zh-trans website/content/zh/docs/concepts/containers/runtime-class.md (#11744)
* zh-trans website/content/zh/docs/concepts/containers/runtime-class.md 根据更新后的英文重新进行了翻译,同时修改了部分译文让阅读更流畅 * zh-trans website/content/zh/docs/concepts/containers/runtime-class.md 重新修改了部分格式,并根据英文补充的原文进行翻译,让中文阅读更为流畅 * Update runtime-class.md
This commit is contained in:
@@ -2,26 +2,19 @@
|
|||||||
reviewers:
|
reviewers:
|
||||||
- tallclair
|
- tallclair
|
||||||
- dchen1107
|
- dchen1107
|
||||||
title: Runtime Class
|
title: RuntimeClass
|
||||||
content_template: templates/concept
|
content_template: templates/concept
|
||||||
weight: 20
|
weight: 20
|
||||||
---
|
---
|
||||||
|
|
||||||
<!-- ---
|
|
||||||
reviewers:
|
|
||||||
- tallclair
|
|
||||||
- dchen1107
|
|
||||||
title: Runtime Class
|
|
||||||
content_template: templates/concept
|
|
||||||
weight: 20
|
|
||||||
--- -->
|
|
||||||
|
|
||||||
{{% capture overview %}}
|
{{% capture overview %}}
|
||||||
|
|
||||||
{{< feature-state for_k8s_version="v1.12" state="alpha" >}}
|
{{< feature-state for_k8s_version="v1.12" state="alpha" >}}
|
||||||
|
|
||||||
<!-- This page describes the RuntimeClass resource and runtime selection mechanism. -->
|
<!--
|
||||||
本页面讨论的是 RuntimeClass 资源和运行时选择的机制问题。
|
This page describes the RuntimeClass resource and runtime selection mechanism.
|
||||||
|
-->
|
||||||
|
本页面讨论了 RuntimeClass 资源和运行时的选择机制。
|
||||||
|
|
||||||
{{% /capture %}}
|
{{% /capture %}}
|
||||||
|
|
||||||
@@ -29,131 +22,151 @@ weight: 20
|
|||||||
|
|
||||||
{{% capture body %}}
|
{{% capture body %}}
|
||||||
|
|
||||||
<!-- ## Runtime Class -->
|
|
||||||
## RuntimeClass
|
## RuntimeClass
|
||||||
|
|
||||||
<!-- RuntimeClass is an alpha feature for selecting the container runtime configuration to use to run a
|
<!--
|
||||||
pod's containers. -->
|
RuntimeClass is an alpha feature for selecting the container runtime configuration to use to run a
|
||||||
RuntimeClass 是一个 alpha 功能,用来选择容器运行时,运行 pod 的容器。
|
pod's containers.
|
||||||
|
-->
|
||||||
|
RuntimeClass 是一个 alpha 功能,用来选择运行 pod 中容器的容器运行时配置。
|
||||||
|
|
||||||
<!-- ### Set Up -->
|
<!--
|
||||||
|
### Set Up
|
||||||
|
-->
|
||||||
### 设置
|
### 设置
|
||||||
|
|
||||||
<!-- As an early alpha feature, there are some additional setup steps that must be taken in order to use
|
<!--
|
||||||
the RuntimeClass feature: -->
|
As an early alpha feature, there are some additional setup steps that must be taken in order to use
|
||||||
作为一个 alpha 功能,必须要完成以下设置步骤才能使用 RuntimeClass 功能:
|
the RuntimeClass feature:
|
||||||
|
-->
|
||||||
|
作为一个处于早期状态的 alpha 特性,必须要完成以下步骤才能使用 RuntimeClass 功能:
|
||||||
|
|
||||||
<!-- 1. Enable the RuntimeClass feature gate (on apiservers & kubelets, requires version 1.12+)
|
<!--
|
||||||
|
1. Enable the RuntimeClass feature gate (on apiservers & kubelets, requires version 1.12+)
|
||||||
2. Install the RuntimeClass CRD
|
2. Install the RuntimeClass CRD
|
||||||
3. Configure the CRI implementation on nodes (runtime dependent)
|
3. Configure the CRI implementation on nodes (runtime dependent)
|
||||||
4. Create the corresponding RuntimeClass resources -->
|
4. Create the corresponding RuntimeClass resources
|
||||||
|
-->
|
||||||
1. 开启 RuntimeClass 功能门(feature gate) (在 apiservers 和 kubelets 上,需要版本号 1.12 以上)
|
1. 开启 RuntimeClass 特性门控(在 apiservers & kubelets 上,需要 1.12 及以上版本)
|
||||||
2. 安装 RuntimeClass CRD
|
2. 安装 RuntimeClass CRD
|
||||||
3. 在节点上配置 CRI 实现(运行时依赖)
|
3. 在节点上配置 CRI 的实现(取决于所选的运行时)
|
||||||
4. 创建相应的 RuntimeClass 资源
|
4. 创建相应的 RuntimeClass 资源
|
||||||
|
|
||||||
|
<!--
|
||||||
|
#### 1. Enable the RuntimeClass feature gate
|
||||||
|
-->
|
||||||
|
#### 1. 开启 RuntimeClass 特性门控
|
||||||
|
|
||||||
<!-- #### 1. Enable the RuntimeClass feature gate -->
|
<!--
|
||||||
#### 1. 开启 RuntimeClass 功能门
|
See [Feature Gates](/docs/reference/command-line-tools-reference/feature-gates/) for an explanation
|
||||||
|
of enabling feature gates. The RuntimeClass feature gate must be enabled on apiservers _and_ kubelets.
|
||||||
|
-->
|
||||||
|
参见[特性门控](/docs/reference/command-line-tools-reference/feature-gates/)文档了解如何开启特定的特性门控。
|
||||||
|
`RuntimeClass` 特性门控必须在 apiservers _和_ kubelets 上同时开启,才能使用。
|
||||||
|
|
||||||
<!-- See [Feature Gates](/docs/reference/command-line-tools-reference/feature-gates/) for an explanation
|
<!--
|
||||||
of enabling feature gates. The `RuntimeClass` feature gate must be enabled on apiservers _and_
|
#### 2. Install the RuntimeClass CRD
|
||||||
kubelets. -->
|
-->
|
||||||
|
|
||||||
参见[功能门](/docs/reference/command-line-tools-reference/feature-gates/),了解如何开启功能门。
|
|
||||||
`RuntimeClass` 功能门必须要在 apiservers _和_ kubelets 上同时开启,才能使用。
|
|
||||||
|
|
||||||
<!-- #### 2. Install the RuntimeClass CRD -->
|
|
||||||
#### 2. 安装 RuntimeClass CRD
|
#### 2. 安装 RuntimeClass CRD
|
||||||
|
|
||||||
<!-- The RuntimeClass [CustomResourceDefinition][/docs/tasks/access-kubernetes-api/custom-resources/custom-resource-definitions/] (CRD) can be found in the addons directory of the
|
<!--
|
||||||
Kubernetes git repo: -->
|
The RuntimeClass [CustomResourceDefinition][/docs/tasks/access-kubernetes-api/custom-resources/custom-resource-definitions/] (CRD) can be found in the addons directory of the
|
||||||
|
Kubernetes git repo:
|
||||||
RuntimeClass [CustomResourceDefinition][/docs/tasks/access-kubernetes-api/custom-resources/custom-resource-definitions/] (CRD)
|
-->
|
||||||
可以在 Kubernetes git 仓库下的 addons 路径下找到:
|
可以在 Kubernetes git 仓库的 addons 目录中找到
|
||||||
|
RuntimeClass [CustomResourceDefinition (CRD)](/docs/tasks/access-kubernetes-api/custom-resources/custom-resource-definitions/) 的定义:
|
||||||
|
|
||||||
https://github.com/kubernetes/kubernetes/tree/release-1.12/cluster/addons/runtimeclass/runtimeclass_crd.yaml
|
https://github.com/kubernetes/kubernetes/tree/release-1.12/cluster/addons/runtimeclass/runtimeclass_crd.yaml
|
||||||
|
|
||||||
<!-- Install the CRD with `kubectl apply -f runtimeclass_crd.yaml`. -->
|
<!--
|
||||||
安装 CRD 只需要 `kubectl apply -f runtimeclass_crd.yaml` 一条命令。
|
Install the CRD with `kubectl apply -f runtimeclass_crd.yaml`.
|
||||||
|
-->
|
||||||
|
|
||||||
[CustomResourceDefinition][/docs/tasks/access-kubernetes-api/custom-resources/custom-resource-definitions/]
|
使用 `kubectl apply -f runtimeclass_crd.yaml` 命令安装 CRD。
|
||||||
|
|
||||||
<!-- #### 3. Configure the CRI implementation on nodes -->
|
<!--
|
||||||
|
#### 3. Configure the CRI implementation on nodes
|
||||||
|
-->
|
||||||
#### 3. 在节点上配置 CRI 实现
|
#### 3. 在节点上配置 CRI 实现
|
||||||
|
|
||||||
<!-- The configurations to select between with RuntimeClass are CRI implementation dependent. See the
|
<!--
|
||||||
|
The configurations to select between with RuntimeClass are CRI implementation dependent. See the
|
||||||
corresponding documentation for your CRI implementation for how to configure. As this is an alpha
|
corresponding documentation for your CRI implementation for how to configure. As this is an alpha
|
||||||
feature, not all CRIs support multiple RuntimeClasses yet. -->
|
feature, not all CRIs support multiple RuntimeClasses yet.
|
||||||
|
-->
|
||||||
|
各 RuntimeClass 所支持的配置选项取决于 CRI 的实现本身。
|
||||||
|
请参阅 CRI 实现的相应文档了解具体如何配置。
|
||||||
|
由于这是一个 alpha 特性功能,并非所有 CRI 都支持多个 RuntimeClass。
|
||||||
|
|
||||||
和 RuntimeClass 的相关配置都和 CRI 的实现有关。参见 CRI 实现的相关文档,了解如何进行配置。
|
<!--
|
||||||
由于这是 alpha 功能,并不是所有的 CRI 都能支持多个 RuntimeClass。
|
RuntimeClass currently assumes a homogeneous node configuration across the cluster
|
||||||
|
|
||||||
{{< note >}}
|
|
||||||
<!-- **Note:** RuntimeClass currently assumes a homogeneous node configuration across the cluster
|
|
||||||
(which means that all nodes are configured the same way with respect to container runtimes). Any heterogeneity (varying configurations) must be
|
(which means that all nodes are configured the same way with respect to container runtimes). Any heterogeneity (varying configurations) must be
|
||||||
managed independently of RuntimeClass through scheduling features (see [Assigning Pods to
|
managed independently of RuntimeClass through scheduling features
|
||||||
Nodes](/docs/concepts/configuration/assign-pod-node/)). -->
|
(see [Assigning Pods to Nodes](/docs/concepts/configuration/assign-pod-node/)).
|
||||||
|
-->
|
||||||
**注意:** RuntimeClass 当前假设的是集群中的节点配置是同构的(换言之,所有的节点在容器运行时方面的配置是相同的)。
|
{{< note >}}
|
||||||
任何异构(不同的配置)必须要通过调度功能,在 RuntimeClass 之外单独管理
|
RuntimeClass 当前假设的是集群中的节点配置是同构的(换言之,所有的节点在容器运行时方面的配置是相同的)。
|
||||||
(参见 [在节点上分配 Pods](/docs/concepts/configuration/assign-pod-node/))。
|
任何异构性(不同的配置)必须通过调度功能在 RuntimeClass 之外单独管理(请参阅[在节点上分配 Pods](/docs/concepts/configuration/assign-pod-node/))。
|
||||||
|
|
||||||
{{< /note >}}
|
{{< /note >}}
|
||||||
|
|
||||||
<!-- The configurations have a corresponding `RuntimeHandler` name, referenced by the RuntimeClass. The
|
<!--
|
||||||
RuntimeHandler must be a valid DNS 1123 subdomain (alpha-numeric + `-` and `.` characters). -->
|
The configurations have a corresponding `RuntimeHandler` name, referenced by the RuntimeClass. The
|
||||||
|
RuntimeHandler must be a valid DNS-1123 subdomain (alpha-numeric characters, `-`, or `.`).
|
||||||
|
-->
|
||||||
|
所有这些配置都具有相应的 `RuntimeHandler` 名,并被 RuntimeClass 引用。
|
||||||
|
RuntimeHandler 必须是有效的 DNS-1123 子域(字母数字字符、`-` 或 `.`)。
|
||||||
|
|
||||||
所有的配置都有相应的 `RuntimeHandler` 名,被 RuntimeClass 引用。
|
<!--
|
||||||
RuntimeHandler 的名字必须是合法的 DNS 1123 子域名 (alpha-numeric `+` `-` and `.` characters)
|
#### 4. Create the corresponding RuntimeClass resources
|
||||||
|
-->
|
||||||
|
|
||||||
<!-- #### 4. Create the corresponding RuntimeClass resources -->
|
|
||||||
#### 4. 创建相应的 RuntimeClass 资源
|
#### 4. 创建相应的 RuntimeClass 资源
|
||||||
|
|
||||||
<!-- The configurations setup in step 3 should each have an associated `RuntimeHandler` name, which
|
<!--
|
||||||
|
The configurations setup in step 3 should each have an associated `RuntimeHandler` name, which
|
||||||
identifies the configuration. For each RuntimeHandler (and optionally the empty `""` handler),
|
identifies the configuration. For each RuntimeHandler (and optionally the empty `""` handler),
|
||||||
create a corresponding RuntimeClass object. -->
|
create a corresponding RuntimeClass object
|
||||||
|
.-->
|
||||||
|
步骤 3 中的配置设置应该有相应的 `RuntimeHandler` 名,用于标识配置。
|
||||||
|
对应每个 RuntimeHandler(以及 `""` 所代表的空处理程序),都创建相应的 RuntimeClass 对象。
|
||||||
|
|
||||||
步骤3中的配置设置应该有相应的 `RuntimeHandler` 名,用来标识配置。
|
<!--The RuntimeClass resource currently only has 2 significant fields: the RuntimeClass name
|
||||||
对应每个 RuntimeHandler (或者空 `""` handler),创建相应的 RuntimeClass 对象。
|
(`metadata.name`) and the RuntimeHandler (`spec.runtimeHandler`). The object definition looks like this:
|
||||||
|
-->
|
||||||
<!-- The RuntimeClass resource currently only has 2 significant fields: the RuntimeClass name
|
RuntimeClass 资源当前只有两个重要的字段:RuntimeClass 名 (`metadata.name`) 和 RuntimeHandler (`spec.runtimeHandler`)。
|
||||||
(`metadata.name`) and the RuntimeHandler (`spec.runtimeHandler`). The object definition looks like this: -->
|
|
||||||
|
|
||||||
RuntimeClass 资源当前只有两个重要的域:RuntimeClass 名 (`metadata.name`) 和 RuntimeHandler (`spec.runtimeHandler`)。
|
|
||||||
对象定义如下所示:
|
对象定义如下所示:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: node.k8s.io/v1alpha1 # RuntimeClass is defined in the node.k8s.io API group
|
apiVersion: node.k8s.io/v1alpha1 # 在 node.k8s.io API 中对 RuntimeClass 进行定义
|
||||||
kind: RuntimeClass
|
kind: RuntimeClass
|
||||||
metadata:
|
metadata:
|
||||||
name: myclass # The name the RuntimeClass will be referenced by
|
name: myclass # 引用 RuntimeClass
|
||||||
# RuntimeClass is a non-namespaced resource
|
# RuntimeClass 是不属于任何名字空间的资源
|
||||||
spec:
|
spec:
|
||||||
runtimeHandler: myconfiguration # The name of the correpsonding CRI configuration
|
runtimeHandler: myconfiguration # 给出 CRI 配置的名称
|
||||||
```
|
```
|
||||||
|
|
||||||
|
<!--
|
||||||
|
It is recommended that RuntimeClass write operations (create/update/patch/delete) be
|
||||||
|
restricted to the cluster administrator. This is typically the default. See [Authorization
|
||||||
|
Overview](https://kubernetes.io/docs/reference/access-authn-authz/authorization/) for more details.
|
||||||
|
-->
|
||||||
|
|
||||||
{{< note >}}
|
{{< note >}}
|
||||||
|
建议将 RuntimeClass 写操作(create、update、patch 和 delete)限定于集群管理员使用。
|
||||||
<!-- **Note:** It is recommended that RuntimeClass write operations (create/update/patch/delete) be
|
通常这是默认配置。参阅[授权概述](https://kubernetes.io/docs/reference/access-authn-authz/authorization/)了解更多信息。
|
||||||
restricted to the cluster administrator. This is typically the default. See [Authorization
|
|
||||||
Overview](https://kubernetes.io/docs/reference/access-authn-authz/authorization/) for more details. -->
|
|
||||||
|
|
||||||
**注意:**:通常推荐的是 RuntimeClass 写操作 (create/update/patch/delete)应仅限于集群管理员使用。
|
|
||||||
这也是默认配置。更多细节,参见 [授权概览](https://kubernetes.io/docs/reference/access-authn-authz/authorization/)。
|
|
||||||
|
|
||||||
{{< /note >}}
|
{{< /note >}}
|
||||||
|
|
||||||
<!-- ### Usage -->
|
<!--
|
||||||
### 使用
|
### Usage
|
||||||
|
Once RuntimeClasses are configured for the cluster, using them is very simple. Specify a
|
||||||
|
`runtimeClassName` in the Pod spec. For example:
|
||||||
|
-->
|
||||||
|
|
||||||
<!-- Once RuntimeClasses are configured for the cluster, using them is very simple. Specify a
|
### 使用说明
|
||||||
`runtimeClassName` in the Pod spec. For example: -->
|
|
||||||
|
|
||||||
一旦完成集群中 RuntimeClasses 的配置,使用起来非常简便。
|
一旦完成集群中 RuntimeClasses 的配置,使用起来非常简便。
|
||||||
在 Pod spec 中声明所需的 `runtimeClassName` 即可。例如:
|
在 Pod spec 中指定 `runtimeClassName` 即可。例如:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
@@ -165,19 +178,20 @@ spec:
|
|||||||
# ...
|
# ...
|
||||||
```
|
```
|
||||||
|
|
||||||
<!-- This will instruct the Kubelet to use the named RuntimeClass to run this pod. If the named
|
<!--This will instruct the Kubelet to use the named RuntimeClass to run this pod. If the named
|
||||||
RuntimeClass does not exist, or the CRI cannot run the corresponding handler, the pod will enter the
|
RuntimeClass does not exist, or the CRI cannot run the corresponding handler, the pod will enter the
|
||||||
`Failed` terminal [phase](/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase). Look for a
|
`Failed` terminal [phase](/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase). Look for a
|
||||||
corresponding [event](/docs/tasks/debug-application-cluster/debug-application-introspection/) for an
|
corresponding [event](/docs/tasks/debug-application-cluster/debug-application-introspection/) for an
|
||||||
error message. -->
|
error message.-->
|
||||||
|
|
||||||
这会告诉 Kubelet 使用命名的 RuntimeClass 来运行这个 pod。如果命名的 RuntimeClass 不存在,
|
这一设置会告诉 Kubelet 使用所指的 RuntimeClass 来运行该 pod。
|
||||||
或者 CRI 无法运行相应的 handler,那么 pod 将会进入 `Failed` 终端 [阶段](/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase)。
|
如果所指的 RuntimeClass 不存在或者 CRI 无法运行相应的 handler,那么 pod 将会进入 `Failed` 终止[阶段](/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase)。
|
||||||
查看相应的 [事件](/docs/tasks/debug-application-cluster/debug-application-introspection/),获取错误信息。
|
你可以查看相应的[事件](/docs/tasks/debug-application-cluster/debug-application-introspection/),获取出错信息。
|
||||||
|
|
||||||
<!-- If no `runtimeClassName` is specified, the default RuntimeHandler will be used, which is equivalent
|
<!--
|
||||||
to the behavior when the RuntimeClass feature is disabled. -->
|
If no `runtimeClassName` is specified, the default RuntimeHandler will be used, which is equivalent
|
||||||
|
to the behavior when the RuntimeClass feature is disabled.
|
||||||
如果没有指明 `runtimeClassName`,将会使用默认的 RuntimeHandler,等效于 RuntimeClass 功能被禁用。
|
-->
|
||||||
|
如果未指定 `runtimeClassName` ,则将使用默认的 RuntimeHandler,相当于禁用 RuntimeClass 功能特性。
|
||||||
|
|
||||||
{{% /capture %}}
|
{{% /capture %}}
|
||||||
|
|||||||
Reference in New Issue
Block a user