Compare commits
229 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 628b9d2115 | |||
| d1751c8101 | |||
| 318ae0b7fe | |||
| 5f1bdf56b9 | |||
| d38d6a4631 | |||
| 0d17ba6f58 | |||
| 8da84d2c2e | |||
| b7403d2140 | |||
| dc2ffc1833 | |||
| 05de8ac4d0 | |||
| 6d252624b2 | |||
| d1c650d2a6 | |||
| 835499b156 | |||
| dcd7fb8cb9 | |||
| da022325b9 | |||
| 460f44bdf8 | |||
| a149f9c2d2 | |||
| 9f7f648e1b | |||
| e6e597b2c4 | |||
| d9d4a7cdf8 | |||
| fc545595f7 | |||
| 5391a59dc4 | |||
| f6fef933b7 | |||
| 44b902cdf9 | |||
| 2e519b024b | |||
| 863d0bc3ba | |||
| 41f8e9da78 | |||
| ca6008c67f | |||
| c48c5fd3c0 | |||
| b890226ee2 | |||
| 3b1b77b837 | |||
| 7841e9e509 | |||
| 17b5158f24 | |||
| 924f4a317c | |||
| 8441afaac1 | |||
| fb976d5844 | |||
| 8b2ecd55ec | |||
| c6194a2473 | |||
| 6c4e752016 | |||
| e0b7222f1a | |||
| ce94ae337b | |||
| 5f4e60db56 | |||
| fe9e5a80ad | |||
| 2325d540bf | |||
| 7f2b282dbe | |||
| 4556399e99 | |||
| 973caa38b1 | |||
| ba51164bfc | |||
| be40912057 | |||
| 411f732ae3 | |||
| 25d8a13220 | |||
| b20641723c | |||
| 4e15cffdf9 | |||
| 5767f39fd1 | |||
| 9717c5bb3b | |||
| 34f1d61c60 | |||
| 6864166901 | |||
| ae317a06fb | |||
| c45c5746b2 | |||
| a806f40897 | |||
| 8b45d0f687 | |||
| 4d20ce5b29 | |||
| 94e021ccf6 | |||
| b28250b68f | |||
| 065cbfb9d0 | |||
| d439f4dd17 | |||
| 7101158992 | |||
| 029d2f6ed8 | |||
| 871e2ad8d6 | |||
| 89277ad575 | |||
| cf780b6545 | |||
| 2047c9bd7f | |||
| fb5f0b7a93 | |||
| ce76e0f875 | |||
| 79845b0c4a | |||
| c8d20ea228 | |||
| e172a7e264 | |||
| b59a32dfbc | |||
| 8eefd68e4f | |||
| 1a6dcc8639 | |||
| 9c0ea12189 | |||
| c71ba4c54c | |||
| 38a9e33a2e | |||
| 714fed8d7f | |||
| 816725246d | |||
| 0db87652fb | |||
| ec6d03d84d | |||
| c43c40e1b0 | |||
| 692e997105 | |||
| a8035792af | |||
| d1556f7dfd | |||
| 19b961a89d | |||
| a66fec504e | |||
| d4597c7c24 | |||
| d5b1793351 | |||
| 936e2c60ce | |||
| 5f3e13e820 | |||
| 0d7d7470dd | |||
| 0da4bfb533 | |||
| c72828aadf | |||
| 5fac89acb0 | |||
| 971412c3fd | |||
| 8b8650eff1 | |||
| 96ab2b0dac | |||
| e77f730256 | |||
| 10fa5744bf | |||
| ba4914fdb2 | |||
| ae1650b2db | |||
| 2885caa95c | |||
| 5467cf82a0 | |||
| fe2f1e2da6 | |||
| f219e4e61a | |||
| 6bff481ebc | |||
| 39c82936d9 | |||
| f98a672883 | |||
| eba27a0e2a | |||
| 293745deed | |||
| edd2882e3d | |||
| bf97c371b2 | |||
| e6e3f00a44 | |||
| 33a84d66df | |||
| f3e31e4ce9 | |||
| 8e65b8abb1 | |||
| d39d4b4bf7 | |||
| b6d0d51111 | |||
| 8995eaa248 | |||
| cbff017b69 | |||
| 15f1a9ca1c | |||
| 68032faacc | |||
| 557a69e959 | |||
| 61fc601333 | |||
| c4f5dc94e4 | |||
| 1cf3ed6403 | |||
| 66206ab141 | |||
| 7f66bfd059 | |||
| f6a5a55a55 | |||
| 377bc93ae8 | |||
| 3ccdb3426a | |||
| 3252fb1d9e | |||
| 29d6c1135d | |||
| 66617a0633 | |||
| 89a2aec131 | |||
| 1dbdda9d34 | |||
| ed7c4e7046 | |||
| 5c589626fd | |||
| d830ee0f5b | |||
| ecede1568a | |||
| 1b1382bd12 | |||
| 8dbb259bac | |||
| c5851cf9c9 | |||
| ab8b27fd6e | |||
| 7ac667b3bb | |||
| 753ec3f745 | |||
| ba04c71760 | |||
| bd63179912 | |||
| b8d7f9f72d | |||
| 469109c1e3 | |||
| 27d37b9b5f | |||
| e08c5a5333 | |||
| 23173257c5 | |||
| 54baa8a639 | |||
| edf03d8277 | |||
| 579aa6d0a4 | |||
| 0721959e1f | |||
| 0a17590014 | |||
| c38481d348 | |||
| cf962dedad | |||
| 08e6a4bd12 | |||
| 229a65e46f | |||
| 72b37b1c6a | |||
| f5150715cc | |||
| da8012d684 | |||
| 248606110f | |||
| d2df5edeff | |||
| aeca0c62bc | |||
| ab0eec79d2 | |||
| 279bf48616 | |||
| bf966609d6 | |||
| c2ab7156ef | |||
| 2d568916a9 | |||
| 61c6f2f5dd | |||
| 90d598cf1f | |||
| 10d741d22b | |||
| f7dc13e923 | |||
| 07d6f33b61 | |||
| 9d6649755d | |||
| 2d31364e3c | |||
| 2c530c295a | |||
| fa5ef755a2 | |||
| 51aa022352 | |||
| 79577607c8 | |||
| a6333facb4 | |||
| 2df104f939 | |||
| e9783b0cb4 | |||
| 3db583a9cd | |||
| 55205a5c1f | |||
| e6aa137ac2 | |||
| 487bd4fa46 | |||
| 10be302dce | |||
| a6f829f29a | |||
| eb9ea62041 | |||
| 1abf84e7cd | |||
| 8d7396eb14 | |||
| f2657734f8 | |||
| f755079d15 | |||
| ca2219f567 | |||
| 918ac7ecae | |||
| 64c16a5836 | |||
| 7be3cdcc91 | |||
| a9918c4af3 | |||
| c5e0cc66d8 | |||
| 5ae7283deb | |||
| 5805ef3738 | |||
| 34f1f44e47 | |||
| 74ce07a55e | |||
| 607e086ffd | |||
| eb4b67d8a2 | |||
| b891ef312a | |||
| 004df073c4 | |||
| 40950997be | |||
| 1ea5f5ee31 | |||
| 22f104c6c3 | |||
| 466b4bd806 | |||
| dd2153d2db | |||
| c009ad8431 | |||
| 7a5da05b95 | |||
| 6c60620ad4 | |||
| 79113f3f68 | |||
| dbcd6627cb |
@@ -869,3 +869,22 @@ body.td-documentation {
|
||||
display: none;
|
||||
}
|
||||
}
|
||||
|
||||
// nav-tabs and tab-content
|
||||
.nav-tabs {
|
||||
border-bottom: none !important;
|
||||
}
|
||||
|
||||
.td-content .tab-content .highlight {
|
||||
margin: 0;
|
||||
}
|
||||
|
||||
.tab-pane {
|
||||
border-radius: 0.25rem;
|
||||
padding: 0 16px 16px;
|
||||
|
||||
border: 1px solid #dee2e6;
|
||||
&:first-of-type.active {
|
||||
border-top-left-radius: 0;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -639,3 +639,10 @@ body.td-documentation {
|
||||
}
|
||||
}
|
||||
|
||||
.td-content {
|
||||
table code {
|
||||
background-color: inherit !important;
|
||||
color: inherit !important;
|
||||
font-size: inherit !important;
|
||||
}
|
||||
}
|
||||
|
||||
+21
-21
@@ -138,13 +138,13 @@ time_format_default = "January 02, 2006 at 3:04 PM PST"
|
||||
description = "Production-Grade Container Orchestration"
|
||||
showedit = true
|
||||
|
||||
latest = "v1.20"
|
||||
latest = "v1.21"
|
||||
|
||||
fullversion = "v1.20.0"
|
||||
fullversion = "v1.20.5"
|
||||
version = "v1.20"
|
||||
githubbranch = "master"
|
||||
docsbranch = "master"
|
||||
deprecated = false
|
||||
githubbranch = "v1.20.5"
|
||||
docsbranch = "release-1.20"
|
||||
deprecated = true
|
||||
currentUrl = "https://kubernetes.io/docs/home/"
|
||||
nextUrl = "https://kubernetes-io-vnext-staging.netlify.com/"
|
||||
|
||||
@@ -178,40 +178,40 @@ js = [
|
||||
]
|
||||
|
||||
[[params.versions]]
|
||||
fullversion = "v1.20.0"
|
||||
version = "v1.20"
|
||||
githubbranch = "v1.20.0"
|
||||
fullversion = "v1.21.0"
|
||||
version = "v1.21"
|
||||
githubbranch = "v1.21.0"
|
||||
docsbranch = "master"
|
||||
url = "https://kubernetes.io"
|
||||
|
||||
[[params.versions]]
|
||||
fullversion = "v1.19.4"
|
||||
fullversion = "v1.20.5"
|
||||
version = "v1.20"
|
||||
githubbranch = "v1.20.5"
|
||||
docsbranch = "release-1.20"
|
||||
url = "https://v1-20.docs.kubernetes.io"
|
||||
|
||||
[[params.versions]]
|
||||
fullversion = "v1.19.9"
|
||||
version = "v1.19"
|
||||
githubbranch = "v1.19.4"
|
||||
githubbranch = "v1.19.9"
|
||||
docsbranch = "release-1.19"
|
||||
url = "https://v1-19.docs.kubernetes.io"
|
||||
|
||||
[[params.versions]]
|
||||
fullversion = "v1.18.12"
|
||||
fullversion = "v1.18.17"
|
||||
version = "v1.18"
|
||||
githubbranch = "v1.18.12"
|
||||
githubbranch = "v1.18.17"
|
||||
docsbranch = "release-1.18"
|
||||
url = "https://v1-18.docs.kubernetes.io"
|
||||
|
||||
[[params.versions]]
|
||||
fullversion = "v1.17.14"
|
||||
fullversion = "v1.17.17"
|
||||
version = "v1.17"
|
||||
githubbranch = "v1.17.14"
|
||||
githubbranch = "v1.17.17"
|
||||
docsbranch = "release-1.17"
|
||||
url = "https://v1-17.docs.kubernetes.io"
|
||||
|
||||
[[params.versions]]
|
||||
fullversion = "v1.16.15"
|
||||
version = "v1.16"
|
||||
githubbranch = "v1.16.15"
|
||||
docsbranch = "release-1.16"
|
||||
url = "https://v1-16.docs.kubernetes.io"
|
||||
|
||||
|
||||
# User interface configuration
|
||||
[params.ui]
|
||||
|
||||
@@ -9,7 +9,7 @@ content_type: concept
|
||||
|
||||
Diese Sektion umfasst verschiedene Optionen zum Einrichten und Betrieb von Kubernetes.
|
||||
|
||||
Verschiedene Kubernetes Lösungen haben verschiedene Anforderungen: Einfache Wartung, Sicherheit, Kontrolle, verfügbare Resourcen und erforderliches Fachwissen zum Betrieb und zur Verwaltung dess folgende Diagramm zeigt die möglichen Abstraktionen eines Kubernetes-Clusters und ob eine Abstraktion selbst verwaltet oder von einem Anbieter verwaltet wird.
|
||||
Verschiedene Kubernetes Lösungen haben verschiedene Anforderungen: Einfache Wartung, Sicherheit, Kontrolle, verfügbare Resourcen und erforderliches Fachwissen zum Betrieb und zur Verwaltung. Das folgende Diagramm zeigt die möglichen Abstraktionen eines Kubernetes-Clusters und ob eine Abstraktion selbst verwaltet oder von einem Anbieter verwaltet wird.
|
||||
|
||||
Sie können einen Kubernetes-Cluster auf einer lokalen Maschine, Cloud, On-Prem Datacenter bereitstellen; oder wählen Sie einen verwalteten Kubernetes-Cluster. Sie können auch eine individuelle Lösung über eine grosse Auswahl an Cloud Anbietern oder Bare-Metal-Umgebungen nutzen.
|
||||
|
||||
|
||||
@@ -0,0 +1,74 @@
|
||||
---
|
||||
layout: blog
|
||||
title: "PodSecurityPolicy Deprecation: Past, Present, and Future"
|
||||
date: 2021-04-06
|
||||
slug: podsecuritypolicy-deprecation-past-present-and-future
|
||||
---
|
||||
|
||||
**Author:** Tabitha Sable (Kubernetes SIG Security)
|
||||
|
||||
PodSecurityPolicy (PSP) is being deprecated in Kubernetes 1.21, to be released later this week. This starts the countdown to its removal, but doesn’t change anything else. PodSecurityPolicy will continue to be fully functional for several more releases before being removed completely. In the meantime, we are developing a replacement for PSP that covers key use cases more easily and sustainably.
|
||||
|
||||
What are Pod Security Policies? Why did we need them? Why are they going away, and what’s next? How does this affect you? These key questions come to mind as we prepare to say goodbye to PSP, so let’s walk through them together. We’ll start with an overview of how features get removed from Kubernetes.
|
||||
|
||||
## What does deprecation mean in Kubernetes?
|
||||
|
||||
Whenever a Kubernetes feature is set to go away, our [deprecation policy](/docs/reference/using-api/deprecation-policy/) is our guide. First the feature is marked as deprecated, then after enough time has passed, it can finally be removed.
|
||||
|
||||
Kubernetes 1.21 starts the deprecation process for PodSecurityPolicy. As with all feature deprecations, PodSecurityPolicy will continue to be fully functional for several more releases. The current plan is to remove PSP from Kubernetes in the 1.25 release.
|
||||
|
||||
Until then, PSP is still PSP. There will be at least a year during which the newest Kubernetes releases will still support PSP, and nearly two years until PSP will pass fully out of all supported Kubernetes versions.
|
||||
|
||||
## What is PodSecurityPolicy?
|
||||
|
||||
[PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/) is a built-in [admission controller](/blog/2019/03/21/a-guide-to-kubernetes-admission-controllers/) that allows a cluster administrator to control security-sensitive aspects of the Pod specification.
|
||||
|
||||
First, one or more PodSecurityPolicy resources are created in a cluster to define the requirements Pods must meet. Then, RBAC rules are created to control which PodSecurityPolicy applies to a given pod. If a pod meets the requirements of its PSP, it will be admitted to the cluster as usual. In some cases, PSP can also modify Pod fields, effectively creating new defaults for those fields. If a Pod does not meet the PSP requirements, it is rejected, and cannot run.
|
||||
|
||||
One more important thing to know about PodSecurityPolicy: it’s not the same as [PodSecurityContext](/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context).
|
||||
|
||||
A part of the Pod specification, PodSecurityContext (and its per-container counterpart `SecurityContext`) is the collection of fields that specify many of the security-relevant settings for a Pod. The security context dictates to the kubelet and container runtime how the Pod should actually be run. In contrast, the PodSecurityPolicy only constrains (or defaults) the values that may be set on the security context.
|
||||
|
||||
The deprecation of PSP does not affect PodSecurityContext in any way.
|
||||
|
||||
## Why did we need PodSecurityPolicy?
|
||||
|
||||
In Kubernetes, we define resources such as Deployments, StatefulSets, and Services that represent the building blocks of software applications. The various controllers inside a Kubernetes cluster react to these resources, creating further Kubernetes resources or configuring some software or hardware to accomplish our goals.
|
||||
|
||||
In most Kubernetes clusters, RBAC (Role-Based Access Control) [rules](/docs/reference/access-authn-authz/rbac/#role-and-clusterrole) control access to these resources. `list`, `get`, `create`, `edit`, and `delete` are the sorts of API operations that RBAC cares about, but _RBAC does not consider what settings are being put into the resources it controls_. For example, a Pod can be almost anything from a simple webserver to a privileged command prompt offering full access to the underlying server node and all the data. It’s all the same to RBAC: a Pod is a Pod is a Pod.
|
||||
|
||||
To control what sorts of settings are allowed in the resources defined in your cluster, you need Admission Control in addition to RBAC. Since Kubernetes 1.3, PodSecurityPolicy has been the built-in way to do that for security-related Pod fields. Using PodSecurityPolicy, you can prevent “create Pod” from automatically meaning “root on every cluster node,” without needing to deploy additional external admission controllers.
|
||||
|
||||
## Why is PodSecurityPolicy going away?
|
||||
|
||||
In the years since PodSecurityPolicy was first introduced, we have realized that PSP has some serious usability problems that can’t be addressed without making breaking changes.
|
||||
|
||||
The way PSPs are applied to Pods has proven confusing to nearly everyone that has attempted to use them. It is easy to accidentally grant broader permissions than intended, and difficult to inspect which PSP(s) apply in a given situation. The “changing Pod defaults” feature can be handy, but is only supported for certain Pod settings and it’s not obvious when they will or will not apply to your Pod. Without a “dry run” or audit mode, it’s impractical to retrofit PSP to existing clusters safely, and it’s impossible for PSP to ever be enabled by default.
|
||||
|
||||
For more information about these and other PSP difficulties, check out SIG Auth’s KubeCon NA 2019 Maintainer Track session video: {{< youtube "SFtHRmPuhEw?start=953" youtube-quote-sm >}}
|
||||
|
||||
Today, you’re not limited only to deploying PSP or writing your own custom admission controller. Several external admission controllers are available that incorporate lessons learned from PSP to provide a better user experience. [K-Rail](https://github.com/cruise-automation/k-rail), [Kyverno](https://github.com/kyverno/kyverno/), and [OPA/Gatekeeper](https://github.com/open-policy-agent/gatekeeper/) are all well-known, and each has its fans.
|
||||
|
||||
Although there are other good options available now, we believe there is still value in having a built-in admission controller available as a choice for users. With this in mind, we turn toward building what’s next, inspired by the lessons learned from PSP.
|
||||
|
||||
## What’s next?
|
||||
|
||||
Kubernetes SIG Security, SIG Auth, and a diverse collection of other community members have been working together for months to ensure that what’s coming next is going to be awesome. We have developed a Kubernetes Enhancement Proposal ([KEP 2579](https://github.com/kubernetes/enhancements/issues/2579)) and a prototype for a new feature, currently being called by the temporary name "PSP Replacement Policy." We are targeting an Alpha release in Kubernetes 1.22.
|
||||
|
||||
PSP Replacement Policy starts with the realization that since there is a robust ecosystem of external admission controllers already available, PSP’s replacement doesn’t need to be all things to all people. Simplicity of deployment and adoption is the key advantage a built-in admission controller has compared to an external webhook, so we have focused on how to best utilize that advantage.
|
||||
|
||||
PSP Replacement Policy is designed to be as simple as practically possible while providing enough flexibility to really be useful in production at scale. It has soft rollout features to enable retrofitting it to existing clusters, and is configurable enough that it can eventually be active by default. It can be deactivated partially or entirely, to coexist with external admission controllers for advanced use cases.
|
||||
|
||||
## What does this mean for you?
|
||||
|
||||
What this all means for you depends on your current PSP situation. If you’re already using PSP, there’s plenty of time to plan your next move. Please review the PSP Replacement Policy KEP and think about how well it will suit your use case.
|
||||
|
||||
If you’re making extensive use of the flexibility of PSP with numerous PSPs and complex binding rules, you will likely find the simplicity of PSP Replacement Policy too limiting. Use the next year to evaluate the other admission controller choices in the ecosystem. There are resources available to ease this transition, such as the [Gatekeeper Policy Library](https://github.com/open-policy-agent/gatekeeper-library).
|
||||
|
||||
If your use of PSP is relatively simple, with a few policies and straightforward binding to service accounts in each namespace, you will likely find PSP Replacement Policy to be a good match for your needs. Evaluate your PSPs compared to the Kubernetes [Pod Security Standards](/docs/concepts/security/pod-security-standards/) to get a feel for where you’ll be able to use the Restricted, Baseline, and Privileged policies. Please follow along with or contribute to the KEP and subsequent development, and try out the Alpha release of PSP Replacement Policy when it becomes available.
|
||||
|
||||
If you’re just beginning your PSP journey, you will save time and effort by keeping it simple. You can approximate the functionality of PSP Replacement Policy today by using the Pod Security Standards’ PSPs. If you set the cluster default by binding a Baseline or Restricted policy to the `system:serviceaccounts` group, and then make a more-permissive policy available as needed in certain Namespaces [using ServiceAccount bindings](/docs/concepts/policy/pod-security-policy/#run-another-pod), you will avoid many of the PSP pitfalls and have an easy migration to PSP Replacement Policy. If your needs are much more complex than this, your effort is probably better spent adopting one of the more fully-featured external admission controllers mentioned above.
|
||||
|
||||
We’re dedicated to making Kubernetes the best container orchestration tool we can, and sometimes that means we need to remove longstanding features to make space for better things to come. When that happens, the Kubernetes deprecation policy ensures you have plenty of time to plan your next move. In the case of PodSecurityPolicy, several options are available to suit a range of needs and use cases. Start planning ahead now for PSP’s eventual removal, and please consider contributing to its replacement! Happy securing!
|
||||
|
||||
**Acknowledgment:** It takes a wonderful group to make wonderful software. Thanks are due to everyone who has contributed to the PSP replacement effort, especially (in alphabetical order) Tim Allclair, Ian Coldwater, and Jordan Liggitt. It’s been a joy to work with y’all on this.
|
||||
@@ -67,6 +67,16 @@ delete the Node object to stop that health checking.
|
||||
The name of a Node object must be a valid
|
||||
[DNS subdomain name](/docs/concepts/overview/working-with-objects/names#dns-subdomain-names).
|
||||
|
||||
### Node name uniqueness
|
||||
|
||||
The [name](/docs/concepts/overview/working-with-objects/names#names) identifies a Node. Two Nodes
|
||||
cannot have the same name at the same time. Kubernetes also assumes that a resource with the same
|
||||
name is the same object. In case of a Node, it is implicitly assumed that an instance using the
|
||||
same name will have the same state (e.g. network settings, root disk contents). This may lead to
|
||||
inconsistencies if an instance was modified without changing its name. If the Node needs to be
|
||||
replaced or updated significantly, the existing Node object needs to be removed from API server
|
||||
first and re-added after the update.
|
||||
|
||||
### Self-registration of Nodes
|
||||
|
||||
When the kubelet flag `--register-node` is true (the default), the kubelet will attempt to
|
||||
@@ -364,4 +374,3 @@ For example, if `ShutdownGracePeriod=30s`, and `ShutdownGracePeriodCriticalPods=
|
||||
* Read the [Node](https://git.k8s.io/community/contributors/design-proposals/architecture/architecture.md#the-kubernetes-node)
|
||||
section of the architecture design document.
|
||||
* Read about [taints and tolerations](/docs/concepts/scheduling-eviction/taint-and-toleration/).
|
||||
|
||||
|
||||
@@ -16,6 +16,7 @@ This page lists some of the available add-ons and links to their respective inst
|
||||
## Networking and Network Policy
|
||||
|
||||
* [ACI](https://www.github.com/noironetworks/aci-containers) provides integrated container networking and network security with Cisco ACI.
|
||||
* [Antrea](https://antrea.io/) operates at Layer 3/4 to provide networking and security services for Kubernetes, leveraging Open vSwitch as the networking data plane.
|
||||
* [Calico](https://docs.projectcalico.org/latest/introduction/) is a networking and network policy provider. Calico supports a flexible set of networking options so you can choose the most efficient option for your situation, including non-overlay and overlay networks, with or without BGP. Calico uses the same engine to enforce network policy for hosts, pods, and (if using Istio & Envoy) applications at the service mesh layer.
|
||||
* [Canal](https://github.com/tigera/canal/tree/master/k8s-install) unites Flannel and Calico, providing networking and network policy.
|
||||
* [Cilium](https://github.com/cilium/cilium) is a L3 network and network policy plugin that can enforce HTTP/API/L7 policies transparently. Both routing and overlay/encapsulation mode are supported, and it can work on top of other CNI plugins.
|
||||
|
||||
@@ -224,7 +224,7 @@ When a ConfigMap currently consumed in a volume is updated, projected keys are e
|
||||
The kubelet checks whether the mounted ConfigMap is fresh on every periodic sync.
|
||||
However, the kubelet uses its local cache for getting the current value of the ConfigMap.
|
||||
The type of the cache is configurable using the `ConfigMapAndSecretChangeDetectionStrategy` field in
|
||||
the [KubeletConfiguration struct](https://github.com/kubernetes/kubernetes/blob/{{< param "docsbranch" >}}/staging/src/k8s.io/kubelet/config/v1beta1/types.go).
|
||||
the [KubeletConfiguration struct](/docs/reference/config-api/kubelet-config.v1beta1/)).
|
||||
A ConfigMap can be either propagated by watch (default), ttl-based, or by redirecting
|
||||
all requests directly to the API server.
|
||||
As a result, the total delay from the moment when the ConfigMap is updated to the moment
|
||||
@@ -233,6 +233,7 @@ propagation delay, where the cache propagation delay depends on the chosen cache
|
||||
(it equals to watch propagation delay, ttl of cache, or zero correspondingly).
|
||||
|
||||
ConfigMaps consumed as environment variables are not updated automatically and require a pod restart.
|
||||
|
||||
## Immutable ConfigMaps {#configmap-immutable}
|
||||
|
||||
{{< feature-state for_k8s_version="v1.19" state="beta" >}}
|
||||
|
||||
@@ -21,9 +21,6 @@ allowed to use more of that resource than the limit you set. The kubelet also re
|
||||
at least the _request_ amount of that system resource specifically for that container
|
||||
to use.
|
||||
|
||||
|
||||
|
||||
|
||||
<!-- body -->
|
||||
|
||||
## Requests and limits
|
||||
@@ -442,12 +439,15 @@ If you want to use project quotas, you should:
|
||||
|
||||
* Enable the `LocalStorageCapacityIsolationFSQuotaMonitoring=true`
|
||||
[feature gate](/docs/reference/command-line-tools-reference/feature-gates/)
|
||||
in the kubelet configuration.
|
||||
using the `featureGates` field in the
|
||||
[kubelet configuration](/docs/reference/config-api/kubelet-config.v1beta1/)
|
||||
or the `--feature-gates` command line flag.
|
||||
|
||||
* Ensure that the root filesystem (or optional runtime filesystem)
|
||||
has project quotas enabled. All XFS filesystems support project quotas.
|
||||
For ext4 filesystems, you need to enable the project quota tracking feature
|
||||
while the filesystem is not mounted.
|
||||
|
||||
```bash
|
||||
# For ext4, with /dev/block-device not mounted
|
||||
sudo tune2fs -O project -Q prjquota /dev/block-device
|
||||
@@ -518,8 +518,7 @@ Cluster-level extended resources are not tied to nodes. They are usually managed
|
||||
by scheduler extenders, which handle the resource consumption and resource quota.
|
||||
|
||||
You can specify the extended resources that are handled by scheduler extenders
|
||||
in [scheduler policy
|
||||
configuration](https://github.com/kubernetes/kubernetes/blob/release-1.10/pkg/scheduler/api/v1/types.go#L31).
|
||||
in [scheduler policy configuration](/docs/reference/config-api/kube-scheduler-policy-config.v1/)
|
||||
|
||||
**Example:**
|
||||
|
||||
@@ -742,23 +741,14 @@ LastState: map[terminated:map[exitCode:137 reason:OOM Killed startedAt:2015-07-0
|
||||
|
||||
You can see that the Container was terminated because of `reason:OOM Killed`, where `OOM` stands for Out Of Memory.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
|
||||
* Get hands-on experience [assigning Memory resources to Containers and Pods](/docs/tasks/configure-pod-container/assign-memory-resource/).
|
||||
|
||||
* Get hands-on experience [assigning CPU resources to Containers and Pods](/docs/tasks/configure-pod-container/assign-cpu-resource/).
|
||||
|
||||
* For more details about the difference between requests and limits, see
|
||||
[Resource QoS](https://git.k8s.io/community/contributors/design-proposals/node/resource-qos.md).
|
||||
|
||||
* Read the [Container](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#container-v1-core) API reference
|
||||
|
||||
* Read the [ResourceRequirements](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#resourcerequirements-v1-core) API reference
|
||||
|
||||
* Read about [project quotas](https://xfs.org/docs/xfsdocs-xml-dev/XFS_User_Guide/tmp/en-US/html/xfs-quotas.html) in XFS
|
||||
* Read more about the [kube-scheduler Policy reference (v1)](/docs/reference/config-api/kube-scheduler-policy-config.v1/)
|
||||
|
||||
|
||||
@@ -668,7 +668,7 @@ When a secret currently consumed in a volume is updated, projected keys are even
|
||||
The kubelet checks whether the mounted secret is fresh on every periodic sync.
|
||||
However, the kubelet uses its local cache for getting the current value of the Secret.
|
||||
The type of the cache is configurable using the `ConfigMapAndSecretChangeDetectionStrategy` field in
|
||||
the [KubeletConfiguration struct](https://github.com/kubernetes/kubernetes/blob/{{< param "docsbranch" >}}/staging/src/k8s.io/kubelet/config/v1beta1/types.go).
|
||||
the [KubeletConfiguration struct](/docs/reference/config-api/kubelet-config.v1beta1/).
|
||||
A Secret can be either propagated by watch (default), ttl-based, or by redirecting
|
||||
all requests directly to the API server.
|
||||
As a result, the total delay from the moment when the Secret is updated to the moment
|
||||
@@ -760,8 +760,8 @@ data has the following advantages:
|
||||
- improves performance of your cluster by significantly reducing load on kube-apiserver, by
|
||||
closing watches for secrets marked as immutable.
|
||||
|
||||
This feature is controlled by the `ImmutableEphemeralVolumes` [feature
|
||||
gate](/docs/reference/command-line-tools-reference/feature-gates/),
|
||||
This feature is controlled by the `ImmutableEphemeralVolumes`
|
||||
[feature gate](/docs/reference/command-line-tools-reference/feature-gates/),
|
||||
which is enabled by default since v1.19. You can create an immutable
|
||||
Secret by setting the `immutable` field to `true`. For example,
|
||||
```yaml
|
||||
@@ -865,6 +865,7 @@ start until all the Pod's volumes are mounted.
|
||||
### Use-Case: As container environment variables
|
||||
|
||||
Create a secret
|
||||
|
||||
```yaml
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
@@ -877,6 +878,7 @@ data:
|
||||
```
|
||||
|
||||
Create the Secret:
|
||||
|
||||
```shell
|
||||
kubectl apply -f mysecret.yaml
|
||||
```
|
||||
@@ -992,7 +994,7 @@ For example, if your actual password is `S!B\*d$zDsb=`, you should execute the c
|
||||
kubectl create secret generic dev-db-secret --from-literal=username=devuser --from-literal=password='S!B\*d$zDsb='
|
||||
```
|
||||
|
||||
You do not need to escape special characters in passwords from files (`--from-file`).
|
||||
You do not need to escape special characters in passwords from files (`--from-file`).
|
||||
{{< /note >}}
|
||||
|
||||
Now make the Pods:
|
||||
@@ -1173,14 +1175,12 @@ privileged, system-level components.
|
||||
|
||||
Applications that need to access the Secret API should perform `get` requests on
|
||||
the secrets they need. This lets administrators restrict access to all secrets
|
||||
while [white-listing access to individual instances](
|
||||
/docs/reference/access-authn-authz/rbac/#referring-to-resources) that
|
||||
while [white-listing access to individual instances](/docs/reference/access-authn-authz/rbac/#referring-to-resources) that
|
||||
the app needs.
|
||||
|
||||
For improved performance over a looping `get`, clients can design resources that
|
||||
reference a secret then `watch` the resource, re-requesting the secret when the
|
||||
reference changes. Additionally, a ["bulk watch" API](
|
||||
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/bulk_watch.md)
|
||||
reference changes. Additionally, a ["bulk watch" API](https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/bulk_watch.md)
|
||||
to let clients `watch` individual resources has also been proposed, and will likely
|
||||
be available in future releases of Kubernetes.
|
||||
|
||||
|
||||
@@ -50,10 +50,11 @@ A more detailed description of the termination behavior can be found in
|
||||
### Hook handler implementations
|
||||
|
||||
Containers can access a hook by implementing and registering a handler for that hook.
|
||||
There are two types of hook handlers that can be implemented for Containers:
|
||||
There are three types of hook handlers that can be implemented for Containers:
|
||||
|
||||
* Exec - Executes a specific command, such as `pre-stop.sh`, inside the cgroups and namespaces of the Container.
|
||||
Resources consumed by the command are counted against the Container.
|
||||
* TCP - Opens a TCP connecton against a specific port on the Container.
|
||||
* HTTP - Executes an HTTP request against a specific endpoint on the Container.
|
||||
|
||||
### Hook handler execution
|
||||
|
||||
@@ -44,7 +44,7 @@ desired state, and continually maintains this state.
|
||||
You can deploy and update a custom controller on a running cluster, independently
|
||||
of the cluster's lifecycle. Custom controllers can work with any kind of resource,
|
||||
but they are especially effective when combined with custom resources. The
|
||||
[Operator pattern](https://coreos.com/blog/introducing-operators.html) combines custom
|
||||
[Operator pattern](/docs/concepts/extend-kubernetes/operator/) combines custom
|
||||
resources and custom controllers. You can use custom controllers to encode domain knowledge
|
||||
for specific applications into an extension of the Kubernetes API.
|
||||
|
||||
|
||||
@@ -33,7 +33,8 @@ The control plane's components make global decisions about the cluster (for exam
|
||||
Control plane components can be run on any machine in the cluster. However,
|
||||
for simplicity, set up scripts typically start all control plane components on
|
||||
the same machine, and do not run user containers on this machine. See
|
||||
[Building High-Availability Clusters](/docs/admin/high-availability/) for an example multi-master-VM setup.
|
||||
[Creating Highly Available clusters with kubeadm](/docs/setup/production-environment/tools/kubeadm/high-availability/)
|
||||
for an example control plane setup that runs across multiple VMs.
|
||||
|
||||
### kube-apiserver
|
||||
|
||||
@@ -132,4 +133,3 @@ saving container logs to a central log store with search/browsing interface.
|
||||
* Learn about [Controllers](/docs/concepts/architecture/controller/)
|
||||
* Learn about [kube-scheduler](/docs/concepts/scheduling-eviction/kube-scheduler/)
|
||||
* Read etcd's official [documentation](https://etcd.io/docs/)
|
||||
|
||||
|
||||
@@ -24,6 +24,10 @@ For non-unique user-provided attributes, Kubernetes provides [labels](/docs/conc
|
||||
|
||||
{{< glossary_definition term_id="name" length="all" >}}
|
||||
|
||||
{{< note >}}
|
||||
In cases when objects represent a physical entity, like a Node representing a physical host, when the host is re-created under the same name without deleting and re-creating the Node, Kubernetes treats the new host as the old one, which may lead to inconsistencies.
|
||||
{{< /note >}}
|
||||
|
||||
Below are three types of commonly used name constraints for resources.
|
||||
|
||||
### DNS Subdomain Names
|
||||
@@ -86,4 +90,3 @@ UUIDs are standardized as ISO/IEC 9834-8 and as ITU-T X.667.
|
||||
|
||||
* Read about [labels](/docs/concepts/overview/working-with-objects/labels/) in Kubernetes.
|
||||
* See the [Identifiers and Names in Kubernetes](https://git.k8s.io/community/contributors/design-proposals/architecture/identifiers.md) design document.
|
||||
|
||||
|
||||
@@ -11,18 +11,17 @@ weight: 20
|
||||
|
||||
<!-- overview -->
|
||||
|
||||
You can constrain a {{< glossary_tooltip text="Pod" term_id="pod" >}} to only be able to run on particular
|
||||
{{< glossary_tooltip text="Node(s)" term_id="node" >}}, or to prefer to run on particular nodes.
|
||||
There are several ways to do this, and the recommended approaches all use
|
||||
[label selectors](/docs/concepts/overview/working-with-objects/labels/) to make the selection.
|
||||
You can constrain a {{< glossary_tooltip text="Pod" term_id="pod" >}} so that it can only run on particular set of
|
||||
{{< glossary_tooltip text="Node(s)" term_id="node" >}}.
|
||||
There are several ways to do this and the recommended approaches all use
|
||||
[label selectors](/docs/concepts/overview/working-with-objects/labels/) to facilitate the selection.
|
||||
Generally such constraints are unnecessary, as the scheduler will automatically do a reasonable placement
|
||||
(e.g. spread your pods across nodes, not place the pod on a node with insufficient free resources, etc.)
|
||||
but there are some circumstances where you may want more control on a node where a pod lands, for example to ensure
|
||||
(e.g. spread your pods across nodes so as not place the pod on a node with insufficient free resources, etc.)
|
||||
but there are some circumstances where you may want to control which node the pod deploys to - for example to ensure
|
||||
that a pod ends up on a machine with an SSD attached to it, or to co-locate pods from two different
|
||||
services that communicate a lot into the same availability zone.
|
||||
|
||||
|
||||
|
||||
<!-- body -->
|
||||
|
||||
## nodeSelector
|
||||
|
||||
@@ -87,6 +87,7 @@ of the scheduler:
|
||||
* Read about [scheduler performance tuning](/docs/concepts/scheduling-eviction/scheduler-perf-tuning/)
|
||||
* Read about [Pod topology spread constraints](/docs/concepts/workloads/pods/pod-topology-spread-constraints/)
|
||||
* Read the [reference documentation](/docs/reference/command-line-tools-reference/kube-scheduler/) for kube-scheduler
|
||||
* Read the [kube-scheduler config (v1beta1)](/docs/reference/config-api/kube-scheduler-config.v1beta1/) reference
|
||||
* Learn about [configuring multiple schedulers](/docs/tasks/extend-kubernetes/configure-multiple-schedulers/)
|
||||
* Learn about [topology management policies](/docs/tasks/administer-cluster/topology-manager/)
|
||||
* Learn about [Pod Overhead](/docs/concepts/scheduling-eviction/pod-overhead/)
|
||||
@@ -94,3 +95,4 @@ of the scheduler:
|
||||
* [Volume Topology Support](/docs/concepts/storage/storage-classes/#volume-binding-mode)
|
||||
* [Storage Capacity Tracking](/docs/concepts/storage/storage-capacity/)
|
||||
* [Node-specific Volume Limits](/docs/concepts/storage/storage-limits/)
|
||||
|
||||
|
||||
@@ -24,8 +24,6 @@ in a process called _Binding_.
|
||||
This page explains performance tuning optimizations that are relevant for
|
||||
large Kubernetes clusters.
|
||||
|
||||
|
||||
|
||||
<!-- body -->
|
||||
|
||||
In large clusters, you can tune the scheduler's behaviour balancing
|
||||
@@ -44,8 +42,10 @@ should use its compiled-in default.
|
||||
If you set `percentageOfNodesToScore` above 100, kube-scheduler acts as if you
|
||||
had set a value of 100.
|
||||
|
||||
To change the value, edit the kube-scheduler configuration file (this is likely
|
||||
to be `/etc/kubernetes/config/kube-scheduler.yaml`), then restart the scheduler.
|
||||
To change the value, edit the
|
||||
[kube-scheduler configuration file](/docs/reference/config-api/kube-scheduler-config.v1beta1/)
|
||||
and then restart the scheduler.
|
||||
In many cases, the configuration file can be found at `/etc/kubernetes/config/kube-scheduler.yaml`.
|
||||
|
||||
After you have made this change, you can run
|
||||
|
||||
@@ -99,7 +99,6 @@ algorithmSource:
|
||||
percentageOfNodesToScore: 50
|
||||
```
|
||||
|
||||
|
||||
## Tuning percentageOfNodesToScore
|
||||
|
||||
`percentageOfNodesToScore` must be a value between 1 and 100 with the default
|
||||
@@ -160,4 +159,7 @@ Node 1, Node 5, Node 2, Node 6, Node 3, Node 4
|
||||
|
||||
After going over all the Nodes, it goes back to Node 1.
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
* Check the [kube-scheduler configuration reference (v1beta1)](/docs/reference/config-api/kube-scheduler-config.v1beta1/)
|
||||
|
||||
|
||||
@@ -513,8 +513,13 @@ allocates a port from a range specified by `--service-node-port-range` flag (def
|
||||
Each node proxies that port (the same port number on every Node) into your Service.
|
||||
Your Service reports the allocated port in its `.spec.ports[*].nodePort` field.
|
||||
|
||||
If you want to specify particular IP(s) to proxy the port, you can set the `--nodeport-addresses` flag in kube-proxy to particular IP block(s); this is supported since Kubernetes v1.10.
|
||||
This flag takes a comma-delimited list of IP blocks (e.g. 10.0.0.0/8, 192.0.2.0/25) to specify IP address ranges that kube-proxy should consider as local to this node.
|
||||
If you want to specify particular IP(s) to proxy the port, you can set the
|
||||
`--nodeport-addresses` flag for kube-proxy or the equivalent `nodePortAddresses`
|
||||
field of the
|
||||
[kube-proxy configuration file](/docs/reference/config-api/kube-proxy-config.v1alpha1/)
|
||||
to particular IP block(s).
|
||||
|
||||
This flag takes a comma-delimited list of IP blocks (e.g. `10.0.0.0/8`, `192.0.2.0/25`) to specify IP address ranges that kube-proxy should consider as local to this node.
|
||||
|
||||
For example, if you start kube-proxy with the `--nodeport-addresses=127.0.0.0/8` flag, kube-proxy only selects the loopback interface for NodePort Services. The default for `--nodeport-addresses` is an empty list. This means that kube-proxy should consider all available network interfaces for NodePort. (That's also compatible with earlier Kubernetes releases).
|
||||
|
||||
@@ -530,7 +535,9 @@ to configure environments that are not fully supported by Kubernetes, or even
|
||||
to expose one or more nodes' IPs directly.
|
||||
|
||||
Note that this Service is visible as `<NodeIP>:spec.ports[*].nodePort`
|
||||
and `.spec.clusterIP:spec.ports[*].port`. (If the `--nodeport-addresses` flag in kube-proxy is set, <NodeIP> would be filtered NodeIP(s).)
|
||||
and `.spec.clusterIP:spec.ports[*].port`.
|
||||
If the `--nodeport-addresses` flag for kube-proxy or the equivalent field
|
||||
in the kube-proxy configuration file is set, `<NodeIP>` would be filtered node IP(s).
|
||||
|
||||
For example:
|
||||
|
||||
|
||||
@@ -932,7 +932,7 @@ GitHub project has [instructions](https://github.com/quobyte/quobyte-csi#quobyte
|
||||
### rbd
|
||||
|
||||
An `rbd` volume allows a
|
||||
[Rados Block Device](https://ceph.com/docs/master/rbd/rbd/) (RBD) volume to mount into your
|
||||
[Rados Block Device](https://docs.ceph.com/en/latest/rbd/) (RBD) volume to mount into your
|
||||
Pod. Unlike `emptyDir`, which is erased when a pod is removed, the contents of
|
||||
an `rbd` volume are preserved and the volume is unmounted. This
|
||||
means that a RBD volume can be pre-populated with data, and that data can
|
||||
|
||||
@@ -54,7 +54,9 @@ Run the example job by downloading the example file and then running this comman
|
||||
```shell
|
||||
kubectl apply -f https://k8s.io/examples/controllers/replication.yaml
|
||||
```
|
||||
|
||||
The output is similar to this:
|
||||
|
||||
```
|
||||
replicationcontroller/nginx created
|
||||
```
|
||||
@@ -64,7 +66,9 @@ Check on the status of the ReplicationController using this command:
|
||||
```shell
|
||||
kubectl describe replicationcontrollers/nginx
|
||||
```
|
||||
|
||||
The output is similar to this:
|
||||
|
||||
```
|
||||
Name: nginx
|
||||
Namespace: default
|
||||
@@ -103,7 +107,9 @@ To list all the pods that belong to the ReplicationController in a machine reada
|
||||
pods=$(kubectl get pods --selector=app=nginx --output=jsonpath={.items..metadata.name})
|
||||
echo $pods
|
||||
```
|
||||
|
||||
The output is similar to this:
|
||||
|
||||
```
|
||||
nginx-3ntk0 nginx-4ok8v nginx-qrm3m
|
||||
```
|
||||
@@ -117,7 +123,7 @@ specifies an expression with the name from each pod in the returned list.
|
||||
As with all other Kubernetes config, a ReplicationController needs `apiVersion`, `kind`, and `metadata` fields.
|
||||
The name of a ReplicationController object must be a valid
|
||||
[DNS subdomain name](/docs/concepts/overview/working-with-objects/names#dns-subdomain-names).
|
||||
For general information about working with config files, see [object management ](/docs/concepts/overview/working-with-objects/object-management/).
|
||||
For general information about working with configuration files, see [object management](/docs/concepts/overview/working-with-objects/object-management/).
|
||||
|
||||
A ReplicationController also needs a [`.spec` section](https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status).
|
||||
|
||||
@@ -139,7 +145,7 @@ for example the [Kubelet](/docs/reference/command-line-tools-reference/kubelet/)
|
||||
|
||||
The ReplicationController can itself have labels (`.metadata.labels`). Typically, you
|
||||
would set these the same as the `.spec.template.metadata.labels`; if `.metadata.labels` is not specified
|
||||
then it defaults to `.spec.template.metadata.labels`. However, they are allowed to be
|
||||
then it defaults to `.spec.template.metadata.labels`. However, they are allowed to be
|
||||
different, and the `.metadata.labels` do not affect the behavior of the ReplicationController.
|
||||
|
||||
### Pod Selector
|
||||
@@ -197,7 +203,7 @@ To update pods to a new spec in a controlled way, use a [rolling update](#rollin
|
||||
|
||||
### Isolating pods from a ReplicationController
|
||||
|
||||
Pods may be removed from a ReplicationController's target set by changing their labels. This technique may be used to remove pods from service for debugging, data recovery, etc. Pods that are removed in this way will be replaced automatically (assuming that the number of replicas is not also changed).
|
||||
Pods may be removed from a ReplicationController's target set by changing their labels. This technique may be used to remove pods from service for debugging and data recovery. Pods that are removed in this way will be replaced automatically (assuming that the number of replicas is not also changed).
|
||||
|
||||
## Common usage patterns
|
||||
|
||||
@@ -207,8 +213,7 @@ As mentioned above, whether you have 1 pod you want to keep running, or 1000, a
|
||||
|
||||
### Scaling
|
||||
|
||||
The ReplicationController scales the number of replicas up or down by setting the `replicas` field.
|
||||
You can configure the ReplicationController to manage the replicas manually or by an auto-scaling control agent.
|
||||
The ReplicationController enables scaling the number of replicas up or down, either manually or by an auto-scaling control agent, by updating the `replicas` field.
|
||||
|
||||
### Rolling updates
|
||||
|
||||
@@ -245,7 +250,6 @@ The ReplicationController is forever constrained to this narrow responsibility.
|
||||
|
||||
The ReplicationController is intended to be a composable building-block primitive. We expect higher-level APIs and/or tools to be built on top of it and other complementary primitives for user convenience in the future. The "macro" operations currently supported by kubectl (run, scale) are proof-of-concept examples of this. For instance, we could imagine something like [Asgard](https://techblog.netflix.com/2012/06/asgard-web-based-cloud-management-and.html) managing ReplicationControllers, auto-scalers, services, scheduling policies, canaries, etc.
|
||||
|
||||
|
||||
## API Object
|
||||
|
||||
Replication controller is a top-level resource in the Kubernetes REST API. More details about the
|
||||
@@ -260,7 +264,6 @@ API object can be found at:
|
||||
It's mainly used by [Deployment](/docs/concepts/workloads/controllers/deployment/) as a mechanism to orchestrate pod creation, deletion and updates.
|
||||
Note that we recommend using Deployments instead of directly using Replica Sets, unless you require custom update orchestration or don't require updates at all.
|
||||
|
||||
|
||||
### Deployment (Recommended)
|
||||
|
||||
[`Deployment`](/docs/concepts/workloads/controllers/deployment/) is a higher-level API object that updates its underlying Replica Sets and their Pods. Deployments are recommended if you want this rolling update functionality because, they are declarative, server-side, and have additional features.
|
||||
@@ -284,5 +287,3 @@ safe to terminate when the machine is otherwise ready to be rebooted/shutdown.
|
||||
## For more information
|
||||
|
||||
Read [Run Stateless Application Deployment](/docs/tasks/run-application/run-stateless-application-deployment/).
|
||||
|
||||
|
||||
|
||||
@@ -313,16 +313,16 @@ limit, the same as the scheduler.
|
||||
A Pod can restart, causing re-execution of init containers, for the following
|
||||
reasons:
|
||||
|
||||
* A user updates the Pod specification, causing the init container image to change.
|
||||
Any changes to the init container image restarts the Pod. App container image
|
||||
changes only restart the app container.
|
||||
* The Pod infrastructure container is restarted. This is uncommon and would
|
||||
have to be done by someone with root access to nodes.
|
||||
* All containers in a Pod are terminated while `restartPolicy` is set to Always,
|
||||
forcing a restart, and the init container completion record has been lost due
|
||||
to garbage collection.
|
||||
|
||||
|
||||
The Pod will not be restarted when the init container image is changed, or the
|
||||
init container completion record has been lost due to garbage collection. This
|
||||
applies for Kubernetes v1.20 and later. If you are using an earlier version of
|
||||
Kubernetes, consult the documentation for the version you are using.
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
|
||||
@@ -83,16 +83,16 @@ This section shows how to generate the
|
||||
### Setting build variables
|
||||
|
||||
* Set `K8S_ROOT` to `<k8s-base>`.
|
||||
* Set `WEB_ROOT` to `<web-base>`.
|
||||
* Set `K8S_WEBROOT` to `<web-base>`.
|
||||
* Set `K8S_RELEASE` to the version of the docs you want to build.
|
||||
For example, if you want to build docs for Kubernetes 1.17, set `K8S_RELEASE` to 1.17.
|
||||
For example, if you want to build docs for Kubernetes 1.17.0, set `K8S_RELEASE` to 1.17.0.
|
||||
|
||||
For example:
|
||||
|
||||
```shell
|
||||
export WEB_ROOT=$(GOPATH)/src/github.com/<your-username>/website
|
||||
export K8S_WEBROOT=$(GOPATH)/src/github.com/<your-username>/website
|
||||
export K8S_ROOT=$(GOPATH)/src/k8s.io/kubernetes
|
||||
export K8S_RELEASE=1.17
|
||||
export K8S_RELEASE=1.17.0
|
||||
```
|
||||
|
||||
### Creating versioned directory and fetching Open API spec
|
||||
@@ -124,8 +124,8 @@ make copyapi
|
||||
Verify that these two files have been generated:
|
||||
|
||||
```shell
|
||||
[ -e "<rdocs-base>/gen-apidocs/generators/build/index.html" ] && echo "index.html built" || echo "no index.html"
|
||||
[ -e "<rdocs-base>/gen-apidocs/generators/build/navData.js" ] && echo "navData.js built" || echo "no navData.js"
|
||||
[ -e "<rdocs-base>/gen-apidocs/build/index.html" ] && echo "index.html built" || echo "no index.html"
|
||||
[ -e "<rdocs-base>/gen-apidocs/build/navData.js" ] && echo "navData.js built" || echo "no navData.js"
|
||||
```
|
||||
|
||||
Go to the base of your local `<web-base>`, and
|
||||
|
||||
@@ -22,8 +22,6 @@ This section of the Kubernetes documentation contains references.
|
||||
|
||||
* [Glossary](/docs/reference/glossary/) - a comprehensive, standardized list of Kubernetes terminology
|
||||
|
||||
|
||||
|
||||
* [Kubernetes API Reference](/docs/reference/kubernetes-api/)
|
||||
* [One-page API Reference for Kubernetes {{< param "version" >}}](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/)
|
||||
* [Using The Kubernetes API](/docs/reference/using-api/) - overview of the API for Kubernetes.
|
||||
@@ -51,17 +49,40 @@ client libraries:
|
||||
|
||||
## Components
|
||||
|
||||
* [kubelet](/docs/reference/command-line-tools-reference/kubelet/) - The primary *node agent* that runs on each node. The kubelet takes a set of PodSpecs and ensures that the described containers are running and healthy.
|
||||
* [kube-apiserver](/docs/reference/command-line-tools-reference/kube-apiserver/) - REST API that validates and configures data for API objects such as pods, services, replication controllers.
|
||||
* [kubelet](/docs/reference/command-line-tools-reference/kubelet/) - The
|
||||
primary agent that runs on each node. The kubelet takes a set of PodSpecs
|
||||
and ensures that the described containers are running and healthy.
|
||||
* [kube-apiserver](/docs/reference/command-line-tools-reference/kube-apiserver/) -
|
||||
REST API that validates and configures data for API objects such as pods,
|
||||
services, replication controllers.
|
||||
* [kube-controller-manager](/docs/reference/command-line-tools-reference/kube-controller-manager/) - Daemon that embeds the core control loops shipped with Kubernetes.
|
||||
* [kube-proxy](/docs/reference/command-line-tools-reference/kube-proxy/) - Can do simple TCP/UDP stream forwarding or round-robin TCP/UDP forwarding across a set of back-ends.
|
||||
* [kube-scheduler](/docs/reference/command-line-tools-reference/kube-scheduler/) - Scheduler that manages availability, performance, and capacity.
|
||||
* [kube-proxy](/docs/reference/command-line-tools-reference/kube-proxy/) - Can
|
||||
do simple TCP/UDP stream forwarding or round-robin TCP/UDP forwarding across
|
||||
a set of back-ends.
|
||||
* [kube-scheduler](/docs/reference/command-line-tools-reference/kube-scheduler/) - Scheduler that manages availability, performance, and capacity.
|
||||
|
||||
## Scheduling
|
||||
* [Scheduler Policies](/docs/reference/scheduling/policies)
|
||||
* [Scheduler Profiles](/docs/reference/scheduling/config#profiles)
|
||||
|
||||
* [Scheduler Policies](/docs/reference/scheduling/policies)
|
||||
* [Scheduler Profiles](/docs/reference/scheduling/config#profiles)
|
||||
## Config APIs
|
||||
|
||||
This section hosts the documentation for "unpublished" APIs which are used to
|
||||
configure kubernetes components or tools. Most of these APIs are not exposed
|
||||
by the API server in a RESTful way though they are essential for a user or an
|
||||
operator to use or manage a cluster.
|
||||
|
||||
* [kubelet configuration (v1beta1)](/docs/reference/config-api/kubelet-config.v1beta1/)
|
||||
* [kube-scheduler configuration (v1beta1)](/docs/reference/config-api/kube-scheduler-config.v1beta1/)
|
||||
* [kube-proxy configuration (v1alpha1)](/docs/reference/config-api/kube-proxy-config.v1alpha1/)
|
||||
* [`audit.k8s.io/v1` API](/docs/reference/config-api/apiserver-audit.v1/)
|
||||
|
||||
## Config APIs
|
||||
|
||||
* [Client authentication API (v1beta1)](/docs/reference/config-api/client-authentication.v1beta1/)
|
||||
|
||||
## Config APIs
|
||||
|
||||
* [kube-scheduler policy reference (v1)](/docs/reference/config-api/kube-scheduler-policy-config.v1/)
|
||||
|
||||
## Design Docs
|
||||
|
||||
|
||||
@@ -176,7 +176,7 @@ The default value for `default-not-ready-toleration-seconds` and `default-unreac
|
||||
This admission controller will intercept all requests to exec a command in a pod if that pod has a privileged container.
|
||||
|
||||
This functionality has been merged into [DenyEscalatingExec](#denyescalatingexec).
|
||||
The DenyExecOnPrivileged admission plugin is deprecated and will be removed in v1.18.
|
||||
The DenyExecOnPrivileged admission plugin is deprecated.
|
||||
|
||||
Use of a policy-based admission plugin (like [PodSecurityPolicy](#podsecuritypolicy) or a custom admission plugin)
|
||||
which can be targeted at specific users or Namespaces and also protects against creation of overly privileged Pods
|
||||
@@ -190,7 +190,7 @@ This admission controller will deny exec and attach commands to pods that run wi
|
||||
allow host access. This includes pods that run as privileged, have access to the host IPC namespace, and
|
||||
have access to the host PID namespace.
|
||||
|
||||
The DenyEscalatingExec admission plugin is deprecated and will be removed in v1.18.
|
||||
The DenyEscalatingExec admission plugin is deprecated.
|
||||
|
||||
Use of a policy-based admission plugin (like [PodSecurityPolicy](#podsecuritypolicy) or a custom admission plugin)
|
||||
which can be targeted at specific users or Namespaces and also protects against creation of overly privileged Pods
|
||||
|
||||
@@ -955,7 +955,8 @@ When run from an interactive session, `stdin` is exposed directly to the plugin.
|
||||
[TTY check](https://godoc.org/golang.org/x/crypto/ssh/terminal#IsTerminal) to determine if it's
|
||||
appropriate to prompt a user interactively.
|
||||
|
||||
To use bearer token credentials, the plugin returns a token in the status of the `ExecCredential`.
|
||||
To use bearer token credentials, the plugin returns a token in the status of the
|
||||
[`ExecCredential`](/docs/reference/config-api/client-authentication.v1beta1/#client-authentication-k8s-io-v1beta1-ExecCredential)
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -1005,6 +1006,7 @@ RFC3339 timestamp. Presence or absence of an expiry has the following impact:
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
To enable the exec plugin to obtain cluster-specific information, set `provideClusterInfo` on the `user.exec`
|
||||
field in the [kubeconfig](/docs/concepts/configuration/organize-cluster-access-kubeconfig/).
|
||||
The plugin will then be supplied with an environment variable, `KUBERNETES_EXEC_INFO`.
|
||||
@@ -1029,3 +1031,8 @@ The following `ExecCredential` manifest describes a cluster information sample.
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
* Read the [client authentication reference (v1beta1)](/docs/reference/config-api/client-authentication.v1beta1/)
|
||||
|
||||
|
||||
@@ -546,10 +546,9 @@ Each feature gate is designed for enabling/disabling a specific feature:
|
||||
[CustomResourceDefinition](/docs/concepts/extend-kubernetes/api-extension/custom-resources/).
|
||||
- `CustomResourceWebhookConversion`: Enable webhook-based conversion
|
||||
on resources created from [CustomResourceDefinition](/docs/concepts/extend-kubernetes/api-extension/custom-resources/).
|
||||
troubleshoot a running Pod.
|
||||
- `DefaultPodTopologySpread`: Enables the use of `PodTopologySpread` scheduling plugin to do
|
||||
[default spreading](/docs/concepts/workloads/pods/pod-topology-spread-constraints/#internal-default-constraints).
|
||||
- `DevicePlugins`: Enable the [device-plugins](/docs/concepts/cluster-administration/device-plugins/)
|
||||
- `DevicePlugins`: Enable the [device-plugins](/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/)
|
||||
based resource provisioning on nodes.
|
||||
- `DisableAcceleratorUsageMetrics`:
|
||||
[Disable accelerator metrics collected by the kubelet](/docs/concepts/cluster-administration/system-metrics/#disable-accelerator-metrics).
|
||||
@@ -728,8 +727,6 @@ Each feature gate is designed for enabling/disabling a specific feature:
|
||||
topology of the cluster. See
|
||||
[ServiceTopology](/docs/concepts/services-networking/service-topology/)
|
||||
for more details.
|
||||
- `SizeMemoryBackedVolumes`: Enables kubelet support to size memory backed volumes.
|
||||
See [volumes](/docs/concepts/storage/volumes) for more details.
|
||||
- `SetHostnameAsFQDN`: Enable the ability of setting Fully Qualified Domain
|
||||
Name(FQDN) as the hostname of a pod. See
|
||||
[Pod's `setHostnameAsFQDN` field](/docs/concepts/services-networking/dns-pod-service/#pod-sethostnameasfqdn-field).
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
+36
-18
@@ -24,11 +24,10 @@ found [here](https://github.com/kubernetes/kubernetes/pull/20439).
|
||||
This document describes the process of node initialization, how to set up TLS client certificate bootstrapping for
|
||||
kubelets, and how it works.
|
||||
|
||||
|
||||
|
||||
<!-- body -->
|
||||
|
||||
## Initialization Process
|
||||
|
||||
When a worker node starts up, the kubelet does the following:
|
||||
|
||||
1. Look for its `kubeconfig` file
|
||||
@@ -54,6 +53,7 @@ The TLS Bootstrapping described in this document is intended to simplify, and pa
|
||||
a cluster.
|
||||
|
||||
### Bootstrap Initialization
|
||||
|
||||
In the bootstrap initialization process, the following occurs:
|
||||
|
||||
1. kubelet begins
|
||||
@@ -77,6 +77,7 @@ In the bootstrap initialization process, the following occurs:
|
||||
The rest of this document describes the necessary steps to configure TLS Bootstrapping, and its limitations.
|
||||
|
||||
## Configuration
|
||||
|
||||
To configure for TLS bootstrapping and optional automatic approval, you must configure options on the following components:
|
||||
|
||||
* kube-apiserver
|
||||
@@ -87,6 +88,7 @@ To configure for TLS bootstrapping and optional automatic approval, you must con
|
||||
In addition, you need your Kubernetes Certificate Authority (CA).
|
||||
|
||||
## Certificate Authority
|
||||
|
||||
As without bootstrapping, you will need a Certificate Authority (CA) key and certificate. As without bootstrapping, these will be used
|
||||
to sign the kubelet certificate. As before, it is your responsibility to distribute them to master nodes.
|
||||
|
||||
@@ -96,6 +98,7 @@ We will refer to these as "Kubernetes CA certificate and key".
|
||||
All Kubernetes components that use these certificates - kubelet, kube-apiserver, kube-controller-manager - assume the key and certificate to be PEM-encoded.
|
||||
|
||||
## kube-apiserver configuration
|
||||
|
||||
The kube-apiserver has several requirements to enable TLS bootstrapping:
|
||||
|
||||
* Recognizing CA that signs the client certificate
|
||||
@@ -103,6 +106,7 @@ The kube-apiserver has several requirements to enable TLS bootstrapping:
|
||||
* Authorize the bootstrapping kubelet to create a certificate signing request (CSR)
|
||||
|
||||
### Recognizing client certificates
|
||||
|
||||
This is normal for all client certificate authentication.
|
||||
If not already set, add the `--client-ca-file=FILENAME` flag to the kube-apiserver command to enable
|
||||
client certificate authentication, referencing a certificate authority bundle
|
||||
@@ -110,6 +114,7 @@ containing the signing certificate, for example
|
||||
`--client-ca-file=/var/lib/kubernetes/ca.pem`.
|
||||
|
||||
### Initial bootstrap authentication
|
||||
|
||||
In order for the bootstrapping kubelet to connect to kube-apiserver and request a certificate, it must first authenticate to the server.
|
||||
You can use any [authenticator](/docs/reference/access-authn-authz/authentication/) that can authenticate the kubelet.
|
||||
|
||||
@@ -132,13 +137,13 @@ A kubelet authenticating using bootstrap tokens is authenticated as a user in th
|
||||
|
||||
As this feature matures, you
|
||||
should ensure tokens are bound to a Role Based Access Control (RBAC) policy
|
||||
which limits requests (using the [bootstrap
|
||||
token](/docs/reference/access-authn-authz/bootstrap-tokens/)) strictly to client
|
||||
which limits requests (using the [bootstrap token](/docs/reference/access-authn-authz/bootstrap-tokens/)) strictly to client
|
||||
requests related to certificate provisioning. With RBAC in place, scoping the
|
||||
tokens to a group allows for great flexibility. For example, you could disable a
|
||||
particular bootstrap group's access when you are done provisioning the nodes.
|
||||
|
||||
#### Bootstrap tokens
|
||||
|
||||
Bootstrap tokens are described in detail [here](/docs/reference/access-authn-authz/bootstrap-tokens/). These are tokens that are stored as secrets in the Kubernetes cluster,
|
||||
and then issued to the individual kubelet. You can use a single token for an entire cluster, or issue one per worker node.
|
||||
|
||||
@@ -148,7 +153,7 @@ The process is two-fold:
|
||||
2. Issue the token to the kubelet
|
||||
|
||||
From the kubelet's perspective, one token is like another and has no special meaning.
|
||||
From the kube-apiserver's perspective, however, the bootstrap token is special. Due to its `Type`, `namespace` and `name`, kube-apiserver recognizes it as a special token,
|
||||
From the kube-apiserver's perspective, however, the bootstrap token is special. Due to its `type`, `namespace` and `name`, kube-apiserver recognizes it as a special token,
|
||||
and grants anyone authenticating with that token special bootstrap rights, notably treating them as a member of the `system:bootstrappers` group. This fulfills a basic requirement
|
||||
for TLS bootstrapping.
|
||||
|
||||
@@ -156,17 +161,18 @@ The details for creating the secret are available [here](/docs/reference/access-
|
||||
|
||||
If you want to use bootstrap tokens, you must enable it on kube-apiserver with the flag:
|
||||
|
||||
```
|
||||
```console
|
||||
--enable-bootstrap-token-auth=true
|
||||
```
|
||||
|
||||
#### Token authentication file
|
||||
|
||||
kube-apiserver has an ability to accept tokens as authentication.
|
||||
These tokens are arbitrary but should represent at least 128 bits of entropy derived
|
||||
from a secure random number generator (such as `/dev/urandom` on most modern Linux
|
||||
systems). There are multiple ways you can generate a token. For example:
|
||||
|
||||
```
|
||||
```shell
|
||||
head -c 16 /dev/urandom | od -An -t x | tr -d ' '
|
||||
```
|
||||
|
||||
@@ -175,7 +181,7 @@ will generate tokens that look like `02b50b05283e98dd0fd71db496ef01e8`.
|
||||
The token file should look like the following example, where the first three
|
||||
values can be anything and the quoted group name should be as depicted:
|
||||
|
||||
```
|
||||
```console
|
||||
02b50b05283e98dd0fd71db496ef01e8,kubelet-bootstrap,10001,"system:bootstrappers"
|
||||
```
|
||||
|
||||
@@ -185,11 +191,16 @@ systemd unit file perhaps) to enable the token file. See docs
|
||||
further details.
|
||||
|
||||
### Authorize kubelet to create CSR
|
||||
Now that the bootstrapping node is _authenticated_ as part of the `system:bootstrappers` group, it needs to be _authorized_ to create a certificate signing request (CSR) as well as retrieve it when done. Fortunately, Kubernetes ships with a `ClusterRole` with precisely these (and only these) permissions, `system:node-bootstrapper`.
|
||||
|
||||
Now that the bootstrapping node is _authenticated_ as part of the
|
||||
`system:bootstrappers` group, it needs to be _authorized_ to create a
|
||||
certificate signing request (CSR) as well as retrieve it when done.
|
||||
Fortunately, Kubernetes ships with a `ClusterRole` with precisely these (and
|
||||
only these) permissions, `system:node-bootstrapper`.
|
||||
|
||||
To do this, you only need to create a `ClusterRoleBinding` that binds the `system:bootstrappers` group to the cluster role `system:node-bootstrapper`.
|
||||
|
||||
```
|
||||
```yaml
|
||||
# enable bootstrapping nodes to create CSR
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -206,6 +217,7 @@ roleRef:
|
||||
```
|
||||
|
||||
## kube-controller-manager configuration
|
||||
|
||||
While the apiserver receives the requests for certificates from the kubelet and authenticates those requests,
|
||||
the controller-manager is responsible for issuing actual signed certificates.
|
||||
|
||||
@@ -221,6 +233,7 @@ In order for the controller-manager to sign certificates, it needs the following
|
||||
* enabling CSR signing
|
||||
|
||||
### Access to key and certificate
|
||||
|
||||
As described earlier, you need to create a Kubernetes CA key and certificate, and distribute it to the master nodes.
|
||||
These will be used by the controller-manager to sign the kubelet certificates.
|
||||
|
||||
@@ -230,23 +243,24 @@ with the flag `--client-ca-file=FILENAME` (for example, `--client-ca-file=/var/l
|
||||
|
||||
To provide the Kubernetes CA key and certificate to kube-controller-manager, use the following flags:
|
||||
|
||||
```
|
||||
```shell
|
||||
--cluster-signing-cert-file="/etc/path/to/kubernetes/ca/ca.crt" --cluster-signing-key-file="/etc/path/to/kubernetes/ca/ca.key"
|
||||
```
|
||||
|
||||
for example:
|
||||
|
||||
```
|
||||
```shell
|
||||
--cluster-signing-cert-file="/var/lib/kubernetes/ca.pem" --cluster-signing-key-file="/var/lib/kubernetes/ca-key.pem"
|
||||
```
|
||||
|
||||
The validity duration of signed certificates can be configured with flag:
|
||||
|
||||
```
|
||||
```shell
|
||||
--cluster-signing-duration
|
||||
```
|
||||
|
||||
### Approval
|
||||
|
||||
In order to approve CSRs, you need to tell the controller-manager that it is acceptable to approve them. This is done by granting
|
||||
RBAC permissions to the correct group.
|
||||
|
||||
@@ -257,7 +271,7 @@ There are two distinct sets of permissions:
|
||||
|
||||
To enable the kubelet to request and receive a new certificate, create a `ClusterRoleBinding` that binds the group in which the bootstrapping node is a member `system:bootstrappers` to the `ClusterRole` that grants it permission, `system:certificates.k8s.io:certificatesigningrequests:nodeclient`:
|
||||
|
||||
```yml
|
||||
```yaml
|
||||
# Approve all CSRs for the group "system:bootstrappers"
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -276,7 +290,7 @@ roleRef:
|
||||
To enable the kubelet to renew its own client certificate, create a `ClusterRoleBinding` that binds the group in which the fully functioning node is a member `system:nodes` to the `ClusterRole` that
|
||||
grants it permission, `system:certificates.k8s.io:certificatesigningrequests:selfnodeclient`:
|
||||
|
||||
```yml
|
||||
```yaml
|
||||
# Approve renewal CSRs for the group "system:nodes"
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -294,8 +308,8 @@ roleRef:
|
||||
|
||||
The `csrapproving` controller that ships as part of
|
||||
[kube-controller-manager](/docs/admin/kube-controller-manager/) and is enabled
|
||||
by default. The controller uses the [`SubjectAccessReview`
|
||||
API](/docs/reference/access-authn-authz/authorization/#checking-api-access) to
|
||||
by default. The controller uses the
|
||||
[`SubjectAccessReview` API](/docs/reference/access-authn-authz/authorization/#checking-api-access) to
|
||||
determine if a given user is authorized to request a CSR, then approves based on
|
||||
the authorization outcome. To prevent conflicts with other approvers, the
|
||||
builtin approver doesn't explicitly deny CSRs. It only ignores unauthorized
|
||||
@@ -304,6 +318,7 @@ collection.
|
||||
|
||||
|
||||
## kubelet configuration
|
||||
|
||||
Finally, with the master nodes properly set up and all of the necessary authentication and authorization in place, we can configure the kubelet.
|
||||
|
||||
The kubelet requires the following configuration to bootstrap:
|
||||
@@ -317,7 +332,7 @@ The bootstrap `kubeconfig` should be in a path available to the kubelet, for exa
|
||||
|
||||
Its format is identical to a normal `kubeconfig` file. A sample file might look as follows:
|
||||
|
||||
```yml
|
||||
```yaml
|
||||
apiVersion: v1
|
||||
kind: Config
|
||||
clusters:
|
||||
@@ -371,6 +386,7 @@ specified by `--kubeconfig`. The certificate and key file will be placed in the
|
||||
directory specified by `--cert-dir`.
|
||||
|
||||
### Client and Serving Certificates
|
||||
|
||||
All of the above relate to kubelet _client_ certificates, specifically, the certificates a kubelet
|
||||
uses to authenticate to kube-apiserver.
|
||||
|
||||
@@ -387,6 +403,7 @@ be used as serving certificates, or `server auth`.
|
||||
However, you _can_ enable its server certificate, at least partially, via certificate rotation.
|
||||
|
||||
### Certificate Rotation
|
||||
|
||||
Kubernetes v1.8 and higher kubelet implements __beta__ features for enabling
|
||||
rotation of its client and/or serving certificates. These can be enabled through
|
||||
the respective `RotateKubeletClientCertificate` and
|
||||
@@ -429,6 +446,7 @@ A deployment-specific approval process for kubelet serving certificates should t
|
||||
{{< /note >}}
|
||||
|
||||
## Other authenticating components
|
||||
|
||||
All of TLS bootstrapping described in this document relates to the kubelet. However,
|
||||
other components may need to communicate directly with kube-apiserver. Notable is kube-proxy, which
|
||||
is part of the Kubernetes control plane and runs on every node, but may also include other components such as monitoring or networking.
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
---
|
||||
title: Configuration APIs
|
||||
weight: 65
|
||||
---
|
||||
|
||||
@@ -0,0 +1,620 @@
|
||||
---
|
||||
title: kube-apiserver Audit Configuration (v1)
|
||||
content_type: tool-reference
|
||||
package: audit.k8s.io/v1
|
||||
auto_generated: true
|
||||
---
|
||||
|
||||
|
||||
## Resource Types
|
||||
|
||||
|
||||
- [Event](#audit-k8s-io-v1-Event)
|
||||
- [EventList](#audit-k8s-io-v1-EventList)
|
||||
- [Policy](#audit-k8s-io-v1-Policy)
|
||||
- [PolicyList](#audit-k8s-io-v1-PolicyList)
|
||||
|
||||
|
||||
|
||||
|
||||
## `Event` {#audit-k8s-io-v1-Event}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [EventList](#audit-k8s-io-v1-EventList)
|
||||
|
||||
|
||||
Event captures all the information that can be included in an API audit log.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
<tr><td><code>apiVersion</code><br/>string</td><td><code>audit.k8s.io/v1</code></td></tr>
|
||||
<tr><td><code>kind</code><br/>string</td><td><code>Event</code></td></tr>
|
||||
|
||||
|
||||
|
||||
|
||||
<tr><td><code>level</code> <B>[Required]</B><br/>
|
||||
<a href="#audit-k8s-io-v1-Level"><code>Level</code></a>
|
||||
</td>
|
||||
<td>
|
||||
AuditLevel at which event was generated</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>auditID</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/types#UID"><code>k8s.io/apimachinery/pkg/types.UID</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Unique audit ID, generated for each request.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>stage</code> <B>[Required]</B><br/>
|
||||
<a href="#audit-k8s-io-v1-Stage"><code>Stage</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Stage of the request handling when this event instance was generated.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>requestURI</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
RequestURI is the request URI as sent by the client to a server.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>verb</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Verb is the kubernetes verb associated with the request.
|
||||
For non-resource requests, this is the lower-cased HTTP method.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>user</code> <B>[Required]</B><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#userinfo-v1-authentication"><code>authentication/v1.UserInfo</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Authenticated user information.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>impersonatedUser</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#userinfo-v1-authentication"><code>authentication/v1.UserInfo</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Impersonated user information.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>sourceIPs</code><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
Source IPs, from where the request originated and intermediate proxies.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>userAgent</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
UserAgent records the user agent string reported by the client.
|
||||
Note that the UserAgent is provided by the client, and must not be trusted.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>objectRef</code><br/>
|
||||
<a href="#audit-k8s-io-v1-ObjectReference"><code>ObjectReference</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Object reference this request is targeted at.
|
||||
Does not apply for List-type requests, or non-resource requests.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>responseStatus</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#status-v1-meta"><code>meta/v1.Status</code></a>
|
||||
</td>
|
||||
<td>
|
||||
The response status, populated even when the ResponseObject is not a Status type.
|
||||
For successful responses, this will only include the Code and StatusSuccess.
|
||||
For non-status type error responses, this will be auto-populated with the error Message.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>requestObject</code><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/runtime#Unknown"><code>k8s.io/apimachinery/pkg/runtime.Unknown</code></a>
|
||||
</td>
|
||||
<td>
|
||||
API object from the request, in JSON format. The RequestObject is recorded as-is in the request
|
||||
(possibly re-encoded as JSON), prior to version conversion, defaulting, admission or
|
||||
merging. It is an external versioned object type, and may not be a valid object on its own.
|
||||
Omitted for non-resource requests. Only logged at Request Level and higher.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>responseObject</code><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/runtime#Unknown"><code>k8s.io/apimachinery/pkg/runtime.Unknown</code></a>
|
||||
</td>
|
||||
<td>
|
||||
API object returned in the response, in JSON. The ResponseObject is recorded after conversion
|
||||
to the external type, and serialized as JSON. Omitted for non-resource requests. Only logged
|
||||
at Response Level.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>requestReceivedTimestamp</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Time the request reached the apiserver.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>stageTimestamp</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Time the request reached current audit stage.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>annotations</code><br/>
|
||||
<code>map[string]string</code>
|
||||
</td>
|
||||
<td>
|
||||
Annotations is an unstructured key value map stored with an audit event that may be set by
|
||||
plugins invoked in the request serving chain, including authentication, authorization and
|
||||
admission plugins. Note that these annotations are for the audit event, and do not correspond
|
||||
to the metadata.annotations of the submitted object. Keys should uniquely identify the informing
|
||||
component to avoid name collisions (e.g. podsecuritypolicy.admission.k8s.io/policy). Values
|
||||
should be short. Annotations are included in the Metadata level.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `EventList` {#audit-k8s-io-v1-EventList}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
EventList is a list of audit Events.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
<tr><td><code>apiVersion</code><br/>string</td><td><code>audit.k8s.io/v1</code></td></tr>
|
||||
<tr><td><code>kind</code><br/>string</td><td><code>EventList</code></td></tr>
|
||||
|
||||
|
||||
|
||||
|
||||
<tr><td><code>metadata</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>items</code> <B>[Required]</B><br/>
|
||||
<a href="#audit-k8s-io-v1-Event"><code>[]Event</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `Policy` {#audit-k8s-io-v1-Policy}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PolicyList](#audit-k8s-io-v1-PolicyList)
|
||||
|
||||
|
||||
Policy defines the configuration of audit logging, and the rules for how different request
|
||||
categories are logged.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
<tr><td><code>apiVersion</code><br/>string</td><td><code>audit.k8s.io/v1</code></td></tr>
|
||||
<tr><td><code>kind</code><br/>string</td><td><code>Policy</code></td></tr>
|
||||
|
||||
|
||||
|
||||
|
||||
<tr><td><code>metadata</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#objectmeta-v1-meta"><code>meta/v1.ObjectMeta</code></a>
|
||||
</td>
|
||||
<td>
|
||||
ObjectMeta is included for interoperability with API infrastructure.Refer to the Kubernetes API documentation for the fields of the <code>metadata</code> field.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>rules</code> <B>[Required]</B><br/>
|
||||
<a href="#audit-k8s-io-v1-PolicyRule"><code>[]PolicyRule</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Rules specify the audit Level a request should be recorded at.
|
||||
A request may match multiple rules, in which case the FIRST matching rule is used.
|
||||
The default audit level is None, but can be overridden by a catch-all rule at the end of the list.
|
||||
PolicyRules are strictly ordered.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>omitStages</code><br/>
|
||||
<a href="#audit-k8s-io-v1-Stage"><code>[]Stage</code></a>
|
||||
</td>
|
||||
<td>
|
||||
OmitStages is a list of stages for which no events are created. Note that this can also
|
||||
be specified per rule in which case the union of both are omitted.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `PolicyList` {#audit-k8s-io-v1-PolicyList}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
PolicyList is a list of audit Policies.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
<tr><td><code>apiVersion</code><br/>string</td><td><code>audit.k8s.io/v1</code></td></tr>
|
||||
<tr><td><code>kind</code><br/>string</td><td><code>PolicyList</code></td></tr>
|
||||
|
||||
|
||||
|
||||
|
||||
<tr><td><code>metadata</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>items</code> <B>[Required]</B><br/>
|
||||
<a href="#audit-k8s-io-v1-Policy"><code>[]Policy</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `GroupResources` {#audit-k8s-io-v1-GroupResources}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PolicyRule](#audit-k8s-io-v1-PolicyRule)
|
||||
|
||||
|
||||
GroupResources represents resource kinds in an API group.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>group</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Group is the name of the API group that contains the resources.
|
||||
The empty string represents the core API group.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>resources</code><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
Resources is a list of resources this rule applies to.
|
||||
|
||||
For example:
|
||||
'pods' matches pods.
|
||||
'pods/log' matches the log subresource of pods.
|
||||
'∗' matches all resources and their subresources.
|
||||
'pods/∗' matches all subresources of pods.
|
||||
'∗/scale' matches all scale subresources.
|
||||
|
||||
If wildcard is present, the validation rule will ensure resources do not
|
||||
overlap with each other.
|
||||
|
||||
An empty list implies all resources and subresources in this API groups apply.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>resourceNames</code><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
ResourceNames is a list of resource instance names that the policy matches.
|
||||
Using this field requires Resources to be specified.
|
||||
An empty list implies that every instance of the resource is matched.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `Level` {#audit-k8s-io-v1-Level}
|
||||
|
||||
(Alias of `string`)
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Event](#audit-k8s-io-v1-Event)
|
||||
|
||||
- [PolicyRule](#audit-k8s-io-v1-PolicyRule)
|
||||
|
||||
|
||||
Level defines the amount of information logged during auditing
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
## `ObjectReference` {#audit-k8s-io-v1-ObjectReference}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Event](#audit-k8s-io-v1-Event)
|
||||
|
||||
|
||||
ObjectReference contains enough information to let you inspect or modify the referred object.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>resource</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>namespace</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>name</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>uid</code><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/types#UID"><code>k8s.io/apimachinery/pkg/types.UID</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>apiGroup</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
APIGroup is the name of the API group that contains the referred object.
|
||||
The empty string represents the core API group.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>apiVersion</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
APIVersion is the version of the API group that contains the referred object.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>resourceVersion</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>subresource</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `PolicyRule` {#audit-k8s-io-v1-PolicyRule}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Policy](#audit-k8s-io-v1-Policy)
|
||||
|
||||
|
||||
PolicyRule maps requests based off metadata to an audit Level.
|
||||
Requests must match the rules of every field (an intersection of rules).
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>level</code> <B>[Required]</B><br/>
|
||||
<a href="#audit-k8s-io-v1-Level"><code>Level</code></a>
|
||||
</td>
|
||||
<td>
|
||||
The Level that requests matching this rule are recorded at.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>users</code><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
The users (by authenticated user name) this rule applies to.
|
||||
An empty list implies every user.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>userGroups</code><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
The user groups this rule applies to. A user is considered matching
|
||||
if it is a member of any of the UserGroups.
|
||||
An empty list implies every user group.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>verbs</code><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
The verbs that match this rule.
|
||||
An empty list implies every verb.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>resources</code><br/>
|
||||
<a href="#audit-k8s-io-v1-GroupResources"><code>[]GroupResources</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Resources that this rule matches. An empty list implies all kinds in all API groups.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>namespaces</code><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
Namespaces that this rule matches.
|
||||
The empty string "" matches non-namespaced resources.
|
||||
An empty list implies every namespace.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>nonResourceURLs</code><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
NonResourceURLs is a set of URL paths that should be audited.
|
||||
∗s are allowed, but only as the full, final step in the path.
|
||||
Examples:
|
||||
"/metrics" - Log requests for apiserver metrics
|
||||
"/healthz∗" - Log all health checks</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>omitStages</code><br/>
|
||||
<a href="#audit-k8s-io-v1-Stage"><code>[]Stage</code></a>
|
||||
</td>
|
||||
<td>
|
||||
OmitStages is a list of stages for which no events are created. Note that this can also
|
||||
be specified policy wide in which case the union of both are omitted.
|
||||
An empty list means no restrictions will apply.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `Stage` {#audit-k8s-io-v1-Stage}
|
||||
|
||||
(Alias of `string`)
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Event](#audit-k8s-io-v1-Event)
|
||||
|
||||
- [Policy](#audit-k8s-io-v1-Policy)
|
||||
|
||||
- [PolicyRule](#audit-k8s-io-v1-PolicyRule)
|
||||
|
||||
|
||||
Stage defines the stages in request handling that audit events may be generated.
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,252 @@
|
||||
---
|
||||
title: Client Authentication (v1beta1)
|
||||
content_type: tool-reference
|
||||
package: client.authentication.k8s.io/v1beta1
|
||||
auto_generated: true
|
||||
---
|
||||
|
||||
|
||||
## Resource Types
|
||||
|
||||
|
||||
- [ExecCredential](#client-authentication-k8s-io-v1beta1-ExecCredential)
|
||||
|
||||
|
||||
|
||||
|
||||
## `ExecCredential` {#client-authentication-k8s-io-v1beta1-ExecCredential}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
ExecCredential is used by exec-based plugins to communicate credentials to
|
||||
HTTP transports.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
<tr><td><code>apiVersion</code><br/>string</td><td><code>client.authentication.k8s.io/v1beta1</code></td></tr>
|
||||
<tr><td><code>kind</code><br/>string</td><td><code>ExecCredential</code></td></tr>
|
||||
|
||||
|
||||
|
||||
|
||||
<tr><td><code>spec</code> <B>[Required]</B><br/>
|
||||
<a href="#client-authentication-k8s-io-v1beta1-ExecCredentialSpec"><code>ExecCredentialSpec</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Spec holds information passed to the plugin by the transport.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>status</code><br/>
|
||||
<a href="#client-authentication-k8s-io-v1beta1-ExecCredentialStatus"><code>ExecCredentialStatus</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Status is filled in by the plugin and holds the credentials that the transport
|
||||
should use to contact the API.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `Cluster` {#client-authentication-k8s-io-v1beta1-Cluster}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [ExecCredentialSpec](#client-authentication-k8s-io-v1beta1-ExecCredentialSpec)
|
||||
|
||||
|
||||
Cluster contains information to allow an exec plugin to communicate
|
||||
with the kubernetes cluster being authenticated to.
|
||||
|
||||
To ensure that this struct contains everything someone would need to communicate
|
||||
with a kubernetes cluster (just like they would via a kubeconfig), the fields
|
||||
should shadow "k8s.io/client-go/tools/clientcmd/api/v1".Cluster, with the exception
|
||||
of CertificateAuthority, since CA data will always be passed to the plugin as bytes.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>server</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Server is the address of the kubernetes cluster (https://hostname:port).</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>tls-server-name</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
TLSServerName is passed to the server for SNI and is used in the client to
|
||||
check server certificates against. If ServerName is empty, the hostname
|
||||
used to contact the server is used.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>insecure-skip-tls-verify</code><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
InsecureSkipTLSVerify skips the validity check for the server's certificate.
|
||||
This will make your HTTPS connections insecure.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>certificate-authority-data</code><br/>
|
||||
<code>[]byte</code>
|
||||
</td>
|
||||
<td>
|
||||
CAData contains PEM-encoded certificate authority certificates.
|
||||
If empty, system roots should be used.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>proxy-url</code><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
ProxyURL is the URL to the proxy to be used for all requests to this
|
||||
cluster.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>config</code><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/runtime/#RawExtension"><code>k8s.io/apimachinery/pkg/runtime.RawExtension</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Config holds additional config data that is specific to the exec
|
||||
plugin with regards to the cluster being authenticated to.
|
||||
|
||||
This data is sourced from the clientcmd Cluster object's
|
||||
extensions[client.authentication.k8s.io/exec] field:
|
||||
|
||||
clusters:
|
||||
- name: my-cluster
|
||||
cluster:
|
||||
...
|
||||
extensions:
|
||||
- name: client.authentication.k8s.io/exec # reserved extension name for per cluster exec config
|
||||
extension:
|
||||
audience: 06e3fbd18de8 # arbitrary config
|
||||
|
||||
In some environments, the user config may be exactly the same across many clusters
|
||||
(i.e. call this exec plugin) minus some details that are specific to each cluster
|
||||
such as the audience. This field allows the per cluster config to be directly
|
||||
specified with the cluster info. Using this field to store secret data is not
|
||||
recommended as one of the prime benefits of exec plugins is that no secrets need
|
||||
to be stored directly in the kubeconfig.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `ExecCredentialSpec` {#client-authentication-k8s-io-v1beta1-ExecCredentialSpec}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [ExecCredential](#client-authentication-k8s-io-v1beta1-ExecCredential)
|
||||
|
||||
|
||||
ExecCredentialSpec holds request and runtime specific information provided by
|
||||
the transport.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>cluster</code><br/>
|
||||
<a href="#client-authentication-k8s-io-v1beta1-Cluster"><code>Cluster</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Cluster contains information to allow an exec plugin to communicate with the
|
||||
kubernetes cluster being authenticated to. Note that Cluster is non-nil only
|
||||
when provideClusterInfo is set to true in the exec provider config (i.e.,
|
||||
ExecConfig.ProvideClusterInfo).</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `ExecCredentialStatus` {#client-authentication-k8s-io-v1beta1-ExecCredentialStatus}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [ExecCredential](#client-authentication-k8s-io-v1beta1-ExecCredential)
|
||||
|
||||
|
||||
ExecCredentialStatus holds credentials for the transport to use.
|
||||
|
||||
Token and ClientKeyData are sensitive fields. This data should only be
|
||||
transmitted in-memory between client and exec plugin process. Exec plugin
|
||||
itself should at least be protected via file permissions.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>expirationTimestamp</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#time-v1-meta"><code>meta/v1.Time</code></a>
|
||||
</td>
|
||||
<td>
|
||||
ExpirationTimestamp indicates a time when the provided credentials expire.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>token</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Token is a bearer token used by the client for request authentication.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>clientCertificateData</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
PEM-encoded client TLS certificates (including intermediates, if any).</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>clientKeyData</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
PEM-encoded private key for the above certificate.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
@@ -0,0 +1,537 @@
|
||||
---
|
||||
title: kube-proxy Configuration (v1alpha1)
|
||||
content_type: tool-reference
|
||||
package: kubeproxy.config.k8s.io/v1alpha1
|
||||
auto_generated: true
|
||||
---
|
||||
|
||||
|
||||
## Resource Types
|
||||
|
||||
|
||||
|
||||
- [KubeProxyConfiguration](#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration)
|
||||
|
||||
|
||||
|
||||
|
||||
## `KubeProxyConfiguration` {#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
KubeProxyConfiguration contains everything necessary to configure the
|
||||
Kubernetes proxy server.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
<tr><td><code>apiVersion</code><br/>string</td><td><code>kubeproxy.config.k8s.io/v1alpha1</code></td></tr>
|
||||
<tr><td><code>kind</code><br/>string</td><td><code>KubeProxyConfiguration</code></td></tr>
|
||||
|
||||
|
||||
|
||||
|
||||
<tr><td><code>featureGates</code> <B>[Required]</B><br/>
|
||||
<code>map[string]bool</code>
|
||||
</td>
|
||||
<td>
|
||||
featureGates is a map of feature names to bools that enable or disable alpha/experimental features.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>bindAddress</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
bindAddress is the IP address for the proxy server to serve on (set to 0.0.0.0
|
||||
for all interfaces)</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>healthzBindAddress</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
healthzBindAddress is the IP address and port for the health check server to serve on,
|
||||
defaulting to 0.0.0.0:10256</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>metricsBindAddress</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
metricsBindAddress is the IP address and port for the metrics server to serve on,
|
||||
defaulting to 127.0.0.1:10249 (set to 0.0.0.0 for all interfaces)</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>bindAddressHardFail</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
bindAddressHardFail, if true, kube-proxy will treat failure to bind to a port as fatal and exit</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>enableProfiling</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
enableProfiling enables profiling via web interface on /debug/pprof handler.
|
||||
Profiling handlers will be handled by metrics server.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>clusterCIDR</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
clusterCIDR is the CIDR range of the pods in the cluster. It is used to
|
||||
bridge traffic coming from outside of the cluster. If not provided,
|
||||
no off-cluster bridging will be performed.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>hostnameOverride</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
hostnameOverride, if non-empty, will be used as the identity instead of the actual hostname.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>clientConnection</code> <B>[Required]</B><br/>
|
||||
<a href="#ClientConnectionConfiguration"><code>ClientConnectionConfiguration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
clientConnection specifies the kubeconfig file and client connection settings for the proxy
|
||||
server to use when communicating with the apiserver.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>iptables</code> <B>[Required]</B><br/>
|
||||
<a href="#kubeproxy-config-k8s-io-v1alpha1-KubeProxyIPTablesConfiguration"><code>KubeProxyIPTablesConfiguration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
iptables contains iptables-related configuration options.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>ipvs</code> <B>[Required]</B><br/>
|
||||
<a href="#kubeproxy-config-k8s-io-v1alpha1-KubeProxyIPVSConfiguration"><code>KubeProxyIPVSConfiguration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
ipvs contains ipvs-related configuration options.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>oomScoreAdj</code> <B>[Required]</B><br/>
|
||||
<code>int32</code>
|
||||
</td>
|
||||
<td>
|
||||
oomScoreAdj is the oom-score-adj value for kube-proxy process. Values must be within
|
||||
the range [-1000, 1000]</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>mode</code> <B>[Required]</B><br/>
|
||||
<a href="#kubeproxy-config-k8s-io-v1alpha1-ProxyMode"><code>ProxyMode</code></a>
|
||||
</td>
|
||||
<td>
|
||||
mode specifies which proxy mode to use.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>portRange</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
portRange is the range of host ports (beginPort-endPort, inclusive) that may be consumed
|
||||
in order to proxy service traffic. If unspecified (0-0) then ports will be randomly chosen.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>udpIdleTimeout</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
udpIdleTimeout is how long an idle UDP connection will be kept open (e.g. '250ms', '2s').
|
||||
Must be greater than 0. Only applicable for proxyMode=userspace.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>conntrack</code> <B>[Required]</B><br/>
|
||||
<a href="#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConntrackConfiguration"><code>KubeProxyConntrackConfiguration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
conntrack contains conntrack-related configuration options.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>configSyncPeriod</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
configSyncPeriod is how often configuration from the apiserver is refreshed. Must be greater
|
||||
than 0.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>nodePortAddresses</code> <B>[Required]</B><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
nodePortAddresses is the --nodeport-addresses value for kube-proxy process. Values must be valid
|
||||
IP blocks. These values are as a parameter to select the interfaces where nodeport works.
|
||||
In case someone would like to expose a service on localhost for local visit and some other interfaces for
|
||||
particular purpose, a list of IP blocks would do that.
|
||||
If set it to "127.0.0.0/8", kube-proxy will only select the loopback interface for NodePort.
|
||||
If set it to a non-zero IP block, kube-proxy will filter that down to just the IPs that applied to the node.
|
||||
An empty string slice is meant to select all network interfaces.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>winkernel</code> <B>[Required]</B><br/>
|
||||
<a href="#kubeproxy-config-k8s-io-v1alpha1-KubeProxyWinkernelConfiguration"><code>KubeProxyWinkernelConfiguration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
winkernel contains winkernel-related configuration options.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>showHiddenMetricsForVersion</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
ShowHiddenMetricsForVersion is the version for which you want to show hidden metrics.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>detectLocalMode</code> <B>[Required]</B><br/>
|
||||
<a href="#kubeproxy-config-k8s-io-v1alpha1-LocalMode"><code>LocalMode</code></a>
|
||||
</td>
|
||||
<td>
|
||||
DetectLocalMode determines mode to use for detecting local traffic, defaults to LocalModeClusterCIDR</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `KubeProxyConntrackConfiguration` {#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConntrackConfiguration}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [KubeProxyConfiguration](#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration)
|
||||
|
||||
|
||||
KubeProxyConntrackConfiguration contains conntrack settings for
|
||||
the Kubernetes proxy server.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>maxPerCore</code> <B>[Required]</B><br/>
|
||||
<code>int32</code>
|
||||
</td>
|
||||
<td>
|
||||
maxPerCore is the maximum number of NAT connections to track
|
||||
per CPU core (0 to leave the limit as-is and ignore min).</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>min</code> <B>[Required]</B><br/>
|
||||
<code>int32</code>
|
||||
</td>
|
||||
<td>
|
||||
min is the minimum value of connect-tracking records to allocate,
|
||||
regardless of conntrackMaxPerCore (set maxPerCore=0 to leave the limit as-is).</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>tcpEstablishedTimeout</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
tcpEstablishedTimeout is how long an idle TCP connection will be kept open
|
||||
(e.g. '2s'). Must be greater than 0 to set.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>tcpCloseWaitTimeout</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
tcpCloseWaitTimeout is how long an idle conntrack entry
|
||||
in CLOSE_WAIT state will remain in the conntrack
|
||||
table. (e.g. '60s'). Must be greater than 0 to set.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `KubeProxyIPTablesConfiguration` {#kubeproxy-config-k8s-io-v1alpha1-KubeProxyIPTablesConfiguration}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [KubeProxyConfiguration](#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration)
|
||||
|
||||
|
||||
KubeProxyIPTablesConfiguration contains iptables-related configuration
|
||||
details for the Kubernetes proxy server.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>masqueradeBit</code> <B>[Required]</B><br/>
|
||||
<code>int32</code>
|
||||
</td>
|
||||
<td>
|
||||
masqueradeBit is the bit of the iptables fwmark space to use for SNAT if using
|
||||
the pure iptables proxy mode. Values must be within the range [0, 31].</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>masqueradeAll</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
masqueradeAll tells kube-proxy to SNAT everything if using the pure iptables proxy mode.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>syncPeriod</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
syncPeriod is the period that iptables rules are refreshed (e.g. '5s', '1m',
|
||||
'2h22m'). Must be greater than 0.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>minSyncPeriod</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
minSyncPeriod is the minimum period that iptables rules are refreshed (e.g. '5s', '1m',
|
||||
'2h22m').</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `KubeProxyIPVSConfiguration` {#kubeproxy-config-k8s-io-v1alpha1-KubeProxyIPVSConfiguration}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [KubeProxyConfiguration](#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration)
|
||||
|
||||
|
||||
KubeProxyIPVSConfiguration contains ipvs-related configuration
|
||||
details for the Kubernetes proxy server.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>syncPeriod</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
syncPeriod is the period that ipvs rules are refreshed (e.g. '5s', '1m',
|
||||
'2h22m'). Must be greater than 0.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>minSyncPeriod</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
minSyncPeriod is the minimum period that ipvs rules are refreshed (e.g. '5s', '1m',
|
||||
'2h22m').</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>scheduler</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
ipvs scheduler</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>excludeCIDRs</code> <B>[Required]</B><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
excludeCIDRs is a list of CIDR's which the ipvs proxier should not touch
|
||||
when cleaning up ipvs services.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>strictARP</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
strict ARP configure arp_ignore and arp_announce to avoid answering ARP queries
|
||||
from kube-ipvs0 interface</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>tcpTimeout</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
tcpTimeout is the timeout value used for idle IPVS TCP sessions.
|
||||
The default value is 0, which preserves the current timeout value on the system.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>tcpFinTimeout</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
tcpFinTimeout is the timeout value used for IPVS TCP sessions after receiving a FIN.
|
||||
The default value is 0, which preserves the current timeout value on the system.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>udpTimeout</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/k8s.io/apimachinery/pkg/apis/meta/v1#Duration"><code>meta/v1.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
udpTimeout is the timeout value used for IPVS UDP packets.
|
||||
The default value is 0, which preserves the current timeout value on the system.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `KubeProxyWinkernelConfiguration` {#kubeproxy-config-k8s-io-v1alpha1-KubeProxyWinkernelConfiguration}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [KubeProxyConfiguration](#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration)
|
||||
|
||||
|
||||
KubeProxyWinkernelConfiguration contains Windows/HNS settings for
|
||||
the Kubernetes proxy server.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>networkName</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
networkName is the name of the network kube-proxy will use
|
||||
to create endpoints and policies</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>sourceVip</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
sourceVip is the IP address of the source VIP endoint used for
|
||||
NAT when loadbalancing</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>enableDSR</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
enableDSR tells kube-proxy whether HNS policies should be created
|
||||
with DSR</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `LocalMode` {#kubeproxy-config-k8s-io-v1alpha1-LocalMode}
|
||||
|
||||
(Alias of `string`)
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [KubeProxyConfiguration](#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration)
|
||||
|
||||
|
||||
LocalMode represents modes to detect local traffic from the node
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
## `ProxyMode` {#kubeproxy-config-k8s-io-v1alpha1-ProxyMode}
|
||||
|
||||
(Alias of `string`)
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [KubeProxyConfiguration](#kubeproxy-config-k8s-io-v1alpha1-KubeProxyConfiguration)
|
||||
|
||||
|
||||
ProxyMode represents modes used by the Kubernetes proxy server.
|
||||
|
||||
Currently, three modes of proxy are available in Linux platform: 'userspace' (older, going to be EOL), 'iptables'
|
||||
(newer, faster), 'ipvs'(newest, better in performance and scalability).
|
||||
|
||||
Two modes of proxy are available in Windows platform: 'userspace'(older, stable) and 'kernelspace' (newer, faster).
|
||||
|
||||
In Linux platform, if proxy mode is blank, use the best-available proxy (currently iptables, but may change in the
|
||||
future). If the iptables proxy is selected, regardless of how, but the system's kernel or iptables versions are
|
||||
insufficient, this always falls back to the userspace proxy. IPVS mode will be enabled when proxy mode is set to 'ipvs',
|
||||
and the fall back path is firstly iptables and then userspace.
|
||||
|
||||
In Windows platform, if proxy mode is blank, use the best-available proxy (currently userspace, but may change in the
|
||||
future). If winkernel proxy is selected, regardless of how, but the Windows kernel can't support this mode of proxy,
|
||||
this always falls back to the userspace proxy.
|
||||
|
||||
|
||||
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,799 @@
|
||||
---
|
||||
title: kube-scheduler Policy Configuration (v1)
|
||||
content_type: tool-reference
|
||||
package: kubescheduler.config.k8s.io/v1
|
||||
auto_generated: true
|
||||
---
|
||||
|
||||
|
||||
## Resource Types
|
||||
|
||||
|
||||
- [Policy](#kubescheduler-config-k8s-io-v1-Policy)
|
||||
|
||||
|
||||
|
||||
|
||||
## `Policy` {#kubescheduler-config-k8s-io-v1-Policy}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Policy describes a struct for a policy resource used in api.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
<tr><td><code>apiVersion</code><br/>string</td><td><code>kubescheduler.config.k8s.io/v1</code></td></tr>
|
||||
<tr><td><code>kind</code><br/>string</td><td><code>Policy</code></td></tr>
|
||||
|
||||
|
||||
|
||||
|
||||
<tr><td><code>predicates</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-PredicatePolicy"><code>[]PredicatePolicy</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Holds the information to configure the fit predicate functions</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>priorities</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-PriorityPolicy"><code>[]PriorityPolicy</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Holds the information to configure the priority functions</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>extenders</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-LegacyExtender"><code>[]LegacyExtender</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Holds the information to communicate with the extender(s)</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>hardPodAffinitySymmetricWeight</code> <B>[Required]</B><br/>
|
||||
<code>int32</code>
|
||||
</td>
|
||||
<td>
|
||||
RequiredDuringScheduling affinity is not symmetric, but there is an implicit PreferredDuringScheduling affinity rule
|
||||
corresponding to every RequiredDuringScheduling affinity rule.
|
||||
HardPodAffinitySymmetricWeight represents the weight of implicit PreferredDuringScheduling affinity rule, in the range 1-100.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>alwaysCheckAllPredicates</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
When AlwaysCheckAllPredicates is set to true, scheduler checks all
|
||||
the configured predicates even after one or more of them fails.
|
||||
When the flag is set to false, scheduler skips checking the rest
|
||||
of the predicates after it finds one predicate that failed.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `ExtenderManagedResource` {#kubescheduler-config-k8s-io-v1-ExtenderManagedResource}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Extender](#kubescheduler-config-k8s-io-v1beta1-Extender)
|
||||
|
||||
- [LegacyExtender](#kubescheduler-config-k8s-io-v1-LegacyExtender)
|
||||
|
||||
|
||||
ExtenderManagedResource describes the arguments of extended resources
|
||||
managed by an extender.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>name</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Name is the extended resource name.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>ignoredByScheduler</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
IgnoredByScheduler indicates whether kube-scheduler should ignore this
|
||||
resource when applying predicates.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `ExtenderTLSConfig` {#kubescheduler-config-k8s-io-v1-ExtenderTLSConfig}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Extender](#kubescheduler-config-k8s-io-v1beta1-Extender)
|
||||
|
||||
- [LegacyExtender](#kubescheduler-config-k8s-io-v1-LegacyExtender)
|
||||
|
||||
|
||||
ExtenderTLSConfig contains settings to enable TLS with extender
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>insecure</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
Server should be accessed without verifying the TLS certificate. For testing only.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>serverName</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
ServerName is passed to the server for SNI and is used in the client to check server
|
||||
certificates against. If ServerName is empty, the hostname used to contact the
|
||||
server is used.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>certFile</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Server requires TLS client certificate authentication</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>keyFile</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Server requires TLS client certificate authentication</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>caFile</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Trusted root certificates for server</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>certData</code> <B>[Required]</B><br/>
|
||||
<code>[]byte</code>
|
||||
</td>
|
||||
<td>
|
||||
CertData holds PEM-encoded bytes (typically read from a client certificate file).
|
||||
CertData takes precedence over CertFile</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>keyData</code> <B>[Required]</B><br/>
|
||||
<code>[]byte</code>
|
||||
</td>
|
||||
<td>
|
||||
KeyData holds PEM-encoded bytes (typically read from a client certificate key file).
|
||||
KeyData takes precedence over KeyFile</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>caData</code> <B>[Required]</B><br/>
|
||||
<code>[]byte</code>
|
||||
</td>
|
||||
<td>
|
||||
CAData holds PEM-encoded bytes (typically read from a root certificates bundle).
|
||||
CAData takes precedence over CAFile</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `LabelPreference` {#kubescheduler-config-k8s-io-v1-LabelPreference}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PriorityArgument](#kubescheduler-config-k8s-io-v1-PriorityArgument)
|
||||
|
||||
|
||||
LabelPreference holds the parameters that are used to configure the corresponding priority function
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>label</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Used to identify node "groups"</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>presence</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
This is a boolean flag
|
||||
If true, higher priority is given to nodes that have the label
|
||||
If false, higher priority is given to nodes that do not have the label</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `LabelsPresence` {#kubescheduler-config-k8s-io-v1-LabelsPresence}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PredicateArgument](#kubescheduler-config-k8s-io-v1-PredicateArgument)
|
||||
|
||||
|
||||
LabelsPresence holds the parameters that are used to configure the corresponding predicate in scheduler policy configuration.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>labels</code> <B>[Required]</B><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
The list of labels that identify node "groups"
|
||||
All of the labels should be either present (or absent) for the node to be considered a fit for hosting the pod</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>presence</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
The boolean flag that indicates whether the labels should be present or absent from the node</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `LegacyExtender` {#kubescheduler-config-k8s-io-v1-LegacyExtender}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Policy](#kubescheduler-config-k8s-io-v1-Policy)
|
||||
|
||||
|
||||
LegacyExtender holds the parameters used to communicate with the extender. If a verb is unspecified/empty,
|
||||
it is assumed that the extender chose not to provide that extension.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>urlPrefix</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
URLPrefix at which the extender is available</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>filterVerb</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Verb for the filter call, empty if not supported. This verb is appended to the URLPrefix when issuing the filter call to extender.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>preemptVerb</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Verb for the preempt call, empty if not supported. This verb is appended to the URLPrefix when issuing the preempt call to extender.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>prioritizeVerb</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Verb for the prioritize call, empty if not supported. This verb is appended to the URLPrefix when issuing the prioritize call to extender.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>weight</code> <B>[Required]</B><br/>
|
||||
<code>int64</code>
|
||||
</td>
|
||||
<td>
|
||||
The numeric multiplier for the node scores that the prioritize call generates.
|
||||
The weight should be a positive integer</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>bindVerb</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Verb for the bind call, empty if not supported. This verb is appended to the URLPrefix when issuing the bind call to extender.
|
||||
If this method is implemented by the extender, it is the extender's responsibility to bind the pod to apiserver. Only one extender
|
||||
can implement this function.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>enableHttps</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
EnableHTTPS specifies whether https should be used to communicate with the extender</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>tlsConfig</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-ExtenderTLSConfig"><code>ExtenderTLSConfig</code></a>
|
||||
</td>
|
||||
<td>
|
||||
TLSConfig specifies the transport layer security config</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>httpTimeout</code> <B>[Required]</B><br/>
|
||||
<a href="https://godoc.org/time#Duration"><code>time.Duration</code></a>
|
||||
</td>
|
||||
<td>
|
||||
HTTPTimeout specifies the timeout duration for a call to the extender. Filter timeout fails the scheduling of the pod. Prioritize
|
||||
timeout is ignored, k8s/other extenders priorities are used to select the node.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>nodeCacheCapable</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
NodeCacheCapable specifies that the extender is capable of caching node information,
|
||||
so the scheduler should only send minimal information about the eligible nodes
|
||||
assuming that the extender already cached full details of all nodes in the cluster</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>managedResources</code><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-ExtenderManagedResource"><code>[]ExtenderManagedResource</code></a>
|
||||
</td>
|
||||
<td>
|
||||
ManagedResources is a list of extended resources that are managed by
|
||||
this extender.
|
||||
- A pod will be sent to the extender on the Filter, Prioritize and Bind
|
||||
(if the extender is the binder) phases iff the pod requests at least
|
||||
one of the extended resources in this list. If empty or unspecified,
|
||||
all pods will be sent to this extender.
|
||||
- If IgnoredByScheduler is set to true for a resource, kube-scheduler
|
||||
will skip checking the resource in predicates.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>ignorable</code> <B>[Required]</B><br/>
|
||||
<code>bool</code>
|
||||
</td>
|
||||
<td>
|
||||
Ignorable specifies if the extender is ignorable, i.e. scheduling should not
|
||||
fail when the extender returns an error or is not reachable.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `PredicateArgument` {#kubescheduler-config-k8s-io-v1-PredicateArgument}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PredicatePolicy](#kubescheduler-config-k8s-io-v1-PredicatePolicy)
|
||||
|
||||
|
||||
PredicateArgument represents the arguments to configure predicate functions in scheduler policy configuration.
|
||||
Only one of its members may be specified
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>serviceAffinity</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-ServiceAffinity"><code>ServiceAffinity</code></a>
|
||||
</td>
|
||||
<td>
|
||||
The predicate that provides affinity for pods belonging to a service
|
||||
It uses a label to identify nodes that belong to the same "group"</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>labelsPresence</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-LabelsPresence"><code>LabelsPresence</code></a>
|
||||
</td>
|
||||
<td>
|
||||
The predicate that checks whether a particular node has a certain label
|
||||
defined or not, regardless of value</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `PredicatePolicy` {#kubescheduler-config-k8s-io-v1-PredicatePolicy}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Policy](#kubescheduler-config-k8s-io-v1-Policy)
|
||||
|
||||
|
||||
PredicatePolicy describes a struct of a predicate policy.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>name</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Identifier of the predicate policy
|
||||
For a custom predicate, the name can be user-defined
|
||||
For the Kubernetes provided predicates, the name is the identifier of the pre-defined predicate</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>argument</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-PredicateArgument"><code>PredicateArgument</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Holds the parameters to configure the given predicate</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `PriorityArgument` {#kubescheduler-config-k8s-io-v1-PriorityArgument}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PriorityPolicy](#kubescheduler-config-k8s-io-v1-PriorityPolicy)
|
||||
|
||||
|
||||
PriorityArgument represents the arguments to configure priority functions in scheduler policy configuration.
|
||||
Only one of its members may be specified
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>serviceAntiAffinity</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-ServiceAntiAffinity"><code>ServiceAntiAffinity</code></a>
|
||||
</td>
|
||||
<td>
|
||||
The priority function that ensures a good spread (anti-affinity) for pods belonging to a service
|
||||
It uses a label to identify nodes that belong to the same "group"</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>labelPreference</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-LabelPreference"><code>LabelPreference</code></a>
|
||||
</td>
|
||||
<td>
|
||||
The priority function that checks whether a particular node has a certain label
|
||||
defined or not, regardless of value</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>requestedToCapacityRatioArguments</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-RequestedToCapacityRatioArguments"><code>RequestedToCapacityRatioArguments</code></a>
|
||||
</td>
|
||||
<td>
|
||||
The RequestedToCapacityRatio priority function is parametrized with function shape.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `PriorityPolicy` {#kubescheduler-config-k8s-io-v1-PriorityPolicy}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [Policy](#kubescheduler-config-k8s-io-v1-Policy)
|
||||
|
||||
|
||||
PriorityPolicy describes a struct of a priority policy.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>name</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Identifier of the priority policy
|
||||
For a custom priority, the name can be user-defined
|
||||
For the Kubernetes provided priority functions, the name is the identifier of the pre-defined priority function</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>weight</code> <B>[Required]</B><br/>
|
||||
<code>int64</code>
|
||||
</td>
|
||||
<td>
|
||||
The numeric multiplier for the node scores that the priority function generates
|
||||
The weight should be non-zero and can be a positive or a negative integer</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>argument</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-PriorityArgument"><code>PriorityArgument</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Holds the parameters to configure the given priority function</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `RequestedToCapacityRatioArguments` {#kubescheduler-config-k8s-io-v1-RequestedToCapacityRatioArguments}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PriorityArgument](#kubescheduler-config-k8s-io-v1-PriorityArgument)
|
||||
|
||||
|
||||
RequestedToCapacityRatioArguments holds arguments specific to RequestedToCapacityRatio priority function.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>shape</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-UtilizationShapePoint"><code>[]UtilizationShapePoint</code></a>
|
||||
</td>
|
||||
<td>
|
||||
Array of point defining priority function shape.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>resources</code> <B>[Required]</B><br/>
|
||||
<a href="#kubescheduler-config-k8s-io-v1-ResourceSpec"><code>[]ResourceSpec</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted">No description provided.</span>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `ResourceSpec` {#kubescheduler-config-k8s-io-v1-ResourceSpec}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [RequestedToCapacityRatioArguments](#kubescheduler-config-k8s-io-v1-RequestedToCapacityRatioArguments)
|
||||
|
||||
|
||||
ResourceSpec represents single resource and weight for bin packing of priority RequestedToCapacityRatioArguments.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>name</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Name of the resource to be managed by RequestedToCapacityRatio function.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>weight</code> <B>[Required]</B><br/>
|
||||
<code>int64</code>
|
||||
</td>
|
||||
<td>
|
||||
Weight of the resource.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `ServiceAffinity` {#kubescheduler-config-k8s-io-v1-ServiceAffinity}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PredicateArgument](#kubescheduler-config-k8s-io-v1-PredicateArgument)
|
||||
|
||||
|
||||
ServiceAffinity holds the parameters that are used to configure the corresponding predicate in scheduler policy configuration.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>labels</code> <B>[Required]</B><br/>
|
||||
<code>[]string</code>
|
||||
</td>
|
||||
<td>
|
||||
The list of labels that identify node "groups"
|
||||
All of the labels should match for the node to be considered a fit for hosting the pod</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `ServiceAntiAffinity` {#kubescheduler-config-k8s-io-v1-ServiceAntiAffinity}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [PriorityArgument](#kubescheduler-config-k8s-io-v1-PriorityArgument)
|
||||
|
||||
|
||||
ServiceAntiAffinity holds the parameters that are used to configure the corresponding priority function
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>label</code> <B>[Required]</B><br/>
|
||||
<code>string</code>
|
||||
</td>
|
||||
<td>
|
||||
Used to identify node "groups"</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
||||
## `UtilizationShapePoint` {#kubescheduler-config-k8s-io-v1-UtilizationShapePoint}
|
||||
|
||||
|
||||
|
||||
|
||||
**Appears in:**
|
||||
|
||||
- [RequestedToCapacityRatioArguments](#kubescheduler-config-k8s-io-v1-RequestedToCapacityRatioArguments)
|
||||
|
||||
|
||||
UtilizationShapePoint represents single point of priority function shape.
|
||||
|
||||
<table class="table">
|
||||
<thead><tr><th width="30%">Field</th><th>Description</th></tr></thead>
|
||||
<tbody>
|
||||
|
||||
|
||||
|
||||
<tr><td><code>utilization</code> <B>[Required]</B><br/>
|
||||
<code>int32</code>
|
||||
</td>
|
||||
<td>
|
||||
Utilization (x axis). Valid values are 0 to 100. Fully utilized node maps to 100.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
<tr><td><code>score</code> <B>[Required]</B><br/>
|
||||
<code>int32</code>
|
||||
</td>
|
||||
<td>
|
||||
Score assigned to given utilization (y axis). Valid values are 0 to 10.</td>
|
||||
</tr>
|
||||
|
||||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -1,4 +0,0 @@
|
||||
---
|
||||
title: "Policies Resources"
|
||||
weight: 6
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Policy Resources"
|
||||
weight: 6
|
||||
---
|
||||
+13
-13
@@ -30,7 +30,7 @@ LimitRange sets resource usage limits for each kind of resource in a Namespace.
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRangeSpec" >}}">LimitRangeSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRangeSpec" >}}">LimitRangeSpec</a>)
|
||||
|
||||
Spec defines the limits enforced. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -95,7 +95,7 @@ LimitRangeList is a list of LimitRange items.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
|
||||
- **items** ([]<a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>), required
|
||||
- **items** ([]<a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>), required
|
||||
|
||||
Items is a list of LimitRange objects. More info: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
|
||||
|
||||
@@ -142,7 +142,7 @@ GET /api/v1/namespaces/{namespace}/limitranges/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -215,7 +215,7 @@ GET /api/v1/namespaces/{namespace}/limitranges
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRangeList" >}}">LimitRangeList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRangeList" >}}">LimitRangeList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -283,7 +283,7 @@ GET /api/v1/limitranges
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRangeList" >}}">LimitRangeList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRangeList" >}}">LimitRangeList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -302,7 +302,7 @@ POST /api/v1/namespaces/{namespace}/limitranges
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -326,11 +326,11 @@ POST /api/v1/namespaces/{namespace}/limitranges
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): Accepted
|
||||
202 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -354,7 +354,7 @@ PUT /api/v1/namespaces/{namespace}/limitranges/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -378,9 +378,9 @@ PUT /api/v1/namespaces/{namespace}/limitranges/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -433,7 +433,7 @@ PATCH /api/v1/namespaces/{namespace}/limitranges/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/limit-range-v1#LimitRange" >}}">LimitRange</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+13
-13
@@ -30,7 +30,7 @@ NetworkPolicy describes what network traffic is allowed for a set of Pods
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicySpec" >}}">NetworkPolicySpec</a>)
|
||||
- **spec** (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicySpec" >}}">NetworkPolicySpec</a>)
|
||||
|
||||
Specification of the desired behavior for this NetworkPolicy.
|
||||
|
||||
@@ -190,7 +190,7 @@ NetworkPolicyList is a list of NetworkPolicy objects.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>), required
|
||||
- **items** ([]<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>), required
|
||||
|
||||
Items is a list of schema objects.
|
||||
|
||||
@@ -237,7 +237,7 @@ GET /apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -310,7 +310,7 @@ GET /apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicyList" >}}">NetworkPolicyList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicyList" >}}">NetworkPolicyList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -378,7 +378,7 @@ GET /apis/networking.k8s.io/v1/networkpolicies
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicyList" >}}">NetworkPolicyList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicyList" >}}">NetworkPolicyList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -397,7 +397,7 @@ POST /apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -421,11 +421,11 @@ POST /apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): Accepted
|
||||
202 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -449,7 +449,7 @@ PUT /apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -473,9 +473,9 @@ PUT /apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -528,7 +528,7 @@ PATCH /apis/networking.k8s.io/v1/namespaces/{namespace}/networkpolicies/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/network-policy-v1#NetworkPolicy" >}}">NetworkPolicy</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+19
-19
@@ -29,11 +29,11 @@ PodDisruptionBudget is an object to define the max disruption that can be caused
|
||||
- **metadata** (<a href="{{< ref "../common-definitions/object-meta#ObjectMeta" >}}">ObjectMeta</a>)
|
||||
|
||||
|
||||
- **spec** (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudgetSpec" >}}">PodDisruptionBudgetSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudgetSpec" >}}">PodDisruptionBudgetSpec</a>)
|
||||
|
||||
Specification of the desired behavior of the PodDisruptionBudget.
|
||||
|
||||
- **status** (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudgetStatus" >}}">PodDisruptionBudgetStatus</a>)
|
||||
- **status** (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudgetStatus" >}}">PodDisruptionBudgetStatus</a>)
|
||||
|
||||
Most recently observed status of the PodDisruptionBudget.
|
||||
|
||||
@@ -121,7 +121,7 @@ PodDisruptionBudgetList is a collection of PodDisruptionBudgets.
|
||||
- **metadata** (<a href="{{< ref "../common-definitions/list-meta#ListMeta" >}}">ListMeta</a>)
|
||||
|
||||
|
||||
- **items** ([]<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>), required
|
||||
- **items** ([]<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>), required
|
||||
|
||||
|
||||
|
||||
@@ -167,7 +167,7 @@ GET /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -200,7 +200,7 @@ GET /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets/{name}/stat
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -273,7 +273,7 @@ GET /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudgetList" >}}">PodDisruptionBudgetList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudgetList" >}}">PodDisruptionBudgetList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -341,7 +341,7 @@ GET /apis/policy/v1beta1/poddisruptionbudgets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudgetList" >}}">PodDisruptionBudgetList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudgetList" >}}">PodDisruptionBudgetList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -360,7 +360,7 @@ POST /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -384,11 +384,11 @@ POST /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): Accepted
|
||||
202 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -412,7 +412,7 @@ PUT /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -436,9 +436,9 @@ PUT /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -462,7 +462,7 @@ PUT /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets/{name}/stat
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -486,9 +486,9 @@ PUT /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets/{name}/stat
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -541,7 +541,7 @@ PATCH /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -594,7 +594,7 @@ PATCH /apis/policy/v1beta1/namespaces/{namespace}/poddisruptionbudgets/{name}/st
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-disruption-budget-v1beta1#PodDisruptionBudget" >}}">PodDisruptionBudget</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+14
-14
@@ -30,7 +30,7 @@ PodSecurityPolicy governs the ability to make requests that affect the Security
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicySpec" >}}">PodSecurityPolicySpec</a>)
|
||||
- **spec** (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicySpec" >}}">PodSecurityPolicySpec</a>)
|
||||
|
||||
spec defines the policy enforced.
|
||||
|
||||
@@ -331,7 +331,7 @@ PodSecurityPolicyList is a list of PodSecurityPolicy objects.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>), required
|
||||
- **items** ([]<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>), required
|
||||
|
||||
items is a list of schema objects.
|
||||
|
||||
@@ -373,7 +373,7 @@ GET /apis/policy/v1beta1/podsecuritypolicies/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -441,7 +441,7 @@ GET /apis/policy/v1beta1/podsecuritypolicies
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicyList" >}}">PodSecurityPolicyList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicyList" >}}">PodSecurityPolicyList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -455,7 +455,7 @@ POST /apis/policy/v1beta1/podsecuritypolicies
|
||||
#### Parameters
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -479,11 +479,11 @@ POST /apis/policy/v1beta1/podsecuritypolicies
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): Accepted
|
||||
202 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -502,7 +502,7 @@ PUT /apis/policy/v1beta1/podsecuritypolicies/{name}
|
||||
name of the PodSecurityPolicy
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -526,9 +526,9 @@ PUT /apis/policy/v1beta1/podsecuritypolicies/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -576,7 +576,7 @@ PATCH /apis/policy/v1beta1/podsecuritypolicies/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -624,9 +624,9 @@ DELETE /apis/policy/v1beta1/podsecuritypolicies/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): OK
|
||||
|
||||
202 (<a href="{{< ref "../policies-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): Accepted
|
||||
202 (<a href="{{< ref "../policy-resources/pod-security-policy-v1beta1#PodSecurityPolicy" >}}">PodSecurityPolicy</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+21
-21
@@ -30,11 +30,11 @@ ResourceQuota sets aggregate quota restrictions enforced per namespace
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuotaSpec" >}}">ResourceQuotaSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuotaSpec" >}}">ResourceQuotaSpec</a>)
|
||||
|
||||
Spec defines the desired quota. https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuotaStatus" >}}">ResourceQuotaStatus</a>)
|
||||
- **status** (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuotaStatus" >}}">ResourceQuotaStatus</a>)
|
||||
|
||||
Status defines the actual enforced quota and its current usage. https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -120,7 +120,7 @@ ResourceQuotaList is a list of ResourceQuota items.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
|
||||
- **items** ([]<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>), required
|
||||
- **items** ([]<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>), required
|
||||
|
||||
Items is a list of ResourceQuota objects. More info: https://kubernetes.io/docs/concepts/policy/resource-quotas/
|
||||
|
||||
@@ -167,7 +167,7 @@ GET /api/v1/namespaces/{namespace}/resourcequotas/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -200,7 +200,7 @@ GET /api/v1/namespaces/{namespace}/resourcequotas/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -273,7 +273,7 @@ GET /api/v1/namespaces/{namespace}/resourcequotas
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuotaList" >}}">ResourceQuotaList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuotaList" >}}">ResourceQuotaList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -341,7 +341,7 @@ GET /api/v1/resourcequotas
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuotaList" >}}">ResourceQuotaList</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuotaList" >}}">ResourceQuotaList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -360,7 +360,7 @@ POST /api/v1/namespaces/{namespace}/resourcequotas
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -384,11 +384,11 @@ POST /api/v1/namespaces/{namespace}/resourcequotas
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Accepted
|
||||
202 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -412,7 +412,7 @@ PUT /api/v1/namespaces/{namespace}/resourcequotas/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -436,9 +436,9 @@ PUT /api/v1/namespaces/{namespace}/resourcequotas/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -462,7 +462,7 @@ PUT /api/v1/namespaces/{namespace}/resourcequotas/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>, required
|
||||
- **body**: <a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -486,9 +486,9 @@ PUT /api/v1/namespaces/{namespace}/resourcequotas/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Created
|
||||
201 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -541,7 +541,7 @@ PATCH /api/v1/namespaces/{namespace}/resourcequotas/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -594,7 +594,7 @@ PATCH /api/v1/namespaces/{namespace}/resourcequotas/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -647,9 +647,9 @@ DELETE /api/v1/namespaces/{namespace}/resourcequotas/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
200 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): OK
|
||||
|
||||
202 (<a href="{{< ref "../policies-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Accepted
|
||||
202 (<a href="{{< ref "../policy-resources/resource-quota-v1#ResourceQuota" >}}">ResourceQuota</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Service Resources"
|
||||
weight: 2
|
||||
---
|
||||
+12
-12
@@ -136,7 +136,7 @@ EndpointSliceList represents a list of endpoint slices
|
||||
|
||||
Standard list metadata.
|
||||
|
||||
- **items** ([]<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>), required
|
||||
- **items** ([]<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>), required
|
||||
|
||||
List of endpoint slices
|
||||
|
||||
@@ -183,7 +183,7 @@ GET /apis/discovery.k8s.io/v1beta1/namespaces/{namespace}/endpointslices/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -256,7 +256,7 @@ GET /apis/discovery.k8s.io/v1beta1/namespaces/{namespace}/endpointslices
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSliceList" >}}">EndpointSliceList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSliceList" >}}">EndpointSliceList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -324,7 +324,7 @@ GET /apis/discovery.k8s.io/v1beta1/endpointslices
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSliceList" >}}">EndpointSliceList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSliceList" >}}">EndpointSliceList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -343,7 +343,7 @@ POST /apis/discovery.k8s.io/v1beta1/namespaces/{namespace}/endpointslices
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -367,11 +367,11 @@ POST /apis/discovery.k8s.io/v1beta1/namespaces/{namespace}/endpointslices
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): Accepted
|
||||
202 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -395,7 +395,7 @@ PUT /apis/discovery.k8s.io/v1beta1/namespaces/{namespace}/endpointslices/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -419,9 +419,9 @@ PUT /apis/discovery.k8s.io/v1beta1/namespaces/{namespace}/endpointslices/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -474,7 +474,7 @@ PATCH /apis/discovery.k8s.io/v1beta1/namespaces/{namespace}/endpointslices/{name
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoint-slice-v1beta1#EndpointSlice" >}}">EndpointSlice</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+12
-12
@@ -144,7 +144,7 @@ EndpointsList is a list of endpoints.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
|
||||
- **items** ([]<a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>), required
|
||||
- **items** ([]<a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>), required
|
||||
|
||||
List of endpoints.
|
||||
|
||||
@@ -191,7 +191,7 @@ GET /api/v1/namespaces/{namespace}/endpoints/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -264,7 +264,7 @@ GET /api/v1/namespaces/{namespace}/endpoints
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoints-v1#EndpointsList" >}}">EndpointsList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoints-v1#EndpointsList" >}}">EndpointsList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -332,7 +332,7 @@ GET /api/v1/endpoints
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoints-v1#EndpointsList" >}}">EndpointsList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoints-v1#EndpointsList" >}}">EndpointsList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -351,7 +351,7 @@ POST /api/v1/namespaces/{namespace}/endpoints
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -375,11 +375,11 @@ POST /api/v1/namespaces/{namespace}/endpoints
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): Accepted
|
||||
202 (<a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -403,7 +403,7 @@ PUT /api/v1/namespaces/{namespace}/endpoints/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -427,9 +427,9 @@ PUT /api/v1/namespaces/{namespace}/endpoints/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -482,7 +482,7 @@ PATCH /api/v1/namespaces/{namespace}/endpoints/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/endpoints-v1#Endpoints" >}}">Endpoints</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+12
-12
@@ -30,7 +30,7 @@ IngressClass represents the class of the Ingress, referenced by the Ingress Spec
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClassSpec" >}}">IngressClassSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClassSpec" >}}">IngressClassSpec</a>)
|
||||
|
||||
Spec is the desired state of the IngressClass. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -72,7 +72,7 @@ IngressClassList is a collection of IngressClasses.
|
||||
|
||||
Standard list metadata.
|
||||
|
||||
- **items** ([]<a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>), required
|
||||
- **items** ([]<a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>), required
|
||||
|
||||
Items is the list of IngressClasses.
|
||||
|
||||
@@ -114,7 +114,7 @@ GET /apis/networking.k8s.io/v1/ingressclasses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -182,7 +182,7 @@ GET /apis/networking.k8s.io/v1/ingressclasses
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClassList" >}}">IngressClassList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClassList" >}}">IngressClassList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -196,7 +196,7 @@ POST /apis/networking.k8s.io/v1/ingressclasses
|
||||
#### Parameters
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -220,11 +220,11 @@ POST /apis/networking.k8s.io/v1/ingressclasses
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): Accepted
|
||||
202 (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -243,7 +243,7 @@ PUT /apis/networking.k8s.io/v1/ingressclasses/{name}
|
||||
name of the IngressClass
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -267,9 +267,9 @@ PUT /apis/networking.k8s.io/v1/ingressclasses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -317,7 +317,7 @@ PATCH /apis/networking.k8s.io/v1/ingressclasses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-class-v1#IngressClass" >}}">IngressClass</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+19
-19
@@ -30,11 +30,11 @@ Ingress is a collection of rules that allow inbound connections to reach the end
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../services-resources/ingress-v1#IngressSpec" >}}">IngressSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../service-resources/ingress-v1#IngressSpec" >}}">IngressSpec</a>)
|
||||
|
||||
Spec is the desired state of the Ingress. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../services-resources/ingress-v1#IngressStatus" >}}">IngressStatus</a>)
|
||||
- **status** (<a href="{{< ref "../service-resources/ingress-v1#IngressStatus" >}}">IngressStatus</a>)
|
||||
|
||||
Status is the current state of the Ingress. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -274,7 +274,7 @@ IngressList is a collection of Ingress.
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>), required
|
||||
- **items** ([]<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>), required
|
||||
|
||||
Items is the list of Ingress.
|
||||
|
||||
@@ -321,7 +321,7 @@ GET /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -354,7 +354,7 @@ GET /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -427,7 +427,7 @@ GET /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#IngressList" >}}">IngressList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#IngressList" >}}">IngressList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -495,7 +495,7 @@ GET /apis/networking.k8s.io/v1/ingresses
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#IngressList" >}}">IngressList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#IngressList" >}}">IngressList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -514,7 +514,7 @@ POST /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -538,11 +538,11 @@ POST /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): Accepted
|
||||
202 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -566,7 +566,7 @@ PUT /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -590,9 +590,9 @@ PUT /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -616,7 +616,7 @@ PUT /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -640,9 +640,9 @@ PUT /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -695,7 +695,7 @@ PATCH /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -748,7 +748,7 @@ PATCH /apis/networking.k8s.io/v1/namespaces/{namespace}/ingresses/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/ingress-v1#Ingress" >}}">Ingress</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+19
-19
@@ -30,11 +30,11 @@ Service is a named abstraction of software service (for example, mysql) consisti
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../services-resources/service-v1#ServiceSpec" >}}">ServiceSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../service-resources/service-v1#ServiceSpec" >}}">ServiceSpec</a>)
|
||||
|
||||
Spec defines the behavior of a service. https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../services-resources/service-v1#ServiceStatus" >}}">ServiceStatus</a>)
|
||||
- **status** (<a href="{{< ref "../service-resources/service-v1#ServiceStatus" >}}">ServiceStatus</a>)
|
||||
|
||||
Most recently observed status of the service. Populated by the system. Read-only. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -290,7 +290,7 @@ ServiceList holds a list of services.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
|
||||
- **items** ([]<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>), required
|
||||
- **items** ([]<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>), required
|
||||
|
||||
List of services
|
||||
|
||||
@@ -337,7 +337,7 @@ GET /api/v1/namespaces/{namespace}/services/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -370,7 +370,7 @@ GET /api/v1/namespaces/{namespace}/services/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -443,7 +443,7 @@ GET /api/v1/namespaces/{namespace}/services
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#ServiceList" >}}">ServiceList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#ServiceList" >}}">ServiceList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -511,7 +511,7 @@ GET /api/v1/services
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#ServiceList" >}}">ServiceList</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#ServiceList" >}}">ServiceList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -530,7 +530,7 @@ POST /api/v1/namespaces/{namespace}/services
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -554,11 +554,11 @@ POST /api/v1/namespaces/{namespace}/services
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): Accepted
|
||||
202 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -582,7 +582,7 @@ PUT /api/v1/namespaces/{namespace}/services/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -606,9 +606,9 @@ PUT /api/v1/namespaces/{namespace}/services/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -632,7 +632,7 @@ PUT /api/v1/namespaces/{namespace}/services/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>, required
|
||||
- **body**: <a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -656,9 +656,9 @@ PUT /api/v1/namespaces/{namespace}/services/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): Created
|
||||
201 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -711,7 +711,7 @@ PATCH /api/v1/namespaces/{namespace}/services/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -764,7 +764,7 @@ PATCH /api/v1/namespaces/{namespace}/services/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../services-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
200 (<a href="{{< ref "../service-resources/service-v1#Service" >}}">Service</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -1,4 +0,0 @@
|
||||
---
|
||||
title: "Services Resources"
|
||||
weight: 2
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
title: "Workload Resources"
|
||||
weight: 1
|
||||
---
|
||||
+12
-12
@@ -88,7 +88,7 @@ ControllerRevisionList is a resource containing a list of ControllerRevision obj
|
||||
|
||||
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>), required
|
||||
|
||||
Items is the list of ControllerRevisions
|
||||
|
||||
@@ -135,7 +135,7 @@ GET /apis/apps/v1/namespaces/{namespace}/controllerrevisions/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -208,7 +208,7 @@ GET /apis/apps/v1/namespaces/{namespace}/controllerrevisions
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevisionList" >}}">ControllerRevisionList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevisionList" >}}">ControllerRevisionList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -276,7 +276,7 @@ GET /apis/apps/v1/controllerrevisions
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevisionList" >}}">ControllerRevisionList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevisionList" >}}">ControllerRevisionList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -295,7 +295,7 @@ POST /apis/apps/v1/namespaces/{namespace}/controllerrevisions
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -319,11 +319,11 @@ POST /apis/apps/v1/namespaces/{namespace}/controllerrevisions
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -347,7 +347,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/controllerrevisions/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -371,9 +371,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/controllerrevisions/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -426,7 +426,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/controllerrevisions/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/controller-revision-v1#ControllerRevision" >}}">ControllerRevision</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+20
-20
@@ -30,11 +30,11 @@ CronJob represents the configuration of a single cron job.
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJobSpec" >}}">CronJobSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJobSpec" >}}">CronJobSpec</a>)
|
||||
|
||||
Specification of the desired behavior of a cron job, including the schedule. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJobStatus" >}}">CronJobStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJobStatus" >}}">CronJobStatus</a>)
|
||||
|
||||
Current status of a cron job. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -59,7 +59,7 @@ CronJobSpec describes how the job execution will look like and when it will actu
|
||||
|
||||
Standard object's metadata of the jobs created from this template. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **jobTemplate.spec** (<a href="{{< ref "../workloads-resources/job-v1#JobSpec" >}}">JobSpec</a>)
|
||||
- **jobTemplate.spec** (<a href="{{< ref "../workload-resources/job-v1#JobSpec" >}}">JobSpec</a>)
|
||||
|
||||
Specification of the desired behavior of the job. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -128,7 +128,7 @@ CronJobList is a collection of cron jobs.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>), required
|
||||
|
||||
items is the list of CronJobs.
|
||||
|
||||
@@ -175,7 +175,7 @@ GET /apis/batch/v1beta1/namespaces/{namespace}/cronjobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -208,7 +208,7 @@ GET /apis/batch/v1beta1/namespaces/{namespace}/cronjobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -281,7 +281,7 @@ GET /apis/batch/v1beta1/namespaces/{namespace}/cronjobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJobList" >}}">CronJobList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJobList" >}}">CronJobList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -349,7 +349,7 @@ GET /apis/batch/v1beta1/cronjobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJobList" >}}">CronJobList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJobList" >}}">CronJobList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -368,7 +368,7 @@ POST /apis/batch/v1beta1/namespaces/{namespace}/cronjobs
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -392,11 +392,11 @@ POST /apis/batch/v1beta1/namespaces/{namespace}/cronjobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -420,7 +420,7 @@ PUT /apis/batch/v1beta1/namespaces/{namespace}/cronjobs/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -444,9 +444,9 @@ PUT /apis/batch/v1beta1/namespaces/{namespace}/cronjobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -470,7 +470,7 @@ PUT /apis/batch/v1beta1/namespaces/{namespace}/cronjobs/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -494,9 +494,9 @@ PUT /apis/batch/v1beta1/namespaces/{namespace}/cronjobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -549,7 +549,7 @@ PATCH /apis/batch/v1beta1/namespaces/{namespace}/cronjobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -602,7 +602,7 @@ PATCH /apis/batch/v1beta1/namespaces/{namespace}/cronjobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v1beta1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+20
-20
@@ -30,11 +30,11 @@ CronJob represents the configuration of a single cron job.
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJobSpec" >}}">CronJobSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJobSpec" >}}">CronJobSpec</a>)
|
||||
|
||||
Specification of the desired behavior of a cron job, including the schedule. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJobStatus" >}}">CronJobStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJobStatus" >}}">CronJobStatus</a>)
|
||||
|
||||
Current status of a cron job. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -59,7 +59,7 @@ CronJobSpec describes how the job execution will look like and when it will actu
|
||||
|
||||
Standard object's metadata of the jobs created from this template. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **jobTemplate.spec** (<a href="{{< ref "../workloads-resources/job-v1#JobSpec" >}}">JobSpec</a>)
|
||||
- **jobTemplate.spec** (<a href="{{< ref "../workload-resources/job-v1#JobSpec" >}}">JobSpec</a>)
|
||||
|
||||
Specification of the desired behavior of the job. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -128,7 +128,7 @@ CronJobList is a collection of cron jobs.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>), required
|
||||
|
||||
items is the list of CronJobs.
|
||||
|
||||
@@ -175,7 +175,7 @@ GET /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -208,7 +208,7 @@ GET /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -281,7 +281,7 @@ GET /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJobList" >}}">CronJobList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJobList" >}}">CronJobList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -349,7 +349,7 @@ GET /apis/batch/v2alpha1/cronjobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJobList" >}}">CronJobList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJobList" >}}">CronJobList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -368,7 +368,7 @@ POST /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -392,11 +392,11 @@ POST /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -420,7 +420,7 @@ PUT /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -444,9 +444,9 @@ PUT /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -470,7 +470,7 @@ PUT /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -494,9 +494,9 @@ PUT /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -549,7 +549,7 @@ PATCH /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -602,7 +602,7 @@ PATCH /apis/batch/v2alpha1/namespaces/{namespace}/cronjobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/cron-job-v2alpha1#CronJob" >}}">CronJob</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+20
-20
@@ -30,11 +30,11 @@ DaemonSet represents the configuration of a daemon set.
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSetSpec" >}}">DaemonSetSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSetSpec" >}}">DaemonSetSpec</a>)
|
||||
|
||||
The desired behavior of this daemon set. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSetStatus" >}}">DaemonSetStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSetStatus" >}}">DaemonSetStatus</a>)
|
||||
|
||||
The current status of this daemon set. This data may be out of date by some window of time. Populated by the system. Read-only. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -52,7 +52,7 @@ DaemonSetSpec is the specification of a daemon set.
|
||||
|
||||
A label query over pods that are managed by the daemon set. Must match in order to be controlled. It must match the pod template's labels. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#label-selectors
|
||||
|
||||
- **template** (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>), required
|
||||
- **template** (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>), required
|
||||
|
||||
An object that describes the pod that will be created. The DaemonSet will create exactly one copy of this pod on every node that matches the template's node selector (or on every node if no node selector is specified). More info: https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#pod-template
|
||||
|
||||
@@ -187,7 +187,7 @@ DaemonSetList is a collection of daemon sets.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>), required
|
||||
|
||||
A list of daemon sets.
|
||||
|
||||
@@ -234,7 +234,7 @@ GET /apis/apps/v1/namespaces/{namespace}/daemonsets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -267,7 +267,7 @@ GET /apis/apps/v1/namespaces/{namespace}/daemonsets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -340,7 +340,7 @@ GET /apis/apps/v1/namespaces/{namespace}/daemonsets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSetList" >}}">DaemonSetList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSetList" >}}">DaemonSetList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -408,7 +408,7 @@ GET /apis/apps/v1/daemonsets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSetList" >}}">DaemonSetList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSetList" >}}">DaemonSetList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -427,7 +427,7 @@ POST /apis/apps/v1/namespaces/{namespace}/daemonsets
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -451,11 +451,11 @@ POST /apis/apps/v1/namespaces/{namespace}/daemonsets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -479,7 +479,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/daemonsets/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -503,9 +503,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/daemonsets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -529,7 +529,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/daemonsets/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -553,9 +553,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/daemonsets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -608,7 +608,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/daemonsets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -661,7 +661,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/daemonsets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/daemon-set-v1#DaemonSet" >}}">DaemonSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+20
-20
@@ -30,11 +30,11 @@ Deployment enables declarative updates for Pods and ReplicaSets.
|
||||
|
||||
Standard object metadata.
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/deployment-v1#DeploymentSpec" >}}">DeploymentSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/deployment-v1#DeploymentSpec" >}}">DeploymentSpec</a>)
|
||||
|
||||
Specification of the desired behavior of the Deployment.
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/deployment-v1#DeploymentStatus" >}}">DeploymentStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/deployment-v1#DeploymentStatus" >}}">DeploymentStatus</a>)
|
||||
|
||||
Most recently observed status of the Deployment.
|
||||
|
||||
@@ -52,7 +52,7 @@ DeploymentSpec is the specification of the desired behavior of the Deployment.
|
||||
|
||||
Label selector for pods. Existing ReplicaSets whose pods are selected by this will be the ones affected by this deployment. It must match the pod template's labels.
|
||||
|
||||
- **template** (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>), required
|
||||
- **template** (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>), required
|
||||
|
||||
Template describes the pods that will be created.
|
||||
|
||||
@@ -207,7 +207,7 @@ DeploymentList is a list of Deployments.
|
||||
|
||||
Standard list metadata.
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>), required
|
||||
|
||||
Items is the list of Deployments.
|
||||
|
||||
@@ -254,7 +254,7 @@ GET /apis/apps/v1/namespaces/{namespace}/deployments/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -287,7 +287,7 @@ GET /apis/apps/v1/namespaces/{namespace}/deployments/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -360,7 +360,7 @@ GET /apis/apps/v1/namespaces/{namespace}/deployments
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#DeploymentList" >}}">DeploymentList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#DeploymentList" >}}">DeploymentList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -428,7 +428,7 @@ GET /apis/apps/v1/deployments
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#DeploymentList" >}}">DeploymentList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#DeploymentList" >}}">DeploymentList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -447,7 +447,7 @@ POST /apis/apps/v1/namespaces/{namespace}/deployments
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -471,11 +471,11 @@ POST /apis/apps/v1/namespaces/{namespace}/deployments
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -499,7 +499,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/deployments/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -523,9 +523,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/deployments/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -549,7 +549,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/deployments/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -573,9 +573,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/deployments/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -628,7 +628,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/deployments/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -681,7 +681,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/deployments/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/deployment-v1#Deployment" >}}">Deployment</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+19
-19
@@ -30,11 +30,11 @@ configuration of a horizontal pod autoscaler.
|
||||
|
||||
Standard object metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscalerSpec" >}}">HorizontalPodAutoscalerSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscalerSpec" >}}">HorizontalPodAutoscalerSpec</a>)
|
||||
|
||||
behaviour of autoscaler. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status.
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscalerStatus" >}}">HorizontalPodAutoscalerStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscalerStatus" >}}">HorizontalPodAutoscalerStatus</a>)
|
||||
|
||||
current information about the autoscaler.
|
||||
|
||||
@@ -132,7 +132,7 @@ list of horizontal pod autoscaler objects.
|
||||
|
||||
Standard list metadata.
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>), required
|
||||
|
||||
list of horizontal pod autoscaler objects.
|
||||
|
||||
@@ -179,7 +179,7 @@ GET /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -212,7 +212,7 @@ GET /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers/{name}/
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -285,7 +285,7 @@ GET /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscalerList" >}}">HorizontalPodAutoscalerList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscalerList" >}}">HorizontalPodAutoscalerList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -353,7 +353,7 @@ GET /apis/autoscaling/v1/horizontalpodautoscalers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscalerList" >}}">HorizontalPodAutoscalerList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscalerList" >}}">HorizontalPodAutoscalerList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -372,7 +372,7 @@ POST /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -396,11 +396,11 @@ POST /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -424,7 +424,7 @@ PUT /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -448,9 +448,9 @@ PUT /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -474,7 +474,7 @@ PUT /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers/{name}/
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -498,9 +498,9 @@ PUT /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers/{name}/
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -553,7 +553,7 @@ PATCH /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers/{name
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -606,7 +606,7 @@ PATCH /apis/autoscaling/v1/namespaces/{namespace}/horizontalpodautoscalers/{name
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v1#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+19
-19
@@ -30,11 +30,11 @@ HorizontalPodAutoscaler is the configuration for a horizontal pod autoscaler, wh
|
||||
|
||||
metadata is the standard object metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscalerSpec" >}}">HorizontalPodAutoscalerSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscalerSpec" >}}">HorizontalPodAutoscalerSpec</a>)
|
||||
|
||||
spec is the specification for the behaviour of the autoscaler. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status.
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscalerStatus" >}}">HorizontalPodAutoscalerStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscalerStatus" >}}">HorizontalPodAutoscalerStatus</a>)
|
||||
|
||||
status is the current information about the autoscaler.
|
||||
|
||||
@@ -684,7 +684,7 @@ HorizontalPodAutoscalerList is a list of horizontal pod autoscaler objects.
|
||||
|
||||
metadata is the standard list metadata.
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>), required
|
||||
|
||||
items is the list of horizontal pod autoscaler objects.
|
||||
|
||||
@@ -731,7 +731,7 @@ GET /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers/{n
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -764,7 +764,7 @@ GET /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers/{n
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -837,7 +837,7 @@ GET /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscalerList" >}}">HorizontalPodAutoscalerList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscalerList" >}}">HorizontalPodAutoscalerList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -905,7 +905,7 @@ GET /apis/autoscaling/v2beta2/horizontalpodautoscalers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscalerList" >}}">HorizontalPodAutoscalerList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscalerList" >}}">HorizontalPodAutoscalerList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -924,7 +924,7 @@ POST /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -948,11 +948,11 @@ POST /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -976,7 +976,7 @@ PUT /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers/{n
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -1000,9 +1000,9 @@ PUT /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers/{n
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -1026,7 +1026,7 @@ PUT /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers/{n
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -1050,9 +1050,9 @@ PUT /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers/{n
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -1105,7 +1105,7 @@ PATCH /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers/
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -1158,7 +1158,7 @@ PATCH /apis/autoscaling/v2beta2/namespaces/{namespace}/horizontalpodautoscalers/
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/horizontal-pod-autoscaler-v2beta2#HorizontalPodAutoscaler" >}}">HorizontalPodAutoscaler</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+20
-20
@@ -30,11 +30,11 @@ Job represents the configuration of a single job.
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/job-v1#JobSpec" >}}">JobSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/job-v1#JobSpec" >}}">JobSpec</a>)
|
||||
|
||||
Specification of the desired behavior of a job. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/job-v1#JobStatus" >}}">JobStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/job-v1#JobStatus" >}}">JobStatus</a>)
|
||||
|
||||
Current status of a job. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -53,7 +53,7 @@ JobSpec describes how the job execution will look like.
|
||||
### Replicas
|
||||
|
||||
|
||||
- **template** (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>), required
|
||||
- **template** (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>), required
|
||||
|
||||
Describes the pod that will be created when executing a job. More info: https://kubernetes.io/docs/concepts/workloads/controllers/jobs-run-to-completion/
|
||||
|
||||
@@ -184,7 +184,7 @@ JobList is a collection of jobs.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>), required
|
||||
|
||||
items is the list of Jobs.
|
||||
|
||||
@@ -231,7 +231,7 @@ GET /apis/batch/v1/namespaces/{namespace}/jobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -264,7 +264,7 @@ GET /apis/batch/v1/namespaces/{namespace}/jobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -337,7 +337,7 @@ GET /apis/batch/v1/namespaces/{namespace}/jobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#JobList" >}}">JobList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#JobList" >}}">JobList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -405,7 +405,7 @@ GET /apis/batch/v1/jobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#JobList" >}}">JobList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#JobList" >}}">JobList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -424,7 +424,7 @@ POST /apis/batch/v1/namespaces/{namespace}/jobs
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -448,11 +448,11 @@ POST /apis/batch/v1/namespaces/{namespace}/jobs
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -476,7 +476,7 @@ PUT /apis/batch/v1/namespaces/{namespace}/jobs/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -500,9 +500,9 @@ PUT /apis/batch/v1/namespaces/{namespace}/jobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -526,7 +526,7 @@ PUT /apis/batch/v1/namespaces/{namespace}/jobs/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -550,9 +550,9 @@ PUT /apis/batch/v1/namespaces/{namespace}/jobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -605,7 +605,7 @@ PATCH /apis/batch/v1/namespaces/{namespace}/jobs/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -658,7 +658,7 @@ PATCH /apis/batch/v1/namespaces/{namespace}/jobs/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/job-v1#Job" >}}">Job</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+16
-16
@@ -30,7 +30,7 @@ PodTemplate describes a template for creating copies of a predefined pod.
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **template** (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>)
|
||||
- **template** (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>)
|
||||
|
||||
Template defines the pods that will be created from this pod template. https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -48,7 +48,7 @@ PodTemplateSpec describes the data a pod should have when created from a templat
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/pod-v1#PodSpec" >}}">PodSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/pod-v1#PodSpec" >}}">PodSpec</a>)
|
||||
|
||||
Specification of the desired behavior of the pod. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -72,7 +72,7 @@ PodTemplateList is a list of PodTemplates.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>), required
|
||||
|
||||
List of pod templates
|
||||
|
||||
@@ -119,7 +119,7 @@ GET /api/v1/namespaces/{namespace}/podtemplates/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -192,7 +192,7 @@ GET /api/v1/namespaces/{namespace}/podtemplates
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateList" >}}">PodTemplateList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateList" >}}">PodTemplateList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -260,7 +260,7 @@ GET /api/v1/podtemplates
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateList" >}}">PodTemplateList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateList" >}}">PodTemplateList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -279,7 +279,7 @@ POST /api/v1/namespaces/{namespace}/podtemplates
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -303,11 +303,11 @@ POST /api/v1/namespaces/{namespace}/podtemplates
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -331,7 +331,7 @@ PUT /api/v1/namespaces/{namespace}/podtemplates/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -355,9 +355,9 @@ PUT /api/v1/namespaces/{namespace}/podtemplates/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -410,7 +410,7 @@ PATCH /api/v1/namespaces/{namespace}/podtemplates/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -463,9 +463,9 @@ DELETE /api/v1/namespaces/{namespace}/podtemplates/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): OK
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplate" >}}">PodTemplate</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+27
-27
@@ -30,11 +30,11 @@ Pod is a collection of containers that can run on a host. This resource is creat
|
||||
|
||||
Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/pod-v1#PodSpec" >}}">PodSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/pod-v1#PodSpec" >}}">PodSpec</a>)
|
||||
|
||||
Specification of the desired behavior of the pod. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/pod-v1#PodStatus" >}}">PodStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/pod-v1#PodStatus" >}}">PodStatus</a>)
|
||||
|
||||
Most recently observed status of the pod. This data may not be up to date. Populated by the system. Read-only. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -53,13 +53,13 @@ PodSpec is a description of a pod.
|
||||
### Containers
|
||||
|
||||
|
||||
- **containers** ([]<a href="{{< ref "../workloads-resources/container#Container" >}}">Container</a>), required
|
||||
- **containers** ([]<a href="{{< ref "../workload-resources/container#Container" >}}">Container</a>), required
|
||||
|
||||
*Patch strategy: merge on key `name`*
|
||||
|
||||
List of containers belonging to the pod. Containers cannot currently be added or removed. There must be at least one container in a Pod. Cannot be updated.
|
||||
|
||||
- **initContainers** ([]<a href="{{< ref "../workloads-resources/container#Container" >}}">Container</a>)
|
||||
- **initContainers** ([]<a href="{{< ref "../workload-resources/container#Container" >}}">Container</a>)
|
||||
|
||||
*Patch strategy: merge on key `name`*
|
||||
|
||||
@@ -430,7 +430,7 @@ PodSpec is a description of a pod.
|
||||
### Alpha level
|
||||
|
||||
|
||||
- **ephemeralContainers** ([]<a href="{{< ref "../workloads-resources/ephemeral-container#EphemeralContainer" >}}">EphemeralContainer</a>)
|
||||
- **ephemeralContainers** ([]<a href="{{< ref "../workload-resources/ephemeral-container#EphemeralContainer" >}}">EphemeralContainer</a>)
|
||||
|
||||
*Patch strategy: merge on key `name`*
|
||||
|
||||
@@ -547,15 +547,15 @@ PodStatus represents information about the status of a pod. Status may trail the
|
||||
|
||||
The Quality of Service (QOS) classification assigned to the pod based on resource requirements See PodQOSClass type for available QOS classes More info: https://git.k8s.io/community/contributors/design-proposals/node/resource-qos.md
|
||||
|
||||
- **initContainerStatuses** ([]<a href="{{< ref "../workloads-resources/container#ContainerStatus" >}}">ContainerStatus</a>)
|
||||
- **initContainerStatuses** ([]<a href="{{< ref "../workload-resources/container#ContainerStatus" >}}">ContainerStatus</a>)
|
||||
|
||||
The list has one entry per init container in the manifest. The most recent successful init container will have ready = true, the most recently started container will have startTime set. More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-and-container-status
|
||||
|
||||
- **containerStatuses** ([]<a href="{{< ref "../workloads-resources/container#ContainerStatus" >}}">ContainerStatus</a>)
|
||||
- **containerStatuses** ([]<a href="{{< ref "../workload-resources/container#ContainerStatus" >}}">ContainerStatus</a>)
|
||||
|
||||
The list has one entry per container in the manifest. Each entry is currently the output of `docker inspect`. More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#pod-and-container-status
|
||||
|
||||
- **ephemeralContainerStatuses** ([]<a href="{{< ref "../workloads-resources/container#ContainerStatus" >}}">ContainerStatus</a>)
|
||||
- **ephemeralContainerStatuses** ([]<a href="{{< ref "../workload-resources/container#ContainerStatus" >}}">ContainerStatus</a>)
|
||||
|
||||
Status for any ephemeral containers that have run in this pod. This field is alpha-level and is only populated by servers that enable the EphemeralContainers feature.
|
||||
|
||||
@@ -579,7 +579,7 @@ PodList is a list of Pods.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>), required
|
||||
|
||||
List of pods. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
|
||||
|
||||
@@ -626,7 +626,7 @@ GET /api/v1/namespaces/{namespace}/pods/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -732,7 +732,7 @@ GET /api/v1/namespaces/{namespace}/pods/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -805,7 +805,7 @@ GET /api/v1/namespaces/{namespace}/pods
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#PodList" >}}">PodList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#PodList" >}}">PodList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -873,7 +873,7 @@ GET /api/v1/pods
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#PodList" >}}">PodList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#PodList" >}}">PodList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -892,7 +892,7 @@ POST /api/v1/namespaces/{namespace}/pods
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -916,11 +916,11 @@ POST /api/v1/namespaces/{namespace}/pods
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -944,7 +944,7 @@ PUT /api/v1/namespaces/{namespace}/pods/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -968,9 +968,9 @@ PUT /api/v1/namespaces/{namespace}/pods/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -994,7 +994,7 @@ PUT /api/v1/namespaces/{namespace}/pods/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -1018,9 +1018,9 @@ PUT /api/v1/namespaces/{namespace}/pods/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -1073,7 +1073,7 @@ PATCH /api/v1/namespaces/{namespace}/pods/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -1126,7 +1126,7 @@ PATCH /api/v1/namespaces/{namespace}/pods/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -1179,9 +1179,9 @@ DELETE /api/v1/namespaces/{namespace}/pods/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): OK
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/pod-v1#Pod" >}}">Pod</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/pod-v1#Pod" >}}">Pod</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+11
-11
@@ -66,7 +66,7 @@ PriorityClassList is a collection of priority classes.
|
||||
|
||||
Standard list metadata More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>), required
|
||||
|
||||
items is the list of PriorityClasses
|
||||
|
||||
@@ -108,7 +108,7 @@ GET /apis/scheduling.k8s.io/v1/priorityclasses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -176,7 +176,7 @@ GET /apis/scheduling.k8s.io/v1/priorityclasses
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClassList" >}}">PriorityClassList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClassList" >}}">PriorityClassList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -190,7 +190,7 @@ POST /apis/scheduling.k8s.io/v1/priorityclasses
|
||||
#### Parameters
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -214,11 +214,11 @@ POST /apis/scheduling.k8s.io/v1/priorityclasses
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -237,7 +237,7 @@ PUT /apis/scheduling.k8s.io/v1/priorityclasses/{name}
|
||||
name of the PriorityClass
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -261,9 +261,9 @@ PUT /apis/scheduling.k8s.io/v1/priorityclasses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -311,7 +311,7 @@ PATCH /apis/scheduling.k8s.io/v1/priorityclasses/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/priority-class-v1#PriorityClass" >}}">PriorityClass</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+20
-20
@@ -30,11 +30,11 @@ ReplicaSet ensures that a specified number of pod replicas are running at any gi
|
||||
|
||||
If the Labels of a ReplicaSet are empty, they are defaulted to be the same as the Pod(s) that the ReplicaSet manages. Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSetSpec" >}}">ReplicaSetSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSetSpec" >}}">ReplicaSetSpec</a>)
|
||||
|
||||
Spec defines the specification of the desired behavior of the ReplicaSet. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSetStatus" >}}">ReplicaSetStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSetStatus" >}}">ReplicaSetStatus</a>)
|
||||
|
||||
Status is the most recently observed status of the ReplicaSet. This data may be out of date by some window of time. Populated by the system. Read-only. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -52,7 +52,7 @@ ReplicaSetSpec is the specification of a ReplicaSet.
|
||||
|
||||
Selector is a label query over pods that should match the replica count. Label keys and values that must match in order to be controlled by this replica set. It must match the pod template's labels. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#label-selectors
|
||||
|
||||
- **template** (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>)
|
||||
- **template** (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>)
|
||||
|
||||
Template is the object that describes the pod that will be created if insufficient replicas are detected. More info: https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#pod-template
|
||||
|
||||
@@ -146,7 +146,7 @@ ReplicaSetList is a collection of ReplicaSets.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>), required
|
||||
|
||||
List of ReplicaSets. More info: https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller
|
||||
|
||||
@@ -193,7 +193,7 @@ GET /apis/apps/v1/namespaces/{namespace}/replicasets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -226,7 +226,7 @@ GET /apis/apps/v1/namespaces/{namespace}/replicasets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -299,7 +299,7 @@ GET /apis/apps/v1/namespaces/{namespace}/replicasets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSetList" >}}">ReplicaSetList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSetList" >}}">ReplicaSetList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -367,7 +367,7 @@ GET /apis/apps/v1/replicasets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSetList" >}}">ReplicaSetList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSetList" >}}">ReplicaSetList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -386,7 +386,7 @@ POST /apis/apps/v1/namespaces/{namespace}/replicasets
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -410,11 +410,11 @@ POST /apis/apps/v1/namespaces/{namespace}/replicasets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -438,7 +438,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/replicasets/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -462,9 +462,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/replicasets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -488,7 +488,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/replicasets/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -512,9 +512,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/replicasets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -567,7 +567,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/replicasets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -620,7 +620,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/replicasets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replica-set-v1#ReplicaSet" >}}">ReplicaSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+20
-20
@@ -30,11 +30,11 @@ ReplicationController represents the configuration of a replication controller.
|
||||
|
||||
If the Labels of a ReplicationController are empty, they are defaulted to be the same as the Pod(s) that the replication controller manages. Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationControllerSpec" >}}">ReplicationControllerSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationControllerSpec" >}}">ReplicationControllerSpec</a>)
|
||||
|
||||
Spec defines the specification of the desired behavior of the replication controller. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationControllerStatus" >}}">ReplicationControllerStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationControllerStatus" >}}">ReplicationControllerStatus</a>)
|
||||
|
||||
Status is the most recently observed status of the replication controller. This data may be out of date by some window of time. Populated by the system. Read-only. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
||||
|
||||
@@ -52,7 +52,7 @@ ReplicationControllerSpec is the specification of a replication controller.
|
||||
|
||||
Selector is a label query over pods that should match the Replicas count. If Selector is empty, it is defaulted to the labels present on the Pod template. Label keys and values that must match in order to be controlled by this replication controller, if empty defaulted to labels on Pod template. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#label-selectors
|
||||
|
||||
- **template** (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>)
|
||||
- **template** (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>)
|
||||
|
||||
Template is the object that describes the pod that will be created if insufficient replicas are detected. This takes precedence over a TemplateRef. More info: https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller#pod-template
|
||||
|
||||
@@ -146,7 +146,7 @@ ReplicationControllerList is a collection of replication controllers.
|
||||
|
||||
Standard list metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>), required
|
||||
|
||||
List of replication controllers. More info: https://kubernetes.io/docs/concepts/workloads/controllers/replicationcontroller
|
||||
|
||||
@@ -193,7 +193,7 @@ GET /api/v1/namespaces/{namespace}/replicationcontrollers/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -226,7 +226,7 @@ GET /api/v1/namespaces/{namespace}/replicationcontrollers/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -299,7 +299,7 @@ GET /api/v1/namespaces/{namespace}/replicationcontrollers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationControllerList" >}}">ReplicationControllerList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationControllerList" >}}">ReplicationControllerList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -367,7 +367,7 @@ GET /api/v1/replicationcontrollers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationControllerList" >}}">ReplicationControllerList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationControllerList" >}}">ReplicationControllerList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -386,7 +386,7 @@ POST /api/v1/namespaces/{namespace}/replicationcontrollers
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -410,11 +410,11 @@ POST /api/v1/namespaces/{namespace}/replicationcontrollers
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -438,7 +438,7 @@ PUT /api/v1/namespaces/{namespace}/replicationcontrollers/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -462,9 +462,9 @@ PUT /api/v1/namespaces/{namespace}/replicationcontrollers/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -488,7 +488,7 @@ PUT /api/v1/namespaces/{namespace}/replicationcontrollers/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -512,9 +512,9 @@ PUT /api/v1/namespaces/{namespace}/replicationcontrollers/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -567,7 +567,7 @@ PATCH /api/v1/namespaces/{namespace}/replicationcontrollers/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -620,7 +620,7 @@ PATCH /api/v1/namespaces/{namespace}/replicationcontrollers/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/replication-controller-v1#ReplicationController" >}}">ReplicationController</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
+20
-20
@@ -32,11 +32,11 @@ The StatefulSet guarantees that a given network identity will always map to the
|
||||
- **metadata** (<a href="{{< ref "../common-definitions/object-meta#ObjectMeta" >}}">ObjectMeta</a>)
|
||||
|
||||
|
||||
- **spec** (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSetSpec" >}}">StatefulSetSpec</a>)
|
||||
- **spec** (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSetSpec" >}}">StatefulSetSpec</a>)
|
||||
|
||||
Spec defines the desired identities of pods in this set.
|
||||
|
||||
- **status** (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSetStatus" >}}">StatefulSetStatus</a>)
|
||||
- **status** (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSetStatus" >}}">StatefulSetStatus</a>)
|
||||
|
||||
Status is the current status of Pods in this StatefulSet. This data may be out of date by some window of time.
|
||||
|
||||
@@ -58,7 +58,7 @@ A StatefulSetSpec is the specification of a StatefulSet.
|
||||
|
||||
selector is a label query over pods that should match the replica count. It must match the pod template's labels. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#label-selectors
|
||||
|
||||
- **template** (<a href="{{< ref "../workloads-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>), required
|
||||
- **template** (<a href="{{< ref "../workload-resources/pod-template-v1#PodTemplateSpec" >}}">PodTemplateSpec</a>), required
|
||||
|
||||
template is the object that describes the pod that will be created if insufficient replicas are detected. Each pod stamped out by the StatefulSet will fulfill this Template, but have a unique identity from the rest of the StatefulSet.
|
||||
|
||||
@@ -193,7 +193,7 @@ StatefulSetList is a collection of StatefulSets.
|
||||
- **metadata** (<a href="{{< ref "../common-definitions/list-meta#ListMeta" >}}">ListMeta</a>)
|
||||
|
||||
|
||||
- **items** ([]<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>), required
|
||||
- **items** ([]<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>), required
|
||||
|
||||
|
||||
|
||||
@@ -239,7 +239,7 @@ GET /apis/apps/v1/namespaces/{namespace}/statefulsets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -272,7 +272,7 @@ GET /apis/apps/v1/namespaces/{namespace}/statefulsets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -345,7 +345,7 @@ GET /apis/apps/v1/namespaces/{namespace}/statefulsets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSetList" >}}">StatefulSetList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSetList" >}}">StatefulSetList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -413,7 +413,7 @@ GET /apis/apps/v1/statefulsets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSetList" >}}">StatefulSetList</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSetList" >}}">StatefulSetList</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -432,7 +432,7 @@ POST /apis/apps/v1/namespaces/{namespace}/statefulsets
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -456,11 +456,11 @@ POST /apis/apps/v1/namespaces/{namespace}/statefulsets
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): Created
|
||||
|
||||
202 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): Accepted
|
||||
202 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): Accepted
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -484,7 +484,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/statefulsets/{name}
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -508,9 +508,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/statefulsets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -534,7 +534,7 @@ PUT /apis/apps/v1/namespaces/{namespace}/statefulsets/{name}/status
|
||||
<a href="{{< ref "../common-parameters/common-parameters#namespace" >}}">namespace</a>
|
||||
|
||||
|
||||
- **body**: <a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>, required
|
||||
- **body**: <a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>, required
|
||||
|
||||
|
||||
|
||||
@@ -558,9 +558,9 @@ PUT /apis/apps/v1/namespaces/{namespace}/statefulsets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
|
||||
201 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): Created
|
||||
201 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): Created
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -613,7 +613,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/statefulsets/{name}
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -666,7 +666,7 @@ PATCH /apis/apps/v1/namespaces/{namespace}/statefulsets/{name}/status
|
||||
#### Response
|
||||
|
||||
|
||||
200 (<a href="{{< ref "../workloads-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
200 (<a href="{{< ref "../workload-resources/stateful-set-v1#StatefulSet" >}}">StatefulSet</a>): OK
|
||||
|
||||
401: Unauthorized
|
||||
|
||||
@@ -1,4 +0,0 @@
|
||||
---
|
||||
title: "Workloads Resources"
|
||||
weight: 1
|
||||
---
|
||||
@@ -19,8 +19,9 @@ Each stage is exposed in a extension point. Plugins provide scheduling behaviors
|
||||
by implementing one or more of these extension points.
|
||||
|
||||
You can specify scheduling profiles by running `kube-scheduler --config <filename>`,
|
||||
using the component config APIs
|
||||
([`v1beta1`](https://pkg.go.dev/k8s.io/kube-scheduler@v0.19.0/config/v1beta1?tab=doc#KubeSchedulerConfiguration)).
|
||||
using the
|
||||
[KubeSchedulerConfiguration (v1beta1)](/docs/reference/config-api/kube-scheduler-config.v1beta1/)
|
||||
struct.
|
||||
|
||||
A minimal configuration looks as follows:
|
||||
|
||||
@@ -97,6 +98,7 @@ for that extension point. This can also be used to rearrange plugins order, if
|
||||
desired.
|
||||
|
||||
### Scheduling plugins
|
||||
|
||||
1. `UnReserve`: This is an informational extension point that is called if
|
||||
a Pod is rejected after being reserved and put on hold by a `Permit` plugin.
|
||||
|
||||
@@ -245,3 +247,5 @@ only has one pending pods queue.
|
||||
|
||||
* Read the [kube-scheduler reference](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-scheduler/)
|
||||
* Learn about [scheduling](/docs/concepts/scheduling-eviction/kube-scheduler/)
|
||||
* Read the [kube-scheduler configuration (v1beta1)](/docs/reference/config-api/kube-scheduler-config.v1beta1/) reference
|
||||
|
||||
|
||||
@@ -14,9 +14,7 @@ respectively.
|
||||
You can set a scheduling policy by running
|
||||
`kube-scheduler --policy-config-file <filename>` or
|
||||
`kube-scheduler --policy-configmap <ConfigMap>`
|
||||
and using the [Policy type](https://pkg.go.dev/k8s.io/kube-scheduler@v0.18.0/config/v1?tab=doc#Policy).
|
||||
|
||||
|
||||
and using the [Policy type](/docs/reference/config-api/kube-scheduler-policy-config.v1/).
|
||||
|
||||
<!-- body -->
|
||||
|
||||
@@ -117,10 +115,10 @@ The following *priorities* implement scoring:
|
||||
- `EvenPodsSpreadPriority`: Implements preferred
|
||||
[pod topology spread constraints](/docs/concepts/workloads/pods/pod-topology-spread-constraints/).
|
||||
|
||||
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
* Learn about [scheduling](/docs/concepts/scheduling-eviction/kube-scheduler/)
|
||||
* Learn about [kube-scheduler Configuration](/docs/reference/scheduling/config/)
|
||||
* Read the [kube-scheduler configuration reference (v1beta1)](/docs/reference/config-api/kube-scheduler-config.v1beta1)
|
||||
* Read the [kube-scheduler Policy reference (v1)](/docs/reference/config-api/kube-scheduler-policy-config.v1/)
|
||||
|
||||
|
||||
@@ -251,7 +251,7 @@ Other API server flags that are set unconditionally are:
|
||||
- `--requestheader-client-ca-file` to`front-proxy-ca.crt`
|
||||
- `--proxy-client-cert-file` to `front-proxy-client.crt`
|
||||
- `--proxy-client-key-file` to `front-proxy-client.key`
|
||||
- Other flags for securing the front proxy ([API Aggregation](https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/aggregated-api-servers.md)) communications:
|
||||
- Other flags for securing the front proxy ([API Aggregation](/docs/concepts/extend-kubernetes/api-extension/apiserver-aggregation/)) communications:
|
||||
- `--requestheader-username-headers=X-Remote-User`
|
||||
- `--requestheader-group-headers=X-Remote-Group`
|
||||
- `--requestheader-extra-headers-prefix=X-Remote-Extra-`
|
||||
@@ -305,7 +305,7 @@ into `/var/lib/kubelet/config/init/kubelet` file.
|
||||
|
||||
The init configuration is used for starting the kubelet on this specific node, providing an alternative for the kubelet drop-in file;
|
||||
such configuration will be replaced by the kubelet base configuration as described in following steps.
|
||||
See [set Kubelet parameters via a config file](/docs/tasks/administer-cluster/kubelet-config-file) for additional info.
|
||||
See [set kubelet parameters via a config file](/docs/tasks/administer-cluster/kubelet-config-file) for additional information.
|
||||
|
||||
Please note that:
|
||||
|
||||
@@ -315,6 +315,9 @@ Please note that:
|
||||
a configuration file `--config some-file.yaml`. The `KubeletConfiguration` object can be separated from other objects such
|
||||
as `InitConfiguration` using the `---` separator. For more details have a look at the `kubeadm config print-default` command.
|
||||
|
||||
For more details about the `KubeletConfiguration` struct, take a look at the
|
||||
[`KubeletConfiguration` reference](/docs/reference/config-api/kubelet-config.v1beta1/).
|
||||
|
||||
### Wait for the control plane to come up
|
||||
|
||||
kubeadm waits (upto 4m0s) until `localhost:6443/healthz` (kube-apiserver liveness) returns `ok`. However in order to detect
|
||||
@@ -325,7 +328,8 @@ kubeadm relies on the kubelet to pull the control plane images and run them prop
|
||||
After the control plane is up, kubeadm completes the tasks described in following paragraphs.
|
||||
|
||||
### (optional) Write base kubelet configuration
|
||||
{{< feature-state for_k8s_version="v1.9" state="alpha" >}}
|
||||
|
||||
{{< feature-state for_k8s_version="v1.11" state="beta" >}}
|
||||
|
||||
If kubeadm is invoked with `--feature-gates=DynamicKubeletConfig`:
|
||||
|
||||
@@ -438,8 +442,8 @@ A ServiceAccount for `kube-proxy` is created in the `kube-system` namespace; the
|
||||
|
||||
- In Kubernetes version 1.18 kube-dns usage with kubeadm is deprecated and will be removed in a future release
|
||||
- The CoreDNS service is named `kube-dns`. This is done to prevent any interruption
|
||||
in service when the user is switching the cluster DNS from kube-dns to CoreDNS or vice-versa
|
||||
the `--config` method described [here](/docs/reference/setup-tools/kubeadm/kubeadm-init-phase/#cmd-phase-addon)
|
||||
in service when the user is switching the cluster DNS from kube-dns to CoreDNS or vice-versa
|
||||
the `--config` method described [here](/docs/reference/setup-tools/kubeadm/kubeadm-init-phase/#cmd-phase-addon)
|
||||
- A ServiceAccount for CoreDNS/kube-dns is created in the `kube-system` namespace.
|
||||
- The `kube-dns` ServiceAccount is bound to the privileges in the `system:kube-dns` ClusterRole
|
||||
|
||||
@@ -499,10 +503,9 @@ when the connection with the cluster is established, kubeadm try to access the `
|
||||
|
||||
## TLS Bootstrap
|
||||
|
||||
Once the cluster info are known, the file `bootstrap-kubelet.conf` is written, thus allowing kubelet to do TLS Bootstrapping
|
||||
(conversely until v.1.7 TLS bootstrapping were managed by kubeadm).
|
||||
Once the cluster info are known, the file `bootstrap-kubelet.conf` is written, thus allowing kubelet to do TLS Bootstrapping.
|
||||
|
||||
The TLS bootstrap mechanism uses the shared token to temporarily authenticate with the Kubernetes Master to submit a certificate
|
||||
The TLS bootstrap mechanism uses the shared token to temporarily authenticate with the Kubernetes API server to submit a certificate
|
||||
signing request (CSR) for a locally created key pair.
|
||||
|
||||
The request is then automatically approved and the operation completes saving `ca.crt` file and `kubelet.conf` file to be used
|
||||
@@ -512,17 +515,17 @@ Please note that:
|
||||
|
||||
- The temporary authentication is validated against the token saved during the `kubeadm init` process (or with additional tokens
|
||||
created with `kubeadm token`)
|
||||
- The temporary authentication resolve to a user member of `system:bootstrappers:kubeadm:default-node-token` group which was granted
|
||||
- The temporary authentication resolve to a user member of `system:bootstrappers:kubeadm:default-node-token` group which was granted
|
||||
access to CSR api during the `kubeadm init` process
|
||||
- The automatic CSR approval is managed by the csrapprover controller, according with configuration done the `kubeadm init` process
|
||||
|
||||
### (optional) Write init kubelet configuration
|
||||
|
||||
{{< feature-state for_k8s_version="v1.9" state="alpha" >}}
|
||||
{{< feature-state for_k8s_version="v1.11" state="beta" >}}
|
||||
|
||||
If kubeadm is invoked with `--feature-gates=DynamicKubeletConfig`:
|
||||
|
||||
1. Read the kubelet base configuration from the `kubelet-base-config-v1.9` ConfigMap in the `kube-system` namespace using the
|
||||
1. Read the kubelet base configuration from the `kubelet-base-config-v1.x` ConfigMap in the `kube-system` namespace using the
|
||||
Bootstrap Token credentials, and write it to disk as kubelet init configuration file `/var/lib/kubelet/config/init/kubelet`
|
||||
2. As soon as kubelet starts with the Node's own credential (`/etc/kubernetes/kubelet.conf`), update current node configuration
|
||||
specifying that the source for the node/kubelet configuration is the above ConfigMap.
|
||||
|
||||
@@ -130,7 +130,7 @@ page and pick a version from [the list](https://pkg.go.dev/k8s.io/kubernetes/cmd
|
||||
### Adding kube-proxy parameters {#kube-proxy}
|
||||
|
||||
For information about kube-proxy parameters in the kubeadm configuration see:
|
||||
- [kube-proxy](https://godoc.org/k8s.io/kubernetes/pkg/proxy/apis/config#KubeProxyConfiguration)
|
||||
- [kube-proxy reference](/docs/reference/config-api/kube-proxy-config.v1alpha1/)
|
||||
|
||||
For information about enabling IPVS mode with kubeadm see:
|
||||
- [IPVS](https://github.com/kubernetes/kubernetes/blob/master/pkg/proxy/ipvs/README.md)
|
||||
|
||||
@@ -46,7 +46,7 @@ Server side apply is meant both as a replacement for the original `kubectl
|
||||
apply` and as a simpler mechanism for controllers to enact their changes.
|
||||
|
||||
If you have Server Side Apply enabled, the control plane tracks managed fields
|
||||
for all newlly created objects.
|
||||
for all newly created objects.
|
||||
|
||||
## Field Management
|
||||
|
||||
|
||||
+1
-1
@@ -229,7 +229,7 @@ Cluster DNS (CoreDNS) will not start up before a network is installed.**
|
||||
{{< /caution >}}
|
||||
|
||||
{{< note >}}
|
||||
Currently Calico is the only CNI plugin that the kubeadm project performs e2e tests against.
|
||||
Kubeadm should be CNI agnostic and the validation of CNI providers is out of the scope of our current e2e testing.
|
||||
If you find an issue related to a CNI plugin you should log a ticket in its respective issue
|
||||
tracker instead of the kubeadm or kubernetes issue trackers.
|
||||
{{< /note >}}
|
||||
|
||||
@@ -71,7 +71,7 @@ For more details please see the [Network Plugin Requirements](/docs/concepts/ext
|
||||
|
||||
| Protocol | Direction | Port Range | Purpose | Used By |
|
||||
|----------|-----------|------------|-------------------------|---------------------------|
|
||||
| TCP | Inbound | 6443* | Kubernetes API server | All |
|
||||
| TCP | Inbound | 6443\* | Kubernetes API server | All |
|
||||
| TCP | Inbound | 2379-2380 | etcd server client API | kube-apiserver, etcd |
|
||||
| TCP | Inbound | 10250 | kubelet API | Self, Control plane |
|
||||
| TCP | Inbound | 10251 | kube-scheduler | Self |
|
||||
@@ -308,7 +308,8 @@ kind: KubeletConfiguration
|
||||
cgroupDriver: <value>
|
||||
```
|
||||
|
||||
For further details, please read [Using kubeadm init with a configuration file](/docs/reference/setup-tools/kubeadm/kubeadm-init/#config-file).
|
||||
For further details, please read [Using kubeadm init with a configuration file](/docs/reference/setup-tools/kubeadm/kubeadm-init/#config-file)
|
||||
and the [`KubeletConfiguration` reference](/docs/reference/config-api/kubelet-config.v1beta1/)
|
||||
|
||||
Please mind, that you **only** have to do that if the cgroup driver of your CRI
|
||||
is not `cgroupfs`, because that is the default value in the kubelet already.
|
||||
@@ -322,12 +323,11 @@ or `/etc/default/kubelet`(`/etc/sysconfig/kubelet` for RPMs), please remove it a
|
||||
The automatic detection of cgroup driver for other container runtimes
|
||||
like CRI-O and containerd is work in progress.
|
||||
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
If you are running into difficulties with kubeadm, please consult our [troubleshooting docs](/docs/setup/production-environment/tools/kubeadm/troubleshooting-kubeadm/).
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
|
||||
* [Using kubeadm to Create a Cluster](/docs/setup/production-environment/tools/kubeadm/create-cluster-kubeadm/)
|
||||
|
||||
|
||||
@@ -23,10 +23,8 @@ manager instead, but you need to configure it manually.
|
||||
Some kubelet configuration details need to be the same across all kubelets involved in the cluster, while
|
||||
other configuration aspects need to be set on a per-kubelet basis to accommodate the different
|
||||
characteristics of a given machine (such as OS, storage, and networking). You can manage the configuration
|
||||
of your kubelets manually, but kubeadm now provides a `KubeletConfiguration` API type for [managing your
|
||||
kubelet configurations centrally](#configure-kubelets-using-kubeadm).
|
||||
|
||||
|
||||
of your kubelets manually, but kubeadm now provides a `KubeletConfiguration` API type for
|
||||
[managing your kubelet configurations centrally](#configure-kubelets-using-kubeadm).
|
||||
|
||||
<!-- body -->
|
||||
|
||||
@@ -52,8 +50,9 @@ Virtual IPs for services are now allocated from this subnet. You also need to se
|
||||
by the kubelet, using the `--cluster-dns` flag. This setting needs to be the same for every kubelet
|
||||
on every manager and Node in the cluster. The kubelet provides a versioned, structured API object
|
||||
that can configure most parameters in the kubelet and push out this configuration to each running
|
||||
kubelet in the cluster. This object is called **the kubelet's ComponentConfig**.
|
||||
The ComponentConfig allows the user to specify flags such as the cluster DNS IP addresses expressed as
|
||||
kubelet in the cluster. This object is called
|
||||
[`KubeletConfiguration`](/docs/reference/config-api/kubelet-config.v1beta1/).
|
||||
The `KubeletConfiguration` allows the user to specify flags such as the cluster DNS IP addresses expressed as
|
||||
a list of values to a camelCased key, illustrated by the following example:
|
||||
|
||||
```yaml
|
||||
@@ -63,7 +62,7 @@ clusterDNS:
|
||||
- 10.96.0.10
|
||||
```
|
||||
|
||||
For more details on the ComponentConfig have a look at [this section](#configure-kubelets-using-kubeadm).
|
||||
For more details on the `KubeletConfiguration` have a look at [this section](#configure-kubelets-using-kubeadm).
|
||||
|
||||
### Providing instance-specific configuration details
|
||||
|
||||
@@ -99,8 +98,8 @@ API object is passed with a configuration file like so `kubeadm ... --config som
|
||||
By calling `kubeadm config print init-defaults --component-configs KubeletConfiguration` you can
|
||||
see all the default values for this structure.
|
||||
|
||||
Also have a look at the [API reference for the
|
||||
kubelet ComponentConfig](https://godoc.org/k8s.io/kubernetes/pkg/kubelet/apis/config#KubeletConfiguration)
|
||||
Also have a look at the
|
||||
[reference for the KubeletConfiguration](/docs/reference/config-api/kubelet-config.v1beta1/)
|
||||
for more information on the individual fields.
|
||||
|
||||
### Workflow when using `kubeadm init`
|
||||
@@ -160,9 +159,13 @@ has finished performing the TLS Bootstrap.
|
||||
`kubeadm` ships with configuration for how systemd should run the kubelet.
|
||||
Note that the kubeadm CLI command never touches this drop-in file.
|
||||
|
||||
This configuration file installed by the `kubeadm` [DEB](https://github.com/kubernetes/release/blob/master/cmd/kubepkg/templates/latest/deb/kubeadm/10-kubeadm.conf) or [RPM package](https://github.com/kubernetes/release/blob/master/cmd/kubepkg/templates/latest/rpm/kubeadm/10-kubeadm.conf) is written to
|
||||
This configuration file installed by the `kubeadm`
|
||||
[DEB](https://github.com/kubernetes/release/blob/master/cmd/kubepkg/templates/latest/deb/kubeadm/10-kubeadm.conf) or
|
||||
[RPM package](https://github.com/kubernetes/release/blob/master/cmd/kubepkg/templates/latest/rpm/kubeadm/10-kubeadm.conf) is written to
|
||||
`/etc/systemd/system/kubelet.service.d/10-kubeadm.conf` and is used by systemd.
|
||||
It augments the basic [`kubelet.service` for RPM](https://github.com/kubernetes/release/blob/master/cmd/kubepkg/templates/latest/rpm/kubelet/kubelet.service) or [`kubelet.service` for DEB](https://github.com/kubernetes/release/blob/master/cmd/kubepkg/templates/latest/deb/kubelet/lib/systemd/system/kubelet.service):
|
||||
It augments the basic
|
||||
[`kubelet.service` for RPM](https://github.com/kubernetes/release/blob/master/cmd/kubepkg/templates/latest/rpm/kubelet/kubelet.service) or
|
||||
[`kubelet.service` for DEB](https://github.com/kubernetes/release/blob/master/cmd/kubepkg/templates/latest/deb/kubelet/lib/systemd/system/kubelet.service):
|
||||
|
||||
```none
|
||||
[Service]
|
||||
|
||||
+11
-6
@@ -99,10 +99,11 @@ This may be caused by a number of problems. The most common are:
|
||||
|
||||
There are two common ways to fix the cgroup driver problem:
|
||||
|
||||
1. Install Docker again following instructions
|
||||
[here](/docs/setup/production-environment/container-runtimes/#docker).
|
||||
1. Install Docker again following instructions
|
||||
[here](/docs/setup/production-environment/container-runtimes/#docker).
|
||||
|
||||
1. Change the kubelet config to match the Docker cgroup driver manually, you can refer to [Configure cgroup driver used by kubelet on control-plane node](/docs/setup/production-environment/tools/kubeadm/install-kubeadm/#configure-cgroup-driver-used-by-kubelet-on-control-plane-node)
|
||||
1. Change the kubelet config to match the Docker cgroup driver manually, you can refer to
|
||||
[Configure cgroup driver used by kubelet on control-plane node](/docs/setup/production-environment/tools/kubeadm/install-kubeadm/#configure-cgroup-driver-used-by-kubelet-on-control-plane-node)
|
||||
|
||||
- control plane Docker containers are crashlooping or hanging. You can check this by running `docker ps` and investigating each container by running `docker logs`.
|
||||
|
||||
@@ -110,8 +111,11 @@ This may be caused by a number of problems. The most common are:
|
||||
|
||||
The following could happen if Docker halts and does not remove any Kubernetes-managed containers:
|
||||
|
||||
```bash
|
||||
```shell
|
||||
sudo kubeadm reset
|
||||
```
|
||||
|
||||
```console
|
||||
[preflight] Running pre-flight checks
|
||||
[reset] Stopping the kubelet service
|
||||
[reset] Unmounting mounted directories in "/var/lib/kubelet"
|
||||
@@ -121,14 +125,14 @@ sudo kubeadm reset
|
||||
|
||||
A possible solution is to restart the Docker service and then re-run `kubeadm reset`:
|
||||
|
||||
```bash
|
||||
```shell
|
||||
sudo systemctl restart docker.service
|
||||
sudo kubeadm reset
|
||||
```
|
||||
|
||||
Inspecting the logs for docker may also be useful:
|
||||
|
||||
```sh
|
||||
```shell
|
||||
journalctl -u docker
|
||||
```
|
||||
|
||||
@@ -415,3 +419,4 @@ If `/var/lib/kubelet` is being mounted, performing a `kubeadm reset` will effect
|
||||
To workaround the issue, re-mount the `/var/lib/kubelet` directory after performing the `kubeadm reset` operation.
|
||||
|
||||
This is a regression introduced in kubeadm 1.15. The issue is fixed in 1.20.
|
||||
|
||||
|
||||
@@ -68,7 +68,7 @@ Kubespray provides the ability to customize many aspects of the deployment:
|
||||
* {{< glossary_tooltip term_id="cri-o" >}}
|
||||
* Certificate generation methods
|
||||
|
||||
Kubespray customizations can be made to a [variable file](https://docs.ansible.com/ansible/playbooks_variables.html). If you are getting started with Kubespray, consider using the Kubespray defaults to deploy your cluster and explore Kubernetes.
|
||||
Kubespray customizations can be made to a [variable file](https://docs.ansible.com/ansible/latest/user_guide/playbooks_variables.html). If you are getting started with Kubespray, consider using the Kubespray defaults to deploy your cluster and explore Kubernetes.
|
||||
|
||||
### (4/5) Deploy a Cluster
|
||||
|
||||
|
||||
+28
-19
@@ -1,7 +1,9 @@
|
||||
---
|
||||
reviewers:
|
||||
- michmike
|
||||
- patricklang
|
||||
- jayunit100
|
||||
- jsturtevant
|
||||
- marosset
|
||||
- perithompson
|
||||
title: Intro to Windows support in Kubernetes
|
||||
content_type: concept
|
||||
weight: 65
|
||||
@@ -233,23 +235,33 @@ Overlay (VXLAN) networks on Windows do not support dual-stack networking today.
|
||||
|
||||
### Limitations
|
||||
|
||||
#### Control Plane
|
||||
|
||||
Windows is only supported as a worker node in the Kubernetes architecture and component matrix. This means that a Kubernetes cluster must always include Linux master nodes, zero or more Linux worker nodes, and zero or more Windows worker nodes.
|
||||
|
||||
#### Compute {#compute-limitations}
|
||||
|
||||
##### Resource management and process isolation
|
||||
#### Resource Handling
|
||||
|
||||
Linux cgroups are used as a pod boundary for resource controls in Linux. Containers are created within that boundary for network, process and file system isolation. The cgroups APIs can be used to gather cpu/io/memory stats. In contrast, Windows uses a Job object per container with a system namespace filter to contain all processes in a container and provide logical isolation from the host. There is no way to run a Windows container without the namespace filtering in place. This means that system privileges cannot be asserted in the context of the host, and thus privileged containers are not available on Windows. Containers cannot assume an identity from the host because the Security Account Manager (SAM) is separate.
|
||||
|
||||
##### Operating System Restrictions
|
||||
#### Resource Reservations
|
||||
|
||||
Windows has strict compatibility rules, where the host OS version must match the container base image OS version. Only Windows containers with a container operating system of Windows Server 2019 are supported. Hyper-V isolation of containers, enabling some backward compatibility of Windows container image versions, is planned for a future release.
|
||||
##### Memory Reservations
|
||||
Windows does not have an out-of-memory process killer as Linux does. Windows always treats all user-mode memory allocations as virtual, and pagefiles are mandatory. The net effect is that Windows won't reach out of memory conditions the same way Linux does, and processes page to disk instead of being subject to out of memory (OOM) termination. If memory is over-provisioned and all physical memory is exhausted, then paging can slow down performance.
|
||||
|
||||
##### Feature Restrictions
|
||||
Keeping memory usage within reasonable bounds is possible using the kubelet parameters `--kubelet-reserve` and/or `--system-reserve` to account for memory usage on the node (outside of containers). This reduces [NodeAllocatable](/docs/tasks/administer-cluster/reserve-compute-resources/#node-allocatable).
|
||||
|
||||
* TerminationGracePeriod: requires CRI-containerD
|
||||
{{< note >}}
|
||||
As you deploy workloads, use resource limits (must set only limits or limits must equal requests) on containers. This also subtracts from NodeAllocatable and prevents the scheduler from adding more pods once a node is full.
|
||||
{{< /note >}}
|
||||
|
||||
A best practice to avoid over-provisioning is to configure the kubelet with a system reserved memory of at least 2GB to account for Windows, Docker, and Kubernetes processes.
|
||||
|
||||
##### CPU Reservations
|
||||
To account for Windows, Docker and other Kubernetes host processes it is recommended to reserve a percentage of CPU so they are able to respond to events. This value needs to be scaled based on the number of CPU cores available on the Windows node.To determine this percentage a user should identify the maximum pod density for each of their nodes and monitor the CPU usage of the system services choosing a value that meets their workload needs.
|
||||
|
||||
Keeping CPU usage within reasonable bounds is possible using the kubelet parameters `--kubelet-reserve` and/or `--system-reserve` to account for CPU usage on the node (outside of containers). This reduces [NodeAllocatable](/docs/tasks/administer-cluster/reserve-compute-resources/#node-allocatable).
|
||||
|
||||
#### Feature Restrictions
|
||||
* TerminationGracePeriod: not implemented
|
||||
* Single file mapping: to be implemented with CRI-ContainerD
|
||||
* Termination message: to be implemented with CRI-ContainerD
|
||||
* Privileged Containers: not currently supported in Windows containers
|
||||
@@ -257,15 +269,8 @@ Windows has strict compatibility rules, where the host OS version must match the
|
||||
* The existing node problem detector is Linux-only and requires privileged containers. In general, we don't expect this to be used on Windows because privileged containers are not supported
|
||||
* Not all features of shared namespaces are supported (see API section for more details)
|
||||
|
||||
##### Memory Reservations and Handling
|
||||
|
||||
Windows does not have an out-of-memory process killer as Linux does. Windows always treats all user-mode memory allocations as virtual, and pagefiles are mandatory. The net effect is that Windows won't reach out of memory conditions the same way Linux does, and processes page to disk instead of being subject to out of memory (OOM) termination. If memory is over-provisioned and all physical memory is exhausted, then paging can slow down performance.
|
||||
|
||||
Keeping memory usage within reasonable bounds is possible with a two-step process. First, use the kubelet parameters `--kubelet-reserve` and/or `--system-reserve` to account for memory usage on the node (outside of containers). This reduces [NodeAllocatable](/docs/tasks/administer-cluster/reserve-compute-resources/#node-allocatable)). As you deploy workloads, use resource limits (must set only limits or limits must equal requests) on containers. This also subtracts from NodeAllocatable and prevents the scheduler from adding more pods once a node is full.
|
||||
|
||||
A best practice to avoid over-provisioning is to configure the kubelet with a system reserved memory of at least 2GB to account for Windows, Docker, and Kubernetes processes.
|
||||
|
||||
The behavior of the flags behave differently as described below:
|
||||
#### Difference in behavior of flags when compared to Linux
|
||||
The behavior of the following kubelet flags is different on Windows nodes as described below:
|
||||
|
||||
* `--kubelet-reserve`, `--system-reserve` , and `--eviction-hard` flags update Node Allocatable
|
||||
* Eviction by using `--enforce-node-allocable` is not implemented
|
||||
@@ -413,6 +418,10 @@ None of the PodSecurityContext fields work on Windows. They're listed here for r
|
||||
* V1.PodSecurityContext.SupplementalGroups - provides GID, not available on Windows
|
||||
* V1.PodSecurityContext.Sysctls - these are part of the Linux sysctl interface. There's no equivalent on Windows.
|
||||
|
||||
#### Operating System Version Restrictions
|
||||
|
||||
Windows has strict compatibility rules, where the host OS version must match the container base image OS version. Only Windows containers with a container operating system of Windows Server 2019 are supported. Hyper-V isolation of containers, enabling some backward compatibility of Windows container image versions, is planned for a future release.
|
||||
|
||||
## Getting Help and Troubleshooting {#troubleshooting}
|
||||
|
||||
Your main source of help for troubleshooting your Kubernetes cluster should start with this [section](/docs/tasks/debug-application-cluster/troubleshooting/). Some additional, Windows-specific troubleshooting help is included in this section. Logs are an important element of troubleshooting issues in Kubernetes. Make sure to include them any time you seek troubleshooting assistance from other contributors. Follow the instructions in the SIG-Windows [contributing guide on gathering logs](https://github.com/kubernetes/community/blob/master/sig-windows/CONTRIBUTING.md#gathering-logs).
|
||||
|
||||
+4
-2
@@ -1,7 +1,9 @@
|
||||
---
|
||||
reviewers:
|
||||
- michmike
|
||||
- patricklang
|
||||
- jayunit100
|
||||
- jsturtevant
|
||||
- marosset
|
||||
- perithompson
|
||||
title: Guide for scheduling Windows containers in Kubernetes
|
||||
content_type: concept
|
||||
weight: 75
|
||||
|
||||
@@ -283,14 +283,14 @@ volume.
|
||||
We can also take the snapshot using various options given by etcdctl. For example
|
||||
|
||||
```shell
|
||||
ETCDCTL_API=3 etcdctl --h
|
||||
ETCDCTL_API=3 etcdctl -h
|
||||
```
|
||||
|
||||
will list various options available from etcdctl. For example, you can take a snapshot by specifying
|
||||
the endpoint, certificates etc as shown below:
|
||||
|
||||
```shell
|
||||
ETCDCTL_API=3 etcdctl --endpoints=[127.0.0.1:2379] \
|
||||
ETCDCTL_API=3 etcdctl --endpoints=https://127.0.0.1:2379 \
|
||||
--cacert=<trusted-ca-file> --cert=<cert-file> --key=<key-file> \
|
||||
snapshot save <backup-file-location>
|
||||
```
|
||||
|
||||
@@ -1,7 +1,9 @@
|
||||
---
|
||||
reviewers:
|
||||
- michmike
|
||||
- patricklang
|
||||
- jayunit100
|
||||
- jsturtevant
|
||||
- marosset
|
||||
- perithompson
|
||||
title: Adding Windows nodes
|
||||
min-kubernetes-server-version: 1.17
|
||||
content_type: tutorial
|
||||
|
||||
@@ -7,31 +7,21 @@ content_type: task
|
||||
---
|
||||
|
||||
<!-- overview -->
|
||||
{{< feature-state for_k8s_version="v1.10" state="beta" >}}
|
||||
|
||||
A subset of the Kubelet's configuration parameters may be
|
||||
set via an on-disk config file, as a substitute for command-line flags.
|
||||
This functionality is considered beta in v1.10.
|
||||
|
||||
Providing parameters via a config file is the recommended approach because
|
||||
it simplifies node deployment and configuration management.
|
||||
|
||||
|
||||
|
||||
## {{% heading "prerequisites" %}}
|
||||
|
||||
|
||||
- A v1.10 or higher Kubelet binary must be installed for beta functionality.
|
||||
|
||||
|
||||
|
||||
<!-- steps -->
|
||||
|
||||
## Create the config file
|
||||
|
||||
The subset of the Kubelet's configuration that can be configured via a file
|
||||
is defined by the `KubeletConfiguration` struct
|
||||
[here (v1beta1)](https://github.com/kubernetes/kubernetes/blob/{{< param "docsbranch" >}}/staging/src/k8s.io/kubelet/config/v1beta1/types.go).
|
||||
is defined by the
|
||||
[`KubeletConfiguration`](/docs/reference/config-api/kubelet-config.v1beta1/)
|
||||
struct.
|
||||
|
||||
The configuration file must be a JSON or YAML representation of the parameters
|
||||
in this struct. Make sure the Kubelet has read permissions on the file.
|
||||
@@ -53,6 +43,11 @@ For a trick to generate a configuration file from a live node, see
|
||||
|
||||
## Start a Kubelet process configured via the config file
|
||||
|
||||
{{< note >}}
|
||||
If you use kubeadm to initialize your cluster, use the kubelet-config while creating your cluster with `kubeadmin init`.
|
||||
See [configuring kubelet using kubeadm](/docs/setup/production-environment/tools/kubeadm/kubelet-integration/) for details.
|
||||
{{< /note >}}
|
||||
|
||||
Start the Kubelet with the `--config` flag set to the path of the Kubelet's config file.
|
||||
The Kubelet will then load its config from this file.
|
||||
|
||||
@@ -68,8 +63,6 @@ If `--config` is provided and the values are not specified via the command line,
|
||||
defaults for the `KubeletConfiguration` version apply.
|
||||
In the above example, this version is `kubelet.config.k8s.io/v1beta1`.
|
||||
|
||||
|
||||
|
||||
<!-- discussion -->
|
||||
|
||||
## Relationship to Dynamic Kubelet Config
|
||||
@@ -78,6 +71,9 @@ If you are using the [Dynamic Kubelet Configuration](/docs/tasks/administer-clus
|
||||
feature, the combination of configuration provided via `--config` and any flags which override these values
|
||||
is considered the default "last known good" configuration by the automatic rollback mechanism.
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
|
||||
- Learn more about kubelet configuration by checking the
|
||||
[`KubeletConfiguration`](/docs/reference/config-api/kubelet-config.v1beta1/)
|
||||
reference.
|
||||
|
||||
|
||||
@@ -22,8 +22,8 @@ but this is unsafe for some parameters. Before deciding to change a parameter
|
||||
dynamically, you need a strong understanding of how that change will affect your
|
||||
cluster's behavior. Always carefully test configuration changes on a small set
|
||||
of nodes before rolling them out cluster-wide. Advice on configuring specific
|
||||
fields is available in the inline `KubeletConfiguration`
|
||||
[type documentation (for v1.20)](https://github.com/kubernetes/kubernetes/blob/release-1.20/staging/src/k8s.io/kubelet/config/v1beta1/types.go).
|
||||
fields is available in the inline
|
||||
[`KubeletConfiguration`](/docs/reference/config-api/kubelet-config.v1beta1/).
|
||||
{{< /warning >}}
|
||||
|
||||
|
||||
@@ -55,7 +55,7 @@ For each node that you're reconfiguring, you must set the kubelet
|
||||
The basic workflow for configuring a kubelet in a live cluster is as follows:
|
||||
|
||||
1. Write a YAML or JSON configuration file containing the
|
||||
kubelet's configuration.
|
||||
kubelet's configuration.
|
||||
2. Wrap this file in a ConfigMap and save it to the Kubernetes control plane.
|
||||
3. Update the kubelet's corresponding Node object to use this ConfigMap.
|
||||
|
||||
@@ -135,24 +135,24 @@ To follow the tasks as written, you need to have `jq` installed. You can
|
||||
adapt the steps if you prefer to extract the `kubeletconfig` subobject manually.
|
||||
{{< /note >}}
|
||||
|
||||
1. Choose a Node to reconfigure. In this example, the name of this Node is
|
||||
referred to as `NODE_NAME`.
|
||||
2. Start the kubectl proxy in the background using the following command:
|
||||
1. Choose a Node to reconfigure. In this example, the name of this Node is
|
||||
referred to as `NODE_NAME`.
|
||||
2. Start the kubectl proxy in the background using the following command:
|
||||
|
||||
```bash
|
||||
kubectl proxy --port=8001 &
|
||||
```
|
||||
3. Run the following command to download and unpack the configuration from the
|
||||
`configz` endpoint. The command is long, so be careful when copying and
|
||||
pasting. **If you use zsh**, note that common zsh configurations add backslashes
|
||||
to escape the opening and closing curly braces around the variable name in the URL.
|
||||
For example: `${NODE_NAME}` will be rewritten as `$\{NODE_NAME\}` during the paste.
|
||||
You must remove the backslashes before running the command, or the command will fail.
|
||||
```shell
|
||||
kubectl proxy --port=8001 &
|
||||
```
|
||||
3. Run the following command to download and unpack the configuration from the
|
||||
`configz` endpoint. The command is long, so be careful when copying and
|
||||
pasting. **If you use zsh**, note that common zsh configurations add backslashes
|
||||
to escape the opening and closing curly braces around the variable name in the URL.
|
||||
For example: `${NODE_NAME}` will be rewritten as `$\{NODE_NAME\}` during the paste.
|
||||
You must remove the backslashes before running the command, or the command will fail.
|
||||
|
||||
|
||||
```bash
|
||||
NODE_NAME="the-name-of-the-node-you-are-reconfiguring"; curl -sSL "http://localhost:8001/api/v1/nodes/${NODE_NAME}/proxy/configz" | jq '.kubeletconfig|.kind="KubeletConfiguration"|.apiVersion="kubelet.config.k8s.io/v1beta1"' > kubelet_configz_${NODE_NAME}
|
||||
```
|
||||
```bash
|
||||
NODE_NAME="the-name-of-the-node-you-are-reconfiguring"; curl -sSL "http://localhost:8001/api/v1/nodes/${NODE_NAME}/proxy/configz" | jq '.kubeletconfig|.kind="KubeletConfiguration"|.apiVersion="kubelet.config.k8s.io/v1beta1"' > kubelet_configz_${NODE_NAME}
|
||||
```
|
||||
|
||||
{{< note >}}
|
||||
You need to manually add the `kind` and `apiVersion` to the downloaded
|
||||
@@ -312,8 +312,6 @@ empty, since all config sources have been reset to `nil`, which indicates that
|
||||
the local default config is `assigned`, `active`, and `lastKnownGood`, and no
|
||||
error is reported.
|
||||
|
||||
|
||||
|
||||
<!-- discussion -->
|
||||
## `kubectl patch` example
|
||||
|
||||
@@ -356,7 +354,7 @@ metadata and checkpoints. The structure of the kubelet's checkpointing directory
|
||||
| - ...
|
||||
```
|
||||
|
||||
## Understanding Node.Status.Config.Error messages {#understanding-node-config-status-errors}
|
||||
## Understanding `Node.Status.Config.Error` messages {#understanding-node-config-status-errors}
|
||||
|
||||
The following table describes error messages that can occur
|
||||
when using Dynamic Kubelet Config. You can search for the identical text
|
||||
@@ -378,6 +376,10 @@ internal failure, see Kubelet log for details | The kubelet encountered some int
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
- For more information on configuring the kubelet via a configuration file, see
|
||||
- For more information on configuring the kubelet via a configuration file, see
|
||||
[Set kubelet parameters via a config file](/docs/tasks/administer-cluster/kubelet-config-file).
|
||||
- See the reference documentation for [`NodeConfigSource`](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#nodeconfigsource-v1-core)
|
||||
- Learn more about kubelet configuration by checking the
|
||||
[`KubeletConfiguration`](/docs/reference/config-api/kubelet-config.v1beta1/)
|
||||
reference.
|
||||
|
||||
|
||||
@@ -90,7 +90,7 @@ In addition to `cpu`, `memory`, and `ephemeral-storage`, `pid` may be
|
||||
specified to reserve the specified number of process IDs for
|
||||
kubernetes system daemons.
|
||||
|
||||
To optionally enforce `kube-reserved` on system daemons, specify the parent
|
||||
To optionally enforce `kube-reserved` on kubernetes system daemons, specify the parent
|
||||
control group for kube daemons as the value for `--kube-reserved-cgroup` kubelet
|
||||
flag.
|
||||
|
||||
|
||||
@@ -31,21 +31,14 @@ Pods to run a Pod on every node, you should probably be using a
|
||||
instead.
|
||||
{{< /note >}}
|
||||
|
||||
|
||||
|
||||
## {{% heading "prerequisites" %}}
|
||||
|
||||
|
||||
{{< include "task-tutorial-prereqs.md" >}} {{< version-check >}}
|
||||
|
||||
This page assumes you're using {{< glossary_tooltip term_id="docker" >}} to run Pods,
|
||||
and that your nodes are running the Fedora operating system.
|
||||
Instructions for other distributions or Kubernetes installations may vary.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
<!-- steps -->
|
||||
|
||||
## Create a static pod {#static-pod-creation}
|
||||
@@ -54,7 +47,9 @@ You can configure a static Pod with either a [file system hosted configuration f
|
||||
|
||||
### Filesystem-hosted static Pod manifest {#configuration-files}
|
||||
|
||||
Manifests are standard Pod definitions in JSON or YAML format in a specific directory. Use the `staticPodPath: <the directory>` field in the [kubelet configuration file](/docs/tasks/administer-cluster/kubelet-config-file), which periodically scans the directory and creates/deletes static Pods as YAML/JSON files appear/disappear there.
|
||||
Manifests are standard Pod definitions in JSON or YAML format in a specific directory. Use the `staticPodPath: <the directory>` field in the
|
||||
[kubelet configuration file](/docs/reference/config-api/kubelet-config.v1beta1/),
|
||||
which periodically scans the directory and creates/deletes static Pods as YAML/JSON files appear/disappear there.
|
||||
Note that the kubelet will ignore files starting with dots when scanning the specified directory.
|
||||
|
||||
For example, this is how to start a simple web server as a static Pod:
|
||||
@@ -90,17 +85,18 @@ For example, this is how to start a simple web server as a static Pod:
|
||||
|
||||
3. Configure your kubelet on the node to use this directory by running it with `--pod-manifest-path=/etc/kubelet.d/` argument. On Fedora edit `/etc/kubernetes/kubelet` to include this line:
|
||||
|
||||
```
|
||||
KUBELET_ARGS="--cluster-dns=10.254.0.10 --cluster-domain=kube.local --pod-manifest-path=/etc/kubelet.d/"
|
||||
```
|
||||
or add the `staticPodPath: <the directory>` field in the [kubelet configuration file](/docs/tasks/administer-cluster/kubelet-config-file).
|
||||
```
|
||||
KUBELET_ARGS="--cluster-dns=10.254.0.10 --cluster-domain=kube.local --pod-manifest-path=/etc/kubelet.d/"
|
||||
```
|
||||
or add the `staticPodPath: <the directory>` field in the
|
||||
[kubelet configuration file](/docs/reference/config-api/kubelet-config.v1beta1/).
|
||||
|
||||
4. Restart the kubelet. On Fedora, you would run:
|
||||
|
||||
```shell
|
||||
# Run this command on the node where the kubelet is running
|
||||
systemctl restart kubelet
|
||||
```
|
||||
```shell
|
||||
# Run this command on the node where the kubelet is running
|
||||
systemctl restart kubelet
|
||||
```
|
||||
|
||||
### Web-hosted static pod manifest {#pods-created-via-http}
|
||||
|
||||
|
||||
@@ -46,7 +46,9 @@ Each request can be recorded with an associated _stage_. The defined stages are:
|
||||
- `Panic` - Events generated when a panic occurred.
|
||||
|
||||
{{< note >}}
|
||||
Audit events are different from the
|
||||
The configuration of an
|
||||
[Audit Event configuration](/docs/reference/config-api/apiserver-audit.v1/#audit-k8s-io-v1-Event)
|
||||
is different from the
|
||||
[Event](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#event-v1-core)
|
||||
API object.
|
||||
{{< /note >}}
|
||||
@@ -59,7 +61,7 @@ Memory consumption depends on the audit logging configuration.
|
||||
|
||||
Audit policy defines rules about what events should be recorded and what data
|
||||
they should include. The audit policy object structure is defined in the
|
||||
[`audit.k8s.io` API group](https://github.com/kubernetes/kubernetes/blob/{{< param "githubbranch" >}}/staging/src/k8s.io/apiserver/pkg/apis/audit/v1/types.go).
|
||||
[`audit.k8s.io` API group](/docs/reference/config-api/apiserver-audit.v1/#audit-k8s-io-v1-Policy).
|
||||
When an event is processed, it's
|
||||
compared against the list of rules in order. The first matching rule sets the
|
||||
_audit level_ of the event. The defined audit levels are:
|
||||
@@ -95,6 +97,9 @@ If you're crafting your own audit profile, you can use the audit profile for Goo
|
||||
[configure-helper.sh](https://github.com/kubernetes/kubernetes/blob/{{< param "githubbranch" >}}/cluster/gce/gci/configure-helper.sh)
|
||||
script, which generates an audit policy file. You can see most of the audit policy file by looking directly at the script.
|
||||
|
||||
You can also refer to the [`Policy` configuration reference](/docs/reference/config-api/apiserver-audit.v1/#audit-k8s-io-v1-Policy)
|
||||
for details about the fields defined.
|
||||
|
||||
## Audit backends
|
||||
|
||||
Audit backends persist audit events to an external storage.
|
||||
@@ -104,9 +109,7 @@ Out of the box, the kube-apiserver provides two backends:
|
||||
- Webhook backend, which sends events to an external HTTP API
|
||||
|
||||
In all cases, audit events follow a structure defined by the Kubernetes API in the
|
||||
`audit.k8s.io` API group. For Kubernetes {{< param "fullversion" >}}, that
|
||||
API is at version
|
||||
[`v1`](https://github.com/kubernetes/kubernetes/blob/{{< param "githubbranch" >}}/staging/src/k8s.io/apiserver/pkg/apis/audit/v1/types.go).
|
||||
[`audit.k8s.io` API group](/docs/reference/config-api/apiserver-audit.v1/#audit-k8s-io-v1-Event).
|
||||
|
||||
{{< note >}}
|
||||
In case of patches, request body is a JSON array with patch operations, not a JSON object
|
||||
@@ -174,8 +177,6 @@ and finally configure the `hostPath`:
|
||||
|
||||
```
|
||||
|
||||
|
||||
|
||||
### Webhook backend
|
||||
|
||||
The webhook audit backend sends audit events to a remote web API, which is assumed to
|
||||
@@ -250,3 +251,5 @@ By default truncate is disabled in both `webhook` and `log`, a cluster administr
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
* Learn about [Mutating webhook auditing annotations](/docs/reference/access-authn-authz/extensible-admission-controllers/#mutating-webhook-auditing-annotations).
|
||||
* Read the [reference for `audit.k8s.io` API group](/docs/reference/config-api/apiserver-audit.v1/).
|
||||
|
||||
|
||||
@@ -354,7 +354,7 @@ and [the walkthrough for using external metrics](/docs/tasks/run-application/hor
|
||||
## Support for configurable scaling behavior
|
||||
|
||||
Starting from
|
||||
[v1.18](https://github.com/kubernetes/enhancements/blob/master/keps/sig-autoscaling/20190307-configurable-scale-velocity-for-hpa.md)
|
||||
[v1.18](https://github.com/kubernetes/enhancements/blob/master/keps/sig-autoscaling/853-configurable-hpa-scale-velocity/README.md)
|
||||
the `v2beta2` API allows scaling behavior to be configured through the HPA
|
||||
`behavior` field. Behaviors are specified separately for scaling up and down in
|
||||
`scaleUp` or `scaleDown` section under the `behavior` field. A stabilization
|
||||
|
||||
@@ -33,7 +33,7 @@ Up to date information on this process can be found at the
|
||||
Once Helm is installed, add the *service-catalog* Helm repository to your local machine by executing the following command:
|
||||
|
||||
```shell
|
||||
helm repo add svc-cat https://svc-catalog-charts.storage.googleapis.com
|
||||
helm repo add svc-cat https://kubernetes-sigs.github.io/service-catalog
|
||||
```
|
||||
|
||||
Check to make sure that it installed successfully by executing the following command:
|
||||
|
||||
@@ -27,6 +27,8 @@ Before walking through each tutorial, you may want to bookmark the
|
||||
|
||||
## Configuration
|
||||
|
||||
* [Example: Configuring a Java Microservice](/docs/tutorials/configuration/configure-java-microservice/)
|
||||
|
||||
* [Configuring Redis Using a ConfigMap](/docs/tutorials/configuration/configure-redis-using-configmap/)
|
||||
|
||||
## Stateless Applications
|
||||
|
||||
@@ -322,7 +322,7 @@ Events:
|
||||
23s 23s 1 {kubelet e2e-test-stclair-node-pool-t1f5} Warning AppArmor Cannot enforce AppArmor: profile "k8s-apparmor-example-allow-write" is not loaded
|
||||
```
|
||||
|
||||
Note the pod status is Failed, with a helpful error message: `Pod Cannot enforce AppArmor: profile
|
||||
Note the pod status is Pending, with a helpful error message: `Pod Cannot enforce AppArmor: profile
|
||||
"k8s-apparmor-example-allow-write" is not loaded`. An event was also recorded with the same message.
|
||||
|
||||
## Administration
|
||||
|
||||
@@ -62,7 +62,7 @@ If you installed minikube locally, run `minikube start`. Before you run `minikub
|
||||
{{< note >}}
|
||||
The `dashboard` command enables the dashboard add-on and opens the proxy in the default web browser. You can create Kubernetes resources on the dashboard such as Deployment and Service.
|
||||
|
||||
If you are running in an environment as root, see [Open Dashboard with URL](/docs/tutorials/hello-minikube#open-dashboard-with-url).
|
||||
If you are running in an environment as root, see [Open Dashboard with URL](#open-dashboard-with-url).
|
||||
|
||||
To stop the proxy, run `Ctrl+C` to exit the process. The dashboard remains running.
|
||||
{{< /note >}}
|
||||
|
||||
@@ -425,7 +425,7 @@ the `service.spec.healthCheckNodePort` field on the Service.
|
||||
Delete the Services:
|
||||
|
||||
```shell
|
||||
kubectl delete svc -l run=source-ip-app
|
||||
kubectl delete svc -l app=source-ip-app
|
||||
```
|
||||
|
||||
Delete the Deployment, ReplicaSet and Pod:
|
||||
|
||||
@@ -49,13 +49,14 @@ The manifest file, included below, specifies a Deployment controller that runs a
|
||||
1. Launch a terminal window in the directory you downloaded the manifest files.
|
||||
1. Apply the MongoDB Deployment from the `mongo-deployment.yaml` file:
|
||||
|
||||
<!---
|
||||
for local testing of the content via relative file path
|
||||
kubectl apply -f ./content/en/examples/application/guestbook/mongo-deployment.yaml
|
||||
-->
|
||||
|
||||
```shell
|
||||
kubectl apply -f https://k8s.io/examples/application/guestbook/mongo-deployment.yaml
|
||||
```
|
||||
<!---
|
||||
for local testing of the content via relative file path
|
||||
kubectl apply -f ./content/en/examples/application/guestbook/mongo-deployment.yaml
|
||||
-->
|
||||
|
||||
1. Query the list of Pods to verify that the MongoDB Pod is running:
|
||||
|
||||
@@ -84,15 +85,15 @@ The guestbook application needs to communicate to the MongoDB to write its data.
|
||||
|
||||
1. Apply the MongoDB Service from the following `mongo-service.yaml` file:
|
||||
|
||||
<!---
|
||||
for local testing of the content via relative file path
|
||||
kubectl apply -f ./content/en/examples/application/guestbook/mongo-service.yaml
|
||||
-->
|
||||
|
||||
```shell
|
||||
kubectl apply -f https://k8s.io/examples/application/guestbook/mongo-service.yaml
|
||||
```
|
||||
|
||||
<!---
|
||||
for local testing of the content via relative file path
|
||||
kubectl apply -f ./content/en/examples/application/guestbook/mongo-service.yaml
|
||||
-->
|
||||
|
||||
1. Query the list of Services to verify that the MongoDB Service is running:
|
||||
|
||||
```shell
|
||||
@@ -122,15 +123,15 @@ The guestbook application has a web frontend serving the HTTP requests written i
|
||||
|
||||
1. Apply the frontend Deployment from the `frontend-deployment.yaml` file:
|
||||
|
||||
<!---
|
||||
for local testing of the content via relative file path
|
||||
kubectl apply -f ./content/en/examples/application/guestbook/frontend-deployment.yaml
|
||||
-->
|
||||
|
||||
```shell
|
||||
kubectl apply -f https://k8s.io/examples/application/guestbook/frontend-deployment.yaml
|
||||
```
|
||||
|
||||
<!---
|
||||
for local testing of the content via relative file path
|
||||
kubectl apply -f ./content/en/examples/application/guestbook/frontend-deployment.yaml
|
||||
-->
|
||||
|
||||
1. Query the list of Pods to verify that the three frontend replicas are running:
|
||||
|
||||
```shell
|
||||
@@ -160,15 +161,15 @@ Some cloud providers, like Google Compute Engine or Google Kubernetes Engine, su
|
||||
|
||||
1. Apply the frontend Service from the `frontend-service.yaml` file:
|
||||
|
||||
<!---
|
||||
for local testing of the content via relative file path
|
||||
kubectl apply -f ./content/en/examples/application/guestbook/frontend-service.yaml
|
||||
-->
|
||||
|
||||
```shell
|
||||
kubectl apply -f https://k8s.io/examples/application/guestbook/frontend-service.yaml
|
||||
```
|
||||
|
||||
<!---
|
||||
for local testing of the content via relative file path
|
||||
kubectl apply -f ./content/en/examples/application/guestbook/frontend-service.yaml
|
||||
-->
|
||||
|
||||
1. Query the list of Services to verify that the frontend Service is running:
|
||||
|
||||
```shell
|
||||
@@ -179,7 +180,7 @@ kubectl apply -f ./content/en/examples/application/guestbook/frontend-service.ya
|
||||
|
||||
```
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
frontend ClusterIP 10.0.0.112 <none> 80/TCP 6s
|
||||
frontend ClusterIP 10.0.0.112 <none> 80/TCP 6s
|
||||
kubernetes ClusterIP 10.0.0.1 <none> 443/TCP 4m
|
||||
mongo ClusterIP 10.0.0.151 <none> 6379/TCP 2m
|
||||
```
|
||||
@@ -214,8 +215,8 @@ If you deployed the `frontend-service.yaml` manifest with type: `LoadBalancer` y
|
||||
The response should be similar to this:
|
||||
|
||||
```
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
frontend ClusterIP 10.51.242.136 109.197.92.229 80:32372/TCP 1m
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
frontend LoadBalancer 10.51.242.136 109.197.92.229 80:32372/TCP 1m
|
||||
```
|
||||
|
||||
1. Copy the external IP address, and load the page in your browser to view your guestbook.
|
||||
@@ -245,7 +246,7 @@ You can scale up or down as needed because your servers are defined as a Service
|
||||
frontend-3823415956-k22zn 1/1 Running 0 54m
|
||||
frontend-3823415956-w9gbt 1/1 Running 0 54m
|
||||
frontend-3823415956-x2pld 1/1 Running 0 5s
|
||||
mongo-1068406935-3lswp 1/1 Running 0 56m
|
||||
mongo-1068406935-3lswp 1/1 Running 0 56m
|
||||
```
|
||||
|
||||
1. Run the following command to scale down the number of frontend Pods:
|
||||
@@ -266,7 +267,7 @@ You can scale up or down as needed because your servers are defined as a Service
|
||||
NAME READY STATUS RESTARTS AGE
|
||||
frontend-3823415956-k22zn 1/1 Running 0 1h
|
||||
frontend-3823415956-w9gbt 1/1 Running 0 1h
|
||||
mongo-1068406935-3lswp 1/1 Running 0 1h
|
||||
mongo-1068406935-3lswp 1/1 Running 0 1h
|
||||
```
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
---
|
||||
title: "Seguridad"
|
||||
weight: 81
|
||||
---
|
||||
|
||||
@@ -0,0 +1,152 @@
|
||||
---
|
||||
title: Vista General de Seguridad Cloud Native
|
||||
content_type: concept
|
||||
weight: 10
|
||||
---
|
||||
|
||||
<!-- overview -->
|
||||
|
||||
Esta descripción general define un modelo para la seguridad de Kubernetes en el contexto de Seguridad en Cloud Native.
|
||||
|
||||
{{< warning >}}
|
||||
Este modelo de seguridad en el contenedor brinda sugerencias, no es una prueba de políticas de seguridad de la información.
|
||||
{{< /warning >}}
|
||||
|
||||
<!-- body -->
|
||||
|
||||
## Las 4C de Seguridad en Cloud Native
|
||||
|
||||
Puede pensar en seguridad por capas. Las 4C de la seguridad en Cloud Native son la nube (Cloud),
|
||||
{{< glossary_tooltip text="Clústeres" term_id="cluster" >}}, {{< glossary_tooltip text="Contenedores" term_id="container" >}} y Código.
|
||||
|
||||
{{< note >}}
|
||||
Este enfoque en capas aumenta la [defensa en profundidad](https://en.wikipedia.org/wiki/Defense_in_depth_(computing))
|
||||
de la seguridad, es considerada una buena práctica en seguridad para el software de sistemas.
|
||||
{{< /note >}}
|
||||
|
||||
{{< figure src="/images/docs/4c.png" title="Las 4C de Seguridad en Cloud Native" >}}
|
||||
|
||||
Cada capa del modelo de seguridad Cloud Native es basada en la siguiente capa más externa.
|
||||
La capa de código se beneficia de una base sólida (nube, clúster, contenedor) de capas seguras.
|
||||
No podemos garantizar la seguridad aplicando solo seguridad a nivel del código, y usar estándares de seguridad deficientes en las otras capas.
|
||||
|
||||
## Nube (Cloud)
|
||||
|
||||
En muchos sentidos, la nube (o los servidores o el centro de datos corporativo) es la
|
||||
[base de computador confiable](https://es.wikipedia.org/wiki/Base_de_computador_confiable)
|
||||
de un clúster de Kubernetes. Si la capa de la nube es vulnerable (o
|
||||
configurado de alguna manera vulnerable), por consecuencia no hay garantía de que los componentes construidos
|
||||
encima de la base sean seguros. Cada proveedor de la nube tiene recomendaciones de seguridad
|
||||
para ejecutar las cargas de trabajo de forma segura en sus entornos.
|
||||
|
||||
### Seguridad del proveedor de la nube
|
||||
|
||||
Si está ejecutando un clúster de Kubernetes en su propio hardware o en un proveedor de nube diferente,
|
||||
consulte la documentación para conocer las mejores prácticas de seguridad.
|
||||
A continuación, algunos enlaces a la documentación de seguridad de los proveedores de nube más populares:
|
||||
|
||||
{{< table caption="Cloud provider security" >}}
|
||||
|
||||
Proveedor IaaS | Link |
|
||||
-------------------- | ------------ |
|
||||
Alibaba Cloud | https://www.alibabacloud.com/trust-center |
|
||||
Amazon Web Services | https://aws.amazon.com/security/ |
|
||||
Google Cloud Platform | https://cloud.google.com/security/ |
|
||||
IBM Cloud | https://www.ibm.com/cloud/security |
|
||||
Microsoft Azure | https://docs.microsoft.com/en-us/azure/security/azure-security |
|
||||
VMWare VSphere | https://www.vmware.com/security/hardening-guides.html |
|
||||
|
||||
{{< /table >}}
|
||||
|
||||
### Seguridad de la Infraestructura {#infrastructure-security}
|
||||
|
||||
Sugerencias para proteger su infraestructura en un clúster de Kubernetes:
|
||||
|
||||
{{< table caption="Infrastructure security" >}}
|
||||
|
||||
Área de Interés para la Infraestructura de Kubernetes | Recomendación |
|
||||
--------------------------------------------- | -------------- |
|
||||
Acceso de red al Plano de Control | Todo acceso público al {{< glossary_tooltip text="plano de control" term_id="control-plane" >}} del Kubernetes en Internet no está permitido y es controlado por listas de control de acceso a la red estrictas a un conjunto de direcciones IP necesarias para administrar el clúster.|
|
||||
Acceso a la red de los Nodos | Los {{< glossary_tooltip text="nodos" term_id="node" >}} deben ser configurados para _solo_ aceptar conexiones (por medio de listas de control de acceso a la red) desde el plano de control en los puertos especificados y aceptar conexiones para servicios en Kubernetes del tipo NodePort y LoadBalancer. Si es posible, estos nodos no deben exponerse públicamente en Internet.
|
||||
Acceso a la API de Kubernetes del proveedor de la nube | Cada proveedor de la nube debe dar un conjunto de permisos al plano de control y nodos del Kubernetes. Es mejor otorgar al clúster el permiso de acceso al proveedor de nube siguiendo el [principio de mínimo privilegio](https://es.wikipedia.org/wiki/Principio_de_m%C3%ADnimo_privilegio) para los recursos que necesite administrar. La [documentación del Kops](https://github.com/kubernetes/kops/blob/master/docs/iam_roles.md#iam-roles) ofrece información sobre las políticas y roles de IAM.
|
||||
Acceso a etcd | El acceso a {{< glossary_tooltip text="etcd" term_id="etcd" >}} (banco de datos de Kubernetes) debe ser limitado apenas al plano de control. Dependiendo de su configuración, debería intentar usar etcd sobre TLS. Puede encontrar mas información en la [documentación de etcd](https://github.com/etcd-io/etcd/tree/master/Documentation).
|
||||
Encriptación etcd | Siempre que sea posible, es una buena práctica encriptar todas las unidades de almacenamiento. Etcd mantiene el estado de todo el clúster (incluidos los Secretos), por lo que su disco debe estar encriptado.
|
||||
|
||||
{{< /table >}}
|
||||
|
||||
## Clúster
|
||||
|
||||
Existen dos áreas de preocupación para proteger Kubernetes:
|
||||
|
||||
* Protección de las configuraciones de los componentes del clúster.
|
||||
* Protección de las aplicaciones que se ejecutan en el clúster.
|
||||
|
||||
### Componentes del Clúster {#cluster-components}
|
||||
|
||||
Si desea proteger su clúster de accesos accidentales o maliciosos y adoptar
|
||||
buenas prácticas de seguridad, a continuación sigue estos consejos sobre
|
||||
[como proteger el clúster](/docs/tasks/administer-cluster/securing-a-cluster/).
|
||||
|
||||
### Componentes del clúster (su aplicación) {#cluster-applications}
|
||||
|
||||
Dependiendo de la superficie de ataque de su aplicación, es posible que desee concentrarse en
|
||||
temas de seguridad específicos. Por ejemplo: si está ejecutando un servicio (Servicio A) que es crítico
|
||||
en una cadena de otros recursos y otra carga de trabajo separada (Servicio B) que es
|
||||
vulnerable a un ataque de sobrecarga de recursos, el riesgo de comprometer el Servicio A
|
||||
es alto si no limita las funciones del Servicio B. La siguiente tabla enumera
|
||||
áreas de atención de seguridad y recomendaciones para proteger las cargas de trabajo que se ejecutan en Kubernetes:
|
||||
|
||||
Áreas para la seguridad de la carga del trabajo | Recomendación |
|
||||
------------------------------ | --------------------- |
|
||||
Autorización RBAC (acceso a la API Kubernetes) | https://kubernetes.io/docs/reference/access-authn-authz/rbac/
|
||||
Autenticación | https://kubernetes.io/docs/concepts/security/controlling-access/
|
||||
Administrar secretos en la aplicación (encriptar el etcd - dato en reposo) | https://kubernetes.io/docs/concepts/configuration/secret/ <br> https://kubernetes.io/docs/tasks/administer-cluster/encrypt-data/
|
||||
Políticas de seguridad de Pod | https://kubernetes.io/docs/concepts/policy/pod-security-policy/
|
||||
Calidad de servicio (y gestión de recursos del clúster) | https://kubernetes.io/docs/tasks/configure-pod-container/quality-service-pod/
|
||||
Políticas de Red | https://kubernetes.io/docs/concepts/services-networking/network-policies/
|
||||
TLS para Kubernetes Ingress | https://kubernetes.io/docs/concepts/services-networking/ingress/#tls
|
||||
|
||||
## Contenedor
|
||||
|
||||
La seguridad de los contenedores está fuera del alcance de la guía. Aquí hay recomendaciones generales y
|
||||
enlaces para explorar este tema:
|
||||
|
||||
Área de Interés para Contenedores | Recomendación |
|
||||
------------------------------ | -------------- |
|
||||
Escáneres de vulnerabilidad de contenedores y seguridad de dependencia del sistema operativo | Como parte del paso de la creación de la imagen, se debe utilizar un escáner de contenedores para detectar vulnerabilidades.
|
||||
Firma de Imágenes y Aplicación | Firma de imágenes de contenedores para mantener un sistema confiable para el contenido de sus contenedores.
|
||||
Prohibir Usuarios Privilegiados | Al crear contenedores, consulte la documentación para crear usuarios dentro de los contenedores con el menor privilegio necesario para cumplir con el propósito del contenedor en el sistema operativo.
|
||||
Utilice el contenedor de tiempo de ejecución con el aislamiento más fuerte | Seleccione [clases del contenedor runtime](/docs/concepts/containers/runtime-class/) con el proveedor de aislamiento más fuerte.
|
||||
|
||||
## Código
|
||||
|
||||
El código de la aplicación es una de las principales superficies de ataque sobre las que tenemos más control.
|
||||
Aunque la protección del código de la aplicación está fuera del tema de seguridad de Kubernetes, aquí algunas
|
||||
recomendaciones para proteger el código de su aplicación:
|
||||
|
||||
### Seguridad del código
|
||||
|
||||
{{< table caption="Code security" >}}
|
||||
|
||||
Áreas de Atención para el Código | Recomendación |
|
||||
-------------------------| -------------- |
|
||||
Acceso solo a través de TLS | Si su código necesita comunicarse a través de TCP, ejecute un handshake TLS con el cliente anticipadamente. Con la excepción de algunos casos, encripte todo lo que está en tránsito. Yendo un paso más allá, es una buena idea cifrar el tráfico de red entre los servicios. Esto se puede hacer a través del proceso de autenticación mutua o [mTLS](https://en.wikipedia.org/wiki/Mutual_authentication), que realiza una verificación bilateral de la comunicación a través de los certificados en los servicios. |
|
||||
Limitación de rangos de puertos de comunicación | Esta recomendación puede ser un poco evidente, pero siempre que sea posible, solo debe exponer los puertos de su servicio que son absolutamente esenciales para la comunicación o la recopilación de métricas. |
|
||||
Seguridad en dependencia de terceros | Es una buena práctica comprobar periódicamente las bibliotecas de terceros de su aplicación en busca de vulnerabilidades de seguridad. Cada lenguaje de programación tiene una herramienta para realizar esta verificación de forma automática. |
|
||||
Análisis de código estático | La mayoría de los lenguajes proporcionan una forma de analizar el código en busca de prácticas de codificación potencialmente inseguras. Siempre que sea posible, debe automatizar los escaneos utilizando herramientas que puedan escanear las bases del código en busca de errores de seguridad comunes. Algunas de las herramientas se pueden encontrar en [OWASP Source Code Analysis Tools](https://owasp.org/www-community/Source_Code_Analysis_Tools). |
|
||||
Ataques de sondeo dinámico | Existen algunas herramientas automatizadas que puede ejecutar en su servicio para explorar algunos de los ataques más conocidos. Esto incluye la inyección de SQL, CSRF y XSS. Una de las herramientas de análisis dinámico más populares es la [OWASP Zed Attack proxy](https://owasp.org/www-project-zap/). |
|
||||
|
||||
{{< /table >}}
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
Obtenga más información sobre los temas de seguridad de Kubernetes:
|
||||
|
||||
* [Estándares de seguridad del pod](/docs/concepts/security/pod-security-standards/)
|
||||
* [Políticas de red para pods](/docs/concepts/services-networking/network-policies/)
|
||||
* [Control de acceso a la API de Kubernetes](/docs/concepts/security/controlling-access)
|
||||
* [Protegiendo su clúster](/docs/tasks/administer-cluster/securing-a-cluster/)
|
||||
* [Criptografía de datos en tránsito](/docs/tasks/tls/managing-tls-in-a-cluster/)
|
||||
* [Criptografía de datos en reposo](/docs/tasks/administer-cluster/encrypt-data/)
|
||||
* [Secretos en Kubernetes](/docs/concepts/configuration/secret/)
|
||||
* [Runtime class](/docs/concepts/containers/runtime-class)
|
||||
@@ -81,7 +81,7 @@ metadata:
|
||||
name: 1.13-sample
|
||||
scheduler:
|
||||
extraArgs:
|
||||
address: 0.0.0.0
|
||||
bind-address: 0.0.0.0
|
||||
config: /home/johndoe/schedconfig.yaml
|
||||
kubeconfig: /home/johndoe/kubeconfig.yaml
|
||||
```
|
||||
|
||||
@@ -102,9 +102,8 @@ yang diinginkannya melalui server API, dan kemudian berkomunikasi langsung
|
||||
dengan sistem eksternal untuk membawa keadaan saat ini mendekat keadaan yang
|
||||
diinginkan.
|
||||
|
||||
(Sebenarnya ada sebuah _controller_ yang melakukan penskalaan node secara
|
||||
horizontal dalam klaster kamu. Silahkan lihat
|
||||
[_autoscaling_ klaster](/docs/tasks/administer-cluster/cluster-management/#cluster-autoscaling)).
|
||||
(Sebenarnya ada sebuah [_controller_](https://github.com/kubernetes/autoscaler/) yang melakukan penskalaan node secara
|
||||
horizontal dalam klaster kamu.
|
||||
|
||||
## Status sekarang berbanding status yang diinginkan {#sekarang-banding-diinginkan}
|
||||
|
||||
|
||||
@@ -134,6 +134,7 @@ Jika sudah tidak tersedia, kontroler node menghilangkan node tersebut dari dafta
|
||||
|
||||
Ketiga, melakukan monitor terhadap kondisi kesehatan (<i>health</i>) node.
|
||||
Kontroler node bertanggung jawab untuk mengubah status `NodeReady condition` pada `NodeStatus` menjadi `ConditionUnknown`, ketika sebuah node terputus jaringannya (kontroler node tidak lagi mendapat <i>heartbeat</i> karena suatu hal, contohnya karena node tidak hidup), dan saat kemudian melakukan <i>eviction</i> terhadap semua pod yang ada pada node tersebut (melalui terminasi halus -- <i>graceful</i>) jika node masih terus terputus. (<i>Timeout</i> standar adalah 40 detik untuk mulai melaporkan `ConditionUnknown` dan 5 menit setelah itu untuk mulai melakukan <i>eviction</i> terhadap pod.)
|
||||
|
||||
Kontroler node memeriksa <i>state</i> masing-masing node untuk durasi yang ditentukan oleh argumen `--node-monitor-period`.
|
||||
|
||||
Pada versi Kubernetes sebelum 1.13, `NodeStatus` adalah <i>heartbeat</i> yang diberikan oleh node.
|
||||
@@ -154,6 +155,7 @@ Perlakuan <i>eviction</i> pada node berubah ketika sebuah node menjadi tidak seh
|
||||
Kontroler node memeriksa berapa persentase node di dalam zona tersebut yang tidak sehat (saat `NodeReady condition` menjadi `ConditionUnknown` atau `ConditionFalse`) pada saat yang bersamaan.
|
||||
Jika persentase node yang tidak sehat bernilai `--unhealthy-zone-threshold` (<i>default</i>-nya 0.55), maka <i>rate eviction</i> berkurang: untuk ukuran klaster yang kecil (saat jumlahnya lebih kecil atau sama dengan jumlah node `--large-cluster-size-threshold` - <i>default</i>-nya 50), maka <i>eviction</i> akan berhenti dilakukan.
|
||||
Jika masih besar jumlahnya, <i>rate eviction</i> dikurangi menjadi `--secondary-node-eviction-rate` (<i>default</i>-nya 0.01) per detik.
|
||||
|
||||
Alasan kenapa hal ini diimplementasi untuk setiap zona <i>availability</i> adalah karena satu zona bisa saja terputus dari master, saat yang lainnya masih terhubung.
|
||||
Jika klaster tidak menjangkau banyak zona <i>availability</i> yang disediakan oleh penyedia cloud, maka hanya ada satu zona (untuk semua node di dalam klaster).
|
||||
|
||||
|
||||
@@ -1,168 +0,0 @@
|
||||
---
|
||||
title: Metrik-Metrik untuk Control Plane Kubernetes
|
||||
content_type: concept
|
||||
weight: 60
|
||||
aliases:
|
||||
- controller-metrics.md
|
||||
---
|
||||
|
||||
<!-- overview -->
|
||||
|
||||
Metrik dari komponen sistem dapat memberikan pandangan yang lebih baik tentang apa
|
||||
yang sedang terjadi di dalam sistem. Metrik sangat berguna untuk membuat dasbor (_dashboard_)
|
||||
dan peringatan (_alert_).
|
||||
|
||||
Metrik di dalam _control plane_ Kubernetes disajikan dalam [format prometheus](https://prometheus.io/docs/instrumenting/exposition_formats/)
|
||||
dan dapat terbaca oleh manusia.
|
||||
|
||||
|
||||
|
||||
<!-- body -->
|
||||
|
||||
## Metrik-Metrik pada Kubernetes
|
||||
|
||||
Dalam kebanyakan kasus, metrik tersedia pada _endpoint_ `/metrics` dari server HTTP.
|
||||
Untuk komponen yang tidak mengekspos _endpoint_ secara bawaan, _endpoint_ tersebut dapat diaktifkan
|
||||
dengan menggunakan opsi `--bind-address`.
|
||||
|
||||
Contoh-contoh untuk komponen tersebut adalah:
|
||||
|
||||
* {{< glossary_tooltip term_id="kube-controller-manager" text="kube-controller-manager" >}}
|
||||
* {{< glossary_tooltip term_id="kube-proxy" text="kube-proxy" >}}
|
||||
* {{< glossary_tooltip term_id="kube-apiserver" text="kube-apiserver" >}}
|
||||
* {{< glossary_tooltip term_id="kube-scheduler" text="kube-scheduler" >}}
|
||||
* {{< glossary_tooltip term_id="kubelet" text="kubelet" >}}
|
||||
|
||||
Di dalam lingkungan produksi, kamu mungkin ingin mengonfigurasi [Server Prometheus](https://prometheus.io/)
|
||||
atau _scraper_ metrik (pengambil metrik) lainnya untuk mengumpulkan metrik-metrik ini secara berkala
|
||||
dan membuatnya tersedia dalam semacam basis data yang _time series_.
|
||||
|
||||
Perlu dicatat bahwa {{< glossary_tooltip term_id="kubelet" text="kubelet" >}}
|
||||
juga mengekspos metrik pada _endpoint-endpoint_ seperti `/metrics/cadvisor`,
|
||||
`/metrics/resource` dan `/metrics/probes`. Metrik-metrik tersebut tidak memiliki
|
||||
siklus hidup yang sama.
|
||||
|
||||
Jika klaster kamu menggunakan {{< glossary_tooltip term_id="rbac" text="RBAC" >}},
|
||||
untuk membaca metrik memerlukan otorisasi melalui sebuah User, Group, atau
|
||||
ServiceAccount dengan ClusterRole yang memperbolehkan mengakses `/metrics`.
|
||||
|
||||
Sebagai contoh:
|
||||
|
||||
```
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: prometheus
|
||||
rules:
|
||||
- nonResourceURLs:
|
||||
- "/metrics"
|
||||
verbs:
|
||||
- get
|
||||
```
|
||||
|
||||
## Siklus Hidup (_Lifecycle_) Metrik
|
||||
|
||||
Alpha metric → Stable metric → Deprecated metric → Hidden metric → Deletion
|
||||
|
||||
Metrik-metrik _Alpha_ tidak memiliki jaminan stabilitas; dengan demikian mereka
|
||||
dapat dimodifikasi atau dihapus kapan saja.
|
||||
|
||||
Metrik-metrik _Stable_ dijamin tidak berubah (dijamin stabilitasnya); Secara khusus, stabilitas berarti:
|
||||
|
||||
* metrik itu sendiri tidak akan dihapus (atau diganti namanya)
|
||||
* jenis metrik tidak akan dimodifikasi
|
||||
|
||||
Metrik _Deprecated_ memberi penanda bahwa metrik tersebut suatu saat akan dihapus; untuk
|
||||
menemukan versi yang mana, kamu perlu memeriksa anotasi, yang mencakup dari versi
|
||||
Kubernetes mana yang metrik tersebut akan dianggap _deprecated_.
|
||||
|
||||
Sebelum _deprecation_:
|
||||
|
||||
```
|
||||
# HELP some_counter this counts things
|
||||
# TYPE some_counter counter
|
||||
some_counter 0
|
||||
```
|
||||
|
||||
Sesudah _deprecation_:
|
||||
|
||||
```
|
||||
# HELP some_counter (Deprecated since 1.15.0) this counts things
|
||||
# TYPE some_counter counter
|
||||
some_counter 0
|
||||
```
|
||||
|
||||
Setelah metrik disembunyikan maka secara bawaan metrik tidak dipublikasikan
|
||||
untuk _scraping_ (pengambilan metrik). Untuk menggunakan metrik yang tersembunyi, kamu perlu mengganti (_override_)
|
||||
konfigurasi untuk komponen klaster yang relevan.
|
||||
|
||||
Setelah metrik dihapus, metrik tidak dipublikasikan. Kamu tidak dapat mengubah
|
||||
metrik tersebut dengan menggunakan _override_.
|
||||
|
||||
## Melihat Metrik tersembunyi
|
||||
|
||||
Seperti dijelaskan di atas, para admin dapat mengaktifkan metrik tersembunyi
|
||||
melalui opsi pada baris perintah (_command line_) untuk _binary_ (program) tertentu. Ini ditujukan untuk
|
||||
digunakan sebagai solusi bagi para admin apabila mereka gagal memigrasi
|
||||
metrik yang sudah _deprecated_ dalam rilis terakhir.
|
||||
|
||||
Opsi `show-hidden-metrics-for-version` menunjukkan versi yang ingin kamu tampilkan
|
||||
metrik yang sudah _deprecated_ dalam rilis tersebut. Versi ini ditampilkan dalam bentuk x.y,
|
||||
di mana x adalah versi _major_, y adalah versi minor. Versi _patch_ tidak
|
||||
diperlukan meskipun metrik dapat di_-deprecate_ dalam rilis _patch_, hal ini
|
||||
adalah karena kebijakan _deprecation_ untuk metrik hanya berlaku terhadap rilis minor.
|
||||
|
||||
Opsi tersebut hanya dapat menggunakan versi minor sebelumnya sebagai parameternya. Semua
|
||||
metrik yang disembunyikan di versi sebelumnya akan dikeluarkan jika para admin
|
||||
mengatur versi sebelumnya ke `show-hidden-metrics-for-version`. Versi yang
|
||||
terlalu lama tidak diizinkan karena hal ini melanggar kebijakan untuk metrik yang
|
||||
sudah _deprecated_.
|
||||
|
||||
Ambil metrik `A` sebagai contoh, di sini diasumsikan bahwa `A` sudah _deprecated_
|
||||
pada rilis 1.n. Menurut kebijakan metrik yang sudah _deprecated_, kita dapat mencapai kesimpulan
|
||||
sebagai berikut:
|
||||
|
||||
* Pada rilis `1.n`, metrik sudah di_-deprecated_, dan dapat diperlihatkan secara bawaan.
|
||||
* Pada rilis `1.n + 1`, metrik disembunyikan secara bawaan dan dapat
|
||||
diperlihatkan dengan baris perintah `show-hidden-metrics-for-version=1.n`.
|
||||
* Pada rilis `1.n + 2`, metrik harus dihapus dari _codebase_. Tidak ada jalan
|
||||
keluar lagi.
|
||||
|
||||
Jika kamu meng-_upgrade_ dari rilis `1.12` ke` 1.13`, tetapi masih bergantung pada
|
||||
metrik `A` yang di-_deprecate_ dalam` 1.12`, kamu harus mengatur metrik
|
||||
tersembunyi melalui baris perintah: `--show-hidden-metrics=1.12` dan ingatlah
|
||||
untuk menghapus ketergantungan terhadap metrik ini sebelum meng-_upgrade_ ke `1.14`.
|
||||
|
||||
## Metrik komponen
|
||||
|
||||
### Metrik kube-controller-manager
|
||||
|
||||
Metrik Controller Manager memberikan pandangan penting
|
||||
tentang kinerja dan kesehatan Controller Manager. Metrik ini mencakup metrik
|
||||
_runtime_ berbahasa Go yang umum seperti jumlah _go_routine_ dan metrik khusus
|
||||
pengontrol seperti latensi _request etcd_ atau latensi API dari Cloud provider
|
||||
(AWS, GCE, OpenStack) yang dapat digunakan untuk mengukur kesehatan klaster.
|
||||
|
||||
Mulai dari Kubernetes 1.7, metrik Cloud provider yang detail tersedia untuk
|
||||
operasi penyimpanan untuk GCE, AWS, Vsphere, dan OpenStack.
|
||||
Metrik ini dapat digunakan untuk memantau kesehatan operasi PersistentVolume.
|
||||
|
||||
Misalnya, untuk GCE metrik tersebut adalah:
|
||||
|
||||
```
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "instance_list"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "disk_insert"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "disk_delete"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "attach_disk"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "detach_disk"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "list_disk"}
|
||||
```
|
||||
|
||||
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
* Baca tentang [format teks Prometheus](https://github.com/prometheus/docs/blob/master/content/docs/instrumenting/exposition_formats.md#text-based-format) untuk berbagai metrik
|
||||
* Lihat daftar [metrik Kubernetes yang _stable_](https://github.com/kubernetes/kubernetes/blob/master/test/instrumentation/testdata/stable-metrics-list.yaml)
|
||||
* Baca tentang [kebijakan _deprecation_ Kubernetes](https://kubernetes.io/docs/reference/using-api/deprecation-policy/#deprecating-a-feature-or-behavior )
|
||||
|
||||
@@ -0,0 +1,166 @@
|
||||
---
|
||||
title: Metrik untuk Komponen Sistem Kubernetes
|
||||
content_type: concept
|
||||
weight: 60
|
||||
---
|
||||
|
||||
<!-- overview -->
|
||||
|
||||
Metrik dari komponen sistem dapat memberikan gambaran yang lebih baik tentang apa
|
||||
yang sedang terjadi di dalam sistem. Metrik sangat berguna untuk membuat dasbor (_dashboard_)
|
||||
dan peringatan (_alert_).
|
||||
|
||||
Komponen Kubernetes mengekspos metrik dalam [format Prometheus](https://prometheus.io/docs/instrumenting/exposition_formats/).
|
||||
Format ini berupa teks biasa yang terstruktur, dirancang agar orang dan mesin dapat membacanya.
|
||||
|
||||
<!-- body -->
|
||||
|
||||
## Metrik-metrik dalam Kubernetes
|
||||
|
||||
Dalam kebanyakan kasus, metrik tersedia pada _endpoint_ `/metrics` dari server HTTP.
|
||||
Untuk komponen yang tidak mengekspos _endpoint_ secara bawaan, _endpoint_ tersebut dapat diaktifkan
|
||||
dengan menggunakan opsi `--bind-address`.
|
||||
|
||||
Contoh-contoh untuk komponen tersebut adalah:
|
||||
|
||||
* {{< glossary_tooltip term_id="kube-controller-manager" text="kube-controller-manager" >}}
|
||||
* {{< glossary_tooltip term_id="kube-proxy" text="kube-proxy" >}}
|
||||
* {{< glossary_tooltip term_id="kube-apiserver" text="kube-apiserver" >}}
|
||||
* {{< glossary_tooltip term_id="kube-scheduler" text="kube-scheduler" >}}
|
||||
* {{< glossary_tooltip term_id="kubelet" text="kubelet" >}}
|
||||
|
||||
Di dalam lingkungan produksi, kamu mungkin ingin mengonfigurasi [Server Prometheus](https://prometheus.io/)
|
||||
atau pengambil metrik (_metrics scraper_) lainnya untuk mengumpulkan metrik-metrik ini secara berkala
|
||||
dan membuatnya tersedia dalam semacam pangkalan data deret waktu (_time series database_).
|
||||
|
||||
Perlu dicatat bahwa {{< glossary_tooltip term_id="kubelet" text="kubelet" >}}
|
||||
juga mengekspos metrik pada _endpoint-endpoint_ seperti `/metrics/cadvisor`,
|
||||
`/metrics/resource` dan `/metrics/probes`. Metrik-metrik tersebut tidak memiliki
|
||||
siklus hidup yang sama.
|
||||
|
||||
Jika klastermu menggunakan {{< glossary_tooltip term_id="rbac" text="RBAC" >}},
|
||||
maka membaca metrik memerlukan otorisasi melalui _user_, _group_, atau
|
||||
ServiceAccount dengan ClusterRole yang memperbolehkan untuk mengakses `/metrics`.
|
||||
|
||||
Sebagai contoh:
|
||||
```yaml
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: prometheus
|
||||
rules:
|
||||
- nonResourceURLs:
|
||||
- "/metrics"
|
||||
verbs:
|
||||
- get
|
||||
```
|
||||
|
||||
## Siklus hidup metrik
|
||||
|
||||
Metrik alfa (_alpha_) → Metrik stabil → Metrik usang (_deprecated_) → Metrik tersembunyi → Metrik terhapus
|
||||
|
||||
Metrik alfa tidak memiliki jaminan stabilitas. Metrik ini
|
||||
dapat dimodifikasi atau dihapus kapan saja.
|
||||
|
||||
Metrik stabil dijamin tidak akan mengalami perubahan. Hal ini berarti:
|
||||
* Metrik stabil tanpa penanda usang (_deprecated signature_) tidak akan dihapus ataupun diganti namanya
|
||||
* Jenis metrik stabil tidak akan dimodifikasi
|
||||
|
||||
Metrik usang dijadwalkan untuk dihapus, tetapi masih tersedia untuk digunakan.
|
||||
Metrik ini mencakup anotasi versi di mana metrik ini dianggap menjadi usang.
|
||||
|
||||
Sebagai contoh:
|
||||
|
||||
* Sebelum menjadi usang
|
||||
|
||||
```
|
||||
# HELP some_counter this counts things
|
||||
# TYPE some_counter counter
|
||||
some_counter 0
|
||||
```
|
||||
|
||||
* Setelah menjadi usang
|
||||
|
||||
```
|
||||
# HELP some_counter (Deprecated since 1.15.0) this counts things
|
||||
# TYPE some_counter counter
|
||||
some_counter 0
|
||||
```
|
||||
|
||||
Metrik tersembunyi tidak lagi dipublikasikan untuk pengambilan metrik (_scraping_), tetapi masih tersedia untuk digunakan. Untuk menggunakan metrik tersembunyi, lihat bagian [Menampilkan metrik tersembunyi](#menampilkan-metrik-tersembunyi).
|
||||
|
||||
Metrik yang terhapus tidak lagi dipublikasikan dan tidak dapat digunakan lagi.
|
||||
|
||||
## Menampilkan metrik tersembunyi
|
||||
|
||||
Seperti yang dijelaskan di atas, admin dapat mengaktifkan metrik tersembunyi melalui opsi baris perintah pada biner (program) tertentu. Ini dimaksudkan untuk digunakan sebagai jalan keluar bagi admin jika mereka melewatkan migrasi metrik usang dalam rilis terakhir.
|
||||
|
||||
Opsi `show-hidden-metrics-for-version` menerima input versi yang kamu inginkan untuk menampilkan metrik usang dalam rilis tersebut. Versi tersebut dinyatakan sebagai x.y, di mana x adalah versi mayor, y adalah versi minor. Versi _patch_ tidak diperlukan meskipun metrik dapat menjadi usang dalam rilis _patch_, alasannya adalah kebijakan penandaan metrik usang dijalankan terhadap rilis minor.
|
||||
|
||||
Opsi tersebut hanya dapat menerima input versi minor sebelumnya sebagai nilai. Semua metrik yang disembunyikan di versi sebelumnya akan dikeluarkan jika admin mengatur versi sebelumnya ke `show-hidden-metrics-for-version`. Versi yang terlalu lama tidak diperbolehkan karena melanggar kebijakan untuk metrik usang.
|
||||
|
||||
Ambil metrik `A` sebagai contoh, di sini diasumsikan bahwa` A` sudah menjadi usang di versi 1.n. Berdasarkan kebijakan metrik usang, kita dapat mencapai kesimpulan berikut:
|
||||
|
||||
* Pada rilis `1.n`, metrik menjadi usang, dan dapat dikeluarkan secara bawaan.
|
||||
* Pada rilis `1.n+1`, metrik disembunyikan secara bawaan dan dapat dikeluarkan dengan baris perintah `show-hidden-metrics-for-version=1.n`.
|
||||
* Pada rilis `1.n+2`, metrik harus dihapus dari _codebase_. Tidak ada jalan keluar lagi.
|
||||
|
||||
Jika kamu meningkatkan versi dari rilis `1.12` ke `1.13`, tetapi masih bergantung pada metrik `A` yang usang di `1.12`, kamu harus mengatur metrik tersembunyi melalui baris perintah: `--show-hidden-metrics = 1.12` dan ingatlah untuk menghapus ketergantungan terhadap metrik ini sebelum meningkatkan versi rilis ke `1.14`.
|
||||
|
||||
## Menonaktifkan metrik akselerator
|
||||
|
||||
kubelet mengumpulkan metrik akselerator melalui cAdvisor. Untuk mengumpulkan metrik ini, untuk akselerator seperti GPU NVIDIA, kubelet membuka koneksi dengan _driver_ GPU. Ini berarti untuk melakukan perubahan infrastruktur (misalnya, pemutakhiran _driver_), administrator klaster perlu menghentikan agen kubelet.
|
||||
|
||||
Pengumpulkan metrik akselerator sekarang menjadi tanggung jawab vendor dibandingkan kubelet. Vendor harus menyediakan sebuah kontainer untuk mengumpulkan metrik dan mengeksposnya ke layanan metrik (misalnya, Prometheus).
|
||||
|
||||
[Gerbang fitur `DisableAcceleratorUsageMetrics`](/docs/reference/command-line-tools-reference/feature-gates/) menonaktifkan metrik yang dikumpulkan oleh kubelet, dengan [lini masa (_timeline_) untuk mengaktifkan fitur ini secara bawaan](https://github.com/kubernetes/enhancements/tree/411e51027db842355bd489691af897afc1a41a5e/keps/sig-node/1867-disable-accelerator-usage-metrics#graduation-criteria).
|
||||
|
||||
## Metrik komponen
|
||||
|
||||
### Metrik kube-controller-manager
|
||||
|
||||
Metrik _controller manager_ memberikan gambaran penting
|
||||
tentang kinerja dan kesehatan _controller manager_. Metrik ini mencakup metrik
|
||||
_runtime_ bahasa Go yang umum seperti jumlah go_routine dan metrik khusus
|
||||
pengontrol seperti latensi permintaan etcd atau latensi API Cloudprovider
|
||||
(AWS, GCE, OpenStack) yang dapat digunakan untuk mengukur kesehatan klaster.
|
||||
|
||||
Mulai dari Kubernetes 1.7, metrik Cloudprovider yang detail tersedia untuk
|
||||
operasi penyimpanan untuk GCE, AWS, Vsphere, dan OpenStack.
|
||||
Metrik ini dapat digunakan untuk memantau kesehatan operasi _persistent volume_.
|
||||
|
||||
Misalnya, untuk GCE metrik-metrik berikut ini dipanggil:
|
||||
|
||||
```
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "instance_list"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "disk_insert"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "disk_delete"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "attach_disk"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "detach_disk"}
|
||||
cloudprovider_gce_api_request_duration_seconds { request = "list_disk"}
|
||||
```
|
||||
|
||||
### Metrik kube-scheduler
|
||||
|
||||
{{< feature-state for_k8s_version="v1.20" state="alpha" >}}
|
||||
|
||||
Penjadwal mengekspos metrik opsional yang melaporkan sumber daya yang diminta dan limit yang diinginkan dari semua pod yang berjalan. Metrik ini dapat digunakan untuk membangun dasbor perencanaan kapasitas, mengevaluasi limit penjadwalan yang digunakan saat ini atau secara historis, dengan cepat mengidentifikasi beban kerja yang tidak dapat dijadwalkan karena kurangnya sumber daya, dan membandingkan permintaan sumber daya oleh pod dengan penggunaannya yang aktual.
|
||||
|
||||
kube-scheduler mengidentifikasi [permintaan dan limit](/docs/concepts/configuration/manage-resources-containers/) sumber daya yang dikonfigurasi untuk setiap Pod; jika permintaan atau limit bukan nol, kube-scheduler akan melaporkan deret waktu (_timeseries_) metrik. Deret waktu diberi label dengan:
|
||||
- namespace
|
||||
- nama pod
|
||||
- node di mana pod dijadwalkan atau _string_ kosong jika belum dijadwalkan
|
||||
- prioritas
|
||||
- penjadwal yang ditugaskan untuk pod itu
|
||||
- nama dari sumber daya (misalnya, `cpu`)
|
||||
- satuan dari sumber daya jika diketahui (misalnya, `cores`)
|
||||
|
||||
Setelah pod selesai (memiliki `restartPolicy` `Never` atau `OnFailure` dan berada dalam fase pod `Succeeded` atau `Failed`, atau telah dihapus dan semua kontainer dalam keadaan Terminated) deret metrik tidak lagi dilaporkan karena penjadwal sekarang sudah dibebaskan untuk menjadwalkan pod lain untuk dijalankan. Metrik yang dibahas pada bagian ini dikenal sebagai `kube_pod_resource_request` dan` kube_pod_resource_limit`.
|
||||
|
||||
Metrik diekspos melalui _endpoint_ HTTP `/metrics/resources` dan memerlukan otorisasi yang sama seperti endpoint `/metrics`
|
||||
pada penjadwal. Kamu harus menggunakan opsi `--show-hidden-metrics-for-version=1.20` untuk mengekspos metrik-metrik stabilitas alfa ini.
|
||||
|
||||
## {{% heading "whatsnext" %}}
|
||||
|
||||
* Baca tentang [format teks Prometheus](https://github.com/prometheus/docs/blob/master/content/docs/instrumenting/exposition_formats.md#text-based-format) untuk berbagai metrik
|
||||
* Baca tentang [kebijakan _deprecation_ Kubernetes](/docs/reference/using-api/deprecation-policy/#deprecating-a-feature-or-behavior)
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user