Compare commits

..

566 Commits

Author SHA1 Message Date
Kubernetes Prow Robot f636e47d42 Merge pull request #34299 from Babapool/correct-invalid-shortcode
[hi]Update hi/docs/setup/production-environment/container-runtimes.md
2022-06-15 03:05:17 -07:00
Vitthal Sai da91d01605 Fixed error causing caution shortcode 2022-06-15 10:55:12 +05:30
Kubernetes Prow Robot 37fa13ca78 Merge pull request #32713 from ashish-jaiswar/newbranch
[hi] update content/hi/docs/setup/production-environment/container-runtimes.md
2022-04-09 07:18:04 -07:00
ashish-jaiswar d22a123c37 [hi] update content/hi/docs/setup/production-environment/container-runtimes.md 2022-04-02 13:22:09 +05:30
Darshna Das 1e8d014694 [hi] Add content/hi/docs/setup/production-environment/container-runtimes.md (#31857)
* Localized container-runtimes.md

* Updated with needed change

* Updated with needed changes

* Updated with needed changes

* Updated with needed changes

* Updated the PR
2022-03-01 10:59:55 -08:00
Kubernetes Prow Robot 7f429d134f Merge pull request #29396 from anubha-v-ardhan/content-hi-docs-tutorials-helloMinikube
[hi] Add content/hi/docs/tutorials/hello-minikube.md
2022-02-21 00:40:11 -08:00
Anubhav Vardhan 065b1ba5ab Update content/hi/docs/tutorials/hello-minikube.md
Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>
2022-02-15 13:53:49 +05:30
Anubhav Vardhan fe74ff0d71 Update content/hi/docs/tutorials/hello-minikube.md
Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>
2022-02-15 13:53:36 +05:30
Anubhav Vardhan c922f43d9e Localize hello-minikube.md
Create hello-minikube.md

Update hello-minikube.md

Update hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update hello-minikube.md

Update hello-minikube.md

Update hello-minikube.md

Update hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Update hello-minikube.md

Update content/hi/docs/tutorials/hello-minikube.md

Co-Authored-By: Tim Bannister <tim@scalefactory.com>
Co-Authored-By: divya-mohan0209 <divya.mohan0209@gmail.com>
Co-Authored-By: Avinesh Tripathi <73980067+AvineshTripathi@users.noreply.github.com>
2022-02-14 19:38:47 +05:30
Keshav Kumar ede710e85b [hi] Add content/hi/docs/setup/production-environment/_index.md (#29518)
* half page is localised only for now

* completed whole page

* corrected a hyperlink

* corrected a hyperlink2

* Update कुबेरनेट -> कुबेरनेट्स

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Updated सेटअप

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Updated kube-apiserver text

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Updated apiserver text

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Updated सेटअप text

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Updated apiserver text

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Updated सेटअप text

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Updated kubernetes text

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/setup/production-environment/_index.md

changed कंट्रोल into कण्ट्रोल

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/setup/production-environment/_index.md

changed कंट्रोल into कण्ट्रोल

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/setup/production-environment/_index.md

changed कंट्रोल into कण्ट्रोल

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/setup/production-environment/_index.md

changed कंट्रोल into कण्ट्रोल

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/setup/production-environment/_index.md

changed कंट्रोल into कण्ट्रोल

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/setup/production-environment/_index.md

changed कंट्रोल into कण्ट्रोल

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/setup/production-environment/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* changed worker nodes translation

* Update content/hi/docs/setup/production-environment/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2022-01-20 19:55:59 -08:00
Anubhav Vardhan 38ef181e80 [hi] Add content/hi/docs/tutorials/kubernetes-basics/explore/explore-intro.html (#29412)
* Create explore-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/explore/explore-intro.html

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>

* Update explore-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/explore/explore-intro.html

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>

* Update explore-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/explore/explore-intro.html

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>

* Update content/hi/docs/tutorials/kubernetes-basics/explore/explore-intro.html

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>

* Update content/hi/docs/tutorials/kubernetes-basics/explore/explore-intro.html

Co-authored-by: Rajat Gupta <55191777+rajatgupta24@users.noreply.github.com>

* Update explore-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/explore/explore-intro.html

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update explore-intro.html

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>
Co-authored-by: Rajat Gupta <55191777+rajatgupta24@users.noreply.github.com>
Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>
2022-01-12 00:20:37 -08:00
Avinesh Tripathi 7f29e4edea [hi] Add content/hi/releases/_index.md (#31292)
* added index.md in release

* Update content/hi/releases/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* fixed typo

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2022-01-11 10:06:25 -08:00
Mohd Nawaz Siddiqui 8fa492b380 [hi] Add content/hi/docs/contribute/_index.md (#31162)
* [hi] Add content/hi/docs/contribute/_index.md

localized the file from website/content/en/docs/contribute/_index.md

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>

* Updated _index.md

Update the suggested changes

* Updated the change as suggested on line 2,3,4,24

* Update _index.md

* Updated सिग डॉक्स to SIG Docs

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Garima Negi <garima.negy@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/contribute/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
Co-authored-by: Garima Negi <garima.negy@gmail.com>
2022-01-11 08:46:26 -08:00
Kubernetes Prow Robot 72e773b2b7 Merge pull request #31072 from Babapool/update-hi-toml
[hi] Update data/i18n/hi/hi.toml
2022-01-11 04:09:16 -08:00
Vitthal Sai 44c5a11dd1 [hi] Update data/i18n/hi/hi.toml 2022-01-11 17:00:10 +05:30
Garima Negi 269b037e00 [hi] Add docs/reference/_index.md to Hindi localization (#31185)
* Add API reference section

* Rename file to _index.md

* fixed annotation to टिप्पणी

* added design  docs

* added config APIs localized

* added localized components section

* added localization for CLI section

* Removed `approvers` from header

* added agent as प्रतिनिधि

* added forwarding simpler meaning in parenthesis

* syntax as सिन्‌टैक्‍स् , वाक्य रचना in parenthesis
2022-01-11 01:25:16 -08:00
Kubernetes Prow Robot 3b684a7279 Merge pull request #31077 from sftim/20211222_fix_hindi_config
[hi] Use localized text for Hindi language configuration
2022-01-09 11:53:12 -08:00
Kubernetes Prow Robot b855e0d692 Merge pull request #29416 from Darshnadas/darshna-localize
[hi] Add content/hi/docs/setup/learning-environment/_index.md
2022-01-03 08:13:02 -08:00
Darshna Das bf315656ed Add content/hi/docs/setup/learning-environment/_index.md 2021-12-27 18:08:41 +05:30
Tim Bannister aa45dbbb6c Use localized text for Hindi language configuration
Co-authored-by: championshuttler <shivams2799@gmail.com>
2021-12-23 09:10:07 +00:00
Kubernetes Prow Robot 56ecf18792 Merge pull request #31008 from sftim/20211217_add_hindi_docs_home_redirect
Add redirect to /docs/home/ for Hindi
2021-12-21 16:43:35 -08:00
Tim Bannister 3e1ed0a6f1 Add redirect to /docs/home/ for Hindi 2021-12-17 15:01:57 +00:00
Kubernetes Prow Robot 7e1deb2008 Merge pull request #29403 from anubha-v-ardhan/content-hi-docs-tutorials-kubernetesBasics-explore-exploreInteractive
[hi] Add content/hi/docs/tutorials/kubernetes-basics/explore/explore-interactive.html
2021-12-16 04:47:19 -08:00
Ashish jaiswar f9760fdd7a [hi] Add content/hi/docs/concepts/overview/what-is-kubernetes.md (#30847)
* [hi] Add  content/hi/docs/concepts/overview/what-is-kubernetes.md

* updated this file what-is-kubernetes.md

* Update content/hi/docs/concepts/overview/what-is-kubernetes.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* updated  content/hi/docs/concepts/overview/what-is-kubernetes.md

* Update content/hi/docs/concepts/overview/what-is-kubernetes.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/concepts/overview/what-is-kubernetes.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-12-16 03:53:20 -08:00
Rajat Gupta 64884b0faf [hi] Add content/hi/docs/tutorials/k8s-basics/expose/expose-intro.html (#29407)
* Add content/hi/docs/tutorials/k8s-basics/expose/expose-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update expose-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update expose-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-12-16 03:33:20 -08:00
Rajat Gupta fedc0f7ee4 [hi] Add content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html (#29401)
* Add content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

* Fix changes

* Fix changing lang="hi"

* Update deploy-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-12-16 03:27:19 -08:00
Harsh Mathur 62cda9b405 [hi] Add content/hi/case-studies/_index.md (#30733)
* Case studies added to `hi` folder

* Removed _index.md and added _index.html

* Update content/hi/case-studies/_index.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/case-studies/_index.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-12-04 08:06:31 -08:00
Kubernetes Prow Robot d85c453561 Merge pull request #30087 from verma-kunal/hi-localise-contentLandingPage
[hi] Add content/hi/_index.html
2021-12-02 11:05:44 -08:00
Anurag Kumar 72c12b7f77 [hi] Add content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md (#30607)
* [hi] Add content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Added the localisation of optional-kubectl-configs-bash-mac.md (#30570)

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-mac.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-11-29 06:55:23 -08:00
Ashish jaiswar 76c2281b62 [hi] Add content/hi/docs/tasks/tools/included/optional-kubectl-confi… (#30627)
* [hi] Add  content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-linux.md

* updated file optional-kubectl-configs-bash-linux.md

* updated this file optional-kubectl-configs-bash-linux.md

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-linux.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-linux.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-linux.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-linux.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/optional-kubectl-configs-bash-linux.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-11-28 10:29:21 -08:00
Mohd Nawaz Siddiqui fe0d12b9b9 [hi] Add content/hi/includes/task-tutorial-prereqs.md (#30602)
* Added task-tutorial-prereqs

Added task-tutorial-prereqs on the path website/content/hi/includes.

* Update content/hi/includes/task-tutorial-prereqs.md

Updated the change as suggested.

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/includes/task-tutorial-prereqs.md

updated change as suggested.

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-11-28 08:53:22 -08:00
Polok-Ghosh ea74766545 [hi] Add content/hi/docs/reference/glossary/index.md (#30652)
* Create index.md

* Update index.md

* Rename content/hi/docs/index.md to content/hi/docs/reference/glossary/index.md
2021-11-27 06:02:41 -08:00
shivam tyagi 5b05c0edec Add content\hi\docs\setup\production-environment\turnkey-solutions.md (#30303)
* file

* Update content/hi/docs/setup/production-environment/turnkey-solutions.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* concept

* Update content/hi/docs/setup/production-environment/turnkey-solutions.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-11-20 03:28:59 -08:00
Kubernetes Prow Robot b2f95de64e Merge pull request #29399 from anubha-v-ardhan/content-hi-docs-tutorials-kubernetesBasics-explore-landing
[hi] Add content/hi/docs/tutorials/kubernetes-basics/explore/_index.md
2021-11-18 08:05:03 -08:00
Anubhav Vardhan c400ec2d3e [hi] Add content/hi/docs/tutorials/_index.md (#29376)
* Create _index.md

* Update content/hi/docs/tutorials/_index.md

Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>

* Update _index.md

* Update content/hi/docs/tutorials/_index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/hi/docs/tutorials/_index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/hi/docs/tutorials/_index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/hi/docs/tutorials/_index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update _index.md

* Update _index.md

Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-11-18 07:35:03 -08:00
Kunal Verma d8521a66e3 Final Update hi/_index.html 2021-10-31 19:17:08 +05:30
Prashant Pandey ca922fe453 [hi] Update data/i8n/hi/hi.toml (#29472)
* translation complete for data/i8n/hi

* added request changes

* updated request changes

* Update data/i18n/hi/hi.toml

Co-authored-by: Rajat Gupta <55191777+rajatgupta24@users.noreply.github.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update data/i18n/hi/hi.toml

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Rajat Gupta <55191777+rajatgupta24@users.noreply.github.com>
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-25 01:18:22 -07:00
Vedant Kakde 4e5d5d6c42 [hi] Add content/hi/docs/tasks/tools/install-kubectl-linux.md (#29457)
* content/en/docs/tasks/tools/install-kubectl-linux.md

* Update install-kubectl-linux.md

* Update install-kubectl-linux.md

* Apply suggestions from code review

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update install-kubectl-linux.md

* Update install-kubectl-linux.md

* Update install-kubectl-linux.md

* Update content/hi/docs/tasks/tools/install-kubectl-linux.md

Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>

* Update content/hi/docs/tasks/tools/install-kubectl-linux.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Apply suggestions from code review

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-10-23 10:08:21 -07:00
Kubernetes Prow Robot 1964daebf2 Merge pull request #29374 from anubha-v-ardhan/content-hi-docs-setup-bestpractices-landing
[hi] Add content/hi/docs/setup/best-practices/_index.md
2021-10-23 04:46:20 -07:00
Keshav Kumar 4150794fba [hi] Add content/hi/docs/setup/_index.md (#29514)
* localised a file in website\content\hi\docs\setup\_index.md

* transcribed control plane word

* [hi] Add content/hi/docs/setup/_index.md

* update suggested sentences

* rephrased some sentences

* Update content/hi/docs/setup/_index.md

updated the refrence docs location

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-23 03:56:21 -07:00
Anubhav Vardhan 170f0c6126 Update explore-interactive.html 2021-10-21 14:22:33 +05:30
Anubhav Vardhan 82a0c67744 Update _index.md 2021-10-21 14:12:13 +05:30
Rajat Gupta fe650578a9 [hi] Add content/hi/docs/tutorial/kubernetes-basics/_index.html (#29391)
* Add content/hi/docs/tutorial/kubernetes-basics/_index.html

* updating tutorial to tutorials

* Add: content/hi/docs/tutorials/kubernetes-basics/_index.html

* Fix words like deployment

* Changing `Deploy`

* Update content/hi/docs/tutorials/kubernetes-basics/_index.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/_index.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/_index.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/_index.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/_index.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-20 05:59:58 -07:00
Kunal Verma 7ab8d65cdd Add content/hi/_index.html 2021-10-15 00:15:08 +05:30
Rajat Gupta c8548e219f [hi] Add content/hi/docs/tutorial/kubernetes-basics/create-cluster (#29392)
* Add content/hi/docs/tutorial/kubernetes-basics/_index.html

* updating tutorial to tutorials

* Add: content/hi/docs/tutorials/kubernetes-basics/create-cluster

* updating words like deployment

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-interactive.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update cluster-intro.html

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update cluster-intro.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-09 13:02:36 -07:00
Rajat Gupta 10e972bebe [hi] Add content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-interactive.html (#29393)
* Add content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-interactive.html

* Fix reviewed changes

* Fix reviewed changes

* Update deploy-interactive.html

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-interactive.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-interactive.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tutorials/kubernetes-basics/deploy-app/deploy-interactive.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-08 02:48:58 -07:00
shivam tyagi 3ebb648a4d [hi] Add content\hi\docs\tasks\tools\included\kubectl-convert-overview.md (#29970)
* add kubectl-convert-overview  file

* Update content/hi/docs/tasks/tools/included/kubectl-convert-overview.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/kubectl-convert-overview.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-08 01:58:58 -07:00
Kubernetes Prow Robot 583661b2c4 Merge pull request #29971 from ShivamTyagi12345/index-dev-1.22-hi.1
[hi] Add content/hi/docs/tutorials/kubernetes-basics/update/_index.md
2021-10-08 01:02:58 -07:00
ShivamTyagi ab9dd0ff1d add file 2021-10-08 12:31:07 +05:30
Rajat Gupta 1bcfd9d2e4 [hi] Add content/hi/docs/tasks/tools/_index.md (#29458)
* Add content/hi/docs/tasks/tools/_index.md

* Update _index.md

* Update _index.md

* Update _index.md

* Update _index.md

* Update content/hi/docs/tasks/tools/_index.md

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/tasks/tools/_index.md

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update content/hi/docs/tasks/tools/_index.md

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>

* Update _index.md

* Update content/hi/docs/tasks/tools/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/_index.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-07 21:13:51 -07:00
shivam tyagi a9b7fb177b [hi] Add content\hi\docs\tasks\tools\included\kubectl-whats-next.md (#29471)
* kubectl-whats-next localized

* Update content/hi/docs/tasks/tools/included/kubectl-whats-next.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/kubectl-whats-next.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/kubectl-whats-next.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/kubectl-whats-next.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/included/kubectl-whats-next.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-07 08:57:46 -07:00
Vedant Kakde 2fa7e1e087 [hi] Add content/hi/docs/tasks/tools/install-kubectl-windows.md (#29465)
* Add content/hi/docs/tasks/tools/install-kubectl-windows.md

* Apply suggestions from code review

Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>

* Apply suggestions from code review

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update install-kubectl-windows.md

* Update install-kubectl-windows.md

* Apply suggestions from code review

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-06 10:12:41 -07:00
Vedant Kakde 6b92e5aa05 [hi] Add content/hi/docs/tasks/tools/install-kubectl-macos.md (#29461)
* Add content/hi/docs/tasks/tools/install-kubectl-macos.md

* Apply suggestions from code review

Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>

* Update install-kubectl-macos.md

* Apply suggestions from code review

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

* Update content/hi/docs/tasks/tools/install-kubectl-macos.md

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-10-01 22:37:06 -07:00
Kubernetes Prow Robot 699ec1ae1b Merge pull request #29434 from rajatgupta24/docs-task
[hi] Add content/hi/docs/tasks/_index.md
2021-09-26 15:04:22 -07:00
Anubhav Vardhan 3d469ee2c7 Update _index.md 2021-09-25 15:41:37 +05:30
Kubernetes Prow Robot cf225e223e Merge pull request #29454 from verma-kunal/hi-docs-tuts-k8s-basics-update-updt-intro
[hi] Add content/hi/docs/tutorials/kubernetes-basics/update/update-intro.html
2021-09-25 02:44:21 -07:00
Kunal Verma f62c5961db Final commit update-intro.html 2021-09-24 20:42:30 +05:30
Rajat Gupta de48775b13 [hi] Add content/hi/docs/tutorials/kubernetes-basics/deploy-app/_index.md (#29400)
* Add content/hi/docs/tutorials/kubernetes-basics/deploy-app/_index.md

* Fix changes

* Update _index.md

* Update _index.md
2021-09-22 20:07:10 -07:00
Rajat Gupta 288c386ee1 [hi] Add content/hi/docs/tutorials/kubernetes-basics/expose/_index.md (#29430)
* Add content/hi/docs/tutorials/kubernetes-basics/expose/_index.md

* Update _index.md

* Update _index.md
2021-09-22 20:03:11 -07:00
Rajat Gupta 49b9366145 [hi] Add content/hi/docs/tutorials/kubernetes-basics/expose/expose-interactive.html (#29405)
* Add content/hi/docs/tutorials/

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-interactive.html

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-interactive.html

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-interactive.html

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>

* Update expose-interactive.html

* Update content/hi/docs/tutorials/kubernetes-basics/expose/expose-interactive.html

Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>

Co-authored-by: Kunal Verma <72245772+verma-kunal@users.noreply.github.com>
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-09-16 21:41:00 -07:00
Kubernetes Prow Robot bbc3764e0b Merge pull request #29469 from vedant-kakde/Hindi-Localization-docs/tasks/tools/included/verify-kubectl.md
[hi] Add content/hi/docs/tasks/tools/included/verify-kubectl.md
2021-09-16 11:55:27 -07:00
Vedant Kakde 55b1ab34cb Apply suggestions from code review
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-09-17 00:21:03 +05:30
Vedant Kakde 747c82aa6c Add content/hi/docs/tasks/tools/included/verify-kubectl.md
Signed-off-by: Vedant Kakde <69970950+vedant-kakde@users.noreply.github.com>
2021-09-16 23:56:36 +05:30
Kubernetes Prow Robot 26ceffbb99 Merge pull request #29420 from verma-kunal/hi-docs-tuts-k8s-basics-scale-scaleIntro
[hi] Add content/hi/docs/tutorials/kubernetes-basics/scale/scale-intro.html
2021-09-16 01:37:47 -07:00
Kubernetes Prow Robot 6cc9c69fc3 Merge pull request #29383 from verma-kunal/Hindi-localization-docs/home1
[hi] Add content/hi/docs/home/_index.md
2021-09-14 23:32:41 -07:00
Kunal Verma 6133cf3b91 Final commit content/hi/docs/home/_index.md 2021-09-15 11:05:48 +05:30
Kubernetes Prow Robot 25aa7be692 Merge pull request #29432 from verma-kunal/hi-docs-tuts-k8s-basics-update-updt-interactive
[hi] Add content/hi/docs/tutorials/kubernetes-basics/update/update-interactive.html
2021-09-14 22:04:41 -07:00
Kunal Verma 43f4a1f822 Update content/hi/docs/tutorials/kubernetes-basics/update/update-interactive.html
Co-authored-by: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-09-15 10:17:14 +05:30
Kubernetes Prow Robot 041af7458c Merge pull request #29674 from sftim/20210912_enable_hindi_localization
[hi] Enable Hindi localization
2021-09-14 16:24:40 -07:00
Kunal Verma a74bd43fdf Final commit content/hi/docs/tutorials/kubernetes-basics/scale/scale-intro.html 2021-09-14 14:43:27 +05:30
Kubernetes Prow Robot b7c9f8febf Merge pull request #29705 from kaiwalyakoparkar/hi/docs/tasks/tools/included/_index.md
[hi] Added hi/docs/tasks/tools/included/_index.md
2021-09-14 02:05:08 -07:00
kaiwalyakoparkar 8dcc80ea24 [hi] Add docs/tasks/tools/included/_index.md 2021-09-14 14:19:01 +05:30
Kubernetes Prow Robot f00815006b Merge pull request #29410 from verma-kunal/hi-docs-tuts-k8s-basics-scale-scale-interactive
[hi] Add content/hi/docs/tutorials/kubernetes-basics/scale/scale-interactive.html
2021-09-13 07:32:08 -07:00
Kubernetes Prow Robot 4fbf99fff2 Merge pull request #29474 from vedant-kakde/Hindi-Localization-docs/tasks/tools/included/optional-kubectl-configs-zsh.md
[hi] Add content/hi/docs/tasks/tools/included/optional-kubectl-configs-zsh.md
2021-09-13 03:38:07 -07:00
Vedant Kakde f0abfe8a1c Add content/hi/docs/tasks/tools/included/optional-kubectl-configs-zsh.md
Update optional-kubectl-configs-zsh.md

Co-Authored-By: Anubhav Vardhan <vardhananubhav@gmail.com>
2021-09-13 16:04:26 +05:30
Kubernetes Prow Robot 634983ca07 Merge pull request #29372 from verma-kunal/Hindi-localization-docs/home2
[hi] Add content/hi/docs/home/supported-doc-versions.md
2021-09-13 02:20:07 -07:00
Kunal Verma 26894350b6 Final Update content/hi/docs/home/supported-doc-versions.md
Update content/hi/docs/home/supported-doc-versions.md

Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>
2021-09-13 14:26:23 +05:30
Kubernetes Prow Robot e1552ba5a8 Merge pull request #29413 from anubha-v-ardhan/content/hi/docs/setup/production-environment/windows/_index.md
[hi] Add content/hi/docs/setup/production-environment/windows/_index.md
2021-09-12 09:46:06 -07:00
Tim Bannister 729ce020fe Enable Hindi localization 2021-09-12 17:34:02 +01:00
Kubernetes Prow Robot 58022246d0 Merge pull request #29421 from verma-kunal/hi-docs-tuts-k8s-basics-scale-scaleLanding
[hi] Add content/hi/docs/tutorials/kubernetes-basics/scale/_index.md
2021-09-12 09:32:06 -07:00
Tim Bannister 57e5594805 Merge pull request #29675 from sftim/20210912_update_hindi_localization
Update the Hindi localization branch with the latest changes from main,
including updates to Hindi reviewers and approvers.
2021-09-12 11:51:25 +01:00
Tim Bannister 53781c1366 Merge branch 'main' ready to merge into 'dev-1.22-hi.1' 2021-09-12 11:16:57 +01:00
Kubernetes Prow Robot 645cbf57e2 Merge pull request #29666 from anubha-v-ardhan/sig-docs-hi-members
[hi] Update sig-docs-hi owners and reviewers
2021-09-12 03:00:06 -07:00
Kubernetes Prow Robot 8e844434c6 Merge pull request #29486 from astraw99/fix_typo_an_extension
Fix typo `a extension` and its related `en` doc sync
2021-09-11 18:42:06 -07:00
Kubernetes Prow Robot 9dc6afc781 Merge pull request #29662 from mysunshine92/scheduling-hugepage
zh: update scheduling-hugepages.md
2021-09-11 18:04:06 -07:00
Anubhav Vardhan 96c79d2e2f Update OWNERS_ALIASES
Update OWNERS_ALIASES

Update OWNERS_ALIASES
2021-09-11 20:44:15 +05:30
Kubernetes Prow Robot bed864e6e6 Merge pull request #29631 from mshalmanov/main
[ru] Add translate addons.md file in the content/ru/docs/concepts/clu…
2021-09-11 03:04:05 -07:00
Kubernetes Prow Robot 558f36cfe6 Merge pull request #28720 from anubha-v-ardhan/patch-2
Replace ha-master-gce.png with SVG
2021-09-10 03:27:59 -07:00
Kubernetes Prow Robot b41e88b2ab Merge pull request #29635 from deepsan/serviceCatalog
Fix service-catalog usage of apiserver aggregation
2021-09-10 01:16:00 -07:00
wangyamei 732e88bd7e zh: update scheduling-hugepages.md 2021-09-10 15:52:46 +08:00
Anubhav Vardhan c9568cbaaf Update highly-available-control-plane.md 2021-09-10 09:44:25 +05:30
Kubernetes Prow Robot 6ec9cf7529 Merge pull request #29650 from likakuli/patch-1
Update nodelocaldns.md
2021-09-09 20:16:00 -07:00
deepsan 84c2324c2b Fix service-catalog usage of apiserver aggregation
The Service Catalog architecture changed from using api aggregation to CRDs, but the docs still refer to the older architecture using api aggregation.

Couple of changes here:
1. Change the sentence on how Service Catalog is implemented
2. Replace the example for usage of api aggregation from service-catalog to metrics-server. There are multiple implementations that can be linked to(keda, prometheus, datadog,...), but keeping the documentation neutral by pointing to kubernetes-sigs/metrics-server

References:
- Service Catalog [v0.3.0 release notes](https://github.com/kubernetes-sigs/service-catalog/releases/tag/v0.3.0):

> In release 0.3.0, we've focused on replacing the Aggregated API Server with the CustomResourceDefinitions (CRDs) and the Admission Webhook solution.

- Project [README](https://github.com/kubernetes-sigs/service-catalog/pull/2691/files)
> Service Catalog recently switched to a new CRDs-based architecture. The old API Server-based implementation is available on the v0.2 branch. We support this implementation by providing bug fixes until July 2020.
2021-09-09 17:58:56 -07:00
Kubernetes Prow Robot b0f242cd3e Merge pull request #29059 from chrishenzie/read-write-once-pod-access-mode-feature-blog
ReadWriteOncePod access mode alpha feature blog
2021-09-09 11:17:54 -07:00
Kubernetes Prow Robot ed9728ca8c Merge pull request #27262 from npu21/node-fr
Fix line separation in concepts/architecture/nodes
2021-09-09 08:04:11 -07:00
Anubhav Vardhan 2e361073b1 Update highly-available-control-plane.md 2021-09-09 20:20:49 +05:30
Anubhav Vardhan a0e52ff56f Changed ha-control-plane.svg location 2021-09-09 20:17:21 +05:30
Arsh Sharma 69be6060ca explaining the interactions of topology spread constraints and node affinity/selector (#29632)
* explaining the interactions of topology spread constraints and node affinity/selector

Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>

* udpates from code review

Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>

* more updated from code reviews

Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>
2021-09-09 06:48:10 -07:00
likakuli 1ba9380f73 Update nodelocaldns.md
use ",__PILLAR__DNS__SERVER__" as old pattern instead of "__PILLAR__DNS__SERVER__" when use ipvs mode
2021-09-09 18:36:21 +08:00
Kubernetes Prow Robot c2f0ae3f05 Merge pull request #29646 from Arhell/env
[ja] kubeadm-install: include env variable for ARCH
2021-09-09 01:40:10 -07:00
Kubernetes Prow Robot 1e578005a8 Merge pull request #29620 from Arhell/upd
[ja] Update the link to cloud interface
2021-09-09 01:38:10 -07:00
Kubernetes Prow Robot 4b18015cd3 Merge pull request #29628 from yechs/patch-1
Fix markdown link rendering & move image kubeadm-stacked-color.png to this repo
2021-09-09 01:00:12 -07:00
Siman 8155f1d16d Update controlling-access.md as --insecure-port flag deprecated (#29447)
* Update English version of controlling-access.md as --insecure-port flag deprecated

* Update controlling-access.md as --insecure-port flag deprecated

* Update content/en/docs/concepts/security/controlling-access.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-09-08 19:30:10 -07:00
Shubham 975bd9e9b7 Improvement: Remove Heapster content from HPA. (#29547)
* Improvement: Remove Heapster content from HPA.

* Add more descriptive link for Metrics Server.
2021-09-08 18:20:10 -07:00
Kubernetes Prow Robot 91d24e6505 Merge pull request #29637 from reylejano/update-kubeops-description
Follow-up to k/website pr 29529, fix small nit for .NET
2021-09-08 18:04:10 -07:00
Kubernetes Prow Robot af7f06193f Merge pull request #27182 from sftim/20210323_update_task_create_external_load_balancer
Reword “Create an External Load Balancer” task
2021-09-08 17:54:11 -07:00
jay vyas 034ab83d92 kube-proxy disclaimer about cleanup (#28147)
* kube-proxy disclaimer about cleanup

* Update content/en/docs/concepts/services-networking/service.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/docs/concepts/services-networking/service.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* kube-proxy config note

* Update service.md

kube proxy configuration

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-09-08 17:34:10 -07:00
Arhell 7b43cfc83d [ja] kubeadm-install: include env variable for ARCH 2021-09-09 01:07:41 +03:00
Chris Henzie 809ff37d3b ReadWriteOncePod access mode alpha feature blog 2021-09-08 14:42:43 -07:00
Ye Shu 826fb8dc90 Change reference to kubeadm-stacked-color.png
Since the image is now moved to this repo, I'm changing all
references to the image to have them point to the local one.
2021-09-08 10:35:23 -04:00
Kubernetes Prow Robot afac60ede7 Merge pull request #29630 from Arhell/env
[fr] kubeadm-install: include env variable for ARCH
2021-09-08 00:59:20 -07:00
Kubernetes Prow Robot 93d7fba356 Merge pull request #29636 from Arhell/var
[id] kubeadm-install: include env variable for ARCH
2021-09-07 20:29:20 -07:00
Kubernetes Prow Robot 7cedec6389 Merge pull request #29584 from chenxuc/task-admin
[zh]sync admin task files
2021-09-07 18:55:20 -07:00
Rey Lejano 892118c9cc follow-up to k website pr 29529 2021-09-07 16:58:20 -07:00
Kubernetes Prow Robot 3130e1d221 Merge pull request #29249 from jmyung/jesang/add-reviewer/v0.1
Add jmyung to sig-docs-ko-reviews
2021-09-07 16:20:16 -07:00
Arhell e167bfeac2 [id] kubeadm-install: include env variable for ARCH 2021-09-08 01:23:53 +03:00
Ye Shu a206af45bf Ends img tag and revert changes to links
- Moves the image to this repo
- Adds <img/> to end the tag
- Revert changes made to markdown links
2021-09-07 17:48:00 +00:00
Kubernetes Prow Robot cf9753423a Merge pull request #29554 from chrismetz09/metz-mermaid-upgrade
upgrade to mermaid 8.11.2
2021-09-07 09:45:16 -07:00
Kubernetes Prow Robot 0a413aa6c2 Merge pull request #29616 from BenHall/upgradeMinikubeKatacodaTerminal
Move to Minikube 1.20 image of Katacoda for Hello Minikube Tutorial
2021-09-07 05:43:15 -07:00
Kubernetes Prow Robot a161d54e9f Merge pull request #29209 from deepsan/api-server
Reword Go requirement for subordinate API servers
2021-09-07 05:39:15 -07:00
Marat b7c57a160c [ru] Add translate addons.md file in the content/ru/docs/concepts/cluster-administration 2021-09-07 11:41:59 +06:00
Kubernetes Prow Robot b125d095ea Merge pull request #29621 from tengqm/fix-kubeadm-api-pointer
Fix kubeadm-config links
2021-09-06 18:23:15 -07:00
Arhell b77e02e739 [fr] kubeadm-install: include env variable for ARCH 2021-09-07 01:22:33 +03:00
Kubernetes Prow Robot c484165cb7 Merge pull request #29579 from Arhell/update
[ja] Updating --cascade=false to --cascade=orphan
2021-09-06 08:58:29 -07:00
Kubernetes Prow Robot 35d465e05f Merge pull request #29506 from nakamasato/improve-ja-secret
[ja] Improve Japanese expression in Secret
2021-09-06 08:56:29 -07:00
Ye Shu 8d3d617d55 Fix not rendered markdown link in docs
The markdown links are not rendered properly on [the website](https://kubernetes.io/docs/setup/production-environment/tools/kubeadm/create-cluster-kubeadm/).
I replace them with html anchor tags to fix this weird issue.
2021-09-06 23:00:28 +08:00
Kubernetes Prow Robot a8071cca02 Merge pull request #29626 from mshalmanov/main
[ru] Add translate garbage-collection.md file in the content/ru/docs/…
2021-09-06 04:58:29 -07:00
Kubernetes Prow Robot 62823ba75d Merge pull request #29623 from Arhell/fixes
[zh] Update the link to cloud interface
2021-09-06 04:06:29 -07:00
Marat 6fe1e1661d [ru] Add translate garbage-collection.md file in the content/ru/docs/reference/glossary 2021-09-06 12:47:50 +06:00
Marat 9d5769e483 [ru] Add translate garbage-collection.md file in the content/ru/docs/concepts/architecture 2021-09-06 12:41:43 +06:00
Kubernetes Prow Robot 6468a24ba0 Merge pull request #29613 from giraffesyo/patch-1
Use correct namespace
2021-09-05 18:44:28 -07:00
Arhell af15ac1e4f [zh] Update the link to cloud interface 2021-09-06 00:50:06 +03:00
chenxuc e5d5f82c72 [zh]sync admin task files 2021-09-05 11:27:15 +08:00
Qiming Teng c7ed438072 Fix kubeadm-config links
This PR fixes the links for kubeadm-config APIs.
2021-09-05 09:59:05 +08:00
Arhell 977feb0e98 [ja] Update the link to cloud interface 2021-09-05 00:56:01 +03:00
Kubernetes Prow Robot 9c8e57535e Merge pull request #29619 from jlbutler/122_release_update_webinar
update 1.22 release webinar date in release blog to rescheduled date
2021-09-04 08:27:19 -07:00
Jesse Butler 3a36f1cf3e update 1.22 release webinar date in release blog due to rescheduling 2021-09-04 11:12:37 -04:00
Kubernetes Prow Robot ba5b36d84c Merge pull request #29607 from fregataa/patch-1
[ko] fix a mistranslated sentence which explains pod-lifecycle
2021-09-04 04:37:19 -07:00
Kubernetes Prow Robot 67c7cc9924 Merge pull request #29488 from howieyuen/contribution-2
[zh]sync contribution files for 1.22(Part-2)
2021-09-04 00:49:19 -07:00
Ben Hall 280e67a4e1 Move to Minikube 1.20 image of Katacoda for Hello Minikube Tutorial
Signed-off-by: Ben Hall <ben@benhall.me.uk>
2021-09-04 07:55:17 +01:00
Kubernetes Prow Robot 1393a4abd7 Merge pull request #28688 from npu21/operator-pt
Update URL for Metacontroller
2021-09-03 12:58:53 -07:00
Kubernetes Prow Robot 60eb426408 Merge pull request #29581 from SwapnaneelChowdhury/patch-1
Fixed Portuguese componenets link (#29522)
2021-09-03 12:56:53 -07:00
Michael McQuade 2aca8f917c Use correct namespace
The namespace for this is `ingress-nginx`
2021-09-03 14:24:17 -05:00
Kubernetes Prow Robot 0a1921e28c Merge pull request #29608 from Arhell/upd
[ru] Update the link to cloud interface
2021-09-02 23:03:50 -07:00
Arhell 036227e956 [ru] Update the link to cloud interface 2021-09-03 00:21:27 +03:00
SangHun Lee b0ea0dc2e4 Update pod-lifecycle.md 2021-09-03 01:52:16 +09:00
Kubernetes Prow Robot 8a26a33998 Merge pull request #29529 from buehler/patch-1
docs: Add "KubeOps" operator SDK to third-party list
2021-09-02 09:26:58 -07:00
Kubernetes Prow Robot 2948ff2fa3 Merge pull request #29127 from tengqm/amend-kubeadm-join
Amend kubeadm join doc for node preparation
2021-09-02 06:40:59 -07:00
Kubernetes Prow Robot fec7dce3ad Merge pull request #29555 from GCES-Kubernetes/translation/SytemLogsPtBr
[pt-br] Adding brazilian portuguese translation of System Logs page
2021-09-02 03:44:10 -07:00
Kubernetes Prow Robot 2ecdd4f151 Merge pull request #29490 from howieyuen/contribution-3
[zh]sync contribution files for 1.22(Part-3)
2021-09-02 02:26:10 -07:00
Qiming Teng 87e92d4893 Update content/en/docs/setup/production-environment/tools/kubeadm/create-cluster-kubeadm.md
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-09-02 14:55:24 +08:00
Kubernetes Prow Robot 5a53712c39 Merge pull request #29601 from Arhell/url
[pt-br] Update URL for Metacontroller
2021-09-01 16:16:09 -07:00
Arhell 0a1f8654a7 [pt-br] Update URL for Metacontroller 2021-09-02 00:50:56 +03:00
Kubernetes Prow Robot ee84275364 Merge pull request #29079 from Ritikaa96/update-cilium-network-policy-task
updating cilium network policy docs
2021-09-01 10:57:41 -07:00
Kubernetes Prow Robot b88fe105c2 Merge pull request #29589 from anuraaga/patch-1
Fix typo in health-checks doc
2021-09-01 10:53:41 -07:00
Kubernetes Prow Robot edc098d8ef Merge pull request #29598 from jlbutler/owners-request
request adding jlbutler to sig-docs-en-owners
2021-09-01 09:15:00 -07:00
Jesse Butler 1b691829dc request adding jlbutler to sig-docs-en-owners 2021-09-01 11:03:22 -04:00
Kubernetes Prow Robot 7486562af6 Merge pull request #29575 from Arhell/upd
[ja] Update default node pod limits for large cluster
2021-09-01 03:10:59 -07:00
Kubernetes Prow Robot 37c9165365 Merge pull request #29563 from mengjiao-liu/sync-1.22-kubeadm-part3
[zh] Setup files to sync for 1.22(kubeadm part-3)
2021-09-01 03:06:59 -07:00
Kubernetes Prow Robot d25b64cbfb Merge pull request #29594 from Arhell/remove
[zh] remove unneeded comma
2021-09-01 03:04:59 -07:00
Arhell a4c0b79970 [zh] remove unneeded comma 2021-09-01 00:37:12 +03:00
Kubernetes Prow Robot 02f64ff775 Merge pull request #29586 from kimcore/patch-1
[ko] fix mistranslated part in statefulset.md
2021-08-31 08:39:38 -07:00
Kubernetes Prow Robot 28ca4eba0b Merge pull request #29546 from mengjiao-liu/sync-1.22-kubeadm-part2
[zh] Setup files to sync for 1.22(kubeadm part-2)
2021-08-30 20:22:28 -07:00
Kubernetes Prow Robot 2b27d92fe8 Merge pull request #29562 from mengjiao-liu/sync-1.22-windows-runtime
[zh] Setup files to sync for 1.22(windows & runtime)
2021-08-30 20:18:28 -07:00
Kubernetes Prow Robot d30c26c3c9 Merge pull request #29551 from zhangguanzhang/zh-feature-gates
[zh] - docs/reference/command-line-tools-reference/feature-gates.md
2021-08-30 20:16:28 -07:00
Kubernetes Prow Robot f44166a7da Merge pull request #29566 from mengjiao-liu/sync-1.22-part5
[zh] Setup files to sync for 1.22(part-5)
2021-08-30 20:14:28 -07:00
Kubernetes Prow Robot 82da8f915d Merge pull request #29451 from steven-my/29329-translation-for-run-app
[zh] translation for the run-app section
2021-08-30 20:12:28 -07:00
Anuraag Agrawal 6c1ecfa016 Fix typo in health-checks doc 2021-08-31 11:53:15 +09:00
Kubernetes Prow Robot 5c316c2c2a Merge pull request #29509 from steven-my/29329-translation-for-kubectl-install
[zh] translation for kubectl install section
2021-08-30 19:34:28 -07:00
Kubernetes Prow Robot b05768dd45 Merge pull request #29574 from niteshseram/fix/ko-links
[ko] fix broken links in install kubectl windows page
2021-08-30 17:56:28 -07:00
Arhell 3d3db5a49c [ja] Updating --cascade=false to --cascade=orphan 2021-08-31 00:15:14 +03:00
kimcore 2fa3b35d84 [ko] fix mistranslated part in statefulset.md 2021-08-30 23:28:01 +09:00
Kubernetes Prow Robot 0cf63c805b Merge pull request #29345 from sftim/20210812_migrate_image_good_practice_images_concept
Migrate good practice for container images into Containers section
2021-08-30 07:20:54 -07:00
Kubernetes Prow Robot 773411fa3c Merge pull request #29030 from sgpinkus/patch-2
Update _index.md
2021-08-30 07:18:54 -07:00
Kubernetes Prow Robot d0959ca3f4 Merge pull request #29526 from tylerauerbeck/fix-dashboard-proxy
Fix proxy url to expose dashboard
2021-08-30 07:16:54 -07:00
Kubernetes Prow Robot e861bd334a Merge pull request #29012 from Kartik494/stableexample
Modify documentation for stable storage
2021-08-30 07:14:54 -07:00
Kubernetes Prow Robot 07725b5490 Merge pull request #29536 from naisuuuu/improve-namespaces-wording
Improve wording of `kube-node-lease` namespace doc
2021-08-30 07:12:54 -07:00
Kubernetes Prow Robot b959e7ba45 Merge pull request #29564 from Roman513/patch-1
Fix errors in russian translation for Cloud Controller Manager page
2021-08-30 07:02:54 -07:00
Marcos Nery 1b6c76745c refact: improving readability 2021-08-30 03:19:28 -03:00
Mengjiao Liu 57deb4fddc [zh] Setup files to sync for 1.22(kubeadm part-2) 2021-08-30 11:41:55 +08:00
Mengjiao Liu 12181a4d7c [zh] Setup files to sync for 1.22(part-5) 2021-08-30 11:12:14 +08:00
Mengjiao Liu b6a1a29963 [zh] Setup files to sync for 1.22(windows & runtime) 2021-08-30 10:56:29 +08:00
Kubernetes Prow Robot cffa9a09cb Merge pull request #29539 from niteshseram/fix/migrate-image
migrate images for 'Alpha in Kubernetes v1.22: API Server Tracing' article
2021-08-29 19:48:53 -07:00
Kubernetes Prow Robot c596818637 Merge pull request #29549 from rf232/patch-1
Remove rf232(myself) from reviewers
2021-08-29 19:30:53 -07:00
Steven Yan 6e61a2b772 translation for kubectl install section 2021-08-30 10:18:34 +08:00
Kubernetes Prow Robot c6b884b0cf Merge pull request #29583 from Arhell/update-basic-set
[id] Updating --cascade=false to --cascade=orphan
2021-08-29 19:00:53 -07:00
Arhell 570dce0dde [id] Updating --cascade=false to --cascade=orphan 2021-08-30 00:39:17 +03:00
SwapnaneelChowdhury d12503c989 Fix a bug #29522
Fixed "What's next" links in portuguese section which was forwarding to the english page
2021-08-29 16:41:25 +05:30
Kubernetes Prow Robot b7a9fe022d Merge pull request #29545 from chenxuc/task-access
[zh]sync access tasks files
2021-08-28 23:36:53 -07:00
zhangguanzhang ba8429cdc6 [zh] - docs/reference/command-line-tools-reference/feature-gates.md
Signed-off-by: zhangguanzhang <zhangguanzhang@qq.com>
2021-08-28 21:07:58 +08:00
Arhell 234fa360ba [ja] Update default node pod limits for large cluster 2021-08-28 12:41:22 +03:00
S Nitesh Singh ab7a302628 [ko] fix broken links in install kubectl windows page 2021-08-28 12:16:38 +05:30
Kubernetes Prow Robot 42a93ae773 Merge pull request #29571 from niteshseram/fix/links-windows
fix broken link in install kubectl windows page
2021-08-27 18:04:52 -07:00
Marcos Nery aa8fb8f871 refact: improving text readability 2021-08-27 15:48:36 -03:00
Marcos Nery eee9345bbf Merge branch 'kubernetes:main' into translation/SytemLogsPtBr 2021-08-27 15:29:25 -03:00
S Nitesh Singh 1016cd383d fix broken link in install kubectl windows page 2021-08-27 23:10:48 +05:30
Kubernetes Prow Robot 7f198cd154 Merge pull request #29411 from tengqm/zh-fix-saadmin
[zh] Fix and resync service accounts admin page
2021-08-27 09:10:04 -07:00
Kubernetes Prow Robot 79bb314051 Merge pull request #29277 from tengqm/zh-prod-env
[zh] Translate production environment
2021-08-27 09:08:04 -07:00
Kubernetes Prow Robot f41c9c0831 Merge pull request #29553 from camachomaria/patch-1
Update static-pod.md
2021-08-27 07:16:03 -07:00
Mengjiao Liu a07b8a79ba [zh] Setup files to sync for 1.22(kubeadm part-3) 2021-08-27 16:01:59 +08:00
Kubernetes Prow Robot f76c2a7b63 Merge pull request #29541 from Arhell/update
[zh] Update determine-reason-pod-failure.md
2021-08-26 21:04:59 -07:00
Arhell 41bc06f1a0 [zh] Update determine-reason-pod-failure.md 2021-08-27 03:05:47 +03:00
Roman513 9163103ee2 Fix errors in russian translation 2021-08-26 23:56:04 +03:00
MarcosN 9b8e046000 improving text readability 2021-08-26 16:42:44 -03:00
MarcosN d50a1cd890 adding pt-br translation for System Logs page 2021-08-26 16:02:02 -03:00
chrismetz09 cbff3ec4ea upgrade to mermaid 8.11.2 2021-08-26 10:53:18 -07:00
Maria Camacho f1b99bb92d Update static-pod.md
Added a missing verb and full stop.
2021-08-26 19:30:42 +03:00
Rob Franken b2f9611849 Remove rf232(myself) from reviewers
I have not been involved in kubernetes dashboard development for years
2021-08-26 13:23:51 +02:00
Kubernetes Prow Robot f6fb295afd Merge pull request #29531 from mengjiao-liu/sync-1.22-kubeadm-part1
[zh] Setup files to sync for 1.22(kubeadm part-1)
2021-08-26 02:19:23 -07:00
chenxuc 1809def31c [zh]sync access tasks files 2021-08-26 16:30:21 +08:00
Kubernetes Prow Robot 03f1829e4f Merge pull request #29507 from Arhell/typo
[zh] Gramma fix for change-pv-reclaim-policy.md
2021-08-25 21:17:22 -07:00
Mengjiao Liu 8ab1f6a5d5 [zh] Setup files to sync for 1.22(kubeadm part-1) 2021-08-26 10:02:20 +08:00
naisu 5220cdf8d2 Explain leases in kube-node-lease namespace doc
Add a reference to `Lease` resource api doc

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-08-26 02:22:45 +02:00
Kubernetes Prow Robot c83e410333 Merge pull request #29492 from sftim/20210820_fix_cronjob_graduation_release
Fix incorrect info about when CronJob reached GA
2021-08-25 10:52:43 -07:00
S Nitesh Singh 9dc4fcc80c migrate images for 'Alpha in Kubernetes v1.22: API Server Tracing' article 2021-08-25 22:59:39 +05:30
Kubernetes Prow Robot 3516b2e199 Merge pull request #29528 from tylerauerbeck/fix-pod-sec-adm-link
Fix link in pod-security-admission
2021-08-25 09:10:41 -07:00
Jesse Butler 6dd696487a 1.22 feature blog for api server tracing (#28991)
* 1.22 feature blog for API server tracing

* Add initial draft of descriptive tracing portions

* demo

demo

* Apply suggestions from code review

Co-authored-by: Chris Negus <cnegus@redhat.com>

* address comments

* address comments and grammar

* Add more explanation to the Demo section; add conclusion

* Update content/en/blog/_posts/2021-08-06-api-server-tracing.md

Co-authored-by: Punya Biswal <punya@google.com>

* address comments

* address feedback

* update alt text

* Update content/en/blog/_posts/2021-08-06-api-server-tracing.md

Co-authored-by: Rey Lejano <rlejano@gmail.com>

* Rename 2021-08-06-api-server-tracing.md to 2021-09-03-api-server-tracing.md

* update alt text on first image

* better alt text.

Co-authored-by: David Ashpole <dashpole@google.com>
Co-authored-by: Chris Negus <cnegus@redhat.com>
Co-authored-by: Punya Biswal <punya@google.com>
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-25 09:06:41 -07:00
naisu 497a5231df Improve wording of kube-node-lease namespace doc
Correct grammar and provide a reference to more detailed documentation of concepts mentioned.
2021-08-25 17:20:22 +02:00
Kubernetes Prow Robot 0e4cdf227a Merge pull request #29517 from Arhell/update
[zh] Update client-libraries.md
2021-08-25 06:58:41 -07:00
Christoph Bühler c031257f3e fix ordering of list 2021-08-25 11:25:29 +02:00
Christoph Bühler d8199078f5 Add additional information about "kubeops" 2021-08-25 09:53:01 +02:00
Kubernetes Prow Robot 6e892c39bc Merge pull request #29527 from Arhell/upd
[ja] Update determine-reason-pod-failure.md
2021-08-25 00:50:39 -07:00
Kubernetes Prow Robot 8d2f5d95d3 Merge pull request #29032 from able8/fix-typos-ja
[ja] Fix typos
2021-08-25 00:48:40 -07:00
Christoph Bühler 8b013b8e92 docs: Add "KubeOps" operator SDK to third-party list
Adding dotnet operator sdk/framework to third-party list of operator sdks.
2021-08-25 09:33:44 +02:00
Kubernetes Prow Robot 0f394a9eab Merge pull request #29191 from nakamasato/improve-ja-k8s-object-management
[ja] Improve Japanese expression in Kubernetes object management
2021-08-24 23:12:39 -07:00
Tyler Auerbeck 3dc86945ed Fix link in pod-security-admission 2021-08-25 00:57:35 -04:00
Kubernetes Prow Robot fcff108a23 Merge pull request #29226 from tmeralus/patch-1
fixed small typo
2021-08-24 21:10:39 -07:00
Tedley Meralus 964ab4a274 changed uprate to promote
changed word to better clarify actions used in kubernetes cluster
2021-08-24 23:57:00 -04:00
Kubernetes Prow Robot ad5e309805 Merge pull request #29515 from sftim/20210823_tweak_dashboard_task
Revise task page to deploy and access the Kubernetes Dashboard
2021-08-24 20:34:39 -07:00
Kubernetes Prow Robot 0857620280 Merge pull request #29363 from mk46/rss_broken
Removed reference for broken link
2021-08-24 16:19:32 -07:00
Tim Bannister 8563416062 Fix typo
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-24 23:59:23 +01:00
Arhell a1ad8a4d72 [ja] Update determine-reason-pod-failure.md 2021-08-25 00:16:06 +03:00
Tyler Auerbeck 08121d0c59 Fix proxy url to expose dashboard 2021-08-24 16:06:35 -04:00
Jesse Butler 9924e7a8db 1.22 feature blog for minReadySeconds in StatefulSets (#28992)
* 1.22 feature blog for minReadySeconds in StatefulSets

* Address reviewer's comments

* Update content/en/blog/_posts/2021-08-16-minreadysecond-statefulsets.md

Co-authored-by: Simon Pasquier <spasquie@redhat.com>

* Bump article publication date

Co-authored-by: ravisantoshgudimetla <ravisantoshgudimetla@gmail.com>
Co-authored-by: Ravi Gudimetla <ravisantoshgudimetla@users.noreply.github.com>
Co-authored-by: Simon Pasquier <spasquie@redhat.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-08-24 10:53:13 -07:00
Kubernetes Prow Robot 9b17097b45 Merge pull request #28451 from vaibhav2107/learning-env
Update in docs/setup/learning-environment/_index.md
2021-08-24 10:43:15 -07:00
Kubernetes Prow Robot dc262ad58b Merge pull request #27905 from jai/jai/fix-20134
docs(manage-resources-containers): add volume and volumeMount for ephemeral storage
2021-08-24 10:41:14 -07:00
Tim Bannister fd19a0c145 Migrate good practice for container images into Containers section 2021-08-24 10:47:18 +01:00
Kubernetes Prow Robot 607405e106 Merge pull request #29505 from jimangel/zoom-policy
adding zoom info for localization teams
2021-08-24 02:37:13 -07:00
Arhell 1c2dc112f3 [zh] Update client-libraries.md 2021-08-24 12:29:28 +03:00
Kubernetes Prow Robot 157f1d76b8 Merge pull request #28951 from saschagrunert/seccomp-default-blog
Add seccomp default feature blog post
2021-08-24 02:27:13 -07:00
Sascha Grunert 84e472e95c Add seccomp default feature blog post
This adds the blog post about the new Kubernetes `SeccompDefault` alpha
feature.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2021-08-24 08:49:50 +02:00
Kubernetes Prow Robot 6e7b621625 Merge pull request #29310 from jonathino2590/jonathino2590-patch-1
Update Document Deployments
2021-08-23 22:27:13 -07:00
Masato Naka a4e37c88b9 fix next sentence
Signed-off-by: Masato Naka <masatonaka1989@gmail.com>
2021-08-24 09:08:09 +09:00
Tim Bannister a532758197 Fix incorrect info about when CronJob reached GA 2021-08-23 23:00:00 +01:00
Tim Bannister 289295c46c Update Dashboard task title and description 2021-08-23 22:57:03 +01:00
Tim Bannister 950600c510 Reword Dashboard task 2021-08-23 22:56:48 +01:00
Kubernetes Prow Robot e220769ea3 Merge pull request #29504 from jimangel/hugo-improvements
Hugo improvements
2021-08-23 10:08:01 -07:00
Kubernetes Prow Robot 5f301dcec5 Merge pull request #29468 from Abirdcfly/patch-2
Update rbac.md: Describe in detail how to specify resourceNames when using list verbs
2021-08-23 07:12:01 -07:00
Abirdcfly 19807f866c Update content/en/docs/reference/access-authn-authz/rbac.md
Co-authored-by: Jordan Liggitt <jordan@liggitt.net>
2021-08-23 21:45:10 +08:00
Kubernetes Prow Robot 294f591267 Merge pull request #29513 from niteshseram/fix/psc
Rename product security committee to security response committee
2021-08-23 05:40:00 -07:00
S Nitesh Singh 2cb0f9cd8f rename product security committee to security response committee 2021-08-23 16:54:01 +05:30
Kubernetes Prow Robot 2f70a10bce Merge pull request #29511 from nak3/fix-typo
Fix typo in japanese doc
2021-08-23 03:54:00 -07:00
Kenjiro Nakayama a9362477d3 Fix typo in japanese doc 2021-08-23 18:15:32 +09:00
Kubernetes Prow Robot 750d42470b Merge pull request #29491 from cpanato/update-patches-sept
release/patches: update patch release September cycle
2021-08-23 00:26:00 -07:00
Kubernetes Prow Robot 5590959850 Merge pull request #29501 from chenxuc/task-misc
[zh]sync misc task files
2021-08-22 23:31:59 -07:00
Kubernetes Prow Robot b6af69503a Merge pull request #29475 from howieyuen/contribution-part-1
[zh]sync contribution files for 1.22(Part-1)
2021-08-22 22:27:59 -07:00
Steven Yan 742e7d7ee4 translation for the run-app section 2021-08-23 12:03:00 +08:00
howieyuen 1698263ca3 [zh]sync contribution files for 1.22(Part-3) 2021-08-23 10:40:28 +08:00
howieyuen 55c7993e9b [zh]sync contribution files for 1.22(Part-1) 2021-08-23 10:33:58 +08:00
Arhell cfc0752351 [zh] Gramma fix for change-pv-reclaim-policy.md 2021-08-23 03:09:48 +03:00
Masato Naka f63ff99d23 [ja] Improve Japanese expression in Secret
Signed-off-by: Masato Naka <masatonaka1989@gmail.com>
2021-08-23 08:37:53 +09:00
Jim Angel d5b67cf560 adding zoom info for localization teams 2021-08-22 21:04:45 +00:00
Jim Angel e01f70dab9 updating theme submodule 2021-08-22 20:06:05 +00:00
Jim Angel bd5223c5af performance tuning and hugo version upgrade 2021-08-22 20:05:12 +00:00
Kubernetes Prow Robot 433480d74e Merge pull request #28756 from jihoon-seo/210702_ru_Update_Netlify_link_address
[ru] Update Netlify link address
2021-08-22 10:11:59 -07:00
Kubernetes Prow Robot 2fb1f22a7b Merge pull request #29498 from Devops-Ramdas/patch-1
Update components.md
2021-08-22 09:49:59 -07:00
Kubernetes Prow Robot 5c95d82945 Merge pull request #29302 from tengqm/fix-examples-test
Fix examples test
2021-08-22 08:46:00 -07:00
astraw99 340125aa5b fix typo and its related en doc sync 2021-08-22 17:57:58 +08:00
chenxuc a33bc3b2b1 [zh]sync misc task files
related: #29329
2021-08-22 17:19:42 +08:00
Kubernetes Prow Robot f244bb0e30 Merge pull request #29500 from astraw99/patch-3
Fix typo `a extension` in `en` language
2021-08-22 00:27:59 -07:00
Cheng Wang a130f6b8b9 Fix typo a extension 2021-08-22 12:12:30 +08:00
Kubernetes Prow Robot b28fa33617 Merge pull request #29499 from Arhell/upd
[zh] Update kustomization.md
2021-08-21 18:19:59 -07:00
Arhell a70567a6a4 [zh] Update kustomization.md 2021-08-21 13:51:07 +03:00
Ramdas Potale 988a62b463 Update components.md
I think adding the "for" word in the below sentence makes more sense.

"This document outlines the various components you need to have "for"
a complete and working Kubernetes cluster."
2021-08-21 09:27:03 +05:30
Kubernetes Prow Robot 116839a094 Merge pull request #29316 from sysnet4admin/patch-2
Update web-ui-dashboard.md
2021-08-20 18:25:59 -07:00
Kubernetes Prow Robot 58e8910312 Merge pull request #29495 from stormqueen1990/addons-pt-br
[pt-br] Update Installing Addons page translation to reflect latest documentation version
2021-08-20 16:43:58 -07:00
Mauren Berti 565555a9d7 Update translation to reflect latest docs version.
Signed-off-by: Mauren Berti <mribeirobert@vmware.com>
2021-08-20 14:26:21 -04:00
Kubernetes Prow Robot 15a909818d Merge pull request #29455 from cndoit18/feat/add-cronjob-timezone
[en]: description of the cronjob schedule timezone
2021-08-20 06:31:24 -07:00
Carlos Panato cf027c8105 release/patches: update patch release September cycle
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-08-20 14:29:35 +02:00
Kubernetes Prow Robot 98e115c86c Merge pull request #27852 from edsoncelio/pt_translate_task_secrets
[PT-BR] Add content/pt-br/docs/tasks/configmap-secret/
2021-08-20 05:09:24 -07:00
Mauren Berti e4ae89a725 [PT-BR] Update CronJob documentation page (#28979)
* Update CronJob page translation to Portuguese.

Update CronJob page to reflect the latest English version in the Brazilian
Portuguese translation.

Signed-off-by: Mauren Berti <mribeirobert@vmware.com>

* Incorporate feedback from pull request.

Signed-off-by: Mauren Berti <mribeirobert@vmware.com>
2021-08-20 05:03:24 -07:00
Kubernetes Prow Robot 370b521a87 Merge pull request #29489 from saschagrunert/privileged-unconfined
Mention that privileged containers run unconfined
2021-08-20 02:35:24 -07:00
Kubernetes Prow Robot 753e70c072 Merge pull request #29487 from borgerli/main
Change CPU and Memory to lowercase because resoure name is case-sensitive
2021-08-20 01:23:24 -07:00
Li Bo 34d7331e4e change CPU and Memory to lowercase because resoure name is case-sensitive 2021-08-20 16:13:55 +08:00
Sascha Grunert 61b8cafa84 Mention that privileged containers run unconfined
This is a note which helps users to understand the interaction between
privileged containers and seccomp profiles.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-08-20 10:09:11 +02:00
Kubernetes Prow Robot b1b1395b0a Merge pull request #28695 from geoffcline/kubectl-namespace-patch-1
update desc of namespace defaulting in CLI
2021-08-20 00:59:25 -07:00
howieyuen 742824d491 [zh]sync contribution files for 1.22(Part-2) 2021-08-20 15:32:00 +08:00
cndoit18 4211fa7007 feat(cronjob): description of the cronjob schedule timezone
Signed-off-by: cndoit18 <cndoit18@outlook.com>
2021-08-20 11:49:09 +08:00
Kubernetes Prow Robot cdefcc3a8b Merge pull request #29477 from brakmic/patch-1
trivial: typo
2021-08-19 20:39:24 -07:00
Kubernetes Prow Robot 49654e7d7a Merge pull request #29481 from Arhell/fix
[id] Fixed link to API priority and fairness enhancement proposal
2021-08-19 19:11:25 -07:00
Kubernetes Prow Robot 28bc7a4152 Merge pull request #29482 from reylejano/website-issue-29480
Add note on owner references back to garbage collection page
2021-08-19 18:15:24 -07:00
Rey Lejano 64f91d8e2c add note on owner references in garbage collection page
add note on owner references to owner dependents page
2021-08-19 17:43:09 -07:00
Arhell b3ecce8eb0 [id] Fixed link to API priority and fairness enhancement proposal 2021-08-20 02:27:49 +03:00
Harris Brakmić 2b268b1a76 trivial: typo
A small typo.
2021-08-19 22:07:59 +02:00
Kubernetes Prow Robot dd2f06f64a Merge pull request #29476 from liggitt/podsecurity-audit-annotations
Clarify audit annotation destination
2021-08-19 08:59:24 -07:00
Abirdcfly 162da6561b Update rbac.md: Describe in detail how to specify resourceNames when using list/watch verbs 2021-08-19 23:39:48 +08:00
Jordan Liggitt 315e290107 Avoid word-break on narrow page widths 2021-08-19 10:04:34 -04:00
Jordan Liggitt 8c3eb6e414 Clarify audit annotation destination 2021-08-19 09:59:19 -04:00
Kubernetes Prow Robot d12f42161e Merge pull request #28970 from skrishna-unix/dev-1.22
Volume Populators Redesign Blog
2021-08-19 03:09:24 -07:00
Tim Bannister de7bca791e Fix hyperlink 2021-08-19 11:00:21 +01:00
Kubernetes Prow Robot 4f203c61e4 Merge pull request #29437 from sftim/20210817_fix_tutorial_html_lang_attribute_zh
Fix HTML language attributes (中文)
2021-08-18 19:46:16 -07:00
Kubernetes Prow Robot fcd160900a Merge pull request #29462 from sftim/20210818_fix_date_for_article
Fix date for published blog article
2021-08-18 15:47:45 -07:00
Kubernetes Prow Robot 8cb22b93bc Merge pull request #29464 from JimBugwadia/master
add kyverno and fix OPA/GK link
2021-08-18 12:51:47 -07:00
Jim Bugwadia dad01370f8 add kyverno and fix OPA/GK link
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
2021-08-18 11:07:02 -07:00
Tim Bannister 944733cb20 Fix date for published blog article
This change affects the date shown in the repository and does NOT affect
the URL or content of the published article.
2021-08-18 16:03:44 +01:00
Kunal Kushwaha ee99447c9d 1.22 Feature Blog for Support for Windows privileged containers (#29022)
* 1.22 feature blog for Support for Windows privileged containers

* Rebased with latest blog content

* dates updated

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md.md

Co-authored-by: Chris Negus <cnegus@redhat.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md.md

Co-authored-by: Chris Negus <cnegus@redhat.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md.md

Co-authored-by: Chris Negus <cnegus@redhat.com>

* Update index.md.md

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Rename index.md.md to index.md

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Fix broken hyperlink

* Fix broken hyperlink

Co-authored-by: Rey Lejano <rlejano@gmail.com>

* Fix hyperlink

Co-authored-by: Rey Lejano <rlejano@gmail.com>

Co-authored-by: Brandon Smith <brasmith@microsoft.com>
Co-authored-by: Chris Negus <cnegus@redhat.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-18 07:32:08 -07:00
Rajat Gupta 232e6d7927 Update _index.md 2021-08-18 14:53:03 +05:30
Kubernetes Prow Robot 5525c49815 Merge pull request #29446 from Arhell/remove
[es] Delete logging-stackdriver.md
2021-08-18 01:32:08 -07:00
Arhell 50c8238a2d [es] Delete logging-stackdriver.md 2021-08-18 02:36:09 +03:00
Geoffrey Cline 57c0fe1120 update desc of namespace defaulting in CLI 2021-08-17 18:27:10 +00:00
Anubhav Vardhan 8eadd71c25 Update content/hi/docs/setup/production-environment/windows/_index.md
Co-authored-by: Yashu Mittal <mittalyashu77@gmail.com>
2021-08-17 23:04:05 +05:30
Kubernetes Prow Robot 40f055cacc Merge pull request #29202 from edithturn/add-content/es/docs/concepts/storage/volume-snapshot-classes
[es] Add concepts/storage/volume-snapshot-classes.md
2021-08-17 09:09:13 -07:00
Edith Puclla 1df20dc263 Update content/es/docs/concepts/storage/volume-snapshot-classes.md
Thank you, Rael! :)

Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-17 10:43:06 -05:00
Kubernetes Prow Robot 389fe5ea40 Merge pull request #29443 from ialidzhikov/fix/eol-dates
Fix EoL dates in data/releases/schedule.yaml
2021-08-17 06:43:13 -07:00
ialidzhikov 43bf8f2a10 Fix EoL dates in data/releases/schedule.yaml
Signed-off-by: ialidzhikov <i.alidjikov@gmail.com>
2021-08-17 16:08:05 +03:00
Kubernetes Prow Robot a5c98695b7 Merge pull request #29440 from sftim/20210817_fix_tutorial_html_lang_attribute_vi
Fix HTML language attributes (tiếng Việt)
2021-08-17 04:48:02 -07:00
Kubernetes Prow Robot c3b8d319f4 Merge pull request #29441 from sftim/20210817_fix_tutorial_html_lang_attribute_pl
Fix HTML language attributes (polszczyzna)
2021-08-17 04:46:01 -07:00
Tim Bannister 399c7749c7 Fix HTML language attribute 2021-08-17 12:23:43 +01:00
Tim Bannister c1af1ad3f5 Fix HTML language attribute 2021-08-17 12:21:47 +01:00
Kubernetes Prow Robot da656a8c99 Merge pull request #29436 from sftim/20210817_fix_tutorial_html_lang_attribute_es
Fix HTML language attributes (español)
2021-08-17 03:36:01 -07:00
Kubernetes Prow Robot 7e148d5c05 Merge pull request #29435 from sftim/20210817_fix_tutorial_html_lang_attribute_de
Fix HTML language attributes (Deutsch)
2021-08-17 02:58:01 -07:00
Tim Bannister a9e6ea897b Fix HTML language attribute 2021-08-17 09:57:53 +01:00
Tim Bannister f146e0103f Fix HTML language attribute 2021-08-17 09:54:43 +01:00
Tim Bannister 711d4ec1f6 Fix HTML language attribute 2021-08-17 09:52:59 +01:00
rajat 8241d8129d Add content/hi/docs/tasks/_index.md 2021-08-17 14:21:33 +05:30
Kunal Verma 7db7aca9ec Add content/hi/docs/tutorials/kubernetes-basics/update/update-interactive.html 2021-08-17 12:27:22 +05:30
Kubernetes Prow Robot ace33e10b3 Merge pull request #29426 from Arhell/delete
[zh] Delete logging-stackdriver.md
2021-08-16 20:22:01 -07:00
Kubernetes Prow Robot 4c047a7495 Merge pull request #29423 from mengjiao-liu/sync-scheduling-1.22
[zh] Concept files to sync for 1.22 - (9) Scheduling
2021-08-16 20:20:01 -07:00
Kubernetes Prow Robot bb3e36d473 Merge pull request #29368 from howieyuen/tutorial
[zh]sync tutorials files for 1.22
2021-08-16 20:16:00 -07:00
howieyuen 9075aa237f [zh]sync tutorials files for 1.22 2021-08-17 10:47:32 +08:00
Mengjiao Liu ec405cce3c [zh] Concept files to sync for 1.22 - (9) Scheduling 2021-08-17 10:42:01 +08:00
Kubernetes Prow Robot 2429254d6b Merge pull request #29110 from mfilocha/pl-update-readme
Update Polish README file
2021-08-16 19:36:01 -07:00
Kubernetes Prow Robot cd052d9381 Merge pull request #29369 from EricWvi/main
[zh] Concept files to sync for 1.22 - (8) Service
2021-08-16 19:22:02 -07:00
Arhell bfb3d16846 [zh] Delete logging-stackdriver.md 2021-08-17 02:30:23 +03:00
Kubernetes Prow Robot 31ef56b98b Merge pull request #29357 from jimangel/updating-docs-co-chairs
updating co-chairs
2021-08-16 16:12:00 -07:00
Kubernetes Prow Robot 5c1d701916 Merge pull request #29176 from NamikoToriyama/ja/fix-notfound-link
[ja] Fix a non-existent link
2021-08-16 14:04:23 -07:00
Ben Swartzlander c0b5d85371 Volume Populators Redesign Blog
For https://github.com/kubernetes/enhancements/issues/1495
2021-08-16 16:59:36 -04:00
Kubernetes Prow Robot 50e16b7175 Merge pull request #29364 from mfilocha/pl-synchronize-1.22a2
Synchronize Polish localization for ver 1.22, part 2
2021-08-16 13:46:23 -07:00
Kubernetes Prow Robot 6e0bd0033f Merge pull request #29339 from mfilocha/pl-synchronize-1.22a
Synchronize Polish localization for ver 1.22, part 1
2021-08-16 13:44:23 -07:00
Kubernetes Prow Robot e081551e5d Merge pull request #29337 from mfilocha/pl-update-main-index-page
Update Polish localization of the home page
2021-08-16 13:42:22 -07:00
Jonathan Lopez Torres 7bb5df553c Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-16 08:53:21 -05:00
Jonathan Lopez Torres aa30cf0ef8 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-16 08:53:09 -05:00
Jonathan Lopez Torres 55d477f61c Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-16 08:52:57 -05:00
Jonathan Lopez Torres 43d0461908 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-16 08:52:41 -05:00
Kubernetes Prow Robot 320259d57f Merge pull request #29418 from Arhell/fix
[zh] Fix list all uniq container images
2021-08-16 06:05:18 -07:00
Kubernetes Prow Robot 87235b508d Merge pull request #29311 from mengjiao-liu/update-githubbranch-param
Hard-code the name of the target repo's default branch instead of using the githubbranch parameter value
2021-08-16 06:03:18 -07:00
Kubernetes Prow Robot 394f382608 Merge pull request #27987 from olivierk7/patch-2
French translation of workloads page
2021-08-16 01:39:47 -07:00
Rémy Léone 28cb1efbed Apply suggestions from code review 2021-08-16 10:24:22 +02:00
Kubernetes Prow Robot 86aa6c434d Merge pull request #29320 from Arhell/del
[fr] Deleted reference to removed file
2021-08-16 01:09:47 -07:00
EricWvi cd9dc4e482 apply suggestion 2021-08-16 15:13:31 +08:00
Kubernetes Prow Robot b89e5c3042 Merge pull request #29419 from Iceber/update-custom-resource-definition-versioning
[zh] update custom-resource-definition-versioning.md
2021-08-15 23:47:47 -07:00
Kunal Verma aade2e9ad4 Add content/hi/docs/tutorials/kubernetes-basics/scale/_index.md 2021-08-16 12:04:33 +05:30
Iceber Gu ed1ce53ab5 [zh] update custom-resource-definition-versioning.md 2021-08-16 12:28:22 +08:00
Arhell f086aba3d8 [zh] Fix list all uniq container images 2021-08-16 00:19:43 +03:00
Kubernetes Prow Robot b354468ed0 Merge pull request #29409 from tengqm/fix-featuregates
Fix some errors in the feature-gates page
2021-08-15 10:59:46 -07:00
Anubhav Vardhan 024ced2584 Update explore-interactive.html 2021-08-15 22:32:45 +05:30
Anubhav Vardhan 7637b93590 Create _index.md 2021-08-15 18:44:43 +05:30
Qiming Teng 3cebde5777 Fix and resync service accounts admin page 2021-08-15 19:57:02 +08:00
Kunal Verma b3d79b5676 Add /hi/docs/tutorials/kubernetes-basics/scale/scale-interactive.html 2021-08-15 16:30:34 +05:30
Kubernetes Prow Robot ff44f2996b Merge pull request #28978 from wesleyw72/cpu-management-burstable-cfs
Clarify that burstable pods also have their limit enforced by CFS quota
2021-08-15 03:39:46 -07:00
Qiming Teng da53892746 Fix some errors in the feature-gates page 2021-08-15 18:26:20 +08:00
Kubernetes Prow Robot d6dbd52b08 Merge pull request #29406 from Patil2099/ko-fix
[ko] Translation in manage-resources-containers improved
2021-08-15 02:53:46 -07:00
Pankaj Patil 05ff7d6597 [ko] Translation in manage-resources-containers improved 2021-08-15 15:04:58 +05:30
Kubernetes Prow Robot cc493080cd Merge pull request #29288 from dimabru/patch-1
docs: Update custom-resource-definition-versioning.md
2021-08-14 23:43:46 -07:00
Kubernetes Prow Robot e743e1da5d Merge pull request #29402 from Arhell/fix
[fr] Fix list all uniq container images
2021-08-14 23:21:46 -07:00
Kubernetes Prow Robot 7ffc6b7598 Merge pull request #29404 from ysharma-dev/patch-1
Update label in NetworkPolicy example explanation
2021-08-14 23:11:46 -07:00
Yug 6c2ff6340e Update label in NetworkPolicy example description
This change intends to fix the label name in the range of ports NetworkPolicy example.
2021-08-14 22:28:25 -07:00
Kubernetes Prow Robot 1866c7e45a Merge pull request #29395 from Patil2099/link-fix
[ko]Fix: Wrong href to heading anchor
2021-08-14 21:45:46 -07:00
Anubhav Vardhan 59c601671a Create explore-interactive.html 2021-08-15 09:55:08 +05:30
Arhell d2151f2dea [fr] Fix list all uniq container images 2021-08-15 02:31:25 +03:00
Anubhav Vardhan 1f6603dd4b Create _index.md 2021-08-14 22:05:16 +05:30
Pankaj Patil ca1e53b826 [ko]Fix: Wrong href to heading anchor 2021-08-14 20:29:55 +05:30
Kubernetes Prow Robot 677c6edc1b Merge pull request #29373 from anubha-v-ardhan/Hi-content-hi-docs-landing
[hi] Add content/hi/docs/_index.md
2021-08-14 04:47:45 -07:00
Kubernetes Prow Robot 92de2a70a0 Merge pull request #29224 from sftim/20210804_update_node_concept
Update the node concept
2021-08-13 14:27:31 -07:00
EricWvi d1a502072e [zh] Concept files to sync for 1.22 - (8) Service 2021-08-13 18:12:06 +08:00
Anubhav Vardhan 078985f2a7 Create _index.md 2021-08-13 14:35:14 +05:30
Anubhav Vardhan 5962a5e939 Create _index.md 2021-08-13 13:39:43 +05:30
Maciej Filocha 9314e3be28 Synchronize Polish localization for ver 1.22, part 2
Synchronize Polish localization with upstream
up to 08d92f9137. Part 2
2021-08-13 09:36:31 +02:00
Manish Kumar d55d770365 Removed reference for broken link 2021-08-13 12:54:47 +05:30
Jim Angel d5de9efdb6 updating co-chairs 2021-08-13 06:39:39 +00:00
Kunal Verma 3a0268eb2c Update supported-doc-versions.md 2021-08-13 11:34:22 +05:30
Kubernetes Prow Robot f095b4bdb4 Merge pull request #29248 from sdghchj/patch-1
Correct wrongly written characters
2021-08-12 20:10:21 -07:00
Kubernetes Prow Robot f2de2a50a5 Merge pull request #29297 from mengjiao-liu/update_apiservice_link_to_api_reference
[zh] Link to new API reference page for APIService
2021-08-12 20:08:21 -07:00
Kubernetes Prow Robot 99b8818db9 Merge pull request #29336 from arugal/patch-1
Modify kubelet-integration page typo
2021-08-12 20:04:22 -07:00
Kubernetes Prow Robot 2805a8762f Merge pull request #29352 from Arhell/list
[id] Fix list all uniq container images
2021-08-12 17:24:58 -07:00
Arhell 74d7ad3118 [id] Fix list all uniq container images 2021-08-13 02:13:25 +03:00
Wesley Williams 41aa2ba727 Revert chinese changes 2021-08-12 22:48:50 +01:00
Kubernetes Prow Robot a33eb6b4c3 Merge pull request #28919 from niteshseram/fix/redirect
Fixing redirection rules with wildcard(*)
2021-08-12 10:05:48 -07:00
Kubernetes Prow Robot 96069e6a32 Merge pull request #28607 from kahirokunn/patch-1
fix: k8s dashboard link.
2021-08-12 08:23:48 -07:00
Kubernetes Prow Robot c7c8027225 Merge pull request #29323 from dgrisonnet/new-events-api
Update recommended events API
2021-08-12 06:29:47 -07:00
Kubernetes Prow Robot d621a66ca5 Merge pull request #29006 from niteshseram/fix/sidebar
fixing the huge whitespace in sidebar
2021-08-12 06:27:47 -07:00
Mengjiao Liu 29ff83785e [zh] Link to new API reference page for APIService 2021-08-12 17:44:18 +08:00
Maciej Filocha 49d64fc388 Synchronize Polish localization for ver 1.22, part 1
Synchronize Polish localization with upstream
up to 08d92f9137. Part 1
2021-08-12 09:51:46 +02:00
Maciej Filocha c07cd04894 Update Polish localization of the home page
Update Polish localization of the main index page
up to 08d92f9137.
2021-08-12 09:09:00 +02:00
zhang-wei 7b0ca655ce fix typo 2021-08-12 14:51:19 +08:00
Kubernetes Prow Robot 08d92f9137 Merge pull request #29171 from ehashman/update-node-perf
Note deprecation of the node performance dashboard
2021-08-11 22:57:47 -07:00
Kubernetes Prow Robot 9383dd8cd0 Merge pull request #28958 from rajula96reddy/memory-manager
Add memory manager moves to beta feature blog post 1.22
2021-08-11 06:16:47 -07:00
Rajula Vineet Reddy a783b05eb2 Add memory manager feature blog post
Co-authored-by: Artyom Lukianov <alukiano@redhat.com>
Co-authored-by: Cezary Zukowski <c.zukowski@samsung.com>
2021-08-11 16:01:22 +03:00
Kubernetes Prow Robot 7c2e229f60 Merge pull request #29236 from reylejano/add-kubewarden-option
Add kubewarden as an alternative to enforce security profiles
2021-08-11 05:26:47 -07:00
Qiming Teng 735701e1cc Amend kubeadm join doc for node preparation
We need to clarify that worker nodes need to be prepared in nearly the
same way as control plane nodes.
2021-08-11 20:10:11 +08:00
Damien Grisonnet 923b2e25f2 kubernetes-api: update recommended events API
In Kubernetes v1.19, the new Events API events.k8s.io was promoted to
v1. As such it now supersedes the original core Events API.

Signed-off-by: Damien Grisonnet <dgrisonn@redhat.com>
2021-08-11 13:02:59 +02:00
Damien Grisonnet 8773d024e7 api-ref-generator: update to include Event changes
Update api-ref-generator submodule to 55bce68 to include changes
updating the recommended Events API from core to events.k8s.io in the
kubernetes-api doc.

Signed-off-by: Damien Grisonnet <dgrisonn@redhat.com>
2021-08-11 13:02:59 +02:00
Tim Bannister 1b8eeb500a Update the node concept
Modernise the page by:
- rewording to follow the style guide
- adding some glossary tooltips
- linking to new-style API reference
- linking to Safely Drain a Node

plus general tweaks.
2021-08-11 11:58:18 +01:00
Kubernetes Prow Robot dd14c2208c Merge pull request #29247 from sanmai/patch-1
Update Managing Resources to mention the measure of CPU time
2021-08-11 03:34:46 -07:00
Alexey Kopytko 9ca04a1014 Update Managing Resources to mention the measure of CPU time 2021-08-11 18:30:33 +09:00
Kubernetes Prow Robot de92339f81 Merge pull request #29229 from sftim/20210804_update_api_aggregation_layer
Retitle “Kubernetes API Aggregation Layer” concept
2021-08-10 18:46:46 -07:00
Kubernetes Prow Robot a78da7908b Merge pull request #29301 from tengqm/fix-go-mod-122
Update go.mod for 1.22
2021-08-10 18:10:46 -07:00
Kubernetes Prow Robot 4097fca5e7 Merge pull request #29205 from sftim/20210803_improve_katacoda_button
Improve Katacoda button
2021-08-10 18:08:46 -07:00
Edith b6dc198148 grammar error second update 2021-08-10 17:16:52 -05:00
Arhell c1785d2dd9 [fr] Deleted reference to removed file 2021-08-11 00:42:28 +03:00
Edith 5c760918bb Merge branch 'main' of https://github.com/kubernetes/website into add-content/es/docs/concepts/storage/volume-snapshot-classes 2021-08-10 14:52:21 -05:00
Edith 90c1306da5 fixing grammar errors 2021-08-10 14:37:22 -05:00
Edith Puclla 382766070a Update content/es/docs/concepts/storage/volume-snapshot-classes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-10 12:36:28 -05:00
Rey Lejano 08387d8434 add kubewarden as an alternative to enforce security profiles
add third-party content shortcode and list
2021-08-10 07:41:30 -07:00
Kubernetes Prow Robot 5703199613 Merge pull request #29282 from kendfinger/patch-1
Fix double usage of "simplify the process" in kubelet-tls-bootstrapping.
2021-08-10 06:05:18 -07:00
Kubernetes Prow Robot 7331e54c09 Merge pull request #28623 from chenxuc/staticPod
static pod not support configmap or secret
2021-08-10 03:23:17 -07:00
Mengjiao Liu f945335af6 Hard-code the name of the target repo's default branch instead of using the githubbranch parameter value 2021-08-10 18:03:21 +08:00
Hoon Jo 11c7b70b41 Update web-ui-dashboard.md
I rquest to update dashboard/v2.3.1 from v2.2.0

Refer to below 
https://github.com/kubernetes/dashboard
2021-08-10 18:51:23 +09:00
Kubernetes Prow Robot 5f65b4fcd0 Merge pull request #28853 from saschagrunert/seccomp-index
Add seccomp tutorial to index
2021-08-10 02:27:17 -07:00
Kubernetes Prow Robot 20890d53b7 Merge pull request #29304 from hokadiri/patch-1
Update safely-drain-node.md
2021-08-10 02:11:18 -07:00
Kubernetes Prow Robot da11af4bbe Merge pull request #29271 from yuswift/update-ssa
update server-side-apply state to stable
2021-08-10 02:09:17 -07:00
yuswift 00c205bc38 update ssa state to stable
Signed-off-by: yuswift <yuswift2018@gmail.com>
2021-08-10 15:47:50 +08:00
Kubernetes Prow Robot 2fbd6ceded Merge pull request #28879 from Shubham82/correct-FQDN_for_dockerhub
Correct FQDN for DockerHub.
2021-08-10 00:35:20 -07:00
Kubernetes Prow Robot e68dc3c075 Merge pull request #28736 from chenxuc/hello-minikube-2
improve hello-minikube page for dashboard
2021-08-10 00:23:19 -07:00
Kubernetes Prow Robot 67eca4178c Merge pull request #28461 from sftim/20210617_improve_make_generate_ref_docs
Improve docs about contributing upstream for generated content
2021-08-10 00:15:19 -07:00
Kubernetes Prow Robot a80328f582 Merge pull request #29295 from mfilocha/fix/rbac-links
Fix links in RBAC default bindings table
2021-08-09 20:37:17 -07:00
Jonathan Lopez Torres c7ee95a654 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:40:55 -05:00
Jonathan Lopez Torres 7a42e5f4b9 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:38:34 -05:00
Jonathan Lopez Torres 76a7e06889 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:38:27 -05:00
Jonathan Lopez Torres 2b00cbf773 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:38:18 -05:00
Jonathan Lopez Torres a6170c1738 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:38:08 -05:00
Jonathan Lopez Torres dd9c4dc83d Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:37:43 -05:00
Jonathan Lopez Torres 65827fd94e Update deployment.md 2021-08-09 20:47:45 -05:00
Jonathan Lopez Torres 317c56cf00 Modificación de salida de deployment 2021-08-09 20:45:51 -05:00
Kubernetes Prow Robot 2bc25c1496 Merge pull request #29275 from tengqm/zh-move-pod-priority-preemption
Drop leftover pod-priority-preemption page
2021-08-09 18:45:17 -07:00
Kubernetes Prow Robot 409a5ef110 Merge pull request #29105 from mauriciopoppe/feature-blogpost-csi-windows-support
[Feature blogpost][1.22] CSI Windows Support with CSI Proxy reaches GA
2021-08-09 11:05:10 -07:00
Mauricio Poppe 57e7b781f2 Update blogpost release date to 2021-08-09 2021-08-09 17:28:34 +00:00
Kubernetes Prow Robot 3e4fc78b51 Merge pull request #29060 from ehashman/swap-blog
1.22 feature blog for alpha swap support
2021-08-09 10:21:32 -07:00
Kubernetes Prow Robot 9c7c238efe Merge pull request #29270 from davidmlentz/patch-2
Fix typo
2021-08-09 09:55:31 -07:00
Kubernetes Prow Robot a78a812311 Merge pull request #29299 from Shubham82/fix_broken_link-webhook.go
Fix the broken link for "webhook.go"
2021-08-09 09:53:32 -07:00
Tim Bannister 39e39c0d02 Move node swap post-release article sooner 2021-08-09 17:48:51 +01:00
Hussein Kadiri e6082aca98 Update safely-drain-node.md 2021-08-09 09:37:05 -07:00
Qiming Teng 1846afe3d5 Fix test case for examples
This is an adaptation for 1.22.
2021-08-09 22:29:17 +08:00
Qiming Teng f805b98659 Update go.mod for 1.22 2021-08-09 22:15:28 +08:00
Kubernetes Prow Robot 302743eb9d Merge pull request #28363 from RA489/update_init
Update activeDeadlineSeconds with Pod page
2021-08-09 07:01:31 -07:00
Kubernetes Prow Robot 34ab657265 Merge pull request #29296 from mengjiao-liu/fix-Selector-yaml
[zh] Fix `selector` expect map not string
2021-08-09 06:57:31 -07:00
Kubernetes Prow Robot 58d9f81010 Merge pull request #29268 from cpanato/update-patch
Update patch schedule and add 1.22 to the party
2021-08-09 06:55:31 -07:00
Shubham Kuchhal bdb4cc4603 Fix the broken link for "webhook.go" 2021-08-09 16:17:06 +05:30
Mengjiao Liu bbc82ea1f2 [zh] Fix selector expect map not string and sync horizontal-pod-autoscale-walkthrough.md file 2021-08-09 18:12:14 +08:00
Maciej Filocha 647e9d6ca8 Fix links in RBAC default bindings table
An extra line needs to be added to allow
the link to be rendered properly.
Also reformatting link line to be better readable.
2021-08-09 12:09:29 +02:00
Carlos Panato fafe6d1e9f patch releases: add 1.22 release to the schedule
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-08-09 11:22:30 +02:00
Kubernetes Prow Robot 91d71e812b Merge pull request #29285 from tengqm/kubectl-122
Update kubectl reference for 1.22
2021-08-09 01:41:30 -07:00
Kubernetes Prow Robot 459d007b9a Merge pull request #29276 from Arhell/delete
[ru] Deleted reference to removed file
2021-08-08 23:45:30 -07:00
Kubernetes Prow Robot 45f539517c Merge pull request #29203 from kerthcet/patch-1
fix punctuation mistyped
2021-08-08 20:47:30 -07:00
Kubernetes Prow Robot aa86cfbe42 Merge pull request #29284 from tengqm/update-kubelet-ref
Update reference for kubelet
2021-08-08 20:07:30 -07:00
Kubernetes Prow Robot 90f2d903fb Merge pull request #29250 from jalagari/main
Selector expect map not string
2021-08-08 13:37:30 -07:00
Dima Brusilovsky 91f4f4adf7 Update custom-resource-definition-versioning.md 2021-08-08 18:47:19 +03:00
kerthcet 8ed0b0fd6d keep the document in sync with deprecation of Dynamic Kubelet Configuration in releasev1.22
Signed-off-by: kerthcet <kerthcet@gmail.com>
2021-08-08 21:26:36 +08:00
Sayantani Saha ee245ff73e Added announcements of KubeCon NA & China (#29192)
* Added announcements of KubeCon NA & China

* svg images added & required changes made

* Requested changes made

* svg images fixed

* small correction required

* added the to the message

* small correction

* Netlify build error fixed
2021-08-08 06:01:30 -07:00
Qiming Teng a6a5d359e5 Update kubectl reference for 1.22 2021-08-08 20:49:16 +08:00
Qiming Teng f45f67739e Update reference for kubelet
The kubelet reference is not auto-generated. This PR is about fixing the
outdated information by manually comparing the reference against the
output from `kubelet --help`.
2021-08-08 19:59:56 +08:00
Kenneth Endfinger f805b220d8 Fix double usage of "simplify the process" in kubelet-tls-bootstrapping. 2021-08-08 01:56:17 -07:00
Arhell 3cafc8c8a5 [ru] Deleted reference to removed file 2021-08-08 11:38:24 +03:00
Kubernetes Prow Robot 9e8003a66e Merge pull request #29184 from Arhell/fixes
[ja] Fix typo in worker.py example script
2021-08-07 08:39:29 -07:00
Kubernetes Prow Robot 7321fd9496 Merge pull request #29091 from mengjiao-liu/fix-secret-name-ja
[ja] Fix secret name to be consistent with examples
2021-08-07 08:37:29 -07:00
Kubernetes Prow Robot 82e7858daa Merge pull request #29174 from Arhell/link
[ja] update link to Flannel
2021-08-07 08:35:30 -07:00
Kubernetes Prow Robot 47124c83b1 Merge pull request #29023 from Arhell/operator
[ja] Operator: Exists missing
2021-08-07 08:33:29 -07:00
Qiming Teng d711ae1874 [zh] Translate production environment 2021-08-07 19:23:48 +08:00
Qiming Teng bbb3ba317a Drop left over pod-priority-preemption page
When attempting to keep the localized sites well synced to the English
upstream, some files were found MOVED. It is difficult to detect such
changes. This PR removes a file that were localized twice.
2021-08-07 10:31:55 +08:00
Elana Hashman cb0d216f72 Add alpha swap support blog 2021-08-06 12:07:05 -07:00
Mauricio Poppe 9f30588101 Non-critical updates from feedback 2021-08-06 17:14:04 +00:00
yuswift 4e06971871 update ssa state to ga
Signed-off-by: yuswift <yuswift2018@gmail.com>
2021-08-06 22:17:24 +08:00
Kubernetes Prow Robot b5c1e98957 Merge pull request #29241 from YuikoTakada/fix_relative_paths
Replace with relative path
2021-08-06 06:51:19 -07:00
Kubernetes Prow Robot 7ea180d688 Merge pull request #29269 from mozillazg/patch-1
Fix a broken link
2021-08-06 06:47:20 -07:00
David M. Lentz e47fba2b92 Fix typo 2021-08-06 07:46:25 -06:00
Kubernetes Prow Robot 76fc52c75b Merge pull request #29256 from zhangguanzhang/invalid-ref
[zh] docs: sync and update the ref
2021-08-06 06:45:20 -07:00
zhangguanzhang 229cdb70b9 [zh] docs: sync and update the ref
Signed-off-by: zhangguanzhang <zhangguanzhang@qq.com>
2021-08-06 20:48:24 +08:00
Huang Huang 11a2e54d7a Fix a broken link 2021-08-06 20:42:30 +08:00
Carlos Panato 555801a38b move cherry-pick deadline to a Friday, was on Saturday
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-08-06 12:35:46 +02:00
Kubernetes Prow Robot 84e5a82364 Merge pull request #29267 from Arhell/typo
[zh] fix typo
2021-08-06 02:31:20 -07:00
Arhell f39fdce207 [zh] fix typo 2021-08-06 03:13:52 +03:00
Kubernetes Prow Robot 60de38d64f Merge pull request #29251 from sftim/20210805_link_to_v1.22_release
Link to v1.22 release announcement from removals article
2021-08-05 16:27:55 -07:00
Kubernetes Prow Robot b24deab7fa Merge pull request #29228 from sftim/20210804_update_apiservice_link_to_api_reference
Link to new API reference page for APIService
2021-08-05 15:19:41 -07:00
deepsan 788b9ce132 Reword Go requirement for Aggregated API
Given 'Aggregated APIs are subordinate API servers that sit behind the primary API server, which acts as a proxy', the comparison table indicates a requirement for the subordinate API servers to use Go, when it is not a requirement as long as the subordinate API server follows the expected contract
2021-08-05 15:07:43 -07:00
Kubernetes Prow Robot 0b09d3ecc5 Merge pull request #29230 from sftim/20210804_update_link_from_secret_concept_to_api
Update links from Secret concept to relevant API reference
2021-08-05 15:07:41 -07:00
Kubernetes Prow Robot c91e60ce01 Merge pull request #29231 from sftim/20210804_update_link_to_api_reference_working_with_objects
Update link from Working With Objects to Kubernetes API Reference
2021-08-05 14:23:41 -07:00
Kubernetes Prow Robot ad3319300f Merge pull request #29232 from sftim/2021084_update_links_to_api_reference_pv
Link from PV / PVC concept to new API reference
2021-08-05 13:47:19 -07:00
Kubernetes Prow Robot c0612021dd Merge pull request #29233 from sftim/20210804_update_link_to_api_reference_init_containers
Update init containers concept to link to new API reference
2021-08-05 13:29:20 -07:00
Kubernetes Prow Robot 0525ee9a1f Merge pull request #29244 from niteshseram/glossary
Adding Eviction to glossary
2021-08-05 13:05:19 -07:00
Kubernetes Prow Robot fc50bd55f5 Merge pull request #29265 from renato1891/patch-1
fix small grammatical error in operator.md
2021-08-05 12:21:19 -07:00
Renato B. Boaventura f2e2995d23 fix small grammatical error in operator.md
"una falha..." -> "uma falha..."
2021-08-05 15:40:29 -03:00
Elana Hashman b480f0fb53 Note deprecation of the node performance dashboard 2021-08-05 11:03:09 -07:00
Mauricio Poppe 02ebc799d7 Change publish date to 2021-08-05 2021-08-05 16:16:40 +00:00
Mauricio Poppe 4bcfded6d8 Moved section about alpha APIs to be along the APIs that are reaching v1 2021-08-05 16:13:50 +00:00
Mauricio Poppe 0398ce4e27 Keep some sentences in third person 2021-08-05 16:13:50 +00:00
Mauricio Poppe 8dcebae500 Explain work done in PD CSI in more detail, add statement for the system API 2021-08-05 16:13:50 +00:00
Mauricio Poppe 111b8032e0 Feature blogpost: CSI Windows support with CSI Proxy reaches GA 2021-08-05 16:13:50 +00:00
Kubernetes Prow Robot 9ebb504c7a Merge pull request #29262 from haugenj/patch-1
fix small grammatical error in kube-scheduler.md
2021-08-05 08:41:22 -07:00
Kubernetes Prow Robot e2b4e2644c Merge pull request #29243 from tengqm/configapi-122
Config API for 1.22
2021-08-05 08:15:22 -07:00
Kubernetes Prow Robot a1c346fd16 Merge pull request #29242 from tengqm/compref-122
Update generated component reference docs for 1.22
2021-08-05 08:09:22 -07:00
Jason Haugen 1b8686e66a Update kube-scheduler.md
fix a small grammatical error
2021-08-05 09:18:38 -05:00
Tim Bannister cd44e2757f Link to v1.22 release announcement from removals article 2021-08-05 11:53:21 +01:00
Vijay Kumar Jalagari 2eda36ea27 Selector expect map not string
If we using string then k8s api is throwing validation error
``` (HorizontalPodAutoscaler.spec.metrics[0].object.metric.selector): invalid type for io.k8s.apimachinery.pkg.apis.meta.v1.LabelSelector: got "string", expected "map"; if you choose to ignore these errors, turn validation off with --validate=false ```
2021-08-05 16:10:36 +05:30
Kubernetes Prow Robot 708cc9a5fe Merge pull request #29216 from danwinship/ipblock-selectors
Add a manual anchor to an interesting spot in the NetworkPolicy docs
2021-08-05 03:25:22 -07:00
jmyung 7a746df1a5 Add jmyung to sig-docs-ko-reviews 2021-08-05 18:59:08 +09:00
sdghchj f21e99e8e7 Update service-accounts-admin.md 2021-08-05 15:29:34 +08:00
S Nitesh Singh 1230f21648 add eviction to glossary 2021-08-05 10:30:26 +05:30
Qiming Teng f51ed0569d Config API for 1.22 2021-08-05 12:50:28 +08:00
Yuiko Mouri 8f301ea379 Replace with relative path 2021-08-05 11:54:46 +09:00
Qiming Teng 8acf5d121e Component reference for 1.22 2021-08-05 09:44:17 +08:00
Tim Bannister 191c2bf4ee Pick example versions based on current release 2021-08-04 23:12:25 +01:00
Tim Bannister 142177068b Refer to the “default” rather than “master” branch
Get ready for a switch to "main"
2021-08-04 23:12:25 +01:00
Tim Bannister c1feea756f Update init containers concept to link to new API reference 2021-08-04 22:58:42 +01:00
Tim Bannister 1b3125353d Link from PV / PVC concept to new API reference 2021-08-04 22:52:27 +01:00
Tim Bannister cba4f57124 Update link from Working With Objects to Kubernetes API Reference 2021-08-04 22:42:14 +01:00
Tim Bannister 97c35ce770 Update links from Secret concept to relevant API reference 2021-08-04 22:35:56 +01:00
Tim Bannister 075fdf2e37 Retitle “Kubernetes API Aggregation Layer” concept
The old title “Extending the Kubernetes API with the aggregation layer”
sounds more like a task page than a concept, so I reworded.
2021-08-04 22:28:54 +01:00
Tim Bannister 1ca5ecbf77 Link to new API reference page for APIService 2021-08-04 22:25:12 +01:00
Tedley Meralus de80496fcf fixed small typo
changed uprate to upgrade on line 12
2021-08-04 17:11:28 -04:00
Dan Winship 5a8bd9216a Add a manual anchor to an interesting spot in the NetworkPolicy docs 2021-08-04 11:50:21 -04:00
Tim Bannister e3b6ab9579 Improve Katacoda button
Separate out the HTML <div> for Katacoda from the in-page button to
trigger it.
2021-08-03 14:31:38 +01:00
Edith b3062eb517 Add concepts/storage/volume-snapshot-classes.md 2021-08-02 23:53:45 -05:00
Naka Masato 3bef97644c Update object-management.md 2021-08-02 22:52:13 +09:00
Arhell 473c228985 [ja] Fix typo in worker.py example script 2021-08-02 01:06:00 +03:00
edsoncelio fe63395af0 feat: fix typos requested by code review 2021-07-31 15:09:11 -03:00
NamikoToriyama 359d239a65 Fix a non-existent link
Signed-off-by: NamikoToriyama <namiko.trym@gmail.com>
2021-08-01 02:22:23 +09:00
Arhell 506dc498ab [ja] update link to Flannel 2021-07-31 14:30:09 +03:00
RA489 7f9d3e3f90 Update activeDeadlineSeconds with Pod page 2021-07-30 16:11:31 +05:30
chenxuc f4e6b41840 improve hello-minikube page for dashboard 2021-07-28 16:26:27 +08:00
kartik494 c7a44f14ea Modify documentation for stablestorage 2021-07-28 09:37:42 +05:30
Maciej Filocha a17e7b61be Update Polish README file
Update Polish translation of main README file.

Synced up to 9c7d7dcdf6.
2021-07-27 10:47:30 +02:00
chenxuc 8c9c9c543c static pod not support configmap or secret 2021-07-27 14:51:45 +08:00
Tim Bannister 39f2c3860d Reword “Create an External Load Balancer” task
- general cleanup
- update sample output
- use more tooltips
- avoid specifying specific cloud providers

The website repo doesn't maintain a definitive list of cloud providers that
pass Kubernetes conformance tests. It's certainly more than AWS and GCP as
the previous revision stated.
2021-07-24 02:19:40 +01:00
Mengjiao Liu b7ec60a564 [ja] Fix secret name to be consistent with examples 2021-07-23 10:35:50 +08:00
Ritikaa96 cee22da0c3 updating cilium network policy docs 2021-07-22 19:34:39 +05:30
able.lv 875cb1a3d7 fix typos ja 2021-07-20 23:27:07 +08:00
sgpinkus 05a45db49c Update _index.md
"Understand the basics" to "Understand Kubernetes". There is no place in the entire docs really to go "Understand the *non* basics". There is one section "Concepts" for better or worse. Don't give the impression there is something else somewhere else. And anyway, this section should aspire to be that cardinal. Also change name of weird button to "Learn" -> "View" to make it clear this is just a link to a section of the documentation.
2021-07-20 21:47:16 +10:00
Arhell e8340128d9 [ja] Operator: Exists missing 2021-07-20 00:51:54 +03:00
kartik494 4270ece858 Modify documentation for stable storage 2021-07-19 15:56:27 +05:30
S Nitesh Singh b1fa203e3a fixing the huge white space in sidebar 2021-07-19 11:13:18 +05:30
Wesley Williams 723b94de50 Clarify that burstable pods also have their limit enforced by CFS quota 2021-07-16 18:10:38 +01:00
Nitesh Seram 2c360ea3c6 fixing redirect and chnaging some links in blog
fixing redirects

Fixing few redirects

changing few redirects and links

fixing redirect

Update content/en/blog/_posts/2016-08-00-Kubernetes-Namespaces-Use-Cases-Insights.md

Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>

Update content/en/blog/_posts/2016-12-00-Statefulset-Run-Scale-Stateful-Applications-In-Kubernetes.md

Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>

Update content/en/blog/_posts/2016-12-00-Statefulset-Run-Scale-Stateful-Applications-In-Kubernetes.md

Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>
2021-07-14 12:35:18 +05:30
Anubhav Vardhan 436d3fe8c4 Update content/en/docs/tasks/administer-cluster/highly-available-control-plane.md
Co-authored-by: chrismetz09 <cymetz@gmail.com>
2021-07-14 08:48:53 +05:30
edsoncelio 7a0c7cae46 fix: fix typo in doc title 2021-07-09 22:52:21 -03:00
edsoncelio 9822c9a4da feat: add configmap-secret translation 2021-07-09 15:12:29 -03:00
Shubham Kuchhal a3b120928d Correct FQDN for DockerHub. 2021-07-09 17:02:58 +05:30
Sascha Grunert 1134821af6 Add seccomp tutorial to index
This adds the seccomp tutorial page to the index side by side to
AppArmor.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2021-07-09 09:12:48 +02:00
Jihoon Seo f37de46d6d [ru] Update Netlify link address 2021-07-02 14:57:13 +09:00
Anubhav Vardhan 6cb9177e2b Update ha-control-plane.svg 2021-07-01 15:07:17 +05:30
Anubhav Vardhan 71507509b3 Update highly-available-control-plane.md 2021-07-01 14:47:28 +05:30
Anubhav Vardhan b9252e5982 Added ha-control-plane.svg 2021-07-01 14:33:55 +05:30
Zhang Yong 9bd06e292d Update URL for Metacontroller 2021-06-29 22:10:57 +08:00
kahirokunn e6271ef41b fix: k8s dashboard link.
k8s dashboard required https.
http does not currently have a corresponding endpoint.
So if you try to access it like this, you will get an error: "no endpoints available for service".
2021-06-24 21:54:12 +09:00
vaibhav dbcc1d550f Update the docs/setup/learning-environment/_index.md 2021-06-17 10:14:23 +05:30
vaibhav a16de9ee7a Comment the body in docs/setup/learning-environment/_index.md 2021-06-17 10:01:28 +05:30
olivierk 1661dbb435 fix typo _index.md
fix typo of a maj after a coma

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-25 11:35:24 +04:00
olivierk 59d526f55c _index.md fix typo maj
fix the typo of a maj on the first letter of a sentence

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-25 11:34:50 +04:00
olivierk 507f934707 Update content/fr/docs/concepts/workloads/_index.md
swap definition

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-20 14:31:40 +04:00
olivierk 1a25dc8e73 Update content/fr/docs/concepts/workloads/_index.md
Fix DaemonSet word, and sentence

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-20 14:27:53 +04:00
olivierk b2e8b6f913 Update content/fr/docs/concepts/workloads/_index.md
delete a non usefull space

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-20 14:27:27 +04:00
olivierk adf73902b7 Update content/fr/docs/concepts/workloads/_index.md
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-20 14:26:38 +04:00
edsoncelio 0a5d839101 Update task secret translation 2021-05-16 09:12:38 -03:00
olivierk 97475e7ba8 French translation of workloads page
Add the translated (french) page of the workload ressource.
2021-05-14 13:51:40 +04:00
Jai Govindani 2c82e7d6cf docs(manage-resources-containers): add volume and volumeMount for ephemeral storage
Signed-off-by: Jai Govindani <jai@honestbank.com>
2021-05-07 19:34:43 +07:00
edsoncelio 72267ac653 Add initial files to translate the secret task 2021-05-02 10:30:34 -03:00
Zhang Yong 1fb6685925 Fix line separation in concepts/architecture/nodes 2021-03-28 11:05:23 +08:00
554 changed files with 13925 additions and 11030 deletions
+2
View File
@@ -8,7 +8,9 @@ approvers:
emeritus_approvers:
# - chenopis, commented out to disable PR assignments
# - irvifa, commented out to disable PR assignments
# - jaredbhatti, commented out to disable PR assignments
# - kbarnard10, commented out to disable PR assignments
# - steveperry-53, commented out to disable PR assignments
- stewart-yu
# - zacharysarah, commented out to disable PR assignments
+7 -14
View File
@@ -1,10 +1,8 @@
aliases:
sig-docs-blog-owners: # Approvers for blog content
- kbarnard10
- onlydole
- mrbobbytables
sig-docs-blog-reviewers: # Reviewers for blog content
- kbarnard10
- mrbobbytables
- onlydole
- sftim
@@ -20,9 +18,8 @@ aliases:
- annajung
- bradtopol
- celestehorgan
- irvifa
- jimangel
- kbarnard10
- jlbutler
- kbhawkey
- onlydole
- pi-victor
@@ -35,7 +32,6 @@ aliases:
- celestehorgan
- daminisatya
- jimangel
- kbarnard10
- kbhawkey
- onlydole
- rajeshdeshpande02
@@ -76,19 +72,18 @@ aliases:
- anthonydahanne
- feloy
sig-docs-hi-owners: # Admins for Hindi content
- avidLearnerInProgress
- daminisatya
- anubha-v-ardhan
- divya-mohan0209
- mittalyashu
sig-docs-hi-reviews: # PR reviews for Hindi content
- avidLearnerInProgress
- daminisatya
- anubha-v-ardhan
- divya-mohan0209
- mittalyashu
sig-docs-id-owners: # Admins for Indonesian content
- ariscahyadi
- danninov
- girikuncoro
- habibrosyad
- irvifa
- phanama
- wahyuoi
sig-docs-id-reviews: # PR reviews for Indonesian content
@@ -96,7 +91,6 @@ aliases:
- danninov
- girikuncoro
- habibrosyad
- irvifa
- phanama
- wahyuoi
sig-docs-it-owners: # Admins for Italian content
@@ -133,14 +127,13 @@ aliases:
- gochist
- ianychoi
- jihoon-seo
- jmyung
- pjhwa
- seokho-son
- yoonian
- ysyukr
sig-docs-leads: # Website chairs and tech leads
- irvifa
- jimangel
- kbarnard10
- kbhawkey
- onlydole
- sftim
@@ -256,4 +249,4 @@ aliases:
- sethmccombs # Release Manager Associate
- thejoycekung # Release Manager Associate
- verolop # Release Manager Associate
- wilsonehusin # Release Manager Associate
- wilsonehusin # Release Manager Associate
+4 -2
View File
@@ -18,7 +18,7 @@ Aby móc skorzystać z tego repozytorium, musisz lokalnie zainstalować:
- [npm](https://www.npmjs.com/)
- [Go](https://golang.org/)
- [Hugo (Extended version)](https://gohugo.io/)
- Środowisko obsługi kontenerów, np. [Docker-a](https://www.docker.com/).
- Środowisko obsługi kontenerów, np. [Dockera](https://www.docker.com/).
Przed rozpoczęciem zainstaluj niezbędne zależności. Sklonuj repozytorium i przejdź do odpowiedniego katalogu:
@@ -43,7 +43,9 @@ make container-image
make container-serve
```
Aby obejrzeć zawartość serwisu otwórz w przeglądarce adres http://localhost:1313. Po każdej zmianie plików źródłowych, Hugo automatycznie aktualizuje stronę i odświeża jej widok w przeglądarce.
Jeśli widzisz błędy, prawdopodobnie kontener z Hugo nie dysponuje wystarczającymi zasobami. Aby rozwiązać ten problem, zwiększ ilość dostępnych zasobów CPU i pamięci dla Dockera na Twojej maszynie ([MacOSX](https://docs.docker.com/docker-for-mac/#resources) i [Windows](https://docs.docker.com/docker-for-windows/#resources)).
Aby obejrzeć zawartość serwisu, otwórz w przeglądarce adres http://localhost:1313. Po każdej zmianie plików źródłowych, Hugo automatycznie aktualizuje stronę i odświeża jej widok w przeglądarce.
## Jak uruchomić lokalną kopię strony przy pomocy Hugo?
+1 -1
View File
@@ -1,6 +1,6 @@
# Документация по Kubernetes
[![Netlify Status](https://api.netlify.com/api/v1/badges/be93b718-a6df-402a-b4a4-855ba186c97d/deploy-status)](https://app.netlify.com/sites/kubernetes-io-master-staging/deploys) [![GitHub release](https://img.shields.io/github/release/kubernetes/website.svg)](https://github.com/kubernetes/website/releases/latest)
[![Netlify Status](https://api.netlify.com/api/v1/badges/be93b718-a6df-402a-b4a4-855ba186c97d/deploy-status)](https://app.netlify.com/sites/kubernetes-io-main-staging/deploys) [![GitHub release](https://img.shields.io/github/release/kubernetes/website.svg)](https://github.com/kubernetes/website/releases/latest)
Данный репозиторий содержит все необходимые файлы для сборки [сайта Kubernetes и документации](https://kubernetes.io/). Мы благодарим вас за желание внести свой вклад!
-3
View File
@@ -4,8 +4,6 @@
Join the [kubernetes-security-announce] group for security and vulnerability announcements.
You can also subscribe to an RSS feed of the above using [this link][kubernetes-security-announce-rss].
## Reporting a Vulnerability
Instructions for reporting a vulnerability can be found on the
@@ -17,6 +15,5 @@ Information about supported Kubernetes versions can be found on the
[Kubernetes version and version skew support policy] page on the Kubernetes website.
[kubernetes-security-announce]: https://groups.google.com/forum/#!forum/kubernetes-security-announce
[kubernetes-security-announce-rss]: https://groups.google.com/forum/feed/kubernetes-security-announce/msgs/rss_v2_0.xml?num=50
[Kubernetes version and version skew support policy]: https://kubernetes.io/docs/setup/release/version-skew-policy/#supported-versions
[Kubernetes Security and Disclosure Information]: https://kubernetes.io/docs/reference/issues-security/security/#report-a-vulnerability
+1 -3
View File
@@ -1,6 +1,6 @@
# Defined below are the security contacts for this repo.
#
# They are the contact point for the Product Security Committee to reach out
# They are the contact point for the Security Response Committee to reach out
# to for triaging and handling of incoming issues.
#
# The below names agree to abide by the
@@ -10,7 +10,5 @@
# DO NOT REPORT SECURITY VULNERABILITIES DIRECTLY TO THESE NAMES, FOLLOW THE
# INSTRUCTIONS AT https://kubernetes.io/security/
irvifa
jimangel
kbarnard10
sftim
+5 -4
View File
@@ -30,8 +30,7 @@ pygmentsStyle = "emacs"
enableGitInfo = true
# Norwegian ("no") is sometimes but not currently used for testing.
# Hindi is disabled because it's currently in development.
disableLanguages = ["hi", "no"]
disableLanguages = ["no"]
[caches]
[caches.assets]
@@ -216,6 +215,8 @@ url = "https://v1-18.docs.kubernetes.io"
[params.ui]
# Enable to show the side bar menu in its compact state.
sidebar_menu_compact = false
# https://github.com/gohugoio/hugo/issues/8918#issuecomment-903314696
sidebar_cache_limit = 1
# Set to true to disable breadcrumb navigation.
breadcrumb_disable = false
# Set to true to hide the sidebar search box (the top nav search box will still be displayed if search is enabled)
@@ -426,8 +427,8 @@ language_alternatives = ["en"]
[languages.hi]
title = "Kubernetes"
description = "Production-Grade Container Orchestration"
languageName = "Hindi"
description = "प्रोडक्शन-ग्रेड कंटेनर ऑर्केस्ट्रेशन"
languageName = "हिन्दी"
weight = 11
contentDir = "content/hi"
languagedirection = "ltr"
@@ -5,7 +5,7 @@ weight: 20
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 20
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 10
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 20
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 10
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 20
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 10
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -125,7 +125,7 @@ You may wish to, but you cannot create a hierarchy of namespaces. Namespaces can
Namespaces are easy to create and use but its also easy to deploy code inadvertently into the wrong namespace. Good DevOps hygiene suggests documenting and automating processes where possible and this will help. The other way to avoid using the wrong namespace is to set a [kubectl context](/docs/user-guide/kubectl/kubectl_config_set-context/).&nbsp;
Namespaces are easy to create and use but its also easy to deploy code inadvertently into the wrong namespace. Good DevOps hygiene suggests documenting and automating processes where possible and this will help. The other way to avoid using the wrong namespace is to set a [kubectl context](/docs/reference/generated/kubectl/kubectl-commands#-em-set-context-em-).&nbsp;
@@ -5,6 +5,11 @@ slug: visualize-kubelet-performance-with-node-dashboard
url: /blog/2016/11/Visualize-Kubelet-Performance-With-Node-Dashboard
---
_Since this article was published, the Node Performance Dashboard was retired and is no longer available._
_This retirement happened in early 2019, as part of the_ `kubernetes/contrib`
_[repository deprecation](https://github.com/kubernetes-retired/contrib/issues/3007)_.
In Kubernetes 1.4, we introduced a new node performance analysis tool, called the _node performance dashboard_, to visualize and explore the behavior of the Kubelet in much richer details. This new feature will make it easy to understand and improve code performance for Kubelet developers, and lets cluster maintainer set configuration according to provided Service Level Objectives (SLOs).
**Background**
@@ -37,7 +37,7 @@ If you run your storage application on high-end hardware or extra-large instance
[ZooKeeper](https://zookeeper.apache.org/doc/current/) is an interesting use case for StatefulSet for two reasons. First, it demonstrates that StatefulSet can be used to run a distributed, strongly consistent storage application on Kubernetes. Second, it's a prerequisite for running workloads like [Apache Hadoop](http://hadoop.apache.org/) and [Apache Kakfa](https://kafka.apache.org/) on Kubernetes. An [in-depth tutorial](/docs/tutorials/stateful-application/zookeeper/) on deploying a ZooKeeper ensemble on Kubernetes is available in the Kubernetes documentation, and well outline a few of the key features below.
**Creating a ZooKeeper Ensemble**
Creating an ensemble is as simple as using [kubectl create](/docs/user-guide/kubectl/kubectl_create/) to generate the objects stored in the manifest.
Creating an ensemble is as simple as using [kubectl create](/docs/reference/generated/kubectl/kubectl-commands#create) to generate the objects stored in the manifest.
```
@@ -297,7 +297,7 @@ zk-0 0/1 Terminating 0 15m
You can use [kubectl apply](/docs/user-guide/kubectl/kubectl_apply/) to recreate the zk StatefulSet and redeploy the ensemble.
You can use [kubectl apply](/docs/reference/generated/kubectl/kubectl-commands#apply) to recreate the zk StatefulSet and redeploy the ensemble.
@@ -19,8 +19,9 @@ is that they have been superseded by a newer, stable (“GA”) API.
Kubernetes 1.22, due for release in August 2021, will remove a number of deprecated
APIs.
[Kubernetes 1.22 Release Information](https://www.kubernetes.dev/resources/release/)
has details on the schedule for the v1.22 release.
_Update_:
[Kubernetes 1.22: Reaching New Peaks](/blog/2021/08/04/kubernetes-1-22-release-announcement/)
has details on the v1.22 release.
## API removals for Kubernetes v1.22 {#api-changes}
@@ -140,7 +140,7 @@ In the v1.22 release cycle, which ran for 15 weeks (April 26 to August 4), we sa
# Upcoming release webinar
Join members of the Kubernetes 1.22 release team on September 7, 2021 to learn about the major features of this release, as well as deprecations and removals to help plan for upgrades. For more information and registration, visit the [event page](https://community.cncf.io/events/details/cncf-cncf-online-programs-presents-cncf-live-webinar-kubernetes-122-release/) on the CNCF Online Programs site.
Join members of the Kubernetes 1.22 release team on October 5, 2021 to learn about the major features of this release, as well as deprecations and removals to help plan for upgrades. For more information and registration, visit the [event page](https://community.cncf.io/events/details/cncf-cncf-online-programs-presents-cncf-live-webinar-kubernetes-122-release/) on the CNCF Online Programs site.
# Get Involved
@@ -0,0 +1,142 @@
---
layout: blog
title: 'New in Kubernetes v1.22: alpha support for using swap memory'
date: 2021-08-09
slug: run-nodes-with-swap-alpha
---
**Author:** Elana Hashman (Red Hat)
The 1.22 release introduced alpha support for configuring swap memory usage for
Kubernetes workloads on a per-node basis.
In prior releases, Kubernetes did not support the use of swap memory on Linux,
as it is difficult to provide guarantees and account for pod memory utilization
when swap is involved. As part of Kubernetes' earlier design, swap support was
considered out of scope, and a kubelet would by default fail to start if swap
was detected on a node.
However, there are a number of [use cases](https://github.com/kubernetes/enhancements/blob/9d127347773ad19894ca488ee04f1cd3af5774fc/keps/sig-node/2400-node-swap/README.md#user-stories)
that would benefit from Kubernetes nodes supporting swap, including improved
node stability, better support for applications with high memory overhead but
smaller working sets, the use of memory-constrained devices, and memory
flexibility.
Hence, over the past two releases, [SIG Node](https://github.com/kubernetes/community/tree/master/sig-node#readme) has
been working to gather appropriate use cases and feedback, and propose a design
for adding swap support to nodes in a controlled, predictable manner so that
Kubernetes users can perform testing and provide data to continue building
cluster capabilities on top of swap. The alpha graduation of swap memory
support for nodes is our first milestone towards this goal!
## How does it work?
There are a number of possible ways that one could envision swap use on a node.
To keep the scope manageable for this initial implementation, when swap is
already provisioned and available on a node, [we have proposed](https://github.com/kubernetes/enhancements/blob/9d127347773ad19894ca488ee04f1cd3af5774fc/keps/sig-node/2400-node-swap/README.md#proposal)
the kubelet should be able to be configured such that:
- It can start with swap on.
- It will direct the Container Runtime Interface to allocate zero swap memory
to Kubernetes workloads by default.
- You can configure the kubelet to specify swap utilization for the entire
node.
Swap configuration on a node is exposed to a cluster admin via the
[`memorySwap` in the KubeletConfiguration](/docs/reference/config-api/kubelet-config.v1beta1/).
As a cluster administrator, you can specify the node's behaviour in the
presence of swap memory by setting `memorySwap.swapBehavior`.
This is possible through the addition of a `memory_swap_limit_in_bytes` field
to the container runtime interface (CRI). The kubelet's config will control how
much swap memory the kubelet instructs the container runtime to allocate to
each container via the CRI. The container runtime will then write the swap
settings to the container level cgroup.
## How do I use it?
On a node where swap memory is already provisioned, Kubernetes use of swap on a
node can be enabled by enabling the `NodeSwap` feature gate on the kubelet, and
disabling the `failSwapOn` [configuration setting](/docs/reference/config-api/kubelet-config.v1beta1/#kubelet-config-k8s-io-v1beta1-KubeletConfiguration)
or the `--fail-swap-on` command line flag.
You can also optionally configure `memorySwap.swapBehavior` in order to
specify how a node will use swap memory. For example,
```yaml
memorySwap:
swapBehavior: LimitedSwap
```
The available configuration options for `swapBehavior` are:
- `LimitedSwap` (default): Kubernetes workloads are limited in how much swap
they can use. Workloads on the node not managed by Kubernetes can still swap.
- `UnlimitedSwap`: Kubernetes workloads can use as much swap memory as they
request, up to the system limit.
If configuration for `memorySwap` is not specified and the feature gate is
enabled, by default the kubelet will apply the same behaviour as the
`LimitedSwap` setting.
The behaviour of the `LimitedSwap` setting depends if the node is running with
v1 or v2 of control groups (also known as "cgroups"):
- **cgroups v1:** Kubernetes workloads can use any combination of memory and
swap, up to the pod's memory limit, if set.
- **cgroups v2:** Kubernetes workloads cannot use swap memory.
### Caveats
Having swap available on a system reduces predictability. Swap's performance is
worse than regular memory, sometimes by many orders of magnitude, which can
cause unexpected performance regressions. Furthermore, swap changes a system's
behaviour under memory pressure, and applications cannot directly control what
portions of their memory usage are swapped out. Since enabling swap permits
greater memory usage for workloads in Kubernetes that cannot be predictably
accounted for, it also increases the risk of noisy neighbours and unexpected
packing configurations, as the scheduler cannot account for swap memory usage.
The performance of a node with swap memory enabled depends on the underlying
physical storage. When swap memory is in use, performance will be significantly
worse in an I/O operations per second (IOPS) constrained environment, such as a
cloud VM with I/O throttling, when compared to faster storage mediums like
solid-state drives or NVMe.
Hence, we do not recommend the use of swap for certain performance-constrained
workloads or environments. Cluster administrators and developers should
benchmark their nodes and applications before using swap in production
scenarios, and [we need your help](#how-do-i-get-involved) with that!
## Looking ahead
The Kubernetes 1.22 release introduces alpha support for swap memory on nodes,
and we will continue to work towards beta graduation in the 1.23 release. This
will include:
* Adding support for controlling swap consumption at the Pod level via cgroups.
* This will include the ability to set a system-reserved quantity of swap
from what kubelet detects on the host.
* Determining a set of metrics for node QoS in order to evaluate the
performance and stability of nodes with and without swap enabled.
* Collecting feedback from test user cases.
* We will consider introducing new configuration modes for swap, such as a
node-wide swap limit for workloads.
## How can I learn more?
You can review the current [documentation](https://kubernetes.io/docs/concepts/architecture/nodes/#swap-memory)
on the Kubernetes website.
For more information, and to assist with testing and provide feedback, please
see [KEP-2400](https://github.com/kubernetes/enhancements/issues/2400) and its
[design proposal](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/2400-node-swap/README.md).
## How do I get involved?
Your feedback is always welcome! SIG Node [meets regularly](https://github.com/kubernetes/community/tree/master/sig-node#meetings)
and [can be reached](https://github.com/kubernetes/community/tree/master/sig-node#contact)
via [Slack](https://slack.k8s.io/) (channel **#sig-node**), or the SIG's
[mailing list](https://groups.google.com/forum/#!forum/kubernetes-sig-node).
Feel free to reach out to me, Elana Hashman (**@ehashman** on Slack and GitHub)
if you'd like to help.
@@ -0,0 +1,76 @@
---
layout: blog
title: 'Kubernetes 1.22: CSI Windows Support (with CSI Proxy) reaches GA'
date: 2021-08-09
slug: csi-windows-support-with-csi-proxy-reaches-ga
---
**Authors:** Mauricio Poppe (Google), Jing Xu (Google), and Deep Debroy (Apple)
*The stable version of CSI Proxy for Windows has been released alongside Kubernetes 1.22. CSI Proxy enables CSI Drivers running on Windows nodes to perform privileged storage operations.*
## Background
Container Storage Interface (CSI) for Kubernetes went GA in the Kubernetes 1.13 release. CSI has become the standard for exposing block and file storage to containerized workloads on Container Orchestration systems (COs) like Kubernetes. It enables third-party storage providers to write and deploy plugins without the need to alter the core Kubernetes codebase. Legacy in-tree drivers are deprecated and new storage features are introduced in CSI, therefore it is important to get CSI Drivers to work on Windows.
A CSI Driver in Kubernetes has two main components: a controller plugin which runs in the control plane and a node plugin which runs on every node.
- The controller plugin generally does not need direct access to the host and can perform all its operations through the Kubernetes API and external control plane services.
- The node plugin, however, requires direct access to the host for making block devices and/or file systems available to the Kubernetes kubelet. Due to the missing capability of running privileged operations from containers on Windows nodes [CSI Proxy was introduced as alpha in Kubernetes 1.18](https://kubernetes.io/blog/2020/04/03/kubernetes-1-18-feature-windows-csi-support-alpha/) as a way to enable containers to perform privileged storage operations. This enables containerized CSI Drivers to run on Windows nodes.
## What's CSI Proxy and how do CSI drivers interact with it?
When a workload that uses persistent volumes is scheduled, it'll go through a sequence of steps defined in the [CSI Spec](https://github.com/container-storage-interface/spec/blob/master/spec.md). First, the workload will be scheduled to run on a node. Then the controller component of a CSI Driver will attach the persistent volume to the node. Finally the node component of a CSI Driver will mount the persistent volume on the node.
The node component of a CSI Driver needs to run on Windows nodes to support Windows workloads. Various privileged operations like scanning of disk devices, mounting of file systems, etc. cannot be done from a containerized application running on Windows nodes yet ([Windows HostProcess containers](https://github.com/kubernetes/enhancements/issues/1981) introduced in Kubernetes 1.22 as alpha enable functionalities that require host access like the operations mentioned before). However, we can perform these operations through a binary (CSI Proxy) that's pre-installed on the Window nodes. CSI Proxy has a client-server architecture and allows CSI drivers to issue privileged storage operations through a gRPC interface exposed over named pipes created during the startup of CSI Proxy.
![CSI Proxy Architecture](/images/blog/2021-08-09-csi-windows-support-with-csi-proxy-reaches-ga/csi-proxy.png)
## CSI Proxy reaches GA
The CSI Proxy development team has worked closely with storage vendors, many of whom started integrating CSI Proxy into their CSI Drivers and provided feedback as early as CSI Proxy design proposal. This cooperation uncovered use cases where additional APIs were needed, found bugs, and identified areas for documentation improvement.
The CSI Proxy design [KEP](https://github.com/kubernetes/enhancements/pull/2737) has been updated to reflect the current CSI Proxy architecture. Additional [development documentation](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/DEVELOPMENT.md) is included for contributors interested in helping with new features or bug fixes.
Before we reached GA we wanted to make sure that our API is simple and consistent. We went through an extensive API review of the v1beta API groups where we made sure that the CSI Proxy API methods and messages are consistent with the naming conventions defined in the [CSI Spec](https://github.com/container-storage-interface/spec/blob/master/spec.md). As part of this effort we're graduating the [Disk](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/apis/disk_v1.md), [Filesystem](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/apis/filesystem_v1.md), [SMB](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/apis/smb_v1.md) and [Volume](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/apis/volume_v1.md) API groups to v1.
Additional Windows system APIs to get information from the Windows nodes and support to mount iSCSI targets in Windows nodes, are available as alpha APIs in the [System API](https://github.com/kubernetes-csi/csi-proxy/tree/v1.0.0/client/api/system/v1alpha1) and the [iSCSI API](https://github.com/kubernetes-csi/csi-proxy/tree/v1.0.0/client/api/iscsi/v1alpha2). These APIs will continue to be improved before we graduate them to v1.
CSI Proxy v1 is compatible with all the previous v1betaX releases. The GA `csi-proxy.exe` binary can handle requests from v1betaX clients thanks to the autogenerated conversion layer that transforms any versioned client request to a version-agnostic request that the server can process. Several [integration tests](https://github.com/kubernetes-csi/csi-proxy/tree/v1.0.0/integrationtests) were added for all the API versions of the API groups that are graduating to v1 to ensure that CSI Proxy is backwards compatible.
Version drift between CSI Proxy and the CSI Drivers that interact with it was also carefully considered. A [connection fallback mechanism](https://github.com/kubernetes-csi/csi-proxy/pull/124) has been provided for CSI Drivers to handle multiple versions of CSI Proxy for a smooth upgrade to v1. This allows CSI Drivers, like the GCE PD CSI Driver, [to recognize which version of the CSI Proxy binary is running](https://github.com/kubernetes-sigs/gcp-compute-persistent-disk-csi-driver/pull/738) and handle multiple versions of the CSI Proxy binary deployed on the node.
CSI Proxy v1 is already being used by many CSI Drivers, including the [AWS EBS CSI Driver](https://github.com/kubernetes-sigs/aws-ebs-csi-driver/pull/966), [Azure Disk CSI Driver](https://github.com/kubernetes-sigs/azuredisk-csi-driver/pull/919), [GCE PD CSI Driver](https://github.com/kubernetes-sigs/gcp-compute-persistent-disk-csi-driver/pull/738), and [SMB CSI Driver](https://github.com/kubernetes-csi/csi-driver-smb/pull/319).
## Future plans
We're very excited for the future of CSI Proxy. With the upcoming [Windows HostProcess containers](https://github.com/kubernetes/enhancements/issues/1981), we are considering converting the CSI Proxy in to a library consumed by CSI Drivers in addition to the current client/server design. This will allow us to iterate faster on new features because the `csi-proxy.exe` binary will no longer be needed.
## How to get involved?
This project, like all of Kubernetes, is the result of hard work by many contributors from diverse backgrounds working together. Those interested in getting involved with the design and development of CSI Proxy, or any part of the Kubernetes Storage system, may join the Kubernetes Storage Special Interest Group (SIG). Were rapidly growing and always welcome new contributors.
For those interested in more details about CSI support in Windows please reach out in the [#csi-windows](https://kubernetes.slack.com/messages/csi-windows) Kubernetes slack channel.
## Acknowledgments
CSI-Proxy received many contributions from members of the Kubernetes community. We thank all of the people that contributed to CSI Proxy with design reviews, bug reports, bug fixes, and for their continuous support in reaching this milestone:
- [Andy Zhang](https://github.com/andyzhangx)
- [Dan Ilan](https://github.com/jmpfar)
- [Deep Debroy](https://github.com/ddebroy)
- [Humble Devassy Chirammal](https://github.com/humblec)
- [Jing Xu](https://github.com/jingxu97)
- [Jean Rougé](https://github.com/wk8)
- [Jordan Liggitt](https://github.com/liggitt)
- [Kalya Subramanian](https://github.com/ksubrmnn)
- [Krishnakumar R](https://github.com/kkmsft)
- [Manuel Tellez](https://github.com/manueltellez)
- [Mark Rossetti](https://github.com/marosset)
- [Mauricio Poppe](https://github.com/mauriciopoppe)
- [Matthew Wong](https://github.com/wongma7)
- [Michelle Au](https://github.com/msau42)
- [Patrick Lang](https://github.com/PatrickLang)
- [Saad Ali](https://github.com/saad-ali)
- [Yuju Hong](https://github.com/yujuhong)
@@ -0,0 +1,144 @@
---
layout: blog
title: "Kubernetes Memory Manager moves to beta"
date: 2021-08-11
slug: kubernetes-1-22-feature-memory-manager-moves-to-beta
---
**Authors:** Artyom Lukianov (Red Hat), Cezary Zukowski (Samsung)
The blog post explains some of the internals of the _Memory manager_, a beta feature
of Kubernetes 1.22. In Kubernetes, the Memory Manager is a
[kubelet](https://kubernetes.io/docs/concepts/overview/components/#kubelet) subcomponent.
The memory manage provides guaranteed memory (and hugepages)
allocation for pods in the `Guaranteed` [QoS class](https://kubernetes.io/docs/tasks/configure-pod-container/quality-service-pod/#qos-classes).
This blog post covers:
1. [Why do you need it?](#Why-do-you-need-it?)
2. [The internal details of how the **MemoryManager** works](#How-does-it-work?)
3. [Current limitations of the **MemoryManager**](#Current-limitations)
4. [Future work for the **MemoryManager**](#Future-work-for-the-Memory-Manager)
## Why do you need it?
Some Kubernetes workloads run on nodes with
[non-uniform memory access](https://en.wikipedia.org/wiki/Non-uniform_memory_access) (NUMA).
Suppose you have NUMA nodes in your cluster. In that case, you'll know about the potential for extra latency when
compute resources need to access memory on the different NUMA locality.
To get the best performance and latency for your workload, container CPUs,
peripheral devices, and memory should all be aligned to the same NUMA
locality.
Before Kubernetes v1.22, the kubelet already provided a set of managers to
align CPUs and PCI devices, but you did not have a way to align memory.
The Linux kernel was able to make best-effort attempts to allocate
memory for tasks from the same NUMA node where the container is
executing are placed, but without any guarantee about that placement.
## How does it work?
The memory manager is doing two main things:
- provides the topology hint to the Topology Manager
- allocates the memory for containers and updates the state
The overall sequence of the Memory Manager under the Kubelet
![MemoryManagerDiagram](/images/blog/2021-08-11-memory-manager-moves-to-beta/MemoryManagerDiagram.svg "MemoryManagerDiagram")
During the Admission phase:
1. When first handling a new pod, the kubelet calls the TopologyManager's `Admit()` method.
2. The Topology Manager is calling `GetTopologyHints()` for every hint provider including the Memory Manager.
3. The Memory Manager calculates all possible NUMA nodes combinations for every container inside the pod and returns hints to the Topology Manager.
4. The Topology Manager calls to `Allocate()` for every hint provider including the Memory Manager.
5. The Memory Manager allocates the memory under the state according to the hint that the Topology Manager chose.
During Pod creation:
1. The kubelet calls `PreCreateContainer()`.
2. For each container, the Memory Manager looks the NUMA nodes where it allocated the
memory for the container and then returns that information to the kubelet.
3. The kubelet creates the container, via CRI, using a container specification
that incorporates information from the Memory Manager information.
### Let's talk about the configuration
By default, the Memory Manager runs with the `None` policy, meaning it will just
relax and not do anything. To make use of the Memory Manager, you should set
two command line options for the kubelet:
- `--memory-manager-policy=Static`
- `--reserved-memory="<numaNodeID>:<resourceName>=<quantity>"`
The value for `--memory-manager-policy` is straightforward: `Static`. Deciding what to specify for `--reserved-memory` takes more thought. To configure it correctly, you should follow two main rules:
- The amount of reserved memory for the `memory` resource must be greater than zero.
- The amount of reserved memory for the resource type must be equal
to [NodeAllocatable](/docs/tasks/administer-cluster/reserve-compute-resources/#node-allocatable)
(`kube-reserved + system-reserved + eviction-hard`) for the resource.
You can read more about memory reservations in [Reserve Compute Resources for System Daemons](/docs/tasks/administer-cluster/reserve-compute-resources/).
![Reserved memory](/images/blog/2021-08-11-memory-manager-moves-to-beta/ReservedMemory.svg)
## Current limitations
The 1.22 release and promotion to beta brings along enhancements and fixes, but the Memory Manager still has several limitations.
### Single vs Cross NUMA node allocation
The NUMA node can not have both single and cross NUMA node allocations. When the container memory is pinned to two or more NUMA nodes, we can not know from which NUMA node the container will consume the memory.
![Single vs Cross NUMA allocation](/images/blog/2021-08-11-memory-manager-moves-to-beta/SingleCrossNUMAAllocation.svg "SingleCrossNUMAAllocation")
1. The `container1` started on the NUMA node 0 and requests *5Gi* of the memory but currently is consuming only *3Gi* of the memory.
2. For container2 the memory request is 10Gi, and no single NUMA node can satisfy it.
3. The `container2` consumes *3.5Gi* of the memory from the NUMA node 0, but once the `container1` will require more memory, it will not have it, and the kernel will kill one of the containers with the *OOM* error.
To prevent such issues, the Memory Manager will fail the admission of the `container2` until the machine has two NUMA nodes without a single NUMA node allocation.
### Works only for Guaranteed pods
The Memory Manager can not guarantee memory allocation for Burstable pods,
also when the Burstable pod has specified equal memory limit and request.
Let's assume you have two Burstable pods: `pod1` has containers with
equal memory request and limits, and `pod2` has containers only with a
memory request set. You want to guarantee memory allocation for the `pod1`.
To the Linux kernel, processes in either pod have the same *OOM score*,
once the kernel finds that it does not have enough memory, it can kill
processes that belong to pod `pod1`.
### Memory fragmentation
The sequence of Pods and containers that start and stop can fragment the memory on NUMA nodes.
The alpha implementation of the Memory Manager does not have any mechanism to balance pods and defragment memory back.
## Future work for the Memory Manager
We do not want to stop with the current state of the Memory Manager and are looking to
make improvements, including in the following areas.
### Make the Memory Manager allocation algorithm smarter
The current algorithm ignores distances between NUMA nodes during the
calculation of the allocation. If same-node placement isn't available, we can still
provide better performance compared to the current implementation, by changing the
Memory Manager to prefer the closest NUMA nodes for cross-node allocation.
### Reduce the number of admission errors
The default Kubernetes scheduler is not aware of the node's NUMA topology, and it can be a reason for many admission errors during the pod start.
We're hoping to add a KEP (Kubernetes Enhancement Proposal) to cover improvements in this area.
Follow [Topology aware scheduler plugin in kube-scheduler](https://github.com/kubernetes/enhancements/issues/2044) to see how this idea progresses.
## Conclusion
With the promotion of the Memory Manager to beta in 1.22, we encourage everyone to give it a try and look forward to any feedback you may have. While there are still several limitations, we have a set of enhancements planned to address them and look forward to providing you with many new features in upcoming releases.
If you have ideas for additional enhancements or a desire for certain features, please let us know. The team is always open to suggestions to enhance and improve the Memory Manager.
We hope you have found this blog informative and helpful! Let us know if you have any questions or comments.
You can contact us via:
- The Kubernetes [#sig-node ](https://kubernetes.slack.com/messages/sig-node)
channel in Slack (visit https://slack.k8s.io/ for an invitation if you need one)
- The SIG Node mailing list, [kubernetes-sig-node@googlegroups.com](https://groups.google.com/g/kubernetes-sig-node)
Binary file not shown.

After

Width:  |  Height:  |  Size: 71 KiB

@@ -0,0 +1,79 @@
---
layout: blog
title: 'Alpha in v1.22: Windows HostProcess Containers'
date: 2021-08-16
slug: windows-hostprocess-containers
---
**Authors:** Brandon Smith (Microsoft)
Kubernetes v1.22 introduced a new alpha feature for clusters that
include Windows nodes: HostProcess containers.
HostProcess containers aim to extend the Windows container model to enable a wider
range of Kubernetes cluster management scenarios. HostProcess containers run
directly on the host and maintain behavior and access similar to that of a regular
process. With HostProcess containers, users can package and distribute management
operations and functionalities that require host access while retaining versioning
and deployment methods provided by containers. This allows Windows containers to
be used for a variety of device plugin, storage, and networking management scenarios
in Kubernetes. With this comes the enablement of host network mode—allowing
HostProcess containers to be created within the host's network namespace instead of
their own. HostProcess containers can also be built on top of existing Windows server
2019 (or later) base images, managed through the Windows container runtime, and run
as any user that is available on or in the domain of the host machine.
Linux privileged containers are currently used for a variety of key scenarios in
Kubernetes, including kube-proxy (via kubeadm), storage, and networking scenarios.
Support for these scenarios in Windows previously required workarounds via proxies
or other implementations. Using HostProcess containers, cluster operators no longer
need to log onto and individually configure each Windows node for administrative
tasks and management of Windows services. Operators can now utilize the container
model to deploy management logic to as many clusters as needed with ease.
## How does it work?
Windows HostProcess containers are implemented with Windows _Job Objects_, a break from the
previous container model using server silos. Job objects are components of the Windows OS which offer the ability to
manage a group of processes as a group (a.k.a. _jobs_) and assign resource constraints to the
group as a whole. Job objects are specific to the Windows OS and are not associated with the Kubernetes [Job API](https://kubernetes.io/docs/concepts/workloads/controllers/job/). They have no process or file system isolation,
enabling the privileged payload to view and edit the host file system with the
correct permissions, among other host resources. The init process, and any processes
it launches or that are explicitly launched by the user, are all assigned to the
job object of that container. When the init process exits or is signaled to exit,
all the processes in the job will be signaled to exit, the job handle will be
closed and the storage will be unmounted.
HostProcess and Linux privileged containers enable similar scenarios but differ
greatly in their implementation (hence the naming difference). HostProcess containers
have their own pod security policies. Those used to configure Linux privileged
containers **do not** apply. Enabling privileged access to a Windows host is a
fundamentally different process than with Linux so the configuration and
capabilities of each differ significantly. Below is a diagram detailing the
overall architecture of Windows HostProcess containers:
{{< figure src="hostprocess-architecture.png" alt="HostProcess Architecture" >}}
## How do I use it?
HostProcess containers can be run from within a
[HostProcess Pod](/docs/tasks/configure-pod-container/create-hostprocess-pod).
With the feature enabled on Kubernetes version 1.22, a containerd container runtime of
1.5.4 or higher, and the latest version of hcsshim, deploying a pod spec with the
[correct HostProcess configuration](/docs/tasks/configure-pod-container/create-hostprocess-pod/#before-you-begin)
will enable you to run HostProcess containers. To get started with running
Windows containers see the general guidance for [Windows in Kubernetes](/docs/setup/production-environment/windows/)
## How can I learn more?
- Work through [Create a Windows HostProcess Pod](/docs/tasks/configure-pod-container/create-hostprocess-pod/)
- Read about Kubernetes [Pod Security Standards](/docs/concepts/security/pod-security-standards/)
- Read the enhancement proposal [Windows Privileged Containers and Host Networking Mode](https://github.com/kubernetes/enhancements/tree/master/keps/sig-windows/1981-windows-privileged-container-support) (KEP-1981)
## How do I get involved?
HostProcess containers are in active development. SIG Windows welcomes suggestions from the community.
Get involved with [SIG Windows](https://github.com/kubernetes/community/tree/master/sig-windows)
to contribute!
@@ -0,0 +1,267 @@
---
layout: blog
title: "Enable seccomp for all workloads with a new v1.22 alpha feature"
date: 2021-08-25
slug: seccomp-default
---
**Author:** Sascha Grunert, Red Hat
This blog post is about a new Kubernetes feature introduced in v1.22, which adds
an additional security layer on top of the existing seccomp support. Seccomp is
a security mechanism for Linux processes to filter system calls (syscalls) based
on a set of defined rules. Applying seccomp profiles to containerized workloads
is one of the key tasks when it comes to enhancing the security of the
application deployment. Developers, site reliability engineers and
infrastructure administrators have to work hand in hand to create, distribute
and maintain the profiles over the applications life-cycle.
You can use the [`securityContext`][seccontext] field of Pods and their
containers can be used to adjust security related configurations of the
workload. Kubernetes introduced dedicated [seccomp related API
fields][seccontext] in this `SecurityContext` with the [graduation of seccomp to
General Availability (GA)][ga] in v1.19.0. This enhancement allowed an easier
way to specify if the whole pod or a specific container should run as:
[seccontext]: /docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
[ga]: https://kubernetes.io/blog/2020/08/26/kubernetes-release-1.19-accentuate-the-paw-sitive/#graduated-to-stable
- `Unconfined`: seccomp will not be enabled
- `RuntimeDefault`: the container runtimes default profile will be used
- `Localhost`: a node local profile will be applied, which is being referenced
by a relative path to the seccomp profile root (`<kubelet-root-dir>/seccomp`)
of the kubelet
With the graduation of seccomp, nothing has changed from an overall security
perspective, because `Unconfined` is still the default. This is totally fine if
you consider this from the upgrade path and backwards compatibility perspective of
Kubernetes releases. But it also means that it is more likely that a workload
runs without seccomp at all, which should be fixed in the long term.
## `SeccompDefault` to the rescue
Kubernetes v1.22.0 introduces a new kubelet [feature gate][gate]
`SeccompDefault`, which has been added in `alpha` state as every other new
feature. This means that it is disabled by default and can be enabled manually
for every single Kubernetes node.
[gate]: /docs/reference/command-line-tools-reference/feature-gates
What does the feature do? Well, it just changes the default seccomp profile from
`Unconfined` to `RuntimeDefault`. If not specified differently in the pod
manifest, then the feature will add a higher set of security constraints by
using the default profile of the container runtime. These profiles may differ
between runtimes like [CRI-O][crio] or [containerd][ctrd]. They also differ for
its used hardware architectures. But generally speaking, those default profiles
allow a common amount of syscalls while blocking the more dangerous ones, which
are unlikely or unsafe to be used in a containerized application.
[crio]: https://github.com/cri-o/cri-o/blob/fe30d62/vendor/github.com/containers/common/pkg/seccomp/default_linux.go#L45
[ctrd]: https://github.com/containerd/containerd/blob/e1445df/contrib/seccomp/seccomp_default.go#L51
### Enabling the feature
Two kubelet configuration changes have to be made to enable the feature:
1. **Enable the feature** gate by setting the `SeccompDefault=true` via the command
line (`--feature-gates`) or the [kubelet configuration][kubelet] file.
2. **Turn on the feature** by enabling the feature by adding the
`--seccomp-default` command line flag or via the [kubelet
configuration][kubelet] file (`seccompDefault: true`).
[kubelet]: /docs/tasks/administer-cluster/kubelet-config-file
The kubelet will error on startup if only one of the above steps have been done.
### Trying it out
If the feature is enabled on a node, then you can create a new workload like
this:
```yaml
apiVersion: v1
kind: Pod
metadata:
name: test-pod
spec:
containers:
- name: test-container
image: nginx:1.21
```
Now it is possible to inspect the used seccomp profile by using
[`crictl`][crictl] while investigating the containers [runtime
specification][rspec]:
[crictl]: https://github.com/kubernetes-sigs/cri-tools
[rspec]: https://github.com/opencontainers/runtime-spec/blob/0c021c1/config-linux.md#seccomp
```bash
CONTAINER_ID=$(sudo crictl ps -q --name=test-container)
sudo crictl inspect $CONTAINER_ID | jq .info.runtimeSpec.linux.seccomp
```
```yaml
{
"defaultAction": "SCMP_ACT_ERRNO",
"architectures": ["SCMP_ARCH_X86_64", "SCMP_ARCH_X86", "SCMP_ARCH_X32"],
"syscalls": [
{
"names": ["_llseek", "_newselect", "accept", …, "write", "writev"],
"action": "SCMP_ACT_ALLOW"
},
]
}
```
You can see that the lower level container runtime ([CRI-O][crio-home] and
[runc][runc] in our case), successfully applied the default seccomp profile.
This profile denies all syscalls per default, while allowing commonly used ones
like [`accept`][accept] or [`write`][write].
[crio-home]: https://github.com/cri-o/cri-o
[runc]: https://github.com/opencontainers/runc
[accept]: https://man7.org/linux/man-pages/man2/accept.2.html
[write]: https://man7.org/linux/man-pages/man2/write.2.html
Please note that the feature will not influence any Kubernetes API for now.
Therefore, it is not possible to retrieve the used seccomp profile via `kubectl`
`get` or `describe` if the [`SeccompProfile`][api] field is unset within the
`SecurityContext`.
[api]: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
The feature also works when using multiple containers within a pod, for example
if you create a pod like this:
```yaml
apiVersion: v1
kind: Pod
metadata:
name: test-pod
spec:
containers:
- name: test-container-nginx
image: nginx:1.21
securityContext:
seccompProfile:
type: Unconfined
- name: test-container-redis
image: redis:6.2
```
then you should see that the `test-container-nginx` runs without a seccomp profile:
```bash
sudo crictl inspect $(sudo crictl ps -q --name=test-container-nginx) |
jq '.info.runtimeSpec.linux.seccomp == null'
true
```
Whereas the container `test-container-redis` runs with `RuntimeDefault`:
```bash
sudo crictl inspect $(sudo crictl ps -q --name=test-container-redis) |
jq '.info.runtimeSpec.linux.seccomp != null'
true
```
The same applies to the pod itself, which also runs with the default profile:
```bash
sudo crictl inspectp (sudo crictl pods -q --name test-pod) |
jq '.info.runtimeSpec.linux.seccomp != null'
true
```
### Upgrade strategy
It is recommended to enable the feature in multiple steps, whereas different
risks and mitigations exist for each one.
#### Feature gate enabling
Enabling the feature gate at the kubelet level will not turn on the feature, but
will make it possible by using the `SeccompDefault` kubelet configuration or the
`--seccomp-default` CLI flag. This can be done by an administrator for the whole
cluster or only a set of nodes.
#### Testing the Application
If you're trying this within a dedicated test environment, you have to ensure
that the application code does not trigger syscalls blocked by the
`RuntimeDefault` profile before enabling the feature on a node. This can be done
by:
- _Recommended_: Analyzing the code (manually or by running the application with
[strace][strace]) for any executed syscalls which may be blocked by the
default profiles. If that's the case, then you can override the default by
explicitly setting the pod or container to run as `Unconfined`. Alternatively,
you can create a custom seccomp profile (see optional step below).
profile based on the default by adding the additional syscalls to the
`"action": "SCMP_ACT_ALLOW"` section.
- _Recommended_: Manually set the profile to the target workload and use a
rolling upgrade to deploy into production. Rollback the deployment if the
application does not work as intended.
- _Optional_: Run the application against an end-to-end test suite to trigger
all relevant code paths with `RuntimeDefault` enabled. If a test fails, use
the same mitigation as mentioned above.
- _Optional_: Create a custom seccomp profile based on the default and change
its default action from `SCMP_ACT_ERRNO` to `SCMP_ACT_LOG`. This means that
the seccomp filter for unknown syscalls will have no effect on the application
at all, but the system logs will now indicate which syscalls may be blocked.
This requires at least a Kernel version 4.14 as well as a recent [runc][runc]
release. Monitor the application hosts audit logs (defaults to
`/var/log/audit/audit.log`) or syslog entries (defaults to `/var/log/syslog`)
for syscalls via `type=SECCOMP` (for audit) or `type=1326` (for syslog).
Compare the syscall ID with those [listed in the Linux Kernel
sources][syscalls] and add them to the custom profile. Be aware that custom
audit policies may lead into missing syscalls, depending on the configuration
of auditd.
- _Optional_: Use cluster additions like the [Security Profiles Operator][spo]
for profiling the application via its [log enrichment][logs] capabilities or
recording a profile by using its [recording feature][rec]. This makes the
above mentioned manual log investigation obsolete.
[syscalls]: https://github.com/torvalds/linux/blob/7bb7f2a/arch/x86/entry/syscalls/syscall_64.tbl
[spo]: https://github.com/kubernetes-sigs/security-profiles-operator
[logs]: https://github.com/kubernetes-sigs/security-profiles-operator/blob/c90ef3a/installation-usage.md#record-profiles-from-workloads-with-profilerecordings
[rec]: https://github.com/kubernetes-sigs/security-profiles-operator/blob/c90ef3a/installation-usage.md#using-the-log-enricher
[strace]: https://man7.org/linux/man-pages/man1/strace.1.html
#### Deploying the modified application
Based on the outcome of the application tests, it may be required to change the
application deployment by either specifying `Unconfined` or a custom seccomp
profile. This is not the case if the application works as intended with
`RuntimeDefault`.
#### Enable the kubelet configuration
If everything went well, then the feature is ready to be enabled by the kubelet
configuration or its corresponding CLI flag. This should be done on a per-node
basis to reduce the overall risk of missing a syscall during the investigations
when running the application tests. If it's possible to monitor audit logs
within the cluster, then it's recommended to do this for eventually missed
seccomp events. If the application works as intended then the feature can be
enabled for further nodes within the cluster.
## Conclusion
Thank you for reading this blog post! I hope you enjoyed to see how the usage of
seccomp profiles has been evolved in Kubernetes over the past releases as much
as I do. On your own cluster, change the default seccomp profile to
`RuntimeDefault` (using this new feature) and see the security benefits, and, of
course, feel free to reach out any time for feedback or questions.
---
_Editor's note: If you have any questions or feedback about this blog post, feel
free to reach out via the [Kubernetes slack in #sig-node][slack]._
[slack]: https://kubernetes.slack.com/messages/sig-node
@@ -0,0 +1,48 @@
---
layout: blog
title: 'Minimum Ready Seconds for StatefulSets'
date: 2021-08-27
slug: minreadyseconds-statefulsets
---
**Authors:** Ravi Gudimetla (Red Hat), Maciej Szulik (Red Hat)
This blog describes the notion of Availability for `StatefulSet` workloads, and a new alpha feature in Kubernetes 1.22 which adds `minReadySeconds` configuration for `StatefulSets`.
## What problems does this solve?
Prior to Kubernetes 1.22 release, once a `StatefulSet` `Pod` is in the `Ready` state it is considered `Available` to receive traffic. For some of the `StatefulSet` workloads, it may not be the case. For example, a workload like Prometheus with multiple instances of Alertmanager, it should be considered `Available` only when Alertmanager's state transfer is complete, not when the `Pod` is in `Ready` state. Since `minReadySeconds` adds buffer, the state transfer may be complete before the `Pod` becomes `Available`. While this is not a fool proof way of identifying if the state transfer is complete or not, it gives a way to the end user to express their intention of waiting for sometime before the `Pod` is considered `Available` and it is ready to serve requests.
Another case, where `minReadySeconds` helps is when using `LoadBalancer` `Services` with cloud providers. Since `minReadySeconds` adds latency after a `Pod` is `Ready`, it provides buffer time to prevent killing pods in rotation before new pods show up. Imagine a load balancer in unhappy path taking 10-15s to propagate. If you have 2 replicas then, you'd kill the second replica only after the first one is up but in reality, first replica cannot be seen because it is not yet ready to serve requests.
So, in general, the notion of `Availability` in `StatefulSets` is pretty useful and this feature helps in solving the above problems. This is a feature that already exists for `Deployments` and `DaemonSets` and we now have them for `StatefulSets` too to give users consistent workload experience.
## How does it work?
The statefulSet controller watches for both `StatefulSets` and the `Pods` associated with them. When the feature gate associated with this feature is enabled, the statefulSet controller identifies how long a particular `Pod` associated with a `StatefulSet` has been in the `Running` state.
If this value is greater than or equal to the time specified by the end user in `.spec.minReadySeconds` field, the statefulSet controller updates a field called `availableReplicas` in the `StatefulSet`'s status subresource to include this `Pod`. The `status.availableReplicas` in `StatefulSet`'s status is an integer field which tracks the number of pods that are `Available`.
## How do I use it?
You are required to prepare the following things in order to try out the feature:
- Download and install a kubectl greater than v1.22.0 version
- Switch on the feature gate with the command line flag `--feature-gates=StatefulSetMinReadySeconds=true` on `kube-apiserver` and `kube-controller-manager`
After successfully starting `kube-apiserver` and `kube-controller-manager`, you will see `AvailableReplicas` in the status and `minReadySeconds` of spec (with a default value of 0).
Specify a value for `minReadySeconds` for any StatefulSet and you can check if `Pods` are available or not by checking `AvailableReplicas` field using:
`kubectl get statefulset/<name_of_the_statefulset> -o yaml`
## How can I learn more?
- Read the KEP: [minReadySeconds for StatefulSets](https://github.com/kubernetes/enhancements/tree/master/keps/sig-apps/2599-minreadyseconds-for-statefulsets#readme)
- Read the documentation: [Minimum ready seconds](/docs/concepts/workloads/controllers/statefulset/#minimum-ready-seconds) for StatefulSet
- Review the [API definition](/docs/reference/kubernetes-api/workload-resources/stateful-set-v1/) for StatefulSet
## How do I get involved?
Please reach out to us in the [#sig-apps](https://kubernetes.slack.com/archives/C18NZM5K9) channel on Slack (visit https://slack.k8s.io/ for an invitation if you need one), or on the SIG Apps mailing list: kubernetes-sig-apps@googlegroups.com
@@ -0,0 +1,219 @@
---
layout: blog
title: "Kubernetes 1.22: A New Design for Volume Populators"
date: 2021-08-30
slug: volume-populators-redesigned
---
**Authors:**
Ben Swartzlander (NetApp)
Kubernetes v1.22, released earlier this month, introduced a redesigned approach for volume
populators. Originally implemented
in v1.18, the API suffered from backwards compatibility issues. Kubernetes v1.22 includes a new API
field called `dataSourceRef` that fixes these problems.
## Data sources
Earlier Kubernetes releases already added a `dataSource` field into the
[PersistentVolumeClaim](/docs/concepts/storage/persistent-volumes/#persistentvolumeclaims) API,
used for cloning volumes and creating volumes from snapshots. You could use the `dataSource` field when
creating a new PVC, referencing either an existing PVC or a VolumeSnapshot in the same namespace.
That also modified the normal provisioning process so that instead of yielding an empty volume, the
new PVC contained the same data as either the cloned PVC or the cloned VolumeSnapshot.
Volume populators embrace the same design idea, but extend it to any type of object, as long
as there exists a [custom resource](/docs/concepts/extend-kubernetes/api-extension/custom-resources/)
to define the data source, and a populator controller to implement the logic. Initially,
the `dataSource` field was directly extended to allow arbitrary objects, if the `AnyVolumeDataSource`
feature gate was enabled on a cluster. That change unfortunately caused backwards compatibility
problems, and so the new `dataSourceRef` field was born.
In v1.22 if the `AnyVolumeDataSource` feature gate is enabled, the `dataSourceRef` field is
added, which behaves similarly to the `dataSource` field except that it allows arbitrary
objects to be specified. The API server ensures that the two fields always have the same
contents, and neither of them are mutable. The differences is that at creation time
`dataSource` allows only PVCs or VolumeSnapshots, and ignores all other values, while
`dataSourceRef` allows most types of objects, and in the few cases it doesn't allow an
object (core objects other than PVCs) a validation error occurs.
When this API change graduates to stable, we would deprecate using `dataSource` and recommend
using `dataSourceRef` field for all use cases.
In the v1.22 release, `dataSourceRef` is available (as an alpha feature) specifically for cases
where you want to use for custom volume populators.
## Using populators
Every volume populator must have one or more CRDs that it supports. Administrators may
install the CRD and the populator controller and then PVCs with a `dataSourceRef` specifies
a CR of the type that the populator supports will be handled by the populator controller
instead of the CSI driver directly.
Underneath the covers, the CSI driver is still invoked to create an empty volume, which
the populator controller fills with the appropriate data. The PVC doesn't bind to the PV
until it's fully populated, so it's safe to define a whole application manifest including
pod and PVC specs and the pods won't begin running until everything is ready, just as if
the PVC was a clone of another PVC or VolumeSnapshot.
## How it works
PVCs with data sources are still noticed by the external-provisioner sidecar for the
related storage class (assuming a CSI provisioner is used), but because the sidecar
doesn't understand the data source kind, it doesn't do anything. The populator controller
is also watching for PVCs with data sources of a kind that it understands and when it
sees one, it creates a temporary PVC of the same size, volume mode, storage class,
and even on the same topology (if topology is used) as the original PVC. The populator
controller creates a worker pod that attaches to the volume and writes the necessary
data to it, then detaches from the volume and the populator controller rebinds the PV
from the temporary PVC to the orignal PVC.
## Trying it out
The following things are required to use volume populators:
* Enable the `AnyVolumeDataSource` feature gate
* Install a CRD for the specific data source / populator
* Install the populator controller itself
Populator controllers may use the [lib-volume-populator](https://github.com/kubernetes-csi/lib-volume-populator)
library to do most of the Kubernetes API level work. Individual populators only need to
provide logic for actually writing data into the volume based on a particular CR
instance. This library provides a sample populator implementation.
These optional components improve user experience:
* Install the VolumePopulator CRD
* Create a VolumePopulator custom respource for each specific data source
* Install the [volume data source validator](https://github.com/kubernetes-csi/volume-data-source-validator)
controller (alpha)
The purpose of these components is to generate warning events on PVCs with data sources
for which there is no populator.
## Putting it all together
To see how this works, you can install the sample "hello" populator and try it
out.
First install the volume-data-source-validator controller.
```terminal
kubectl apply -f https://github.com/kubernetes-csi/volume-data-source-validator/blob/master/deploy/kubernetes/rbac-data-source-validator.yaml
kubectl apply -f https://github.com/kubernetes-csi/volume-data-source-validator/blob/master/deploy/kubernetes/setup-data-source-validator.yaml
```
Next install the example populator.
```terminal
kubectl apply -f https://github.com/kubernetes-csi/lib-volume-populator/blob/master/example/hello-populator/crd.yaml
kubectl apply -f https://github.com/kubernetes-csi/lib-volume-populator/blob/master/example/hello-populator/deploy.yaml
```
Create an instance of the `Hello` CR, with some text.
```yaml
apiVersion: hello.k8s.io/v1alpha1
kind: Hello
metadata:
name: example-hello
spec:
fileName: example.txt
fileContents: Hello, world!
```
Create a PVC that refers to that CR as its data source.
```yaml
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: example-pvc
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 10Mi
dataSourceRef:
apiGroup: hello.k8s.io
kind: Hello
name: example-hello
volumeMode: Filesystem
```
Next, run a job that reads the file in the PVC.
```yaml
apiVersion: batch/v1
kind: Job
metadata:
name: example-job
spec:
template:
spec:
containers:
- name: example-container
image: busybox:latest
command:
- cat
- /mnt/example.txt
volumeMounts:
- name: vol
mountPath: /mnt
restartPolicy: Never
volumes:
- name: vol
persistentVolumeClaim:
claimName: example-pvc
```
Wait for the job to complete (including all of its dependencies).
```terminal
kubectl wait --for=condition=Complete job/example-job
```
And last examine the log from the job.
```terminal
kubectl logs job/example-job
Hello, world!
```
Note that the volume already contained a text file with the string contents from
the CR. This is only the simplest example. Actual populators can set up the volume
to contain arbitrary contents.
## How to write your own volume populator
Developers interested in writing new poplators are encouraged to use the
[lib-volume-populator](https://github.com/kubernetes-csi/lib-volume-populator) library
and to only supply a small controller wrapper around the library, and a pod image
capable of attaching to volumes and writing the appropriate data to the volume.
Individual populators can be extremely generic such that they work with every type
of PVC, or they can do vendor specific things to rapidly fill a volume with data
if the volume was provisioned by a specific CSI driver from the same vendor, for
example, by communicating directly with the storage for that volume.
## The future
As this feature is still in alpha, we expect to update the out of tree controllers
with more tests and documentation. The community plans to eventually re-implement
the populator library as a sidecar, for ease of operations.
We hope to see some official community-supported populators for some widely-shared
use cases. Also, we expect that volume populators will be used by backup vendors
as a way to "restore" backups to volumes, and possibly a standardized API to do
this will evolve.
## How can I learn more?
The enhancement proposal,
[Volume Populators](https://github.com/kubernetes/enhancements/tree/master/keps/sig-storage/1495-volume-populators), includes lots of detail about the history and technical implementation
of this feature.
[Volume populators and data sources](/docs/concepts/storage/persistent-volumes/#volume-populators-and-data-sources), within the documentation topic about persistent volumes,
explains how to use this feature in your cluster.
Please get involved by joining the Kubernetes storage SIG to help us enhance this
feature. There are a lot of good ideas already and we'd be thrilled to have more!
@@ -0,0 +1,67 @@
---
layout: blog
title: 'Alpha in Kubernetes v1.22: API Server Tracing'
date: 2021-09-03
slug: api-server-tracing
---
**Authors:** David Ashpole (Google)
In distributed systems, it can be hard to figure out where problems are. You grep through one component's logs just to discover that the source of your problem is in another component. You search there only to discover that you need to enable debug logs to figure out what really went wrong... And it goes on. The more complex the path your request takes, the harder it is to answer questions about where it went. I've personally spent many hours doing this dance with a variety of Kubernetes components. Distributed tracing is a tool which is designed to help in these situations, and the Kubernetes API Server is, perhaps, the most important Kubernetes component to be able to debug. At Kubernetes' Sig Instrumentation, our mission is to make it easier to understand what's going on in your cluster, and we are happy to announce that distributed tracing in the Kubernetes API Server reached alpha in 1.22.
## What is Tracing?
Distributed tracing links together a bunch of super-detailed information from multiple different sources, and structures that telemetry into a single tree for that request. Unlike logging, which limits the quantity of data ingested by using log levels, tracing collects all of the details and uses sampling to collect only a small percentage of requests. This means that once you have a trace which demonstrates an issue, you should have all the information you need to root-cause the problem--no grepping for object UID required! My favorite aspect, though, is how useful the visualizations of traces are. Even if you don't understand the inner workings of the API Server, or don't have a clue what an etcd "Transaction" is, I'd wager you (yes, you!) could tell me roughly what the order of events was, and which components were involved in the request. If some step takes a long time, it is easy to tell where the problem is.
## Why OpenTelemetry?
It's important that Kubernetes works well for everyone, regardless of who manages your infrastructure, or which vendors you choose to integrate with. That is particularly true for Kubernetes' integrations with telemetry solutions. OpenTelemetry, being a CNCF project, shares these core values, and is creating exactly what we need in Kubernetes: A set of open standards for Tracing client library APIs and a standard trace format. By using OpenTelemetry, we can ensure users have the freedom to choose their backend, and ensure vendors have a level playing field. The timing couldn't be better: the OpenTelemetry golang API and SDK are very close to their 1.0 release, and will soon offer backwards-compatibility for these open standards.
## Why instrument the API Server?
The Kubernetes API Server is a great candidate for tracing for a few reasons:
* It follows the standard "RPC" model (serve a request by making requests to downstream components), which makes it easy to instrument.
* Users are latency-sensitive: If a request takes more than 10 seconds to complete, many clients will time-out.
* It has a complex service topology: A single request could require consulting a dozen webhooks, or involve multiple requests to etcd.
## Trying out APIServer Tracing with a webhook
### Enabling API Server Tracing
1. Enable the APIServerTracing [feature-gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/).
2. Set our configuration for tracing by pointing the `--tracing-config-file` flag on the kube-apiserver at our config file, which contains:
```yaml
apiVersion: apiserver.config.k8s.io/v1alpha1
kind: TracingConfiguration
# 1% sampling rate
samplingRatePerMillion: 10000
```
### Enabling Etcd Tracing
Add `--experimental-enable-distributed-tracing`, `--experimental-distributed-tracing-address=0.0.0.0:4317`, `--experimental-distributed-tracing-service-name=etcd` flags to etcd to enable tracing. Note that this traces every request, so it will probably generate a lot of traces if you enable it.
### Example Trace: List Nodes
I could've used any trace backend, but decided to use Jaeger, since it is one of the most popular open-source tracing projects. I deployed [the Jaeger All-in-one container](https://hub.docker.com/r/jaegertracing/all-in-one) in my cluster, deployed [the OpenTelemetry collector](https://github.com/open-telemetry/opentelemetry-collector) on my control-plane node ([example](https://github.com/dashpole/dashpole_demos/tree/master/otel/controlplane)), and captured traces like this one:
![Jaeger screenshot showing API server and etcd trace](/images/blog/2021-09-03-api-server-tracing/example-trace-1.png "Jaeger screenshot showing API server and etcd trace")
The teal lines are from the API Server, and includes it serving a request to `/api/v1/nodes`, and issuing a grpc `Range` RPC to ETCD. The yellow-ish line is from ETCD handling the `Range` RPC.
### Example Trace: Create Pod with Mutating Webhook
I instrumented the [example webhook](https://github.com/kubernetes-sigs/controller-runtime/tree/master/examples/builtins) with OpenTelemetry (I had to [patch](https://github.com/dashpole/controller-runtime/commit/85fdda7ba03dd2c22ef62c1a3dbdf5aa651f90da) controller-runtime, but it makes a neat demo), and routed traces to Jaeger as well. I collected traces like this one:
![Jaeger screenshot showing API server, admission webhook, and etcd trace](/images/blog/2021-09-03-api-server-tracing/example-trace-2.png "Jaeger screenshot showing API server, admission webhook, and etcd trace")
Compared with the previous trace, there are two new spans: A teal span from the API Server making a request to the admission webhook, and a brown span from the admission webhook serving the request. Even if you didn't instrument your webhook, you would still get the span from the API Server making the request to the webhook.
## Get involved!
As this is our first attempt at adding distributed tracing to a Kubernetes component, there is probably a lot we can improve! If my struggles resonated with you, or if you just want to try out the latest Kubernetes has to offer, please give the feature a try and open issues with any problem you encountered and ways you think the feature could be improved.
This is just the very beginning of what we can do with distributed tracing in Kubernetes. If there are other components you think would benefit from distributed tracing, or want to help bring API Server Tracing to GA, join sig-instrumentation at our [regular meetings](https://github.com/kubernetes/community/tree/master/sig-instrumentation#instrumentation-special-interest-group) and get involved!
@@ -0,0 +1,287 @@
---
layout: blog
title: "Introducing Single Pod Access Mode for PersistentVolumes"
date: 2021-09-13
slug: read-write-once-pod-access-mode-alpha
---
**Author:** Chris Henzie (Google)
Last month's release of Kubernetes v1.22 introduced a new ReadWriteOncePod access mode for [PersistentVolumes](/docs/concepts/storage/persistent-volumes/#persistent-volumes) and [PersistentVolumeClaims](/docs/concepts/storage/persistent-volumes/#persistentvolumeclaims).
With this alpha feature, Kubernetes allows you to restrict volume access to a single pod in the cluster.
## What are access modes and why are they important?
When using storage, there are different ways to model how that storage is consumed.
For example, a storage system like a network file share can have many users all reading and writing data simultaneously.
In other cases maybe everyone is allowed to read data but not write it.
For highly sensitive data, maybe only one user is allowed to read and write data but nobody else.
In the world of Kubernetes, [access modes](/docs/concepts/storage/persistent-volumes/#access-modes) are the way you can define how durable storage is consumed.
These access modes are a part of the spec for PersistentVolumes (PVs) and PersistentVolumeClaims (PVCs).
```yaml
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: shared-cache
spec:
accessModes:
- ReadWriteMany # Allow many pods to access shared-cache simultaneously.
resources:
requests:
storage: 1Gi
```
Before v1.22, Kubernetes offered three access modes for PVs and PVCs:
- ReadWriteOnce &ndash; the volume can be mounted as read-write by a single node
- ReadOnlyMany &ndash; the volume can be mounted read-only by many nodes
- ReadWriteMany &ndash; the volume can be mounted as read-write by many nodes
These access modes are enforced by Kubernetes components like the `kube-controller-manager` and `kubelet` to ensure only certain pods are allowed to access a given PersistentVolume.
## What is this new access mode and how does it work?
Kubernetes v1.22 introduced a fourth access mode for PVs and PVCs, that you can use for CSI volumes:
- ReadWriteOncePod &ndash; the volume can be mounted as read-write by a single pod
If you create a pod with a PVC that uses the ReadWriteOncePod access mode, Kubernetes ensures that pod is the only pod across your whole cluster that can read that PVC or write to it.
If you create another pod that references the same PVC with this access mode, the pod will fail to start because the PVC is already in use by another pod.
For example:
```
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Warning FailedScheduling 1s default-scheduler 0/1 nodes are available: 1 node has pod using PersistentVolumeClaim with the same name and ReadWriteOncePod access mode.
```
### How is this different than the ReadWriteOnce access mode?
The ReadWriteOnce access mode restricts volume access to a single *node*, which means it is possible for multiple pods on the same node to read from and write to the same volume.
This could potentially be a major problem for some applications, especially if they require at most one writer for data safety guarantees.
With ReadWriteOncePod these issues go away.
Set the access mode on your PVC, and Kubernetes guarantees that only a single pod has access.
## How do I use it?
The ReadWriteOncePod access mode is in alpha for Kubernetes v1.22 and is only supported for CSI volumes.
As a first step you need to enable the ReadWriteOncePod [feature gate](/docs/reference/command-line-tools-reference/feature-gates) for `kube-apiserver`, `kube-scheduler`, and `kubelet`.
You can enable the feature by setting command line arguments:
```
--feature-gates="...,ReadWriteOncePod=true"
```
You also need to update the following CSI sidecars to these versions or greater:
- [csi-provisioner:v3.0.0+](https://github.com/kubernetes-csi/external-provisioner/releases/tag/v3.0.0)
- [csi-attacher:v3.3.0+](https://github.com/kubernetes-csi/external-attacher/releases/tag/v3.3.0)
- [csi-resizer:v1.3.0+](https://github.com/kubernetes-csi/external-resizer/releases/tag/v1.3.0)
### Creating a PersistentVolumeClaim
In order to use the ReadWriteOncePod access mode for your PVs and PVCs, you will need to create a new PVC with the access mode:
```yaml
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: single-writer-only
spec:
accessModes:
- ReadWriteOncePod # Allow only a single pod to access single-writer-only.
resources:
requests:
storage: 1Gi
```
If your storage plugin supports [dynamic provisioning](/docs/concepts/storage/dynamic-provisioning/), new PersistentVolumes will be created with the ReadWriteOncePod access mode applied.
#### Migrating existing PersistentVolumes
If you have existing PersistentVolumes, they can be migrated to use ReadWriteOncePod.
In this example, we already have a "cat-pictures-pvc" PersistentVolumeClaim that is bound to a "cat-pictures-pv" PersistentVolume, and a "cat-pictures-writer" Deployment that uses this PersistentVolumeClaim.
As a first step, you need to edit your PersistentVolume's `spec.persistentVolumeReclaimPolicy` and set it to `Retain`.
This ensures your PersistentVolume will not be deleted when we delete the corresponding PersistentVolumeClaim:
```shell
kubectl patch pv cat-pictures-pv -p '{"spec":{"persistentVolumeReclaimPolicy":"Retain"}}'
```
Next you need to stop any workloads that are using the PersistentVolumeClaim bound to the PersistentVolume you want to migrate, and then delete the PersistentVolumeClaim.
Once that is done, you need to clear your PersistentVolume's `spec.claimRef.uid` to ensure PersistentVolumeClaims can bind to it upon recreation:
```shell
kubectl scale --replicas=0 deployment cat-pictures-writer
kubectl delete pvc cat-pictures-pvc
kubectl patch pv cat-pictures-pv -p '{"spec":{"claimRef":{"uid":""}}}'
```
After that you need to replace the PersistentVolume's access modes with ReadWriteOncePod:
```shell
kubectl patch pv cat-pictures-pv -p '{"spec":{"accessModes":["ReadWriteOncePod"]}}'
```
{{< note >}}
The ReadWriteOncePod access mode cannot be combined with other access modes.
Make sure ReadWriteOncePod is the only access mode on the PersistentVolume when updating, otherwise the request will fail.
{{< /note >}}
Next you need to modify your PersistentVolumeClaim to set ReadWriteOncePod as the only access mode.
You should also set your PersistentVolumeClaim's `spec.volumeName` to the name of your PersistentVolume.
Once this is done, you can recreate your PersistentVolumeClaim and start up your workloads:
```shell
# IMPORTANT: Make sure to edit your PVC in cat-pictures-pvc.yaml before applying. You need to:
# - Set ReadWriteOncePod as the only access mode
# - Set spec.volumeName to "cat-pictures-pv"
kubectl apply -f cat-pictures-pvc.yaml
kubectl apply -f cat-pictures-writer-deployment.yaml
```
Lastly you may edit your PersistentVolume's `spec.persistentVolumeReclaimPolicy` and set to it back to `Delete` if you previously changed it.
```shell
kubectl patch pv cat-pictures-pv -p '{"spec":{"persistentVolumeReclaimPolicy":"Delete"}}'
```
You can read [Configure a Pod to Use a PersistentVolume for Storage](/docs/tasks/configure-pod-container/configure-persistent-volume-storage/) for more details on working with PersistentVolumes and PersistentVolumeClaims.
## What volume plugins support this?
The only volume plugins that support this are CSI drivers.
SIG Storage does not plan to support this for in-tree plugins because they are being deprecated as part of [CSI migration](/blog/2019/12/09/kubernetes-1-17-feature-csi-migration-beta/#what-is-the-timeline-status).
Support may be considered for beta for users that prefer to use the legacy in-tree volume APIs with CSI migration enabled.
## As a storage vendor, how do I add support for this access mode to my CSI driver?
The ReadWriteOncePod access mode will work out of the box without any required updates to CSI drivers, but [does require updates to CSI sidecars](#update-your-csi-sidecars).
With that being said, if you would like to stay up to date with the latest changes to the CSI specification (v1.5.0+), read on.
Two new access modes were introduced to the CSI specification in order to disambiguate the legacy [`SINGLE_NODE_WRITER`](https://github.com/container-storage-interface/spec/blob/v1.5.0/csi.proto#L418-L420) access mode.
They are [`SINGLE_NODE_SINGLE_WRITER` and `SINGLE_NODE_MULTI_WRITER`](https://github.com/container-storage-interface/spec/blob/v1.5.0/csi.proto#L437-L447).
In order to communicate to sidecars (like the [external-provisioner](https://github.com/kubernetes-csi/external-provisioner)) that your driver understands and accepts these two new CSI access modes, your driver will also need to advertise the `SINGLE_NODE_MULTI_WRITER` capability for the [controller service](https://github.com/container-storage-interface/spec/blob/v1.5.0/csi.proto#L1073-L1081) and [node service](https://github.com/container-storage-interface/spec/blob/v1.5.0/csi.proto#L1515-L1524).
If you'd like to read up on the motivation for these access modes and capability bits, you can also read the [CSI Specification Changes, Volume Capabilities](https://github.com/kubernetes/enhancements/blob/master/keps/sig-storage/2485-read-write-once-pod-pv-access-mode/README.md#csi-specification-changes-volume-capabilities) section of KEP-2485 (ReadWriteOncePod PersistentVolume Access Mode).
### Update your CSI driver to use the new interface
As a first step you will need to update your driver's `container-storage-interface` dependency to v1.5.0+, which contains support for these new access modes and capabilities.
### Accept new CSI access modes
If your CSI driver contains logic for validating CSI access modes for requests , it may need updating.
If it currently accepts `SINGLE_NODE_WRITER`, it should be updated to also accept `SINGLE_NODE_SINGLE_WRITER` and `SINGLE_NODE_MULTI_WRITER`.
Using the [GCP PD CSI driver validation logic](https://github.com/kubernetes-sigs/gcp-compute-persistent-disk-csi-driver/blob/v1.2.2/pkg/gce-pd-csi-driver/utils.go#L116-L130) as an example, here is how it can be extended:
```diff
diff --git a/pkg/gce-pd-csi-driver/utils.go b/pkg/gce-pd-csi-driver/utils.go
index 281242c..b6c5229 100644
--- a/pkg/gce-pd-csi-driver/utils.go
+++ b/pkg/gce-pd-csi-driver/utils.go
@@ -123,6 +123,8 @@ func validateAccessMode(am *csi.VolumeCapability_AccessMode) error {
case csi.VolumeCapability_AccessMode_SINGLE_NODE_READER_ONLY:
case csi.VolumeCapability_AccessMode_MULTI_NODE_READER_ONLY:
case csi.VolumeCapability_AccessMode_MULTI_NODE_MULTI_WRITER:
+ case csi.VolumeCapability_AccessMode_SINGLE_NODE_SINGLE_WRITER:
+ case csi.VolumeCapability_AccessMode_SINGLE_NODE_MULTI_WRITER:
default:
return fmt.Errorf("%v access mode is not supported for for PD", am.GetMode())
}
```
### Advertise new CSI controller and node service capabilities
Your CSI driver will also need to return the new `SINGLE_NODE_MULTI_WRITER` capability as part of the `ControllerGetCapabilities` and `NodeGetCapabilities` RPCs.
Using the [GCP PD CSI driver capability advertisement logic](https://github.com/kubernetes-sigs/gcp-compute-persistent-disk-csi-driver/blob/v1.2.2/pkg/gce-pd-csi-driver/gce-pd-driver.go#L54-L77) as an example, here is how it can be extended:
```diff
diff --git a/pkg/gce-pd-csi-driver/gce-pd-driver.go b/pkg/gce-pd-csi-driver/gce-pd-driver.go
index 45903f3..0d7ea26 100644
--- a/pkg/gce-pd-csi-driver/gce-pd-driver.go
+++ b/pkg/gce-pd-csi-driver/gce-pd-driver.go
@@ -56,6 +56,8 @@ func (gceDriver *GCEDriver) SetupGCEDriver(name, vendorVersion string, extraVolu
csi.VolumeCapability_AccessMode_SINGLE_NODE_WRITER,
csi.VolumeCapability_AccessMode_MULTI_NODE_READER_ONLY,
csi.VolumeCapability_AccessMode_MULTI_NODE_MULTI_WRITER,
+ csi.VolumeCapability_AccessMode_SINGLE_NODE_SINGLE_WRITER,
+ csi.VolumeCapability_AccessMode_SINGLE_NODE_MULTI_WRITER,
}
gceDriver.AddVolumeCapabilityAccessModes(vcam)
csc := []csi.ControllerServiceCapability_RPC_Type{
@@ -67,12 +69,14 @@ func (gceDriver *GCEDriver) SetupGCEDriver(name, vendorVersion string, extraVolu
csi.ControllerServiceCapability_RPC_EXPAND_VOLUME,
csi.ControllerServiceCapability_RPC_LIST_VOLUMES,
csi.ControllerServiceCapability_RPC_LIST_VOLUMES_PUBLISHED_NODES,
+ csi.ControllerServiceCapability_RPC_SINGLE_NODE_MULTI_WRITER,
}
gceDriver.AddControllerServiceCapabilities(csc)
ns := []csi.NodeServiceCapability_RPC_Type{
csi.NodeServiceCapability_RPC_STAGE_UNSTAGE_VOLUME,
csi.NodeServiceCapability_RPC_EXPAND_VOLUME,
csi.NodeServiceCapability_RPC_GET_VOLUME_STATS,
+ csi.NodeServiceCapability_RPC_SINGLE_NODE_MULTI_WRITER,
}
gceDriver.AddNodeServiceCapabilities(ns)
```
### Implement `NodePublishVolume` behavior
The CSI spec outlines expected behavior for the `NodePublishVolume` RPC when called more than once for the same volume but with different arguments (like the target path).
Please refer to [the second table in the NodePublishVolume section of the CSI spec](https://github.com/container-storage-interface/spec/blob/v1.5.0/spec.md#nodepublishvolume) for more details on expected behavior when implementing in your driver.
### Update your CSI sidecars
When deploying your CSI drivers, you must update the following CSI sidecars to versions that depend on CSI spec v1.5.0+ and the Kubernetes v1.22 API.
The minimum required versions are:
- [csi-provisioner:v3.0.0+](https://github.com/kubernetes-csi/external-provisioner/releases/tag/v3.0.0)
- [csi-attacher:v3.3.0+](https://github.com/kubernetes-csi/external-attacher/releases/tag/v3.3.0)
- [csi-resizer:v1.3.0+](https://github.com/kubernetes-csi/external-resizer/releases/tag/v1.3.0)
## Whats next?
As part of the beta graduation for this feature, SIG Storage plans to update the Kubenetes scheduler to support pod preemption in relation to ReadWriteOncePod storage.
This means if two pods request a PersistentVolumeClaim with ReadWriteOncePod, the pod with highest priority will gain access to the PersistentVolumeClaim and any pod with lower priority will be preempted from the node and be unable to access the PersistentVolumeClaim.
## How can I learn more?
Please see [KEP-2485](https://github.com/kubernetes/enhancements/blob/master/keps/sig-storage/2485-read-write-once-pod-pv-access-mode/README.md) for more details on the ReadWriteOncePod access mode and motivations for CSI spec changes.
## How do I get involved?
The [Kubernetes #csi Slack channel](https://kubernetes.slack.com/messages/csi) and any of the [standard SIG Storage communication channels](https://github.com/kubernetes/community/blob/master/sig-storage/README.md#contact) are great mediums to reach out to the SIG Storage and the CSI teams.
Special thanks to the following people for their insightful reviews and design considerations:
* Abdullah Gharaibeh (ahg-g)
* Aldo Culquicondor (alculquicondor)
* Ben Swartzlander (bswartz)
* Deep Debroy (ddebroy)
* Hemant Kumar (gnufied)
* Humble Devassy Chirammal (humblec)
* James DeFelice (jdef)
* Jan Šafránek (jsafrane)
* Jing Xu (jingxu97)
* Jordan Liggitt (liggitt)
* Michelle Au (msau42)
* Saad Ali (saad-ali)
* Tim Hockin (thockin)
* Xing Yang (xing-yang)
If youre interested in getting involved with the design and development of CSI or any part of the Kubernetes storage system, join the [Kubernetes Storage Special Interest Group](https://github.com/kubernetes/community/tree/master/sig-storage) (SIG).
Were rapidly growing and always welcome new contributors.
@@ -37,6 +37,24 @@ to the labels, each `EndpointSlice` that is managed on behalf of a Service has
an owner reference. Owner references help different parts of Kubernetes avoid
interfering with objects they dont control.
{{< note >}}
Cross-namespace owner references are disallowed by design.
Namespaced dependents can specify cluster-scoped or namespaced owners.
A namespaced owner **must** exist in the same namespace as the dependent.
If it does not, the owner reference is treated as absent, and the dependent
is subject to deletion once all owners are verified absent.
Cluster-scoped dependents can only specify cluster-scoped owners.
In v1.20+, if a cluster-scoped dependent specifies a namespaced kind as an owner,
it is treated as having an unresolvable owner reference, and is not able to be garbage collected.
In v1.20+, if the garbage collector detects an invalid cross-namespace `ownerReference`,
or a cluster-scoped dependent with an `ownerReference` referencing a namespaced kind, a warning Event
with a reason of `OwnerRefInvalidNamespace` and an `involvedObject` of the invalid dependent is reported.
You can check for that kind of Event by running
`kubectl get events -A --field-selector=reason=OwnerRefInvalidNamespace`.
{{< /note >}}
## Cascading deletion {#cascading-deletion}
Kubernetes checks for and deletes objects that no longer have owner
+76 -46
View File
@@ -122,6 +122,9 @@ To mark a Node unschedulable, run:
kubectl cordon $NODENAME
```
See [Safely Drain a Node](/docs/tasks/administer-cluster/safely-drain-node/)
for more details.
{{< note >}}
Pods that are part of a {{< glossary_tooltip term_id="daemonset" >}} tolerate
being run on an unschedulable Node. DaemonSets typically provide node-local services
@@ -162,8 +165,8 @@ The `conditions` field describes the status of all `Running` nodes. Examples of
| Node Condition | Description |
|----------------------|-------------|
| `Ready` | `True` if the node is healthy and ready to accept pods, `False` if the node is not healthy and is not accepting pods, and `Unknown` if the node controller has not heard from the node in the last `node-monitor-grace-period` (default is 40 seconds) |
| `DiskPressure` | `True` if pressure exists on the disk size--that is, if the disk capacity is low; otherwise `False` |
| `MemoryPressure` | `True` if pressure exists on the node memory--that is, if the node memory is low; otherwise `False` |
| `DiskPressure` | `True` if pressure exists on the disk sizethat is, if the disk capacity is low; otherwise `False` |
| `MemoryPressure` | `True` if pressure exists on the node memorythat is, if the node memory is low; otherwise `False` |
| `PIDPressure` | `True` if pressure exists on the processes—that is, if there are too many processes on the node; otherwise `False` |
| `NetworkUnavailable` | `True` if the network for the node is not correctly configured, otherwise `False` |
{{< /table >}}
@@ -174,7 +177,8 @@ If you use command-line tools to print details of a cordoned Node, the Condition
cordoned nodes are marked Unschedulable in their spec.
{{< /note >}}
The node condition is represented as a JSON object. For example, the following structure describes a healthy node:
In the Kubernetes API, a node's condition is represented as part of the `.status`
of the Node resource. For example, the following JSON structure describes a healthy node:
```json
"conditions": [
@@ -189,7 +193,17 @@ The node condition is represented as a JSON object. For example, the following s
]
```
If the Status of the Ready condition remains `Unknown` or `False` for longer than the `pod-eviction-timeout` (an argument passed to the {{< glossary_tooltip text="kube-controller-manager" term_id="kube-controller-manager" >}}), then all the Pods on the node are scheduled for deletion by the node controller. The default eviction timeout duration is **five minutes**. In some cases when the node is unreachable, the API server is unable to communicate with the kubelet on the node. The decision to delete the pods cannot be communicated to the kubelet until communication with the API server is re-established. In the meantime, the pods that are scheduled for deletion may continue to run on the partitioned node.
If the `status` of the Ready condition remains `Unknown` or `False` for longer
than the `pod-eviction-timeout` (an argument passed to the
{{< glossary_tooltip text="kube-controller-manager" term_id="kube-controller-manager"
>}}), then the [node controller](#node-controller) triggers
{{< glossary_tooltip text="API-initiated eviction" term_id="api-eviction" >}}
for all Pods assigned to that node. The default eviction timeout duration is
**five minutes**.
In some cases when the node is unreachable, the API server is unable to communicate
with the kubelet on the node. The decision to delete the pods cannot be communicated to
the kubelet until communication with the API server is re-established. In the meantime,
the pods that are scheduled for deletion may continue to run on the partitioned node.
The node controller does not force delete pods until it is confirmed that they have stopped
running in the cluster. You can see the pods that might be running on an unreachable node as
@@ -199,10 +213,12 @@ may need to delete the node object by hand. Deleting the node object from Kubern
all the Pod objects running on the node to be deleted from the API server and frees up their
names.
The node lifecycle controller automatically creates
[taints](/docs/concepts/scheduling-eviction/taint-and-toleration/) that represent conditions.
When problems occur on nodes, the Kubernetes control plane automatically creates
[taints](/docs/concepts/scheduling-eviction/taint-and-toleration/) that match the conditions
affecting the node.
The scheduler takes the Node's taints into consideration when assigning a Pod to a Node.
Pods can also have tolerations which let them tolerate a Node's taints.
Pods can also have {{< glossary_tooltip text="tolerations" term_id="toleration" >}} that let
them run on a Node even though it has a specific taint.
See [Taint Nodes by Condition](/docs/concepts/scheduling-eviction/taint-and-toleration/#taint-nodes-by-condition)
for more details.
@@ -222,10 +238,43 @@ on a Node.
### Info
Describes general information about the node, such as kernel version, Kubernetes version (kubelet and kube-proxy version), Docker version (if used), and OS name.
This information is gathered by Kubelet from the node.
Describes general information about the node, such as kernel version, Kubernetes
version (kubelet and kube-proxy version), container runtime details, and which
operating system the node uses.
The kubelet gathers this information from the node and publishes it into
the Kubernetes API.
### Node controller
## Heartbeats
Heartbeats, sent by Kubernetes nodes, help your cluster determine the
availability of each node, and to take action when failures are detected.
For nodes there are two forms of heartbeats:
* updates to the `.status` of a Node
* [Lease](/docs/reference/kubernetes-api/cluster-resources/lease-v1/) objects
within the `kube-node-lease`
{{< glossary_tooltip term_id="namespace" text="namespace">}}.
Each Node has an associated Lease object.
Compared to updates to `.status` of a Node, a Lease is a lightweight resource.
Using Leases for heartbeats reduces the performance impact of these updates
for large clusters.
The kubelet is responsible for creating and updating the `.status` of Nodes,
and for updating their related Leases.
- The kubelet updates the node's `.status` either when there is change in status
or if there has been no update for a configured interval. The default interval
for `.status` updates to Nodes is 5 minutes, which is much longer than the 40
second default timeout for unreachable nodes.
- The kubelet creates and then updates its Lease object every 10 seconds
(the default update interval). Lease updates occur independently from
updates to the Node's `.status`. If the Lease update fails, the kubelet retries,
using exponential backoff that starts at 200 milliseconds and capped at 7 seconds.
## Node controller
The node {{< glossary_tooltip text="controller" term_id="controller" >}} is a
Kubernetes control plane component that manages various aspects of nodes.
@@ -241,39 +290,18 @@ controller deletes the node from its list of nodes.
The third is monitoring the nodes' health. The node controller is
responsible for:
- Updating the NodeReady condition of NodeStatus to ConditionUnknown when a node
becomes unreachable, as the node controller stops receiving heartbeats for some
reason such as the node being down.
- Evicting all the pods from the node using graceful termination if
the node continues to be unreachable. The default timeouts are 40s to start
reporting ConditionUnknown and 5m after that to start evicting pods.
- In the case that a node becomes unreachable, updating the NodeReady condition
of within the Node's `.status`. In this case the node controller sets the
NodeReady condition to `ConditionUnknown`.
- If a node remains unreachable: triggering
[API-initiated eviction](/docs/concepts/scheduling-eviction/api-eviction/)
for all of the Pods on the unreachable node. By default, the node controller
waits 5 minutes between marking the node as `ConditionUnknown` and submitting
the first eviction request.
The node controller checks the state of each node every `--node-monitor-period` seconds.
#### Heartbeats
Heartbeats, sent by Kubernetes nodes, help determine the availability of a node.
There are two forms of heartbeats: updates of `NodeStatus` and the
[Lease object](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#lease-v1-coordination-k8s-io).
Each Node has an associated Lease object in the `kube-node-lease`
{{< glossary_tooltip term_id="namespace" text="namespace">}}.
Lease is a lightweight resource, which improves the performance
of the node heartbeats as the cluster scales.
The kubelet is responsible for creating and updating the `NodeStatus` and
a Lease object.
- The kubelet updates the `NodeStatus` either when there is change in status
or if there has been no update for a configured interval. The default interval
for `NodeStatus` updates is 5 minutes, which is much longer than the 40 second default
timeout for unreachable nodes.
- The kubelet creates and then updates its Lease object every 10 seconds
(the default update interval). Lease updates occur independently from the
`NodeStatus` updates. If the Lease update fails, the kubelet retries with
exponential backoff starting at 200 milliseconds and capped at 7 seconds.
#### Reliability
### Rate limits on eviction
In most cases, the node controller limits the eviction rate to
`--node-eviction-rate` (default 0.1) per second, meaning it won't evict pods
@@ -281,7 +309,7 @@ from more than 1 node per 10 seconds.
The node eviction behavior changes when a node in a given availability zone
becomes unhealthy. The node controller checks what percentage of nodes in the zone
are unhealthy (NodeReady condition is ConditionUnknown or ConditionFalse) at
are unhealthy (NodeReady condition is `ConditionUnknown` or `ConditionFalse`) at
the same time:
- If the fraction of unhealthy nodes is at least `--unhealthy-zone-threshold`
(default 0.55), then the eviction rate is reduced.
@@ -293,15 +321,17 @@ the same time:
The reason these policies are implemented per availability zone is because one
availability zone might become partitioned from the master while the others remain
connected. If your cluster does not span multiple cloud provider availability zones,
then there is only one availability zone (i.e. the whole cluster).
then the eviction mechanism does not take per-zone unavailability into account.
A key reason for spreading your nodes across availability zones is so that the
workload can be shifted to healthy zones when one entire zone goes down.
Therefore, if all nodes in a zone are unhealthy, then the node controller evicts at
the normal rate of `--node-eviction-rate`. The corner case is when all zones are
completely unhealthy (i.e. there are no healthy nodes in the cluster). In such a
case, the node controller assumes that there is some problem with master
connectivity and stops all evictions until some connectivity is restored.
completely unhealthy (none of the nodes in the cluster are healthy). In such a
case, the node controller assumes that there is some problem with connectivity
between the control plane and the nodes, and doesn't perform any evictions.
(If there has been an outage and some nodes reappear, the node controller does
evict pods from the remaining nodes that are unhealthy or unreachable).
The node controller is also responsible for evicting pods running on nodes with
`NoExecute` taints, unless those pods tolerate that taint.
@@ -309,7 +339,7 @@ The node controller also adds {{< glossary_tooltip text="taints" term_id="taint"
corresponding to node problems like node unreachable or not ready. This means
that the scheduler won't place Pods onto unhealthy nodes.
### Node capacity
## Resource capacity tracking {#node-capacity}
Node objects track information about the Node's resource capacity: for example, the amount
of memory available and the number of CPUs.
@@ -81,7 +81,7 @@ rotate an application's logs automatically.
As an example, you can find detailed information about how `kube-up.sh` sets
up logging for COS image on GCP in the corresponding
[`configure-helper` script](https://github.com/kubernetes/kubernetes/blob/{{< param "githubbranch" >}}/cluster/gce/gci/configure-helper.sh).
[`configure-helper` script](https://github.com/kubernetes/kubernetes/blob/master/cluster/gce/gci/configure-helper.sh).
When using a **CRI container runtime**, the kubelet is responsible for rotating the logs and managing the logging directory structure.
The kubelet sends this information to the CRI container runtime and the runtime writes the container logs to the given location.
@@ -160,7 +160,7 @@ If you're interested in learning more about `kubectl`, go ahead and read [kubect
The examples we've used so far apply at most a single label to any resource. There are many scenarios where multiple labels should be used to distinguish sets from one another.
For instance, different applications would use different values for the `app` label, but a multi-tier application, such as the [guestbook example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/guestbook/), would additionally need to distinguish each tier. The frontend could carry the following labels:
For instance, different applications would use different values for the `app` label, but a multi-tier application, such as the [guestbook example](https://github.com/kubernetes/examples/tree/master/guestbook/), would additionally need to distinguish each tier. The frontend could carry the following labels:
```yaml
labels:
@@ -61,6 +61,11 @@ You can write a Pod `spec` that refers to a ConfigMap and configures the contain
in that Pod based on the data in the ConfigMap. The Pod and the ConfigMap must be in
the same {{< glossary_tooltip text="namespace" term_id="namespace" >}}.
{{< note >}}
The `spec` of a {{< glossary_tooltip text="static Pod" term_id="static-pod" >}} cannot refer to a ConfigMap
or any other API objects.
{{< /note >}}
Here's an example ConfigMap that has some keys with single values,
and other keys where the value looks like a fragment of a configuration
format.
@@ -181,8 +181,9 @@ When using Docker:
flag in the `docker run` command.
- The `spec.containers[].resources.limits.cpu` is converted to its millicore value and
multiplied by 100. The resulting value is the total amount of CPU time that a container can use
every 100ms. A container cannot use more than its share of CPU time during this interval.
multiplied by 100. The resulting value is the total amount of CPU time in microseconds
that a container can use every 100ms. A container cannot use more than its share of
CPU time during this interval.
{{< note >}}
The default quota period is 100ms. The minimum resolution of CPU quota is 1ms.
@@ -337,6 +338,9 @@ spec:
ephemeral-storage: "2Gi"
limits:
ephemeral-storage: "4Gi"
volumeMounts:
- name: ephemeral
mountPath: "/tmp"
- name: log-aggregator
image: images.my-company.example/log-aggregator:v6
resources:
@@ -344,6 +348,12 @@ spec:
ephemeral-storage: "2Gi"
limits:
ephemeral-storage: "4Gi"
volumeMounts:
- name: ephemeral
mountPath: "/tmp"
volumes:
- name: ephemeral
emptyDir: {}
```
### How Pods with ephemeral-storage requests are scheduled
@@ -21,7 +21,7 @@ This is a living document. If you think of something that is not on this list bu
- Write your configuration files using YAML rather than JSON. Though these formats can be used interchangeably in almost all scenarios, YAML tends to be more user-friendly.
- Group related objects into a single file whenever it makes sense. One file is often easier to manage than several. See the [guestbook-all-in-one.yaml](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/guestbook/all-in-one/guestbook-all-in-one.yaml) file as an example of this syntax.
- Group related objects into a single file whenever it makes sense. One file is often easier to manage than several. See the [guestbook-all-in-one.yaml](https://github.com/kubernetes/examples/tree/master/guestbook/all-in-one/guestbook-all-in-one.yaml) file as an example of this syntax.
- Note also that many `kubectl` commands can be called on a directory. For example, you can call `kubectl apply` on a directory of config files.
@@ -63,7 +63,7 @@ DNS server watches the Kubernetes API for new `Services` and creates a set of DN
## Using Labels
- Define and use [labels](/docs/concepts/overview/working-with-objects/labels/) that identify __semantic attributes__ of your application or Deployment, such as `{ app: myapp, tier: frontend, phase: test, deployment: v3 }`. You can use these labels to select the appropriate Pods for other resources; for example, a Service that selects all `tier: frontend` Pods, or all `phase: test` components of `app: myapp`. See the [guestbook](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/guestbook/) app for examples of this approach.
- Define and use [labels](/docs/concepts/overview/working-with-objects/labels/) that identify __semantic attributes__ of your application or Deployment, such as `{ app: myapp, tier: frontend, phase: test, deployment: v3 }`. You can use these labels to select the appropriate Pods for other resources; for example, a Service that selects all `tier: frontend` Pods, or all `phase: test` components of `app: myapp`. See the [guestbook](https://github.com/kubernetes/examples/tree/master/guestbook/) app for examples of this approach.
A Service can be made to span multiple Deployments by omitting release-specific labels from its selector. When you need to update a running service without downtime, use a [Deployment](/docs/concepts/workloads/controllers/deployment/).
@@ -73,32 +73,6 @@ A desired state of an object is described by a Deployment, and if changes to tha
- You can manipulate labels for debugging. Because Kubernetes controllers (such as ReplicaSet) and Services match to Pods using selector labels, removing the relevant labels from a Pod will stop it from being considered by a controller or from being served traffic by a Service. If you remove the labels of an existing Pod, its controller will create a new Pod to take its place. This is a useful way to debug a previously "live" Pod in a "quarantine" environment. To interactively remove or add labels, use [`kubectl label`](/docs/reference/generated/kubectl/kubectl-commands#label).
## Container Images
The [imagePullPolicy](/docs/concepts/containers/images/#updating-images) and the tag of the image affect when the [kubelet](/docs/reference/command-line-tools-reference/kubelet/) attempts to pull the specified image.
- `imagePullPolicy: IfNotPresent`: the image is pulled only if it is not already present locally.
- `imagePullPolicy: Always`: every time the kubelet launches a container, the kubelet queries the container image registry to resolve the name to an image digest. If the kubelet has a container image with that exact digest cached locally, the kubelet uses its cached image; otherwise, the kubelet downloads (pulls) the image with the resolved digest, and uses that image to launch the container.
- `imagePullPolicy` is omitted and either the image tag is `:latest` or it is omitted: `imagePullPolicy` is automatically set to `Always`. Note that this will _not_ be updated to `IfNotPresent` if the tag changes value.
- `imagePullPolicy` is omitted and the image tag is present but not `:latest`: `imagePullPolicy` is automatically set to `IfNotPresent`. Note that this will _not_ be updated to `Always` if the tag is later removed or changed to `:latest`.
- `imagePullPolicy: Never`: the image is assumed to exist locally. No attempt is made to pull the image.
{{< note >}}
To make sure the container always uses the same version of the image, you can specify its [digest](https://docs.docker.com/engine/reference/commandline/pull/#pull-an-image-by-digest-immutable-identifier); replace `<image-name>:<tag>` with `<image-name>@<digest>` (for example, `image@sha256:45b23dee08af5e43a7fea6c4cf9c25ccf269ee113168c19722f87876677c5cb2`). The digest uniquely identifies a specific version of the image, so it is never updated by Kubernetes unless you change the digest value.
{{< /note >}}
{{< note >}}
You should avoid using the `:latest` tag when deploying containers in production as it is harder to track which version of the image is running and more difficult to roll back properly.
{{< /note >}}
{{< note >}}
The caching semantics of the underlying image provider make even `imagePullPolicy: Always` efficient, as long as the registry is reliably accessible. With Docker, for example, if the image already exists, the pull attempt is fast because all image layers are cached and no image download is needed.
{{< /note >}}
## Using kubectl
- Use `kubectl apply -f <directory>`. This looks for Kubernetes configuration in all `.yaml`, `.yml`, and `.json` files in `<directory>` and passes it to `apply`.
@@ -75,9 +75,9 @@ precedence.
## Types of Secret {#secret-types}
When creating a Secret, you can specify its type using the `type` field of
the [`Secret`](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#secret-v1-core)
resource, or certain equivalent `kubectl` command line flags (if available).
The Secret type is used to facilitate programmatic handling of the Secret data.
a Secret resource, or certain equivalent `kubectl` command line flags (if available).
The `type` of a Secret is used to facilitate programmatic handling of different
kinds of confidential data.
Kubernetes provides several builtin types for some common usage scenarios.
These types vary in terms of the validations performed and the constraints
@@ -833,7 +833,10 @@ are obtained from the API server.
This includes any Pods created using `kubectl`, or indirectly via a replication
controller. It does not include Pods created as a result of the kubelet
`--manifest-url` flag, its `--config` flag, or its REST API (these are
not common ways to create Pods.)
not common ways to create Pods).
The `spec` of a {{< glossary_tooltip text="static Pod" term_id="static-pod" >}} cannot refer to a Secret
or any other API objects.
Secrets must be created before they are consumed in Pods as environment
variables unless they are marked as optional. References to secrets that do
@@ -1252,3 +1255,4 @@ for secret data, so that the secrets are not stored in the clear into {{< glossa
- Learn how to [manage Secret using `kubectl`](/docs/tasks/configmap-secret/managing-secret-using-kubectl/)
- Learn how to [manage Secret using config file](/docs/tasks/configmap-secret/managing-secret-using-config-file/)
- Learn how to [manage Secret using kustomize](/docs/tasks/configmap-secret/managing-secret-using-kustomize/)
- Read the [API reference](/docs/reference/kubernetes-api/config-and-storage-resources/secret-v1/) for `Secret`
@@ -52,7 +52,7 @@ FOO_SERVICE_PORT=<the port the service is running on>
```
Services have dedicated IP addresses and are available to the Container via DNS,
if [DNS addon](https://releases.k8s.io/{{< param "githubbranch" >}}/cluster/addons/dns/) is enabled. 
if [DNS addon](https://releases.k8s.io/{{< param "fullversion" >}}/cluster/addons/dns/) is enabled. 
+73 -15
View File
@@ -39,14 +39,6 @@ There are additional rules about where you can place the separator
characters (`_`, `-`, and `.`) inside an image tag.
If you don't specify a tag, Kubernetes assumes you mean the tag `latest`.
{{< caution >}}
You should avoid using the `latest` tag when deploying containers in production,
as it is harder to track which version of the image is running and more difficult
to roll back to a working version.
Instead, specify a meaningful tag such as `v1.42.0`.
{{< /caution >}}
## Updating images
When you first create a {{< glossary_tooltip text="Deployment" term_id="deployment" >}},
@@ -57,13 +49,68 @@ specified. This policy causes the
{{< glossary_tooltip text="kubelet" term_id="kubelet" >}} to skip pulling an
image if it already exists.
If you would like to always force a pull, you can do one of the following:
### Image pull policy
- set the `imagePullPolicy` of the container to `Always`.
- omit the `imagePullPolicy` and use `:latest` as the tag for the image to use;
Kubernetes will set the policy to `Always`.
- omit the `imagePullPolicy` and the tag for the image to use.
- enable the [AlwaysPullImages](/docs/reference/access-authn-authz/admission-controllers/#alwayspullimages) admission controller.
The `imagePullPolicy` for a container and the tag of the image affect when the
[kubelet](/docs/reference/command-line-tools-reference/kubelet/) attempts to pull (download) the specified image.
Here's a list of the values you can set for `imagePullPolicy` and the effects
these values have:
`IfNotPresent`
: the image is pulled only if it is not already present locally.
`Always`
: every time the kubelet launches a container, the kubelet queries the container
image registry to resolve the name to an image
[digest](https://docs.docker.com/engine/reference/commandline/pull/#pull-an-image-by-digest-immutable-identifier). If the kubelet has a
container image with that exact digest cached locally, the kubelet uses its cached
image; otherwise, the kubelet pulls the image with the resolved digest,
and uses that image to launch the container.
`Never`
: the kubelet does not try fetching the image. If the image is somehow already present
locally, the kubelet attempts to start the container; otherwise, startup fails.
See [pre-pulled images](#pre-pulled-images) for more details.
The caching semantics of the underlying image provider make even
`imagePullPolicy: Always` efficient, as long as the registry is reliably accessible.
Your container runtime can notice that the image layers already exist on the node
so that they don't need to be downloaded again.
{{< note >}}
You should avoid using the `:latest` tag when deploying containers in production as
it is harder to track which version of the image is running and more difficult to
roll back properly.
Instead, specify a meaningful tag such as `v1.42.0`.
{{< /note >}}
To make sure the Pod always uses the same version of a container image, you can specify
the image's digest;
replace `<image-name>:<tag>` with `<image-name>@<digest>`
(for example, `image@sha256:45b23dee08af5e43a7fea6c4cf9c25ccf269ee113168c19722f87876677c5cb2`).
When using image tags, if the image registry were to change the code that the tag on that image represents, you might end up with a mix of Pods running the old and new code. An image digest uniquely identifies a specific version of the image, so Kubernetes runs the same code every time it starts a container with that image name and digest specified. Specifying an image fixes the code that you run so that a change at the registry cannot lead to that mix of versions.
There are third-party [admission controllers](/docs/reference/access-authn-authz/admission-controllers/)
that mutate Pods (and pod templates) when they are created, so that the
running workload is defined based on an image digest rather than a tag.
That might be useful if you want to make sure that all your workload is
running the same code no matter what tag changes happen at the registry.
#### Default image pull policy {#imagepullpolicy-defaulting}
When you (or a controller) submit a new Pod to the API server, your cluster sets the
`imagePullPolicy` field when specific conditions are met:
- if you omit the `imagePullPolicy` field, and the tag for the container image is
`:latest`, `imagePullPolicy` is automatically set to `Always`;
- if you omit the `imagePullPolicy` field, and you don't specify the tag for the
container image, `imagePullPolicy` is automatically set to `Always`;
- if you omit the `imagePullPolicy` field, and you don't specify the tag for the
container image that isn't `:latest`, the `imagePullPolicy` is automatically set to
`IfNotPresent`.
{{< note >}}
The value of `imagePullPolicy` of the container is always set when the object is
@@ -75,7 +122,17 @@ For example, if you create a Deployment with an image whose tag is _not_
the pull policy of any object after its initial creation.
{{< /note >}}
When `imagePullPolicy` is defined without a specific value, it is also set to `Always`.
#### Required image pull
If you would like to always force a pull, you can do one of the following:
- Set the `imagePullPolicy` of the container to `Always`.
- Omit the `imagePullPolicy` and use `:latest` as the tag for the image to use;
Kubernetes will set the policy to `Always` when you submit the Pod.
- Omit the `imagePullPolicy` and the tag for the image to use;
Kubernetes will set the policy to `Always` when you submit the Pod.
- Enable the [AlwaysPullImages](/docs/reference/access-authn-authz/admission-controllers/#alwayspullimages) admission controller.
### ImagePullBackOff
@@ -328,6 +385,7 @@ common use cases and suggested solutions.
If you need access to multiple registries, you can create one secret for each registry.
Kubelet will merge any `imagePullSecrets` into a single virtual `.docker/config.json`
## {{% heading "whatsnext" %}}
* Read the [OCI Image Manifest Specification](https://github.com/opencontainers/image-spec/blob/master/manifest.md).
@@ -1,5 +1,5 @@
---
title: Extending the Kubernetes API with the aggregation layer
title: Kubernetes API Aggregation Layer
reviewers:
- lavalamp
- cheftako
@@ -11,7 +11,7 @@ weight: 20
<!-- overview -->
The aggregation layer allows Kubernetes to be extended with additional APIs, beyond what is offered by the core Kubernetes APIs.
The additional APIs can either be ready-made solutions such as [service-catalog](/docs/concepts/extend-kubernetes/service-catalog/), or APIs that you develop yourself.
The additional APIs can either be ready-made solutions such as a [metrics server](https://github.com/kubernetes-sigs/metrics-server), or APIs that you develop yourself.
The aggregation layer is different from [Custom Resources](/docs/concepts/extend-kubernetes/api-extension/custom-resources/), which are a way to make the {{< glossary_tooltip term_id="kube-apiserver" text="kube-apiserver" >}} recognise new kinds of object.
@@ -34,7 +34,7 @@ If your extension API server cannot achieve that latency requirement, consider m
* To get the aggregator working in your environment, [configure the aggregation layer](/docs/tasks/extend-kubernetes/configure-aggregation-layer/).
* Then, [setup an extension api-server](/docs/tasks/extend-kubernetes/setup-extension-api-server/) to work with the aggregation layer.
* Also, learn how to [extend the Kubernetes API using Custom Resource Definitions](/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definitions/).
* Read the specification for [APIService](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#apiservice-v1-apiregistration-k8s-io)
* Read about [APIService](/docs/reference/kubernetes-api/cluster-resources/api-service-v1/) in the API reference
Alternatively: learn how to [extend the Kubernetes API using Custom Resource Definitions](/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definitions/).
@@ -167,7 +167,7 @@ CRDs are easier to create than Aggregated APIs.
| CRDs | Aggregated API |
| --------------------------- | -------------- |
| Do not require programming. Users can choose any language for a CRD controller. | Requires programming in Go and building binary and image. |
| Do not require programming. Users can choose any language for a CRD controller. | Requires programming and building binary and image. |
| No additional service to run; CRDs are handled by API server. | An additional service to create and that could fail. |
| No ongoing support once the CRD is created. Any bug fixes are picked up as part of normal Kubernetes Master upgrades. | May need to periodically pickup bug fixes from upstream and rebuild and update the Aggregated API server. |
| No need to handle multiple versions of your API; for example, when you control the client for this resource, you can upgrade it in sync with the API. | You need to handle multiple versions of your API; for example, when developing an extension to share with the world. |
@@ -114,6 +114,7 @@ Operator.
* [Charmed Operator Framework](https://juju.is/)
* [kubebuilder](https://book.kubebuilder.io/)
* [KubeOps](https://buehler.github.io/dotnet-operator-sdk/) (.NET operator SDK)
* [KUDO](https://kudo.dev/) (Kubernetes Universal Declarative Operator)
* [Metacontroller](https://metacontroller.github.io/metacontroller/intro.html) along with WebHooks that
you implement yourself
@@ -32,7 +32,7 @@ The application can access the message queue as a service.
Service Catalog uses the [Open service broker API](https://github.com/openservicebrokerapi/servicebroker) to communicate with service brokers, acting as an intermediary for the Kubernetes API Server to negotiate the initial provisioning and retrieve the credentials necessary for the application to use a managed service.
It is implemented as an extension API server and a controller, using etcd for storage. It also uses the [aggregation layer](/docs/concepts/extend-kubernetes/api-extension/apiserver-aggregation/) available in Kubernetes 1.7+ to present its API.
It is implemented using a [CRDs-based](/docs/concepts/extend-kubernetes/api-extension/custom-resources/#custom-resources) architecture.
<br>
@@ -16,7 +16,7 @@ card:
When you deploy Kubernetes, you get a cluster.
{{< glossary_definition term_id="cluster" length="all" prepend="A Kubernetes cluster consists of">}}
This document outlines the various components you need to have
This document outlines the various components you need to have for
a complete and working Kubernetes cluster.
Here's the diagram of a Kubernetes cluster with all the components tied together.
@@ -47,7 +47,7 @@ and the controller deletes the volume.
Like {{<glossary_tooltip text="labels" term_id="label">}}, [owner references](/concepts/overview/working-with-objects/owners-dependents/)
describe the relationships between objects in Kubernetes, but are used for a
different purpose. When a
{{<glossary_tooltip text="controllers" term_id="controller">}} manages objects
{{<glossary_tooltip text="controller" term_id="controller">}} manages objects
like Pods, it uses labels to track changes to groups of related objects. For
example, when a {{<glossary_tooltip text="Job" term_id="job">}} creates one or
more Pods, the Job controller applies labels to those pods and tracks changes to
@@ -77,4 +77,4 @@ your cluster.
## {{% heading "whatsnext" %}}
* Read [Using Finalizers to Control Deletion](/blog/2021/05/14/using-finalizers-to-control-deletion/)
on the Kubernetes blog.
on the Kubernetes blog.
@@ -81,12 +81,11 @@ In the `.yaml` file for the Kubernetes object you want to create, you'll need to
* `metadata` - Data that helps uniquely identify the object, including a `name` string, `UID`, and optional `namespace`
* `spec` - What state you desire for the object
The precise format of the object `spec` is different for every Kubernetes object, and contains nested fields specific to that object. The [Kubernetes API Reference](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/) can help you find the spec format for all of the objects you can create using Kubernetes.
For example, the `spec` format for a Pod can be found in
[PodSpec v1 core](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#podspec-v1-core),
and the `spec` format for a Deployment can be found in
[DeploymentSpec v1 apps](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#deploymentspec-v1-apps).
The precise format of the object `spec` is different for every Kubernetes object, and contains nested fields specific to that object. The [Kubernetes API Reference](https://kubernetes.io/docs/reference/kubernetes-api/) can help you find the spec format for all of the objects you can create using Kubernetes.
For example, the reference for Pod details the [`spec` field](/docs/reference/kubernetes-api/workload-resources/pod-v1/#PodSpec)
for a Pod in the API, and the reference for Deployment details the [`spec` field](/docs/reference/kubernetes-api/workload-resources/deployment-v1/#DeploymentSpec) for Deployments.
In those API reference pages you'll see mention of PodSpec and DeploymentSpec. These names are implementation details of the Golang code that Kubernetes uses to implement its API.
## {{% heading "whatsnext" %}}
@@ -62,7 +62,10 @@ Kubernetes starts with four initial namespaces:
* `default` The default namespace for objects with no other namespace
* `kube-system` The namespace for objects created by the Kubernetes system
* `kube-public` This namespace is created automatically and is readable by all users (including those not authenticated). This namespace is mostly reserved for cluster usage, in case that some resources should be visible and readable publicly throughout the whole cluster. The public aspect of this namespace is only a convention, not a requirement.
* `kube-node-lease` This namespace for the lease objects associated with each node which improves the performance of the node heartbeats as the cluster scales.
* `kube-node-lease` This namespace holds [Lease](/docs/reference/kubernetes-api/cluster-resources/lease-v1/)
objects associated with each node. Node leases allow the kubelet to send
[heartbeats](/docs/concepts/architecture/nodes/#heartbeats) so that the control plane
can detect node failure.
### Setting the namespace for a request
@@ -42,6 +42,24 @@ A Kubernetes admission controller controls user access to change this field for
dependent resources, based on the delete permissions of the owner. This control
prevents unauthorized users from delaying owner object deletion.
{{< note >}}
Cross-namespace owner references are disallowed by design.
Namespaced dependents can specify cluster-scoped or namespaced owners.
A namespaced owner **must** exist in the same namespace as the dependent.
If it does not, the owner reference is treated as absent, and the dependent
is subject to deletion once all owners are verified absent.
Cluster-scoped dependents can only specify cluster-scoped owners.
In v1.20+, if a cluster-scoped dependent specifies a namespaced kind as an owner,
it is treated as having an unresolvable owner reference, and is not able to be garbage collected.
In v1.20+, if the garbage collector detects an invalid cross-namespace `ownerReference`,
or a cluster-scoped dependent with an `ownerReference` referencing a namespaced kind, a warning Event
with a reason of `OwnerRefInvalidNamespace` and an `involvedObject` of the invalid dependent is reported.
You can check for that kind of Event by running
`kubectl get events -A --field-selector=reason=OwnerRefInvalidNamespace`.
{{< /note >}}
## Ownership and finalizers
When you tell Kubernetes to delete a resource, the API server allows the
@@ -47,7 +47,7 @@ functions to score the feasible Nodes and picks a Node with the highest
score among the feasible ones to run the Pod. The scheduler then notifies
the API server about this decision in a process called _binding_.
Factors that need taken into account for scheduling decisions include
Factors that need to be taken into account for scheduling decisions include
individual and collective resource requirements, hardware / software /
policy constraints, affinity and anti-affinity specifications, data
locality, inter-workload interference, and so on.
@@ -92,9 +92,9 @@ shape:
``` yaml
resources:
- name: CPU
- name: cpu
weight: 1
- name: Memory
- name: memory
weight: 1
```
@@ -104,9 +104,9 @@ It can be used to add extended resources as follows:
resources:
- name: intel.com/foo
weight: 5
- name: CPU
- name: cpu
weight: 3
- name: Memory
- name: memory
weight: 1
```
@@ -123,16 +123,16 @@ Requested resources:
```
intel.com/foo : 2
Memory: 256MB
CPU: 2
memory: 256MB
cpu: 2
```
Resource weights:
```
intel.com/foo : 5
Memory: 1
CPU: 3
memory: 1
cpu: 3
```
FunctionShapePoint {{0, 0}, {100, 10}}
@@ -142,13 +142,13 @@ Node 1 spec:
```
Available:
intel.com/foo: 4
Memory: 1 GB
CPU: 8
memory: 1 GB
cpu: 8
Used:
intel.com/foo: 1
Memory: 256MB
CPU: 1
memory: 256MB
cpu: 1
```
Node score:
@@ -161,13 +161,13 @@ intel.com/foo = resourceScoringFunction((2+1),4)
= rawScoringFunction(75)
= 7 # floor(75/10)
Memory = resourceScoringFunction((256+256),1024)
memory = resourceScoringFunction((256+256),1024)
= (100 -((1024-512)*100/1024))
= 50 # requested + used = 50% * available
= rawScoringFunction(50)
= 5 # floor(50/10)
CPU = resourceScoringFunction((2+1),8)
cpu = resourceScoringFunction((2+1),8)
= (100 -((8-3)*100/8))
= 37.5 # requested + used = 37.5% * available
= rawScoringFunction(37.5)
@@ -182,12 +182,12 @@ Node 2 spec:
```
Available:
intel.com/foo: 8
Memory: 1GB
CPU: 8
memory: 1GB
cpu: 8
Used:
intel.com/foo: 2
Memory: 512MB
CPU: 6
memory: 512MB
cpu: 6
```
Node score:
@@ -200,13 +200,13 @@ intel.com/foo = resourceScoringFunction((2+2),8)
= rawScoringFunction(50)
= 5
Memory = resourceScoringFunction((256+512),1024)
memory = resourceScoringFunction((256+512),1024)
= (100 -((1024-768)*100/1024))
= 75
= rawScoringFunction(75)
= 7
CPU = resourceScoringFunction((2+6),8)
cpu = resourceScoringFunction((2+6),8)
= (100 -((8-8)*100/8))
= 100
= rawScoringFunction(100)
@@ -142,7 +142,7 @@ By default, the Kubernetes API server serves HTTP on 2 ports:
- is intended for testing and bootstrap, and for other components of the master node
(scheduler, controller-manager) to talk to the API
- no TLS
- default is port 8080, change with `--insecure-port` flag.
- default is port 8080
- default IP is localhost, change with `--insecure-bind-address` flag.
- request **bypasses** authentication and authorization modules.
- request handled by admission control module(s).
@@ -62,9 +62,9 @@ takes if a potential violation is detected:
{{< table caption="Pod Security Admission modes" >}}
Mode | Description
:---------|:------------
**`enforce`** | Policy violations will cause the pod to be rejected.
**`audit`** | Policy violations will trigger the addition of an audit annotation, but are otherwise allowed.
**`warn`** | Policy violations will trigger a user-facing warning, but are otherwise allowed.
**enforce** | Policy violations will cause the pod to be rejected.
**audit** | Policy violations will trigger the addition of an audit annotation to the event recorded in the [audit log](/docs/tasks/debug-application-cluster/audit/), but are otherwise allowed.
**warn** | Policy violations will trigger a user-facing warning, but are otherwise allowed.
{{< /table >}}
A namespace can configure any or all modes, or even set a different level for different modes.
@@ -91,7 +91,7 @@ Check out [Enforce Pod Security Standards with Namespace Labels](/docs/tasks/con
## Workload resources and Pod templates
Pods are often created indirectly, by creating a [workload
object](https://kubernetes.io/docs/concepts/workloads/controllers/) such as a {{< glossary_tooltip
object](/docs/concepts/workloads/controllers/) such as a {{< glossary_tooltip
term_id="deployment" >}} or {{< glossary_tooltip term_id="job">}}. The workload object defines a
_Pod template_ and a {{< glossary_tooltip term_id="controller" text="controller" >}} for the
workload resource creates Pods based on that template. To help catch violations early, both the
@@ -103,7 +103,7 @@ applied to workload resources, only to the resulting pod objects.
You can define _exemptions_ from pod security enforcement in order allow the creation of pods that
would have otherwise been prohibited due to the policy associated with a given namespace.
Exemptions can be statically configured in the
[Admission Controller configuration](#configuring-the-admission-controller).
[Admission Controller configuration](/docs/tasks/configure-pod-container/enforce-standards-admission-controller/#configure-the-admission-controller).
Exemptions must be explicitly enumerated. Requests meeting exemption criteria are _ignored_ by the
Admission Controller (all `enforce`, `audit` and `warn` behaviors are skipped). Exemption dimensions include:
@@ -142,4 +142,4 @@ current policy level:
- [Enforcing Pod Security Standards](/docs/setup/best-practices/enforcing-pod-security-standards)
- [Enforce Pod Security Standards by Configuring the Built-in Admission Controller](/docs/tasks/configure-pod-container/enforce-standards-admission-controller)
- [Enforce Pod Security Standards with Namespace Labels](/docs/tasks/configure-pod-container/enforce-standards-namespace-labels)
- [Migrating from PodSecurityPolicy to PodSecurity](/docs/tasks/secure-pods/migrate-from-psp)
- [Migrate from PodSecurityPolicy to the Built-In PodSecurity Admission Controller](/docs/tasks/configure-pod-container/migrate-from-psp)
@@ -495,8 +495,13 @@ as well as other related parameters outside the Security Context. As of July 202
[Pod Security Policies](/docs/concepts/profile/pod-security-profile/) are deprecated in favor of the
built-in [Pod Security Admission Controller](/docs/concepts/security/pod-security-admission/).
{{% thirdparty-content %}}
Other alternatives for enforcing security profiles are being developed in the Kubernetes
ecosystem, such as [OPA Gatekeeper](https://github.com/open-profile-agent/gatekeeper).
ecosystem, such as:
- [OPA Gatekeeper](https://github.com/open-policy-agent/gatekeeper).
- [Kubewarden](https://github.com/kubewarden).
- [Kyverno](https://kyverno.io/policies/pod-security/).
### What profiles should I apply to my Windows Pods?
@@ -133,7 +133,7 @@ about the [service proxy](/docs/concepts/services-networking/service/#virtual-ip
Kubernetes supports 2 primary modes of finding a Service - environment variables
and DNS. The former works out of the box while the latter requires the
[CoreDNS cluster addon](https://releases.k8s.io/{{< param "githubbranch" >}}/cluster/addons/dns/coredns).
[CoreDNS cluster addon](https://releases.k8s.io/{{< param "fullversion" >}}/cluster/addons/dns/coredns).
{{< note >}}
If the service environment variables are not desired (because possible clashing with expected program ones,
too many variables to process, only using DNS, etc) you can disable this mode by setting the `enableServiceLinks`
@@ -231,7 +231,7 @@ Till now we have only accessed the nginx server from within the cluster. Before
* An nginx server configured to use the certificates
* A [secret](/docs/concepts/configuration/secret/) that makes the certificates accessible to pods
You can acquire all these from the [nginx https example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/https-nginx/). This requires having go and make tools installed. If you don't want to install those, then follow the manual steps later. In short:
You can acquire all these from the [nginx https example](https://github.com/kubernetes/examples/tree/master/staging/https-nginx/). This requires having go and make tools installed. If you don't want to install those, then follow the manual steps later. In short:
```shell
make keys KEY=/tmp/nginx.key CERT=/tmp/nginx.crt
@@ -303,7 +303,7 @@ Now modify your nginx replicas to start an https server using the certificate in
Noteworthy points about the nginx-secure-app manifest:
- It contains both Deployment and Service specification in the same file.
- The [nginx server](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/https-nginx/default.conf)
- The [nginx server](https://github.com/kubernetes/examples/tree/master/staging/https-nginx/default.conf)
serves HTTP traffic on port 80 and HTTPS traffic on 443, and nginx Service
exposes both ports.
- Each container has access to the keys through a volume mounted at `/etc/nginx/ssl`.
@@ -154,6 +154,7 @@ contains two elements in the `from` array, and allows connections from Pods in t
When in doubt, use `kubectl describe` to see how Kubernetes has interpreted the policy.
<a name="behavior-of-ipblock-selectors"></a>
__ipBlock__: This selects particular IP CIDR ranges to allow as ingress sources or egress destinations. These should be cluster-external IPs, since Pod IPs are ephemeral and unpredictable.
Cluster ingress and egress mechanisms often require rewriting the source or destination IP
@@ -251,7 +252,7 @@ spec:
endPort: 32768
```
The above rule allows any Pod with label `db` on the namespace `default` to communicate
The above rule allows any Pod with label `role=db` on the namespace `default` to communicate
with any IP within the range `10.0.0.0/24` over TCP, provided that the target
port is between the range 32000 and 32768.
@@ -242,9 +242,25 @@ There are a few reasons for using proxying for Services:
on the DNS records could impose a high load on DNS that then becomes
difficult to manage.
Later in this page you can read about various kube-proxy implementations work. Overall,
you should note that, when running `kube-proxy`, kernel level rules may be
modified (for example, iptables rules might get created), which won't get cleaned up,
in some cases until you reboot. Thus, running kube-proxy is something that should
only be done by an administrator which understands the consequences of having a
low level, privileged network proxying service on a computer. Although the `kube-proxy`
executable supports a `cleanup` function, this function is not an official feature and
thus is only available to use as-is.
### Configuration
Note that the kube-proxy starts up in different modes, which are determined by its configuration.
- The kube-proxy's configuration is done via a ConfigMap, and the ConfigMap for kube-proxy effectively deprecates the behaviour for almost all of the flags for the kube-proxy.
- The ConfigMap for the kube-proxy does not support live reloading of configuration.
- The ConfigMap parameters for the kube-proxy cannot all be validated and verified on startup. For example, if your operating system doesn't allow you to run iptables commands, the standard kernel kube-proxy implementation will not work. Likewise, if you have an operating system which doesn't support `netsh`, it will not run in Windows userspace mode.
### User space proxy mode {#proxy-mode-userspace}
In this mode, kube-proxy watches the Kubernetes control plane for the addition and
In this (legacy) mode, kube-proxy watches the Kubernetes control plane for the addition and
removal of Service and Endpoint objects. For each Service it opens a
port (randomly chosen) on the local node. Any connections to this "proxy port"
are proxied to one of the Service's backend Pods (as reported via
@@ -429,7 +445,7 @@ variables and DNS.
When a Pod is run on a Node, the kubelet adds a set of environment variables
for each active Service. It supports both [Docker links
compatible](https://docs.docker.com/userguide/dockerlinks/) variables (see
[makeLinkVariables](https://releases.k8s.io/{{< param "githubbranch" >}}/pkg/kubelet/envvars/envvars.go#L49))
[makeLinkVariables](https://releases.k8s.io/{{< param "fullversion" >}}/pkg/kubelet/envvars/envvars.go#L49))
and simpler `{SVCNAME}_SERVICE_HOST` and `{SVCNAME}_SERVICE_PORT` variables,
where the Service name is upper-cased and dashes are converted to underscores.
@@ -509,7 +509,7 @@ it will become fully deprecated in a future Kubernetes release.
For most volume types, you do not need to set this field. It is automatically populated for [AWS EBS](/docs/concepts/storage/volumes/#awselasticblockstore), [GCE PD](/docs/concepts/storage/volumes/#gcepersistentdisk) and [Azure Disk](/docs/concepts/storage/volumes/#azuredisk) volume block types. You need to explicitly set this for [local](/docs/concepts/storage/volumes/#local) volumes.
{{< /note >}}
A PV can specify [node affinity](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#volumenodeaffinity-v1-core) to define constraints that limit what nodes this volume can be accessed from. Pods that use a PV will only be scheduled to nodes that are selected by the node affinity.
A PV can specify node affinity to define constraints that limit what nodes this volume can be accessed from. Pods that use a PV will only be scheduled to nodes that are selected by the node affinity. To specify node affinity, set `nodeAffinity` in the `.spec` of a PV. The [PersistentVolume](/docs/reference/kubernetes-api/config-and-storage-resources/persistent-volume-v1/#PersistentVolumeSpec) API reference has more details on this field.
### Phase
@@ -897,16 +897,15 @@ and need persistent storage, it is recommended that you use the following patter
or the cluster has no storage system (in which case the user cannot deploy
config requiring PVCs).
## {{% heading "whatsnext" %}}
## {{% heading "whatsnext" %}}
* Learn more about [Creating a PersistentVolume](/docs/tasks/configure-pod-container/configure-persistent-volume-storage/#create-a-persistentvolume).
* Learn more about [Creating a PersistentVolumeClaim](/docs/tasks/configure-pod-container/configure-persistent-volume-storage/#create-a-persistentvolumeclaim).
* Read the [Persistent Storage design document](https://git.k8s.io/community/contributors/design-proposals/storage/persistent-storage.md).
### Reference
### API references {#reference}
* [PersistentVolume](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#persistentvolume-v1-core)
* [PersistentVolumeSpec](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#persistentvolumespec-v1-core)
* [PersistentVolumeClaim](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#persistentvolumeclaim-v1-core)
* [PersistentVolumeClaimSpec](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#persistentvolumeclaimspec-v1-core)
Read about the APIs described in this page:
* [`PersistentVolume`](/docs/reference/kubernetes-api/config-and-storage-resources/persistent-volume-v1/)
* [`PersistentVolumeClaim`](/docs/reference/kubernetes-api/config-and-storage-resources/persistent-volume-claim-v1/)
+11 -11
View File
@@ -130,7 +130,7 @@ and the kubelet, set the `InTreePluginAWSUnregister` flag to `true`.
The `azureDisk` volume type mounts a Microsoft Azure [Data Disk](https://docs.microsoft.com/en-us/azure/aks/csi-storage-drivers) into a pod.
For more details, see the [`azureDisk` volume plugin](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/volumes/azure_disk/README.md).
For more details, see the [`azureDisk` volume plugin](https://github.com/kubernetes/examples/tree/master/staging/volumes/azure_disk/README.md).
#### azureDisk CSI migration
@@ -148,7 +148,7 @@ features must be enabled.
The `azureFile` volume type mounts a Microsoft Azure File volume (SMB 2.1 and 3.0)
into a pod.
For more details, see the [`azureFile` volume plugin](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/volumes/azure_file/README.md).
For more details, see the [`azureFile` volume plugin](https://github.com/kubernetes/examples/tree/master/staging/volumes/azure_file/README.md).
#### azureFile CSI migration
@@ -176,7 +176,7 @@ writers simultaneously.
You must have your own Ceph server running with the share exported before you can use it.
{{< /note >}}
See the [CephFS example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/volumes/cephfs/) for more details.
See the [CephFS example](https://github.com/kubernetes/examples/tree/master/volumes/cephfs/) for more details.
### cinder
@@ -347,7 +347,7 @@ You must configure FC SAN Zoning to allocate and mask those LUNs (volumes) to th
beforehand so that Kubernetes hosts can access them.
{{< /note >}}
See the [fibre channel example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/volumes/fibre_channel) for more details.
See the [fibre channel example](https://github.com/kubernetes/examples/tree/master/staging/volumes/fibre_channel) for more details.
### flocker (deprecated) {#flocker}
@@ -365,7 +365,7 @@ can be shared between pods as required.
You must have your own Flocker installation running before you can use it.
{{< /note >}}
See the [Flocker example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/volumes/flocker) for more details.
See the [Flocker example](https://github.com/kubernetes/examples/tree/master/staging/volumes/flocker) for more details.
### gcePersistentDisk
@@ -533,7 +533,7 @@ simultaneously.
You must have your own GlusterFS installation running before you can use it.
{{< /note >}}
See the [GlusterFS example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/volumes/glusterfs) for more details.
See the [GlusterFS example](https://github.com/kubernetes/examples/tree/master/volumes/glusterfs) for more details.
### hostPath {#hostpath}
@@ -661,7 +661,7 @@ and then serve it in parallel from as many Pods as you need. Unfortunately,
iSCSI volumes can only be mounted by a single consumer in read-write mode.
Simultaneous writers are not allowed.
See the [iSCSI example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/volumes/iscsi) for more details.
See the [iSCSI example](https://github.com/kubernetes/examples/tree/master/volumes/iscsi) for more details.
### local
@@ -749,7 +749,7 @@ writers simultaneously.
You must have your own NFS server running with the share exported before you can use it.
{{< /note >}}
See the [NFS example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/volumes/nfs) for more details.
See the [NFS example](https://github.com/kubernetes/examples/tree/master/staging/volumes/nfs) for more details.
### persistentVolumeClaim {#persistentvolumeclaim}
@@ -797,7 +797,7 @@ Make sure you have an existing PortworxVolume with name `pxvol`
before using it in the Pod.
{{< /note >}}
For more details, see the [Portworx volume](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/volumes/portworx/README.md) examples.
For more details, see the [Portworx volume](https://github.com/kubernetes/examples/tree/master/staging/volumes/portworx/README.md) examples.
### projected
@@ -811,7 +811,7 @@ Currently, the following types of volume sources can be projected:
* `serviceAccountToken`
All sources are required to be in the same namespace as the Pod. For more details,
see the [all-in-one volume design document](https://github.com/kubernetes/community/blob/{{< param "githubbranch" >}}/contributors/design-proposals/node/all-in-one-volume.md).
see the [all-in-one volume design document](https://github.com/kubernetes/community/blob/master/contributors/design-proposals/node/all-in-one-volume.md).
#### Example configuration with a secret, a downwardAPI, and a configMap {#example-configuration-secret-downwardapi-configmap}
@@ -972,7 +972,7 @@ and then serve it in parallel from as many pods as you need. Unfortunately,
RBD volumes can only be mounted by a single consumer in read-write mode.
Simultaneous writers are not allowed.
See the [RBD example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/volumes/rbd)
See the [RBD example](https://github.com/kubernetes/examples/tree/master/volumes/rbd)
for more details.
### secret
@@ -17,6 +17,8 @@ A _CronJob_ creates {{< glossary_tooltip term_id="job" text="Jobs" >}} on a repe
One CronJob object is like one line of a _crontab_ (cron table) file. It runs a job periodically
on a given schedule, written in [Cron](https://en.wikipedia.org/wiki/Cron) format.
In addition, the CronJob schedule supports timezone handling, you can specify the timezone by adding "CRON_TZ=<time zone>" at the beginning of the CronJob schedule, and it is recommended to always set `CRON_TZ`.
{{< caution >}}
All **CronJob** `schedule:` times are based on the timezone of the
{{< glossary_tooltip term_id="kube-controller-manager" text="kube-controller-manager" >}}.
@@ -53,15 +55,16 @@ takes you through this example in more detail).
### Cron schedule syntax
```
# ───────────── minute (0 - 59)
# ┌───────────── hour (0 - 23)
# │ ┌───────────── day of the month (1 - 31)
# │ │ ┌───────────── month (1 - 12)
# │ │ │ ┌───────────── day of the week (0 - 6) (Sunday to Saturday;
# │ │ │ │ │ 7 is also Sunday on some systems)
# │ │ │ │ │
# │ │ │ │ │
# * * * * *
# ┌────────────────── timezone (optional)
# | ┌───────────── minute (0 - 59)
# | │ ┌───────────── hour (0 - 23)
# | │ │ ┌───────────── day of the month (1 - 31)
# | │ │ │ ┌───────────── month (1 - 12)
# | │ │ │ │ ┌───────────── day of the week (0 - 6) (Sunday to Saturday;
# | │ │ │ │ │ 7 is also Sunday on some systems)
# | │ │ │ │ │
# | │ │ │ │ │
# CRON_TZ=UTC * * * * *
```
@@ -75,9 +78,9 @@ takes you through this example in more detail).
For example, the line below states that the task must be started every Friday at midnight, as well as on the 13th of each month at midnight:
For example, the line below states that the task must be started every Friday at midnight, as well as on the 13th of each month at midnight(in UTC):
`0 0 13 * 5`
`CRON_TZ=UTC 0 0 13 * 5`
To generate CronJob schedule expressions, you can also use web tools like [crontab.guru](https://crontab.guru/).
@@ -632,7 +632,7 @@ of custom controller for those Pods. This allows the most flexibility, but may
complicated to get started with and offers less integration with Kubernetes.
One example of this pattern would be a Job which starts a Pod which runs a script that in turn
starts a Spark master controller (see [spark example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/spark/README.md)), runs a spark
starts a Spark master controller (see [spark example](https://github.com/kubernetes/examples/tree/master/staging/spark/README.md)), runs a spark
driver, and then cleans up.
An advantage of this approach is that the overall process gets the completion guarantee of a Job
@@ -39,7 +39,7 @@ that provides a set of stateless replicas.
## Limitations
* The storage for a given Pod must either be provisioned by a [PersistentVolume Provisioner](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/staging/persistent-volume-provisioning/README.md) based on the requested `storage class`, or pre-provisioned by an admin.
* The storage for a given Pod must either be provisioned by a [PersistentVolume Provisioner](https://github.com/kubernetes/examples/tree/master/staging/persistent-volume-provisioning/README.md) based on the requested `storage class`, or pre-provisioned by an admin.
* Deleting and/or scaling a StatefulSet down will *not* delete the volumes associated with the StatefulSet. This is done to ensure data safety, which is generally more valuable than an automatic purge of all related StatefulSet resources.
* StatefulSets currently require a [Headless Service](/docs/concepts/services-networking/service/#headless-services) to be responsible for the network identity of the Pods. You are responsible for creating this Service.
* StatefulSets do not provide any guarantees on the termination of pods when a StatefulSet is deleted. To achieve ordered and graceful termination of the pods in the StatefulSet, it is possible to scale the StatefulSet down to 0 prior to deletion.
@@ -173,9 +173,7 @@ Cluster Domain will be set to `cluster.local` unless
### Stable Storage
Kubernetes creates one [PersistentVolume](/docs/concepts/storage/persistent-volumes/) for each
VolumeClaimTemplate. In the nginx example above, each Pod will receive a single PersistentVolume
with a StorageClass of `my-storage-class` and 1 Gib of provisioned storage. If no StorageClass
For each VolumeClaimTemplate entry defined in a StatefulSet, each Pod receives one PersistentVolumeClaim. In the nginx example above, each Podreceives a single PersistentVolume with a StorageClass of `my-storage-class` and 1 Gib of provisioned storage. If no StorageClass
is specified, then the default StorageClass will be used. When a Pod is (re)scheduled
onto a node, its `volumeMounts` mount the PersistentVolumes associated with its
PersistentVolume Claims. Note that, the PersistentVolumes associated with the
@@ -283,6 +283,13 @@ on the Kubernetes API server for each static Pod.
This means that the Pods running on a node are visible on the API server,
but cannot be controlled from there.
{{< note >}}
The `spec` of a static Pod cannot refer to other API objects
(e.g., {{< glossary_tooltip text="ServiceAccount" term_id="service-account" >}},
{{< glossary_tooltip text="ConfigMap" term_id="configmap" >}},
{{< glossary_tooltip text="Secret" term_id="secret" >}}, etc).
{{< /note >}}
## Container probes
A _probe_ is a diagnostic performed periodically by the kubelet on a container. To perform a diagnostic, the kubelet can invoke different actions:
@@ -32,9 +32,11 @@ If a Pod's init container fails, the kubelet repeatedly restarts that init conta
However, if the Pod has a `restartPolicy` of Never, and an init container fails during startup of that Pod, Kubernetes treats the overall Pod as failed.
To specify an init container for a Pod, add the `initContainers` field into
the Pod specification, as an array of objects of type
[Container](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#container-v1-core),
alongside the app `containers` array.
the [Pod specification](/docs/reference/kubernetes-api/workload-resources/pod-v1/#PodSpec),
as an array of `container` items (similar to the app `containers` field and its contents).
See [Container](/docs/reference/kubernetes-api/workload-resources/pod-v1/#Container) in the
API reference for more details.
The status of the init containers is returned in `.status.initContainerStatuses`
field as an array of the container statuses (similar to the `.status.containerStatuses`
field).
@@ -278,9 +280,11 @@ Init containers have all of the fields of an app container. However, Kubernetes
prohibits `readinessProbe` from being used because init containers cannot
define readiness distinct from completion. This is enforced during validation.
Use `activeDeadlineSeconds` on the Pod and `livenessProbe` on the container to
prevent init containers from failing forever. The active deadline includes init
containers.
Use `activeDeadlineSeconds` on the Pod to prevent init containers from failing forever.
The active deadline includes init containers.
However it is recommended to use `activeDeadlineSeconds` if user deploy their application
as a Job, because `activeDeadlineSeconds` has an effect even after initContainer finished.
The Pod which is already running correctly would be killed by `activeDeadlineSeconds` if you set.
The name of each app and init container in a Pod must be unique; a
validation error is thrown for any container sharing a name with another.
@@ -230,20 +230,9 @@ If you apply "two-constraints.yaml" to this cluster, you will notice "mypod" sta
To overcome this situation, you can either increase the `maxSkew` or modify one of the constraints to use `whenUnsatisfiable: ScheduleAnyway`.
### Conventions
### Interaction With Node Affinity and Node Selectors
There are some implicit conventions worth noting here:
- Only the Pods holding the same namespace as the incoming Pod can be matching candidates.
- Nodes without `topologySpreadConstraints[*].topologyKey` present will be bypassed. It implies that:
1. the Pods located on those nodes do not impact `maxSkew` calculation - in the above example, suppose "node1" does not have label "zone", then the 2 Pods will be disregarded, hence the incoming Pod will be scheduled into "zoneA".
2. the incoming Pod has no chances to be scheduled onto this kind of nodes - in the above example, suppose a "node5" carrying label `{zone-typo: zoneC}` joins the cluster, it will be bypassed due to the absence of label key "zone".
- Be aware of what will happen if the incomingPod's `topologySpreadConstraints[*].labelSelector` doesn't match its own labels. In the above example, if we remove the incoming Pod's labels, it can still be placed onto "zoneB" since the constraints are still satisfied. However, after the placement, the degree of imbalance of the cluster remains unchanged - it's still zoneA having 2 Pods which hold label {foo:bar}, and zoneB having 1 Pod which holds label {foo:bar}. So if this is not what you expect, we recommend the workload's `topologySpreadConstraints[*].labelSelector` to match its own labels.
- If the incoming Pod has `spec.nodeSelector` or `spec.affinity.nodeAffinity` defined, nodes not matching them will be bypassed.
The scheduler will skip the non-matching nodes from the skew calculations if the incoming Pod has `spec.nodeSelector` or `spec.affinity.nodeAffinity` defined.
Suppose you have a 5-node cluster ranging from zoneA to zoneC:
@@ -283,6 +272,21 @@ There are some implicit conventions worth noting here:
{{< codenew file="pods/topology-spread-constraints/one-constraint-with-nodeaffinity.yaml" >}}
The scheduler doesn't have prior knowledge of all the zones or other topology domains that a cluster has. They are determined from the existing nodes in the cluster. This could lead to a problem in autoscaled clusters, when a node pool (or node group) is scaled to zero nodes and the user is expecting them to scale up, because, in this case, those topology domains won't be considered until there is at least one node in them.
### Other Noticeable Semantics
There are some implicit conventions worth noting here:
- Only the Pods holding the same namespace as the incoming Pod can be matching candidates.
- The scheduler will bypass the nodes without `topologySpreadConstraints[*].topologyKey` present. This implies that:
1. the Pods located on those nodes do not impact `maxSkew` calculation - in the above example, suppose "node1" does not have label "zone", then the 2 Pods will be disregarded, hence the incoming Pod will be scheduled into "zoneA".
2. the incoming Pod has no chances to be scheduled onto this kind of nodes - in the above example, suppose a "node5" carrying label `{zone-typo: zoneC}` joins the cluster, it will be bypassed due to the absence of label key "zone".
- Be aware of what will happen if the incomingPod's `topologySpreadConstraints[*].labelSelector` doesn't match its own labels. In the above example, if we remove the incoming Pod's labels, it can still be placed onto "zoneB" since the constraints are still satisfied. However, after the placement, the degree of imbalance of the cluster remains unchanged - it's still zoneA having 2 Pods which hold label {foo:bar}, and zoneB having 1 Pod which holds label {foo:bar}. So if this is not what you expect, we recommend the workload's `topologySpreadConstraints[*].labelSelector` to match its own labels.
### Cluster-level default constraints
It is possible to set default topology spread constraints for a cluster. Default
@@ -91,7 +91,7 @@ will be different in your situation.
Here's an example of editing a comment in the Kubernetes source code.
In your local kubernetes/kubernetes repository, check out the master branch,
In your local kubernetes/kubernetes repository, check out the default branch,
and make sure it is up to date:
```shell
@@ -100,7 +100,7 @@ git checkout master
git pull https://github.com/kubernetes/kubernetes master
```
Suppose this source file in the master branch has the typo "atmost":
Suppose this source file in that default branch has the typo "atmost":
[kubernetes/kubernetes/staging/src/k8s.io/api/apps/v1/types.go](https://github.com/kubernetes/kubernetes/blob/master/staging/src/k8s.io/api/apps/v1/types.go)
@@ -183,12 +183,13 @@ In the preceding section, you edited a file in the master branch and then ran sc
to generate an OpenAPI spec and related files. Then you submitted your changes in a pull request
to the master branch of the kubernetes/kubernetes repository. Now suppose you want to backport
your change into a release branch. For example, suppose the master branch is being used to develop
Kubernetes version 1.10, and you want to backport your change into the release-1.9 branch.
Kubernetes version {{< skew latestVersion >}}, and you want to backport your change into the
release-{{< skew prevMinorVersion >}} branch.
Recall that your pull request has two commits: one for editing `types.go`
and one for the files generated by scripts. The next step is to propose a cherry pick of your first
commit into the release-1.9 branch. The idea is to cherry pick the commit that edited `types.go`, but not
the commit that has the results of running the scripts. For instructions, see
commit into the release-{{< skew prevMinorVersion >}} branch. The idea is to cherry pick the commit
that edited `types.go`, but not the commit that has the results of running the scripts. For instructions, see
[Propose a Cherry Pick](https://git.k8s.io/community/contributors/devel/sig-release/cherry-picks.md).
{{< note >}}
@@ -197,8 +198,9 @@ pull request. If you don't have those permissions, you will need to work with so
and milestone for you.
{{< /note >}}
When you have a pull request in place for cherry picking your one commit into the release-1.9 branch,
the next step is to run these scripts in the release-1.9 branch of your local environment.
When you have a pull request in place for cherry picking your one commit into the
release-{{< skew prevMinorVersion >}} branch, the next step is to run these scripts in the
release-{{< skew prevMinorVersion >}} branch of your local environment.
```shell
hack/update-generated-swagger-docs.sh
@@ -208,14 +210,15 @@ hack/update-api-reference-docs.sh
```
Now add a commit to your cherry-pick pull request that has the recently generated OpenAPI spec
and related files. Monitor your pull request until it gets merged into the release-1.9 branch.
and related files. Monitor your pull request until it gets merged into the
release-{{< skew prevMinorVersion >}} branch.
At this point, both the master branch and the release-1.9 branch have your updated `types.go`
At this point, both the master branch and the release-{{< skew prevMinorVersion >}} branch have your updated `types.go`
file and a set of generated files that reflect the change you made to `types.go`. Note that the
generated OpenAPI spec and other generated files in the release-1.9 branch are not necessarily
the same as the generated files in the master branch. The generated files in the release-1.9 branch
contain API elements only from Kubernetes 1.9. The generated files in the master branch might contain
API elements that are not in 1.9, but are under development for 1.10.
generated OpenAPI spec and other generated files in the release-{{< skew prevMinorVersion >}} branch are not necessarily
the same as the generated files in the master branch. The generated files in the release-{{< skew prevMinorVersion >}} branch
contain API elements only from Kubernetes {{< skew prevMinorVersion >}}. The generated files in the master branch might contain
API elements that are not in {{< skew prevMinorVersion >}}, but are under development for {{< skew latestVersion >}}.
## Generating the published reference docs
@@ -86,12 +86,12 @@ The remaining steps refer to your base directory as `<rdocs-base>`.
In your local k8s.io/kubernetes repository, check out the branch of interest,
and make sure it is up to date. For example, if you want to generate docs for
Kubernetes 1.17, you could use these commands:
Kubernetes {{< skew prevMinorVersion >}}.0, you could use these commands:
```shell
cd <k8s-base>
git checkout v1.17.0
git pull https://github.com/kubernetes/kubernetes v1.17.0
git checkout v{{< skew prevMinorVersion >}}.0
git pull https://github.com/kubernetes/kubernetes {{< skew prevMinorVersion >}}.0
```
If you do not need to edit the `kubectl` source code, follow the instructions for
@@ -109,7 +109,7 @@ local kubernetes/kubernetes repository, and then submit a pull request to the ma
is an example of a pull request that fixes a typo in the kubectl source code.
Monitor your pull request, and respond to reviewer comments. Continue to monitor your
pull request until it is merged into the master branch of the kubernetes/kubernetes repository.
pull request until it is merged into the target branch of the kubernetes/kubernetes repository.
## Cherry picking your change into a release branch
@@ -118,9 +118,10 @@ Kubernetes release. If you want your change to appear in the docs for a Kubernet
version that has already been released, you need to propose that your change be
cherry picked into the release branch.
For example, suppose the master branch is being used to develop Kubernetes 1.10,
and you want to backport your change to the release-1.15 branch. For instructions
on how to do this, see
For example, suppose the master branch is being used to develop Kubernetes
{{< skew currentVersion >}}
and you want to backport your change to the release-{{< skew prevMinorVersion >}} branch. For
instructions on how to do this, see
[Propose a Cherry Pick](https://git.k8s.io/community/contributors/devel/sig-release/cherry-picks.md).
Monitor your cherry-pick pull request until it is merged into the release branch.
@@ -138,14 +139,14 @@ Go to `<rdocs-base>`. On you command line, set the following environment variabl
* Set `K8S_ROOT` to `<k8s-base>`.
* Set `K8S_WEBROOT` to `<web-base>`.
* Set `K8S_RELEASE` to the version of the docs you want to build.
For example, if you want to build docs for Kubernetes 1.17, set `K8S_RELEASE` to 1.17.
For example, if you want to build docs for Kubernetes {{< skew prevMinorVersion >}}, set `K8S_RELEASE` to {{< skew prevMinorVersion >}}.
For example:
```shell
export K8S_WEBROOT=$GOPATH/src/github.com/<your-username>/website
export K8S_ROOT=$GOPATH/src/k8s.io/kubernetes
export K8S_RELEASE=1.17
export K8S_RELEASE={{< skew prevMinorVersion >}}
```
## Creating a versioned directory
@@ -165,13 +166,14 @@ make createversiondirs
In your local `<k8s-base>` repository, checkout the branch that has
the version of Kubernetes that you want to document. For example, if you want
to generate docs for Kubernetes 1.17, checkout the `v1.17.0` tag. Make sure
to generate docs for Kubernetes {{< skew prevMinorVersion >}}.0, check out the
`v{{< skew prevMinorVersion >}}` tag. Make sure
you local branch is up to date.
```shell
cd <k8s-base>
git checkout v1.17.0
git pull https://github.com/kubernetes/kubernetes v1.17.0
git checkout v{{< skew prevMinorVersion >}}.0
git pull https://github.com/kubernetes/kubernetes v{{< skew prevMinorVersion >}}.0
```
## Running the doc generation code
@@ -308,6 +308,12 @@ Localizing site strings lets you customize site-wide text and features: for exam
Some language teams have their own language-specific style guide and glossary. For example, see the [Korean Localization Guide](/ko/docs/contribute/localization_ko/).
### Language specific Zoom meetings
If the localization project needs a separate meeting time, contact a SIG Docs Co-Chair or Tech Lead to create a new reoccurring Zoom meeting and calendar invite. This is only needed when the the team is large enough to sustain and require a separate meeting.
Per CNCF policy, the localization teams must upload their meetings to the SIG Docs YouTube playlist. A SIG Docs Co-Chair or Tech Lead can help with the process until SIG Docs automates it.
## Branching strategy
Because localization projects are highly collaborative efforts, we
+2 -2
View File
@@ -22,9 +22,9 @@ overview: >
Kubernetes is an open source container orchestration engine for automating deployment, scaling, and management of containerized applications. The open source project is hosted by the Cloud Native Computing Foundation (<a href="https://www.cncf.io/about">CNCF</a>).
cards:
- name: concepts
title: "Understand the basics"
title: "Understand Kubernetes"
description: "Learn about Kubernetes and its fundamental concepts."
button: "Learn Concepts"
button: "View Concepts"
button_path: "/docs/concepts"
- name: tutorials
title: "Try Kubernetes"
File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 175 KiB

@@ -127,7 +127,7 @@ up the verbosity:
{"apiVersion": "abac.authorization.kubernetes.io/v1beta1", "kind": "Policy", "spec": {"group": "system:unauthenticated", "readonly": true, "nonResourcePath": "*"}}
```
[Complete file example](https://releases.k8s.io/{{< param "githubbranch" >}}/pkg/auth/authorizer/abac/example_policy_file.jsonl)
[Complete file example](https://releases.k8s.io/{{< param "fullversion" >}}/pkg/auth/authorizer/abac/example_policy_file.jsonl)
## A quick note on service accounts
@@ -70,7 +70,7 @@ controller on the controller manager.
Each valid token is backed by a secret in the `kube-system` namespace. You can
find the full design doc
[here](https://github.com/kubernetes/community/blob/{{< param "githubbranch" >}}/contributors/design-proposals/cluster-lifecycle/bootstrap-discovery.md).
[here](https://github.com/kubernetes/community/blob/master/contributors/design-proposals/cluster-lifecycle/bootstrap-discovery.md).
Here is what the secret looks like.
@@ -279,8 +279,10 @@ rules:
```
{{< note >}}
You cannot restrict `create` or `deletecollection` requests by resourceName. For `create`, this
limitation is because the object name is not known at authorization time.
You cannot restrict `create` or `deletecollection` requests by their resource name.
For `create`, this limitation is because the name of the new object may not be known at authorization time.
If you restrict `list` or `watch` by resourceName, clients must include a `metadata.name` field selector in their `list` or `watch` request that matches the specified resourceName in order to be authorized.
For example, `kubectl get configmaps --field-selector=metadata.name=my-configmap`
{{< /note >}}
@@ -683,12 +685,13 @@ When used in a <b>RoleBinding</b>, it gives full control over every resource in
<td><b>admin</b></td>
<td>None</td>
<td>Allows admin access, intended to be granted within a namespace using a <b>RoleBinding</b>.
If used in a <b>RoleBinding</b>, allows read/write access to most resources in a namespace,
including the ability to create roles and role bindings within the namespace.
This role does not allow write access to resource quota or to the namespace itself.
This role also does not allow write access to Endpoints in clusters created
using Kubernetes v1.22+. More information is available in the ["Write Access for
Endpoints" section](#write-access-for-endpoints).</td>
using Kubernetes v1.22+. More information is available in the
["Write Access for Endpoints" section](#write-access-for-endpoints).</td>
</tr>
<tr>
<td><b>edit</b></td>
@@ -172,5 +172,5 @@ Access to other non-resource paths can be disallowed without restricting access
to the REST api.
For further documentation refer to the authorization.v1beta1 API objects and
[webhook.go](https://github.com/kubernetes/kubernetes/blob/{{< param "githubbranch" >}}/staging/src/k8s.io/apiserver/plugin/pkg/authorizer/webhook/webhook.go).
[webhook.go](https://github.com/kubernetes/kubernetes/blob/master/staging/src/k8s.io/apiserver/plugin/pkg/authorizer/webhook/webhook.go).
@@ -165,8 +165,8 @@ different Kubernetes components.
| `PreferNominatedNode` | `true` | Beta | 1.22 | |
| `ProbeTerminationGracePeriod` | `false` | Alpha | 1.21 | 1.21 |
| `ProbeTerminationGracePeriod` | `false` | Beta | 1.22 | |
| `ProxyTerminatingEndpoints` | `false` | Alpha | 1.22 | |
| `ProcMountType` | `false` | Alpha | 1.12 | |
| `ProxyTerminatingEndpoints` | `false` | Alpha | 1.22 | |
| `QOSReserved` | `false` | Alpha | 1.11 | |
| `ReadWriteOncePod` | `false` | Alpha | 1.22 | |
| `RemainingItemCount` | `false` | Alpha | 1.15 | 1.15 |
@@ -789,10 +789,6 @@ Each feature gate is designed for enabling/disabling a specific feature:
and volume controllers.
- `IndexedJob`: Allows the [Job](/docs/concepts/workloads/controllers/job/)
controller to manage Pod completions per completion index.
- `JobTrackingWithFinalizers`: Enables tracking [Job](/docs/concepts/workloads/controllers/job)
completions without relying on Pods remaining in the cluster indefinitely.
The Job controller uses Pod finalizers and a field in the Job status to keep
track of the finished Pods to count towards completion.
- `IngressClassNamespacedParams`: Allow namespace-scoped parameters reference in
`IngressClass` resource. This feature adds two fields - `Scope` and `Namespace`
to `IngressClass.spec.parameters`.
@@ -800,10 +796,10 @@ Each feature gate is designed for enabling/disabling a specific feature:
Initializers admission plugin.
- `IPv6DualStack`: Enable [dual stack](/docs/concepts/services-networking/dual-stack/)
support for IPv6.
- `JobTrackingWithFinalizers`: Enables the tracking of Job completion without
relying on Pods remaining in the cluster indefinitely. Pod finalizers, in
addition to a field in the Job status, allow the Job controller to track
Pods that it didn't account for yet.
- `JobTrackingWithFinalizers`: Enables tracking [Job](/docs/concepts/workloads/controllers/job)
completions without relying on Pods remaining in the cluster indefinitely.
The Job controller uses Pod finalizers and a field in the Job status to keep
track of the finished Pods to count towards completion.
- `KubeletConfigFile`: Enable loading kubelet configuration from
a file specified using a config file.
See [setting kubelet parameters via a config file](/docs/tasks/administer-cluster/kubelet-config-file/)
@@ -1012,18 +1008,16 @@ Each feature gate is designed for enabling/disabling a specific feature:
- `WatchBookmark`: Enable support for watch bookmark events.
- `WinDSR`: Allows kube-proxy to create DSR loadbalancers for Windows.
- `WinOverlay`: Allows kube-proxy to run in overlay mode for Windows.
- `WindowsEndpointSliceProxying`: When enabled, kube-proxy running on Windows
will use EndpointSlices as the primary data source instead of Endpoints,
enabling scalability and performance improvements. See
[Enabling Endpoint Slices](/docs/tasks/administer-cluster/enabling-endpointslices/).
- `WindowsGMSA`: Enables passing of GMSA credential specs from pods to container runtimes.
- `WindowsHostProcessContainers`: Enables support for Windows HostProcess containers.
- `WindowsRunAsUserName` : Enable support for running applications in Windows containers
with as a non-default user. See
[Configuring RunAsUserName](/docs/tasks/configure-pod-container/configure-runasusername)
for more details.
- `WindowsEndpointSliceProxying`: When enabled, kube-proxy running on Windows
will use EndpointSlices as the primary data source instead of Endpoints,
enabling scalability and performance improvements. See
[Enabling Endpoint Slices](/docs/tasks/administer-cluster/enabling-endpointslices/).
- `WindowsHostProcessContainers`: Enables the support for `HostProcess`
containers on Windows nodes.
## {{% heading "whatsnext" %}}
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -18,7 +18,7 @@ The normal process of bootstrapping these components, especially worker nodes th
can be a challenging process as it is often outside of the scope of Kubernetes and requires significant additional work.
This in turn, can make it challenging to initialize or scale a cluster.
In order to simplify the process, beginning in version 1.4, Kubernetes introduced a certificate request and signing API to simplify the process. The proposal can be
In order to simplify the process, beginning in version 1.4, Kubernetes introduced a certificate request and signing API. The proposal can be
found [here](https://github.com/kubernetes/kubernetes/pull/20439).
This document describes the process of node initialization, how to set up TLS client certificate bootstrapping for
File diff suppressed because it is too large Load Diff
@@ -81,7 +81,7 @@ For non-resource requests, this is the lower-cased HTTP method.</td>
<tr><td><code>user</code> <B>[Required]</B><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#userinfo-v1-authentication"><code>authentication/v1.UserInfo</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#userinfo-v1-authentication"><code>authentication/v1.UserInfo</code></a>
</td>
<td>
Authenticated user information.</td>
@@ -89,7 +89,7 @@ For non-resource requests, this is the lower-cased HTTP method.</td>
<tr><td><code>impersonatedUser</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#userinfo-v1-authentication"><code>authentication/v1.UserInfo</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#userinfo-v1-authentication"><code>authentication/v1.UserInfo</code></a>
</td>
<td>
Impersonated user information.</td>
@@ -123,7 +123,7 @@ Does not apply for List-type requests, or non-resource requests.</td>
<tr><td><code>responseStatus</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#status-v1-meta"><code>meta/v1.Status</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#status-v1-meta"><code>meta/v1.Status</code></a>
</td>
<td>
The response status, populated even when the ResponseObject is not a Status type.
@@ -154,7 +154,7 @@ at Response Level.</td>
<tr><td><code>requestReceivedTimestamp</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
</td>
<td>
Time the request reached the apiserver.</td>
@@ -162,7 +162,7 @@ at Response Level.</td>
<tr><td><code>stageTimestamp</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
</td>
<td>
Time the request reached current audit stage.</td>
@@ -206,7 +206,7 @@ EventList is a list of audit Events.
<tr><td><code>metadata</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
</td>
<td>
<span class="text-muted">No description provided.</span>
@@ -252,7 +252,7 @@ categories are logged.
<tr><td><code>metadata</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#objectmeta-v1-meta"><code>meta/v1.ObjectMeta</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#objectmeta-v1-meta"><code>meta/v1.ObjectMeta</code></a>
</td>
<td>
ObjectMeta is included for interoperability with API infrastructure.Refer to the Kubernetes API documentation for the fields of the <code>metadata</code> field.</td>
@@ -303,7 +303,7 @@ PolicyList is a list of audit Policies.
<tr><td><code>metadata</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
</td>
<td>
<span class="text-muted">No description provided.</span>
@@ -187,6 +187,14 @@ ExecConfig.ProvideClusterInfo).</td>
</tr>
<tr><td><code>interactive</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
Interactive declares whether stdin has been passed to this exec plugin.</td>
</tr>
</tbody>
</table>
@@ -215,7 +223,7 @@ itself should at least be protected via file permissions.
<tr><td><code>expirationTimestamp</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#time-v1-meta"><code>meta/v1.Time</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#time-v1-meta"><code>meta/v1.Time</code></a>
</td>
<td>
ExpirationTimestamp indicates a time when the provided credentials expire.</td>
@@ -546,6 +546,10 @@ this always falls back to the userspace proxy.
- [KubeProxyConfiguration](#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration)
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
- [GenericControllerManagerConfiguration](#controllermanager-config-k8s-io-v1alpha1-GenericControllerManagerConfiguration)
ClientConnectionConfiguration contains details for constructing a client.
@@ -597,5 +601,180 @@ client.</td>
</tr>
</tbody>
</table>
## `DebuggingConfiguration` {#DebuggingConfiguration}
**Appears in:**
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
- [GenericControllerManagerConfiguration](#controllermanager-config-k8s-io-v1alpha1-GenericControllerManagerConfiguration)
DebuggingConfiguration holds configuration for Debugging related features.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>enableProfiling</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
enableProfiling enables profiling via web interface host:port/debug/pprof/</td>
</tr>
<tr><td><code>enableContentionProfiling</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
enableContentionProfiling enables lock contention profiling, if
enableProfiling is true.</td>
</tr>
</tbody>
</table>
## `LeaderElectionConfiguration` {#LeaderElectionConfiguration}
**Appears in:**
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
- [GenericControllerManagerConfiguration](#controllermanager-config-k8s-io-v1alpha1-GenericControllerManagerConfiguration)
LeaderElectionConfiguration defines the configuration of leader election
clients for components that can run with leader election enabled.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>leaderElect</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
leaderElect enables a leader election client to gain leadership
before executing the main loop. Enable this when running replicated
components for high availability.</td>
</tr>
<tr><td><code>leaseDuration</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
leaseDuration is the duration that non-leader candidates will wait
after observing a leadership renewal until attempting to acquire
leadership of a led but unrenewed leader slot. This is effectively the
maximum duration that a leader can be stopped before it is replaced
by another candidate. This is only applicable if leader election is
enabled.</td>
</tr>
<tr><td><code>renewDeadline</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
renewDeadline is the interval between attempts by the acting master to
renew a leadership slot before it stops leading. This must be less
than or equal to the lease duration. This is only applicable if leader
election is enabled.</td>
</tr>
<tr><td><code>retryPeriod</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
retryPeriod is the duration the clients should wait between attempting
acquisition and renewal of a leadership. This is only applicable if
leader election is enabled.</td>
</tr>
<tr><td><code>resourceLock</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceLock indicates the resource object type that will be used to lock
during leader election cycles.</td>
</tr>
<tr><td><code>resourceName</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceName indicates the name of resource object that will be used to lock
during leader election cycles.</td>
</tr>
<tr><td><code>resourceNamespace</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceName indicates the namespace of resource object that will be used to lock
during leader election cycles.</td>
</tr>
</tbody>
</table>
## `LoggingConfiguration` {#LoggingConfiguration}
**Appears in:**
- [KubeletConfiguration](#kubelet-config-k8s-io-v1beta1-KubeletConfiguration)
LoggingConfiguration contains logging options
Refer [Logs Options](https://github.com/kubernetes/component-base/blob/master/logs/options.go) for more information.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>format</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
Format Flag specifies the structure of log messages.
default value of format is `text`</td>
</tr>
<tr><td><code>sanitization</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
[Experimental] When enabled prevents logging of fields tagged as sensitive (passwords, keys, tokens).
Runtime log sanitization may introduce significant computation overhead and therefore should not be enabled in production.`)</td>
</tr>
</tbody>
</table>
@@ -13,16 +13,250 @@ auto_generated: true
- [InterPodAffinityArgs](#kubescheduler-config-k8s-io-v1beta2-InterPodAffinityArgs)
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
- [NodeAffinityArgs](#kubescheduler-config-k8s-io-v1beta2-NodeAffinityArgs)
- [NodeResourcesBalancedAllocationArgs](#kubescheduler-config-k8s-io-v1beta2-NodeResourcesBalancedAllocationArgs)
- [NodeResourcesFitArgs](#kubescheduler-config-k8s-io-v1beta2-NodeResourcesFitArgs)
- [NodeResourcesLeastAllocatedArgs](#kubescheduler-config-k8s-io-v1beta2-NodeResourcesLeastAllocatedArgs)
- [NodeResourcesMostAllocatedArgs](#kubescheduler-config-k8s-io-v1beta2-NodeResourcesMostAllocatedArgs)
- [PodTopologySpreadArgs](#kubescheduler-config-k8s-io-v1beta2-PodTopologySpreadArgs)
- [RequestedToCapacityRatioArgs](#kubescheduler-config-k8s-io-v1beta2-RequestedToCapacityRatioArgs)
- [VolumeBindingArgs](#kubescheduler-config-k8s-io-v1beta2-VolumeBindingArgs)
- [Policy](#kubescheduler-config-k8s-io-v1-Policy)
## `ClientConnectionConfiguration` {#ClientConnectionConfiguration}
**Appears in:**
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
ClientConnectionConfiguration contains details for constructing a client.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>kubeconfig</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
kubeconfig is the path to a KubeConfig file.</td>
</tr>
<tr><td><code>acceptContentTypes</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
acceptContentTypes defines the Accept header sent by clients when connecting to a server, overriding the
default value of 'application/json'. This field will control all connections to the server used by a particular
client.</td>
</tr>
<tr><td><code>contentType</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
contentType is the content type used when sending data to the server from this client.</td>
</tr>
<tr><td><code>qps</code> <B>[Required]</B><br/>
<code>float32</code>
</td>
<td>
qps controls the number of queries per second allowed for this connection.</td>
</tr>
<tr><td><code>burst</code> <B>[Required]</B><br/>
<code>int32</code>
</td>
<td>
burst allows extra queries to accumulate when a client is exceeding its rate.</td>
</tr>
</tbody>
</table>
## `DebuggingConfiguration` {#DebuggingConfiguration}
**Appears in:**
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
DebuggingConfiguration holds configuration for Debugging related features.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>enableProfiling</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
enableProfiling enables profiling via web interface host:port/debug/pprof/</td>
</tr>
<tr><td><code>enableContentionProfiling</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
enableContentionProfiling enables lock contention profiling, if
enableProfiling is true.</td>
</tr>
</tbody>
</table>
## `LeaderElectionConfiguration` {#LeaderElectionConfiguration}
**Appears in:**
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
LeaderElectionConfiguration defines the configuration of leader election
clients for components that can run with leader election enabled.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>leaderElect</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
leaderElect enables a leader election client to gain leadership
before executing the main loop. Enable this when running replicated
components for high availability.</td>
</tr>
<tr><td><code>leaseDuration</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
leaseDuration is the duration that non-leader candidates will wait
after observing a leadership renewal until attempting to acquire
leadership of a led but unrenewed leader slot. This is effectively the
maximum duration that a leader can be stopped before it is replaced
by another candidate. This is only applicable if leader election is
enabled.</td>
</tr>
<tr><td><code>renewDeadline</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
renewDeadline is the interval between attempts by the acting master to
renew a leadership slot before it stops leading. This must be less
than or equal to the lease duration. This is only applicable if leader
election is enabled.</td>
</tr>
<tr><td><code>retryPeriod</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
retryPeriod is the duration the clients should wait between attempting
acquisition and renewal of a leadership. This is only applicable if
leader election is enabled.</td>
</tr>
<tr><td><code>resourceLock</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceLock indicates the resource object type that will be used to lock
during leader election cycles.</td>
</tr>
<tr><td><code>resourceName</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceName indicates the name of resource object that will be used to lock
during leader election cycles.</td>
</tr>
<tr><td><code>resourceNamespace</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceName indicates the namespace of resource object that will be used to lock
during leader election cycles.</td>
</tr>
</tbody>
</table>
## `LoggingConfiguration` {#LoggingConfiguration}
**Appears in:**
- [KubeletConfiguration](#kubelet-config-k8s-io-v1beta1-KubeletConfiguration)
LoggingConfiguration contains logging options
Refer [Logs Options](https://github.com/kubernetes/component-base/blob/master/logs/options.go) for more information.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>format</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
Format Flag specifies the structure of log messages.
default value of format is `text`</td>
</tr>
<tr><td><code>sanitization</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
[Experimental] When enabled prevents logging of fields tagged as sensitive (passwords, keys, tokens).
Runtime log sanitization may introduce significant computation overhead and therefore should not be enabled in production.`)</td>
</tr>
</tbody>
</table>
## `DefaultPreemptionArgs` {#kubescheduler-config-k8s-io-v1beta2-DefaultPreemptionArgs}
@@ -254,7 +488,7 @@ NodeAffinityArgs holds arguments to configure the NodeAffinity plugin.
<tr><td><code>addedAffinity</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#nodeaffinity-v1-core"><code>core/v1.NodeAffinity</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#nodeaffinity-v1-core"><code>core/v1.NodeAffinity</code></a>
</td>
<td>
AddedAffinity is applied to all Pods additionally to the NodeAffinity
@@ -271,6 +505,37 @@ a specific Node (such as Daemonset Pods) might remain unschedulable.</td>
## `NodeResourcesBalancedAllocationArgs` {#kubescheduler-config-k8s-io-v1beta2-NodeResourcesBalancedAllocationArgs}
NodeResourcesBalancedAllocationArgs holds arguments used to configure NodeResourcesBalancedAllocation plugin.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>apiVersion</code><br/>string</td><td><code>kubescheduler.config.k8s.io/v1beta2</code></td></tr>
<tr><td><code>kind</code><br/>string</td><td><code>NodeResourcesBalancedAllocationArgs</code></td></tr>
<tr><td><code>resources</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-ResourceSpec"><code>[]ResourceSpec</code></a>
</td>
<td>
Resources to be managed, the default is "cpu" and "memory" if not specified.</td>
</tr>
</tbody>
</table>
## `NodeResourcesFitArgs` {#kubescheduler-config-k8s-io-v1beta2-NodeResourcesFitArgs}
@@ -294,7 +559,7 @@ NodeResourcesFitArgs holds arguments used to configure the NodeResourcesFit plug
</td>
<td>
IgnoredResources is the list of resources that NodeResources fit filter
should ignore.</td>
should ignore. This doesn't apply to scoring.</td>
</tr>
@@ -305,73 +570,16 @@ should ignore.</td>
IgnoredResourceGroups defines the list of resource groups that NodeResources fit filter should ignore.
e.g. if group is ["example.com"], it will ignore all resource names that begin
with "example.com", such as "example.com/aaa" and "example.com/bbb".
A resource group name can't contain '/'.</td>
A resource group name can't contain '/'. This doesn't apply to scoring.</td>
</tr>
</tbody>
</table>
## `NodeResourcesLeastAllocatedArgs` {#kubescheduler-config-k8s-io-v1beta2-NodeResourcesLeastAllocatedArgs}
NodeResourcesLeastAllocatedArgs holds arguments used to configure NodeResourcesLeastAllocated plugin.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>apiVersion</code><br/>string</td><td><code>kubescheduler.config.k8s.io/v1beta2</code></td></tr>
<tr><td><code>kind</code><br/>string</td><td><code>NodeResourcesLeastAllocatedArgs</code></td></tr>
<tr><td><code>resources</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-ResourceSpec"><code>[]ResourceSpec</code></a>
<tr><td><code>scoringStrategy</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-ScoringStrategy"><code>ScoringStrategy</code></a>
</td>
<td>
Resources to be managed, if no resource is provided, default resource set with both
the weight of "cpu" and "memory" set to "1" will be applied.
Resource with "0" weight will not accountable for the final score.</td>
</tr>
</tbody>
</table>
## `NodeResourcesMostAllocatedArgs` {#kubescheduler-config-k8s-io-v1beta2-NodeResourcesMostAllocatedArgs}
NodeResourcesMostAllocatedArgs holds arguments used to configure NodeResourcesMostAllocated plugin.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>apiVersion</code><br/>string</td><td><code>kubescheduler.config.k8s.io/v1beta2</code></td></tr>
<tr><td><code>kind</code><br/>string</td><td><code>NodeResourcesMostAllocatedArgs</code></td></tr>
<tr><td><code>resources</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-ResourceSpec"><code>[]ResourceSpec</code></a>
</td>
<td>
Resources to be managed, if no resource is provided, default resource set with both
the weight of "cpu" and "memory" set to "1" will be applied.
Resource with "0" weight will not accountable for the final score.</td>
ScoringStrategy selects the node resource scoring strategy.
The default strategy is LeastAllocated with an equal "cpu" and "memory" weight.</td>
</tr>
@@ -399,7 +607,7 @@ PodTopologySpreadArgs holds arguments used to configure the PodTopologySpread pl
<tr><td><code>defaultConstraints</code><br/>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#topologyspreadconstraint-v1-core"><code>[]core/v1.TopologySpreadConstraint</code></a>
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#topologyspreadconstraint-v1-core"><code>[]core/v1.TopologySpreadConstraint</code></a>
</td>
<td>
DefaultConstraints defines topology spread constraints to be applied to
@@ -432,45 +640,6 @@ and to "System" if enabled.</td>
## `RequestedToCapacityRatioArgs` {#kubescheduler-config-k8s-io-v1beta2-RequestedToCapacityRatioArgs}
RequestedToCapacityRatioArgs holds arguments used to configure RequestedToCapacityRatio plugin.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>apiVersion</code><br/>string</td><td><code>kubescheduler.config.k8s.io/v1beta2</code></td></tr>
<tr><td><code>kind</code><br/>string</td><td><code>RequestedToCapacityRatioArgs</code></td></tr>
<tr><td><code>shape</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-UtilizationShapePoint"><code>[]UtilizationShapePoint</code></a>
</td>
<td>
Points defining priority function shape</td>
</tr>
<tr><td><code>resources</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-ResourceSpec"><code>[]ResourceSpec</code></a>
</td>
<td>
Resources to be managed</td>
</tr>
</tbody>
</table>
## `VolumeBindingArgs` {#kubescheduler-config-k8s-io-v1beta2-VolumeBindingArgs}
@@ -499,6 +668,24 @@ If this value is nil, the default value (600) will be used.</td>
</tr>
<tr><td><code>shape</code><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-UtilizationShapePoint"><code>[]UtilizationShapePoint</code></a>
</td>
<td>
Shape specifies the points defining the score function shape, which is
used to score nodes based on the utilization of statically provisioned
PVs. The utilization is calculated by dividing the total requested
storage of the pod by the total capacity of feasible PVs on each node.
Each point contains utilization (ranges from 0 to 100) and its
associated score (ranges from 0 to 10). You can turn the priority by
specifying different scores for different utilization numbers.
The default shape points are:
1) 0 for 0 utilization
2) 10 for 100 utilization
All points must be sorted in increasing order by utilization.</td>
</tr>
</tbody>
</table>
@@ -800,6 +987,8 @@ If an array is empty, missing, or nil, default plugins at that extension point w
</td>
<td>
Enabled specifies plugins that should be enabled in addition to default plugins.
If the default plugin is also configured in the scheduler config file, the weight of plugin will
be overridden accordingly.
These are called after default plugins and in the same order specified here.</td>
</tr>
@@ -952,6 +1141,37 @@ for the PodTopologySpread plugin.
## `RequestedToCapacityRatioParam` {#kubescheduler-config-k8s-io-v1beta2-RequestedToCapacityRatioParam}
**Appears in:**
- [ScoringStrategy](#kubescheduler-config-k8s-io-v1beta2-ScoringStrategy)
RequestedToCapacityRatioParam define RequestedToCapacityRatio parameters
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>shape</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-UtilizationShapePoint"><code>[]UtilizationShapePoint</code></a>
</td>
<td>
Shape is a list of points defining the scoring function shape.</td>
</tr>
</tbody>
</table>
## `ResourceSpec` {#kubescheduler-config-k8s-io-v1beta2-ResourceSpec}
@@ -959,14 +1179,12 @@ for the PodTopologySpread plugin.
**Appears in:**
- [NodeResourcesLeastAllocatedArgs](#kubescheduler-config-k8s-io-v1beta2-NodeResourcesLeastAllocatedArgs)
- [NodeResourcesBalancedAllocationArgs](#kubescheduler-config-k8s-io-v1beta2-NodeResourcesBalancedAllocationArgs)
- [NodeResourcesMostAllocatedArgs](#kubescheduler-config-k8s-io-v1beta2-NodeResourcesMostAllocatedArgs)
- [RequestedToCapacityRatioArgs](#kubescheduler-config-k8s-io-v1beta2-RequestedToCapacityRatioArgs)
- [ScoringStrategy](#kubescheduler-config-k8s-io-v1beta2-ScoringStrategy)
ResourceSpec represents single resource and weight for bin packing of priority RequestedToCapacityRatioArguments.
ResourceSpec represents a single resource.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
@@ -978,7 +1196,7 @@ ResourceSpec represents single resource and weight for bin packing of priority R
<code>string</code>
</td>
<td>
Name of the resource to be managed by RequestedToCapacityRatio function.</td>
Name of the resource.</td>
</tr>
@@ -995,6 +1213,72 @@ ResourceSpec represents single resource and weight for bin packing of priority R
## `ScoringStrategy` {#kubescheduler-config-k8s-io-v1beta2-ScoringStrategy}
**Appears in:**
- [NodeResourcesFitArgs](#kubescheduler-config-k8s-io-v1beta2-NodeResourcesFitArgs)
ScoringStrategy define ScoringStrategyType for node resource plugin
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>type</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-ScoringStrategyType"><code>ScoringStrategyType</code></a>
</td>
<td>
Type selects which strategy to run.</td>
</tr>
<tr><td><code>resources</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-ResourceSpec"><code>[]ResourceSpec</code></a>
</td>
<td>
Resources to consider when scoring.
The default resource set includes "cpu" and "memory" with an equal weight.
Allowed weights go from 1 to 100.
Weight defaults to 1 if not specified or explicitly set to 0.</td>
</tr>
<tr><td><code>requestedToCapacityRatio</code> <B>[Required]</B><br/>
<a href="#kubescheduler-config-k8s-io-v1beta2-RequestedToCapacityRatioParam"><code>RequestedToCapacityRatioParam</code></a>
</td>
<td>
Arguments specific to RequestedToCapacityRatio strategy.</td>
</tr>
</tbody>
</table>
## `ScoringStrategyType` {#kubescheduler-config-k8s-io-v1beta2-ScoringStrategyType}
(Alias of `string`)
**Appears in:**
- [ScoringStrategy](#kubescheduler-config-k8s-io-v1beta2-ScoringStrategy)
ScoringStrategyType the type of scoring strategy used in NodeResourcesFit plugin.
## `UtilizationShapePoint` {#kubescheduler-config-k8s-io-v1beta2-UtilizationShapePoint}
@@ -1002,7 +1286,9 @@ ResourceSpec represents single resource and weight for bin packing of priority R
**Appears in:**
- [RequestedToCapacityRatioArgs](#kubescheduler-config-k8s-io-v1beta2-RequestedToCapacityRatioArgs)
- [VolumeBindingArgs](#kubescheduler-config-k8s-io-v1beta2-VolumeBindingArgs)
- [RequestedToCapacityRatioParam](#kubescheduler-config-k8s-io-v1beta2-RequestedToCapacityRatioParam)
UtilizationShapePoint represents single point of priority function shape.
@@ -1820,199 +2106,3 @@ UtilizationShapePoint represents single point of priority function shape.
</table>
## `ClientConnectionConfiguration` {#ClientConnectionConfiguration}
**Appears in:**
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
ClientConnectionConfiguration contains details for constructing a client.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>kubeconfig</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
kubeconfig is the path to a KubeConfig file.</td>
</tr>
<tr><td><code>acceptContentTypes</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
acceptContentTypes defines the Accept header sent by clients when connecting to a server, overriding the
default value of 'application/json'. This field will control all connections to the server used by a particular
client.</td>
</tr>
<tr><td><code>contentType</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
contentType is the content type used when sending data to the server from this client.</td>
</tr>
<tr><td><code>qps</code> <B>[Required]</B><br/>
<code>float32</code>
</td>
<td>
qps controls the number of queries per second allowed for this connection.</td>
</tr>
<tr><td><code>burst</code> <B>[Required]</B><br/>
<code>int32</code>
</td>
<td>
burst allows extra queries to accumulate when a client is exceeding its rate.</td>
</tr>
</tbody>
</table>
## `DebuggingConfiguration` {#DebuggingConfiguration}
**Appears in:**
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
DebuggingConfiguration holds configuration for Debugging related features.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>enableProfiling</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
enableProfiling enables profiling via web interface host:port/debug/pprof/</td>
</tr>
<tr><td><code>enableContentionProfiling</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
enableContentionProfiling enables lock contention profiling, if
enableProfiling is true.</td>
</tr>
</tbody>
</table>
## `LeaderElectionConfiguration` {#LeaderElectionConfiguration}
**Appears in:**
- [KubeSchedulerConfiguration](#kubescheduler-config-k8s-io-v1beta2-KubeSchedulerConfiguration)
LeaderElectionConfiguration defines the configuration of leader election
clients for components that can run with leader election enabled.
<table class="table">
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
<tbody>
<tr><td><code>leaderElect</code> <B>[Required]</B><br/>
<code>bool</code>
</td>
<td>
leaderElect enables a leader election client to gain leadership
before executing the main loop. Enable this when running replicated
components for high availability.</td>
</tr>
<tr><td><code>leaseDuration</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
leaseDuration is the duration that non-leader candidates will wait
after observing a leadership renewal until attempting to acquire
leadership of a led but unrenewed leader slot. This is effectively the
maximum duration that a leader can be stopped before it is replaced
by another candidate. This is only applicable if leader election is
enabled.</td>
</tr>
<tr><td><code>renewDeadline</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
renewDeadline is the interval between attempts by the acting master to
renew a leadership slot before it stops leading. This must be less
than or equal to the lease duration. This is only applicable if leader
election is enabled.</td>
</tr>
<tr><td><code>retryPeriod</code> <B>[Required]</B><br/>
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
</td>
<td>
retryPeriod is the duration the clients should wait between attempting
acquisition and renewal of a leadership. This is only applicable if
leader election is enabled.</td>
</tr>
<tr><td><code>resourceLock</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceLock indicates the resource object type that will be used to lock
during leader election cycles.</td>
</tr>
<tr><td><code>resourceName</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceName indicates the name of resource object that will be used to lock
during leader election cycles.</td>
</tr>
<tr><td><code>resourceNamespace</code> <B>[Required]</B><br/>
<code>string</code>
</td>
<td>
resourceName indicates the namespace of resource object that will be used to lock
during leader election cycles.</td>
</tr>
</tbody>
</table>
@@ -89,7 +89,7 @@ of the predicates after it finds one predicate that failed.</td>
**Appears in:**
- [Extender](#kubescheduler-config-k8s-io-v1beta1-Extender)
- [Extender](#kubescheduler-config-k8s-io-v1beta2-Extender)
- [LegacyExtender](#kubescheduler-config-k8s-io-v1-LegacyExtender)
@@ -132,7 +132,7 @@ resource when applying predicates.</td>
**Appears in:**
- [Extender](#kubescheduler-config-k8s-io-v1beta1-Extender)
- [Extender](#kubescheduler-config-k8s-io-v1beta2-Extender)
- [LegacyExtender](#kubescheduler-config-k8s-io-v1-LegacyExtender)
@@ -1413,9 +1413,15 @@ first alpha-numerically.</td>
</tbody>
</table>
## `BootstrapToken` {#BootstrapToken}
**Appears in:**
- [InitConfiguration](#kubeadm-k8s-io-v1beta3-InitConfiguration)
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,18 @@
---
title: Eviction
id: eviction
date: 2021-05-08
full_link: /docs/concepts/scheduling-eviction/
short_description: >
Process of terminating one or more Pods on Nodes
aka:
tags:
- operation
---
Eviction is the process of terminating one or more Pods on Nodes.
<!--more-->
There are two kinds of eviction:
* [Node-pressure eviction](/docs/concepts/scheduling-eviction/node-pressure-eviction/)
* [API-initiated eviction](/docs/concepts/scheduling-eviction/api-eviction/)
@@ -29,7 +29,7 @@ To make a report, submit your vulnerability to the [Kubernetes bug bounty progra
You can also email the private [security@kubernetes.io](mailto:security@kubernetes.io) list with the security details and the details expected for [all Kubernetes bug reports](https://git.k8s.io/kubernetes/.github/ISSUE_TEMPLATE/bug-report.md).
You may encrypt your email to this list using the GPG keys of the [Product Security Committee members](https://git.k8s.io/security/README.md#product-security-committee-psc). Encryption using GPG is NOT required to make a disclosure.
You may encrypt your email to this list using the GPG keys of the [Security Response Committee members](https://git.k8s.io/security/README.md#product-security-committee-psc). Encryption using GPG is NOT required to make a disclosure.
### When Should I Report a Vulnerability?
@@ -47,13 +47,13 @@ You may encrypt your email to this list using the GPG keys of the [Product Secur
## Security Vulnerability Response
Each report is acknowledged and analyzed by Product Security Committee members within 3 working days. This will set off the [Security Release Process](https://git.k8s.io/security/security-release-process.md#disclosures).
Each report is acknowledged and analyzed by Security Response Committee members within 3 working days. This will set off the [Security Release Process](https://git.k8s.io/security/security-release-process.md#disclosures).
Any vulnerability information shared with Product Security Committee stays within Kubernetes project and will not be disseminated to other projects unless it is necessary to get the issue fixed.
Any vulnerability information shared with Security Response Committee stays within Kubernetes project and will not be disseminated to other projects unless it is necessary to get the issue fixed.
As the security issue moves from triage, to identified fix, to release planning we will keep the reporter updated.
## Public Disclosure Timing
A public disclosure date is negotiated by the Kubernetes Product Security Committee and the bug submitter. We prefer to fully disclose the bug as soon as possible once a user mitigation is available. It is reasonable to delay disclosure when the bug or the fix is not yet fully understood, the solution is not well-tested, or for vendor coordination. The timeframe for disclosure is from immediate (especially if it's already publicly known) to a few weeks. For a vulnerability with a straightforward mitigation, we expect report date to disclosure date to be on the order of 7 days. The Kubernetes Product Security Committee holds the final say when setting a disclosure date.
A public disclosure date is negotiated by the Kubernetes Security Response Committee and the bug submitter. We prefer to fully disclose the bug as soon as possible once a user mitigation is available. It is reasonable to delay disclosure when the bug or the fix is not yet fully understood, the solution is not well-tested, or for vendor coordination. The timeframe for disclosure is from immediate (especially if it's already publicly known) to a few weeks. For a vulnerability with a straightforward mitigation, we expect report date to disclosure date to be on the order of 7 days. The Kubernetes Security Response Committee holds the final say when setting a disclosure date.
@@ -71,6 +71,32 @@ Flags that you specify from the command line override default values and any cor
If you need help, run `kubectl help` from the terminal window.
## In-cluster authentication and namespace overrides
By default `kubectl` will first determine if it is running within a pod, and thus in a cluster. It starts by checking for the `KUBERNETES_SERVICE_HOST` and `KUBERNETES_SERVICE_PORT` environment variables and the existence of a service account token file at `/var/run/secrets/kubernetes.io/serviceaccount/token`. If all three are found in-cluster authentication is assumed.
To maintain backwards compatibility, if the `POD_NAMESPACE` environment variable is set during in-cluster authentication it will override the default namespace from the from the service account token. Any manifests or tools relying on namespace defaulting will be affected by this.
**`POD_NAMESPACE` environment variable**
If the `POD_NAMESPACE` environment variable is set, cli operations on namespaced resources will default to the variable value. For example, if the variable is set to `seattle`, `kubectl get pods` would return pods in the `seattle` namespace. This is because pods are a namespaced resource, and no namespace was provided in the command. Review the output of `kubectl api-resources` to determine if a resource is namespaced.
Explicit use of `--namespace <value>` overrides this behavior.
**How kubectl handles ServiceAccount tokens**
If:
* there is Kubernetes service account token file mounted at
`/var/run/secrets/kubernetes.io/serviceaccount/token`, and
* the `KUBERNETES_SERVICE_HOST` environment variable is set, and
* the `KUBERNETES_SERVICE_PORT` environment variable is set, and
* you don't explicitly specify a namespace on the kubectl command line
then kubectl assumes it is running in your cluster. The kubectl tool looks up the
namespace of that ServiceAccount (this is the same as the namespace of the Pod)
and acts against that namespace. This is different from what happens outside of a
cluster; when kubectl runs outside a cluster and you don't specify a namespace,
the kubectl command acts against the `default` namespace.
## Operations
The following table includes short descriptions and the general syntax for all of the `kubectl` operations:
@@ -15,7 +15,7 @@ file and passing its path as a command line argument.
A scheduling Profile allows you to configure the different stages of scheduling
in the {{< glossary_tooltip text="kube-scheduler" term_id="kube-scheduler" >}}.
Each stage is exposed in a extension point. Plugins provide scheduling behaviors
Each stage is exposed in an extension point. Plugins provide scheduling behaviors
by implementing one or more of these extension points.
You can specify scheduling profiles by running `kube-scheduler --config <filename>`,
@@ -8,7 +8,7 @@ card:
weight: 40
---
<img src="https://raw.githubusercontent.com/kubernetes/kubeadm/master/logos/stacked/color/kubeadm-stacked-color.png" align="right" width="150px">Kubeadm is a tool built to provide `kubeadm init` and `kubeadm join` as best-practice "fast paths" for creating Kubernetes clusters.
<img src="/images/kubeadm-stacked-color.png" align="right" width="150px">Kubeadm is a tool built to provide `kubeadm init` and `kubeadm join` as best-practice "fast paths" for creating Kubernetes clusters.
kubeadm performs the actions necessary to get a minimum viable cluster up and running. By design, it cares only about bootstrapping, not about provisioning machines. Likewise, installing various nice-to-have addons, like the Kubernetes Dashboard, monitoring solutions, and cloud-specific addons, is not in scope.
@@ -1,61 +0,0 @@
<!--
The file is auto-generated from the Go source code of the component using a generic
[generator](https://github.com/kubernetes-sigs/reference-docs/). To learn how
to generate the reference documentation, please read
[Contributing to the reference documentation](/docs/contribute/generate-ref-docs/).
To update the reference conent, please follow the
[Contributing upstream](/docs/contribute/generate-ref-docs/contribute-upstream/)
guide. You can file document formatting bugs against the
[reference-docs](https://github.com/kubernetes-sigs/reference-docs/) project.
-->
Kubeadm experimental sub-commands
### Synopsis
Kubeadm experimental sub-commands
### Options
<table style="width: 100%; table-layout: fixed;">
<colgroup>
<col span="1" style="width: 10px;" />
<col span="1" />
</colgroup>
<tbody>
<tr>
<td colspan="2">-h, --help</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>help for alpha</p></td>
</tr>
</tbody>
</table>
### Options inherited from parent commands
<table style="width: 100%; table-layout: fixed;">
<colgroup>
<col span="1" style="width: 10px;" />
<col span="1" />
</colgroup>
<tbody>
<tr>
<td colspan="2">--rootfs string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>[EXPERIMENTAL] The path to the 'real' host root filesystem.</p></td>
</tr>
</tbody>
</table>
@@ -1,63 +0,0 @@
<!--
The file is auto-generated from the Go source code of the component using a generic
[generator](https://github.com/kubernetes-sigs/reference-docs/). To learn how
to generate the reference documentation, please read
[Contributing to the reference documentation](/docs/contribute/generate-ref-docs/).
To update the reference conent, please follow the
[Contributing upstream](/docs/contribute/generate-ref-docs/contribute-upstream/)
guide. You can file document formatting bugs against the
[reference-docs](https://github.com/kubernetes-sigs/reference-docs/) project.
-->
Kubeconfig file utilities
### Synopsis
Kubeconfig file utilities.
Alpha Disclaimer: this command is currently alpha.
### Options
<table style="width: 100%; table-layout: fixed;">
<colgroup>
<col span="1" style="width: 10px;" />
<col span="1" />
</colgroup>
<tbody>
<tr>
<td colspan="2">-h, --help</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>help for kubeconfig</p></td>
</tr>
</tbody>
</table>
### Options inherited from parent commands
<table style="width: 100%; table-layout: fixed;">
<colgroup>
<col span="1" style="width: 10px;" />
<col span="1" />
</colgroup>
<tbody>
<tr>
<td colspan="2">--rootfs string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>[EXPERIMENTAL] The path to the 'real' host root filesystem.</p></td>
</tr>
</tbody>
</table>
@@ -1,102 +0,0 @@
<!--
The file is auto-generated from the Go source code of the component using a generic
[generator](https://github.com/kubernetes-sigs/reference-docs/). To learn how
to generate the reference documentation, please read
[Contributing to the reference documentation](/docs/contribute/generate-ref-docs/).
To update the reference conent, please follow the
[Contributing upstream](/docs/contribute/generate-ref-docs/contribute-upstream/)
guide. You can file document formatting bugs against the
[reference-docs](https://github.com/kubernetes-sigs/reference-docs/) project.
-->
Output a kubeconfig file for an additional user
### Synopsis
Output a kubeconfig file for an additional user.
Alpha Disclaimer: this command is currently alpha.
```
kubeadm alpha kubeconfig user [flags]
```
### Examples
```
# Output a kubeconfig file for an additional user named foo using a kubeadm config file bar
kubeadm alpha kubeconfig user --client-name=foo --config=bar
```
### Options
<table style="width: 100%; table-layout: fixed;">
<colgroup>
<col span="1" style="width: 10px;" />
<col span="1" />
</colgroup>
<tbody>
<tr>
<td colspan="2">--client-name string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>The name of user. It will be used as the CN if client certificates are created</p></td>
</tr>
<tr>
<td colspan="2">--config string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>Path to a kubeadm configuration file.</p></td>
</tr>
<tr>
<td colspan="2">-h, --help</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>help for user</p></td>
</tr>
<tr>
<td colspan="2">--org strings</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>The orgnizations of the client certificate. It will be used as the O if client certificates are created</p></td>
</tr>
<tr>
<td colspan="2">--token string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>The token that should be used as the authentication mechanism for this kubeconfig, instead of client certificates</p></td>
</tr>
</tbody>
</table>
### Options inherited from parent commands
<table style="width: 100%; table-layout: fixed;">
<colgroup>
<col span="1" style="width: 10px;" />
<col span="1" />
</colgroup>
<tbody>
<tr>
<td colspan="2">--rootfs string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>[EXPERIMENTAL] The path to the 'real' host root filesystem.</p></td>
</tr>
</tbody>
</table>
@@ -17,7 +17,7 @@ Generate keys and certificate signing requests
Generates keys and certificate signing requests (CSRs) for all the certificates required to run the control plane. This command also generates partial kubeconfig files with private key data in the "users &gt; user &gt; client-key-data" field, and for each kubeconfig file an accompanying ".csr" file is created.
This command is designed for use in [Kubeadm External CA Mode](/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#external-ca-mode). It generates CSRs which you can then submit to your external certificate authority for signing.
This command is designed for use in [Kubeadm External CA Mode](https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#external-ca-mode). It generates CSRs which you can then submit to your external certificate authority for signing.
The PEM encoded signed certificates should then be saved alongside the key files, using ".crt" as the file extension, or in the case of kubeconfig files, the PEM encoded signed certificate should be base64 encoded and added to the kubeconfig file in the "users &gt; user &gt; client-certificate-data" field.
@@ -29,7 +29,7 @@ kubeadm certs generate-csr [flags]
```
# The following command will generate keys and CSRs for all control-plane certificates and kubeconfig files:
kubeadm alpha certs generate-csr --kubeconfig-dir /tmp/etc-k8s --cert-dir /tmp/etc-k8s/pki
kubeadm certs generate-csr --kubeconfig-dir /tmp/etc-k8s --cert-dir /tmp/etc-k8s/pki
```
### Options
@@ -50,20 +50,6 @@ kubeadm certs renew admin.conf [flags]
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>Path to a kubeadm configuration file.</p></td>
</tr>
<tr>
<td colspan="2">--csr-dir string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>The path to output the CSRs and private keys to</p></td>
</tr>
<tr>
<td colspan="2">--csr-only</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>Create CSRs instead of generating certificates</p></td>
</tr>
<tr>
<td colspan="2">-h, --help</td>
</tr>
@@ -44,20 +44,6 @@ kubeadm certs renew all [flags]
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>Path to a kubeadm configuration file.</p></td>
</tr>
<tr>
<td colspan="2">--csr-dir string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>The path to output the CSRs and private keys to</p></td>
</tr>
<tr>
<td colspan="2">--csr-only</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>Create CSRs instead of generating certificates</p></td>
</tr>
<tr>
<td colspan="2">-h, --help</td>
</tr>
@@ -50,20 +50,6 @@ kubeadm certs renew apiserver-etcd-client [flags]
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>Path to a kubeadm configuration file.</p></td>
</tr>
<tr>
<td colspan="2">--csr-dir string</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>The path to output the CSRs and private keys to</p></td>
</tr>
<tr>
<td colspan="2">--csr-only</td>
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;"><p>Create CSRs instead of generating certificates</p></td>
</tr>
<tr>
<td colspan="2">-h, --help</td>
</tr>

Some files were not shown because too many files have changed in this diff Show More