27b7b453a9
* Update metadata.generation behaviour for custom resources (#10705) * update docs promoting plugins to beta (#10796) * docs update to promote TaintBasedEvictions to beta (#10765) * First Korean l10n work for dev-1.13 (#10719) * Update outdated l10n(ko) contents (#10689) fixes #10686 * Translate concepts/overview/what-is-kubernetes in Korean (#10690) * Translate concepts/overview/what-is-kubernetes in Korean * Feedback from ClaudiaJKang * Translate concepts/overview/components in Korean (#10882) * Translate concepts/overview/components in Korean #10717 * Translate concepts/overview/components in Korean * Translate concepts/overview/components in Korean * Apply Korean glossary: 서비스 어카운트 * Translate concepts/overview/kubernetes-api in Korean (#10773) * Translate concepts/overview/kubernetes-api in Korean * Applied feedback from ianychoi * kubeadm: update the configuration docs to v1beta1 (#10959) * kubeadm: add small v1beta1 related updates (#10988) * ADD content/zh/docs/reference/setup-tools/kubeadm/kubeadm.md (#11031) * ADD content/zh/docs/reference/setup-tools/kubeadm/kubeadm.md * ADD content/zh/docs/reference/setup-tools/kubeadm/generated/kubeadm_init.md * Update content/zh/docs/reference/setup-tools/kubeadm/kubeadm.md Accepted Co-Authored-By: YouthLab <tsui@highyouth.com> * do not change 'master' or 'worker' nodes to '主从' * Doc updates for volume scheduling GA (#10743) * Doc updates for volume scheduling GA * Make trivial change to kick build * Document nodelease feature (#10699) * advanced audit doc for ModeBlockingStrict (#10203) * Rename EncryptionConfig to EncryptionConfiguration (#11080) EncryptionConfig was renamed to EncryptedConfiguration and added to the `apiserver.config.k8s.io` API group in Kubernetes 1.13. The feature was previously in alpha and was not handling versions properly, which lead to an originally unnoticed `v1` in the docs. * content/zh/docs/reference/setup-tools/kubeadm/kubeadm-init.md * trsanlate create-cluster-kubeadm.md to chinese (#11041) * trsanlate create-cluster-kubeadm.md to chinese * Update create-cluster-kubeadm.md * update the feature stage in v1.13 (#11307) * update new feature gates to document (#11295) * refresh controller role list on rbac description page (#11290) * node labeling restriction docs (#10944) * Update 1.13 docs for CSI GA (#10893) * dynamic audit documentation (#9947) * adds dynamic audit documentation * Copyedit for clarity See also inline question/s * Fix feature state shortcode * Update feature state * changes wording for dynamic audit flag behavior * Minor copyedit * fix dynamic audit yaml * adds api enablement command to dynamic audit docs * change ordering dynamic audit appears in * add references to dynamic audit in webhook backend * reword dynamic audit reference * updates stages field for audit sink object * changes audit sink api definition; rewords policy * kubeadm: remove kube-proxy workaround (#11162) * zh-trans content/en/docs/setup/independent/install-kubeadm.md (#11338) * zh-trans content/en/docs/setup/independent/install-kubeadm.md * Update install-kubeadm.md * Update dry run feature to beta (#11140) * vSphere volume raw block support doc update (#10932) * Add docs for Windows DNS configurations (#10036) * Update docs for fields allowed at root of CRD schema (#9973) * Add docs for Windows DNS configurations * add device monitoring documentation (#9945) * kubeadm: adds upgrade instructions for 1.13 (#11138) * kubeadm: adds upgrade instructions for 1.13 Signed-off-by: Chuck Ha <ha.chuck@gmail.com> * add minor copyedits Addressed a couple of copyedit comments a bit more cleanly. * kubeadm: add improvements to HA docs (#11094) * kubeadm: add information and diagrams for HA topologies * kubeadm: update HA doc with simplified steps * kubeadm: update HA doc with simplified steps * edit ha, add new topology topic, reorder by weight * troubleshoot markdown * fix more markdown, fix links * more markdown * more markdown * more markdown * changes after reviewer comments * add steps about Weave * update note about stacked topology * kubeadm external etcd HA upgrade 1.13 (#11364) * kubeadm external etcd HA upgrade 1.13 Signed-off-by: Ruben Orduz <rubenoz@gmail.com> * Update stacked controlplane steps * kubeadm cert documentation (#11093) * kubeadm certificate API and CSR documentation * copyedits * fix typo * PR for diff docs (#10789) * Empty commit against dev-1.13 for diff documentation * Complete Declarative maangement with diff commands * Second Korean l10n work for dev-1.13. (#11030) * Update outdated l10n(ko) contents (#10915) * Translate main menu for l10n(ko) docs (#10916) * Translate tasks/run-application/horizontal-pod-autoscale-walkthrough (#10980) * Translate content/ko/docs/concepts/overview/working-with-objects/kubernetes-object in Korean #11104 (#11332) * Pick-right-solution page translates into Korean. (#11340) * ko-trans: add jd/..., sap/..., ebay/..., homeoffice/... (#11336) * Translate concept/workloads/pods/pod-overview.md (#11092) Co-authored-by: June Yi <june.yi@samsung.com> Co-authored-by: Jesang Myung <jesang.myung@gmail.com> Co-authored-by: zerobig <38598117+zer0big@users.noreply.github.com> Co-authored-by: Claudia J.Kang <claudiajkang@gmail.com> Co-authored-by: lIuDuI <1693291525@qq.com> Co-authored-by: Woojin Na(Eddie) <cheapluv@gmail.com> * Rename encryption-at-rest related objects (#11059) EncryptionConfig was renamed to EncryptedConfiguration and added to the `apiserver.config.k8s.io` API group in Kubernetes 1.13. The feature was previously in alpha and was not handling versions properly, which lead to an originally unnoticed `v1` in the docs. Also, the `--experimental-encryption-provider-config` flag is now called just `--encryption-provider-config`. * Documenting FlexVolume Resize alpha feature. (#10097) * CR webhook conversion documentation (#10986) * CR Conversion * Addressing comments * Addressing more comments * Addressing even more comments * Addressing even^2 more comments * Remove references to etcd2 in v1.13 since support has been removed (#11414) * Remove etcd2 references as etcd2 is deprecated Link back to the v1.12 version of the etcd3 doc for the etcd2->etcd3 migration instructions. I updated the kube-apiserver reference manually, unsure if that is auto-generated somehow. The federation-apiserver can still potentially support etcd2 so I didn't touch that. * Remove outdated {master,node}.yaml files There are master/node yaml files that reference etcd2.service that are likely highly out of date. I couldn't find any docs that actually reference these templates so I removed them * Address review comments * Final Korean l10n work for dev-1.13 (#11440) * Update outdated l10n(ko) contents (#11425) fixes #11424 * Remove references to etcd2 in content/ko (#11416) * Resolve conflicts against master for /ko contents (#11438) * Fix unopened caution shortcode * kubeadm: update the reference docs for 1.13 (#10960) * docs update to promote TaintBasedEvictions to beta (#10765) * First Korean l10n work for dev-1.13 (#10719) * Update outdated l10n(ko) contents (#10689) fixes #10686 * Translate concepts/overview/what-is-kubernetes in Korean (#10690) * Translate concepts/overview/what-is-kubernetes in Korean * Feedback from ClaudiaJKang * Translate concepts/overview/components in Korean (#10882) * Translate concepts/overview/components in Korean #10717 * Translate concepts/overview/components in Korean * Translate concepts/overview/components in Korean * Apply Korean glossary: 서비스 어카운트 * Translate concepts/overview/kubernetes-api in Korean (#10773) * Translate concepts/overview/kubernetes-api in Korean * Applied feedback from ianychoi * kubeadm: update the configuration docs to v1beta1 (#10959) * kubeadm: add small v1beta1 related updates (#10988) * update new feature gates to document (#11295) * Update dry run feature to beta (#11140) * kubeadm: add improvements to HA docs (#11094) * kubeadm: add information and diagrams for HA topologies * kubeadm: update HA doc with simplified steps * kubeadm: update HA doc with simplified steps * edit ha, add new topology topic, reorder by weight * troubleshoot markdown * fix more markdown, fix links * more markdown * more markdown * more markdown * changes after reviewer comments * add steps about Weave * update note about stacked topology * kubeadm: update reference docs - add section about working with phases under kubeadm-init.md - update GA / beta status of features - kubeadm alpha phase was moved to kubeadm init phase - new commands were added under kubeadm alpha - included new CoreDNS usage examples * Generate components and tools reference * Add generated federation API Reference (#11491) * Add generated federation API Reference * Add front matter to federation reference * Remove whitespace from federation front matter * Remove more whitespace from federation front matter * Remove superfluous kubefed reference * Add frontmatter to generated kubefed reference * Fix kubefed reference page frontmatter * Generate kubectl reference docs 1.13 (#11487) * Generate kubectl reference docs 1.13 * Fix links in kubectl reference * Add 1.13 API reference (#11489) * Update config.toml (#11486) * Update config.toml Preparing for 1.13 release, updating the config.toml and dropping the 1.8 docs reference. * update dot releases and docsbranch typo * adding .Site. to Params.currentUrl (#11503) see https://github.com/kubernetes/website/pull/11502 for context * Add 1.13 Release notes (#11499)
187 lines
6.7 KiB
Markdown
187 lines
6.7 KiB
Markdown
---
|
|
title: Kubernetes Object Management
|
|
content_template: templates/concept
|
|
weight: 10
|
|
---
|
|
|
|
{{% capture overview %}}
|
|
The `kubectl` command-line tool supports several different ways to create and manage
|
|
Kubernetes objects. This document provides an overview of the different
|
|
approaches.
|
|
{{% /capture %}}
|
|
|
|
{{% capture body %}}
|
|
|
|
## Management techniques
|
|
|
|
{{< warning >}}
|
|
A Kubernetes object should be managed using only one technique. Mixing
|
|
and matching techniques for the same object results in undefined behavior.
|
|
{{< /warning >}}
|
|
|
|
| Management technique | Operates on |Recommended environment | Supported writers | Learning curve |
|
|
|----------------------------------|----------------------|------------------------|--------------------|----------------|
|
|
| Imperative commands | Live objects | Development projects | 1+ | Lowest |
|
|
| Imperative object configuration | Individual files | Production projects | 1 | Moderate |
|
|
| Declarative object configuration | Directories of files | Production projects | 1+ | Highest |
|
|
|
|
## Imperative commands
|
|
|
|
When using imperative commands, a user operates directly on live objects
|
|
in a cluster. The user provides operations to
|
|
the `kubectl` command as arguments or flags.
|
|
|
|
This is the simplest way to get started or to run a one-off task in
|
|
a cluster. Because this technique operates directly on live
|
|
objects, it provides no history of previous configurations.
|
|
|
|
### Examples
|
|
|
|
Run an instance of the nginx container by creating a Deployment object:
|
|
|
|
```sh
|
|
kubectl run nginx --image nginx
|
|
```
|
|
|
|
Do the same thing using a different syntax:
|
|
|
|
```sh
|
|
kubectl create deployment nginx --image nginx
|
|
```
|
|
|
|
### Trade-offs
|
|
|
|
Advantages compared to object configuration:
|
|
|
|
- Commands are simple, easy to learn and easy to remember.
|
|
- Commands require only a single step to make changes to the cluster.
|
|
|
|
Disadvantages compared to object configuration:
|
|
|
|
- Commands do not integrate with change review processes.
|
|
- Commands do not provide an audit trail associated with changes.
|
|
- Commands do not provide a source of records except for what is live.
|
|
- Commands do not provide a template for creating new objects.
|
|
|
|
## Imperative object configuration
|
|
|
|
In imperative object configuration, the kubectl command specifies the
|
|
operation (create, replace, etc.), optional flags and at least one file
|
|
name. The file specified must contain a full definition of the object
|
|
in YAML or JSON format.
|
|
|
|
See the [API reference](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/)
|
|
for more details on object definitions.
|
|
|
|
{{< warning >}}
|
|
The imperative `replace` command replaces the existing
|
|
spec with the newly provided one, dropping all changes to the object missing from
|
|
the configuration file. This approach should not be used with resource
|
|
types whose specs are updated independently of the configuration file.
|
|
Services of type `LoadBalancer`, for example, have their `externalIPs` field updated
|
|
independently from the configuration by the cluster.
|
|
{{< /warning >}}
|
|
|
|
### Examples
|
|
|
|
Create the objects defined in a configuration file:
|
|
|
|
```sh
|
|
kubectl create -f nginx.yaml
|
|
```
|
|
|
|
Delete the objects defined in two configuration files:
|
|
|
|
```sh
|
|
kubectl delete -f nginx.yaml -f redis.yaml
|
|
```
|
|
|
|
Update the objects defined in a configuration file by overwriting
|
|
the live configuration:
|
|
|
|
```sh
|
|
kubectl replace -f nginx.yaml
|
|
```
|
|
|
|
### Trade-offs
|
|
|
|
Advantages compared to imperative commands:
|
|
|
|
- Object configuration can be stored in a source control system such as Git.
|
|
- Object configuration can integrate with processes such as reviewing changes before push and audit trails.
|
|
- Object configuration provides a template for creating new objects.
|
|
|
|
Disadvantages compared to imperative commands:
|
|
|
|
- Object configuration requires basic understanding of the object schema.
|
|
- Object configuration requires the additional step of writing a YAML file.
|
|
|
|
Advantages compared to declarative object configuration:
|
|
|
|
- Imperative object configuration behavior is simpler and easier to understand.
|
|
- As of Kubernetes version 1.5, imperative object configuration is more mature.
|
|
|
|
Disadvantages compared to declarative object configuration:
|
|
|
|
- Imperative object configuration works best on files, not directories.
|
|
- Updates to live objects must be reflected in configuration files, or they will be lost during the next replacement.
|
|
|
|
## Declarative object configuration
|
|
|
|
When using declarative object configuration, a user operates on object
|
|
configuration files stored locally, however the user does not define the
|
|
operations to be taken on the files. Create, update, and delete operations
|
|
are automatically detected per-object by `kubectl`. This enables working on
|
|
directories, where different operations might be needed for different objects.
|
|
|
|
{{< note >}}
|
|
Declarative object configuration retains changes made by other
|
|
writers, even if the changes are not merged back to the object configuration file.
|
|
This is possible by using the `patch` API operation to write only
|
|
observed differences, instead of using the `replace`
|
|
API operation to replace the entire object configuration.
|
|
{{< /note >}}
|
|
|
|
### Examples
|
|
|
|
Process all object configuration files in the `configs` directory, and create or
|
|
patch the live objects. You can first `diff` to see what changes are going to be
|
|
made, and then apply:
|
|
|
|
```sh
|
|
kubectl diff -f configs/
|
|
kubectl apply -f configs/
|
|
```
|
|
|
|
Recursively process directories:
|
|
|
|
```sh
|
|
kubectl diff -R -f configs/
|
|
kubectl apply -R -f configs/
|
|
```
|
|
|
|
### Trade-offs
|
|
|
|
Advantages compared to imperative object configuration:
|
|
|
|
- Changes made directly to live objects are retained, even if they are not merged back into the configuration files.
|
|
- Declarative object configuration has better support for operating on directories and automatically detecting operation types (create, patch, delete) per-object.
|
|
|
|
Disadvantages compared to imperative object configuration:
|
|
|
|
- Declarative object configuration is harder to debug and understand results when they are unexpected.
|
|
- Partial updates using diffs create complex merge and patch operations.
|
|
|
|
{{% /capture %}}
|
|
|
|
{{% capture whatsnext %}}
|
|
- [Managing Kubernetes Objects Using Imperative Commands](/docs/concepts/overview/object-management-kubectl/imperative-command/)
|
|
- [Managing Kubernetes Objects Using Object Configuration (Imperative)](/docs/concepts/overview/object-management-kubectl/imperative-config/)
|
|
- [Managing Kubernetes Objects Using Object Configuration (Declarative)](/docs/concepts/overview/object-management-kubectl/declarative-config/)
|
|
- [Kubectl Command Reference](/docs/reference/generated/kubectl/kubectl-commands/)
|
|
- [Kubernetes API Reference](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/)
|
|
|
|
{{< comment >}}
|
|
{{< /comment >}}
|
|
{{% /capture %}}
|