mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-25 04:28:15 +00:00
update missing Chinese translation for latest and v2.8 (#1234)
- Cluster API - Deprecated features
This commit is contained in:
@@ -11,13 +11,13 @@
|
||||
"message": "快速入门指南",
|
||||
"description": "The label for category Quick Start Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Deploy Rancher": {
|
||||
"sidebar.tutorialSidebar.category.Deploying Rancher Server": {
|
||||
"message": "部署 Rancher",
|
||||
"description": "The label for category Deploy Rancher in sidebar tutorialSidebar"
|
||||
"description": "The label for category Deploying Rancher Server in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Deploy Workloads": {
|
||||
"sidebar.tutorialSidebar.category.Deploying Workloads": {
|
||||
"message": "部署工作负载",
|
||||
"description": "The label for category Deploy Workloads in sidebar tutorialSidebar"
|
||||
"description": "The label for category Deploying Workloads in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Installation and Upgrade": {
|
||||
"message": "安装和升级",
|
||||
@@ -95,9 +95,9 @@
|
||||
"message": "关于 RKE1 模板",
|
||||
"description": "The label for category About RKE1 Templates in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Manage Clusters": {
|
||||
"message": "管理集群",
|
||||
"description": "The label for category Manage Clusters in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Cluster Administration": {
|
||||
"message": "集群管理",
|
||||
"description": "The label for category Cluster Administration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Access Clusters": {
|
||||
"message": "访问集群",
|
||||
@@ -115,9 +115,9 @@
|
||||
"message": "配置存储示例",
|
||||
"description": "The label for category Provisioning Storage Examples in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Kubernetes Cluster Setup": {
|
||||
"sidebar.tutorialSidebar.category.Setting up a Kubernetes Cluster for Rancher Server": {
|
||||
"message": "Kubernetes 集群设置",
|
||||
"description": "The label for category Kubernetes Cluster Setup in sidebar tutorialSidebar"
|
||||
"description": "The label for category Setting up a Kubernetes Cluster for Rancher Server in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Infrastructure Setup": {
|
||||
"message": "基础设施设置",
|
||||
@@ -156,16 +156,16 @@
|
||||
"description": "The label for category Launch Kubernetes with Rancher in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Launching New Nodes in an Infra Provider": {
|
||||
"message": "在基础设施提供商中启动新节点",
|
||||
"message": "在基础设施提供商中使用新节点",
|
||||
"description": "The label for category Launching New Nodes in an Infra Provider in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.vSphere": {
|
||||
"message": "vSphere",
|
||||
"description": "The label for category vSphere in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Creating a vSphere Cluster": {
|
||||
"message": "创建 vSphere 集群",
|
||||
"description": "The label for category Creating a vSphere Cluster in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Nutanix": {
|
||||
"message": "Nutanix",
|
||||
"description": "The label for category Nutanix in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Creating a Nutanix AOS Cluster": {
|
||||
"message": "创建 Nutanix AOS 集群",
|
||||
"description": "The label for category Creating a Nutanix AOS Cluster in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Kubernetes Resources Setup": {
|
||||
"message": "Kubernetes 资源设置",
|
||||
@@ -183,9 +183,9 @@
|
||||
"message": "负载均衡和 Ingress Controller",
|
||||
"description": "The label for category Load Balancer and Ingress Controller in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Helm Charts in Rancher": {
|
||||
"message": "Rancher 中的 Helm Chart",
|
||||
"description": "The label for category Helm Charts in Rancher in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Helm Charts and Apps": {
|
||||
"message": "Helm Charts 和 Apps",
|
||||
"description": "The label for category Helm Charts and Apps in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Deploy Apps Across Clusters": {
|
||||
"message": "跨集群部署应用",
|
||||
@@ -199,13 +199,13 @@
|
||||
"message": "高级用户指南",
|
||||
"description": "The label for category Advanced User Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Manage Projects": {
|
||||
"message": "管理项目",
|
||||
"description": "The label for category Manage Projects in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Project Administration": {
|
||||
"message": "项目管理",
|
||||
"description": "The label for category Project Administration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Manage Project Resource Quotas": {
|
||||
"message": "管理项目资源配额",
|
||||
"description": "The label for category Manage Project Resource Quotas in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Project Resource Quotas": {
|
||||
"message": "项目资源配额",
|
||||
"description": "The label for category Project Resource Quotas in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Monitoring/Alerting Guides": {
|
||||
"message": "Monitoring/Alerting 指南",
|
||||
@@ -215,33 +215,33 @@
|
||||
"message": "Prometheus Federator 指南",
|
||||
"description": "The label for category Prometheus Federator Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Monitoring V2 Configuration Guides": {
|
||||
"message": "Monitoring V2 配置指南",
|
||||
"description": "The label for category Monitoring V2 Configuration Guides in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Monitoring Configuration Guides": {
|
||||
"message": "Monitoring 配置指南",
|
||||
"description": "The label for category Monitoring Configuration Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Advanced Configuration": {
|
||||
"message": "高级配置",
|
||||
"description": "The label for category Advanced Configuration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Istio Setup Guide": {
|
||||
"sidebar.tutorialSidebar.category.Istio Setup Guides": {
|
||||
"message": "Istio 设置指南",
|
||||
"description": "The label for category Istio Setup Guide in sidebar tutorialSidebar"
|
||||
"description": "The label for category Istio Setup Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.CIS Scan Guides": {
|
||||
"message": "CIS 扫描指南",
|
||||
"description": "The label for category CIS Scan Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Enable Experimental Features": {
|
||||
"sidebar.tutorialSidebar.category.Enabling Experimental Features": {
|
||||
"message": "启用实验功能",
|
||||
"description": "The label for category Enable Experimental Features in sidebar tutorialSidebar"
|
||||
"description": "The label for category Enabling Experimental Features in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Reference Guides": {
|
||||
"message": "参考指南",
|
||||
"description": "The label for category Reference Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Best Practices": {
|
||||
"sidebar.tutorialSidebar.category.Best Practice Guides": {
|
||||
"message": "最佳实践",
|
||||
"description": "The label for category Best Practices in sidebar tutorialSidebar"
|
||||
"description": "The label for category Best Practice Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Rancher Server": {
|
||||
"message": "Rancher Server",
|
||||
@@ -263,9 +263,9 @@
|
||||
"message": "Rancher Server 配置",
|
||||
"description": "The label for category Rancher Server Configuration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.GKE Cluster Configuration": {
|
||||
"sidebar.tutorialSidebar.category.GKE Cluster Configuration Reference": {
|
||||
"message": "GKE 集群配置",
|
||||
"description": "The label for category GKE Cluster Configuration in sidebar tutorialSidebar"
|
||||
"description": "The label for category GKE Cluster Configuration Reference in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Use Existing Nodes": {
|
||||
"message": "使用现有节点",
|
||||
@@ -291,9 +291,9 @@
|
||||
"message": "备份和恢复配置",
|
||||
"description": "The label for category Backup & Restore Configuration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Monitoring V2 Configuration": {
|
||||
"message": "Monitoring V2 配置",
|
||||
"description": "The label for category Monitoring V2 Configuration in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Monitoring Configuration Reference": {
|
||||
"message": "Monitoring 配置",
|
||||
"description": "The label for category Monitoring Configuration Reference in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Prometheus Federator": {
|
||||
"message": "Prometheus Federator",
|
||||
@@ -311,9 +311,9 @@
|
||||
"message": "关于 API",
|
||||
"description": "The label for category About the API in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Rancher Security": {
|
||||
"message": "Rancher 安全",
|
||||
"description": "The label for category Rancher Security in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Rancher Security Guides": {
|
||||
"message": "Rancher 安全指南",
|
||||
"description": "The label for category Rancher Security Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.SELinux RPM": {
|
||||
"message": "SELinux RPM",
|
||||
@@ -406,5 +406,9 @@
|
||||
"sidebar.tutorialSidebar.category.Container Security with Neuvector": {
|
||||
"message": "使用 NeuVector 实现容器安全",
|
||||
"description": "The label for category Container Security with Neuvector in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Cluster API (CAPI) with Rancher Turtles": {
|
||||
"message": "Cluster API (CAPI) 与 Rancher Turtles",
|
||||
"description": "The label for category Cluster API (CAPI) with Rancher Turtles in sidebar tutorialSidebar"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
---
|
||||
title: Rancher 中已弃用的功能
|
||||
---
|
||||
|
||||
<head>
|
||||
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/zh/faq/deprecated-features"/>
|
||||
</head>
|
||||
|
||||
### Rancher 的弃用策略是什么?
|
||||
|
||||
我们已经在支持的[服务条款](https://rancher.com/support-maintenance-terms)中发布了官方的弃用策略。
|
||||
|
||||
### 在哪里可以了解 Rancher 中已弃用哪些功能?
|
||||
|
||||
Rancher 将在 GitHub 上发布的 Rancher 的[发版说明](https://github.com/rancher/rancher/releases)中发布已弃用的功能。有关已弃用的功能,请参阅以下的补丁版本:
|
||||
|
||||
| Patch 版本 | 发布时间 |
|
||||
| --------------------------------------------------------------- | ------------------ |
|
||||
| [2.8.3](https://github.com/rancher/rancher/releases/tag/v2.8.3) | 2024 年 3 月 28 日 |
|
||||
| [2.8.2](https://github.com/rancher/rancher/releases/tag/v2.8.2) | 2024 年 2 月 8 日 |
|
||||
| [2.8.1](https://github.com/rancher/rancher/releases/tag/v2.8.1) | 2024 年 1 月 22 日 |
|
||||
| [2.8.0](https://github.com/rancher/rancher/releases/tag/v2.8.0) | 2023 年 12 月 6 日 |
|
||||
|
||||
### 当一个功能被标记为弃用我可以得到什么样的预期?
|
||||
|
||||
当功能被标记为“已弃用”时,它依然可用并得到支持,允许按照常规的流程进行升级。一旦升级完成,用户/管理员应开始计划在升级到标记为已移除的版本之前放弃使用已弃用的功能。对于新的部署,建议不要使用已弃用的功能。
|
||||
+14
@@ -0,0 +1,14 @@
|
||||
---
|
||||
title: Cluster API (CAPI) 与 Rancher Turtles
|
||||
---
|
||||
|
||||
<head>
|
||||
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/zh/integrations-in-rancher/cluster-api"/>
|
||||
</head>
|
||||
|
||||
[Rancher Turtles](https://turtles.docs.rancher.com/) 是一个 [Rancher 扩展](../rancher-extensions.md),通过提供 Cluster API (CAPI) 和 Rancher 之间的集成来管理配置的 Kubernetes 集群的生命周期。使用 Rancher Turtles,你可以:
|
||||
|
||||
- 通过在 CAPI 配置的集群中安装 Rancher Cluster Agent,将 CAPI 集群导入 Rancher。
|
||||
- 配置 [CAPI Operator](https://turtles.docs.rancher.com/docs/reference-guides/rancher-turtles-chart/values#cluster-api-operator-values)。
|
||||
|
||||
[概述](./overview.md)部分介绍了安装选项、Rancher Turtles 架构和简要 Demo。有关详细信息,请参阅 [Rancher Turtles 文档](https://turtles.docs.rancher.com/)。
|
||||
+221
@@ -0,0 +1,221 @@
|
||||
---
|
||||
title: 概述
|
||||
---
|
||||
|
||||
<head>
|
||||
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/zh/integrations-in-rancher/cluster-api/overview"/>
|
||||
</head>
|
||||
|
||||
## 架构图
|
||||
|
||||
下面是 Rancher Turtles 的关键组件及其与 Rancher 和 Rancher Cluster Agent 的关系的架构图,了解这些组件对于深入了解 Rancher 如何利用 CAPI operator 进行集群管理至关重要。
|
||||
|
||||

|
||||
|
||||
## 先决条件
|
||||
|
||||
在 Rancher 环境中安装 Rancher Turtles 之前,你必须禁用 Rancher 的 `embedded-cluster-api` 功能。这还包括清理 Rancher 专用的 webhook,否则这些 webhook 将与 CAPI 的 webhook 冲突。
|
||||
|
||||
为了简化 Rancher 安装 Rancher Turtles 的设置,官方的 Rancher Turtles Helm chart 包含一个删除以下内容的 `pre-install` hook:
|
||||
|
||||
- 禁用 Rancher 中的 `embedded-cluster-api` 功能。
|
||||
- 删除不再需要的 `mutating-webhook-configuration` 和 `validating-webhook-configuration` webhook。
|
||||
|
||||
## 安装 Rancher Turtles Operator
|
||||
|
||||
你可以通过 Rancher UI 或使用 Helm 安装 Rancher Turtles operator。对于大多数环境推荐使用第一种方法。
|
||||
|
||||
:::caution
|
||||
|
||||
如果你的集群中已经安装了 Cluster API (CAPI) Operator,你必须使用[手动 Helm 安装方法](#通过-helm-安装)。
|
||||
|
||||
:::
|
||||
|
||||
### 通过 Rancher UI 安装
|
||||
|
||||
通过 Rancher UI 添加 Turtles 仓库,Rancher 可以处理 CAPI 扩展的安装和配置。
|
||||
|
||||
1. 点击 **☰**。在左侧导航栏**浏览集群**的菜单下,选择 **local**。
|
||||
1. 在 **Cluster Dashboard** 的左侧导航菜单中,点击 **Apps > Repositories**。
|
||||
1. 点击 **Create** 创建一个新的仓库。
|
||||
1. 输入以下信息:
|
||||
- **Name**: turtles
|
||||
- **Index URL**: https://rancher.github.io/turtles
|
||||
1. 等待新的仓库状态更新为 `Active`。
|
||||
1. 在左侧导航菜单中,点击 **Apps > Charts**。
|
||||
1. 在搜索过滤器中输入 "turtles" 来查找 Turtles chart。
|
||||
1. 点击 **Rancher Turtles - the Cluster API Extension**。
|
||||
1. 点击 **Install > Next > Install**.
|
||||
|
||||
此过程使用 Helm chart 的默认值,这些值适用于大部分的安装场景。如果你的配置需要覆盖其中一些默认值,你可以在安装期间通过 Rancher UI 指定这些值,也可以通过 [Helm 手动安装 Chart](#通过-helm-安装)。有关可用的 values 设置的详细信息,请参阅 Rancher Turtles 的 [Helm chart 参考指南](https://turtles.docs.rancher.com/docs/reference-guides/rancher-turtles-chart/values)。
|
||||
|
||||
安装可能需要几分钟时间,安装完成后,你可以在集群中看到以下新部署:
|
||||
|
||||
- `rancher-turtles-system/rancher-turtles-controller-manager`
|
||||
- `rancher-turtles-system/rancher-turtles-cluster-api-operator`
|
||||
- `capi-system/capi-controller-manager`
|
||||
|
||||
#### Demo
|
||||
|
||||
这个 demo 演示了如何使用 Rancher UI 安装 Rancher Turtles、创建/导入一个 CAPI 集群,以及在集群上安装监控:
|
||||
|
||||
<iframe width="560" height="315" src="https://www.youtube.com/embed/lGsr7KfBjgU?si=ORkzuAJjcdXUXMxh" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
|
||||
|
||||
### 通过 Helm 安装
|
||||
|
||||
通过 Helm 安装 Rancher Turtles 有两种方法,这取决于你是否将 CAPI operator 作为依赖项包含其中:
|
||||
|
||||
- [使用 CAPI Operator 作为依赖项安装 Rancher Turtles](#使用-cluster-api-capi-operator-作为-helm-依赖项安装-rancher-turtles)。
|
||||
- [安装没有 CAPI Operator 的 Rancher Turtles](#不使用-cluster-api-capi-operator-作为-helm-依赖安装-rancher-turtles)。
|
||||
|
||||
安装 Rancher Turtles 需要 CAPI Operator。你可以选择自己处理此依赖项,还是让 Rancher Turtles Helm chart 替你管理它。[使用 CAPI Operator 作为依赖项安装 Rancher Turtles](#使用-cluster-api-capi-operator-作为-helm-依赖项安装-rancher-turtles) 更简单,但是你的最佳选择取决于你的具体配置。
|
||||
|
||||
CAPI Operator 允许使用声明式方法处理 CAPI provider 的生命周期,扩展了 `clusterctl` 的能力。如果你想了解更多相关内容,可以参考 [Cluster API Operator book](https://cluster-api-operator.sigs.k8s.io/)。
|
||||
|
||||
#### 使用 `Cluster API (CAPI) Operator` 作为 Helm 依赖项安装 Rancher Turtles
|
||||
|
||||
1. 添加包含 `rancher-turtles` chart 的 Helm 仓库作为安装的第一步:
|
||||
|
||||
```bash
|
||||
helm repo add turtles https://rancher.github.io/turtles
|
||||
helm repo update
|
||||
```
|
||||
|
||||
2. 如前面所述,安装 Rancher Turtles 需要 [CAPI Operator](https://github.com/kubernetes-sigs/cluster-api-operator)。Helm chart 可以使用一组最少的参数自动安装:
|
||||
|
||||
```bash
|
||||
helm install rancher-turtles turtles/rancher-turtles --version <version> \
|
||||
-n rancher-turtles-system \
|
||||
--dependency-update \
|
||||
--create-namespace --wait \
|
||||
--timeout 180s
|
||||
```
|
||||
|
||||
3. 此操作可能需要几分钟时间,完成后,你可以查看下面列出的已安装的控制器:
|
||||
|
||||
- `rancher-turtles-controller`
|
||||
- `capi-operator`
|
||||
|
||||
:::note
|
||||
|
||||
- 如果集群中已经有可用的 `cert-manager`,请在安装时通过以下参数将 Rancher Turtles 的此项依赖禁用掉,来阻止冲突:
|
||||
`--set cluster-api-operator.cert-manager.enabled=false`
|
||||
- 有关 Rancher Turtles 的版本列表,请参阅 [Turtles 发布页面](https://github.com/rancher/turtles/releases)。
|
||||
|
||||
:::
|
||||
|
||||
这是最基本的推荐配置,用于管理在核心提供商的命名空间中创建包含所需 CAPI 功能标志(已启用 `CLUSTER_TOPOLOGY`, `EXP_CLUSTER_RESOURCE_SET` 和 `EXP_MACHINE_POOL` )的 secret。要启用其他 CAPI 功能需要启用上述功能标志。
|
||||
|
||||
如果你需要覆盖默认的行为并使用现有 secret 或添加自定义环境变量,你可以将 secret 名称通过 Helm 参数传入。在这种情况下,你作为负责管理 secret 创建和内容的用户,需要启用的最少特性包括:`CLUSTER_TOPOLOGY`, `EXP_CLUSTER_RESOURCE_SET` 和 `EXP_MACHINE_POOL`。
|
||||
|
||||
```bash
|
||||
helm install ...
|
||||
# Passing secret name and namespace for additional environment variables
|
||||
--set cluster-api-operator.cluster-api.configSecret.name=<secret-name>
|
||||
```
|
||||
|
||||
以下是一个用户管理 secret `cluster-api-operator.cluster-api.configSecret.name=variables` 的示例,其中设置了 `CLUSTER_TOPOLOGY`, `EXP_CLUSTER_RESOURCE_SET` 和 `EXP_MACHINE_POOL` 功能以及一个额外的自定义变量:
|
||||
|
||||
```yaml title="secret.yaml"
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: variables
|
||||
namespace: rancher-turtles-system
|
||||
type: Opaque
|
||||
stringData:
|
||||
CLUSTER_TOPOLOGY: "true"
|
||||
EXP_CLUSTER_RESOURCE_SET: "true"
|
||||
EXP_MACHINE_POOL: "true"
|
||||
CUSTOM_ENV_VAR: "false"
|
||||
```
|
||||
|
||||
:::info
|
||||
|
||||
有关 chart 支持的 values 及其用法的详细信息,请参阅 [Helm chart 选项](https://turtles.docs.rancher.com/docs/reference-guides/rancher-turtles-chart/values)
|
||||
|
||||
:::
|
||||
|
||||
#### 不使用 `Cluster API (CAPI) Operator` 作为 Helm 依赖安装 Rancher Turtles
|
||||
|
||||
:::note
|
||||
|
||||
请记住,如果使用此安装选项,你必须自行管理 CAPI Operator 的安装。你可以参照 Rancher Turtles 文档中的 [CAPI Operator 指南](https://turtles.docs.rancher.com/docs/tasks/capi-operator/intro)
|
||||
|
||||
:::
|
||||
|
||||
1. 添加包含 `rancher-turtles` chart 的 Helm 仓库作为安装的第一步:
|
||||
|
||||
```bash
|
||||
helm repo add turtles https://rancher.github.io/turtles
|
||||
helm repo update
|
||||
```
|
||||
|
||||
2. 将 chart 安装到 `rancher-turtles-system` 命名空间:
|
||||
|
||||
```bash
|
||||
helm install rancher-turtles turtles/rancher-turtles --version <version>
|
||||
-n rancher-turtles-system
|
||||
--set cluster-api-operator.enabled=false
|
||||
--set cluster-api-operator.cluster-api.enabled=false
|
||||
--create-namespace --wait
|
||||
--dependency-update
|
||||
```
|
||||
|
||||
前面的命令告诉 Helm 忽略将 `cluster-api-operator` 作为依赖项安装。
|
||||
|
||||
3. 此操作可能需要几分钟,完成后你可以查看下面列出的已安装的控制器:
|
||||
|
||||
- `rancher-turtles-controller`
|
||||
|
||||
## 卸载 Rancher Turtles
|
||||
|
||||
:::caution
|
||||
|
||||
在 Rancher 环境中安装 Rancher Turtles 时,Rancher Turtles 默认会启用 CAPI Operator 清理。这包括清理 CAPI Operator 特定的 webhook 和 deployments,否则会导致 Rancher 配置出现问题。
|
||||
|
||||
为了简化 Rancher Turtles 卸载(通过 Rancher 或 Helm 命令),官方的 Rancher Turtles Helm chart 包含了一个删除以下内容的 `post-delete` hook:
|
||||
|
||||
- 删除不再需要的 `mutating-webhook-configuration` 和 `validating-webhook-configuration` webhook。
|
||||
- 删除不再需要的 CAPI `deployments`。
|
||||
|
||||
:::
|
||||
|
||||
卸载 Rancher Turtles:
|
||||
|
||||
```bash
|
||||
helm uninstall -n rancher-turtles-system rancher-turtles --cascade foreground --wait
|
||||
```
|
||||
|
||||
这可能需要几分钟才能完成。
|
||||
|
||||
:::note
|
||||
|
||||
请记住,如果你在安装时使用了不同的名称或不同的命名空间,你需要针对你的特定配置自定义卸载命令。
|
||||
|
||||
:::
|
||||
|
||||
卸载 Rancher Turtles 后, Rancher 的 `embedded-cluster-api` 功能必须重新启用。
|
||||
|
||||
1. 创建一个 `feature.yaml` 文件,将 `embedded-cluster-api` 设置为 true:
|
||||
|
||||
```yaml title="feature.yaml"
|
||||
apiVersion: management.cattle.io/v3
|
||||
kind: Feature
|
||||
metadata:
|
||||
name: embedded-cluster-api
|
||||
spec:
|
||||
value: true
|
||||
```
|
||||
|
||||
2. 使用 `kubectl` 将 `feature.yaml` 文件应用到集群:
|
||||
|
||||
```bash
|
||||
kubectl apply -f feature.yaml
|
||||
```
|
||||
|
||||
## 安全
|
||||
|
||||
[SLSA](https://slsa.dev/spec/v1.0/about) 是一套由行业共识制定的可逐步采用的供应链安全指南。SLSA 制定的规范对软件生产者和消费者都很有用:生产者可以遵循 SLSA 的指导方针,使他们的软件供应链更加安全,消费者可以使用 SLSA 来决定是否信任软件包。
|
||||
|
||||
Rancher Turtles 满足 [SLSA Level 3](https://slsa.dev/spec/v1.0/levels#build-l3) 对适当的构建平台、一致的构建过程和来源分布的要求。更多信息请参阅 [Rancher Turtles 安全](https://turtles.docs.rancher.com/docs/security/slsa)文档。
|
||||
@@ -11,13 +11,13 @@
|
||||
"message": "快速入门指南",
|
||||
"description": "The label for category Quick Start Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Deploy Rancher": {
|
||||
"sidebar.tutorialSidebar.category.Deploying Rancher Server": {
|
||||
"message": "部署 Rancher",
|
||||
"description": "The label for category Deploy Rancher in sidebar tutorialSidebar"
|
||||
"description": "The label for category Deploying Rancher Server in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Deploy Workloads": {
|
||||
"sidebar.tutorialSidebar.category.Deploying Workloads": {
|
||||
"message": "部署工作负载",
|
||||
"description": "The label for category Deploy Workloads in sidebar tutorialSidebar"
|
||||
"description": "The label for category Deploying Workloads in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Installation and Upgrade": {
|
||||
"message": "安装和升级",
|
||||
@@ -95,9 +95,9 @@
|
||||
"message": "关于 RKE1 模板",
|
||||
"description": "The label for category About RKE1 Templates in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Manage Clusters": {
|
||||
"message": "管理集群",
|
||||
"description": "The label for category Manage Clusters in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Cluster Administration": {
|
||||
"message": "集群管理",
|
||||
"description": "The label for category Cluster Administration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Access Clusters": {
|
||||
"message": "访问集群",
|
||||
@@ -115,9 +115,9 @@
|
||||
"message": "配置存储示例",
|
||||
"description": "The label for category Provisioning Storage Examples in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Kubernetes Cluster Setup": {
|
||||
"sidebar.tutorialSidebar.category.Setting up a Kubernetes Cluster for Rancher Server": {
|
||||
"message": "Kubernetes 集群设置",
|
||||
"description": "The label for category Kubernetes Cluster Setup in sidebar tutorialSidebar"
|
||||
"description": "The label for category Setting up a Kubernetes Cluster for Rancher Server in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Infrastructure Setup": {
|
||||
"message": "基础设施设置",
|
||||
@@ -147,7 +147,7 @@
|
||||
"message": "设置 Cloud Provider",
|
||||
"description": "The label for category Setting up Cloud Providers in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Launch Kubernetes with Rancher": {
|
||||
"sidebar.tutorialSidebar.category.Launching Kubernetes with Rancher": {
|
||||
"message": "使用 Rancher 启动 Kubernetes",
|
||||
"description": "The label for category Launch Kubernetes with Rancher in sidebar tutorialSidebar"
|
||||
},
|
||||
@@ -159,13 +159,13 @@
|
||||
"message": "在基础设施提供商中使用新节点",
|
||||
"description": "The label for category Launching New Nodes in an Infra Provider in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.vSphere": {
|
||||
"message": "vSphere",
|
||||
"description": "The label for category vSphere in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Creating a vSphere Cluster": {
|
||||
"message": "创建 vSphere 集群",
|
||||
"description": "The label for category Creating a vSphere Cluster in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Nutanix": {
|
||||
"message": "Nutanix",
|
||||
"description": "The label for category Nutanix in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Creating a Nutanix AOS Cluster": {
|
||||
"message": "创建 Nutanix AOS 集群",
|
||||
"description": "The label for category Creating a Nutanix AOS Cluster in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Kubernetes Resources Setup": {
|
||||
"message": "Kubernetes 资源设置",
|
||||
@@ -183,9 +183,9 @@
|
||||
"message": "负载均衡和 Ingress Controller",
|
||||
"description": "The label for category Load Balancer and Ingress Controller in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Helm Charts in Rancher": {
|
||||
"message": "Rancher 中的 Helm Chart",
|
||||
"description": "The label for category Helm Charts in Rancher in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Helm Charts and Apps": {
|
||||
"message": "Helm Charts 和 Apps",
|
||||
"description": "The label for category Helm Charts and Apps in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Deploy Apps Across Clusters": {
|
||||
"message": "跨集群部署应用",
|
||||
@@ -199,13 +199,13 @@
|
||||
"message": "高级用户指南",
|
||||
"description": "The label for category Advanced User Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Manage Projects": {
|
||||
"message": "管理项目",
|
||||
"description": "The label for category Manage Projects in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Project Administration": {
|
||||
"message": "项目管理",
|
||||
"description": "The label for category Project Administration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Manage Project Resource Quotas": {
|
||||
"message": "管理项目资源配额",
|
||||
"description": "The label for category Manage Project Resource Quotas in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Project Resource Quotas": {
|
||||
"message": "项目资源配额",
|
||||
"description": "The label for category Project Resource Quotas in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Monitoring/Alerting Guides": {
|
||||
"message": "Monitoring/Alerting 指南",
|
||||
@@ -215,33 +215,33 @@
|
||||
"message": "Prometheus Federator 指南",
|
||||
"description": "The label for category Prometheus Federator Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Monitoring V2 Configuration Guides": {
|
||||
"message": "Monitoring V2 配置指南",
|
||||
"description": "The label for category Monitoring V2 Configuration Guides in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Monitoring Configuration Guides": {
|
||||
"message": "Monitoring 配置指南",
|
||||
"description": "The label for category Monitoring Configuration Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Advanced Configuration": {
|
||||
"message": "高级配置",
|
||||
"description": "The label for category Advanced Configuration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Istio Setup Guide": {
|
||||
"sidebar.tutorialSidebar.category.Istio Setup Guides": {
|
||||
"message": "Istio 设置指南",
|
||||
"description": "The label for category Istio Setup Guide in sidebar tutorialSidebar"
|
||||
"description": "The label for category Istio Setup Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.CIS Scan Guides": {
|
||||
"message": "CIS 扫描指南",
|
||||
"description": "The label for category CIS Scan Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Enable Experimental Features": {
|
||||
"sidebar.tutorialSidebar.category.Enabling Experimental Features": {
|
||||
"message": "启用实验功能",
|
||||
"description": "The label for category Enable Experimental Features in sidebar tutorialSidebar"
|
||||
"description": "The label for category Enabling Experimental Features in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Reference Guides": {
|
||||
"message": "参考指南",
|
||||
"description": "The label for category Reference Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Best Practices": {
|
||||
"sidebar.tutorialSidebar.category.Best Practice Guides": {
|
||||
"message": "最佳实践",
|
||||
"description": "The label for category Best Practices in sidebar tutorialSidebar"
|
||||
"description": "The label for category Best Practice Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Rancher Server": {
|
||||
"message": "Rancher Server",
|
||||
@@ -263,9 +263,9 @@
|
||||
"message": "Rancher Server 配置",
|
||||
"description": "The label for category Rancher Server Configuration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.GKE Cluster Configuration": {
|
||||
"sidebar.tutorialSidebar.category.GKE Cluster Configuration Reference": {
|
||||
"message": "GKE 集群配置",
|
||||
"description": "The label for category GKE Cluster Configuration in sidebar tutorialSidebar"
|
||||
"description": "The label for category GKE Cluster Configuration Reference in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Use Existing Nodes": {
|
||||
"message": "使用现有节点",
|
||||
@@ -291,9 +291,9 @@
|
||||
"message": "备份和恢复配置",
|
||||
"description": "The label for category Backup & Restore Configuration in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Monitoring V2 Configuration": {
|
||||
"message": "Monitoring V2 配置",
|
||||
"description": "The label for category Monitoring V2 Configuration in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Monitoring Configuration Reference": {
|
||||
"message": "Monitoring 配置",
|
||||
"description": "The label for category Monitoring Configuration Reference in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Prometheus Federator": {
|
||||
"message": "Prometheus Federator",
|
||||
@@ -311,9 +311,9 @@
|
||||
"message": "关于 API",
|
||||
"description": "The label for category About the API in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Rancher Security": {
|
||||
"message": "Rancher 安全",
|
||||
"description": "The label for category Rancher Security in sidebar tutorialSidebar"
|
||||
"sidebar.tutorialSidebar.category.Rancher Security Guides": {
|
||||
"message": "Rancher 安全指南",
|
||||
"description": "The label for category Rancher Security Guides in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.SELinux RPM": {
|
||||
"message": "SELinux RPM",
|
||||
@@ -406,6 +406,10 @@
|
||||
"sidebar.tutorialSidebar.category.Container Security with Neuvector": {
|
||||
"message": "使用 NeuVector 实现容器安全",
|
||||
"description": "The label for category Container Security with Neuvector in sidebar tutorialSidebar"
|
||||
},
|
||||
"sidebar.tutorialSidebar.category.Cluster API (CAPI) with Rancher Turtles": {
|
||||
"message": "Cluster API (CAPI) 与 Rancher Turtles",
|
||||
"description": "The label for category Cluster API (CAPI) with Rancher Turtles in sidebar tutorialSidebar"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
---
|
||||
title: Rancher 中已弃用的功能
|
||||
---
|
||||
|
||||
<head>
|
||||
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/zh/faq/deprecated-features"/>
|
||||
</head>
|
||||
|
||||
### Rancher 的弃用策略是什么?
|
||||
|
||||
我们已经在支持的[服务条款](https://rancher.com/support-maintenance-terms)中发布了官方的弃用策略。
|
||||
|
||||
### 在哪里可以了解 Rancher 中已弃用哪些功能?
|
||||
|
||||
Rancher 将在 GitHub 上发布的 Rancher 的[发版说明](https://github.com/rancher/rancher/releases)中发布已弃用的功能。有关已弃用的功能,请参阅以下的补丁版本:
|
||||
|
||||
| Patch 版本 | 发布时间 |
|
||||
| --------------------------------------------------------------- | ------------------ |
|
||||
| [2.8.3](https://github.com/rancher/rancher/releases/tag/v2.8.3) | 2024 年 3 月 28 日 |
|
||||
| [2.8.2](https://github.com/rancher/rancher/releases/tag/v2.8.2) | 2024 年 2 月 8 日 |
|
||||
| [2.8.1](https://github.com/rancher/rancher/releases/tag/v2.8.1) | 2024 年 1 月 22 日 |
|
||||
| [2.8.0](https://github.com/rancher/rancher/releases/tag/v2.8.0) | 2023 年 12 月 6 日 |
|
||||
|
||||
### 当一个功能被标记为弃用我可以得到什么样的预期?
|
||||
|
||||
当功能被标记为“已弃用”时,它依然可用并得到支持,允许按照常规的流程进行升级。一旦升级完成,用户/管理员应开始计划在升级到标记为已移除的版本之前放弃使用已弃用的功能。对于新的部署,建议不要使用已弃用的功能。
|
||||
+14
@@ -0,0 +1,14 @@
|
||||
---
|
||||
title: Cluster API (CAPI) 与 Rancher Turtles
|
||||
---
|
||||
|
||||
<head>
|
||||
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/zh/integrations-in-rancher/cluster-api"/>
|
||||
</head>
|
||||
|
||||
[Rancher Turtles](https://turtles.docs.rancher.com/) 是一个 [Rancher 扩展](../rancher-extensions.md),通过提供 Cluster API (CAPI) 和 Rancher 之间的集成来管理配置的 Kubernetes 集群的生命周期。使用 Rancher Turtles,你可以:
|
||||
|
||||
- 通过在 CAPI 配置的集群中安装 Rancher Cluster Agent,将 CAPI 集群导入 Rancher。
|
||||
- 配置 [CAPI Operator](https://turtles.docs.rancher.com/docs/reference-guides/rancher-turtles-chart/values#cluster-api-operator-values)。
|
||||
|
||||
[概述](./overview.md)部分介绍了安装选项、Rancher Turtles 架构和简要 Demo。有关详细信息,请参阅 [Rancher Turtles 文档](https://turtles.docs.rancher.com/)。
|
||||
+221
@@ -0,0 +1,221 @@
|
||||
---
|
||||
title: 概述
|
||||
---
|
||||
|
||||
<head>
|
||||
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/zh/integrations-in-rancher/cluster-api/overview"/>
|
||||
</head>
|
||||
|
||||
## 架构图
|
||||
|
||||
下面是 Rancher Turtles 的关键组件及其与 Rancher 和 Rancher Cluster Agent 的关系的架构图,了解这些组件对于深入了解 Rancher 如何利用 CAPI operator 进行集群管理至关重要。
|
||||
|
||||

|
||||
|
||||
## 先决条件
|
||||
|
||||
在 Rancher 环境中安装 Rancher Turtles 之前,你必须禁用 Rancher 的 `embedded-cluster-api` 功能。这还包括清理 Rancher 专用的 webhook,否则这些 webhook 将与 CAPI 的 webhook 冲突。
|
||||
|
||||
为了简化 Rancher 安装 Rancher Turtles 的设置,官方的 Rancher Turtles Helm chart 包含一个删除以下内容的 `pre-install` hook:
|
||||
|
||||
- 禁用 Rancher 中的 `embedded-cluster-api` 功能。
|
||||
- 删除不再需要的 `mutating-webhook-configuration` 和 `validating-webhook-configuration` webhook。
|
||||
|
||||
## 安装 Rancher Turtles Operator
|
||||
|
||||
你可以通过 Rancher UI 或使用 Helm 安装 Rancher Turtles operator。对于大多数环境推荐使用第一种方法。
|
||||
|
||||
:::caution
|
||||
|
||||
如果你的集群中已经安装了 Cluster API (CAPI) Operator,你必须使用[手动 Helm 安装方法](#通过-helm-安装)。
|
||||
|
||||
:::
|
||||
|
||||
### 通过 Rancher UI 安装
|
||||
|
||||
通过 Rancher UI 添加 Turtles 仓库,Rancher 可以处理 CAPI 扩展的安装和配置。
|
||||
|
||||
1. 点击 **☰**。在左侧导航栏**浏览集群**的菜单下,选择 **local**。
|
||||
1. 在 **Cluster Dashboard** 的左侧导航菜单中,点击 **Apps > Repositories**。
|
||||
1. 点击 **Create** 创建一个新的仓库。
|
||||
1. 输入以下信息:
|
||||
- **Name**: turtles
|
||||
- **Index URL**: https://rancher.github.io/turtles
|
||||
1. 等待新的仓库状态更新为 `Active`。
|
||||
1. 在左侧导航菜单中,点击 **Apps > Charts**。
|
||||
1. 在搜索过滤器中输入 "turtles" 来查找 Turtles chart。
|
||||
1. 点击 **Rancher Turtles - the Cluster API Extension**。
|
||||
1. 点击 **Install > Next > Install**.
|
||||
|
||||
此过程使用 Helm chart 的默认值,这些值适用于大部分的安装场景。如果你的配置需要覆盖其中一些默认值,你可以在安装期间通过 Rancher UI 指定这些值,也可以通过 [Helm 手动安装 Chart](#通过-helm-安装)。有关可用的 values 设置的详细信息,请参阅 Rancher Turtles 的 [Helm chart 参考指南](https://turtles.docs.rancher.com/docs/reference-guides/rancher-turtles-chart/values)。
|
||||
|
||||
安装可能需要几分钟时间,安装完成后,你可以在集群中看到以下新部署:
|
||||
|
||||
- `rancher-turtles-system/rancher-turtles-controller-manager`
|
||||
- `rancher-turtles-system/rancher-turtles-cluster-api-operator`
|
||||
- `capi-system/capi-controller-manager`
|
||||
|
||||
#### Demo
|
||||
|
||||
这个 demo 演示了如何使用 Rancher UI 安装 Rancher Turtles、创建/导入一个 CAPI 集群,以及在集群上安装监控:
|
||||
|
||||
<iframe width="560" height="315" src="https://www.youtube.com/embed/lGsr7KfBjgU?si=ORkzuAJjcdXUXMxh" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
|
||||
|
||||
### 通过 Helm 安装
|
||||
|
||||
通过 Helm 安装 Rancher Turtles 有两种方法,这取决于你是否将 CAPI operator 作为依赖项包含其中:
|
||||
|
||||
- [使用 CAPI Operator 作为依赖项安装 Rancher Turtles](#使用-cluster-api-capi-operator-作为-helm-依赖项安装-rancher-turtles)。
|
||||
- [安装没有 CAPI Operator 的 Rancher Turtles](#不使用-cluster-api-capi-operator-作为-helm-依赖安装-rancher-turtles)。
|
||||
|
||||
安装 Rancher Turtles 需要 CAPI Operator。你可以选择自己处理此依赖项,还是让 Rancher Turtles Helm chart 替你管理它。[使用 CAPI Operator 作为依赖项安装 Rancher Turtles](#使用-cluster-api-capi-operator-作为-helm-依赖项安装-rancher-turtles) 更简单,但是你的最佳选择取决于你的具体配置。
|
||||
|
||||
CAPI Operator 允许使用声明式方法处理 CAPI provider 的生命周期,扩展了 `clusterctl` 的能力。如果你想了解更多相关内容,可以参考 [Cluster API Operator book](https://cluster-api-operator.sigs.k8s.io/)。
|
||||
|
||||
#### 使用 `Cluster API (CAPI) Operator` 作为 Helm 依赖项安装 Rancher Turtles
|
||||
|
||||
1. 添加包含 `rancher-turtles` chart 的 Helm 仓库作为安装的第一步:
|
||||
|
||||
```bash
|
||||
helm repo add turtles https://rancher.github.io/turtles
|
||||
helm repo update
|
||||
```
|
||||
|
||||
2. 如前面所述,安装 Rancher Turtles 需要 [CAPI Operator](https://github.com/kubernetes-sigs/cluster-api-operator)。Helm chart 可以使用一组最少的参数自动安装:
|
||||
|
||||
```bash
|
||||
helm install rancher-turtles turtles/rancher-turtles --version <version> \
|
||||
-n rancher-turtles-system \
|
||||
--dependency-update \
|
||||
--create-namespace --wait \
|
||||
--timeout 180s
|
||||
```
|
||||
|
||||
3. 此操作可能需要几分钟时间,完成后,你可以查看下面列出的已安装的控制器:
|
||||
|
||||
- `rancher-turtles-controller`
|
||||
- `capi-operator`
|
||||
|
||||
:::note
|
||||
|
||||
- 如果集群中已经有可用的 `cert-manager`,请在安装时通过以下参数将 Rancher Turtles 的此项依赖禁用掉,来阻止冲突:
|
||||
`--set cluster-api-operator.cert-manager.enabled=false`
|
||||
- 有关 Rancher Turtles 的版本列表,请参阅 [Turtles 发布页面](https://github.com/rancher/turtles/releases)。
|
||||
|
||||
:::
|
||||
|
||||
这是最基本的推荐配置,用于管理在核心提供商的命名空间中创建包含所需 CAPI 功能标志(已启用 `CLUSTER_TOPOLOGY`, `EXP_CLUSTER_RESOURCE_SET` 和 `EXP_MACHINE_POOL` )的 secret。要启用其他 CAPI 功能需要启用上述功能标志。
|
||||
|
||||
如果你需要覆盖默认的行为并使用现有 secret 或添加自定义环境变量,你可以将 secret 名称通过 Helm 参数传入。在这种情况下,你作为负责管理 secret 创建和内容的用户,需要启用的最少特性包括:`CLUSTER_TOPOLOGY`, `EXP_CLUSTER_RESOURCE_SET` 和 `EXP_MACHINE_POOL`。
|
||||
|
||||
```bash
|
||||
helm install ...
|
||||
# Passing secret name and namespace for additional environment variables
|
||||
--set cluster-api-operator.cluster-api.configSecret.name=<secret-name>
|
||||
```
|
||||
|
||||
以下是一个用户管理 secret `cluster-api-operator.cluster-api.configSecret.name=variables` 的示例,其中设置了 `CLUSTER_TOPOLOGY`, `EXP_CLUSTER_RESOURCE_SET` 和 `EXP_MACHINE_POOL` 功能以及一个额外的自定义变量:
|
||||
|
||||
```yaml title="secret.yaml"
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: variables
|
||||
namespace: rancher-turtles-system
|
||||
type: Opaque
|
||||
stringData:
|
||||
CLUSTER_TOPOLOGY: "true"
|
||||
EXP_CLUSTER_RESOURCE_SET: "true"
|
||||
EXP_MACHINE_POOL: "true"
|
||||
CUSTOM_ENV_VAR: "false"
|
||||
```
|
||||
|
||||
:::info
|
||||
|
||||
有关 chart 支持的 values 及其用法的详细信息,请参阅 [Helm chart 选项](https://turtles.docs.rancher.com/docs/reference-guides/rancher-turtles-chart/values)
|
||||
|
||||
:::
|
||||
|
||||
#### 不使用 `Cluster API (CAPI) Operator` 作为 Helm 依赖安装 Rancher Turtles
|
||||
|
||||
:::note
|
||||
|
||||
请记住,如果使用此安装选项,你必须自行管理 CAPI Operator 的安装。你可以参照 Rancher Turtles 文档中的 [CAPI Operator 指南](https://turtles.docs.rancher.com/docs/tasks/capi-operator/intro)
|
||||
|
||||
:::
|
||||
|
||||
1. 添加包含 `rancher-turtles` chart 的 Helm 仓库作为安装的第一步:
|
||||
|
||||
```bash
|
||||
helm repo add turtles https://rancher.github.io/turtles
|
||||
helm repo update
|
||||
```
|
||||
|
||||
2. 将 chart 安装到 `rancher-turtles-system` 命名空间:
|
||||
|
||||
```bash
|
||||
helm install rancher-turtles turtles/rancher-turtles --version <version>
|
||||
-n rancher-turtles-system
|
||||
--set cluster-api-operator.enabled=false
|
||||
--set cluster-api-operator.cluster-api.enabled=false
|
||||
--create-namespace --wait
|
||||
--dependency-update
|
||||
```
|
||||
|
||||
前面的命令告诉 Helm 忽略将 `cluster-api-operator` 作为依赖项安装。
|
||||
|
||||
3. 此操作可能需要几分钟,完成后你可以查看下面列出的已安装的控制器:
|
||||
|
||||
- `rancher-turtles-controller`
|
||||
|
||||
## 卸载 Rancher Turtles
|
||||
|
||||
:::caution
|
||||
|
||||
在 Rancher 环境中安装 Rancher Turtles 时,Rancher Turtles 默认会启用 CAPI Operator 清理。这包括清理 CAPI Operator 特定的 webhook 和 deployments,否则会导致 Rancher 配置出现问题。
|
||||
|
||||
为了简化 Rancher Turtles 卸载(通过 Rancher 或 Helm 命令),官方的 Rancher Turtles Helm chart 包含了一个删除以下内容的 `post-delete` hook:
|
||||
|
||||
- 删除不再需要的 `mutating-webhook-configuration` 和 `validating-webhook-configuration` webhook。
|
||||
- 删除不再需要的 CAPI `deployments`。
|
||||
|
||||
:::
|
||||
|
||||
卸载 Rancher Turtles:
|
||||
|
||||
```bash
|
||||
helm uninstall -n rancher-turtles-system rancher-turtles --cascade foreground --wait
|
||||
```
|
||||
|
||||
这可能需要几分钟才能完成。
|
||||
|
||||
:::note
|
||||
|
||||
请记住,如果你在安装时使用了不同的名称或不同的命名空间,你需要针对你的特定配置自定义卸载命令。
|
||||
|
||||
:::
|
||||
|
||||
卸载 Rancher Turtles 后, Rancher 的 `embedded-cluster-api` 功能必须重新启用。
|
||||
|
||||
1. 创建一个 `feature.yaml` 文件,将 `embedded-cluster-api` 设置为 true:
|
||||
|
||||
```yaml title="feature.yaml"
|
||||
apiVersion: management.cattle.io/v3
|
||||
kind: Feature
|
||||
metadata:
|
||||
name: embedded-cluster-api
|
||||
spec:
|
||||
value: true
|
||||
```
|
||||
|
||||
2. 使用 `kubectl` 将 `feature.yaml` 文件应用到集群:
|
||||
|
||||
```bash
|
||||
kubectl apply -f feature.yaml
|
||||
```
|
||||
|
||||
## 安全
|
||||
|
||||
[SLSA](https://slsa.dev/spec/v1.0/about) 是一套由行业共识制定的可逐步采用的供应链安全指南。SLSA 制定的规范对软件生产者和消费者都很有用:生产者可以遵循 SLSA 的指导方针,使他们的软件供应链更加安全,消费者可以使用 SLSA 来决定是否信任软件包。
|
||||
|
||||
Rancher Turtles 满足 [SLSA Level 3](https://slsa.dev/spec/v1.0/levels#build-l3) 对适当的构建平台、一致的构建过程和来源分布的要求。更多信息请参阅 [Rancher Turtles 安全](https://turtles.docs.rancher.com/docs/security/slsa)文档。
|
||||
Reference in New Issue
Block a user