Compare commits

...

1230 Commits

Author SHA1 Message Date
Kubernetes Prow Robot 3ea9a06953 Merge pull request #34423 from jihoon-seo/220620_Update_outdated_dev-1.23-ko.3_M44
[ko] Update outdated files in `dev-1.23-ko.3` (M44-M77)
2022-07-25 11:54:34 -07:00
Kubernetes Prow Robot 724e2b9e88 Merge pull request #34254 from jihoon-seo/220613_Update_outdated_dev-1.23-ko.3_M1
[ko] Update outdated files in `dev-1.23-ko.3` (M1-M16)
2022-06-30 03:38:09 -07:00
Jihoon Seo 6d6a8be31b [ko] Update outdated files in dev-1.23-ko.3 (M44-M77) 2022-06-20 22:34:23 +09:00
Kubernetes Prow Robot 04e900f07b Merge pull request #34257 from jihoon-seo/220613_Update_outdated_dev-1.23-ko.3_M17
[ko] Update outdated files in `dev-1.23-ko.3` (M17-M43)
2022-06-19 16:04:03 -07:00
Jihoon Seo 848f6a180e [ko] Update outdated files in dev-1.23-ko.3 (M17-M43) 2022-06-20 07:52:50 +09:00
Jihoon Seo e8c5a078e4 [ko] Update outdated files in dev-1.23-ko.3 (M1-M16) 2022-06-20 07:43:28 +09:00
Kubernetes Prow Robot d81ac28907 Merge pull request #33706 from jihoon-seo/220516_ko_Update_links_in_dev-1.23-ko.3
[ko] Update links in `dev-1.23-ko.3`
2022-06-07 02:27:48 -07:00
Jihoon Seo 4cb6761b49 [ko] Update links in dev-1.23-ko.3 2022-05-16 12:09:15 +09:00
Nate W 28fe5e2814 Merge pull request #33412 from nate-double-u/update-release-1.23-config.toml
update release-1.23 config.toml for release 1.24
2022-05-03 16:12:42 -07:00
Nate W f0b1ec8a8e update release-1.23 config.toml for release 1.24
Signed-off-by: Nate W <4453979+nate-double-u@users.noreply.github.com>
2022-05-02 11:41:46 -07:00
Kubernetes Prow Robot a8b640bd6f Merge pull request #33388 from kinzhi/kinzhi79
[zh]Update /docs/tasks/debug/debug-application/debug-running-pod
2022-05-02 04:07:14 -07:00
Kubernetes Prow Robot cdbdf86f50 Merge pull request #33389 from kinzhi/kinzhi80
[zh]Update content/zh/docs/setup/production-environment/_index.md
2022-05-02 04:05:13 -07:00
Kubernetes Prow Robot c2c0864b39 Merge pull request #33376 from my-git9/cassandra4
[zh] Update statefule-application/cassandra.md
2022-05-02 03:57:13 -07:00
Kubernetes Prow Robot cc862075d0 Merge pull request #33358 from kinzhi/kinzhi70
[zh]Update content/zh/blog/_posts/2022-02-17-updated-dockershim-faq.md
2022-05-02 03:51:13 -07:00
Kubernetes Prow Robot f96d4b35ac Merge pull request #33394 from Arhell/upd-name
[fr] update pod-topology-spread-constraints adding the missing schedu…
2022-05-01 23:33:14 -07:00
Arhell 2ee729786c [fr] update pod-topology-spread-constraints adding the missing scheduler name 2022-05-02 00:34:38 +03:00
wei.wang 17321b2b64 [zh]Update content/zh/docs/setup/production-environment/_index.md 2022-05-02 03:17:44 +08:00
wei.wang d2a0ae199d [zh]Update /docs/tasks/debug/debug-application/debug-running-pod) 2022-05-02 03:07:26 +08:00
xin.li 6b326ece29 [zh] Update statefule-application/cassandra.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-05-01 19:42:32 +08:00
Kubernetes Prow Robot 06e3808ae1 Merge pull request #33370 from kinzhi/kinzhi75
[zh]Update content/zh/blog/_posts/2020-12-08-kubernetes-release-1.20.md
2022-05-01 03:49:12 -07:00
Kubernetes Prow Robot 3bad0359e4 Merge pull request #33369 from my-git9/resource-metrics-pipeline4
[zh] Sync horizontal-pod-autoscale.md
2022-05-01 03:47:12 -07:00
Kubernetes Prow Robot 37f35be43d Merge pull request #33349 from JarHMJ/add/content/zh/docs/tasks/debug/debug-application/_index.md
[zh] add content/zh/docs/tasks/debug/debug-application/_index.md
2022-05-01 03:43:13 -07:00
Kubernetes Prow Robot 46d1b3c69a Merge pull request #33368 from kinzhi/kinzhi74
[zh]Update content/zh/examples/pods/probe/exec-liveness.yaml
2022-05-01 03:41:12 -07:00
wei.wang 5da1001dda [zh]Update content/zh/blog/_posts/2020-12-08-kubernetes-release-1.20.md 2022-05-01 18:22:09 +08:00
xin.li cdea498639 [zh] change debug link
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-05-01 18:21:30 +08:00
wei.wang d640b30faa [zh]Update content/zh/examples/pods/probe/exec-liveness.yaml 2022-05-01 18:16:26 +08:00
Kubernetes Prow Robot a8cc362592 Merge pull request #33359 from kinzhi/kinzhi71
[zh]Sync content/zh/docs/tasks/debug/debug-application/debug-service.md
2022-05-01 02:21:13 -07:00
Kubernetes Prow Robot a782ed0712 Merge pull request #33357 from kinzhi/kinzhi69
[zh]Sync content/zh/docs/tasks/debug/debug-cluster/crictl.md
2022-05-01 02:13:13 -07:00
Kubernetes Prow Robot 449d80c1c8 Merge pull request #32919 from tallclair/broken-links-ru
[ru] Clean up various broken links
2022-05-01 00:11:12 -07:00
Kubernetes Prow Robot 2c6a497b16 Merge pull request #33352 from JarHMJ/content/zh/docs/tasks/debug-application-cluster/resource-metrics-pipeline.md
[zh] sync Resource metrics pipeline of task section
2022-05-01 00:01:13 -07:00
huangminjie 388ac4d825 [zh] sync content/zh/docs/tasks/debug-application-cluster/resource-metrics-pipeline.md 2022-05-01 14:54:19 +08:00
wei.wang eaf047e51b [zh]Update content/zh/blog/_posts/2022-02-17-updated-dockershim-faq.md
Update content/zh/blog/_posts/2022-02-17-updated-dockershim-faq.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-05-01 14:25:59 +08:00
huangminjie c5b195d41d [zh] add content/zh/docs/tasks/debug/debug-application/_index.md 2022-05-01 09:08:45 +08:00
Kubernetes Prow Robot 683b9cd198 Merge pull request #33351 from JarHMJ/content/zh/docs/tasks/debug-application-cluster/monitor-node-health.md
[zh] sync content/zh/docs/tasks/debug/debug-cluster/monitor-node-heal…
2022-04-30 17:55:12 -07:00
Kubernetes Prow Robot 1afdc660ff Merge pull request #33348 from kinzhi/kinzhi63
[zh]Update content/zh/docs/concepts/configuration/manage-resources-containers.md
2022-04-30 17:53:12 -07:00
Kubernetes Prow Robot 4e5482fb45 Merge pull request #33347 from JarHMJ/update/local-debugging
[zh] sync content/zh/docs/tasks/debug/debug-cluster/local-debugging.md
2022-04-30 17:51:12 -07:00
Kubernetes Prow Robot afdb056cce Merge pull request #33332 from kinzhi/kinzhi60
[zh]Add content/zh/docs/tasks/debug/debug-application/get-shell-running-container.md
2022-04-30 17:49:12 -07:00
Kubernetes Prow Robot 0cc95c646a Merge pull request #33330 from kinzhi/kinzhi58
[zh]Update content/zh/docs/tutorials/stateful-application/mysql-wordpress-persistent-volume.md
2022-04-30 17:47:13 -07:00
Kubernetes Prow Robot c3d577cac0 Merge pull request #33350 from kinzhi/kinzhi65
[zh]Update content/zh/docs/concepts/overview/components.md
2022-04-30 17:43:12 -07:00
Kubernetes Prow Robot ac5faa199f Merge pull request #33344 from JarHMJ/patch-3
[en] Update tools/_index.md  remove old helm definition
2022-04-30 17:41:12 -07:00
Kubernetes Prow Robot f0fe1778e5 Merge pull request #33353 from JarHMJ/content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade.md
[zh] update content/zh/docs/reference/setup-tools/kubeadm/generated/k…
2022-04-30 17:39:13 -07:00
Kubernetes Prow Robot 0245a54018 Merge pull request #33354 from kinzhi/kinzhi66
[en]Modify /docs/tasks/debug/debug-application/debug-running-pod/
2022-04-30 17:07:12 -07:00
Kubernetes Prow Robot 8f68cd36b4 Merge pull request #33355 from kinzhi/kinzhi67
[zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_certs_renew.md
2022-04-30 17:05:12 -07:00
wei.wang b008adb1e6 [zh]Sync content/zh/docs/tasks/debug/debug-application/debug-service.md 2022-05-01 02:01:28 +08:00
wei.wang 9716dd08cf [zh]Sync content/zh/docs/tasks/debug/debug-cluster/crictl.md 2022-05-01 01:34:21 +08:00
wei.wang cd693ade42 [zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_certs_renew.md 2022-05-01 01:11:32 +08:00
Kubernetes Prow Robot 314ad4c43a Merge pull request #32326 from nirroz93/patch-2
Changing note about limits without requests
2022-04-30 10:11:12 -07:00
Kubernetes Prow Robot f57b6a42a9 Merge pull request #32221 from amitech/patch-1
Updated configure-liveness-readiness-startup-probes.md
2022-04-30 10:07:12 -07:00
Kubernetes Prow Robot ed5ae05402 Merge pull request #33316 from my-git9/debug-running-pod3
[en] modify debug-application/debug-running-pod
2022-04-30 09:59:13 -07:00
wei.wang 708924d9d5 [en]Modify /docs/tasks/debug/debug-application/debug-running-pod/ 2022-05-01 00:57:38 +08:00
huangminjie e6c738a96b [zh] update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_upgrade.md 2022-05-01 00:34:09 +08:00
huangminjie f0990a0f29 update 2022-05-01 00:10:45 +08:00
huangminjie 439665c82e [zh] sync content/zh/docs/tasks/debug/debug-cluster/monitor-node-health.md 2022-05-01 00:02:51 +08:00
wei.wang 59b33cc694 [zh]Update content/zh/docs/concepts/overview/components.md 2022-04-30 23:52:09 +08:00
wei.wang b761b7de94 [zh]Update content/zh/docs/concepts/configuration/manage-resources-containers.md 2022-04-30 23:45:05 +08:00
wei.wang aaf7e99434 [zh]Add content/zh/docs/tasks/debug/debug-application/get-shell-running-container.md
[zh]Add content/zh/docs/tasks/debug/debug-application/get-shell-running-container.md

[zh]Add content/zh/docs/tasks/debug/debug-application/get-shell-running-container.md
2022-04-30 23:32:23 +08:00
huangminjie fdcf1d8a4c [zh] sync content/zh/docs/tasks/debug/debug-cluster/local-debugging.md 2022-04-30 22:46:12 +08:00
Kubernetes Prow Robot 22dbbe1dda Merge pull request #33343 from JarHMJ/update/generated/kubeadm.md
[zh] update content/zh/docs/reference/setup-tools/kubeadm/generated/k…
2022-04-30 07:09:12 -07:00
Kubernetes Prow Robot 57a43f30ca Merge pull request #33340 from my-git9/resource-usage-monitoring3
[en] modify link about debug
2022-04-30 07:07:12 -07:00
Kubernetes Prow Robot 1096f1f5c2 Merge pull request #33270 from kinzhi/kinzhi46
[zh]Update content/zh/docs/tasks/configmap-secret/managing-secret-using-kubectl.md
2022-04-30 07:05:13 -07:00
Kubernetes Prow Robot 41dfc83423 Merge pull request #33339 from my-git9/debuglink4
[en] modify link about debug
2022-04-30 07:03:12 -07:00
Kubernetes Prow Robot 28cffafcd9 Merge pull request #33331 from kinzhi/kinzhi59
[en]Update content/en/docs/reference/kubectl/docker-cli-to-kubectl.md
2022-04-30 06:51:13 -07:00
Kubernetes Prow Robot 0579b23b9a Merge pull request #33329 from kinzhi/kinzhi57
[zh]Sync content/zh/docs/tasks/debug/debug-cluster/audit.md
2022-04-30 06:49:12 -07:00
Kubernetes Prow Robot 92ec6853fc Merge pull request #33328 from kinzhi/kinzhi56
[en]Update content/en/docs/concepts/workloads/pods/init-containers.md
2022-04-30 06:47:13 -07:00
Kubernetes Prow Robot 62ee8c2a11 Merge pull request #33326 from geraldmayr/main
Add missing verb
2022-04-30 06:45:13 -07:00
Kubernetes Prow Robot f6c9375176 Merge pull request #33318 from JarHMJ/fix/kubeadm_init_phase_certs_etcd-server
[zh] update   kubeadm_init_phase_certs_etcd-server.md
2022-04-30 06:37:12 -07:00
Kubernetes Prow Robot 11bfde39cd Merge pull request #33325 from kinzhi/kinzhi55
[zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_certs.md
2022-04-30 05:39:12 -07:00
Kubernetes Prow Robot a66ba6a53e Merge pull request #33291 from kinzhi/kinzhi52
[zh]Sync content/zh/examples/policy/restricted-psp.yaml
2022-04-30 05:37:12 -07:00
Kubernetes Prow Robot 20ce068d30 Merge pull request #33314 from my-git9/debug-cluster-crictl
[en] modify  link debug-cluster/crictl
2022-04-30 05:35:13 -07:00
xin.li 5810ecfd49 [en] modify debug-cluster/crictl
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-30 18:58:16 +08:00
wei.wang bf84c6a5a0 [zh]Sync content/zh/examples/policy/restricted-psp.yaml
[zh]Sync content/zh/examples/policy/restricted-psp.yaml
2022-04-30 18:38:25 +08:00
Kubernetes Prow Robot ced5dc9fa7 Merge pull request #33333 from kinzhi/kinzhi61
[zh]Update content/zh/docs/doc-contributor-tools/linkchecker/README.md
2022-04-30 03:21:13 -07:00
Kubernetes Prow Robot d2c2ba269b Merge pull request #33319 from kinzhi/kinzhi54
[zh]Update content/zh/docs/concepts/cluster-administration/_index.md
2022-04-30 03:17:12 -07:00
huangminjie 5f5be17db9 [en] Update tools/_index.md remove old helm definition 2022-04-30 16:16:28 +08:00
huangminjie 551a8e5bcf [zh] update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm.md 2022-04-30 15:25:43 +08:00
xin.li e6276724bb [en] modify link about debug
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-30 09:48:28 +08:00
xin.li 781b2b381c [en] modify link about debug
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-30 09:21:16 +08:00
wei.wang f19090942f [zh]Update content/zh/docs/doc-contributor-tools/linkchecker/README.md 2022-04-30 03:28:13 +08:00
wei.wang 64f58b2c75 [en]Update content/en/docs/reference/kubectl/docker-cli-to-kubectl.md 2022-04-30 03:11:53 +08:00
wei.wang 91754929a8 [zh]Update content/zh/docs/tutorials/stateful-application/mysql-wordpress-persistent-volume.md 2022-04-30 03:08:22 +08:00
wei.wang be918fc2b3 [zh]Sync content/zh/docs/tasks/debug/debug-cluster/audit.md 2022-04-30 03:02:03 +08:00
Kubernetes Prow Robot c22bef44a0 Merge pull request #32418 from bswartz/volume-populators-beta-blog
v1.24 blog post: Volume populators beta
2022-04-29 11:57:14 -07:00
wei.wang d9690ad314 [en]Update content/en/docs/concepts/workloads/pods/init-containers.md 2022-04-30 02:55:03 +08:00
Gerald Mayr 86c0e4e5b9 Add missing verb 2022-04-29 20:27:22 +02:00
wei.wang a4d0f3e347 [zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_certs.md 2022-04-30 02:26:20 +08:00
Kubernetes Prow Robot 9fba921214 Merge pull request #33321 from marosset/win-containerd-install-fixes
Updating containerd install details
2022-04-29 11:04:15 -07:00
Mark Rossetti aaadcc1c9a Update content/en/docs/setup/production-environment/container-runtimes.md
Co-authored-by: divya-mohan0209 <divya.mohan0209@gmail.com>
2022-04-29 10:33:57 -07:00
Mark Rossetti 86265a1742 Updating containerd install details
Signed-off-by: Mark Rossetti <marosset@microsoft.com>
2022-04-29 10:23:14 -07:00
Kubernetes Prow Robot e506834edc Merge pull request #33311 from Tej-Singh-Rana/master
fixed the link
2022-04-29 09:29:13 -07:00
wei.wang 283448b922 [zh]Update content/zh/docs/concepts/cluster-administration/_index.md 2022-04-29 23:38:12 +08:00
Kubernetes Prow Robot 9c710f7f7b Merge pull request #33315 from thomasd-ign/patch-1
Dead link correction
2022-04-29 08:29:13 -07:00
huangminjie e29fa4ea2e update kubeadm_init_phase_certs_etcd-server.md
Signed-off-by: huangminjie <minjie.huang@daocloud.io>
2022-04-29 23:12:34 +08:00
thomasd-ign 99c5658119 Update content/en/blog/_posts/2022-04-28-Increasing-the-security-bar-in-Ingress-NGINX/index.md
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2022-04-29 17:11:14 +02:00
Kubernetes Prow Robot cb12791012 Merge pull request #33222 from kinzhi/kinzhi37
[zh]Sync content/zh/case-studies/babylon
2022-04-29 07:59:13 -07:00
Kubernetes Prow Robot b54bcde04e Merge pull request #33292 from kinzhi/kinzhi53
[zh]Sync content/zh/case-studies/squarespace
2022-04-29 07:09:13 -07:00
Kubernetes Prow Robot 4a67ea76d0 Merge pull request #33313 from my-git9/debug-cluster-audit
[en] modify debug-cluster/audit
2022-04-29 07:01:13 -07:00
Tej Singh Rana c68c4e9518 Added back the bracket 2022-04-29 19:17:14 +05:30
Mitesh Jain a2bf86409a Adding dockershim to glossary. (#32950)
* Adding dockershim to glossary.

* updated dockershim faq url.

Co-authored-by: Chris Negus <cnegus@redhat.com>

* Update content/en/docs/reference/glossary/dockershim.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/docs/reference/glossary/dockershim.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/docs/reference/glossary/dockershim.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Changes to accomodate review comments.

Co-authored-by: Chris Negus <cnegus@redhat.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2022-04-29 06:37:13 -07:00
xin.li d46e06a1c3 [en] modify debug-application/debug-running-pod
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 20:53:12 +08:00
thomasd-ign 34c8d99054 Dead link correction
Correct a dead link pointing to a page about namespaces in kubernetes
2022-04-29 14:50:10 +02:00
xin.li b831e96c6a [en] modify debug-cluster/audit
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 20:40:59 +08:00
Tej Singh Rana ca413bf30e fixed the broken link 2022-04-29 18:07:53 +05:30
Tej Singh Rana bc04fd0df7 Merge branch 'kubernetes:main' into master 2022-04-29 18:07:00 +05:30
Kubernetes Prow Robot 6d9dea7623 Merge pull request #33306 from my-git9/security-a-cluster1
[en] modify debug link in securing-a-cluster.md
2022-04-29 05:33:15 -07:00
Kubernetes Prow Robot ddb35a0be8 Merge pull request #33309 from my-git9/local-debug2
[en] modify debug link in local-debug
2022-04-29 05:29:14 -07:00
Tej Singh Rana 256d6a2638 Fixed the link 2022-04-29 17:56:41 +05:30
Tej Singh Rana 6006d67647 Merge branch 'kubernetes:main' into master 2022-04-29 17:54:26 +05:30
Kubernetes Prow Robot 86bdc7228a Merge pull request #33310 from my-git9/define-comom
[en] modify link in define-command-argument-container
2022-04-29 05:19:13 -07:00
Tej Singh Rana a982e451bb fixed the link 2022-04-29 17:45:55 +05:30
Kubernetes Prow Robot 8b116a343a Merge pull request #33305 from my-git9/resource-metrics-pipeline3
[en]modify debug link in resource-metrics-pipeline.md
2022-04-29 05:05:13 -07:00
Kubernetes Prow Robot 4aa7234881 Merge pull request #33272 from kinzhi/kinzhi48
[zh]Sync case-studies/jd-com
2022-04-29 04:57:12 -07:00
Kubernetes Prow Robot 68c3adc0a8 Merge pull request #33308 from my-git9/configure-pod-init1
[en] modify debug link in configure-pod-init
2022-04-29 04:47:13 -07:00
Kubernetes Prow Robot 4e96ae79d7 Merge pull request #33307 from my-git9/resource-usage-monitoring2
[en] modify debug link in resource-usage-monitoring
2022-04-29 04:43:12 -07:00
xin.li cb6b4c8dcb [en] modify debug link in resource-usage-monitoring
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 19:28:10 +08:00
Kubernetes Prow Robot 7dc296222e Merge pull request #33262 from kinzhi/kinzhi43
[zh]Update content/zh/docs/setup/production-environment/windows/user-guide-windows-containers.md
2022-04-29 04:27:13 -07:00
xin.li 6f0bc9a0a1 [en] modify link in define-command-argument-container
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 19:07:13 +08:00
xin.li 8acb8f13f6 [en] modify debug link in local-debug
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 19:04:11 +08:00
Kubernetes Prow Robot aae0e2e64b Merge pull request #33304 from my-git9/manual-rotation-of-ca2
[en] modify the link about debug-application
2022-04-29 04:03:14 -07:00
xin.li 3d69e98fb4 [en] modify debug link in configure-pod-init
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 19:01:34 +08:00
xin.li aef1fb68d1 [zh] modify debug link in securing-a-cluster.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 18:49:00 +08:00
xin.li b66a80db00 [zh] modify debug link in resource-metrics-pipeline.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 18:43:27 +08:00
Kubernetes Prow Robot 76c5c6df6d Merge pull request #33303 from my-git9/mysql-wordpress-persistent
[en] modify the link about debug-application
2022-04-29 03:39:13 -07:00
xin.li 0e0f62c478 [en] modify the link about debug-application
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 18:34:13 +08:00
Kubernetes Prow Robot 1e11e7e813 Merge pull request #33302 from my-git9/kubeadm-upgrade2
[zh] Update administer-cluster/kubeadm/kubeadm-upgrade.md
2022-04-29 03:31:13 -07:00
Kubernetes Prow Robot 68b340858b Merge pull request #33296 from my-git9/linkchecker1
[en] Update docs/doc-contributor-tools/linkchecker
2022-04-29 03:29:12 -07:00
Kubernetes Prow Robot 7ad1a47fae Merge pull request #33271 from kinzhi/kinzhi47
[zh]Update content/zh/blog/_posts/2018-10-01-health-checking-grpc.md
2022-04-29 03:27:12 -07:00
Kubernetes Prow Robot df074540c4 Merge pull request #33233 from kinzhi/kinzhi38
[zh]Update content/zh/examples/application/mysql/mysql-statefulset.yaml
2022-04-29 03:25:13 -07:00
xin.li f43e6f5cdb [en] modify the link about debug-application in mysql-wordpress-persistent-volume.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 18:13:46 +08:00
xin.li 13c03b0d58 [zh] Update administer-cluster/kubeadm/kubeadm-upgrade.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 17:58:37 +08:00
Ed 3ae803b707 Added link to Version Skew Policy in Upgrading Kubeadm Cluster (#33293)
* Added link to Version Skew Policy in Upgrading Kubeadm Cluster

* Update content/en/docs/tasks/administer-cluster/kubeadm/kubeadm-upgrade.md

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>
2022-04-29 02:53:13 -07:00
Kubernetes Prow Robot 2f0824c6ea Merge pull request #33298 from skmkzyk/patch-1
current link is pointing 404 page.
2022-04-29 00:53:12 -07:00
Kubernetes Prow Robot 2f0c1a741d Merge pull request #33260 from kinzhi/kinzhi42
[zh]Update content/zh/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definition-versioning.md
2022-04-29 00:47:13 -07:00
Kubernetes Prow Robot ce5e2830e1 Merge pull request #33289 from kinzhi/kinzhi50
[zh]Update content/zh/docs/reference/labels-annotations-taints/audit-annotations.md
2022-04-29 00:41:12 -07:00
Kazuyuki Sakemi 9d98815cc5 current link is pointing 404 page.
replacing relative link from "/docs/tasks/debug-application-cluster/debug-service/" to "/docs/tasks/debug/debug-application/debug-service/".
2022-04-29 15:10:44 +09:00
xin.li e832559fa0 [en] Update docs/doc-contributor-tools/linkchecker
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-29 12:11:43 +08:00
wei.wang 75a812ca5c [zh]Update content/zh/docs/setup/production-environment/windows/user-guide-windows-containers.md
[zh]Sync x

[zh]Update content/zh/docs/setup/production-environment/windows/user-guide-windows-containers.md
2022-04-29 12:08:43 +08:00
wei.wang 1be8669808 [zh]Update content/zh/docs/reference/labels-annotations-taints/audit-annotations.md
[zh]Update content/zh/docs/reference/labels-annotations-taints/audit-annotations.md

Update content/zh/docs/reference/labels-annotations-taints/audit-annotations.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/docs/reference/labels-annotations-taints/audit-annotations.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/docs/reference/labels-annotations-taints/audit-annotations.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-29 11:51:02 +08:00
Kubernetes Prow Robot 5fe82f5e21 Merge pull request #33288 from kinzhi/kinzhi49
[zh]Update content/zh/docs/concepts/storage/storage-classes.md
2022-04-28 16:59:12 -07:00
Kubernetes Prow Robot ba287bed01 Merge pull request #33290 from kinzhi/kinzhi51
[zh]Sync content/zh/docs/tasks/configure-pod-container/security-context.md
2022-04-28 16:57:12 -07:00
Kubernetes Prow Robot f781bf851d Merge pull request #31734 from serithemage/patch-1
[ko] Update namespaces.md to align with en site
2022-04-28 16:43:12 -07:00
Kubernetes Prow Robot d320ecb2ab Merge pull request #33286 from reylejano/followup-blog
Follow-up to PR 33280, Blog 1.23 lead interview transcript
2022-04-28 11:13:50 -07:00
wei.wang 2e92ea8627 [zh]Sync content/zh/case-studies/squarespace 2022-04-29 01:47:29 +08:00
wei.wang a571fef7c8 [zh]Sync content/zh/docs/tasks/configure-pod-container/security-context.md 2022-04-29 01:32:16 +08:00
wei.wang b569079875 [zh]Update content/zh/docs/concepts/storage/storage-classes.md 2022-04-29 01:07:30 +08:00
wei.wang 2d733bbb03 [zh]Update content/zh/blog/_posts/2018-10-01-health-checking-grpc.md
Update content/zh/blog/_posts/2018-10-01-health-checking-grpc.md

Co-authored-by: Hao Yuan <howieyuen@outlook.com>

Update content/zh/blog/_posts/2018-10-01-health-checking-grpc.md

Co-authored-by: Hao Yuan <howieyuen@outlook.com>

Update content/zh/blog/_posts/2018-10-01-health-checking-grpc.md

Co-authored-by: Hao Yuan <howieyuen@outlook.com>
2022-04-29 00:58:05 +08:00
wei.wang d9a0e4123b [zh]Update content/zh/docs/tasks/configmap-secret/managing-secret-using-kubectl.md
Update content/zh/docs/tasks/configmap-secret/managing-secret-using-kubectl.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/docs/tasks/configmap-secret/managing-secret-using-kubectl.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-29 00:54:24 +08:00
Kubernetes Prow Robot 48788780ec Merge pull request #33089 from MrErlison/annotation-ptbr
Add content/pt-br/docs/reference/glossary/annotation.md
2022-04-28 09:27:50 -07:00
wei.wang 1f9f0a29d0 [zh]Update content/zh/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definition-versioning.md
Update content/zh/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definition-versioning.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definition-versioning.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definition-versioning.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-29 00:13:42 +08:00
wei.wang c88343d6b5 [zh]Update content/zh/examples/application/mysql/mysql-statefulset.yaml
[zh]Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Update content/zh/examples/application/mysql/mysql-statefulset.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-28 23:53:50 +08:00
Kubernetes Prow Robot 859641120b Merge pull request #33281 from SataQiu/fix-20220428
Update content/en/docs/reference/labels-annotations-taints/audit-annotations.md
2022-04-28 08:37:51 -07:00
Rey Lejano b0d1c433cd follow-up PR to PR 33280 2022-04-28 08:24:50 -07:00
Kubernetes Prow Robot cc442b1dcb Merge pull request #32659 from pohly/kubernetes-1.24-storage-capacity-ga
storage capacity GA blog post
2022-04-28 08:19:50 -07:00
Kubernetes Prow Robot d4bbdb5aa7 Merge pull request #33219 from chrisnegus/dockershim-podsecurity-docs
Update pod security docs for dockershim removal
2022-04-28 08:17:50 -07:00
Kubernetes Prow Robot 27d1959c22 Merge pull request #33280 from craigbox/interview-1.23
Add release interview for 1.23
2022-04-28 08:15:50 -07:00
Ricardo Katz 78a765f16c Add Ingress NGINX v1.2.0 blogpost (#32965)
* Add Ingress NGINX v1.2.0 blogpost

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Apply suggestions from code review

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Apply suggestions from code review

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2022-04-15-Increasing-the-security-bar-in-Ingress-NGINX/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Fix some reviews

* Change publishing date

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2022-04-28 07:37:50 -07:00
Patrick Ohly 0e56bf9cae blog: storage capacity GA 2022-04-28 15:54:08 +02:00
SataQiu 279fbc658d Update content/en/docs/reference/labels-annotations-taints/audit-annotations.md
Signed-off-by: SataQiu <shidaqiu2018@gmail.com>
2022-04-28 19:53:21 +08:00
Kubernetes Prow Robot a56ad60c84 Merge pull request #33167 from tengqm/zh-crictl
[zh] Resync crictl
2022-04-28 04:43:51 -07:00
Craig Box f5e420e226 You know, I actually wanted some --s 2022-04-28 23:26:53 +12:00
Craig Box b00a8192a1 Add 1.23 blog post 2022-04-28 23:19:49 +12:00
Kubernetes Prow Robot d0a46e83bd Merge pull request #33277 from howieyuen/managing-tls-in-a-cluster
[zh]resync tls task: Manage TLS Certificates in a Cluster
2022-04-28 03:57:51 -07:00
Kubernetes Prow Robot 0bb6926031 Merge pull request #33256 from youwalther65/patch-1
Remove gp3 from supported EBS volume types for in-tree provisioner "kubernetes.io/aws-ebs"
2022-04-28 03:45:51 -07:00
howieyuen bf5afce482 [zh]resync tls task: Manage TLS Certificates in a Cluster 2022-04-28 16:56:33 +08:00
Kubernetes Prow Robot 84971bc765 Merge pull request #33267 from HeGaoYuan/patch-5
Update security-context.md
2022-04-27 20:18:55 -07:00
Kubernetes Prow Robot be58d7882d Merge pull request #33275 from Arhell/upd-link
[zh] update external provisioner specification reference
2022-04-27 19:50:54 -07:00
kinzhi ecbd6257a4 [zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_certs_certificate-key.md (#33269)
* [zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_certs_certificate-key.md

* [zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_certs_certificate-key.md

* [zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_certs_certificate-key.md
2022-04-27 19:40:55 -07:00
Kubernetes Prow Robot be881ec734 Merge pull request #33125 from tengqm/zh-tweak-nodes-page
[zh] Update the nodes concept page
2022-04-27 19:20:55 -07:00
Qiming Teng 3660d10034 [zh] Update the nodes concept page 2022-04-28 08:37:24 +08:00
Kubernetes Prow Robot 79552a5af3 Merge pull request #33258 from my-git9/podindexmd
[zh] Update workloads/pods/_index.md
2022-04-27 17:32:54 -07:00
Kubernetes Prow Robot 5f77c3e475 Merge pull request #33257 from my-git9/caseing2
[zh] Update case-studies/ing
2022-04-27 17:30:54 -07:00
Kubernetes Prow Robot 573aab1693 Merge pull request #33253 from my-git9/denso
[zh] Sync denso
2022-04-27 17:26:54 -07:00
Arhell 67227ff394 [zh] update external provisioner specification reference 2022-04-28 01:16:59 +03:00
wei.wang bc617ec9ce [zh]Sync case-studies/jd-com 2022-04-28 02:10:54 +08:00
Ben Swartzlander e7089f9c40 v1.24 blog post: Volume populators beta 2022-04-27 13:31:52 -04:00
HeGaoYuan ae677063f9 Update security-context.md
typo
2022-04-28 00:47:00 +08:00
Kubernetes Prow Robot eabb62c66c Merge pull request #33254 from Arhell/upd-link
[id] Update external provisioner specification reference
2022-04-27 09:04:11 -07:00
Kubernetes Prow Robot 87aaa6dd8e Merge pull request #33064 from 85humberto/patch-1
[pt-br] Correct typing error
2022-04-27 08:58:10 -07:00
Kubernetes Prow Robot 6744be1a00 Merge pull request #33189 from my-git9/pod-security-policy4
[zh] Update docs/reference/glossary/pod-security-policy.md
2022-04-27 05:42:10 -07:00
Kubernetes Prow Robot 93b8604924 Merge pull request #33126 from tengqm/zh-update-node-comm
[zh] Update control plane to node communication page
2022-04-27 05:40:10 -07:00
xin.li 4993a0d743 [zh] Update workloads/pods/_index.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-27 19:03:39 +08:00
xin.li 107ff07d78 [zh] Update case-studies/ing
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-27 18:14:39 +08:00
Jens-Uwe Walther 511c74564d Remove gp3 from supported EBS volume types
gp3 is not supported for the in-tree plugin "kubernetes.io/aws-ebs", only for external EBS CSI driver. So we have to remove it here
See following issue which shows that it does not work:
https://github.com/kubernetes/website/issues/33036#issuecomment-1110766774
2022-04-27 12:14:03 +02:00
Arhell 7f57114949 [id] Update external provisioner specification reference 2022-04-27 12:39:02 +03:00
xin.li 2983e62cb0 [zh] Sync denso
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-27 16:21:30 +08:00
Kubernetes Prow Robot dcff2a8ac0 Merge pull request #33249 from my-git9/booz-allen-case-stu
[zh] Sync booz-allen
2022-04-27 01:16:10 -07:00
xin.li 7727724266 --amend
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-27 16:14:03 +08:00
kinzhi 69b402cccf [zh]Update content/zh/examples/admin/dns/dns-horizontal-autoscaler.yaml (#33234)
* [zh]Update content/zh/examples/admin/dns/dns-horizontal-autoscaler.yaml

* [zh]Update content/zh/examples/admin/dns/dns-horizontal-autoscaler.yaml

* Update content/zh/examples/admin/dns/dns-horizontal-autoscaler.yaml

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-27 01:12:10 -07:00
xin.li a9a1b0d2b6 [zh] Sync booz-allen
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-27 15:50:21 +08:00
Kubernetes Prow Robot d97df38b70 Merge pull request #33121 from nasa9084/update-readme-ja
[ja] Update README-ja.md
2022-04-26 23:00:10 -07:00
nasa9084 3c54dacb3e Update README-ja.md
Update README-ja.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

fix anchor
2022-04-27 14:44:51 +09:00
Kubernetes Prow Robot 56d177d0b4 Merge pull request #33245 from chengleqi/patch-1
Update configure-projected-volume-storage.md
2022-04-26 22:24:09 -07:00
Qiming Teng 446de63a6c [zh] Update controlplane to node communication page 2022-04-27 13:18:13 +08:00
chengleqi 10e566a222 Update configure-projected-volume-storage.md 2022-04-27 12:15:30 +08:00
Kubernetes Prow Robot 059cd734dd Merge pull request #33172 from zaunist/main
[zh]: Resync kubeadm-upgrade.md
2022-04-26 19:58:10 -07:00
Kubernetes Prow Robot 931d9bf5f1 Merge pull request #33173 from kinzhi/kinzhi24
[zh]Remove content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha.md
2022-04-26 19:54:10 -07:00
Kubernetes Prow Robot 682bafa836 Merge pull request #33214 from my-git9/exampletls
[zh] Add examples/tls
2022-04-26 19:42:10 -07:00
Kubernetes Prow Robot cdabbdab46 Merge pull request #33216 from my-git9/examplesecurity
[zh] Sync security/*.sh
2022-04-26 19:40:10 -07:00
Kubernetes Prow Robot 14b2c1938e Merge pull request #33215 from my-git9/mongodbexamples
[zh] Create examples/mongodb
2022-04-26 19:18:10 -07:00
Kubernetes Prow Robot e41b1698c0 Merge pull request #33210 from fenggw-fnst/update-kubeadm-join
[zh] Update kubeadm-join.md
2022-04-26 19:02:10 -07:00
Kubernetes Prow Robot 4181b99270 Merge pull request #33217 from my-git9/docsimages2
[zh] Create docs/images
2022-04-26 18:58:10 -07:00
xin.li f86fe141aa [zh] Create docs/images
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-27 09:40:42 +08:00
Kubernetes Prow Robot de90edc29d Merge pull request #33241 from tengqm/fix-33232
Fix dockershim alias
2022-04-26 18:38:10 -07:00
xin.li 08bfda6a06 [zh] Sync security/*.sh
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-27 09:30:18 +08:00
Qiming Teng a9c422d816 Fix dockershim alias 2022-04-27 09:12:38 +08:00
Kubernetes Prow Robot 45ad741b81 Merge pull request #33203 from kinzhi/kinzhi36
[zh]Update content/zh/docs/concepts/architecture/nodes.md
2022-04-26 18:10:11 -07:00
Guangwen Feng d21ecec59e [zh] Update kubeadm-join.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2022-04-27 09:09:04 +08:00
Kubernetes Prow Robot 0577a89dff Merge pull request #33218 from my-git9/case-studiesadidas
[zh] Sync case-studies/adidas
2022-04-26 18:08:10 -07:00
Kubernetes Prow Robot 23af479d73 Merge pull request #33237 from kinzhi/kinzhi40
[zh]Update content/zh/docs/test.md
2022-04-26 17:06:10 -07:00
Kubernetes Prow Robot eb2e24a71e Merge pull request #33238 from kinzhi/kinzhi41
[zh]Sync content/zh/case-studies/booking-com
2022-04-26 16:58:11 -07:00
wei.wang a1831b3eb1 [zh]Sync content/zh/case-studies/booking-com 2022-04-27 07:14:54 +08:00
wei.wang a61b79601d [zh]Update content/zh/docs/test.md 2022-04-27 07:04:41 +08:00
wei.wang 8b9a91cbf5 [zh]Sync content/zh/case-studies/babylon 2022-04-26 22:53:16 +08:00
Christopher Negus a34a0567f9 Updated wording in yaml file 2022-04-26 13:59:38 +00:00
Christopher Negus 59d3e1e7a2 Update pod security docs for dockershim removal 2022-04-26 13:39:55 +00:00
xin.li cfe468a0d5 [zh] Sync case-studies/adidas
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-26 21:13:19 +08:00
kinzhi e0e1b3095c Update content/zh/docs/concepts/architecture/nodes.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-26 21:03:04 +08:00
xin.li 38aada60db [zh] Create examples/mongodb
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-26 20:54:03 +08:00
xin.li 32b87c471a [zh] Add examples/tls
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-26 20:49:42 +08:00
Sean 6b15373d61 [zh] Fix the translation for "Advanced" (#33162)
* [zh] Sync Hugo shortcodes with upstream

* [zh] Fix the translation for "Advanced"
2022-04-26 04:56:53 -07:00
Kubernetes Prow Robot 4854405971 Merge pull request #33207 from fenggw-fnst/fix-typo
Fix a typo in cadvisor.md
2022-04-26 04:54:52 -07:00
Kubernetes Prow Robot ea8f1032dc Merge pull request #33209 from 0xff-dev/storageclass
[zh] update dynamic-provisioning.md
2022-04-26 04:52:53 -07:00
0xff-dev 6e35802d4c [zh] update dynamic-provisioning.md 2022-04-26 17:15:56 +08:00
Guangwen Feng 8f68e2cc94 Fix a typo in cadvisor.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2022-04-26 16:12:42 +08:00
Kubernetes Prow Robot ec74e19095 Merge pull request #33199 from Arhell/fix-build
[es] use cat instead of shell built-in to read checksum
2022-04-26 01:04:52 -07:00
wei.wang 5e46c9bac2 [zh]Update content/zh/docs/concepts/architecture/nodes.md 2022-04-26 13:15:50 +08:00
Kubernetes Prow Robot 05d16dd49f Merge pull request #33185 from my-git9/panic-kubernetes-and-docker
[zh] Update 2020-12-02-dont-panic-kubernetes-and-docker.md
2022-04-25 22:06:51 -07:00
Kubernetes Prow Robot 3c357de8da Merge pull request #33184 from kinzhi/kinzhi28
[zh]Use JavaScript instead of Javascript
2022-04-25 22:04:52 -07:00
Kubernetes Prow Robot 7e035aa7e2 Merge pull request #33181 from fenggw-fnst/fix-ref_idx
[zh] Fix incorrect description
2022-04-25 22:02:52 -07:00
Kubernetes Prow Robot 8fff2ddd22 Merge pull request #33186 from my-git9/dockershim-faq2
[zh] Update blog/2020-12-02-dockershim-faq.md
2022-04-25 22:00:52 -07:00
Kubernetes Prow Robot a0c7a38874 Merge pull request #33191 from kinzhi/kinzhi29
[zh]Update content/zh/examples/service/networking/minimal-ingress.yaml
2022-04-25 21:52:51 -07:00
Kubernetes Prow Robot d00be65c2d Merge pull request #33190 from my-git9/shuffle-sharding4
[zh] Update shuffle-sharding.md
2022-04-25 21:50:51 -07:00
Kubernetes Prow Robot 047515bd68 Merge pull request #33187 from my-git9/volumes4
[zh] Update storage/volumes.md
2022-04-25 21:48:51 -07:00
Kubernetes Prow Robot 7298ae1eaa Merge pull request #33192 from kinzhi/kinzhi30
[zh]Update content/zh/examples/service/access/Dockerfile
2022-04-25 21:46:51 -07:00
Kubernetes Prow Robot eed5cc1598 Merge pull request #33196 from kinzhi/kinzhi34
[zh]Update content/zh/examples/README.md
2022-04-25 21:42:52 -07:00
Kubernetes Prow Robot dba55fc802 Merge pull request #33195 from kinzhi/kinzhi33
[zh]Update content/zh/examples/application/mysql/mysql-services.yaml
2022-04-25 21:40:52 -07:00
Kubernetes Prow Robot 63619c645c Merge pull request #33178 from Sea-n/fix-state
[zh] Fix 2 missing feature state
2022-04-25 21:38:52 -07:00
Kubernetes Prow Robot 6515c93e79 Merge pull request #33194 from kinzhi/kinzhi32
[zh]Sync from the English format
2022-04-25 21:36:52 -07:00
Kubernetes Prow Robot a9e59b8119 Merge pull request #33193 from kinzhi/kinzhi31
[zh]Remove excess whitespace
2022-04-25 21:34:53 -07:00
Kubernetes Prow Robot b6f08cd226 Merge pull request #33198 from kinzhi/kinzhi35
[zh]Sync content/zh/training/_index.html
2022-04-25 21:32:51 -07:00
Paul Schweigert f26e8eff23 Reorg the monitoring task section (#32823)
* reorg the monitoring task section

Signed-off-by: Paul S. Schweigert <paulschw@us.ibm.com>

* reorg from review comments

Signed-off-by: Paul S. Schweigert <paulschw@us.ibm.com>

* review comments

Signed-off-by: Paul S. Schweigert <paulschw@us.ibm.com>

* review fixes

Signed-off-by: Paul S. Schweigert <paulschw@us.ibm.com>
2022-04-25 21:30:51 -07:00
Kubernetes Prow Robot 5521d32c12 Merge pull request #33201 from soul-craft/patch-1
Update labels.md
2022-04-25 20:00:52 -07:00
Soul Craft e39058d2e4 Update labels.md
add a new line
2022-04-26 10:34:37 +08:00
Arhell 8e1ca057b6 [es] use cat instead of shell built-in to read checksum 2022-04-26 00:33:44 +03:00
Kubernetes Prow Robot b01ce83193 Merge pull request #33188 from sftim/20220425_fix_codenew_old_releases
Use previous release examples in codenew shortcode
2022-04-25 13:25:38 -07:00
Kubernetes Prow Robot c2666031e0 Merge pull request #33124 from tengqm/tweak-nodes-page
Tweak the Nodes page
2022-04-25 11:47:40 -07:00
wei.wang 193abb66c4 [zh]Sync content/zh/training/_index.html 2022-04-26 02:28:25 +08:00
wei.wang c0739ad6ef [zh]Sync content/zh/training/_index.html 2022-04-26 00:59:24 +08:00
wei.wang 6dbf0cfaf8 [zh]Update content/zh/examples/README.md 2022-04-25 23:50:10 +08:00
wei.wang 68dbecde3a [zh]Update content/zh/examples/application/mysql/mysql-services.yaml 2022-04-25 23:36:20 +08:00
zaunist 36f3fedebb docs: Rsyc kubeadm-upgrade.md 2022-04-25 23:32:32 +08:00
Sean Wei d124118918 [zh] Fix feature state 2022-04-25 23:31:29 +08:00
wei.wang 97dbcfbb9f [zh]Remove excess whitespace 2022-04-25 23:30:56 +08:00
wei.wang 0182438cfa [zh]Sync from the English format 2022-04-25 23:29:03 +08:00
wei.wang 8251775798 [zh]Remove excess whitespace 2022-04-25 23:24:52 +08:00
wei.wang e4e09e7241 [zh]Update content/zh/examples/service/access/Dockerfile 2022-04-25 22:12:25 +08:00
wei.wang 3af7b0a15f [zh]Update content/zh/examples/service/networking/minimal-ingress.yaml 2022-04-25 22:05:52 +08:00
xin.li e635ad2bcf [zh] Update shuffle-sharding.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-25 21:45:03 +08:00
xin.li 5fbba61bbc [zh] Update docs/reference/glossary/pod-security-policy.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-25 21:40:02 +08:00
Tim Bannister d3708001d8 Use previous release examples in codenew shortcode
Fix a minor bug in the codenew shortcode.
When serving a previous release, link to the example for that specific
release (and not to the example for the current release).
2022-04-25 14:27:28 +01:00
xin.li 248cf890a3 Update storage/volumes.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-25 21:17:55 +08:00
xin.li 6f9f2b8efa [zh] Update blog/2020-12-02-dockershim-faq.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-25 20:58:21 +08:00
xin.li 5a1b3ce971 [zh] Update 2020-12-02-dont-panic-kubernetes-and-docker.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-25 20:49:10 +08:00
wei.wang 38cbb50e5c [zh]Use JavaScript instead of Javascript 2022-04-25 20:14:42 +08:00
Guangwen Feng 77d736f31c [zh] Fix incorrect description
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2022-04-25 16:41:29 +08:00
Kubernetes Prow Robot a49bb7fed1 Merge pull request #33161 from Sea-n/fix-js
Use JavaScript instead of Javascript
2022-04-24 23:47:38 -07:00
Kubernetes Prow Robot 7e386e505f Merge pull request #33170 from kinzhi/kinzhi22
[zh]Update content/zh/docs/reference/glossary/api-eviction.md
2022-04-24 17:25:37 -07:00
Kubernetes Prow Robot adcce7a46c Merge pull request #33176 from kinzhi/kinzhi27
[zh]Update content/zh/docs/reference/setup-tools/kubeadm/kubeadm-reset-phase.md
2022-04-24 17:21:37 -07:00
Kubernetes Prow Robot 7298ee3ea7 Merge pull request #33174 from kinzhi/kinzhi25
[zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_print.md
2022-04-24 15:55:36 -07:00
Kubernetes Prow Robot c35adc1bac Merge pull request #33177 from Arhell/fix-state
[zh] fix feature state
2022-04-24 15:43:37 -07:00
Arhell f73d046f63 [zh] fix feature state 2022-04-25 00:33:16 +03:00
wei.wang ab63d9a541 [zh]Update content/zh/docs/reference/setup-tools/kubeadm/kubeadm-reset-phase.md 2022-04-25 02:15:45 +08:00
wei.wang 560e16d93b [zh]Update content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_config_print.md 2022-04-25 01:52:02 +08:00
wei.wang 190bd0b902 [zh]Remove content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_alpha.md 2022-04-25 01:45:02 +08:00
wei.wang 87edc6a9f8 [zh]Update content/zh/docs/reference/glossary/api-eviction.md 2022-04-24 23:09:57 +08:00
Qiming Teng 7f7f53dc53 [zh] Resync crictl 2022-04-24 21:14:20 +08:00
kinzhi 22c0708cdf [zh]update content/zh/docs/concepts/workloads/controllers/job.md (#33157)
* [zh]update content/zh/docs/concepts/workloads/controllers/job.md

* [zh]update content/zh/docs/concepts/workloads/controllers/job.md

* Update content/zh/docs/concepts/workloads/controllers/job.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* Update content/zh/docs/concepts/workloads/controllers/job.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* Update content/zh/docs/concepts/workloads/controllers/job.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* Update content/zh/docs/concepts/workloads/controllers/job.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* Update content/zh/docs/concepts/workloads/controllers/job.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* Update content/zh/docs/concepts/workloads/controllers/job.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* [zh]update content/zh/docs/concepts/workloads/controllers/job.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-24 03:49:36 -07:00
Kubernetes Prow Robot 353e867151 Merge pull request #33144 from my-git9/zookeeperyaml
[zh] Sync application/zookeeper/zookerper.yaml
2022-04-24 01:33:37 -07:00
Kubernetes Prow Robot e43e4f57cb Merge pull request #33147 from my-git9/security-apparmor.md
[zh] Update security/apparmor.md
2022-04-24 01:21:36 -07:00
Kubernetes Prow Robot 55499e4f55 Merge pull request #33109 from zhangxyjlu/steering-committee-results-2021
[zh]Add 2021-11-08-steering-committee-results-2021.md
2022-04-24 01:19:36 -07:00
Kubernetes Prow Robot e5d2145d17 Merge pull request #33146 from my-git9/ns-level-pss2
[zh] Update tutorials/security/ns-level-pss.md
2022-04-24 01:17:36 -07:00
xin.li a0fbfe2ae7 [zh] Update tutorials/security/ns-level-pss.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-24 16:09:34 +08:00
Sean Wei 649328ac2f Use JavaScript instead of Javascript 2022-04-24 11:54:22 +08:00
xin.li b5cc85ad69 [zh] Update security/apparmor.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-24 09:29:57 +08:00
zhangxiaoyang a1ff03e1e6 [zh]Add 2021-11-08-steering-committee-results-2021.md 2022-04-24 09:27:19 +08:00
Kubernetes Prow Robot e53215aaa8 Merge pull request #33148 from my-git9/stateful-application-zookeeper
[zh] Update zookeeper.md
2022-04-23 18:07:36 -07:00
Kubernetes Prow Robot b07b108e6e Merge pull request #33149 from kinzhi/kinzhi18
[zh]Sync english doc format
2022-04-23 18:05:36 -07:00
Kubernetes Prow Robot 23f066983f Merge pull request #33155 from kinzhi/kinzhi19
[zh]update content/zh/docs/concepts/services-networking/topology-aware-hints.md
2022-04-23 18:03:36 -07:00
Kubernetes Prow Robot 992eba2cef Merge pull request #33156 from kinzhi/kinzhi20
[zh]fix content/zh/docs/concepts/scheduling-eviction/pod-overhead.md
2022-04-23 17:05:36 -07:00
Kubernetes Prow Robot ad2133524f Merge pull request #33158 from kinzhi/kinzhi22
[zh]Fix format
2022-04-23 16:55:36 -07:00
Kubernetes Prow Robot 1bbf31c08d Merge pull request #33159 from Arhell/remove-space
[zh] remove whitespaces
2022-04-23 16:53:36 -07:00
Arhell c03e0ff944 [zh] remove whitespaces 2022-04-24 01:15:09 +03:00
wei.wang 15926508f3 [zh]Fix format 2022-04-24 03:30:33 +08:00
wei.wang 92d5b58e90 [zh]fix content/zh/docs/concepts/scheduling-eviction/pod-overhead.md 2022-04-24 01:50:14 +08:00
wei.wang ee9412445d [zh]update content/zh/docs/concepts/services-networking/topology-aware-hints.md 2022-04-24 01:41:24 +08:00
Kubernetes Prow Robot cbc2234938 Merge pull request #33079 from nonylene/patch-1
scheduling-eviction/pod-overhaed.md: Fix typo
2022-04-23 09:31:36 -07:00
nonylene 4759a9f652 scheduling-eviction/pod-overhaed.md: Fix a typo
Bustrable -> Burstable
2022-04-24 01:15:51 +09:00
xin.li 87772570f3 [zh] Update zookeeper.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 22:47:09 +08:00
wei.wang ff9e790f42 [zh]Sync english doc format 2022-04-23 22:42:52 +08:00
Kubernetes Prow Robot a56eb46c15 Merge pull request #33143 from my-git9/default-pod2
[zh] Sync examples/pods/security/seccomp/ga
2022-04-23 07:01:36 -07:00
Kubernetes Prow Robot d5d7911db9 Merge pull request #33142 from my-git9/memory-request-limit2
[zh] Sync examples/pods/resource/yaml
2022-04-23 06:55:36 -07:00
Kubernetes Prow Robot 97a798ea02 Merge pull request #33141 from my-git9/health-for-strangers2
[zh] Sync examples/priority-and-fairness/health-for-strangers.yaml
2022-04-23 06:51:36 -07:00
Kubernetes Prow Robot b4c8d6bbcc Merge pull request #33139 from kinzhi/kinzhi17
[zh]adjust the layout
2022-04-23 06:45:36 -07:00
Kubernetes Prow Robot 4a11c8522a Merge pull request #33137 from my-git9/StatefulSet-PVC-Auto-Deletion3
[zh] Update blog/2021-12-16-StatefulSet-PVC-Auto-Deletion.md
2022-04-23 06:43:36 -07:00
Kubernetes Prow Robot c21a98490c Merge pull request #33136 from my-git9/migrate-from-psp3
[zh] Update migrate-from-psp.md
2022-04-23 06:41:36 -07:00
xin.li efb56c01ba [zh] Sync application/zookeeper/zookerper.yaml
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 21:41:01 +08:00
xin.li c8e35e23f0 [zh] Sync examples/pods/security/seccomp/ga
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 21:35:41 +08:00
xin.li d239f341b2 [zh] Sync examples/pods/resource/yaml
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 21:31:24 +08:00
xin.li b86b43d273 [zh] Sync examples/priority-and-fairness/health-for-strangers.yaml
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 21:25:02 +08:00
Kubernetes Prow Robot ba5f32cc4c Merge pull request #33129 from my-git9/badlink1
[en] fix wrong link
2022-04-23 05:49:36 -07:00
Kubernetes Prow Robot 6a5bb3b725 Merge pull request #31976 from tengqm/zh-kubelet-cfg-v1beta1
[zh] Translate kubelet config v1beta1
2022-04-23 05:19:36 -07:00
wei.wang 0aca1901e3 [zh]adjust the layout 2022-04-23 19:00:43 +08:00
xin.li b31b7f86af [zh] Update blog/2021-12-16-StatefulSet-PVC-Auto-Deletion.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 18:44:16 +08:00
Kubernetes Prow Robot 287d581339 Merge pull request #33135 from Arhell/remove-space
[en] remove trailing whitespaces install-kubectl-windows.md
2022-04-23 03:41:36 -07:00
xin.li 7007e5049a [zh] Update migrate-from-psp.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 18:40:57 +08:00
Arhell 49114042bc [en] remove trailing whitespaces install-kubectl-windows.md 2022-04-23 13:08:45 +03:00
Kubernetes Prow Robot 5549336898 Merge pull request #33131 from my-git9/use-cascading-deletion2
[zh] fix the wrong link in use-cascading-deletion.md
2022-04-23 02:01:36 -07:00
xin.li f13a63baff [zh] fix the wrong link in use-cascading-deletion.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 14:37:17 +08:00
xin.li 7f624802ab [en] fix wrong link
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 14:33:25 +08:00
Kubernetes Prow Robot e5eeaba1eb Merge pull request #33127 from my-git9/statefulset-pvc-auto-delete
[en] fix wrong link
2022-04-22 22:29:36 -07:00
kinzhi c43e1ddb8f [zh]Update content/zh/docs/concepts/workloads/controllers/daemonset.md (#33120)
* [zh]Update content/zh/docs/concepts/workloads/controllers/daemonset.md

* Update content/zh/docs/concepts/workloads/controllers/daemonset.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* Update content/zh/docs/concepts/workloads/controllers/daemonset.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-22 21:51:36 -07:00
Kubernetes Prow Robot b96c88ae58 Merge pull request #33128 from my-git9/migrate-from-psp1
[en] fix wrong link
2022-04-22 21:49:35 -07:00
xin.li 1ab38bbaa1 [en] fix wrong link
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 11:33:52 +08:00
xin.li a27c23e081 [en] fix wrong link
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-23 11:13:02 +08:00
Qiming Teng e71768592e Tweak the Nodes page
Field names like `NodeReady`, `ConditionUnknown` etc are only meaningful
for developers, rather than users.
2022-04-23 10:56:34 +08:00
Kubernetes Prow Robot 285affba7e Merge pull request #33097 from MrErlison/wg-ptbr
Add content/pt-br/docs/reference/glossary/wg.md
2022-04-22 13:51:37 -07:00
Wang 4b85c7b058 [ja] Translate tasks/debug-application-cluster/debug-cluster into Japanese #30874 (#31087)
* done

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update debug-cluster.md

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update debug-cluster.md

* Update content/ja/docs/tasks/debug-application-cluster/debug-cluster.md

Co-authored-by: Ryota Yamada <ryota10069.tech5.jizi@gmail.com>

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
Co-authored-by: Ryota Yamada <ryota10069.tech5.jizi@gmail.com>
2022-04-22 11:41:36 -07:00
Wang 6613b13b65 [ja] Translate tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you into Japanese (#31285)
* done

* change back

* done

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* fix

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: inductor(Kohei) <kela@inductor.me>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: inductor(Kohei) <kela@inductor.me>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: Ryota Yamada <ryota10069.tech5.jizi@gmail.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: Ryota Yamada <ryota10069.tech5.jizi@gmail.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

Co-authored-by: Ryota Yamada <ryota10069.tech5.jizi@gmail.com>

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
Co-authored-by: inductor(Kohei) <kela@inductor.me>
Co-authored-by: Ryota Yamada <ryota10069.tech5.jizi@gmail.com>
2022-04-22 11:39:36 -07:00
Kubernetes Prow Robot 814ad64fe7 Merge pull request #33019 from Arhell/fix-code
[ja] fix a nit in the feature-state short code
2022-04-22 11:30:12 -07:00
Kubernetes Prow Robot 079f2592fc Merge pull request #32916 from tallclair/broken-links-ja
[ja] Clean up various broken links
2022-04-22 11:28:13 -07:00
Mr. Erlison 30f16e5fef Translate cross-SIG term 2022-04-22 13:54:57 -03:00
Kubernetes Prow Robot 919c6a07fd Merge pull request #33119 from MrErlison/api-group-ptbr
Add /pt-br/docs/reference/glossary/api-group.md
2022-04-22 06:04:12 -07:00
Mr. Erlison a626607539 Add /pt-br/docs/reference/glossary/api-group.md 2022-04-22 09:34:59 -03:00
Kubernetes Prow Robot 1613606a16 Merge pull request #32774 from miteshskj/daemonset-review
Remove stale information about pod selector.
2022-04-22 01:16:13 -07:00
kinzhi d63dbd782e [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md (#33068)
* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md

* [zh]update file content/zh/docs/reference/labels-annotations-taints/_index.md
2022-04-21 23:32:12 -07:00
kinzhi 359c7607e7 [zh]Update content/zh/docs/reference/access-authn-authz/rbac.md (#33108)
* [zh]Update content/zh/docs/reference/access-authn-authz/rbac.md

* [zh]Update content/zh/docs/reference/access-authn-authz/rbac.md
2022-04-21 22:16:12 -07:00
jpanda 04e30709f9 Fix hyperlink to CNCF on https://k8s.io/docs/home/ (#33038)
* [bugfix/fix-cncf-hyperlink-on-home] fix🐛: Explicitly set the margin-top property

* [bugfix/fix-cncf-hyperlink-on-home] fix🐛:  remove important

* [bugfix/fix-cncf-hyperlink-on-home] format🥚:  Add comments to indicate the role of css
2022-04-21 22:02:12 -07:00
Kubernetes Prow Robot 53803f0d06 Merge pull request #33047 from my-git9/token-review-v1
[zh] Update authentication-resouces/tokern-review-v1.md
2022-04-21 21:10:12 -07:00
xin.li f2c44002ff [zh] Update authentication-resouces/tokern-review-v1.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-22 11:24:25 +08:00
Kubernetes Prow Robot 0f6a9ee52f Merge pull request #33084 from my-git9/release-announcement
[zh] Update blog/2020-03-25-kubernetes-1.18-release-announcement.md
2022-04-21 19:56:12 -07:00
Kubernetes Prow Robot b42ec741cd Merge pull request #33083 from my-git9/Develop-A-Kubernetes-Controller
[zh] Update blog/2019-11-26-cloud-native-java-controller-sdk.md
2022-04-21 19:54:12 -07:00
Kubernetes Prow Robot 65b47f6325 Merge pull request #33085 from my-git9/kubernetes-1.17-release-announcement
[zh] Update blog/2019-12-09-kubernetes-release-announcement.md
2022-04-21 19:32:12 -07:00
Kubernetes Prow Robot 67984f7d7b Merge pull request #33104 from Arhell/upd-ver
[id] use for_k8s_version not for_kubernetes_version
2022-04-21 19:12:12 -07:00
Kubernetes Prow Robot 688010e123 Merge pull request #33087 from my-git9/code-of-conduct1
[zh] Update community/code-of-conduct.md
2022-04-21 19:10:12 -07:00
Mr. Erlison 5dc71848c3 Removed final line with this [-] 2022-04-21 19:34:57 -03:00
Arhell 83d77e1682 [id] use for_k8s_version not for_kubernetes_version 2022-04-22 01:04:09 +03:00
Kubernetes Prow Robot 7acae8a086 Merge pull request #33073 from jihoon-seo/220420_Update_api-reference_shortcode
Update `api-reference` shortcode
2022-04-21 15:00:12 -07:00
Kubernetes Prow Robot e602482da6 Merge pull request #33103 from cjcullen/patch-2
Update rbac.md
2022-04-21 14:52:13 -07:00
CJ Cullen a3638c4fde Update rbac.md
Fix description of magic service account group.
2022-04-21 14:07:32 -07:00
Mr. Erlison 63313c68dc Add content/pt-br/docs/reference/glossary/wg.md 2022-04-21 14:23:01 -03:00
Mr. Erlison 88403cfc77 Add content/pt-br/docs/reference/glossary/annotation.md 2022-04-21 13:27:28 -03:00
xin.li f0eb331689 [zh] Update community/code-of-conduct.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-21 23:12:59 +08:00
xin.li f8a88c5f38 [zh] Update blog/2019-12-09-kubernetes-release-announcement.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-21 22:42:19 +08:00
xin.li 5829407558 [zh] Update blog/2020-03-25-kubernetes-1.18-release-announcement.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-21 22:24:14 +08:00
xin.li f10a5e6a9e [zh] Update blog/2019-11-26-cloud-native-java-controller-sdk.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-21 22:20:46 +08:00
kinzhi 84184494fc [zh]update file content/zh/docs/tasks/network/customize-hosts-file-for-pods.md (#33042)
* [zh]update file content/zh/docs/tasks/network/customize-hosts-file-for-pods.md

* [zh]update file content/zh/docs/tasks/network/customize-hosts-file-for-pods.md

* [zh]update file content/zh/docs/tasks/network/customize-hosts-file-for-pods.md

* [zh]update file content/zh/docs/tasks/network/customize-hosts-file-for-pods.md

* Update content/zh/docs/tasks/network/customize-hosts-file-for-pods.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-21 07:10:58 -07:00
Kubernetes Prow Robot 99f28e6eb1 Merge pull request #33008 from my-git9/deprecation-policy2
[zh] Update deprecation-policy.md
2022-04-21 04:20:58 -07:00
Kubernetes Prow Robot 0ccbd6ebca Merge pull request #33080 from liuhanguang123/main
Update deployment.md
2022-04-21 02:34:58 -07:00
kinzhi 81a8d46bd3 [zh]update file content/zh/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md (#33043)
* [zh]update file content/zh/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

* [zh]update file content/zh/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

* [zh]update file content/zh/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md

* [zh]update file content/zh/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you.md
2022-04-21 02:32:59 -07:00
Kubernetes Prow Robot 245e9280f7 Merge pull request #33078 from liuhanguang123/patch-1
Update field-selectors.md
2022-04-21 02:28:58 -07:00
liuhanguang123 8d1bfee7c1 Update content/zh/docs/concepts/overview/working-with-objects/field-selectors.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-21 16:47:59 +08:00
liuhanguang123 ff612509b4 Update deployment.md
Fixed the difference between the Chinese and English versions
2022-04-21 16:45:12 +08:00
Arhell fd1d03cc5f [ja] fix a nit in the feature-state short code 2022-04-21 11:43:19 +03:00
liuhanguang123 48db2e4d1d Update field-selectors.md
Update the bracket on the right to become tilted
2022-04-21 14:40:30 +08:00
Kubernetes Prow Robot 9d74338c99 Merge pull request #33052 from kinzhi/kinzhi9
[zh]update file content/zh/docs/setup/production-environment/tools/kubeadm/install-kubeadm.md
2022-04-20 21:06:56 -07:00
Kubernetes Prow Robot 088c7fa34f Merge pull request #33074 from my-git9/daemonset2
[zh] Update /content/zh/docs/concepts/workloads/controllers/daemonset.md
2022-04-20 19:28:57 -07:00
Kubernetes Prow Robot ecd68d9852 Merge pull request #33057 from my-git9/kubelet-integration2
[zh] Sync kubeadm/kubelet-integration.md
2022-04-20 19:20:57 -07:00
Kubernetes Prow Robot 1fb1cba101 Merge pull request #33013 from my-git9/debug-pod-replication-controller2
[zh] Update debug-pod-replication-controller.md
2022-04-20 19:18:57 -07:00
Kubernetes Prow Robot 23af551365 Merge pull request #33060 from my-git9/2022-05-03-dockershim-historical-context
[zh] add blog/2022-05-03-dockershim-historical-context.md
2022-04-20 19:16:57 -07:00
xin.li 57b2d14c2a [zh] Update /content/zh/docs/concepts/workloads/controllers/daemonset.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-21 10:02:01 +08:00
xin.li 480edf2561 [zh] add blog/2022-05-03-dockershim-historical-context.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-21 09:30:49 +08:00
xin.li d931086b19 [zh] Sync kubeadm/kubelet-integration.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-21 09:26:55 +08:00
xin.li 2f27924d32 [zh] Update debug-pod-replication-controller.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-21 09:22:57 +08:00
Kubernetes Prow Robot 03cc1cbcd0 Merge pull request #33053 from kinzhi/kinzhi10
[zh]update file content/zh/docs/tasks/administer-cluster/kubeadm/adding-windows-nodes.md
2022-04-20 18:16:59 -07:00
Kubernetes Prow Robot ac425aee81 Merge pull request #33067 from kinzhi/kinzhi13
[zh]update file content/zh/docs/concepts/services-networking/ingress.md
2022-04-20 18:02:59 -07:00
Jihoon Seo c6b6e5acb6 Update api-reference shortcode 2022-04-21 10:02:26 +09:00
Kubernetes Prow Robot c1294b4c76 Merge pull request #33062 from my-git9/examplego
[zh] Sync examples_test.go
2022-04-20 18:00:58 -07:00
Kubernetes Prow Robot bb45e8a2ed Merge pull request #33010 from my-git9/ingress-minikube2
[zh] Update access-cluster.md
2022-04-20 17:58:59 -07:00
Kubernetes Prow Robot 46df8eb2a6 Merge pull request #33063 from my-git9/kubernetes-1-20-release-announcement
[zh] Update blog/kubernetes-1-20-release-announcement.md
2022-04-20 17:57:00 -07:00
Kubernetes Prow Robot d60eff2299 Merge pull request #33065 from kinzhi/kinzhi11
[zh]update file content/zh/docs/reference/access-authn-authz/abac.md
2022-04-20 17:55:00 -07:00
Kubernetes Prow Robot e6bd5b9395 Merge pull request #33066 from kinzhi/kinzhi12
[zh]update file content/zh/docs/reference/access-authn-authz/rbac.md
2022-04-20 17:52:59 -07:00
Kubernetes Prow Robot 82c1c11b64 Merge pull request #33071 from atoato88/use-feature-k8s-version
use for_k8s_version not for_kubernetes_version
2022-04-20 17:47:00 -07:00
Akihito INOH c4b703f11f use for_k8s_version not for_kubernetes_version
This commit use "for_k8s_version" property on feature-state short
code, not "for_kubernetes_version".
2022-04-21 06:43:44 +09:00
wei.wang 1e6e5ad6b6 [zh]update file content/zh/docs/concepts/services-networking/ingress.md 2022-04-21 01:32:46 +08:00
wei.wang 1e6c02e1cd [zh]update file content/zh/docs/reference/access-authn-authz/rbac.md 2022-04-21 01:25:21 +08:00
wei.wang ec3c51ecf7 [zh]update file content/zh/docs/reference/access-authn-authz/abac.md 2022-04-21 01:11:48 +08:00
Kubernetes Prow Robot c62c9e9c61 Merge pull request #32909 from Sea-n/deprecate-ext
Remove deprecated `extensions` API group in document
2022-04-20 08:57:43 -07:00
Humberto 62e61461d9 Update components.md 2022-04-20 11:22:52 -03:00
xin.li fd32dc1159 [zh] Update access-cluster.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-20 22:14:49 +08:00
xin.li 134c25a1d8 [zh] Update blog/kubernetes-1-20-release-announcement.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-20 22:12:09 +08:00
xin.li ca25763e5e [zh] Sync examples_test.go
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-20 21:53:05 +08:00
Kubernetes Prow Robot 7c09c7b4be Merge pull request #32997 from guresonur/patch-2
Update ingress.md
2022-04-20 04:31:40 -07:00
Priyanshu Ahlawat 320d290da5 Add Traffic Shaping Annotations (#32549)
* Update _index.md

* Update _index.md

* Update _index.md

* Update _index.md

* Update _index.md
2022-04-20 04:29:41 -07:00
wei.wang 63cf9b57c2 [zh]update file content/zh/docs/tasks/administer-cluster/kubeadm/adding-windows-nodes.md 2022-04-20 18:20:34 +08:00
wei.wang bd3eb7ad6f [zh]update file content/en/docs/setup/production-environment/tools/kubeadm/install-kubeadm.md 2022-04-20 18:14:27 +08:00
Kubernetes Prow Robot 955ed016df Merge pull request #33044 from w4-jaesup/patch-1
[ko] fix assign-pod-node.md
2022-04-20 01:45:42 -07:00
Kubernetes Prow Robot bad34de21d Merge pull request #33045 from reylejano/revert-32941
Revert changes from PR 32941 that merged before 1.24 release
2022-04-20 01:39:40 -07:00
Kubernetes Prow Robot 2f3d505a7a Merge pull request #33037 from mengjiao-liu/add_blog_moving-on-from-dockershim
[zh]Add 2022-01-07-kubernetes-is-moving-on-from-dockershim.md
2022-04-19 22:43:40 -07:00
Shivam Sharma ac879ddbaa Hyperlink to support period update (#33007)
* Hyperlink to support period update

* Update _index.md
2022-04-19 21:21:41 -07:00
Mengjiao Liu 0050ad941d [zh]Add 2022-01-07-kubernetes-is-moving-on-from-dockershim.md 2022-04-20 11:20:03 +08:00
Kubernetes Prow Robot 02968fde21 Merge pull request #33035 from zaunist/access-cluster-service
[zh]: Rsync access-cluster-service.md
2022-04-19 15:45:43 -07:00
Rey Lejano 28cea36e93 revert changes from PR 32941 that merged before 1.24 release 2022-04-19 14:50:25 -07:00
Jaesup Kwak 42f4abba4a Update assign-pod-node.md 2022-04-20 01:42:23 +09:00
zaunist 3458b424e9 docs: Rsync access-cluster-service 2022-04-19 22:09:45 +08:00
Kat Cosgrove f23de579b3 adds historical context of the dockershim removal blog (#32697)
* adds historical context of the dockershim removal blog

* Update content/en/blog/_posts/2022-04-19-dockershim-historical-context.md

Co-authored-by: Rey Lejano <rlejano@gmail.com>

* Update content/en/blog/_posts/2022-04-19-dockershim-historical-context.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update content/en/blog/_posts/2022-04-19-dockershim-historical-context.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update content/en/blog/_posts/2022-04-19-dockershim-historical-context.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update content/en/blog/_posts/2022-04-19-dockershim-historical-context.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update content/en/blog/_posts/2022-04-19-dockershim-historical-context.md

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>

* Update content/en/blog/_posts/2022-04-19-dockershim-historical-context.md

Co-authored-by: Sergey Kanzhelev <S.Kanzhelev@live.com>

* clarity and grammar edits

* updates publication date and filename

Co-authored-by: Rey Lejano <rlejano@gmail.com>
Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>
Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>
Co-authored-by: Sergey Kanzhelev <S.Kanzhelev@live.com>
2022-04-19 06:39:28 -07:00
Kubernetes Prow Robot fea06301e4 Merge pull request #33028 from kinzhi/kinzhi3
[zh]update file content/zh/docs/tasks/administer-cluster/kubeadm/adding-windows-nodes.md
2022-04-19 05:11:16 -07:00
Kubernetes Prow Robot 4c8d6126f0 Merge pull request #33022 from kinzhi/main
[zh]update file content/zh/blog/_index.md
2022-04-19 05:09:17 -07:00
Kubernetes Prow Robot a88928a518 Merge pull request #33024 from AllenZMC/patch-1
[zh] fix spelling
2022-04-19 05:03:16 -07:00
Kubernetes Prow Robot f94ee9f972 Merge pull request #33025 from my-git9/install-kubeadm2
[zh] Sync tools/kubeadm/install-kubeadm.md
2022-04-19 05:01:16 -07:00
wei.wang 0e6d0b6bab [zh]update file content/zh/docs/tasks/administer-cluster/kubeadm/adding-windows-nodes.md 2022-04-19 19:21:17 +08:00
Kubernetes Prow Robot 65daf9ca54 Merge pull request #33020 from HirazawaUi/main
[zh]Fix the format of scheduling/config.md
2022-04-19 02:55:17 -07:00
xin.li 53522d88b1 [zh] Sync tools/kubeadm/install-kubeadm.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-19 17:13:39 +08:00
Zhongmin 1c4980445f fix spelling 2022-04-19 16:50:06 +08:00
Kubernetes Prow Robot 6708ea3c87 Merge pull request #32993 from CodyBuilder-dev/patch-1
[ko] Correct typo in object-management.md
2022-04-19 00:09:16 -07:00
wei.wang 6cd17b446d update file content/zh/blog/_index.md 2022-04-19 15:08:09 +08:00
HirazawaUi 208ffb99ac Fix the format of scheduling/config.md 2022-04-19 15:01:25 +08:00
syxunion 31431d3ccf translate content/en/docs/reference/kubernetes-api/common-parameters/common-parameters.md (#32949)
* Modify the translation

* Modify according to Suggestions

* Modify according to Suggestions
2022-04-18 23:09:16 -07:00
Kubernetes Prow Robot 3dda62aa82 Merge pull request #33016 from Babapool/dockershim-migration-msg
Reword dockershim migration recommendation
2022-04-18 20:39:17 -07:00
Kubernetes Prow Robot cb885f51c9 Merge pull request #33011 from howieyuen/images
[zh]Sync content/zh/docs/concepts/containers/images.md
2022-04-18 20:37:17 -07:00
Kubernetes Prow Robot f02b0ac91f Merge pull request #33015 from Icarus9913/patch-1
fix chinese translation mistake
2022-04-18 19:51:18 -07:00
Kubernetes Prow Robot 795cc5d74f Merge pull request #33014 from my-git9/determine-reason-pod-failure2
[zh] update determine-reason-pod-failure.md
2022-04-18 19:49:17 -07:00
Kubernetes Prow Robot b398ada880 Merge pull request #32951 from HirazawaUi/main
[zh] Update scheduling/config.md
2022-04-18 19:45:17 -07:00
howieyuen 0a667fcc2d [zh]Sync content/zh/docs/concepts/containers/images.md 2022-04-19 10:31:40 +08:00
Kubernetes Prow Robot 4ff6f32121 Merge pull request #33005 from mengjiao-liu/sync_static_pod
[zh]Sync static-pod file
2022-04-18 19:31:17 -07:00
Kubernetes Prow Robot 6e5451d666 Merge pull request #32471 from serewicz/patch-2
install-kubeadm: use nc instead of telnet
2022-04-18 19:17:18 -07:00
Kubernetes Prow Robot 6541860e63 Merge pull request #32941 from chrisnegus/dockershim-shortcode-pages
Add dockershim shortcode to appropriate pages
2022-04-18 17:17:50 -07:00
Christopher Negus fcdf66a1fd Deleted a blank line 2022-04-18 23:41:41 +00:00
Christopher Negus ebc817852f Add dockershim shortcode to other files 2022-04-18 23:41:41 +00:00
Kubernetes Prow Robot 22d86412bf Merge pull request #32826 from chrisnegus/dockershim-shortcode
Create dockershim shortcode
2022-04-18 16:09:50 -07:00
Christopher Negus ee36e095d9 Reworded dockershim message 2022-04-18 22:58:03 +00:00
Vitthal Sai 98d8be323f Reword dockershim migration recommendation 2022-04-18 23:19:58 +05:30
Christopher Negus 6d560379a8 Create dockershim shortcode 2022-04-18 17:13:23 +00:00
serewicz 5750981c00 Update content/en/docs/setup/production-environment/tools/kubeadm/install-kubeadm.md
Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>
2022-04-18 11:25:13 -05:00
Icarus9913 80ad09f51b fix chinese translation mistake 2022-04-19 00:23:27 +08:00
xin.li 6f0de11cc3 [zh] Update debug-pod-replication-controller.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-18 23:26:55 +08:00
HirazawaUi 291e7ab873 Update scheduling/config.md 2022-04-18 23:17:57 +08:00
xin.li 6ce860aa89 [zh] Update deprecation-policy.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-18 21:54:44 +08:00
Kubernetes Prow Robot a8b1be1d5c Merge pull request #33012 from my-git9/declare-network-policy2
[zh] Update declare-network-policy.md
2022-04-18 06:36:41 -07:00
Kubernetes Prow Robot 60a36c7dcc Merge pull request #33009 from my-git9/Dual-stack
[zh] Update dual-stack-support.md
2022-04-18 06:26:41 -07:00
Mengjiao Liu bd0d8b79dd [zh]Sync static-pod file 2022-04-18 21:08:23 +08:00
xin.li 3a1ecd2138 [zh] Update declare-network-policy.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-18 20:58:30 +08:00
Kubernetes Prow Robot bee30a8eae Merge pull request #32995 from howieyuen/client-authentication-v1beta1
[zh] translate zh/docs/reference/config-api/client-authentication.v1beta1
2022-04-18 05:52:41 -07:00
xin.li aa0ca9fe41 [zh] Update dual-stack-support.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-18 20:45:35 +08:00
Kubernetes Prow Robot 2dffc165f4 Merge pull request #32974 from my-git9/kubeadm-reconfigure
[zh] translate kubeadm-reconfigure.md
2022-04-18 05:34:41 -07:00
howieyuen 36be4cb47a [zh] translate zh/docs/reference/config-api/client-authentication.v1beta1 2022-04-18 19:35:31 +08:00
Kubernetes Prow Robot 3470795b2a Merge pull request #33004 from zaunist/access-cluster-api
[zh]: Rsync access-cluster-api.md
2022-04-18 04:08:42 -07:00
Kubernetes Prow Robot c83b6390e2 Merge pull request #32964 from 0xff-dev/main
[zh] sync horizontal-pod-autoscale.md
2022-04-18 02:46:42 -07:00
0xff-dev d430cf1a34 [zh] sync horizontal-pod-autoscale.md 2022-04-18 17:35:32 +08:00
zaunist 53cec5e6d0 docs: Rsync access-cluster-api.md 2022-04-18 15:53:35 +08:00
Onur 50e01a032a Update content/en/docs/concepts/services-networking/ingress.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-18 09:28:49 +03:00
Kubernetes Prow Robot 0ea46664bf Merge pull request #32968 from my-git9/quality-service-pod1
[zh] Update quality-service-pod.md
2022-04-17 22:48:41 -07:00
xin.li b1cbb92dba [zh] Update quality-service-pod.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-18 13:27:27 +08:00
Kubernetes Prow Robot 89c91ff2c5 Merge pull request #32934 from sftim/20220414_fix_git_ownership_trust_concern
Work around git directory ownership change check
2022-04-17 21:24:41 -07:00
Kubernetes Prow Robot 13a928bef5 Merge pull request #32954 from Sea-n/fix-id
[id] Fix Markdown format
2022-04-17 19:44:41 -07:00
Kubernetes Prow Robot 1f2556375d Merge pull request #32996 from my-git9/network-policies2
[zh] Update network-policies.md
2022-04-17 18:46:42 -07:00
Kubernetes Prow Robot 93c301ad13 Merge pull request #32981 from my-git9/policy-resources
[zh] Sync policy-resources/_index.md
2022-04-17 18:44:41 -07:00
Qiming Teng 5d099dba12 [zh] Translate kubelet config v1beta1 2022-04-18 09:41:43 +08:00
xin.li 69984b9616 [zh] Update network-policies.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-18 09:11:23 +08:00
Kubernetes Prow Robot f490abd9b4 Merge pull request #32932 from TinySong/update-outdate-file
[zh] update outdate setup-konnectivity file
2022-04-17 17:54:41 -07:00
Onur 70c7785cdd Update ingress.md
'spec' is just another field that any Kubernetes object (Ingress here) needs.
2022-04-17 20:02:10 +03:00
song 9b4516d8fe [zh] update outdate setup-konnectivity file 2022-04-17 22:16:41 +08:00
Kubernetes Prow Robot 09b773966b Merge pull request #32955 from Sea-n/fix-fr
[fr] Fix Markdown format
2022-04-17 01:36:40 -07:00
CodyBuilder-dev 9a90377a14 Update object-management.md 2022-04-17 13:53:53 +09:00
xin.li d4fb60ae20 [zh] Sync policy-resources/_index.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-17 12:17:06 +08:00
Kubernetes Prow Robot 3920b5e71f Merge pull request #32813 from tengqm/networkpolicy-example
Move NetworkPolicy into examples
2022-04-16 13:57:10 -07:00
Kubernetes Prow Robot 19ad6cb714 Merge pull request #32966 from Arhell/fix-code
[id] fix a nit in the feature-state short code
2022-04-16 09:05:10 -07:00
Kubernetes Prow Robot f140406dec Merge pull request #32948 from Arhell/upd-value
[id] updated allowedTopologies values format
2022-04-16 09:03:10 -07:00
Kubernetes Prow Robot 78f30d22ee Merge pull request #32915 from tallclair/broken-links-it
[it] Clean up various broken links
2022-04-16 08:59:11 -07:00
Sean Wei 613bb080ff Remove deprecated extensions API group in document 2022-04-16 21:56:25 +08:00
Kubernetes Prow Robot 549a67b303 Merge pull request #32985 from my-git9/install-kubectl-linux2
[zh] update install-kubectl-linux.md
2022-04-16 06:51:10 -07:00
Kubernetes Prow Robot 41933c5f9e Merge pull request #32983 from my-git9/create-hostprocess-pod
[zh] Update  create-hostprocess-pod.md
2022-04-16 06:49:10 -07:00
Kubernetes Prow Robot 474addc07a Merge pull request #32982 from my-git9/workload-resources
[zh] add dir workload-resources'
2022-04-16 06:47:10 -07:00
Kubernetes Prow Robot 6cfe3f5c5b Merge pull request #32980 from my-git9/extend-resources2
[zh] add dir extend-resources
2022-04-16 06:45:10 -07:00
Kubernetes Prow Robot a466967f56 Merge pull request #32978 from my-git9/cluster-resources
[zh] Update cluster-resources/_index.md
2022-04-16 06:43:10 -07:00
Kubernetes Prow Robot af39584dae Merge pull request #32977 from my-git9/Authorization
[zh] Create dir authorization-resources
2022-04-16 06:41:10 -07:00
Kubernetes Prow Robot b1693de98c Merge pull request #32979 from my-git9/common-parameters
[zh] Sync config-and-storage-resources/_index.md
2022-04-16 06:37:10 -07:00
xin.li 8dcdc15b04 [zh] translate kubeadm-reconfigure.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 21:25:58 +08:00
Kubernetes Prow Robot 8ac6b0360c Merge pull request #32923 from jai/jai/add-app-labels-well-known
Register and properly document recommended workload labels
2022-04-16 04:35:11 -07:00
196Ikuchil 97295ed88f Improvement for en/docs/reference/glossary/api-eviction.md (#32959)
* fix:add description of PodDisruptionBudgets and hyperlink

* Update api-eviction.md
2022-04-16 04:33:10 -07:00
Kubernetes Prow Robot 6213b9368f Merge pull request #32963 from Sea-n/remove-space
Remove space in filename
2022-04-16 04:29:10 -07:00
Kubernetes Prow Robot b43ee14fba Merge pull request #32962 from Sea-n/change-filename
Rename non-ASCII filename
2022-04-16 04:27:10 -07:00
xin.li 72799df83f [zh] update install-kubectl-linux.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 18:13:36 +08:00
xin.li 3ad1ecf396 [zh] Update create-hostprocess-pod.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 18:09:54 +08:00
xin.li 4be6562f2c [zh] add dir workload-resources'
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 18:05:44 +08:00
xin.li 1225a7ce39 add dir extend-resources
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 17:57:27 +08:00
xin.li b4d5d8965b [zh] Update config-and-storage-resources/_index.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 17:54:46 +08:00
xin.li 1a440c7111 [zh] Create dir authorization-resources
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 17:50:45 +08:00
xin.li fc8b4f0dac [zh] Update cluster-resources/_index.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 17:47:16 +08:00
Kubernetes Prow Robot 26b33f3885 Merge pull request #32976 from my-git9/Authentication
[zh] Create dir authentication-resources
2022-04-16 02:47:10 -07:00
xin.li 2875b151b9 [zh] Create dir authentication-resources
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 17:44:36 +08:00
Kubernetes Prow Robot 4fbbfd7895 Merge pull request #32975 from my-git9/service-resources
[zh] add dir /reference/kubernetes-api/service-resources
2022-04-16 02:41:10 -07:00
xin.li 4d218f16c4 [zh] add dir /reference/kubernetes-api/service-resources
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 17:39:22 +08:00
Kubernetes Prow Robot 2e08644bf0 Merge pull request #32973 from my-git9/control-plane-flags2
[zh] Update control-plane-flags.md
2022-04-16 02:39:10 -07:00
xin.li ffc34de946 [zh] Update control-plane-flags.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 17:28:45 +08:00
Kubernetes Prow Robot 7962632a49 Merge pull request #32520 from howieyuen/ref_api_common_status
[zh]translate content/docs/reference/kubernetes-api/common-definition…
2022-04-16 02:21:10 -07:00
Kubernetes Prow Robot 3681ef47d0 Merge pull request #32972 from my-git9/contribute-upstream2
[zh]Update contribute-upstream.md
2022-04-16 01:53:10 -07:00
Kubernetes Prow Robot 56a5789efa Merge pull request #32971 from my-git9/pod-topology-spread-constraints2
[zh] Update pod-topology-spread-constraints.md
2022-04-16 01:51:12 -07:00
Kubernetes Prow Robot a2f35492eb Merge pull request #32969 from my-git9/runtime-class2
[zh] Update runtime-class.md
2022-04-16 01:49:12 -07:00
Kubernetes Prow Robot f5679b61ae Merge pull request #32970 from my-git9/dns-pod-service2
[zh] Update dns-pod-service.md
2022-04-16 01:47:12 -07:00
Kubernetes Prow Robot 255899ae35 Merge pull request #32917 from tallclair/broken-links-ko
[ko] Clean up various broken links
2022-04-16 01:43:12 -07:00
xin.li 2c95aad902 [zh]Update contribute-upstream.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 15:20:17 +08:00
xin.li 6b5c8a3291 [zh] Update pod-topology-spread-constraints.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 15:15:45 +08:00
lishuai-hw f4fd890221 translate this page into Chinese: https://kubernetes.io/blog/2022/01/… (#32953)
* translate this page into Chinese: https://kubernetes.io/blog/2022/01/10/meet-our-contributors-india-ep-01/

* translate this page into Chinese (add one space before/after English words): https://kubernetes.io/blog/2022/01/10/meet-our-contributors-india-ep-01/

* translate this page into Chinese (add one space before/after English words): https://kubernetes.io/blog/2022/01/10/meet-our-contributors-india-ep-01/
2022-04-16 00:11:10 -07:00
xin.li 2ec3334f6a [zh] Update dns-pod-service.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 15:10:02 +08:00
xin.li c808dd1e9e [zh] Update runtime-class.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-16 15:04:32 +08:00
Kubernetes Prow Robot ee11573cc1 Merge pull request #32961 from mengjiao-liu/sync_create_hostprocess_pod_zh
[zh]Sync pull-image-private-registry.md
2022-04-15 20:43:10 -07:00
Arhell a9b44a09c6 [id] fix a nit in the feature-state short code 2022-04-16 00:34:27 +03:00
Kubernetes Prow Robot e6ad2431e5 Merge pull request #32956 from Sea-n/fix-es
[es] Fix Markdown format
2022-04-15 08:57:10 -07:00
Mengjiao Liu d82f6d402f [zh]Sync pull-image-private-registry.md 2022-04-15 22:27:18 +08:00
Kubernetes Prow Robot ca5792e572 Merge pull request #32958 from Sea-n/fix-pt-br
[pt-br] Fix Markdown format
2022-04-15 06:11:10 -07:00
Sean Wei 73ecc2aacf Remove space in filename 2022-04-15 20:58:06 +08:00
Kubernetes Prow Robot dd54eb8e24 Merge pull request #32957 from Sea-n/fix-de
[de] Fix Markdown format
2022-04-15 05:53:10 -07:00
Sean Wei bcef1ba452 Rename non-ASCII filename 2022-04-15 20:47:49 +08:00
Kubernetes Prow Robot 3bbffadea1 Merge pull request #32907 from Sea-n/fix-zh
[zh] Fix Markdown format
2022-04-15 03:31:10 -07:00
Kubernetes Prow Robot b61c0d6963 Merge pull request #32899 from mengjiao-liu/add_blog_1_24_removals_and_deprecations_zh
[zh] Add 2022-04-07-Kubernetes-1-24-removals-and-deprecations.md
2022-04-15 03:07:10 -07:00
Kubernetes Prow Robot f37bd3849b Merge pull request #32947 from ydFu/update-addons
[zh] Sync cluster-administration pages for addons.md
2022-04-15 03:03:10 -07:00
Kubernetes Prow Robot 4d766bc2e4 Merge pull request #31383 from KobayashiD27/translate-concepts/services-networking/topology-aware-hints
[ja]Translate concepts/services networking/topology aware hints into Japanese
2022-04-15 02:49:10 -07:00
Kubernetes Prow Robot 376b12511f Merge pull request #31333 from jberkus/jalink
[ja] Fix link to dev@kubernetes mailing list
2022-04-15 02:43:10 -07:00
Kubernetes Prow Robot 94c9a3dd61 Merge pull request #32084 from 196Ikuchil/policies
[ja] Translate /docs/reference/scheduling/policies/ into Japanese
2022-04-15 02:41:10 -07:00
Sean Wei f8b15c9bea [zh] Fix Markdown format 2022-04-15 16:47:31 +08:00
Mengjiao Liu 4a7a35e06a [zh] Add 2022-04-07-Kubernetes-1-24-removals-and-deprecations.md 2022-04-15 16:25:51 +08:00
Kubernetes Prow Robot 0c7e131a11 Merge pull request #32865 from zaunist/kubelet-in-users
[zh] Rsync kubelet-in-userns.md
2022-04-15 01:17:10 -07:00
zaunist 3e54683ac7 docs: rsync kubelet-in-userns 2022-04-15 15:28:14 +08:00
ydFu 50615919a2 [zh] Sync cluster-administration pages for addons.md
* Sync with english version in 'Fix Contiv addon link.' (#32938)

Signed-off-by: ydFu <ader.ydfu@gmail.com>
2022-04-15 15:16:28 +08:00
Arhell e8ad3bb411 [id] updated allowedTopologies values format 2022-04-15 09:45:02 +03:00
Kubernetes Prow Robot b3d6cddcc6 Merge pull request #32870 from Arhell/upd-link
[id] update proposal link to point to archive
2022-04-14 23:15:10 -07:00
Kubernetes Prow Robot 45747ba56e Merge pull request #32929 from mengjiao-liu/sync_kustomization_zh
[zh]Sync kustomization.md
2022-04-14 22:53:11 -07:00
Kubernetes Prow Robot a669fd860b Merge pull request #32928 from mengjiao-liu/sync_configure-pod-configmap_zh
[zh]Reflect the changed behaviour for multiple use of --from-env-file in ConfigMap creation
2022-04-14 22:51:10 -07:00
Kubernetes Prow Robot 5c57cce5d6 Merge pull request #32711 from astraw99/patch-4
Update quality-service-pod.md
2022-04-14 22:41:10 -07:00
Mengjiao Liu a7daeaa871 [zh]Sync kustomization.md 2022-04-15 10:20:32 +08:00
Kubernetes Prow Robot 9b7d904bc4 Merge pull request #32926 from mengjiao-liu/sync_debug_application_zh
[zh]Sync debug-application.md
2022-04-14 19:03:09 -07:00
Kubernetes Prow Robot 6fb52c5790 Merge pull request #32897 from Sea-n/main
[en] Fix Markdown formats
2022-04-14 18:17:10 -07:00
Kubernetes Prow Robot 44269ec404 Merge pull request #32898 from mengjiao-liu/fix_change_runtime_containerd_title_zh
[zh] Fix change-runtime-containerd.md title display error
2022-04-14 17:25:09 -07:00
Kubernetes Prow Robot df7785e4fe Merge pull request #32759 from AkihiroSuda/update-containerd-cri-link
runtime-class.md: update containerd/cri link
2022-04-14 17:23:10 -07:00
Kubernetes Prow Robot 8250200d0a Merge pull request #30507 from riita10069/riita10069-patch-1
[ja]Update `content/ja/docs/concepts/configuration/secret.md`
2022-04-14 11:25:35 -07:00
Kubernetes Prow Robot 57fc90807a Merge pull request #30161 from riita10069/feature/concepts/security/pod-security-standards
[ja]Update pod-security-standards.md
2022-04-14 11:23:36 -07:00
Kubernetes Prow Robot ca50f67c88 Merge pull request #32083 from 196Ikuchil/reference_scheduling_config
[ja] Translate reference/scheduling/config/ & reference/glossary/replica-set.md into Japanese
2022-04-14 11:21:35 -07:00
Kubernetes Prow Robot 0de3784c77 Merge pull request #31935 from 196Ikuchil/translate_resource_bin_packing
[ja] Translate concepts/scheduling-eviction/resource-bin-packing/ into Japanese
2022-04-14 11:17:35 -07:00
Kubernetes Prow Robot c4d186d68c Merge pull request #32872 from mengjiao-liu/sync_mysql_cm_ja
[ja]Sync mysql-configmap.yaml
2022-04-14 11:15:35 -07:00
Kubernetes Prow Robot 0fc468096c Merge pull request #32678 from 196Ikuchil/fix_kube_scheduler
[ja] Update ja/docs/concepts/scheduling-eviction/kube-scheduler.md to fix the weight and some links
2022-04-14 11:13:35 -07:00
Kubernetes Prow Robot 55b4635e9d Merge pull request #30157 from riita10069/feature/concepts/architecture/nodes
[ja]Update `content/ja/docs/concepts/architecture/nodes.md`
2022-04-14 11:11:36 -07:00
Kubernetes Prow Robot 6e87cbe551 Merge pull request #32906 from sftim/20220413_update_docsy
Update Docsy to v0.2.0
2022-04-14 10:56:48 -07:00
Kubernetes Prow Robot 165fcc818b Merge pull request #32938 from tallclair/contivvpp
Fix Contiv addon link.
2022-04-14 10:14:47 -07:00
Tim Allclair 2dbbadd7d7 Fix contiv link 2022-04-14 09:49:19 -07:00
Tim Allclair 33d6f7a697 Revert "Delete broken link (contiv.io)"
This reverts commit b0e4e7a03c.
2022-04-14 09:47:26 -07:00
Tim Bannister edb9f05b84 Work around git directory ownership change check
Add a mitigation for the extra checks that Git added in response to
CVE-2022-24765.
2022-04-14 17:12:53 +01:00
Mengjiao Liu 4f70538d4f [zh] Fix change-runtime-containerd.md title display error 2022-04-14 21:04:03 +08:00
Mengjiao Liu 32975b8bda [zh]Reflect the changed behaviour for multiple use of --from-env-file in ConfigMap creation 2022-04-14 20:18:55 +08:00
Kubernetes Prow Robot 108434f8b1 Merge pull request #32925 from mengjiao-liu/synx_change_runtime_containerd_zh
[zh]Sync debug-running-pod.md
2022-04-14 03:56:45 -07:00
Mengjiao Liu 5588e0ce24 [zh]Sync debug-application.md 2022-04-14 18:43:20 +08:00
Mengjiao Liu 919dd1f4a8 [zh]Sync debug-running-pod.md 2022-04-14 18:21:52 +08:00
Kubernetes Prow Robot 9e3fa7be50 Merge pull request #32912 from tallclair/broken-links-de
[de] Clean up various broken links
2022-04-14 01:02:46 -07:00
Jai Govindani 795672d928 feat(labels-annotations-taints): Add recommended labels 2022-04-14 09:24:21 +07:00
Mitesh Jain fbd099a209 Adding more information to Installing kubeadm step. (#32884)
* Adding more information to Installing kubeadm step.

* Adding more information to installing kubeadm step.

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>

* Remove unnecessary quotes.

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>
2022-04-13 17:54:46 -07:00
Kubernetes Prow Robot 58bf5a37da Merge pull request #32821 from howieyuen/object-meta
[zh]translate content/zh/docs/reference/kubernetes-api/common-definitions/object-meta.md into Chinese
2022-04-13 17:20:47 -07:00
Tim Allclair 00a6dc0c10 [ru] Clean up various broken links 2022-04-13 17:09:02 -07:00
Tim Allclair 0f087d5d7f [ko] Clean up various broken links 2022-04-13 17:06:02 -07:00
Tim Allclair af059477fb [ja] Clean up various broken links 2022-04-13 17:03:39 -07:00
Tim Allclair 5da572c915 [it] Clean up various broken links 2022-04-13 17:01:15 -07:00
Tim Allclair ac9368c9ba [de] Clean up various broken links 2022-04-13 16:53:01 -07:00
Kubernetes Prow Robot d9c3c04087 Merge pull request #32908 from Sea-n/fix-it
[it] Fix Markdown format
2022-04-13 14:26:46 -07:00
Sean Wei a1741bcee9 [de] Fix Markdown format 2022-04-14 01:43:08 +08:00
Sean Wei 872f2eecab [pt-br] Fix Markdown format 2022-04-14 01:42:34 +08:00
Sean Wei e2375cc164 [es] Fix Markdown format 2022-04-14 01:42:27 +08:00
Sean Wei 4d06efb2b8 [it] Fix Markdown format 2022-04-14 01:41:45 +08:00
Sean Wei 7c221a3688 [fr] Fix Markdown format 2022-04-14 01:41:28 +08:00
Sean Wei 56dc4a0998 [id] Fix Markdown format 2022-04-14 01:40:10 +08:00
Sean Wei 01c3c53b7d [en] Fix Markdown format 2022-04-14 01:33:53 +08:00
Tim Bannister e88e05dbb7 Update Docsy to v0.2.0 2022-04-13 17:48:00 +01:00
Kubernetes Prow Robot c6472cbea3 Merge pull request #32132 from shannonxtreme/dockershim-am-i-on-dockerhsim
Add info about finding the runtime endpoint
2022-04-13 09:32:46 -07:00
Shannon Kularathna d3ad42f669 Add info about finding the runtime endpoint 2022-04-13 15:36:55 +00:00
Kubernetes Prow Robot 3fa88512a6 Merge pull request #32892 from my-git9/replicationcontroller1
[zh] Update replicationcontroller.md
2022-04-13 06:54:46 -07:00
howieyuen 8fe863faf8 [zh]translate content/zh/docs/reference/kubernetes-api/common-definitions/object-meta.md into Chinese 2022-04-13 17:31:30 +08:00
xin.li 0c6d37d1cf [zh] Update replicationcontroller.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-13 15:56:36 +08:00
Kubernetes Prow Robot 0d171a1c23 Merge pull request #32891 from mengjiao-liu/fix_missing_links_zh
[zh]Fix missing links
2022-04-12 20:42:48 -07:00
done b86f126263 [ja] Translate concepts/cluster-administration/logging into Japanese (#31808)
* add ja/concepts/cluster-administration/logging

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix typo

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix typo, word

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix typo

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix branch name

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix link lang

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

fix `ポッド` -> `Pod`

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* remove reviwers block

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

* Update content/ja/docs/concepts/cluster-administration/logging.md

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>

Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-12 20:04:46 -07:00
Mengjiao Liu 758c357119 [zh]Fix missing links 2022-04-13 10:47:17 +08:00
Kubernetes Prow Robot 6283010d87 Merge pull request #32147 from tengqm/zh-feature-gates
[zh] Resync feature gates
2022-04-12 18:52:46 -07:00
Chris Short a582a21cf0 Mention Detector for Docker Socket in dockershim removal FAQ (#32685)
* Update 2022-02-17-updated-dockershim-faq.md

Adding the new Detector for Docker Socket plugin to the FAQ.

The tool will help folks find Dockershim usage in files on disk as well as running clusters.

* Apply suggestions from code review

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update 2022-02-17-updated-dockershim-faq.md

Adding period

* Update content/en/blog/_posts/2022-02-17-updated-dockershim-faq.md

Co-authored-by: Rey Lejano <rlejano@gmail.com>

* Update content/en/blog/_posts/2022-02-17-updated-dockershim-faq.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>
Co-authored-by: Rey Lejano <rlejano@gmail.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2022-04-12 15:42:46 -07:00
Arhell 2a15957d13 [id] update proposal link to point to archive 2022-04-13 00:22:05 +03:00
Kubernetes Prow Robot 2ca30c11c8 Merge pull request #30840 from sftim/20211209_highlight_dockershim_deprecation_discussion_issue
Highlight discussion issue for dockershim deprecation
2022-04-12 12:52:46 -07:00
Kubernetes Prow Robot 7a44e32fb9 Merge pull request #32805 from chrisnegus/dockershim-banner
Add dockershim removal banner
2022-04-12 12:38:46 -07:00
Christopher Negus de066e6a71 Responded to review comments 2022-04-12 18:04:09 +00:00
Kubernetes Prow Robot b69b3d76cb Merge pull request #32098 from Babapool/pr-shadow-wrangler-docs
Add documentation for PR Wrangler Shadow program
2022-04-12 10:33:24 -07:00
Tim Bannister 05e987a47b Highlight discussion issue for dockershim deprecation
- Link to k/kubernetes issue 106917
  (various places)
- Related rewording to make that extra link work in context

and also:
- Replace alias for dockershim FAQ with a Netlify redirect

Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>
2022-04-12 18:02:26 +01:00
Kubernetes Prow Robot 89cf5eb7ce Merge pull request #32738 from sftim/20220401_update_container_runtimes_dockershim_removal
Revise “Container runtimes” page in light of dockershim removal
2022-04-12 07:55:23 -07:00
Kubernetes Prow Robot 383fd26f21 Merge pull request #32761 from sftim/20220405_update_kubelet_container_runtime_detection_dockershim
Update kubeadm CRI detection docs in light of dockershim deprecation
2022-04-12 07:19:23 -07:00
Qiming Teng 479a599438 [zh] Resync feature gates 2022-04-12 19:07:32 +08:00
Kubernetes Prow Robot 9cf4b3d116 Merge pull request #32874 from mengjiao-liu/fix_missing_links
Fix missing links
2022-04-12 04:03:24 -07:00
Kubernetes Prow Robot 2c8a25cb2f Merge pull request #32871 from mengjiao-liu/sync_configmap_yaml_zh
[zh] Sync mysql-configmap.yaml
2022-04-12 04:01:24 -07:00
Mengjiao Liu 7e0a2162d7 Fix missing links 2022-04-12 16:46:38 +08:00
Mengjiao Liu 224b80dbc4 [ja]Sync mysql-configmap.yaml 2022-04-12 15:08:27 +08:00
Mengjiao Liu 70cabe4a5b [zh] Sync mysql-configmap.yaml 2022-04-12 14:57:13 +08:00
Kubernetes Prow Robot bc8c561815 Merge pull request #32842 from tengqm/zh-resync-assign-pod
[zh] Resync assign pod to node
2022-04-11 21:49:22 -07:00
Kubernetes Prow Robot e1927a684a Merge pull request #32868 from mengjiao-liu/fix-mysql-conf
Fix mysql-configmap.yaml  error
2022-04-11 21:41:22 -07:00
Mengjiao Liu 812dafd7ef Fix mysql-configmap.yaml error 2022-04-12 12:05:40 +08:00
Qiming Teng 6a375baa5e [zh] Resync assign pod to node
The whole page was rewritten. This is a full resync.
2022-04-12 10:32:41 +08:00
Ldsdsy 71b06a9973 translate 2021-09-27-SIG-Node-Spotlight (#32847)
translate 2021-09-27-SIG-Node-Spotlight

translate 2021-09-27-SIG-Node-Spotlight
2022-04-11 19:19:21 -07:00
Kubernetes Prow Robot e4d521d1cf Merge pull request #32846 from tengqm/zh-resync-deployment
[zh] Resync deployment page
2022-04-11 19:15:21 -07:00
Kubernetes Prow Robot 52fc7e7db2 Merge pull request #32845 from tengqm/zh-resync-nodes
[zh] Resync nodes page
2022-04-11 19:09:21 -07:00
Kubernetes Prow Robot 6841e420c6 Merge pull request #32819 from mengjiao-liu/add_pv_provisioner_link_zh
[zh]Synchronize default-storage-class-prereqs.md files and improve translations
2022-04-11 18:23:22 -07:00
Kubernetes Prow Robot e45bfb5027 Merge pull request #32860 from miteshskj/replicationctrl-review
Adding link for client library to client-libraries page.
2022-04-11 18:05:22 -07:00
Kubernetes Prow Robot a63179c3c1 Merge pull request #32861 from miteshskj/dnspodservice-review
Remove stale information about pod dnsConfig.
2022-04-11 18:01:22 -07:00
Mitesh Jain bcc87b7c34 Remove stale information about pod dnsConfig. 2022-04-11 20:58:24 +05:30
Mitesh Jain a21e006ebe Adding link for client library to client-libraries page. 2022-04-11 20:47:44 +05:30
Mengjiao Liu 82e8574fc9 [zh]Synchronize default-storage-class-prereqs.md files and improve translations 2022-04-11 21:53:18 +08:00
Kubernetes Prow Robot 80e2e7d547 Merge pull request #32810 from 0xff-dev/main
[zh] sync resource-metrics-pipeline.md
2022-04-11 06:48:06 -07:00
Kubernetes Prow Robot 6e79a96731 Merge pull request #32843 from Arhell/fix-path
[ja] fix wrong path
2022-04-11 06:22:06 -07:00
0xff-dev 5b50040c54 [zh] sync resource-metrics-pipeline.md 2022-04-11 20:30:42 +08:00
Kubernetes Prow Robot bfa1c7fc24 Merge pull request #32856 from mengjiao-liu/update_pv_link
Update links in file default-storage-class-prereqs.md to avoid using targets that are redirected.
2022-04-11 03:16:06 -07:00
Kubernetes Prow Robot 0c51fdf5c9 Merge pull request #32853 from Arhell/update-conf
[zh] update scheduler configuration sample version
2022-04-11 03:02:07 -07:00
Mengjiao Liu 164bdfa5a1 Update links in file default-storage-class-prereqs.md to avoid using targets that are redirected. 2022-04-11 17:50:08 +08:00
Arhell 4fdd497988 [zh] update scheduler configuration sample version 2022-04-11 11:19:09 +03:00
Wang feebdc06d0 [ja] Translate tasks/administer-cluster/migrating-from-dockershim into Japanese (#31322)
* new pr

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/_index.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-10 23:24:05 -07:00
Wang eeaee1f058 [ja] Translate tasks/administer-cluster/kubeadm/configure-cgroup-driver into Japanese (#31222)
* done

* self review

* fix

* Update content/ja/docs/tasks/administer-cluster/kubeadm/configure-cgroup-driver.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/kubeadm/configure-cgroup-driver.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-10 23:22:06 -07:00
Wang d62122cecb [ja] Translate tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents into Japanese (#31304)
* done

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

* Update content/ja/docs/tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents.md

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>

Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-10 23:16:06 -07:00
Qiming Teng e0302f46f2 [zh] Resync nodes page 2022-04-11 14:11:00 +08:00
Kubernetes Prow Robot 9cf7661cd7 Merge pull request #32852 from mengjiao-liu/fix-garbage-collection-link
[zh] Fix wrong link in garbage-collection file
2022-04-10 20:34:06 -07:00
Kubernetes Prow Robot ad23315489 Merge pull request #32850 from my-git9/addons1
[zh] Update addons.md
2022-04-10 20:26:05 -07:00
Kubernetes Prow Robot 4a9697803c Merge pull request #32841 from tengqm/zh-rm-psp
[zh] Remove PSP
2022-04-10 20:16:05 -07:00
Mengjiao Liu 004ee5e793 [zh] Fix wrong link in garbage-collection file 2022-04-11 11:08:21 +08:00
xin.li d1fb823abc [zh] Update addons.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-11 09:26:36 +08:00
Kubernetes Prow Robot ab44da16f1 Merge pull request #32836 from 08thse/patch-1
Fix typo in create-hostprocess-pod.md
2022-04-10 17:06:05 -07:00
Qiming Teng c44f50decf [zh] Resync deployment page 2022-04-10 20:11:46 +08:00
Arhell 0bb7611b6d [ja] fix wrong path 2022-04-10 09:26:33 +03:00
Qiming Teng 5a4e1e3254 [zh] Remove PSP
The upstream English page is removed.
2022-04-10 09:18:37 +08:00
Kubernetes Prow Robot 1365e326d4 Merge pull request #32834 from mrk-andreev/patch-1
Remove link to domana.io
2022-04-09 18:16:04 -07:00
sou 4764a50fee Update create-hostprocess-pod.md
Fix typo (Window -> Windows)
2022-04-09 23:52:46 +09:00
Mark Andreev 27ec191771 Remove link to domana.io
The domain name Romana.io is for sale. I suggest to remove this invalid ref.
2022-04-09 13:13:20 +04:00
Kubernetes Prow Robot 872f57ab95 Merge pull request #32234 from tengqm/zh-probes
[zh] Resync configure probes
2022-04-09 00:06:04 -07:00
Kubernetes Prow Robot a90c43ad3b Merge pull request #32809 from tengqm/zh-resync-securing-a-cluster
[zh] Rersync securing a cluster
2022-04-08 21:58:06 -07:00
Kubernetes Prow Robot fd9f11b32c Merge pull request #32703 from tengqm/fix-32702
[zh] Fix cassandra tutorial translation
2022-04-08 21:56:05 -07:00
Qiming Teng f922ccf273 [zh] Resync configure probes 2022-04-09 11:55:09 +08:00
Kubernetes Prow Robot f7ca4fd0a9 Merge pull request #32719 from zaunist/docs/concepts/services-networking
[zh]: Resync network-policies.md
2022-04-08 20:52:04 -07:00
Kubernetes Prow Robot 74b148081f Merge pull request #32793 from TheSamDickey/patch-1
Update ingress-v1 rules.http.paths.pathType values
2022-04-08 16:36:04 -07:00
Kubernetes Prow Robot 9169cc8ebc Merge pull request #32791 from jihoon-seo/220407_Replace_Go_Doc_URL_with_pkg.go.dev
Replace Go Doc URL with `pkg.go.dev`
2022-04-08 16:06:04 -07:00
阿杰鲁 85ad3461af docs: Resync network-policies.md 2022-04-09 01:20:15 +08:00
Christopher Negus 1fba7dcc8a Fixed link 2022-04-08 11:18:14 +00:00
Kubernetes Prow Robot 2ef5c665e8 Merge pull request #32816 from skeetwu/patch-1
[zh] Enhance format in rbac.md
2022-04-08 04:00:42 -07:00
Kubernetes Prow Robot 259fd8fe69 Merge pull request #32815 from mengjiao-liu/sync-tail-zh
[zh]Added retry option to tail
2022-04-08 03:58:42 -07:00
Kubernetes Prow Robot 12e12f8f05 Merge pull request #32817 from sarangjo/patch-1
Nit: grammar fix on install-kubectl-linux.md
2022-04-08 03:46:42 -07:00
Kubernetes Prow Robot 75ce0b8cfb Merge pull request #32814 from ktsakalozos/patch-1
Fix minor typo in certificates.md
2022-04-08 03:44:42 -07:00
Kubernetes Prow Robot 3b19dbf22f Merge pull request #32764 from neolit123/1.24-add-steps-for-reconf
kubeadm: add task page for cluster reconf
2022-04-08 03:28:42 -07:00
Sarang Joshi b3e75c52a6 Nit: grammar fix on install-kubectl-linux.md 2022-04-08 15:19:53 +05:30
Skeet WU 40b3832fe0 [zh] Enhance format in rbac.md 2022-04-08 17:36:50 +08:00
Mengjiao Liu ab76ffa2d4 [zh]Added retry option to tail 2022-04-08 17:32:13 +08:00
Kubernetes Prow Robot f764ec7338 Merge pull request #32800 from my-git9/localization1
[zh]UPdate localization.md
2022-04-08 02:18:42 -07:00
Konstantinos Tsakalozos eb53819201 Fix minor typo in certificates.md 2022-04-08 12:08:55 +03:00
xin.li 528692cbef [zh]UPdate localization.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-08 16:51:01 +08:00
Kubernetes Prow Robot e408a389b3 Merge pull request #32757 from iamNoah1/main
Revise page “Contributing to the Upstream Kubernetes Code”
2022-04-08 01:34:41 -07:00
Kubernetes Prow Robot 3b27c941f1 Merge pull request #32811 from Arhell/fix-path
[fr] fix wrong path
2022-04-08 01:24:42 -07:00
Qiming Teng b51b1d6b1d Move NetworkPolicy into examples 2022-04-08 16:00:56 +08:00
Arhell 1eb33cde88 [fr] fix wrong path 2022-04-08 10:41:58 +03:00
Mads Jensen eefc776e29 Fix typos in Markdown links. (#32802)
* Fix typos in Markdown links.

* Test

Co-authored-by: Mads Jensen <atombrella@users.noreply.github.com>
2022-04-08 00:16:41 -07:00
Qiming Teng 6b25f92384 [zh] Rersync securing a cluster
This PR also fixes an English link in the admission controllers page,
which doesn't deserve a separate PR.
2022-04-08 10:49:23 +08:00
Lubomir I. Ivanov 931581eb88 kubeadm: add task page for cluster reconf
The new task page outlines steps for reconfiguring
a kubeadm cluster and persisting reconfiguration.

Link the new page from the existing guides for
"customizing components", "creating a cluster",
and "kubeadm upgrade".

Co-authored-by: Paco Xu <paco.xu@daocloud.io>
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-08 01:57:42 +03:00
Christopher Negus 7365b45a2d Added PR and changed expiration date 2022-04-07 21:36:40 +00:00
Christopher Negus f5f099c71d Changed the wording 2022-04-07 21:08:40 +00:00
Christopher Negus 8bdb53b2ef Create dockershim banner 2022-04-07 21:02:25 +00:00
Kubernetes Prow Robot d8dfd81d0c Merge pull request #32786 from reylejano/update-removal-blog
Follow-up PR to 1.24 Removals and Deprecations blog
2022-04-07 08:41:58 -07:00
Kubernetes Prow Robot 3b5f31e6de Merge pull request #32797 from Arhell/update-link
[ja] update networking model link
2022-04-07 07:39:57 -07:00
Kubernetes Prow Robot 220720a2b8 Merge pull request #32799 from guresonur/patch-2
Update service.md
2022-04-07 02:05:57 -07:00
Kubernetes Prow Robot 3aef33c651 Merge pull request #32259 from tengqm/fix-links-3
Fix nits in the change runtime containerd page
2022-04-07 02:03:57 -07:00
Kubernetes Prow Robot ed8d57455a Merge pull request #32190 from tengqm/fix-nodelocaldns
Reformat the node local DNS cache page
2022-04-07 01:39:57 -07:00
Onur e42c5e6c86 Update service.md 2022-04-07 11:28:58 +03:00
Kubernetes Prow Robot 6cffdff8e6 Merge pull request #32782 from reylejano/ko-broken-link
[ko] Remove broken link in Addons page
2022-04-07 01:09:56 -07:00
Arhell 69fd8c46ef [ja] update networking model link 2022-04-07 10:15:03 +03:00
Kubernetes Prow Robot c38941a3b1 Merge pull request #32789 from kubernetes/dev-1.23-ko.2
[ko] 2nd Korean localization work for v1.23
2022-04-06 23:53:56 -07:00
Kubernetes Prow Robot a6aee0c410 Merge pull request #32639 from tengqm/zh-flowcontrol
[zh] Resync flow-control page
2022-04-06 23:01:56 -07:00
Kubernetes Prow Robot 715761bd95 Merge pull request #32636 from tengqm/zh-resync-overview
[zh] Resync pages under overview
2022-04-06 22:59:56 -07:00
TheSamDickey 1be2b6e05c Update ingress-v1.md
While reading through the documentation, I noticed weird asterisk characters that seemed like they should be bullet points.  I kept reading and saw the formatting for `loadBalancer.ingress.ports.protocol`.  I liked how it organized the values into an easy to read list.

This proposed change formats the possible values for `rules.http.paths.pathType` to be a bullet point list, in (imo) a format that is easier to read.
2022-04-06 23:33:52 -05:00
Kubernetes Prow Robot f481a2b3ca Merge pull request #32788 from my-git9/replicaset2
[zh] Update replicaset.md
2022-04-06 19:41:56 -07:00
Jihoon Seo b16e2bc7f4 Replace Go Doc URL with pkg.go.dev 2022-04-07 11:22:38 +09:00
xin.li fac8de5456 [zh] Update replicaset.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-07 09:28:44 +08:00
Kubernetes Prow Robot 7da9d0d276 Merge pull request #31880 from jihoon-seo/220224_Outdated_M60
[ko] Update outdated files in `dev-1.23-ko.2` (M60-M73)
2022-04-06 17:59:56 -07:00
Kubernetes Prow Robot a6c1cf30c4 Merge pull request #31793 from jihoon-seo/220218_Outdated_M50-M58
[ko] Update outdated files in `dev-1.23-ko.2` (M50-M59)
2022-04-06 17:57:56 -07:00
Rey Lejano 53d2c177d6 followup PR to 1-24 removals and deprecations blog 2022-04-06 17:04:12 -07:00
Mickey Boxell f71cba23be Add Kubernetes 1.24 Removals and Deprecations blog post (#31767)
* Kubernetes 1.24 removals and deprecations blog

* Rename 2022-03-31-Kubernetes-1-24-deprecations-and-removals to 2022-03-31-Kubernetes-1-24-deprecations-and-removals.md

* Update 2022-03-31-Kubernetes-1-24-deprecations-and-removals.md

* Rename 2022-03-31-Kubernetes-1-24-deprecations-and-removals.md to 2022-04-07-Kubernetes-1-24-removals-and-deprecations.md

File rename
2022-04-06 14:50:25 -07:00
Tim Bannister 9c8227a521 Update kubeadm CRI detection docs
Update kubeadm CRI detection docs in light of dockershim deprecation.

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>
2022-04-06 22:14:49 +01:00
Rey Lejano 59b9738f58 update ko addons page to remove broken link 2022-04-06 14:03:56 -07:00
Kubernetes Prow Robot 31076af0d7 Merge pull request #32775 from Arhell/add-proxy
[ja] adding kube-proxy & update list
2022-04-06 07:10:55 -07:00
Akihiro Suda 8c48fa656f runtime-class.md: update containerd/cri link
The `containerd/cri` repo was merged into the `containerd/containerd` repo.
The `containerd/cri` repo is now archived.

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2022-04-06 17:38:50 +09:00
Arhell 17f000b4f1 [ja] adding kube-proxy & update list 2022-04-06 11:07:46 +03:00
Mitesh Jain 1eca303e91 Remove stale information about pod selector. 2022-04-06 11:07:24 +05:30
Kubernetes Prow Robot b0a0544579 Merge pull request #32771 from mrunalp/pod_priority_shutdown_beta
Update docs for Pod Priority Based Node Graceful Shutdown beta
2022-04-05 21:54:57 -07:00
Mrunal Patel bf90a22aaf Update docs for Pod Priority Based Node Graceful Shutdown beta
Signed-off-by: Mrunal Patel <mrunalp@gmail.com>
2022-04-05 18:17:52 -07:00
Kubernetes Prow Robot 275bb93aa6 Merge pull request #32763 from miteshskj/replicaset-review
Remove stale information about apiVersion.
2022-04-05 18:06:55 -07:00
Kubernetes Prow Robot d442f4c89b Merge pull request #32616 from 196Ikuchil/trans-controlling-access
[ja] Translate concepts/security/controlling-access/ into Japanese
2022-04-05 17:34:55 -07:00
Kubernetes Prow Robot cdf578eb69 Merge pull request #32766 from miteshskj/statefulset-review
Remove stale information about unsupported versions.
2022-04-05 17:28:56 -07:00
Priyanshu Ahlawat 508f111b60 Update resource-metrics-pipeline.md (#32467)
* Update resource-metrics-pipeline.md

* Update resource-metrics-pipeline.md

* Update content/en/docs/tasks/debug-application-cluster/resource-metrics-pipeline.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2022-04-05 17:18:56 -07:00
Mitesh Jain 7c58a81b89 Remove stale information about unsupported versions. 2022-04-06 01:48:25 +05:30
Mitesh Jain 1a5fe3ccbb Remove stale information about apiVersion. 2022-04-06 00:49:09 +05:30
Vitthal Sai 4a05cab07e Adds documentation for PR Wrangler Shadow program 2022-04-06 00:10:50 +05:30
Mitesh Jain f218c25778 Remove stale information about apiVersion. 2022-04-05 21:56:52 +05:30
196Ikuchil e80f838699 Update content/ja/docs/concepts/security/controlling-access.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-04-05 22:56:43 +09:00
196Ikuchil f741c87d1e Update content/ja/docs/concepts/security/controlling-access.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-04-05 22:56:34 +09:00
196Ikuchil c649f235f8 Update content/ja/docs/concepts/security/controlling-access.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-04-05 22:56:23 +09:00
Kubernetes Prow Robot 3cadb66eb8 Merge pull request #32704 from miteshskj/fix-32689
Add information about InTreePluginAzureFileUnregister and InTreePlugi…
2022-04-05 05:41:36 -07:00
Qiming Teng 4242d54768 [zh] Resync flow-control page 2022-04-05 20:40:02 +08:00
Qiming Teng 3a20474c11 [zh] Resync pages under overview 2022-04-05 20:38:12 +08:00
Qiming Teng 63e7cf796b [zh] Fix cassandra tutorial translation 2022-04-05 20:36:36 +08:00
Noah Ispas (iamNoah1) c231ba5be3 add necessary tools, correct git output example 2022-04-05 10:15:15 +02:00
Kubernetes Prow Robot 3bf1df5a12 Merge pull request #32692 from pipo02mix/patch-1
Update pod-topology-spread-constraints adding the missing scheduler name
2022-04-04 23:41:36 -07:00
Kubernetes Prow Robot 883ee38fe2 Merge pull request #32168 from jihoon-seo/220310_Translate_ns-level-pss
[ko] Translate 'cluster-level-pss' & 'ns-level-pss'
2022-04-04 22:13:36 -07:00
Jihoon Seo d5e79985bb [ko] Translate 'cluster-level-pss', 'ns-level-pss' 2022-04-05 13:53:23 +09:00
Jihoon Seo 2c535e2680 [ko] Update outdated files in dev-1.23-ko.2 M60-73 2022-04-05 13:21:01 +09:00
Jihoon Seo 3c29f68586 [ko] Update outdated files in dev-1.23-ko.2 M50-59 2022-04-05 13:18:39 +09:00
Kubernetes Prow Robot 59d7fde1ca Merge pull request #32723 from sohan-lh/patch-1
Update horizontal-pod-autoscale-walkthrough.md
2022-04-04 16:51:35 -07:00
Kubernetes Prow Robot a4bd36fbe8 Merge pull request #32755 from guettli/patch-4
PodSecurityPolicy is deprecated (glossary)
2022-04-04 16:31:36 -07:00
Thomas Güttler 7ce04aeb14 PodSecurityPolicy is deprecated (glossary) 2022-04-04 21:15:26 +02:00
Kubernetes Prow Robot 44ed64e205 Merge pull request #32751 from seokho-son/l10ng
Update l10n guide to use both native and English names in config.toml
2022-04-04 11:40:11 -07:00
Kubernetes Prow Robot 132fece161 Merge pull request #32652 from tidusete/patch-1
Missunderstood pods/pod-with-node-affinity.yaml
2022-04-04 09:56:10 -07:00
Seokho Son 3f70b2fca7 Update description for languageName 2022-04-05 00:47:45 +09:00
Kubernetes Prow Robot 016148039b Merge pull request #32712 from Arhell/remove-link
[id] remove link
2022-04-04 08:32:11 -07:00
Kubernetes Prow Robot 72f115fbbd Merge pull request #32731 from Arhell/fix-command
[ja] simplify commands
2022-04-04 08:06:11 -07:00
Kubernetes Prow Robot 463a88191c Merge pull request #32593 from tengqm/server-side-field-alpha
Add ServerSideFieldValidation feature
2022-04-04 07:34:12 -07:00
Seokho Son 258b71ae01 Update l10n guide to use both native and English names 2022-04-04 23:25:00 +09:00
Kubernetes Prow Robot 503e0cf1c9 Merge pull request #32748 from my-git9/kubeadm-reset
[zh]Update kubeadm-reset.md
2022-04-04 05:44:10 -07:00
196Ikuchil 4d8a3381e5 fix:ja documentation 2022-04-04 21:27:33 +09:00
196Ikuchil 98f2561376 fix:add auditing section 2022-04-04 21:25:03 +09:00
196Ikuchil 31b82a7bd9 Update content/ja/docs/concepts/security/controlling-access.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-04-04 21:16:02 +09:00
196Ikuchil 2bee59baf6 Update content/ja/docs/concepts/security/controlling-access.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-04-04 21:16:02 +09:00
196Ikuchil bffd0b822a Update content/ja/docs/concepts/security/controlling-access.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-04-04 21:16:02 +09:00
196Ikuchil 1e1ab08a43 fix:delete localized image 2022-04-04 21:16:02 +09:00
196Ikuchil a3d98f8ed8 fix:change 制御 to コントロール 2022-04-04 21:16:02 +09:00
196Ikuchil b22c87c411 fix:change admission control to アドミッションコントロール 2022-04-04 21:16:02 +09:00
196Ikuchil 9fa798cd48 add:localize diagram 2022-04-04 21:16:02 +09:00
196Ikuchil b86b858735 fix:change がある to があります 2022-04-04 21:16:02 +09:00
196Ikuchil 5323c317e8 add:translate concepts/security/controlling-access.md 2022-04-04 21:16:02 +09:00
xin.li 8a485f11e3 [zh]Update kubeadm-reset.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-04 18:59:16 +08:00
Kubernetes Prow Robot 5b507dfee8 Merge pull request #32749 from koushik-ms/patch-1
Manage TLS Certificates in a Cluster: Fix typo in template for glossary reference
2022-04-04 03:32:10 -07:00
Kubernetes Prow Robot e6c526b79d Merge pull request #32747 from my-git9/kubeadm-init-phase
[zh] Update kubeadm-init-phase.md
2022-04-04 03:30:10 -07:00
Kubernetes Prow Robot b74c283100 Merge pull request #32746 from my-git9/admission-controller
[zh] Update admission-controllers.md
2022-04-04 03:28:10 -07:00
Kubernetes Prow Robot a7ee8ae3bf Merge pull request #32739 from kylezhang/main
fixed typo.
2022-04-04 03:26:11 -07:00
Kubernetes Prow Robot 397655e8d3 Merge pull request #32745 from my-git9/authorization2
[zh] Update authorization.md
2022-04-04 03:24:10 -07:00
Kubernetes Prow Robot bf770beb28 Merge pull request #32744 from my-git9/pod-lifecycle
[zh]Update pod-lifecycle.md
2022-04-04 02:54:12 -07:00
koushik-ms 9b9e56f5de fix typo in template for glossary reference
Link to glossary term "ConfigMap" didn't render correctly due to
a missing "{" at the beginning of template. This commit fixes it.
2022-04-04 11:53:55 +02:00
Kubernetes Prow Robot 51354ee826 Merge pull request #32733 from my-git9/pod-overhead1
[zh] Update pod-overhead.md
2022-04-04 02:46:10 -07:00
Yu.Baizhong 77de2d6714 docs: sync ephermeral-volumes.md (#32716) 2022-04-04 02:44:10 -07:00
xin.li ca7e5dac3b [zh] Update kubeadm-init-phase.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-04 17:19:28 +08:00
xin.li e7f92e51d4 [zh] Update admission-controllers.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-04 17:08:15 +08:00
xin.li 48b5e2b898 [zh] Update authorization.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-04 16:56:51 +08:00
xin.li 0844572daf [zh]Update pod-lifecycle.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-04 16:53:11 +08:00
Kubernetes Prow Robot b3b7a184e0 Merge pull request #32698 from Arhell/add-link
[ja] add Kopf framework to list
2022-04-03 18:56:10 -07:00
Kubernetes Prow Robot 134bcbe014 Merge pull request #32741 from ankita-shirodkar/patch-3
Updating Kubernetes Overview page
2022-04-03 18:04:10 -07:00
Ankita Shirodkar 043121abdf Updating Kubernetes Overview page
In alignment with the CNCF Style Guide, proposing a change from open-source to open source.
2022-04-04 01:15:48 +05:30
Tim Bannister ba81191440 Fix typo
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-04-03 19:24:23 +01:00
xin.li f1590c4ff4 [zh] Update pod-overhead.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-03 21:50:22 +08:00
kyle 6a7812967e fixed typo. 2022-04-03 20:49:49 +08:00
Tim Bannister afe13e859a (Further) update Container Runtmes to prepare for dockershim removal 2022-04-03 12:31:25 +01:00
Kubernetes Prow Robot 7f784112cd Merge pull request #32736 from 0xff-dev/main
[zh] update run-replicated-stateful-application.md
2022-04-03 03:42:11 -07:00
Kubernetes Prow Robot ce94db14bf Merge pull request #32735 from my-git9/ingress
[zh] Update volumes.md
2022-04-03 03:40:09 -07:00
0xff-dev e10ed9ee49 [zh] update run-replicated-stateful-application.md 2022-04-03 17:57:50 +08:00
xin.li 6b9727e6eb [zh] Update volumes.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-03 16:33:14 +08:00
Kubernetes Prow Robot fe8b412ee1 Merge pull request #31063 from KobayashiD27/translate-docs/architecture/gc
[ja] Translate docs/concepts/architecture/garbage-collection into Japanese
2022-04-02 20:14:09 -07:00
Kubernetes Prow Robot 31e231de62 Merge pull request #32729 from my-git9/ephemeral-volumes
[zh]Update ephemeral-volumes.md
2022-04-02 16:24:09 -07:00
Arhell fe3ef9d9bf [ja] simplify commands 2022-04-03 00:51:32 +03:00
xin.li 54c1b88505 [zh]Update ephemeral-volumes.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-02 21:26:26 +08:00
Kubernetes Prow Robot 09f753c4c1 Merge pull request #32730 from my-git9/safely-drain-node
[zh]Update safely-drain-node.md
2022-04-02 05:26:09 -07:00
Kubernetes Prow Robot 235220a095 Merge pull request #32727 from my-git9/resever-compute-resources
[zh] Update resever-compute-resources.md
2022-04-02 05:12:09 -07:00
Kubernetes Prow Robot 03345eba34 Merge pull request #32725 from my-git9/configmap1
[zh]Update configmap
2022-04-02 05:10:09 -07:00
Kubernetes Prow Robot 8504801db7 Merge pull request #32714 from zaunist/docs/concepts/controlling-access
[zh]: Resync controlling-access.md
2022-04-02 05:08:09 -07:00
xin.li c8bb212381 [zh]Update safely-drain-node.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-02 20:01:36 +08:00
xin.li d0496c7c7b [zh] Update resever-compute-resources.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-02 19:41:42 +08:00
xin.li 0e2c67d5d0 [zh]Update configmap
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-02 19:06:09 +08:00
Sohan Kr Choudhary 3a3961a87d Update horizontal-pod-autoscale-walkthrough.md
Fix missing closing parentheses
2022-04-02 16:22:29 +05:30
阿杰鲁 495e22ec49 docs: Resync controlling-access.md 2022-04-02 17:58:45 +08:00
Kubernetes Prow Robot d4a878d2d7 Merge pull request #32706 from my-git9/pod-security-standards
[zh]Update PodSecurityPolicy address in dir security
2022-04-02 02:06:09 -07:00
Kubernetes Prow Robot 5f3c97667a Merge pull request #32707 from zaunist/docs/concepts_configmap.md
[zh]: Resync concepts/configmap.md
2022-04-02 02:02:09 -07:00
Kubernetes Prow Robot cb3050ce32 Merge pull request #32710 from zaunist/docs/concepts_kubeconfig
[zh]: Resync organizs-cluster-access-kubeconfig.md
2022-04-02 02:00:09 -07:00
xin.li 004510c057 Update PodSecurityPolicy address in dir security
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-02 16:21:41 +08:00
阿杰鲁 8ab6120d12 docs: Resync configmap.md 2022-04-02 14:29:54 +08:00
Arhell b4803b77ce [id] remove link 2022-04-02 09:27:17 +03:00
阿杰鲁 ea3b2874a2 docs: Resync kubeconfig docs 2022-04-02 14:21:20 +08:00
Cheng Wang 82456a84de Update quality-service-pod.md
Update `Burstable` conditions
2022-04-02 13:09:56 +08:00
Kubernetes Prow Robot bd609bacb6 Merge pull request #32709 from my-git9/security-contex
[zh] Update  security-context.md
2022-04-01 21:36:10 -07:00
xin.li c448a308cd [zh] Update security-context.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-02 11:41:54 +08:00
Kubernetes Prow Robot 2a8ac31e2a Merge pull request #32218 from tengqm/zh-leader-mig
[zh] Tweak controller manager leader migration
2022-04-01 20:30:09 -07:00
Mitesh Jain cea33bb349 Add information about InTreePluginAzureFileUnregister and InTreePluginAzureDiskUnregister. 2022-04-01 19:30:20 +05:30
Kubernetes Prow Robot ea0d0327c9 Merge pull request #32618 from Tellz777/typos
[ru] Make some small fixes
2022-04-01 05:52:46 -07:00
Kubernetes Prow Robot 5018ca2d10 Merge pull request #32701 from mengjiao-liu/fix-finalizers
[zh]Fix translation of finalizers.md
2022-04-01 05:14:45 -07:00
Qiming Teng 1456dc3fdb [zh] Tweak controller manager leader migration
The existing translation has some nits to be fixed.
2022-04-01 20:11:07 +08:00
Mengjiao Liu be05380bf2 [zh]Fix translation of finalizers.md 2022-04-01 19:50:18 +08:00
Kubernetes Prow Robot f446e318ff Merge pull request #32635 from tengqm/zh-resync-working-with-objs
[zh] Resync pages under working-with-objects
2022-04-01 04:32:48 -07:00
Kubernetes Prow Robot 8f3d4134f1 Merge pull request #32640 from tengqm/zh-logs
[zh] Resync system-logs
2022-04-01 04:20:47 -07:00
Kubernetes Prow Robot abd287207f Merge pull request #32699 from my-git9/pod-security-admission1
[zh] Update pod-security-admission.md
2022-04-01 04:06:48 -07:00
xin.li 07a430e1aa [zh] Update pod-security-admission.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-04-01 17:48:41 +08:00
Kubernetes Prow Robot a3cc62677a Merge pull request #32095 from tengqm/zh-i18n-feature
[zh] Translate 'feature_state' string data
2022-04-01 01:40:46 -07:00
Kubernetes Prow Robot 701d0f82d5 Merge pull request #32682 from mengjiao-liu/add-sig-docs-zh-owners
Add mengjiao-liu to sig-doc-zh-owners
2022-04-01 01:14:46 -07:00
Mengjiao Liu 3e34a71a57 Add mengjiao-liu to sig-doc-zh-owners. 2022-04-01 15:52:43 +08:00
Kobayashi Daisuke caf4fd1c62 Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-01 15:40:41 +09:00
Kobayashi Daisuke 27456336a4 Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-01 15:40:35 +09:00
Kobayashi Daisuke 4e5265c6a6 Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-01 15:40:28 +09:00
Kobayashi Daisuke 3d73628432 Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-01 15:40:13 +09:00
Fernando Ripoll 8a58d35c10 Update pod-topology-spread-constraints.md 2022-04-01 07:57:04 +02:00
Arhell aff60f44b4 [ja] add Kopf framework to list 2022-04-01 08:52:11 +03:00
Tim Rosenblatt f16c446d0a Explain Service without selector is for non-Pod backends (#32602)
* Minor edit for clarity

The previous phrasing didn't emphasize the point that the reason you define a Service with no selectors is to point to a backend that's not a Pod, and the emphasis on the external nature of the backend

* Add note that Services w/o selectors, but +Endpoints is the technique to use for abstracting external backends

Co-authored-by: Rey Lejano <rlejano@gmail.com>

Co-authored-by: Rey Lejano <rlejano@gmail.com>
2022-03-31 22:40:37 -07:00
Kubernetes Prow Robot 74c12d3bca Merge pull request #32643 from j9t/patch-1
docs: correct capitalization, add hyphenation, remove double spaces
2022-03-31 22:38:37 -07:00
Kobayashi Daisuke 020a6aa13a Update content/ja/docs/concepts/services-networking/topology-aware-hints.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-01 14:36:55 +09:00
Kobayashi Daisuke a86a5c6511 Update content/ja/docs/concepts/services-networking/topology-aware-hints.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-04-01 14:36:48 +09:00
Kubernetes Prow Robot 23cc4de865 Merge pull request #32690 from rkatti/patch-1
Added retry option to tail
2022-03-31 22:34:39 -07:00
KobayashiD27 bbe4711b75 fix links and translations 2022-04-01 13:50:36 +09:00
Kubernetes Prow Robot 94999c0031 Merge pull request #32233 from tengqm/zh-cfg-sa
[zh] Resync configure service account
2022-03-31 20:46:37 -07:00
Kobayashi Daisuke bdca2ccb0c Update garbage-collection.md 2022-04-01 12:42:20 +09:00
Kubernetes Prow Robot e94ce37cc2 Merge pull request #32671 from zaunist/docs/concepts
[zh] Resync device-plugins
2022-03-31 17:40:38 -07:00
Kubernetes Prow Robot b53955eed4 Merge pull request #32628 from waynerv/patch-3
Update pod-security-admission.md
2022-03-31 14:43:07 -07:00
Kubernetes Prow Robot 27684b7e90 Merge pull request #32565 from vaibhav2107/sec-context
Update the doc regarding outdated info in the link
2022-03-31 14:41:05 -07:00
Fernando Ripoll eb33931ae3 Update pod-topology-spread-constraints.md 2022-03-31 22:30:06 +02:00
Raghu Katti 1c418bddd2 Added retry option to tail
If the logs get rotated the above tail would fail. -F ensures that it is logrotate proof.
2022-03-31 13:08:23 -04:00
Kubernetes Prow Robot ba8e9f14ae Merge pull request #32686 from reylejano/fix-link-blog
Fix link on blog
2022-03-31 09:23:02 -07:00
Kubernetes Prow Robot 9cfd2a51c5 Merge pull request #32674 from tengqm/fix-32292
[zh] Fix a link issue on the logging page
2022-03-31 08:57:00 -07:00
Rey Lejano dc3425b79c fix link on blog 2022-03-31 08:55:14 -07:00
阿杰鲁 fd9b3076be docs: sync Chinese translation
docs: fix review

fix: review
2022-03-31 21:38:51 +08:00
Qiming Teng ea26b67f98 [zh] Resync configure service account 2022-03-31 21:16:07 +08:00
Qiming Teng 9fd0199a20 [zh] Resync system-logs 2022-03-31 20:29:40 +08:00
Kubernetes Prow Robot 285dd5711a Merge pull request #32679 from my-git9/patch-4
[zh] Update pod-topology-spread-constraints.md
2022-03-31 05:27:01 -07:00
Kubernetes Prow Robot b6e3a1f78b Merge pull request #32680 from my-git9/extend-kubernetes_index
Extend kubernetes index
2022-03-31 05:25:01 -07:00
196Ikuchil db65b54571 fix:weight & some links 2022-03-31 21:21:43 +09:00
xin.li 99bf6b71cd --amend
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-31 19:48:06 +08:00
xin.li 5618f29eb8 [zh] Update extend-kubernetes/_index.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-31 19:44:19 +08:00
my-git9 421eb9a5cb Update pod-topology-spread-constraints.md 2022-03-31 19:37:15 +08:00
my-git9 f3c202fca2 [zh] Update pod-topology-spread-constraints.md
Correct wrong syntax
2022-03-31 18:17:11 +08:00
Qiming Teng 4e05e9ff5b [zh] Fix a link issue on the logging page 2022-03-31 14:19:45 +08:00
Kubernetes Prow Robot 70dbc89f33 Merge pull request #32283 from PriyanshuAhlawat/adding_auditing
Update controlling-access.md issue-32224
2022-03-30 20:44:59 -07:00
Kubernetes Prow Robot 9d902a23e8 Merge pull request #32004 from jihoon-seo/220302_Translate_ephemeral-volumes
[ko] Translate 'Ephemeral Volumes'
2022-03-30 20:11:00 -07:00
Kubernetes Prow Robot ffa959f7f4 Merge pull request #31761 from jihoon-seo/220216_Outdated_M25-M39
[ko] Update outdated files in `dev-1.23-ko.2` (M25-M39)
2022-03-30 20:07:00 -07:00
Priyanshu Ahlawat e62d2f7302 Update content/en/docs/concepts/security/controlling-access.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-03-31 08:30:44 +05:30
Kubernetes Prow Robot beb21b60c2 Merge pull request #32641 from twilight0620/blog1
[zh] Translate blog Securing-Admission-Controllers-2022.1.19
2022-03-30 19:17:00 -07:00
Kobayashi Daisuke 184e0f7fb3 Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-31 11:05:41 +09:00
Kobayashi Daisuke e48418a83a Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-31 11:05:36 +09:00
Kobayashi Daisuke cabd7e09c4 Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-31 11:05:30 +09:00
Kobayashi Daisuke 13b70f272b Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-31 11:05:16 +09:00
Kobayashi Daisuke 12ca7076fe Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-31 11:05:03 +09:00
Kobayashi Daisuke 1af7a3a9ca Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-31 11:04:52 +09:00
Kobayashi Daisuke 657bb6d5f1 Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-31 11:04:40 +09:00
Kobayashi Daisuke bbddf8c0f2 Update content/ja/docs/concepts/architecture/garbage-collection.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-31 11:04:33 +09:00
twilight0620 25c9403bf3 [zh] comments modify 2022-03-31 09:59:04 +08:00
Kubernetes Prow Robot e6d999c311 Merge pull request #32122 from Shubham82/update_Feature_state_NamespaceDefaultLabelName
Improvement: Updated FEATURE STATE of NamespaceDefaultLabelName.
2022-03-30 18:41:00 -07:00
Kubernetes Prow Robot 59baf2fff2 Merge pull request #32661 from guettli/patch-5
typo: "the" --> "then"
2022-03-30 17:43:00 -07:00
Kubernetes Prow Robot 226abdf52d Merge pull request #32666 from sftim/20220330_fixup_cri-dockerd_task
Fixup incorrect systemctl command
2022-03-30 14:53:57 -07:00
Kubernetes Prow Robot 2258bc2308 Merge pull request #32637 from guettli/patch-4
Link to Guaranteed pods
2022-03-30 14:51:57 -07:00
Tim Bannister 3cb2b0cb14 Fixup incorrect systemctl command
The subcommand for restart is "restart"
2022-03-30 22:26:12 +01:00
Kubernetes Prow Robot 994f5c5a48 Merge pull request #32131 from shannonxtreme/dockershim-migrate-dockerd
Add content for migrating to cri-dockerd
2022-03-30 14:09:57 -07:00
Thomas Güttler 8df0736acb typo: "the" --> "then"
fixed typo
2022-03-30 21:03:48 +02:00
Thomas Güttler 998d762331 S/'Guaranteed'/Guaranteed 2022-03-30 20:52:00 +02:00
Thomas Güttler 16ae848701 Link to 'Guaranteed' pods.
related to #32619
2022-03-30 20:52:00 +02:00
Kubernetes Prow Robot e047c71b9b Merge pull request #31276 from sftim/20220110_move_pod_security_policy
Move PSP into Security concepts section
2022-03-30 11:46:20 -07:00
Kubernetes Prow Robot 8134e9ca3e Merge pull request #32307 from PriyanshuAhlawat/version_skew_doc
create-cluster-kubeadm: update the version skew policy
2022-03-30 09:42:25 -07:00
Kubernetes Prow Robot b356cda5ea Merge pull request #32651 from miteshskj/pod-topology-review
Remove stale note about EvenPodsSpread
2022-03-30 09:36:25 -07:00
Priyanshu Ahlawat 1f25824e05 Update content/en/docs/setup/production-environment/tools/kubeadm/create-cluster-kubeadm.md
Co-authored-by: Stefan Büringer <4662360+sbueringer@users.noreply.github.com>
2022-03-30 22:01:29 +05:30
Tim Bannister 672813f3e7 Move PSP into Security concepts section
The logical navigation definitely works better if Pod Security admission
and PodSecurityPolicy are pages in the same section. Make It So.

Co-authored-by: Rey Lejano <rlejano@gmail.com>
2022-03-30 17:30:35 +01:00
tidusete 64da6792e9 Missunderstood pods/pod-with-node-affinity.yaml
Either we correct the code from pods/pod-with-node-affinity.yaml to match the description about the rules that apply or we correct the description in order to match the pods/pod-with-node-affinity.yaml
2022-03-30 18:01:59 +02:00
Mitesh Jain f0e4a10636 Remove note for unsupported version. 2022-03-30 21:24:51 +05:30
Kubernetes Prow Robot 7523b0f253 Merge pull request #31745 from KoditkarVedant/update-hyperlinks-to-point-to-main-branch-ja-local
[ja] Update hyperlinks to point to main branch
2022-03-30 08:06:25 -07:00
Kubernetes Prow Robot 7512a26e91 Merge pull request #32647 from jpc/patch-1
Added a link to the SocketCAN device plugin
2022-03-30 07:52:26 -07:00
Wang ea3bdee54f add index.md (#31362) 2022-03-30 07:48:25 -07:00
Kubernetes Prow Robot c4da96a605 Merge pull request #32581 from 196Ikuchil/Pod-Security-Admission
[ja] Translate concepts/security/pod-security-admission/ into Japanese
2022-03-30 07:30:26 -07:00
Kubernetes Prow Robot 3a486bf1ba Merge pull request #32649 from ggallon/patch-1
[fr] Incorrect spaces in paragraph to deploy-intro tutorial page
2022-03-30 06:06:25 -07:00
Gwenaël Gallon dd5fd20fb0 Merge branch 'kubernetes:main' into patch-1 2022-03-30 14:30:40 +02:00
Jakub Piotr Cłapa 26716d7326 Added a link to the SocketCAN device plugin 2022-03-30 13:18:11 +02:00
Kubernetes Prow Robot 4fe8c26186 Merge pull request #32574 from luolanzone/fix-typo
[zh]Remove extra double quotation mark
2022-03-30 04:00:27 -07:00
196Ikuchil 3bc2141575 fix:_exemptions_ 2022-03-30 18:52:22 +09:00
twilight0620 f8c9721c52 [zh] comments modify 2022-03-30 17:51:19 +08:00
196Ikuchil 1df046ce08 fix:typo 2022-03-30 18:46:32 +09:00
196Ikuchil fce303bf3b fix:pluralization 2022-03-30 18:46:15 +09:00
Kubernetes Prow Robot b8bdb15985 Merge pull request #32627 from liutaot/patch-3
Update custom-resources.md
2022-03-30 02:40:25 -07:00
196Ikuchil c112afaba2 fix:heading 2022-03-30 18:39:34 +09:00
Yu.Bozhong 0561eaa17a [zh] Resync kubectl-convert-overview (#32642)
* docs: update translation

* Update content/zh/docs/tasks/tools/included/kubectl-convert-overview.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-03-30 02:18:25 -07:00
liutao f90ea705c9 Update custom-resources.md 2022-03-30 17:07:56 +08:00
Jens Oliver Meiert 67c726ef45 docs: correct capitalization, add hyphenation, remove double spaces 2022-03-30 10:51:47 +02:00
Kubernetes Prow Robot 264701a019 Merge pull request #32440 from sarazqy/main
[zh] Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese
2022-03-30 01:36:26 -07:00
twilight0620 c33389c974 [zh] Translate blog Securing-Admission-Controllers-2022.1.19 2022-03-30 16:26:59 +08:00
Qiming Teng 5d231f1774 Add ServerSideFieldValidation feature gate
It turns out the feature was not documented for 1.23.
2022-03-30 16:09:06 +08:00
zqy 44ec983b19 Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese
Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese

Translate /blog/2022/02/16/sig-node-ci-subproject-celebrates/ page into Chinese
2022-03-30 14:19:41 +08:00
Qiming Teng 6f7ee0ca7d [zh] Resync pages under working-with-objects 2022-03-30 14:07:05 +08:00
Kubernetes Prow Robot 9b9ac3a458 Merge pull request #32609 from my-git9/pod-configmap-env-var-valueFrom
[zh]Pod configmap env var value from
2022-03-29 22:34:27 -07:00
Kubernetes Prow Robot c0eef74a22 Merge pull request #32633 from my-git9/kubelet-tls-bootstrapping
[zh] Update kubelet-tls-bootstrapping.md
2022-03-29 21:52:26 -07:00
Kubernetes Prow Robot e7a52eb75a Merge pull request #32632 from my-git9/authentication-0
[zh] Update authentication.md
2022-03-29 21:50:27 -07:00
Kubernetes Prow Robot a5f3becde3 Merge pull request #32629 from my-git9/garbage-collection
[zh] Update garbage-collection
2022-03-29 21:48:27 -07:00
Kubernetes Prow Robot ed79e82359 Merge pull request #32631 from my-git9/projected-volumes
[zh] Update projected-volumes.md
2022-03-29 21:42:24 -07:00
Kubernetes Prow Robot 14cbd8b2f5 Merge pull request #32630 from my-git9/manage-resources-containers
[zh]Update manage-resources-containers.md
2022-03-29 21:40:24 -07:00
xin.li b25f4761a8 [zh] Update kubelet-tls-bootstrapping.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-30 12:26:31 +08:00
xin.li 1905b25b89 [zh] Update authentication.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-30 12:24:19 +08:00
xin.li 74449d1459 [zh] Update projected-volumes.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-30 12:15:19 +08:00
xin.li 8966e293a0 [zh]Update manage-resources-containers.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-30 11:29:57 +08:00
Kubernetes Prow Robot d784e24c88 Merge pull request #32612 from my-git9/baseline-psp
[zh] Update restricted-psp.yaml
2022-03-29 19:32:25 -07:00
xin.li 7f782da3b7 [zh] Update garbage-collection
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-30 10:20:55 +08:00
Waynerv adde98e681 Update pod-security-admission.md
No need to use the ssh protocol to access a public repository
2022-03-30 10:13:53 +08:00
xin.li 7b7b8d2d5c [zh] Update restricted-psp.yaml
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-30 10:09:59 +08:00
Kubernetes Prow Robot 9b411cb71d Merge pull request #32620 from chuckha/volume-typo
Removes a space that breaks a markdown link
2022-03-29 14:40:06 -07:00
Chuck Ha e611a04e6d Removes a space that breaks a markdown link
Signed-off-by: Chuck Ha <chuckh@twitter.com>
2022-03-29 12:56:15 -07:00
Kubernetes Prow Robot 2457eac448 Merge pull request #32584 from CharlesCZ/patch-1
fix typo
2022-03-29 10:36:55 -07:00
Cezary Czekalski 5650e76c45 Fix typo 2022-03-29 19:27:32 +02:00
Ilya Z 1e64ac5da9 ru_small_fixes 2022-03-29 21:10:06 +04:00
Kubernetes Prow Robot 7dc9feccef Merge pull request #32383 from edithturn/add-storage-limits
[es] Add content/es/docs/concepts/storage/storage-limits.md
2022-03-29 09:54:56 -07:00
Mitesh Jain 7580383a7d Reflect the changed behaviour for multiple use of --from-env-file in ConfigMap creation (#32603)
* Fix 32392 - Reflect the changed behaviour for multiple from-env-file in configmap creation.

* Update content/en/docs/tasks/configure-pod-container/configure-pod-configmap.md

updated suggestions.

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-03-29 06:48:46 -07:00
Kubernetes Prow Robot 4edd7fa89e Merge pull request #32614 from my-git9/zookeeper-pod-disruption-budget-minavailable
[zh] Update zookeeper-pod-disruption-budget-minavailable.yaml
2022-03-29 05:48:47 -07:00
Kubernetes Prow Robot e9b915be99 Merge pull request #32613 from my-git9/baseline-psp1
[zh] Update baseline-psp.yaml
2022-03-29 05:44:47 -07:00
xin.li cde6f321b2 [zh] Update zookeeper-pod-disruption-budget-minavailable.yaml
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 19:56:50 +08:00
Kubernetes Prow Robot 85f4570807 Merge pull request #32610 from my-git9/zookeeper-pod-disruption-budget-maxunavailable
[zh] Update zookeeper-pod-disruption-budget-maxunavailable.yaml
2022-03-29 04:56:46 -07:00
xin.li 6ef4d46143 [zh] Update baseline-psp.yaml
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 19:54:49 +08:00
xin.li ee0d8a0b27 [zh] Update zookeeper-pod-disruption-budget-maxunavailable.yaml
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 19:29:43 +08:00
my-git9 fb58df71c6 Merge branch 'kubernetes:main' into pod-configmap-env-var-valueFrom 2022-03-29 19:02:58 +08:00
xin.li 41336b8c06 [zh] Update pod-configmap-env-var-valueFrom.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 19:01:46 +08:00
Kubernetes Prow Robot bfca5b112f Merge pull request #32605 from my-git9/cluster-intro.md
[zh]Update  cluster-intro.md
2022-03-29 04:00:47 -07:00
Kubernetes Prow Robot 5fe595f833 Merge pull request #32607 from my-git9/cluster-level-pss
[zh] Update cluster-level-pass.md
2022-03-29 03:58:47 -07:00
Kubernetes Prow Robot 573f11d412 Merge pull request #32608 from my-git9/pod-configmap-env-var-valueFrom
[zh] Update pod-configmap-env-var-valueFrom.md
2022-03-29 03:54:47 -07:00
xin.li df4728f9cd [zh] Update pod-configmap-env-var-valueFrom.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 18:30:34 +08:00
xin.li 200f5f5e4c [zh] Update cluster-level-pass.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 17:52:33 +08:00
196Ikuchil 138c15205d fix:change Podセキュリティのアドミッション to Podのセキュリティアドミッション 2022-03-29 18:51:24 +09:00
196Ikuchil 2cdd9e9db4 Update content/ja/docs/reference/scheduling/policies.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-03-29 18:28:12 +09:00
196Ikuchil f1ae421043 Update content/ja/docs/reference/scheduling/policies.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-03-29 18:28:06 +09:00
196Ikuchil 550bfd5391 Update content/ja/docs/reference/scheduling/policies.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-03-29 18:28:00 +09:00
Kubernetes Prow Robot 9e9e65bf93 Merge pull request #32586 from Tellz777/small-fix
[ru] Fix typos
2022-03-29 00:48:47 -07:00
xin.li 62c4ddc8f6 [zh]Update cluster-intro.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 15:35:59 +08:00
Kubernetes Prow Robot 0ec1eef9d6 Merge pull request #32559 from tengqm/zh-resync-secret
[zh] Resync secret
2022-03-29 00:17:11 -07:00
Kubernetes Prow Robot 18db072a0e Merge pull request #32601 from my-git9/create-cluster_index.md
[zh] update create-cluster_index.md
2022-03-29 00:09:11 -07:00
xin.li 047966418e [zh] update create-cluster_index.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 14:19:16 +08:00
Kubernetes Prow Robot ae9e22bd71 Merge pull request #32600 from my-git9/optional-kubectl-configs-zsh
[zh] Update optional-kubectl-configs-zsh.md
2022-03-28 22:41:11 -07:00
Kubernetes Prow Robot 770e97a203 Merge pull request #31881 from jihoon-seo/220224_Outdated_M74
[ko] Update outdated files in `dev-1.23-ko.2` (M74-M85)
2022-03-28 22:15:11 -07:00
xin.li 849eed7d0a [zh] Update optional-kubectl-configs-zsh.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-29 12:26:07 +08:00
Qiming Teng dd29e003dd [zh] Resync secret 2022-03-29 09:32:11 +08:00
Kubernetes Prow Robot 6795e63579 Merge pull request #32591 from sftim/20220328_fix_dockershim_alias
Remove incorrect /dockershim alias
2022-03-28 16:11:41 -07:00
Tim Bannister fb3db4db2b Remove incorrect /dockershim alias
This fixes up a previous, inadvertent mistake where the alias was
retained during localization.
2022-03-28 23:47:19 +01:00
Kubernetes Prow Robot e1b941a1da Merge pull request #32590 from sftim/2022-328_fix_dockershim_alias
Remove incorrect /dockershim alias
2022-03-28 15:41:42 -07:00
Kubernetes Prow Robot 1336c6461f Merge pull request #32150 from tengqm/tune-feature-gates
Tune the feature gates page
2022-03-28 15:31:41 -07:00
Tim Bannister 5ff402c477 Remove incorrect /dockershim alias
This fixes up a previous, inadvertent mistake where the alias was
retained during localization.
2022-03-28 23:08:25 +01:00
Kubernetes Prow Robot db02b0c3f1 Merge pull request #32575 from miteshskj/tls-bootstrap-token
Remove bootstrap token being in beta state in kubelet-tls-bootstrappi…
2022-03-28 14:45:43 -07:00
Kubernetes Prow Robot 8f3fcc0542 Merge pull request #32576 from bobcode99/patch-1
Update horizontal-pod-autoscale.md
2022-03-28 14:27:42 -07:00
Ilya Z abab541c57 small_fix 2022-03-28 23:40:05 +04:00
Kubernetes Prow Robot 1cc768a796 Merge pull request #32578 from miteshskj/brokenlink-gc-csr
Fix broken link for stale CSR clean up in garbage-collection.md
2022-03-28 11:15:30 -07:00
Kubernetes Prow Robot 4f3244804c Merge pull request #32557 from bngsudheer/patch-1
Minor text edit to correct the grammar and presentation
2022-03-28 10:09:32 -07:00
196Ikuchil 273271bbef add:translate concepts/security/pod-security-admission.md 2022-03-29 01:02:17 +09:00
Mitesh Jain a76cc64203 Fix broken link for stale CSR clean up in garbage-collection.md 2022-03-28 20:53:39 +05:30
Bob 5183202a3b Update horizontal-pod-autoscale.md
Update HPA V2, custom.metrics.k8s.io, external.metrics.k8s.io design proposals to archive github link.
2022-03-28 22:36:36 +08:00
Mitesh Jain d21c4302bc Remove bootstrap token being in beta state in kubelet-tls-bootstrapping.md 2022-03-28 19:17:39 +05:30
Lan Luo a4196f77f5 Fix extra double quotation mark
Signed-off-by: Lan Luo <luolanzone@gmail.com>
2022-03-28 21:17:12 +08:00
196Ikuchil a3ab2f3412 fix:parameter name 2022-03-28 22:09:56 +09:00
Kubernetes Prow Robot df12f23ec4 Merge pull request #32519 from howieyuen/ref_api_common_resource_field_selector
[zh]translate content/docs/reference/kubernetes-api/common-definition…
2022-03-28 05:55:23 -07:00
howieyuen 1698664aed [zh]translate content/docs/reference/kubernetes-api/common-definitions/resource-field-selector.md into Chinese 2022-03-28 20:18:39 +08:00
Kubernetes Prow Robot 47df22358a Merge pull request #32571 from my-git9/install-kubectl
[zh] Update install-kubectl-windows.md
2022-03-28 04:21:24 -07:00
Kubernetes Prow Robot faffa177ea Merge pull request #32518 from howieyuen/ref_api_common_quantity
[zh]translate content/docs/reference/kubernetes-api/common-definition…
2022-03-28 04:13:23 -07:00
Kubernetes Prow Robot c1b2b7cb19 Merge pull request #32521 from zhangxyjlu/dual_stack_networking_ga
[zh]Add 2021-12-08-dual-stack-networking-ga.md
2022-03-28 03:35:23 -07:00
howieyuen b765f0fee6 [zh]translate content/docs/reference/kubernetes-api/common-definitions/quantity.md into Chinese 2022-03-28 18:33:37 +08:00
Kubernetes Prow Robot e943d03de6 Merge pull request #31724 from Arhell/audit-upd
[ja] update audit.md
2022-03-28 03:33:23 -07:00
Kubernetes Prow Robot d02938ed6d Merge pull request #32476 from jihoon-seo/220325_Update_links_2
[ko] Update links in `dev-1.23-ko.2`
2022-03-28 02:37:23 -07:00
Kubernetes Prow Robot c66d4a34cc Merge pull request #32522 from zhangxyjlu/meet_our_contributors
[zh]Add 2022-03-15-meet-our-contributors-APAC-AU-NZ-region-01.md
2022-03-28 02:01:22 -07:00
xin.li 03926364b5 [zh] Update install-kubectl-windows.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-28 16:29:17 +08:00
Kubernetes Prow Robot 9c7f14d19f Merge pull request #32556 from Tellz777/minor_changes
kubectl_docs_fixes
2022-03-28 00:17:22 -07:00
Kubernetes Prow Robot 15803d6273 Merge pull request #32555 from Tellz777/cheatsheet
cheatsheet_fixes
2022-03-28 00:15:22 -07:00
Kubernetes Prow Robot d1440af53c Merge pull request #32551 from Tellz777/advanced_md
advanced_guide_edited
2022-03-28 00:13:22 -07:00
Kubernetes Prow Robot 9e1840fe3c Merge pull request #32550 from Tellz777/content-guide
Edited content-guide.
2022-03-28 00:11:22 -07:00
Kubernetes Prow Robot f5bc7d5df0 Merge pull request #32548 from Tellz777/kube_api
kube_api_typos
2022-03-28 00:09:22 -07:00
Kubernetes Prow Robot 454a196424 Merge pull request #32547 from Tellz777/addons_typos
Addons_doc_typos
2022-03-28 00:07:23 -07:00
zhangxiaoyang 99b0fce444 [zh]Add 2021-12-08-dual-stack-networking-ga.md 2022-03-28 15:04:40 +08:00
Kubernetes Prow Robot 597a3c0d5a Merge pull request #32546 from Tellz777/index_typos
cluster_admin_typos
2022-03-27 23:59:22 -07:00
Kubernetes Prow Robot 6d0094f72f Merge pull request #32545 from Tellz777/nodes_doc
fix_some_typos
2022-03-27 23:57:22 -07:00
Kubernetes Prow Robot e4d73f3e89 Merge pull request #32544 from Tellz777/gc_typos
gc_typos
2022-03-27 23:55:22 -07:00
Kubernetes Prow Robot 49af2ea5ff Merge pull request #32540 from Tellz777/cloud-controller
fix_cloud_controller
2022-03-27 23:53:23 -07:00
Kubernetes Prow Robot 484aeddb4b Merge pull request #32537 from Tellz777/translated_quote
translated_quote
2022-03-27 23:51:21 -07:00
Kubernetes Prow Robot fd9d199c68 Merge pull request #32538 from Tellz777/architecture_translate
arch_concept
2022-03-27 23:49:21 -07:00
Kubernetes Prow Robot e39b3e6d31 Merge pull request #32558 from tengqm/zh-resync-topology
[zh] Resync pod topology spread constraints page
2022-03-27 23:01:22 -07:00
zhangxiaoyang 8260ee0f42 [zh]Add 2022-03-15-meet-our-contributors-APAC-AU-NZ-region-01.md 2022-03-28 11:28:53 +08:00
Kubernetes Prow Robot 8b783129d3 Merge pull request #31912 from tengqm/zh-diagram-guide
[zh] Translate diagram guide page
2022-03-27 20:07:21 -07:00
Kubernetes Prow Robot 3e2e616983 Merge pull request #32562 from my-git9/access-api-from-pod
[zh] Update configure-pdb.md
2022-03-27 17:45:21 -07:00
Kubernetes Prow Robot b1f9801f16 Merge pull request #32560 from my-git9/update-daemon-set
[zh] Update update-daemon-set.md
2022-03-27 17:43:21 -07:00
Kubernetes Prow Robot a9273c9e20 Merge pull request #32561 from my-git9/update-api-object-kubectl-patch
[zh] Update update-api-object-kubectl-patch.md
2022-03-27 17:41:21 -07:00
Vaibhav fa8872f70f Update the doc regarding out of date link 2022-03-28 01:07:38 +05:30
xin.li 1e3943a6b1 [zh] Update configure-pdb.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-27 21:07:25 +08:00
xin.li 10ff885b1c [zh] Update update-api-object-kubectl-patch.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-27 21:02:03 +08:00
xin.li 27ba7df7b2 [zh] Update update-daemon-set.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-27 20:58:47 +08:00
Kubernetes Prow Robot b1438b718a Merge pull request #32553 from miteshskj/broken-link-labels
Fix broken link for attach labels in assign-pod-node.md
2022-03-27 05:43:21 -07:00
Qiming Teng f01be79f66 [zh] Resync pod topology spread constraints page 2022-03-27 19:43:59 +08:00
Kubernetes Prow Robot bda7bfab02 Merge pull request #32539 from shaggyyy2002/langugae
Incorrect or out of date script localization in init 容器 concept
2022-03-27 04:13:21 -07:00
Kubernetes Prow Robot 486cdc3f1e Merge pull request #32528 from my-git9/source-ip
[zh] Update source-ip.md
2022-03-27 04:07:21 -07:00
Kubernetes Prow Robot 5a98854672 Merge pull request #32527 from my-git9/install-kubectl-macos
[zh] Update install-kubectl-macos.md
2022-03-27 04:05:21 -07:00
Kubernetes Prow Robot 7c36d57a14 Merge pull request #32526 from my-git9/install-kubectl-linux
[zh] Update install-kubectl-linux.md
2022-03-27 04:03:20 -07:00
Kubernetes Prow Robot 7da2d15264 Merge pull request #32554 from my-git9/example-busybox
[zh] modify busybox to busybox:1.28 in dir examples
2022-03-27 04:01:21 -07:00
Kubernetes Prow Robot a5513faded Merge pull request #32524 from my-git9/parallel-processing-expansion
[zh] update parallel-processing-expansion.md
2022-03-27 03:59:21 -07:00
Sudheer Satyanarayana 81881f8d84 minor text edit
`Pay attention to the case of suffixes` seems better than `Take care about case for suffixes`
2022-03-27 16:01:25 +05:30
Ilya Z 482bfee980 kubectl_docs_fixes 2022-03-27 12:47:02 +04:00
Ilya Z 9a49299b4f cheatsheet_fixes 2022-03-27 12:20:37 +04:00
xin.li ed2ded76e3 [zh] modify busybox to busybox:1.28 in dir examples
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-27 15:22:18 +08:00
Mitesh Jain bf59d01af7 Fix broken link for attach labels in assign-pod-node.md 2022-03-27 12:26:44 +05:30
Edith Puclla 280104545a Update content/es/docs/concepts/storage/storage-limits.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2022-03-26 17:41:43 -05:00
Edith Puclla 01a210abdf Update content/es/docs/concepts/storage/storage-limits.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2022-03-26 17:41:19 -05:00
Edith Puclla b12f7e1ad3 Update content/es/docs/concepts/storage/storage-limits.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2022-03-26 17:39:03 -05:00
Edith Puclla 6c24e33f92 Update content/es/docs/concepts/storage/storage-limits.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2022-03-26 17:38:43 -05:00
Edith Puclla ecaffa667b Update content/es/docs/concepts/storage/storage-limits.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2022-03-26 17:38:28 -05:00
Edith Puclla 5bb9befe1c Update content/es/docs/concepts/storage/storage-limits.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2022-03-26 17:37:45 -05:00
Ilya Z 9f0afaf0c3 advanced_guide_edited 2022-03-27 01:41:03 +04:00
Ilya Z 6319b586d6 content-guide_fix 2022-03-27 01:03:40 +04:00
Kubernetes Prow Robot b68cfbd60a Merge pull request #32485 from tengqm/fix-ip-masq-agent
Fix the ip-masq-agent page
2022-03-26 13:21:21 -07:00
Ilya Z 6525c0cab5 kube_api_typos 2022-03-26 23:55:11 +04:00
Ilya Z 026b8773ff addons_typos 2022-03-26 23:40:25 +04:00
Ilya Z 0c259797db cluster_admin_typos 2022-03-26 23:18:08 +04:00
Kubernetes Prow Robot e58fca00fe Merge pull request #32543 from Tellz777/controller_md
fix_some_typos
2022-03-26 12:07:20 -07:00
Ilya Z 232c79f4e4 fix_some_typos 2022-03-26 23:03:46 +04:00
Ilya Z 510bd76dd7 gc_typos 2022-03-26 22:49:23 +04:00
Kubernetes Prow Robot 94c8a0b1b7 Merge pull request #32542 from Tellz777/control_plane
small_changes_to_docs
2022-03-26 11:47:21 -07:00
Ilya Z 48dc63e27f fix_some_typos 2022-03-26 22:37:48 +04:00
Ilya Z b761dd5cb2 small_changes_to_docs 2022-03-26 22:15:05 +04:00
Ilya Z a664033f69 fix_misspellings 2022-03-26 20:54:01 +04:00
shaggyyy2002 12d8e01ce9 Incorrect or out of date script localization in init 容器 concept #32466 2022-03-26 21:46:19 +05:30
Ilya Z 2139601101 arch_concept 2022-03-26 20:14:01 +04:00
Ilya Z accbd5ef66 translated_quote 2022-03-26 19:45:18 +04:00
Kubernetes Prow Robot 344f7c6d0b Merge pull request #32536 from Tellz777/fix-typo
fix_little_typo
2022-03-26 08:19:20 -07:00
Ilya Z b33b54b447 fix_little_typo 2022-03-26 19:04:14 +04:00
xin.li feb1cbed51 [zh] Update source-ip.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-26 22:50:18 +08:00
xin.li 6c4a40eff3 [zh] Update install-kubectl-macos.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-26 22:47:46 +08:00
xin.li c6c9ab547a [zh] Update install-kubectl-linux.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-26 22:40:05 +08:00
xin.li 26e080cc1f [zh] update parallel-processing-expansion.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-26 22:23:09 +08:00
Qiming Teng fc144300d6 [zh] Translate diagram guide 2022-03-26 21:42:21 +08:00
Kubernetes Prow Robot 47251f7dfc Merge pull request #32514 from reylejano/update-docs-owners
Update website owners aliases
2022-03-26 04:31:22 -07:00
Kubernetes Prow Robot ee6bd562c0 Merge pull request #31444 from tengqm/zh-configmap
[zh] Resync the configmap page
2022-03-26 02:13:21 -07:00
Kubernetes Prow Robot f6984542a0 Merge pull request #32087 from tengqm/zh-extend-index
[zh] Optimize k8s extension index page
2022-03-26 02:11:21 -07:00
Kubernetes Prow Robot b8920e5b08 Merge pull request #32498 from my-git9/enforce-standards-admission-controller
[zh] Update enforce-standards-admission-controller.md
2022-03-26 02:09:21 -07:00
Kubernetes Prow Robot 75c8a15234 Merge pull request #32517 from howieyuen/ref_api_common_patch
[zh]translate content/docs/reference/kubernetes-api/common-definition…
2022-03-26 00:49:20 -07:00
Kubernetes Prow Robot 77949e7382 Merge pull request #32516 from my-git9/troubleshooting
[zh] Update trobleshooting.md
2022-03-26 00:47:21 -07:00
Kubernetes Prow Robot 9f42eecb60 Merge pull request #32507 from my-git9/translate-compose-kubernetes.md
[zh] Update install-kubectl-macos.md
2022-03-26 00:45:20 -07:00
zhangxyjlu dd54580d17 [zh]Add 2021-12-16-StatefulSet-PVC-Auto-Deletion.md (#32492)
* [zh]Add 2021-12-16-StatefulSet-PVC-Auto-Deletion.md

* [zh]Add 2021-12-16-StatefulSet-PVC-Auto-Deletion.md

* [zh]Add 2021-12-16-StatefulSet-PVC-Auto-Deletion.md

* [zh]Add 2021-12-16-StatefulSet-PVC-Auto-Deletion.md
2022-03-26 00:43:20 -07:00
Kubernetes Prow Robot ed50e1bd6f Merge pull request #32236 from tengqm/zh-config-cfgmap
[zh] Update configure pod configmap
2022-03-26 00:41:20 -07:00
Kubernetes Prow Robot 2d3fc12c7b Merge pull request #32205 from tengqm/zh-coredns
[zh] Update coredns page
2022-03-26 00:39:21 -07:00
Kubernetes Prow Robot 46ff8f8922 Merge pull request #32097 from tengqm/zh-fix-networkpolicy
[zh] Fix translation of network policy index page
2022-03-26 00:37:21 -07:00
howieyuen 43efe8258a [zh]translate content/docs/reference/kubernetes-api/common-definitions/status.md into Chinese 2022-03-26 15:31:54 +08:00
howieyuen d6beaff60f [zh]translate content/docs/reference/kubernetes-api/common-definitions/patch.md into Chinese 2022-03-26 13:54:29 +08:00
xin.li d284aca7a4 [zh] Update trobleshooting.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-26 12:37:27 +08:00
Rey Lejano 4576b07883 update owners aliases 2022-03-25 18:24:50 -07:00
Kubernetes Prow Robot a98b05f558 Merge pull request #32506 from my-git9/readme
[zh] Update cncf-code-of-conduct/readme
2022-03-25 17:59:58 -07:00
Manish Kumar 8f8d9b215e Register and document some authz-related audit annotations (#32200)
* Registered audit annotation

* Update content/en/docs/reference/labels-annotations-taints/audit-annotations.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* fix.

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-03-25 17:25:58 -07:00
Subhasmita Swain 09f8637c05 sample outputs created working with Kubernetes v1.24 without docker (#31454)
* sample outputs created without docker working with kubernetes v1.24

* updated

* cleaned and updated

* sample outputs created without docker working with kubernetes v1.24

* updated

* cleaned and updated
2022-03-25 17:17:58 -07:00
Kubernetes Prow Robot 7de1f240a5 Merge pull request #31964 from jihoon-seo/220228_Translate_topology-aware-hints
[ko] Translate 'Topology Aware Hints'
2022-03-25 17:11:58 -07:00
Kubernetes Prow Robot 185512f752 Merge pull request #32000 from Kartik494/podsecuritypolicies
Added Pod security deprecation note
2022-03-25 15:47:58 -07:00
Kubernetes Prow Robot 39fd63ba12 Merge pull request #31989 from guettli/31930__fix_busybox_image_1.28
fix busybox image to version 1.28
2022-03-25 15:45:59 -07:00
Kubernetes Prow Robot 689417422e Merge pull request #32012 from bwolmarans/patch-1
--all-namespaces shorthand
2022-03-25 15:41:58 -07:00
Meha Bhalodiya a3660a0d76 feat: documenting serviceAccountToken volume type (#31329)
* feat: documenting serviceAccountToken volume type

* serviceAccountToken: correct few terms

* Update volumes.md

* Migrate to projected-volumes

* Update projected-volumes.md

* Remove serviceAccountToken from volume type

* Update projected-volumes.md

* Change heading's fragment identifier
2022-03-25 15:31:58 -07:00
Kubernetes Prow Robot 388a12af54 Merge pull request #28934 from atoato88/add-review-url-script
Add script for list URLs updated by target PR
2022-03-25 14:07:00 -07:00
Kubernetes Prow Robot 1dec188e52 Merge pull request #32501 from guresonur/patch-1
Update service.md
2022-03-25 13:41:58 -07:00
Kubernetes Prow Robot a55bc5584e Merge pull request #32486 from tengqm/leadership-migration-state
Fix feature state for ControllerLeaderMigration
2022-03-25 13:39:59 -07:00
Kubernetes Prow Robot 70bb3ee178 Merge pull request #32472 from lukashass/kubectl-install-sh
Use cat instead of shell built-in to read checksum
2022-03-25 13:27:58 -07:00
Kubernetes Prow Robot b91979ef89 Merge pull request #32494 from tengqm/remove-dup-content
Remove duplicated contents for accessing the API server
2022-03-25 13:19:59 -07:00
Kubernetes Prow Robot cafc3455a0 Merge pull request #32503 from my-git9/ingress-controllers
[zh] Update ingress-controllers
2022-03-25 09:23:58 -07:00
Shannon Kularathna 180fa82d9c Add draft content for migrating to dockerd 2022-03-25 15:19:17 +00:00
xin.li 5af719eac8 [zh] Update install-kubectl-macos.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-25 22:58:58 +08:00
xin.li bbe16c5e26 [zh] Update cncf-code-of-conduct/readme
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-25 22:43:30 +08:00
Kubernetes Prow Robot 27573dada6 Merge pull request #32502 from my-git9/daemonsetd
[zh] Update daemonset.md
2022-03-25 07:17:58 -07:00
xin.li 423e1ecc28 [zh] Update ingress-controllers
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-25 21:32:56 +08:00
xin.li d5fccd7c46 [zh] Update daemonset.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-25 21:28:57 +08:00
Onur fe86ff7ae8 Update service.md
http-web-service as a name for port is failing as it has more than 15 characters, hence the change to http-web-svc
2022-03-25 16:07:49 +03:00
Kubernetes Prow Robot c883ec32af Merge pull request #32468 from PriyanshuAhlawat/kube_proxy
Mark user-space kube-proxy as deprecated
2022-03-25 06:03:58 -07:00
Kubernetes Prow Robot 25767f9900 Merge pull request #32497 from my-git9/assign-memory-resource
[zh] Update assign-memory-resource.md
2022-03-25 05:59:58 -07:00
xin.li 035f0f493f [zh] Update enforce-standards-admission-controller.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-25 20:33:06 +08:00
xin.li 8a47855a77 [zh] Update assign-memory-resource.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-25 20:11:13 +08:00
PriyanshuAhlawat 70574cfdb0 Update service.md 2022-03-25 16:25:55 +05:30
Qiming Teng 58a00cfb36 Remove duplicated contents for accessing the API server
The topic of accessing the API server can be found in two places. This
is not good.
2022-03-25 18:48:27 +08:00
Gwenaël Gallon 28ae4d7809 [fr] fix spaces 2022-03-25 10:31:42 +01:00
Kubernetes Prow Robot 24aeb48d8a Merge pull request #32355 from yyyoungha/patch-2
[ko] Update incorrect expression dev-1.23-ko.2
2022-03-25 02:23:50 -07:00
Young Ha 66b414f0e2 [ko] Update incorrect expression in dev-1.23-ko.2
MaxUnavailable is calculated using the Ceil() function and MaxSurge using Floor() function.
2022-03-25 18:16:37 +09:00
Kubernetes Prow Robot 5328fdf797 Merge pull request #32489 from Arhell/zh-sync
[zh] sync storage-classes.md
2022-03-25 01:23:51 -07:00
Arhell 876a1d570c [zh] sync storage-classes.md 2022-03-25 09:59:41 +02:00
Kubernetes Prow Robot 8c2df852be Merge pull request #32161 from tengqm/zh-secure-cluster
[zh] Rework securing cluster page
2022-03-25 00:03:50 -07:00
Qiming Teng 2330573219 Merge branch 'main' into zh-secure-cluster 2022-03-25 14:41:11 +08:00
Jihoon Seo fcd5db6f41 [ko] Translate 'Topology Aware Hints' 2022-03-25 15:37:13 +09:00
Kubernetes Prow Robot 7720ef4bb8 Merge pull request #32182 from mattcary/patch-1
Update external provisioner specification reference in storage-classes.md
2022-03-24 23:25:50 -07:00
Kubernetes Prow Robot f5e8071030 Merge pull request #30588 from dialogbox/patch-2
Update certificates.md
2022-03-24 23:23:50 -07:00
Qiming Teng cfc613135f Fix feature state for ControllerLeaderMigration
The feature has been promoted to Beta in 1.22, according to
content/en/docs/tasks/administer-cluster/controller-manager-leader-migration.md
and upstream source.
2022-03-25 14:12:41 +08:00
Qiming Teng 3b21d5bc69 Fix the ip-masq-agent page 2022-03-25 14:02:40 +08:00
Kubernetes Prow Robot 3013adb039 Merge pull request #32015 from damyl4sure/patch-1
updated allowedTopologies values format
2022-03-24 22:51:50 -07:00
Kubernetes Prow Robot bfdb4647bd Merge pull request #31789 from Mikhail2048/patch-1
Add example of Service targetPort binding by name
2022-03-24 22:45:50 -07:00
Kubernetes Prow Robot 06b8c6c172 Merge pull request #28561 from jihoon-seo/210622_vi_Remove_exec_permission_on_markdown_files
[vi] Remove exec permission on markdown files
2022-03-24 22:43:50 -07:00
Kubernetes Prow Robot 587ddaf696 Merge pull request #31698 from jihoon-seo/220211_Outdated_M18-M24
[ko] Update outdated files in `dev-1.23-ko.2` (M18-M24)
2022-03-24 21:59:51 -07:00
Kubernetes Prow Robot 582a6a793b Merge pull request #32475 from jihoon-seo/220325_Update_links
[ko] Remove deprecated 'kubelet-garbage-collection' page
2022-03-24 21:53:50 -07:00
Kubernetes Prow Robot 0d37b034e7 Merge pull request #32464 from wansir/main
[zh] Fix typo in securing-a-cluster.md
2022-03-24 19:21:51 -07:00
Kubernetes Prow Robot 4351187bc4 Merge pull request #32463 from Gsealy/patch-1
Fix typo CRS → CSR
2022-03-24 19:09:50 -07:00
Jihoon Seo 80fe41b86d [ko] Remove deprecated 'kubelet-garbage-collection' page 2022-03-25 10:47:54 +09:00
Jihoon Seo 9e6b2ef46a [ko] Update links in dev-1.23-ko.2 2022-03-25 10:37:49 +09:00
Kubernetes Prow Robot 20a36d1f14 Merge pull request #32474 from tengqm/fix-feature-state
Fix a nit in the feature-state short code
2022-03-24 18:05:50 -07:00
Qiming Teng d65e53644c Fix a nit in the feature-state short code 2022-03-25 08:39:55 +08:00
Kubernetes Prow Robot e7af510fde Merge pull request #31658 from sftim/20220207_revise_community_page_and_styles
Revise community page and styles
2022-03-24 17:19:50 -07:00
Lukas Hass 3980c42945 Use cat instead of shell built-in to read checksum 2022-03-24 19:58:00 +01:00
Brett Wolmarans 2d69c47782 Update content/en/docs/reference/kubectl/cheatsheet.md
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2022-03-24 10:29:42 -07:00
serewicz ad2921225b Update install-kubeadm.md
Telnet is a command that really should not be used, as there is too great a chance it could be misused. NetCat, nc, is a better and newer tool for testing single open ports.
2022-03-24 09:58:58 -05:00
PriyanshuAhlawat 49436e3dcb Update service.md 2022-03-24 17:56:10 +05:30
hongming b501d626a1 [zh] Fix typo in securing-a-cluster.md 2022-03-24 16:34:52 +08:00
Kubernetes Prow Robot dc947abf0a Merge pull request #32457 from Arhell/ru-typo
[ru] fix typo
2022-03-23 23:30:41 -07:00
Kubernetes Prow Robot 92333db41f Merge pull request #32438 from wellshs/patch-2
edit horizontal-pod-autoscale korean description
2022-03-23 21:20:41 -07:00
Kubernetes Prow Robot 5175726aa6 Merge pull request #32461 from my-git9/sysctl-cluster
[zh] Update sysctl-cluster.md
2022-03-23 20:48:41 -07:00
Kubernetes Prow Robot ba8ef207f7 Merge pull request #32462 from my-git9/safely-drain-node
[zh] Update safely-drain-node
2022-03-23 20:36:41 -07:00
Gsealy dfc52b96eb typo CRS -> CSR 2022-03-24 11:28:50 +08:00
Kubernetes Prow Robot b9d4734630 Merge pull request #32459 from 0xff-dev/main
[zh] delete pod overhead title
2022-03-23 20:26:41 -07:00
Kubernetes Prow Robot 771e57059b Merge pull request #32458 from my-git9/reserve-compute-resources
[zh] Update reserve-compute-resources.md
2022-03-23 20:24:41 -07:00
Kubernetes Prow Robot 71b9d081cf Merge pull request #32447 from xuezhixin/main
Translate ObjectReference #32433
2022-03-23 20:18:41 -07:00
Gerzone 94970599cc Translate ObjectReference #32433 2022-03-24 10:53:57 +08:00
xin.li b555410155 [zh] Update safely-drain-node
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-24 10:19:09 +08:00
xin.li bdfc1b64e6 [zh] Update sysctl-cluster.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-24 09:53:43 +08:00
xin.li eb20f3a34d [zh] Update reserve-compute-resources.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-24 09:47:04 +08:00
0xff-dev 49c3eda945 [zh] delete pod overhead title 2022-03-24 09:46:40 +08:00
shixiuguo d1ea334a70 Translate docs/reference/kubernetes-api/common-definitions/node-selector-requirement.md into Chinese (#32038)
* Translate node-selector-requirement.md into Chinese

* Modify as suggested

* Modify according to the review results

* 删除文档中注释的部分

* Translate node-selector-requirement.md into Chinese

Modify according to the review results
2022-03-23 17:46:41 -07:00
zhangxyjlu 1eae49aec8 [zh] Add 2022-02-17-updated-dockershim-faq.md (#32342)
* [zh] Add 2022-02-17-updated-dockershim-faq.md #32270

* [zh] Add 2022-02-17-updated-dockershim-faq.md

* [zh] Add 2022-02-17-updated-dockershim-faq.md

* [zh] Add 2022-02-17-updated-dockershim-faq.md
2022-03-23 17:44:41 -07:00
Kubernetes Prow Robot 7a1cc8a4ff Merge pull request #32445 from my-git9/kops
[zh] Update kops.md
2022-03-23 17:18:40 -07:00
Kubernetes Prow Robot 766e3ef829 Merge pull request #32454 from natalisucks/co-chair-todos
Add natalisucks to docs reviewers and approvers of English language content
2022-03-23 16:46:48 -07:00
Kubernetes Prow Robot f81bf804fb Merge pull request #32145 from afoster/remove-more-kompose-up-down
Remove kompose up and down command doc
2022-03-23 16:44:49 -07:00
Kubernetes Prow Robot 6d3e04c327 Merge pull request #32051 from zr-msft/patch-1
Update link to Azure Gateway Ingress Controller
2022-03-23 16:42:48 -07:00
Kat Cosgrove fb744abdd1 adds 1.24 cluster dockershim removal ready blog (#32303)
* adds 1.24 cluster dockershim removal ready blog

* small rephrasings

* Update content/en/blog/_posts/2022-03-31-ready-for-dockershim-removal.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update content/en/blog/_posts/2022-03-31-ready-for-dockershim-removal.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update content/en/blog/_posts/2022-03-31-ready-for-dockershim-removal.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update content/en/blog/_posts/2022-03-31-ready-for-dockershim-removal.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* Update content/en/blog/_posts/2022-03-31-ready-for-dockershim-removal.md

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>

* small rephrasings and link adds

Co-authored-by: Nate W. <4453979+nate-double-u@users.noreply.github.com>
2022-03-23 15:31:18 -07:00
Arhell f128a0db14 [ru] fix typo 2022-03-24 00:16:26 +02:00
Natali Vlatko bdf2e6ee97 Add natalisucks to reviewers/approvers of English language content 2022-03-23 19:30:36 +01:00
xin.li 2a2ab57c82 [zh] Update kops.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2022-03-23 21:11:18 +08:00
Hyunsuk Shin 3acb359995 오타 수정 2022-03-23 16:53:06 +09:00
Qiming Teng dcd6f99724 [zh] Rework securing cluster page
This page was translated poorly. Many texts were not properly translated.
2022-03-23 11:29:14 +08:00
196Ikuchil 019bc61951 fix:remove line feeds in text 2022-03-22 20:27:30 +09:00
196Ikuchil 2f438dd510 Update content/ja/docs/reference/scheduling/config.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-22 20:12:21 +09:00
196Ikuchil 3ab3a17d48 Update content/ja/docs/reference/scheduling/config.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-22 20:12:13 +09:00
196Ikuchil 32852dca8b Update content/ja/docs/reference/scheduling/config.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-22 20:12:02 +09:00
196Ikuchil 87733b3a57 Update content/ja/docs/reference/scheduling/config.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-03-22 20:11:17 +09:00
196Ikuchil d8e4686ab7 Update content/ja/docs/reference/scheduling/config.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-03-22 20:11:06 +09:00
196Ikuchil e853954a19 Update content/ja/docs/reference/scheduling/config.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-03-22 20:10:35 +09:00
196Ikuchil c7b87d9143 Update content/ja/docs/reference/scheduling/policies.md
Co-authored-by: Toshiaki Inukai <82919057+t-inu@users.noreply.github.com>
2022-03-22 20:08:51 +09:00
196Ikuchil e9f7ba6b93 fix:最も要求が多い場合か最も要求が少ない 2022-03-22 20:07:56 +09:00
196Ikuchil f99e18c781 fix:utilization and score 2022-03-22 20:05:52 +09:00
196Ikuchil a380843143 Update content/ja/docs/concepts/scheduling-eviction/resource-bin-packing.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-03-22 19:58:33 +09:00
Arhell 61849547f2 [ja] update audit.md 2022-03-22 10:38:22 +02:00
Jihoon Seo cc8e3c5897 [ko] Translate 'Ephemeral Volumes' 2022-03-21 18:26:08 +09:00
Jihoon Seo 6378609cd7 [ko] Update outdated files in dev-1.23-ko.2 M74-85 2022-03-21 18:21:13 +09:00
Jihoon Seo ce19161d60 [ko] Update outdated files in dev-1.23-ko.2 M25-39 2022-03-21 15:02:09 +09:00
Jihoon Seo 13e4d2d37e [ko] Update outdated files in dev-1.23-ko.2 M18-24 2022-03-21 14:48:19 +09:00
edithturn 131f3b2b46 fix minor typo errors 2022-03-20 21:01:32 -05:00
edithturn 0ffcc66120 add storage limits documentation 2022-03-20 20:33:55 -05:00
Nir Rosenthal 76e78444ef per https://github.com/kubernetes/website/pull/32326#discussion_r830493057 2022-03-19 17:39:59 +02:00
Kubernetes Prow Robot 7e2afa9bbf Merge pull request #31924 from anencore94/ko_update_garbage_collection
[ko] update garbage collection
2022-03-18 05:47:16 -07:00
Kubernetes Prow Robot 662682a6fa Merge pull request #31697 from jihoon-seo/220211_Outdated_M9-M17
[ko] Update outdated files in `dev-1.23-ko.2` (M9-M17)
2022-03-18 05:13:16 -07:00
Kubernetes Prow Robot 2acb136fe4 Merge pull request #31695 from jihoon-seo/220211_Outdated_M1-M8
[ko] Update outdated files in `dev-1.23-ko.2` (M1-M8)
2022-03-18 05:07:16 -07:00
Nir Rosenthal 3f0f56f0f2 Changing note about limits without requests
this is true for all limits (not only CPU and memory but also ephemeral storage)

https://github.com/kubernetes/kubernetes/blob/4d08582d1fa21e1f5887e73380001ac827371553/pkg/apis/core/v1/defaults.go#L159
2022-03-18 00:06:10 +02:00
PriyanshuAhlawat 3d78bd31df Update create-cluster-kubeadm.md 2022-03-17 02:21:16 +05:30
196Ikuchil 5f47ac7965 Update config.md 2022-03-16 23:32:27 +09:00
196Ikuchil 2a638d61c2 Update replica-set.md 2022-03-16 23:21:01 +09:00
PriyanshuAhlawat c7952b2c3e Update controlling-access.md 2022-03-16 19:16:46 +05:30
Qiming Teng 2d0d647d0b [zh] Update configure pod configmap
This PR resyncs the configure-pod-configmap page, and translates the comments in the reference example YAML files.
2022-03-16 16:33:40 +08:00
PriyanshuAhlawat 7e54b18dd4 Update controlling-access.md 2022-03-16 01:31:54 +05:30
Qiming Teng a11ecef6f1 Wrap long lines and fix a few nits in the text 2022-03-14 20:36:51 +08:00
Qiming Teng 06f35a55d5 Fix link to use relative path 2022-03-14 20:29:23 +08:00
Amit Sharma a60e9203e0 Update exec-liveness.yaml 2022-03-12 14:42:48 +05:30
Amit Sharma ef297288fa Updated configure-liveness-readiness-startup-probes.md
We don't need to pass -r flag with rm command to delete a file.
2022-03-12 14:13:06 +05:30
Kubernetes Prow Robot dccc9cd077 Merge pull request #32206 from dghg/fixtypo
[ko] fix typo in get-shell-running-container page
2022-03-11 20:54:23 -08:00
Donghyeong Kang 37e282aaae FIX: typo in get-shell-running-container.md 2022-03-11 21:34:05 +09:00
Qiming Teng da8b6d730f [zh] Update coredns page 2022-03-11 19:55:17 +08:00
Jaeyeon Kim cb2e99ecb6 reflect reviews 2022-03-11 18:22:31 +09:00
Jaeyeon Kim 94e766e920 Update content/ko/docs/reference/glossary/garbage-collection.md
Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>
2022-03-11 18:16:21 +09:00
Jaeyeon Kim a28df2ffcb Update content/ko/docs/reference/glossary/garbage-collection.md
Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>
2022-03-11 18:13:25 +09:00
Qiming Teng 29f5e89770 Reformat the node local DNS cache page 2022-03-11 11:15:47 +08:00
Matt Cary 35e901cdbf Update storage-classes.md
The link to the external provisioner specification had gone stale, it now lives in design-proposals-archive.
2022-03-10 09:47:42 -08:00
Jihoon Seo 7ea395ab2f Reflect review suggestions 2022-03-10 10:54:09 +09:00
Qiming Teng 461a09332b [zh] Tune the feature gates page
Reformat some line wraps, reorder some items in the description and
fix a version missing in table 1.
2022-03-09 21:28:09 +08:00
Andrew Foster 77123a0e91 Remove kompose up and down command doc 2022-03-09 22:55:23 +11:00
Shubham Kuchhal aa8b37770e Improvement: Updated FEATURE STATE of NamespaceDefaultLabelName. 2022-03-08 13:10:22 +05:30
Qiming Teng 67fa0bc573 [zh] Fix translation of network policy index page 2022-03-07 20:16:35 +08:00
kartik494 8540194ccd Added Pod security deprecation note 2022-03-07 17:43:10 +05:30
Qiming Teng 3b13867bf6 [zh] Translate 'feature_state' string data 2022-03-07 19:46:13 +08:00
Qiming Teng 6c64631944 [zh] Optimize k8s extension index page
There are some italics font style which doesn't render well in Chinese, we should avoid using them when possible.

There are some inappropriate line wraps that are creating extra spaces between Chinese characters, this PR tries to optimizes that as well.

The subsection title 'configuration' was not translated, also fixed in this PR.
2022-03-07 17:55:37 +08:00
196Ikuchil d1c505e171 fix:test errors 2022-03-07 00:06:44 +09:00
196Ikuchil 1a4044bf30 add:policies.md 2022-03-06 23:48:53 +09:00
196Ikuchil 8981587a68 add:replica-set.md 2022-03-06 23:27:23 +09:00
196Ikuchil 46a13354a1 add:config.md 2022-03-06 23:27:09 +09:00
196Ikuchil 3359ef1ad1 add:content/ja/docs/reference/scheduling/_index.md 2022-03-06 23:26:56 +09:00
Kubernetes Prow Robot 03683630a8 Merge pull request #32057 from ianychoi/fix-anchor-on-using-subpath
[ko] Fix anchor usage on docs/concepts/storage/volumes
2022-03-06 04:18:52 -08:00
Jason Kim (Jun Chul Kim) 2cca1a2f85 Update content/en/docs/setup/best-practices/certificates.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2022-03-06 09:39:02 +09:00
Ian Y. Choi 1a11802f42 [ko] Fix anchor usage on docs/concepts/storage/volumes
The document uses anchor point for "Using Subpath" section
as "#using-subpath", not "#subpath-사용하기", so correcting anchor usage.
2022-03-05 14:18:49 +09:00
Zach Rhoads bbcf9e316f Update link to Azure Gateway Ingress Controller
Changed link for Azure Gateway Ingress Controller to Microsoft documentation.
2022-03-04 16:48:29 -06:00
Thomas Guettler 7122a4498a fix busybox image to 1.28 (issues with nslookup).
Changes where done with these commands:

reprec 'image: busybox(?!:)' 'image: busybox:1.28' */docs */examples
reprec -- '--image=busybox(?!:)' '--image=busybox:1.28' */docs */examples

Related issues:

 https://github.com/docker-library/busybox/issues/48
 https://github.com/kubernetes/kubernetes/issues/66924
2022-03-02 20:48:26 +01:00
Damilola Abioye bf7b94c65a updated allowedTopologies values format 2022-03-02 20:04:02 +01:00
Brett Wolmarans 8dd6fa677d --all-namespaces shorthand
As a beginner to kubectl, I must have typed (and re-typed due to typos) --all-namespaces many hundreds of times before I stumbled across the -A shorthand notation for this.  I sincerely would be grateful on behalf of all kubectl beginners if this very useful cheat could be added to this cheatsheet.  I have proposed in this PR a location quite near the beginning of the cheatsheet for this so that it is very hard to miss.
2022-03-02 09:21:06 -08:00
Jihoon Seo 8880c5571f [ko] Update outdated files in dev-1.23-ko.2 M1-M8 2022-02-28 10:24:27 +09:00
Kubernetes Prow Robot 82d43bc35d Merge pull request #31949 from yoonian/patch-3
[ko] fix typo in quickstart
2022-02-27 16:17:18 -08:00
Yoon 7ea94acfa9 [ko] fix typo in quickstart 2022-02-27 22:48:37 +09:00
Kubernetes Prow Robot a2a91d8865 Merge pull request #31792 from jihoon-seo/220218_Outdated_M40-M49
[ko] Update outdated files in `dev-1.23-ko.2` (M40-M49)
2022-02-27 01:45:17 -08:00
196Ikuchil 33d4e36f6e docs:translate resource-bin-packing 2022-02-27 15:06:31 +09:00
Jaeyeon Kim a1b1aaefc8 [ko] add garbage-collection.md in Korean
Signed-off-by: Jaeyeon Kim <anencore94@gmail.com>
2022-02-26 15:06:46 +09:00
Kubernetes Prow Robot 83faf5f7ad Merge pull request #31746 from KoditkarVedant/update-hyperlinks-to-point-to-main-branch-ko-local
[ko] Fix link
2022-02-25 06:45:51 -08:00
Vedant Koditkar 4141162984 Update hyperlinks to point to main branch & Fixed link 2022-02-25 16:25:50 +05:30
Jihoon Seo b1aa9e7a32 [ko] Update outdated files in dev-1.23-ko.2 M9-M17 2022-02-22 19:27:43 +09:00
PranshuSrivastava 8b1b8a4f80 updated the container-runtime page to include info about dockershim deprecation. 2022-02-22 12:21:36 +05:30
Kubernetes Prow Robot 282d9b56d1 Merge pull request #31762 from jihoon-seo/220216_Remove_invisible_char
[ko] Remove invisible chars
2022-02-21 19:31:46 -08:00
Tim Bannister 49c8a25044 Restrict approvals for community static content
The intent here is to make really sure that we only accept changes that
match upstream exactly.
2022-02-20 16:11:33 +00:00
Tim Bannister a520a7bb2d Update code-of-conduct page to use new styles 2022-02-20 16:11:33 +00:00
Tim Bannister d6a755b474 Revise community values page
- reduce sitemap priority; the contributor site is a better version
- make title match included file
2022-02-20 16:11:33 +00:00
Tim Bannister afc338c0bf Update and restyle community page
- Use new styles (and remove inline CSS)
- Fix some hyperlinks
- Wording tweaks
- Link to Server Fault, not Stack Overflow
2022-02-20 16:11:33 +00:00
Tim Bannister e993de5dc6 Tidy styles for community section
This change enables an opt-in switch to new styles for /community
It is opt-in to enable localizations to migrate to the new page on their
own timeline.
2022-02-20 16:11:31 +00:00
Jihoon Seo 8a73287e65 [ko] Update outdated files in dev-1.23-ko.2 M40-49 2022-02-18 18:24:25 +09:00
Mikhail Polivakha d78f8d2736 Add example of Service targetPort binding by name
Add example of Service targetPort binding by name
2022-02-18 11:10:47 +03:00
Jihoon Seo 0f1e8df67f [ko] Remove invisible chars 2022-02-16 14:25:35 +09:00
Vedant Koditkar 4b85efed41 Update hyperlinks to point to main branch 2022-02-15 12:22:46 +05:30
Dohyun Jung ede7013dc7 Update namespaces.md
Delete content that doesn't exist in the English version.
2022-02-14 19:24:54 +09:00
Qiming Teng d97e53f2a1 [zh] Resync the configmap page 2022-02-12 18:59:43 +08:00
Kobayashi Daisuke 9e65cf1ba8 update 2022-02-01 12:06:30 +09:00
Kobayashi Daisuke 01abcb22e0 fix some points commented 2022-02-01 11:55:19 +09:00
Kobayashi Daisuke 849a28d4aa Update content/ja/docs/concepts/services-networking/topology-aware-hints.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-02-01 11:51:29 +09:00
Kobayashi Daisuke ffa586acf4 Corresponds to review comments about comma. 2022-01-19 18:03:14 +09:00
Kobayashi Daisuke d48800b763 address reviews (change "ー", ":") 2022-01-19 17:21:35 +09:00
Kobayashi Daisuke 027b08ca22 fix some mistakes 2022-01-18 16:07:37 +09:00
Kobayashi Daisuke d2ad1640c3 fix build error 2022-01-18 15:40:34 +09:00
Kobayashi Daisuke f5fac359bb translate topology-aware-hints into Japanese 2022-01-18 15:35:10 +09:00
Josh Berkus 730b9b09e9 Fix link to dev@kubernetes mailing list
Signed-off-by: Josh Berkus <josh@agliodbs.com>
2022-01-13 17:45:04 -08:00
Ryota Yamada 6530c8c1ee Update nodes.md 2022-01-02 18:32:17 +09:00
Ryota Yamada 5b8e9f9684 Update content/ja/docs/concepts/architecture/nodes.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:30:57 +09:00
Ryota Yamada a7e39dfeea Update content/ja/docs/concepts/architecture/nodes.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:30:48 +09:00
Ryota Yamada 6cc732a817 Update content/ja/docs/concepts/architecture/nodes.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:30:37 +09:00
Ryota Yamada db97e76b41 Update content/ja/docs/concepts/architecture/nodes.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:30:19 +09:00
Ryota Yamada dc5509d107 Update content/ja/docs/concepts/architecture/nodes.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:30:09 +09:00
Ryota Yamada a4e66916cc Update content/ja/docs/concepts/architecture/nodes.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:30:03 +09:00
Ryota Yamada 396ce8ed36 Update content/ja/docs/concepts/architecture/nodes.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:29:57 +09:00
Ryota Yamada 7a4cc6ca66 Update secret.md 2022-01-02 18:28:03 +09:00
Ryota Yamada 61cbfe80b2 Update content/ja/docs/concepts/configuration/secret.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:25:37 +09:00
Ryota Yamada 76fdf0e3e6 Update content/ja/docs/concepts/configuration/secret.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:25:32 +09:00
Ryota Yamada 6c6d267a48 Update content/ja/docs/concepts/configuration/secret.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:25:23 +09:00
Ryota Yamada f829e1698d Update content/ja/docs/concepts/configuration/secret.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:25:12 +09:00
Ryota Yamada 93c0c2a514 Update content/ja/docs/concepts/configuration/secret.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:25:03 +09:00
Ryota Yamada e0d3ec65b6 Update content/ja/docs/concepts/configuration/secret.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:24:53 +09:00
Ryota Yamada 8dd92746a4 Update content/ja/docs/concepts/security/pod-security-standards.md
Co-authored-by: nasa9084 <nasa9084@users.noreply.github.com>
2022-01-02 18:23:07 +09:00
Kobayashi Daisuke 3fb0bf8391 Fix the commented point 2021-12-23 15:13:38 +09:00
Kobayashi Daisuke ac1710e060 fix title 2021-12-22 15:22:29 +09:00
Kobayashi Daisuke b2e3c4a78e modify some words 2021-12-22 15:12:10 +09:00
Kobayashi Daisuke 7719b8a0fe Fix build error 2021-12-22 14:24:35 +09:00
Kobayashi Daisuke 74da123ef9 [ja] Translate docs/concepts/architecture/garbage-
collection into Japanese
2021-12-22 14:13:34 +09:00
Jason Kim (Jun Chul Kim) e0fdee6b0d Update certificates.md
[kubelet has client and server certificates](https://kubernetes.io/docs/reference/command-line-tools-reference/kubelet-tls-bootstrapping/#client-and-serving-certificates).

But this page only mentions kubelet client certificate. I linked to the [page](https://kubernetes.io/docs/reference/command-line-tools-reference/kubelet-tls-bootstrapping/#client-and-serving-certificates) because I couldn't find the doc about what are those `certain features`. Please suggest a better link if there are any.
2021-11-22 15:19:13 +09:00
Riita b37a9ca361 Update secret.md 2021-11-17 00:45:02 +09:00
Riita 7d24269a64 Update pod-security-standards.md 2021-11-16 19:32:40 +09:00
Riita 54cd481f36 Update nodes.md 2021-10-30 00:32:32 +09:00
Riita 79a6b1972f Update nodes.md 2021-10-30 00:29:55 +09:00
Riita 2fdb8e2c17 Update pod-security-standards.md 2021-10-20 23:10:30 +09:00
Riita cf858d854f Update nodes.md 2021-10-20 19:17:34 +09:00
Akihito INOH 79364dad11 Add script to print URLs updated by target PR 2021-07-19 10:10:22 +09:00
Jihoon Seo 585bcee188 [vi] Remove exec permission on markdown files 2021-06-22 18:32:02 +09:00
793 changed files with 32095 additions and 14880 deletions
+1
View File
@@ -1,6 +1,7 @@
[submodule "themes/docsy"]
path = themes/docsy
url = https://github.com/google/docsy.git
branch = v0.2.0
[submodule "api-ref-generator"]
path = api-ref-generator
url = https://github.com/kubernetes-sigs/reference-docs
+5 -3
View File
@@ -27,16 +27,18 @@ RUN mkdir $HOME/src && \
FROM golang:1.16-alpine
RUN apk add --no-cache \
runuser \
git \
openssh-client \
rsync \
npm && \
npm install -D autoprefixer postcss-cli
RUN mkdir -p /usr/local/src && \
cd /usr/local/src && \
RUN mkdir -p /var/hugo && \
addgroup -Sg 1000 hugo && \
adduser -Sg hugo -u 1000 -h /src hugo
adduser -Sg hugo -u 1000 -h /var/hugo hugo && \
chown -R hugo: /var/hugo && \
runuser -u hugo -- git config --global --add safe.directory /src
COPY --from=0 /go/bin/hugo /usr/local/bin/hugo
+6 -1
View File
@@ -24,6 +24,7 @@ aliases:
- jimangel
- jlbutler
- kbhawkey
- natalisucks
- onlydole
- pi-victor
- reylejano
@@ -39,6 +40,7 @@ aliases:
- jimangel
- kbhawkey
- mehabhalodiya
- natalisucks
- onlydole
- rajeshdeshpande02
- sftim
@@ -146,8 +148,11 @@ aliases:
- divya-mohan0209
- jimangel
- kbhawkey
- natalisucks
- onlydole
- reylejano
- sftim
- tengqm
sig-docs-zh-owners: # Admins for Chinese content
# chenopis
- chenrui333
@@ -156,6 +161,7 @@ aliases:
# hanjiayao
- howieyuen
# lichuqiang
- mengjiao-liu
- SataQiu
- tanjunchen
- tengqm
@@ -240,7 +246,6 @@ aliases:
# authoritative source: https://git.k8s.io/sig-release/OWNERS_ALIASES
sig-release-leads:
- cpanato # SIG Technical Lead
- hasheddan # SIG Technical Lead
- jeremyrickard # SIG Technical Lead
- justaugustus # SIG Chair
- LappleApple # SIG Program Manager
+50 -2
View File
@@ -4,6 +4,9 @@
このリポジトリには、[KubernetesのWebサイトとドキュメント](https://kubernetes.io/)をビルドするために必要な全アセットが格納されています。貢献に興味を持っていただきありがとうございます!
- [ドキュメントに貢献する](#contributing-to-the-docs)
- [翻訳された`README.md`一覧](#localization-readmemds)
# リポジトリの使い方
Hugo(Extended version)を使用してWebサイトをローカルで実行することも、コンテナランタイムで実行することもできます。コンテナランタイムを使用することを強くお勧めします。これにより、本番Webサイトとのデプロイメントの一貫性が得られます。
@@ -56,6 +59,43 @@ make serve
これで、Hugoのサーバーが1313番ポートを使って開始します。お使いのブラウザにて http://localhost:1313 にアクセスしてください。リポジトリ内のソースファイルに変更を加えると、HugoがWebサイトの内容を更新してブラウザに反映します。
## API reference pagesをビルドする
`content/en/docs/reference/kubernetes-api`に配置されているAPIリファレンスページは<https://github.com/kubernetes-sigs/reference-docs/tree/master/gen-resourcesdocs>を使ってSwagger仕様書からビルドされています。
新しいKubernetesリリースのためにリファレンスページをアップデートするには、次の手順を実行します:
1. `api-ref-generator`サブモジュールをプルする:
```bash
git submodule update --init --recursive --depth 1
```
2. Swagger仕様書を更新する:
```bash
curl 'https://raw.githubusercontent.com/kubernetes/kubernetes/master/api/openapi-spec/swagger.json' > api-ref-assets/api/swagger.json
```
3. 新しいリリースの変更を反映するため、`api-ref-assets/config/`で`toc.yaml`と`fields.yaml`を適用する。
4. 次に、ページをビルドする:
```bash
make api-reference
```
コンテナイメージからサイトを作成・サーブする事でローカルで結果をテストすることができます:
```bash
make container-image
make container-serve
```
APIリファレンスを見るために、ブラウザで<http://localhost:1313/docs/reference/kubernetes-api/>を開いてください。
5. 新しいコントラクトのすべての変更が設定ファイル`toc.yaml`と`fields.yaml`に反映されたら、新しく生成されたAPIリファレンスページとともにPull Requestを作成します。
## トラブルシューティング
### error: failed to transform resource: TOCSS: failed to transform "scss/main.scss" (text/x-scss): this feature is not available in your current Hugo version
@@ -107,7 +147,7 @@ sudo launchctl load -w /Library/LaunchDaemons/limit.maxfiles.plist
- [Slack](https://kubernetes.slack.com/messages/kubernetes-docs-ja)
- [メーリングリスト](https://groups.google.com/forum/#!forum/kubernetes-sig-docs)
## ドキュメントに貢献する
## ドキュメントに貢献する {#contributing-to-the-docs}
GitHubの画面右上にある**Fork**ボタンをクリックすると、お使いのGitHubアカウントに紐付いた本リポジトリのコピーが作成され、このコピーのことを*フォーク*と呼びます。フォークリポジトリの中ではお好きなように変更を加えていただいて構いません。加えた変更をこのリポジトリに追加したい任意のタイミングにて、フォークリポジトリからPull Reqeustを作成してください。
@@ -124,7 +164,15 @@ Kubernetesのドキュメントへの貢献に関する詳細については以
* [ドキュメントのスタイルガイド](https://kubernetes.io/docs/contribute/style/style-guide/)
* [Kubernetesドキュメントの翻訳方法](https://kubernetes.io/docs/contribute/localization/)
## 翻訳された`README.md`一覧
### New Contributor Ambassadors
コントリビュートする時に何か助けが必要なら、[New Contributor Ambassadors](https://kubernetes.io/docs/contribute/advanced/#serve-as-a-new-contributor-ambassador)に聞いてみると良いでしょう。彼らはSIG Docsのapproverで、最初の数回のPull Requestを通して新しいコントリビューターを指導し助けることを責務としています。New Contributors Ambassadorsにコンタクトするには、[Kubernetes Slack](https://slack.k8s.io)が最適な場所です。現在のSIG DocsのNew Contributor Ambassadorは次の通りです:
| 名前 | Slack | GitHub |
| -------------------------- | -------------------------- | -------------------------- |
| Arsh Sharma | @arsh | @RinkiyaKeDad |
## 翻訳された`README.md`一覧 {#localization-readmemds}
| Language | Language |
|---|---|
+2 -2
View File
@@ -123,7 +123,7 @@ Hugo is shipped in two set of binaries for technical reasons. The current websit
由于技术原因,Hugo 会发布两套二进制文件。
当前网站仅基于 **Hugo Extended** 版本运行。
在 [发布页面](https://github.com/gohugoio/hugo/releases) 中查找名称为 `extended` 的归档。可以运行 `huge version` 查看是否有单词 `extended` 来确认。
在 [发布页面](https://github.com/gohugoio/hugo/releases) 中查找名称为 `extended` 的归档。可以运行 `hugo version` 查看是否有单词 `extended` 来确认。
<!--
### Troubleshooting macOS for too many open files
@@ -131,7 +131,7 @@ Hugo is shipped in two set of binaries for technical reasons. The current websit
If you run `make serve` on macOS and receive the following error:
-->
### 对 macOs 上打开太多文件的故障排除
### 对 macOS 上打开太多文件的故障排除
如果在 macOS 上运行 `make serve` 收到以下错误:
+2 -1
View File
@@ -566,7 +566,8 @@ main.content {
}
}
/* COMMUNITY */
/* COMMUNITY legacy styles */
/* Leave these in place until localizations are caught up */
.newcommunitywrapper {
.news {
+18 -18
View File
@@ -139,9 +139,9 @@ time_format_default = "January 02, 2006 at 3:04 PM PST"
description = "Production-Grade Container Orchestration"
showedit = true
latest = "v1.23"
latest = "v1.24"
fullversion = "v1.23.0"
fullversion = "v1.23.6"
version = "v1.23"
githubbranch = "main"
docsbranch = "main"
@@ -179,40 +179,40 @@ js = [
]
[[params.versions]]
fullversion = "v1.23.0"
version = "v1.23"
githubbranch = "v1.23.0"
fullversion = "v1.24.0"
version = "v1.24"
githubbranch = "v1.24.0"
docsbranch = "main"
url = "https://kubernetes.io"
[[params.versions]]
fullversion = "v1.22.4"
fullversion = "v1.23.6"
version = "v1.23"
githubbranch = "v1.23.6"
docsbranch = "release-1.23"
url = "https://v1-23.docs.kubernetes.io"
[[params.versions]]
fullversion = "v1.22.9"
version = "v1.22"
githubbranch = "v1.22.4"
githubbranch = "v1.22.9"
docsbranch = "release-1.22"
url = "https://v1-22.docs.kubernetes.io"
[[params.versions]]
fullversion = "v1.21.7"
fullversion = "v1.21.12"
version = "v1.21"
githubbranch = "v1.21.7"
githubbranch = "v1.21.12"
docsbranch = "release-1.21"
url = "https://v1-21.docs.kubernetes.io"
[[params.versions]]
fullversion = "v1.20.13"
fullversion = "v1.20.15"
version = "v1.20"
githubbranch = "v1.20.13"
githubbranch = "v1.20.15"
docsbranch = "release-1.20"
url = "https://v1-20.docs.kubernetes.io"
[[params.versions]]
fullversion = "v1.19.16"
version = "v1.19"
githubbranch = "v1.19.16"
docsbranch = "release-1.19"
url = "https://v1-19.docs.kubernetes.io"
# User interface configuration
[params.ui]
# Enable to show the side bar menu in its compact state.
@@ -24,14 +24,14 @@ Die Add-Ons in den einzelnen Kategorien sind alphabetisch sortiert - Die Reihenf
* [Canal](https://github.com/tigera/canal/tree/master/k8s-install) vereint Flannel und Calico um Networking- und Network-Policies bereitzustellen.
* [Cilium](https://github.com/cilium/cilium) ist ein L3 Network- and Network-Policy-Plugin welches das transparent HTTP/API/L7-Policies durchsetzen kann. Sowohl Routing- als auch Overlay/Encapsulation-Modes werden uterstützt. Außerdem kann Cilium auf andere CNI-Plugins aufsetzen.
* [CNI-Genie](https://github.com/Huawei-PaaS/CNI-Genie) ermöglicht das nahtlose Verbinden von Kubernetes mit einer Reihe an CNI-Plugins wie z.B. Calico, Canal, Flannel, Romana, oder Weave.
* [Contiv](http://contiv.github.io) bietet konfigurierbares Networking (Native L3 auf BGP, Overlay mit vxlan, Klassisches L2, Cisco-SDN/ACI) für verschiedene Anwendungszwecke und auch umfangreiches Policy-Framework. Das Contiv-Projekt ist vollständig [Open Source](http://github.com/contiv). Der [installer](http://github.com/contiv/install) bietet sowohl kubeadm als auch nicht-kubeadm basierte Installationen.
* [Contiv](https://contivpp.io/) bietet konfigurierbares Networking (Native L3 auf BGP, Overlay mit vxlan, Klassisches L2, Cisco-SDN/ACI) für verschiedene Anwendungszwecke und auch umfangreiches Policy-Framework. Das Contiv-Projekt ist vollständig [Open Source](http://github.com/contiv). Der [installer](http://github.com/contiv/install) bietet sowohl kubeadm als auch nicht-kubeadm basierte Installationen.
* [Contrail](http://www.juniper.net/us/en/products-services/sdn/contrail/contrail-networking/), basierend auf [Tungsten Fabric](https://tungsten.io), ist eine Open Source, multi-Cloud Netzwerkvirtualisierungs- und Policy-Management Plattform. Contrail und Tungsten Fabric sind mit Orechstratoren wie z.B. Kubernetes, OpenShift, OpenStack und Mesos integriert und bieten Isolationsmodi für Virtuelle Maschinen, Container (bzw. Pods) und Bare Metal workloads.
* [Flannel](https://github.com/flannel-io/flannel#deploying-flannel-manually) ist ein Overlay-Network-Provider der mit Kubernetes genutzt werden kann.
* [Knitter](https://github.com/ZTE/Knitter/) ist eine Network-Lösung die Mehrfach-Network in Kubernetes ermöglicht.
* Multus ist ein Multi-Plugin für Mehrfachnetzwerk-Unterstützung um alle CNI-Plugins (z.B. Calico, Cilium, Contiv, Flannel), zusätzlich zu SRIOV-, DPDK-, OVS-DPDK- und VPP-Basierten Workloads in Kubernetes zu unterstützen.
* [NSX-T](https://docs.vmware.com/en/VMware-NSX-T/2.0/nsxt_20_ncp_kubernetes.pdf) Container Plug-in (NCP) bietet eine Integration zwischen VMware NSX-T und einem Orchestator wie z.B. Kubernetes. Außerdem bietet es eine Integration zwischen NSX-T und Containerbasierten CaaS/PaaS-Plattformen wie z.B. Pivotal Container Service (PKS) und OpenShift.
* [Nuage](https://github.com/nuagenetworks/nuage-kubernetes/blob/v5.1.1-1/docs/kubernetes-1-installation.rst) ist eine SDN-Plattform die Policy-Basiertes Networking zwischen Kubernetes Pods und nicht-Kubernetes Umgebungen inklusive Sichtbarkeit und Security-Monitoring bereitstellt.
* [Romana](http://romana.io) ist eine Layer 3 Network-Lösung für Pod-Netzwerke welche auch die [NetworkPolicy API](/docs/concepts/services-networking/network-policies/) unterstützt. Details zur Installation als kubeadm Add-On sind [hier](https://github.com/romana/romana/tree/master/containerize) verfügbar.
* [Romana](https://github.com/romana/romana) ist eine Layer 3 Network-Lösung für Pod-Netzwerke welche auch die [NetworkPolicy API](/docs/concepts/services-networking/network-policies/) unterstützt. Details zur Installation als kubeadm Add-On sind [hier](https://github.com/romana/romana/tree/master/containerize) verfügbar.
* [Weave Net](https://www.weave.works/docs/net/latest/kube-addon/) bietet Networking and Network-Policies und arbeitet auf beiden Seiten der Network-Partition ohne auf eine externe Datenbank angwiesen zu sein.
## Service-Discovery
@@ -52,5 +52,3 @@ Die Add-Ons in den einzelnen Kategorien sind alphabetisch sortiert - Die Reihenf
Es gibt einige weitere Add-Ons die in dem abgekündigten [cluster/addons](https://git.k8s.io/kubernetes/cluster/addons)-Verzeichnis dokumentiert sind.
Add-Ons die ordentlich gewartet werden dürfen gerne hier aufgezählt werden. Wir freuen uns auf PRs!
@@ -248,7 +248,7 @@ einige Einschränkungen:
Eintrag zur Liste `metadata.finalizers` hinzugefügt werden.
- Pod-Updates dürfen keine Felder ändern, die Ausnahmen sind
`spec.containers[*].image`,
`spec.initContainers[*].image`,` spec.activeDeadlineSeconds` oder
`spec.initContainers[*].image`, `spec.activeDeadlineSeconds` oder
`spec.tolerations`. Für `spec.tolerations` kannnst du nur neue Einträge
hinzufügen.
- Für `spec.activeDeadlineSeconds` sind nur zwei Änderungen erlaubt:
@@ -322,7 +322,7 @@ Ausgabeformat | Beschreibung
### Kubectl Ausgabe Ausführlichkeit und Debugging
Die Ausführlichkeit von Kubectl wird mit den Flags `-v` oder `--v ` gesteuert, gefolgt von einer Ganzzahl, die die Protokollebene darstellt. Allgemeine Protokollierungskonventionen für Kubernetes und die zugehörigen Protokollebenen werden [hier](https://github.com/kubernetes/community/blob/master/contributors/devel/sig-instrumentation/logging.md) beschrieben.
Die Ausführlichkeit von Kubectl wird mit den Flags `-v` oder `--v` gesteuert, gefolgt von einer Ganzzahl, die die Protokollebene darstellt. Allgemeine Protokollierungskonventionen für Kubernetes und die zugehörigen Protokollebenen werden [hier](https://github.com/kubernetes/community/blob/master/contributors/devel/sig-instrumentation/logging.md) beschrieben.
Ausführlichkeit | Beschreibung
--------------| -----------
@@ -19,7 +19,7 @@ Security:
- [Node authorizer](/docs/reference/access-authn-authz/node/) and admission control plugin are new additions that restrict kubelets access to secrets, pods and other objects based on its node.
- [Encryption for Secrets](/docs/tasks/administer-cluster/encrypt-data/), and other resources in etcd, is now available as alpha.&nbsp;
- [Kubelet TLS bootstrapping](/docs/admin/kubelet-tls-bootstrapping/) now supports client and server certificate rotation.
- [Audit logs](/docs/tasks/debug-application-cluster/audit/) stored by the API server are now more customizable and extensible with support for event filtering and webhooks. They also provide richer data for system audit.
- [Audit logs](/docs/tasks/debug/debug-cluster/audit/) stored by the API server are now more customizable and extensible with support for event filtering and webhooks. They also provide richer data for system audit.
Stateful workloads:
@@ -4,7 +4,12 @@ date: 2017-11-02
slug: containerd-container-runtime-options-kubernetes
url: /blog/2017/11/Containerd-Container-Runtime-Options-Kubernetes
---
**_Editor's note: Today's post is by Lantao Liu, Software Engineer at Google, and Mike Brown, Open Source Developer Advocate at IBM._**
**Authors:** Lantao Liu (Google), and Mike Brown (IBM)
_Update: Kubernetes support for Docker via `dockershim` is now deprecated.
For more information, read the [deprecation notice](/blog/2020/12/08/kubernetes-1-20-release-announcement/#dockershim-deprecation).
You can also discuss the deprecation via a dedicated [GitHub issue](https://github.com/kubernetes/kubernetes/issues/106917)._
A _container runtime_ is software that executes containers and manages container images on a node. Today, the most widely known container runtime is [Docker](https://www.docker.com/), but there are other container runtimes in the ecosystem, such as [rkt](https://coreos.com/rkt/), [containerd](https://containerd.io/), and [lxd](https://linuxcontainers.org/lxd/). Docker is by far the most common container runtime used in production Kubernetes environments, but Dockers smaller offspring, containerd, may prove to be a better option. This post describes using containerd with Kubernetes.
@@ -117,7 +117,7 @@ To achieve the best possible isolation, each function call would have to happen
By using Landlock, we could isolate function calls from each other within the same container, making a temporary file created by one function call inaccessible to the next function call, for example. Integration between Landlock and technologies like Kubernetes-based serverless frameworks would be a ripe area for further exploration.
## Auditing kubectl-exec with eBPF
In Kubernetes 1.7 the [audit proposal](/docs/tasks/debug-application-cluster/audit/) started making its way in. It's currently pre-stable with plans to be stable in the 1.10 release. As the name implies, it allows administrators to log and audit events that take place in a Kubernetes cluster.
In Kubernetes 1.7 the [audit proposal](/docs/tasks/debug/debug-cluster/audit/) started making its way in. It's currently pre-stable with plans to be stable in the 1.10 release. As the name implies, it allows administrators to log and audit events that take place in a Kubernetes cluster.
While these events log Kubernetes events, they don't currently provide the level of visibility that some may require. For example, while we can see that someone has used `kubectl exec` to enter a container, we are not able to see what commands were executed in that session. With eBPF one can attach a BPF program that would record any commands executed in the `kubectl exec` session and pass those commands to a user-space program that logs those events. We could then play that session back and know the exact sequence of events that took place.
## Learn more about eBPF
@@ -66,7 +66,7 @@ There are plenty of [good examples](https://docs.bitnami.com/kubernetes/how-to/c
Incorrect or excessively permissive RBAC policies are a security threat in case of a compromised pod. Maintaining least privilege, and continuously reviewing and improving RBAC rules, should be considered part of the "technical debt hygiene" that teams build into their development lifecycle.
[Audit Logging](/docs/tasks/debug-application-cluster/audit/) (beta in 1.10) provides customisable API logging at the payload (e.g. request and response), and also metadata levels. Log levels can be tuned to your organisation&#39;s security policy - [GKE](https://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging#audit_policy) provides sane defaults to get you started.
[Audit Logging](/docs/tasks/debug/debug-cluster/audit/) (beta in 1.10) provides customisable API logging at the payload (e.g. request and response), and also metadata levels. Log levels can be tuned to your organisation&#39;s security policy - [GKE](https://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging#audit_policy) provides sane defaults to get you started.
For read requests such as get, list, and watch, only the request object is saved in the audit logs; the response object is not. For requests involving sensitive data such as Secret and ConfigMap, only the metadata is exported. For all other requests, both request and response objects are saved in audit logs.
@@ -174,7 +174,7 @@ Cluster-distributed stateful services (e.g., Cassandra) can benefit from splitti
## Other considerations
[Logs](/docs/concepts/cluster-administration/logging/) and [metrics](/docs/tasks/debug-application-cluster/resource-usage-monitoring/) (if collected and persistently retained) are valuable to diagnose outages, but given the variety of technologies available it will not be addressed in this blog. If Internet connectivity is available, it may be desirable to retain logs and metrics externally at a central location.
[Logs](/docs/concepts/cluster-administration/logging/) and [metrics](/docs/tasks/debug/debug-cluster/resource-usage-monitoring/) (if collected and persistently retained) are valuable to diagnose outages, but given the variety of technologies available it will not be addressed in this blog. If Internet connectivity is available, it may be desirable to retain logs and metrics externally at a central location.
Your production deployment should utilize an automated installation, configuration and update tool (e.g., [Ansible](https://github.com/kubernetes-incubator/kubespray), [BOSH](https://github.com/cloudfoundry-incubator/kubo-deployment), [Chef](https://github.com/chef-cookbooks/kubernetes), [Juju](/docs/getting-started-guides/ubuntu/installation/), [kubeadm](/docs/reference/setup-tools/kubeadm/), [Puppet](https://forge.puppet.com/puppetlabs/kubernetes), etc.). A manual process will have repeatability issues, be labor intensive, error prone, and difficult to scale. [Certified distributions](https://www.cncf.io/certification/software-conformance/#logos) are likely to include a facility for retaining configuration settings across updates, but if you implement your own install and config toolchain, then retention, backup and recovery of the configuration artifacts is essential. Consider keeping your deployment components and settings under a version control system such as Git.
@@ -360,7 +360,7 @@ So let's fix the issue by installing the missing package:
sudo apt install -y conntrack
```
![minikube-install-conntrack](/images/blog/2020-05-21-wsl2-dockerdesktop-k8s/wsl2-minikube-install conntrack.png)
![minikube-install-conntrack](/images/blog/2020-05-21-wsl2-dockerdesktop-k8s/wsl2-minikube-install-conntrack.png)
Let's try to launch it again:
@@ -177,7 +177,7 @@ group_right() apiserver_request_total
Metrics are a fast way to check whether deprecated APIs are being used, and at what rate,
but they don't include enough information to identify particular clients or API objects.
Starting in Kubernetes v1.19, [audit events](/docs/tasks/debug-application-cluster/audit/)
Starting in Kubernetes v1.19, [audit events](/docs/tasks/debug/debug-cluster/audit/)
for requests to deprecated APIs include an audit annotation of `"k8s.io/deprecated":"true"`.
Administrators can use those audit events to identify specific clients or objects that need to be updated.
@@ -18,9 +18,9 @@ The paper attempts to _not_ focus on any specific [cloud native project](https:/
## Kubernetes native security controls
When using Kubernetes as a workload orchestrator, some of the security controls this version of the whitepaper recommends are:
* [Pod Security Policies](/docs/concepts/policy/pod-security-policy/): Implement a single source of truth for “least privilege” workloads across the entire cluster
* [Pod Security Policies](/docs/concepts/security/pod-security-policy/): Implement a single source of truth for “least privilege” workloads across the entire cluster
* [Resource requests and limits](/docs/concepts/configuration/manage-resources-containers/#requests-and-limits): Apply requests (soft constraint) and limits (hard constraint) for shared resources such as memory and CPU
* [Audit log analysis](/docs/tasks/debug-application-cluster/audit/): Enable Kubernetes API auditing and filtering for security relevant events
* [Audit log analysis](/docs/tasks/debug/debug-cluster/audit/): Enable Kubernetes API auditing and filtering for security relevant events
* [Control plane authentication and certificate root of trust](/docs/concepts/architecture/control-plane-node-communication/): Enable mutual TLS authentication with a trusted CA for communication within the cluster
* [Secrets management](/docs/concepts/configuration/secret/): Integrate with a built-in or external secrets store
@@ -155,7 +155,7 @@ runtime where possible.
Another thing to look out for is anything expecting to run for system maintenance
or nested inside a container when building images will no longer work. For the
former, you can use the [`crictl`][cr] tool as a drop-in replacement (see [mapping from docker cli to crictl](https://kubernetes.io/docs/tasks/debug-application-cluster/crictl/#mapping-from-docker-cli-to-crictl)) and for the
former, you can use the [`crictl`][cr] tool as a drop-in replacement (see [mapping from docker cli to crictl](https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/#mapping-from-docker-cli-to-crictl)) and for the
latter you can use newer container build options like [img], [buildah],
[kaniko], or [buildkit-cli-for-kubectl] that dont require Docker.
@@ -7,6 +7,10 @@ slug: dont-panic-kubernetes-and-docker
**Authors:** Jorge Castro, Duffie Cooley, Kat Cosgrove, Justin Garrison, Noah Kantrowitz, Bob Killen, Rey Lejano, Dan “POP” Papandrea, Jeffrey Sica, Davanum “Dims” Srinivas
_Update: Kubernetes support for Docker via `dockershim` is now deprecated.
For more information, read the [deprecation notice](/blog/2020/12/08/kubernetes-1-20-release-announcement/#dockershim-deprecation).
You can also discuss the deprecation via a dedicated [GitHub issue](https://github.com/kubernetes/kubernetes/issues/106917)._
Kubernetes is [deprecating
Docker](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.20.md#deprecation)
as a container runtime after v1.20.
@@ -32,7 +32,7 @@ The `kubectl alpha debug` features graduates to beta in 1.20, becoming `kubectl
Note that as a new built-in command, `kubectl debug` takes priority over any kubectl plugin named “debug”. You must rename the affected plugin.
Invocations using `kubectl alpha debug` are now deprecated and will be removed in a subsequent release. Update your scripts to use `kubectl debug`. For more information about `kubectl debug`, see [Debugging Running Pods](https://kubernetes.io/docs/tasks/debug-application-cluster/debug-running-pod/).
Invocations using `kubectl alpha debug` are now deprecated and will be removed in a subsequent release. Update your scripts to use `kubectl debug`. For more information about `kubectl debug`, see [Debugging Running Pods](https://kubernetes.io/docs/tasks/debug/debug-application/debug-running-pod/).
### Beta: API Priority and Fairness
@@ -21,7 +21,7 @@ Until then, PSP is still PSP. There will be at least a year during which the new
## What is PodSecurityPolicy?
[PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/) is a built-in [admission controller](/blog/2019/03/21/a-guide-to-kubernetes-admission-controllers/) that allows a cluster administrator to control security-sensitive aspects of the Pod specification.
[PodSecurityPolicy](/docs/concepts/security/pod-security-policy/) is a built-in [admission controller](/blog/2019/03/21/a-guide-to-kubernetes-admission-controllers/) that allows a cluster administrator to control security-sensitive aspects of the Pod specification.
First, one or more PodSecurityPolicy resources are created in a cluster to define the requirements Pods must meet. Then, RBAC rules are created to control which PodSecurityPolicy applies to a given pod. If a pod meets the requirements of its PSP, it will be admitted to the cluster as usual. In some cases, PSP can also modify Pod fields, effectively creating new defaults for those fields. If a Pod does not meet the PSP requirements, it is rejected, and cannot run.
@@ -62,7 +62,7 @@ spec:
Note that completion mode is an alpha feature in the 1.21 release. To be able to
use it in your cluster, make sure to enable the `IndexedJob` [feature
gate](/docs/reference/command-line-tools-reference/feature-gates/) on the
[API server](docs/reference/command-line-tools-reference/kube-apiserver/) and
[API server](/docs/reference/command-line-tools-reference/kube-apiserver/) and
the [controller manager](/docs/reference/command-line-tools-reference/kube-controller-manager/).
When you run the example, you will see that each of the three created Pods gets a
@@ -175,7 +175,7 @@ require internet access to update the vulnerability database.
### Pod Security Policies
Since Kubernetes v1.21, the [PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/)
Since Kubernetes v1.21, the [PodSecurityPolicy](/docs/concepts/security/pod-security-policy/)
API and related features are [deprecated](/blog/2021/04/06/podsecuritypolicy-deprecation-past-present-and-future/),
but some of the guidance in this section will still apply for the next few years, until cluster operators
upgrade their clusters to newer Kubernetes versions.
@@ -317,7 +317,7 @@ RequestResponse's including metadata and request / response bodies. While helpfu
Each organization needs to evaluate their
own threat model and build an audit policy that complements or helps troubleshooting incident response. Think
about how someone would attack your organization and what audit trail could identify it. Review more advanced options for tuning audit logs in the official [audit logging documentation](/docs/tasks/debug-application-cluster/audit/#audit-policy).
about how someone would attack your organization and what audit trail could identify it. Review more advanced options for tuning audit logs in the official [audit logging documentation](/docs/tasks/debug/debug-cluster/audit/#audit-policy).
It's crucial to tune your audit logs to only include events that meet your threat model. A minimal audit policy that logs everything at `metadata` level can also be a good starting point.
Audit logging configurations can also be tested with
@@ -18,7 +18,7 @@ One of the key security principles for running containers in Kubernetes is the
principle of least privilege. The Pod/container `securityContext` specifies the config
options to set, e.g., Linux capabilities, MAC policies, and user/group ID values to achieve this.
Furthermore, the cluster admins are supported with tools like [PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/) (deprecated) or
Furthermore, the cluster admins are supported with tools like [PodSecurityPolicy](/docs/concepts/security/pod-security-policy/) (deprecated) or
[Pod Security Admission](/docs/concepts/security/pod-security-admission/) (alpha) to enforce the desired security settings for pods that are being deployed in
the cluster. These settings could, for instance, require that containers must be `runAsNonRoot` or
that they are forbidden from running with root's group ID in `runAsGroup` or `supplementalGroups`.
@@ -5,13 +5,20 @@ date: 2021-11-12
slug: are-you-ready-for-dockershim-removal
---
**Author:** Sergey Kanzhelev, Google. With reviews from Davanum Srinivas, Elana Hashman, Noah Kantrowitz, Rey Lejano.
**Authors:** Sergey Kanzhelev, Google. With reviews from Davanum Srinivas, Elana Hashman, Noah Kantrowitz, Rey Lejano.
{{% alert color="info" title="Poll closed" %}}
This poll closed on January 7, 2022.
{{% /alert %}}
Last year we announced that Dockershim is being deprecated: [Dockershim Deprecation FAQ](/blog/2020/12/02/dockershim-faq/).
Last year we [announced](/blog/2020/12/08/kubernetes-1-20-release-announcement/#dockershim-deprecation)
that Kubernetes' dockershim component (which provides a built-in integration for
Docker Engine) is deprecated.
_Update: There's a [Dockershim Deprecation FAQ](/blog/2020/12/02/dockershim-faq/)
with more information, and you can also discuss the deprecation via a dedicated
[GitHub issue](https://github.com/kubernetes/kubernetes/issues/106917)._
Our current plan is to remove dockershim from the Kubernetes codebase soon.
We are looking for feedback from you whether you are ready for dockershim
removal and to ensure that you are ready when the time comes.
@@ -9,7 +9,7 @@ slug: pod-security-admission-beta
With the release of Kubernetes v1.23, [Pod Security admission](/docs/concepts/security/pod-security-admission/) has now entered beta. Pod Security is a [built-in](/docs/reference/access-authn-authz/admission-controllers/) admission controller that evaluates pod specifications against a predefined set of [Pod Security Standards](/docs/concepts/security/pod-security-standards/) and determines whether to `admit` or `deny` the pod from running.
Pod Security is the successor to [PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/) which was deprecated in the v1.21 release, and will be removed in Kubernetes v1.25. In this article, we cover the key concepts of Pod Security along with how to use it. We hope that cluster administrators and developers alike will use this new mechanism to enforce secure defaults for their workloads.
Pod Security is the successor to [PodSecurityPolicy](/docs/concepts/security/pod-security-policy/) which was deprecated in the v1.21 release, and will be removed in Kubernetes v1.25. In this article, we cover the key concepts of Pod Security along with how to use it. We hope that cluster administrators and developers alike will use this new mechanism to enforce secure defaults for their workloads.
## Why Pod Security
@@ -8,8 +8,8 @@ slug: kubernetes-1-23-statefulset-pvc-auto-deletion
**Author:** Matthew Cary (Google)
Kubernetes v1.23 introduced a new, alpha-level policy for
[StatefulSets](docs/concepts/workloads/controllers/statefulset/) that controls the lifetime of
[PersistentVolumeClaims](docs/concepts/storage/persistent-volumes/) (PVCs) generated from the
[StatefulSets](/docs/concepts/workloads/controllers/statefulset/) that controls the lifetime of
[PersistentVolumeClaims](/docs/concepts/storage/persistent-volumes/) (PVCs) generated from the
StatefulSet spec template for cases when they should be deleted automatically when the StatefulSet
is deleted or pods in the StatefulSet are scaled down.
@@ -82,7 +82,7 @@ This policy forms a matrix with four cases. Ill walk through and give an exam
new replicas will automatically use them.
Visit the
[documentation](docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-policies) to
[documentation](/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-policies) to
see all the details.
## Whats next?
@@ -1,6 +1,7 @@
---
layout: blog
title: "Updated: Dockershim Removal FAQ"
linkTitle: "Dockershim Removal FAQ"
date: 2022-02-17
slug: dockershim-faq
aliases: [ '/dockershim' ]
@@ -168,7 +169,7 @@ runtime where possible.
Another thing to look out for is anything expecting to run for system maintenance
or nested inside a container when building images will no longer work. For the
former, you can use the [`crictl`][cr] tool as a drop-in replacement (see [mapping from docker cli to crictl](https://kubernetes.io/docs/tasks/debug-application-cluster/crictl/#mapping-from-docker-cli-to-crictl)) and for the
former, you can use the [`crictl`][cr] tool as a drop-in replacement (see [mapping from docker cli to crictl](https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/#mapping-from-docker-cli-to-crictl)) and for the
latter you can use newer container build options like [img], [buildah],
[kaniko], or [buildkit-cli-for-kubectl] that dont require Docker.
@@ -184,7 +185,7 @@ options are available as you migrate things over.
[documentation]: https://github.com/containerd/cri/blob/master/docs/registry.md
For instructions on how to use containerd and CRI-O with Kubernetes, see the
Kubernetes documentation on [Container Runtimes]
Kubernetes documentation on [Container Runtimes].
[Container Runtimes]: /docs/setup/production-environment/container-runtimes/
@@ -192,7 +193,10 @@ Kubernetes documentation on [Container Runtimes]
If you use a vendor-supported Kubernetes distribution, you can ask them about
upgrade plans for their products. For end-user questions, please post them
to our end user community forum: https://discuss.kubernetes.io/.
to our end user community forum: https://discuss.kubernetes.io/.
You can discuss the decision to remove dockershim via a dedicated
[GitHub issue](https://github.com/kubernetes/kubernetes/issues/106917).
You can also check out the excellent blog post
[Wait, Docker is deprecated in Kubernetes now?][dep] a more in-depth technical
@@ -200,6 +204,15 @@ discussion of the changes.
[dep]: https://dev.to/inductor/wait-docker-is-deprecated-in-kubernetes-now-what-do-i-do-e4m
### Is there any tooling that can help me find dockershim in use
Yes! The [Detector for Docker Socket (DDS)][dds] is a kubectl plugin that you can
install and then use to check your cluster. DDS can detect if active Kubernetes workloads
are mounting the Docker Engine socket (`docker.sock`) as a volume.
Find more details and usage patterns in the DDS project's [README][dds].
[dds]: https://github.com/aws-containers/kubectl-detector-for-docker-socket
### Can I have a hug?
Yes, we're still giving hugs as requested. 🤗🤗🤗
@@ -0,0 +1,34 @@
---
layout: blog
title: "Is Your Cluster Ready for v1.24?"
date: 2022-03-31
slug: ready-for-dockershim-removal
---
**Author:** Kat Cosgrove
Way back in December of 2020, Kubernetes announced the [deprecation of Dockershim](/blog/2020/12/02/dont-panic-kubernetes-and-docker/). In Kubernetes, dockershim is a software shim that allows you to use the entire Docker engine as your container runtime within Kubernetes. In the upcoming v1.24 release, we are removing Dockershim - the delay between deprecation and removal in line with the [projects policy](https://kubernetes.io/docs/reference/using-api/deprecation-policy/) of supporting features for at least one year after deprecation. If you are a cluster operator, this guide includes the practical realities of what you need to know going into this release. Also, what do you need to do to ensure your cluster doesnt fall over!
## First, does this even affect you?
If you are rolling your own cluster or are otherwise unsure whether or not this removal affects you, stay on the safe side and [check to see if you have any dependencies on Docker Engine](/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you/). Please note that using Docker Desktop to build your application containers is not a Docker dependency for your cluster. Container images created by Docker are compliant with the [Open Container Initiative (OCI)](https://opencontainers.org/), a Linux Foundation governance structure that defines industry standards around container formats and runtimes. They will work just fine on any container runtime supported by Kubernetes.
If you are using a managed Kubernetes service from a cloud provider, and you havent explicitly changed the container runtime, there may be nothing else for you to do. Amazon EKS, Azure AKS, and Google GKE all default to containerd now, though you should make sure they do not need updating if you have any node customizations. To check the runtime of your nodes, follow [Find Out What Container Runtime is Used on a Node](/docs/tasks/administer-cluster/migrating-from-dockershim/find-out-runtime-you-use/).
Regardless of whether you are rolling your own cluster or using a managed Kubernetes service from a cloud provider, you may need to [migrate telemetry or security agents that rely on Docker Engine](/docs/tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents/).
## I have a Docker dependency. What now?
If your Kubernetes cluster depends on Docker Engine and you intend to upgrade to Kubernetes v1.24 (which you should eventually do for security and similar reasons), you will need to change your container runtime from Docker Engine to something else or use [cri-dockerd](https://github.com/Mirantis/cri-dockerd). Since [containerd](https://containerd.io/) is a graduated CNCF project and the runtime within Docker itself, its a safe bet as an alternative container runtime. Fortunately, the Kubernetes project has already documented the process of [changing a nodes container runtime](/docs/tasks/administer-cluster/migrating-from-dockershim/change-runtime-containerd/), using containerd as an example. Instructions are similar for switching to one of the other supported runtimes.
## I want to upgrade Kubernetes, and I need to maintain compatibility with Docker as a runtime. What are my options?
Fear not, you arent being left out in the cold and you dont have to take the security risk of staying on an old version of Kubernetes. Mirantis and Docker have jointly released, and are maintaining, a replacement for dockershim. That replacement is called [cri-dockerd](https://github.com/Mirantis/cri-dockerd). If you do need to maintain compatibility with Docker as a runtime, install cri-dockerd following the instructions in the projects documentation.
## Is that it?
Yes. As long as you go into this release aware of the changes being made and the details of your own clusters, and you make sure to communicate clearly with your development teams, it will be minimally dramatic. You may have some changes to make to your cluster, application code, or scripts, but all of these requirements are documented. Switching from using Docker Engine as your runtime to using [one of the other supported container runtimes](/docs/setup/production-environment/container-runtimes/) effectively means removing the middleman, since the purpose of dockershim is to access the container runtime used by Docker itself. From a practical perspective, this removal is better both for you and for Kubernetes maintainers in the long-run.
If you still have questions, please first check the [Dockershim Removal FAQ](/blog/2022/02/17/dockershim-faq/).
@@ -0,0 +1,133 @@
---
layout: blog
title: "Kubernetes Removals and Deprecations In 1.24"
date: 2022-04-07
slug: upcoming-changes-in-kubernetes-1-24
---
**Author**: Mickey Boxell (Oracle)
As Kubernetes evolves, features and APIs are regularly revisited and removed. New features may offer
an alternative or improved approach to solving existing problems, motivating the team to remove the
old approach.
We want to make sure you are aware of the changes coming in the Kubernetes 1.24 release. The release will
**deprecate** several (beta) APIs in favor of stable versions of the same APIs. The major change coming
in the Kubernetes 1.24 release is the
[removal of Dockershim](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2221-remove-dockershim).
This is discussed below and will be explored in more depth at release time. For an early look at the
changes coming in Kubernetes 1.24, take a look at the in-progress
[CHANGELOG](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.24.md).
## A note about Dockershim
It's safe to say that the removal receiving the most attention with the release of Kubernetes 1.24
is Dockershim. Dockershim was deprecated in v1.20. As noted in the [Kubernetes 1.20 changelog](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.20.md#deprecation):
"Docker support in the kubelet is now deprecated and will be removed in a future release. The kubelet
uses a module called "dockershim" which implements CRI support for Docker and it has seen maintenance
issues in the Kubernetes community." With the upcoming release of Kubernetes 1.24, the Dockershim will
finally be removed.
In the article [Don't Panic: Kubernetes and Docker](/blog/2020/12/02/dont-panic-kubernetes-and-docker/),
the authors succinctly captured the change's impact and encouraged users to remain calm:
> Docker as an underlying runtime is being deprecated in favor of runtimes that use the
> Container Runtime Interface (CRI) created for Kubernetes. Docker-produced images
> will continue to work in your cluster with all runtimes, as they always have.
Several guides have been created with helpful information about migrating from dockershim
to container runtimes that are directly compatible with Kubernetes. You can find them on the
[Migrating from dockershim](/docs/tasks/administer-cluster/migrating-from-dockershim/)
page in the Kubernetes documentation.
For more information about why Kubernetes is moving away from dockershim, check out the aptly
named: [Kubernetes is Moving on From Dockershim](/blog/2022/01/07/kubernetes-is-moving-on-from-dockershim/)
and the [updated dockershim removal FAQ](/blog/2022/02/17/dockershim-faq/).
Take a look at the [Is Your Cluster Ready for v1.24?](/blog/2022/03/31/ready-for-dockershim-removal/) post to learn about how to ensure your cluster continues to work after upgrading from v1.23 to v1.24.
## The Kubernetes API removal and deprecation process
Kubernetes contains a large number of components that evolve over time. In some cases, this
evolution results in APIs, flags, or entire features, being removed. To prevent users from facing
breaking changes, Kubernetes contributors adopted a feature [deprecation policy](/docs/reference/using-api/deprecation-policy/).
This policy ensures that stable APIs may only be deprecated when a newer stable version of that
same API is available and that APIs have a minimum lifetime as indicated by the following stability levels:
* Generally available (GA) or stable API versions may be marked as deprecated but must not be removed within a major version of Kubernetes.
* Beta or pre-release API versions must be supported for 3 releases after deprecation.
* Alpha or experimental API versions may be removed in any release without prior deprecation notice.
Removals follow the same deprecation policy regardless of whether an API is removed due to a beta feature
graduating to stable or because that API was not proven to be successful. Kubernetes will continue to make
sure migration options are documented whenever APIs are removed.
**Deprecated** APIs are those that have been marked for removal in a future Kubernetes release. **Removed**
APIs are those that are no longer available for use in current, supported Kubernetes versions after having
been deprecated. These removals have been superseded by newer, stable/generally available (GA) APIs.
## API removals, deprecations, and other changes for Kubernetes 1.24
* [Dynamic kubelet configuration](https://github.com/kubernetes/enhancements/issues/281): `DynamicKubeletConfig` is used to enable the dynamic configuration of the kubelet. The `DynamicKubeletConfig` flag was deprecated in Kubernetes 1.22. In v1.24, this feature gate will be removed from the kubelet. See [Reconfigure kubelet](/docs/tasks/administer-cluster/reconfigure-kubelet/). Refer to the ["Dynamic kubelet config is removed" KEP](https://github.com/kubernetes/enhancements/issues/281) for more information.
* [Dynamic log sanitization](https://github.com/kubernetes/kubernetes/pull/107207): The experimental dynamic log sanitization feature is deprecated and will be removed in v1.24. This feature introduced a logging filter that could be applied to all Kubernetes system components logs to prevent various types of sensitive information from leaking via logs. Refer to [KEP-1753: Kubernetes system components logs sanitization](https://github.com/kubernetes/enhancements/tree/master/keps/sig-instrumentation/1753-logs-sanitization#deprecation) for more information and an [alternative approach](https://github.com/kubernetes/enhancements/tree/master/keps/sig-instrumentation/1753-logs-sanitization#alternatives=).
* In-tree provisioner to CSI driver migration: This applies to a number of in-tree plugins, including [Portworx](https://github.com/kubernetes/enhancements/issues/2589). Refer to the [In-tree Storage Plugin to CSI Migration Design Doc](https://github.com/kubernetes/design-proposals-archive/blob/main/storage/csi-migration.md#background-and-motivations) for more information.
* [Removing Dockershim from kubelet](https://github.com/kubernetes/enhancements/issues/2221): the Container Runtime Interface (CRI) for Docker (i.e. Dockershim) is currently a built-in container runtime in the kubelet code base. It was deprecated in v1.20. As of v1.24, the kubelet will no longer have dockershim. Check out this blog on [what you need to do be ready for v1.24](/blog/2022/03/31/ready-for-dockershim-removal/).
* [Storage capacity tracking for pod scheduling](https://github.com/kubernetes/enhancements/issues/1472): The CSIStorageCapacity API supports exposing currently available storage capacity via CSIStorageCapacity objects and enhances scheduling of pods that use CSI volumes with late binding. In v1.24, the CSIStorageCapacity API will be stable. The API graduating to stable initates the deprecation of the v1beta1 CSIStorageCapacity API. Refer to the [Storage Capacity Constraints for Pod Scheduling KEP](https://github.com/kubernetes/enhancements/tree/master/keps/sig-storage/1472-storage-capacity-tracking) for more information.
* [The `master` label is no longer present on kubeadm control plane nodes](https://github.com/kubernetes/kubernetes/pull/107533). For new clusters, the label 'node-role.kubernetes.io/master' will no longer be added to control plane nodes, only the label 'node-role.kubernetes.io/control-plane' will be added. For more information, refer to [KEP-2067: Rename the kubeadm "master" label and taint](https://github.com/kubernetes/enhancements/tree/master/keps/sig-cluster-lifecycle/kubeadm/2067-rename-master-label-taint).
* [VolumeSnapshot v1beta1 CRD will be removed](https://github.com/kubernetes/enhancements/issues/177). Volume snapshot and restore functionality for Kubernetes and the [Container Storage Interface](https://github.com/container-storage-interface/spec/blob/master/spec.md) (CSI), which provides standardized APIs design (CRDs) and adds PV snapshot/restore support for CSI volume drivers, entered beta in v1.20. VolumeSnapshot v1beta1 was deprecated in v1.21 and is now unsupported. Refer to [KEP-177: CSI Snapshot](https://github.com/kubernetes/enhancements/tree/master/keps/sig-storage/177-volume-snapshot#kep-177-csi-snapshot) and [kubernetes-csi/external-snapshotter](https://github.com/kubernetes-csi/external-snapshotter/releases/tag/v4.1.0) for more information.
## What to do
### Dockershim removal
As stated earlier, there are several guides about
[Migrating from dockershim](/docs/tasks/administer-cluster/migrating-from-dockershim/).
You can start with [Finding what container runtime are on your nodes](/docs/tasks/administer-cluster/migrating-from-dockershim/find-out-runtime-you-use/).
If your nodes are using dockershim, there are other possible Docker Engine dependencies such as
Pods or third-party tools executing Docker commands or private registries in the Docker configuration file. You can follow the
[Check whether Dockershim deprecation affects you](/docs/tasks/administer-cluster/migrating-from-dockershim/check-if-dockershim-deprecation-affects-you/) guide to review possible
Docker Engine dependencies. Before upgrading to v1.24, you decide to either remain using Docker Engine and
[Migrate Docker Engine nodes from dockershim to cri-dockerd](/docs/tasks/administer-cluster/migrating-from-dockershim/migrate-dockershim-dockerd/) or migrate to a CRI-compatible runtime. Here's a guide to
[change the container runtime on a node from Docker Engine to containerd](/docs/tasks/administer-cluster/migrating-from-dockershim/change-runtime-containerd/).
### `kubectl convert`
The [`kubectl convert`](/docs/tasks/tools/included/kubectl-convert-overview/) plugin for `kubectl`
can be helpful to address migrating off deprecated APIs. The plugin facilitates the conversion of
manifests between different API versions, for example, from a deprecated to a non-deprecated API
version. More general information about the API migration process can be found in the [Deprecated API Migration Guide](/docs/reference/using-api/deprecation-guide/).
Follow the [install `kubectl convert` plugin](https://kubernetes.io/docs/tasks/tools/install-kubectl-linux/#install-kubectl-convert-plugin)
documentation to download and install the `kubectl-convert` binary.
### Looking ahead
The Kubernetes 1.25 and 1.26 releases planned for later this year will stop serving beta versions
of several currently stable Kubernetes APIs. The v1.25 release will also remove PodSecurityPolicy,
which was deprecated with Kubernetes 1.21 and will not graduate to stable. See [PodSecurityPolicy
Deprecation: Past, Present, and Future](/blog/2021/04/06/podsecuritypolicy-deprecation-past-present-and-future/) for more information.
The official [list of API removals planned for Kubernetes 1.25](/docs/reference/using-api/deprecation-guide/#v1-25) is:
* The beta CronJob API (batch/v1beta1)
* The beta EndpointSlice API (discovery.k8s.io/v1beta1)
* The beta Event API (events.k8s.io/v1beta1)
* The beta HorizontalPodAutoscaler API (autoscaling/v2beta1)
* The beta PodDisruptionBudget API (policy/v1beta1)
* The beta PodSecurityPolicy API (policy/v1beta1)
* The beta RuntimeClass API (node.k8s.io/v1beta1)
The official [list of API removals planned for Kubernetes 1.26](/docs/reference/using-api/deprecation-guide/#v1-26) is:
* The beta FlowSchema and PriorityLevelConfiguration APIs (flowcontrol.apiserver.k8s.io/v1beta1)
* The beta HorizontalPodAutoscaler API (autoscaling/v2beta2)
### Want to know more?
Deprecations are announced in the Kubernetes release notes. You can see the announcements of pending deprecations in the release notes for:
* [Kubernetes 1.21](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.21.md#deprecation)
* [Kubernetes 1.22](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.22.md#deprecation)
* [Kubernetes 1.23](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.23.md#deprecation)
* We will formally announce the deprecations that come with [Kubernetes 1.24](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.24.md#deprecation) as part of the CHANGELOG for that release.
For information on the process of deprecation and removal, check out the official Kubernetes [deprecation policy](/docs/reference/using-api/deprecation-policy/#deprecating-parts-of-the-api) document.
@@ -0,0 +1,155 @@
---
layout: blog
title: 'Increasing the security bar in Ingress-NGINX v1.2.0'
date: 2022-04-28
slug: ingress-nginx-1-2-0
---
**Authors:** Ricardo Katz (VMware), James Strong (Chainguard)
The [Ingress](/docs/concepts/services-networking/ingress/) may be one of the most targeted components
of Kubernetes. An Ingress typically defines an HTTP reverse proxy, exposed to the Internet, containing
multiple websites, and with some privileged access to Kubernetes API (such as to read Secrets relating to
TLS certificates and their private keys).
While it is a risky component in your architecture, it is still the most popular way to properly expose your services.
Ingress-NGINX has been part of security assessments that figured out we have a big problem: we don't
do all proper sanitization before turning the configuration into an `nginx.conf` file, which may lead to information
disclosure risks.
While we understand this risk and the real need to fix this, it's not an easy process to do, so we took another approach to reduce (but not remove!) this risk in the current (v1.2.0) release.
## Meet Ingress NGINX v1.2.0 and the chrooted NGINX process
One of the main challenges is that Ingress-NGINX runs the web proxy server (NGINX) alongside the Ingress
controller (the component that has access to Kubernetes API that and that creates the `nginx.conf` file).
So, NGINX does have the same access to the filesystem of the controller (and Kubernetes service account token, and other configurations from the container). While splitting those components is our end goal, the project needed a fast response; that lead us to the idea of using `chroot()`.
Let's take a look into what an Ingress-NGINX container looked like before this change:
![Ingress NGINX pre chroot](ingress-pre-chroot.png)
As we can see, the same container (not the Pod, the container!) that provides HTTP Proxy is the one that watches Ingress objects and writes the Container Volume
Now, meet the new architecture:
![Ingress NGINX post chroot](ingress-post-chroot.png)
What does all of this mean? A basic summary is: that we are isolating the NGINX service as a container inside the
controller container.
While this is not strictly true, to understand what was done here, it's good to understand how
Linux containers (and underlying mechanisms such as kernel namespaces) work.
You can read about cgroups in the Kubernetes glossary: [`cgroup`](https://kubernetes.io/docs/reference/glossary/?fundamental=true#term-cgroup) and learn more about cgroups interact with namespaces in the NGINX project article
[What Are Namespaces and cgroups, and How Do They Work?](https://www.nginx.com/blog/what-are-namespaces-cgroups-how-do-they-work/).
(As you read that, bear in mind that Linux kernel namespaces are a different thing from
[Kubernetes namespaces](/docs/concepts/overview/working-with-objects/namespaces/)).
## Skip the talk, what do I need to use this new approach?
While this increases the security, we made this feature an opt-in in this release so you can have
time to make the right adjustments in your environment(s). This new feature is only available from
release v1.2.0 of the Ingress-NGINX controller.
There are two required changes in your deployments to use this feature:
* Append the suffix "-chroot" to the container image name. For example: `gcr.io/k8s-staging-ingress-nginx/controller-chroot:v1.2.0`
* In your Pod template for the Ingress controller, find where you add the capability `NET_BIND_SERVICE` and add the capability `SYS_CHROOT`. After you edit the manifest, you'll see a snippet like:
```yaml
capabilities:
drop:
- ALL
add:
- NET_BIND_SERVICE
- SYS_CHROOT
```
If you deploy the controller using the official Helm chart then change the following setting in
`values.yaml`:
```yaml
controller:
image:
chroot: true
```
Ingress controllers are normally set up cluster-wide (the IngressClass API is cluster scoped). If you manage the
Ingress-NGINX controller but you're not the overall cluster operator, then check with your cluster admin about
whether you can use the `SYS_CHROOT` capability, **before** you enable it in your deployment.
## OK, but how does this increase the security of my Ingress controller?
Take the following configuration snippet and imagine, for some reason it was added to your `nginx.conf`:
```
location /randomthing/ {
alias /;
autoindex on;
}
```
If you deploy this configuration, someone can call `http://website.example/randomthing` and get some listing (and access) to the whole filesystem of the Ingress controller.
Now, can you spot the difference between chrooted and non chrooted Nginx on the listings below?
| Without extra `chroot()` | With extra `chroot()` |
|----------------------------|--------|
| `bin` | `bin` |
| `dev` | `dev` |
| `etc` | `etc` |
| `home` | |
| `lib` | `lib` |
| `media` | |
| `mnt` | |
| `opt` | `opt` |
| `proc` | `proc` |
| `root` | |
| `run` | `run` |
| `sbin` | |
| `srv` | |
| `sys` | |
| `tmp` | `tmp` |
| `usr` | `usr` |
| `var` | `var` |
| `dbg` | |
| `nginx-ingress-controller` | |
| `wait-shutdown` | |
The one in left side is not chrooted. So NGINX has full access to the filesystem. The one in right side is chrooted, so a new filesystem with only the required files to make NGINX work is created.
## What about other security improvements in this release?
We know that the new `chroot()` mechanism helps address some portion of the risk, but still, someone
can try to inject commands to read, for example, the `nginx.conf` file and extract sensitive information.
So, another change in this release (this is opt-out!) is the _deep inspector_.
We know that some directives or regular expressions may be dangerous to NGINX, so the deep inspector
checks all fields from an Ingress object (during its reconciliation, and also with a
[validating admission webhook](/docs/reference/access-authn-authz/admission-controllers/#validatingadmissionwebhook))
to verify if any fields contains these dangerous directives.
The ingress controller already does this for annotations, and our goal is to move this existing validation to happen inside
deep inspection as part of a future release.
You can take a look into the existing rules in [https://github.com/kubernetes/ingress-nginx/blob/main/internal/ingress/inspector/rules.go](https://github.com/kubernetes/ingress-nginx/blob/main/internal/ingress/inspector/rules.go).
Due to the nature of inspecting and matching all strings within relevant Ingress objects, this new feature may consume a bit more CPU. You can disable it by running the ingress controller with the command line argument `--deep-inspect=false`.
## What's next?
This is not our final goal. Our final goal is to split the control plane and the data plane processes.
In fact, doing so will help us also achieve a [Gateway](https://gateway-api.sigs.k8s.io/) API implementation,
as we may have a different controller as soon as it "knows" what to provide to the data plane
(we need some help here!!)
Some other projects in Kubernetes already take this approach
(like [KPNG](https://github.com/kubernetes-sigs/kpng), the proposed replacement for `kube-proxy`),
and we plan to align with them and get the same experience for Ingress-NGINX.
## Further reading
If you want to take a look into how chrooting was done in Ingress NGINX, take a look
into [https://github.com/kubernetes/ingress-nginx/pull/8337](https://github.com/kubernetes/ingress-nginx/pull/8337)
The release v1.2.0 containing all the changes can be found at
[https://github.com/kubernetes/ingress-nginx/releases/tag/controller-v1.2.0](https://github.com/kubernetes/ingress-nginx/releases/tag/controller-v1.2.0)
Binary file not shown.

After

Width:  |  Height:  |  Size: 59 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 51 KiB

@@ -0,0 +1,319 @@
---
layout: blog
title: "Frontiers, fsGroups and frogs: the Kubernetes 1.23 release interview"
date: 2022-04-29
---
**Author**: Craig Box (Google)
One of the highlights of hosting the weekly [Kubernetes Podcast from Google](https://kubernetespodcast.com/) is talking to the release managers for each new Kubernetes version. The release team is constantly refreshing. Many working their way from small documentation fixes, step up to shadow roles, and then eventually lead a release.
As we prepare for the 1.24 release next week, [in accordance with long-standing tradition](https://www.google.com/search?q=%22release+interview%22+site%3Akubernetes.io%2Fblog), I'm pleased to bring you a look back at the story of 1.23. The release was led by [Rey Lejano](https://twitter.com/reylejano), a Field Engineer at SUSE. [I spoke to Rey](https://kubernetespodcast.com/episode/167-kubernetes-1.23/) in December, as he was awaiting the birth of his first child.
Make sure you [subscribe, wherever you get your podcasts](https://kubernetespodcast.com/subscribe/), so you hear all our stories from the Cloud Native community, including the story of 1.24 next week.
*This transcript has been lightly edited and condensed for clarity.*
---
**CRAIG BOX: I'd like to start with what is, of course, on top of everyone's mind at the moment. Let's talk African clawed frogs!**
REY LEJANO: [CHUCKLES] Oh, you mean [Xenopus lavis](https://en.wikipedia.org/wiki/African_clawed_frog), the scientific name for the African clawed frog?
**CRAIG BOX: Of course.**
REY LEJANO: Not many people know, but my background and my degree is actually in microbiology, from the University of California Davis. I did some research for about four years in biochemistry, in a biochemistry lab, and I [do have a research paper published](https://www.sciencedirect.com/science/article/pii/). It's actually on glycoproteins, particularly something called "cortical granule lectin". We used frogs, because they generate lots and lots of eggs, from which we can extract the protein. That protein prevents polyspermy. When the sperm goes into the egg, the egg releases a glycoprotein, cortical granule lectin, to the membrane, and prevents any other sperm from going inside the egg.
**CRAIG BOX: Were you able to take anything from the testing that we did on frogs and generalize that to higher-order mammals, perhaps?**
REY LEJANO: Yes. Since mammals also have cortical granule lectin, we were able to analyze both the convergence and the evolutionary pattern, not just from multiple species of frogs, but also into mammals as well.
**CRAIG BOX: Now, there's a couple of different threads to unravel here. When you were young, what led you into the fields of biology, and perhaps more the technical side of it?**
REY LEJANO: I think it was mostly from family, since I do have a family history in the medical field that goes back generations. So I kind of felt like that was the natural path going into college.
**CRAIG BOX: Now, of course, you're working in a more abstract tech field. What led you out of microbiology?**
REY LEJANO: [CHUCKLES] Well, I've always been interested in tech. Taught myself a little programming when I was younger, before high school, did some web dev stuff. Just kind of got burnt out being in a lab. I was literally in the basement. I had a great opportunity to join a consultancy that specialized in [ITIL](https://www.axelos.com/certifications/itil-service-management/what-is-itil). I actually started off with application performance management, went into monitoring, went into operation management and also ITIL, which is aligning your IT asset management and service managements with business services. Did that for a good number of years, actually.
**CRAIG BOX: It's very interesting, as people describe the things that they went through and perhaps the technologies that they worked on, you can pretty much pinpoint how old they might be. There's a lot of people who come into tech these days that have never heard of ITIL. They have no idea what it is. It's basically just SRE with more process.**
REY LEJANO: Yes, absolutely. It's not very cloud native. [CHUCKLES]
**CRAIG BOX: Not at all.**
REY LEJANO: You don't really hear about it in the cloud native landscape. Definitely, you can tell someone's been in the field for a little bit, if they specialize or have worked with ITIL before.
**CRAIG BOX: You mentioned that you wanted to get out of the basement. That is quite often where people put the programmers. Did they just give you a bit of light in the new basement?**
REY LEJANO: [LAUGHS] They did give us much better lighting. Able to get some vitamin D sometimes, as well.
**CRAIG BOX: To wrap up the discussion about your previous career — over the course of the last year, with all of the things that have happened in the world, I could imagine that microbiology skills may be more in demand than perhaps they were when you studied them?**
REY LEJANO: Oh, absolutely. I could definitely see a big increase of numbers of people going into the field. Also, reading what's going on with the world currently kind of brings back all the education I've learned in the past, as well.
**CRAIG BOX: Do you keep in touch with people you went through school with?**
REY LEJANO: Just some close friends, but not in the microbiology field.
**CRAIG BOX: One thing that I think will probably happen as a result of the pandemic is a renewed interest in some of these STEM fields. It will be interesting to see what impact that has on society at large.**
REY LEJANO: Yeah. I think that'll be great.
**CRAIG BOX: You mentioned working at a consultancy doing IT management, application performance monitoring, and so on. When did Kubernetes come into your professional life?**
REY LEJANO: One of my good friends at the company I worked at, left in mid-2015. He went on to a company that was pretty heavily into Docker. He taught me a little bit. I did my first "docker run" around 2015, maybe 2016. Then, one of the applications we were using for the ITIL framework was containerized around 2018 or so, also in Kubernetes. At that time, it was pretty buggy. That was my initial introduction to Kubernetes and containerised applications.
Then I left that company, and I actually joined my friend over at [RX-M](https://rx-m.com/), which is a cloud native consultancy and training firm. They specialize in Docker and Kubernetes. I was able to get my feet wet. I got my CKD, got my CKA as well. And they were really, really great at encouraging us to learn more about Kubernetes and also to be involved in the community.
**CRAIG BOX: You will have seen, then, the life cycle of people adopting Kubernetes and containerization at large, through your own initial journey and then through helping customers. How would you characterize how that journey has changed from the early days to perhaps today?**
REY LEJANO: I think the early days, there was a lot of questions of, why do I have to containerize? Why can't I just stay with virtual machines?
**CRAIG BOX: It's a line item on your CV.**
REY LEJANO: [CHUCKLES] It is. And nowadays, I think people know the value of using containers, of orchestrating containers with Kubernetes. I don't want to say "jumping on the bandwagon", but it's become the de-facto standard to orchestrate containers.
**CRAIG BOX: It's not something that a consultancy needs to go out and pitch to customers that they should be doing. They're just taking it as, that will happen, and starting a bit further down the path, perhaps.**
REY LEJANO: Absolutely.
**CRAIG BOX: Working at a consultancy like that, how much time do you get to work on improving process, perhaps for multiple customers, and then looking at how you can upstream that work, versus paid work that you do for just an individual customer at a time?**
REY LEJANO: Back then, it would vary. They helped me introduce myself, and I learned a lot about the cloud native landscape and Kubernetes itself. They helped educate me as to how the cloud native landscape, and the tools around it, can be used together. My boss at that company, Randy, he actually encouraged us to start contributing upstream, and encouraged me to join the release team. He just said, this is a great opportunity. Definitely helped me with starting with the contributions early on.
**CRAIG BOX: Was the release team the way that you got involved with upstream Kubernetes contribution?**
REY LEJANO: Actually, no. My first contribution was with SIG Docs. I met Taylor Dolezal — he was the release team lead for 1.19, but he is involved with SIG Docs as well. I met him at KubeCon 2019, I sat at his table during a luncheon. I remember Paris Pittman was hosting this luncheon at the Marriott. Taylor says he was involved with SIG Docs. He encouraged me to join. I started joining into meetings, started doing a few drive-by PRs. That's what we call them — drive-by — little typo fixes. Then did a little bit more, started to send better or higher quality pull requests, and also reviewing PRs.
**CRAIG BOX: When did you first formally take your release team role?**
REY LEJANO: That was in [1.18](https://github.com/kubernetes/sig-release/blob/master/releases/release-1.18/release_team.md), in December. My boss at the time encouraged me to apply. I did, was lucky enough to get accepted for the release notes shadow. Then from there, stayed in with release notes for a few cycles, then went into Docs, naturally then led Docs, then went to Enhancements, and now I'm the release lead for 1.23.
**CRAIG BOX: I don't know that a lot of people think about what goes into a good release note. What would you say does?**
REY LEJANO: [CHUCKLES] You have to tell the end user what has changed or what effect that they might see in the release notes. It doesn't have to be highly technical. It could just be a few lines, and just saying what has changed, what they have to do if they have to do anything as well.
**CRAIG BOX: As you moved through the process of shadowing, how did you learn from the people who were leading those roles?**
REY LEJANO: I said this a few times when I was the release lead for this cycle. You get out of the release team as much as you put in, or it directly aligns to how much you put in. I learned a lot. I went into the release team having that mindset of learning from the role leads, learning from the other shadows, as well. That's actually a saying that my first role lead told me. I still carry it to heart, and that was back in 1.18. That was Eddie, in the very first meeting we had, and I still carry it to heart.
**CRAIG BOX: You, of course, were [the release lead for 1.23](https://github.com/kubernetes/sig-release/tree/master/releases/release-1.23). First of all, congratulations on the release.**
REY LEJANO: Thank you very much.
**CRAIG BOX: The theme for this release is [The Next Frontier](https://kubernetes.io/blog/2021/12/07/kubernetes-1-23-release-announcement/). Tell me the story of how we came to the theme and then the logo.**
REY LEJANO: The Next Frontier represents a few things. It not only represents the next enhancements in this release, but Kubernetes itself also has a history of Star Trek references. The original codename for Kubernetes was Project Seven, a reference to Seven of Nine, originally from Star Trek Voyager. Also the seven spokes in the helm in the logo of Kubernetes as well. And, of course, Borg, the predecessor to Kubernetes.
The Next Frontier continues that Star Trek reference. It's a fusion of two titles in the Star Trek universe. One is [Star Trek V, the Final Frontier](https://en.wikipedia.org/wiki/Star_Trek_V:_The_Final_Frontier), and the Star Trek: The Next Generation.
**CRAIG BOX: Do you have any opinion on the fact that Star Trek V was an odd-numbered movie, and they are [canonically referred to as being lesser than the even-numbered ones](https://screenrant.com/star-trek-movies-odd-number-curse-explained/)?**
REY LEJANO: I can't say, because I am such a sci-fi nerd that I love all of them even though they're bad. Even the post-Next Generation movies, after the series, I still liked all of them, even though I know some weren't that great.
**CRAIG BOX: Am I right in remembering that Star Trek V was the one directed by William Shatner?**
REY LEJANO: Yes, that is correct.
**CRAIG BOX: I think that says it all.**
REY LEJANO: [CHUCKLES] Yes.
**CRAIG BOX: Now, I understand that the theme comes from a part of the [SIG Release charter](https://github.com/kubernetes/community/blob/master/sig-release/charter.md)?**
REY LEJANO: Yes. There's a line in the SIG Release charter, "ensure there is a consistent group of community members in place to support the release process across time." With the release team, we have new shadows that join every single release cycle. With this, we're growing with this community. We're growing the release team members. We're growing SIG Release. We're growing the Kubernetes community itself. For a lot of people, this is their first time contributing to open source, so that's why I say it's their new open source frontier.
**CRAIG BOX: And the logo is obviously very Star Trek-inspired. It sort of surprised me that it took that long for someone to go this route.**
REY LEJANO: I was very surprised as well. I had to relearn Adobe Illustrator to create the logo.
**CRAIG BOX: This your own work, is it?**
REY LEJANO: This is my own work.
**CRAIG BOX: It's very nice.**
REY LEJANO: Thank you very much. Funny, the galaxy actually took me the longest time versus the ship. Took me a few days to get that correct. I'm always fine-tuning it, so there might be a final change when this is actually released.
**CRAIG BOX: No frontier is ever truly final.**
REY LEJANO: True, very true.
**CRAIG BOX: Moving now from the theme of the release to the substance, perhaps, what is new in 1.23?**
REY LEJANO: We have 47 enhancements. I'm going to run through most of the stable ones, if not all of them, some of the key Beta ones, and a few of the Alpha enhancements for 1.23.
One of the key enhancements is [dual-stack IPv4/IPv6](https://github.com/kubernetes/enhancements/issues/563), which went GA in 1.23.
Some background info: dual-stack was introduced as Alpha in 1.15. You probably saw a keynote at KubeCon 2019. Back then, the way dual-stack worked was that you needed two services — you needed a service per IP family. You would need a service for IPv4 and a service for IPv6. It was refactored in 1.20. In 1.21, it was in Beta; clusters were enabled to be dual-stack by default.
And then in 1.23 we did remove the IPv6 dual-stack feature flag. It's not mandatory to use dual-stack. It's actually not "default" still. The pods, the services still default to single-stack. There are some requirements to be able to use dual-stack. The nodes have to be routable on IPv4 and IPv6 network interfaces. You need a CNI plugin that supports dual-stack. The pods themselves have to be configured to be dual-stack. And the services need the ipFamilyPolicy field to specify prefer dual-stack, or require dual-stack.
**CRAIG BOX: This sounds like there's an implication in this that v4 is still required. Do you see a world where we can actually move to v6-only clusters?**
REY LEJANO: I think we'll be talking about IPv4 and IPv6 for many, many years to come. I remember a long time ago, they kept saying "it's going to be all IPv6", and that was decades ago.
**CRAIG BOX: I think I may have mentioned on the show before, but there was [a meeting in London that Vint Cerf attended](https://www.youtube.com/watch?v=AEaJtZVimqs), and he gave a public presentation at the time to say, now is the time of v6. And that was 10 years ago at least. It's still not the time of v6, and my desktop still doesn't have Linux on it. One day.**
REY LEJANO: [LAUGHS] In my opinion, that's one of the big key features that went stable for 1.23.
One of the other highlights of 1.23 is [pod security admission going to Beta](/blog/2021/12/09/pod-security-admission-beta/). I know this feature is going to Beta, but I highlight this because as some people might know, PodSecurityPolicy, which was deprecated in 1.21, is targeted to be removed in 1.25. Pod security admission replaces pod security policy. It's an admission controller. It evaluates the pods against a predefined set of pod security standards to either admit or deny the pod for running.
There's three levels of pod security standards. Privileged, that's totally open. Baseline, known privileges escalations are minimized. Or Restricted, which is hardened. And you could set pod security standards either to run in three modes, which is enforce: reject any pods that are in violation; to audit: pods are allowed to be created, but the violations are recorded; or warn: it will send a warning message to the user, and the pod is allowed.
**CRAIG BOX: You mentioned there that PodSecurityPolicy is due to be deprecated in two releases' time. Are we lining up these features so that pod security admission will be GA at that time?**
REY LEJANO: Yes. Absolutely. I'll talk about that for another feature in a little bit as well. There's also another feature that went to GA. It was an API that went to GA, and therefore the Beta API is now deprecated. I'll talk about that a little bit.
**CRAIG BOX: All right. Let's talk about what's next on the list.**
REY LEJANO: Let's move on to more stable enhancements. One is the [TTL controller](https://github.com/kubernetes/enhancements/issues/592). This cleans up jobs and pods after the jobs are finished. There is a TTL timer that starts when the job or pod is finished. This TTL controller watches all the jobs, and ttlSecondsAfterFinished needs to be set. The controller will see if the ttlSecondsAfterFinished, combined with the last transition time, if it's greater than now. If it is, then it will delete the job and the pods of that job.
**CRAIG BOX: Loosely, it could be called a garbage collector?**
REY LEJANO: Yes. Garbage collector for pods and jobs, or jobs and pods.
**CRAIG BOX: If Kubernetes is truly becoming a programming language, it of course has to have a garbage collector implemented.**
REY LEJANO: Yeah. There's another one, too, coming in Alpha. [CHUCKLES]
**CRAIG BOX: Tell me about that.**
REY LEJANO: That one is coming in in Alpha. It's actually one of my favorite features, because there's only a few that I'm going to highlight today. [PVCs for StafeulSet will be cleaned up](https://github.com/kubernetes/enhancements/issues/1847). It will auto-delete PVCs created by StatefulSets, when you delete that StatefulSet.
**CRAIG BOX: What's next on our tour of stable features?**
REY LEJANO: Next one is, [skip volume ownership change goes to stable](https://github.com/kubernetes/enhancements/issues/695). This is from SIG Storage. There are times when you're running a stateful application, like many databases, they're sensitive to permission bits changing underneath. Currently, when a volume is bind mounted inside the container, the permissions of that volume will change recursively. It might take a really long time.
Now, there's a field, the fsGroupChangePolicy, which allows you, as a user, to tell Kubernetes how you want the permission and ownership change for that volume to happen. You can set it to always, to always change permissions, or just on mismatch, to only do it when the permission ownership changes at the top level is different from what is expected.
**CRAIG BOX: It does feel like a lot of these enhancements came from a very particular use case where someone said, "hey, this didn't work for me and I've plumbed in a feature that works with exactly the thing I need to have".**
REY LEJANO: Absolutely. People create issues for these, then create Kubernetes enhancement proposals, and then get targeted for releases.
**CRAIG BOX: Another GA feature in this release — ephemeral volumes.**
REY LEJANO: We've always been able to use empty dir for ephemeral volumes, but now we could actually have [ephemeral inline volumes](https://github.com/kubernetes/enhancements/issues/1698), meaning that you could take your standard CSI driver and be able to use ephemeral volumes with it.
**CRAIG BOX: And, a long time coming, [CronJobs](https://github.com/kubernetes/enhancements/issues/19).**
REY LEJANO: CronJobs is a funny one, because it was stable before 1.23. For 1.23, it was still tracked,but it was just cleaning up some of the old controller. With CronJobs, there's a v2 controller. What was cleaned up in 1.23 is just the old v1 controller.
**CRAIG BOX: Were there any other duplications or major cleanups of note in this release?**
REY LEJANO: Yeah. There were a few you might see in the major themes. One's a little tricky, around FlexVolumes. This is one of the efforts from SIG Storage. They have an effort to migrate in-tree plugins to CSI drivers. This is a little tricky, because FlexVolumes were actually deprecated in November 2020. We're [formally announcing it in 1.23](https://github.com/kubernetes/community/blob/master/sig-storage/volume-plugin-faq.md#kubernetes-volume-plugin-faq-for-storage-vendors).
**CRAIG BOX: FlexVolumes, in my mind, predate CSI as a concept. So it's about time to get rid of them.**
REY LEJANO: Yes, it is. There's another deprecation, just some [klog specific flags](https://kubernetes.io/docs/concepts/cluster-administration/system-logs/#klog), but other than that, there are no other big deprecations in 1.23.
**CRAIG BOX: The buzzword of the last KubeCon, and in some ways the theme of the last 12 months, has been secure software supply chain. What work is Kubernetes doing to improve in this area?**
REY LEJANO: For 1.23, Kubernetes is now SLSA compliant at Level 1, which means that provenance attestation files that describe the staging and release phases of the release process are satisfactory for the SLSA framework.
**CRAIG BOX: What needs to happen to step up to further levels?**
REY LEJANO: Level 1 means a few things — that the build is scripted; that the provenance is available, meaning that the artifacts are verified and they're handed over from one phase to the next; and describes how the artifact is produced. Level 2 means that the source is version-controlled, which it is, provenance is authenticated, provenance is service-generated, and there is a build service. There are four levels of SLSA compliance.
**CRAIG BOX: It does seem like the levels were largely influenced by what it takes to build a big, secure project like this. It doesn't seem like it will take a lot of extra work to move up to verifiable provenance, for example. There's probably just a few lines of script required to meet many of those requirements.**
REY LEJANO: Absolutely. I feel like we're almost there; we'll see what will come out of 1.24. And I do want to give a big shout-out to SIG Release and Release Engineering, primarily to Adolfo García Veytia, who is aka Puerco on GitHub and on Slack. He's been driving this forward.
**CRAIG BOX: You've mentioned some APIs that are being graduated in time to replace their deprecated version. Tell me about the new HPA API.**
REY LEJANO: The [horizontal pod autoscaler v2 API](https://github.com/kubernetes/enhancements/issues/2702), is now stable, which means that the v2beta2 API is deprecated. Just for everyone's knowledge, the v1 API is not being deprecated. The difference is that v2 adds support for multiple and custom metrics to be used for HPA.
**CRAIG BOX: There's also now a facility to validate my CRDs with an expression language.**
REY LEJANO: Yeah. You can use the [Common Expression Language, or CEL](https://github.com/google/cel-spec), to validate your CRDs, so you no longer need to use webhooks. This also makes the CRDs more self-contained and declarative, because the rules are now kept within the CRD object definition.
**CRAIG BOX: What new features, perhaps coming in Alpha or Beta, have taken your interest?**
REY LEJANO: Aside from pod security policies, I really love [ephemeral containers](https://github.com/kubernetes/enhancements/issues/277) supporting kubectl debug. It launches an ephemeral container and a running pod, shares those pod namespaces, and you can do all your troubleshooting with just running kubectl debug.
**CRAIG BOX: There's also been some interesting changes in the way that events are handled with kubectl.**
REY LEJANO: Yeah. kubectl events has always had some issues, like how things weren't sorted. [kubectl events improved](https://github.com/kubernetes/enhancements/issues/1440) that so now you can do `--watch`, and it will also sort with the `--watch` option as well. That is something new. You can actually combine fields and custom columns. And also, you can list events in the timeline with doing the last N number of minutes. And you can also sort events using other criteria as well.
**CRAIG BOX: You are a field engineer at SUSE. Are there any things that are coming in that your individual customers that you deal with are looking out for?**
REY LEJANO: More of what I look out for to help the customers.
**CRAIG BOX: Right.**
REY LEJANO: I really love kubectl events. Really love the PVCs being cleaned up with StatefulSets. Most of it's for selfish reasons that it will improve troubleshooting efforts. [CHUCKLES]
**CRAIG BOX: I have always hoped that a release team lead would say to me, "yes, I have selfish reasons. And I finally got something I wanted in."**
REY LEJANO: [LAUGHS]
**CRAIG BOX: Perhaps I should run to be release team lead, just so I can finally get init containers fixed once and for all.**
REY LEJANO: Oh, init containers, I've been looking for that for a while. I've actually created animated GIFs on how init containers will be run with that Kubernetes enhancement proposal, but it's halted currently.
**CRAIG BOX: One day.**
REY LEJANO: One day. Maybe I shouldn't stay halted.
**CRAIG BOX: You mentioned there are obviously the things you look out for. Are there any things that are coming down the line, perhaps Alpha features or maybe even just proposals you've seen lately, that you're personally really looking forward to seeing which way they go?**
REY LEJANO: Yeah. Oone is a very interesting one, it affects the whole community, so it's not just for personal reasons. As you may have known, Dockershim is deprecated. And we did release a blog that it will be removed in 1.24.
**CRAIG BOX: Scared a bunch of people.**
REY LEJANO: Scared a bunch of people. From a survey, we saw that a lot of people are still using Docker and Dockershim. One of the enhancements for 1.23 is, [kubelet CRI goes to Beta](https://github.com/kubernetes/enhancements/issues/2040). This promotes the CRI API, which is required. This had to be in Beta for Dockershim to be removed in 1.24.
**CRAIG BOX: Now, in the last release team lead interview, [we spoke with Savitha Raghunathan](https://kubernetespodcast.com/episode/157-kubernetes-1.22/), and she talked about what she would advise you as her successor. It was to look out for the mental health of the team members. How were you able to take that advice on board?**
REY LEJANO: That was great advice from Savitha. A few things I've made note of with each release team meeting. After each release team meeting, I stop the recording, because we do record all the meetings and post them on YouTube. And I open up the floor to anyone who wants to say anything that's not recorded, that's not going to be on the agenda. Also, I tell people not to work on weekends. I broke this rule once, but other than that, I told people it could wait. Just be mindful of your mental health.
**CRAIG BOX: It's just been announced that [James Laverack from Jetstack](https://twitter.com/JamesLaverack/status/1466834312993644551) will be the release team lead for 1.24. James and I shared an interesting Mexican dinner at the last KubeCon in San Diego.**
REY LEJANO: Oh, nice. I didn't know you knew James.
**CRAIG BOX: The British tech scene. We're a very small world. What will your advice to James be?**
REY LEJANO: What I would tell James for 1.24 is use teachable moments in the release team meetings. When you're a shadow for the first time, it's very daunting. It's very difficult, because you don't know the repos. You don't know the release process. Everyone around you seems like they know the release process, and very familiar with what the release process is. But as a first-time shadow, you don't know all the vernacular for the community. I just advise to use teachable moments. Take a few minutes in the release team meetings to make it a little easier for new shadows to ramp up and to be familiar with the release process.
**CRAIG BOX: Has there been major evolution in the process in the time that you've been involved? Or do you think that it's effectively doing what it needs to do?**
REY LEJANO: It's always evolving. I remember my first time in release notes, 1.18, we said that our goal was to automate and program our way out so that we don't have a release notes team anymore. That's changed [CHUCKLES] quite a bit. Although there's been significant advancements in the release notes process by Adolfo and also James, they've created a subcommand in krel to generate release notes.
But nowadays, all their release notes are richer. Still not there at the automation process yet. Every release cycle, there is something a little bit different. For this release cycle, we had a production readiness review deadline. It was a soft deadline. A production readiness review is a review by several people in the community. It's actually been required since 1.21, and it ensures that the enhancements are observable, scalable, supportable, and it's safe to operate in production, and could also be disabled or rolled back. In 1.23, we had a deadline to have the production readiness review completed by a specific date.
**CRAIG BOX: How have you found the change of schedule to three releases per year rather than four?**
REY LEJANO: Moving to three releases a year from four, in my opinion, has been an improvement, because we support the last three releases, and now we can actually support the last releases in a calendar year instead of having 9 months out of 12 months of the year.
**CRAIG BOX: The next event on the calendar is a [Kubernetes contributor celebration](https://www.kubernetes.dev/events/kcc2021/) starting next Monday. What can we expect from that event?**
REY LEJANO: This is our second time running this virtual event. It's a virtual celebration to recognize the whole community and all of our accomplishments of the year, and also contributors. There's a number of events during this week of celebration. It starts the week of December 13.
There's events like the Kubernetes Contributor Awards, where SIGs honor and recognize the hard work of the community and contributors. There's also a DevOps party game as well. There is a cloud native bake-off. I do highly suggest people to go to [kubernetes.dev/celebration](https://www.kubernetes.dev/events/past-events/2021/kcc2021/) to learn more.
**CRAIG BOX: How exactly does one judge a virtual bake-off?**
REY LEJANO: That I don't know. [CHUCKLES]
**CRAIG BOX: I tasted my scones. I think they're the best. I rate them 10 out of 10.**
REY LEJANO: Yeah. That is very difficult to do virtually. I would have to say, probably what the dish is, how closely it is tied with Kubernetes or open source or to CNCF. There's a few judges. I know Josh Berkus and Rin Oliver are a few of the judges running the bake-off.
**CRAIG BOX: Yes. We spoke with Josh about his love of the kitchen, and so he seems like a perfect fit for that role.**
REY LEJANO: He is.
**CRAIG BOX: Finally, your wife and yourself are expecting your first child in January. Have you had a production readiness review for that?**
REY LEJANO: I think we failed that review. [CHUCKLES]
**CRAIG BOX: There's still time.**
REY LEJANO: We are working on refactoring. We're going to refactor a little bit in December, and `--apply` again.
---
_[Rey Lejano](https://twitter.com/reylejano) is a field engineer at SUSE, by way of Rancher Labs, and was the release team lead for Kubernetes 1.23. He is now also a co-chair for SIG Docs. His son Liam is now 3 and a half months old._
_You can find the [Kubernetes Podcast from Google](http://www.kubernetespodcast.com/) at [@KubernetesPod](https://twitter.com/KubernetesPod) on Twitter, and you can [subscribe](https://kubernetespodcast.com/subscribe/) so you never miss an episode._
@@ -0,0 +1,25 @@
---
layout: blog
title: "Dockershim: The Historical Context"
date: 2022-05-03
slug: dockershim-historical-context
---
**Author:** Kat Cosgrove
Dockershim has been removed as of Kubernetes v1.24, and this is a positive move for the project. However, context is important for fully understanding something, be it socially or in software development, and this deserves a more in-depth review. Alongside the dockershim removal in Kubernetes v1.24, weve seen some confusion (sometimes at a panic level) and dissatisfaction with this decision in the community, largely due to a lack of context around this removal. The decision to deprecate and eventually remove dockershim from Kubernetes was not made quickly or lightly. Still, its been in the works for so long that many of todays users are newer than that decision, and certainly newer than the choices that led to the dockershim being necessary in the first place.
So what is the dockershim, and why is it going away?
In the early days of Kubernetes, we only supported one container runtime. That runtime was Docker Engine. Back then, there werent really a lot of other options out there and Docker was the dominant tool for working with containers, so this was not a controversial choice. Eventually, we started adding more container runtimes, like rkt and hypernetes, and it became clear that Kubernetes users want a choice of runtimes working best for them. So Kubernetes needed a way to allow cluster operators the flexibility to use whatever runtime they choose.
The [Container Runtime Interface](/blog/2016/12/container-runtime-interface-cri-in-kubernetes/) (CRI) was released to allow that flexibility. The introduction of CRI was great for the project and users alike, but it did introduce a problem: Docker Engines use as a container runtime predates CRI, and Docker Engine is not CRI-compatible. To solve this issue, a small software shim (dockershim) was introduced as part of the kubelet component specifically to fill in the gaps between Docker Engine and CRI, allowing cluster operators to continue using Docker Engine as their container runtime largely uninterrupted.
However, this little software shim was never intended to be a permanent solution. Over the course of years, its existence has introduced a lot of unnecessary complexity to the kubelet itself. Some integrations are inconsistently implemented for Docker because of this shim, resulting in an increased burden on maintainers, and maintaining vendor-specific code is not in line with our open source philosophy. To reduce this maintenance burden and move towards a more collaborative community in support of open standards, [KEP-2221 was introduced](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2221-remove-dockershim), proposing the removal of the dockershim. With the release of Kubernetes v1.20, the deprecation was official.
We didnt do a great job communicating this, and unfortunately, the deprecation announcement led to some panic within the community. Confusion around what this meant for Docker as a company, if container images built by Docker would still run, and what Docker Engine actually is led to a conflagration on social media. This was our fault; we should have more clearly communicated what was happening and why at the time. To combat this, we released [a blog](/blog/2020/12/02/dont-panic-kubernetes-and-docker/) and [accompanying FAQ](/blog/2020/12/02/dockershim-faq/) to allay the communitys fears and correct some misconceptions about what Docker is and how containers work within Kubernetes. As a result of the communitys concerns, Docker and Mirantis jointly agreed to continue supporting the dockershim code in the form of [cri-dockerd](https://www.mirantis.com/blog/the-future-of-dockershim-is-cri-dockerd/), allowing you to continue using Docker Engine as your container runtime if need be. For the interest of users who want to try other runtimes, like containerd or cri-o, [migration documentation was written](/docs/tasks/administer-cluster/migrating-from-dockershim/change-runtime-containerd/).
We later [surveyed the community](https://kubernetes.io/blog/2021/11/12/are-you-ready-for-dockershim-removal/) and [discovered that there are still many users with questions and concerns](/blog/2022/01/07/kubernetes-is-moving-on-from-dockershim). In response, Kubernetes maintainers and the CNCF committed to addressing these concerns by extending documentation and other programs. In fact, this blog post is a part of this program. With so many end users successfully migrated to other runtimes, and improved documentation, we believe that everyone has a paved way to migration now.
Docker is not going away, either as a tool or as a company. Its an important part of the cloud native community and the history of the Kubernetes project. We wouldnt be where we are without them. That said, removing dockershim from kubelet is ultimately good for the community, the ecosystem, the project, and open source at large. This is an opportunity for all of us to come together to support open standards, and were glad to be doing so with the help of Docker and the community.
@@ -0,0 +1,79 @@
---
layout: blog
title: "Storage Capacity Tracking reaches GA in Kubernetes 1.24"
date: 2022-05-06
slug: storage-capacity-ga
---
**Authors:** Patrick Ohly (Intel)
The v1.24 release of Kubernetes brings [storage capacity](/docs/concepts/storage/storage-capacity/)
tracking as a generally available feature.
## Problems we have solved
As explained in more detail in the [previous blog post about this
feature](/blog/2021/04/14/local-storage-features-go-beta/), storage capacity
tracking allows a CSI driver to publish information about remaining
capacity. The kube-scheduler then uses that information to pick suitable nodes
for a Pod when that Pod has volumes that still need to be provisioned.
Without this information, a Pod may get stuck without ever being scheduled onto
a suitable node because kube-scheduler has to choose blindly and always ends up
picking a node for which the volume cannot be provisioned because the
underlying storage system managed by the CSI driver does not have sufficient
capacity left.
Because CSI drivers publish storage capacity information that gets used at a
later time when it might not be up-to-date anymore, it can still happen that a
node is picked that doesn't work out after all. Volume provisioning recovers
from that by informing the scheduler that it needs to try again with a
different node.
[Load
tests](https://github.com/kubernetes-csi/csi-driver-host-path/blob/master/docs/storage-capacity-tracking.md)
that were done again for promotion to GA confirmed that all storage in a
cluster can be consumed by Pods with storage capacity tracking whereas Pods got
stuck without it.
## Problems we have *not* solved
Recovery from a failed volume provisioning attempt has one known limitation: if a Pod
uses two volumes and only one of them could be provisioned, then all future
scheduling decisions are limited by the already provisioned volume. If that
volume is local to a node and the other volume cannot be provisioned there, the
Pod is stuck. This problem pre-dates storage capacity tracking and while the
additional information makes it less likely to occur, it cannot be avoided in
all cases, except of course by only using one volume per Pod.
An idea for solving this was proposed in a [KEP
draft](https://github.com/kubernetes/enhancements/pull/1703): volumes that were
provisioned and haven't been used yet cannot have any valuable data and
therefore could be freed and provisioned again elsewhere. SIG Storage is
looking for interested developers who want to continue working on this.
Also not solved is support in Cluster Autoscaler for Pods with volumes. For CSI
drivers with storage capacity tracking, a prototype was developed and discussed
in [a PR](https://github.com/kubernetes/autoscaler/pull/3887). It was meant to
work with arbitrary CSI drivers, but that flexibility made it hard to configure
and slowed down scale up operations: because autoscaler was unable to simulate
volume provisioning, it only scaled the cluster by one node at a time, which
was seen as insufficient.
Therefore that PR was not merged and a different approach with tighter coupling
between autoscaler and CSI driver will be needed. For this a better
understanding is needed about which local storage CSI drivers are used in
combination with cluster autoscaling. Should this lead to a new KEP, then users
will have to try out an implementation in practice before it can move to beta
or GA. So please reach out to SIG Storage if you have an interest in this
topic.
## Acknowledgements
Thanks a lot to the members of the community who have contributed to this
feature or given feedback including members of [SIG
Scheduling](https://github.com/kubernetes/community/tree/master/sig-scheduling),
[SIG
Autoscaling](https://github.com/kubernetes/community/tree/master/sig-autoscaling),
and of course [SIG
Storage](https://github.com/kubernetes/community/tree/master/sig-storage)!
@@ -0,0 +1,162 @@
---
layout: blog
title: "Kubernetes 1.24: Volume Populators Graduate to Beta"
date: 2022-05-16
slug: volume-populators-beta
---
**Author:**
Ben Swartzlander (NetApp)
The volume populators feature is now two releases old and entering beta! The `AnyVolumeDataSouce` feature
gate defaults to enabled in Kubernetes v1.24, which means that users can specify any custom resource
as the data source of a PVC.
An [earlier blog article](/blog/2021/08/30-volume-populators-redesigned/) detailed how the
volume populators feature works. In short, a cluster administrator can install a CRD and
associated populator controller in the cluster, and any user who can create instances of
the CR can create pre-populated volumes by taking advantage of the populator.
Multiple populators can be installed side by side for different purposes. The SIG storage
community is already seeing some implementations in public, and more prototypes should
appear soon.
Cluster administrations are **strongly encouraged** to install the
volume-data-source-validator controller and associated `VolumePopulator` CRD before installing
any populators so that users can get feedback about invalid PVC data sources.
## New Features
The [lib-volume-populator](https://github.com/kubernetes-csi/lib-volume-populator) library
on which populators are built now includes metrics to help operators monitor and detect
problems. This library is now beta and latest release is v1.0.1.
The [volume data source validator](https://github.com/kubernetes-csi/volume-data-source-validator)
controller also has metrics support added, and is in beta. The `VolumePopulator` CRD is
beta and the latest release is v1.0.1.
## Trying it out
To see how this works, you can install the sample "hello" populator and try it
out.
First install the volume-data-source-validator controller.
```shell
kubectl apply -f https://raw.githubusercontent.com/kubernetes-csi/volume-data-source-validator/v1.0.1/client/config/crd/populator.storage.k8s.io_volumepopulators.yaml
kubectl apply -f https://raw.githubusercontent.com/kubernetes-csi/volume-data-source-validator/v1.0.1/deploy/kubernetes/rbac-data-source-validator.yaml
kubectl apply -f https://raw.githubusercontent.com/kubernetes-csi/volume-data-source-validator/v1.0.1/deploy/kubernetes/setup-data-source-validator.yaml
```
Next install the example populator.
```shell
kubectl apply -f https://raw.githubusercontent.com/kubernetes-csi/lib-volume-populator/v1.0.1/example/hello-populator/crd.yaml
kubectl apply -f https://raw.githubusercontent.com/kubernetes-csi/lib-volume-populator/87a47467b86052819e9ad13d15036d65b9a32fbb/example/hello-populator/deploy.yaml
```
Your cluster now has a new CustomResourceDefinition that provides a test API named Hello.
Create an instance of the `Hello` custom resource, with some text:
```yaml
apiVersion: hello.example.com/v1alpha1
kind: Hello
metadata:
name: example-hello
spec:
fileName: example.txt
fileContents: Hello, world!
```
Create a PVC that refers to that CR as its data source.
```yaml
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: example-pvc
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 10Mi
dataSourceRef:
apiGroup: hello.example.com
kind: Hello
name: example-hello
volumeMode: Filesystem
```
Next, run a Job that reads the file in the PVC.
```yaml
apiVersion: batch/v1
kind: Job
metadata:
name: example-job
spec:
template:
spec:
containers:
- name: example-container
image: busybox:latest
command:
- cat
- /mnt/example.txt
volumeMounts:
- name: vol
mountPath: /mnt
restartPolicy: Never
volumes:
- name: vol
persistentVolumeClaim:
claimName: example-pvc
```
Wait for the job to complete (including all of its dependencies).
```shell
kubectl wait --for=condition=Complete job/example-job
```
And last examine the log from the job.
```shell
kubectl logs job/example-job
```
The output should be:
```terminal
Hello, world!
```
Note that the volume already contained a text file with the string contents from
the CR. This is only the simplest example. Actual populators can set up the volume
to contain arbitrary contents.
## How to write your own volume populator
Developers interested in writing new poplators are encouraged to use the
[lib-volume-populator](https://github.com/kubernetes-csi/lib-volume-populator) library
and to only supply a small controller wrapper around the library, and a pod image
capable of attaching to volumes and writing the appropriate data to the volume.
Individual populators can be extremely generic such that they work with every type
of PVC, or they can do vendor specific things to rapidly fill a volume with data
if the volume was provisioned by a specific CSI driver from the same vendor, for
example, by communicating directly with the storage for that volume.
## How can I learn more?
The enhancement proposal,
[Volume Populators](https://github.com/kubernetes/enhancements/tree/master/keps/sig-storage/1495-volume-populators), includes lots of detail about the history and technical implementation
of this feature.
[Volume populators and data sources](/docs/concepts/storage/persistent-volumes/#volume-populators-and-data-sources), within the documentation topic about persistent volumes,
explains how to use this feature in your cluster.
Please get involved by joining the Kubernetes storage SIG to help us enhance this
feature. There are a lot of good ideas already and we'd be thrilled to have more!
+183 -257
View File
@@ -1,257 +1,183 @@
---
title: Community
layout: basic
cid: community
---
<div class="newcommunitywrapper">
<div class="banner1">
<img src="/images/community/kubernetes-community-final-02.jpg" alt="Kubernetes Conference Gallery" style="width:100%;padding-left:0px" class="desktop">
<img src="/images/community/kubernetes-community-02-mobile.jpg" alt="Kubernetes Conference Gallery" style="width:100%;padding-left:0px" class="mobile">
</div>
<div class="intro">
<br class="mobile">
<p>The Kubernetes community -- users, contributors, and the culture we've built together -- is one of the biggest reasons for the meteoric rise of this open source project. Our culture and values continue to grow and change as the project itself grows and changes. We all work together toward constant improvement of the project and the ways we work on it.
<br><br>We are the people who file issues and pull requests, attend SIG meetings, Kubernetes meetups, and KubeCon, advocate for its adoption and innovation, run <code>kubectl get pods</code>, and contribute in a thousand other vital ways. Read on to learn how you can get involved and become part of this amazing community.</p>
<br class="mobile">
</div>
<div class="community__navbar">
<a href="https://www.kubernetes.dev/">Contributor Community</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#values">Community Values</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#conduct">Code of conduct </a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#videos">Videos</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#discuss">Discussions</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#events">Events and meetups</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#news">News</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="/releases">Releases</a>
</div>
<br class="mobile"><br class="mobile">
<div class="imagecols">
<br class="mobile">
<div class="imagecol">
<img src="/images/community/kubernetes-community-final-03.jpg" alt="Kubernetes Conference Gallery" style="width:100%" class="desktop">
</div>
<div class="imagecol">
<img src="/images/community/kubernetes-community-final-04.jpg" alt="Kubernetes Conference Gallery" style="width:100%" class="desktop">
</div>
<div class="imagecol" style="margin-right:0% important">
<img src="/images/community/kubernetes-community-final-05.jpg" alt="Kubernetes Conference Gallery" style="width:100%;margin-right:0% important" class="desktop">
</div>
<img src="/images/community/kubernetes-community-04-mobile.jpg" alt="Kubernetes Conference Gallery" style="width:100%;margin-bottom:3%" class="mobile">
<a name="values"></a>
</div>
<div><a name="values"></a></div>
<div class="conduct">
<div class="conducttext">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<div class="conducttextnobutton" style="margin-bottom:2%"><h1>Community Values</h1>
The Kubernetes Community values are the keystone to the ongoing success of the project.<br>
These principles guide every aspect of the Kubernetes project.
<br>
<a href="/community/values/">
<br class="mobile"><br class="mobile">
<span class="fullbutton">
READ MORE
</span>
</a>
</div><a name="conduct"></a>
</div>
</div>
<div class="conduct">
<div class="conducttext">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<div class="conducttextnobutton" style="margin-bottom:2%"><h1>Code of Conduct</h1>
The Kubernetes community values respect and inclusiveness, and enforces a Code of Conduct in all interactions. If you notice a violation of the Code of Conduct at an event or meeting, in Slack, or in another communication mechanism, reach out to the Kubernetes Code of Conduct Committee at <a href="mailto:conduct@kubernetes.io" style="color:#0662EE;font-weight:300">conduct@kubernetes.io</a>. All reports are kept confidential. You can read about the committee&nbsp;<a href="https://github.com/kubernetes/community/tree/master/committee-code-of-conduct" style="color:#0662EE;font-weight:300">here</a>.
<br>
<a href="https://kubernetes.io/community/code-of-conduct/">
<br class="mobile"><br class="mobile">
<span class="fullbutton">
READ MORE
</span>
</a>
</div><a name="videos"></a>
</div>
</div>
<div class="videos">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<h1 style="margin-top:0px">Videos</h1>
<div style="margin-bottom:4%;font-weight:300;text-align:center;padding-left:10%;padding-right:10%">We're on YouTube, a lot. Subscribe for a wide range of&nbsp;topics.</div>
<div class="videocontainer">
<div class="video">
<iframe width="100%" height="250" src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP3azFUvYJjGn45YbF6C-uIg" title="Monthly office hours" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP3azFUvYJjGn45YbF6C-uIg">
<div class="videocta">
Watch monthly office hours&nbsp;&#9654;</div>
</a>
</div>
<div class="video">
<iframe width="100%" height="250" src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP1pkHsbPjzAewvMgGUpkCnJ" title="Weekly community meetings" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP1pkHsbPjzAewvMgGUpkCnJ">
<div class="videocta">
Watch weekly community meetings&nbsp;&#9654;
</div>
</a>
</div>
<div class="video">
<iframe width="100%" height="250" src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP3QpQrhZq_sLYo77BVKv09F" title="Talk from a community member" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP3QpQrhZq_sLYo77BVKv09F">
<div class="videocta">
Watch a talk from a community member&nbsp;&#9654;
</div>
</a>
<a name="discuss"></a>
</div>
</div>
</div>
<div class="resources">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<h1 style="padding-top:1%">Discussions</h1>
<div style="font-weight:300;text-align:center">We talk a lot. Find us and join the conversation on any of these&nbsp;platforms.</div>
<div class="resourcecontainer">
<div class="resourcebox">
<img src="/images/community/discuss.png" alt=Forum" style="width:80%;padding-bottom:2%">
<a href="https://discuss.kubernetes.io/" style="color:#0662EE;display:block;margin-top:1%">
forum&nbsp;&#9654;
</a>
<div class="resourceboxtext" style="font-size:12px;text-transform:none !important;font-weight:300;line-height:1.4em;color:#333333;margin-top:4%">
Topic-based technical discussions that bridge docs, StackOverflow, and so much&nbsp;more
</div>
</div>
<div class="resourcebox">
<img src="/images/community/twitter.png" alt="Twitter" style="width:80%;padding-bottom:2%">
<a href="https://twitter.com/kubernetesio" style="color:#0662EE;display:block;margin-top:1%">
twitter&nbsp;&#9654;
</a>
<div class="resourceboxtext" style="font-size:12px;text-transform:none !important;font-weight:300;line-height:1.4em;color:#333333;margin-top:4%">Real-time announcements of blog posts, events, news, ideas
</div>
</div>
<div class="resourcebox">
<img src="/images/community/github.png" alt="GitHub" style="width:80%;padding-bottom:2%">
<a href="https://github.com/kubernetes/kubernetes" style="color:#0662EE;display:block;margin-top:1%">
github&nbsp;&#9654;
</a>
<div class="resourceboxtext" style="font-size:12px;text-transform:none !important;font-weight:300;line-height:1.4em;color:#333333;margin-top:4%">
All the project and issue tracking, plus of course code
</div>
</div>
<div class="resourcebox">
<img src="/images/community/stack.png" alt="Stack Overflow" style="width:80%;padding-bottom:2%">
<a href="https://stackoverflow.com/search?q=kubernetes" style="color:#0662EE;display:block;margin-top:1%">
stack overflow&nbsp;&#9654;
</a>
<div class="resourceboxtext" style="font-size:12px;text-transform:none !important;font-weight:300;line-height:1.4em;color:#333333;margin-top:4%">
Technical troubleshooting for any use&nbsp;case
<a name="events"></a>
</div>
</div>
<!--
<div class="resourcebox">
<img src="/images/community/slack.png" style="width:80%">
slack&nbsp;&#9654;
<div class="resourceboxtext" style="font-size:11px;text-transform:none !important;font-weight:200;line-height:1.4em;color:#333333;margin-top:4%">
With 170+ channels, you'll find one that fits your needs.
</div>
</div>-->
</div>
</div>
<div class="events">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<div class="eventcontainer">
<h1 style="color:white !important">Upcoming Events</h1>
{{< upcoming-events >}}
</div>
</div>
<div class="meetups">
<div class="meetupcol">
<div class="meetuptext">
<h1 style="text-align:left">Global Community</h1>
With over 150 meetups in the world and growing, go find your local kube people. If one isn't near, take charge and create your own.
</div>
<a href="https://www.meetup.com/topics/kubernetes/">
<div class="button">
FIND A MEETUP
</div>
</a>
<a name="news"></a>
</div>
</div>
<!--
<div class="contributor">
<div class="contributortext">
<br>
<h1 style="text-align:left">
New Contributors Site
</h1>
Text about new contributors site.
<br><br>
<div class="button">
VISIT SITE
</div>
</div>
</div>
-->
<div class="news">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<h1 style="margin-bottom:2%">Recent News</h1>
<br>
<div class="twittercol1">
<a class="twitter-timeline" data-tweet-limit="1" href="https://twitter.com/kubernetesio?ref_src=twsrc%5Etfw">Tweets by kubernetesio</a> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</div>
<br>
<br><br><br><br>
</div>
</div>
---
title: Community
layout: basic
cid: community
community_styles_migrated: true
---
<img
id="banner"
srcset="/images/community/kubernetes-community-final-02.jpg 1500w, /images/community/kubernetes-community-02-mobile.jpg 900w"
sizes="(max-width: 900px) 900px, (max-width: 1920px) 1500px"
src="/images/community/kubernetes-community-final-02.jpg"
alt="Kubernetes conference photo">
<div class="community-section" id="introduction">
<p>The Kubernetes community users, contributors, and the culture we've
built together — is one of the biggest reasons for the meteoric rise of
this open source project. Our culture and values continue to grow and change
as the project itself grows and changes. We all work together toward constant
improvement of the project and the ways we work on it.</p>
<p> We are the people who file issues and pull requests, attend SIG meetings,
Kubernetes meetups, and KubeCon, advocate for its adoption and innovation,
run <code>kubectl get pods</code>, and contribute in a thousand other vital
ways. Read on to learn how you can get involved and become part of this amazing
community.</p>
</div>
<div id="navigation-items">
<div class="community-nav-item external-link">
<a href="https://www.kubernetes.dev/">Contributor community</a>
</div>
<div class="community-nav-item">
<a href="#values">Community values</a>
</div>
<div class="community-nav-item">
<a href="#conduct">Code of conduct</a>
</div>
<div class="community-nav-item">
<a href="#videos">Videos</a>
</div>
<div class="community-nav-item">
<a href="#discuss">Discussions</a>
</div>
<div class="community-nav-item">
<a href="#meetups">Meetups</a>
</div>
<div class="community-nav-item">
<a href="#news">News</a>
</div>
<div class="community-nav-item">
<a href="/releases">Releases</a>
</div>
</div>
<div class="community-section" id="gallery">
<img src="/images/community/kubernetes-community-final-03.jpg" alt="Kubernetes conference gallery photo" class="community-gallery-desktop">
<img src="/images/community/kubernetes-community-final-04.jpg" alt="Kubernetes conference gallery photo" class="community-gallery-desktop">
<img src="/images/community/kubernetes-community-final-05.jpg" alt="Kubernetes conference gallery photo" class="community-gallery-desktop">
<img src="/images/community/kubernetes-community-04-mobile.jpg" alt="Kubernetes conference gallery photo" class="community-gallery-mobile">
</div>
<div class="community-section" id="values">
<h2>Community Values</h2>
<p>The Kubernetes Community values are the keystone to the ongoing success of the project.<br class="optional"/>
These principles guide every aspect of the Kubernetes project.</p>
<a href="https://www.kubernetes.dev/community/values/" class="community-cta-button">
<span class="community-cta">Read more</span>
</a>
</div>
<div class="community-section" id="conduct">
<h2>Code of Conduct</h2>
<p>The Kubernetes community values respect and inclusiveness, and enforces a Code of Conduct in all interactions.</p>
<p>If you notice a violation of the Code of Conduct at an event or meeting, in <a href="#slack">Slack</a>, or in another communication mechanism, reach out to the Kubernetes Code of Conduct Committee at <a href="mailto:conduct@kubernetes.io">conduct@kubernetes.io</a>. All reports are kept confidential. You can read <a href="https://github.com/kubernetes/community/tree/master/committee-code-of-conduct">about the committee</a> in the Kubernetes community repository on GitHub.</p>
<a href="/community/code-of-conduct/" class="community-cta-button">
<span class="community-cta">Read more</span>
</a>
</div>
<div id="videos" class="community-section">
<h2>Videos</h2>
<p class="community-simple">Kubernetes is on YouTube, a lot. Subscribe for a wide range of&nbsp;topics.</p>
<div class="container">
<div class="video youtube">
<iframe src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP3azFUvYJjGn45YbF6C-uIg" title="Monthly office hours" allow="camera 'none'; microphone 'none'; geolocation 'none'; fullscreen https://www.youtube.com/" ></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP3azFUvYJjGn45YbF6C-uIg">
<span class="videocta">Watch monthly office hours&nbsp;&#9654;</span>
</a>
</div>
<div class="video youtube">
<iframe src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP1pkHsbPjzAewvMgGUpkCnJ" title="Weekly community meetings" allow="camera 'none'; microphone 'none'; geolocation 'none'; fullscreen https://www.youtube.com/"></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP1pkHsbPjzAewvMgGUpkCnJ">
<span class="videocta">Watch weekly community meetings&nbsp;&#9654;</span>
</a>
</div>
<div class="video youtube" id="discuss">
<iframe src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP3QpQrhZq_sLYo77BVKv09F" title="Talk from a community member" allow="camera 'none'; microphone 'none'; geolocation 'none'; fullscreen https://www.youtube.com/"></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP3QpQrhZq_sLYo77BVKv09F">
<span class="videocta">Watch a talk from a community member&nbsp;&#9654;</span>
</a>
</div>
</div>
</div>
<div id="resources" class="community-section">
<h2>Discussions</h2>
<p class="community-simple">We talk a lot. Find us and join the conversation on any of these&nbsp;platforms.</p>
<div class="container">
<div class="community-resource">
<a href="https://discuss.kubernetes.io/">
<img src="/images/community/discuss.png" alt="Forum">
</a>
<a href="https://discuss.kubernetes.io/">Community forums&nbsp;&#9654;</a>
<p>Topic-based technical discussions that bridge docs,
troubleshooting, and so much&nbsp;more.</p>
</div>
<div id="twitter" class="community-resource">
<a href="https://twitter.com/kubernetesio">
<img src="/images/community/twitter.png" alt="Twitter">
</a>
<a href="https://twitter.com/kubernetesio">Twitter&nbsp;&#9654;</a>
<p><em>#kubernetesio</em></p>
<p>Real-time announcements of blog posts, events, news, ideas.</p>
</div>
<div id="github" class="community-resource">
<a href="https://github.com/kubernetes/kubernetes">
<img src="/images/community/github.png" alt="GitHub">
</a>
<a href="https://github.com/kubernetes/kubernetes">GitHub&nbsp;&#9654;</a>
<p>All the project and issue tracking, plus of course code.</p>
</div>
<div id="server-fault" class="community-resource">
<a href="https://serverfault.com/questions/tagged/kubernetes">
<img src="/images/community/serverfault.png" alt="Server Fault">
</a>
<a href="https://serverfault.com/questions/tagged/kubernetes">Server Fault&nbsp;&#9654;</a>
<p>Kubernetes-related discussion on Server Fault. Ask a question, or answer one.</p>
</div>
<div id="slack" class="community-resource">
<a href="https://kubernetes.slack.com/">
<img src="/images/community/slack.png" alt="Slack">
</a>
<a href="https://kubernetes.slack.com/">Slack&nbsp;&#9654;</a>
<p>With 170+ channels, you'll find one that fits your needs.</p>
<details><summary><em>Need an invitation?</em></summary>
Visit <a href="https://slack.k8s.io/">https://slack.k8s.io/</a>
for an invitation.</details>
</div>
</div>
</div>
<div class="community-section" id="events">
<div class="container">
<h2>Upcoming Events</h2>
{{< upcoming-events >}}
</div>
</div>
<div class="community-section" id="meetups">
<h2>Global community</h2>
<p>
With over 150 meetups in the world and growing, go find your local kube people. If one isn't near, take charge and create your own.
</p>
<a href="https://www.meetup.com/topics/kubernetes/" class="community-cta-button">
<span class="community-cta">Find a meetup</span>
</a>
</div>
<div class="community-section community-frame" id="news">
<h2>Recent News</h2>
<div class="twittercol1">
<a class="twitter-timeline" data-tweet-limit="1" href="https://twitter.com/kubernetesio?ref_src=twsrc%5Etfw">Tweets by kubernetesio</a>
</div>
</div>
+9 -7
View File
@@ -1,27 +1,29 @@
---
title: Community
title: Kubernetes Community Code of Conduct
layout: basic
cid: community
css: /css/community.css
community_styles_migrated: true
---
<div class="community_main">
<h1>Kubernetes Community Code of Conduct</h1>
<div class="community-section" id="cncf-code-of-conduct-intro">
<p>
Kubernetes follows the
<a href="https://github.com/cncf/foundation/blob/master/code-of-conduct.md">CNCF Code of Conduct</a>.
The text of the CNCF CoC is replicated below, as of
<a href="https://github.com/cncf/foundation/blob/214585e24aab747fb85c2ea44fbf4a2442e30de6/code-of-conduct.md">commit 214585e</a>.
If you notice that this is out of date, please
<a href="https://github.com/kubernetes/website/issues/new">file an issue</a>.
</p>
<p>
If you notice a violation of the Code of Conduct at an event or meeting, in
Slack, or in another communication mechanism, reach out to
the <a href="https://git.k8s.io/community/committee-code-of-conduct">Kubernetes Code of Conduct Committee</a>.
You can reach us by email at <a href="mailto:conduct@kubernetes.io">conduct@kubernetes.io</a>.
Your anonymity will be protected.
</p>
</div>
<div class="cncf_coc_container">
<div id="cncf-code-of-conduct">
{{< include "/static/cncf-code-of-conduct.md" >}}
</div>
</div>
+7
View File
@@ -0,0 +1,7 @@
# See the OWNERS docs at https://go.k8s.io/owners
# Disable inheritance to encourage careful review of any changes here.
options:
no_parent_owners: true
approvers:
- sig-docs-leads
+4 -1
View File
@@ -1,2 +1,5 @@
The files in this directory have been imported from other sources. Do not
edit them directly, except by replacing them with new versions.
edit them directly, except by replacing them with new versions.
Localization note: you do not need to create localized versions of any of
the files in this directory.
+12 -7
View File
@@ -1,13 +1,18 @@
---
title: Community
title: Kubernetes Community Values
layout: basic
cid: community
css: /css/community.css
community_styles_migrated: true
# this page is deprecated
# canonical page is https://www.kubernetes.dev/community/values/
sitemap:
priority: 0.1
---
<div class="community_main">
<div class="cncf_coc_container">
<div class="community-section" id="values-legacy">
{{< include "/static/community-values.md" >}}
</div>
</div>
<!-- no need to localize this file, nor the contents of the static directory -->
<!-- if localizing, find the appropriate localized version of the CNCF code of
conduct, and link directly to that -->
@@ -13,7 +13,7 @@ allows the clean up of resources like the following:
* [Objects without owner references](#owners-dependents)
* [Unused containers and container images](#containers-images)
* [Dynamically provisioned PersistentVolumes with a StorageClass reclaim policy of Delete](/docs/concepts/storage/persistent-volumes/#delete)
* [Stale or expired CertificateSigningRequests (CSRs)](/reference/access-authn-authz/certificate-signing-requests/#request-signing-process)
* [Stale or expired CertificateSigningRequests (CSRs)](/docs/reference/access-authn-authz/certificate-signing-requests/#request-signing-process)
* {{<glossary_tooltip text="Nodes" term_id="node">}} deleted in the following scenarios:
* On a cloud when the cluster uses a [cloud controller manager](/docs/concepts/architecture/cloud-controller/)
* On-premises when the cluster uses an addon similar to a cloud controller
+13 -8
View File
@@ -312,16 +312,18 @@ controller deletes the node from its list of nodes.
The third is monitoring the nodes' health. The node controller is
responsible for:
- In the case that a node becomes unreachable, updating the NodeReady condition
of within the Node's `.status`. In this case the node controller sets the
NodeReady condition to `ConditionUnknown`.
- In the case that a node becomes unreachable, updating the `Ready` condition
in the Node's `.status` field. In this case the node controller sets the
`Ready` condition to `Unknown`.
- If a node remains unreachable: triggering
[API-initiated eviction](/docs/concepts/scheduling-eviction/api-eviction/)
for all of the Pods on the unreachable node. By default, the node controller
waits 5 minutes between marking the node as `ConditionUnknown` and submitting
waits 5 minutes between marking the node as `Unknown` and submitting
the first eviction request.
The node controller checks the state of each node every `--node-monitor-period` seconds.
By default, the node controller checks the state of each node every 5 seconds.
This period can be configured using the `--node-monitor-period` flag on the
`kube-controller-manager` component.
### Rate limits on eviction
@@ -331,7 +333,7 @@ from more than 1 node per 10 seconds.
The node eviction behavior changes when a node in a given availability zone
becomes unhealthy. The node controller checks what percentage of nodes in the zone
are unhealthy (NodeReady condition is `ConditionUnknown` or `ConditionFalse`) at
are unhealthy (the `Ready` condition is `Unknown` or `False`) at
the same time:
- If the fraction of unhealthy nodes is at least `--unhealthy-zone-threshold`
@@ -384,7 +386,7 @@ If you want to explicitly reserve resources for non-Pod processes, see
## Node topology
{{< feature-state state="alpha" for_k8s_version="v1.16" >}}
{{< feature-state state="beta" for_k8s_version="v1.18" >}}
If you have enabled the `TopologyManager`
[feature gate](/docs/reference/command-line-tools-reference/feature-gates/), then
@@ -412,7 +414,7 @@ enabled by default in 1.21.
Note that by default, both configuration options described below,
`shutdownGracePeriod` and `shutdownGracePeriodCriticalPods` are set to zero,
thus not activating Graceful node shutdown functionality.
thus not activating the graceful node shutdown functionality.
To activate the feature, the two kubelet config settings should be configured appropriately and
set to non-zero values.
@@ -539,6 +541,9 @@ Using this feature, requires enabling the
config's `ShutdownGracePeriodByPodPriority` to the desired configuration
containing the pod priority class values and their respective shutdown periods.
Metrics `graceful_shutdown_start_time_seconds` and `graceful_shutdown_end_time_seconds`
are emitted under the kubelet subsystem to monitor node shutdowns.
## Swap memory management {#swap-memory}
{{< feature-state state="alpha" for_k8s_version="v1.22" >}}
@@ -59,7 +59,7 @@ Before choosing a guide, here are some considerations:
* [Using Sysctls in a Kubernetes Cluster](/docs/tasks/administer-cluster/sysctl-cluster/) describes to an administrator how to use the `sysctl` command-line tool to set kernel parameters .
* [Auditing](/docs/tasks/debug-application-cluster/audit/) describes how to interact with Kubernetes' audit logs.
* [Auditing](/docs/tasks/debug/debug-cluster/audit/) describes how to interact with Kubernetes' audit logs.
### Securing the kubelet
* [Control Plane-Node communication](/docs/concepts/architecture/control-plane-node-communication/)
@@ -21,6 +21,7 @@ This page lists some of the available add-ons and links to their respective inst
* [Canal](https://github.com/tigera/canal/tree/master/k8s-install) unites Flannel and Calico, providing networking and network policy.
* [Cilium](https://github.com/cilium/cilium) is a L3 network and network policy plugin that can enforce HTTP/API/L7 policies transparently. Both routing and overlay/encapsulation mode are supported, and it can work on top of other CNI plugins.
* [CNI-Genie](https://github.com/Huawei-PaaS/CNI-Genie) enables Kubernetes to seamlessly connect to a choice of CNI plugins, such as Calico, Canal, Flannel, Romana, or Weave.
* [Contiv](https://contivpp.io/) provides configurable networking (native L3 using BGP, overlay using vxlan, classic L2, and Cisco-SDN/ACI) for various use cases and a rich policy framework. Contiv project is fully [open sourced](https://github.com/contiv). The [installer](https://github.com/contiv/install) provides both kubeadm and non-kubeadm based installation options.
* [Contrail](https://www.juniper.net/us/en/products-services/sdn/contrail/contrail-networking/), based on [Tungsten Fabric](https://tungsten.io), is an open source, multi-cloud network virtualization and policy management platform. Contrail and Tungsten Fabric are integrated with orchestration systems such as Kubernetes, OpenShift, OpenStack and Mesos, and provide isolation modes for virtual machines, containers/pods and bare metal workloads.
* [Flannel](https://github.com/flannel-io/flannel#deploying-flannel-manually) is an overlay network provider that can be used with Kubernetes.
* [Knitter](https://github.com/ZTE/Knitter/) is a plugin to support multiple network interfaces in a Kubernetes pod.
@@ -29,7 +30,7 @@ This page lists some of the available add-ons and links to their respective inst
* [OVN4NFV-K8S-Plugin](https://github.com/opnfv/ovn4nfv-k8s-plugin) is OVN based CNI controller plugin to provide cloud native based Service function chaining(SFC), Multiple OVN overlay networking, dynamic subnet creation, dynamic creation of virtual networks, VLAN Provider network, Direct provider network and pluggable with other Multi-network plugins, ideal for edge based cloud native workloads in Multi-cluster networking
* [NSX-T](https://docs.vmware.com/en/VMware-NSX-T/2.0/nsxt_20_ncp_kubernetes.pdf) Container Plug-in (NCP) provides integration between VMware NSX-T and container orchestrators such as Kubernetes, as well as integration between NSX-T and container-based CaaS/PaaS platforms such as Pivotal Container Service (PKS) and OpenShift.
* [Nuage](https://github.com/nuagenetworks/nuage-kubernetes/blob/v5.1.1-1/docs/kubernetes-1-installation.rst) is an SDN platform that provides policy-based networking between Kubernetes Pods and non-Kubernetes environments with visibility and security monitoring.
* [Romana](https://romana.io) is a Layer 3 networking solution for pod networks that also supports the [NetworkPolicy API](/docs/concepts/services-networking/network-policies/). Kubeadm add-on installation details available [here](https://github.com/romana/romana/tree/master/containerize).
* **Romana** is a Layer 3 networking solution for pod networks that also supports the [NetworkPolicy API](/docs/concepts/services-networking/network-policies/). Kubeadm add-on installation details available [here](https://github.com/romana/romana/tree/master/containerize).
* [Weave Net](https://www.weave.works/docs/net/latest/kubernetes/kube-addon/) provides networking and network policy, will carry on working on both sides of a network partition, and does not require an external database.
## Service Discovery
@@ -15,7 +15,6 @@ If the data you want to store are confidential, use a
or use additional (third party) tools to keep your data private.
{{< /caution >}}
<!-- body -->
## Motivation
@@ -282,5 +281,3 @@ to the deleted ConfigMap, it is recommended to recreate these pods.
* Read [Configure a Pod to Use a ConfigMap](/docs/tasks/configure-pod-container/configure-pod-configmap/).
* Read [The Twelve-Factor App](https://12factor.net/) to understand the motivation for
separating code from configuration.
@@ -47,10 +47,9 @@ or by enforcement (the system prevents the container from ever exceeding the lim
runtimes can have different ways to implement the same restrictions.
{{< note >}}
If a container specifies its own memory limit, but does not specify a memory request, Kubernetes
automatically assigns a memory request that matches the limit. Similarly, if a container specifies its own
CPU limit, but does not specify a CPU request, Kubernetes automatically assigns a CPU request that matches
the limit.
If you specify a limit for a resource, but do not specify any request, and no admission-time
mechanism has applied a default request for that resource, then Kubernetes copies the limit
you specified and uses it as the requested value for the resource.
{{< /note >}}
## Resource types
@@ -134,7 +133,7 @@ Mi, Ki. For example, the following represent roughly the same value:
128974848, 129e6, 129M, 128974848000m, 123Mi
```
Take care about case for suffixes. If you request `400m` of memory, this is a request
Pay attention to the case of the suffixes. If you request `400m` of memory, this is a request
for 0.4 bytes. Someone who types that probably meant to ask for 400 mebibytes (`400Mi`)
or 400 megabytes (`400M`).
@@ -229,9 +228,9 @@ see the [Troubleshooting](#troubleshooting) section.
The kubelet reports the resource usage of a Pod as part of the Pod
[`status`](/docs/concepts/overview/working-with-objects/kubernetes-objects/#object-spec-and-status).
If optional [tools for monitoring](/docs/tasks/debug-application-cluster/resource-usage-monitoring/)
If optional [tools for monitoring](/docs/tasks/debug/debug-cluster/resource-usage-monitoring/)
are available in your cluster, then Pod resource usage can be retrieved either
from the [Metrics API](/docs/tasks/debug-application-cluster/resource-metrics-pipeline/#metrics-api)
from the [Metrics API](/docs/tasks/debug/debug-cluster/resource-metrics-pipeline/#metrics-api)
directly or from your monitoring tools.
## Local ephemeral storage
@@ -126,8 +126,7 @@ Runtime handlers are configured through containerd's configuration at
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.${HANDLER_NAME}]
```
See containerd's config documentation for more details:
https://github.com/containerd/cri/blob/master/docs/config.md
See the containerd [CRI Plugin Config Guide](https://github.com/containerd/containerd/blob/main/docs/cri/config.md) for more details.
#### {{< glossary_tooltip term_id="cri-o" >}}
@@ -46,7 +46,7 @@ Customization approaches can be broadly divided into *configuration*, which only
Flags and configuration files may not always be changeable in a hosted Kubernetes service or a distribution with managed installation. When they are changeable, they are usually only changeable by the cluster administrator. Also, they are subject to change in future Kubernetes versions, and setting them may require restarting processes. For those reasons, they should be used only when there are no other options.
*Built-in Policy APIs*, such as [ResourceQuota](/docs/concepts/policy/resource-quotas/), [PodSecurityPolicies](/docs/concepts/policy/pod-security-policy/), [NetworkPolicy](/docs/concepts/services-networking/network-policies/) and Role-based Access Control ([RBAC](/docs/reference/access-authn-authz/rbac/)), are built-in Kubernetes APIs. APIs are typically used with hosted Kubernetes services and with managed Kubernetes installations. They are declarative and use the same conventions as other Kubernetes resources like pods, so new cluster configuration can be repeatable and be managed the same way as applications. And, where they are stable, they enjoy a [defined support policy](/docs/reference/using-api/deprecation-policy/) like other Kubernetes APIs. For these reasons, they are preferred over *configuration files* and *flags* where suitable.
*Built-in Policy APIs*, such as [ResourceQuota](/docs/concepts/policy/resource-quotas/), [PodSecurityPolicies](/docs/concepts/security/pod-security-policy/), [NetworkPolicy](/docs/concepts/services-networking/network-policies/) and Role-based Access Control ([RBAC](/docs/reference/access-authn-authz/rbac/)), are built-in Kubernetes APIs. APIs are typically used with hosted Kubernetes services and with managed Kubernetes installations. They are declarative and use the same conventions as other Kubernetes resources like pods, so new cluster configuration can be repeatable and be managed the same way as applications. And, where they are stable, they enjoy a [defined support policy](/docs/reference/using-api/deprecation-policy/) like other Kubernetes APIs. For these reasons, they are preferred over *configuration files* and *flags* where suitable.
## Extensions
@@ -350,6 +350,7 @@ Here are some examples of device plugin implementations:
* Requires [nvidia-docker](https://github.com/NVIDIA/nvidia-docker) 2.0, which allows you to run GPU-enabled Docker containers.
* The [NVIDIA GPU device plugin for Container-Optimized OS](https://github.com/GoogleCloudPlatform/container-engine-accelerators/tree/master/cmd/nvidia_gpu)
* The [RDMA device plugin](https://github.com/hustcat/k8s-rdma-device-plugin)
* The [SocketCAN device plugin](https://github.com/collabora/k8s-socketcan)
* The [Solarflare device plugin](https://github.com/vikaschoudhary16/sfc-device-plugin)
* The [SR-IOV Network device plugin](https://github.com/intel/sriov-network-device-plugin)
* The [Xilinx FPGA device plugins](https://github.com/Xilinx/FPGA_as_a_Service/tree/master/k8s-fpga-device-plugin) for Xilinx FPGA devices
@@ -114,7 +114,7 @@ Containers started by Kubernetes automatically include this DNS server in their
### Container Resource Monitoring
[Container Resource Monitoring](/docs/tasks/debug-application-cluster/resource-usage-monitoring/) records generic time-series metrics
[Container Resource Monitoring](/docs/tasks/debug/debug-cluster/resource-usage-monitoring/) records generic time-series metrics
about containers in a central database, and provides a UI for browsing that data.
### Cluster-level Logging
@@ -4,7 +4,7 @@ reviewers:
- mikedanese
title: What is Kubernetes?
description: >
Kubernetes is a portable, extensible, open-source platform for managing containerized workloads and services, that facilitates both declarative configuration and automation. It has a large, rapidly growing ecosystem. Kubernetes services, support, and tools are widely available.
Kubernetes is a portable, extensible, open source platform for managing containerized workloads and services, that facilitates both declarative configuration and automation. It has a large, rapidly growing ecosystem. Kubernetes services, support, and tools are widely available.
content_type: concept
weight: 10
card:
@@ -19,7 +19,7 @@ This page is an overview of Kubernetes.
<!-- body -->
Kubernetes is a portable, extensible, open-source platform for managing containerized workloads and services, that facilitates both declarative configuration and automation. It has a large, rapidly growing ecosystem. Kubernetes services, support, and tools are widely available.
Kubernetes is a portable, extensible, open source platform for managing containerized workloads and services, that facilitates both declarative configuration and automation. It has a large, rapidly growing ecosystem. Kubernetes services, support, and tools are widely available.
The name Kubernetes originates from Greek, meaning helmsman or pilot. K8s as an abbreviation results from counting the eight letters between the "K" and the "s". Google open-sourced the Kubernetes project in 2014. Kubernetes combines [over 15 years of Google's experience](/blog/2015/04/borg-predecessor-to-kubernetes/) running production workloads at scale with best-of-breed ideas and practices from the community.
@@ -33,7 +33,7 @@ specific Pods:
## Node labels {#built-in-node-labels}
Like many other Kubernetes objects, nodes have
[labels](/docs/concepts/overview/working-with-objects/labels/). You can [attach labels manually](/docs/tasks/confiure-pod-container/assign-pods-nodes/#add-a-label-to-a-node).
[labels](/docs/concepts/overview/working-with-objects/labels/). You can [attach labels manually](/docs/tasks/configure-pod-container/assign-pods-nodes/#add-a-label-to-a-node).
Kubernetes also populates a standard set of labels on all nodes in a cluster. See [Well-Known Labels, Annotations and Taints](/docs/reference/labels-annotations-taints/)
for a list of common node labels.
@@ -120,12 +120,12 @@ your Pod spec.
For example, consider the following Pod spec:
{{<codenew file="pods/pod-with-node-affinity.yaml">}}
{{< codenew file="pods/pod-with-node-affinity.yaml" >}}
In this example, the following rules apply:
* The node *must* have a label with the key `kubernetes.io/e2e-az-name` and
the value is either `e2e-az1` or `e2e-az2`.
* The node *must* have a label with the key `kubernetes.io/os` and
the value `linux`.
* The node *preferably* has a label with the key `another-node-label-key` and
the value `another-node-label-value`.
@@ -167,7 +167,7 @@ scheduling decision for the Pod.
For example, consider the following Pod spec:
{{<codenew file="pods/pod-with-affinity-anti-affinity.yaml">}}
{{< codenew file="pods/pod-with-affinity-anti-affinity.yaml" >}}
If there are two possible nodes that match the
`requiredDuringSchedulingIgnoredDuringExecution` rule, one with the
@@ -72,7 +72,7 @@ spec:
runtimeClassName: kata-fc
containers:
- name: busybox-ctr
image: busybox
image: busybox:1.28
stdin: true
tty: true
resources:
@@ -113,7 +113,7 @@ requests and the overhead, then looks for a node that has 2.25 CPU and 320 MiB o
Once a Pod is scheduled to a node, the kubelet on that node creates a new {{< glossary_tooltip text="cgroup" term_id="cgroup" >}}
for the Pod. It is within this pod that the underlying container runtime will create containers.
If the resource has a limit defined for each container (Guaranteed QoS or Bustrable QoS with limits defined),
If the resource has a limit defined for each container (Guaranteed QoS or Burstable QoS with limits defined),
the kubelet will set an upper limit for the pod cgroup associated with that resource (cpu.cfs_quota_us for CPU
and memory.limit_in_bytes memory). This upper limit is based on the sum of the container limits plus the `overhead`
defined in the PodSpec.
@@ -129,6 +129,12 @@ The available Admission Control modules are described in [Admission Controllers]
Once a request passes all admission controllers, it is validated using the validation routines
for the corresponding API object, and then written to the object store (shown as step **4**).
## Auditing
Kubernetes auditing provides a security-relevant, chronological set of records documenting the sequence of actions in a cluster.
The cluster audits the activities generated by users, by applications that use the Kubernetes API, and by the control plane itself.
For more information, see [Auditing](/docs/tasks/debug/debug-cluster/audit/).
## API server ports and IPs
@@ -21,7 +21,7 @@ behavior of pods in a clear, consistent fashion.
As a Beta feature, Kubernetes offers a built-in _Pod Security_ {{< glossary_tooltip
text="admission controller" term_id="admission-controller" >}}, the successor
to [PodSecurityPolicies](/docs/concepts/policy/pod-security-policy/). Pod security restrictions
to [PodSecurityPolicies](/docs/concepts/security/pod-security-policy/). Pod security restrictions
are applied at the {{< glossary_tooltip text="namespace" term_id="namespace" >}} level when pods
are created.
@@ -55,7 +55,7 @@ are available at [https://git.k8s.io/pod-security-admission/webhook](https://git
To install:
```shell
git clone git@github.com:kubernetes/pod-security-admission.git
git clone https://github.com/kubernetes/pod-security-admission.git
cd pod-security-admission/webhook
make certs
kubectl apply -k .
@@ -88,7 +88,7 @@ takes if a potential violation is detected:
Mode | Description
:---------|:------------
**enforce** | Policy violations will cause the pod to be rejected.
**audit** | Policy violations will trigger the addition of an audit annotation to the event recorded in the [audit log](/docs/tasks/debug-application-cluster/audit/), but are otherwise allowed.
**audit** | Policy violations will trigger the addition of an audit annotation to the event recorded in the [audit log](/docs/tasks/debug/debug-cluster/audit/), but are otherwise allowed.
**warn** | Policy violations will trigger a user-facing warning, but are otherwise allowed.
{{< /table >}}
@@ -658,8 +658,7 @@ added. Capabilities listed in `RequiredDropCapabilities` must not be included in
**DefaultAddCapabilities** - The capabilities which are added to containers by
default, in addition to the runtime defaults. See the
[Docker documentation](https://docs.docker.com/engine/reference/run/#runtime-privilege-and-linux-capabilities)
for the default list of capabilities when using the Docker runtime.
the documentation for your container runtime for information on working with Linux capabilities.
### SELinux
@@ -452,7 +452,7 @@ of individual policies are not defined here.
- {{< example file="security/podsecurity-baseline.yaml" >}}Baseline namespace{{< /example >}}
- {{< example file="security/podsecurity-restricted.yaml" >}}Restricted namespace{{< /example >}}
[**PodSecurityPolicy**](/docs/concepts/policy/pod-security-policy/) (Deprecated)
[**PodSecurityPolicy**](/docs/concepts/security/pod-security-policy/) (Deprecated)
- {{< example file="policy/privileged-psp.yaml" >}}Privileged{{< /example >}}
- {{< example file="policy/baseline-psp.yaml" >}}Baseline{{< /example >}}
@@ -478,7 +478,7 @@ in the Pod manifest, and represent parameters to the container runtime.
Security profiles are control plane mechanisms to enforce specific settings in the Security Context,
as well as other related parameters outside the Security Context. As of July 2021,
[Pod Security Policies](/docs/concepts/profile/pod-security-profile/) are deprecated in favor of the
[Pod Security Policies](/docs/concepts/security/pod-security-policy/) are deprecated in favor of the
built-in [Pod Security Admission Controller](/docs/concepts/security/pod-security-admission/).
{{% thirdparty-content %}}
@@ -323,17 +323,6 @@ If the feature gate `ExpandedDNSConfig` is enabled for the kube-apiserver and
the kubelet, it is allowed for Kubernetes to have at most 32 search domains and
a list of search domains of up to 2048 characters.
### Feature availability
The availability of Pod DNS Config and DNS Policy "`None`" is shown as below.
| k8s version | Feature support |
| :---------: |:-----------:|
| 1.14 | Stable |
| 1.10 | Beta (on by default)|
| 1.9 | Alpha |
## {{% heading "whatsnext" %}}
@@ -23,7 +23,7 @@ Kubernetes as a project supports and maintains [AWS](https://github.com/kubernet
{{% thirdparty-content %}}
* [AKS Application Gateway Ingress Controller](https://azure.github.io/application-gateway-kubernetes-ingress/) is an ingress controller that configures the [Azure Application Gateway](https://docs.microsoft.com/azure/application-gateway/overview).
* [AKS Application Gateway Ingress Controller](https://docs.microsoft.com/azure/application-gateway/tutorial-ingress-controller-add-on-existing?toc=https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Faks%2Ftoc.json&bc=https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fbread%2Ftoc.json) is an ingress controller that configures the [Azure Application Gateway](https://docs.microsoft.com/azure/application-gateway/overview).
* [Ambassador](https://www.getambassador.io/) API Gateway is an [Envoy](https://www.envoyproxy.io)-based ingress
controller.
* [Apache APISIX ingress controller](https://github.com/apache/apisix-ingress-controller) is an [Apache APISIX](https://github.com/apache/apisix)-based ingress controller.
@@ -74,7 +74,7 @@ A minimal Ingress resource example:
{{< codenew file="service/networking/minimal-ingress.yaml" >}}
As with all other Kubernetes resources, an Ingress needs `apiVersion`, `kind`, and `metadata` fields.
An Ingress needs `apiVersion`, `kind`, `metadata` and `spec` fields.
The name of an Ingress object must be a valid
[DNS subdomain name](/docs/concepts/overview/working-with-objects/names#dns-subdomain-names).
For general information about working with config files, see [deploying applications](/docs/tasks/run-application/run-stateless-application-deployment/), [configuring containers](/docs/tasks/configure-pod-container/configure-pod-configmap/), [managing resources](/docs/concepts/cluster-administration/manage-deployment/).
@@ -45,42 +45,7 @@ See the [NetworkPolicy](/docs/reference/generated/kubernetes-api/{{< param "vers
An example NetworkPolicy might look like this:
```yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: test-network-policy
namespace: default
spec:
podSelector:
matchLabels:
role: db
policyTypes:
- Ingress
- Egress
ingress:
- from:
- ipBlock:
cidr: 172.17.0.0/16
except:
- 172.17.1.0/24
- namespaceSelector:
matchLabels:
project: myproject
- podSelector:
matchLabels:
role: frontend
ports:
- protocol: TCP
port: 6379
egress:
- to:
- ipBlock:
cidr: 10.0.0.0/24
ports:
- protocol: TCP
port: 5978
```
{{< codenew file="service/networking/networkpolicy.yaml" >}}
{{< note >}}
POSTing this to the API server for your cluster will have no effect unless your chosen networking solution supports network policy.
@@ -281,7 +246,7 @@ the policy will be applied only for the single `port` field.
## Targeting a Namespace by its name
{{< feature-state state="beta" for_k8s_version="1.21" >}}
{{< feature-state for_k8s_version="1.22" state="stable" >}}
The Kubernetes control plane sets an immutable label `kubernetes.io/metadata.name` on all
namespaces, provided that the `NamespaceDefaultLabelName`
@@ -25,7 +25,7 @@ and can load-balance across them.
## Motivation
Kubernetes {{< glossary_tooltip term_id="pod" text="Pods" >}} are created and destroyed
to match the state of your cluster. Pods are nonpermanent resources.
to match the desired state of your cluster. Pods are nonpermanent resources.
If you use a {{< glossary_tooltip term_id="deployment" >}} to run your app,
it can create and destroy Pods dynamically.
@@ -109,12 +109,45 @@ field.
{{< /note >}}
Port definitions in Pods have names, and you can reference these names in the
`targetPort` attribute of a Service. This works even if there is a mixture
of Pods in the Service using a single configured name, with the same network
protocol available via different port numbers.
This offers a lot of flexibility for deploying and evolving your Services.
For example, you can change the port numbers that Pods expose in the next
version of your backend software, without breaking clients.
`targetPort` attribute of a Service. For example, we can bind the `targetPort`
of the Service to the Pod port in the following way:
```yaml
apiVersion: v1
kind: Pod
metadata:
name: nginx
labels:
app.kubernetes.io/name: proxy
spec:
containers:
- name: nginx
image: nginx:11.14.2
ports:
- containerPort: 80
name: http-web-svc
---
apiVersion: v1
kind: Service
metadata:
name: nginx-service
spec:
selector:
app.kubernetes.io/name: proxy
ports:
- name: name-of-service-port
protocol: TCP
port: 80
targetPort: http-web-svc
```
This works even if there is a mixture of Pods in the Service using a single
configured name, with the same network protocol available via different
port numbers. This offers a lot of flexibility for deploying and evolving
your Services. For example, you can change the port numbers that Pods expose
in the next version of your backend software, without breaking clients.
The default protocol for Services is TCP; you can also use any other
[supported protocol](#protocol-support).
@@ -125,9 +158,9 @@ Each port definition can have the same `protocol`, or a different one.
### Services without selectors
Services most commonly abstract access to Kubernetes Pods, but they can also
abstract other kinds of backends.
For example:
Services most commonly abstract access to Kubernetes Pods thanks to the selector,
but when used with a corresponding Endpoints object and without a selector, the Service can abstract other kinds of backends,
including ones that run outside the cluster. For example:
* You want to have an external database cluster in production, but in your
test environment you use your own databases.
@@ -107,7 +107,7 @@ metadata:
spec:
containers:
- name: my-frontend
image: busybox
image: busybox:1.28
volumeMounts:
- mountPath: "/data"
name: my-csi-inline-vol
@@ -125,9 +125,17 @@ driver. These attributes are specific to each driver and not
standardized. See the documentation of each CSI driver for further
instructions.
As a cluster administrator, you can use a [PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/) to control which CSI drivers can be used in a Pod, specified with the
### CSI driver restrictions
{{< feature-state for_k8s_version="v1.21" state="deprecated" >}}
As a cluster administrator, you can use a [PodSecurityPolicy](/docs/concepts/security/pod-security-policy/) to control which CSI drivers can be used in a Pod, specified with the
[`allowedCSIDrivers` field](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#podsecuritypolicyspec-v1beta1-policy).
{{< note >}}
PodSecurityPolicy is deprecated and will be removed in the Kubernetes v1.25 release.
{{< /note >}}
### Generic ephemeral volumes
{{< feature-state for_k8s_version="v1.23" state="stable" >}}
@@ -158,7 +166,7 @@ metadata:
spec:
containers:
- name: my-frontend
image: busybox
image: busybox:1.28
volumeMounts:
- mountPath: "/scratch"
name: scratch-volume
@@ -242,13 +250,12 @@ PVCs indirectly if they can create Pods, even if they do not have
permission to create PVCs directly. Cluster administrators must be
aware of this. If this does not fit their security model, they have
two choices:
- Use a [Pod Security
Policy](/docs/concepts/policy/pod-security-policy/) where the
`volumes` list does not contain the `ephemeral` volume type
(deprecated in Kubernetes 1.21).
- Use an [admission webhook](/docs/reference/access-authn-authz/extensible-admission-controllers/)
which rejects objects like Pods that have a generic ephemeral
that rejects objects like Pods that have a generic ephemeral
volume.
- Use a [Pod Security Policy](/docs/concepts/security/pod-security-policy/)
where the `volumes` list does not contain the `ephemeral` volume type
(deprecated since Kubernetes 1.21).
The normal [namespace quota for PVCs](/docs/concepts/policy/resource-quotas/#storage-resource-quota) still applies, so
even if users are allowed to use this new mechanism, they cannot use
@@ -23,7 +23,7 @@ Currently, the following types of volume sources can be projected:
* [`secret`](/docs/concepts/storage/volumes/#secret)
* [`downwardAPI`](/docs/concepts/storage/volumes/#downwardapi)
* [`configMap`](/docs/concepts/storage/volumes/#configmap)
* `serviceAccountToken`
* [`serviceAccountToken`](#serviceaccounttoken)
All sources are required to be in the same namespace as the Pod. For more details,
see the [all-in-one volume](https://github.com/kubernetes/design-proposals-archive/blob/main/node/all-in-one-volume.md) design document.
@@ -45,6 +45,7 @@ parameters are nearly the same with two exceptions:
volume source. However, as illustrated above, you can explicitly set the `mode`
for each individual projection.
## serviceAccountToken projected volumes {#serviceaccounttoken}
When the `TokenRequestProjection` feature is enabled, you can inject the token
for the current [service account](/docs/reference/access-authn-authz/authentication/#service-account-tokens)
into a Pod at a specified path. For example:
@@ -52,8 +53,9 @@ into a Pod at a specified path. For example:
{{< codenew file="pods/storage/projected-service-account-token.yaml" >}}
The example Pod has a projected volume containing the injected service account
token. This token can be used by a Pod's containers to access the Kubernetes API
server. The `audience` field contains the intended audience of the
token. Containers in this Pod can use that token to access the Kubernetes API
server, authenticating with the identity of [the pod's ServiceAccount](/docs/tasks/configure-pod-container/configure-service-account/).
The `audience` field contains the intended audience of the
token. A recipient of the token must identify itself with an identifier specified
in the audience of the token, and otherwise should reject the token. This field
is optional and it defaults to the identifier of the API server.
@@ -49,7 +49,7 @@ metadata:
name: standard
provisioner: kubernetes.io/aws-ebs
parameters:
type: gp3
type: gp2
reclaimPolicy: Retain
allowVolumeExpansion: true
mountOptions:
@@ -87,7 +87,7 @@ for provisioning PVs. This field must be specified.
You are not restricted to specifying the "internal" provisioners
listed here (whose names are prefixed with "kubernetes.io" and shipped
alongside Kubernetes). You can also run and specify external provisioners,
which are independent programs that follow a [specification](https://git.k8s.io/community/contributors/design-proposals/storage/volume-provisioning.md)
which are independent programs that follow a [specification](https://github.com/kubernetes/design-proposals-archive/blob/main/storage/volume-provisioning.md)
defined by Kubernetes. Authors of external provisioners have full discretion
over where their code lives, how the provisioner is shipped, how it needs to be
run, what volume plugin it uses (including Flex), etc. The repository
@@ -241,8 +241,8 @@ allowedTopologies:
- matchLabelExpressions:
- key: failure-domain.beta.kubernetes.io/zone
values:
- us-central1-a
- us-central1-b
- us-central-1a
- us-central-1b
```
## Parameters
@@ -271,9 +271,9 @@ parameters:
fsType: ext4
```
* `type`: `io1`, `gp2`, `gp3`, `sc1`, `st1`. See
* `type`: `io1`, `gp2`, `sc1`, `st1`. See
[AWS docs](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html)
for details. Default: `gp3`.
for details. Default: `gp2`.
* `zone` (Deprecated): AWS zone. If neither `zone` nor `zones` is specified, volumes are
generally round-robin-ed across all active zones where Kubernetes cluster
has a node. `zone` and `zones` parameters must not be used at the same time.
+16 -2
View File
@@ -152,6 +152,13 @@ Driver](https://github.com/kubernetes-sigs/azuredisk-csi-driver)
must be installed on the cluster and the `CSIMigration` and `CSIMigrationAzureDisk`
features must be enabled.
#### azureDisk CSI migration complete
{{< feature-state for_k8s_version="v1.21" state="alpha" >}}
To disable the `azureDisk` storage plugin from being loaded by the controller manager
and the kubelet, set the `InTreePluginAzureDiskUnregister` flag to `true`.
### azureFile {#azurefile}
The `azureFile` volume type mounts a Microsoft Azure File volume (SMB 2.1 and 3.0)
@@ -172,6 +179,13 @@ must be installed on the cluster and the `CSIMigration` and `CSIMigrationAzureFi
Azure File CSI driver does not support using same volume with different fsgroups, if Azurefile CSI migration is enabled, using same volume with different fsgroups won't be supported at all.
#### azureFile CSI migration complete
{{< feature-state for_k8s_version="v1.21" state="alpha" >}}
To disable the `azureFile` storage plugin from being loaded by the controller manager
and the kubelet, set the `InTreePluginAzureFileUnregister` flag to `true`.
### cephfs
A `cephfs` volume allows an existing CephFS volume to be
@@ -251,7 +265,7 @@ metadata:
spec:
containers:
- name: test
image: busybox
image: busybox:1.28
volumeMounts:
- name: config-vol
mountPath: /etc/config
@@ -1128,7 +1142,7 @@ spec:
fieldRef:
apiVersion: v1
fieldPath: metadata.name
image: busybox
image: busybox:1.28
command: [ "sh", "-c", "while [ true ]; do echo 'Hello'; sleep 10; done | tee -a /logs/hello.txt" ]
volumeMounts:
- name: workdir1
@@ -76,9 +76,9 @@ A Pod Template in a DaemonSet must have a [`RestartPolicy`](/docs/concepts/workl
The `.spec.selector` field is a pod selector. It works the same as the `.spec.selector` of
a [Job](/docs/concepts/workloads/controllers/job/).
As of Kubernetes 1.8, you must specify a pod selector that matches the labels of the
`.spec.template`. The pod selector will no longer be defaulted when left empty. Selector
defaulting was not compatible with `kubectl apply`. Also, once a DaemonSet is created,
You must specify a pod selector that matches the labels of the
`.spec.template`.
Also, once a DaemonSet is created,
its `.spec.selector` can not be mutated. Mutating the pod selector can lead to the
unintentional orphaning of Pods, and it was found to be confusing to users.
@@ -91,8 +91,8 @@ The `.spec.selector` is an object consisting of two fields:
When the two are specified the result is ANDed.
If the `.spec.selector` is specified, it must match the `.spec.template.metadata.labels`.
Config with these not matching will be rejected by the API.
The `.spec.selector` must match the `.spec.template.metadata.labels`.
Config with these two not matching will be rejected by the API.
### Running Pods on select Nodes
@@ -107,7 +107,7 @@ If you do not specify either, then the DaemonSet controller will create Pods on
### Scheduled by default scheduler
{{< feature-state state="stable" for-kubernetes-version="1.17" >}}
{{< feature-state for_k8s_version="1.17" state="stable" >}}
A DaemonSet ensures that all eligible nodes run a copy of a Pod. Normally, the
node that a Pod runs on is selected by the Kubernetes scheduler. However,
@@ -223,8 +223,6 @@ In this manner, a ReplicaSet can own a non-homogenous set of Pods
As with all other Kubernetes API objects, a ReplicaSet needs the `apiVersion`, `kind`, and `metadata` fields.
For ReplicaSets, the `kind` is always a ReplicaSet.
In Kubernetes 1.9 the API version `apps/v1` on the ReplicaSet kind is the current version and is enabled by default. The API version `apps/v1beta2` is deprecated.
Refer to the first lines of the `frontend.yaml` example for guidance.
The name of a ReplicaSet object must be a valid
[DNS subdomain name](/docs/concepts/overview/working-with-objects/names#dns-subdomain-names).
@@ -185,7 +185,7 @@ delete`](/docs/reference/generated/kubectl/kubectl-commands#delete). Kubectl wi
for it to delete each pod before deleting the ReplicationController itself. If this kubectl
command is interrupted, it can be restarted.
When using the REST API or Go client library, you need to do the steps explicitly (scale replicas to
When using the REST API or [client library](/docs/reference/using-api/client-libraries), you need to do the steps explicitly (scale replicas to
0, wait for pod deletions, then delete the ReplicationController).
### Deleting only a ReplicationController
@@ -194,7 +194,7 @@ You can delete a ReplicationController without affecting any of its pods.
Using kubectl, specify the `--cascade=orphan` option to [`kubectl delete`](/docs/reference/generated/kubectl/kubectl-commands#delete).
When using the REST API or Go client library, you can delete the ReplicationController object.
When using the REST API or [client library](/docs/reference/using-api/client-libraries), you can delete the ReplicationController object.
Once the original is deleted, you can create a new ReplicationController to replace it. As long
as the old and new `.spec.selector` are the same, then the new one will adopt the old pods.
@@ -115,7 +115,7 @@ The name of a StatefulSet object must be a valid
### Pod Selector
You must set the `.spec.selector` field of a StatefulSet to match the labels of its `.spec.template.metadata.labels`. In 1.8 and later versions, failing to specify a matching Pod Selector will result in a validation error during StatefulSet creation.
You must set the `.spec.selector` field of a StatefulSet to match the labels of its `.spec.template.metadata.labels`. Failing to specify a matching Pod Selector will result in a validation error during StatefulSet creation.
### Volume Claim Templates
@@ -226,7 +226,7 @@ is completely shutdown, but prior to web-1's termination, web-1 would not be ter
until web-0 is Running and Ready.
### Pod Management Policies
In Kubernetes 1.7 and later, StatefulSet allows you to relax its ordering guarantees while
StatefulSet allows you to relax its ordering guarantees while
preserving its uniqueness and identity guarantees via its `.spec.podManagementPolicy` field.
#### OrderedReady Pod Management
@@ -180,7 +180,7 @@ spec:
spec:
containers:
- name: hello
image: busybox
image: busybox:1.28
command: ['sh', '-c', 'echo "Hello, Kubernetes!" && sleep 3600']
restartPolicy: OnFailure
# The pod template ends here
@@ -261,8 +261,7 @@ Within a Pod, containers share an IP address and port space, and
can find each other via `localhost`. The containers in a Pod can also communicate
with each other using standard inter-process communications like SystemV semaphores
or POSIX shared memory. Containers in different Pods have distinct IP addresses
and can not communicate by IPC without
[special configuration](/docs/concepts/policy/pod-security-policy/).
and can not communicate by OS-level IPC without special configuration.
Containers that want to interact with a container running in a different Pod can
use IP networking to communicate.
@@ -70,5 +70,5 @@ you can view processes in other containers.
## {{% heading "whatsnext" %}}
* Learn how to [debug pods using ephemeral containers](/docs/tasks/debug-application-cluster/debug-running-pod/#ephemeral-container).
* Learn how to [debug pods using ephemeral containers](/docs/tasks/debug/debug-application/debug-running-pod/#ephemeral-container).
@@ -332,5 +332,6 @@ Kubernetes, consult the documentation for the version you are using.
## {{% heading "whatsnext" %}}
* Read about [creating a Pod that has an init container](/docs/tasks/configure-pod-container/configure-pod-initialization/#create-a-pod-that-has-an-init-container)
* Learn how to [debug init containers](/docs/tasks/debug-application-cluster/debug-init-containers/)
* Learn how to [debug init containers](/docs/tasks/debug/debug-application/debug-init-containers/)
@@ -12,14 +12,6 @@ obsolete -->
You can use _topology spread constraints_ to control how {{< glossary_tooltip text="Pods" term_id="Pod" >}} are spread across your cluster among failure-domains such as regions, zones, nodes, and other user-defined topology domains. This can help to achieve high availability as well as efficient resource utilization.
{{< note >}}
In versions of Kubernetes before v1.18, you must enable the `EvenPodsSpread`
[feature gate](/docs/reference/command-line-tools-reference/feature-gates/) on
the [API server](/docs/concepts/overview/components/#kube-apiserver) and the
[scheduler](/docs/reference/command-line-tools-reference/kube-scheduler/) in order to use Pod
topology spread constraints.
{{< /note >}}
<!-- body -->
## Prerequisites
@@ -310,7 +302,8 @@ apiVersion: kubescheduler.config.k8s.io/v1beta3
kind: KubeSchedulerConfiguration
profiles:
- pluginConfig:
- schedulerName: default-scheduler
pluginConfig:
- name: PodTopologySpread
args:
defaultConstraints:
@@ -370,7 +363,8 @@ apiVersion: kubescheduler.config.k8s.io/v1beta3
kind: KubeSchedulerConfiguration
profiles:
- pluginConfig:
- schedulerName: default-scheduler
pluginConfig:
- name: PodTopologySpread
args:
defaultConstraints: []
@@ -27,6 +27,8 @@ API or the `kube-*` components from the upstream code, see the following instruc
- [Golang](https://golang.org/doc/install) version 1.13+
- [Docker](https://docs.docker.com/engine/installation/)
- [etcd](https://github.com/coreos/etcd/)
- [make](https://www.gnu.org/software/make/)
- [gcc compiler/linker](https://gcc.gnu.org/)
- Your `GOPATH` environment variable must be set, and the location of `etcd`
must be in your `PATH` environment variable.
@@ -142,8 +144,9 @@ Run `git status` to see what was generated.
On branch master
...
modified: api/openapi-spec/swagger.json
modified: api/openapi-spec/v3/apis__apps__v1_openapi.json
modified: pkg/generated/openapi/zz_generated.openapi.go
modified: staging/src/k8s.io/api/apps/v1/generated.proto
modified: staging/src/k8s.io/api/apps/v1/types.go
modified: staging/src/k8s.io/api/apps/v1/types_swagger_doc_generated.go
```
+5 -2
View File
@@ -125,11 +125,14 @@ Add a configuration block for the new language to `config.toml`, under the exist
[languages.de]
title = "Kubernetes"
description = "Produktionsreife Container-Verwaltung"
languageName = "Deutsch"
languageName = "Deutsch (German)"
languageNameLatinScript = "German"
contentDir = "content/de"
weight = 3
weight = 8
```
The value for `languageName` will be listed in language selection bar. Assign "language name in native script (language name in latin script)" to `languageName`, for example, `languageName = "한국어 (Korean)"`. `languageNameLatinScript` can be used to access the language name in latin script and use it in the theme. Assign "language name in latin script" to `languageNameLatinScript`, for example, `languageNameLatinScript ="Korean"`.
When assigning a `weight` parameter for your block, find the language block with the highest weight and add 1 to that value.
For more information about Hugo's multilingual support, see "[Multilingual Mode](https://gohugo.io/content-management/multilingual/)".
@@ -87,3 +87,17 @@ To close a pull request, leave a `/close` comment on the PR.
The [`fejta-bot`](https://github.com/fejta-bot) bot marks issues as stale after 90 days of inactivity. After 30 more days it marks issues as rotten and closes them. PR wranglers should close issues after 14-30 days of inactivity.
{{< /note >}}
## PR Wrangler shadow program
In late 2021, SIG Docs introduced the PR Wrangler Shadow Program. The program was introduced to help new contributors understand the PR wrangling process.
### Become a shadow
- If you are interested in shadowing as a PR wrangler, please visit the [PR Wranglers Wiki page](https://github.com/kubernetes/website/wiki/PR-Wranglers) to see the PR wrangling schedule for this year and sign up.
- Kubernetes org members can edit the [PR Wranglers Wiki page](https://github.com/kubernetes/website/wiki/PR-Wranglers) and sign up to shadow an existing PR Wrangler for a week.
- Others can reach out on the [#sig-docs Slack channel](https://kubernetes.slack.com/messages/sig-docs) for requesting to shadow an assigned PR Wrangler for a specific week. Feel free to reach out to Brad Topol (`@bradtopol`) or one of the [SIG Docs co-chairs/leads](https://github.com/kubernetes/community/tree/master/sig-docs#leadership).
- Once you've signed up to shadow a PR Wrangler, introduce yourself to the PR Wrangler on the [Kubernetes Slack](slack.k8s.io).
@@ -8,7 +8,7 @@ weight: 15
<!--Overview-->
This guide shows you how to create, edit and share diagrams using the Mermaid
Javascript library. Mermaid.js allows you to generate diagrams using a simple
JavaScript library. Mermaid.js allows you to generate diagrams using a simple
markdown-like syntax inside Markdown files. You can also use Mermaid to
generate `.svg` or `.png` image files that you can add to your documentation.
@@ -46,7 +46,7 @@ To run the link checker:
2. Run the following command:
```
make docker-internal-linkcheck
make container-internal-linkcheck
```
## Understanding the output
@@ -33,13 +33,13 @@ properties:
- `group`, type string; if you specify `group`, it must match one of the groups of the authenticated user. `system:authenticated` matches all authenticated requests. `system:unauthenticated` matches all unauthenticated requests.
- Resource-matching properties:
- `apiGroup`, type string; an API group.
- Ex: `extensions`
- Ex: `apps`, `networking.k8s.io`
- Wildcard: `*` matches all API groups.
- `namespace`, type string; a namespace.
- Ex: `kube-system`
- Wildcard: `*` matches all resource requests.
- `resource`, type string; a resource type
- Ex: `pods`
- Ex: `pods`, `deployments`
- Wildcard: `*` matches all resource requests.
- Non-resource-matching properties:
- `nonResourcePath`, type string; non-resource request paths.
@@ -716,7 +716,7 @@ for more information.
This admission controller acts on creation and modification of the pod and determines if it should be admitted
based on the requested security context and the available Pod Security Policies.
See also [Pod Security Policy documentation](/docs/concepts/policy/pod-security-policy/)
See also the [PodSecurityPolicy](/docs/concepts/security/pod-security-policy/) documentation
for more information.
### PodTolerationRestriction {#podtolerationrestriction}
@@ -777,14 +777,17 @@ for more information.
### SecurityContextDeny {#securitycontextdeny}
This admission controller will deny any pod that attempts to set certain escalating
This admission controller will deny any Pod that attempts to set certain escalating
[SecurityContext](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#securitycontext-v1-core)
fields, as shown in the
[Configure a Security Context for a Pod or Container](/docs/tasks/configure-pod-container/security-context/)
task.
This should be enabled if a cluster doesn't utilize
[pod security policies](/docs/concepts/policy/pod-security-policy/)
to restrict the set of values a security context can take.
If you don't use [Pod Security admission](/docs/concepts/security/pod-security-admission/),
[PodSecurityPolicies](/docs/concepts/security/pod-security-policy/), nor any external enforcement mechanism,
then you could use this admission controller to restrict the set of values a security context can take.
See [Pod Security Standards](/docs/concepts/security/pod-security-standards/) for more context on restricting
pod privileges.
### ServiceAccount {#serviceaccount}
@@ -121,7 +121,7 @@ token,user,uid,"group1,group2,group3"
When using bearer token authentication from an http client, the API
server expects an `Authorization` header with a value of `Bearer
THETOKEN`. The bearer token must be a character sequence that can be
<token>`. The bearer token must be a character sequence that can be
put in an HTTP header value using no more than the encoding and
quoting facilities of HTTP. For example: if the bearer token is
`31ada4fd-adec-460c-809a-9e56ceb75269` then it would appear in an HTTP
@@ -76,7 +76,7 @@ DELETE | delete (for individual resources), deletecollection (for collections
Kubernetes sometimes checks authorization for additional permissions using specialized verbs. For example:
* [PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/)
* [PodSecurityPolicy](/docs/concepts/security/pod-security-policy/)
* `use` verb on `podsecuritypolicies` resources in the `policy` API group.
* [RBAC](/docs/reference/access-authn-authz/rbac/#privilege-escalation-prevention-and-bootstrapping)
* `bind` and `escalate` verbs on `roles` and `clusterroles` resources in the `rbac.authorization.k8s.io` API group.
@@ -1396,7 +1396,7 @@ monitoring mechanisms help cluster admins to answer questions like:
Sometimes it's useful to know which mutating webhook mutated the object in a API request, and what change did the
webhook apply.
In v1.16+, kube-apiserver performs [auditing](/docs/tasks/debug-application-cluster/audit/) on each mutating webhook
In v1.16+, kube-apiserver performs [auditing](/docs/tasks/debug/debug-cluster/audit/) on each mutating webhook
invocation. Each invocation generates an auditing annotation
capturing if a request object is mutated by the invocation, and optionally generates an annotation capturing the applied
patch from the webhook admission response. The annotations are set in the audit event for given request on given stage of
@@ -31,7 +31,7 @@ kube-apiserver --authorization-mode=Example,RBAC --other-options --more-options
The RBAC API declares four kinds of Kubernetes object: _Role_, _ClusterRole_,
_RoleBinding_ and _ClusterRoleBinding_. You can
[describe objects](/docs/concepts/overview/working-with-objects/kubernetes-objects/#understanding-kubernetes-objects),
or amend them, using tools such as `kubectl,` just like any other Kubernetes object.
or amend them, using tools such as `kubectl`, just like any other Kubernetes object.
{{< caution >}}
These objects, by design, impose access restrictions. If you are making changes
@@ -384,11 +384,11 @@ rules:
```
Allow reading/writing Deployments (at the HTTP level: objects with `"deployments"`
in the resource part of their URL) in both the `"extensions"` and `"apps"` API groups:
in the resource part of their URL) in the `"apps"` API groups:
```yaml
rules:
- apiGroups: ["extensions", "apps"]
- apiGroups: ["apps"]
#
# at the HTTP level, the name of the resource for accessing Deployment
# objects is "deployments"
@@ -397,7 +397,7 @@ rules:
```
Allow reading Pods in the core API group, as well as reading or writing Job
resources in the `"batch"` or `"extensions"` API groups:
resources in the `"batch"` API group:
```yaml
rules:
@@ -407,7 +407,7 @@ rules:
# objects is "pods"
resources: ["pods"]
verbs: ["get", "list", "watch"]
- apiGroups: ["batch", "extensions"]
- apiGroups: ["batch"]
#
# at the HTTP level, the name of the resource for accessing Job
# objects is "jobs"
@@ -517,7 +517,7 @@ subjects:
namespace: kube-system
```
For all service accounts in the "qa" group in any namespace:
For all service accounts in the "qa" namespace:
```yaml
subjects:
@@ -525,15 +525,6 @@ subjects:
name: system:serviceaccounts:qa
apiGroup: rbac.authorization.k8s.io
```
For all service accounts in the "dev" group in the "development" namespace:
```yaml
subjects:
- kind: Group
name: system:serviceaccounts:dev
apiGroup: rbac.authorization.k8s.io
namespace: development
```
For all service accounts in any namespace:
@@ -63,7 +63,8 @@ different Kubernetes components.
| `AllowInsecureBackendProxy` | `true` | Beta | 1.17 | |
| `AnyVolumeDataSource` | `false` | Alpha | 1.18 | |
| `AppArmor` | `true` | Beta | 1.4 | |
| `ControllerManagerLeaderMigration` | `false` | Alpha | 1.21 | |
| `ControllerManagerLeaderMigration` | `false` | Alpha | 1.21 | 1.21 |
| `ControllerManagerLeaderMigration` | `true` | Beta | 1.22 | |
| `CPUManager` | `false` | Alpha | 1.8 | 1.9 |
| `CPUManager` | `true` | Beta | 1.10 | |
| `CPUManagerPolicyAlphaOptions` | `false` | Alpha | 1.23 | |
@@ -74,7 +75,7 @@ different Kubernetes components.
| `CSIInlineVolume` | `true` | Beta | 1.16 | - |
| `CSIMigration` | `false` | Alpha | 1.14 | 1.16 |
| `CSIMigration` | `true` | Beta | 1.17 | |
| `CSIMigrationAWS` | `false` | Alpha | 1.14 | |
| `CSIMigrationAWS` | `false` | Alpha | 1.14 | 1.16 |
| `CSIMigrationAWS` | `false` | Beta | 1.17 | 1.22 |
| `CSIMigrationAWS` | `true` | Beta | 1.23 | |
| `CSIMigrationAzureDisk` | `false` | Alpha | 1.15 | 1.18 |
@@ -129,6 +130,7 @@ different Kubernetes components.
| `GracefulNodeShutdown` | `false` | Alpha | 1.20 | 1.20 |
| `GracefulNodeShutdown` | `true` | Beta | 1.21 | |
| `GracefulNodeShutdownBasedOnPodPriority` | `false` | Alpha | 1.23 | |
| `GracefulNodeShutdownBasedOnPodPriority` | `true` | Beta | 1.24 | |
| `GRPCContainerProbe` | `false` | Alpha | 1.23 | |
| `HonorPVReclaimPolicy` | `false` | Alpha | 1.23 | |
| `HPAContainerMetrics` | `false` | Alpha | 1.20 | |
@@ -428,6 +430,7 @@ different Kubernetes components.
| `ServerSideApply` | `false` | Alpha | 1.14 | 1.15 |
| `ServerSideApply` | `true` | Beta | 1.16 | 1.21 |
| `ServerSideApply` | `true` | GA | 1.22 | - |
| `ServerSideFieldValidation` | `false` | Alpha | 1.23 | - |
| `ServiceAccountIssuerDiscovery` | `false` | Alpha | 1.18 | 1.19 |
| `ServiceAccountIssuerDiscovery` | `true` | Beta | 1.20 | 1.20 |
| `ServiceAccountIssuerDiscovery` | `true` | GA | 1.21 | - |
@@ -567,7 +570,7 @@ Each feature gate is designed for enabling/disabling a specific feature:
Docker Engine; no longer available. See
[Device Plugins](/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/) for
an alternative.
- `AdvancedAuditing`: Enable [advanced auditing](/docs/tasks/debug-application-cluster/audit/#advanced-audit)
- `AdvancedAuditing`: Enable [advanced auditing](/docs/tasks/debug/debug-cluster/audit/#advanced-audit)
- `AffinityInAnnotations`: Enable setting
[Pod affinity or anti-affinity](/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity).
- `AllowExtTrafficLocalEndpoints`: Enable a service to route external requests to node local endpoints.
@@ -579,39 +582,47 @@ Each feature gate is designed for enabling/disabling a specific feature:
See [AppArmor Tutorial](/docs/tutorials/security/apparmor/) for more details.
- `AttachVolumeLimit`: Enable volume plugins to report limits on number of volumes
that can be attached to a node.
See [dynamic volume limits](/docs/concepts/storage/storage-limits/#dynamic-volume-limits) for more details.
- `BalanceAttachedNodeVolumes`: Include volume count on node to be considered for balanced resource allocation
while scheduling. A node which has closer CPU, memory utilization, and volume count is favored by the scheduler
while making decisions.
See [dynamic volume limits](/docs/concepts/storage/storage-limits/#dynamic-volume-limits)
for more details.
- `BalanceAttachedNodeVolumes`: Include volume count on node to be considered for
balanced resource allocation while scheduling. A node which has closer CPU,
memory utilization, and volume count is favored by the scheduler while making decisions.
- `BlockVolume`: Enable the definition and consumption of raw block devices in Pods.
See [Raw Block Volume Support](/docs/concepts/storage/persistent-volumes/#raw-block-volume-support)
for more details.
- `BoundServiceAccountTokenVolume`: Migrate ServiceAccount volumes to use a projected volume consisting of a
ServiceAccountTokenVolumeProjection. Cluster admins can use metric `serviceaccount_stale_tokens_total` to
monitor workloads that are depending on the extended tokens. If there are no such workloads, turn off
extended tokens by starting `kube-apiserver` with flag `--service-account-extend-token-expiration=false`.
- `BoundServiceAccountTokenVolume`: Migrate ServiceAccount volumes to use a projected volume
consisting of a ServiceAccountTokenVolumeProjection. Cluster admins can use metric
`serviceaccount_stale_tokens_total` to monitor workloads that are depending on the extended
tokens. If there are no such workloads, turn off extended tokens by starting `kube-apiserver` with
flag `--service-account-extend-token-expiration=false`.
Check [Bound Service Account Tokens](https://github.com/kubernetes/enhancements/blob/master/keps/sig-auth/1205-bound-service-account-tokens/README.md)
for more details.
for more details.
- `ControllerManagerLeaderMigration`: Enables Leader Migration for
[kube-controller-manager](/docs/tasks/administer-cluster/controller-manager-leader-migration/#initial-leader-migration-configuration) and
[cloud-controller-manager](/docs/tasks/administer-cluster/controller-manager-leader-migration/#deploy-cloud-controller-manager) which allows a cluster operator to live migrate
[cloud-controller-manager](/docs/tasks/administer-cluster/controller-manager-leader-migration/#deploy-cloud-controller-manager)
which allows a cluster operator to live migrate
controllers from the kube-controller-manager into an external controller-manager
(e.g. the cloud-controller-manager) in an HA cluster without downtime.
- `CPUManager`: Enable container level CPU affinity support, see
[CPU Management Policies](/docs/tasks/administer-cluster/cpu-management-policies/).
- `CPUManagerPolicyAlphaOptions`: This allows fine-tuning of CPUManager policies, experimental, Alpha-quality options
- `CPUManagerPolicyAlphaOptions`: This allows fine-tuning of CPUManager policies,
experimental, Alpha-quality options
This feature gate guards *a group* of CPUManager options whose quality level is alpha.
This feature gate will never graduate to beta or stable.
- `CPUManagerPolicyBetaOptions`: This allows fine-tuning of CPUManager policies, experimental, Beta-quality options
- `CPUManagerPolicyBetaOptions`: This allows fine-tuning of CPUManager policies,
experimental, Beta-quality options
This feature gate guards *a group* of CPUManager options whose quality level is beta.
This feature gate will never graduate to stable.
- `CPUManagerPolicyOptions`: Allow fine-tuning of CPUManager policies.
- `CRIContainerLogRotation`: Enable container log rotation for CRI container runtime. The default max size of a log file is 10MB and the
default max number of log files allowed for a container is 5. These values can be configured in the kubelet config.
See the [logging at node level](/docs/concepts/cluster-administration/logging/#logging-at-the-node-level) documentation for more details.
- `CRIContainerLogRotation`: Enable container log rotation for CRI container runtime.
The default max size of a log file is 10MB and the default max number of
log files allowed for a container is 5.
These values can be configured in the kubelet config.
See [logging at node level](/docs/concepts/cluster-administration/logging/#logging-at-the-node-level)
for more details.
- `CSIBlockVolume`: Enable external CSI volume drivers to support block storage.
See the [`csi` raw block volume support](/docs/concepts/storage/volumes/#csi-raw-block-volume-support)
documentation for more details.
See [`csi` raw block volume support](/docs/concepts/storage/volumes/#csi-raw-block-volume-support)
for more details.
- `CSIDriverRegistry`: Enable all logic related to the CSIDriver API object in
csi.storage.k8s.io.
- `CSIInlineVolume`: Enable CSI Inline volumes support for pods.
@@ -643,7 +654,8 @@ Each feature gate is designed for enabling/disabling a specific feature:
AzureDisk CSI plugin. Requires CSIMigration and CSIMigrationAzureDisk feature
flags enabled and AzureDisk CSI plugin installed and configured on all nodes
in the cluster. This flag has been deprecated in favor of the
`InTreePluginAzureDiskUnregister` feature flag which prevents the registration of in-tree AzureDisk plugin.
`InTreePluginAzureDiskUnregister` feature flag which prevents the registration
of in-tree AzureDisk plugin.
- `CSIMigrationAzureFile`: Enables shims and translation logic to route volume
operations from the Azure-File in-tree plugin to AzureFile CSI plugin.
Supports falling back to in-tree AzureFile plugin for mount operations to
@@ -666,19 +678,13 @@ Each feature gate is designed for enabling/disabling a specific feature:
Does not support falling back for provision operations, for those the CSI
plugin must be installed and configured. Requires CSIMigration feature flag
enabled.
- `csiMigrationRBD`: Enables shims and translation logic to route volume
operations from the RBD in-tree plugin to Ceph RBD CSI plugin. Requires
CSIMigration and csiMigrationRBD feature flags enabled and Ceph CSI plugin
installed and configured in the cluster. This flag has been deprecated in
favor of the
`InTreePluginRBDUnregister` feature flag which prevents the registration of
in-tree RBD plugin.
- `CSIMigrationGCEComplete`: Stops registering the GCE-PD in-tree plugin in
kubelet and volume controllers and enables shims and translation logic to
route volume operations from the GCE-PD in-tree plugin to PD CSI plugin.
Requires CSIMigration and CSIMigrationGCE feature flags enabled and PD CSI
plugin installed and configured on all nodes in the cluster. This flag has
been deprecated in favor of the `InTreePluginGCEUnregister` feature flag which prevents the registration of in-tree GCE PD plugin.
been deprecated in favor of the `InTreePluginGCEUnregister` feature flag which
prevents the registration of in-tree GCE PD plugin.
- `CSIMigrationOpenStack`: Enables shims and translation logic to route volume
operations from the Cinder in-tree plugin to Cinder CSI plugin. Supports
falling back to in-tree Cinder plugin for mount operations to nodes that have
@@ -691,7 +697,14 @@ Each feature gate is designed for enabling/disabling a specific feature:
volume operations from the Cinder in-tree plugin to Cinder CSI plugin.
Requires CSIMigration and CSIMigrationOpenStack feature flags enabled and Cinder
CSI plugin installed and configured on all nodes in the cluster. This flag has
been deprecated in favor of the `InTreePluginOpenStackUnregister` feature flag which prevents the registration of in-tree openstack cinder plugin.
been deprecated in favor of the `InTreePluginOpenStackUnregister` feature flag
which prevents the registration of in-tree openstack cinder plugin.
- `csiMigrationRBD`: Enables shims and translation logic to route volume
operations from the RBD in-tree plugin to Ceph RBD CSI plugin. Requires
CSIMigration and csiMigrationRBD feature flags enabled and Ceph CSI plugin
installed and configured in the cluster. This flag has been deprecated in
favor of the `InTreePluginRBDUnregister` feature flag which prevents the registration of
in-tree RBD plugin.
- `CSIMigrationvSphere`: Enables shims and translation logic to route volume operations
from the vSphere in-tree plugin to vSphere CSI plugin. Supports falling back
to in-tree vSphere plugin for mount operations to nodes that have the feature
@@ -704,11 +717,12 @@ Each feature gate is designed for enabling/disabling a specific feature:
from the vSphere in-tree plugin to vSphere CSI plugin. Requires CSIMigration and
CSIMigrationvSphere feature flags enabled and vSphere CSI plugin installed and
configured on all nodes in the cluster. This flag has been deprecated in favor
of the `InTreePluginvSphereUnregister` feature flag which prevents the registration of in-tree vsphere plugin.
of the `InTreePluginvSphereUnregister` feature flag which prevents the
registration of in-tree vsphere plugin.
- `CSIMigrationPortworx`: Enables shims and translation logic to route volume operations
from the Portworx in-tree plugin to Portworx CSI plugin.
Requires Portworx CSI driver to be installed and configured in the cluster, and feature gate set `CSIMigrationPortworx=true` in kube-controller-manager and kubelet configs.
- `CSINodeInfo`: Enable all logic related to the CSINodeInfo API object in csi.storage.k8s.io.
Requires Portworx CSI driver to be installed and configured in the cluster.
- `CSINodeInfo`: Enable all logic related to the CSINodeInfo API object in `csi.storage.k8s.io`.
- `CSIPersistentVolume`: Enable discovering and mounting volumes provisioned through a
[CSI (Container Storage Interface)](https://github.com/kubernetes/community/blob/master/contributors/design-proposals/storage/container-storage-interface.md)
compatible volume plugin.
@@ -736,7 +750,9 @@ Each feature gate is designed for enabling/disabling a specific feature:
version 1 of the same controller is selected.
- `CustomCPUCFSQuotaPeriod`: Enable nodes to change `cpuCFSQuotaPeriod` in
[kubelet config](/docs/tasks/administer-cluster/kubelet-config-file/).
- `CustomResourceValidationExpressions`: Enable expression language validation in CRD which will validate customer resource based on validation rules written in `x-kubernetes-validations` extension.
- `CustomResourceValidationExpressions`: Enable expression language validation in CRD
which will validate customer resource based on validation rules written in
the `x-kubernetes-validations` extension.
- `CustomPodDNS`: Enable customizing the DNS settings for a Pod using its `dnsConfig` property.
Check [Pod's DNS Config](/docs/concepts/services-networking/dns-pod-service/#pods-dns-config)
for more details.
@@ -819,7 +835,8 @@ Each feature gate is designed for enabling/disabling a specific feature:
host mounts, or containers that are privileged or using specific non-namespaced
capabilities (e.g. `MKNODE`, `SYS_MODULE` etc.). This should only be enabled
if user namespace remapping is enabled in the Docker daemon.
- `ExternalPolicyForExternalIP`: Fix a bug where ExternalTrafficPolicy is not applied to Service ExternalIPs.
- `ExternalPolicyForExternalIP`: Fix a bug where ExternalTrafficPolicy is not
applied to Service ExternalIPs.
- `GCERegionalPersistentDisk`: Enable the regional PD feature on GCE.
- `GenericEphemeralVolume`: Enables ephemeral, inline volumes that support all features
of normal volumes (can be provided by third-party storage vendors, storage capacity tracking,
@@ -832,8 +849,10 @@ Each feature gate is designed for enabling/disabling a specific feature:
for more details.
- `GracefulNodeShutdownBasedOnPodPriority`: Enables the kubelet to check Pod priorities
when shutting down a node gracefully.
- `GRPCContainerProbe`: Enables the gRPC probe method for {Liveness,Readiness,Startup}Probe. See [Configure Liveness, Readiness and Startup Probes](/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-a-grpc-liveness-probe).
- `HonorPVReclaimPolicy`: Honor persistent volume reclaim policy when it is `Delete` irrespective of PV-PVC deletion ordering.
- `GRPCContainerProbe`: Enables the gRPC probe method for {Liveness,Readiness,Startup}Probe.
See [Configure Liveness, Readiness and Startup Probes](/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-a-grpc-liveness-probe).
- `HonorPVReclaimPolicy`: Honor persistent volume reclaim policy when it is `Delete`
irrespective of PV-PVC deletion ordering.
- `HPAContainerMetrics`: Enable the `HorizontalPodAutoscaler` to scale based on
metrics from individual containers in target pods.
- `HPAScaleToZero`: Enables setting `minReplicas` to 0 for `HorizontalPodAutoscaler`
@@ -845,10 +864,19 @@ Each feature gate is designed for enabling/disabling a specific feature:
- `HyperVContainer`: Enable
[Hyper-V isolation](https://docs.microsoft.com/en-us/virtualization/windowscontainers/manage-containers/hyperv-container)
for Windows containers.
- `IdentifyPodOS`: Allows the Pod OS field to be specified. This helps in identifying the OS of the pod
authoritatively during the API server admission time. In Kubernetes {{< skew currentVersion >}}, the allowed values for the `pod.spec.os.name` are `windows` and `linux`.
- `IdentifyPodOS`: Allows the Pod OS field to be specified. This helps in identifying
the OS of the pod authoritatively during the API server admission time.
In Kubernetes {{< skew currentVersion >}}, the allowed values for the `pod.spec.os.name`
are `windows` and `linux`.
- `ImmutableEphemeralVolumes`: Allows for marking individual Secrets and ConfigMaps as
immutable for better safety and performance.
- `IndexedJob`: Allows the [Job](/docs/concepts/workloads/controllers/job/)
controller to manage Pod completions per completion index.
- `IngressClassNamespacedParams`: Allow namespace-scoped parameters reference in
`IngressClass` resource. This feature adds two fields - `Scope` and `Namespace`
to `IngressClass.spec.parameters`.
- `Initializers`: Allow asynchronous coordination of object creation using the
Initializers admission plugin.
- `InTreePluginAWSUnregister`: Stops registering the aws-ebs in-tree plugin in kubelet
and volume controllers.
- `InTreePluginAzureDiskUnregister`: Stops registering the azuredisk in-tree plugin in kubelet
@@ -865,13 +893,6 @@ Each feature gate is designed for enabling/disabling a specific feature:
and volume controllers.
- `InTreePluginvSphereUnregister`: Stops registering the vSphere in-tree plugin in kubelet
and volume controllers.
- `IndexedJob`: Allows the [Job](/docs/concepts/workloads/controllers/job/)
controller to manage Pod completions per completion index.
- `IngressClassNamespacedParams`: Allow namespace-scoped parameters reference in
`IngressClass` resource. This feature adds two fields - `Scope` and `Namespace`
to `IngressClass.spec.parameters`.
- `Initializers`: Allow asynchronous coordination of object creation using the
Initializers admission plugin.
- `IPv6DualStack`: Enable [dual stack](/docs/concepts/services-networking/dual-stack/)
support for IPv6.
- `JobMutableNodeSchedulingDirectives`: Allows updating node scheduling directives in
@@ -889,17 +910,21 @@ Each feature gate is designed for enabling/disabling a specific feature:
a file specified using a config file.
See [setting kubelet parameters via a config file](/docs/tasks/administer-cluster/kubelet-config-file/)
for more details.
- `KubeletCredentialProviders`: Enable kubelet exec credential providers for image pull credentials.
- `KubeletInUserNamespace`: Enables support for running kubelet in a {{<glossary_tooltip text="user namespace" term_id="userns">}}.
- `KubeletCredentialProviders`: Enable kubelet exec credential providers for
image pull credentials.
- `KubeletInUserNamespace`: Enables support for running kubelet in a
{{<glossary_tooltip text="user namespace" term_id="userns">}}.
See [Running Kubernetes Node Components as a Non-root User](/docs/tasks/administer-cluster/kubelet-in-userns/).
- `KubeletPluginsWatcher`: Enable probe-based plugin watcher utility to enable kubelet
to discover plugins such as [CSI volume drivers](/docs/concepts/storage/volumes/#csi).
- `KubeletPodResources`: Enable the kubelet's pod resources gRPC endpoint. See
[Support Device Monitoring](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/606-compute-device-assignment/README.md)
for more details.
- `KubeletPodResourcesGetAllocatable`: Enable the kubelet's pod resources `GetAllocatableResources` functionality.
This API augments the [resource allocation reporting](/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/#monitoring-device-plugin-resources)
with informations about the allocatable resources, enabling clients to properly track the free compute resources on a node.
- `KubeletPodResourcesGetAllocatable`: Enable the kubelet's pod resources
`GetAllocatableResources` functionality. This API augments the
[resource allocation reporting](/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/#monitoring-device-plugin-resources)
with informations about the allocatable resources, enabling clients to properly
track the free compute resources on a node.
- `LegacyNodeRoleBehavior`: When disabled, legacy behavior in service load balancers and
node disruption will ignore the `node-role.kubernetes.io/master` label in favor of the
feature-specific labels provided by `NodeDisruptionExclusion` and `ServiceNodeExclusion`.
@@ -918,18 +943,22 @@ Each feature gate is designed for enabling/disabling a specific feature:
based on logarithmic bucketing of pod timestamps.
- `MemoryManager`: Allows setting memory affinity for a container based on
NUMA topology.
- `MemoryQoS`: Enable memory protection and usage throttle on pod / container using cgroup v2 memory controller.
- `MemoryQoS`: Enable memory protection and usage throttle on pod / container using
cgroup v2 memory controller.
- `MixedProtocolLBService`: Enable using different protocols in the same `LoadBalancer` type
Service instance.
- `MountContainers`: Enable using utility containers on host as the volume mounter.
- `MountPropagation`: Enable sharing volume mounted by one container to other containers or pods.
For more details, please see [mount propagation](/docs/concepts/storage/volumes/#mount-propagation).
- `NamespaceDefaultLabelName`: Configure the API Server to set an immutable {{< glossary_tooltip text="label" term_id="label" >}}
`kubernetes.io/metadata.name` on all namespaces, containing the namespace name.
- `NetworkPolicyEndPort`: Enable use of the field `endPort` in NetworkPolicy objects, allowing the selection of a port range instead of a single port.
- `NamespaceDefaultLabelName`: Configure the API Server to set an immutable
{{< glossary_tooltip text="label" term_id="label" >}} `kubernetes.io/metadata.name`
on all namespaces, containing the namespace name.
- `NetworkPolicyEndPort`: Enable use of the field `endPort` in NetworkPolicy objects,
allowing the selection of a port range instead of a single port.
- `NodeDisruptionExclusion`: Enable use of the Node label `node.kubernetes.io/exclude-disruption`
which prevents nodes from being evacuated during zone failures.
- `NodeLease`: Enable the new Lease API to report node heartbeats, which could be used as a node health signal.
- `NodeLease`: Enable the new Lease API to report node heartbeats, which could be used
as a node health signal.
- `NodeSwap`: Enable the kubelet to allocate swap memory for Kubernetes workloads on a node.
Must be used with `KubeletConfiguration.failSwapOn` set to false.
For more details, please see [swap memory](/docs/concepts/architecture/nodes/#swap-memory)
@@ -937,23 +966,23 @@ Each feature gate is designed for enabling/disabling a specific feature:
- `OpenAPIEnums`: Enables populating "enum" fields of OpenAPI schemas in the
spec returned from the API server.
- `OpenAPIV3`: Enables the API server to publish OpenAPI v3.
- `PVCProtection`: Enable the prevention of a PersistentVolumeClaim (PVC) from
being deleted when it is still used by any Pod.
- `PodDeletionCost`: Enable the [Pod Deletion Cost](/docs/concepts/workloads/controllers/replicaset/#pod-deletion-cost)
feature which allows users to influence ReplicaSet downscaling order.
- `PersistentLocalVolumes`: Enable the usage of `local` volume type in Pods.
Pod affinity has to be specified if requesting a `local` volume.
- `PodAndContainerStatsFromCRI`: Configure the kubelet to gather container and pod stats from the CRI container runtime
rather than gathering them from cAdvisor.
- `PodAndContainerStatsFromCRI`: Configure the kubelet to gather container and
pod stats from the CRI container runtime rather than gathering them from cAdvisor.
- `PodDisruptionBudget`: Enable the [PodDisruptionBudget](/docs/tasks/run-application/configure-pdb/) feature.
- `PodAffinityNamespaceSelector`: Enable the [Pod Affinity Namespace Selector](/docs/concepts/scheduling-eviction/assign-pod-node/#namespace-selector)
and [CrossNamespacePodAffinity](/docs/concepts/policy/resource-quotas/#cross-namespace-pod-affinity-quota) quota scope features.
- `PodAffinityNamespaceSelector`: Enable the
[Pod Affinity Namespace Selector](/docs/concepts/scheduling-eviction/assign-pod-node/#namespace-selector)
and [CrossNamespacePodAffinity](/docs/concepts/policy/resource-quotas/#cross-namespace-pod-affinity-quota)
quota scope features.
- `PodOverhead`: Enable the [PodOverhead](/docs/concepts/scheduling-eviction/pod-overhead/)
feature to account for pod overheads.
- `PodPriority`: Enable the descheduling and preemption of Pods based on their
[priorities](/docs/concepts/scheduling-eviction/pod-priority-preemption/).
- `PodReadinessGates`: Enable the setting of `PodReadinessGate` field for extending
Pod readiness evaluation. See [Pod readiness gate](/docs/concepts/workloads/pods/pod-lifecycle/#pod-readiness-gate)
Pod readiness evaluation. See [Pod readiness gate](/docs/concepts/workloads/pods/pod-lifecycle/#pod-readiness-gate)
for more details.
- `PodSecurity`: Enables the `PodSecurity` admission plugin.
- `PodShareProcessNamespace`: Enable the setting of `shareProcessNamespace` in a Pod for sharing
@@ -964,25 +993,27 @@ Each feature gate is designed for enabling/disabling a specific feature:
the cluster.
- `ProbeTerminationGracePeriod`: Enable [setting probe-level
`terminationGracePeriodSeconds`](/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#probe-level-terminationgraceperiodseconds)
on pods. See the [enhancement proposal](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2238-liveness-probe-grace-period) for more details.
on pods. See the [enhancement proposal](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2238-liveness-probe-grace-period)
for more details.
- `ProcMountType`: Enables control over the type proc mounts for containers
by setting the `procMount` field of a SecurityContext.
- `ProxyTerminatingEndpoints`: Enable the kube-proxy to handle terminating
endpoints when `ExternalTrafficPolicy=Local`.
- `PVCProtection`: Enable the prevention of a PersistentVolumeClaim (PVC) from
being deleted when it is still used by any Pod.
- `QOSReserved`: Allows resource reservations at the QoS level preventing pods
at lower QoS levels from bursting into resources requested at higher QoS levels
(memory only for now).
- `ReadWriteOncePod`: Enables the usage of `ReadWriteOncePod` PersistentVolume
access mode.
- `RecoverVolumeExpansionFailure`: Enables users to edit their PVCs to smaller sizes so as they can recover from previously issued
volume expansion failures. See
[Recovering from Failure when Expanding Volumes](/docs/concepts/storage/persistent-volumes/#recovering-from-failure-when-expanding-volumes)
- `RecoverVolumeExpansionFailure`: Enables users to edit their PVCs to smaller
sizes so as they can recover from previously issued volume expansion failures.
See [Recovering from Failure when Expanding Volumes](/docs/concepts/storage/persistent-volumes/#recovering-from-failure-when-expanding-volumes)
for more details.
- `RemainingItemCount`: Allow the API servers to show a count of remaining
items in the response to a
[chunking list request](/docs/reference/using-api/api-concepts/#retrieving-large-results-sets-in-chunks).
- `RemoveSelfLink`: Deprecates and removes `selfLink` from ObjectMeta and
ListMeta.
- `RemoveSelfLink`: Deprecates and removes `selfLink` from ObjectMeta and ListMeta.
- `RequestManagement`: Enables managing request concurrency with prioritization and fairness
at each API server. Deprecated by `APIPriorityAndFairness` since 1.17.
- `ResourceLimitsPriorityFunction`: Enable a scheduler priority function that
@@ -997,7 +1028,8 @@ Each feature gate is designed for enabling/disabling a specific feature:
[Bound Service Account Tokens](https://github.com/kubernetes/enhancements/blob/master/keps/sig-auth/1205-bound-service-account-tokens/README.md)
for more details.
- `RotateKubeletClientCertificate`: Enable the rotation of the client TLS certificate on the kubelet.
See [kubelet configuration](/docs/reference/command-line-tools-reference/kubelet-tls-bootstrapping/#kubelet-configuration) for more details.
See [kubelet configuration](/docs/reference/command-line-tools-reference/kubelet-tls-bootstrapping/#kubelet-configuration)
for more details.
- `RotateKubeletServerCertificate`: Enable the rotation of the server TLS certificate on the kubelet.
See [kubelet configuration](/docs/reference/command-line-tools-reference/kubelet-tls-bootstrapping/#kubelet-configuration)
for more details.
@@ -1009,12 +1041,16 @@ Each feature gate is designed for enabling/disabling a specific feature:
instead of the DaemonSet controller.
- `SCTPSupport`: Enables the _SCTP_ `protocol` value in Pod, Service,
Endpoints, EndpointSlice, and NetworkPolicy definitions.
- `SeccompDefault`: Enables the use of `RuntimeDefault` as the default seccomp profile for all workloads.
- `SeccompDefault`: Enables the use of `RuntimeDefault` as the default seccomp profile
for all workloads.
The seccomp profile is specified in the `securityContext` of a Pod and/or a Container.
- `SelectorIndex`: Allows label and field based indexes in API server watch
cache to accelerate list operations.
- `ServerSideApply`: Enables the [Sever Side Apply (SSA)](/docs/reference/using-api/server-side-apply/)
feature on the API Server.
- `ServerSideFieldValidation`: Enables server-side field validation. This means the validation
of resource schema is performed at the API server side rather than the client side
(for example, the `kubectl create` or `kubectl apply` command line).
- `ServiceAccountIssuerDiscovery`: Enable OIDC discovery endpoints (issuer and
JWKS URLs) for the service account issuer in the API server. See
[Configure Service Accounts for Pods](/docs/tasks/configure-pod-container/configure-service-account/#service-account-issuer-discovery)
@@ -1023,7 +1059,8 @@ Each feature gate is designed for enabling/disabling a specific feature:
- `ServiceInternalTrafficPolicy`: Enables the `internalTrafficPolicy` field on Services
- `ServiceLBNodePortControl`: Enables the `allocateLoadBalancerNodePorts` field on Services.
- `ServiceLoadBalancerClass`: Enables the `loadBalancerClass` field on Services. See
[Specifying class of load balancer implementation](/docs/concepts/services-networking/service/#load-balancer-class) for more details.
[Specifying class of load balancer implementation](/docs/concepts/services-networking/service/#load-balancer-class)
for more details.
- `ServiceLoadBalancerFinalizer`: Enable finalizer protection for Service load balancers.
- `ServiceNodeExclusion`: Enable the exclusion of nodes from load balancers
created by a cloud provider. A node is eligible for exclusion if labelled with
@@ -126,7 +126,6 @@ of provisioning.
2. [Token authentication file](#token-authentication-file)
Bootstrap tokens are a simpler and more easily managed method to authenticate kubelets, and do not require any additional flags when starting kube-apiserver.
Using bootstrap tokens is currently __beta__ as of Kubernetes version 1.12.
Whichever method you choose, the requirement is that the kubelet be able to authenticate as a user with the rights to:
@@ -19,4 +19,9 @@ You can request eviction either by directly calling the Eviction API
using a client of the kube-apiserver, like the `kubectl drain` command.
When an `Eviction` object is created, the API server terminates the Pod.
API-initiated evictions respect your configured [`PodDisruptionBudgets`](/docs/tasks/run-application/configure-pdb/)
and [`terminationGracePeriodSeconds`](/docs/concepts/workloads/pods/pod-lifecycle#pod-termination).
API-initiated eviction is not the same as [node-pressure eviction](/docs/concepts/scheduling-eviction/eviction/#kubelet-eviction).
* See [API-initiated eviction](/docs/concepts/scheduling-eviction/api-eviction/) for more information.
@@ -4,7 +4,7 @@ id: cadvisor
date: 2021-12-09
full_link: https://github.com/google/cadvisor/
short_description: >
Tool that provides understanding of the resource usage and perfomance characteristics for containers
Tool that provides understanding of the resource usage and performance characteristics for containers
aka:
tags:
- tool
@@ -0,0 +1,18 @@
---
title: Dockershim
id: dockershim
date: 2022-04-15
full_link: /dockershim
short_description: >
A component of Kubernetes v1.23 and earlier, which allows Kubernetes system components to communicate with Docker Engine.
aka:
tags:
- fundamental
---
The dockershim is a component of Kubernetes version 1.23 and earlier. It allows the kubelet
to communicate with {{< glossary_tooltip text="Docker Engine" term_id="docker" >}}.
<!--more-->
Starting with version 1.24, dockershim has been removed from Kubernetes. For more information, see [Dockershim FAQ](/dockershim).
+1 -1
View File
@@ -21,5 +21,5 @@ or the continued existence of events with that reason.
Events should be treated as informative, best-effort, supplemental data.
In Kubernetes, [auditing](/docs/tasks/debug-application-cluster/audit/) generates a different kind of
In Kubernetes, [auditing](/docs/tasks/debug/debug-cluster/audit/) generates a different kind of
Event record (API group `audit.k8s.io`).
@@ -2,7 +2,7 @@
title: Pod Security Policy
id: pod-security-policy
date: 2018-04-12
full_link: /docs/concepts/policy/pod-security-policy/
full_link: /docs/concepts/security/pod-security-policy/
short_description: >
Enables fine-grained authorization of pod creation and updates.
@@ -17,3 +17,4 @@ tags:
A cluster-level resource that controls security sensitive aspects of the Pod specification. The `PodSecurityPolicy` objects define a set of conditions that a Pod must run with in order to be accepted into the system, as well as defaults for the related fields. Pod Security Policy control is implemented as an optional admission controller.
PodSecurityPolicy is deprecated as of Kubernetes v1.21, and will be removed in v1.25. We recommend migrating to [Pod Security Admission](/docs/concepts/security/pod-security-admission/), or a 3rd party admission plugin.
@@ -1,5 +1,5 @@
---
title: shuffle sharding
title: Shuffle-sharding
id: shuffle-sharding
date: 2020-03-04
full_link:
@@ -18,28 +18,28 @@ We are often concerned with insulating different flows of requests
from each other, so that a high-intensity flow does not crowd out low-intensity flows.
A simple way to put requests into queues is to hash some
characteristics of the request, modulo the number of queues, to get
the index of the queue to use. The hash function uses as input
characteristics of the request that align with flows. For example, in
the index of the queue to use. The hash function uses as input
characteristics of the request that align with flows. For example, in
the Internet this is often the 5-tuple of source and destination
address, protocol, and source and destination port.
That simple hash-based scheme has the property that any high-intensity flow
will crowd out all the low-intensity flows that hash to the same queue.
Providing good insulation for a large number of flows requires a large
number of queues, which is problematic. Shuffle sharding is a more
number of queues, which is problematic. Shuffle-sharding is a more
nimble technique that can do a better job of insulating the low-intensity
flows from the high-intensity flows. The terminology of shuffle sharding uses
flows from the high-intensity flows. The terminology of shuffle-sharding uses
the metaphor of dealing a hand from a deck of cards; each queue is a
metaphorical card. The shuffle sharding technique starts with hashing
metaphorical card. The shuffle-sharding technique starts with hashing
the flow-identifying characteristics of the request, to produce a hash
value with dozens or more of bits. Then the hash value is used as a
value with dozens or more of bits. Then the hash value is used as a
source of entropy to shuffle the deck and deal a hand of cards
(queues). All the dealt queues are examined, and the request is put
into one of the examined queues with the shortest length. With a
(queues). All the dealt queues are examined, and the request is put
into one of the examined queues with the shortest length. With a
modest hand size, it does not cost much to examine all the dealt cards
and a given low-intensity flow has a good chance to dodge the effects of a
given high-intensity flow. With a large hand size it is expensive to examine
given high-intensity flow. With a large hand size it is expensive to examine
the dealt queues and more difficult for the low-intensity flows to dodge the
collective effects of a set of high-intensity flows. Thus, the hand size
collective effects of a set of high-intensity flows. Thus, the hand size
should be chosen judiciously.
@@ -39,6 +39,11 @@ complete -F __start_kubectl k
source <(kubectl completion zsh) # setup autocomplete in zsh into the current shell
echo "[[ $commands[kubectl] ]] && source <(kubectl completion zsh)" >> ~/.zshrc # add autocomplete permanently to your zsh shell
```
### A Note on --all-namespaces
Appending `--all-namespaces` happens frequently enough where you should be aware of the shorthand for `--all-namespaces`:
```kubectl -A```
## Kubectl context and configuration
@@ -97,10 +102,10 @@ kubectl apply -f https://git.io/vPieo # create resource(s) from url
kubectl create deployment nginx --image=nginx # start a single instance of nginx
# create a Job which prints "Hello World"
kubectl create job hello --image=busybox -- echo "Hello World"
kubectl create job hello --image=busybox:1.28 -- echo "Hello World"
# create a CronJob that prints "Hello World" every minute
kubectl create cronjob hello --image=busybox --schedule="*/1 * * * *" -- echo "Hello World"
kubectl create cronjob hello --image=busybox:1.28 --schedule="*/1 * * * *" -- echo "Hello World"
kubectl explain pods # get the documentation for pod manifests
@@ -113,7 +118,7 @@ metadata:
spec:
containers:
- name: busybox
image: busybox
image: busybox:1.28
args:
- sleep
- "1000000"
@@ -125,7 +130,7 @@ metadata:
spec:
containers:
- name: busybox
image: busybox
image: busybox:1.28
args:
- sleep
- "1000"
@@ -315,7 +320,7 @@ kubectl logs my-pod -c my-container --previous # dump pod container logs (s
kubectl logs -f my-pod # stream pod logs (stdout)
kubectl logs -f my-pod -c my-container # stream pod container logs (stdout, multi-container case)
kubectl logs -f -l name=myLabel --all-containers # stream all pods logs with label name=myLabel (stdout)
kubectl run -i --tty busybox --image=busybox -- sh # Run pod as interactive shell
kubectl run -i --tty busybox --image=busybox:1.28 -- sh # Run pod as interactive shell
kubectl run nginx --image=nginx -n mynamespace # Start a single instance of nginx pod in the namespace of mynamespace
kubectl run nginx --image=nginx # Run pod nginx and write its spec into a file called pod.yaml
--dry-run=client -o yaml > pod.yaml
@@ -187,7 +187,7 @@ kubectl exec -ti nginx-app-5jyvm -- /bin/sh
# exit
```
For more information, see [Get a Shell to a Running Container](/docs/tasks/debug-application-cluster/get-shell-running-container/).
For more information, see [Get a Shell to a Running Container](/docs/tasks/debug/debug-application/get-shell-running-container/).
## docker logs
@@ -109,14 +109,16 @@ IngressSpec describes the Ingress the user wishes to exist.
- **rules.http.paths.pathType** (string), required
PathType determines the interpretation of the Path matching. PathType can be one of the following values: * Exact: Matches the URL path exactly. * Prefix: Matches based on a URL path prefix split by '/'. Matching is
PathType determines the interpretation of the Path matching. PathType can be one of the following enum values:
- `"Exact"` Matches the URL path exactly.
- `"Prefix"` Matches based on a URL path prefix split by '/'. Matching is
done on a path element by element basis. A path element refers is the
list of labels in the path split by the '/' separator. A request is a
match for path p if every p is an element-wise prefix of p of the
request path. Note that if the last element of the path is a substring
of the last element in request path, it is not a match (e.g. /foo/bar
matches /foo/bar/baz, but does not match /foo/barbaz).
* ImplementationSpecific: Interpretation of the Path matching is up to
- `"ImplementationSpecific"` Interpretation of the Path matching is up to
the IngressClass. Implementations can treat this as a separate PathType
or treat it identically to Prefix or Exact path types.
Implementations are required to support all path types.

Some files were not shown because too many files have changed in this diff Show More