diff --git a/community.html b/community.html index 626832f512..a1e0e04d61 100644 --- a/community.html +++ b/community.html @@ -71,6 +71,7 @@ title: Community + diff --git a/docs/admin/accessing-the-api.md b/docs/admin/accessing-the-api.md index 57d67a0a5d..6569ac93f8 100644 --- a/docs/admin/accessing-the-api.md +++ b/docs/admin/accessing-the-api.md @@ -116,7 +116,7 @@ rejects, then the request is immediately rejected. In addition to rejecting objects, admission controllers can also set complex defaults for fields. -The available Admission Control Modules are described [here](docs/admin/admission-controllers/). +The available Admission Control Modules are described [here](/docs/admin/admission-controllers/). Once a request passes all admission controllers, it is validated using the validation routines for the corresponding API object, and then written to the object store (shown as step **4**). diff --git a/docs/admin/node-problem.md b/docs/admin/node-problem.md index ab09a78dfc..fdb557311c 100644 --- a/docs/admin/node-problem.md +++ b/docs/admin/node-problem.md @@ -36,8 +36,8 @@ it to [support other log format](/docs/admin/node-problem/#support-other-log-for ## Enable/Disable in GCE cluster -Node problem detector is running as a cluster -[addon](docs/admin/cluster-large/#addon-resources) enabled by default in the +Node problem detector is [running as a cluster +addon](/docs/admin/cluster-large/#addon-resources) enabled by default in the gce cluster. You can enable/disable it by setting the environment variable diff --git a/docs/reference.md b/docs/reference.md index b8ed937049..c95f21a0c0 100644 --- a/docs/reference.md +++ b/docs/reference.md @@ -20,7 +20,7 @@ In the reference section, you can find reference documentation for Kubernetes AP ## Glossary -Explore the glossary of essential Kubernetes concepts. Some good starting points are the entries for [Pods](/docs/user-guide/pods/), [Nodes](/docs/admin/nodes/), [Services](/docs/user-guide/services/), and [Replication Controllers](/docs/user-guide/replication-controller/). +Explore the glossary of essential Kubernetes concepts. Some good starting points are the entries for [Pods](/docs/user-guide/pods/), [Nodes](/docs/admin/node/), [Services](/docs/user-guide/services/), and [Replication Controllers](/docs/user-guide/replication-controller/). ## Design Docs diff --git a/docs/user-guide/kubectl/kubectl.md b/docs/user-guide/kubectl/kubectl.md index daeff4a144..bc9ba1a76f 100644 --- a/docs/user-guide/kubectl/kubectl.md +++ b/docs/user-guide/kubectl/kubectl.md @@ -46,40 +46,40 @@ kubectl ### SEE ALSO -* [kubectl annotate](kubectl_annotate.md) - Update the annotations on a resource -* [kubectl api-versions](kubectl_api-versions.md) - Print the supported API versions on the server, in the form of "group/version". -* [kubectl apply](kubectl_apply.md) - Apply a configuration to a resource by filename or stdin -* [kubectl attach](kubectl_attach.md) - Attach to a running container. -* [kubectl autoscale](kubectl_autoscale.md) - Auto-scale a Deployment, ReplicaSet, or ReplicationController -* [kubectl cluster-info](kubectl_cluster-info.md) - Display cluster info -* [kubectl completion](kubectl_completion.md) - Output shell completion code for the given shell (bash or zsh) -* [kubectl config](kubectl_config.md) - config modifies kubeconfig files -* [kubectl convert](kubectl_convert.md) - Convert config files between different API versions -* [kubectl cordon](kubectl_cordon.md) - Mark node as unschedulable -* [kubectl create](kubectl_create.md) - Create a resource by filename or stdin -* [kubectl delete](kubectl_delete.md) - Delete resources by filenames, stdin, resources and names, or by resources and label selector. -* [kubectl describe](kubectl_describe.md) - Show details of a specific resource or group of resources -* [kubectl drain](kubectl_drain.md) - Drain node in preparation for maintenance -* [kubectl edit](kubectl_edit.md) - Edit a resource on the server -* [kubectl exec](kubectl_exec.md) - Execute a command in a container. -* [kubectl explain](kubectl_explain.md) - Documentation of resources. -* [kubectl expose](kubectl_expose.md) - Take a replication controller, service, deployment or pod and expose it as a new Kubernetes Service -* [kubectl get](kubectl_get.md) - Display one or many resources -* [kubectl label](kubectl_label.md) - Update the labels on a resource -* [kubectl logs](kubectl_logs.md) - Print the logs for a container in a pod. -* [kubectl namespace](kubectl_namespace.md) - SUPERSEDED: Set and view the current Kubernetes namespace -* [kubectl patch](kubectl_patch.md) - Update field(s) of a resource using strategic merge patch. -* [kubectl port-forward](kubectl_port-forward.md) - Forward one or more local ports to a pod. -* [kubectl proxy](kubectl_proxy.md) - Run a proxy to the Kubernetes API server -* [kubectl replace](kubectl_replace.md) - Replace a resource by filename or stdin. -* [kubectl rolling-update](kubectl_rolling-update.md) - Perform a rolling update of the given ReplicationController. -* [kubectl rollout](kubectl_rollout.md) - rollout manages a deployment -* [kubectl run](kubectl_run.md) - Run a particular image on the cluster. -* [kubectl scale](kubectl_scale.md) - Set a new size for a Deployment, ReplicaSet, Replication Controller, or Job. -* [kubectl set](kubectl_set.md) - Set specific features on objects -* [kubectl taint](kubectl_taint.md) - Update the taints on one or more nodes -* [kubectl uncordon](kubectl_uncordon.md) - Mark node as schedulable -* [kubectl version](kubectl_version.md) - Print the client and server version information. +* [kubectl annotate](../kubectl_annotate/) - Update the annotations on a resource +* [kubectl api-versions](../kubectl_api-versions/) - Print the supported API versions on the server, in the form of "group/version". +* [kubectl apply](../kubectl_apply/) - Apply a configuration to a resource by filename or stdin +* [kubectl attach](../kubectl_attach/) - Attach to a running container. +* [kubectl autoscale](../kubectl_autoscale/) - Auto-scale a Deployment, ReplicaSet, or ReplicationController +* [kubectl cluster-info](../kubectl_cluster-info/) - Display cluster info +* [kubectl completion](../kubectl_completion/) - Output shell completion code for the given shell (bash or zsh) +* [kubectl config](../kubectl_config/) - config modifies kubeconfig files +* [kubectl convert](../kubectl_convert/) - Convert config files between different API versions +* [kubectl cordon](../kubectl_cordon/) - Mark node as unschedulable +* [kubectl create](../kubectl_create/) - Create a resource by filename or stdin +* [kubectl delete](../kubectl_delete/) - Delete resources by filenames, stdin, resources and names, or by resources and label selector. +* [kubectl describe](../kubectl_describe/) - Show details of a specific resource or group of resources +* [kubectl drain](../kubectl_drain/) - Drain node in preparation for maintenance +* [kubectl edit](../kubectl_edit/) - Edit a resource on the server +* [kubectl exec](../kubectl_exec/) - Execute a command in a container. +* [kubectl explain](../kubectl_explain/) - Documentation of resources. +* [kubectl expose](../kubectl_expose/) - Take a replication controller, service, deployment or pod and expose it as a new Kubernetes Service +* [kubectl get](../kubectl_get/) - Display one or many resources +* [kubectl label](../kubectl_label/) - Update the labels on a resource +* [kubectl logs](../kubectl_logs/) - Print the logs for a container in a pod. +* [kubectl namespace](../kubectl_namespace/) - SUPERSEDED: Set and view the current Kubernetes namespace +* [kubectl patch](../kubectl_patch/) - Update field(s) of a resource using strategic merge patch. +* [kubectl port-forward](../kubectl_port-forward/) - Forward one or more local ports to a pod. +* [kubectl proxy](../kubectl_proxy/) - Run a proxy to the Kubernetes API server +* [kubectl replace](../kubectl_replace/) - Replace a resource by filename or stdin. +* [kubectl rolling-update](../kubectl_rolling-update/) - Perform a rolling update of the given ReplicationController. +* [kubectl rollout](../kubectl_rollout/) - rollout manages a deployment +* [kubectl run](../kubectl_run/) - Run a particular image on the cluster. +* [kubectl scale](../kubectl_scale/) - Set a new size for a Deployment, ReplicaSet, Replication Controller, or Job. +* [kubectl set](../kubectl_set/) - Set specific features on objects +* [kubectl taint](../kubectl_taint/) - Update the taints on one or more nodes +* [kubectl uncordon](../kubectl_uncordon/) - Mark node as schedulable +* [kubectl version](../kubectl_version/) - Print the client and server version information. ###### Auto generated by spf13/cobra on 12-Aug-2016 diff --git a/docs/user-guide/load-balancer.md b/docs/user-guide/load-balancer.md index 7c9c43a63b..c129190248 100644 --- a/docs/user-guide/load-balancer.md +++ b/docs/user-guide/load-balancer.md @@ -8,19 +8,28 @@ ## Overview When creating a service, you have the option of automatically creating a -network load balancer. This provides an +cloud network load balancer. This provides an externally-accessible IP address that sends traffic to the correct port on your -cluster nodes. +cluster nodes _provided your cluster runs in a supported environment and is configured with the correct cloud load balancer provider package_. + +## External Load Balancer Providers + +It is important to note that the datapath for this functionality is provided by a load balancer external to the Kubernetes cluster. + +When the service type is set to `LoadBalancer`, Kubernetes provides functionality equivalent to type=`ClusterIP` to pods within the cluster and extends it by programming the (external to Kubernetes) load balancer with entries for the Kubernetes VMs. The Kubernetes service controller automates the creation of the external load balancer, health checks (if needed), firewall rules (if needed) and retrieves the external IP allocated by the cloud provider and populates it in the service object. ## Configuration file To create an external load balancer, add the following line to your [service configuration file](/docs/user-guide/services/operations/#service-configuration-file): +```json "type": "LoadBalancer" +``` Your configuration file might look like: +```json { "kind": "Service", "apiVersion": "v1", @@ -38,14 +47,17 @@ Your configuration file might look like: "type": "LoadBalancer" } } +``` ## Using kubectl You can alternatively create the service with the `kubectl expose` command and its `--type=LoadBalancer` flag: +```bash $ kubectl expose rc example --port=8765 --target-port=9376 \ --name=example-service --type=LoadBalancer +``` This command creates a new service using the same selectors as the referenced resource (in the case of the example above, a replication controller named @@ -59,6 +71,7 @@ For more information, including optional flags, refer to the You can find the IP address created for your service by getting the service information through `kubectl`: +```bash $ kubectl describe services example-service Name: example-service Selector: app=example @@ -70,5 +83,70 @@ information through `kubectl`: Endpoints: 10.64.0.4:80,10.64.1.5:80,10.64.2.4:80 Session Affinity: None No events. +``` The IP address is listed next to `LoadBalancer Ingress`. + +## Loss of client source IP for external traffic + +Due to the implementation of this feature, the source IP for sessions as seen in the target container will *not be the original source IP* of the client. This is the default behavior as of Kubernetes v1.4. However, starting in v1.4, an optional alpha feature has been added +that will preserve the client Source IP for GCE/GKE environments. This feature will be phased in for other cloud providers in subsequent releases. + +## Annotation to modify the LoadBalancer behavior for preservation of Source IP +In 1.4, an Alpha feature has been added that changes the behavior of the external LoadBalancer feature. + +This feature can be activated by adding the alpha annotation below to the metadata section of the Service Configuration file. + +```json + { + "kind": "Service", + "apiVersion": "v1", + "metadata": { + "name": "example-service", + "annotations": { + "service.alpha.kubernetes.io/external-traffic": "OnlyLocal" + } + }, + "spec": { + "ports": [{ + "port": 8765, + "targetPort": 9376 + }], + "selector": { + "app": "example" + }, + "type": "LoadBalancer" + } + } +``` + +### Alpha Feature Gate for the 'service.alpha.kubernetes.io/external-traffic' annotation + +Alpha features are not enabled by default, they must be enabled using the release gate command line flags +for kube-controller-manager and kube-proxy. +See [https://github.com/kubernetes/kubernetes/blob/master/docs/proposals/runtimeconfig.md](Runtime feature flags proposal) for more details on feature gate flags. + +If this feature is not enabled in your cluster, this annotation in your service configuration will be rejected. + +### Implementation across different cloudproviders/environments + +Note that this feature is not currently implemented for all cloudproviders/environments. +This feature does not work for nodePorts yet, so environments/cloud providers with proxy-style load-balancers cannot use it yet. + +### Caveats and Limitations when preserving source IPs + +GCE/AWS load balancers do not provide weights for their target pools. This was not an issue with the old LB +kube-proxy rules which would correctly balance across all endpoints. + +With the new functionality, the external traffic will not be equally load balanced across pods, but rather +equally balanced at the node level (because GCE/AWS and other external LB implementations do not have the ability +for specifying the weight per node, they balance equally across all target nodes, disregarding the number of +pods on each node). + +We can, however, state that for NumServicePods << NumNodes or NumServicePods >> NumNodes, a fairly close-to-equal +distribution will be seen, even without weights. + +Once the external load balancers provide weights, this functionality can be added to the LB programming path. +*Future Work: No support for weights is provided for the 1.4 release, but may be added at a future date* + +Internal pod to pod traffic should behave similar to ClusterIP services, with equal probability across all pods. diff --git a/docs/user-guide/petset.md b/docs/user-guide/petset.md index 91796a4316..47213c188d 100644 --- a/docs/user-guide/petset.md +++ b/docs/user-guide/petset.md @@ -83,7 +83,7 @@ Example workloads for Pet Set: Before you start deploying applications as Pet Sets, there are a few limitations you should understand. * Pet Set is an *alpha* resource, not available in any Kubernetes release prior to 1.3. -* As with all alpha/beta resources, it can be disable through the `--runtime-config` option passed to the apiserver, and in fact most likely will be disabled on hosted offerings of Kubernetes. +* As with all alpha/beta resources, it can be disabled through the `--runtime-config` option passed to the apiserver, and in fact most likely will be disabled on hosted offerings of Kubernetes. * The only updatable field on a Pet Set is `replicas` * The storage for a given pet must either be provisioned by a [dynamic storage provisioner](http://releases.k8s.io/{{page.githubbranch}}/examples/experimental/persistent-volume-provisioning/README.md) based on the requested `storage class`, or pre-provisioned by an admin. Note that dynamic volume provisioning is also currently in alpha. * Deleting the Pet Set *will not* delete any pets. You will either have to manually scale it down to 0 pets first, or delete the pets yourself. @@ -145,7 +145,7 @@ Cluster Domain | Service (ns/name) | Pet Set (ns/name) | Pet Set Domain | Pet DN Note that Cluster Domain will be set to `cluster.local` unless [otherwise configured](http://releases.k8s.io/{{page.githubbranch}}/build/kube-dns/README.md#how-do-i-configure-it). -Lets verify our assertion with a simple test. +Let's verify our assertion with a simple test. ```shell $ kubectl get svc @@ -154,7 +154,7 @@ nginx None 80/TCP 12m ... ``` -First, the PetSet gives provides a stable hostname: +First, the PetSet provides a stable hostname: ```shell $ for i in 0 1; do kubectl exec web-$i -- sh -c 'hostname'; done @@ -181,7 +181,7 @@ Name: web-1.nginx Address 1: 10.180.0.9 ``` -The containers are running nginx webservers, which by default will look for an index.html file in `/usr/share/nginx/html/index.html`. That directory is backed by a `PersistentVolume` created by the Pet Set. So lets write our hostname there: +The containers are running nginx webservers, which by default will look for an index.html file in `/usr/share/nginx/html/index.html`. That directory is backed by a `PersistentVolume` created by the Pet Set. So let's write our hostname there: ```shell $ for i in 0 1; do diff --git a/images/community_logos/ibm_logo.png b/images/community_logos/ibm_logo.png new file mode 100644 index 0000000000..79ccf45253 Binary files /dev/null and b/images/community_logos/ibm_logo.png differ