Fix typos and add a paragraph for initializers doc (#4369)
* Fix typos and add a paragraph for initializers doc - Fixed a few consistency issues and typos in the doc - Also fixed an username typo in assignees - Added a paragraph explaining how the example initializerconfiguration will be applied once it is created. Signed-off-by: Ahmet Alp Balkan <ahmetb@google.com> * Add .pending to metadata.initializers, re-wording Signed-off-by: Ahmet Alp Balkan <ahmetb@google.com>
This commit is contained in:
committed by
Andrew Chen
parent
11238eea0e
commit
acef396611
@@ -3,7 +3,7 @@ assignees:
|
|||||||
- smarterclayton
|
- smarterclayton
|
||||||
- lavalamp
|
- lavalamp
|
||||||
- whitlockjc
|
- whitlockjc
|
||||||
- caesrxuchao
|
- caesarxuchao
|
||||||
title: Dynamic Admission Control
|
title: Dynamic Admission Control
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -41,7 +41,7 @@ This page describes how to use Initializers and External Admission Webhooks.
|
|||||||
|
|
||||||
Once the controller has performed its assigned task, it removes its name from
|
Once the controller has performed its assigned task, it removes its name from
|
||||||
the list. For example, it may send a PATCH that inserts a container in a pod and
|
the list. For example, it may send a PATCH that inserts a container in a pod and
|
||||||
also removes its name from `metadata.initializers`. Initializers may make
|
also removes its name from `metadata.initializers.pending`. Initializers may make
|
||||||
mutations to objects.
|
mutations to objects.
|
||||||
|
|
||||||
Objects which have a non-empty initializer list are considered uninitialized,
|
Objects which have a non-empty initializer list are considered uninitialized,
|
||||||
@@ -64,7 +64,7 @@ external admission webhooks, as they have better performance.
|
|||||||
When an object is POSTed, it is checked against all existing
|
When an object is POSTed, it is checked against all existing
|
||||||
`initializerConfiguration` objects (explained below). For all that it matches,
|
`initializerConfiguration` objects (explained below). For all that it matches,
|
||||||
all `spec.initializers[].name`s are appended to the new object's
|
all `spec.initializers[].name`s are appended to the new object's
|
||||||
`metadata.initializers` field.
|
`metadata.initializers.pending` field.
|
||||||
|
|
||||||
An initializer controller should list and watch for uninitialized objects, by
|
An initializer controller should list and watch for uninitialized objects, by
|
||||||
using the query parameter `?includeUninitialized=true`. If using client-go, just
|
using the query parameter `?includeUninitialized=true`. If using client-go, just
|
||||||
@@ -73,7 +73,7 @@ set
|
|||||||
to true.
|
to true.
|
||||||
|
|
||||||
For the observed uninitialized objects, an initializer controller should first
|
For the observed uninitialized objects, an initializer controller should first
|
||||||
check if its name matches `metadata.initializers[0]`. If so, it should then
|
check if its name matches `metadata.initializers.pending[0]`. If so, it should then
|
||||||
perform its assigned task and remove its name from the list.
|
perform its assigned task and remove its name from the list.
|
||||||
|
|
||||||
### Enable initializers alpha feature
|
### Enable initializers alpha feature
|
||||||
@@ -99,13 +99,13 @@ API](/docs/api-reference/{{page.version}}/#deployment-v1beta1-apps).
|
|||||||
### Configure initializers on the fly
|
### Configure initializers on the fly
|
||||||
|
|
||||||
You can configure what initializers are enabled and what resources are subject
|
You can configure what initializers are enabled and what resources are subject
|
||||||
to the initializers by creating `initializerconfigurations`.
|
to the initializers by creating `initializerConfiguration` resources.
|
||||||
|
|
||||||
You should first deploy the initializer controller and make sure that it is
|
You should first deploy the initializer controller and make sure that it is
|
||||||
working properly before creating the `initializerconfigurations`. Otherwise, any
|
working properly before creating the `initializerConfiguration`. Otherwise, any
|
||||||
newly created resources will be stuck in an uninitialized state.
|
newly created resources will be stuck in an uninitialized state.
|
||||||
|
|
||||||
The following is an example `initiallizerConfiguration`.
|
The following is an example `initializerConfiguration`:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: admissionregistration.k8s.io/v1alpha1
|
apiVersion: admissionregistration.k8s.io/v1alpha1
|
||||||
@@ -126,12 +126,16 @@ initializers:
|
|||||||
- pods
|
- pods
|
||||||
```
|
```
|
||||||
|
|
||||||
|
After you create the `initializerConfiguration`, the system will take a few
|
||||||
|
seconds to honor the new configuration. Then, `"podimage.example.com"` will be
|
||||||
|
appended to the `metadata.initializers.pending` field of newly created pods. You
|
||||||
|
should already have a ready "podimage" initializer controller that handles pods
|
||||||
|
whose `metadata.initializers.pending[0].name="podimage.example.com"`. Otherwise
|
||||||
|
the pods will stuck uninitialized.
|
||||||
|
|
||||||
Make sure that all expansions of the `<apiGroup, apiVersions, resources>` tuple
|
Make sure that all expansions of the `<apiGroup, apiVersions, resources>` tuple
|
||||||
in a `rule` are valid. If they are not, separate them in different `rules`.
|
in a `rule` are valid. If they are not, separate them in different `rules`.
|
||||||
|
|
||||||
After you create the `initializerConfiguration`, the system will take a few
|
|
||||||
seconds to honor the new configuration.
|
|
||||||
|
|
||||||
## External Admission Webhooks
|
## External Admission Webhooks
|
||||||
|
|
||||||
### What are external admission webhooks?
|
### What are external admission webhooks?
|
||||||
@@ -232,7 +236,7 @@ it is working properly before creating the externaladmissionhookconfigurations.
|
|||||||
Otherwise, depending whether the webhook is configured as fail open or fail
|
Otherwise, depending whether the webhook is configured as fail open or fail
|
||||||
closed, operations will be unconditionally accepted or rejected.
|
closed, operations will be unconditionally accepted or rejected.
|
||||||
|
|
||||||
The following is an example externaladmissionhookconfiguration.
|
The following is an example `externaladmissionhookconfiguration`:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: admissionregistration.k8s.io/v1alpha1
|
apiVersion: admissionregistration.k8s.io/v1alpha1
|
||||||
|
|||||||
Reference in New Issue
Block a user