Merge remote-tracking branch 'upstream/main' into dev-1.24
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
title: Pod 安全策略
|
||||
id: pod-security-policy
|
||||
date: 2018-04-12
|
||||
full_link: /zh/docs/concepts/policy/pod-security-policy/
|
||||
full_link: /zh/docs/concepts/security/pod-security-policy/
|
||||
short_description: >
|
||||
为 Pod 的创建和更新操作启用细粒度的授权。
|
||||
|
||||
@@ -17,7 +17,7 @@ tags:
|
||||
title: Pod Security Policy
|
||||
id: pod-security-policy
|
||||
date: 2018-04-12
|
||||
full_link: /docs/concepts/policy/pod-security-policy/
|
||||
full_link: /docs/concepts/security/pod-security-policy/
|
||||
short_description: >
|
||||
Enables fine-grained authorization of pod creation and updates.
|
||||
|
||||
@@ -43,4 +43,9 @@ A cluster-level resource that controls security sensitive aspects of the Pod spe
|
||||
Pod 安全策略是集群级别的资源,它控制着 Pod 规约中的安全性敏感的内容。
|
||||
`PodSecurityPolicy`对象定义了一组条件以及相关字段的默认值,Pod 运行时必须满足这些条件。Pod 安全策略控制实现上体现为一个可选的准入控制器。
|
||||
|
||||
<!--
|
||||
PodSecurityPolicy is deprecated as of Kubernetes v1.21, and will be removed in v1.25. We recommend migrating to [Pod Security Admission](/docs/concepts/security/pod-security-admission/), or a 3rd party admission plugin.
|
||||
-->
|
||||
PodSecurityPolicy 自 Kubernetes v1.21 起已弃用,并将在 v1.25 中删除。
|
||||
我们建议迁移到 [Pod 安全准入](/zh/docs/concepts/security/pod-security-admission/)或第三方准入插件。
|
||||
|
||||
|
||||
@@ -88,7 +88,7 @@ that was transgressed as well as the specific policies on the fields that were
|
||||
violated from the PodSecurity enforcement.
|
||||
|
||||
See [Pod Security Standards](/docs/concepts/security/pod-security-standards/)
|
||||
for more information
|
||||
for more information.
|
||||
-->
|
||||
## pod-security.kubernetes.io/audit-violations {#pod-security-kubernetes-io-audit-violations}
|
||||
|
||||
@@ -99,4 +99,38 @@ PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container
|
||||
注解值给出审计策略违规的详细说明,它包含所违反的 [Pod 安全标准](/zh/docs/concepts/security/pod-security-standards/)级别以及
|
||||
PodSecurity 执行中违反的特定策略及对应字段。
|
||||
|
||||
有关详细信息,请参阅 [Pod 安全标准](/zh/docs/concepts/security/pod-security-standards/)。
|
||||
有关详细信息,请参阅 [Pod 安全标准](/zh/docs/concepts/security/pod-security-standards/)。
|
||||
|
||||
<!--
|
||||
## authorization.k8s.io/decision
|
||||
|
||||
Example: `authorization.k8s.io/decision: "forbid"`
|
||||
|
||||
This annotation indicates whether or not a request was authorized in Kubernetes audit logs.
|
||||
|
||||
See [Auditing](/docs/tasks/debug-application-cluster/audit/) for more information.
|
||||
-->
|
||||
## authorization.k8s.io/decision {#authorization-k8s-io-decision}
|
||||
|
||||
例子:`authorization.k8s.io/decision: "forbid"`
|
||||
|
||||
此注解在 Kubernetes 审计日志中表示请求是否获得授权。
|
||||
|
||||
有关详细信息,请参阅[审计](/zh/docs/tasks/debug-application-cluster/audit/)。
|
||||
|
||||
<!--
|
||||
## authorization.k8s.io/reason
|
||||
|
||||
Example: `authorization.k8s.io/reason: "Human-readable reason for the decision"`
|
||||
|
||||
This annotation gives reason for the [decision](#authorization-k8s-io-decision) in Kubernetes audit logs.
|
||||
|
||||
See [Auditing](/docs/tasks/debug-application-cluster/audit/) for more information.
|
||||
-->
|
||||
## authorization.k8s.io/reason {#authorization-k8s-io-reason}
|
||||
|
||||
例子:`authorization.k8s.io/reason: "Human-readable reason for the decision"`
|
||||
|
||||
此注解给出了 Kubernetes 审计日志中 [decision](#authorization-k8s-io-decision) 的原因。
|
||||
|
||||
有关详细信息,请参阅[审计](/zh/docs/tasks/debug-application-cluster/audit/)。
|
||||
@@ -1,8 +1,11 @@
|
||||
|
||||
<!--
|
||||
kubeadm: easily bootstrap a secure Kubernetes cluster
|
||||
|
||||
### Synopsis
|
||||
-->
|
||||
|
||||
kubeadm: 轻松创建一个安全的 Kubernetes 集群
|
||||
### 摘要
|
||||
|
||||
<!--
|
||||
@@ -90,9 +93,9 @@ Example usage:
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
help for kubeadm
|
||||
<p>help for kubeadm</p>
|
||||
-->
|
||||
kubeadm 操作的帮助信息
|
||||
<p>kubeadm 操作的帮助信息<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -102,9 +105,9 @@ kubeadm 操作的帮助信息
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
[EXPERIMENTAL] The path to the 'real' host root filesystem.
|
||||
<p>[EXPERIMENTAL] The path to the 'real' host root filesystem.</p>
|
||||
-->
|
||||
[实验] 指向 '真实' 宿主机根文件系统的路径。
|
||||
<p>[实验] 指向 '真实' 宿主机根文件系统的路径。<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
@@ -1,69 +0,0 @@
|
||||
|
||||
<!--
|
||||
### Synopsis
|
||||
-->
|
||||
|
||||
### 概要
|
||||
|
||||
<!--
|
||||
Kubeadm experimental sub-commands
|
||||
-->
|
||||
|
||||
kubeadm 实验子命令
|
||||
|
||||
<!--
|
||||
### Options
|
||||
-->
|
||||
|
||||
### 选项
|
||||
|
||||
<table style="width: 100%; table-layout: fixed;">
|
||||
<colgroup>
|
||||
<col span="1" style="width: 10px;" />
|
||||
<col span="1" />
|
||||
</colgroup>
|
||||
<tbody>
|
||||
|
||||
<tr>
|
||||
<td colspan="2">-h, --help</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
help for alpha
|
||||
-->
|
||||
alpha 操作的帮助命令
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<!--
|
||||
### Options inherited from parent commands
|
||||
-->
|
||||
|
||||
### 从父命令继承的选项
|
||||
|
||||
<table style="width: 100%; table-layout: fixed;">
|
||||
<colgroup>
|
||||
<col span="1" style="width: 10px;" />
|
||||
<col span="1" />
|
||||
</colgroup>
|
||||
<tbody>
|
||||
|
||||
<tr>
|
||||
<td colspan="2">--rootfs string</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
[EXPERIMENTAL] The path to the 'real' host root filesystem.
|
||||
-->
|
||||
[实验] 指向 '真实' 宿主机的根文件系统的路径。
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
@@ -1,3 +1,18 @@
|
||||
<!--
|
||||
The file is auto-generated from the Go source code of the component using a generic
|
||||
[generator](https://github.com/kubernetes-sigs/reference-docs/). To learn how
|
||||
to generate the reference documentation, please read
|
||||
[Contributing to the reference documentation](/docs/contribute/generate-ref-docs/).
|
||||
To update the reference conent, please follow the
|
||||
[Contributing upstream](/docs/contribute/generate-ref-docs/contribute-upstream/)
|
||||
guide. You can file document formatting bugs against the
|
||||
[reference-docs](https://github.com/kubernetes-sigs/reference-docs/) project.
|
||||
-->
|
||||
|
||||
<!--
|
||||
Commands related to handling kubernetes certificates
|
||||
-->
|
||||
处理 Kubernetes 证书的相关命令
|
||||
|
||||
<!--
|
||||
### Synopsis
|
||||
@@ -7,7 +22,7 @@
|
||||
<!--
|
||||
Commands related to handling kubernetes certificates
|
||||
-->
|
||||
与处理 kubernetes 证书相关的命令
|
||||
处理 Kubernetes 证书相关的命令
|
||||
|
||||
<!--
|
||||
### Options
|
||||
@@ -25,8 +40,8 @@ Commands related to handling kubernetes certificates
|
||||
<td colspan="2">-h, --help</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<!-- td></td><td style="line-height: 130%; word-wrap: break-word;">help for certs</td -->
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;"><!-- help for certs-->certs 命令的帮助</td>
|
||||
<!-- td></td><td style="line-height: 130%; word-wrap: break-word;"><p>help for certs</p></td -->
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;"><!-- help for certs--><p>certs 命令的帮助</p></td>
|
||||
</tr>
|
||||
|
||||
</tbody>
|
||||
@@ -48,8 +63,8 @@ Commands related to handling kubernetes certificates
|
||||
<td colspan="2">--rootfs string</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<!-- td></td><td style="line-height: 130%; word-wrap: break-word;">[EXPERIMENTAL] The path to the 'real' host root filesystem.</td -->
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">[实验] 到'真实'主机根文件系统的路径。</td>
|
||||
<!-- td></td><td style="line-height: 130%; word-wrap: break-word;"><p>[EXPERIMENTAL] The path to the 'real' host root filesystem.</p></td -->
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>[实验] 到'真实'主机根文件系统的路径。</p></td>
|
||||
</tr>
|
||||
|
||||
</tbody>
|
||||
|
||||
+19
@@ -1,3 +1,18 @@
|
||||
<!--
|
||||
The file is auto-generated from the Go source code of the component using a generic
|
||||
[generator](https://github.com/kubernetes-sigs/reference-docs/). To learn how
|
||||
to generate the reference documentation, please read
|
||||
[Contributing to the reference documentation](/docs/contribute/generate-ref-docs/).
|
||||
To update the reference conent, please follow the
|
||||
[Contributing upstream](/docs/contribute/generate-ref-docs/contribute-upstream/)
|
||||
guide. You can file document formatting bugs against the
|
||||
[reference-docs](https://github.com/kubernetes-sigs/reference-docs/) project.
|
||||
-->
|
||||
|
||||
<!--
|
||||
Generate certificate keys
|
||||
-->
|
||||
生成证书密钥
|
||||
|
||||
<!--
|
||||
### Synopsis
|
||||
@@ -37,10 +52,12 @@ kubeadm certs certificate-key [flags]
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<p>
|
||||
<!--
|
||||
help for certificate-key
|
||||
-->
|
||||
certificate-key 操作的帮助命令
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -64,10 +81,12 @@ certificate-key 操作的帮助命令
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<p>
|
||||
<!--
|
||||
[EXPERIMENTAL] The path to the 'real' host root filesystem.
|
||||
-->
|
||||
[实验] 到 '真实' 主机根文件系统的路径。
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
@@ -1,3 +1,18 @@
|
||||
<!--
|
||||
The file is auto-generated from the Go source code of the component using a generic
|
||||
[generator](https://github.com/kubernetes-sigs/reference-docs/). To learn how
|
||||
to generate the reference documentation, please read
|
||||
[Contributing to the reference documentation](/docs/contribute/generate-ref-docs/).
|
||||
To update the reference conent, please follow the
|
||||
[Contributing upstream](/docs/contribute/generate-ref-docs/contribute-upstream/)
|
||||
guide. You can file document formatting bugs against the
|
||||
[reference-docs](https://github.com/kubernetes-sigs/reference-docs/) project.
|
||||
-->
|
||||
|
||||
<!--
|
||||
Renew certificates for a Kubernetes cluster
|
||||
-->
|
||||
为 Kubernetes 集群更新证书
|
||||
|
||||
<!--
|
||||
### Synopsis
|
||||
@@ -30,10 +45,12 @@ kubeadm certs renew [flags]
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<p>
|
||||
<!--
|
||||
help for renew
|
||||
-->
|
||||
renew 操作的帮助命令
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -58,10 +75,12 @@ renew 操作的帮助命令
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<p>
|
||||
<!--
|
||||
[EXPERIMENTAL] The path to the 'real' host root filesystem.
|
||||
-->
|
||||
[实验] 到 '真实' 主机根文件系统的路径。
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
+12
-12
@@ -6,9 +6,9 @@
|
||||
|
||||
|
||||
<!--
|
||||
Generate the certificate for serving etcd, and save them into etcd/server.cert and etcd/server.key files.
|
||||
Generate the certificate for serving etcd, and save them into etcd/server.crt and etcd/server.key files.
|
||||
-->
|
||||
生成用于提供 etcd 服务的证书,并将其保存到 etcd/server.cert 和 etcd/server.key 文件中。
|
||||
生成用于提供 etcd 服务的证书,并将其保存到 etcd/server.crt 和 etcd/server.key 文件中。
|
||||
|
||||
<!--
|
||||
Default SANs are localhost, 127.0.0.1, 127.0.0.1, ::1
|
||||
@@ -52,9 +52,9 @@ kubeadm init phase certs etcd-server [flags]
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
The path where to save and store the certificates.
|
||||
<p>The path where to save and store the certificates.</p>
|
||||
-->
|
||||
保存和存储证书的路径。
|
||||
<p>保存和存储证书的路径。<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -64,9 +64,9 @@ The path where to save and store the certificates.
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
Path to kubeadm configuration file.
|
||||
<p>Path to a kubeadm configuration file.</p>
|
||||
-->
|
||||
kubeadm 配置文件的路径。
|
||||
<p>kubeadm 配置文件的路径。<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -76,9 +76,9 @@ kubeadm 配置文件的路径。
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
help for etcd-server
|
||||
<p>help for etcd-server</p>
|
||||
-->
|
||||
etcd-server 操作的帮助命令
|
||||
<p>etcd-server 操作的帮助命令<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -93,9 +93,9 @@ etcd-server 操作的帮助命令
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
Choose a specific Kubernetes version for the control plane.
|
||||
<p>Choose a specific Kubernetes version for the control plane.</p>
|
||||
-->
|
||||
为控制平面指定特定的 Kubernetes 版本。
|
||||
<p>为控制平面指定特定的 Kubernetes 版本。<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -122,9 +122,9 @@ Choose a specific Kubernetes version for the control plane.
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
[EXPERIMENTAL] The path to the 'real' host root filesystem.
|
||||
<p>[EXPERIMENTAL] The path to the 'real' host root filesystem.</p>
|
||||
-->
|
||||
[实验] 到 '真实' 主机根文件系统的路径。
|
||||
<p>[实验] 到 '真实' 主机根文件系统的路径。<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
@@ -1,3 +1,8 @@
|
||||
<!--
|
||||
Upgrade your cluster smoothly to a newer version with this command
|
||||
-->
|
||||
|
||||
此命令能将集群平滑升级到新版本
|
||||
|
||||
<!--
|
||||
### Synopsis
|
||||
@@ -34,9 +39,9 @@ kubeadm upgrade [flags]
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
help for upgrade
|
||||
<p>help for upgrade</p>
|
||||
-->
|
||||
upgrade 操作的帮助命令
|
||||
<p>upgrade 操作的帮助命令<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -62,9 +67,9 @@ upgrade 操作的帮助命令
|
||||
<tr>
|
||||
<td></td><td style="line-height: 130%; word-wrap: break-word;">
|
||||
<!--
|
||||
[EXPERIMENTAL] The path to the 'real' host root filesystem.
|
||||
<p>[EXPERIMENTAL] The path to the 'real' host root filesystem.</p>
|
||||
-->
|
||||
[实验] 指向 '真实' 宿主机根文件系统的路径。
|
||||
<p>[实验] 指向 '真实' 宿主机根文件系统的路径。<p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
@@ -67,8 +67,6 @@ For control-plane nodes additional steps are performed:
|
||||
1. Generating control-plane component manifests, certificates and kubeconfig.
|
||||
|
||||
1. Adding new local etcd member.
|
||||
|
||||
1. Adding this node to the ClusterStatus of the kubeadm cluster.
|
||||
-->
|
||||
对于控制平面节点,执行额外的步骤:
|
||||
|
||||
@@ -78,8 +76,6 @@ For control-plane nodes additional steps are performed:
|
||||
|
||||
1. 添加新的本地 etcd 成员。
|
||||
|
||||
1. 将此节点添加到 kubeadm 集群的 ClusterStatus。
|
||||
|
||||
<!--
|
||||
### Using join phases with kubeadm {#join-phases}
|
||||
-->
|
||||
@@ -123,6 +119,13 @@ For example:
|
||||
sudo kubeadm join --skip-phases=preflight --config=config.yaml
|
||||
```
|
||||
|
||||
{{< feature-state for_k8s_version="v1.22" state="beta" >}}
|
||||
|
||||
<!--
|
||||
Alternatively, you can use the `skipPhases` field in `JoinConfiguration`.
|
||||
-->
|
||||
或者,你可以使用 `JoinConfiguration` 中的 `skipPhases` 字段。
|
||||
|
||||
<!--
|
||||
### Discovering what cluster CA to trust
|
||||
-->
|
||||
@@ -523,11 +526,11 @@ the [kubeadm config migrate](/docs/reference/setup-tools/kubeadm/kubeadm-config/
|
||||
命令转换。
|
||||
|
||||
<!--
|
||||
For more information on the fields and usage of the configuration you can navigate to our API reference
|
||||
page and pick a version from [the list](https://godoc.org/k8s.io/kubernetes/cmd/kubeadm/app/apis/kubeadm#pkg-subdirectories).
|
||||
For more information on the fields and usage of the configuration you can navigate to our
|
||||
[API reference](/docs/reference/config-api/kubeadm-config.v1beta3/).
|
||||
-->
|
||||
有关配置的字段和用法的更多信息,你可以导航到我们的 API 参考页
|
||||
并从[列表]中选择一个版本(https://godoc.org/k8s.io/kubernetes/cmd/kubeadm/app/apis/kubeadm#pkg-subdirectories)。
|
||||
有关配置的字段和用法的更多信息,你可以导航到我们的
|
||||
[API 参考页](/zh/docs/reference/config-api/kubeadm-config.v1beta3/)。
|
||||
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
Reference in New Issue
Block a user