zh-trans: add examples/podpreset/ examples/pods/{config,inject,probe,qos,resource,security,storage} yaml files
This commit is contained in:
@@ -0,0 +1,37 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: website
|
||||||
|
labels:
|
||||||
|
app: website
|
||||||
|
role: frontend
|
||||||
|
annotations:
|
||||||
|
podpreset.admission.kubernetes.io/podpreset-allow-database: "resource version"
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: website
|
||||||
|
image: nginx
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /cache
|
||||||
|
name: cache-volume
|
||||||
|
- mountPath: /etc/app/config.json
|
||||||
|
readOnly: true
|
||||||
|
name: secret-volume
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
env:
|
||||||
|
- name: DB_PORT
|
||||||
|
value: "6379"
|
||||||
|
- name: duplicate_key
|
||||||
|
value: FROM_ENV
|
||||||
|
- name: expansion
|
||||||
|
value: $(REPLACE_ME)
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: etcd-env-config
|
||||||
|
volumes:
|
||||||
|
- name: cache-volume
|
||||||
|
emptyDir: {}
|
||||||
|
- name: secret-volume
|
||||||
|
secret:
|
||||||
|
secretName: config-details
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
apiVersion: settings.k8s.io/v1alpha1
|
||||||
|
kind: PodPreset
|
||||||
|
metadata:
|
||||||
|
name: allow-database
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
role: frontend
|
||||||
|
env:
|
||||||
|
- name: DB_PORT
|
||||||
|
value: "6379"
|
||||||
|
- name: duplicate_key
|
||||||
|
value: FROM_ENV
|
||||||
|
- name: expansion
|
||||||
|
value: $(REPLACE_ME)
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: etcd-env-config
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /cache
|
||||||
|
name: cache-volume
|
||||||
|
- mountPath: /etc/app/config.json
|
||||||
|
readOnly: true
|
||||||
|
name: secret-volume
|
||||||
|
volumes:
|
||||||
|
- name: cache-volume
|
||||||
|
emptyDir: {}
|
||||||
|
- name: secret-volume
|
||||||
|
secret:
|
||||||
|
secretName: config-details
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: etcd-env-config
|
||||||
|
data:
|
||||||
|
number_of_members: "1"
|
||||||
|
initial_cluster_state: new
|
||||||
|
initial_cluster_token: DUMMY_ETCD_INITIAL_CLUSTER_TOKEN
|
||||||
|
discovery_token: DUMMY_ETCD_DISCOVERY_TOKEN
|
||||||
|
discovery_url: http://etcd_discovery:2379
|
||||||
|
etcdctl_peers: http://etcd:2379
|
||||||
|
duplicate_key: FROM_CONFIG_MAP
|
||||||
|
REPLACE_ME: "a value"
|
||||||
|
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: website
|
||||||
|
labels:
|
||||||
|
app: website
|
||||||
|
role: frontend
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: website
|
||||||
|
image: nginx
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /cache
|
||||||
|
name: cache-volume
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
volumes:
|
||||||
|
- name: cache-volume
|
||||||
|
emptyDir: {}
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
apiVersion: settings.k8s.io/v1alpha1
|
||||||
|
kind: PodPreset
|
||||||
|
metadata:
|
||||||
|
name: allow-database
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
role: frontend
|
||||||
|
env:
|
||||||
|
- name: DB_PORT
|
||||||
|
value: "6379"
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /cache
|
||||||
|
name: other-volume
|
||||||
|
volumes:
|
||||||
|
- name: other-volume
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: website
|
||||||
|
labels:
|
||||||
|
app: website
|
||||||
|
role: frontend
|
||||||
|
annotations:
|
||||||
|
podpreset.admission.kubernetes.io/podpreset-allow-database: "resource version"
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: website
|
||||||
|
image: nginx
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /cache
|
||||||
|
name: cache-volume
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
env:
|
||||||
|
- name: DB_PORT
|
||||||
|
value: "6379"
|
||||||
|
volumes:
|
||||||
|
- name: cache-volume
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: website
|
||||||
|
labels:
|
||||||
|
app: website
|
||||||
|
role: frontend
|
||||||
|
annotations:
|
||||||
|
podpreset.admission.kubernetes.io/podpreset-allow-database: "resource version"
|
||||||
|
podpreset.admission.kubernetes.io/podpreset-proxy: "resource version"
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: website
|
||||||
|
image: nginx
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /cache
|
||||||
|
name: cache-volume
|
||||||
|
- mountPath: /etc/proxy/configs
|
||||||
|
name: proxy-volume
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
env:
|
||||||
|
- name: DB_PORT
|
||||||
|
value: "6379"
|
||||||
|
volumes:
|
||||||
|
- name: cache-volume
|
||||||
|
emptyDir: {}
|
||||||
|
- name: proxy-volume
|
||||||
|
emptyDir: {}
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: website
|
||||||
|
labels:
|
||||||
|
app: website
|
||||||
|
role: frontend
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: website
|
||||||
|
image: nginx
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: settings.k8s.io/v1alpha1
|
||||||
|
kind: PodPreset
|
||||||
|
metadata:
|
||||||
|
name: allow-database
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
role: frontend
|
||||||
|
env:
|
||||||
|
- name: DB_PORT
|
||||||
|
value: "6379"
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /cache
|
||||||
|
name: cache-volume
|
||||||
|
volumes:
|
||||||
|
- name: cache-volume
|
||||||
|
emptyDir: {}
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: settings.k8s.io/v1alpha1
|
||||||
|
kind: PodPreset
|
||||||
|
metadata:
|
||||||
|
name: proxy
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
role: frontend
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /etc/proxy/configs
|
||||||
|
name: proxy-volume
|
||||||
|
volumes:
|
||||||
|
- name: proxy-volume
|
||||||
|
emptyDir: {}
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
labels:
|
||||||
|
app: guestbook
|
||||||
|
role: frontend
|
||||||
|
annotations:
|
||||||
|
podpreset.admission.kubernetes.io/podpreset-allow-database: "resource version"
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: php-redis
|
||||||
|
image: gcr.io/google_samples/gb-frontend:v3
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 100Mi
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /cache
|
||||||
|
name: cache-volume
|
||||||
|
env:
|
||||||
|
- name: GET_HOSTS_FROM
|
||||||
|
value: dns
|
||||||
|
- name: DB_PORT
|
||||||
|
value: "6379"
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
volumes:
|
||||||
|
- name: cache-volume
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: ReplicaSet
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
spec:
|
||||||
|
replicas: 3
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
role: frontend
|
||||||
|
matchExpressions:
|
||||||
|
- {key: role, operator: In, values: [frontend]}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: guestbook
|
||||||
|
role: frontend
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: php-redis
|
||||||
|
image: gcr.io/google_samples/gb-frontend:v3
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 100Mi
|
||||||
|
env:
|
||||||
|
- name: GET_HOSTS_FROM
|
||||||
|
value: dns
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: command-demo
|
||||||
|
labels:
|
||||||
|
purpose: demonstrate-command
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: command-demo-container
|
||||||
|
image: debian
|
||||||
|
command: ["printenv"]
|
||||||
|
args: ["HOSTNAME", "KUBERNETES_PORT"]
|
||||||
|
restartPolicy: OnFailure
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: redis
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: redis
|
||||||
|
image: kubernetes/redis:v1
|
||||||
|
env:
|
||||||
|
- name: MASTER
|
||||||
|
value: "true"
|
||||||
|
ports:
|
||||||
|
- containerPort: 6379
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: "0.1"
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /redis-master-data
|
||||||
|
name: data
|
||||||
|
- mountPath: /redis-master
|
||||||
|
name: config
|
||||||
|
volumes:
|
||||||
|
- name: data
|
||||||
|
emptyDir: {}
|
||||||
|
- name: config
|
||||||
|
configMap:
|
||||||
|
name: example-redis-config
|
||||||
|
items:
|
||||||
|
- key: redis-config
|
||||||
|
path: redis.conf
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: init-demo
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: nginx
|
||||||
|
image: nginx
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
volumeMounts:
|
||||||
|
- name: workdir
|
||||||
|
mountPath: /usr/share/nginx/html
|
||||||
|
# These containers are run during pod initialization
|
||||||
|
initContainers:
|
||||||
|
- name: install
|
||||||
|
image: busybox
|
||||||
|
command:
|
||||||
|
- wget
|
||||||
|
- "-O"
|
||||||
|
- "/work-dir/index.html"
|
||||||
|
- http://kubernetes.io
|
||||||
|
volumeMounts:
|
||||||
|
- name: workdir
|
||||||
|
mountPath: "/work-dir"
|
||||||
|
dnsPolicy: Default
|
||||||
|
volumes:
|
||||||
|
- name: workdir
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: dapi-envars-resourcefieldref
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: test-container
|
||||||
|
image: k8s.gcr.io/busybox:1.24
|
||||||
|
command: [ "sh", "-c"]
|
||||||
|
args:
|
||||||
|
- while true; do
|
||||||
|
echo -en '\n';
|
||||||
|
printenv MY_CPU_REQUEST MY_CPU_LIMIT;
|
||||||
|
printenv MY_MEM_REQUEST MY_MEM_LIMIT;
|
||||||
|
sleep 10;
|
||||||
|
done;
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "32Mi"
|
||||||
|
cpu: "125m"
|
||||||
|
limits:
|
||||||
|
memory: "64Mi"
|
||||||
|
cpu: "250m"
|
||||||
|
env:
|
||||||
|
- name: MY_CPU_REQUEST
|
||||||
|
valueFrom:
|
||||||
|
resourceFieldRef:
|
||||||
|
containerName: test-container
|
||||||
|
resource: requests.cpu
|
||||||
|
- name: MY_CPU_LIMIT
|
||||||
|
valueFrom:
|
||||||
|
resourceFieldRef:
|
||||||
|
containerName: test-container
|
||||||
|
resource: limits.cpu
|
||||||
|
- name: MY_MEM_REQUEST
|
||||||
|
valueFrom:
|
||||||
|
resourceFieldRef:
|
||||||
|
containerName: test-container
|
||||||
|
resource: requests.memory
|
||||||
|
- name: MY_MEM_LIMIT
|
||||||
|
valueFrom:
|
||||||
|
resourceFieldRef:
|
||||||
|
containerName: test-container
|
||||||
|
resource: limits.memory
|
||||||
|
restartPolicy: Never
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: dapi-envars-fieldref
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: test-container
|
||||||
|
image: k8s.gcr.io/busybox
|
||||||
|
command: [ "sh", "-c"]
|
||||||
|
args:
|
||||||
|
- while true; do
|
||||||
|
echo -en '\n';
|
||||||
|
printenv MY_NODE_NAME MY_POD_NAME MY_POD_NAMESPACE;
|
||||||
|
printenv MY_POD_IP MY_POD_SERVICE_ACCOUNT;
|
||||||
|
sleep 10;
|
||||||
|
done;
|
||||||
|
env:
|
||||||
|
- name: MY_NODE_NAME
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: spec.nodeName
|
||||||
|
- name: MY_POD_NAME
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.name
|
||||||
|
- name: MY_POD_NAMESPACE
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.namespace
|
||||||
|
- name: MY_POD_IP
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: status.podIP
|
||||||
|
- name: MY_POD_SERVICE_ACCOUNT
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: spec.serviceAccountName
|
||||||
|
restartPolicy: Never
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: kubernetes-downwardapi-volume-example-2
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: client-container
|
||||||
|
image: k8s.gcr.io/busybox:1.24
|
||||||
|
command: ["sh", "-c"]
|
||||||
|
args:
|
||||||
|
- while true; do
|
||||||
|
echo -en '\n';
|
||||||
|
if [[ -e /etc/podinfo/cpu_limit ]]; then
|
||||||
|
echo -en '\n'; cat /etc/podinfo/cpu_limit; fi;
|
||||||
|
if [[ -e /etc/podinfo/cpu_request ]]; then
|
||||||
|
echo -en '\n'; cat /etc/podinfo/cpu_request; fi;
|
||||||
|
if [[ -e /etc/podinfo/mem_limit ]]; then
|
||||||
|
echo -en '\n'; cat /etc/podinfo/mem_limit; fi;
|
||||||
|
if [[ -e /etc/podinfo/mem_request ]]; then
|
||||||
|
echo -en '\n'; cat /etc/podinfo/mem_request; fi;
|
||||||
|
sleep 5;
|
||||||
|
done;
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "32Mi"
|
||||||
|
cpu: "125m"
|
||||||
|
limits:
|
||||||
|
memory: "64Mi"
|
||||||
|
cpu: "250m"
|
||||||
|
volumeMounts:
|
||||||
|
- name: podinfo
|
||||||
|
mountPath: /etc/podinfo
|
||||||
|
readOnly: false
|
||||||
|
volumes:
|
||||||
|
- name: podinfo
|
||||||
|
downwardAPI:
|
||||||
|
items:
|
||||||
|
- path: "cpu_limit"
|
||||||
|
resourceFieldRef:
|
||||||
|
containerName: client-container
|
||||||
|
resource: limits.cpu
|
||||||
|
divisor: 1m
|
||||||
|
- path: "cpu_request"
|
||||||
|
resourceFieldRef:
|
||||||
|
containerName: client-container
|
||||||
|
resource: requests.cpu
|
||||||
|
divisor: 1m
|
||||||
|
- path: "mem_limit"
|
||||||
|
resourceFieldRef:
|
||||||
|
containerName: client-container
|
||||||
|
resource: limits.memory
|
||||||
|
divisor: 1Mi
|
||||||
|
- path: "mem_request"
|
||||||
|
resourceFieldRef:
|
||||||
|
containerName: client-container
|
||||||
|
resource: requests.memory
|
||||||
|
divisor: 1Mi
|
||||||
|
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: kubernetes-downwardapi-volume-example
|
||||||
|
labels:
|
||||||
|
zone: us-est-coast
|
||||||
|
cluster: test-cluster1
|
||||||
|
rack: rack-22
|
||||||
|
annotations:
|
||||||
|
build: two
|
||||||
|
builder: john-doe
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: client-container
|
||||||
|
image: k8s.gcr.io/busybox
|
||||||
|
command: ["sh", "-c"]
|
||||||
|
args:
|
||||||
|
- while true; do
|
||||||
|
if [[ -e /etc/podinfo/labels ]]; then
|
||||||
|
echo -en '\n\n'; cat /etc/podinfo/labels; fi;
|
||||||
|
if [[ -e /etc/podinfo/annotations ]]; then
|
||||||
|
echo -en '\n\n'; cat /etc/podinfo/annotations; fi;
|
||||||
|
sleep 5;
|
||||||
|
done;
|
||||||
|
volumeMounts:
|
||||||
|
- name: podinfo
|
||||||
|
mountPath: /etc/podinfo
|
||||||
|
readOnly: false
|
||||||
|
volumes:
|
||||||
|
- name: podinfo
|
||||||
|
downwardAPI:
|
||||||
|
items:
|
||||||
|
- path: "labels"
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.labels
|
||||||
|
- path: "annotations"
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.annotations
|
||||||
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: envar-demo
|
||||||
|
labels:
|
||||||
|
purpose: demonstrate-envars
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: envar-demo-container
|
||||||
|
image: gcr.io/google-samples/node-hello:1.0
|
||||||
|
env:
|
||||||
|
- name: DEMO_GREETING
|
||||||
|
value: "Hello from the environment"
|
||||||
|
- name: DEMO_FAREWELL
|
||||||
|
value: "Such a sweet sorrow"
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: secret-envars-test-pod
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: envars-test-container
|
||||||
|
image: nginx
|
||||||
|
env:
|
||||||
|
- name: SECRET_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: test-secret
|
||||||
|
key: username
|
||||||
|
- name: SECRET_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: test-secret
|
||||||
|
key: password
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: secret-test-pod
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: test-container
|
||||||
|
image: nginx
|
||||||
|
volumeMounts:
|
||||||
|
# name must match the volume name below
|
||||||
|
- name: secret-volume
|
||||||
|
mountPath: /etc/secret-volume
|
||||||
|
# The secret data is exposed to Containers in the Pod through a Volume.
|
||||||
|
volumes:
|
||||||
|
- name: secret-volume
|
||||||
|
secret:
|
||||||
|
secretName: test-secret
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: test-secret
|
||||||
|
data:
|
||||||
|
username: bXktYXBw
|
||||||
|
password: Mzk1MjgkdmRnN0pi
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: lifecycle-demo
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: lifecycle-demo-container
|
||||||
|
image: nginx
|
||||||
|
lifecycle:
|
||||||
|
postStart:
|
||||||
|
exec:
|
||||||
|
command: ["/bin/sh", "-c", "echo Hello from the postStart handler > /usr/share/message"]
|
||||||
|
preStop:
|
||||||
|
exec:
|
||||||
|
command: ["/usr/sbin/nginx","-s","quit"]
|
||||||
|
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: with-node-affinity
|
||||||
|
spec:
|
||||||
|
affinity:
|
||||||
|
nodeAffinity:
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
nodeSelectorTerms:
|
||||||
|
- matchExpressions:
|
||||||
|
- key: kubernetes.io/e2e-az-name
|
||||||
|
operator: In
|
||||||
|
values:
|
||||||
|
- e2e-az1
|
||||||
|
- e2e-az2
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- weight: 1
|
||||||
|
preference:
|
||||||
|
matchExpressions:
|
||||||
|
- key: another-node-label-key
|
||||||
|
operator: In
|
||||||
|
values:
|
||||||
|
- another-node-label-value
|
||||||
|
containers:
|
||||||
|
- name: with-node-affinity
|
||||||
|
image: k8s.gcr.io/pause:2.0
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: with-pod-affinity
|
||||||
|
spec:
|
||||||
|
affinity:
|
||||||
|
podAffinity:
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- labelSelector:
|
||||||
|
matchExpressions:
|
||||||
|
- key: security
|
||||||
|
operator: In
|
||||||
|
values:
|
||||||
|
- S1
|
||||||
|
topologyKey: failure-domain.beta.kubernetes.io/zone
|
||||||
|
podAntiAffinity:
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- weight: 100
|
||||||
|
podAffinityTerm:
|
||||||
|
labelSelector:
|
||||||
|
matchExpressions:
|
||||||
|
- key: security
|
||||||
|
operator: In
|
||||||
|
values:
|
||||||
|
- S2
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
containers:
|
||||||
|
- name: with-pod-affinity
|
||||||
|
image: k8s.gcr.io/pause:2.0
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: private-reg
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: private-reg-container
|
||||||
|
image: <your-private-image>
|
||||||
|
imagePullSecrets:
|
||||||
|
- name: regcred
|
||||||
|
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
test: liveness
|
||||||
|
name: liveness-exec
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: liveness
|
||||||
|
image: k8s.gcr.io/busybox
|
||||||
|
args:
|
||||||
|
- /bin/sh
|
||||||
|
- -c
|
||||||
|
- touch /tmp/healthy; sleep 30; rm -rf /tmp/healthy; sleep 600
|
||||||
|
livenessProbe:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- cat
|
||||||
|
- /tmp/healthy
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 5
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
test: liveness
|
||||||
|
name: liveness-http
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: liveness
|
||||||
|
image: k8s.gcr.io/liveness
|
||||||
|
args:
|
||||||
|
- /server
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: 8080
|
||||||
|
httpHeaders:
|
||||||
|
- name: X-Custom-Header
|
||||||
|
value: Awesome
|
||||||
|
initialDelaySeconds: 3
|
||||||
|
periodSeconds: 3
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: pod-with-http-healthcheck
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: nginx
|
||||||
|
image: nginx
|
||||||
|
# defines the health checking
|
||||||
|
livenessProbe:
|
||||||
|
# an http probe
|
||||||
|
httpGet:
|
||||||
|
path: /_status/healthz
|
||||||
|
port: 80
|
||||||
|
# length of time to wait for a pod to initialize
|
||||||
|
# after pod startup, before applying health checking
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
timeoutSeconds: 1
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: pod-with-tcp-socket-healthcheck
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: redis
|
||||||
|
image: redis
|
||||||
|
# defines the health checking
|
||||||
|
livenessProbe:
|
||||||
|
# a TCP socket probe
|
||||||
|
tcpSocket:
|
||||||
|
port: 6379
|
||||||
|
# length of time to wait for a pod to initialize
|
||||||
|
# after pod startup, before applying health checking
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
timeoutSeconds: 1
|
||||||
|
ports:
|
||||||
|
- containerPort: 6379
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: goproxy
|
||||||
|
labels:
|
||||||
|
app: goproxy
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: goproxy
|
||||||
|
image: k8s.gcr.io/goproxy:0.1
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
readinessProbe:
|
||||||
|
tcpSocket:
|
||||||
|
port: 8080
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
livenessProbe:
|
||||||
|
tcpSocket:
|
||||||
|
port: 8080
|
||||||
|
initialDelaySeconds: 15
|
||||||
|
periodSeconds: 20
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: qos-demo-2
|
||||||
|
namespace: qos-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: qos-demo-2-ctr
|
||||||
|
image: nginx
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: "200Mi"
|
||||||
|
requests:
|
||||||
|
memory: "100Mi"
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: qos-demo-3
|
||||||
|
namespace: qos-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: qos-demo-3-ctr
|
||||||
|
image: nginx
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: qos-demo-4
|
||||||
|
namespace: qos-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
|
||||||
|
- name: qos-demo-4-ctr-1
|
||||||
|
image: nginx
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "200Mi"
|
||||||
|
|
||||||
|
- name: qos-demo-4-ctr-2
|
||||||
|
image: redis
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: qos-demo
|
||||||
|
namespace: qos-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: qos-demo-ctr
|
||||||
|
image: nginx
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: "200Mi"
|
||||||
|
cpu: "700m"
|
||||||
|
requests:
|
||||||
|
memory: "200Mi"
|
||||||
|
cpu: "700m"
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: cpu-demo-2
|
||||||
|
namespace: cpu-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: cpu-demo-ctr-2
|
||||||
|
image: vish/stress
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: "100"
|
||||||
|
requests:
|
||||||
|
cpu: "100"
|
||||||
|
args:
|
||||||
|
- -cpus
|
||||||
|
- "2"
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: cpu-demo
|
||||||
|
namespace: cpu-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: cpu-demo-ctr
|
||||||
|
image: vish/stress
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: "1"
|
||||||
|
requests:
|
||||||
|
cpu: "0.5"
|
||||||
|
args:
|
||||||
|
- -cpus
|
||||||
|
- "2"
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: extended-resource-demo-2
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: extended-resource-demo-2-ctr
|
||||||
|
image: nginx
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
example.com/dongle: 2
|
||||||
|
limits:
|
||||||
|
example.com/dongle: 2
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: extended-resource-demo
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: extended-resource-demo-ctr
|
||||||
|
image: nginx
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
example.com/dongle: 3
|
||||||
|
limits:
|
||||||
|
example.com/dongle: 3
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: memory-demo-2
|
||||||
|
namespace: mem-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: memory-demo-2-ctr
|
||||||
|
image: polinux/stress
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "50Mi"
|
||||||
|
limits:
|
||||||
|
memory: "100Mi"
|
||||||
|
command: ["stress"]
|
||||||
|
args: ["--vm", "1", "--vm-bytes", "250M", "--vm-hang", "1"]
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: memory-demo-3
|
||||||
|
namespace: mem-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: memory-demo-3-ctr
|
||||||
|
image: polinux/stress
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: "1000Gi"
|
||||||
|
requests:
|
||||||
|
memory: "1000Gi"
|
||||||
|
command: ["stress"]
|
||||||
|
args: ["--vm", "1", "--vm-bytes", "150M", "--vm-hang", "1"]
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: memory-demo
|
||||||
|
namespace: mem-example
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: memory-demo-ctr
|
||||||
|
image: polinux/stress
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: "200Mi"
|
||||||
|
requests:
|
||||||
|
memory: "100Mi"
|
||||||
|
command: ["stress"]
|
||||||
|
args: ["--vm", "1", "--vm-bytes", "150M", "--vm-hang", "1"]
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: hello-apparmor
|
||||||
|
annotations:
|
||||||
|
# Tell Kubernetes to apply the AppArmor profile "k8s-apparmor-example-deny-write".
|
||||||
|
# Note that this is ignored if the Kubernetes node is not running version 1.4 or greater.
|
||||||
|
container.apparmor.security.beta.kubernetes.io/hello: localhost/k8s-apparmor-example-deny-write
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: hello
|
||||||
|
image: busybox
|
||||||
|
command: [ "sh", "-c", "echo 'Hello AppArmor!' && sleep 1h" ]
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: security-context-demo-2
|
||||||
|
spec:
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 1000
|
||||||
|
containers:
|
||||||
|
- name: sec-ctx-demo-2
|
||||||
|
image: gcr.io/google-samples/node-hello:1.0
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 2000
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: security-context-demo-3
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: sec-ctx-3
|
||||||
|
image: gcr.io/google-samples/node-hello:1.0
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: security-context-demo-4
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: sec-ctx-4
|
||||||
|
image: gcr.io/google-samples/node-hello:1.0
|
||||||
|
securityContext:
|
||||||
|
capabilities:
|
||||||
|
add: ["NET_ADMIN", "SYS_TIME"]
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: security-context-demo
|
||||||
|
spec:
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 1000
|
||||||
|
fsGroup: 2000
|
||||||
|
volumes:
|
||||||
|
- name: sec-ctx-vol
|
||||||
|
emptyDir: {}
|
||||||
|
containers:
|
||||||
|
- name: sec-ctx-demo
|
||||||
|
image: gcr.io/google-samples/node-hello:1.0
|
||||||
|
volumeMounts:
|
||||||
|
- name: sec-ctx-vol
|
||||||
|
mountPath: /data/demo
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: nginx
|
||||||
|
spec:
|
||||||
|
shareProcessNamespace: true
|
||||||
|
containers:
|
||||||
|
- name: nginx
|
||||||
|
image: nginx
|
||||||
|
- name: shell
|
||||||
|
image: busybox
|
||||||
|
securityContext:
|
||||||
|
capabilities:
|
||||||
|
add:
|
||||||
|
- SYS_PTRACE
|
||||||
|
stdin: true
|
||||||
|
tty: true
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: test-projected-volume
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: test-projected-volume
|
||||||
|
image: busybox
|
||||||
|
args:
|
||||||
|
- sleep
|
||||||
|
- "86400"
|
||||||
|
volumeMounts:
|
||||||
|
- name: all-in-one
|
||||||
|
mountPath: "/projected-volume"
|
||||||
|
readOnly: true
|
||||||
|
volumes:
|
||||||
|
- name: all-in-one
|
||||||
|
projected:
|
||||||
|
sources:
|
||||||
|
- secret:
|
||||||
|
name: user
|
||||||
|
- secret:
|
||||||
|
name: pass
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
kind: PersistentVolumeClaim
|
||||||
|
apiVersion: v1
|
||||||
|
metadata:
|
||||||
|
name: task-pv-claim
|
||||||
|
spec:
|
||||||
|
storageClassName: manual
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 3Gi
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
kind: Pod
|
||||||
|
apiVersion: v1
|
||||||
|
metadata:
|
||||||
|
name: task-pv-pod
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: task-pv-storage
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: task-pv-claim
|
||||||
|
containers:
|
||||||
|
- name: task-pv-container
|
||||||
|
image: nginx
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
name: "http-server"
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: "/usr/share/nginx/html"
|
||||||
|
name: task-pv-storage
|
||||||
|
|
||||||
|
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
kind: PersistentVolume
|
||||||
|
apiVersion: v1
|
||||||
|
metadata:
|
||||||
|
name: task-pv-volume
|
||||||
|
labels:
|
||||||
|
type: local
|
||||||
|
spec:
|
||||||
|
storageClassName: manual
|
||||||
|
capacity:
|
||||||
|
storage: 10Gi
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
hostPath:
|
||||||
|
path: "/mnt/data"
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: two-containers
|
||||||
|
spec:
|
||||||
|
|
||||||
|
restartPolicy: Never
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
- name: shared-data
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
|
containers:
|
||||||
|
|
||||||
|
- name: nginx-container
|
||||||
|
image: nginx
|
||||||
|
volumeMounts:
|
||||||
|
- name: shared-data
|
||||||
|
mountPath: /usr/share/nginx/html
|
||||||
|
|
||||||
|
- name: debian-container
|
||||||
|
image: debian
|
||||||
|
volumeMounts:
|
||||||
|
- name: shared-data
|
||||||
|
mountPath: /pod-data
|
||||||
|
command: ["/bin/sh"]
|
||||||
|
args: ["-c", "echo Hello from the debian container > /pod-data/index.html"]
|
||||||
Reference in New Issue
Block a user