From 809c3cf9b546cd8284f3c002c45c244cc783ba83 Mon Sep 17 00:00:00 2001 From: steveperry-53 Date: Thu, 12 Jan 2017 16:29:19 -0800 Subject: [PATCH 1/9] Redirect User Guide topic: Working with Containers in Production. --- _data/guides.yml | 1 - docs/tasks/index.md | 3 + docs/user-guide/production-pods.md | 245 ----------------------------- 3 files changed, 3 insertions(+), 246 deletions(-) delete mode 100644 docs/user-guide/production-pods.md diff --git a/_data/guides.yml b/_data/guides.yml index 9d08a88367..c1bdd99a4e 100644 --- a/_data/guides.yml +++ b/_data/guides.yml @@ -71,7 +71,6 @@ toc: - docs/user-guide/pods/init-container.md - docs/user-guide/configuring-containers.md - docs/user-guide/pod-templates.md - - docs/user-guide/production-pods.md - docs/user-guide/containers.md - docs/user-guide/environment-guide/index.md - docs/user-guide/compute-resources.md diff --git a/docs/tasks/index.md b/docs/tasks/index.md index 2482a13677..92521ad0dd 100644 --- a/docs/tasks/index.md +++ b/docs/tasks/index.md @@ -1,5 +1,8 @@ --- title: Tasks +redirect_from: +- "/docs/user-guide/production-pods/" +- "/docs/user-guide/production-pods.html" --- This section of the Kubernetes documentation contains pages that diff --git a/docs/user-guide/production-pods.md b/docs/user-guide/production-pods.md deleted file mode 100644 index 586838f852..0000000000 --- a/docs/user-guide/production-pods.md +++ /dev/null @@ -1,245 +0,0 @@ ---- -assignees: -- bgrant0607 -- janetkuo -- thockin -title: Working with Containers in Production ---- - -You've seen [how to configure and deploy pods and containers](/docs/user-guide/configuring-containers), using some of the most common configuration parameters. This section dives into additional features that are especially useful for running applications in production. - -* TOC -{:toc} - -## Using a Volume for storage - -The container file system only lives as long as the container does, so when a container crashes and restarts, changes to the filesystem will be lost and the container will restart from a clean slate. For more consistent storage that lasts for the life of a Pod, you need a [*volume*](/docs/user-guide/volumes). This is especially important to stateful applications, such as key-value stores and databases. - -For example, [Redis](http://redis.io/) is a key-value cache and store, which we use in the [guestbook](https://github.com/kubernetes/kubernetes/tree/{{page.githubbranch}}/examples/guestbook/) and other examples. We can add a volume to it to store data as follows: - -{% include code.html language="yaml" file="redis-deployment.yaml" ghlink="/docs/user-guide/redis-deployment.yaml" %} - -`emptyDir` volumes live for the lifespan of the [pod](/docs/user-guide/pods), which is longer than the lifespan of any one container, so if the container fails and is restarted, our storage will live on. - -In addition to the local disk storage provided by `emptyDir`, Kubernetes supports many different network-attached storage solutions, including PD on GCE and EBS on EC2, which are preferred for critical data, and will handle details such as mounting and unmounting the devices on the nodes. See [the volumes doc](/docs/user-guide/volumes) for more details. - -## Distributing credentials - -Many applications need credentials, such as passwords, OAuth tokens, and TLS keys, to authenticate with other applications, databases, and services. Storing these credentials in container images or environment variables is less than ideal, since the credentials can then be copied by anyone with access to the image, pod/container specification, host file system, or host Docker daemon. - -Kubernetes provides a mechanism, called [*secrets*](/docs/user-guide/secrets), that facilitates delivery of sensitive credentials to applications. A `Secret` is a simple resource containing a map of data. For instance, you can create a simple secret with a username and password as follows: - -```shell -$ kubectl create secret generic mysecret --from-literal=username="admin",password="1234" -secret "mysecret" created -``` - -This is equivalent to `kubectl create -f`: - -```yaml -apiVersion: v1 -kind: Secret -metadata: - name: mysecret -type: Opaque -data: - username: YWRtaW4= - password: MTIzNA== -``` - -As with other resources, the created secret can be viewed with `get`: - -```shell -$ kubectl get secrets -NAME TYPE DATA AGE -default-token-zirbw kubernetes.io/service-account-token 3 3h -mysecret Opaque 2 2m -``` - -To use the secret, you need to reference it in a pod or pod template. The `secret` volume source enables you to mount it as an in-memory directory into your containers. - -{% include code.html language="yaml" file="redis-secret-deployment.yaml" ghlink="/docs/user-guide/redis-secret-deployment.yaml" %} - -For more details, see the [secrets document](/docs/user-guide/secrets), [example](/docs/user-guide/secrets/) and [design doc](https://github.com/kubernetes/kubernetes/blob/{{page.githubbranch}}/docs/design/secrets.md). - -## Authenticating with a private image registry - -Secrets can also be used to pass [image registry credentials](/docs/user-guide/images/#using-a-private-registry). - -The easiest way to create a secret for Docker registry is: - -```shell -$ kubectl create secret docker-registry myregistrykey --docker-username=janedoe --docker-password=●●●●●●●●●●● --docker-email=jdoe@example.com -secret "myregistrykey" created -``` - -Alternatively, you can do the equivalent with the following steps. First, create a `.docker/config.json`, such as by running `docker login `. -Then put the resulting `.docker/config.json` file into a [secret resource](secrets.md). For example: - -```shell -$ docker login -Username: janedoe -Password: ●●●●●●●●●●● -Email: jdoe@example.com -WARNING: login credentials saved in /Users/jdoe/.docker/config.json. -Login Succeeded - -$ echo $(cat ~/.docker/config.json) -{ "https://index.docker.io/v1/": { "auth": "ZmFrZXBhc3N3b3JkMTIK", "email": "jdoe@example.com" } } - -$ cat ~/.docker/config.json | base64 -eyAiaHR0cHM6Ly9pbmRleC5kb2NrZXIuaW8vdjEvIjogeyAiYXV0aCI6ICJabUZyWlhCaGMzTjNiM0prTVRJSyIsICJlbWFpbCI6ICJqZG9lQGV4YW1wbGUuY29tIiB9IH0K - -$ cat > /tmp/image-pull-secret.yaml < Date: Sun, 15 Jan 2017 23:09:45 +0800 Subject: [PATCH 2/9] fix the named anchor name anchor `loading-and-merging` should be `loading-and-merging-rules` --- docs/user-guide/kubeconfig-file.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/user-guide/kubeconfig-file.md b/docs/user-guide/kubeconfig-file.md index fd44eaf999..b4d7425127 100644 --- a/docs/user-guide/kubeconfig-file.md +++ b/docs/user-guide/kubeconfig-file.md @@ -16,7 +16,7 @@ So in order to easily switch between multiple clusters, for multiple users, a ku This file contains a series of authentication mechanisms and cluster connection information associated with nicknames. It also introduces the concept of a tuple of authentication information (user) and cluster connection information called a context that is also associated with a nickname. -Multiple kubeconfig files are allowed, if specified explicitly. At runtime they are loaded and merged along with override options specified from the command line (see [rules](#loading-and-merging) below). +Multiple kubeconfig files are allowed, if specified explicitly. At runtime they are loaded and merged along with override options specified from the command line (see [rules](#loading-and-merging-rules) below). ## Related discussion From ab7cbe3a49386987ed2ff56ffc1506bc909dfe9d Mon Sep 17 00:00:00 2001 From: Xing Zhou Date: Mon, 16 Jan 2017 11:03:01 +0800 Subject: [PATCH 3/9] Fixed Typo --- docs/api.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/api.md b/docs/api.md index cfc3c32125..7c6ae95e73 100644 --- a/docs/api.md +++ b/docs/api.md @@ -77,7 +77,7 @@ groups*](https://github.com/kubernetes/kubernetes/blob/{{page.githubbranch}}/doc same underlying resources. The API group is specified in a REST path and in the `apiVersion` field of a serialized object. -Currently there are two API groups in use: +Currently there are several API groups in use: 1. the "core" group, which is at REST path `/api/v1` and is not specified as part of the `apiVersion` field, e.g. `apiVersion: v1`. From 26385f0e46a85da5c8d3cc2f0e2a20f869d71484 Mon Sep 17 00:00:00 2001 From: steveperry-53 Date: Tue, 10 Jan 2017 15:49:33 -0800 Subject: [PATCH 4/9] Write new Task: Attaching Handlers to Container Lifecycle Events. --- _data/tasks.yml | 3 +- .../attach-handler-lifecycle-event.md | 72 +++++++++++++++++++ .../lifecycle-events.yaml | 33 +++++++++ docs/tasks/index.md | 1 + 4 files changed, 108 insertions(+), 1 deletion(-) create mode 100644 docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md create mode 100644 docs/tasks/configure-pod-container/lifecycle-events.yaml diff --git a/_data/tasks.yml b/_data/tasks.yml index 9605e925b0..13315bf5ed 100644 --- a/_data/tasks.yml +++ b/_data/tasks.yml @@ -13,7 +13,8 @@ toc: - docs/tasks/configure-pod-container/pull-image-private-registry.md - docs/tasks/configure-pod-container/configure-liveness-readiness-probes.md - docs/tasks/configure-pod-container/communicate-containers-same-pod.md - - docs/tasks/configure-pod-container/configure-pod-initialization.md + - docs/tasks/configure-pod-container/configure-pod-initialization.md + - docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md - title: Accessing Applications in a Cluster section: diff --git a/docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md b/docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md new file mode 100644 index 0000000000..e6492c7577 --- /dev/null +++ b/docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md @@ -0,0 +1,72 @@ +--- +title: Attaching Handlers to Container Lifecycle Events +--- + +{% capture overview %} + +This page shows how to attach handlers to Container lifecycle events. Kubernetes supports +the postStart event and the preStop event. Kubernetes sends the postStart event immediately +after a Container is started, and it sends the preStop event immediately before the +Container is terminated. + +{% endcapture %} + + +{% capture prerequisites %} + +{% include task-tutorial-prereqs.md %} + +{% endcapture %} + + +{% capture steps %} + +### Defining postStart and preStop handlers + +In this exercise, you create a Pod that has one Container. The Container has handlers +for the postStart and preStop events. + +Here is the configuration file for the Pod: + +{% include code.html language="yaml" file="lifecycle-events.yaml" ghlink="/docs/tasks/configure-pod-container/lifecycle-events.yaml" %} + +In the configuration file, you can see that the postStart command writes a `message` +file to the Container's `/usr/share` directory. The preStop command shuts down +nginx gracefully. This is helpful if the Container is being terminated because of a failure. + +Create the Pod: + + kubectl create -f http://k8s.io/docs/tasks/configure-pod-container/lifecycle-events.yaml + +Verify that the Container in the Pod is running: + + kubectl get pod lifecycle-demo + +Get a shell into the Container running in your Pod: + + kubectl exec -it lifecycle-demo -- /bin/bash + +In your shell, verify that the `postStart` handler created the `message` file: + + root@lifecycle-demo:/# cat /usr/share/message + +The output shows the text written by the postStart handler: + + Hello from the postStart handler + +{% endcapture %} + + +{% capture whatsnext %} + +* Learn more about [Container lifecycle hooks](/docs/user-guide/container-environment/.) +* Learn more about the [lifecycle of a Pod](https://kubernetes.io/docs/user-guide/pod-states/). + +#### Reference + +* [Lifecycle](https://kubernetes.io/docs/resources-reference/1_5/#lifecycle-v1) +* [Container](https://kubernetes.io/docs/resources-reference/1_5/#container-v1) + +{% endcapture %} + +{% include templates/task.md %} diff --git a/docs/tasks/configure-pod-container/lifecycle-events.yaml b/docs/tasks/configure-pod-container/lifecycle-events.yaml new file mode 100644 index 0000000000..c62028d7ef --- /dev/null +++ b/docs/tasks/configure-pod-container/lifecycle-events.yaml @@ -0,0 +1,33 @@ +apiVersion: v1 +kind: Pod +metadata: + name: lifecycle-demo +spec: + containers: + - name: lifecycle-demo-container + image: nginx + + lifecycle: + postStart: + exec: + command: ["/bin/sh", "-c", "echo Hello from the postStart handler > /usr/share/message"] + preStop: + exec: + command: ["/usr/sbin/nginx","-s","quit"] + + + + + + + + + + + + + + + + + diff --git a/docs/tasks/index.md b/docs/tasks/index.md index 2482a13677..b9d0284d5e 100644 --- a/docs/tasks/index.md +++ b/docs/tasks/index.md @@ -17,6 +17,7 @@ single thing, typically by giving a short sequence of steps. * [Configuring Liveness and Readiness Probes](/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/) * [Communicating Between Pods Running in the Same Container](/docs/tasks/configure-pod-container/communicate-containers-same-pod/) * [Configuring Pod Initialization](/docs/tasks/configure-pod-container/configure-pod-initialization/) +* [Attaching Handlers to Container Lifecycle Events](/docs/tasks/configure-pod-container/attach-handler-lifecycle-event/) #### Accessing Applications in a Cluster From 6a6028c72704842d43a4668530ad4f43e33d4ee8 Mon Sep 17 00:00:00 2001 From: steveperry-53 Date: Tue, 17 Jan 2017 12:40:55 -0800 Subject: [PATCH 5/9] Address reviewer comments. --- .../attach-handler-lifecycle-event.md | 26 +++++++++++++++++-- 1 file changed, 24 insertions(+), 2 deletions(-) diff --git a/docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md b/docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md index e6492c7577..715ea3effb 100644 --- a/docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md +++ b/docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md @@ -5,7 +5,7 @@ title: Attaching Handlers to Container Lifecycle Events {% capture overview %} This page shows how to attach handlers to Container lifecycle events. Kubernetes supports -the postStart event and the preStop event. Kubernetes sends the postStart event immediately +the postStart and preStop events. Kubernetes sends the postStart event immediately after a Container is started, and it sends the preStop event immediately before the Container is terminated. @@ -57,15 +57,37 @@ The output shows the text written by the postStart handler: {% endcapture %} + +{% capture discussion %} + +### Discussion + +Kubernetes sends the postStart event immediately after the Container is created. +There is no guarantee, however, that the postStart handler is called before +the Container's entrypoint is called. The postStart handler runs asynchronously +relative to the Container's code, but Kubernetes' management of the container +blocks until the postStart handler completes. The Container's status is not +set to RUNNING until the postStart handler completes. + +Kubernetes sends the preStop event immediately before the Container is terminated. +Kubernetes' management of the Container blocks until the preStop handler completes, +unless the Pod's grace period expires. For more details, see +[Termination of Pods](/docs/user-guide/pods/#termination-of-pods). + +{% endcapture %} + + {% capture whatsnext %} * Learn more about [Container lifecycle hooks](/docs/user-guide/container-environment/.) * Learn more about the [lifecycle of a Pod](https://kubernetes.io/docs/user-guide/pod-states/). -#### Reference +#### Reference + * [Lifecycle](https://kubernetes.io/docs/resources-reference/1_5/#lifecycle-v1) * [Container](https://kubernetes.io/docs/resources-reference/1_5/#container-v1) +* See `terminationGracePeriodSeconds` in [PodSpec](/docs/resources-reference/v1.5/#podspec-v1) {% endcapture %} From 8858b56753fab59c5f432ca4da837f682fe8e46a Mon Sep 17 00:00:00 2001 From: Nathan Quarles Date: Mon, 16 Jan 2017 09:38:07 -0500 Subject: [PATCH 6/9] grammar fix --- docs/tutorials/kubernetes-basics/explore-intro.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/tutorials/kubernetes-basics/explore-intro.html b/docs/tutorials/kubernetes-basics/explore-intro.html index e16d2a0755..5f5cb6354e 100644 --- a/docs/tutorials/kubernetes-basics/explore-intro.html +++ b/docs/tutorials/kubernetes-basics/explore-intro.html @@ -28,7 +28,7 @@ title: Viewing Pods and Nodes

Kubernetes Pods

-

When you created a Deployment in Module 2, Kubernetes created a Pod to host your application instance. A Pod is Kubernetes abstraction that represents a group of one or more application containers (such as Docker or rkt), and some shared resources for those containers. Those resources include:

+

When you created a Deployment in Module 2, Kubernetes created a Pod to host your application instance. A Pod is a Kubernetes abstraction that represents a group of one or more application containers (such as Docker or rkt), and some shared resources for those containers. Those resources include:

  • Shared storage, as Volumes
  • Networking, as a unique cluster IP address
  • From 2495fb890d6fa5346cfbd6230ba08abf579b80c9 Mon Sep 17 00:00:00 2001 From: Francesc Rosas Date: Tue, 17 Jan 2017 14:57:48 +0000 Subject: [PATCH 7/9] Fix jsonpath --- docs/getting-started-guides/minikube.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/getting-started-guides/minikube.md b/docs/getting-started-guides/minikube.md index 65b7893be5..731ad1c9a4 100644 --- a/docs/getting-started-guides/minikube.md +++ b/docs/getting-started-guides/minikube.md @@ -225,7 +225,7 @@ Any services of type `NodePort` can be accessed over that IP address, on the Nod To determine the NodePort for your service, you can use a `kubectl` command like this: -`kubectl get service $SERVICE --output='jsonpath="{.spec.ports[0].NodePort}"'` +`kubectl get service $SERVICE --output='jsonpath="{.spec.ports[0].nodePort}"'` ## Persistent Volumes Minikube supports [PersistentVolumes](http://kubernetes.io/docs/user-guide/persistent-volumes/) of type `hostPath`. From 4a33f4f44c2648806ca77e60012c970d9968d607 Mon Sep 17 00:00:00 2001 From: Janet Kuo Date: Tue, 17 Jan 2017 15:16:27 -0800 Subject: [PATCH 8/9] Fix travis failure by bumping go version to 1.7.3 --- .travis.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.travis.yml b/.travis.yml index 33db17d9e7..791d289e88 100644 --- a/.travis.yml +++ b/.travis.yml @@ -1,6 +1,6 @@ language: go go: - - 1.6.2 + - 1.7.3 # Don't want default ./... here: install: From 705f74fad0b6b69ed9dc693ba484e378d50f71c7 Mon Sep 17 00:00:00 2001 From: Michael Mrowetz Date: Fri, 13 Jan 2017 17:16:16 +0900 Subject: [PATCH 9/9] de-duplicated sentence. --- docs/admin/salt.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/admin/salt.md b/docs/admin/salt.md index d2479ffff2..ab495521bd 100644 --- a/docs/admin/salt.md +++ b/docs/admin/salt.md @@ -6,7 +6,7 @@ title: Configuring Kubernetes with Salt The Kubernetes cluster can be configured using Salt. -The Salt scripts are shared across multiple hosting providers, so it's important to understand some background information prior to making a modification to ensure your changes do not break hosting Kubernetes across multiple environments. Depending on where you host your Kubernetes cluster, you may be using different operating systems and different networking configurations. As a result, it's important to understand some background information before making Salt changes in order to minimize introducing failures for other hosting providers. +The Salt scripts are shared across multiple hosting providers and depending on where you host your Kubernetes cluster, you may be using different operating systems and different networking configurations. As a result, it's important to understand some background information before making Salt changes in order to minimize introducing failures for other hosting providers. ## Salt cluster setup