mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-29 22:49:17 +00:00
@@ -18,7 +18,8 @@ In this command, `<DATE>` is a placeholder for the date that the data container
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the [procedure below](#creating-a-backup).
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the [procedure below](#creating-a-backup).
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
@@ -49,7 +50,7 @@ This procedure creates a backup that you can restore if Rancher encounters a dis
|
|||||||
docker create --volumes-from <RANCHER_CONTAINER_NAME> --name rancher-data-<DATE> rancher/rancher:<RANCHER_CONTAINER_TAG>
|
docker create --volumes-from <RANCHER_CONTAINER_NAME> --name rancher-data-<DATE> rancher/rancher:<RANCHER_CONTAINER_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
1. <a id="tarball"></a>From the data container that you just created (`rancher-data-<DATE>`), create a backup tarball (`rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz`). Use the following command, replacing each placeholder:
|
1. <a id="tarball"></a>From the data container that you just created (<code>rancher-data-<DATE></code>), create a backup tarball (<code>rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz</code>). Use the following command, replacing each placeholder:
|
||||||
|
|
||||||
```
|
```
|
||||||
docker run --volumes-from rancher-data-<DATE> -v $PWD:/backup:z busybox tar pzcvf /backup/rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz /var/lib/rancher
|
docker run --volumes-from rancher-data-<DATE> -v $PWD:/backup:z busybox tar pzcvf /backup/rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz /var/lib/rancher
|
||||||
|
|||||||
@@ -20,7 +20,8 @@ In this command, `<RANCHER_CONTAINER_NAME>` and `<RANCHER_VERSION>-<DATE>` are e
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
|
|||||||
@@ -30,7 +30,7 @@ helm repo update
|
|||||||
helm install rancher-backup-crd rancher-charts/rancher-backup-crd -n cattle-resources-system --create-namespace --version $CHART_VERSION
|
helm install rancher-backup-crd rancher-charts/rancher-backup-crd -n cattle-resources-system --create-namespace --version $CHART_VERSION
|
||||||
helm install rancher-backup rancher-charts/rancher-backup -n cattle-resources-system --version $CHART_VERSION
|
helm install rancher-backup rancher-charts/rancher-backup -n cattle-resources-system --version $CHART_VERSION
|
||||||
```
|
```
|
||||||
</br>
|
<br/>
|
||||||
For an **air-gapped environment**, use the option below to pull the `backup-restore-operator` image from your private registry when installing the rancher-backup-crd helm chart.
|
For an **air-gapped environment**, use the option below to pull the `backup-restore-operator` image from your private registry when installing the rancher-backup-crd helm chart.
|
||||||
```
|
```
|
||||||
--set image.repository $REGISTRY/rancher/backup-restore-operator
|
--set image.repository $REGISTRY/rancher/backup-restore-operator
|
||||||
|
|||||||
@@ -296,8 +296,8 @@ This table shows cluster-autoscaler parameters for fine tuning:
|
|||||||
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
||||||
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
||||||
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
||||||
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
cloud-provider|-|Cloud provider type|
|
cloud-provider|-|Cloud provider type|
|
||||||
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
||||||
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
||||||
@@ -307,7 +307,7 @@ cloud-provider|-|Cloud provider type|
|
|||||||
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
||||||
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
||||||
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
||||||
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: <min>:<max>:<other...>|
|
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: `<min>:<max>:<other...>`|
|
||||||
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
||||||
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
||||||
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
||||||
|
|||||||
+3
-2
@@ -227,7 +227,8 @@ For the complete reference for configurable options for RKE Kubernetes clusters
|
|||||||
|
|
||||||
RKE (Rancher Kubernetes Engine) is the tool that Rancher uses to provision Kubernetes clusters. Rancher's cluster config files used to have the same structure as [RKE config files,]({{<baseurl>}}/rke/latest/en/example-yamls/) but the structure changed so that in Rancher, RKE cluster config items are separated from non-RKE config items. Therefore, configuration for your cluster needs to be nested under the `rancher_kubernetes_engine_config` directive in the cluster config file. Cluster config files created with earlier versions of Rancher will need to be updated for this format. An example cluster config file is included below.
|
RKE (Rancher Kubernetes Engine) is the tool that Rancher uses to provision Kubernetes clusters. Rancher's cluster config files used to have the same structure as [RKE config files,]({{<baseurl>}}/rke/latest/en/example-yamls/) but the structure changed so that in Rancher, RKE cluster config items are separated from non-RKE config items. Therefore, configuration for your cluster needs to be nested under the `rancher_kubernetes_engine_config` directive in the cluster config file. Cluster config files created with earlier versions of Rancher will need to be updated for this format. An example cluster config file is included below.
|
||||||
|
|
||||||
{{% accordion id="v2.3.0-cluster-config-file" label="Example Cluster Config File" %}}
|
<details id="v2.3.0-cluster-config-file">
|
||||||
|
<summary>Example Cluster Config File</summary>
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
#
|
#
|
||||||
@@ -319,7 +320,7 @@ rancher_kubernetes_engine_config: # Your RKE template config goes here.
|
|||||||
ssh_agent_auth: false
|
ssh_agent_auth: false
|
||||||
windows_prefered_cluster: false
|
windows_prefered_cluster: false
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Default DNS provider
|
### Default DNS provider
|
||||||
|
|
||||||
|
|||||||
@@ -80,30 +80,32 @@ Only hosts expected to be load balancer back ends need to be in this group.
|
|||||||
necessary. Your Cloud Provider Configuration **must** match the fields in the Machine Pools section. If you have multiple pools, they must all use the same Resource Group, Availability Set, Subnet, Virtual Network, and Network Security Group.
|
necessary. Your Cloud Provider Configuration **must** match the fields in the Machine Pools section. If you have multiple pools, they must all use the same Resource Group, Availability Set, Subnet, Virtual Network, and Network Security Group.
|
||||||
* An example is provided below. You will modify it as needed.
|
* An example is provided below. You will modify it as needed.
|
||||||
|
|
||||||
{{% accordion id="v2.6.0-cloud-provider-config-file" label="Example Cloud Provider Config" %}}
|
<details id="v2.6.0-cloud-provider-config-file">
|
||||||
|
<summary>Example Cloud Provider Config</summary>
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
{
|
{
|
||||||
"cloud":"AzurePublicCloud",
|
"cloud":"AzurePublicCloud",
|
||||||
"tenantId": "YOUR TENANTID HERE",
|
"tenantId": "YOUR TENANTID HERE",
|
||||||
"aadClientId": "YOUR AADCLIENTID HERE",
|
"aadClientId": "YOUR AADCLIENTID HERE",
|
||||||
"aadClientSecret": "YOUR AADCLIENTSECRET HERE",
|
"aadClientSecret": "YOUR AADCLIENTSECRET HERE",
|
||||||
"subscriptionId": "YOUR SUBSCRIPTIONID HERE",
|
"subscriptionId": "YOUR SUBSCRIPTIONID HERE",
|
||||||
"resourceGroup": "docker-machine",
|
"resourceGroup": "docker-machine",
|
||||||
"location": "westus",
|
"location": "westus",
|
||||||
"subnetName": "docker-machine",
|
"subnetName": "docker-machine",
|
||||||
"securityGroupName": "rancher-managed-KA4jV9V2",
|
"securityGroupName": "rancher-managed-KA4jV9V2",
|
||||||
"securityGroupResourceGroup": "docker-machine",
|
"securityGroupResourceGroup": "docker-machine",
|
||||||
"vnetName": "docker-machine-vnet",
|
"vnetName": "docker-machine-vnet",
|
||||||
"vnetResourceGroup": "docker-machine",
|
"vnetResourceGroup": "docker-machine",
|
||||||
"primaryAvailabilitySetName": "docker-machine",
|
"primaryAvailabilitySetName": "docker-machine",
|
||||||
"routeTableResourceGroup": "docker-machine",
|
"routeTableResourceGroup": "docker-machine",
|
||||||
"cloudProviderBackoff": false,
|
"cloudProviderBackoff": false,
|
||||||
"useManagedIdentityExtension": false,
|
"useManagedIdentityExtension": false,
|
||||||
"useInstanceMetadata": true
|
"useInstanceMetadata": true
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. Under the **Cluster Configuration > Advanced** section, click **Add** under **Additional Controller Manager Args** and add this flag: `--configure-cloud-routes=false`
|
1. Under the **Cluster Configuration > Advanced** section, click **Add** under **Additional Controller Manager Args** and add this flag: `--configure-cloud-routes=false`
|
||||||
|
|
||||||
|
|||||||
@@ -66,7 +66,7 @@ The Helm chart in the git repository must include its dependencies in the charts
|
|||||||
---
|
---
|
||||||
* **Known Issue:** clientSecretName and helmSecretName secrets for Fleet gitrepos are not included in the backup nor restore created by the [backup-restore-operator]({{<baseurl>}}/rancher/v2.6/en/backups/back-up-rancher/#1-install-the-rancher-backups-operator). We will update the community once a permanent solution is in place.
|
* **Known Issue:** clientSecretName and helmSecretName secrets for Fleet gitrepos are not included in the backup nor restore created by the [backup-restore-operator]({{<baseurl>}}/rancher/v2.6/en/backups/back-up-rancher/#1-install-the-rancher-backups-operator). We will update the community once a permanent solution is in place.
|
||||||
|
|
||||||
* **Temporary Workaround:** </br>
|
* **Temporary Workaround:** <br/>
|
||||||
By default, user-defined secrets are not backed up in Fleet. It is necessary to recreate secrets if performing a disaster recovery restore or migration of Rancher into a fresh cluster. To modify resourceSet to include extra resources you want to backup, refer to docs [here](https://github.com/rancher/backup-restore-operator#user-flow).
|
By default, user-defined secrets are not backed up in Fleet. It is necessary to recreate secrets if performing a disaster recovery restore or migration of Rancher into a fresh cluster. To modify resourceSet to include extra resources you want to backup, refer to docs [here](https://github.com/rancher/backup-restore-operator#user-flow).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -129,7 +129,8 @@ New in v2.6.4, cert-manager versions 1.6.2 and 1.7.1 are compatible. We recommen
|
|||||||
|
|
||||||
This step is only required to use certificates issued by Rancher's generated CA (`ingress.tls.source=rancher`) or to request Let's Encrypt issued certificates (`ingress.tls.source=letsEncrypt`).
|
This step is only required to use certificates issued by Rancher's generated CA (`ingress.tls.source=rancher`) or to request Let's Encrypt issued certificates (`ingress.tls.source=letsEncrypt`).
|
||||||
|
|
||||||
{{% accordion id="cert-manager" label="Click to Expand" %}}
|
<details id="cert-manager">
|
||||||
|
<summary>Click to Expand</summary>
|
||||||
|
|
||||||
:::note Important:
|
:::note Important:
|
||||||
|
|
||||||
@@ -167,7 +168,7 @@ cert-manager-cainjector-577f6d9fd7-tr77l 1/1 Running 0 2m
|
|||||||
cert-manager-webhook-787858fcdb-nlzsq 1/1 Running 0 2m
|
cert-manager-webhook-787858fcdb-nlzsq 1/1 Running 0 2m
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### 5. Install Rancher with Helm and Your Chosen Certificate Option
|
### 5. Install Rancher with Helm and Your Chosen Certificate Option
|
||||||
|
|
||||||
|
|||||||
+9
-6
@@ -27,7 +27,8 @@ Choose from the following options:
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
||||||
|
|
||||||
@@ -49,11 +50,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
||||||
|
|
||||||
@@ -91,11 +93,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
||||||
|
|
||||||
@@ -135,7 +138,7 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+4
-3
@@ -69,7 +69,7 @@ When setting up the Rancher Helm template, there are several options in the Helm
|
|||||||
|
|
||||||
| Chart Option | Chart Value | Description |
|
| Chart Option | Chart Value | Description |
|
||||||
| ----------------------- | -------------------------------- | ---- |
|
| ----------------------- | -------------------------------- | ---- |
|
||||||
| `certmanager.version` | "<version>" | Configure proper Rancher TLS issuer depending of running cert-manager version. |
|
| `certmanager.version` | `<version>` | Configure proper Rancher TLS issuer depending of running cert-manager version. |
|
||||||
| `systemDefaultRegistry` | `<REGISTRY.YOURDOMAIN.COM:PORT>` | Configure Rancher server to always pull from your private registry when provisioning clusters. |
|
| `systemDefaultRegistry` | `<REGISTRY.YOURDOMAIN.COM:PORT>` | Configure Rancher server to always pull from your private registry when provisioning clusters. |
|
||||||
| `useBundledSystemChart` | `true` | Configure Rancher server to use the packaged copy of Helm system charts. The [system charts](https://github.com/rancher/system-charts) repository contains all the catalog items required for features such as monitoring, logging, alerting and global DNS. These [Helm charts](https://github.com/rancher/system-charts) are located in GitHub, but since you are in an air gapped environment, using the charts that are bundled within Rancher is much easier than setting up a Git mirror. |
|
| `useBundledSystemChart` | `true` | Configure Rancher server to use the packaged copy of Helm system charts. The [system charts](https://github.com/rancher/system-charts) repository contains all the catalog items required for features such as monitoring, logging, alerting and global DNS. These [Helm charts](https://github.com/rancher/system-charts) are located in GitHub, but since you are in an air gapped environment, using the charts that are bundled within Rancher is much easier than setting up a Git mirror. |
|
||||||
|
|
||||||
@@ -212,7 +212,8 @@ If you choose to use self-signed certificates in [B. Choose your SSL Configurati
|
|||||||
|
|
||||||
### For Self-Signed Certificate Installs, Install Cert-manager
|
### For Self-Signed Certificate Installs, Install Cert-manager
|
||||||
|
|
||||||
{{% accordion id="install-cert-manager" label="Click to expand" %}}
|
<details id="install-cert-manager">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you are using self-signed certificates, install cert-manager:
|
If you are using self-signed certificates, install cert-manager:
|
||||||
|
|
||||||
@@ -237,7 +238,7 @@ kubectl apply -f cert-manager/cert-manager-crd.yaml
|
|||||||
kubectl apply -R -f ./cert-manager
|
kubectl apply -R -f ./cert-manager
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Install Rancher with kubectl
|
### Install Rancher with kubectl
|
||||||
|
|
||||||
|
|||||||
+1
-2
@@ -20,8 +20,7 @@ In this command, `<PRIOR_RANCHER_VERSION>` is the version of Rancher you were ru
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<PRIOR_RANCHER_VERSION>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><PRIOR_RANCHER_VERSION></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||

|
|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
| -------------------------- | -------------------------- | ------------------------------------------------------- |
|
| -------------------------- | -------------------------- | ------------------------------------------------------- |
|
||||||
|
|||||||
+24
-16
@@ -41,7 +41,8 @@ docker ps
|
|||||||
|
|
||||||
Write down or copy this information before starting the upgrade.
|
Write down or copy this information before starting the upgrade.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
@@ -83,7 +84,7 @@ During upgrade, you create a copy of the data from your current Rancher containe
|
|||||||
|
|
||||||
# 2. Create a backup tarball
|
# 2. Create a backup tarball
|
||||||
|
|
||||||
1. <a id="tarball"></a>From the data container that you just created (`rancher-data`), create a backup tarball (`rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz`).
|
1. <a id="tarball"></a>From the data container that you just created (<code>rancher-data</code>), create a backup tarball (<code>rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz</code>).
|
||||||
|
|
||||||
This tarball will serve as a rollback point if something goes wrong during upgrade. Use the following command, replacing each placeholder.
|
This tarball will serve as a rollback point if something goes wrong during upgrade. Use the following command, replacing each placeholder.
|
||||||
|
|
||||||
@@ -143,7 +144,8 @@ Select which option you had installed Rancher server
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
||||||
|
|
||||||
@@ -161,11 +163,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
|
|
||||||
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
||||||
|
|
||||||
@@ -196,11 +199,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
|
|
||||||
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with. Remember to include `--no-cacerts` as an argument to the container to disable the default CA certificate generated by Rancher.
|
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with. Remember to include `--no-cacerts` as an argument to the container to disable the default CA certificate generated by Rancher.
|
||||||
|
|
||||||
@@ -229,11 +233,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
```
|
```
|
||||||
|
|
||||||
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option D: Let's Encrypt Certificate
|
### Option D: Let's Encrypt Certificate
|
||||||
|
|
||||||
{{% accordion id="option-d" label="Click to expand" %}}
|
<details id="option-d">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
:::caution
|
:::caution
|
||||||
|
|
||||||
@@ -266,7 +271,7 @@ docker run -d --volumes-from rancher-data \
|
|||||||
|
|
||||||
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
</TabItem>
|
</TabItem>
|
||||||
<TabItem value="Docker Air Gap Upgrade">
|
<TabItem value="Docker Air Gap Upgrade">
|
||||||
@@ -277,7 +282,8 @@ When starting the new Rancher server container, choose from the following option
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
||||||
|
|
||||||
@@ -297,11 +303,12 @@ Placeholder | Description
|
|||||||
```
|
```
|
||||||
|
|
||||||
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
||||||
|
|
||||||
@@ -332,11 +339,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
Privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with.
|
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with.
|
||||||
|
|
||||||
@@ -373,7 +381,7 @@ docker run -d --volumes-from rancher-data \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
privileged access is [required.]({{<baseurl>}}/rancher/v2.6/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher)
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
</TabItem>
|
</TabItem>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|||||||
@@ -44,7 +44,8 @@ Rancher can be installed on any Kubernetes cluster. For Rancher installs on a K3
|
|||||||
|
|
||||||
### Ports for Rancher Server Nodes on K3s
|
### Ports for Rancher Server Nodes on K3s
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The K3s server needs port 6443 to be accessible by the nodes.
|
The K3s server needs port 6443 to be accessible by the nodes.
|
||||||
|
|
||||||
@@ -79,11 +80,12 @@ The following tables break down the port requirements for inbound and outbound t
|
|||||||
| TCP | 2376 | Any node IP from a node created using Node driver | Docker daemon TLS port used by Docker Machine |
|
| TCP | 2376 | Any node IP from a node created using Node driver | Docker daemon TLS port used by Docker Machine |
|
||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Server Nodes on RKE
|
### Ports for Rancher Server Nodes on RKE
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
Typically Rancher is installed on three RKE nodes that all have the etcd, control plane and worker roles.
|
Typically Rancher is installed on three RKE nodes that all have the etcd, control plane and worker roles.
|
||||||
|
|
||||||
@@ -124,11 +126,12 @@ The following tables break down the port requirements for inbound and outbound t
|
|||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
| TCP | Provider dependent | Port of the Kubernetes API endpoint in hosted cluster | Kubernetes API |
|
| TCP | Provider dependent | Port of the Kubernetes API endpoint in hosted cluster | Kubernetes API |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Server Nodes on RKE2
|
### Ports for Rancher Server Nodes on RKE2
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The RKE2 server needs port 6443 and 9345 to be accessible by other nodes in the cluster.
|
The RKE2 server needs port 6443 and 9345 to be accessible by other nodes in the cluster.
|
||||||
|
|
||||||
@@ -158,11 +161,12 @@ The VXLAN port on nodes should not be exposed to the world as it opens up your c
|
|||||||
| HTTPS | 8443 | <ul><li>hosted/registered Kubernetes</li><li>any source that needs to be able to use the Rancher UI or API</li></ul> | Rancher agent, Rancher UI/API, kubectl. Not needed if you have LB doing TLS termination. |
|
| HTTPS | 8443 | <ul><li>hosted/registered Kubernetes</li><li>any source that needs to be able to use the Rancher UI or API</li></ul> | Rancher agent, Rancher UI/API, kubectl. Not needed if you have LB doing TLS termination. |
|
||||||
|
|
||||||
Typically all outbound traffic is allowed.
|
Typically all outbound traffic is allowed.
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Server in Docker
|
### Ports for Rancher Server in Docker
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following tables break down the port requirements for Rancher nodes, for inbound and outbound traffic:
|
The following tables break down the port requirements for Rancher nodes, for inbound and outbound traffic:
|
||||||
|
|
||||||
@@ -182,7 +186,7 @@ The following tables break down the port requirements for Rancher nodes, for inb
|
|||||||
| TCP | 2376 | Any node IP from a node created using a node driver | Docker daemon TLS port used by Docker Machine |
|
| TCP | 2376 | Any node IP from a node created using a node driver | Docker daemon TLS port used by Docker Machine |
|
||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
# Downstream Kubernetes Cluster Nodes
|
# Downstream Kubernetes Cluster Nodes
|
||||||
|
|
||||||
@@ -204,7 +208,8 @@ If security isn't a large concern and you're okay with opening a few additional
|
|||||||
|
|
||||||
### Ports for Rancher Launched Kubernetes Clusters using Node Pools
|
### Ports for Rancher Launched Kubernetes Clusters using Node Pools
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/) with nodes created in an [Infrastructure Provider]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/node-pools/).
|
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/) with nodes created in an [Infrastructure Provider]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/node-pools/).
|
||||||
|
|
||||||
@@ -216,27 +221,29 @@ The required ports are automatically opened by Rancher during creation of cluste
|
|||||||
|
|
||||||
{{< ports-iaas-nodes >}}
|
{{< ports-iaas-nodes >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Launched Kubernetes Clusters using Custom Nodes
|
### Ports for Rancher Launched Kubernetes Clusters using Custom Nodes
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/) with [Custom Nodes]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/custom-nodes/).
|
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/) with [Custom Nodes]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/custom-nodes/).
|
||||||
|
|
||||||
{{< ports-custom-nodes >}}
|
{{< ports-custom-nodes >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Hosted Kubernetes Clusters
|
### Ports for Hosted Kubernetes Clusters
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [hosted clusters]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/hosted-kubernetes-clusters).
|
The following table depicts the port requirements for [hosted clusters]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/hosted-kubernetes-clusters).
|
||||||
|
|
||||||
{{< ports-imported-hosted >}}
|
{{< ports-imported-hosted >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Registered Clusters
|
### Ports for Registered Clusters
|
||||||
|
|
||||||
@@ -246,13 +253,14 @@ Registered clusters were called imported clusters before Rancher v2.5.
|
|||||||
|
|
||||||
:::
|
:::
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [registered clusters]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/registered-clusters/).
|
The following table depicts the port requirements for [registered clusters]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/registered-clusters/).
|
||||||
|
|
||||||
{{< ports-imported-hosted >}}
|
{{< ports-imported-hosted >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
# Other Port Considerations
|
# Other Port Considerations
|
||||||
|
|||||||
+8
-4
@@ -42,7 +42,9 @@ See [Advanced Options](#advanced-options) below before continuing.
|
|||||||
|
|
||||||
Choose from the following options:
|
Choose from the following options:
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Option A-Bring Your Own Certificate: Self-Signed" %}}
|
<details id="option-a">
|
||||||
|
<summary>Option A-Bring Your Own Certificate: Self-Signed</summary>
|
||||||
|
|
||||||
If you elect to use a self-signed certificate to encrypt communication, you must install the certificate on your load balancer (which you'll do later) and your Rancher container. Run the Docker command to deploy Rancher, pointing it toward your certificate.
|
If you elect to use a self-signed certificate to encrypt communication, you must install the certificate on your load balancer (which you'll do later) and your Rancher container. Run the Docker command to deploy Rancher, pointing it toward your certificate.
|
||||||
|
|
||||||
:::note Prerequisites:
|
:::note Prerequisites:
|
||||||
@@ -64,8 +66,10 @@ Create a self-signed certificate.
|
|||||||
rancher/rancher:latest
|
rancher/rancher:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="option-b" label="Option B-Bring Your Own Certificate: Signed by Recognized CA" %}}
|
<details id="option-b">
|
||||||
|
<summary>Option B-Bring Your Own Certificate: Signed by Recognized CA</summary>
|
||||||
|
|
||||||
If your cluster is public facing, it's best to use a certificate signed by a recognized CA.
|
If your cluster is public facing, it's best to use a certificate signed by a recognized CA.
|
||||||
|
|
||||||
:::note Prerequisites:
|
:::note Prerequisites:
|
||||||
@@ -86,7 +90,7 @@ If you use a certificate signed by a recognized CA, installing your certificate
|
|||||||
rancher/rancher:latest --no-cacerts
|
rancher/rancher:latest --no-cacerts
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
## 3. Configure Load Balancer
|
## 3. Configure Load Balancer
|
||||||
|
|
||||||
|
|||||||
@@ -28,7 +28,9 @@ In order to upgrade cert-manager, follow these instructions:
|
|||||||
|
|
||||||
### Option A: Upgrade cert-manager with Internet Access
|
### Option A: Upgrade cert-manager with Internet Access
|
||||||
|
|
||||||
{{% accordion id="normal" label="Click to expand" %}}
|
<details id="normal">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
1. [Back up existing resources](https://cert-manager.io/docs/tutorials/backup/) as a precaution
|
1. [Back up existing resources](https://cert-manager.io/docs/tutorials/backup/) as a precaution
|
||||||
|
|
||||||
```plain
|
```plain
|
||||||
@@ -101,11 +103,12 @@ In order to upgrade cert-manager, follow these instructions:
|
|||||||
kubectl apply -f cert-manager-backup.yaml
|
kubectl apply -f cert-manager-backup.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Upgrade cert-manager in an Air-Gapped Environment
|
### Option B: Upgrade cert-manager in an Air-Gapped Environment
|
||||||
|
|
||||||
{{% accordion id="airgap" label="Click to expand" %}}
|
<details id="airgap">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
@@ -214,11 +217,12 @@ Before you can perform the upgrade, you must prepare your air gapped environment
|
|||||||
kubectl apply -f cert-manager-backup.yaml
|
kubectl apply -f cert-manager-backup.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Upgrade cert-manager from Versions 1.5 and Below
|
### Option C: Upgrade cert-manager from Versions 1.5 and Below
|
||||||
|
|
||||||
{{% accordion id="normal" label="Click to expand" %}}
|
<details id="normal">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
Previously, in order to upgrade cert-manager from an older version, an uninstall and reinstall of Rancher was recommended. Using the method below, you may upgrade cert-manager without those additional steps in order to better preserve your production environment:
|
Previously, in order to upgrade cert-manager from an older version, an uninstall and reinstall of Rancher was recommended. Using the method below, you may upgrade cert-manager without those additional steps in order to better preserve your production environment:
|
||||||
|
|
||||||
@@ -239,7 +243,7 @@ Previously, in order to upgrade cert-manager from an older version, an uninstall
|
|||||||
|
|
||||||
1. Upgrade Rancher normally with `helm upgrade`.
|
1. Upgrade Rancher normally with `helm upgrade`.
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Verify the Deployment
|
### Verify the Deployment
|
||||||
|
|
||||||
|
|||||||
+15
-6
@@ -158,7 +158,10 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
# kubectl logs prometheus-adapter-prometheus-adapter-568674d97f-hbzfx -n kube-system
|
# kubectl logs prometheus-adapter-prometheus-adapter-568674d97f-hbzfx -n kube-system
|
||||||
```
|
```
|
||||||
Then review the log output to confirm the service is running.
|
Then review the log output to confirm the service is running.
|
||||||
{{% accordion id="prometheus-logs" label="Prometheus Adaptor Logs" %}}
|
|
||||||
|
<details id="prometheus-logs">
|
||||||
|
<summary>Prometheus Adaptor Logs</summary>
|
||||||
|
|
||||||
...
|
...
|
||||||
I0724 10:18:45.696679 1 round_trippers.go:436] GET https://10.43.0.1:443/api/v1/namespaces/default/pods?labelSelector=app%3Dhello-world 200 OK in 2 milliseconds
|
I0724 10:18:45.696679 1 round_trippers.go:436] GET https://10.43.0.1:443/api/v1/namespaces/default/pods?labelSelector=app%3Dhello-world 200 OK in 2 milliseconds
|
||||||
I0724 10:18:45.696695 1 round_trippers.go:442] Response Headers:
|
I0724 10:18:45.696695 1 round_trippers.go:442] Response Headers:
|
||||||
@@ -171,7 +174,7 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
I0724 10:18:45.699939 1 wrap.go:42] GET /apis/custom.metrics.k8s.io/v1beta1/namespaces/default/pods/%2A/fs_read?labelSelector=app%3Dhello-world: (12.431262ms) 200 [[kube-controller-manager/v1.10.1 (linux/amd64) kubernetes/d4ab475/system:serviceaccount:kube-system:horizontal-pod-autoscaler] 10.42.0.0:24268]
|
I0724 10:18:45.699939 1 wrap.go:42] GET /apis/custom.metrics.k8s.io/v1beta1/namespaces/default/pods/%2A/fs_read?labelSelector=app%3Dhello-world: (12.431262ms) 200 [[kube-controller-manager/v1.10.1 (linux/amd64) kubernetes/d4ab475/system:serviceaccount:kube-system:horizontal-pod-autoscaler] 10.42.0.0:24268]
|
||||||
I0724 10:18:51.727845 1 request.go:836] Request Body: {"kind":"SubjectAccessReview","apiVersion":"authorization.k8s.io/v1beta1","metadata":{"creationTimestamp":null},"spec":{"nonResourceAttributes":{"path":"/","verb":"get"},"user":"system:anonymous","group":["system:unauthenticated"]},"status":{"allowed":false}}
|
I0724 10:18:51.727845 1 request.go:836] Request Body: {"kind":"SubjectAccessReview","apiVersion":"authorization.k8s.io/v1beta1","metadata":{"creationTimestamp":null},"spec":{"nonResourceAttributes":{"path":"/","verb":"get"},"user":"system:anonymous","group":["system:unauthenticated"]},"status":{"allowed":false}}
|
||||||
...
|
...
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -182,15 +185,21 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
# kubectl get --raw /apis/custom.metrics.k8s.io/v1beta1
|
# kubectl get --raw /apis/custom.metrics.k8s.io/v1beta1
|
||||||
```
|
```
|
||||||
If the API is accessible, you should receive output that's similar to what follows.
|
If the API is accessible, you should receive output that's similar to what follows.
|
||||||
{{% accordion id="custom-metrics-api-response" label="API Response" %}}
|
|
||||||
|
<details id="custom-metrics-api-response">
|
||||||
|
<summary>API Response</summary>
|
||||||
|
|
||||||
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
- If you are accessing the cluster through Rancher, enter your Server URL in the kubectl config in the following format: `https://<RANCHER_URL>/k8s/clusters/<CLUSTER_ID>`. Add the suffix `/k8s/clusters/<CLUSTER_ID>` to API path.
|
- If you are accessing the cluster through Rancher, enter your Server URL in the kubectl config in the following format: `https://<RANCHER_URL>/k8s/clusters/<CLUSTER_ID>`. Add the suffix `/k8s/clusters/<CLUSTER_ID>` to API path.
|
||||||
```
|
```
|
||||||
# kubectl get --raw /k8s/clusters/<CLUSTER_ID>/apis/custom.metrics.k8s.io/v1beta1
|
# kubectl get --raw /k8s/clusters/<CLUSTER_ID>/apis/custom.metrics.k8s.io/v1beta1
|
||||||
```
|
```
|
||||||
If the API is accessible, you should receive output that's similar to what follows.
|
If the API is accessible, you should receive output that's similar to what follows.
|
||||||
{{% accordion id="custom-metrics-api-response-rancher" label="API Response" %}}
|
|
||||||
|
<details id="custom-metrics-api-response-rancher">
|
||||||
|
<summary>API Response</summary>
|
||||||
|
|
||||||
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|||||||
@@ -9,58 +9,62 @@ For HPA to work correctly, service deployments should have resources request def
|
|||||||
|
|
||||||
1. Configure `kubectl` to connect to your Kubernetes cluster.
|
1. Configure `kubectl` to connect to your Kubernetes cluster.
|
||||||
|
|
||||||
2. Copy the `hello-world` deployment manifest below.
|
1. Copy the `hello-world` deployment manifest below.
|
||||||
{{% accordion id="hello-world" label="Hello World Manifest" %}}
|
|
||||||
```
|
<details id="hello-world">
|
||||||
apiVersion: apps/v1beta2
|
<summary>Hello World Manifest</summary>
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
```
|
||||||
labels:
|
apiVersion: apps/v1beta2
|
||||||
app: hello-world
|
kind: Deployment
|
||||||
name: hello-world
|
metadata:
|
||||||
namespace: default
|
labels:
|
||||||
spec:
|
app: hello-world
|
||||||
replicas: 1
|
name: hello-world
|
||||||
selector:
|
namespace: default
|
||||||
matchLabels:
|
spec:
|
||||||
app: hello-world
|
replicas: 1
|
||||||
strategy:
|
selector:
|
||||||
rollingUpdate:
|
matchLabels:
|
||||||
maxSurge: 1
|
app: hello-world
|
||||||
maxUnavailable: 0
|
strategy:
|
||||||
type: RollingUpdate
|
rollingUpdate:
|
||||||
template:
|
maxSurge: 1
|
||||||
metadata:
|
maxUnavailable: 0
|
||||||
labels:
|
type: RollingUpdate
|
||||||
app: hello-world
|
template:
|
||||||
spec:
|
metadata:
|
||||||
containers:
|
labels:
|
||||||
- image: rancher/hello-world
|
app: hello-world
|
||||||
imagePullPolicy: Always
|
spec:
|
||||||
name: hello-world
|
containers:
|
||||||
resources:
|
- image: rancher/hello-world
|
||||||
requests:
|
imagePullPolicy: Always
|
||||||
cpu: 500m
|
name: hello-world
|
||||||
memory: 64Mi
|
resources:
|
||||||
ports:
|
requests:
|
||||||
- containerPort: 80
|
cpu: 500m
|
||||||
protocol: TCP
|
memory: 64Mi
|
||||||
restartPolicy: Always
|
ports:
|
||||||
---
|
- containerPort: 80
|
||||||
apiVersion: v1
|
protocol: TCP
|
||||||
kind: Service
|
restartPolicy: Always
|
||||||
metadata:
|
---
|
||||||
name: hello-world
|
apiVersion: v1
|
||||||
namespace: default
|
kind: Service
|
||||||
spec:
|
metadata:
|
||||||
ports:
|
name: hello-world
|
||||||
- port: 80
|
namespace: default
|
||||||
protocol: TCP
|
spec:
|
||||||
targetPort: 80
|
ports:
|
||||||
selector:
|
- port: 80
|
||||||
app: hello-world
|
protocol: TCP
|
||||||
```
|
targetPort: 80
|
||||||
{{% /accordion %}}
|
selector:
|
||||||
|
app: hello-world
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. Deploy it to your cluster.
|
1. Deploy it to your cluster.
|
||||||
|
|
||||||
@@ -69,423 +73,459 @@ spec:
|
|||||||
```
|
```
|
||||||
|
|
||||||
1. Copy one of the HPAs below based on the metric type you're using:
|
1. Copy one of the HPAs below based on the metric type you're using:
|
||||||
{{% accordion id="service-deployment-resource-metrics" label="Hello World HPA: Resource Metrics" %}}
|
|
||||||
```
|
<details id="service-deployment-resource-metrics">
|
||||||
apiVersion: autoscaling/v2beta1
|
<summary>Hello World HPA: Resource Metrics</summary>
|
||||||
kind: HorizontalPodAutoscaler
|
|
||||||
metadata:
|
```
|
||||||
name: hello-world
|
apiVersion: autoscaling/v2beta1
|
||||||
namespace: default
|
kind: HorizontalPodAutoscaler
|
||||||
spec:
|
metadata:
|
||||||
scaleTargetRef:
|
name: hello-world
|
||||||
apiVersion: extensions/v1beta1
|
namespace: default
|
||||||
kind: Deployment
|
spec:
|
||||||
name: hello-world
|
scaleTargetRef:
|
||||||
minReplicas: 1
|
apiVersion: extensions/v1beta1
|
||||||
maxReplicas: 10
|
kind: Deployment
|
||||||
metrics:
|
name: hello-world
|
||||||
- type: Resource
|
minReplicas: 1
|
||||||
resource:
|
maxReplicas: 10
|
||||||
name: cpu
|
metrics:
|
||||||
targetAverageUtilization: 50
|
- type: Resource
|
||||||
- type: Resource
|
resource:
|
||||||
resource:
|
name: cpu
|
||||||
name: memory
|
targetAverageUtilization: 50
|
||||||
targetAverageValue: 1000Mi
|
- type: Resource
|
||||||
```
|
resource:
|
||||||
{{% /accordion %}}
|
name: memory
|
||||||
{{% accordion id="service-deployment-custom-metrics" label="Hello World HPA: Custom Metrics" %}}
|
targetAverageValue: 1000Mi
|
||||||
```
|
```
|
||||||
apiVersion: autoscaling/v2beta1
|
|
||||||
kind: HorizontalPodAutoscaler
|
</details>
|
||||||
metadata:
|
<details id="service-deployment-custom-metrics">
|
||||||
name: hello-world
|
<summary>Hello World HPA: Custom Metrics</summary>
|
||||||
namespace: default
|
|
||||||
spec:
|
```
|
||||||
scaleTargetRef:
|
apiVersion: autoscaling/v2beta1
|
||||||
apiVersion: extensions/v1beta1
|
kind: HorizontalPodAutoscaler
|
||||||
kind: Deployment
|
metadata:
|
||||||
name: hello-world
|
name: hello-world
|
||||||
minReplicas: 1
|
namespace: default
|
||||||
maxReplicas: 10
|
spec:
|
||||||
metrics:
|
scaleTargetRef:
|
||||||
- type: Resource
|
apiVersion: extensions/v1beta1
|
||||||
resource:
|
kind: Deployment
|
||||||
name: cpu
|
name: hello-world
|
||||||
targetAverageUtilization: 50
|
minReplicas: 1
|
||||||
- type: Resource
|
maxReplicas: 10
|
||||||
resource:
|
metrics:
|
||||||
name: memory
|
- type: Resource
|
||||||
targetAverageValue: 100Mi
|
resource:
|
||||||
- type: Pods
|
name: cpu
|
||||||
pods:
|
targetAverageUtilization: 50
|
||||||
metricName: cpu_system
|
- type: Resource
|
||||||
targetAverageValue: 20m
|
resource:
|
||||||
```
|
name: memory
|
||||||
{{% /accordion %}}
|
targetAverageValue: 100Mi
|
||||||
|
- type: Pods
|
||||||
|
pods:
|
||||||
|
metricName: cpu_system
|
||||||
|
targetAverageValue: 20m
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. View the HPA info and description. Confirm that metric data is shown.
|
1. View the HPA info and description. Confirm that metric data is shown.
|
||||||
{{% accordion id="hpa-info-resource-metrics" label="Resource Metrics" %}}
|
|
||||||
1. Enter the following commands.
|
|
||||||
```
|
|
||||||
# kubectl get hpa
|
|
||||||
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
|
|
||||||
hello-world Deployment/hello-world 1253376 / 100Mi, 0% / 50% 1 10 1 6m
|
|
||||||
# kubectl describe hpa
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 20:21:16 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 1253376 / 100Mi
|
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events: <none>
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="hpa-info-custom-metrics" label="Custom Metrics" %}}
|
|
||||||
1. Enter the following command.
|
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive the output that follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:36:28 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 3514368 / 100Mi
|
|
||||||
"cpu_system" on pods: 0 / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events: <none>
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
|
|
||||||
|
<details id="hpa-info-resource-metrics">
|
||||||
|
<summary>Resource Metrics</summary>
|
||||||
|
|
||||||
|
1. Enter the following commands.
|
||||||
|
```
|
||||||
|
# kubectl get hpa
|
||||||
|
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
|
||||||
|
hello-world Deployment/hello-world 1253376 / 100Mi, 0% / 50% 1 10 1 6m
|
||||||
|
# kubectl describe hpa
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Mon, 23 Jul 2018 20:21:16 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 1253376 / 100Mi
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events: <none>
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="hpa-info-custom-metrics">
|
||||||
|
<summary>Custom Metrics</summary>
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive the output that follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:36:28 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 3514368 / 100Mi
|
||||||
|
"cpu_system" on pods: 0 / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events: <none>
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. Generate a load for the service to test that your pods autoscale as intended. You can use any load-testing tool (Hey, Gatling, etc.), but we're using [Hey](https://github.com/rakyll/hey).
|
1. Generate a load for the service to test that your pods autoscale as intended. You can use any load-testing tool (Hey, Gatling, etc.), but we're using [Hey](https://github.com/rakyll/hey).
|
||||||
|
|
||||||
1. Test that pod autoscaling works as intended.<br/><br/>
|
1. Test that pod autoscaling works as intended.<br/><br/>
|
||||||
**To Test Autoscaling Using Resource Metrics:**
|
**To Test Autoscaling Using Resource Metrics:**
|
||||||
{{% accordion id="observe-upscale-2-pods-cpu" label="Upscale to 2 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to scale up to two pods based on CPU Usage.
|
|
||||||
|
|
||||||
1. View your HPA.
|
<details id="observe-upscale-2-pods-cpu">
|
||||||
```
|
<summary>Upscale to 2 Pods: CPU Usage Up to Target</summary>
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 10928128 / 100Mi
|
|
||||||
resource cpu on pods (as a percentage of request): 56% (280m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm you've scaled to two pods.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-k8ph2 1/1 Running 0 1m
|
|
||||||
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-3-pods-cpu-cooldown" label="Upscale to 3 pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to upscale to 3 pods based on CPU usage with `horizontal-pod-autoscaler-upscale-delay` set to 3 minutes.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
Use your load testing tool to scale up to two pods based on CPU Usage.
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 9424896 / 100Mi
|
|
||||||
resource cpu on pods (as a percentage of request): 66% (333m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 4m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
2. Enter the following command to confirm three pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-f46kh 0/1 Running 0 1m
|
|
||||||
hello-world-54764dfbf8-k8ph2 1/1 Running 0 5m
|
|
||||||
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-downscale-1-pod" label="Downscale to 1 Pod: All Metrics Below Target" %}}
|
|
||||||
Use your load testing to scale down to 1 pod when all metrics are below target for `horizontal-pod-autoscaler-downscale-delay` (5 minutes by default).
|
|
||||||
|
|
||||||
1. Enter the following command.
|
1. View your HPA.
|
||||||
```
|
```
|
||||||
# kubectl describe hpa
|
# kubectl describe hpa
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows.
|
||||||
```
|
```
|
||||||
Name: hello-world
|
Name: hello-world
|
||||||
Namespace: default
|
Namespace: default
|
||||||
Labels: <none>
|
Labels: <none>
|
||||||
Annotations: <none>
|
Annotations: <none>
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
Reference: Deployment/hello-world
|
Reference: Deployment/hello-world
|
||||||
Metrics: ( current / target )
|
Metrics: ( current / target )
|
||||||
resource memory on pods: 10070016 / 100Mi
|
resource memory on pods: 10928128 / 100Mi
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
resource cpu on pods (as a percentage of request): 56% (280m) / 50%
|
||||||
Min replicas: 1
|
Min replicas: 1
|
||||||
Max replicas: 10
|
Max replicas: 10
|
||||||
Conditions:
|
Conditions:
|
||||||
Type Status Reason Message
|
Type Status Reason Message
|
||||||
---- ------ ------ -------
|
---- ------ ------ -------
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
Events:
|
Events:
|
||||||
Type Reason Age From Message
|
Type Reason Age From Message
|
||||||
---- ------ ---- ---- -------
|
---- ------ ---- ---- -------
|
||||||
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 6m horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
```
|
||||||
Normal SuccessfulRescale 1s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
1. Enter the following command to confirm you've scaled to two pods.
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
# kubectl get pods
|
||||||
<br/>
|
```
|
||||||
**To Test Autoscaling Using Custom Metrics:**
|
You should receive output similar to what follows:
|
||||||
{{% accordion id="custom-observe-upscale-2-pods-cpu" label="Upscale to 2 Pods: CPU Usage Up to Target" %}}
|
```
|
||||||
Use your load testing tool to upscale two pods based on CPU usage.
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-k8ph2 1/1 Running 0 1m
|
||||||
|
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
||||||
|
```
|
||||||
|
|
||||||
1. Enter the following command.
|
</details>
|
||||||
```
|
<details id="observe-upscale-3-pods-cpu-cooldown">
|
||||||
# kubectl describe hpa
|
<summary>Upscale to 3 pods: CPU Usage Up to Target</summary>
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8159232 / 100Mi
|
|
||||||
"cpu_system" on pods: 7m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 64% (321m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm two pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-3-pods-cpu-cooldown-2" label="Upscale to 3 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to scale up to three pods when the cpu_system usage limit is up to target.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
Use your load testing tool to upscale to 3 pods based on CPU usage with `horizontal-pod-autoscaler-upscale-delay` set to 3 minutes.
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8374272 / 100Mi
|
|
||||||
"cpu_system" on pods: 27m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 3s horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm three pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3m
|
|
||||||
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-4-pods" label="Upscale to 4 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to upscale to four pods based on CPU usage. `horizontal-pod-autoscaler-upscale-delay` is set to three minutes by default.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
1. Enter the following command.
|
||||||
```
|
```
|
||||||
# kubectl describe hpa
|
# kubectl describe hpa
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows
|
||||||
```
|
```
|
||||||
Name: hello-world
|
Name: hello-world
|
||||||
Namespace: default
|
Namespace: default
|
||||||
Labels: <none>
|
Labels: <none>
|
||||||
Annotations: <none>
|
Annotations: <none>
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
Reference: Deployment/hello-world
|
Reference: Deployment/hello-world
|
||||||
Metrics: ( current / target )
|
Metrics: ( current / target )
|
||||||
resource memory on pods: 8374272 / 100Mi
|
resource memory on pods: 9424896 / 100Mi
|
||||||
"cpu_system" on pods: 27m / 20m
|
resource cpu on pods (as a percentage of request): 66% (333m) / 50%
|
||||||
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
Min replicas: 1
|
||||||
Min replicas: 1
|
Max replicas: 10
|
||||||
Max replicas: 10
|
Conditions:
|
||||||
Conditions:
|
Type Status Reason Message
|
||||||
Type Status Reason Message
|
---- ------ ------ -------
|
||||||
---- ------ ------ -------
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
Events:
|
||||||
Events:
|
Type Reason Age From Message
|
||||||
Type Reason Age From Message
|
---- ------ ---- ---- -------
|
||||||
---- ------ ---- ---- -------
|
Normal SuccessfulRescale 4m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
```
|
||||||
Normal SuccessfulRescale 4s horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
2. Enter the following command to confirm three pods are running.
|
||||||
```
|
```
|
||||||
1. Enter the following command to confirm four pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-2p9xb 1/1 Running 0 5m
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 2m
|
|
||||||
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="custom-metrics-observe-downscale-1-pod" label="Downscale to 1 Pod: All Metrics Below Target" %}}
|
|
||||||
Use your load testing tool to scale down to one pod when all metrics below target for `horizontal-pod-autoscaler-downscale-delay`.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive similar output to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8101888 / 100Mi
|
|
||||||
"cpu_system" on pods: 8m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 8m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
|
||||||
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm a single pods is running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
# kubectl get pods
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows.
|
||||||
```
|
```
|
||||||
NAME READY STATUS RESTARTS AGE
|
NAME READY STATUS RESTARTS AGE
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
hello-world-54764dfbf8-f46kh 0/1 Running 0 1m
|
||||||
```
|
hello-world-54764dfbf8-k8ph2 1/1 Running 0 5m
|
||||||
{{% /accordion %}}
|
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-downscale-1-pod">
|
||||||
|
<summary>Downscale to 1 Pod: All Metrics Below Target</summary>
|
||||||
|
|
||||||
|
Use your load testing to scale down to 1 pod when all metrics are below target for `horizontal-pod-autoscaler-downscale-delay` (5 minutes by default).
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 10070016 / 100Mi
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 6m horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 1s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
**To Test Autoscaling Using Custom Metrics:**
|
||||||
|
|
||||||
|
<details id="custom-observe-upscale-2-pods-cpu">
|
||||||
|
<summary>Upscale to 2 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to upscale two pods based on CPU usage.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8159232 / 100Mi
|
||||||
|
"cpu_system" on pods: 7m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 64% (321m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm two pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-upscale-3-pods-cpu-cooldown-2">
|
||||||
|
<summary>Upscale to 3 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to scale up to three pods when the cpu_system usage limit is up to target.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows:
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8374272 / 100Mi
|
||||||
|
"cpu_system" on pods: 27m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 3s horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm three pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows:
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3m
|
||||||
|
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-upscale-4-pods">
|
||||||
|
<summary>Upscale to 4 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to upscale to four pods based on CPU usage. `horizontal-pod-autoscaler-upscale-delay` is set to three minutes by default.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8374272 / 100Mi
|
||||||
|
"cpu_system" on pods: 27m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
Normal SuccessfulRescale 4s horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm four pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-2p9xb 1/1 Running 0 5m
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 2m
|
||||||
|
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="custom-metrics-observe-downscale-1-pod">
|
||||||
|
<summary>Downscale to 1 Pod: All Metrics Below Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to scale down to one pod when all metrics below target for `horizontal-pod-autoscaler-downscale-delay`.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive similar output to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8101888 / 100Mi
|
||||||
|
"cpu_system" on pods: 8m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 8m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm a single pods is running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|||||||
@@ -59,7 +59,7 @@ Some cloud-managed layer-7 load balancers (such as the ALB ingress controller on
|
|||||||
Other layer-7 load balancers, such as the Google Load Balancer or Nginx Ingress Controller, directly expose one or more IP addresses. Google Load Balancer provides a single routable IP address. Nginx Ingress Controller exposes the external IP of all nodes that run the Nginx Ingress Controller. You can do either of the following:
|
Other layer-7 load balancers, such as the Google Load Balancer or Nginx Ingress Controller, directly expose one or more IP addresses. Google Load Balancer provides a single routable IP address. Nginx Ingress Controller exposes the external IP of all nodes that run the Nginx Ingress Controller. You can do either of the following:
|
||||||
|
|
||||||
1. Configure your own DNS to map (via A records) your domain name to the IP addresses exposes by the Layer-7 load balancer.
|
1. Configure your own DNS to map (via A records) your domain name to the IP addresses exposes by the Layer-7 load balancer.
|
||||||
2. Ask Rancher to generate an xip.io host name for your ingress rule. Rancher will take one of your exposed IPs, say a.b.c.d, and generate a host name <ingressname>.<namespace>.a.b.c.d.xip.io.
|
2. Ask Rancher to generate an xip.io host name for your ingress rule. Rancher will take one of your exposed IPs, say `a.b.c.d`, and generate a host name `<ingressname>.<namespace>.a.b.c.d.xip.io`.
|
||||||
|
|
||||||
The benefit of using xip.io is that you obtain a working entrypoint URL immediately after you create the ingress rule. Setting up your own domain name, on the other hand, requires you to configure DNS servers and wait for DNS to propagate.
|
The benefit of using xip.io is that you obtain a working entrypoint URL immediately after you create the ingress rule. Setting up your own domain name, on the other hand, requires you to configure DNS servers and wait for DNS to propagate.
|
||||||
|
|
||||||
|
|||||||
@@ -111,15 +111,15 @@ For more information about querying the Prometheus time series database, refer t
|
|||||||
|
|
||||||
| Catalog | Expression |
|
| Catalog | Expression |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Detail | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr></table> |
|
| Detail | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr></table> |
|
||||||
| Summary | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr></table> |
|
| Summary | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr></table> |
|
||||||
|
|
||||||
### Cluster Network I/O
|
### Cluster Network I/O
|
||||||
|
|
||||||
| Catalog | Expression |
|
| Catalog | Expression |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Detail | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr></table> |
|
| Detail | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr></table> |
|
||||||
| Summary | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr></table> |
|
| Summary | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr></table> |
|
||||||
|
|
||||||
# Node Metrics
|
# Node Metrics
|
||||||
|
|
||||||
@@ -162,15 +162,15 @@ For more information about querying the Prometheus time series database, refer t
|
|||||||
|
|
||||||
| Catalog | Expression |
|
| Catalog | Expression |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Detail | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr></table> |
|
| Detail | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr></table> |
|
||||||
| Summary | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr></table> |
|
| Summary | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr></table> |
|
||||||
|
|
||||||
### Node Network I/O
|
### Node Network I/O
|
||||||
|
|
||||||
| Catalog | Expression |
|
| Catalog | Expression |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Detail | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr></table> |
|
| Detail | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr></table> |
|
||||||
| Summary | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr></table> |
|
| Summary | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr></table> |
|
||||||
|
|
||||||
# Etcd Metrics
|
# Etcd Metrics
|
||||||
|
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ ServiceMonitors and PodMonitors declaratively specify targets, such as Services
|
|||||||
1. The internal component responds by pushing metrics back to the proxy.
|
1. The internal component responds by pushing metrics back to the proxy.
|
||||||
|
|
||||||
|
|
||||||
<figcaption><br>Process for Exporting Metrics with PushProx:</br></figcaption>
|
<figcaption><br/>Process for Exporting Metrics with PushProx:<br/></figcaption>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|||||||
@@ -562,7 +562,7 @@ root 121142 121120 7 12:27 ? 00:06:27 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --basic-auth-file=<filename> parameter.
|
on the master node and remove the `--basic-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -590,7 +590,7 @@ root 121142 121120 7 12:27 ? 00:06:27 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --token-auth-file=<filename> parameter.
|
on the master node and remove the `--token-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -677,8 +677,8 @@ root 121142 121120 7 12:27 ? 00:06:27 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
Follow the Kubernetes documentation and setup the TLS connection between
|
Follow the Kubernetes documentation and setup the TLS connection between
|
||||||
the apiserver and kubelets. Then, edit the API server pod specification file
|
the apiserver and kubelets. Then, edit the API server pod specification file
|
||||||
/etc/kubernetes/manifests/kube-apiserver.yaml on the master node and set the
|
/etc/kubernetes/manifests/kube-apiserver.yaml on the master node and set the
|
||||||
--kubelet-certificate-authority parameter to the path to the cert file for the certificate authority.
|
`--kubelet-certificate-authority` parameter to the path to the cert file for the certificate authority.
|
||||||
--kubelet-certificate-authority=<ca-string>
|
`--kubelet-certificate-authority=<ca-string>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1288,7 +1288,7 @@ root 121142 121120 7 12:27 ? 00:06:28 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the --service-account-key-file parameter
|
on the master node and set the --service-account-key-file parameter
|
||||||
to the public key file for service accounts:
|
to the public key file for service accounts:
|
||||||
--service-account-key-file=<filename>
|
`--service-account-key-file=<filename>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1317,8 +1317,8 @@ root 121142 121120 7 12:27 ? 00:06:28 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
||||||
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the etcd certificate and key file parameters.
|
on the master node and set the etcd certificate and key file parameters.
|
||||||
--etcd-certfile=<path/to/client-certificate-file>
|
`--etcd-certfile=<path/to/client-certificate-file>`
|
||||||
--etcd-keyfile=<path/to/client-key-file>
|
`--etcd-keyfile=<path/to/client-key-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1347,8 +1347,8 @@ root 121142 121120 7 12:27 ? 00:06:28 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
||||||
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the TLS certificate and private key file parameters.
|
on the master node and set the TLS certificate and private key file parameters.
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1377,7 +1377,7 @@ root 121142 121120 7 12:27 ? 00:06:28 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
||||||
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the client certificate authority file.
|
on the master node and set the client certificate authority file.
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1406,7 +1406,7 @@ root 121142 121120 7 12:27 ? 00:06:28 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
||||||
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the etcd certificate authority file parameter.
|
on the master node and set the etcd certificate authority file parameter.
|
||||||
--etcd-cafile=<path/to/ca-file>
|
`--etcd-cafile=<path/to/ca-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1626,7 +1626,7 @@ root 121366 121346 1 12:27 ? 00:01:13 kube-controller-manager --cluster-cidr=10.
|
|||||||
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
|
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
|
||||||
on the master node and set the --service-account-private-key-file parameter
|
on the master node and set the --service-account-private-key-file parameter
|
||||||
to the private key file for service accounts.
|
to the private key file for service accounts.
|
||||||
--service-account-private-key-file=<filename>
|
`--service-account-private-key-file=<filename>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1654,7 +1654,7 @@ root 121366 121346 1 12:27 ? 00:01:13 kube-controller-manager --cluster-cidr=10.
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
|
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
|
||||||
on the master node and set the --root-ca-file parameter to the certificate bundle file`.
|
on the master node and set the --root-ca-file parameter to the certificate bundle file`.
|
||||||
--root-ca-file=<path/to/file>
|
`--root-ca-file=<path/to/file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1779,8 +1779,8 @@ root 121587 121567 0 12:27 ? 00:00:12 kube-scheduler --kubeconfig=/etc/kubernete
|
|||||||
Follow the etcd service documentation and configure TLS encryption.
|
Follow the etcd service documentation and configure TLS encryption.
|
||||||
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml
|
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml
|
||||||
on the master node and set the below parameters.
|
on the master node and set the below parameters.
|
||||||
--cert-file=</path/to/ca-file>
|
`--cert-file=</path/to/ca-file>`
|
||||||
--key-file=</path/to/key-file>
|
`--key-file=</path/to/key-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1866,8 +1866,8 @@ Follow the etcd service documentation and configure peer TLS encryption as appro
|
|||||||
for your etcd cluster.
|
for your etcd cluster.
|
||||||
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
|
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
|
||||||
master node and set the below parameters.
|
master node and set the below parameters.
|
||||||
--peer-client-file=</path/to/peer-cert-file>
|
`--peer-client-file=</path/to/peer-cert-file>`
|
||||||
--peer-key-file=</path/to/peer-key-file>
|
`--peer-key-file=</path/to/peer-key-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1954,7 +1954,7 @@ Follow the etcd documentation and create a dedicated certificate authority setup
|
|||||||
etcd service.
|
etcd service.
|
||||||
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
|
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
|
||||||
master node and set the below parameter.
|
master node and set the below parameter.
|
||||||
--trusted-ca-file=</path/to/ca-file>
|
`--trusted-ca-file=</path/to/ca-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -2145,7 +2145,7 @@ root:root
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the file permissions of the
|
Run the following command to modify the file permissions of the
|
||||||
--client-ca-file chmod 644 <filename>
|
`--client-ca-file chmod 644 <filename>`
|
||||||
|
|
||||||
**Audit Script:** `check_cafile_permissions.sh`
|
**Audit Script:** `check_cafile_permissions.sh`
|
||||||
|
|
||||||
@@ -2177,7 +2177,7 @@ if test -e $CAFILE; then stat -c permissions=%a $CAFILE; fi
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the ownership of the --client-ca-file.
|
Run the following command to modify the ownership of the --client-ca-file.
|
||||||
chown root:root <filename>
|
`chown root:root <filename>`
|
||||||
|
|
||||||
**Audit Script:** `check_cafile_ownership.sh`
|
**Audit Script:** `check_cafile_ownership.sh`
|
||||||
|
|
||||||
@@ -2305,7 +2305,7 @@ the location of the client CA file.
|
|||||||
If using command line arguments, edit the kubelet service file
|
If using command line arguments, edit the kubelet service file
|
||||||
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
||||||
set the below parameter in KUBELET_AUTHZ_ARGS variable.
|
set the below parameter in KUBELET_AUTHZ_ARGS variable.
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
systemctl restart kubelet.service
|
systemctl restart kubelet.service
|
||||||
@@ -2526,8 +2526,8 @@ to the location of the corresponding private key file.
|
|||||||
If using command line arguments, edit the kubelet service file
|
If using command line arguments, edit the kubelet service file
|
||||||
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
||||||
set the below parameters in KUBELET_CERTIFICATE_ARGS variable.
|
set the below parameters in KUBELET_CERTIFICATE_ARGS variable.
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
systemctl restart kubelet.service
|
systemctl restart kubelet.service
|
||||||
|
|||||||
+23
-23
@@ -754,7 +754,7 @@ on the master node and set the below parameter.
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --basic-auth-file=<filename> parameter.
|
on the master node and remove the `--basic-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -782,7 +782,7 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --token-auth-file=<filename> parameter.
|
on the master node and remove the `--token-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -869,8 +869,8 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
Follow the Kubernetes documentation and setup the TLS connection between
|
Follow the Kubernetes documentation and setup the TLS connection between
|
||||||
the apiserver and kubelets. Then, edit the API server pod specification file
|
the apiserver and kubelets. Then, edit the API server pod specification file
|
||||||
/var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml on the master node and set the
|
/var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml on the master node and set the
|
||||||
--kubelet-certificate-authority parameter to the path to the cert file for the certificate authority.
|
`--kubelet-certificate-authority` parameter to the path to the cert file for the certificate authority.
|
||||||
--kubelet-certificate-authority=<ca-string>
|
`--kubelet-certificate-authority=<ca-string>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1468,7 +1468,7 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
Edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
Edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and set the --service-account-key-file parameter
|
on the master node and set the --service-account-key-file parameter
|
||||||
to the public key file for service accounts:
|
to the public key file for service accounts:
|
||||||
--service-account-key-file=<filename>
|
`--service-account-key-file=<filename>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1497,8 +1497,8 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
||||||
Then, edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and set the etcd certificate and key file parameters.
|
on the master node and set the etcd certificate and key file parameters.
|
||||||
--etcd-certfile=<path/to/client-certificate-file>
|
`--etcd-certfile=<path/to/client-certificate-file>`
|
||||||
--etcd-keyfile=<path/to/client-key-file>
|
`--etcd-keyfile=<path/to/client-key-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1527,8 +1527,8 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
||||||
Then, edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and set the TLS certificate and private key file parameters.
|
on the master node and set the TLS certificate and private key file parameters.
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1557,7 +1557,7 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
||||||
Then, edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and set the client certificate authority file.
|
on the master node and set the client certificate authority file.
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1586,7 +1586,7 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
||||||
Then, edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and set the etcd certificate authority file parameter.
|
on the master node and set the etcd certificate authority file parameter.
|
||||||
--etcd-cafile=<path/to/ca-file>
|
`--etcd-cafile=<path/to/ca-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1787,7 +1787,7 @@ root 5522 5416 3 14:58 ? 00:00:16 kube-controller-manager --flex-volume-plugin-d
|
|||||||
Edit the Controller Manager pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-controller-manager.yaml
|
Edit the Controller Manager pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-controller-manager.yaml
|
||||||
on the master node and set the --service-account-private-key-file parameter
|
on the master node and set the --service-account-private-key-file parameter
|
||||||
to the private key file for service accounts.
|
to the private key file for service accounts.
|
||||||
--service-account-private-key-file=<filename>
|
`--service-account-private-key-file=<filename>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1815,7 +1815,7 @@ root 5522 5416 3 14:58 ? 00:00:16 kube-controller-manager --flex-volume-plugin-d
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Edit the Controller Manager pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-controller-manager.yaml
|
Edit the Controller Manager pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-controller-manager.yaml
|
||||||
on the master node and set the --root-ca-file parameter to the certificate bundle file`.
|
on the master node and set the --root-ca-file parameter to the certificate bundle file`.
|
||||||
--root-ca-file=<path/to/file>
|
`--root-ca-file=<path/to/file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -1938,8 +1938,8 @@ root 5533 5414 0 14:58 ? 00:00:02 kube-scheduler --permit-port-sharing=true --ad
|
|||||||
Follow the etcd service documentation and configure TLS encryption.
|
Follow the etcd service documentation and configure TLS encryption.
|
||||||
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml
|
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml
|
||||||
on the master node and set the below parameters.
|
on the master node and set the below parameters.
|
||||||
--cert-file=</path/to/ca-file>
|
`--cert-file=</path/to/ca-file>`
|
||||||
--key-file=</path/to/key-file>
|
`--key-file=</path/to/key-file>`
|
||||||
|
|
||||||
### 2.2 Ensure that the --client-cert-auth argument is set to true (Automated)
|
### 2.2 Ensure that the --client-cert-auth argument is set to true (Automated)
|
||||||
|
|
||||||
@@ -1989,8 +1989,8 @@ Follow the etcd service documentation and configure peer TLS encryption as appro
|
|||||||
for your etcd cluster.
|
for your etcd cluster.
|
||||||
Then, edit the etcd pod specification file /var/lib/rancher/rke2/agent/pod-manifests/etcd.yaml on the
|
Then, edit the etcd pod specification file /var/lib/rancher/rke2/agent/pod-manifests/etcd.yaml on the
|
||||||
master node and set the below parameters.
|
master node and set the below parameters.
|
||||||
--peer-client-file=</path/to/peer-cert-file>
|
`--peer-client-file=</path/to/peer-cert-file>`
|
||||||
--peer-key-file=</path/to/peer-key-file>
|
`--peer-key-file=</path/to/peer-key-file>`
|
||||||
|
|
||||||
### 2.5 Ensure that the --peer-client-cert-auth argument is set to true (Automated)
|
### 2.5 Ensure that the --peer-client-cert-auth argument is set to true (Automated)
|
||||||
|
|
||||||
@@ -2041,7 +2041,7 @@ Follow the etcd documentation and create a dedicated certificate authority setup
|
|||||||
etcd service.
|
etcd service.
|
||||||
Then, edit the etcd pod specification file /var/lib/rancher/rke2/agent/pod-manifests/etcd.yaml on the
|
Then, edit the etcd pod specification file /var/lib/rancher/rke2/agent/pod-manifests/etcd.yaml on the
|
||||||
master node and set the below parameter.
|
master node and set the below parameter.
|
||||||
--trusted-ca-file=</path/to/ca-file>
|
`--trusted-ca-file=</path/to/ca-file>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -2258,7 +2258,7 @@ root:root
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the file permissions of the
|
Run the following command to modify the file permissions of the
|
||||||
--client-ca-file chmod 644 <filename>
|
`--client-ca-file chmod 644 <filename>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -2273,7 +2273,7 @@ stat -c %a /var/lib/rancher/rke2/server/tls/server-ca.crt
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the ownership of the --client-ca-file.
|
Run the following command to modify the ownership of the --client-ca-file.
|
||||||
chown root:roset: trueot <filename>
|
`chown root:roset: trueot <filename>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -2438,7 +2438,7 @@ the location of the client CA file.
|
|||||||
If using command line arguments, edit the kubelet service file
|
If using command line arguments, edit the kubelet service file
|
||||||
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
||||||
set the below parameter in KUBELET_AUTHZ_ARGS variable.
|
set the below parameter in KUBELET_AUTHZ_ARGS variable.
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
systemctl restart kubelet.service
|
systemctl restart kubelet.service
|
||||||
@@ -2693,8 +2693,8 @@ to the location of the corresponding private key file.
|
|||||||
If using command line arguments, edit the kubelet service file
|
If using command line arguments, edit the kubelet service file
|
||||||
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
||||||
set the below parameters in KUBELET_CERTIFICATE_ARGS variable.
|
set the below parameters in KUBELET_CERTIFICATE_ARGS variable.
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
systemctl restart kubelet.service
|
systemctl restart kubelet.service
|
||||||
|
|||||||
+10
-4
@@ -164,14 +164,20 @@ You can change the cluster or project role(s) that are automatically assigned to
|
|||||||
1. Find the custom or individual role that you want to use as default. Then edit the role by selecting **⋮ > Edit**.
|
1. Find the custom or individual role that you want to use as default. Then edit the role by selecting **⋮ > Edit**.
|
||||||
|
|
||||||
1. Enable the role as default.
|
1. Enable the role as default.
|
||||||
{{% accordion id="cluster" label="For Clusters" %}}
|
<details id="cluster">
|
||||||
|
<summary>For Clusters</summary>
|
||||||
|
|
||||||
1. From **Cluster Creator Default**, choose **Yes: Default role for new cluster creation**.
|
1. From **Cluster Creator Default**, choose **Yes: Default role for new cluster creation**.
|
||||||
1. Click **Save**.
|
1. Click **Save**.
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="project" label="For Projects" %}}
|
</details>
|
||||||
|
<details id="project">
|
||||||
|
|
||||||
|
<summary>For Projects</summary>
|
||||||
1. From **Project Creator Default**, choose **Yes: Default role for new project creation**.
|
1. From **Project Creator Default**, choose **Yes: Default role for new project creation**.
|
||||||
1. Click **Save**.
|
1. Click **Save**.
|
||||||
{{% /accordion %}}
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. If you want to remove a default role, edit the permission and select **No** from the default roles option.
|
1. If you want to remove a default role, edit the permission and select **No** from the default roles option.
|
||||||
|
|
||||||
|
|||||||
+3
-2
@@ -37,7 +37,8 @@ docker ps
|
|||||||
|
|
||||||
Write down or copy this information before starting the [procedure below](#creating-a-backup).
|
Write down or copy this information before starting the [procedure below](#creating-a-backup).
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
@@ -68,7 +69,7 @@ This procedure creates a backup that you can restore if Rancher encounters a dis
|
|||||||
docker create --volumes-from <RANCHER_CONTAINER_NAME> --name rancher-data-<DATE> rancher/rancher:<RANCHER_CONTAINER_TAG>
|
docker create --volumes-from <RANCHER_CONTAINER_NAME> --name rancher-data-<DATE> rancher/rancher:<RANCHER_CONTAINER_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
1. <a id="tarball"></a>From the data container that you just created (`rancher-data-<DATE>`), create a backup tarball (`rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz`). Use the following command, replacing each placeholder.
|
1. <a id="tarball"></a>From the data container that you just created (<code>rancher-data-<DATE></code>), create a backup tarball (<code>rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz</code>). Use the following command, replacing each placeholder.
|
||||||
|
|
||||||
```
|
```
|
||||||
docker run --volumes-from rancher-data-<DATE> -v $PWD:/backup:z busybox tar pzcvf /backup/rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz /var/lib/rancher
|
docker run --volumes-from rancher-data-<DATE> -v $PWD:/backup:z busybox tar pzcvf /backup/rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz /var/lib/rancher
|
||||||
|
|||||||
+2
-1
@@ -25,7 +25,8 @@ In this command, `<RANCHER_CONTAINER_NAME>` and `<RANCHER_VERSION>-<DATE>` are e
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ Alternatively, you can switch between projects and clusters directly in the navi
|
|||||||
|
|
||||||
After clusters have been [provisioned into Rancher]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/), [cluster owners]({{<baseurl>}}/rancher/v2.0-v2.4/en/admin-settings/rbac/cluster-project-roles/#cluster-roles) will need to manage these clusters. There are many different options of how to manage your cluster.
|
After clusters have been [provisioned into Rancher]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/), [cluster owners]({{<baseurl>}}/rancher/v2.0-v2.4/en/admin-settings/rbac/cluster-project-roles/#cluster-roles) will need to manage these clusters. There are many different options of how to manage your cluster.
|
||||||
|
|
||||||
{{% include file="/rancher/v2.0-v2.4/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.0-v2.4/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
## Configuring Tools
|
## Configuring Tools
|
||||||
|
|
||||||
|
|||||||
+3
-3
@@ -296,8 +296,8 @@ This table shows cluster-autoscaler parameters for fine tuning:
|
|||||||
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
||||||
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
||||||
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
||||||
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
cloud-provider|-|Cloud provider type|
|
cloud-provider|-|Cloud provider type|
|
||||||
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
||||||
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
||||||
@@ -307,7 +307,7 @@ cloud-provider|-|Cloud provider type|
|
|||||||
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
||||||
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
||||||
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
||||||
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: <min>:<max>:<other...>|
|
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: `<min>:<max>:<other...>`|
|
||||||
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
||||||
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
||||||
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
||||||
|
|||||||
+1
-1
@@ -18,7 +18,7 @@ The options and settings available for an existing cluster change based on the m
|
|||||||
|
|
||||||
The following table summarizes the options and settings available for each cluster type:
|
The following table summarizes the options and settings available for each cluster type:
|
||||||
|
|
||||||
{{% include file="/rancher/v2.0-v2.4/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.0-v2.4/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
### Editing Clusters in the Rancher UI
|
### Editing Clusters in the Rancher UI
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -28,7 +28,7 @@ This section covers the following topics:
|
|||||||
|
|
||||||
The following table summarizes the options and settings available for each cluster type:
|
The following table summarizes the options and settings available for each cluster type:
|
||||||
|
|
||||||
{{% include file="/rancher/v2.0-v2.4/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.0-v2.4/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
# Setting up Clusters in a Hosted Kubernetes Provider
|
# Setting up Clusters in a Hosted Kubernetes Provider
|
||||||
|
|
||||||
|
|||||||
+8
-4
@@ -139,7 +139,8 @@ Option | Description
|
|||||||
|
|
||||||
If you choose to assign a public IP address to your cluster's worker nodes, you have the option of choosing between a VPC that's automatically generated by Rancher (i.e., **Standard: Rancher generated VPC and Subnet**), or a VPC that you've already created with AWS (i.e., **Custom: Choose from your existing VPC and Subnets**). Choose the option that best fits your use case.
|
If you choose to assign a public IP address to your cluster's worker nodes, you have the option of choosing between a VPC that's automatically generated by Rancher (i.e., **Standard: Rancher generated VPC and Subnet**), or a VPC that you've already created with AWS (i.e., **Custom: Choose from your existing VPC and Subnets**). Choose the option that best fits your use case.
|
||||||
|
|
||||||
{{% accordion id="yes" label="Click to expand" %}}
|
<details id="yes">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you're using **Custom: Choose from your existing VPC and Subnets**:
|
If you're using **Custom: Choose from your existing VPC and Subnets**:
|
||||||
|
|
||||||
@@ -152,10 +153,13 @@ If you're using **Custom: Choose from your existing VPC and Subnets**:
|
|||||||
1. Click **Next: Select Subnets**. Then choose one of the **Subnets** that displays.
|
1. Click **Next: Select Subnets**. Then choose one of the **Subnets** that displays.
|
||||||
|
|
||||||
1. Click **Next: Select Security Group**.
|
1. Click **Next: Select Security Group**.
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
If your worker nodes have Private IPs only, you must also choose a **VPC & Subnet** that allow your instances to access the internet. This access is required so that your worker nodes can connect to the Kubernetes control plane.
|
If your worker nodes have Private IPs only, you must also choose a **VPC & Subnet** that allow your instances to access the internet. This access is required so that your worker nodes can connect to the Kubernetes control plane.
|
||||||
{{% accordion id="no" label="Click to expand" %}}
|
|
||||||
|
<details id="no">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
Follow the steps below.
|
Follow the steps below.
|
||||||
|
|
||||||
>**Tip:** When using only private IP addresses, you can provide your nodes internet access by creating a VPC constructed with two subnets, a private set and a public set. The private set should have its route tables configured to point toward a NAT in the public set. For more information on routing traffic from private subnets, please see the [official AWS documentation](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html).
|
>**Tip:** When using only private IP addresses, you can provide your nodes internet access by creating a VPC constructed with two subnets, a private set and a public set. The private set should have its route tables configured to point toward a NAT in the public set. For more information on routing traffic from private subnets, please see the [official AWS documentation](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html).
|
||||||
@@ -164,7 +168,7 @@ Follow the steps below.
|
|||||||
|
|
||||||
1. Click **Next: Select Subnets**. Then choose one of the **Subnets** that displays.
|
1. Click **Next: Select Subnets**. Then choose one of the **Subnets** that displays.
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Security Group
|
### Security Group
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -11,10 +11,10 @@ The following table lists the permissions required for the vSphere user account:
|
|||||||
|
|
||||||
| Privilege Group | Operations |
|
| Privilege Group | Operations |
|
||||||
|:----------------------|:-----------------------------------------------------------------------|
|
|:----------------------|:-----------------------------------------------------------------------|
|
||||||
| Datastore | AllocateSpace </br> Browse </br> FileManagement (Low level file operations) </br> UpdateVirtualMachineFiles </br> UpdateVirtualMachineMetadata |
|
| Datastore | AllocateSpace <br/> Browse <br/> FileManagement (Low level file operations) <br/> UpdateVirtualMachineFiles <br/> UpdateVirtualMachineMetadata |
|
||||||
| Network | Assign |
|
| Network | Assign |
|
||||||
| Resource | AssignVMToPool |
|
| Resource | AssignVMToPool |
|
||||||
| Virtual Machine | Config (All) </br> GuestOperations (All) </br> Interact (All) </br> Inventory (All) </br> Provisioning (All) |
|
| Virtual Machine | Config (All) <br/> GuestOperations (All) <br/> Interact (All) <br/> Inventory (All) <br/> Provisioning (All) |
|
||||||
|
|
||||||
The following steps create a role with the required privileges and then assign it to a new user in the vSphere console:
|
The following steps create a role with the required privileges and then assign it to a new user in the vSphere console:
|
||||||
|
|
||||||
|
|||||||
+7
-4
@@ -169,7 +169,8 @@ The structure of the config file is different depending on your version of Ranch
|
|||||||
|
|
||||||
RKE (Rancher Kubernetes Engine) is the tool that Rancher uses to provision Kubernetes clusters. Rancher's cluster config files used to have the same structure as [RKE config files,]({{<baseurl>}}/rke/latest/en/example-yamls/) but the structure changed so that in Rancher, RKE cluster config items are separated from non-RKE config items. Therefore, configuration for your cluster needs to be nested under the `rancher_kubernetes_engine_config` directive in the cluster config file. Cluster config files created with earlier versions of Rancher will need to be updated for this format. An example cluster config file is included below.
|
RKE (Rancher Kubernetes Engine) is the tool that Rancher uses to provision Kubernetes clusters. Rancher's cluster config files used to have the same structure as [RKE config files,]({{<baseurl>}}/rke/latest/en/example-yamls/) but the structure changed so that in Rancher, RKE cluster config items are separated from non-RKE config items. Therefore, configuration for your cluster needs to be nested under the `rancher_kubernetes_engine_config` directive in the cluster config file. Cluster config files created with earlier versions of Rancher will need to be updated for this format. An example cluster config file is included below.
|
||||||
|
|
||||||
{{% accordion id="v2.3.0-cluster-config-file" label="Example Cluster Config File for Rancher v2.3.0+" %}}
|
<details id="v2.3.0-cluster-config-file">
|
||||||
|
<summary>Example Cluster Config File for Rancher v2.3.0+</summary>
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
#
|
#
|
||||||
@@ -261,13 +262,15 @@ rancher_kubernetes_engine_config: # Your RKE template config goes here.
|
|||||||
ssh_agent_auth: false
|
ssh_agent_auth: false
|
||||||
windows_prefered_cluster: false
|
windows_prefered_cluster: false
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Config File Structure in Rancher v2.0.0-v2.2.x
|
### Config File Structure in Rancher v2.0.0-v2.2.x
|
||||||
|
|
||||||
An example cluster config file is included below.
|
An example cluster config file is included below.
|
||||||
|
|
||||||
{{% accordion id="before-v2.3.0-cluster-config-file" label="Example Cluster Config File for Rancher v2.0.0-v2.2.x" %}}
|
<details id="before-v2.3.0-cluster-config-file">
|
||||||
|
<summary>Example Cluster Config File for Rancher v2.0.0-v2.2.x</summary>
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
addon_job_timeout: 30
|
addon_job_timeout: 30
|
||||||
authentication:
|
authentication:
|
||||||
@@ -344,7 +347,7 @@ services:
|
|||||||
service_node_port_range: 30000-32767
|
service_node_port_range: 30000-32767
|
||||||
ssh_agent_auth: false
|
ssh_agent_auth: false
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Default DNS provider
|
### Default DNS provider
|
||||||
|
|
||||||
|
|||||||
@@ -13,25 +13,25 @@ This page contains frequently asked questions about the changes between Rancher
|
|||||||
|
|
||||||
Rancher v2.x is a complete container management platform built 100% on Kubernetes leveraging its Custom Resource and Controller framework. All features are written as a CustomResourceDefinition (CRD) which extends the existing Kubernetes API and can leverage native features such as RBAC.
|
Rancher v2.x is a complete container management platform built 100% on Kubernetes leveraging its Custom Resource and Controller framework. All features are written as a CustomResourceDefinition (CRD) which extends the existing Kubernetes API and can leverage native features such as RBAC.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Do you plan to implement upstream Kubernetes, or continue to work on your own fork?**
|
**Do you plan to implement upstream Kubernetes, or continue to work on your own fork?**
|
||||||
|
|
||||||
We're still going to provide our distribution when you select the default option of having us create your Kubernetes cluster, but it will be very close to upstream.
|
We're still going to provide our distribution when you select the default option of having us create your Kubernetes cluster, but it will be very close to upstream.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Does this release mean that we need to re-train our support staff in Kubernetes?**
|
**Does this release mean that we need to re-train our support staff in Kubernetes?**
|
||||||
|
|
||||||
Yes. Rancher will offer the native Kubernetes functionality via `kubectl` but will also offer our own UI dashboard to allow you to deploy Kubernetes workload without having to understand the full complexity of Kubernetes. However, to fully leverage Kubernetes, we do recommend understanding Kubernetes. We do plan on improving our UX with subsequent releases to make Kubernetes easier to use.
|
Yes. Rancher will offer the native Kubernetes functionality via `kubectl` but will also offer our own UI dashboard to allow you to deploy Kubernetes workload without having to understand the full complexity of Kubernetes. However, to fully leverage Kubernetes, we do recommend understanding Kubernetes. We do plan on improving our UX with subsequent releases to make Kubernetes easier to use.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Is a Rancher compose going to make a Kubernetes pod? Do we have to learn both now? We usually use the filesystem layer of files, not the UI.**
|
**Is a Rancher compose going to make a Kubernetes pod? Do we have to learn both now? We usually use the filesystem layer of files, not the UI.**
|
||||||
|
|
||||||
No. Unfortunately, the differences were enough such that we cannot support Rancher compose anymore in 2.x. We will be providing both a tool and guides to help with this migration.
|
No. Unfortunately, the differences were enough such that we cannot support Rancher compose anymore in 2.x. We will be providing both a tool and guides to help with this migration.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**If we use Kubernetes native YAML files for creating resources, should we expect that to work as expected, or do we need to use Rancher/Docker compose files to deploy infrastructure?**
|
**If we use Kubernetes native YAML files for creating resources, should we expect that to work as expected, or do we need to use Rancher/Docker compose files to deploy infrastructure?**
|
||||||
|
|
||||||
@@ -43,7 +43,7 @@ Absolutely.
|
|||||||
|
|
||||||
Cattle will not supported in v2.x as Rancher has been re-architected to be based on Kubernetes. You can, however, expect majority of Cattle features you use will exist and function similarly on Kubernetes. We will develop migration tools in Rancher v2.1 to help you transform your existing Rancher Compose files into Kubernetes YAML files.
|
Cattle will not supported in v2.x as Rancher has been re-architected to be based on Kubernetes. You can, however, expect majority of Cattle features you use will exist and function similarly on Kubernetes. We will develop migration tools in Rancher v2.1 to help you transform your existing Rancher Compose files into Kubernetes YAML files.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Can I migrate existing Cattle workloads into Kubernetes?**
|
**Can I migrate existing Cattle workloads into Kubernetes?**
|
||||||
|
|
||||||
@@ -55,19 +55,19 @@ Yes. In the upcoming Rancher v2.1 release we will provide a tool to help transla
|
|||||||
|
|
||||||
Yes. You can manage Kubernetes storage, networking, and its vast ecosystem of add-ons.
|
Yes. You can manage Kubernetes storage, networking, and its vast ecosystem of add-ons.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Are there changes to default roles available now or going forward? Will the Kubernetes alignment impact plans for roles/RBAC?**
|
**Are there changes to default roles available now or going forward? Will the Kubernetes alignment impact plans for roles/RBAC?**
|
||||||
|
|
||||||
The default roles will be expanded to accommodate the new Rancher 2.x features, and will also take advantage of the Kubernetes RBAC (Role-Based Access Control) capabilities to give you more flexibility.
|
The default roles will be expanded to accommodate the new Rancher 2.x features, and will also take advantage of the Kubernetes RBAC (Role-Based Access Control) capabilities to give you more flexibility.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Will there be any functions like network policies to separate a front-end container from a back-end container through some kind of firewall in v2.x?**
|
**Will there be any functions like network policies to separate a front-end container from a back-end container through some kind of firewall in v2.x?**
|
||||||
|
|
||||||
Yes. You can do so by leveraging Kubernetes' network policies.
|
Yes. You can do so by leveraging Kubernetes' network policies.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**What about the CLI? Will that work the same way with the same features?**
|
**What about the CLI? Will that work the same way with the same features?**
|
||||||
|
|
||||||
@@ -81,7 +81,7 @@ Starting with 2.0, the concept of an environment has now been changed to a Kuber
|
|||||||
|
|
||||||
Kubernetes RKE Templates is on our roadmap for 2.x. Please refer to our Release Notes and documentation for all the features that we currently support.
|
Kubernetes RKE Templates is on our roadmap for 2.x. Please refer to our Release Notes and documentation for all the features that we currently support.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Can you still add an existing host to an environment? (i.e. not provisioned directly from Rancher)**
|
**Can you still add an existing host to an environment? (i.e. not provisioned directly from Rancher)**
|
||||||
|
|
||||||
@@ -93,7 +93,7 @@ Yes. We still provide you with the same way of executing our Rancher agents dire
|
|||||||
|
|
||||||
Due to the technical difficulty in transforming a Docker container into a pod running Kubernetes, upgrading will require users to "replay" those workloads from v1.x into new v2.x environments. We plan to ship with a tool in v2.1 to translate existing Rancher Compose files into Kubernetes YAML files. You will then be able to deploy those workloads on the v2.x platform.
|
Due to the technical difficulty in transforming a Docker container into a pod running Kubernetes, upgrading will require users to "replay" those workloads from v1.x into new v2.x environments. We plan to ship with a tool in v2.1 to translate existing Rancher Compose files into Kubernetes YAML files. You will then be able to deploy those workloads on the v2.x platform.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Is it possible to upgrade from Rancher v1.x to v2.x without any disruption to Cattle and Kubernetes clusters?**
|
**Is it possible to upgrade from Rancher v1.x to v2.x without any disruption to Cattle and Kubernetes clusters?**
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -117,7 +117,7 @@ This reference contains variables that you can use in `questions.yml` nested und
|
|||||||
| max_length | int | false | Max character length.|
|
| max_length | int | false | Max character length.|
|
||||||
| min | int | false | Min integer length. |
|
| min | int | false | Min integer length. |
|
||||||
| max | int | false | Max integer length. |
|
| max | int | false | Max integer length. |
|
||||||
| options | []string | false | Specify the options when the variable type is `enum`, for example: options:<br> - "ClusterIP" <br> - "NodePort" <br> - "LoadBalancer"|
|
| options | []string | false | Specify the options when the variable type is `enum`, for example: options:<br/> - "ClusterIP" <br/> - "NodePort" <br/> - "LoadBalancer"|
|
||||||
| valid_chars | string | false | Regular expression for input chars validation. |
|
| valid_chars | string | false | Regular expression for input chars validation. |
|
||||||
| invalid_chars | string | false | Regular expression for invalid input chars validation.|
|
| invalid_chars | string | false | Regular expression for invalid input chars validation.|
|
||||||
| subquestions | []subquestion | false| Add an array of subquestions.|
|
| subquestions | []subquestion | false| Add an array of subquestions.|
|
||||||
|
|||||||
+3
-2
@@ -103,7 +103,8 @@ There are three recommended options for the source of the certificate used for T
|
|||||||
|
|
||||||
This step is only required to use certificates issued by Rancher's generated CA (`ingress.tls.source=rancher`) or to request Let's Encrypt issued certificates (`ingress.tls.source=letsEncrypt`).
|
This step is only required to use certificates issued by Rancher's generated CA (`ingress.tls.source=rancher`) or to request Let's Encrypt issued certificates (`ingress.tls.source=letsEncrypt`).
|
||||||
|
|
||||||
{{% accordion id="cert-manager" label="Click to Expand" %}}
|
<details id="cert-manager">
|
||||||
|
<summary>Click to Expand</summary>
|
||||||
|
|
||||||
> **Important:** Recent changes to cert-manager require an upgrade. If you are upgrading Rancher and using a version of cert-manager older than v0.11.0, please see our [upgrade documentation]({{<baseurl>}}/rancher/v2.0-v2.4/en/installation/options/upgrading-cert-manager/).
|
> **Important:** Recent changes to cert-manager require an upgrade. If you are upgrading Rancher and using a version of cert-manager older than v0.11.0, please see our [upgrade documentation]({{<baseurl>}}/rancher/v2.0-v2.4/en/installation/options/upgrading-cert-manager/).
|
||||||
|
|
||||||
@@ -150,7 +151,7 @@ cert-manager-cainjector-577f6d9fd7-tr77l 1/1 Running 0 2m
|
|||||||
cert-manager-webhook-787858fcdb-nlzsq 1/1 Running 0 2m
|
cert-manager-webhook-787858fcdb-nlzsq 1/1 Running 0 2m
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### 6. Install Rancher with Helm and Your Chosen Certificate Option
|
### 6. Install Rancher with Helm and Your Chosen Certificate Option
|
||||||
|
|
||||||
|
|||||||
+12
-8
@@ -102,7 +102,8 @@ hostname: rancher.my.org
|
|||||||
|
|
||||||
If you are also upgrading cert-manager to the latest version from a version older than 0.11.0, follow `Option B: Reinstalling Rancher`. Otherwise, follow `Option A: Upgrading Rancher`.
|
If you are also upgrading cert-manager to the latest version from a version older than 0.11.0, follow `Option B: Reinstalling Rancher`. Otherwise, follow `Option A: Upgrading Rancher`.
|
||||||
|
|
||||||
{{% accordion label="Option A: Upgrading Rancher" %}}
|
<details>
|
||||||
|
<summary>Option A: Upgrading Rancher</summary>
|
||||||
|
|
||||||
Upgrade Rancher to the latest version with all your settings.
|
Upgrade Rancher to the latest version with all your settings.
|
||||||
|
|
||||||
@@ -113,9 +114,10 @@ helm upgrade --install rancher rancher-<CHART_REPO>/rancher \
|
|||||||
--namespace cattle-system \
|
--namespace cattle-system \
|
||||||
--set hostname=rancher.my.org
|
--set hostname=rancher.my.org
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
{{% accordion label="Option B: Reinstalling Rancher chart" %}}
|
<details>
|
||||||
|
<summary>Option B: Reinstalling Rancher chart</summary>
|
||||||
|
|
||||||
If you are currently running the cert-manager whose version is older than v0.11, and want to upgrade both Rancher and cert-manager to a newer version, then you need to reinstall both Rancher and cert-manager due to the API change in cert-manager v0.11.
|
If you are currently running the cert-manager whose version is older than v0.11, and want to upgrade both Rancher and cert-manager to a newer version, then you need to reinstall both Rancher and cert-manager due to the API change in cert-manager v0.11.
|
||||||
|
|
||||||
@@ -137,7 +139,7 @@ If you are currently running the cert-manager whose version is older than v0.11,
|
|||||||
--set hostname=rancher.my.org
|
--set hostname=rancher.my.org
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
</TabItem>
|
</TabItem>
|
||||||
<TabItem value="Kubernetes Air Gap Upgrade">
|
<TabItem value="Kubernetes Air Gap Upgrade">
|
||||||
@@ -153,7 +155,8 @@ If you are currently running the cert-manager whose version is older than v0.11,
|
|||||||
`<REGISTRY.YOURDOMAIN.COM:PORT>` | The DNS name for your private registry.
|
`<REGISTRY.YOURDOMAIN.COM:PORT>` | The DNS name for your private registry.
|
||||||
`<CERTMANAGER_VERSION>` | Cert-manager version running on k8s cluster.
|
`<CERTMANAGER_VERSION>` | Cert-manager version running on k8s cluster.
|
||||||
|
|
||||||
{{% accordion id="self-signed" label="Option A-Default Self-Signed Certificate" %}}
|
<details id="self-signed">
|
||||||
|
<summary>Option A-Default Self-Signed Certificate</summary>
|
||||||
|
|
||||||
```plain
|
```plain
|
||||||
helm template ./rancher-<VERSION>.tgz --output-dir . \
|
helm template ./rancher-<VERSION>.tgz --output-dir . \
|
||||||
@@ -166,8 +169,9 @@ helm template ./rancher-<VERSION>.tgz --output-dir . \
|
|||||||
--set useBundledSystemChart=true # Available as of v2.3.0, use the packaged Rancher system charts
|
--set useBundledSystemChart=true # Available as of v2.3.0, use the packaged Rancher system charts
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="secret" label="Option B: Certificates From Files using Kubernetes Secrets" %}}
|
<details id="secret">
|
||||||
|
<summary>Option B: Certificates From Files using Kubernetes Secrets</summary>
|
||||||
|
|
||||||
```plain
|
```plain
|
||||||
helm template ./rancher-<VERSION>.tgz --output-dir . \
|
helm template ./rancher-<VERSION>.tgz --output-dir . \
|
||||||
@@ -194,7 +198,7 @@ helm template ./rancher-<VERSION>.tgz --output-dir . \
|
|||||||
--set useBundledSystemChart=true # Available as of v2.3.0, use the packaged Rancher system charts
|
--set useBundledSystemChart=true # Available as of v2.3.0, use the packaged Rancher system charts
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
2. Copy the rendered manifest directories to a system with access to the Rancher server cluster and apply the rendered templates.
|
2. Copy the rendered manifest directories to a system with access to the Rancher server cluster and apply the rendered templates.
|
||||||
|
|
||||||
|
|||||||
+19
-13
@@ -68,7 +68,7 @@ When setting up the Rancher Helm template, there are several options in the Helm
|
|||||||
|
|
||||||
| Chart Option | Chart Value | Description |
|
| Chart Option | Chart Value | Description |
|
||||||
| ----------------------- | -------------------------------- | ---- |
|
| ----------------------- | -------------------------------- | ---- |
|
||||||
| `certmanager.version` | "<version>" | Configure proper Rancher TLS issuer depending of running cert-manager version. |
|
| `certmanager.version` | `<version>` | Configure proper Rancher TLS issuer depending of running cert-manager version. |
|
||||||
| `systemDefaultRegistry` | `<REGISTRY.YOURDOMAIN.COM:PORT>` | Configure Rancher server to always pull from your private registry when provisioning clusters. |
|
| `systemDefaultRegistry` | `<REGISTRY.YOURDOMAIN.COM:PORT>` | Configure Rancher server to always pull from your private registry when provisioning clusters. |
|
||||||
| `useBundledSystemChart` | `true` | Configure Rancher server to use the packaged copy of Helm system charts. The [system charts](https://github.com/rancher/system-charts) repository contains all the catalog items required for features such as monitoring, logging, alerting and global DNS. These [Helm charts](https://github.com/rancher/system-charts) are located in GitHub, but since you are in an air gapped environment, using the charts that are bundled within Rancher is much easier than setting up a Git mirror. _Available as of v2.3.0_ |
|
| `useBundledSystemChart` | `true` | Configure Rancher server to use the packaged copy of Helm system charts. The [system charts](https://github.com/rancher/system-charts) repository contains all the catalog items required for features such as monitoring, logging, alerting and global DNS. These [Helm charts](https://github.com/rancher/system-charts) are located in GitHub, but since you are in an air gapped environment, using the charts that are bundled within Rancher is much easier than setting up a Git mirror. _Available as of v2.3.0_ |
|
||||||
|
|
||||||
@@ -76,7 +76,8 @@ Based on the choice your made in [B. Choose your SSL Configuration](#b-choose-yo
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="k8s-1" label="Click to expand" %}}
|
<details id="k8s-1">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
By default, Rancher generates a CA and uses cert-manager to issue the certificate for access to the Rancher server interface.
|
By default, Rancher generates a CA and uses cert-manager to issue the certificate for access to the Rancher server interface.
|
||||||
|
|
||||||
@@ -131,11 +132,12 @@ By default, Rancher generates a CA and uses cert-manager to issue the certificat
|
|||||||
|
|
||||||
**Optional**: To install a specific Rancher version, set the `rancherImageTag` value, example: `--set rancherImageTag=v2.3.6`
|
**Optional**: To install a specific Rancher version, set the `rancherImageTag` value, example: `--set rancherImageTag=v2.3.6`
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Certificates From Files using Kubernetes Secrets
|
### Option B: Certificates From Files using Kubernetes Secrets
|
||||||
|
|
||||||
{{% accordion id="k8s-2" label="Click to expand" %}}
|
<details id="k8s-2">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
Create Kubernetes secrets from your own certificates for Rancher to use. The common name for the cert will need to match the `hostname` option in the command below, or the ingress controller will fail to provision the site for Rancher.
|
Create Kubernetes secrets from your own certificates for Rancher to use. The common name for the cert will need to match the `hostname` option in the command below, or the ingress controller will fail to provision the site for Rancher.
|
||||||
|
|
||||||
@@ -174,7 +176,7 @@ If you are using a Private CA signed cert, add `--set privateCA=true` following
|
|||||||
|
|
||||||
Then refer to [Adding TLS Secrets]({{<baseurl>}}/rancher/v2.0-v2.4/en/installation/resources/encryption/tls-secrets/) to publish the certificate files so Rancher and the ingress controller can use them.
|
Then refer to [Adding TLS Secrets]({{<baseurl>}}/rancher/v2.0-v2.4/en/installation/resources/encryption/tls-secrets/) to publish the certificate files so Rancher and the ingress controller can use them.
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
# 4. Install Rancher
|
# 4. Install Rancher
|
||||||
|
|
||||||
@@ -186,7 +188,8 @@ If you choose to use self-signed certificates in [B. Choose your SSL Configurati
|
|||||||
|
|
||||||
### For Self-Signed Certificate Installs, Install Cert-manager
|
### For Self-Signed Certificate Installs, Install Cert-manager
|
||||||
|
|
||||||
{{% accordion id="install-cert-manager" label="Click to expand" %}}
|
<details id="install-cert-manager">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you are using self-signed certificates, install cert-manager:
|
If you are using self-signed certificates, install cert-manager:
|
||||||
|
|
||||||
@@ -208,7 +211,7 @@ kubectl apply -f cert-manager/cert-manager-crd.yaml
|
|||||||
kubectl apply -R -f ./cert-manager
|
kubectl apply -R -f ./cert-manager
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Install Rancher with kubectl
|
### Install Rancher with kubectl
|
||||||
|
|
||||||
@@ -259,7 +262,8 @@ Choose from the following options:
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
||||||
|
|
||||||
@@ -278,11 +282,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
||||||
|
|
||||||
@@ -316,11 +321,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
||||||
|
|
||||||
@@ -349,7 +355,7 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
If you are installing Rancher v2.3.0+, the installation is complete.
|
If you are installing Rancher v2.3.0+, the installation is complete.
|
||||||
|
|
||||||
|
|||||||
+1
-2
@@ -23,8 +23,7 @@ In this command, `<PRIOR_RANCHER_VERSION>` is the version of Rancher you were ru
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<PRIOR_RANCHER_VERSION>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><PRIOR_RANCHER_VERSION></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||

|
|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
| -------------------------- | -------------------------- | ------------------------------------------------------- |
|
| -------------------------- | -------------------------- | ------------------------------------------------------- |
|
||||||
|
|||||||
+24
-16
@@ -41,7 +41,8 @@ docker ps
|
|||||||
|
|
||||||
Write down or copy this information before starting the upgrade.
|
Write down or copy this information before starting the upgrade.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
@@ -83,7 +84,7 @@ During upgrade, you create a copy of the data from your current Rancher containe
|
|||||||
|
|
||||||
# 2. Create a backup tarball
|
# 2. Create a backup tarball
|
||||||
|
|
||||||
1. <a id="tarball"></a>From the data container that you just created (`rancher-data`), create a backup tarball (`rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz`).
|
1. <a id="tarball"></a>From the data container that you just created (<code>rancher-data</code>), create a backup tarball (<code>rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz</code>).
|
||||||
|
|
||||||
This tarball will serve as a rollback point if something goes wrong during upgrade. Use the following command, replacing each placeholder.
|
This tarball will serve as a rollback point if something goes wrong during upgrade. Use the following command, replacing each placeholder.
|
||||||
|
|
||||||
@@ -139,7 +140,8 @@ Select which option you had installed Rancher server
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
||||||
|
|
||||||
@@ -154,11 +156,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
rancher/rancher:<RANCHER_VERSION_TAG>
|
rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
||||||
|
|
||||||
@@ -183,11 +186,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with. Remember to include `--no-cacerts` as an argument to the container to disable the default CA certificate generated by Rancher.
|
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with. Remember to include `--no-cacerts` as an argument to the container to disable the default CA certificate generated by Rancher.
|
||||||
|
|
||||||
@@ -210,11 +214,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
--no-cacerts
|
--no-cacerts
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option D: Let's Encrypt Certificate
|
### Option D: Let's Encrypt Certificate
|
||||||
|
|
||||||
{{% accordion id="option-d" label="Click to expand" %}}
|
<details id="option-d">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
>**Remember:** Let's Encrypt provides rate limits for requesting new certificates. Therefore, limit how often you create or destroy the container. For more information, see [Let's Encrypt documentation on rate limits](https://letsencrypt.org/docs/rate-limits/).
|
>**Remember:** Let's Encrypt provides rate limits for requesting new certificates. Therefore, limit how often you create or destroy the container. For more information, see [Let's Encrypt documentation on rate limits](https://letsencrypt.org/docs/rate-limits/).
|
||||||
|
|
||||||
@@ -238,7 +243,7 @@ docker run -d --volumes-from rancher-data \
|
|||||||
--acme-domain <YOUR.DNS.NAME>
|
--acme-domain <YOUR.DNS.NAME>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
</TabItem>
|
</TabItem>
|
||||||
<TabItem value="Docker Air Gap Upgrade">
|
<TabItem value="Docker Air Gap Upgrade">
|
||||||
@@ -251,7 +256,8 @@ When starting the new Rancher server container, choose from the following option
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
||||||
|
|
||||||
@@ -269,11 +275,12 @@ Placeholder | Description
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
||||||
|
|
||||||
@@ -298,11 +305,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
-e CATTLE_SYSTEM_CATALOG=bundled \ #Available as of v2.3.0, use the packaged Rancher system charts
|
-e CATTLE_SYSTEM_CATALOG=bundled \ #Available as of v2.3.0, use the packaged Rancher system charts
|
||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with.
|
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with.
|
||||||
|
|
||||||
@@ -330,7 +338,7 @@ docker run -d --volumes-from rancher-data \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
</TabItem>
|
</TabItem>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|||||||
+22
-15
@@ -35,7 +35,8 @@ The port requirements differ based on the Rancher server architecture.
|
|||||||
|
|
||||||
### Ports for Rancher Server Nodes on K3s
|
### Ports for Rancher Server Nodes on K3s
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The K3s server needs port 6443 to be accessible by the nodes.
|
The K3s server needs port 6443 to be accessible by the nodes.
|
||||||
|
|
||||||
@@ -66,11 +67,12 @@ The following tables break down the port requirements for inbound and outbound t
|
|||||||
| TCP | 2376 | Any node IP from a node created using Node driver | Docker daemon TLS port used by Docker Machine |
|
| TCP | 2376 | Any node IP from a node created using Node driver | Docker daemon TLS port used by Docker Machine |
|
||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Server Nodes on RKE
|
### Ports for Rancher Server Nodes on RKE
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
Typically Rancher is installed on three RKE nodes that all have the etcd, control plane and worker roles.
|
Typically Rancher is installed on three RKE nodes that all have the etcd, control plane and worker roles.
|
||||||
|
|
||||||
@@ -110,11 +112,12 @@ The following tables break down the port requirements for inbound and outbound t
|
|||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
| TCP | Provider dependent | Port of the Kubernetes API endpoint in hosted cluster | Kubernetes API |
|
| TCP | Provider dependent | Port of the Kubernetes API endpoint in hosted cluster | Kubernetes API |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Server in Docker
|
### Ports for Rancher Server in Docker
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following tables break down the port requirements for Rancher nodes, for inbound and outbound traffic:
|
The following tables break down the port requirements for Rancher nodes, for inbound and outbound traffic:
|
||||||
|
|
||||||
@@ -134,7 +137,7 @@ The following tables break down the port requirements for Rancher nodes, for inb
|
|||||||
| TCP | 2376 | Any node IP from a node created using a node driver | Docker daemon TLS port used by Docker Machine |
|
| TCP | 2376 | Any node IP from a node created using a node driver | Docker daemon TLS port used by Docker Machine |
|
||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
# Downstream Kubernetes Cluster Nodes
|
# Downstream Kubernetes Cluster Nodes
|
||||||
|
|
||||||
@@ -154,7 +157,8 @@ The following diagram depicts the ports that are opened for each [cluster type](
|
|||||||
|
|
||||||
### Ports for Rancher Launched Kubernetes Clusters using Node Pools
|
### Ports for Rancher Launched Kubernetes Clusters using Node Pools
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/rke-clusters/) with nodes created in an [Infrastructure Provider]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/rke-clusters/node-pools/).
|
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/rke-clusters/) with nodes created in an [Infrastructure Provider]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/rke-clusters/node-pools/).
|
||||||
|
|
||||||
@@ -163,38 +167,41 @@ The following table depicts the port requirements for [Rancher Launched Kubernet
|
|||||||
|
|
||||||
{{< ports-iaas-nodes >}}
|
{{< ports-iaas-nodes >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Launched Kubernetes Clusters using Custom Nodes
|
### Ports for Rancher Launched Kubernetes Clusters using Custom Nodes
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/rke-clusters/) with [Custom Nodes]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/rke-clusters/custom-nodes/).
|
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/rke-clusters/) with [Custom Nodes]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/rke-clusters/custom-nodes/).
|
||||||
|
|
||||||
{{< ports-custom-nodes >}}
|
{{< ports-custom-nodes >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Hosted Kubernetes Clusters
|
### Ports for Hosted Kubernetes Clusters
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [hosted clusters]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/hosted-kubernetes-clusters).
|
The following table depicts the port requirements for [hosted clusters]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/hosted-kubernetes-clusters).
|
||||||
|
|
||||||
{{< ports-imported-hosted >}}
|
{{< ports-imported-hosted >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Imported Clusters
|
### Ports for Imported Clusters
|
||||||
|
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [imported clusters]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/imported-clusters/).
|
The following table depicts the port requirements for [imported clusters]({{<baseurl>}}/rancher/v2.0-v2.4/en/cluster-provisioning/imported-clusters/).
|
||||||
|
|
||||||
{{< ports-imported-hosted >}}
|
{{< ports-imported-hosted >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
# Other Port Considerations
|
# Other Port Considerations
|
||||||
@@ -203,7 +210,7 @@ The following table depicts the port requirements for [imported clusters]({{<bas
|
|||||||
|
|
||||||
These ports are typically opened on your Kubernetes nodes, regardless of what type of cluster it is.
|
These ports are typically opened on your Kubernetes nodes, regardless of what type of cluster it is.
|
||||||
|
|
||||||
{{% include file="/rancher/v2.0-v2.4/en/installation/requirements/ports/common-ports-table" %}}
|
{{% include file="/rancher/v2.0-v2.4/en/installation/requirements/ports/common-ports-table</summary>
|
||||||
|
|
||||||
----
|
----
|
||||||
|
|
||||||
|
|||||||
+4
-2
@@ -116,7 +116,9 @@ These requirements apply to a host with a [single-node]({{<baseurl>}}/rancher/v2
|
|||||||
|
|
||||||
### CPU and Memory for Rancher before v2.4.0
|
### CPU and Memory for Rancher before v2.4.0
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
These requirements apply to installing Rancher on an RKE Kubernetes cluster before Rancher v2.4.0:
|
These requirements apply to installing Rancher on an RKE Kubernetes cluster before Rancher v2.4.0:
|
||||||
|
|
||||||
| Deployment Size | Clusters | Nodes | vCPUs | RAM |
|
| Deployment Size | Clusters | Nodes | vCPUs | RAM |
|
||||||
@@ -126,7 +128,7 @@ These requirements apply to installing Rancher on an RKE Kubernetes cluster befo
|
|||||||
| Large | Up to 50 | Up to 500 | 8 | 32 GB |
|
| Large | Up to 50 | Up to 500 | 8 | 32 GB |
|
||||||
| X-Large | Up to 100 | Up to 1000 | 32 | 128 GB |
|
| X-Large | Up to 100 | Up to 1000 | 32 | 128 GB |
|
||||||
| XX-Large | 100+ | 1000+ | [Contact Rancher](https://rancher.com/contact/) | [Contact Rancher](https://rancher.com/contact/) |
|
| XX-Large | 100+ | 1000+ | [Contact Rancher](https://rancher.com/contact/) | [Contact Rancher](https://rancher.com/contact/) |
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Disks
|
### Disks
|
||||||
|
|
||||||
|
|||||||
+21
-15
@@ -61,8 +61,8 @@ When Rancher is installed on an air gapped Kubernetes cluster, there are two rec
|
|||||||
|
|
||||||
| Configuration | Chart option | Description | Requires cert-manager |
|
| Configuration | Chart option | Description | Requires cert-manager |
|
||||||
| ------------------------------------------ | ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- |
|
| ------------------------------------------ | ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- |
|
||||||
| Rancher Generated Self-Signed Certificates | `ingress.tls.source=rancher` | Use certificates issued by Rancher's generated CA (self signed)<br> This is the **default** and does not need to be added when rendering the Helm template. | yes |
|
| Rancher Generated Self-Signed Certificates | `ingress.tls.source=rancher` | Use certificates issued by Rancher's generated CA (self signed)<br/> This is the **default** and does not need to be added when rendering the Helm template. | yes |
|
||||||
| Certificates from Files | `ingress.tls.source=secret` | Use your own certificate files by creating Kubernetes Secret(s). <br> This option must be passed when rendering the Rancher Helm template. | no |
|
| Certificates from Files | `ingress.tls.source=secret` | Use your own certificate files by creating Kubernetes Secret(s). <br/> This option must be passed when rendering the Rancher Helm template. | no |
|
||||||
|
|
||||||
### C. Render the Rancher Helm Template
|
### C. Render the Rancher Helm Template
|
||||||
|
|
||||||
@@ -70,13 +70,14 @@ When setting up the Rancher Helm template, there are several options in the Helm
|
|||||||
|
|
||||||
| Chart Option | Chart Value | Description |
|
| Chart Option | Chart Value | Description |
|
||||||
| ----------------------- | -------------------------------- | ---- |
|
| ----------------------- | -------------------------------- | ---- |
|
||||||
| `certmanager.version` | "<version>" | Configure proper Rancher TLS issuer depending of running cert-manager version. |
|
| `certmanager.version` | `<version>` | Configure proper Rancher TLS issuer depending of running cert-manager version. |
|
||||||
| `systemDefaultRegistry` | `<REGISTRY.YOURDOMAIN.COM:PORT>` | Configure Rancher server to always pull from your private registry when provisioning clusters. |
|
| `systemDefaultRegistry` | `<REGISTRY.YOURDOMAIN.COM:PORT>` | Configure Rancher server to always pull from your private registry when provisioning clusters. |
|
||||||
| `useBundledSystemChart` | `true` | Configure Rancher server to use the packaged copy of Helm system charts. The [system charts](https://github.com/rancher/system-charts) repository contains all the catalog items required for features such as monitoring, logging, alerting and global DNS. These [Helm charts](https://github.com/rancher/system-charts) are located in GitHub, but since you are in an air gapped environment, using the charts that are bundled within Rancher is much easier than setting up a Git mirror. _Available as of v2.3.0_ |
|
| `useBundledSystemChart` | `true` | Configure Rancher server to use the packaged copy of Helm system charts. The [system charts](https://github.com/rancher/system-charts) repository contains all the catalog items required for features such as monitoring, logging, alerting and global DNS. These [Helm charts](https://github.com/rancher/system-charts) are located in GitHub, but since you are in an air gapped environment, using the charts that are bundled within Rancher is much easier than setting up a Git mirror. _Available as of v2.3.0_ |
|
||||||
|
|
||||||
Based on the choice your made in [B. Choose your SSL Configuration](#b-choose-your-ssl-configuration), complete one of the procedures below.
|
Based on the choice your made in [B. Choose your SSL Configuration](#b-choose-your-ssl-configuration), complete one of the procedures below.
|
||||||
|
|
||||||
{{% accordion id="self-signed" label="Option A-Default Self-Signed Certificate" %}}
|
<details id="self-signed">
|
||||||
|
<summary>Option A-Default Self-Signed Certificate</summary>
|
||||||
|
|
||||||
By default, Rancher generates a CA and uses cert-manager to issue the certificate for access to the Rancher server interface.
|
By default, Rancher generates a CA and uses cert-manager to issue the certificate for access to the Rancher server interface.
|
||||||
|
|
||||||
@@ -129,9 +130,10 @@ By default, Rancher generates a CA and uses cert-manager to issue the certificat
|
|||||||
--set useBundledSystemChart=true # Available as of v2.3.0, use the packaged Rancher system charts
|
--set useBundledSystemChart=true # Available as of v2.3.0, use the packaged Rancher system charts
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
{{% accordion id="secret" label="Option B: Certificates From Files using Kubernetes Secrets" %}}
|
<details id="secret">
|
||||||
|
<summary>Option B: Certificates From Files using Kubernetes Secrets</summary>
|
||||||
|
|
||||||
Create Kubernetes secrets from your own certificates for Rancher to use. The common name for the cert will need to match the `hostname` option in the command below, or the ingress controller will fail to provision the site for Rancher.
|
Create Kubernetes secrets from your own certificates for Rancher to use. The common name for the cert will need to match the `hostname` option in the command below, or the ingress controller will fail to provision the site for Rancher.
|
||||||
|
|
||||||
@@ -170,7 +172,7 @@ If you are using a Private CA signed cert, add `--set privateCA=true` following
|
|||||||
|
|
||||||
Then refer to [Adding TLS Secrets]({{<baseurl>}}/rancher/v2.0-v2.4/en/installation/resources/tls-secrets/) to publish the certificate files so Rancher and the ingress controller can use them.
|
Then refer to [Adding TLS Secrets]({{<baseurl>}}/rancher/v2.0-v2.4/en/installation/resources/tls-secrets/) to publish the certificate files so Rancher and the ingress controller can use them.
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### D. Install Rancher
|
### D. Install Rancher
|
||||||
|
|
||||||
@@ -180,7 +182,8 @@ Use `kubectl` to create namespaces and apply the rendered manifests.
|
|||||||
|
|
||||||
If you choose to use self-signed certificates in [B. Choose your SSL Configuration](#b-choose-your-ssl-configuration), install cert-manager.
|
If you choose to use self-signed certificates in [B. Choose your SSL Configuration](#b-choose-your-ssl-configuration), install cert-manager.
|
||||||
|
|
||||||
{{% accordion id="install-cert-manager" label="Self-Signed Certificate Installs - Install Cert-manager" %}}
|
<details id="install-cert-manager">
|
||||||
|
<summary>Self-Signed Certificate Installs - Install Cert-manager</summary>
|
||||||
|
|
||||||
If you are using self-signed certificates, install cert-manager:
|
If you are using self-signed certificates, install cert-manager:
|
||||||
|
|
||||||
@@ -202,7 +205,7 @@ kubectl apply -f cert-manager/cert-manager-crd.yaml
|
|||||||
kubectl apply -R -f ./cert-manager
|
kubectl apply -R -f ./cert-manager
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
Install Rancher:
|
Install Rancher:
|
||||||
|
|
||||||
@@ -246,7 +249,8 @@ For security purposes, SSL (Secure Sockets Layer) is required when using Rancher
|
|||||||
|
|
||||||
Choose from the following options:
|
Choose from the following options:
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Option A-Default Self-Signed Certificate" %}}
|
<details id="option-a">
|
||||||
|
<summary>Option A-Default Self-Signed Certificate</summary>
|
||||||
|
|
||||||
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
||||||
|
|
||||||
@@ -265,8 +269,9 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="option-b" label="Option B-Bring Your Own Certificate: Self-Signed" %}}
|
<details id="option-b">
|
||||||
|
<summary>Option B-Bring Your Own Certificate: Self-Signed</summary>
|
||||||
|
|
||||||
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
||||||
|
|
||||||
@@ -298,8 +303,9 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="option-c" label="Option C-Bring Your Own Certificate: Signed by Recognized CA" %}}
|
<details id="option-c">
|
||||||
|
<summary>Option C-Bring Your Own Certificate: Signed by Recognized CA</summary>
|
||||||
|
|
||||||
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
||||||
|
|
||||||
@@ -328,7 +334,7 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
If you are installing Rancher v2.3.0+, the installation is complete.
|
If you are installing Rancher v2.3.0+, the installation is complete.
|
||||||
|
|
||||||
|
|||||||
+15
-13
@@ -29,9 +29,9 @@ By default, we provide the steps of how to populate your private registry assumi
|
|||||||
|
|
||||||
For Rancher servers that will only provision Linux clusters, these are the steps to populate your private registry.
|
For Rancher servers that will only provision Linux clusters, these are the steps to populate your private registry.
|
||||||
|
|
||||||
A. Find the required assets for your Rancher version <br>
|
A. Find the required assets for your Rancher version <br/>
|
||||||
B. Collect all the required images <br>
|
B. Collect all the required images <br/>
|
||||||
C. Save the images to your workstation <br>
|
C. Save the images to your workstation <br/>
|
||||||
D. Populate the private registry
|
D. Populate the private registry
|
||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
@@ -115,12 +115,13 @@ For Rancher servers that will provision Linux and Windows clusters, there are di
|
|||||||
|
|
||||||
The Windows images need to be collected and pushed from a Windows server workstation.
|
The Windows images need to be collected and pushed from a Windows server workstation.
|
||||||
|
|
||||||
A. Find the required assets for your Rancher version <br>
|
A. Find the required assets for your Rancher version <br/>
|
||||||
B. Save the images to your Windows Server workstation <br>
|
B. Save the images to your Windows Server workstation <br/>
|
||||||
C. Prepare the Docker daemon <br>
|
C. Prepare the Docker daemon <br/>
|
||||||
D. Populate the private registry
|
D. Populate the private registry
|
||||||
|
|
||||||
{{% accordion label="Collecting and Populating Windows Images into the Private Registry"%}}
|
<details>
|
||||||
|
<summary>Collecting and Populating Windows Images into the Private Registry"%}}
|
||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
@@ -183,18 +184,19 @@ Move the images in the `rancher-windows-images.tar.gz` to your private registry
|
|||||||
./rancher-load-images.ps1 --registry <REGISTRY.YOURDOMAIN.COM:PORT>
|
./rancher-load-images.ps1 --registry <REGISTRY.YOURDOMAIN.COM:PORT>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Linux Steps
|
### Linux Steps
|
||||||
|
|
||||||
The Linux images needs to be collected and pushed from a Linux host, but _must be done after_ populating the Windows images into the private registry. These step are different from the Linux only steps as the Linux images that are pushed will actually manifests that support Windows and Linux images.
|
The Linux images needs to be collected and pushed from a Linux host, but _must be done after_ populating the Windows images into the private registry. These step are different from the Linux only steps as the Linux images that are pushed will actually manifests that support Windows and Linux images.
|
||||||
|
|
||||||
A. Find the required assets for your Rancher version <br>
|
A. Find the required assets for your Rancher version <br/>
|
||||||
B. Collect all the required images <br>
|
B. Collect all the required images <br/>
|
||||||
C. Save the images to your Linux workstation <br>
|
C. Save the images to your Linux workstation <br/>
|
||||||
D. Populate the private registry
|
D. Populate the private registry
|
||||||
|
|
||||||
{{% accordion label="Collecting and Populating Linux Images into the Private Registry" %}}
|
<details>
|
||||||
|
<summary>Collecting and Populating Linux Images into the Private Registry</summary>
|
||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
@@ -270,7 +272,7 @@ Move the images in the `rancher-images.tar.gz` to your private registry using th
|
|||||||
--registry <REGISTRY.YOURDOMAIN.COM:PORT>
|
--registry <REGISTRY.YOURDOMAIN.COM:PORT>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
</TabItem>
|
</TabItem>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|||||||
+6
-4
@@ -220,7 +220,8 @@ For security purposes, SSL (Secure Sockets Layer) is required when using Rancher
|
|||||||
|
|
||||||
Choose from the following options:
|
Choose from the following options:
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Option A—Bring Your Own Certificate: Self-Signed" %}}
|
<details id="option-a">
|
||||||
|
<summary>Option A—Bring Your Own Certificate: Self-Signed</summary>
|
||||||
|
|
||||||
>**Prerequisites:**
|
>**Prerequisites:**
|
||||||
>Create a self-signed certificate.
|
>Create a self-signed certificate.
|
||||||
@@ -272,9 +273,10 @@ Choose from the following options:
|
|||||||
cacerts.pem: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNvRENDQVlnQ0NRRHVVWjZuMEZWeU16QU5CZ2txaGtpRzl3MEJBUXNGQURBU01SQXdEZ1lEVlFRRERBZDAKWlhOMExXTmhNQjRYRFRFNE1EVXdOakl4TURRd09Wb1hEVEU0TURjd05USXhNRFF3T1Zvd0VqRVFNQTRHQTFVRQpBd3dIZEdWemRDMWpZVENDQVNJd0RRWUpLb1pJaHZjTkFRRUJCUUFEZ2dFUEFEQ0NBUW9DZ2dFQkFNQmpBS3dQCndhRUhwQTdaRW1iWWczaTNYNlppVmtGZFJGckJlTmFYTHFPL2R0RUdmWktqYUF0Wm45R1VsckQxZUlUS3UzVHgKOWlGVlV4Mmo1Z0tyWmpwWitCUnFiZ1BNbk5hS1hocmRTdDRtUUN0VFFZdGRYMVFZS0pUbWF5NU45N3FoNTZtWQprMllKRkpOWVhHWlJabkdMUXJQNk04VHZramF0ZnZOdmJ0WmtkY2orYlY3aWhXanp2d2theHRUVjZlUGxuM2p5CnJUeXBBTDliYnlVcHlad3E2MWQvb0Q4VUtwZ2lZM1dOWmN1YnNvSjhxWlRsTnN6UjVadEFJV0tjSE5ZbE93d2oKaG41RE1tSFpwZ0ZGNW14TU52akxPRUc0S0ZRU3laYlV2QzlZRUhLZTUxbGVxa1lmQmtBZWpPY002TnlWQUh1dApuay9DMHpXcGdENkIwbkVDQXdFQUFUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUFHTCtaNkRzK2R4WTZsU2VBClZHSkMvdzE1bHJ2ZXdia1YxN3hvcmlyNEMxVURJSXB6YXdCdFJRSGdSWXVtblVqOGo4T0hFWUFDUEthR3BTVUsKRDVuVWdzV0pMUUV0TDA2eTh6M3A0MDBrSlZFZW9xZlVnYjQrK1JLRVJrWmowWXR3NEN0WHhwOVMzVkd4NmNOQQozZVlqRnRQd2hoYWVEQmdma1hXQWtISXFDcEsrN3RYem9pRGpXbi8walI2VDcrSGlaNEZjZ1AzYnd3K3NjUDIyCjlDQVZ1ZFg4TWpEQ1hTcll0Y0ZINllBanlCSTJjbDhoSkJqa2E3aERpVC9DaFlEZlFFVFZDM3crQjBDYjF1NWcKdE03Z2NGcUw4OVdhMnp5UzdNdXk5bEthUDBvTXl1Ty82Tm1wNjNsVnRHeEZKSFh4WTN6M0lycGxlbTNZQThpTwpmbmlYZXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
cacerts.pem: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNvRENDQVlnQ0NRRHVVWjZuMEZWeU16QU5CZ2txaGtpRzl3MEJBUXNGQURBU01SQXdEZ1lEVlFRRERBZDAKWlhOMExXTmhNQjRYRFRFNE1EVXdOakl4TURRd09Wb1hEVEU0TURjd05USXhNRFF3T1Zvd0VqRVFNQTRHQTFVRQpBd3dIZEdWemRDMWpZVENDQVNJd0RRWUpLb1pJaHZjTkFRRUJCUUFEZ2dFUEFEQ0NBUW9DZ2dFQkFNQmpBS3dQCndhRUhwQTdaRW1iWWczaTNYNlppVmtGZFJGckJlTmFYTHFPL2R0RUdmWktqYUF0Wm45R1VsckQxZUlUS3UzVHgKOWlGVlV4Mmo1Z0tyWmpwWitCUnFiZ1BNbk5hS1hocmRTdDRtUUN0VFFZdGRYMVFZS0pUbWF5NU45N3FoNTZtWQprMllKRkpOWVhHWlJabkdMUXJQNk04VHZramF0ZnZOdmJ0WmtkY2orYlY3aWhXanp2d2theHRUVjZlUGxuM2p5CnJUeXBBTDliYnlVcHlad3E2MWQvb0Q4VUtwZ2lZM1dOWmN1YnNvSjhxWlRsTnN6UjVadEFJV0tjSE5ZbE93d2oKaG41RE1tSFpwZ0ZGNW14TU52akxPRUc0S0ZRU3laYlV2QzlZRUhLZTUxbGVxa1lmQmtBZWpPY002TnlWQUh1dApuay9DMHpXcGdENkIwbkVDQXdFQUFUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUFHTCtaNkRzK2R4WTZsU2VBClZHSkMvdzE1bHJ2ZXdia1YxN3hvcmlyNEMxVURJSXB6YXdCdFJRSGdSWXVtblVqOGo4T0hFWUFDUEthR3BTVUsKRDVuVWdzV0pMUUV0TDA2eTh6M3A0MDBrSlZFZW9xZlVnYjQrK1JLRVJrWmowWXR3NEN0WHhwOVMzVkd4NmNOQQozZVlqRnRQd2hoYWVEQmdma1hXQWtISXFDcEsrN3RYem9pRGpXbi8walI2VDcrSGlaNEZjZ1AzYnd3K3NjUDIyCjlDQVZ1ZFg4TWpEQ1hTcll0Y0ZINllBanlCSTJjbDhoSkJqa2E3aERpVC9DaFlEZlFFVFZDM3crQjBDYjF1NWcKdE03Z2NGcUw4OVdhMnp5UzdNdXk5bEthUDBvTXl1Ty82Tm1wNjNsVnRHeEZKSFh4WTN6M0lycGxlbTNZQThpTwpmbmlYZXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Option B—Bring Your Own Certificate: Signed by Recognized CA" %}}
|
<details id="option-b">
|
||||||
|
<summary>Option B—Bring Your Own Certificate: Signed by Recognized CA</summary>
|
||||||
|
|
||||||
If you are using a Certificate Signed By A Recognized Certificate Authority, you will need to generate a base64 encoded string for the Certificate file and the Certificate Key file. Make sure that your certificate file includes all the intermediate certificates in the chain, the order of certificates in this case is first your own certificate, followed by the intermediates. Please refer to the documentation of your CSP (Certificate Service Provider) to see what intermediate certificate(s) need to be included.
|
If you are using a Certificate Signed By A Recognized Certificate Authority, you will need to generate a base64 encoded string for the Certificate file and the Certificate Key file. Make sure that your certificate file includes all the intermediate certificates in the chain, the order of certificates in this case is first your own certificate, followed by the intermediates. Please refer to the documentation of your CSP (Certificate Service Provider) to see what intermediate certificate(s) need to be included.
|
||||||
|
|
||||||
@@ -301,7 +303,7 @@ data:
|
|||||||
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb3dJQkFBS0NBUUVBdEY3WEN6TVZHaDF1aU5oWTBJZW50RVlpSVFmUUlLQkMvYUFzU3gxQUlsOWI0OUQ5ClhmanEzdWI3c3RCNnRsYTlqV09keDZkZzBnZDBCSVNCSWFlcHJWdkZNZzRTRXpjRE51aW0xZnh3aVkwZCtFRlUKTXVCc3NYZEV6V0k3ZEVvdUFjcVJjamZWL0J5WTZ4ZDdTRWhjSE5PZVdEZWI5TDFiK3hLd2k2M21uZ0lKQjdBeQpLSmRlYzhnbWlaNk4wcTV3ZXFEWDJ6QVgrbDVPTldTcG1mWUVhVHBDSnFMVTNtZFpCWWx5cnhMTytvemx0MGdLCktLbG81cGgzc05CcDFMUG5LOUMxc3MvbWZRek9EMDNzck1Xa21oTDcwQ0IxZmIydCtOWnRITW5BYmYwYkJETnoKTlNRcXU4T2cwaUxnOUVhd3l1dEF4U3BGdmhHUGMvd0dHMExWaXdJREFRQUJBb0lCQUJKYUErOHp4MVhjNEw0egpwUFd5bDdHVDRTMFRLbTNuWUdtRnZudjJBZXg5WDFBU2wzVFVPckZyTnZpK2xYMnYzYUZoSFZDUEN4N1RlMDVxClhPa2JzZnZkZG5iZFQ2RjgyMnJleVByRXNINk9TUnBWSzBmeDVaMDQwVnRFUDJCWm04eTYyNG1QZk1vbDdya2MKcm9Kd09rOEVpUHZZekpsZUd0bTAwUm1sRysyL2c0aWJsOTVmQXpyc1MvcGUyS3ZoN2NBVEtIcVh6MjlpUmZpbApiTGhBamQwcEVSMjNYU0hHR1ZqRmF3amNJK1c2L2RtbDZURDhrSzFGaUtldmJKTlREeVNXQnpPbXRTYUp1K01JCm9iUnVWWG4yZVNoamVGM1BYcHZRMWRhNXdBa0dJQWxOWjRHTG5QU2ZwVmJyU0plU3RrTGNzdEJheVlJS3BWZVgKSVVTTHM0RUNnWUVBMmNnZUE2WHh0TXdFNU5QWlNWdGhzbXRiYi9YYmtsSTdrWHlsdk5zZjFPdXRYVzkybVJneQpHcEhUQ0VubDB0Z1p3T081T1FLNjdFT3JUdDBRWStxMDJzZndwcmgwNFZEVGZhcW5QNTBxa3BmZEJLQWpmanEyCjFoZDZMd2hLeDRxSm9aelp2VkowV0lvR1ZLcjhJSjJOWGRTUVlUanZUZHhGczRTamdqNFFiaEVDZ1lFQTFBWUUKSEo3eVlza2EvS2V2OVVYbmVrSTRvMm5aYjJ1UVZXazRXSHlaY2NRN3VMQVhGY3lJcW5SZnoxczVzN3RMTzJCagozTFZNUVBzazFNY25oTTl4WE4vQ3ZDTys5b2t0RnNaMGJqWFh6NEJ5V2lFNHJPS1lhVEFwcDVsWlpUT3ZVMWNyCm05R3NwMWJoVDVZb2RaZ3IwUHQyYzR4U2krUVlEWnNFb2lFdzNkc0NnWUVBcVJLYWNweWZKSXlMZEJjZ0JycGkKQTRFalVLMWZsSjR3enNjbGFKUDVoM1NjZUFCejQzRU1YT0kvSXAwMFJsY3N6em83N3cyMmpud09mOEJSM0RBMwp6ZTRSWDIydWw4b0hGdldvdUZOTTNOZjNaNExuYXpVc0F0UGhNS2hRWGMrcEFBWGthUDJkZzZ0TU5PazFxaUNHCndvU212a1BVVE84b1ViRTB1NFZ4ZmZFQ2dZQUpPdDNROVNadUlIMFpSSitIV095enlOQTRaUEkvUkhwN0RXS1QKajVFS2Y5VnR1OVMxY1RyOTJLVVhITXlOUTNrSjg2OUZPMnMvWk85OGg5THptQ2hDTjhkOWN6enI5SnJPNUFMTApqWEtBcVFIUlpLTFgrK0ZRcXZVVlE3cTlpaHQyMEZPb3E5OE5SZDMzSGYxUzZUWDNHZ3RWQ21YSml6dDAxQ3ZHCmR4VnVnd0tCZ0M2Mlp0b0RLb3JyT2hvdTBPelprK2YwQS9rNDJBOENiL29VMGpwSzZtdmxEWmNYdUF1QVZTVXIKNXJCZjRVYmdVYndqa1ZWSFR6LzdDb1BWSjUvVUxJWk1Db1RUNFprNTZXWDk4ZE93Q3VTVFpZYnlBbDZNS1BBZApTZEpuVVIraEpnSVFDVGJ4K1dzYnh2d0FkbWErWUhtaVlPRzZhSklXMXdSd1VGOURLUEhHCi0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg==
|
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb3dJQkFBS0NBUUVBdEY3WEN6TVZHaDF1aU5oWTBJZW50RVlpSVFmUUlLQkMvYUFzU3gxQUlsOWI0OUQ5ClhmanEzdWI3c3RCNnRsYTlqV09keDZkZzBnZDBCSVNCSWFlcHJWdkZNZzRTRXpjRE51aW0xZnh3aVkwZCtFRlUKTXVCc3NYZEV6V0k3ZEVvdUFjcVJjamZWL0J5WTZ4ZDdTRWhjSE5PZVdEZWI5TDFiK3hLd2k2M21uZ0lKQjdBeQpLSmRlYzhnbWlaNk4wcTV3ZXFEWDJ6QVgrbDVPTldTcG1mWUVhVHBDSnFMVTNtZFpCWWx5cnhMTytvemx0MGdLCktLbG81cGgzc05CcDFMUG5LOUMxc3MvbWZRek9EMDNzck1Xa21oTDcwQ0IxZmIydCtOWnRITW5BYmYwYkJETnoKTlNRcXU4T2cwaUxnOUVhd3l1dEF4U3BGdmhHUGMvd0dHMExWaXdJREFRQUJBb0lCQUJKYUErOHp4MVhjNEw0egpwUFd5bDdHVDRTMFRLbTNuWUdtRnZudjJBZXg5WDFBU2wzVFVPckZyTnZpK2xYMnYzYUZoSFZDUEN4N1RlMDVxClhPa2JzZnZkZG5iZFQ2RjgyMnJleVByRXNINk9TUnBWSzBmeDVaMDQwVnRFUDJCWm04eTYyNG1QZk1vbDdya2MKcm9Kd09rOEVpUHZZekpsZUd0bTAwUm1sRysyL2c0aWJsOTVmQXpyc1MvcGUyS3ZoN2NBVEtIcVh6MjlpUmZpbApiTGhBamQwcEVSMjNYU0hHR1ZqRmF3amNJK1c2L2RtbDZURDhrSzFGaUtldmJKTlREeVNXQnpPbXRTYUp1K01JCm9iUnVWWG4yZVNoamVGM1BYcHZRMWRhNXdBa0dJQWxOWjRHTG5QU2ZwVmJyU0plU3RrTGNzdEJheVlJS3BWZVgKSVVTTHM0RUNnWUVBMmNnZUE2WHh0TXdFNU5QWlNWdGhzbXRiYi9YYmtsSTdrWHlsdk5zZjFPdXRYVzkybVJneQpHcEhUQ0VubDB0Z1p3T081T1FLNjdFT3JUdDBRWStxMDJzZndwcmgwNFZEVGZhcW5QNTBxa3BmZEJLQWpmanEyCjFoZDZMd2hLeDRxSm9aelp2VkowV0lvR1ZLcjhJSjJOWGRTUVlUanZUZHhGczRTamdqNFFiaEVDZ1lFQTFBWUUKSEo3eVlza2EvS2V2OVVYbmVrSTRvMm5aYjJ1UVZXazRXSHlaY2NRN3VMQVhGY3lJcW5SZnoxczVzN3RMTzJCagozTFZNUVBzazFNY25oTTl4WE4vQ3ZDTys5b2t0RnNaMGJqWFh6NEJ5V2lFNHJPS1lhVEFwcDVsWlpUT3ZVMWNyCm05R3NwMWJoVDVZb2RaZ3IwUHQyYzR4U2krUVlEWnNFb2lFdzNkc0NnWUVBcVJLYWNweWZKSXlMZEJjZ0JycGkKQTRFalVLMWZsSjR3enNjbGFKUDVoM1NjZUFCejQzRU1YT0kvSXAwMFJsY3N6em83N3cyMmpud09mOEJSM0RBMwp6ZTRSWDIydWw4b0hGdldvdUZOTTNOZjNaNExuYXpVc0F0UGhNS2hRWGMrcEFBWGthUDJkZzZ0TU5PazFxaUNHCndvU212a1BVVE84b1ViRTB1NFZ4ZmZFQ2dZQUpPdDNROVNadUlIMFpSSitIV095enlOQTRaUEkvUkhwN0RXS1QKajVFS2Y5VnR1OVMxY1RyOTJLVVhITXlOUTNrSjg2OUZPMnMvWk85OGg5THptQ2hDTjhkOWN6enI5SnJPNUFMTApqWEtBcVFIUlpLTFgrK0ZRcXZVVlE3cTlpaHQyMEZPb3E5OE5SZDMzSGYxUzZUWDNHZ3RWQ21YSml6dDAxQ3ZHCmR4VnVnd0tCZ0M2Mlp0b0RLb3JyT2hvdTBPelprK2YwQS9rNDJBOENiL29VMGpwSzZtdmxEWmNYdUF1QVZTVXIKNXJCZjRVYmdVYndqa1ZWSFR6LzdDb1BWSjUvVUxJWk1Db1RUNFprNTZXWDk4ZE93Q3VTVFpZYnlBbDZNS1BBZApTZEpuVVIraEpnSVFDVGJ4K1dzYnh2d0FkbWErWUhtaVlPRzZhSklXMXdSd1VGOURLUEhHCi0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg==
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+8
-4
@@ -169,7 +169,9 @@ For security purposes, SSL (Secure Sockets Layer) is required when using Rancher
|
|||||||
|
|
||||||
Choose from the following options:
|
Choose from the following options:
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Option A—Bring Your Own Certificate: Self-Signed" %}}
|
<details id="option-a">
|
||||||
|
<summary>Option A—Bring Your Own Certificate: Self-Signed</summary>
|
||||||
|
|
||||||
>**Prerequisites:**
|
>**Prerequisites:**
|
||||||
>Create a self-signed certificate.
|
>Create a self-signed certificate.
|
||||||
>
|
>
|
||||||
@@ -193,10 +195,12 @@ After replacing the values, the file should look like the example below (the bas
|
|||||||
data:
|
data:
|
||||||
cacerts.pem: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNvRENDQVlnQ0NRRHVVWjZuMEZWeU16QU5CZ2txaGtpRzl3MEJBUXNGQURBU01SQXdEZ1lEVlFRRERBZDAKWlhOMExXTmhNQjRYRFRFNE1EVXdOakl4TURRd09Wb1hEVEU0TURjd05USXhNRFF3T1Zvd0VqRVFNQTRHQTFVRQpBd3dIZEdWemRDMWpZVENDQVNJd0RRWUpLb1pJaHZjTkFRRUJCUUFEZ2dFUEFEQ0NBUW9DZ2dFQkFNQmpBS3dQCndhRUhwQTdaRW1iWWczaTNYNlppVmtGZFJGckJlTmFYTHFPL2R0RUdmWktqYUF0Wm45R1VsckQxZUlUS3UzVHgKOWlGVlV4Mmo1Z0tyWmpwWitCUnFiZ1BNbk5hS1hocmRTdDRtUUN0VFFZdGRYMVFZS0pUbWF5NU45N3FoNTZtWQprMllKRkpOWVhHWlJabkdMUXJQNk04VHZramF0ZnZOdmJ0WmtkY2orYlY3aWhXanp2d2theHRUVjZlUGxuM2p5CnJUeXBBTDliYnlVcHlad3E2MWQvb0Q4VUtwZ2lZM1dOWmN1YnNvSjhxWlRsTnN6UjVadEFJV0tjSE5ZbE93d2oKaG41RE1tSFpwZ0ZGNW14TU52akxPRUc0S0ZRU3laYlV2QzlZRUhLZTUxbGVxa1lmQmtBZWpPY002TnlWQUh1dApuay9DMHpXcGdENkIwbkVDQXdFQUFUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUFHTCtaNkRzK2R4WTZsU2VBClZHSkMvdzE1bHJ2ZXdia1YxN3hvcmlyNEMxVURJSXB6YXdCdFJRSGdSWXVtblVqOGo4T0hFWUFDUEthR3BTVUsKRDVuVWdzV0pMUUV0TDA2eTh6M3A0MDBrSlZFZW9xZlVnYjQrK1JLRVJrWmowWXR3NEN0WHhwOVMzVkd4NmNOQQozZVlqRnRQd2hoYWVEQmdma1hXQWtISXFDcEsrN3RYem9pRGpXbi8walI2VDcrSGlaNEZjZ1AzYnd3K3NjUDIyCjlDQVZ1ZFg4TWpEQ1hTcll0Y0ZINllBanlCSTJjbDhoSkJqa2E3aERpVC9DaFlEZlFFVFZDM3crQjBDYjF1NWcKdE03Z2NGcUw4OVdhMnp5UzdNdXk5bEthUDBvTXl1Ty82Tm1wNjNsVnRHeEZKSFh4WTN6M0lycGxlbTNZQThpTwpmbmlYZXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
cacerts.pem: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNvRENDQVlnQ0NRRHVVWjZuMEZWeU16QU5CZ2txaGtpRzl3MEJBUXNGQURBU01SQXdEZ1lEVlFRRERBZDAKWlhOMExXTmhNQjRYRFRFNE1EVXdOakl4TURRd09Wb1hEVEU0TURjd05USXhNRFF3T1Zvd0VqRVFNQTRHQTFVRQpBd3dIZEdWemRDMWpZVENDQVNJd0RRWUpLb1pJaHZjTkFRRUJCUUFEZ2dFUEFEQ0NBUW9DZ2dFQkFNQmpBS3dQCndhRUhwQTdaRW1iWWczaTNYNlppVmtGZFJGckJlTmFYTHFPL2R0RUdmWktqYUF0Wm45R1VsckQxZUlUS3UzVHgKOWlGVlV4Mmo1Z0tyWmpwWitCUnFiZ1BNbk5hS1hocmRTdDRtUUN0VFFZdGRYMVFZS0pUbWF5NU45N3FoNTZtWQprMllKRkpOWVhHWlJabkdMUXJQNk04VHZramF0ZnZOdmJ0WmtkY2orYlY3aWhXanp2d2theHRUVjZlUGxuM2p5CnJUeXBBTDliYnlVcHlad3E2MWQvb0Q4VUtwZ2lZM1dOWmN1YnNvSjhxWlRsTnN6UjVadEFJV0tjSE5ZbE93d2oKaG41RE1tSFpwZ0ZGNW14TU52akxPRUc0S0ZRU3laYlV2QzlZRUhLZTUxbGVxa1lmQmtBZWpPY002TnlWQUh1dApuay9DMHpXcGdENkIwbkVDQXdFQUFUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUFHTCtaNkRzK2R4WTZsU2VBClZHSkMvdzE1bHJ2ZXdia1YxN3hvcmlyNEMxVURJSXB6YXdCdFJRSGdSWXVtblVqOGo4T0hFWUFDUEthR3BTVUsKRDVuVWdzV0pMUUV0TDA2eTh6M3A0MDBrSlZFZW9xZlVnYjQrK1JLRVJrWmowWXR3NEN0WHhwOVMzVkd4NmNOQQozZVlqRnRQd2hoYWVEQmdma1hXQWtISXFDcEsrN3RYem9pRGpXbi8walI2VDcrSGlaNEZjZ1AzYnd3K3NjUDIyCjlDQVZ1ZFg4TWpEQ1hTcll0Y0ZINllBanlCSTJjbDhoSkJqa2E3aERpVC9DaFlEZlFFVFZDM3crQjBDYjF1NWcKdE03Z2NGcUw4OVdhMnp5UzdNdXk5bEthUDBvTXl1Ty82Tm1wNjNsVnRHeEZKSFh4WTN6M0lycGxlbTNZQThpTwpmbmlYZXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="option-b" label="Option B—Bring Your Own Certificate: Signed by Recognized CA" %}}
|
<details id="option-b">
|
||||||
|
<summary>Option B—Bring Your Own Certificate: Signed by Recognized CA</summary>
|
||||||
|
|
||||||
If you are using a Certificate Signed By A Recognized Certificate Authority, you don't need to perform any step in this part.
|
If you are using a Certificate Signed By A Recognized Certificate Authority, you don't need to perform any step in this part.
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
## 8. Configure FQDN
|
## 8. Configure FQDN
|
||||||
|
|
||||||
|
|||||||
+6
-4
@@ -218,7 +218,8 @@ For security purposes, SSL (Secure Sockets Layer) is required when using Rancher
|
|||||||
|
|
||||||
Choose from the following options:
|
Choose from the following options:
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Option A—Bring Your Own Certificate: Self-Signed" %}}
|
<details id="option-a">
|
||||||
|
<summary>Option A—Bring Your Own Certificate: Self-Signed</summary>
|
||||||
|
|
||||||
>**Prerequisites:**
|
>**Prerequisites:**
|
||||||
>Create a self-signed certificate.
|
>Create a self-signed certificate.
|
||||||
@@ -270,9 +271,10 @@ Choose from the following options:
|
|||||||
cacerts.pem: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNvRENDQVlnQ0NRRHVVWjZuMEZWeU16QU5CZ2txaGtpRzl3MEJBUXNGQURBU01SQXdEZ1lEVlFRRERBZDAKWlhOMExXTmhNQjRYRFRFNE1EVXdOakl4TURRd09Wb1hEVEU0TURjd05USXhNRFF3T1Zvd0VqRVFNQTRHQTFVRQpBd3dIZEdWemRDMWpZVENDQVNJd0RRWUpLb1pJaHZjTkFRRUJCUUFEZ2dFUEFEQ0NBUW9DZ2dFQkFNQmpBS3dQCndhRUhwQTdaRW1iWWczaTNYNlppVmtGZFJGckJlTmFYTHFPL2R0RUdmWktqYUF0Wm45R1VsckQxZUlUS3UzVHgKOWlGVlV4Mmo1Z0tyWmpwWitCUnFiZ1BNbk5hS1hocmRTdDRtUUN0VFFZdGRYMVFZS0pUbWF5NU45N3FoNTZtWQprMllKRkpOWVhHWlJabkdMUXJQNk04VHZramF0ZnZOdmJ0WmtkY2orYlY3aWhXanp2d2theHRUVjZlUGxuM2p5CnJUeXBBTDliYnlVcHlad3E2MWQvb0Q4VUtwZ2lZM1dOWmN1YnNvSjhxWlRsTnN6UjVadEFJV0tjSE5ZbE93d2oKaG41RE1tSFpwZ0ZGNW14TU52akxPRUc0S0ZRU3laYlV2QzlZRUhLZTUxbGVxa1lmQmtBZWpPY002TnlWQUh1dApuay9DMHpXcGdENkIwbkVDQXdFQUFUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUFHTCtaNkRzK2R4WTZsU2VBClZHSkMvdzE1bHJ2ZXdia1YxN3hvcmlyNEMxVURJSXB6YXdCdFJRSGdSWXVtblVqOGo4T0hFWUFDUEthR3BTVUsKRDVuVWdzV0pMUUV0TDA2eTh6M3A0MDBrSlZFZW9xZlVnYjQrK1JLRVJrWmowWXR3NEN0WHhwOVMzVkd4NmNOQQozZVlqRnRQd2hoYWVEQmdma1hXQWtISXFDcEsrN3RYem9pRGpXbi8walI2VDcrSGlaNEZjZ1AzYnd3K3NjUDIyCjlDQVZ1ZFg4TWpEQ1hTcll0Y0ZINllBanlCSTJjbDhoSkJqa2E3aERpVC9DaFlEZlFFVFZDM3crQjBDYjF1NWcKdE03Z2NGcUw4OVdhMnp5UzdNdXk5bEthUDBvTXl1Ty82Tm1wNjNsVnRHeEZKSFh4WTN6M0lycGxlbTNZQThpTwpmbmlYZXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
cacerts.pem: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNvRENDQVlnQ0NRRHVVWjZuMEZWeU16QU5CZ2txaGtpRzl3MEJBUXNGQURBU01SQXdEZ1lEVlFRRERBZDAKWlhOMExXTmhNQjRYRFRFNE1EVXdOakl4TURRd09Wb1hEVEU0TURjd05USXhNRFF3T1Zvd0VqRVFNQTRHQTFVRQpBd3dIZEdWemRDMWpZVENDQVNJd0RRWUpLb1pJaHZjTkFRRUJCUUFEZ2dFUEFEQ0NBUW9DZ2dFQkFNQmpBS3dQCndhRUhwQTdaRW1iWWczaTNYNlppVmtGZFJGckJlTmFYTHFPL2R0RUdmWktqYUF0Wm45R1VsckQxZUlUS3UzVHgKOWlGVlV4Mmo1Z0tyWmpwWitCUnFiZ1BNbk5hS1hocmRTdDRtUUN0VFFZdGRYMVFZS0pUbWF5NU45N3FoNTZtWQprMllKRkpOWVhHWlJabkdMUXJQNk04VHZramF0ZnZOdmJ0WmtkY2orYlY3aWhXanp2d2theHRUVjZlUGxuM2p5CnJUeXBBTDliYnlVcHlad3E2MWQvb0Q4VUtwZ2lZM1dOWmN1YnNvSjhxWlRsTnN6UjVadEFJV0tjSE5ZbE93d2oKaG41RE1tSFpwZ0ZGNW14TU52akxPRUc0S0ZRU3laYlV2QzlZRUhLZTUxbGVxa1lmQmtBZWpPY002TnlWQUh1dApuay9DMHpXcGdENkIwbkVDQXdFQUFUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUFHTCtaNkRzK2R4WTZsU2VBClZHSkMvdzE1bHJ2ZXdia1YxN3hvcmlyNEMxVURJSXB6YXdCdFJRSGdSWXVtblVqOGo4T0hFWUFDUEthR3BTVUsKRDVuVWdzV0pMUUV0TDA2eTh6M3A0MDBrSlZFZW9xZlVnYjQrK1JLRVJrWmowWXR3NEN0WHhwOVMzVkd4NmNOQQozZVlqRnRQd2hoYWVEQmdma1hXQWtISXFDcEsrN3RYem9pRGpXbi8walI2VDcrSGlaNEZjZ1AzYnd3K3NjUDIyCjlDQVZ1ZFg4TWpEQ1hTcll0Y0ZINllBanlCSTJjbDhoSkJqa2E3aERpVC9DaFlEZlFFVFZDM3crQjBDYjF1NWcKdE03Z2NGcUw4OVdhMnp5UzdNdXk5bEthUDBvTXl1Ty82Tm1wNjNsVnRHeEZKSFh4WTN6M0lycGxlbTNZQThpTwpmbmlYZXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Option B—Bring Your Own Certificate: Signed by Recognized CA" %}}
|
<details id="option-b">
|
||||||
|
<summary>Option B—Bring Your Own Certificate: Signed by Recognized CA</summary>
|
||||||
|
|
||||||
If you are using a Certificate Signed By A Recognized Certificate Authority, you will need to generate a base64 encoded string for the Certificate file and the Certificate Key file. Make sure that your certificate file includes all the intermediate certificates in the chain, the order of certificates in this case is first your own certificate, followed by the intermediates. Please refer to the documentation of your CSP (Certificate Service Provider) to see what intermediate certificate(s) need to be included.
|
If you are using a Certificate Signed By A Recognized Certificate Authority, you will need to generate a base64 encoded string for the Certificate file and the Certificate Key file. Make sure that your certificate file includes all the intermediate certificates in the chain, the order of certificates in this case is first your own certificate, followed by the intermediates. Please refer to the documentation of your CSP (Certificate Service Provider) to see what intermediate certificate(s) need to be included.
|
||||||
|
|
||||||
@@ -299,7 +301,7 @@ data:
|
|||||||
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb3dJQkFBS0NBUUVBdEY3WEN6TVZHaDF1aU5oWTBJZW50RVlpSVFmUUlLQkMvYUFzU3gxQUlsOWI0OUQ5ClhmanEzdWI3c3RCNnRsYTlqV09keDZkZzBnZDBCSVNCSWFlcHJWdkZNZzRTRXpjRE51aW0xZnh3aVkwZCtFRlUKTXVCc3NYZEV6V0k3ZEVvdUFjcVJjamZWL0J5WTZ4ZDdTRWhjSE5PZVdEZWI5TDFiK3hLd2k2M21uZ0lKQjdBeQpLSmRlYzhnbWlaNk4wcTV3ZXFEWDJ6QVgrbDVPTldTcG1mWUVhVHBDSnFMVTNtZFpCWWx5cnhMTytvemx0MGdLCktLbG81cGgzc05CcDFMUG5LOUMxc3MvbWZRek9EMDNzck1Xa21oTDcwQ0IxZmIydCtOWnRITW5BYmYwYkJETnoKTlNRcXU4T2cwaUxnOUVhd3l1dEF4U3BGdmhHUGMvd0dHMExWaXdJREFRQUJBb0lCQUJKYUErOHp4MVhjNEw0egpwUFd5bDdHVDRTMFRLbTNuWUdtRnZudjJBZXg5WDFBU2wzVFVPckZyTnZpK2xYMnYzYUZoSFZDUEN4N1RlMDVxClhPa2JzZnZkZG5iZFQ2RjgyMnJleVByRXNINk9TUnBWSzBmeDVaMDQwVnRFUDJCWm04eTYyNG1QZk1vbDdya2MKcm9Kd09rOEVpUHZZekpsZUd0bTAwUm1sRysyL2c0aWJsOTVmQXpyc1MvcGUyS3ZoN2NBVEtIcVh6MjlpUmZpbApiTGhBamQwcEVSMjNYU0hHR1ZqRmF3amNJK1c2L2RtbDZURDhrSzFGaUtldmJKTlREeVNXQnpPbXRTYUp1K01JCm9iUnVWWG4yZVNoamVGM1BYcHZRMWRhNXdBa0dJQWxOWjRHTG5QU2ZwVmJyU0plU3RrTGNzdEJheVlJS3BWZVgKSVVTTHM0RUNnWUVBMmNnZUE2WHh0TXdFNU5QWlNWdGhzbXRiYi9YYmtsSTdrWHlsdk5zZjFPdXRYVzkybVJneQpHcEhUQ0VubDB0Z1p3T081T1FLNjdFT3JUdDBRWStxMDJzZndwcmgwNFZEVGZhcW5QNTBxa3BmZEJLQWpmanEyCjFoZDZMd2hLeDRxSm9aelp2VkowV0lvR1ZLcjhJSjJOWGRTUVlUanZUZHhGczRTamdqNFFiaEVDZ1lFQTFBWUUKSEo3eVlza2EvS2V2OVVYbmVrSTRvMm5aYjJ1UVZXazRXSHlaY2NRN3VMQVhGY3lJcW5SZnoxczVzN3RMTzJCagozTFZNUVBzazFNY25oTTl4WE4vQ3ZDTys5b2t0RnNaMGJqWFh6NEJ5V2lFNHJPS1lhVEFwcDVsWlpUT3ZVMWNyCm05R3NwMWJoVDVZb2RaZ3IwUHQyYzR4U2krUVlEWnNFb2lFdzNkc0NnWUVBcVJLYWNweWZKSXlMZEJjZ0JycGkKQTRFalVLMWZsSjR3enNjbGFKUDVoM1NjZUFCejQzRU1YT0kvSXAwMFJsY3N6em83N3cyMmpud09mOEJSM0RBMwp6ZTRSWDIydWw4b0hGdldvdUZOTTNOZjNaNExuYXpVc0F0UGhNS2hRWGMrcEFBWGthUDJkZzZ0TU5PazFxaUNHCndvU212a1BVVE84b1ViRTB1NFZ4ZmZFQ2dZQUpPdDNROVNadUlIMFpSSitIV095enlOQTRaUEkvUkhwN0RXS1QKajVFS2Y5VnR1OVMxY1RyOTJLVVhITXlOUTNrSjg2OUZPMnMvWk85OGg5THptQ2hDTjhkOWN6enI5SnJPNUFMTApqWEtBcVFIUlpLTFgrK0ZRcXZVVlE3cTlpaHQyMEZPb3E5OE5SZDMzSGYxUzZUWDNHZ3RWQ21YSml6dDAxQ3ZHCmR4VnVnd0tCZ0M2Mlp0b0RLb3JyT2hvdTBPelprK2YwQS9rNDJBOENiL29VMGpwSzZtdmxEWmNYdUF1QVZTVXIKNXJCZjRVYmdVYndqa1ZWSFR6LzdDb1BWSjUvVUxJWk1Db1RUNFprNTZXWDk4ZE93Q3VTVFpZYnlBbDZNS1BBZApTZEpuVVIraEpnSVFDVGJ4K1dzYnh2d0FkbWErWUhtaVlPRzZhSklXMXdSd1VGOURLUEhHCi0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg==
|
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb3dJQkFBS0NBUUVBdEY3WEN6TVZHaDF1aU5oWTBJZW50RVlpSVFmUUlLQkMvYUFzU3gxQUlsOWI0OUQ5ClhmanEzdWI3c3RCNnRsYTlqV09keDZkZzBnZDBCSVNCSWFlcHJWdkZNZzRTRXpjRE51aW0xZnh3aVkwZCtFRlUKTXVCc3NYZEV6V0k3ZEVvdUFjcVJjamZWL0J5WTZ4ZDdTRWhjSE5PZVdEZWI5TDFiK3hLd2k2M21uZ0lKQjdBeQpLSmRlYzhnbWlaNk4wcTV3ZXFEWDJ6QVgrbDVPTldTcG1mWUVhVHBDSnFMVTNtZFpCWWx5cnhMTytvemx0MGdLCktLbG81cGgzc05CcDFMUG5LOUMxc3MvbWZRek9EMDNzck1Xa21oTDcwQ0IxZmIydCtOWnRITW5BYmYwYkJETnoKTlNRcXU4T2cwaUxnOUVhd3l1dEF4U3BGdmhHUGMvd0dHMExWaXdJREFRQUJBb0lCQUJKYUErOHp4MVhjNEw0egpwUFd5bDdHVDRTMFRLbTNuWUdtRnZudjJBZXg5WDFBU2wzVFVPckZyTnZpK2xYMnYzYUZoSFZDUEN4N1RlMDVxClhPa2JzZnZkZG5iZFQ2RjgyMnJleVByRXNINk9TUnBWSzBmeDVaMDQwVnRFUDJCWm04eTYyNG1QZk1vbDdya2MKcm9Kd09rOEVpUHZZekpsZUd0bTAwUm1sRysyL2c0aWJsOTVmQXpyc1MvcGUyS3ZoN2NBVEtIcVh6MjlpUmZpbApiTGhBamQwcEVSMjNYU0hHR1ZqRmF3amNJK1c2L2RtbDZURDhrSzFGaUtldmJKTlREeVNXQnpPbXRTYUp1K01JCm9iUnVWWG4yZVNoamVGM1BYcHZRMWRhNXdBa0dJQWxOWjRHTG5QU2ZwVmJyU0plU3RrTGNzdEJheVlJS3BWZVgKSVVTTHM0RUNnWUVBMmNnZUE2WHh0TXdFNU5QWlNWdGhzbXRiYi9YYmtsSTdrWHlsdk5zZjFPdXRYVzkybVJneQpHcEhUQ0VubDB0Z1p3T081T1FLNjdFT3JUdDBRWStxMDJzZndwcmgwNFZEVGZhcW5QNTBxa3BmZEJLQWpmanEyCjFoZDZMd2hLeDRxSm9aelp2VkowV0lvR1ZLcjhJSjJOWGRTUVlUanZUZHhGczRTamdqNFFiaEVDZ1lFQTFBWUUKSEo3eVlza2EvS2V2OVVYbmVrSTRvMm5aYjJ1UVZXazRXSHlaY2NRN3VMQVhGY3lJcW5SZnoxczVzN3RMTzJCagozTFZNUVBzazFNY25oTTl4WE4vQ3ZDTys5b2t0RnNaMGJqWFh6NEJ5V2lFNHJPS1lhVEFwcDVsWlpUT3ZVMWNyCm05R3NwMWJoVDVZb2RaZ3IwUHQyYzR4U2krUVlEWnNFb2lFdzNkc0NnWUVBcVJLYWNweWZKSXlMZEJjZ0JycGkKQTRFalVLMWZsSjR3enNjbGFKUDVoM1NjZUFCejQzRU1YT0kvSXAwMFJsY3N6em83N3cyMmpud09mOEJSM0RBMwp6ZTRSWDIydWw4b0hGdldvdUZOTTNOZjNaNExuYXpVc0F0UGhNS2hRWGMrcEFBWGthUDJkZzZ0TU5PazFxaUNHCndvU212a1BVVE84b1ViRTB1NFZ4ZmZFQ2dZQUpPdDNROVNadUlIMFpSSitIV095enlOQTRaUEkvUkhwN0RXS1QKajVFS2Y5VnR1OVMxY1RyOTJLVVhITXlOUTNrSjg2OUZPMnMvWk85OGg5THptQ2hDTjhkOWN6enI5SnJPNUFMTApqWEtBcVFIUlpLTFgrK0ZRcXZVVlE3cTlpaHQyMEZPb3E5OE5SZDMzSGYxUzZUWDNHZ3RWQ21YSml6dDAxQ3ZHCmR4VnVnd0tCZ0M2Mlp0b0RLb3JyT2hvdTBPelprK2YwQS9rNDJBOENiL29VMGpwSzZtdmxEWmNYdUF1QVZTVXIKNXJCZjRVYmdVYndqa1ZWSFR6LzdDb1BWSjUvVUxJWk1Db1RUNFprNTZXWDk4ZE93Q3VTVFpZYnlBbDZNS1BBZApTZEpuVVIraEpnSVFDVGJ4K1dzYnh2d0FkbWErWUhtaVlPRzZhSklXMXdSd1VGOURLUEhHCi0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg==
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+9
-4
@@ -166,7 +166,9 @@ For security purposes, SSL (Secure Sockets Layer) is required when using Rancher
|
|||||||
|
|
||||||
Choose from the following options:
|
Choose from the following options:
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Option A—Bring Your Own Certificate: Self-Signed" %}}
|
<details id="option-a">
|
||||||
|
<summary>Option A—Bring Your Own Certificate: Self-Signed</summary>
|
||||||
|
|
||||||
>**Prerequisites:**
|
>**Prerequisites:**
|
||||||
>Create a self-signed certificate.
|
>Create a self-signed certificate.
|
||||||
>
|
>
|
||||||
@@ -190,10 +192,13 @@ After replacing the values, the file should look like the example below (the bas
|
|||||||
data:
|
data:
|
||||||
cacerts.pem: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNvRENDQVlnQ0NRRHVVWjZuMEZWeU16QU5CZ2txaGtpRzl3MEJBUXNGQURBU01SQXdEZ1lEVlFRRERBZDAKWlhOMExXTmhNQjRYRFRFNE1EVXdOakl4TURRd09Wb1hEVEU0TURjd05USXhNRFF3T1Zvd0VqRVFNQTRHQTFVRQpBd3dIZEdWemRDMWpZVENDQVNJd0RRWUpLb1pJaHZjTkFRRUJCUUFEZ2dFUEFEQ0NBUW9DZ2dFQkFNQmpBS3dQCndhRUhwQTdaRW1iWWczaTNYNlppVmtGZFJGckJlTmFYTHFPL2R0RUdmWktqYUF0Wm45R1VsckQxZUlUS3UzVHgKOWlGVlV4Mmo1Z0tyWmpwWitCUnFiZ1BNbk5hS1hocmRTdDRtUUN0VFFZdGRYMVFZS0pUbWF5NU45N3FoNTZtWQprMllKRkpOWVhHWlJabkdMUXJQNk04VHZramF0ZnZOdmJ0WmtkY2orYlY3aWhXanp2d2theHRUVjZlUGxuM2p5CnJUeXBBTDliYnlVcHlad3E2MWQvb0Q4VUtwZ2lZM1dOWmN1YnNvSjhxWlRsTnN6UjVadEFJV0tjSE5ZbE93d2oKaG41RE1tSFpwZ0ZGNW14TU52akxPRUc0S0ZRU3laYlV2QzlZRUhLZTUxbGVxa1lmQmtBZWpPY002TnlWQUh1dApuay9DMHpXcGdENkIwbkVDQXdFQUFUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUFHTCtaNkRzK2R4WTZsU2VBClZHSkMvdzE1bHJ2ZXdia1YxN3hvcmlyNEMxVURJSXB6YXdCdFJRSGdSWXVtblVqOGo4T0hFWUFDUEthR3BTVUsKRDVuVWdzV0pMUUV0TDA2eTh6M3A0MDBrSlZFZW9xZlVnYjQrK1JLRVJrWmowWXR3NEN0WHhwOVMzVkd4NmNOQQozZVlqRnRQd2hoYWVEQmdma1hXQWtISXFDcEsrN3RYem9pRGpXbi8walI2VDcrSGlaNEZjZ1AzYnd3K3NjUDIyCjlDQVZ1ZFg4TWpEQ1hTcll0Y0ZINllBanlCSTJjbDhoSkJqa2E3aERpVC9DaFlEZlFFVFZDM3crQjBDYjF1NWcKdE03Z2NGcUw4OVdhMnp5UzdNdXk5bEthUDBvTXl1Ty82Tm1wNjNsVnRHeEZKSFh4WTN6M0lycGxlbTNZQThpTwpmbmlYZXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
cacerts.pem: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNvRENDQVlnQ0NRRHVVWjZuMEZWeU16QU5CZ2txaGtpRzl3MEJBUXNGQURBU01SQXdEZ1lEVlFRRERBZDAKWlhOMExXTmhNQjRYRFRFNE1EVXdOakl4TURRd09Wb1hEVEU0TURjd05USXhNRFF3T1Zvd0VqRVFNQTRHQTFVRQpBd3dIZEdWemRDMWpZVENDQVNJd0RRWUpLb1pJaHZjTkFRRUJCUUFEZ2dFUEFEQ0NBUW9DZ2dFQkFNQmpBS3dQCndhRUhwQTdaRW1iWWczaTNYNlppVmtGZFJGckJlTmFYTHFPL2R0RUdmWktqYUF0Wm45R1VsckQxZUlUS3UzVHgKOWlGVlV4Mmo1Z0tyWmpwWitCUnFiZ1BNbk5hS1hocmRTdDRtUUN0VFFZdGRYMVFZS0pUbWF5NU45N3FoNTZtWQprMllKRkpOWVhHWlJabkdMUXJQNk04VHZramF0ZnZOdmJ0WmtkY2orYlY3aWhXanp2d2theHRUVjZlUGxuM2p5CnJUeXBBTDliYnlVcHlad3E2MWQvb0Q4VUtwZ2lZM1dOWmN1YnNvSjhxWlRsTnN6UjVadEFJV0tjSE5ZbE93d2oKaG41RE1tSFpwZ0ZGNW14TU52akxPRUc0S0ZRU3laYlV2QzlZRUhLZTUxbGVxa1lmQmtBZWpPY002TnlWQUh1dApuay9DMHpXcGdENkIwbkVDQXdFQUFUQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUFHTCtaNkRzK2R4WTZsU2VBClZHSkMvdzE1bHJ2ZXdia1YxN3hvcmlyNEMxVURJSXB6YXdCdFJRSGdSWXVtblVqOGo4T0hFWUFDUEthR3BTVUsKRDVuVWdzV0pMUUV0TDA2eTh6M3A0MDBrSlZFZW9xZlVnYjQrK1JLRVJrWmowWXR3NEN0WHhwOVMzVkd4NmNOQQozZVlqRnRQd2hoYWVEQmdma1hXQWtISXFDcEsrN3RYem9pRGpXbi8walI2VDcrSGlaNEZjZ1AzYnd3K3NjUDIyCjlDQVZ1ZFg4TWpEQ1hTcll0Y0ZINllBanlCSTJjbDhoSkJqa2E3aERpVC9DaFlEZlFFVFZDM3crQjBDYjF1NWcKdE03Z2NGcUw4OVdhMnp5UzdNdXk5bEthUDBvTXl1Ty82Tm1wNjNsVnRHeEZKSFh4WTN6M0lycGxlbTNZQThpTwpmbmlYZXc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="option-b" label="Option B—Bring Your Own Certificate: Signed by Recognized CA" %}}
|
<details id="option-b">
|
||||||
|
<summary>Option B—Bring Your Own Certificate: Signed by Recognized CA</summary>
|
||||||
|
|
||||||
If you are using a Certificate Signed By A Recognized Certificate Authority, you don't need to perform any step in this part.
|
If you are using a Certificate Signed By A Recognized Certificate Authority, you don't need to perform any step in this part.
|
||||||
{{% /accordion %}}
|
|
||||||
|
</details>
|
||||||
|
|
||||||
## 8. Configure FQDN
|
## 8. Configure FQDN
|
||||||
|
|
||||||
|
|||||||
+7
-4
@@ -48,7 +48,9 @@ For security purposes, SSL (Secure Sockets Layer) is required when using Rancher
|
|||||||
|
|
||||||
Choose from the following options:
|
Choose from the following options:
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Option A-Bring Your Own Certificate: Self-Signed" %}}
|
<details id="option-a">
|
||||||
|
<summary>Option A-Bring Your Own Certificate: Self-Signed</summary>
|
||||||
|
|
||||||
If you elect to use a self-signed certificate to encrypt communication, you must install the certificate on your load balancer (which you'll do later) and your Rancher container. Run the Docker command to deploy Rancher, pointing it toward your certificate.
|
If you elect to use a self-signed certificate to encrypt communication, you must install the certificate on your load balancer (which you'll do later) and your Rancher container. Run the Docker command to deploy Rancher, pointing it toward your certificate.
|
||||||
|
|
||||||
> **Prerequisites:**
|
> **Prerequisites:**
|
||||||
@@ -67,8 +69,9 @@ If you elect to use a self-signed certificate to encrypt communication, you must
|
|||||||
rancher/rancher:latest
|
rancher/rancher:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="option-b" label="Option B-Bring Your Own Certificate: Signed by Recognized CA" %}}
|
<details id="option-b">
|
||||||
|
<summary>Option B-Bring Your Own Certificate: Signed by Recognized CA</summary>
|
||||||
If your cluster is public facing, it's best to use a certificate signed by a recognized CA.
|
If your cluster is public facing, it's best to use a certificate signed by a recognized CA.
|
||||||
|
|
||||||
> **Prerequisites:**
|
> **Prerequisites:**
|
||||||
@@ -87,7 +90,7 @@ If you use a certificate signed by a recognized CA, installing your certificate
|
|||||||
rancher/rancher:latest --no-cacerts
|
rancher/rancher:latest --no-cacerts
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
## 3. Configure Load Balancer
|
## 3. Configure Load Balancer
|
||||||
|
|
||||||
|
|||||||
+7
-4
@@ -38,7 +38,8 @@ The namespace used in these instructions depends on the namespace cert-manager i
|
|||||||
|
|
||||||
In order to upgrade cert-manager, follow these instructions:
|
In order to upgrade cert-manager, follow these instructions:
|
||||||
|
|
||||||
{{% accordion id="normal" label="Upgrading cert-manager with Internet access" %}}
|
<details id="normal">
|
||||||
|
<summary>Upgrading cert-manager with Internet access</summary>
|
||||||
1. Back up existing resources as a precaution
|
1. Back up existing resources as a precaution
|
||||||
|
|
||||||
```plain
|
```plain
|
||||||
@@ -74,9 +75,11 @@ In order to upgrade cert-manager, follow these instructions:
|
|||||||
```plain
|
```plain
|
||||||
helm install --version 0.12.0 --name cert-manager --namespace kube-system jetstack/cert-manager
|
helm install --version 0.12.0 --name cert-manager --namespace kube-system jetstack/cert-manager
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
<details id="airgap">
|
||||||
|
<summary>Upgrading cert-manager in an airgapped environment</summary>
|
||||||
|
|
||||||
{{% accordion id="airgap" label="Upgrading cert-manager in an airgapped environment" %}}
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
Before you can perform the upgrade, you must prepare your air gapped environment by adding the necessary container images to your private registry and downloading or rendering the required Kubernetes manifest files.
|
Before you can perform the upgrade, you must prepare your air gapped environment by adding the necessary container images to your private registry and downloading or rendering the required Kubernetes manifest files.
|
||||||
@@ -138,7 +141,7 @@ Before you can perform the upgrade, you must prepare your air gapped environment
|
|||||||
```plain
|
```plain
|
||||||
kubectl -n kube-system apply -R -f ./cert-manager
|
kubectl -n kube-system apply -R -f ./cert-manager
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
Once you’ve installed cert-manager, you can verify it is deployed correctly by checking the kube-system namespace for running pods:
|
Once you’ve installed cert-manager, you can verify it is deployed correctly by checking the kube-system namespace for running pods:
|
||||||
|
|||||||
+6
-4
@@ -39,7 +39,8 @@ In order to upgrade cert-manager, follow these instructions:
|
|||||||
|
|
||||||
### Option A: Upgrade cert-manager with Internet Access
|
### Option A: Upgrade cert-manager with Internet Access
|
||||||
|
|
||||||
{{% accordion id="normal" label="Click to expand" %}}
|
<details id="normal">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
1. [Back up existing resources](https://cert-manager.io/docs/tutorials/backup/) as a precaution
|
1. [Back up existing resources](https://cert-manager.io/docs/tutorials/backup/) as a precaution
|
||||||
|
|
||||||
```plain
|
```plain
|
||||||
@@ -104,11 +105,12 @@ In order to upgrade cert-manager, follow these instructions:
|
|||||||
kubectl apply -f cert-manager-backup.yaml
|
kubectl apply -f cert-manager-backup.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Upgrade cert-manager in an Air Gap Environment
|
### Option B: Upgrade cert-manager in an Air Gap Environment
|
||||||
|
|
||||||
{{% accordion id="airgap" label="Click to expand" %}}
|
<details id="airgap">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
@@ -211,7 +213,7 @@ Before you can perform the upgrade, you must prepare your air gapped environment
|
|||||||
kubectl apply -f cert-manager-backup.yaml
|
kubectl apply -f cert-manager-backup.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Verify the Deployment
|
### Verify the Deployment
|
||||||
|
|
||||||
|
|||||||
+13
-6
@@ -80,7 +80,10 @@ To create HPA resources based on resource metrics such as CPU and memory use, yo
|
|||||||
# kubectl -n kube-system logs metrics-server-6fbfb84cdd-t2fk9
|
# kubectl -n kube-system logs metrics-server-6fbfb84cdd-t2fk9
|
||||||
```
|
```
|
||||||
Then review the log to confirm that the `metrics-server` package is running.
|
Then review the log to confirm that the `metrics-server` package is running.
|
||||||
{{% accordion id="metrics-server-run-check" label="Metrics Server Log Output" %}}
|
|
||||||
|
<details id="metrics-server-run-check">
|
||||||
|
<summary>Metrics Server Log Output</summary>
|
||||||
|
|
||||||
I0723 08:09:56.193136 1 heapster.go:71] /metrics-server --source=kubernetes.summary_api:''
|
I0723 08:09:56.193136 1 heapster.go:71] /metrics-server --source=kubernetes.summary_api:''
|
||||||
I0723 08:09:56.193574 1 heapster.go:72] Metrics Server version v0.2.1
|
I0723 08:09:56.193574 1 heapster.go:72] Metrics Server version v0.2.1
|
||||||
I0723 08:09:56.194480 1 configs.go:61] Using Kubernetes client with master "https://10.43.0.1:443" and version
|
I0723 08:09:56.194480 1 configs.go:61] Using Kubernetes client with master "https://10.43.0.1:443" and version
|
||||||
@@ -91,7 +94,7 @@ To create HPA resources based on resource metrics such as CPU and memory use, yo
|
|||||||
[restful] 2018/07/23 08:09:57 log.go:33: [restful/swagger] listing is available at https:///swaggerapi
|
[restful] 2018/07/23 08:09:57 log.go:33: [restful/swagger] listing is available at https:///swaggerapi
|
||||||
[restful] 2018/07/23 08:09:57 log.go:33: [restful/swagger] https:///swaggerui/ is mapped to folder /swagger-ui/
|
[restful] 2018/07/23 08:09:57 log.go:33: [restful/swagger] https:///swaggerui/ is mapped to folder /swagger-ui/
|
||||||
I0723 08:09:57.394080 1 serve.go:85] Serving securely on 0.0.0.0:443
|
I0723 08:09:57.394080 1 serve.go:85] Serving securely on 0.0.0.0:443
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
1. Check that the metrics api is accessible from `kubectl`.
|
1. Check that the metrics api is accessible from `kubectl`.
|
||||||
@@ -124,7 +127,10 @@ To do it, follow these steps:
|
|||||||
1. Configure `kubectl` to connect to your cluster.
|
1. Configure `kubectl` to connect to your cluster.
|
||||||
|
|
||||||
1. Copy the ClusterRole and ClusterRoleBinding manifest for the type of metrics you're using for your HPA.
|
1. Copy the ClusterRole and ClusterRoleBinding manifest for the type of metrics you're using for your HPA.
|
||||||
{{% accordion id="cluster-role-resource-metrics" label="Resource Metrics: ApiGroups resource.metrics.k8s.io" %}}
|
|
||||||
|
<details id="cluster-role-resource-metrics">
|
||||||
|
<summary>Resource Metrics: ApiGroups resource.metrics.k8s.io</summary>
|
||||||
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
@@ -152,8 +158,9 @@ To do it, follow these steps:
|
|||||||
- apiGroup: rbac.authorization.k8s.io
|
- apiGroup: rbac.authorization.k8s.io
|
||||||
kind: User
|
kind: User
|
||||||
name: system:anonymous
|
name: system:anonymous
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="cluster-role-custom-resources" label="Custom Metrics: ApiGroups custom.metrics.k8s.io" %}}
|
<details id="cluster-role-custom-resources">
|
||||||
|
<summary>Custom Metrics: ApiGroups custom.metrics.k8s.io</summary>
|
||||||
|
|
||||||
```
|
```
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
@@ -183,7 +190,7 @@ To do it, follow these steps:
|
|||||||
kind: User
|
kind: User
|
||||||
name: system:anonymous
|
name: system:anonymous
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
1. Create them in your cluster using one of the follow commands, depending on the metrics you're using.
|
1. Create them in your cluster using one of the follow commands, depending on the metrics you're using.
|
||||||
```
|
```
|
||||||
# kubectl create -f <RESOURCE_METRICS_MANIFEST>
|
# kubectl create -f <RESOURCE_METRICS_MANIFEST>
|
||||||
|
|||||||
+15
-6
@@ -164,7 +164,10 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
# kubectl logs prometheus-adapter-prometheus-adapter-568674d97f-hbzfx -n kube-system
|
# kubectl logs prometheus-adapter-prometheus-adapter-568674d97f-hbzfx -n kube-system
|
||||||
```
|
```
|
||||||
Then review the log output to confirm the service is running.
|
Then review the log output to confirm the service is running.
|
||||||
{{% accordion id="prometheus-logs" label="Prometheus Adaptor Logs" %}}
|
|
||||||
|
<details id="prometheus-logs">
|
||||||
|
<summary>Prometheus Adaptor Logs</summary>
|
||||||
|
|
||||||
...
|
...
|
||||||
I0724 10:18:45.696679 1 round_trippers.go:436] GET https://10.43.0.1:443/api/v1/namespaces/default/pods?labelSelector=app%3Dhello-world 200 OK in 2 milliseconds
|
I0724 10:18:45.696679 1 round_trippers.go:436] GET https://10.43.0.1:443/api/v1/namespaces/default/pods?labelSelector=app%3Dhello-world 200 OK in 2 milliseconds
|
||||||
I0724 10:18:45.696695 1 round_trippers.go:442] Response Headers:
|
I0724 10:18:45.696695 1 round_trippers.go:442] Response Headers:
|
||||||
@@ -177,7 +180,7 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
I0724 10:18:45.699939 1 wrap.go:42] GET /apis/custom.metrics.k8s.io/v1beta1/namespaces/default/pods/%2A/fs_read?labelSelector=app%3Dhello-world: (12.431262ms) 200 [[kube-controller-manager/v1.10.1 (linux/amd64) kubernetes/d4ab475/system:serviceaccount:kube-system:horizontal-pod-autoscaler] 10.42.0.0:24268]
|
I0724 10:18:45.699939 1 wrap.go:42] GET /apis/custom.metrics.k8s.io/v1beta1/namespaces/default/pods/%2A/fs_read?labelSelector=app%3Dhello-world: (12.431262ms) 200 [[kube-controller-manager/v1.10.1 (linux/amd64) kubernetes/d4ab475/system:serviceaccount:kube-system:horizontal-pod-autoscaler] 10.42.0.0:24268]
|
||||||
I0724 10:18:51.727845 1 request.go:836] Request Body: {"kind":"SubjectAccessReview","apiVersion":"authorization.k8s.io/v1beta1","metadata":{"creationTimestamp":null},"spec":{"nonResourceAttributes":{"path":"/","verb":"get"},"user":"system:anonymous","group":["system:unauthenticated"]},"status":{"allowed":false}}
|
I0724 10:18:51.727845 1 request.go:836] Request Body: {"kind":"SubjectAccessReview","apiVersion":"authorization.k8s.io/v1beta1","metadata":{"creationTimestamp":null},"spec":{"nonResourceAttributes":{"path":"/","verb":"get"},"user":"system:anonymous","group":["system:unauthenticated"]},"status":{"allowed":false}}
|
||||||
...
|
...
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -188,15 +191,21 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
# kubectl get --raw /apis/custom.metrics.k8s.io/v1beta1
|
# kubectl get --raw /apis/custom.metrics.k8s.io/v1beta1
|
||||||
```
|
```
|
||||||
If the API is accessible, you should receive output that's similar to what follows.
|
If the API is accessible, you should receive output that's similar to what follows.
|
||||||
{{% accordion id="custom-metrics-api-response" label="API Response" %}}
|
|
||||||
|
<details id="custom-metrics-api-response">
|
||||||
|
<summary>API Response</summary>
|
||||||
|
|
||||||
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
- If you are accessing the cluster through Rancher, enter your Server URL in the kubectl config in the following format: `https://<RANCHER_URL>/k8s/clusters/<CLUSTER_ID>`. Add the suffix `/k8s/clusters/<CLUSTER_ID>` to API path.
|
- If you are accessing the cluster through Rancher, enter your Server URL in the kubectl config in the following format: `https://<RANCHER_URL>/k8s/clusters/<CLUSTER_ID>`. Add the suffix `/k8s/clusters/<CLUSTER_ID>` to API path.
|
||||||
```
|
```
|
||||||
# kubectl get --raw /k8s/clusters/<CLUSTER_ID>/apis/custom.metrics.k8s.io/v1beta1
|
# kubectl get --raw /k8s/clusters/<CLUSTER_ID>/apis/custom.metrics.k8s.io/v1beta1
|
||||||
```
|
```
|
||||||
If the API is accessible, you should receive output that's similar to what follows.
|
If the API is accessible, you should receive output that's similar to what follows.
|
||||||
{{% accordion id="custom-metrics-api-response-rancher" label="API Response" %}}
|
|
||||||
|
<details id="custom-metrics-api-response-rancher">
|
||||||
|
<summary>API Response</summary>
|
||||||
|
|
||||||
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|||||||
+496
-458
@@ -12,58 +12,62 @@ For HPA to work correctly, service deployments should have resources request def
|
|||||||
|
|
||||||
1. Configure `kubectl` to connect to your Kubernetes cluster.
|
1. Configure `kubectl` to connect to your Kubernetes cluster.
|
||||||
|
|
||||||
2. Copy the `hello-world` deployment manifest below.
|
1. Copy the `hello-world` deployment manifest below.
|
||||||
{{% accordion id="hello-world" label="Hello World Manifest" %}}
|
|
||||||
```
|
<details id="hello-world">
|
||||||
apiVersion: apps/v1beta2
|
<summary>Hello World Manifest</summary>
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
```
|
||||||
labels:
|
apiVersion: apps/v1beta2
|
||||||
app: hello-world
|
kind: Deployment
|
||||||
name: hello-world
|
metadata:
|
||||||
namespace: default
|
labels:
|
||||||
spec:
|
app: hello-world
|
||||||
replicas: 1
|
name: hello-world
|
||||||
selector:
|
namespace: default
|
||||||
matchLabels:
|
spec:
|
||||||
app: hello-world
|
replicas: 1
|
||||||
strategy:
|
selector:
|
||||||
rollingUpdate:
|
matchLabels:
|
||||||
maxSurge: 1
|
app: hello-world
|
||||||
maxUnavailable: 0
|
strategy:
|
||||||
type: RollingUpdate
|
rollingUpdate:
|
||||||
template:
|
maxSurge: 1
|
||||||
metadata:
|
maxUnavailable: 0
|
||||||
labels:
|
type: RollingUpdate
|
||||||
app: hello-world
|
template:
|
||||||
spec:
|
metadata:
|
||||||
containers:
|
labels:
|
||||||
- image: rancher/hello-world
|
app: hello-world
|
||||||
imagePullPolicy: Always
|
spec:
|
||||||
name: hello-world
|
containers:
|
||||||
resources:
|
- image: rancher/hello-world
|
||||||
requests:
|
imagePullPolicy: Always
|
||||||
cpu: 500m
|
name: hello-world
|
||||||
memory: 64Mi
|
resources:
|
||||||
ports:
|
requests:
|
||||||
- containerPort: 80
|
cpu: 500m
|
||||||
protocol: TCP
|
memory: 64Mi
|
||||||
restartPolicy: Always
|
ports:
|
||||||
---
|
- containerPort: 80
|
||||||
apiVersion: v1
|
protocol: TCP
|
||||||
kind: Service
|
restartPolicy: Always
|
||||||
metadata:
|
---
|
||||||
name: hello-world
|
apiVersion: v1
|
||||||
namespace: default
|
kind: Service
|
||||||
spec:
|
metadata:
|
||||||
ports:
|
name: hello-world
|
||||||
- port: 80
|
namespace: default
|
||||||
protocol: TCP
|
spec:
|
||||||
targetPort: 80
|
ports:
|
||||||
selector:
|
- port: 80
|
||||||
app: hello-world
|
protocol: TCP
|
||||||
```
|
targetPort: 80
|
||||||
{{% /accordion %}}
|
selector:
|
||||||
|
app: hello-world
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. Deploy it to your cluster.
|
1. Deploy it to your cluster.
|
||||||
|
|
||||||
@@ -72,423 +76,457 @@ spec:
|
|||||||
```
|
```
|
||||||
|
|
||||||
1. Copy one of the HPAs below based on the metric type you're using:
|
1. Copy one of the HPAs below based on the metric type you're using:
|
||||||
{{% accordion id="service-deployment-resource-metrics" label="Hello World HPA: Resource Metrics" %}}
|
|
||||||
```
|
<details id="service-deployment-resource-metrics">
|
||||||
apiVersion: autoscaling/v2beta1
|
<summary>Hello World HPA: Resource Metrics</summary>
|
||||||
kind: HorizontalPodAutoscaler
|
|
||||||
metadata:
|
```
|
||||||
name: hello-world
|
apiVersion: autoscaling/v2beta1
|
||||||
namespace: default
|
kind: HorizontalPodAutoscaler
|
||||||
spec:
|
metadata:
|
||||||
scaleTargetRef:
|
name: hello-world
|
||||||
apiVersion: extensions/v1beta1
|
namespace: default
|
||||||
kind: Deployment
|
spec:
|
||||||
name: hello-world
|
scaleTargetRef:
|
||||||
minReplicas: 1
|
apiVersion: extensions/v1beta1
|
||||||
maxReplicas: 10
|
kind: Deployment
|
||||||
metrics:
|
name: hello-world
|
||||||
- type: Resource
|
minReplicas: 1
|
||||||
resource:
|
maxReplicas: 10
|
||||||
name: cpu
|
metrics:
|
||||||
targetAverageUtilization: 50
|
- type: Resource
|
||||||
- type: Resource
|
resource:
|
||||||
resource:
|
name: cpu
|
||||||
name: memory
|
targetAverageUtilization: 50
|
||||||
targetAverageValue: 1000Mi
|
- type: Resource
|
||||||
```
|
resource:
|
||||||
{{% /accordion %}}
|
name: memory
|
||||||
{{% accordion id="service-deployment-custom-metrics" label="Hello World HPA: Custom Metrics" %}}
|
targetAverageValue: 1000Mi
|
||||||
```
|
```
|
||||||
apiVersion: autoscaling/v2beta1
|
|
||||||
kind: HorizontalPodAutoscaler
|
</details>
|
||||||
metadata:
|
<details id="service-deployment-custom-metrics">
|
||||||
name: hello-world
|
<summary>Hello World HPA: Custom Metrics</summary>
|
||||||
namespace: default
|
|
||||||
spec:
|
```
|
||||||
scaleTargetRef:
|
apiVersion: autoscaling/v2beta1
|
||||||
apiVersion: extensions/v1beta1
|
kind: HorizontalPodAutoscaler
|
||||||
kind: Deployment
|
metadata:
|
||||||
name: hello-world
|
name: hello-world
|
||||||
minReplicas: 1
|
namespace: default
|
||||||
maxReplicas: 10
|
spec:
|
||||||
metrics:
|
scaleTargetRef:
|
||||||
- type: Resource
|
apiVersion: extensions/v1beta1
|
||||||
resource:
|
kind: Deployment
|
||||||
name: cpu
|
name: hello-world
|
||||||
targetAverageUtilization: 50
|
minReplicas: 1
|
||||||
- type: Resource
|
maxReplicas: 10
|
||||||
resource:
|
metrics:
|
||||||
name: memory
|
- type: Resource
|
||||||
targetAverageValue: 100Mi
|
resource:
|
||||||
- type: Pods
|
name: cpu
|
||||||
pods:
|
targetAverageUtilization: 50
|
||||||
metricName: cpu_system
|
- type: Resource
|
||||||
targetAverageValue: 20m
|
resource:
|
||||||
```
|
name: memory
|
||||||
{{% /accordion %}}
|
targetAverageValue: 100Mi
|
||||||
|
- type: Pods
|
||||||
|
pods:
|
||||||
|
metricName: cpu_system
|
||||||
|
targetAverageValue: 20m
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. View the HPA info and description. Confirm that metric data is shown.
|
1. View the HPA info and description. Confirm that metric data is shown.
|
||||||
{{% accordion id="hpa-info-resource-metrics" label="Resource Metrics" %}}
|
|
||||||
1. Enter the following commands.
|
<details id="hpa-info-resource-metrics">
|
||||||
```
|
<summary>Resource Metrics</summary>
|
||||||
# kubectl get hpa
|
|
||||||
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
|
1. Enter the following commands.
|
||||||
hello-world Deployment/hello-world 1253376 / 100Mi, 0% / 50% 1 10 1 6m
|
```
|
||||||
# kubectl describe hpa
|
# kubectl get hpa
|
||||||
Name: hello-world
|
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
|
||||||
Namespace: default
|
hello-world Deployment/hello-world 1253376 / 100Mi, 0% / 50% 1 10 1 6m
|
||||||
Labels: <none>
|
# kubectl describe hpa
|
||||||
Annotations: <none>
|
Name: hello-world
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 20:21:16 +0200
|
Namespace: default
|
||||||
Reference: Deployment/hello-world
|
Labels: <none>
|
||||||
Metrics: ( current / target )
|
Annotations: <none>
|
||||||
resource memory on pods: 1253376 / 100Mi
|
CreationTimestamp: Mon, 23 Jul 2018 20:21:16 +0200
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
Reference: Deployment/hello-world
|
||||||
Min replicas: 1
|
Metrics: ( current / target )
|
||||||
Max replicas: 10
|
resource memory on pods: 1253376 / 100Mi
|
||||||
Conditions:
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
Type Status Reason Message
|
Min replicas: 1
|
||||||
---- ------ ------ -------
|
Max replicas: 10
|
||||||
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
Conditions:
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
Type Status Reason Message
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
---- ------ ------ -------
|
||||||
Events: <none>
|
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
||||||
```
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
{{% /accordion %}}
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
{{% accordion id="hpa-info-custom-metrics" label="Custom Metrics" %}}
|
Events: <none>
|
||||||
1. Enter the following command.
|
```
|
||||||
```
|
</details>
|
||||||
# kubectl describe hpa
|
<details id="hpa-info-custom-metrics">
|
||||||
```
|
<summary>Custom Metrics</summary>
|
||||||
You should receive the output that follows.
|
|
||||||
```
|
1. Enter the following command.
|
||||||
Name: hello-world
|
```
|
||||||
Namespace: default
|
# kubectl describe hpa
|
||||||
Labels: <none>
|
```
|
||||||
Annotations: <none>
|
You should receive the output that follows.
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:36:28 +0200
|
```
|
||||||
Reference: Deployment/hello-world
|
Name: hello-world
|
||||||
Metrics: ( current / target )
|
Namespace: default
|
||||||
resource memory on pods: 3514368 / 100Mi
|
Labels: <none>
|
||||||
"cpu_system" on pods: 0 / 20m
|
Annotations: <none>
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
CreationTimestamp: Tue, 24 Jul 2018 18:36:28 +0200
|
||||||
Min replicas: 1
|
Reference: Deployment/hello-world
|
||||||
Max replicas: 10
|
Metrics: ( current / target )
|
||||||
Conditions:
|
resource memory on pods: 3514368 / 100Mi
|
||||||
Type Status Reason Message
|
"cpu_system" on pods: 0 / 20m
|
||||||
---- ------ ------ -------
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
Min replicas: 1
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
Max replicas: 10
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
Conditions:
|
||||||
Events: <none>
|
Type Status Reason Message
|
||||||
```
|
---- ------ ------ -------
|
||||||
{{% /accordion %}}
|
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events: <none>
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
|
||||||
1. Generate a load for the service to test that your pods autoscale as intended. You can use any load-testing tool (Hey, Gatling, etc.), but we're using [Hey](https://github.com/rakyll/hey).
|
1. Generate a load for the service to test that your pods autoscale as intended. You can use any load-testing tool (Hey, Gatling, etc.), but we're using [Hey](https://github.com/rakyll/hey).
|
||||||
|
|
||||||
1. Test that pod autoscaling works as intended.<br/></br>
|
1. Test that pod autoscaling works as intended.<br/><br/>
|
||||||
**To Test Autoscaling Using Resource Metrics:**
|
**To Test Autoscaling Using Resource Metrics:**
|
||||||
{{% accordion id="observe-upscale-2-pods-cpu" label="Upscale to 2 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to scale up to two pods based on CPU Usage.
|
|
||||||
|
|
||||||
1. View your HPA.
|
<details id="observe-upscale-2-pods-cpu">
|
||||||
```
|
<summary>Upscale to 2 Pods: CPU Usage Up to Target</summary>
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 10928128 / 100Mi
|
|
||||||
resource cpu on pods (as a percentage of request): 56% (280m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm you've scaled to two pods.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-k8ph2 1/1 Running 0 1m
|
|
||||||
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-3-pods-cpu-cooldown" label="Upscale to 3 pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to upscale to 3 pods based on CPU usage with `horizontal-pod-autoscaler-upscale-delay` set to 3 minutes.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
Use your load testing tool to scale up to two pods based on CPU Usage.
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 9424896 / 100Mi
|
|
||||||
resource cpu on pods (as a percentage of request): 66% (333m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 4m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
2. Enter the following command to confirm three pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-f46kh 0/1 Running 0 1m
|
|
||||||
hello-world-54764dfbf8-k8ph2 1/1 Running 0 5m
|
|
||||||
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-downscale-1-pod" label="Downscale to 1 Pod: All Metrics Below Target" %}}
|
|
||||||
Use your load testing to scale down to 1 pod when all metrics are below target for `horizontal-pod-autoscaler-downscale-delay` (5 minutes by default).
|
|
||||||
|
|
||||||
1. Enter the following command.
|
1. View your HPA.
|
||||||
```
|
```
|
||||||
# kubectl describe hpa
|
# kubectl describe hpa
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows.
|
||||||
```
|
```
|
||||||
Name: hello-world
|
Name: hello-world
|
||||||
Namespace: default
|
Namespace: default
|
||||||
Labels: <none>
|
Labels: <none>
|
||||||
Annotations: <none>
|
Annotations: <none>
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
Reference: Deployment/hello-world
|
Reference: Deployment/hello-world
|
||||||
Metrics: ( current / target )
|
Metrics: ( current / target )
|
||||||
resource memory on pods: 10070016 / 100Mi
|
resource memory on pods: 10928128 / 100Mi
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
resource cpu on pods (as a percentage of request): 56% (280m) / 50%
|
||||||
Min replicas: 1
|
Min replicas: 1
|
||||||
Max replicas: 10
|
Max replicas: 10
|
||||||
Conditions:
|
Conditions:
|
||||||
Type Status Reason Message
|
Type Status Reason Message
|
||||||
---- ------ ------ -------
|
---- ------ ------ -------
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
Events:
|
Events:
|
||||||
Type Reason Age From Message
|
Type Reason Age From Message
|
||||||
---- ------ ---- ---- -------
|
---- ------ ---- ---- -------
|
||||||
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 6m horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
```
|
||||||
Normal SuccessfulRescale 1s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
1. Enter the following command to confirm you've scaled to two pods.
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
# kubectl get pods
|
||||||
<br/>
|
```
|
||||||
**To Test Autoscaling Using Custom Metrics:**
|
You should receive output similar to what follows:
|
||||||
{{% accordion id="custom-observe-upscale-2-pods-cpu" label="Upscale to 2 Pods: CPU Usage Up to Target" %}}
|
```
|
||||||
Use your load testing tool to upscale two pods based on CPU usage.
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-k8ph2 1/1 Running 0 1m
|
||||||
|
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
||||||
|
```
|
||||||
|
|
||||||
1. Enter the following command.
|
</details>
|
||||||
```
|
<details id="observe-upscale-3-pods-cpu-cooldown">
|
||||||
# kubectl describe hpa
|
<summary>Upscale to 3 pods: CPU Usage Up to Target</summary>
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8159232 / 100Mi
|
|
||||||
"cpu_system" on pods: 7m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 64% (321m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm two pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-3-pods-cpu-cooldown-2" label="Upscale to 3 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to scale up to three pods when the cpu_system usage limit is up to target.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
Use your load testing tool to upscale to 3 pods based on CPU usage with `horizontal-pod-autoscaler-upscale-delay` set to 3 minutes.
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8374272 / 100Mi
|
|
||||||
"cpu_system" on pods: 27m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 3s horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm three pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3m
|
|
||||||
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-4-pods" label="Upscale to 4 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to upscale to four pods based on CPU usage. `horizontal-pod-autoscaler-upscale-delay` is set to three minutes by default.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
1. Enter the following command.
|
||||||
```
|
```
|
||||||
# kubectl describe hpa
|
# kubectl describe hpa
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows
|
||||||
```
|
```
|
||||||
Name: hello-world
|
Name: hello-world
|
||||||
Namespace: default
|
Namespace: default
|
||||||
Labels: <none>
|
Labels: <none>
|
||||||
Annotations: <none>
|
Annotations: <none>
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
Reference: Deployment/hello-world
|
Reference: Deployment/hello-world
|
||||||
Metrics: ( current / target )
|
Metrics: ( current / target )
|
||||||
resource memory on pods: 8374272 / 100Mi
|
resource memory on pods: 9424896 / 100Mi
|
||||||
"cpu_system" on pods: 27m / 20m
|
resource cpu on pods (as a percentage of request): 66% (333m) / 50%
|
||||||
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
Min replicas: 1
|
||||||
Min replicas: 1
|
Max replicas: 10
|
||||||
Max replicas: 10
|
Conditions:
|
||||||
Conditions:
|
Type Status Reason Message
|
||||||
Type Status Reason Message
|
---- ------ ------ -------
|
||||||
---- ------ ------ -------
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
Events:
|
||||||
Events:
|
Type Reason Age From Message
|
||||||
Type Reason Age From Message
|
---- ------ ---- ---- -------
|
||||||
---- ------ ---- ---- -------
|
Normal SuccessfulRescale 4m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
```
|
||||||
Normal SuccessfulRescale 4s horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
2. Enter the following command to confirm three pods are running.
|
||||||
```
|
```
|
||||||
1. Enter the following command to confirm four pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-2p9xb 1/1 Running 0 5m
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 2m
|
|
||||||
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="custom-metrics-observe-downscale-1-pod" label="Downscale to 1 Pod: All Metrics Below Target" %}}
|
|
||||||
Use your load testing tool to scale down to one pod when all metrics below target for `horizontal-pod-autoscaler-downscale-delay`.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive similar output to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8101888 / 100Mi
|
|
||||||
"cpu_system" on pods: 8m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 8m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
|
||||||
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm a single pods is running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
# kubectl get pods
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows.
|
||||||
```
|
```
|
||||||
NAME READY STATUS RESTARTS AGE
|
NAME READY STATUS RESTARTS AGE
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
hello-world-54764dfbf8-f46kh 0/1 Running 0 1m
|
||||||
```
|
hello-world-54764dfbf8-k8ph2 1/1 Running 0 5m
|
||||||
{{% /accordion %}}
|
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-downscale-1-pod">
|
||||||
|
<summary>Downscale to 1 Pod: All Metrics Below Target</summary>
|
||||||
|
|
||||||
|
Use your load testing to scale down to 1 pod when all metrics are below target for `horizontal-pod-autoscaler-downscale-delay` (5 minutes by default).
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 10070016 / 100Mi
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 6m horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 1s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
**To Test Autoscaling Using Custom Metrics:**
|
||||||
|
|
||||||
|
<details id="custom-observe-upscale-2-pods-cpu">
|
||||||
|
<summary>Upscale to 2 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to upscale two pods based on CPU usage.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8159232 / 100Mi
|
||||||
|
"cpu_system" on pods: 7m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 64% (321m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm two pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-upscale-3-pods-cpu-cooldown-2">
|
||||||
|
<summary>Upscale to 3 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to scale up to three pods when the cpu_system usage limit is up to target.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows:
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8374272 / 100Mi
|
||||||
|
"cpu_system" on pods: 27m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 3s horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm three pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows:
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3m
|
||||||
|
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-upscale-4-pods">
|
||||||
|
<summary>Upscale to 4 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to upscale to four pods based on CPU usage. `horizontal-pod-autoscaler-upscale-delay` is set to three minutes by default.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8374272 / 100Mi
|
||||||
|
"cpu_system" on pods: 27m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
Normal SuccessfulRescale 4s horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm four pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-2p9xb 1/1 Running 0 5m
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 2m
|
||||||
|
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
</details>
|
||||||
|
<details id="custom-metrics-observe-downscale-1-pod">
|
||||||
|
<summary>Downscale to 1 Pod: All Metrics Below Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to scale down to one pod when all metrics below target for `horizontal-pod-autoscaler-downscale-delay`.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive similar output to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8101888 / 100Mi
|
||||||
|
"cpu_system" on pods: 8m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 8m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm a single pods is running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
</details>
|
||||||
|
|||||||
@@ -60,4 +60,4 @@ After a cluster is created with Rancher, a cluster administrator can manage clus
|
|||||||
|
|
||||||
The following table summarizes the options and settings available for each cluster type:
|
The following table summarizes the options and settings available for each cluster type:
|
||||||
|
|
||||||
{{% include file="/rancher/v2.0-v2.4/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.0-v2.4/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|||||||
+18
-12
@@ -1271,7 +1271,8 @@ runcmd:
|
|||||||
|
|
||||||
Before apply, replace `rancher_kubernetes_engine_config.services.etcd.gid` and `rancher_kubernetes_engine_config.services.etcd.uid` with the proper etcd group and user ids that were created on etcd nodes.
|
Before apply, replace `rancher_kubernetes_engine_config.services.etcd.gid` and `rancher_kubernetes_engine_config.services.etcd.uid` with the proper etcd group and user ids that were created on etcd nodes.
|
||||||
|
|
||||||
{{% accordion id="cluster-1.14" label="RKE yaml for k8s 1.14" %}}
|
<details id="cluster-1.14">
|
||||||
|
<summary>RKE yaml for k8s 1.14</summary>
|
||||||
|
|
||||||
``` yaml
|
``` yaml
|
||||||
nodes:
|
nodes:
|
||||||
@@ -1401,9 +1402,10 @@ services:
|
|||||||
ssh_agent_auth: false
|
ssh_agent_auth: false
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
{{% accordion id="cluster-1.15" label="RKE yaml for k8s 1.15" %}}
|
<details id="cluster-1.15">
|
||||||
|
<summary>RKE yaml for k8s 1.15</summary>
|
||||||
|
|
||||||
``` yaml
|
``` yaml
|
||||||
nodes:
|
nodes:
|
||||||
@@ -1525,9 +1527,10 @@ services:
|
|||||||
ssh_agent_auth: false
|
ssh_agent_auth: false
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
{{% accordion id="cluster-1.16" label="RKE yaml for k8s 1.16" %}}
|
<details id="cluster-1.16">
|
||||||
|
<summary>RKE yaml for k8s 1.16</summary>
|
||||||
|
|
||||||
``` yaml
|
``` yaml
|
||||||
nodes:
|
nodes:
|
||||||
@@ -1649,14 +1652,15 @@ services:
|
|||||||
ssh_agent_auth: false
|
ssh_agent_auth: false
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
## Appendix C - Complete RKE Template Example
|
## Appendix C - Complete RKE Template Example
|
||||||
|
|
||||||
Before apply, replace `rancher_kubernetes_engine_config.services.etcd.gid` and `rancher_kubernetes_engine_config.services.etcd.uid` with the proper etcd group and user ids that were created on etcd nodes.
|
Before apply, replace `rancher_kubernetes_engine_config.services.etcd.gid` and `rancher_kubernetes_engine_config.services.etcd.uid` with the proper etcd group and user ids that were created on etcd nodes.
|
||||||
|
|
||||||
|
|
||||||
{{% accordion id="k8s-1.14" label="RKE template for k8s 1.14" %}}
|
<details id="k8s-1.14">
|
||||||
|
<summary>RKE template for k8s 1.14</summary>
|
||||||
|
|
||||||
``` yaml
|
``` yaml
|
||||||
#
|
#
|
||||||
@@ -1790,9 +1794,10 @@ rancher_kubernetes_engine_config:
|
|||||||
windows_prefered_cluster: false
|
windows_prefered_cluster: false
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
{{% accordion id="k8s-1.15" label="RKE template for k8s 1.15" %}}
|
<details id="k8s-1.15">
|
||||||
|
<summary>RKE template for k8s 1.15</summary>
|
||||||
|
|
||||||
``` yaml
|
``` yaml
|
||||||
#
|
#
|
||||||
@@ -1916,9 +1921,10 @@ rancher_kubernetes_engine_config:
|
|||||||
windows_prefered_cluster: false
|
windows_prefered_cluster: false
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
{{% accordion id="k8s-1.16" label="RKE template for k8s 1.16" %}}
|
<details id="k8s-1.16">
|
||||||
|
<summary>RKE template for k8s 1.16</summary>
|
||||||
|
|
||||||
``` yaml
|
``` yaml
|
||||||
#
|
#
|
||||||
@@ -2042,4 +2048,4 @@ rancher_kubernetes_engine_config:
|
|||||||
windows_prefered_cluster: false
|
windows_prefered_cluster: false
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|||||||
+15
-15
@@ -938,7 +938,7 @@ on the master node and set the `--service-account-key-file` parameter
|
|||||||
to the public key file for service accounts:
|
to the public key file for service accounts:
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--service-account-key-file=<filename>
|
`--service-account-key-file=<filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -963,8 +963,8 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the **etcd** certificate and **key** file parameters.
|
on the master node and set the **etcd** certificate and **key** file parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--etcd-certfile=<path/to/client-certificate-file>
|
`--etcd-certfile=<path/to/client-certificate-file>`
|
||||||
--etcd-keyfile=<path/to/client-key-file>
|
`--etcd-keyfile=<path/to/client-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -989,8 +989,8 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the TLS certificate and private key file parameters.
|
on the master node and set the TLS certificate and private key file parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1015,7 +1015,7 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the client certificate authority file.
|
on the master node and set the client certificate authority file.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1040,7 +1040,7 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the etcd certificate authority file parameter.
|
on the master node and set the etcd certificate authority file parameter.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--etcd-cafile=<path/to/ca-file>
|
`--etcd-cafile=<path/to/ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1202,7 +1202,7 @@ on the master node and set the `--service-account-private-key-file` parameter
|
|||||||
to the private key file for service accounts.
|
to the private key file for service accounts.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--service-account-private-key-file=<filename>
|
`--service-account-private-key-file=<filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1226,7 +1226,7 @@ Edit the Controller Manager pod specification file `/etc/kubernetes/manifests/ku
|
|||||||
on the master node and set the `--root-ca-file` parameter to the certificate bundle file`.
|
on the master node and set the `--root-ca-file` parameter to the certificate bundle file`.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--root-ca-file=<path/to/file>
|
`--root-ca-file=<path/to/file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1344,8 +1344,8 @@ Then, edit the etcd pod specification file `/etc/kubernetes/manifests/etcd.yaml`
|
|||||||
on the master node and set the below parameters.
|
on the master node and set the below parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--cert-file=</path/to/ca-file>
|
`--cert-file=</path/to/ca-file>`
|
||||||
--key-file=</path/to/key-file>
|
`--key-file=</path/to/key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1418,8 +1418,8 @@ for your etcd cluster. Then, edit the etcd pod specification file `/etc/kubernet
|
|||||||
master node and set the below parameters.
|
master node and set the below parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--peer-client-file=</path/to/peer-cert-file>
|
`--peer-client-file=</path/to/peer-cert-file>`
|
||||||
--peer-key-file=</path/to/peer-key-file>
|
`--peer-key-file=</path/to/peer-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1635,7 +1635,7 @@ chown root:root /etc/kubernetes/ssl/kubecfg-kube-node.yaml
|
|||||||
Run the following command to modify the file permissions of the
|
Run the following command to modify the file permissions of the
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file chmod 644 <filename>
|
`--client-ca-file chmod 644 <filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1780,7 +1780,7 @@ If using command line arguments, edit the kubelet service file
|
|||||||
set the below parameter in `KUBELET_AUTHZ_ARGS` variable.
|
set the below parameter in `KUBELET_AUTHZ_ARGS` variable.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
|
|||||||
+15
-15
@@ -938,7 +938,7 @@ on the master node and set the `--service-account-key-file` parameter
|
|||||||
to the public key file for service accounts:
|
to the public key file for service accounts:
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--service-account-key-file=<filename>
|
`--service-account-key-file=<filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -963,8 +963,8 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the **etcd** certificate and **key** file parameters.
|
on the master node and set the **etcd** certificate and **key** file parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--etcd-certfile=<path/to/client-certificate-file>
|
`--etcd-certfile=<path/to/client-certificate-file>`
|
||||||
--etcd-keyfile=<path/to/client-key-file>
|
`--etcd-keyfile=<path/to/client-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -989,8 +989,8 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the TLS certificate and private key file parameters.
|
on the master node and set the TLS certificate and private key file parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1015,7 +1015,7 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the client certificate authority file.
|
on the master node and set the client certificate authority file.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1040,7 +1040,7 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the etcd certificate authority file parameter.
|
on the master node and set the etcd certificate authority file parameter.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--etcd-cafile=<path/to/ca-file>
|
`--etcd-cafile=<path/to/ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1202,7 +1202,7 @@ on the master node and set the `--service-account-private-key-file` parameter
|
|||||||
to the private key file for service accounts.
|
to the private key file for service accounts.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--service-account-private-key-file=<filename>
|
`--service-account-private-key-file=<filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1226,7 +1226,7 @@ Edit the Controller Manager pod specification file `/etc/kubernetes/manifests/ku
|
|||||||
on the master node and set the `--root-ca-file` parameter to the certificate bundle file`.
|
on the master node and set the `--root-ca-file` parameter to the certificate bundle file`.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--root-ca-file=<path/to/file>
|
`--root-ca-file=<path/to/file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1344,8 +1344,8 @@ Then, edit the etcd pod specification file `/etc/kubernetes/manifests/etcd.yaml`
|
|||||||
on the master node and set the below parameters.
|
on the master node and set the below parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--cert-file=</path/to/ca-file>
|
`--cert-file=</path/to/ca-file>`
|
||||||
--key-file=</path/to/key-file>
|
`--key-file=</path/to/key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1418,8 +1418,8 @@ for your etcd cluster. Then, edit the etcd pod specification file `/etc/kubernet
|
|||||||
master node and set the below parameters.
|
master node and set the below parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--peer-client-file=</path/to/peer-cert-file>
|
`--peer-client-file=</path/to/peer-cert-file>`
|
||||||
--peer-key-file=</path/to/peer-key-file>
|
`--peer-key-file=</path/to/peer-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1635,7 +1635,7 @@ chown root:root /etc/kubernetes/ssl/kubecfg-kube-node.yaml
|
|||||||
Run the following command to modify the file permissions of the
|
Run the following command to modify the file permissions of the
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file chmod 644 <filename>
|
`--client-ca-file chmod 644 <filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1780,7 +1780,7 @@ If using command line arguments, edit the kubelet service file
|
|||||||
set the below parameter in `KUBELET_AUTHZ_ARGS` variable.
|
set the below parameter in `KUBELET_AUTHZ_ARGS` variable.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
|
|||||||
+11
-4
@@ -165,14 +165,21 @@ You can change the cluster or project role(s) that are automatically assigned to
|
|||||||
1. Find the custom or individual role that you want to use as default. Then edit the role by selecting **⋮ > Edit**.
|
1. Find the custom or individual role that you want to use as default. Then edit the role by selecting **⋮ > Edit**.
|
||||||
|
|
||||||
1. Enable the role as default.
|
1. Enable the role as default.
|
||||||
{{% accordion id="cluster" label="For Clusters" %}}
|
|
||||||
|
<details id="cluster">
|
||||||
|
<summary>For Clusters</summary>
|
||||||
|
|
||||||
1. From **Cluster Creator Default**, choose **Yes: Default role for new cluster creation**.
|
1. From **Cluster Creator Default**, choose **Yes: Default role for new cluster creation**.
|
||||||
1. Click **Save**.
|
1. Click **Save**.
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="project" label="For Projects" %}}
|
</details>
|
||||||
|
<details id="project">
|
||||||
|
|
||||||
|
<summary>For Projects</summary>
|
||||||
1. From **Project Creator Default**, choose **Yes: Default role for new project creation**.
|
1. From **Project Creator Default**, choose **Yes: Default role for new project creation**.
|
||||||
1. Click **Save**.
|
1. Click **Save**.
|
||||||
{{% /accordion %}}
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. If you want to remove a default role, edit the permission and select **No** from the default roles option.
|
1. If you want to remove a default role, edit the permission and select **No** from the default roles option.
|
||||||
|
|
||||||
|
|||||||
+3
-2
@@ -26,7 +26,8 @@ In this command, `<DATE>` is a placeholder for the date that the data container
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the [procedure below](#creating-a-backup).
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the [procedure below](#creating-a-backup).
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
@@ -57,7 +58,7 @@ This procedure creates a backup that you can restore if Rancher encounters a dis
|
|||||||
docker create --volumes-from <RANCHER_CONTAINER_NAME> --name rancher-data-<DATE> rancher/rancher:<RANCHER_CONTAINER_TAG>
|
docker create --volumes-from <RANCHER_CONTAINER_NAME> --name rancher-data-<DATE> rancher/rancher:<RANCHER_CONTAINER_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
1. <a id="tarball"></a>From the data container that you just created (`rancher-data-<DATE>`), create a backup tarball (`rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz`). Use the following command, replacing each placeholder:
|
1. <a id="tarball"></a>From the data container that you just created (<code>rancher-data-<DATE></code>), create a backup tarball (<code>rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz</code>). Use the following command, replacing each placeholder:
|
||||||
|
|
||||||
```
|
```
|
||||||
docker run --volumes-from rancher-data-<DATE> -v $PWD:/backup:z busybox tar pzcvf /backup/rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz /var/lib/rancher
|
docker run --volumes-from rancher-data-<DATE> -v $PWD:/backup:z busybox tar pzcvf /backup/rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz /var/lib/rancher
|
||||||
|
|||||||
+2
-1
@@ -25,7 +25,8 @@ In this command, `<RANCHER_CONTAINER_NAME>` and `<RANCHER_VERSION>-<DATE>` are e
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ helm repo update
|
|||||||
helm install rancher-backup-crd rancher-charts/rancher-backup-crd -n cattle-resources-system --create-namespace --version $CHART_VERSION
|
helm install rancher-backup-crd rancher-charts/rancher-backup-crd -n cattle-resources-system --create-namespace --version $CHART_VERSION
|
||||||
helm install rancher-backup rancher-charts/rancher-backup -n cattle-resources-system --version $CHART_VERSION
|
helm install rancher-backup rancher-charts/rancher-backup -n cattle-resources-system --version $CHART_VERSION
|
||||||
```
|
```
|
||||||
</br>
|
<br/>
|
||||||
For an **air-gapped environment**, use the option below to pull the `backup-restore-operator` image from your private registry when installing the rancher-backup-crd helm chart.
|
For an **air-gapped environment**, use the option below to pull the `backup-restore-operator` image from your private registry when installing the rancher-backup-crd helm chart.
|
||||||
```
|
```
|
||||||
--set image.repository $REGISTRY/rancher/backup-restore-operator
|
--set image.repository $REGISTRY/rancher/backup-restore-operator
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ Alternatively, you can switch between projects and clusters directly in the navi
|
|||||||
|
|
||||||
After clusters have been [provisioned into Rancher]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/), [cluster owners]({{<baseurl>}}/rancher/v2.5/en/admin-settings/rbac/cluster-project-roles/#cluster-roles) will need to manage these clusters. There are many different options of how to manage your cluster.
|
After clusters have been [provisioned into Rancher]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/), [cluster owners]({{<baseurl>}}/rancher/v2.5/en/admin-settings/rbac/cluster-project-roles/#cluster-roles) will need to manage these clusters. There are many different options of how to manage your cluster.
|
||||||
|
|
||||||
{{% include file="/rancher/v2.5/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.5/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
## Configuring Tools
|
## Configuring Tools
|
||||||
|
|
||||||
|
|||||||
+3
-3
@@ -298,8 +298,8 @@ This table shows cluster-autoscaler parameters for fine tuning:
|
|||||||
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
||||||
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
||||||
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
||||||
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
cloud-provider|-|Cloud provider type|
|
cloud-provider|-|Cloud provider type|
|
||||||
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
||||||
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
||||||
@@ -309,7 +309,7 @@ cloud-provider|-|Cloud provider type|
|
|||||||
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
||||||
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
||||||
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
||||||
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: <min>:<max>:<other...>|
|
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: `<min>:<max>:<other...>`|
|
||||||
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
||||||
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
||||||
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
||||||
|
|||||||
+1
-1
@@ -24,5 +24,5 @@ The options and settings available for an existing cluster change based on the m
|
|||||||
|
|
||||||
The following table summarizes the options and settings available for each cluster type:
|
The following table summarizes the options and settings available for each cluster type:
|
||||||
|
|
||||||
{{% include file="/rancher/v2.5/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.5/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
|
|||||||
+8
-4
@@ -341,7 +341,8 @@ Option | Description
|
|||||||
|
|
||||||
If you choose to assign a public IP address to your cluster's worker nodes, you have the option of choosing between a VPC that's automatically generated by Rancher (i.e., **Standard: Rancher generated VPC and Subnet**), or a VPC that you've already created with AWS (i.e., **Custom: Choose from your existing VPC and Subnets**). Choose the option that best fits your use case.
|
If you choose to assign a public IP address to your cluster's worker nodes, you have the option of choosing between a VPC that's automatically generated by Rancher (i.e., **Standard: Rancher generated VPC and Subnet**), or a VPC that you've already created with AWS (i.e., **Custom: Choose from your existing VPC and Subnets**). Choose the option that best fits your use case.
|
||||||
|
|
||||||
{{% accordion id="yes" label="Click to expand" %}}
|
<details id="yes">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you're using **Custom: Choose from your existing VPC and Subnets**:
|
If you're using **Custom: Choose from your existing VPC and Subnets**:
|
||||||
|
|
||||||
@@ -354,10 +355,13 @@ If you're using **Custom: Choose from your existing VPC and Subnets**:
|
|||||||
1. Click **Next: Select Subnets**. Then choose one of the **Subnets** that displays.
|
1. Click **Next: Select Subnets**. Then choose one of the **Subnets** that displays.
|
||||||
|
|
||||||
1. Click **Next: Select Security Group**.
|
1. Click **Next: Select Security Group**.
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
If your worker nodes have Private IPs only, you must also choose a **VPC & Subnet** that allow your instances to access the internet. This access is required so that your worker nodes can connect to the Kubernetes control plane.
|
If your worker nodes have Private IPs only, you must also choose a **VPC & Subnet** that allow your instances to access the internet. This access is required so that your worker nodes can connect to the Kubernetes control plane.
|
||||||
{{% accordion id="no" label="Click to expand" %}}
|
|
||||||
|
<details id="no">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
Follow the steps below.
|
Follow the steps below.
|
||||||
|
|
||||||
>**Tip:** When using only private IP addresses, you can provide your nodes internet access by creating a VPC constructed with two subnets, a private set and a public set. The private set should have its route tables configured to point toward a NAT in the public set. For more information on routing traffic from private subnets, please see the [official AWS documentation](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html).
|
>**Tip:** When using only private IP addresses, you can provide your nodes internet access by creating a VPC constructed with two subnets, a private set and a public set. The private set should have its route tables configured to point toward a NAT in the public set. For more information on routing traffic from private subnets, please see the [official AWS documentation](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html).
|
||||||
@@ -366,7 +370,7 @@ Follow the steps below.
|
|||||||
|
|
||||||
1. Click **Next: Select Subnets**. Then choose one of the **Subnets** that displays.
|
1. Click **Next: Select Subnets**. Then choose one of the **Subnets** that displays.
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Security Group
|
### Security Group
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -21,8 +21,8 @@ After installing the initiator tool on your nodes, edit the YAML for your cluste
|
|||||||
|
|
||||||
>**Notes:**
|
>**Notes:**
|
||||||
>
|
>
|
||||||
>- Before updating your Kubernetes YAML to mount the iSCSI binary and configuration, make sure either the `open-iscsi` (deb) or `iscsi-initiator-utils` (yum) package is installed on your cluster nodes. If this package isn't installed _before_ the bind mounts are created in your Kubernetes YAML, Docker will automatically create the directories and files on each node and will not allow the package install to succeed.</br>
|
>- Before updating your Kubernetes YAML to mount the iSCSI binary and configuration, make sure either the `open-iscsi` (deb) or `iscsi-initiator-utils` (yum) package is installed on your cluster nodes. If this package isn't installed _before_ the bind mounts are created in your Kubernetes YAML, Docker will automatically create the directories and files on each node and will not allow the package install to succeed.<br/>
|
||||||
></br>
|
><br/>
|
||||||
>
|
>
|
||||||
>- The example YAML below does not apply to K3s, but only to RKE clusters. Since the K3s kubelet does not run in a container, adding extra binds is not necessary. However, all iSCSI tools must still be installed on your K3s nodes.
|
>- The example YAML below does not apply to K3s, but only to RKE clusters. Since the K3s kubelet does not run in a container, adding extra binds is not necessary. However, all iSCSI tools must still be installed on your K3s nodes.
|
||||||
|
|
||||||
|
|||||||
@@ -32,7 +32,7 @@ This section covers the following topics:
|
|||||||
|
|
||||||
The following table summarizes the options and settings available for each cluster type:
|
The following table summarizes the options and settings available for each cluster type:
|
||||||
|
|
||||||
{{% include file="/rancher/v2.5/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.5/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
# Setting up Clusters in a Hosted Kubernetes Provider
|
# Setting up Clusters in a Hosted Kubernetes Provider
|
||||||
|
|
||||||
|
|||||||
+3
-2
@@ -177,7 +177,8 @@ Instead of using the Rancher UI to choose Kubernetes options for the cluster, ad
|
|||||||
|
|
||||||
RKE (Rancher Kubernetes Engine) is the tool that Rancher uses to provision Kubernetes clusters. Rancher's cluster config files used to have the same structure as [RKE config files,]({{<baseurl>}}/rke/latest/en/example-yamls/) but the structure changed so that in Rancher, RKE cluster config items are separated from non-RKE config items. Therefore, configuration for your cluster needs to be nested under the `rancher_kubernetes_engine_config` directive in the cluster config file. Cluster config files created with earlier versions of Rancher will need to be updated for this format. An example cluster config file is included below.
|
RKE (Rancher Kubernetes Engine) is the tool that Rancher uses to provision Kubernetes clusters. Rancher's cluster config files used to have the same structure as [RKE config files,]({{<baseurl>}}/rke/latest/en/example-yamls/) but the structure changed so that in Rancher, RKE cluster config items are separated from non-RKE config items. Therefore, configuration for your cluster needs to be nested under the `rancher_kubernetes_engine_config` directive in the cluster config file. Cluster config files created with earlier versions of Rancher will need to be updated for this format. An example cluster config file is included below.
|
||||||
|
|
||||||
{{% accordion id="v2.3.0-cluster-config-file" label="Example Cluster Config File" %}}
|
<details id="v2.3.0-cluster-config-file">
|
||||||
|
<summary>Example Cluster Config File</summary>
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
#
|
#
|
||||||
@@ -269,7 +270,7 @@ rancher_kubernetes_engine_config: # Your RKE template config goes here.
|
|||||||
ssh_agent_auth: false
|
ssh_agent_auth: false
|
||||||
windows_prefered_cluster: false
|
windows_prefered_cluster: false
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Default DNS provider
|
### Default DNS provider
|
||||||
|
|
||||||
|
|||||||
+3
-2
@@ -120,7 +120,8 @@ There are three recommended options for the source of the certificate used for T
|
|||||||
|
|
||||||
This step is only required to use certificates issued by Rancher's generated CA (`ingress.tls.source=rancher`) or to request Let's Encrypt issued certificates (`ingress.tls.source=letsEncrypt`).
|
This step is only required to use certificates issued by Rancher's generated CA (`ingress.tls.source=rancher`) or to request Let's Encrypt issued certificates (`ingress.tls.source=letsEncrypt`).
|
||||||
|
|
||||||
{{% accordion id="cert-manager" label="Click to Expand" %}}
|
<details id="cert-manager">
|
||||||
|
<summary>Click to Expand</summary>
|
||||||
|
|
||||||
> **Important:** Recent changes to cert-manager require an upgrade. If you are upgrading Rancher and using a version of cert-manager older than v0.11.0, please see our [upgrade documentation]({{<baseurl>}}/rancher/v2.5/en/installation/options/upgrading-cert-manager/).
|
> **Important:** Recent changes to cert-manager require an upgrade. If you are upgrading Rancher and using a version of cert-manager older than v0.11.0, please see our [upgrade documentation]({{<baseurl>}}/rancher/v2.5/en/installation/options/upgrading-cert-manager/).
|
||||||
|
|
||||||
@@ -154,7 +155,7 @@ cert-manager-cainjector-577f6d9fd7-tr77l 1/1 Running 0 2m
|
|||||||
cert-manager-webhook-787858fcdb-nlzsq 1/1 Running 0 2m
|
cert-manager-webhook-787858fcdb-nlzsq 1/1 Running 0 2m
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### 5. Install Rancher with Helm and Your Chosen Certificate Option
|
### 5. Install Rancher with Helm and Your Chosen Certificate Option
|
||||||
|
|
||||||
|
|||||||
+9
-6
@@ -25,7 +25,8 @@ Choose from the following options:
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
||||||
|
|
||||||
@@ -47,11 +48,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
||||||
|
|
||||||
@@ -86,11 +88,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
||||||
|
|
||||||
@@ -122,7 +125,7 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+4
-3
@@ -76,7 +76,7 @@ When setting up the Rancher Helm template, there are several options in the Helm
|
|||||||
|
|
||||||
| Chart Option | Chart Value | Description |
|
| Chart Option | Chart Value | Description |
|
||||||
| ----------------------- | -------------------------------- | ---- |
|
| ----------------------- | -------------------------------- | ---- |
|
||||||
| `certmanager.version` | "<version>" | Configure proper Rancher TLS issuer depending of running cert-manager version. |
|
| `certmanager.version` | `<version>` | Configure proper Rancher TLS issuer depending of running cert-manager version. |
|
||||||
| `systemDefaultRegistry` | `<REGISTRY.YOURDOMAIN.COM:PORT>` | Configure Rancher server to always pull from your private registry when provisioning clusters. |
|
| `systemDefaultRegistry` | `<REGISTRY.YOURDOMAIN.COM:PORT>` | Configure Rancher server to always pull from your private registry when provisioning clusters. |
|
||||||
| `useBundledSystemChart` | `true` | Configure Rancher server to use the packaged copy of Helm system charts. The [system charts](https://github.com/rancher/system-charts) repository contains all the catalog items required for features such as monitoring, logging, alerting and global DNS. These [Helm charts](https://github.com/rancher/system-charts) are located in GitHub, but since you are in an air gapped environment, using the charts that are bundled within Rancher is much easier than setting up a Git mirror. |
|
| `useBundledSystemChart` | `true` | Configure Rancher server to use the packaged copy of Helm system charts. The [system charts](https://github.com/rancher/system-charts) repository contains all the catalog items required for features such as monitoring, logging, alerting and global DNS. These [Helm charts](https://github.com/rancher/system-charts) are located in GitHub, but since you are in an air gapped environment, using the charts that are bundled within Rancher is much easier than setting up a Git mirror. |
|
||||||
|
|
||||||
@@ -272,7 +272,8 @@ If you choose to use self-signed certificates in [B. Choose your SSL Configurati
|
|||||||
|
|
||||||
### For Self-Signed Certificate Installs, Install Cert-manager
|
### For Self-Signed Certificate Installs, Install Cert-manager
|
||||||
|
|
||||||
{{% accordion id="install-cert-manager" label="Click to expand" %}}
|
<details id="install-cert-manager">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you are using self-signed certificates, install cert-manager:
|
If you are using self-signed certificates, install cert-manager:
|
||||||
|
|
||||||
@@ -294,7 +295,7 @@ kubectl apply -f cert-manager/cert-manager-crd.yaml
|
|||||||
kubectl apply -R -f ./cert-manager
|
kubectl apply -R -f ./cert-manager
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Install Rancher with kubectl
|
### Install Rancher with kubectl
|
||||||
|
|
||||||
|
|||||||
+1
-2
@@ -24,8 +24,7 @@ In this command, `<PRIOR_RANCHER_VERSION>` is the version of Rancher you were ru
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<PRIOR_RANCHER_VERSION>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><PRIOR_RANCHER_VERSION></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||

|
|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
| -------------------------- | -------------------------- | ------------------------------------------------------- |
|
| -------------------------- | -------------------------- | ------------------------------------------------------- |
|
||||||
|
|||||||
+24
-16
@@ -42,7 +42,8 @@ docker ps
|
|||||||
|
|
||||||
Write down or copy this information before starting the upgrade.
|
Write down or copy this information before starting the upgrade.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
@@ -84,7 +85,7 @@ During upgrade, you create a copy of the data from your current Rancher containe
|
|||||||
|
|
||||||
# 2. Create a backup tarball
|
# 2. Create a backup tarball
|
||||||
|
|
||||||
1. <a id="tarball"></a>From the data container that you just created (`rancher-data`), create a backup tarball (`rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz`).
|
1. <a id="tarball"></a>From the data container that you just created (<code>rancher-data</code>), create a backup tarball (<code>rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz</code>).
|
||||||
|
|
||||||
This tarball will serve as a rollback point if something goes wrong during upgrade. Use the following command, replacing each placeholder.
|
This tarball will serve as a rollback point if something goes wrong during upgrade. Use the following command, replacing each placeholder.
|
||||||
|
|
||||||
@@ -140,7 +141,8 @@ Select which option you had installed Rancher server
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
||||||
|
|
||||||
@@ -158,11 +160,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
|
|
||||||
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
||||||
|
|
||||||
@@ -189,11 +192,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
|
|
||||||
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with. Remember to include `--no-cacerts` as an argument to the container to disable the default CA certificate generated by Rancher.
|
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with. Remember to include `--no-cacerts` as an argument to the container to disable the default CA certificate generated by Rancher.
|
||||||
|
|
||||||
@@ -218,11 +222,12 @@ docker run -d --volumes-from rancher-data \
|
|||||||
```
|
```
|
||||||
|
|
||||||
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option D: Let's Encrypt Certificate
|
### Option D: Let's Encrypt Certificate
|
||||||
|
|
||||||
{{% accordion id="option-d" label="Click to expand" %}}
|
<details id="option-d">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
>**Remember:** Let's Encrypt provides rate limits for requesting new certificates. Therefore, limit how often you create or destroy the container. For more information, see [Let's Encrypt documentation on rate limits](https://letsencrypt.org/docs/rate-limits/).
|
>**Remember:** Let's Encrypt provides rate limits for requesting new certificates. Therefore, limit how often you create or destroy the container. For more information, see [Let's Encrypt documentation on rate limits](https://letsencrypt.org/docs/rate-limits/).
|
||||||
|
|
||||||
@@ -249,7 +254,7 @@ docker run -d --volumes-from rancher-data \
|
|||||||
|
|
||||||
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
</TabItem>
|
</TabItem>
|
||||||
<TabItem value="Docker Air Gap Upgrade">
|
<TabItem value="Docker Air Gap Upgrade">
|
||||||
@@ -260,7 +265,8 @@ When starting the new Rancher server container, choose from the following option
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
If you have selected to use the Rancher generated self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container.
|
||||||
|
|
||||||
@@ -280,11 +286,12 @@ Placeholder | Description
|
|||||||
```
|
```
|
||||||
|
|
||||||
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
If you have selected to bring your own self-signed certificate, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificate that you had originally installed with.
|
||||||
|
|
||||||
@@ -311,11 +318,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with.
|
If you have selected to use a certificate signed by a recognized CA, you add the `--volumes-from rancher-data` to the command that you had started your original Rancher server container and need to have access to the same certificates that you had originally installed with.
|
||||||
|
|
||||||
@@ -344,7 +352,7 @@ docker run -d --volumes-from rancher-data \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
As of Rancher v2.5, privileged access is [required.]({{<baseurl>}}/rancher/v2.5/en/installation/other-installation-methods/single-node-docker/#privileged-access-for-rancher-v2-5)
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
</TabItem>
|
</TabItem>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
|
|||||||
@@ -43,7 +43,8 @@ As of Rancher v2.5, Rancher can be installed on any Kubernetes cluster. For Ranc
|
|||||||
|
|
||||||
### Ports for Rancher Server Nodes on K3s
|
### Ports for Rancher Server Nodes on K3s
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The K3s server needs port 6443 to be accessible by the nodes.
|
The K3s server needs port 6443 to be accessible by the nodes.
|
||||||
|
|
||||||
@@ -74,11 +75,12 @@ The following tables break down the port requirements for inbound and outbound t
|
|||||||
| TCP | 2376 | Any node IP from a node created using Node driver | Docker daemon TLS port used by Docker Machine |
|
| TCP | 2376 | Any node IP from a node created using Node driver | Docker daemon TLS port used by Docker Machine |
|
||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Server Nodes on RKE
|
### Ports for Rancher Server Nodes on RKE
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
Typically Rancher is installed on three RKE nodes that all have the etcd, control plane and worker roles.
|
Typically Rancher is installed on three RKE nodes that all have the etcd, control plane and worker roles.
|
||||||
|
|
||||||
@@ -118,13 +120,14 @@ The following tables break down the port requirements for inbound and outbound t
|
|||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
| TCP | Provider dependent | Port of the Kubernetes API endpoint in hosted cluster | Kubernetes API |
|
| TCP | Provider dependent | Port of the Kubernetes API endpoint in hosted cluster | Kubernetes API |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Server Nodes on RancherD or RKE2
|
### Ports for Rancher Server Nodes on RancherD or RKE2
|
||||||
|
|
||||||
> **Note:** RancherD was an experimental feature available as part of Rancher v2.5.4 through v2.5.10 but is now deprecated and not available for recent releases.
|
> **Note:** RancherD was an experimental feature available as part of Rancher v2.5.4 through v2.5.10 but is now deprecated and not available for recent releases.
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The RancherD (or RKE2) server needs port 6443 and 9345 to be accessible by other nodes in the cluster.
|
The RancherD (or RKE2) server needs port 6443 and 9345 to be accessible by other nodes in the cluster.
|
||||||
|
|
||||||
@@ -149,11 +152,12 @@ If you wish to utilize the metrics server, you will need to open port 10250 on e
|
|||||||
| HTTPS | 8443 | <ul><li>hosted/registered Kubernetes</li><li>any source that needs to be able to use the Rancher UI or API</li></ul> | Rancher agent, Rancher UI/API, kubectl. Not needed if you have LB doing TLS termination. |
|
| HTTPS | 8443 | <ul><li>hosted/registered Kubernetes</li><li>any source that needs to be able to use the Rancher UI or API</li></ul> | Rancher agent, Rancher UI/API, kubectl. Not needed if you have LB doing TLS termination. |
|
||||||
|
|
||||||
Typically all outbound traffic is allowed.
|
Typically all outbound traffic is allowed.
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Server in Docker
|
### Ports for Rancher Server in Docker
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following tables break down the port requirements for Rancher nodes, for inbound and outbound traffic:
|
The following tables break down the port requirements for Rancher nodes, for inbound and outbound traffic:
|
||||||
|
|
||||||
@@ -173,7 +177,7 @@ The following tables break down the port requirements for Rancher nodes, for inb
|
|||||||
| TCP | 2376 | Any node IP from a node created using a node driver | Docker daemon TLS port used by Docker Machine |
|
| TCP | 2376 | Any node IP from a node created using a node driver | Docker daemon TLS port used by Docker Machine |
|
||||||
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
| TCP | 6443 | Hosted/Imported Kubernetes API | Kubernetes API server |
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
# Downstream Kubernetes Cluster Nodes
|
# Downstream Kubernetes Cluster Nodes
|
||||||
|
|
||||||
@@ -193,7 +197,8 @@ The following diagram depicts the ports that are opened for each [cluster type](
|
|||||||
|
|
||||||
### Ports for Rancher Launched Kubernetes Clusters using Node Pools
|
### Ports for Rancher Launched Kubernetes Clusters using Node Pools
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/) with nodes created in an [Infrastructure Provider]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/node-pools/).
|
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/) with nodes created in an [Infrastructure Provider]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/node-pools/).
|
||||||
|
|
||||||
@@ -202,39 +207,42 @@ The following table depicts the port requirements for [Rancher Launched Kubernet
|
|||||||
|
|
||||||
{{< ports-iaas-nodes >}}
|
{{< ports-iaas-nodes >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Rancher Launched Kubernetes Clusters using Custom Nodes
|
### Ports for Rancher Launched Kubernetes Clusters using Custom Nodes
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/) with [Custom Nodes]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/custom-nodes/).
|
The following table depicts the port requirements for [Rancher Launched Kubernetes]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/) with [Custom Nodes]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/rke-clusters/custom-nodes/).
|
||||||
|
|
||||||
{{< ports-custom-nodes >}}
|
{{< ports-custom-nodes >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Hosted Kubernetes Clusters
|
### Ports for Hosted Kubernetes Clusters
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [hosted clusters]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/hosted-kubernetes-clusters).
|
The following table depicts the port requirements for [hosted clusters]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/hosted-kubernetes-clusters).
|
||||||
|
|
||||||
{{< ports-imported-hosted >}}
|
{{< ports-imported-hosted >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Ports for Registered Clusters
|
### Ports for Registered Clusters
|
||||||
|
|
||||||
Note: Registered clusters were called imported clusters before Rancher v2.5.
|
Note: Registered clusters were called imported clusters before Rancher v2.5.
|
||||||
|
|
||||||
{{% accordion label="Click to expand" %}}
|
<details>
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
The following table depicts the port requirements for [registered clusters]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/registered-clusters/).
|
The following table depicts the port requirements for [registered clusters]({{<baseurl>}}/rancher/v2.5/en/cluster-provisioning/registered-clusters/).
|
||||||
|
|
||||||
{{< ports-imported-hosted >}}
|
{{< ports-imported-hosted >}}
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
# Other Port Considerations
|
# Other Port Considerations
|
||||||
@@ -243,7 +251,7 @@ The following table depicts the port requirements for [registered clusters]({{<b
|
|||||||
|
|
||||||
These ports are typically opened on your Kubernetes nodes, regardless of what type of cluster it is.
|
These ports are typically opened on your Kubernetes nodes, regardless of what type of cluster it is.
|
||||||
|
|
||||||
{{% include file="/rancher/v2.5/en/installation/requirements/ports/common-ports-table" %}}
|
{{% include file="/rancher/v2.5/en/installation/requirements/ports/common-ports-table</summary>
|
||||||
|
|
||||||
----
|
----
|
||||||
|
|
||||||
|
|||||||
+8
-4
@@ -49,7 +49,9 @@ For security purposes, SSL (Secure Sockets Layer) is required when using Rancher
|
|||||||
|
|
||||||
Choose from the following options:
|
Choose from the following options:
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Option A-Bring Your Own Certificate: Self-Signed" %}}
|
<details id="option-a">
|
||||||
|
<summary>Option A-Bring Your Own Certificate: Self-Signed</summary>
|
||||||
|
|
||||||
If you elect to use a self-signed certificate to encrypt communication, you must install the certificate on your load balancer (which you'll do later) and your Rancher container. Run the Docker command to deploy Rancher, pointing it toward your certificate.
|
If you elect to use a self-signed certificate to encrypt communication, you must install the certificate on your load balancer (which you'll do later) and your Rancher container. Run the Docker command to deploy Rancher, pointing it toward your certificate.
|
||||||
|
|
||||||
> **Prerequisites:**
|
> **Prerequisites:**
|
||||||
@@ -68,8 +70,10 @@ If you elect to use a self-signed certificate to encrypt communication, you must
|
|||||||
rancher/rancher:latest
|
rancher/rancher:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
{{% accordion id="option-b" label="Option B-Bring Your Own Certificate: Signed by Recognized CA" %}}
|
<details id="option-b">
|
||||||
|
<summary>Option B-Bring Your Own Certificate: Signed by Recognized CA</summary>
|
||||||
|
|
||||||
If your cluster is public facing, it's best to use a certificate signed by a recognized CA.
|
If your cluster is public facing, it's best to use a certificate signed by a recognized CA.
|
||||||
|
|
||||||
> **Prerequisites:**
|
> **Prerequisites:**
|
||||||
@@ -88,7 +92,7 @@ If you use a certificate signed by a recognized CA, installing your certificate
|
|||||||
rancher/rancher:latest --no-cacerts
|
rancher/rancher:latest --no-cacerts
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
## 3. Configure Load Balancer
|
## 3. Configure Load Balancer
|
||||||
|
|
||||||
|
|||||||
+8
-4
@@ -37,7 +37,9 @@ The namespace used in these instructions depends on the namespace cert-manager i
|
|||||||
|
|
||||||
In order to upgrade cert-manager, follow these instructions:
|
In order to upgrade cert-manager, follow these instructions:
|
||||||
|
|
||||||
{{% accordion id="normal" label="Upgrading cert-manager with Internet access" %}}
|
<details id="normal">
|
||||||
|
<summary>Upgrading cert-manager with Internet access</summary>
|
||||||
|
|
||||||
1. Back up existing resources as a precaution
|
1. Back up existing resources as a precaution
|
||||||
|
|
||||||
```plain
|
```plain
|
||||||
@@ -73,9 +75,11 @@ In order to upgrade cert-manager, follow these instructions:
|
|||||||
```plain
|
```plain
|
||||||
helm install --version 0.12.0 --name cert-manager --namespace kube-system jetstack/cert-manager
|
helm install --version 0.12.0 --name cert-manager --namespace kube-system jetstack/cert-manager
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
<details id="airgap">
|
||||||
|
<summary>Upgrading cert-manager in an airgapped environment</summary>
|
||||||
|
|
||||||
{{% accordion id="airgap" label="Upgrading cert-manager in an airgapped environment" %}}
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
Before you can perform the upgrade, you must prepare your air gapped environment by adding the necessary container images to your private registry and downloading or rendering the required Kubernetes manifest files.
|
Before you can perform the upgrade, you must prepare your air gapped environment by adding the necessary container images to your private registry and downloading or rendering the required Kubernetes manifest files.
|
||||||
@@ -137,7 +141,7 @@ Before you can perform the upgrade, you must prepare your air gapped environment
|
|||||||
```plain
|
```plain
|
||||||
kubectl -n kube-system apply -R -f ./cert-manager
|
kubectl -n kube-system apply -R -f ./cert-manager
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
Once you’ve installed cert-manager, you can verify it is deployed correctly by checking the kube-system namespace for running pods:
|
Once you’ve installed cert-manager, you can verify it is deployed correctly by checking the kube-system namespace for running pods:
|
||||||
|
|||||||
+7
-4
@@ -40,7 +40,9 @@ In order to upgrade cert-manager, follow these instructions:
|
|||||||
|
|
||||||
### Option A: Upgrade cert-manager with Internet Access
|
### Option A: Upgrade cert-manager with Internet Access
|
||||||
|
|
||||||
{{% accordion id="normal" label="Click to expand" %}}
|
<details id="normal">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
1. [Back up existing resources](https://cert-manager.io/docs/tutorials/backup/) as a precaution
|
1. [Back up existing resources](https://cert-manager.io/docs/tutorials/backup/) as a precaution
|
||||||
|
|
||||||
```plain
|
```plain
|
||||||
@@ -105,11 +107,12 @@ In order to upgrade cert-manager, follow these instructions:
|
|||||||
kubectl apply -f cert-manager-backup.yaml
|
kubectl apply -f cert-manager-backup.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Upgrade cert-manager in an Air Gap Environment
|
### Option B: Upgrade cert-manager in an Air Gap Environment
|
||||||
|
|
||||||
{{% accordion id="airgap" label="Click to expand" %}}
|
<details id="airgap">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
@@ -212,7 +215,7 @@ Before you can perform the upgrade, you must prepare your air gapped environment
|
|||||||
kubectl apply -f cert-manager-backup.yaml
|
kubectl apply -f cert-manager-backup.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Verify the Deployment
|
### Verify the Deployment
|
||||||
|
|
||||||
|
|||||||
+15
-6
@@ -161,7 +161,10 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
# kubectl logs prometheus-adapter-prometheus-adapter-568674d97f-hbzfx -n kube-system
|
# kubectl logs prometheus-adapter-prometheus-adapter-568674d97f-hbzfx -n kube-system
|
||||||
```
|
```
|
||||||
Then review the log output to confirm the service is running.
|
Then review the log output to confirm the service is running.
|
||||||
{{% accordion id="prometheus-logs" label="Prometheus Adaptor Logs" %}}
|
|
||||||
|
<details id="prometheus-logs">
|
||||||
|
<summary>Prometheus Adaptor Logs</summary>
|
||||||
|
|
||||||
...
|
...
|
||||||
I0724 10:18:45.696679 1 round_trippers.go:436] GET https://10.43.0.1:443/api/v1/namespaces/default/pods?labelSelector=app%3Dhello-world 200 OK in 2 milliseconds
|
I0724 10:18:45.696679 1 round_trippers.go:436] GET https://10.43.0.1:443/api/v1/namespaces/default/pods?labelSelector=app%3Dhello-world 200 OK in 2 milliseconds
|
||||||
I0724 10:18:45.696695 1 round_trippers.go:442] Response Headers:
|
I0724 10:18:45.696695 1 round_trippers.go:442] Response Headers:
|
||||||
@@ -174,7 +177,7 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
I0724 10:18:45.699939 1 wrap.go:42] GET /apis/custom.metrics.k8s.io/v1beta1/namespaces/default/pods/%2A/fs_read?labelSelector=app%3Dhello-world: (12.431262ms) 200 [[kube-controller-manager/v1.10.1 (linux/amd64) kubernetes/d4ab475/system:serviceaccount:kube-system:horizontal-pod-autoscaler] 10.42.0.0:24268]
|
I0724 10:18:45.699939 1 wrap.go:42] GET /apis/custom.metrics.k8s.io/v1beta1/namespaces/default/pods/%2A/fs_read?labelSelector=app%3Dhello-world: (12.431262ms) 200 [[kube-controller-manager/v1.10.1 (linux/amd64) kubernetes/d4ab475/system:serviceaccount:kube-system:horizontal-pod-autoscaler] 10.42.0.0:24268]
|
||||||
I0724 10:18:51.727845 1 request.go:836] Request Body: {"kind":"SubjectAccessReview","apiVersion":"authorization.k8s.io/v1beta1","metadata":{"creationTimestamp":null},"spec":{"nonResourceAttributes":{"path":"/","verb":"get"},"user":"system:anonymous","group":["system:unauthenticated"]},"status":{"allowed":false}}
|
I0724 10:18:51.727845 1 request.go:836] Request Body: {"kind":"SubjectAccessReview","apiVersion":"authorization.k8s.io/v1beta1","metadata":{"creationTimestamp":null},"spec":{"nonResourceAttributes":{"path":"/","verb":"get"},"user":"system:anonymous","group":["system:unauthenticated"]},"status":{"allowed":false}}
|
||||||
...
|
...
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -185,15 +188,21 @@ For HPA to use custom metrics from Prometheus, package [k8s-prometheus-adapter](
|
|||||||
# kubectl get --raw /apis/custom.metrics.k8s.io/v1beta1
|
# kubectl get --raw /apis/custom.metrics.k8s.io/v1beta1
|
||||||
```
|
```
|
||||||
If the API is accessible, you should receive output that's similar to what follows.
|
If the API is accessible, you should receive output that's similar to what follows.
|
||||||
{{% accordion id="custom-metrics-api-response" label="API Response" %}}
|
|
||||||
|
<details id="custom-metrics-api-response">
|
||||||
|
<summary>API Response</summary>
|
||||||
|
|
||||||
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
- If you are accessing the cluster through Rancher, enter your Server URL in the kubectl config in the following format: `https://<RANCHER_URL>/k8s/clusters/<CLUSTER_ID>`. Add the suffix `/k8s/clusters/<CLUSTER_ID>` to API path.
|
- If you are accessing the cluster through Rancher, enter your Server URL in the kubectl config in the following format: `https://<RANCHER_URL>/k8s/clusters/<CLUSTER_ID>`. Add the suffix `/k8s/clusters/<CLUSTER_ID>` to API path.
|
||||||
```
|
```
|
||||||
# kubectl get --raw /k8s/clusters/<CLUSTER_ID>/apis/custom.metrics.k8s.io/v1beta1
|
# kubectl get --raw /k8s/clusters/<CLUSTER_ID>/apis/custom.metrics.k8s.io/v1beta1
|
||||||
```
|
```
|
||||||
If the API is accessible, you should receive output that's similar to what follows.
|
If the API is accessible, you should receive output that's similar to what follows.
|
||||||
{{% accordion id="custom-metrics-api-response-rancher" label="API Response" %}}
|
|
||||||
|
<details id="custom-metrics-api-response-rancher">
|
||||||
|
<summary>API Response</summary>
|
||||||
|
|
||||||
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
{"kind":"APIResourceList","apiVersion":"v1","groupVersion":"custom.metrics.k8s.io/v1beta1","resources":[{"name":"pods/fs_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_rss","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_period","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_read","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_user","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/last_seen","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/tasks_state","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_quota","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/start_time_seconds","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_write","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_cache","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_cfs_throttled_periods","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_working_set_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_udp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes_free","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_inodes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_time_weighted","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failures","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_swap","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_cpu_shares","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_swap_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_io_current","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_failcnt","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_writes_merged","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/network_tcp_usage","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/memory_max_usage_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/spec_memory_reservation_limit_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_load_average_10s","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/cpu_system","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_reads_bytes","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]},{"name":"pods/fs_sector_reads","singularName":"","namespaced":true,"kind":"MetricValueList","verbs":["get"]}]}
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|||||||
+498
-458
@@ -12,58 +12,62 @@ For HPA to work correctly, service deployments should have resources request def
|
|||||||
|
|
||||||
1. Configure `kubectl` to connect to your Kubernetes cluster.
|
1. Configure `kubectl` to connect to your Kubernetes cluster.
|
||||||
|
|
||||||
2. Copy the `hello-world` deployment manifest below.
|
1. Copy the `hello-world` deployment manifest below.
|
||||||
{{% accordion id="hello-world" label="Hello World Manifest" %}}
|
|
||||||
```
|
<details id="hello-world">
|
||||||
apiVersion: apps/v1beta2
|
<summary>Hello World Manifest</summary>
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
```
|
||||||
labels:
|
apiVersion: apps/v1beta2
|
||||||
app: hello-world
|
kind: Deployment
|
||||||
name: hello-world
|
metadata:
|
||||||
namespace: default
|
labels:
|
||||||
spec:
|
app: hello-world
|
||||||
replicas: 1
|
name: hello-world
|
||||||
selector:
|
namespace: default
|
||||||
matchLabels:
|
spec:
|
||||||
app: hello-world
|
replicas: 1
|
||||||
strategy:
|
selector:
|
||||||
rollingUpdate:
|
matchLabels:
|
||||||
maxSurge: 1
|
app: hello-world
|
||||||
maxUnavailable: 0
|
strategy:
|
||||||
type: RollingUpdate
|
rollingUpdate:
|
||||||
template:
|
maxSurge: 1
|
||||||
metadata:
|
maxUnavailable: 0
|
||||||
labels:
|
type: RollingUpdate
|
||||||
app: hello-world
|
template:
|
||||||
spec:
|
metadata:
|
||||||
containers:
|
labels:
|
||||||
- image: rancher/hello-world
|
app: hello-world
|
||||||
imagePullPolicy: Always
|
spec:
|
||||||
name: hello-world
|
containers:
|
||||||
resources:
|
- image: rancher/hello-world
|
||||||
requests:
|
imagePullPolicy: Always
|
||||||
cpu: 500m
|
name: hello-world
|
||||||
memory: 64Mi
|
resources:
|
||||||
ports:
|
requests:
|
||||||
- containerPort: 80
|
cpu: 500m
|
||||||
protocol: TCP
|
memory: 64Mi
|
||||||
restartPolicy: Always
|
ports:
|
||||||
---
|
- containerPort: 80
|
||||||
apiVersion: v1
|
protocol: TCP
|
||||||
kind: Service
|
restartPolicy: Always
|
||||||
metadata:
|
---
|
||||||
name: hello-world
|
apiVersion: v1
|
||||||
namespace: default
|
kind: Service
|
||||||
spec:
|
metadata:
|
||||||
ports:
|
name: hello-world
|
||||||
- port: 80
|
namespace: default
|
||||||
protocol: TCP
|
spec:
|
||||||
targetPort: 80
|
ports:
|
||||||
selector:
|
- port: 80
|
||||||
app: hello-world
|
protocol: TCP
|
||||||
```
|
targetPort: 80
|
||||||
{{% /accordion %}}
|
selector:
|
||||||
|
app: hello-world
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. Deploy it to your cluster.
|
1. Deploy it to your cluster.
|
||||||
|
|
||||||
@@ -72,423 +76,459 @@ spec:
|
|||||||
```
|
```
|
||||||
|
|
||||||
1. Copy one of the HPAs below based on the metric type you're using:
|
1. Copy one of the HPAs below based on the metric type you're using:
|
||||||
{{% accordion id="service-deployment-resource-metrics" label="Hello World HPA: Resource Metrics" %}}
|
|
||||||
```
|
<details id="service-deployment-resource-metrics">
|
||||||
apiVersion: autoscaling/v2beta1
|
<summary>Hello World HPA: Resource Metrics</summary>
|
||||||
kind: HorizontalPodAutoscaler
|
|
||||||
metadata:
|
```
|
||||||
name: hello-world
|
apiVersion: autoscaling/v2beta1
|
||||||
namespace: default
|
kind: HorizontalPodAutoscaler
|
||||||
spec:
|
metadata:
|
||||||
scaleTargetRef:
|
name: hello-world
|
||||||
apiVersion: extensions/v1beta1
|
namespace: default
|
||||||
kind: Deployment
|
spec:
|
||||||
name: hello-world
|
scaleTargetRef:
|
||||||
minReplicas: 1
|
apiVersion: extensions/v1beta1
|
||||||
maxReplicas: 10
|
kind: Deployment
|
||||||
metrics:
|
name: hello-world
|
||||||
- type: Resource
|
minReplicas: 1
|
||||||
resource:
|
maxReplicas: 10
|
||||||
name: cpu
|
metrics:
|
||||||
targetAverageUtilization: 50
|
- type: Resource
|
||||||
- type: Resource
|
resource:
|
||||||
resource:
|
name: cpu
|
||||||
name: memory
|
targetAverageUtilization: 50
|
||||||
targetAverageValue: 1000Mi
|
- type: Resource
|
||||||
```
|
resource:
|
||||||
{{% /accordion %}}
|
name: memory
|
||||||
{{% accordion id="service-deployment-custom-metrics" label="Hello World HPA: Custom Metrics" %}}
|
targetAverageValue: 1000Mi
|
||||||
```
|
```
|
||||||
apiVersion: autoscaling/v2beta1
|
|
||||||
kind: HorizontalPodAutoscaler
|
</details>
|
||||||
metadata:
|
<details id="service-deployment-custom-metrics">
|
||||||
name: hello-world
|
<summary>Hello World HPA: Custom Metrics</summary>
|
||||||
namespace: default
|
|
||||||
spec:
|
```
|
||||||
scaleTargetRef:
|
apiVersion: autoscaling/v2beta1
|
||||||
apiVersion: extensions/v1beta1
|
kind: HorizontalPodAutoscaler
|
||||||
kind: Deployment
|
metadata:
|
||||||
name: hello-world
|
name: hello-world
|
||||||
minReplicas: 1
|
namespace: default
|
||||||
maxReplicas: 10
|
spec:
|
||||||
metrics:
|
scaleTargetRef:
|
||||||
- type: Resource
|
apiVersion: extensions/v1beta1
|
||||||
resource:
|
kind: Deployment
|
||||||
name: cpu
|
name: hello-world
|
||||||
targetAverageUtilization: 50
|
minReplicas: 1
|
||||||
- type: Resource
|
maxReplicas: 10
|
||||||
resource:
|
metrics:
|
||||||
name: memory
|
- type: Resource
|
||||||
targetAverageValue: 100Mi
|
resource:
|
||||||
- type: Pods
|
name: cpu
|
||||||
pods:
|
targetAverageUtilization: 50
|
||||||
metricName: cpu_system
|
- type: Resource
|
||||||
targetAverageValue: 20m
|
resource:
|
||||||
```
|
name: memory
|
||||||
{{% /accordion %}}
|
targetAverageValue: 100Mi
|
||||||
|
- type: Pods
|
||||||
|
pods:
|
||||||
|
metricName: cpu_system
|
||||||
|
targetAverageValue: 20m
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. View the HPA info and description. Confirm that metric data is shown.
|
1. View the HPA info and description. Confirm that metric data is shown.
|
||||||
{{% accordion id="hpa-info-resource-metrics" label="Resource Metrics" %}}
|
|
||||||
1. Enter the following commands.
|
|
||||||
```
|
|
||||||
# kubectl get hpa
|
|
||||||
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
|
|
||||||
hello-world Deployment/hello-world 1253376 / 100Mi, 0% / 50% 1 10 1 6m
|
|
||||||
# kubectl describe hpa
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 20:21:16 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 1253376 / 100Mi
|
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events: <none>
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="hpa-info-custom-metrics" label="Custom Metrics" %}}
|
|
||||||
1. Enter the following command.
|
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive the output that follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:36:28 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 3514368 / 100Mi
|
|
||||||
"cpu_system" on pods: 0 / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events: <none>
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
|
|
||||||
|
<details id="hpa-info-resource-metrics">
|
||||||
|
<summary>Resource Metrics</summary>
|
||||||
|
|
||||||
|
1. Enter the following commands.
|
||||||
|
```
|
||||||
|
# kubectl get hpa
|
||||||
|
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
|
||||||
|
hello-world Deployment/hello-world 1253376 / 100Mi, 0% / 50% 1 10 1 6m
|
||||||
|
# kubectl describe hpa
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Mon, 23 Jul 2018 20:21:16 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 1253376 / 100Mi
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events: <none>
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="hpa-info-custom-metrics">
|
||||||
|
<summary>Custom Metrics</summary>
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive the output that follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:36:28 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 3514368 / 100Mi
|
||||||
|
"cpu_system" on pods: 0 / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True ReadyForNewScale the last scale time was sufficiently old as to warrant a new scale
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events: <none>
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. Generate a load for the service to test that your pods autoscale as intended. You can use any load-testing tool (Hey, Gatling, etc.), but we're using [Hey](https://github.com/rakyll/hey).
|
1. Generate a load for the service to test that your pods autoscale as intended. You can use any load-testing tool (Hey, Gatling, etc.), but we're using [Hey](https://github.com/rakyll/hey).
|
||||||
|
|
||||||
1. Test that pod autoscaling works as intended.<br/></br>
|
1. Test that pod autoscaling works as intended.<br/><br/>
|
||||||
**To Test Autoscaling Using Resource Metrics:**
|
**To Test Autoscaling Using Resource Metrics:**
|
||||||
{{% accordion id="observe-upscale-2-pods-cpu" label="Upscale to 2 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to scale up to two pods based on CPU Usage.
|
|
||||||
|
|
||||||
1. View your HPA.
|
<details id="observe-upscale-2-pods-cpu">
|
||||||
```
|
<summary>Upscale to 2 Pods: CPU Usage Up to Target</summary>
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 10928128 / 100Mi
|
|
||||||
resource cpu on pods (as a percentage of request): 56% (280m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm you've scaled to two pods.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-k8ph2 1/1 Running 0 1m
|
|
||||||
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-3-pods-cpu-cooldown" label="Upscale to 3 pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to upscale to 3 pods based on CPU usage with `horizontal-pod-autoscaler-upscale-delay` set to 3 minutes.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
Use your load testing tool to scale up to two pods based on CPU Usage.
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 9424896 / 100Mi
|
|
||||||
resource cpu on pods (as a percentage of request): 66% (333m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 4m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
2. Enter the following command to confirm three pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-f46kh 0/1 Running 0 1m
|
|
||||||
hello-world-54764dfbf8-k8ph2 1/1 Running 0 5m
|
|
||||||
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-downscale-1-pod" label="Downscale to 1 Pod: All Metrics Below Target" %}}
|
|
||||||
Use your load testing to scale down to 1 pod when all metrics are below target for `horizontal-pod-autoscaler-downscale-delay` (5 minutes by default).
|
|
||||||
|
|
||||||
1. Enter the following command.
|
1. View your HPA.
|
||||||
```
|
```
|
||||||
# kubectl describe hpa
|
# kubectl describe hpa
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows.
|
||||||
```
|
```
|
||||||
Name: hello-world
|
Name: hello-world
|
||||||
Namespace: default
|
Namespace: default
|
||||||
Labels: <none>
|
Labels: <none>
|
||||||
Annotations: <none>
|
Annotations: <none>
|
||||||
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
Reference: Deployment/hello-world
|
Reference: Deployment/hello-world
|
||||||
Metrics: ( current / target )
|
Metrics: ( current / target )
|
||||||
resource memory on pods: 10070016 / 100Mi
|
resource memory on pods: 10928128 / 100Mi
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
resource cpu on pods (as a percentage of request): 56% (280m) / 50%
|
||||||
Min replicas: 1
|
Min replicas: 1
|
||||||
Max replicas: 10
|
Max replicas: 10
|
||||||
Conditions:
|
Conditions:
|
||||||
Type Status Reason Message
|
Type Status Reason Message
|
||||||
---- ------ ------ -------
|
---- ------ ------ -------
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
Events:
|
Events:
|
||||||
Type Reason Age From Message
|
Type Reason Age From Message
|
||||||
---- ------ ---- ---- -------
|
---- ------ ---- ---- -------
|
||||||
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 6m horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
```
|
||||||
Normal SuccessfulRescale 1s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
1. Enter the following command to confirm you've scaled to two pods.
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
# kubectl get pods
|
||||||
<br/>
|
```
|
||||||
**To Test Autoscaling Using Custom Metrics:**
|
You should receive output similar to what follows:
|
||||||
{{% accordion id="custom-observe-upscale-2-pods-cpu" label="Upscale to 2 Pods: CPU Usage Up to Target" %}}
|
```
|
||||||
Use your load testing tool to upscale two pods based on CPU usage.
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-k8ph2 1/1 Running 0 1m
|
||||||
|
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
||||||
|
```
|
||||||
|
|
||||||
1. Enter the following command.
|
</details>
|
||||||
```
|
<details id="observe-upscale-3-pods-cpu-cooldown">
|
||||||
# kubectl describe hpa
|
<summary>Upscale to 3 pods: CPU Usage Up to Target</summary>
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8159232 / 100Mi
|
|
||||||
"cpu_system" on pods: 7m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 64% (321m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm two pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-3-pods-cpu-cooldown-2" label="Upscale to 3 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to scale up to three pods when the cpu_system usage limit is up to target.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
Use your load testing tool to upscale to 3 pods based on CPU usage with `horizontal-pod-autoscaler-upscale-delay` set to 3 minutes.
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8374272 / 100Mi
|
|
||||||
"cpu_system" on pods: 27m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 3s horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm three pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows:
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3m
|
|
||||||
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="observe-upscale-4-pods" label="Upscale to 4 Pods: CPU Usage Up to Target" %}}
|
|
||||||
Use your load testing tool to upscale to four pods based on CPU usage. `horizontal-pod-autoscaler-upscale-delay` is set to three minutes by default.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
1. Enter the following command.
|
||||||
```
|
```
|
||||||
# kubectl describe hpa
|
# kubectl describe hpa
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows
|
||||||
```
|
```
|
||||||
Name: hello-world
|
Name: hello-world
|
||||||
Namespace: default
|
Namespace: default
|
||||||
Labels: <none>
|
Labels: <none>
|
||||||
Annotations: <none>
|
Annotations: <none>
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
Reference: Deployment/hello-world
|
Reference: Deployment/hello-world
|
||||||
Metrics: ( current / target )
|
Metrics: ( current / target )
|
||||||
resource memory on pods: 8374272 / 100Mi
|
resource memory on pods: 9424896 / 100Mi
|
||||||
"cpu_system" on pods: 27m / 20m
|
resource cpu on pods (as a percentage of request): 66% (333m) / 50%
|
||||||
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
Min replicas: 1
|
||||||
Min replicas: 1
|
Max replicas: 10
|
||||||
Max replicas: 10
|
Conditions:
|
||||||
Conditions:
|
Type Status Reason Message
|
||||||
Type Status Reason Message
|
---- ------ ------ -------
|
||||||
---- ------ ------ -------
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
Events:
|
||||||
Events:
|
Type Reason Age From Message
|
||||||
Type Reason Age From Message
|
---- ------ ---- ---- -------
|
||||||
---- ------ ---- ---- -------
|
Normal SuccessfulRescale 4m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
||||||
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
```
|
||||||
Normal SuccessfulRescale 4s horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
2. Enter the following command to confirm three pods are running.
|
||||||
```
|
```
|
||||||
1. Enter the following command to confirm four pods are running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
|
||||||
```
|
|
||||||
You should receive output similar to what follows.
|
|
||||||
```
|
|
||||||
NAME READY STATUS RESTARTS AGE
|
|
||||||
hello-world-54764dfbf8-2p9xb 1/1 Running 0 5m
|
|
||||||
hello-world-54764dfbf8-5pfdr 1/1 Running 0 2m
|
|
||||||
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
|
||||||
```
|
|
||||||
{{% /accordion %}}
|
|
||||||
{{% accordion id="custom-metrics-observe-downscale-1-pod" label="Downscale to 1 Pod: All Metrics Below Target" %}}
|
|
||||||
Use your load testing tool to scale down to one pod when all metrics below target for `horizontal-pod-autoscaler-downscale-delay`.
|
|
||||||
|
|
||||||
1. Enter the following command.
|
|
||||||
```
|
|
||||||
# kubectl describe hpa
|
|
||||||
```
|
|
||||||
You should receive similar output to what follows.
|
|
||||||
```
|
|
||||||
Name: hello-world
|
|
||||||
Namespace: default
|
|
||||||
Labels: <none>
|
|
||||||
Annotations: <none>
|
|
||||||
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
|
||||||
Reference: Deployment/hello-world
|
|
||||||
Metrics: ( current / target )
|
|
||||||
resource memory on pods: 8101888 / 100Mi
|
|
||||||
"cpu_system" on pods: 8m / 20m
|
|
||||||
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
|
||||||
Min replicas: 1
|
|
||||||
Max replicas: 10
|
|
||||||
Conditions:
|
|
||||||
Type Status Reason Message
|
|
||||||
---- ------ ------ -------
|
|
||||||
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
|
||||||
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
|
||||||
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
|
||||||
Events:
|
|
||||||
Type Reason Age From Message
|
|
||||||
---- ------ ---- ---- -------
|
|
||||||
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 8m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
|
||||||
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
|
||||||
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
|
||||||
```
|
|
||||||
1. Enter the following command to confirm a single pods is running.
|
|
||||||
```
|
|
||||||
# kubectl get pods
|
# kubectl get pods
|
||||||
```
|
```
|
||||||
You should receive output similar to what follows.
|
You should receive output similar to what follows.
|
||||||
```
|
```
|
||||||
NAME READY STATUS RESTARTS AGE
|
NAME READY STATUS RESTARTS AGE
|
||||||
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
hello-world-54764dfbf8-f46kh 0/1 Running 0 1m
|
||||||
```
|
hello-world-54764dfbf8-k8ph2 1/1 Running 0 5m
|
||||||
{{% /accordion %}}
|
hello-world-54764dfbf8-q6l4v 1/1 Running 0 3h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-downscale-1-pod">
|
||||||
|
<summary>Downscale to 1 Pod: All Metrics Below Target</summary>
|
||||||
|
|
||||||
|
Use your load testing to scale down to 1 pod when all metrics are below target for `horizontal-pod-autoscaler-downscale-delay` (5 minutes by default).
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Mon, 23 Jul 2018 22:22:04 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 10070016 / 100Mi
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 6m horizontal-pod-autoscaler New size: 3; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 1s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
**To Test Autoscaling Using Custom Metrics:**
|
||||||
|
|
||||||
|
<details id="custom-observe-upscale-2-pods-cpu">
|
||||||
|
<summary>Upscale to 2 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to upscale two pods based on CPU usage.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8159232 / 100Mi
|
||||||
|
"cpu_system" on pods: 7m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 64% (321m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 2
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 16s horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm two pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-upscale-3-pods-cpu-cooldown-2">
|
||||||
|
<summary>Upscale to 3 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to scale up to three pods when the cpu_system usage limit is up to target.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows:
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8374272 / 100Mi
|
||||||
|
"cpu_system" on pods: 27m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 3s horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm three pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows:
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 3m
|
||||||
|
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="observe-upscale-4-pods">
|
||||||
|
<summary>Upscale to 4 Pods: CPU Usage Up to Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to upscale to four pods based on CPU usage. `horizontal-pod-autoscaler-upscale-delay` is set to three minutes by default.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8374272 / 100Mi
|
||||||
|
"cpu_system" on pods: 27m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 71% (357m) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 3
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from cpu resource utilization (percentage of request)
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 3m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
Normal SuccessfulRescale 4s horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm four pods are running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-2p9xb 1/1 Running 0 5m
|
||||||
|
hello-world-54764dfbf8-5pfdr 1/1 Running 0 2m
|
||||||
|
hello-world-54764dfbf8-m2hrl 1/1 Running 0 1s
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
<details id="custom-metrics-observe-downscale-1-pod">
|
||||||
|
<summary>Downscale to 1 Pod: All Metrics Below Target</summary>
|
||||||
|
|
||||||
|
Use your load testing tool to scale down to one pod when all metrics below target for `horizontal-pod-autoscaler-downscale-delay`.
|
||||||
|
|
||||||
|
1. Enter the following command.
|
||||||
|
```
|
||||||
|
# kubectl describe hpa
|
||||||
|
```
|
||||||
|
You should receive similar output to what follows.
|
||||||
|
```
|
||||||
|
Name: hello-world
|
||||||
|
Namespace: default
|
||||||
|
Labels: <none>
|
||||||
|
Annotations: <none>
|
||||||
|
CreationTimestamp: Tue, 24 Jul 2018 18:01:11 +0200
|
||||||
|
Reference: Deployment/hello-world
|
||||||
|
Metrics: ( current / target )
|
||||||
|
resource memory on pods: 8101888 / 100Mi
|
||||||
|
"cpu_system" on pods: 8m / 20m
|
||||||
|
resource cpu on pods (as a percentage of request): 0% (0) / 50%
|
||||||
|
Min replicas: 1
|
||||||
|
Max replicas: 10
|
||||||
|
Conditions:
|
||||||
|
Type Status Reason Message
|
||||||
|
---- ------ ------ -------
|
||||||
|
AbleToScale True SucceededRescale the HPA controller was able to update the target scale to 1
|
||||||
|
ScalingActive True ValidMetricFound the HPA was able to successfully calculate a replica count from memory resource
|
||||||
|
ScalingLimited False DesiredWithinRange the desired count is within the acceptable range
|
||||||
|
Events:
|
||||||
|
Type Reason Age From Message
|
||||||
|
---- ------ ---- ---- -------
|
||||||
|
Normal SuccessfulRescale 10m horizontal-pod-autoscaler New size: 2; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 8m horizontal-pod-autoscaler New size: 3; reason: pods metric cpu_system above target
|
||||||
|
Normal SuccessfulRescale 5m horizontal-pod-autoscaler New size: 4; reason: cpu resource utilization (percentage of request) above target
|
||||||
|
Normal SuccessfulRescale 13s horizontal-pod-autoscaler New size: 1; reason: All metrics below target
|
||||||
|
```
|
||||||
|
1. Enter the following command to confirm a single pods is running.
|
||||||
|
```
|
||||||
|
# kubectl get pods
|
||||||
|
```
|
||||||
|
You should receive output similar to what follows.
|
||||||
|
```
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
hello-world-54764dfbf8-q6l82 1/1 Running 0 6h
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|||||||
@@ -118,15 +118,15 @@ For more information about querying the Prometheus time series database, refer t
|
|||||||
|
|
||||||
| Catalog | Expression |
|
| Catalog | Expression |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Detail | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr></table> |
|
| Detail | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr></table> |
|
||||||
| Summary | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr></table> |
|
| Summary | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr></table> |
|
||||||
|
|
||||||
### Cluster Network I/O
|
### Cluster Network I/O
|
||||||
|
|
||||||
| Catalog | Expression |
|
| Catalog | Expression |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Detail | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr></table> |
|
| Detail | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m])) by (instance)</code></td></tr></table> |
|
||||||
| Summary | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr></table> |
|
| Summary | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*"}[5m]))</code></td></tr></table> |
|
||||||
|
|
||||||
# Node Metrics
|
# Node Metrics
|
||||||
|
|
||||||
@@ -169,15 +169,15 @@ For more information about querying the Prometheus time series database, refer t
|
|||||||
|
|
||||||
| Catalog | Expression |
|
| Catalog | Expression |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Detail | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr></table> |
|
| Detail | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr></table> |
|
||||||
| Summary | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr></table> |
|
| Summary | <table><tr><td>receive-dropped</td><td><code>sum(rate(node_network_receive_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>receive-errs</td><td><code>sum(rate(node_network_receive_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>receive-packets</td><td><code>sum(rate(node_network_receive_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-dropped</td><td><code>sum(rate(node_network_transmit_drop_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-errs</td><td><code>sum(rate(node_network_transmit_errs_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit-packets</td><td><code>sum(rate(node_network_transmit_packets_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr></table> |
|
||||||
|
|
||||||
### Node Network I/O
|
### Node Network I/O
|
||||||
|
|
||||||
| Catalog | Expression |
|
| Catalog | Expression |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Detail | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr></table> |
|
| Detail | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m])) by (device)</code></td></tr></table> |
|
||||||
| Summary | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr></table> |
|
| Summary | <table><tr><td>receive</td><td><code>sum(rate(node_network_receive_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr><tr><td>transmit</td><td><code>sum(rate(node_network_transmit_bytes_total{device!~"lo | veth.* | docker.* | flannel.* | cali.* | cbr.*",instance=~"$instance"}[5m]))</code></td></tr></table> |
|
||||||
|
|
||||||
# Etcd Metrics
|
# Etcd Metrics
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -43,7 +43,7 @@ ServiceMonitors and PodMonitors declaratively specify targets, such as Services
|
|||||||
1. The internal component responds by pushing metrics back to the proxy.
|
1. The internal component responds by pushing metrics back to the proxy.
|
||||||
|
|
||||||
|
|
||||||
<figcaption><br>Process for Exporting Metrics with PushProx:</br></figcaption>
|
<figcaption><br/>Process for Exporting Metrics with PushProx:<br/></figcaption>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|||||||
@@ -62,4 +62,4 @@ After a cluster is created with Rancher, a cluster administrator can manage clus
|
|||||||
|
|
||||||
The following table summarizes the options and settings available for each cluster type:
|
The following table summarizes the options and settings available for each cluster type:
|
||||||
|
|
||||||
{{% include file="/rancher/v2.5/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.5/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|||||||
+15
-15
@@ -937,7 +937,7 @@ on the master node and set the `--service-account-key-file` parameter
|
|||||||
to the public key file for service accounts:
|
to the public key file for service accounts:
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--service-account-key-file=<filename>
|
`--service-account-key-file=<filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -962,8 +962,8 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the **etcd** certificate and **key** file parameters.
|
on the master node and set the **etcd** certificate and **key** file parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--etcd-certfile=<path/to/client-certificate-file>
|
`--etcd-certfile=<path/to/client-certificate-file>`
|
||||||
--etcd-keyfile=<path/to/client-key-file>
|
`--etcd-keyfile=<path/to/client-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -988,8 +988,8 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the TLS certificate and private key file parameters.
|
on the master node and set the TLS certificate and private key file parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1014,7 +1014,7 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the client certificate authority file.
|
on the master node and set the client certificate authority file.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1039,7 +1039,7 @@ Then, edit the API server pod specification file `/etc/kubernetes/manifests/kube
|
|||||||
on the master node and set the etcd certificate authority file parameter.
|
on the master node and set the etcd certificate authority file parameter.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--etcd-cafile=<path/to/ca-file>
|
`--etcd-cafile=<path/to/ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1201,7 +1201,7 @@ on the master node and set the `--service-account-private-key-file` parameter
|
|||||||
to the private key file for service accounts.
|
to the private key file for service accounts.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--service-account-private-key-file=<filename>
|
`--service-account-private-key-file=<filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1225,7 +1225,7 @@ Edit the Controller Manager pod specification file `/etc/kubernetes/manifests/ku
|
|||||||
on the master node and set the `--root-ca-file` parameter to the certificate bundle file`.
|
on the master node and set the `--root-ca-file` parameter to the certificate bundle file`.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--root-ca-file=<path/to/file>
|
`--root-ca-file=<path/to/file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1343,8 +1343,8 @@ Then, edit the etcd pod specification file `/etc/kubernetes/manifests/etcd.yaml`
|
|||||||
on the master node and set the below parameters.
|
on the master node and set the below parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--cert-file=</path/to/ca-file>
|
`--cert-file=</path/to/ca-file>`
|
||||||
--key-file=</path/to/key-file>
|
`--key-file=</path/to/key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1417,8 +1417,8 @@ for your etcd cluster. Then, edit the etcd pod specification file `/etc/kubernet
|
|||||||
master node and set the below parameters.
|
master node and set the below parameters.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--peer-client-file=</path/to/peer-cert-file>
|
`--peer-client-file=</path/to/peer-cert-file>`
|
||||||
--peer-key-file=</path/to/peer-key-file>
|
`--peer-key-file=</path/to/peer-key-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1634,7 +1634,7 @@ chown root:root /etc/kubernetes/ssl/kubecfg-kube-node.yaml
|
|||||||
Run the following command to modify the file permissions of the
|
Run the following command to modify the file permissions of the
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file chmod 644 <filename>
|
`--client-ca-file chmod 644 <filename>`
|
||||||
```
|
```
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1779,7 +1779,7 @@ If using command line arguments, edit the kubelet service file
|
|||||||
set the below parameter in `KUBELET_AUTHZ_ARGS` variable.
|
set the below parameter in `KUBELET_AUTHZ_ARGS` variable.
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
```
|
```
|
||||||
|
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
|
|||||||
+23
-23
@@ -651,7 +651,7 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --basic-auth-file=<filename> parameter.
|
on the master node and remove the `--basic-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -679,7 +679,7 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --token-auth-file=<filename> parameter.
|
on the master node and remove the `--token-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -766,8 +766,8 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
Follow the Kubernetes documentation and setup the TLS connection between
|
Follow the Kubernetes documentation and setup the TLS connection between
|
||||||
the apiserver and kubelets. Then, edit the API server pod specification file
|
the apiserver and kubelets. Then, edit the API server pod specification file
|
||||||
/etc/kubernetes/manifests/kube-apiserver.yaml on the master node and set the
|
/etc/kubernetes/manifests/kube-apiserver.yaml on the master node and set the
|
||||||
--kubelet-certificate-authority parameter to the path to the cert file for the certificate authority.
|
`--kubelet-certificate-authority` parameter to the path to the cert file for the certificate authority.
|
||||||
--kubelet-certificate-authority=<ca-string>
|
`--kubelet-certificate-authority=<ca-string>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1379,7 +1379,7 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the --service-account-key-file parameter
|
on the master node and set the --service-account-key-file parameter
|
||||||
to the public key file for service accounts:
|
to the public key file for service accounts:
|
||||||
--service-account-key-file=<filename>
|
`--service-account-key-file=<filename>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1408,8 +1408,8 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
||||||
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the etcd certificate and key file parameters.
|
on the master node and set the etcd certificate and key file parameters.
|
||||||
--etcd-certfile=<path/to/client-certificate-file>
|
`--etcd-certfile=<path/to/client-certificate-file>`
|
||||||
--etcd-keyfile=<path/to/client-key-file>
|
`--etcd-keyfile=<path/to/client-key-file>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1438,8 +1438,8 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
||||||
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the TLS certificate and private key file parameters.
|
on the master node and set the TLS certificate and private key file parameters.
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1468,7 +1468,7 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
|
||||||
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the client certificate authority file.
|
on the master node and set the client certificate authority file.
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1497,7 +1497,7 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
|
||||||
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and set the etcd certificate authority file parameter.
|
on the master node and set the etcd certificate authority file parameter.
|
||||||
--etcd-cafile=<path/to/ca-file>
|
`--etcd-cafile=<path/to/ca-file>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1717,7 +1717,7 @@ root 4788 4773 4 16:16 ? 00:00:09 kube-controller-manager --co
|
|||||||
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
|
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
|
||||||
on the master node and set the --service-account-private-key-file parameter
|
on the master node and set the --service-account-private-key-file parameter
|
||||||
to the private key file for service accounts.
|
to the private key file for service accounts.
|
||||||
--service-account-private-key-file=<filename>
|
`--service-account-private-key-file=<filename>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1745,7 +1745,7 @@ root 4788 4773 4 16:16 ? 00:00:09 kube-controller-manager --co
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
|
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
|
||||||
on the master node and set the --root-ca-file parameter to the certificate bundle file`.
|
on the master node and set the --root-ca-file parameter to the certificate bundle file`.
|
||||||
--root-ca-file=<path/to/file>
|
`--root-ca-file=<path/to/file>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1877,8 +1877,8 @@ root 4947 4930 1 16:16 ? 00:00:02 kube-scheduler --kubeconfig=
|
|||||||
Follow the etcd service documentation and configure TLS encryption.
|
Follow the etcd service documentation and configure TLS encryption.
|
||||||
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml
|
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml
|
||||||
on the master node and set the below parameters.
|
on the master node and set the below parameters.
|
||||||
--cert-file=</path/to/ca-file>
|
`--cert-file=</path/to/ca-file>`
|
||||||
--key-file=</path/to/key-file>
|
`--key-file=</path/to/key-file>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -1973,8 +1973,8 @@ Follow the etcd service documentation and configure peer TLS encryption as appro
|
|||||||
for your etcd cluster.
|
for your etcd cluster.
|
||||||
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
|
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
|
||||||
master node and set the below parameters.
|
master node and set the below parameters.
|
||||||
--peer-client-file=</path/to/peer-cert-file>
|
`--peer-client-file=</path/to/peer-cert-file>`
|
||||||
--peer-key-file=</path/to/peer-key-file>
|
`--peer-key-file=</path/to/peer-key-file>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -2070,7 +2070,7 @@ Follow the etcd documentation and create a dedicated certificate authority setup
|
|||||||
etcd service.
|
etcd service.
|
||||||
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
|
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
|
||||||
master node and set the below parameter.
|
master node and set the below parameter.
|
||||||
--trusted-ca-file=</path/to/ca-file>
|
`--trusted-ca-file=</path/to/ca-file>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -2292,7 +2292,7 @@ root:root
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the file permissions of the
|
Run the following command to modify the file permissions of the
|
||||||
--client-ca-file chmod 644 <filename>
|
`--client-ca-file chmod 644 <filename>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -2322,7 +2322,7 @@ if test -e $CAFILE; then stat -c permissions=%a $CAFILE; fi
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the ownership of the --client-ca-file.
|
Run the following command to modify the ownership of the --client-ca-file.
|
||||||
chown root:root <filename>
|
`chown root:root <filename>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -2450,7 +2450,7 @@ the location of the client CA file.
|
|||||||
If using command line arguments, edit the kubelet service file
|
If using command line arguments, edit the kubelet service file
|
||||||
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
||||||
set the below parameter in KUBELET_AUTHZ_ARGS variable.
|
set the below parameter in KUBELET_AUTHZ_ARGS variable.
|
||||||
--client-ca-file=<path/to/client-ca-file>
|
`--client-ca-file=<path/to/client-ca-file>`
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
systemctl restart kubelet.service
|
systemctl restart kubelet.service
|
||||||
@@ -2643,8 +2643,8 @@ to the location of the corresponding private key file.
|
|||||||
If using command line arguments, edit the kubelet service file
|
If using command line arguments, edit the kubelet service file
|
||||||
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
|
||||||
set the below parameters in KUBELET_CERTIFICATE_ARGS variable.
|
set the below parameters in KUBELET_CERTIFICATE_ARGS variable.
|
||||||
--tls-cert-file=<path/to/tls-certificate-file>
|
`--tls-cert-file=<path/to/tls-certificate-file>`
|
||||||
--tls-private-key-file=<path/to/tls-key-file>
|
`--tls-private-key-file=<path/to/tls-key-file>`
|
||||||
Based on your system, restart the kubelet service. For example:
|
Based on your system, restart the kubelet service. For example:
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
systemctl restart kubelet.service
|
systemctl restart kubelet.service
|
||||||
|
|||||||
+3
-2
@@ -18,7 +18,8 @@ In this command, `<DATE>` is a placeholder for the date that the data container
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the [procedure below](#creating-a-backup).
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the [procedure below](#creating-a-backup).
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
@@ -49,7 +50,7 @@ This procedure creates a backup that you can restore if Rancher encounters a dis
|
|||||||
docker create --volumes-from <RANCHER_CONTAINER_NAME> --name rancher-data-<DATE> rancher/rancher:<RANCHER_CONTAINER_TAG>
|
docker create --volumes-from <RANCHER_CONTAINER_NAME> --name rancher-data-<DATE> rancher/rancher:<RANCHER_CONTAINER_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
1. <a id="tarball"></a>From the data container that you just created (`rancher-data-<DATE>`), create a backup tarball (`rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz`). Use the following command, replacing each placeholder:
|
1. <a id="tarball"></a>From the data container that you just created (<code>rancher-data-<DATE></code>), create a backup tarball (<code>rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz</code>). Use the following command, replacing each placeholder:
|
||||||
|
|
||||||
```
|
```
|
||||||
docker run --volumes-from rancher-data-<DATE> -v $PWD:/backup:z busybox tar pzcvf /backup/rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz /var/lib/rancher
|
docker run --volumes-from rancher-data-<DATE> -v $PWD:/backup:z busybox tar pzcvf /backup/rancher-data-backup-<RANCHER_VERSION>-<DATE>.tar.gz /var/lib/rancher
|
||||||
|
|||||||
+2
-1
@@ -20,7 +20,8 @@ In this command, `<RANCHER_CONTAINER_NAME>` and `<RANCHER_VERSION>-<DATE>` are e
|
|||||||
|
|
||||||
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
Cross reference the image and reference table below to learn how to obtain this placeholder data. Write down or copy this information before starting the procedure below.
|
||||||
|
|
||||||
<sup>Terminal `docker ps` Command, Displaying Where to Find `<RANCHER_CONTAINER_TAG>` and `<RANCHER_CONTAINER_NAME>`</sup>
|
<sup>Terminal <code>docker ps</code> Command, Displaying Where to Find <code><RANCHER_CONTAINER_TAG></code> and <code><RANCHER_CONTAINER_NAME></code></sup>
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
| Placeholder | Example | Description |
|
| Placeholder | Example | Description |
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ This page covers the following topics:
|
|||||||
|
|
||||||
After clusters have been [provisioned into Rancher]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/), [cluster owners]({{<baseurl>}}/rancher/v2.6/en/admin-settings/rbac/cluster-project-roles/#cluster-roles) will need to manage these clusters. There are many different options of how to manage your cluster.
|
After clusters have been [provisioned into Rancher]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/), [cluster owners]({{<baseurl>}}/rancher/v2.6/en/admin-settings/rbac/cluster-project-roles/#cluster-roles) will need to manage these clusters. There are many different options of how to manage your cluster.
|
||||||
|
|
||||||
{{% include file="/rancher/v2.6/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.6/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
## Configuring Tools
|
## Configuring Tools
|
||||||
|
|
||||||
|
|||||||
+3
-3
@@ -296,8 +296,8 @@ This table shows cluster-autoscaler parameters for fine tuning:
|
|||||||
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
||||||
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
||||||
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
||||||
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
cloud-provider|-|Cloud provider type|
|
cloud-provider|-|Cloud provider type|
|
||||||
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
||||||
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
||||||
@@ -307,7 +307,7 @@ cloud-provider|-|Cloud provider type|
|
|||||||
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
||||||
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
||||||
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
||||||
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: <min>:<max>:<other...>|
|
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: `<min>:<max>:<other...>`|
|
||||||
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
||||||
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
||||||
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
||||||
|
|||||||
+1
-1
@@ -24,5 +24,5 @@ The options and settings available for an existing cluster change based on the m
|
|||||||
|
|
||||||
The following table summarizes the options and settings available for each cluster type:
|
The following table summarizes the options and settings available for each cluster type:
|
||||||
|
|
||||||
{{% include file="/rancher/v2.6/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.6/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
|
|||||||
+3
-2
@@ -209,7 +209,8 @@ For the complete reference for configurable options for RKE Kubernetes clusters
|
|||||||
|
|
||||||
RKE (Rancher Kubernetes Engine) is the tool that Rancher uses to provision Kubernetes clusters. Rancher's cluster config files used to have the same structure as [RKE config files,]({{<baseurl>}}/rke/latest/en/example-yamls/) but the structure changed so that in Rancher, RKE cluster config items are separated from non-RKE config items. Therefore, configuration for your cluster needs to be nested under the `rancher_kubernetes_engine_config` directive in the cluster config file. Cluster config files created with earlier versions of Rancher will need to be updated for this format. An example cluster config file is included below.
|
RKE (Rancher Kubernetes Engine) is the tool that Rancher uses to provision Kubernetes clusters. Rancher's cluster config files used to have the same structure as [RKE config files,]({{<baseurl>}}/rke/latest/en/example-yamls/) but the structure changed so that in Rancher, RKE cluster config items are separated from non-RKE config items. Therefore, configuration for your cluster needs to be nested under the `rancher_kubernetes_engine_config` directive in the cluster config file. Cluster config files created with earlier versions of Rancher will need to be updated for this format. An example cluster config file is included below.
|
||||||
|
|
||||||
{{% accordion id="v2.3.0-cluster-config-file" label="Example Cluster Config File" %}}
|
<details id="v2.3.0-cluster-config-file">
|
||||||
|
<summary>Example Cluster Config File</summary>
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
#
|
#
|
||||||
@@ -301,7 +302,7 @@ rancher_kubernetes_engine_config: # Your RKE template config goes here.
|
|||||||
ssh_agent_auth: false
|
ssh_agent_auth: false
|
||||||
windows_prefered_cluster: false
|
windows_prefered_cluster: false
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Default DNS provider
|
### Default DNS provider
|
||||||
|
|
||||||
|
|||||||
@@ -28,7 +28,7 @@ This section covers the following topics:
|
|||||||
|
|
||||||
The following table summarizes the options and settings available for each cluster type:
|
The following table summarizes the options and settings available for each cluster type:
|
||||||
|
|
||||||
{{% include file="/rancher/v2.6/en/cluster-provisioning/cluster-capabilities-table" %}}
|
{{% include file="/rancher/v2.6/en/cluster-provisioning/cluster-capabilities-table</summary>
|
||||||
|
|
||||||
# Setting up Clusters in a Hosted Kubernetes Provider
|
# Setting up Clusters in a Hosted Kubernetes Provider
|
||||||
|
|
||||||
|
|||||||
+25
-23
@@ -80,30 +80,32 @@ Only hosts expected to be load balancer back ends need to be in this group.
|
|||||||
necessary. Your Cloud Provider Configuration **must** match the fields in the Machine Pools section. If you have multiple pools, they must all use the same Resource Group, Availability Set, Subnet, Virtual Network, and Network Security Group.
|
necessary. Your Cloud Provider Configuration **must** match the fields in the Machine Pools section. If you have multiple pools, they must all use the same Resource Group, Availability Set, Subnet, Virtual Network, and Network Security Group.
|
||||||
* An example is provided below. You will modify it as needed.
|
* An example is provided below. You will modify it as needed.
|
||||||
|
|
||||||
{{% accordion id="v2.6.0-cloud-provider-config-file" label="Example Cloud Provider Config" %}}
|
<details id="v2.6.0-cloud-provider-config-file">
|
||||||
|
<summary>Example Cloud Provider Config</summary>
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
{
|
{
|
||||||
"cloud":"AzurePublicCloud",
|
"cloud":"AzurePublicCloud",
|
||||||
"tenantId": "YOUR TENANTID HERE",
|
"tenantId": "YOUR TENANTID HERE",
|
||||||
"aadClientId": "YOUR AADCLIENTID HERE",
|
"aadClientId": "YOUR AADCLIENTID HERE",
|
||||||
"aadClientSecret": "YOUR AADCLIENTSECRET HERE",
|
"aadClientSecret": "YOUR AADCLIENTSECRET HERE",
|
||||||
"subscriptionId": "YOUR SUBSCRIPTIONID HERE",
|
"subscriptionId": "YOUR SUBSCRIPTIONID HERE",
|
||||||
"resourceGroup": "docker-machine",
|
"resourceGroup": "docker-machine",
|
||||||
"location": "westus",
|
"location": "westus",
|
||||||
"subnetName": "docker-machine",
|
"subnetName": "docker-machine",
|
||||||
"securityGroupName": "rancher-managed-KA4jV9V2",
|
"securityGroupName": "rancher-managed-KA4jV9V2",
|
||||||
"securityGroupResourceGroup": "docker-machine",
|
"securityGroupResourceGroup": "docker-machine",
|
||||||
"vnetName": "docker-machine-vnet",
|
"vnetName": "docker-machine-vnet",
|
||||||
"vnetResourceGroup": "docker-machine",
|
"vnetResourceGroup": "docker-machine",
|
||||||
"primaryAvailabilitySetName": "docker-machine",
|
"primaryAvailabilitySetName": "docker-machine",
|
||||||
"routeTableResourceGroup": "docker-machine",
|
"routeTableResourceGroup": "docker-machine",
|
||||||
"cloudProviderBackoff": false,
|
"cloudProviderBackoff": false,
|
||||||
"useManagedIdentityExtension": false,
|
"useManagedIdentityExtension": false,
|
||||||
"useInstanceMetadata": true
|
"useInstanceMetadata": true
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
{{% /accordion %}}
|
|
||||||
|
</details>
|
||||||
|
|
||||||
1. Under the **Cluster Configuration > Advanced** section, click **Add** under **Additional Controller Manager Args** and add this flag: `--configure-cloud-routes=false`
|
1. Under the **Cluster Configuration > Advanced** section, click **Add** under **Additional Controller Manager Args** and add this flag: `--configure-cloud-routes=false`
|
||||||
|
|
||||||
|
|||||||
@@ -66,7 +66,7 @@ The Helm chart in the git repository must include its dependencies in the charts
|
|||||||
---
|
---
|
||||||
* **Known Issue:** clientSecretName and helmSecretName secrets for Fleet gitrepos are not included in the backup nor restore created by the [backup-restore-operator]({{<baseurl>}}/rancher/v2.6/en/backups/back-up-rancher/#1-install-the-rancher-backups-operator). We will update the community once a permanent solution is in place.
|
* **Known Issue:** clientSecretName and helmSecretName secrets for Fleet gitrepos are not included in the backup nor restore created by the [backup-restore-operator]({{<baseurl>}}/rancher/v2.6/en/backups/back-up-rancher/#1-install-the-rancher-backups-operator). We will update the community once a permanent solution is in place.
|
||||||
|
|
||||||
* **Temporary Workaround:** </br>
|
* **Temporary Workaround:** <br/>
|
||||||
By default, user-defined secrets are not backed up in Fleet. It is necessary to recreate secrets if performing a disaster recovery restore or migration of Rancher into a fresh cluster. To modify resourceSet to include extra resources you want to backup, refer to docs [here](https://github.com/rancher/backup-restore-operator#user-flow).
|
By default, user-defined secrets are not backed up in Fleet. It is necessary to recreate secrets if performing a disaster recovery restore or migration of Rancher into a fresh cluster. To modify resourceSet to include extra resources you want to backup, refer to docs [here](https://github.com/rancher/backup-restore-operator#user-flow).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -17,13 +17,13 @@ For users looking to use another container runtime, Rancher has the edge-focused
|
|||||||
|
|
||||||
### FAQ
|
### FAQ
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
Q. Do I have to upgrade Rancher to get Rancher’s support of the upstream Dockershim?
|
Q. Do I have to upgrade Rancher to get Rancher’s support of the upstream Dockershim?
|
||||||
|
|
||||||
The upstream support of Dockershim begins for RKE in Kubernetes 1.21. You will need to be on Rancher 2.6 or above to have support for RKE with Kubernetes 1.21. See our [support matrix](https://rancher.com/support-maintenance-terms/all-supported-versions/rancher-v2.6.0/) for details.
|
The upstream support of Dockershim begins for RKE in Kubernetes 1.21. You will need to be on Rancher 2.6 or above to have support for RKE with Kubernetes 1.21. See our [support matrix](https://rancher.com/support-maintenance-terms/all-supported-versions/rancher-v2.6.0/) for details.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
Q. I am currently on RKE with Kubernetes 1.20. Do I need to upgrade to RKE with Kubernetes 1.21 sooner to avoid being out of support for Dockershim?
|
Q. I am currently on RKE with Kubernetes 1.20. Do I need to upgrade to RKE with Kubernetes 1.21 sooner to avoid being out of support for Dockershim?
|
||||||
|
|
||||||
@@ -31,16 +31,16 @@ A. The version of Dockershim in RKE with Kubernetes 1.20 will continue to work a
|
|||||||
|
|
||||||
For more information on the deprecation and its timeline, see the [Kubernetes Dockershim Deprecation FAQ](https://kubernetes.io/blog/2020/12/02/dockershim-faq/#when-will-dockershim-be-removed).
|
For more information on the deprecation and its timeline, see the [Kubernetes Dockershim Deprecation FAQ](https://kubernetes.io/blog/2020/12/02/dockershim-faq/#when-will-dockershim-be-removed).
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
Q: What are my other options if I don’t want to depend on the Dockershim?
|
Q: What are my other options if I don’t want to depend on the Dockershim?
|
||||||
|
|
||||||
A: You can use a runtime like containerd with Kubernetes that does not require Dockershim support. RKE2 or K3s are two options for doing this.
|
A: You can use a runtime like containerd with Kubernetes that does not require Dockershim support. RKE2 or K3s are two options for doing this.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
Q: If I am already using RKE1 and want to switch to RKE2, what are my migration options?
|
Q: If I am already using RKE1 and want to switch to RKE2, what are my migration options?
|
||||||
|
|
||||||
A: Rancher is exploring the possibility of an in-place upgrade path. Alternatively you can always migrate workloads from one cluster to another using kubectl.
|
A: Rancher is exploring the possibility of an in-place upgrade path. Alternatively you can always migrate workloads from one cluster to another using kubectl.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|||||||
@@ -7,25 +7,25 @@ This FAQ is a work in progress designed to answers the questions our users most
|
|||||||
|
|
||||||
See [Technical FAQ]({{<baseurl>}}/rancher/v2.6/en/faq/technical/), for frequently asked technical questions.
|
See [Technical FAQ]({{<baseurl>}}/rancher/v2.6/en/faq/technical/), for frequently asked technical questions.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Does Rancher v2.x support Docker Swarm and Mesos as environment types?**
|
**Does Rancher v2.x support Docker Swarm and Mesos as environment types?**
|
||||||
|
|
||||||
When creating an environment in Rancher v2.x, Swarm and Mesos will no longer be standard options you can select. However, both Swarm and Mesos will continue to be available as Catalog applications you can deploy. It was a tough decision to make but, in the end, it came down to adoption. For example, out of more than 15,000 clusters, only about 200 or so are running Swarm.
|
When creating an environment in Rancher v2.x, Swarm and Mesos will no longer be standard options you can select. However, both Swarm and Mesos will continue to be available as Catalog applications you can deploy. It was a tough decision to make but, in the end, it came down to adoption. For example, out of more than 15,000 clusters, only about 200 or so are running Swarm.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Is it possible to manage Azure Kubernetes Services with Rancher v2.x?**
|
**Is it possible to manage Azure Kubernetes Services with Rancher v2.x?**
|
||||||
|
|
||||||
Yes.
|
Yes.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Does Rancher support Windows?**
|
**Does Rancher support Windows?**
|
||||||
|
|
||||||
As of Rancher 2.3.0, we support Windows Server 1809 containers. For details on how to set up a cluster with Windows worker nodes, refer to the section on [configuring custom clusters for Windows.]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/windows-clusters/)
|
As of Rancher 2.3.0, we support Windows Server 1809 containers. For details on how to set up a cluster with Windows worker nodes, refer to the section on [configuring custom clusters for Windows.]({{<baseurl>}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/windows-clusters/)
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Does Rancher support Istio?**
|
**Does Rancher support Istio?**
|
||||||
|
|
||||||
@@ -33,37 +33,37 @@ As of Rancher 2.3.0, we support [Istio.]({{<baseurl>}}/rancher/v2.6/en/istio/)
|
|||||||
|
|
||||||
Furthermore, Istio is implemented in our micro-PaaS "Rio", which works on Rancher 2.x along with any CNCF compliant Kubernetes cluster. You can read more about it [here](https://rio.io/)
|
Furthermore, Istio is implemented in our micro-PaaS "Rio", which works on Rancher 2.x along with any CNCF compliant Kubernetes cluster. You can read more about it [here](https://rio.io/)
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Will Rancher v2.x support Hashicorp's Vault for storing secrets?**
|
**Will Rancher v2.x support Hashicorp's Vault for storing secrets?**
|
||||||
|
|
||||||
Secrets management is on our roadmap but we haven't assigned it to a specific release yet.
|
Secrets management is on our roadmap but we haven't assigned it to a specific release yet.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Does Rancher v2.x support RKT containers as well?**
|
**Does Rancher v2.x support RKT containers as well?**
|
||||||
|
|
||||||
At this time, we only support Docker.
|
At this time, we only support Docker.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Does Rancher v2.x support Calico, Contiv, Contrail, Flannel, Weave net, etc., for embedded and registered Kubernetes?**
|
**Does Rancher v2.x support Calico, Contiv, Contrail, Flannel, Weave net, etc., for embedded and registered Kubernetes?**
|
||||||
|
|
||||||
Out-of-the-box, Rancher provides the following CNI network providers for Kubernetes clusters: Canal, Flannel, Calico and Weave. Always refer to the [Rancher Support Matrix](https://rancher.com/support-maintenance-terms/) for details about what is officially supported.
|
Out-of-the-box, Rancher provides the following CNI network providers for Kubernetes clusters: Canal, Flannel, Calico and Weave. Always refer to the [Rancher Support Matrix](https://rancher.com/support-maintenance-terms/) for details about what is officially supported.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Are you planning on supporting Traefik for existing setups?**
|
**Are you planning on supporting Traefik for existing setups?**
|
||||||
|
|
||||||
We don't currently plan on providing embedded Traefik support, but we're still exploring load-balancing approaches.
|
We don't currently plan on providing embedded Traefik support, but we're still exploring load-balancing approaches.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Can I import OpenShift Kubernetes clusters into v2.x?**
|
**Can I import OpenShift Kubernetes clusters into v2.x?**
|
||||||
|
|
||||||
Our goal is to run any upstream Kubernetes clusters. Therefore, Rancher v2.x should work with OpenShift, but we haven't tested it yet.
|
Our goal is to run any upstream Kubernetes clusters. Therefore, Rancher v2.x should work with OpenShift, but we haven't tested it yet.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**Are you going to integrate Longhorn?**
|
**Are you going to integrate Longhorn?**
|
||||||
|
|
||||||
|
|||||||
@@ -131,7 +131,7 @@ Cilium enables networking and network policies (L3, L4, and L7) in Kubernetes. B
|
|||||||
Cilium recommends kernel versions greater than 5.2 to be able to leverage the full potential of eBPF. Kubernetes workers should open TCP port `8472` for VXLAN and TCP port `4240` for health checks. In addition, ICMP 8/0 must be enabled for health checks. For more information, check [Cilium System Requirements](https://docs.cilium.io/en/latest/operations/system_requirements/#firewall-requirements).
|
Cilium recommends kernel versions greater than 5.2 to be able to leverage the full potential of eBPF. Kubernetes workers should open TCP port `8472` for VXLAN and TCP port `4240` for health checks. In addition, ICMP 8/0 must be enabled for health checks. For more information, check [Cilium System Requirements](https://docs.cilium.io/en/latest/operations/system_requirements/#firewall-requirements).
|
||||||
|
|
||||||
##### Ingress Routing Across Nodes in Cilium
|
##### Ingress Routing Across Nodes in Cilium
|
||||||
<br>
|
<br/>
|
||||||
By default, Cilium does not allow pods to contact pods on other nodes. To work around this, enable the ingress controller to route requests across nodes with a `CiliumNetworkPolicy`.
|
By default, Cilium does not allow pods to contact pods on other nodes. To work around this, enable the ingress controller to route requests across nodes with a `CiliumNetworkPolicy`.
|
||||||
|
|
||||||
After selecting the Cilium CNI and enabling Project Network Isolation for your new cluster, configure as follows:
|
After selecting the Cilium CNI and enabling Project Network Isolation for your new cluster, configure as follows:
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ weight: 8007
|
|||||||
|
|
||||||
The Hardening Guide is now located in the main [Security]({{<baseurl>}}/rancher/v2.6/en/security/) section.
|
The Hardening Guide is now located in the main [Security]({{<baseurl>}}/rancher/v2.6/en/security/) section.
|
||||||
|
|
||||||
<br>
|
<br/>
|
||||||
|
|
||||||
**What are the results of Rancher's Kubernetes cluster when it is CIS benchmarked?**
|
**What are the results of Rancher's Kubernetes cluster when it is CIS benchmarked?**
|
||||||
|
|
||||||
|
|||||||
@@ -118,7 +118,7 @@ This reference contains variables that you can use in `questions.yml` nested und
|
|||||||
| max_length | int | false | Max character length.|
|
| max_length | int | false | Max character length.|
|
||||||
| min | int | false | Min integer length. |
|
| min | int | false | Min integer length. |
|
||||||
| max | int | false | Max integer length. |
|
| max | int | false | Max integer length. |
|
||||||
| options | []string | false | Specify the options when the variable type is `enum`, for example: options:<br> - "ClusterIP" <br> - "NodePort" <br> - "LoadBalancer"|
|
| options | []string | false | Specify the options when the variable type is `enum`, for example: options:<br/> - "ClusterIP" <br/> - "NodePort" <br/> - "LoadBalancer"|
|
||||||
| valid_chars | string | false | Regular expression for input chars validation. |
|
| valid_chars | string | false | Regular expression for input chars validation. |
|
||||||
| invalid_chars | string | false | Regular expression for invalid input chars validation.|
|
| invalid_chars | string | false | Regular expression for invalid input chars validation.|
|
||||||
| subquestions | []subquestion | false| Add an array of subquestions.|
|
| subquestions | []subquestion | false| Add an array of subquestions.|
|
||||||
|
|||||||
+3
-2
@@ -113,7 +113,8 @@ There are three recommended options for the source of the certificate used for T
|
|||||||
|
|
||||||
This step is only required to use certificates issued by Rancher's generated CA (`ingress.tls.source=rancher`) or to request Let's Encrypt issued certificates (`ingress.tls.source=letsEncrypt`).
|
This step is only required to use certificates issued by Rancher's generated CA (`ingress.tls.source=rancher`) or to request Let's Encrypt issued certificates (`ingress.tls.source=letsEncrypt`).
|
||||||
|
|
||||||
{{% accordion id="cert-manager" label="Click to Expand" %}}
|
<details id="cert-manager">
|
||||||
|
<summary>Click to Expand</summary>
|
||||||
|
|
||||||
> **Important:** Recent changes to cert-manager require an upgrade. If you are upgrading Rancher and using a version of cert-manager older than v0.11.0, please see our [upgrade documentation]({{<baseurl>}}/rancher/v2.6/en/installation/resources/upgrading-cert-manager/).
|
> **Important:** Recent changes to cert-manager require an upgrade. If you are upgrading Rancher and using a version of cert-manager older than v0.11.0, please see our [upgrade documentation]({{<baseurl>}}/rancher/v2.6/en/installation/resources/upgrading-cert-manager/).
|
||||||
|
|
||||||
@@ -147,7 +148,7 @@ cert-manager-cainjector-577f6d9fd7-tr77l 1/1 Running 0 2m
|
|||||||
cert-manager-webhook-787858fcdb-nlzsq 1/1 Running 0 2m
|
cert-manager-webhook-787858fcdb-nlzsq 1/1 Running 0 2m
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### 5. Install Rancher with Helm and Your Chosen Certificate Option
|
### 5. Install Rancher with Helm and Your Chosen Certificate Option
|
||||||
|
|
||||||
|
|||||||
+9
-6
@@ -25,7 +25,8 @@ Choose from the following options:
|
|||||||
|
|
||||||
### Option A: Default Self-Signed Certificate
|
### Option A: Default Self-Signed Certificate
|
||||||
|
|
||||||
{{% accordion id="option-a" label="Click to expand" %}}
|
<details id="option-a">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
If you are installing Rancher in a development or testing environment where identity verification isn't a concern, install Rancher using the self-signed certificate that it generates. This installation option omits the hassle of generating a certificate yourself.
|
||||||
|
|
||||||
@@ -47,11 +48,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option B: Bring Your Own Certificate: Self-Signed
|
### Option B: Bring Your Own Certificate: Self-Signed
|
||||||
|
|
||||||
{{% accordion id="option-b" label="Click to expand" %}}
|
<details id="option-b">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
In development or testing environments where your team will access your Rancher server, create a self-signed certificate for use with your install so that your team can verify they're connecting to your instance of Rancher.
|
||||||
|
|
||||||
@@ -86,11 +88,12 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
### Option C: Bring Your Own Certificate: Signed by Recognized CA
|
||||||
|
|
||||||
{{% accordion id="option-c" label="Click to expand" %}}
|
<details id="option-c">
|
||||||
|
<summary>Click to expand</summary>
|
||||||
|
|
||||||
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
In development or testing environments where you're exposing an app publicly, use a certificate signed by a recognized CA so that your user base doesn't encounter security warnings.
|
||||||
|
|
||||||
@@ -122,7 +125,7 @@ docker run -d --restart=unless-stopped \
|
|||||||
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
<REGISTRY.YOURDOMAIN.COM:PORT>/rancher/rancher:<RANCHER_VERSION_TAG>
|
||||||
```
|
```
|
||||||
|
|
||||||
{{% /accordion %}}
|
</details>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user