diff --git a/OWNERS_ALIASES b/OWNERS_ALIASES new file mode 100644 index 0000000000..2ac8989ed2 --- /dev/null +++ b/OWNERS_ALIASES @@ -0,0 +1,206 @@ +aliases: + sig-api-machinery: #Team: API Server; GH: sig-api-machinery-pr-reviews; e.g. Annotations, Labels + - lavalamp + - sttts + - liggitt + - smarterclayton + - deads2k + sig-apps: #Team: Workloads; GH: sig-apps-pr-reviews; e.g. ConfigMaps, CronJobs, CustomResourceDefinitions, DaemonSets, Deployments, Jobs, Secrets, StatefulSets + - enisoc + - erictune + - foxish + - janetkuo + - kow3ns + - lukaszo + - mfojtik + - smarterclayton + - soltysh + - tnozicka + sig-architecture: #GH: sig-architecture-pr-reviews + - smarterclayton + - bgrant0607 + sig-auth: #GH: sig-auth-pr-reviews + - php-coder + - liggitt + - mikedanese + - ericchiang + - mattmoyer + - enj + - deads2k + - davidopp + sig-autoscaling: #GH: sig-autoscaling-pr-reviews + - DirectXMan12 + - bskiba + - aleksandra-malinowska + - MaciekPytel + - davidopp + - mwielgus + sig-aws: #Amazon AWS + - justinsb + - kris-nova + - chrislovecnm + - mfburnett + sig-azure: #Microsoft Azure + - slack + - colemickens + - jdumars + sig-big-data: #GH: sig-big-data-pr-reviews + - foxish + sig-cli: #Team: CLI; GH: sig-cli-pr-reviews; e.g. kubectl + - adohe + - deads2k + - derekwaynecarr + - dims + - dshulyak + - eparis + - ericchiang + - ghodss + - mengqiy + - rootfs + - shiywang + - smarterclayton + - soltysh + - sttts + sig-cluster-lifecycle: #GH: sig-cluster-lifecycle-pr-reviews + - jbeda + - timothysc + - lukemarsden + - pipejakob + - dmmcquay + - mattmoyer + - luxas + - roberthbailey + - medinatiger + sig-cluster-ops: + - zehicle + - jdumars + sig-contribex: #aka Contributor Experience; GH: sig-contributor-experience-pr-reviews + - rmmh + - cblecker + - apelisse + - grodrigues3 + - spxtr + sig-contributor-experience: #GH: sig-contributor-experience-pr-reviews + - rmmh + - cblecker + - apelisse + - grodrigues3 + - spxtr + sig-docs: #Team: documentation; GH: sig-docs-pr-reviews + - a-mccarthy + - abiogenesis-now + - bradamant3 + - steveperry-53 + - zacharysarah + sig-federation: #Team: Federation; e.g. Federated Clusters + - csbell + sig-gcp: #Google Cloud Platform; GH: sig-gcp-pr-reviews + - abgworrall + sig-instrumentation: #GH: sig-instrumentation-pr-reviews; e.g. metrics, logging, events + - DirectXMan12 + - x13n + - kawych + - crassirostris + - brancz + - fabxc + - loburm + - piosz + - fgrzadkowski + sig-multicluster: #GH: sig-multicluster-pr-reviews; e.g. resiliency against availability zone outages; hybrid clouds; spanning multiple cloud providers; migration to public clouds + - madhusudancs + - marun + - jianhuiz + - shashidharatd + - nikhiljindal + - quinton-hoole + - mwielgus + - csbell + sig-network: #Team: Network; GH: sig-network-pr-reviews; e.g. Ingress, Network Policies, Services + - bowei + - caseydavenport + - danwinship + - dcbw + - dnardo + - freehan + - mrhohn + - nicksardo + - thockin + sig-node: #Team: Node; GH: sig-node-pr-reviews; e.g. Containers, Docker, Images, OS images, Pods, Registries + - Random-Liu + - dashpole + - dchen1107 + - derekwaynecarr + - dims + - feiskyer + - mtaufen + - ncdc + - pmorie + - resouer + - sjpotter + - tallclair + - tmrts + - vishh + - yifan-gu + - yujuhong + sig-onprem: #On-premises; GH: sig-onprem-pr-reviews + - zen + - idvoretskyi + - pigmej + - feiskyer + - nebril + sig-openstack: #GH: sig-openstack-pr-reviews + - idvoretskyi + - xsgordon + - NickrenREN + sig-pm: #aka Product Management + - apsinha + - idvoretskyi + - calebamiles + sig-product-management: + - apsinha + - idvoretskyi + - calebamiles + sig-release: #GH: sig-release-pr-reviews + - calebamiles + - enisoc + - pwittrock + sig-rktnetes: + - calebamiles + sig-scalability: #GH: sig-scalability-pr-reviews + - jbeda + - spiffxp + - lavalamp + - countspongebob + sig-scheduling: #Team: Sharing; GH: sig-scheduling-pr-reviews; e.g. Scheduler + - bsalamat + - davidopp + - jayunit100 + - k82cn + - resouer + - timothysc + - wojtek-t + sig-service-catalog: #GH: sig-service-catalog-pr-reviews; e.g. Service Broker + - pmorie + - jessfraz + - pwittrock + - droot + - seans3 + sig-storage: #Team: Storage; GH: sig-storage-pr-reviews; e.g. Volumes + - childsb + - jsafrane + - rootfs + - saad-ali + - matchstick + - msau42 + sig-testing: #GH: sig-testing-pr-reviews + - fejta + - ixdy + - rmmh + - spiffxp + - spxtr + sig-ui: #User Interface + - danielromlein + - floreks + sig-windows: + - michmike + diff --git a/_config.yml b/_config.yml index d601fa4f51..3471320708 100644 --- a/_config.yml +++ b/_config.yml @@ -27,27 +27,27 @@ defaults: version: "v1.9" githubbranch: "v1.9.0" docsbranch: "release-1.9" - url: https://kubernetes.io/docs/home/ + url: https://kubernetes.io - fullversion: "v1.8.4" version: "v1.8" githubbranch: "v1.8.4" docsbranch: "release-1.8" - url: https://v1-8.docs.kubernetes.io/docs/home/ + url: https://v1-8.docs.kubernetes.io - fullversion: "v1.7.6" version: "v1.7" githubbranch: "v1.7.6" docsbranch: "release-1.7" - url: https://v1-7.docs.kubernetes.io/docs/home/ + url: https://v1-7.docs.kubernetes.io - fullversion: "v1.6.8" version: "v1.6" githubbranch: "v1.6.8" docsbranch: "release-1.6" - url: https://v1-6.docs.kubernetes.io/docs/home/ + url: https://v1-6.docs.kubernetes.io - fullversion: "v1.5.7" version: "v1.5" githubbranch: "v1.5.7" docsbranch: "release-1.5" - url: https://v1-5.docs.kubernetes.io/docs/ + url: https://v1-5.docs.kubernetes.io deprecated: false currentUrl: https://kubernetes.io/docs/home/ nextUrl: http://kubernetes-io-vnext-staging.netlify.com/ diff --git a/_data/glossary/configmap.yaml b/_data/glossary/configmap.yaml index b961b734b0..faebef5297 100644 --- a/_data/glossary/configmap.yaml +++ b/_data/glossary/configmap.yaml @@ -1,6 +1,6 @@ id: configmap name: ConfigMap -full-link: /docs/tasks/configure-pod-container/configmap/ +full-link: /docs/tasks/configure-pod-container/configure-pod-configmap/ related: - pod - secret diff --git a/_data/glossary/labels.yaml b/_data/glossary/labels.yaml index 024620571c..c74accddb5 100644 --- a/_data/glossary/labels.yaml +++ b/_data/glossary/labels.yaml @@ -1,9 +1,10 @@ -id: labels -name: Labels +id: label +name: Label full-link: /docs/concepts/overview/working-with-objects/labels tags: - fundamental short-description: > - Used to tag objects with identifying attributes that are meaningful and relevant to users. + Tags objects with identifying attributes that are meaningful and relevant to users. long-description: > - Labels are key/value pairs that are attached to objects, such as pods. They can be used to organize and to select subsets of objects. \ No newline at end of file + Labels are key/value pairs that are attached to objects such as {% glossary_tooltip text="Pods" term_id="pod" %}. + They are used to organize and to select subsets of objects. diff --git a/_data/glossary/namespace.yaml b/_data/glossary/namespace.yaml index 6661479620..be733fc35d 100644 --- a/_data/glossary/namespace.yaml +++ b/_data/glossary/namespace.yaml @@ -2,8 +2,9 @@ id: namespace name: Namespace full-link: /docs/concepts/overview/working-with-objects/namespaces tags: -- fundamental + - fundamental short-description: > - An abstraction used by Kubernetes to support virtual clusters on the same physical {% glossary_tooltip term_id="cluster" %}. + An abstraction used by Kubernetes to support multiple virtual clusters on the same physical {% glossary_tooltip term_id="cluster" %}. long-description: > - Namespaces are used to organize objects in a cluster and provide a way to divide cluster resources. Names of resources need to be unique within a namespace, but not across namespaces. + Namespaces are used to organize objects in a cluster and provide a way to divide cluster resources. + Names of resources need to be unique within a namespace, but not across namespaces. diff --git a/_data/glossary/persistent-volume-claim.yaml b/_data/glossary/persistent-volume-claim.yaml new file mode 100644 index 0000000000..6929a7516a --- /dev/null +++ b/_data/glossary/persistent-volume-claim.yaml @@ -0,0 +1,15 @@ +id: persistent-volume-claim +name: Persistent Volume Claim +full-link: /docs/concepts/storage/persistent-volumes/ +related: +- persistent-volume +- statefulset +- deployment +- pod +tags: +- core-object +- storage +short-description: > + Claims storage resources defined in a {% glossary_tooltip text="PersistentVolume (PV)" term_id="persistent-volume" %} so that it can be mounted as a volume in a container. +long-description: | + Specifies the amount of storage, how the storage will be accessed (read-only, read-write and/or exclusive) and how it is reclaimed (retained, recycled or deleted). Details of the storage itself are in the PersistentVolume specification. diff --git a/_data/glossary/persistent-volume.yaml b/_data/glossary/persistent-volume.yaml new file mode 100644 index 0000000000..1f0fe7b528 --- /dev/null +++ b/_data/glossary/persistent-volume.yaml @@ -0,0 +1,17 @@ +id: persistent-volume +name: Persistent Volume +full-link: /docs/concepts/storage/persistent-volumes/ +related: +- statefulset +- deployment +- persistent-volume-claim +- pod +tags: +- core-object +- storage +short-description: > + An API object that represents a piece of storage in the cluster. Available as a general, pluggable resource that persists beyond the lifecycle of any individual {% glossary_tooltip term_id="pod" %}. +long-description: | + PersistentVolumes (PVs) provide an API that abstracts details of how storage is provided from how it is consumed. + PVs are used directly in scenarios where storage can be be created ahead of time (static provisioning). + For scenarios that require on-demand storage (dynamic provisioning), PersistentVolumeClaims (PVCs) are used instead. diff --git a/_data/glossary/secret.yml b/_data/glossary/secret.yml index 1565df28f8..c131817f8b 100644 --- a/_data/glossary/secret.yml +++ b/_data/glossary/secret.yml @@ -12,4 +12,4 @@ short-description: > long-description: > Allows for more control over how sensitive information is used and reduces the risk of accidental exposure, including [encryption](https://kubernetes.io/docs/tasks/administer-cluster/encrypt-data/#ensure-all-secrets-are-encrypted) at rest. A {% glossary_tooltip text="Pod" term_id="pod" %} references the secret as a file in a volume mount or by the kubelet pulling images for a pod. - Secrets are great for confidential data and [ConfigMaps](https://kubernetes.io/docs/tasks/configure-pod-container/configmap/) for non-confidential data. + Secrets are great for confidential data and [ConfigMaps](https://kubernetes.io/docs/tasks/configure-pod-container/configure-pod-configmap/) for non-confidential data. diff --git a/_data/glossary/service-catalog.yaml b/_data/glossary/service-catalog.yaml index bcbadd309c..10cd2288a7 100644 --- a/_data/glossary/service-catalog.yaml +++ b/_data/glossary/service-catalog.yaml @@ -5,4 +5,4 @@ tags: short-description: > An extension API that enables applications running in Kubernetes clusters to easily use external managed software offerings, such as a datastore service offered by a cloud provider. long-description: > - Service Catalog provides a way to list, provision, and bind with external {% glossary_tooltip text="Managed Services" term_id="managed-service" %} from {% glossary_tooltip text="Service Brokers" term_id="service-broker" %} without needing detailed knowledge about how those services are created or managed. \ No newline at end of file + It provides a way to list, provision, and bind with external {% glossary_tooltip text="Managed Services" term_id="managed-service" %} from {% glossary_tooltip text="Service Brokers" term_id="service-broker" %} without needing detailed knowledge about how those services are created or managed. diff --git a/_data/tasks.yml b/_data/tasks.yml index d6a0376601..19303d038c 100644 --- a/_data/tasks.yml +++ b/_data/tasks.yml @@ -28,7 +28,6 @@ toc: - docs/tasks/configure-pod-container/assign-pods-nodes.md - docs/tasks/configure-pod-container/configure-pod-initialization.md - docs/tasks/configure-pod-container/attach-handler-lifecycle-event.md - - docs/tasks/configure-pod-container/configmap.md - docs/tasks/configure-pod-container/configure-pod-configmap.md - docs/tools/kompose/user-guide.md diff --git a/_includes/footer.html b/_includes/footer.html index c01c5d5e1b..4d15180920 100644 --- a/_includes/footer.html +++ b/_includes/footer.html @@ -28,7 +28,7 @@ © {{ 'now' | date: "%Y" }} The Kubernetes Authors | Documentation Distributed under CC BY 4.0
- Copyright © {{ 'now' | date: "%Y" }} The Linux Foundation®. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page: https://www.linuxfoundation.org/trademark-usage + Copyright © {{ 'now' | date: "%Y" }} The Linux Foundation®. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page
diff --git a/_includes/header.html b/_includes/header.html index a4c5250282..8db73df89d 100644 --- a/_includes/header.html +++ b/_includes/header.html @@ -16,7 +16,11 @@ diff --git a/_includes/partner-script.js b/_includes/partner-script.js index d1d3a3963a..d319ab48d8 100644 --- a/_includes/partner-script.js +++ b/_includes/partner-script.js @@ -11,8 +11,8 @@ type: 0, name: 'Puppet', logo: 'puppet', - link: 'https://puppet.com/blog/managing-kubernetes-configuration-puppet', - blurb: 'The Puppet module for Kubernetes makes it easy to manage Pods, Replication Controllers, Services and more in Kubernetes, and to build domain-specific interfaces to one\'s Kubernetes configuration.' + link: 'https://puppet.com/blog/announcing-kream-and-new-kubernetes-helm-and-docker-modules', + blurb: 'We\'ve developed tools and products to make your adoption of Kubernetes as efficient as possible, covering your full workflow cycle from development to production. And now Puppet Pipelines for Containers is your complete DevOps dashboard for Kubernetes.' }, { type: 0, @@ -43,7 +43,7 @@ blurb: 'Powering the GIFEE (Google’s Infrastructure for Everyone Else), to run OpenStack deployments on Kubernetes.' }, { - type: 0, + type: 3, name: 'Platform9', logo: 'platform9', link: 'https://platform9.com/products/kubernetes/', @@ -131,7 +131,7 @@ name: 'Hasura', logo: 'hasura', link: 'https://hasura.io', - blurb: 'Hasura - Hasura' + blurb: 'Hasura is a Kubernetes-based PaaS and a Postgres-based BaaS that accelerates app development with ready-to-use components.' }, { type: 3, @@ -462,6 +462,13 @@ link: 'http://kublr.com', blurb: 'Kublr - Accelerate and control the deployment, scaling, monitoring and management of your containerized applications.' }, + { + type: 1, + name: 'ControlPlane', + logo: 'controlplane', + link: 'https://control-plane.io', + blurb: 'We are a London-based Kubernetes consultancy with a focus on security and continuous delivery. We offer consulting & training.' + }, { type: 3, name: 'Nirmata', @@ -469,6 +476,13 @@ link: 'https://www.nirmata.com/', blurb: 'Nirmata - Nirmata Managed Kubernetes' }, + { + type: 2, + name: 'Nirmata', + logo: 'nirmata', + link: 'https://www.nirmata.com/', + blurb: 'Nirmata is a software platform that helps DevOps teams deliver enterprise-grade and cloud-provider agnostic Kubernetes based container management solutions.' + }, { type: 3, name: 'TenxCloud', @@ -477,11 +491,11 @@ blurb: 'TenxCloud - TenxCloud Container Engine (TCE)' }, { - type: 3, + type: 0, name: 'Twistlock', logo: 'twistlock', link: 'https://www.twistlock.com/', - blurb: 'Twistlock - Twistlock' + blurb: 'Security at Kubernetes Scale: Twistlock allows you to deploy fearlessly with assurance that your images and containers are free of vulnerabilities and protected at runtime.' }, { type: 0, @@ -519,7 +533,7 @@ blurb: 'CloudKite.io helps companies build and maintain highly automated, resilient, and impressively performing software on Kubernetes.' }, { - type: 1, + type: 2, name: 'CloudOps', logo: 'CloudOps', link: 'https://www.cloudops.com/services/docker-and-kubernetes-workshops/', @@ -532,6 +546,13 @@ link: 'https://www.ghostcloud.cn/ecos-kubernetes', blurb: 'EcOS is an enterprise-grade PaaS / CaaS based on Docker and Kubernetes, which makes it easier to configure, deploy and manage containerized applications.' }, + { + type: 3, + name: 'Ghostcloud', + logo: 'ghostcloud', + link: 'https://www.ghostcloud.cn/ecos-kubernetes', + blurb: 'EcOS is an enterprise-grade PaaS / CaaS based on Docker and Kubernetes, which makes it easier to configure, deploy and manage containerized applications.' + }, { type: 2, name: 'Contino', @@ -703,7 +724,7 @@ { type: 3, name: 'Google Kubernetes Engine', - logo: 'gcp', + logo: 'google', link: 'https://cloud.google.com/kubernetes-engine/', blurb: 'Google - Google Kubernetes Engine' }, @@ -864,7 +885,7 @@ { type: 3, name: 'Google', - logo: 'gcp', + logo: 'google', link: 'https://github.com/kubernetes/kubernetes/tree/master/cluster', blurb: 'Google - kube-up.sh on Google Compute Engine' }, @@ -882,6 +903,13 @@ link: 'https://www.163yun.com/product/container-service-dedicated', blurb: 'Netease - Netease Container Service Dedicated' }, + { + type: 2, + name: 'Loodse', + logo: 'loodse', + link: 'https://loodse.com', + blurb: 'Loodse provides Kubernetes training & consulting, and host related events regularly across Europe.' + }, { type: 3, name: 'Loodse', @@ -889,6 +917,13 @@ link: 'https://loodse.com', blurb: 'Loodse - Kubermatic Container Engine' }, + { + type: 1, + name: 'LTI', + logo: 'lti', + link: 'https://www.lntinfotech.com/', + blurb: 'LTI helps enterprises architect, develop and support scalable cloud native apps using Docker and Kubernetes for private or public cloud.' + }, { type: 3, name: 'Microsoft', @@ -966,6 +1001,13 @@ link: 'https://kubernetes.io/docs/setup/independent/create-cluster-kubeadm/', blurb: 'Weaveworks - kubeadm' }, + { + type: 3, + name: 'Joyent', + logo: 'joyent', + link: 'https://github.com/joyent/triton-kubernetes', + blurb: 'Joyent - Triton Kubernetes' + }, { type: 3, name: 'Wise2c', @@ -994,6 +1036,13 @@ link: 'http://www.daocloud.io/dce', blurb: 'DaoCloud - DaoCloud Enterprise' }, + { + type: 2, + name: 'Daocloud', + logo: 'daocloud', + link: 'http://www.daocloud.io/dce', + blurb: 'We provide enterprise-level cloud native application platform that supports both Kubernetes and Docker Swarm.' + }, { type: 3, name: 'SUSE', @@ -1127,6 +1176,13 @@ link: 'http://dataspine.xyz/', blurb: 'Dataspine is building a secure, elastic and serverless deployment platform for production ML/AI workloads on top of k8s.' }, + { + type: 1, + name: 'CloudBourne', + logo: 'cloudbourne', + link: 'https://cloudbourne.com/kubernetes-enterprise-hybrid-cloud/', + blurb: 'Want to achieve maximum build, deploy and monitoring automation using Kubernetes? We can help.' + }, { type: 0, name: 'Logdna', diff --git a/_includes/v1.3/v1-definitions.html b/_includes/v1.3/v1-definitions.html index 4cd88cc6ed..42ed010f3c 100755 --- a/_includes/v1.3/v1-definitions.html +++ b/_includes/v1.3/v1-definitions.html @@ -6415,7 +6415,7 @@ The resulting set of endpoints can be viewed as:

names

-

Names by which this image is known. e.g. ["gcr.io/google_containers/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"]

+

Names by which this image is known. e.g. ["k8s.gcr.io/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"]

true

string array

diff --git a/_includes/v1.4/v1-definitions.html b/_includes/v1.4/v1-definitions.html index 254075b5cb..8e61a5b040 100755 --- a/_includes/v1.4/v1-definitions.html +++ b/_includes/v1.4/v1-definitions.html @@ -6671,7 +6671,7 @@ The resulting set of endpoints can be viewed as:

names

-

Names by which this image is known. e.g. ["gcr.io/google_containers/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"]

+

Names by which this image is known. e.g. ["k8s.gcr.io/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"]

true

string array

diff --git a/_includes/v1.5/v1-definitions.html b/_includes/v1.5/v1-definitions.html index ed1b302484..5dbb6c7094 100755 --- a/_includes/v1.5/v1-definitions.html +++ b/_includes/v1.5/v1-definitions.html @@ -6850,7 +6850,7 @@ The resulting set of endpoints can be viewed as:

names

-

Names by which this image is known. e.g. ["gcr.io/google_containers/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"]

+

Names by which this image is known. e.g. ["k8s.gcr.io/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"]

true

string array

diff --git a/_plugins/README.md b/_plugins/README.md index d4a192840e..3f30927e31 100644 --- a/_plugins/README.md +++ b/_plugins/README.md @@ -25,6 +25,7 @@ This renders the definition of the glossary term inside a `
`, preserving Ma | --- | --- | --- | | `term_id` | N/A (Required) | The `id` of the glossary term whose definition will be used. (This `id` is the same as the filename of the term, i.e. `_data/glossary/.yml`.) | | `length` | "short" | Specifies which term definition should be used ("short" for the `short-definition`, "long" for `long-description`, "all" when both should be included). | +| `prepend` | "Service Catalog is" | A prefix which can be attached in front of a term's short definition (which is one or more sentence fragments). | #### (2) `glossary_tooltip` tag diff --git a/_plugins/glossary_tags.rb b/_plugins/glossary_tags.rb index c59ccf0e9f..8faaedfb37 100644 --- a/_plugins/glossary_tags.rb +++ b/_plugins/glossary_tags.rb @@ -55,11 +55,17 @@ module Jekyll class Definition < Base VALID_PARAM_NAMES = [ :term_id, - :length + :length, + :prepend, ].freeze def render(context) - include_snippet(context) + text = include_snippet(context) + if @args[:prepend] + text.sub(/

(.)/) { "

#{@args[:prepend]} #{$1.downcase}" } + else + text + end end end diff --git a/_redirects b/_redirects index f10c8d57d0..fbd6069238 100644 --- a/_redirects +++ b/_redirects @@ -76,11 +76,10 @@ /docs/api-reference/v1.5/* https://v1-5.docs.kubernetes.io/docs/reference/ 301 /docs/api-reference/v1.6/* https://v1-6.docs.kubernetes.io/docs/reference/ 301 /docs/api-reference/v1.7/* https://v1-7.docs.kubernetes.io/docs/reference/ 301 -/docs/api-reference/v1.8/* https://v1-8.docs.kubernetes.io/docs/reference/ 301 +/docs/api-reference/v1.8/* https://v1-8.docs.kubernetes.io/docs/api-reference/v1.8/:splat 301 /docs/api-reference/v1/definitions/ /docs/api-reference/v1.9/ 301 /docs/api-reference/v1/operations/ /docs/api-reference/v1.9/ 301 - /docs/concepts/abstractions/controllers/garbage-collection/ /docs/concepts/workloads/controllers/garbage-collection/ 301 /docs/concepts/abstractions/controllers/petsets/ /docs/concepts/workloads/controllers/statefulset/ 301 /docs/concepts/abstractions/controllers/statefulsets/ /docs/concepts/workloads/controllers/statefulset/ 301 @@ -197,9 +196,9 @@ /docs/resources-reference/1_5/* /docs/resources-reference/v1.5/ 301 /docs/resources-reference/1_5/* https://v1-5.docs.kubernetes.io/docs/resources-reference/v1.5/ 301 +/docs/resources-reference/v1.5/node_modules/* https://v1-5.docs.kubernetes.io/docs/resources-reference/v1.5/ 301 /docs/resources-reference/1_6/* /docs/resources-reference/v1.6/ 301 /docs/resources-reference/1_7/* /docs/resources-reference/v1.7/ 301 -/docs/resources-reference/v1.5/node_modules/* https://v1-5.docs.kubernetes.io/docs/resources-reference/v1.5/ 301 /docs/resources-reference/v1.8/* /docs/api-reference/v1.8/:splat 301 /docs/roadmap/ https://github.com/kubernetes/kubernetes/milestones/ 301 @@ -218,7 +217,7 @@ /docs/tasks/administer-cluster/default-cpu-request-limit/ /docs/tasks/configure-pod-container/assign-cpu-resource/#specify-a-cpu-request-and-a-cpu-limit/ 301 /docs/tasks/administer-cluster/default-memory-request-limit/ /docs/tasks/configure-pod-container/assign-memory-resource/#specify-a-memory-request-and-a-memory-limit/ 301 /docs/tasks/administer-cluster/developing-cloud-controller-manager.md /docs/tasks/administer-cluster/developing-cloud-controller-manager/ 301 -/docs/tasks/administer-cluster/out-of-resource/memory-available.sh /docs/concepts/cluster-administration/out-of-resource/memory-available.sh 301 +/docs/tasks/administer-cluster/out-of-resource/memory-available.sh /docs/tasks/administer-cluster/memory-available.sh 301 /docs/tasks/administer-cluster/overview/ /docs/concepts/cluster-administration/cluster-administration-overview/ 301 /docs/tasks/administer-cluster/reserve-compute-resources/out-of-resource.md /docs/tasks/administer-cluster/out-of-resource/ 301 /docs/tasks/administer-cluster/running-cloud-controller.md /docs/tasks/administer-cluster/running-cloud-controller/ 301 @@ -341,7 +340,8 @@ /docs/user-guide/kubeconfig-file/ /docs/tasks/access-application-cluster/authenticate-across-clusters-kubeconfig/ 301 /docs/user-guide/kubectl-overview/ /docs/reference/kubectl/overview/ /docs/user-guide/kubectl/ /docs/reference/generated/kubectl/kubectl-options/ -/docs/user-guide/kubectl/v1.8/ /docs/reference/generated/kubectl/kubectl-commands/ +/docs/user-guide/kubectl/v1.8/* https://v1-8.docs.kubernetes.io/docs/reference/generated/kubectl/kubectl-commands/:splat 301 +/docs/user-guide/kubectl/v1.9/* /docs/reference/generated/kubectl/kubectl-commands/:splat 301 /docs/user-guide/kubectl-conventions/ /docs/reference/kubectl/conventions/ /docs/user-guide/kubectl-cheatsheet/ /docs/reference/kubectl/cheatsheet/ /docs/user-guide/kubectl/1_5/* https://v1-5.docs.kubernetes.io/docs/user-guide/kubectl/v1.5/ 301 @@ -443,3 +443,4 @@ https://kubernetes-io-v1-7.netlify.com/* https://v1-7.docs.kubernetes.io/:spl /docs/admin/kubefed_unjoin/ /docs/reference/generated/kubefed_unjoin/ 301 /docs/admin/kubefed_version/ /docs/reference/generated/kubefed_version/ 301 +/docs/reference/generated/kubeadm/ /docs/reference/setup-tools/kubeadm/kubeadm/ 301 diff --git a/cn/docs/admin/cluster-large.md b/cn/docs/admin/cluster-large.md index 9f6b33c94f..5670f7e0ae 100644 --- a/cn/docs/admin/cluster-large.md +++ b/cn/docs/admin/cluster-large.md @@ -85,7 +85,7 @@ AWS使用的规格为: ```yaml containers: - name: fluentd-cloud-logging - image: gcr.io/google_containers/fluentd-gcp:1.16 + image: k8s.gcr.io/fluentd-gcp:1.16 resources: limits: cpu: 100m diff --git a/cn/docs/admin/node-conformance.md b/cn/docs/admin/node-conformance.md index 6be4ba50a0..91af9fde63 100644 --- a/cn/docs/admin/node-conformance.md +++ b/cn/docs/admin/node-conformance.md @@ -40,7 +40,7 @@ title: 节点设置校验 # $LOG_DIR 是测试结果输出的路径。 sudo docker run -it --rm --privileged --net=host \ -v /:/rootfs -v $CONFIG_DIR:$CONFIG_DIR -v $LOG_DIR:/var/result \ - gcr.io/google_containers/node-test:0.2 + k8s.gcr.io/node-test:0.2 ``` ## 针对其他硬件体系结构运行节点合规性测试 @@ -61,7 +61,7 @@ Kubernetes 也为其他硬件体系结构的系统提供了节点合规性测试 sudo docker run -it --rm --privileged --net=host \ -v /:/rootfs:ro -v $CONFIG_DIR:$CONFIG_DIR -v $LOG_DIR:/var/result \ -e FOCUS=MirrorPod \ # 只运行MirrorPod测试 - gcr.io/google_containers/node-test:0.2 + k8s.gcr.io/node-test:0.2 ``` 为跳过指定的测试,用正则表达式来描述将要跳过的测试,并重载 `SKIP` 环境变量。 @@ -70,7 +70,7 @@ sudo docker run -it --rm --privileged --net=host \ sudo docker run -it --rm --privileged --net=host \ -v /:/rootfs:ro -v $CONFIG_DIR:$CONFIG_DIR -v $LOG_DIR:/var/result \ -e SKIP=MirrorPod \ # 运行除MirrorPod外的所有测试 - gcr.io/google_containers/node-test:0.2 + k8s.gcr.io/node-test:0.2 ``` 节点合规性测试是[节点端到端测试](https://github.com/kubernetes/community/blob/{{page.githubbranch}}/contributors/devel/e2e-node-tests.md)的一个容器化的版本。 diff --git a/cn/docs/concepts/architecture/cloud-controller.md b/cn/docs/concepts/architecture/cloud-controller.md index 644e3e7d0a..15840fd8b5 100644 --- a/cn/docs/concepts/architecture/cloud-controller.md +++ b/cn/docs/concepts/architecture/cloud-controller.md @@ -172,7 +172,7 @@ v1/ServiceAccount: 针对CCM的RBAC ClusterRole如下所示: ```yaml -apiVersion: rbac.authorization.k8s.io/v1beta1 +apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: cloud-controller-manager diff --git a/cn/docs/concepts/architecture/nodes.md b/cn/docs/concepts/architecture/nodes.md index fa9bb53098..da999dd7a6 100644 --- a/cn/docs/concepts/architecture/nodes.md +++ b/cn/docs/concepts/architecture/nodes.md @@ -216,7 +216,7 @@ metadata: spec: containers: - name: sleep-forever - image: gcr.io/google_containers/pause:0.8.0 + image: k8s.gcr.io/pause:0.8.0 resources: requests: cpu: 100m diff --git a/cn/docs/concepts/configuration/manage-compute-resources-container.md b/cn/docs/concepts/configuration/manage-compute-resources-container.md index 6b06fc5064..341706ef10 100644 --- a/cn/docs/concepts/configuration/manage-compute-resources-container.md +++ b/cn/docs/concepts/configuration/manage-compute-resources-container.md @@ -199,7 +199,7 @@ Conditions: Events: FirstSeen LastSeen Count From SubobjectPath Reason Message Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {scheduler } scheduled Successfully assigned simmemleak-hra99 to kubernetes-node-tf0f - Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} implicitly required container POD pulled Pod container image "gcr.io/google_containers/pause:0.8.0" already present on machine + Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} implicitly required container POD pulled Pod container image "k8s.gcr.io/pause:0.8.0" already present on machine Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} implicitly required container POD created Created with docker id 6a41280f516d Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} implicitly required container POD started Started with docker id 6a41280f516d Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} spec.containers{simmemleak} created Created with docker id 87348f12526a diff --git a/cn/docs/concepts/configuration/pod-with-node-affinity.yaml b/cn/docs/concepts/configuration/pod-with-node-affinity.yaml index 7c38e19997..253d2b21ea 100644 --- a/cn/docs/concepts/configuration/pod-with-node-affinity.yaml +++ b/cn/docs/concepts/configuration/pod-with-node-affinity.yaml @@ -23,4 +23,4 @@ spec: - another-node-label-value containers: - name: with-node-affinity - image: gcr.io/google_containers/pause:2.0 \ No newline at end of file + image: k8s.gcr.io/pause:2.0 \ No newline at end of file diff --git a/cn/docs/concepts/configuration/pod-with-pod-affinity.yaml b/cn/docs/concepts/configuration/pod-with-pod-affinity.yaml index 3728537d5a..1897af901f 100644 --- a/cn/docs/concepts/configuration/pod-with-pod-affinity.yaml +++ b/cn/docs/concepts/configuration/pod-with-pod-affinity.yaml @@ -26,4 +26,4 @@ spec: topologyKey: kubernetes.io/hostname containers: - name: with-pod-affinity - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 diff --git a/cn/docs/concepts/configuration/secret.md b/cn/docs/concepts/configuration/secret.md index 9b61a725eb..c8c9319485 100644 --- a/cn/docs/concepts/configuration/secret.md +++ b/cn/docs/concepts/configuration/secret.md @@ -518,7 +518,7 @@ spec: secretName: dotfile-secret containers: - name: dotfile-test-container - image: gcr.io/google_containers/busybox + image: k8s.gcr.io/busybox command: - ls - "-l" diff --git a/cn/docs/concepts/workloads/pods/pod-lifecycle.md b/cn/docs/concepts/workloads/pods/pod-lifecycle.md index 8420f318bc..176e57b829 100644 --- a/cn/docs/concepts/workloads/pods/pod-lifecycle.md +++ b/cn/docs/concepts/workloads/pods/pod-lifecycle.md @@ -108,7 +108,7 @@ spec: containers: - args: - /server - image: gcr.io/google_containers/liveness + image: k8s.gcr.io/liveness livenessProbe: httpGet: # when "host" is not defined, "PodIP" will be used diff --git a/cn/docs/tasks/access-application-cluster/connecting-frontend-backend.md b/cn/docs/tasks/access-application-cluster/connecting-frontend-backend.md index f2d82fae7e..a63ad90777 100644 --- a/cn/docs/tasks/access-application-cluster/connecting-frontend-backend.md +++ b/cn/docs/tasks/access-application-cluster/connecting-frontend-backend.md @@ -160,7 +160,7 @@ service "frontend" created **注意**:这个 nginx 配置文件是被打包在 [容器镜像](/docs/tasks/access-application-cluster/frontend/Dockerfile) 里的。 -更好的方法是使用 [ConfigMap](/docs/tasks/configure-pod-container/configmap/),这样的话你可以更轻易地更改配置。 +更好的方法是使用 [ConfigMap](/docs/tasks/configure-pod-container/configure-pod-configmap/),这样的话你可以更轻易地更改配置。 ### 与前端 Service 交互 @@ -216,7 +216,7 @@ curl http:// * 了解更多 [Services](/docs/concepts/services-networking/service/) -* 了解更多 [ConfigMaps](/docs/tasks/configure-pod-container/configmap/) +* 了解更多 [ConfigMaps](/docs/tasks/configure-pod-container/configure-pod-configmap/) {% endcapture %} diff --git a/cn/docs/tasks/access-application-cluster/redis-master.yaml b/cn/docs/tasks/access-application-cluster/redis-master.yaml index 57305a7a35..589de648f5 100644 --- a/cn/docs/tasks/access-application-cluster/redis-master.yaml +++ b/cn/docs/tasks/access-application-cluster/redis-master.yaml @@ -9,7 +9,7 @@ metadata: spec: containers: - name: master - image: gcr.io/google_containers/redis:v1 + image: k8s.gcr.io/redis:v1 env: - name: MASTER value: "true" diff --git a/cn/docs/tasks/administer-cluster/cpu-memory-limit.md b/cn/docs/tasks/administer-cluster/cpu-memory-limit.md index b437c8a2f0..341e3070f6 100644 --- a/cn/docs/tasks/administer-cluster/cpu-memory-limit.md +++ b/cn/docs/tasks/administer-cluster/cpu-memory-limit.md @@ -178,7 +178,7 @@ $ kubectl get pods valid-pod --namespace=limit-example -o yaml | grep -C 6 resou uid: 3b1bfd7a-f53c-11e5-b066-64510658e388 spec: containers: - - image: gcr.io/google_containers/serve_hostname + - image: k8s.gcr.io/serve_hostname imagePullPolicy: Always name: kubernetes-serve-hostname resources: diff --git a/cn/docs/tasks/administer-cluster/dns-horizontal-autoscaler.yaml b/cn/docs/tasks/administer-cluster/dns-horizontal-autoscaler.yaml index f29dd2e275..b427829b5f 100644 --- a/cn/docs/tasks/administer-cluster/dns-horizontal-autoscaler.yaml +++ b/cn/docs/tasks/administer-cluster/dns-horizontal-autoscaler.yaml @@ -13,7 +13,7 @@ spec: spec: containers: - name: autoscaler - image: gcr.io/google_containers/cluster-proportional-autoscaler-amd64:1.0.0 + image: k8s.gcr.io/cluster-proportional-autoscaler-amd64:1.0.0 resources: requests: cpu: "20m" diff --git a/cn/docs/tasks/administer-cluster/pod1.yaml b/cn/docs/tasks/administer-cluster/pod1.yaml index 733aa97d99..560b6aa0fb 100644 --- a/cn/docs/tasks/administer-cluster/pod1.yaml +++ b/cn/docs/tasks/administer-cluster/pod1.yaml @@ -7,4 +7,4 @@ metadata: spec: containers: - name: pod-with-no-annotation-container - image: gcr.io/google_containers/pause:2.0 \ No newline at end of file + image: k8s.gcr.io/pause:2.0 \ No newline at end of file diff --git a/cn/docs/tasks/administer-cluster/pod2.yaml b/cn/docs/tasks/administer-cluster/pod2.yaml index e1e280ff09..2f065efe65 100644 --- a/cn/docs/tasks/administer-cluster/pod2.yaml +++ b/cn/docs/tasks/administer-cluster/pod2.yaml @@ -8,4 +8,4 @@ spec: schedulerName: default-scheduler containers: - name: pod-with-default-annotation-container - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 diff --git a/cn/docs/tasks/administer-cluster/pod3.yaml b/cn/docs/tasks/administer-cluster/pod3.yaml index 63be0e0aa3..a1b8db3200 100644 --- a/cn/docs/tasks/administer-cluster/pod3.yaml +++ b/cn/docs/tasks/administer-cluster/pod3.yaml @@ -8,4 +8,4 @@ spec: schedulerName: my-scheduler containers: - name: pod-with-second-annotation-container - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 diff --git a/cn/docs/tasks/configure-pod-container/exec-liveness.yaml b/cn/docs/tasks/configure-pod-container/exec-liveness.yaml index 7b04a5eb8d..1ecb6cc25f 100644 --- a/cn/docs/tasks/configure-pod-container/exec-liveness.yaml +++ b/cn/docs/tasks/configure-pod-container/exec-liveness.yaml @@ -15,7 +15,7 @@ spec: - -c - touch /tmp/healthy; sleep 30; rm -rf /tmp/healthy; sleep 600 - image: gcr.io/google_containers/busybox + image: k8s.gcr.io/busybox livenessProbe: exec: diff --git a/cn/docs/tasks/configure-pod-container/http-liveness.yaml b/cn/docs/tasks/configure-pod-container/http-liveness.yaml index 6381ab3d1a..9d15abcd02 100644 --- a/cn/docs/tasks/configure-pod-container/http-liveness.yaml +++ b/cn/docs/tasks/configure-pod-container/http-liveness.yaml @@ -9,7 +9,7 @@ spec: - name: liveness args: - /server - image: gcr.io/google_containers/liveness + image: k8s.gcr.io/liveness livenessProbe: httpGet: path: /healthz diff --git a/cn/docs/tasks/configure-pod-container/tcp-liveness-readiness.yaml b/cn/docs/tasks/configure-pod-container/tcp-liveness-readiness.yaml index 08065019c5..08fb77ff0f 100644 --- a/cn/docs/tasks/configure-pod-container/tcp-liveness-readiness.yaml +++ b/cn/docs/tasks/configure-pod-container/tcp-liveness-readiness.yaml @@ -7,7 +7,7 @@ metadata: spec: containers: - name: goproxy - image: gcr.io/google_containers/goproxy:0.1 + image: k8s.gcr.io/goproxy:0.1 ports: - containerPort: 8080 readinessProbe: diff --git a/cn/docs/tasks/debug-application-cluster/debug-application.md b/cn/docs/tasks/debug-application-cluster/debug-application.md index 11538f35de..cc4513e204 100644 --- a/cn/docs/tasks/debug-application-cluster/debug-application.md +++ b/cn/docs/tasks/debug-application-cluster/debug-application.md @@ -8,10 +8,6 @@ title: 应用故障排查 * TOC {:toc} -## FAQ - -强烈建议用户参考我们的[FAQ](https://github.com/kubernetes/kubernetes/wiki/User-FAQ). - ## 诊断问题 故障排查的第一步是先给问题分下类。这个问题是什么?Pods,Replication Controller或者Service? diff --git a/cn/docs/tasks/inject-data-application/dapi-envars-container.yaml b/cn/docs/tasks/inject-data-application/dapi-envars-container.yaml index 8b3b3a39d3..55bd4dd263 100644 --- a/cn/docs/tasks/inject-data-application/dapi-envars-container.yaml +++ b/cn/docs/tasks/inject-data-application/dapi-envars-container.yaml @@ -5,7 +5,7 @@ metadata: spec: containers: - name: test-container - image: gcr.io/google_containers/busybox:1.24 + image: k8s.gcr.io/busybox:1.24 command: [ "sh", "-c"] args: - while true; do diff --git a/cn/docs/tasks/inject-data-application/dapi-envars-pod.yaml b/cn/docs/tasks/inject-data-application/dapi-envars-pod.yaml index 00762373b3..071fa82bb3 100644 --- a/cn/docs/tasks/inject-data-application/dapi-envars-pod.yaml +++ b/cn/docs/tasks/inject-data-application/dapi-envars-pod.yaml @@ -5,7 +5,7 @@ metadata: spec: containers: - name: test-container - image: gcr.io/google_containers/busybox + image: k8s.gcr.io/busybox command: [ "sh", "-c"] args: - while true; do diff --git a/cn/docs/tasks/inject-data-application/dapi-volume-resources.yaml b/cn/docs/tasks/inject-data-application/dapi-volume-resources.yaml index 65770f283f..55af44ac1b 100644 --- a/cn/docs/tasks/inject-data-application/dapi-volume-resources.yaml +++ b/cn/docs/tasks/inject-data-application/dapi-volume-resources.yaml @@ -5,7 +5,7 @@ metadata: spec: containers: - name: client-container - image: gcr.io/google_containers/busybox:1.24 + image: k8s.gcr.io/busybox:1.24 command: ["sh", "-c"] args: - while true; do diff --git a/cn/docs/tasks/inject-data-application/dapi-volume.yaml b/cn/docs/tasks/inject-data-application/dapi-volume.yaml index 7126cefae5..864c99d11e 100644 --- a/cn/docs/tasks/inject-data-application/dapi-volume.yaml +++ b/cn/docs/tasks/inject-data-application/dapi-volume.yaml @@ -12,7 +12,7 @@ metadata: spec: containers: - name: client-container - image: gcr.io/google_containers/busybox + image: k8s.gcr.io/busybox command: ["sh", "-c"] args: - while true; do diff --git a/cn/docs/tasks/inject-data-application/define-command-argument-container.md b/cn/docs/tasks/inject-data-application/define-command-argument-container.md index 23fce58e28..abcef87811 100644 --- a/cn/docs/tasks/inject-data-application/define-command-argument-container.md +++ b/cn/docs/tasks/inject-data-application/define-command-argument-container.md @@ -63,7 +63,7 @@ title: 为容器设置启动时要执行的命令及其入参 args: ["$(MESSAGE)"] 这样一来,我们就可以将那些用来设置环境变量的方法应用于设置命令的入参,其 -中包括了[ConfigMaps](/docs/tasks/configure-pod-container/configmap/) +中包括了[ConfigMaps](/docs/tasks/configure-pod-container/configure-pod-configmap/) 与 [Secrets](/docs/concepts/configuration/secret/). diff --git a/cn/docs/tasks/manage-gpus/scheduling-gpus.md b/cn/docs/tasks/manage-gpus/scheduling-gpus.md index 208d01caf1..6aded77023 100644 --- a/cn/docs/tasks/manage-gpus/scheduling-gpus.md +++ b/cn/docs/tasks/manage-gpus/scheduling-gpus.md @@ -41,13 +41,13 @@ spec: containers: - name: gpu-container-1 - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 resources: limits: alpha.kubernetes.io/nvidia-gpu: 2 # requesting 2 GPUs - name: gpu-container-2 - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 resources: limits: alpha.kubernetes.io/nvidia-gpu: 3 # requesting 3 GPUs @@ -141,7 +141,7 @@ metadata: spec: containers: - name: gpu-container-1 - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 resources: limits: alpha.kubernetes.io/nvidia-gpu: 1 diff --git a/cn/docs/tutorials/configuration/configure-redis-using-configmap.md b/cn/docs/tutorials/configuration/configure-redis-using-configmap.md index 1c4b339df8..1b633e20c3 100644 --- a/cn/docs/tutorials/configuration/configure-redis-using-configmap.md +++ b/cn/docs/tutorials/configuration/configure-redis-using-configmap.md @@ -7,7 +7,7 @@ title: 使用ConfigMap来配置Redis {% capture overview %} -这篇文档基于[在Pods中使用ConfigMap数据](/docs/tasks/configure-pod-container/configure-pod-configmap/) 和 [使用ConfigMap来配置Containers](/docs/tasks/configure-pod-container/configmap/) 两个任务,提供了一个使用ConfigMap来配置Redis的真实案例。 +这篇文档基于[使用ConfigMap来配置Containers](/docs/tasks/configure-pod-container/configure-pod-configmap/) 这个任务,提供了一个使用ConfigMap来配置Redis的真实案例。 {% endcapture %} @@ -23,8 +23,7 @@ title: 使用ConfigMap来配置Redis {% capture prerequisites %} * {% include task-tutorial-prereqs.md %} -* 理解[在Pods中使用ConfigMap数据](/docs/tasks/configure-pod-container/configure-pod-configmap/)。 -* 理解[使用ConfigMap来配置Containers](/docs/tasks/configure-pod-container/configmap/)。 +* 理解[使用ConfigMap来配置Containers](/docs/tasks/configure-pod-container/configure-pod-configmap/)。 {% endcapture %} @@ -120,8 +119,7 @@ title: 使用ConfigMap来配置Redis {% capture whatsnext %} -* 了解关于[ConfigMaps](/docs/tasks/configure-pod-container/configmap/)的更多知识。 -* 参见[在Pods中使用ConfigMap数据](/docs/tasks/configure-pod-container/configure-pod-configmap/)。 +* 了解关于[ConfigMaps](/docs/tasks/configure-pod-container/configure-pod-configmap/)的更多知识。 {% endcapture %} diff --git a/cn/docs/tutorials/services/source-ip.md b/cn/docs/tutorials/services/source-ip.md index 18d0c4f902..92191c5cc4 100644 --- a/cn/docs/tutorials/services/source-ip.md +++ b/cn/docs/tutorials/services/source-ip.md @@ -33,7 +33,7 @@ Kubernetes 集群中运行的应用通过抽象的 Service 查找彼此,相互 你必须拥有一个正常工作的 Kubernetes 1.5 集群,用来运行本文中的示例。该示例使用一个简单的 nginx webserver 回送它接收到的请求的 HTTP 头中的源 IP 地址。你可以像下面这样创建它: ```console -$ kubectl run source-ip-app --image=gcr.io/google_containers/echoserver:1.4 +$ kubectl run source-ip-app --image=k8s.gcr.io/echoserver:1.4 deployment "source-ip-app" created ``` diff --git a/cn/docs/tutorials/stateful-application/basic-stateful-set.md b/cn/docs/tutorials/stateful-application/basic-stateful-set.md index 049c86de11..5f2b5f9edf 100644 --- a/cn/docs/tutorials/stateful-application/basic-stateful-set.md +++ b/cn/docs/tutorials/stateful-application/basic-stateful-set.md @@ -434,7 +434,7 @@ Kubernetes 1.7 版本的 StatefulSet 控制器支持自动更新。更新策略 Patch `web` StatefulSet 的容器镜像。 ```shell -kubectl patch statefulset web --type='json' -p='[{"op": "replace", "path": "/spec/template/spec/containers/0/image", "value":"gcr.io/google_containers/nginx-slim:0.7"}]' +kubectl patch statefulset web --type='json' -p='[{"op": "replace", "path": "/spec/template/spec/containers/0/image", "value":"k8s.gcr.io/nginx-slim:0.7"}]' "web" patched ``` @@ -470,9 +470,9 @@ web-0 1/1 Running 0 3s ```shell{% raw %} kubectl get pod -l app=nginx -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{.spec.containers[0].image}{"\n"}{end}' -web-0 gcr.io/google_containers/nginx-slim:0.7 -web-1 gcr.io/google_containers/nginx-slim:0.8 -web-2 gcr.io/google_containers/nginx-slim:0.8 +web-0 k8s.gcr.io/nginx-slim:0.7 +web-1 k8s.gcr.io/nginx-slim:0.8 +web-2 k8s.gcr.io/nginx-slim:0.8 {% endraw %}``` `web-0` has had its image updated, but `web-0` and `web-1` still have the original @@ -513,9 +513,9 @@ web-2 1/1 Running 0 36s ```shell{% raw %} kubectl get pod -l app=nginx -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{.spec.containers[0].image}{"\n"}{end}' -web-0 gcr.io/google_containers/nginx-slim:0.7 -web-1 gcr.io/google_containers/nginx-slim:0.7 -web-2 gcr.io/google_containers/nginx-slim:0.7 +web-0 k8s.gcr.io/nginx-slim:0.7 +web-1 k8s.gcr.io/nginx-slim:0.7 +web-2 k8s.gcr.io/nginx-slim:0.7 {% endraw %} ``` @@ -539,7 +539,7 @@ statefulset "web" patched 在一个终端窗口中 patch `web` StatefulSet 来再次的改变容器镜像。 ```shell -kubectl patch statefulset web --type='json' -p='[{"op": "replace", "path": "/spec/template/spec/containers/0/image", "value":"gcr.io/google_containers/nginx-slim:0.8"}]' +kubectl patch statefulset web --type='json' -p='[{"op": "replace", "path": "/spec/template/spec/containers/0/image", "value":"k8s.gcr.io/nginx-slim:0.8"}]' statefulset "web" patched ``` @@ -589,9 +589,9 @@ StatefulSet 里的 Pod 采用和序号相反的顺序更新。在更新下一个 ```shell{% raw %} for p in 0 1 2; do kubectl get po web-$p --template '{{range $i, $c := .spec.containers}}{{$c.image}}{{end}}'; echo; done -gcr.io/google_containers/nginx-slim:0.8 -gcr.io/google_containers/nginx-slim:0.8 -gcr.io/google_containers/nginx-slim:0.8 +k8s.gcr.io/nginx-slim:0.8 +k8s.gcr.io/nginx-slim:0.8 +k8s.gcr.io/nginx-slim:0.8 {% endraw %} ``` @@ -617,7 +617,7 @@ statefulset "web" patched 再次 Patch StatefulSet 来改变容器镜像。 ```shell -kubectl patch statefulset web --type='json' -p='[{"op": "replace", "path": "/spec/template/spec/containers/0/image", "value":"gcr.io/google_containers/nginx-slim:0.7"}]' +kubectl patch statefulset web --type='json' -p='[{"op": "replace", "path": "/spec/template/spec/containers/0/image", "value":"k8s.gcr.io/nginx-slim:0.7"}]' statefulset "web" patched ``` @@ -646,7 +646,7 @@ web-2 1/1 Running 0 18s ```shell{% raw %} get po web-2 --template '{{range $i, $c := .spec.containers}}{{$c.image}}{{end}}' -gcr.io/google_containers/nginx-slim:0.8 +k8s.gcr.io/nginx-slim:0.8 {% endraw %} ``` @@ -683,7 +683,7 @@ web-2 1/1 Running 0 18s ```shell{% raw %} kubectl get po web-2 --template '{{range $i, $c := .spec.containers}}{{$c.image}}{{end}}' -gcr.io/google_containers/nginx-slim:0.7 +k8s.gcr.io/nginx-slim:0.7 {% endraw %} ``` @@ -721,7 +721,7 @@ web-1 1/1 Running 0 18s ```shell{% raw %} get po web-1 --template '{{range $i, $c := .spec.containers}}{{$c.image}}{{end}}' -gcr.io/google_containers/nginx-slim:0.8 +k8s.gcr.io/nginx-slim:0.8 {% endraw %} ``` @@ -767,9 +767,9 @@ web-0 1/1 Running 0 3s ```shell{% raw %} for p in 0 1 2; do kubectl get po web-$p --template '{{range $i, $c := .spec.containers}}{{$c.image}}{{end}}'; echo; done -gcr.io/google_containers/nginx-slim:0.7 -gcr.io/google_containers/nginx-slim:0.7 -gcr.io/google_containers/nginx-slim:0.7 +k8s.gcr.io/nginx-slim:0.7 +k8s.gcr.io/nginx-slim:0.7 +k8s.gcr.io/nginx-slim:0.7 {% endraw %} ``` diff --git a/cn/docs/tutorials/stateful-application/web.yaml b/cn/docs/tutorials/stateful-application/web.yaml index f5f246c47f..e9f9b7e5d0 100644 --- a/cn/docs/tutorials/stateful-application/web.yaml +++ b/cn/docs/tutorials/stateful-application/web.yaml @@ -27,7 +27,7 @@ spec: spec: containers: - name: nginx - image: gcr.io/google_containers/nginx-slim:0.8 + image: k8s.gcr.io/nginx-slim:0.8 ports: - containerPort: 80 name: web diff --git a/cn/docs/tutorials/stateful-application/webp.yaml b/cn/docs/tutorials/stateful-application/webp.yaml index 0a56f234e0..c2ab595cf2 100644 --- a/cn/docs/tutorials/stateful-application/webp.yaml +++ b/cn/docs/tutorials/stateful-application/webp.yaml @@ -28,7 +28,7 @@ spec: spec: containers: - name: nginx - image: gcr.io/google_containers/nginx-slim:0.8 + image: k8s.gcr.io/nginx-slim:0.8 ports: - containerPort: 80 name: web diff --git a/cn/docs/tutorials/stateful-application/zookeeper.md b/cn/docs/tutorials/stateful-application/zookeeper.md index f6f3ef46f9..d6578d32e1 100644 --- a/cn/docs/tutorials/stateful-application/zookeeper.md +++ b/cn/docs/tutorials/stateful-application/zookeeper.md @@ -25,7 +25,7 @@ title: 运行 ZooKeeper, 一个 CP 分布式系统 * [Headless Services](/docs/concepts/services-networking/service/#headless-services) * [PersistentVolumes](/docs/concepts/storage/volumes/) * [PersistentVolume Provisioning](http://releases.k8s.io/{{page.githubbranch}}/examples/persistent-volume-provisioning/) -* [ConfigMaps](/docs/tasks/configure-pod-container/configmap/) +* [ConfigMaps](/docs/tasks/configure-pod-container/configure-pod-configmap/) * [StatefulSets](/docs/concepts/abstractions/controllers/statefulsets/) * [PodDisruptionBudgets](/docs/admin/disruptions/#specifying-a-poddisruptionbudget) * [PodAntiAffinity](/docs/user-guide/node-selection/#inter-pod-affinity-and-anti-affinity-beta-feature) @@ -67,7 +67,7 @@ ZooKeeper 在内存中保存它们的整个状态机,但是每个改变都被 ## 创建一个 ZooKeeper Ensemble -下面的清单包含一个 [Headless Service](/docs/user-guide/services/#headless-services),一个 [ConfigMap](/docs/tasks/configure-pod-container/configmap/),一个 [PodDisruptionBudget](/docs/admin/disruptions/#specifying-a-poddisruptionbudget) 和 一个 [StatefulSet](/docs/concepts/abstractions/controllers/statefulsets/)。 +下面的清单包含一个 [Headless Service](/docs/user-guide/services/#headless-services),一个 [ConfigMap](/docs/tasks/configure-pod-container/configure-pod-configmap/),一个 [PodDisruptionBudget](/docs/admin/disruptions/#specifying-a-poddisruptionbudget) 和 一个 [StatefulSet](/docs/concepts/abstractions/controllers/statefulsets/)。 {% include code.html language="yaml" file="zookeeper.yaml" ghlink="/docs/tutorials/stateful-application/zookeeper.yaml" %} diff --git a/cn/index.html b/cn/index.html index 63e059c497..7443e05d59 100644 --- a/cn/index.html +++ b/cn/index.html @@ -107,7 +107,7 @@ cid: home

Kubernetes 逐渐部署对应用程序或其配置的更改,同时监视应用程序运行状况,以确保它不会同时终止所有实例。 如果出现问题,Kubernetes会为您恢复更改,利用日益增长的部署解决方案的生态系统。

-

密钥配置 管理

+

密钥配置 管理

部署和更新密钥和应用程序配置,不会重新编译您的镜像,不会在堆栈配置中暴露密钥(secrets)。

diff --git a/code-of-conduct.md b/code-of-conduct.md new file mode 100644 index 0000000000..0d15c00cf3 --- /dev/null +++ b/code-of-conduct.md @@ -0,0 +1,3 @@ +# Kubernetes Community Code of Conduct + +Please refer to our [Kubernetes Community Code of Conduct](https://git.k8s.io/community/code-of-conduct.md) diff --git a/community/index.html b/community/index.html index d15a52f0e8..43225786a1 100644 --- a/community/index.html +++ b/community/index.html @@ -24,7 +24,7 @@ cid: community

Special Interest Groups (SIGs)

Have a special interest in how Kubernetes works with another technology? See our ever growing - lists of SIGs, + lists of SIGs, from AWS and Openstack to Big Data and Scalability, there's a place for you to contribute and instructions for forming a new SIG if your special interest isn't covered (yet).

@@ -35,13 +35,13 @@ cid: community frameborder="0" scrolling="no">
-
+ diff --git a/docs/admin/admission-controllers.md b/docs/admin/admission-controllers.md index ae175d1bd5..ca063be2c6 100644 --- a/docs/admin/admission-controllers.md +++ b/docs/admin/admission-controllers.md @@ -56,6 +56,19 @@ support all the features you expect. The Kubernetes API server supports a flag, `admission-control` that takes a comma-delimited, ordered list of admission control choices to invoke prior to modifying objects in the cluster. +For example, the following command line turns on the `NamespaceLifecycle` and the `LimitRanger` +admission controller: + +```shell +kube-apiserver --admission-control=NamespaceLifecyle,LimitRanger ... +``` + +**Note**: Depending on the way your Kubernetes cluster is deployed and how the +API server is started, you may need to apply the settings in different ways. +For example, you may have to modify the systemd unit file if the API server is +deployed as a systemd service, you may modify the manifest file for the API +server if Kubernetes is deployed in a self-hosted way. +{: .note} ## What does each admission controller do? @@ -321,7 +334,7 @@ If a webhook called by this has side effects (for example, decrementing quota) i webhooks or validating admission controllers will permit the request to finish. If you disable the MutatingAdmissionWebhook, you must also disable the -`MutatingWebhookConfiguration` object in the `admissionregistration/v1beta1` +`MutatingWebhookConfiguration` object in the `admissionregistration.k8s.io/v1beta1` group/version via the `--runtime-config` flag (both are on by default in versions >= 1.9). @@ -522,7 +535,7 @@ If a webhook called by this has side effects (for example, decrementing quota) i webhooks or other validating admission controllers will permit the request to finish. If you disable the ValidatingAdmissionWebhook, you must also disable the -`ValidatingWebhookConfiguration` object in the `admissionregistration/v1beta1` +`ValidatingWebhookConfiguration` object in the `admissionregistration.k8s.io/v1beta1` group/version via the `--runtime-config` flag (both are on by default in versions >= 1.9). diff --git a/docs/admin/authentication.md b/docs/admin/authentication.md index 2dc4e9fd58..8d3bd1885f 100644 --- a/docs/admin/authentication.md +++ b/docs/admin/authentication.md @@ -196,10 +196,10 @@ spec: metadata: # ... spec: + serviceAccountName: bob-the-bot containers: - name: nginx image: nginx:1.7.9 - serviceAccountName: bob-the-bot ``` Service account bearer tokens are perfectly valid to use outside the cluster and diff --git a/docs/admin/authorization/rbac.md b/docs/admin/authorization/rbac.md index a2222b8822..83649663b6 100644 --- a/docs/admin/authorization/rbac.md +++ b/docs/admin/authorization/rbac.md @@ -851,7 +851,7 @@ You can use that information to determine which roles need to be granted to whic Once you have [granted roles to service accounts](#service-account-permissions) and workloads are running with no RBAC denial messages in the server logs, you can remove the ABAC authorizer. -### Permissive RBAC Permissions +## Permissive RBAC Permissions You can replicate a permissive policy using RBAC role bindings. diff --git a/docs/admin/bootstrap-tokens.md b/docs/admin/bootstrap-tokens.md index 552f056337..e84fd2cd6e 100644 --- a/docs/admin/bootstrap-tokens.md +++ b/docs/admin/bootstrap-tokens.md @@ -36,74 +36,86 @@ information. It is used when referring to a token without leaking the secret part used for authentication. The second part is the "Token Secret" and should only be shared with trusted parties. -## Enabling Bootstrap Tokens +## Enabling Bootstrap Token Authentication -All features for Bootstrap Tokens are disabled by default in Kubernetes v1.8. +The Bootstrap Token authenticator can be enabled using the following flag on the +API server: -You can enable the Bootstrap Token authenticator with the -`--enable-bootstrap-token-auth` flag on the API server. You can enable -the Bootstrap controllers by specifying them with the `--controllers` flag on the -controller manager with something like -`--controllers=*,tokencleaner,bootstrapsigner`. This is done automatically when -using `kubeadm`. +``` +--enable-bootstrap-token-auth +``` -Tokens are used in an HTTPS call as follows: +When enabled, bootstrapping tokens can be used as bearer token credentials to +authenticate requests against the API server. ```http Authorization: Bearer 07401b.f395accd246ae52d ``` +Tokens authenticate as the username `system:bootstrap:` and are members +of the group `system:bootstrappers`. Additional groups may be specified in the +token's Secret. + +Expired tokens can be deleted automatically by enabling the `tokencleaner` +controller on the controller manager. + +``` +--controllers=*,tokencleaner +``` + ## Bootstrap Token Secret Format Each valid token is backed by a secret in the `kube-system` namespace. You can find the full design doc [here](https://github.com/kubernetes/community/blob/{{page.githubbranch}}/contributors/design-proposals/cluster-lifecycle/bootstrap-discovery.md). -Here is what the secret looks like. Note that `base64(string)` indicates the -value should be base64 encoded. The undecoded version is provided here for -readability. +Here is what the secret looks like. ```yaml apiVersion: v1 kind: Secret metadata: + # Name MUST be of form "bootstrap-token-" name: bootstrap-token-07401b namespace: kube-system + +# Type MUST be 'bootstrap.kubernetes.io/token' type: bootstrap.kubernetes.io/token -data: - description: base64(The default bootstrap token generated by 'kubeadm init'.) - token-id: base64(07401b) - token-secret: base64(f395accd246ae52d) - expiration: base64(2017-03-10T03:22:11Z) - usage-bootstrap-authentication: base64(true) - usage-bootstrap-signing: base64(true) - auth-extra-groups: base64(system:bootstrappers:group1,system:bootstrappers:group2) +stringData: + # Human readable description. Optional. + description: "The default bootstrap token generated by 'kubeadm init'." + + # Token ID and secret. Required. + token-id: 07401b + token-secret: f395accd246ae52d + + # Expiration. Optional. + expiration: 2017-03-10T03:22:11Z + + # Allowed usages. + usage-bootstrap-authentication: true + usage-bootstrap-signing: true + + # Extra groups to authenticate the token as. Must start with "system:bootstrappers:" + auth-extra-groups: system:bootstrappers:worker,system:bootstrappers:ingress ``` The type of the secret must be `bootstrap.kubernetes.io/token` and the name must be `bootstrap-token-`. It must also exist in the `kube-system` -namespace. `description` is a human readable description that should not be -used for machine readable information. The Token ID and Secret are included in -the data dictionary. +namespace. The `usage-bootstrap-*` members indicate what this secret is intended to be used for. A value must be set to `true` to be enabled. -`usage-bootstrap-authentication` indicates that the token can be used to -authenticate to the API server. The authenticator authenticates as -`system:bootstrap:`. It is included in the `system:bootstrappers` -group. `auth-extra-groups` indicates that it will also be included in the -`system:bootstrappers:group1`, and `system:bootstrappers:group2` groups. The -naming and groups are intentionally limited to discourage users from using these -tokens past bootstrapping. Extra bootstrap token groups must start with -`system:bootstrappers:`. - -`usage-bootstrap-signing` indicates that the token should be used to sign the +* `usage-bootstrap-authentication` indicates that the token can be used to +authenticate to the API server as a bearer token. +* `usage-bootstrap-signing` indicates that the token may be used to sign the `cluster-info` ConfigMap as described below. -The `expiration` data member lists a time after which the token is no longer -valid. This is encoded as an absolute UTC time using RFC3339. The TokenCleaner -controller will delete expired tokens. +The `expiration` field controls the expiry of the token. Expired tokens are +rejected when used for authentication and ignored during ConfigMap signing. +The expiry value is encoded as an absolute UTC time using RFC3339. Enable the +`tokencleaner` controller to automatically delete expired tokens. ## Token Management with `kubeadm` @@ -116,6 +128,13 @@ In addition to authentication, the tokens can be used to sign a ConfigMap. This is used early in a cluster bootstrap process before the client trusts the API server. The signed ConfigMap can be authenticated by the shared token. +Enable ConfigMap signing by enabling the `bootstrapsigner` controller on the +Controller Manager. + +``` +--controllers=*,bootstrapsigner +``` + The ConfigMap that is signed is `cluster-info` in the `kube-public` namespace. The typical flow is that a client reads this ConfigMap while unauthenticated and ignoring TLS errors. It then validates the payload of the ConfigMap by looking @@ -156,3 +175,11 @@ is then used to form a whole JWS by inserting it between the 2 dots. You can verify the JWS using the `HS256` scheme (HMAC-SHA256) with the full token (e.g. `07401b.f395accd246ae52d`) as the shared secret. Users _must_ verify that HS256 is used. + +WARNING: Any party with a bootstrapping token can create a valid signature for that +token. When using ConfigMap signing it's discouraged to share the same token with +many clients, since a compromised client can potentially man-in-the middle another +client relying on the signature to bootstrap TLS trust. + +Consult the [kubeadm security model](/docs/reference/generated/kubeadm/#security-model) +section for more information. diff --git a/docs/admin/cluster-large.md b/docs/admin/cluster-large.md index b443d42132..21c50531aa 100644 --- a/docs/admin/cluster-large.md +++ b/docs/admin/cluster-large.md @@ -86,7 +86,7 @@ For example: ```yaml containers: - name: fluentd-cloud-logging - image: gcr.io/google_containers/fluentd-gcp:1.16 + image: k8s.gcr.io/fluentd-gcp:1.16 resources: limits: cpu: 100m diff --git a/docs/admin/federation/index.md b/docs/admin/federation/index.md index 9127a1aa36..f52fb5a035 100644 --- a/docs/admin/federation/index.md +++ b/docs/admin/federation/index.md @@ -87,9 +87,9 @@ images or you can build them yourself from HEAD. ### Using official release images As part of every Kubernetes release, official release images are pushed to -`gcr.io/google_containers`. To use the images in this repository, you can +`k8s.gcr.io`. To use the images in this repository, you can set the container image fields in the following configs to point to the -images in this repository. `gcr.io/google_containers/hyperkube` image +images in this repository. `k8s.gcr.io/hyperkube` image includes the federation-apiserver and federation-controller-manager binaries, so you can point the corresponding configs for those components to the hyperkube image. @@ -247,7 +247,7 @@ federation, and in your federation DNS. You can find more details about config maps in general at -[config map](/docs/tasks/configure-pod-container/configmap/). +[config map](/docs/tasks/configure-pod-container/configure-pod-configmap/). ### Kubernetes 1.4 and earlier: Setting federations flag on kube-dns-rc @@ -315,8 +315,8 @@ official release images or you can build from HEAD. #### Using official release images -As part of every release, images are pushed to `gcr.io/google_containers`. To use -these images, set env var `FEDERATION_PUSH_REPO_BASE=gcr.io/google_containers` +As part of every release, images are pushed to `k8s.gcr.io`. To use +these images, set env var `FEDERATION_PUSH_REPO_BASE=k8s.gcr.io` This will always use the latest image. To use the hyperkube image which includes federation-apiserver and federation-controller-manager from a specific release, set the @@ -345,7 +345,7 @@ Once you have the images, you can run these as pods on your existing kubernetes The command to run these pods on an existing GCE cluster will look like: ```shell -$ KUBERNETES_PROVIDER=gce FEDERATION_DNS_PROVIDER=google-clouddns FEDERATION_NAME=myfederation DNS_ZONE_NAME=myfederation.example FEDERATION_PUSH_REPO_BASE=gcr.io/google_containers ./federation/cluster/federation-up.sh +$ KUBERNETES_PROVIDER=gce FEDERATION_DNS_PROVIDER=google-clouddns FEDERATION_NAME=myfederation DNS_ZONE_NAME=myfederation.example FEDERATION_PUSH_REPO_BASE=k8s.gcr.io ./federation/cluster/federation-up.sh ``` `KUBERNETES_PROVIDER` is the cloud provider. diff --git a/docs/admin/high-availability/etcd.yaml b/docs/admin/high-availability/etcd.yaml index 8bcf52b159..364791da6f 100644 --- a/docs/admin/high-availability/etcd.yaml +++ b/docs/admin/high-availability/etcd.yaml @@ -5,7 +5,7 @@ metadata: spec: hostNetwork: true containers: - - image: gcr.io/google_containers/etcd:3.0.17 + - image: k8s.gcr.io/etcd:3.0.17 name: etcd-container command: - /usr/local/bin/etcd diff --git a/docs/admin/high-availability/index.md b/docs/admin/high-availability/index.md index 0b0cf61708..8516613493 100644 --- a/docs/admin/high-availability/index.md +++ b/docs/admin/high-availability/index.md @@ -175,6 +175,57 @@ For pods that you deploy into the cluster, the `kubernetes` service/dns name sho For external users of the API (e.g. the `kubectl` command line interface, continuous build pipelines, or other clients) you will want to configure them to talk to the external load balancer's IP address. +### Endpoint reconciler + +As mentioned in the previous section, the apiserver is exposed through a +service called `kubernetes`. The endpoints for this service correspond to +the apiserver replicas that we just deployed. + +Since updating endpoints and services requires the apiserver to be up, there +is special code in the apiserver to let it update its own endpoints directly. +This code is called the "reconciler," because it reconciles the list of +endpoints stored in etcd, and the list of endpoints that are actually up +and running. + +Prior Kubernetes 1.9, the reconciler expects you to provide the +number of endpoints (i.e., the number of apiserver replicas) through +a command-line flag (e.g. `--apiserver-count=3`). If more replicas +are available, the reconciler trims down the list of endpoints. +As a result, if a node running a replica of the apiserver crashes +and gets replaced, the list of endpoints is eventually updated. +However, until the replica gets replaced, its endpoint stays in +the list. During that time, a fraction of the API requests sent +to the `kubernetes` service will fail, because they will be sent +to a down endpoint. + +This is why the previous section advises you to deploy a load +balancer, and access the API through that load balancer. The +load balancer will directly assess the health of the apiserver +replicas, and make sure that requests are not sent to crashed +instances. + +If you do not add the `--apiserver-count` flag, the value defaults to 1. +Your cluster will work correctly, but each apiserver replica will +continuously try to add itself to the list of endpoints while removing +the other ones, causing a lot of extraneous updates in kube-proxy +and other components. + +Starting with Kubernetes 1.9, a new reconciler implementation is available. +It uses a *lease* that is regularly renewed by each apiserver +replica. When a replica is down, it stops renewing its lease, and +the other replicas notice that the lease expired and remove it +from the list of endpoints. You can switch to the new reconciler +by adding the flag `--endpoint-reconciler-type=lease` when starting +your apiserver replicas. + +If you want to know more, you can check the following resources: +- [issue kubernetes/kuberenetes#22609](https://github.com/kubernetes/kubernetes/issues/22609), + which gives additional context +- [master/reconcilers/mastercount.go](https://github.com/kubernetes/kubernetes/blob/dd9981d038012c120525c9e6df98b3beb3ef19e1/pkg/master/reconcilers/mastercount.go#L63), + the implementation of the master count reconciler +- [PR kubernetes/kubernetes#51698](https://github.com/kubernetes/kubernetes/pull/51698), + which adds support for the lease reconciler + ## Master elected components So far we have set up state storage, and we have set up the API server, but we haven't run anything that actually modifies diff --git a/docs/admin/high-availability/kube-apiserver.yaml b/docs/admin/high-availability/kube-apiserver.yaml index 33d5cff5cd..057764fc52 100644 --- a/docs/admin/high-availability/kube-apiserver.yaml +++ b/docs/admin/high-availability/kube-apiserver.yaml @@ -6,7 +6,7 @@ spec: hostNetwork: true containers: - name: kube-apiserver - image: gcr.io/google_containers/kube-apiserver:9680e782e08a1a1c94c656190011bd02 + image: k8s.gcr.io/kube-apiserver:9680e782e08a1a1c94c656190011bd02 command: - /bin/sh - -c diff --git a/docs/admin/high-availability/kube-controller-manager.yaml b/docs/admin/high-availability/kube-controller-manager.yaml index 0ecbebb276..ba481fbfc3 100644 --- a/docs/admin/high-availability/kube-controller-manager.yaml +++ b/docs/admin/high-availability/kube-controller-manager.yaml @@ -10,7 +10,7 @@ spec: - /usr/local/bin/kube-controller-manager --master=127.0.0.1:8080 --cluster-name=e2e-test-bburns --cluster-cidr=10.245.0.0/16 --allocate-node-cidrs=true --cloud-provider=gce --service-account-private-key-file=/srv/kubernetes/server.key --v=2 --leader-elect=true 1>>/var/log/kube-controller-manager.log 2>&1 - image: gcr.io/google_containers/kube-controller-manager:fda24638d51a48baa13c35337fcd4793 + image: k8s.gcr.io/kube-controller-manager:fda24638d51a48baa13c35337fcd4793 livenessProbe: httpGet: path: /healthz diff --git a/docs/admin/high-availability/kube-scheduler.yaml b/docs/admin/high-availability/kube-scheduler.yaml index 40c863da48..b4ef0e466e 100644 --- a/docs/admin/high-availability/kube-scheduler.yaml +++ b/docs/admin/high-availability/kube-scheduler.yaml @@ -6,7 +6,7 @@ spec: hostNetwork: true containers: - name: kube-scheduler - image: gcr.io/google_containers/kube-scheduler:34d0b8f8b31e27937327961528739bc9 + image: k8s.gcr.io/kube-scheduler:34d0b8f8b31e27937327961528739bc9 command: - /bin/sh - -c diff --git a/docs/admin/high-availability/podmaster.yaml b/docs/admin/high-availability/podmaster.yaml index d634225b93..cd20e15b38 100644 --- a/docs/admin/high-availability/podmaster.yaml +++ b/docs/admin/high-availability/podmaster.yaml @@ -6,7 +6,7 @@ spec: hostNetwork: true containers: - name: scheduler-elector - image: gcr.io/google_containers/podmaster:1.1 + image: k8s.gcr.io/podmaster:1.1 command: - /podmaster - --etcd-servers=http://127.0.0.1:4001 @@ -20,7 +20,7 @@ spec: - mountPath: /manifests name: manifests - name: controller-manager-elector - image: gcr.io/google_containers/podmaster:1.1 + image: k8s.gcr.io/podmaster:1.1 command: - /podmaster - --etcd-servers=http://127.0.0.1:4001 diff --git a/docs/admin/limitrange/invalid-pod.yaml b/docs/admin/limitrange/invalid-pod.yaml index b63f25deba..ecb45dd95f 100644 --- a/docs/admin/limitrange/invalid-pod.yaml +++ b/docs/admin/limitrange/invalid-pod.yaml @@ -5,7 +5,7 @@ metadata: spec: containers: - name: kubernetes-serve-hostname - image: gcr.io/google_containers/serve_hostname + image: k8s.gcr.io/serve_hostname resources: limits: cpu: "3" diff --git a/docs/admin/limitrange/valid-pod.yaml b/docs/admin/limitrange/valid-pod.yaml index c1ec54183b..d83e91267a 100644 --- a/docs/admin/limitrange/valid-pod.yaml +++ b/docs/admin/limitrange/valid-pod.yaml @@ -7,7 +7,7 @@ metadata: spec: containers: - name: kubernetes-serve-hostname - image: gcr.io/google_containers/serve_hostname + image: k8s.gcr.io/serve_hostname resources: limits: cpu: "1" diff --git a/docs/admin/multiple-schedulers/pod1.yaml b/docs/admin/multiple-schedulers/pod1.yaml index 6cf8fec25a..60cdab226d 100644 --- a/docs/admin/multiple-schedulers/pod1.yaml +++ b/docs/admin/multiple-schedulers/pod1.yaml @@ -7,4 +7,4 @@ metadata: spec: containers: - name: pod-with-no-annotation-container - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 diff --git a/docs/admin/multiple-schedulers/pod2.yaml b/docs/admin/multiple-schedulers/pod2.yaml index e1e280ff09..2f065efe65 100644 --- a/docs/admin/multiple-schedulers/pod2.yaml +++ b/docs/admin/multiple-schedulers/pod2.yaml @@ -8,4 +8,4 @@ spec: schedulerName: default-scheduler containers: - name: pod-with-default-annotation-container - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 diff --git a/docs/admin/multiple-schedulers/pod3.yaml b/docs/admin/multiple-schedulers/pod3.yaml index 63be0e0aa3..a1b8db3200 100644 --- a/docs/admin/multiple-schedulers/pod3.yaml +++ b/docs/admin/multiple-schedulers/pod3.yaml @@ -8,4 +8,4 @@ spec: schedulerName: my-scheduler containers: - name: pod-with-second-annotation-container - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 diff --git a/docs/admin/multiple-zones.md b/docs/admin/multiple-zones.md index 3f590016c0..1900e7e1a4 100644 --- a/docs/admin/multiple-zones.md +++ b/docs/admin/multiple-zones.md @@ -43,7 +43,7 @@ placement, and so if the zones in your cluster are heterogeneous (e.g. different numbers of nodes, different types of nodes, or different pod resource requirements), this might prevent perfectly even spreading of your pods across zones. If desired, you can use -homogenous zones (same number and types of nodes) to reduce the +homogeneous zones (same number and types of nodes) to reduce the probability of unequal spreading. When persistent volumes are created, the `PersistentVolumeLabel` diff --git a/docs/admin/namespaces/OWNERS b/docs/admin/namespaces/OWNERS deleted file mode 100644 index cca389a741..0000000000 --- a/docs/admin/namespaces/OWNERS +++ /dev/null @@ -1,4 +0,0 @@ -approvers: -- derekwaynecarr -- janetkuo - diff --git a/docs/admin/namespaces/namespace-dev.json b/docs/admin/namespaces/namespace-dev.json deleted file mode 100644 index b2b43b0b73..0000000000 --- a/docs/admin/namespaces/namespace-dev.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "kind": "Namespace", - "apiVersion": "v1", - "metadata": { - "name": "development", - "labels": { - "name": "development" - } - } -} diff --git a/docs/admin/node-conformance.md b/docs/admin/node-conformance.md index 5c3997fe53..5b6a1297fa 100644 --- a/docs/admin/node-conformance.md +++ b/docs/admin/node-conformance.md @@ -48,7 +48,7 @@ other Kubelet flags you may care: # $LOG_DIR is the test output path. sudo docker run -it --rm --privileged --net=host \ -v /:/rootfs -v $CONFIG_DIR:$CONFIG_DIR -v $LOG_DIR:/var/result \ - gcr.io/google_containers/node-test:0.2 + k8s.gcr.io/node-test:0.2 ``` ## Running Node Conformance Test for Other Architectures @@ -71,7 +71,7 @@ regular expression of tests you want to run. sudo docker run -it --rm --privileged --net=host \ -v /:/rootfs:ro -v $CONFIG_DIR:$CONFIG_DIR -v $LOG_DIR:/var/result \ -e FOCUS=MirrorPod \ # Only run MirrorPod test - gcr.io/google_containers/node-test:0.2 + k8s.gcr.io/node-test:0.2 ``` To skip specific tests, overwrite the environment variable `SKIP` with the @@ -81,7 +81,7 @@ regular expression of tests you want to skip. sudo docker run -it --rm --privileged --net=host \ -v /:/rootfs:ro -v $CONFIG_DIR:$CONFIG_DIR -v $LOG_DIR:/var/result \ -e SKIP=MirrorPod \ # Run all conformance tests but skip MirrorPod test - gcr.io/google_containers/node-test:0.2 + k8s.gcr.io/node-test:0.2 ``` Node conformance test is a containerized version of [node e2e test](https://github.com/kubernetes/community/blob/{{page.githubbranch}}/contributors/devel/e2e-node-tests.md). diff --git a/docs/api-reference/v1.9/index.html b/docs/api-reference/v1.9/index.html index 18cc2917db..c255107dc7 100644 --- a/docs/api-reference/v1.9/index.html +++ b/docs/api-reference/v1.9/index.html @@ -56950,7 +56950,7 @@ Appears In: names
string array -Names by which this image is known. e.g. ["gcr.io/google_containers/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"] +Names by which this image is known. e.g. ["k8s.gcr.io/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"] sizeBytes
integer diff --git a/docs/concepts/api-extension/custom-resources.md b/docs/concepts/api-extension/custom-resources.md index 710a334a48..eb24a70fb0 100644 --- a/docs/concepts/api-extension/custom-resources.md +++ b/docs/concepts/api-extension/custom-resources.md @@ -55,7 +55,7 @@ In a Declarative API, typically: - the main operations on the objects are CRUD-y (creating, reading, updating and deleting) - transactions across objects are not required: the API represents a desired state, not an exact state. -Imperative APIs are not declarative. +Imperative APIs are not declarative. Signs that your API might not be declarative include: - the client says "do this", and then gets a synchornous response back when it is done. - the client says "do this", and then gets an operation ID back, and has to check a separate Operation objects to determine completion of the request. @@ -98,7 +98,7 @@ Kubernetes provides two ways to add custom resources to your cluster: Kubernetes provides these two options to meet the needs of different users, so that neither ease of use nor flexibility are compromised. -Aggregated APIs are subordinate APIServers that sit behind the primary API server, which acts as a proxy. This arrangement is called [API Aggregation](docs/concepts/api-extension/apiserver-aggregation.md) (AA). To users, it simply appears that the Kubernetes API is extended. +Aggregated APIs are subordinate APIServers that sit behind the primary API server, which acts as a proxy. This arrangement is called [API Aggregation](/docs/concepts/api-extension/apiserver-aggregation/) (AA). To users, it simply appears that the Kubernetes API is extended. Custom Resource Definitions (CRDS) allow users to create new types of resources without adding another APIserver. You do not need to understand API Aggregation to use CRDs. @@ -112,7 +112,7 @@ This frees you from writing your own API server to handle the custom resource, but the generic nature of the implementation means you have less flexibility than with [API server aggregation](#api-server-aggregation). -Refer to the [Custom Controler example, which uses Custom Resources](https://github.com/kubernetes/sample-controller) +Refer to the [Custom Controller example, which uses Custom Resources](https://github.com/kubernetes/sample-controller) for a demonstration of how to register a new custom resource, work with instances of your new resource type, and setup a controller to handle events. diff --git a/docs/concepts/architecture/cloud-controller.md b/docs/concepts/architecture/cloud-controller.md index 12d5e13c53..fe87703e9a 100644 --- a/docs/concepts/architecture/cloud-controller.md +++ b/docs/concepts/architecture/cloud-controller.md @@ -97,7 +97,7 @@ The Node controller contains the cloud-dependent functionality of the kubelet. P In this new model, the kubelet initializes a node without cloud-specific information. However, it adds a taint to the newly created node that makes the node unschedulable until the CCM initializes the node with cloud-specific information, and then removes this taint. -### 3. Kubernets API server +### 3. Kubernetes API server The PersistentVolumeLabels controller moves the cloud-dependent functionality of the Kubernetes API server to the CCM as described in the preceding sections. @@ -174,7 +174,7 @@ v1/ServiceAccount: The RBAC ClusterRole for the CCM looks like this: ```yaml -apiVersion: rbac.authorization.k8s.io/v1beta1 +apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: cloud-controller-manager diff --git a/docs/concepts/architecture/nodes.md b/docs/concepts/architecture/nodes.md index 4cc4424111..27b9e01e30 100644 --- a/docs/concepts/architecture/nodes.md +++ b/docs/concepts/architecture/nodes.md @@ -265,7 +265,7 @@ metadata: spec: containers: - name: sleep-forever - image: gcr.io/google_containers/pause:0.8.0 + image: k8s.gcr.io/pause:0.8.0 resources: requests: cpu: 100m diff --git a/docs/concepts/cluster-administration/addons.md b/docs/concepts/cluster-administration/addons.md index 7099338c4d..fee92ecae5 100644 --- a/docs/concepts/cluster-administration/addons.md +++ b/docs/concepts/cluster-administration/addons.md @@ -17,10 +17,10 @@ Add-ons in each section are sorted alphabetically - the ordering does not imply * [Cilium](https://github.com/cilium/cilium) is a L3 network and network policy plugin that can enforce HTTP/API/L7 policies transparently. Both routing and overlay/encapsulation mode are supported. * [CNI-Genie](https://github.com/Huawei-PaaS/CNI-Genie) enables Kubernetes to seamlessly connect to a choice of CNI plugins, such as Calico, Canal, Flannel, Romana, or Weave. * [Contiv](http://contiv.github.io) provides configurable networking (native L3 using BGP, overlay using vxlan, classic L2, and Cisco-SDN/ACI) for various use cases and a rich policy framework. Contiv project is fully [open sourced](http://github.com/contiv). The [installer](http://github.com/contiv/install) provides both kubeadm and non-kubeadm based installation options. -* [Flannel](https://github.com/coreos/flannel/blob/master/Documentation/kube-flannel.yml) is an overlay network provider that can be used with Kubernetes. -* [Multus](https://github.com/Intel-Corp/multus-cni) is a Multi plugin for multiple network support in Kubernetes to support all CNI plugins (e.g. Calico, Cilium, Contiv, Flannel), in addition to SRIOV, DPDK, OVS-DPDK and VPP based workloads in Kubernetes. +* [Flannel](https://github.com/coreos/flannel/blob/master/Documentation/kubernetes.md) is an overlay network provider that can be used with Kubernetes. +* [Multus](https://github.com/Intel-Corp/multus-cni) is a Multi plugin for multiple network support in Kubernetes to support all CNI plugins (e.g. Calico, Cilium, Contiv, Flannel), in addition to SRIOV, DPDK, OVS-DPDK and VPP based workloads in Kubernetes. * [NSX-T](https://docs.vmware.com/en/VMware-NSX-T/2.0/nsxt_20_ncp_kubernetes.pdf) Container Plug-in (NCP) provides integration between VMware NSX-T and container orchestrators such as Kubernetes, as well as integration between NSX-T and container-based CaaS/PaaS platforms such as Pivotal Container Service (PKS) and Openshift. -* [Nuage](https://github.com/nuagenetworks/nuage-kubernetes/blob/v5.1.1-1/docs/kubernetes-1-installation.rst) is an SDN platform that provides policy-based networking between Kubernetes Pods and non-Kubernetes environments with visibility and security monitoring. +* [Nuage](https://github.com/nuagenetworks/nuage-kubernetes/blob/v5.1.1-1/docs/kubernetes-1-installation.rst) is an SDN platform that provides policy-based networking between Kubernetes Pods and non-Kubernetes environments with visibility and security monitoring. * [Romana](http://romana.io) is a Layer 3 networking solution for pod networks that also supports the [NetworkPolicy API](/docs/concepts/services-networking/network-policies/). Kubeadm add-on installation details available [here](https://github.com/romana/romana/tree/master/containerize). * [Weave Net](https://www.weave.works/docs/net/latest/kube-addon/) provides networking and network policy, will carry on working on both sides of a network partition, and does not require an external database. diff --git a/docs/concepts/cluster-administration/controller-metrics.md b/docs/concepts/cluster-administration/controller-metrics.md index ceca94f7de..2f1c71e34a 100644 --- a/docs/concepts/cluster-administration/controller-metrics.md +++ b/docs/concepts/cluster-administration/controller-metrics.md @@ -13,10 +13,10 @@ the controller manager. Controller manager metrics provide important insight into the performance and health of the controller manager. These metrics include common Go language runtime metrics such as go_routine count and controller specific metrics such as -etcd request latencies or Cloudprovider (AWS, GCE, Openstack) API latencies that can be used +etcd request latencies or Cloudprovider (AWS, GCE, OpenStack) API latencies that can be used to gauge the health of a cluster. -Starting from Kubernetes 1.7, detailed Cloudprovider metrics are available for storage operations for GCE, AWS, Vsphere and Openstack. +Starting from Kubernetes 1.7, detailed Cloudprovider metrics are available for storage operations for GCE, AWS, Vsphere and OpenStack. These metrics can be used to monitor health of persistent volume operations. For example, for GCE these metrics are called: diff --git a/docs/concepts/cluster-administration/device-plugins.md b/docs/concepts/cluster-administration/device-plugins.md index 310c2793df..5ed94dcd2c 100644 --- a/docs/concepts/cluster-administration/device-plugins.md +++ b/docs/concepts/cluster-administration/device-plugins.md @@ -34,7 +34,7 @@ During the registration, the device plugin needs to send: * The name of its Unix socket. * The Device Plugin API version against which it was built. * The `ResourceName` it wants to advertise. Here `ResourceName` needs to follow the - [extended resource naming scheme](https://github.com/kubernetes/kubernetes/pull/48922) + [extended resource naming scheme](https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/#extended-resources) as `vendor-domain/resource`. For example, an Nvidia GPU is advertised as `nvidia.com/gpu`. @@ -45,12 +45,29 @@ For example, after a device plugin registers `vendor-domain/foo` with the kubele and reports two healthy devices on a node, the node status is updated to advertise 2 `vendor-domain/foo`. -Then, developers can request devices in a +Then, users can request devices in a [Container](/docs/api-reference/{{page.version}}/#container-v1-core) -specification by using the same process that is used for -[opaque integer resources](/docs/concepts/configuration/manage-compute-resources-container/#opaque-integer-resources-alpha-feature). -In version 1.8, extended resources are supported only as integer resources and must have -`limit` equal to `request` in the Container specification. +specification as they request other types of resources, with the following limitations: + * Extended resources are only supported as integer resources and cannot be overcommitted. + * Devices cannot be shared among Containers. + +Suppose a Kubernetes cluster is running a device plugin that advertises resource `vendor-domain/resource` +on certain nodes, here is an example user pod requesting this resource: + +```yaml +apiVersion: v1 +kind: Pod +metadata: + name: demo-pod +spec: + containers: + - + name: demo-container-1 + image: gcr.io/google_containers/pause:2.0 + resources: + limits: + vendor-domain/resource: 2 # requesting 2 vendor-domain/resource +``` ## Device plugin implementation @@ -65,7 +82,7 @@ The general workflow of a device plugin includes the following steps: ```gRPC service DevicePlugin { // ListAndWatch returns a stream of List of Devices - // Whenever a Device state change or a Device disapears, ListAndWatch + // Whenever a Device state change or a Device disappears, ListAndWatch // returns the new list rpc ListAndWatch(Empty) returns (stream ListAndWatchResponse) {} @@ -88,7 +105,7 @@ runtime configurations for accessing the allocated devices. The kubelet passes t to the container runtime. A device plugin is expected to detect kubelet restarts and re-register itself with the new -kubelet instance. In version 1.8, a new kubelet instance cleans up all the existing Unix sockets +kubelet instance. In the current implementation, a new kubelet instance deletes all the existing Unix sockets under `/var/lib/kubelet/device-plugins` when it starts. A device plugin can monitor the deletion of its Unix socket and re-register itself upon such an event. @@ -105,10 +122,22 @@ must be mounted as a in the plugin's [PodSpec](/docs/api-reference/{{page.version}}/#podspec-v1-core). +Kubernetes device plugin support is still in alpha. As development continues, its API version can +change in incompatible ways. We recommend that device plugin developers do the following: + * Watch for changes in future releases. + * Support multiple versions of the device plugin API for backward/forward compatibility. + +If you enable the DevicePlugins feature and run device plugins on nodes that need to be upgraded to +a Kubernetes release with a newer device plugin API version, upgrade your device plugins +to support both versions before upgrading these nodes to +ensure the continuous functioning of the device allocations during the upgrade. + ## Examples -For an example device plugin implementation, see -[nvidia GPU device plugin for COS base OS](https://github.com/GoogleCloudPlatform/container-engine-accelerators/tree/master/cmd/nvidia_gpu). +For examples of device plugin implementations, see: +* The official [NVIDIA GPU device plugin](https://github.com/NVIDIA/k8s-device-plugin) + * it requires using [nvidia-docker 2.0](https://github.com/NVIDIA/nvidia-docker) which allows you to run GPU enabled docker containers +* The [NVIDIA GPU device plugin for COS base OS](https://github.com/GoogleCloudPlatform/container-engine-accelerators/tree/master/cmd/nvidia_gpu). {% endcapture %} diff --git a/docs/concepts/cluster-administration/logging.md b/docs/concepts/cluster-administration/logging.md index ad90ba9e4e..bed53edc2e 100644 --- a/docs/concepts/cluster-administration/logging.md +++ b/docs/concepts/cluster-administration/logging.md @@ -216,7 +216,7 @@ by the kubelet. As an example, you could use [Stackdriver](/docs/tasks/debug-application-cluster/logging-stackdriver/), which uses fluentd as a logging agent. Here are two configuration files that you can use to implement this approach. The first file contains -a [ConfigMap](/docs/tasks/configure-pod-container/configmap/) to configure fluentd. +a [ConfigMap](/docs/tasks/configure-pod-container/configure-pod-configmap/) to configure fluentd. {% include code.html language="yaml" file="fluentd-sidecar-config.yaml" ghlink="/docs/concepts/cluster-administration/fluentd-sidecar-config.yaml" %} diff --git a/docs/concepts/cluster-administration/networking.md b/docs/concepts/cluster-administration/networking.md index e23f590765..55f52e6d3f 100644 --- a/docs/concepts/cluster-administration/networking.md +++ b/docs/concepts/cluster-administration/networking.md @@ -128,7 +128,7 @@ people have reported success with Flannel and Kubernetes. ### Google Compute Engine (GCE) For the Google Compute Engine cluster configuration scripts, we use [advanced -routing](https://cloud.google.com/compute/docs/networking#routing) to +routing](https://cloud.google.com/vpc/docs/routes) to assign each VM a subnet (default is `/24` - 254 IPs). Any traffic bound for that subnet will be routed directly to the VM by the GCE network fabric. This is in addition to the "main" IP address assigned to the VM, which is NAT'ed for diff --git a/docs/concepts/cluster-administration/two-files-counter-pod-agent-sidecar.yaml b/docs/concepts/cluster-administration/two-files-counter-pod-agent-sidecar.yaml index 9737f13493..b37b616e6f 100644 --- a/docs/concepts/cluster-administration/two-files-counter-pod-agent-sidecar.yaml +++ b/docs/concepts/cluster-administration/two-files-counter-pod-agent-sidecar.yaml @@ -22,7 +22,7 @@ spec: - name: varlog mountPath: /var/log - name: count-agent - image: gcr.io/google_containers/fluentd-gcp:1.30 + image: k8s.gcr.io/fluentd-gcp:1.30 env: - name: FLUENTD_ARGS value: -c /etc/fluentd-config/fluentd.conf diff --git a/docs/concepts/configuration/assign-pod-node.md b/docs/concepts/configuration/assign-pod-node.md index c6fc8ebf3a..df6ace536b 100644 --- a/docs/concepts/configuration/assign-pod-node.md +++ b/docs/concepts/configuration/assign-pod-node.md @@ -212,7 +212,7 @@ must be satisfied for the pod to schedule onto a node. #### More Practical Use-cases -Interpod Affinity and AnitAffinity can be even more useful when they are used with higher +Interpod Affinity and AntiAffinity can be even more useful when they are used with higher level collections such as ReplicaSets, Statefulsets, Deployments, etc. One can easily configure that a set of workloads should be co-located in the same defined topology, eg., the same node. diff --git a/docs/concepts/configuration/manage-compute-resources-container.md b/docs/concepts/configuration/manage-compute-resources-container.md index 8508f6642a..16ce9419d5 100644 --- a/docs/concepts/configuration/manage-compute-resources-container.md +++ b/docs/concepts/configuration/manage-compute-resources-container.md @@ -239,7 +239,7 @@ the node. The amount of resources available to Pods is less than the node capacity, because system daemons use a portion of the available resources. The `allocatable` field -[NodeStatus](/docs/resources-reference/{{page.version}}/#nodestatus-v1-core) +[NodeStatus](/docs/api-reference/{{page.version}}/#nodestatus-v1-core) gives the amount of resources that are available to Pods. For more information, see [Node Allocatable Resources](https://git.k8s.io/community/contributors/design-proposals/node/node-allocatable.md). @@ -285,7 +285,7 @@ Conditions: Events: FirstSeen LastSeen Count From SubobjectPath Reason Message Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {scheduler } scheduled Successfully assigned simmemleak-hra99 to kubernetes-node-tf0f - Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} implicitly required container POD pulled Pod container image "gcr.io/google_containers/pause:0.8.0" already present on machine + Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} implicitly required container POD pulled Pod container image "k8s.gcr.io/pause:0.8.0" already present on machine Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} implicitly required container POD created Created with docker id 6a41280f516d Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} implicitly required container POD started Started with docker id 6a41280f516d Tue, 07 Jul 2015 12:53:51 -0700 Tue, 07 Jul 2015 12:53:51 -0700 1 {kubelet kubernetes-node-tf0f} spec.containers{simmemleak} created Created with docker id 87348f12526a @@ -312,7 +312,7 @@ Kubernetes version 1.8 introduces a new resource, _ephemeral-storage_ for managi This partition is “ephemeral” and applications cannot expect any performance SLAs (Disk IOPS for example) from this partition. Local ephemeral storage management only applies for the root partition; the optional partition for image layer and writable layer is out of scope. -**Note:** If an optional runntime partition is used, root partition will not hold any image layer or writable layers. +**Note:** If an optional runtime partition is used, root partition will not hold any image layer or writable layers. {: .note} ### Requests and limits setting for local ephemeral storage @@ -507,7 +507,7 @@ JSON-Pointer. For more details, see {: .note} To consume an Extended Resource in a Pod, include the resource name as a key -in the `spec.containers[].resources.requests` map. +in the `spec.containers[].resources.limits` map in the container spec. **Note:** Extended resources cannot be overcommitted, so request and limit must be equal if both are present in a container spec. @@ -535,6 +535,8 @@ spec: requests: cpu: 2 example.com/foo: 1 + limits: + example.com/foo: 1 ``` ## Planned Improvements @@ -570,7 +572,7 @@ consistency across providers and platforms. * [Container](/docs/api-reference/{{page.version}}/#container-v1-core) -* [ResourceRequirements](/docs/resources-reference/{{page.version}}/#resourcerequirements-v1-core) +* [ResourceRequirements](/docs/api-reference/{{page.version}}/#resourcerequirements-v1-core) {% endcapture %} diff --git a/docs/concepts/configuration/pod-priority-preemption.md b/docs/concepts/configuration/pod-priority-preemption.md index 9ee15dafbf..ff052de7db 100644 --- a/docs/concepts/configuration/pod-priority-preemption.md +++ b/docs/concepts/configuration/pod-priority-preemption.md @@ -12,19 +12,15 @@ title: Pod Priority and Preemption [Pods](/docs/user-guide/pods) in Kubernetes 1.8 and later can have priority. Priority indicates the importance of a Pod relative to other Pods. When a Pod cannot be scheduled, the scheduler tries to preempt (evict) lower priority Pods to make scheduling of the -pending Pod possible. In a future Kubernetes release, priority will also affect -out-of-resource eviction ordering on the Node. - -**Note:** Preemption does not respect PodDisruptionBudget; see -[the limitations section](#poddisruptionbudget-is-not-supported) for more details. -{: .note} +pending Pod possible. In Kubernetes 1.9 and later, Priority also affects scheduling +order of pods and out-of-resource eviction ordering on the Node. {% endcapture %} {% capture body %} ## How to use priority and preemption -To use priority and preemption in Kubernetes 1.8, follow these steps: +To use priority and preemption in Kubernetes 1.8 and later, follow these steps: 1. Enable the feature. @@ -135,6 +131,15 @@ spec: priorityClassName: high-priority ``` +### Effect of Pod priority on scheduling order + +In Kubernetes 1.9 and later, when Pod priority is enabled, scheduler orders pending +pods by their priority and a pending Pod is placed ahead of other pending Pods with +lower priority in the scheduling queue. As a result, the higher priority pod may +by scheduled sooner that pods with lower priority if its scheduling requirements +are met. If such pod cannot be scheduled, scheduler will continue and tries to +schedule other lower priority Pods. + ## Preemption When Pods are created, they go to a queue and wait to be scheduled. The scheduler @@ -145,9 +150,9 @@ where removal of one or more Pods with lower priority than P would enable P to b on that Node. If such a Node is found, one or more lower priority Pods get deleted from the Node. After the Pods are gone, P can be scheduled on the Node. -### Limitations of preemption (alpha version) +### Limitations of preemption -#### Starvation of preempting Pod +#### Graceful termination of preemption victims When Pods are preempted, the victims get their [graceful termination period](https://kubernetes.io/docs/concepts/workloads/pods/pod/#termination-of-pods). @@ -156,33 +161,24 @@ killed. This graceful termination period creates a time gap between the point that the scheduler preempts Pods and the time when the pending Pod (P) can be scheduled on the Node (N). In the meantime, the scheduler keeps scheduling other pending Pods. As victims exit or get terminated, the scheduler tries to schedule -Pods in the pending queue, and one or more of them may be considered and -scheduled to N before the scheduler considers scheduling P on N. In such a case, -it is likely that when all the victims exit, Pod P won't fit on Node N anymore. -So, scheduler will have to preempt other Pods on Node N or another Node so that -P can be scheduled. This scenario might be repeated again for the second and -subsequent rounds of preemption, and P might not get scheduled for a while. -This scenario can cause problems in various clusters, but is particularly -problematic in clusters with a high Pod creation rate. +Pods in the pending queue. Therefore, there is usually a time gap between the point +that scheduler preempts victims and the time that Pod P is scheduled. In order to +minimize this gap, one can set graceful termination period of lower priority pods +to zero or a small number. -We will address this problem in the beta version of Pod preemption. The solution -we plan to implement is -[provided here](https://github.com/kubernetes/community/blob/master/contributors/design-proposals/scheduling/pod-preemption.md#preemption-mechanics). - -#### PodDisruptionBudget is not supported +#### PodDisruptionBudget is supported, but not guaranteed! A [Pod Disruption Budget (PDB)](https://kubernetes.io/docs/concepts/workloads/pods/disruptions/) allows application owners to limit the number Pods of a replicated application that -are down simultaneously from voluntary disruptions. However, the alpha version of -preemption does not respect PDB when choosing preemption victims. -We plan to add PDB support in beta, but even in beta, respecting PDB will be best -effort. The Scheduler will try to find victims whose PDB won't be violated by preemption, -but if no such victims are found, preemption will still happen, and lower priority Pods -will be removed despite their PDBs being violated. +are down simultaneously from voluntary disruptions. Kubernetes 1.9 supports PDB +when preempting pods, but respecting PDB is best effort. The Scheduler tries to +find victims whose PDB are not violated by preemption, but if no such victims are +found, preemption will still happen, and lower priority Pods will be removed +despite their PDBs being violated. #### Inter-Pod affinity on lower-priority Pods -In version 1.8, a Node is considered for preemption only when +A Node is considered for preemption only when the answer to this question is yes: "If all the Pods with lower priority than the pending Pod are removed from the Node, can the pending pod be scheduled on the Node?" @@ -200,15 +196,6 @@ lower-priority Pods. In this case, the scheduler does not preempt any Pods on th Node. Instead, it looks for another Node. The scheduler might find a suitable Node or it might not. There is no guarantee that the pending Pod can be scheduled. -We might address this issue in future versions, but we don't have a clear plan yet. -We will not consider it a blocker for Beta or GA. Part -of the reason is that finding the set of lower-priority Pods that satisfy all -inter-Pod affinity rules is computationally expensive, and adds substantial -complexity to the preemption logic. Besides, even if preemption keeps the lower-priority -Pods to satisfy inter-Pod affinity, the lower priority Pods might be preempted -later by other Pods, which removes the benefits of having the complex logic of -respecting inter-Pod affinity. - Our recommended solution for this problem is to create inter-Pod affinity only towards equal or higher priority pods. diff --git a/docs/concepts/configuration/pod-with-node-affinity.yaml b/docs/concepts/configuration/pod-with-node-affinity.yaml index 7c38e19997..253d2b21ea 100644 --- a/docs/concepts/configuration/pod-with-node-affinity.yaml +++ b/docs/concepts/configuration/pod-with-node-affinity.yaml @@ -23,4 +23,4 @@ spec: - another-node-label-value containers: - name: with-node-affinity - image: gcr.io/google_containers/pause:2.0 \ No newline at end of file + image: k8s.gcr.io/pause:2.0 \ No newline at end of file diff --git a/docs/concepts/configuration/pod-with-pod-affinity.yaml b/docs/concepts/configuration/pod-with-pod-affinity.yaml index 3728537d5a..1897af901f 100644 --- a/docs/concepts/configuration/pod-with-pod-affinity.yaml +++ b/docs/concepts/configuration/pod-with-pod-affinity.yaml @@ -26,4 +26,4 @@ spec: topologyKey: kubernetes.io/hostname containers: - name: with-pod-affinity - image: gcr.io/google_containers/pause:2.0 + image: k8s.gcr.io/pause:2.0 diff --git a/docs/concepts/configuration/secret.md b/docs/concepts/configuration/secret.md index ee8f85d4b5..548c5bca95 100644 --- a/docs/concepts/configuration/secret.md +++ b/docs/concepts/configuration/secret.md @@ -399,10 +399,10 @@ You can manually create an imagePullSecret, and reference it from a serviceAccount. Any pods created with that serviceAccount or that default to use that serviceAccount, will get their imagePullSecret field set to that of the service account. -See [Adding ImagePullSecrets to a service account](/docs/tasks/configure-pod-container/configure-service-account/#adding-imagepullsecrets-to-a-service-account) +See [Add ImagePullSecrets to a service account](/docs/tasks/configure-pod-container/configure-service-account/#add-imagepullsecrets-to-a-service-account) for a detailed explanation of that process. -#### Automatic Mounting of Manually Created Secrets +### Automatic Mounting of Manually Created Secrets Manually created secrets (e.g. one containing a token for accessing a github account) can be automatically attached to pods based on their service account. @@ -618,7 +618,7 @@ spec: secretName: dotfile-secret containers: - name: dotfile-test-container - image: gcr.io/google_containers/busybox + image: k8s.gcr.io/busybox command: - ls - "-l" diff --git a/docs/concepts/configuration/taint-and-toleration.md b/docs/concepts/configuration/taint-and-toleration.md index 463ab28b33..ebf153aa2d 100644 --- a/docs/concepts/configuration/taint-and-toleration.md +++ b/docs/concepts/configuration/taint-and-toleration.md @@ -171,7 +171,7 @@ the special nodes and hence the admission controller should add the toleration. To ensure that the pods that need the special hardware *only* schedule onto the nodes that have the special hardware, you will need some additional mechanism, e.g. you could represent the special resource using -[opaque integer resources](/docs/concepts/configuration/manage-compute-resources-container/#opaque-integer-resources-alpha-feature) +[extended resources](/docs/concepts/configuration/manage-compute-resources-container/#extended-resources) and request it as a resource in the PodSpec, or you could label the nodes that have the special hardware and use node affinity on the pods that need the hardware. diff --git a/docs/concepts/containers/images.md b/docs/concepts/containers/images.md index 6212b44e1f..20385dd2cf 100644 --- a/docs/concepts/containers/images.md +++ b/docs/concepts/containers/images.md @@ -291,6 +291,7 @@ This needs to be done for each pod that is using a private registry. However, setting of this field can be automated by setting the imagePullSecrets in a [serviceAccount](/docs/user-guide/service-accounts) resource. +Check [Add ImagePullSecrets to a Service Account](/docs/tasks/configure-pod-container/configure-service-account/#add-imagepullsecrets-to-a-service-account) for detailed instructions. You can use this in conjunction with a per-node `.docker/config.json`. The credentials will be merged. This approach will work on Google Kubernetes Engine. diff --git a/docs/concepts/overview/components.md b/docs/concepts/overview/components.md index 52fcd42175..debb1f98b6 100644 --- a/docs/concepts/overview/components.md +++ b/docs/concepts/overview/components.md @@ -58,8 +58,8 @@ The following controllers have cloud provider dependencies: ### kube-scheduler -[kube-scheduler](/docs/admin/kube-scheduler/) watches newly created pods that have no node assigned, and -selects a node for them to run on. +[kube-scheduler](/docs/admin/kube-scheduler/) watches newly created pods that +are not assigned to any node, and selects a node for them to run on. ### addons diff --git a/docs/concepts/overview/working-with-objects/kubernetes-objects.md b/docs/concepts/overview/working-with-objects/kubernetes-objects.md index 26cd5ac891..71133af5da 100644 --- a/docs/concepts/overview/working-with-objects/kubernetes-objects.md +++ b/docs/concepts/overview/working-with-objects/kubernetes-objects.md @@ -57,6 +57,10 @@ In the `.yaml` file for the Kubernetes object you want to create, you'll need to * `metadata` - Data that helps uniquely identify the object, including a `name` string, UID, and optional `namespace` You'll also need to provide the object `spec` field. The precise format of the object `spec` is different for every Kubernetes object, and contains nested fields specific to that object. The [Kubernetes API reference](/docs/concepts/overview/kubernetes-api/) can help you find the spec format for all of the objects you can create using Kubernetes. +For example, the `spec` format for a `Pod` object can be found +[here](/docs/reference/generated/kubernetes-api/{{page.version}}/#podspec-v1-core), +and the `spec` format for a `Deployment` object can be found +[here](/docs/reference/generated/kubernetes-api/{{page.version}}/#deploymentspec-v1-apps). {% endcapture %} diff --git a/docs/concepts/overview/working-with-objects/labels.md b/docs/concepts/overview/working-with-objects/labels.md index b804f26d0f..e5853b920d 100644 --- a/docs/concepts/overview/working-with-objects/labels.md +++ b/docs/concepts/overview/working-with-objects/labels.md @@ -73,6 +73,25 @@ The former selects all resources with key equal to `environment` and value equal The latter selects all resources with key equal to `tier` and value distinct from `frontend`, and all resources with no labels with the `tier` key. One could filter for resources in `production` excluding `frontend` using the comma operator: `environment=production,tier!=frontend` +One usage scenario for equality-based label requirement is for Pods to specify +node selection criteria. For example, the sample Pod below selects nodes with +the label "`accelerator=nvidia-tesla-p100`". + +```yaml +apiVersion: v1 +kind: Pod +metadata: + name: cuda-test +spec: + containers: + - name: cuda-test + image: "k8s.gcr.io/cuda-vector-add:v0.1" + resources: + limits: + nvidia.com/gpu: 1 + nodeSelector: + accelerator: nvidia-tesla-p100 +``` ### _Set-based_ requirement diff --git a/docs/concepts/policy/pod-security-policy.md b/docs/concepts/policy/pod-security-policy.md index 884ad55fc6..26cb760916 100644 --- a/docs/concepts/policy/pod-security-policy.md +++ b/docs/concepts/policy/pod-security-policy.md @@ -1,71 +1,492 @@ --- approvers: - pweil- +- tallclair title: Pod Security Policies --- -Objects of type `PodSecurityPolicy` govern the ability -to make requests on a pod that affect the `SecurityContext` that will be -applied to a pod and container. +{% include feature-state-beta.md %} -See [PodSecurityPolicy proposal](https://git.k8s.io/community/contributors/design-proposals/auth/pod-security-policy.md) for more information. +Pod Security Policies enable fine-grained authorization of pod creation and +updates. * TOC {:toc} ## What is a Pod Security Policy? -A _Pod Security Policy_ is a cluster-level resource that controls the -actions that a pod can perform and what it has the ability to access. The -`PodSecurityPolicy` objects define a set of conditions that a pod must -run with in order to be accepted into the system. They allow an +A _Pod Security Policy_ is a cluster-level resource that controls security +sensitive aspects of the pod specification. The `PodSecurityPolicy` objects +define a set of conditions that a pod must run with in order to be accepted into +the system, as well as defaults for the related fields. They allow an administrator to control the following: -| Control Aspect | Field Name | -| ---------------------------------------------------------------------- | ------------------------------------------- | -| Running of privileged containers | `privileged` | -| Default set of capabilities that will be added to a container | `defaultAddCapabilities` | -| Capabilities that will be dropped from a container | `requiredDropCapabilities` | -| Capabilities a container can request to be added | `allowedCapabilities` | -| Controlling the usage of volume types | [`volumes`](#controlling-volumes) | -| The use of host networking | [`hostNetwork`](#host-network) | -| The use of host ports | `hostPorts` | -| The use of host's PID namespace | `hostPID` | -| The use of host's IPC namespace | `hostIPC` | -| The SELinux context of the container | [`seLinux`](#selinux) | -| The user ID | [`runAsUser`](#runasuser) | -| Configuring allowable supplemental groups | [`supplementalGroups`](#supplementalgroups) | -| Allocating an FSGroup that owns the pod's volumes | [`fsGroup`](#fsgroup) | -| Requiring the use of a read only root file system | `readOnlyRootFilesystem` | -| Running of a container that allow privilege escalation from its parent | [`allowPrivilegeEscalation`](#allowprivilegeescalation) | -| Control whether a process can gain more privileges than its parent process | [`defaultAllowPrivilegeEscalation`](#defaultallowprivilegeescalation) | -| Whitelist of allowed host paths | [`allowedHostPaths`](#allowedhostpaths) | -| Whitelist of the flex volume drivers | [`allowedFlexVolumes`](#allowedflexvolumes) | - -_Pod Security Policies_ are comprised of settings and strategies that -control the security features a pod has access to. These settings fall -into three categories: - -- *Controlled by a Boolean*: Fields of this type default to the most -restrictive value. -- *Controlled by an allowable set*: Fields of this type are checked -against the set to ensure their values are allowed. -- *Controlled by a strategy*: Items that have a strategy to provide -a mechanism to generate the value and a mechanism to ensure that a -specified value falls into the set of allowable values. +| Control Aspect | Field Names | +| ----------------------------------------------------| ------------------------------------------- | +| Running of privileged containers | `privileged` | +| Usage of the root namespaces | [`hostPID`, `hostIPC`](#host-namespaces) | +| Usage of host networking and ports | [`hostNetwork`, `hostPorts`](#host-namespaces) | +| Usage of volume types | [`volumes`](#volumes-and-file-systems) | +| Usage of the host filesystem | [`allowedHostPaths`](#volumes-and-file-systems) | +| Allocating an FSGroup that owns the pod's volumes | [`fsGroup`](#volumes-and-file-systems) | +| Requiring the use of a read only root file system | [`readOnlyRootFilesystem`](#volumes-and-file-systems) | +| The user and group IDs of the container | [`runAsUser`, `supplementalGroups`](#users-and-groups) | +| Restricting escalation to root privileges | [`allowPrivilegeEscalation`, `defaultAllowPrivilegeEscalation`](#privilege-escalation) | +| Linux capabilities | [`defaultAddCapabilities`, `requiredDropCapabilities`, `allowedCapabilities`](#capabilities) | +| The SELinux context of the container | [`seLinux`](#selinux) | +| The AppArmor profile used by containers | [annotations](#apparmor) | +| The seccomp profile used by containers | [annotations](#seccomp) | -## Strategies +## Enabling Pod Security Policies -### RunAsUser +Pod security policy control is implemented as an optional (but recommended) +[admission +controller](/docs/admin/admission-controllers/#podsecuritypolicy). PodSecurityPolicies +are enforced by [enabling the admission +controller](/docs/admin/admission-controllers/#how-do-i-turn-on-an-admission-control-plug-in), +but doing so without authorizing any policies **will prevent any pods from being +created** in the cluster. -- *MustRunAs* - Requires a `range` to be configured. Uses the first value -of the range as the default. Validates against the configured range. +Since the pod security policy API (`extensions/v1beta1/podsecuritypolicy`) is +enabled independently of the admission controller, for existing clusters it is +recommended that policies are added and authorized before enabling the admission +controller. + +## Authorizing Policies + +When a PodSecurityPolicy resource is created, it does nothing. In order to use +it, the requesting user or target pod's [service +account](/docs/tasks/configure-pod-container/configure-service-account/) must be +authorized to use the policy, by allowing the `use` verb on the policy. + +Most Kubernetes pods are not created directly by users. Instead, they are +typically created indirectly as part of a +[Deployment](/docs/concepts/workloads/controllers/deployment/), +[ReplicaSet](/docs/concepts/workloads/controllers/replicaset/), or other +templated controller via the controller manager. Granting the controller access +to the policy would grant access for *all* pods created by that the controller, +so the preferred method for authorizing policies is to grant access to the +pod's service account (see [example](#run-another-pod)). + +### Via RBAC + +[RBAC](/docs/admin/authorization/rbac/) is a standard Kubernetes authorization +mode, and can easily be used to authorize use of policies. + +First, a `Role` or `ClusterRole` needs to grant access to `use` the desired +policies. The rules to grant access look like this: + +```yaml +kind: ClusterRole +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: +rules: +- apiGroups: ['extensions'] + resources: ['podsecuritypolicies'] + verbs: ['use'] + resourceNames: + - +``` + +Then the `(Cluster)Role` is bound to the authorized user(s): + +```yaml +kind: ClusterRoleBinding +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: +roleRef: + kind: ClusterRole + name: + apiGroup: rbac.authorization.k8s.io +subjects: +# Authorize specific service accounts: +- kind: ServiceAccount + name: + namespace: +# Authorize specific users (not recommended): +- kind: User + apiGroup: rbac.authorization.k8s.io + name: +``` + +If a `RoleBinding` (not a `ClusterRoleBinding`) is used, it will only grant +usage for pods being run in the same namespace as the binding. This can be +paired with system groups to grant access to all pods run in the namespace: +```yaml +# Authorize all service accounts in a namespace: +- kind: Group + apiGroup: rbac.authorization.k8s.io + name: system:serviceaccounts +# Or equivalently, all authenticated users in a namespace: +- kind: Group + apiGroup: rbac.authorization.k8s.io + name: system:authenticated +``` + +For more examples of RBAC bindings, see [Role Binding +Examples](/docs/admin/authorization/rbac#role-binding-examples). For a complete +example of authorizing a PodSecurityPolicy, see +[below](#example). + + +### Troubleshooting + +- The [Controller Manager](/docs/admin/kube-controller-manager/) must be run +against [the secured API port](/docs/admin/accessing-the-api/), and must not +have superuser permissions. Otherwise requests would bypass authentication and +authorization modules, all PodSecurityPolicy objects would be allowed, and users +would be able to create privileged containers. For more details on configuring +Controller Manager authorization, see [Controller +Roles](docs/admin/authorization/rbac/#controller-roles). + +## Policy Order + +In addition to restricting pod creation and update, pod security policies can +also be used to provide default values for many of the fields that it +controls. When multiple policies are available, the pod security policy +controller selects policies in the following order: + +1. If any policies successfully validate the pod without altering it, they are + used. +2. Otherwise, the first valid policy in alphabetical order is used. + +## Example + +_This example assumes you have a running cluster with the PodSecurityPolicy +admission controller enabled and you have cluster admin privileges._ + +### Set up + +Set up a namespace and a service account to act as for this example. We'll use +this service account to mock a non-admin user. + +```shell +$ kubectl create namespace psp-example +$ kubectl create serviceaccount -n psp-example fake-user +$ kubectl create rolebinding -n psp-example fake-editor --clusterrole=edit --serviceaccount=psp-example:fake-user +``` + +To make it clear which user we're acting as and save some typing, create 2 +aliases: + +```shell +$ alias kubectl-admin='kubectl -n psp-example' +$ alias kubectl-user='kubectl --as=system:serviceaccount:psp-example:fake-user -n psp-example' +``` + +### Create a policy and a pod + +Define the example PodSecurityPolicy object in a file. This is a policy that +simply prevents the creation of privileged pods. + +{% include code.html language="yaml" file="example-psp.yaml" ghlink="/docs/concepts/policy/example-psp.yaml" %} + +And create it with kubectl: + +```shell +$ kubectl-admin create -f example-psp.yaml +``` + +Now, as the unprivileged user, try to create a simple pod: + +```shell +$ kubectl-user create -f- <` - Specify a profile as a file on the node located at + `/`, where `` is defined via the + `--seccomp-profile-root` flag on the Kubelet. -1. azureFile -1. azureDisk -1. flocker -1. flexVolume -1. hostPath -1. emptyDir -1. gcePersistentDisk -1. awsElasticBlockStore -1. gitRepo -1. secret -1. nfs -1. iscsi -1. glusterfs -1. persistentVolumeClaim -1. rbd -1. cinder -1. cephFS -1. downwardAPI -1. fc -1. configMap -1. vsphereVolume -1. quobyte -1. photonPersistentDisk -1. projected -1. portworxVolume -1. scaleIO -1. storageos -1. \* (allow all volumes) - -The recommended minimum set of allowed volumes for new PSPs are -configMap, downwardAPI, emptyDir, persistentVolumeClaim, secret, and projected. - -### Host Network - - *HostPorts*, default `empty`. List of `HostPortRange`, defined by `min`(inclusive) and `max`(inclusive), which define the allowed host ports. - -### AllowPrivilegeEscalation - -Gates whether or not a user is allowed to set the security context of a container -to `allowPrivilegeEscalation=true`. This field defaults to `false`. - -### DefaultAllowPrivilegeEscalation - -Sets the default for the security context `AllowPrivilegeEscalation` of a container. -This bool directly controls whether the `no_new_privs` flag gets set on the -container process. It defaults to `nil`. The default behavior of `nil` -allows privilege escalation so as to not break setuid binaries. Setting it to `false` -ensures that no child process of a container can gain more privileges than -its parent. - -### AllowedHostPaths - -This specifies a whitelist of host paths that are allowed to be used by Pods. -An empty list means there is no restriction on host paths used. -Each item in the list must specify a string value named `pathPrefix` that -defines a host path to match. The value cannot be "`*`" though. -An example is shown below: - -```yaml -apiVersion: extensions/v1beta1 -kind: PodSecurityPolicy -metadata: - name: custom-paths -spec: - allowedHostPaths: - # This allows "/foo", "/foo/", "/foo/bar" etc., but - # disallows "/fool", "/etc/foo" etc. - - pathPrefix: "/foo" -``` - -### AllowedFlexVolumes - -This specifies a whitelist of flex volume drivers that are allowed -to be used by flexVolume. An empty list means there is no restriction on the drivers. Please -make sure `volumes` contains the `flexVolume` volume type, no flex volume driver is allowed -otherwise. For example: - -```yaml -apiVersion: extensions/v1beta1 -kind: PodSecurityPolicy -metadata: - name: allow-flex-volumes -spec: - volumes: - - flexVolume - allowedFlexVolumes: - - driver: example/lvm - - driver: example/cifs -``` - -## Admission - -[_Admission control_ with `PodSecurityPolicy`](/docs/admin/admission-controllers/#podsecuritypolicy) -allows for control over the creation and modification of resources based on the -capabilities allowed in the cluster. - -Admission uses the following approach to create the final security context for -the pod: - -1. Retrieve all PSPs available for use. -1. Generate field values for security context settings that were not specified -on the request. -1. Validate the final settings against the available policies. - -If a matching policy is found, then the pod is accepted. If the -request cannot be matched to a PSP, the pod is rejected. - -A pod must validate every field against the PSP. - -## Creating a Pod Security Policy - -Here is an example Pod Security Policy. It has permissive settings for -all fields - -{% include code.html language="yaml" file="psp.yaml" ghlink="/docs/concepts/policy/psp.yaml" %} - -Create the policy by downloading the example file and then running this command: - -```shell -$ kubectl create -f ./psp.yaml -podsecuritypolicy "permissive" created -``` - -## Getting a list of Pod Security Policies - -To get a list of existing policies, use `kubectl get`: - -```shell -$ kubectl get psp -NAME PRIV CAPS SELINUX RUNASUSER FSGROUP SUPGROUP READONLYROOTFS VOLUMES -permissive false [] RunAsAny RunAsAny RunAsAny RunAsAny false [*] -privileged true [] RunAsAny RunAsAny RunAsAny RunAsAny false [*] -restricted false [] RunAsAny MustRunAsNonRoot RunAsAny RunAsAny false [emptyDir secret downwardAPI configMap persistentVolumeClaim projected] -``` - -## Editing a Pod Security Policy - -To modify policy interactively, use `kubectl edit`: - -```shell -$ kubectl edit psp permissive -``` - -This command will open a default text editor where you will be able to modify policy. - -## Deleting a Pod Security Policy - -Once you don't need a policy anymore, simply delete it with `kubectl`: - -```shell -$ kubectl delete psp permissive -podsecuritypolicy "permissive" deleted -``` - -## Enabling Pod Security Policies - -In order to use Pod Security Policies in your cluster you must ensure the -following - -1. You have enabled the API type `extensions/v1beta1/podsecuritypolicy` (only for versions prior 1.6) -1. [You have enabled the admission control plug-in `PodSecurityPolicy`](/docs/admin/admission-controllers/#how-do-i-turn-on-an-admission-control-plug-in) -1. You have defined your policies - -## Working With RBAC - -In Kubernetes 1.5 and newer, you can use PodSecurityPolicy to control access to -privileged containers based on user role and groups. Access to different -PodSecurityPolicy objects can be controlled via authorization. - -Note that [Controller Manager](/docs/admin/kube-controller-manager/) must be run -against [the secured API port](/docs/admin/accessing-the-api/), and must not -have superuser permissions. Otherwise requests would bypass authentication and -authorization modules, all PodSecurityPolicy objects would be allowed, -and user will be able to create privileged containers. - -PodSecurityPolicy authorization uses the union of all policies available to the -user creating the pod and -[the service account specified on the pod](/docs/tasks/configure-pod-container/configure-service-account/). - -Access to given PSP policies for a user will be effective only when creating -Pods directly. - -For pods created on behalf of a user, in most cases by Controller Manager, -access should be given to the service account specified on the pod spec -template. Examples of resources that create pods on behalf of a user are -Deployments, ReplicaSets, etc. - -For more details, see the -[PodSecurityPolicy RBAC example](https://git.k8s.io/examples/staging/podsecuritypolicy/rbac/README.md) -of applying PodSecurityPolicy to control access to privileged containers based -on role and groups when deploying Pods directly. +**seccomp.security.alpha.kubernetes.io/allowedProfileNames** - Annotation that +specifies which values are allowed for the pod seccomp annotations. Specified as +a comma-delimited list of allowed values. Possible values are those listed +above, plus `*` to allow all profiles. Absence of this annotation means that the +default cannot be changed. diff --git a/docs/concepts/service-catalog/index.md b/docs/concepts/service-catalog/index.md index 814505ccb3..f85b1bea37 100644 --- a/docs/concepts/service-catalog/index.md +++ b/docs/concepts/service-catalog/index.md @@ -5,7 +5,7 @@ approvers: --- {% capture overview %} -{% glossary_definition term_id="service-catalog" length="all" prepend="Service Catalog is " %} +{% glossary_definition term_id="service-catalog" length="all" prepend="Service Catalog is" %} A *Service Broker*, as defined by the [Open Service Broker API spec](https://github.com/openservicebrokerapi/servicebroker/blob/v2.13/spec.md), is an endpoint for a set of Managed Services offered and maintained by a third-party, which could be a cloud provider such as AWS, GCP, or Azure. Some examples of *Managed Services* are Microsoft Azure Cloud Queue, Amazon Simple Queue Service, and Google Cloud Pub/Sub, but they can be any software offering that can be used by an application. @@ -55,7 +55,7 @@ Upon creation, the Service Catalog controller will create a Kubernetes `Secret` ### Authentication -Service Catalog supports these methods of authentication: +Service Catalog supports these methods of authentication: * Basic (username/password) * [OAuth 2.0 Bearer Token](https://tools.ietf.org/html/rfc6750) @@ -118,7 +118,7 @@ The following is a sequence diagram illustrating the steps involved in listing M ### Provisioning a new instance -A {% glossary_tooltip text="Cluster Operator" term_id="cluster-operator" %} can initiate the provisioning of a new instance by creating a `ServiceInstance` resource. +A {% glossary_tooltip text="Cluster Operator" term_id="cluster-operator" %} can initiate the provisioning of a new instance by creating a `ServiceInstance` resource. This is an example of a `ServiceInstance` resource: @@ -133,7 +133,7 @@ spec: clusterServiceClassExternalName: cloud-provider-service clusterServicePlanExternalName: service-plan-name ##### - # Additional parameters can be added here, + # Additional parameters can be added here, # which may be used by the Service Broker. ##### ``` @@ -148,7 +148,7 @@ The following sequence diagram illustrates the steps involved in provisioning a ### Binding to a Managed Service -After a new instance has been provisioned, a {% glossary_tooltip text="Cluster Operator" term_id="cluster-operator" %} must bind to the Managed Service to get the connection credentials and service account details necessary for the application to use the service. This is done by creating a `ServiceBinding` resource. +After a new instance has been provisioned, a {% glossary_tooltip text="Cluster Operator" term_id="cluster-operator" %} must bind to the Managed Service to get the connection credentials and service account details necessary for the application to use the service. This is done by creating a `ServiceBinding` resource. The following is an example of a `ServiceBinding` resource: @@ -162,7 +162,7 @@ spec: instanceRef: name: cloud-queue-instance ##### - # Additional information can be added here, such as a secretName or + # Additional information can be added here, such as a secretName or # service account parameters, which may be used by the Service Broker. ##### ``` diff --git a/docs/concepts/services-networking/ingress.md b/docs/concepts/services-networking/ingress.md index 256410d4cc..a22a817f54 100644 --- a/docs/concepts/services-networking/ingress.md +++ b/docs/concepts/services-networking/ingress.md @@ -73,7 +73,7 @@ spec: *POSTing this to the API server will have no effect if you have not configured an [Ingress controller](#ingress-controllers).* -__Lines 1-6__: As with all other Kubernetes config, an Ingress needs `apiVersion`, `kind`, and `metadata` fields. For general information about working with config files, see [deploying applications](/docs/tasks/run-application/run-stateless-application-deployment/), [configuring containers](/docs/tasks/configure-pod-container/configmap/), [managing resources](/docs/concepts/cluster-administration/manage-deployment/) and [ingress configuration rewrite](https://github.com/kubernetes/ingress-nginx/blob/master/docs/examples/rewrite/README.md). +__Lines 1-6__: As with all other Kubernetes config, an Ingress needs `apiVersion`, `kind`, and `metadata` fields. For general information about working with config files, see [deploying applications](/docs/tasks/run-application/run-stateless-application-deployment/), [configuring containers](/docs/tasks/configure-pod-container/configure-pod-configmap/), [managing resources](/docs/concepts/cluster-administration/manage-deployment/) and [ingress configuration rewrite](https://github.com/kubernetes/ingress-nginx/blob/master/docs/examples/rewrite/README.md). __Lines 7-9__: Ingress [spec](https://git.k8s.io/community/contributors/devel/api-conventions.md#spec-and-status) has all the information needed to configure a loadbalancer or proxy server. Most importantly, it contains a list of rules matched against all incoming requests. Currently the Ingress resource only supports http rules. @@ -224,7 +224,7 @@ Note that there is a gap between TLS features supported by various Ingress contr ### Loadbalancing -An Ingress controller is bootstrapped with some load balancing policy settings that it applies to all Ingress, such as the load balancing algorithm, backend weight scheme, and others. More advanced load balancing concepts (e.g.: persistent sessions, dynamic weights) are not yet exposed through the Ingress. You can still get these features through the [service loadbalancer](https://git.k8s.io/contrib/service-loadbalancer). With time, we plan to distill load balancing patterns that are applicable cross platform into the Ingress resource. +An Ingress controller is bootstrapped with some load balancing policy settings that it applies to all Ingress, such as the load balancing algorithm, backend weight scheme, and others. More advanced load balancing concepts (e.g.: persistent sessions, dynamic weights) are not yet exposed through the Ingress. You can still get these features through the [service loadbalancer](https://github.com/kubernetes/ingress-nginx/blob/master/docs/catalog.md). With time, we plan to distill load balancing patterns that are applicable cross platform into the Ingress resource. It's also worth noting that even though health checks are not exposed directly through the Ingress, there exist parallel concepts in Kubernetes such as [readiness probes](/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/) which allow you to achieve the same end result. Please review the controller specific docs to see how they handle health checks ([nginx](https://git.k8s.io/ingress-nginx/README.md), [GCE](https://git.k8s.io/ingress-gce/README.md#health-checks)). diff --git a/docs/concepts/services-networking/network-policies.md b/docs/concepts/services-networking/network-policies.md index addcd89710..8b96771b64 100644 --- a/docs/concepts/services-networking/network-policies.md +++ b/docs/concepts/services-networking/network-policies.md @@ -68,7 +68,7 @@ spec: *POSTing this to the API server will have no effect unless your chosen networking solution supports network policy.* -__Mandatory Fields__: As with all other Kubernetes config, a `NetworkPolicy` needs `apiVersion`, `kind`, and `metadata` fields. For general information about working with config files, see [Configure Containers Using a ConfigMap](/docs/tasks/configure-pod-container/configmap/), and [Object Management](https://kubernetes.io/docs/tutorials/object-management-kubectl/object-management/). +__Mandatory Fields__: As with all other Kubernetes config, a `NetworkPolicy` needs `apiVersion`, `kind`, and `metadata` fields. For general information about working with config files, see [Configure Containers Using a ConfigMap](/docs/tasks/configure-pod-container/configure-pod-configmap/), and [Object Management](https://kubernetes.io/docs/tutorials/object-management-kubectl/object-management/). __spec__: `NetworkPolicy` [spec](https://git.k8s.io/community/contributors/devel/api-conventions.md#spec-and-status) has all the information needed to define a particular network policy in the given namespace. diff --git a/docs/concepts/services-networking/service.md b/docs/concepts/services-networking/service.md index ddbca9c9a0..1090ecb48a 100644 --- a/docs/concepts/services-networking/service.md +++ b/docs/concepts/services-networking/service.md @@ -154,7 +154,7 @@ than `ExternalName`. In Kubernetes v1.0, `Services` are a "layer 4" (TCP/UDP over IP) construct, the proxy was purely in userspace. In Kubernetes v1.1, the `Ingress` API was added (beta) to represent "layer 7"(HTTP) services, iptables proxy was added too, -and become the default operating mode since Kubernetes v1.2. In Kubernetes v1.9-alpha, +and become the default operating mode since Kubernetes v1.2. In Kubernetes v1.8.0-beta.0, ipvs proxy was added. ### Proxy-mode: userspace @@ -171,6 +171,8 @@ By default, the choice of backend is round robin. ![Services overview diagram for userspace proxy](/images/docs/services-userspace-overview.svg) +Note that in the above diagram, `clusterIP` is shown as `ServiceIP`. + ### Proxy-mode: iptables In this mode, kube-proxy watches the Kubernetes master for the addition and @@ -188,20 +190,22 @@ having working [readiness probes](/docs/tasks/configure-pod-container/configure- ![Services overview diagram for iptables proxy](/images/docs/services-iptables-overview.svg) +Note that in the above diagram, `clusterIP` is shown as `ServiceIP`. + ### Proxy-mode: ipvs {% assign for_k8s_version="v1.9" %}{% include feature-state-beta.md %} In this mode, kube-proxy watches Kubernetes `services` and `endpoints`, -call `netlink` interface create ipvs rules accordingly and sync ipvs rules with Kubernetes +calls `netlink` interface to create ipvs rules accordingly and syncs ipvs rules with Kubernetes `services` and `endpoints` periodically, to make sure ipvs status is -consistent with the expectation. When access the `service`, traffic will -be redirect to one of the backend `pod`. +consistent with the expectation. When `service` is accessed, traffic will +be redirected to one of the backend `pod`s. -Similar to iptables, Ipvs is based on netfilter hook function, but use hash -table as the underlying data structure and work in the kernal state. -That means ipvs redirects traffic can be much faster, and have much -better performance when sync proxy rules. Furthermore, ipvs provides more +Similar to iptables, Ipvs is based on netfilter hook function, but uses hash +table as the underlying data structure and works in the kernel space. +That means ipvs redirects traffic much faster, and has much +better performance when syncing proxy rules. Furthermore, ipvs provides more options for load balancing algorithm, such as: - rr: round-robin @@ -211,7 +215,7 @@ options for load balancing algorithm, such as: - sed: shortest expected delay - nq: never queue -**Note:** ipvs mode assumed IPVS kernel modules are installed on the node +**Note:** ipvs mode assumes IPVS kernel modules are installed on the node before running kube-proxy. When kube-proxy starts with ipvs proxy mode, kube-proxy would validate if IPVS modules are installed on the node, if it's not installed kube-proxy will fall back to iptables proxy mode. diff --git a/docs/concepts/storage/dynamic-provisioning.md b/docs/concepts/storage/dynamic-provisioning.md index 6b60989208..e6bee64a26 100644 --- a/docs/concepts/storage/dynamic-provisioning.md +++ b/docs/concepts/storage/dynamic-provisioning.md @@ -116,7 +116,7 @@ When a default `StorageClass` exists in a cluster and a user creates a `storageClassName` field pointing to the default storage class. Note that there can be at most one *default* storage class on a cluster, or -a `PersistentVolumeClaim` with `storageClassName` explicitly specified cannot +a `PersistentVolumeClaim` without `storageClassName` explicitly specified cannot be created. {% endcapture %} diff --git a/docs/concepts/storage/persistent-volumes.md b/docs/concepts/storage/persistent-volumes.md index c7a12a83d2..c8fd40284d 100644 --- a/docs/concepts/storage/persistent-volumes.md +++ b/docs/concepts/storage/persistent-volumes.md @@ -125,7 +125,7 @@ spec: path: /any/path/it/will/be/replaced containers: - name: pv-recycler - image: "gcr.io/google_containers/busybox" + image: "k8s.gcr.io/busybox" command: ["/bin/sh", "-c", "test -e /scrub && rm -rf /scrub/..?* /scrub/.[!.]* /scrub/* && test -z \"$(ls -A /scrub)\" || exit 1"] volumeMounts: - name: vol @@ -218,24 +218,24 @@ resizing to take place. Also, file system resizing is only supported for followi Each PV contains a spec and status, which is the specification and status of the volume. ```yaml - apiVersion: v1 - kind: PersistentVolume - metadata: - name: pv0003 - spec: - capacity: - storage: 5Gi - volumeMode: Filesystem - accessModes: - - ReadWriteOnce - persistentVolumeReclaimPolicy: Recycle - storageClassName: slow - mountOptions: - - hard - - nfsvers=4.1 - nfs: - path: /tmp - server: 172.17.0.2 +apiVersion: v1 +kind: PersistentVolume +metadata: + name: pv0003 +spec: + capacity: + storage: 5Gi + volumeMode: Filesystem + accessModes: + - ReadWriteOnce + persistentVolumeReclaimPolicy: Recycle + storageClassName: slow + mountOptions: + - hard + - nfsvers=4.1 + nfs: + path: /tmp + server: 172.17.0.2 ``` ### Capacity diff --git a/docs/concepts/storage/volumes.md b/docs/concepts/storage/volumes.md index 247c593d75..414913726d 100644 --- a/docs/concepts/storage/volumes.md +++ b/docs/concepts/storage/volumes.md @@ -131,7 +131,7 @@ metadata: name: test-ebs spec: containers: - - image: gcr.io/google_containers/test-webserver + - image: k8s.gcr.io/test-webserver name: test-container volumeMounts: - mountPath: /test-ebs @@ -246,7 +246,7 @@ metadata: name: test-pd spec: containers: - - image: gcr.io/google_containers/test-webserver + - image: k8s.gcr.io/test-webserver name: test-container volumeMounts: - mountPath: /cache @@ -326,7 +326,7 @@ metadata: name: test-pd spec: containers: - - image: gcr.io/google_containers/test-webserver + - image: k8s.gcr.io/test-webserver name: test-container volumeMounts: - mountPath: /test-pd @@ -432,7 +432,7 @@ metadata: name: test-pd spec: containers: - - image: gcr.io/google_containers/test-webserver + - image: k8s.gcr.io/test-webserver name: test-container volumeMounts: - mountPath: /test-pd @@ -665,7 +665,7 @@ metadata: name: test-portworx-volume-pod spec: containers: - - image: gcr.io/google_containers/test-webserver + - image: k8s.gcr.io/test-webserver name: test-container volumeMounts: - mountPath: /mnt @@ -736,7 +736,7 @@ metadata: name: pod-0 spec: containers: - - image: gcr.io/google_containers/test-webserver + - image: k8s.gcr.io/test-webserver name: pod-0 volumeMounts: - mountPath: /test-pd @@ -866,7 +866,7 @@ metadata: name: test-vmdk spec: containers: - - image: gcr.io/google_containers/test-webserver + - image: k8s.gcr.io/test-webserver name: test-container volumeMounts: - mountPath: /test-vmdk @@ -953,13 +953,14 @@ redesigned or even removed in future releases. Mount propagation allows for sharing volumes mounted by a Container to other Containers in the same Pod, or even to other Pods on the same node. -If the MountPropagation feature is disabled, volume mounts in pods are not propagated. +If the "`MountPropagation`" feature is disabled, volume mounts in pods are not propagated. That is, Containers run with `private` mount propagation as described in the [Linux kernel documentation](https://www.kernel.org/doc/Documentation/filesystems/sharedsubtree.txt). To enable this feature, specify `MountPropagation=true` in the -`--feature-gates` command line option. When enabled, the `volumeMounts` field -of a Container has a new `mountPropagation` subfield. Its values are: +`--feature-gates` command line option for the API server and kubelets. +When enabled, the `volumeMounts` field of a Container has a new +`mountPropagation` subfield. Its values are: * `HostToContainer` - This volume mount will receive all subsequent mounts that are mounted to this volume or any of its subdirectories. This is diff --git a/docs/concepts/workloads/controllers/cron-jobs.md b/docs/concepts/workloads/controllers/cron-jobs.md index e424aa4e5f..39fc6548d1 100644 --- a/docs/concepts/workloads/controllers/cron-jobs.md +++ b/docs/concepts/workloads/controllers/cron-jobs.md @@ -3,7 +3,7 @@ approvers: - erictune - soltysh - janetkuo -title: Cron Jobs +title: CronJob --- * TOC @@ -37,7 +37,8 @@ A typical use case is: You need a working Kubernetes cluster at version >= 1.8 (for CronJob). For previous versions of cluster (< 1.8) you need to explicitly enable `batch/v2alpha1` API by passing `--runtime-config=batch/v2alpha1=true` to the API server (see [Turn on or off an API version for your cluster](/docs/admin/cluster-management/#turn-on-or-off-an-api-version-for-your-cluster) -for more). +for more), and then restart both the API server and the controller manager +component. ## Creating a Cron Job diff --git a/docs/concepts/workloads/controllers/daemonset.md b/docs/concepts/workloads/controllers/daemonset.md index ca285bd183..4ffa9144da 100644 --- a/docs/concepts/workloads/controllers/daemonset.md +++ b/docs/concepts/workloads/controllers/daemonset.md @@ -5,7 +5,7 @@ approvers: - foxish - janetkuo - kow3ns -title: Daemon Sets +title: DaemonSet --- * TOC diff --git a/docs/concepts/workloads/controllers/deployment.md b/docs/concepts/workloads/controllers/deployment.md index 1b4f3c43b3..360a979bcf 100644 --- a/docs/concepts/workloads/controllers/deployment.md +++ b/docs/concepts/workloads/controllers/deployment.md @@ -214,12 +214,10 @@ nginx-deployment-1564180365-z9gth 1/1 Running 0 14s Next time we want to update these Pods, we only need to update the Deployment's pod template again. Deployment can ensure that only a certain number of Pods may be down while they are being updated. By -default, it ensures that at least 1 less than the desired number of Pods are up (1 max unavailable). +default, it ensures that at least 25% less than the desired number of Pods are up (25% max unavailable). Deployment can also ensure that only a certain number of Pods may be created above the desired number of -Pods. By default, it ensures that at most 1 more than the desired number of Pods are up (1 max surge). - -In a future version of Kubernetes, the defaults will change from 1-1 to 25%-25%. +Pods. By default, it ensures that at most 25% more than the desired number of Pods are up (25% max surge). For example, if you look at the above Deployment closely, you will see that it first created a new Pod, then deleted some old Pods and created new ones. It does not kill old Pods until a sufficient number of @@ -228,41 +226,42 @@ It makes sure that number of available Pods is at least 2 and the number of tota ```shell $ kubectl describe deployments -Name: nginx-deployment -Namespace: default -CreationTimestamp: Tue, 15 Mar 2016 12:01:06 -0700 -Labels: app=nginx -Annotations: deployment.kubernetes.io/revision=2 -Selector: app=nginx -Replicas: 3 desired | 3 updated | 3 total | 3 available | 0 unavailable -StrategyType: RollingUpdate -MinReadySeconds: 0 -RollingUpdateStrategy: 1 max unavailable, 1 max surge +Name: nginx-deployment +Namespace: default +CreationTimestamp: Thu, 30 Nov 2017 10:56:25 +0000 +Labels: app=nginx +Annotations: deployment.kubernetes.io/revision=2 +Selector: app=nginx +Replicas: 3 desired | 3 updated | 3 total | 3 available | 0 unavailable +StrategyType: RollingUpdate +MinReadySeconds: 0 +RollingUpdateStrategy: 25% max unavailable, 25% max surge Pod Template: - Labels: app=nginx + Labels: app=nginx Containers: nginx: - Image: nginx:1.9.1 - Port: 80/TCP - Environment: - Mounts: - Volumes: + Image: nginx:1.9.1 + Port: 80/TCP + Environment: + Mounts: + Volumes: Conditions: - Type Status Reason - ---- ------ ------ - Available True MinimumReplicasAvailable - Progressing True NewReplicaSetAvailable -OldReplicaSets: -NewReplicaSet: nginx-deployment-1564180365 (3/3 replicas created) + Type Status Reason + ---- ------ ------ + Available True MinimumReplicasAvailable + Progressing True NewReplicaSetAvailable +OldReplicaSets: +NewReplicaSet: nginx-deployment-6bd4859cdb (3/3 replicas created) Events: - FirstSeen LastSeen Count From SubobjectPath Type Reason Message - --------- -------- ----- ---- ------------- -------- ------ ------- - 36s 36s 1 {deployment-controller } Normal ScalingReplicaSet Scaled up replica set nginx-deployment-2035384211 to 3 - 23s 23s 1 {deployment-controller } Normal ScalingReplicaSet Scaled up replica set nginx-deployment-1564180365 to 1 - 23s 23s 1 {deployment-controller } Normal ScalingReplicaSet Scaled down replica set nginx-deployment-2035384211 to 2 - 23s 23s 1 {deployment-controller } Normal ScalingReplicaSet Scaled up replica set nginx-deployment-1564180365 to 2 - 21s 21s 1 {deployment-controller } Normal ScalingReplicaSet Scaled down replica set nginx-deployment-2035384211 to 0 - 21s 21s 1 {deployment-controller } Normal ScalingReplicaSet Scaled up replica set nginx-deployment-1564180365 to 3 + Type Reason Age From Message + ---- ------ ---- ---- ------- + Normal ScalingReplicaSet 2m deployment-controller Scaled up replica set nginx-deployment-569477d6d8 to 3 + Normal ScalingReplicaSet 24s deployment-controller Scaled up replica set nginx-deployment-6bd4859cdb to 1 + Normal ScalingReplicaSet 22s deployment-controller Scaled down replica set nginx-deployment-569477d6d8 to 2 + Normal ScalingReplicaSet 22s deployment-controller Scaled up replica set nginx-deployment-6bd4859cdb to 2 + Normal ScalingReplicaSet 19s deployment-controller Scaled down replica set nginx-deployment-569477d6d8 to 1 + Normal ScalingReplicaSet 19s deployment-controller Scaled up replica set nginx-deployment-6bd4859cdb to 3 + Normal ScalingReplicaSet 14s deployment-controller Scaled down replica set nginx-deployment-569477d6d8 to 0 ``` Here we see that when we first created the Deployment, it created a ReplicaSet (nginx-deployment-2035384211) diff --git a/docs/concepts/workloads/controllers/garbage-collection.md b/docs/concepts/workloads/controllers/garbage-collection.md index 98c78d184c..8957411b19 100644 --- a/docs/concepts/workloads/controllers/garbage-collection.md +++ b/docs/concepts/workloads/controllers/garbage-collection.md @@ -102,8 +102,8 @@ the background. ### Setting the cascading deletion policy -To control the cascading deletion policy, set the `deleteOptions.propagationPolicy` -field on your owner object. Possible values include "Orphan", +To control the cascading deletion policy, set the `propagationPolicy` +field on the `deleteOptions` argument when deleting an Object. Possible values include "Orphan", "Foreground", or "Background". Prior to Kubernetes 1.9, the default garbage collection policy for many controller resources was `orphan`. diff --git a/docs/concepts/workloads/controllers/job.yaml b/docs/concepts/workloads/controllers/job.yaml index feebd880cb..b448f2eb81 100644 --- a/docs/concepts/workloads/controllers/job.yaml +++ b/docs/concepts/workloads/controllers/job.yaml @@ -4,8 +4,6 @@ metadata: name: pi spec: template: - metadata: - name: pi spec: containers: - name: pi diff --git a/docs/concepts/workloads/controllers/jobs-run-to-completion.md b/docs/concepts/workloads/controllers/jobs-run-to-completion.md index a0276e8b32..08324bb86e 100644 --- a/docs/concepts/workloads/controllers/jobs-run-to-completion.md +++ b/docs/concepts/workloads/controllers/jobs-run-to-completion.md @@ -240,8 +240,6 @@ spec: backoffLimit: 5 activeDeadlineSeconds: 100 template: - metadata: - name: pi spec: containers: - name: pi diff --git a/docs/concepts/workloads/controllers/replicaset.md b/docs/concepts/workloads/controllers/replicaset.md index 79cc6bf27a..fdaec4fe5e 100644 --- a/docs/concepts/workloads/controllers/replicaset.md +++ b/docs/concepts/workloads/controllers/replicaset.md @@ -3,7 +3,7 @@ approvers: - Kashomon - bprashanth - madhusudancs -title: Replica Sets +title: ReplicaSet --- {% capture overview %} diff --git a/docs/concepts/workloads/controllers/replicationcontroller.md b/docs/concepts/workloads/controllers/replicationcontroller.md index 555df714a3..7a4eb08a47 100644 --- a/docs/concepts/workloads/controllers/replicationcontroller.md +++ b/docs/concepts/workloads/controllers/replicationcontroller.md @@ -2,7 +2,7 @@ approvers: - bprashanth - janetkuo -title: Replication Controller +title: ReplicationController --- {% capture overview %} diff --git a/docs/concepts/workloads/controllers/statefulset.md b/docs/concepts/workloads/controllers/statefulset.md index d2496f443a..8fa4c6f8c7 100644 --- a/docs/concepts/workloads/controllers/statefulset.md +++ b/docs/concepts/workloads/controllers/statefulset.md @@ -41,7 +41,7 @@ provides a set of stateless replicas. Controllers such as ## Limitations -* StatefulSet is a beta resource, not available in any Kubernetes release prior to 1.5. +* StatefulSet was a beta resource prior to 1.9 and not available in any Kubernetes release prior to 1.5. * As with all alpha/beta resources, you can disable StatefulSet through the `--runtime-config` option passed to the apiserver. * The storage for a given Pod must either be provisioned by a [PersistentVolume Provisioner](https://github.com/kubernetes/examples/tree/{{page.githubbranch}}/staging/persistent-volume-provisioning/README.md) based on the requested `storage class`, or pre-provisioned by an admin. * Deleting and/or scaling a StatefulSet down will *not* delete the volumes associated with the StatefulSet. This is done to ensure data safety, which is generally more valuable than an automatic purge of all related StatefulSet resources. @@ -87,7 +87,7 @@ spec: terminationGracePeriodSeconds: 10 containers: - name: nginx - image: gcr.io/google_containers/nginx-slim:0.8 + image: k8s.gcr.io/nginx-slim:0.8 ports: - containerPort: 80 name: web diff --git a/docs/concepts/workloads/pods/disruptions.md b/docs/concepts/workloads/pods/disruptions.md index f19e179692..d2049b3ec6 100644 --- a/docs/concepts/workloads/pods/disruptions.md +++ b/docs/concepts/workloads/pods/disruptions.md @@ -131,7 +131,7 @@ during application updates is configured in the controller spec. (Learn about [updating a deployment](/docs/concepts/workloads/controllers/deployment/#updating-a-deployment).) When a pod is evicted using the eviction API, it is gracefully terminated (see -`terminationGracePeriodSeconds` in [PodSpec](/docs/resources-reference/{{page.version}}/#podspec-v1-core).) +`terminationGracePeriodSeconds` in [PodSpec](/docs/api-reference/{{page.version}}/#podspec-v1-core).) ## PDB Example diff --git a/docs/concepts/workloads/pods/pod-lifecycle.md b/docs/concepts/workloads/pods/pod-lifecycle.md index 8f3f62dcb8..8e22ec2556 100644 --- a/docs/concepts/workloads/pods/pod-lifecycle.md +++ b/docs/concepts/workloads/pods/pod-lifecycle.md @@ -17,7 +17,7 @@ This page describes the lifecycle of a Pod. ## Pod phase A Pod's `status` field is a -[PodStatus](/docs/resources-reference/{{page.version}}/#podstatus-v1-core) +[PodStatus](/docs/api-reference/{{page.version}}/#podstatus-v1-core) object, which has a `phase` field. The phase of a Pod is a simple, high-level summary of where the Pod is in its @@ -52,7 +52,7 @@ Here are the possible values for `phase`: ## Pod conditions A Pod has a PodStatus, which has an array of -[PodConditions](/docs/resources-reference/{{page.version}}/#podcondition-v1-core). Each element +[PodConditions](/docs/api-reference/{{page.version}}/#podcondition-v1-core). Each element of the PodCondition array has a `type` field and a `status` field. The `type` field is a string, with possible values PodScheduled, Ready, Initialized, and Unschedulable. The `status` field is a string, with possible values True, False, @@ -60,22 +60,22 @@ and Unknown. ## Container probes -A [Probe](/docs/resources-reference/{{page.version}}/#probe-v1-core) is a diagnostic +A [Probe](/docs/api-reference/{{page.version}}/#probe-v1-core) is a diagnostic performed periodically by the [kubelet](/docs/admin/kubelet/) on a Container. To perform a diagnostic, the kubelet calls a [Handler](https://godoc.org/k8s.io/kubernetes/pkg/api/v1#Handler) implemented by the Container. There are three types of handlers: -* [ExecAction](/docs/resources-reference/{{page.version}}/#execaction-v1-core): +* [ExecAction](/docs/api-reference/{{page.version}}/#execaction-v1-core): Executes a specified command inside the Container. The diagnostic is considered successful if the command exits with a status code of 0. -* [TCPSocketAction](/docs/resources-reference/{{page.version}}/#tcpsocketaction-v1-core): +* [TCPSocketAction](/docs/api-reference/{{page.version}}/#tcpsocketaction-v1-core): Performs a TCP check against the Container's IP address on a specified port. The diagnostic is considered successful if the port is open. -* [HTTPGetAction](/docs/resources-reference/{{page.version}}/#httpgetaction-v1-core): +* [HTTPGetAction](/docs/api-reference/{{page.version}}/#httpgetaction-v1-core): Performs an HTTP Get request against the Container's IP address on a specified port and path. The diagnostic is considered successful if the response has a status code greater than or equal to 200 and less than 400. @@ -129,11 +129,11 @@ to stop. ## Pod and Container status For detailed information about Pod Container status, see -[PodStatus](/docs/resources-reference/{{page.version}}/#podstatus-v1-core) +[PodStatus](/docs/api-reference/{{page.version}}/#podstatus-v1-core) and -[ContainerStatus](/docs/resources-reference/{{page.version}}/#containerstatus-v1-core). +[ContainerStatus](/docs/api-reference/{{page.version}}/#containerstatus-v1-core). Note that the information reported as Pod status depends on the current -[ContainerState](/docs/resources-reference/{{page.version}}/#containerstatus-v1-core). +[ContainerState](/docs/api-reference/{{page.version}}/#containerstatus-v1-core). ## Restart policy @@ -198,7 +198,7 @@ spec: containers: - args: - /server - image: gcr.io/google_containers/liveness + image: k8s.gcr.io/liveness livenessProbe: httpGet: # when "host" is not defined, "PodIP" will be used diff --git a/docs/concepts/workloads/pods/pod.md b/docs/concepts/workloads/pods/pod.md index 3364d24a14..c07608e601 100644 --- a/docs/concepts/workloads/pods/pod.md +++ b/docs/concepts/workloads/pods/pod.md @@ -32,7 +32,9 @@ Containers within a pod share an IP address and port space, and can find each other via `localhost`. They can also communicate with each other using standard inter-process communications like SystemV semaphores or POSIX shared memory. Containers in different pods have distinct IP addresses -and can not communicate by IPC. +and can not communicate by IPC without +[special configuration](/docs/concepts/policy/pod-security-policy/). +These containers usually communicate with each other via Pod IP addresses. Applications within a pod also have access to shared volumes, which are defined as part of a pod and are made available to be mounted into each application's @@ -40,7 +42,7 @@ filesystem. In terms of [Docker](https://www.docker.com/) constructs, a pod is modelled as a group of Docker containers with shared namespaces and shared -[volumes](/docs/concepts/storage/volumes/). PID namespace sharing is not yet implemented in Docker. +[volumes](/docs/concepts/storage/volumes/). Like individual application containers, pods are considered to be relatively ephemeral (rather than durable) entities. As discussed in [life of a diff --git a/docs/getting-started-guides/binary_release.md b/docs/getting-started-guides/binary_release.md index 8fa4e66f83..404ec368b9 100644 --- a/docs/getting-started-guides/binary_release.md +++ b/docs/getting-started-guides/binary_release.md @@ -50,11 +50,7 @@ export KUBERNETES_PROVIDER=YOUR_PROVIDER; curl -sS https://get.k8s.io | bash Possible values for `YOUR_PROVIDER` include: * `gce` - Google Compute Engine [default] -* `gke` - Google Kubernetes Engine -* `aws` - Amazon EC2 -* `azure` - Microsoft Azure * `vagrant` - Vagrant (on local virtual machines) * `vsphere` - VMWare VSphere -* `rackspace` - Rackspace For the complete, up-to-date list of providers supported by this script, see the [`/cluster`](https://github.com/kubernetes/kubernetes/tree/{{page.githubbranch}}/cluster) folder in the main Kubernetes repo, where each folder represents a possible value for `YOUR_PROVIDER`. If you don't see your desired provider, try looking at our [getting started guides](/docs/setup/); there's a good chance we have docs for them. diff --git a/docs/getting-started-guides/fluentd-gcp.yaml b/docs/getting-started-guides/fluentd-gcp.yaml index a81427bdfc..d212752cca 100644 --- a/docs/getting-started-guides/fluentd-gcp.yaml +++ b/docs/getting-started-guides/fluentd-gcp.yaml @@ -14,7 +14,7 @@ spec: dnsPolicy: Default containers: - name: fluentd-cloud-logging - image: gcr.io/google_containers/fluentd-gcp:2.0.2 + image: k8s.gcr.io/fluentd-gcp:2.0.2 # If fluentd consumes its own logs, the following situation may happen: # fluentd fails to send a chunk to the server => writes it to the log => # tries to send this message to the server => fails to send a chunk and so on. diff --git a/docs/getting-started-guides/minikube.md b/docs/getting-started-guides/minikube.md index 470a452c11..54f172add9 100644 --- a/docs/getting-started-guides/minikube.md +++ b/docs/getting-started-guides/minikube.md @@ -35,7 +35,8 @@ the following drivers: * virtualbox * vmwarefusion * kvm ([driver installation](https://git.k8s.io/minikube/docs/drivers.md#kvm-driver)) -* xhyve ([driver installation](https://git.k8s.io/minikube/docs/drivers.md#xhyve-driver)) +* hyperkit ([driver installation](https://git.k8s.io/minikube/docs/drivers.md#hyperkit-driver)) +* xhyve ([driver installation](https://git.k8s.io/minikube/docs/drivers.md#xhyve-driver)) (deprecated) Note that the IP below is dynamic and can change. It can be retrieved with `minikube ip`. @@ -46,7 +47,7 @@ Running pre-create checks... Creating machine... Starting local Kubernetes cluster... -$ kubectl run hello-minikube --image=gcr.io/google_containers/echoserver:1.4 --port=8080 +$ kubectl run hello-minikube --image=k8s.gcr.io/echoserver:1.4 --port=8080 deployment "hello-minikube" created $ kubectl expose deployment hello-minikube --type=NodePort service "hello-minikube" exposed @@ -160,7 +161,7 @@ This command also configures your [kubectl](/docs/user-guide/kubectl-overview/) If you are behind a web proxy, you will need to pass this information in e.g. via ``` -https_proxy= minikube start --docker-env HTTP_PROXY= --docker-env HTTPS_PROXY= --docker-env NO_PROXY=192.168.99.0/24 +https_proxy= minikube start --docker-env http_proxy= --docker-env https_proxy= --docker-env no_proxy=192.168.99.0/24 ``` Unfortunately just setting the environment variables will not work. @@ -325,8 +326,8 @@ To do this, pass the required environment variables as flags during `minikube st For example: ```shell -$ minikube start --docker-env HTTP_PROXY=http://$YOURPROXY:PORT \ - --docker-env HTTPS_PROXY=https://$YOURPROXY:PORT +$ minikube start --docker-env http_proxy=http://$YOURPROXY:PORT \ + --docker-env https_proxy=https://$YOURPROXY:PORT ``` If your Virtual Machine address is 192.168.99.100, then chances are your proxy settings will prevent kubectl from directly reaching it. diff --git a/docs/home/contribute/write-new-topic.md b/docs/home/contribute/write-new-topic.md index 95f57d2f3d..ccde10eb9f 100644 --- a/docs/home/contribute/write-new-topic.md +++ b/docs/home/contribute/write-new-topic.md @@ -27,7 +27,7 @@ is the best fit for your content: Tutorial - A tutorial page shows how to accomplish a goal that ties together several Kubernetes features. A tutorial might provide several sequences of steps that readers can actually do as they read the page. Or it might provide explanations of related pieces of code. For example, a tutorial could provide a walkthrough of a code sample. A tutorial can include brief explanations of the Kubernetes features that are being tied togeter, but should link to related concept topics for deep explanations of individual features. + A tutorial page shows how to accomplish a goal that ties together several Kubernetes features. A tutorial might provide several sequences of steps that readers can actually do as they read the page. Or it might provide explanations of related pieces of code. For example, a tutorial could provide a walkthrough of a code sample. A tutorial can include brief explanations of the Kubernetes features that are being tied together, but should link to related concept topics for deep explanations of individual features. diff --git a/docs/reference/client-libraries.md b/docs/reference/client-libraries.md index e4770be0f6..185612a51d 100644 --- a/docs/reference/client-libraries.md +++ b/docs/reference/client-libraries.md @@ -57,6 +57,7 @@ their authors, not the Kubernetes team. | Ruby | [github.com/abonas/kubeclient](https://github.com/abonas/kubeclient) | | Scala | [github.com/doriordan/skuber](https://github.com/doriordan/skuber) | | dotNet | [https://github.com/tonnyeremin/kubernetes_gen](https://github.com/tonnyeremin/kubernetes_gen) +| DotNet (RestSharp) | [github.com/masroorhasan/Kubernetes.DotNet](https://github.com/masroorhasan/Kubernetes.DotNet) {% endcapture %} {% include templates/concept.md %} diff --git a/docs/reference/generated/kubefed_init.md b/docs/reference/generated/kubefed_init.md index b8920cb603..d58736792e 100644 --- a/docs/reference/generated/kubefed_init.md +++ b/docs/reference/generated/kubefed_init.md @@ -40,13 +40,13 @@ kubefed init FEDERATION_NAME --host-cluster-context=HOST_CONTEXT --dns-provider-config string Config file path on local file system for configuring DNS provider. --dns-zone-name string DNS suffix for this federation. Federated Service DNS names are published with this suffix. --dry-run dry run without sending commands to server. - --etcd-image string Image to use for etcd server. (default "gcr.io/google_containers/etcd:3.1.10") + --etcd-image string Image to use for etcd server. (default "k8s.gcr.io/etcd:3.1.10") --etcd-persistent-storage Use persistent volume for etcd. Defaults to 'true'. (default true) --etcd-pv-capacity string Size of persistent volume claim to be used for etcd. (default "10Gi") --etcd-pv-storage-class string The storage class of the persistent volume claim used for etcd. Must be provided if a default storage class is not enabled for the host cluster. --federation-system-namespace string Namespace in the host cluster where the federation system components are installed (default "federation-system") --host-cluster-context string Host cluster context - --image string Image to use for federation API server and controller manager binaries. (default "gcr.io/google_containers/hyperkube-amd64:v0.0.0-master_$Format:%h$") + --image string Image to use for federation API server and controller manager binaries. (default "k8s.gcr.io/hyperkube-amd64:v0.0.0-master_$Format:%h$") --image-pull-policy string PullPolicy describes a policy for if/when to pull a container image. The default pull policy is IfNotPresent which will not pull an image if it already exists. (default "IfNotPresent") --image-pull-secrets string Provide secrets that can access the private registry. --kubeconfig string Path to the kubeconfig file to use for CLI requests. diff --git a/docs/reference/generated/kubelet.md b/docs/reference/generated/kubelet.md index 0f3cdf79f1..c97c0bc95c 100644 --- a/docs/reference/generated/kubelet.md +++ b/docs/reference/generated/kubelet.md @@ -167,7 +167,7 @@ VolumeScheduling=true|false (ALPHA - default=false) --node-status-update-frequency duration Specifies how often kubelet posts node status to master. Note: be cautious when changing the constant, it must work with nodeMonitorGracePeriod in nodecontroller. (default 10s) --oom-score-adj int32 The oom-score-adj value for kubelet process. Values must be within the range [-1000, 1000] (default -999) --pod-cidr string The CIDR to use for pod IP addresses, only used in standalone mode. In cluster mode, this is obtained from the master. - --pod-infra-container-image string The image whose network/ipc namespaces containers in each pod will use. (default "gcr.io/google_containers/pause-amd64:3.0") + --pod-infra-container-image string The image whose network/ipc namespaces containers in each pod will use. (default "k8s.gcr.io/pause-amd64:3.0") --pod-manifest-path string Path to the directory containing pod manifest files to run, or the path to a single pod manifest file. Files starting with dots will be ignored. --pods-per-core int32 Number of Pods per core that can run on this Kubelet. The total number of Pods on this Kubelet cannot exceed max-pods, so max-pods will be used if this calculation results in a larger number of Pods allowed on the Kubelet. A value of 0 disables this limit. --port int32 The port for the Kubelet to serve on. (default 10250) diff --git a/docs/reference/generated/kubernetes-api/v1.9/index.html b/docs/reference/generated/kubernetes-api/v1.9/index.html index 0f81fe78e8..ee5ea737b1 100644 --- a/docs/reference/generated/kubernetes-api/v1.9/index.html +++ b/docs/reference/generated/kubernetes-api/v1.9/index.html @@ -520,6 +520,10 @@ Appears In: +202
CronJob +Accepted + + 200
CronJob OK @@ -527,10 +531,6 @@ Appears In: 201
CronJob Created - -202
CronJob -Accepted -

Patch

@@ -712,13 +712,13 @@ Appears In: -200
CronJob -OK - - 201
CronJob Created + +200
CronJob +OK +

Delete

@@ -2235,10 +2235,6 @@ spec: -202
DaemonSet -Accepted - - 200
DaemonSet OK @@ -2246,6 +2242,10 @@ spec: 201
DaemonSet Created + +202
DaemonSet +Accepted +

Patch

@@ -3785,7 +3785,7 @@ Appears In: maxSurge -The maximum number of pods that can be scheduled above the desired number of pods. Value can be an absolute number (ex: 5) or a percentage of desired pods (ex: 10%). This can not be 0 if MaxUnavailable is 0. Absolute number is calculated from percentage by rounding up. Defaults to 25%. Example: when this is set to 30%, the new RC can be scaled up immediately when the rolling update starts, such that the total number of old and new pods do not exceed 130% of desired pods. Once old pods have been killed, new RC can be scaled up further, ensuring that total number of pods running at any time during the update is atmost 130% of desired pods. +The maximum number of pods that can be scheduled above the desired number of pods. Value can be an absolute number (ex: 5) or a percentage of desired pods (ex: 10%). This can not be 0 if MaxUnavailable is 0. Absolute number is calculated from percentage by rounding up. Defaults to 25%. Example: when this is set to 30%, the new RC can be scaled up immediately when the rolling update starts, such that the total number of old and new pods do not exceed 130% of desired pods. Once old pods have been killed, new RC can be scaled up further, ensuring that total number of pods running at any time during the update is at most 130% of desired pods. maxUnavailable @@ -3975,6 +3975,10 @@ spec: +200
Deployment +OK + + 201
Deployment Created @@ -3982,10 +3986,6 @@ spec: 202
Deployment Accepted - -200
Deployment -OK -

Patch

@@ -4342,13 +4342,13 @@ spec: -201
Deployment -Created - - 200
Deployment OK + +201
Deployment +Created +

Delete

@@ -6372,10 +6372,6 @@ spec: -202
Job -Accepted - - 200
Job OK @@ -6383,6 +6379,10 @@ spec: 201
Job Created + +202
Job +Accepted +

Patch

@@ -8016,7 +8016,8 @@ $ kubectl proxy name: pod-example spec: containers: - - image: ubuntu:trusty + - name: ubuntu + image: ubuntu:trusty command: ["echo"] args: ["Hello World"] @@ -8030,7 +8031,8 @@ $ kubectl proxy name: pod-example spec: containers: - - image: ubuntu:trusty + - name: ubuntu + image: ubuntu:trusty command: ["echo"] args: ["Hello World"] @@ -8387,10 +8389,6 @@ Appears In: -202
Pod -Accepted - - 200
Pod OK @@ -8398,6 +8396,10 @@ Appears In: 201
Pod Created + +202
Pod +Accepted +

Patch

@@ -8579,13 +8581,13 @@ Appears In: -201
Pod -Created - - 200
Pod OK + +201
Pod +Created +

Delete

@@ -9641,13 +9643,13 @@ Appears In: -200
Pod -OK - - 201
Pod Created + +200
Pod +OK +

Proxy Operations

@@ -11701,13 +11703,13 @@ Appears In: -201
ReplicaSet -Created - - 200
ReplicaSet OK + +201
ReplicaSet +Created +

Delete

@@ -12763,13 +12765,13 @@ Appears In: -201
ReplicaSet -Created - - 200
ReplicaSet OK + +201
ReplicaSet +Created +
@@ -14320,13 +14322,13 @@ Appears In: -201
ReplicationController -Created - - 200
ReplicationController OK + +201
ReplicationController +Created +
@@ -14609,10 +14611,6 @@ Appears In: -200
StatefulSet -OK - - 201
StatefulSet Created @@ -14620,6 +14618,10 @@ Appears In: 202
StatefulSet Accepted + +200
StatefulSet +OK +

Patch

@@ -16058,6 +16060,10 @@ Appears In: +202
Endpoints +Accepted + + 200
Endpoints OK @@ -16065,10 +16071,6 @@ Appears In: 201
Endpoints Created - -202
Endpoints -Accepted -

Patch

@@ -16250,13 +16252,13 @@ Appears In: -201
Endpoints -Created - - 200
Endpoints OK + +201
Endpoints +Created +

Delete

@@ -18528,13 +18530,13 @@ Appears In: -200
Ingress -OK - - 201
Ingress Created + +200
Ingress +OK +
@@ -19208,13 +19210,13 @@ service "deployment-example" replaced -201
Service -Created - - 200
Service OK + +201
Service +Created +

Delete

@@ -21789,10 +21791,6 @@ Appears In: -202
ConfigMap -Accepted - - 200
ConfigMap OK @@ -21800,6 +21798,10 @@ Appears In: 201
ConfigMap Created + +202
ConfigMap +Accepted +

Patch

@@ -22957,10 +22959,6 @@ Appears In: -201
Secret -Created - - 202
Secret Accepted @@ -22968,6 +22966,10 @@ Appears In: 200
Secret OK + +201
Secret +Created +

Patch

@@ -23149,13 +23151,13 @@ Appears In: -200
Secret -OK - - 201
Secret Created + +200
Secret +OK +

Delete

@@ -24397,13 +24399,13 @@ Appears In: -201
PersistentVolumeClaim -Created - - 200
PersistentVolumeClaim OK + +201
PersistentVolumeClaim +Created +

Delete

@@ -25641,6 +25643,10 @@ Appears In: +200
StorageClass +OK + + 201
StorageClass Created @@ -25648,10 +25654,6 @@ Appears In: 202
StorageClass Accepted - -200
StorageClass -OK -

Patch

@@ -26465,7 +26467,7 @@ Appears In: flexVolume
FlexVolumeSource -FlexVolume represents a generic volume resource that is provisioned/attached using an exec based plugin. This is an alpha feature and may change in future. +FlexVolume represents a generic volume resource that is provisioned/attached using an exec based plugin. flocker
FlockerVolumeSource @@ -26759,10 +26761,6 @@ Appears In: -200
VolumeAttachment -OK - - 201
VolumeAttachment Created @@ -26770,6 +26768,10 @@ Appears In: 202
VolumeAttachment Accepted + +200
VolumeAttachment +OK +

Patch

@@ -27883,13 +27885,13 @@ Appears In: -200
ControllerRevision -OK - - 201
ControllerRevision Created + +200
ControllerRevision +OK +

Delete

@@ -28904,10 +28906,6 @@ Appears In: -202
CustomResourceDefinition -Accepted - - 200
CustomResourceDefinition OK @@ -28915,6 +28913,10 @@ Appears In: 201
CustomResourceDefinition Created + +202
CustomResourceDefinition +Accepted +

Patch

@@ -29740,13 +29742,13 @@ Appears In: -201
CustomResourceDefinition -Created - - 200
CustomResourceDefinition OK + +201
CustomResourceDefinition +Created +
@@ -29968,6 +29970,10 @@ Appears In: +202
Event +Accepted + + 200
Event OK @@ -29975,10 +29981,6 @@ Appears In: 201
Event Created - -202
Event -Accepted -

Patch

@@ -30160,13 +30162,13 @@ Appears In: -200
Event -OK - - 201
Event Created + +200
Event +OK +

Delete

@@ -31342,13 +31344,13 @@ Appears In: -201
LimitRange -Created - - 200
LimitRange OK + +201
LimitRange +Created +

Delete

@@ -32389,10 +32391,6 @@ Appears In: -200
HorizontalPodAutoscaler -OK - - 201
HorizontalPodAutoscaler Created @@ -32400,6 +32398,10 @@ Appears In: 202
HorizontalPodAutoscaler Accepted + +200
HorizontalPodAutoscaler +OK +

Patch

@@ -32581,13 +32583,13 @@ Appears In: -201
HorizontalPodAutoscaler -Created - - 200
HorizontalPodAutoscaler OK + +201
HorizontalPodAutoscaler +Created +

Delete

@@ -33643,13 +33645,13 @@ Appears In: -200
HorizontalPodAutoscaler -OK - - 201
HorizontalPodAutoscaler Created + +200
HorizontalPodAutoscaler +OK +
@@ -33801,10 +33803,6 @@ Appears In: -202
InitializerConfiguration -Accepted - - 200
InitializerConfiguration OK @@ -33812,6 +33810,10 @@ Appears In: 201
InitializerConfiguration Created + +202
InitializerConfiguration +Accepted +

Patch

@@ -34701,10 +34703,6 @@ Appears In: -202
MutatingWebhookConfiguration -Accepted - - 200
MutatingWebhookConfiguration OK @@ -34712,6 +34710,10 @@ Appears In: 201
MutatingWebhookConfiguration Created + +202
MutatingWebhookConfiguration +Accepted +

Patch

@@ -35601,10 +35603,6 @@ Appears In: -202
ValidatingWebhookConfiguration -Accepted - - 200
ValidatingWebhookConfiguration OK @@ -35612,6 +35610,10 @@ Appears In: 201
ValidatingWebhookConfiguration Created + +202
ValidatingWebhookConfiguration +Accepted +

Patch

@@ -36557,10 +36559,6 @@ Appears In: -200
PodTemplate -OK - - 201
PodTemplate Created @@ -36568,6 +36566,10 @@ Appears In: 202
PodTemplate Accepted + +200
PodTemplate +OK +

Patch

@@ -37793,10 +37795,6 @@ Appears In: -200
PodDisruptionBudget -OK - - 201
PodDisruptionBudget Created @@ -37804,6 +37802,10 @@ Appears In: 202
PodDisruptionBudget Accepted + +200
PodDisruptionBudget +OK +

Patch

@@ -41413,6 +41415,10 @@ Appears In: +202
PodSecurityPolicy +Accepted + + 200
PodSecurityPolicy OK @@ -41420,10 +41426,6 @@ Appears In: 201
PodSecurityPolicy Created - -202
PodSecurityPolicy -Accepted -

Patch

@@ -43363,10 +43365,6 @@ Appears In: -200
Binding -OK - - 201
Binding Created @@ -43374,6 +43372,10 @@ Appears In: 202
Binding Accepted + +200
Binding +OK +
@@ -43597,10 +43599,6 @@ Appears In: -201
CertificateSigningRequest -Created - - 202
CertificateSigningRequest Accepted @@ -43608,6 +43606,10 @@ Appears In: 200
CertificateSigningRequest OK + +201
CertificateSigningRequest +Created +

Patch

@@ -44598,6 +44600,10 @@ Appears In: +200
ClusterRole +OK + + 201
ClusterRole Created @@ -44605,10 +44611,6 @@ Appears In: 202
ClusterRole Accepted - -200
ClusterRole -OK -

Patch

@@ -45497,6 +45499,10 @@ Appears In: +200
ClusterRoleBinding +OK + + 201
ClusterRoleBinding Created @@ -45504,10 +45510,6 @@ Appears In: 202
ClusterRoleBinding Accepted - -200
ClusterRoleBinding -OK -

Patch

@@ -45681,13 +45683,13 @@ Appears In: -200
ClusterRoleBinding -OK - - 201
ClusterRoleBinding Created + +200
ClusterRoleBinding +OK +

Delete

@@ -46621,6 +46623,10 @@ Appears In: +200
LocalSubjectAccessReview +OK + + 201
LocalSubjectAccessReview Created @@ -46628,10 +46634,6 @@ Appears In: 202
LocalSubjectAccessReview Accepted - -200
LocalSubjectAccessReview -OK -
@@ -48000,6 +48002,10 @@ Appears In: +200
Node +OK + + 201
Node Created @@ -48007,10 +48013,6 @@ Appears In: 202
Node Accepted - -200
Node -OK -

Patch

@@ -50357,7 +50359,7 @@ Appears In: flexVolume
FlexVolumeSource -FlexVolume represents a generic volume resource that is provisioned/attached using an exec based plugin. This is an alpha feature and may change in future. +FlexVolume represents a generic volume resource that is provisioned/attached using an exec based plugin. flocker
FlockerVolumeSource @@ -50744,13 +50746,13 @@ Appears In: -201
PersistentVolume -Created - - 200
PersistentVolume OK + +201
PersistentVolume +Created +

Delete

@@ -51786,6 +51788,10 @@ Appears In: +200
ResourceQuota +OK + + 201
ResourceQuota Created @@ -51793,10 +51799,6 @@ Appears In: 202
ResourceQuota Accepted - -200
ResourceQuota -OK -

Patch

@@ -53216,6 +53218,10 @@ Appears In: +202
Role +Accepted + + 200
Role OK @@ -53223,10 +53229,6 @@ Appears In: 201
Role Created - -202
Role -Accepted -

Patch

@@ -53408,13 +53410,13 @@ Appears In: -200
Role -OK - - 201
Role Created + +200
Role +OK +

Delete

@@ -55511,6 +55513,10 @@ Appears In: +200
SelfSubjectAccessReview +OK + + 201
SelfSubjectAccessReview Created @@ -55518,10 +55524,6 @@ Appears In: 202
SelfSubjectAccessReview Accepted - -200
SelfSubjectAccessReview -OK -
@@ -55668,6 +55670,10 @@ Appears In: +200
SelfSubjectRulesReview +OK + + 201
SelfSubjectRulesReview Created @@ -55675,10 +55681,6 @@ Appears In: 202
SelfSubjectRulesReview Accepted - -200
SelfSubjectRulesReview -OK -
@@ -56045,13 +56047,13 @@ Appears In: -200
ServiceAccount -OK - - 201
ServiceAccount Created + +200
ServiceAccount +OK +

Delete

@@ -57050,10 +57052,6 @@ Appears In: -202
SubjectAccessReview -Accepted - - 200
SubjectAccessReview OK @@ -57061,6 +57059,10 @@ Appears In: 201
SubjectAccessReview Created + +202
SubjectAccessReview +Accepted +
@@ -57451,6 +57453,10 @@ Appears In: +201
NetworkPolicy +Created + + 202
NetworkPolicy Accepted @@ -57458,10 +57464,6 @@ Appears In: 200
NetworkPolicy OK - -201
NetworkPolicy -Created -

Patch

@@ -57643,13 +57645,13 @@ Appears In: -200
NetworkPolicy -OK - - 201
NetworkPolicy Created + +200
NetworkPolicy +OK +

Delete

@@ -59719,7 +59721,7 @@ Appears In: names
string array -Names by which this image is known. e.g. ["gcr.io/google_containers/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"] +Names by which this image is known. e.g. ["k8s.gcr.io/hyperkube:v1.0.7", "dockerhub.io/google_containers/hyperkube:v1.0.7"] sizeBytes
integer @@ -61247,7 +61249,7 @@ Appears In: -

FlexVolume represents a generic volume resource that is provisioned/attached using an exec based plugin. This is an alpha feature and may change in future.

+

FlexVolume represents a generic volume resource that is provisioned/attached using an exec based plugin.

-

Secret and configuration management

+

Secret and configuration management

Deploy and update secrets and application configuration without rebuilding your image and without exposing secrets in your stack configuration.

diff --git a/skip_title_check.txt b/skip_title_check.txt index f1fa02234b..e463d20bce 100644 --- a/skip_title_check.txt +++ b/skip_title_check.txt @@ -5,12 +5,6 @@ docs/reference/generated/federation/v1/definitions.html docs/reference/generated/federation/extensions/v1beta1/operations.html docs/reference/generated/federation/extensions/v1beta1/definitions.html docs/sitemap.md -docs/user-guide/configmap/README.md -docs/user-guide/downward-api/README.md -docs/user-guide/pods/_viewing-a-pod.md -docs/user-guide/simple-yaml.md -docs/user-guide/update-demo/images/kitten/README.md -docs/user-guide/update-demo/images/nautilus/README.md docs/reference/setup-tools/kubeadm/generated/README.md docs/reference/setup-tools/kubeadm/generated/kubeadm.md docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha.md diff --git a/skip_toc_check.txt b/skip_toc_check.txt index 6ed6f639e4..dab2f84379 100644 --- a/skip_toc_check.txt +++ b/skip_toc_check.txt @@ -1,24 +1,10 @@ # Put files you want to skip table of contents entry check here: -docs/reference/setup-tools/kubeadm/generated/kubelet-authentication-authorization.md -docs/reference/setup-tools/kubeadm/generated/kubelet-tls-bootstrapping.md -docs/api-reference/labels-annotations-taints.md docs/concepts/example-concept-template.md -docs/contribute/README.md docs/reference/generated/README.md -docs/reference/deprecation-policy.md docs/search.md docs/sitemap.md docs/tasks/example-task-template.md docs/tutorials/example-tutorial-template.md -docs/user-guide/configmap/README.md -docs/user-guide/downward-api/README.md -docs/user-guide/liveness/image/README.md -docs/user-guide/pods/_viewing-a-pod.md -docs/user-guide/simple-yaml.md -docs/user-guide/update-demo/images/kitten/README.md -docs/user-guide/update-demo/images/nautilus/README.md -docs/user-guide/walkthrough/index.md -docs/user-guide/walkthrough/k8s201.md docs/reference/setup-tools/kubeadm/generated/README.md docs/reference/setup-tools/kubeadm/generated/kubeadm.md docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha.md diff --git a/test/examples_test.go b/test/examples_test.go index 085738ff73..b6d9e8c9c7 100644 --- a/test/examples_test.go +++ b/test/examples_test.go @@ -34,6 +34,8 @@ import ( "k8s.io/apimachinery/pkg/util/yaml" utilfeature "k8s.io/apiserver/pkg/util/feature" "k8s.io/kubernetes/pkg/api/testapi" + "k8s.io/kubernetes/pkg/apis/admissionregistration" + ar_validation "k8s.io/kubernetes/pkg/apis/admissionregistration/validation" "k8s.io/kubernetes/pkg/apis/apps" apps_validation "k8s.io/kubernetes/pkg/apis/apps/validation" "k8s.io/kubernetes/pkg/apis/autoscaling" @@ -45,36 +47,49 @@ import ( "k8s.io/kubernetes/pkg/apis/extensions" ext_validation "k8s.io/kubernetes/pkg/apis/extensions/validation" "k8s.io/kubernetes/pkg/apis/policy" - policyvalidation "k8s.io/kubernetes/pkg/apis/policy/validation" + policy_validation "k8s.io/kubernetes/pkg/apis/policy/validation" + "k8s.io/kubernetes/pkg/apis/rbac" + rbac_validation "k8s.io/kubernetes/pkg/apis/rbac/validation" + "k8s.io/kubernetes/pkg/apis/settings" + settings_validation "k8s.io/kubernetes/pkg/apis/settings/validation" "k8s.io/kubernetes/pkg/apis/storage" - storagevalidation "k8s.io/kubernetes/pkg/apis/storage/validation" + storage_validation "k8s.io/kubernetes/pkg/apis/storage/validation" "k8s.io/kubernetes/pkg/capabilities" "k8s.io/kubernetes/pkg/registry/batch/job" - schedulerapilatest "k8s.io/kubernetes/plugin/pkg/scheduler/api/latest" + schedulerapilatest "k8s.io/kubernetes/pkg/scheduler/api/latest" ) func validateObject(obj runtime.Object) (errors field.ErrorList) { // Enable CustomPodDNS for testing utilfeature.DefaultFeatureGate.Set("CustomPodDNS=true") switch t := obj.(type) { - case *api.ReplicationController: + case *admissionregistration.InitializerConfiguration: + // cluster scope resource + errors = ar_validation.ValidateInitializerConfiguration(t) + case *api.ConfigMap: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } - errors = validation.ValidateReplicationController(t) - case *api.ReplicationControllerList: - for i := range t.Items { - errors = append(errors, validateObject(&t.Items[i])...) - } - case *api.Service: + errors = validation.ValidateConfigMap(t) + case *api.Endpoints: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } - errors = validation.ValidateService(t) - case *api.ServiceList: - for i := range t.Items { - errors = append(errors, validateObject(&t.Items[i])...) + errors = validation.ValidateEndpoints(t) + case *api.LimitRange: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault } + errors = validation.ValidateLimitRange(t) + case *api.Namespace: + errors = validation.ValidateNamespace(t) + case *api.PersistentVolume: + errors = validation.ValidatePersistentVolume(t) + case *api.PersistentVolumeClaim: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = validation.ValidatePersistentVolumeClaim(t) case *api.Pod: if t.Namespace == "" { t.Namespace = api.NamespaceDefault @@ -84,55 +99,54 @@ func validateObject(obj runtime.Object) (errors field.ErrorList) { for i := range t.Items { errors = append(errors, validateObject(&t.Items[i])...) } - case *api.PersistentVolume: - errors = validation.ValidatePersistentVolume(t) - case *api.PersistentVolumeClaim: - if t.Namespace == "" { - t.Namespace = api.NamespaceDefault - } - errors = validation.ValidatePersistentVolumeClaim(t) case *api.PodTemplate: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } errors = validation.ValidatePodTemplate(t) - case *api.Endpoints: + case *api.ReplicationController: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } - errors = validation.ValidateEndpoints(t) - case *api.Namespace: - errors = validation.ValidateNamespace(t) - case *api.Secret: - if t.Namespace == "" { - t.Namespace = api.NamespaceDefault + errors = validation.ValidateReplicationController(t) + case *api.ReplicationControllerList: + for i := range t.Items { + errors = append(errors, validateObject(&t.Items[i])...) } - errors = validation.ValidateSecret(t) - case *api.LimitRange: - if t.Namespace == "" { - t.Namespace = api.NamespaceDefault - } - errors = validation.ValidateLimitRange(t) case *api.ResourceQuota: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } errors = validation.ValidateResourceQuota(t) + case *api.Secret: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = validation.ValidateSecret(t) + case *api.Service: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = validation.ValidateService(t) + case *api.ServiceAccount: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = validation.ValidateServiceAccount(t) + case *api.ServiceList: + for i := range t.Items { + errors = append(errors, validateObject(&t.Items[i])...) + } + case *apps.StatefulSet: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = apps_validation.ValidateStatefulSet(t) case *autoscaling.HorizontalPodAutoscaler: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } errors = autoscaling_validation.ValidateHorizontalPodAutoscaler(t) - case *extensions.Deployment: - if t.Namespace == "" { - t.Namespace = api.NamespaceDefault - } - errors = ext_validation.ValidateDeployment(t) - case *extensions.ReplicaSet: - if t.Namespace == "" { - t.Namespace = api.NamespaceDefault - } - errors = ext_validation.ValidateReplicaSet(t) case *batch.Job: if t.Namespace == "" { t.Namespace = api.NamespaceDefault @@ -140,42 +154,53 @@ func validateObject(obj runtime.Object) (errors field.ErrorList) { // Job needs generateSelector called before validation, and job.Validate does this. // See: https://github.com/kubernetes/kubernetes/issues/20951#issuecomment-187787040 t.ObjectMeta.UID = types.UID("fakeuid") - errors = job.Strategy.Validate(nil, t) - case *extensions.Ingress: - if t.Namespace == "" { - t.Namespace = api.NamespaceDefault + if strings.Index(t.ObjectMeta.Name, "$") > -1 { + t.ObjectMeta.Name = "skip-for-good" } - errors = ext_validation.ValidateIngress(t) + errors = job.Strategy.Validate(nil, t) case *extensions.DaemonSet: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } errors = ext_validation.ValidateDaemonSet(t) + case *extensions.Deployment: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = ext_validation.ValidateDeployment(t) + case *extensions.Ingress: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = ext_validation.ValidateIngress(t) case *extensions.PodSecurityPolicy: errors = ext_validation.ValidatePodSecurityPolicy(t) + case *extensions.ReplicaSet: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = ext_validation.ValidateReplicaSet(t) case *batch.CronJob: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } errors = batch_validation.ValidateCronJob(t) - case *api.ConfigMap: - if t.Namespace == "" { - t.Namespace = api.NamespaceDefault - } - errors = validation.ValidateConfigMap(t) - case *apps.StatefulSet: - if t.Namespace == "" { - t.Namespace = api.NamespaceDefault - } - errors = apps_validation.ValidateStatefulSet(t) case *policy.PodDisruptionBudget: if t.Namespace == "" { t.Namespace = api.NamespaceDefault } - errors = policyvalidation.ValidatePodDisruptionBudget(t) + errors = policy_validation.ValidatePodDisruptionBudget(t) + case *rbac.ClusterRoleBinding: + // clusterolebinding does not accept namespace + errors = rbac_validation.ValidateClusterRoleBinding(t) + case *settings.PodPreset: + if t.Namespace == "" { + t.Namespace = api.NamespaceDefault + } + errors = settings_validation.ValidatePodPreset(t) case *storage.StorageClass: // storageclass does not accept namespace - errors = storagevalidation.ValidateStorageClass(t) + errors = storage_validation.ValidateStorageClass(t) default: errors = field.ErrorList{} errors = append(errors, field.InternalError(field.NewPath(""), fmt.Errorf("no validation defined for %#v", obj))) @@ -254,10 +279,6 @@ func TestExampleObjectSchemas(t *testing.T) { "pod2": {&api.Pod{}}, "pod3": {&api.Pod{}}, }, - "../docs/admin/namespaces": { - "namespace-dev": {&api.Namespace{}}, - "namespace-prod": {&api.Namespace{}}, - }, "../docs/admin/resourcequota": { "best-effort": {&api.ResourceQuota{}}, "compute-resources": {&api.ResourceQuota{}}, @@ -288,7 +309,7 @@ func TestExampleObjectSchemas(t *testing.T) { }, "../docs/concepts/services-networking": { "curlpod": {&extensions.Deployment{}}, - "custom-dns": {&api.Pod{}}, + "custom-dns": {&api.Pod{}}, "hostaliases-pod": {&api.Pod{}}, "ingress": {&extensions.Ingress{}}, "nginx-secure-app": {&api.Service{}, &extensions.Deployment{}}, @@ -305,6 +326,121 @@ func TestExampleObjectSchemas(t *testing.T) { "nginx-deployment": {&extensions.Deployment{}}, "replication": {&api.ReplicationController{}}, }, + "../docs/tasks/access-application-cluster": { + "frontend": {&api.Service{}, &extensions.Deployment{}}, + "hello-service": {&api.Service{}}, + "hello": {&extensions.Deployment{}}, + "redis-master": {&api.Pod{}}, + "two-container-pod": {&api.Pod{}}, + }, + "../docs/tasks/administer-cluster": { + "busybox": {&api.Pod{}}, + "cloud-controller-manager-daemonset-example": {&api.ServiceAccount{}, &rbac.ClusterRoleBinding{}, &extensions.DaemonSet{}}, + "cpu-constraints": {&api.LimitRange{}}, + "cpu-constraints-pod": {&api.Pod{}}, + "cpu-constraints-pod-2": {&api.Pod{}}, + "cpu-constraints-pod-3": {&api.Pod{}}, + "cpu-constraints-pod-4": {&api.Pod{}}, + "cpu-defaults": {&api.LimitRange{}}, + "cpu-defaults-pod": {&api.Pod{}}, + "cpu-defaults-pod-2": {&api.Pod{}}, + "cpu-defaults-pod-3": {&api.Pod{}}, + "dns-horizontal-autoscaler": {&extensions.Deployment{}}, + "memory-constraints": {&api.LimitRange{}}, + "memory-constraints-pod": {&api.Pod{}}, + "memory-constraints-pod-2": {&api.Pod{}}, + "memory-constraints-pod-3": {&api.Pod{}}, + "memory-constraints-pod-4": {&api.Pod{}}, + "memory-defaults": {&api.LimitRange{}}, + "memory-defaults-pod": {&api.Pod{}}, + "memory-defaults-pod-2": {&api.Pod{}}, + "memory-defaults-pod-3": {&api.Pod{}}, + "my-scheduler": {&extensions.Deployment{}}, + "namespace-dev": {&api.Namespace{}}, + "namespace-prod": {&api.Namespace{}}, + "persistent-volume-label-initializer-config": {&admissionregistration.InitializerConfiguration{}}, + "pod1": {&api.Pod{}}, + "pod2": {&api.Pod{}}, + "pod3": {&api.Pod{}}, + "quota-mem-cpu": {&api.ResourceQuota{}}, + "quota-mem-cpu-pod": {&api.Pod{}}, + "quota-mem-cpu-pod-2": {&api.Pod{}}, + "quota-objects": {&api.ResourceQuota{}}, + "quota-objects-pvc": {&api.PersistentVolumeClaim{}}, + "quota-objects-pvc-2": {&api.PersistentVolumeClaim{}}, + "quota-pod": {&api.ResourceQuota{}}, + "quota-pod-deployment": {&extensions.Deployment{}}, + "quota-pvc-2": {&api.PersistentVolumeClaim{}}, + }, + "../docs/tasks/configure-pod-container": { + "cpu-request-limit": {&api.Pod{}}, + "cpu-request-limit-2": {&api.Pod{}}, + "exec-liveness": {&api.Pod{}}, + "extended-resource-pod": {&api.Pod{}}, + "extended-resource-pod-2": {&api.Pod{}}, + "http-liveness": {&api.Pod{}}, + "init-containers": {&api.Pod{}}, + "lifecycle-events": {&api.Pod{}}, + "mem-limit-range": {&api.LimitRange{}}, + "memory-request-limit": {&api.Pod{}}, + "memory-request-limit-2": {&api.Pod{}}, + "memory-request-limit-3": {&api.Pod{}}, + "oir-pod": {&api.Pod{}}, + "oir-pod-2": {&api.Pod{}}, + "pod": {&api.Pod{}}, + "pod-redis": {&api.Pod{}}, + "private-reg-pod": {&api.Pod{}}, + "projected-volume": {&api.Pod{}}, + "qos-pod": {&api.Pod{}}, + "qos-pod-2": {&api.Pod{}}, + "qos-pod-3": {&api.Pod{}}, + "qos-pod-4": {&api.Pod{}}, + "rq-compute-resources": {&api.ResourceQuota{}}, + "security-context": {&api.Pod{}}, + "security-context-2": {&api.Pod{}}, + "security-context-3": {&api.Pod{}}, + "security-context-4": {&api.Pod{}}, + "task-pv-claim": {&api.PersistentVolumeClaim{}}, + "task-pv-pod": {&api.Pod{}}, + "task-pv-volume": {&api.PersistentVolume{}}, + "tcp-liveness-readiness": {&api.Pod{}}, + }, + "../docs/tasks/debug-application-cluster": { + "counter-pod": {&api.Pod{}}, + "event-exporter-deploy": {&api.ServiceAccount{}, &rbac.ClusterRoleBinding{}, &extensions.Deployment{}}, + "fluentd-gcp-configmap": {&api.ConfigMap{}}, + "fluentd-gcp-ds": {&extensions.DaemonSet{}}, + "nginx-dep": {&extensions.Deployment{}}, + "shell-demo": {&api.Pod{}}, + "termination": {&api.Pod{}}, + }, + // TODO: decide whether federation examples should be added + "../docs/tasks/inject-data-application": { + "commands": {&api.Pod{}}, + "dapi-envars-container": {&api.Pod{}}, + "dapi-envars-pod": {&api.Pod{}}, + "dapi-volume": {&api.Pod{}}, + "dapi-volume-resources": {&api.Pod{}}, + "envars": {&api.Pod{}}, + "podpreset-allow-db": {&settings.PodPreset{}}, + "podpreset-allow-db-merged": {&api.Pod{}}, + "podpreset-configmap": {&api.ConfigMap{}}, + "podpreset-conflict-pod": {&api.Pod{}}, + "podpreset-conflict-preset": {&settings.PodPreset{}}, + "podpreset-merged": {&api.Pod{}}, + "podpreset-multi-merged": {&api.Pod{}}, + "podpreset-pod": {&api.Pod{}}, + "podpreset-preset": {&settings.PodPreset{}}, + "podpreset-proxy": {&settings.PodPreset{}}, + "podpreset-replicaset-merged": {&api.Pod{}}, + "podpreset-replicaset": {&extensions.ReplicaSet{}}, + "secret": {&api.Secret{}}, + "secret-envars-pod": {&api.Pod{}}, + "secret-pod": {&api.Pod{}}, + }, + "../docs/tasks/job": { + "job": {&batch.Job{}}, + }, "../docs/tasks/job/coarse-parallel-processing-work-queue": { "job": {&batch.Job{}}, }, @@ -313,21 +449,54 @@ func TestExampleObjectSchemas(t *testing.T) { "redis-pod": {&api.Pod{}}, "redis-service": {&api.Service{}}, }, - "../docs/tutorials/stateful-application": { - "gce-volume": {&api.PersistentVolume{}}, + "../docs/tasks/run-application": { + "deployment": {&extensions.Deployment{}}, + "deployment-patch-demo": {&extensions.Deployment{}}, + "deployment-scale": {&extensions.Deployment{}}, + "deployment-update": {&extensions.Deployment{}}, + "hpa-php-apache": {&autoscaling.HorizontalPodAutoscaler{}}, + "mysql-configmap": {&api.ConfigMap{}}, "mysql-deployment": {&api.Service{}, &api.PersistentVolumeClaim{}, &extensions.Deployment{}}, "mysql-services": {&api.Service{}, &api.Service{}}, - "mysql-configmap": {&api.ConfigMap{}}, "mysql-statefulset": {&apps.StatefulSet{}}, - "cassandra-service": {&api.Service{}}, - "cassandra-statefulset": {&apps.StatefulSet{}, &storage.StorageClass{}}, + }, + "../docs/tutorials/clusters": { + "hello-apparmor-pod": {&api.Pod{}}, + "my-scheduler": {&extensions.Deployment{}}, + }, + "../docs/tutorials/object-management-kubectl": { + "simple_deployment": {&extensions.Deployment{}}, + "update_deployment": {&extensions.Deployment{}}, + }, + "../docs/tutorials/stateful-application": { "web": {&api.Service{}, &apps.StatefulSet{}}, "webp": {&api.Service{}, &apps.StatefulSet{}}, "zookeeper": {&api.Service{}, &api.Service{}, &policy.PodDisruptionBudget{}, &apps.StatefulSet{}}, }, + "../docs/tutorials/stateful-application/cassandra": { + "cassandra-service": {&api.Service{}}, + "cassandra-statefulset": {&apps.StatefulSet{}, &storage.StorageClass{}}, + }, + "../docs/tutorials/stateful-application/mysql-wordpress-persistent-volume": { + "local-volumes": {&api.PersistentVolume{}, &api.PersistentVolume{}}, + "mysql-deployment": {&api.Service{}, &api.PersistentVolumeClaim{}, &extensions.Deployment{}}, + "wordpress-deployment": {&api.Service{}, &api.PersistentVolumeClaim{}, &extensions.Deployment{}}, + }, + "../docs/tutorials/stateless-application": { + "deployment": {&extensions.Deployment{}}, + "deployment-scale": {&extensions.Deployment{}}, + "deployment-update": {&extensions.Deployment{}}, + }, + "../docs/tutorials/stateless-application/guestbook": { + "frontend-deployment": {&extensions.Deployment{}}, + "frontend-service": {&api.Service{}}, + "redis-master-deployment": {&extensions.Deployment{}}, + "redis-master-service": {&api.Service{}}, + "redis-slave-deployment": {&extensions.Deployment{}}, + "redis-slave-service": {&api.Service{}}, + }, "../docs/user-guide": { "bad-nginx-deployment": {&extensions.Deployment{}}, - "counter-pod": {&api.Pod{}}, "curlpod": {&extensions.Deployment{}}, "deployment": {&extensions.Deployment{}}, "ingress": {&extensions.Ingress{}}, @@ -347,46 +516,69 @@ func TestExampleObjectSchemas(t *testing.T) { "redis-resource-deployment": {&extensions.Deployment{}}, "redis-secret-deployment": {&extensions.Deployment{}}, "run-my-nginx": {&extensions.Deployment{}}, - "cronjob": {&batch.CronJob{}}, + }, + "../docs/user-guide/configmap": { + "command-pod": {&api.Pod{}}, + "configmap": {&api.ConfigMap{}}, + "env-pod": {&api.Pod{}}, + "mount-file-pod": {&api.Pod{}}, + "volume-pod": {&api.Pod{}}, + }, + "../docs/user-guide/configmap/redis": { + "redis-pod": {&api.Pod{}}, }, "../docs/user-guide/downward-api": { "dapi-pod": {&api.Pod{}}, "dapi-container-resources": {&api.Pod{}}, }, - "../docs/user-guide/downward-api/volume/": { + "../docs/user-guide/downward-api/volume": { "dapi-volume": {&api.Pod{}}, "dapi-volume-resources": {&api.Pod{}}, }, + "../docs/user-guide/environment-guide": { + "backend-rc": {&api.ReplicationController{}}, + "backend-srv": {&api.Service{}}, + "show-rc": {&api.ReplicationController{}}, + "show-srv": {&api.Service{}}, + }, + "../docs/user-guide/horizontal-pod-autoscaling": { + "hpa-php-apache": {&autoscaling.HorizontalPodAutoscaler{}}, + }, + "../docs/user-guide/jobs/work-queue-1": { + "job": {&batch.Job{}}, + }, + "../docs/user-guide/jobs/work-queue-2": { + "job": {&batch.Job{}}, + "redis-pod": {&api.Pod{}}, + "redis-service": {&api.Service{}}, + }, "../docs/user-guide/liveness": { "exec-liveness": {&api.Pod{}}, "http-liveness": {&api.Pod{}}, "http-liveness-named-port": {&api.Pod{}}, }, + "../docs/user-guide/nginx": { + "nginx-deployment": {&extensions.Deployment{}}, + "nginx-svc": {&api.Service{}}, + }, "../docs/user-guide/node-selection": { "pod": {&api.Pod{}}, "pod-with-node-affinity": {&api.Pod{}}, "pod-with-pod-affinity": {&api.Pod{}}, }, - "../docs/user-guide/persistent-volumes/volumes": { - "local-01": {&api.PersistentVolume{}}, - "local-02": {&api.PersistentVolume{}}, - "gce": {&api.PersistentVolume{}}, - "nfs": {&api.PersistentVolume{}}, - }, - "../docs/user-guide/persistent-volumes/claims": { - "claim-01": {&api.PersistentVolumeClaim{}}, - "claim-02": {&api.PersistentVolumeClaim{}}, - "claim-03": {&api.PersistentVolumeClaim{}}, - }, - "../docs/user-guide/persistent-volumes/simpletest": { - "namespace": {&api.Namespace{}}, - "pod": {&api.Pod{}}, - "service": {&api.Service{}}, + "../docs/user-guide/replicasets": { + "frontend": {&extensions.ReplicaSet{}}, + "hpa-rs": {&autoscaling.HorizontalPodAutoscaler{}}, + "redis-slave": {&extensions.ReplicaSet{}}, }, "../docs/user-guide/secrets": { - "secret-pod": {&api.Pod{}}, "secret": {&api.Secret{}}, "secret-env-pod": {&api.Pod{}}, + "secret-pod": {&api.Pod{}}, + }, + "../docs/user-guide/services": { + "load-balancer-sample": {&api.Service{}}, + "service-sample": {&api.Service{}}, }, "../docs/user-guide/update-demo": { "kitten-rc": {&api.ReplicationController{}}, @@ -405,6 +597,11 @@ func TestExampleObjectSchemas(t *testing.T) { }, } + filesIgnore := map[string]map[string]bool{ + "../docs/tasks/debug-application-cluster": { + "audit-policy": true, + }, + } capabilities.SetForTests(capabilities.Capabilities{ AllowPrivileged: true, }) @@ -415,6 +612,12 @@ func TestExampleObjectSchemas(t *testing.T) { err := walkConfigFiles(path, func(name, path string, docs [][]byte) { expectedTypes, found := expected[name] if !found { + p := filepath.Dir(path) + if files, ok := filesIgnore[p]; ok { + if files[name] { + return + } + } t.Errorf("%s: %s does not have a test case defined", path, name) return } diff --git a/update-imported-docs/README b/update-imported-docs/README new file mode 100644 index 0000000000..0314070896 --- /dev/null +++ b/update-imported-docs/README @@ -0,0 +1,5 @@ +update-imported-docs/update-imported-docs.go will update the target files generated from other repos. +You should modify update-imported-docs/config.yaml to reflect the desired src and dst path. +``` +go run update-imported-docs/update-imported-docs.go +``` diff --git a/update-imported-docs/config.yaml b/update-imported-docs/config.yaml new file mode 100644 index 0000000000..340bd25fd2 --- /dev/null +++ b/update-imported-docs/config.yaml @@ -0,0 +1,40 @@ +repos: +- name: kubernetes + remote: https://github.com/kubernetes/kubernetes.git + branch: release-1.9 + files: + - src: docs/admin/cloud-controller-manager.md + dst: docs/reference/generated/cloud-controller-manager.md + - src: docs/admin/kube-apiserver.md + dst: docs/reference/generated/kube-apiserver.md + - src: docs/admin/kube-controller-manager.md + dst: docs/reference/generated/kube-controller-manager.md + - src: docs/admin/kubelet.md + dst: docs/reference/generated/kubelet.md + - src: docs/admin/kube-proxy.md + dst: docs/reference/generated/kube-proxy.md + - src: docs/admin/kube-scheduler.md + dst: docs/reference/generated/kube-scheduler.md + - src: docs/user-guide/kubectl/kubectl.md + dst: docs/reference/generated/kubectl/kubectl.md +- name: federation + remote: https://github.com/kubernetes/federation.git +# # Change this to a release branch when federation has release branches. + branch: master + files: + - src: docs/admin/federation-apiserver.md + dst: docs/reference/generated/federation-apiserver.md + - src: docs/admin/federation-controller-manager.md + dst: docs/reference/generated/federation-controller-manager.md + - src: docs/admin/kubefed_init.md + dst: docs/reference/generated/kubefed_init.md + - src: docs/admin/kubefed_join.md + dst: docs/reference/generated/kubefed_join.md + - src: docs/admin/kubefed.md + dst: docs/reference/generated/kubefed.md + - src: docs/admin/kubefed_options.md + dst: docs/reference/generated/kubefed_options.md + - src: docs/admin/kubefed_unjoin.md + dst: docs/reference/generated/kubefed_unjoin.md + - src: docs/admin/kubefed_version.md + dst: docs/reference/generated/kubefed_version.md diff --git a/update-imported-docs/update-imported-docs.go b/update-imported-docs/update-imported-docs.go new file mode 100644 index 0000000000..cb8de3aabb --- /dev/null +++ b/update-imported-docs/update-imported-docs.go @@ -0,0 +1,124 @@ +package main + +import ( + "fmt" + "io" + "io/ioutil" + "os" + "os/exec" + "path" + "path/filepath" + "regexp" + + "github.com/ghodss/yaml" +) + +func main() { + websiteRepo, err := os.Getwd() + checkError(err) + + content, err := ioutil.ReadFile("update-imported-docs/config.yaml") + if err != nil { + fmt.Fprintf(os.Stderr, "error when reading file: %v\n", err) + os.Exit(1) + } + + var config map[string]interface{} + err = yaml.Unmarshal(content, &config) + if err != nil { + fmt.Fprintf(os.Stderr, "error when unmarshal the config file: %v\n", err) + os.Exit(1) + } + + tmpDir := "/tmp/update_docs" + os.RemoveAll(tmpDir) + os.Mkdir(tmpDir, 0750) + + // Match the content between 2 `---` + // It mostly have something like: + // --- + // title: *** + // notile: *** + // --- + titleRegex := regexp.MustCompile("^---\n(.*\n)*---\n") + + repos := config["repos"].([]interface{}) + for _, repo := range repos { + err = os.Chdir(tmpDir) + checkError(err) + + r := repo.(map[string]interface{}) + repoName := r["name"].(string) + cmd := "git" + args := []string{"clone", "--depth=1", "-b", r["branch"].(string), r["remote"].(string), repoName} + fmt.Fprintf(os.Stdout, "Cloning repo %q\n", repoName) + if err := exec.Command(cmd, args...).Run(); err != nil { + fmt.Fprintf(os.Stderr, "error when cloning repo %q: %v\n", repoName, err) + os.Exit(1) + } + + err = os.Chdir(repoName) + checkError(err) + + fmt.Fprintf(os.Stdout, "Generating docs for repo %q\n", repoName) + if err := exec.Command("hack/generate-docs.sh").Run(); err != nil { + fmt.Fprintf(os.Stderr, "error when generating docs for repo %q: %v\n", repoName, err) + os.Exit(1) + } + + err = os.Chdir(websiteRepo) + checkError(err) + files := r["files"].([]interface{}) + for _, file := range files { + f := file.(map[string]interface{}) + src := f["src"].(string) + dst := f["dst"].(string) + absSrc, err := filepath.Abs(path.Join(tmpDir, repoName, src)) + checkError(err) + absDst, err := filepath.Abs(dst) + checkError(err) + // Ignore the error if the old file is not found/ + content, _ := ioutil.ReadFile(absDst) + titleBlock := titleRegex.Find(content) + content, err = ioutil.ReadFile(absSrc) + checkError(err) + dstFile, err := os.OpenFile(absDst, os.O_RDWR|os.O_CREATE, 0755) + checkError(err) + defer dstFile.Close() + _, err = dstFile.Write(titleBlock) + checkError(err) + _, err = dstFile.Write(content) + checkError(err) + dstFile.Sync() + } + } + fmt.Fprintf(os.Stdout, "Docs imported! Run 'git add .' 'git commit -m ' and 'git push' to upload them\n") +} + +func copyFile(src, dst string) error { + sf, err := os.Open(src) + if err != nil { + return err + } + defer sf.Close() + + df, err := os.Create(dst) + if err != nil { + return err + } + defer df.Close() + + _, err = io.Copy(df, sf) + if err != nil { + return err + } + + return df.Sync() +} + +func checkError(err error) { + if err != nil { + fmt.Fprintln(os.Stderr, err) + os.Exit(1) + } +}