = '_blank'
+ link.textContent = 'Learn more'
+
+ div.appendChild(p)
+ div.appendChild(link)
+
+ box.appendChild(img)
+ box.appendChild(div)
+
+ var container = obj.type ? servContainer : isvContainer
+ container.appendChild(box)
+ })
+})();
diff --git a/_includes/partner-style.css b/_includes/partner-style.css
new file mode 100644
index 0000000000..a8cc125992
--- /dev/null
+++ b/_includes/partner-style.css
@@ -0,0 +1,94 @@
+h5 {
+ font-size: 18px;
+ line-height: 1.5em;
+ margin-bottom: 2em;
+}
+
+#usersGrid a {
+ display: inline-block;
+ background-color: #f9f9f9;
+}
+
+#isvContainer, #servContainer {
+ position: relative;
+ width: 100%;
+ display: flex;
+ justify-content: space-between;
+ flex-wrap: wrap;
+}
+
+#isvContainer {
+ margin-bottom: 80px;
+}
+
+.partner-box {
+ position: relative;
+ width: 47%;
+ max-width: 48%;
+ min-width: 48%;
+ margin-bottom: 20px;
+ padding: 20px;
+ flex: 1;
+ display: flex;
+ justify-content: space-between;
+ align-items: flex-start;
+}
+
+.partner-box img {
+ background-color: #f9f9f9;
+}
+
+.partner-box > div {
+ margin-left: 30px;
+}
+
+.partner-box a {
+ color: #3576E3;
+}
+
+@media screen and (max-width: 1024px) {
+ .partner-box {
+ flex-direction: column;
+ justify-content: flex-start;
+ }
+
+ .partner-box > div {
+ margin: 20px 0 0;
+ }
+}
+
+@media screen and (max-width: 568px) {
+ #isvContainer, #servContainer {
+ justify-content: center;
+ }
+
+ .partner-box {
+ flex-direction: column;
+ justify-content: flex-start;
+ width: 100%;
+ max-width: 100%;
+ min-width: 100%;
+ }
+
+ .partner-box > div {
+ margin: 20px 0 0;
+ }
+}
+
+@media screen and (max-width: 568px) {
+ #isvContainer, #servContainer {
+ justify-content: center;
+ }
+
+ .partner-box {
+ flex-direction: column;
+ justify-content: flex-start;
+ width: 100%;
+ max-width: 100%;
+ min-width: 100%;
+ }
+
+ .partner-box > div {
+ margin: 20px 0 0;
+ }
+}
diff --git a/_includes/task-tutorial-prereqs.md b/_includes/task-tutorial-prereqs.md
new file mode 100644
index 0000000000..a9cf90d265
--- /dev/null
+++ b/_includes/task-tutorial-prereqs.md
@@ -0,0 +1,4 @@
+You need to have a Kubernetes cluster, and the kubectl command-line tool must
+be configured to communicate with your cluster. If you do not already have a
+cluster, you can create one by using
+[Minikube](/docs/getting-started-guides/minikube).
diff --git a/_sass/_desktop.sass b/_sass/_desktop.sass
index 033e998ba0..9c02fbcf6c 100644
--- a/_sass/_desktop.sass
+++ b/_sass/_desktop.sass
@@ -164,10 +164,11 @@ $video-section-height: 550px
margin-bottom: 20px
a
- width: 20%
+ width: 16.65%
float: left
font-size: 24px
font-weight: 300
+ white-space: nowrap
.social
padding: 0 30px
diff --git a/_sass/_tablet.sass b/_sass/_tablet.sass
index ce9bcd941d..15d5b496f4 100644
--- a/_sass/_tablet.sass
+++ b/_sass/_tablet.sass
@@ -222,8 +222,7 @@ $feature-box-div-width: 45%
text-align: center
a
- font-size: 22px
- width: auto
+ width: 30%
padding: 0 20px
.social
diff --git a/community.html b/community.html
index f47bff33e7..9ef63c1b66 100644
--- a/community.html
+++ b/community.html
@@ -10,8 +10,6 @@ title: Community
Community
-
-
@@ -29,20 +27,6 @@ title: Community
from AWS and Openstack to Big Data and Scalability, there’s a place for you to contribute and instructions
for forming a new SIG if your special interest isn’t covered (yet).
-
Events
@@ -50,34 +34,6 @@ title: Community
frameborder="0" scrolling="no">
-
-
Partners
-
We are working with a broad group of partners who contribute to the kubernetes core codebase, making it stronger and richer, as well as help in growing the kubernetes ecosystem supporting
- a sprectrum of compelmenting platforms, from open source solutions to market-leading technologies.
-
-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-
-
diff --git a/docs/admin/addons.md b/docs/admin/addons.md
index 6e28edfaa2..e802343ab9 100644
--- a/docs/admin/addons.md
+++ b/docs/admin/addons.md
@@ -12,6 +12,7 @@ This page lists some of the available add-ons and links to their respective inst
* [Weave Net](https://github.com/weaveworks/weave-kube) provides networking and network policy, will carry on working on both sides of a network partition, and does not require an external database.
* [Calico](https://github.com/projectcalico/calico-containers/tree/master/docs/cni/kubernetes/manifests/kubeadm) is a secure L3 networking and network policy provider.
* [Canal](https://github.com/tigera/canal/tree/master/k8s-install/kubeadm) unites Flannel and Calico, providing networking and network policy.
+* [Romana](http://romana.io) is a Layer 3 networking solution for pod networks that also supports the [NetworkPolicy API](/docs/user-guide/networkpolicies/). Kubeadm add-on installation details available [here](https://github.com/romana/romana/tree/master/containerize).
## Visualization & Control
diff --git a/docs/admin/kubeadm.md b/docs/admin/kubeadm.md
index 57a21528c2..a8acd6b1cb 100644
--- a/docs/admin/kubeadm.md
+++ b/docs/admin/kubeadm.md
@@ -9,26 +9,43 @@ assignees:
This document provides information on how to use kubeadm's advanced options.
-Running kubeadm init bootstraps a Kubernetes cluster. This consists of the
+Running `kubeadm init` bootstraps a Kubernetes cluster. This consists of the
following steps:
-1. kubeadm generates a token that additional nodes can use to register themselves
-with the master in future.
+1. kubeadm runs a series of pre-flight checks to validate the system state
+before making changes. Some checks only trigger warnings, others are
+considered errors and will exit kubeadm until the problem is corrected or
+the user specifies `--skip-preflight-checks`.
+
+1. kubeadm generates a token that additional nodes can use to register
+themselves with the master in future. Optionally, the user can provide a token.
1. kubeadm generates a self-signed CA using openssl to provision identities
for each node in the cluster, and for the API server to secure communication
with clients.
-1. Outputting a kubeconfig file for the kubelet to use to connect to the API server,
-as well as an additional kubeconfig file for administration.
+1. Outputting a kubeconfig file for the kubelet to use to connect to the API
+server, as well as an additional kubeconfig file for administration.
-1. kubeadm generates Kubernetes resource manifests for the API server, controller manager
-and scheduler, and placing them in `/etc/kubernetes/manifests`. The kubelet watches
-this directory for static resources to create on startup. These are the core
-components of Kubernetes, and once they are up and running we can use `kubectl`
-to set up/manage any additional components.
+1. kubeadm generates Kubernetes resource manifests for the API server,
+controller manager and scheduler, and placing them in
+`/etc/kubernetes/manifests`. The kubelet watches this directory for static
+resources to create on startup. These are the core components of Kubernetes, and
+once they are up and running we can use `kubectl` to set up/manage any
+additional components.
-1. kubeadm installs any add-on components, such as DNS or discovery, via the API server.
+1. kubeadm installs any add-on components, such as DNS or discovery, via the API
+server.
+
+Running `kubeadm join` on each node in the cluster consists of the following steps:
+
+1. Use the token to talk to the API server and securely get the root CA
+certificate.
+
+1. Creates a local key pair. Prepares a certificate signing request (CSR) and
+sends that off to the API server for signing.
+
+1. Configures the local kubelet to connect to the API server
## Usage
@@ -112,11 +129,17 @@ to change the DNS name suffix. Again, you will need to update the
`/etc/systemd/system/kubelet.service.d/10-kubeadm.conf` file accordingly else DNS will
not function correctly.
+- `--skip-preflight-checks`
+
+By default, `kubeadm` runs a series of preflight checks to validate the system
+before making any changes. Advanced users can use this flag to bypass these if
+necessary.
+
- `--token`
By default, `kubeadm init` automatically generates the token used to initialise
each new node. If you would like to manually specify this token, you can use the
-`--token` flag. The token must be of the format '<6 character string>.<16 character string>'.
+`--token` flag. The token must be of the format `<6 character string>.<16 character string>`.
- `--use-kubernetes-version` (default 'v1.4.1') the kubernetes version to initialise
@@ -127,18 +150,59 @@ for a full list of available versions).
### `kubeadm join`
-`kubeadm join` has one mandatory flag, the token used to secure cluster bootstrap,
-and one mandatory argument, the master IP address.
+When you use kubeadm join, you must supply the token used to secure cluster
+boostrap as a mandatory flag, and the master IP address as a mandatory argument.
Here's an example on how to use it:
`kubeadm join --token=the_secret_token 192.168.1.1`
+- `--skip-preflight-checks`
+
+By default, `kubeadm` runs a series of preflight checks to validate the system
+before making any changes. Advanced users can use this flag to bypass these if
+necessary.
+
- `--token=`
By default, when `kubeadm init` runs, a token is generated and revealed in the output.
That's the token you should use here.
+## Automating kubeadm
+
+Rather than copying the token you obtained from `kubeadm init` to each node, as
+in the basic `kubeadm` tutorials, you can parallelize the token distribution for
+easier automation. To implement this automation, you must know the IP address
+that the master will have after it is started.
+
+1. Generate a token. This token must have the form `<6 character string>.<16
+character string>`
+
+ Here is a simple python one-liner for this:
+
+ ```
+ python -c 'import random; print "%0x.%0x" % (random.SystemRandom().getrandbits(3*8), random.SystemRandom().getrandbits(8*8))'
+ ```
+
+1. Start both the master node and the worker nodes concurrently with this token. As they come up they should find each other and form the cluster.
+
+Once the cluster is up, you can grab the admin credentials from the master node at `/etc/kubernetes/admin.conf` and use that to talk to the cluster.
+
+## Environment variables
+
+There are some environment variables that modify the way that `kubeadm` works. Most users will have no need to set these.
+
+| Variable | Default | Description |
+| --- | --- | --- |
+| `KUBE_KUBERNETES_DIR` | `/etc/kubernetes` | Where most configuration files are written to and read from |
+| `KUBE_HOST_PKI_PATH` | `/etc/kubernetes/pki` | Directory for master PKI assets |
+| `KUBE_HOST_ETCD_PATH` | `/var/lib/etcd` | Local etcd state for Kubernetes cluster |
+| `KUBE_HYPERKUBE_IMAGE` | `` | If set, use a single hyperkube image with this name. If not set, individual images per server component will be used. |
+| `KUBE_DISCOVERY_IMAGE` | `gcr.io/google_containers/kube-discovery-:1.0` | The bootstrap discovery helper image to use. |
+| `KUBE_ETCD_IMAGE` | `gcr.io/google_containers/etcd-:2.2.5` | The etcd container image to use. |
+| `KUBE_COMPONENT_LOGLEVEL` | `--v=4` | Logging configuration for all Kubernetes components |
+
+
## Troubleshooting
* Some users on RHEL/CentOS 7 have reported issues with traffic being routed incorrectly due to iptables being bypassed. You should ensure `net.bridge.bridge-nf-call-iptables` is set to 1 in your sysctl config, eg.
diff --git a/docs/admin/network-plugins.md b/docs/admin/network-plugins.md
index c0397016da..8cfeb658c9 100644
--- a/docs/admin/network-plugins.md
+++ b/docs/admin/network-plugins.md
@@ -36,7 +36,11 @@ Place plugins in `network-plugin-dir/plugin-name/plugin-name`, i.e if you have a
### CNI
-The CNI plugin is selected by passing Kubelet the `--network-plugin=cni` command-line option. Kubelet reads the first CNI configuration file from `--network-plugin-dir` and uses the CNI configuration from that file to set up each pod's network. The CNI configuration file must match the [CNI specification](https://github.com/containernetworking/cni/blob/master/SPEC.md), and any required CNI plugins referenced by the configuration must be present in `/opt/cni/bin`.
+The CNI plugin is selected by passing Kubelet the `--network-plugin=cni` command-line option. Kubelet reads a file from `--cni-conf-dir` (default `/etc/cni/net.d`) and uses the CNI configuration from that file to set up each pod's network. The CNI configuration file must match the [CNI specification](https://github.com/containernetworking/cni/blob/master/SPEC.md), and any required CNI plugins referenced by the configuration must be present in `--cni-bin-dir` (default `/opt/cni/bin`).
+
+If there are multiple CNI configuration files in the directory, the first one in lexicographic order of file name is used.
+
+In addition to the CNI plugin specified by the configuration file, Kubernetes requires the standard CNI `lo` plugin, at minimum version 0.2.0
### kubenet
@@ -44,7 +48,7 @@ The Linux-only kubenet plugin provides functionality similar to the `--configure
The plugin requires a few things:
-* The standard CNI `bridge` and `host-local` plugins are required. Kubenet will first search for them in `/opt/cni/bin`. Specify `network-plugin-dir` to supply additional search path. The first found match will take effect.
+* The standard CNI `bridge`, `lo` and `host-local` plugins are required, at minimum version 0.2.0. Kubenet will first search for them in `/opt/cni/bin`. Specify `network-plugin-dir` to supply additional search path. The first found match will take effect.
* Kubelet must be run with the `--network-plugin=kubenet` argument to enable the plugin
* Kubelet must also be run with the `--reconcile-cidr` argument to ensure the IP subnet assigned to the node by configuration or the controller-manager is propagated to the plugin
* The node must be assigned an IP subnet through either the `--pod-cidr` kubelet command-line option or the `--allocate-node-cidrs=true --cluster-cidr=` controller-manager command-line options.
@@ -66,6 +70,6 @@ This option is provided to the network-plugin; currently **only kubenet supports
## Usage Summary
* `--network-plugin=exec` specifies that we use the `exec` plugin, with executables located in `--network-plugin-dir`.
-* `--network-plugin=cni` specifies that we use the `cni` network plugin with actual CNI plugin binaries located in `/opt/cni/bin` and CNI plugin configuration located in `network-plugin-dir`, config location defaults to `/etc/cni/net.d`.
+* `--network-plugin=cni` specifies that we use the `cni` network plugin with actual CNI plugin binaries located in `--cni-bin-dir` (default `/opt/cni/bin`) and CNI plugin configuration located in `--cni-conf-dir` (default `/etc/cni/net.d`).
* `--network-plugin=kubenet` specifies that we use the `kubenet` network plugin with CNI `bridge` and `host-local` plugins placed in `/opt/cni/bin` or `network-plugin-dir`.
* `--network-plugin-mtu=9001` specifies the MTU to use, currently only used by the `kubenet` network plugin.
\ No newline at end of file
diff --git a/docs/admin/networking.md b/docs/admin/networking.md
index 9275b88565..2acbf062d4 100644
--- a/docs/admin/networking.md
+++ b/docs/admin/networking.md
@@ -1,4 +1,4 @@
----
+---
assignees:
- lavalamp
- thockin
@@ -191,7 +191,7 @@ Calico can also be run in policy enforcement mode in conjunction with other netw
### Romana
-[Romana](http://romana.io) is an open source software defined networking (SDN) solution that lets you deploy Kubernetes without an overlay network.
+[Romana](http://romana.io) is an open source network and security automation solution that lets you deploy Kubernetes without an overlay network. Romana supports Kubernetes [Network Policy](/docs/user-guide/networkpolicies/) to provide isolation across network namespaces.
### Contiv
diff --git a/docs/getting-started-guides/centos/centos_manual_config.md b/docs/getting-started-guides/centos/centos_manual_config.md
index 75b7cccbf7..08419bcff7 100644
--- a/docs/getting-started-guides/centos/centos_manual_config.md
+++ b/docs/getting-started-guides/centos/centos_manual_config.md
@@ -123,7 +123,7 @@ KUBE_API_ARGS=""
```shell
$ etcdctl mkdir /kube-centos/network
-$ etcdclt mk /kube-centos/network/config "{ \"Network\": \"172.30.0.0/16\", \"SubnetLen\": 24, \"Backend\": { \"Type\": \"vxlan\" } }"
+$ etcdctl mk /kube-centos/network/config "{ \"Network\": \"172.30.0.0/16\", \"SubnetLen\": 24, \"Backend\": { \"Type\": \"vxlan\" } }"
```
* Configure flannel to overlay Docker network in /etc/sysconfig/flanneld on the master (also in the nodes as we'll see):
@@ -196,6 +196,13 @@ for SERVICES in kube-proxy kubelet flanneld docker; do
systemctl status $SERVICES
done
```
+* Configure kubectl
+
+```shell
+kubectl config set-cluster default-cluster --server=http://centos-master:8080
+kubectl config set-context default-context --cluster=default-cluster --user=default-admin
+kubectl config use-context default-context
+```
*You should be finished!*
diff --git a/docs/getting-started-guides/kops.md b/docs/getting-started-guides/kops.md
new file mode 100644
index 0000000000..0cc28fb547
--- /dev/null
+++ b/docs/getting-started-guides/kops.md
@@ -0,0 +1,160 @@
+---
+---
+
+
+
+## Overview
+
+This quickstart shows you how to easily install a Kubernetes cluster on AWS.
+It uses a tool called [`kops`](https://github.com/kubernetes/kops).
+
+kops is an opinionated provisioning system:
+
+* Fully automated installation
+* Uses DNS to identify clusters
+* Self-healing: everything runs in Auto-Scaling Groups
+* Limited OS support (Debian preferred, Ubuntu 16.04 supported, early support for CentOS & RHEL)
+* High-Availability support
+* Can directly provision, or generate terraform manifests
+
+If your opinions differ from these you may prefer to build your own cluster using [kubeadm](kubeadm) as
+a building block. kops builds on the kubeadm work.
+
+## Creating a cluster
+
+### (1/5) Install kops
+
+Download kops from the [releases page](https://github.com/kubernetes/kops/releases) (it is also easy to build from source):
+
+On MacOS:
+
+```
+wget https://github.com/kubernetes/kops/releases/download/v1.4.1/kops-darwin-amd64
+chmod +x kops-darwin-amd64
+mv kops-darwin-amd64 /usr/local/bin/kops
+```
+
+On Linux:
+
+```
+wget https://github.com/kubernetes/kops/releases/download/v1.4.1/kops-linux-amd64
+chmod +x kops-linux-amd64
+mv kops-linux-amd64 /usr/local/bin/kops
+```
+
+### (2/5) Create a route53 domain for your cluster
+
+kops uses DNS for discovery, both inside the cluster and so that you can reach the kubernetes API server
+from clients.
+
+kops has a strong opinion on the cluster name: it should be a valid DNS name. By doing so you will
+no longer get your clusters confused, you can share clusters with your colleagues unambigiously,
+and you can reach them without relying on remembering an IP address.
+
+You can, and probably should, use subdomains to divide your clusters. As our example we will use
+`useast1.dev.example.com`. The API server endpoint will then be `api.useast1.dev.example.com`.
+
+A Route53 hosted zone can serve subdomains. Your hosted zone could be `useast1.dev.example.com`,
+but also `dev.example.com` or even `example.com`. kops works with any of these, so typically
+you choose for organization reasons (e.g. you are allowed to create records under `dev.example.com`,
+but not under `example.com`).
+
+Let's assume you're using `dev.example.com` as your hosted zone. You create that hosted zone using
+the [normal process](http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/CreatingNewSubdomain.html), or
+with a command such as `aws route53 create-hosted-zone --name dev.example.com --caller-reference 1`.
+
+You must then set up your NS records in the parent domain, so that records in the domain will resolve. Here,
+you would create NS records in `example.com` for `dev`. If it is a root domain name you would configure the NS
+records at your domain registrar (e.g. `example.com` would need to be configured where you bought `example.com`).
+
+This step is easy to mess up (it is the #1 cause of problems!) You can double-check that
+your cluster is configured correctly if you have the dig tool by running:
+
+`dig NS dev.example.com`
+
+You should see the 4 NS records that Route53 assigned your hosted zone.
+
+### (3/5) Create an S3 bucket to store your clusters state
+
+kops lets you manage your clusters even after installation. To do this, it must keep track of the clusters
+that you have created, along with their configuration, the keys they are using etc. This information is stored
+in an S3 bucket. S3 permissions are used to control access to the bucket.
+
+Multiple clusters can use the same S3 bucket, and you can share an S3 bucket between your colleagues that
+administer the same clusters - this is much easier than passing around kubecfg files. But anyone with access
+to the S3 bucket will have administrative access to all your clusters, so you don't want to share it beyond
+the operations team.
+
+So typically you have one S3 bucket for each ops team (and often the name will correspond
+to the name of the hosted zone above!)
+
+In our example, we chose `dev.example.com` as our hosted zone, so let's pick `clusters.dev.example.com` as
+the S3 bucket name.
+
+* Export `AWS_PROFILE` (if you need to select a profile for the AWS CLI to work)
+
+* Create the S3 bucket using `aws s3 mb s3://clusters.dev.example.com`
+
+* You can `export KOPS_STATE_STORE=s3://clusters.dev.example.com` and then kops will use this location by default.
+ We suggest putting this in your bash profile or similar.
+
+
+### (4/5) Build your cluster configuration
+
+Run "kops create cluster" to create your cluster configuration:
+
+`kops create cluster --zones=us-east-1c useast1.dev.example.com`
+
+kops will create the configuration for your cluster. Note that it _only_ creates the configuration, it does
+not actually create the cloud resources - you'll do that in the next step with a `kops update cluster`. This
+give you an opportunity to review the configuration or change it.
+
+It prints commands you can use to explore further:
+
+* List your clusters with: `kops get cluster`
+* Edit this cluster with: `kops edit cluster useast1.dev.example.com`
+* Edit your node instance group: `kops edit ig --name=useast1.dev.example.com nodes`
+* Edit your master instance group: `kops edit ig --name=useast1.dev.example.com master-us-east-1c`
+
+If this is your first time using kops, do spend a few minutes to try those out! An instance group is a
+set of instances, which will be registered as kubernetes nodes. On AWS this is implemented via auto-scaling-groups.
+You can have several instance groups, for example if you wanted nodes that are a mix of spot and on-demand instances, or
+GPU and non-GPU instances.
+
+
+### (5/5) Create the cluster in AWS
+
+Run "kops update cluster" to create your cluster in AWS:
+
+`kops update cluster useast1.dev.awsdata.com --yes`
+
+That takes a few seconds to run, but then your cluster will likely take a few minutes to actually be ready.
+`kops update cluster` will be the tool you'll use whenever you change the configuration of your cluster; it
+applies the changes you have made to the configuration to your cluster - reconfiguring AWS or kubernetes as needed.
+
+For example, after you `kops edit ig nodes`, then `kops update cluster --yes` to apply your configuration, and
+sometimes you will also have to `kops rolling-update cluster` to roll out the configuration immediately.
+
+Without `--yes`, `kops update cluster` will show you a preview of what it is going to do. This is handy
+for production clusters!
+
+### Explore other add-ons
+
+See the [list of add-ons](/docs/admin/addons/) to explore other add-ons, including tools for logging, monitoring, network policy, visualization & control of your Kubernetes cluster.
+
+## What's next
+
+* Learn more about [Kubernetes concepts and kubectl in Kubernetes 101](/docs/user-guide/walkthrough/).
+* Learn about `kops` [advanced usage](https://github.com/kubernetes/kops)
+
+## Cleanup
+
+* To delete you cluster: `kops delete cluster useast1.dev.example.com --yes`
+
+## Feedback
+
+* Slack Channel: [#sig-aws](https://kubernetes.slack.com/messages/sig-aws/) has a lot of kops users
+* [GitHub Issues](https://github.com/kubernetes/kops/issues)
+
diff --git a/docs/getting-started-guides/kubeadm.md b/docs/getting-started-guides/kubeadm.md
index f4f4c15211..5848fbdc5f 100644
--- a/docs/getting-started-guides/kubeadm.md
+++ b/docs/getting-started-guides/kubeadm.md
@@ -1,4 +1,10 @@
---
+assignees:
+- mikedanese
+- luxas
+- errordeveloper
+- jbeda
+
---
{% include footer.html %}
{% include case-study-styles.html %}
+
+
+
+