Merge pull request #33834 from neolit123/1.25-cleanup-kubeadm-master-taint
kubeadm: apply changes around "master" taint for 1.25
This commit is contained in:
@@ -493,9 +493,9 @@ The kubelet checks D-value of the size of `/proc/sys/kernel/pid_max` and the PID
|
||||
|
||||
Example: `node.kubernetes.io/out-of-service:NoExecute`
|
||||
|
||||
A user can manually add the taint to a Node marking it out-of-service. If the `NodeOutOfServiceVolumeDetach`
|
||||
A user can manually add the taint to a Node marking it out-of-service. If the `NodeOutOfServiceVolumeDetach`
|
||||
[feature gate](/docs/reference/command-line-tools-reference/feature-gates/) is enabled on
|
||||
`kube-controller-manager`, and a Node is marked out-of-service with this taint, the pods on the node will be forcefully deleted if there are no matching tolerations on it and volume detach operations for the pods terminating on the node will happen immediately. This allows the Pods on the out-of-service node to recover quickly on a different node.
|
||||
`kube-controller-manager`, and a Node is marked out-of-service with this taint, the pods on the node will be forcefully deleted if there are no matching tolerations on it and volume detach operations for the pods terminating on the node will happen immediately. This allows the Pods on the out-of-service node to recover quickly on a different node.
|
||||
|
||||
{{< caution >}}
|
||||
Refer to
|
||||
@@ -627,7 +627,7 @@ This determines whether a user can modify the mode of the source volume when a
|
||||
{{< glossary_tooltip text="PersistentVolumeClaim" term_id="persistent-volume-claim" >}} is being
|
||||
created from a VolumeSnapshot.
|
||||
|
||||
Refer to [Converting the volume mode of a Snapshot](/docs/concepts/storage/volume-snapshots/#convert-volume-mode)
|
||||
Refer to [Converting the volume mode of a Snapshot](/docs/concepts/storage/volume-snapshots/#convert-volume-mode)
|
||||
and the [Kubernetes CSI Developer Documentation](https://kubernetes-csi.github.io/docs/) for more information.
|
||||
|
||||
## Annotations used for audit
|
||||
@@ -695,14 +695,3 @@ Used on: Node
|
||||
Example: `node-role.kubernetes.io/control-plane:NoSchedule`
|
||||
|
||||
Taint that kubeadm applies on control plane nodes to allow only critical workloads to schedule on them.
|
||||
|
||||
### node-role.kubernetes.io/master
|
||||
|
||||
Used on: Node
|
||||
|
||||
Example: `node-role.kubernetes.io/master:NoSchedule`
|
||||
|
||||
Taint that kubeadm applies on control plane nodes to allow only critical workloads to schedule on them.
|
||||
|
||||
{{< note >}} Starting in v1.20, this taint is deprecated in favor of `node-role.kubernetes.io/control-plane`
|
||||
and will be removed in v1.25.{{< /note >}}
|
||||
|
||||
@@ -319,12 +319,10 @@ Please note that:
|
||||
As soon as the control plane is available, kubeadm executes following actions:
|
||||
|
||||
- Labels the node as control-plane with `node-role.kubernetes.io/control-plane=""`
|
||||
- Taints the node with `node-role.kubernetes.io/master:NoSchedule` and `node-role.kubernetes.io/control-plane:NoSchedule`
|
||||
- Taints the node with `node-role.kubernetes.io/control-plane:NoSchedule`
|
||||
|
||||
Please note that:
|
||||
|
||||
1. The `node-role.kubernetes.io/master` taint is deprecated and will be removed in kubeadm version 1.25
|
||||
1. Mark control-plane phase phase can be invoked individually with the [`kubeadm init phase mark-control-plane`](/docs/reference/setup-tools/kubeadm/kubeadm-init-phase/#cmd-phase-mark-control-plane) command
|
||||
Please note that the phase to mark the control-plane phase phase can be invoked
|
||||
individually with the [`kubeadm init phase mark-control-plane`](/docs/reference/setup-tools/kubeadm/kubeadm-init-phase/#cmd-phase-mark-control-plane) command.
|
||||
|
||||
### Configure TLS-Bootstrapping for node joining
|
||||
|
||||
|
||||
+4
-9
@@ -303,7 +303,7 @@ reasons. If you want to be able to schedule Pods on the control plane nodes,
|
||||
for example for a single machine Kubernetes cluster, run:
|
||||
|
||||
```bash
|
||||
kubectl taint nodes --all node-role.kubernetes.io/control-plane- node-role.kubernetes.io/master-
|
||||
kubectl taint nodes --all node-role.kubernetes.io/control-plane-
|
||||
```
|
||||
|
||||
The output will look something like:
|
||||
@@ -313,14 +313,9 @@ node "test-01" untainted
|
||||
...
|
||||
```
|
||||
|
||||
This will remove the `node-role.kubernetes.io/control-plane` and
|
||||
`node-role.kubernetes.io/master` taints from any nodes that have them,
|
||||
including the control plane nodes, meaning that the scheduler will then be able
|
||||
to schedule Pods everywhere.
|
||||
|
||||
{{< note >}}
|
||||
The `node-role.kubernetes.io/master` taint is deprecated and kubeadm will stop using it in version 1.25.
|
||||
{{< /note >}}
|
||||
This will remove the `node-role.kubernetes.io/control-plane:NoSchedule` taint
|
||||
from any nodes that have it, including the control plane nodes, meaning that the
|
||||
scheduler will then be able to schedule Pods everywhere.
|
||||
|
||||
### Joining your nodes {#join-nodes}
|
||||
|
||||
|
||||
+1
-1
@@ -351,7 +351,7 @@ A known solution is to patch the kube-proxy DaemonSet to allow scheduling it on
|
||||
nodes regardless of their conditions, keeping it off of other nodes until their initial guarding
|
||||
conditions abate:
|
||||
```
|
||||
kubectl -n kube-system patch ds kube-proxy -p='{ "spec": { "template": { "spec": { "tolerations": [ { "key": "CriticalAddonsOnly", "operator": "Exists" }, { "effect": "NoSchedule", "key": "node-role.kubernetes.io/master" }, { "effect": "NoSchedule", "key": "node-role.kubernetes.io/control-plane" } ] } } } }'
|
||||
kubectl -n kube-system patch ds kube-proxy -p='{ "spec": { "template": { "spec": { "tolerations": [ { "key": "CriticalAddonsOnly", "operator": "Exists" }, { "effect": "NoSchedule", "key": "node-role.kubernetes.io/control-plane" } ] } } } }'
|
||||
```
|
||||
|
||||
The tracking issue for this problem is [here](https://github.com/kubernetes/kubeadm/issues/1027).
|
||||
|
||||
Reference in New Issue
Block a user