Merge branch 'master' into master

This commit is contained in:
Raúl Naveiras
2016-10-02 17:41:29 +01:00
committed by GitHub
21 changed files with 302 additions and 119 deletions
+4
View File
@@ -10,4 +10,8 @@ toc:
section:
- title: Using an HTTP Proxy to Access the Kubernetes API
path: /docs/tasks/access-kubernetes-api/http-proxy-access-api/
- title: Administering a Cluster
section:
- title: Assigning Pods to Nodes
path: /docs/tasks/administer-cluster/assign-pods-nodes/
+1 -1
View File
@@ -56,5 +56,5 @@ toc:
section:
- title: Running a Stateless Application Using a Deployment
path: /docs/tutorials/stateless-application/run-stateless-application-deployment/
- title: Exposing an External IP Address Using a Service
- title: Using a Service to Access an Application in a Cluster
path: /docs/tutorials/stateless-application/expose-external-ip-address-service/
+38 -38
View File
@@ -3,40 +3,40 @@
margin-top: 1em !important;
}
#caseStudies p {
.gridPage p {
color: rgb(26,26,26) !important;
margin-left: 0 !important;
padding-left: 0 !important;
font-weight: 300 !important;
}
#caseStudies #mainContent {
.gridPage #mainContent {
padding: 0;
}
#caseStudies #mainContent .content {
.gridPage #mainContent .content {
padding-top: 0;
}
#caseStudies main {
.gridPage main {
max-width: 1100px !important;
}
#caseStudies .content {
.gridPage .content {
position: relative;
margin: 0 auto 50px;
max-width: 90%;
}
#caseStudies .content p {
.gridPage .content p {
line-height: 24px !important;
}
#caseStudies .content h3 {
.gridPage .content h3 {
padding: 0 !important;
}
#caseStudies #hero h5 {
.gridPage #hero h5 {
padding-left: 20px;
margin: 0;
}
@@ -67,7 +67,7 @@
left: 0;
}
#caseStudies #mainContent .content .case-study p {
.gridPage #mainContent .content .case-study p {
font-family: "Roboto", sans-serif;
font-size: 16px;
padding: 0;
@@ -77,13 +77,13 @@
font-style: italic;
}
#caseStudies #video {
.gridPage #video {
background: #f9f9f9;
height: auto;
/*height: 340px;*/
}
#caseStudies #video main {
.gridPage #video main {
position: relative;
max-width: 900px !important;
height: 100%;
@@ -93,19 +93,19 @@
padding: 50px 20px;
}
#caseStudies #video main > div {
.gridPage #video main > div {
width: 50%;
}
#caseStudies #video main #zulilyLogo {
.gridPage #video main #zulilyLogo {
width: 100px;
}
#caseStudies #video main img {
.gridPage #video main img {
max-width: 100%;
}
#caseStudies #video h3 {
.gridPage #video h3 {
font-size: 32px;
font-weight: 300;
line-height: 38px;
@@ -113,57 +113,57 @@
margin: 0 0 1em 0;
}
#caseStudies #video p {
.gridPage #video p {
margin: 0;
}
#caseStudies #video p.attrib {
.gridPage #video p.attrib {
margin-bottom: 20px;
}
#caseStudies #video button > h6 {
.gridPage #video button > h6 {
font-size: 18px;
font-weight: 500;
margin: 1em 0;
color: #326de6;
}
#caseStudies #users {
.gridPage #users {
padding: 50px;
}
#caseStudies #users main {
.gridPage #users main {
max-width: 1150px !important;
}
#caseStudies #users main h3 {
.gridPage #users main h3 {
padding-left: 20px;
margin-bottom: 20px;
}
#caseStudies #usersGrid {
.gridPage #usersGrid {
position: relative;
display: flex;
flex-wrap: wrap;
justify-content: center;
}
#caseStudies #usersGrid a {
.gridPage #usersGrid a {
display: inline-block;
margin: 5px;
}
#caseStudies #usersGrid a img {
.gridPage #usersGrid a img {
box-shadow: 1px 1px 2px transparent;
transition: box-shadow 0.25s;
}
#caseStudies #usersGrid a img:hover {
.gridPage #usersGrid a img:hover {
box-shadow: 1px 1px 2px #cccccc;
}
#caseStudies #usersGrid a:last-child img,
#caseStudies #usersGrid a:last-child img:hover {
.gridPage #usersGrid a:last-child img,
.gridPage #usersGrid a:last-child img:hover {
box-shadow: 1px 1px 2px transparent;
}
@@ -173,12 +173,12 @@
box-shadow: 1px 2px 2px #dddddd;
}
#caseStudies .feature {
.gridPage .feature {
position: relative;
padding: 20px 0 20px 242px;
}
#caseStudies .feature img {
.gridPage .feature img {
position: absolute;
top: 20px;
left: 0;
@@ -225,7 +225,7 @@
margin-bottom: 0.5em;
}
#caseStudies .feature p.quote {
.gridPage .feature p.quote {
font-size: 20px;
line-height: 28px !important;
}
@@ -250,20 +250,20 @@
}
@media screen and (max-width: 900px){
#caseStudies #video main {
.gridPage #video main {
flex-direction: column;
align-items: center;
}
#caseStudies #video main > div {
.gridPage #video main > div {
width: 400px;
}
#caseStudies #video main > div + div {
.gridPage #video main > div + div {
margin-top: 30px;
}
#caseStudies #video h3 {
.gridPage #video h3 {
max-width: 100%;
}
}
@@ -282,12 +282,12 @@
transform: translateX(-50%);
}
#caseStudies .feature {
.gridPage .feature {
margin-top: 50px;
padding: 180px 0 0;
}
#caseStudies .feature img {
.gridPage .feature img {
top: 0;
left: 50%;
transform: translateX(-50%);
@@ -295,12 +295,12 @@
}
@media screen and (max-width: 480px){
#caseStudies #hero {
.gridPage #hero {
padding-right: 20px;
padding-left: 20px;
}
#caseStudies #video main > div {
.gridPage #video main > div {
width: 80%;
min-width: 280px;
}
+2 -1
View File
@@ -1131,7 +1131,7 @@ $feature-box-div-margin-bottom: 40px
// Community
#community, #caseStudies
#community, .gridPage
&.open-nav, &.flip-nav
.logo
background-image: url(/images/nav_logo2.svg)
@@ -1340,3 +1340,4 @@ $feature-box-div-margin-bottom: 40px
//
//
//
//
+1 -1
View File
@@ -270,7 +270,7 @@ $video-section-height: 550px
#community, #caseStudies
#community, .gridPage
#hero
text-align: left
+1 -1
View File
@@ -3,7 +3,7 @@ title: Case Studies
---
<!Doctype html>
<html id="caseStudies">
<html id="caseStudies" class="gridPage">
{% include head-header.html %}
<section id="hero" class="light-text">
+1 -1
View File
@@ -3,7 +3,7 @@ title: Pearson Case Study
---
<!Doctype html>
<html id="caseStudies">
<html id="caseStudies" class="gridPage">
{% include head-header.html %}
<section id="hero" class="light-text">
+1 -1
View File
@@ -3,7 +3,7 @@ title: Wikimedia Case Study
---
<!Doctype html>
<html id="caseStudies">
<html id="caseStudies" class="gridPage">
{% include head-header.html %}
<section id="hero" class="light-text">
+2 -2
View File
@@ -349,8 +349,8 @@ logs or through `journalctl`. More information is provided in
Additional resources:
- http://wiki.apparmor.net/index.php/QuickProfileLanguage
- http://wiki.apparmor.net/index.php/ProfileLanguage
- [Quick guide to the AppArmor profile language](http://wiki.apparmor.net/index.php/QuickProfileLanguage)
- [AppArmor core policy reference](http://wiki.apparmor.net/index.php/ProfileLanguage)
## API Reference
+22 -13
View File
@@ -66,8 +66,7 @@ See [APPENDIX](#appendix) for how to generate a client cert.
### Static Token File
Token file is enabled by passing the `--token-auth-file=SOMEFILE` option to the
API server. Currently, tokens last indefinitely, and the token list cannot be
The API server reads bearer tokens from a file when given the `--token-auth-file=SOMEFILE` option on the command line. Currently, tokens last indefinitely, and the token list cannot be
changed without restarting API server.
The token file format is implemented in `plugin/pkg/auth/authenticator/token/tokenfile/...`
@@ -78,8 +77,19 @@ optional group names. Note, if you have more than one group the column must be d
token,user,uid,"group1,group2,group3"
```
When using token authentication from an http client the API server expects an `Authorization`
header with a value of `Bearer SOMETOKEN`.
#### Putting a Bearer Token in a Request
When using bearer token authentication from an http client, the API
server expects an `Authorization` header with a value of `Bearer
THETOKEN`. The bearer token must be a character sequence that can be
put in an HTTP header value using no more than the encoding and
quoting facilities of HTTP. For example: if the bearer token is
`31ada4fd-adec-460c-809a-9e56ceb75269` then it would appear in an HTTP
header as shown below.
```http
Authentication: Bearer 31ada4fd-adec-460c-809a-9e56ceb75269
```
### Static Password File
@@ -171,7 +181,8 @@ type: kubernetes.io/service-account-token
Note: values are base64 encoded because secrets are always base64 encoded.
The signed JWT can be used as a bearer token to authenticate as the given service
account. Normally these secrets are mounted into pods for in-cluster access to
account. See [above](#putting-a-bearer-token-in-a-request) for how the token is included
in a request. Normally these secrets are mounted into pods for in-cluster access to
the API server, but can be used from outside the cluster as well.
Service accounts authenticate with the username `system:serviceaccount:(NAMESPACE):(SERVICEACCOUNT)`,
@@ -192,11 +203,8 @@ email, signed by the server.
To identify the user, the authenticator uses the `id_token` (not the `access_token`)
from the OAuth2 [token response](https://openid.net/specs/openid-connect-core-1_0.html#TokenResponse)
as a bearer token.
```
Authentication: Bearer (id_token)
```
as a bearer token. See [above](#putting-a-bearer-token-in-a-request) for how the token
is included in a request.
To enable the plugin, pass the following required flags:
@@ -272,10 +280,11 @@ contexts:
name: webhook
```
When a client attempts to authenticate with the API server using a bearer token,
using the `Authorization: Bearer (TOKEN)` HTTP header the authentication webhook
When a client attempts to authenticate with the API server using a bearer token
as discussed [above](#putting-a-bearer-token-in-a-request),
the authentication webhook
queries the remote service with a review object containing the token. Kubernetes
will not challenge request that lack such a header.
will not challenge a request that lacks such a header.
Note that webhook API objects are subject to the same [versioning compatibility rules](/docs/api/)
as other Kubernetes API objects. Implementers should be aware of looser
@@ -134,7 +134,7 @@ export KUBERNETES_PROVIDER=libvirt-coreos; wget -q -O - https://get.k8s.io | bas
Here is the curl version of this command:
```shell
export KUBERNETES_PROVIDER=libvirt-coreos; curl -sS https://get.k8s.io | bash`
export KUBERNETES_PROVIDER=libvirt-coreos; curl -sS https://get.k8s.io | bash
```
This script downloads and unpacks the tarball, then spawns a Kubernetes cluster on CoreOS instances with the following characteristics:
+2 -3
View File
@@ -47,9 +47,8 @@ ssh jclouds@${ip_address_of_master_node}
Build Kubernetes-Mesos.
```shell
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
export KUBERNETES_CONTRIB=mesos
git clone https://github.com/kubernetes-incubator/kube-mesos-framework
cd kube-mesos-framework
make
```
@@ -0,0 +1,88 @@
---
---
{% capture overview %}
This page shows how to assign a Kubernetes Pod to a particular node in a
Kubernetes cluster.
{% endcapture %}
{% capture prerequisites %}
* Install [kubectl](http://kubernetes.io/docs/user-guide/prereqs).
* Create a Kubernetes cluster, including a running Kubernetes
API server. One way to create a new cluster is to use
[Minikube](/docs/getting-started-guides/minikube).
* Configure `kubectl` to communicate with your Kubernetes API server. This
configuration is done automatically if you use Minikube.
{% endcapture %}
{% capture steps %}
### Adding a label to a node
1. List the nodes in your cluster:
kubectl get nodes
The output is similar to this:
NAME STATUS AGE
worker0 Ready 1d
worker1 Ready 1d
worker2 Ready 1d
1. Chose one of your nodes, and add a label to it:
kubectl label nodes <your-node-name> disktype=ssd
where `<your-node-name>` is the name of your chosen node.
1. Verify that your chosen node has a `disktype=ssd` label:
kubectl get nodes --show-labels
The output is similar to this:
NAME STATUS AGE LABELS
worker0 Ready 1d ...,disktype=ssd,kubernetes.io/hostname=worker0
worker1 Ready 1d ...,kubernetes.io/hostname=worker1
worker2 Ready 1d ...,kubernetes.io/hostname=worker2
In the preceding output, you can see that the `worker0` node has a
`disktype=ssd` label.
### Creating a pod that gets scheduled to your chosen node
This pod configuration file describes a pod that has a node selector,
`disktype: ssd`. This means that the pod will get scheduled on a node that has
a `disktype=ssd` label.
{% include code.html language="yaml" file="pod.yaml" ghlink="/docs/tasks/administer-cluster/pod.yaml" %}
1. Use the configuration file to create a pod that will get scheduled on your
chosen node:
export REPO=https://raw.githubusercontent.com/kubernetes/kubernetes.github.io/master
kubectl create -f $REPO/docs/tasks/administer-cluster/pod.yaml
1. Verify that the pod is running on your chosen node:
kubectl get pods --output=wide
The output is similar to this:
NAME READY STATUS RESTARTS AGE IP NODE
nginx 1/1 Running 0 13s 10.200.0.4 worker0
{% endcapture %}
{% capture whatsnext %}
Learn more about
[labels and selectors](/docs/user-guide/labels/).
{% endcapture %}
{% include templates/task.md %}
+13
View File
@@ -0,0 +1,13 @@
apiVersion: v1
kind: Pod
metadata:
name: nginx
labels:
env: test
spec:
containers:
- name: nginx
image: nginx
imagePullPolicy: IfNotPresent
nodeSelector:
disktype: ssd
+3
View File
@@ -11,6 +11,9 @@ The Tasks section of the Kubernetes documentation is a work in progress
* [Using an HTTP Proxy to Access the Kubernetes API](/docs/tasks/access-kubernetes-api/http-proxy-access-api)
#### Administering a Cluster
* [Assigning Pods to Nodes](/docs/tasks/administer-cluster/assign-pods-nodes/)
### What's next
+1 -1
View File
@@ -7,7 +7,7 @@ The Tutorials section of the Kubernetes documentation is a work in progress.
* [Running a Stateless Application Using a Deployment](/docs/tutorials/stateless-application/run-stateless-application-deployment/)
* [Exposing an External IP Address Using a Service](/docs/tutorials/stateless-application/expose-external-ip-address-service/)
* [Using a Service to Access an Application in a Cluster](/docs/tutorials/stateless-application/expose-external-ip-address-service/)
### What's next
@@ -4,9 +4,8 @@
{% capture overview %}
This page shows how to create a Kubernetes Service object that external
clients can use to access an application running in a cluster. The
Service exposes a stable IP address and provides load balancing for
an application that has two running instances.
clients can use to access an application running in a cluster. The Service
provides load balancing for an application that has two running instances.
{% endcapture %}
@@ -28,7 +27,7 @@ an application that has two running instances.
{% capture objectives %}
* Run two instances of a Hello World application.
* Create a Service object that exposes an external IP address.
* Create a Service object that exposes a node port.
* Use the Service object to access the running application.
{% endcapture %}
@@ -55,63 +54,68 @@ an application that has two running instances.
kubectl get deployments hello-world
kubectl describe deployments hello-world
1. Display information about the ReplicaSet:
1. Display information about your ReplicaSet objects:
kubectl get replicasets hello-world
kubectl describe replicasets hello-world
1. List the pods that are running the Hello World application:
kubectl get pods --selector="run=load-balancer-example"
The output is similar to this:
NAME READY STATUS RESTARTS AGE
hello-world-2189936611-8fyp0 1/1 Running 0 6m
hello-world-2189936611-9isq8 1/1 Running 0 6m
kubectl get replicasets
kubectl describe replicasets
1. Create a Service object that exposes the deployment:
kubectl expose deployment hello-world --type="LoadBalancer" --name="example-service"
kubectl expose deployment hello-world --type=NodePort --name=example-service
1. Display the IP addresses for your service:
1. Display information about the Service:
kubectl get services example-service
The output shows the internal IP address and the external IP address of
your service. If the external IP address shows as `<pending>`, repeat the
command.
Note: If you are using Minikube, you don't get an external IP address. The
external IP address remains in the pending state.
NAME CLUSTER-IP EXTERNAL-IP PORT(S) AGE
example-service 10.0.0.160 <pending> 8080/TCP 40s
1. Use your service to access the Hello World application:
curl <your-external-ip-address>:8080
where `<your-external-ip-address>` is the external IP address of your
service.
The output is a hello message from the application:
Hello Kubernetes!
Note: If you are using Minikube, enter these commands:
kubectl cluster-info
kubectl describe services example-service
The output displays the IP address of your Minikube node and the NodePort
value for your service. Enter this command to access the Hello World
application:
The output is similar to this:
curl <minikube-node-ip-address>:<service-node-port>
Name: example-service
Namespace: default
Labels: run=load-balancer-example
Selector: run=load-balancer-example
Type: NodePort
IP: 10.32.0.16
Port: <unset> 8080/TCP
NodePort: <unset> 31496/TCP
Endpoints: 10.200.1.4:8080,10.200.2.5:8080
Session Affinity: None
No events.
where `<minikube-node-ip-address>` us the IP address of your Minikube node,
and `<service-node-port>` is the NodePort value for your service.
Make a note of the NodePort value for the service. For example,
in the preceding output, the NodePort value is 31496.
1. List the pods that are running the Hello World application:
kubectl get pods --selector="run=load-balancer-example" --output=wide
The output is similar to this:
NAME READY STATUS ... IP NODE
hello-world-2895499144-bsbk5 1/1 Running ... 10.200.1.4 worker1
hello-world-2895499144-m1pwt 1/1 Running ... 10.200.2.5 worker2
1. Get the public IP address of one of your nodes that is running
a Hello World pod. How you get this address depends on how you set
up your cluster. For example, if you are using Minikube, you can
see the node address by running `kubectl cluster-info`. If you are
using Google Compute Engine instances, you can use the
`gcloud compute instances list` command to see the public addresses of your
nodes.
1. On your chosen node, create a firewall rule that allows TCP traffic
on your node port. For example, if your Service has a NodePort value of
31568, create a firewall rule that allows TCP traffic on port 31568.
1. Use the node address and node port to access the Hello World application:
curl http://<public-node-ip>:<node-port>
where `<public-node-ip>` us the public IP address of your node,
and `<node-port>` is the NodePort value for your service.
The response to a successful request is a hello message:
Hello Kubernetes!
### Using a service configuration file
+2 -1
View File
@@ -451,7 +451,8 @@ nginx-deployment-2035384211 0 0 1h
nginx-deployment-3066724191 0 0 1h
```
Note: A paused Deployment cannot be scaled at this moment, and we will add this feature in 1.3 release, see [issue #20853](https://github.com/kubernetes/kubernetes/issues/20853). You cannot rollback a paused Deployment either, and you should resume a Deployment first before doing a rollback.
Note: You cannot rollback a paused Deployment until you resume it.
## Use Cases
+2 -2
View File
@@ -89,5 +89,5 @@ Pods and containers
* [Images and registries](/docs/user-guide/images/)
* [Migrating from docker-cli to kubectl](/docs/user-guide/docker-cli-to-kubectl/)
* [Configuration Best Practices and Tips](/docs/user-guide/config-best-practices/)
* [Assign pods to selected nodes](https://github.com/kubernetes/kubernetes.github.io/tree/{{page.docsbranch}}/docs/user-guide/node-selection/)
* [Perform a rolling update on a running group of pods](https://github.com/kubernetes/kubernetes.github.io/tree/{{page.docsbranch}}/docs/user-guide/update-demo/)
* [Assign pods to selected nodes](/docs/user-guide/node-selection/)
* [Perform a rolling update on a running group of pods](/docs/user-guide/update-demo/)
+2 -1
View File
@@ -135,8 +135,9 @@ var kub = (function () {
// case 'caseStudies':
bodyHeight = windowHeight;
break;
case 'caseStudies':
case 'partners':
bodyHeight = windowHeight * 2;
break;
+60
View File
@@ -0,0 +1,60 @@
---
title: Partners
---
<!Doctype html>
<html id="partners" class="gridPage">
{% include head-header.html %}
<section id="hero" class="light-text">
<h1>Kubernetes Partners</h1>
<h5>Growing the Kubernetes ecosystem.</h5>
<!--<h5></h5>-->
</section>
<section id="users">
<main>
<h5>We are working with a broad group of partners who contribute to the Kubernetes core codebase, making it stronger and richer, creating a vibrant Kubernetes ecosystem supporting a spectrum of complementing platforms, from open source solutions to market-leading technologies.</h5>
<h3>ISV Partners</h3>
<div id="usersGrid">
<a target="_blank" href="https://coreos.com/kubernetes"><img src="/images/community_logos/core_os_logo.png"></a>
<a target="_blank" href="https://deis.com"><img src="/images/community_logos/deis_logo.png"></a>
<a target="_blank" href="https://sysdig.com/blog/monitoring-kubernetes-with-sysdig-cloud"><img src="/images/community_logos/sysdig_cloud_logo.png"></a>
<a target="_blank" href="https://puppet.com/blog/managing-kubernetes-configuration-puppet"><img src="/images/community_logos/puppet_logo.png"></a>
<a target="_blank" href="https://www.microloadbalancer.com/docs/deploy-netscaler-cpx-kubernetes-environment"><img src="/images/community_logos/citrix_logo.png"></a>
<a target="_blank" href="http://wercker.com/workflows/partners/kubernetes/"><img src="/images/community_logos/wercker_logo.png"></a>
<a target="_blank" href="http://rancher.com/kubernetes/"><img src="/images/community_logos/rancher_logo.png"></a>
<a target="_blank" href="https://www.openshift.com/"><img src="/images/community_logos/red_hat_logo.png"></a>
<a target="_blank" href="https://tectonic.com/press/intel-coreos-collaborate-on-openstack-with-kubernetes.html"><img src="/images/community_logos/intel_logo.png"></a>
<a target="_blank" href="https://elasticbox.com/kubernetes/"><img src="/images/community_logos/elastickube_logo.png"></a>
<a target="_blank" href="https://platform9.com/blog/containers-as-a-service-kubernetes-docker"><img src="/images/community_logos/platform9_logo.png"></a>
<a target="_blank" href="http://www.appformix.com/solutions/appformix-for-kubernetes/"><img src="/images/community_logos/appformix_logo.png"></a>
<a target="_blank" href="http://kubernetes.io/docs/getting-started-guides/dcos"><img src="/images/community_logos/mesosphere_logo.png"></a>
<a target="_blank" href="http://docs.datadoghq.com/integrations/kubernetes/"><img src="/images/community_logos/datadog_logo.png"></a>
<a target="_blank" href="https://apprenda.com/kubernetes-support/"><img src="/images/community_logos/apprenda_logo.png"></a>
<a target="_blank" href="http://www.ibm.com/cloud-computing/"><img src="/images/community_logos/ibm_logo.png"></a>
<a target="_blank" href="http://info.crunchydata.com/blog/advanced-crunchy-containers-for-postgresql"><img src="/images/community_logos/crunchy_data_logo.png"></a>
<a target="_blank" href="https://content.mirantis.com/Containerizing-OpenStack-on-Kubernetes-Video-Landing-Page.html"><img src="/images/community_logos/mirantis_logo.png"></a>
<a target="_blank" href="http://blog.aquasec.com/security-best-practices-for-kubernetes-deployment"><img src="/images/community_logos/aqua_logo.png"></a>
<a target="_blank" href="https://jujucharms.com/canonical-kubernetes/"><img src="/images/community_logos/ubuntu_cannonical_logo.png"></a>
</div>
</main>
</section>
<style>
h5 {
font-size: 18px;
line-height: 1.5em;
margin-bottom: 2em;
}
#usersGrid a {
display: inline-block;
background-color: #f9f9f9;
}
</style>
{% include footer.html %}
{% include case-study-styles.html %}
</body>
</html>