ZH-trans: merge release1.16-temporary to master (#18217)
* zh-trans:/docs/docs/concepts/workloads/pods/ephemeral-containers.md (#16948) * update zh-trans of define-environment-variable-container.md (#16999) Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> * update chinese docs (#16985) * Fix ordered list (#16988) Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> * zh-trans:/docs/reference/setup-tools/kubeadm/kubeadm-upgrade-phase.md (#16951) Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> * Remove redundant symbol and fix some ordered list (#17000) Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> * update-zh-translation/docs/reference/setup-tools/kubeadm/kubeadm-init.md (#16997) * update zh translation kubeadm-reset.md kubeadm-upgrade.md (#16992) * Create kubeadm_join_phase_control-plane-join_all.md (#16987) * Update web-ui-dashboard.md (#16976) * update format problem (#16956) Signed-off-by: PingWang <wang.ping5@zte.com.cn> update Signed-off-by: PingWang <wang.ping5@zte.com.cn> * zh-trans:/docs/docs/concepts/storage/volume-pvc-datasource.md (#17021) * update zh translation /docs/reference/access-authn-authz/webhook.md (#16860) * fix confict update zh translation (#16863) * zh-trans:/docs/concepts/workloads/pods/disruptions.md (#16983) * zh-trans:/docs/concepts/workloads/pods/disruptions.md * Update content/zh/docs/concepts/workloads/pods/disruptions.md Co-Authored-By: Qiming <tengqim@cn.ibm.com> * update zh translation content/zh/docs/reference/command-line-tools-reference/kube-scheduler.md (#17006) * Update RC's link (#16935) Signed-off-by: PingWang <wang.ping5@zte.com.cn> Update Signed-off-by: PingWang <wang.ping5@zte.com.cn> update the style Signed-off-by: PingWang <wang.ping5@zte.com.cn> * Update the links for /zh/docs/setup (#16938) Signed-off-by: PingWang <wang.ping5@zte.com.cn> * zh-trans:/docs/docs/concepts/services-networking/dual-stack.md (#17024) * update zh translation /reference/setup-tools/kubeadm/generated/kubeadm.md (#17036) * update zh tanslation /reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubelet_config_download.md (#17037) * update zh translation -/reference/setup-tools/kubeadm/generated/kubeadm_alpha.md (#17038) * update zh translation /docs/contribute/participating.md (#17040) * Fix cri-o's links to match English docs (#16936) Signed-off-by: PingWang <wang.ping5@zte.com.cn> * update zh translation content/zh/docs/reference/kubectl/jsonpath.md (#16862) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_token_generate.md (#17049) * update Unkown -> Unknown (#17062) * zh-translation:high-availability.md (#16960) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update Runnning -> Running (#17061) * zh-trans:/docs/docs/concepts/storage/volume-snapshots.md (#17054) * update zh transation /docs/reference/setup-tools/kubeadm/generated/kubeadm_reset.md (#17060) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_token_create.md (#17052) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_token.md (#17055) * update zh translation update-zh-translation-/docs/reference/setup-tools/kubeadm/generated/kubeadm_token_list.md (#17048) * update zh-translation:ha-topology.md (#17099) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-trans /reference/setup-tools/kubeadm/generated/kubeadm_config_images_list.md (#17093) * update zh translation /reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_all.md (#17083) * Add Chinese translation for scheduler-perf-tuning (#17087) Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for scheduler-perf-tuning Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for scheduler-perf-tuning Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for scheduler-perf-tuning Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> * zh trans content/zh/docs/setup/production-environment/tools/kubeadm/control-plane-flags.md (#17121) * update zh trans content/zh/docs/tasks/access-application-cluster/service-access-application-cluster.md (#17122) * zh-translation:content/zh/docs/tasks/administer-cluster/namespaces-walkthrough.md (#17105) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update-zh-translation-/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_migrate.md (#17091) * update zh trans /docs/setup/learning-environment/minikube.md (#17143) * update zh trans /zh/docs/reference/_index.md (#17146) * update zh trans /docs/tasks/access-application-cluster/port-forward-access-application-cluster.md (#17134) * update zh translation 20191020-update-zh-translation-/docs/contribute/localization.md (#17046) * update zh trans /docs/reference/using-api/client-libraries.md (#17144) * update zh trans /docs/reference/setup-tools/kubeadm/generated/kubeadm_version.md (#17145) * update zh /docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade_node.md (#17131) * update zh translation /reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_front-proxy-client.md (#17081) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig.md (#17078) * add zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-join_update-status.md (#17076) * update zh trans content/zh/docs/contribute/generate-ref-docs/kubectl.md (#17165) * update zh translation /reference/command-line-tools-reference/kube-proxy.md (#17107) * zh-trans:/docs/docs/concepts/workloads/pods/pod-topology-spread-const… (#16955) * zh-trans:/docs/docs/concepts/workloads/pods/pod-topology-spread-constraints.md * Update pod-topology-spread-constraints.md * zh-trans:/docs/concepts/configuration/scheduling-framework.md (#17088) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_upload-config_kubelet.md (#17079) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane_apiserver.md (#17077) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-join.md (#17075) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_token_delete.md (#17050) * update zh trans /docs/concepts/overview/working-with-objects/namespaces.md (#17205) * update zh trans /docs/concepts/overview/what-is-kubernetes.md (#17203) * pr_release-1.16_crictl (#17201) * update zh docs/tasks/administer-cluster/dns-debugging-resolution.md (#17186) * update zh trans content/zh/docs/concepts/overview/working-with-objects/field-selectors.md (#17191) * translate configure_upgrade_etcd (#17160) * translate kubeadm_upgrade_apply (#17159) * update zh /docs/tasks/job/coarse-parallel-processing-work-queue.md (#17155) * translate docs/setup/release/version-skew-policy.md to Chinese (#17142) * update zh trans content/zh/docs/tasks/access-application-cluster/create-external-load-balancer.md (#17124) * zh-trans replace the wrong translation (#17103) zh-trans replace the wrong translation * Merged 1.14~1.16 changes (#17117) * zh-trans:/docs/concepts/configuration/assign-pod-node.md (#17129) * update zh trans /docs/contribute/generate-ref-docs/kubernetes-api.md (#17161) * pr_release-1.16_basic-ss (#17169) * Add zh-trans of assign-cpu-resource.md (#17063) Signed-off-by: heqg <he.qingguo@zte.com.cn> Add zh-trans of assign-cpu-resource.md Signed-off-by: heqg <he.qingguo@zte.com.cn> Add zh-trans of assign-cpu-resource.md Signed-off-by: heqg <he.qingguo@zte.com.cn> Add zh-trans of assign-cpu-resource.md Signed-off-by: heqg <he.qingguo@zte.com.cn> Add zh-trans of assign-cpu-resource.md Signed-off-by: heqg <he.qingguo@zte.com.cn> * update zh trans content/zh/docs/concepts/overview/working-with-objects/common-labels.md (#17193) * update zh translation /docs/contribute/intermediate.md (#17041) * zh-trans:docs/setup/production-environment/turnkey/tencent.md (#17207) * pr_release-1.16_mysql-wordpress-pv (#17202) * pr_release-1.16_reconfig-kubelet (#17200) * zh-trans:/docs/docs/concepts/workloads/controllers/jobs-run-completio… (#17020) * zh-trans:/docs/docs/concepts/workloads/controllers/jobs-run-completion.md * Update jobs-run-completion.md * Update jobs-run-completion.md * update zh trans content/zh/docs/concepts/extend-kubernetes/extend-cluster.md (#17212) * update zh trans content/zh/docs/concepts/extend-kubernetes/api-extension/apiserver-aggregation.md (#17213) * add zh trans /docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare_kubeconfig.md (#17220) kubeadm_join_phase_control-plane-prepare_download-certs.md * add zh trans /reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs.md and /reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare.md (#17219) * update zh trans content/zh/docs/concepts/containers/images.md (#17216) * ZH-trans: add _index.md (#17214) * ZH-trans: add _index.md * add _index.md file * add _index.md files * pr_release-1.16_crd-versions (#17198) * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_config_images_pull.md (#17092) * zh-trans /reference/setup-tools/kubeadm/generated/kubeadm_config_images.md (#17094) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_addon_kube-proxy.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_sa.md (#17222) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare_all.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare_certs.md (#17221) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_addon_all.md (#17223) * 013 /docs/concepts/services networking/ingress.md (#17185) * x * update zh trans content/zh/docs/concepts/services-networking/ingress.md * zh-trans:/reference/setup-tools/kubeadm/generated/kubeadm_completion.md and kubeadm_config.md (#17097) * add zh trans reference/glossary/pod-lifecycle (#17226) * update zh-translation document (#17096) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update zh-translation:setup-ha-etcd-with-kubeadm.md (#17098) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * add zh trans /docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_selfhosting.md and /docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubelet_config_enable-dynamic.md (#17227) * add zh trans /docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubeconfig_user.md and /docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_upload-config_kubeadm.md (#17228) * zh-translation:content/zh/docs/tasks/extend-kubectl/kubectl-plugins.md (#17089) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update zh translation /docs/reference/setup-tools/kubeadm/generated/kubeadm_join.md (#17080) * update zh translation /reference/setup-tools/kubeadm/generated/kubeadm_config_view.md (#17085) * zh-translation:troubleshooting-kubeadm.md (#17069) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-trans: docs/concepts/scheduling/kube-scheduler.md (#17067) * Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> Add Chinese translation for kube-scheduler Signed-off-by: GeorgeSen <wang.sen2@zte.com.cn> * Update kube-scheduler.md * Add Chinese translation for kube-scheduler * Update kube-scheduler.md * Update kube-scheduler.md * Update kube-scheduler.md * translate pods.md and init-containers.md for branch release-1.16 (#17208) * update zh translation /docs/contribute/start.md (#17039) * zh-translation:2017-10-00-Five-Days-Of-Kubernetes-18.md (#17229) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * translate kubeadm-certs.md (#17090) * update the Illegal comment such as : (<!--、<--) (#17266) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_etcd-ca.md (#17268) * update zh /docs/concepts/architecture/cloud-controller.md (#17263) * update zh /docs/concepts/cluster-administration/logging.md (#17247) * modify the show of zh translation /concepts/overview/what-is-kubernetes.md /reference/setup-tools/kubeadm/generated/kubeadm_init.md /reference/setup-tools/kubeadm/kubeadm-init.md (#17246) * zh-translation:kubeadm_init_phase_control-plane_all.md (#17243) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-translation:kubeadm_join_phase_control-plane-join_etcd.md (#17236) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubelet-start.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_upload-certs.md (#17230) * add content/zh/docs/reference/glossary/container-runtime.md file fix-up to pass the ci and trans content/zh/docs/reference/glossary/container-runtime.md、content/zh/docs/concepts/overview/components.md (#17211) * zh-translation:mirror-pod.md (#17231) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-translation:kubeadm_init_phase_upload-config.md (#17238) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * update zh /docs/concepts/workloads/pods/pod-overview.md (#17239) * update the format of zh translation content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade_apply.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade_plan.md content/zh/docs/reference/setup-tools/kubeadm/kubeadm-config.md content/zh/docs/reference/setup-tools/kubeadm/kubeadm-reset.md content/zh/docs/reference/setup-tools/kubeadm/kubeadm-token.md content/zh/docs/reference/setup-tools/kubeadm/kubeadm-upgrade.md (#17248) * Create advanced.md (#17256) * Create advanced.md * trans the advanced.md and fix the build bugs * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane_scheduler.md (#17269) * zh-translation:kubelet-integration.md (#17272) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * pr_release-1.16_out-of-resource (#17199) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_front-proxy-ca.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane_controller-manager.md (#17267) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_etcd-peer.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_admin.md (#17271) * pr_release-1.16_ext-admission-ctl (#17196) * update zh translation /docs/contribute/advanced.md (#17042) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_apiserver-etcd-client.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_ca.md (#17275) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_print.md update zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_print_init-defaults.md (#17282) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated… (#17287) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_etcd.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_upload-config_all.md update zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_control-plane.md * Update kubeadm_init_phase_etcd.md * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/… (#17285) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_etcd-server.md content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubelet.md update zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_apiserver.md * Update kubeadm_alpha_kubelet.md * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_all.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_addon.md fix-up bad comment kubeadm_alpha_certs_renew.md、kubeadm_alpha_certs_renew_apiserver-etcd-client.md、kubeadm_init_phase_addon_all.md (#17276) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/… (#17281) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_etcd_local.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_print_join-defaults.md * Update kubeadm_init_phase_etcd_local.md * zh trans update-daemon-set.md (#16872) * zh trans update-daemon-set.md * Update update-daemon-set.md * managing-tls-in-a-cluster.md (#16874) * update-api-object-kubectl-patch.md (#16875) * improve the zh trans /kubeadm/generated/kubeadm_init_phase_.* 1 (#17295) * improve the zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_.* (#17294) * modify the zh translation content/zh/docs/reference/setup-tools/kubea… (#17293) * modify the zh translation content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_.* * Update kubeadm_alpha.md * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_all.md and content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_preflight.md (#17280) * add zh /docs/reference/glossary/cgroup.md (#17291) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubelet_config.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_apiserver-kubelet-client.md (#17288) * improve zh trans of command in /kubeadm/generated/kubeadm_init_phase_.* files (#17297) * improve zh command translation /kubeadm/generated/kubeadm_init_.* files (#17298) * update zh trans in /kubeadm/generated/kubeadm_.* files (#17306) * add zh trans /reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_etcd-healthcheck-client.md、/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_etcd-peer.md、/reference/setup-tools/kubeadm/generated/kubeadm_alpha_kubeconfig.md (#17308) * Improve previously translated documents (#17327) Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * zh-trans: docs/setup/production-environment/turnkey/aws.md (#17320) * Update zh.toml * update zh trans /generated/kubeadm_join_phase_.* files (#17301) * Update zh.toml * add zh /docs/reference/glossary/pod-disruption-budget.md (#17344) * pr_release-1.16_config-aggregation-layer (#17197) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_controller-manager.conf.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_scheduler.conf.md (#17390) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_scheduler.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-prepare_control-plane.md (#17381) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_apiserver-kubelet-client.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_control-plane-join_mark-control-plane.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_kubelet-start.md (#17380) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_addon_coredns.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_bootstrap-token.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_apiserver.md (#17383) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_certificate-key.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset_phase_preflight.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset_phase_update-cluster-status.md (#17385) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_admin.conf.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset_phase.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_reset_phase_cleanup-node.md (#17387) * add zh trans content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_apiserver-kubelet-client.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_certs_renew_front-proxy-client.md、content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha_selfhosting_pivot.md (#17384) * add zh /docs/reference/glossary/limitrange.md (#17324) * add zh trans content/zh/docs/setup/best-practices/cluster-large.md (#17321) * add zh trans content/zh/docs/setup/best-practices/cluster-large.md * Update cluster-large.md * add zh trans /docs/reference/setup-tools/kubeadm/kubeadm-alpha.md、/do… (#17403) * add zh trans /docs/reference/setup-tools/kubeadm/kubeadm-alpha.md、/docs/reference/setup-tools/kubeadm/generated/kubeadm_join_phase_preflight.md、/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_certs_etcd-server.md * Update kubeadm_init_phase_certs_etcd-server.md * add zh /docs/reference/glossary/cluster-operations.md (#17300) * add zh /docs/reference/glossary/applications.md (#17419) * update zh trans kubelet (#17379) * update zh trans kubelet * update the file according to feedback from reviewer tengqm * update 1000-1757 lines * update the advice zh trans * add zh /docs/reference/glossary/static-pod.md (#17418) * add zh /docs/reference/glossary/preemption.md (#17423) * add zh /docs/reference/glossary/pod-priority.md (#17421) * add zh /docs/reference/glossary/control-plane.md (#17425) * add zh /docs/reference/glossary/cluster-infrastructure.md (#17424) * pr_release-1.16_api-overview (#17444) * pr_release-1.16_daemonset (#17435) * pr_release-1.16_gc (#17445) * pr_release-1.16_qos-class (#17442) * fix QoS Class to QoS 类 (#17464) * pr_release-1.16-abac (#17427) * zh-trans:docs/setup/production-environment/turnkey/alibaba-cloud.md (#17345) * pr_release-1.16_endpoint-slice (#17468) * pr_release-1.16_taint (#17469) * pr_release-1.16_operator-pattern (#17467) * pr_release-1.16_ss (#17433) * pr_release-1.16_admission-controller (#17440) * pr_release-1.16_containerd (#17441) * pr_release-1.16_app-container (#17466) * add zh-trans content/zh/docs/setup/_index.md、content/zh/docs/setup/release/_index.md (#17503) * pr-release-1.16_enabling-endpoint-slices (#17504) * update zh trans content/zh/docs/reference/setup-tools/kubeadm/kubeadm… (#17495) * update zh trans content/zh/docs/reference/setup-tools/kubeadm/kubeadm-upgrade-phase.md、content/zh/docs/reference/setup-tools/kubeadm/kubeadm-init-phase.md * add content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_kubelet.md * pr-release-1.16_logging (#17491) * pr-release-1.16_cri (#17486) * add zh-trans:docs/setup/production-environment/turnkey/azure.md (#17482) * pattern translate into 模式 (#17485) * fix zk affinity description in zh trans (#17393) * pr-release-1.16_ephemeral-container (#17487) * pr-release-1.16_data-plane (#17489) * pr-release-1.16_cncf (#17490) * zh-trans add content\zh\docs\tools\install-minikube.md (#16920) * zh-trans add content\zh\docs\tools\install-minikube.md * zh-trans update content\zh\docs\tools\install-minikube.md * zh-trans update content\zh\docs\tools\install-minikube.md * update \docs\tasks\tools\install-minikube.md * update docs\concepts\workloads\controllers\deployment.md * update deployment.md * pr-release-1.16_extensions (#17492) * pr-release-1.16_toleration (#17493) * Revert "update zh trans content/zh/docs/reference/setup-tools/kubeadm/kubeadm… (#17495)" (#17521) This reverts commit 1134c14e0a39bdc3d1a920ac9797139a6dcccf4b. * motidy extensions in content/zh/docs/reference/glossary/extensions (#17524) * motidy toleration in content/zh/docs/reference/glossary/toleration.md (#17523) * motidy toleration in content/zh/docs/reference/glossary/toleration.md * Update toleration.md * improve zh-trans in content/zh/docs/setup/_index.md (#17526) * add zh-trans /zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init_phase_kubeconfig_kubelet.md (#17527) * Broken Link (#17546) Issue available at https://kubernetes.io/zh/docs/concepts/containers/runtime-class/ and introduced by original English documentation (see #17543) * Update trans kubeadm_upgrade_plan.md (#17395) * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * Update kubeadm_upgrade_plan.md * update zh-trans of define-command-argument-container.md (#17022) Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> update zh-trans of define-command-argument-container.md Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> Add back the Original English Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> update title of define-command-argument-container.md Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> update table title and reference Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> update reference of define-command-argument-container.md Signed-off-by: Yixiang2019 <wang.yixiang@zte.com.cn> * ZH-trans: fix multiple jump links and update files (#17603) * ZH-trans: fix multiple jump links and update files * Update _index.html * update zh trans content/zh/docs/reference/setup-tools/kubeadm/kubeadm-init-phase.md (#17528) * update zh trans /doc/concepts/architecture/nodes.md (#17617) * update zh trans content/zh/docs/concepts/architecture/nodes.md * fix-up content/zh/docs/concepts/architecture/nodes.md * add zh-trans /docs/setup/release/notes.md (#17519) * add zh-trans /docs/setup/release/notes.md update-750 * fix-up 1575 line and udpate 2483 line * update to line 2980 * update to the last line 3160 * add zh-trans:docs/setup/production-environment/turnkey/icp.md (#17568) * zh-trans: /docs/setup/production-environment/container-runtimes.md (#17646) * zh-trs:container-runtimes.md Signed-off-by: yuxiaobo <yuxiaobogo@163.com> * Update container-runtimes.md * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese (#17791) * Translate /docs/concepts/cluster-administration/cloud-providers.md into Chinese * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese * Sorry, wrong commit, roll back... * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese * Create trans kubeadm_upgrade_diff.md (#17392) * Update kubeadm_upgrade_diff.md * Update kubeadm_upgrade_diff.md * Update kubeadm_upgrade_diff.md * Create _index.md (#17831) * zh-trans zh-trans-/docs/reference/command-line-tools-reference/feature-gates.md (#17658) * Update volume-snapshots.md (#17829) * Update volume-snapshots.md * Update volume-snapshots.md * Update volume-snapshots.md * Create ovirt.md (#17849) * Create ovirt.md * Update ovirt.md * Translate /docs/concepts/cluster-administration/cloud-providers.md into Chinese (#17761) * Translate /docs/concepts/cluster-administration/cloud-providers.md into Chinese * Translate /docs/concepts/workloads/controllers/ttlafterfinished.md into Chinese * Sorry, wrong commit, roll back... * Update translation after tengqm's review. * Update cloud-providers.md * Update dual-stack.md (#17836) * Update dual-stack.md * Update dual-stack.md * Update dual-stack.md * Update dual-stack.md * Create validate-dual-stack.md (#17833) * Create validate-dual-stack.md * Update validate-dual-stack.md * translation content/zh/docs/reference/setup-tools/kubeadm/ kubeadm-join-phase、kubeadm-reset-phase (#17881) * zh-trans content/zh/docs/contribute/generate-ref-docs/contribute-upstream.md (#17882) * Chinese translation /docs/tasks/administer-cluster/highly-available-master.md (#17884) * Chinese translation /docs/tasks/administer-cluster/highly-available-master.md * Apply suggestions from code review Co-Authored-By: Qiming <tengqim@cn.ibm.com> * Fix format issue (#17921) * Create topology-manager.md (#17901) * Create topology-manager.md * Update topology-manager.md * add zh-trans:docs/setup/production-environment/windows/user-guide-windows-containers.md (#17876) * Update pod-overhead.md (#17931) * Update scheduler-perf-tuning.md (#17934) * Create dcos.md (#17932) * Create dcos.md * Update dcos.md * Update object-management.md (#17937) * zh-translation content/zh/docs/setup/production-environment/tools/kops.md (#17991) * Create imperative-config.md (#17956) * Create imperative-config.md * Update imperative-config.md * Create self-hosting.md (#17950) * Create resource-bin-packing.md (#17935) * Create nodelocaldns.md (#17938) * Update config.toml(release-1.16) for 1.17 (#18025) * Update config.toml(release-1.16) for 1.17 * Update config.toml * Remove ru language * Update the conflict and merge the two commits * add nginx-deployment.yaml file Co-authored-by: ZhongliangXiong <xiong.zhongliang@zte.com.cn> Co-authored-by: Yixiang Wang <wang.yixiang@zte.com.cn> Co-authored-by: li mengyang <hwdef97@gmail.com> Co-authored-by: PingWang <wang.ping5@zte.com.cn> Co-authored-by: chentanjun <tanjunchen20@gmail.com> Co-authored-by: Sophy417 <53026875+Sophy417@users.noreply.github.com> Co-authored-by: zhangx501 <zhang0000xun@gmail.com> Co-authored-by: Qiming <tengqim@cn.ibm.com> Co-authored-by: yuxiaobo96 <41496192+yuxiaobo96@users.noreply.github.com> Co-authored-by: senwang <wang.sen2@zte.com.cn> Co-authored-by: lichuqiang <lichuqiang@huawei.com> Co-authored-by: lpf7551321 <liupengfei20@huawei.com> Co-authored-by: Hongcai Ren <renhongcai@huawei.com> Co-authored-by: jiajie <jiaj12@chinaunicom.cn> Co-authored-by: heqg <56527988+heqg@users.noreply.github.com> Co-authored-by: IreneByron <zhangbingqing7@huawei.com> Co-authored-by: Wang Bing <wangbing.adam@gmail.com> Co-authored-by: Damini Satya <daminisatya@gmail.com> Co-authored-by: liufangwai <liufangwai@huawei.com> Co-authored-by: wangcong <congfairy2536@gmail.com> Co-authored-by: XuefeiWang2 <wangxuefei2@huawei.com> Co-authored-by: Kubernetes Prow Robot <k8s-ci-robot@users.noreply.github.com> Co-authored-by: Ziqiu Zhu <zzqshu@126.com> Co-authored-by: ten2ton <50288981+ten2ton@users.noreply.github.com> Co-authored-by: Oleg Butuzov <butuzov@users.noreply.github.com> Co-authored-by: jiazxjason <52809535+jiazxjason@users.noreply.github.com> Co-authored-by: Coffey Gao <coffiney@qq.com> Co-authored-by: Bingshen Wang <bingshen.wbs@alibaba-inc.com>
This commit is contained in:
committed by
Kubernetes Prow Robot
parent
9135bdbe6d
commit
b8b2cc7c74
@@ -0,0 +1,27 @@
|
||||
---
|
||||
|
||||
title: " Kubernetes 采集视频 "
|
||||
date: 2015-03-23
|
||||
slug: kubernetes-gathering-videos
|
||||
url: /blog/2015/03/Kubernetes-Gathering-Videos
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
|
||||
title: " Kubernetes Gathering Videos "
|
||||
date: 2015-03-23
|
||||
slug: kubernetes-gathering-videos
|
||||
url: /blog/2015/03/Kubernetes-Gathering-Videos
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
If you missed the Kubernetes Gathering in SF last month, fear not! Here are the videos from the evening presentations organized into a playlist on YouTube
|
||||
|
||||
[](https://www.youtube.com/playlist?list=PL69nYSiGNLP2FBVvSLHpJE8_6hRHW8Kxe)
|
||||
-->
|
||||
|
||||
如果你错过了上个月在旧金山举行的 Kubernetes 大会,不要害怕!以下是在 YouTube 上组织成播放列表的晚间演示文稿中的视频。
|
||||
|
||||
[](https://www.youtube.com/playlist?list=PL69nYSiGNLP2FBVvSLHpJE8_6hRHW8Kxe)
|
||||
@@ -0,0 +1,186 @@
|
||||
---
|
||||
title: " Kubernetes 社区每周聚会笔记 - 2015年3月27日 "
|
||||
date: 2015-03-28
|
||||
slug: weekly-kubernetes-community-hangout
|
||||
url: /blog/2015/03/Weekly-Kubernetes-Community-Hangout
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Weekly Kubernetes Community Hangout Notes - March 27 2015 "
|
||||
date: 2015-03-28
|
||||
slug: weekly-kubernetes-community-hangout
|
||||
url: /blog/2015/03/Weekly-Kubernetes-Community-Hangout
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
Every week the Kubernetes contributing community meet virtually over Google Hangouts. We want anyone who's interested to know what's discussed in this forum.
|
||||
-->
|
||||
每个星期,Kubernetes 贡献者社区几乎都会在谷歌 Hangouts 上聚会。我们希望任何对此感兴趣的人都能了解这个论坛的讨论内容。
|
||||
|
||||
<!--
|
||||
Agenda:
|
||||
-->
|
||||
日程安排:
|
||||
|
||||
<!--
|
||||
|
||||
\- Andy - demo remote execution and port forwarding
|
||||
|
||||
\- Quinton - Cluster federation - Postponed
|
||||
|
||||
\- Clayton - UI code sharing and collaboration around Kubernetes
|
||||
|
||||
-->
|
||||
|
||||
\- Andy - 演示远程执行和端口转发
|
||||
|
||||
\- Quinton - 联邦集群 - 延迟
|
||||
|
||||
\- Clayton - 围绕 Kubernetes 的 UI 代码共享和协作
|
||||
|
||||
<!--
|
||||
Notes from meeting:
|
||||
-->
|
||||
从会议指出:
|
||||
|
||||
<!--
|
||||
|
||||
1\. Andy from RedHat:
|
||||
|
||||
-->
|
||||
|
||||
1\. Andy 从 RedHat:
|
||||
|
||||
<!--
|
||||
|
||||
* Demo remote execution
|
||||
|
||||
-->
|
||||
|
||||
* 演示远程执行
|
||||
|
||||
<!--
|
||||
|
||||
* kubectl exec -p $POD -- $CMD
|
||||
|
||||
* Makes a connection to the master as proxy, figures out which node the pod is on, proxies connection to kubelet, which does the interesting bit. via nsenter.
|
||||
|
||||
* Multiplexed streaming over HTTP using SPDY
|
||||
|
||||
* Also interactive mode:
|
||||
|
||||
* Assumes first container. Can use -c $CONTAINER to pick a particular one.
|
||||
|
||||
* If have gdb pre-installed in container, then can interactively attach it to running process
|
||||
|
||||
* backtrace, symbol tbles, print, etc. Most things you can do with gdb.
|
||||
|
||||
* Can also with careful flag crafting run rsync over this or set up sshd inside container.
|
||||
|
||||
* Some feedback via chat:
|
||||
|
||||
-->
|
||||
|
||||
* kubectl exec -p $POD -- $CMD
|
||||
|
||||
* 作为代理与主机建立连接,找出 pod 所在的节点,代理与 kubelet 的连接,这一点很有趣。通过 nsenter。
|
||||
|
||||
* 使用 SPDY 通过 HTTP 进行多路复用流式传输
|
||||
|
||||
* 还有互动模式:
|
||||
|
||||
* 假设第一个容器,可以使用 -c $CONTAINER 一个特定的。
|
||||
|
||||
* 如果在容器中预先安装了 gdb,则可以交互地将其附加到正在运行的进程中
|
||||
|
||||
* backtrace、symbol tbles、print 等。 使用gdb可以做的大多数事情。
|
||||
|
||||
* 也可以用精心制作的参数在上面运行 rsync 或者在容器内设置 sshd。
|
||||
|
||||
* 一些聊天反馈:
|
||||
|
||||
<!--
|
||||
|
||||
* Andy also demoed port forwarding
|
||||
* nsenter vs. docker exec
|
||||
|
||||
-->
|
||||
|
||||
* Andy 还演示了端口转发
|
||||
* nnsenter 与 docker exec
|
||||
|
||||
<!--
|
||||
|
||||
* want to inject a binary under control of the host, similar to pre-start hooks
|
||||
|
||||
* socat, nsenter, whatever the pre-start hook needs
|
||||
|
||||
-->
|
||||
|
||||
* 想要在主机的控制下注入二进制文件,类似于预启动钩子
|
||||
|
||||
* socat、nsenter,任何预启动钩子需要的
|
||||
|
||||
<!--
|
||||
|
||||
* would be nice to blog post on this
|
||||
* version of nginx in wheezy is too old to support needed master-proxy functionality
|
||||
|
||||
-->
|
||||
|
||||
* 如果能在博客上发表这方面的文章就太好了
|
||||
* wheezy 中的 nginx 版本太旧,无法支持所需的主代理功能
|
||||
|
||||
<!--
|
||||
|
||||
2\. Clayton: where are we wrt a community organization for e.g. kubernetes UI components?
|
||||
|
||||
* google-containers-ui IRC channel, mailing list.
|
||||
* Tim: google-containers prefix is historical, should just do "kubernetes-ui"
|
||||
* also want to put design resources in, and bower expects its own repo.
|
||||
* General agreement
|
||||
|
||||
-->
|
||||
|
||||
2\. Clayton: 我们的社区组织在哪里,例如 kubernetes UI 组件?
|
||||
|
||||
* google-containers-ui IRC 频道,邮件列表。
|
||||
* Tim: google-containers 前缀是历史的,应该只做 "kubernetes-ui"
|
||||
* 也希望将设计资源投入使用,并且 bower 期望自己的仓库。
|
||||
* 通用协议
|
||||
|
||||
<!--
|
||||
|
||||
3\. Brian Grant:
|
||||
|
||||
* Testing v1beta3, getting that ready to go in.
|
||||
* Paul working on changes to commandline stuff.
|
||||
* Early to mid next week, try to enable v1beta3 by default?
|
||||
* For any other changes, file issue and CC thockin.
|
||||
|
||||
-->
|
||||
|
||||
3\. Brian Grant:
|
||||
|
||||
* 测试 v1beta3,准备进入。
|
||||
* Paul 力于改变命令行的内容。
|
||||
* 下周初至中旬,尝试默认启用v1beta3 ?
|
||||
* 对于任何其他更改,请发出文件并抄送 thockin。
|
||||
|
||||
<!--
|
||||
|
||||
4\. General consensus that 30 minutes is better than 60
|
||||
|
||||
-->
|
||||
|
||||
4\. 一般认为30分钟比60分钟好
|
||||
|
||||
<!--
|
||||
|
||||
* Shouldn't artificially try to extend just to fill time.
|
||||
|
||||
-->
|
||||
|
||||
* 不应该为了填满时间而人为地延长。
|
||||
@@ -0,0 +1,62 @@
|
||||
---
|
||||
title: 欢迎来到 Kubernetes 博客!
|
||||
date: 2015-03-20
|
||||
slug: welcome-to-kubernetes-blog
|
||||
url: /blog/2015/03/Welcome-To-Kubernetes-Blog
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: Welcome to the Kubernetes Blog!
|
||||
date: 2015-03-20
|
||||
slug: welcome-to-kubernetes-blog
|
||||
url: /blog/2015/03/Welcome-To-Kubernetes-Blog
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
Welcome to the new Kubernetes Blog. Follow this blog to learn about the Kubernetes Open Source project. We plan to post release notes, how-to articles, events, and maybe even some off topic fun here from time to time.
|
||||
-->
|
||||
欢迎来到新的 Kubernetes 博客。关注此博客,了解 Kubernetes 开源项目。我们计划不时发布发布说明,操作方法文章,活动,甚至一些非常有趣的话题。
|
||||
|
||||
<!--
|
||||
If you are using Kubernetes or contributing to the project and would like to do a guest post, [please let me know](mailto:kitm@google.com).
|
||||
-->
|
||||
如果您正在使用 Kubernetes 或为该项目做出贡献并想要发帖子,[请告诉我](mailto:kitm@google.com)。
|
||||
|
||||
<!--
|
||||
To start things off, here's a roundup of recent Kubernetes posts from other sites:
|
||||
-->
|
||||
首先,以下是 Kubernetes 最近在其他网站上发布的文章摘要:
|
||||
|
||||
<!--
|
||||
- [Scaling MySQL in the cloud with Vitess and Kubernetes](http://googlecloudplatform.blogspot.com/2015/03/scaling-MySQL-in-the-cloud-with-Vitess-and-Kubernetes.html)
|
||||
- [Container Clusters on VMs](http://googlecloudplatform.blogspot.com/2015/02/container-clusters-on-vms.html)
|
||||
- [Everything you wanted to know about Kubernetes but were afraid to ask](http://googlecloudplatform.blogspot.com/2015/01/everything-you-wanted-to-know-about-Kubernetes-but-were-afraid-to-ask.html)
|
||||
- [What makes a container cluster?](http://googlecloudplatform.blogspot.com/2015/01/what-makes-a-container-cluster.html)
|
||||
- [Integrating OpenStack and Kubernetes with Murano](https://www.mirantis.com/blog/integrating-openstack-and-kubernetes-with-murano/)
|
||||
- [An introduction to containers, Kubernetes, and the trajectory of modern cloud computing](http://googlecloudplatform.blogspot.com/2015/01/in-coming-weeks-we-will-be-publishing.html)
|
||||
- [What is Kubernetes and how to use it?](http://www.centurylinklabs.com/what-is-kubernetes-and-how-to-use-it/)
|
||||
- [OpenShift V3, Docker and Kubernetes Strategy](https://blog.openshift.com/v3-docker-kubernetes-interview/)
|
||||
- [An Introduction to Kubernetes](https://www.digitalocean.com/community/tutorials/an-introduction-to-kubernetes)
|
||||
-->
|
||||
|
||||
- [使用 Vitess 和 Kubernetes 在云中扩展 MySQL](http://googlecloudplatform.blogspot.com/2015/03/scaling-MySQL-in-the-cloud-with-Vitess-and-Kubernetes.html)
|
||||
- [虚拟机上的容器群集](http://googlecloudplatform.blogspot.com/2015/02/container-clusters-on-vms.html)
|
||||
- [想知道的关于 kubernetes 的一切,却又不敢问](http://googlecloudplatform.blogspot.com/2015/01/everything-you-wanted-to-know-about-Kubernetes-but-were-afraid-to-ask.html)
|
||||
- [什么构成容器集群?](http://googlecloudplatform.blogspot.com/2015/01/what-makes-a-container-cluster.html)
|
||||
- [将 OpenStack 和 Kubernetes 与 Murano 集成](https://www.mirantis.com/blog/integrating-openstack-and-kubernetes-with-murano/)
|
||||
- [容器介绍,Kubernetes 以及现代云计算的发展轨迹](http://googlecloudplatform.blogspot.com/2015/01/in-coming-weeks-we-will-be-publishing.html)
|
||||
- [什么是 Kubernetes 以及如何使用它?](http://www.centurylinklabs.com/what-is-kubernetes-and-how-to-use-it/)
|
||||
- [OpenShift V3,Docker 和 Kubernetes 策略](https://blog.openshift.com/v3-docker-kubernetes-interview/)
|
||||
- [Kubernetes 简介](https://www.digitalocean.com/community/tutorials/an-introduction-to-kubernetes)
|
||||
|
||||
<!--
|
||||
Happy cloud computing!
|
||||
-->
|
||||
快乐的云计算!
|
||||
|
||||
<!--
|
||||
- Kit Merker - Product Manager, Google Cloud Platform
|
||||
-->
|
||||
- Kit Merker - Google 云平台产品经理
|
||||
@@ -0,0 +1,176 @@
|
||||
---
|
||||
title: " Kubernetes Release: 0.15.0 "
|
||||
date: 2015-04-16
|
||||
slug: kubernetes-release-0150
|
||||
url: /blog/2015/04/Kubernetes-Release-0150
|
||||
---
|
||||
|
||||
<!--
|
||||
Release Notes:
|
||||
-->
|
||||
|
||||
Release 说明:
|
||||
|
||||
<!--
|
||||
|
||||
* Enables v1beta3 API and sets it to the default API version ([#6098][1])
|
||||
* Added multi-port Services ([#6182][2])
|
||||
* New Getting Started Guides
|
||||
* Multi-node local startup guide ([#6505][3])
|
||||
* Mesos on Google Cloud Platform ([#5442][4])
|
||||
* Ansible Setup instructions ([#6237][5])
|
||||
* Added a controller framework ([#5270][6], [#5473][7])
|
||||
* The Kubelet now listens on a secure HTTPS port ([#6380][8])
|
||||
* Made kubectl errors more user-friendly ([#6338][9])
|
||||
* The apiserver now supports client cert authentication ([#6190][10])
|
||||
* The apiserver now limits the number of concurrent requests it processes ([#6207][11])
|
||||
* Added rate limiting to pod deleting ([#6355][12])
|
||||
* Implement Balanced Resource Allocation algorithm as a PriorityFunction in scheduler package ([#6150][13])
|
||||
* Enabled log collection from master ([#6396][14])
|
||||
* Added an api endpoint to pull logs from Pods ([#6497][15])
|
||||
* Added latency metrics to scheduler ([#6368][16])
|
||||
* Added latency metrics to REST client ([#6409][17])
|
||||
|
||||
-->
|
||||
|
||||
* 启用 1beta3 API 并将其设置为默认 API 版本 ([#6098][1])
|
||||
* 增加了多端口服务([#6182][2])
|
||||
* 新入门指南
|
||||
* 多节点本地启动指南 ([#6505][3])
|
||||
* Google 云平台上的 Mesos ([#5442][4])
|
||||
* Ansible 安装说明 ([#6237][5])
|
||||
* 添加了一个控制器框架 ([#5270][6], [#5473][7])
|
||||
* Kubelet 现在监听一个安全的 HTTPS 端口 ([#6380][8])
|
||||
* 使 kubectl 错误更加友好 ([#6338][9])
|
||||
* apiserver 现在支持客户端 cert 身份验证 ([#6190][10])
|
||||
* apiserver 现在限制了它处理的并发请求的数量 ([#6207][11])
|
||||
* 添加速度限制删除 pod ([#6355][12])
|
||||
* 将平衡资源分配算法作为优先级函数实现在调度程序包中 ([#6150][13])
|
||||
* 从主服务器启用日志收集功能 ([#6396][14])
|
||||
* 添加了一个 api 端口来从 Pod 中提取日志 ([#6497][15])
|
||||
* 为调度程序添加了延迟指标 ([#6368][16])
|
||||
* 为 REST 客户端添加了延迟指标 ([#6409][17])
|
||||
|
||||
<!--
|
||||
|
||||
* etcd now runs in a pod on the master ([#6221][18])
|
||||
* nginx now runs in a container on the master ([#6334][19])
|
||||
* Began creating Docker images for master components ([#6326][20])
|
||||
* Updated GCE provider to work with gcloud 0.9.54 ([#6270][21])
|
||||
* Updated AWS provider to fix Region vs Zone semantics ([#6011][22])
|
||||
* Record event when image GC fails ([#6091][23])
|
||||
* Add a QPS limiter to the kubernetes client ([#6203][24])
|
||||
* Decrease the time it takes to run make release ([#6196][25])
|
||||
* New volume support
|
||||
* Added iscsi volume plugin ([#5506][26])
|
||||
* Added glusterfs volume plugin ([#6174][27])
|
||||
* AWS EBS volume support ([#5138][28])
|
||||
* Updated to heapster version to v0.10.0 ([#6331][29])
|
||||
* Updated to etcd 2.0.9 ([#6544][30])
|
||||
* Updated to Kibana to v1.2 ([#6426][31])
|
||||
* Bug Fixes
|
||||
* Kube-proxy now updates iptables rules if a service's public IPs change ([#6123][32])
|
||||
* Retry kube-addons creation if the initial creation fails ([#6200][33])
|
||||
* Make kube-proxy more resiliant to running out of file descriptors ([#6727][34])
|
||||
|
||||
-->
|
||||
|
||||
* etcd 现在在 master 上的一个 pod 中运行 ([#6221][18])
|
||||
* nginx 现在在 master上的容器中运行 ([#6334][19])
|
||||
* 开始为主组件构建 Docker 镜像 ([#6326][20])
|
||||
* 更新了 GCE 程序以使用 gcloud 0.9.54 ([#6270][21])
|
||||
* 更新了 AWS 程序来修复区域与区域语义 ([#6011][22])
|
||||
* 记录镜像 GC 失败时的事件 ([#6091][23])
|
||||
* 为 kubernetes 客户端添加 QPS 限制器 ([#6203][24])
|
||||
* 减少运行 make release 所需的时间 ([#6196][25])
|
||||
* 新卷的支持
|
||||
* 添加 iscsi 卷插件 ([#5506][26])
|
||||
* 添加 glusterfs 卷插件 ([#6174][27])
|
||||
* AWS EBS 卷支持 ([#5138][28])
|
||||
* 更新到 heapster 版本到 v0.10.0 ([#6331][29])
|
||||
* 更新到 etcd 2.0.9 ([#6544][30])
|
||||
* 更新到 Kibana 到 v1.2 ([#6426][31])
|
||||
* 漏洞修复
|
||||
* 如果服务的公共 IP 发生变化,Kube-proxy现在会更新iptables规则 ([#6123][32])
|
||||
* 如果初始创建失败,则重试 kube-addons 创建 ([#6200][33])
|
||||
* 使 kube-proxy 对耗尽文件描述符更具弹性 ([#6727][34])
|
||||
|
||||
<!--
|
||||
To download, please visit https://github.com/GoogleCloudPlatform/kubernetes/releases/tag/v0.15.0
|
||||
-->
|
||||
要下载,请访问 https://github.com/GoogleCloudPlatform/kubernetes/releases/tag/v0.15.0
|
||||
|
||||
<!--
|
||||
[1]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6098 "Enabling v1beta3 api version by default in master"
|
||||
[2]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6182 "Implement multi-port Services"
|
||||
[3]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6505 "Docker multi-node"
|
||||
[4]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5442 "Getting started guide for Mesos on Google Cloud Platform"
|
||||
[5]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6237 "example ansible setup repo"
|
||||
[6]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5270 "Controller framework"
|
||||
[7]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5473 "Add DeltaFIFO (a controller framework piece)"
|
||||
[8]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6380 "Configure the kubelet to use HTTPS (take 2)"
|
||||
[9]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6338 "Return a typed error for config validation, and make errors simple"
|
||||
[10]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6190 "Add client cert authentication"
|
||||
[11]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6207 "Add a limit to the number of in-flight requests that a server processes."
|
||||
[12]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6355 "Added rate limiting to pod deleting"
|
||||
[13]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6150 "Implement Balanced Resource Allocation (BRA) algorithm as a PriorityFunction in scheduler package."
|
||||
[14]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6396 "Enable log collection from master."
|
||||
[15]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6497 "Pod log subresource"
|
||||
[16]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6368 "Add basic latency metrics to scheduler."
|
||||
[17]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6409 "Add latency metrics to REST client"
|
||||
[18]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6221 "Run etcd 2.0.5 in a pod"
|
||||
[19]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6334 "Add an nginx docker image for use on the master."
|
||||
[20]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6326 "Create Docker images for master components "
|
||||
[21]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6270 "Updates for gcloud 0.9.54"
|
||||
-->
|
||||
[1]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6098 "在 master 中默认启用 v1beta3 api 版本"
|
||||
[2]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6182 "实现多端口服务"
|
||||
[3]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6505 "Docker 多节点"
|
||||
[4]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5442 "谷歌云平台上 Mesos 入门指南"
|
||||
[5]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6237 "示例 ansible 设置仓库"
|
||||
[6]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5270 "控制器框架"
|
||||
[7]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5473 "添加 DeltaFIFO(控制器框架块)"
|
||||
[8]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6380 "将 kubelet 配置为使用 HTTPS (获得 2)"
|
||||
[9]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6338 "返回用于配置验证的类型化错误,并简化错误"
|
||||
[10]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6190 "添加客户端证书认证"
|
||||
[11]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6207 "为服务器处理的正在运行的请求数量添加一个限制。"
|
||||
[12]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6355 "添加速度限制删除 pod"
|
||||
[13]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6150 "将均衡资源分配算法作为优先级函数实现在调度程序包中。"
|
||||
[14]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6396 "启用主服务器收集日志。"
|
||||
[15]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6497 "pod 子日志资源"
|
||||
[16]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6368 "将基本延迟指标添加到调度程序。"
|
||||
[17]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6409 "向 REST 客户端添加延迟指标"
|
||||
[18]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6221 "在 pod 中运行 etcd 2.0.5"
|
||||
[19]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6334 "添加一个 nginx docker 镜像用于主程序。"
|
||||
[20]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6326 "为主组件创建 Docker 镜像"
|
||||
[21]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6270 "gcloud 0.9.54 的更新"
|
||||
|
||||
<!--
|
||||
[22]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6011 "Fix AWS region vs zone"
|
||||
[23]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6091 "Record event when image GC fails."
|
||||
[24]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6203 "Add a QPS limiter to the kubernetes client."
|
||||
[25]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6196 "Parallelize architectures in both the building and packaging phases of `make release`"
|
||||
[26]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5506 "add iscsi volume plugin"
|
||||
[27]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6174 "implement glusterfs volume plugin"
|
||||
[28]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5138 "AWS EBS volume support"
|
||||
[29]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6331 "Update heapster version to v0.10.0"
|
||||
[30]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6544 "Build etcd image (version 2.0.9), and upgrade kubernetes cluster to the new version"
|
||||
[31]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6426 "Update Kibana to v1.2 which paramaterizes location of Elasticsearch"
|
||||
[32]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6123 "Fix bug in kube-proxy of not updating iptables rules if a service's public IPs change"
|
||||
[33]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6200 "Retry kube-addons creation if kube-addons creation fails."
|
||||
[34]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6727 "pkg/proxy: panic if run out of fd"
|
||||
-->
|
||||
[22]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6011 "修复 AWS 区域 与 zone"
|
||||
[23]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6091 "记录镜像 GC 失败时的事件。"
|
||||
[24]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6203 "向 kubernetes 客户端添加 QPS 限制器。"
|
||||
[25]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6196 "在 `make release` 的构建和打包阶段并行化架构"
|
||||
[26]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5506 "添加 iscsi 卷插件"
|
||||
[27]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6174 "实现 glusterfs 卷插件"
|
||||
[28]: https://github.com/GoogleCloudPlatform/kubernetes/pull/5138 "AWS EBS 卷支持"
|
||||
[29]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6331 "将 heapster 版本更新到 v0.10.0"
|
||||
[30]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6544 "构建 etcd 镜像(版本 2.0.9),并将 kubernetes 集群升级到新版本"
|
||||
[31]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6426 "更新 Kibana 到 v1.2,它对 Elasticsearch 的位置进行了参数化"
|
||||
[32]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6123 "修复了 kube-proxy 中的一个错误,如果一个服务的公共 ip 发生变化,它不会更新 iptables 规则"
|
||||
[33]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6200 "如果 kube-addons 创建失败,请重试 kube-addons 创建。"
|
||||
[34]: https://github.com/GoogleCloudPlatform/kubernetes/pull/6727 "pkg/proxy: fd 用完后引起恐慌"
|
||||
|
||||
@@ -0,0 +1,287 @@
|
||||
---
|
||||
title: " Kubernetes 社区每周聚会笔记- 2015年4月17日 "
|
||||
date: 2015-04-17
|
||||
slug: weekly-kubernetes-community-hangout_17
|
||||
url: /blog/2015/04/Weekly-Kubernetes-Community-Hangout_17
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Weekly Kubernetes Community Hangout Notes - April 17 2015 "
|
||||
date: 2015-04-17
|
||||
slug: weekly-kubernetes-community-hangout_17
|
||||
url: /blog/2015/04/Weekly-Kubernetes-Community-Hangout_17
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
Every week the Kubernetes contributing community meet virtually over Google Hangouts. We want anyone who's interested to know what's discussed in this forum.
|
||||
-->
|
||||
每个星期,Kubernetes 贡献者社区几乎都会在谷歌 Hangouts 上聚会。我们希望任何对此感兴趣的人都能了解这个论坛的讨论内容。
|
||||
|
||||
<!--
|
||||
Agenda
|
||||
|
||||
* Mesos Integration
|
||||
* High Availability (HA)
|
||||
* Adding performance and profiling details to e2e to track regressions
|
||||
* Versioned clients
|
||||
|
||||
-->
|
||||
议程
|
||||
|
||||
* Mesos 集成
|
||||
* 高可用性(HA)
|
||||
* 向 e2e 添加性能和分析详细信息以跟踪回归
|
||||
* 客户端版本化
|
||||
|
||||
<!--
|
||||
Notes
|
||||
-->
|
||||
笔记
|
||||
|
||||
<!--
|
||||
|
||||
* Mesos integration
|
||||
|
||||
* Mesos integration proposal:
|
||||
|
||||
* No blockers to integration.
|
||||
|
||||
* Documentation needs to be updated.
|
||||
|
||||
-->
|
||||
|
||||
* Mesos 集成
|
||||
|
||||
* Mesos 集成提案:
|
||||
|
||||
* 没有阻塞集成的因素。
|
||||
|
||||
* 文档需要更新。
|
||||
|
||||
<!--
|
||||
|
||||
* HA
|
||||
|
||||
* Proposal should land today.
|
||||
|
||||
* Etcd cluster.
|
||||
|
||||
* Load-balance apiserver.
|
||||
|
||||
* Cold standby for controller manager and other master components.
|
||||
|
||||
-->
|
||||
|
||||
* HA
|
||||
|
||||
* 提案今天应该会提交。
|
||||
|
||||
* Etcd 集群。
|
||||
|
||||
* apiserver 负载均衡。
|
||||
|
||||
* 控制器管理器和其他主组件的冷备用。
|
||||
|
||||
<!--
|
||||
|
||||
* Adding performance and profiling details to e2e to track regression
|
||||
|
||||
* Want red light for performance regression
|
||||
|
||||
* Need a public DB to post the data
|
||||
|
||||
* See
|
||||
|
||||
* Justin working on multi-platform e2e dashboard
|
||||
|
||||
-->
|
||||
|
||||
* 向 e2e 添加性能和分析详细信息以跟踪回归
|
||||
|
||||
* 希望红色为性能回归
|
||||
|
||||
* 需要公共数据库才能发布数据
|
||||
|
||||
* 查看
|
||||
|
||||
* Justin 致力于多平台 e2e 仪表盘
|
||||
|
||||
<!--
|
||||
|
||||
* Versioned clients
|
||||
|
||||
*
|
||||
|
||||
*
|
||||
|
||||
* Client library currently uses internal API objects.
|
||||
|
||||
* Nobody reported that frequent changes to types.go have been painful, but we are worried about it.
|
||||
|
||||
* Structured types are useful in the client. Versioned structs would be ok.
|
||||
|
||||
* If start with json/yaml (kubectl), shouldn’t convert to structured types. Use swagger.
|
||||
|
||||
-->
|
||||
|
||||
* 客户端版本化
|
||||
|
||||
*
|
||||
|
||||
*
|
||||
|
||||
* 客户端库当前使用内部 API 对象。
|
||||
|
||||
* 尽管没有人反映频繁修改 `types.go` 有多痛苦,但我们很为此担心。
|
||||
|
||||
* 结构化类型在客户端中很有用。版本化的结构就可以了。
|
||||
|
||||
* 如果从 json/yaml (kubectl) 开始,则不应转换为结构化类型。使用 swagger。
|
||||
|
||||
<!--
|
||||
|
||||
* Security context
|
||||
|
||||
*
|
||||
|
||||
* Administrators can restrict who can run privileged containers or require specific unix uids
|
||||
|
||||
* Kubelet will be able to get pull credentials from apiserver
|
||||
|
||||
* Policy proposal coming in the next week or so
|
||||
-->
|
||||
|
||||
* Security context
|
||||
|
||||
*
|
||||
|
||||
* 管理员可以限制谁可以运行特权容器或需要特定的 unix uid
|
||||
|
||||
* kubelet 将能够从 apiserver 获取证书
|
||||
|
||||
* 政策提案将于下周左右出台
|
||||
|
||||
<!--
|
||||
|
||||
* Discussing upstreaming of users, etc. into Kubernetes, at least as optional
|
||||
* 1.0 Roadmap
|
||||
|
||||
* Focus is performance, stability, cluster upgrades
|
||||
|
||||
* TJ has been making some edits to [roadmap.md][4] but hasn’t sent out a PR yet
|
||||
* Kubernetes UI
|
||||
|
||||
* Dependencies broken out into third-party
|
||||
|
||||
* @lavalamp is reviewer
|
||||
|
||||
-->
|
||||
|
||||
* 讨论用户的上游,等等进入Kubernetes,至少是可选的
|
||||
* 1.0 路线图
|
||||
|
||||
* 重点是性能,稳定性,集群升级
|
||||
|
||||
* TJ 一直在对[roadmap.md][4]进行一些编辑,但尚未发布PR
|
||||
* Kubernetes UI
|
||||
|
||||
* 依赖关系分解为第三方
|
||||
|
||||
* @lavalamp 是评论家
|
||||
|
||||
|
||||
[1]: http://kubernetes.io/images/nav_logo.svg
|
||||
[2]: http://kubernetes.io/docs/
|
||||
[3]: https://kubernetes.io/blog/
|
||||
[4]: https://github.com/GoogleCloudPlatform/kubernetes/blob/master/docs/roadmap.md
|
||||
[5]: https://kubernetes.io/blog/2015/04/weekly-kubernetes-community-hangout_17 "permanent link"
|
||||
[6]: https://resources.blogblog.com/img/icon18_edit_allbkg.gif
|
||||
[7]: https://www.blogger.com/post-edit.g?blogID=112706738355446097&postID=630924463010638300&from=pencil "Edit Post"
|
||||
[8]: https://www.blogger.com/share-post.g?blogID=112706738355446097&postID=630924463010638300&target=email "Email This"
|
||||
[9]: https://www.blogger.com/share-post.g?blogID=112706738355446097&postID=630924463010638300&target=blog "BlogThis!"
|
||||
[10]: https://www.blogger.com/share-post.g?blogID=112706738355446097&postID=630924463010638300&target=twitter "Share to Twitter"
|
||||
[11]: https://www.blogger.com/share-post.g?blogID=112706738355446097&postID=630924463010638300&target=facebook "Share to Facebook"
|
||||
[12]: https://www.blogger.com/share-post.g?blogID=112706738355446097&postID=630924463010638300&target=pinterest "Share to Pinterest"
|
||||
[13]: https://kubernetes.io/blog/search/label/community%20meetings
|
||||
[14]: https://kubernetes.io/blog/search/label/containers
|
||||
[15]: https://kubernetes.io/blog/search/label/docker
|
||||
[16]: https://kubernetes.io/blog/search/label/k8s
|
||||
[17]: https://kubernetes.io/blog/search/label/kubernetes
|
||||
[18]: https://kubernetes.io/blog/search/label/open%20source
|
||||
[19]: https://kubernetes.io/blog/2015/04/kubernetes-and-mesosphere-dcos "Newer Post"
|
||||
[20]: https://kubernetes.io/blog/2015/04/introducing-kubernetes-v1beta3 "Older Post"
|
||||
[21]: https://kubernetes.io/blog/feeds/630924463010638300/comments/default
|
||||
[22]: https://img2.blogblog.com/img/widgets/arrow_dropdown.gif
|
||||
[23]: https://img1.blogblog.com/img/icon_feed12.png
|
||||
[24]: https://img1.blogblog.com/img/widgets/subscribe-netvibes.png
|
||||
[25]: https://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fblog.kubernetes.io%2Ffeeds%2Fposts%2Fdefault
|
||||
[26]: https://img1.blogblog.com/img/widgets/subscribe-yahoo.png
|
||||
[27]: https://add.my.yahoo.com/content?url=http%3A%2F%2Fblog.kubernetes.io%2Ffeeds%2Fposts%2Fdefault
|
||||
[28]: https://kubernetes.io/blog/feeds/posts/default
|
||||
[29]: https://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fblog.kubernetes.io%2Ffeeds%2F630924463010638300%2Fcomments%2Fdefault
|
||||
[30]: https://add.my.yahoo.com/content?url=http%3A%2F%2Fblog.kubernetes.io%2Ffeeds%2F630924463010638300%2Fcomments%2Fdefault
|
||||
[31]: https://resources.blogblog.com/img/icon18_wrench_allbkg.png
|
||||
[32]: //www.blogger.com/rearrange?blogID=112706738355446097&widgetType=Subscribe&widgetId=Subscribe1&action=editWidget§ionId=sidebar-right-1 "Edit"
|
||||
[33]: https://twitter.com/kubernetesio
|
||||
[34]: https://github.com/kubernetes/kubernetes
|
||||
[35]: http://slack.k8s.io/
|
||||
[36]: http://stackoverflow.com/questions/tagged/kubernetes
|
||||
[37]: http://get.k8s.io/
|
||||
[38]: //www.blogger.com/rearrange?blogID=112706738355446097&widgetType=HTML&widgetId=HTML2&action=editWidget§ionId=sidebar-right-1 "Edit"
|
||||
[39]: javascript:void(0)
|
||||
[40]: https://kubernetes.io/blog/2018/
|
||||
[41]: https://kubernetes.io/blog/2018/01/
|
||||
[42]: https://kubernetes.io/blog/2017/
|
||||
[43]: https://kubernetes.io/blog/2017/12/
|
||||
[44]: https://kubernetes.io/blog/2017/11/
|
||||
[45]: https://kubernetes.io/blog/2017/10/
|
||||
[46]: https://kubernetes.io/blog/2017/09/
|
||||
[47]: https://kubernetes.io/blog/2017/08/
|
||||
[48]: https://kubernetes.io/blog/2017/07/
|
||||
[49]: https://kubernetes.io/blog/2017/06/
|
||||
[50]: https://kubernetes.io/blog/2017/05/
|
||||
[51]: https://kubernetes.io/blog/2017/04/
|
||||
[52]: https://kubernetes.io/blog/2017/03/
|
||||
[53]: https://kubernetes.io/blog/2017/02/
|
||||
[54]: https://kubernetes.io/blog/2017/01/
|
||||
[55]: https://kubernetes.io/blog/2016/
|
||||
[56]: https://kubernetes.io/blog/2016/12/
|
||||
[57]: https://kubernetes.io/blog/2016/11/
|
||||
[58]: https://kubernetes.io/blog/2016/10/
|
||||
[59]: https://kubernetes.io/blog/2016/09/
|
||||
[60]: https://kubernetes.io/blog/2016/08/
|
||||
[61]: https://kubernetes.io/blog/2016/07/
|
||||
[62]: https://kubernetes.io/blog/2016/06/
|
||||
[63]: https://kubernetes.io/blog/2016/05/
|
||||
[64]: https://kubernetes.io/blog/2016/04/
|
||||
[65]: https://kubernetes.io/blog/2016/03/
|
||||
[66]: https://kubernetes.io/blog/2016/02/
|
||||
[67]: https://kubernetes.io/blog/2016/01/
|
||||
[68]: https://kubernetes.io/blog/2015/
|
||||
[69]: https://kubernetes.io/blog/2015/12/
|
||||
[70]: https://kubernetes.io/blog/2015/11/
|
||||
[71]: https://kubernetes.io/blog/2015/10/
|
||||
[72]: https://kubernetes.io/blog/2015/09/
|
||||
[73]: https://kubernetes.io/blog/2015/08/
|
||||
[74]: https://kubernetes.io/blog/2015/07/
|
||||
[75]: https://kubernetes.io/blog/2015/06/
|
||||
[76]: https://kubernetes.io/blog/2015/05/
|
||||
[77]: https://kubernetes.io/blog/2015/04/
|
||||
[78]: https://kubernetes.io/blog/2015/04/weekly-kubernetes-community-hangout_29
|
||||
[79]: https://kubernetes.io/blog/2015/04/borg-predecessor-to-kubernetes
|
||||
[80]: https://kubernetes.io/blog/2015/04/kubernetes-and-mesosphere-dcos
|
||||
[81]: https://kubernetes.io/blog/2015/04/weekly-kubernetes-community-hangout_17
|
||||
[82]: https://kubernetes.io/blog/2015/04/introducing-kubernetes-v1beta3
|
||||
[83]: https://kubernetes.io/blog/2015/04/kubernetes-release-0150
|
||||
[84]: https://kubernetes.io/blog/2015/04/weekly-kubernetes-community-hangout_11
|
||||
[85]: https://kubernetes.io/blog/2015/04/faster-than-speeding-latte
|
||||
[86]: https://kubernetes.io/blog/2015/04/weekly-kubernetes-community-hangout
|
||||
[87]: https://kubernetes.io/blog/2015/03/
|
||||
[88]: //www.blogger.com/rearrange?blogID=112706738355446097&widgetType=BlogArchive&widgetId=BlogArchive1&action=editWidget§ionId=sidebar-right-1 "Edit"
|
||||
[89]: //www.blogger.com/rearrange?blogID=112706738355446097&widgetType=HTML&widgetId=HTML1&action=editWidget§ionId=sidebar-right-1 "Edit"
|
||||
[90]: https://www.blogger.com
|
||||
[91]: //www.blogger.com/rearrange?blogID=112706738355446097&widgetType=Attribution&widgetId=Attribution1&action=editWidget§ionId=footer-3 "Edit"
|
||||
|
||||
[*[3:27 PM]: 2015-04-17T15:27:00-07:00
|
||||
@@ -0,0 +1,143 @@
|
||||
---
|
||||
title: " Kubernetes 社区每周聚会笔记- 2015年4月24日 "
|
||||
date: 2015-04-30
|
||||
slug: weekly-kubernetes-community-hangout_29
|
||||
url: /blog/2015/04/Weekly-Kubernetes-Community-Hangout_29
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Weekly Kubernetes Community Hangout Notes - April 24 2015 "
|
||||
date: 2015-04-30
|
||||
slug: weekly-kubernetes-community-hangout_29
|
||||
url: /blog/2015/04/Weekly-Kubernetes-Community-Hangout_29
|
||||
---
|
||||
|
||||
-->
|
||||
|
||||
<!--
|
||||
Every week the Kubernetes contributing community meet virtually over Google Hangouts. We want anyone who's interested to know what's discussed in this forum.
|
||||
-->
|
||||
每个星期,Kubernetes 贡献者社区几乎都会在谷歌 Hangouts 上聚会。我们希望任何对此感兴趣的人都能了解这个论坛的讨论内容。
|
||||
|
||||
<!--
|
||||
Agenda:
|
||||
|
||||
* Flocker and Kubernetes integration demo
|
||||
|
||||
-->
|
||||
日程安排:
|
||||
|
||||
* Flocker 和 Kubernetes 集成演示
|
||||
|
||||
<!--
|
||||
Notes:
|
||||
|
||||
* flocker and kubernetes integration demo
|
||||
* * Flocker Q/A
|
||||
|
||||
* Does the file still exists on node1 after migration?
|
||||
|
||||
* Brendan: Any plan this to make it a volume? So we don't need powerstrip?
|
||||
|
||||
* Luke: Need to figure out interest to decide if we want to make it a first-class persistent disk provider in kube.
|
||||
|
||||
* Brendan: Removing need for powerstrip would make it simple to use. Totally go for it.
|
||||
|
||||
* Tim: Should take no more than 45 minutes to add it to kubernetes:)
|
||||
|
||||
-->
|
||||
笔记:
|
||||
|
||||
* flocker 和 kubernetes 集成演示
|
||||
* * Flocker Q/A
|
||||
|
||||
* 迁移后文件是否仍存在于node1上?
|
||||
|
||||
* Brendan: 有没有计划把它做成一本书?我们不需要 powerstrip?
|
||||
|
||||
* Luke: 需要找出感兴趣的来决定我们是否想让它成为 kube 中的一个一流的持久性磁盘提供商。
|
||||
|
||||
* Brendan: 删除对 powerstrip 的需求会使其易于使用。完全去做。
|
||||
|
||||
* Tim: 将它添加到 kubernetes 应该不超过45分钟:)
|
||||
|
||||
<!--
|
||||
|
||||
* Derek: Contrast this with persistent volumes and claims?
|
||||
|
||||
* Luke: Not much difference, except for the novel ZFS based backend. Makes workloads really portable.
|
||||
|
||||
* Tim: very different than network-based volumes. Its interesting that it is the only offering that allows upgrading media.
|
||||
|
||||
* Brendan: claims, how does it look for replicated claims? eg Cassandra wants to have replicated data underneath. It would be efficient to scale up and down. Create storage on the fly based on load dynamically. Its step beyond taking snapshots - programmatically creating replicas with preallocation.
|
||||
|
||||
* Tim: helps with auto-provisioning.
|
||||
|
||||
-->
|
||||
|
||||
* Derek: 持久卷和请求相比呢?
|
||||
|
||||
* Luke: 除了基于 ZFS 的新后端之外,差别不大。使工作负载真正可移植。
|
||||
|
||||
* Tim: 与基于网络的卷非常不同。有趣的是,它是唯一允许升级媒体的产品。
|
||||
|
||||
* Brendan: 请求,它如何查找重复请求?Cassandra 希望在底层复制数据。向上和向下扩缩是有效的。根据负载动态地创建存储。它的步骤不仅仅是快照——通过编程使用预分配创建副本。
|
||||
|
||||
* Tim: 帮助自动配置。
|
||||
|
||||
<!--
|
||||
|
||||
* Brian: Does flocker requires any other component?
|
||||
|
||||
* Kai: Flocker control service co-located with the master. (dia on blog post). Powerstrip + Powerstrip Flocker. Very interested in mpersisting state in etcd. It keeps metadata about each volume.
|
||||
|
||||
* Brendan: In future, flocker can be a plugin and we'll take care of persistence. Post v1.0.
|
||||
|
||||
* Brian: Interested in adding generic plugin for services like flocker.
|
||||
|
||||
* Luke: Zfs can become really valuable when scaling to lot of containers on a single node.
|
||||
|
||||
-->
|
||||
|
||||
* Brian: flocker 是否需要其他组件?
|
||||
|
||||
* Kai: Flocker 控制服务与主服务器位于同一位置。(dia 在博客上)。Powerstrip + Powerstrip Flocker。对在 etcd 中持久化状态非常有趣。它保存关于每个卷的元数据。
|
||||
|
||||
* Brendan: 在未来,flocker 可以是一个插件,我们将负责持久性。发布 v1.0。
|
||||
|
||||
* Brian: 有兴趣为 flocker 等服务添加通用插件。
|
||||
|
||||
* Luke: 当扩展到单个节点上的许多容器时,Zfs 会变得非常有价值。
|
||||
|
||||
<!--
|
||||
|
||||
* Alex: Can flocker service can be run as a pod?
|
||||
|
||||
* Kai: Yes, only requirement is the flocker control service should be able to talk to zfs agent. zfs agent needs to be installed on the host and zfs binaries need to be accessible.
|
||||
|
||||
* Brendan: In theory, all zfs bits can be put it into a container with devices.
|
||||
|
||||
* Luke: Yes, still working through cross-container mounting issue.
|
||||
|
||||
* Tim: pmorie is working through it to make kubelet work in a container. Possible re-use.
|
||||
|
||||
* Kai: Cinder support is coming. Few days away.
|
||||
* Bob: What's the process of pushing kube to GKE? Need more visibility for confidence.
|
||||
|
||||
-->
|
||||
|
||||
* Alex: flocker 服务可以作为 pod 运行吗?
|
||||
|
||||
* Kai: 是的,唯一的要求是 flocker 控制服务应该能够与 zfs 代理对话。需要在主机上安装 zfs 代理,并且需要访问 zfs 二进制文件。
|
||||
|
||||
* Brendan: 从理论上讲,所有 zfs 位都可以与设备一起放入容器中。
|
||||
|
||||
* Luke: 是的,仍然在处理跨容器安装问题。
|
||||
|
||||
* Tim: pmorie 正在通过它使 kubelet 在容器中工作。可能重复使用。
|
||||
|
||||
* Kai: Cinder 支持即将到来。几天之后。
|
||||
* Bob: 向 GKE 推送 kube 的过程是怎样的?需要更多的可见度。
|
||||
|
||||
|
||||
@@ -0,0 +1,112 @@
|
||||
---
|
||||
title: " OpenStack 上的 Kubernetes "
|
||||
date: 2015-05-19
|
||||
slug: kubernetes-on-openstack
|
||||
url: /blog/2015/05/Kubernetes-On-Openstack
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Kubernetes on OpenStack "
|
||||
date: 2015-05-19
|
||||
slug: kubernetes-on-openstack
|
||||
url: /blog/2015/05/Kubernetes-On-Openstack
|
||||
---
|
||||
-->
|
||||
|
||||
[](https://3.bp.blogspot.com/-EOrCHChZJZE/VVZzq43g6CI/AAAAAAAAF-E/JUilRHk369E/s1600/Untitled%2Bdrawing.jpg)
|
||||
|
||||
|
||||
<!--
|
||||
Today, the [OpenStack foundation](https://www.openstack.org/foundation/) made it even easier for you deploy and manage clusters of Docker containers on OpenStack clouds by including Kubernetes in its [Community App Catalog](http://apps.openstack.org/). At a keynote today at the OpenStack Summit in Vancouver, Mark Collier, COO of the OpenStack Foundation, and Craig Peters, [Mirantis](https://www.mirantis.com/) product line manager, demonstrated the Community App Catalog workflow by launching a Kubernetes cluster in a matter of seconds by leveraging the compute, storage, networking and identity systems already present in an OpenStack cloud.
|
||||
-->
|
||||
今天,[OpenStack 基金会](https://www.openstack.org/foundation/)通过在其[社区应用程序目录](http://apps.openstack.org/)中包含 Kubernetes,使您更容易在 OpenStack 云上部署和管理 Docker 容器集群。
|
||||
今天在温哥华 OpenStack 峰会上的主题演讲中,OpenStack 基金会的首席运营官:Mark Collier 和 [Mirantis](https://www.mirantis.com/) 产品线经理 Craig Peters 通过利用 OpenStack 云中已经存在的计算、存储、网络和标识系统,在几秒钟内启动了 Kubernetes 集群,展示了社区应用程序目录的工作流。
|
||||
|
||||
<!--
|
||||
The entries in the catalog include not just the ability to [start a Kubernetes cluster](http://apps.openstack.org/#tab=murano-apps&asset=Kubernetes%20Cluster), but also a range of applications deployed in Docker containers managed by Kubernetes. These applications include:
|
||||
-->
|
||||
目录中的条目不仅包括[启动 Kubernetes 集群](http://apps.openstack.org/#tab=murano-apps&asset=Kubernetes%20Cluster)的功能,还包括部署在 Kubernetes 管理的 Docker 容器中的一系列应用程序。这些应用包括:
|
||||
|
||||
<!--
|
||||
|
||||
-
|
||||
Apache web server
|
||||
-
|
||||
Nginx web server
|
||||
-
|
||||
Crate - The Distributed Database for Docker
|
||||
-
|
||||
GlassFish - Java EE 7 Application Server
|
||||
-
|
||||
Tomcat - An open-source web server and servlet container
|
||||
-
|
||||
InfluxDB - An open-source, distributed, time series database
|
||||
-
|
||||
Grafana - Metrics dashboard for InfluxDB
|
||||
-
|
||||
Jenkins - An extensible open source continuous integration server
|
||||
-
|
||||
MariaDB database
|
||||
-
|
||||
MySql database
|
||||
-
|
||||
Redis - Key-value cache and store
|
||||
-
|
||||
PostgreSQL database
|
||||
-
|
||||
MongoDB NoSQL database
|
||||
-
|
||||
Zend Server - The Complete PHP Application Platform
|
||||
|
||||
-->
|
||||
|
||||
|
||||
-
|
||||
Apache web 服务器
|
||||
-
|
||||
Nginx web 服务器
|
||||
-
|
||||
Crate - Docker的分布式数据库
|
||||
-
|
||||
GlassFish - Java EE 7 应用服务器
|
||||
-
|
||||
Tomcat - 一个开源的 web 服务器和 servlet 容器
|
||||
-
|
||||
InfluxDB - 一个开源的、分布式的、时间序列数据库
|
||||
-
|
||||
Grafana - InfluxDB 的度量仪表板
|
||||
-
|
||||
Jenkins - 一个可扩展的开放源码持续集成服务器
|
||||
-
|
||||
MariaDB 数据库
|
||||
-
|
||||
MySql 数据库
|
||||
-
|
||||
Redis - 键-值缓存和存储
|
||||
-
|
||||
PostgreSQL 数据库
|
||||
-
|
||||
MongoDB NoSQL 数据库
|
||||
-
|
||||
Zend 服务器 - 完整的 PHP 应用程序平台
|
||||
|
||||
<!--
|
||||
This list will grow, and is curated [here](https://github.com/openstack/murano-apps/tree/master/Docker/Kubernetes). You can examine (and contribute to) the YAML file that tells Murano how to install and start the Kubernetes cluster [here](https://github.com/openstack/murano-apps/blob/master/Docker/Kubernetes/KubernetesCluster/package/Classes/KubernetesCluster.yaml).
|
||||
-->
|
||||
此列表将会增长,并在[此处](https://github.com/openstack/murano-apps/tree/master/Docker/Kubernetes)进行策划。您可以检查(并参与)YAML 文件,该文件告诉 Murano 如何根据[此处](https://github.com/openstack/murano-apps/blob/master/Docker/Kubernetes/KubernetesCluster/package/Classes/KubernetesCluster.yaml)定义来安装和启动 ...apps/blob/master/Docker/Kubernetes/KubernetesCluster/package/Classes/KubernetesCluster.yaml)安装和启动 Kubernetes 集群。
|
||||
|
||||
<!--
|
||||
[The Kubernetes open source project](https://github.com/GoogleCloudPlatform/kubernetes) has continued to see fantastic community adoption and increasing momentum, with over 11,000 commits and 7,648 stars on GitHub. With supporters ranging from Red Hat and Intel to CoreOS and Box.net, it has come to represent a range of customer interests ranging from enterprise IT to cutting edge startups. We encourage you to give it a try, give us your feedback, and get involved in our growing community.
|
||||
-->
|
||||
[Kubernetes 开源项目](https://github.com/GoogleCloudPlatform/kubernetes)继续受到社区的欢迎,并且势头越来越好,GitHub 上有超过 11000 个提交和 7648 颗星。从 Red Hat 和 Intel 到 CoreOS 和 Box.net,它已经代表了从企业 IT 到前沿创业企业的一系列客户。我们鼓励您尝试一下,给我们您的反馈,并参与到我们不断增长的社区中来。
|
||||
|
||||
|
||||
<!--
|
||||
|
||||
- Martin Buhr, Product Manager, Kubernetes Open Source Project
|
||||
|
||||
-->
|
||||
|
||||
- Martin Buhr, Kubernetes 开源项目产品经理
|
||||
|
||||
@@ -0,0 +1,121 @@
|
||||
---
|
||||
title: " Kubernetes 社区每周聚会笔记- 2015年5月1日 "
|
||||
date: 2015-05-11
|
||||
slug: weekly-kubernetes-community-hangout
|
||||
url: /blog/2015/05/Weekly-Kubernetes-Community-Hangout
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Weekly Kubernetes Community Hangout Notes - May 1 2015 "
|
||||
date: 2015-05-11
|
||||
slug: weekly-kubernetes-community-hangout
|
||||
url: /blog/2015/05/Weekly-Kubernetes-Community-Hangout
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
Every week the Kubernetes contributing community meet virtually over Google Hangouts. We want anyone who's interested to know what's discussed in this forum.
|
||||
-->
|
||||
每个星期,Kubernetes 贡献者社区几乎都会在谷歌 Hangouts 上聚会。我们希望任何对此感兴趣的人都能了解这个论坛的讨论内容。
|
||||
|
||||
<!--
|
||||
|
||||
* Simple rolling update - Brendan
|
||||
|
||||
* Rolling update = nice example of why RCs and Pods are good.
|
||||
|
||||
* ...pause… (Brendan needs demo recovery tips from Kelsey)
|
||||
|
||||
* Rolling update has recovery: Cancel update and restart, update continues from where it stopped.
|
||||
|
||||
* New controller gets name of old controller, so appearance is pure update.
|
||||
|
||||
* Can also name versions in update (won't do rename at the end).
|
||||
|
||||
-->
|
||||
|
||||
* 简单的滚动更新 - Brendan
|
||||
|
||||
* 滚动更新 = RCs和Pods很好的例子。
|
||||
|
||||
* ...pause… (Brendan 需要 Kelsey 的演示恢复技巧)
|
||||
|
||||
* 滚动更新具有恢复功能:取消更新并重新启动,更新从停止的地方继续。
|
||||
|
||||
* 新控制器获取旧控制器的名称,因此外观是纯粹的更新。
|
||||
|
||||
* 还可以在 update 中命名版本(最后不会重命名)。
|
||||
|
||||
<!--
|
||||
|
||||
* Rocket demo - CoreOS folks
|
||||
|
||||
* 2 major differences between rocket & docker: Rocket is daemonless & pod-centric.
|
||||
|
||||
* Rocket has AppContainer format as native, but also supports docker image format.
|
||||
|
||||
* Can run AppContainer and docker containers in same pod.
|
||||
|
||||
* Changes are close to merged.
|
||||
|
||||
-->
|
||||
|
||||
* Rocket 演示 - CoreOS 的伙计们
|
||||
|
||||
* Rocket 和 docker 之间的主要区别: Rocket 是无守护进程和以 pod 为中心。。
|
||||
|
||||
* Rocket 具有原生的 AppContainer 格式,但也支持 docker 镜像格式。
|
||||
|
||||
* 可以在同一个 pod 中运行 AppContainer 和 docker 容器。
|
||||
|
||||
* 变更接近于合并。
|
||||
|
||||
<!--
|
||||
|
||||
* demo service accounts and secrets being added to pods - Jordan
|
||||
|
||||
* Problem: It's hard to get a token to talk to the API.
|
||||
|
||||
* New API object: "ServiceAccount"
|
||||
|
||||
* ServiceAccount is namespaced, controller makes sure that at least 1 default service account exists in a namespace.
|
||||
|
||||
* Typed secret "ServiceAccountToken", controller makes sure there is at least 1 default token.
|
||||
|
||||
* DEMO
|
||||
|
||||
* * Can create new service account with ServiceAccountToken. Controller will create token for it.
|
||||
|
||||
* Can create a pod with service account, pods will have service account secret mounted at /var/run/secrets/kubernetes.io/…
|
||||
|
||||
-->
|
||||
|
||||
* 演示 service accounts 和 secrets 被添加到 pod - Jordan
|
||||
|
||||
* 问题:很难获得与API通信的令牌。
|
||||
|
||||
* 新的API对象:"ServiceAccount"
|
||||
|
||||
* ServiceAccount 是命名空间,控制器确保命名空间中至少存在一个个默认 service account。
|
||||
|
||||
* 键入 "ServiceAccountToken",控制器确保至少有一个默认令牌。
|
||||
|
||||
* 演示
|
||||
|
||||
* * 可以使用 ServiceAccountToken 创建新的 service account。控制器将为它创建令牌。
|
||||
|
||||
* 可以创建一个带有 service account 的 pod, pod 将在 /var/run/secrets/kubernets.io/…
|
||||
|
||||
<!--
|
||||
|
||||
* Kubelet running in a container - Paul
|
||||
|
||||
* Kubelet successfully ran pod w/ mounted secret.
|
||||
|
||||
-->
|
||||
|
||||
* Kubelet 在容器中运行 - Paul
|
||||
|
||||
* Kubelet 成功地运行了带有 secret 的 pod。
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
---
|
||||
title: "幻灯片:Kubernetes 集群管理,爱丁堡大学演讲"
|
||||
date: 2015-06-26
|
||||
slug: slides-cluster-management-with
|
||||
url: /blog/2015/06/Slides-Cluster-Management-With
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Slides: Cluster Management with Kubernetes, talk given at the University of Edinburgh "
|
||||
date: 2015-06-26
|
||||
slug: slides-cluster-management-with
|
||||
url: /blog/2015/06/Slides-Cluster-Management-With
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
On Friday 5 June 2015 I gave a talk called [Cluster Management with Kubernetes](https://docs.google.com/presentation/d/1H4ywDb4vAJeg8KEjpYfhNqFSig0Q8e_X5I36kM9S6q0/pub?start=false&loop=false&delayms=3000) to a general audience at the University of Edinburgh. The talk includes an example of a music store system with a Kibana front end UI and an Elasticsearch based back end which helps to make concrete concepts like pods, replication controllers and services.
|
||||
|
||||
[Cluster Management with Kubernetes](https://docs.google.com/presentation/d/1H4ywDb4vAJeg8KEjpYfhNqFSig0Q8e_X5I36kM9S6q0/pub?start=false&loop=false&delayms=3000).
|
||||
-->
|
||||
|
||||
2015年6月5日星期五,我在爱丁堡大学给普通听众做了一个演讲,题目是[使用 Kubernetes 进行集群管理](https://docs.google.com/presentation/d/1H4ywDb4vAJeg8KEjpYfhNqFSig0Q8e_X5I36kM9S6q0/pub?start=false&loop=false&delayms=3000)。这次演讲包括一个带有 Kibana 前端 UI 的音乐存储系统的例子,以及一个基于 Elasticsearch 的后端,该后端有助于生成具体的概念,如 pods、复制控制器和服务。
|
||||
|
||||
[Kubernetes 集群管理](https://docs.google.com/presentation/d/1H4ywDb4vAJeg8KEjpYfhNqFSig0Q8e_X5I36kM9S6q0/pub?start=false&loop=false&delayms=3000)。
|
||||
@@ -0,0 +1,24 @@
|
||||
---
|
||||
title: "宣布首个Kubernetes企业培训课程 "
|
||||
date: 2015-07-08
|
||||
slug: announcing-first-kubernetes-enterprise
|
||||
url: /blog/2015/07/Announcing-First-Kubernetes-Enterprise
|
||||
---
|
||||
<!-- ---
|
||||
title: " Announcing the First Kubernetes Enterprise Training Course "
|
||||
date: 2015-07-08
|
||||
slug: announcing-first-kubernetes-enterprise
|
||||
url: /blog/2015/07/Announcing-First-Kubernetes-Enterprise
|
||||
--- -->
|
||||
|
||||
<!-- At Google we rely on Linux application containers to run our core infrastructure. Everything from Search to Gmail runs in containers. In fact, we like containers so much that even our Google Compute Engine VMs run in containers! Because containers are critical to our business, we have been working with the community on many of the basic container technologies (from cgroups to Docker’s LibContainer) and even decided to build the next generation of Google’s container scheduling technology, Kubernetes, in the open. -->
|
||||
在谷歌,我们依赖 Linux 容器应用程序去运行我们的核心基础架构。所有服务,从搜索引擎到Gmail服务,都运行在容器中。事实上,我们非常喜欢容器,甚至我们的谷歌云计算引擎虚拟机也运行在容器上!由于容器对于我们的业务至关重要,我们已经与社区合作开发许多基本的容器技术(从 cgroups 到 Docker 的 LibContainer),甚至决定去构建谷歌的下一代开源容器调度技术,Kubernetes。
|
||||
|
||||
<!-- One year into the Kubernetes project, and on the eve of our planned V1 release at OSCON, we are pleased to announce the first-ever formal Kubernetes enterprise-focused training session organized by a key Kubernetes contributor, Mesosphere. The inaugural session will be taught by Zed Shaw and Michael Hausenblas from Mesosphere, and will take place on July 20 at OSCON in Portland. [Pre-registration](https://mesosphere.com/training/kubernetes/) is free for early registrants, but space is limited so act soon! -->
|
||||
在 Kubernetes 项目进行一年后,在 OSCON 上发布 V1 版本的前夕,我们很高兴的宣布Kubernetes 的主要贡献者 Mesosphere 组织了有史以来第一次正规的以企业为中心的 Kubernetes 培训会议。首届会议将于 6 月 20 日在波特兰的 OSCON 举办,由来自 Mesosphere 的 Zed Shaw 和 Michael Hausenblas 演讲。[Pre-registration](https://mesosphere.com/training/kubernetes/) 对于优先注册者是免费的,但名额有限,立刻行动吧!
|
||||
|
||||
<!-- This one-day course will cover the basics of building and deploying containerized applications using Kubernetes. It will walk attendees through the end-to-end process of creating a Kubernetes application architecture, building and configuring Docker images, and deploying them on a Kubernetes cluster. Users will also learn the fundamentals of deploying Kubernetes applications and services on our Google Container Engine and Mesosphere’s Datacenter Operating System. -->
|
||||
这个为期一天的课程将包涵使用 Kubernetes 构建和部署容器化应用程序的基础知识。它将通过完整的流程引导与参会者创建一个 Kubernetes 的应用程序体系结构,创建和配置 Docker 镜像,并把它们部署到 Kubernetes 集群上。用户还将了解在我们的谷歌容器引擎和 Mesosphere 的数据中心操作系统上部署 Kubernetes 应用程序和服务的基础知识。
|
||||
|
||||
<!-- The upcoming Kubernetes bootcamp will be a great way to learn how to apply Kubernetes to solve long-standing deployment and application management problems. This is just the first of what we hope are many, and from a broad set of contributors. -->
|
||||
即将推出的 Kubernetes bootcamp 将是学习如何应用 Kubernetes 解决长期部署和应用程序管理问题的一个好途径。相对于我们所预期的,来自于广泛社区的众多培训项目而言,这只是其中一个。
|
||||
+164
@@ -0,0 +1,164 @@
|
||||
---
|
||||
title: " 使用 Puppet 管理 Kubernetes Pods,Services 和 Replication Controllers "
|
||||
date: 2015-12-17
|
||||
slug: managing-kubernetes-pods-services-and-replication-controllers-with-puppet
|
||||
url: /blog/2015/12/Managing-Kubernetes-Pods-Services-And-Replication-Controllers-With-Puppet
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Managing Kubernetes Pods, Services and Replication Controllers with Puppet "
|
||||
date: 2015-12-17
|
||||
slug: managing-kubernetes-pods-services-and-replication-controllers-with-puppet
|
||||
url: /blog/2015/12/Managing-Kubernetes-Pods-Services-And-Replication-Controllers-With-Puppet
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
_Today’s guest post is written by Gareth Rushgrove, Senior Software Engineer at Puppet Labs, a leader in IT automation. Gareth tells us about a new Puppet module that helps manage resources in Kubernetes. _
|
||||
|
||||
People familiar with [Puppet](https://github.com/puppetlabs/puppet) might have used it for managing files, packages and users on host computers. But Puppet is first and foremost a configuration management tool, and config management is a much broader discipline than just managing host-level resources. A good definition of configuration management is that it aims to solve four related problems: identification, control, status accounting and verification and audit. These problems exist in the operation of any complex system, and with the new [Puppet Kubernetes module](https://forge.puppetlabs.com/garethr/kubernetes) we’re starting to look at how we can solve those problems for Kubernetes.
|
||||
-->
|
||||
|
||||
_今天的嘉宾帖子是由 IT 自动化领域的领导者 Puppet Labs 的高级软件工程师 Gareth Rushgrove 撰写的。Gareth告诉我们一个新的 Puppet 模块,它帮助管理 Kubernetes 中的资源。_
|
||||
|
||||
熟悉[Puppet]的人(https://github.com/puppetlabs/puppet)可能使用它来管理主机上的文件、包和用户。但是Puppet首先是一个配置管理工具,配置管理是一个比管理主机级资源更广泛的规程。配置管理的一个很好的定义是它旨在解决四个相关的问题:标识、控制、状态核算和验证审计。这些问题存在于任何复杂系统的操作中,并且有了新的[Puppet Kubernetes module](https://forge.puppetlabs.com/garethr/kubernetes),我们开始研究如何为 Kubernetes 解决这些问题。
|
||||
|
||||
<!--
|
||||
### The Puppet Kubernetes Module
|
||||
|
||||
The Puppet Kubernetes module currently assumes you already have a Kubernetes cluster [up and running](http://kubernetes.io/gettingstarted/). Its focus is on managing the resources in Kubernetes, like Pods, Replication Controllers and Services, not (yet) on managing the underlying kubelet or etcd services. Here’s a quick snippet of code describing a Pod in Puppet’s DSL.
|
||||
-->
|
||||
|
||||
### Puppet Kubernetes 模块
|
||||
|
||||
Puppet kubernetes 模块目前假设您已经有一个 kubernetes 集群 [启动并运行]](http://kubernetes.io/gettingstarted/)。它的重点是管理 Kubernetes中的资源,如 Pods、Replication Controllers 和 Services,而不是(现在)管理底层的 kubelet 或 etcd services。下面是描述 Puppet’s DSL 中一个 Pod 的简短代码片段。
|
||||
|
||||
<!--
|
||||
```
|
||||
kubernetes_pod { 'sample-pod':
|
||||
ensure => present,
|
||||
metadata => {
|
||||
namespace => 'default',
|
||||
},
|
||||
spec => {
|
||||
containers => [{
|
||||
name => 'container-name',
|
||||
image => 'nginx',
|
||||
}]
|
||||
},
|
||||
```
|
||||
}
|
||||
-->
|
||||
|
||||
```
|
||||
kubernetes_pod { 'sample-pod':
|
||||
ensure => present,
|
||||
metadata => {
|
||||
namespace => 'default',
|
||||
},
|
||||
spec => {
|
||||
containers => [{
|
||||
name => 'container-name',
|
||||
image => 'nginx',
|
||||
}]
|
||||
},
|
||||
}
|
||||
```
|
||||
<!--
|
||||
If you’re familiar with the YAML file format, you’ll probably recognise the structure immediately. The interface is intentionally identical to aid conversion between different formats — in fact, the code powering this is autogenerated from the Kubernetes API Swagger definitions. Running the above code, assuming we save it as pod.pp, is as simple as:
|
||||
|
||||
|
||||
```
|
||||
puppet apply pod.pp
|
||||
```
|
||||
-->
|
||||
|
||||
如果您熟悉 YAML 文件格式,您可能会立即识别该结构。 该接口故意采取相同的格式以帮助在不同格式之间进行转换 — 事实上,为此提供支持的代码是从Kubernetes API Swagger自动生成的。 运行上面的代码,假设我们将其保存为 pod.pp,就像下面这样简单:
|
||||
|
||||
|
||||
```
|
||||
puppet apply pod.pp
|
||||
```
|
||||
|
||||
<!--
|
||||
Authentication uses the standard kubectl configuration file. You can find complete [installation instructions in the module's README](https://github.com/garethr/garethr-kubernetes/blob/master/README.md).
|
||||
|
||||
Kubernetes has several resources, from Pods and Services to Replication Controllers and Service Accounts. You can see an example of the module managing these resources in the [Kubernetes guestbook sample in Puppet](https://puppetlabs.com/blog/kubernetes-guestbook-example-puppet) post. This demonstrates converting the canonical hello-world example to use Puppet code. -->
|
||||
|
||||
身份验证使用标准的 kubectl 配置文件。您可以在模块的自述文件中找到完整的[README](https://github.com/garethr/garethr-kubernetes/blob/master/README.md)。
|
||||
|
||||
Kubernetes 有很多资源,来自 Pods、 Services、 Replication Controllers 和 Service Accounts。您可以在[Puppet 中的 kubernetes 留言簿示例](https://puppetlabs.com/blog/kubernetes-guestbook-example-puppet)文章中看到管理这些资源的模块示例。这演示了如何将规范的 hello-world 示例转换为使用 Puppet代码。
|
||||
|
||||
<!--
|
||||
One of the main advantages of using Puppet for this, however, is that you can create your own higher-level and more business-specific interfaces to Kubernetes-managed applications. For instance, for the guestbook, you could create something like the following:
|
||||
|
||||
|
||||
```
|
||||
guestbook { 'myguestbook':
|
||||
redis_slave_replicas => 2,
|
||||
frontend_replicas => 3,
|
||||
redis_master_image => 'redis',
|
||||
redis_slave_image => 'gcr.io/google_samples/gb-redisslave:v1',
|
||||
frontend_image => 'gcr.io/google_samples/gb-frontend:v3',
|
||||
}
|
||||
```
|
||||
-->
|
||||
|
||||
然而,使用 Puppet 的一个主要优点是,您可以创建自己的更高级别和更特定于业务的接口,以连接 kubernetes 管理的应用程序。例如,对于留言簿,可以创建如下内容:
|
||||
|
||||
```
|
||||
guestbook { 'myguestbook':
|
||||
redis_slave_replicas => 2,
|
||||
frontend_replicas => 3,
|
||||
redis_master_image => 'redis',
|
||||
redis_slave_image => 'gcr.io/google_samples/gb-redisslave:v1',
|
||||
frontend_image => 'gcr.io/google_samples/gb-frontend:v3',
|
||||
}
|
||||
```
|
||||
|
||||
<!--
|
||||
You can read more about using Puppet’s defined types, and see lots more code examples, in the Puppet blog post, [Building Your Own Abstractions for Kubernetes in Puppet](https://puppetlabs.com/blog/building-your-own-abstractions-kubernetes-puppet).
|
||||
|
||||
|
||||
### Conclusions
|
||||
|
||||
The advantages of using Puppet rather than just the standard YAML files and kubectl are:
|
||||
-->
|
||||
|
||||
您可以在Puppet博客文章[在 Puppet 中为 Kubernetes 构建自己的抽象](https://puppetlabs.com/blog/building-your-own-abstractions-kubernetes-puppet)中阅读更多关于使用 Puppet 定义的类型的信息,并看到更多的代码示例。
|
||||
|
||||
|
||||
### 结论
|
||||
|
||||
使用 Puppet 而不仅仅是使用标准的 YAML 文件和 kubectl 的优点是:
|
||||
|
||||
<!--
|
||||
- The ability to create your own abstractions to cut down on repetition and craft higher-level user interfaces, like the guestbook example above.
|
||||
- Use of Puppet’s development tools for validating code and for writing unit tests.
|
||||
- Integration with other tools such as Puppet Server, for ensuring that your model in code matches the state of your cluster, and with PuppetDB for storing reports and tracking changes.
|
||||
- The ability to run the same code repeatedly against the Kubernetes API, to detect any changes or remediate configuration drift.
|
||||
-->
|
||||
|
||||
- 能够创建自己的抽象,以减少重复和设计更高级别的用户界面,如上面的留言簿示例。
|
||||
- 使用 Puppet 的开发工具验证代码和编写单元测试。
|
||||
- 与 Puppet Server 等其他工具配合,以确保代码中的模型与集群的状态匹配,并与 PuppetDB 配合工作,以存储报告和跟踪更改。
|
||||
- 能够针对 Kubernetes API 重复运行相同的代码,以检测任何更改或修正配置。
|
||||
|
||||
<!--
|
||||
It’s also worth noting that most large organisations will have very heterogenous environments, running a wide range of software and operating systems. Having a single toolchain that unifies those discrete systems can make adopting new technology like Kubernetes much easier.
|
||||
-->
|
||||
|
||||
值得注意的是,大多数大型组织都将拥有非常异构的环境,运行各种各样的软件和操作系统。拥有统一这些离散系统的单一工具链可以使采用 Kubernetes 等新技术变得更加容易。
|
||||
|
||||
<!--
|
||||
It’s safe to say that Kubernetes provides an excellent set of primitives on which to build cloud-native systems. And with Puppet, you can address some of the operational and configuration management issues that come with running any complex system in production. [Let us know](mailto:gareth@puppetlabs.com) what you think if you try the module out, and what else you’d like to see supported in the future.
|
||||
|
||||
- Gareth Rushgrove, Senior Software Engineer, Puppet Labs
|
||||
-->
|
||||
|
||||
可以肯定地说,Kubernetes提供了一组优秀的组件来构建云原生系统。使用 Puppet,您可以解决在生产中运行任何复杂系统所带来的一些操作和配置管理问题。[告诉我们](mailto:gareth@puppetlabs.com)如果您试用了该模块,您会有什么想法,以及您希望在将来看到哪些支持。
|
||||
|
||||
|
||||
Gareth Rushgrove,Puppet Labs 高级软件工程师
|
||||
|
||||
@@ -0,0 +1,303 @@
|
||||
<!--
|
||||
---
|
||||
title: " Simple leader election with Kubernetes and Docker "
|
||||
date: 2016-01-11
|
||||
slug: simple-leader-election-with-kubernetes
|
||||
url: /blog/2016/01/Simple-Leader-Election-With-Kubernetes
|
||||
---
|
||||
|
||||
#### Overview
|
||||
-->
|
||||
|
||||
title: "Kubernetes 和 Docker 简单的 leader election"
|
||||
date: 2016-01-11
|
||||
slug: simple-leader-election-with-kubernetes
|
||||
url: /blog/2016/01/Simple-Leader-Election-With-Kubernetes
|
||||
|
||||
<!--
|
||||
Kubernetes simplifies the deployment and operational management of services running on clusters. However, it also simplifies the development of these services. In this post we'll see how you can use Kubernetes to easily perform leader election in your distributed application. Distributed applications usually replicate the tasks of a service for reliability and scalability, but often it is necessary to designate one of the replicas as the leader who is responsible for coordination among all of the replicas.
|
||||
-->
|
||||
|
||||
Kubernetes 简化了集群上运行的服务的部署和操作管理。但是,它也简化了这些服务的发展。在本文中,我们将看到如何使用 Kubernetes 在分布式应用程序中轻松地执行 leader election。分布式应用程序通常为了可靠性和可伸缩性而复制服务的任务,但通常需要指定其中一个副本作为负责所有副本之间协调的负责人。
|
||||
|
||||
<!--
|
||||
Typically in leader election, a set of candidates for becoming leader is identified. These candidates all race to declare themselves the leader. One of the candidates wins and becomes the leader. Once the election is won, the leader continually "heartbeats" to renew their position as the leader, and the other candidates periodically make new attempts to become the leader. This ensures that a new leader is identified quickly, if the current leader fails for some reason.
|
||||
-->
|
||||
|
||||
通常在 leader election 中,会确定一组成为领导者的候选人。这些候选人都竞相宣布自己为领袖。其中一位候选人获胜并成为领袖。一旦选举获胜,领导者就会不断地“信号”以表示他们作为领导者的地位,其他候选人也会定期地做出新的尝试来成为领导者。这样可以确保在当前领导因某种原因失败时,快速确定新领导。
|
||||
|
||||
<!--
|
||||
Implementing leader election usually requires either deploying software such as ZooKeeper, etcd or Consul and using it for consensus, or alternately, implementing a consensus algorithm on your own. We will see below that Kubernetes makes the process of using leader election in your application significantly easier.
|
||||
|
||||
#### Implementing leader election in Kubernetes
|
||||
-->
|
||||
|
||||
实现 leader election 通常需要部署 ZooKeeper、etcd 或 Consul 等软件并将其用于协商一致,或者也可以自己实现协商一致算法。我们将在下面看到,Kubernetes 使在应用程序中使用 leader election 的过程大大简化。
|
||||
|
||||
####在 Kubernetes 实施领导人选举
|
||||
|
||||
<!--
|
||||
The first requirement in leader election is the specification of the set of candidates for becoming the leader. Kubernetes already uses _Endpoints_ to represent a replicated set of pods that comprise a service, so we will re-use this same object. (aside: You might have thought that we would use _ReplicationControllers_, but they are tied to a specific binary, and generally you want to have a single leader even if you are in the process of performing a rolling update)
|
||||
|
||||
To perform leader election, we use two properties of all Kubernetes API objects:
|
||||
-->
|
||||
|
||||
Leader election 的首要条件是确定候选人的人选。Kubernetes 已经使用 _Endpoints_ 来表示组成服务的一组复制 pod,因此我们将重用这个相同的对象。(旁白:您可能认为我们会使用 _ReplicationControllers_,但它们是绑定到特定的二进制文件,而且通常您希望只有一个领导者,即使您正在执行滚动更新)
|
||||
|
||||
要执行 leader election,我们使用所有 Kubernetes api 对象的两个属性:
|
||||
|
||||
<!--
|
||||
* ResourceVersions - Every API object has a unique ResourceVersion, and you can use these versions to perform compare-and-swap on Kubernetes objects
|
||||
* Annotations - Every API object can be annotated with arbitrary key/value pairs to be used by clients.
|
||||
|
||||
Given these primitives, the code to use master election is relatively straightforward, and you can find it [here][1]. Let's run it ourselves.
|
||||
-->
|
||||
|
||||
* ResourceVersions - 每个 API 对象都有一个惟一的 ResourceVersion,您可以使用这些版本对 Kubernetes 对象执行比较和交换
|
||||
* Annotations - 每个 API 对象都可以用客户端使用的任意键/值对进行注释。
|
||||
|
||||
给定这些原语,使用 master election 的代码相对简单,您可以在这里找到[here][1]。我们自己来做吧。
|
||||
|
||||
<!--
|
||||
```
|
||||
$ kubectl run leader-elector --image=gcr.io/google_containers/leader-elector:0.4 --replicas=3 -- --election=example
|
||||
```
|
||||
|
||||
This creates a leader election set with 3 replicas:
|
||||
|
||||
```
|
||||
$ kubectl get pods
|
||||
NAME READY STATUS RESTARTS AGE
|
||||
leader-elector-inmr1 1/1 Running 0 13s
|
||||
leader-elector-qkq00 1/1 Running 0 13s
|
||||
leader-elector-sgwcq 1/1 Running 0 13s
|
||||
```
|
||||
-->
|
||||
|
||||
```
|
||||
$ kubectl run leader-elector --image=gcr.io/google_containers/leader-elector:0.4 --replicas=3 -- --election=example
|
||||
```
|
||||
|
||||
这将创建一个包含3个副本的 leader election 集合:
|
||||
|
||||
```
|
||||
$ kubectl get pods
|
||||
NAME READY STATUS RESTARTS AGE
|
||||
leader-elector-inmr1 1/1 Running 0 13s
|
||||
leader-elector-qkq00 1/1 Running 0 13s
|
||||
leader-elector-sgwcq 1/1 Running 0 13s
|
||||
```
|
||||
|
||||
<!--
|
||||
To see which pod was chosen as the leader, you can access the logs of one of the pods, substituting one of your own pod's names in place of
|
||||
|
||||
```
|
||||
${pod_name}, (e.g. leader-elector-inmr1 from the above)
|
||||
|
||||
$ kubectl logs -f ${name}
|
||||
leader is (leader-pod-name)
|
||||
```
|
||||
… Alternately, you can inspect the endpoints object directly:
|
||||
-->
|
||||
|
||||
要查看哪个pod被选为领导,您可以访问其中一个 pod 的日志,用您自己的一个 pod 的名称替换
|
||||
|
||||
```
|
||||
${pod_name}, (e.g. leader-elector-inmr1 from the above)
|
||||
|
||||
$ kubectl logs -f ${name}
|
||||
leader is (leader-pod-name)
|
||||
```
|
||||
…或者,可以直接检查 endpoints 对象:
|
||||
|
||||
<!--
|
||||
_'example' is the name of the candidate set from the above kubectl run … command_
|
||||
```
|
||||
$ kubectl get endpoints example -o yaml
|
||||
```
|
||||
Now to validate that leader election actually works, in a different terminal, run:
|
||||
|
||||
```
|
||||
$ kubectl delete pods (leader-pod-name)
|
||||
```
|
||||
-->
|
||||
|
||||
_'example' 是上面 kubectl run … 命令_中候选集的名称
|
||||
```
|
||||
$ kubectl get endpoints example -o yaml
|
||||
```
|
||||
现在,要验证 leader election 是否实际有效,请在另一个终端运行:
|
||||
```
|
||||
$ kubectl delete pods (leader-pod-name)
|
||||
```
|
||||
|
||||
<!--
|
||||
This will delete the existing leader. Because the set of pods is being managed by a replication controller, a new pod replaces the one that was deleted, ensuring that the size of the replicated set is still three. Via leader election one of these three pods is selected as the new leader, and you should see the leader failover to a different pod. Because pods in Kubernetes have a _grace period_ before termination, this may take 30-40 seconds.
|
||||
|
||||
The leader-election container provides a simple webserver that can serve on any address (e.g. http://localhost:4040). You can test this out by deleting the existing leader election group and creating a new one where you additionally pass in a --http=(host):(port) specification to the leader-elector image. This causes each member of the set to serve information about the leader via a webhook.
|
||||
-->
|
||||
|
||||
这将删除现有领导。由于 pod 集由 replication controller 管理,因此新的 pod 将替换已删除的pod,确保复制集的大小仍为3。通过 leader election,这三个pod中的一个被选为新的领导者,您应该会看到领导者故障转移到另一个pod。因为 Kubernetes 的吊舱在终止前有一个 _grace period_,这可能需要30-40秒。
|
||||
|
||||
Leader-election container 提供了一个简单的 web 服务器,可以服务于任何地址(e.g. http://localhost:4040)。您可以通过删除现有的 leader election 组并创建一个新的 leader elector 组来测试这一点,在该组中,您还可以向 leader elector 映像传递--http=(host):(port) 规范。这将导致集合中的每个成员通过 webhook 提供有关领导者的信息。
|
||||
|
||||
<!--
|
||||
```
|
||||
# delete the old leader elector group
|
||||
$ kubectl delete rc leader-elector
|
||||
|
||||
# create the new group, note the --http=localhost:4040 flag
|
||||
$ kubectl run leader-elector --image=gcr.io/google_containers/leader-elector:0.4 --replicas=3 -- --election=example --http=0.0.0.0:4040
|
||||
|
||||
# create a proxy to your Kubernetes api server
|
||||
$ kubectl proxy
|
||||
```
|
||||
-->
|
||||
|
||||
```
|
||||
# delete the old leader elector group
|
||||
$ kubectl delete rc leader-elector
|
||||
|
||||
# create the new group, note the --http=localhost:4040 flag
|
||||
$ kubectl run leader-elector --image=gcr.io/google_containers/leader-elector:0.4 --replicas=3 -- --election=example --http=0.0.0.0:4040
|
||||
|
||||
# create a proxy to your Kubernetes api server
|
||||
$ kubectl proxy
|
||||
```
|
||||
|
||||
<!--
|
||||
You can then access:
|
||||
|
||||
|
||||
http://localhost:8001/api/v1/proxy/namespaces/default/pods/(leader-pod-name):4040/
|
||||
|
||||
|
||||
And you will see:
|
||||
|
||||
```
|
||||
{"name":"(name-of-leader-here)"}
|
||||
```
|
||||
#### Leader election with sidecars
|
||||
-->
|
||||
|
||||
然后您可以访问:
|
||||
|
||||
|
||||
|
||||
|
||||
http://localhost:8001/api/v1/proxy/namespaces/default/pods/(leader-pod-name):4040/
|
||||
|
||||
|
||||
|
||||
|
||||
你会看到:
|
||||
|
||||
```
|
||||
{"name":"(name-of-leader-here)"}
|
||||
```
|
||||
#### 有副手的 leader election
|
||||
|
||||
<!--
|
||||
Ok, that's great, you can do leader election and find out the leader over HTTP, but how can you use it from your own application? This is where the notion of sidecars come in. In Kubernetes, Pods are made up of one or more containers. Often times, this means that you add sidecar containers to your main application to make up a Pod. (for a much more detailed treatment of this subject see my earlier blog post).
|
||||
|
||||
The leader-election container can serve as a sidecar that you can use from your own application. Any container in the Pod that's interested in who the current master is can simply access http://localhost:4040 and they'll get back a simple JSON object that contains the name of the current master. Since all containers in a Pod share the same network namespace, there's no service discovery required!
|
||||
-->
|
||||
|
||||
好吧,那太好了,你可以通过 HTTP 进行leader election 并找到 leader,但是你如何从自己的应用程序中使用它呢?这就是 sidecar 的由来。Kubernetes 中,Pods 由一个或多个容器组成。通常情况下,这意味着您将 sidecar containers 添加到主应用程序中以组成 pod。(关于这个主题的更详细的处理,请参阅我之前的博客文章)。
|
||||
Leader-election container 可以作为一个 sidecar,您可以从自己的应用程序中使用。Pod 中任何对当前 master 感兴趣的容器都可以简单地访问http://localhost:4040,它们将返回一个包含当前 master 名称的简单 json 对象。由于 pod中 的所有容器共享相同的网络命名空间,因此不需要服务发现!
|
||||
|
||||
<!--
|
||||
For example, here is a simple Node.js application that connects to the leader election sidecar and prints out whether or not it is currently the master. The leader election sidecar sets its identifier to `hostname` by default.
|
||||
|
||||
```
|
||||
var http = require('http');
|
||||
// This will hold info about the current master
|
||||
var master = {};
|
||||
|
||||
// The web handler for our nodejs application
|
||||
var handleRequest = function(request, response) {
|
||||
response.writeHead(200);
|
||||
response.end("Master is " + master.name);
|
||||
};
|
||||
|
||||
// A callback that is used for our outgoing client requests to the sidecar
|
||||
var cb = function(response) {
|
||||
var data = '';
|
||||
response.on('data', function(piece) { data = data + piece; });
|
||||
response.on('end', function() { master = JSON.parse(data); });
|
||||
};
|
||||
|
||||
// Make an async request to the sidecar at http://localhost:4040
|
||||
var updateMaster = function() {
|
||||
var req = http.get({host: 'localhost', path: '/', port: 4040}, cb);
|
||||
req.on('error', function(e) { console.log('problem with request: ' + e.message); });
|
||||
req.end();
|
||||
};
|
||||
|
||||
/ / Set up regular updates
|
||||
updateMaster();
|
||||
setInterval(updateMaster, 5000);
|
||||
|
||||
// set up the web server
|
||||
var www = http.createServer(handleRequest);
|
||||
www.listen(8080);
|
||||
```
|
||||
Of course, you can use this sidecar from any language that you choose that supports HTTP and JSON.
|
||||
-->
|
||||
|
||||
例如,这里有一个简单的 Node.js 应用程序,它连接到 leader election sidecar 并打印出它当前是否是 master。默认情况下,leader election sidecar 将其标识符设置为 `hostname`。
|
||||
|
||||
```
|
||||
var http = require('http');
|
||||
// This will hold info about the current master
|
||||
var master = {};
|
||||
|
||||
// The web handler for our nodejs application
|
||||
var handleRequest = function(request, response) {
|
||||
response.writeHead(200);
|
||||
response.end("Master is " + master.name);
|
||||
};
|
||||
|
||||
// A callback that is used for our outgoing client requests to the sidecar
|
||||
var cb = function(response) {
|
||||
var data = '';
|
||||
response.on('data', function(piece) { data = data + piece; });
|
||||
response.on('end', function() { master = JSON.parse(data); });
|
||||
};
|
||||
|
||||
// Make an async request to the sidecar at http://localhost:4040
|
||||
var updateMaster = function() {
|
||||
var req = http.get({host: 'localhost', path: '/', port: 4040}, cb);
|
||||
req.on('error', function(e) { console.log('problem with request: ' + e.message); });
|
||||
req.end();
|
||||
};
|
||||
|
||||
/ / Set up regular updates
|
||||
updateMaster();
|
||||
setInterval(updateMaster, 5000);
|
||||
|
||||
// set up the web server
|
||||
var www = http.createServer(handleRequest);
|
||||
www.listen(8080);
|
||||
```
|
||||
当然,您可以从任何支持 HTTP 和 JSON 的语言中使用这个 sidecar。
|
||||
|
||||
<!--
|
||||
#### Conclusion
|
||||
|
||||
|
||||
Hopefully I've shown you how easy it is to build leader election for your distributed application using Kubernetes. In future installments we'll show you how Kubernetes is making building distributed systems even easier. In the meantime, head over to [Google Container Engine][2] or [kubernetes.io][3] to get started with Kubernetes.
|
||||
|
||||
[1]: https://github.com/kubernetes/contrib/pull/353
|
||||
[2]: https://cloud.google.com/container-engine/
|
||||
[3]: http://kubernetes.io/
|
||||
-->
|
||||
|
||||
#### 结论
|
||||
|
||||
|
||||
希望我已经向您展示了使用 Kubernetes 为您的分布式应用程序构建 leader election 是多么容易。在以后的部分中,我们将向您展示 Kubernetes 如何使构建分布式系统变得更加容易。同时,转到[Google Container Engine][2]或[kubernetes.io][3]开始使用Kubernetes。
|
||||
|
||||
[1]: https://github.com/kubernetes/contrib/pull/353
|
||||
[2]: https://cloud.google.com/container-engine/
|
||||
[3]: http://kubernetes.io/
|
||||
@@ -0,0 +1,79 @@
|
||||
---
|
||||
title: " 为什么 Kubernetes 不用 libnetwork "
|
||||
date: 2016-01-14
|
||||
slug: why-kubernetes-doesnt-use-libnetwork
|
||||
url: /blog/2016/01/Why-Kubernetes-Doesnt-Use-Libnetwork
|
||||
---
|
||||
|
||||
<!-- ---
|
||||
title: " Why Kubernetes doesn’t use libnetwork "
|
||||
date: 2016-01-14
|
||||
slug: why-kubernetes-doesnt-use-libnetwork
|
||||
url: /blog/2016/01/Why-Kubernetes-Doesnt-Use-Libnetwork
|
||||
--- -->
|
||||
|
||||
<!-- Kubernetes has had a very basic form of network plugins since before version 1.0 was released — around the same time as Docker's [libnetwork](https://github.com/docker/libnetwork) and Container Network Model ([CNM](https://github.com/docker/libnetwork/blob/master/docs/design.md)) was introduced. Unlike libnetwork, the Kubernetes plugin system still retains its "alpha" designation. Now that Docker's network plugin support is released and supported, an obvious question we get is why Kubernetes has not adopted it yet. After all, vendors will almost certainly be writing plugins for Docker — we would all be better off using the same drivers, right? -->
|
||||
|
||||
在 1.0 版本发布之前,Kubernetes 已经有了一个非常基础的网络插件形式-大约在引入 Docker’s [libnetwork](https://github.com/docker/libnetwork) 和 Container Network Model ([CNM](https://github.com/docker/libnetwork/blob/master/docs/design.md)) 的时候。与 libnetwork 不同,Kubernetes 插件系统仍然保留它的 'alpha' 名称。现在 Docker 的网络插件支持已经发布并得到支持,我们发现一个明显的问题是 Kubernetes 尚未采用它。毕竟,供应商几乎肯定会为 Docker 编写插件-我们最好还是用相同的驱动程序,对吧?
|
||||
|
||||
<!-- Before going further, it's important to remember that Kubernetes is a system that supports multiple container runtimes, of which Docker is just one. Configuring networking is a facet of each runtime, so when people ask "will Kubernetes support CNM?" what they really mean is "will kubernetes support CNM drivers with the Docker runtime?" It would be great if we could achieve common network support across runtimes, but that’s not an explicit goal. -->
|
||||
|
||||
在进一步说明之前,重要的是记住 Kubernetes 是一个支持多种容器运行时的系统, Docker 只是其中之一。配置网络只是每一个运行时的一个方面,所以当人们问起“ Kubernetes 会支持CNM吗?”,他们真正的意思是“ Kubernetes 会支持 Docker 运行时的 CNM 驱动吗?”如果我们能够跨运行时实现通用的网络支持会很棒,但这不是一个明确的目标。
|
||||
|
||||
<!-- Indeed, Kubernetes has not adopted CNM/libnetwork for the Docker runtime. In fact, we’ve been investigating the alternative Container Network Interface ([CNI](https://github.com/appc/cni/blob/master/SPEC.md)) model put forth by CoreOS and part of the App Container ([appc](https://github.com/appc)) specification. Why? There are a number of reasons, both technical and non-technical. -->
|
||||
|
||||
实际上, Kubernetes 还没有为 Docker 运行时采用 CNM/libnetwork 。事实上,我们一直在研究 CoreOS 提出的替代 Container Network Interface ([CNI](https://github.com/appc/cni/blob/master/SPEC.md)) 模型以及 App Container ([appc](https://github.com/appc)) 规范的一部分。为什么我们要这么做?有很多技术和非技术的原因。
|
||||
|
||||
<!-- First and foremost, there are some fundamental assumptions in the design of Docker's network drivers that cause problems for us. -->
|
||||
|
||||
首先,Docker 的网络驱动程序设计中存在一些基本假设,这些假设会给我们带来问题。
|
||||
|
||||
<!-- Docker has a concept of "local" and "global" drivers. Local drivers (such as "bridge") are machine-centric and don’t do any cross-node coordination. Global drivers (such as "overlay") rely on [libkv](https://github.com/docker/libkv) (a key-value store abstraction) to coordinate across machines. This key-value store is a another plugin interface, and is very low-level (keys and values, no semantic meaning). To run something like Docker's overlay driver in a Kubernetes cluster, we would either need cluster admins to run a whole different instance of [consul](https://github.com/hashicorp/consul), [etcd](https://github.com/coreos/etcd) or [zookeeper](https://zookeeper.apache.org/) (see [multi-host networking](https://docs.docker.com/engine/userguide/networking/get-started-overlay/)), or else we would have to provide our own libkv implementation that was backed by Kubernetes. -->
|
||||
|
||||
Docker 有一个“本地”和“全局”驱动程序的概念。本地驱动程序(例如 "bridge" )以机器为中心,不进行任何跨节点协调。全局驱动程序(例如 "overlay" )依赖于 [libkv](https://github.com/docker/libkv) (一个键值存储抽象库)来协调跨机器。这个键值存储是另一个插件接口,并且是非常低级的(键和值,没有其他含义)。 要在 Kubernetes 集群中运行类似 Docker's overlay 驱动程序,我们要么需要集群管理员来运行 [consul](https://github.com/hashicorp/consul), [etcd](https://github.com/coreos/etcd) 或 [zookeeper](https://zookeeper.apache.org/) 的整个不同实例 (see [multi-host networking](https://docs.docker.com/engine/userguide/networking/get-started-overlay/)) 否则我们必须提供我们自己的 libkv 实现,那被 Kubernetes 支持。
|
||||
|
||||
<!-- The latter sounds attractive, and we tried to implement it, but the libkv interface is very low-level, and the schema is defined internally to Docker. We would have to either directly expose our underlying key-value store or else offer key-value semantics (on top of our structured API which is itself implemented on a key-value system). Neither of those are very attractive for performance, scalability and security reasons. The net result is that the whole system would significantly be more complicated, when the goal of using Docker networking is to simplify things. -->
|
||||
|
||||
后者听起来很有吸引力,并且我们尝试实现它,但 libkv 接口是非常低级的,并且架构在内部定义为 Docker 。我们必须直接暴露我们的底层键值存储,或者提供键值语义(在我们的结构化API之上,它本身是在键值系统上实现的)。对于性能,可伸缩性和安全性原因,这些都不是很有吸引力。最终结果是,当使用 Docker 网络的目标是简化事情时,整个系统将显得更加复杂。
|
||||
|
||||
<!-- For users that are willing and able to run the requisite infrastructure to satisfy Docker global drivers and to configure Docker themselves, Docker networking should "just work." Kubernetes will not get in the way of such a setup, and no matter what direction the project goes, that option should be available. For default installations, though, the practical conclusion is that this is an undue burden on users and we therefore cannot use Docker's global drivers (including "overlay"), which eliminates a lot of the value of using Docker's plugins at all. -->
|
||||
|
||||
对于愿意并且能够运行必需的基础架构以满足 Docker 全局驱动程序并自己配置 Docker 的用户, Docker 网络应该“正常工作。” Kubernetes 不会妨碍这样的设置,无论项目的方向如何,该选项都应该可用。但是对于默认安装,实际的结论是这对用户来说是一个不应有的负担,因此我们不能使用 Docker 的全局驱动程序(包括 "overlay" ),这消除了使用 Docker 插件的很多价值。
|
||||
|
||||
<!-- Docker's networking model makes a lot of assumptions that aren’t valid for Kubernetes. In docker versions 1.8 and 1.9, it includes a fundamentally flawed implementation of "discovery" that results in corrupted `/etc/hosts` files in containers ([docker #17190](https://github.com/docker/docker/issues/17190)) — and this cannot be easily turned off. In version 1.10 Docker is planning to [bundle a new DNS server](https://github.com/docker/docker/issues/17195), and it’s unclear whether this will be able to be turned off. Container-level naming is not the right abstraction for Kubernetes — we already have our own concepts of service naming, discovery, and binding, and we already have our own DNS schema and server (based on the well-established [SkyDNS](https://github.com/skynetservices/skydns)). The bundled solutions are not sufficient for our needs but are not disableable. -->
|
||||
|
||||
Docker 的网络模型做出了许多对 Kubernetes 无效的假设。在 docker 1.8 和 1.9 版本中,它包含一个从根本上有缺陷的“发现”实现,导致容器中的 `/etc/hosts` 文件损坏 ([docker #17190](https://github.com/docker/docker/issues/17190)) - 并且这不容易被关闭。在 1.10 版本中,Docker 计划 [捆绑一个新的DNS服务器](https://github.com/docker/docker/issues/17195),目前还不清楚是否可以关闭它。容器级命名不是 Kubernetes 的正确抽象 - 我们已经有了自己的服务命名,发现和绑定概念,并且我们已经有了自己的 DNS 模式和服务器(基于完善的 [SkyDNS](https://github.com/skynetservices/skydns) )。捆绑的解决方案不足以满足我们的需求,但不能禁用。
|
||||
|
||||
<!-- Orthogonal to the local/global split, Docker has both in-process and out-of-process ("remote") plugins. We investigated whether we could bypass libnetwork (and thereby skip the issues above) and drive Docker remote plugins directly. Unfortunately, this would mean that we could not use any of the Docker in-process plugins, "bridge" and "overlay" in particular, which again eliminates much of the utility of libnetwork. -->
|
||||
|
||||
与本地/全局拆分正交, Docker 具有进程内和进程外( "remote" )插件。我们调查了是否可以绕过 libnetwork (从而跳过上面的问题)并直接驱动 Docker remote 插件。不幸的是,这意味着我们无法使用任何 Docker 进程中的插件,特别是 "bridge" 和 "overlay",这再次消除了 libnetwork 的大部分功能。
|
||||
|
||||
<!-- On the other hand, CNI is more philosophically aligned with Kubernetes. It's far simpler than CNM, doesn't require daemons, and is at least plausibly cross-platform (CoreOS’s [rkt](https://coreos.com/rkt/docs/) container runtime supports it). Being cross-platform means that there is a chance to enable network configurations which will work the same across runtimes (e.g. Docker, Rocket, Hyper). It follows the UNIX philosophy of doing one thing well. -->
|
||||
|
||||
另一方面, CNI 在哲学上与 Kubernetes 更加一致。它比 CNM 简单得多,不需要守护进程,并且至少是合理的跨平台( CoreOS 的 [rkt](https://coreos.com/rkt/docs/) 容器运行时支持它)。跨平台意味着有机会启用跨运行时(例如 Docker , Rocket , Hyper )运行相同的网络配置。 它遵循 UNIX 的理念,即做好一件事。
|
||||
|
||||
<!-- Additionally, it's trivial to wrap a CNI plugin and produce a more customized CNI plugin — it can be done with a simple shell script. CNM is much more complex in this regard. This makes CNI an attractive option for rapid development and iteration. Early prototypes have proven that it's possible to eject almost 100% of the currently hard-coded network logic in kubelet into a plugin. -->
|
||||
|
||||
此外,包装 CNI 插件并生成更加个性化的 CNI 插件是微不足道的 - 它可以通过简单的 shell 脚本完成。 CNM 在这方面要复杂得多。这使得 CNI 对于快速开发和迭代是有吸引力的选择。早期的原型已经证明,可以将 kubelet 中几乎 100% 的当前硬编码网络逻辑弹出到插件中。
|
||||
|
||||
<!-- We investigated [writing a "bridge" CNM driver](https://groups.google.com/forum/#!topic/kubernetes-sig-network/5MWRPxsURUw) for Docker that ran CNI drivers. This turned out to be very complicated. First, the CNM and CNI models are very different, so none of the "methods" lined up. We still have the global vs. local and key-value issues discussed above. Assuming this driver would declare itself local, we have to get info about logical networks from Kubernetes. -->
|
||||
|
||||
我们调查了为 Docker [编写 "bridge" CNM驱动程序](https://groups.google.com/forum/#!topic/kubernetes-sig-network/5MWRPxsURUw) 并运行 CNI 驱动程序。事实证明这非常复杂。首先, CNM 和 CNI 模型非常不同,因此没有一种“方法”协调一致。 我们仍然有上面讨论的全球与本地和键值问题。假设这个驱动程序会声明自己是本地的,我们必须从 Kubernetes 获取有关逻辑网络的信息。
|
||||
|
||||
<!-- Unfortunately, Docker drivers are hard to map to other control planes like Kubernetes. Specifically, drivers are not told the name of the network to which a container is being attached — just an ID that Docker allocates internally. This makes it hard for a driver to map back to any concept of network that exists in another system. -->
|
||||
|
||||
不幸的是, Docker 驱动程序很难映射到像 Kubernetes 这样的其他控制平面。具体来说,驱动程序不会被告知连接容器的网络名称 - 只是 Docker 内部分配的 ID 。这使得驱动程序很难映射回另一个系统中存在的任何网络概念。
|
||||
|
||||
<!-- This and other issues have been brought up to Docker developers by network vendors, and are usually closed as "working as intended" ([libnetwork #139](https://github.com/docker/libnetwork/issues/139), [libnetwork #486](https://github.com/docker/libnetwork/issues/486), [libnetwork #514](https://github.com/docker/libnetwork/pull/514), [libnetwork #865](https://github.com/docker/libnetwork/issues/865), [docker #18864](https://github.com/docker/docker/issues/18864)), even though they make non-Docker third-party systems more difficult to integrate with. Throughout this investigation Docker has made it clear that they’re not very open to ideas that deviate from their current course or that delegate control. This is very worrisome to us, since Kubernetes complements Docker and adds so much functionality, but exists outside of Docker itself. -->
|
||||
|
||||
这个问题和其他问题已由网络供应商提出给 Docker 开发人员,并且通常关闭为“按预期工作”,([libnetwork #139](https://github.com/docker/libnetwork/issues/139), [libnetwork #486](https://github.com/docker/libnetwork/issues/486), [libnetwork #514](https://github.com/docker/libnetwork/pull/514), [libnetwork #865](https://github.com/docker/libnetwork/issues/865), [docker #18864](https://github.com/docker/docker/issues/18864)),即使它们使非 Docker 第三方系统更难以与之集成。在整个调查过程中, Docker 明确表示他们对偏离当前路线或委托控制的想法不太欢迎。这对我们来说非常令人担忧,因为 Kubernetes 补充了 Docker 并增加了很多功能,但它存在于 Docker 之外。
|
||||
|
||||
<!-- For all of these reasons we have chosen to invest in CNI as the Kubernetes plugin model. There will be some unfortunate side-effects of this. Most of them are relatively minor (for example, `docker inspect` will not show an IP address), but some are significant. In particular, containers started by `docker run` might not be able to communicate with containers started by Kubernetes, and network integrators will have to provide CNI drivers if they want to fully integrate with Kubernetes. On the other hand, Kubernetes will get simpler and more flexible, and a lot of the ugliness of early bootstrapping (such as configuring Docker to use our bridge) will go away. -->
|
||||
|
||||
出于所有这些原因,我们选择投资 CNI 作为 Kubernetes 插件模型。这会有一些不幸的副作用。它们中的大多数都相对较小(例如, `docker inspect` 不会显示 IP 地址),但有些是重要的。特别是,由 `docker run` 启动的容器可能无法与 Kubernetes 启动的容器通信,如果网络集成商想要与 Kubernetes 完全集成,则必须提供 CNI 驱动程序。另一方面, Kubernetes 将变得更简单,更灵活,早期引入的许多丑陋的(例如配置 Docker 使用我们的网桥)将会消失。
|
||||
|
||||
<!-- As we proceed down this path, we’ll certainly keep our eyes and ears open for better ways to integrate and simplify. If you have thoughts on how we can do that, we really would like to hear them — find us on [slack](http://slack.k8s.io/) or on our [network SIG mailing-list](https://groups.google.com/forum/#!forum/kubernetes-sig-network). -->
|
||||
|
||||
当我们沿着这条道路前进时,我们肯定会保持眼睛和耳朵的开放,以便更好地整合和简化。如果您对我们如何做到这一点有所想法,我们真的希望听到它们 - 在 [slack](http://slack.k8s.io/) 或者 [network SIG mailing-list](https://groups.google.com/forum/#!forum/kubernetes-sig-network) 找到我们。
|
||||
|
||||
Tim Hockin, Software Engineer, Google
|
||||
@@ -0,0 +1,84 @@
|
||||
---
|
||||
title: " KubeCon EU 2016:伦敦 Kubernetes 社区 "
|
||||
date: 2016-02-24
|
||||
slug: kubecon-eu-2016-kubernetes-community-in
|
||||
url: /blog/2016/02/Kubecon-Eu-2016-Kubernetes-Community-In
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " KubeCon EU 2016: Kubernetes Community in London "
|
||||
date: 2016-02-24
|
||||
slug: kubecon-eu-2016-kubernetes-community-in
|
||||
url: /blog/2016/02/Kubecon-Eu-2016-Kubernetes-Community-In
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
KubeCon EU 2016 is the inaugural [European Kubernetes](http://kubernetes.io/) community conference that follows on the American launch in November 2015. KubeCon is fully dedicated to education and community engagement for[Kubernetes](http://kubernetes.io/) enthusiasts, production users and the surrounding ecosystem.
|
||||
-->
|
||||
KubeCon EU 2016 是首届[欧洲 Kubernetes](http://kubernetes.io/) 社区会议,紧随 2015 年 11 月召开的北美会议。KubeCon 致力于为 [Kubernetes](http://kubernetes.io/) 爱好者、产品用户和周围的生态系统提供教育和社区参与。
|
||||
|
||||
<!--
|
||||
Come join us in London and hang out with hundreds from the Kubernetes community and experience a wide variety of deep technical expert talks and use cases.
|
||||
-->
|
||||
快来加入我们在伦敦,与 Kubernetes 社区的数百人一起出去,体验各种深入的技术专家讲座和用例。
|
||||
|
||||
<!--
|
||||
Don’t miss these great speaker sessions at the conference:
|
||||
-->
|
||||
不要错过这些优质的演讲:
|
||||
|
||||
<!--
|
||||
* “Kubernetes Hardware Hacks: Exploring the Kubernetes API Through Knobs, Faders, and Sliders” by Ian Lewis and Brian Dorsey, Developer Advocate, Google -* [http://sched.co/6Bl3](http://sched.co/6Bl3)
|
||||
|
||||
* “rktnetes: what's new with container runtimes and Kubernetes” by Jonathan Boulle, Developer and Team Lead at CoreOS -* [http://sched.co/6BY7](http://sched.co/6BY7)
|
||||
|
||||
* “Kubernetes Documentation: Contributing, fixing issues, collecting bounties” by John Mulhausen, Lead Technical Writer, Google -* [http://sched.co/6BUP](http://sched.co/6BUP)
|
||||
* “[What is OpenStack's role in a Kubernetes world?](https://kubeconeurope2016.sched.org/event/6BYC/what-is-openstacks-role-in-a-kubernetes-world?iframe=yes&w=i:0;&sidebar=yes&bg=no#?iframe=yes&w=i:100;&sidebar=yes&bg=no)” By Thierry Carrez, Director of Engineering, OpenStack Foundation -* http://sched.co/6BYC
|
||||
* “A Practical Guide to Container Scheduling” by Mandy Waite, Developer Advocate, Google -* [http://sched.co/6BZa](http://sched.co/6BZa)
|
||||
|
||||
* “[Kubernetes in Production in The New York Times newsroom](https://kubeconeurope2016.sched.org/event/67f2/kubernetes-in-production-in-the-new-york-times-newsroom?iframe=yes&w=i:0;&sidebar=yes&bg=no#?iframe=yes&w=i:100;&sidebar=yes&bg=no)” Eric Lewis, Web Developer, New York Times -* [http://sched.co/67f2](http://sched.co/67f2)
|
||||
* “[Creating an Advanced Load Balancing Solution for Kubernetes with NGINX](https://kubeconeurope2016.sched.org/event/6Bc9/creating-an-advanced-load-balancing-solution-for-kubernetes-with-nginx?iframe=yes&w=i:0;&sidebar=yes&bg=no#?iframe=yes&w=i:100;&sidebar=yes&bg=no)” by Andrew Hutchings, Technical Product Manager, NGINX -* http://sched.co/6Bc9
|
||||
* And many more http://kubeconeurope2016.sched.org/
|
||||
-->
|
||||
|
||||
* “Kubernetes 硬件黑客:通过旋钮、推杆和滑块探索 Kubernetes API” 演讲者 Ian Lewis 和 Brian Dorsey,谷歌开发布道师* [http://sched.co/6Bl3](http://sched.co/6Bl3)
|
||||
|
||||
* “rktnetes: 容器运行时和 Kubernetes 的新功能” 演讲者 Jonathan Boulle, CoreOS 的主程 -* [http://sched.co/6BY7](http://sched.co/6BY7)
|
||||
|
||||
* “Kubernetes 文档:贡献、修复问题、收集奖金” 作者:John Mulhausen,首席技术作家,谷歌 -* [http://sched.co/6BUP](http://sched.co/6BUP)
|
||||
* “[OpenStack 在 Kubernetes 的世界中扮演什么角色?](https://kubeconeurope2016.sched.org/event/6BYC/what-is-openstacks-role-in-a-kubernetes-world?iframe=yes&w=i:0;&sidebar=yes&bg=no#?iframe=yes&w=i:100;&sidebar=yes&bg=no)” 作者:Thierry carez, OpenStack 基金会工程总监 -* http://sched.co/6BYC
|
||||
* “容器调度的实用指南” 作者:Mandy Waite,开发者倡导者,谷歌 -* [http://sched.co/6BZa](http://sched.co/6BZa)
|
||||
|
||||
* “[《纽约时报》编辑部正在制作 Kubernetes](https://kubeconeurope2016.sched.org/event/67f2/kubernetes-in-production-in-the-new-york-times-newsroom?iframe=yes&w=i:0;&sidebar=yes&bg=no#?iframe=yes&w=i:100;&sidebar=yes&bg=no)” Eric Lewis,《纽约时报》网站开发人员 -* [http://sched.co/67f2](http://sched.co/67f2)
|
||||
* “[使用 NGINX 为 Kubernetes 创建一个高级负载均衡解决方案](https://kubeconeurope2016.sched.org/event/6Bc9/creating-an-advanced-load-balancing-solution-for-kubernetes-with-nginx?iframe=yes&w=i:0;&sidebar=yes&bg=no#?iframe=yes&w=i:100;&sidebar=yes&bg=no)” 作者:Andrew Hutchings, NGINX 技术产品经理 -* http://sched.co/6Bc9
|
||||
* 还有更多 http://kubeconeurope2016.sched.org/
|
||||
|
||||
<!--
|
||||
Get your KubeCon EU [tickets here](https://ti.to/kubecon/kubecon-eu-2016).
|
||||
-->
|
||||
[在这里](https://ti.to/kubecon/kubecon-eu-2016)获取您的 KubeCon EU 门票。
|
||||
|
||||
<!--
|
||||
Venue Location: CodeNode * 10 South Pl, London, United Kingdom
|
||||
Accommodations: [hotels](https://skillsmatter.com/contact-us#hotels)
|
||||
Website: [kubecon.io](https://www.kubecon.io/)
|
||||
Twitter: [@KubeConio](https://twitter.com/kubeconio) #KubeCon
|
||||
Google is a proud Diamond sponsor of KubeCon EU 2016. Come to London next month, March 10th & 11th, and visit booth #13 to learn all about Kubernetes, Google Container Engine (GKE) and Google Cloud Platform!
|
||||
-->
|
||||
会场地址:CodeNode * 英国伦敦南广场 10 号
|
||||
酒店住宿:[酒店](https://skillsmatter.com/contact-us)
|
||||
网站:[kubecon.io] (https://www.kubecon.io/)
|
||||
推特:[@KubeConio] (https://twitter.com/kubeconio)
|
||||
谷歌是 KubeCon EU 2016 的钻石赞助商。下个月 3 月 10 - 11 号来伦敦,参观 13 号展位,了解 Kubernetes,Google Container Engine(GKE),Google Cloud Platform 的所有信息!
|
||||
|
||||
<!--
|
||||
_KubeCon is organized by KubeAcademy, LLC, a community-driven group of developers focused on the education of developers and the promotion of Kubernetes._
|
||||
|
||||
-* Sarah Novotny, Kubernetes Community Manager, Google
|
||||
-->
|
||||
|
||||
_KubeCon 是由 KubeAcademy、LLC 组织的,这是一个由社区驱动的开发者团体,专注于开发人员的教育和 kubernet.com 的推广
|
||||
-* Sarah Novotny, 谷歌的 Kubernetes 社区经理
|
||||
|
||||
@@ -0,0 +1,117 @@
|
||||
---
|
||||
title: " Kubernetes 社区会议记录 - 20160204 "
|
||||
date: 2016-02-09
|
||||
slug: kubernetes-community-meeting-notes
|
||||
url: /blog/2016/02/Kubernetes-Community-Meeting-Notes
|
||||
---
|
||||
<!--
|
||||
---
|
||||
title: " Kubernetes community meeting notes - 20160204 "
|
||||
date: 2016-02-09
|
||||
slug: kubernetes-community-meeting-notes
|
||||
url: /blog/2016/02/Kubernetes-Community-Meeting-Notes
|
||||
---
|
||||
-->
|
||||
<!--
|
||||
#### February 4th - rkt demo (congratulations on the 1.0, CoreOS!), eBay puts k8s on Openstack and considers Openstack on k8s, SIGs, and flaky test surge makes progress.
|
||||
-->
|
||||
#### 2月4日 - rkt演示(祝贺 1.0 版本, CoreOS!), eBay 将 k8s 放在 Openstack 上并认为 Openstack 在 k8s, SIG 和片状测试激增方面取得了进展。
|
||||
|
||||
<!--
|
||||
The Kubernetes contributing community meets most Thursdays at 10:00PT to discuss the project's status via a videoconference. Here are the notes from the latest meeting.
|
||||
-->
|
||||
Kubernetes 贡献社区在每周四 10:00 PT 开会,通过视频会议讨论项目状态。以下是最近一次会议的笔记。
|
||||
|
||||
<!--
|
||||
* Note taker: Rob Hirschfeld
|
||||
* Demo (20 min): CoreOS rkt + Kubernetes [Shaya Potter]
|
||||
* expect to see integrations w/ rkt & k8s in the coming months ("rkt-netes"). not integrated into the v1.2 release.
|
||||
* Shaya gave a demo (8 minutes into meeting for video reference)
|
||||
* CLI of rkt shown spinning up containers
|
||||
* [note: audio is garbled at points]
|
||||
* Discussion about integration w/ k8s & rkt
|
||||
* rkt community sync next week: https://groups.google.com/forum/#!topic/rkt-dev/FlwZVIEJGbY
|
||||
* Dawn Chen:
|
||||
* The remaining issues of integrating rkt with kubernetes: 1) cadivsor 2) DNS 3) bugs related to logging
|
||||
* But need more work on e2e test suites
|
||||
-->
|
||||
* 书记员:Rob Hirschfeld
|
||||
* 演示视频(20分钟):CoreOS rkt + Kubernetes[Shaya Potter]
|
||||
* 期待在未来几个月内看到与rkt和k8s的整合(“rkt-netes”)。 还没有集成到 v1.2版本中。
|
||||
* Shaya 做了一个演示(8分钟的会议视频参考)
|
||||
* rkt的CLI显示了旋转容器
|
||||
* [注意:音频在点数上是乱码]
|
||||
* 关于 k8s&rkt 整合的讨论
|
||||
* 下周 rkt 社区同步:https://groups.google.com/forum/#!topic/rkt-dev/FlwZVIEJGbY
|
||||
* Dawn Chen:
|
||||
* 将 rkt 与 kubernetes 集成的其余问题:1)cadivsor 2) DNS 3)与日志记录相关的错误
|
||||
* 但是需要在 e2e 测试套件上做更多的工作
|
||||
<!--
|
||||
* Use Case (10 min): eBay k8s on OpenStack and OpenStack on k8s [Ashwin Raveendran]
|
||||
* eBay is currently running Kubernetes on OpenStack
|
||||
* Goal for eBay is to manage the OpenStack control plane w/ k8s. Goal would be to achieve upgrades
|
||||
* OpenStack Kolla creates containers for the control plane. Uses Ansible+Docker for management of the containers.
|
||||
* Working on k8s control plan management - Saltstack is proving to be a management challenge at the scale they want to operate. Looking for automated management of the k8s control plane.
|
||||
-->
|
||||
* 用例(10分钟):在 OpenStack 上的 eBay k8s 和 k8s 上的 OpenStack [Ashwin Raveendran]
|
||||
* eBay 目前正在 OpenStack 上运行 Kubernetes
|
||||
* eBay 的目标是管理带有 k8s 的 OpenStack 控制平面。目标是实现升级。
|
||||
* OpenStack Kolla 为控制平面创建容器。使用 Ansible+Docker 来管理容器。
|
||||
* 致力于 k8s 控制计划管理 - Saltstack 被证明是他们想运营的规模的管理挑战。寻找 k8s 控制平面的自动化管理。
|
||||
<!--
|
||||
* SIG Report
|
||||
* Testing update [Jeff, Joe, and Erick]
|
||||
* Working to make the workflow about contributing to K8s easier to understanding
|
||||
* [pull/19714][1] has flow chart of the bot flow to help users understand
|
||||
* Need a consistent way to run tests w/ hacking config scripts (you have to fake a Jenkins process right now)
|
||||
* Want to create necessary infrastructure to make test setup less flaky
|
||||
* want to decouple test start (single or full) from Jenkins
|
||||
* goal is to get to point where you have 1 script to run that can be pointed to any cluster
|
||||
* demo included Google internal views - working to try get that external.
|
||||
* want to be able to collect test run results
|
||||
* Bob Wise calls for testing infrastructure to be a blocker on v1.3
|
||||
* Long discussion about testing practices…
|
||||
* consensus that we want to have tests work over multiple platforms.
|
||||
* would be helpful to have a comprehensive state dump for test reports
|
||||
* "phone-home" to collect stack traces - should be available
|
||||
-->
|
||||
* SIG 报告
|
||||
* 测试更新 [Jeff, Joe, 和 Erick]
|
||||
* 努力使有助于 K8s 的工作流程更容易理解
|
||||
* [pull/19714][1]有 bot 流程图来帮助用户理解
|
||||
* 需要一种一致的方法来运行测试 w/hacking 配置脚本(你现在必须伪造一个 Jenkins 进程)
|
||||
* 想要创建必要的基础设施,使测试设置不那么薄弱
|
||||
* 想要将测试开始(单次或完整)与 Jenkins分离
|
||||
* 目标是指出你有一个可以指向任何集群的脚本
|
||||
* 演示包括 Google 内部视图 - 努力尝试获取外部视图。
|
||||
* 希望能够收集测试运行结果
|
||||
* Bob Wise 不赞同在 v1.3 版本进行测试方面的基础设施建设。
|
||||
* 关于测试实践的长期讨论…
|
||||
* 我们希望在多个平台上进行测试的共识。
|
||||
* 为测试报告提供一个全面转储会很有帮助
|
||||
* 可以使用"phone-home"收集异常
|
||||
|
||||
|
||||
<!--
|
||||
* 1.2 Release Watch
|
||||
* CoC [Sarah]
|
||||
* GSoC [Sarah]
|
||||
-->
|
||||
* 1.2发布观察
|
||||
* CoC [Sarah]
|
||||
* GSoC [Sarah]
|
||||
|
||||
<!--
|
||||
To get involved in the Kubernetes community consider joining our [Slack channel][2], taking a look at the [Kubernetes project][3] on GitHub, or join the [Kubernetes-dev Google group][4]. If you're really excited, you can do all of the above and join us for the next community conversation -- February 11th, 2016. Please add yourself or a topic you want to know about to the [agenda][5] and get a calendar invitation by joining [this group][6].
|
||||
-->
|
||||
要参与 Kubernetes 社区,请考虑加入我们的[Slack 频道][2],查看 GitHub上的 [Kubernetes 项目][3],或加入[Kubernetes-dev Google 小组][4]。如果你真的很兴奋,你可以完成上述所有工作并加入我们的下一次社区对话-2016年2月11日。请将您自己或您想要了解的主题添加到[议程][5]并通过加入[此组][6]来获取日历邀请。
|
||||
|
||||
"https://youtu.be/IScpP8Cj0hw?list=PL69nYSiGNLP1pkHsbPjzAewvMgGUpkCnJ"
|
||||
|
||||
|
||||
[1]: https://github.com/kubernetes/kubernetes/pull/19714
|
||||
[2]: http://slack.k8s.io/
|
||||
[3]: https://github.com/kubernetes/
|
||||
[4]: https://groups.google.com/forum/#!forum/kubernetes-dev
|
||||
[5]: https://docs.google.com/document/d/1VQDIAB0OqiSjIHI8AWMvSdceWhnz56jNpZrLs6o7NJY/edit#
|
||||
[6]: https://groups.google.com/forum/#!forum/kubernetes-community-video-chat
|
||||
@@ -1,182 +0,0 @@
|
||||
<!-- ---
|
||||
title: " SIG-Networking: Kubernetes Network Policy APIs Coming in 1.3 "
|
||||
date: 2016-04-18
|
||||
slug: kubernetes-network-policy-apis
|
||||
url: /blog/2016/04/Kubernetes-Network-Policy-APIs
|
||||
--- -->
|
||||
|
||||
---
|
||||
title: "SIG-Networking: Kubernetes Network Policy APIs Coming in 1.3 "
|
||||
date: 2016-04-18
|
||||
slug: kubernetes-network-policy-apis
|
||||
url: /blog/2016/04/Kubernetes-Network-Policy-APIs
|
||||
---
|
||||
|
||||
<!-- _Editor’s note: This week we’re featuring [Kubernetes Special Interest Groups](https://github.com/kubernetes/kubernetes/wiki/Special-Interest-Groups-(SIGs)); Today’s post is by the Network-SIG team describing network policy APIs coming in 1.3 - policies for security, isolation and multi-tenancy._ -->
|
||||
|
||||
编者按:这一周,我们的封面主题是 [Kubernetes 特别兴趣小组](https://github.com/kubernetes/kubernetes/wiki/Special-Interest-Groups-(SIGs));今天的文章由网络兴趣小组撰写,来谈谈 1.3 版本中即将出现的网络策略 API - 针对安全,隔离和多租户的策略。
|
||||
|
||||
<!-- The [Kubernetes network SIG](https://kubernetes.slack.com/messages/sig-network/) has been meeting regularly since late last year to work on bringing network policy to Kubernetes and we’re starting to see the results of this effort. -->
|
||||
|
||||
自去年下半年起,[Kubernetes 网络特别兴趣小组](https://kubernetes.slack.com/messages/sig-network/)经常定期开会,讨论如何将网络策略带入到 Kubernetes 之中,现在,我们也将慢慢看到这些工作的成果。
|
||||
|
||||
<!-- One problem many users have is that the open access network policy of Kubernetes is not suitable for applications that need more precise control over the traffic that accesses a pod or service. Today, this could be a multi-tier application where traffic is only allowed from a tier’s neighbor. But as new Cloud Native applications are built by composing microservices, the ability to control traffic as it flows among these services becomes even more critical. -->
|
||||
|
||||
很多用户经常会碰到的一个问题是, Kubernetes 的开放访问网络策略并不能很好地满足那些需要对 pod 或服务( service )访问进行更为精确控制的场景。今天,这个场景可以是在多层应用中,只允许临近层的访问。然而,随着组合微服务构建原生应用程序潮流的发展,如何控制流量在不同服务之间的流动会别的越发的重要。
|
||||
|
||||
<!-- In most IaaS environments (both public and private) this kind of control is provided by allowing VMs to join a ‘security group’ where traffic to members of the group is defined by a network policy or Access Control List (ACL) and enforced by a network packet filter. -->
|
||||
|
||||
在大多数的(公共的或私有的) IaaS 环境中,这种网络控制通常是将 VM 和“安全组”结合,其中安全组中成员的通信都是通过一个网络策略或者访问控制表( Access Control List, ACL )来定义,以及借助于网络包过滤器来实现。
|
||||
|
||||
<!-- The Network SIG started the effort by identifying [specific use case scenarios](https://docs.google.com/document/d/1blfqiH4L_fpn33ZrnQ11v7LcYP0lmpiJ_RaapAPBbNU/edit?pref=2&pli=1#) that require basic network isolation for enhanced security. Getting the API right for these simple and common use cases is important because they are also the basis for the more sophisticated network policies necessary for multi-tenancy within Kubernetes. -->
|
||||
|
||||
“网络特别兴趣小组”刚开始的工作是确定 [特定的使用场景](https://docs.google.com/document/d/1blfqiH4L_fpn33ZrnQ11v7LcYP0lmpiJ_RaapAPBbNU/edit?pref=2&pli=1#) ,这些用例需要基本的网络隔离来提升安全性。
|
||||
让这些API恰如其分地满足简单、共通的用例尤其重要,因为它们将为那些服务于 Kubernetes 内多租户,更为复杂的网络策略奠定基础。
|
||||
|
||||
<!-- From these scenarios several possible approaches were considered and a minimal [policy specification](https://docs.google.com/document/d/1qAm-_oSap-f1d6a-xRTj6xaH1sYQBfK36VyjB5XOZug/edit) was defined. The basic idea is that if isolation were enabled on a per namespace basis, then specific pods would be selected where specific traffic types would be allowed. -->
|
||||
|
||||
根据这些应用场景,我们考虑了集中不同的方法,然后定义了一个最简[策略规范](https://docs.google.com/document/d/1qAm-_oSap-f1d6a-xRTj6xaH1sYQBfK36VyjB5XOZug/edit)。
|
||||
基本的想法是,如果是根据命名空间的不同来进行隔离,那么就会根据所被允许的流量类型的不同,来选择特定的 pods 。
|
||||
|
||||
<!-- The simplest way to quickly support this experimental API is in the form of a ThirdPartyResource extension to the API Server, which is possible today in Kubernetes 1.2. -->
|
||||
|
||||
快速支持这个实验性 API 的办法是往 API 服务器上加入一个 `ThirdPartyResource` 扩展,这在 Kubernetes 1.2 就能办到。
|
||||
|
||||
<!-- If you’re not familiar with how this works, the Kubernetes API can be extended by defining ThirdPartyResources that create a new API endpoint at a specified URL. -->
|
||||
|
||||
如果你还不是很熟悉这其中的细节, Kubernetes API 是可以通过定义 `ThirdPartyResources` 扩展在特定的 URL 上创建一个新的 API 端点。
|
||||
|
||||
#### third-party-res-def.yaml
|
||||
|
||||
```
|
||||
kind: ThirdPartyResource
|
||||
apiVersion: extensions/v1beta1
|
||||
metadata:
|
||||
- name: network-policy.net.alpha.kubernetes.io
|
||||
description: "Network policy specification"
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
```
|
||||
|
||||
```
|
||||
$kubectl create -f third-party-res-def.yaml
|
||||
```
|
||||
|
||||
<!-- This will create an API endpoint (one for each namespace): -->
|
||||
这条命令会创建一个 API 端点(每个命名空间各一个):
|
||||
|
||||
```
|
||||
/net.alpha.kubernetes.io/v1alpha1/namespace/default/networkpolicys/
|
||||
```
|
||||
|
||||
<!-- Third party network controllers can now listen on these endpoints and react as necessary when resources are created, modified or deleted. _Note: With the upcoming release of Kubernetes 1.3 - when the Network Policy API is released in beta form - there will be no need to create a ThirdPartyResource API endpoint as shown above._ -->
|
||||
|
||||
|
||||
第三方网络控制器可以监听这些端点,根据资源的创建,修改或者删除作出必要的响应。
|
||||
_注意:在接下来的 Kubernetes 1.3 发布中, Network Policy API 会以 beta API 的形式出现,这也就不需要像上面那样,创建一个 `ThirdPartyResource` API 端点了。_
|
||||
|
||||
<!-- Network isolation is off by default so that all pods can communicate as they normally do. However, it’s important to know that once network isolation is enabled, all traffic to all pods, in all namespaces is blocked, which means that enabling isolation is going to change the behavior of your pods -->
|
||||
|
||||
网络隔离默认是关闭的,因而,所有的 pods 之间可以自由地通信。
|
||||
然而,很重要的一点是,一旦开通了网络隔离,所有命名空间下的所有 pods 之间的通信都会被阻断,换句话说,开通隔离会改变 pods 的行为。
|
||||
|
||||
<!-- Network isolation is enabled by defining the _network-isolation_ annotation on namespaces as shown below: -->
|
||||
|
||||
网络隔离可以通过定义命名空间, `net.alpha.kubernetes.io` 里的 `network-isolation` 注释来开通关闭:
|
||||
|
||||
```
|
||||
net.alpha.kubernetes.io/network-isolation: [on | off]
|
||||
```
|
||||
|
||||
<!-- Once network isolation is enabled, explicit network policies **must be applied** to enable pod communication. -->
|
||||
|
||||
一旦开通了网络隔离,**一定需要使用** 显示的网络策略来允许 pod 间的通信。
|
||||
|
||||
<!-- A policy specification can be applied to a namespace to define the details of the policy as shown below: -->
|
||||
|
||||
一个策略规范可以被用到一个命名空间中,来定义策略的细节(如下所示):
|
||||
|
||||
```
|
||||
POST /apis/net.alpha.kubernetes.io/v1alpha1/namespaces/tenant-a/networkpolicys/
|
||||
{
|
||||
"kind": "NetworkPolicy",
|
||||
"metadata": {
|
||||
"name": "pol1"
|
||||
},
|
||||
"spec": {
|
||||
"allowIncoming": {
|
||||
"from": [
|
||||
{
|
||||
"pods": {
|
||||
"segment": "frontend"
|
||||
}
|
||||
}
|
||||
],
|
||||
"toPorts": [
|
||||
{
|
||||
"port": 80,
|
||||
"protocol": "TCP"
|
||||
}
|
||||
]
|
||||
},
|
||||
"podSelector": {
|
||||
"segment": "backend"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
<!-- In this example, the ‘ **tenant-a** ’ namespace would get policy ‘ **pol1** ’ applied as indicated. Specifically, pods with the **segment** label ‘ **backend** ’ would allow TCP traffic on port 80 from pods with the **segment** label ‘ **frontend** ’ to be received. -->
|
||||
|
||||
在这个例子中,**tenant-a** 空间将会使用 **pol1** 策略。
|
||||
具体而言,带有 **segment** 标签为 **backend** 的 pods 会允许 **segment** 标签为 **frontend** 的 pods 访问其端口 80 。
|
||||
|
||||
|
||||
<!-- Today, [Romana](http://romana.io/), [OpenShift](https://www.openshift.com/), [OpenContrail](http://www.opencontrail.org/) and [Calico](http://projectcalico.org/) support network policies applied to namespaces and pods. Cisco and VMware are working on implementations as well. Both Romana and Calico demonstrated these capabilities with Kubernetes 1.2 recently at KubeCon. You can watch their presentations here: [Romana](https://www.youtube.com/watch?v=f-dLKtK6qCs) ([slides](http://www.slideshare.net/RomanaProject/kubecon-london-2016-ronana-cloud-native-sdn)), [Calico](https://www.youtube.com/watch?v=p1zfh4N4SX0) ([slides](http://www.slideshare.net/kubecon/kubecon-eu-2016-secure-cloudnative-networking-with-project-calico)). -->
|
||||
|
||||
|
||||
今天,[Romana](http://romana.io/), [OpenShift](https://www.openshift.com/), [OpenContrail](http://www.opencontrail.org/) 以及 [Calico](http://projectcalico.org/) 都已经支持在命名空间和pods中使用网络策略。
|
||||
而 Cisco 和 VMware 也在努力实现支持之中。
|
||||
Romana 和 Calico 已经在最近的 KubeCon 中展示了如何在 Kubernetes 1.2 下使用这些功能。
|
||||
你可以在这里看到他们的演讲:
|
||||
[Romana](https://www.youtube.com/watch?v=f-dLKtK6qCs) ([幻灯片](http://www.slideshare.net/RomanaProject/kubecon-london-2016-ronana-cloud-native-sdn)),
|
||||
[Calico](https://www.youtube.com/watch?v=p1zfh4N4SX0) ([幻灯片](http://www.slideshare.net/kubecon/kubecon-eu-2016-secure-cloudnative-networking-with-project-calico)).
|
||||
|
||||
<!-- **How does it work?** -->
|
||||
|
||||
**这是如何工作的**
|
||||
|
||||
<!-- Each solution has their their own specific implementation details. Today, they rely on some kind of on-host enforcement mechanism, but future implementations could also be built that apply policy on a hypervisor, or even directly by the network itself. -->
|
||||
|
||||
每套解决方案都有自己不同的具体实现。尽管今天,他们都借助于每种主机上( on-host )的实现机制,但未来的实现可以通过将策略使用在 hypervisor 上,亦或是直接使用到网络本身上来达到同样的目的。
|
||||
|
||||
<!-- External policy control software (specifics vary across implementations) will watch the new API endpoint for pods being created and/or new policies being applied. When an event occurs that requires policy configuration, the listener will recognize the change and a controller will respond by configuring the interface and applying the policy. The diagram below shows an API listener and policy controller responding to updates by applying a network policy locally via a host agent. The network interface on the pods is configured by a CNI plugin on the host (not shown). -->
|
||||
|
||||
外部策略控制软件(不同实现各有不同)可以监听 pods 创建以及新加载策略的 API 端点。
|
||||
当产生一个需要策略配置的事件之后,监听器会确认这个请求,相应的,控制器会配置接口,使用该策略。
|
||||
下面的图例展示了 API 监视器和策略控制器是如何通过主机代理在本地应用网络策略的。
|
||||
这些 pods 的网络接口是使用过主机上的 CNI 插件来进行配置的(并未在图中注明)。
|
||||
|
||||

|
||||
|
||||
|
||||
<!-- If you’ve been holding back on developing applications with Kubernetes because of network isolation and/or security concerns, these new network policies go a long way to providing the control you need. No need to wait until Kubernetes 1.3 since network policy is available now as an experimental API enabled as a ThirdPartyResource. -->
|
||||
|
||||
如果你一直受网络隔离或安全考虑的困扰,而犹豫要不要使用 Kubernetes 来开发应用程序,这些新的网络策略将会极大地解决你这方面的需求。并不需要等到 Kubernetes 1.3 ,现在就可以通过 `ThirdPartyResource` 的方式来使用这个实现性 API 。
|
||||
|
||||
|
||||
<!-- If you’re interested in Kubernetes and networking, there are several ways to participate - join us at:
|
||||
|
||||
- Our [Networking slack channel](https://kubernetes.slack.com/messages/sig-network/)
|
||||
- Our [Kubernetes Networking Special Interest Group](https://groups.google.com/forum/#!forum/kubernetes-sig-network) email list -->
|
||||
|
||||
如果你对 Kubernetes 和网络感兴趣,可以通过下面的方式参与、加入其中:
|
||||
|
||||
- 我们的[网络 slack channel](https://kubernetes.slack.com/messages/sig-network/)
|
||||
- 我们的[Kubernetes 特别网络兴趣小组](https://groups.google.com/forum/#!forum/kubernetes-sig-network) 邮件列表
|
||||
|
||||
<!-- The Networking “Special Interest Group,” which meets bi-weekly at 3pm (15h00) Pacific Time at [SIG-Networking hangout](https://zoom.us/j/5806599998). -->
|
||||
|
||||
网络“特别兴趣小组”每两周下午三点(太平洋时间)开会,地址是[SIG-Networking hangout](https://zoom.us/j/5806599998).
|
||||
|
||||
_--Chris Marino, Co-Founder, Pani Networks_
|
||||
@@ -1,129 +0,0 @@
|
||||
<!-- ---
|
||||
title: " How to deploy secure, auditable, and reproducible Kubernetes clusters on AWS "
|
||||
date: 2016-04-15
|
||||
slug: kubernetes-on-aws_15
|
||||
url: /blog/2016/04/Kubernetes-On-Aws_15
|
||||
--- -->
|
||||
|
||||
---
|
||||
title: " 如何在AWS上部署安全,可审计,可复现的k8s集群 "
|
||||
date: 2016-04-15
|
||||
slug: kubernetes-on-aws_15
|
||||
url: /blog/2016/04/Kubernetes-On-Aws_15
|
||||
---
|
||||
|
||||
<!-- _Today’s guest post is written by Colin Hom, infrastructure engineer at [CoreOS](https://coreos.com/), the company delivering Google’s Infrastructure for Everyone Else (#GIFEE) and running the world's containers securely on CoreOS Linux, Tectonic and Quay._
|
||||
|
||||
_Join us at [CoreOS Fest Berlin](https://coreos.com/fest/), the Open Source Distributed Systems Conference, and learn more about CoreOS and Kubernetes._ -->
|
||||
|
||||
_今天的客座文章是由Colin Hom撰写,[CoreOS](https://coreos.com/)的基础架构工程师。CoreOS致力于推广谷歌的基础架构模式(Google’s Infrastructure for Everyone Else, #GIFEE),让全世界的容器都能在CoreOS Linux, Tectonic 和 Quay上安全运行。_
|
||||
|
||||
_加入到我们的[柏林CoreOS盛宴](https://coreos.com/fest/),这是一个开源分布式系统主题的会议,在这里可以了解到更多关于CoreOS和Kubernetes的信息。_
|
||||
|
||||
<!-- At CoreOS, we're all about deploying Kubernetes in production at scale. Today we are excited to share a tool that makes deploying Kubernetes on Amazon Web Services (AWS) a breeze. Kube-aws is a tool for deploying auditable and reproducible Kubernetes clusters to AWS, currently used by CoreOS to spin up production clusters. -->
|
||||
|
||||
在CoreOS, 我们一直都是在生产环境中大规模部署Kubernetes。今天我们非常兴奋地想分享一款工具,它能让你的Kubernetes生产环境大规模部署更加的轻松。Kube-aws这个工具可以用来在AWS上部署可审计,可复现的k8s集群,而CoreOS本身就在生产环境中使用它。
|
||||
|
||||
<!-- Today you might be putting the Kubernetes components together in a more manual way. With this helpful tool, Kubernetes is delivered in a streamlined package to save time, minimize interdependencies and quickly create production-ready deployments. -->
|
||||
|
||||
也许今天,你更多的可能是用手工的方式来拼接Kubernetes组件。但有了这个工具之后,Kubernetes可以流水化地打包、交付,节省时间,减少了相互间的依赖,更加快捷地实现生产环境的部署。
|
||||
|
||||
<!-- A simple templating system is leveraged to generate cluster configuration as a set of declarative configuration templates that can be version controlled, audited and re-deployed. Since the entirety of the provisioning is by [AWS CloudFormation](https://aws.amazon.com/cloudformation/) and cloud-init, there’s no need for external configuration management tools on your end. Batteries included! -->
|
||||
|
||||
借助于一个简单的模板系统,来生成集群配置,这么做是因为一套声明式的配置模板可以版本控制,审计以及重复部署。而且,由于整个创建过程只用到了[AWS CloudFormation](https://aws.amazon.com/cloudformation/) 和 cloud-init,你也就不需要额外用到其它的配置管理工具。开箱即用!
|
||||
|
||||
<!-- To skip the talk and go straight to the project, check out [the latest release of kube-aws](https://github.com/coreos/coreos-kubernetes/releases), which supports Kubernetes 1.2.x. To get your cluster running, [check out the documentation](https://coreos.com/kubernetes/docs/latest/kubernetes-on-aws.html). -->
|
||||
|
||||
如果要跳过演讲,直接了解这个项目,可以看看[kube-aws的最新发布](https://github.com/coreos/coreos-kubernetes/releases),支持Kubernetes 1.2.x。如果要部署集群,可以参考[文档]](https://coreos.com/kubernetes/docs/latest/kubernetes-on-aws.html).
|
||||
|
||||
<!-- **Why kube-aws? Security, auditability and reproducibility** -->
|
||||
**为什么是kube-aws?安全,可审计,可复现**
|
||||
|
||||
<!-- Kube-aws is designed with three central goals in mind. -->
|
||||
Kube-aws设计初衷有三个目标。
|
||||
|
||||
<!-- **Secure** : TLS assets are encrypted via the [AWS Key Management Service (KMS)](https://aws.amazon.com/kms/) before being embedded in the CloudFormation JSON. By managing [IAM policy](http://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html) for the KMS key independently, an operator can decouple operational access to the CloudFormation stack from access to the TLS secrets. -->
|
||||
|
||||
**安全** : TLS 资源在嵌入到CloudFormation JSON之前,通过[AWS 秘钥管理服务](https://aws.amazon.com/kms/)加密。通过单独管理KMS密钥的[IAM 策略](http://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html),可以将CloudFormation栈的访问与TLS秘钥的访问分离开。
|
||||
|
||||
<!-- **Auditable** : kube-aws is built around the concept of cluster assets. These configuration and credential assets represent the complete description of the cluster. Since KMS is used to encrypt TLS assets, you can feel free to check your unencrypted stack JSON into version control as well! -->
|
||||
|
||||
**可审计** : kube-aws是围绕集群资产的概念来创建。这些配置和账户资产是对集群的完全描述。由于KMS被用来加密TLS资产,因而可以无所顾忌地将未加密的CloudFormation栈 JSON签入到版本控制服务中。
|
||||
|
||||
<!-- **Reproducible** : The _--export_ option packs your parameterized cluster definition into a single JSON file which defines a CloudFormation stack. This file can be version controlled and submitted directly to the CloudFormation API via existing deployment tooling, if desired. -->
|
||||
|
||||
**可重复** : _--export_ 选项将参数化的集群定义打包成一整个JSON文件,对应一个CloudFormation栈。这个文件可以版本控制,然后,如果需要的话,通过现有的部署工具直接提交给CloudFormation API。
|
||||
|
||||
<!-- **How to get started with kube-aws** -->
|
||||
**如何开始用kube-aws**
|
||||
|
||||
<!-- On top of this foundation, kube-aws implements features that make Kubernetes deployments on AWS easier to manage and more flexible. Here are some examples. -->
|
||||
在此基础之上,kube-aws也实现了一些功能,使得在AWS上部署Kubernetes集群更加容易,灵活。下面是一些例子。
|
||||
|
||||
<!-- **Route53 Integration** : Kube-aws can manage your cluster DNS records as part of the provisioning process. -->
|
||||
**Route53集成** : Kube-aws 可以管理你的集群DNS记录,作为配置过程的一部分。
|
||||
|
||||
cluster.yaml
|
||||
```
|
||||
externalDNSName: my-cluster.kubernetes.coreos.com
|
||||
|
||||
createRecordSet: true
|
||||
|
||||
hostedZone: kubernetes.coreos.com
|
||||
|
||||
recordSetTTL: 300
|
||||
```
|
||||
|
||||
<!-- **Existing VPC Support** : Deploy your cluster to an existing VPC. -->
|
||||
**现有VPC支持** : 将集群部署到现有的VPC上。
|
||||
|
||||
cluster.yaml
|
||||
```
|
||||
vpcId: vpc-xxxxx
|
||||
|
||||
routeTableId: rtb-xxxxx
|
||||
```
|
||||
|
||||
<!-- **Validation** : Kube-aws supports validation of cloud-init and CloudFormation definitions, along with any external resources that the cluster stack will integrate with. For example, here’s a cloud-config with a misspelled parameter: -->
|
||||
**验证** : kube-aws 支持验证 cloud-init 和 CloudFormation定义,以及集群栈会集成用到的外部资源。例如,下面就是一个cloud-config,外带一个拼写错误的参数:
|
||||
|
||||
userdata/cloud-config-worker
|
||||
```
|
||||
#cloud-config
|
||||
|
||||
coreos:
|
||||
|
||||
flannel:
|
||||
interrface: $private\_ipv4
|
||||
etcd\_endpoints: {{ .ETCDEndpoints }}
|
||||
```
|
||||
|
||||
$ kube-aws validate
|
||||
|
||||
\> Validating UserData...
|
||||
Error: cloud-config validation errors:
|
||||
UserDataWorker: line 4: warning: unrecognized key "interrface"
|
||||
|
||||
<!-- To get started, check out the [kube-aws documentation](https://coreos.com/kubernetes/docs/latest/kubernetes-on-aws.html). -->
|
||||
考虑如何起步?看看[kube-aws 文档](https://coreos.com/kubernetes/docs/latest/kubernetes-on-aws.html)!
|
||||
|
||||
<!-- **Future Work** -->
|
||||
**未来的工作**
|
||||
|
||||
<!-- As always, the goal with kube-aws is to make deployments that are production ready. While we use kube-aws in production on AWS today, this project is pre-1.0 and there are a number of areas in which kube-aws needs to evolve. -->
|
||||
一如既往,kube-aws的目标是让生产环境部署更加的简单。尽管我们现在在AWS下使用kube-aws进行生产环境部署,但是这个项目还是pre-1.0,所以还有很多的地方,kube-aws需要考虑、扩展。
|
||||
|
||||
<!-- **Fault tolerance** : At CoreOS we believe Kubernetes on AWS is a potent platform for fault-tolerant and self-healing deployments. In the upcoming weeks, kube-aws will be rising to a new challenge: surviving the [Chaos Monkey](https://github.com/Netflix/SimianArmy/wiki/Chaos-Monkey) – control plane and all! -->
|
||||
**容错** : CoreOS坚信 Kubernetes on AWS是强健的平台,适于容错、自恢复部署。在接下来的几个星期,kube-aws将会迎接新的考验:混世猴子([Chaos Monkey](https://github.com/Netflix/SimianArmy/wiki/Chaos-Monkey))测试 - 控制平面以及全部!
|
||||
|
||||
<!-- **Zero-downtime updates** : Updating CoreOS nodes and Kubernetes components can be done without downtime and without interdependency with the correct instance replacement strategy. -->
|
||||
**零停机更新** : 更新CoreOS节点和Kubernetes组件不需要停机,也不需要考虑实例更新策略(instance replacement strategy)的影响。
|
||||
|
||||
<!-- A [github issue](https://github.com/coreos/coreos-kubernetes/issues/340) tracks the work towards this goal. We look forward to seeing you get involved with the project by filing issues or contributing directly. -->
|
||||
有一个[github issue](https://github.com/coreos/coreos-kubernetes/issues/340)来追踪这些工作进展。我们期待你的参与,提交issue,或是直接贡献。
|
||||
|
||||
<!-- _Learn more about Kubernetes and meet the community at [CoreOS Fest Berlin](https://coreos.com/fest/) - May 9-10, 2016_ -->
|
||||
_想要更多地了解Kubernetes,来[柏林CoreOS盛宴](https://coreos.com/fest/)看看,- 五月 9-10, 2016_
|
||||
|
||||
<!-- _– Colin Hom, infrastructure engineer, CoreOS_ -->
|
||||
_– Colin Hom, 基础架构工程师, CoreOS_
|
||||
@@ -0,0 +1,72 @@
|
||||
---
|
||||
title: " Citrix + Kubernetes = 全垒打 "
|
||||
date: 2016-07-14
|
||||
slug: citrix-netscaler-and-kubernetes
|
||||
url: /blog/2016/07/Citrix-Netscaler-And-Kubernetes
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Citrix + Kubernetes = A Home Run "
|
||||
date: 2016-07-14
|
||||
slug: citrix-netscaler-and-kubernetes
|
||||
url: /blog/2016/07/Citrix-Netscaler-And-Kubernetes
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
_Editor’s note: today’s guest post is by Mikko Disini, a Director of Product Management at Citrix Systems, sharing their collaboration experience on a Kubernetes integration. _
|
||||
-->
|
||||
编者按:今天的客座文章来自 Citrix Systems 的产品管理总监 Mikko Disini,他分享了他们在 Kubernetes 集成上的合作经验。 _
|
||||
|
||||
<!--
|
||||
Technical collaboration is like sports. If you work together as a team, you can go down the homestretch and pull through for a win. That’s our experience with the Google Cloud Platform team.
|
||||
-->
|
||||
技术合作就像体育运动。如果你能像一个团队一样合作,你就能在最后关头取得胜利。这就是我们对谷歌云平台团队的经验。
|
||||
|
||||
<!--
|
||||
Recently, we approached Google Cloud Platform (GCP) to collaborate on behalf of Citrix customers and the broader enterprise market looking to migrate workloads. This migration required including the [NetScaler Docker load balancer](https://www.citrix.com/blogs/2016/06/20/the-best-docker-load-balancer-at-dockercon-in-seattle-this-week/), CPX, into Kubernetes nodes and resolving any issues with getting traffic into the CPX proxies.
|
||||
-->
|
||||
最近,我们与 Google 云平台(GCP)联系,代表 Citrix 客户以及更广泛的企业市场,希望就工作负载的迁移进行协作。此迁移需要将 [NetScaler Docker 负载均衡器]https://www.citrix.com/blogs/2016/06/20/the-best-docker-load-balancer-at-dockercon-in-seattle-this-week/) CPX 包含到 Kubernetes 节点中,并解决将流量引入 CPX 代理的任何问题。
|
||||
|
||||
<!--
|
||||
**Why NetScaler and Kubernetes?**
|
||||
-->
|
||||
|
||||
**为什么是 NetScaler 和 Kubernetes**
|
||||
|
||||
<!--
|
||||
1. Citrix customers want the same Layer 4 to Layer 7 capabilities from NetScaler that they have on-prem as they move to the cloud as they begin deploying their container and microservices architecture with Kubernetes
|
||||
2. Kubernetes provides a proven infrastructure for running containers and VMs with automated workload delivery
|
||||
3. NetScaler CPX provides Layer 4 to Layer 7 services and highly efficient telemetry data to a logging and analytics platform, [NetScaler Management and Analytics System](https://www.citrix.com/blogs/2016/05/24/introducing-the-next-generation-netscaler-management-and-analytics-system/)
|
||||
-->
|
||||
|
||||
1. Citrix 的客户希望他们开始使用 Kubernetes 部署他们的容器和微服务体系结构时,能够像当初迁移到云计算时一样,享有 NetScaler 所提供的第 4 层到第 7 层能力
|
||||
2. Kubernetes 提供了一套经过验证的基础设施,可用来运行容器和虚拟机,并自动交付工作负载;
|
||||
3. NetScaler CPX 提供第 4 层到第 7 层的服务,并为日志和分析平台 [NetScaler 管理和分析系统](https://www.citrix.com/blogs/2016/05/24/introducing-the-next-generation-netscaler-management-and-analytics-system/) 提供高效的度量数据。
|
||||
|
||||
<!--
|
||||
I wish all our experiences working together with a technical partner were as good as working with GCP. We had a list of issues to enable our use cases and were able to collaborate swiftly on a solution. To resolve these, GCP team offered in depth technical assistance, working with Citrix such that NetScaler CPX can spin up and take over as a client-side proxy running on each host.
|
||||
-->
|
||||
我希望我们所有与技术合作伙伴一起工作的经验都能像与 GCP 一起工作一样好。我们有一个列表,包含支持我们的用例所需要解决的问题。我们能够快速协作形成解决方案。为了解决这些问题,GCP 团队提供了深入的技术支持,与 Citrix 合作,从而使得 NetScaler CPX 能够在每台主机上作为客户端代理启动运行。
|
||||
|
||||
<!--
|
||||
Next, NetScaler CPX needed to be inserted in the data path of GCP ingress load balancer so that NetScaler CPX can spread traffic to front end web servers. The NetScaler team made modifications so that NetScaler CPX listens to API server events and configures itself to create a VIP, IP table rules and server rules to take ingress traffic and load balance across front end applications. Google Cloud Platform team provided feedback and assistance to verify modifications made to overcome the technical hurdles. Done!
|
||||
-->
|
||||
接下来,需要在 GCP 入口负载均衡器的数据路径中插入 NetScaler CPX,使 NetScaler CPX 能够将流量分散到前端 web 服务器。NetScaler 团队进行了修改,以便 NetScaler CPX 监听 API 服务器事件,并配置自己来创建 VIP、IP 表规则和服务器规则,以便跨前端应用程序接收流量和负载均衡。谷歌云平台团队提供反馈和帮助,验证为克服技术障碍所做的修改。完成了!
|
||||
|
||||
<!--
|
||||
NetScaler CPX use case is supported in [Kubernetes 1.3](https://kubernetes.io/blog/2016/07/kubernetes-1.3-bridging-cloud-native-and-enterprise-workloads). Citrix customers and the broader enterprise market will have the opportunity to leverage NetScaler with Kubernetes, thereby lowering the friction to move workloads to the cloud.
|
||||
-->
|
||||
NetScaler CPX 用例在 [Kubernetes 1.3](https://kubernetes.io/blog/2016/07/kubernets-1.3 - bridge -cloud-native-and-enterprise-workload) 中提供支持。Citrix 的客户和更广泛的企业市场将有机会基于 Kubernetes 享用 NetScaler 服务,从而降低将工作负载转移到云平台的阻力。
|
||||
|
||||
<!--
|
||||
You can learn more about NetScaler CPX [here](https://www.citrix.com/networking/microservices.html).
|
||||
-->
|
||||
您可以在[此处](https://www.citrix.com/networking/microservices.html)了解有关 NetScaler CPX 的更多信息。
|
||||
|
||||
<!--
|
||||
_ -- Mikko Disini, Director of Product Management - NetScaler, Citrix Systems_
|
||||
-->
|
||||
_ -- Mikko Disini,Citrix Systems NetScaler 产品管理总监
|
||||
|
||||
@@ -0,0 +1,139 @@
|
||||
---
|
||||
title: " Dashboard - Kubernetes 的全功能 Web 界面 "
|
||||
date: 2016-07-15
|
||||
slug: dashboard-web-interface-for-kubernetes
|
||||
url: /blog/2016/07/Dashboard-Web-Interface-For-Kubernetes
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Dashboard - Full Featured Web Interface for Kubernetes "
|
||||
date: 2016-07-15
|
||||
slug: dashboard-web-interface-for-kubernetes
|
||||
url: /blog/2016/07/Dashboard-Web-Interface-For-Kubernetes
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
_Editor’s note: this post is part of a [series of in-depth articles](https://kubernetes.io/blog/2016/07/five-days-of-kubernetes-1.3) on what's new in Kubernetes 1.3_
|
||||
|
||||
[Kubernetes Dashboard](http://github.com/kubernetes/dashboard) is a project that aims to bring a general purpose monitoring and operational web interface to the Kubernetes world. Three months ago we [released](https://kubernetes.io/blog/2016/04/building-awesome-user-interfaces-for-kubernetes) the first production ready version, and since then the dashboard has made massive improvements. In a single UI, you’re able to perform majority of possible interactions with your Kubernetes clusters without ever leaving your browser. This blog post breaks down new features introduced in the latest release and outlines the roadmap for the future.
|
||||
-->
|
||||
|
||||
_编者按:这篇文章是[一系列深入的文章](https://kubernetes.io/blog/2016/07/five-days-of-kubernetes-1.3) 中关于Kubernetes 1.3的新内容的一部分_
|
||||
[Kubernetes Dashboard](http://github.com/kubernetes/dashboard)是一个旨在为 Kubernetes 世界带来通用监控和操作 Web 界面的项目。三个月前,我们[发布](https://kubernetes.io/blog/2016/04/building-awesome-user-interfaces-for-kubernetes)第一个面向生产的版本,从那时起 dashboard 已经做了大量的改进。在一个 UI 中,您可以在不离开浏览器的情况下,与 Kubernetes 集群执行大多数可能的交互。这篇博客文章分解了最新版本中引入的新功能,并概述了未来的路线图。
|
||||
|
||||
<!--
|
||||
**Full-Featured Dashboard**
|
||||
|
||||
Thanks to a large number of contributions from the community and project members, we were able to deliver many new features for [Kubernetes 1.3 release](https://kubernetes.io/blog/2016/07/kubernetes-1.3-bridging-cloud-native-and-enterprise-workloads). We have been carefully listening to all the great feedback we have received from our users (see the [summary infographics](http://static.lwy.io/img/kubernetes_dashboard_infographic.png)) and addressed the highest priority requests and pain points.
|
||||
-->
|
||||
|
||||
**全功能的 Dashboard**
|
||||
|
||||
由于社区和项目成员的大量贡献,我们能够为[Kubernetes 1.3发行版](https://kubernetes.io/blog/2016/07/kubernetes-1.3-bridging-cloud-native-and-enterprise-workloads)提供许多新功能。我们一直在认真听取用户的反馈(参见[摘要信息图表](http://static.lwy.io/img/kubernetes_dashboard_infographic.png)),并解决了最高优先级的请求和难点。
|
||||
-->
|
||||
|
||||
<!--
|
||||
The Dashboard UI now handles all workload resources. This means that no matter what workload type you run, it is visible in the web interface and you can do operational changes on it. For example, you can modify your stateful MySQL installation with [Pet Sets](/docs/user-guide/petset/), do a rolling update of your web server with Deployments or install cluster monitoring with DaemonSets.
|
||||
|
||||
|
||||
|
||||
[ ](https://lh3.googleusercontent.com/p9bMGxPx4jE6_Z2KB-MktmyuAxyFst-bEk29M_Bn0Bj5ul7uzinH6u5WjHsMmqhGvBwlABZt06dwQ5qkBZiLq_EM1oddCmpwChvXDNXZypaS5l8uzkKuZj3PBUmzTQT4dgDxSXgz)
|
||||
-->
|
||||
|
||||
Dashboard UI 现在处理所有工作负载资源。这意味着无论您运行什么工作负载类型,它都在 web 界面中可见,并且您可以对其进行操作更改。例如,可以使用[Pet Sets](/docs/user-guide/petset/)修改有状态的 mysql 安装,使用部署对 web 服务器进行滚动更新,或使用守护程序安装群集监视。
|
||||
|
||||
|
||||
|
||||
[ ](https://lh3.googleusercontent.com/p9bMGxPx4jE6_Z2KB-MktmyuAxyFst-bEk29M_Bn0Bj5ul7uzinH6u5WjHsMmqhGvBwlABZt06dwQ5qkBZiLq_EM1oddCmpwChvXDNXZypaS5l8uzkKuZj3PBUmzTQT4dgDxSXgz)
|
||||
|
||||
<!--
|
||||
In addition to viewing resources, you can create, edit, update, and delete them. This feature enables many use cases. For example, you can kill a failed Pod, do a rolling update on a Deployment, or just organize your resources. You can also export and import YAML configuration files of your cloud apps and store them in a version control system.
|
||||
|
||||
|
||||
|
||||

|
||||
-->
|
||||
|
||||
除了查看资源外,还可以创建、编辑、更新和删除资源。这个特性支持许多用例。例如,您可以杀死一个失败的 pod,对部署进行滚动更新,或者只组织资源。您还可以导出和导入云应用程序的 yaml 配置文件,并将它们存储在版本控制系统中。
|
||||
|
||||
|
||||
|
||||

|
||||
|
||||
<!--
|
||||
The release includes a beta view of cluster nodes for administration and operational use cases. The UI lists all nodes in the cluster to allow for overview analysis and quick screening for problematic nodes. The details view shows all information about the node and links to pods running on it.
|
||||
|
||||
|
||||
|
||||

|
||||
-->
|
||||
|
||||
这个版本包括一个用于管理和操作用例的集群节点的 beta 视图。UI 列出集群中的所有节点,以便进行总体分析和快速筛选有问题的节点。details 视图显示有关该节点的所有信息以及指向在其上运行的 pod 的链接。
|
||||
|
||||
|
||||
|
||||

|
||||
|
||||
<!--
|
||||
There are also many smaller scope new features that the we shipped with the release, namely: support for namespaced resources, internationalization, performance improvements, and many bug fixes (find out more in the [release notes](https://github.com/kubernetes/dashboard/releases/tag/v1.1.0)). All these improvements result in a better and simpler user experience of the product.
|
||||
-->
|
||||
|
||||
我们随发行版提供的还有许多小范围的新功能,即:支持命名空间资源、国际化、性能改进和许多错误修复(请参阅[发行说明](https://github.com/kubernetes/dashboard/releases/tag/v1.1.0)中的更多内容)。所有这些改进都会带来更好、更简单的产品用户体验。
|
||||
|
||||
<!--
|
||||
**Future Work**
|
||||
|
||||
|
||||
|
||||
The team has ambitious plans for the future spanning across multiple use cases. We are also open to all feature requests, which you can post on our [issue tracker](https://github.com/kubernetes/dashboard/issues).
|
||||
-->
|
||||
|
||||
**Future Work**
|
||||
|
||||
|
||||
|
||||
该团队对跨越多个用例的未来有着雄心勃勃的计划。我们还对所有功能请求开放,您可以在我们的[问题跟踪程序](https://github.com/kubernetes/dashboard/issues)上发布这些请求。
|
||||
|
||||
<!--
|
||||
Here is a list of our focus areas for the following months:
|
||||
|
||||
- [Handle more Kubernetes resources](https://github.com/kubernetes/dashboard/issues/961) - To show all resources that a cluster user may potentially interact with. Once done, Dashboard can act as a complete replacement for CLI.
|
||||
- [Monitoring and troubleshooting](https://github.com/kubernetes/dashboard/issues/962) - To add resource usage statistics/graphs to the objects shown in Dashboard. This focus area will allow for actionable debugging and troubleshooting of cloud applications.
|
||||
- [Security, auth and logging in](https://github.com/kubernetes/dashboard/issues/964) - Make Dashboard accessible from networks external to a Cluster and work with custom authentication systems.
|
||||
-->
|
||||
|
||||
以下是我们接下来几个月的重点领域:
|
||||
|
||||
- [Handle more Kubernetes resources](https://github.com/kubernetes/dashboard/issues/961) - 显示群集用户可能与之交互的所有资源。一旦完成,dashboard 就可以完全替代cli。
|
||||
- [Monitoring and troubleshooting](https://github.com/kubernetes/dashboard/issues/962) - 将资源使用统计信息/图表添加到 Dashboard 中显示的对象。这个重点领域将允许对云应用程序进行可操作的调试和故障排除。
|
||||
- [Security, auth and logging in](https://github.com/kubernetes/dashboard/issues/964) - 使仪表板可从群集外部的网络访问,并使用自定义身份验证系统。
|
||||
|
||||
<!--
|
||||
**Connect With Us**
|
||||
|
||||
|
||||
|
||||
We would love to talk with you and hear your feedback!
|
||||
|
||||
- Email us at the [SIG-UI mailing list](https://groups.google.com/forum/#!forum/kubernetes-sig-ui)
|
||||
- Chat with us on the Kubernetes Slack [#SIG-UI channel](https://kubernetes.slack.com/messages/sig-ui/)
|
||||
- Join our meetings: 4PM CEST. See the [SIG-UI calendar](https://calendar.google.com/calendar/embed?src=google.com_52lm43hc2kur57dgkibltqc6kc%40group.calendar.google.com&ctz=Europe/Warsaw) for details.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
_-- Piotr Bryk, Software Engineer, Google_
|
||||
-->
|
||||
|
||||
**联系我们**
|
||||
|
||||
|
||||
|
||||
我们很乐意与您交谈并听取您的反馈!
|
||||
|
||||
- 请在[SIG-UI邮件列表](https://groups.google.com/forum/向我们发送电子邮件!论坛/kubernetes sig ui)
|
||||
- 在 kubernetes slack 上与我们聊天。[#SIG-UI channel](https://kubernetes.slack.com/messages/sig-ui/)
|
||||
- 参加我们的会议:东部时间下午4点。请参阅[SIG-UI日历](https://calendar.google.com/calendar/embed?src=google.com_52lm43hc2kur57dgkibltqc6kc%40group.calendar.google.com&ctz=Europe/Warsaw)了解详细信息。
|
||||
@@ -0,0 +1,89 @@
|
||||
---
|
||||
title: " Kubernetes 生日快乐。哦,这是你要去的地方! "
|
||||
date: 2016-07-21
|
||||
slug: oh-the-places-you-will-go
|
||||
url: /blog/2016/07/Oh-The-Places-You-Will-Go
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Happy Birthday Kubernetes. Oh, the places you’ll go! "
|
||||
date: 2016-07-21
|
||||
slug: oh-the-places-you-will-go
|
||||
url: /blog/2016/07/Oh-The-Places-You-Will-Go
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
_Editor’s note, Today’s guest post is from an independent Kubernetes contributor, Justin Santa Barbara, sharing his reflection on growth of the project from inception to its future._
|
||||
|
||||
**Dear K8s,**
|
||||
|
||||
_It’s hard to believe you’re only one - you’ve grown up so fast. On the occasion of your first birthday, I thought I would write a little note about why I was so excited when you were born, why I feel fortunate to be part of the group that is raising you, and why I’m eager to watch you continue to grow up!_
|
||||
-->
|
||||
|
||||
_编者按,今天的嘉宾帖子来自一位独立的 kubernetes 撰稿人 Justin Santa Barbara,分享了他对项目从一开始到未来发展的思考。_
|
||||
|
||||
**亲爱的 K8s,**
|
||||
|
||||
_很难相信你是唯一的一个 - 成长这么快的。在你一岁生日的时候,我想我可以写一个小纸条,告诉你为什么我在你出生的时候那么兴奋,为什么我觉得很幸运能成为抚养你长大的一员,为什么我渴望看到你继续成长!_
|
||||
|
||||
<!--
|
||||
_--Justin_
|
||||
|
||||
You started with an excellent foundation - good declarative functionality, built around a solid API with a well defined schema and the machinery so that we could evolve going forwards. And sure enough, over your first year you grew so fast: autoscaling, HTTP load-balancing support (Ingress), support for persistent workloads including clustered databases (PetSets). You’ve made friends with more clouds (welcome Azure & OpenStack to the family), and even started to span zones and clusters (Federation). And these are just some of the most visible changes - there’s so much happening inside that brain of yours!
|
||||
|
||||
I think it’s wonderful you’ve remained so open in all that you do - you seem to write down everything on GitHub - for better or worse. I think we’ve all learned a lot about that on the way, like the perils of having engineers make scaling statements that are then weighed against claims made without quite the same framework of precision and rigor. But I’m proud that you chose not to lower your standards, but rose to the challenge and just ran faster instead - it might not be the most realistic approach, but it is the only way to move mountains!
|
||||
-->
|
||||
|
||||
_--Justin_
|
||||
|
||||
你从一个优秀的基础 - 良好的声明性功能开始,它是围绕一个具有良好定义的模式和机制的坚实的 API 构建的,这样我们就可以向前发展了。果然,在你的第一年里,你增长得如此之快:autoscaling、HTTP load-balancing support (Ingress)、support for persistent workloads including clustered databases (PetSets)。你已经和更多的云交了朋友(欢迎 azure 和 openstack 加入家庭),甚至开始跨越区域和集群(Federation)。这些只是一些最明显的变化 - 在你的大脑里发生了太多的变化!
|
||||
|
||||
我觉得你一直保持开放的态度真是太好了 - 你好像把所有的东西都写在 github 上 - 不管是好是坏。我想我们在这方面都学到了很多,比如让工程师做缩放声明的风险,然后在没有完全相同的精确性和严谨性框架的情况下,将这些声明与索赔进行权衡。但我很自豪你选择了不降低你的标准,而是上升到挑战,只是跑得更快 - 这可能不是最现实的办法,但这是唯一的方式能移动山!
|
||||
|
||||
<!--
|
||||
And yet, somehow, you’ve managed to avoid a lot of the common dead-ends that other open source software has fallen into, particularly as those projects got bigger and the developers end up working on it more than they use it directly. How did you do that? There’s a probably-apocryphal story of an employee at IBM that makes a huge mistake, and is summoned to meet with the big boss, expecting to be fired, only to be told “We just spent several million dollars training you. Why would we want to fire you?”. Despite all the investment google is pouring into you (along with Redhat and others), I sometimes wonder if the mistakes we are avoiding could be worth even more. There is a very open development process, yet there’s also an “oracle” that will sometimes course-correct by telling us what happens two years down the road if we make a particular design decision. This is a parent you should probably listen to!
|
||||
-->
|
||||
|
||||
然而,不知何故,你已经设法避免了许多其他开源软件陷入的共同死胡同,特别是当那些项目越来越大,开发人员最终要做的比直接使用它更多的时候。你是怎么做到的?有一个很可能是虚构的故事,讲的是 IBM 的一名员工犯了一个巨大的错误,被传唤去见大老板,希望被解雇,却被告知“我们刚刚花了几百万美元培训你。我们为什么要解雇你?“。尽管谷歌对你进行了大量的投资(包括 redhat 和其他公司),但我有时想知道,我们正在避免的错误是否更有价值。有一个非常开放的开发过程,但也有一个“oracle”,它有时会通过告诉我们两年后如果我们做一个特定的设计决策会发生什么来纠正错误。这是你应该听的父母!
|
||||
|
||||
<!--
|
||||
And so although you’re only a year old, you really have an [old soul](http://queue.acm.org/detail.cfm?id=2898444). I’m just one of the [many people raising you](https://kubernetes.io/blog/2016/07/happy-k8sbday-1), but it’s a wonderful learning experience for me to be able to work with the people that have built these incredible systems and have all this domain knowledge. Yet because we started from scratch (rather than taking the existing Borg code) we’re at the same level and can still have genuine discussions about how to raise you. Well, at least as close to the same level as we could ever be, but it’s to their credit that they are all far too nice ever to mention it!
|
||||
|
||||
If I would pick just two of the wise decisions those brilliant people made:
|
||||
-->
|
||||
|
||||
所以,尽管你只有一岁,你真的有一个[旧灵魂](http://queue.acm.org/detail.cfm?ID=2898444)。我只是[很多人抚养你]中的一员(https://kubernetes.io/blog/2016/07/happy-k8sbday-1),但对我来说,能够与那些建立了这些令人难以置信的系统并拥有所有这些领域知识的人一起工作是一次极好的学习经历。然而,因为我们是白手起家(而不是采用现有的 Borg 代码),我们处于同一水平,仍然可以就如何培养你进行真正的讨论。好吧,至少和我们的水平一样接近,但值得称赞的是,他们都太好了,从来没提过!
|
||||
|
||||
如果我选择两个聪明人做出的明智决定:
|
||||
|
||||
<!--
|
||||
- Labels & selectors give us declarative “pointers”, so we can say “why” we want things, rather than listing the things directly. It’s the secret to how you can scale to [great heights](https://kubernetes.io/blog/2016/07/thousand-instances-of-cassandra-using-kubernetes-pet-set); not by naming each step, but saying “a thousand more steps just like that first one”.
|
||||
- Controllers are state-synchronizers: we specify the goals, and your controllers will indefatigably work to bring the system to that state. They work through that strongly-typed API foundation, and are used throughout the code, so Kubernetes is more of a set of a hundred small programs than one big one. It’s not enough to scale to thousands of nodes technically; the project also has to scale to thousands of developers and features; and controllers help us get there.
|
||||
-->
|
||||
|
||||
- 标签和选择器给我们声明性的“pointers”,所以我们可以说“为什么”我们想要东西,而不是直接列出东西。这是如何扩展到[伟大高度]的秘密(https://kubernetes.io/blog/2016/07/thousand-instances-of-cassandra-using-kubernetes-pet-set);不是命名每一步,而是说“像第一步一样多走一千步”。
|
||||
- 控制器是状态同步器:我们指定目标,您的控制器将不遗余力地工作,使系统达到该状态。它们工作在强类型 API 基础上,并且贯穿整个代码,因此 Kubernetes 比一个大的程序多一百个小程序。仅仅从技术上扩展到数千个节点是不够的;这个项目还必须扩展到数千个开发人员和特性;控制器帮助我们达到目的。
|
||||
|
||||
<!--
|
||||
And so on we will go! We’ll be replacing those controllers and building on more, and the API-foundation lets us build anything we can express in that way - with most things just a label or annotation away! But your thoughts will not be defined by language: with third party resources you can express anything you choose. Now we can build Kubernetes without building in Kubernetes, creating things that feel as much a part of Kubernetes as anything else. Many of the recent additions, like ingress, DNS integration, autoscaling and network policies were done or could be done in this way. Eventually it will be hard to imagine you before these things, but tomorrow’s standard functionality can start today, with no obstacles or gatekeeper, maybe even for an audience of one.
|
||||
|
||||
So I’m looking forward to seeing more and more growth happen further and further from the core of Kubernetes. We had to work our way through those phases; starting with things that needed to happen in the kernel of Kubernetes - like replacing replication controllers with deployments. Now we’re starting to build things that don’t require core changes. But we’re still still talking about infrastructure separately from applications. It’s what comes next that gets really interesting: when we start building applications that rely on the Kubernetes APIs. We’ve always had the Cassandra example that uses the Kubernetes API to self-assemble, but we haven’t really even started to explore this more widely yet. In the same way that the S3 APIs changed how we build things that remember, I think the k8s APIs are going to change how we build things that think.
|
||||
-->
|
||||
|
||||
等等我们就走!我们将取代那些控制器,建立更多,API 基金会让我们构建任何我们可以用这种方式表达的东西 - 大多数东西只是标签或注释远离!但你的思想不会由语言来定义:有了第三方资源,你可以表达任何你选择的东西。现在我们可以不用在 Kubernetes 建造Kubernetes 了,创造出与其他任何东西一样感觉是 Kubernetes 的一部分的东西。最近添加的许多功能,如ingress、DNS integration、autoscaling and network policies ,都已经完成或可以通过这种方式完成。最终,在这些事情发生之前很难想象你会是怎样的一个人,但是明天的标准功能可以从今天开始,没有任何障碍或看门人,甚至对一个听众来说也是这样。
|
||||
|
||||
所以我期待着看到越来越多的增长发生在离 Kubernetes 核心越来越远的地方。我们必须通过这些阶段来工作;从需要在 kubernetes 内核中发生的事情开始——比如用部署替换复制控制器。现在我们开始构建不需要核心更改的东西。但我们仍然在讨论基础设施和应用程序。接下来真正有趣的是:当我们开始构建依赖于 kubernetes api 的应用程序时。我们一直有使用 kubernetes api 进行自组装的 cassandra 示例,但我们还没有真正开始更广泛地探讨这个问题。正如 S3 APIs 改变了我们构建记忆事物的方式一样,我认为 k8s APIs 也将改变我们构建思考事物的方式。
|
||||
|
||||
<!--
|
||||
So I’m looking forward to your second birthday: I can try to predict what you’ll look like then, but I know you’ll surpass even the most audacious things I can imagine. Oh, the places you’ll go!
|
||||
|
||||
|
||||
_-- Justin Santa Barbara, Independent Kubernetes Contributor_
|
||||
-->
|
||||
|
||||
所以我很期待你的二岁生日:我可以试着预测你那时的样子,但我知道你会超越我所能想象的最大胆的东西。哦,这是你要去的地方!
|
||||
|
||||
|
||||
_-- Justin Santa Barbara, 独立的 Kubernetes 贡献者_
|
||||
@@ -0,0 +1,72 @@
|
||||
---
|
||||
title: " Kubernetes 1.8 的五天 "
|
||||
date: 2017-10-24
|
||||
slug: five-days-of-kubernetes-18
|
||||
url: /blog/2017/10/Five-Days-Of-Kubernetes-18
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Five Days of Kubernetes 1.8 "
|
||||
date: 2017-10-24
|
||||
slug: five-days-of-kubernetes-18
|
||||
url: /blog/2017/10/Five-Days-Of-Kubernetes-18
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
Kubernetes 1.8 is live, made possible by hundreds of contributors pushing thousands of commits in this latest releases.
|
||||
-->
|
||||
Kubernetes 1.8 已经推出,数百名贡献者在这个最新版本中推出了成千上万的提交。
|
||||
|
||||
<!--
|
||||
The community has tallied more than 66,000 commits in the main repo and continues rapid growth outside of the main repo, which signals growing maturity and stability for the project. The community has logged more than 120,000 commits across all repos and 17,839 commits across all repos for v1.7.0 to v1.8.0 alone.
|
||||
-->
|
||||
社区已经有超过 66,000 个提交在主仓库,并在主仓库之外继续快速增长,这标志着该项目日益成熟和稳定。仅 v1.7.0 到 v1.8.0,社区就记录了所有仓库的超过 120,000 次提交和 17839 次提交。
|
||||
|
||||
<!--
|
||||
With the help of our growing community of 1,400 plus contributors, we issued more than 3,000 PRs and pushed more than 5,000 commits to deliver Kubernetes 1.8 with significant security and workload support updates. This all points to increased stability, a result of our project-wide focus on maturing [process](https://github.com/kubernetes/sig-release), formalizing [architecture](https://github.com/kubernetes/community/tree/master/sig-architecture), and strengthening Kubernetes’ [governance model](https://github.com/kubernetes/community/tree/master/community/elections/2017).
|
||||
-->
|
||||
在拥有 1400 多名贡献者,并且不断发展壮大的社区的帮助下,我们合并了 3000 多个 PR,并发布了 5000 多个提交,最后的 Kubernetes 1.8 在安全和工作负载方面添加了很多的更新。
|
||||
这一切都表明稳定性的提高,这是我们整个项目关注成熟[流程](https://github.com/kubernetes/sig-release)、形式化[架构](https://github.com/kubernetes/community/tree/master/sig-architecture)和加强 Kubernetes 的[治理模型](https://github.com/kubernetes/community/tree/master/community/elections/2017)的结果。
|
||||
|
||||
<!--
|
||||
While many improvements have been contributed, we highlight key features in this series of in-depth posts listed below. [Follow along](https://twitter.com/kubernetesio) and see what’s new and improved with storage, security and more.
|
||||
-->
|
||||
虽然有很多改进,但我们在下面列出的这一系列深度文章中突出了一些关键特性。[跟随](https://twitter.com/kubernetesio)并了解存储,安全等方面的新功能和改进功能。
|
||||
|
||||
<!--
|
||||
**Day 1:** [5 Days of Kubernetes 1.8](https://kubernetes.io/blog/2017/10/five-days-of-kubernetes-18)
|
||||
**Day 2:** [kubeadm v1.8 Introduces Easy Upgrades for Kubernetes Clusters](https://kubernetes.io/blog/2017/10/kubeadm-v18-released)
|
||||
**Day 3:** [Kubernetes v1.8 Retrospective: It Takes a Village to Raise a Kubernetes](https://kubernetes.io/blog/2017/10/it-takes-village-to-raise-kubernetes)
|
||||
**Day 4:** [Using RBAC, Generally Available in Kubernetes v1.8](https://kubernetes.io/blog/2017/10/using-rbac-generally-available-18)
|
||||
**Day 5:** [Enforcing Network Policies in Kubernetes](https://kubernetes.io/blog/2017/10/enforcing-network-policies-in-kubernetes)
|
||||
-->
|
||||
|
||||
**第一天:** [Kubernetes 1.8 的五天](https://kubernetes.io/blog/2017/10/five-days-of-kubernetes-18)
|
||||
**第二天:** [kubeadm v1.8 为 Kubernetes 集群引入了简单的升级](https://kubernetes.io/blog/2017/10/kubeadm-v18-released)
|
||||
**第三天:** [Kubernetes v1.8 回顾:提升一个 Kubernetes 需要一个 Village](https://kubernetes.io/blog/2017/10/it-takes-village-to-raise-kubernetes)
|
||||
**第四天:** [使用 RBAC,一般在 Kubernetes v1.8 中提供](https://kubernetes.io/blog/2017/10/using-rbac-generally-available-18)
|
||||
**第五天:** [在 Kubernetes 执行网络策略](https://kubernetes.io/blog/2017/10/enforcing-network-policies-in-kubernetes)
|
||||
|
||||
<!--
|
||||
**Connect**
|
||||
-->
|
||||
|
||||
**链接**
|
||||
|
||||
<!--
|
||||
- Post questions (or answer questions) on [Stack Overflow](http://stackoverflow.com/questions/tagged/kubernetes)
|
||||
- Join the community portal for advocates on [K8sPort](http://k8sport.org/)
|
||||
- Follow us on Twitter [@Kubernetesio](https://twitter.com/kubernetesio) for latest updates
|
||||
- Connect with the community on [Slack](http://slack.k8s.io/)
|
||||
- Get involved with the Kubernetes project on [GitHub](https://github.com/kubernetes/kubernetes)
|
||||
-->
|
||||
|
||||
- 在 [Stack Overflow](http://stackoverflow.com/questions/tagged/kubernetes) 上发布问题(或回答问题)
|
||||
- 加入 [K8sPort](http://k8sport.org/) 布道师的社区门户网站
|
||||
- 在 Twitter [@Kubernetesio](https://twitter.com/kubernetesio) 关注我们以获取最新更新
|
||||
- 与 [Slack](http://slack.k8s.io/) 上的社区联系
|
||||
- 参与 [GitHub](https://github.com/kubernetes/kubernetes) 上的 Kubernetes 项目
|
||||
|
||||
|
||||
@@ -0,0 +1,32 @@
|
||||
---
|
||||
title: " Kubernetes 中自动缩放 "
|
||||
date: 2017-11-17
|
||||
slug: autoscaling-in-kubernetes
|
||||
url: /blog/2017/11/Autoscaling-In-Kubernetes
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: " Autoscaling in Kubernetes "
|
||||
date: 2017-11-17
|
||||
slug: autoscaling-in-kubernetes
|
||||
url: /blog/2017/11/Autoscaling-In-Kubernetes
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
Kubernetes allows developers to automatically adjust cluster sizes and the number of pod replicas based on current traffic and load. These adjustments reduce the amount of unused nodes, saving money and resources. In this talk, Marcin Wielgus of Google walks you through the current state of pod and node autoscaling in Kubernetes: .how it works, and how to use it, including best practices for deployments in production applications.
|
||||
-->
|
||||
Kubernetes 允许开发人员根据当前的流量和负载自动调整集群大小和 pod 副本的数量。这些调整减少了未使用节点的数量,节省了资金和资源。
|
||||
在这次演讲中,谷歌的 Marcin Wielgus 将带领您了解 Kubernetes 中 pod 和 node 自动调焦的当前状态:它是如何工作的,以及如何使用它,包括在生产应用程序中部署的最佳实践。
|
||||
|
||||
<!--
|
||||
Enjoyed this talk? Join us for more exciting sessions on scaling and automating your Kubernetes clusters at KubeCon in Austin on December 6-8. [Register Now](https://www.eventbrite.com/e/kubecon-cloudnativecon-north-america-registration-37824050754?_ga=2.9666039.317115486.1510003873-1623727562.1496428006)
|
||||
-->
|
||||
喜欢这个演讲吗? 12 月 6 日至 8 日,在 Austin 参加 KubeCon 关于扩展和自动化您的 Kubernetes 集群的更令人兴奋的会议。[现在注册](https://www.eventbrite.com/e/kubecon-cloudnativecon-north-america-registration-37824050754?_ga=2.9666039.317115486.1510003873-1623727562.1496428006)。
|
||||
|
||||
<!--
|
||||
Be sure to check out [Automating and Testing Production Ready Kubernetes Clusters in the Public Cloud](http://sched.co/CU64) by Ron Lipke, Senior Developer, Platform as a Service, Gannet/USA Today Network.
|
||||
-->
|
||||
一定要查看由 Ron Lipke, Gannet/USA Today Network, 平台即服务高级开发人员,在[公共云中自动化和测试产品就绪的 Kubernetes 集群](http://sched.co/CU64)。
|
||||
|
||||
@@ -1,81 +0,0 @@
|
||||
---
|
||||
title: "Principles of Container-based Application Design"
|
||||
date: 2018-03-15
|
||||
slug: principles-of-container-app-design
|
||||
url: /blog/2018/03/Principles-Of-Container-App-Design
|
||||
---
|
||||
|
||||
<!-- It's possible nowadays to put almost any application in a container and run it. Creating cloud-native applications, however—containerized applications that are automated and orchestrated effectively by a cloud-native platform such as Kubernetes—requires additional effort. Cloud-native applications anticipate failure; they run and scale reliably even when their infrastructure experiences outages. To offer such capabilities, cloud-native platforms like Kubernetes impose a set of contracts and constraints on applications. These contracts ensure that applications they run conform to certain constraints and allow the platform to automate application management. -->
|
||||
|
||||
现如今,几乎所有的的应用程序都可以在容器中运行。但创建云原生应用,通过诸如 Kubernetes 的云原生平台更有效地自动化运行、管理容器化的应用却需要额外的工作。
|
||||
云原生应用需要考虑故障;即使是在底层架构发生故障时也需要可靠地运行。
|
||||
为了提供这样的功能,像 Kubernetes 这样的云原生平台需要向运行的应用程序强加一些契约和约束。
|
||||
这些契约确保应用可以在符合某些约束的条件下运行,从而使得平台可以自动化应用管理。
|
||||
|
||||
<!-- I've outlined [seven principles][1]for containerized applications to follow in order to be fully cloud-native. -->
|
||||
|
||||
我已经为容器化应用如何之为云原生应用概括出了[七项原则][1]。
|
||||
|
||||
| ----- |
|
||||
| ![][2] |
|
||||
| Container Design Principles |
|
||||
|
||||
|
||||
<!-- These seven principles cover both build time and runtime concerns. -->
|
||||
|
||||
这里所述的七项原则涉及到构建时和运行时,两类关注点。
|
||||
|
||||
<!-- #### Build time -->
|
||||
#### 构建时
|
||||
|
||||
<!-- * **Single Concern:** Each container addresses a single concern and does it well.
|
||||
* **Self-Containment:** A container relies only on the presence of the Linux kernel. Additional libraries are added when the container is built.
|
||||
* **Image Immutability:** Containerized applications are meant to be immutable, and once built are not expected to change between different environments. -->
|
||||
|
||||
* **单一关注点:** 每个容器只解决一个关注点,并且完成的很好。
|
||||
* **自包含:** 一个容器只依赖Linux内核。额外的库要求可以在构建容器时加入。
|
||||
* **镜像不变性:** 容器化的应用意味着不变性,一旦构建完成,不需要根据环境的不同而重新构建。
|
||||
|
||||
<!-- #### Runtime -->
|
||||
#### 运行时
|
||||
|
||||
<!-- * **High Observability:** Every container must implement all necessary APIs to help the platform observe and manage the application in the best way possible.
|
||||
* **Lifecycle Conformance:** A container must have a way to read events coming from the platform and conform by reacting to those events.
|
||||
* **Process Disposability:** Containerized applications must be as ephemeral as possible and ready to be replaced by another container instance at any point in time.
|
||||
* **Runtime Confinement:** Every container must declare its resource requirements and restrict resource use to the requirements indicated. -->
|
||||
|
||||
* **高可观测性:** 每个容器必须实现所有必要的 API 来帮助平台以最好的方式来观测、管理应用。
|
||||
* **生命周期一致性:** 一个容器必须要能从平台中获取事件信息,并作出相应的反应。
|
||||
* **进程易处理性:** 容器化应用的寿命一定要尽可能的短暂,这样,可以随时被另一个容器所替换。
|
||||
* **运行时限制:** 每个容器都必须要声明自己的资源需求,并将资源使用限制在所需要的范围之内。
|
||||
|
||||
<!-- The build time principles ensure that containers have the right granularity, consistency, and structure in place. The runtime principles dictate what functionalities must be implemented in order for containerized applications to possess cloud-native function. Adhering to these principles helps ensure that your applications are suitable for automation in Kubernetes. -->
|
||||
|
||||
编译时原则保证了容器拥有合适的粒度,一致性以及结构。运行时原则明确了容器化必须要实现那些功能才能成为云原生函数。遵循这些原则可以帮助你的应用适应 Kubernetes 上的自动化。
|
||||
|
||||
<!-- The white paper is freely available for download: -->
|
||||
|
||||
白皮书可以免费下载:
|
||||
|
||||
<!-- To read more about designing cloud-native applications for Kubernetes, check out my [Kubernetes Patterns][3] book. -->
|
||||
|
||||
想要了解更多关于如何面向 Kubernetes 设计云原生应用,可以看看我的 [Kubernetes 模式][3] 一书。
|
||||
|
||||
<!-- — [Bilgin Ibryam][4], Principal Architect, Red Hat -->
|
||||
|
||||
— [Bilgin Ibryam][4], 首席架构师, Red Hat
|
||||
|
||||
Twitter:
|
||||
Blog: [http://www.ofbizian.com][5]
|
||||
Linkedin:
|
||||
|
||||
<!-- Bilgin Ibryam (@bibryam) is a principal architect at Red Hat, open source committer at ASF, blogger, author, and speaker. He is the author of Camel Design Patterns and Kubernetes Patterns books. In his day-to-day job, Bilgin enjoys mentoring, training and leading teams to be successful with distributed systems, microservices, containers, and cloud-native applications in general. -->
|
||||
|
||||
Bilgin Ibryam (@bibryam) 是 Red Hat 的一名首席架构师, ASF 的开源贡献者,博主,作者以及演讲者。
|
||||
他是 Camel 设计模式、 Kubernetes 模式的作者。在他的日常生活中,他非常享受指导、培训以及帮助各个团队更加成功地使用分布式系统、微服务、容器,以及云原生应用。
|
||||
|
||||
[1]: https://www.redhat.com/en/resources/cloud-native-container-design-whitepaper
|
||||
[2]: https://lh5.googleusercontent.com/1XqojkVC0CET1yKCJqZ3-0VWxJ3W8Q74zPLlqnn6eHSJsjHOiBTB7EGUX5o_BOKumgfkxVdgBeLyoyMfMIXwVm9p2QXkq_RRy2mDJG1qEExJDculYL5PciYcWfPAKxF2-DGIdiLw
|
||||
[3]: http://leanpub.com/k8spatterns/
|
||||
[4]: http://twitter.com/bibryam
|
||||
[5]: http://www.ofbizian.com/
|
||||
@@ -0,0 +1,728 @@
|
||||
---
|
||||
title: 在 Kubernetes 上开发
|
||||
date: 2018-05-01
|
||||
slug: developing-on-kubernetes
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: Developing on Kubernetes
|
||||
date: 2018-05-01
|
||||
slug: developing-on-kubernetes
|
||||
---
|
||||
-->
|
||||
|
||||
<!--**Authors**:-->
|
||||
**作者**: [Michael Hausenblas](https://twitter.com/mhausenblas) (Red Hat), [Ilya Dmitrichenko](https://twitter.com/errordeveloper) (Weaveworks)
|
||||
|
||||
<!--
|
||||
How do you develop a Kubernetes app? That is, how do you write and test an app that is supposed to run on Kubernetes? This article focuses on the challenges, tools and methods you might want to be aware of to successfully write Kubernetes apps alone or in a team setting.
|
||||
-->
|
||||
|
||||
您将如何开发一个 Kubernates 应用?也就是说,您如何编写并测试一个要在 Kubernates 上运行的应用程序?本文将重点介绍在独自开发或者团队协作中,您可能希望了解到的为了成功编写 Kubernetes 应用程序而需面临的挑战,工具和方法。
|
||||
|
||||
<!--
|
||||
We’re assuming you are a developer, you have a favorite programming language, editor/IDE, and a testing framework available. The overarching goal is to introduce minimal changes to your current workflow when developing the app for Kubernetes. For example, if you’re a Node.js developer and are used to a hot-reload setup—that is, on save in your editor the running app gets automagically updated—then dealing with containers and container images, with container registries, Kubernetes deployments, triggers, and more can not only be overwhelming but really take all the fun out if it.
|
||||
-->
|
||||
|
||||
我们假定您是一位开发人员,有您钟爱的编程语言,编辑器/IDE(集成开发环境),以及可用的测试框架。在针对 Kubernates 开发应用时,最重要的目标是减少对当前工作流程的影响,改变越少越好,尽量做到最小。举个例子,如果您是 Node.js 开发人员,习惯于那种热重载的环境 - 也就是说您在编辑器里一做保存,正在运行的程序就会自动更新 - 那么跟容器、容器镜像或者镜像仓库打交道,又或是跟 Kubernetes 部署、triggers 以及更多头疼东西打交道,不仅会让人难以招架也真的会让开发过程完全失去乐趣。
|
||||
|
||||
<!--
|
||||
In the following, we’ll first discuss the overall development setup, then review tools of the trade, and last but not least do a hands-on walkthrough of three exemplary tools that allow for iterative, local app development against Kubernetes.
|
||||
-->
|
||||
|
||||
在下文中,我们将首先讨论 Kubernetes 总体开发环境,然后回顾常用工具,最后进行三个示例性工具的实践演练。这些工具允许针对 Kubernetes 进行本地应用程序的开发和迭代。
|
||||
|
||||
<!--
|
||||
## Where to run your cluster?
|
||||
-->
|
||||
|
||||
## 您的集群运行在哪里?
|
||||
|
||||
<!--
|
||||
As a developer you want to think about where the Kubernetes cluster you’re developing against runs as well as where the development environment sits. Conceptually there are four development modes:
|
||||
-->
|
||||
|
||||
作为开发人员,您既需要考虑所针对开发的 Kubernetes 集群运行在哪里,也需要思考开发环境如何配置。概念上,有四种开发模式:
|
||||
|
||||

|
||||
|
||||
<!--
|
||||
A number of tools support pure offline development including Minikube, Docker for Mac/Windows, Minishift, and the ones we discuss in detail below. Sometimes, for example, in a microservices setup where certain microservices already run in the cluster, a proxied setup (forwarding traffic into and from the cluster) is preferable and Telepresence is an example tool in this category. The live mode essentially means you’re building and/or deploying against a remote cluster and, finally, the pure online mode means both your development environment and the cluster are remote, as this is the case with, for example, [Eclipse Che](https://www.eclipse.org/che/docs/kubernetes-single-user.html) or [Cloud 9](https://github.com/errordeveloper/k9c). Let’s now have a closer look at the basics of offline development: running Kubernetes locally.
|
||||
-->
|
||||
|
||||
许多工具支持纯 offline 开发,包括 Minikube、Docker(Mac 版/Windows 版)、Minishift 以及下文中我们将详细讨论的几种。有时,比如说在一个微服务系统中,已经有若干微服务在运行,proxied 模式(通过转发把数据流传进传出集群)就非常合适,Telepresence 就是此类工具的一个实例。live 模式,本质上是您基于一个远程集群进行构建和部署。最后,纯 online 模式意味着您的开发环境和运行集群都是远程的,典型的例子是 [Eclipse Che](https://www.eclipse.org/che/docs/kubernetes-single-user.html) 或者 [Cloud 9](https://github.com/errordeveloper/k9c)。现在让我们仔细看看离线开发的基础:在本地运行 Kubernetes。
|
||||
|
||||
<!--
|
||||
[Minikube](/docs/getting-started-guides/minikube/) is a popular choice for those who prefer to run Kubernetes in a local VM. More recently Docker for [Mac](https://docs.docker.com/docker-for-mac/kubernetes/) and [Windows](https://docs.docker.com/docker-for-windows/kubernetes/) started shipping Kubernetes as an experimental package (in the “edge” channel). Some reasons why you may want to prefer using Minikube over the Docker desktop option are:
|
||||
-->
|
||||
|
||||
[Minikube](/docs/getting-started-guides/minikube/) 在更加喜欢于本地 VM 上运行 Kubernetes 的开发人员中,非常受欢迎。不久前,Docker 的 [Mac](https://docs.docker.com/docker-for-mac/kubernetes/) 版和 [Windows](https://docs.docker.com/docker-for-windows/kubernetes/) 版,都试验性地开始自带 Kubernetes(需要下载 “edge” 安装包)。在两者之间,以下原因也许会促使您选择 Minikube 而不是 Docker 桌面版:
|
||||
|
||||
<!--
|
||||
* You already have Minikube installed and running
|
||||
* You prefer to wait until Docker ships a stable package
|
||||
* You’re a Linux desktop user
|
||||
* You are a Windows user who doesn’t have Windows 10 Pro with Hyper-V
|
||||
-->
|
||||
|
||||
* 您已经安装了 Minikube 并且它运行良好
|
||||
* 您想等到 Docker 出稳定版本
|
||||
* 您是 Linux 桌面用户
|
||||
* 您是 Windows 用户,但是没有配有 Hyper-V 的 Windows 10 Pro
|
||||
|
||||
<!--
|
||||
Running a local cluster allows folks to work offline and that you don’t have to pay for using cloud resources. Cloud provider costs are often rather affordable and free tiers exists, however some folks prefer to avoid having to approve those costs with their manager as well as potentially incur unexpected costs, for example, when leaving cluster running over the weekend.
|
||||
-->
|
||||
|
||||
运行一个本地集群,开发人员可以离线工作,不用支付云服务。云服务收费一般不会太高,并且免费的等级也有,但是一些开发人员不喜欢为了使用云服务而必须得到经理的批准,也不愿意支付意想不到的费用,比如说忘了下线而集群在周末也在运转。
|
||||
|
||||
<!--
|
||||
Some developers prefer to use a remote Kubernetes cluster, and this is usually to allow for larger compute and storage capacity and also enable collaborative workflows more easily. This means it’s easier for you to pull in a colleague to help with debugging or share access to an app in the team. Additionally, for some developers it can be critical to mirror production environment as closely as possible, especially when it comes down to external cloud services, say, proprietary databases, object stores, message queues, external load balancer, or mail delivery systems.
|
||||
-->
|
||||
|
||||
有些开发人员却更喜欢远程的 Kubernetes 集群,这样他们通常可以获得更大的计算能力和存储容量,也简化了协同工作流程。您可以更容易的拉上一个同事来帮您调试,或者在团队内共享一个应用的使用。再者,对某些开发人员来说,尽可能的让开发环境类似生产环境至关重要,尤其是您依赖外部厂商的云服务时,如:专有数据库、云对象存储、消息队列、外商的负载均衡器或者邮件投递系统。
|
||||
|
||||
<!--
|
||||
In summary, there are good reasons for you to develop against a local cluster as well as a remote one. It very much depends on in which phase you are: from early prototyping and/or developing alone to integrating a set of more stable microservices.
|
||||
-->
|
||||
|
||||
总之,无论您选择本地或者远程集群,理由都足够多。这很大程度上取决于您所处的阶段:从早期的原型设计/单人开发到后期面对一批稳定微服务的集成。
|
||||
|
||||
<!--
|
||||
Now that you have a basic idea of the options around the runtime environment, let’s move on to how to iteratively develop and deploy your app.
|
||||
-->
|
||||
|
||||
既然您已经了解到运行环境的基本选项,那么我们就接着讨论如何迭代式的开发并部署您的应用。
|
||||
|
||||
<!--
|
||||
## The tools of the trade
|
||||
-->
|
||||
|
||||
## 常用工具
|
||||
|
||||
<!--
|
||||
We are now going to review tooling allowing you to develop apps on Kubernetes with the focus on having minimal impact on your existing workflow. We strive to provide an unbiased description including implications of using each of the tools in general terms.
|
||||
-->
|
||||
|
||||
我们现在回顾既可以允许您可以在 Kubernetes 上开发应用程序又尽可能最小地改变您现有的工作流程的一些工具。我们致力于提供一份不偏不倚的描述,也会提及使用某个工具将会意味着什么。
|
||||
|
||||
<!--
|
||||
Note that this is a tricky area since even for established technologies such as, for example, JSON vs YAML vs XML or REST vs gRPC vs SOAP a lot depends on your background, your preferences and organizational settings. It’s even harder to compare tooling in the Kubernetes ecosystem as things evolve very rapidly and new tools are announced almost on a weekly basis; during the preparation of this post alone, for example, [Gitkube](https://gitkube.sh/) and [Watchpod](https://github.com/MinikubeAddon/watchpod) came out. To cover these new tools as well as related, existing tooling such as [Weave Flux](https://github.com/weaveworks/flux) and OpenShift’s [S2I](https://docs.openshift.com/container-platform/3.9/creating_images/s2i.html) we are planning a follow-up blog post to the one you’re reading.
|
||||
-->
|
||||
|
||||
请注意这很棘手,因为即使在成熟定型的技术中做选择,比如说在 JSON、YAML、XML、REST、gRPC 或者 SOAP 之间做选择,很大程度也取决于您的背景、喜好以及公司环境。在 Kubernetes 生态系统内比较各种工具就更加困难,因为技术发展太快,几乎每周都有新工具面市;举个例子,仅在准备这篇博客的期间,[Gitkube](https://gitkube.sh/) 和 [Watchpod](https://github.com/MinikubeAddon/watchpod) 相继出品。为了进一步覆盖到这些新的,以及一些相关的已推出的工具,例如 [Weave Flux](https://github.com/weaveworks/flux) 和 OpenShift 的 [S2I](https://docs.openshift.com/container-platform/3.9/creating_images/s2i.html),我们计划再写一篇跟进的博客。
|
||||
|
||||
### Draft
|
||||
|
||||
|
||||
<!--
|
||||
[Draft](https://github.com/Azure/draft) aims to help you get started deploying any app to Kubernetes. It is capable of applying heuristics as to what programming language your app is written in and generates a Dockerfile along with a Helm chart. It then runs the build for you and deploys resulting image to the target cluster via the Helm chart. It also allows user to setup port forwarding to localhost very easily.
|
||||
-->
|
||||
|
||||
[Draft](https://github.com/Azure/draft) 旨在帮助您将任何应用程序部署到 Kubernetes。它能够检测到您的应用所使用的编程语言,并且生成一份 Dockerfile 和 Helm 图表。然后它替您启动构建并且依照 Helm 图表把所生产的镜像部署到目标集群。它也可以让您很容易地设置到 localhost 的端口映射。
|
||||
|
||||
<!--
|
||||
Implications:
|
||||
-->
|
||||
|
||||
这意味着:
|
||||
|
||||
<!--
|
||||
* User can customise the chart and Dockerfile templates however they like, or even create a [custom pack](https://github.com/Azure/draft/blob/master/docs/reference/dep-003.md) (with Dockerfile, the chart and more) for future use
|
||||
-->
|
||||
* 用户可以任意地自定义 Helm 图表和 Dockerfile 模版,或者甚至创建一个 [custom pack](https://github.com/Azure/draft/blob/master/docs/reference/dep-003.md)(使用 Dockerfile、Helm 图表以及其他)以备后用
|
||||
|
||||
<!--
|
||||
* It’s not very simple to guess how just any app is supposed to be built, in some cases user may need to tweak Dockerfile and the Helm chart that Draft generates
|
||||
-->
|
||||
* 要想理解一个应用应该怎么构建并不容易,在某些情况下,用户也许需要修改 Draft 生成的 Dockerfile 和 Heml 图表
|
||||
|
||||
<!--
|
||||
* With [Draft version 0.12.0](https://github.com/Azure/draft/releases/tag/v0.12.0) or older, every time user wants to test a change, they need to wait for Draft to copy the code to the cluster, then run the build, push the image and release updated chart; this can timely, but it results in an image being for every single change made by the user (whether it was committed to git or not)
|
||||
-->
|
||||
* 如果使用 [Draft version 0.12.0](https://github.com/Azure/draft/releases/tag/v0.12.0)<sup>1</sup> 或者更老版本,每一次用户想要测试一个改动,他们需要等 Draft 把代码拷贝到集群,运行构建,推送镜像并且发布更新后的图表;这些步骤可能进行得很快,但是每一次用户的改动都会产生一个镜像(无论是否提交到 git )
|
||||
|
||||
<!--
|
||||
* As of Draft version 0.12.0, builds are executed locally
|
||||
* User doesn’t have an option to choose something other than Helm for deployment
|
||||
* It can watch local changes and trigger deployments, but this feature is not enabled by default
|
||||
-->
|
||||
* 在 Draft 0.12.0版本,构建是本地进行的
|
||||
* 用户不能选择 Helm 以外的工具进行部署
|
||||
* 它可以监控本地的改动并且触发部署,但是这个功能默认是关闭的
|
||||
|
||||
<!--
|
||||
* It allows developer to use either local or remote Kubernetes cluster
|
||||
* Deploying to production is up to the user, Draft authors recommend their other project – Brigade
|
||||
* Can be used instead of Skaffold, and along the side of Squash
|
||||
-->
|
||||
* 它允许开发人员使用本地或者远程的 Kubernates 集群
|
||||
* 如何部署到生产环境取决于用户, Draft 的作者推荐了他们的另一个项目 - Brigade
|
||||
* 可以代替 Skaffold, 并且可以和 Squash 一起使用
|
||||
|
||||
<!--
|
||||
More info:
|
||||
-->
|
||||
|
||||
更多信息:
|
||||
|
||||
* [Draft: Kubernetes container development made easy](https://kubernetes.io/blog/2017/05/draft-kubernetes-container-development)
|
||||
* [Getting Started Guide](https://github.com/Azure/draft/blob/master/docs/getting-started.md)
|
||||
|
||||
【1】:此处疑为 0.11.0,因为 0.12.0 已经支持本地构建,见下一条
|
||||
|
||||
### Skaffold
|
||||
|
||||
<!--
|
||||
[Skaffold](https://github.com/GoogleCloudPlatform/skaffold) is a tool that aims to provide portability for CI integrations with different build system, image registry and deployment tools. It is different from Draft, yet somewhat comparable. It has a basic capability for generating manifests, but it’s not a prominent feature. Skaffold is extendible and lets user pick tools for use in each of the steps in building and deploying their app.
|
||||
-->
|
||||
|
||||
[Skaffold](https://github.com/GoogleCloudPlatform/skaffold) 让 CI 集成具有可移植性的,它允许用户采用不同的构建系统,镜像仓库和部署工具。它不同于 Draft,同时也具有一定的可比性。它具有生成系统清单的基本能力,但那不是一个重要功能。Skaffold 易于扩展,允许用户在构建和部署应用的每一步选取相应的工具。
|
||||
|
||||
<!--
|
||||
Implications:
|
||||
-->
|
||||
|
||||
这意味着:
|
||||
|
||||
<!--
|
||||
* Modular by design
|
||||
* Works independently of CI vendor, user doesn’t need Docker or Kubernetes plugin
|
||||
* Works without CI as such, i.e. from the developer’s laptop
|
||||
* It can watch local changes and trigger deployments
|
||||
-->
|
||||
* 模块化设计
|
||||
* 不依赖于 CI,用户不需要 Docker 或者 Kubernetes 插件
|
||||
* 没有 CI 也可以工作,也就是说,可以在开发人员的电脑上工作
|
||||
* 它可以监控本地的改动并且触发部署
|
||||
|
||||
<!--
|
||||
* It allows developer to use either local or remote Kubernetes cluster
|
||||
* It can be used to deploy to production, user can configure how exactly they prefer to do it and provide different kind of pipeline for each target environment
|
||||
* Can be used instead of Draft, and along the side with most other tools
|
||||
-->
|
||||
* 它允许开发人员使用本地或者远程的 Kubernetes 集群
|
||||
* 它可以用于部署生产环境,用户可以精确配置,也可以为每一套目标环境提供不同的生产线
|
||||
* 可以代替 Draft,并且和其他工具一起使用
|
||||
|
||||
<!--
|
||||
More info:
|
||||
-->
|
||||
|
||||
更多信息:
|
||||
|
||||
* [Introducing Skaffold: Easy and repeatable Kubernetes development](https://cloudplatform.googleblog.com/2018/03/introducing-Skaffold-Easy-and-repeatable-Kubernetes-development.html)
|
||||
* [Getting Started Guide](https://github.com/GoogleCloudPlatform/skaffold#getting-started-with-local-tooling)
|
||||
|
||||
### Squash
|
||||
|
||||
<!--
|
||||
[Squash](https://github.com/solo-io/squash) consists of a debug server that is fully integrated with Kubernetes, and a IDE plugin. It allows you to insert breakpoints and do all the fun stuff you are used to doing when debugging an application using an IDE. It bridges IDE debugging experience with your Kubernetes cluster by allowing you to attach the debugger to a pod running in your Kubernetes cluster.
|
||||
-->
|
||||
[Squash](https://github.com/solo-io/squash) 包含一个与 Kubernetes 全面集成的调试服务器,以及一个 IDE 插件。它允许您插入断点和所有的调试操作,就像您所习惯的使用 IDE 调试一个程序一般。它允许您将调试器应用到 Kubernetes 集群中运行的 pod 上,从而让您可以使用 IDE 调试 Kubernetes 集群。
|
||||
|
||||
<!--
|
||||
Implications:
|
||||
-->
|
||||
|
||||
这意味着:
|
||||
|
||||
<!--
|
||||
* Can be used independently of other tools you chose
|
||||
* Requires a privileged DaemonSet
|
||||
* Integrates with popular IDEs
|
||||
* Supports Go, Python, Node.js, Java and gdb
|
||||
-->
|
||||
* 不依赖您选择的其它工具
|
||||
* 需要一组特权 DaemonSet
|
||||
* 可以和流行 IDE 集成
|
||||
* 支持 Go、Python、Node.js、Java 和 gdb
|
||||
|
||||
<!--
|
||||
* User must ensure application binaries inside the container image are compiled with debug symbols
|
||||
* Can be used in combination with any other tools described here
|
||||
* It can be used with either local or remote Kubernetes cluster
|
||||
-->
|
||||
* 用户必须确保容器中的应用程序使编译时使用了调试符号
|
||||
* 可与此处描述的任何其他工具结合使用
|
||||
* 它可以与本地或远程 Kubernetes 集群一起使用
|
||||
|
||||
<!--
|
||||
More info:
|
||||
-->
|
||||
|
||||
更多信息:
|
||||
|
||||
* [Squash: A Debugger for Kubernetes Apps](https://www.youtube.com/watch?v=5TrV3qzXlgI)
|
||||
* [Getting Started Guide](https://github.com/solo-io/squash/blob/master/docs/getting-started.md)
|
||||
|
||||
### Telepresence
|
||||
|
||||
<!--
|
||||
[Telepresence](https://www.telepresence.io/) connects containers running on developer’s workstation with a remote Kubernetes cluster using a two-way proxy and emulates in-cluster environment as well as provides access to config maps and secrets. It aims to improve iteration time for container app development by eliminating the need for deploying app to the cluster and leverages local container to abstract network and filesystem interface in order to make it appear as if the app was running in the cluster.
|
||||
-->
|
||||
[Telepresence](https://www.telepresence.io/) 使用双向代理将开发人员工作站上运行的容器与远程 Kubernetes 集群连接起来,并模拟集群内环境以及提供对配置映射和机密的访问。它消除了将应用部署到集群的需要,并利用本地容器抽象出网络和文件系统接口,以使其看起来应用好像就在集群中运行,从而改进容器应用程序开发的迭代时间。
|
||||
|
||||
<!--
|
||||
Implications:
|
||||
-->
|
||||
|
||||
这意味着:
|
||||
|
||||
<!--
|
||||
* It can be used independently of other tools you chose
|
||||
* Using together with Squash is possible, although Squash would have to be used for pods in the cluster, while conventional/local debugger would need to be used for debugging local container that’s connected to the cluster via Telepresence
|
||||
* Telepresence imposes some network latency
|
||||
-->
|
||||
* 它不依赖于其它您选取的工具
|
||||
* 可以同 Squash 一起使用,但是 Squash 必须用于调试集群中的 pods,而传统/本地调试器需要用于调试通过 Telepresence 连接到集群的本地容器
|
||||
* Telepresence 会产生一些网络延迟
|
||||
|
||||
<!--
|
||||
* It provides connectivity via a side-car process - sshuttle, which is based on SSH
|
||||
* More intrusive dependency injection mode with LD_PRELOAD/DYLD_INSERT_LIBRARIES is also available
|
||||
* It is most commonly used with a remote Kubernetes cluster, but can be used with a local one also
|
||||
-->
|
||||
* 它通过辅助进程提供连接 - sshuttle,基于SSH的一个工具
|
||||
* 还提供了使用 LD_PRELOAD/DYLD_INSERT_LIBRARIES 的更具侵入性的依赖注入模式
|
||||
* 它最常用于远程 Kubernetes 集群,但也可以与本地集群一起使用
|
||||
|
||||
<!--
|
||||
More info:
|
||||
-->
|
||||
|
||||
更多信息:
|
||||
|
||||
* [Telepresence: fast, realistic local development for Kubernetes microservices](https://www.telepresence.io/)
|
||||
* [Getting Started Guide](https://www.telepresence.io/tutorials/docker)
|
||||
* [How It Works](https://www.telepresence.io/discussion/how-it-works)
|
||||
|
||||
### Ksync
|
||||
|
||||
<!--
|
||||
[Ksync](https://github.com/vapor-ware/ksync) synchronizes application code (and configuration) between your local machine and the container running in Kubernetes, akin to what [oc rsync](https://docs.openshift.com/container-platform/3.9/dev_guide/copy_files_to_container.html) does in OpenShift. It aims to improve iteration time for app development by eliminating build and deployment steps.
|
||||
-->
|
||||
|
||||
|
||||
[Ksync](https://github.com/vapor-ware/ksync) 在本地计算机和运行在 Kubernetes 中的容器之间同步应用程序代码(和配置),类似于 [oc rsync](https://docs.openshift.com/container-platform/3.9/dev_guide/copy_files_to_container.html) 在 OpenShift 中的角色。它旨在通过消除构建和部署步骤来缩短应用程序开发的迭代时间。
|
||||
|
||||
|
||||
<!--
|
||||
Implications:
|
||||
-->
|
||||
|
||||
这意味着:
|
||||
|
||||
<!--
|
||||
* It bypasses container image build and revision control
|
||||
* Compiled language users have to run builds inside the pod (TBC)
|
||||
* Two-way sync – remote files are copied to local directory
|
||||
* Container is restarted each time remote filesystem is updated
|
||||
* No security features – development only
|
||||
-->
|
||||
* 它绕过容器图像构建和修订控制
|
||||
* 使用编译语言的用户必须在 pod(TBC)内运行构建
|
||||
* 双向同步 - 远程文件会复制到本地目录
|
||||
* 每次更新远程文件系统时都会重启容器
|
||||
* 无安全功能 - 仅限开发
|
||||
|
||||
<!--
|
||||
* Utilizes [Syncthing](https://github.com/syncthing/syncthing), a Go library for peer-to-peer sync
|
||||
* Requires a privileged DaemonSet running in the cluster
|
||||
* Node has to use Docker with overlayfs2 – no other CRI implementations are supported at the time of writing
|
||||
-->
|
||||
* 使用 [Syncthing](https://github.com/syncthing/syncthing),一个用于点对点同步的 Go 语言库
|
||||
* 需要一个在集群中运行的特权 DaemonSet
|
||||
* Node 必须使用带有 overlayfs2 的 Docker - 在写作本文时,尚不支持其他 CRI 实现
|
||||
|
||||
<!--
|
||||
More info:
|
||||
-->
|
||||
|
||||
更多信息:
|
||||
|
||||
* [Getting Started Guide](https://github.com/vapor-ware/ksync#getting-started)
|
||||
* [How It Works](https://github.com/vapor-ware/ksync/blob/master/docs/architecture.md)
|
||||
* [Katacoda scenario to try out ksync in your browser](https://www.katacoda.com/vaporio/scenarios/ksync)
|
||||
* [Syncthing Specification](https://docs.syncthing.net/specs/)
|
||||
|
||||
<!--
|
||||
## Hands-on walkthroughs
|
||||
-->
|
||||
|
||||
## 实践演练
|
||||
|
||||
|
||||
<!--
|
||||
The app we will be using for the hands-on walkthroughs of the tools in the following is a simple [stock market simulator](https://github.com/kubernauts/dok-example-us), consisting of two microservices:
|
||||
-->
|
||||
|
||||
我们接下来用于练习使用工具的应用是一个简单的[股市模拟器](https://github.com/kubernauts/dok-example-us),包含两个微服务:
|
||||
|
||||
<!--
|
||||
* The `stock-gen` microservice is written in Go and generates stock data randomly and exposes it via HTTP endpoint `/stockdata`.
|
||||
* A second microservice, `stock-con` is a Node.js app that consumes the stream of stock data from `stock-gen` and provides an aggregation in form of a moving average via the HTTP endpoint `/average/$SYMBOL` as well as a health-check endpoint at `/healthz`.
|
||||
-->
|
||||
|
||||
* `stock-gen`(股市数据生成器)微服务是用 Go 编写的,随机生成股票数据并通过 HTTP 端点 `/ stockdata` 公开
|
||||
* 第二个微服务,`stock-con`(股市数据消费者)是一个 Node.js 应用程序,它使用来自 `stock-gen` 的股票数据流,并通过 HTTP 端点 `/average/$SYMBOL` 提供股价移动平均线,也提供一个健康检查端点 `/healthz`。
|
||||
|
||||
<!--
|
||||
Overall, the default setup of the app looks as follows:
|
||||
-->
|
||||
|
||||
总体上,此应用的默认配置如下图所示:
|
||||
|
||||

|
||||
|
||||
<!--
|
||||
In the following we’ll do a hands-on walkthrough for a representative selection of tools discussed above: ksync, Minikube with local build, as well as Skaffold. For each of the tools we do the following:
|
||||
-->
|
||||
|
||||
在下文中,我们将选取以上讨论的代表性工具进行实践演练:ksync,具有本地构建的 Minikube 以及 Skaffold。对于每个工具,我们执行以下操作:
|
||||
|
||||
<!--
|
||||
* Set up the respective tool incl. preparations for the deployment and local consumption of the `stock-con` microservice.
|
||||
* Perform a code update, that is, change the source code of the `/healthz` endpoint in the `stock-con` microservice and observe the updates.
|
||||
-->
|
||||
|
||||
* 设置相应的工具,包括部署准备和 `stock-con` 微服务数据的本地读取
|
||||
* 执行代码更新,即更改 `stock-con` 微服务的 `/healthz` 端点的源代码并观察网页刷新
|
||||
|
||||
<!--
|
||||
Note that for the target Kubernetes cluster we’ve been using Minikube locally, but you can also a remote cluster for ksync and Skaffold if you want to follow along.
|
||||
-->
|
||||
|
||||
请注意,我们一直使用 Minikube 的本地 Kubernetes 集群,但是您也可以使用 ksync 和 Skaffold 的远程集群跟随练习。
|
||||
|
||||
<!--
|
||||
### Walkthrough: ksync
|
||||
-->
|
||||
|
||||
### 实践演练:ksync
|
||||
|
||||
<!--
|
||||
As a preparation, install [ksync](https://vapor-ware.github.io/ksync/#installation) and then carry out the following steps to prepare the development setup:
|
||||
-->
|
||||
|
||||
作为准备,安装 [ksync](https://vapor-ware.github.io/ksync/#installation),然后执行以下步骤配置开发环境:
|
||||
|
||||
```
|
||||
$ mkdir -p $(pwd)/ksync
|
||||
$ kubectl create namespace dok
|
||||
$ ksync init -n dok
|
||||
```
|
||||
<!--
|
||||
With the basic setup completed we're ready to tell ksync’s local client to watch a certain Kubernetes namespace and then we create a spec to define what we want to sync (the directory `$(pwd)/ksync` locally with `/app` in the container). Note that target pod is specified via the selector parameter:
|
||||
-->
|
||||
|
||||
|
||||
完成基本设置后,我们可以告诉 ksync 的本地客户端监控 Kubernetes 的某个命名空间,然后我们创建一个规范来定义我们想要同步的文件夹(本地的 `$(pwd)/ksync` 和容器中的 `/ app` )。请注意,目标 pod 是用 selector 参数指定:
|
||||
|
||||
```
|
||||
$ ksync watch -n dok
|
||||
$ ksync create -n dok --selector=app=stock-con $(pwd)/ksync /app
|
||||
$ ksync get -n dok
|
||||
```
|
||||
|
||||
<!--
|
||||
Now we deploy the stock generator and the stock consumer microservice:
|
||||
-->
|
||||
|
||||
现在我们部署股价数据生成器和股价数据消费者微服务:
|
||||
|
||||
```
|
||||
$ kubectl -n=dok apply \
|
||||
-f https://raw.githubusercontent.com/kubernauts/dok-example-us/master/stock-gen/app.yaml
|
||||
$ kubectl -n=dok apply \
|
||||
-f https://raw.githubusercontent.com/kubernauts/dok-example-us/master/stock-con/app.yaml
|
||||
```
|
||||
<!--
|
||||
Once both deployments are created and the pods are running, we forward the `stock-con` service for local consumption (in a separate terminal session):
|
||||
-->
|
||||
|
||||
|
||||
一旦两个部署建好并且 pod 开始运行,我们转发 `stock-con` 服务以供本地读取(另开一个终端窗口):
|
||||
|
||||
```
|
||||
$ kubectl get -n dok po --selector=app=stock-con \
|
||||
-o=custom-columns=:metadata.name --no-headers | \
|
||||
xargs -IPOD kubectl -n dok port-forward POD 9898:9898
|
||||
```
|
||||
<!--
|
||||
With that we should be able to consume the `stock-con` service from our local machine; we do this by regularly checking the response of the `healthz` endpoint like so (in a separate terminal session):
|
||||
-->
|
||||
|
||||
|
||||
这样,通过定期查询 `healthz` 端点,我们就应该能够从本地机器上读取 `stock-con` 服务,查询命令如下(在一个单独的终端窗口):
|
||||
|
||||
```
|
||||
$ watch curl localhost:9898/healthz
|
||||
```
|
||||
<!--
|
||||
Now change the code in the `ksync/stock-con`directory, for example update the [`/healthz` endpoint code in `service.js`](https://github.com/kubernauts/dok-example-us/blob/2334ee8fb11f8813370122bd46285cf45bdd4c48/stock-con/service.js#L52) by adding a field to the JSON response and observe how the pod gets updated and the response of the `curl localhost:9898/healthz` command changes. Overall you should have something like the following in the end:
|
||||
-->
|
||||
|
||||
|
||||
现在,改动 `ksync/stock-con` 目录中的代码,例如改动 [`service.js` 中定义的 `/healthz` 端点代码](https://github.com/kubernauts/dok-example-us/blob/2334ee8fb11f8813370122bd46285cf45bdd4c48/stock-con/service.js#L52),在其 JSON 形式的响应中新添一个字段并观察 pod 如何更新以及 `curl localhost:9898/healthz` 命令的输出发生何种变化。总的来说,您最后应该看到类似的内容:
|
||||
|
||||
|
||||

|
||||
|
||||
|
||||
<!--
|
||||
### Walkthrough: Minikube with local build
|
||||
-->
|
||||
|
||||
### 实践演练:带本地构建的 Minikube
|
||||
|
||||
<!--
|
||||
For the following you will need to have Minikube up and running and we will leverage the Minikube-internal Docker daemon for building images, locally. As a preparation, do the following
|
||||
-->
|
||||
|
||||
|
||||
对于以下内容,您需要启动并运行 Minikube,我们将利用 Minikube 自带的 Docker daemon 在本地构建镜像。作为准备,请执行以下操作
|
||||
|
||||
```
|
||||
$ git clone https://github.com/kubernauts/dok-example-us.git && cd dok-example-us
|
||||
$ eval $(minikube docker-env)
|
||||
$ kubectl create namespace dok
|
||||
```
|
||||
|
||||
<!--
|
||||
Now we deploy the stock generator and the stock consumer microservice:
|
||||
-->
|
||||
|
||||
现在我们部署股价数据生成器和股价数据消费者微服务:
|
||||
|
||||
|
||||
```
|
||||
$ kubectl -n=dok apply -f stock-gen/app.yaml
|
||||
$ kubectl -n=dok apply -f stock-con/app.yaml
|
||||
```
|
||||
<!--
|
||||
Once both deployments are created and the pods are running, we forward the `stock-con` service for local consumption (in a separate terminal session):
|
||||
-->
|
||||
|
||||
|
||||
一旦两个部署建好并且 pod 开始运行,我们转发 `stock-con` 服务以供本地读取(另开一个终端窗口):
|
||||
|
||||
```
|
||||
$ kubectl get -n dok po --selector=app=stock-con \
|
||||
-o=custom-columns=:metadata.name --no-headers | \
|
||||
xargs -IPOD kubectl -n dok port-forward POD 9898:9898 &
|
||||
$ watch curl localhost:9898/healthz
|
||||
```
|
||||
<!--
|
||||
Now change the code in the `stock-con`directory, for example, update the [`/healthz` endpoint code in `service.js`](https://github.com/kubernauts/dok-example-us/blob/2334ee8fb11f8813370122bd46285cf45bdd4c48/stock-con/service.js#L52) by adding a field to the JSON response. Once you’re done with your code update, the last step is to build a new container image and kick off a new deployment like shown below:
|
||||
-->
|
||||
|
||||
现在,改一下 `ksync/stock-con` 目录中的代码,例如修改 [`service.js` 中定义的 `/healthz` 端点代码](https://github.com/kubernauts/dok-example-us/blob/2334ee8fb11f8813370122bd46285cf45bdd4c48/stock-con/service.js#L52),在其 JSON 形式的响应中添加一个字段。在您更新完代码后,最后一步是构建新的容器镜像并启动新部署,如下所示:
|
||||
|
||||
|
||||
```
|
||||
$ docker build -t stock-con:dev -f Dockerfile .
|
||||
$ kubectl -n dok set image deployment/stock-con *=stock-con:dev
|
||||
```
|
||||
<!--
|
||||
Overall you should have something like the following in the end:
|
||||
-->
|
||||
|
||||
总的来说,您最后应该看到类似的内容:
|
||||
|
||||

|
||||
|
||||
<!--
|
||||
### Walkthrough: Skaffold
|
||||
-->
|
||||
|
||||
### 实践演练:Skaffold
|
||||
|
||||
<!--
|
||||
To perform this walkthrough you first need to install [Skaffold](https://github.com/GoogleContainerTools/skaffold#installation). Once that is done, you can do the following steps to prepare the development setup:
|
||||
-->
|
||||
|
||||
要进行此演练,首先需要安装 [Skaffold](https://github.com/GoogleContainerTools/skaffold#installation)。完成后,您可以执行以下步骤来配置开发环境:
|
||||
|
||||
```
|
||||
$ git clone https://github.com/kubernauts/dok-example-us.git && cd dok-example-us
|
||||
$ kubectl create namespace dok
|
||||
```
|
||||
<!--
|
||||
Now we deploy the stock generator (but not the stock consumer microservice, that is done via Skaffold):
|
||||
-->
|
||||
|
||||
现在我们部署股价数据生成器(但是暂不部署股价数据消费者,此服务将使用 Skaffold 完成):
|
||||
|
||||
```
|
||||
$ kubectl -n=dok apply -f stock-gen/app.yaml
|
||||
```
|
||||
|
||||
<!--
|
||||
Note that initially we experienced an authentication error when doing `skaffold dev` and needed to apply a fix as described in [Issue 322](https://github.com/GoogleContainerTools/skaffold/issues/322). Essentially it means changing the content of `~/.docker/config.json` to:
|
||||
-->
|
||||
|
||||
|
||||
请注意,最初我们在执行 `skaffold dev` 时发生身份验证错误,为避免此错误需要安装[问题322](https://github.com/GoogleContainerTools/skaffold/issues/322) 中所述的修复。本质上,需要将 `〜/.docker/config.json` 的内容改为:
|
||||
|
||||
|
||||
```
|
||||
{
|
||||
"auths": {}
|
||||
}
|
||||
```
|
||||
|
||||
<!--
|
||||
Next, we had to patch `stock-con/app.yaml` slightly to make it work with Skaffold:
|
||||
-->
|
||||
|
||||
接下来,我们需要略微改动 `stock-con/app.yaml`,这样 Skaffold 才能正常使用此文件:
|
||||
|
||||
<!--
|
||||
Add a `namespace` field to both the `stock-con` deployment and the service with the value of `dok`.
|
||||
Change the `image` field of the container spec to `quay.io/mhausenblas/stock-con` since Skaffold manages the container image tag on the fly.
|
||||
-->
|
||||
|
||||
在 `stock-con` 部署和服务中添加一个 `namespace` 字段,其值为 `dok`
|
||||
|
||||
将容器规范的 `image` 字段更改为 `quay.io/mhausenblas/stock-con`,因为 Skaffold 可以即时管理容器镜像标签。
|
||||
|
||||
<!--
|
||||
The resulting `app.yaml` file stock-con looks as follows:
|
||||
-->
|
||||
最终的 stock-con 的 `app.yaml` 文件看起来如下:
|
||||
|
||||
|
||||
```
|
||||
apiVersion: apps/v1beta1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
labels:
|
||||
app: stock-con
|
||||
name: stock-con
|
||||
namespace: dok
|
||||
spec:
|
||||
replicas: 1
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: stock-con
|
||||
spec:
|
||||
containers:
|
||||
- name: stock-con
|
||||
image: quay.io/mhausenblas/stock-con
|
||||
env:
|
||||
- name: DOK_STOCKGEN_HOSTNAME
|
||||
value: stock-gen
|
||||
- name: DOK_STOCKGEN_PORT
|
||||
value: "9999"
|
||||
ports:
|
||||
- containerPort: 9898
|
||||
protocol: TCP
|
||||
livenessProbe:
|
||||
initialDelaySeconds: 2
|
||||
periodSeconds: 5
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: 9898
|
||||
readinessProbe:
|
||||
initialDelaySeconds: 2
|
||||
periodSeconds: 5
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: 9898
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
labels:
|
||||
app: stock-con
|
||||
name: stock-con
|
||||
namespace: dok
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- name: http
|
||||
port: 80
|
||||
protocol: TCP
|
||||
targetPort: 9898
|
||||
selector:
|
||||
app: stock-con
|
||||
```
|
||||
<!--
|
||||
The final step before we can start development is to configure Skaffold. So, create a file `skaffold.yaml` in the `stock-con/` directory with the following content:
|
||||
-->
|
||||
|
||||
我们能够开始开发之前的最后一步是配置 Skaffold。因此,在 `stock-con/` 目录中创建文件 `skaffold.yaml`,其中包含以下内容:
|
||||
|
||||
```
|
||||
apiVersion: skaffold/v1alpha2
|
||||
kind: Config
|
||||
build:
|
||||
artifacts:
|
||||
- imageName: quay.io/mhausenblas/stock-con
|
||||
workspace: .
|
||||
docker: {}
|
||||
local: {}
|
||||
deploy:
|
||||
kubectl:
|
||||
manifests:
|
||||
- app.yaml
|
||||
```
|
||||
<!--
|
||||
Now we’re ready to kick off the development. For that execute the following in the `stock-con/` directory:
|
||||
-->
|
||||
|
||||
现在我们准备好开始开发了。为此,在 `stock-con/` 目录中执行以下命令:
|
||||
|
||||
```
|
||||
$ skaffold dev
|
||||
```
|
||||
<!--
|
||||
Above command triggers a build of the `stock-con` image and then a deployment. Once the pod of the `stock-con` deployment is running, we again forward the `stock-con` service for local consumption (in a separate terminal session) and check the response of the `healthz` endpoint:
|
||||
-->
|
||||
|
||||
|
||||
上面的命令将触发 `stock-con` 图像的构建和部署。一旦 `stock-con` 部署的 pod 开始运行,我们再次转发 `stock-con` 服务以供本地读取(在单独的终端窗口中)并检查 `healthz` 端点的响应:
|
||||
|
||||
```bash
|
||||
$ kubectl get -n dok po --selector=app=stock-con \
|
||||
-o=custom-columns=:metadata.name --no-headers | \
|
||||
xargs -IPOD kubectl -n dok port-forward POD 9898:9898 &
|
||||
$ watch curl localhost:9898/healthz
|
||||
```
|
||||
<!--
|
||||
If you now change the code in the `stock-con`directory, for example, by updating the [`/healthz` endpoint code in `service.js`](https://github.com/kubernauts/dok-example-us/blob/2334ee8fb11f8813370122bd46285cf45bdd4c48/stock-con/service.js#L52) by adding a field to the JSON response, you should see Skaffold noticing the change and create a new image as well as deploy it. The resulting screen would look something like this:
|
||||
-->
|
||||
|
||||
现在,如果您修改一下 `stock-con` 目录中的代码,例如 [`service.js` 中定义的 `/healthz` 端点代码](https://github.com/kubernauts/dok-example-us/blob/2334ee8fb11f8813370122bd46285cf45bdd4c48/stock-con/service.js#L52),在其 JSON 形式的响应中添加一个字段,您应该看到 Skaffold 可以检测到代码改动并创建新图像以及部署它。您的屏幕看起来应该类似这样:
|
||||
|
||||
|
||||

|
||||
<!--
|
||||
By now you should have a feeling how different tools enable you to develop apps on Kubernetes and if you’re interested to learn more about tools and or methods, check out the following resources:
|
||||
-->
|
||||
|
||||
至此,您应该对不同的工具如何帮您在 Kubernetes 上开发应用程序有了一定的概念,如果您有兴趣了解有关工具和/或方法的更多信息,请查看以下资源:
|
||||
|
||||
* Blog post by Shahidh K Muhammed on [Draft vs Gitkube vs Helm vs Ksonnet vs Metaparticle vs Skaffold](https://blog.hasura.io/draft-vs-gitkube-vs-helm-vs-ksonnet-vs-metaparticle-vs-skaffold-f5aa9561f948) (03/2018)
|
||||
* Blog post by Gergely Nemeth on [Using Kubernetes for Local Development](https://nemethgergely.com/using-kubernetes-for-local-development/index.html), with a focus on Skaffold (03/2018)
|
||||
* Blog post by Richard Li on [Locally developing Kubernetes services (without waiting for a deploy)](https://hackernoon.com/locally-developing-kubernetes-services-without-waiting-for-a-deploy-f63995de7b99), with a focus on Telepresence
|
||||
* Blog post by Abhishek Tiwari on [Local Development Environment for Kubernetes using Minikube](https://abhishek-tiwari.com/local-development-environment-for-kubernetes-using-minikube/) (09/2017)
|
||||
* Blog post by Aymen El Amri on [Using Kubernetes for Local Development — Minikube](https://medium.com/devopslinks/using-kubernetes-minikube-for-local-development-c37c6e56e3db) (08/2017)
|
||||
* Blog post by Alexis Richardson on [GitOps - Operations by Pull Request](https://www.weave.works/blog/gitops-operations-by-pull-request) (08/2017)
|
||||
* Slide deck [GitOps: Drive operations through git](https://docs.google.com/presentation/d/1d3PigRVt_m5rO89Ob2XZ16bW8lRSkHHH5k816-oMzZo/), with a focus on Gitkube by Tirumarai Selvan (03/2018)
|
||||
* Slide deck [Developing apps on Kubernetes](https://speakerdeck.com/mhausenblas/developing-apps-on-kubernetes), a talk Michael Hausenblas gave at a CNCF Paris meetup (04/2018)
|
||||
* YouTube videos:
|
||||
* [TGI Kubernetes 029: Developing Apps with Ksync](https://www.youtube.com/watch?v=QW85Y0Ug3KY )
|
||||
* [TGI Kubernetes 030: Exploring Skaffold](https://www.youtube.com/watch?v=McwwWhCXMxc)
|
||||
* [TGI Kubernetes 031: Connecting with Telepresence](https://www.youtube.com/watch?v=zezeBAJ_3w8)
|
||||
* [TGI Kubernetes 033: Developing with Draft](https://www.youtube.com/watch?v=8B1D7cTMPgA)
|
||||
* Raw responses to the [Kubernetes Application Survey](https://docs.google.com/spreadsheets/d/12ilRCly2eHKPuicv1P_BD6z__PXAqpiaR-tDYe2eudE/edit) 2018 by SIG Apps
|
||||
|
||||
<!--
|
||||
With that we wrap up this post on how to go about developing apps on Kubernetes, we hope you learned something and if you have feedback and/or want to point out a tool that you found useful, please let us know via Twitter: [Ilya](https://twitter.com/errordeveloper) and [Michael](https://twitter.com/mhausenblas).
|
||||
-->
|
||||
|
||||
有了这些,我们这篇关于如何在 Kubernetes 上开发应用程序的博客就可以收尾了,希望您有所收获,如果您有反馈和/或想要指出您认为有用的工具,请通过 Twitter 告诉我们:[Ilya](https://twitter.com/errordeveloper) 和 [Michael](https://twitter.com/mhausenblas)
|
||||
@@ -0,0 +1,67 @@
|
||||
---
|
||||
title: 'Kubernetes 1 11:向 discuss kubernetes 问好'
|
||||
layout: blog
|
||||
date: 2018-05-30
|
||||
---
|
||||
|
||||
<!--
|
||||
---
|
||||
title: ' Kubernetes 1 11:say-hello-to-discuss-kubernetes '
|
||||
cn-approvers:
|
||||
- congfairy
|
||||
layout: blog
|
||||
date: 2018-05-30
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
|
||||
Author: Jorge Castro (Heptio)
|
||||
|
||||
-->
|
||||
|
||||
作者: Jorge Castro (Heptio)
|
||||
|
||||
<!--
|
||||
|
||||
Communication is key when it comes to engaging a community of over 35,000 people in a global and remote environment. Keeping track of everything in the Kubernetes community can be an overwhelming task. On one hand we have our official resources, like Stack Overflow, GitHub, and the mailing lists, and on the other we have more ephemeral resources like Slack, where you can hop in, chat with someone, and then go on your merry way.
|
||||
|
||||
-->
|
||||
|
||||
就一个超过 35,000 人的全球性社区而言,参与其中时沟通是非常关键的。 跟踪 Kubernetes 社区中的所有内容可能是一项艰巨的任务。 一方面,我们有官方资源,如 Stack Overflow,GitHub 和邮件列表,另一方面,我们有更多瞬时性的资源,如 Slack,你可以加入进去、与某人聊天然后各走各路。
|
||||
|
||||
|
||||
<!--
|
||||
|
||||
Slack is great for casual and timely conversations and keeping up with other community members, but communication can't be easily referenced in the future. Plus it can be hard to raise your hand in a room filled with 35,000 participants and find a voice. Mailing lists are useful when trying to reach a specific group of people with a particular ask and want to keep track of responses on the thread, but can be daunting with a large amount of people. Stack Overflow and GitHub are ideal for collaborating on projects or questions that involve code and need to be searchable in the future, but certain topics like "What's your favorite CI/CD tool" or "Kubectl tips and tricks" are offtopic there.
|
||||
|
||||
While our current assortment of communication channels are valuable in their own rights, we found that there was still a gap between email and real time chat. Across the rest of the web, many other open source projects like Docker, Mozilla, Swift, Ghost, and Chef have had success building communities on top of Discourse, an open source discussion platform. So what if we could use this tool to bring our discussions together under a modern roof, with an open API, and perhaps not let so much of our information fade into the ether? There's only one way to find out: Welcome to discuss.kubernetes.io
|
||||
|
||||
-->
|
||||
|
||||
Slack 非常适合随意和及时的对话,并与其他社区成员保持联系,但未来很难轻易引用通信。此外,在35,000名参与者中提问并得到回答很难。邮件列表在有问题尝试联系特定人群并且想要跟踪大家的回应时非常有用,但是对于大量人员来说可能是麻烦的。 Stack Overflow 和 GitHub 非常适合在涉及代码的项目或问题上进行协作,并且如果在将来要进行搜索也很有用,但某些主题如“你最喜欢的 CI/CD 工具是什么”或“[Kubectl提示和技巧](http://discuss.kubernetes.io/t/kubectl-tips-and-tricks/192)“在那里是没有意义的。
|
||||
|
||||
虽然我们目前的各种沟通渠道对他们自己来说都很有价值,但我们发现电子邮件和实时聊天之间仍然存在差距。在网络的其他部分,许多其他开源项目,如 Docker、Mozilla、Swift、Ghost 和 Chef,已经成功地在[Discourse](http://www.discourse.org/features)之上构建社区,一个开放的讨论平台。那么,如果我们可以使用这个工具将我们的讨论结合在一个平台下,使用开放的API,或许也不会让我们的大部分信息消失在网络中呢?只有一种方法可以找到:欢迎来到[discuss.kubernetes.io](http://discuss.kubernetes.io)
|
||||
|
||||
<!--
|
||||
|
||||
Right off the bat we have categories that users can browse. Checking and posting in these categories allow users to participate in things they might be interested in without having to commit to subscribing to a list. Granular notification controls allow the users to subscribe to just the category or tag they want, and allow for responding to topics via email.
|
||||
|
||||
Ecosystem partners and developers now have a place where they can [announce projects](https://discuss.kubernetes.io/c/announcements) that they're working on to users without wondering if it would be offtopic on an official list. We can make this place be not just about core Kubernetes, but about the hundreds of wonderful tools our community is building.
|
||||
|
||||
|
||||
This new community forum gives people a place to go where they can discuss Kubernetes, and a sounding board for developers to make announcements of things happening around Kubernetes, all while being searchable and easily accessible to a wider audience.
|
||||
|
||||
Hop in and take a look. We're just getting started, so you might want to begin by [introducing yourself](https://discuss.kubernetes.io/t/introduce-yourself-here/56) and then browsing around. Apps are also available for [Android](https://play.google.com/store/apps/details?id=com.discourse&hl=en_US&rdid=com.discourse&pli=1)and [iOS](https://itunes.apple.com/us/app/discourse-app/id1173672076?mt=8).
|
||||
|
||||
|
||||
-->
|
||||
|
||||
马上,我们有用户可以浏览的类别。检查和发布这些类别允许用户参与他们可能感兴趣的事情,而无需订阅列表。精细的通知控件允许用户只订阅他们想要的类别或标签,并允许通过电子邮件回复主题。
|
||||
|
||||
生态系统合作伙伴和开发人员现在有一个地方可以[宣布项目](http://discuss.kubernetes.io/c/announcements),他们正在为用户工作,而不会想知道它是否会在官方列表中脱离主题。我们可以让这个地方不仅仅是关于核心 Kubernetes,而是关于我们社区正在建设的数百个精彩工具。
|
||||
|
||||
这个新的社区论坛为人们提供了一个可以讨论 Kubernetes 的地方,也是开发人员在 Kubernetes 周围发布事件的声音板,同时可以搜索并且更容易被更广泛的用户访问。
|
||||
|
||||
进来看看。我们刚刚开始,所以,您可能希望从[自我介绍](http://discuss.kubernetes.io/t/introduce-yourself-here/56)开始,到处浏览。也有 [Android](http://play.google.com/store/apps/details?id=com.discourse&hl=en_US&rdid=com.discourse&pli=1) 和 [iOS](http://itunes.apple.com/us/app/discourse-app/id1173672076?mt=8) 应用下载。
|
||||
|
||||
@@ -0,0 +1,42 @@
|
||||
---
|
||||
title: Kubernetes 这四年
|
||||
approvers:
|
||||
cn-approvers:
|
||||
- congfairy
|
||||
layout: blog
|
||||
date: 2018-06-06
|
||||
---
|
||||
<!--
|
||||
**Author**: Joe Beda (CTO and Founder, Heptio)
|
||||
On June 6, 2014 I checked in the [first commit](https://github.com/kubernetes/kubernetes/commit/2c4b3a562ce34cddc3f8218a2c4d11c7310e6d56) of what would become the public repository for Kubernetes. Many would assume that is where the story starts. It is the beginning of history, right? But that really doesn’t tell the whole story.
|
||||
-->
|
||||
|
||||
**作者**:Joe Beda( Heptio 首席技术官兼创始人)
|
||||
2014 年 6 月 6 日,我检查了 Kubernetes 公共代码库的[第一次 commit](https://github.com/kubernetes/kubernetes/commit/2c4b3a562ce34cddc3f8218a2c4d11c7310e6d56) 。许多人会认为这是故事开始的地方。这难道不是一切开始的地方吗?但这的确不能把整个过程说清楚。
|
||||
|
||||

|
||||
|
||||
<!--
|
||||
The cast leading up to that commit was large and the success for Kubernetes since then is owed to an ever larger cast.
|
||||
Kubernetes was built on ideas that had been proven out at Google over the previous ten years with Borg. And Borg, itself, owed its existence to even earlier efforts at Google and beyond.
|
||||
Concretely, Kubernetes started as some prototypes from Brendan Burns combined with ongoing work from me and Craig McLuckie to better align the internal Google experience with the Google Cloud experience. Brendan, Craig, and I really wanted people to use this, so we made the case to build out this prototype as an open source project that would bring the best ideas from Borg out into the open.
|
||||
After we got the nod, it was time to actually build the system. We took Brendan’s prototype (in Java), rewrote it in Go, and built just enough to get the core ideas across. By this time the team had grown to include Ville Aikas, Tim Hockin, Brian Grant, Dawn Chen and Daniel Smith. Once we had something working, someone had to sign up to clean things up to get it ready for public launch. That ended up being me. Not knowing the significance at the time, I created a new repo, moved things over, and checked it in. So while I have the first public commit to the repo, there was work underway well before that.
|
||||
The version of Kubernetes at that point was really just a shadow of what it was to become. The core concepts were there but it was very raw. For example, Pods were called Tasks. That was changed a day before we went public. All of this led up to the public announcement of Kubernetes on June 10th, 2014 in a keynote from Eric Brewer at the first DockerCon. You can watch that video here:
|
||||
-->
|
||||
|
||||
第一次 commit 涉及的人员众多,自那以后 Kubernetes 的成功归功于更大的开发者阵容。
|
||||
Kubernetes 建立在过去十年曾经在 Google 的 Borg 集群管理系统中验证过的思路之上。而 Borg 本身也是 Google 和其他公司早期努力的结果。
|
||||
具体而言,Kubernetes 最初是从 Brendan Burns 的一些原型开始,结合我和 Craig McLuckie 正在进行的工作,以更好地将 Google 内部实践与 Google Cloud 的经验相结合。 Brendan,Craig 和我真的希望人们使用它,所以我们建议将这个原型构建为一个开源项目,将 Borg 的最佳创意带给大家。
|
||||
在我们所有人同意后,就开始着手构建这个系统了。我们采用了 Brendan 的原型(Java 语言),用 Go 语言重写了它,并且以上述核心思想去构建该系统。到这个时候,团队已经成长为包括 Ville Aikas,Tim Hockin,Brian Grant,Dawn Chen 和 Daniel Smith。一旦我们有了一些工作需求,有人必须承担一些脱敏的工作,以便为公开发布做好准备。这个角色最终由我承担。当时,我不知道这件事情的重要性,我创建了一个新的仓库,把代码搬过来,然后进行了检查。所以在我第一次提交 public commit 之前,就有工作已经启动了。
|
||||
那时 Kubernetes 的版本只是现在版本的简单雏形。核心概念已经有了,但非常原始。例如,Pods 被称为 Tasks,这在我们推广前一天就被替换。2014年6月10日 Eric Brewe 在第一届 DockerCon 上的演讲中正式发布了 Kubernetes 。您可以在此处观看该视频:
|
||||
|
||||
|
||||
<center><iframe width="560" height="315" src="https://www.youtube.com/embed/YrxnVKZeqK8" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe></center>
|
||||
|
||||
<!--
|
||||
But, however raw, that modest start was enough to pique the interest of a community that started strong and has only gotten stronger. Over the past four years Kubernetes has exceeded the expectations of all of us that were there early on. We owe the Kubernetes community a huge debt. The success the project has seen is based not just on code and technology but also the way that an amazing group of people have come together to create something special. The best expression of this is the [set of Kubernetes values](https://github.com/kubernetes/steering/blob/master/values.md) that Sarah Novotny helped curate.
|
||||
Here is to another 4 years and beyond! 🎉🎉🎉
|
||||
-->
|
||||
|
||||
但是,无论多么原始,这小小的一步足以激起一个开始强大而且变得更强大的社区的兴趣。在过去的四年里,Kubernetes 已经超出了我们所有人的期望。我们对 Kubernetes 社区的所有人员表示感谢。该项目所取得的成功不仅基于代码和技术,还基于一群出色的人聚集在一起所做的有意义的事情。Sarah Novotny 策划的一套 [Kubernetes 价值观](https://github.com/kubernetes/steering/blob/master/values.md)是以上最好的表现形式。
|
||||
让我们一起期待下一个4年!🎉🎉🎉
|
||||
@@ -0,0 +1,129 @@
|
||||
---
|
||||
title: 'Kubernetes 内的动态 Ingress'
|
||||
layout: blog
|
||||
---
|
||||
|
||||
<!--
|
||||
title: Dynamic Ingress in Kubernetes
|
||||
date: 2018-06-07
|
||||
Author: Richard Li (Datawire)
|
||||
-->
|
||||
|
||||
作者: Richard Li (Datawire)
|
||||
|
||||
<!--
|
||||
Kubernetes makes it easy to deploy applications that consist of many microservices, but one of the key challenges with this type of architecture is dynamically routing ingress traffic to each of these services. One approach is Ambassador, a Kubernetes-native open source API Gateway built on the Envoy Proxy. Ambassador is designed for dynamic environment where services may come and go frequently.
|
||||
Ambassador is configured using Kubernetes annotations. Annotations are used to configure specific mappings from a given Kubernetes service to a particular URL. A mapping can include a number of annotations for configuring a route. Examples include rate limiting, protocol, cross-origin request sharing, traffic shadowing, and routing rules.
|
||||
-->
|
||||
|
||||
Kubernetes 可以轻松部署由许多微服务组成的应用程序,但这种架构的关键挑战之一是动态地将流量路由到这些服务中的每一个。
|
||||
一种方法是使用 [Ambassador](https://www.getambassador.io),
|
||||
一个基于 [Envoy Proxy](https://www.envoyproxy.io) 构建的 Kubernetes 原生开源 API 网关。
|
||||
Ambassador 专为动态环境而设计,这类环境中的服务可能被频繁添加或删除。
|
||||
|
||||
Ambassador 使用 Kubernetes 注解进行配置。
|
||||
注解用于配置从给定 Kubernetes 服务到特定 URL 的具体映射关系。
|
||||
每个映射中可以包括多个注解,用于配置路由。
|
||||
注解的例子有速率限制、协议、跨源请求共享(CORS)、流量影射和路由规则等。
|
||||
|
||||
<!--
|
||||
## A Basic Ambassador Example
|
||||
Ambassador is typically installed as a Kubernetes deployment, and is also available as a Helm chart. To configure Ambassador, create a Kubernetes service with the Ambassador annotations. Here is an example that configures Ambassador to route requests to /httpbin/ to the public httpbin.org service:
|
||||
-->
|
||||
|
||||
## 一个简单的 Ambassador 示例
|
||||
|
||||
Ambassador 通常作为 Kubernetes Deployment 来安装,也可以作为 Helm Chart 使用。
|
||||
配置 Ambassador 时,请使用 Ambassador 注解创建 Kubernetes 服务。
|
||||
下面是一个例子,用来配置 Ambassador,将针对 /httpbin/ 的请求路由到公共的 httpbin.org 服务:
|
||||
|
||||
```
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: httpbin
|
||||
annotations:
|
||||
getambassador.io/config: |
|
||||
---
|
||||
apiVersion: ambassador/v0
|
||||
kind: Mapping
|
||||
name: httpbin_mapping
|
||||
prefix: /httpbin/
|
||||
service: httpbin.org:80
|
||||
host_rewrite: httpbin.org
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- port: 80
|
||||
```
|
||||
|
||||
<!--
|
||||
A mapping object is created with a prefix of /httpbin/ and a service name of httpbin.org. The host_rewrite annotation specifies that the HTTP host header should be set to httpbin.org.
|
||||
-->
|
||||
|
||||
例子中创建了一个 Mapping 对象,其 prefix 设置为 /httpbin/,service 名称为 httpbin.org。
|
||||
其中的 host_rewrite 注解指定 HTTP 的 host 头部字段应设置为 httpbin.org。
|
||||
|
||||
<!--
|
||||
## Kubeflow
|
||||
Kubeflow provides a simple way to easily deploy machine learning infrastructure on Kubernetes. The Kubeflow team needed a proxy that provided a central point of authentication and routing to the wide range of services used in Kubeflow, many of which are ephemeral in nature.
|
||||
<center><i>Kubeflow architecture, pre-Ambassador</center></i>
|
||||
-->
|
||||
|
||||
## Kubeflow
|
||||
|
||||
[Kubeflow](https://github.com/kubeflow/kubeflow) 提供了一种简单的方法,用于在 Kubernetes 上轻松部署机器学习基础设施。
|
||||
Kubeflow 团队需要一个代理,为 Kubeflow 中所使用的各种服务提供集中化的认证和路由能力;Kubeflow 中许多服务本质上都是生命期很短的。
|
||||
|
||||
<center><i>Kubeflow architecture, pre-Ambassador</center></i>
|
||||
|
||||
<!--
|
||||
## Service configuration
|
||||
With Ambassador, Kubeflow can use a distributed model for configuration. Instead of a central configuration file, Ambassador allows each service to configure its route in Ambassador via Kubernetes annotations. Here is a simplified example configuration:
|
||||
-->
|
||||
|
||||
## 服务配置
|
||||
|
||||
有了 Ambassador,Kubeflow 可以使用分布式模型进行配置。
|
||||
Ambassador 不使用集中的配置文件,而是允许每个服务通过 Kubernetes 注解在 Ambassador 中配置其路由。
|
||||
下面是一个简化的配置示例:
|
||||
|
||||
```
|
||||
---
|
||||
apiVersion: ambassador/v0
|
||||
kind: Mapping
|
||||
name: tfserving-mapping-test-post
|
||||
prefix: /models/test/
|
||||
rewrite: /model/test/:predict
|
||||
method: POST
|
||||
service: test.kubeflow:8000
|
||||
```
|
||||
|
||||
<!--
|
||||
In this example, the “test” service uses Ambassador annotations to dynamically configure a route to the service, triggered only when the HTTP method is a POST, and the annotation also specifies a rewrite rule.
|
||||
-->
|
||||
|
||||
示例中,“test” 服务使用 Ambassador 注解来为服务动态配置路由。
|
||||
所配置的路由仅在 HTTP 方法是 POST 时触发;注解中同时还给出了一条重写规则。
|
||||
|
||||
<!--
|
||||
With Ambassador, Kubeflow manages routing easily with Kubernetes annotations. Kubeflow configures a single ingress object that directs traffic to Ambassador, then creates services with Ambassador annotations as needed to direct traffic to specific backends. For example, when deploying TensorFlow services, Kubeflow creates and and annotates a K8s service so that the model will be served at https://<ingress host>/models/<model name>/. Kubeflow can also use the Envoy Proxy to do the actual L7 routing. Using Ambassador, Kubeflow takes advantage of additional routing configuration like URL rewriting and method-based routing.
|
||||
If you’re interested in using Ambassador with Kubeflow, the standard Kubeflow install automatically installs and configures Ambassador.
|
||||
If you’re interested in using Ambassador as an API Gateway or Kubernetes ingress solution for your non-Kubeflow services, check out the Getting Started with Ambassador guide.
|
||||
## Kubeflow and Ambassador
|
||||
-->
|
||||
|
||||
## Kubeflow 和 Ambassador
|
||||
|
||||
通过 Ambassador,Kubeflow 可以使用 Kubernetes 注解轻松管理路由。
|
||||
Kubeflow 配置同一个 Ingress 对象,将流量定向到 Ambassador,然后根据需要创建具有 Ambassador 注解的服务,以将流量定向到特定后端。
|
||||
例如,在部署 TensorFlow 服务时,Kubeflow 会创建 Kubernetes 服务并为其添加注解,
|
||||
以便用户能够在 `https://<ingress主机>/models/<模型名称>/` 处访问到模型本身。
|
||||
Kubeflow 还可以使用 Envoy Proxy 来进行实际的 L7 路由。
|
||||
通过 Ambassador,Kubeflow 能够更充分地利用 URL 重写和基于方法的路由等额外的路由配置能力。
|
||||
|
||||
如果您对在 Kubeflow 中使用 Ambassador 感兴趣,标准的 Kubeflow 安装会自动安装和配置 Ambassador。
|
||||
|
||||
如果您有兴趣将 Ambassador 用作 API 网关或 Kubernetes 的 Ingress 解决方案,
|
||||
请参阅 [Ambassador 入门指南](https://www.getambassador.io/user-guide/getting-started)。
|
||||
|
||||
+241
@@ -0,0 +1,241 @@
|
||||
<!--
|
||||
---
|
||||
layout: blog
|
||||
title: 'The Machines Can Do the Work, a Story of Kubernetes Testing, CI, and Automating the Contributor Experience'
|
||||
date: 2018-08-29
|
||||
---
|
||||
-->
|
||||
|
||||
---
|
||||
layout: blog
|
||||
title: '机器可以完成这项工作,一个关于 kubernetes 测试、CI 和自动化贡献者体验的故事'
|
||||
date: 2019-08-29
|
||||
---
|
||||
|
||||
<!--
|
||||
**Author**: Aaron Crickenberger (Google) and Benjamin Elder (Google)
|
||||
-->
|
||||
|
||||
**作者**:Aaron Crickenberger(谷歌)和 Benjamin Elder(谷歌)
|
||||
|
||||
<!--
|
||||
_“Large projects have a lot of less exciting, yet, hard work. We value time spent automating repetitive work more highly than toil. Where that work cannot be automated, it is our culture to recognize and reward all types of contributions. However, heroism is not sustainable.”_ - [Kubernetes Community Values](https://git.k8s.io/community/values.md#automation-over-process)
|
||||
-->
|
||||
|
||||
_”大型项目有很多不那么令人兴奋,但却很辛苦的工作。比起辛苦工作,我们更重视把时间花在自动化重复性工作上,如果这项工作无法实现自动化,我们的文化就是承认并奖励所有类型的贡献。然而,英雄主义是不可持续的。“_ - [Kubernetes Community Values](https://git.k8s.io/community/values.md#automation-over-process)
|
||||
|
||||
<!--
|
||||
Like many open source projects, Kubernetes is hosted on GitHub. We felt the barrier to participation would be lowest if the project lived where developers already worked, using tools and processes developers already knew. Thus the project embraced the service fully: it was the basis of our workflow, our issue tracker, our documentation, our blog platform, our team structure, and more.
|
||||
-->
|
||||
|
||||
像许多开源项目一样,Kubernetes 托管在 GitHub 上。 如果项目位于在开发人员已经工作的地方,使用的开发人员已经知道的工具和流程,那么参与的障碍将是最低的。 因此,该项目完全接受了这项服务:它是我们工作流程,问题跟踪,文档,博客平台,团队结构等的基础。
|
||||
|
||||
<!--
|
||||
This strategy worked. It worked so well that the project quickly scaled past its contributors’ capacity as humans. What followed was an incredible journey of automation and innovation. We didn’t just need to rebuild our airplane mid-flight without crashing, we needed to convert it into a rocketship and launch into orbit. We needed machines to do the work.
|
||||
-->
|
||||
|
||||
这个策略奏效了。 它运作良好,以至于该项目迅速超越了其贡献者的人类能力。 接下来是一次令人难以置信的自动化和创新之旅。 我们不仅需要在飞行途中重建我们的飞机而不会崩溃,我们需要将其转换为火箭飞船并发射到轨道。 我们需要机器来完成这项工作。
|
||||
|
||||
<!--
|
||||
## The Work
|
||||
-->
|
||||
|
||||
## 工作
|
||||
|
||||
<!--
|
||||
Initially, we focused on the fact that we needed to support the sheer volume of tests mandated by a complex distributed system such as Kubernetes. Real world failure scenarios had to be exercised via end-to-end (e2e) tests to ensure proper functionality. Unfortunately, e2e tests were susceptible to flakes (random failures) and took anywhere from an hour to a day to complete.
|
||||
-->
|
||||
|
||||
最初,我们关注的事实是,我们需要支持复杂的分布式系统(如 Kubernetes)所要求的大量测试。 真实世界中的故障场景必须通过端到端(e2e)测试来执行,确保正确的功能。 不幸的是,e2e 测试容易受到薄片(随机故障)的影响,并且需要花费一个小时到一天才能完成。
|
||||
|
||||
<!--
|
||||
Further experience revealed other areas where machines could do the work for us:
|
||||
-->
|
||||
|
||||
进一步的经验揭示了机器可以为我们工作的其他领域:
|
||||
|
||||
<!--
|
||||
* PR Workflow
|
||||
* Did the contributor sign our CLA?
|
||||
* Did the PR pass tests?
|
||||
* Is the PR mergeable?
|
||||
* Did the merge commit pass tests?
|
||||
* Triage
|
||||
* Who should be reviewing PRs?
|
||||
* Is there enough information to route an issue to the right people?
|
||||
* Is an issue still relevant?
|
||||
* Project Health
|
||||
* What is happening in the project?
|
||||
* What should we be paying attention to?
|
||||
-->
|
||||
|
||||
* Pull Request 工作流程
|
||||
* 贡献者是否签署了我们的 CLA?
|
||||
* Pull Request 通过测试吗?
|
||||
* Pull Request 可以合并吗?
|
||||
* 合并提交是否通过了测试?
|
||||
* 鉴别分类
|
||||
* 谁应该审查 Pull Request?
|
||||
* 是否有足够的信息将问题发送给合适的人?
|
||||
* 问题是否依旧存在?
|
||||
* 项目健康
|
||||
* 项目中发生了什么?
|
||||
* 我们应该注意什么?
|
||||
|
||||
<!--
|
||||
As we developed automation to improve our situation, we followed a few guiding principles:
|
||||
-->
|
||||
|
||||
当我们开发自动化来改善我们的情况时,我们遵循了以下几个指导原则:
|
||||
|
||||
<!--
|
||||
* Follow the push/pull control loop patterns that worked well for Kubernetes
|
||||
* Prefer stateless loosely coupled services that do one thing well
|
||||
* Prefer empowering the entire community over empowering a few core contributors
|
||||
* Eat our own dogfood and avoid reinventing wheels
|
||||
-->
|
||||
|
||||
* 遵循适用于 Kubernetes 的推送/拉取控制循环模式
|
||||
* 首选无状态松散耦合服务
|
||||
* 更倾向于授权整个社区权利,而不是赋予少数核心贡献者权力
|
||||
* 做好自己的事,而不要重新造轮子
|
||||
|
||||
<!--
|
||||
## Enter Prow
|
||||
-->
|
||||
|
||||
## 了解 Prow
|
||||
|
||||
<!--
|
||||
This led us to create [Prow](https://git.k8s.io/test-infra/prow) as the central component for our automation. Prow is sort of like an [If This, Then That](https://ifttt.com/) for GitHub events, with a built-in library of [commands](https://prow.k8s.io/command-help), [plugins](https://prow.k8s.io/plugins), and utilities. We built Prow on top of Kubernetes to free ourselves from worrying about resource management and scheduling, and ensure a more pleasant operational experience.
|
||||
-->
|
||||
|
||||
这促使我们创建 [Prow](https://git.k8s.io/test-infra/prow) 作为我们自动化的核心组件。 Prow有点像 [If This, Then That](https://ifttt.com/) 用于 GitHub 事件, 内置 [commands](https://prow.k8s.io/command-help), [plugins](https://prow.k8s.io/plugins), 和实用程序。 我们在 Kubernetes 之上建立了 Prow,让我们不必担心资源管理和日程安排,并确保更愉快的运营体验。
|
||||
|
||||
<!--
|
||||
Prow lets us do things like:
|
||||
-->
|
||||
|
||||
Prow 让我们做以下事情:
|
||||
|
||||
<!--
|
||||
* Allow our community to triage issues/PRs by commenting commands such as “/priority critical-urgent”, “/assign mary” or “/close”
|
||||
* Auto-label PRs based on how much code they change, or which files they touch
|
||||
* Age out issues/PRs that have remained inactive for too long
|
||||
* Auto-merge PRs that meet our PR workflow requirements
|
||||
* Run CI jobs defined as [Knative Builds](https://github.com/knative/build), Kubernetes Pods, or Jenkins jobs
|
||||
* Enforce org-wide and per-repo GitHub policies like [branch protection](https://github.com/kubernetes/test-infra/tree/master/prow/cmd/branchprotector) and [GitHub labels](https://github.com/kubernetes/test-infra/tree/master/label_sync)
|
||||
-->
|
||||
|
||||
* 允许我们的社区通过评论诸如“/priority critical-urgent”,“/assign mary”或“/close”之类的命令对 issues/Pull Requests 进行分类
|
||||
* 根据用户更改的代码数量或创建的文件自动标记 Pull Requests
|
||||
* 标出长时间保持不活动状态 issues/Pull Requests
|
||||
* 自动合并符合我们PR工作流程要求的 Pull Requests
|
||||
* 运行定义为[Knative Builds](https://github.com/knative/build)的 Kubernetes Pods或 Jenkins jobs的 CI 作业
|
||||
* 实施组织范围和重构 GitHub 仓库策略,如[Knative Builds](https://github.com/kubernetes/test-infra/tree/master/prow/cmd/branchprotector)和[GitHub labels](https://github.com/kubernetes/test-infra/tree/master/label_sync)
|
||||
|
||||
<!--
|
||||
Prow was initially developed by the engineering productivity team building Google Kubernetes Engine, and is actively contributed to by multiple members of Kubernetes SIG Testing. Prow has been adopted by several other open source projects, including Istio, JetStack, Knative and OpenShift. [Getting started with Prow](https://github.com/kubernetes/test-infra/blob/master/prow/getting_started.md) takes a Kubernetes cluster and `kubectl apply starter.yaml` (running pods on a Kubernetes cluster).
|
||||
-->
|
||||
|
||||
Prow最初由构建 Google Kubernetes Engine 的工程效率团队开发,并由 Kubernetes SIG Testing 的多个成员积极贡献。 Prow 已被其他几个开源项目采用,包括 Istio,JetStack,Knative 和 OpenShift。 [Getting started with Prow](https://github.com/kubernetes/test-infra/blob/master/prow/getting_started.md)需要一个 Kubernetes 集群和 `kubectl apply starter.yaml`(在 Kubernetes 集群上运行 pod)。
|
||||
|
||||
<!--
|
||||
Once we had Prow in place, we began to hit other scaling bottlenecks, and so produced additional tooling to support testing at the scale required by Kubernetes, including:
|
||||
-->
|
||||
|
||||
一旦我们安装了 Prow,我们就开始遇到其他的问题,因此需要额外的工具以支持 Kubernetes 所需的规模测试,包括:
|
||||
|
||||
<!--
|
||||
- [Boskos](https://github.com/kubernetes/test-infra/tree/master/boskos): manages job resources (such as GCP projects) in pools, checking them out for jobs and cleaning them up automatically ([with monitoring](http://velodrome.k8s.io/dashboard/db/boskos-dashboard?orgId=1))
|
||||
- [ghProxy](https://github.com/kubernetes/test-infra/tree/master/ghproxy): a reverse proxy HTTP cache optimized for use with the GitHub API, to ensure our token usage doesn’t hit API limits ([with monitoring](http://velodrome.k8s.io/dashboard/db/github-cache?refresh=1m&orgId=1))
|
||||
- [Greenhouse](https://github.com/kubernetes/test-infra/tree/master/greenhouse): allows us to use a remote bazel cache to provide faster build and test results for PRs ([with monitoring](http://velodrome.k8s.io/dashboard/db/bazel-cache?orgId=1))
|
||||
- [Splice](https://github.com/kubernetes/test-infra/tree/master/prow/cmd/splice): allows us to test and merge PRs in a batch, ensuring our merge velocity is not limited to our test velocity
|
||||
- [Tide](https://github.com/kubernetes/test-infra/tree/master/prow/cmd/tide): allows us to merge PRs selected via GitHub queries rather than ordered in a queue, allowing for significantly higher merge velocity in tandem with splice
|
||||
-->
|
||||
|
||||
- [Boskos](https://github.com/kubernetes/test-infra/tree/master/boskos): 管理池中的作业资源(例如 GCP 项目),检查它们是否有工作并自动清理它们 ([with monitoring](http://velodrome.k8s.io/dashboard/db/boskos-dashboard?orgId=1))
|
||||
- [ghProxy](https://github.com/kubernetes/test-infra/tree/master/ghproxy): 优化用于 GitHub API 的反向代理 HTTP 缓存,以确保我们的令牌使用不会达到 API 限制 ([with monitoring](http://velodrome.k8s.io/dashboard/db/github-cache?refresh=1m&orgId=1))
|
||||
- [Greenhouse](https://github.com/kubernetes/test-infra/tree/master/greenhouse): 允许我们使用远程 bazel 缓存为 Pull requests 提供更快的构建和测试结果 ([with monitoring](http://velodrome.k8s.io/dashboard/db/bazel-cache?orgId=1))
|
||||
- [Splice](https://github.com/kubernetes/test-infra/tree/master/prow/cmd/splice): 允许我们批量测试和合并 Pull requests,确保我们的合并速度不仅限于我们的测试速度
|
||||
- [Tide](https://github.com/kubernetes/test-infra/tree/master/prow/cmd/tide): 允许我们合并通过 GitHub 查询选择的 Pull requests,而不是在队列中排序,允许显着更高合并速度与拼接一起
|
||||
|
||||
<!--
|
||||
## Scaling Project Health
|
||||
-->
|
||||
|
||||
## 关注项目健康状况
|
||||
|
||||
<!--
|
||||
With workflow automation addressed, we turned our attention to project health. We chose to use Google Cloud Storage (GCS) as our source of truth for all test data, allowing us to lean on established infrastructure, and allowed the community to contribute results. We then built a variety of tools to help individuals and the project as a whole make sense of this data, including:
|
||||
-->
|
||||
|
||||
随着工作流自动化的实施,我们将注意力转向了项目健康。我们选择使用 Google Cloud Storage (GCS)作为所有测试数据的真实来源,允许我们依赖已建立的基础设施,并允许社区贡献结果。然后,我们构建了各种工具来帮助个人和整个项目理解这些数据,包括:
|
||||
|
||||
<!--
|
||||
* [Gubernator](https://github.com/kubernetes/test-infra/tree/master/gubernator): display the results and test history for a given PR
|
||||
* [Kettle](https://github.com/kubernetes/test-infra/tree/master/kettle): transfer data from GCS to a publicly accessible bigquery dataset
|
||||
* [PR dashboard](https://k8s-gubernator.appspot.com/pr): a workflow-aware dashboard that allows contributors to understand which PRs require attention and why
|
||||
* [Triage](https://storage.googleapis.com/k8s-gubernator/triage/index.html): identify common failures that happen across all jobs and tests
|
||||
* [Testgrid](https://k8s-testgrid.appspot.com/): display test results for a given job across all runs, summarize test results across groups of jobs
|
||||
-->
|
||||
|
||||
* [Gubernator](https://github.com/kubernetes/test-infra/tree/master/gubernator): 显示给定 Pull Request 的结果和测试历史
|
||||
* [Kettle](https://github.com/kubernetes/test-infra/tree/master/kettle): 将数据从 GCS 传输到可公开访问的 bigquery 数据集
|
||||
* [PR dashboard](https://k8s-gubernator.appspot.com/pr): 一个工作流程识别仪表板,允许参与者了解哪些 Pull Request 需要注意以及为什么
|
||||
* [Triage](https://storage.googleapis.com/k8s-gubernator/triage/index.html): 识别所有作业和测试中发生的常见故障
|
||||
* [Testgrid](https://k8s-testgrid.appspot.com/): 显示所有运行中给定作业的测试结果,汇总各组作业的测试结果
|
||||
|
||||
<!--
|
||||
We approached the Cloud Native Computing Foundation (CNCF) to develop DevStats to glean insights from our GitHub events such as:
|
||||
-->
|
||||
|
||||
我们与云计算本地计算基金会(CNCF)联系,开发 DevStats,以便从我们的 GitHub 活动中收集见解,例如:
|
||||
|
||||
<!--
|
||||
* [Which prow commands are people most actively using](https://k8s.devstats.cncf.io/d/5/bot-commands-repository-groups?orgId=1)
|
||||
* [PR reviews by contributor over time](https://k8s.devstats.cncf.io/d/46/pr-reviews-by-contributor?orgId=1&var-period=d7&var-repo_name=All&var-reviewers=All)
|
||||
* [Time spent in each phase of our PR workflow](https://k8s.devstats.cncf.io/d/44/pr-time-to-approve-and-merge?orgId=1)
|
||||
-->
|
||||
|
||||
* [Which prow commands are people most actively using](https://k8s.devstats.cncf.io/d/5/bot-commands-repository-groups?orgId=1)
|
||||
* [PR reviews by contributor over time](https://k8s.devstats.cncf.io/d/46/pr-reviews-by-contributor?orgId=1&var-period=d7&var-repo_name=All&var-reviewers=All)
|
||||
* [Time spent in each phase of our PR workflow](https://k8s.devstats.cncf.io/d/44/pr-time-to-approve-and-merge?orgId=1)
|
||||
|
||||
<!--
|
||||
## Into the Beyond
|
||||
-->
|
||||
|
||||
## Into the Beyond
|
||||
|
||||
<!--
|
||||
Today, the Kubernetes project spans over 125 repos across five orgs. There are 31 Special Interests Groups and 10 Working Groups coordinating development within the project. In the last year the project has had [participation from over 13,800 unique developers](https://k8s.devstats.cncf.io/d/13/developer-activity-counts-by-repository-group?orgId=1&var-period_name=Last%20year&var-metric=contributions&var-repogroup_name=All) on GitHub.
|
||||
-->
|
||||
|
||||
今天,Kubernetes 项目跨越了5个组织125个仓库。有31个特殊利益集团和10个工作组在项目内协调发展。在过去的一年里,该项目有 [来自13800多名独立开发人员的参与](https://k8s.devstats.cncf.io/d/13/developer-activity-counts-by-repository-group?orgId=1&var-period_name=Last%20year&var-metric=contributions&var-repogroup_name=All)。
|
||||
|
||||
<!--
|
||||
On any given weekday our Prow instance [runs over 10,000 CI jobs](http://velodrome.k8s.io/dashboard/db/bigquery-metrics?panelId=10&fullscreen&orgId=1&from=now-6M&to=now); from March 2017 to March 2018 it ran 4.3 million jobs. Most of these jobs involve standing up an entire Kubernetes cluster, and exercising it using real world scenarios. They allow us to ensure all supported releases of Kubernetes work across cloud providers, container engines, and networking plugins. They make sure the latest releases of Kubernetes work with various optional features enabled, upgrade safely, meet performance requirements, and work across architectures.
|
||||
-->
|
||||
|
||||
在任何给定的工作日,我们的 Prow 实例[运行超过10,000个 CI 工作](http://velodrome.k8s.io/dashboard/db/bigquery-metrics?panelId=10&fullscreen&orgId=1&from=now-6M&to=now); 从2017年3月到2018年3月,它有430万个工作岗位。 这些工作中的大多数涉及建立整个 Kubernetes 集群,并使用真实场景来实施它。 它们使我们能够确保所有受支持的 Kubernetes 版本跨云提供商,容器引擎和网络插件工作。 他们确保最新版本的 Kubernetes 能够启用各种可选功能,安全升级,满足性能要求,并跨架构工作。
|
||||
|
||||
<!--
|
||||
With today’s [announcement from CNCF](https://www.cncf.io/announcement/2018/08/29/cncf-receives-9-million-cloud-credit-grant-from-google) – noting that Google Cloud has begun transferring ownership and management of the Kubernetes project’s cloud resources to CNCF community contributors, we are excited to embark on another journey. One that allows the project infrastructure to be owned and operated by the community of contributors, following the same open governance model that has worked for the rest of the project. Sound exciting to you? Come talk to us at #sig-testing on kubernetes.slack.com.
|
||||
-->
|
||||
|
||||
今天[来自CNCF的公告](https://www.cncf.io/announcement/2018/08/29/cncf-receives-9-million-cloud-credit-grant-from-google) - 注意到 Google Cloud 有开始将 Kubernetes 项目的云资源的所有权和管理权转让给 CNCF 社区贡献者,我们很高兴能够开始另一个旅程。 允许项目基础设施由贡献者社区拥有和运营,遵循对项目其余部分有效的相同开放治理模型。 听起来令人兴奋。 请来 kubernetes.slack.com 上的 #sig-testing on kubernetes.slack.com 与我们联系。
|
||||
|
||||
<!--
|
||||
Want to find out more? Come check out these resources:
|
||||
-->
|
||||
|
||||
想了解更多? 快来看看这些资源:
|
||||
|
||||
<!--
|
||||
* [Prow: Testing the way to Kubernetes Next](https://bentheelder.io/posts/prow)
|
||||
* [Automation and the Kubernetes Contributor Experience](https://www.youtube.com/watch?v=BsIC7gPkH5M)
|
||||
-->
|
||||
|
||||
* [Prow: Testing the way to Kubernetes Next](https://bentheelder.io/posts/prow)
|
||||
* [Automation and the Kubernetes Contributor Experience](https://www.youtube.com/watch?v=BsIC7gPkH5M)
|
||||
@@ -0,0 +1,306 @@
|
||||
---
|
||||
layout: blog
|
||||
title: 'KubeDirector:在 Kubernetes 上运行复杂状态应用程序的简单方法'
|
||||
date: 2018-10-03
|
||||
---
|
||||
|
||||
<!--
|
||||
layout: blog
|
||||
title: 'KubeDirector: The easy way to run complex stateful applications on Kubernetes'
|
||||
date: 2018-10-03
|
||||
-->
|
||||
|
||||
<!--
|
||||
**Author**: Thomas Phelan (BlueData)
|
||||
-->
|
||||
|
||||
**作者**:Thomas Phelan(BlueData)
|
||||
|
||||
<!--
|
||||
KubeDirector is an open source project designed to make it easy to run complex stateful scale-out application clusters on Kubernetes. KubeDirector is built using the custom resource definition (CRD) framework and leverages the native Kubernetes API extensions and design philosophy. This enables transparent integration with Kubernetes user/resource management as well as existing clients and tools.
|
||||
-->
|
||||
KubeDirector 是一个开源项目,旨在简化在 Kubernetes 上运行复杂的有状态扩展应用程序集群。KubeDirector 使用自定义资源定义(CRD)
|
||||
框架构建,并利用了本地 Kubernetes API 扩展和设计哲学。这支持与 Kubernetes 用户/资源 管理以及现有客户端和工具的透明集成。
|
||||
|
||||
<!--
|
||||
We recently [introduced the KubeDirector project](https://medium.com/@thomas_phelan/operation-stateful-introducing-bluek8s-and-kubernetes-director-aa204952f619/), as part of a broader open source Kubernetes initiative we call BlueK8s. I’m happy to announce that the pre-alpha
|
||||
code for [KubeDirector](https://github.com/bluek8s/kubedirector/) is now available. And in this blog post, I’ll show how it works.
|
||||
-->
|
||||
我们最近[介绍了 KubeDirector 项目](https://medium.com/@thomas_phelan/operation-stateful-introducing-bluek8s-and-kubernetes-director-aa204952f619/),作为我们称为 BlueK8s 的更广泛的 Kubernetes 开源项目的一部分。我很高兴地宣布 [KubeDirector](https://github.com/bluek8s/kubedirector/) 的
|
||||
pre-alpha 代码现在已经可用。在这篇博客文章中,我将展示它是如何工作的。
|
||||
|
||||
<!--
|
||||
KubeDirector provides the following capabilities:
|
||||
-->
|
||||
KubeDirector 提供以下功能:
|
||||
|
||||
<!--
|
||||
* The ability to run non-cloud native stateful applications on Kubernetes without modifying the code. In other words, it’s not necessary to decompose these existing applications to fit a microservices design pattern.
|
||||
* Native support for preserving application-specific configuration and state.
|
||||
* An application-agnostic deployment pattern, minimizing the time to onboard new stateful applications to Kubernetes.
|
||||
-->
|
||||
|
||||
* 无需修改代码即可在 Kubernetes 上运行非云原生有状态应用程序。换句话说,不需要分解这些现有的应用程序来适应微服务设计模式。
|
||||
* 本机支持保存特定于应用程序的配置和状态。
|
||||
* 与应用程序无关的部署模式,最大限度地减少将新的有状态应用程序装载到 Kubernetes 的时间。
|
||||
|
||||
<!--
|
||||
KubeDirector enables data scientists familiar with data-intensive distributed applications such as Hadoop, Spark, Cassandra, TensorFlow, Caffe2, etc. to run these applications on Kubernetes -- with a minimal learning curve and no need to write GO code. The applications controlled by KubeDirector are defined by some basic metadata and an associated package of configuration artifacts. The application metadata is referred to as a KubeDirectorApp resource.
|
||||
-->
|
||||
KubeDirector 使熟悉数据密集型分布式应用程序(如 Hadoop、Spark、Cassandra、TensorFlow、Caffe2 等)的数据科学家能够在 Kubernetes 上运行这些应用程序 -- 只需极少的学习曲线,无需编写 GO 代码。由 KubeDirector 控制的应用程序由一些基本元数据和相关的配置工件包定义。应用程序元数据称为 KubeDirectorApp 资源。
|
||||
|
||||
<!--
|
||||
To understand the components of KubeDirector, clone the repository on [GitHub](https://github.com/bluek8s/kubedirector/) using a command similar to:
|
||||
-->
|
||||
要了解 KubeDirector 的组件,请使用类似于以下的命令在 [GitHub](https://github.com/bluek8s/kubedirector/) 上克隆存储库:
|
||||
|
||||
```
|
||||
git clone http://<userid>@github.com/bluek8s/kubedirector.
|
||||
```
|
||||
|
||||
<!--
|
||||
The KubeDirectorApp definition for the Spark 2.2.1 application is located
|
||||
in the file `kubedirector/deploy/example_catalog/cr-app-spark221e2.json`.
|
||||
-->
|
||||
Spark 2.2.1 应用程序的 KubeDirectorApp 定义位于文件 `kubedirector/deploy/example_catalog/cr-app-spark221e2.json` 中。
|
||||
|
||||
```
|
||||
~> cat kubedirector/deploy/example_catalog/cr-app-spark221e2.json
|
||||
{
|
||||
"apiVersion": "kubedirector.bluedata.io/v1alpha1",
|
||||
"kind": "KubeDirectorApp",
|
||||
"metadata": {
|
||||
"name" : "spark221e2"
|
||||
},
|
||||
"spec" : {
|
||||
"systemctlMounts": true,
|
||||
"config": {
|
||||
"node_services": [
|
||||
{
|
||||
"service_ids": [
|
||||
"ssh",
|
||||
"spark",
|
||||
"spark_master",
|
||||
"spark_worker"
|
||||
],
|
||||
…
|
||||
```
|
||||
|
||||
<!--
|
||||
The configuration of an application cluster is referred to as a KubeDirectorCluster resource. The
|
||||
KubeDirectorCluster definition for a sample Spark 2.2.1 cluster is located in the file
|
||||
`kubedirector/deploy/example_clusters/cr-cluster-spark221.e1.yaml`.
|
||||
-->
|
||||
应用程序集群的配置称为 KubeDirectorCluster 资源。示例 Spark 2.2.1 集群的 KubeDirectorCluster 定义位于文件
|
||||
`kubedirector/deploy/example_clusters/cr-cluster-spark221.e1.yaml` 中。
|
||||
|
||||
```
|
||||
~> cat kubedirector/deploy/example_clusters/cr-cluster-spark221.e1.yaml
|
||||
apiVersion: "kubedirector.bluedata.io/v1alpha1"
|
||||
kind: "KubeDirectorCluster"
|
||||
metadata:
|
||||
name: "spark221e2"
|
||||
spec:
|
||||
app: spark221e2
|
||||
roles:
|
||||
- name: controller
|
||||
replicas: 1
|
||||
resources:
|
||||
requests:
|
||||
memory: "4Gi"
|
||||
cpu: "2"
|
||||
limits:
|
||||
memory: "4Gi"
|
||||
cpu: "2"
|
||||
- name: worker
|
||||
replicas: 2
|
||||
resources:
|
||||
requests:
|
||||
memory: "4Gi"
|
||||
cpu: "2"
|
||||
limits:
|
||||
memory: "4Gi"
|
||||
cpu: "2"
|
||||
- name: jupyter
|
||||
…
|
||||
```
|
||||
|
||||
<!--
|
||||
## Running Spark on Kubernetes with KubeDirector
|
||||
-->
|
||||
|
||||
## 使用 KubeDirector 在 Kubernetes 上运行 Spark
|
||||
|
||||
<!--
|
||||
With KubeDirector, it’s easy to run Spark clusters on Kubernetes.
|
||||
-->
|
||||
使用 KubeDirector,可以轻松在 Kubernetes 上运行 Spark 集群。
|
||||
|
||||
<!--
|
||||
First, verify that Kubernetes (version 1.9 or later) is running, using the command `kubectl version`
|
||||
-->
|
||||
首先,使用命令 `kubectl version` 验证 Kubernetes(版本 1.9 或更高)是否正在运行
|
||||
|
||||
```
|
||||
~> kubectl version
|
||||
Client Version: version.Info{Major:"1", Minor:"11", GitVersion:"v1.11.3", GitCommit:"a4529464e4629c21224b3d52edfe0ea91b072862", GitTreeState:"clean", BuildDate:"2018-09-09T18:02:47Z", GoVersion:"go1.10.3", Compiler:"gc", Platform:"linux/amd64"}
|
||||
Server Version: version.Info{Major:"1", Minor:"11", GitVersion:"v1.11.3", GitCommit:"a4529464e4629c21224b3d52edfe0ea91b072862", GitTreeState:"clean", BuildDate:"2018-09-09T17:53:03Z", GoVersion:"go1.10.3", Compiler:"gc", Platform:"linux/amd64"}
|
||||
```
|
||||
|
||||
<!--
|
||||
Deploy the KubeDirector service and the example KubeDirectorApp resource definitions with the commands:
|
||||
-->
|
||||
使用以下命令部署 KubeDirector 服务和示例 KubeDirectorApp 资源定义:
|
||||
|
||||
```
|
||||
cd kubedirector
|
||||
make deploy
|
||||
```
|
||||
|
||||
<!--
|
||||
These will start the KubeDirector pod:
|
||||
-->
|
||||
这些将启动 KubeDirector pod:
|
||||
|
||||
```
|
||||
~> kubectl get pods
|
||||
NAME READY STATUS RESTARTS AGE
|
||||
kubedirector-58cf59869-qd9hb 1/1 Running 0 1m
|
||||
```
|
||||
|
||||
<!--
|
||||
List the installed KubeDirector applications with `kubectl get KubeDirectorApp`
|
||||
-->
|
||||
`kubectl get KubeDirectorApp` 列出中已安装的 KubeDirector 应用程序
|
||||
|
||||
```
|
||||
~> kubectl get KubeDirectorApp
|
||||
NAME AGE
|
||||
cassandra311 30m
|
||||
spark211up 30m
|
||||
spark221e2 30m
|
||||
```
|
||||
|
||||
<!--
|
||||
Now you can launch a Spark 2.2.1 cluster using the example KubeDirectorCluster file and the
|
||||
`kubectl create -f deploy/example_clusters/cr-cluster-spark211up.yaml` command.
|
||||
Verify that the Spark cluster has been started:
|
||||
-->
|
||||
现在,您可以使用示例 KubeDirectorCluster 文件和 `kubectl create -f deploy/example_clusters/cr-cluster-spark211up.yaml` 命令
|
||||
启动 Spark 2.2.1 集群。验证 Spark 集群已经启动:
|
||||
|
||||
```
|
||||
~> kubectl get pods
|
||||
NAME READY STATUS RESTARTS AGE
|
||||
kubedirector-58cf59869-djdwl 1/1 Running 0 19m
|
||||
spark221e2-controller-zbg4d-0 1/1 Running 0 23m
|
||||
spark221e2-jupyter-2km7q-0 1/1 Running 0 23m
|
||||
spark221e2-worker-4gzbz-0 1/1 Running 0 23m
|
||||
spark221e2-worker-4gzbz-1 1/1 Running 0 23m
|
||||
```
|
||||
|
||||
<!--
|
||||
The running services now include the Spark services:
|
||||
-->
|
||||
现在运行的服务包括 Spark 服务:
|
||||
|
||||
```
|
||||
~> kubectl get service
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
kubedirector ClusterIP 10.98.234.194 <none> 60000/TCP 1d
|
||||
kubernetes ClusterIP 10.96.0.1 <none> 443/TCP 1d
|
||||
svc-spark221e2-5tg48 ClusterIP None <none> 8888/TCP 21s
|
||||
svc-spark221e2-controller-tq8d6-0 NodePort 10.104.181.123 <none> 22:30534/TCP,8080:31533/TCP,7077:32506/TCP,8081:32099/TCP 20s
|
||||
svc-spark221e2-jupyter-6989v-0 NodePort 10.105.227.249 <none> 22:30632/TCP,8888:30355/TCP 20s
|
||||
svc-spark221e2-worker-d9892-0 NodePort 10.107.131.165 <none> 22:30358/TCP,8081:32144/TCP 20s
|
||||
svc-spark221e2-worker-d9892-1 NodePort 10.110.88.221 <none> 22:30294/TCP,8081:31436/TCP 20s
|
||||
```
|
||||
|
||||
<!--
|
||||
Pointing the browser at port 31533 connects to the Spark Master UI:
|
||||
-->
|
||||
将浏览器指向端口 31533 连接到 Spark 主节点 UI:
|
||||
|
||||

|
||||
|
||||
<!--
|
||||
That’s all there is to it!
|
||||
In fact, in the example above we also deployed a Jupyter notebook along with the Spark cluster.
|
||||
-->
|
||||
就是这样!
|
||||
事实上,在上面的例子中,我们还部署了一个 Jupyter notebook 和 Spark 集群。
|
||||
|
||||
<!--
|
||||
To start another application (e.g. Cassandra), just specify another KubeDirectorApp file:
|
||||
-->
|
||||
要启动另一个应用程序(例如 Cassandra),只需指定另一个 KubeDirectorApp 文件:
|
||||
|
||||
```
|
||||
kubectl create -f deploy/example_clusters/cr-cluster-cassandra311.yaml
|
||||
```
|
||||
|
||||
<!--
|
||||
See the running Cassandra cluster:
|
||||
-->
|
||||
查看正在运行的 Cassandra 集群:
|
||||
|
||||
```
|
||||
~> kubectl get pods
|
||||
NAME READY STATUS RESTARTS AGE
|
||||
cassandra311-seed-v24r6-0 1/1 Running 0 1m
|
||||
cassandra311-seed-v24r6-1 1/1 Running 0 1m
|
||||
cassandra311-worker-rqrhl-0 1/1 Running 0 1m
|
||||
cassandra311-worker-rqrhl-1 1/1 Running 0 1m
|
||||
kubedirector-58cf59869-djdwl 1/1 Running 0 1d
|
||||
spark221e2-controller-tq8d6-0 1/1 Running 0 22m
|
||||
spark221e2-jupyter-6989v-0 1/1 Running 0 22m
|
||||
spark221e2-worker-d9892-0 1/1 Running 0 22m
|
||||
spark221e2-worker-d9892-1 1/1 Running 0 22m
|
||||
```
|
||||
|
||||
<!--
|
||||
Now you have a Spark cluster (with a Jupyter notebook) and a Cassandra cluster running on Kubernetes.
|
||||
Use `kubectl get service` to see the set of services.
|
||||
-->
|
||||
现在,您有一个 Spark 集群(带有 Jupyter notebook )和一个运行在 Kubernetes 上的 Cassandra 集群。
|
||||
使用 `kubectl get service` 查看服务集。
|
||||
|
||||
```
|
||||
~> kubectl get service
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
kubedirector ClusterIP 10.98.234.194 <none> 60000/TCP 1d
|
||||
kubernetes ClusterIP 10.96.0.1 <none> 443/TCP 1d
|
||||
svc-cassandra311-seed-v24r6-0 NodePort 10.96.94.204 <none> 22:31131/TCP,9042:30739/TCP 3m
|
||||
svc-cassandra311-seed-v24r6-1 NodePort 10.106.144.52 <none> 22:30373/TCP,9042:32662/TCP 3m
|
||||
svc-cassandra311-vhh29 ClusterIP None <none> 8888/TCP 3m
|
||||
svc-cassandra311-worker-rqrhl-0 NodePort 10.109.61.194 <none> 22:31832/TCP,9042:31962/TCP 3m
|
||||
svc-cassandra311-worker-rqrhl-1 NodePort 10.97.147.131 <none> 22:31454/TCP,9042:31170/TCP 3m
|
||||
svc-spark221e2-5tg48 ClusterIP None <none> 8888/TCP 24m
|
||||
svc-spark221e2-controller-tq8d6-0 NodePort 10.104.181.123 <none> 22:30534/TCP,8080:31533/TCP,7077:32506/TCP,8081:32099/TCP 24m
|
||||
svc-spark221e2-jupyter-6989v-0 NodePort 10.105.227.249 <none> 22:30632/TCP,8888:30355/TCP 24m
|
||||
svc-spark221e2-worker-d9892-0 NodePort 10.107.131.165 <none> 22:30358/TCP,8081:32144/TCP 24m
|
||||
svc-spark221e2-worker-d9892-1 NodePort 10.110.88.221 <none> 22:30294/TCP,8081:31436/TCP 24m
|
||||
```
|
||||
|
||||
<!--
|
||||
## Get Involved
|
||||
-->
|
||||
|
||||
## 参与其中
|
||||
|
||||
<!--
|
||||
KubeDirector is a fully open source, Apache v2 licensed, project – the first of multiple open source projects within a broader initiative we call BlueK8s.
|
||||
The pre-alpha code for KubeDirector has just been released and we would love for you to join the growing community of developers, contributors, and adopters.
|
||||
Follow [@BlueK8s](https://twitter.com/BlueK8s/) on Twitter and get involved through these channels:
|
||||
-->
|
||||
KubeDirector 是一个完全开放源码的 Apache v2 授权项目 – 在我们称为 BlueK8s 的更广泛的计划中,它是多个开放源码项目中的第一个。
|
||||
KubeDirector 的 pre-alpha 代码刚刚发布,我们希望您加入到不断增长的开发人员、贡献者和使用者社区。
|
||||
在 Twitter 上关注 [@BlueK8s](https://twitter.com/BlueK8s/),并通过以下渠道参与:
|
||||
|
||||
<!--
|
||||
* KubeDirector [chat room on Slack](https://join.slack.com/t/bluek8s/shared_invite/enQtNDUwMzkwODY5OTM4LTRhYmRmZmE4YzY3OGUzMjA1NDg0MDVhNDQ2MGNkYjRhM2RlMDNjMTI1NDQyMjAzZGVlMDFkNThkNGFjZGZjMGY/)
|
||||
* KubeDirector [GitHub repo](https://github.com/bluek8s/kubedirector/)
|
||||
-->
|
||||
|
||||
* KubeDirector [Slack 聊天室](https://join.slack.com/t/bluek8s/shared_invite/enQtNDUwMzkwODY5OTM4LTRhYmRmZmE4YzY3OGUzMjA1NDg0MDVhNDQ2MGNkYjRhM2RlMDNjMTI1NDQyMjAzZGVlMDFkNThkNGFjZGZjMGY/)
|
||||
* KubeDirector [GitHub 仓库](https://github.com/bluek8s/kubedirector/)
|
||||
@@ -0,0 +1,268 @@
|
||||
---
|
||||
layout: blog
|
||||
title: 'Kubernetes 中的拓扑感知数据卷供应'
|
||||
date: 2018-10-11
|
||||
---
|
||||
<!--
|
||||
---
|
||||
layout: blog
|
||||
title: 'Topology-Aware Volume Provisioning in Kubernetes'
|
||||
date: 2018-10-11
|
||||
---
|
||||
-->
|
||||
|
||||
<!--
|
||||
**Author**: Michelle Au (Google)
|
||||
-->
|
||||
**作者**: Michelle Au(谷歌)
|
||||
|
||||
<!--
|
||||
The multi-zone cluster experience with persistent volumes is improving in Kubernetes 1.12 with the topology-aware dynamic provisioning beta feature. This feature allows Kubernetes to make intelligent decisions when dynamically provisioning volumes by getting scheduler input on the best place to provision a volume for a pod. In multi-zone clusters, this means that volumes will get provisioned in an appropriate zone that can run your pod, allowing you to easily deploy and scale your stateful workloads across failure domains to provide high availability and fault tolerance.
|
||||
-->
|
||||
通过提供拓扑感知动态卷供应功能,具有持久卷的多区域集群体验在 Kubernetes 1.12 中得到了改进。此功能使得 Kubernetes 在动态供应卷时能做出明智的决策,方法是从调度器获得为 Pod 提供数据卷的最佳位置。在多区域集群环境,这意味着数据卷能够在满足你的 Pod 运行需要的合适的区域被供应,从而允许您跨故障域轻松部署和扩展有状态工作负载,从而提供高可用性和容错能力。
|
||||
|
||||
<!--
|
||||
## Previous challenges
|
||||
-->
|
||||
## 以前的挑战
|
||||
|
||||
<!--
|
||||
Before this feature, running stateful workloads with zonal persistent disks (such as AWS ElasticBlockStore, Azure Disk, GCE PersistentDisk) in multi-zone clusters had many challenges. Dynamic provisioning was handled independently from pod scheduling, which meant that as soon as you created a PersistentVolumeClaim (PVC), a volume would get provisioned. This meant that the provisioner had no knowledge of what pods were using the volume, and any pod constraints it had that could impact scheduling.
|
||||
-->
|
||||
在此功能被提供之前,在多区域集群中使用区域化的持久磁盘(例如 AWS ElasticBlockStore,Azure Disk,GCE PersistentDisk)运行有状态工作负载存在许多挑战。动态供应独立于 Pod 调度处理,这意味着只要您创建了一个 PersistentVolumeClaim(PVC),一个卷就会被供应。这也意味着供应者不知道哪些 Pod 正在使用该卷,也不清楚任何可能影响调度的 Pod 约束。
|
||||
|
||||
<!--
|
||||
This resulted in unschedulable pods because volumes were provisioned in zones that:
|
||||
-->
|
||||
这导致了不可调度的 Pod,因为在以下区域中配置了卷:
|
||||
|
||||
<!--
|
||||
* did not have enough CPU or memory resources to run the pod
|
||||
* conflicted with node selectors, pod affinity or anti-affinity policies
|
||||
* could not run the pod due to taints
|
||||
-->
|
||||
* 没有足够的 CPU 或内存资源来运行 Pod
|
||||
* 与节点选择器、Pod 亲和或反亲和策略冲突
|
||||
* 由于污点(taint)不能运行 Pod
|
||||
|
||||
<!--
|
||||
Another common issue was that a non-StatefulSet pod using multiple persistent volumes could have each volume provisioned in a different zone, again resulting in an unschedulable pod.
|
||||
-->
|
||||
另一个常见问题是,使用多个持久卷的非有状态 Pod 可能会在不同的区域中配置每个卷,从而导致一个不可调度的 Pod。
|
||||
|
||||
<!--
|
||||
Suboptimal workarounds included overprovisioning of nodes, or manual creation of volumes in the correct zones, making it difficult to dynamically deploy and scale stateful workloads.
|
||||
-->
|
||||
次优的解决方法包括节点超配,或在正确的区域中手动创建卷,但这会造成难以动态部署和扩展有状态工作负载的问题。
|
||||
|
||||
<!--
|
||||
The topology-aware dynamic provisioning feature addresses all of the above issues.
|
||||
-->
|
||||
拓扑感知动态供应功能解决了上述所有问题。
|
||||
|
||||
<!--
|
||||
## Supported Volume Types
|
||||
-->
|
||||
## 支持的卷类型
|
||||
|
||||
<!--
|
||||
In 1.12, the following drivers support topology-aware dynamic provisioning:
|
||||
-->
|
||||
在 1.12 中,以下驱动程序支持拓扑感知动态供应:
|
||||
|
||||
<!--
|
||||
* AWS EBS
|
||||
* Azure Disk
|
||||
* GCE PD (including Regional PD)
|
||||
* CSI (alpha) - currently only the GCE PD CSI driver has implemented topology support
|
||||
-->
|
||||
* AWS EBS
|
||||
* Azure Disk
|
||||
* GCE PD (包括 Regional PD)
|
||||
* CSI(alpha) - 目前只有 GCE PD CSI 驱动实现了拓扑支持
|
||||
|
||||
<!--
|
||||
## Design Principles
|
||||
-->
|
||||
## 设计原则
|
||||
|
||||
<!--
|
||||
While the initial set of supported plugins are all zonal-based, we designed this feature to adhere to the Kubernetes principle of portability across environments. Topology specification is generalized and uses a similar label-based specification like in Pod nodeSelectors and nodeAffinity. This mechanism allows you to define your own topology boundaries, such as racks in on-premise clusters, without requiring modifications to the scheduler to understand these custom topologies.
|
||||
-->
|
||||
虽然最初支持的插件集都是基于区域的,但我们设计此功能时遵循 Kubernetes 跨环境可移植性的原则。
|
||||
拓扑规范是通用的,并使用类似于基于标签的规范,如 Pod nodeSelectors 和 nodeAffinity。
|
||||
该机制允许您定义自己的拓扑边界,例如内部部署集群中的机架,而无需修改调度程序以了解这些自定义拓扑。
|
||||
|
||||
<!--
|
||||
In addition, the topology information is abstracted away from the pod specification, so a pod does not need knowledge of the underlying storage system’s topology characteristics. This means that you can use the same pod specification across multiple clusters, environments, and storage systems.
|
||||
-->
|
||||
此外,拓扑信息是从 Pod 规范中抽象出来的,因此 Pod 不需要了解底层存储系统的拓扑特征。
|
||||
这意味着您可以在多个集群、环境和存储系统中使用相同的 Pod 规范。
|
||||
|
||||
<!--
|
||||
## Getting Started
|
||||
-->
|
||||
## 入门
|
||||
|
||||
<!--
|
||||
To enable this feature, all you need to do is to create a StorageClass with `volumeBindingMode` set to `WaitForFirstConsumer`:
|
||||
-->
|
||||
要启用此功能,您需要做的就是创建一个将 `volumeBindingMode` 设置为 `WaitForFirstConsumer` 的 StorageClass:
|
||||
|
||||
```
|
||||
kind: StorageClass
|
||||
apiVersion: storage.k8s.io/v1
|
||||
metadata:
|
||||
name: topology-aware-standard
|
||||
provisioner: kubernetes.io/gce-pd
|
||||
volumeBindingMode: WaitForFirstConsumer
|
||||
parameters:
|
||||
type: pd-standard
|
||||
```
|
||||
|
||||
<!--
|
||||
This new setting instructs the volume provisioner to not create a volume immediately, and instead, wait for a pod using an associated PVC to run through scheduling. Note that previous StorageClass `zone` and `zones` parameters do not need to be specified anymore, as pod policies now drive the decision of which zone to provision a volume in.
|
||||
-->
|
||||
这个新设置表明卷配置器不立即创建卷,而是等待使用关联的 PVC 的 Pod 通过调度运行。
|
||||
请注意,不再需要指定以前的 StorageClass `zone` 和 `zones` 参数,因为现在在哪个区域中配置卷由 Pod 策略决定。
|
||||
|
||||
<!--
|
||||
Next, create a pod and PVC with this StorageClass. This sequence is the same as before, but with a different StorageClass specified in the PVC. The following is a hypothetical example, demonstrating the capabilities of the new feature by specifying many pod constraints and scheduling policies:
|
||||
-->
|
||||
接下来,使用此 StorageClass 创建一个 Pod 和 PVC。
|
||||
此过程与之前相同,但在 PVC 中指定了不同的 StorageClass。
|
||||
以下是一个假设示例,通过指定许多 Pod 约束和调度策略来演示新功能特性:
|
||||
|
||||
<!--
|
||||
* multiple PVCs in a pod
|
||||
* nodeAffinity across a subset of zones
|
||||
* pod anti-affinity on zones
|
||||
-->
|
||||
* 一个 Pod 多个 PVC
|
||||
* 跨子区域的节点亲和
|
||||
* 同一区域 Pod 反亲和
|
||||
|
||||
```
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: web
|
||||
spec:
|
||||
serviceName: "nginx"
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: nginx
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: nginx
|
||||
spec:
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: failure-domain.beta.kubernetes.io/zone
|
||||
operator: In
|
||||
values:
|
||||
- us-central1-a
|
||||
- us-central1-f
|
||||
podAntiAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
- labelSelector:
|
||||
matchExpressions:
|
||||
- key: app
|
||||
operator: In
|
||||
values:
|
||||
- nginx
|
||||
topologyKey: failure-domain.beta.kubernetes.io/zone
|
||||
containers:
|
||||
- name: nginx
|
||||
image: gcr.io/google_containers/nginx-slim:0.8
|
||||
ports:
|
||||
- containerPort: 80
|
||||
name: web
|
||||
volumeMounts:
|
||||
- name: www
|
||||
mountPath: /usr/share/nginx/html
|
||||
- name: logs
|
||||
mountPath: /logs
|
||||
volumeClaimTemplates:
|
||||
- metadata:
|
||||
name: www
|
||||
spec:
|
||||
accessModes: [ "ReadWriteOnce" ]
|
||||
storageClassName: topology-aware-standard
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Gi
|
||||
- metadata:
|
||||
name: logs
|
||||
spec:
|
||||
accessModes: [ "ReadWriteOnce" ]
|
||||
storageClassName: topology-aware-standard
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
```
|
||||
|
||||
<!--
|
||||
Afterwards, you can see that the volumes were provisioned in zones according to the policies set by the pod:
|
||||
-->
|
||||
之后,您可以看到根据 Pod 设置的策略在区域中配置卷:
|
||||
|
||||
```
|
||||
$ kubectl get pv -o=jsonpath='{range .items[*]}{.spec.claimRef.name}{"\t"}{.metadata.labels.failure\-domain\.beta\.kubernetes\.io/zone}{"\n"}{end}'
|
||||
www-web-0 us-central1-f
|
||||
logs-web-0 us-central1-f
|
||||
www-web-1 us-central1-a
|
||||
logs-web-1 us-central1-a
|
||||
```
|
||||
|
||||
<!--
|
||||
## How can I learn more?
|
||||
-->
|
||||
## 我怎样才能了解更多?
|
||||
|
||||
<!--
|
||||
Official documentation on the topology-aware dynamic provisioning feature is available here:https://kubernetes.io/docs/concepts/storage/storage-classes/#volume-binding-mode
|
||||
-->
|
||||
有关拓扑感知动态供应功能的官方文档可在此处获取:https://kubernetes.io/docs/concepts/storage/storage-classes/#volume-binding-mode
|
||||
|
||||
<!--
|
||||
Documentation for CSI drivers is available at https://kubernetes-csi.github.io/docs/
|
||||
-->
|
||||
有关 CSI 驱动程序的文档,请访问:https://kubernetes-csi.github.io/docs/
|
||||
|
||||
<!--
|
||||
## What’s next?
|
||||
-->
|
||||
## 下一步是什么?
|
||||
|
||||
<!--
|
||||
We are actively working on improving this feature to support:
|
||||
-->
|
||||
我们正积极致力于改进此功能以支持:
|
||||
|
||||
<!--
|
||||
* more volume types, including dynamic provisioning for local volumes
|
||||
* dynamic volume attachable count and capacity limits per node
|
||||
-->
|
||||
* 更多卷类型,包括本地卷的动态供应
|
||||
* 动态容量可附加计数和每个节点的容量限制
|
||||
|
||||
<!--
|
||||
## How do I get involved?
|
||||
-->
|
||||
## 我如何参与?
|
||||
|
||||
<!--
|
||||
If you have feedback for this feature or are interested in getting involved with the design and development, join the [Kubernetes Storage Special-Interest-Group](https://github.com/kubernetes/community/tree/master/sig-storage) (SIG). We’re rapidly growing and always welcome new contributors.
|
||||
-->
|
||||
如果您对此功能有反馈意见或有兴趣参与设计和开发,请加入 [Kubernetes 存储特别兴趣小组](https://github.com/kubernetes/community/tree/master/sig-storage)(SIG)。我们正在快速成长,并始终欢迎新的贡献者。
|
||||
|
||||
<!--
|
||||
Special thanks to all the contributors that helped bring this feature to beta, including Cheng Xing ([verult](https://github.com/verult)), Chuqiang Li ([lichuqiang](https://github.com/lichuqiang)), David Zhu ([davidz627](https://github.com/davidz627)), Deep Debroy ([ddebroy](https://github.com/ddebroy)), Jan Šafránek ([jsafrane](https://github.com/jsafrane)), Jordan Liggitt ([liggitt](https://github.com/liggitt)), Michelle Au ([msau42](https://github.com/msau42)), Pengfei Ni ([feiskyer](https://github.com/feiskyer)), Saad Ali ([saad-ali](https://github.com/saad-ali)), Tim Hockin ([thockin](https://github.com/thockin)), and Yecheng Fu ([cofyc](https://github.com/cofyc)).
|
||||
-->
|
||||
特别感谢帮助推出此功能的所有贡献者,包括 Cheng Xing ([verult](https://github.com/verult))、Chuqiang Li ([lichuqiang](https://github.com/lichuqiang))、David Zhu ([davidz627](https://github.com/davidz627))、Deep Debroy ([ddebroy](https://github.com/ddebroy))、Jan Šafránek ([jsafrane](https://github.com/jsafrane))、Jordan Liggitt ([liggitt](https://github.com/liggitt))、Michelle Au ([msau42](https://github.com/msau42))、Pengfei Ni ([feiskyer](https://github.com/feiskyer))、Saad Ali ([saad-ali](https://github.com/saad-ali))、Tim Hockin ([thockin](https://github.com/thockin)),以及 Yecheng Fu ([cofyc](https://github.com/cofyc))。
|
||||
@@ -0,0 +1,73 @@
|
||||
---
|
||||
layout: blog
|
||||
title: '2018 年督导委员会选举结果'
|
||||
date: 2018-10-15
|
||||
---
|
||||
<!--
|
||||
---
|
||||
layout: blog
|
||||
title: '2018 Steering Committee Election Results'
|
||||
date: 2018-10-15
|
||||
---
|
||||
-->
|
||||
|
||||
<!-- **Authors**: Jorge Castro (Heptio), Ihor Dvoretskyi (CNCF), Paris Pittman (Google) -->
|
||||
**作者**: Jorge Castro (Heptio), Ihor Dvoretskyi (CNCF), Paris Pittman (Google)
|
||||
|
||||
<!--
|
||||
## Results
|
||||
-->
|
||||
## 结果
|
||||
<!--
|
||||
The [Kubernetes Steering Committee Election](https://kubernetes.io/blog/2018/09/06/2018-steering-committee-election-cycle-kicks-off/) is now complete and the following candidates came ahead to secure two year terms that start immediately:
|
||||
-->
|
||||
[Kubernetes 督导委员会选举](https://kubernetes.io/blog/2018/09/06/2018-steering-committee-election-cycle-kicks-off/)现已完成,以下候选人获得了立即开始的两年任期:
|
||||
|
||||
* Aaron Crickenberger, Google, [@spiffxp](https://github.com/spiffxp)
|
||||
* Davanum Srinivas, Huawei, [@dims](https://github.com/dims)
|
||||
* Tim St. Clair, Heptio, [@timothysc](https://github.com/timothysc)
|
||||
|
||||
<!--
|
||||
## Big Thanks!
|
||||
-->
|
||||
## 十分感谢!
|
||||
|
||||
<!--
|
||||
* Steering Committee Member Emeritus [Quinton Hoole](https://github.com/quinton-hoole) for his service to the community over the past year. We look forward to
|
||||
* The candidates that came forward to run for election. May we always have a strong set of people who want to push community forward like yours in every election.
|
||||
* All 307 voters who cast a ballot.
|
||||
* And last but not least...Cornell University for hosting [CIVS](https://civs.cs.cornell.edu/)!
|
||||
-->
|
||||
* 督导委员会荣誉退休成员 [Quinton Hoole](https://github.com/quinton-hoole),表扬他在过去一年为社区所作的贡献。我们期待着
|
||||
* 参加竞选的候选人。愿我们永远拥有一群强大的人,他们希望在每一次选举中都能像你们一样推动社区向前发展。
|
||||
* 共计 307 名选民参与投票。
|
||||
* 本次选举由康奈尔大学主办 [CIVS](https://civs.cs.cornell.edu/)!
|
||||
|
||||
<!--
|
||||
## Get Involved with the Steering Committee
|
||||
-->
|
||||
## 加入督导委员会
|
||||
<!--
|
||||
You can follow along to Steering Committee [backlog items](https://git.k8s.io/steering/backlog.md) and weigh in by filing an issue or creating a PR against their [repo](https://github.com/kubernetes/steering). They meet bi-weekly on [Wednesdays at 8pm UTC](https://github.com/kubernetes/steering) and regularly attend Meet Our Contributors.
|
||||
-->
|
||||
你可以关注督导委员会的[任务清单](https://git.k8s.io/steering/backlog.md),并通过向他们的[代码仓库](https://github.com/kubernetes/steering)提交 issue 或 PR 的方式来参与。他们也会在[UTC 时间每周三晚 8 点](https://github.com/kubernetes/steering)举行会议,并定期与我们的贡献者见面。
|
||||
|
||||
<!--
|
||||
Steering Committee Meetings:
|
||||
-->
|
||||
督导委员会会议:
|
||||
|
||||
* [YouTube 播放列表](https://www.youtube.com/playlist?list=PL69nYSiGNLP1yP1B_nd9-drjoxp0Q14qM)
|
||||
|
||||
<!--
|
||||
Meet Our Contributors Steering AMA’s:
|
||||
-->
|
||||
与我们的贡献者会面:
|
||||
|
||||
<!--
|
||||
* [Oct 3 2018](https://youtu.be/x6Jm8p0K-IQ)
|
||||
* [Sept 5 2018](https://youtu.be/UbxWV12Or58)
|
||||
-->
|
||||
|
||||
* [2018 年 10 月 3 日](https://youtu.be/x6Jm8p0K-IQ)
|
||||
* [2018 年 7 月 5 日](https://youtu.be/UbxWV12Or58)
|
||||
+118
@@ -0,0 +1,118 @@
|
||||
---
|
||||
layout: "Blog"
|
||||
title: "Kubernetes 2018 年北美贡献者峰会"
|
||||
date: 2018-10-16
|
||||
---
|
||||
<!--
|
||||
---
|
||||
layout: "Blog"
|
||||
title: "Kubernetes 2018 North American Contributor Summit"
|
||||
date: 2018-10-16
|
||||
---
|
||||
-->
|
||||
<!--
|
||||
**Authors:**
|
||||
-->
|
||||
**作者:**
|
||||
<!--
|
||||
[Bob Killen][bob] (University of Michigan)
|
||||
[Sahdev Zala][sahdev] (IBM),
|
||||
[Ihor Dvoretskyi][ihor] (CNCF)
|
||||
-->
|
||||
[Bob Killen][bob](密歇根大学)
|
||||
[Sahdev Zala][sahdev](IBM),
|
||||
[Ihor Dvoretskyi][ihor](CNCF)
|
||||
|
||||
<!--
|
||||
The 2018 North American Kubernetes Contributor Summit to be hosted right before
|
||||
[KubeCon + CloudNativeCon][kubecon] Seattle is shaping up to be the largest yet.
|
||||
-->
|
||||
2018 年北美 Kubernetes 贡献者峰会将在西雅图 [KubeCon + CloudNativeCon][kubecon] 会议之前举办,这将是迄今为止规模最大的一次盛会。
|
||||
<!--
|
||||
It is an event that brings together new and current contributors alike to
|
||||
connect and share face-to-face; and serves as an opportunity for existing
|
||||
contributors to help shape the future of community development. For new
|
||||
community members, it offers a welcoming space to learn, explore and put the
|
||||
contributor workflow to practice.
|
||||
-->
|
||||
这是一个将新老贡献者聚集在一起,面对面交流和分享的活动;并为现有的贡献者提供一个机会,帮助塑造社区发展的未来。它为新的社区成员提供了一个学习、探索和实践贡献工作流程的良好空间。
|
||||
|
||||
<!--
|
||||
Unlike previous Contributor Summits, the event now spans two-days with a more
|
||||
relaxed ‘hallway’ track and general Contributor get-together to be hosted from
|
||||
5-8pm on Sunday December 9th at the [Garage Lounge and Gaming Hall][garage], just
|
||||
a short walk away from the Convention Center. There, contributors can enjoy
|
||||
billiards, bowling, trivia and more; accompanied by a variety of food and drink.
|
||||
-->
|
||||
与之前的贡献者峰会不同,本次活动为期两天,有一个更为轻松的行程安排,一般贡献者将于 12 月 9 日(周日)下午 5 点至 8 点在距离会议中心仅几步远的 [Garage Lounge and Gaming Hall][garage] 举办峰会。在那里,贡献者也可以进行台球、保龄球等娱乐活动,而且还有各种食品和饮料。
|
||||
|
||||
<!--
|
||||
Things pick up the following day, Monday the 10th with three separate tracks:
|
||||
-->
|
||||
接下来的一天,也就是 10 号星期一,有三个独立的会议你可以选择参与:
|
||||
|
||||
<!--
|
||||
### New Contributor Workshop:
|
||||
A half day workshop aimed at getting new and first time contributors onboarded
|
||||
and comfortable with working within the Kubernetes Community. Staying for the
|
||||
duration is required; this is not a workshop you can drop into.
|
||||
-->
|
||||
### 新贡献者研讨会:
|
||||
|
||||
为期半天的研讨会旨在让新贡献者加入社区,并营造一个良好的 Kubernetes 社区工作环境。
|
||||
请在开会期间保持在场,该讨论会不允许随意进出。
|
||||
|
||||
<!--
|
||||
### Current Contributor Track:
|
||||
Reserved for those that are actively engaged with the development of the
|
||||
project; the Current Contributor Track includes Talks, Workshops, Birds of a
|
||||
Feather, Unconferences, Steering Committee Sessions, and more! Keep an eye on
|
||||
the [schedule in GitHub][schedule] as content is frequently being updated.
|
||||
-->
|
||||
### 当前贡献者追踪:
|
||||
|
||||
保留给那些积极参与项目开发的贡献者;目前的贡献者追踪包括讲座、研讨会、聚会、Unconferences 会议、指导委员会会议等等!
|
||||
请留意 [GitHub 中的时间表][时间表],因为内容经常更新。
|
||||
|
||||
<!--
|
||||
### Docs Sprint:
|
||||
SIG-Docs will have a curated list of issues and challenges to be tackled closer
|
||||
to the event date.
|
||||
-->
|
||||
### Docs 冲刺:
|
||||
|
||||
SIG-Docs 将在活动日期临近的时候列出一个需要处理的问题和挑战列表。
|
||||
|
||||
<!--
|
||||
## To Register:
|
||||
To register for the Contributor Summit, see the [Registration section of the
|
||||
Event Details in GitHub][register]. Please note that registrations are being
|
||||
reviewed. If you select the “Current Contributor Track” and are not an active
|
||||
contributor, you will be asked to attend the New Contributor Workshop, or asked
|
||||
to be put on a waitlist. With thousands of contributors and only 300 spots, we
|
||||
need to make sure the right folks are in the room.
|
||||
-->
|
||||
## 注册:
|
||||
|
||||
要注册贡献者峰会,请参阅 Git Hub 上的[活动详情注册部分][注册]。请注意报名正在审核中。
|
||||
如果您选择了 “当前贡献者追踪”,而您却不是一个活跃的贡献者,您将被要求参加新贡献者研讨会,或者被要求进入候补名单。
|
||||
成千上万的贡献者只有 300 个位置,我们需要确保正确的人被安排席位。
|
||||
|
||||
<!--
|
||||
If you have any questions or concerns, please don’t hesitate to reach out to
|
||||
the Contributor Summit Events Team at community@kubernetes.io.
|
||||
-->
|
||||
如果您有任何问题或疑虑,请随时通过 community@kubernetes.io 联系贡献者峰会组织团队。
|
||||
|
||||
<!--
|
||||
Look forward to seeing everyone there!
|
||||
-->
|
||||
期待在那里看到每个人!
|
||||
|
||||
[bob]: https://twitter.com/mrbobbytables
|
||||
[sahdev]: https://twitter.com/sp_zala
|
||||
[ihor]: https://twitter.com/idvoretskyi
|
||||
[kubecon]: https://events.linuxfoundation.org/events/kubecon-cloudnativecon-north-america-2018/
|
||||
[garage]: https://www.garagebilliards.com/
|
||||
[时间表]: https://git.k8s.io/community/events/2018/12-contributor-summit#agenda
|
||||
[注册]: https://git.k8s.io/community/events/2018/12-contributor-summit#registration
|
||||
@@ -0,0 +1,89 @@
|
||||
---
|
||||
layout: blog
|
||||
title: 'Kubernetes 文档更新,国际版'
|
||||
date: 2018-11-08
|
||||
---
|
||||
<!--
|
||||
---
|
||||
layout: blog
|
||||
title: 'Kubernetes Docs Updates, International Edition'
|
||||
date: 2018-11-08
|
||||
---
|
||||
-->
|
||||
|
||||
<!-- **Author**: Zach Corleissen (Linux Foundation) -->
|
||||
**作者**:Zach Corleissen (Linux 基金会)
|
||||
|
||||
<!-- As a co-chair of SIG Docs, I'm excited to share that Kubernetes docs have a fully mature workflow for localization (l10n). -->
|
||||
作为文档特别兴趣小组(SIG Docs)的联合主席,我很高兴能与大家分享 Kubernetes 文档在本地化(l10n)方面所拥有的一个完全成熟的工作流。
|
||||
|
||||
<!-- ## Abbreviations galore -->
|
||||
## 丰富的缩写
|
||||
|
||||
<!-- L10n is an abbreviation for _localization_. -->
|
||||
L10n 是 _localization_ 的缩写。
|
||||
|
||||
<!-- I18n is an abbreviation for _internationalization_. -->
|
||||
I18n 是 _internationalization_ 的缩写。
|
||||
|
||||
<!-- I18n is [what you do](https://www.w3.org/International/questions/qa-i18n) to make l10n easier. L10n is a fuller, more comprehensive process than translation (_t9n_). -->
|
||||
I18n 定义了[做什么](https://www.w3.org/International/questions/qa-i18n) 能让 l10n 更容易。而 L10n 更全面,相比翻译( _t9n_ )具备更完善的流程。
|
||||
|
||||
<!-- ## Why localization matters -->
|
||||
## 为什么本地化很重要
|
||||
|
||||
<!-- The goal of SIG Docs is to make Kubernetes easier to use for as many people as possible. -->
|
||||
SIG Docs 的目标是让 Kubernetes 更容易为尽可能多的人使用。
|
||||
|
||||
<!-- One year ago, we looked at whether it was possible to host the output of a Chinese team working independently to translate the Kubernetes docs. After many conversations (including experts on OpenStack l10n), [much transformation](https://kubernetes.io/blog/2018/05/05/hugo-migration/), and [renewed commitment to easier localization](https://github.com/kubernetes/website/pull/10485), we realized that open source documentation is, like open source software, an ongoing exercise at the edges of what's possible. -->
|
||||
一年前,我们研究了是否有可能由一个独立翻译 Kubernetes 文档的中国团队来主持文档输出。经过多次交谈(包括 OpenStack l10n 的专家),[多次转变](https://kubernetes.io/blog/2018/05/05/hugo-migration/),以及[重新致力于更轻松的本地化](https://github.com/kubernetes/website/pull/10485),我们意识到,开源文档就像开源软件一样,是在可能的边缘不断进行实践。
|
||||
|
||||
<!-- Consolidating workflows, language labels, and team-level ownership may seem like simple improvements, but these features make l10n scalable for increasing numbers of l10n teams. While SIG Docs continues to iterate improvements, we've paid off a significant amount of technical debt and streamlined l10n in a single workflow. That's great for the future as well as the present. -->
|
||||
整合工作流程、语言标签和团队级所有权可能看起来像是十分简单的改进,但是这些功能使 l10n 可以扩展到规模越来越大的 l10n 团队。随着 SIG Docs 不断改进,我们已经在单一工作流程中偿还了大量技术债务并简化了 l10n。这对未来和现在都很有益。
|
||||
|
||||
<!-- ## Consolidated workflow -->
|
||||
## 整合的工作流程
|
||||
|
||||
<!-- Localization is now consolidated in the [kubernetes/website](https://github.com/kubernetes/website) repository. We've configured the Kubernetes CI/CD system, [Prow](https://github.com/kubernetes/test-infra/tree/master/prow), to handle automatic language label assignment as well as team-level PR review and approval. -->
|
||||
现在,本地化已整合到 [kubernetes/website](https://github.com/kubernetes/website) 存储库。我们已经配置了 Kubernetes CI/CD 系统,[Prow](https://github.com/kubernetes/test-infra/tree/master/prow) 来处理自动语言标签分配以及团队级 PR 审查和批准。
|
||||
|
||||
<!-- ### Language labels -->
|
||||
### 语言标签
|
||||
|
||||
<!-- Prow automatically applies language labels based on file path. Thanks to SIG Docs contributor [June Yi](https://github.com/kubernetes/test-infra/pull/9835), folks can also manually assign language labels in pull request (PR) comments. For example, when left as a comment on an issue or PR, this command assigns the label `language/ko` (Korean). -->
|
||||
Prow 根据文件路径自动添加语言标签。感谢 SIG Docs 贡献者 [June Yi](https://github.com/kubernetes/test-infra/pull/9835),他让人们还可以在 pull request(PR)注释中手动分配语言标签。例如,当为 issue 或 PR 留下下述注释时,将为之分配标签 `language/ko`(Korean)。
|
||||
|
||||
```
|
||||
/language ko
|
||||
```
|
||||
|
||||
|
||||
<!-- These repo labels let reviewers filter for PRs and issues by language. For example, you can now filter the k/website dashboard for [PRs with Chinese content](https://github.com/kubernetes/website/pulls?utf8=%E2%9C%93&q=is%3Aopen+is%3Apr+label%3Alanguage%2Fzh). -->
|
||||
这些存储库标签允许审阅者按语言过滤 PR 和 issue。例如,您现在可以过滤 kubernetes/website 面板中[具有中文内容的 PR](https://github.com/kubernetes/website/pulls?utf8=%E2%9C%93&q=is%3Aopen+is%3Apr+label%3Alanguage%2Fzh)。
|
||||
|
||||
<!-- ### Team review -->
|
||||
### 团队审核
|
||||
|
||||
<!-- L10n teams can now review and approve their own PRs. For example, review and approval permissions for English are [assigned in an OWNERS file](https://github.com/kubernetes/website/blob/master/content/en/OWNERS) in the top subfolder for English content. -->
|
||||
L10n 团队现在可以审查和批准他们自己的 PR。例如,英语的审核和批准权限在位于用于显示英语内容的顶级子文件夹中的 [OWNERS 文件中指定](https://github.com/kubernetes/website/blob/master/content/en/OWNERS)。
|
||||
|
||||
<!-- Adding `OWNERS` files to subdirectories lets localization teams review and approve changes without requiring a rubber stamp approval from reviewers who may lack fluency. -->
|
||||
将 `OWNERS` 文件添加到子目录可以让本地化团队审查和批准更改,而无需由可能并不擅长该门语言的审阅者进行批准。
|
||||
|
||||
<!-- ## What's next -->
|
||||
## 下一步是什么
|
||||
|
||||
<!-- We're looking forward to the [doc sprint in Shanghai](https://kccncchina2018english.sched.com/event/HVb2/contributor-summit-doc-sprint-additional-registration-required) to serve as a resource for the Chinese l10n team. -->
|
||||
我们期待着[上海的 doc sprint](https://kccncchina2018english.sched.com/event/HVb2/contributor-summit-doc-sprint-additional-registration-required) 能作为中国 l10n 团队的资源。
|
||||
|
||||
<!-- We're excited to continue supporting the Japanese and Korean l10n teams, who are making excellent progress. -->
|
||||
我们很高兴继续支持正在取得良好进展的日本和韩国 l10n 队伍。
|
||||
|
||||
<!-- If you're interested in localizing Kubernetes for your own language or region, check out our [guide to localizing Kubernetes docs](https://kubernetes.io/docs/contribute/localization/) and reach out to a [SIG Docs chair](https://github.com/kubernetes/community/tree/master/sig-docs#leadership) for support. -->
|
||||
如果您有兴趣将 Kubernetes 本地化为您自己的语言或地区,请查看我们的[本地化 Kubernetes 文档指南](https://kubernetes.io/docs/contribute/localization/),并联系 [SIG Docs 主席团](https://github.com/kubernetes/community/tree/master/sig-docs#leadership)获取支持。
|
||||
|
||||
<!-- ### Get involved with SIG Docs -->
|
||||
### 加入SIG Docs
|
||||
|
||||
<!-- If you're interested in Kubernetes documentation, come to a SIG Docs [weekly meeting](https://github.com/kubernetes/community/tree/master/sig-docs#meetings), or join [#sig-docs in Kubernetes Slack](https://kubernetes.slack.com/messages/C1J0BPD2M/details/). -->
|
||||
如果您对 Kubernetes 文档感兴趣,请参加 SIG Docs [每周会议](https://github.com/kubernetes/community/tree/master/sig-docs#meetings),或在 [Kubernetes Slack 加入 #sig-docs](https://kubernetes.slack.com/messages/C1J0BPD2M/details/)。
|
||||
@@ -3,8 +3,8 @@ layout: blog
|
||||
title: '新贡献者工作坊上海站'
|
||||
date: 2018-12-05
|
||||
---
|
||||
|
||||
<!--
|
||||
|
||||
<!--
|
||||
---
|
||||
layout: blog
|
||||
title: 'New Contributor Workshop Shanghai'
|
||||
|
||||
Reference in New Issue
Block a user