Compare commits

...

1743 Commits

Author SHA1 Message Date
Kubernetes Prow Robot 767215ff3c Merge pull request #32479 from jihoon-seo/220325_Update_links_1.22-ko.4
[ko] Update links in `dev-1.22-ko.4`
2022-03-25 00:19:50 -07:00
Jihoon Seo d42829f16e [ko] Update links in dev-1.22-ko.4 2022-03-25 11:52:36 +09:00
Kubernetes Prow Robot 9d70f6a818 Merge pull request #31774 from inerplat/fix/pv_access_modes
[ko] fix description of the access mode of pv
2022-02-18 01:38:23 -08:00
DH Kim 7032cbd36c [ko] fix description of the access mode of pv 2022-02-18 14:23:19 +09:00
Kubernetes Prow Robot 8d983ba5f0 Merge pull request #31417 from jihoon-seo/220120_ko_Update_links_in_dev-1.22-ko.4
[ko] Update links in `dev-1.22-ko.4`
2022-01-20 16:53:59 -08:00
Kubernetes Prow Robot 1f256b0498 Merge pull request #31416 from jihoon-seo/220120_ko_Update_type-nodeport_anchor
[ko] Update anchor (type-nodeport)
2022-01-20 16:51:59 -08:00
Jihoon Seo 1e2ba97595 [ko] Update links in dev-1.22-ko.4 2022-01-20 18:51:30 +09:00
Jihoon Seo ca96b1a14d [ko] Update anchor (type-nodeport) 2022-01-20 18:41:34 +09:00
Kubernetes Prow Robot 5cc8f3da14 Merge pull request #30851 from jihoon-seo/211210_Outdated_M27-M33
[ko] Update outdated files in dev-1.22-ko.4 (M27-M33)
2022-01-20 01:33:51 -08:00
Jihoon Seo bd70b604e2 [ko] Update outdated files in dev-1.22-ko.4 M27-33 2022-01-14 17:21:08 +09:00
Kubernetes Prow Robot eb89208739 Merge pull request #30852 from jihoon-seo/211210_Outdated_M34-M42
[ko] Update outdated files in dev-1.22-ko.4 (M34-M42)
2022-01-13 23:52:28 -08:00
Kubernetes Prow Robot fde5db81d7 Merge pull request #30892 from jihoon-seo/211213_Outdated_M43
[ko] Update outdated files in dev-1.22-ko.4 (M43-M55)
2022-01-13 22:12:28 -08:00
Jihoon Seo 7d020244e7 [ko] Update outdated files in dev-1.22-ko.4 M43-55 2022-01-14 11:08:01 +09:00
Kubernetes Prow Robot dda55048cd Merge pull request #31146 from jihoon-seo/211230_ko_Update_ingress.md
[ko] Update `ingress.md` in `dev-1.22-ko.4`
2022-01-11 22:26:36 -08:00
Kubernetes Prow Robot 2663de6b83 Merge pull request #30848 from jihoon-seo/211210_Outdated_M1-M9
[ko] Update outdated files in dev-1.22-ko.4 (M1-M11)
2022-01-09 19:11:11 -08:00
Jihoon Seo 563575b33b [ko] Update ingress.md in dev-1.22-ko.4 2021-12-30 18:00:29 +09:00
Kubernetes Prow Robot 7e07310275 Merge pull request #30893 from jihoon-seo/211213_Outdated_M56
[ko] Update outdated files in dev-1.22-ko.4 (M56-M70)
2021-12-29 23:50:50 -08:00
Jihoon Seo 6fc5dff87b [ko] Update outdated files in dev-1.22-ko.4 M56-70 2021-12-30 11:04:35 +09:00
Jihoon Seo f7e1a9f9f6 [ko] Update outdated files in dev-1.22-ko.4 M1-M11 2021-12-13 13:48:27 +09:00
Jihoon Seo 8171fd069c [ko] Update outdated files in dev-1.22-ko.4 M34-42 2021-12-10 19:19:08 +09:00
Kubernetes Prow Robot 854318acaa Merge pull request #30850 from jihoon-seo/211210_Outdated_M12-M26
[ko] Update outdated files in dev-1.22-ko.4 (M12-M26)
2021-12-10 00:57:10 -08:00
Jihoon Seo 2ee31ae39c [ko] Update outdated files in dev-1.22-ko.4 M12-26 2021-12-10 17:23:34 +09:00
Kubernetes Prow Robot 37e625e28c Merge pull request #30780 from jlbutler/update-122-config-for-123
update release-1.22 config for release 1.23
2021-12-07 15:57:22 -08:00
Jesse Butler d3298e927b update release-1.22 config for release 1.23 2021-12-06 18:10:14 -05:00
Kubernetes Prow Robot aa2f69c15f Merge pull request #30756 from waynerv/patch-2
fix typo in reference/setup-tools/kubeadm/implementation-details.md
2021-12-06 08:34:32 -08:00
Kubernetes Prow Robot d6865d1a1f Merge pull request #30712 from funkypenguin/issue30661
Fix auditing example to permit log rotation
2021-12-06 06:04:32 -08:00
Waynerv c2b5d6041f fix typo 2021-12-06 18:51:21 +08:00
Kubernetes Prow Robot b904695d10 Merge pull request #30755 from fenggw-fnst/update-volume-snapshots
[zh] Update volume-snapshots.md
2021-12-06 02:38:33 -08:00
Guangwen Feng 556d37b312 [zh] Update volume-snapshots.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-12-06 15:11:14 +08:00
Kubernetes Prow Robot 5014b9377a Merge pull request #30749 from kubernetes/dev-1.22-ko.3
[ko] 3rd Korean localization work for v1.22
2021-12-05 21:16:33 -08:00
Kubernetes Prow Robot e6359e23b1 Merge pull request #30524 from jihoon-seo/211117_Update_outdated_files_in_dev-1.22-ko.3_M19-M26
[ko] Update outdated files in dev-1.22-ko.3 (M19-M26)
2021-12-05 20:44:33 -08:00
Kubernetes Prow Robot fdac57e01c Merge pull request #30346 from sureshdsk/sureshdsk-patch-1
Update parallel-processing-expansion.md
2021-12-05 20:40:32 -08:00
Kubernetes Prow Robot 200c6cadeb Merge pull request #30501 from dialogbox/patch-1
Update manage-resources-containers.md
2021-12-05 20:16:32 -08:00
Kubernetes Prow Robot 524e61c17a Merge pull request #30457 from umairadeeb/patch-1
Kubelet accepts graceful node shutdown parameters in camel case while they are written in the document in pascal case
2021-12-05 20:14:32 -08:00
Erico Fusco f04516f995 Update kubeadm-upgrade.md (#30135)
* Update kubeadm-upgrade.md

`apt-mark hold` is still required when `apt-get` is used with `--allow-change-held-packages`.

`--allow-change-held-packages` unholds the package but it doesn't pin the new version.

* Add missing changes

* Update kubeadm-upgrade.md

Remove apt >1.1 examples.
2021-12-05 20:12:32 -08:00
Kubernetes Prow Robot 440409e8b1 Merge pull request #29663 from abhibhaw/issue-29524
feat: Documents effects on secrets when memory swap is enabled
2021-12-05 20:10:32 -08:00
Kubernetes Prow Robot a3c6627798 Merge pull request #30125 from chirangaalwis/patch-4
Combine Service Account to Map with Resource Type
2021-12-05 20:08:32 -08:00
Kubernetes Prow Robot b640a95056 Merge pull request #30371 from reylejano/update-about-blogs
Add line about contributor blogs should go to kubernetes.dev on the blog-case-studies page
2021-12-05 20:06:32 -08:00
Kubernetes Prow Robot c9fb665413 Merge pull request #30741 from ptux/patch-10
[en] Update admission-controllers.md
2021-12-05 20:04:32 -08:00
Brandon Smith 1c90494c38 1.22 Windows HostProcess containers update (#30699)
* Transferred applicable modifications for 1.23 over to 1.22.

* kublet -> kubelet

* Update content/en/docs/tasks/configure-pod-container/create-hostprocess-pod.md

Co-authored-by: Mark Rossetti <marosset@microsoft.com>

Co-authored-by: Mark Rossetti <marosset@microsoft.com>
2021-12-05 20:02:33 -08:00
Meha Bhalodiya 798aae5127 Fix a few grammar issues and typos (#28387)
* Fix a few grammar issues and typos

* Minor changes
2021-12-05 19:50:32 -08:00
Kubernetes Prow Robot 4187c652f8 Merge pull request #29152 from tiraboschi/crd_edit_status
Concretely explain how to patch CRD status
2021-12-05 19:24:32 -08:00
Kubernetes Prow Robot 24c84387ac Merge pull request #29078 from vaibhav2107/cluster-services
Remove the duplicate content from access-cluster.md
2021-12-05 19:22:32 -08:00
Kubernetes Prow Robot e2eff1fa69 Merge pull request #29686 from rguichard/blog-en/fix-typo
fix(blog): RWX access mode is about nodes, not pods
2021-12-05 18:02:33 -08:00
Kubernetes Prow Robot 8efdd0c9c1 Merge pull request #29716 from Nordix/pod-topology-spread
Updates in pod-topology-spread-constraints.md
2021-12-05 18:00:32 -08:00
Kubernetes Prow Robot 63db6dbf66 Merge pull request #29717 from jonassteinberg1/patch-1
add 'the' to 'without restarting [the] API server' from Static Token …
2021-12-05 17:56:32 -08:00
Kubernetes Prow Robot 1b95b8b60d Merge pull request #29719 from sftim/20210915_document_node_problem_detector_add_on
Add node problem detector to add-ons
2021-12-05 17:54:35 -08:00
Kubernetes Prow Robot 246d261529 Merge pull request #29841 from pacoxu/patch-7
Add safe sysctl net.ipv4.ip_unprivileged_port_start
2021-12-05 17:46:32 -08:00
Kubernetes Prow Robot 1664e4e4c4 Merge pull request #29964 from MikeSpreitzer/fix-105494
Improve API Priority and Fairness for clients
2021-12-05 17:32:32 -08:00
prameshj 63420166a1 Update docs to clarify the dns configmap format. (#29988)
* Update docs to clarify the dns configmap format.

* Update content/en/docs/tasks/administer-cluster/nodelocaldns.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-12-05 17:28:32 -08:00
Kubernetes Prow Robot 307252f513 Merge pull request #29985 from stormqueen1990/update-secret-text
[en] Clarify secret encryption in the glossary
2021-12-05 17:26:33 -08:00
Mohit Sharma 1660298346 fixed the list container images by pod section (#30207)
Signed-off-by: Mohit Sharma <imoisharma@icloud.com>
2021-12-05 17:18:32 -08:00
Kubernetes Prow Robot a6f6f7d9d9 Merge pull request #30213 from avinashupadhya99/fix-deployment-rollout-pause-resume-wordings
Improvement for k8s.io/docs/concepts/workloads/controllers/deployment/ pause rollout wordings
2021-12-05 16:58:32 -08:00
Kubernetes Prow Robot 8abfbc924e Merge pull request #30210 from voor/pod-topology-spread-constraints-fix-formatting-example
Pod Topology Spread Constraints: Resolve formatting issue and add example for node affinity example.
2021-12-05 16:36:32 -08:00
Wang 8a8f9c40f9 Update admission-controllers.md 2021-12-06 09:16:27 +09:00
Kubernetes Prow Robot 44ef715019 Merge pull request #30673 from gbarceloPIB/patch-1
Kubectl command waits until init containers terminated
2021-12-05 15:44:32 -08:00
Kubernetes Prow Robot 5eede16691 Merge pull request #30730 from sftim/20211404_link_to_page_about_help_and_good_first_issues
Link to https://k8s.dev/ docs about good first issues
2021-12-05 15:32:32 -08:00
Kubernetes Prow Robot 4d7746fc1b Merge pull request #29901 from sftim/20211003_fix_announcement_background
Fix gradient background rendering for announcements
2021-12-05 15:22:32 -08:00
Ayushman 3f91237afc changed links from beta2-beta3 (#30059)
Signed-off-by: Ayushman <ayushvidushi01@gmail.com>
2021-12-05 15:20:32 -08:00
Kubernetes Prow Robot fbf753d35e Merge pull request #29906 from sftim/20211003_fix_cid_class_logic
Fix logic for setting cid-* classes
2021-12-05 15:18:32 -08:00
Suvro a0c6f3fd6f Replaced annotation with ingressClassName (#30171)
* Replaced annotation with ingressClassName

Updated content of https://kubernetes.io/docs/concepts/services-networking/ingress-controllers/#using-multiple-ingress-controllers
with ingressClassName which replaces annotations

Signed-off-by: Suvro Ghosh <sughosh@redhat.com>

* Update content/en/docs/concepts/services-networking/ingress-controllers.md

Co-authored-by: Deepak Gupta <deepakgdkg1g8868@gmail.com>

Co-authored-by: Deepak Gupta <deepakgdkg1g8868@gmail.com>
2021-12-05 15:14:32 -08:00
Kubernetes Prow Robot d2d722ae30 Merge pull request #30223 from slayer321/add-volume-example
docs: add PV duplicate example
2021-12-05 15:12:32 -08:00
prabhsimransingh 5f369513e0 Fixing kubectl cheatsheet run command comment to be more accurate (#29879)
* Fixing kubectl cheatsheet run command comment to be more accurate

* remove new line
2021-12-05 15:10:32 -08:00
Kubernetes Prow Robot 6ce3307738 Merge pull request #30690 from hangyan/patch-1
Remove kompose up and down command doc
2021-12-05 14:58:32 -08:00
Kubernetes Prow Robot bbeb5184a7 Merge pull request #29739 from jtslear/jts/recommend-hpa-config
Add recommendation for Deployment when HPA is enabled
2021-12-05 14:56:32 -08:00
Kubernetes Prow Robot 097bf85ed8 Merge pull request #30722 from amandapunch/update-kubecon-date
Update date to mention KubeCon NA 2022
2021-12-05 12:08:32 -08:00
Kubernetes Prow Robot ec41959cc1 Merge pull request #30134 from ixodie/patch-10
Removing GCE bridging/routing config tweaks
2021-12-05 12:06:32 -08:00
Kubernetes Prow Robot 04d4d3e86b Merge pull request #30517 from sftim/20211117_reorder_storage_concepts
Reorder storage concepts
2021-12-05 11:56:32 -08:00
Kubernetes Prow Robot 163fae3fee Merge pull request #30736 from Arhell/update
[id] updated circtl version
2021-12-05 05:08:32 -08:00
Kubernetes Prow Robot acac2240e8 Merge pull request #30734 from chenxuc/authn-authz-2
[zh] sync auth for 1.22
2021-12-04 17:20:31 -08:00
Arhell 61d8c13028 [id] updated circtl version 2021-12-05 02:45:39 +02:00
chenxuc fdfa669e72 [zh] sync auth for 1.22 2021-12-04 20:36:19 +08:00
Tim Bannister 2087546633 Link to https://k8s.dev/ docs about good first issues
Where we mention the "help" or "good first issue" labels, let's
hyperlink to https://kubernetes.dev/docs/guide/help-wanted/ (our
official page on that topic).
2021-12-04 10:13:50 +00:00
amandapunch a3cfde913b Merge branch 'kubernetes:main' into update-kubecon-date 2021-12-03 15:21:37 -08:00
amandapunch 1a3e293393 Update chronological order and remove korean language updates 2021-12-03 15:16:38 -08:00
Kubernetes Prow Robot 4d519daf9b Merge pull request #30724 from fenggw-fnst/fix-server-side-apply
[zh] Add translation for the missing sentence
2021-12-03 05:32:26 -08:00
Guangwen Feng f6e8932b28 [zh] Add translation for the missing sentence
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-12-03 17:55:07 +08:00
amandapunch f7a9e0e729 update date to mention kubecon North America 2022 2021-12-02 20:51:16 -08:00
Jihoon Seo 27b24fd4b2 [ko] Update outdated files in dev-1.22-ko.3 19-26 2021-12-03 09:50:34 +09:00
Kubernetes Prow Robot 089d6ee918 Merge pull request #30108 from sftim/20211016_revise_dynamic_kubelet_config_task
Revise dynamic kubelet config task
2021-12-02 10:03:34 -08:00
Kubernetes Prow Robot 6b936f65ad Merge pull request #30714 from fenggw-fnst/update-policies
[zh] Update policies.md
2021-12-02 05:09:33 -08:00
Kubernetes Prow Robot 74ab4e5f41 Merge pull request #30663 from fenggw-fnst/update-health-checks
[zh] Update health-checks.md
2021-12-01 22:43:33 -08:00
Guangwen Feng 67bb302d80 [zh] Update policies.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-12-02 13:22:17 +08:00
Kubernetes Prow Robot b3219adc40 Merge pull request #29896 from jeefy/update-change-cause-docs
Add change-cause annotation to labels/annotations page
2021-12-01 18:55:33 -08:00
Kubernetes Prow Robot 378b0e50c9 Merge pull request #29915 from sftim/20211003_improve_recent_release_list
Improve recent release list
2021-12-01 18:39:33 -08:00
Kubernetes Prow Robot eb186c2f9e Merge pull request #30682 from bang9211/bang9211/ports-and-protocols/v0.1
[ko] Translate reference/ports-and-protocols.md in Korean
2021-12-01 18:35:32 -08:00
David Young 4f96e391b4 Fix auditing example
Signed-off-by: David Young <davidy@funkypenguin.co.nz>
2021-12-02 14:36:53 +13:00
Kubernetes Prow Robot 6058c6f8c6 Merge pull request #30708 from craigbox/em-dashes
Post-publication fixes to 1.22 release interview post
2021-12-01 15:23:17 -08:00
Craig Box d123775bbe Emdashen 2021-12-02 12:05:31 +13:00
Kubernetes Prow Robot d654529ae1 Merge pull request #30688 from craigbox/master
Add release interview for 1.22
2021-12-01 13:51:17 -08:00
Craig Box 5441cfe431 Fix nit per review 2021-12-02 07:28:10 +13:00
Kubernetes Prow Robot 81389449f1 Merge pull request #29845 from RinkiyaKeDad/pr_wrangller_fix
adding info about tagging SIGs in pr wrangling guide
2021-12-01 06:07:16 -08:00
Kubernetes Prow Robot f20b27e539 Merge pull request #30094 from ixodie/patch-9
Remove Open vSwitch from “How to implement the Kubernetes networking model”
2021-12-01 04:23:16 -08:00
Kubernetes Prow Robot 819d7c8289 Merge pull request #30657 from SataQiu/fix-kubeadm-20211128
kubeadm: add instructions about rebalancing CoreDNS Pods after joining more nodes
2021-12-01 04:21:14 -08:00
SataQiu 344aa15779 kubeadm: add instructions about rebalancing CoreDNS Pods after joining more nodes 2021-12-01 18:14:12 +08:00
Kubernetes Prow Robot be94f3ff50 Merge pull request #30667 from fenggw-fnst/update-install-kubectl-macos
[zh] Update install-kubectl-macos.md
2021-11-30 22:57:17 -08:00
Kubernetes Prow Robot 1554a30155 Merge pull request #30666 from fenggw-fnst/update-install-kubectl-windows
[zh] Update install-kubectl-windows.md
2021-11-30 22:55:17 -08:00
Kubernetes Prow Robot b3a36f6769 Merge pull request #30668 from fenggw-fnst/update-install-kubectl-linux
[zh] Update install-kubectl-linux.md
2021-11-30 22:51:17 -08:00
Kubernetes Prow Robot 4afed8f01f Merge pull request #30664 from ashish-jaiswar/NewBranch
updated setup-konnectivity.md page
2021-11-30 22:09:17 -08:00
Wang 0693d2b240 [zh] Update custom-resources.md (#30408)
* Update custom-resources.md

* Update custom-resources.md
2021-11-30 19:05:17 -08:00
Kubernetes Prow Robot 50162729d9 Merge pull request #30665 from h4ghhh/etcd_client_cert_zh
[zh] Fix the etcd client certs
2021-11-30 19:03:17 -08:00
Kubernetes Prow Robot 7111cac189 Merge pull request #30659 from Arhell/upd
[pt-br] updated circtl version
2021-11-30 18:25:18 -08:00
Kubernetes Prow Robot 6d4f278716 Merge pull request #30683 from h4ghhh/fix_etcd_restore_zh
[zh] Add an example for restoring etcd cluster
2021-11-30 17:39:17 -08:00
Craig Box 42597a0162 Tone down the humour 2021-12-01 13:53:59 +13:00
Craig Box 61edd87d8a Spelling and grammar fixes 2021-12-01 12:42:50 +13:00
John T Skarbek df3184bd52 Add recommendation for Deployment when HPA is enabled
* Advertise that we need to remove `spec.replicas` when a Horizontal Pod
  Autoscaler is active to prevent unnecessary changes in Pod counts during
  Deployment object changes
* Make note that a Deployment that has this value set behave awkwardly if a
  Deployment is scaled manually outside of the Deployment object

Signed-off-by: John T Skarbek <jtslear@gmail.com>
2021-11-30 18:37:10 -05:00
Craig Box 55bb7d2912 Second draft 2021-12-01 12:28:18 +13:00
bang9211 13c18873e1 Translate reference/ports-and-protocols.md in Korean 2021-12-01 08:14:10 +09:00
Craig Box ce2092a123 Review fixes 2021-12-01 11:13:04 +13:00
Hang Yan 56035c1f8c Remove kompose up and down command doc
kompose has drop support for `up` and `down` subcommand since v1.22.0.
Also update kompose versions
2021-11-30 23:19:13 +08:00
Jihoon Seo 2f4e2f56d0 Fix wrong /security redirection (#30684)
* Fix wrong redirections

* Add/Modify redirection rules

* Use a 302 redirect for shortened URL

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-11-30 03:34:56 -08:00
Craig Box 3fc912e791 First draft of blog for submission 2021-11-30 21:54:49 +13:00
Ashish jaiswar b546825c32 Update content/en/docs/tasks/extend-kubernetes/setup-konnectivity.md
Co-authored-by: Meha Bhalodiya <mehabhalodiya@gmail.com>
2021-11-30 13:22:22 +05:30
00255991 3314d313bd [zh] Add an example for restoring etcd cluster 2021-11-30 10:22:58 +08:00
h4ghhh 4448cdd097 Update content/zh/docs/tasks/administer-cluster/configure-upgrade-etcd.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-11-30 09:38:04 +08:00
Kubernetes Prow Robot 0ed0a0cce5 Merge pull request #30110 from sftim/20211016_add_now_delete_to_cheat_sheet
Add immediate pod deletion to cheat sheet
2021-11-29 17:04:57 -08:00
Kubernetes Prow Robot 0f4eb182c5 Merge pull request #30430 from Shubham82/Correct-link-Authorization
Improvement: Corrected the link for Authorization.
2021-11-29 16:38:56 -08:00
gbarceloPIB 6cb934ba19 Update pod-lifecycle.md 2021-11-29 13:59:13 +01:00
sandipanpanda 269dad43a0 Fix broken link of Install Docker Engine - Enterprise on Windows Servers (#30105)
* Fix the broken link of Install Docker Engine

Fix the broken link of Install Docker Engine - Enterprise on Windows Servers. Updated the redirect URL from https://hub.docker.com/editions/enterprise/docker-ee-server-windows to https://docs.microsoft.com/en-us/virtualization/windowscontainers/quick-start/set-up-environment?tabs=Windows-Server#install-docker

* Fix the broken link of Install Docker Engine

* Fix the broken link of Install Docker Engine

* Update adding-windows-nodes.md

* Update adding-windows-nodes.md
2021-11-29 01:09:22 -08:00
Kubernetes Prow Robot 73f7c7ae32 Merge pull request #30605 from cpanato/dev-21-cycle
patches: update patch release calendar for December/21 cycle
2021-11-29 00:37:22 -08:00
Guangwen Feng 0e0e36d0ec [zh] Update install-kubectl-linux.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-29 14:10:27 +08:00
00255991 547ca752e6 [zh] Fix the etcd client certs 2021-11-29 14:00:05 +08:00
Guangwen Feng 735327e888 [zh] Update install-kubectl-macos.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-29 13:58:39 +08:00
Guangwen Feng 06abbb5e1b [zh] Update install-kubectl-windows.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-29 13:46:35 +08:00
Kubernetes Prow Robot 457eb7b61d Merge pull request #30616 from fenggw-fnst/fix-command-output
[zh] Fix the output of "kubectl get deployment"
2021-11-28 21:09:22 -08:00
ashish-jaiswar edc96615a6 updated setup-konnectivity.md 2021-11-29 10:11:47 +05:30
Guangwen Feng 6dd87665bf [zh] Update health-checks.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-29 11:38:38 +08:00
Arhell 3f9f20178b [pt-br] updated circtl version 2021-11-29 00:28:59 +02:00
halfC 2c6a411fde [zh] typo Update images.md (#30545)
* Update images.md

typo

* sync en docs

* [zh] translate images.md

[zh] translate interpretation of config.json images.md

* [zh] modify the wording in images.md

* [zh] remove origin english in images.md

* [zh] del extra # in images.md

* [zh] del origin english in images.md
2021-11-28 04:23:21 -08:00
Kubernetes Prow Robot 1c8a9291e8 Merge pull request #30617 from fenggw-fnst/update-horizontal-pod-autoscale-walkthrough
[zh] Update horizontal-pod-autoscale-walkthrough.md
2021-11-28 04:21:22 -08:00
Kubernetes Prow Robot 44412a352b Merge pull request #30643 from xzyangNB/main
Delete redundant 。in /zh/docs/setup/_index.md
2021-11-28 03:39:21 -08:00
Tim Bannister 4dc09070ee Improve recent release list
- fix unwanted trailing separator
- better styling for the items
- more semantic markup (also enables improved CSS)
2021-11-27 18:42:11 +00:00
Kubernetes Prow Robot 5cad9834f7 Merge pull request #28626 from sandipb/patch-1
dns-pod-service.md: Fix unqualified host search ex
2021-11-27 10:38:40 -08:00
Tim Bannister c0c3d040f8 Add node problem detector to add-ons 2021-11-27 18:37:48 +00:00
Tim Bannister 5799a8cd48 Add immediate pod deletion to cheat sheet 2021-11-27 18:20:19 +00:00
Tim Bannister c043aca0dc Tidy page 2021-11-27 18:19:40 +00:00
Tim Bannister 282bc9187c Revise what's next section 2021-11-27 18:19:40 +00:00
Kubernetes Prow Robot 946bfef940 Merge pull request #30650 from saygenie/saygenie/fix-bullet-indent
[ko] Fix the wrong indent for bullet list
2021-11-26 21:04:40 -08:00
Sejin Kim 55bcd4ec4b Fix the wrong indent for bullet list 2021-11-27 00:01:46 +09:00
Kubernetes Prow Robot b6352610cf Merge pull request #30520 from jihoon-seo/211117_Update_outdated_files_in_dev-1.22-ko.3_M28-M38
[ko] Update outdated files in dev-1.22-ko.3 (M28-M38)
2021-11-26 06:18:51 -08:00
Kubernetes Prow Robot f3bfa4379f Merge pull request #30642 from jihoon-seo/211126_Update_outdated_in_dev-1.22-ko.3_M9-M18
[ko] Update outdated files in dev-1.22-ko.3 (M9-M18)
2021-11-26 06:16:52 -08:00
Kubernetes Prow Robot b69f55a27b Merge pull request #30630 from bang9211/bang9211/install-service-catalog-using-sc/v0.2
[ko] Translate tasks/service-catalog/install-service-catalog-using-sc.md in Korean
2021-11-26 06:06:52 -08:00
Kubernetes Prow Robot a9e0d4f3f1 Merge pull request #30473 from seokho-son/out-ko.3-m1
[ko] Fix outdated in ko architecture/nodes
2021-11-26 06:04:51 -08:00
Kubernetes Prow Robot 129b15b0a3 Merge pull request #30631 from Babapool/fix-metadata
Correcting the docs for label kubernetes.io/metadata.name
2021-11-26 01:04:52 -08:00
Kubernetes Prow Robot a9a08ac18b Merge pull request #30644 from xiaoxubeii/fix-containerd-version
Fix containerd version typo in /en/blog/_posts/2021-11-26-memory-qos-cgroups-v2/index.md
2021-11-26 00:26:52 -08:00
xiaoxubeii f183a65cfe Fix containerd version typo 2021-11-26 15:41:24 +08:00
xzyangNB bd68246227 Delete redundant ‘。’ in /zh/docs/setup/_index.md 2021-11-26 14:10:03 +08:00
Jihoon Seo abc7aa0e8b [ko] Update outdated files in dev-1.22-ko.3 M9-18 2021-11-26 14:08:29 +09:00
Vitthal Sai 2ae0496450 Added mention of the K8s API Server 2021-11-25 23:27:12 +05:30
Kubernetes Prow Robot fe2b4047db Merge pull request #30264 from doughgle/patch-2
Clarify why cordon all but 4 nodes.
2021-11-25 06:54:34 -08:00
Kubernetes Prow Robot c3963990dc Merge pull request #30637 from jihoon-seo/211125_Update_outdated_in_dev-1.22-ko.3_M4-M8
[ko] Update outdated files in dev-1.22-ko.3 (M4-M8)
2021-11-25 04:34:33 -08:00
Kubernetes Prow Robot 44a3025b52 Merge pull request #30628 from 243f6a8885a308d313198a2e037/patch-1
fix: typos in health-checks.md
2021-11-25 03:10:33 -08:00
Jihoon Seo 5961160ac2 [ko] Update outdated files in dev-1.22-ko.3 M4-M8 2021-11-25 19:25:15 +09:00
243f6a88 85a308d3 af2a60b57f fix: typo in health-checks.md 2021-11-25 19:00:41 +09:00
Robot Jelly fbe2194d5b added line separation in kubectl page (#30359)
* added line separation in kubectl page

added line separation in kubectl page - 2

added line separation in kubectl page - 3 added space at ends

final changes

added spaces at end

* removed Line-549 from end of the file

* added Line-548 at the end of file
2021-11-25 01:26:33 -08:00
Vitthal Sai 82c3a0785d Incorporated the suggested feedback 2021-11-25 14:47:29 +05:30
Kubernetes Prow Robot 020cbc46b0 Merge pull request #30586 from wiggitywhitney/concepts-pdb
Clarify PDB line in disruptions concept page
2021-11-24 23:22:33 -08:00
Vitthal Sai 1f34679e9f Correcting the docs for label kubernetes.io/metadata.name 2021-11-25 12:29:18 +05:30
bang9211 506fede20c Translate tasks/service-catalog/install-service-catalog-using-sc.md in Korean 2021-11-25 15:40:19 +09:00
Kubernetes Prow Robot 133012d517 Merge pull request #30618 from fenggw-fnst/update-hello-minikube
[zh] Update hello-minikube.md
2021-11-24 16:34:33 -08:00
Kubernetes Prow Robot c02a0715e1 Merge pull request #29015 from rajula96reddy/memory-qos
1.22 feature blog for memory qos support with cgroups v2
2021-11-24 15:39:32 -08:00
Tim Bannister f71bc6d90a Fix punctuation nit 2021-11-24 23:28:06 +00:00
Tim Bannister bfb6fd44d0 Update article publication date 2021-11-24 23:27:07 +00:00
Kubernetes Prow Robot e117ed71cc Merge pull request #30103 from ramrodo/gh-13948-translate-es-init-containers
[es] Add content/es/docs/concepts/workloads/pods/init-containers.md
2021-11-24 12:19:32 -08:00
Jason Kim (Jun Chul Kim) add3441154 Update manage-resources-containers.md
Warn people about mistaking "M" suffix for "m" when setting resource limits #30499
2021-11-24 23:11:27 +09:00
Kubernetes Prow Robot 26d2200d13 Merge pull request #30615 from Arhell/update
[fr] updated circtl version
2021-11-24 04:46:20 -08:00
Kubernetes Prow Robot dc68cebdb8 Merge pull request #30375 from mfilocha/pl-sync-1.22.a5
Synchronize Polish localization for ver 1.22, part 5
2021-11-24 04:34:20 -08:00
Kubernetes Prow Robot f20afa3bd2 Merge pull request #30598 from Babapool/add-kui
Create an entry that describes the Kui tool within docs
2021-11-24 03:14:20 -08:00
Vitthal Sai fddb61757e Added content for better phrasing as suggested 2021-11-24 16:36:37 +05:30
Guangwen Feng 4edccb8044 [zh] Update hello-minikube.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-24 11:13:46 +08:00
Guangwen Feng c6c4a709bd [zh] Update horizontal-pod-autoscale-walkthrough.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-24 10:26:59 +08:00
Guangwen Feng 972711149b [zh] Fix the output of "kubectl get deployment"
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-24 09:52:09 +08:00
Arhell c61eccb64c [fr] updated circtl version 2021-11-24 02:41:45 +02:00
Kubernetes Prow Robot 38459dcdfb Merge pull request #30603 from fenggw-fnst/update-kubectl
[zh] Update kubectl.md
2021-11-23 16:38:20 -08:00
Daniel Weibel 8c5c7de4a9 Change 'container' to 'Pod' in Jobs documentation (#30592)
* Fix wording in Jobs documentation

* Apply change in Chinese text
2021-11-23 16:30:20 -08:00
Kubernetes Prow Robot 73ae0f84d2 Merge pull request #30610 from budhirajamadhav/patch-1
Remove extra bracket
2021-11-23 15:03:45 -08:00
Madhav Budhiraja 2ff1bffa3d Remove extra bracket 2021-11-23 23:56:41 +05:30
Shubham Kuchhal 349be77566 Improvement for Authorization in Extending Kubernetes docs.
Improvement: Corrected the link for Authorization.

Fix Typo
2021-11-23 16:49:02 +05:30
Carlos Panato 0810f31204 patches: update patch release calendar for December/21 cycle
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-11-23 09:20:16 +01:00
Guangwen Feng 2b6b6cfa50 [zh] Update kubectl.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-23 15:01:58 +08:00
Kubernetes Prow Robot 1c31b83f9d Merge pull request #30294 from bradbeck/zsh-completion
Fix zsh completion setup
2021-11-22 18:14:16 -08:00
Kubernetes Prow Robot 62bccf0712 Merge pull request #30599 from budhirajamadhav/pr-repair-obsolote-link-sigdocsagenda
Fix obsolete link to Sig docs agenda doc
2021-11-22 18:12:16 -08:00
Kubernetes Prow Robot 2363c92474 Merge pull request #28701 from rajeshdeshpande02/add-cp-command
Adding kubectl cp command examples in the cheat sheet
2021-11-22 17:56:16 -08:00
Kubernetes Prow Robot 8b9ed000f2 Merge pull request #28218 from kelvinn/patch-2
Fix incorrect command
2021-11-22 17:48:16 -08:00
Kubernetes Prow Robot 85d4742e75 Merge pull request #30543 from fossilet/patch-1
Fix shell misquote.
2021-11-22 17:34:16 -08:00
liuzhilin12 fb797d6072 [zh] Translate Reference/glossary/pod-disruption (#30546)
* Translate Reference/glossary/pod-disruption

* translate reference/glossary/pod-disruption page

* Translate Reference/glossary/pod-disruption

* Translate Reference/glossary/pod-disruption

* Translate Reference/glossary/pod-disruption
2021-11-22 16:32:16 -08:00
budhirajamadhav fbeab275d0 Fix obsolete link to sig docs agenda doc 2021-11-23 03:12:10 +05:30
Vitthal Sai a6ba36764d Create an entry that describes the Kui tool within docs 2021-11-23 02:01:43 +05:30
Seokho Son c8deb047c2 Merge branch 'dev-1.22-ko.3' into out-ko.3-m1 2021-11-23 02:45:15 +09:00
Kubernetes Prow Robot 0fcaddc0c9 Merge pull request #30485 from jihoon-seo/211115_ko_Update_links_in_dev-1.22-ko.3
[ko] Update links in dev-1.22-ko.3
2021-11-22 04:15:09 -08:00
Kubernetes Prow Robot 162d7bcd50 Merge pull request #30589 from fenggw-fnst/update-implementation-details
[zh] Update implementation-details.md
2021-11-22 04:05:09 -08:00
Seokho Son d75f6f2a46 Rev-1 to be squashed 2021-11-22 21:02:47 +09:00
Guangwen Feng 180baaff7f [zh] Update implementation-details.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-22 17:47:13 +08:00
Kubernetes Prow Robot a05f047b99 Merge pull request #30587 from Arhell/remove
[zh] removed depracated ruby client library
2021-11-21 23:31:08 -08:00
wiggitywhitney 97495989fc Clarify PDB line in disruptions concept page 2021-11-21 18:39:54 -06:00
Arhell 9d13885b77 [zh] removed depracated ruby client library 2021-11-22 02:26:55 +02:00
Kubernetes Prow Robot 7714140cc6 Merge pull request #30500 from sysnet4admin/patch-5
Update managing-tls-in-a-cluster.md
2021-11-21 16:19:03 -08:00
Kubernetes Prow Robot bca3cdbf1d Merge pull request #30566 from wiggitywhitney/pdb-glossary
Clarify glossary entry for PodDisruptionBudget
2021-11-21 16:15:02 -08:00
wiggitywhitney c0a8fe5be2 Clarify glossary entry for PodDisruptionBudget 2021-11-21 17:11:05 -06:00
Kubernetes Prow Robot 0140ee7152 Merge pull request #30580 from Arhell/fix-typo
[zh] corrected grammatical error
2021-11-21 04:45:00 -08:00
Arhell d2ef6f9fa2 [zh] corrected grammatical error 2021-11-21 00:48:31 +02:00
Kubernetes Prow Robot 074e35836b Merge pull request #30573 from SijmenHuizenga/patch-1
Fix broken ref in services-networking/service.md
2021-11-20 08:49:00 -08:00
Kubernetes Prow Robot 000a9de46f Merge pull request #30559 from aravindhp/windows-projected-volume-follow-up
storage: Minor fixes to Windows projected volumes
2021-11-20 08:40:59 -08:00
Sijmen 20685c80c5 Fix broken ref in services-networking/service.md 2021-11-20 17:33:12 +01:00
Kubernetes Prow Robot 2b46eef739 Merge pull request #30568 from Arhell/upd
[zh] update pod mapping to avoid deprecation notice
2021-11-19 22:37:00 -08:00
Yongzhi Pan a5b097977f Fix misquote. 2021-11-20 09:35:31 +08:00
Arhell 2b40286fdd [zh] update pod mapping to avoid deprecation notice 2021-11-20 02:26:37 +02:00
Aravindh Puthiyaparambil 11f5db4461 storage: Minor fixes to Windows projected volumes
- Add missing period
- Link to projected volume permission KEP instead of PR
- Add missing PowerShell command
2021-11-19 12:58:42 -08:00
popomen be1deab0bf [zh] - docs/reference/command-line-tools-reference/kube-proxy.md (#30531)
* [zh] - docs/reference/command-line-tools-reference/kube-proxy.md

* [zh] - docs/reference/command-line-tools-reference/kube-apiserver.md

* [zh] - docs/reference/command-line-tools-reference/kube-controller-manager.md

* Fix some translation errors
2021-11-19 05:30:51 -08:00
Guangwen Feng 305384206d [zh] Update storage-classes.md (#30561)
* [zh] Update storage-classes.md

Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>

* [zh] Fix an invalid link in storage-classes.md

Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-19 04:54:51 -08:00
Kubernetes Prow Robot 48a2a132b7 Merge pull request #29478 from ravisantoshgudimetla/patch-12
Recommend using TTL field in job
2021-11-19 04:16:51 -08:00
Kubernetes Prow Robot 2040c81a31 Merge pull request #30525 from weibeld/main
Change 'container' to 'Pod' in Jobs documentation
2021-11-19 02:10:52 -08:00
Kubernetes Prow Robot 6d8c2b68af Merge pull request #30539 from Arhell/upd-app
[ja] update apparmor.md
2021-11-18 19:34:51 -08:00
Kubernetes Prow Robot 4064a3598d Merge pull request #30471 from Arhell/fixed
[ja] fixed the broken link
2021-11-18 19:32:51 -08:00
Kubernetes Prow Robot 476cce5a24 Merge pull request #30437 from Arhell/remove
[ja] removed Contiv.io
2021-11-18 19:30:51 -08:00
Kubernetes Prow Robot dcd6672e67 Merge pull request #30354 from Arhell/fix-link
[ja] fixed broken link in intro-windows-in-kubernetes.md
2021-11-18 19:28:51 -08:00
Kubernetes Prow Robot fa87a0f399 Merge pull request #30297 from Arhell/cloud
[ja] Including Oracle Cloud Infrastructure
2021-11-18 19:26:51 -08:00
Kubernetes Prow Robot 38bfe67cad Merge pull request #29980 from riita10069/feature/concepts/_index
[ja] Replace with a link in Japanese about `/concepts/_index.md`
2021-11-18 19:24:51 -08:00
Kubernetes Prow Robot 7e5dd27992 Merge pull request #29977 from riita10069/feature/concepts/overview/components
[ja] Replace with a link in Japanese about concepts/overview/components
2021-11-18 19:22:51 -08:00
Kubernetes Prow Robot dfd14b0564 Merge pull request #29976 from riita10069/feature/concepts/configuration/overview
[ja] Replace with a link in Japanese about overview.md
2021-11-18 19:20:52 -08:00
Kubernetes Prow Robot f4e5f3693a Merge pull request #29974 from riita10069/feature/tasks/run-application/scale-stateful-set
[ja] Replace with a link in Japanese about scale-stateful-set.md
2021-11-18 19:19:53 -08:00
Kubernetes Prow Robot 3a61194945 Merge pull request #29958 from riita10069/feature/pod-lifecycle
[ja] Update pod-lifecycle.md
2021-11-18 19:16:52 -08:00
Kubernetes Prow Robot 054abe062f Merge pull request #30548 from lyzhang1999/patch-1
Update get-shell-running-container.md
2021-11-18 17:44:52 -08:00
Kubernetes Prow Robot 3929001cde Merge pull request #30554 from neha-viswanathan/30523-dead-links
replace dead links
2021-11-18 17:32:51 -08:00
Kubernetes Prow Robot 07d956cd38 Merge pull request #30549 from lyzhang1999/patch-2
Update debug-pod-replication-controller.md
2021-11-18 17:30:51 -08:00
Daniel Weibel d367806825 Fix wording in Jobs documentation 2021-11-19 00:58:17 +04:00
Neha Viswanathan eaf2004e2a replace dead links 2021-11-18 09:44:51 -08:00
Neha Viswanathan d9d2c78964 replace dead links 2021-11-18 09:29:12 -08:00
Kubernetes Prow Robot 2183ddad1f Merge pull request #30541 from fenggw-fnst/update-apparmor
[zh] Update apparmor.md
2021-11-18 05:43:02 -08:00
Kubernetes Prow Robot b96fc31dfc Merge pull request #30542 from cndoit18/unsupported-cron-tz
[zh]: Add warning about using unsupported CRON_TZ
2021-11-18 05:27:03 -08:00
wangwei 36d5dbd887 Update debug-pod-replication-controller.md
Add English and Chinese spaces
2021-11-18 20:23:59 +08:00
wangwei 9c641a8583 Update get-shell-running-container.md
Delete meaningless spaces
2021-11-18 20:10:29 +08:00
cndoit18 65b7de840d [zh]: Add warning about using unsupported CRON_TZ
Signed-off-by: cndoit18 <cndoit18@outlook.com>
2021-11-18 16:34:19 +08:00
Vaibhav e8ff60d0e9 Update the reference statement in access-cluster-services.md 2021-11-18 10:49:08 +05:30
Guangwen Feng 2151d4e5c4 [zh] Update apparmor.md
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-18 11:06:58 +08:00
Arhell 2a1ba00aa7 [ja] update apparmor.md 2021-11-18 02:39:08 +02:00
Kubernetes Prow Robot 0aa00b6902 Merge pull request #30509 from soltysh/cronjob_warning
Add warning about using unsupported CRON_TZ
2021-11-17 07:17:54 -08:00
Kubernetes Prow Robot d54f09182f Merge pull request #30504 from wiggitywhitney/quantity-glossary-si
Update 'Quantity' glossary definition to explain acronym SI
2021-11-17 04:27:54 -08:00
wiggitywhitney 93df00af00 Update to explain acronym SI 2021-11-17 06:08:52 -06:00
Kubernetes Prow Robot 9028af1ae3 Merge pull request #28226 from saschagrunert/image-config-json
Add docs about auth differences between Docker and Kubernetes
2021-11-17 03:49:54 -08:00
Hoon Jo 0cb7bc3295 Update managing-tls-in-a-cluster.md
In my humble view, `kubectl certificate approve my-svc.my-namespace` command may understand easily to follow up this procedure.

Update managing-tls-in-a-cluster.md

Change some text as Divya Mohan's guidance.

Update managing-tls-in-a-cluster.md

Change text as sftim's guidance.! Thank you so much!
2021-11-17 18:56:37 +09:00
Kubernetes Prow Robot 1afb8768f4 Merge pull request #30521 from occase/ocBranch
Add k8s.dev url to Community page
2021-11-17 01:53:54 -08:00
Oline Case cd7f704703 Add k8s.dev url to Community page 2021-11-16 23:43:53 -08:00
Jihoon Seo 0f26532d91 [ko] Update outdated files in dev-1.22-ko.3 28-38 2021-11-17 13:52:56 +09:00
Kubernetes Prow Robot 55b773c2b5 Merge pull request #30513 from sftim/20211116_add_mehabhalodiya_reviewer_en
Add mehabhalodiya as (en) reviewer for SIG Docs
2021-11-16 19:55:54 -08:00
Falimonda 8815230e45 Fixes grammatical errors in Kubespray setup doc (#29460)
* Fixes grammatical errors

* Removes period as recommended in review

* Update content/en/docs/setup/production-environment/tools/kubespray.md

Co-authored-by: Rey Lejano <rlejano@gmail.com>

Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-11-16 19:07:53 -08:00
Kubernetes Prow Robot 36be0ebac9 Merge pull request #30288 from drigz/patch-2
Remove "basic" from supported API auth methods
2021-11-16 18:51:53 -08:00
Tim Bannister 195ab34d01 Fix nits
Tidying that I spotted whilst reordering the storage concepts section.
2021-11-17 00:21:53 +00:00
Tim Bannister 9c0c75e0f2 Reorder storage concepts
Introduce concepts in an order that should suit people new to
Kubernetes, so that you don't encounter details like volume cloning
until you've seen more of the basic volume types (persistent,
ephemeral, projected).
2021-11-17 00:20:18 +00:00
Kubernetes Prow Robot cee6c712bd Merge pull request #30366 from aravindhp/windows-projected-volume
storage: document Windows projected volume limitations
2021-11-16 16:11:53 -08:00
Kubernetes Prow Robot 490e286a35 Merge pull request #30512 from tallclair/patch-3
Remove link to compromised github account
2021-11-16 15:43:54 -08:00
Kubernetes Prow Robot 768905ec73 Merge pull request #30385 from kvaps/fix-konnectivity-audience
Refer ServiceAccountTokenVolumeProjection documentation instead of providing incorrect instructions.
2021-11-16 14:42:33 -08:00
Tim Bannister 6ae5961ca3 Add mehabhalodiya as (en) reviewer for SIG Docs 2021-11-16 22:28:32 +00:00
Tim Allclair db7dfbf166 Remove link to compromised github account
Follow up from incomplete fix in https://github.com/kubernetes/website/pull/30496
2021-11-16 14:20:10 -08:00
Aravindh Puthiyaparambil 4c296c6ad0 storage: document Windows projected volume limitations
xref: https://github.com/kubernetes/kubernetes/issues/102849
2021-11-16 09:38:05 -08:00
Maciej Szulik b5e83e8944 Add warning about using unsupported CRON_TZ 2021-11-16 17:38:01 +01:00
Kubernetes Prow Robot 20b6b87a99 Merge pull request #30479 from Arhell/upd-link
[id] update link
2021-11-16 05:47:28 -08:00
Kubernetes Prow Robot 368dd8dd9a Merge pull request #30497 from vincent-pli/remove-useless-content
[zh] Remove BoundServiceAccountTokenVolume from service-account-admin page
2021-11-16 03:53:26 -08:00
RinkiyaKeDad b2d8188cc7 add hyperlink to list of sigs
Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>
2021-11-16 15:56:43 +05:30
Kubernetes Prow Robot 7dba300e6d Merge pull request #30498 from lachie83/update-gh-username
Update incorrect GH profile link
2021-11-15 19:43:26 -08:00
Lachlan Evenson 06431e1801 Update incorrect GH profile link
Signed-off-by: Lachlan Evenson <lachlan.evenson@microsoft.com>
2021-11-15 17:16:55 -08:00
Kubernetes Prow Robot dfd0f41cc4 Merge pull request #30496 from tallclair/patch-2
Remove link to compromised github account
2021-11-15 17:01:26 -08:00
pengli 89d06b512b remove useless content 2021-11-16 08:46:14 +08:00
Tim Allclair 1c8ec705a3 Remove link to compromised github account
This abandoned account was identified by a security researcher, and reported through the Kubernetes bug bounty program.

Don't we have a link checker that should identify cases like this? I'm guessing the github username was changed, so the link was redirecting (still valid), until the researcher recreated it. We should probably have the link checker flag redirects as well.
2021-11-15 16:28:37 -08:00
Arhell 77429f2802 [id] update link 2021-11-16 02:25:54 +02:00
Kubernetes Prow Robot 7754cf242b Merge pull request #30405 from ptux/patch-4
[en] update custom-resources
2021-11-15 16:21:52 -08:00
Kubernetes Prow Robot 191a2bf0f4 Merge pull request #30443 from shannonxtreme/patch-1
Add shannon to reviewers
2021-11-15 16:06:53 -08:00
Kubernetes Prow Robot 3055d99813 Merge pull request #30440 from vaibhav2107/service-networking
Remove the link as refereneced content is missing
2021-11-15 12:40:49 -08:00
Kubernetes Prow Robot 9709a7e42c Merge pull request #30477 from seokho-son/fix-readme
Enhance readability regarding Slack info in Readme.md
2021-11-15 12:34:48 -08:00
Kubernetes Prow Robot 34bddaac6d Merge pull request #30490 from webbertakken/patch-1
Fix layout issue in docs pages, like jobs
2021-11-15 11:26:48 -08:00
Webber Takken 123e57390e Fix layout issue in docs pages, like jobs
See #30470 for more details.
2021-11-15 14:29:30 +01:00
Kubernetes Prow Robot 2fd0ab9f1f Merge pull request #30426 from luizgribeiro/patch-2
docs: update scale-intro.html (pt-br)
2021-11-15 04:52:47 -08:00
Rajula Vineet Reddy 3af41facff 1.22 feature blog for memory qos support 2021-11-15 18:49:43 +08:00
Vaibhav ab99e7b104 Update the referenced link to kuberentes network model 2021-11-15 14:03:46 +05:30
Kubernetes Prow Robot 25ed878238 Merge pull request #30478 from chirangaalwis/patch-6
Review Network Policy Ingress rules during Service debugging
2021-11-15 00:32:48 -08:00
Kubernetes Prow Robot fea66f8543 Merge pull request #30466 from ptux/patch-10
[zh] Update operator.md
2021-11-15 00:02:48 -08:00
Wang 02abdd28bf Update content/zh/docs/concepts/extend-kubernetes/operator.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-11-15 16:28:16 +09:00
Chiranga Alwis 45148c60e0 Review network policy ingress rules
Add missing note to review Kubernetes Network Policy Ingress rules during debugging Kubernetes Service issues

Update document link

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-11-15 11:49:39 +05:30
Jihoon Seo 0d09bd668f [ko] Update links in dev-1.22-ko.3 2021-11-15 15:11:00 +09:00
Kubernetes Prow Robot 870d4472fc Merge pull request #30474 from seokho-son/out-ko.3-m2
[ko] Update outdated in dev-1.22-ko.3 (M2-M3)
2021-11-14 22:00:48 -08:00
Kubernetes Prow Robot 0600d52693 Merge pull request #30476 from seokho-son/fix-ko
[ko] Apply 1.21-ko.8 enhancement to 1.22-ko.3
2021-11-14 21:54:48 -08:00
Seokho Son dcb8a2f7c1 Add brackets for Slack info in Readme 2021-11-15 13:49:14 +09:00
Kubernetes Prow Robot 6320991d0a Merge pull request #30373 from Babapool/crictlv
Updated circtl version to v1.22.0 from v1.17.0 in install kubeadm doc #30349
2021-11-14 18:08:48 -08:00
Kubernetes Prow Robot 0027ada6e0 Merge pull request #30464 from ptux/patch-8
[en] Update operator.md
2021-11-14 16:16:48 -08:00
Seokho Son 7373ffe1fd Apply 1.21-ko.2 enhancement to 1.22-ko.3 2021-11-15 05:46:26 +09:00
Seokho Son 4616e63617 Update outdated in dev-1.22-ko.3 (M2-M3) 2021-11-15 04:16:42 +09:00
Seokho Son 62a3baf06c Fix outdated in ko architecture/nodes 2021-11-15 03:53:10 +09:00
Wang 91df163eed Update operator.md 2021-11-14 19:34:41 +09:00
Wang 0f643c43e3 Update operator.md 2021-11-14 13:10:01 +09:00
Arhell b4855bce54 [ja] fixed the broken link 2021-11-14 02:03:19 +02:00
Maciej Filocha d30b591c95 Synchronize Polish localization for ver 1.22, part 5
Synchronize Polish localization with upstream up to 08d92f9.
Part 5
2021-11-13 22:02:54 +01:00
Kubernetes Prow Robot 6ff0695578 Merge pull request #30226 from leoluz/leoluz/blog/fix-ssa-codesnip
Fix server-side-apply code snippet in blog post
2021-11-13 09:24:46 -08:00
Kubernetes Prow Robot d2f227d73e Merge pull request #29727 from jonassteinberg1/patch-2
"First this user must have [a] certificate issued..."
2021-11-12 21:06:46 -08:00
Avinash Upadhyaya 0913d9ed39 fix: deployment rollout pause and resume wordings
fix: revert link change for pausing deployments and some rewording

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-11-13 10:01:32 +05:30
Kubernetes Prow Robot 098501ebfd Merge pull request #30082 from sftim/20211013_revise_header_style
Revise page header styles
2021-11-12 20:00:46 -08:00
Kubernetes Prow Robot d9a041eb7d Merge pull request #30067 from sftim/20211013_tidy_pull_image_private_registry_task
Tidy task “Pull an Image from a Private Registry”
2021-11-12 19:46:46 -08:00
Kubernetes Prow Robot bf1a799b85 Merge pull request #30458 from wiggitywhitney/pod-disruption-glossary
Fix to reveal more info when '[+]' is clicked
2021-11-12 19:20:46 -08:00
Kubernetes Prow Robot 99f80cc0ab Merge pull request #30461 from Anakin100100/patch-1
Removed depracated ruby client library
2021-11-12 19:06:46 -08:00
Kubernetes Prow Robot 13323ce82a Merge pull request #28986 from xeathen/fix-typo
[zh] fix typo of expose-intro.html
2021-11-12 17:24:47 -08:00
Kubernetes Prow Robot 6e9676f5c2 Merge pull request #30453 from fenggw-fnst/cleanup-zh
[zh] Remove ^H character
2021-11-12 17:16:47 -08:00
Kubernetes Prow Robot 79e2a98b54 Merge pull request #30444 from wiggitywhitney/pdb-glossary
Fix to reveal more info when '[+]' is clicked
2021-11-12 16:20:47 -08:00
Kubernetes Prow Robot 20573065b3 Merge pull request #30460 from SubtextRyan/patch-1
Corrected grammatical error
2021-11-12 16:14:47 -08:00
Anakin100100 358ec86ec4 Removed depracated ruby client library
The 'kubr' gem has last been updated 7 years ago. It doesn't provide the required modern functionalities. The documentation consists of one code example and that's it. It's inclusion in this list only wastes time of Ruby on Rails developers because no sane person would chose it.
2021-11-12 21:44:23 +01:00
Kubernetes Prow Robot 5e7776274f Merge pull request #30447 from SergeyKanzhelev/dockershim-removal-blog
dockershim removal readiness blog post
2021-11-12 12:14:28 -08:00
Sergey Kanzhelev 5d09f5edb5 dockershim removal readiness blog post 2021-11-12 17:42:51 +00:00
Kubernetes Prow Robot c3439b3e15 Merge pull request #30295 from siddhantprateek/main-v2
Mentioned Markdown flavor in Contribution new content
2021-11-12 09:38:28 -08:00
Siddhant Prateek Mahanayak 12854d0586 Suggested Changes
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-11-12 23:01:48 +05:30
Kubernetes Prow Robot 3c1d642746 Merge pull request #30393 from elmiko/update-ccm-node-controller
update cloud controller doc on node controller
2021-11-12 09:20:28 -08:00
SubtextRyan 46988781a3 Corrected grammatical error
Subject/verb disagreement: changed "...system execute the handler..." to "...system executes the handler..."
2021-11-12 12:05:00 -05:00
Kubernetes Prow Robot 1406c2d85a Merge pull request #30170 from bobfuru/clarify-container-images-wording
Replace "Docker image" with "container image", other minor edits
2021-11-12 09:02:28 -08:00
sandipanpanda 7a513e6dee Fix broken anchor link of #type-nodeport in service.md (#30388)
* Fix broken anchor link of #type-nodeport in service.md

* Update anchor link from #nodeport to #type-nodeport

Update anchor link from #nodeport to #type-nodeport in overview.md

* Update anchor link from #nodeport to #type-nodeport

Update anchor link from #nodeport to #type-nodeport in ingress.md

* Update anchor link from #nodeport to #type-nodeport

Update anchor link from #nodeport to #type-nodeport in troubleshooting-kubeadm.md

* Update anchor link from #nodeport to #type-nodeport

Update anchor link from #nodeport to #type-nodeport in connecting-frontend-backend.md

* Update anchor link from #nodeport to #type-nodeport

Update anchor link from #nodeport to #type-nodeport in source-ip.md
2021-11-12 08:02:28 -08:00
Michael McCune 0d864c18d9 update cloud controller doc on node controller
This change updates the information about the node controller in the
cloud controller managers. The node controller is not responsible for
creating new node objects, it updates them with information from the
provider infrastructure.
2021-11-12 08:25:40 -05:00
Kubernetes Prow Robot 152082f1db Merge pull request #30454 from mayocream/patch-2
[zh] Sync changes in 使用 kubeadm API 定制组件
2021-11-12 05:24:27 -08:00
Kubernetes Prow Robot e0ffcf9342 Merge pull request #30374 from clarinette9/docs-bfe-ingress
add BFE-ingress-controller to the document ingress-controllers.md.
2021-11-12 05:22:28 -08:00
Kubernetes Prow Robot 4de6225385 Merge pull request #30350 from spiffxp/drop-kubernetes-e2e-test-images
replace dnsutils example image
2021-11-12 05:20:28 -08:00
wiggitywhitney 8716bb6e1e Fix to reveal more info when plus is clicked 2021-11-12 06:34:30 -06:00
Umair A. Shahid 53bf4f212a Kubelet accepts graceful node shutdown parameters in camel case while they are written in the document in pascal case 2021-11-12 12:29:34 +01:00
Mayo Cream ae61db3ca5 Sync changes in content/zh/docs/setup/production-environment/tools/kubeadm/control-plane-flags.md 2021-11-12 16:39:27 +08:00
qlijin efbbe7f183 [zh]translate. fix issue #30217 (#30403)
* [zh]translate. fix issue #30217

* [zh-Hans] translate kubelet-in-userns.md. Update code after review
2021-11-11 21:52:28 -08:00
Guangwen Feng b658c945d0 [zh] Remove ^H character
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-12 13:11:23 +08:00
Kubernetes Prow Robot 6a237d0298 Merge pull request #30446 from Arhell/upd-link
[zh] update references in Finalizers
2021-11-11 19:34:29 -08:00
Akihiro Suda e2f17b7579 Fix typos,config paths in kubelet-in-userns.md. Add link to port forwarder implementation (#30410)
* kubelet-in-userns.md: fix typoes

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>

* kubelet-in-userns.md: fix unexpected config paths

Referring to `/etc/containerd/config.toml` makes sense only when the user has
read/write permissions to `/etc/containerd/config.toml` in the current mount
namespace, which is not always assumed in the context of this documentation.

The same applies to `/etc/crio/crio.conf`, too.

Partially revert PR 30020.

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>

* kubelet-in-userns.md: add back the link to example port forwarder implementation

Add back the link to `k3s/pkg/rootlessports/controller.go` removed in PR 30020.

As stated in `{{ <note> }}`, the corresponding section is written for developers
of Kubernetes distros, not for end users.
So we should retain the implementation details here.

Partially revert PR 30020.

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2021-11-11 18:02:28 -08:00
Kubernetes Prow Robot 1e36c7611f Merge pull request #30360 from qzdl/patch-2
update pod mapping to avoid deprecation notice
2021-11-11 17:44:28 -08:00
Arhell d012f0b4a2 [zh] update references in Finalizers 2021-11-12 01:19:48 +02:00
wiggitywhitney 89b1ee4032 Fix to reveal more info when plus is clicked 2021-11-11 12:09:05 -06:00
Shannon Kularathna 5d480f0b2b Add shannon to reviewers
I’ve been a member for a fair bit. Reviewed, worked on, or been involved in tracking 50+ PRs.

Some highlights:

* https://github.com/kubernetes/website/pull/26848
* https://github.com/kubernetes/website/pull/27716
* https://github.com/kubernetes/website/pull/27739
* https://github.com/kubernetes/website/pull/28870
* https://github.com/kubernetes/website/pull/28740
* https://github.com/kubernetes/website/pull/28617

Search for PRs involving me: https://github.com/kubernetes/website/pulls?page=2&q=is%3Apr+involves%3Ashannonxtreme
2021-11-11 12:53:31 -05:00
Kubernetes Prow Robot ed72287310 Merge pull request #30433 from SgtCoDFish/cert-manager-link-ko
[ko] update cert-manager docs link
2021-11-11 09:48:08 -08:00
Kubernetes Prow Robot 92e5d41881 Merge pull request #30439 from sysnet4admin/patch-4
Update apparmor.md
2021-11-11 09:46:08 -08:00
Kubernetes Prow Robot 0a17c09a37 Merge pull request #30257 from aysabzevar/feature/add-sudo-redhat-es
[es] add sudo to Red Hat-based distributions
2021-11-11 08:08:08 -08:00
Kubernetes Prow Robot 297bb525fe Merge pull request #30383 from fenggw-fnst/work
[zh] Update create-cluster-kubeadm.md and fix invalid links
2021-11-11 02:55:51 -08:00
syxunion 8039754872 translate Reference/Glossary/Eviction (#30438)
* translate Reference/Glossary/Eviction

* modify full_link path
2021-11-11 02:53:50 -08:00
Kubernetes Prow Robot 3f0994baba Merge pull request #30434 from SgtCoDFish/cert-manager-link-zh
[zh] Update cert-manager docs link
2021-11-11 00:55:50 -08:00
Kubernetes Prow Robot 3c7097a2df Merge pull request #30432 from SgtCoDFish/cert-manager-link
[en] Update link to cert-manager website
2021-11-11 00:51:51 -08:00
Vaibhav f58c7705bb Remove the link as refereneced content is missing 2021-11-11 14:10:19 +05:30
Hoon Jo 9ac60ec13d Update apparmor.md
Due to exec command DEPRECATED. so please add `--` to avoid info message. 

`Current`
```
root@wk8s-m:~# kubectl exec hello-apparmor cat /proc/1/attr/current
kubectl exec [POD] [COMMAND] is DEPRECATED and will be removed in a future version. Use kubectl exec [POD] -- [COMMAND] instead.
k8s-apparmor-example-deny-write (enforce)
``` 

```
root@wk8s-m:~# kubectl exec hello-apparmor touch /tmp/test
kubectl exec [POD] [COMMAND] is DEPRECATED and will be removed in a future version. Use kubectl exec [POD] -- [COMMAND] instead.
touch: /tmp/test: Permission denied
command terminated with exit code 1
```

`Change`
```
root@wk8s-m:~# kubectl exec hello-apparmor -- cat /proc/1/attr/current
k8s-apparmor-example-deny-write (enforce)
```

```
root@wk8s-m:~# kubectl exec hello-apparmor -- touch /tmp/test
touch: /tmp/test: Permission denied
command terminated with exit code 1
```
2021-11-11 16:02:04 +09:00
Arhell f5dea3bb90 [ja] removed Contiv.io 2021-11-11 00:35:47 +02:00
Ashley Davis 5e4e284a71 [zh] update cert-manager docs link
Signed-off-by: Ashley Davis <ashley.davis@jetstack.io>
2021-11-10 14:19:50 +00:00
Ashley Davis ed69e93716 [ko] update cert-manager docs link
Signed-off-by: Ashley Davis <ashley.davis@jetstack.io>
2021-11-10 14:19:04 +00:00
Ashley Davis 8ae9faaed1 [en] update link to cert-manager docs
Signed-off-by: Ashley Davis <ashley.davis@jetstack.io>
2021-11-10 14:18:23 +00:00
Kubernetes Prow Robot 53f7612552 Merge pull request #30186 from sandersaares/request-is-not-a-guarantee
A CPU request does not result in a guarantee
2021-11-09 23:15:26 -08:00
Kubernetes Prow Robot 8f52166ac8 Merge pull request #28887 from chenxuc/pause-resume2
clarify rollout behavior in deployment
2021-11-09 23:13:26 -08:00
Guangwen Feng a7d816000a [zh] Update create-cluster-kubeadm.md and fix invalid links
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-10 14:03:24 +08:00
Kubernetes Prow Robot dea1834fe9 Merge pull request #30396 from Arhell/typo-fix
[zh] fixed a typo
2021-11-09 19:21:25 -08:00
Kubernetes Prow Robot 23ab74022d Merge pull request #30402 from fenggw-fnst/work2
[zh] Fix typo
2021-11-09 19:19:26 -08:00
Kubernetes Prow Robot 8e846d1655 Merge pull request #30367 from steven-my/29329-translation-for-admin-4
translation for section admin4
2021-11-09 18:39:27 -08:00
Kubernetes Prow Robot c3318e0cd9 Merge pull request #30400 from RA489/ha
Improvement to create cluster using minikube
2021-11-09 18:35:26 -08:00
Kubernetes Prow Robot 5436d4af9d Merge pull request #30398 from jihoon-seo/211109_Make_redirection_for_highly-available-control-plane
Make redirection for highly-available-control-plane
2021-11-09 18:33:26 -08:00
Kubernetes Prow Robot 2245b59156 Merge pull request #30387 from kvaps/omit-api-audiences
ServiceAccountTokenVolumeProjection: api-audiences flag can be omitted
2021-11-09 18:31:27 -08:00
Kubernetes Prow Robot c4ce619f28 Merge pull request #30369 from vivek-koppuru/basic-auth-fix
Fix wording of basic auth secret doc to keep it consistent with validation
2021-11-09 17:15:26 -08:00
Luiz Guilherme Ribeiro 51802636f9 Update scale-intro.html (pt-br)
The doc version for brazilian portuguese scale-intro page seems to be generated by an AI powered engine, which is not quite right and/or specific as the original one.

This PR changes a few words and a bit of the structure of the phrase in the pt-br doc, using de original (en) version as source of information.
2021-11-09 21:21:46 -03:00
Kubernetes Prow Robot c15f89b549 Merge pull request #30411 from justaugustus/steering-2021
Update Steering membership following 2021 election
2021-11-09 13:21:48 -08:00
Wang 2d560fd4fb Update custom-resources.md 2021-11-10 05:07:02 +09:00
Kubernetes Prow Robot a03498f9eb Merge pull request #30421 from jberkus/arnaud
Add Arnaud to the Thanks section.
2021-11-09 10:53:48 -08:00
Josh Berkus 009e15655a Add Arnaud to the Thanks section.
Signed-off-by: Josh Berkus <josh@agliodbs.com>
2021-11-09 10:05:24 -08:00
Kubernetes Prow Robot b81dcba911 Merge pull request #30412 from kubernetes/dev-1.22-ko.2
[ko] 2nd Korean localization work for v1.22
2021-11-09 05:39:47 -08:00
Stephen Augustus 5cebb20920 blog: Lint warnings and username fixes in 2021 Steering post
Signed-off-by: Stephen Augustus <foo@auggie.dev>
2021-11-09 06:35:34 -05:00
Stephen Augustus 60d192d332 OWNERS_ALIASES: Update Steering membership following 2021 election
Emeritus:
- Nikhita
- Derek

Returning:
- Paris
- Christoph

New:
- Stephen
- Tim

Signed-off-by: Stephen Augustus <foo@auggie.dev>
2021-11-09 06:31:10 -05:00
Wang 324e4e07fa [en] update custom-resources
Make it clear that the main API server delegates requests to user created API server.
2021-11-09 18:31:31 +09:00
Kubernetes Prow Robot 0e19aed5dc Merge pull request #30137 from anyulled/main
[es] add concepts/services-networking/service
2021-11-09 00:59:39 -08:00
Guangwen Feng 0877306b40 [zh] Fix typo
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-09 14:25:48 +08:00
RA489 1ddef08a50 Improvement to create cluster page 2021-11-09 11:06:25 +05:30
Kubernetes Prow Robot 7d7d0224f7 Merge pull request #30010 from ClaudiaJKang/ko-29560
[ko] Translate docs/tasks/administer-cluster/sysctl-cluster.md in Korean
2021-11-08 19:49:40 -08:00
Juhee Kang ccf05596df [ko] Translate docs/tasks/administer-cluster/sysctl-cluster.md in Korean 2021-11-09 11:28:07 +09:00
Kubernetes Prow Robot d886d65675 Merge pull request #29957 from sftim/20211007_document_thirdparty-content_shortcode
Document {{% thirdparty-content %}} shortcode
2021-11-08 18:23:39 -08:00
Jihoon Seo 047c8577d5 Make redirection for highly-available-control-plane 2021-11-09 10:50:38 +09:00
Kubernetes Prow Robot e35a6e103f Merge pull request #30118 from Shatakshi0805/fix-link-in-release-managers.md
fix broken link in release-managers.md
2021-11-08 17:26:49 -08:00
Kubernetes Prow Robot a45e1b3347 Merge pull request #30368 from TreeKat71/main
Typo `etcdutl` in configure-upgrade-etcd.md
2021-11-08 17:20:49 -08:00
Kubernetes Prow Robot 59fe5002e2 Merge pull request #30397 from cblecker/typo-blog
Fix typo in SC blog post
2021-11-08 17:06:49 -08:00
Aravindh Puthiyaparambil c0dd24a8ba storage: create new file for projected volumes
Move inline examples into the examples folder
2021-11-08 16:07:33 -08:00
Christoph Blecker bf0e9ea2e5 Fix typo in SC blog post 2021-11-08 15:15:53 -08:00
Arhell a5180ea3e1 [zh] fixed a typo 2021-11-09 00:29:52 +02:00
Kubernetes Prow Robot a812761d1d Merge pull request #30395 from reylejano/update-non-root-blog
Blog: renamed non-root-containers-and-devices.md to have date prefix
2021-11-08 14:27:20 -08:00
Kubernetes Prow Robot 6fb2f53ceb Merge pull request #30394 from reylejano/steering-blog
Blog: update 2021 steering blog post
2021-11-08 13:51:20 -08:00
Rey Lejano 120d0424c2 renamed non-root-containers-and-devices.md to 2021-11-09-non-root-containers-and-devices.md 2021-11-08 13:45:03 -08:00
Rey Lejano aba3e29883 renamed steering-committee-results-2021 to 2021-11-08-steering-committee-results-2021.md and update date 2021-11-08 13:33:55 -08:00
Kubernetes Prow Robot b7899c1e2d Merge pull request #30392 from kaslin/patch-1
Blog Post for steering-committee-results-2021
2021-11-08 12:11:20 -08:00
Kaslin Fields 65faac6f3e Create steering-committee-results-2021 2021-11-08 11:48:36 -08:00
Kubernetes Prow Robot 5ac4b5f765 Merge pull request #29703 from mythi/non-root-containers-and-devices-blog
blog: non-root containers and devices
2021-11-08 07:47:20 -08:00
Mikko Ylinen c7cb7683f9 blog: non-root containers and devices
Signed-off-by: Mikko Ylinen <mikko.ylinen@intel.com>
2021-11-08 17:39:13 +02:00
Kubernetes Prow Robot 1e090d8f1a Merge pull request #29868 from RA489/activedeadlinesec
explanation of the role of activeDeadlineSeconds in initContainers be…
2021-11-08 06:43:00 -08:00
Andrei Kvapil 69c6dc0a82 Refer ServiceAccountTokenVolumeProjection documentation instead of providing incorrect instructions.
Since Kubernetes v1.20 it is enabled by default.
2021-11-08 15:16:05 +01:00
Andrei Kvapil 02d9cec45e api-audiences flag can be omitted 2021-11-08 11:52:11 +01:00
Kubernetes Prow Robot 8453f2e116 Merge pull request #29981 from riita10069/feature/content/concepts/services-networking/service
[ja] Replace with a link in Japanese  `concepts/service`
2021-11-08 00:40:58 -08:00
Kubernetes Prow Robot 5c6b0ca541 Merge pull request #29979 from riita10069/feature/concepts/cluster-administration/cluster-administration-overview
[ja] Replace with a link in Japanese about cluster-administration-overview.md
2021-11-08 00:38:58 -08:00
Kubernetes Prow Robot e287b837ed Merge pull request #29982 from riita10069/feature/reference/access-authn-authz/rbac
[ja] Replace with a link in Japanese about `reference/access-authn-authz/rbac.md`
2021-11-08 00:36:59 -08:00
Kubernetes Prow Robot 67f5fdbc68 Merge pull request #30329 from ClaudiaJKang/ko-30039
[ko] Translate docs/tasks/debug-application-cluster/debug-stateful-set.md in Korean
2021-11-07 23:12:52 -08:00
Steven Yan f4962730fa translation for section admin4 2021-11-08 14:57:40 +08:00
Juhee Kang c6f45d97d7 [ko] Translate docs/tasks/debug-application-cluster/debug-stateful-set.md in Korean 2021-11-08 13:55:18 +09:00
Kubernetes Prow Robot 9217cc4c33 Merge pull request #30380 from Arhell/update-gates
[zh] Update feature-gates.md
2021-11-07 19:24:52 -08:00
Kubernetes Prow Robot 4dfa86568d Merge pull request #30381 from yoonian/dev-1.22-ko.2-yoonian
[ko] Update dev-1.22-ko.2 (M52,M53)
2021-11-07 18:28:52 -08:00
PyungHo Yoon 3b1edf71c7 [ko] Update dev-1.22-ko.2 (M52,M53) 2021-11-08 11:06:16 +09:00
Kubernetes Prow Robot dee445dded Merge pull request #30310 from bang9211/bang9211/setup-konnectivity/v0.1
[ko] Translate tasks/extend-kubernetes/setup-konnectivity.md in Korean
2021-11-07 17:42:54 -08:00
Bob Furu b5b60db805 Replace Docker image with container image and other minor edits for clarity 2021-11-07 20:21:09 -05:00
Kubernetes Prow Robot 565f0259f0 Merge pull request #30211 from superleo/branch1
[zh]Concept files to sync for 1.22 #29325 task 12
2021-11-07 16:40:52 -08:00
Kubernetes Prow Robot afba06097b Merge pull request #30382 from Arhell/typos
[zh] fix typos
2021-11-07 16:34:53 -08:00
Arhell a547f15396 [zh] fix typos 2021-11-08 00:35:10 +02:00
bang9211 ae23d6d492 Translate tasks/extend-kubernetes/setup-konnectivity.md in Korean 2021-11-08 01:03:34 +09:00
superleo c5abf03306 [zh]Concept files to sync for 1.22 #29325 task 12 2021-11-07 23:26:26 +08:00
Arhell f8e9d4e60b [zh] Update feature-gates.md 2021-11-07 11:36:55 +02:00
Kubernetes Prow Robot 9a81b3c08d Merge pull request #30372 from Arhell/upd
[zh] Update configure-gmsa.md
2021-11-06 22:14:52 -07:00
Kubernetes Prow Robot dfbb64991f Merge pull request #30117 from ztzxt/patch-1
Bump dashboard version to 2.4.0 from 2.3.1
2021-11-06 19:26:51 -07:00
Kubernetes Prow Robot c43a519134 Merge pull request #30377 from mfilocha/pl-synchronize-1.22b1
Synchronize Polish localization for ver 1.22, part b1
2021-11-06 08:16:51 -07:00
Maciej Filocha aaa429e62d Synchronize Polish localization for ver 1.22, part b1
Synchronize Polish localization with upstream up to 273ea3671f.
Part 1.
2021-11-06 15:52:17 +01:00
Kubernetes Prow Robot 6eb257fee5 Merge pull request #30328 from ClaudiaJKang/ko-30038
[ko] Translate docs/tasks/debug-application-cluster/get-shell-running-container.md in Korean
2021-11-06 06:50:51 -07:00
Kubernetes Prow Robot fde75d600a Merge pull request #30272 from bang9211/bang9211/ingress-minikube/v0.2
[ko] Translate tasks/access-application-cluster/ingress-minikube.md in Korean
2021-11-06 06:48:51 -07:00
Juhee Kang 9941eaa555 [ko] Translate docs/tasks/debug-application-cluster/get-shell-running-container.md in Korean 2021-11-06 22:43:39 +09:00
Kubernetes Prow Robot e4509e714e Merge pull request #30358 from jihoon-seo/211104_ko_Update_outdated_files_p1
[ko] Update outdated files in dev-1.22-ko.2 (M42-M47)
2021-11-06 06:42:52 -07:00
Kubernetes Prow Robot 1199160897 Merge pull request #30363 from seokho-son/out1.22ko-m57
[ko] Add note for outdated Korean for windows docker in k8s
2021-11-06 06:40:51 -07:00
Kubernetes Prow Robot 6053227298 Merge pull request #30315 from seokho-son/out1.22ko-m38
[ko] Fix outdated pod-topology-spread-constraints.md Korean
2021-11-06 06:38:51 -07:00
Kubernetes Prow Robot e1db27adb3 Merge pull request #30362 from seokho-son/out1.22ko-m46
[ko] Update dev-1.22-ko.2 (M46, M48-M50)
2021-11-06 06:34:51 -07:00
Kubernetes Prow Robot ee388cd638 Merge pull request #30309 from seokho-son/out1.22ko-m36
[ko] Update outdated in dev-1.22-ko.2(36-37)
2021-11-06 06:32:51 -07:00
clarinette9 d450873fcf add bfe to ingress-controllers.md
add link and introduction of bfe ingress controller to /content/zh/docs/concepts/services-networking/ingress-controllers.md
2021-11-06 20:36:33 +08:00
clarinette9 5de494f375 add bfe to ingress-controllers.md
add link and introduction of bfe ingress controller to /content/en/docs/concepts/services-networking/ingress-controllers.md
2021-11-06 20:31:47 +08:00
Vitthal Sai f200e6d223 Updated circtl version to v1.22.0 from v1.17.0 in install kubeadm doc 2021-11-06 11:56:43 +05:30
Kubernetes Prow Robot 273ea3671f Merge pull request #30370 from chris-short/patch-1
Adding links to kubernetes.dev
2021-11-05 23:14:51 -07:00
Arhell 9d5f23ab6b [zh] Update configure-gmsa.md 2021-11-06 00:18:44 +02:00
Kubernetes Prow Robot 6aad0849aa Merge pull request #30278 from wiggitywhitney/extensions-copy
Improve Extensions Definition
2021-11-05 13:56:41 -07:00
Kubernetes Prow Robot 80b4fe0cac Merge pull request #30069 from sftim/20211013_tweak_kubectl_skew_advice
Tweak advice about kubectl skew
2021-11-05 13:52:40 -07:00
Rey Lejano ba4390cf48 add line about contributor blogs to kubernetes.dev 2021-11-05 12:05:15 -07:00
Chris Short ee6b1a831e Adding links to kubernetes.dev
Boosting the contributor site up in Google rankings is a priority for the Kubernetes Upstream Marketing team: https://github.com/kubernetes/contributor-site/issues/202

Adding links here where appropriate:
- Contributor Cheatsheet
- kubernetes.dev itself
- contributor resources
2021-11-05 12:52:38 -04:00
Kubernetes Prow Robot f446293659 Merge pull request #30320 from Arhell/oracle
[pt-br] Including Oracle Cloud Infrastructure
2021-11-05 06:43:52 -07:00
Vivek Koppuru 4f9f1dccfc Fix wording of basic auth secret doc to keep it consistent with validation 2021-11-05 18:18:03 +05:30
Muller Hsu f0c98092e9 Update configure-upgrade-etcd.md
Typo
Should be `etcdctl` not etcdutl
2021-11-05 17:53:56 +08:00
Kubernetes Prow Robot 77106691d7 Merge pull request #30251 from aysabzevar/feature/add-sudo-redhat-ko
[ko] add sudo to Red Hat-based distributions
2021-11-04 20:11:53 -07:00
Kubernetes Prow Robot ff7a649956 Merge pull request #30151 from kerthcet/feature/add-introduce-to-scheduler-v1beta3
add introductions for scheduler component config api migrations
2021-11-04 17:31:53 -07:00
Kubernetes Prow Robot 65ee4acae8 Merge pull request #30277 from seokho-son/out1.22ko-m39
[ko] Update contribute new-content of 1.22-ko.2
2021-11-04 09:08:04 -07:00
Kubernetes Prow Robot 174c41370c Merge pull request #30228 from seokho-son/out1.22ko-m62
[ko] Update kubeadm-upgrade
2021-11-04 09:06:05 -07:00
Kubernetes Prow Robot 4c46ade2e6 Merge pull request #30227 from seokho-son/out1.22ko-m61
[ko] Update highly-available-control-plane
2021-11-04 09:00:06 -07:00
wiggitywhitney 2ec7040fd4 Improve Extensions Definition 2021-11-04 10:37:37 -05:00
Seokho Son ba621d0919 Add note for outdated Korean for win k8s 2021-11-05 00:25:32 +09:00
Seokho Son d571d0585d Update dev-1.22-ko.2 (M46, M48-M50) 2021-11-04 23:19:07 +09:00
Samuel Culpepper 7a8fef9992 update pod mapping to avoid deprecation notice 2021-11-04 14:30:51 +01:00
Jihoon Seo 91303e1a93 [ko] Update outdated files in dev-1.22-ko.2 (M42-M47) 2021-11-04 18:53:28 +09:00
Kubernetes Prow Robot 6119f088aa Merge pull request #30356 from cpanato/nov-21-cycle
update patch release for november 2021 cycle
2021-11-04 02:00:05 -07:00
Kubernetes Prow Robot 2011e9af62 Merge pull request #30316 from seokho-son/out1.22ko-m55
[ko] Update outdated contents in dev-1.22-ko.2 M55-56
2021-11-04 01:50:04 -07:00
Seokho Son 134a0c1c9e Update outdated in dev-1.22-ko.2(36-37) 2021-11-04 17:49:06 +09:00
Kubernetes Prow Robot 30a45ebddd Merge pull request #30276 from seokho-son/out1.22ko-m67
[ko] Update outdated Korean for task m67-m71
2021-11-04 01:48:03 -07:00
Kubernetes Prow Robot 014eb69dbd Merge pull request #30275 from seokho-son/out1.22ko-m6x
[ko] Update outdated Korean for task m63-m66
2021-11-04 01:46:04 -07:00
Carlos Panato bbe5439576 update patch release for november 2021 cycle
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-11-04 09:05:56 +01:00
Carlos Panato 1068af1a37 remove release 1.19 from the active patch release
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-11-04 09:05:31 +01:00
kerthcet c0175c5635 add introductions for scheduler component config api migrations
Signed-off-by: kerthcet <kerthcet@gmail.com>
2021-11-04 10:10:30 +08:00
Kubernetes Prow Robot 0c04e2c54c Merge pull request #30146 from neolit123/1.23-update-ts-guide-for-cert-rotation
kubeadm/TS guide: fix a misleading step about cert rotation
2021-11-03 18:28:03 -07:00
Kubernetes Prow Robot 5862d9155e Merge pull request #30147 from chirangaalwis/patch-5
Notify deletion of Kubelet Bootstrap Token
2021-11-03 17:56:03 -07:00
Arhell 38cae7e7e8 [ja] fixed broken link in intro-windows-in-kubernetes.md 2021-11-04 01:42:48 +02:00
Aaron Crickenberger 156173d622 replace dnsutils example image
The gcr.io/kubernetes-e2e-test-images repo is deprecated and will
eventually go away. Use an equivalent image from the project-owned
k8s.gcr.io repo
2021-11-03 14:32:58 -07:00
Kubernetes Prow Robot e8d6117d3e Merge pull request #30203 from gochist/ko-controllers
[ko] Update concepts/workloads/controllers
2021-11-03 11:46:32 -07:00
Seokho Son 09f1a0073b Update outdated in dev-1.22-ko.2 M55-56 2021-11-04 03:38:49 +09:00
Kubernetes Prow Robot 34f4f9154b Merge pull request #30323 from tengqm/zh-sync-manage-resource
[zh] Resync manage resources for containers
2021-11-03 08:39:26 -07:00
Kubernetes Prow Robot 55f1be7728 Merge pull request #30343 from lifeoncloud/dev-1.22-ko.2
Translate content/en/docs/reference/using-api/health-checks.md in Korean
2021-11-03 07:49:05 -07:00
Suresh Kumar 2b61e464a6 Update parallel-processing-expansion.md
removed unwanted jinja tags
2021-11-03 19:33:09 +05:30
lifeoncloud 973c4b561c fixed typo 2021-11-03 21:09:17 +09:00
Mayo Cream b28f95e934 [zh] concept of owners and dependents (#30325)
* [zh] concept of owners and dependents

* update shell example

* Update owners-dependents.md
2021-11-03 04:26:58 -07:00
Mayo Cream 43f3660d2b [zh] fix typo in endpoint slices (#30335) 2021-11-03 02:44:58 -07:00
Kubernetes Prow Robot 8eb247531e Merge pull request #30199 from gochist/ko-storage
[ko] Update content/ko/docs/concepts/storage
2021-11-03 01:30:58 -07:00
Kubernetes Prow Robot 07cafe7848 Merge pull request #30339 from ptux/patch-4
Update _index.md
2021-11-02 23:40:57 -07:00
Kubernetes Prow Robot 5898244c16 Merge pull request #30336 from Arhell/line
[zh] add a newline
2021-11-02 23:38:57 -07:00
Qiming Teng a2d70a7740 [zh] Resync manage resources for containers 2021-11-03 14:34:10 +08:00
Wang 6ae08f504e Update _index.md
Releated PR:

https://github.com/kubernetes/website/pull/30337
2021-11-03 14:10:55 +09:00
Arhell d31f2b963a [zh] add a newline 2021-11-03 00:49:02 +02:00
Kubernetes Prow Robot f8276a4830 Merge pull request #30107 from chirangaalwis/patch-3
Update "multiple schedulers" example
2021-11-02 15:31:42 -07:00
Kubernetes Prow Robot 191cc3f267 Merge pull request #29790 from GCES-Kubernetes/translation/ptBrPortsAndProtocols
[pt-br] Adding translation of ports and protocols page
2021-11-02 15:19:42 -07:00
Kubernetes Prow Robot d56c8b4e28 Merge pull request #30324 from tengqm/zh-sync-install-kubectl-win
[zh] Resync install-kubectl-windows page
2021-11-02 08:18:59 -07:00
June Yi 70c42572af [ko] Update concepts/workloads/controllers
refs #30000 tasks M29-M35

Co-authored-by: Jerry Park <jaehwa@gmail.com>
2021-11-02 23:47:06 +09:00
chirangaalwis 7449bb36a0 Update config refs to KubeSchedulerConfiguration 2021-11-02 19:56:21 +05:30
Kubernetes Prow Robot 007f515d17 Merge pull request #30168 from arosequist/patch-1
Add missing space before parenthesis
2021-11-02 05:18:59 -07:00
Marcos Nery bd66c9294b fixing typo 2021-11-02 05:39:11 -03:00
Chiranga Alwis c5cb03ab13 Shorten the description on field updating
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-11-02 14:01:35 +05:30
Chiranga Alwis 7b6d84ec7c Use note short code to highlight the content
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-11-02 13:59:24 +05:30
Kubernetes Prow Robot 16ac777557 Merge pull request #30322 from fenggw-fnst/work
Fix typo
2021-11-01 23:26:58 -07:00
Qiming Teng 2514621e9e [zh] Resync install-kubectl-windows page 2021-11-02 13:56:08 +08:00
Guangwen Feng 5a92aaf08b Fix typo
Signed-off-by: Guangwen Feng <fenggw-fnst@cn.fujitsu.com>
2021-11-02 13:38:41 +08:00
Kubernetes Prow Robot ad70f37b94 Merge pull request #30255 from aysabzevar/feature/add-sudo-redhat-zh
[zh] add sudo to Red Hat-based distributions
2021-11-01 22:10:58 -07:00
Kubernetes Prow Robot f49e939aa7 Merge pull request #30247 from aysabzevar/main
add sudo to Red Hat-based distributions - en
2021-11-01 22:06:58 -07:00
Kubernetes Prow Robot 63329f4959 Merge pull request #30307 from cloris-cc/patch-2
correct the word
2021-11-01 22:02:59 -07:00
Chiranga Alwis 514db9eb70 Improve and reorder the wording
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-11-02 10:31:38 +05:30
Chiranga Alwis eedbfd5724 Add content best practices
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-11-02 10:28:51 +05:30
Kubernetes Prow Robot e0538831df Merge pull request #30219 from calvin0327/fix-zh-kubeadm
[zh] update the kubeadm website
2021-11-01 21:56:58 -07:00
Arhell bf9e748dfb [pt-br] Including Oracle Cloud Infrastructure 2021-11-02 00:15:18 +02:00
Seokho Son 16d70bddc9 Fix outdated pod-topology-spread-constraints.md Korean 2021-11-02 02:50:38 +09:00
Kubernetes Prow Robot afbc5fc55f Merge pull request #30305 from Arhell/include
[es] Including Oracle Cloud Infrastructure
2021-11-01 10:29:19 -07:00
Seokho Son 6d18d306c2 Update outdated in dev-1.22-ko.2(67-71) 2021-11-02 02:12:17 +09:00
Seokho Son b5f838fb88 Update outdated in dev-1.22-ko.2(63-66) 2021-11-02 02:09:26 +09:00
Seokho Son 41a823b194 Update highly-available-control-plane Ko 2021-11-02 02:01:39 +09:00
Kubernetes Prow Robot fdeb34b1fd Merge pull request #30313 from Shubham82/correct-K8s_bug_reports-link
Corrected the "all Kubernetes bug reports" link in Kubernetes Security and Disclosure Information.
2021-11-01 09:55:20 -07:00
Kubernetes Prow Robot 1a8c641d79 Merge pull request #25299 from sftim/20201129_revise_api_reference
Revise “Kubernetes API Concepts”
2021-11-01 09:47:20 -07:00
Kubernetes Prow Robot b30a5df214 Merge pull request #30262 from doughgle/patch-1
Use kubectl exec [POD] -- [COMMAND] instead.
2021-11-01 09:09:18 -07:00
Kubernetes Prow Robot 7c5f6e0ea9 Merge pull request #29645 from GCES-Kubernetes/translation/InstallingKubeadmPtBr
[pt-br] Adding brazilian portuguese translation of Installing Kubeadm page
2021-11-01 04:47:19 -07:00
Shubham Kuchhal f9faa6f658 Corrected the "all Kubernetes bug reports" link in Kubernetes Security and Disclosure Information. 2021-11-01 15:20:47 +05:30
Björn Svensson f160db17d6 PodTopology: add notes of possible changed default behavior
Signed-off-by: Björn Svensson <bjorn.a.svensson@est.tech>
2021-11-01 08:34:50 +01:00
calvin 10b2b47d24 fix the kubeadm websit. 2021-11-01 10:23:00 +08:00
Arhell 7e9fe3df12 [es] Including Oracle Cloud Infrastructure 2021-11-01 00:53:06 +02:00
Kubernetes Prow Robot cae09cc667 Merge pull request #30197 from gochist/ko-service-networking
[ko] Update content/ko/docs/concepts/services-networking/
2021-10-31 08:51:17 -07:00
Kubernetes Prow Robot 3b451370f1 Merge pull request #30301 from msyhu/dev-1.22-ko.2
debug content/ko/docs/concepts/scheduling-eviction/assign-pod-node.md…
2021-10-31 08:49:19 -07:00
Kubernetes Prow Robot 574997c97e Merge pull request #30298 from deepak1725/dk-korean-netflix
[ko] fix broken blog link
2021-10-31 08:45:18 -07:00
Kubernetes Prow Robot 8600a6aa08 Merge pull request #30291 from alculquicondor/patch-2
Fix whitespace in pod topology spread constraints page
2021-10-31 06:31:18 -07:00
June Yi c86777c6a1 [ko] Update content/ko/docs/concepts/services-networking/
refs #30000 tasks M23, M24, M25 and M26

Co-authored-by: Seokho Son <shsongist@gmail.com>
2021-10-31 17:59:16 +09:00
Jacky 55192e1214 correct the word 2021-10-31 16:52:15 +08:00
msyhu cd7474e1e4 debug content/ko/docs/concepts/scheduling-eviction/assign-pod-node.md in Korean 2021-10-30 11:08:25 +09:00
Arhell 5aa34694fa [ja] Including Oracle Cloud Infrastructure 2021-10-30 01:08:34 +03:00
Kubernetes Prow Robot bc785b9dbc Merge pull request #30256 from marosset/windows-runasnonroot-updates
Updating runAsNonRoot support for Windows
2021-10-29 14:37:10 -07:00
Deepak Sharma ef7d2b1985 fix broken blog link in korean locale 2021-10-29 19:01:07 +05:30
Kubernetes Prow Robot 3dd978ec23 Merge pull request #29019 from SergeyKanzhelev/nodeRegistrationRequired
Node re-registration required to update the node labels
2021-10-29 01:10:51 -07:00
Sergey Kanzhelev 40b013b63f Node re-registration required to update the node labels 2021-10-29 05:25:48 +00:00
Anyul Rivas a898d3884f Apply suggestions from code review
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-10-28 21:48:35 +02:00
Siddhant Prateek 6ba1534f10 Mentioned Markdown flavor in Contribution new content
Signed-off-by: Siddhant Prateek <siddhantprateek@gmail.com>
2021-10-28 22:31:00 +05:30
Brad Beck b48ddd9e90 Fix zsh completion setup 2021-10-28 10:02:50 -05:00
Aldo Culquicondor 1061e7ff22 Fix whitespace in pod topology spread constraints page 2021-10-28 08:46:17 -04:00
Rodrigo Queiro f3921c9028 Remove "basic" from supported API auth methods
This was removed in v1.19.
2021-10-28 11:57:07 +02:00
Kubernetes Prow Robot 891953ec20 Merge pull request #30260 from neolit123/1.23-update-note-about-config-print
kubeadm-config.md: update the page to reflect current state
2021-10-28 02:16:28 -07:00
Kubernetes Prow Robot 5f7c3bca75 Merge pull request #30282 from aserputov/issue-30281
Fix: typo in install-kubeadm.md
2021-10-28 01:02:27 -07:00
Kubernetes Prow Robot 30d7ee91e1 Merge pull request #30196 from gochist/ko-security
[ko] Update `content/ko/docs/concepts/security`
2021-10-27 21:47:01 -07:00
Kubernetes Prow Robot b4f69ff8ad Merge pull request #30195 from gochist/ko-ingress
[ko] Update content/ko/docs/concepts/services-networking/ingress.md
2021-10-27 21:45:02 -07:00
Kubernetes Prow Robot de4728e314 Merge pull request #30178 from gochist/ko-outdated-m2
[ko] Update `concepts/architecture/nodes.md`
2021-10-27 21:43:02 -07:00
Kubernetes Prow Robot 7137b0be9f Merge pull request #30236 from zwpaper/patch-2
[zh]drop the ServerSideApply disabling part as it is GA
2021-10-27 19:27:02 -07:00
Anatoliy Serputov cb60b1dd00 Fix: typo in install-kubeadm.md 2021-10-27 19:57:28 -04:00
Kubernetes Prow Robot 62f62f3828 Merge pull request #30230 from neolit123/1.23-fix-link-to-custom-images
kubeadm: fix link to kubeadm-init#custom-images
2021-10-27 16:29:03 -07:00
Kubernetes Prow Robot 850e16fe38 Merge pull request #30193 from PranshuSrivastava/broken_link
fixed the broken link
2021-10-27 16:21:02 -07:00
Kubernetes Prow Robot 01a8f26250 Merge pull request #30234 from calvin0327/improvement-install-kubeadm
Improvement for install-kubeadm
2021-10-27 16:07:02 -07:00
Kubernetes Prow Robot a3c025e979 Merge pull request #30274 from liggitt/podsecurity-typo
Fix typo in podsecurity config example
2021-10-27 13:08:25 -07:00
Seokho Son a3666a7dac Update contribute/new-content of 1.22-ko.2 2021-10-28 04:43:17 +09:00
Anyul Rivas 8db68de0bb Apply suggestions from code review
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-10-27 21:39:59 +02:00
Anyul Rivas ec14f72ae3 Update content/es/docs/concepts/services-networking/service.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-10-27 21:28:02 +02:00
Kubernetes Prow Robot 3feb2bdf1b Merge pull request #30023 from gochist/ko-outdated-m11
[ko] Update outdated content in dev-1.22-ko.2 (Task M11)
2021-10-27 11:22:25 -07:00
Jordan Liggitt 0dfdffe95f Fix typo in podsecurity config example 2021-10-27 13:58:12 -04:00
Ali Yousefi Sabzevar e8f6406a33 add sudo to Red Hat-based distibutions, fix the sudo problem with cat using tee - es 2021-10-27 18:15:38 +02:00
Ali Yousefi Sabzevar 5a5d5584d8 fix the sudo problem with cat using tee - zh 2021-10-27 18:05:19 +02:00
Ali Yousefi Sabzevar bf117eb1b4 fix the sudo problem with cat using tee - ko 2021-10-27 18:01:27 +02:00
Lubomir I. Ivanov 586b359b05 kubeadm-config.md: update the page to reflect current state
We have seen a number of questions around the usage of "config print".
Clarify the usage of this command. Add a note that the output should
not be taken literally.

Link to the "customizing components" page instead of the "kubelet
integration" page. The former already links to the later.

Remove note about kube-dns which hasn't been supported for a while.
2021-10-27 18:52:53 +03:00
bang9211 c739af9cf1 Translate tasks/access-application-cluster/ingress-minikube.md in Korean 2021-10-28 00:34:37 +09:00
June Yi 50b47b2d4a [ko] Update outdated content in dev-1.22-ko.2 (Task M11)
Co-authored-by: Seokho Son <shsongist@gmail.com>
2021-10-28 00:08:22 +09:00
Kubernetes Prow Robot 09fe734baa Merge pull request #30270 from jonassteinberg1/patch-4
remove period and change script to command
2021-10-27 07:31:26 -07:00
Jonas Steinberg 094d9c034b remove period and change script to command
Incorrect punctuative period and change the word script to command for uniformity.
2021-10-27 08:41:51 -05:00
Guilherme Macedo b1d1fc369e Minor typo corrections and improvements for 'Overview of Cloud Native Security' page (#30185)
* Update overview.md

Minor typo corrections and improvements.

* Update overview.md

* Fix broken link
2021-10-27 05:53:25 -07:00
Ali Yousefi Sabzevar d895791f1f fix the sudo problem with cat using tee - en 2021-10-27 14:22:35 +02:00
Kubernetes Prow Robot c45bc1d9bb Merge pull request #30266 from RichieMcG/patch-1
Revert an incorrect fix
2021-10-27 03:51:25 -07:00
Tim Bannister f5bb0c7e8a Document thirdparty-content shortcode 2021-10-27 11:04:28 +01:00
Richie McG a7a4745b79 Revert an incorrect fix
corrections for  etctutl command name incorrectly “fixed” #30215
2021-10-27 18:56:16 +09:00
Kubernetes Prow Robot 069a17ce6d Merge pull request #30249 from aysabzevar/feature/add-sudo-redhat-ru
add sudo to Red Hat-based distributions - ru
2021-10-27 01:45:25 -07:00
Kubernetes Prow Robot 0a43f74008 Merge pull request #30252 from aysabzevar/feature/add-sudo-redhat-fr
add sudo to Red Hat-based distributions - fr
2021-10-27 01:33:25 -07:00
Douglas Hellinger b2035168a7 Clarify why cordon all but 4 nodes. 2021-10-27 15:58:55 +08:00
Kubernetes Prow Robot 6490aafd51 Merge pull request #30242 from sftim/20211026_fix_version_for_release_notes
Link to the release notes for the version of Kubernetes being documented
2021-10-26 21:43:26 -07:00
Kubernetes Prow Robot 63921abd6e Merge pull request #30246 from mlbiam/patch-2
Update link to new OpenUnison project documentation site
2021-10-26 21:37:26 -07:00
Wei Zhang 8c63481ccd clean up tailing spaces
Signed-off-by: Wei Zhang <kweizh@gmail.com>
2021-10-27 11:35:44 +08:00
Wei Zhang 90266acc59 sync ssa stable feature state
Signed-off-by: Wei Zhang <kweizh@gmail.com>
2021-10-27 11:35:15 +08:00
Douglas Hellinger 52fe4549f9 Update zookeeper.md 2021-10-27 10:37:34 +08:00
Douglas Hellinger 593fb144b6 Update zookeeper.md
kubectl exec [POD] [COMMAND] is DEPRECATED and will be removed in a future version. Use kubectl exec [POD] -- [COMMAND] instead.
2021-10-27 10:31:23 +08:00
calvin 7780084390 improvement for install-kubeadm. 2021-10-27 10:07:49 +08:00
Kubernetes Prow Robot 99e49b2751 Merge pull request #30068 from sftim/20211013_use_docsy_alerts
Use Docsy alert classes
2021-10-26 18:01:41 -07:00
Kubernetes Prow Robot 9497ae4123 Merge pull request #30222 from rikatz/edson-owner-pt
Add edsoncelio as language-pt approver
2021-10-26 17:59:40 -07:00
Kubernetes Prow Robot 4a3f2ef536 Merge pull request #30198 from SergeyKanzhelev/dockershimUpdates
Find out what container runtime is used and mention private registries
2021-10-26 17:15:41 -07:00
Kubernetes Prow Robot 93ec17f502 Merge pull request #30235 from zwpaper/patch-1
ServerSideApply GA, drop the beta notice
2021-10-26 17:09:47 -07:00
Kubernetes Prow Robot 4c26929247 Merge pull request #30261 from marosset/windows-limits-updates
Remove outdated section stating Windows does not support CPU limits
2021-10-26 17:07:46 -07:00
Mark Rossetti bf6ab9519d Remove outdated section stating Windows does not support CPU limits
Signed-off-by: Mark Rossetti <marosset@microsoft.com>
2021-10-26 14:35:13 -07:00
Kubernetes Prow Robot 88cec414e7 Merge pull request #30176 from bene2k1/de-feat-training-20211021
[de] Add "Training" page
2021-10-26 13:29:09 -07:00
Mark Rossetti afbb133e9f Updating runAsNonRoot support for Windows
Signed-off-by: Mark Rossetti <marosset@microsoft.com>
2021-10-26 13:25:31 -07:00
Ali Yousefi Sabzevar 982b48e20c add sudo to Red Hat-based distributions - zh 2021-10-26 22:24:42 +02:00
Ali Yousefi Sabzevar c76f61199b add sudo to Red Hat-based distributions - fr 2021-10-26 22:16:57 +02:00
Ali Yousefi Sabzevar 8fac429dbb add sudo to Red Hat-based distributions - ko 2021-10-26 22:13:59 +02:00
Ali Yousefi Sabzevar 0fc0045dba add sudo to Red Hat-based distributions - ru 2021-10-26 22:03:01 +02:00
Ali Yousefi Sabzevar 9a36c05f6a add sudo to Red Hat-based distributions - en 2021-10-26 21:43:55 +02:00
Marc Boorshtein e779d2d3fc Update link to new project documentation site 2021-10-26 15:35:17 -04:00
Rodolfo Martínez Vega 3514d186bb Update content/es/docs/concepts/workloads/pods/init-containers.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-10-26 11:57:35 -05:00
Sergey Kanzhelev 4a6d4d5dd3 find out what container runtime is used and mention private registries 2021-10-26 16:26:59 +00:00
Kubernetes Prow Robot 2cf8506197 Merge pull request #30241 from lizzzcai/update-debug-on-node
[zh] update docs for debug running pod
2021-10-26 07:07:30 -07:00
Kubernetes Prow Robot 586e74abe9 Merge pull request #30233 from ManuSquall/docs_setup_release_notes
[fr] Suggest setup/release/notes/ translation in french
2021-10-26 05:29:30 -07:00
Kubernetes Prow Robot 4565bc8716 Merge pull request #30232 from Arhell/operator
[zh] Add "KubeOps" operator SDK to third-party list
2021-10-26 04:59:31 -07:00
Kubernetes Prow Robot eeef239745 Merge pull request #30239 from Shubham82/Update-empty-link_Dynamic_Admission_Control
Improvement: Correct the "empty" link in Dynamic Admission Control.
2021-10-26 04:35:30 -07:00
Kubernetes Prow Robot b750d985eb Merge pull request #30229 from neolit123/1.23-link-to-ha-guide-main-branch
kubeadm: use git.k8s.io to link to kubeadm repo
2021-10-26 04:15:30 -07:00
Tim Bannister 45e902468c Link to the release notes for the version of Kubernetes being documented 2021-10-26 12:08:02 +01:00
Kubernetes Prow Robot cc888c6eaa Merge pull request #29881 from mallow111/issue-29850
Fix issue  #29850 - Drop v1.apps in Deployment
2021-10-26 03:35:31 -07:00
Kubernetes Prow Robot 56d10a53fb Merge pull request #30208 from adithyaakrishna/bug/language-hi
[hi] - Updated Hindi Maintainers
2021-10-26 03:31:30 -07:00
Kubernetes Prow Robot 4119c5086b Merge pull request #30091 from shannonxtreme/css-training
Modify training page CSS to wrap 2 icons at a time
2021-10-26 03:27:30 -07:00
lizzzcai 10aa724db2 [zh] update docs for debug running pod 2021-10-26 17:16:23 +08:00
Shubham Kuchhal 8fbccfcd8f Improvement: Correct the "empty" link in Dynamic Admission Control. 2021-10-26 13:51:38 +05:30
Wei Zhang d1578c4384 drop the ServerSideApply disabling part 2021-10-26 12:04:35 +08:00
Wei Zhang d7e05554de ServerSideApply GA, drop the beta notice 2021-10-26 11:54:23 +08:00
Charles Emmanuel S. Ndiaye e6ba790d73 Suggest setup/release/notes/ translation in french 2021-10-26 00:30:04 +00:00
Arhell 7150f42461 [zh] Add "KubeOps" operator SDK to third-party list 2021-10-26 01:21:09 +03:00
Kubernetes Prow Robot 1db9bf46a1 Merge pull request #30231 from stormqueen1990/update-i18n-pt-br
[pt-br] Update text for Brazilian Portuguese i18n strings
2021-10-25 14:54:25 -07:00
Lubomir I. Ivanov b8d0c07ba8 kubeadm: fix link to kubeadm-init#custom-images
Add missing / prefix otherwise the link to
"custom-images" points towards a 404.
2021-10-26 00:20:56 +03:00
Lubomir I. Ivanov 0162445d1e kubeadm: use git.k8s.io to link to kubeadm repo
With the kubeadm repository changing branch from
master -> main, use the "branchless" URL:
  git.k8s.io/kubeadm
when linking to the HA guide.
2021-10-26 00:09:19 +03:00
Seokho Son ccd10a4e08 Update ko/kubeadm-upgrade 2021-10-26 04:56:47 +09:00
Leonardo Luz Almeida 5dfe3bf1db Fix server-side-apply code snippet in blog post 2021-10-25 15:26:28 -04:00
Min Wang 7ebe37aa3a Update deployment.md 2021-10-25 12:24:22 -07:00
Kubernetes Prow Robot d6fad21377 Merge pull request #30075 from nuno-faria/patch-1
Remove extra parenthesis
2021-10-25 11:21:03 -07:00
Adithya Krishna b992026a37 Made Requested Changes
Signed-off-by: Adithya Krishna <aadithya794@gmail.com>
2021-10-25 23:12:32 +05:30
Kubernetes Prow Robot b2a401f5e7 Merge pull request #30224 from mikhailsidorov/patch-1
Fix missed word in russian translation
2021-10-25 09:30:23 -07:00
Mikhail Sidorov 8071fed3aa Fix missed word in russian translation 2021-10-25 18:52:21 +03:00
Robert Van Voorhees 489e938f1c Resolve formatting issue and add example for node affinity example. 2021-10-25 10:29:57 -04:00
Kubernetes Prow Robot b7e1c2a041 Merge pull request #30212 from deepak1725/dk-fix-netflix
fix broken blog link
2021-10-25 07:22:23 -07:00
Kubernetes Prow Robot 1a2cf23605 Merge pull request #30220 from qingsenLi/211025-fix
[zh]fix error word
2021-10-25 07:10:24 -07:00
Deepak Sharma a24fa75c7b fix broken blog link 2021-10-25 19:24:20 +05:30
slayer321 d283c1f545 docs: add PV duplicate example 2021-10-25 09:52:46 -04:00
Ricardo Katz b4ec402881 Add edsoncelio as language-pt approver 2021-10-25 10:38:24 -03:00
Kubernetes Prow Robot 092ea9b605 Merge pull request #30221 from RinkiyaKeDad/spacing_fix
fixing whitespace for pod topology spread constraints page
2021-10-25 04:38:22 -07:00
Benedikt Rollik 3af05121d3 Apply suggestions from code review
Co-authored-by: Roy Lenferink <lenferinkroy@gmail.com>
2021-10-25 13:02:20 +02:00
RinkiyaKeDad 95d9f0c19f fixing whitespace for pod topology spread constraints page
Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>
2021-10-25 15:36:11 +05:30
gwnara c771e3f2df [zh]fix error word 2021-10-25 16:16:12 +08:00
Kubernetes Prow Robot 7c0630d88b Merge pull request #30187 from qlijin/main
[zh]translate en/docs/reference/ports-and-protocols.md
2021-10-24 23:42:22 -07:00
Kubernetes Prow Robot 0a0609b234 Merge pull request #30074 from yitingdc/main
Chinese doc bugs in Admission Control session:update requests for all status subresources
2021-10-24 20:26:22 -07:00
Jin Li 19e2e57c2f [zh]translate en/docs/reference/ports-and-protocols.md. amend 2021-10-25 02:21:49 +00:00
Kubernetes Prow Robot 6d3b02a800 Merge pull request #30106 from Arhell/list
[ja] Add "KubeOps" operator SDK to third-party list
2021-10-24 19:06:21 -07:00
Kubernetes Prow Robot 7502b9e383 Merge pull request #29206 from sftim/20210803_revise_nginx_ingress_minikube_tutorial_task
Revise task for practising NGINX Ingress controller
2021-10-24 16:56:21 -07:00
Kubernetes Prow Robot 57a9c8d287 Merge pull request #29923 from Arhell/add
[pt-br] Add seccomp tutorial to index
2021-10-24 14:56:21 -07:00
Min Wang 046e3a1643 Update deployment.md 2021-10-24 12:25:04 -07:00
Kubernetes Prow Robot 0f78d4b9b8 Merge pull request #30194 from Arhell/add-oracle
[id] Including Oracle Cloud Infrastructure
2021-10-24 11:26:21 -07:00
Tim Bannister 3fc2bcbbd0 Add left indent for definition lists
Use padding to make the lists stand out from surrounding text.
2021-10-24 14:34:48 +01:00
Tim Bannister a49c612734 Rewrap API concepts page 2021-10-24 14:31:20 +01:00
Tim Bannister 2ca81a1cd2 Bump Table API to v1
Table is now GA
2021-10-24 14:31:20 +01:00
Tim Bannister a53db47615 Revise API details page 2021-10-24 14:31:19 +01:00
Kubernetes Prow Robot 90fe3d169f Merge pull request #30120 from bang9211/bang9211/force-delete-stateful-set-pod/v0.1
[ko]Translate tasks/run-application/force-delete-stateful-set-pod.md in Korean
2021-10-24 04:56:21 -07:00
Kubernetes Prow Robot c35e0742f2 Merge pull request #30024 from jmyung/jesang/gmsa/v0.2
[ko] Translate docs/tasks/configure-pod-container/configure-gmsa in Korean
2021-10-24 04:54:21 -07:00
Kubernetes Prow Robot 89c429b2e5 Merge pull request #30165 from bene2k1/de-feat-community-20211020
[de] Rework community page
2021-10-24 03:52:21 -07:00
Kubernetes Prow Robot d6bd65059d Merge pull request #30164 from bene2k1/de-fix-kubernetes-partners-20211020
[de] Fix kubernetes partners 20211020
2021-10-24 03:32:21 -07:00
Mayo 37508f176e [zh] translate concept finalizer (#30130)
* [zh] translate concept finalizer

* [zh] update translations

* [zh] update concept finalizers translations

* Update content/zh/docs/reference/glossary/finalizer.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

* Update content/zh/docs/reference/glossary/finalizer.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-10-24 02:42:21 -07:00
Adithya Krishna fab447c8e0 Updated Hindi Maintainers
Signed-off-by: Adithya Krishna <aadithya794@gmail.com>
2021-10-24 12:30:58 +05:30
yiting.jiang fd51701707 [zh] Update Dynamic Admission Control session:update requests for all status subresources 2021-10-24 07:57:39 +08:00
Zilmar de Souza Junior b0904d2328 [l10n] PT-BR - docs/concepts/scheduling-eviction/taint-and-toleration.md (#30049)
* [l10n] starting pt-br l10n

[l10n] Localização para pt-br finalizada

* Apply suggestions from code review

Co-authored-by: Ricardo Katz <rikatz@users.noreply.github.com>

Co-authored-by: Ricardo Katz <rikatz@users.noreply.github.com>
2021-10-23 13:08:21 -07:00
Kubernetes Prow Robot f0c759ded2 Merge pull request #29034 from rguichard/fr/fix-typo
[fr] fix typos and trailing spaces
2021-10-23 11:52:22 -07:00
Mauren Berti 032f1bc7fd Update translation for pt-br strings. 2021-10-23 14:14:16 -04:00
jmyung fa02dd9e77 Translate content\en\docs\tasks\configure-pod-container\configure-gmsa.md in Korean 2021-10-23 21:28:17 +09:00
Kubernetes Prow Robot 233c12b256 Merge pull request #30202 from RichieMcG/patch-1
Correct Typo
2021-10-23 02:48:20 -07:00
Richie McG 64b5b16bac Correct Typo
Correct typo form etcdutl to etcdctl on line 333
2021-10-23 17:29:03 +09:00
June Yi da17eafbd3 [ko] Update content/ko/docs/concepts/storage
refs #30000 task M27 and M28

Note: There's nothing to do for M28(`concepts/storage/volumes.md`).
2021-10-23 15:54:46 +09:00
Kubernetes Prow Robot 21e7ae323c Merge pull request #29990 from jizusun/fix-link
fix broken link for owner references in Finalizers
2021-10-22 17:46:49 -07:00
Kubernetes Prow Robot f5049435ab Merge pull request #30064 from sftim/20211012_link_pv_reclaim_policy_change_task_new_api_reference
Tidy task about PV reclaim policy
2021-10-22 17:00:50 -07:00
June Yi 3a0844cdf0 [ko] Update content/ko/docs/concepts/security
refs #30000 task M21 and M22
2021-10-23 08:51:16 +09:00
Kubernetes Prow Robot adae6c457b Merge pull request #30148 from robotjellyzone/fixingSkew
Fixing Skew in localization doc
2021-10-22 16:40:49 -07:00
June Yi c1a024808a [ko] Update content/ko/docs/concepts/services-networking/ingress.md
refs #30192
2021-10-23 08:38:16 +09:00
Pranshu Srivastava 2642b12efc made requested changes 2021-10-23 04:21:22 +05:30
Arhell e4177d31ee [id] Including Oracle Cloud Infrastructure 2021-10-23 00:35:38 +03:00
Kubernetes Prow Robot 4ecb2fda5b Merge pull request #30099 from lucasbasquerotto/patch-1
Fix typo at deployment.md
2021-10-22 13:26:44 -07:00
Pranshu Srivastava 1ee91f08c9 fixed the broken link 2021-10-22 21:29:07 +05:30
Sander Saares 667d338866 Adjust wording based on review comment 2021-10-22 16:41:21 +03:00
Kubernetes Prow Robot 754b9e5a9f Merge pull request #30054 from Arhell/add-volume
[ja] add volume and volumeMount for ephemeral storage
2021-10-22 05:08:37 -07:00
Kubernetes Prow Robot 2198295876 Merge pull request #28550 from jihoon-seo/210622_ru_Remove_exec_permission_on_markdown_files
[ru] Remove exec permission on markdown files
2021-10-22 00:38:38 -07:00
Sander Saares 3f5ab3f982 A CPU request does not result in a guarantee
It is merely a pod placement constraint but the phrasing leads readers to  the incorrect understanding that some actual CPU time is guaranteed/reserved. Re-phrase to make it clear this is nothing more than a request.
2021-10-22 09:02:42 +03:00
Kubernetes Prow Robot 66d9eb730d Merge pull request #29946 from neolit123/1.23-update-docs-about-image-repository
kubeadm: add more details about air-gapped and custom images
2021-10-21 22:42:37 -07:00
Kubernetes Prow Robot 286db402a2 Merge pull request #30123 from sftim/20211017_more_responsive_figure_sizing
Make  figure sizing more responsive
2021-10-21 17:10:37 -07:00
Marcos Nery 1e7a48f0eb improving translation 2021-10-21 15:59:28 -03:00
Kubernetes Prow Robot a50554d5a8 Merge pull request #30142 from afro-coder/p1-dev
Added CSS to improve user experience with docs and reduce wasted space
2021-10-21 11:27:46 -07:00
Kubernetes Prow Robot 9cdec9389e Merge pull request #30158 from sandipanpanda/fix-ko-issue-30101
Fix broken link of Install Docker Engine - Enterprise on Windows Servers in Ko docs
2021-10-21 08:55:37 -07:00
Kubernetes Prow Robot a60955f8f2 Merge pull request #30177 from lucasbasquerotto/patch-2
Fix typo at network-policies.md
2021-10-21 08:47:39 -07:00
June Yi ae291c71d6 [ko] Update concepts/architecture/nodes.md
refs #30000 task M2
2021-10-22 00:19:27 +09:00
Ravi Gudimetla 1afd786d1b Apply suggestions from code review
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-10-21 10:46:42 -04:00
Benedikt Rollik be22f0ce77 typo 2021-10-21 15:58:07 +02:00
Lucas Basquerotto c9847dafe2 Fix typo at network-policies.md 2021-10-21 10:57:42 -03:00
Benedikt Rollik a8cd1e5b50 fix typo 2021-10-21 15:53:14 +02:00
Benedikt Rollik 00887ca1b3 de-add-training-page 2021-10-21 15:50:35 +02:00
Benedikt Rollik d9db5520af fixed some translations 2021-10-21 15:07:18 +02:00
Jizu Sun 2342716d89 Merge branch 'main' into fix-link 2021-10-21 18:05:15 +08:00
bang9211 c1d5cec4c3 Translate tasks/run-application/force-delete-stateful-set-pod.md in Korean 2021-10-21 17:48:24 +09:00
Kubernetes Prow Robot c8b54b4b19 Merge pull request #30033 from gochist/ko-update-m17-m18
[ko] Update working-with-objects
2021-10-20 18:12:08 -07:00
Kubernetes Prow Robot de826159ab Merge pull request #29905 from sftim/20211003_clean_up_post_docsy
Clean up pre-Docsy content and styles
2021-10-20 17:54:09 -07:00
June Yi b8a764b843 [ko] Update working-with-objects
refs #30000 task M17, M18

Co-authored-by: Seokho Son <shsongist@gmail.com>
2021-10-21 09:42:27 +09:00
Kubernetes Prow Robot f971d36953 Merge pull request #29984 from superleo/branch1
[zh] Concept files to sync for 1.22 - task13 - k8s Extension
2021-10-20 17:16:08 -07:00
sandipanpanda d33605578f Fix broken link in k8s.io/docs/concepts/overview/working-with-objects/finalizers/ (#30159)
* Fix broken link in finalizers.md

* Update finalizers.md

* Update finalizers.md
2021-10-20 16:56:08 -07:00
Kubernetes Prow Robot 6c5c10a087 Merge pull request #30163 from bene2k1/de-fix-kubecon-dates-20211020
[de] Fix homepage kubecon dates
2021-10-20 13:26:05 -07:00
Anthony Rosequist ebe5a92cbe Add missing space before parenthesis 2021-10-20 15:24:22 -05:00
Benedikt Rollik 569b037a13 fix typo 2021-10-20 20:36:02 +02:00
Benedikt Rollik d31a7ebcfc fix typo 2021-10-20 20:33:57 +02:00
Benedikt Rollik 64e4933cf6 Update content/de/_index.html 2021-10-20 20:11:08 +02:00
Benedikt Rollik af2f72f603 de-fix-kubecon-dates-20211020 2021-10-20 17:51:03 +02:00
Benedikt Rollik a12ab9693f de-feat-community-20211020 2021-10-20 17:41:21 +02:00
Benedikt Rollik 897969944d de-fix-kubernetes-partners 2021-10-20 17:13:18 +02:00
Benedikt Rollik 260f0231f5 de-fix-kubernetes-partners 2021-10-20 17:12:19 +02:00
Benedikt Rollik c25da5c007 fix(homepage): kubecon dates 2021-10-20 16:44:02 +02:00
superleo b67a853e93 Concept files to sync for 1.22 - task13 - k8s Extension 2021-10-20 22:16:36 +08:00
Kubernetes Prow Robot 4eaafa14e3 Merge pull request #28551 from jihoon-seo/210622_de_Remove_exec_permission_on_markdown_files
[de] Remove exec permission on markdown files
2021-10-20 07:05:59 -07:00
robotjellyzone 2fbb744783 added one space at end 2021-10-20 17:48:49 +05:30
sandipanpanda 4ec23262f4 Update adding-windows-nodes.md 2021-10-20 16:43:30 +05:30
Anyul Rivas 8d5de7eb71 Apply suggestions from code review
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-10-20 10:50:12 +02:00
Anyul Rivas b952419be6 docs: Spanish translation for Service
chore: fix indentation
2021-10-20 10:50:11 +02:00
robotjellyzone 5f2dd40003 added two spaces at end 2021-10-20 14:16:37 +05:30
robotjellyzone 5ad520a6ab Fixing Skew localization doc 2021-10-20 11:46:52 +05:30
Kubernetes Prow Robot bbd7abf107 Merge pull request #29978 from riita10069/feature/reference/access-authn-authz/authentication
[ja] Replace with a link in Japanese about authentication.md
2021-10-19 18:47:58 -07:00
Kubernetes Prow Robot 41d2c8856e Merge pull request #30132 from Arhell/update-compose
[zh] Update translate-compose-kubernetes.md
2021-10-19 17:05:57 -07:00
Chiranga Alwis 40f5256924 Notify deletion of Kubelet bootstrap token
Kubeadm deletes the file `/etc/kubernetes/bootstrap-kubelet.conf` as per https://github.com/kubernetes/kubernetes/pull/80676
2021-10-20 02:20:40 +05:30
Rodolfo Martínez Vega 675e427426 Update typos and apply suggestions from PR review 2021-10-19 13:08:05 -05:00
Lubomir I. Ivanov 6ea5318972 kubeadm/TS guide: fix a misleading step about cert rotation
The "kubelet-finalize" step does not work on worker nodes,
because commonly they do not have the cluster CA key and all
"init" phases have a pre-step to check for the existence of
the CA key, designating the cluster as one that uses external CA
or not.

Changing this behavior is complicated in kubeadm, thus manually
instruct the user how to do edit the file and to restart the kubelet.

This is already what we do in:
https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#check-certificate-expiration
2021-10-19 20:24:48 +03:00
Kubernetes Prow Robot 3d826f0957 Merge pull request #29695 from ixodie/patch-5
Removed Contiv.io
2021-10-19 07:47:04 -07:00
ixodie 33c363a370 Added open contiv repo
Adding back repo and removing broken link
2021-10-19 09:19:25 -04:00
ixodie 46fc61cd04 Merge branch 'main' into patch-9 2021-10-19 09:16:16 -04:00
afro-coder f4bea11f53 Added css to improve user experience with docs 2021-10-19 18:12:48 +05:30
Kubernetes Prow Robot 1ec4e8effc Merge pull request #30114 from Arhell/update
[zh] pdate controlling-access.md as --insecure-port flag deprecated
2021-10-19 01:20:39 -07:00
Jizu Sun a6f27be7e1 Update content/en/docs/concepts/overview/working-with-objects/finalizers.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-10-19 10:48:54 +08:00
Kubernetes Prow Robot e19471938e Merge pull request #30065 from Arhell/upd-vol
[es] add volume and volumeMount for ephemeral storage
2021-10-18 16:27:35 -07:00
ixodie 7d9051266d Removing GCE bridging/routing config tweaks
Removing this content seems to be appropriate:

Content does not contain a link to a CNI.
Content is not required for k8s to function.
Content seems to be replicated in longer form on the Google Cloud docs site.
2021-10-18 18:29:33 -04:00
Arhell 6c38d87555 [zh] Update translate-compose-kubernetes.md 2021-10-19 00:33:07 +03:00
Kubernetes Prow Robot ea8244a5e9 Merge pull request #30090 from ixodie/patch-7
Removed Nuage marketing
2021-10-18 13:37:22 -07:00
chirangaalwis 35525d17b5 Add extra details for clarity 2021-10-18 20:44:13 +05:30
chirangaalwis fc25753118 Remove unnecessary comment 2021-10-18 20:32:38 +05:30
Chiranga Alwis dcbf152118 Remove unnecessary reference to scheduler
Co-authored-by: Aldo Culquicondor <1299064+alculquicondor@users.noreply.github.com>
2021-10-18 20:29:53 +05:30
Chiranga Alwis 9a0f0e25ea Rearrange words for better meaning
Co-authored-by: Deepak Gupta <deepakgdkg1g8868@gmail.com>
2021-10-18 20:28:17 +05:30
Kubernetes Prow Robot 3ffaf8bc11 Merge pull request #30124 from Arhell/release
[zh] Fix release cadence in deprecation policy page
2021-10-18 05:51:50 -07:00
Kubernetes Prow Robot 9a0ab2260c Merge pull request #29973 from riita10069/feature/tutorials/stateless-application/guestbook
[ja] Replace with a link in Japanese regard as guestbook.md
2021-10-18 04:55:49 -07:00
Kubernetes Prow Robot 3f824a8989 Merge pull request #28601 from RA489/update_etcd
Example with data dir for restore
2021-10-18 01:35:51 -07:00
Kubernetes Prow Robot 15235d6e1a Merge pull request #30119 from tzzs/patch-1
Update install-kubectl-linux.md
2021-10-17 22:57:49 -07:00
chirangaalwis 029ec4cd67 Combine Service Account to map with resource kind 2021-10-18 10:53:00 +05:30
RA489 cbc8ad69f5 explanation of the role of activeDeadlineSeconds in initContainers behaviour 2021-10-18 10:40:44 +05:30
RA489 c689362c08 Example with data dir for restore 2021-10-18 10:32:25 +05:30
Chiranga Alwis 10846473ac Add reference to the created scheduler configuration CM
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-10-18 10:21:13 +05:30
Arhell 056f2cbcb6 [zh] Fix release cadence in deprecation policy page 2021-10-18 00:17:33 +03:00
Tim Bannister dc84f0cb97 Mark figures' intended size
This commit activates Sass styling to make image sizes more responsive
on the rendered page.
2021-10-17 21:31:52 +01:00
Tim Bannister 1fe561a4de Style diagrams based on intended size 2021-10-17 21:31:27 +01:00
Kubernetes Prow Robot e9cee7345b Merge pull request #30113 from 100mik/add-create-pod-example
Add Pod creation example in k8s.io/docs/concepts/workloads/pods/
2021-10-17 12:57:48 -07:00
Kubernetes Prow Robot 282661404d Merge pull request #30008 from chirangaalwis/patch-2
Add missing example for querying permissions of a Service Account
2021-10-17 12:09:49 -07:00
Kubernetes Prow Robot 381dfa36e4 Merge pull request #29466 from chrismetz09/metz-pictContrib
Add mermaid figures to /docs/contribute section
2021-10-17 09:51:48 -07:00
Shatakshi 114d66760e update release-managers.md 2021-10-17 21:05:00 +05:30
TAN ZHENG 27fd1a3bc0 Update install-kubectl-linux.md
fix the problem that kubectl convert part of the serial number error
2021-10-17 20:16:37 +08:00
Shatakshi cdb2735dae update release-managers.md 2021-10-17 17:32:25 +05:30
Shatakshi b91526b51a fix broken link in release-managers.md 2021-10-17 16:31:59 +05:30
ztzxt c864a62dff Bump dashboard version to 2.4.0 from 2.3.1 2021-10-17 13:28:03 +03:00
Arhell 8029142078 [zh] pdate controlling-access.md as --insecure-port flag deprecated 2021-10-17 01:26:14 +03:00
Soumik Majumder 04a53b8ad0 Add Pod creation example in k8s.io/docs/concepts/workloads/pods/ 2021-10-17 01:50:02 +05:30
chirangaalwis b06baf8f80 Re-order ConfigMap definition 2021-10-16 21:52:09 +05:30
nuno-faria d7ccf551bf Create a separate sentence 2021-10-16 12:55:35 +01:00
chirangaalwis 8e250cf405 Update references to invalid --scheduler-name arg 2021-10-16 15:02:45 +05:30
chirangaalwis 95be4e5e65 Update multiple scheduler with HA guide 2021-10-16 14:55:30 +05:30
chirangaalwis 6ec90297d0 Update multiple scheduler deployment guide 2021-10-16 13:31:18 +05:30
chirangaalwis 0add8b4a53 Remove --bind-address kube-scheduler argument
Defaults to 0.0.0.0
2021-10-16 13:30:24 +05:30
chirangaalwis 067f8a9370 Update custom scheduler example for v1.22+
Remove invalid scheduler args, add new scheduler args and add new Scheduler Configuration for defining scheduler name
2021-10-16 12:49:55 +05:30
Arhell f6ff10e5ab [ja] Add "KubeOps" operator SDK to third-party list 2021-10-16 00:23:36 +03:00
Rodolfo Martínez Vega 68502af09c Improve translation of about 2021-10-15 16:22:18 -05:00
Rodolfo Martínez Vega bf38b5f17a [es] Add content/es/docs/concepts/workloads/pods/init-containers.md 2021-10-15 13:45:29 -05:00
Lucas Basquerotto 3dd5ec4121 Fix typo at deployment.md 2021-10-15 10:20:36 -03:00
Kubernetes Prow Robot df256aaee5 Merge pull request #30098 from ba1ajinaidu/patch-1
fixed a typo
2021-10-15 03:48:54 -07:00
Kubernetes Prow Robot a583a3ef03 Merge pull request #29975 from riita10069/feature/concepts/services-networking/ingress
[ja] Replace with a link in Japanese about ingress.md
2021-10-15 03:46:54 -07:00
Kubernetes Prow Robot 9731195690 Merge pull request #30088 from Shabirmean/patch-1
doc: update definition for namespaces
2021-10-15 03:24:54 -07:00
Balajinaidu V cbd7a7ab74 fixed a typo 2021-10-15 15:07:17 +05:30
Kubernetes Prow Robot 69c0cc7457 Merge pull request #29884 from Arhell/loc
[ja] Update location of PrepareNode.ps1
2021-10-15 01:46:55 -07:00
Kubernetes Prow Robot 86ebfe00bd Merge pull request #30081 from Arhell/typo
[zh] fixed typo
2021-10-14 18:08:54 -07:00
Kubernetes Prow Robot 8fb866a9d2 Merge pull request #30020 from tengqm/fix-kubelet-userns
Tweak the kubelet in user namespace page
2021-10-14 17:54:54 -07:00
Shabir Mohamed Abdul Samadh 867eb85e3d doc: update the glossary with new namespace re-write 2021-10-14 20:35:23 -04:00
Shabir Mohamed Abdul Samadh b3ff003048 doc: accommodate re-write of intro line 2021-10-14 20:31:16 -04:00
Shabir Mohamed Abdul Samadh 86b6584d0a doc: accept review suggestion 2021-10-14 20:25:30 -04:00
ixodie f8dcb7e792 Removed OVS
Open vSwitch is in no way required for Kubernetes to function.  Kubernetes is not mentioned once on this project's website, nor are there any instructions for how you might use this in a k8s environment.
2021-10-14 16:04:38 -07:00
ixodie 8d4006d8ed Removed Nuage marketing
This entry is not necessary for Kubernetes to function.  Entry provides a link to the main corporate website, not to any relevant information.  No CNI.  Acronym refers to product marketing, not an actual technology.
2021-10-14 15:37:19 -07:00
Shannon Kularathna 3a19cabbe6 Modify CSS to wrap 2 icons at a time 2021-10-14 22:36:09 +00:00
shabirmean 0ca22ac568 doc: update definition for namespaces
Update namespace definition to not use _Virtual Clusters_ as a means of explaining namespaces.

Motif: KubeCon NA 21 Talk on ***"Beyond Namespaces: Virtual Clusters are the Future of Multi-Tenancy - Lukas Gentele, Loft Labs"***
2021-10-14 15:06:29 -04:00
Kubernetes Prow Robot d2f2b29394 Merge pull request #30078 from shannonxtreme/training-kcnf
Add KCNA to training
2021-10-14 09:57:18 -07:00
Kubernetes Prow Robot c7289133df Merge pull request #30062 from seokho-son/out-dev-1.22-ko.2-m59-60
[ko] Update outdated Korean for task m59-m60
2021-10-13 21:59:28 -07:00
Kubernetes Prow Robot de9c63ecf2 Merge pull request #30061 from seokho-son/out-dev-1.22-ko.2-m58
[ko] Update outdated Korean in web-ui-dashboard.md
2021-10-13 21:57:28 -07:00
seokho-son 920818b73a Update outdated Korean for task m59-m60 2021-10-14 11:03:42 +09:00
seokho-son fe2ab336f6 Update outdated Korean in web-ui-dashboard.md 2021-10-14 10:30:32 +09:00
Tim Bannister 23b677d6fb Exempt case studies list from announcements
Announcements don't show for individual case studies. Make the list
page also skip any current announcement.
2021-10-13 22:49:42 +01:00
Tim Bannister 1e436f4587 Revise page header styles
- more compact headers when announcements are showing
- when no announcement showing, top level docs sections
  (eg Concepts, Tasks, Reference) have a heading in the top nav
- when announcement is showing, rely on the breadcrumb trail plus
  page introduction text for each top level section
- switch from plain black docs header to match other sections
2021-10-13 22:47:29 +01:00
Arhell 81692fa0da [zh] fixed typo 2021-10-14 00:31:41 +03:00
Shannon Kularathna c798fdc4fb Add KCNA to training 2021-10-13 20:55:39 +00:00
Tim Bannister cccf7b2102 Tweak advice about kubectl skew
This change helps make the example apply more relevantly to older docs
releases.
2021-10-13 19:35:06 +01:00
Kubernetes Prow Robot 239eb65bc2 Merge pull request #30071 from chetak123/main
changed links from beta2-beta3
2021-10-13 09:27:49 -07:00
Kubernetes Prow Robot 8c73ffe376 Merge pull request #30072 from huzhengchuan/patch-4
fix typos
2021-10-13 07:53:50 -07:00
nuno-faria 3ee7b1f354 Remove extra parenthesis 2021-10-13 12:02:00 +01:00
Kubernetes Prow Robot daf5a932b6 Merge pull request #30035 from gochist/ko-update-m19-m20
[ko] Update scheduling-eviction
2021-10-12 23:31:50 -07:00
Kubernetes Prow Robot d7989c9af4 Merge pull request #30029 from gochist/ko-update-m13
[ko] Update custom-resources.md (task M13)
2021-10-12 23:29:49 -07:00
huzhengchuan 98e5b3e90b fix typos
not need '('
2021-10-13 14:21:15 +08:00
Kubernetes Prow Robot b74927a468 Merge pull request #30030 from gochist/ko-update-m14-m16
[ko] Update extend-kubernetes
2021-10-12 22:59:48 -07:00
Ayushman Mishra 8387af37e8 changed links from beta2-beta3
Signed-off-by: Ayushman Mishra <ayushvidushi01@gmail.com>
2021-10-13 10:34:55 +05:30
Kubernetes Prow Robot d2dc3b13d9 Merge pull request #30032 from mayocream/update_concept_pods
[zh]: update concept workload pods
2021-10-12 20:25:48 -07:00
Tim Bannister 4a57e58ab4 Use Docsy alert classes
Update the Kubernetes overrides from the Docsy theme to diverge less,
specifically in the areas of callouts (alerts) and pageinfo blocks.
2021-10-13 01:10:58 +01:00
Tim Bannister 8230d25180 Mark Docker as third-party software
As per the content guide, Docker is (essential) third party software.
Alternatives exist but Docker is certainly the most common tool used for
this kind of task.

Anyway, mark that it's third party.
2021-10-13 00:10:56 +01:00
Tim Bannister 0ce669e40d Revise “Pull an Image from a Private Registry”
- link to new-style API reference
- call a manifest a manifest
- use tooltips where appropriate
- other general tidying
2021-10-13 00:10:06 +01:00
Arhell 6e88ee45a2 [es] add volume and volumeMount for ephemeral storage 2021-10-13 00:48:35 +03:00
Tim Bannister 24dab6c202 Tidy task about PV reclaim policy
- Use new API reference shortcode
- Tweak What's Next subheading to be a plural
2021-10-12 21:36:37 +01:00
Tim Bannister 9d77a6bf22 Revise task for practising NGINX Ingress controller 2021-10-12 20:33:40 +01:00
chrismetz09 aec7dd4ea3 Add mermaid figures to /docs/contribute section 2021-10-12 11:30:39 -07:00
Kubernetes Prow Robot f00d77fa93 Merge pull request #30028 from gochist/ko-outdated-m12
[ko] Update outdated content in dev-1.22-ko.2 (Task M12)
2021-10-12 07:23:47 -07:00
Kubernetes Prow Robot d6ad1d1e1e Merge pull request #30018 from gochist/ko-outdated-m10
[ko] Update outdated content in dev-1.22-ko.2 (Task M10)
2021-10-12 06:39:48 -07:00
Kubernetes Prow Robot d166c4b5c6 Merge pull request #30017 from gochist/ko-update-m9
[ko] Update outdated content of dev-1.22-ko.2 (Task M9)
2021-10-12 06:37:47 -07:00
Mayo dd1e1ae107 [zh] update concept workload pods 2021-10-12 21:35:14 +08:00
Kubernetes Prow Robot 85d3fb9900 Merge pull request #30015 from mayocream/update_concept_policy
[zh] update concept policy
2021-10-11 19:49:46 -07:00
Kubernetes Prow Robot 814fcb5f02 Merge pull request #30014 from mayocream/update_concept_workload_ctl
[zh] update concept workload controller
2021-10-11 19:47:46 -07:00
Kubernetes Prow Robot 627de25492 Merge pull request #29991 from mysunshine92/update-feature-gates-JobTrackingWithFinalizers
Update feature-gates
2021-10-11 19:43:46 -07:00
Kubernetes Prow Robot 503995c764 Merge pull request #30037 from mayocream/update_concept_basic_objects
[zh] update concept basic objects
2021-10-11 19:33:46 -07:00
wangyamei 0f35593261 Update feature-gates.md 2021-10-12 10:32:48 +08:00
Mayo 997ddb150a [zh] update concept basic objects 2021-10-12 10:28:52 +08:00
Qiming Teng 59ad3d65b0 Tweak the kubelet in user namespace page
This PR fixes some nits in the page and adds some links for the
convenience of users.
2021-10-12 09:10:18 +08:00
Arhell 5254e90988 [ja] add volume and volumeMount for ephemeral storage 2021-10-12 00:37:01 +03:00
Kubernetes Prow Robot 451bbe2fc3 Merge pull request #30050 from sftim/20211011_fix_api_reference_kubeadm_link
replaced link from api-beta2 to api-beta3
2021-10-11 11:01:02 -07:00
Lubomir I. Ivanov a7badaddeb kubeadm: add more details about air-gapped and custom images
- Include more details about custom image repositories, such
as making sure that paths in custom repositories comply with
kubeadm execution.
- Move the section "without internet connection" above
the section about custom images.
- Link the "create-cluster-kubeadm.md" guide these new section
as a pre-req step for nodes.
2021-10-11 20:45:00 +03:00
siddhantprateek 99b807a761 replaced link from api-beta2 to api-beta3
Signed-off-by: siddhantprateek <siddhantprateek@gmail.com>
2021-10-11 17:52:01 +01:00
Kubernetes Prow Robot e007d9e7f2 Merge pull request #29944 from paranoidsp/docs-fixes
docs: document nlb eip allocation annotation on AWS
2021-10-11 09:50:40 -07:00
Kubernetes Prow Robot 0c69a1939e Merge pull request #30048 from sftim/20211011_tidy_kpng_article
Tidy kpng article
2021-10-11 09:24:40 -07:00
Tim Bannister cde171c42a Follow convention for article attribution 2021-10-11 16:23:28 +01:00
Tim Bannister d41ca5886c Tweak wording 2021-10-11 16:23:18 +01:00
Kubernetes Prow Robot 873a25adf7 Merge pull request #29783 from Nordix/kpng-1
Added blog post kpng-specialized-proxiers
2021-10-11 08:16:40 -07:00
Kubernetes Prow Robot 4be7035112 Merge pull request #30043 from lifeoncloud/dev-1.22-ko.2
Translate content/en/blog/_posts/2021-08-04-kubernetes-release-1.22.md in Korean
2021-10-11 08:08:40 -07:00
Kubernetes Prow Robot 9e24e75f6b Merge pull request #30009 from ClaudiaJKang/ko-29559
[ko] Translate docs/reference/glossary/sysctl.md in Korean
2021-10-11 08:02:40 -07:00
Mayo 8c6927dcc7 add missing translation 2021-10-11 23:01:19 +08:00
Mayo/IO a630d578a4 Apply suggestions from code review
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-10-11 22:52:49 +08:00
Karthikeya Viswanath 7dd48726df fix: correct the url
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-10-11 19:17:05 +05:30
Kubernetes Prow Robot 4dc89571de Merge pull request #30027 from Arhell/update
[zh] docs: Update custom-resource-definition-versioning.md
2021-10-11 06:44:40 -07:00
Kubernetes Prow Robot d199236402 Merge pull request #30025 from jmyung/patch-2
Update configure-gmsa.md
2021-10-11 06:42:40 -07:00
Chiranga Alwis dc326f0389 Add example for querying SA permissions
Add example for querying SA permissions

Add missing example for querying the API authorization layer for checking the permissions of a Service Account

Add missing SA identifying prefix

Improve suggested text to align with current content

Co-authored-by: Sam Roth <2413031+sejr@users.noreply.github.com>

Improve suggested text to align with current content

Co-authored-by: Sam Roth <2413031+sejr@users.noreply.github.com>
2021-10-11 18:14:39 +05:30
lifeoncloud e616b0a519 Update 2021-08-04-kubernetes-release-1.22.md
update date in Upcoming release webinar
2021-10-11 21:29:33 +09:00
June Yi 43508d68fc [ko] Update extend-kubernetes
refs #30000 (Tasks: M14, M15, M16)

note: M16 is not needed to be updated in Korean

Co-authored-by: Juhee Kang <claudiajkang@gmail.com>
2021-10-11 20:29:03 +09:00
Kubernetes Prow Robot 213108de46 Merge pull request #30002 from mayocream/update_concept_pv
[zh] update concept pv
2021-10-11 02:58:39 -07:00
Kubernetes Prow Robot e40d643241 Merge pull request #29996 from mayocream/update_pod_security_standards
[zh] update pod security standards
2021-10-11 02:56:39 -07:00
Juhee Kang 893b982719 [ko] Translate docs/reference/glossary/sysctl.md in Korean 2021-10-11 18:45:24 +09:00
June Yi f5981bc701 [ko] Update scheduling-eviction
refs #30000 task M19, M20
2021-10-11 18:08:14 +09:00
Kubernetes Prow Robot 8952e71897 Merge pull request #30007 from elderdeveloper15/JesusCota
[es] Add content/es/docs/reference/glossary/workload
2021-10-11 00:18:37 -07:00
June Yi b48071ad7a [ko] Update custom-resources.md
refs #30000
2021-10-11 13:30:44 +09:00
Kubernetes Prow Robot 05ef75cf19 Merge pull request #29965 from howieyuen/concept-10
[zh] sync storage-classes.md & volumes.md in storage
2021-10-10 19:18:36 -07:00
June Yi 25837b5599 [ko] Update outdated content in dev-1.22-ko.2 (Task M12) 2021-10-11 10:42:18 +09:00
Kubernetes Prow Robot 15be8889a6 Merge pull request #30026 from jmyung/patch-3
Update feature-gates.md
2021-10-10 18:34:37 -07:00
Arhell 587d19c83c [zh] docs: Update custom-resource-definition-versioning.md 2021-10-11 00:21:10 +03:00
Jesang Myung 05a21707dd Update feature-gates.md
Delete duplicated lines (DynamicKubeletConfig)
2021-10-11 03:13:52 +09:00
Jesang Myung 56506ce8db Update configure-gmsa.md
add start backquote in line 261. It was missing.
2021-10-11 03:05:25 +09:00
Kubernetes Prow Robot 0f0114aab8 Merge pull request #29989 from DiegoServinHdn/DiegoServinHDN-translations
[es] Add content/es/docs/reference/glossary/wg
2021-10-10 09:28:37 -07:00
June Yi f5270d64c8 [ko] Update outdated content in dev-1.22-ko.2 (Task M10) 2021-10-10 21:15:39 +09:00
June Yi 0c3dbcb2e8 [ko] Update outdated content of dev-1.22-ko.2 (Task M9) 2021-10-10 21:08:11 +09:00
Mayo 93e202cd5f [zh] update concept policy 2021-10-10 18:25:27 +08:00
Mayo 5cce85b5dc [zh] update concept workload controller 2021-10-10 17:43:42 +08:00
Kubernetes Prow Robot 3daa802073 Merge pull request #30001 from seokho-son/out-1.22-ko.2-01
[ko] Update outdated in dev-1.22-ko.2 (Task M3-M5)
2021-10-09 20:58:36 -07:00
Mayo d3c842419d [zh] update concept pv 2021-10-10 11:45:34 +08:00
elderdeveloper15 b31d7cd878 Feedback sugerido por Victor Morales aplicado. 2021-10-09 19:39:43 -05:00
Kubernetes Prow Robot b7a6f0e532 Merge pull request #29853 from EricWvi/main
modify kubeadm config example about joining a node to dual-stack cluster
2021-10-09 13:24:35 -07:00
elderdeveloper15 7b5dac2987 Add [es] content\es\docs\reference\glossary\workload.md
Traducción del archivo workload.md al idioma español.
2021-10-09 14:55:40 -05:00
Kubernetes Prow Robot 98c1f3099f Merge pull request #30005 from gochist/ko-update-m8
[ko] Update outdated content in dev-1.22-ko.2 (Task M8)
2021-10-09 11:36:41 -07:00
Kubernetes Prow Robot c579e16a0e Merge pull request #30003 from gochist/update-outdated-m6
[ko] Update outdated in dev-1.22-ko.2 (Task M6)
2021-10-09 11:34:36 -07:00
Kubernetes Prow Robot 2887606771 Merge pull request #30004 from gochist/ko-outdated-m7
[ko] Update outdated content in dev-1.22-ko.2 (Task M7)
2021-10-09 11:32:36 -07:00
June Yi 4499017f7c [ko] Update outdated content in dev-1.22-ko.2 (Task M8) 2021-10-10 02:44:22 +09:00
June Yi 850144b6ef [ko] Update outdated content in dev-1.22-ko.2 (Task M7) 2021-10-10 02:19:08 +09:00
June Yi 1a256a68cd [ko] Update outdated in dev-1.22-ko.2 (Task M6) 2021-10-10 01:58:51 +09:00
Mayo 3ec48a1963 [zh] update concept pod security standarts 2021-10-10 00:49:59 +08:00
Seokho Son 0cc9ae1a50 Update outdated in dev-1.22-ko.2 (Task M3-M5) 2021-10-10 00:54:09 +09:00
Kubernetes Prow Robot 38be851062 Merge pull request #29998 from kubernetes/dev-1.22-ko.1
[ko] 1st Korean localization work for v1.22
2021-10-09 06:54:36 -07:00
Kubernetes Prow Robot 1cd35c2a42 Merge pull request #29651 from likakuli/patch-2
[ja] Update nodelocaldns.md
2021-10-09 03:20:36 -07:00
Kubernetes Prow Robot 14e5fe697f Merge pull request #29941 from seokho-son/outdate-1.22-ko.1-m52
[ko] Update outdated files in dev-1.22-ko.1 (M52)
2021-10-08 22:12:36 -07:00
Kubernetes Prow Robot 2bf7e078e9 Merge pull request #29934 from seokho-son/outdate-ko-1.22-nodes
[ko] Update outdated Korean architecture/nodes
2021-10-08 22:10:36 -07:00
Lars Ekman 1d1c96c176 Added blog post kpng-specialized-proxiers 2021-10-09 06:44:48 +02:00
howieyuen c599644f69 [zh] sync storage-classes.md & volumes.md in storage 2021-10-09 10:52:41 +08:00
Jizu Sun 5c0dd0414b remove blank 2021-10-09 10:50:09 +08:00
Jizu Sun 95a772fea7 fix link 2021-10-09 10:47:55 +08:00
Diego Servin Hamden 21fe964b9d Update content/es/docs/reference/glossary/wg.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-10-08 19:38:47 -05:00
Kubernetes Prow Robot a03a4f2c5e Merge pull request #29969 from seokho-son/outdate-1.22-ko.1-d1.d2
[ko] Update outdated files in dev-1.22-ko.1 (D1-D2)
2021-10-08 17:36:37 -07:00
Kubernetes Prow Robot eca37a7161 Merge pull request #29961 from bang9211/bang9211/run-stateless-application-deployment/v0.1
[ko]Translate tasks/run-application/run-stateless-application-deployment.md in Korean
2021-10-08 17:34:36 -07:00
Diego Servin 4d5af741f8 [es] Add content/es/docs/tasks/tools/wg.md 2021-10-08 17:45:22 -05:00
Kubernetes Prow Robot 383dbc251c Merge pull request #29572 from stormqueen1990/configmaps-pt-br
[pt-br] Translate ConfigMap page to Brazilian Portuguese
2021-10-08 15:38:36 -07:00
Mauren Berti 48808351dd Add explanation on secret encryption. 2021-10-08 14:13:52 -04:00
Mauren Berti 31e44b5774 Clarify secret encryption in the glossary.
- Add a sentence clarifying that secrets are not encrypted by default.
2021-10-08 14:03:40 -04:00
Kubernetes Prow Robot a49eac05fc Merge pull request #29815 from steven-my/29329-translation-for-admin-3
[zh] translation for admin3
2021-10-08 05:42:58 -07:00
Kubernetes Prow Robot 9fc70b4938 Merge pull request #29878 from aychen99/aychen99-patch-1
[zh] Update basic-stateful-set.md
2021-10-08 05:04:58 -07:00
Kubernetes Prow Robot 9dce5a744d Merge pull request #29807 from anubha-v-ardhan/verma-kunal
Update sig-docs-hi reviewers
2021-10-08 04:02:58 -07:00
Riita 05692590ad Update rbac.md 2021-10-08 17:55:56 +09:00
Riita 7fe322059f Update service.md 2021-10-08 17:49:49 +09:00
Riita 03c87a4746 Update guestbook.md 2021-10-08 17:48:40 +09:00
Riita 56a0c18256 Update scale-stateful-set.md 2021-10-08 17:46:33 +09:00
Riita 5919a94075 Update ingress.md 2021-10-08 17:44:20 +09:00
Riita 40accf234d Update overview.md 2021-10-08 17:37:18 +09:00
Riita 19dafaa6ee Update components.md 2021-10-08 17:32:21 +09:00
Riita 4da4d1bb0a Update authentication.md 2021-10-08 17:30:40 +09:00
Riita 650d956be6 Update cluster-administration-overview.md 2021-10-08 17:25:27 +09:00
Riita b293a1529a Update components.md 2021-10-08 17:20:33 +09:00
Riita 4c2413c0bf Update _index.md 2021-10-08 17:09:00 +09:00
Kubernetes Prow Robot 6b1effe886 Merge pull request #29922 from mfilocha/pl-sync-1.22a4
Synchronize Polish localization for ver 1.22, part 4
2021-10-08 00:52:58 -07:00
Kubernetes Prow Robot 7429f9070a Merge pull request #29921 from mfilocha/pl-sync-1.22a3
Synchronize Polish localization for ver 1.22, part 3
2021-10-08 00:50:59 -07:00
seokho-son 704a303a4a Update outdated files in dev-1.22-ko.1 (M52) 2021-10-08 16:36:51 +09:00
seokho-son d253d7e5af Update outdated files in dev-1.22-ko.1 (D1-D2) 2021-10-08 16:14:35 +09:00
Andy Chen 26898c2495 Update zh basic-stateful-set.md with upstream 2021-10-07 23:41:58 -07:00
Kubernetes Prow Robot ffe1d460fe Merge pull request #29851 from ClaudiaJKang/outdated-ko-1-22-p8
[ko] Update outdated files in dev-1.22-ko.1 (p8)
2021-10-07 21:13:51 -07:00
Kubernetes Prow Robot 8a39269530 Merge pull request #29936 from seokho-son/outdate-ko-1.22-secret
[ko] Update outdated Korean configuration/secret
2021-10-07 21:11:50 -07:00
Kubernetes Prow Robot 6811777a0c Merge pull request #29859 from riita10069/feature/29857
Update running-cloud-controller.md
2021-10-07 19:43:50 -07:00
bang9211 a2040433f6 Translate tasks/run-application/run-stateless-application-deployment.md in Korean 2021-10-08 11:24:58 +09:00
Steven Yan 583ead2dd6 [zh] translation for admin3 2021-10-08 09:11:58 +08:00
Chris Negus 2a84b55424 Add file paths to keys and certificates (#28367)
* Adding diagrams to certificates page

* Cropped diagrams

* Changed diagrams to tree output

* Formatting fix

* Fixed text block markup and spacing

* Changed tree view of files to full-path view

* Changed order of two cert files

* Broke up links into separate sentences, per review comment

* More changes per review comments
2021-10-07 17:41:50 -07:00
Kubernetes Prow Robot 88bb1969b3 Merge pull request #29932 from sftim/20211005_update_licence
Update to latest CC-BY 4.x license text
2021-10-07 17:21:51 -07:00
Mike Spreitzer 7122c51152 Improve API Priority and Fairness for clients 2021-10-07 15:58:56 -07:00
Kubernetes Prow Robot 558b1be429 Merge pull request #29963 from Arhell/add-tutor
[uk] Add seccomp tutorial to index
2021-10-07 14:55:34 -07:00
Arhell 0a50d3ed53 [uk] Add seccomp tutorial to index 2021-10-08 00:38:30 +03:00
Kubernetes Prow Robot 750c2e5894 Merge pull request #29834 from ClaudiaJKang/outdated-ko-1-22-p4
[ko] Update outdated files in dev-1.22-ko.1 (p4)
2021-10-07 10:11:46 -07:00
Seokho Son e47542c90c Update outdated Korean architecture/nodes 2021-10-08 02:02:49 +09:00
Seokho Son b1a2be6706 Update outdated Korean configuration/secret 2021-10-08 01:59:47 +09:00
Kubernetes Prow Robot 06d9a1500b Merge pull request #29950 from Arhell/add-tutorial
[ru] Add seccomp tutorial to index
2021-10-07 07:21:46 -07:00
Riita 11103c7c5c Update pod-lifecycle.md 2021-10-07 22:39:36 +09:00
Juhee Kang f0192d5c9e [ko] Update outdated files in dev-1.22-ko.1 (p4) 2021-10-07 22:14:59 +09:00
Juhee Kang da31405d7b [ko] Update outdated files in dev-1.22-ko.1 (p8) 2021-10-07 21:57:17 +09:00
Karthikeya Viswanath f37e6269ad docs: add nlb documentation page reference for aws 2021-10-07 12:37:07 +01:00
Kubernetes Prow Robot 92767c8610 Merge pull request #29955 from PulkitSinghDev/patch-1
fixed broken link in intro-windows-in-kubernetes.md
2021-10-07 02:19:45 -07:00
Kubernetes Prow Robot 708c442e38 Merge pull request #29949 from fabriziopandini/align-ClusterClass-blog-to-CAPI-tutorial
Align the ClusterClass blog to the CAPI book tutorial
2021-10-07 02:17:45 -07:00
Kubernetes Prow Robot 1ef0e9aa7f Merge pull request #27428 from RA489/updatetools
Improvement for other tools
2021-10-07 01:35:45 -07:00
Pulkit Singh cb9e9352a0 Update intro-windows-in-kubernetes.md 2021-10-07 12:44:21 +05:30
RA489 78f125c222 Improvement for other tools 2021-10-07 11:24:04 +05:30
Kubernetes Prow Robot ab52a12ff0 Merge pull request #29843 from jihoon-seo/210928_Update_outdated_files_in_dev-1.22-ko.1_p7
[ko] Update outdated files in dev-1.22-ko.1 (p7)
2021-10-06 22:47:46 -07:00
Arhell f57f004bd0 [ru] Add seccomp tutorial to index 2021-10-07 00:26:31 +03:00
fabriziopandini f268125675 align ClusterClass blog to CAPI book tutorial 2021-10-06 23:13:42 +02:00
Maciej Filocha 98834b6366 Synchronize Polish localization for ver 1.22, part 3
Synchronize Polish localization with upstream
up to 08d92f9137. Part 3.
2021-10-06 21:42:02 +02:00
Kubernetes Prow Robot 1739e65828 Merge pull request #29920 from Shubham82/Correct-link_Dynamic_Admission_Control
Improvement: Correct the "code" link in Dynamic Admission Control.
2021-10-06 07:12:35 -07:00
Kubernetes Prow Robot 35abb6e9f2 Merge pull request #29883 from lxlxok/main
Fix the page links to a section that doesn't exist
2021-10-06 05:58:33 -07:00
Kubernetes Prow Robot 37aa6b13e2 Merge pull request #29938 from cpretzer/cpretzer/fix-blog-link
Update blog post to include the fix version and fix the link to the PR
2021-10-06 05:54:33 -07:00
Kubernetes Prow Robot 129aff0077 Merge pull request #29942 from cpanato/follow-up-patch
releng: update patch release dates for 1.19
2021-10-06 01:28:33 -07:00
Carlos Panato 7994d24f5e releng: update patch release dates for 1.19
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-10-06 09:55:33 +02:00
RA489 42d2ca583d Merge branch 'main' into updatetools 2021-10-06 10:31:11 +05:30
Kubernetes Prow Robot 6aa0912947 Merge pull request #29931 from seokho-son/outdate-ko-1.22-sh01
[ko] Update outdated files in dev-1.22-ko.1 (M1-M18)
2021-10-05 21:56:33 -07:00
Kubernetes Prow Robot 51c27db8d2 Merge pull request #29842 from jihoon-seo/210928_Update_outdated_files_in_dev-1.22-ko.1_p6
[ko] Update outdated files in dev-1.22-ko.1 (p6)
2021-10-05 21:12:33 -07:00
Kubernetes Prow Robot c5df6a47fd Merge pull request #29877 from sftim/20211001_update_third_party_disclaimer
Revise third-party content warning
2021-10-05 21:02:33 -07:00
Jihoon Seo 710fa9288d [ko] Update outdated files in dev-1.22-ko.1 (p6) 2021-10-06 10:08:36 +09:00
Kubernetes Prow Robot fcac6a17ac Merge pull request #29928 from mehabhalodiya/fix25123
Migrate "Contributing new content" overview into section index
2021-10-05 15:41:16 -07:00
Kubernetes Prow Robot 4ec8b5c994 Merge pull request #29939 from puerco/web-dates
releng: Bump website dates one week later
2021-10-05 15:14:57 -07:00
Kubernetes Prow Robot c61e352f88 Merge pull request #29925 from ckotzbauer/patch-1
fix: removed duplicate "called"
2021-10-05 15:08:57 -07:00
Adolfo García Veytia (Puerco) c8300c0560 releng: Bump website dates one week later
This commit moves the October '21 patch release dates one week later as
the original dates for CP and release fell during KubeCon Week.

Follow-up to https://github.com/kubernetes/website/pull/29937

Signed-off-by: Adolfo García Veytia (Puerco) <adolfo.garcia@uservers.net>
2021-10-05 16:55:44 -05:00
Charles Pretzer e5aca814aa Update blog post to include the fix version and fix the link to the PR
Signed-off-by: Charles Pretzer <charles@charlespretzer.com>
2021-10-05 14:33:40 -07:00
Kubernetes Prow Robot 0fe81fdf70 Merge pull request #29937 from puerco/patches-oct
releng: Bump oct patch release one week later
2021-10-05 14:04:57 -07:00
Adolfo García Veytia (Puerco) 104f241aab releng: Bump oct patch release one week later
As the cherry pick deadline for october '21 lands right during kubecon
week, SIG Release decided to move the patch releases one week later.

This PR modifies the dates in the schedule data file.

Signed-off-by: Adolfo García Veytia (Puerco) <adolfo.garcia@uservers.net>
2021-10-05 15:43:34 -05:00
Kubernetes Prow Robot a62f77a869 Merge pull request #29933 from sftim/20211005_fix_approval_for_workflows
Fix approval rules for GitHub workflows
2021-10-05 09:31:18 -07:00
Kubernetes Prow Robot 1904c435c1 Merge pull request #29835 from ClaudiaJKang/outdated-ko-1-22-p5
[ko] Update outdated files in dev-1.22-ko.1 (p5)
2021-10-05 09:19:12 -07:00
Kubernetes Prow Robot 4ec807fe57 Merge pull request #29826 from ClaudiaJKang/outdated-ko-1-22-p3
[ko] Update outdated files in dev-1.22-ko.1 (p3)
2021-10-05 09:15:09 -07:00
Tim Bannister 053fb85c04 Fix approval rules for GitHub workflows
Only SIG Docs leads (chairs + tech leads) should be able to approve
changes to workflows.
2021-10-05 17:14:41 +01:00
Kubernetes Prow Robot 827156f244 Merge pull request #29813 from ClaudiaJKang/outdated-ko-1-22-p2
[ko] Update outdated files in dev-1.22-ko.1 (p2)
2021-10-05 09:13:10 -07:00
Tim Bannister ff517544ea Update to latest CC-BY 4.x license text
Copied from https://creativecommons.org/licenses/by/4.0/legalcode.txt
2021-10-05 17:11:24 +01:00
Kubernetes Prow Robot 177568ab69 Merge pull request #29661 from bang9211/bang9211/downward-api-volume-expose-pod-information/v0.1
[ko]Translate tasks/inject-data-application/downward-api-volume-expose-po
2021-10-05 09:11:10 -07:00
Seokho Son adad63fa59 Update outdated files in dev-1.22-ko.1 (p1) 2021-10-06 00:58:54 +09:00
mehabhalodiya fb2cc8ed6d Delete overview.md 2021-10-05 17:56:08 +05:30
mehabhalodiya 716da39b21 Redirect overview to new content 2021-10-05 17:51:45 +05:30
mehabhalodiya 0d58976695 Migrate Contributing new content overview into section index 2021-10-05 17:43:17 +05:30
Jihoon Seo 5894fa3942 [ko] Update outdated files in dev-1.22-ko.1 (p7) 2021-10-05 16:30:38 +09:00
Christian Kotzbauer 3049f75a01 fix: removed duplicate "called" 2021-10-05 09:00:53 +02:00
bang9211 5c73239f39 Translate tasks/inject-data-application/downward-api-volume-expose-pod-information in Korean 2021-10-05 14:41:36 +09:00
Kubernetes Prow Robot 3b319987f3 Merge pull request #29671 from bang9211/bang9211/distribute-credentials-secure/v0.1
[ko] tasks/inject-data-application/distribute-credentials-secure
2021-10-04 22:13:49 -07:00
Pushkar Joglekar a72f7fac17 Blog post: A closer look at NSA / CISA Kubernetes Hardening Guidance (#29791)
* Blog post: NSA / CISA Hardening

This is a community response blog post that
acts as complementary resource that takes a
closer look at the guidance.

This blog post is not a substitute for reading
the guidance
Apply suggestions from code review

Co-authored-by: Jim Angel <jameswangel@gmail.com>
Co-authored-by: Savitha Raghunathan <saveetha13@gmail.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
Co-authored-by: Shannon Kularathna <ax3shannonkularathna@gmail.com>
Co-authored-by: Robert <hyakuhei@gmail.com>
Co-authored-by: Rey Lejano <rlejano@gmail.com>

* Changes based on NSA/CISA initial
feedback

Co-authored-by: Jim Angel <jameswangel@gmail.com>
Co-authored-by: Savitha Raghunathan <saveetha13@gmail.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
Co-authored-by: Shannon Kularathna <ax3shannonkularathna@gmail.com>
Co-authored-by: Robert <hyakuhei@gmail.com>
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-10-04 20:59:49 -07:00
Arhell aa7a58485e [pt-br] Add seccomp tutorial to index 2021-10-05 00:50:05 +03:00
Mauren Berti e24cf41794 Changes from code review. 2021-10-04 16:49:15 -04:00
Shubham Kuchhal 1262222578 Change master to v1.22.0 2021-10-04 15:52:46 +05:30
Maciej Filocha 0540e157a5 Synchronize Polish localization for ver 1.22, part 4
Synchronize Polish localization with upstream
up to 08d92f9137. Part 4
2021-10-04 12:02:01 +02:00
Kubernetes Prow Robot 03542add29 Merge pull request #29897 from Arhell/add
[pl] Add seccomp tutorial to index
2021-10-04 01:29:08 -07:00
Shubham Kuchhal d4a08df1b9 Improvement: Correct the "code" link in Dynamic Admission Control. 2021-10-04 12:40:03 +05:30
Kubernetes Prow Robot 6a701c485d Merge pull request #29908 from aysabzevar/fix-a-grammar-mistake-Chinese-version
fix a grammar mistake - Chinese version
2021-10-03 18:25:07 -07:00
Kubernetes Prow Robot 2900c15d7f Merge pull request #29907 from aysabzevar/main
fix a grammar mistake - English version
2021-10-03 10:27:06 -07:00
Ali Yousefi Sabzevar 0b814897cb fix a grammar mistake - Chinese version 2021-10-03 19:07:02 +02:00
Ali Yousefi Sabzevar 739a72185f fix a grammar mistake - English version 2021-10-03 18:42:55 +02:00
Tim Bannister 95321d0a77 Fix logic for setting cid-* classes
Only set a cid-* class on the body element if the value won't actually
be "cid-".
2021-10-03 17:22:10 +01:00
Tim Bannister aed3469661 Clean up pre-Docsy content and styles
These files being removed were already deprecated and are
not in fact used. Tidy them up.
2021-10-03 17:17:27 +01:00
Tim Bannister 5f6c6877bb Fix gradient background rendering for announcements
When an announcement uses a gradient background, the inherited
background looks wrong. Instead, make the child element's background
transparent.
2021-10-03 16:33:15 +01:00
Arhell a87f507049 [pl] Add seccomp tutorial to index 2021-10-03 01:18:07 +03:00
Jeffrey Sica aefc9dfe6e add change-cause annotation to labels/annotations page 2021-10-02 15:53:08 -04:00
Kubernetes Prow Robot 9c475f3c2b Merge pull request #29889 from learner0810/fix/typo-command-line-tools-reference/kubelet
fix/typo-command-line-tools-reference/kubelet
2021-10-02 09:29:05 -07:00
Tim Bannister bab43543f0 Set custom color for third-party-content alert 2021-10-02 17:01:11 +01:00
Tim Bannister feb2785238 Highlight third party content disclaimer
When the (new) third party content disclaimer is the current target,
highlight it with a flash of yellow that fades to a yellow background,
rather than the usual gray.
2021-10-02 16:53:59 +01:00
Tim Bannister 8a736308a9 Revise third-party content warning 2021-10-02 16:40:09 +01:00
learner0810 5e9d700ddb fix/typo-command-line-tools-reference/kubelet 2021-10-02 15:30:34 +08:00
Kubernetes Prow Robot 326469394c Merge pull request #29875 from imoisharma/hotfix-replica-link
fix the doc link issue for pod deltion cost.
2021-10-01 18:33:05 -07:00
Min Wang c170ba469f Fix issue #29850 - drop .v1.apps in doc deployment 2021-10-01 18:27:08 -07:00
Kubernetes Prow Robot 7734cd5ce7 Merge pull request #29880 from toli/patch-1
Update job.md to add a newline
2021-10-01 16:49:06 -07:00
xiao.li abadaf1ead Fix the page links to a section that doesn't exist 2021-10-01 14:25:25 -07:00
Arhell b04b2cf2ff [ja] Update location of PrepareNode.ps1 2021-10-02 00:21:32 +03:00
Toli Kuznets 7b07d97a0b Update job.md
add a newline per bug #29840
2021-10-01 12:21:42 -07:00
aychen99 cd7fa760e0 Update basic-stateful-set.md
Fix syntax issue
2021-10-01 13:41:39 -04:00
Mohit Sharma db9d2110f8 fix the korean doc link issue for pod deltion cost.
Signed-off-by: Mohit Sharma <imoisharma@icloud.com>
2021-10-02 01:31:27 +10:00
Kubernetes Prow Robot 450c997fbe Merge pull request #29862 from Arhell/add-tutor
[ja] Add seccomp tutorial to index
2021-10-01 06:27:22 -07:00
Kubernetes Prow Robot a76e3dad6e Merge pull request #29710 from Arhell/runtime
[ja] Improvement: Runtime Class
2021-10-01 06:25:22 -07:00
Kubernetes Prow Robot d1cfb687c7 Merge pull request #26848 from sftim/20210304_tweak_windows_introduction
Tweak windows introduction page
2021-10-01 05:27:22 -07:00
Kubernetes Prow Robot 76f96df041 Merge pull request #29806 from divya-mohan0209/master
Update OWNERS_ALIASES & SECURITY_CONTACTS
2021-10-01 05:11:22 -07:00
Kubernetes Prow Robot 92d8d1e966 Merge pull request #28733 from Kartik494/dockerserver
Add docker server registry
2021-09-30 22:03:21 -07:00
Kubernetes Prow Robot eb8fd2a960 Merge pull request #29752 from khenidak/svc-external-ip
add a note re selectorless services and proxy
2021-09-30 18:33:21 -07:00
Kubernetes Prow Robot dfbb6d988f Merge pull request #29872 from Victorp99/en-dup-proxy-terms
concepts/services-networking/service: removed duplicate proxy term
2021-09-30 18:07:21 -07:00
Victor Paredes 2284c9dcec concepts/services-networking/service: Removed duplicate ProxyTerminatingEndpoints term. 2021-09-30 18:54:05 -04:00
Kubernetes Prow Robot e4e0bf43a8 Merge pull request #29102 from hoskeri/encrypt-data-doc
encrypt-data: Don't recommend AES-CBC
2021-09-30 14:27:15 -07:00
Kubernetes Prow Robot 9be4acc0a4 Merge pull request #29866 from howieyuen/concept-4
[zh] sync content/zh/docs/concepts/cluster-administration/flow-contro…
2021-09-30 10:55:16 -07:00
Kubernetes Prow Robot e6e710ea54 Merge pull request #29821 from superleo/sync-2
Sync 6 files under configure-pod-container/ with 1.22 version
2021-09-30 10:51:15 -07:00
Kubernetes Prow Robot 65a98bf5ce Merge pull request #29799 from jumping/patch-1
Update debug-cluster.md
2021-09-30 10:49:15 -07:00
Tim Bannister 7f88af518e Update compatibility statement for TerminationGracePeriod
Co-authored-by: Mark Rossetti <marosset@microsoft.com>
2021-09-30 18:09:26 +01:00
RA489 b033b85cd9 Improvement for thirdparty tools 2021-09-30 15:35:17 +05:30
Kubernetes Prow Robot dd03f76bab Merge pull request #29860 from fabriziopandini/postpone-clusterclass-blog
Postpone ClusterClass blog
2021-09-30 02:32:08 -07:00
howieyuen c36a610e8e [zh] sync content/zh/docs/concepts/cluster-administration/flow-control.md 2021-09-30 15:43:06 +08:00
Kubernetes Prow Robot 01ebc1fb5a Merge pull request #29742 from chenxuc/admin5
[zh] sync admin cluster docs
2021-09-29 22:48:07 -07:00
Arhell d113a7066f [ja] Add seccomp tutorial to index 2021-09-30 00:20:11 +03:00
fabriziopandini c232ecfbb4 Postpone ClusterClass blog 2021-09-29 21:34:32 +02:00
Kubernetes Prow Robot b50819e5f9 Merge pull request #29349 from jaypipes/controller-dec-api
clarify declarative API in custom controller docs
2021-09-29 09:10:50 -07:00
Riita 32b394f808 Update running-cloud-controller.md 2021-09-30 00:20:06 +09:00
EricWvi 4033f3480b modify kubeadm config example about joining a node to dual-stack cluster 2021-09-29 21:39:10 +08:00
Tim Bannister 640ca8aec8 Tidy Windows node introduction
Partial tidying to bring this page more in line with the Kubernetes
documentation style guide.

Co-authored-by: Shannon Kularathna <ax3shannonkularathna@gmail.com>
2021-09-29 11:23:51 +01:00
Kubernetes Prow Robot 4924944ea2 Merge pull request #29770 from Kartik494/ReadWriteOnceBehvaviour
Added a note for improvement in documentation for ReadWriteOnce and ReadWriteOncePod access mode.
2021-09-29 02:52:49 -07:00
Kubernetes Prow Robot 23d649eeb4 Merge pull request #29816 from howieyuen/task-14
[zh]translate indexed-parallel-processing-static.md
2021-09-29 01:48:49 -07:00
Kubernetes Prow Robot 9a5dc73a16 Merge pull request #29814 from steven-my/29329-translation-for-admin-2
[zh] translation for admin2
2021-09-29 01:34:48 -07:00
Kubernetes Prow Robot d8cf78ae5b Merge pull request #29736 from jihoon-seo/210917_Update_outdated_files_in_dev-1.22-ko.1_p1
[ko] Update outdated files in dev-1.22-ko.1 (p1)
2021-09-28 20:54:48 -07:00
howieyuen ba6cfa2784 [zh]translate indexed-parallel-processing-static.md 2021-09-29 11:49:00 +08:00
Juhee Kang fd83a01141 [ko] Update outdated files in dev-1.22-ko.1 (p5) 2021-09-29 12:05:08 +09:00
Kubernetes Prow Robot 41896a5426 Merge pull request #29831 from gilsonmelo/patch-1
Including Oracle Cloud Infrastructure
2021-09-28 19:08:48 -07:00
Kubernetes Prow Robot de67f09673 Merge pull request #29838 from AvineshTripathi/readmechange
updated README-hi.md
2021-09-28 19:06:48 -07:00
Kubernetes Prow Robot 4321ffd6d7 Merge pull request #29768 from radva/patch-1
Update translate-compose-kubernetes.md
2021-09-28 17:31:31 -07:00
Khaled (Kal) Henidak 2cf2b1937e add a note re selectorless services and proxy 2021-09-28 21:26:54 +00:00
Jay Pipes 6a4dddd251 clarify declarative API in custom controller docs
The content describing a declarative API in the custom controller
section of the custom resources doc was confusing:

> A declarative API allows you to declare or specify the desired state
of your resource **and tries to keep the current state of Kubernetes
objects in sync with the desired state**. The controller interprets the
structured data as a record of the user's desired state, and continually
maintains this state.

(emphasis added)

It is not the declarative API that tries to keep the current state of
the objects in sync with the desired state. It's the controller that
does that.

I've reworded this paragraph to hopefully clarify this.

Closes Issue #29348

Signed-off-by: Jay Pipes <jaypipes@gmail.com>
2021-09-28 16:19:54 -04:00
Kubernetes Prow Robot dd9a56889b Merge pull request #29846 from sftim/20210928_restrict_figure_width_wide_viewport
Restrict width of blog figures for wide viewports
2021-09-28 11:17:16 -07:00
Tim Bannister 968dbbaaad Restrict width of blog figures for wide viewports
Docsy uses Bootstrap to restrict the width of text paragraphs when the
viewport is very wide. Also apply that to <figure> elements within blog
articles.
2021-09-28 18:44:42 +01:00
Kubernetes Prow Robot aec8618576 Merge pull request #29634 from AugustinasS/blog-data-duplication
add blog post on handling data duplication in data-heavy environments
2021-09-28 10:39:17 -07:00
Tim Bannister a7662f40fc Update publication date 2021-09-28 18:31:13 +01:00
Kubernetes Prow Robot fc04dbea45 Merge pull request #29748 from JacobValdemar/patch-1
Remove unessesary indentation on code
2021-09-28 05:34:42 -07:00
kartik494 9fe3e942ff Added note to improve access modes documentation 2021-09-28 17:06:34 +05:30
RinkiyaKeDad 1e967d0b25 adding info about tagging SIGs in pr wrangling guide
Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>
2021-09-28 15:53:10 +05:30
Kubernetes Prow Robot 3cf6f4a031 Merge pull request #29744 from cpanato/update-patches-oct
patches: update releases for October cycle
2021-09-28 03:06:43 -07:00
Kubernetes Prow Robot 68f2c185b6 Merge pull request #29839 from niteshseram/fix/issue29828
remove addonmanager.kubernetes.io labels
2021-09-28 02:44:42 -07:00
Kubernetes Prow Robot 883668ebaa Merge pull request #29823 from howieyuen/concept-1
[zh]sync content/zh/docs/concepts/configuration/secret.md
2021-09-28 01:38:42 -07:00
Paco Xu 39d0870882 Add safe sysctl net.ipv4.ip_unprivileged_port_start
https://github.com/kubernetes/kubernetes/pull/103326
2021-09-28 14:46:25 +08:00
Kubernetes Prow Robot d924a67235 Merge pull request #29833 from aak74/patch-1
typos
2021-09-27 23:12:43 -07:00
Nitesh Seram d3a5a71e88 remove addonmanager.kubernetes.io labels 2021-09-28 10:49:37 +05:30
Avinesh Tripathi ba50c160da updated README-hi.md 2021-09-28 09:59:34 +05:30
Kubernetes Prow Robot 8890ac3668 Merge pull request #29593 from vaibhav2107/record-deployment
Remove the --record flag in https://kubernetes.io/docs/concepts/workloads/controllers/deployment.md
2021-09-27 18:40:43 -07:00
Tim Bannister 5b373f5bb9 Update “What's next” section of Workloads concept pages (#29730)
* Update “What's next” section of Workloads concept pages

Co-authored-by: Jihoon Seo <jihoon.seo@etri.re.kr>

* Add missing trailing / characters

Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>
Co-authored-by: Arsh Sharma <56963264+RinkiyaKeDad@users.noreply.github.com>

Co-authored-by: Jihoon Seo <jihoon.seo@etri.re.kr>
Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>
Co-authored-by: Arsh Sharma <56963264+RinkiyaKeDad@users.noreply.github.com>
2021-09-27 17:16:43 -07:00
Kubernetes Prow Robot 23a158b6a5 Merge pull request #29818 from zhiguo-lu/trans-glossary-garbage-collection
[zh] translate glossary/Garbage Collection
2021-09-27 16:58:43 -07:00
Andrew Kopylov 05af5caf3d typos 2021-09-27 22:06:42 +03:00
Kubernetes Prow Robot 24a3780608 Merge pull request #29808 from Bigsmooth68/patch-1
Update nodes.md
2021-09-27 11:15:45 -07:00
Kubernetes Prow Robot 5102e31079 Merge pull request #29801 from spiffxp/use-k8s-infra-gcb-docker-gcloud
use k8s-staging-test-infra/gcb-docker-gcloud
2021-09-27 09:57:36 -07:00
superleo 225f93c49e Sync 6 files under configure-pod-container/ with 1.22 version 2021-09-28 00:13:54 +08:00
Gilson Melo 740c8762e2 Include Oracle Cloud Infrastructure
Including Oracle Cloud Infrastructure Security page.
2021-09-27 11:08:02 -05:00
Kubernetes Prow Robot 9ffc8c8c56 Merge pull request #29803 from Arhell/add
[it] Add seccomp tutorial to index
2021-09-27 05:27:35 -07:00
Juhee Kang 6cdf4202f0 [ko] Update outdated files in dev-1.22-ko.1 (p3) 2021-09-27 19:55:21 +09:00
zhiguo-lu 6d61d43ab0 [zh] translate glossary/Garbage Collection 2021-09-27 17:09:06 +08:00
Juhee Kang baa9233f77 [ko] Update outdated files in dev-1.22-ko.1 (p2) 2021-09-27 16:02:52 +09:00
chenxuc 649cc1d25a [zh] sync admin cluster docs 2021-09-27 12:51:06 +08:00
howieyuen 6aaf609db6 [zh]sync content/zh/docs/concepts/configuration/secret.md 2021-09-27 11:48:07 +08:00
Steven Yan 864a3808b8 [zh] translation for admin2 2021-09-27 11:27:54 +08:00
Kubernetes Prow Robot 59b6a8be50 Merge pull request #29187 from sanusatyadarshi/patch-1
Added missing ServiceAccount, ClusterRole and ClusterRoleBinding to DNS Horizontal Autoscaler.
2021-09-26 18:52:22 -07:00
Kubernetes Prow Robot 04a6898a42 Merge pull request #29811 from rbrtmrtn/patch-1
Update hello-minikube.md
2021-09-26 18:30:22 -07:00
divya-mohan0209 992d352d51 Adding myself to OWNERS_ALIASES & SECURITY_CONTACTS after rebasing 2021-09-26 12:09:11 +00:00
Kubernetes Prow Robot 3f53f166cf Merge pull request #29796 from mengjiao-liu/update_dockershim_removal
[zh] Update kep link and release version for dockershim removal in faq
2021-09-26 04:10:22 -07:00
Kubernetes Prow Robot 52f0a16621 Merge pull request #29797 from steven-my/29329-translation-for-admin-1
[zh] translation for admin1
2021-09-26 01:04:21 -07:00
Kubernetes Prow Robot e3544b2222 Merge pull request #29767 from zhiguo-lu/trans-concept-traces-for-kubernetes-system-conponments
[zh] translate concepts/Traces For Kubernetes System Components
2021-09-25 20:38:21 -07:00
Steven Yan ea36ff4621 [zh] translation for admin 1 2021-09-26 11:06:16 +08:00
Robert Martin bd59a5fc20 Update hello-minikube.md
Fix minor typos
2021-09-25 20:02:10 -05:00
Bigsmooth68 24f5f7251b Update nodes.md
and => et
2021-09-25 16:19:54 +02:00
Anubhav Vardhan 461a0b4a6d Update OWNERS_ALIASES 2021-09-25 15:29:46 +05:30
Arhell 9bcd6a3579 [it] Add seccomp tutorial to index 2021-09-25 04:41:55 +03:00
Kubernetes Prow Robot ce5ec30e0e Merge pull request #29715 from regentov/patch-1
fix typo that is semantically important
2021-09-24 18:28:21 -07:00
Kubernetes Prow Robot a1669eee41 Merge pull request #29782 from niteshseram/fix/issue29771
remove 'Tools Included' from sidebar of translated page
2021-09-24 17:14:21 -07:00
Kubernetes Prow Robot 3a7a495c6c Merge pull request #29055 from Ritikaa96/update-docs-cluster-networking-concept
updating flannel link address
2021-09-24 16:30:21 -07:00
Kubernetes Prow Robot c1ec23f4c2 Merge pull request #28863 from sgpinkus/patch-1
Update persistent-volumes.md
2021-09-24 16:28:22 -07:00
Richard Tweed 780dae2785 Clarified scenarios that could lead to privilege escalation (#29378)
* Clarified scenarios that could lead to privilege escalation

Made it clearer that it's not just creating pods which enables the privilege escalation. It's all workloads, all reconfiguration of workloads, and conceptually the creation and reconfiguration of custom resources which create workloads.

* Allowing link to priv escalation heading if required

* Update content/en/docs/reference/access-authn-authz/authorization.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Adding further clarifications

* Retitled escalation section

* Apply suggestions from vjftw

Co-authored-by: VJ Patel <VJftw@users.noreply.github.com>

* Clarified CRDs and reduced duplication

* Updating caution based on Geoffrey's comments

* Updating controller comment and linking out to reference docs

Co-authored-by: Tim Bannister <tim@scalefactory.com>
Co-authored-by: VJ Patel <VJftw@users.noreply.github.com>
2021-09-24 16:02:21 -07:00
Kubernetes Prow Robot bb55a9e4fa Merge pull request #29693 from PushkarJ/patch-2
Replace k/security with k/committee-security-response
2021-09-24 15:25:49 -07:00
Pushkar Joglekar 391148fcd5 Update content/en/releases/release-managers.md
Co-authored-by: Bob Killen <killen.bob@gmail.com>
2021-09-24 15:02:56 -07:00
Abhibhaw Asthana 8bc9488622 Adds suggested changes to #29663
Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-09-25 01:50:09 +05:30
Carlos Panato eb65e4d9f5 patches: update releases for October cycle
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-09-24 17:03:21 +02:00
Aaron Crickenberger e2448063df use k8s-staging-test-infra/gcb-docker-gcloud 2021-09-24 06:42:23 -07:00
Kubernetes Prow Robot 8e645478c7 Merge pull request #29774 from mengjiao-liu/kubeadm-upgrade-current-version-zh
[zh] Sync administer-cluster kubeadm-upgrade.md
2021-09-24 03:25:24 -07:00
zhiguo-lu 6ce11bb1f8 [zh] translate concepts/Traces For Kubernetes System Components 2021-09-24 16:54:21 +08:00
Jumping Qu 548dee7af3 Update debug-cluster.md
remove the ":" after "具体情况: " and "缓解措施:"
2021-09-24 16:28:56 +08:00
Kubernetes Prow Robot 80a660635a Merge pull request #29792 from Arhell/add
[id] Add seccomp tutorial to index
2021-09-24 00:57:23 -07:00
Kubernetes Prow Robot abd74a7e63 Merge pull request #29772 from steven-my/29329-translation-for-objects-network
[zh] translation for section objects & network
2021-09-24 00:49:23 -07:00
Kubernetes Prow Robot c0a2f54bc1 Merge pull request #29798 from superleo/sync-1
Update content/zh/docs/tasks/configure-pod-container/configure-gmsa.md
2021-09-23 23:39:23 -07:00
superleo 40d2fdbe65 Update content/zh/docs/tasks/configure-pod-container/configure-gmsa.md 2021-09-24 14:35:25 +08:00
Steven Yan 43b151752d translation for section objects & network 2021-09-24 14:30:04 +08:00
Mengjiao Liu d8245b95be [zh] Update kep link and release version for dockershim removal in faq 2021-09-24 12:34:42 +08:00
Kubernetes Prow Robot 82fbc21e0d Merge pull request #29777 from jimmymccrory/fix-typo
Fix typo in control-plane-flags
2021-09-23 17:13:23 -07:00
Kubernetes Prow Robot 5607c5c345 Merge pull request #29763 from fabriziopandini/clusterclass-blog
ClusterClass and managed topologies blog
2021-09-23 15:22:54 -07:00
Arhell 4ba25b0885 [id] Add seccomp tutorial to index 2021-09-24 00:23:51 +03:00
Marcos Nery fd6447bc7e Merge branch 'kubernetes:main' into translation/ptBrPortsAndProtocols 2021-09-23 16:13:41 -03:00
Kubernetes Prow Robot b1226e203e Merge pull request #29787 from dewan-ahmed/sig-node-spotlight-blog-update
Sig node spotlight blog introduction update before publication date
2021-09-23 10:07:13 -07:00
Kubernetes Prow Robot 3467875f92 Merge pull request #29781 from aldlfkahs/fix-link
[ko] Fix link from 'param githubbranch' to 'master'
2021-09-23 09:43:13 -07:00
Dewan Ahmed 577e0c7ca5 Match folder name with publication date 2021-09-23 11:55:16 -03:00
Dewan Ahmed 0920641570 Update to the introduction 2021-09-23 11:53:58 -03:00
fabriziopandini 02809ef886 address comments 2021-09-23 16:01:08 +02:00
Kubernetes Prow Robot 1646156a0e Merge pull request #29780 from reylejano/issue-29776
Update kep link and release version for dockershim removal in faq
2021-09-23 05:21:22 -07:00
S Nitesh Singh a6ed49bca9 remove 'Tools Included' from sidebar of translated page 2021-09-23 10:59:48 +05:30
aldlfkahs 4a275f1426 [ko] Fix branch of link from 'param githubbranch' to 'master' 2021-09-23 13:31:45 +09:00
Marcos Nery 1ebf0f30b0 translating ports and protocols to pt-br 2021-09-23 01:29:19 -03:00
Jimmy McCrory e9b951239f Fix typo in control-plane-flags
`ClusteConfiguration` should be `ClusterConfiguration`
2021-09-22 19:46:44 -07:00
Kubernetes Prow Robot 36bd261728 Merge pull request #29773 from mengjiao-liu/fix-bound-sa-timeout-zh
[zh] fix expiration of bound SA tokens
2021-09-22 18:47:10 -07:00
Rey Lejano 54bb13c3fb Trigger netlify rebuild 2021-09-22 18:19:17 -07:00
Rey Lejano 66045fc93c update kep link and release version for dockershim removal in faq 2021-09-22 18:14:20 -07:00
Kubernetes Prow Robot 39dcd0c8c8 Merge pull request #29640 from bhumijgupta/Fix/Release-Cadence
Fix release cadence in deprecation policy page
2021-09-22 16:25:11 -07:00
Kubernetes Prow Robot 3814edaeda Merge pull request #29779 from Arhell/tutorial
[es] Add seccomp tutorial to index
2021-09-22 14:58:32 -07:00
Arhell c0fe173a48 [es] Add seccomp tutorial to index 2021-09-23 00:37:49 +03:00
Kubernetes Prow Robot 2cbfbd005c Merge pull request #29380 from dewan-ahmed/dewan-sig-node-spotlight
Blog on SIG Node spotlight 2021
2021-09-22 10:52:32 -07:00
Dewan Ahmed 3291b1141c Update SIG Node Spotlight blog 2021-09-22 13:29:19 -03:00
Dewan Ahmed 5a089356b9 Addressed review comments. 2021-09-22 13:28:03 -03:00
Mengjiao Liu b4d1304c2a [zh] Sync administer-cluster kubeadm-upgrade.md 2021-09-22 18:25:20 +08:00
Kubernetes Prow Robot cfd025c0ac Merge pull request #29682 from AkihiroSuda/minikube-rootless-docker
kubelet-in-userns.md: update for minikube
2021-09-22 02:50:02 -07:00
fabriziopandini 2cd822f120 ClusterClass and managed topologies blog 2021-09-22 11:48:18 +02:00
Mengjiao Liu 93c957e9a6 [zh] fix expiration of bound SA tokens 2021-09-22 17:37:19 +08:00
Kubernetes Prow Robot 0297612be4 Merge pull request #29721 from Arhell/update
[zh] using-api/health-checks.md: use consistent casing
2021-09-21 18:24:01 -07:00
Arhell c1d3db08c9 [zh] using-api/health-checks.md: use consistent casing 2021-09-22 03:43:43 +03:00
Kubernetes Prow Robot 28cc5d4473 Merge pull request #29759 from silenceshell/improve-kubeadm-upgrade-doc
kubeadm upgrade to the latest patch release, not the latest stable
2021-09-21 17:32:00 -07:00
Kubernetes Prow Robot 014f24660a Merge pull request #29762 from s-urbaniak/fix-bound-sa-timeout
fix expiration of bound SA tokens
2021-09-21 17:20:01 -07:00
Kubernetes Prow Robot 101d58d111 Merge pull request #29756 from Arhell/add
[de] Add seccomp tutorial to index
2021-09-21 10:14:24 -07:00
radva 5d0c9eae0e Update translate-compose-kubernetes.md
update to latest release version since version 1.22 doesn't support 3.8
2021-09-21 17:53:57 +02:00
bang9211 bb870812fe Translate tasks/inject-data-application/environment-variable-expose-pod-information in Korean 2021-09-22 00:07:49 +09:00
Mauren Berti bc4b686a97 Changes from code review. 2021-09-21 07:58:41 -04:00
Sergiusz Urbaniak 0ad09c36d6 fix expiration of bound SA tokens
Signed-off-by: Sergiusz Urbaniak <sergiusz.urbaniak@gmail.com>
2021-09-21 08:21:46 +02:00
Jacob Valdemar c724a097bd Add Line Break element after tab widget 2021-09-21 07:09:11 +02:00
silenceshell 064d6676d1 kubeadm upgrade to latest patch release, not latest stable 2021-09-21 10:23:14 +08:00
Kubernetes Prow Robot b56a0db979 Merge pull request #28355 from Kartik494/ingressControllerNamespace
Updating documentation to show ingress pods are deployed in ingress-nginx namespace for minikube v1.19.0 or later
2021-09-20 18:22:23 -07:00
Kubernetes Prow Robot 46f7ce6924 Merge pull request #29743 from HecvStyle/patch-1
修改错误文字
2021-09-20 18:04:23 -07:00
Kubernetes Prow Robot e6b9490fb1 Merge pull request #29694 from ixodie/patch-4
Removed Apstra AOS from Cluster Networking
2021-09-20 17:56:24 -07:00
Kubernetes Prow Robot d4fc621936 Merge pull request #29757 from justaugustus/relmgr
releng: Update Release Managers
2021-09-20 15:06:23 -07:00
Arhell ece10cd2af [de] Add seccomp tutorial to index 2021-09-21 00:32:18 +03:00
Stephen Augustus d9d4daa184 releng: Update Release Managers
- Promote Verónica López to Release Manager
- Dan Mangum to Emeritus (TL + Release Manager)

Signed-off-by: Stephen Augustus <foo@auggie.dev>
2021-09-20 17:30:28 -04:00
Kubernetes Prow Robot e43b176447 Merge pull request #29750 from raelga/clean/remove-3rd-party-content
clean: remove 3rd party links
2021-09-20 13:02:35 -07:00
Rael Garcia 1fbed1d920 fix: reword phrase
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-20 21:45:09 +02:00
august 54185d178d add blog post on handling data duplication in data-heavy environments 2021-09-20 18:29:35 +03:00
Rael Garcia 0abc481f3b clean: remove 3rd party links
Signed-off-by: Rael Garcia <rael@redhat.com>
2021-09-20 10:32:00 +02:00
Marcos Nery 997efe20b0 improving translation 2021-09-19 18:44:22 -03:00
Jacob Valdemar 0e47e6de2b Merge branch 'main' into patch-1 2021-09-19 22:24:31 +02:00
Kubernetes Prow Robot 30c47c9ce1 Merge pull request #29746 from silenceshell/kubeadm-upgrade-current-version-main
kubeadm-upgrade should upgrade to current branch version other than the latest version
2021-09-19 13:18:09 -07:00
Jacob Valdemar 2cac383a7c Undo "Add another newline after the tab widgets" 2021-09-19 22:17:40 +02:00
Jacob Valdemar cc8bda3f41 Add another newline after the tab widgets 2021-09-19 22:07:09 +02:00
Kubernetes Prow Robot e5e0542c33 Merge pull request #29697 from Arhell/improve
[pt-br] Improvement: Runtime Class
2021-09-19 12:30:09 -07:00
Jacob Valdemar 483779104b Undo accidental change to tabs name 2021-09-19 18:01:51 +02:00
Jacob Valdemar 6b610b8e33 Remove prefixed spaces in code environment 2021-09-19 17:55:11 +02:00
silenceshell 160d68bd43 kubeadm-upgrade should upgrade to current branch version other than the latest version 2021-09-19 11:00:41 +08:00
fakedoom a978aa3a3b 修改错误文字
修改错误文字
2021-09-18 10:56:20 +08:00
Mauren Berti cb9c4853ac Translate ConfigMap page to Brazilian Portuguese. 2021-09-17 15:05:05 -04:00
Kubernetes Prow Robot 0a4887ebde Merge pull request #29699 from PushkarJ/netw-ports-protocols
Add a ports and protocols reference page
2021-09-17 08:51:00 -07:00
Kubernetes Prow Robot 508cc6fa82 Merge pull request #29625 from ultradio/ko-29452
[ko] Translate /concepts/storage/storage-capacity.md in Korean
2021-09-16 21:33:01 -07:00
Hanchul Kwon 178bfdb879 [ko] Translate /concepts/storage/storage-capacity.md in Korean
Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>
Co-authored-by: Seokho Son <shsongist@gmail.com>
2021-09-17 11:59:38 +09:00
Jihoon Seo 39301f0e1f [ko] Update outdated files in dev-1.22-ko.1 (p1) 2021-09-17 11:57:57 +09:00
Kubernetes Prow Robot cd0b3b5695 Merge pull request #29177 from anyulled/master
[es] add concepts/storage/volumes
2021-09-16 08:19:46 -07:00
Kubernetes Prow Robot eea088f151 Merge pull request #29315 from danrot/patch-1
Fix a typo in Deployments
2021-09-16 07:31:46 -07:00
Jonas Steinberg c2742b279e "First this user must have [a] certificate issued..."
Added 'a' to the sentence "First this user must have certificate issued..." from the subsection "Normal Users"
2021-09-16 08:20:34 -05:00
Kubernetes Prow Robot 6630873d9d Merge pull request #29344 from victuos/main
Adjust broken link in service.md
2021-09-16 05:47:46 -07:00
Pushkar Joglekar 7655d8d778 Add a ports and protocols reference page
- Refactored ports and protocols info under docs/reference
- Updated the ports for kube-scheduler and kube-controller based on
  current state

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-09-15 13:19:04 -07:00
Kubernetes Prow Robot d924c223cc Merge pull request #29659 from Arhell/fix
[pt-br] Fix secret name to be consistent with examples
2021-09-15 10:52:12 -07:00
Jonas Steinberg f9d5ab0627 add 'the' to 'without restarting [the] API server' from Static Token File section
smol.
2021-09-15 09:29:37 -05:00
Kubernetes Prow Robot 1e66ec193a Merge pull request #29624 from edithturn/add-content/es/docs/concepts/storage/volume-snapshots
[es] Add concepts/storage/volume-snapshots.md
2021-09-15 05:36:42 -07:00
Andrey Regentov 49d7b493bb semantic fix
use "latest" => "Always"
use nothing => "Always"
use any but "latest" => "IfNotPresent"
2021-09-15 15:46:26 +07:00
Kubernetes Prow Robot 59e9b43f1c Merge pull request #26151 from feloy/feloy-api-reference-links
api-reference shortcode + script to test links
2021-09-14 18:22:40 -07:00
Kubernetes Prow Robot fa882c6ac3 Merge pull request #29394 from Patil2099/cascade-fix
Replace cascade=false -> cascade=orphan
2021-09-14 17:46:41 -07:00
Pushkar Joglekar 4b2661e932 Replace k/security with k/committee-security-response
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-09-14 17:04:43 -07:00
Arhell 0506656da1 [ja] Improvement: Runtime Class 2021-09-15 00:17:28 +03:00
Kubernetes Prow Robot faa7ed23c7 Merge pull request #29707 from Shubham82/fix-Exemptions_link
Fixed the link for Exemptions.
2021-09-14 10:29:08 -07:00
Philippe Martin 7d0e235a99 Add shortcode doc 2021-09-14 15:51:58 +02:00
Shubham Kuchhal 2a6272ddf8 Fixed the link for Exemptions. 2021-09-14 18:18:31 +05:30
Kubernetes Prow Robot 828e7629a8 Merge pull request #29691 from ixodie/patch-3
Removed Big Switch Fabric
2021-09-14 01:47:08 -07:00
Akihiro Suda bc0a2487f8 kubelet-in-userns.md: update for minikube
minikube now supports Rootless Docker driver.

minikube internally sets the KubeletInUserNamespace feature gate automatically
for supporting Rootless Docker driver.

https://minikube.sigs.k8s.io/docs/drivers/docker/

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2021-09-14 16:54:05 +09:00
Kubernetes Prow Robot 2e054f9d12 Merge pull request #29700 from tedhexaflow/main
Fix Spelling
2021-09-13 21:35:08 -07:00
Metal c1c2f08662 Fix spelling 2021-09-14 09:05:42 +07:00
Arhell a2f89a2492 [pt-br] Improvement: Runtime Class 2021-09-14 01:03:29 +03:00
ixodie 309065ce9b Removed Contiv.io
Project did not have direct integration with k8s.

URL to project info goes to malicious browser plugin install and ad-based squatter on contiv.io.
2021-09-13 16:42:43 -04:00
ixodie f1751b1e24 Removed Apstra AOS
Apstra AOS (now owned by Juniper) has no direct integration with Kubernetes.

No CNI, no operator, no CRDs, nothing.

Kubernetes is not natively supported in the product, there is no mention of any k8s construct in the product.

This entry should be removed because it does not follow https://github.com/kubernetes/website/issues/20232
2021-09-13 16:34:52 -04:00
ixodie e6f83df546 Removed Big Switch Fabric
None of the links for this entry actually work.
2021-09-13 12:40:56 -04:00
Kubernetes Prow Robot a72e754203 Merge pull request #29681 from Arhell/class
[es] Improvement: Runtime Class
2021-09-13 08:12:09 -07:00
Romain Guichard 56342b7ed6 fix: RWX access mode is about nodes, not pods 2021-09-13 14:50:05 +02:00
Marcos Nery 1f2e4cf9e0 improving readability 2021-09-13 02:55:20 -03:00
Arhell a99b008fc5 [es] Improvement: Runtime Class 2021-09-13 00:29:23 +03:00
Kubernetes Prow Robot 4c5a4f17b6 Merge pull request #29639 from zlatin/fix-duplicate
Fix duplicate words in kubectl overview
2021-09-12 13:24:06 -07:00
Kubernetes Prow Robot 24d412d34a Merge pull request #29672 from Arhell/improve
[id] Improvement: Runtime Class
2021-09-12 10:32:06 -07:00
Victuos a225c841f0 Adjust broken link in service.md 2021-09-12 19:24:09 +02:00
Kubernetes Prow Robot 645cbf57e2 Merge pull request #29666 from anubha-v-ardhan/sig-docs-hi-members
[hi] Update sig-docs-hi owners and reviewers
2021-09-12 03:00:06 -07:00
Kubernetes Prow Robot 8e844434c6 Merge pull request #29486 from astraw99/fix_typo_an_extension
Fix typo `a extension` and its related `en` doc sync
2021-09-11 18:42:06 -07:00
Kubernetes Prow Robot 9dc6afc781 Merge pull request #29662 from mysunshine92/scheduling-hugepage
zh: update scheduling-hugepages.md
2021-09-11 18:04:06 -07:00
Arhell 68549e4d5d [id] Improvement: Runtime Class 2021-09-12 03:33:32 +03:00
Anubhav Vardhan 96c79d2e2f Update OWNERS_ALIASES
Update OWNERS_ALIASES

Update OWNERS_ALIASES
2021-09-11 20:44:15 +05:30
Kubernetes Prow Robot bed864e6e6 Merge pull request #29631 from mshalmanov/main
[ru] Add translate addons.md file in the content/ru/docs/concepts/clu…
2021-09-11 03:04:05 -07:00
Philippe Martin 216b34a3d1 Update script to check api-reference links 2021-09-11 10:59:46 +02:00
Philippe Martin 787e703fa0 Add api-reference shortcode 2021-09-11 10:59:46 +02:00
Kubernetes Prow Robot 558f36cfe6 Merge pull request #28720 from anubha-v-ardhan/patch-2
Replace ha-master-gce.png with SVG
2021-09-10 03:27:59 -07:00
Abhibhaw a886ec620c feat: Documents effects on secrets when memory swap is enabled 2021-09-10 15:41:03 +05:30
Kubernetes Prow Robot b41e88b2ab Merge pull request #29635 from deepsan/serviceCatalog
Fix service-catalog usage of apiserver aggregation
2021-09-10 01:16:00 -07:00
wangyamei 732e88bd7e zh: update scheduling-hugepages.md 2021-09-10 15:52:46 +08:00
Anubhav Vardhan c9568cbaaf Update highly-available-control-plane.md 2021-09-10 09:44:25 +05:30
Kubernetes Prow Robot 6ec9cf7529 Merge pull request #29650 from likakuli/patch-1
Update nodelocaldns.md
2021-09-09 20:16:00 -07:00
deepsan 84c2324c2b Fix service-catalog usage of apiserver aggregation
The Service Catalog architecture changed from using api aggregation to CRDs, but the docs still refer to the older architecture using api aggregation.

Couple of changes here:
1. Change the sentence on how Service Catalog is implemented
2. Replace the example for usage of api aggregation from service-catalog to metrics-server. There are multiple implementations that can be linked to(keda, prometheus, datadog,...), but keeping the documentation neutral by pointing to kubernetes-sigs/metrics-server

References:
- Service Catalog [v0.3.0 release notes](https://github.com/kubernetes-sigs/service-catalog/releases/tag/v0.3.0):

> In release 0.3.0, we've focused on replacing the Aggregated API Server with the CustomResourceDefinitions (CRDs) and the Admission Webhook solution.

- Project [README](https://github.com/kubernetes-sigs/service-catalog/pull/2691/files)
> Service Catalog recently switched to a new CRDs-based architecture. The old API Server-based implementation is available on the v0.2 branch. We support this implementation by providing bug fixes until July 2020.
2021-09-09 17:58:56 -07:00
Arhell 82c3bf13a3 [pt-br] Fix secret name to be consistent with examples 2021-09-10 00:39:28 +03:00
Kubernetes Prow Robot b0f242cd3e Merge pull request #29059 from chrishenzie/read-write-once-pod-access-mode-feature-blog
ReadWriteOncePod access mode alpha feature blog
2021-09-09 11:17:54 -07:00
Kubernetes Prow Robot ed9728ca8c Merge pull request #27262 from npu21/node-fr
Fix line separation in concepts/architecture/nodes
2021-09-09 08:04:11 -07:00
Anubhav Vardhan 2e361073b1 Update highly-available-control-plane.md 2021-09-09 20:20:49 +05:30
Anubhav Vardhan a0e52ff56f Changed ha-control-plane.svg location 2021-09-09 20:17:21 +05:30
Arsh Sharma 69be6060ca explaining the interactions of topology spread constraints and node affinity/selector (#29632)
* explaining the interactions of topology spread constraints and node affinity/selector

Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>

* udpates from code review

Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>

* more updated from code reviews

Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>
2021-09-09 06:48:10 -07:00
likakuli 1e4a57b563 Update nodelocaldns.md
use ",_PILLAR__DNS__SERVER_" as old pattern instead of "_PILLAR__DNS__SERVER_" when use ipvs mode.
In English localization, the pattern is ",_PILLAR__DNS__SERVER_" but when in zh localization, the comma lost.
2021-09-09 19:18:57 +08:00
likakuli 1ba9380f73 Update nodelocaldns.md
use ",__PILLAR__DNS__SERVER__" as old pattern instead of "__PILLAR__DNS__SERVER__" when use ipvs mode
2021-09-09 18:36:21 +08:00
Kubernetes Prow Robot c2f0ae3f05 Merge pull request #29646 from Arhell/env
[ja] kubeadm-install: include env variable for ARCH
2021-09-09 01:40:10 -07:00
Kubernetes Prow Robot 1e578005a8 Merge pull request #29620 from Arhell/upd
[ja] Update the link to cloud interface
2021-09-09 01:38:10 -07:00
Kubernetes Prow Robot 4b18015cd3 Merge pull request #29628 from yechs/patch-1
Fix markdown link rendering & move image kubeadm-stacked-color.png to this repo
2021-09-09 01:00:12 -07:00
Sascha Grunert c86b8a3e43 Add docs about auth differences between Docker and Kubernetes
The interpretation between Docker and Kubernetes varies when comparing
its implementations. This allows different use cases and should be
documented accordingly.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
Co-authored-by: Geoffrey Cline <gcline@amazon.com>
Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2021-09-09 09:20:38 +02:00
Kartik Sharma bd8f97816a Merge branch 'main' into ingressControllerNamespace 2021-09-09 08:40:39 +05:30
Kubernetes Prow Robot 2a1a44894e Merge pull request #29600 from bang9211/bang9211/environment-variable-expose-pod-information/v0.2
[ko] Translate tasks/inject-data-application/environment-variable-expose-p…
2021-09-08 19:34:10 -07:00
Siman 8155f1d16d Update controlling-access.md as --insecure-port flag deprecated (#29447)
* Update English version of controlling-access.md as --insecure-port flag deprecated

* Update controlling-access.md as --insecure-port flag deprecated

* Update content/en/docs/concepts/security/controlling-access.md

Co-authored-by: Qiming Teng <tengqm@outlook.com>

Co-authored-by: Qiming Teng <tengqm@outlook.com>
2021-09-08 19:30:10 -07:00
Shubham 975bd9e9b7 Improvement: Remove Heapster content from HPA. (#29547)
* Improvement: Remove Heapster content from HPA.

* Add more descriptive link for Metrics Server.
2021-09-08 18:20:10 -07:00
Kubernetes Prow Robot 91d24e6505 Merge pull request #29637 from reylejano/update-kubeops-description
Follow-up to k/website pr 29529, fix small nit for .NET
2021-09-08 18:04:10 -07:00
Kubernetes Prow Robot af7f06193f Merge pull request #27182 from sftim/20210323_update_task_create_external_load_balancer
Reword “Create an External Load Balancer” task
2021-09-08 17:54:11 -07:00
jay vyas 034ab83d92 kube-proxy disclaimer about cleanup (#28147)
* kube-proxy disclaimer about cleanup

* Update content/en/docs/concepts/services-networking/service.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/docs/concepts/services-networking/service.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* kube-proxy config note

* Update service.md

kube proxy configuration

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-09-08 17:34:10 -07:00
Arhell 7b43cfc83d [ja] kubeadm-install: include env variable for ARCH 2021-09-09 01:07:41 +03:00
Chris Henzie 809ff37d3b ReadWriteOncePod access mode alpha feature blog 2021-09-08 14:42:43 -07:00
Marcos Nery 7d2a184556 feat: improving readability 2021-09-08 18:26:05 -03:00
Edith 6aa8b805b0 grammar error 2021-09-08 14:18:49 -05:00
MarcosN 61ab2f7232 feat: adding pt-br translation for install kubeadm page 2021-09-08 16:02:10 -03:00
Edith Puclla 1ba143bafa Update content/es/docs/concepts/storage/volume-snapshots.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 13:55:31 -05:00
Edith Puclla 2a020aeaa3 Update content/es/docs/concepts/storage/volume-snapshots.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 13:55:22 -05:00
Edith Puclla 065922912f Update content/es/docs/concepts/storage/volume-snapshots.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 13:54:56 -05:00
Edith Puclla 63a685522a Update content/es/docs/concepts/storage/volume-snapshots.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 13:54:40 -05:00
Edith Puclla 4df48b736d Update content/es/docs/concepts/storage/volume-snapshots.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 13:54:09 -05:00
Edith Puclla 76b2e13255 Update content/es/docs/concepts/storage/volume-snapshots.md
great!

Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 13:52:25 -05:00
Edith Puclla 2c410e31c0 Update content/es/docs/concepts/storage/volume-snapshots.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 11:59:05 -05:00
Edith Puclla f3b24cd30b Update content/es/docs/concepts/storage/volume-snapshots.md
I translated instantáneas it :O, bad bad! :)

Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 11:53:34 -05:00
Edith Puclla c0c54fca4d Update content/es/docs/concepts/storage/volume-snapshots.md
ups, se me fue! gracias!

Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-09-08 11:50:36 -05:00
Ye Shu 826fb8dc90 Change reference to kubeadm-stacked-color.png
Since the image is now moved to this repo, I'm changing all
references to the image to have them point to the local one.
2021-09-08 10:35:23 -04:00
bhumijgupta d3dcda21a5 Revert change to double spacing
Signed-off-by: bhumijgupta <bhumijgupta@gmail.com>
2021-09-08 19:05:01 +05:30
bhumijgupta 2e55433aec Fix release cadence in deprecation policy page
Signed-off-by: bhumijgupta <bhumijgupta@gmail.com>
2021-09-08 19:01:08 +05:30
Maxym Zalata 8555d69bb5 fix duplicate words 2021-09-08 13:51:27 +03:00
Kubernetes Prow Robot afac60ede7 Merge pull request #29630 from Arhell/env
[fr] kubeadm-install: include env variable for ARCH
2021-09-08 00:59:20 -07:00
Kubernetes Prow Robot 93d7fba356 Merge pull request #29636 from Arhell/var
[id] kubeadm-install: include env variable for ARCH
2021-09-07 20:29:20 -07:00
Kubernetes Prow Robot 7cedec6389 Merge pull request #29584 from chenxuc/task-admin
[zh]sync admin task files
2021-09-07 18:55:20 -07:00
Rey Lejano 892118c9cc follow-up to k website pr 29529 2021-09-07 16:58:20 -07:00
Kubernetes Prow Robot 3130e1d221 Merge pull request #29249 from jmyung/jesang/add-reviewer/v0.1
Add jmyung to sig-docs-ko-reviews
2021-09-07 16:20:16 -07:00
Arhell e167bfeac2 [id] kubeadm-install: include env variable for ARCH 2021-09-08 01:23:53 +03:00
Ye Shu a206af45bf Ends img tag and revert changes to links
- Moves the image to this repo
- Adds <img/> to end the tag
- Revert changes made to markdown links
2021-09-07 17:48:00 +00:00
Kubernetes Prow Robot cf9753423a Merge pull request #29554 from chrismetz09/metz-mermaid-upgrade
upgrade to mermaid 8.11.2
2021-09-07 09:45:16 -07:00
Kubernetes Prow Robot 0a413aa6c2 Merge pull request #29616 from BenHall/upgradeMinikubeKatacodaTerminal
Move to Minikube 1.20 image of Katacoda for Hello Minikube Tutorial
2021-09-07 05:43:15 -07:00
Kubernetes Prow Robot a161d54e9f Merge pull request #29209 from deepsan/api-server
Reword Go requirement for subordinate API servers
2021-09-07 05:39:15 -07:00
Marat b7c57a160c [ru] Add translate addons.md file in the content/ru/docs/concepts/cluster-administration 2021-09-07 11:41:59 +06:00
Kubernetes Prow Robot b125d095ea Merge pull request #29621 from tengqm/fix-kubeadm-api-pointer
Fix kubeadm-config links
2021-09-06 18:23:15 -07:00
Arhell b77e02e739 [fr] kubeadm-install: include env variable for ARCH 2021-09-07 01:22:33 +03:00
Kubernetes Prow Robot c484165cb7 Merge pull request #29579 from Arhell/update
[ja] Updating --cascade=false to --cascade=orphan
2021-09-06 08:58:29 -07:00
Kubernetes Prow Robot 35d465e05f Merge pull request #29506 from nakamasato/improve-ja-secret
[ja] Improve Japanese expression in Secret
2021-09-06 08:56:29 -07:00
Ye Shu 8d3d617d55 Fix not rendered markdown link in docs
The markdown links are not rendered properly on [the website](https://kubernetes.io/docs/setup/production-environment/tools/kubeadm/create-cluster-kubeadm/).
I replace them with html anchor tags to fix this weird issue.
2021-09-06 23:00:28 +08:00
Kubernetes Prow Robot a8071cca02 Merge pull request #29626 from mshalmanov/main
[ru] Add translate garbage-collection.md file in the content/ru/docs/…
2021-09-06 04:58:29 -07:00
Kubernetes Prow Robot 62823ba75d Merge pull request #29623 from Arhell/fixes
[zh] Update the link to cloud interface
2021-09-06 04:06:29 -07:00
Marat 6fe1e1661d [ru] Add translate garbage-collection.md file in the content/ru/docs/reference/glossary 2021-09-06 12:47:50 +06:00
Marat 9d5769e483 [ru] Add translate garbage-collection.md file in the content/ru/docs/concepts/architecture 2021-09-06 12:41:43 +06:00
Kubernetes Prow Robot 6468a24ba0 Merge pull request #29613 from giraffesyo/patch-1
Use correct namespace
2021-09-05 18:44:28 -07:00
Edith ebc4f25415 Add concepts/storage/volume-snapshots.md 2021-09-05 18:45:12 -05:00
Arhell af15ac1e4f [zh] Update the link to cloud interface 2021-09-06 00:50:06 +03:00
chenxuc e5d5f82c72 [zh]sync admin task files 2021-09-05 11:27:15 +08:00
Qiming Teng c7ed438072 Fix kubeadm-config links
This PR fixes the links for kubeadm-config APIs.
2021-09-05 09:59:05 +08:00
Arhell 977feb0e98 [ja] Update the link to cloud interface 2021-09-05 00:56:01 +03:00
Kubernetes Prow Robot 9c8e57535e Merge pull request #29619 from jlbutler/122_release_update_webinar
update 1.22 release webinar date in release blog to rescheduled date
2021-09-04 08:27:19 -07:00
Jesse Butler 3a36f1cf3e update 1.22 release webinar date in release blog due to rescheduling 2021-09-04 11:12:37 -04:00
Kubernetes Prow Robot ba5b36d84c Merge pull request #29607 from fregataa/patch-1
[ko] fix a mistranslated sentence which explains pod-lifecycle
2021-09-04 04:37:19 -07:00
Kubernetes Prow Robot 67c7cc9924 Merge pull request #29488 from howieyuen/contribution-2
[zh]sync contribution files for 1.22(Part-2)
2021-09-04 00:49:19 -07:00
Ben Hall 280e67a4e1 Move to Minikube 1.20 image of Katacoda for Hello Minikube Tutorial
Signed-off-by: Ben Hall <ben@benhall.me.uk>
2021-09-04 07:55:17 +01:00
Kubernetes Prow Robot 1393a4abd7 Merge pull request #28688 from npu21/operator-pt
Update URL for Metacontroller
2021-09-03 12:58:53 -07:00
Kubernetes Prow Robot 60eb426408 Merge pull request #29581 from SwapnaneelChowdhury/patch-1
Fixed Portuguese componenets link (#29522)
2021-09-03 12:56:53 -07:00
Michael McQuade 2aca8f917c Use correct namespace
The namespace for this is `ingress-nginx`
2021-09-03 14:24:17 -05:00
Kubernetes Prow Robot 0a1921e28c Merge pull request #29608 from Arhell/upd
[ru] Update the link to cloud interface
2021-09-02 23:03:50 -07:00
Arhell 036227e956 [ru] Update the link to cloud interface 2021-09-03 00:21:27 +03:00
SangHun Lee b0ea0dc2e4 Update pod-lifecycle.md 2021-09-03 01:52:16 +09:00
Kubernetes Prow Robot 8a26a33998 Merge pull request #29529 from buehler/patch-1
docs: Add "KubeOps" operator SDK to third-party list
2021-09-02 09:26:58 -07:00
Kubernetes Prow Robot 2948ff2fa3 Merge pull request #29127 from tengqm/amend-kubeadm-join
Amend kubeadm join doc for node preparation
2021-09-02 06:40:59 -07:00
Kubernetes Prow Robot fec7dce3ad Merge pull request #29555 from GCES-Kubernetes/translation/SytemLogsPtBr
[pt-br] Adding brazilian portuguese translation of System Logs page
2021-09-02 03:44:10 -07:00
Kubernetes Prow Robot 2ecdd4f151 Merge pull request #29490 from howieyuen/contribution-3
[zh]sync contribution files for 1.22(Part-3)
2021-09-02 02:26:10 -07:00
Qiming Teng 87e92d4893 Update content/en/docs/setup/production-environment/tools/kubeadm/create-cluster-kubeadm.md
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-09-02 14:55:24 +08:00
Kubernetes Prow Robot 5a53712c39 Merge pull request #29601 from Arhell/url
[pt-br] Update URL for Metacontroller
2021-09-01 16:16:09 -07:00
Arhell 0a1f8654a7 [pt-br] Update URL for Metacontroller 2021-09-02 00:50:56 +03:00
bang9211 bc8814864c Translate tasks/inject-data-application/environment-variable-expose-pod-information in Korean 2021-09-02 04:45:50 +09:00
Kubernetes Prow Robot ee84275364 Merge pull request #29079 from Ritikaa96/update-cilium-network-policy-task
updating cilium network policy docs
2021-09-01 10:57:41 -07:00
Kubernetes Prow Robot b88fe105c2 Merge pull request #29589 from anuraaga/patch-1
Fix typo in health-checks doc
2021-09-01 10:53:41 -07:00
Kubernetes Prow Robot edc098d8ef Merge pull request #29598 from jlbutler/owners-request
request adding jlbutler to sig-docs-en-owners
2021-09-01 09:15:00 -07:00
Jesse Butler 1b691829dc request adding jlbutler to sig-docs-en-owners 2021-09-01 11:03:22 -04:00
Kubernetes Prow Robot 7486562af6 Merge pull request #29575 from Arhell/upd
[ja] Update default node pod limits for large cluster
2021-09-01 03:10:59 -07:00
Kubernetes Prow Robot 37c9165365 Merge pull request #29563 from mengjiao-liu/sync-1.22-kubeadm-part3
[zh] Setup files to sync for 1.22(kubeadm part-3)
2021-09-01 03:06:59 -07:00
Kubernetes Prow Robot d25b64cbfb Merge pull request #29594 from Arhell/remove
[zh] remove unneeded comma
2021-09-01 03:04:59 -07:00
Vaibhav f6c813de44 Remove the remaining last flag --record from deployment.md 2021-09-01 15:21:31 +05:30
Arhell a4c0b79970 [zh] remove unneeded comma 2021-09-01 00:37:12 +03:00
Vaibhav a0d63d1125 Remove the --record flag in https://kubernetes.io/docs/concepts/workloads/controllers/deployment.md 2021-09-01 01:49:22 +05:30
Kubernetes Prow Robot 02f64ff775 Merge pull request #29586 from kimcore/patch-1
[ko] fix mistranslated part in statefulset.md
2021-08-31 08:39:38 -07:00
Kubernetes Prow Robot 0e5cbec4c4 Merge pull request #29568 from bang9211/bang9211/define-interdependent-environment-variables/v0.1
[ko] Translate tasks/inject-data-application/define-interdependent-environ…
2021-08-30 22:18:28 -07:00
bang9211 47262d1bba Translate tasks/inject-data-application/define-interdependent-environment-variables in Korean 2021-08-31 13:57:08 +09:00
Kubernetes Prow Robot 28ca4eba0b Merge pull request #29546 from mengjiao-liu/sync-1.22-kubeadm-part2
[zh] Setup files to sync for 1.22(kubeadm part-2)
2021-08-30 20:22:28 -07:00
Kubernetes Prow Robot 2b27d92fe8 Merge pull request #29562 from mengjiao-liu/sync-1.22-windows-runtime
[zh] Setup files to sync for 1.22(windows & runtime)
2021-08-30 20:18:28 -07:00
Kubernetes Prow Robot d30c26c3c9 Merge pull request #29551 from zhangguanzhang/zh-feature-gates
[zh] - docs/reference/command-line-tools-reference/feature-gates.md
2021-08-30 20:16:28 -07:00
Kubernetes Prow Robot f44166a7da Merge pull request #29566 from mengjiao-liu/sync-1.22-part5
[zh] Setup files to sync for 1.22(part-5)
2021-08-30 20:14:28 -07:00
Kubernetes Prow Robot 82da8f915d Merge pull request #29451 from steven-my/29329-translation-for-run-app
[zh] translation for the run-app section
2021-08-30 20:12:28 -07:00
Anuraag Agrawal 6c1ecfa016 Fix typo in health-checks doc 2021-08-31 11:53:15 +09:00
Kubernetes Prow Robot 5c316c2c2a Merge pull request #29509 from steven-my/29329-translation-for-kubectl-install
[zh] translation for kubectl install section
2021-08-30 19:34:28 -07:00
Kubernetes Prow Robot b05768dd45 Merge pull request #29574 from niteshseram/fix/ko-links
[ko] fix broken links in install kubectl windows page
2021-08-30 17:56:28 -07:00
Arhell 3d3db5a49c [ja] Updating --cascade=false to --cascade=orphan 2021-08-31 00:15:14 +03:00
kimcore 2fa3b35d84 [ko] fix mistranslated part in statefulset.md 2021-08-30 23:28:01 +09:00
Kubernetes Prow Robot 0cf63c805b Merge pull request #29345 from sftim/20210812_migrate_image_good_practice_images_concept
Migrate good practice for container images into Containers section
2021-08-30 07:20:54 -07:00
Kubernetes Prow Robot 773411fa3c Merge pull request #29030 from sgpinkus/patch-2
Update _index.md
2021-08-30 07:18:54 -07:00
Kubernetes Prow Robot d0959ca3f4 Merge pull request #29526 from tylerauerbeck/fix-dashboard-proxy
Fix proxy url to expose dashboard
2021-08-30 07:16:54 -07:00
Kubernetes Prow Robot e861bd334a Merge pull request #29012 from Kartik494/stableexample
Modify documentation for stable storage
2021-08-30 07:14:54 -07:00
Kubernetes Prow Robot 07725b5490 Merge pull request #29536 from naisuuuu/improve-namespaces-wording
Improve wording of `kube-node-lease` namespace doc
2021-08-30 07:12:54 -07:00
Kubernetes Prow Robot b959e7ba45 Merge pull request #29564 from Roman513/patch-1
Fix errors in russian translation for Cloud Controller Manager page
2021-08-30 07:02:54 -07:00
Marcos Nery 1b6c76745c refact: improving readability 2021-08-30 03:19:28 -03:00
Mengjiao Liu 57deb4fddc [zh] Setup files to sync for 1.22(kubeadm part-2) 2021-08-30 11:41:55 +08:00
Mengjiao Liu 12181a4d7c [zh] Setup files to sync for 1.22(part-5) 2021-08-30 11:12:14 +08:00
Mengjiao Liu b6a1a29963 [zh] Setup files to sync for 1.22(windows & runtime) 2021-08-30 10:56:29 +08:00
Kubernetes Prow Robot cffa9a09cb Merge pull request #29539 from niteshseram/fix/migrate-image
migrate images for 'Alpha in Kubernetes v1.22: API Server Tracing' article
2021-08-29 19:48:53 -07:00
Kubernetes Prow Robot c596818637 Merge pull request #29549 from rf232/patch-1
Remove rf232(myself) from reviewers
2021-08-29 19:30:53 -07:00
Steven Yan 6e61a2b772 translation for kubectl install section 2021-08-30 10:18:34 +08:00
Kubernetes Prow Robot c6b884b0cf Merge pull request #29583 from Arhell/update-basic-set
[id] Updating --cascade=false to --cascade=orphan
2021-08-29 19:00:53 -07:00
Arhell 570dce0dde [id] Updating --cascade=false to --cascade=orphan 2021-08-30 00:39:17 +03:00
SwapnaneelChowdhury d12503c989 Fix a bug #29522
Fixed "What's next" links in portuguese section which was forwarding to the english page
2021-08-29 16:41:25 +05:30
Kubernetes Prow Robot b7a9fe022d Merge pull request #29545 from chenxuc/task-access
[zh]sync access tasks files
2021-08-28 23:36:53 -07:00
zhangguanzhang ba8429cdc6 [zh] - docs/reference/command-line-tools-reference/feature-gates.md
Signed-off-by: zhangguanzhang <zhangguanzhang@qq.com>
2021-08-28 21:07:58 +08:00
Arhell 234fa360ba [ja] Update default node pod limits for large cluster 2021-08-28 12:41:22 +03:00
S Nitesh Singh ab7a302628 [ko] fix broken links in install kubectl windows page 2021-08-28 12:16:38 +05:30
Kubernetes Prow Robot 9f9790dcf0 Merge pull request #29377 from ClaudiaJKang/ko-29194
[ko] Translate /tasks/debug-application-cluster/debug-running-pod.md
2021-08-27 20:34:52 -07:00
Kubernetes Prow Robot 42a93ae773 Merge pull request #29571 from niteshseram/fix/links-windows
fix broken link in install kubectl windows page
2021-08-27 18:04:52 -07:00
Marcos Nery aa8fb8f871 refact: improving text readability 2021-08-27 15:48:36 -03:00
Marcos Nery eee9345bbf Merge branch 'kubernetes:main' into translation/SytemLogsPtBr 2021-08-27 15:29:25 -03:00
S Nitesh Singh 1016cd383d fix broken link in install kubectl windows page 2021-08-27 23:10:48 +05:30
Kubernetes Prow Robot 7f198cd154 Merge pull request #29411 from tengqm/zh-fix-saadmin
[zh] Fix and resync service accounts admin page
2021-08-27 09:10:04 -07:00
Kubernetes Prow Robot 79bb314051 Merge pull request #29277 from tengqm/zh-prod-env
[zh] Translate production environment
2021-08-27 09:08:04 -07:00
Kubernetes Prow Robot f41c9c0831 Merge pull request #29553 from camachomaria/patch-1
Update static-pod.md
2021-08-27 07:16:03 -07:00
Mengjiao Liu a07b8a79ba [zh] Setup files to sync for 1.22(kubeadm part-3) 2021-08-27 16:01:59 +08:00
Kubernetes Prow Robot f76c2a7b63 Merge pull request #29541 from Arhell/update
[zh] Update determine-reason-pod-failure.md
2021-08-26 21:04:59 -07:00
Arhell 41bc06f1a0 [zh] Update determine-reason-pod-failure.md 2021-08-27 03:05:47 +03:00
Roman513 9163103ee2 Fix errors in russian translation 2021-08-26 23:56:04 +03:00
MarcosN 9b8e046000 improving text readability 2021-08-26 16:42:44 -03:00
MarcosN d50a1cd890 adding pt-br translation for System Logs page 2021-08-26 16:02:02 -03:00
chrismetz09 cbff3ec4ea upgrade to mermaid 8.11.2 2021-08-26 10:53:18 -07:00
Maria Camacho f1b99bb92d Update static-pod.md
Added a missing verb and full stop.
2021-08-26 19:30:42 +03:00
Rob Franken b2f9611849 Remove rf232(myself) from reviewers
I have not been involved in kubernetes dashboard development for years
2021-08-26 13:23:51 +02:00
Kubernetes Prow Robot f6fb295afd Merge pull request #29531 from mengjiao-liu/sync-1.22-kubeadm-part1
[zh] Setup files to sync for 1.22(kubeadm part-1)
2021-08-26 02:19:23 -07:00
chenxuc 1809def31c [zh]sync access tasks files 2021-08-26 16:30:21 +08:00
Kubernetes Prow Robot 03f1829e4f Merge pull request #29507 from Arhell/typo
[zh] Gramma fix for change-pv-reclaim-policy.md
2021-08-25 21:17:22 -07:00
Mengjiao Liu 8ab1f6a5d5 [zh] Setup files to sync for 1.22(kubeadm part-1) 2021-08-26 10:02:20 +08:00
naisu 5220cdf8d2 Explain leases in kube-node-lease namespace doc
Add a reference to `Lease` resource api doc

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-08-26 02:22:45 +02:00
Dewan Ishtiaque Ahmed 25a7c8f02e Update content/en/blog/_posts/2021-08-13-SIG-Node-Spotlight/index.md
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-25 17:29:05 -03:00
Dewan Ishtiaque Ahmed 2b09e539ef Update content/en/blog/_posts/2021-08-13-SIG-Node-Spotlight/index.md
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-25 17:28:56 -03:00
Dewan Ishtiaque Ahmed f93e3cb2be Update content/en/blog/_posts/2021-08-13-SIG-Node-Spotlight/index.md
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-25 17:28:41 -03:00
Dewan Ishtiaque Ahmed 3f51160e89 Update content/en/blog/_posts/2021-08-13-SIG-Node-Spotlight/index.md
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-25 17:28:13 -03:00
Kubernetes Prow Robot c83e410333 Merge pull request #29492 from sftim/20210820_fix_cronjob_graduation_release
Fix incorrect info about when CronJob reached GA
2021-08-25 10:52:43 -07:00
S Nitesh Singh 9dc4fcc80c migrate images for 'Alpha in Kubernetes v1.22: API Server Tracing' article 2021-08-25 22:59:39 +05:30
Kubernetes Prow Robot 3516b2e199 Merge pull request #29528 from tylerauerbeck/fix-pod-sec-adm-link
Fix link in pod-security-admission
2021-08-25 09:10:41 -07:00
Jesse Butler 6dd696487a 1.22 feature blog for api server tracing (#28991)
* 1.22 feature blog for API server tracing

* Add initial draft of descriptive tracing portions

* demo

demo

* Apply suggestions from code review

Co-authored-by: Chris Negus <cnegus@redhat.com>

* address comments

* address comments and grammar

* Add more explanation to the Demo section; add conclusion

* Update content/en/blog/_posts/2021-08-06-api-server-tracing.md

Co-authored-by: Punya Biswal <punya@google.com>

* address comments

* address feedback

* update alt text

* Update content/en/blog/_posts/2021-08-06-api-server-tracing.md

Co-authored-by: Rey Lejano <rlejano@gmail.com>

* Rename 2021-08-06-api-server-tracing.md to 2021-09-03-api-server-tracing.md

* update alt text on first image

* better alt text.

Co-authored-by: David Ashpole <dashpole@google.com>
Co-authored-by: Chris Negus <cnegus@redhat.com>
Co-authored-by: Punya Biswal <punya@google.com>
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-25 09:06:41 -07:00
naisu 497a5231df Improve wording of kube-node-lease namespace doc
Correct grammar and provide a reference to more detailed documentation of concepts mentioned.
2021-08-25 17:20:22 +02:00
Kubernetes Prow Robot 0e4cdf227a Merge pull request #29517 from Arhell/update
[zh] Update client-libraries.md
2021-08-25 06:58:41 -07:00
Christoph Bühler c031257f3e fix ordering of list 2021-08-25 11:25:29 +02:00
Christoph Bühler d8199078f5 Add additional information about "kubeops" 2021-08-25 09:53:01 +02:00
Kubernetes Prow Robot 6e892c39bc Merge pull request #29527 from Arhell/upd
[ja] Update determine-reason-pod-failure.md
2021-08-25 00:50:39 -07:00
Kubernetes Prow Robot 8d2f5d95d3 Merge pull request #29032 from able8/fix-typos-ja
[ja] Fix typos
2021-08-25 00:48:40 -07:00
Christoph Bühler 8b013b8e92 docs: Add "KubeOps" operator SDK to third-party list
Adding dotnet operator sdk/framework to third-party list of operator sdks.
2021-08-25 09:33:44 +02:00
Kubernetes Prow Robot 0f394a9eab Merge pull request #29191 from nakamasato/improve-ja-k8s-object-management
[ja] Improve Japanese expression in Kubernetes object management
2021-08-24 23:12:39 -07:00
Tyler Auerbeck 3dc86945ed Fix link in pod-security-admission 2021-08-25 00:57:35 -04:00
Kubernetes Prow Robot fcff108a23 Merge pull request #29226 from tmeralus/patch-1
fixed small typo
2021-08-24 21:10:39 -07:00
Tedley Meralus 964ab4a274 changed uprate to promote
changed word to better clarify actions used in kubernetes cluster
2021-08-24 23:57:00 -04:00
Kubernetes Prow Robot ad5e309805 Merge pull request #29515 from sftim/20210823_tweak_dashboard_task
Revise task page to deploy and access the Kubernetes Dashboard
2021-08-24 20:34:39 -07:00
Kubernetes Prow Robot 0857620280 Merge pull request #29363 from mk46/rss_broken
Removed reference for broken link
2021-08-24 16:19:32 -07:00
Tim Bannister 8563416062 Fix typo
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-24 23:59:23 +01:00
Arhell a1ad8a4d72 [ja] Update determine-reason-pod-failure.md 2021-08-25 00:16:06 +03:00
Tyler Auerbeck 08121d0c59 Fix proxy url to expose dashboard 2021-08-24 16:06:35 -04:00
Jesse Butler 9924e7a8db 1.22 feature blog for minReadySeconds in StatefulSets (#28992)
* 1.22 feature blog for minReadySeconds in StatefulSets

* Address reviewer's comments

* Update content/en/blog/_posts/2021-08-16-minreadysecond-statefulsets.md

Co-authored-by: Simon Pasquier <spasquie@redhat.com>

* Bump article publication date

Co-authored-by: ravisantoshgudimetla <ravisantoshgudimetla@gmail.com>
Co-authored-by: Ravi Gudimetla <ravisantoshgudimetla@users.noreply.github.com>
Co-authored-by: Simon Pasquier <spasquie@redhat.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-08-24 10:53:13 -07:00
Kubernetes Prow Robot 9b17097b45 Merge pull request #28451 from vaibhav2107/learning-env
Update in docs/setup/learning-environment/_index.md
2021-08-24 10:43:15 -07:00
Kubernetes Prow Robot dc262ad58b Merge pull request #27905 from jai/jai/fix-20134
docs(manage-resources-containers): add volume and volumeMount for ephemeral storage
2021-08-24 10:41:14 -07:00
Tim Bannister fd19a0c145 Migrate good practice for container images into Containers section 2021-08-24 10:47:18 +01:00
Kubernetes Prow Robot 607405e106 Merge pull request #29505 from jimangel/zoom-policy
adding zoom info for localization teams
2021-08-24 02:37:13 -07:00
Arhell 1c2dc112f3 [zh] Update client-libraries.md 2021-08-24 12:29:28 +03:00
Kubernetes Prow Robot 157f1d76b8 Merge pull request #28951 from saschagrunert/seccomp-default-blog
Add seccomp default feature blog post
2021-08-24 02:27:13 -07:00
Sascha Grunert 84e472e95c Add seccomp default feature blog post
This adds the blog post about the new Kubernetes `SeccompDefault` alpha
feature.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2021-08-24 08:49:50 +02:00
Kubernetes Prow Robot 6e7b621625 Merge pull request #29310 from jonathino2590/jonathino2590-patch-1
Update Document Deployments
2021-08-23 22:27:13 -07:00
Claudia J. Kang 583e4d50e4 [ko] Translate /tasks/debug-application-cluster/debug-running-pod.md 2021-08-24 12:22:03 +09:00
Masato Naka a4e37c88b9 fix next sentence
Signed-off-by: Masato Naka <masatonaka1989@gmail.com>
2021-08-24 09:08:09 +09:00
Tim Bannister a532758197 Fix incorrect info about when CronJob reached GA 2021-08-23 23:00:00 +01:00
Tim Bannister 289295c46c Update Dashboard task title and description 2021-08-23 22:57:03 +01:00
Tim Bannister 950600c510 Reword Dashboard task 2021-08-23 22:56:48 +01:00
Kubernetes Prow Robot e220769ea3 Merge pull request #29504 from jimangel/hugo-improvements
Hugo improvements
2021-08-23 10:08:01 -07:00
Kubernetes Prow Robot 5f301dcec5 Merge pull request #29468 from Abirdcfly/patch-2
Update rbac.md: Describe in detail how to specify resourceNames when using list verbs
2021-08-23 07:12:01 -07:00
Abirdcfly 19807f866c Update content/en/docs/reference/access-authn-authz/rbac.md
Co-authored-by: Jordan Liggitt <jordan@liggitt.net>
2021-08-23 21:45:10 +08:00
Kubernetes Prow Robot 294f591267 Merge pull request #29513 from niteshseram/fix/psc
Rename product security committee to security response committee
2021-08-23 05:40:00 -07:00
S Nitesh Singh 2cb0f9cd8f rename product security committee to security response committee 2021-08-23 16:54:01 +05:30
Kubernetes Prow Robot 2f70a10bce Merge pull request #29511 from nak3/fix-typo
Fix typo in japanese doc
2021-08-23 03:54:00 -07:00
Kenjiro Nakayama a9362477d3 Fix typo in japanese doc 2021-08-23 18:15:32 +09:00
Kubernetes Prow Robot 750d42470b Merge pull request #29491 from cpanato/update-patches-sept
release/patches: update patch release September cycle
2021-08-23 00:26:00 -07:00
Kubernetes Prow Robot 5590959850 Merge pull request #29501 from chenxuc/task-misc
[zh]sync misc task files
2021-08-22 23:31:59 -07:00
Kubernetes Prow Robot b6af69503a Merge pull request #29475 from howieyuen/contribution-part-1
[zh]sync contribution files for 1.22(Part-1)
2021-08-22 22:27:59 -07:00
Steven Yan 742e7d7ee4 translation for the run-app section 2021-08-23 12:03:00 +08:00
howieyuen 1698263ca3 [zh]sync contribution files for 1.22(Part-3) 2021-08-23 10:40:28 +08:00
howieyuen 55c7993e9b [zh]sync contribution files for 1.22(Part-1) 2021-08-23 10:33:58 +08:00
Arhell cfc0752351 [zh] Gramma fix for change-pv-reclaim-policy.md 2021-08-23 03:09:48 +03:00
Masato Naka f63ff99d23 [ja] Improve Japanese expression in Secret
Signed-off-by: Masato Naka <masatonaka1989@gmail.com>
2021-08-23 08:37:53 +09:00
Jim Angel d5b67cf560 adding zoom info for localization teams 2021-08-22 21:04:45 +00:00
Jim Angel e01f70dab9 updating theme submodule 2021-08-22 20:06:05 +00:00
Jim Angel bd5223c5af performance tuning and hugo version upgrade 2021-08-22 20:05:12 +00:00
Kubernetes Prow Robot 433480d74e Merge pull request #28756 from jihoon-seo/210702_ru_Update_Netlify_link_address
[ru] Update Netlify link address
2021-08-22 10:11:59 -07:00
Kubernetes Prow Robot 2fb1f22a7b Merge pull request #29498 from Devops-Ramdas/patch-1
Update components.md
2021-08-22 09:49:59 -07:00
Kubernetes Prow Robot 5c95d82945 Merge pull request #29302 from tengqm/fix-examples-test
Fix examples test
2021-08-22 08:46:00 -07:00
astraw99 340125aa5b fix typo and its related en doc sync 2021-08-22 17:57:58 +08:00
chenxuc a33bc3b2b1 [zh]sync misc task files
related: #29329
2021-08-22 17:19:42 +08:00
Kubernetes Prow Robot f244bb0e30 Merge pull request #29500 from astraw99/patch-3
Fix typo `a extension` in `en` language
2021-08-22 00:27:59 -07:00
Cheng Wang a130f6b8b9 Fix typo a extension 2021-08-22 12:12:30 +08:00
Kubernetes Prow Robot b28fa33617 Merge pull request #29499 from Arhell/upd
[zh] Update kustomization.md
2021-08-21 18:19:59 -07:00
Arhell a70567a6a4 [zh] Update kustomization.md 2021-08-21 13:51:07 +03:00
Ramdas Potale 988a62b463 Update components.md
I think adding the "for" word in the below sentence makes more sense.

"This document outlines the various components you need to have "for"
a complete and working Kubernetes cluster."
2021-08-21 09:27:03 +05:30
Kubernetes Prow Robot 116839a094 Merge pull request #29316 from sysnet4admin/patch-2
Update web-ui-dashboard.md
2021-08-20 18:25:59 -07:00
Kubernetes Prow Robot 58e8910312 Merge pull request #29495 from stormqueen1990/addons-pt-br
[pt-br] Update Installing Addons page translation to reflect latest documentation version
2021-08-20 16:43:58 -07:00
Mauren Berti 565555a9d7 Update translation to reflect latest docs version.
Signed-off-by: Mauren Berti <mribeirobert@vmware.com>
2021-08-20 14:26:21 -04:00
Kubernetes Prow Robot 15a909818d Merge pull request #29455 from cndoit18/feat/add-cronjob-timezone
[en]: description of the cronjob schedule timezone
2021-08-20 06:31:24 -07:00
Carlos Panato cf027c8105 release/patches: update patch release September cycle
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-08-20 14:29:35 +02:00
Kubernetes Prow Robot 98e115c86c Merge pull request #27852 from edsoncelio/pt_translate_task_secrets
[PT-BR] Add content/pt-br/docs/tasks/configmap-secret/
2021-08-20 05:09:24 -07:00
Mauren Berti e4ae89a725 [PT-BR] Update CronJob documentation page (#28979)
* Update CronJob page translation to Portuguese.

Update CronJob page to reflect the latest English version in the Brazilian
Portuguese translation.

Signed-off-by: Mauren Berti <mribeirobert@vmware.com>

* Incorporate feedback from pull request.

Signed-off-by: Mauren Berti <mribeirobert@vmware.com>
2021-08-20 05:03:24 -07:00
Kubernetes Prow Robot 370b521a87 Merge pull request #29489 from saschagrunert/privileged-unconfined
Mention that privileged containers run unconfined
2021-08-20 02:35:24 -07:00
Kubernetes Prow Robot 753e70c072 Merge pull request #29487 from borgerli/main
Change CPU and Memory to lowercase because resoure name is case-sensitive
2021-08-20 01:23:24 -07:00
Li Bo 34d7331e4e change CPU and Memory to lowercase because resoure name is case-sensitive 2021-08-20 16:13:55 +08:00
Sascha Grunert 61b8cafa84 Mention that privileged containers run unconfined
This is a note which helps users to understand the interaction between
privileged containers and seccomp profiles.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-08-20 10:09:11 +02:00
Kubernetes Prow Robot b1b1395b0a Merge pull request #28695 from geoffcline/kubectl-namespace-patch-1
update desc of namespace defaulting in CLI
2021-08-20 00:59:25 -07:00
howieyuen 742824d491 [zh]sync contribution files for 1.22(Part-2) 2021-08-20 15:32:00 +08:00
cndoit18 4211fa7007 feat(cronjob): description of the cronjob schedule timezone
Signed-off-by: cndoit18 <cndoit18@outlook.com>
2021-08-20 11:49:09 +08:00
Kubernetes Prow Robot cdefcc3a8b Merge pull request #29477 from brakmic/patch-1
trivial: typo
2021-08-19 20:39:24 -07:00
Kubernetes Prow Robot 49654e7d7a Merge pull request #29481 from Arhell/fix
[id] Fixed link to API priority and fairness enhancement proposal
2021-08-19 19:11:25 -07:00
Kubernetes Prow Robot 28bc7a4152 Merge pull request #29482 from reylejano/website-issue-29480
Add note on owner references back to garbage collection page
2021-08-19 18:15:24 -07:00
Rey Lejano 64f91d8e2c add note on owner references in garbage collection page
add note on owner references to owner dependents page
2021-08-19 17:43:09 -07:00
Arhell b3ecce8eb0 [id] Fixed link to API priority and fairness enhancement proposal 2021-08-20 02:27:49 +03:00
Ravi Gudimetla 6c50bc639f Recommend using TTL field in job
Recommend using ttlSecondsAfterFinished in the job spec so that the pod deletion can be guaranteed when jobs get deleted.
2021-08-19 16:59:53 -04:00
Harris Brakmić 2b268b1a76 trivial: typo
A small typo.
2021-08-19 22:07:59 +02:00
Kubernetes Prow Robot dd2f06f64a Merge pull request #29476 from liggitt/podsecurity-audit-annotations
Clarify audit annotation destination
2021-08-19 08:59:24 -07:00
Abirdcfly 162da6561b Update rbac.md: Describe in detail how to specify resourceNames when using list/watch verbs 2021-08-19 23:39:48 +08:00
Jordan Liggitt 315e290107 Avoid word-break on narrow page widths 2021-08-19 10:04:34 -04:00
Jordan Liggitt 8c3eb6e414 Clarify audit annotation destination 2021-08-19 09:59:19 -04:00
Kubernetes Prow Robot d12f42161e Merge pull request #28970 from skrishna-unix/dev-1.22
Volume Populators Redesign Blog
2021-08-19 03:09:24 -07:00
Tim Bannister de7bca791e Fix hyperlink 2021-08-19 11:00:21 +01:00
Kubernetes Prow Robot 4f203c61e4 Merge pull request #29437 from sftim/20210817_fix_tutorial_html_lang_attribute_zh
Fix HTML language attributes (中文)
2021-08-18 19:46:16 -07:00
Kubernetes Prow Robot fcd160900a Merge pull request #29462 from sftim/20210818_fix_date_for_article
Fix date for published blog article
2021-08-18 15:47:45 -07:00
Kubernetes Prow Robot 8cb22b93bc Merge pull request #29464 from JimBugwadia/master
add kyverno and fix OPA/GK link
2021-08-18 12:51:47 -07:00
Jim Bugwadia dad01370f8 add kyverno and fix OPA/GK link
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
2021-08-18 11:07:02 -07:00
Tim Bannister 944733cb20 Fix date for published blog article
This change affects the date shown in the repository and does NOT affect
the URL or content of the published article.
2021-08-18 16:03:44 +01:00
Kunal Kushwaha ee99447c9d 1.22 Feature Blog for Support for Windows privileged containers (#29022)
* 1.22 feature blog for Support for Windows privileged containers

* Rebased with latest blog content

* dates updated

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md.md

Co-authored-by: Chris Negus <cnegus@redhat.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md.md

Co-authored-by: Chris Negus <cnegus@redhat.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md.md

Co-authored-by: Chris Negus <cnegus@redhat.com>

* Update index.md.md

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Rename index.md.md to index.md

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Update content/en/blog/_posts/2021-08-11-support-for-HostProcess-Containers/index.md

Co-authored-by: Brandon Smith <BRASMITH@MICROSOFT.COM>

* Fix broken hyperlink

* Fix broken hyperlink

Co-authored-by: Rey Lejano <rlejano@gmail.com>

* Fix hyperlink

Co-authored-by: Rey Lejano <rlejano@gmail.com>

Co-authored-by: Brandon Smith <brasmith@microsoft.com>
Co-authored-by: Chris Negus <cnegus@redhat.com>
Co-authored-by: Tim Bannister <tim@scalefactory.com>
Co-authored-by: Rey Lejano <rlejano@gmail.com>
2021-08-18 07:32:08 -07:00
Kubernetes Prow Robot 5525c49815 Merge pull request #29446 from Arhell/remove
[es] Delete logging-stackdriver.md
2021-08-18 01:32:08 -07:00
Arhell 50c8238a2d [es] Delete logging-stackdriver.md 2021-08-18 02:36:09 +03:00
Geoffrey Cline 57c0fe1120 update desc of namespace defaulting in CLI 2021-08-17 18:27:10 +00:00
Kubernetes Prow Robot 40f055cacc Merge pull request #29202 from edithturn/add-content/es/docs/concepts/storage/volume-snapshot-classes
[es] Add concepts/storage/volume-snapshot-classes.md
2021-08-17 09:09:13 -07:00
Edith Puclla 1df20dc263 Update content/es/docs/concepts/storage/volume-snapshot-classes.md
Thank you, Rael! :)

Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-17 10:43:06 -05:00
Kubernetes Prow Robot 389fe5ea40 Merge pull request #29443 from ialidzhikov/fix/eol-dates
Fix EoL dates in data/releases/schedule.yaml
2021-08-17 06:43:13 -07:00
ialidzhikov 43bf8f2a10 Fix EoL dates in data/releases/schedule.yaml
Signed-off-by: ialidzhikov <i.alidjikov@gmail.com>
2021-08-17 16:08:05 +03:00
Victuos 457fd23848 Merge branch 'main' into main 2021-08-17 14:19:44 +02:00
Kubernetes Prow Robot a5c98695b7 Merge pull request #29440 from sftim/20210817_fix_tutorial_html_lang_attribute_vi
Fix HTML language attributes (tiếng Việt)
2021-08-17 04:48:02 -07:00
Kubernetes Prow Robot c3b8d319f4 Merge pull request #29441 from sftim/20210817_fix_tutorial_html_lang_attribute_pl
Fix HTML language attributes (polszczyzna)
2021-08-17 04:46:01 -07:00
Tim Bannister 399c7749c7 Fix HTML language attribute 2021-08-17 12:23:43 +01:00
Tim Bannister c1af1ad3f5 Fix HTML language attribute 2021-08-17 12:21:47 +01:00
Kubernetes Prow Robot da656a8c99 Merge pull request #29436 from sftim/20210817_fix_tutorial_html_lang_attribute_es
Fix HTML language attributes (español)
2021-08-17 03:36:01 -07:00
Kubernetes Prow Robot 7e148d5c05 Merge pull request #29435 from sftim/20210817_fix_tutorial_html_lang_attribute_de
Fix HTML language attributes (Deutsch)
2021-08-17 02:58:01 -07:00
Tim Bannister a9e6ea897b Fix HTML language attribute 2021-08-17 09:57:53 +01:00
Tim Bannister f146e0103f Fix HTML language attribute 2021-08-17 09:54:43 +01:00
Tim Bannister 711d4ec1f6 Fix HTML language attribute 2021-08-17 09:52:59 +01:00
Kubernetes Prow Robot ace33e10b3 Merge pull request #29426 from Arhell/delete
[zh] Delete logging-stackdriver.md
2021-08-16 20:22:01 -07:00
Kubernetes Prow Robot 4c047a7495 Merge pull request #29423 from mengjiao-liu/sync-scheduling-1.22
[zh] Concept files to sync for 1.22 - (9) Scheduling
2021-08-16 20:20:01 -07:00
Kubernetes Prow Robot bb3e36d473 Merge pull request #29368 from howieyuen/tutorial
[zh]sync tutorials files for 1.22
2021-08-16 20:16:00 -07:00
howieyuen 9075aa237f [zh]sync tutorials files for 1.22 2021-08-17 10:47:32 +08:00
Mengjiao Liu ec405cce3c [zh] Concept files to sync for 1.22 - (9) Scheduling 2021-08-17 10:42:01 +08:00
Kubernetes Prow Robot 2429254d6b Merge pull request #29110 from mfilocha/pl-update-readme
Update Polish README file
2021-08-16 19:36:01 -07:00
Kubernetes Prow Robot cd052d9381 Merge pull request #29369 from EricWvi/main
[zh] Concept files to sync for 1.22 - (8) Service
2021-08-16 19:22:02 -07:00
Arhell bfb3d16846 [zh] Delete logging-stackdriver.md 2021-08-17 02:30:23 +03:00
Kubernetes Prow Robot 31ef56b98b Merge pull request #29357 from jimangel/updating-docs-co-chairs
updating co-chairs
2021-08-16 16:12:00 -07:00
Kubernetes Prow Robot 5c1d701916 Merge pull request #29176 from NamikoToriyama/ja/fix-notfound-link
[ja] Fix a non-existent link
2021-08-16 14:04:23 -07:00
Ben Swartzlander c0b5d85371 Volume Populators Redesign Blog
For https://github.com/kubernetes/enhancements/issues/1495
2021-08-16 16:59:36 -04:00
Kubernetes Prow Robot 50e16b7175 Merge pull request #29364 from mfilocha/pl-synchronize-1.22a2
Synchronize Polish localization for ver 1.22, part 2
2021-08-16 13:46:23 -07:00
Kubernetes Prow Robot 6e0bd0033f Merge pull request #29339 from mfilocha/pl-synchronize-1.22a
Synchronize Polish localization for ver 1.22, part 1
2021-08-16 13:44:23 -07:00
Kubernetes Prow Robot e081551e5d Merge pull request #29337 from mfilocha/pl-update-main-index-page
Update Polish localization of the home page
2021-08-16 13:42:22 -07:00
Jonathan Lopez Torres 7bb5df553c Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-16 08:53:21 -05:00
Jonathan Lopez Torres aa30cf0ef8 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-16 08:53:09 -05:00
Jonathan Lopez Torres 55d477f61c Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-16 08:52:57 -05:00
Jonathan Lopez Torres 43d0461908 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Rael Garcia <rael@rael.io>
2021-08-16 08:52:41 -05:00
Kubernetes Prow Robot 320259d57f Merge pull request #29418 from Arhell/fix
[zh] Fix list all uniq container images
2021-08-16 06:05:18 -07:00
Kubernetes Prow Robot 87235b508d Merge pull request #29311 from mengjiao-liu/update-githubbranch-param
Hard-code the name of the target repo's default branch instead of using the githubbranch parameter value
2021-08-16 06:03:18 -07:00
Kubernetes Prow Robot 394f382608 Merge pull request #27987 from olivierk7/patch-2
French translation of workloads page
2021-08-16 01:39:47 -07:00
Rémy Léone 28cb1efbed Apply suggestions from code review 2021-08-16 10:24:22 +02:00
Kubernetes Prow Robot 86aa6c434d Merge pull request #29320 from Arhell/del
[fr] Deleted reference to removed file
2021-08-16 01:09:47 -07:00
EricWvi cd9dc4e482 apply suggestion 2021-08-16 15:13:31 +08:00
Kubernetes Prow Robot b89e5c3042 Merge pull request #29419 from Iceber/update-custom-resource-definition-versioning
[zh] update custom-resource-definition-versioning.md
2021-08-15 23:47:47 -07:00
Iceber Gu ed1ce53ab5 [zh] update custom-resource-definition-versioning.md 2021-08-16 12:28:22 +08:00
Arhell f086aba3d8 [zh] Fix list all uniq container images 2021-08-16 00:19:43 +03:00
Kubernetes Prow Robot b354468ed0 Merge pull request #29409 from tengqm/fix-featuregates
Fix some errors in the feature-gates page
2021-08-15 10:59:46 -07:00
Qiming Teng 3cebde5777 Fix and resync service accounts admin page 2021-08-15 19:57:02 +08:00
Kubernetes Prow Robot ff44f2996b Merge pull request #28978 from wesleyw72/cpu-management-burstable-cfs
Clarify that burstable pods also have their limit enforced by CFS quota
2021-08-15 03:39:46 -07:00
Qiming Teng da53892746 Fix some errors in the feature-gates page 2021-08-15 18:26:20 +08:00
Kubernetes Prow Robot d6dbd52b08 Merge pull request #29406 from Patil2099/ko-fix
[ko] Translation in manage-resources-containers improved
2021-08-15 02:53:46 -07:00
Pankaj Patil 05ff7d6597 [ko] Translation in manage-resources-containers improved 2021-08-15 15:04:58 +05:30
Kubernetes Prow Robot cc493080cd Merge pull request #29288 from dimabru/patch-1
docs: Update custom-resource-definition-versioning.md
2021-08-14 23:43:46 -07:00
Kubernetes Prow Robot e743e1da5d Merge pull request #29402 from Arhell/fix
[fr] Fix list all uniq container images
2021-08-14 23:21:46 -07:00
Kubernetes Prow Robot 7ffc6b7598 Merge pull request #29404 from ysharma-dev/patch-1
Update label in NetworkPolicy example explanation
2021-08-14 23:11:46 -07:00
Yug 6c2ff6340e Update label in NetworkPolicy example description
This change intends to fix the label name in the range of ports NetworkPolicy example.
2021-08-14 22:28:25 -07:00
Kubernetes Prow Robot 1866c7e45a Merge pull request #29395 from Patil2099/link-fix
[ko]Fix: Wrong href to heading anchor
2021-08-14 21:45:46 -07:00
Arhell d2151f2dea [fr] Fix list all uniq container images 2021-08-15 02:31:25 +03:00
Pankaj Patil ca1e53b826 [ko]Fix: Wrong href to heading anchor 2021-08-14 20:29:55 +05:30
Pankaj Patil b4ef0b940e Replace cascade=false -> cascade=orphan 2021-08-14 20:27:40 +05:30
Kubernetes Prow Robot 677c6edc1b Merge pull request #29373 from anubha-v-ardhan/Hi-content-hi-docs-landing
[hi] Add content/hi/docs/_index.md
2021-08-14 04:47:45 -07:00
Kubernetes Prow Robot 92de2a70a0 Merge pull request #29224 from sftim/20210804_update_node_concept
Update the node concept
2021-08-13 14:27:31 -07:00
Dewan Ahmed 5b34d70e92 Post-PR grammatical fixes 2021-08-13 14:24:53 -03:00
Dewan Ahmed df8f30b120 Fixing minor typos. 2021-08-13 12:26:24 -03:00
Dewan Ahmed ad05f090e7 Removing interviewer initials 2021-08-13 11:50:13 -03:00
Dewan Ahmed 3571016b3c v0.1 for sig node spotlight 2021-08-13 11:47:50 -03:00
EricWvi d1a502072e [zh] Concept files to sync for 1.22 - (8) Service 2021-08-13 18:12:06 +08:00
Anubhav Vardhan 5962a5e939 Create _index.md 2021-08-13 13:39:43 +05:30
Maciej Filocha 9314e3be28 Synchronize Polish localization for ver 1.22, part 2
Synchronize Polish localization with upstream
up to 08d92f9137. Part 2
2021-08-13 09:36:31 +02:00
Manish Kumar d55d770365 Removed reference for broken link 2021-08-13 12:54:47 +05:30
Jim Angel d5de9efdb6 updating co-chairs 2021-08-13 06:39:39 +00:00
Kubernetes Prow Robot f095b4bdb4 Merge pull request #29248 from sdghchj/patch-1
Correct wrongly written characters
2021-08-12 20:10:21 -07:00
Kubernetes Prow Robot f2de2a50a5 Merge pull request #29297 from mengjiao-liu/update_apiservice_link_to_api_reference
[zh] Link to new API reference page for APIService
2021-08-12 20:08:21 -07:00
Kubernetes Prow Robot 99b8818db9 Merge pull request #29336 from arugal/patch-1
Modify kubelet-integration page typo
2021-08-12 20:04:22 -07:00
Kubernetes Prow Robot e917746c36 Merge pull request #29261 from ClaudiaJKang/ko-29259
[ko] Enhance docs/tasks/tools/install-kubectl-windows.md
2021-08-12 17:52:58 -07:00
Kubernetes Prow Robot 2805a8762f Merge pull request #29352 from Arhell/list
[id] Fix list all uniq container images
2021-08-12 17:24:58 -07:00
Arhell 74d7ad3118 [id] Fix list all uniq container images 2021-08-13 02:13:25 +03:00
Wesley Williams 41aa2ba727 Revert chinese changes 2021-08-12 22:48:50 +01:00
Kubernetes Prow Robot a33eb6b4c3 Merge pull request #28919 from niteshseram/fix/redirect
Fixing redirection rules with wildcard(*)
2021-08-12 10:05:48 -07:00
Victuos d7f3eeb214 Adjust broken link in service.md
Adjust broken link in service.md
2021-08-12 17:30:43 +02:00
Victuos cfccbdfb1f Adjust broken link in service.md 2021-08-12 17:28:53 +02:00
Kubernetes Prow Robot 96069e6a32 Merge pull request #28607 from kahirokunn/patch-1
fix: k8s dashboard link.
2021-08-12 08:23:48 -07:00
Kubernetes Prow Robot c7c8027225 Merge pull request #29323 from dgrisonnet/new-events-api
Update recommended events API
2021-08-12 06:29:47 -07:00
Kubernetes Prow Robot d621a66ca5 Merge pull request #29006 from niteshseram/fix/sidebar
fixing the huge whitespace in sidebar
2021-08-12 06:27:47 -07:00
Mengjiao Liu 29ff83785e [zh] Link to new API reference page for APIService 2021-08-12 17:44:18 +08:00
Maciej Filocha 49d64fc388 Synchronize Polish localization for ver 1.22, part 1
Synchronize Polish localization with upstream
up to 08d92f9137. Part 1
2021-08-12 09:51:46 +02:00
Maciej Filocha c07cd04894 Update Polish localization of the home page
Update Polish localization of the main index page
up to 08d92f9137.
2021-08-12 09:09:00 +02:00
zhang-wei 7b0ca655ce fix typo 2021-08-12 14:51:19 +08:00
Daniel Rotter a7639240ea Fix a typo in Deplyoments 2021-08-12 08:17:58 +02:00
Kubernetes Prow Robot 08d92f9137 Merge pull request #29171 from ehashman/update-node-perf
Note deprecation of the node performance dashboard
2021-08-11 22:57:47 -07:00
Kubernetes Prow Robot 9383dd8cd0 Merge pull request #28958 from rajula96reddy/memory-manager
Add memory manager moves to beta feature blog post 1.22
2021-08-11 06:16:47 -07:00
Rajula Vineet Reddy a783b05eb2 Add memory manager feature blog post
Co-authored-by: Artyom Lukianov <alukiano@redhat.com>
Co-authored-by: Cezary Zukowski <c.zukowski@samsung.com>
2021-08-11 16:01:22 +03:00
Kubernetes Prow Robot 7c2e229f60 Merge pull request #29236 from reylejano/add-kubewarden-option
Add kubewarden as an alternative to enforce security profiles
2021-08-11 05:26:47 -07:00
Qiming Teng 735701e1cc Amend kubeadm join doc for node preparation
We need to clarify that worker nodes need to be prepared in nearly the
same way as control plane nodes.
2021-08-11 20:10:11 +08:00
Damien Grisonnet 923b2e25f2 kubernetes-api: update recommended events API
In Kubernetes v1.19, the new Events API events.k8s.io was promoted to
v1. As such it now supersedes the original core Events API.

Signed-off-by: Damien Grisonnet <dgrisonn@redhat.com>
2021-08-11 13:02:59 +02:00
Damien Grisonnet 8773d024e7 api-ref-generator: update to include Event changes
Update api-ref-generator submodule to 55bce68 to include changes
updating the recommended Events API from core to events.k8s.io in the
kubernetes-api doc.

Signed-off-by: Damien Grisonnet <dgrisonn@redhat.com>
2021-08-11 13:02:59 +02:00
Tim Bannister 1b8eeb500a Update the node concept
Modernise the page by:
- rewording to follow the style guide
- adding some glossary tooltips
- linking to new-style API reference
- linking to Safely Drain a Node

plus general tweaks.
2021-08-11 11:58:18 +01:00
Kubernetes Prow Robot dd14c2208c Merge pull request #29247 from sanmai/patch-1
Update Managing Resources to mention the measure of CPU time
2021-08-11 03:34:46 -07:00
Alexey Kopytko 9ca04a1014 Update Managing Resources to mention the measure of CPU time 2021-08-11 18:30:33 +09:00
Kubernetes Prow Robot de92339f81 Merge pull request #29229 from sftim/20210804_update_api_aggregation_layer
Retitle “Kubernetes API Aggregation Layer” concept
2021-08-10 18:46:46 -07:00
Kubernetes Prow Robot a78da7908b Merge pull request #29301 from tengqm/fix-go-mod-122
Update go.mod for 1.22
2021-08-10 18:10:46 -07:00
Kubernetes Prow Robot 4097fca5e7 Merge pull request #29205 from sftim/20210803_improve_katacoda_button
Improve Katacoda button
2021-08-10 18:08:46 -07:00
Edith b6dc198148 grammar error second update 2021-08-10 17:16:52 -05:00
Arhell c1785d2dd9 [fr] Deleted reference to removed file 2021-08-11 00:42:28 +03:00
Edith 5c760918bb Merge branch 'main' of https://github.com/kubernetes/website into add-content/es/docs/concepts/storage/volume-snapshot-classes 2021-08-10 14:52:21 -05:00
Edith 90c1306da5 fixing grammar errors 2021-08-10 14:37:22 -05:00
Edith Puclla 382766070a Update content/es/docs/concepts/storage/volume-snapshot-classes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-10 12:36:28 -05:00
Rey Lejano 08387d8434 add kubewarden as an alternative to enforce security profiles
add third-party content shortcode and list
2021-08-10 07:41:30 -07:00
Kubernetes Prow Robot 5703199613 Merge pull request #29282 from kendfinger/patch-1
Fix double usage of "simplify the process" in kubelet-tls-bootstrapping.
2021-08-10 06:05:18 -07:00
Kubernetes Prow Robot 7331e54c09 Merge pull request #28623 from chenxuc/staticPod
static pod not support configmap or secret
2021-08-10 03:23:17 -07:00
Mengjiao Liu f945335af6 Hard-code the name of the target repo's default branch instead of using the githubbranch parameter value 2021-08-10 18:03:21 +08:00
Hoon Jo 11c7b70b41 Update web-ui-dashboard.md
I rquest to update dashboard/v2.3.1 from v2.2.0

Refer to below 
https://github.com/kubernetes/dashboard
2021-08-10 18:51:23 +09:00
Kubernetes Prow Robot 5f65b4fcd0 Merge pull request #28853 from saschagrunert/seccomp-index
Add seccomp tutorial to index
2021-08-10 02:27:17 -07:00
Kubernetes Prow Robot 20890d53b7 Merge pull request #29304 from hokadiri/patch-1
Update safely-drain-node.md
2021-08-10 02:11:18 -07:00
Kubernetes Prow Robot da11af4bbe Merge pull request #29271 from yuswift/update-ssa
update server-side-apply state to stable
2021-08-10 02:09:17 -07:00
yuswift 00c205bc38 update ssa state to stable
Signed-off-by: yuswift <yuswift2018@gmail.com>
2021-08-10 15:47:50 +08:00
Kubernetes Prow Robot 2fbd6ceded Merge pull request #28879 from Shubham82/correct-FQDN_for_dockerhub
Correct FQDN for DockerHub.
2021-08-10 00:35:20 -07:00
Kubernetes Prow Robot e68dc3c075 Merge pull request #28736 from chenxuc/hello-minikube-2
improve hello-minikube page for dashboard
2021-08-10 00:23:19 -07:00
Kubernetes Prow Robot 67eca4178c Merge pull request #28461 from sftim/20210617_improve_make_generate_ref_docs
Improve docs about contributing upstream for generated content
2021-08-10 00:15:19 -07:00
Kubernetes Prow Robot a80328f582 Merge pull request #29295 from mfilocha/fix/rbac-links
Fix links in RBAC default bindings table
2021-08-09 20:37:17 -07:00
Jonathan Lopez Torres c7ee95a654 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:40:55 -05:00
Jonathan Lopez Torres 7a42e5f4b9 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:38:34 -05:00
Jonathan Lopez Torres 76a7e06889 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:38:27 -05:00
Jonathan Lopez Torres 2b00cbf773 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:38:18 -05:00
Jonathan Lopez Torres a6170c1738 Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:38:08 -05:00
Jonathan Lopez Torres dd9c4dc83d Update content/es/docs/concepts/workloads/controllers/deployment.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-09 21:37:43 -05:00
Jonathan Lopez Torres 65827fd94e Update deployment.md 2021-08-09 20:47:45 -05:00
Jonathan Lopez Torres 317c56cf00 Modificación de salida de deployment 2021-08-09 20:45:51 -05:00
Kubernetes Prow Robot 2bc25c1496 Merge pull request #29275 from tengqm/zh-move-pod-priority-preemption
Drop leftover pod-priority-preemption page
2021-08-09 18:45:17 -07:00
Kubernetes Prow Robot 409a5ef110 Merge pull request #29105 from mauriciopoppe/feature-blogpost-csi-windows-support
[Feature blogpost][1.22] CSI Windows Support with CSI Proxy reaches GA
2021-08-09 11:05:10 -07:00
Mauricio Poppe 57e7b781f2 Update blogpost release date to 2021-08-09 2021-08-09 17:28:34 +00:00
Kubernetes Prow Robot 3e4fc78b51 Merge pull request #29060 from ehashman/swap-blog
1.22 feature blog for alpha swap support
2021-08-09 10:21:32 -07:00
Kubernetes Prow Robot 9c7c238efe Merge pull request #29270 from davidmlentz/patch-2
Fix typo
2021-08-09 09:55:31 -07:00
Kubernetes Prow Robot a78a812311 Merge pull request #29299 from Shubham82/fix_broken_link-webhook.go
Fix the broken link for "webhook.go"
2021-08-09 09:53:32 -07:00
Tim Bannister 39e39c0d02 Move node swap post-release article sooner 2021-08-09 17:48:51 +01:00
Hussein Kadiri e6082aca98 Update safely-drain-node.md 2021-08-09 09:37:05 -07:00
Qiming Teng 1846afe3d5 Fix test case for examples
This is an adaptation for 1.22.
2021-08-09 22:29:17 +08:00
Qiming Teng f805b98659 Update go.mod for 1.22 2021-08-09 22:15:28 +08:00
Kubernetes Prow Robot 302743eb9d Merge pull request #28363 from RA489/update_init
Update activeDeadlineSeconds with Pod page
2021-08-09 07:01:31 -07:00
Kubernetes Prow Robot 34ab657265 Merge pull request #29296 from mengjiao-liu/fix-Selector-yaml
[zh] Fix `selector` expect map not string
2021-08-09 06:57:31 -07:00
Kubernetes Prow Robot 58d9f81010 Merge pull request #29268 from cpanato/update-patch
Update patch schedule and add 1.22 to the party
2021-08-09 06:55:31 -07:00
Claudia J. Kang 9bd532fc67 [ko] Enhance docs/tasks/tools/install-kubectl-windows.md 2021-08-09 22:52:32 +09:00
Shubham Kuchhal bdb4cc4603 Fix the broken link for "webhook.go" 2021-08-09 16:17:06 +05:30
Mengjiao Liu bbc82ea1f2 [zh] Fix selector expect map not string and sync horizontal-pod-autoscale-walkthrough.md file 2021-08-09 18:12:14 +08:00
Maciej Filocha 647e9d6ca8 Fix links in RBAC default bindings table
An extra line needs to be added to allow
the link to be rendered properly.
Also reformatting link line to be better readable.
2021-08-09 12:09:29 +02:00
Carlos Panato fafe6d1e9f patch releases: add 1.22 release to the schedule
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-08-09 11:22:30 +02:00
Kubernetes Prow Robot 91d71e812b Merge pull request #29285 from tengqm/kubectl-122
Update kubectl reference for 1.22
2021-08-09 01:41:30 -07:00
Kubernetes Prow Robot 459d007b9a Merge pull request #29276 from Arhell/delete
[ru] Deleted reference to removed file
2021-08-08 23:45:30 -07:00
Kubernetes Prow Robot 45f539517c Merge pull request #29203 from kerthcet/patch-1
fix punctuation mistyped
2021-08-08 20:47:30 -07:00
Kubernetes Prow Robot aa86cfbe42 Merge pull request #29284 from tengqm/update-kubelet-ref
Update reference for kubelet
2021-08-08 20:07:30 -07:00
Kubernetes Prow Robot 90f2d903fb Merge pull request #29250 from jalagari/main
Selector expect map not string
2021-08-08 13:37:30 -07:00
Dima Brusilovsky 91f4f4adf7 Update custom-resource-definition-versioning.md 2021-08-08 18:47:19 +03:00
kerthcet 8ed0b0fd6d keep the document in sync with deprecation of Dynamic Kubelet Configuration in releasev1.22
Signed-off-by: kerthcet <kerthcet@gmail.com>
2021-08-08 21:26:36 +08:00
Sayantani Saha ee245ff73e Added announcements of KubeCon NA & China (#29192)
* Added announcements of KubeCon NA & China

* svg images added & required changes made

* Requested changes made

* svg images fixed

* small correction required

* added the to the message

* small correction

* Netlify build error fixed
2021-08-08 06:01:30 -07:00
Qiming Teng a6a5d359e5 Update kubectl reference for 1.22 2021-08-08 20:49:16 +08:00
Qiming Teng f45f67739e Update reference for kubelet
The kubelet reference is not auto-generated. This PR is about fixing the
outdated information by manually comparing the reference against the
output from `kubelet --help`.
2021-08-08 19:59:56 +08:00
Kenneth Endfinger f805b220d8 Fix double usage of "simplify the process" in kubelet-tls-bootstrapping. 2021-08-08 01:56:17 -07:00
Arhell 3cafc8c8a5 [ru] Deleted reference to removed file 2021-08-08 11:38:24 +03:00
Kubernetes Prow Robot 9e8003a66e Merge pull request #29184 from Arhell/fixes
[ja] Fix typo in worker.py example script
2021-08-07 08:39:29 -07:00
Kubernetes Prow Robot 7321fd9496 Merge pull request #29091 from mengjiao-liu/fix-secret-name-ja
[ja] Fix secret name to be consistent with examples
2021-08-07 08:37:29 -07:00
Kubernetes Prow Robot 82e7858daa Merge pull request #29174 from Arhell/link
[ja] update link to Flannel
2021-08-07 08:35:30 -07:00
Kubernetes Prow Robot 47124c83b1 Merge pull request #29023 from Arhell/operator
[ja] Operator: Exists missing
2021-08-07 08:33:29 -07:00
Qiming Teng d711ae1874 [zh] Translate production environment 2021-08-07 19:23:48 +08:00
Qiming Teng bbb3ba317a Drop left over pod-priority-preemption page
When attempting to keep the localized sites well synced to the English
upstream, some files were found MOVED. It is difficult to detect such
changes. This PR removes a file that were localized twice.
2021-08-07 10:31:55 +08:00
Elana Hashman cb0d216f72 Add alpha swap support blog 2021-08-06 12:07:05 -07:00
Mauricio Poppe 9f30588101 Non-critical updates from feedback 2021-08-06 17:14:04 +00:00
yuswift 4e06971871 update ssa state to ga
Signed-off-by: yuswift <yuswift2018@gmail.com>
2021-08-06 22:17:24 +08:00
Kubernetes Prow Robot b5c1e98957 Merge pull request #29241 from YuikoTakada/fix_relative_paths
Replace with relative path
2021-08-06 06:51:19 -07:00
Kubernetes Prow Robot 7ea180d688 Merge pull request #29269 from mozillazg/patch-1
Fix a broken link
2021-08-06 06:47:20 -07:00
David M. Lentz e47fba2b92 Fix typo 2021-08-06 07:46:25 -06:00
Kubernetes Prow Robot 76fc52c75b Merge pull request #29256 from zhangguanzhang/invalid-ref
[zh] docs: sync and update the ref
2021-08-06 06:45:20 -07:00
zhangguanzhang 229cdb70b9 [zh] docs: sync and update the ref
Signed-off-by: zhangguanzhang <zhangguanzhang@qq.com>
2021-08-06 20:48:24 +08:00
Huang Huang 11a2e54d7a Fix a broken link 2021-08-06 20:42:30 +08:00
Carlos Panato 555801a38b move cherry-pick deadline to a Friday, was on Saturday
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-08-06 12:35:46 +02:00
Kubernetes Prow Robot 84e5a82364 Merge pull request #29267 from Arhell/typo
[zh] fix typo
2021-08-06 02:31:20 -07:00
Arhell f39fdce207 [zh] fix typo 2021-08-06 03:13:52 +03:00
Kubernetes Prow Robot 60de38d64f Merge pull request #29251 from sftim/20210805_link_to_v1.22_release
Link to v1.22 release announcement from removals article
2021-08-05 16:27:55 -07:00
Kubernetes Prow Robot b24deab7fa Merge pull request #29228 from sftim/20210804_update_apiservice_link_to_api_reference
Link to new API reference page for APIService
2021-08-05 15:19:41 -07:00
deepsan 788b9ce132 Reword Go requirement for Aggregated API
Given 'Aggregated APIs are subordinate API servers that sit behind the primary API server, which acts as a proxy', the comparison table indicates a requirement for the subordinate API servers to use Go, when it is not a requirement as long as the subordinate API server follows the expected contract
2021-08-05 15:07:43 -07:00
Kubernetes Prow Robot 0b09d3ecc5 Merge pull request #29230 from sftim/20210804_update_link_from_secret_concept_to_api
Update links from Secret concept to relevant API reference
2021-08-05 15:07:41 -07:00
Kubernetes Prow Robot c91e60ce01 Merge pull request #29231 from sftim/20210804_update_link_to_api_reference_working_with_objects
Update link from Working With Objects to Kubernetes API Reference
2021-08-05 14:23:41 -07:00
Kubernetes Prow Robot ad3319300f Merge pull request #29232 from sftim/2021084_update_links_to_api_reference_pv
Link from PV / PVC concept to new API reference
2021-08-05 13:47:19 -07:00
Kubernetes Prow Robot c0612021dd Merge pull request #29233 from sftim/20210804_update_link_to_api_reference_init_containers
Update init containers concept to link to new API reference
2021-08-05 13:29:20 -07:00
Kubernetes Prow Robot 0525ee9a1f Merge pull request #29244 from niteshseram/glossary
Adding Eviction to glossary
2021-08-05 13:05:19 -07:00
Kubernetes Prow Robot fc50bd55f5 Merge pull request #29265 from renato1891/patch-1
fix small grammatical error in operator.md
2021-08-05 12:21:19 -07:00
Renato B. Boaventura f2e2995d23 fix small grammatical error in operator.md
"una falha..." -> "uma falha..."
2021-08-05 15:40:29 -03:00
Elana Hashman b480f0fb53 Note deprecation of the node performance dashboard 2021-08-05 11:03:09 -07:00
Mauricio Poppe 02ebc799d7 Change publish date to 2021-08-05 2021-08-05 16:16:40 +00:00
Mauricio Poppe 4bcfded6d8 Moved section about alpha APIs to be along the APIs that are reaching v1 2021-08-05 16:13:50 +00:00
Mauricio Poppe 0398ce4e27 Keep some sentences in third person 2021-08-05 16:13:50 +00:00
Mauricio Poppe 8dcebae500 Explain work done in PD CSI in more detail, add statement for the system API 2021-08-05 16:13:50 +00:00
Mauricio Poppe 111b8032e0 Feature blogpost: CSI Windows support with CSI Proxy reaches GA 2021-08-05 16:13:50 +00:00
Kubernetes Prow Robot 9ebb504c7a Merge pull request #29262 from haugenj/patch-1
fix small grammatical error in kube-scheduler.md
2021-08-05 08:41:22 -07:00
Kubernetes Prow Robot e2b4e2644c Merge pull request #29243 from tengqm/configapi-122
Config API for 1.22
2021-08-05 08:15:22 -07:00
Kubernetes Prow Robot a1c346fd16 Merge pull request #29242 from tengqm/compref-122
Update generated component reference docs for 1.22
2021-08-05 08:09:22 -07:00
Jason Haugen 1b8686e66a Update kube-scheduler.md
fix a small grammatical error
2021-08-05 09:18:38 -05:00
Tim Bannister cd44e2757f Link to v1.22 release announcement from removals article 2021-08-05 11:53:21 +01:00
Vijay Kumar Jalagari 2eda36ea27 Selector expect map not string
If we using string then k8s api is throwing validation error
``` (HorizontalPodAutoscaler.spec.metrics[0].object.metric.selector): invalid type for io.k8s.apimachinery.pkg.apis.meta.v1.LabelSelector: got "string", expected "map"; if you choose to ignore these errors, turn validation off with --validate=false ```
2021-08-05 16:10:36 +05:30
Kubernetes Prow Robot 708cc9a5fe Merge pull request #29216 from danwinship/ipblock-selectors
Add a manual anchor to an interesting spot in the NetworkPolicy docs
2021-08-05 03:25:22 -07:00
jmyung 7a746df1a5 Add jmyung to sig-docs-ko-reviews 2021-08-05 18:59:08 +09:00
Kubernetes Prow Robot 8c6e5926f8 Merge pull request #29240 from seokho-son/blog-1.22-release
[ko] Translate kubernetes-release-1.22 blog into Korean
2021-08-05 02:51:23 -07:00
Kubernetes Prow Robot a772fcf9cc Merge pull request #29237 from kubernetes/dev-1.21-ko.7
[ko] 7th Korean localization work for v1.21
2021-08-05 02:25:22 -07:00
Kubernetes Prow Robot eed4b02959 Merge pull request #29246 from YuikoTakada/fix_missing_link
Fix missing link
2021-08-05 02:21:22 -07:00
seokho-son b2f7ce183e Translate kubernetes-release-1.22 blog into Korean 2021-08-05 16:45:51 +09:00
Kubernetes Prow Robot c28fd4bfb5 Merge pull request #29173 from ariscahyadi/id-local-rename-jobs
[ID] Rename "Job" Concept page.
2021-08-05 00:33:01 -07:00
sdghchj f21e99e8e7 Update service-accounts-admin.md 2021-08-05 15:29:34 +08:00
Yuiko Mouri 1ad2bce475 Fix missing link 2021-08-05 14:55:29 +09:00
S Nitesh Singh 1230f21648 add eviction to glossary 2021-08-05 10:30:26 +05:30
Qiming Teng f51ed0569d Config API for 1.22 2021-08-05 12:50:28 +08:00
Yuiko Mouri 8f301ea379 Replace with relative path 2021-08-05 11:54:46 +09:00
Kubernetes Prow Robot 43b2e77275 Merge pull request #29167 from ClaudiaJKang/outdated-1.21-ko.7-part2
[ko] Update outdated files in dev-1.21-ko.7 (p2)
2021-08-04 19:18:55 -07:00
Qiming Teng 8acf5d121e Component reference for 1.22 2021-08-05 09:44:17 +08:00
Claudia J. Kang a4aa4613cd [ko] Update outdated files in dev-1.21-ko.7 (p2)
This commit fixes M13~M19 on 28963.
2021-08-05 10:05:56 +09:00
Kubernetes Prow Robot 93f57fd152 Merge pull request #29235 from sftim/20210804_update_tense_for_v1.22_api_deprecations
Update tense for v1.22 API removals
2021-08-04 16:28:38 -07:00
Kubernetes Prow Robot e8b4f229ce Merge pull request #29234 from sftim/20210804_update_v1.22_blog_link_to_kubeadm_v1beta3_config
Link to kubeadm v1beta3 config API
2021-08-04 16:09:10 -07:00
Kubernetes Prow Robot d34ad68f39 Merge pull request #29218 from elKei24/fix/broken-link
[de] fix malformed link on front page
2021-08-04 16:01:11 -07:00
Kubernetes Prow Robot 9c4b023f9b Merge pull request #28964 from Jefftree/ssa-ga
Blog post for Server Side Apply to GA
2021-08-04 15:59:11 -07:00
Kubernetes Prow Robot 2c66264fab Merge pull request #29160 from seokho-son/out1-1.21-ko.7
[ko] Update outdated files in dev-1.21-ko.7 (p1)
2021-08-04 15:55:12 -07:00
Tim Bannister af24e94361 Update tense for v1.22 API removals
These removals have happened, so refer to them in the past.
2021-08-04 23:54:40 +01:00
Kubernetes Prow Robot 0dd81658c7 Merge pull request #29212 from Arhell/improve
[id] update annotations
2021-08-04 15:53:11 -07:00
Kubernetes Prow Robot 4af87260d3 Merge pull request #29029 from jihoon-seo/210720_Translate_node-pressure-eviction
[ko] Translate node-pressure-eviction.md
2021-08-04 15:53:11 -07:00
Tim Bannister b20979dbc4 Link to kubeadm v1beta3 config API
https://k8s.io/docs/reference/config-api/kubeadm-config.v1beta3/ exists,
so let's link to it.
2021-08-04 23:48:38 +01:00
Tim Bannister 191c2bf4ee Pick example versions based on current release 2021-08-04 23:12:25 +01:00
Tim Bannister 142177068b Refer to the “default” rather than “master” branch
Get ready for a switch to "main"
2021-08-04 23:12:25 +01:00
Tim Bannister c1feea756f Update init containers concept to link to new API reference 2021-08-04 22:58:42 +01:00
Tim Bannister 1b3125353d Link from PV / PVC concept to new API reference 2021-08-04 22:52:27 +01:00
Tim Bannister cba4f57124 Update link from Working With Objects to Kubernetes API Reference 2021-08-04 22:42:14 +01:00
Tim Bannister 97c35ce770 Update links from Secret concept to relevant API reference 2021-08-04 22:35:56 +01:00
Tim Bannister 075fdf2e37 Retitle “Kubernetes API Aggregation Layer” concept
The old title “Extending the Kubernetes API with the aggregation layer”
sounds more like a task page than a concept, so I reworded.
2021-08-04 22:28:54 +01:00
Tim Bannister 1ca5ecbf77 Link to new API reference page for APIService 2021-08-04 22:25:12 +01:00
Tedley Meralus de80496fcf fixed small typo
changed uprate to upgrade on line 12
2021-08-04 17:11:28 -04:00
Dan Winship 5a8bd9216a Add a manual anchor to an interesting spot in the NetworkPolicy docs 2021-08-04 11:50:21 -04:00
Jefftree 437f38b0dc Address comments 2021-08-04 08:20:12 -07:00
Jeffrey Ying 04e5a046f7 Apply suggestions from code review
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-08-04 08:20:12 -07:00
Jefftree 8f7c04acb9 Draft blog post for SSA GA 2021-08-04 08:20:12 -07:00
Elias Keis 81fe8fcd7f fix broken link 2021-08-04 14:47:11 +02:00
anyulled 03d287c19d docs: volumes - style correction 2021-08-04 05:13:21 +02:00
Anyul Rivas 21f41c6830 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:09:07 +02:00
Anyul Rivas 9960d32d98 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:08:55 +02:00
Anyul Rivas c73166a15a Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:08:48 +02:00
Anyul Rivas 563b74e02e Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:08:41 +02:00
Anyul Rivas 0f97e0c5ac Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:08:32 +02:00
Anyul Rivas dd316d5525 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:08:16 +02:00
Anyul Rivas fb1e0fbd86 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:07:52 +02:00
Anyul Rivas 75872b71cd Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:07:30 +02:00
Anyul Rivas 3718b99928 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:07:22 +02:00
Anyul Rivas 059b7c53ac Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:07:10 +02:00
Anyul Rivas faf4af3354 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:06:58 +02:00
Anyul Rivas 752aaafc25 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:06:48 +02:00
Anyul Rivas 1bb637a36d Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:06:28 +02:00
Anyul Rivas 0b62eba441 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:06:08 +02:00
Anyul Rivas c1f24b1529 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:05:57 +02:00
Anyul Rivas e509859458 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:05:44 +02:00
Anyul Rivas 9a112c60c9 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:05:26 +02:00
Anyul Rivas f0a52d106f Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 05:05:11 +02:00
Anyul Rivas 30996f3b66 Update content/es/docs/concepts/storage/volumes.md
Co-authored-by: Victor Morales <chipahuac@hotmail.com>
2021-08-04 04:58:43 +02:00
Arhell 85e6e51e9e [id] update annotations 2021-08-04 00:49:24 +03:00
Tim Bannister e3b6ab9579 Improve Katacoda button
Separate out the HTML <div> for Katacoda from the in-page button to
trigger it.
2021-08-03 14:31:38 +01:00
seokho-son 25f168f2f6 Update outdated files in dev-1.21-ko.7 (p1) 2021-08-03 17:55:32 +09:00
Edith b3062eb517 Add concepts/storage/volume-snapshot-classes.md 2021-08-02 23:53:45 -05:00
Kubernetes Prow Robot 8ff25b3f5e Merge pull request #29168 from ClaudiaJKang/outdated-1.21-ko.7-part3
[ko] Update outdated files in dev-1.21-ko.7 (p3)
2021-08-02 19:58:47 -07:00
Kubernetes Prow Robot da58c71c2a Merge pull request #29182 from ClaudiaJKang/ko-29075
[ko] Translate content/ko/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods.md
2021-08-02 19:56:47 -07:00
Anyul Rivas 925b3ed76d Merge branch 'kubernetes:main' into master 2021-08-02 21:12:41 +02:00
anyulled f1f300645b docs: volumes - spanish translation 2021-08-02 21:11:49 +02:00
Claudia J. Kang 08e0981775 [ko] Translate content/ko/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods.md 2021-08-02 23:38:05 +09:00
Naka Masato 3bef97644c Update object-management.md 2021-08-02 22:52:13 +09:00
Sanu Satyadarshi 0032199ed6 Add missing ServiceAccount
Added missing ServiceAccount, ClusterRole and ClusterRoleBinding.

https://github.com/kubernetes/website/issues/15280
https://github.com/kubernetes/kubernetes/blob/master/cluster/addons/dns-horizontal-autoscaler/dns-horizontal-autoscaler.yaml
2021-08-02 12:55:33 +05:30
Jihoon Seo ada25d09e0 Add ko/glossary/node-pressure-eviction.md 2021-08-02 15:22:37 +09:00
Jihoon Seo 9a311f4c3a Reflect review comments 2021-08-02 15:00:07 +09:00
Kubernetes Prow Robot 828806b973 Merge pull request #29180 from ClaudiaJKang/fix-29179
[ko] Fix CoreDNS typo on kubeadm-upgrade
2021-08-01 20:03:21 -07:00
Arhell 473c228985 [ja] Fix typo in worker.py example script 2021-08-02 01:06:00 +03:00
Juhee Kang 4d330619dd [ko] Fix CoreDNS typo on kubeadm-upgrade 2021-08-01 23:20:38 +09:00
anyulled a1801a3416 docs: volumes - spanish translation
CSI
2021-08-01 10:36:37 +02:00
edsoncelio fe63395af0 feat: fix typos requested by code review 2021-07-31 15:09:11 -03:00
NamikoToriyama 359d239a65 Fix a non-existent link
Signed-off-by: NamikoToriyama <namiko.trym@gmail.com>
2021-08-01 02:22:23 +09:00
Arhell 506dc498ab [ja] update link to Flannel 2021-07-31 14:30:09 +03:00
anyulled 69c70cd418 docs: volumes - spanish translation 2021-07-31 12:26:57 +02:00
Anyul Rivas e9b4cee5b2 Merge branch 'kubernetes:main' into master 2021-07-31 11:53:06 +02:00
anyulled d9e4982509 docs: volumes - spanish translation 2021-07-31 11:52:20 +02:00
Aris Cahyadi Risdianto 11ded1cca1 rename "Job" Concept page. 2021-07-31 15:16:01 +07:00
Kubernetes Prow Robot 9ff9f5dd16 Merge pull request #29169 from anushkamittal20/patch-1
[ko]: Fixes wrong link in assign-pod-node.md
2021-07-30 09:59:37 -07:00
Anushka Mittal d818691764 Update wrong link in assign-pod-node.md 2021-07-30 20:32:42 +05:30
Claudia J. Kang a850ca2fc2 [ko] Update outdated files in dev-1.21-ko.7 (p3)
This commit fixes M20~M26 on 28963.
2021-07-30 23:44:18 +09:00
Kubernetes Prow Robot 3ac2177603 Merge pull request #29162 from seokho-son/out-m27-1.21-ko.7
[ko] Update outdated files in dev-1.21-ko.7 (m27)
2021-07-30 06:47:38 -07:00
RA489 7f9d3e3f90 Update activeDeadlineSeconds with Pod page 2021-07-30 16:11:31 +05:30
Kubernetes Prow Robot 1e0c138fad Merge pull request #29003 from ClaudiaJKang/ko-28983
[ko] Translate docs/tasks/administer-cluster/enable-disable-api.md
2021-07-30 00:15:37 -07:00
seokho-son 4bfd5a6acd Update outdated files in dev-1.21-ko.7 (m27) 2021-07-30 15:14:59 +09:00
Kubernetes Prow Robot 1c15c9167e Merge pull request #29074 from ClaudiaJKang/ko-29013
[ko] Translate docs/tasks/administer-cluster/enabling-topology-aware-…
2021-07-29 15:09:18 -07:00
Simone Tiraboschi eca82e08f9 Concretely explain how to patch CRD status
Current documentation simply suggest
"Remove v1beta1 from the CustomResourceDefinition
status.storedVersions field."
but this cannot be done just with kubectl and
it's not so intuitive.

Adding an example to make it more clear.

Signed-off-by: Simone Tiraboschi <stirabos@redhat.com>
2021-07-29 13:50:42 +02:00
Claudia J. Kang d071289f7e [ko] Translate docs/tasks/administer-cluster/enabling-topology-aware-hints.md 2021-07-28 21:01:57 +09:00
chenxuc f4e6b41840 improve hello-minikube page for dashboard 2021-07-28 16:26:27 +08:00
kartik494 c7a44f14ea Modify documentation for stablestorage 2021-07-28 09:37:42 +05:30
Maciej Filocha a17e7b61be Update Polish README file
Update Polish translation of main README file.

Synced up to 9c7d7dcdf6.
2021-07-27 10:47:30 +02:00
chenxuc 8c9c9c543c static pod not support configmap or secret 2021-07-27 14:51:45 +08:00
Vaibhav 03dea1a56f Update the changes in access-cluster-services.md 2021-07-26 13:54:44 +05:30
Tim Bannister 39f2c3860d Reword “Create an External Load Balancer” task
- general cleanup
- update sample output
- use more tooltips
- avoid specifying specific cloud providers

The website repo doesn't maintain a definitive list of cloud providers that
pass Kubernetes conformance tests. It's certainly more than AWS and GCP as
the previous revision stated.
2021-07-24 02:19:40 +01:00
Abhijit Hoskeri ff63695666 encrypt-data: Don't recommend AES-CBC
CBC is not recommended any more due to vulnerability
to padding oracle attacks.

Promote secretbox instead.
2021-07-23 13:03:33 -07:00
Mengjiao Liu b7ec60a564 [ja] Fix secret name to be consistent with examples 2021-07-23 10:35:50 +08:00
Ritikaa96 cee22da0c3 updating cilium network policy docs 2021-07-22 19:34:39 +05:30
Vaibhav 816a5debe8 Remove the duplicate content from access-cluster.md 2021-07-22 18:54:41 +05:30
Kubernetes Prow Robot 9021c7470f Merge pull request #29024 from chhanz/ko-29005-2
[ko] Translate /docs/tasks/configmap-secret/ into Korean
2021-07-21 05:40:08 -07:00
Ritikaa96 570757a47a updatnig flannel link address
Signed-off-by: Ritikaa96 <ritika@india.nec.com>
2021-07-21 16:46:18 +05:30
chhanz 59b4b7f494 Translate /docs/tasks/configmap-secret/ into Korean
Translate /docs/tasks/configmap-secret/ into Korean - fix ver 2
2021-07-21 16:30:27 +09:00
Romain Guichard 25b6493dd8 fix(fr): typo and trailing spaces 2021-07-20 18:36:19 +02:00
able.lv 875cb1a3d7 fix typos ja 2021-07-20 23:27:07 +08:00
sgpinkus 05a45db49c Update _index.md
"Understand the basics" to "Understand Kubernetes". There is no place in the entire docs really to go "Understand the *non* basics". There is one section "Concepts" for better or worse. Don't give the impression there is something else somewhere else. And anyway, this section should aspire to be that cardinal. Also change name of weird button to "Learn" -> "View" to make it clear this is just a link to a section of the documentation.
2021-07-20 21:47:16 +10:00
Jihoon Seo cbc3d89fef [ko] Translate node-pressure-eviction.md 2021-07-20 16:46:16 +09:00
Arhell e8340128d9 [ja] Operator: Exists missing 2021-07-20 00:51:54 +03:00
Claudia J. Kang 5b988bd661 [ko] Translate docs/tasks/administer-cluster/enable-disable-api.md 2021-07-19 20:22:55 +09:00
kartik494 4270ece858 Modify documentation for stable storage 2021-07-19 15:56:27 +05:30
S Nitesh Singh b1fa203e3a fixing the huge white space in sidebar 2021-07-19 11:13:18 +05:30
xeathen ef94676e4e [zh] fix typo of expose-intro.html 2021-07-17 15:59:31 +08:00
Wesley Williams 723b94de50 Clarify that burstable pods also have their limit enforced by CFS quota 2021-07-16 18:10:38 +01:00
kartik494 cb712cdcd1 Add commit for hostname 2021-07-14 23:52:22 +05:30
Nitesh Seram 2c360ea3c6 fixing redirect and chnaging some links in blog
fixing redirects

Fixing few redirects

changing few redirects and links

fixing redirect

Update content/en/blog/_posts/2016-08-00-Kubernetes-Namespaces-Use-Cases-Insights.md

Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>

Update content/en/blog/_posts/2016-12-00-Statefulset-Run-Scale-Stateful-Applications-In-Kubernetes.md

Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>

Update content/en/blog/_posts/2016-12-00-Statefulset-Run-Scale-Stateful-Applications-In-Kubernetes.md

Co-authored-by: Jihoon Seo <46767780+jihoon-seo@users.noreply.github.com>
2021-07-14 12:35:18 +05:30
Anubhav Vardhan 436d3fe8c4 Update content/en/docs/tasks/administer-cluster/highly-available-control-plane.md
Co-authored-by: chrismetz09 <cymetz@gmail.com>
2021-07-14 08:48:53 +05:30
chenxuc 1955629f42 clarify rollout behavior in deployment 2021-07-11 09:17:37 +08:00
edsoncelio 7a0c7cae46 fix: fix typo in doc title 2021-07-09 22:52:21 -03:00
edsoncelio 9822c9a4da feat: add configmap-secret translation 2021-07-09 15:12:29 -03:00
Shubham Kuchhal a3b120928d Correct FQDN for DockerHub. 2021-07-09 17:02:58 +05:30
Sascha Grunert 1134821af6 Add seccomp tutorial to index
This adds the seccomp tutorial page to the index side by side to
AppArmor.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2021-07-09 09:12:48 +02:00
sgpinkus 6158a7f926 Update persistent-volumes.md
Makes option 3 for "reclaiming" a released PV a bit clearer. Used to be:

> Manually delete the associated storage asset, or if you want to reuse the same storage asset, create a new PersistentVolume with the same storage asset definition.

But the 2nd part applies more to reclamation option 1 and is kind of contradictory with option 3 (which isn't really "reclaiming" anything AFAICT). So just  move to it's own stand alone sentence.
2021-07-09 00:00:03 +10:00
Jihoon Seo f37de46d6d [ru] Update Netlify link address 2021-07-02 14:57:13 +09:00
rajeshdeshpande02 d0f94114a1 Adding kubectl cp command examples in cheatsheet 2021-07-01 16:08:39 +05:30
Anubhav Vardhan 6cb9177e2b Update ha-control-plane.svg 2021-07-01 15:07:17 +05:30
Anubhav Vardhan 71507509b3 Update highly-available-control-plane.md 2021-07-01 14:47:28 +05:30
Anubhav Vardhan b9252e5982 Added ha-control-plane.svg 2021-07-01 14:33:55 +05:30
kartik494 c1dc2b074f Add docker server registry 2021-07-01 13:05:52 +05:30
Zhang Yong 9bd06e292d Update URL for Metacontroller 2021-06-29 22:10:57 +08:00
Sandip Bhattacharya 08506d03da dns-pod-service.md: Fix unqualified host search ex
Unless I am mistake, according to the provided search config, the query for `data` is missing the `svc` component in the full search.
2021-06-25 13:15:19 +02:00
kahirokunn e6271ef41b fix: k8s dashboard link.
k8s dashboard required https.
http does not currently have a corresponding endpoint.
So if you try to access it like this, you will get an error: "no endpoints available for service".
2021-06-24 21:54:12 +09:00
Jihoon Seo bee4cb77c2 [de] Remove exec permission on markdown files 2021-06-22 18:12:05 +09:00
Jihoon Seo f334e9e23d [ru] Remove exec permission on markdown files 2021-06-22 18:08:32 +09:00
vaibhav dbcc1d550f Update the docs/setup/learning-environment/_index.md 2021-06-17 10:14:23 +05:30
vaibhav a16de9ee7a Comment the body in docs/setup/learning-environment/_index.md 2021-06-17 10:01:28 +05:30
kartik494 b16ccb3d1d Adding output for ingress-nginx namespace 2021-06-11 12:00:27 +05:30
Kelvin Nicholson 04b5916f26 Fix incorrect command 2021-06-01 22:15:18 +10:00
olivierk 1661dbb435 fix typo _index.md
fix typo of a maj after a coma

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-25 11:35:24 +04:00
olivierk 59d526f55c _index.md fix typo maj
fix the typo of a maj on the first letter of a sentence

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-25 11:34:50 +04:00
olivierk 507f934707 Update content/fr/docs/concepts/workloads/_index.md
swap definition

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-20 14:31:40 +04:00
olivierk 1a25dc8e73 Update content/fr/docs/concepts/workloads/_index.md
Fix DaemonSet word, and sentence

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-20 14:27:53 +04:00
olivierk b2e8b6f913 Update content/fr/docs/concepts/workloads/_index.md
delete a non usefull space

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-20 14:27:27 +04:00
olivierk adf73902b7 Update content/fr/docs/concepts/workloads/_index.md
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2021-05-20 14:26:38 +04:00
edsoncelio 0a5d839101 Update task secret translation 2021-05-16 09:12:38 -03:00
olivierk 97475e7ba8 French translation of workloads page
Add the translated (french) page of the workload ressource.
2021-05-14 13:51:40 +04:00
Jai Govindani 2c82e7d6cf docs(manage-resources-containers): add volume and volumeMount for ephemeral storage
Signed-off-by: Jai Govindani <jai@honestbank.com>
2021-05-07 19:34:43 +07:00
edsoncelio 72267ac653 Add initial files to translate the secret task 2021-05-02 10:30:34 -03:00
RA489 7c75b157ac Improvement for other tools 2021-04-06 16:52:44 +05:30
Zhang Yong 1fb6685925 Fix line separation in concepts/architecture/nodes 2021-03-28 11:05:23 +08:00
1079 changed files with 34428 additions and 19813 deletions
+3
View File
@@ -3,6 +3,9 @@
# When modifying this file, consider the security implications of
# allowing listed reviewers / approvals to modify or remove any
# configured GitHub Actions.
#
options:
no_parent_owners: true
reviewers:
- sig-docs-leads
+6 -5
View File
@@ -33,7 +33,7 @@ exhaustive, and do not form part of our licenses.
material not subject to the license. This includes other CC-
licensed material, or material used under an exception or
limitation to copyright. More considerations for licensors:
wiki.creativecommons.org/Considerations_for_licensors
wiki.creativecommons.org/Considerations_for_licensors
Considerations for the public: By using one of our public
licenses, a licensor grants the public permission to use the
@@ -48,9 +48,9 @@ exhaustive, and do not form part of our licenses.
rights in the material. A licensor may make special requests,
such as asking that all changes be marked or described.
Although not required by our licenses, you are encouraged to
respect those requests where reasonable. More_considerations
for the public:
wiki.creativecommons.org/Considerations_for_licensees
respect those requests where reasonable. More considerations
for the public:
wiki.creativecommons.org/Considerations_for_licensees
=======================================================================
@@ -378,7 +378,7 @@ Section 8 -- Interpretation.
Creative Commons is not a party to its public
licenses. Notwithstanding, Creative Commons may elect to apply one of
its public licenses to material it publishes and in those instances
will be considered the "Licensor." The text of the Creative Commons
will be considered the Licensor. The text of the Creative Commons
public licenses is dedicated to the public domain under the CC0 Public
Domain Dedication. Except for the limited purpose of indicating that
material is shared under a Creative Commons public license or as
@@ -393,3 +393,4 @@ the avoidance of doubt, this paragraph does not form part of the
public licenses.
Creative Commons may be contacted at creativecommons.org.
+2
View File
@@ -8,7 +8,9 @@ approvers:
emeritus_approvers:
# - chenopis, commented out to disable PR assignments
# - irvifa, commented out to disable PR assignments
# - jaredbhatti, commented out to disable PR assignments
# - kbarnard10, commented out to disable PR assignments
# - steveperry-53, commented out to disable PR assignments
- stewart-yu
# - zacharysarah, commented out to disable PR assignments
+17 -16
View File
@@ -1,10 +1,8 @@
aliases:
sig-docs-blog-owners: # Approvers for blog content
- kbarnard10
- onlydole
- mrbobbytables
sig-docs-blog-reviewers: # Reviewers for blog content
- kbarnard10
- mrbobbytables
- onlydole
- sftim
@@ -20,9 +18,9 @@ aliases:
- annajung
- bradtopol
- celestehorgan
- irvifa
- divya-mohan0209
- jimangel
- kbarnard10
- jlbutler
- kbhawkey
- onlydole
- pi-victor
@@ -34,12 +32,14 @@ aliases:
- bradtopol
- celestehorgan
- daminisatya
- divya-mohan0209
- jimangel
- kbarnard10
- kbhawkey
- mehabhalodiya
- onlydole
- rajeshdeshpande02
- sftim
- shannonxtreme
- tengqm
sig-docs-es-owners: # Admins for Spanish content
- raelga
@@ -76,19 +76,19 @@ aliases:
- anthonydahanne
- feloy
sig-docs-hi-owners: # Admins for Hindi content
- avidLearnerInProgress
- daminisatya
- anubha-v-ardhan
- divya-mohan0209
- mittalyashu
sig-docs-hi-reviews: # PR reviews for Hindi content
- avidLearnerInProgress
- daminisatya
- anubha-v-ardhan
- divya-mohan0209
- mittalyashu
- verma-kunal
sig-docs-id-owners: # Admins for Indonesian content
- ariscahyadi
- danninov
- girikuncoro
- habibrosyad
- irvifa
- phanama
- wahyuoi
sig-docs-id-reviews: # PR reviews for Indonesian content
@@ -96,7 +96,6 @@ aliases:
- danninov
- girikuncoro
- habibrosyad
- irvifa
- phanama
- wahyuoi
sig-docs-it-owners: # Admins for Italian content
@@ -133,14 +132,14 @@ aliases:
- gochist
- ianychoi
- jihoon-seo
- jmyung
- pjhwa
- seokho-son
- yoonian
- ysyukr
sig-docs-leads: # Website chairs and tech leads
- irvifa
- divya-mohan0209
- jimangel
- kbarnard10
- kbhawkey
- onlydole
- sftim
@@ -169,6 +168,7 @@ aliases:
- xichengliudui
# zhangxiaoyu-zidif
sig-docs-pt-owners: # Admins for Portuguese content
- edsoncelio
- femrtnz
- jailton
- jcjesus
@@ -177,6 +177,7 @@ aliases:
- rikatz
- yagonobre
sig-docs-pt-reviews: # PR reviews for Portugese content
- edsoncelio
- femrtnz
- jailton
- jcjesus
@@ -224,12 +225,12 @@ aliases:
# authoritative source: git.k8s.io/community/OWNERS_ALIASES
committee-steering: # provide PR approvals for announcements
- cblecker
- derekwaynecarr
- dims
- justaugustus
- liggitt
- mrbobbytables
- nikhita
- parispittman
- tpepper
# authoritative source: https://git.k8s.io/sig-release/OWNERS_ALIASES
sig-release-leads:
- cpanato # SIG Technical Lead
@@ -256,4 +257,4 @@ aliases:
- sethmccombs # Release Manager Associate
- thejoycekung # Release Manager Associate
- verolop # Release Manager Associate
- wilsonehusin # Release Manager Associate
- wilsonehusin # Release Manager Associate
+5 -2
View File
@@ -7,7 +7,7 @@
## डॉक्स में योगदान देना
आप अपने GitHub खाते में इस रिपॉजिटरी की एक copy बनाने के लिए स्क्रीन के ऊपरी-दाएँ क्षेत्र में **Fork** बटन पर क्लिक करें। इस copy को *Fork* कहा जाता है। अपने fork में कोई भी परिवर्तन करना चाहते हैं, और जब आप उन परिवर्तनों को हमारे पास भेजने के लिए तैयार हों, तो अपने fork पर जाएं और हमें इसके बारे में बताने के लिए एक नया pull request बनाएं।
आप अपने GitHub खाते में इस रिपॉजिटरी की एक copy बनाने के लिए स्क्रीन के ऊपरी-दाएँ क्षेत्र में **Fork** बटन पर क्लिक करें। इस copy को *Fork* कहा जाता है। अपने fork में परिवर्तन करने के बाद जब आप उनको हमारे पास भेजने के लिए तैयार हों, तो अपने fork पर जाएं और हमें इसके बारे में बताने के लिए एक नया pull request बनाएं।
एक बार जब आपका pull request बन जाता है, तो एक कुबरनेट्स समीक्षक स्पष्ट, कार्रवाई योग्य प्रतिक्रिया प्रदान करने की जिम्मेदारी लेगा। pull request के मालिक के रूप में, **यह आपकी जिम्मेदारी है कि आप कुबरनेट्स समीक्षक द्वारा प्रदान की गई प्रतिक्रिया को संबोधित करने के लिए अपने pull request को संशोधित करें।**
@@ -23,9 +23,12 @@
## `README.md`'s स्थानीयकरण कुबरनेट्स प्रलेखन
आप पर हिंदी स्थानीयकरण के maintainers तक पहुँच सकते हैं:
आप हिंदी स्थानीयकरण के मैन्टेनरों तक पहुँच सकते हैं:
* Anubhav Vardhan ([Slack](https://kubernetes.slack.com/archives/D0261C0A3R8), [Twitter](https://twitter.com/anubha_v_ardhan), [GitHub](https://github.com/anubha-v-ardhan))
* Divya Mohan ([Slack](https://kubernetes.slack.com/archives/D027R7BE804), [Twitter](https://twitter.com/Divya_Mohan02), [GitHub](https://github.com/divya-mohan0209))
* Yashu Mittal ([Twitter](https://twitter.com/mittalyashu77), [GitHub](https://github.com/mittalyashu))
* [Slack channel](https://kubernetes.slack.com/messages/kubernetes-docs-hi)
## स्थानीय रूप से डॉकर का उपयोग करके साइट चलाना
+4 -2
View File
@@ -18,7 +18,7 @@ Aby móc skorzystać z tego repozytorium, musisz lokalnie zainstalować:
- [npm](https://www.npmjs.com/)
- [Go](https://golang.org/)
- [Hugo (Extended version)](https://gohugo.io/)
- Środowisko obsługi kontenerów, np. [Docker-a](https://www.docker.com/).
- Środowisko obsługi kontenerów, np. [Dockera](https://www.docker.com/).
Przed rozpoczęciem zainstaluj niezbędne zależności. Sklonuj repozytorium i przejdź do odpowiedniego katalogu:
@@ -43,7 +43,9 @@ make container-image
make container-serve
```
Aby obejrzeć zawartość serwisu otwórz w przeglądarce adres http://localhost:1313. Po każdej zmianie plików źródłowych, Hugo automatycznie aktualizuje stronę i odświeża jej widok w przeglądarce.
Jeśli widzisz błędy, prawdopodobnie kontener z Hugo nie dysponuje wystarczającymi zasobami. Aby rozwiązać ten problem, zwiększ ilość dostępnych zasobów CPU i pamięci dla Dockera na Twojej maszynie ([MacOSX](https://docs.docker.com/docker-for-mac/#resources) i [Windows](https://docs.docker.com/docker-for-windows/#resources)).
Aby obejrzeć zawartość serwisu, otwórz w przeglądarce adres http://localhost:1313. Po każdej zmianie plików źródłowych, Hugo automatycznie aktualizuje stronę i odświeża jej widok w przeglądarce.
## Jak uruchomić lokalną kopię strony przy pomocy Hugo?
+1 -1
View File
@@ -1,6 +1,6 @@
# Документация по Kubernetes
[![Netlify Status](https://api.netlify.com/api/v1/badges/be93b718-a6df-402a-b4a4-855ba186c97d/deploy-status)](https://app.netlify.com/sites/kubernetes-io-master-staging/deploys) [![GitHub release](https://img.shields.io/github/release/kubernetes/website.svg)](https://github.com/kubernetes/website/releases/latest)
[![Netlify Status](https://api.netlify.com/api/v1/badges/be93b718-a6df-402a-b4a4-855ba186c97d/deploy-status)](https://app.netlify.com/sites/kubernetes-io-main-staging/deploys) [![GitHub release](https://img.shields.io/github/release/kubernetes/website.svg)](https://github.com/kubernetes/website/releases/latest)
Данный репозиторий содержит все необходимые файлы для сборки [сайта Kubernetes и документации](https://kubernetes.io/). Мы благодарим вас за желание внести свой вклад!
+2 -1
View File
@@ -146,7 +146,8 @@ Learn more about SIG Docs Kubernetes community and meetings on the [community pa
You can also reach the maintainers of this project at:
- [Slack](https://kubernetes.slack.com/messages/sig-docs) [Get an invite for this Slack](https://slack.k8s.io/)
- [Slack](https://kubernetes.slack.com/messages/sig-docs)
- [Get an invite for this Slack](https://slack.k8s.io/)
- [Mailing List](https://groups.google.com/forum/#!forum/kubernetes-sig-docs)
## Contributing to the docs
-3
View File
@@ -4,8 +4,6 @@
Join the [kubernetes-security-announce] group for security and vulnerability announcements.
You can also subscribe to an RSS feed of the above using [this link][kubernetes-security-announce-rss].
## Reporting a Vulnerability
Instructions for reporting a vulnerability can be found on the
@@ -17,6 +15,5 @@ Information about supported Kubernetes versions can be found on the
[Kubernetes version and version skew support policy] page on the Kubernetes website.
[kubernetes-security-announce]: https://groups.google.com/forum/#!forum/kubernetes-security-announce
[kubernetes-security-announce-rss]: https://groups.google.com/forum/feed/kubernetes-security-announce/msgs/rss_v2_0.xml?num=50
[Kubernetes version and version skew support policy]: https://kubernetes.io/docs/setup/release/version-skew-policy/#supported-versions
[Kubernetes Security and Disclosure Information]: https://kubernetes.io/docs/reference/issues-security/security/#report-a-vulnerability
+3 -4
View File
@@ -1,6 +1,6 @@
# Defined below are the security contacts for this repo.
#
# They are the contact point for the Product Security Committee to reach out
# They are the contact point for the Security Response Committee to reach out
# to for triaging and handling of incoming issues.
#
# The below names agree to abide by the
@@ -10,7 +10,6 @@
# DO NOT REPORT SECURITY VULNERABILITIES DIRECTLY TO THESE NAMES, FOLLOW THE
# INSTRUCTIONS AT https://kubernetes.io/security/
irvifa
divya-mohan0209
jimangel
kbarnard10
sftim
sftim
+4 -16
View File
@@ -810,11 +810,10 @@ section#cncf {
}
}
.td-search {
header > .header-filler {
height: $hero-padding-top;
background-color: black;
}
// Header filler size adjustment
.header-hero.filler {
height: $hero-padding-top;
}
// Docs specific
@@ -859,17 +858,6 @@ section#cncf {
/* DOCUMENTATION */
body.td-documentation {
header > .header-filler {
height: $hero-padding-top;
background-color: black;
}
/* Special case for if an announcement is active */
header section#announcement ~ .header-filler {
display: none;
}
}
// nav-tabs and tab-content
.nav-tabs {
border-bottom: none !important;
+214 -70
View File
@@ -26,6 +26,10 @@ $announcement-size-adjustment: 8px;
}
}
.header-hero #quickstartButton.button {
margin-top: 1em;
}
section {
.main-section {
@media only screen and (min-width: 1024px) {
@@ -34,8 +38,11 @@ section {
}
}
.td-outer {
padding: 0 !important;
body {
header + .td-outer {
min-height: 50vh;
height: auto;
}
}
@@ -313,37 +320,68 @@ main {
// blockquotes and callouts
.td-content, body {
blockquote.callout {
body {
.alert {
// Override Docsy styles
padding: 0.4rem 0.4rem 0.4rem 1rem;
border: 1px solid #eee;
border-left-width: 0.5em;
border-top: 1px solid #eee;
border-bottom: 1px solid #eee;
border-right: 1px solid #eee;
border-radius: 0.25em;
border-left-width: 0.5em; // fallback in case calc() is missing
background: #fff;
color: #000;
margin-top: 0.5em;
margin-bottom: 0.5em;
}
blockquote.callout {
border-radius: calc(1em/3);
// Set minimum width and radius for alert color
.alert {
border-left-width: calc(max(0.5em, 4px));
border-top-left-radius: calc(max(0.5em, 4px));
border-bottom-left-radius: calc(max(0.5em, 4px));
}
.callout.caution {
.alert.callout.caution {
border-left-color: #f0ad4e;
}
.callout.note {
.alert.callout.note {
border-left-color: #428bca;
}
.callout.warning {
.alert.callout.warning {
border-left-color: #d9534f;
}
.alert.third-party-content {
border-left-color: #444;
}
h1:first-of-type + blockquote.callout {
h1:first-of-type + .alert.callout {
margin-top: 1.5em;
}
}
.deprecation-warning {
// Special color for third party content disclaimers
.alert.third-party-content { border-left-color: #222 };
// Highlight disclaimer when targeted as a fragment
#third-party-content-disclaimer {
color: #000;
background: #f8f9fa;
transition: all 0.5s ease;
}
@keyframes disclaimer-highlight {
from { background: #f8f922; color: #000; }
50% { background: #f8f944; color: #000; }
to { background: #f8f9cb; color: #000; }
}
#third-party-content-disclaimer:target {
color: #000;
animation: disclaimer-highlight 1.25s ease;
background: #f8f9cb;
}
.deprecation-warning, .pageinfo.deprecation-warning {
padding: 20px;
margin: 20px 0;
background-color: #faf5b6;
@@ -354,6 +392,12 @@ body.td-home .deprecation-warning, body.td-blog .deprecation-warning, body.td-do
border-radius: 3px;
}
.td-documentation .td-content > .highlight {
max-width: initial;
width: 100%;
}
body.td-home #deprecation-warning {
max-width: 1000px;
margin-top: 2.5rem;
@@ -524,34 +568,6 @@ main.content {
}
}
/* ANNOUNCEMENTS */
section#fp-announcement ~ .header-hero {
padding: $announcement-size-adjustment 0;
> div {
margin-top: $announcement-size-adjustment;
margin-bottom: $announcement-size-adjustment;
}
h1, h2, h3, h4, h5 {
margin: $announcement-size-adjustment 0;
}
}
section#announcement ~ .header-hero {
padding: #{$announcement-size-adjustment / 2} 0;
> div {
margin-top: #{$announcement-size-adjustment / 2};
margin-bottom: #{$announcement-size-adjustment / 2};
padding-bottom: #{$announcement-size-adjustment / 2};
}
h1, h2, h3, h4, h5 {
margin: #{$announcement-size-adjustment / 2} 0;
}
}
/* DOCUMENTATION */
/* Don't show lead text */
@@ -577,15 +593,15 @@ body.td-documentation {
@media print {
/* Do not print announcements */
#announcement, section#announcement, #fp-announcement, section#fp-announcement {
#announcement {
display: none;
}
}
#announcement, #fp-announcement {
#announcement {
> * {
color: inherit;
background: inherit;
background: transparent;
}
a {
@@ -599,42 +615,97 @@ body.td-documentation {
}
}
#announcement {
padding-top: 105px;
padding-bottom: 25px;
}
.header-hero {
padding-top: 40px;
}
/* Extra announcement height only for landscape viewports */
@media (min-aspect-ratio: 8/9) {
#fp-announcement {
min-height: 25vh;
}
}
#fp-announcement aside {
padding-top: 115px;
padding-bottom: 25px;
}
.announcement {
.content {
#announcement {
.announcement-main {
margin-left: auto;
margin-right: auto;
margin-bottom: 0px;
// for padding-top see _size.scss
padding-bottom: calc(max(2em, 2rem));
max-width: calc(min(1200px - 8em, 80vw));
}
> p {
.gridPage #announcement .content p,
.announcement > h4,
.announcement > h3 {
color: #ffffff;
/* always white */
h1, h2, h3, h4, h5, h6, p * {
color: #ffffff;
background: transparent;
img.event-logo {
display: inline-block;
max-height: calc(min(80px, 8em));
max-width: calc(min(240px, 33vw));
float: right;
}
}
}
#announcement + .header-hero {
padding-top: 2em;
}
// Extra padding for anything except wide viewports
@media (min-width: 992px) {
#announcement aside { // more specific
.announcement-main {
padding-top: calc(max(8em, 8rem));
}
}
}
@media (max-width: 768px) {
#announcement {
padding-top: 4rem;
padding-bottom: 4rem;
.announcement-main, aside .announcement-main {
padding-top: calc(min(2rem,2em));
}
}
}
@media (max-width: 480px) {
#announcement {
padding-bottom: 0.5em;
}
#announcement aside {
h1, h2, h3, h4, h5, h6 {
img.event-logo {
margin-left: auto;
margin-right: auto;
margin-bottom: 0.75em;
display: block;
max-height: initial;
max-width: calc(min(calc(100vw - 2em), 240px));
float: initial;
}
}
}
}
#announcement + .header-hero.filler {
display: none;
}
@media (min-width: 768px) {
#announcement + .header-hero {
display: none;
}
}
// Match Docsy-imposed max width on text body
@media (min-width: 1200px) {
body.td-blog main .td-content > figure {
max-width: 80%;
}
}
.td-content {
table code {
background-color: inherit !important;
@@ -642,3 +713,76 @@ body.td-documentation {
font-size: inherit !important;
}
}
/* Force size constraints on figures */
figure {
&.diagram-small img {
max-height: clamp(20mm,12em,80vh);
margin-left: auto;
margin-right: auto;
display: block;
}
&.diagram-medium img {
max-height: clamp(25mm,20em,80vh);
margin-left: auto;
margin-right: auto;
display: block;
}
&.diagram-large img {
max-width: clamp(0vw, 95vw, 100%);
max-height: calc(80vh - 8rem);
}
}
@media only screen and (min-width: 768px) {
figure {
&.diagram-small, &.diagram-medium {
max-width: 80%;
}
&.diagram-large {
max-width: 100%;
width: 100%;
}
&.diagram-small img {
max-width: clamp(30rem, 45ch, 100mm);
}
&.diagram-medium img {
max-width: clamp(50rem, 20ch, 160mm);
}
&.diagram-large img {
max-width: clamp(25vw, 95vw, 100%);
max-height: calc(100vh - 10rem);
}
}
}
// Indent definition lists
dl {
padding-left: 1.5em;
// Add vertical space before definitions
> *:not(dt) + dt, dt:first-child {
margin-top: 1.5em;
}
}
.release-details {
padding-left: 2em;
> :not(p) {
font-size: 1.125em;
}
.release-inline-heading, .release-inline-value {
display: inline-block
}
.release-inline-value {
padding-left: 0.25em;
}
p {
margin-top: 1em;
margin-bottom: 1em;
}
}
+8
View File
@@ -18,3 +18,11 @@ section,
line-height: $vendor-strip-height;
font-size: $vendor-strip-font-size;
}
#announcement {
min-height: $hero-padding-top;
.announcement-main {
padding-top: calc(max(8em, 8rem, #{$hero-padding-top} / 3));
}
}
+1 -1
View File
@@ -8,7 +8,7 @@ options:
substitution_option: ALLOW_LOOSE
steps:
# It's fine to bump the tag to a recent version, as needed
- name: "gcr.io/k8s-testimages/gcb-docker-gcloud:v20190906-745fed4"
- name: "gcr.io/k8s-staging-test-infra/gcb-docker-gcloud:v20210917-12df099d55"
entrypoint: make
env:
- DOCKER_CLI_EXPERIMENTAL=enabled
+24 -21
View File
@@ -123,6 +123,7 @@ id = "UA-00000000-0"
[params]
copyright_k8s = "The Kubernetes Authors"
copyright_linux = "Copyright © 2020 The Linux Foundation ®."
# privacy_policy = "https://policies.google.com/privacy"
# First one is picked as the Twitter card image if not set on page.
@@ -138,13 +139,13 @@ time_format_default = "January 02, 2006 at 3:04 PM PST"
description = "Production-Grade Container Orchestration"
showedit = true
latest = "v1.22"
latest = "v1.23"
fullversion = "v1.22.0"
fullversion = "v1.22.4"
version = "v1.22"
githubbranch = "main"
docsbranch = "main"
deprecated = false
githubbranch = "v1.22.4"
docsbranch = "release-1.22"
deprecated = true
currentUrl = "https://kubernetes.io/docs/home/"
nextUrl = "https://kubernetes-io-vnext-staging.netlify.com/"
@@ -178,44 +179,46 @@ js = [
]
[[params.versions]]
fullversion = "v1.22.0"
version = "v1.22"
githubbranch = "v1.22.0"
fullversion = "v1.23.0"
version = "v1.23"
githubbranch = "v1.23.0"
docsbranch = "main"
url = "https://kubernetes.io"
[[params.versions]]
fullversion = "v1.21.4"
fullversion = "v1.22.4"
version = "v1.22"
githubbranch = "v1.22.4"
docsbranch = "release-1.22"
url = "https://v1-22.docs.kubernetes.io"
[[params.versions]]
fullversion = "v1.21.7"
version = "v1.21"
githubbranch = "v1.21.4"
githubbranch = "v1.21.7"
docsbranch = "release-1.21"
url = "https://v1-21.docs.kubernetes.io"
[[params.versions]]
fullversion = "v1.20.10"
fullversion = "v1.20.13"
version = "v1.20"
githubbranch = "v1.20.10"
githubbranch = "v1.20.13"
docsbranch = "release-1.20"
url = "https://v1-20.docs.kubernetes.io"
[[params.versions]]
fullversion = "v1.19.14"
fullversion = "v1.19.16"
version = "v1.19"
githubbranch = "v1.19.14"
githubbranch = "v1.19.16"
docsbranch = "release-1.19"
url = "https://v1-19.docs.kubernetes.io"
[[params.versions]]
fullversion = "v1.18.20"
version = "v1.18"
githubbranch = "v1.18.20"
docsbranch = "release-1.18"
url = "https://v1-18.docs.kubernetes.io"
# User interface configuration
[params.ui]
# Enable to show the side bar menu in its compact state.
sidebar_menu_compact = false
# https://github.com/gohugoio/hugo/issues/8918#issuecomment-903314696
sidebar_cache_limit = 1
# Set to true to disable breadcrumb navigation.
breadcrumb_disable = false
# Set to true to hide the sidebar search box (the top nav search box will still be displayed if search is enabled)
+4 -4
View File
@@ -9,7 +9,7 @@ cid: home
{{% blocks/feature image="flower" %}}
### [Kubernetes (K8s)]({{< relref "/docs/concepts/overview/what-is-kubernetes" >}}) ist ein Open-Source-System zur Automatisierung der Bereitstellung, Skalierung und Verwaltung von containerisierten Anwendungen.
Es gruppiert Container, aus denen sich eine Anwendung zusammensetzt, in logische Einheiten, um die Verwaltung und Erkennung zu erleichtern. Kubernetes baut auf [15 Jahre Erfahrung in Bewältigung von Produktions-Workloads bei Google] (http://queue.acm.org/detail.cfm?id=2898444), kombiniert mit Best-of-Breed-Ideen und Praktiken aus der Community.
Es gruppiert Container, aus denen sich eine Anwendung zusammensetzt, in logische Einheiten, um die Verwaltung und Erkennung zu erleichtern. Kubernetes baut auf [15 Jahre Erfahrung in Bewältigung von Produktions-Workloads bei Google](http://queue.acm.org/detail.cfm?id=2898444), kombiniert mit Best-of-Breed-Ideen und Praktiken aus der Community.
{{% /blocks/feature %}}
{{% blocks/feature image="scalable" %}}
@@ -42,12 +42,12 @@ Kubernetes ist Open Source und bietet Dir die Freiheit, die Infrastruktur vor Or
<button id="desktopShowVideoButton" onclick="kub.showVideo()">Video ansehen</button>
<br>
<br>
<a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/?utm_source=kubernetes.io&utm_medium=nav&utm_campaign=kccnceu20" button id="desktopKCButton">Besuche die KubeCon - 13-16 August 2020 in Amsterdam</a>
<a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/?utm_source=kubernetes.io&utm_medium=nav&utm_campaign=kccncna21" button id="desktopKCButton">Besuche die KubeCon North America vom 11. bis 15. Oktober 2021</a>
<br>
<br>
<br>
<br>
<a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/?utm_source=kubernetes.io&utm_medium=nav&utm_campaign=kccncna20" button id="desktopKCButton">Besuche die KubeCon - 17-20 November 2020 in Boston</a>
<a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-europe-2022/?utm_source=kubernetes.io&utm_medium=nav&utm_campaign=kccnceu22" button id="desktopKCButton">Besuche die KubeCon Europe vom 17. bis 20. Mai 2022</a>
</div>
<div id="videoPlayer">
<iframe data-url="https://www.youtube.com/embed/H06qrNmGqyE?autoplay=1" frameborder="0" allowfullscreen></iframe>
@@ -57,4 +57,4 @@ Kubernetes ist Open Source und bietet Dir die Freiheit, die Infrastruktur vor Or
{{< blocks/kubernetes-features >}}
{{< blocks/case-studies >}}
{{< blocks/case-studies >}}
+246 -51
View File
@@ -4,58 +4,253 @@ layout: basic
cid: community
---
<section id="mainContent">
<main>
<div class="content">
<h3>Die Gewissheit, dass Kubernetes überall und für alle gut funktioniert.</h3>
<p>Verbinden Sie sich mit der Kubernetes-Community in unserem <a href="http://slack.k8s.io/">Slack Kanal</a>, <a href="https://discuss.kubernetes.io/">Diskussionsforum</a>, oder beteiligen Sie sich an der <a href="https://groups.google.com/g/kubernetes-dev"> Kubernetes-dev-Google-Gruppe</a>. Eine wöchentliches Community-Meeting findet per Videokonferenz statt, um den Stand der Dinge zu diskutieren, folgen Sie
<a href="https://github.com/kubernetes/community/blob/master/events/community-meeting.md">diesen Anweisungen</a> für Informationen wie Sie teilnehmen können.</p>
<p>Sie können Kubernetes auch auf der ganzen Welt über unsere
<a href="https://www.meetup.com/topics/kubernetes/">Kubernetes Meetup Community</a> und der
<a href="https://www.meetup.com/Kubernetes-Cloud-Native-Online-Meetup/">Kubernetes Cloud Native Meetup Community</a> beitreten.</p>
</div>
<div class="content">
<h3>Special Interest Groups (SIGs)</h3>
<p>Haben Sie ein besonderes Interesse daran, wie Kubernetes mit einer anderen Technologie arbeitet? Werfen Sie einen Blick auf unsere kontinuierlich wachsende
<a href="https://git.k8s.io/community/sig-list.md">Listen von SIGs</a>, von AWS und Openstack bis hin zu Big Data und Skalierbarkeit, es gibt einen Platz für Sie, an dem Sie mitwirken können, und Anweisungen zur Gründung einer neuen SIG finden, wenn Ihr besonderes Interesse (noch) nicht abgedeckt ist.
</p>
<div class="newcommunitywrapper">
<div class="banner1">
<img src="/images/community/kubernetes-community-final-02.jpg" alt="Kubernetes-Konferenz Galerie" style="width:100%;padding-left:0px" class="desktop">
<img src="/images/community/kubernetes-community-02-mobile.jpg" alt="Kubernetes-Konferenz Galerie" style="width:100%;padding-left:0px" class="mobile">
</div>
<p>Als Mitglied der Kubernetes-Community sind Sie herzlich eingeladen, an allen SIG-Treffen teilzunehmen, die Sie interessieren. Eine Registrierung ist nicht erforderlich.</p>
<div class="intro">
<br class="mobile">
<p>Die Kubernetes-Community - Nutzer, Mitwirkende und die Kultur, die wir gemeinsam aufgebaut haben - ist einer der Hauptgründe für den kometenhaften Aufstieg dieses Open-Source-Projekts. Unsere Kultur und unsere Werte wachsen und entwickeln sich mit dem Wachstum und der Veränderung des Projekts selbst. Wir alle arbeiten gemeinsam an der ständigen Verbesserung des Projekts und der Art und Weise, wie wir daran arbeiten.
<br><br>Wir sind die Leute, die Probleme und Pull-Requests einreichen, an SIG-Treffen (Special Interest Groups), Kubernetes-Treffen und der KubeCon teilnehmen, sich für die Einführung und Innovation von Kubernetes einsetzen, <code>kubectl get pods</code> ausführen und auf tausend andere wichtige Arten beitragen. Lies weiter, um zu erfahren, wie Du dich engagieren und Teil dieser faszinierenden Gemeinschaft werden kannst.</p>
<br class="mobile">
</div>
</div>
<div class="community__navbar">
<div class="content">
<h3>Verhaltensregeln</h3>
<p>Die Kubernetes-Community schätzt Respekt und Inklusivität und setzt einen <a href="code-of-conduct/">Verhaltenskodex</a>
in allen Interaktionen durch. Wenn Sie einen Verstoß gegen den Verhaltenskodex bei einer Veranstaltung oder Sitzung,
in Slack oder in einem anderen Kommunikationsmechanismus feststellen, wenden Sie sich
bitte an das <a href="https://github.com/kubernetes/community/tree/master/committee-code-of-conduct">Kubernetes Code of Conduct Committee</a> <a href="mailto:conduct@kubernetes.io">conduct@kubernetes.io</a>. Ihre Anonymität wird geschützt.
</p>
</div>
</main>
</section>
<a href="#values">Gemeinschaftswerte</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#conduct">Verhaltenskodex </a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#videos">Videos</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#discuss">Diskussionen</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#events">Veranstaltungen und meetups</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#news">Neuigkeiten</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="/releases">Releases</a>
<section id="talkToUs">
<main>
<h3>Talk to Us!</h3>
<h4>Wir würden uns freuen, von Ihnen zu hören, wie Sie Kubernetes verwenden<br>und was wir tun können, um es besser zu machen.</h4>
<div id="bigSocial">
<div>
<a href="https://twitter.com/kubernetesio">@kubernetesio</a>
<p>Erhalten Sie die neuesten Nachrichten und Updates.</p>
</div>
<div>
<a href="https://github.com/kubernetes/kubernetes">Github Project</a>
<p>Informieren Sie sich über das Projekt und erwägen Sie, einen Beitrag zu leisten.</p>
</div>
<div>
<a href="http://slack.k8s.io/">#kubernetes-users</a>
<p>Unser Slack-Kanal ist der beste Weg, um unsere Ingenieure zu kontaktieren und Ihre Ideen mit ihnen zu teilen.</p>
</div>
<div>
<a href="http://stackoverflow.com/questions/tagged/kubernetes">Stack Overflow</a>
<p>Unser Benutzerforum ist ein großartiger Ort, um Community-Support zu erhalten.</p>
</div>
</div>
</main>
</section>
</div>
<br class="mobile"><br class="mobile">
<div class="imagecols">
<br class="mobile">
<div class="imagecol">
<img src="/images/community/kubernetes-community-final-03.jpg" alt="Kubernetes-Konferenz Galerie" style="width:100%" class="desktop">
</div>
<div class="imagecol">
<img src="/images/community/kubernetes-community-final-04.jpg" alt="Kubernetes-Konferenz Galerie" style="width:100%" class="desktop">
</div>
<div class="imagecol" style="margin-right:0% important">
<img src="/images/community/kubernetes-community-final-05.jpg" alt="Kubernetes-Konferenz Galerie" style="width:100%;margin-right:0% important" class="desktop">
</div>
<img src="/images/community/kubernetes-community-04-mobile.jpg" alt="Kubernetes-Konferenz Galerie" style="width:100%;margin-bottom:3%" class="mobile">
<a name="values"></a>
</div>
<div><a name="values"></a></div>
<div class="conduct">
<div class="conducttext">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<div class="conducttextnobutton" style="margin-bottom:2%"><h1>Gemeinschaftswerte</h1>
Die Werte der Kubernetes-Community sind der Grundstein für den anhaltenden Erfolg des Projekts.<br>
Diese Prinzipien leiten jeden Aspekt des Kubernetes-Projekts.
<br>
<a href="/community/values/">
<br class="mobile"><br class="mobile">
<span class="fullbutton">
MEHR ERFAHREN
</span>
</a>
</div><a name="conduct"></a>
</div>
</div>
<div class="conduct">
<div class="conducttext">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<div class="conducttextnobutton" style="margin-bottom:2%"><h1>Verhaltenskodex</h1>
Die Kubernetes-Gemeinschaft legt Wert auf Respekt und Inklusivität und setzt bei allen Interaktionen einen Verhaltenskodex durch. Wenn Du einen Verstoß gegen den Verhaltenskodex bei einer Veranstaltung oder einem Treffen, in Slack oder in einem anderen Kommunikationsmechanismus bemerkst, wende dich an das Kubernetes Code of Conduct Committee unter <a href="mailto:conduct@kubernetes.io" style="color:#0662EE;font-weight:300">conduct@kubernetes.io</a>. Alle Berichte werden vertraulich behandelt. Du kannst&nbsp;<a href="https://github.com/kubernetes/community/tree/master/committee-code-of-conduct" style="color:#0662EE;font-weight:300">hier</a> mehr über den Ausschuss erfahren.
<br>
<a href="https://kubernetes.io/de/community/code-of-conduct/">
<br class="mobile"><br class="mobile">
<span class="fullbutton">
MEHR ERFAHREN
</span>
</a>
</div><a name="videos"></a>
</div>
</div>
<div class="videos">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<h1 style="margin-top:0px">Videos</h1>
<div style="margin-bottom:4%;font-weight:300;text-align:center;padding-left:10%;padding-right:10%">Wir sind auf YouTube, und zwar oft. Abonniere uns für eine Vielzahl von&nbsp;Themen.</div>
<div class="videocontainer">
<div class="video">
<iframe width="100%" height="250" src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP3azFUvYJjGn45YbF6C-uIg" title="Monatliche Bürozeiten" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP3azFUvYJjGn45YbF6C-uIg">
<div class="videocta">
Monatliche Bürozeiten ansehen&nbsp;&#9654;</div>
</a>
</div>
<div class="video">
<iframe width="100%" height="250" src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP1pkHsbPjzAewvMgGUpkCnJ" title="Wöchentliche Treffen der Gemeinschaft" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP1pkHsbPjzAewvMgGUpkCnJ">
<div class="videocta">
Wöchentliche Treffen der Gemeinschaft ansehen&nbsp;&#9654;
</div>
</a>
</div>
<div class="video">
<iframe width="100%" height="250" src="https://www.youtube.com/embed/videoseries?list=PL69nYSiGNLP3QpQrhZq_sLYo77BVKv09F" title="Vortrag eines Mitglieds der Gemeinschaft" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe>
<a href="https://www.youtube.com/playlist?list=PL69nYSiGNLP3QpQrhZq_sLYo77BVKv09F">
<div class="videocta">
Vortrag eines Mitglieds der Gemeinschaft ansehen&nbsp;&#9654;
</div>
</a>
<a name="discuss"></a>
</div>
</div>
</div>
<div class="resources">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<h1 style="padding-top:1%">Diskussionen</h1>
<div style="font-weight:300;text-align:center">Wir reden gerne und viel. Triff uns auf einer dieser Plattformen und beteilige dich an den Diskussionen.</div>
<div class="resourcecontainer">
<div class="resourcebox">
<img src="/images/community/discuss.png" alt=Forum" style="width:80%;padding-bottom:2%">
<a href="https://discuss.kubernetes.io/" style="color:#0662EE;display:block;margin-top:1%">
forum&nbsp;&#9654;
</a>
<div class="resourceboxtext" style="font-size:12px;text-transform:none !important;font-weight:300;line-height:1.4em;color:#333333;margin-top:4%">
Themenbezogene technische Diskussionen, die eine Brücke zu Docs, StackOverflow und vielem mehr schlagen.
</div>
</div>
<div class="resourcebox">
<img src="/images/community/twitter.png" alt="Twitter" style="width:80%;padding-bottom:2%">
<a href="https://twitter.com/kubernetesio" style="color:#0662EE;display:block;margin-top:1%">
twitter&nbsp;&#9654;
</a>
<div class="resourceboxtext" style="font-size:12px;text-transform:none !important;font-weight:300;line-height:1.4em;color:#333333;margin-top:4%">Echtzeit-Ankündigungen von Blogeinträgen, Veranstaltungen, Neuigkeiten und Ideen
</div>
</div>
<div class="resourcebox">
<img src="/images/community/github.png" alt="GitHub" style="width:80%;padding-bottom:2%">
<a href="https://github.com/kubernetes/kubernetes" style="color:#0662EE;display:block;margin-top:1%">
github&nbsp;&#9654;
</a>
<div class="resourceboxtext" style="font-size:12px;text-transform:none !important;font-weight:300;line-height:1.4em;color:#333333;margin-top:4%">
Die gesamte Projekt- und Problemverfolgung und natürlich der Code
</div>
</div>
<div class="resourcebox">
<img src="/images/community/stack.png" alt="Stack Overflow" style="width:80%;padding-bottom:2%">
<a href="https://stackoverflow.com/search?q=kubernetes" style="color:#0662EE;display:block;margin-top:1%">
stack overflow&nbsp;&#9654;
</a>
<div class="resourceboxtext" style="font-size:12px;text-transform:none !important;font-weight:300;line-height:1.4em;color:#333333;margin-top:4%">
Technische Problemlösung für jeden Anwendungsfall
<a name="events"></a>
</div>
</div>
<!--
<div class="resourcebox">
<img src="/images/community/slack.png" style="width:80%">
slack&nbsp;&#9654;
<div class="resourceboxtext" style="font-size:11px;text-transform:none !important;font-weight:200;line-height:1.4em;color:#333333;margin-top:4%">
With 170+ channels, you'll find one that fits your needs.
</div>
</div>-->
</div>
</div>
<div class="events">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<div class="eventcontainer">
<h1 style="color:white !important">Bevorstehende Veranstaltungen</h1>
{{< upcoming-events >}}
</div>
</div>
<div class="meetups">
<div class="meetupcol">
<div class="meetuptext">
<h1 style="text-align:left">Globale Gemeinschaft</h1>
Mit mehr als 150 Treffen auf der ganzen Welt, Tendenz steigend, solltest du deine lokalen Kube-Leute finden. Wenn keins in der Nähe ist, nimm die Sache in die Hand und gründe dein eigenes.
</div>
<a href="https://www.meetup.com/topics/kubernetes/">
<div class="button">
EIN MEETUP FINDEN
</div>
</a>
<a name="news"></a>
</div>
</div>
<!--
<div class="contributor">
<div class="contributortext">
<br>
<h1 style="text-align:left">
New Contributors Site
</h1>
Text about new contributors site.
<br><br>
<div class="button">
VISIT SITE
</div>
</div>
</div>
-->
<div class="news">
<br class="mobile"><br class="mobile">
<br class="tablet"><br class="tablet">
<h1 style="margin-bottom:2%">Aktuelle Neuigkeiten</h1>
<br>
<div class="twittercol1">
<a class="twitter-timeline" data-tweet-limit="1" href="https://twitter.com/kubernetesio?ref_src=twsrc%5Etfw">Tweets von kubernetesio</a> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</div>
<br>
<br><br><br><br>
</div>
</div>
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
+2
View File
@@ -50,6 +50,8 @@ Bevor Sie die einzelnen Lernprogramme durchgehen, möchten Sie möglicherweise e
* [AppArmor](/docs/tutorials/clusters/apparmor/)
* [seccomp](/docs/tutorials/clusters/seccomp/)
## Services
* [Source IP verwenden](/docs/tutorials/services/source-ip/)
@@ -5,7 +5,7 @@ weight: 20
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 20
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 10
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 20
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 10
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 20
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
@@ -5,7 +5,7 @@ weight: 10
<!DOCTYPE html>
<html lang="en">
<html lang="de">
<body>
+201
View File
@@ -0,0 +1,201 @@
/* SECTIONS */
.section {
clear: both;
padding: 0px;
margin-bottom: 2em;
}
.kcsp_section {
clear: both;
padding: 0px;
margin-bottom: 2em;
}
/* COLUMN SETUP */
.col {
display: block;
float:left;
margin: 1% 0 1% 1.6%;
background-color: #f9f9f9;
}
.col:first-child { margin-left: 0; }
/* GROUPING */
.group:before,
.group:after {
content:"";
display:table;
}
.group:after {
clear:both;
}
.group {
zoom:1; /* For IE 6/7 */
}
/* GRID OF THREE */
.span_3_of_3 {
width: 35%;
background-color: #f9f9f9;
padding: 20px;
}
.span_2_of_3 {
width: 35%;
background-color: #f9f9f9;
padding: 20px;
}
.span_1_of_3 {
width: 35%;
background-color: #f9f9f9;
padding: 20px;
}
.col-container {
display: table; /* Make the container element behave like a table */
width: 100%; /* Set full-width to expand the whole page */
padding-bottom: 30px;
}
.col-nav {
display: table-cell; /* Make elements inside the container behave like table cells */
width: 18%;
background-color: #f9f9f9;
padding: 20px;
border: 5px solid white;
}
/* GO FULL WIDTH AT LESS THAN 480 PIXELS */
@media only screen and (max-width: 480px) {
.col { margin: 1% 0 1% 0%;}
.span_3_of_3, .span_2_of_3, .span_1_of_3 { width: 100%; }
}
@media only screen and (max-width: 650px) {
.col-nav {
display: block;
width: 100%;
}
}
.button{
max-width: 100%;
box-sizing: border-box;
margin: 0;
display: inline-block;
border-radius: 6px;
padding: 0 20px;
line-height: 40px;
color: #ffffff;
font-size: 16px;
background-color: #3371e3;
text-decoration: none;
}
h5 {
font-size: 16px;
line-height: 1.5em;
margin-bottom: 2em;
}
#usersGrid a {
display: inline-block;
background-color: #f9f9f9;
}
#ktpContainer, #distContainer, #kcspContainer, #isvContainer, #servContainer {
position: relative;
width: 100%;
display: flex;
justify-content: space-between;
flex-wrap: wrap;
}
#isvContainer {
margin-bottom: 80px;
}
#kcspContainer {
margin-bottom: 80px;
}
#distContainer {
margin-bottom: 80px;
}
#ktpContainer {
margin-bottom: 80px;
}
.partner-box {
position: relative;
width: 47%;
max-width: 48%;
min-width: 48%;
margin-bottom: 20px;
padding: 20px;
flex: 1;
display: flex;
justify-content: left;
align-items: flex-start;
}
.partner-box img {
background-color: #f9f9f9;
}
.partner-box > div {
margin-left: 30px;
}
.partner-box a {
color: #3576E3;
}
@media screen and (max-width: 1024px) {
.partner-box {
flex-direction: column;
justify-content: flex-start;
}
.partner-box > div {
margin: 20px 0 0;
}
}
@media screen and (max-width: 568px) {
#ktpContainer, #distContainter, #kcspContainer, #isvContainer, #servContainer {
justify-content: center;
}
.partner-box {
flex-direction: column;
justify-content: flex-start;
width: 100%;
max-width: 100%;
min-width: 100%;
}
.partner-box > div {
margin: 20px 0 0;
}
}
@media screen and (max-width: 568px) {
#ktpContainer, #distContainer, #kcspContainer, #isvContainer, #servContainer {
justify-content: center;
}
.partner-box {
flex-direction: column;
justify-content: flex-start;
width: 100%;
max-width: 100%;
min-width: 100%;
}
.partner-box > div {
margin: 20px 0 0;
}
}
+40 -78
View File
@@ -1,91 +1,53 @@
---
title: Partner
bigheader: Kubernetes Partner
abstract: Entwicklung des Kubernetes-Ökosystems.
abstract: Erweiterung des Kubernetes-Ökosystems.
class: gridPage
cid: partners
---
<section id="users">
<main>
<h5>Kubernetes arbeitet mit Partnern zusammen, um eine starke, dynamische Codebasis zu schaffen, die ein Spektrum von aufeinander abgestimmten Plattformen unterstützt.</h5>
<div class="col-container">
<div class="col-nav">
<center>
<h5>
<b>Kubernetes zertifizierte Service Provider</b>
</h5>
<br>Geprüfte Service Provider mit großer Erfahrung, die Unternehmen bei der erfolgreichen Einführung von Kubernetes unterstützen.
<br><br><br>
<button id="kcsp" class="button" onClick="updateSrc(this.id)">KCSP-Partner anzeigen</button>
<br><br>Interessiert daran, ein <a href="https://www.cncf.io/certification/kcsp/">KCSP</a> zu werden?
</center>
</div>
<div class="col-nav">
<center>
<h5>
<b>Kubernetes-Distributionen, gehostete Plattformen und zertifizierte Installateure</b>
</h5>Software-Konformität stellt sicher, dass die Kubernetes-Versionen aller Hersteller die erforderlichen APIs unterstützen.
<br><br><br>
<button id="conformance" class="button" onClick="updateSrc(this.id)">Zertifizierte Partner anzeigen</button>
<br><br>Interessiert daran, <a href="https://www.cncf.io/certification/software-conformance/">Kubernetes zertifiziert</a> zu werden?
</center>
</div>
<div class="col-nav">
<center>
<h5><b>Kubernetes Training Partner</b></h5>
<br>Geprüfte Schulungsanbieter, die über umfassende Erfahrung in Cloud Native Technologietrainings verfügen.
<br><br><br><br>
<button id="ktp" class="button" onClick="updateSrc(this.id)">KTP Partner anzeigen</button>
<br><br>Interessiert daran, ein <a href="https://www.cncf.io/certification/training/">KTP</a> zu werden?
</center>
</div>
</div>
<script src="https://code.jquery.com/jquery-3.3.1.min.js" integrity="sha256-FgpCb/KJQlLNfOu91ta32o/NMZxltwRo8QtmkMRdAu8=" crossorigin="anonymous"></script>
<script type="text/javascript">
var defaultLink = "https://landscape.cncf.io/category=kubernetes-certified-service-provider&format=card-mode&grouping=category&embed=yes";
var firstLink = "https://landscape.cncf.io/category=certified-kubernetes-distribution,certified-kubernetes-hosted,certified-kubernetes-installer&format=card-mode&grouping=category&embed=yes";
var secondLink = "https://landscape.cncf.io/category=kubernetes-training-partner&format=card-mode&grouping=category&embed=yes";
function updateSrc(buttonId) {
if (buttonId == "kcsp") {
$("#landscape").attr("src",defaultLink);
window.location.hash = "#kcsp";
}
if (buttonId == "conformance") {
$("#landscape").attr("src",firstLink);
window.location.hash = "#conformance";
}
if (buttonId == "ktp") {
$("#landscape").attr("src",secondLink);
window.location.hash = "#ktp";
}
}
// Automatically load the correct iframe based on the URL fragment
document.addEventListener('DOMContentLoaded', function() {
var showContent = "kcsp";
if (window.location.hash) {
console.log('hash is:', window.location.hash.substring(1));
showContent = window.location.hash.substring(1);
}
updateSrc(showContent);
});
</script>
<body>
<div id="frameHolder">
<iframe id="landscape" frameBorder="0" scrolling="no" style="width: 1px; min-width: 100%" src=""></iframe>
<script src="https://landscape.cncf.io/iframeResizer.js"></script>
<h5>Kubernetes arbeitet mit Partnern zusammen, um eine starke, lebendige Codebasis zu schaffen, die ein Spektrum von ergänzenden Plattformen unterstützt.</h5>
<div class="col-container">
<div class="col-nav">
<center>
<h5>
<b>Kubernetes-zertifizierte Service-Anbieter</b>
</h5>
<br>Geprüfte Dienstleister mit umfassender Erfahrung bei der erfolgreichen Einführung von Kubernetes in Unternehmen.
<br><br><br>
<button class="button landscape-trigger landscape-default" data-landscape-types="kubernetes-certified-service-provider" id="kcsp">KCSP Partner anzeigen</button>
<br><br>Interessiert daran, ein
<a href="https://www.cncf.io/certification/kcsp/">KCSP</a> zu werden?
</center>
</div>
<div class="col-nav">
<center>
<h5>
<b>Zertifizierte Kubernetes-Distributionen, gehostete Plattformen und Installationssysteme</b>
</h5>Die Softwarekonformität stellt sicher, dass die Kubernetes-Version eines jeden Anbieters die erforderlichen APIs unterstützt.
<br><br><br>
<button class="button landscape-trigger" data-landscape-types="certified-kubernetes-distribution,certified-kubernetes-hosted,certified-kubernetes-installer" id="conformance">Konforme Partner anzeigen</button>
<br><br>Interessiert daran,
<a href="https://www.cncf.io/certification/software-conformance/">Kubernetes Zertifiziert</a> zu werden?
</center>
</div>
<div class="col-nav">
<center>
<h5>
<b>Kubernetes Schulungspartner</b>
</h5>
<br>Geprüfte Schulungsanbieter mit umfassender Erfahrung in der Weiterbildung im Bereich Cloud Native Technology.
<br><br><br>
<button class="button landscape-trigger" data-landscape-types="kubernetes-training-partner" id="ktp">KTP Partner anzeigen</button>
<br><br>Interessiert daran, ein
<a href="https://www.cncf.io/certification/training/">KTP</a> zu werden?
</center>
</div>
</div>
</body>
</main>
{{< cncf-landscape helpers=true >}}
</section>
<style>
{{< include "partner-style.css" >}}
</style>
<script>
{{< include "partner-script.js" >}}
</script>
</style>
+137
View File
@@ -0,0 +1,137 @@
---
title: Schulungen
bigheader: Kubernetes Schulungen und Zertifizierungen
abstract: Schulungsprogramme, Zertifizierungen und Partner.
layout: basic
cid: training
class: training
---
<section class="call-to-action">
<div class="main-section">
<div class="call-to-action" id="cta-certification">
<div class="cta-text">
<h2>Gestalte deine Cloud Native Karriere</h2>
<p>Kubernetes ist das Herzstück der Cloud Native-Bewegung. Mit den Schulungen und Zertifizierungen der Linux Foundation und unserer Schulungspartner kannst Du in deine Karriere investieren, Kubernetes lernen und deine Cloud Native-Projekte zum Erfolg führen.</p>
</div>
<div class="logo-certification cta-image" id="logo-kcnf">
<img src="/images/training/kubernetes-kcnf-white.svg" />
</div>
<div class="logo-certification cta-image" id="logo-cka">
<img src="/images/training/kubernetes-cka-white.svg"/>
</div>
<div class="logo-certification cta-image" id="logo-ckad">
<img src="/images/training/kubernetes-ckad-white.svg"/>
</div>
<div class="logo-certification cta-image" id="logo-cks">
<img src="/images/training/kubernetes-cks-white.svg"/>
</div>
</div>
</div>
</section>
<section>
<div class="main-section padded">
<center>
<h2>Nimm an einen kostenlosen Kurs bei edX teil</h2>
</center>
<div class="col-container">
<div class="col-nav">
<center>
<h5>
<b>Einf&uuml;hrung in Kubernetes <br> &nbsp;</b>
</h5>
<p>M&ouml;chtest Du Kubernetes lernen? Erfahre alles über dieses leistungsstarke System zur Verwaltung von Containeranwendungen.</p>
<br>
<a href="https://www.edx.org/course/introduction-to-kubernetes" target="_blank" class="button">Zum Kurs</a>
</center>
</div>
<div class="col-nav">
<center>
<h5>
<b>Einführung in Cloud-Infrastruktur Technologien</b>
</h5>
<p>Lerne die Grundlagen für den Aufbau und die Verwaltung von Cloud-Technologien direkt von der Linux Foundation, dem Marktführer im Bereich Open Source.</p>
<br>
<a href="https://www.edx.org/course/introduction-to-cloud-infrastructure-technologies" target="_blank" class="button">Zum Kurs</a>
</center>
</div>
<div class="col-nav">
<center>
<h5>
<b>Einf&uuml;hrung in Linux</b>
</h5>
<p>Du hast nie Linux gelernt? Willst du eine Auffrischung? Erarbeite dir gute Linux-Kenntnisse über die grafische Oberfläche und die Kommandozeile der wichtigsten Linux-Distributionen.</p>
<br>
<a href="https://www.edx.org/course/introduction-to-linux" target="_blank" class="button">Zum Kurs</a>
</center>
</div>
</div>
</section>
<div class="padded lighter-gray-bg">
<div class="main-section two-thirds-centered">
<center>
<h2>Mit der Linux Foundation lernen</h2>
<p>Die Linux Foundation bietet Kurse für alle Aspekte der Entwicklung und des Betriebs von Kubernetes-Anwendungen an, die entweder von Lehrkräften geleitet werden oder zum Selbststudium geeignet sind.</p>
<br/><br/>
<a href="https://training.linuxfoundation.org/training/course-catalog/?_sft_technology=kubernetes" target="_blank" class="button">Kurse anzeigen</a>
</center>
</div>
</div>
<section id="get-certified">
<div class="main-section padded">
<h2>Werde Kubernetes zertifiziert</h2>
<div class="col-container">
<div class="col-nav">
<h5>
<b>Kubernetes and Cloud Native Associate (KCNA)</b>
</h5>
<p>Die Prüfung zum Kubernetes and Cloud Native Associate (KCNA) weist die grundlegenden Kenntnisse und Fähigkeiten eines Benutzers in Kubernetes und dem breiteren Cloud Native-Ökosystem nach.</p>
<p>Ein zertifizierter KCNA bestätigt konzeptionelles Wissen über das gesamte Cloud Native Ecosystem, mit besonderem Fokus auf Kubernetes.</p>
<br>
<a href="https://training.linuxfoundation.org/certification/kubernetes-cloud-native-associate/" target="_blank" class="button">Zur Zertifizierung</a>
</div>
<div class="col-nav">
<h5>
<b>Certified Kubernetes Application Developer (CKAD)</b>
</h5>
<p>Die Prüfung zum Certified Kubernetes Application Developer (Zertifizierter Kubernetes-Anwendungsentwickler) bescheinigt, dass Teilnehmer Cloud Native-Anwendungen für Kubernetes entwerfen, erstellen, konfigurieren und bereitstellen können.</p>
<p>Ein CKAD kann Anwendungsressourcen definieren und zentrale Elemente verwenden, um skalierbare Anwendungen und Tools in Kubernetes zu erstellen, zu überwachen und Fehler zu beheben.</p>
<br>
<a href="https://training.linuxfoundation.org/certification/certified-kubernetes-application-developer-ckad/" target="_blank" class="button">Zur Zertifizierung</a>
</div>
<div class="col-nav">
<h5>
<b>Certified Kubernetes Administrator (CKA)</b>
</h5>
<p>Das Certified Kubernetes Administrator (CKA)-Programm garantiert, dass CKAs die Fähigkeiten, das Wissen und die Kompetenz besitzen, um die Aufgaben eines Kubernetes-Administrators zu erfüllen.</p>
<p>Ein zertifizierter Kubernetes-Administrator hat nachgewiesen, dass er in der Lage ist, grundlegende Installationen durchzuführen sowie Kubernetes-Cluster in einer Produktionsumgebung zu konfigurieren und zu verwalten.</p>
<br>
<a href="https://training.linuxfoundation.org/certification/certified-kubernetes-administrator-cka/" target="_blank" class="button">Zur Zertifizierung</a>
</div>
<div class="col-nav">
<h5>
<b>Certified Kubernetes Security Specialist (CKS)</b>
</h5>
<p>Das Programm Certified Kubernetes Security Specialist (CKS) bietet die Gewissheit, dass der Zertifikatsinhaber mit einem breiten Spektrum an Best Practices vertraut ist und diese beherrscht. Die CKS-Zertifizierung umfasst Fähigkeiten zur Sicherung von Container-basierten Anwendungen und Kubernetes-Plattformen während der Erstellung, Bereitstellung und Laufzeit.</p>
<p><em>Kandidaten für den CKS müssen über eine aktuelle Zertifizierung als Certified Kubernetes Administrator (CKA) verfügen, um nachzuweisen, dass sie über ausreichende Kubernetes-Kenntnisse verfügen, bevor sie sich für den CKS anmelden.</em></p>
<br>
<a href="https://training.linuxfoundation.org/certification/certified-kubernetes-security-specialist/" target="_blank" class="button">Zur Zertifizierung</a>
</div>
</div>
</div>
</section>
<div class="padded lighter-gray-bg">
<div class="main-section two-thirds-centered">
<center>
<h2>Kubernetes Schulungspartner</h2>
<p>Unser Netzwerk von Kubernetes-Schulungspartnern bietet Schulungsangebote für Kubernetes- und Cloud Native-Projekte.</p>
</center>
</div>
<div class="main-section landscape-section">
{{< cncf-landscape helpers=false category="kubernetes-training-partner" >}}
</div>
</div>
+5 -5
View File
@@ -43,12 +43,12 @@ Kubernetes is open source giving you the freedom to take advantage of on-premise
<button id="desktopShowVideoButton" onclick="kub.showVideo()">Watch Video</button>
<br>
<br>
<a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/?utm_source=kubernetes.io&utm_medium=nav&utm_campaign=kccncna21" button id="desktopKCButton">Attend KubeCon North America on October 11-15, 2021</a>
<br>
<br>
<br>
<br>
<a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-europe-2022/?utm_source=kubernetes.io&utm_medium=nav&utm_campaign=kccnceu22" button id="desktopKCButton">Attend KubeCon Europe on May 17-20, 2022</a>
<br>
<br>
<br>
<br>
<a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/?utm_source=kubernetes.io&utm_medium=nav&utm_campaign=kccncna21" button id="desktopKCButton">Attend KubeCon North America on October 24-28, 2022</a>
</div>
<div id="videoPlayer">
<iframe data-url="https://www.youtube.com/embed/H06qrNmGqyE?autoplay=1" frameborder="0" allowfullscreen></iframe>
@@ -125,7 +125,7 @@ You may wish to, but you cannot create a hierarchy of namespaces. Namespaces can
Namespaces are easy to create and use but its also easy to deploy code inadvertently into the wrong namespace. Good DevOps hygiene suggests documenting and automating processes where possible and this will help. The other way to avoid using the wrong namespace is to set a [kubectl context](/docs/user-guide/kubectl/kubectl_config_set-context/).&nbsp;
Namespaces are easy to create and use but its also easy to deploy code inadvertently into the wrong namespace. Good DevOps hygiene suggests documenting and automating processes where possible and this will help. The other way to avoid using the wrong namespace is to set a [kubectl context](/docs/reference/generated/kubectl/kubectl-commands#-em-set-context-em-).&nbsp;
@@ -5,6 +5,11 @@ slug: visualize-kubelet-performance-with-node-dashboard
url: /blog/2016/11/Visualize-Kubelet-Performance-With-Node-Dashboard
---
_Since this article was published, the Node Performance Dashboard was retired and is no longer available._
_This retirement happened in early 2019, as part of the_ `kubernetes/contrib`
_[repository deprecation](https://github.com/kubernetes-retired/contrib/issues/3007)_.
In Kubernetes 1.4, we introduced a new node performance analysis tool, called the _node performance dashboard_, to visualize and explore the behavior of the Kubelet in much richer details. This new feature will make it easy to understand and improve code performance for Kubelet developers, and lets cluster maintainer set configuration according to provided Service Level Objectives (SLOs).
**Background**
@@ -37,7 +37,7 @@ If you run your storage application on high-end hardware or extra-large instance
[ZooKeeper](https://zookeeper.apache.org/doc/current/) is an interesting use case for StatefulSet for two reasons. First, it demonstrates that StatefulSet can be used to run a distributed, strongly consistent storage application on Kubernetes. Second, it's a prerequisite for running workloads like [Apache Hadoop](http://hadoop.apache.org/) and [Apache Kakfa](https://kafka.apache.org/) on Kubernetes. An [in-depth tutorial](/docs/tutorials/stateful-application/zookeeper/) on deploying a ZooKeeper ensemble on Kubernetes is available in the Kubernetes documentation, and well outline a few of the key features below.
**Creating a ZooKeeper Ensemble**
Creating an ensemble is as simple as using [kubectl create](/docs/user-guide/kubectl/kubectl_create/) to generate the objects stored in the manifest.
Creating an ensemble is as simple as using [kubectl create](/docs/reference/generated/kubectl/kubectl-commands#create) to generate the objects stored in the manifest.
```
@@ -297,7 +297,7 @@ zk-0 0/1 Terminating 0 15m
You can use [kubectl apply](/docs/user-guide/kubectl/kubectl_apply/) to recreate the zk StatefulSet and redeploy the ensemble.
You can use [kubectl apply](/docs/reference/generated/kubectl/kubectl-commands#apply) to recreate the zk StatefulSet and redeploy the ensemble.
@@ -144,10 +144,9 @@ ways to address it.
- Specifically add an iptables rule to drop the packets that are marked as
*INVALID*, so it wont reach to client pod and cause harm.
The fix is drafted (https://github.com/kubernetes/kubernetes/pull/74840), but
unfortunately it didnt catch the v1.14 release window. However, for the users
that are affected by this bug, there is a way to mitigate the problem by applying
the following rule in your cluster.
The [fix](https://github.com/kubernetes/kubernetes/pull/74840) is available in v1.15+.
However, for the users that are affected by this bug, there is a way to mitigate the
problem by applying the following rule in your cluster.
```yaml
apiVersion: extensions/v1beta1
@@ -29,7 +29,7 @@ They join continuing members Christoph Blecker ([@cblecker](https://github.com/c
* Josh Berkus ([@jberkus](https://github.com/jberkus)), Red Hat
* Thanks to the Emeritus Steering Committee Members. Your prior service is appreciated by the community:
* Aaron Crickenberger ([@spiffxp](https://github.com/spiffxp)), Google
* and Lachlan Evenson([@lachie8e)](https://github.com/lachie8e)), Microsoft
* and Lachlan Evenson([@lachie83)](https://github.com/lachie83)), Microsoft
* And thank you to all the candidates who came forward to run for election. As [Jorge Castro put it](https://twitter.com/castrojo/status/1315718627639820288?s=20): we are spoiled with capable, kind, and selfless volunteers who put the needs of the project first.
## Get Involved with the Steering Committee
@@ -28,7 +28,7 @@ as cgroups v2 and user namespaces are being implemented in these newer CRI
runtimes. Removing support for the dockershim will allow further development in
those areas.
[drkep]: https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/1985-remove-dockershim
[drkep]: https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2221-remove-dockershim
### Can I still use Docker in Kubernetes 1.20?
@@ -42,9 +42,11 @@ startup if using Docker as the runtime.
Given the impact of this change, we are using an extended deprecation timeline.
It will not be removed before Kubernetes 1.22, meaning the earliest release without
dockershim would be 1.23 in late 2021. We will be working closely with vendors
and other ecosystem groups to ensure a smooth transition and will evaluate things
as the situation evolves.
dockershim would be 1.23 in late 2021.
_Update_: removal of dockershim is scheduled for Kubernetes v1.24, see
[Dockershim Removal Kubernetes Enhancement Proposal][drkep].
We will be working closely with vendors and other ecosystem groups to ensure a smooth transition and will evaluate
things as the situation evolves.
### Can I still use dockershim after it is removed from Kubernetes?
@@ -190,9 +190,9 @@ kubectl get configmap
No resources found in default namespace.
```
To sum things up, when there's an override owner reference from a child to a parent, deleting the parent deletes the children automatically. This is called `cascade`. The default for cascade is `true`, however, you can use the --cascade=false option for `kubectl delete` to delete an object and orphan its children.
To sum things up, when there's an override owner reference from a child to a parent, deleting the parent deletes the children automatically. This is called `cascade`. The default for cascade is `true`, however, you can use the --cascade=orphan option for `kubectl delete` to delete an object and orphan its children.
In the following example, there is a parent and a child. Notice the owner references are still included. If I delete the parent using --cascade=false, the parent is deleted but the child still exists:
In the following example, there is a parent and a child. Notice the owner references are still included. If I delete the parent using --cascade=orphan, the parent is deleted but the child still exists:
```
kubectl get configmap
@@ -200,7 +200,7 @@ NAME DATA AGE
mymap-child 0 13m8s
mymap-parent 0 13m8s
kubectl delete --cascade=false configmap/mymap-parent
kubectl delete --cascade=orphan configmap/mymap-parent
configmap "mymap-parent" deleted
kubectl get configmap
@@ -19,8 +19,9 @@ is that they have been superseded by a newer, stable (“GA”) API.
Kubernetes 1.22, due for release in August 2021, will remove a number of deprecated
APIs.
[Kubernetes 1.22 Release Information](https://www.kubernetes.dev/resources/release/)
has details on the schedule for the v1.22 release.
_Update_:
[Kubernetes 1.22: Reaching New Peaks](/blog/2021/08/04/kubernetes-1-22-release-announcement/)
has details on the v1.22 release.
## API removals for Kubernetes v1.22 {#api-changes}
@@ -54,7 +54,7 @@ An alpha feature for default seccomp profiles has been added to the kubelet, alo
A new alpha feature allows running the `kubeadm` control plane components as non-root users. This is a long requested security measure in `kubeadm`. To try it you must enable the `kubeadm` specific RootlessControlPlane feature gate. When you deploy a cluster using this alpha feature, your control plane runs with lower privileges.
For `kubeadm`, Kubernetes 1.22 also brings a new [v1beta3 configuration API](https://github.com/kubernetes/kubeadm/issues/1796). This iteration adds some long requested features and deprecates some existing ones. The v1beta3 version is now the preferred API version; the v1beta2 API also remains available and is not yet deprecated.
For `kubeadm`, Kubernetes 1.22 also brings a new [v1beta3 configuration API](/docs/reference/config-api/kubeadm-config.v1beta3/). This iteration adds some long requested features and deprecates some existing ones. The v1beta3 version is now the preferred API version; the v1beta2 API also remains available and is not yet deprecated.
## Major Changes
@@ -140,7 +140,7 @@ In the v1.22 release cycle, which ran for 15 weeks (April 26 to August 4), we sa
# Upcoming release webinar
Join members of the Kubernetes 1.22 release team on September 7, 2021 to learn about the major features of this release, as well as deprecations and removals to help plan for upgrades. For more information and registration, visit the [event page](https://community.cncf.io/events/details/cncf-cncf-online-programs-presents-cncf-live-webinar-kubernetes-122-release/) on the CNCF Online Programs site.
Join members of the Kubernetes 1.22 release team on October 5, 2021 to learn about the major features of this release, as well as deprecations and removals to help plan for upgrades. For more information and registration, visit the [event page](https://community.cncf.io/events/details/cncf-cncf-online-programs-presents-cncf-live-webinar-kubernetes-122-release/) on the CNCF Online Programs site.
# Get Involved
@@ -0,0 +1,177 @@
---
layout: blog
title: "Kubernetes 1.22: Server Side Apply moves to GA"
date: 2021-08-06
slug: server-side-apply-ga
---
**Authors:** Jeffrey Ying, Google & Joe Betz, Google
Server-side Apply (SSA) has been promoted to GA in the Kubernetes v1.22 release. The GA milestone means you can depend on the feature and its API, without fear of future backwards-incompatible changes. GA features are protected by the Kubernetes [deprecation policy](/docs/reference/using-api/deprecation-policy/).
## What is Server-side Apply?
Server-side Apply helps users and controllers manage their resources through declarative configurations. Server-side Apply replaces the client side apply feature implemented by “kubectl apply” with a server-side implementation, permitting use by tools/clients other than kubectl. Server-side Apply is a new merging algorithm, as well as tracking of field ownership, running on the Kubernetes api-server. Server-side Apply enables new features like conflict detection, so the system knows when two actors are trying to edit the same field. Refer to the [Server-side Apply Documentation](/docs/reference/using-api/server-side-apply/) and [Beta 2 release announcement](https://kubernetes.io/blog/2020/04/01/kubernetes-1.18-feature-server-side-apply-beta-2/) for more information.
## Whats new since Beta?
Since the [Beta 2 release](https://kubernetes.io/blog/2020/04/01/kubernetes-1.18-feature-server-side-apply-beta-2/) subresources support has been added, and both client-go and Kubebuilder have added comprehensive support for Server-side Apply. This completes the Server-side Apply functionality required to make controller development practical.
### Support for subresources
Server-side Apply now fully supports subresources like `status` and `scale`. This is particularly important for [controllers](/docs/concepts/architecture/controller/), which are often responsible for writing to subresources.
## Server-side Apply support in client-go
Previously, Server-side Apply could only be called from the client-go typed client using the `Patch` function, with `PatchType` set to `ApplyPatchType`. Now, `Apply` functions are included in the client to allow for a more direct and typesafe way of calling Server-side Apply. Each `Apply` function takes an "apply configuration" type as an argument, which is a structured representation of an Apply request. For example:
```go
import (
...
v1ac "k8s.io/client-go/applyconfigurations/autoscaling/v1"
)
hpaApplyConfig := v1ac.HorizontalPodAutoscaler(autoscalerName, ns).
WithSpec(v1ac.HorizontalPodAutoscalerSpec().
WithMinReplicas(0)
)
return hpav1client.Apply(ctx, hpaApplyConfig, metav1.ApplyOptions{FieldManager: "mycontroller", Force: true})
```
Note in this example that `HorizontalPodAutoscaler` is imported from an "applyconfigurations" package. Each "apply configuration" type represents the same Kubernetes object kind as the corresponding go struct, but where all fields are pointers to make them optional, allowing apply requests to be accurately represented. For example, when the apply configuration in the above example is marshalled to YAML, it produces:
```yaml
apiVersion: autoscaling/v1
kind: HorizontalPodAutoscaler
metadata:
name: myHPA
namespace: myNamespace
spec:
minReplicas: 0
```
To understand why this is needed, the above YAML cannot be produced by the v1.HorizontalPodAutoscaler go struct. Take for example:
```go
hpa := v1.HorizontalPodAutoscaler{
TypeMeta: metav1.TypeMeta{
APIVersion: "autoscaling/v1",
Kind: "HorizontalPodAutoscaler",
},
ObjectMeta: ObjectMeta{
Namespace: ns,
Name: autoscalerName,
},
Spec: v1.HorizontalPodAutoscalerSpec{
MinReplicas: pointer.Int32Ptr(0),
},
}
```
The above code attempts to declare the same apply configuration as shown in the previous examples, but when marshalled to YAML, produces:
```yaml
kind: HorizontalPodAutoscaler
apiVersion: autoscaling/v1
metadata
name: myHPA
namespace: myNamespace
creationTimestamp: null
spec:
scaleTargetRef:
kind: ""
name: ""
minReplicas: 0
maxReplicas: 0
```
Which, among other things, contains `spec.maxReplicas` set to `0`. This is almost certainly not what the caller intended (the intended apply configuration says nothing about the `maxReplicas` field), and could have serious consequences on a production system: it directs the autoscaler to downscale to zero pods. The problem here originates from the fact that the go structs contain required fields that are zero valued if not set explicitly. The go structs work as intended for create and update operations, but are fundamentally incompatible with apply, which is why we have introduced the generated "apply configuration" types.
The "apply configurations" also have convenience `With<FieldName>` functions that make it easier to build apply requests. This allows developers to set fields without having to deal with the fact that all the fields in the "apply configuration" types are pointers, and are inconvenient to set using go. For example `MinReplicas: &0` is not legal go code, so without the `With` functions, developers would work around this problem by using a library, e.g. `MinReplicas: pointer.Int32Ptr(0)`, but string enumerations like `corev1.Protocol` are still a problem since they cannot be supported by a general purpose library. In addition to the convenience, the `With` functions also isolate developers from the underlying representation, which makes it safer for the underlying representation to be changed to support additional features in the future.
## Using Server-side Apply in a controller
You can use the new support for Server-side Apply no matter how you implemented your controller. However, the new client-go support makes it easier to use Server-side Apply in controllers.
When authoring new controllers to use Server-side Apply, a good approach is to have the controller recreate the apply configuration for an object each time it reconciles that object. This ensures that the controller fully reconciles all the fields that it is responsible for. Controllers typically should unconditionally set all the fields they own by setting `Force: true` in the `ApplyOptions`. Controllers must also provide a `FieldManager` name that is unique to the reconciliation loop that apply is called from.
When upgrading existing controllers to use Server-side Apply the same approach often works well--migrate the controllers to recreate the apply configuration each time it reconciles any object. Unfortunately, the controller might have multiple code paths that update different parts of an object depending on various conditions. Migrating a controller like this to Server-side Apply can be risky because if the controller forgets to include any fields in an apply configuration that is included in a previous apply request, a field can be accidently deleted. To ease this type of migration, client-go apply support provides a way to replace any controller reconciliation code that performs a "read/modify-in-place/update" (or patch) workflow with a "extract/modify-in-place/apply" workflow. Here's an example of the new workflow:
```go
fieldMgr := "my-field-manager"
deploymentClient := clientset.AppsV1().Deployments("default")
// read, could also be read from a shared informer
deployment, err := deploymentClient.Get(ctx, "example-deployment", metav1.GetOptions{})
if err != nil {
// handle error
}
// extract
deploymentApplyConfig, err := appsv1ac.ExtractDeployment(deployment, fieldMgr)
if err != nil {
// handle error
}
// modify-in-place
deploymentApplyConfig.Spec.Template.Spec.WithContainers(corev1ac.Container().
WithName("modify-slice").
WithImage("nginx:1.14.2"),
)
// apply
applied, err := deploymentClient.Apply(ctx, deploymentApplyConfig, metav1.ApplyOptions{FieldManager: fieldMgr})
```
For developers using Custom Resource Definitions (CRDs), the Kubebuilder apply support will provide the same capabilities. Documentation will be included in the Kubebuilder book when available.
## Server-side Apply and CustomResourceDefinitions
It is strongly recommended that all [Custom Resource Definitions](/docs/concepts/extend-kubernetes/api-extension/custom-resources/) (CRDs) have a schema. CRDs without a schema are treated as unstructured data by Server-side Apply. Keys are treated as fields in a struct and lists are assumed to be atomic.
CRDs that specify a schema are able to specify additional annotations in the schema. Please refer to the documentation on the full list of available annotations.
New annotations since beta:
**Defaulting:** Values for fields that appliers do not express explicit interest in should be defaulted. This prevents an applier from unintentionally owning a defaulted field that might cause conflicts with other appliers. If unspecified, the default value is nil or the nil equivalent for the corresponding type.
- Usage: see the [CRD Defaulting](/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definitions/#defaulting) documentation for more details.
- Golang: `+default=<value>`
- OpenAPI extension: `default: <value>`
Atomic for maps and structs:
**Maps:** By default maps are granular. A different manager is able to manage each map entry. They can also be configured to be atomic such that a single manager owns the entire map.
- Usage: Refer to [Merge Strategy](/docs/reference/using-api/server-side-apply/#merge-strategy) for a more detailed overview
- Golang: `+mapType=granular/atomic`
- OpenAPI extension: `x-kubernetes-map-type: granular/atomic`
**Structs:** By default structs are granular and a separate applier may own each field. For certain kinds of structs, atomicity may be desired. This is most commonly seen in small coordinate-like structs such as Field/Object/Namespace Selectors, Object References, RGB values, Endpoints (Protocol/Port pairs), etc.
- Usage: Refer to [Merge Strategy](/docs/reference/using-api/server-side-apply/#merge-strategy) for a more detailed overview
- Golang: `+structType=granular/atomic`
- OpenAPI extension: `x-kubernetes-map-type:atomic/granular`
## What's Next?
After Server Side Apply, the next focus for the API Expression working-group is around improving the expressiveness and size of the published Kubernetes API schema. To see the full list of items we are working on, please join our working group and refer to the work items document.
## How to get involved?
The working-group for apply is [wg-api-expression](https://github.com/kubernetes/community/tree/master/wg-api-expression). It is available on slack [#wg-api-expression](https://kubernetes.slack.com/archives/C0123CNN8F3), through the [mailing list](https://groups.google.com/g/kubernetes-wg-api-expression) and we also meet every other Tuesday at 9.30 PT on Zoom.
We would also like to use the opportunity to thank the hard work of all the contributors involved in making this promotion to GA possible:
- Andrea Nodari
- Antoine Pelisse
- Daniel Smith
- Jeffrey Ying
- Jenny Buckley
- Joe Betz
- Julian Modesto
- Kevin Delgado
- Kevin Wiesmüller
- Maria Ntalla
@@ -0,0 +1,142 @@
---
layout: blog
title: 'New in Kubernetes v1.22: alpha support for using swap memory'
date: 2021-08-09
slug: run-nodes-with-swap-alpha
---
**Author:** Elana Hashman (Red Hat)
The 1.22 release introduced alpha support for configuring swap memory usage for
Kubernetes workloads on a per-node basis.
In prior releases, Kubernetes did not support the use of swap memory on Linux,
as it is difficult to provide guarantees and account for pod memory utilization
when swap is involved. As part of Kubernetes' earlier design, swap support was
considered out of scope, and a kubelet would by default fail to start if swap
was detected on a node.
However, there are a number of [use cases](https://github.com/kubernetes/enhancements/blob/9d127347773ad19894ca488ee04f1cd3af5774fc/keps/sig-node/2400-node-swap/README.md#user-stories)
that would benefit from Kubernetes nodes supporting swap, including improved
node stability, better support for applications with high memory overhead but
smaller working sets, the use of memory-constrained devices, and memory
flexibility.
Hence, over the past two releases, [SIG Node](https://github.com/kubernetes/community/tree/master/sig-node#readme) has
been working to gather appropriate use cases and feedback, and propose a design
for adding swap support to nodes in a controlled, predictable manner so that
Kubernetes users can perform testing and provide data to continue building
cluster capabilities on top of swap. The alpha graduation of swap memory
support for nodes is our first milestone towards this goal!
## How does it work?
There are a number of possible ways that one could envision swap use on a node.
To keep the scope manageable for this initial implementation, when swap is
already provisioned and available on a node, [we have proposed](https://github.com/kubernetes/enhancements/blob/9d127347773ad19894ca488ee04f1cd3af5774fc/keps/sig-node/2400-node-swap/README.md#proposal)
the kubelet should be able to be configured such that:
- It can start with swap on.
- It will direct the Container Runtime Interface to allocate zero swap memory
to Kubernetes workloads by default.
- You can configure the kubelet to specify swap utilization for the entire
node.
Swap configuration on a node is exposed to a cluster admin via the
[`memorySwap` in the KubeletConfiguration](/docs/reference/config-api/kubelet-config.v1beta1/).
As a cluster administrator, you can specify the node's behaviour in the
presence of swap memory by setting `memorySwap.swapBehavior`.
This is possible through the addition of a `memory_swap_limit_in_bytes` field
to the container runtime interface (CRI). The kubelet's config will control how
much swap memory the kubelet instructs the container runtime to allocate to
each container via the CRI. The container runtime will then write the swap
settings to the container level cgroup.
## How do I use it?
On a node where swap memory is already provisioned, Kubernetes use of swap on a
node can be enabled by enabling the `NodeSwap` feature gate on the kubelet, and
disabling the `failSwapOn` [configuration setting](/docs/reference/config-api/kubelet-config.v1beta1/#kubelet-config-k8s-io-v1beta1-KubeletConfiguration)
or the `--fail-swap-on` command line flag.
You can also optionally configure `memorySwap.swapBehavior` in order to
specify how a node will use swap memory. For example,
```yaml
memorySwap:
swapBehavior: LimitedSwap
```
The available configuration options for `swapBehavior` are:
- `LimitedSwap` (default): Kubernetes workloads are limited in how much swap
they can use. Workloads on the node not managed by Kubernetes can still swap.
- `UnlimitedSwap`: Kubernetes workloads can use as much swap memory as they
request, up to the system limit.
If configuration for `memorySwap` is not specified and the feature gate is
enabled, by default the kubelet will apply the same behaviour as the
`LimitedSwap` setting.
The behaviour of the `LimitedSwap` setting depends if the node is running with
v1 or v2 of control groups (also known as "cgroups"):
- **cgroups v1:** Kubernetes workloads can use any combination of memory and
swap, up to the pod's memory limit, if set.
- **cgroups v2:** Kubernetes workloads cannot use swap memory.
### Caveats
Having swap available on a system reduces predictability. Swap's performance is
worse than regular memory, sometimes by many orders of magnitude, which can
cause unexpected performance regressions. Furthermore, swap changes a system's
behaviour under memory pressure, and applications cannot directly control what
portions of their memory usage are swapped out. Since enabling swap permits
greater memory usage for workloads in Kubernetes that cannot be predictably
accounted for, it also increases the risk of noisy neighbours and unexpected
packing configurations, as the scheduler cannot account for swap memory usage.
The performance of a node with swap memory enabled depends on the underlying
physical storage. When swap memory is in use, performance will be significantly
worse in an I/O operations per second (IOPS) constrained environment, such as a
cloud VM with I/O throttling, when compared to faster storage mediums like
solid-state drives or NVMe.
Hence, we do not recommend the use of swap for certain performance-constrained
workloads or environments. Cluster administrators and developers should
benchmark their nodes and applications before using swap in production
scenarios, and [we need your help](#how-do-i-get-involved) with that!
## Looking ahead
The Kubernetes 1.22 release introduces alpha support for swap memory on nodes,
and we will continue to work towards beta graduation in the 1.23 release. This
will include:
* Adding support for controlling swap consumption at the Pod level via cgroups.
* This will include the ability to set a system-reserved quantity of swap
from what kubelet detects on the host.
* Determining a set of metrics for node QoS in order to evaluate the
performance and stability of nodes with and without swap enabled.
* Collecting feedback from test user cases.
* We will consider introducing new configuration modes for swap, such as a
node-wide swap limit for workloads.
## How can I learn more?
You can review the current [documentation](https://kubernetes.io/docs/concepts/architecture/nodes/#swap-memory)
on the Kubernetes website.
For more information, and to assist with testing and provide feedback, please
see [KEP-2400](https://github.com/kubernetes/enhancements/issues/2400) and its
[design proposal](https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/2400-node-swap/README.md).
## How do I get involved?
Your feedback is always welcome! SIG Node [meets regularly](https://github.com/kubernetes/community/tree/master/sig-node#meetings)
and [can be reached](https://github.com/kubernetes/community/tree/master/sig-node#contact)
via [Slack](https://slack.k8s.io/) (channel **#sig-node**), or the SIG's
[mailing list](https://groups.google.com/forum/#!forum/kubernetes-sig-node).
Feel free to reach out to me, Elana Hashman (**@ehashman** on Slack and GitHub)
if you'd like to help.
@@ -0,0 +1,76 @@
---
layout: blog
title: 'Kubernetes 1.22: CSI Windows Support (with CSI Proxy) reaches GA'
date: 2021-08-09
slug: csi-windows-support-with-csi-proxy-reaches-ga
---
**Authors:** Mauricio Poppe (Google), Jing Xu (Google), and Deep Debroy (Apple)
*The stable version of CSI Proxy for Windows has been released alongside Kubernetes 1.22. CSI Proxy enables CSI Drivers running on Windows nodes to perform privileged storage operations.*
## Background
Container Storage Interface (CSI) for Kubernetes went GA in the Kubernetes 1.13 release. CSI has become the standard for exposing block and file storage to containerized workloads on Container Orchestration systems (COs) like Kubernetes. It enables third-party storage providers to write and deploy plugins without the need to alter the core Kubernetes codebase. Legacy in-tree drivers are deprecated and new storage features are introduced in CSI, therefore it is important to get CSI Drivers to work on Windows.
A CSI Driver in Kubernetes has two main components: a controller plugin which runs in the control plane and a node plugin which runs on every node.
- The controller plugin generally does not need direct access to the host and can perform all its operations through the Kubernetes API and external control plane services.
- The node plugin, however, requires direct access to the host for making block devices and/or file systems available to the Kubernetes kubelet. Due to the missing capability of running privileged operations from containers on Windows nodes [CSI Proxy was introduced as alpha in Kubernetes 1.18](https://kubernetes.io/blog/2020/04/03/kubernetes-1-18-feature-windows-csi-support-alpha/) as a way to enable containers to perform privileged storage operations. This enables containerized CSI Drivers to run on Windows nodes.
## What's CSI Proxy and how do CSI drivers interact with it?
When a workload that uses persistent volumes is scheduled, it'll go through a sequence of steps defined in the [CSI Spec](https://github.com/container-storage-interface/spec/blob/master/spec.md). First, the workload will be scheduled to run on a node. Then the controller component of a CSI Driver will attach the persistent volume to the node. Finally the node component of a CSI Driver will mount the persistent volume on the node.
The node component of a CSI Driver needs to run on Windows nodes to support Windows workloads. Various privileged operations like scanning of disk devices, mounting of file systems, etc. cannot be done from a containerized application running on Windows nodes yet ([Windows HostProcess containers](https://github.com/kubernetes/enhancements/issues/1981) introduced in Kubernetes 1.22 as alpha enable functionalities that require host access like the operations mentioned before). However, we can perform these operations through a binary (CSI Proxy) that's pre-installed on the Window nodes. CSI Proxy has a client-server architecture and allows CSI drivers to issue privileged storage operations through a gRPC interface exposed over named pipes created during the startup of CSI Proxy.
![CSI Proxy Architecture](/images/blog/2021-08-09-csi-windows-support-with-csi-proxy-reaches-ga/csi-proxy.png)
## CSI Proxy reaches GA
The CSI Proxy development team has worked closely with storage vendors, many of whom started integrating CSI Proxy into their CSI Drivers and provided feedback as early as CSI Proxy design proposal. This cooperation uncovered use cases where additional APIs were needed, found bugs, and identified areas for documentation improvement.
The CSI Proxy design [KEP](https://github.com/kubernetes/enhancements/pull/2737) has been updated to reflect the current CSI Proxy architecture. Additional [development documentation](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/DEVELOPMENT.md) is included for contributors interested in helping with new features or bug fixes.
Before we reached GA we wanted to make sure that our API is simple and consistent. We went through an extensive API review of the v1beta API groups where we made sure that the CSI Proxy API methods and messages are consistent with the naming conventions defined in the [CSI Spec](https://github.com/container-storage-interface/spec/blob/master/spec.md). As part of this effort we're graduating the [Disk](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/apis/disk_v1.md), [Filesystem](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/apis/filesystem_v1.md), [SMB](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/apis/smb_v1.md) and [Volume](https://github.com/kubernetes-csi/csi-proxy/blob/master/docs/apis/volume_v1.md) API groups to v1.
Additional Windows system APIs to get information from the Windows nodes and support to mount iSCSI targets in Windows nodes, are available as alpha APIs in the [System API](https://github.com/kubernetes-csi/csi-proxy/tree/v1.0.0/client/api/system/v1alpha1) and the [iSCSI API](https://github.com/kubernetes-csi/csi-proxy/tree/v1.0.0/client/api/iscsi/v1alpha2). These APIs will continue to be improved before we graduate them to v1.
CSI Proxy v1 is compatible with all the previous v1betaX releases. The GA `csi-proxy.exe` binary can handle requests from v1betaX clients thanks to the autogenerated conversion layer that transforms any versioned client request to a version-agnostic request that the server can process. Several [integration tests](https://github.com/kubernetes-csi/csi-proxy/tree/v1.0.0/integrationtests) were added for all the API versions of the API groups that are graduating to v1 to ensure that CSI Proxy is backwards compatible.
Version drift between CSI Proxy and the CSI Drivers that interact with it was also carefully considered. A [connection fallback mechanism](https://github.com/kubernetes-csi/csi-proxy/pull/124) has been provided for CSI Drivers to handle multiple versions of CSI Proxy for a smooth upgrade to v1. This allows CSI Drivers, like the GCE PD CSI Driver, [to recognize which version of the CSI Proxy binary is running](https://github.com/kubernetes-sigs/gcp-compute-persistent-disk-csi-driver/pull/738) and handle multiple versions of the CSI Proxy binary deployed on the node.
CSI Proxy v1 is already being used by many CSI Drivers, including the [AWS EBS CSI Driver](https://github.com/kubernetes-sigs/aws-ebs-csi-driver/pull/966), [Azure Disk CSI Driver](https://github.com/kubernetes-sigs/azuredisk-csi-driver/pull/919), [GCE PD CSI Driver](https://github.com/kubernetes-sigs/gcp-compute-persistent-disk-csi-driver/pull/738), and [SMB CSI Driver](https://github.com/kubernetes-csi/csi-driver-smb/pull/319).
## Future plans
We're very excited for the future of CSI Proxy. With the upcoming [Windows HostProcess containers](https://github.com/kubernetes/enhancements/issues/1981), we are considering converting the CSI Proxy in to a library consumed by CSI Drivers in addition to the current client/server design. This will allow us to iterate faster on new features because the `csi-proxy.exe` binary will no longer be needed.
## How to get involved?
This project, like all of Kubernetes, is the result of hard work by many contributors from diverse backgrounds working together. Those interested in getting involved with the design and development of CSI Proxy, or any part of the Kubernetes Storage system, may join the Kubernetes Storage Special Interest Group (SIG). Were rapidly growing and always welcome new contributors.
For those interested in more details about CSI support in Windows please reach out in the [#csi-windows](https://kubernetes.slack.com/messages/csi-windows) Kubernetes slack channel.
## Acknowledgments
CSI-Proxy received many contributions from members of the Kubernetes community. We thank all of the people that contributed to CSI Proxy with design reviews, bug reports, bug fixes, and for their continuous support in reaching this milestone:
- [Andy Zhang](https://github.com/andyzhangx)
- [Dan Ilan](https://github.com/jmpfar)
- [Deep Debroy](https://github.com/ddebroy)
- [Humble Devassy Chirammal](https://github.com/humblec)
- [Jing Xu](https://github.com/jingxu97)
- [Jean Rougé](https://github.com/wk8)
- [Jordan Liggitt](https://github.com/liggitt)
- [Kalya Subramanian](https://github.com/ksubrmnn)
- [Krishnakumar R](https://github.com/kkmsft)
- [Manuel Tellez](https://github.com/manueltellez)
- [Mark Rossetti](https://github.com/marosset)
- [Mauricio Poppe](https://github.com/mauriciopoppe)
- [Matthew Wong](https://github.com/wongma7)
- [Michelle Au](https://github.com/msau42)
- [Patrick Lang](https://github.com/PatrickLang)
- [Saad Ali](https://github.com/saad-ali)
- [Yuju Hong](https://github.com/yujuhong)
@@ -0,0 +1,144 @@
---
layout: blog
title: "Kubernetes Memory Manager moves to beta"
date: 2021-08-11
slug: kubernetes-1-22-feature-memory-manager-moves-to-beta
---
**Authors:** Artyom Lukianov (Red Hat), Cezary Zukowski (Samsung)
The blog post explains some of the internals of the _Memory manager_, a beta feature
of Kubernetes 1.22. In Kubernetes, the Memory Manager is a
[kubelet](https://kubernetes.io/docs/concepts/overview/components/#kubelet) subcomponent.
The memory manage provides guaranteed memory (and hugepages)
allocation for pods in the `Guaranteed` [QoS class](https://kubernetes.io/docs/tasks/configure-pod-container/quality-service-pod/#qos-classes).
This blog post covers:
1. [Why do you need it?](#Why-do-you-need-it?)
2. [The internal details of how the **MemoryManager** works](#How-does-it-work?)
3. [Current limitations of the **MemoryManager**](#Current-limitations)
4. [Future work for the **MemoryManager**](#Future-work-for-the-Memory-Manager)
## Why do you need it?
Some Kubernetes workloads run on nodes with
[non-uniform memory access](https://en.wikipedia.org/wiki/Non-uniform_memory_access) (NUMA).
Suppose you have NUMA nodes in your cluster. In that case, you'll know about the potential for extra latency when
compute resources need to access memory on the different NUMA locality.
To get the best performance and latency for your workload, container CPUs,
peripheral devices, and memory should all be aligned to the same NUMA
locality.
Before Kubernetes v1.22, the kubelet already provided a set of managers to
align CPUs and PCI devices, but you did not have a way to align memory.
The Linux kernel was able to make best-effort attempts to allocate
memory for tasks from the same NUMA node where the container is
executing are placed, but without any guarantee about that placement.
## How does it work?
The memory manager is doing two main things:
- provides the topology hint to the Topology Manager
- allocates the memory for containers and updates the state
The overall sequence of the Memory Manager under the Kubelet
![MemoryManagerDiagram](/images/blog/2021-08-11-memory-manager-moves-to-beta/MemoryManagerDiagram.svg "MemoryManagerDiagram")
During the Admission phase:
1. When first handling a new pod, the kubelet calls the TopologyManager's `Admit()` method.
2. The Topology Manager is calling `GetTopologyHints()` for every hint provider including the Memory Manager.
3. The Memory Manager calculates all possible NUMA nodes combinations for every container inside the pod and returns hints to the Topology Manager.
4. The Topology Manager calls to `Allocate()` for every hint provider including the Memory Manager.
5. The Memory Manager allocates the memory under the state according to the hint that the Topology Manager chose.
During Pod creation:
1. The kubelet calls `PreCreateContainer()`.
2. For each container, the Memory Manager looks the NUMA nodes where it allocated the
memory for the container and then returns that information to the kubelet.
3. The kubelet creates the container, via CRI, using a container specification
that incorporates information from the Memory Manager information.
### Let's talk about the configuration
By default, the Memory Manager runs with the `None` policy, meaning it will just
relax and not do anything. To make use of the Memory Manager, you should set
two command line options for the kubelet:
- `--memory-manager-policy=Static`
- `--reserved-memory="<numaNodeID>:<resourceName>=<quantity>"`
The value for `--memory-manager-policy` is straightforward: `Static`. Deciding what to specify for `--reserved-memory` takes more thought. To configure it correctly, you should follow two main rules:
- The amount of reserved memory for the `memory` resource must be greater than zero.
- The amount of reserved memory for the resource type must be equal
to [NodeAllocatable](/docs/tasks/administer-cluster/reserve-compute-resources/#node-allocatable)
(`kube-reserved + system-reserved + eviction-hard`) for the resource.
You can read more about memory reservations in [Reserve Compute Resources for System Daemons](/docs/tasks/administer-cluster/reserve-compute-resources/).
![Reserved memory](/images/blog/2021-08-11-memory-manager-moves-to-beta/ReservedMemory.svg)
## Current limitations
The 1.22 release and promotion to beta brings along enhancements and fixes, but the Memory Manager still has several limitations.
### Single vs Cross NUMA node allocation
The NUMA node can not have both single and cross NUMA node allocations. When the container memory is pinned to two or more NUMA nodes, we can not know from which NUMA node the container will consume the memory.
![Single vs Cross NUMA allocation](/images/blog/2021-08-11-memory-manager-moves-to-beta/SingleCrossNUMAAllocation.svg "SingleCrossNUMAAllocation")
1. The `container1` started on the NUMA node 0 and requests *5Gi* of the memory but currently is consuming only *3Gi* of the memory.
2. For container2 the memory request is 10Gi, and no single NUMA node can satisfy it.
3. The `container2` consumes *3.5Gi* of the memory from the NUMA node 0, but once the `container1` will require more memory, it will not have it, and the kernel will kill one of the containers with the *OOM* error.
To prevent such issues, the Memory Manager will fail the admission of the `container2` until the machine has two NUMA nodes without a single NUMA node allocation.
### Works only for Guaranteed pods
The Memory Manager can not guarantee memory allocation for Burstable pods,
also when the Burstable pod has specified equal memory limit and request.
Let's assume you have two Burstable pods: `pod1` has containers with
equal memory request and limits, and `pod2` has containers only with a
memory request set. You want to guarantee memory allocation for the `pod1`.
To the Linux kernel, processes in either pod have the same *OOM score*,
once the kernel finds that it does not have enough memory, it can kill
processes that belong to pod `pod1`.
### Memory fragmentation
The sequence of Pods and containers that start and stop can fragment the memory on NUMA nodes.
The alpha implementation of the Memory Manager does not have any mechanism to balance pods and defragment memory back.
## Future work for the Memory Manager
We do not want to stop with the current state of the Memory Manager and are looking to
make improvements, including in the following areas.
### Make the Memory Manager allocation algorithm smarter
The current algorithm ignores distances between NUMA nodes during the
calculation of the allocation. If same-node placement isn't available, we can still
provide better performance compared to the current implementation, by changing the
Memory Manager to prefer the closest NUMA nodes for cross-node allocation.
### Reduce the number of admission errors
The default Kubernetes scheduler is not aware of the node's NUMA topology, and it can be a reason for many admission errors during the pod start.
We're hoping to add a KEP (Kubernetes Enhancement Proposal) to cover improvements in this area.
Follow [Topology aware scheduler plugin in kube-scheduler](https://github.com/kubernetes/enhancements/issues/2044) to see how this idea progresses.
## Conclusion
With the promotion of the Memory Manager to beta in 1.22, we encourage everyone to give it a try and look forward to any feedback you may have. While there are still several limitations, we have a set of enhancements planned to address them and look forward to providing you with many new features in upcoming releases.
If you have ideas for additional enhancements or a desire for certain features, please let us know. The team is always open to suggestions to enhance and improve the Memory Manager.
We hope you have found this blog informative and helpful! Let us know if you have any questions or comments.
You can contact us via:
- The Kubernetes [#sig-node ](https://kubernetes.slack.com/messages/sig-node)
channel in Slack (visit https://slack.k8s.io/ for an invitation if you need one)
- The SIG Node mailing list, [kubernetes-sig-node@googlegroups.com](https://groups.google.com/g/kubernetes-sig-node)
Binary file not shown.

After

Width:  |  Height:  |  Size: 71 KiB

@@ -0,0 +1,79 @@
---
layout: blog
title: 'Alpha in v1.22: Windows HostProcess Containers'
date: 2021-08-16
slug: windows-hostprocess-containers
---
**Authors:** Brandon Smith (Microsoft)
Kubernetes v1.22 introduced a new alpha feature for clusters that
include Windows nodes: HostProcess containers.
HostProcess containers aim to extend the Windows container model to enable a wider
range of Kubernetes cluster management scenarios. HostProcess containers run
directly on the host and maintain behavior and access similar to that of a regular
process. With HostProcess containers, users can package and distribute management
operations and functionalities that require host access while retaining versioning
and deployment methods provided by containers. This allows Windows containers to
be used for a variety of device plugin, storage, and networking management scenarios
in Kubernetes. With this comes the enablement of host network mode—allowing
HostProcess containers to be created within the host's network namespace instead of
their own. HostProcess containers can also be built on top of existing Windows server
2019 (or later) base images, managed through the Windows container runtime, and run
as any user that is available on or in the domain of the host machine.
Linux privileged containers are currently used for a variety of key scenarios in
Kubernetes, including kube-proxy (via kubeadm), storage, and networking scenarios.
Support for these scenarios in Windows previously required workarounds via proxies
or other implementations. Using HostProcess containers, cluster operators no longer
need to log onto and individually configure each Windows node for administrative
tasks and management of Windows services. Operators can now utilize the container
model to deploy management logic to as many clusters as needed with ease.
## How does it work?
Windows HostProcess containers are implemented with Windows _Job Objects_, a break from the
previous container model using server silos. Job objects are components of the Windows OS which offer the ability to
manage a group of processes as a group (a.k.a. _jobs_) and assign resource constraints to the
group as a whole. Job objects are specific to the Windows OS and are not associated with the Kubernetes [Job API](https://kubernetes.io/docs/concepts/workloads/controllers/job/). They have no process or file system isolation,
enabling the privileged payload to view and edit the host file system with the
correct permissions, among other host resources. The init process, and any processes
it launches or that are explicitly launched by the user, are all assigned to the
job object of that container. When the init process exits or is signaled to exit,
all the processes in the job will be signaled to exit, the job handle will be
closed and the storage will be unmounted.
HostProcess and Linux privileged containers enable similar scenarios but differ
greatly in their implementation (hence the naming difference). HostProcess containers
have their own pod security policies. Those used to configure Linux privileged
containers **do not** apply. Enabling privileged access to a Windows host is a
fundamentally different process than with Linux so the configuration and
capabilities of each differ significantly. Below is a diagram detailing the
overall architecture of Windows HostProcess containers:
{{< figure src="hostprocess-architecture.png" alt="HostProcess Architecture" >}}
## How do I use it?
HostProcess containers can be run from within a
[HostProcess Pod](/docs/tasks/configure-pod-container/create-hostprocess-pod).
With the feature enabled on Kubernetes version 1.22, a containerd container runtime of
1.5.4 or higher, and the latest version of hcsshim, deploying a pod spec with the
[correct HostProcess configuration](/docs/tasks/configure-pod-container/create-hostprocess-pod/#before-you-begin)
will enable you to run HostProcess containers. To get started with running
Windows containers see the general guidance for [Windows in Kubernetes](/docs/setup/production-environment/windows/)
## How can I learn more?
- Work through [Create a Windows HostProcess Pod](/docs/tasks/configure-pod-container/create-hostprocess-pod/)
- Read about Kubernetes [Pod Security Standards](/docs/concepts/security/pod-security-standards/)
- Read the enhancement proposal [Windows Privileged Containers and Host Networking Mode](https://github.com/kubernetes/enhancements/tree/master/keps/sig-windows/1981-windows-privileged-container-support) (KEP-1981)
## How do I get involved?
HostProcess containers are in active development. SIG Windows welcomes suggestions from the community.
Get involved with [SIG Windows](https://github.com/kubernetes/community/tree/master/sig-windows)
to contribute!
@@ -0,0 +1,267 @@
---
layout: blog
title: "Enable seccomp for all workloads with a new v1.22 alpha feature"
date: 2021-08-25
slug: seccomp-default
---
**Author:** Sascha Grunert, Red Hat
This blog post is about a new Kubernetes feature introduced in v1.22, which adds
an additional security layer on top of the existing seccomp support. Seccomp is
a security mechanism for Linux processes to filter system calls (syscalls) based
on a set of defined rules. Applying seccomp profiles to containerized workloads
is one of the key tasks when it comes to enhancing the security of the
application deployment. Developers, site reliability engineers and
infrastructure administrators have to work hand in hand to create, distribute
and maintain the profiles over the applications life-cycle.
You can use the [`securityContext`][seccontext] field of Pods and their
containers can be used to adjust security related configurations of the
workload. Kubernetes introduced dedicated [seccomp related API
fields][seccontext] in this `SecurityContext` with the [graduation of seccomp to
General Availability (GA)][ga] in v1.19.0. This enhancement allowed an easier
way to specify if the whole pod or a specific container should run as:
[seccontext]: /docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
[ga]: https://kubernetes.io/blog/2020/08/26/kubernetes-release-1.19-accentuate-the-paw-sitive/#graduated-to-stable
- `Unconfined`: seccomp will not be enabled
- `RuntimeDefault`: the container runtimes default profile will be used
- `Localhost`: a node local profile will be applied, which is being referenced
by a relative path to the seccomp profile root (`<kubelet-root-dir>/seccomp`)
of the kubelet
With the graduation of seccomp, nothing has changed from an overall security
perspective, because `Unconfined` is still the default. This is totally fine if
you consider this from the upgrade path and backwards compatibility perspective of
Kubernetes releases. But it also means that it is more likely that a workload
runs without seccomp at all, which should be fixed in the long term.
## `SeccompDefault` to the rescue
Kubernetes v1.22.0 introduces a new kubelet [feature gate][gate]
`SeccompDefault`, which has been added in `alpha` state as every other new
feature. This means that it is disabled by default and can be enabled manually
for every single Kubernetes node.
[gate]: /docs/reference/command-line-tools-reference/feature-gates
What does the feature do? Well, it just changes the default seccomp profile from
`Unconfined` to `RuntimeDefault`. If not specified differently in the pod
manifest, then the feature will add a higher set of security constraints by
using the default profile of the container runtime. These profiles may differ
between runtimes like [CRI-O][crio] or [containerd][ctrd]. They also differ for
its used hardware architectures. But generally speaking, those default profiles
allow a common amount of syscalls while blocking the more dangerous ones, which
are unlikely or unsafe to be used in a containerized application.
[crio]: https://github.com/cri-o/cri-o/blob/fe30d62/vendor/github.com/containers/common/pkg/seccomp/default_linux.go#L45
[ctrd]: https://github.com/containerd/containerd/blob/e1445df/contrib/seccomp/seccomp_default.go#L51
### Enabling the feature
Two kubelet configuration changes have to be made to enable the feature:
1. **Enable the feature** gate by setting the `SeccompDefault=true` via the command
line (`--feature-gates`) or the [kubelet configuration][kubelet] file.
2. **Turn on the feature** by enabling the feature by adding the
`--seccomp-default` command line flag or via the [kubelet
configuration][kubelet] file (`seccompDefault: true`).
[kubelet]: /docs/tasks/administer-cluster/kubelet-config-file
The kubelet will error on startup if only one of the above steps have been done.
### Trying it out
If the feature is enabled on a node, then you can create a new workload like
this:
```yaml
apiVersion: v1
kind: Pod
metadata:
name: test-pod
spec:
containers:
- name: test-container
image: nginx:1.21
```
Now it is possible to inspect the used seccomp profile by using
[`crictl`][crictl] while investigating the containers [runtime
specification][rspec]:
[crictl]: https://github.com/kubernetes-sigs/cri-tools
[rspec]: https://github.com/opencontainers/runtime-spec/blob/0c021c1/config-linux.md#seccomp
```bash
CONTAINER_ID=$(sudo crictl ps -q --name=test-container)
sudo crictl inspect $CONTAINER_ID | jq .info.runtimeSpec.linux.seccomp
```
```yaml
{
"defaultAction": "SCMP_ACT_ERRNO",
"architectures": ["SCMP_ARCH_X86_64", "SCMP_ARCH_X86", "SCMP_ARCH_X32"],
"syscalls": [
{
"names": ["_llseek", "_newselect", "accept", …, "write", "writev"],
"action": "SCMP_ACT_ALLOW"
},
]
}
```
You can see that the lower level container runtime ([CRI-O][crio-home] and
[runc][runc] in our case), successfully applied the default seccomp profile.
This profile denies all syscalls per default, while allowing commonly used ones
like [`accept`][accept] or [`write`][write].
[crio-home]: https://github.com/cri-o/cri-o
[runc]: https://github.com/opencontainers/runc
[accept]: https://man7.org/linux/man-pages/man2/accept.2.html
[write]: https://man7.org/linux/man-pages/man2/write.2.html
Please note that the feature will not influence any Kubernetes API for now.
Therefore, it is not possible to retrieve the used seccomp profile via `kubectl`
`get` or `describe` if the [`SeccompProfile`][api] field is unset within the
`SecurityContext`.
[api]: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
The feature also works when using multiple containers within a pod, for example
if you create a pod like this:
```yaml
apiVersion: v1
kind: Pod
metadata:
name: test-pod
spec:
containers:
- name: test-container-nginx
image: nginx:1.21
securityContext:
seccompProfile:
type: Unconfined
- name: test-container-redis
image: redis:6.2
```
then you should see that the `test-container-nginx` runs without a seccomp profile:
```bash
sudo crictl inspect $(sudo crictl ps -q --name=test-container-nginx) |
jq '.info.runtimeSpec.linux.seccomp == null'
true
```
Whereas the container `test-container-redis` runs with `RuntimeDefault`:
```bash
sudo crictl inspect $(sudo crictl ps -q --name=test-container-redis) |
jq '.info.runtimeSpec.linux.seccomp != null'
true
```
The same applies to the pod itself, which also runs with the default profile:
```bash
sudo crictl inspectp (sudo crictl pods -q --name test-pod) |
jq '.info.runtimeSpec.linux.seccomp != null'
true
```
### Upgrade strategy
It is recommended to enable the feature in multiple steps, whereas different
risks and mitigations exist for each one.
#### Feature gate enabling
Enabling the feature gate at the kubelet level will not turn on the feature, but
will make it possible by using the `SeccompDefault` kubelet configuration or the
`--seccomp-default` CLI flag. This can be done by an administrator for the whole
cluster or only a set of nodes.
#### Testing the Application
If you're trying this within a dedicated test environment, you have to ensure
that the application code does not trigger syscalls blocked by the
`RuntimeDefault` profile before enabling the feature on a node. This can be done
by:
- _Recommended_: Analyzing the code (manually or by running the application with
[strace][strace]) for any executed syscalls which may be blocked by the
default profiles. If that's the case, then you can override the default by
explicitly setting the pod or container to run as `Unconfined`. Alternatively,
you can create a custom seccomp profile (see optional step below).
profile based on the default by adding the additional syscalls to the
`"action": "SCMP_ACT_ALLOW"` section.
- _Recommended_: Manually set the profile to the target workload and use a
rolling upgrade to deploy into production. Rollback the deployment if the
application does not work as intended.
- _Optional_: Run the application against an end-to-end test suite to trigger
all relevant code paths with `RuntimeDefault` enabled. If a test fails, use
the same mitigation as mentioned above.
- _Optional_: Create a custom seccomp profile based on the default and change
its default action from `SCMP_ACT_ERRNO` to `SCMP_ACT_LOG`. This means that
the seccomp filter for unknown syscalls will have no effect on the application
at all, but the system logs will now indicate which syscalls may be blocked.
This requires at least a Kernel version 4.14 as well as a recent [runc][runc]
release. Monitor the application hosts audit logs (defaults to
`/var/log/audit/audit.log`) or syslog entries (defaults to `/var/log/syslog`)
for syscalls via `type=SECCOMP` (for audit) or `type=1326` (for syslog).
Compare the syscall ID with those [listed in the Linux Kernel
sources][syscalls] and add them to the custom profile. Be aware that custom
audit policies may lead into missing syscalls, depending on the configuration
of auditd.
- _Optional_: Use cluster additions like the [Security Profiles Operator][spo]
for profiling the application via its [log enrichment][logs] capabilities or
recording a profile by using its [recording feature][rec]. This makes the
above mentioned manual log investigation obsolete.
[syscalls]: https://github.com/torvalds/linux/blob/7bb7f2a/arch/x86/entry/syscalls/syscall_64.tbl
[spo]: https://github.com/kubernetes-sigs/security-profiles-operator
[logs]: https://github.com/kubernetes-sigs/security-profiles-operator/blob/c90ef3a/installation-usage.md#record-profiles-from-workloads-with-profilerecordings
[rec]: https://github.com/kubernetes-sigs/security-profiles-operator/blob/c90ef3a/installation-usage.md#using-the-log-enricher
[strace]: https://man7.org/linux/man-pages/man1/strace.1.html
#### Deploying the modified application
Based on the outcome of the application tests, it may be required to change the
application deployment by either specifying `Unconfined` or a custom seccomp
profile. This is not the case if the application works as intended with
`RuntimeDefault`.
#### Enable the kubelet configuration
If everything went well, then the feature is ready to be enabled by the kubelet
configuration or its corresponding CLI flag. This should be done on a per-node
basis to reduce the overall risk of missing a syscall during the investigations
when running the application tests. If it's possible to monitor audit logs
within the cluster, then it's recommended to do this for eventually missed
seccomp events. If the application works as intended then the feature can be
enabled for further nodes within the cluster.
## Conclusion
Thank you for reading this blog post! I hope you enjoyed to see how the usage of
seccomp profiles has been evolved in Kubernetes over the past releases as much
as I do. On your own cluster, change the default seccomp profile to
`RuntimeDefault` (using this new feature) and see the security benefits, and, of
course, feel free to reach out any time for feedback or questions.
---
_Editor's note: If you have any questions or feedback about this blog post, feel
free to reach out via the [Kubernetes slack in #sig-node][slack]._
[slack]: https://kubernetes.slack.com/messages/sig-node
@@ -0,0 +1,48 @@
---
layout: blog
title: 'Minimum Ready Seconds for StatefulSets'
date: 2021-08-27
slug: minreadyseconds-statefulsets
---
**Authors:** Ravi Gudimetla (Red Hat), Maciej Szulik (Red Hat)
This blog describes the notion of Availability for `StatefulSet` workloads, and a new alpha feature in Kubernetes 1.22 which adds `minReadySeconds` configuration for `StatefulSets`.
## What problems does this solve?
Prior to Kubernetes 1.22 release, once a `StatefulSet` `Pod` is in the `Ready` state it is considered `Available` to receive traffic. For some of the `StatefulSet` workloads, it may not be the case. For example, a workload like Prometheus with multiple instances of Alertmanager, it should be considered `Available` only when Alertmanager's state transfer is complete, not when the `Pod` is in `Ready` state. Since `minReadySeconds` adds buffer, the state transfer may be complete before the `Pod` becomes `Available`. While this is not a fool proof way of identifying if the state transfer is complete or not, it gives a way to the end user to express their intention of waiting for sometime before the `Pod` is considered `Available` and it is ready to serve requests.
Another case, where `minReadySeconds` helps is when using `LoadBalancer` `Services` with cloud providers. Since `minReadySeconds` adds latency after a `Pod` is `Ready`, it provides buffer time to prevent killing pods in rotation before new pods show up. Imagine a load balancer in unhappy path taking 10-15s to propagate. If you have 2 replicas then, you'd kill the second replica only after the first one is up but in reality, first replica cannot be seen because it is not yet ready to serve requests.
So, in general, the notion of `Availability` in `StatefulSets` is pretty useful and this feature helps in solving the above problems. This is a feature that already exists for `Deployments` and `DaemonSets` and we now have them for `StatefulSets` too to give users consistent workload experience.
## How does it work?
The statefulSet controller watches for both `StatefulSets` and the `Pods` associated with them. When the feature gate associated with this feature is enabled, the statefulSet controller identifies how long a particular `Pod` associated with a `StatefulSet` has been in the `Running` state.
If this value is greater than or equal to the time specified by the end user in `.spec.minReadySeconds` field, the statefulSet controller updates a field called `availableReplicas` in the `StatefulSet`'s status subresource to include this `Pod`. The `status.availableReplicas` in `StatefulSet`'s status is an integer field which tracks the number of pods that are `Available`.
## How do I use it?
You are required to prepare the following things in order to try out the feature:
- Download and install a kubectl greater than v1.22.0 version
- Switch on the feature gate with the command line flag `--feature-gates=StatefulSetMinReadySeconds=true` on `kube-apiserver` and `kube-controller-manager`
After successfully starting `kube-apiserver` and `kube-controller-manager`, you will see `AvailableReplicas` in the status and `minReadySeconds` of spec (with a default value of 0).
Specify a value for `minReadySeconds` for any StatefulSet and you can check if `Pods` are available or not by checking `AvailableReplicas` field using:
`kubectl get statefulset/<name_of_the_statefulset> -o yaml`
## How can I learn more?
- Read the KEP: [minReadySeconds for StatefulSets](https://github.com/kubernetes/enhancements/tree/master/keps/sig-apps/2599-minreadyseconds-for-statefulsets#readme)
- Read the documentation: [Minimum ready seconds](/docs/concepts/workloads/controllers/statefulset/#minimum-ready-seconds) for StatefulSet
- Review the [API definition](/docs/reference/kubernetes-api/workload-resources/stateful-set-v1/) for StatefulSet
## How do I get involved?
Please reach out to us in the [#sig-apps](https://kubernetes.slack.com/archives/C18NZM5K9) channel on Slack (visit https://slack.k8s.io/ for an invitation if you need one), or on the SIG Apps mailing list: kubernetes-sig-apps@googlegroups.com
@@ -0,0 +1,219 @@
---
layout: blog
title: "Kubernetes 1.22: A New Design for Volume Populators"
date: 2021-08-30
slug: volume-populators-redesigned
---
**Authors:**
Ben Swartzlander (NetApp)
Kubernetes v1.22, released earlier this month, introduced a redesigned approach for volume
populators. Originally implemented
in v1.18, the API suffered from backwards compatibility issues. Kubernetes v1.22 includes a new API
field called `dataSourceRef` that fixes these problems.
## Data sources
Earlier Kubernetes releases already added a `dataSource` field into the
[PersistentVolumeClaim](/docs/concepts/storage/persistent-volumes/#persistentvolumeclaims) API,
used for cloning volumes and creating volumes from snapshots. You could use the `dataSource` field when
creating a new PVC, referencing either an existing PVC or a VolumeSnapshot in the same namespace.
That also modified the normal provisioning process so that instead of yielding an empty volume, the
new PVC contained the same data as either the cloned PVC or the cloned VolumeSnapshot.
Volume populators embrace the same design idea, but extend it to any type of object, as long
as there exists a [custom resource](/docs/concepts/extend-kubernetes/api-extension/custom-resources/)
to define the data source, and a populator controller to implement the logic. Initially,
the `dataSource` field was directly extended to allow arbitrary objects, if the `AnyVolumeDataSource`
feature gate was enabled on a cluster. That change unfortunately caused backwards compatibility
problems, and so the new `dataSourceRef` field was born.
In v1.22 if the `AnyVolumeDataSource` feature gate is enabled, the `dataSourceRef` field is
added, which behaves similarly to the `dataSource` field except that it allows arbitrary
objects to be specified. The API server ensures that the two fields always have the same
contents, and neither of them are mutable. The differences is that at creation time
`dataSource` allows only PVCs or VolumeSnapshots, and ignores all other values, while
`dataSourceRef` allows most types of objects, and in the few cases it doesn't allow an
object (core objects other than PVCs) a validation error occurs.
When this API change graduates to stable, we would deprecate using `dataSource` and recommend
using `dataSourceRef` field for all use cases.
In the v1.22 release, `dataSourceRef` is available (as an alpha feature) specifically for cases
where you want to use for custom volume populators.
## Using populators
Every volume populator must have one or more CRDs that it supports. Administrators may
install the CRD and the populator controller and then PVCs with a `dataSourceRef` specifies
a CR of the type that the populator supports will be handled by the populator controller
instead of the CSI driver directly.
Underneath the covers, the CSI driver is still invoked to create an empty volume, which
the populator controller fills with the appropriate data. The PVC doesn't bind to the PV
until it's fully populated, so it's safe to define a whole application manifest including
pod and PVC specs and the pods won't begin running until everything is ready, just as if
the PVC was a clone of another PVC or VolumeSnapshot.
## How it works
PVCs with data sources are still noticed by the external-provisioner sidecar for the
related storage class (assuming a CSI provisioner is used), but because the sidecar
doesn't understand the data source kind, it doesn't do anything. The populator controller
is also watching for PVCs with data sources of a kind that it understands and when it
sees one, it creates a temporary PVC of the same size, volume mode, storage class,
and even on the same topology (if topology is used) as the original PVC. The populator
controller creates a worker pod that attaches to the volume and writes the necessary
data to it, then detaches from the volume and the populator controller rebinds the PV
from the temporary PVC to the orignal PVC.
## Trying it out
The following things are required to use volume populators:
* Enable the `AnyVolumeDataSource` feature gate
* Install a CRD for the specific data source / populator
* Install the populator controller itself
Populator controllers may use the [lib-volume-populator](https://github.com/kubernetes-csi/lib-volume-populator)
library to do most of the Kubernetes API level work. Individual populators only need to
provide logic for actually writing data into the volume based on a particular CR
instance. This library provides a sample populator implementation.
These optional components improve user experience:
* Install the VolumePopulator CRD
* Create a VolumePopulator custom respource for each specific data source
* Install the [volume data source validator](https://github.com/kubernetes-csi/volume-data-source-validator)
controller (alpha)
The purpose of these components is to generate warning events on PVCs with data sources
for which there is no populator.
## Putting it all together
To see how this works, you can install the sample "hello" populator and try it
out.
First install the volume-data-source-validator controller.
```terminal
kubectl apply -f https://github.com/kubernetes-csi/volume-data-source-validator/blob/master/deploy/kubernetes/rbac-data-source-validator.yaml
kubectl apply -f https://github.com/kubernetes-csi/volume-data-source-validator/blob/master/deploy/kubernetes/setup-data-source-validator.yaml
```
Next install the example populator.
```terminal
kubectl apply -f https://github.com/kubernetes-csi/lib-volume-populator/blob/master/example/hello-populator/crd.yaml
kubectl apply -f https://github.com/kubernetes-csi/lib-volume-populator/blob/master/example/hello-populator/deploy.yaml
```
Create an instance of the `Hello` CR, with some text.
```yaml
apiVersion: hello.k8s.io/v1alpha1
kind: Hello
metadata:
name: example-hello
spec:
fileName: example.txt
fileContents: Hello, world!
```
Create a PVC that refers to that CR as its data source.
```yaml
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: example-pvc
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 10Mi
dataSourceRef:
apiGroup: hello.k8s.io
kind: Hello
name: example-hello
volumeMode: Filesystem
```
Next, run a job that reads the file in the PVC.
```yaml
apiVersion: batch/v1
kind: Job
metadata:
name: example-job
spec:
template:
spec:
containers:
- name: example-container
image: busybox:latest
command:
- cat
- /mnt/example.txt
volumeMounts:
- name: vol
mountPath: /mnt
restartPolicy: Never
volumes:
- name: vol
persistentVolumeClaim:
claimName: example-pvc
```
Wait for the job to complete (including all of its dependencies).
```terminal
kubectl wait --for=condition=Complete job/example-job
```
And last examine the log from the job.
```terminal
kubectl logs job/example-job
Hello, world!
```
Note that the volume already contained a text file with the string contents from
the CR. This is only the simplest example. Actual populators can set up the volume
to contain arbitrary contents.
## How to write your own volume populator
Developers interested in writing new poplators are encouraged to use the
[lib-volume-populator](https://github.com/kubernetes-csi/lib-volume-populator) library
and to only supply a small controller wrapper around the library, and a pod image
capable of attaching to volumes and writing the appropriate data to the volume.
Individual populators can be extremely generic such that they work with every type
of PVC, or they can do vendor specific things to rapidly fill a volume with data
if the volume was provisioned by a specific CSI driver from the same vendor, for
example, by communicating directly with the storage for that volume.
## The future
As this feature is still in alpha, we expect to update the out of tree controllers
with more tests and documentation. The community plans to eventually re-implement
the populator library as a sidecar, for ease of operations.
We hope to see some official community-supported populators for some widely-shared
use cases. Also, we expect that volume populators will be used by backup vendors
as a way to "restore" backups to volumes, and possibly a standardized API to do
this will evolve.
## How can I learn more?
The enhancement proposal,
[Volume Populators](https://github.com/kubernetes/enhancements/tree/master/keps/sig-storage/1495-volume-populators), includes lots of detail about the history and technical implementation
of this feature.
[Volume populators and data sources](/docs/concepts/storage/persistent-volumes/#volume-populators-and-data-sources), within the documentation topic about persistent volumes,
explains how to use this feature in your cluster.
Please get involved by joining the Kubernetes storage SIG to help us enhance this
feature. There are a lot of good ideas already and we'd be thrilled to have more!
@@ -0,0 +1,67 @@
---
layout: blog
title: 'Alpha in Kubernetes v1.22: API Server Tracing'
date: 2021-09-03
slug: api-server-tracing
---
**Authors:** David Ashpole (Google)
In distributed systems, it can be hard to figure out where problems are. You grep through one component's logs just to discover that the source of your problem is in another component. You search there only to discover that you need to enable debug logs to figure out what really went wrong... And it goes on. The more complex the path your request takes, the harder it is to answer questions about where it went. I've personally spent many hours doing this dance with a variety of Kubernetes components. Distributed tracing is a tool which is designed to help in these situations, and the Kubernetes API Server is, perhaps, the most important Kubernetes component to be able to debug. At Kubernetes' Sig Instrumentation, our mission is to make it easier to understand what's going on in your cluster, and we are happy to announce that distributed tracing in the Kubernetes API Server reached alpha in 1.22.
## What is Tracing?
Distributed tracing links together a bunch of super-detailed information from multiple different sources, and structures that telemetry into a single tree for that request. Unlike logging, which limits the quantity of data ingested by using log levels, tracing collects all of the details and uses sampling to collect only a small percentage of requests. This means that once you have a trace which demonstrates an issue, you should have all the information you need to root-cause the problem--no grepping for object UID required! My favorite aspect, though, is how useful the visualizations of traces are. Even if you don't understand the inner workings of the API Server, or don't have a clue what an etcd "Transaction" is, I'd wager you (yes, you!) could tell me roughly what the order of events was, and which components were involved in the request. If some step takes a long time, it is easy to tell where the problem is.
## Why OpenTelemetry?
It's important that Kubernetes works well for everyone, regardless of who manages your infrastructure, or which vendors you choose to integrate with. That is particularly true for Kubernetes' integrations with telemetry solutions. OpenTelemetry, being a CNCF project, shares these core values, and is creating exactly what we need in Kubernetes: A set of open standards for Tracing client library APIs and a standard trace format. By using OpenTelemetry, we can ensure users have the freedom to choose their backend, and ensure vendors have a level playing field. The timing couldn't be better: the OpenTelemetry golang API and SDK are very close to their 1.0 release, and will soon offer backwards-compatibility for these open standards.
## Why instrument the API Server?
The Kubernetes API Server is a great candidate for tracing for a few reasons:
* It follows the standard "RPC" model (serve a request by making requests to downstream components), which makes it easy to instrument.
* Users are latency-sensitive: If a request takes more than 10 seconds to complete, many clients will time-out.
* It has a complex service topology: A single request could require consulting a dozen webhooks, or involve multiple requests to etcd.
## Trying out APIServer Tracing with a webhook
### Enabling API Server Tracing
1. Enable the APIServerTracing [feature-gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/).
2. Set our configuration for tracing by pointing the `--tracing-config-file` flag on the kube-apiserver at our config file, which contains:
```yaml
apiVersion: apiserver.config.k8s.io/v1alpha1
kind: TracingConfiguration
# 1% sampling rate
samplingRatePerMillion: 10000
```
### Enabling Etcd Tracing
Add `--experimental-enable-distributed-tracing`, `--experimental-distributed-tracing-address=0.0.0.0:4317`, `--experimental-distributed-tracing-service-name=etcd` flags to etcd to enable tracing. Note that this traces every request, so it will probably generate a lot of traces if you enable it.
### Example Trace: List Nodes
I could've used any trace backend, but decided to use Jaeger, since it is one of the most popular open-source tracing projects. I deployed [the Jaeger All-in-one container](https://hub.docker.com/r/jaegertracing/all-in-one) in my cluster, deployed [the OpenTelemetry collector](https://github.com/open-telemetry/opentelemetry-collector) on my control-plane node ([example](https://github.com/dashpole/dashpole_demos/tree/master/otel/controlplane)), and captured traces like this one:
![Jaeger screenshot showing API server and etcd trace](/images/blog/2021-09-03-api-server-tracing/example-trace-1.png "Jaeger screenshot showing API server and etcd trace")
The teal lines are from the API Server, and includes it serving a request to `/api/v1/nodes`, and issuing a grpc `Range` RPC to ETCD. The yellow-ish line is from ETCD handling the `Range` RPC.
### Example Trace: Create Pod with Mutating Webhook
I instrumented the [example webhook](https://github.com/kubernetes-sigs/controller-runtime/tree/master/examples/builtins) with OpenTelemetry (I had to [patch](https://github.com/dashpole/controller-runtime/commit/85fdda7ba03dd2c22ef62c1a3dbdf5aa651f90da) controller-runtime, but it makes a neat demo), and routed traces to Jaeger as well. I collected traces like this one:
![Jaeger screenshot showing API server, admission webhook, and etcd trace](/images/blog/2021-09-03-api-server-tracing/example-trace-2.png "Jaeger screenshot showing API server, admission webhook, and etcd trace")
Compared with the previous trace, there are two new spans: A teal span from the API Server making a request to the admission webhook, and a brown span from the admission webhook serving the request. Even if you didn't instrument your webhook, you would still get the span from the API Server making the request to the webhook.
## Get involved!
As this is our first attempt at adding distributed tracing to a Kubernetes component, there is probably a lot we can improve! If my struggles resonated with you, or if you just want to try out the latest Kubernetes has to offer, please give the feature a try and open issues with any problem you encountered and ways you think the feature could be improved.
This is just the very beginning of what we can do with distributed tracing in Kubernetes. If there are other components you think would benefit from distributed tracing, or want to help bring API Server Tracing to GA, join sig-instrumentation at our [regular meetings](https://github.com/kubernetes/community/tree/master/sig-instrumentation#instrumentation-special-interest-group) and get involved!
@@ -0,0 +1,287 @@
---
layout: blog
title: "Introducing Single Pod Access Mode for PersistentVolumes"
date: 2021-09-13
slug: read-write-once-pod-access-mode-alpha
---
**Author:** Chris Henzie (Google)
Last month's release of Kubernetes v1.22 introduced a new ReadWriteOncePod access mode for [PersistentVolumes](/docs/concepts/storage/persistent-volumes/#persistent-volumes) and [PersistentVolumeClaims](/docs/concepts/storage/persistent-volumes/#persistentvolumeclaims).
With this alpha feature, Kubernetes allows you to restrict volume access to a single pod in the cluster.
## What are access modes and why are they important?
When using storage, there are different ways to model how that storage is consumed.
For example, a storage system like a network file share can have many users all reading and writing data simultaneously.
In other cases maybe everyone is allowed to read data but not write it.
For highly sensitive data, maybe only one user is allowed to read and write data but nobody else.
In the world of Kubernetes, [access modes](/docs/concepts/storage/persistent-volumes/#access-modes) are the way you can define how durable storage is consumed.
These access modes are a part of the spec for PersistentVolumes (PVs) and PersistentVolumeClaims (PVCs).
```yaml
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: shared-cache
spec:
accessModes:
- ReadWriteMany # Allow many nodes to access shared-cache simultaneously.
resources:
requests:
storage: 1Gi
```
Before v1.22, Kubernetes offered three access modes for PVs and PVCs:
- ReadWriteOnce &ndash; the volume can be mounted as read-write by a single node
- ReadOnlyMany &ndash; the volume can be mounted read-only by many nodes
- ReadWriteMany &ndash; the volume can be mounted as read-write by many nodes
These access modes are enforced by Kubernetes components like the `kube-controller-manager` and `kubelet` to ensure only certain pods are allowed to access a given PersistentVolume.
## What is this new access mode and how does it work?
Kubernetes v1.22 introduced a fourth access mode for PVs and PVCs, that you can use for CSI volumes:
- ReadWriteOncePod &ndash; the volume can be mounted as read-write by a single pod
If you create a pod with a PVC that uses the ReadWriteOncePod access mode, Kubernetes ensures that pod is the only pod across your whole cluster that can read that PVC or write to it.
If you create another pod that references the same PVC with this access mode, the pod will fail to start because the PVC is already in use by another pod.
For example:
```
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Warning FailedScheduling 1s default-scheduler 0/1 nodes are available: 1 node has pod using PersistentVolumeClaim with the same name and ReadWriteOncePod access mode.
```
### How is this different than the ReadWriteOnce access mode?
The ReadWriteOnce access mode restricts volume access to a single *node*, which means it is possible for multiple pods on the same node to read from and write to the same volume.
This could potentially be a major problem for some applications, especially if they require at most one writer for data safety guarantees.
With ReadWriteOncePod these issues go away.
Set the access mode on your PVC, and Kubernetes guarantees that only a single pod has access.
## How do I use it?
The ReadWriteOncePod access mode is in alpha for Kubernetes v1.22 and is only supported for CSI volumes.
As a first step you need to enable the ReadWriteOncePod [feature gate](/docs/reference/command-line-tools-reference/feature-gates) for `kube-apiserver`, `kube-scheduler`, and `kubelet`.
You can enable the feature by setting command line arguments:
```
--feature-gates="...,ReadWriteOncePod=true"
```
You also need to update the following CSI sidecars to these versions or greater:
- [csi-provisioner:v3.0.0+](https://github.com/kubernetes-csi/external-provisioner/releases/tag/v3.0.0)
- [csi-attacher:v3.3.0+](https://github.com/kubernetes-csi/external-attacher/releases/tag/v3.3.0)
- [csi-resizer:v1.3.0+](https://github.com/kubernetes-csi/external-resizer/releases/tag/v1.3.0)
### Creating a PersistentVolumeClaim
In order to use the ReadWriteOncePod access mode for your PVs and PVCs, you will need to create a new PVC with the access mode:
```yaml
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: single-writer-only
spec:
accessModes:
- ReadWriteOncePod # Allow only a single pod to access single-writer-only.
resources:
requests:
storage: 1Gi
```
If your storage plugin supports [dynamic provisioning](/docs/concepts/storage/dynamic-provisioning/), new PersistentVolumes will be created with the ReadWriteOncePod access mode applied.
#### Migrating existing PersistentVolumes
If you have existing PersistentVolumes, they can be migrated to use ReadWriteOncePod.
In this example, we already have a "cat-pictures-pvc" PersistentVolumeClaim that is bound to a "cat-pictures-pv" PersistentVolume, and a "cat-pictures-writer" Deployment that uses this PersistentVolumeClaim.
As a first step, you need to edit your PersistentVolume's `spec.persistentVolumeReclaimPolicy` and set it to `Retain`.
This ensures your PersistentVolume will not be deleted when we delete the corresponding PersistentVolumeClaim:
```shell
kubectl patch pv cat-pictures-pv -p '{"spec":{"persistentVolumeReclaimPolicy":"Retain"}}'
```
Next you need to stop any workloads that are using the PersistentVolumeClaim bound to the PersistentVolume you want to migrate, and then delete the PersistentVolumeClaim.
Once that is done, you need to clear your PersistentVolume's `spec.claimRef.uid` to ensure PersistentVolumeClaims can bind to it upon recreation:
```shell
kubectl scale --replicas=0 deployment cat-pictures-writer
kubectl delete pvc cat-pictures-pvc
kubectl patch pv cat-pictures-pv -p '{"spec":{"claimRef":{"uid":""}}}'
```
After that you need to replace the PersistentVolume's access modes with ReadWriteOncePod:
```shell
kubectl patch pv cat-pictures-pv -p '{"spec":{"accessModes":["ReadWriteOncePod"]}}'
```
{{< note >}}
The ReadWriteOncePod access mode cannot be combined with other access modes.
Make sure ReadWriteOncePod is the only access mode on the PersistentVolume when updating, otherwise the request will fail.
{{< /note >}}
Next you need to modify your PersistentVolumeClaim to set ReadWriteOncePod as the only access mode.
You should also set your PersistentVolumeClaim's `spec.volumeName` to the name of your PersistentVolume.
Once this is done, you can recreate your PersistentVolumeClaim and start up your workloads:
```shell
# IMPORTANT: Make sure to edit your PVC in cat-pictures-pvc.yaml before applying. You need to:
# - Set ReadWriteOncePod as the only access mode
# - Set spec.volumeName to "cat-pictures-pv"
kubectl apply -f cat-pictures-pvc.yaml
kubectl apply -f cat-pictures-writer-deployment.yaml
```
Lastly you may edit your PersistentVolume's `spec.persistentVolumeReclaimPolicy` and set to it back to `Delete` if you previously changed it.
```shell
kubectl patch pv cat-pictures-pv -p '{"spec":{"persistentVolumeReclaimPolicy":"Delete"}}'
```
You can read [Configure a Pod to Use a PersistentVolume for Storage](/docs/tasks/configure-pod-container/configure-persistent-volume-storage/) for more details on working with PersistentVolumes and PersistentVolumeClaims.
## What volume plugins support this?
The only volume plugins that support this are CSI drivers.
SIG Storage does not plan to support this for in-tree plugins because they are being deprecated as part of [CSI migration](/blog/2019/12/09/kubernetes-1-17-feature-csi-migration-beta/#what-is-the-timeline-status).
Support may be considered for beta for users that prefer to use the legacy in-tree volume APIs with CSI migration enabled.
## As a storage vendor, how do I add support for this access mode to my CSI driver?
The ReadWriteOncePod access mode will work out of the box without any required updates to CSI drivers, but [does require updates to CSI sidecars](#update-your-csi-sidecars).
With that being said, if you would like to stay up to date with the latest changes to the CSI specification (v1.5.0+), read on.
Two new access modes were introduced to the CSI specification in order to disambiguate the legacy [`SINGLE_NODE_WRITER`](https://github.com/container-storage-interface/spec/blob/v1.5.0/csi.proto#L418-L420) access mode.
They are [`SINGLE_NODE_SINGLE_WRITER` and `SINGLE_NODE_MULTI_WRITER`](https://github.com/container-storage-interface/spec/blob/v1.5.0/csi.proto#L437-L447).
In order to communicate to sidecars (like the [external-provisioner](https://github.com/kubernetes-csi/external-provisioner)) that your driver understands and accepts these two new CSI access modes, your driver will also need to advertise the `SINGLE_NODE_MULTI_WRITER` capability for the [controller service](https://github.com/container-storage-interface/spec/blob/v1.5.0/csi.proto#L1073-L1081) and [node service](https://github.com/container-storage-interface/spec/blob/v1.5.0/csi.proto#L1515-L1524).
If you'd like to read up on the motivation for these access modes and capability bits, you can also read the [CSI Specification Changes, Volume Capabilities](https://github.com/kubernetes/enhancements/blob/master/keps/sig-storage/2485-read-write-once-pod-pv-access-mode/README.md#csi-specification-changes-volume-capabilities) section of KEP-2485 (ReadWriteOncePod PersistentVolume Access Mode).
### Update your CSI driver to use the new interface
As a first step you will need to update your driver's `container-storage-interface` dependency to v1.5.0+, which contains support for these new access modes and capabilities.
### Accept new CSI access modes
If your CSI driver contains logic for validating CSI access modes for requests , it may need updating.
If it currently accepts `SINGLE_NODE_WRITER`, it should be updated to also accept `SINGLE_NODE_SINGLE_WRITER` and `SINGLE_NODE_MULTI_WRITER`.
Using the [GCP PD CSI driver validation logic](https://github.com/kubernetes-sigs/gcp-compute-persistent-disk-csi-driver/blob/v1.2.2/pkg/gce-pd-csi-driver/utils.go#L116-L130) as an example, here is how it can be extended:
```diff
diff --git a/pkg/gce-pd-csi-driver/utils.go b/pkg/gce-pd-csi-driver/utils.go
index 281242c..b6c5229 100644
--- a/pkg/gce-pd-csi-driver/utils.go
+++ b/pkg/gce-pd-csi-driver/utils.go
@@ -123,6 +123,8 @@ func validateAccessMode(am *csi.VolumeCapability_AccessMode) error {
case csi.VolumeCapability_AccessMode_SINGLE_NODE_READER_ONLY:
case csi.VolumeCapability_AccessMode_MULTI_NODE_READER_ONLY:
case csi.VolumeCapability_AccessMode_MULTI_NODE_MULTI_WRITER:
+ case csi.VolumeCapability_AccessMode_SINGLE_NODE_SINGLE_WRITER:
+ case csi.VolumeCapability_AccessMode_SINGLE_NODE_MULTI_WRITER:
default:
return fmt.Errorf("%v access mode is not supported for for PD", am.GetMode())
}
```
### Advertise new CSI controller and node service capabilities
Your CSI driver will also need to return the new `SINGLE_NODE_MULTI_WRITER` capability as part of the `ControllerGetCapabilities` and `NodeGetCapabilities` RPCs.
Using the [GCP PD CSI driver capability advertisement logic](https://github.com/kubernetes-sigs/gcp-compute-persistent-disk-csi-driver/blob/v1.2.2/pkg/gce-pd-csi-driver/gce-pd-driver.go#L54-L77) as an example, here is how it can be extended:
```diff
diff --git a/pkg/gce-pd-csi-driver/gce-pd-driver.go b/pkg/gce-pd-csi-driver/gce-pd-driver.go
index 45903f3..0d7ea26 100644
--- a/pkg/gce-pd-csi-driver/gce-pd-driver.go
+++ b/pkg/gce-pd-csi-driver/gce-pd-driver.go
@@ -56,6 +56,8 @@ func (gceDriver *GCEDriver) SetupGCEDriver(name, vendorVersion string, extraVolu
csi.VolumeCapability_AccessMode_SINGLE_NODE_WRITER,
csi.VolumeCapability_AccessMode_MULTI_NODE_READER_ONLY,
csi.VolumeCapability_AccessMode_MULTI_NODE_MULTI_WRITER,
+ csi.VolumeCapability_AccessMode_SINGLE_NODE_SINGLE_WRITER,
+ csi.VolumeCapability_AccessMode_SINGLE_NODE_MULTI_WRITER,
}
gceDriver.AddVolumeCapabilityAccessModes(vcam)
csc := []csi.ControllerServiceCapability_RPC_Type{
@@ -67,12 +69,14 @@ func (gceDriver *GCEDriver) SetupGCEDriver(name, vendorVersion string, extraVolu
csi.ControllerServiceCapability_RPC_EXPAND_VOLUME,
csi.ControllerServiceCapability_RPC_LIST_VOLUMES,
csi.ControllerServiceCapability_RPC_LIST_VOLUMES_PUBLISHED_NODES,
+ csi.ControllerServiceCapability_RPC_SINGLE_NODE_MULTI_WRITER,
}
gceDriver.AddControllerServiceCapabilities(csc)
ns := []csi.NodeServiceCapability_RPC_Type{
csi.NodeServiceCapability_RPC_STAGE_UNSTAGE_VOLUME,
csi.NodeServiceCapability_RPC_EXPAND_VOLUME,
csi.NodeServiceCapability_RPC_GET_VOLUME_STATS,
+ csi.NodeServiceCapability_RPC_SINGLE_NODE_MULTI_WRITER,
}
gceDriver.AddNodeServiceCapabilities(ns)
```
### Implement `NodePublishVolume` behavior
The CSI spec outlines expected behavior for the `NodePublishVolume` RPC when called more than once for the same volume but with different arguments (like the target path).
Please refer to [the second table in the NodePublishVolume section of the CSI spec](https://github.com/container-storage-interface/spec/blob/v1.5.0/spec.md#nodepublishvolume) for more details on expected behavior when implementing in your driver.
### Update your CSI sidecars
When deploying your CSI drivers, you must update the following CSI sidecars to versions that depend on CSI spec v1.5.0+ and the Kubernetes v1.22 API.
The minimum required versions are:
- [csi-provisioner:v3.0.0+](https://github.com/kubernetes-csi/external-provisioner/releases/tag/v3.0.0)
- [csi-attacher:v3.3.0+](https://github.com/kubernetes-csi/external-attacher/releases/tag/v3.3.0)
- [csi-resizer:v1.3.0+](https://github.com/kubernetes-csi/external-resizer/releases/tag/v1.3.0)
## Whats next?
As part of the beta graduation for this feature, SIG Storage plans to update the Kubenetes scheduler to support pod preemption in relation to ReadWriteOncePod storage.
This means if two pods request a PersistentVolumeClaim with ReadWriteOncePod, the pod with highest priority will gain access to the PersistentVolumeClaim and any pod with lower priority will be preempted from the node and be unable to access the PersistentVolumeClaim.
## How can I learn more?
Please see [KEP-2485](https://github.com/kubernetes/enhancements/blob/master/keps/sig-storage/2485-read-write-once-pod-pv-access-mode/README.md) for more details on the ReadWriteOncePod access mode and motivations for CSI spec changes.
## How do I get involved?
The [Kubernetes #csi Slack channel](https://kubernetes.slack.com/messages/csi) and any of the [standard SIG Storage communication channels](https://github.com/kubernetes/community/blob/master/sig-storage/README.md#contact) are great mediums to reach out to the SIG Storage and the CSI teams.
Special thanks to the following people for their insightful reviews and design considerations:
* Abdullah Gharaibeh (ahg-g)
* Aldo Culquicondor (alculquicondor)
* Ben Swartzlander (bswartz)
* Deep Debroy (ddebroy)
* Hemant Kumar (gnufied)
* Humble Devassy Chirammal (humblec)
* James DeFelice (jdef)
* Jan Šafránek (jsafrane)
* Jing Xu (jingxu97)
* Jordan Liggitt (liggitt)
* Michelle Au (msau42)
* Saad Ali (saad-ali)
* Tim Hockin (thockin)
* Xing Yang (xing-yang)
If youre interested in getting involved with the design and development of CSI or any part of the Kubernetes storage system, join the [Kubernetes Storage Special Interest Group](https://github.com/kubernetes/community/tree/master/sig-storage) (SIG).
Were rapidly growing and always welcome new contributors.
@@ -0,0 +1,72 @@
---
layout: blog
title: "Spotlight on SIG Node"
date: 2021-09-27
slug: sig-node-spotlight-2021
---
**Author:** Dewan Ahmed, Red Hat
## Introduction
In Kubernetes, a _Node_ is a representation of a single machine in your cluster. [SIG Node](https://github.com/kubernetes/community/tree/master/sig-node) owns that very important Node component and supports various subprojects such as Kubelet, Container Runtime Interface (CRI) and more to support how the pods and host resources interact. In this blog, we have summarized our conversation with [Elana Hashman (EH)](https://twitter.com/ehashdn) & [Sergey Kanzhelev (SK)](https://twitter.com/SergeyKanzhelev), who walk us through the various aspects of being a part of the SIG and share some insights about how others can get involved.
## A summary of our conversation
### Could you tell us a little about what SIG Node does?
SK: SIG Node is a vertical SIG responsible for the components that support the controlled interactions between the pods and host resources. We manage the lifecycle of pods that are scheduled to a node. This SIG's focus is to enable a broad set of workload types, including workloads with hardware specific or performance sensitive requirements. All while maintaining isolation boundaries between pods on a node, as well as the pod and the host. This SIG maintains quite a few components and has many external dependencies (like container runtimes or operating system features), which makes the complexity we deal with huge. We tame the complexity and aim to continuously improve node reliability.
### "SIG Node is a vertical SIG" could you explain a bit more?
EH: There are two kinds of SIGs: horizontal and vertical. Horizontal SIGs are concerned with a particular function of every component in Kubernetes: for example, SIG Security considers security aspects of every component in Kubernetes, or SIG Instrumentation looks at the logs, metrics, traces and events of every component in Kubernetes. Such SIGs don't tend to own a lot of code.
Vertical SIGs, on the other hand, own a single component, and are responsible for approving and merging patches to that code base. SIG Node owns the "Node" vertical, pertaining to the kubelet and its lifecycle. This includes the code for the kubelet itself, as well as the node controller, the container runtime interface, and related subprojects like the node problem detector.
### How did the CI subproject start? Is this specific to SIG Node and how does it help the SIG?
SK: The subproject started as a follow up after one of the releases was blocked by numerous test failures of critical tests. These tests havent started falling all at once, rather continuous lack of attention led to slow degradation of tests quality. SIG Node was always prioritizing quality and reliability, and forming of the subproject was a way to highlight this priority.
### As the 3rd largest SIG in terms of number of issues and PRs, how does your SIG juggle so much work?
EH: It helps to be organized. When I increased my contributions to the SIG in January of 2021, I found myself overwhelmed by the volume of pull requests and issues and wasn't sure where to start. We were already tracking test-related issues and pull requests on the CI subproject board, but that was missing a lot of our bugfixes and feature work. So I began putting together a triage board for the rest of our pull requests, which allowed me to sort each one by status and what actions to take, and documented its use for other contributors. We closed or merged over 500 issues and pull requests tracked by our two boards in each of the past two releases. The Kubernetes devstats showed that we have significantly increased our velocity as a result.
In June, we ran our first bug scrub event to work through the backlog of issues filed against SIG Node, ensuring they were properly categorized. We closed over 130 issues over the course of this 48 hour global event, but as of writing we still have 333 open issues.
### Why should new and existing contributors consider joining SIG Node?
SK: Being a SIG Node contributor gives you skills and recognition that are rewarding and useful. Understanding under the hood of a kubelet helps architecting better apps, tune and optimize those apps, and gives leg up in issues troubleshooting. If you are a new contributor, SIG Node gives you the foundational knowledge that is key to understanding why other Kubernetes components are designed the way they are. Existing contributors may benefit as many features will require SIG Node changes one way or another. So being a SIG Node contributor helps building features in other SIGs faster.
SIG Node maintains numerous components, many of which have dependency on external projects or OS features. This makes the onboarding process quite lengthy and demanding. But if you are up for a challenge, there is always a place for you, and a group of people to support.
### What do you do to help new contributors get started?
EH: Getting started in SIG Node can be intimidating, since there is so much work to be done, our SIG meetings are very large, and it can be hard to find a place to start.
I always encourage new contributors to work on things that they have some investment in already. In SIG Node, that might mean volunteering to help fix a bug that you have personally been affected by, or helping to triage bugs you care about by priority.
To come up to speed on any open source code base, there are two strategies you can take: start by exploring a particular issue deeply, and follow that to expand the edges of your knowledge as needed, or briefly review as many issues and change requests as you possibly can to get a higher level picture of how the component works. Ultimately, you will need to do both if you want to become a Node reviewer or approver.
[Davanum Srinivas](https://twitter.com/dims) and I each ran a cohort of group mentoring to help teach new contributors the skills to become Node reviewers, and if there's interest we can work to find a mentor to run another session. I also encourage new contributors to attend our Node CI Subproject meeting: it's a smaller audience and we don't record the triage sessions, so it can be a less intimidating way to get started with the SIG.
### Are there any particular skills youd like to recruit for? What skills are contributors to SIG Usability likely to learn?
SK: SIG Node works on many workstreams in very different areas. All of these areas are on system level. For the typical code contributions you need to have a passion for building and utilizing low level APIs and writing performant and reliable components. Being a contributor you will learn how to debug and troubleshoot, profile, and monitor these components, as well as user workload that is run by these components. Often, with the limited to no access to Nodes, as they are running production workloads.
The other way of contribution is to help document SIG node features. This type of contribution requires a deep understanding of features, and ability to explain them in simple terms.
Finally, we are always looking for feedback on how best to run your workload. Come and explain specifics of it, and what features in SIG Node components may help to run it better.
### What are you getting positive feedback on, and whats coming up next for SIG Node?
EH: Over the past year SIG Node has adopted some new processes to help manage our feature development and Kubernetes enhancement proposals, and other SIGs have looked to us for inspiration in managing large workloads. I hope that this is an area we can continue to provide leadership in and further iterate on.
We have a great balance of new features and deprecations in flight right now. Deprecations of unused or difficult to maintain features help us keep technical debt and maintenance load under control, and examples include the dockershim and DynamicKubeletConfiguration deprecations. New features will unlock additional functionality in end users' clusters, and include exciting features like support for cgroups v2, swap memory, graceful node shutdowns, and device management policies.
### Any closing thoughts/resources youd like to share?
SK/EH: It takes time and effort to get to any open source community. SIG Node may overwhelm you at first with the number of participants, volume of work, and project scope. But it is totally worth it. Join our welcoming community! [SIG Node GitHub Repo](https://github.com/kubernetes/community/tree/master/sig-node) contains many useful resources including Slack, mailing list and other contact info.
## Wrap Up
SIG Node hosted a [KubeCon + CloudNativeCon Europe 2021 talk](https://www.youtube.com/watch?v=z5aY4e2RENA) with an intro and deep dive to their awesome SIG. Join the SIG's meetings to find out about the most recent research results, what the plans are for the forthcoming year, and how to get involved in the upstream Node team as a contributor!
@@ -0,0 +1,243 @@
---
layout: blog
title: "How to Handle Data Duplication in Data-Heavy Kubernetes Environments"
date: 2021-09-29
slug: how-to-handle-data-duplication-in-data-heavy-kubernetes-environments
---
**Authors:**
Augustinas Stirbis (CAST AI)
## Why Duplicate Data?
Its convenient to create a copy of your application with a copy of its state for each team.
For example, you might want a separate database copy to test some significant schema changes
or develop other disruptive operations like bulk insert/delete/update...
**Duplicating data takes a lot of time.** Thats because you need first to download
all the data from a source block storage provider to compute and then send
it back to a storage provider again. Theres a lot of network traffic and CPU/RAM used in this process.
Hardware acceleration by offloading certain expensive operations to dedicated hardware is
**always a huge performance boost**. It reduces the time required to complete an operation by orders
of magnitude.
## Volume Snapshots to the rescue
Kubernetes introduced [VolumeSnapshots](/docs/concepts/storage/volume-snapshots/) as alpha in 1.12,
beta in 1.17, and the Generally Available version in 1.20.
VolumeSnapshots use specialized APIs from storage providers to duplicate volume of data.
Since data is already in the same storage device (array of devices), duplicating data is usually
a metadata operation for storage providers with local snapshots (majority of on-premise storage providers).
All you need to do is point a new disk to an immutable snapshot and only
save deltas (or let it do a full-disk copy). As an operation that is inside the storage back-end,
its much quicker and usually doesnt involve sending traffic over the network.
Public Clouds storage providers under the hood work a bit differently. They save snapshots
to Object Storage and then copy back from Object storage to Block storage when "duplicating" disk.
Technically there is a lot of Compute and network resources spent on Cloud providers side,
but from Kubernetes user perspective VolumeSnapshots work the same way whether is it local or
remote snapshot storage provider and no Compute and Network resources are involved in this operation.
## Sounds like we have our solution, right?
Actually, VolumeSnapshots are namespaced, and Kubernetes protects namespaced data from
being shared between tenants (Namespaces). This Kubernetes limitation is a conscious design
decision so that a Pod running in a different namespace cant mount another applications
[PersistentVolumeClaim](/docs/concepts/storage/persistent-volumes/#persistentvolumeclaims) (PVC).
One way around it would be to create multiple volumes with duplicate data in one namespace.
However, you could easily reference the wrong copy.
So the idea is to separate teams/initiatives by namespaces to avoid that and generally
limit access to the production namespace.
## Solution? Creating a Golden Snapshot externally
Another way around this design limitation is to create Snapshot externally (not through Kubernetes).
This is also called pre-provisioning a snapshot manually. Next, I will import it
as a multi-tenant golden snapshot that can be used for many namespaces. Below illustration will be
for AWS EBS (Elastic Block Storage) and GCE PD (Persistent Disk) services.
### High-level plan for preparing the Golden Snapshot
1. Identify Disk (EBS/Persistent Disk) that you want to clone with data in the cloud provider
2. Make a Disk Snapshot (in cloud provider console)
3. Get Disk Snapshot ID
### High-level plan for cloning data for each team
1. Create Namespace “sandbox01”
2. Import Disk Snapshot (ID) as VolumeSnapshotContent to Kubernetes
3. Create VolumeSnapshot in the Namespace "sandbox01" mapped to VolumeSnapshotContent
4. Create the PersistentVolumeClaim from VolumeSnapshot
5. Install Deployment or StatefulSet with PVC
## Step 1: Identify Disk
First, you need to identify your golden source. In my case, its a PostgreSQL database
on PersistentVolumeClaim “postgres-pv-claim” in the “production” namespace.
```terminal
kubectl -n <namespace> get pvc <pvc-name> -o jsonpath='{.spec.volumeName}'
```
The output will look similar to:
```
pvc-3096b3ba-38b6-4fd1-a42f-ec99176ed0d90
```
## Step 2: Prepare your golden source
You need to do this once or every time you want to refresh your golden data.
### Make a Disk Snapshot
Go to AWS EC2 or GCP Compute Engine console and search for an EBS volume
(on AWS) or Persistent Disk (on GCP), that has a label matching the last output.
In this case I saw: `pvc-3096b3ba-38b6-4fd1-a42f-ec99176ed0d9`.
Click on Create snapshot and give it a name. You can do it in Console manually,
in AWS CloudShell / Google Cloud Shell, or in the terminal. To create a snapshot in the
terminal you must have the AWS CLI tool (`aws`) or Google's CLI (`gcloud`)
installed and configured.
Heres the command to create snapshot on GCP:
```terminal
gcloud compute disks snapshot <cloud-disk-id> --project=<gcp-project-id> --snapshot-names=<set-new-snapshot-name> --zone=<availability-zone> --storage-location=<region>
```
{{< figure src="/images/blog/2021-09-07-data-duplication-in-data-heavy-k8s-env/create-volume-snapshot-gcp.png" alt="Screenshot of a terminal showing volume snapshot creation on GCP" title="GCP snapshot creation" >}}
GCP identifies the disk by its PVC name, so its direct mapping. In AWS, you need to
find volume by the CSIVolumeName AWS tag with PVC name value first that will be used for snapshot creation.
{{< figure src="/images/blog/2021-09-07-data-duplication-in-data-heavy-k8s-env/identify-volume-aws.png" alt="Screenshot of AWS web console, showing EBS volume identification" title="Identify disk ID on AWS" >}}
Mark done Volume (volume-id) ```vol-00c7ecd873c6fb3ec``` and ether create EBS snapshot in AWS Console, or use ```aws cli```.
```terminal
aws ec2 create-snapshot --volume-id '<volume-id>' --description '<set-new-snapshot-name>' --tag-specifications 'ResourceType=snapshot'
```
## Step 3: Get your Disk Snapshot ID
In AWS, the command above will output something similar to:
```terminal
"SnapshotId": "snap-09ed24a70bc19bbe4"
```
If youre using the GCP cloud, you can get the snapshot ID from the gcloud command by querying for the snapshots given name:
```terminal
gcloud compute snapshots --project=<gcp-project-id> describe <new-snapshot-name> | grep id:
```
You should get similar output to:
```
id: 6645363163809389170
```
## Step 4: Create a development environment for each team
Now I have my Golden Snapshot, which is immutable data. Each team will get a copy
of this data, and team members can modify it as they see fit, given that a new EBS/persistent
disk will be created for each team.
Below I will define a manifest for each namespace. To save time, you can replace
the namespace name (such as changing “sandbox01” → “sandbox42”) using tools
such as `sed` or `yq`, with Kubernetes-aware templating tools like
[Kustomize](/docs/tasks/manage-kubernetes-objects/kustomization/),
or using variable substitution in a CI/CD pipeline.
Here's an example manifest:
```yaml
---
apiVersion: snapshot.storage.k8s.io/v1
kind: VolumeSnapshotContent
metadata:
name: postgresql-orders-db-sandbox01
namespace: sandbox01
spec:
deletionPolicy: Retain
driver: pd.csi.storage.gke.io
source:
snapshotHandle: 'gcp/projects/staging-eu-castai-vt5hy2/global/snapshots/6645363163809389170'
volumeSnapshotRef:
kind: VolumeSnapshot
name: postgresql-orders-db-snap
namespace: sandbox01
---
apiVersion: snapshot.storage.k8s.io/v1
kind: VolumeSnapshot
metadata:
name: postgresql-orders-db-snap
namespace: sandbox01
spec:
source:
volumeSnapshotContentName: postgresql-orders-db-sandbox01
```
In Kubernetes, VolumeSnapshotContent (VSC) objects are not namespaced.
However, I need a separate VSC for each different namespace to use, so the
`metadata.name` of each VSC must also be different. To make that straightfoward,
I used the target namespace as part of the name.
Now its time to replace the driver field with the CSI (Container Storage Interface) driver
installed in your K8s cluster. Major cloud providers have CSI driver for block storage that
support VolumeSnapshots but quite often CSI drivers are not installed by default, consult
with your Kubernetes provider.
That manifest above defines a VSC that works on GCP.
On AWS, driver and SnashotHandle values might look like:
```YAML
driver: ebs.csi.aws.com
source:
snapshotHandle: "snap-07ff83d328c981c98"
```
At this point, I need to use the *Retain* policy, so that the CSI driver doesnt try to
delete my manually created EBS disk snapshot.
For GCP, you will have to build this string by hand - add a full project ID and snapshot ID.
For AWS, its just a plain snapshot ID.
VSC also requires specifying which VolumeSnapshot (VS) will use it, so VSC and VS are
referencing each other.
Now I can create PersistentVolumeClaim from VS above. Its important to set this first:
```yaml
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: postgres-pv-claim
namespace: sandbox01
spec:
dataSource:
kind: VolumeSnapshot
name: postgresql-orders-db-snap
apiGroup: snapshot.storage.k8s.io
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 21Gi
```
If default StorageClass has [WaitForFirstConsumer](https://kubernetes.io/docs/concepts/storage/storage-classes/#volume-binding-mode) policy,
then the actual Cloud Disk will be created from the Golden Snapshot only when some Pod bounds that PVC.
Now I assign that PVC to my Pod (in my case, its Postgresql) as I would with any other PVC.
```terminal
kubectl -n <namespace> get volumesnapshotContent,volumesnapshot,pvc,pod
```
Both VS and VSC should be *READYTOUSE* true, PVC bound, and the Pod (from Deployment or StatefulSet) running.
**To keep on using data from my Golden Snapshot, I just need to repeat this for the
next namespace and voilà! No need to waste time and compute resources on the duplication process.**
@@ -0,0 +1,417 @@
---
layout: blog
title: A Closer Look at NSA/CISA Kubernetes Hardening Guidance
date: 2021-10-05
slug: nsa-cisa-kubernetes-hardening-guidance
---
**Authors:** Jim Angel (Google), Pushkar Joglekar (VMware), and Savitha
Raghunathan (Red Hat)
{{% alert title="Disclaimer" %}}
The open source tools listed in this article are to serve as examples only
and are in no way a direct recommendation from the Kubernetes community or authors.
{{% /alert %}}
## Background
USA's National Security Agency (NSA) and the Cybersecurity and Infrastructure
Security Agency (CISA)
released, "[Kubernetes Hardening Guidance](https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF)"
on August 3rd, 2021. The guidance details threats to Kubernetes environments
and provides secure configuration guidance to minimize risk.
The following sections of this blog correlate to the sections in the NSA/CISA guidance.
Any missing sections are skipped because of limited opportunities to add
anything new to the existing content.
_Note_: This blog post is not a substitute for reading the guide. Reading the published
guidance is recommended before proceeding as the following content is
complementary.
## Introduction and Threat Model
Note that the threats identified as important by the NSA/CISA, or the intended audience of this guidance, may be different from the threats that other enterprise users of Kubernetes consider important. This section
is still useful for organizations that care about data, resource theft and
service unavailability.
The guidance highlights the following three sources of compromises:
- Supply chain risks
- Malicious threat actors
- Insider threats (administrators, users, or cloud service providers)
The [threat model](https://en.wikipedia.org/wiki/Threat_model) tries to take a step back and review threats that not only
exist within the boundary of a Kubernetes cluster but also include the underlying
infrastructure and surrounding workloads that Kubernetes does not manage.
For example, when a workload outside the cluster shares the same physical
network, it has access to the kubelet and to control plane components: etcd, controller manager, scheduler and API
server. Therefore, the guidance recommends having network level isolation
separating Kubernetes clusters from other workloads that do not need connectivity
to Kubernetes control plane nodes. Specifically, scheduler, controller-manager,
etcd only need to be accessible to the API server. Any interactions with Kubernetes
from outside the cluster can happen by providing access to API server port.
List of ports and protocols for each of these components are
defined in [Ports and Protocols](/docs/reference/ports-and-protocols/)
within the Kubernetes documentation.
> Special note: kube-scheduler and kube-controller-manager uses different ports than the ones mentioned in the guidance
The [Threat modelling](https://cnsmap.netlify.app/threat-modelling) section
from the CNCF [Cloud Native Security Whitepaper + Map](https://github.com/cncf/tag-security/tree/main/security-whitepaper)
provides another perspective on approaching threat modelling Kubernetes, from a
cloud native lens.
## Kubernetes Pod security
Kubernetes by default does not guarantee strict workload isolation between pods
running in the same node in a cluster. However, the guidance provides several
techniques to enhance existing isolation and reduce the attack surface in case of a
compromise.
### "Non-root" containers and "rootless" container engines
Several best practices related to basic security principle of least privilege
i.e. provide only the permissions are needed; no more, no less, are worth a
second look.
The guide recommends setting non-root user at build time instead of relying on
setting `runAsUser` at runtime in your Pod spec. This is a good practice and provides
some level of defense in depth. For example, if the container image is built with user `10001`
and the Pod spec misses adding the `runAsuser` field in its `Deployment` object. In this
case there are certain edge cases that are worth exploring for awareness:
1. Pods can fail to start, if the user defined at build time is different from
the one defined in pod spec and some files are as a result inaccessible.
2. Pods can end up sharing User IDs unintentionally. This can be problematic
even if the User IDs are non-zero in a situation where a container escape to
host file system is possible. Once the attacker has access to the host file
system, they get access to all the file resources that are owned by other
unrelated pods that share the same UID.
3. Pods can end up sharing User IDs, with other node level processes not managed
by Kubernetes e.g. node level daemons for auditing, vulnerability scanning,
telemetry. The threat is similar to the one above where host file system
access can give attacker full access to these node level daemons without
needing to be root on the node.
However, none of these cases will have as severe an impact as a container
running as root being able to escape as a root user on the host, which can provide
an attacker with complete control of the worker node, further allowing lateral
movement to other worker or control plane nodes.
Kubernetes 1.22 introduced
an [alpha feature](/docs/tasks/administer-cluster/kubelet-in-userns/)
that specifically reduces the impact of such a control plane component running
as root user to a non-root user through user namespaces.
That ([alpha stage](/docs/reference/command-line-tools-reference/feature-gates/#feature-stages)) support for user namespaces / rootless mode is available with
the following container runtimes:
- [Docker Engine](https://docs.docker.com/engine/security/rootless/)
- [Podman](https://developers.redhat.com/blog/2020/09/25/rootless-containers-with-podman-the-basics)
Some distributions support running in rootless mode, like the following:
- [kind](https://kind.sigs.k8s.io/docs/user/rootless/)
- [k3s](https://rancher.com/docs/k3s/latest/en/advanced/#running-k3s-with-rootless-mode-experimental)
- [Usernetes](https://github.com/rootless-containers/usernetes)
### Immutable container filesystems
The NSA/CISA Kubernetes Hardening Guidance highlights an often overlooked feature `readOnlyRootFileSystem`, with a
working example in [Appendix B](https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF#page=42). This example limits execution and tampering of
containers at runtime. Any read/write activity can then be limited to few
directories by using `tmpfs` volume mounts.
However, some applications that modify the container filesystem at runtime, like exploding a WAR or JAR file at container startup,
could face issues when enabling this feature. To avoid this issue, consider making minimal changes to the filesystem at runtime
when possible.
### Building secure container images
Kubernetes Hardening Guidance also recommends running a scanner at deploy time as an admission controller,
to prevent vulnerable or misconfigured pods from running in the cluster.
Theoretically, this sounds like a good approach but there are several caveats to
consider before this can be implemented in practice:
- Depending on network bandwidth, available resources and scanner of choice,
scanning for vulnerabilities for an image can take an indeterminate amount of
time. This could lead to slower or unpredictable pod start up times, which
could result in spikes of unavailability when apps are serving peak load.
- If the policy that allows or denies pod startup is made using incorrect or
incomplete data it could result in several false positive or false negative
outcomes like the following:
- inside a container image, the `openssl` package is detected as vulnerable. However,
the application is written in Golang and uses the Go `crypto` package for TLS. Therefore, this vulnerability
is not in the code execution path and as such has minimal impact if it
remains unfixed.
- A vulnerability is detected in the `openssl` package for a Debian base image.
However, the upstream Debian community considers this as a Minor impact
vulnerability and as a result does not release a patch fix for this
vulnerability. The owner of this image is now stuck with a vulnerability that
cannot be fixed and a cluster that does not allow the image to run because
of predefined policy that does not take into account whether the fix for a
vulnerability is available or not
- A Golang app is built on top of a [distroless](https://github.com/GoogleContainerTools/distroless)
image, but it is compiled with a Golang version that uses a vulnerable [standard library](https://pkg.go.dev/std).
The scanner has
no visibility into golang version but only on OS level packages. So it
allows the pod to run in the cluster in spite of the image containing an
app binary built on vulnerable golang.
To be clear, relying on vulnerability scanners is absolutely a good idea but
policy definitions should be flexible enough to allow:
- Creation of exception lists for images or vulnerabilities through labelling
- Overriding the severity with a risk score based on impact of a vulnerability
- Applying the same policies at build time to catch vulnerable images with
fixable vulnerabilities before they can be deployed into Kubernetes clusters
Special considerations like offline vulnerability database fetch, may also be
needed, if the clusters run in an air-gapped environment and the scanners
require internet access to update the vulnerability database.
### Pod Security Policies
Since Kubernetes v1.21, the [PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/)
API and related features are [deprecated](/blog/2021/04/06/podsecuritypolicy-deprecation-past-present-and-future/),
but some of the guidance in this section will still apply for the next few years, until cluster operators
upgrade their clusters to newer Kubernetes versions.
The Kubernetes project is working on a replacement for PodSecurityPolicy.
Kubernetes v1.22 includes an alpha feature called [Pod Security Admission](/docs/concepts/security/pod-security-admission/)
that is intended to allow enforcing a minimum level of isolation between pods.
The built-in isolation levels for Pod Security Admission are derived
from [Pod Security Standards](/docs/concepts/security/pod-security-standards/), which is a superset of all the components mentioned in Table I [page 10](https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF#page=17) of
the guidance.
Information about migrating from PodSecurityPolicy to the Pod Security
Admission feature is available
in
[Migrate from PodSecurityPolicy to the Built-In PodSecurity Admission Controller](/docs/tasks/configure-pod-container/migrate-from-psp/).
One important behavior mentioned in the guidance that remains the same between
Pod Security Policy and its replacement is that enforcing either of them does
not affect pods that are already running. With both PodSecurityPolicy and Pod Security Admission,
the enforcement happens during the pod creation
stage.
### Hardening container engines
Some container workloads are less trusted than others but may need to run in the
same cluster. In those cases, running them on dedicated nodes that include
hardened container runtimes that provide stricter pod isolation boundaries can
act as a useful security control.
Kubernetes supports
an API called [RuntimeClass](/docs/concepts/containers/runtime-class/) that is
stable / GA (and, therefore, enabled by default) stage as of Kubernetes v1.20.
RuntimeClass allows you to ensure that Pods requiring strong isolation are scheduled onto
nodes that can offer it.
Some third-party projects that you can use in conjunction with RuntimeClass are:
- [kata containers](https://github.com/kata-containers/kata-containers/blob/main/docs/how-to/how-to-use-k8s-with-cri-containerd-and-kata.md#create-runtime-class-for-kata-containers)
- [gvisor](https://gvisor.dev/docs/user_guide/containerd/quick_start/)
As discussed here and in the guidance, many features and tooling exist in and around
Kubernetes that can enhance the isolation boundaries between
pods. Based on relevant threats and risk posture, you should pick and choose
between them, instead of trying to apply all the recommendations. Having said that, cluster
level isolation i.e. running workloads in dedicated clusters, remains the strictest workload
isolation mechanism, in spite of improvements mentioned earlier here and in the guide.
## Network Separation and Hardening
Kubernetes Networking can be tricky and this section focuses on how to secure
and harden the relevant configurations. The guide identifies the following as key
takeaways:
- Using NetworkPolicies to create isolation between resources,
- Securing the control plane
- Encrypting traffic and sensitive data
### Network Policies
Network policies can be created with the help of network plugins. In order to
make the creation and visualization easier for users, Cilium supports
a [web GUI tool](https://editor.cilium.io). That web GUI lets you create Kubernetes
NetworkPolicies (a generic API that nevertheless requires a compatible CNI plugin),
and / or Cilium network policies (CiliumClusterwideNetworkPolicy and CiliumNetworkPolicy,
which only work in clusters that use the Cilium CNI plugin).
You can use these APIs to restrict network traffic between pods, and therefore minimize the
attack vector.
Another scenario that is worth exploring is the usage of external IPs. Some
services, when misconfigured, can create random external IPs. An attacker can take
advantage of this misconfiguration and easily intercept traffic. This vulnerability
has been reported
in [CVE-2020-8554](https://www.cvedetails.com/cve/CVE-2020-8554/).
Using [externalip-webhook](https://github.com/kubernetes-sigs/externalip-webhook)
can mitigate this vulnerability by preventing the services from using random
external IPs. [externalip-webhook](https://github.com/kubernetes-sigs/externalip-webhook)
only allows creation of services that don't require external IPs or whose
external IPs are within the range specified by the administrator.
> CVE-2020-8554 - Kubernetes API server in all versions allow an attacker
> who is able to create a ClusterIP service and set the `spec.externalIPs` field,
> to intercept traffic to that IP address. Additionally, an attacker who is able to
> patch the `status` (which is considered a privileged operation and should not
> typically be granted to users) of a LoadBalancer service can set the
> `status.loadBalancer.ingress.ip` to similar effect.
### Resource Policies
In addition to configuring ResourceQuotas and limits, consider restricting how many process
IDs (PIDs) a given Pod can use, and also to reserve some PIDs for node-level use to avoid
resource exhaustion. More details to apply these limits can be
found in [Process ID Limits And Reservations](/docs/concepts/policy/pid-limiting/).
### Control Plane Hardening
In the next section, the guide covers control plane hardening. It is worth
noting that
from [Kubernetes 1.20](https://github.com/kubernetes/kubernetes/issues/91506),
insecure port from API server, has been removed.
### Etcd
As a general rule, the etcd server should be configured to only trust
certificates assigned to the API server. It limits the attack surface and prevents a
malicious attacker from gaining access to the cluster. It might be beneficial to
use a separate CA for etcd, as it by default trusts all the certificates issued
by the root CA.
### Kubeconfig Files
In addition to specifying the token and certificates directly, `.kubeconfig`
supports dynamic retrieval of temporary tokens using auth provider plugins.
Beware of the possibility of malicious
shell [code execution](https://banzaicloud.com/blog/kubeconfig-security/) in a
`kubeconfig` file. Once attackers gain access to the cluster, they can steal ssh
keys/secrets or more.
### Secrets
Kubernetes [Secrets](/docs/concepts/configuration/secret/) is the native way of managing secrets as a Kubernetes
API object. However, in some scenarios such as a desire to have a single source of truth for all app secrets, irrespective of whether they run on Kubernetes or not, secrets can be managed loosely coupled with
Kubernetes and consumed by pods through side-cars or init-containers with minimal usage of Kubernetes Secrets API.
[External secrets providers](https://github.com/external-secrets/kubernetes-external-secrets)
and [csi-secrets-store](https://github.com/kubernetes-sigs/secrets-store-csi-driver)
are some of these alternatives to Kubernetes Secrets
## Log Auditing
The NSA/CISA guidance stresses monitoring and alerting based on logs. The key points
include logging at the host level, application level, and on the cloud. When
running Kubernetes in production, it's important to understand who's
responsible, and who's accountable, for each layer of logging.
### Kubernetes API auditing
One area that deserves more focus is what exactly should alert or be logged. The
document outlines a sample policy in [Appendix L: Audit Policy](https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF#page=55) that logs all
RequestResponse's including metadata and request / response bodies. While helpful for a demo, it may not be practical for production.
Each organization needs to evaluate their
own threat model and build an audit policy that complements or helps troubleshooting incident response. Think
about how someone would attack your organization and what audit trail could identify it. Review more advanced options for tuning audit logs in the official [audit logging documentation](/docs/tasks/debug-application-cluster/audit/#audit-policy).
It's crucial to tune your audit logs to only include events that meet your threat model. A minimal audit policy that logs everything at `metadata` level can also be a good starting point.
Audit logging configurations can also be tested with
kind following these [instructions](https://kind.sigs.k8s.io/docs/user/auditing).
### Streaming logs and auditing
Logging is important for threat and anomaly detection. As the document outlines,
it's a best practice to scan and alert on logs as close to real time as possible
and to protect logs from tampering if a compromise occurs. It's important to
reflect on the various levels of logging and identify the critical areas such as
API endpoints.
Kubernetes API audit logging can stream to a webhook and there's an example in [Appendix N: Webhook configuration](https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF#page=58). Using a webhook could be a method that
stores logs off cluster and/or centralizes all audit logs. Once logs are
centrally managed, look to enable alerting based on critical events. Also ensure
you understand what the baseline is for normal activities.
### Alert identification
While the guide stressed the importance of notifications, there is not a blanket
event list to alert from. The alerting requirements vary based on your own
requirements and threat model. Examples include the following events:
- Changes to the `securityContext` of a Pod
- Updates to admission controller configs
- Accessing certain files / URLs
### Additional logging resources
- [Seccomp Security Profiles and You: A Practical Guide - Duffie Cooley](https://www.youtube.com/watch?v=OPuu8wsu2Zc)
- [TGI Kubernetes 119: Gatekeeper and OPA](https://www.youtube.com/watch?v=ZJgaGJm9NJE)
- [Abusing The Lack of Kubernetes Auditing Policies](https://www.lacework.com/blog/hiding-in-plaintext-sight-abusing-the-lack-of-kubernetes-auditing-policies/)
- [Enable seccomp for all workloads with a new v1.22 alpha feature](https://kubernetes.io/blog/2021/08/25/seccomp-default/)
- [This Week in Cloud Native: Auditing / Pod Security](https://www.twitch.tv/videos/1147889860)
## Upgrading and Application Security practices
Kubernetes releases three times per year, so upgrade-related toil is a common problem for
people running production clusters. In addition to this, operators must
regularly upgrade the underlying node's operating system and running
applications. This is a best practice to ensure continued support and to reduce
the likelihood of bugs or vulnerabilities.
Kubernetes supports the three most recent stable releases. While each Kubernetes
release goes through a large number of tests before being published, some
teams aren't comfortable running the latest stable release until some time has
passed. No matter what version you're running, ensure that patch upgrades
happen frequently or automatically. More information can be found in
the [version skew](/releases/version-skew-policy/) policy
pages.
When thinking about how you'll manage node OS upgrades, consider ephemeral
nodes. Having the ability to destroy and add nodes allows your team to respond
quicker to node issues. In addition, having deployments that tolerate node
instability (and a culture that encourages frequent deployments) allows for
easier cluster upgrades.
Additionally, it's worth reiterating from the guidance that periodic
vulnerability scans and penetration tests can be performed on the various system
components to proactively look for insecure configurations and vulnerabilities.
### Finding release & security information
To find the most recent Kubernetes supported versions, refer to
[https://k8s.io/releases](https://k8s.io/releases), which includes minor versions. It's good to stay up to date with
your minor version patches.
If you're running a managed Kubernetes offering, look for their release
documentation and find their various security channels.
Subscribe to
the [Kubernetes Announce mailing list](https://groups.google.com/g/kubernetes-announce).
The Kubernetes Announce mailing list is searchable for terms such
as "[Security Advisories](https://groups.google.com/g/kubernetes-announce/search?q=%5BSecurity%20Advisory%5D)".
You can set up alerts and email notifications as long as you know what key
words to alert on.
## Conclusion
In summary, it is fantastic to see security practitioners sharing this
level of detailed guidance in public. This guidance further highlights
Kubernetes going mainstream and how securing Kubernetes clusters and the
application containers running on Kubernetes continues to need attention and focus of
practitioners. Only a few weeks after the guidance was published, an open source
tool [kubescape](https://github.com/armosec/kubescape) to validate cluster
against this guidance became available.
This tool can be a great starting point to check the current state of your
clusters, after which you can use the information in this blog post and in the guidance to assess
where improvements can be made.
Finally, it is worth reiterating that not all controls in this guidance will
make sense for all practitioners. The best way to know which controls matter is
to rely on the threat model of your own Kubernetes environment.
_A special shout out and thanks to Rory McCune (@raesene) for his inputs to this blog post_
@@ -0,0 +1,141 @@
---
layout: blog
title: "Introducing ClusterClass and Managed Topologies in Cluster API"
date: 2021-10-08
slug: capi-clusterclass-and-managed-topologies
---
**Author:** Fabrizio Pandini (VMware)
The [Cluster API community](https://cluster-api.sigs.k8s.io/) is happy to announce the implementation of *ClusterClass and Managed Topologies*, a new feature that will greatly simplify how you can provision, upgrade, and operate multiple Kubernetes clusters in a declarative way.
## A little bit of context…
Before getting into the details, let's take a step back and look at the history of Cluster API.
The [Cluster API project](https://github.com/kubernetes-sigs/cluster-api/) started three years ago, and the first releases focused on extensibility and implementing a declarative API that allows a seamless experience across infrastructure providers. This was a success with many cloud providers: AWS, Azure, Digital Ocean, GCP, Metal3, vSphere and still counting.
With extensibility addressed, the focus shifted to features, like automatic control plane and etcd management, health-based machine remediation, machine rollout strategies and more.
Fast forwarding to 2021, with lots of companies using Cluster API to manage fleets of Kubernetes clusters running workloads in production, the community focused its effort on stabilization of both code, APIs, documentation, and on extensive test signals which inform Kubernetes releases.
With solid foundations in place, and a vibrant and welcoming community that still continues to grow, it was time to plan another iteration on our UX for both new and advanced users.
Enter ClusterClass and Managed Topologies, tada!
## ClusterClass
As the name suggests, ClusterClass and managed topologies are built in two parts.
The idea behind ClusterClass is simple: define the shape of your cluster once, and reuse it many times, abstracting the complexities and the internals of a Kubernetes cluster away.
![Defining a ClusterClass](/images/blog/2021-10-08-clusterclass-and-managed-topologies/clusterclass.svg)
ClusterClass, at its heart, is a collection of Cluster and Machine templates. You can use it as a “stamp” that can be leveraged to create many clusters of a similar shape.
```yaml
---
apiVersion: cluster.x-k8s.io/v1beta1
kind: ClusterClass
metadata:
name: my-amazing-cluster-class
spec:
controlPlane:
ref:
apiVersion: controlplane.cluster.x-k8s.io/v1beta1
kind: KubeadmControlPlaneTemplate
name: high-availability-control-plane
machineInfrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
kind: DockerMachineTemplate
name: control-plane-machine
workers:
machineDeployments:
- class: type1-workers
template:
bootstrap:
ref:
apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
kind: KubeadmConfigTemplate
name: type1-bootstrap
infrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
kind: DockerMachineTemplate
name: type1-machine
- class: type2-workers
template:
bootstrap:
ref:
apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
kind: KubeadmConfigTemplate
name: type2-bootstrap
infrastructure:
ref:
kind: DockerMachineTemplate
apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
name: type2-machine
infrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta1
kind: DockerClusterTemplate
name: cluster-infrastructure
```
The possibilities are endless; you can get a default ClusterClass from the community, “off-the-shelf” classes from your vendor of choice, “certified” classes from the platform admin in your company, or even create custom ones for advanced scenarios.
## Managed Topologies
Managed Topologies let you put the power of ClusterClass into action.
Given a ClusterClass, you can create many Clusters of a similar shape by providing a single resource, the Cluster.
![Create a Cluster with ClusterClass](/images/blog/2021-10-08-clusterclass-and-managed-topologies/create-cluster.svg)
Here is an example:
```yaml
---
apiVersion: cluster.x-k8s.io/v1beta1
kind: Cluster
metadata:
name: my-amazing-cluster
namespace: bar
spec:
topology: # define a managed topology
class: my-amazing-cluster-class # use the ClusterClass mentioned earlier
version: v1.21.2
controlPlane:
replicas: 3
workers:
machineDeployments:
- class: type1-workers
name: big-pool-of-machines
replicas: 5
- class: type2-workers
name: small-pool-of-machines
replicas: 1
```
But there is more than simplified cluster creation. Now the Cluster acts as a single control point for your entire topology.
All the power of Cluster API, extensibility, lifecycle automation, stability, all the features required for managing an enterprise grade Kubernetes cluster on the infrastructure provider of your choice are now at your fingertips: you can create your Cluster, add new machines, upgrade to the next Kubernetes version, and all from a single place.
It is just as simple as it looks!
## Whats next
While the amazing Cluster API community is working hard to deliver the first version of ClusterClass and managed topologies later this year, we are already looking forward to what comes next for the project and its ecosystem.
There are a lot of great ideas and opportunities ahead!
We want to make managed topologies even more powerful and flexible, allowing users to dynamically change bits of a ClusterClass according to the specific needs of a Cluster; this will ensure the same simple and intuitive UX for solving complex problems like e.g. selecting machine image for a specific Kubernetes version and for a specific region of your infrastructure provider, or injecting proxy configurations in the entire Cluster, and so on.
Stay tuned for what comes next, and if you have any questions, comments or suggestions:
* Chat with us on the Kubernetes [Slack](http://slack.k8s.io/):[#cluster-api](https://kubernetes.slack.com/archives/C8TSNPY4T)
* Join the SIG Cluster Lifecycle [Google Group](https://groups.google.com/g/kubernetes-sig-cluster-lifecycle) to receive calendar invites and gain access to documents
* Join our [Zoom meeting](https://zoom.us/j/861487554), every Wednesday at 10:00 Pacific Time
* Check out the [ClusterClass tutorial](https://cluster-api.sigs.k8s.io/tasks/experimental-features/cluster-classes.html) in the Cluster API book.
@@ -0,0 +1,241 @@
---
layout: blog
title: "Use KPNG to Write Specialized kube-proxiers"
date: 2021-10-18
slug: use-kpng-to-write-specialized-kube-proxiers
---
**Author**: Lars Ekman (Ericsson)
The post will show you how to create a specialized service kube-proxy
style network proxier using Kubernetes Proxy NG
[kpng](https://github.com/kubernetes-sigs/kpng) without interfering
with the existing kube-proxy. The kpng project aims at renewing the
the default Kubernetes Service implementation, the "kube-proxy". An
important feature of kpng is that it can be used as a library to
create proxiers outside K8s. While this is useful for CNI-plugins that
replaces the kube-proxy it also opens the possibility for anyone to
create a proxier for a special purpose.
## Define a service that uses a specialized proxier
```
apiVersion: v1
kind: Service
metadata:
name: kpng-example
labels:
service.kubernetes.io/service-proxy-name: kpng-example
spec:
clusterIP: None
ipFamilyPolicy: RequireDualStack
externalIPs:
- 10.0.0.55
- 1000::55
selector:
app: kpng-alpine
ports:
- port: 6000
```
If the `service.kubernetes.io/service-proxy-name` label is defined the
`kube-proxy` will ignore the service. A custom controller can watch
services with the label set to it's own name, "kpng-example" in
this example, and setup specialized load-balancing.
The `service.kubernetes.io/service-proxy-name` label is [not
new](https://kubernetes.io/docs/reference/labels-annotations-taints/#servicekubernetesioservice-proxy-name),
but so far is has been quite hard to write a specialized proxier.
The common use for a specialized proxier is assumed to be handling
external traffic for some use-case not supported by K8s. In that
case `ClusterIP` is not needed, so we use a "headless" service in this
example.
## Specialized proxier using kpng
A [kpng](https://github.com/kubernetes-sigs/kpng) based proxier
consists of the `kpng` controller handling all the K8s api related
functions, and a "backend" implementing the load-balancing. The
backend can be linked with the `kpng` controller binary or be a
separate program communicating with the controller using gRPC.
```
kpng kube --service-proxy-name=kpng-example to-api
```
This starts the `kpng` controller and tell it to watch only services
with the "kpng-example" service proxy name. The "to-api" parameter
will open a gRPC server for backends.
You can test this yourself outside your cluster. Please see the example
below.
Now we start a backend that simply prints the updates from the
controller.
```
$ kubectl apply -f kpng-example.yaml
$ kpng-json | jq # (this is the backend)
{
"Service": {
"Namespace": "default",
"Name": "kpng-example",
"Type": "ClusterIP",
"IPs": {
"ClusterIPs": {},
"ExternalIPs": {
"V4": [
"10.0.0.55"
],
"V6": [
"1000::55"
]
},
"Headless": true
},
"Ports": [
{
"Protocol": 1,
"Port": 6000,
"TargetPort": 6000
}
]
},
"Endpoints": [
{
"IPs": {
"V6": [
"1100::202"
]
},
"Local": true
},
{
"IPs": {
"V4": [
"11.0.2.2"
]
},
"Local": true
},
{
"IPs": {
"V4": [
"11.0.1.2"
]
}
},
{
"IPs": {
"V6": [
"1100::102"
]
}
}
]
}
```
A real backend would use some mechanism to load-balance traffic from
the external IPs to the endpoints.
## Writing a backend
The `kpng-json` backend looks like this:
```go
package main
import (
"os"
"encoding/json"
"sigs.k8s.io/kpng/client"
)
func main() {
client.Run(jsonPrint)
}
func jsonPrint(items []*client.ServiceEndpoints) {
enc := json.NewEncoder(os.Stdout)
for _, item := range items {
_ = enc.Encode(item)
}
}
```
(yes, that is the entire program)
A real backend would of course be much more complex, but this
illustrates how `kpng` let you focus on load-balancing.
You can have several backends connected to a `kpng` controller, so
during development or debug it can be useful to let something like the
`kpng-json` backend run in parallel with your real backend.
## Example
The complete example can be found [here](https://github.com/kubernetes-sigs/kpng/tree/master/examples/pipe-exec).
As an example we implement an "all-ip" backend. It direct all traffic
for the externalIPs to a local endpoint, regardless of ports and upper
layer protocols. There is a
[KEP](https://github.com/kubernetes/enhancements/pull/2611) for this
function and this example is a much simplified version.
To direct all traffic from an external address to a local POD [only
one iptables rule is
needed](https://github.com/kubernetes/enhancements/pull/2611#issuecomment-895061013),
for instance;
```
ip6tables -t nat -A PREROUTING -d 1000::55/128 -j DNAT --to-destination 1100::202
```
As you can see the addresses are in the call to the backend and all it
have to do is:
* Extract the addresses with `Local: true`
* Setup iptables rules for the `ExternalIPs`
A script doing that may look like:
```
xip=$(cat /tmp/out | jq -r .Service.IPs.ExternalIPs.V6[0])
podip=$(cat /tmp/out | jq -r '.Endpoints[]|select(.Local == true)|select(.IPs.V6 != null)|.IPs.V6[0]')
ip6tables -t nat -A PREROUTING -d $xip/128 -j DNAT --to-destination $podip
```
Assuming the JSON output above is stored in `/tmp/out` ([jq](https://stedolan.github.io/jq/) is an *awesome* program!).
As this is an example we make it really simple for ourselves by using
a minor variation of the `kpng-json` backend above. Instead of just
printing, a program is called and the JSON output is passed as `stdin`
to that program. The backend can be tested stand-alone:
```
CALLOUT=jq kpng-callout
```
Where `jq` can be replaced with your own program or script. A script
may look like the example above. For more info and the complete
example please see [https://github.com/kubernetes-sigs/kpng/tree/master/examples/pipe-exec](https://github.com/kubernetes-sigs/kpng/tree/master/examples/pipe-exec).
## Summary
While [kpng](https://github.com/kubernetes-sigs/kpng) is in early
stage of development this post wants to show how you may build your
own specialized K8s proxiers in the future. The only thing your
applications need to do is to add the
`service.kubernetes.io/service-proxy-name` label in the Service
manifest.
It is a tedious process to get new features into the `kube-proxy` and
it is not unlikely that they will be rejected, so to write a
specialized proxier may be the only option.
@@ -0,0 +1,56 @@
---
layout: blog
title: "Announcing the 2021 Steering Committee Election Results"
date: 2021-11-08
slug: steering-committee-results-2021
---
**Author**: Kaslin Fields
The [2021 Steering Committee Election](https://github.com/kubernetes/community/tree/master/events/elections/2021) is now complete. The Kubernetes Steering Committee consists of 7 seats, 4 of which were up for election in 2021. Incoming committee members serve a term of 2 years, and all members are elected by the Kubernetes Community.
This community body is significant since it oversees the governance of the entire Kubernetes project. With that great power comes great responsibility. You can learn more about the steering committees role in their [charter](https://github.com/kubernetes/steering/blob/master/charter.md).
## Results
Congratulations to the elected committee members whose two year terms begin immediately (listed in alphabetical order by GitHub handle):
* **Christoph Blecker ([@cblecker](https://github.com/cblecker)), Red Hat**
* **Stephen Augustus ([@justaugustus](https://github.com/justaugustus)), Cisco**
* **Paris Pittman ([@parispittman](https://github.com/parispittman)), Apple**
* **Tim Pepper ([@tpepper](https://github.com/tpepper)), VMware**
They join continuing members:
* **Davanum Srinivas ([@dims](https://github.com/dims)), VMware**
* **Jordan Liggitt ([@liggitt](https://github.com/liggitt)), Google**
* **Bob Killen ([@mrbobbytables](https://github.com/mrbobbytables)), Google**
Paris Pittman and Christoph Blecker are returning Steering Committee Members.
## Big Thanks
Thank you and congratulations on a successful election to this rounds election officers:
* Alison Dowdney, ([@alisondy](https://github.com/alisondy))
* Noah Kantrowitz ([@coderanger](https://github.com/coderanger))
* Josh Berkus ([@jberkus](https://github.com/jberkus))
Special thanks to Arnaud Meukam ([@ameukam](https://github.com/ameukam)), k8s-infra liaison, who enabled our voting software on community-owned infrastructure.
Thanks to the Emeritus Steering Committee Members. Your prior service is appreciated by the community:
* Derek Carr ([@derekwaynecarr](https://github.com/derekwaynecarr))
* Nikhita Raghunath ([@nikhita](https://github.com/nikhita))
And thank you to all the candidates who came forward to run for election.
## Get Involved with the Steering Committee
This governing body, like all of Kubernetes, is open to all. You can follow along with Steering Committee [backlog items](https://github.com/kubernetes/steering/projects/1) and weigh in by filing an issue or creating a PR against their [repo](https://github.com/kubernetes/steering). They have an open meeting on [the first Monday at 9:30am PT of every month](https://github.com/kubernetes/steering) and regularly attend Meet Our Contributors. They can also be contacted at their public mailing list steering@kubernetes.io.
You can see what the Steering Committee meetings are all about by watching past meetings on the [YouTube Playlist](https://www.youtube.com/playlist?list=PL69nYSiGNLP1yP1B_nd9-drjoxp0Q14qM).
---
_This post was written by the [Upstream Marketing Working Group](https://github.com/kubernetes/community/tree/master/communication/marketing-team#contributor-marketing). If you want to write stories about the Kubernetes community, learn more about us._
@@ -0,0 +1,238 @@
---
layout: blog
title: 'Non-root Containers And Devices'
date: 2021-11-09
slug: non-root-containers-and-devices
---
**Author:** Mikko Ylinen (Intel)
The user/group ID related security settings in Pod's `securityContext` trigger a problem when users want to
deploy containers that use accelerator devices (via [Kubernetes Device Plugins](/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/)) on Linux. In this blog
post I talk about the problem and describe the work done so far to address it. It's not meant to be a long story about getting the [k/k issue](https://github.com/kubernetes/kubernetes/issues/92211) fixed.
Instead, this post aims to raise awareness of the issue and to highlight important device use-cases too. This is needed as Kubernetes works on new related features such as support for user namespaces.
## Why non-root containers can't use devices and why it matters
One of the key security principles for running containers in Kubernetes is the
principle of least privilege. The Pod/container `securityContext` specifies the config
options to set, e.g., Linux capabilities, MAC policies, and user/group ID values to achieve this.
Furthermore, the cluster admins are supported with tools like [PodSecurityPolicy](/docs/concepts/policy/pod-security-policy/) (deprecated) or
[Pod Security Admission](/docs/concepts/security/pod-security-admission/) (alpha) to enforce the desired security settings for pods that are being deployed in
the cluster. These settings could, for instance, require that containers must be `runAsNonRoot` or
that they are forbidden from running with root's group ID in `runAsGroup` or `supplementalGroups`.
In Kubernetes, the kubelet builds the list of [`Device`](https://pkg.go.dev/k8s.io/cri-api@v0.22.1/pkg/apis/runtime/v1#Device) resources to be made available to a container
(based on inputs from the Device Plugins) and the list is included in the CreateContainer CRI message
sent to the CRI container runtime. Each `Device` contains little information: host/container device
paths and the desired devices cgroups permissions.
The [OCI Runtime Spec for Linux Container Configuration](https://github.com/opencontainers/runtime-spec/blob/master/config-linux.md)
expects that in addition to the devices cgroup fields, more detailed information about the devices
must be provided:
```yaml
{
"type": "<string>",
"path": "<string>",
"major": <int64>,
"minor": <int64>,
"fileMode": <uint32>,
"uid": <uint32>,
"gid": <uint32>
},
```
The CRI container runtimes (containerd, CRI-O) are responsible for obtaining this information
from the host for each `Device`. By default, the runtimes copy the host device's user and group IDs:
- `uid` (uint32, OPTIONAL) - id of device owner in the container namespace.
- `gid` (uint32, OPTIONAL) - id of device group in the container namespace.
Similarly, the runtimes prepare other mandatory `config.json` sections based on the CRI fields,
including the ones defined in `securityContext`: `runAsUser`/`runAsGroup`, which become part of the POSIX
platforms user structure via:
- `uid` (int, REQUIRED) specifies the user ID in the container namespace.
- `gid` (int, REQUIRED) specifies the group ID in the container namespace.
- `additionalGids` (array of ints, OPTIONAL) specifies additional group IDs in the container namespace to be added to the process.
However, the resulting `config.json` triggers a problem when trying to run containers with
both devices added and with non-root uid/gid set via `runAsUser`/`runAsGroup`: the container user process
has no permission to use the device even when its group id (gid, copied from host) was permissive to
non-root groups. This is because the container user does not belong to that host group (e.g., via `additionalGids`).
Being able to run applications that use devices as non-root user is normal and expected to work so that
the security principles can be met. Therefore, several alternatives were considered to get the gap filled with what the PodSec/CRI/OCI supports today.
## What was done to solve the issue?
You might have noticed from the problem definition that it would at least be possible to workaround
the problem by manually adding the device gid(s) to `supplementalGroups`, or in
the case of just one device, set `runAsGroup` to the device's group id. However, this is problematic because the device gid(s) may have
different values depending on the nodes' distro/version in the cluster. For example, with GPUs the following commands for different distros and versions return different gids:
Fedora 33:
```
$ ls -l /dev/dri/
total 0
drwxr-xr-x. 2 root root 80 19.10. 10:21 by-path
crw-rw----+ 1 root video 226, 0 19.10. 10:42 card0
crw-rw-rw-. 1 root render 226, 128 19.10. 10:21 renderD128
$ grep -e video -e render /etc/group
video:x:39:
render:x:997:
```
Ubuntu 20.04:
```
$ ls -l /dev/dri/
total 0
drwxr-xr-x 2 root root 80 19.10. 17:36 by-path
crw-rw---- 1 root video 226, 0 19.10. 17:36 card0
crw-rw---- 1 root render 226, 128 19.10. 17:36 renderD128
$ grep -e video -e render /etc/group
video:x:44:
render:x:133:
```
Which number to choose in your `securityContext`? Also, what if the `runAsGroup`/`runAsUser` values cannot be hard-coded because
they are automatically assigned during pod admission time via external security policies?
Unlike volumes with `fsGroup`, the devices have no official notion of `deviceGroup`/`deviceUser` that the CRI runtimes (or kubelet)
would be able to use. We considered using container annotations set by the device plugins (e.g., `io.kubernetes.cri.hostDeviceSupplementalGroup/`) to get custom OCI `config.json` uid/gid values.
This would have required changes to all existing device plugins which was not ideal.
Instead, a solution that is *seamless* to end-users without getting the device plugin vendors involved was preferred. The selected approach was
to re-use `runAsUser` and `runAsGroup` values in `config.json` for devices:
```yaml
{
"type": "c",
"path": "/dev/foo",
"major": 123,
"minor": 4,
"fileMode": 438,
"uid": <runAsUser>,
"gid": <runAsGroup>
},
```
With `runc` OCI runtime (in non-rootless mode), the device is created (`mknod(2)`) in
the container namespace and the ownership is changed to `runAsUser`/`runAsGroup` using `chmod(2)`.
{{< note >}}
[Rootless mode](/docs/tasks/administer-cluster/kubelet-in-userns/) and devices is not supported.
{{</note>}}
Having the ownership updated in the container namespace is justified as the user process is the only one accessing the device. Only `runAsUser`/`runAsGroup`
are taken into account, and, e.g., the `USER` setting in the container is currently ignored.
While it is likely that the "faulty" deployments (i.e., non-root `securityContext` + devices) do not exist, to be absolutely sure no
deployments break, an opt-in config entry in both containerd and CRI-O to enable the new behavior was added. The following:
`device_ownership_from_security_context (bool)`
defaults to `false` and must be enabled to use the feature.
## See non-root containers using devices after the fix
To demonstrate the new behavior, let's use a Data Plane Development Kit (DPDK) application using hardware accelerators, Kubernetes CPU manager, and HugePages as an example. The cluster runs containerd with:
```toml
[plugins]
[plugins."io.containerd.grpc.v1.cri"]
device_ownership_from_security_context = true
```
or CRI-O with:
```toml
[crio.runtime]
device_ownership_from_security_context = true
```
and the `Guaranteed` QoS Class Pod that runs DPDK's crypto-perf test utility with this YAML:
```yaml
...
metadata:
name: qat-dpdk
spec:
securityContext:
runAsUser: 1000
runAsGroup: 2000
fsGroup: 3000
containers:
- name: crypto-perf
image: intel/crypto-perf:devel
...
resources:
requests:
cpu: "3"
memory: "128Mi"
qat.intel.com/generic: '4'
hugepages-2Mi: "128Mi"
limits:
cpu: "3"
memory: "128Mi"
qat.intel.com/generic: '4'
hugepages-2Mi: "128Mi"
...
```
To verify the results, check the user and group ID that the container runs as:
```
$ kubectl exec -it qat-dpdk -c crypto-perf -- id
```
They are set to non-zero values as expected:
```
uid=1000 gid=2000 groups=2000,3000
```
Next, check the device node permissions (`qat.intel.com/generic` exposes `/dev/vfio/` devices) are accessible to `runAsUser`/`runAsGroup`:
```
$ kubectl exec -it qat-dpdk -c crypto-perf -- ls -la /dev/vfio
total 0
drwxr-xr-x 2 root root 140 Sep 7 10:55 .
drwxr-xr-x 7 root root 380 Sep 7 10:55 ..
crw------- 1 1000 2000 241, 0 Sep 7 10:55 58
crw------- 1 1000 2000 241, 2 Sep 7 10:55 60
crw------- 1 1000 2000 241, 10 Sep 7 10:55 68
crw------- 1 1000 2000 241, 11 Sep 7 10:55 69
crw-rw-rw- 1 1000 2000 10, 196 Sep 7 10:55 vfio
```
Finally, check the non-root container is also allowed to create HugePages:
```
$ kubectl exec -it qat-dpdk -c crypto-perf -- ls -la /dev/hugepages/
```
`fsGroup` gives a `runAsUser` writable HugePages emptyDir mountpoint:
```
total 0
drwxrwsr-x 2 root 3000 0 Sep 7 10:55 .
drwxr-xr-x 7 root root 380 Sep 7 10:55 ..
```
## Help us test it and provide feedback!
The functionality described here is expected to help with cluster security and the configurability of device permissions. To allow
non-root containers to use devices requires cluster admins to opt-in to the functionality by setting
`device_ownership_from_security_context = true`. To make it a default setting, please test it and provide your feedback (via SIG-Node meetings or issues)!
The flag is available in CRI-O v1.22 release and queued for containerd v1.6.
More work is needed to get it *properly* supported. It is known to work with `runc` but it also needs to be made to function
with other OCI runtimes too, where applicable. For instance, Kata Containers supports device passthrough and allows it to make devices
available to containers in VM sandboxes too.
Moreover, the additional challenge comes with support of user names and devices. This problem is still [open](https://github.com/kubernetes/enhancements/pull/2101)
and requires more brainstorming.
Finally, it needs to be understood whether `runAsUser`/`runAsGroup` are enough or if device specific settings similar to `fsGroups` are needed in PodSpec/CRI v2.
## Thanks
My thanks goes to Mike Brown (IBM, containerd), Peter Hunt (Redhat, CRI-O), and Alexander Kanevskiy (Intel) for providing all the feedback and good conversations.
@@ -0,0 +1,59 @@
---
layout: blog
title: "Dockershim removal is coming. Are you ready?"
date: 2021-11-12
slug: are-you-ready-for-dockershim-removal
---
**Author:** Sergey Kanzhelev, Google. With reviews from Davanum Srinivas, Elana Hashman, Noah Kantrowitz, Rey Lejano.
Last year we announced that Dockershim is being deprecated: [Dockershim Deprecation FAQ](/blog/2020/12/02/dockershim-faq/).
Our current plan is to remove dockershim from the Kubernetes codebase soon.
We are looking for feedback from you whether you are ready for dockershim
removal and to ensure that you are ready when the time comes.
**Please fill out this survey: https://forms.gle/svCJmhvTv78jGdSx8**.
The dockershim component that enables Docker as a Kubernetes container runtime is
being deprecated in favor of runtimes that directly use the [Container Runtime Interface](/blog/2016/12/container-runtime-interface-cri-in-kubernetes/)
created for Kubernetes. Many Kubernetes users have migrated to
other container runtimes without problems. However we see that dockershim is
still very popular. You may see some public numbers in recent [Container Report](https://www.datadoghq.com/container-report/#8) from DataDog.
Some Kubernetes hosting vendors just recently enabled other runtimes support
(especially for Windows nodes). And we know that many third party tools vendors
are still not ready: [migrating telemetry and security agents](/docs/tasks/administer-cluster/migrating-from-dockershim/migrating-telemetry-and-security-agents/#telemetry-and-security-agent-vendors).
At this point, we believe that there is feature parity between Docker and the
other runtimes. Many end-users have used our [migration guide](/docs/tasks/administer-cluster/migrating-from-dockershim/)
and are running production workload using these different runtimes. The plan of
record today is that dockershim will be removed in version 1.24, slated for
release around April of next year. For those developing or running alpha and
beta versions, dockershim will be removed in December at the beginning of the
1.24 release development cycle.
There is only one month left to give us feedback. We want you to tell us how
ready you are.
**We are collecting opinions through this survey: [https://forms.gle/svCJmhvTv78jGdSx8](https://forms.gle/svCJmhvTv78jGdSx8)**
To better understand preparedness for the dockershim removal, our survey is
asking the version of Kubernetes you are currently using, and an estimate of
when you think you will adopt Kubernetes 1.24. All the aggregated information
on dockershim removal readiness will be published.
Free form comments will be reviewed by SIG Node leadership. If you want to
discuss any details of migrating from dockershim, report bugs or adoption
blockers, you can use one of the SIG Node contact options any time:
https://github.com/kubernetes/community/tree/master/sig-node#contact
Kubernetes is a mature project. This deprecation is another
step in the effort to get away from permanent beta features and providing more
stability and compatibility guarantees. With the migration from dockershim you
will get more flexibility and choice of container runtime features as well as
less dependencies of your apps on specific underlying technology. Please take
time to review the [dockershim migration documentation](/docs/tasks/administer-cluster/migrating-from-dockershim/)
and consult your Kubernetes hosting vendor (if you have one) what container runtime options are available for you.
Read up [container runtime documentation with instructions on how to use containerd and CRI-O](/docs/setup/production-environment/container-runtimes/#container-runtimes)
to help prepare you when you're ready to upgrade to 1.24. CRI-O, containerd, and
Docker with [Mirantis cri-dockerd](https://github.com/Mirantis/cri-dockerd) are
not the only container runtime options, we encourage you to explore the [CNCF landscape on container runtimes](https://landscape.cncf.io/card-mode?category=container-runtime&grouping=category)
in case another suits you better.
Thank you!
File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 25 KiB

@@ -0,0 +1,87 @@
<?xml version='1.0' encoding='UTF-8'?>
<!-- Generated by CodeCogs with dvisvgm 2.9.1 -->
<svg version='1.1' xmlns='http://www.w3.org/2000/svg' xmlns:xlink='http://www.w3.org/1999/xlink' width='389.559851pt' height='13.50934pt' viewBox='-.239051 -.240635 389.559851 13.50934'>
<defs>
<path id='g1-61' d='M8.069738-3.873474C8.237111-3.873474 8.452304-3.873474 8.452304-4.088667C8.452304-4.315816 8.249066-4.315816 8.069738-4.315816H1.028144C.860772-4.315816 .645579-4.315816 .645579-4.100623C.645579-3.873474 .848817-3.873474 1.028144-3.873474H8.069738ZM8.069738-1.649813C8.237111-1.649813 8.452304-1.649813 8.452304-1.865006C8.452304-2.092154 8.249066-2.092154 8.069738-2.092154H1.028144C.860772-2.092154 .645579-2.092154 .645579-1.876961C.645579-1.649813 .848817-1.649813 1.028144-1.649813H8.069738Z'/>
<path id='g1-91' d='M2.988792 2.988792V2.546451H1.829141V-8.524035H2.988792V-8.966376H1.3868V2.988792H2.988792Z'/>
<path id='g1-93' d='M1.853051-8.966376H.251059V-8.524035H1.41071V2.546451H.251059V2.988792H1.853051V-8.966376Z'/>
<path id='g0-58' d='M2.199751-.573848C2.199751-.920548 1.912827-1.159651 1.625903-1.159651C1.279203-1.159651 1.0401-.872727 1.0401-.585803C1.0401-.239103 1.327024 0 1.613948 0C1.960648 0 2.199751-.286924 2.199751-.573848Z'/>
<path id='g0-97' d='M3.598506-1.422665C3.53873-1.219427 3.53873-1.195517 3.371357-.968369C3.108344-.633624 2.582316-.119552 2.020423-.119552C1.530262-.119552 1.255293-.561893 1.255293-1.267248C1.255293-1.924782 1.625903-3.263761 1.853051-3.765878C2.259527-4.60274 2.82142-5.033126 3.287671-5.033126C4.076712-5.033126 4.23213-4.052802 4.23213-3.957161C4.23213-3.945205 4.196264-3.789788 4.184309-3.765878L3.598506-1.422665ZM4.363636-4.483188C4.23213-4.794022 3.90934-5.272229 3.287671-5.272229C1.936737-5.272229 .478207-3.526775 .478207-1.75741C.478207-.573848 1.171606 .119552 1.984558 .119552C2.642092 .119552 3.203985-.394521 3.53873-.789041C3.658281-.083686 4.220174 .119552 4.578829 .119552S5.224408-.095641 5.439601-.526027C5.630884-.932503 5.798257-1.661768 5.798257-1.709589C5.798257-1.769365 5.750436-1.817186 5.678705-1.817186C5.571108-1.817186 5.559153-1.75741 5.511333-1.578082C5.332005-.872727 5.104857-.119552 4.614695-.119552C4.267995-.119552 4.244085-.430386 4.244085-.669489C4.244085-.944458 4.27995-1.075965 4.387547-1.542217C4.471233-1.841096 4.531009-2.10411 4.62665-2.450809C5.068991-4.244085 5.176588-4.674471 5.176588-4.746202C5.176588-4.913574 5.045081-5.045081 4.865753-5.045081C4.483188-5.045081 4.387547-4.62665 4.363636-4.483188Z'/>
<path id='g0-99' d='M4.674471-4.495143C4.447323-4.495143 4.339726-4.495143 4.172354-4.351681C4.100623-4.291905 3.969116-4.112578 3.969116-3.921295C3.969116-3.682192 4.148443-3.53873 4.375592-3.53873C4.662516-3.53873 4.985305-3.777833 4.985305-4.25604C4.985305-4.829888 4.435367-5.272229 3.610461-5.272229C2.044334-5.272229 .478207-3.56264 .478207-1.865006C.478207-.824907 1.123786 .119552 2.343213 .119552C3.969116 .119552 4.99726-1.147696 4.99726-1.303113C4.99726-1.374844 4.925529-1.43462 4.877709-1.43462C4.841843-1.43462 4.829888-1.422665 4.722291-1.315068C3.957161-.298879 2.82142-.119552 2.367123-.119552C1.542217-.119552 1.279203-.836862 1.279203-1.43462C1.279203-1.853051 1.482441-3.012702 1.912827-3.825654C2.223661-4.387547 2.86924-5.033126 3.622416-5.033126C3.777833-5.033126 4.435367-5.009215 4.674471-4.495143Z'/>
<path id='g0-100' d='M6.01345-7.998007C6.025405-8.045828 6.049315-8.117559 6.049315-8.177335C6.049315-8.296887 5.929763-8.296887 5.905853-8.296887C5.893898-8.296887 5.308095-8.249066 5.248319-8.237111C5.045081-8.225156 4.865753-8.201245 4.65056-8.18929C4.351681-8.16538 4.267995-8.153425 4.267995-7.938232C4.267995-7.81868 4.363636-7.81868 4.531009-7.81868C5.116812-7.81868 5.128767-7.711083 5.128767-7.591532C5.128767-7.519801 5.104857-7.424159 5.092902-7.388294L4.363636-4.483188C4.23213-4.794022 3.90934-5.272229 3.287671-5.272229C1.936737-5.272229 .478207-3.526775 .478207-1.75741C.478207-.573848 1.171606 .119552 1.984558 .119552C2.642092 .119552 3.203985-.394521 3.53873-.789041C3.658281-.083686 4.220174 .119552 4.578829 .119552S5.224408-.095641 5.439601-.526027C5.630884-.932503 5.798257-1.661768 5.798257-1.709589C5.798257-1.769365 5.750436-1.817186 5.678705-1.817186C5.571108-1.817186 5.559153-1.75741 5.511333-1.578082C5.332005-.872727 5.104857-.119552 4.614695-.119552C4.267995-.119552 4.244085-.430386 4.244085-.669489C4.244085-.71731 4.244085-.968369 4.327771-1.303113L6.01345-7.998007ZM3.598506-1.422665C3.53873-1.219427 3.53873-1.195517 3.371357-.968369C3.108344-.633624 2.582316-.119552 2.020423-.119552C1.530262-.119552 1.255293-.561893 1.255293-1.267248C1.255293-1.924782 1.625903-3.263761 1.853051-3.765878C2.259527-4.60274 2.82142-5.033126 3.287671-5.033126C4.076712-5.033126 4.23213-4.052802 4.23213-3.957161C4.23213-3.945205 4.196264-3.789788 4.184309-3.765878L3.598506-1.422665Z'/>
<path id='g0-101' d='M2.139975-2.773599C2.462765-2.773599 3.275716-2.797509 3.849564-3.012702C4.758157-3.359402 4.841843-4.052802 4.841843-4.267995C4.841843-4.794022 4.387547-5.272229 3.598506-5.272229C2.343213-5.272229 .537983-4.136488 .537983-2.008468C.537983-.753176 1.255293 .119552 2.343213 .119552C3.969116 .119552 4.99726-1.147696 4.99726-1.303113C4.99726-1.374844 4.925529-1.43462 4.877709-1.43462C4.841843-1.43462 4.829888-1.422665 4.722291-1.315068C3.957161-.298879 2.82142-.119552 2.367123-.119552C1.685679-.119552 1.327024-.657534 1.327024-1.542217C1.327024-1.709589 1.327024-2.008468 1.506351-2.773599H2.139975ZM1.566127-3.012702C2.080199-4.853798 3.21594-5.033126 3.598506-5.033126C4.124533-5.033126 4.483188-4.722291 4.483188-4.267995C4.483188-3.012702 2.570361-3.012702 2.068244-3.012702H1.566127Z'/>
<path id='g0-105' d='M3.383313-1.709589C3.383313-1.769365 3.335492-1.817186 3.263761-1.817186C3.156164-1.817186 3.144209-1.78132 3.084433-1.578082C2.773599-.490162 2.283437-.119552 1.888917-.119552C1.745455-.119552 1.578082-.155417 1.578082-.514072C1.578082-.836862 1.721544-1.195517 1.853051-1.554172L2.689913-3.777833C2.725778-3.873474 2.809465-4.088667 2.809465-4.315816C2.809465-4.817933 2.450809-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.554919 1.362889-5.033126 1.829141-5.033126C1.936737-5.033126 2.139975-5.021171 2.139975-4.638605C2.139975-4.327771 1.984558-3.93325 1.888917-3.670237L1.052055-1.446575C.980324-1.255293 .908593-1.06401 .908593-.848817C.908593-.310834 1.279203 .119552 1.853051 .119552C2.952927 .119552 3.383313-1.625903 3.383313-1.709589ZM3.287671-7.460025C3.287671-7.639352 3.144209-7.854545 2.881196-7.854545C2.606227-7.854545 2.295392-7.591532 2.295392-7.280697C2.295392-6.981818 2.546451-6.886177 2.689913-6.886177C3.012702-6.886177 3.287671-7.197011 3.287671-7.460025Z'/>
<path id='g0-109' d='M2.462765-3.502864C2.486675-3.574595 2.785554-4.172354 3.227895-4.554919C3.53873-4.841843 3.945205-5.033126 4.411457-5.033126C4.889664-5.033126 5.057036-4.674471 5.057036-4.196264C5.057036-4.124533 5.057036-3.88543 4.913574-3.323537L4.614695-2.092154C4.519054-1.733499 4.291905-.848817 4.267995-.71731C4.220174-.537983 4.148443-.227148 4.148443-.179328C4.148443-.011955 4.27995 .119552 4.459278 .119552C4.817933 .119552 4.877709-.155417 4.985305-.585803L5.702615-3.443088C5.726526-3.53873 6.348194-5.033126 7.663263-5.033126C8.141469-5.033126 8.308842-4.674471 8.308842-4.196264C8.308842-3.526775 7.84259-2.223661 7.579577-1.506351C7.47198-1.219427 7.412204-1.06401 7.412204-.848817C7.412204-.310834 7.782814 .119552 8.356663 .119552C9.468493 .119552 9.886924-1.637858 9.886924-1.709589C9.886924-1.769365 9.839103-1.817186 9.767372-1.817186C9.659776-1.817186 9.647821-1.78132 9.588045-1.578082C9.313076-.621669 8.870735-.119552 8.392528-.119552C8.272976-.119552 8.081694-.131507 8.081694-.514072C8.081694-.824907 8.225156-1.207472 8.272976-1.338979C8.488169-1.912827 9.026152-3.323537 9.026152-4.016936C9.026152-4.734247 8.607721-5.272229 7.699128-5.272229C6.898132-5.272229 6.252553-4.817933 5.774346-4.112578C5.738481-4.758157 5.34396-5.272229 4.447323-5.272229C3.383313-5.272229 2.82142-4.519054 2.606227-4.220174C2.570361-4.901619 2.080199-5.272229 1.554172-5.272229C1.207472-5.272229 .932503-5.104857 .705355-4.65056C.490162-4.220174 .32279-3.490909 .32279-3.443088S.37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.812951-4.327771 1.0401-5.033126 1.518306-5.033126C1.793275-5.033126 1.888917-4.841843 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.350934 .119552 1.518306 .047821 1.613948-.131507C1.637858-.191283 1.745455-.609714 1.80523-.848817L2.068244-1.924782L2.462765-3.502864Z'/>
<path id='g0-110' d='M2.462765-3.502864C2.486675-3.574595 2.785554-4.172354 3.227895-4.554919C3.53873-4.841843 3.945205-5.033126 4.411457-5.033126C4.889664-5.033126 5.057036-4.674471 5.057036-4.196264C5.057036-3.514819 4.566874-2.15193 4.327771-1.506351C4.220174-1.219427 4.160399-1.06401 4.160399-.848817C4.160399-.310834 4.531009 .119552 5.104857 .119552C6.216687 .119552 6.635118-1.637858 6.635118-1.709589C6.635118-1.769365 6.587298-1.817186 6.515567-1.817186C6.40797-1.817186 6.396015-1.78132 6.336239-1.578082C6.06127-.597758 5.606974-.119552 5.140722-.119552C5.021171-.119552 4.829888-.131507 4.829888-.514072C4.829888-.812951 4.961395-1.171606 5.033126-1.338979C5.272229-1.996513 5.774346-3.335492 5.774346-4.016936C5.774346-4.734247 5.355915-5.272229 4.447323-5.272229C3.383313-5.272229 2.82142-4.519054 2.606227-4.220174C2.570361-4.901619 2.080199-5.272229 1.554172-5.272229C1.171606-5.272229 .908593-5.045081 .705355-4.638605C.490162-4.208219 .32279-3.490909 .32279-3.443088S.37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.824907-4.351681 1.0401-5.033126 1.518306-5.033126C1.793275-5.033126 1.888917-4.841843 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.350934 .119552 1.518306 .047821 1.613948-.131507C1.637858-.191283 1.745455-.609714 1.80523-.848817L2.068244-1.924782L2.462765-3.502864Z'/>
<path id='g0-111' d='M5.451557-3.287671C5.451557-4.423412 4.710336-5.272229 3.622416-5.272229C2.044334-5.272229 .490162-3.550685 .490162-1.865006C.490162-.729265 1.231382 .119552 2.319303 .119552C3.90934 .119552 5.451557-1.601993 5.451557-3.287671ZM2.331258-.119552C1.733499-.119552 1.291158-.597758 1.291158-1.43462C1.291158-1.984558 1.578082-3.203985 1.912827-3.801743C2.450809-4.722291 3.120299-5.033126 3.610461-5.033126C4.196264-5.033126 4.65056-4.554919 4.65056-3.718057C4.65056-3.239851 4.399502-1.960648 3.945205-1.231382C3.455044-.430386 2.797509-.119552 2.331258-.119552Z'/>
<path id='g0-112' d='M.514072 1.518306C.430386 1.876961 .382565 1.972603-.107597 1.972603C-.251059 1.972603-.37061 1.972603-.37061 2.199751C-.37061 2.223661-.358655 2.319303-.227148 2.319303C-.071731 2.319303 .095641 2.295392 .251059 2.295392H.765131C1.016189 2.295392 1.625903 2.319303 1.876961 2.319303C1.948692 2.319303 2.092154 2.319303 2.092154 2.10411C2.092154 1.972603 2.008468 1.972603 1.80523 1.972603C1.255293 1.972603 1.219427 1.888917 1.219427 1.793275C1.219427 1.649813 1.75741-.406476 1.829141-.681445C1.960648-.3467 2.283437 .119552 2.905106 .119552C4.25604 .119552 5.71457-1.637858 5.71457-3.395268C5.71457-4.495143 5.092902-5.272229 4.196264-5.272229C3.431133-5.272229 2.785554-4.531009 2.654047-4.363636C2.558406-4.961395 2.092154-5.272229 1.613948-5.272229C1.267248-5.272229 .992279-5.104857 .765131-4.65056C.549938-4.220174 .382565-3.490909 .382565-3.443088S.430386-3.335492 .514072-3.335492C.609714-3.335492 .621669-3.347447 .6934-3.622416C.872727-4.327771 1.099875-5.033126 1.578082-5.033126C1.853051-5.033126 1.948692-4.841843 1.948692-4.483188C1.948692-4.196264 1.912827-4.076712 1.865006-3.861519L.514072 1.518306ZM2.582316-3.730012C2.666002-4.064757 3.000747-4.411457 3.19203-4.578829C3.323537-4.698381 3.718057-5.033126 4.172354-5.033126C4.698381-5.033126 4.937484-4.507098 4.937484-3.88543C4.937484-3.311582 4.60274-1.960648 4.303861-1.338979C4.004981-.6934 3.455044-.119552 2.905106-.119552C2.092154-.119552 1.960648-1.147696 1.960648-1.195517C1.960648-1.231382 1.984558-1.327024 1.996513-1.3868L2.582316-3.730012Z'/>
<path id='g0-113' d='M5.272229-5.152677C5.272229-5.212453 5.224408-5.260274 5.164633-5.260274C5.068991-5.260274 4.60274-4.829888 4.375592-4.411457C4.160399-4.94944 3.789788-5.272229 3.275716-5.272229C1.924782-5.272229 .466252-3.526775 .466252-1.75741C.466252-.573848 1.159651 .119552 1.972603 .119552C2.606227 .119552 3.132254-.358655 3.383313-.633624L3.395268-.621669L2.940971 1.171606L2.833375 1.601993C2.725778 1.960648 2.546451 1.960648 1.984558 1.972603C1.853051 1.972603 1.733499 1.972603 1.733499 2.199751C1.733499 2.283437 1.80523 2.319303 1.888917 2.319303C2.056289 2.319303 2.271482 2.295392 2.438854 2.295392H3.658281C3.837609 2.295392 4.040847 2.319303 4.220174 2.319303C4.291905 2.319303 4.435367 2.319303 4.435367 2.092154C4.435367 1.972603 4.339726 1.972603 4.160399 1.972603C3.598506 1.972603 3.56264 1.888917 3.56264 1.793275C3.56264 1.733499 3.574595 1.721544 3.610461 1.566127L5.272229-5.152677ZM3.58655-1.422665C3.526775-1.219427 3.526775-1.195517 3.359402-.968369C3.096389-.633624 2.570361-.119552 2.008468-.119552C1.518306-.119552 1.243337-.561893 1.243337-1.267248C1.243337-1.924782 1.613948-3.263761 1.841096-3.765878C2.247572-4.60274 2.809465-5.033126 3.275716-5.033126C4.064757-5.033126 4.220174-4.052802 4.220174-3.957161C4.220174-3.945205 4.184309-3.789788 4.172354-3.765878L3.58655-1.422665Z'/>
<path id='g0-114' d='M4.65056-4.889664C4.27995-4.817933 4.088667-4.554919 4.088667-4.291905C4.088667-4.004981 4.315816-3.90934 4.483188-3.90934C4.817933-3.90934 5.092902-4.196264 5.092902-4.554919C5.092902-4.937484 4.722291-5.272229 4.124533-5.272229C3.646326-5.272229 3.096389-5.057036 2.594271-4.327771C2.510585-4.961395 2.032379-5.272229 1.554172-5.272229C1.08792-5.272229 .848817-4.913574 .705355-4.65056C.502117-4.220174 .32279-3.502864 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.812951-4.339726 1.0401-5.033126 1.518306-5.033126C1.80523-5.033126 1.888917-4.829888 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.338979 .119552 1.566127 .035866 1.637858-.203238C1.673724-.298879 2.116065-2.10411 2.187796-2.379078C2.247572-2.642092 2.319303-2.893151 2.379078-3.156164C2.426899-3.323537 2.47472-3.514819 2.510585-3.670237C2.546451-3.777833 2.86924-4.363636 3.16812-4.62665C3.311582-4.758157 3.622416-5.033126 4.112578-5.033126C4.303861-5.033126 4.495143-4.99726 4.65056-4.889664Z'/>
<path id='g0-115' d='M2.725778-2.391034C2.929016-2.355168 3.251806-2.283437 3.323537-2.271482C3.478954-2.223661 4.016936-2.032379 4.016936-1.458531C4.016936-1.08792 3.682192-.119552 2.295392-.119552C2.044334-.119552 1.147696-.155417 .908593-.812951C1.3868-.753176 1.625903-1.123786 1.625903-1.3868C1.625903-1.637858 1.458531-1.769365 1.219427-1.769365C.956413-1.769365 .609714-1.566127 .609714-1.028144C.609714-.32279 1.327024 .119552 2.283437 .119552C4.100623 .119552 4.638605-1.219427 4.638605-1.841096C4.638605-2.020423 4.638605-2.355168 4.25604-2.737733C3.957161-3.024658 3.670237-3.084433 3.024658-3.21594C2.701868-3.287671 2.187796-3.395268 2.187796-3.93325C2.187796-4.172354 2.402989-5.033126 3.53873-5.033126C4.040847-5.033126 4.531009-4.841843 4.65056-4.411457C4.124533-4.411457 4.100623-3.957161 4.100623-3.945205C4.100623-3.694147 4.327771-3.622416 4.435367-3.622416C4.60274-3.622416 4.937484-3.753923 4.937484-4.25604S4.483188-5.272229 3.550685-5.272229C1.984558-5.272229 1.566127-4.040847 1.566127-3.550685C1.566127-2.642092 2.450809-2.450809 2.725778-2.391034Z'/>
<path id='g0-116' d='M2.402989-4.805978H3.502864C3.730012-4.805978 3.849564-4.805978 3.849564-5.021171C3.849564-5.152677 3.777833-5.152677 3.53873-5.152677H2.486675L2.929016-6.898132C2.976837-7.065504 2.976837-7.089415 2.976837-7.173101C2.976837-7.364384 2.82142-7.47198 2.666002-7.47198C2.570361-7.47198 2.295392-7.436115 2.199751-7.053549L1.733499-5.152677H.609714C.37061-5.152677 .263014-5.152677 .263014-4.925529C.263014-4.805978 .3467-4.805978 .573848-4.805978H1.637858L.848817-1.649813C.753176-1.231382 .71731-1.111831 .71731-.956413C.71731-.394521 1.111831 .119552 1.78132 .119552C2.988792 .119552 3.634371-1.625903 3.634371-1.709589C3.634371-1.78132 3.58655-1.817186 3.514819-1.817186C3.490909-1.817186 3.443088-1.817186 3.419178-1.769365C3.407223-1.75741 3.395268-1.745455 3.311582-1.554172C3.060523-.956413 2.510585-.119552 1.817186-.119552C1.458531-.119552 1.43462-.418431 1.43462-.681445C1.43462-.6934 1.43462-.920548 1.470486-1.06401L2.402989-4.805978Z'/>
<path id='g0-117' d='M4.076712-.6934C4.23213-.02391 4.805978 .119552 5.092902 .119552C5.475467 .119552 5.762391-.131507 5.953674-.537983C6.156912-.968369 6.312329-1.673724 6.312329-1.709589C6.312329-1.769365 6.264508-1.817186 6.192777-1.817186C6.085181-1.817186 6.073225-1.75741 6.025405-1.578082C5.810212-.753176 5.595019-.119552 5.116812-.119552C4.758157-.119552 4.758157-.514072 4.758157-.669489C4.758157-.944458 4.794022-1.06401 4.913574-1.566127C4.99726-1.888917 5.080946-2.211706 5.152677-2.546451L5.642839-4.495143C5.726526-4.794022 5.726526-4.817933 5.726526-4.853798C5.726526-5.033126 5.583064-5.152677 5.403736-5.152677C5.057036-5.152677 4.97335-4.853798 4.901619-4.554919C4.782067-4.088667 4.136488-1.518306 4.052802-1.099875C4.040847-1.099875 3.574595-.119552 2.701868-.119552C2.080199-.119552 1.960648-.657534 1.960648-1.099875C1.960648-1.78132 2.295392-2.737733 2.606227-3.53873C2.749689-3.921295 2.809465-4.076712 2.809465-4.315816C2.809465-4.829888 2.438854-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.578829 1.374844-5.033126 1.829141-5.033126C1.948692-5.033126 2.139975-5.021171 2.139975-4.638605C2.139975-4.327771 2.008468-3.981071 1.829141-3.526775C1.303113-2.10411 1.243337-1.649813 1.243337-1.291158C1.243337-.071731 2.163885 .119552 2.654047 .119552C3.419178 .119552 3.837609-.406476 4.076712-.6934Z'/>
<path id='g0-121' d='M3.144209 1.338979C2.82142 1.793275 2.355168 2.199751 1.769365 2.199751C1.625903 2.199751 1.052055 2.175841 .872727 1.625903C.908593 1.637858 .968369 1.637858 .992279 1.637858C1.350934 1.637858 1.590037 1.327024 1.590037 1.052055S1.362889 .681445 1.183562 .681445C.992279 .681445 .573848 .824907 .573848 1.41071C.573848 2.020423 1.08792 2.438854 1.769365 2.438854C2.964882 2.438854 4.172354 1.338979 4.507098 .011955L5.678705-4.65056C5.69066-4.710336 5.71457-4.782067 5.71457-4.853798C5.71457-5.033126 5.571108-5.152677 5.391781-5.152677C5.284184-5.152677 5.033126-5.104857 4.937484-4.746202L4.052802-1.231382C3.993026-1.016189 3.993026-.992279 3.897385-.860772C3.658281-.526027 3.263761-.119552 2.689913-.119552C2.020423-.119552 1.960648-.777086 1.960648-1.099875C1.960648-1.78132 2.283437-2.701868 2.606227-3.56264C2.737733-3.90934 2.809465-4.076712 2.809465-4.315816C2.809465-4.817933 2.450809-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.554919 1.362889-5.033126 1.829141-5.033126C1.936737-5.033126 2.139975-5.033126 2.139975-4.638605C2.139975-4.327771 2.008468-3.981071 1.829141-3.526775C1.243337-1.960648 1.243337-1.566127 1.243337-1.279203C1.243337-.143462 2.056289 .119552 2.654047 .119552C3.000747 .119552 3.431133 .011955 3.849564-.430386L3.861519-.418431C3.682192 .286924 3.56264 .753176 3.144209 1.338979Z'/>
</defs>
<g id='page1' transform='matrix(1.13 0 0 1.13 -63.986043 -64.41)'>
<use x='56.413267' y='65.753425' xlink:href='#g0-109'/>
<use x='66.652534' y='65.753425' xlink:href='#g0-101'/>
<use x='72.077974' y='65.753425' xlink:href='#g0-109'/>
<use x='82.317241' y='65.753425' xlink:href='#g0-111'/>
<use x='87.944679' y='65.753425' xlink:href='#g0-114'/>
<use x='93.545152' y='65.753425' xlink:href='#g0-121'/>
<use x='99.681804' y='65.753425' xlink:href='#g0-58'/>
<use x='102.933465' y='65.753425' xlink:href='#g0-109'/>
<use x='113.172732' y='65.753425' xlink:href='#g0-105'/>
<use x='117.166164' y='65.753425' xlink:href='#g0-110'/>
<use x='127.474599' y='65.753425' xlink:href='#g1-61'/>
<use x='139.90008' y='65.753425' xlink:href='#g0-112'/>
<use x='145.775223' y='65.753425' xlink:href='#g0-111'/>
<use x='151.402661' y='65.753425' xlink:href='#g0-100'/>
<use x='157.485354' y='65.753425' xlink:href='#g0-58'/>
<use x='160.737015' y='65.753425' xlink:href='#g0-115'/>
<use x='166.251021' y='65.753425' xlink:href='#g0-112'/>
<use x='172.126164' y='65.753425' xlink:href='#g0-101'/>
<use x='177.551604' y='65.753425' xlink:href='#g0-99'/>
<use x='182.589592' y='65.753425' xlink:href='#g0-58'/>
<use x='185.841254' y='65.753425' xlink:href='#g0-99'/>
<use x='190.879242' y='65.753425' xlink:href='#g0-111'/>
<use x='196.50668' y='65.753425' xlink:href='#g0-110'/>
<use x='203.494285' y='65.753425' xlink:href='#g0-116'/>
<use x='207.721445' y='65.753425' xlink:href='#g0-97'/>
<use x='213.866389' y='65.753425' xlink:href='#g0-105'/>
<use x='217.859822' y='65.753425' xlink:href='#g0-110'/>
<use x='224.847427' y='65.753425' xlink:href='#g0-101'/>
<use x='230.272867' y='65.753425' xlink:href='#g0-114'/>
<use x='235.873341' y='65.753425' xlink:href='#g0-115'/>
<use x='241.387347' y='65.753425' xlink:href='#g1-91'/>
<use x='244.639008' y='65.753425' xlink:href='#g0-105'/>
<use x='248.63244' y='65.753425' xlink:href='#g1-93'/>
<use x='251.884101' y='65.753425' xlink:href='#g0-58'/>
<use x='255.135763' y='65.753425' xlink:href='#g0-114'/>
<use x='260.736236' y='65.753425' xlink:href='#g0-101'/>
<use x='266.161676' y='65.753425' xlink:href='#g0-115'/>
<use x='271.675682' y='65.753425' xlink:href='#g0-111'/>
<use x='277.303119' y='65.753425' xlink:href='#g0-117'/>
<use x='283.965559' y='65.753425' xlink:href='#g0-114'/>
<use x='289.566032' y='65.753425' xlink:href='#g0-99'/>
<use x='294.604021' y='65.753425' xlink:href='#g0-101'/>
<use x='300.029461' y='65.753425' xlink:href='#g0-115'/>
<use x='305.543467' y='65.753425' xlink:href='#g0-58'/>
<use x='308.795128' y='65.753425' xlink:href='#g0-114'/>
<use x='314.395601' y='65.753425' xlink:href='#g0-101'/>
<use x='319.821042' y='65.753425' xlink:href='#g0-113'/>
<use x='325.440198' y='65.753425' xlink:href='#g0-117'/>
<use x='332.102638' y='65.753425' xlink:href='#g0-101'/>
<use x='337.528078' y='65.753425' xlink:href='#g0-115'/>
<use x='343.042083' y='65.753425' xlink:href='#g0-116'/>
<use x='347.269243' y='65.753425' xlink:href='#g0-115'/>
<use x='352.783249' y='65.753425' xlink:href='#g1-91'/>
<use x='356.03491' y='65.753425' xlink:href='#g0-109'/>
<use x='366.274177' y='65.753425' xlink:href='#g0-101'/>
<use x='371.699617' y='65.753425' xlink:href='#g0-109'/>
<use x='381.938884' y='65.753425' xlink:href='#g0-111'/>
<use x='387.566322' y='65.753425' xlink:href='#g0-114'/>
<use x='393.166795' y='65.753425' xlink:href='#g0-121'/>
<use x='399.303447' y='65.753425' xlink:href='#g1-93'/>
</g>
</svg>

After

Width:  |  Height:  |  Size: 23 KiB

@@ -0,0 +1,118 @@
---
layout: blog
title: 'Quality-of-Service for Memory Resources'
date: 2021-11-26
slug: qos-memory-resources
---
**Authors:** Tim Xu (Tencent Cloud)
Kubernetes v1.22, released in August 2021, introduced a new alpha feature that improves how Linux nodes implement memory resource requests and limits.
In prior releases, Kubernetes did not support memory quality guarantees.
For example, if you set container resources as follows:
```
apiVersion: v1
kind: Pod
metadata:
name: example
spec:
containers:
- name: nginx
resources:
requests:
memory: "64Mi"
cpu: "250m"
limits:
memory: "64Mi"
cpu: "500m"
```
`spec.containers[].resources.requests`(e.g. cpu, memory) is designed for scheduling. When you create a Pod, the Kubernetes scheduler selects a node for the Pod to run on. Each node has a maximum capacity for each of the resource types: the amount of CPU and memory it can provide for Pods. The scheduler ensures that, for each resource type, the sum of the resource requests of the scheduled Containers is less than the capacity of the node.
`spec.containers[].resources.limits` is passed to the container runtime when the kubelet starts a container. CPU is considered a "compressible" resource. If your app starts hitting your CPU limits, Kubernetes starts throttling your container, giving your app potentially worse performance. However, it wont be terminated. That is what "compressible" means.
In cgroup v1, and prior to this feature, the container runtime never took into account and effectively ignored spec.containers[].resources.requests["memory"]. This is unlike CPU, in which the container runtime consider both requests and limits. Furthermore, memory actually can't be compressed in cgroup v1. Because there is no way to throttle memory usage, if a container goes past its memory limit it will be terminated by the kernel with an OOM (Out of Memory) kill.
Fortunately, cgroup v2 brings a new design and implementation to achieve full protection on memory. The new feature relies on cgroups v2 which most current operating system releases for Linux already provide. With this experimental feature, [quality-of-service for pods and containers](/docs/tasks/configure-pod-container/quality-service-pod/) extends to cover not just CPU time but memory as well.
## How does it work?
Memory QoS uses the memory controller of cgroup v2 to guarantee memory resources in Kubernetes. Memory requests and limits of containers in pod are used to set specific interfaces `memory.min` and `memory.high` provided by the memory controller. When `memory.min` is set to memory requests, memory resources are reserved and never reclaimed by the kernel; this is how Memory QoS ensures the availability of memory for Kubernetes pods. And if memory limits are set in the container, this means that the system needs to limit container memory usage, Memory QoS uses `memory.high` to throttle workload approaching it's memory limit, ensuring that the system is not overwhelmed by instantaneous memory allocation.
![](./memory-qos-cal.svg)
The following table details the specific functions of these two parameters and how they correspond to Kubernetes container resources.
<table>
<tr>
<th style="text-align:center">File</th>
<th style="text-align:center">Description</th>
</tr>
<tr>
<td>memory.min</td>
<td><code>memory.min</code> specifies a minimum amount of memory the cgroup must always retain, i.e., memory that can never be reclaimed by the system. If the cgroup's memory usage reaches this low limit and cant be increased, the system OOM killer will be invoked.
<br>
<br>
<i>We map it to the container's memory request</i>
</td>
</tr>
<tr>
<td>memory.high</td>
<td><code>memory.high</code> is the memory usage throttle limit. This is the main mechanism to control a cgroup's memory use. If a cgroup's memory use goes over the high boundary specified here, the cgroups processes are throttled and put under heavy reclaim pressure. The default is max, meaning there is no limit.
<br>
<br>
<i>We use a formula to calculate <code>memory.high</code>, depending on container's memory limit or node allocatable memory (if container's memory limit is empty) and a throttling factor. Please refer to the KEP for more details on the formula.</i>
</td>
</tr>
</table>
When container memory requests are made, kubelet passes `memory.min` to the back-end CRI runtime (possibly containerd, cri-o) via the `Unified` field in CRI during container creation. The `memory.min` in container level cgroup will be set to:
![](./container-memory-min.svg)
<sub>i: the i<sup>th</sup> container in one pod</sub>
Since the `memory.min` interface requires that the ancestor cgroup directories are all set, the pod and node cgroup directories need to be set correctly.
`memory.min` in pod level cgroup:
![](./pod-memory-min.svg)
<sub>i: the i<sup>th</sup> container in one pod</sub>
`memory.min` in node level cgroup:
![](./node-memory-min.svg)
<sub>i: the i<sup>th</sup> pod in one node, j: the j<sup>th</sup> container in one pod</sub>
Kubelet will manage the cgroup hierarchy of the pod level and node level cgroups directly using runc libcontainer library, while container cgroup limits are managed by the container runtime.
For memory limits, in addition to the original way of limiting memory usage, Memory QoS adds an additional feature of throttling memory allocation. A throttling factor is introduced as a multiplier (default is 0.8). If the result of multiplying memory limits by the factor is greater than memory requests, kubelet will set `memory.high` to the value and use `Unified` via CRI. And if the container does not specify memory limits, kubelet will use node allocatable memory instead. The `memory.high` in container level cgroup is set to:
![](./container-memory-high.svg)
<sub>i: the i<sup>th</sup> container in one pod</sub>
This can can help improve stability when pod memory usage increases, ensuring that memory is throttled as it approaches the memory limit.
## How do I use it?
Here are the prerequisites for enabling Memory QoS on your Linux node, some of these are related to [Kubernetes support for cgroup v2](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2254-cgroup-v2).
1. Kubernetes since v1.22
2. [runc](https://github.com/opencontainers/runc) since v1.0.0-rc93; [containerd](https://containerd.io/) since 1.4; [cri-o](https://cri-o.io/) since 1.20
3. Linux kernel minimum version: 4.15, recommended version: 5.2+
4. Linux image with cgroupv2 enabled or enabling cgroupv2 unified_cgroup_hierarchy manually
OCI runtimes such as runc and crun already support cgroups v2 [`Unified`](https://github.com/opencontainers/runtime-spec/blob/master/config-linux.md#unified), and Kubernetes CRI has also made the desired changes to support passing [`Unified`](https://github.com/kubernetes/kubernetes/pull/102578). However, CRI Runtime support is required as well. Memory QoS in Alpha phase is designed to support containerd and cri-o. Related PR [Feature: containerd-cri support LinuxContainerResources.Unified #5627](https://github.com/containerd/containerd/pull/5627) has been merged and will be released in containerd 1.6. CRI-O [implement kube alpha features for 1.22 #5207](https://github.com/cri-o/cri-o/pull/5207) is still in WIP.
With those prerequisites met, you can enable the memory QoS feature gate (see [Set kubelet parameters via a config file](/docs/tasks/administer-cluster/kubelet-config-file/)).
## How can I learn more?
You can find more details as follows:
- [Support Memory QoS with cgroup v2](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2570-memory-qos/#readme)
- [cgroup v2](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2254-cgroup-v2/#readme)
## How do I get involved?
You can reach SIG Node by several means:
- Slack: [#sig-node](https://kubernetes.slack.com/messages/sig-node)
- [Mailing list](https://groups.google.com/forum/#!forum/kubernetes-sig-node)
- [Open Community Issues/PRs](https://github.com/kubernetes/community/labels/sig%2Fnode)
You can also contact me directly:
- GitHub / Slack: @xiaoxubeii
- Email: xiaoxubeii@gmail.com
File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 63 KiB

@@ -0,0 +1,98 @@
<?xml version='1.0' encoding='UTF-8'?>
<!-- Generated by CodeCogs with dvisvgm 2.9.1 -->
<svg version='1.1' xmlns='http://www.w3.org/2000/svg' xmlns:xlink='http://www.w3.org/1999/xlink' width='446.671233pt' height='30.306891pt' viewBox='-.239051 -.248234 446.671233 30.306891'>
<defs>
<path id='g0-88' d='M15.135243 16.737235L16.581818 12.911582H16.282939C15.816687 14.154919 14.54944 14.96787 13.174595 15.326526C12.923537 15.386301 11.75193 15.697136 9.456538 15.697136H2.247572L8.332752 8.5599C8.416438 8.464259 8.440349 8.428394 8.440349 8.368618C8.440349 8.344707 8.440349 8.308842 8.356663 8.18929L2.785554 .573848H9.336986C10.938979 .573848 12.026899 .74122 12.134496 .765131C12.780075 .860772 13.820174 1.06401 14.764633 1.661768C15.063512 1.853051 15.876463 2.391034 16.282939 3.359402H16.581818L15.135243 0H1.004234C.729265 0 .71731 .011955 .681445 .083686C.669489 .119552 .669489 .3467 .669489 .478207L6.993773 9.133748L.800996 16.390535C.681445 16.533998 .681445 16.593773 .681445 16.605729C.681445 16.737235 .789041 16.737235 1.004234 16.737235H15.135243Z'/>
<path id='g1-105' d='M2.375093-4.97335C2.375093-5.148692 2.247572-5.276214 2.064259-5.276214C1.857036-5.276214 1.625903-5.084932 1.625903-4.845828C1.625903-4.670486 1.753425-4.542964 1.936737-4.542964C2.14396-4.542964 2.375093-4.734247 2.375093-4.97335ZM1.211457-2.048319L.781071-.948443C.74122-.828892 .70137-.73325 .70137-.597758C.70137-.207223 1.004234 .079701 1.42665 .079701C2.199751 .079701 2.526526-1.036115 2.526526-1.139726C2.526526-1.219427 2.462765-1.243337 2.406974-1.243337C2.311333-1.243337 2.295392-1.187547 2.271482-1.107846C2.088169-.470237 1.761395-.143462 1.44259-.143462C1.346949-.143462 1.251308-.183313 1.251308-.398506C1.251308-.589788 1.307098-.73325 1.41071-.980324C1.490411-1.195517 1.570112-1.41071 1.657783-1.625903L1.904857-2.271482C1.976588-2.454795 2.072229-2.701868 2.072229-2.83736C2.072229-3.235866 1.753425-3.514819 1.346949-3.514819C.573848-3.514819 .239103-2.399004 .239103-2.295392C.239103-2.223661 .294894-2.191781 .358655-2.191781C.462267-2.191781 .470237-2.239601 .494147-2.319303C.71731-3.076463 1.083935-3.291656 1.323039-3.291656C1.43462-3.291656 1.514321-3.251806 1.514321-3.028643C1.514321-2.948941 1.506351-2.83736 1.42665-2.598257L1.211457-2.048319Z'/>
<path id='g1-106' d='M3.291656-4.97335C3.291656-5.124782 3.172105-5.276214 2.980822-5.276214C2.741719-5.276214 2.534496-5.053051 2.534496-4.845828C2.534496-4.694396 2.654047-4.542964 2.84533-4.542964C3.084433-4.542964 3.291656-4.766127 3.291656-4.97335ZM1.625903 .398506C1.506351 .884682 1.115816 1.40274 .629639 1.40274C.502117 1.40274 .382565 1.370859 .366625 1.362889C.613699 1.243337 .645579 1.028144 .645579 .956413C.645579 .765131 .502117 .661519 .334745 .661519C.103611 .661519-.111582 .860772-.111582 1.123786C-.111582 1.42665 .183313 1.625903 .637609 1.625903C1.123786 1.625903 2.000498 1.323039 2.239601 .366625L2.956912-2.486675C2.980822-2.582316 2.996762-2.646077 2.996762-2.765629C2.996762-3.203985 2.646077-3.514819 2.183811-3.514819C1.338979-3.514819 .844832-2.399004 .844832-2.295392C.844832-2.223661 .900623-2.191781 .964384-2.191781C1.052055-2.191781 1.060025-2.215691 1.115816-2.335243C1.354919-2.885181 1.761395-3.291656 2.1599-3.291656C2.327273-3.291656 2.422914-3.180075 2.422914-2.917061C2.422914-2.805479 2.399004-2.693898 2.375093-2.582316L1.625903 .398506Z'/>
<path id='g3-61' d='M8.069738-3.873474C8.237111-3.873474 8.452304-3.873474 8.452304-4.088667C8.452304-4.315816 8.249066-4.315816 8.069738-4.315816H1.028144C.860772-4.315816 .645579-4.315816 .645579-4.100623C.645579-3.873474 .848817-3.873474 1.028144-3.873474H8.069738ZM8.069738-1.649813C8.237111-1.649813 8.452304-1.649813 8.452304-1.865006C8.452304-2.092154 8.249066-2.092154 8.069738-2.092154H1.028144C.860772-2.092154 .645579-2.092154 .645579-1.876961C.645579-1.649813 .848817-1.649813 1.028144-1.649813H8.069738Z'/>
<path id='g3-91' d='M2.988792 2.988792V2.546451H1.829141V-8.524035H2.988792V-8.966376H1.3868V2.988792H2.988792Z'/>
<path id='g3-93' d='M1.853051-8.966376H.251059V-8.524035H1.41071V2.546451H.251059V2.988792H1.853051V-8.966376Z'/>
<path id='g2-58' d='M2.199751-.573848C2.199751-.920548 1.912827-1.159651 1.625903-1.159651C1.279203-1.159651 1.0401-.872727 1.0401-.585803C1.0401-.239103 1.327024 0 1.613948 0C1.960648 0 2.199751-.286924 2.199751-.573848Z'/>
<path id='g2-97' d='M3.598506-1.422665C3.53873-1.219427 3.53873-1.195517 3.371357-.968369C3.108344-.633624 2.582316-.119552 2.020423-.119552C1.530262-.119552 1.255293-.561893 1.255293-1.267248C1.255293-1.924782 1.625903-3.263761 1.853051-3.765878C2.259527-4.60274 2.82142-5.033126 3.287671-5.033126C4.076712-5.033126 4.23213-4.052802 4.23213-3.957161C4.23213-3.945205 4.196264-3.789788 4.184309-3.765878L3.598506-1.422665ZM4.363636-4.483188C4.23213-4.794022 3.90934-5.272229 3.287671-5.272229C1.936737-5.272229 .478207-3.526775 .478207-1.75741C.478207-.573848 1.171606 .119552 1.984558 .119552C2.642092 .119552 3.203985-.394521 3.53873-.789041C3.658281-.083686 4.220174 .119552 4.578829 .119552S5.224408-.095641 5.439601-.526027C5.630884-.932503 5.798257-1.661768 5.798257-1.709589C5.798257-1.769365 5.750436-1.817186 5.678705-1.817186C5.571108-1.817186 5.559153-1.75741 5.511333-1.578082C5.332005-.872727 5.104857-.119552 4.614695-.119552C4.267995-.119552 4.244085-.430386 4.244085-.669489C4.244085-.944458 4.27995-1.075965 4.387547-1.542217C4.471233-1.841096 4.531009-2.10411 4.62665-2.450809C5.068991-4.244085 5.176588-4.674471 5.176588-4.746202C5.176588-4.913574 5.045081-5.045081 4.865753-5.045081C4.483188-5.045081 4.387547-4.62665 4.363636-4.483188Z'/>
<path id='g2-99' d='M4.674471-4.495143C4.447323-4.495143 4.339726-4.495143 4.172354-4.351681C4.100623-4.291905 3.969116-4.112578 3.969116-3.921295C3.969116-3.682192 4.148443-3.53873 4.375592-3.53873C4.662516-3.53873 4.985305-3.777833 4.985305-4.25604C4.985305-4.829888 4.435367-5.272229 3.610461-5.272229C2.044334-5.272229 .478207-3.56264 .478207-1.865006C.478207-.824907 1.123786 .119552 2.343213 .119552C3.969116 .119552 4.99726-1.147696 4.99726-1.303113C4.99726-1.374844 4.925529-1.43462 4.877709-1.43462C4.841843-1.43462 4.829888-1.422665 4.722291-1.315068C3.957161-.298879 2.82142-.119552 2.367123-.119552C1.542217-.119552 1.279203-.836862 1.279203-1.43462C1.279203-1.853051 1.482441-3.012702 1.912827-3.825654C2.223661-4.387547 2.86924-5.033126 3.622416-5.033126C3.777833-5.033126 4.435367-5.009215 4.674471-4.495143Z'/>
<path id='g2-100' d='M6.01345-7.998007C6.025405-8.045828 6.049315-8.117559 6.049315-8.177335C6.049315-8.296887 5.929763-8.296887 5.905853-8.296887C5.893898-8.296887 5.308095-8.249066 5.248319-8.237111C5.045081-8.225156 4.865753-8.201245 4.65056-8.18929C4.351681-8.16538 4.267995-8.153425 4.267995-7.938232C4.267995-7.81868 4.363636-7.81868 4.531009-7.81868C5.116812-7.81868 5.128767-7.711083 5.128767-7.591532C5.128767-7.519801 5.104857-7.424159 5.092902-7.388294L4.363636-4.483188C4.23213-4.794022 3.90934-5.272229 3.287671-5.272229C1.936737-5.272229 .478207-3.526775 .478207-1.75741C.478207-.573848 1.171606 .119552 1.984558 .119552C2.642092 .119552 3.203985-.394521 3.53873-.789041C3.658281-.083686 4.220174 .119552 4.578829 .119552S5.224408-.095641 5.439601-.526027C5.630884-.932503 5.798257-1.661768 5.798257-1.709589C5.798257-1.769365 5.750436-1.817186 5.678705-1.817186C5.571108-1.817186 5.559153-1.75741 5.511333-1.578082C5.332005-.872727 5.104857-.119552 4.614695-.119552C4.267995-.119552 4.244085-.430386 4.244085-.669489C4.244085-.71731 4.244085-.968369 4.327771-1.303113L6.01345-7.998007ZM3.598506-1.422665C3.53873-1.219427 3.53873-1.195517 3.371357-.968369C3.108344-.633624 2.582316-.119552 2.020423-.119552C1.530262-.119552 1.255293-.561893 1.255293-1.267248C1.255293-1.924782 1.625903-3.263761 1.853051-3.765878C2.259527-4.60274 2.82142-5.033126 3.287671-5.033126C4.076712-5.033126 4.23213-4.052802 4.23213-3.957161C4.23213-3.945205 4.196264-3.789788 4.184309-3.765878L3.598506-1.422665Z'/>
<path id='g2-101' d='M2.139975-2.773599C2.462765-2.773599 3.275716-2.797509 3.849564-3.012702C4.758157-3.359402 4.841843-4.052802 4.841843-4.267995C4.841843-4.794022 4.387547-5.272229 3.598506-5.272229C2.343213-5.272229 .537983-4.136488 .537983-2.008468C.537983-.753176 1.255293 .119552 2.343213 .119552C3.969116 .119552 4.99726-1.147696 4.99726-1.303113C4.99726-1.374844 4.925529-1.43462 4.877709-1.43462C4.841843-1.43462 4.829888-1.422665 4.722291-1.315068C3.957161-.298879 2.82142-.119552 2.367123-.119552C1.685679-.119552 1.327024-.657534 1.327024-1.542217C1.327024-1.709589 1.327024-2.008468 1.506351-2.773599H2.139975ZM1.566127-3.012702C2.080199-4.853798 3.21594-5.033126 3.598506-5.033126C4.124533-5.033126 4.483188-4.722291 4.483188-4.267995C4.483188-3.012702 2.570361-3.012702 2.068244-3.012702H1.566127Z'/>
<path id='g2-105' d='M3.383313-1.709589C3.383313-1.769365 3.335492-1.817186 3.263761-1.817186C3.156164-1.817186 3.144209-1.78132 3.084433-1.578082C2.773599-.490162 2.283437-.119552 1.888917-.119552C1.745455-.119552 1.578082-.155417 1.578082-.514072C1.578082-.836862 1.721544-1.195517 1.853051-1.554172L2.689913-3.777833C2.725778-3.873474 2.809465-4.088667 2.809465-4.315816C2.809465-4.817933 2.450809-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.554919 1.362889-5.033126 1.829141-5.033126C1.936737-5.033126 2.139975-5.021171 2.139975-4.638605C2.139975-4.327771 1.984558-3.93325 1.888917-3.670237L1.052055-1.446575C.980324-1.255293 .908593-1.06401 .908593-.848817C.908593-.310834 1.279203 .119552 1.853051 .119552C2.952927 .119552 3.383313-1.625903 3.383313-1.709589ZM3.287671-7.460025C3.287671-7.639352 3.144209-7.854545 2.881196-7.854545C2.606227-7.854545 2.295392-7.591532 2.295392-7.280697C2.295392-6.981818 2.546451-6.886177 2.689913-6.886177C3.012702-6.886177 3.287671-7.197011 3.287671-7.460025Z'/>
<path id='g2-106' d='M4.184309-3.789788C4.23213-3.981071 4.23213-4.148443 4.23213-4.196264C4.23213-4.889664 3.718057-5.272229 3.180075-5.272229C1.972603-5.272229 1.327024-3.526775 1.327024-3.443088C1.327024-3.383313 1.374844-3.335492 1.446575-3.335492C1.542217-3.335492 1.554172-3.383313 1.613948-3.502864C2.092154-4.662516 2.689913-5.033126 3.144209-5.033126C3.395268-5.033126 3.526775-4.901619 3.526775-4.483188C3.526775-4.196264 3.490909-4.076712 3.443088-3.861519L2.307347 .645579C2.080199 1.530262 1.518306 2.199751 .860772 2.199751C.812951 2.199751 .561893 2.199751 .334745 2.080199C.621669 2.020423 .848817 1.793275 .848817 1.506351C.848817 1.315068 .705355 1.123786 .442341 1.123786C.131507 1.123786-.155417 1.3868-.155417 1.745455C-.155417 2.235616 .37061 2.438854 .860772 2.438854C1.685679 2.438854 2.773599 1.829141 3.072478 .633624L4.184309-3.789788ZM4.674471-7.460025C4.674471-7.758904 4.423412-7.854545 4.27995-7.854545C3.957161-7.854545 3.682192-7.543711 3.682192-7.280697C3.682192-7.10137 3.825654-6.886177 4.088667-6.886177C4.363636-6.886177 4.674471-7.149191 4.674471-7.460025Z'/>
<path id='g2-109' d='M2.462765-3.502864C2.486675-3.574595 2.785554-4.172354 3.227895-4.554919C3.53873-4.841843 3.945205-5.033126 4.411457-5.033126C4.889664-5.033126 5.057036-4.674471 5.057036-4.196264C5.057036-4.124533 5.057036-3.88543 4.913574-3.323537L4.614695-2.092154C4.519054-1.733499 4.291905-.848817 4.267995-.71731C4.220174-.537983 4.148443-.227148 4.148443-.179328C4.148443-.011955 4.27995 .119552 4.459278 .119552C4.817933 .119552 4.877709-.155417 4.985305-.585803L5.702615-3.443088C5.726526-3.53873 6.348194-5.033126 7.663263-5.033126C8.141469-5.033126 8.308842-4.674471 8.308842-4.196264C8.308842-3.526775 7.84259-2.223661 7.579577-1.506351C7.47198-1.219427 7.412204-1.06401 7.412204-.848817C7.412204-.310834 7.782814 .119552 8.356663 .119552C9.468493 .119552 9.886924-1.637858 9.886924-1.709589C9.886924-1.769365 9.839103-1.817186 9.767372-1.817186C9.659776-1.817186 9.647821-1.78132 9.588045-1.578082C9.313076-.621669 8.870735-.119552 8.392528-.119552C8.272976-.119552 8.081694-.131507 8.081694-.514072C8.081694-.824907 8.225156-1.207472 8.272976-1.338979C8.488169-1.912827 9.026152-3.323537 9.026152-4.016936C9.026152-4.734247 8.607721-5.272229 7.699128-5.272229C6.898132-5.272229 6.252553-4.817933 5.774346-4.112578C5.738481-4.758157 5.34396-5.272229 4.447323-5.272229C3.383313-5.272229 2.82142-4.519054 2.606227-4.220174C2.570361-4.901619 2.080199-5.272229 1.554172-5.272229C1.207472-5.272229 .932503-5.104857 .705355-4.65056C.490162-4.220174 .32279-3.490909 .32279-3.443088S.37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.812951-4.327771 1.0401-5.033126 1.518306-5.033126C1.793275-5.033126 1.888917-4.841843 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.350934 .119552 1.518306 .047821 1.613948-.131507C1.637858-.191283 1.745455-.609714 1.80523-.848817L2.068244-1.924782L2.462765-3.502864Z'/>
<path id='g2-110' d='M2.462765-3.502864C2.486675-3.574595 2.785554-4.172354 3.227895-4.554919C3.53873-4.841843 3.945205-5.033126 4.411457-5.033126C4.889664-5.033126 5.057036-4.674471 5.057036-4.196264C5.057036-3.514819 4.566874-2.15193 4.327771-1.506351C4.220174-1.219427 4.160399-1.06401 4.160399-.848817C4.160399-.310834 4.531009 .119552 5.104857 .119552C6.216687 .119552 6.635118-1.637858 6.635118-1.709589C6.635118-1.769365 6.587298-1.817186 6.515567-1.817186C6.40797-1.817186 6.396015-1.78132 6.336239-1.578082C6.06127-.597758 5.606974-.119552 5.140722-.119552C5.021171-.119552 4.829888-.131507 4.829888-.514072C4.829888-.812951 4.961395-1.171606 5.033126-1.338979C5.272229-1.996513 5.774346-3.335492 5.774346-4.016936C5.774346-4.734247 5.355915-5.272229 4.447323-5.272229C3.383313-5.272229 2.82142-4.519054 2.606227-4.220174C2.570361-4.901619 2.080199-5.272229 1.554172-5.272229C1.171606-5.272229 .908593-5.045081 .705355-4.638605C.490162-4.208219 .32279-3.490909 .32279-3.443088S.37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.824907-4.351681 1.0401-5.033126 1.518306-5.033126C1.793275-5.033126 1.888917-4.841843 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.350934 .119552 1.518306 .047821 1.613948-.131507C1.637858-.191283 1.745455-.609714 1.80523-.848817L2.068244-1.924782L2.462765-3.502864Z'/>
<path id='g2-111' d='M5.451557-3.287671C5.451557-4.423412 4.710336-5.272229 3.622416-5.272229C2.044334-5.272229 .490162-3.550685 .490162-1.865006C.490162-.729265 1.231382 .119552 2.319303 .119552C3.90934 .119552 5.451557-1.601993 5.451557-3.287671ZM2.331258-.119552C1.733499-.119552 1.291158-.597758 1.291158-1.43462C1.291158-1.984558 1.578082-3.203985 1.912827-3.801743C2.450809-4.722291 3.120299-5.033126 3.610461-5.033126C4.196264-5.033126 4.65056-4.554919 4.65056-3.718057C4.65056-3.239851 4.399502-1.960648 3.945205-1.231382C3.455044-.430386 2.797509-.119552 2.331258-.119552Z'/>
<path id='g2-112' d='M.514072 1.518306C.430386 1.876961 .382565 1.972603-.107597 1.972603C-.251059 1.972603-.37061 1.972603-.37061 2.199751C-.37061 2.223661-.358655 2.319303-.227148 2.319303C-.071731 2.319303 .095641 2.295392 .251059 2.295392H.765131C1.016189 2.295392 1.625903 2.319303 1.876961 2.319303C1.948692 2.319303 2.092154 2.319303 2.092154 2.10411C2.092154 1.972603 2.008468 1.972603 1.80523 1.972603C1.255293 1.972603 1.219427 1.888917 1.219427 1.793275C1.219427 1.649813 1.75741-.406476 1.829141-.681445C1.960648-.3467 2.283437 .119552 2.905106 .119552C4.25604 .119552 5.71457-1.637858 5.71457-3.395268C5.71457-4.495143 5.092902-5.272229 4.196264-5.272229C3.431133-5.272229 2.785554-4.531009 2.654047-4.363636C2.558406-4.961395 2.092154-5.272229 1.613948-5.272229C1.267248-5.272229 .992279-5.104857 .765131-4.65056C.549938-4.220174 .382565-3.490909 .382565-3.443088S.430386-3.335492 .514072-3.335492C.609714-3.335492 .621669-3.347447 .6934-3.622416C.872727-4.327771 1.099875-5.033126 1.578082-5.033126C1.853051-5.033126 1.948692-4.841843 1.948692-4.483188C1.948692-4.196264 1.912827-4.076712 1.865006-3.861519L.514072 1.518306ZM2.582316-3.730012C2.666002-4.064757 3.000747-4.411457 3.19203-4.578829C3.323537-4.698381 3.718057-5.033126 4.172354-5.033126C4.698381-5.033126 4.937484-4.507098 4.937484-3.88543C4.937484-3.311582 4.60274-1.960648 4.303861-1.338979C4.004981-.6934 3.455044-.119552 2.905106-.119552C2.092154-.119552 1.960648-1.147696 1.960648-1.195517C1.960648-1.231382 1.984558-1.327024 1.996513-1.3868L2.582316-3.730012Z'/>
<path id='g2-113' d='M5.272229-5.152677C5.272229-5.212453 5.224408-5.260274 5.164633-5.260274C5.068991-5.260274 4.60274-4.829888 4.375592-4.411457C4.160399-4.94944 3.789788-5.272229 3.275716-5.272229C1.924782-5.272229 .466252-3.526775 .466252-1.75741C.466252-.573848 1.159651 .119552 1.972603 .119552C2.606227 .119552 3.132254-.358655 3.383313-.633624L3.395268-.621669L2.940971 1.171606L2.833375 1.601993C2.725778 1.960648 2.546451 1.960648 1.984558 1.972603C1.853051 1.972603 1.733499 1.972603 1.733499 2.199751C1.733499 2.283437 1.80523 2.319303 1.888917 2.319303C2.056289 2.319303 2.271482 2.295392 2.438854 2.295392H3.658281C3.837609 2.295392 4.040847 2.319303 4.220174 2.319303C4.291905 2.319303 4.435367 2.319303 4.435367 2.092154C4.435367 1.972603 4.339726 1.972603 4.160399 1.972603C3.598506 1.972603 3.56264 1.888917 3.56264 1.793275C3.56264 1.733499 3.574595 1.721544 3.610461 1.566127L5.272229-5.152677ZM3.58655-1.422665C3.526775-1.219427 3.526775-1.195517 3.359402-.968369C3.096389-.633624 2.570361-.119552 2.008468-.119552C1.518306-.119552 1.243337-.561893 1.243337-1.267248C1.243337-1.924782 1.613948-3.263761 1.841096-3.765878C2.247572-4.60274 2.809465-5.033126 3.275716-5.033126C4.064757-5.033126 4.220174-4.052802 4.220174-3.957161C4.220174-3.945205 4.184309-3.789788 4.172354-3.765878L3.58655-1.422665Z'/>
<path id='g2-114' d='M4.65056-4.889664C4.27995-4.817933 4.088667-4.554919 4.088667-4.291905C4.088667-4.004981 4.315816-3.90934 4.483188-3.90934C4.817933-3.90934 5.092902-4.196264 5.092902-4.554919C5.092902-4.937484 4.722291-5.272229 4.124533-5.272229C3.646326-5.272229 3.096389-5.057036 2.594271-4.327771C2.510585-4.961395 2.032379-5.272229 1.554172-5.272229C1.08792-5.272229 .848817-4.913574 .705355-4.65056C.502117-4.220174 .32279-3.502864 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.812951-4.339726 1.0401-5.033126 1.518306-5.033126C1.80523-5.033126 1.888917-4.829888 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.338979 .119552 1.566127 .035866 1.637858-.203238C1.673724-.298879 2.116065-2.10411 2.187796-2.379078C2.247572-2.642092 2.319303-2.893151 2.379078-3.156164C2.426899-3.323537 2.47472-3.514819 2.510585-3.670237C2.546451-3.777833 2.86924-4.363636 3.16812-4.62665C3.311582-4.758157 3.622416-5.033126 4.112578-5.033126C4.303861-5.033126 4.495143-4.99726 4.65056-4.889664Z'/>
<path id='g2-115' d='M2.725778-2.391034C2.929016-2.355168 3.251806-2.283437 3.323537-2.271482C3.478954-2.223661 4.016936-2.032379 4.016936-1.458531C4.016936-1.08792 3.682192-.119552 2.295392-.119552C2.044334-.119552 1.147696-.155417 .908593-.812951C1.3868-.753176 1.625903-1.123786 1.625903-1.3868C1.625903-1.637858 1.458531-1.769365 1.219427-1.769365C.956413-1.769365 .609714-1.566127 .609714-1.028144C.609714-.32279 1.327024 .119552 2.283437 .119552C4.100623 .119552 4.638605-1.219427 4.638605-1.841096C4.638605-2.020423 4.638605-2.355168 4.25604-2.737733C3.957161-3.024658 3.670237-3.084433 3.024658-3.21594C2.701868-3.287671 2.187796-3.395268 2.187796-3.93325C2.187796-4.172354 2.402989-5.033126 3.53873-5.033126C4.040847-5.033126 4.531009-4.841843 4.65056-4.411457C4.124533-4.411457 4.100623-3.957161 4.100623-3.945205C4.100623-3.694147 4.327771-3.622416 4.435367-3.622416C4.60274-3.622416 4.937484-3.753923 4.937484-4.25604S4.483188-5.272229 3.550685-5.272229C1.984558-5.272229 1.566127-4.040847 1.566127-3.550685C1.566127-2.642092 2.450809-2.450809 2.725778-2.391034Z'/>
<path id='g2-116' d='M2.402989-4.805978H3.502864C3.730012-4.805978 3.849564-4.805978 3.849564-5.021171C3.849564-5.152677 3.777833-5.152677 3.53873-5.152677H2.486675L2.929016-6.898132C2.976837-7.065504 2.976837-7.089415 2.976837-7.173101C2.976837-7.364384 2.82142-7.47198 2.666002-7.47198C2.570361-7.47198 2.295392-7.436115 2.199751-7.053549L1.733499-5.152677H.609714C.37061-5.152677 .263014-5.152677 .263014-4.925529C.263014-4.805978 .3467-4.805978 .573848-4.805978H1.637858L.848817-1.649813C.753176-1.231382 .71731-1.111831 .71731-.956413C.71731-.394521 1.111831 .119552 1.78132 .119552C2.988792 .119552 3.634371-1.625903 3.634371-1.709589C3.634371-1.78132 3.58655-1.817186 3.514819-1.817186C3.490909-1.817186 3.443088-1.817186 3.419178-1.769365C3.407223-1.75741 3.395268-1.745455 3.311582-1.554172C3.060523-.956413 2.510585-.119552 1.817186-.119552C1.458531-.119552 1.43462-.418431 1.43462-.681445C1.43462-.6934 1.43462-.920548 1.470486-1.06401L2.402989-4.805978Z'/>
<path id='g2-117' d='M4.076712-.6934C4.23213-.02391 4.805978 .119552 5.092902 .119552C5.475467 .119552 5.762391-.131507 5.953674-.537983C6.156912-.968369 6.312329-1.673724 6.312329-1.709589C6.312329-1.769365 6.264508-1.817186 6.192777-1.817186C6.085181-1.817186 6.073225-1.75741 6.025405-1.578082C5.810212-.753176 5.595019-.119552 5.116812-.119552C4.758157-.119552 4.758157-.514072 4.758157-.669489C4.758157-.944458 4.794022-1.06401 4.913574-1.566127C4.99726-1.888917 5.080946-2.211706 5.152677-2.546451L5.642839-4.495143C5.726526-4.794022 5.726526-4.817933 5.726526-4.853798C5.726526-5.033126 5.583064-5.152677 5.403736-5.152677C5.057036-5.152677 4.97335-4.853798 4.901619-4.554919C4.782067-4.088667 4.136488-1.518306 4.052802-1.099875C4.040847-1.099875 3.574595-.119552 2.701868-.119552C2.080199-.119552 1.960648-.657534 1.960648-1.099875C1.960648-1.78132 2.295392-2.737733 2.606227-3.53873C2.749689-3.921295 2.809465-4.076712 2.809465-4.315816C2.809465-4.829888 2.438854-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.578829 1.374844-5.033126 1.829141-5.033126C1.948692-5.033126 2.139975-5.021171 2.139975-4.638605C2.139975-4.327771 2.008468-3.981071 1.829141-3.526775C1.303113-2.10411 1.243337-1.649813 1.243337-1.291158C1.243337-.071731 2.163885 .119552 2.654047 .119552C3.419178 .119552 3.837609-.406476 4.076712-.6934Z'/>
<path id='g2-121' d='M3.144209 1.338979C2.82142 1.793275 2.355168 2.199751 1.769365 2.199751C1.625903 2.199751 1.052055 2.175841 .872727 1.625903C.908593 1.637858 .968369 1.637858 .992279 1.637858C1.350934 1.637858 1.590037 1.327024 1.590037 1.052055S1.362889 .681445 1.183562 .681445C.992279 .681445 .573848 .824907 .573848 1.41071C.573848 2.020423 1.08792 2.438854 1.769365 2.438854C2.964882 2.438854 4.172354 1.338979 4.507098 .011955L5.678705-4.65056C5.69066-4.710336 5.71457-4.782067 5.71457-4.853798C5.71457-5.033126 5.571108-5.152677 5.391781-5.152677C5.284184-5.152677 5.033126-5.104857 4.937484-4.746202L4.052802-1.231382C3.993026-1.016189 3.993026-.992279 3.897385-.860772C3.658281-.526027 3.263761-.119552 2.689913-.119552C2.020423-.119552 1.960648-.777086 1.960648-1.099875C1.960648-1.78132 2.283437-2.701868 2.606227-3.56264C2.737733-3.90934 2.809465-4.076712 2.809465-4.315816C2.809465-4.817933 2.450809-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.554919 1.362889-5.033126 1.829141-5.033126C1.936737-5.033126 2.139975-5.033126 2.139975-4.638605C2.139975-4.327771 2.008468-3.981071 1.829141-3.526775C1.243337-1.960648 1.243337-1.566127 1.243337-1.279203C1.243337-.143462 2.056289 .119552 2.654047 .119552C3.000747 .119552 3.431133 .011955 3.849564-.430386L3.861519-.418431C3.682192 .286924 3.56264 .753176 3.144209 1.338979Z'/>
</defs>
<g id='page1' transform='matrix(1.13 0 0 1.13 -63.986043 -66.444003)'>
<use x='56.413267' y='69.937791' xlink:href='#g2-109'/>
<use x='66.652534' y='69.937791' xlink:href='#g2-101'/>
<use x='72.077974' y='69.937791' xlink:href='#g2-109'/>
<use x='82.317241' y='69.937791' xlink:href='#g2-111'/>
<use x='87.944679' y='69.937791' xlink:href='#g2-114'/>
<use x='93.545152' y='69.937791' xlink:href='#g2-121'/>
<use x='99.681804' y='69.937791' xlink:href='#g2-58'/>
<use x='102.933465' y='69.937791' xlink:href='#g2-109'/>
<use x='113.172732' y='69.937791' xlink:href='#g2-105'/>
<use x='117.166164' y='69.937791' xlink:href='#g2-110'/>
<use x='127.474599' y='69.937791' xlink:href='#g3-61'/>
<use x='139.90008' y='58.580327' xlink:href='#g0-88'/>
<use x='147.092819' y='83.774682' xlink:href='#g1-105'/>
<use x='159.161195' y='58.580327' xlink:href='#g0-88'/>
<use x='165.85349' y='83.774682' xlink:href='#g1-106'/>
<use x='178.422309' y='69.937791' xlink:href='#g2-112'/>
<use x='184.297452' y='69.937791' xlink:href='#g2-111'/>
<use x='189.92489' y='69.937791' xlink:href='#g2-100'/>
<use x='196.007582' y='69.937791' xlink:href='#g3-91'/>
<use x='199.259244' y='69.937791' xlink:href='#g2-105'/>
<use x='203.252676' y='69.937791' xlink:href='#g3-93'/>
<use x='206.504337' y='69.937791' xlink:href='#g2-58'/>
<use x='209.755998' y='69.937791' xlink:href='#g2-115'/>
<use x='215.270004' y='69.937791' xlink:href='#g2-112'/>
<use x='221.145147' y='69.937791' xlink:href='#g2-101'/>
<use x='226.570587' y='69.937791' xlink:href='#g2-99'/>
<use x='231.608576' y='69.937791' xlink:href='#g2-58'/>
<use x='234.860237' y='69.937791' xlink:href='#g2-99'/>
<use x='239.898226' y='69.937791' xlink:href='#g2-111'/>
<use x='245.525663' y='69.937791' xlink:href='#g2-110'/>
<use x='252.513269' y='69.937791' xlink:href='#g2-116'/>
<use x='256.740429' y='69.937791' xlink:href='#g2-97'/>
<use x='262.885373' y='69.937791' xlink:href='#g2-105'/>
<use x='266.878805' y='69.937791' xlink:href='#g2-110'/>
<use x='273.866411' y='69.937791' xlink:href='#g2-101'/>
<use x='279.291851' y='69.937791' xlink:href='#g2-114'/>
<use x='284.892324' y='69.937791' xlink:href='#g2-115'/>
<use x='290.40633' y='69.937791' xlink:href='#g3-91'/>
<use x='293.657991' y='69.937791' xlink:href='#g2-106'/>
<use x='299.173487' y='69.937791' xlink:href='#g3-93'/>
<use x='302.425148' y='69.937791' xlink:href='#g2-58'/>
<use x='305.676809' y='69.937791' xlink:href='#g2-114'/>
<use x='311.277283' y='69.937791' xlink:href='#g2-101'/>
<use x='316.702723' y='69.937791' xlink:href='#g2-115'/>
<use x='322.216728' y='69.937791' xlink:href='#g2-111'/>
<use x='327.844166' y='69.937791' xlink:href='#g2-117'/>
<use x='334.506606' y='69.937791' xlink:href='#g2-114'/>
<use x='340.107079' y='69.937791' xlink:href='#g2-99'/>
<use x='345.145068' y='69.937791' xlink:href='#g2-101'/>
<use x='350.570508' y='69.937791' xlink:href='#g2-115'/>
<use x='356.084513' y='69.937791' xlink:href='#g2-58'/>
<use x='359.336175' y='69.937791' xlink:href='#g2-114'/>
<use x='364.936648' y='69.937791' xlink:href='#g2-101'/>
<use x='370.362088' y='69.937791' xlink:href='#g2-113'/>
<use x='375.981245' y='69.937791' xlink:href='#g2-117'/>
<use x='382.643684' y='69.937791' xlink:href='#g2-101'/>
<use x='388.069124' y='69.937791' xlink:href='#g2-115'/>
<use x='393.58313' y='69.937791' xlink:href='#g2-116'/>
<use x='397.81029' y='69.937791' xlink:href='#g2-115'/>
<use x='403.324295' y='69.937791' xlink:href='#g3-91'/>
<use x='406.575957' y='69.937791' xlink:href='#g2-109'/>
<use x='416.815224' y='69.937791' xlink:href='#g2-101'/>
<use x='422.240664' y='69.937791' xlink:href='#g2-109'/>
<use x='432.479931' y='69.937791' xlink:href='#g2-111'/>
<use x='438.107368' y='69.937791' xlink:href='#g2-114'/>
<use x='443.707842' y='69.937791' xlink:href='#g2-121'/>
<use x='449.844493' y='69.937791' xlink:href='#g3-93'/>
</g>
</svg>

After

Width:  |  Height:  |  Size: 28 KiB

@@ -0,0 +1,97 @@
<?xml version='1.0' encoding='UTF-8'?>
<!-- Generated by CodeCogs with dvisvgm 2.9.1 -->
<svg version='1.1' xmlns='http://www.w3.org/2000/svg' xmlns:xlink='http://www.w3.org/1999/xlink' width='411.32491pt' height='36.683306pt' viewBox='-.239051 -.232683 411.32491 36.683306'>
<defs>
<path id='g0-88' d='M15.135243 16.737235L16.581818 12.911582H16.282939C15.816687 14.154919 14.54944 14.96787 13.174595 15.326526C12.923537 15.386301 11.75193 15.697136 9.456538 15.697136H2.247572L8.332752 8.5599C8.416438 8.464259 8.440349 8.428394 8.440349 8.368618C8.440349 8.344707 8.440349 8.308842 8.356663 8.18929L2.785554 .573848H9.336986C10.938979 .573848 12.026899 .74122 12.134496 .765131C12.780075 .860772 13.820174 1.06401 14.764633 1.661768C15.063512 1.853051 15.876463 2.391034 16.282939 3.359402H16.581818L15.135243 0H1.004234C.729265 0 .71731 .011955 .681445 .083686C.669489 .119552 .669489 .3467 .669489 .478207L6.993773 9.133748L.800996 16.390535C.681445 16.533998 .681445 16.593773 .681445 16.605729C.681445 16.737235 .789041 16.737235 1.004234 16.737235H15.135243Z'/>
<path id='g3-48' d='M3.897385-2.542466C3.897385-3.395268 3.809714-3.913325 3.5467-4.423412C3.196015-5.124782 2.550436-5.300125 2.11208-5.300125C1.107846-5.300125 .74122-4.550934 .629639-4.327771C.342715-3.745953 .326775-2.956912 .326775-2.542466C.326775-2.016438 .350685-1.211457 .73325-.573848C1.099875 .01594 1.689664 .167372 2.11208 .167372C2.494645 .167372 3.180075 .047821 3.57858-.74122C3.873474-1.315068 3.897385-2.024408 3.897385-2.542466ZM2.11208-.055791C1.841096-.055791 1.291158-.183313 1.123786-1.020174C1.036115-1.474471 1.036115-2.223661 1.036115-2.638107C1.036115-3.188045 1.036115-3.745953 1.123786-4.184309C1.291158-4.99726 1.912827-5.076961 2.11208-5.076961C2.383064-5.076961 2.933001-4.941469 3.092403-4.216189C3.188045-3.777833 3.188045-3.180075 3.188045-2.638107C3.188045-2.16787 3.188045-1.45056 3.092403-1.004234C2.925031-.167372 2.375093-.055791 2.11208-.055791Z'/>
<path id='g3-61' d='M5.826152-2.654047C5.945704-2.654047 6.105106-2.654047 6.105106-2.83736S5.913823-3.020672 5.794271-3.020672H.781071C.661519-3.020672 .470237-3.020672 .470237-2.83736S.629639-2.654047 .749191-2.654047H5.826152ZM5.794271-.964384C5.913823-.964384 6.105106-.964384 6.105106-1.147696S5.945704-1.331009 5.826152-1.331009H.749191C.629639-1.331009 .470237-1.331009 .470237-1.147696S.661519-.964384 .781071-.964384H5.794271Z'/>
<path id='g1-105' d='M2.375093-4.97335C2.375093-5.148692 2.247572-5.276214 2.064259-5.276214C1.857036-5.276214 1.625903-5.084932 1.625903-4.845828C1.625903-4.670486 1.753425-4.542964 1.936737-4.542964C2.14396-4.542964 2.375093-4.734247 2.375093-4.97335ZM1.211457-2.048319L.781071-.948443C.74122-.828892 .70137-.73325 .70137-.597758C.70137-.207223 1.004234 .079701 1.42665 .079701C2.199751 .079701 2.526526-1.036115 2.526526-1.139726C2.526526-1.219427 2.462765-1.243337 2.406974-1.243337C2.311333-1.243337 2.295392-1.187547 2.271482-1.107846C2.088169-.470237 1.761395-.143462 1.44259-.143462C1.346949-.143462 1.251308-.183313 1.251308-.398506C1.251308-.589788 1.307098-.73325 1.41071-.980324C1.490411-1.195517 1.570112-1.41071 1.657783-1.625903L1.904857-2.271482C1.976588-2.454795 2.072229-2.701868 2.072229-2.83736C2.072229-3.235866 1.753425-3.514819 1.346949-3.514819C.573848-3.514819 .239103-2.399004 .239103-2.295392C.239103-2.223661 .294894-2.191781 .358655-2.191781C.462267-2.191781 .470237-2.239601 .494147-2.319303C.71731-3.076463 1.083935-3.291656 1.323039-3.291656C1.43462-3.291656 1.514321-3.251806 1.514321-3.028643C1.514321-2.948941 1.506351-2.83736 1.42665-2.598257L1.211457-2.048319Z'/>
<path id='g1-110' d='M1.594022-1.307098C1.617933-1.42665 1.697634-1.729514 1.721544-1.849066C1.833126-2.279452 1.833126-2.287422 2.016438-2.550436C2.279452-2.940971 2.654047-3.291656 3.188045-3.291656C3.474969-3.291656 3.642341-3.124284 3.642341-2.749689C3.642341-2.311333 3.307597-1.40274 3.156164-1.012204C3.052553-.749191 3.052553-.70137 3.052553-.597758C3.052553-.143462 3.427148 .079701 3.769863 .079701C4.550934 .079701 4.877709-1.036115 4.877709-1.139726C4.877709-1.219427 4.813948-1.243337 4.758157-1.243337C4.662516-1.243337 4.646575-1.187547 4.622665-1.107846C4.431382-.454296 4.096638-.143462 3.793773-.143462C3.666252-.143462 3.602491-.223163 3.602491-.406476S3.666252-.765131 3.745953-.964384C3.865504-1.267248 4.216189-2.183811 4.216189-2.630137C4.216189-3.227895 3.801743-3.514819 3.227895-3.514819C2.582316-3.514819 2.16787-3.124284 1.936737-2.82142C1.880946-3.259776 1.530262-3.514819 1.123786-3.514819C.836862-3.514819 .637609-3.331507 .510087-3.084433C.318804-2.709838 .239103-2.311333 .239103-2.295392C.239103-2.223661 .294894-2.191781 .358655-2.191781C.462267-2.191781 .470237-2.223661 .526027-2.430884C.621669-2.82142 .765131-3.291656 1.099875-3.291656C1.307098-3.291656 1.354919-3.092403 1.354919-2.917061C1.354919-2.773599 1.315068-2.622167 1.251308-2.359153C1.235367-2.295392 1.115816-1.825156 1.083935-1.713574L.789041-.518057C.757161-.398506 .70934-.199253 .70934-.167372C.70934 .01594 .860772 .079701 .964384 .079701C1.107846 .079701 1.227397-.01594 1.283188-.111582C1.307098-.159402 1.370859-.430386 1.41071-.597758L1.594022-1.307098Z'/>
<path id='g4-61' d='M8.069738-3.873474C8.237111-3.873474 8.452304-3.873474 8.452304-4.088667C8.452304-4.315816 8.249066-4.315816 8.069738-4.315816H1.028144C.860772-4.315816 .645579-4.315816 .645579-4.100623C.645579-3.873474 .848817-3.873474 1.028144-3.873474H8.069738ZM8.069738-1.649813C8.237111-1.649813 8.452304-1.649813 8.452304-1.865006C8.452304-2.092154 8.249066-2.092154 8.069738-2.092154H1.028144C.860772-2.092154 .645579-2.092154 .645579-1.876961C.645579-1.649813 .848817-1.649813 1.028144-1.649813H8.069738Z'/>
<path id='g4-91' d='M2.988792 2.988792V2.546451H1.829141V-8.524035H2.988792V-8.966376H1.3868V2.988792H2.988792Z'/>
<path id='g4-93' d='M1.853051-8.966376H.251059V-8.524035H1.41071V2.546451H.251059V2.988792H1.853051V-8.966376Z'/>
<path id='g2-58' d='M2.199751-.573848C2.199751-.920548 1.912827-1.159651 1.625903-1.159651C1.279203-1.159651 1.0401-.872727 1.0401-.585803C1.0401-.239103 1.327024 0 1.613948 0C1.960648 0 2.199751-.286924 2.199751-.573848Z'/>
<path id='g2-97' d='M3.598506-1.422665C3.53873-1.219427 3.53873-1.195517 3.371357-.968369C3.108344-.633624 2.582316-.119552 2.020423-.119552C1.530262-.119552 1.255293-.561893 1.255293-1.267248C1.255293-1.924782 1.625903-3.263761 1.853051-3.765878C2.259527-4.60274 2.82142-5.033126 3.287671-5.033126C4.076712-5.033126 4.23213-4.052802 4.23213-3.957161C4.23213-3.945205 4.196264-3.789788 4.184309-3.765878L3.598506-1.422665ZM4.363636-4.483188C4.23213-4.794022 3.90934-5.272229 3.287671-5.272229C1.936737-5.272229 .478207-3.526775 .478207-1.75741C.478207-.573848 1.171606 .119552 1.984558 .119552C2.642092 .119552 3.203985-.394521 3.53873-.789041C3.658281-.083686 4.220174 .119552 4.578829 .119552S5.224408-.095641 5.439601-.526027C5.630884-.932503 5.798257-1.661768 5.798257-1.709589C5.798257-1.769365 5.750436-1.817186 5.678705-1.817186C5.571108-1.817186 5.559153-1.75741 5.511333-1.578082C5.332005-.872727 5.104857-.119552 4.614695-.119552C4.267995-.119552 4.244085-.430386 4.244085-.669489C4.244085-.944458 4.27995-1.075965 4.387547-1.542217C4.471233-1.841096 4.531009-2.10411 4.62665-2.450809C5.068991-4.244085 5.176588-4.674471 5.176588-4.746202C5.176588-4.913574 5.045081-5.045081 4.865753-5.045081C4.483188-5.045081 4.387547-4.62665 4.363636-4.483188Z'/>
<path id='g2-99' d='M4.674471-4.495143C4.447323-4.495143 4.339726-4.495143 4.172354-4.351681C4.100623-4.291905 3.969116-4.112578 3.969116-3.921295C3.969116-3.682192 4.148443-3.53873 4.375592-3.53873C4.662516-3.53873 4.985305-3.777833 4.985305-4.25604C4.985305-4.829888 4.435367-5.272229 3.610461-5.272229C2.044334-5.272229 .478207-3.56264 .478207-1.865006C.478207-.824907 1.123786 .119552 2.343213 .119552C3.969116 .119552 4.99726-1.147696 4.99726-1.303113C4.99726-1.374844 4.925529-1.43462 4.877709-1.43462C4.841843-1.43462 4.829888-1.422665 4.722291-1.315068C3.957161-.298879 2.82142-.119552 2.367123-.119552C1.542217-.119552 1.279203-.836862 1.279203-1.43462C1.279203-1.853051 1.482441-3.012702 1.912827-3.825654C2.223661-4.387547 2.86924-5.033126 3.622416-5.033126C3.777833-5.033126 4.435367-5.009215 4.674471-4.495143Z'/>
<path id='g2-100' d='M6.01345-7.998007C6.025405-8.045828 6.049315-8.117559 6.049315-8.177335C6.049315-8.296887 5.929763-8.296887 5.905853-8.296887C5.893898-8.296887 5.308095-8.249066 5.248319-8.237111C5.045081-8.225156 4.865753-8.201245 4.65056-8.18929C4.351681-8.16538 4.267995-8.153425 4.267995-7.938232C4.267995-7.81868 4.363636-7.81868 4.531009-7.81868C5.116812-7.81868 5.128767-7.711083 5.128767-7.591532C5.128767-7.519801 5.104857-7.424159 5.092902-7.388294L4.363636-4.483188C4.23213-4.794022 3.90934-5.272229 3.287671-5.272229C1.936737-5.272229 .478207-3.526775 .478207-1.75741C.478207-.573848 1.171606 .119552 1.984558 .119552C2.642092 .119552 3.203985-.394521 3.53873-.789041C3.658281-.083686 4.220174 .119552 4.578829 .119552S5.224408-.095641 5.439601-.526027C5.630884-.932503 5.798257-1.661768 5.798257-1.709589C5.798257-1.769365 5.750436-1.817186 5.678705-1.817186C5.571108-1.817186 5.559153-1.75741 5.511333-1.578082C5.332005-.872727 5.104857-.119552 4.614695-.119552C4.267995-.119552 4.244085-.430386 4.244085-.669489C4.244085-.71731 4.244085-.968369 4.327771-1.303113L6.01345-7.998007ZM3.598506-1.422665C3.53873-1.219427 3.53873-1.195517 3.371357-.968369C3.108344-.633624 2.582316-.119552 2.020423-.119552C1.530262-.119552 1.255293-.561893 1.255293-1.267248C1.255293-1.924782 1.625903-3.263761 1.853051-3.765878C2.259527-4.60274 2.82142-5.033126 3.287671-5.033126C4.076712-5.033126 4.23213-4.052802 4.23213-3.957161C4.23213-3.945205 4.196264-3.789788 4.184309-3.765878L3.598506-1.422665Z'/>
<path id='g2-101' d='M2.139975-2.773599C2.462765-2.773599 3.275716-2.797509 3.849564-3.012702C4.758157-3.359402 4.841843-4.052802 4.841843-4.267995C4.841843-4.794022 4.387547-5.272229 3.598506-5.272229C2.343213-5.272229 .537983-4.136488 .537983-2.008468C.537983-.753176 1.255293 .119552 2.343213 .119552C3.969116 .119552 4.99726-1.147696 4.99726-1.303113C4.99726-1.374844 4.925529-1.43462 4.877709-1.43462C4.841843-1.43462 4.829888-1.422665 4.722291-1.315068C3.957161-.298879 2.82142-.119552 2.367123-.119552C1.685679-.119552 1.327024-.657534 1.327024-1.542217C1.327024-1.709589 1.327024-2.008468 1.506351-2.773599H2.139975ZM1.566127-3.012702C2.080199-4.853798 3.21594-5.033126 3.598506-5.033126C4.124533-5.033126 4.483188-4.722291 4.483188-4.267995C4.483188-3.012702 2.570361-3.012702 2.068244-3.012702H1.566127Z'/>
<path id='g2-105' d='M3.383313-1.709589C3.383313-1.769365 3.335492-1.817186 3.263761-1.817186C3.156164-1.817186 3.144209-1.78132 3.084433-1.578082C2.773599-.490162 2.283437-.119552 1.888917-.119552C1.745455-.119552 1.578082-.155417 1.578082-.514072C1.578082-.836862 1.721544-1.195517 1.853051-1.554172L2.689913-3.777833C2.725778-3.873474 2.809465-4.088667 2.809465-4.315816C2.809465-4.817933 2.450809-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.554919 1.362889-5.033126 1.829141-5.033126C1.936737-5.033126 2.139975-5.021171 2.139975-4.638605C2.139975-4.327771 1.984558-3.93325 1.888917-3.670237L1.052055-1.446575C.980324-1.255293 .908593-1.06401 .908593-.848817C.908593-.310834 1.279203 .119552 1.853051 .119552C2.952927 .119552 3.383313-1.625903 3.383313-1.709589ZM3.287671-7.460025C3.287671-7.639352 3.144209-7.854545 2.881196-7.854545C2.606227-7.854545 2.295392-7.591532 2.295392-7.280697C2.295392-6.981818 2.546451-6.886177 2.689913-6.886177C3.012702-6.886177 3.287671-7.197011 3.287671-7.460025Z'/>
<path id='g2-109' d='M2.462765-3.502864C2.486675-3.574595 2.785554-4.172354 3.227895-4.554919C3.53873-4.841843 3.945205-5.033126 4.411457-5.033126C4.889664-5.033126 5.057036-4.674471 5.057036-4.196264C5.057036-4.124533 5.057036-3.88543 4.913574-3.323537L4.614695-2.092154C4.519054-1.733499 4.291905-.848817 4.267995-.71731C4.220174-.537983 4.148443-.227148 4.148443-.179328C4.148443-.011955 4.27995 .119552 4.459278 .119552C4.817933 .119552 4.877709-.155417 4.985305-.585803L5.702615-3.443088C5.726526-3.53873 6.348194-5.033126 7.663263-5.033126C8.141469-5.033126 8.308842-4.674471 8.308842-4.196264C8.308842-3.526775 7.84259-2.223661 7.579577-1.506351C7.47198-1.219427 7.412204-1.06401 7.412204-.848817C7.412204-.310834 7.782814 .119552 8.356663 .119552C9.468493 .119552 9.886924-1.637858 9.886924-1.709589C9.886924-1.769365 9.839103-1.817186 9.767372-1.817186C9.659776-1.817186 9.647821-1.78132 9.588045-1.578082C9.313076-.621669 8.870735-.119552 8.392528-.119552C8.272976-.119552 8.081694-.131507 8.081694-.514072C8.081694-.824907 8.225156-1.207472 8.272976-1.338979C8.488169-1.912827 9.026152-3.323537 9.026152-4.016936C9.026152-4.734247 8.607721-5.272229 7.699128-5.272229C6.898132-5.272229 6.252553-4.817933 5.774346-4.112578C5.738481-4.758157 5.34396-5.272229 4.447323-5.272229C3.383313-5.272229 2.82142-4.519054 2.606227-4.220174C2.570361-4.901619 2.080199-5.272229 1.554172-5.272229C1.207472-5.272229 .932503-5.104857 .705355-4.65056C.490162-4.220174 .32279-3.490909 .32279-3.443088S.37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.812951-4.327771 1.0401-5.033126 1.518306-5.033126C1.793275-5.033126 1.888917-4.841843 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.350934 .119552 1.518306 .047821 1.613948-.131507C1.637858-.191283 1.745455-.609714 1.80523-.848817L2.068244-1.924782L2.462765-3.502864Z'/>
<path id='g2-110' d='M2.462765-3.502864C2.486675-3.574595 2.785554-4.172354 3.227895-4.554919C3.53873-4.841843 3.945205-5.033126 4.411457-5.033126C4.889664-5.033126 5.057036-4.674471 5.057036-4.196264C5.057036-3.514819 4.566874-2.15193 4.327771-1.506351C4.220174-1.219427 4.160399-1.06401 4.160399-.848817C4.160399-.310834 4.531009 .119552 5.104857 .119552C6.216687 .119552 6.635118-1.637858 6.635118-1.709589C6.635118-1.769365 6.587298-1.817186 6.515567-1.817186C6.40797-1.817186 6.396015-1.78132 6.336239-1.578082C6.06127-.597758 5.606974-.119552 5.140722-.119552C5.021171-.119552 4.829888-.131507 4.829888-.514072C4.829888-.812951 4.961395-1.171606 5.033126-1.338979C5.272229-1.996513 5.774346-3.335492 5.774346-4.016936C5.774346-4.734247 5.355915-5.272229 4.447323-5.272229C3.383313-5.272229 2.82142-4.519054 2.606227-4.220174C2.570361-4.901619 2.080199-5.272229 1.554172-5.272229C1.171606-5.272229 .908593-5.045081 .705355-4.638605C.490162-4.208219 .32279-3.490909 .32279-3.443088S.37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.824907-4.351681 1.0401-5.033126 1.518306-5.033126C1.793275-5.033126 1.888917-4.841843 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.350934 .119552 1.518306 .047821 1.613948-.131507C1.637858-.191283 1.745455-.609714 1.80523-.848817L2.068244-1.924782L2.462765-3.502864Z'/>
<path id='g2-111' d='M5.451557-3.287671C5.451557-4.423412 4.710336-5.272229 3.622416-5.272229C2.044334-5.272229 .490162-3.550685 .490162-1.865006C.490162-.729265 1.231382 .119552 2.319303 .119552C3.90934 .119552 5.451557-1.601993 5.451557-3.287671ZM2.331258-.119552C1.733499-.119552 1.291158-.597758 1.291158-1.43462C1.291158-1.984558 1.578082-3.203985 1.912827-3.801743C2.450809-4.722291 3.120299-5.033126 3.610461-5.033126C4.196264-5.033126 4.65056-4.554919 4.65056-3.718057C4.65056-3.239851 4.399502-1.960648 3.945205-1.231382C3.455044-.430386 2.797509-.119552 2.331258-.119552Z'/>
<path id='g2-112' d='M.514072 1.518306C.430386 1.876961 .382565 1.972603-.107597 1.972603C-.251059 1.972603-.37061 1.972603-.37061 2.199751C-.37061 2.223661-.358655 2.319303-.227148 2.319303C-.071731 2.319303 .095641 2.295392 .251059 2.295392H.765131C1.016189 2.295392 1.625903 2.319303 1.876961 2.319303C1.948692 2.319303 2.092154 2.319303 2.092154 2.10411C2.092154 1.972603 2.008468 1.972603 1.80523 1.972603C1.255293 1.972603 1.219427 1.888917 1.219427 1.793275C1.219427 1.649813 1.75741-.406476 1.829141-.681445C1.960648-.3467 2.283437 .119552 2.905106 .119552C4.25604 .119552 5.71457-1.637858 5.71457-3.395268C5.71457-4.495143 5.092902-5.272229 4.196264-5.272229C3.431133-5.272229 2.785554-4.531009 2.654047-4.363636C2.558406-4.961395 2.092154-5.272229 1.613948-5.272229C1.267248-5.272229 .992279-5.104857 .765131-4.65056C.549938-4.220174 .382565-3.490909 .382565-3.443088S.430386-3.335492 .514072-3.335492C.609714-3.335492 .621669-3.347447 .6934-3.622416C.872727-4.327771 1.099875-5.033126 1.578082-5.033126C1.853051-5.033126 1.948692-4.841843 1.948692-4.483188C1.948692-4.196264 1.912827-4.076712 1.865006-3.861519L.514072 1.518306ZM2.582316-3.730012C2.666002-4.064757 3.000747-4.411457 3.19203-4.578829C3.323537-4.698381 3.718057-5.033126 4.172354-5.033126C4.698381-5.033126 4.937484-4.507098 4.937484-3.88543C4.937484-3.311582 4.60274-1.960648 4.303861-1.338979C4.004981-.6934 3.455044-.119552 2.905106-.119552C2.092154-.119552 1.960648-1.147696 1.960648-1.195517C1.960648-1.231382 1.984558-1.327024 1.996513-1.3868L2.582316-3.730012Z'/>
<path id='g2-113' d='M5.272229-5.152677C5.272229-5.212453 5.224408-5.260274 5.164633-5.260274C5.068991-5.260274 4.60274-4.829888 4.375592-4.411457C4.160399-4.94944 3.789788-5.272229 3.275716-5.272229C1.924782-5.272229 .466252-3.526775 .466252-1.75741C.466252-.573848 1.159651 .119552 1.972603 .119552C2.606227 .119552 3.132254-.358655 3.383313-.633624L3.395268-.621669L2.940971 1.171606L2.833375 1.601993C2.725778 1.960648 2.546451 1.960648 1.984558 1.972603C1.853051 1.972603 1.733499 1.972603 1.733499 2.199751C1.733499 2.283437 1.80523 2.319303 1.888917 2.319303C2.056289 2.319303 2.271482 2.295392 2.438854 2.295392H3.658281C3.837609 2.295392 4.040847 2.319303 4.220174 2.319303C4.291905 2.319303 4.435367 2.319303 4.435367 2.092154C4.435367 1.972603 4.339726 1.972603 4.160399 1.972603C3.598506 1.972603 3.56264 1.888917 3.56264 1.793275C3.56264 1.733499 3.574595 1.721544 3.610461 1.566127L5.272229-5.152677ZM3.58655-1.422665C3.526775-1.219427 3.526775-1.195517 3.359402-.968369C3.096389-.633624 2.570361-.119552 2.008468-.119552C1.518306-.119552 1.243337-.561893 1.243337-1.267248C1.243337-1.924782 1.613948-3.263761 1.841096-3.765878C2.247572-4.60274 2.809465-5.033126 3.275716-5.033126C4.064757-5.033126 4.220174-4.052802 4.220174-3.957161C4.220174-3.945205 4.184309-3.789788 4.172354-3.765878L3.58655-1.422665Z'/>
<path id='g2-114' d='M4.65056-4.889664C4.27995-4.817933 4.088667-4.554919 4.088667-4.291905C4.088667-4.004981 4.315816-3.90934 4.483188-3.90934C4.817933-3.90934 5.092902-4.196264 5.092902-4.554919C5.092902-4.937484 4.722291-5.272229 4.124533-5.272229C3.646326-5.272229 3.096389-5.057036 2.594271-4.327771C2.510585-4.961395 2.032379-5.272229 1.554172-5.272229C1.08792-5.272229 .848817-4.913574 .705355-4.65056C.502117-4.220174 .32279-3.502864 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.549938-3.335492 .561893-3.347447 .633624-3.622416C.812951-4.339726 1.0401-5.033126 1.518306-5.033126C1.80523-5.033126 1.888917-4.829888 1.888917-4.483188C1.888917-4.220174 1.769365-3.753923 1.685679-3.383313L1.350934-2.092154C1.303113-1.865006 1.171606-1.327024 1.111831-1.111831C1.028144-.800996 .896638-.239103 .896638-.179328C.896638-.011955 1.028144 .119552 1.207472 .119552C1.338979 .119552 1.566127 .035866 1.637858-.203238C1.673724-.298879 2.116065-2.10411 2.187796-2.379078C2.247572-2.642092 2.319303-2.893151 2.379078-3.156164C2.426899-3.323537 2.47472-3.514819 2.510585-3.670237C2.546451-3.777833 2.86924-4.363636 3.16812-4.62665C3.311582-4.758157 3.622416-5.033126 4.112578-5.033126C4.303861-5.033126 4.495143-4.99726 4.65056-4.889664Z'/>
<path id='g2-115' d='M2.725778-2.391034C2.929016-2.355168 3.251806-2.283437 3.323537-2.271482C3.478954-2.223661 4.016936-2.032379 4.016936-1.458531C4.016936-1.08792 3.682192-.119552 2.295392-.119552C2.044334-.119552 1.147696-.155417 .908593-.812951C1.3868-.753176 1.625903-1.123786 1.625903-1.3868C1.625903-1.637858 1.458531-1.769365 1.219427-1.769365C.956413-1.769365 .609714-1.566127 .609714-1.028144C.609714-.32279 1.327024 .119552 2.283437 .119552C4.100623 .119552 4.638605-1.219427 4.638605-1.841096C4.638605-2.020423 4.638605-2.355168 4.25604-2.737733C3.957161-3.024658 3.670237-3.084433 3.024658-3.21594C2.701868-3.287671 2.187796-3.395268 2.187796-3.93325C2.187796-4.172354 2.402989-5.033126 3.53873-5.033126C4.040847-5.033126 4.531009-4.841843 4.65056-4.411457C4.124533-4.411457 4.100623-3.957161 4.100623-3.945205C4.100623-3.694147 4.327771-3.622416 4.435367-3.622416C4.60274-3.622416 4.937484-3.753923 4.937484-4.25604S4.483188-5.272229 3.550685-5.272229C1.984558-5.272229 1.566127-4.040847 1.566127-3.550685C1.566127-2.642092 2.450809-2.450809 2.725778-2.391034Z'/>
<path id='g2-116' d='M2.402989-4.805978H3.502864C3.730012-4.805978 3.849564-4.805978 3.849564-5.021171C3.849564-5.152677 3.777833-5.152677 3.53873-5.152677H2.486675L2.929016-6.898132C2.976837-7.065504 2.976837-7.089415 2.976837-7.173101C2.976837-7.364384 2.82142-7.47198 2.666002-7.47198C2.570361-7.47198 2.295392-7.436115 2.199751-7.053549L1.733499-5.152677H.609714C.37061-5.152677 .263014-5.152677 .263014-4.925529C.263014-4.805978 .3467-4.805978 .573848-4.805978H1.637858L.848817-1.649813C.753176-1.231382 .71731-1.111831 .71731-.956413C.71731-.394521 1.111831 .119552 1.78132 .119552C2.988792 .119552 3.634371-1.625903 3.634371-1.709589C3.634371-1.78132 3.58655-1.817186 3.514819-1.817186C3.490909-1.817186 3.443088-1.817186 3.419178-1.769365C3.407223-1.75741 3.395268-1.745455 3.311582-1.554172C3.060523-.956413 2.510585-.119552 1.817186-.119552C1.458531-.119552 1.43462-.418431 1.43462-.681445C1.43462-.6934 1.43462-.920548 1.470486-1.06401L2.402989-4.805978Z'/>
<path id='g2-117' d='M4.076712-.6934C4.23213-.02391 4.805978 .119552 5.092902 .119552C5.475467 .119552 5.762391-.131507 5.953674-.537983C6.156912-.968369 6.312329-1.673724 6.312329-1.709589C6.312329-1.769365 6.264508-1.817186 6.192777-1.817186C6.085181-1.817186 6.073225-1.75741 6.025405-1.578082C5.810212-.753176 5.595019-.119552 5.116812-.119552C4.758157-.119552 4.758157-.514072 4.758157-.669489C4.758157-.944458 4.794022-1.06401 4.913574-1.566127C4.99726-1.888917 5.080946-2.211706 5.152677-2.546451L5.642839-4.495143C5.726526-4.794022 5.726526-4.817933 5.726526-4.853798C5.726526-5.033126 5.583064-5.152677 5.403736-5.152677C5.057036-5.152677 4.97335-4.853798 4.901619-4.554919C4.782067-4.088667 4.136488-1.518306 4.052802-1.099875C4.040847-1.099875 3.574595-.119552 2.701868-.119552C2.080199-.119552 1.960648-.657534 1.960648-1.099875C1.960648-1.78132 2.295392-2.737733 2.606227-3.53873C2.749689-3.921295 2.809465-4.076712 2.809465-4.315816C2.809465-4.829888 2.438854-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.578829 1.374844-5.033126 1.829141-5.033126C1.948692-5.033126 2.139975-5.021171 2.139975-4.638605C2.139975-4.327771 2.008468-3.981071 1.829141-3.526775C1.303113-2.10411 1.243337-1.649813 1.243337-1.291158C1.243337-.071731 2.163885 .119552 2.654047 .119552C3.419178 .119552 3.837609-.406476 4.076712-.6934Z'/>
<path id='g2-121' d='M3.144209 1.338979C2.82142 1.793275 2.355168 2.199751 1.769365 2.199751C1.625903 2.199751 1.052055 2.175841 .872727 1.625903C.908593 1.637858 .968369 1.637858 .992279 1.637858C1.350934 1.637858 1.590037 1.327024 1.590037 1.052055S1.362889 .681445 1.183562 .681445C.992279 .681445 .573848 .824907 .573848 1.41071C.573848 2.020423 1.08792 2.438854 1.769365 2.438854C2.964882 2.438854 4.172354 1.338979 4.507098 .011955L5.678705-4.65056C5.69066-4.710336 5.71457-4.782067 5.71457-4.853798C5.71457-5.033126 5.571108-5.152677 5.391781-5.152677C5.284184-5.152677 5.033126-5.104857 4.937484-4.746202L4.052802-1.231382C3.993026-1.016189 3.993026-.992279 3.897385-.860772C3.658281-.526027 3.263761-.119552 2.689913-.119552C2.020423-.119552 1.960648-.777086 1.960648-1.099875C1.960648-1.78132 2.283437-2.701868 2.606227-3.56264C2.737733-3.90934 2.809465-4.076712 2.809465-4.315816C2.809465-4.817933 2.450809-5.272229 1.865006-5.272229C.765131-5.272229 .32279-3.53873 .32279-3.443088C.32279-3.395268 .37061-3.335492 .454296-3.335492C.561893-3.335492 .573848-3.383313 .621669-3.550685C.908593-4.554919 1.362889-5.033126 1.829141-5.033126C1.936737-5.033126 2.139975-5.033126 2.139975-4.638605C2.139975-4.327771 2.008468-3.981071 1.829141-3.526775C1.243337-1.960648 1.243337-1.566127 1.243337-1.279203C1.243337-.143462 2.056289 .119552 2.654047 .119552C3.000747 .119552 3.431133 .011955 3.849564-.430386L3.861519-.418431C3.682192 .286924 3.56264 .753176 3.144209 1.338979Z'/>
</defs>
<g id='page1' transform='matrix(1.13 0 0 1.13 -63.986043 -62.281577)'>
<use x='56.413267' y='73.369366' xlink:href='#g2-109'/>
<use x='66.652534' y='73.369366' xlink:href='#g2-101'/>
<use x='72.077974' y='73.369366' xlink:href='#g2-109'/>
<use x='82.317241' y='73.369366' xlink:href='#g2-111'/>
<use x='87.944679' y='73.369366' xlink:href='#g2-114'/>
<use x='93.545152' y='73.369366' xlink:href='#g2-121'/>
<use x='99.681804' y='73.369366' xlink:href='#g2-58'/>
<use x='102.933465' y='73.369366' xlink:href='#g2-109'/>
<use x='113.172732' y='73.369366' xlink:href='#g2-105'/>
<use x='117.166164' y='73.369366' xlink:href='#g2-110'/>
<use x='127.474599' y='73.369366' xlink:href='#g4-61'/>
<use x='145.965287' y='58.425345' xlink:href='#g1-110'/>
<use x='139.90008' y='62.011901' xlink:href='#g0-88'/>
<use x='141.682474' y='87.206256' xlink:href='#g1-105'/>
<use x='144.565614' y='87.206256' xlink:href='#g3-61'/>
<use x='151.15212' y='87.206256' xlink:href='#g3-48'/>
<use x='159.161195' y='73.369366' xlink:href='#g2-112'/>
<use x='165.036338' y='73.369366' xlink:href='#g2-111'/>
<use x='170.663775' y='73.369366' xlink:href='#g2-100'/>
<use x='176.746468' y='73.369366' xlink:href='#g2-58'/>
<use x='179.998129' y='73.369366' xlink:href='#g2-115'/>
<use x='185.512135' y='73.369366' xlink:href='#g2-112'/>
<use x='191.387278' y='73.369366' xlink:href='#g2-101'/>
<use x='196.812718' y='73.369366' xlink:href='#g2-99'/>
<use x='201.850707' y='73.369366' xlink:href='#g2-58'/>
<use x='205.102368' y='73.369366' xlink:href='#g2-99'/>
<use x='210.140357' y='73.369366' xlink:href='#g2-111'/>
<use x='215.767794' y='73.369366' xlink:href='#g2-110'/>
<use x='222.7554' y='73.369366' xlink:href='#g2-116'/>
<use x='226.982559' y='73.369366' xlink:href='#g2-97'/>
<use x='233.127504' y='73.369366' xlink:href='#g2-105'/>
<use x='237.120936' y='73.369366' xlink:href='#g2-110'/>
<use x='244.108542' y='73.369366' xlink:href='#g2-101'/>
<use x='249.533982' y='73.369366' xlink:href='#g2-114'/>
<use x='255.134455' y='73.369366' xlink:href='#g2-115'/>
<use x='260.648461' y='73.369366' xlink:href='#g4-91'/>
<use x='263.900122' y='73.369366' xlink:href='#g2-105'/>
<use x='267.893554' y='73.369366' xlink:href='#g4-93'/>
<use x='271.145216' y='73.369366' xlink:href='#g2-58'/>
<use x='274.396877' y='73.369366' xlink:href='#g2-114'/>
<use x='279.99735' y='73.369366' xlink:href='#g2-101'/>
<use x='285.42279' y='73.369366' xlink:href='#g2-115'/>
<use x='290.936796' y='73.369366' xlink:href='#g2-111'/>
<use x='296.564234' y='73.369366' xlink:href='#g2-117'/>
<use x='303.226673' y='73.369366' xlink:href='#g2-114'/>
<use x='308.827147' y='73.369366' xlink:href='#g2-99'/>
<use x='313.865135' y='73.369366' xlink:href='#g2-101'/>
<use x='319.290575' y='73.369366' xlink:href='#g2-115'/>
<use x='324.804581' y='73.369366' xlink:href='#g2-58'/>
<use x='328.056242' y='73.369366' xlink:href='#g2-114'/>
<use x='333.656716' y='73.369366' xlink:href='#g2-101'/>
<use x='339.082156' y='73.369366' xlink:href='#g2-113'/>
<use x='344.701312' y='73.369366' xlink:href='#g2-117'/>
<use x='351.363752' y='73.369366' xlink:href='#g2-101'/>
<use x='356.789192' y='73.369366' xlink:href='#g2-115'/>
<use x='362.303198' y='73.369366' xlink:href='#g2-116'/>
<use x='366.530357' y='73.369366' xlink:href='#g2-115'/>
<use x='372.044363' y='73.369366' xlink:href='#g4-91'/>
<use x='375.296024' y='73.369366' xlink:href='#g2-109'/>
<use x='385.535291' y='73.369366' xlink:href='#g2-101'/>
<use x='390.960731' y='73.369366' xlink:href='#g2-109'/>
<use x='401.199998' y='73.369366' xlink:href='#g2-111'/>
<use x='406.827436' y='73.369366' xlink:href='#g2-114'/>
<use x='412.427909' y='73.369366' xlink:href='#g2-121'/>
<use x='418.564561' y='73.369366' xlink:href='#g4-93'/>
</g>
</svg>

After

Width:  |  Height:  |  Size: 28 KiB

@@ -0,0 +1,343 @@
---
layout: blog
title: "Contribution, containers and cricket: the Kubernetes 1.22 release interview"
date: 2021-12-01
---
**Author**: Craig Box (Google)
The Kubernetes release train rolls on, and we look ahead to the release of 1.23 next week. [As is our tradition](https://www.google.com/search?q=%22release+interview%22+site%3Akubernetes.io%2Fblog), I'm pleased to bring you a look back at the process that brought us the previous version.
The release team for 1.22 was led by [Savitha Raghunathan](https://twitter.com/coffeeartgirl), who was, at the time, a Senior Platform Engineer at MathWorks. [I spoke to Savitha](https://kubernetespodcast.com/episode/157-kubernetes-1.22/) on the [Kubernetes Podcast from Google](https://kubernetespodcast.com/), the weekly<super>*</super> show covering the Kubernetes and Cloud Native ecosystem.
Our release conversations shine a light on the team that puts together each Kubernetes release. Make sure you [subscribe, wherever you get your podcasts](https://kubernetespodcast.com/subscribe/) so you catch the story of 1.23.
And in case you're interested in why the show has been on a hiatus the last few weeks, all will be revealed in the next episode!
*This transcript has been lightly edited and condensed for clarity.*
---
**CRAIG BOX: Welcome to the show, Savitha.**
SAVITHA RAGHUNATHAN: Hey, Craig. Thanks for having me on the show. How are you today?
**CRAIG BOX: I'm very well, thank you. I've interviewed a lot of people on the show, and you're actually the first person who's asked that of me.**
SAVITHA RAGHUNATHAN: I'm glad. It's something that I always do. I just want to make sure the other person is good and happy.
**CRAIG BOX: That's very kind of you. Thank you for kicking off on a wonderful foot there. I want to ask first of all — you grew up in Chennai. My association with Chennai is the [Super Kings cricket team](https://en.wikipedia.org/wiki/Chennai_Super_Kings). Was cricket part of your upbringing?**
SAVITHA RAGHUNATHAN: Yeah. Actually, a lot. My mom loves watching cricket. I have a younger brother, and when we were growing up, we used to play cricket on the terrace. Everyone surrounding me, my best friends — and even now, my partner — loves watching cricket, too. Cricket is a part of my life.
I stopped watching it a while ago, but I still enjoy a good game.
**CRAIG BOX: It's probably a bit harder in the US. Everything's in a different time zone. I find, with my cricket team being on the other side of the world, that it's a lot easier when they're playing near me, as opposed to trying to keep up with what they're doing when they're playing at 3:00 in the morning.**
SAVITHA RAGHUNATHAN: That is actually one of the things that made me lose touch with cricket. I'm going to give you a piece of interesting information. I never supported Chennai Super Kings. I always supported [Royal Challengers of Bangalore](https://en.wikipedia.org/wiki/Royal_Challengers_Bangalore).
I once went to the stadium, and it was a match between the Chennai Super Kings and the RCB. I was the only one who was cheering whenever the RCB hit a 6, or when they were scoring. I got the stares of thousands of people looking at me. I'm like, "what are you doing?" My friends are like, "you're going to get us killed! Just stop screaming!"
**CRAIG BOX: I hear you. As a New Zealander in the UK, there are a lot of international cricket matches I've been to where I am one of the few people dressed in the full beige kit. But I have to ask, why an affiliation with a different team?**
SAVITHA RAGHUNATHAN: I'm not sure. When the IPL came out, I really liked Virat Kohli. He was playing for RCB at that time, and I think pretty much that's it.
**CRAIG BOX: Well, what I know about the Chennai Super Kings is that their coach is New Zealand's finest batsmen and [air conditioning salesman](https://www.youtube.com/watch?v=vSZAaUCAclw), [Stephen Fleming](https://en.wikipedia.org/wiki/Stephen_Fleming).**
SAVITHA RAGHUNATHAN: Oh, really?
**CRAIG BOX: Yeah, he's a dead ringer for the guy who played the [yellow Wiggle](https://s1.reutersmedia.net/resources/r/?m=02&d=20061130&t=2&i=153531&w=&fh=545px&fw=&ll=&pl=&sq=&r=153531) back in the day.**
SAVITHA RAGHUNATHAN: Oh, interesting. I remember the name, but I cannot put the picture and the name together. I stopped watching cricket once I moved to the States. Then, all my focus was on studies and extracurriculars. I have always been an introvert. The campus — it was a new thing for me — they had international festivals.
And every week, they'd have some kind of new thing going on, so I'd go check them out. I wouldn't participate, but I did go out and check them out. That was a big feat for me around that time because a lot of people — and still, even now, a lot of people — they kind of scare me. I don't know how to make a conversation with everyone.
I'll just go and say, "hi, how are you? OK, I'm good. I'm just going to move on". And I'll just go to the next person. And after two hours, I'm out of that place.
**CRAIG BOX: Perhaps a pleasant side effect of the last 12 months — a lot fewer gatherings of people.**
SAVITHA RAGHUNATHAN: Could be that, but I'm so excited about KubeCon. But when I think about it, I'm like "oh my God. There's going to be a lot of people. What am I going to do? I'm going to meet all my friends over there".
Sometimes I have social anxiety like, what's going to happen?
**CRAIG BOX: What's going to happen is you're going to ask them how they are at the beginning, and they're immediately going to be set at ease.**
SAVITHA RAGHUNATHAN: *laughs* I hope so.
**CRAIG BOX: Let's talk a little bit, then, about your transition from India to the US. You did your undergraduate degree in computer science at the SSN College of Engineering. How did you end up at Arizona State?**
SAVITHA RAGHUNATHAN: I always wanted to pursue higher studies when I was in India, and I didn't have the opportunity immediately. Once I graduated from my school there, I went and I worked for a couple of years. My aim was always to get out of there and come here, do my graduate studies.
Eventually, I want to do a PhD. I have an idea of what I want to do. I always wanted to keep studying. If there's an option that I could just keep studying and not do work or anything of that sort, I'd just pick that other one — I'll just keep studying.
But unfortunately, you need money and other things to live and sustain in this world. So I'm like, OK, I'll take a break from studies, and I will work for a while.
**CRAIG BOX: The road to success is littered with dreams of PhDs. I have a lot of friends who thought that that was the path they were going to take, and they've had a beautiful career and probably aren't going to go back to study. Did you use the [Matlab](https://en.wikipedia.org/wiki/MATLAB) software at all while you were going through your schooling?**
SAVITHA RAGHUNATHAN: No, unfortunately. That is a question that everyone asks. I have not used Matlab. I haven't used it even now. I don't use it for work. I didn't have any necessity for my school work. I didn't have anything to do with Matlab. I never analysed, or did data processing, or anything, with Matlab. So unfortunately, no.
Everyone asks me like, you're working at [MathWorks](https://en.wikipedia.org/wiki/MathWorks). Have you used Matlab? I'm like, no.
**CRAIG BOX: Fair enough. Nor have I. But it's been around since the late 1970s, so I imagine there are a lot of people who will have come across it at some point. Do you work with a lot of people who have been working on it that whole time?**
SAVITHA RAGHUNATHAN: Kind of. Not all the time, but I get to meet some folks who work on the product itself. Most of my interactions are with the infrastructure team and platform engineering teams at MathWorks. One other interesting fact is that when I joined the company — MathWorks has an extensive internal curriculum for training and learning, which I really love. They have an "Intro to Matlab" course, and that's on my bucket of things to do.
It was like 500 years ago. I added it, and I never got to it. I'm like, OK, maybe this year at least I want to get to it and I want to learn something new. My partner used Matlab extensively. He misses it right now at his current employer. And he's like, "you have the entire licence! You have access to the entire suite and you haven't used it?" I'm like, "no!"
**CRAIG BOX: Well, I have bad news for the idea of you doing a PhD, I'm sorry.**
SAVITHA RAGHUNATHAN: Another thing is that none of my family knew about the company MathWorks and Matlab. The only person who knew was my younger brother. He was so proud. He was like, "oh my God".
When he was 12 years old, he started getting involved in robotics and all that stuff. That's how he got introduced to Matlab. He goes absolutely bananas for the swag. So all the t-shirts, all the hoodies — any swag that I get from MathWorks goes to him, without saying.
Over the five, six years, the things that I've got — there was only one sweatshirt that I kept for myself. Everything else I've just given to him. And he cherishes it. He's the only one in my family who knew about Matlab and MathWorks.
Now, everyone knows, because I'm working there. They were initially like, I don't even know that company name. Is it like Amazon? I'm like, no, we make software that can send people to the moon. And we also make software that can do amazing robotic surgeries and even make a car drive on its own. That's something that I take immense pride in.
I know I don't directly work on the product, but I'm enabling the people who are creating the product. I'm really, really proud of that.
**CRAIG BOX: I think Jeff Bezos is working on at least two out of three of those disciplines that you mentioned before, so it's maybe a little bit like Amazon. One thing I've always thought about Matlab is that, because it's called Matlab, it solves that whole problem where [Americans call it math, and the rest of the world call it maths](https://www.grammar.com/math_vs._maths). Why do Americans think there's only one math?**
SAVITHA RAGHUNATHAN: Definitely. I had trouble — growing up in India, it's always British English. And I had so much trouble when I moved here. So many things changed.
One of the things is maths. I always got used to writing maths, physics, and everything.
**CRAIG BOX: They don't call it "physic" in the US, do they?**
SAVITHA RAGHUNATHAN: No, no, they don't. Luckily, they don't. That still stays "physics". But math — I had trouble. It's maths. Even when you do the full abbreviations like mathematics and you are still calling it math, I'm like, mm.
**CRAIG BOX: They can do the computer science abbreviation thing and call it math-7-S or whatever the number of letters is.**
SAVITHA RAGHUNATHAN: Just like Kubernetes. K-8-s.
**CRAIG BOX: Your path to Kubernetes is through MathWorks. They started out as a company making software which was distributed in a physical sense — boxed copies, if you will. I understand now there is a cloud version. Can I assume that that is where the two worlds intersect?**
SAVITHA RAGHUNATHAN: Kind of. I have interaction with the team that supports Matlab on the cloud, but I don't get to work with them on a day-to-day basis. They use Docker containers, and they are building the platform using Kubernetes. So yeah, a little bit of that.
**CRAIG BOX: So what exactly is the platform that you are engineering day to day?**
SAVITHA RAGHUNATHAN: Providing Kubernetes as a platform, obviously — that goes without saying — to some of the internal development teams. In the future we might expand it to more teams within the company. That is a focus area right now, so that's what we are doing. In the process, we might even get to work with the people who are deploying Matlab on the cloud, which is exciting.
**CRAIG BOX: Now, your path to contribution to Kubernetes, you've said before, was through [fixing a 404 error on the Kubernetes.io website](https://github.com/kubernetes/website/pull/15588). Do you remember what the page was?**
SAVITHA RAGHUNATHAN: I do. I was going to something for work, and I came across this changelog. In Kubernetes there's a nice page — once you got to the release page, there would be a long list of changelogs.
One of the things that I fixed was, the person who worked on the feature had changed their GitHub handle, and that wasn't reflected on this page. So that was my first. I got curious and clicked on the links. One of the links was the handle, and that went to a 404. And I was like "Yeah, I'll just fix that. They have done all the hard work. They can get the credit that's due".
It was easy. It wasn't overwhelming for me to pick it up as my first issue. Before that I logged on around Kubernetes for about six to eight months without doing anything because it was just a lot.
**CRAIG BOX: One of the other things that you said about your initial contribution is that you had to learn how to use Git. As a very powerful tool, I find Git is a high barrier to entry for even contributing code to a project. When you want to contribute a blog post or documentation or a fix like you did before, I find it almost impossible to think how a new user would come along and do that. What was your process? Do you think that there's anything we can do to make that barrier lower for new contributors?**
SAVITHA RAGHUNATHAN: Of course. There are more and more tutorials available these days. There is a new contributor workshop. They actually have a [GitHub workflow section](https://www.kubernetes.dev/docs/guide/github-workflow/), [how to do a pull request](https://www.kubernetes.dev/docs/guide/pull-requests/) and stuff like that. I know a couple of folks from SIG Docs that are working on which Git commands that you need, or how to get to writing something small and getting it committed. But more tutorials or more links to intro to Git would definitely help.
The thing is also, someone like a documentation writer — they don't actually want to know the entirety of Git. Honestly, it's an ocean. I don't know how to do it. Most of the time, I still ask for help even though I work with Git on a day to day basis. There are several articles and a lot of help is available already within the community. Maybe we could just add a couple more to [kubernetes.dev](https://kubernetes.dev/). That is an amazing site for all the new contributors and existing contributors who want to build code, who want to write documentation.
We could just add a tutorial there like, "hey, don't know Git, you are new to Git? You just need to know these main things".
**CRAIG BOX: I find it a shame, to be honest, that people need to use Git for that, by comparison to Wikipedia where you can come along, and even though it might be written in Markdown or something like it, it seems like the barrier is a lot lower. Similar to you, I always have to look up anything more complicated than the five or six Git commands that I use on a day to day basis. Even to do simple things, I basically just go and follow a recipe which I find on the internet.**
SAVITHA RAGHUNATHAN: This is how I got introduced to one of the amazing mentors in Kubernetes. Everyone knows him by his handle, Dims. It was my second PR to the Kubernetes website, and I made a mistake. I destroyed the Git history. I could not push my reviews and comments — I addressed them. I couldn't push them back.
My immediate thought was to delete it and recreate, do another pull request. But then I was like, "what happens to others who have already put effort into reviewing them?" I asked for help, and Dims was there.
I would say I just got lucky he was there. And he was like, "OK, let me walk you through". We did troubleshooting through Slack messages. I copied and pasted all the errors. Every single command that he said, I copied and pasted. And then he was like, "OK, run this one. Try this one. And do this one".
Finally, I got it fixed. So you know what I did? I went and I stored the command history somewhere local for the next time when I run into this problem. Luckily, I haven't. But I find the contributors so helpful. They are busy. They have a lot of things to do, but they take moments to stop and help someone who's new.
That is also another part of the reason why I stay — I want to contribute more. It's mainly the community. It's the Kubernetes community. I know you asked me about Git, and I just took the conversation to the Kubernetes community. That's how my brain works.
**CRAIG BOX: A lot of people in the community do that and think that's fantastic, obviously, people like Dims who are just floating around on Slack and seem to have endless time. I don't know how they do it.**
SAVITHA RAGHUNATHAN: I really want to know the secret for endless time. If I only had 48 hours in a day. I would sleep for 16 hours, and I would use the rest of the time for doing the things that I want.
**CRAIG BOX: If I had a chance to sleep up to 48 hours a day, I think it'd be a lot more than 16.**
**Now, one of the areas that you've been contributing to Kubernetes is in the release team. In 1.18, you were a shadow for the docs role. You led that role in 1.19. And you were a release lead shadow for versions 1,20 and 1.21 before finally leading this release, 1.22, which we will talk about soon.**
**How did you get involved? And how did you decide which roles to take as you went through that process?**
SAVITHA RAGHUNATHAN: That is a topic I love to talk about. This was fresh when I started learning about Kubernetes and using Kubernetes at work. And I got so much help from the community, I got interested in contributing back.
At the first KubeCon that I attended in 2018, in Seattle, they had a speed mentoring session. Now they call it "pod mentoring". I went to the session, and said, "hey, I want to contribute. I don't know where to start". And I got a lot of information on how to get started.
One of the places was SIG Release and the release team. I came back and diligently attended all the SIG Release meetings for four to six months. And in between, I applied to the Kubernetes release team — 1.14 and 1.15. I didn't get through. So I took a little bit of a break, and I focused on doing some documentation work. Then I applied for 1.18.
Since I was already working on some kinds of — not like full fledged "documentation" documentation, I still don't write. I eventually want to write something really nice and full fledged documentation like other awesome folks.
**CRAIG BOX: You'll need a lot more than 48 hours in your day to do that.**
SAVITHA RAGHUNATHAN: *laughing* That's how I applied for the docs role, because I know a little bit about the website. I've done a few pull requests and commits. That's how I got started. I applied for that one role, and I got selected for the 1.18 team. That's how my journey just took off.
And the next release, I was leading the documentation team. And as everyone knows, the pandemic hit. It was one of the longest releases. I could lean back on the community. I would just wait for the release team meetings.
It was my way of coping with the pandemic. It took my mind off. It was actually more than a release team, they were people. They were all people first, and we took care of each other. So it felt good.
And then, I became a release lead shadow for 1.20 and 1.21 because I wanted to know more. I wanted to learn more. I wasn't ready. I still don't feel ready, but I have led 1.22. So if I could do it, anyone could do it.
**CRAIG BOX: How much of this work is day job?**
SAVITHA RAGHUNATHAN: I am lucky to be blessed with an awesome team. I do most of my work after work, but there have been times where I have to take meetings and attend to immediate urgent stuff. During the time of exception requests and stuff like that, I take a little bit of time from my work.
My team has been wonderful: they support me in all possible ways, and the management as well. Other than the meetings, I don't do much of the work during the day job. It just takes my focus and attention away too much, and I end up having to spend a lot of time sitting in front of the computer, which I don't like.
Before the pandemic I had a good work life balance. I'd just go to work at 7:00, 7:30, and I'd be back by 4 o'clock. I never touched my laptop ever again. I left all work behind when I came home. So right now, I'm still learning how to get through.
I try to limit the amount of open source work that I do during work time. The release lead shadow and the release lead job — they require a lot of time, effort. So on average, I'd be spending two to three hours post work time on the release activities.
**CRAIG BOX: Before the pandemic, everyone was worried that if we let people work from home, they wouldn't work enough. I think the opposite has actually happened, is that now we're worried that if we let people work from home, they will just get on the computer in the morning and you'll have to pry it out of their hands at midnight.**
SAVITHA RAGHUNATHAN: Yeah, I think the productivity has increased at least twofold, I would say, for everyone, once they started working from home.
**CRAIG BOX: But at the expense of work-life balance, though, because as you say, when you're sitting in the same chair in front of, perhaps, the same computer doing your MathWorks work and then your open source work, they kind of can blur into one perhaps?**
SAVITHA RAGHUNATHAN: That is a challenge. I face it every day. But so many others are also facing it. I implemented a few little tricks to help me. When I used to come back home from work, the first thing I would do is remove my watch. That was an indication that OK, I'm done.
That's the thing that I still do. I just remove my watch, and I just keep it right where my workstation is. And I just close the door so that I never look back. Even going past the room, I don't get a glimpse of my work office. I start implementing tiny little things like that to avoid burnout.
I think I'm still facing a little bit of burnout. I don't know if I have fully recovered from it. I constantly feel like I need a vacation. And I could just take a vacation for like a month or two. If it's possible, I will just do it.
**CRAIG BOX: I do hope that travel opens up for everyone as an opportunity because I know that, for a lot of people, it's not so much they've been working from home but they've been living at work. The idea of taking vacation effectively means, well, I've been stuck in the same place, if I've been under a lockdown. It's hard to justify that. It will be good as things improve worldwide for us to be able to start focusing more on mental health and perhaps getting away from the "everything room," as I sometimes call it.**
SAVITHA RAGHUNATHAN: I'm totally looking forward to it. I hope that travel opens up and I could go home and I could meet my siblings and my aunt and my parents.
**CRAIG BOX: Catch a cricket match?**
SAVITHA RAGHUNATHAN: Yeah. Probably yes, if I have company and if there is anything interesting happening around the time. I don't mind going back to the Chepauk Stadium and catching a match or two.
**CRAIG BOX: Let's turn now to the recently released [Kubernetes 1.22](https://kubernetes.io/blog/2021/08/04/kubernetes-1-22-release-announcement/). Congratulations on the launch.**
SAVITHA RAGHUNATHAN: Thank you.
**CRAIG BOX: Each launch comes with a theme and a mascot or a logo. What is the theme for this release?**
SAVITHA RAGHUNATHAN: The theme for the release is reaching new peaks. I am fascinated with a lot of space travel and chasing stars, the Milky Way. The best place to do that is over the top of a mountain. So that is the release logo, basically. It's a mountain — Mount Rainier. On top of that, there is a Kubernetes flag, and it's overlooking the Milky Way.
It's also symbolic that with every release, that we are achieving something new, bigger, and better, and we are making the release awesome. So I just wanted to incorporate that into the team as to say, we are achieving new things with every release. That's the "reaching new peaks" theme.
**CRAIG BOX: The last couple of releases have both been incrementally larger — as a result, perhaps, of the fact there are now only three releases per year rather than four. There were also changes to the process, where the work has been driven a lot more by the SIGs than by the release team having to go and ask the SIGs what was going on. What can you say about the size and scope of the 1.22 release?**
SAVITHA RAGHUNATHAN: The 1.22 release is the largest release to date. We have 56 enhancements if I'm not wrong, and we have a good amount of features that's graduated as stable. You can now say that Kubernetes as a project has become more mature because you see new features coming in. At the same time, you see the features that weren't used getting deprecated — we have like three deprecations in this release.
Aside from that fact, we also have a big team that's supporting one of the longest releases. This is the first official release cycle after the cadence KEP got approved. Officially, we are at four months, even though 1.19 was six months, and 1.21 was like 3 and 1/2 months, I think, this is the first one after the official KEP approval.
**CRAIG BOX: What changes did you make to the process knowing that you had that extra month?**
SAVITHA RAGHUNATHAN: One of the things the community had asked for is more time for development. We tried to incorporate that in the release schedule. We had about six weeks between the enhancements freeze and the code freeze. That's one.
It might not be visible to everyone, but one of the things that I wanted to make sure of was the health of the team — since it was a long, long release, we had time to plan out, and not have everyone work during the weekends or during their evenings or time off. That actually helped everyone keep their sanity, and also in making good progress and delivering good results at the end of the release. That's one of the process improvements that I'd call out.
We got better by making a post during the exception request process. Everyone works around the world. People from the UK start a little earlier than the people in the US East Coast. The West Coast starts three hours later than the East Coast. We used to make a post every Friday evening saying "hey, we actually received this many requests. We have addressed a number of them. We are waiting on a couple, or whatever. All the release team members are done for the day. We will see you around on Monday. Have a good weekend." Something like that.
We set the expectations from the community as well. We understand things are really important and urgent, but we are done. This gave everyone their time back. They don't have to worry over the weekend thinking like, hey, what's happening? What's happening in the release? They could spend time with their family, or they could do whatever they want to do, like go on a hike, or just sit and watch TV.
There have been weekends that I just did that. I just binge-watched a series. That's what I did.
**CRAIG BOX: Any recommendations?**
SAVITHA RAGHUNATHAN: I'm a big fan of Marvel, so I have watched the new [Loki](https://en.wikipedia.org/wiki/Loki_(TV_series)), which I really love. Loki is one of my favourite characters in Marvel. And I also liked [WandaVision](https://en.wikipedia.org/wiki/WandaVision). That was good, too.
**CRAIG BOX: I've not seen Loki yet, but I've heard it described as the best series of Doctor Who in the last few years.**
SAVITHA RAGHUNATHAN: Really?
**CRAIG BOX: There must be an element of time-travelling in there if that's how people are describing it.**
SAVITHA RAGHUNATHAN: You should really go and watch it whenever you have time. It's really amazing. I might go back and watch it again because I might have missed bits and pieces. That always happens in Marvel movies and the episodes; you need to watch them a couple of times to catch, "oh, this is how they relate".
**CRAIG BOX: Yes, the mark of good media that you want to immediately go back and watch it again once you've seen it.**
**Let's look now at some of the new features in Kubernetes 1.22. A couple of things that have graduated to general availability — server-side apply, external credential providers, a couple of new security features — the replacement for pod security policy has been announced, and seccomp is now available by default.**
**Do you have any favourite features in 1.22 that you'd like to discuss?**
SAVITHA RAGHUNATHAN: I have a lot of them. All my favourite features are related to security. OK, one of them is not security, but a major theme of my favourite KEPs is security. I'll start with the [default seccomp](https://github.com/kubernetes/enhancements/issues/2413). I think it will help make clusters secure by default, and may assist in preventing more vulnerabilities, which means less headaches for the cluster administrators.
This is close to my heart because the base of the MathWorks platform is provisioning Kubernetes clusters. Knowing that they are secure by default will definitely provide me with some good sleep. And also, I'm paranoid about security most of the time. I'm super interested in making everything secure. It might get in the way of making the users of the platform angry because it's not usable in any way.
My next one is [rootless Kubelet](https://github.com/kubernetes/enhancements/issues/2033). That feature's going to enable the cluster admin, the platform developers to deploy Kubernetes components to run in a user namespace. And I think that is also a great addition.
Like you mention, the most awaited drop in for the PSP replacement is here. It's [pod admission control](https://github.com/kubernetes/enhancements/issues/2579). It lets cluster admins apply the pod security standards. And I think it's just not related to the cluster admins. I might have to go back and check on that. Anyone can probably use it — the developers and the admins alike.
It also supports various modes, which is most welcome. There are times where you don't want to just cut the users off because they are trying to do something which is not securely correct. You just want to warn them, hey, this is what you are doing. This might just cause a security issue later, so you might want to correct it. But you just don't want to cut them off from using the platform, or them trying to attempt to do something — deploy their workload and get their day-to-day job done. That is something that I really like, that it also supports a warning mechanism.
Another one which is not security is [node swap support](https://github.com/kubernetes/enhancements/issues/2400). Kubernetes didn't have support for swap before, but it is taken into consideration now. This is an alpha feature. With this, you can take advantage of the swap, which is provisioned on the Linux VMs.
Some of the workloads — when they are deployed, they might need a lot of swap for the start-up — example, like Node and Java applications, which I just took out of their KEP user stories. So if anyone's interested, they can go and look in the KEP. That's useful. And it also increases the node stability and whatnot. So I think it's going to be beneficial for a lot of folks.
We know how Java and containers work. I think it has gotten better, but five years ago, it was so hard to get a Java application to fit in a small container. It always needed a lot of memory, swap, and everything to start up and run. I think this will help the users and help the admins and keep the cost low, and it will tie into so many other things as well. I'm excited about that feature.
Another feature that I want to just call out — I don't use Windows that much, but I just want to give a shout out to the folks who are doing an amazing job bringing all the Kubernetes features to Windows as well, to give a seamless experience.
One of the things is [Windows privileged containers](https://github.com/kubernetes/enhancements/issues/1981). I think it went alpha this release. And that is a wonderful addition, if you ask me. It can take advantage of whatever that's happening on the Linux side. And they can also port it over and see, OK, I can now run Windows containers in a privileged mode.
So whatever they are trying to achieve, they can do it. So that's a noteworthy mention. I need to give a shout out for the folks who work and make things happen in the Windows ecosystem as well.
**CRAIG BOX: One of the things that's great about the release process is the continuity between groups and teams. There's always an emeritus advisor who was a lead from a previous release. One thing that I always ask when I do these interviews is, what is the advice that you give to the next person? When [we talked to Nabarun for the 1.21 interview](https://kubernetespodcast.com/episode/146-kubernetes-1.21/), he said that his advice to you would be "do, delegate, and defer". Figure out what you can do, figure out what you can ask other people to do, and figure out what doesn't need to be done. Were you able to take that advice on board?**
SAVITHA RAGHUNATHAN: Yeah, you won't believe it. [I have it right here stuck to my monitor.](https://twitter.com/KubernetesPod/status/1423188323347177474/photo/3)
**CRAIG BOX: Next to your Git cheat sheet?**
SAVITHA RAGHUNATHAN: *laughs* Absolutely. I just have it stuck there. I just took a look at it.
**CRAIG BOX: Someone that you will have been able to delegate and defer to is Rey Lejano from Rancher Labs and SUSE, who is the release lead to be for 1.23.**
SAVITHA RAGHUNATHAN: I want to tell Rey to beware of the team's mental health. Schedule in such a way that it avoids burnout. Check in, and make sure that everyone is doing good. If they need some kind of help, create a safe space where they can actually ask for help, if they want to step back, if they need someone to cover.
I think that is most important. The releases are successful based on the thousands and thousands of contributors. But when it comes to a release team, you need to have a healthy team where people feel they are in a good place and they just want to make good contributions, which means they want to be heard. That's one thing that I want to tell Rey.
Also collaborate and learn from each other. I constantly learn. I think the team was 39 folks, including me. Every day I learned something or the other, even starting from how to interact.
Sometimes I have learned more leadership skills from my release lead shadows. They are awesome, and they are mature. I constantly learn from them, and I admire them a lot.
It also helps to have good, strong individuals in the team who can step up and help when needed. For example, unfortunately, we lost one of our teammates after the start of the release cycle. That was tragic. His name was [Peeyush Gupta](https://github.com/cncf/memorials/blob/main/peeyush-gupta.md). He was an awesome and wonderful human — very warm.
I didn't get more of a chance to interact with him. I had exchanged a few Slack messages, but I got his warm personality. I just want to take a couple of seconds to remember him. He was awesome.
After we lost him, we had this strong person from the team step up and lead the communications, who had never been a part of the release team before at all. He was a shadow for the first time. His name is Jesse Butler. So he stepped up, and he just took it away. He ran the comms show for 1.22.
That's what the community is about. You take care of team members, and the team will take care of you. So that's one other thing that I want to let Rey know, and maybe whoever — I think it's applicable overall.
**CRAIG BOX: There's a link to a [family education fund for Peeyush Gupta](https://milaap.org/fundraisers/support-peeyush-gupta-family-education), which you can find in the show notes.**
**Five releases in a row now you've been a member of the release team. Will you be putting your feet up now for 1.23?**
SAVITHA RAGHUNATHAN: I am going to take a break for a while. In the future, I want to be contributing, if not the release team, the SIG Release and the release management effort. But right now, I have been there for five releases. And I feel like, OK, I just need a little bit of fresh air.
And also the pandemic and the burnout has caught up, so I'm going to take a break from certain contributions. You will see me in the future. I will be around, but I might not be actively participating in the release team activities. I will be around the community. Anyone can reach out to me. They all know my Slack, so they can just reach out to me via Slack or Twitter.
**CRAIG BOX: Yes, your Twitter handle is CoffeeArtGirl. Does that mean that you'll be spending some time working on your lattes?**
SAVITHA RAGHUNATHAN: I am very bad at making lattes. The coffee art means that I used to [make art with coffee](https://twitter.com/KubernetesPod/status/1423188323347177474/photo/1). You get instant coffee powder and just mix it with water. You get the colours, very beautiful brown colours. I used to make art using that.
And I love coffee. So I just combined all the words together. And I had to come up with it in a span of one hour or so because I was joining this 'meet our contributors' panel. And Paris asked me, "do you have a Twitter handle?" I was planning to create one, but I didn't have the time.
I'm like, well, let me just think what I could just come up with real quick. So I just came up with that. So that's the story behind my Twitter handle. Everyone's interested in it. You are not the first person you have asked me or mentioned about it. So many others are like, why coffee art?
**CRAIG BOX: And you are also interested in art with perhaps other materials?**
SAVITHA RAGHUNATHAN: Yes. My interests keep changing. I used to do pebble art. It's just collecting pebbles from wherever I go, and I used to paint on them. I used to use watercolour, but I want to come back to watercolour sometime.
My recent interests are coloured pencils, which came back. When I was very young, I used to do a lot of coloured pencils. And then I switched to watercolours and oil painting. So I just go around in circles.
One of the hobbies that I picked up during a pandemic is crochet. I made a scarf for Mother's Day. My mum and my dad were here last year. They got stuck because of the pandemic, and they couldn't go back home. So they stayed with me for 10 months. That is the jackpot that I had, that I got to spend so much time with my parents after I moved to the US.
**CRAIG BOX: And they got rewarded with a scarf.**
SAVITHA RAGHUNATHAN: Yeah.
**CRAIG BOX: One to share between them.**
SAVITHA RAGHUNATHAN: I started making a blanket for my dad. And it became so heavy, I might have to just pick up some lighter yarn. I still don't know the differences between different kinds of yarns, but I'm getting better.
I started out because I wanted to make these little toys. They call them [amigurumi](https://en.wikipedia.org/wiki/Amigurumi) in the crochet world. I wanted to make them. That's why I started out. I'm trying. I made [a little cat](https://twitter.com/KubernetesPod/status/1423188323347177474/photo/2) which doesn't look like a cat, but it is a cat. I have to tell everyone that it's a cat so that they don't mock me later, but.
**CRAIG BOX: It's an artistic interpretation of a cat.**
SAVITHA RAGHUNATHAN: It definitely is!
---
_[Savitha Raghunathan](https://twitter.com/coffeeartgirl), now a Senior Software Engineer at Red Hat, served as the Kubernetes 1.22 release team lead._
_You can find the [Kubernetes Podcast from Google](http://www.kubernetespodcast.com/) at [@KubernetesPod](https://twitter.com/KubernetesPod) on Twitter, and you can [subscribe](https://kubernetespodcast.com/subscribe/) so you never miss an episode._
+1
View File
@@ -19,6 +19,7 @@ cid: community
<div class="community__navbar">
<a href="https://www.kubernetes.dev/">Contributor Community</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#values">Community Values</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#conduct">Code of conduct </a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<a href="#videos">Videos</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
@@ -43,11 +43,11 @@ The controllers inside the cloud controller manager include:
### Node controller
The node controller is responsible for creating {{< glossary_tooltip text="Node" term_id="node" >}} objects
The node controller is responsible for updating {{< glossary_tooltip text="Node" term_id="node" >}} objects
when new servers are created in your cloud infrastructure. The node controller obtains information about the
hosts running inside your tenancy with the cloud provider. The node controller performs the following functions:
1. Initialize a Node object for each server that the controller discovers through the cloud provider API.
1. Update a Node object with the corresponding server's unique identifier obtained from the cloud provider API.
2. Annotating and labelling the Node object with cloud-specific information, such as the region the node
is deployed into and the resources (CPU, memory, etc) that it has available.
3. Obtain the node's hostname and network addresses.
@@ -37,6 +37,24 @@ to the labels, each `EndpointSlice` that is managed on behalf of a Service has
an owner reference. Owner references help different parts of Kubernetes avoid
interfering with objects they dont control.
{{< note >}}
Cross-namespace owner references are disallowed by design.
Namespaced dependents can specify cluster-scoped or namespaced owners.
A namespaced owner **must** exist in the same namespace as the dependent.
If it does not, the owner reference is treated as absent, and the dependent
is subject to deletion once all owners are verified absent.
Cluster-scoped dependents can only specify cluster-scoped owners.
In v1.20+, if a cluster-scoped dependent specifies a namespaced kind as an owner,
it is treated as having an unresolvable owner reference, and is not able to be garbage collected.
In v1.20+, if the garbage collector detects an invalid cross-namespace `ownerReference`,
or a cluster-scoped dependent with an `ownerReference` referencing a namespaced kind, a warning Event
with a reason of `OwnerRefInvalidNamespace` and an `involvedObject` of the invalid dependent is reported.
You can check for that kind of Event by running
`kubectl get events -A --field-selector=reason=OwnerRefInvalidNamespace`.
{{< /note >}}
## Cascading deletion {#cascading-deletion}
Kubernetes checks for and deletes objects that no longer have owner
+104 -53
View File
@@ -72,7 +72,8 @@ The name of a Node object must be a valid
The [name](/docs/concepts/overview/working-with-objects/names#names) identifies a Node. Two Nodes
cannot have the same name at the same time. Kubernetes also assumes that a resource with the same
name is the same object. In case of a Node, it is implicitly assumed that an instance using the
same name will have the same state (e.g. network settings, root disk contents). This may lead to
same name will have the same state (e.g. network settings, root disk contents)
and attributes like node labels. This may lead to
inconsistencies if an instance was modified without changing its name. If the Node needs to be
replaced or updated significantly, the existing Node object needs to be removed from API server
first and re-added after the update.
@@ -98,6 +99,21 @@ When the [Node authorization mode](/docs/reference/access-authn-authz/node/) and
[NodeRestriction admission plugin](/docs/reference/access-authn-authz/admission-controllers/#noderestriction) are enabled,
kubelets are only authorized to create/modify their own Node resource.
{{< note >}}
As mentioned in the [Node name uniqueness](#node-name-uniqueness) section,
when Node configuration needs to be updated, it is a good practice to re-register
the node with the API server. For example, if the kubelet being restarted with
the new set of `--node-labels`, but the same Node name is used, the change will
not take an effect, as labels are being set on the Node registration.
Pods already scheduled on the Node may misbehave or cause issues if the Node
configuration will be changed on kubelet restart. For example, already running
Pod may be tainted against the new labels assigned to the Node, while other
Pods, that are incompatible with that Pod will be scheduled based on this new
label. Node re-registration ensures all Pods will be drained and properly
re-scheduled.
{{< /note >}}
### Manual Node administration
You can create and modify Node objects using
@@ -122,6 +138,9 @@ To mark a Node unschedulable, run:
kubectl cordon $NODENAME
```
See [Safely Drain a Node](/docs/tasks/administer-cluster/safely-drain-node/)
for more details.
{{< note >}}
Pods that are part of a {{< glossary_tooltip term_id="daemonset" >}} tolerate
being run on an unschedulable Node. DaemonSets typically provide node-local services
@@ -162,8 +181,8 @@ The `conditions` field describes the status of all `Running` nodes. Examples of
| Node Condition | Description |
|----------------------|-------------|
| `Ready` | `True` if the node is healthy and ready to accept pods, `False` if the node is not healthy and is not accepting pods, and `Unknown` if the node controller has not heard from the node in the last `node-monitor-grace-period` (default is 40 seconds) |
| `DiskPressure` | `True` if pressure exists on the disk size--that is, if the disk capacity is low; otherwise `False` |
| `MemoryPressure` | `True` if pressure exists on the node memory--that is, if the node memory is low; otherwise `False` |
| `DiskPressure` | `True` if pressure exists on the disk sizethat is, if the disk capacity is low; otherwise `False` |
| `MemoryPressure` | `True` if pressure exists on the node memorythat is, if the node memory is low; otherwise `False` |
| `PIDPressure` | `True` if pressure exists on the processes—that is, if there are too many processes on the node; otherwise `False` |
| `NetworkUnavailable` | `True` if the network for the node is not correctly configured, otherwise `False` |
{{< /table >}}
@@ -174,7 +193,8 @@ If you use command-line tools to print details of a cordoned Node, the Condition
cordoned nodes are marked Unschedulable in their spec.
{{< /note >}}
The node condition is represented as a JSON object. For example, the following structure describes a healthy node:
In the Kubernetes API, a node's condition is represented as part of the `.status`
of the Node resource. For example, the following JSON structure describes a healthy node:
```json
"conditions": [
@@ -189,7 +209,17 @@ The node condition is represented as a JSON object. For example, the following s
]
```
If the Status of the Ready condition remains `Unknown` or `False` for longer than the `pod-eviction-timeout` (an argument passed to the {{< glossary_tooltip text="kube-controller-manager" term_id="kube-controller-manager" >}}), then all the Pods on the node are scheduled for deletion by the node controller. The default eviction timeout duration is **five minutes**. In some cases when the node is unreachable, the API server is unable to communicate with the kubelet on the node. The decision to delete the pods cannot be communicated to the kubelet until communication with the API server is re-established. In the meantime, the pods that are scheduled for deletion may continue to run on the partitioned node.
If the `status` of the Ready condition remains `Unknown` or `False` for longer
than the `pod-eviction-timeout` (an argument passed to the
{{< glossary_tooltip text="kube-controller-manager" term_id="kube-controller-manager"
>}}), then the [node controller](#node-controller) triggers
{{< glossary_tooltip text="API-initiated eviction" term_id="api-eviction" >}}
for all Pods assigned to that node. The default eviction timeout duration is
**five minutes**.
In some cases when the node is unreachable, the API server is unable to communicate
with the kubelet on the node. The decision to delete the pods cannot be communicated to
the kubelet until communication with the API server is re-established. In the meantime,
the pods that are scheduled for deletion may continue to run on the partitioned node.
The node controller does not force delete pods until it is confirmed that they have stopped
running in the cluster. You can see the pods that might be running on an unreachable node as
@@ -199,10 +229,12 @@ may need to delete the node object by hand. Deleting the node object from Kubern
all the Pod objects running on the node to be deleted from the API server and frees up their
names.
The node lifecycle controller automatically creates
[taints](/docs/concepts/scheduling-eviction/taint-and-toleration/) that represent conditions.
When problems occur on nodes, the Kubernetes control plane automatically creates
[taints](/docs/concepts/scheduling-eviction/taint-and-toleration/) that match the conditions
affecting the node.
The scheduler takes the Node's taints into consideration when assigning a Pod to a Node.
Pods can also have tolerations which let them tolerate a Node's taints.
Pods can also have {{< glossary_tooltip text="tolerations" term_id="toleration" >}} that let
them run on a Node even though it has a specific taint.
See [Taint Nodes by Condition](/docs/concepts/scheduling-eviction/taint-and-toleration/#taint-nodes-by-condition)
for more details.
@@ -222,10 +254,43 @@ on a Node.
### Info
Describes general information about the node, such as kernel version, Kubernetes version (kubelet and kube-proxy version), Docker version (if used), and OS name.
This information is gathered by Kubelet from the node.
Describes general information about the node, such as kernel version, Kubernetes
version (kubelet and kube-proxy version), container runtime details, and which
operating system the node uses.
The kubelet gathers this information from the node and publishes it into
the Kubernetes API.
### Node controller
## Heartbeats
Heartbeats, sent by Kubernetes nodes, help your cluster determine the
availability of each node, and to take action when failures are detected.
For nodes there are two forms of heartbeats:
* updates to the `.status` of a Node
* [Lease](/docs/reference/kubernetes-api/cluster-resources/lease-v1/) objects
within the `kube-node-lease`
{{< glossary_tooltip term_id="namespace" text="namespace">}}.
Each Node has an associated Lease object.
Compared to updates to `.status` of a Node, a Lease is a lightweight resource.
Using Leases for heartbeats reduces the performance impact of these updates
for large clusters.
The kubelet is responsible for creating and updating the `.status` of Nodes,
and for updating their related Leases.
- The kubelet updates the node's `.status` either when there is change in status
or if there has been no update for a configured interval. The default interval
for `.status` updates to Nodes is 5 minutes, which is much longer than the 40
second default timeout for unreachable nodes.
- The kubelet creates and then updates its Lease object every 10 seconds
(the default update interval). Lease updates occur independently from
updates to the Node's `.status`. If the Lease update fails, the kubelet retries,
using exponential backoff that starts at 200 milliseconds and capped at 7 seconds.
## Node controller
The node {{< glossary_tooltip text="controller" term_id="controller" >}} is a
Kubernetes control plane component that manages various aspects of nodes.
@@ -241,39 +306,18 @@ controller deletes the node from its list of nodes.
The third is monitoring the nodes' health. The node controller is
responsible for:
- Updating the NodeReady condition of NodeStatus to ConditionUnknown when a node
becomes unreachable, as the node controller stops receiving heartbeats for some
reason such as the node being down.
- Evicting all the pods from the node using graceful termination if
the node continues to be unreachable. The default timeouts are 40s to start
reporting ConditionUnknown and 5m after that to start evicting pods.
- In the case that a node becomes unreachable, updating the NodeReady condition
of within the Node's `.status`. In this case the node controller sets the
NodeReady condition to `ConditionUnknown`.
- If a node remains unreachable: triggering
[API-initiated eviction](/docs/concepts/scheduling-eviction/api-eviction/)
for all of the Pods on the unreachable node. By default, the node controller
waits 5 minutes between marking the node as `ConditionUnknown` and submitting
the first eviction request.
The node controller checks the state of each node every `--node-monitor-period` seconds.
#### Heartbeats
Heartbeats, sent by Kubernetes nodes, help determine the availability of a node.
There are two forms of heartbeats: updates of `NodeStatus` and the
[Lease object](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#lease-v1-coordination-k8s-io).
Each Node has an associated Lease object in the `kube-node-lease`
{{< glossary_tooltip term_id="namespace" text="namespace">}}.
Lease is a lightweight resource, which improves the performance
of the node heartbeats as the cluster scales.
The kubelet is responsible for creating and updating the `NodeStatus` and
a Lease object.
- The kubelet updates the `NodeStatus` either when there is change in status
or if there has been no update for a configured interval. The default interval
for `NodeStatus` updates is 5 minutes, which is much longer than the 40 second default
timeout for unreachable nodes.
- The kubelet creates and then updates its Lease object every 10 seconds
(the default update interval). Lease updates occur independently from the
`NodeStatus` updates. If the Lease update fails, the kubelet retries with
exponential backoff starting at 200 milliseconds and capped at 7 seconds.
#### Reliability
### Rate limits on eviction
In most cases, the node controller limits the eviction rate to
`--node-eviction-rate` (default 0.1) per second, meaning it won't evict pods
@@ -281,7 +325,7 @@ from more than 1 node per 10 seconds.
The node eviction behavior changes when a node in a given availability zone
becomes unhealthy. The node controller checks what percentage of nodes in the zone
are unhealthy (NodeReady condition is ConditionUnknown or ConditionFalse) at
are unhealthy (NodeReady condition is `ConditionUnknown` or `ConditionFalse`) at
the same time:
- If the fraction of unhealthy nodes is at least `--unhealthy-zone-threshold`
(default 0.55), then the eviction rate is reduced.
@@ -293,15 +337,17 @@ the same time:
The reason these policies are implemented per availability zone is because one
availability zone might become partitioned from the master while the others remain
connected. If your cluster does not span multiple cloud provider availability zones,
then there is only one availability zone (i.e. the whole cluster).
then the eviction mechanism does not take per-zone unavailability into account.
A key reason for spreading your nodes across availability zones is so that the
workload can be shifted to healthy zones when one entire zone goes down.
Therefore, if all nodes in a zone are unhealthy, then the node controller evicts at
the normal rate of `--node-eviction-rate`. The corner case is when all zones are
completely unhealthy (i.e. there are no healthy nodes in the cluster). In such a
case, the node controller assumes that there is some problem with master
connectivity and stops all evictions until some connectivity is restored.
completely unhealthy (none of the nodes in the cluster are healthy). In such a
case, the node controller assumes that there is some problem with connectivity
between the control plane and the nodes, and doesn't perform any evictions.
(If there has been an outage and some nodes reappear, the node controller does
evict pods from the remaining nodes that are unhealthy or unreachable).
The node controller is also responsible for evicting pods running on nodes with
`NoExecute` taints, unless those pods tolerate that taint.
@@ -309,7 +355,7 @@ The node controller also adds {{< glossary_tooltip text="taints" term_id="taint"
corresponding to node problems like node unreachable or not ready. This means
that the scheduler won't place Pods onto unhealthy nodes.
### Node capacity
## Resource capacity tracking {#node-capacity}
Node objects track information about the Node's resource capacity: for example, the amount
of memory available and the number of CPUs.
@@ -356,7 +402,7 @@ Graceful node shutdown is controlled with the `GracefulNodeShutdown`
enabled by default in 1.21.
Note that by default, both configuration options described below,
`ShutdownGracePeriod` and `ShutdownGracePeriodCriticalPods` are set to zero,
`shutdownGracePeriod` and `shutdownGracePeriodCriticalPods` are set to zero,
thus not activating Graceful node shutdown functionality.
To activate the feature, the two kubelet config settings should be configured appropriately and set to non-zero values.
@@ -366,13 +412,13 @@ During a graceful shutdown, kubelet terminates pods in two phases:
2. Terminate [critical pods](/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/#marking-pod-as-critical) running on the node.
Graceful node shutdown feature is configured with two [`KubeletConfiguration`](/docs/tasks/administer-cluster/kubelet-config-file/) options:
* `ShutdownGracePeriod`:
* `shutdownGracePeriod`:
* Specifies the total duration that the node should delay the shutdown by. This is the total grace period for pod termination for both regular and [critical pods](/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/#marking-pod-as-critical).
* `ShutdownGracePeriodCriticalPods`:
* Specifies the duration used to terminate [critical pods](/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/#marking-pod-as-critical) during a node shutdown. This value should be less than `ShutdownGracePeriod`.
* `shutdownGracePeriodCriticalPods`:
* Specifies the duration used to terminate [critical pods](/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/#marking-pod-as-critical) during a node shutdown. This value should be less than `shutdownGracePeriod`.
For example, if `ShutdownGracePeriod=30s`, and
`ShutdownGracePeriodCriticalPods=10s`, kubelet will delay the node shutdown by
For example, if `shutdownGracePeriod=30s`, and
`shutdownGracePeriodCriticalPods=10s`, kubelet will delay the node shutdown by
30 seconds. During the shutdown, the first 20 (30-10) seconds would be reserved
for gracefully terminating normal pods, and the last 10 seconds would be
reserved for terminating [critical pods](/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/#marking-pod-as-critical).
@@ -405,6 +451,11 @@ the kubelet, and the `--fail-swap-on` command line flag or `failSwapOn`
[configuration setting](/docs/reference/config-api/kubelet-config.v1beta1/#kubelet-config-k8s-io-v1beta1-KubeletConfiguration)
must be set to false.
{{< warning >}}
When the memory swap feature is turned on, Kubernetes data such as the content
of Secret objects that were written to tmpfs now could be swapped to disk.
{{< /warning >}}
A user can also optionally configure `memorySwap.swapBehavior` in order to
specify how a node will use swap memory. For example,
@@ -25,7 +25,7 @@ This page lists some of the available add-ons and links to their respective inst
* [Contrail](https://www.juniper.net/us/en/products-services/sdn/contrail/contrail-networking/), based on [Tungsten Fabric](https://tungsten.io), is an open source, multi-cloud network virtualization and policy management platform. Contrail and Tungsten Fabric are integrated with orchestration systems such as Kubernetes, OpenShift, OpenStack and Mesos, and provide isolation modes for virtual machines, containers/pods and bare metal workloads.
* [Flannel](https://github.com/flannel-io/flannel#deploying-flannel-manually) is an overlay network provider that can be used with Kubernetes.
* [Knitter](https://github.com/ZTE/Knitter/) is a plugin to support multiple network interfaces in a Kubernetes pod.
* [Multus](https://github.com/Intel-Corp/multus-cni) is a Multi plugin for multiple network support in Kubernetes to support all CNI plugins (e.g. Calico, Cilium, Contiv, Flannel), in addition to SRIOV, DPDK, OVS-DPDK and VPP based workloads in Kubernetes.
* Multus is a Multi plugin for multiple network support in Kubernetes to support all CNI plugins (e.g. Calico, Cilium, Contiv, Flannel), in addition to SRIOV, DPDK, OVS-DPDK and VPP based workloads in Kubernetes.
* [OVN-Kubernetes](https://github.com/ovn-org/ovn-kubernetes/) is a networking provider for Kubernetes based on [OVN (Open Virtual Network)](https://github.com/ovn-org/ovn/), a virtual networking implementation that came out of the Open vSwitch (OVS) project. OVN-Kubernetes provides an overlay based networking implementation for Kubernetes, including an OVS based implementation of load balancing and network policy.
* [OVN4NFV-K8S-Plugin](https://github.com/opnfv/ovn4nfv-k8s-plugin) is OVN based CNI controller plugin to provide cloud native based Service function chaining(SFC), Multiple OVN overlay networking, dynamic subnet creation, dynamic creation of virtual networks, VLAN Provider network, Direct provider network and pluggable with other Multi-network plugins, ideal for edge based cloud native workloads in Multi-cluster networking
* [NSX-T](https://docs.vmware.com/en/VMware-NSX-T/2.0/nsxt_20_ncp_kubernetes.pdf) Container Plug-in (NCP) provides integration between VMware NSX-T and container orchestrators such as Kubernetes, as well as integration between NSX-T and container-based CaaS/PaaS platforms such as Pivotal Container Service (PKS) and OpenShift.
@@ -45,6 +45,11 @@ This page lists some of the available add-ons and links to their respective inst
## Infrastructure
* [KubeVirt](https://kubevirt.io/user-guide/#/installation/installation) is an add-on to run virtual machines on Kubernetes. Usually run on bare-metal clusters.
* The
[node problem detector](https://github.com/kubernetes/node-problem-detector)
runs on Linux nodes and reports system issues as either
[Events](/docs/reference/kubernetes-api/cluster-resources/event-v1/) or
[Node conditions](/docs/concepts/architecture/nodes/#condition).
## Legacy Add-ons
@@ -26,6 +26,10 @@ fair queuing technique so that, for example, a poorly-behaved
{{< glossary_tooltip text="controller" term_id="controller" >}} need not
starve others (even at the same priority level).
This feature is designed to work well with standard controllers, which
use informers and react to failures of API requests with exponential
back-off, and other clients that also work this way.
{{< caution >}}
Requests classified as "long-running" — primarily watches — are not
subject to the API Priority and Fairness filter. This is also true for
@@ -102,6 +106,8 @@ name of the matching FlowSchema plus a _flow distinguisher_ — which
is either the requesting user, the target resource's namespace, or nothing — and the
system attempts to give approximately equal weight to requests in different
flows of the same priority level.
To enable distinct handling of distinct instances, controllers that have
many instances should authenticate with distinct usernames
After classifying a request into a flow, the API Priority and Fairness
feature then may assign the request to a queue. This assignment uses
@@ -81,7 +81,7 @@ rotate an application's logs automatically.
As an example, you can find detailed information about how `kube-up.sh` sets
up logging for COS image on GCP in the corresponding
[`configure-helper` script](https://github.com/kubernetes/kubernetes/blob/{{< param "githubbranch" >}}/cluster/gce/gci/configure-helper.sh).
[`configure-helper` script](https://github.com/kubernetes/kubernetes/blob/master/cluster/gce/gci/configure-helper.sh).
When using a **CRI container runtime**, the kubelet is responsible for rotating the logs and managing the logging directory structure.
The kubelet sends this information to the CRI container runtime and the runtime writes the container logs to the given location.
@@ -160,7 +160,7 @@ If you're interested in learning more about `kubectl`, go ahead and read [kubect
The examples we've used so far apply at most a single label to any resource. There are many scenarios where multiple labels should be used to distinguish sets from one another.
For instance, different applications would use different values for the `app` label, but a multi-tier application, such as the [guestbook example](https://github.com/kubernetes/examples/tree/{{< param "githubbranch" >}}/guestbook/), would additionally need to distinguish each tier. The frontend could carry the following labels:
For instance, different applications would use different values for the `app` label, but a multi-tier application, such as the [guestbook example](https://github.com/kubernetes/examples/tree/master/guestbook/), would additionally need to distinguish each tier. The frontend could carry the following labels:
```yaml
labels:

Some files were not shown because too many files have changed in this diff Show More