Update safely-drain-node.md

This commit is contained in:
jiazxjason
2020-12-07 09:46:12 +08:00
committed by GitHub
parent 23be39e00d
commit b4484da6f6
@@ -1,28 +1,30 @@
--- ---
title: 确保 PodDisruptionBudget 的前提下安全地清空一个节点 title: 安全地清空一个节点
content_type: task content_type: task
min-kubernetes-server-version: 1.5
--- ---
<!-- <!--
---
reviewers: reviewers:
- davidopp - davidopp
- mml - mml
- foxish - foxish
- kow3ns - kow3ns
title: Safely Drain a Node while Respecting the PodDisruptionBudget title: Safely Drain a Node
content_type: task content_type: task
min-kubernetes-server-version: 1.5
---
--> -->
<!-- overview --> <!-- overview -->
<!-- <!--
This page shows how to safely drain a node, respecting the PodDisruptionBudget you have defined. This page shows how to safely drain a node, respecting the PodDisruptionBudget you have defined.
--> -->
本页展示了如何在确保 PodDisruptionBudget 的前提下,安全地清空一个 本页展示了如何在确保 PodDisruptionBudget 的前提下,安全地清空一个{{< glossary_tooltip text="节点" term_id="node" >}}。
{{< glossary_tooltip text="节点" term_id="node" >}}。
## {{% heading "prerequisites" %}} ## {{% heading "prerequisites" %}}
{{% version-check %}} {{% version-check %}}
<!-- <!--
This task assumes that you have met the following prerequisites: This task assumes that you have met the following prerequisites:
@@ -30,20 +32,35 @@ This task assumes that you have met the following prerequisites:
* Either: * Either:
1. You do not require your applications to be highly available during the 1. You do not require your applications to be highly available during the
node drain, or node drain, or
1. You have read about the [PodDisruptionBudget concept](/docs/concepts/workloads/pods/disruptions/) 2. You have read about the [PodDisruptionBudget concept](/docs/concepts/workloads/pods/disruptions/)
and [Configured PodDisruptionBudgets](/docs/tasks/run-application/configure-pdb/) for and [Configured PodDisruptionBudgets](/docs/tasks/run-application/configure-pdb/) for
applications that need them. applications that need them.
--> -->
此任务假您已经满足以下先决条件: 此任务假您已经满足以下先决条件:
* 使用的 Kubernetes 版本 >= 1.5。 * 使用的 Kubernetes 版本 >= 1.5。
* 以下两项,具备其一: * 以下两项,具备其一:
1. 在节点清空期间,不要求应用程序具有高可用性 1. 在节点清空期间,不要求应用程序具有高可用性
1.已经了解了 [PodDisruptionBudget 的概念](/zh/docs/concepts/workloads/pods/disruptions/) 2.已经了解了 [PodDisruptionBudget 的概念](/zh/docs/concepts/workloads/pods/disruptions/)并为需要它的应用程序[配置了 PodDisruptionBudget](/zh/docs/tasks/run-application/configure-pdb/)。
并为需要它的应用程序[配置了 PodDisruptionBudget](/zh/docs/tasks/run-application/configure-pdb/)。
<!-- steps --> <!-- steps -->
<!--
## (Optional) Configure a disruption budget {#configure-poddisruptionbudget}
To endure that your workloads remain available during maintenance, you can
configure a [PodDisruptionBudget](/docs/concepts/workloads/pods/disruptions/).
If availability is important for any applications that run or could run on the node(s)
that you are draining, [configure a PodDisruptionBudgets](/docs/tasks/run-application/configure-pdb/)
first and the continue following this guide.
-->
## (可选) 配置中断预算 {#configure-poddisruptionbudget}
为了确保您的工作在维护期间仍然可用,您可以配置一个 [PodDisruptionBudget](/docs/concepts/workloads/pods/disruptions/)。
如果可用性对于正在清空的该节点上运行或可能在该节点上运行的任何应用程序很重要,首先 [配置一个 PodDisruptionBudgets](/docs/tasks/run-application/configure-pdb/) 并继续遵循本指南。
<!-- <!--
## Use `kubectl drain` to remove a node from service ## Use `kubectl drain` to remove a node from service
@@ -147,8 +164,7 @@ replicas to fall below the specified budget are blocked.
并设置了一个 `PodDisruptionBudget`,指定 `minAvailable: 2` 并设置了一个 `PodDisruptionBudget`,指定 `minAvailable: 2`
如果所有的三个 Pod 均就绪,并且你并行地发出多个 drain 命令, 如果所有的三个 Pod 均就绪,并且你并行地发出多个 drain 命令,
那么 `kubectl drain` 只会从 StatefulSet 中逐出一个 Pod 那么 `kubectl drain` 只会从 StatefulSet 中逐出一个 Pod
因为 Kubernetes 会遵守 PodDisruptionBudget 并确保在任何时候只有一个 Pod 不可用 因为 Kubernetes 会遵守 PodDisruptionBudget 并确保在任何时候只有一个 Pod 不可用(最多不可用 Pod 个数的计算方法:`replicas - minAvailable`)。
(最多不可用 Pod 个数的计算方法:`replicas - minAvailable`)。
任何会导致就绪副本数量低于指定预算的清空操作都将被阻止。 任何会导致就绪副本数量低于指定预算的清空操作都将被阻止。
<!-- <!--
@@ -160,7 +176,7 @@ eviction process), you can also programmatically cause evictions using the evict
--> -->
## 驱逐 API {#the-eviction-api} ## 驱逐 API {#the-eviction-api}
如果你不喜欢使用 如果你不喜欢使用
[kubectl drain](/docs/reference/generated/kubectl/kubectl-commands/#drain) [kubectl drain](/zh/docs/reference/generated/kubectl/kubectl-commands/#drain)
(比如避免调用外部命令,或者更细化地控制 pod 驱逐过程), (比如避免调用外部命令,或者更细化地控制 pod 驱逐过程),
你也可以用驱逐 API 通过编程的方式达到驱逐的效果。 你也可以用驱逐 API 通过编程的方式达到驱逐的效果。
@@ -176,8 +192,7 @@ itself. To attempt an eviction (perhaps more REST-precisely, to attempt to
[Kubernetes 语言客户端](/zh/docs/tasks/administer-cluster/access-cluster-api/#programmatic-access-to-the-api)。 [Kubernetes 语言客户端](/zh/docs/tasks/administer-cluster/access-cluster-api/#programmatic-access-to-the-api)。
Pod 的 Eviction 子资源可以看作是一种策略控制的 DELETE 操作,作用于 Pod 本身。 Pod 的 Eviction 子资源可以看作是一种策略控制的 DELETE 操作,作用于 Pod 本身。
要尝试驱逐(更准确地说,尝试 *创建* 一个 Eviction),需要用 POST 要尝试驱逐(更准确地说,尝试 *创建* 一个 Eviction),需要用 POST 发出所尝试的操作。这里有一个例子:
发出所尝试的操作。这里有一个例子:
```json ```json
{ {
@@ -212,8 +227,8 @@ The API can respond in one of three ways:
future versions. future versions.
- If there is some kind of misconfiguration, like multiple budgets pointing at - If there is some kind of misconfiguration, like multiple budgets pointing at
the same pod, you will get `500 Internal Server Error`. the same pod, you will get `500 Internal Server Error`.
--> -->
API可以通过以下三种方式之一进行响应: API 可以通过以下三种方式之一进行响应:
- 如果驱逐被授权,那么 Pod 将被删掉,并且你会收到 `200 OK` - 如果驱逐被授权,那么 Pod 将被删掉,并且你会收到 `200 OK`
就像你向 Pod 的 URL 发送了 `DELETE` 请求一样。 就像你向 Pod 的 URL 发送了 `DELETE` 请求一样。
@@ -229,9 +244,9 @@ For a given eviction request, there are two cases:
- There is no budget that matches this pod. In this case, the server always - There is no budget that matches this pod. In this case, the server always
returns `200 OK`. returns `200 OK`.
- There is at least one budget. In this case, any of the three above responses may - There is at least one budget. In this case, any of the three above responses may
apply. apply.
--> -->
对于一个给定的驱逐请求,有两种情况: 对于一个给定的驱逐请求,有两种情况:
- 没有匹配这个 Pod 的预算。这种情况,服务器总是返回 `200 OK` - 没有匹配这个 Pod 的预算。这种情况,服务器总是返回 `200 OK`
- 至少匹配一个预算。在这种情况下,上述三种回答中的任何一种都可能适用。 - 至少匹配一个预算。在这种情况下,上述三种回答中的任何一种都可能适用。
@@ -259,8 +274,7 @@ application owners and cluster owners to establish an agreement on behavior in t
## 驱逐阻塞 ## 驱逐阻塞
在某些情况下,应用程序可能会到达一个中断状态,除了 429 或 500 之外,它将永远不会返回任何内容。 在某些情况下,应用程序可能会到达一个中断状态,除了 429 或 500 之外,它将永远不会返回任何内容。
例如 ReplicaSet 创建的替换 Pod 没有变成就绪状态,或者被驱逐的最后一个 例如 ReplicaSet 创建的替换 Pod 没有变成就绪状态,或者被驱逐的最后一个 Pod 有很长的终止宽限期,就会发生这种情况。
Pod 有很长的终止宽限期,就会发生这种情况。
在这种情况下,有两种可能的解决方案: 在这种情况下,有两种可能的解决方案:
@@ -272,9 +286,11 @@ Kubernetes 并没有具体说明在这种情况下应该采取什么行为,
## {{% heading "whatsnext" %}} ## {{% heading "whatsnext" %}}
<!-- <!--
* Follow steps to protect your application by [configuring a Pod Disruption Budget](/docs/tasks/run-application/configure-pdb/). * Follow steps to protect your application by [configuring a Pod Disruption Budget](/docs/tasks/run-application/configure-pdb/).
--> * Learn more about [maintenance on a node](/docs/tasks/administer-cluster/cluster-management/#maintenance-on-a-node).
* 执行[配置 PDB](/zh/docs/tasks/run-application/configure-pdb/)中的各个步骤, -->
保护你的应用 * 跟随以下步骤保护应用程序:[配置 Pod 中断预算](/zh/docs/tasks/run-application/configure-pdb/)。
* 进一步了解[节点维护](/zh/docs/tasks/administer-cluster/cluster-management/#maintenance-on-a-node)。