add feature state labels to admission controllers (#12689)

* add feature state labels to admission controllers

* Minor edits
This commit is contained in:
Zach Arnold
2019-03-11 17:32:38 -07:00
committed by Kubernetes Prow Robot
parent c319d0c501
commit 5e50314b27
@@ -97,9 +97,9 @@ NamespaceLifecycle,LimitRanger,ServiceAccount,PersistentVolumeClaimResize,Defaul
## What does each admission controller do? ## What does each admission controller do?
### AlwaysAdmit (DEPRECATED) {#alwaysadmit} ### AlwaysAdmit {#alwaysadmit} {{< feature-state for_k8s_version="v1.13" state="deprecated" >}}
Use this admission controller by itself to pass-through all requests. AlwaysAdmit is DEPRECATED as no real meaning. This admission controller allows all pods into the cluster. It is deprecated because its behavior is the same as if there were no admission controller at all.
### AlwaysPullImages {#alwayspullimages} ### AlwaysPullImages {#alwayspullimages}
@@ -111,7 +111,7 @@ scheduled onto the right node), without any authorization check against the imag
is enabled, images are always pulled prior to starting containers, which means valid credentials are is enabled, images are always pulled prior to starting containers, which means valid credentials are
required. required.
### AlwaysDeny (DEPRECATED) {#alwaysdeny} ### AlwaysDeny {#alwaysdeny} {{< feature-state for_k8s_version="v1.13" state="deprecated" >}}
Rejects all requests. AlwaysDeny is DEPRECATED as no real meaning. Rejects all requests. AlwaysDeny is DEPRECATED as no real meaning.
@@ -138,7 +138,7 @@ if the pods don't already have toleration for taints
`node.kubernetes.io/not-ready:NoExecute` or `node.kubernetes.io/not-ready:NoExecute` or
`node.alpha.kubernetes.io/unreachable:NoExecute`. `node.alpha.kubernetes.io/unreachable:NoExecute`.
### DenyExecOnPrivileged (deprecated) {#denyexeconprivileged} ### DenyExecOnPrivileged {#denyexeconprivileged} {{< feature-state for_k8s_version="v1.13" state="deprecated" >}}
This admission controller will intercept all requests to exec a command in a pod if that pod has a privileged container. This admission controller will intercept all requests to exec a command in a pod if that pod has a privileged container.
@@ -149,7 +149,7 @@ Use of a policy-based admission plugin (like [PodSecurityPolicy](#podsecuritypol
which can be targeted at specific users or Namespaces and also protects against creation of overly privileged Pods which can be targeted at specific users or Namespaces and also protects against creation of overly privileged Pods
is recommended instead. is recommended instead.
### DenyEscalatingExec (deprecated) {#denyescalatingexec} ### DenyEscalatingExec {#denyescalatingexec} {{< feature-state for_k8s_version="v1.13" state="deprecated" >}}
This admission controller will deny exec and attach commands to pods that run with escalated privileges that This admission controller will deny exec and attach commands to pods that run with escalated privileges that
allow host access. This includes pods that run as privileged, have access to the host IPC namespace, and allow host access. This includes pods that run as privileged, have access to the host IPC namespace, and
@@ -161,7 +161,7 @@ Use of a policy-based admission plugin (like [PodSecurityPolicy](#podsecuritypol
which can be targeted at specific users or Namespaces and also protects against creation of overly privileged Pods which can be targeted at specific users or Namespaces and also protects against creation of overly privileged Pods
is recommended instead. is recommended instead.
### EventRateLimit (alpha) {#eventratelimit} ### EventRateLimit {#eventratelimit} {{< feature-state for_k8s_version="v1.13" state="alpha" >}}
This admission controller mitigates the problem where the API server gets flooded by This admission controller mitigates the problem where the API server gets flooded by
event requests. The cluster admin can specify event rate limits by: event requests. The cluster admin can specify event rate limits by:
@@ -339,7 +339,7 @@ Examples of information you might put here are:
In any case, the annotations are provided by the user and are not validated by Kubernetes in any way. In the future, if an annotation is determined to be widely useful, it may be promoted to a named field of ImageReviewSpec. In any case, the annotations are provided by the user and are not validated by Kubernetes in any way. In the future, if an annotation is determined to be widely useful, it may be promoted to a named field of ImageReviewSpec.
### Initializers (alpha) {#initializers} ### Initializers {#initializers} {{< feature-state for_k8s_version="v1.13" state="alpha" >}}
The admission controller determines the initializers of a resource based on the existing The admission controller determines the initializers of a resource based on the existing
`InitializerConfiguration`s. It sets the pending initializers by modifying the `InitializerConfiguration`s. It sets the pending initializers by modifying the
@@ -361,7 +361,7 @@ applies a 0.1 CPU requirement to all Pods in the `default` namespace.
See the [limitRange design doc](https://git.k8s.io/community/contributors/design-proposals/resource-management/admission_control_limit_range.md) and the [example of Limit Range](/docs/tasks/configure-pod-container/limit-range/) for more details. See the [limitRange design doc](https://git.k8s.io/community/contributors/design-proposals/resource-management/admission_control_limit_range.md) and the [example of Limit Range](/docs/tasks/configure-pod-container/limit-range/) for more details.
### MutatingAdmissionWebhook (beta in 1.9) {#mutatingadmissionwebhook} ### MutatingAdmissionWebhook {#mutatingadmissionwebhook} {{< feature-state for_k8s_version="v1.13" state="beta" >}}
This admission controller calls any mutating webhooks which match the request. Matching This admission controller calls any mutating webhooks which match the request. Matching
webhooks are called in serial; each one may modify the object if it desires. webhooks are called in serial; each one may modify the object if it desires.
@@ -449,7 +449,7 @@ This admission controller also protects the access to `metadata.ownerReferences[
of an object, so that only users with "update" permission to the `finalizers` of an object, so that only users with "update" permission to the `finalizers`
subresource of the referenced *owner* can change it. subresource of the referenced *owner* can change it.
### PersistentVolumeLabel (DEPRECATED) {#persistentvolumelabel} ### PersistentVolumeLabel {#persistentvolumelabel} {{< feature-state for_k8s_version="v1.13" state="deprecated" >}}
This admission controller automatically attaches region or zone labels to PersistentVolumes This admission controller automatically attaches region or zone labels to PersistentVolumes
as defined by the cloud provider (for example, GCE or AWS). as defined by the cloud provider (for example, GCE or AWS).
@@ -610,7 +610,7 @@ We strongly recommend using this admission controller if you intend to make use
The `StorageObjectInUseProtection` plugin adds the `kubernetes.io/pvc-protection` or `kubernetes.io/pv-protection` finalizers to newly created Persistent Volume Claims (PVCs) or Persistent Volumes (PV). In case a user deletes a PVC or PV the PVC or PV is not removed until the finalizer is removed from the PVC or PV by PVC or PV Protection Controller. Refer to the [Storage Object in Use Protection](/docs/concepts/storage/persistent-volumes/#storage-object-in-use-protection) for more detailed information. The `StorageObjectInUseProtection` plugin adds the `kubernetes.io/pvc-protection` or `kubernetes.io/pv-protection` finalizers to newly created Persistent Volume Claims (PVCs) or Persistent Volumes (PV). In case a user deletes a PVC or PV the PVC or PV is not removed until the finalizer is removed from the PVC or PV by PVC or PV Protection Controller. Refer to the [Storage Object in Use Protection](/docs/concepts/storage/persistent-volumes/#storage-object-in-use-protection) for more detailed information.
### ValidatingAdmissionWebhook (alpha in 1.8; beta in 1.9) {#validatingadmissionwebhook} ### ValidatingAdmissionWebhook {#validatingadmissionwebhook} {{< feature-state for_k8s_version="v1.13" state="beta" >}}
This admission controller calls any validating webhooks which match the request. Matching This admission controller calls any validating webhooks which match the request. Matching
webhooks are called in parallel; if any of them rejects the request, the request webhooks are called in parallel; if any of them rejects the request, the request
@@ -658,27 +658,4 @@ in the mutating phase.
For earlier versions, there was no concept of validating vs mutating and the For earlier versions, there was no concept of validating vs mutating and the
admission controllers ran in the exact order specified. admission controllers ran in the exact order specified.
* v1.6 - v1.8
```shell
--admission-control=NamespaceLifecycle,LimitRanger,ServiceAccount,PersistentVolumeLabel,DefaultStorageClass,ResourceQuota,DefaultTolerationSeconds
```
* v1.4 - v1.5
```shell
--admission-control=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,ResourceQuota
```
* v1.2 - v1.3
```shell
--admission-control=NamespaceLifecycle,LimitRanger,ServiceAccount,ResourceQuota
```
* v1.0 - v1.1
```shell
--admission-control=NamespaceLifecycle,LimitRanger,SecurityContextDeny,ServiceAccount,PersistentVolumeLabel,ResourceQuota
```
{{% /capture %}} {{% /capture %}}