Merge branch 'master' of https://github.com/kubernetes/kubernetes.github.io into release-1.7
* 'master' of https://github.com/kubernetes/kubernetes.github.io: Fixed a minor mistake docs/concepts/policy/pod-security-policy.md: add projected to list of allowed types. Init container exists beta in 1.6.
This commit is contained in:
@@ -122,7 +122,7 @@ to the volume sources that are defined when creating a volume:
|
|||||||
1. \* (allow all volumes)
|
1. \* (allow all volumes)
|
||||||
|
|
||||||
The recommended minimum set of allowed volumes for new PSPs are
|
The recommended minimum set of allowed volumes for new PSPs are
|
||||||
configMap, downwardAPI, emptyDir, persistentVolumeClaim, and secret.
|
configMap, downwardAPI, emptyDir, persistentVolumeClaim, secret, and projected.
|
||||||
|
|
||||||
### Host Network
|
### Host Network
|
||||||
- *HostPorts*, default `empty`. List of `HostPortRange`, defined by `min`(inclusive) and `max`(inclusive), which define the allowed host ports.
|
- *HostPorts*, default `empty`. List of `HostPortRange`, defined by `min`(inclusive) and `max`(inclusive), which define the allowed host ports.
|
||||||
@@ -168,7 +168,7 @@ $ kubectl get psp
|
|||||||
NAME PRIV CAPS SELINUX RUNASUSER FSGROUP SUPGROUP READONLYROOTFS VOLUMES
|
NAME PRIV CAPS SELINUX RUNASUSER FSGROUP SUPGROUP READONLYROOTFS VOLUMES
|
||||||
permissive false [] RunAsAny RunAsAny RunAsAny RunAsAny false [*]
|
permissive false [] RunAsAny RunAsAny RunAsAny RunAsAny false [*]
|
||||||
privileged true [] RunAsAny RunAsAny RunAsAny RunAsAny false [*]
|
privileged true [] RunAsAny RunAsAny RunAsAny RunAsAny false [*]
|
||||||
restricted false [] RunAsAny MustRunAsNonRoot RunAsAny RunAsAny false [emptyDir secret downwardAPI configMap persistentVolumeClaim]
|
restricted false [] RunAsAny MustRunAsNonRoot RunAsAny RunAsAny false [emptyDir secret downwardAPI configMap persistentVolumeClaim projected]
|
||||||
```
|
```
|
||||||
|
|
||||||
## Editing a Pod Security Policy
|
## Editing a Pod Security Policy
|
||||||
|
|||||||
@@ -550,7 +550,7 @@ ensure that no two `Services` can collide. We do that by allocating each
|
|||||||
`Service` its own IP address.
|
`Service` its own IP address.
|
||||||
|
|
||||||
To ensure each service receives a unique IP, an internal allocator atomically
|
To ensure each service receives a unique IP, an internal allocator atomically
|
||||||
updates a global allocation map in etcd prior to each service. The map object
|
updates a global allocation map in etcd prior to creating each service. The map object
|
||||||
must exist in the registry for services to get IPs, otherwise creations will
|
must exist in the registry for services to get IPs, otherwise creations will
|
||||||
fail with a message indicating an IP could not be allocated. A background
|
fail with a message indicating an IP could not be allocated. A background
|
||||||
controller is responsible for creating that map (to migrate from older versions
|
controller is responsible for creating that map (to migrate from older versions
|
||||||
|
|||||||
@@ -17,10 +17,9 @@ scripts not present in an app image.
|
|||||||
|
|
||||||
{:toc}
|
{:toc}
|
||||||
|
|
||||||
{% assign for_k8s_version="v1.5" %}{% include feature-state-beta.md %}
|
This feature has exited beta in 1.6. Init Containers can be specified in the PodSpec
|
||||||
|
alongside the app `containers` array. The beta annotation value will still be respected
|
||||||
Once the feature exits beta, Init Containers will be specified in the PodSpec
|
and overrides the PodSpec field value.
|
||||||
alongside the app `containers` array.
|
|
||||||
|
|
||||||
{% capture body %}
|
{% capture body %}
|
||||||
## Understanding Init Containers
|
## Understanding Init Containers
|
||||||
|
|||||||
Reference in New Issue
Block a user