Compare commits

...
Author SHA1 Message Date
Sunil Singh 3608567e91 Merge pull request #1843 from rancher/v2.10.7
Merge Branch v2.10.7
2025-06-25 16:26:40 -07:00
Sunil Singh 262340aa89 Merge pull request #1842 from rancher/v2.11.3
Merge Branch v2.11.3
2025-06-25 16:26:17 -07:00
Sunil Singh b631f1a613 Merge pull request #1837 from sunilarjun/v2.10.7-maintenance
v2.10.7 Maintenance Tasks
2025-06-25 08:59:51 -07:00
Sunil Singh ce19a938ed Merge pull request #1836 from sunilarjun/v2.11.3-maintenance
v2.11.3 Maintenance Tasks
2025-06-25 08:59:41 -07:00
Sunil Singh ed176cb275 Merge pull request #1838 from sunilarjun/add-v2.12
Adding v2.12 Rancher Docs - UI Preview
2025-06-24 16:53:01 -07:00
Sunil Singh 919a0c4128 [2.10.7] deprecated features update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 15:13:16 -07:00
Sunil Singh 195bf9e1b0 [2.10.7] CSP adapter update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 15:11:37 -07:00
Sunil Singh cb0c444f01 [2.10.7] webhook update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 15:09:43 -07:00
Sunil Singh 74c82af2ca [2.10.7] versions update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 15:07:58 -07:00
Sunil Singh 697e8ab178 [2.11.3] CNI update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 15:01:30 -07:00
Sunil Singh 010c474078 [2.11.3] deprecated features update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 14:57:22 -07:00
Sunil Singh 50ad16cd11 [2.11.3] CSP adapter update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 14:54:35 -07:00
Sunil Singh e132f13396 [2.11.3] webhook update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 14:52:13 -07:00
Sunil Singh 294f6a0337 [2.11.3] versions update
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 14:49:00 -07:00
Sunil Singh 8ed7881920 Adding preview for v2.12 Rancher documentation.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-23 14:10:05 -07:00
Sunil Singh 4def8a407e Merge pull request #1828 from sunilarjun/archive-v2.6-v2.7
Archive v2.6-v2.7 Docs
2025-06-16 12:40:24 -07:00
Sunil Singh cf23579f56 Adjusting after review, editing zh canonical links.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-16 11:10:32 -07:00
Sunil Singh af77fc8954 Archiving the v2.6/v2.7 zh docs. Updating the zh sidebar version JSON files to reflect archived messaging in navigation dropdown.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-11 16:10:14 -07:00
Sunil Singh 5069378133 Updating link to GH archive link.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-11 15:43:32 -07:00
Sunil Singh 5570fef31d Removing redirects for v2.6/v2.7.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-11 15:37:35 -07:00
Sunil Singh c48a5095ad Moving versions 2.6 and 2.7 to the archived_docs directory. Removed the sidebar entries in the versioned_sidebars folder and added the notice page to the versioned_docs folder. Added 'Archived' labels to the docusaurus.config.js file for v2.6/v2.7.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-06-11 14:43:52 -07:00
Diogo Souza ee1165860b Merge pull request #1798 from diogoasouza/update-logging-docs-about-hosttailer-image
add doc on how to use custom image with HostTailer
2025-06-11 18:30:05 -03:00
Billy Tat b04087240f Merge pull request #1825 from JonCrowther/update-aggregated-clusterrole-version
Update the version specified for Aggregated ClusterRole beta
2025-06-09 14:32:33 -07:00
Billy Tat 922eeac1c4 Merge pull request #1826 from tomleb/per-version-api-references
Per Rancher version API references
2025-06-09 14:31:46 -07:00
Tom Lebreux 7f3f3a81f7 Make docs/ point to v2.11 2025-06-09 16:50:16 -04:00
Tom Lebreux f22dba31ad Per Rancher version API references 2025-06-09 14:39:21 -04:00
Jonathan Crowther cc4de11363 Update the version specified for feature beta 2025-06-09 11:27:48 -04:00
Diogo Souza 11db12dd12 update versioned docs for 2.10 and 2.11 2025-06-06 20:10:38 -03:00
Billy Tat a9fb327853 Merge pull request #1821 from pmkovar/1773
Include Flannel as option with RKE2 with Windows
2025-06-05 16:23:05 -07:00
Billy Tat d53e9c8edc Merge pull request #1816 from johnwc/patch-1
Updating external TLS termination required settings
2025-06-05 16:20:41 -07:00
John Carew 551d60f193 Update TLS termination documentation for NGINX v0.22
Clarify the configuration for external TLS termination with NGINX
v0.22, including:

- Instructions to enable the `use-forwarded-headers` option for
  ingress in both RKE and RKE2 installations.
- A new section for RKE2 detailing how to create a custom
  configuration file for this setting.
- Updates to the required headers section to include
  `X-Forwarded-Proto` and `X-Forwarded-Port`.
2025-06-05 13:37:59 -05:00
John Carew e73b7efaef Update Ingress TLS configuration documentation for NGINX v0.22
The documentation has been revised to provide clearer guidance on
configuring Ingress for external TLS with NGINX v0.22. Key changes
include:

- Removed references to NGINX v0.25.
- Added instructions for enabling the `use-forwarded-headers`
  option in the `cluster.yml` for RKE installations.
- Included steps for creating a custom
  `rke2-ingress-nginx-config.yaml` for RKE2 installations.
- Provided a YAML snippet for HelmChartConfig to demonstrate
  how to set the `use-forwarded-headers` option in Helm chart
  values.
2025-06-05 13:34:10 -05:00
Petr Kovar 73dba2e2a6 Fix #1773 2025-06-05 16:39:54 +02:00
John CarewandPetr Kovar cb46b1030b Update docs/getting-started/installation-and-upgrade/installation-references/helm-chart-options.md
Co-authored-by: Petr Kovar <pknbe@volny.cz>
2025-06-05 03:12:08 -05:00
Alessio GreggiandLucas Saintarbor 2a770e00c2 docs: add manage users disclaimer (#1765)
* docs: add manage users disclaimer

Signed-off-by: Alessio Greggi <alessio.greggi@suse.com>
Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>
2025-06-04 18:38:38 +02:00
John Carew 17e94a4704 Updating external TLS termination required settings
Updating external TLS termination required settings. Updating the documentation to be clear on RKE configuration vs RKE2 configuration.

Based on closed issue: https://github.com/rancher/rancher/issues/35088
2025-06-03 15:08:11 -05:00
Billy Tat 148c5da3ad Merge pull request #1813 from btat/prometheus-op-gh-links
Fix broken links to upstream prometheus-operator GitHub repo
2025-06-02 10:24:49 -07:00
Sunil Singh 5c44cc1abf Merge pull request #1814 from sunilarjun/updating-about-rancher-selinux
Updating "About rancher-selinux"
2025-05-30 14:23:36 -07:00
Sunil Singh 03e2e34398 Updating outdated information with GH definition of rancher-selinux.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-30 10:54:50 -07:00
Billy Tat e9cebe3aae Merge pull request #1810 from btat/broken-links
Fix broken links
2025-05-29 14:20:31 -07:00
Billy Tat d694bfd026 Fix broken links to upstream prometheus-operator GitHub repo
* Some links were updated only to reflect the master -> main naming change
2025-05-28 17:03:15 -07:00
Billy Tat 7630d7b766 Merge pull request #1785 from SjuulJanssen/patch-1
Fix link to helm chart readme
2025-05-27 16:11:12 -07:00
Billy Tat ad9b6083fd Apply 0ca949b8 (Fix link to helm chart readme) to other versions 2025-05-27 15:35:47 -07:00
Sunil Singh fbe6b7ec53 Merge pull request #1602 from sunilarjun/update-directories
Removing Incorrect Directories - [SURE-8597]
2025-05-27 13:25:24 -07:00
Sunil Singh 5512ce8360 Updating distribution directories wrt RKE, RKE2, K3s. Verified across distribution versions and updated in the docs across versions/i18n.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-27 12:01:07 -07:00
Billy Tat fc438733e0 Fix broken links 2025-05-22 17:01:00 -07:00
Sunil Singh 83d2550b95 Merge pull request #1803 from rancher/v2.9.10
Merge release branch v2.9.10 into main
2025-05-22 16:48:41 -07:00
Sunil Singh 0797ee6e1d Merge pull request #1804 from rancher/v2.10.6
Merge release branch v2.10.6 into main
2025-05-22 16:48:14 -07:00
Sunil Singh d985c93a8a Merge pull request #1805 from rancher/v2.11.2
Merge release branch v2.11.2 main
2025-05-22 16:48:00 -07:00
Sunil Singh fd49c58acd Merge pull request #1809 from sunilarjun/v2.9.10-date
Updating Release Date v2.9.10
2025-05-22 16:08:59 -07:00
Sunil Singh 38483158da Merge pull request #1808 from sunilarjun/v2.10.6-date
Updating Release Date v2.10.6
2025-05-22 16:08:50 -07:00
Sunil Singh a9905c266f Merge pull request #1807 from sunilarjun/v2.11.2-date
Updating Release Date v2.11.2
2025-05-22 16:08:39 -07:00
Sunil Singh b68517fd26 Updating release date v2.9.10
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-21 15:57:53 -07:00
Sunil Singh 4315dc06ff Updating release date v2.10.6
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-21 15:55:05 -07:00
Sunil Singh 7a97968cd0 Updating release date v2.11.2
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-21 15:46:22 -07:00
Billy Tat af02485a69 Merge pull request #1802 from sunilarjun/update-codeowners
Updating CODEOWNERS file - @pmkovar
2025-05-20 15:51:52 -07:00
Billy Tat 4fc8fbae90 Merge pull request #1799 from pmkovar/v2.11.2-maintenance
[v2.11.2] Maintenance tasks
2025-05-20 15:20:49 -07:00
Billy Tat ebd37e8cbe Merge pull request #1800 from pmkovar/v2.10.6-maintenance
[v2.10.6] Maintenance tasks
2025-05-20 15:20:42 -07:00
Billy Tat f27c1c985d Merge pull request #1801 from pmkovar/v2.9.10-maintenance
[v2.9.10] Maintenance tasks
2025-05-20 15:20:38 -07:00
Sunil Singh cc307bb6b7 Keeping list alphabetized
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-20 15:16:03 -07:00
Sunil Singh 728f51e7bb Updating CODEOWNERS file - @pmkovar
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-20 15:01:52 -07:00
Sunil Singh 56e0c55c1a Adding updates to Zh files and standardizing v2.10 webhook table syntax
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-20 13:40:43 -07:00
Sunil Singh 5672c6549d Adding updates to Zh files
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-05-20 13:25:40 -07:00
Petr Kovar ee701a969e [v2.11.2] Fix Webhook version 2025-05-20 19:12:46 +02:00
Petr Kovar 8386ff12bc [v2.9.10] Maintenance tasks
Helps #1781.
2025-05-20 14:27:40 +02:00
Petr Kovar cae834df4e [v2.10.6] Maintenance tasks
Helps #1782.
2025-05-20 14:10:27 +02:00
Petr Kovar b21e5fd961 [v2.11.2] Maintenance tasks
Helps #1783.
2025-05-20 13:40:16 +02:00
Diogo Souza c6b7a8d6ae add doc on how to use custom image with HostTailer 2025-05-19 18:02:25 -03:00
Sunil Singh 988c958747 Merge branch 'rancher:main' into update-directories 2025-05-19 10:21:23 -07:00
Billy Tat 3bca8e71ea Merge pull request #1786 from AngeloCicero/patch-1
fix: Misspelling
2025-05-16 21:09:45 -07:00
Angelo Cicero 655b2ba1d1 fix: Misspelling 2025-05-16 22:24:41 -04:00
Angelo Cicero c89f4b3f10 fix: Misspelling 2025-05-16 22:24:16 -04:00
Angelo Cicero 497cef1e93 fix: Misspelling 2025-05-16 22:23:41 -04:00
Angelo Cicero f199f99255 fix: Misspelling 2025-05-16 22:22:46 -04:00
Billy Tat 3cc383f156 Merge pull request #1375 from rancher/Tejeev-patch-1
Update clean-cluster-nodes.md to point to RKE2 specific docs
2025-05-16 16:36:18 -07:00
Billy Tat 8ef2e36b90 Fix spacing so note renders and apply to other versions 2025-05-16 15:46:37 -07:00
Marty Hernandez Avedon 8105e75263 Update docs/how-to-guides/new-user-guides/manage-clusters/clean-cluster-nodes.md 2025-05-16 15:42:52 -07:00
Tejeev c295a4205d Update clean-cluster-nodes.md to point to RKE2 specific docs
When cleaning nodes for re-use which were deployed manually with RKE2, the process differs slightly.  This is more important in reverse so I'm editing that doc as well.  I think there's like a note callout or something that might be better?
2025-05-16 15:42:50 -07:00
Billy Tat 0e193241ca Merge pull request #1777 from btat/growpart-p2
Apply PR #1584 (Clarify dependency) to v2.11
2025-05-16 13:39:11 -07:00
Billy Tat d3f64dcfdb Merge pull request #1772 from burnedoutman/patch-6
Fix comma in authorized-cluster-endpoint.md
2025-05-15 17:56:28 -07:00
Billy Tat b6a6b2adaf Merge pull request #1760 from burnedoutman/patch-5
Remove double word in back-up-restore-usage-guide.md
2025-05-15 17:12:33 -07:00
Billy Tat b3836c4ada Merge pull request #1759 from burnedoutman/patch-4
Fix typo in ingress-configuration.md
2025-05-15 17:04:04 -07:00
Billy Tat 06e275454b Merge pull request #1757 from burnedoutman/patch-2
Fix whitespace in authentication-permissions-and-global-configuration.md
2025-05-15 16:57:35 -07:00
Billy Tat 253d460bfb Merge pull request #1756 from burnedoutman/patch-1
Fix whitespace in upgrades.md
2025-05-15 16:50:36 -07:00
Billy Tat f3111278ef Apply 9f472265 (Fix comma in authorized-cluster-endpoint.md) to other versions 2025-05-15 16:48:59 -07:00
Billy Tat b37e22ad80 Apply 2bfa05732 (Remove double word in back-up-restore-usage-guide.md) to other versions 2025-05-15 16:36:23 -07:00
Billy Tat e0fa8ecc6d Apply 072d66f1 (fix word in ingress-configuration.md) to other versions 2025-05-15 16:26:55 -07:00
Billy Tat ab23b32b02 Apply 32acfa94 (Fix whitespace in authentication-permissions-and-global-configuration.md) to other versions 2025-05-15 16:05:06 -07:00
Billy Tat 01711c8029 Apply 13e57364 (fix whitespace) to other versions (en/zh) 2025-05-15 15:43:14 -07:00
Billy Tat c87821fd68 Merge pull request #1525 from weyfonk/document-user-search-behaviour
Clarify how user search works
2025-05-14 17:20:13 -07:00
Billy Tat 979f656768 Apply 5ddddd1a...42143c42 (Clarify how user search works) to other versions 2025-05-14 16:40:22 -07:00
Billy Tat 915ef93dd1 Merge pull request #1639 from axeal/patch-1
Add kubectl image for air-gapped environments
2025-05-14 16:13:27 -07:00
Corentin Néau 42143c423c Improve formatting
This applies suggestions from code review.
2025-05-14 15:56:48 -07:00
Corentin Néau a55b901d08 Fix notes formatting
This improves formatting of notes on searching users, by making them
appear in notes blocks.
2025-05-14 15:56:46 -07:00
Corentin Néau d37b9fed51 Mention that search is prefix-based
This explains the difference that it makes as opposed to substring-based
search.
2025-05-14 15:56:44 -07:00
Corentin Néau 5ddddd1a81 Clarify how user search works
This adds a few points which should shed light on how to search users
using a drop-down list in Rancher, whether to add users to clusters or
to projects.
2025-05-14 15:56:40 -07:00
Billy Tat c9b95f1a9f Apply 3bed7afb (Add kubectl image for air-gapped environments...) to other versions 2025-05-14 15:13:02 -07:00
Alex Seymour 3bed7afb65 Add kubectl image for air-gapped environments
Add global.kubectl.repository value for air-gapped environments
2025-05-14 14:08:01 -07:00
Angelo Cicero 97fd27bc08 fix: Misspelling 2025-05-14 14:34:23 -04:00
SjuulJanssen 0ca949b866 Fix link to helm chart readme 2025-05-14 09:19:43 +02:00
Billy Tat f4cf47d332 Merge pull request #1778 from kakabisht/fix-Noteheading-Vagrant
Fixing a wrong Note header in Vagrant
2025-05-07 09:36:35 -07:00
hridyesh bisht 44e21d18a4 Merge branch 'main' into fix-Noteheading-Vagrant 2025-05-07 20:24:47 +05:30
hridyesh bisht 996e6d360c Merge branch 'fix-Noteheading-Vagrant' of https://github.com/kakabisht/rancher-docs into fix-Noteheading-Vagrant 2025-05-07 20:24:24 +05:30
hridyesh bisht 7d280c143e Fixing zh translations as well 2025-05-07 20:24:11 +05:30
Billy Tat 5f389f4374 Merge pull request #1779 from btat/keycloak-typo
Fix typo. Missing word
2025-05-01 14:52:13 -07:00
Billy Tat 9659b80d6b Fix typo. Missing word 2025-05-01 13:44:52 -07:00
hridyesh bisht 00374743ab Merge branch 'main' into fix-Noteheading-Vagrant 2025-04-30 16:33:56 +05:30
hridyesh bisht aa28932257 Fixing a wrong Note header in Vagrant 2025-04-30 16:32:14 +05:30
Billy Tat 035ea0ef5d Merge pull request #1637 from mkrutov/mkr_cli
Update wording for navigation "about" item
2025-04-29 17:14:45 -07:00
Billy Tat 282376c40f Apply 3860d52f (About -> version number) w/ fixed format/grammar to other versions and zh files 2025-04-29 16:30:39 -07:00
Mikhail Krutov 3860d52f9e About -> version number 2025-04-29 16:01:12 -07:00
Billy Tat f606f278c2 Apply PR #1584 ( Update create-a-vm-template.md) to v2.11 2025-04-29 15:59:04 -07:00
Billy Tat 4ca5f3752d Merge pull request #1584 from aseques/patch-1
Update create-a-vm-template.md
2025-04-29 14:56:52 -07:00
Billy Tat 8930cf92b3 Apply aac1fc2e (Clarify a dpendency that's part of another package) to other versions 2025-04-29 14:15:01 -07:00
Sunil Singh 1c5be0c836 Merge pull request #1774 from sunilarjun/cve-pages-update-april-2025
Add April 2025 Release CVE's
2025-04-25 11:54:00 -07:00
Sunil Singh 43f4f2380b Updating after review from release notes
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-04-25 10:08:37 -07:00
Sunil Singh 32ca20ee68 Adding the April 2025 CVEs for this release cycle.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-04-25 08:32:43 -07:00
Lucas SaintarborandBilly Tat 1d3f2985b4 Merge release branch v2.11.1 into main (#1753)
* v2.11.1 Maintenance Items (#1748)

* [v2.11.1] version update

* [v2.11.1] webhook update

* [v2.11.1] webhook update

* [v2.11.1] deprecated features update

* [v2.11.1] CSP adapter update

* Fix date typo in deprecated features table

* [2.11.1] CNI community popularity table

* [v2.11.1] (zh) webhook update

* [v2.11.1] (zh) CSP adapter update

* [v2.11.1] (zh) deprecated features update

* [2.11.1] Update date and sync to zh

Also remove duplicate file

---------

Co-authored-by: Billy Tat <btat@suse.com>
2025-04-24 17:04:36 -07:00
Lucas SaintarborandBilly Tat b75ebcef2f Merge release branch v2.10.5 into main (#1752)
* v2.10.5 Maintenance Items (#1747)

* [v2.10.5] version update

* [v2.10.5] webhook update

* [v2.10.5] deprecated features update

* [v2.10.5] CSP adapter update

* [2.10.5] Update date and sync to zh

---------

Co-authored-by: Billy Tat <btat@suse.com>
2025-04-24 17:04:16 -07:00
Lucas SaintarborandBilly Tat 4971ece6b5 Merge release branch v2.9.9 into main (#1751)
* v2.9.9 Maintenance Items (#1749)

* [v2.9.9] version update

* [v2.9.9] webhook update

* [v2.9.9] deprecated features update

* [v2.9.9] CSP adapter update

* [2.9.9] Update date and sync to zh

---------

Co-authored-by: Billy Tat <btat@suse.com>
2025-04-24 17:03:32 -07:00
Lucas SaintarborandBilly Tat e455586ff9 Merge release branch v2.8.15 into main (#1750)
* v2.8.15 Maintenance Items (#1746)

* [v2.8.15] version update

* [v2.8.15] webhook update

* [v2.8.15] deprecated features update

* [v2.8.15] CSP adapter update

* [2.8.15] Update date and sync to zh

---------

Co-authored-by: Billy Tat <btat@suse.com>
2025-04-24 17:03:17 -07:00
burnedoutman 9f47226500 Update authorized-cluster-endpoint.md
fix comma
2025-04-24 18:43:24 +03:00
Billy Tat 3c5f4ccc77 Merge pull request #1754 from Tejeev/patch-3
Update networking.md
2025-04-23 16:24:41 -07:00
Billy Tat 3fa65a6033 Apply a64e5988 (Just a slightly better way to keep the container up) to other instances 2025-04-23 15:19:06 -07:00
Billy Tat bca3170dce Merge pull request #1762 from btat/istio-deprecation
Extend Istio deprecation warning to all subpages
2025-04-23 08:51:03 -07:00
Billy Tat bae87275b8 Merge pull request #1693 from Tejeev/patch-1
Update servicemonitors-and-podmonitors.md
2025-04-22 17:08:56 -07:00
Billy Tat f6cfb24eb3 Apply 5d519406 (Update servicemonitors and podmonitors spec links) to all instances 2025-04-22 16:21:54 -07:00
Billy Tat 05b45ea361 Extend Istio deprecation warning to all subpages 2025-04-21 17:09:02 -07:00
Sunil Singh c23d741a25 Merge pull request #1755 from sunilarjun/register-existing-cluster-page-edit
Port Product PR #238 (Editing Register Existing Cluster Version Callout)
2025-04-21 08:38:27 -07:00
burnedoutman 2bfa05732f Update back-up-restore-usage-guide.md
remove doubled word
2025-04-21 17:35:32 +03:00
burnedoutman 072d66f1cf Update ingress-configuration.md
fix word
2025-04-21 16:49:16 +03:00
burnedoutman 32acfa94fd Update authentication-permissions-and-global-configuration.md
fix whitespace
2025-04-21 13:54:43 +03:00
burnedoutman 13e57364ab Update upgrades.md
fix whitespace
2025-04-21 12:23:52 +03:00
Sunil Singh 23ca4b35bb Removing version callout as applicable to all v2.11 versions.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-04-18 13:08:57 -07:00
Tejeev a64e5988d5 Update networking.md
Just a slightly better way to keep the container up
2025-04-18 04:51:27 -06:00
Billy Tat 9ac71edd37 Merge pull request #1744 from btat/oci-experimental-removal
Remove experimental banner for OCI p2
2025-04-14 17:00:17 -07:00
Billy Tat 4849f46664 Remove experimental banner for OCI p2 2025-04-14 14:24:49 -07:00
Billy Tat abefa0bf59 Merge pull request #1738 from btat/fix-links
Fix external links
2025-04-11 11:28:08 -07:00
Billy Tat dff5fab800 Merge pull request #1737 from btat/2.11-banner
2.11: Remove banner with incorrect release status
2025-04-10 09:37:28 -07:00
Billy TatandSunil Singh 894c506a5f Update docusaurus.config.js
Co-authored-by: Sunil Singh <sunil.singh@suse.com>
2025-04-10 08:50:21 -07:00
Billy Tat 5f578d70d7 2.11: Remove banner with incorrect release status 2025-04-10 07:07:46 -07:00
Billy Tat 8baef95292 Fix external links 2025-04-10 07:06:16 -07:00
Billy Tat 48013d15cc Merge pull request #1734 from btat/v2.8-archive-notice
Add archive notice to v2.8
2025-04-07 08:48:13 -07:00
Billy Tat ba89f6bff0 Add archive notice to v2.8 2025-04-04 17:02:05 -07:00
Lucas Saintarbor bd71b780b6 Add March 2025 release CVEs and advisories (#1732)
* Update CVE page for March 2025 release

* Update zh CVE page for March 2025 release
2025-04-01 14:45:37 -07:00
Tejeev 5d5194065f Update servicemonitors-and-podmonitors.md
Updated spec links
2025-03-05 03:05:59 -07:00
Sunil Singh 18a2d91c57 Syncing code block zh
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2024-12-20 08:11:35 -08:00
Sunil Singh baaae2a77f Removing from zh files
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2024-12-20 08:10:08 -08:00
Sunil Singh c3e7113b3e Removing incorrect directories from list of directories used by RKE1, RKE2, and K3s. Also updating admonition.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2024-12-19 16:41:27 -08:00
aseques aac1fc2ed5 Update create-a-vm-template.md
Clarify a dpendency that's part of another package
2024-12-09 09:04:12 +01:00
3270 changed files with 150752 additions and 12074 deletions
+1 -1
View File
@@ -1 +1 @@
* @btat @LucasSaintarbor @sunilarjun * @btat @LucasSaintarbor @pmkovar @sunilarjun
@@ -41,7 +41,7 @@ Prometheus RemoteRead and RemoteWrite can be configured as custom answers in the
For more information on remote endpoints and storage, refer to the [Prometheus documentation.](https://prometheus.io/docs/operating/integrations/#remote-endpoints-and-storage) For more information on remote endpoints and storage, refer to the [Prometheus documentation.](https://prometheus.io/docs/operating/integrations/#remote-endpoints-and-storage)
The Prometheus operator documentation contains the full [RemoteReadSpec](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#remotereadspec) and [RemoteWriteSpec.](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#remotewritespec) The Prometheus operator documentation contains the full [RemoteReadSpec](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#remotereadspec) and [RemoteWriteSpec.](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#remotewritespec)
An example configuration would be: An example configuration would be:
@@ -155,15 +155,32 @@ You may terminate the SSL/TLS on a L7 load balancer external to the Rancher clus
Your load balancer must support long lived websocket connections and will need to insert proxy headers so Rancher can route links correctly. Your load balancer must support long lived websocket connections and will need to insert proxy headers so Rancher can route links correctly.
#### Configuring Ingress for External TLS when Using NGINX v0.25 ### Configuring Ingress for External TLS when Using NGINX v0.22
In NGINX v0.25, the behavior of NGINX has [changed](https://github.com/kubernetes/ingress-nginx/blob/main/Changelog.md#0220) regarding forwarding headers and external TLS termination. Therefore, in the scenario that you are using external TLS termination configuration with NGINX v0.25, you must edit the `cluster.yml` to enable the `use-forwarded-headers` option for ingress: In NGINX v0.22, the behavior of NGINX has [changed](https://github.com/kubernetes/ingress-nginx/blob/06efac9f0b6f8f84b553f58ccecf79dc42c75cc6/Changelog.md) regarding forwarding headers and external TLS termination. Therefore, in the scenario that you are using external TLS termination configuration with NGINX v0.22, you must enable the `use-forwarded-headers` option for ingress:
For RKE installations, edit the `cluster.yml` to add the following settings.
```yaml ```yaml
ingress: ingress:
provider: nginx provider: nginx
options: options:
use-forwarded-headers: "true" use-forwarded-headers: 'true'
```
For RKE2 installations, you can create a custom `rke2-ingress-nginx-config.yaml` file at `/var/lib/rancher/rke2/server/manifests/rke2-ingress-nginx-config.yaml` containing this required setting to enable using forwarded headers with external TLS termination. Without this required setting applied, the external LB will continuously respond with redirect loops it receives from the ingress controller. (This can be created before or after rancher is installed, rke2 server agent will notice this addition and automatically apply it.)
```yaml
---
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
name: rke2-ingress-nginx
namespace: kube-system
spec:
valuesContent: |-
controller:
config:
use-forwarded-headers: "true"
``` ```
#### Required Headers #### Required Headers
@@ -121,7 +121,7 @@ To test the overlay network, you can launch the following `DaemonSet` definition
- image: alpine - image: alpine
imagePullPolicy: Always imagePullPolicy: Always
name: alpine name: alpine
command: ["sh", "-c", "tail -f /dev/null"] command: ["sleep", "infinity"]
terminationMessagePath: /dev/termination-log terminationMessagePath: /dev/termination-log
``` ```
@@ -41,7 +41,7 @@ Note that upgrades _to_ or _from_ any chart in the [rancher-alpha repository](..
The upgrade instructions assume you are using Helm 3. The upgrade instructions assume you are using Helm 3.
For migration of installs started with Helm 2, refer to the official [Helm 2 to 3 migration docs.](https://helm.sh/blog/migrate-from-helm-v2-to-helm-v3/) The [Helm 2 upgrade page here](helm2.md)provides a copy of the older upgrade instructions that used Helm 2, and it is intended to be used if upgrading to Helm 3 is not feasible. For migration of installs started with Helm 2, refer to the official [Helm 2 to 3 migration docs.](https://helm.sh/blog/migrate-from-helm-v2-to-helm-v3/) The [Helm 2 upgrade page here](helm2.md) provides a copy of the older upgrade instructions that used Helm 2, and it is intended to be used if upgrading to Helm 3 is not feasible.
### For air gap installs: Populate private registry ### For air gap installs: Populate private registry
@@ -16,12 +16,13 @@ The following steps quickly deploy a Rancher Server with a single node cluster a
- [Virtualbox](https://www.virtualbox.org): The virtual machines that Vagrant provisions need to be provisioned to VirtualBox. - [Virtualbox](https://www.virtualbox.org): The virtual machines that Vagrant provisions need to be provisioned to VirtualBox.
- At least 4GB of free RAM. - At least 4GB of free RAM.
### Note :::note
- Vagrant will require plugins to create VirtualBox VMs. Install them with the following commands:
`vagrant plugin install vagrant-vboxmanage` Vagrant requires plugins to create VirtualBox VMs. Install them with the following commands:
- `vagrant plugin install vagrant-vboxmanage`
- `vagrant plugin install vagrant-vbguest`
`vagrant plugin install vagrant-vbguest` :::
## Getting Started ## Getting Started
@@ -111,7 +111,7 @@ If you are experiencing issues while testing the connection to the Keycloak serv
When you click on **Authenticate with Keycloak**, your are not redirected to your IdP. When you click on **Authenticate with Keycloak**, your are not redirected to your IdP.
* Verify your Keycloak client configuration. * Verify your Keycloak client configuration.
* Make sure `Force Post Binding` set to `OFF`. * Make sure `Force Post Binding` is set to `OFF`.
### Forbidden message displayed after IdP login ### Forbidden message displayed after IdP login
@@ -10,7 +10,7 @@ After installation, the [system administrator](manage-role-based-access-control-
## First Log In ## First Log In
After you log into Rancher for the first time, Rancher will prompt you for a **Rancher Server URL**.You should set the URL to the main entry point to the Rancher Server. When a load balancer sits in front a Rancher Server cluster, the URL should resolve to the load balancer. The system will automatically try to infer the Rancher Server URL from the IP address or host name of the host running the Rancher Server. This is only correct if you are running a single node Rancher Server installation. In most cases, therefore, you need to set the Rancher Server URL to the correct value yourself. After you log into Rancher for the first time, Rancher will prompt you for a **Rancher Server URL**. You should set the URL to the main entry point to the Rancher Server. When a load balancer sits in front a Rancher Server cluster, the URL should resolve to the load balancer. The system will automatically try to infer the Rancher Server URL from the IP address or host name of the host running the Rancher Server. This is only correct if you are running a single node Rancher Server installation. In most cases, therefore, you need to set the Rancher Server URL to the correct value yourself.
>**Important!** After you set the Rancher Server URL, we do not support updating it. Set the URL with extreme care. >**Important!** After you set the Rancher Server URL, we do not support updating it. Set the URL with extreme care.
@@ -38,7 +38,7 @@ These methods of communicating with downstream Kubernetes clusters are also expl
### About the kube-api-auth Authentication Webhook ### About the kube-api-auth Authentication Webhook
The `kube-api-auth` microservice is deployed to provide the user authentication functionality for the [authorized cluster endpoint,](../../../../reference-guides/rancher-manager-architecture/communicating-with-downstream-user-clusters.md#4-authorized-cluster-endpoint) which is only available for [RKE clusters.](../../../new-user-guides/kubernetes-clusters-in-rancher-setup/launch-kubernetes-with-rancher/launch-kubernetes-with-rancher.md) When you access the user cluster using `kubectl`, the cluster's Kubernetes API server authenticates you by using the `kube-api-auth` service as a webhook. The `kube-api-auth` microservice is deployed to provide the user authentication functionality for the [authorized cluster endpoint](../../../../reference-guides/rancher-manager-architecture/communicating-with-downstream-user-clusters.md#4-authorized-cluster-endpoint) which is only available for [RKE clusters.](../../../new-user-guides/kubernetes-clusters-in-rancher-setup/launch-kubernetes-with-rancher/launch-kubernetes-with-rancher.md) When you access the user cluster using `kubectl`, the cluster's Kubernetes API server authenticates you by using the `kube-api-auth` service as a webhook.
During cluster provisioning, the file `/etc/kubernetes/kube-api-authn-webhook.yaml` is deployed and `kube-apiserver` is configured with `--authentication-token-webhook-config-file=/etc/kubernetes/kube-api-authn-webhook.yaml`. This configures the `kube-apiserver` to query `http://127.0.0.1:6440/v1/authenticate` to determine authentication for bearer tokens. During cluster provisioning, the file `/etc/kubernetes/kube-api-authn-webhook.yaml` is deployed and `kube-apiserver` is configured with `--authentication-token-webhook-config-file=/etc/kubernetes/kube-api-authn-webhook.yaml`. This configures the `kube-apiserver` to query `http://127.0.0.1:6440/v1/authenticate` to determine authentication for bearer tokens.
@@ -100,7 +100,7 @@ If you want to check resolving of domain names on all of the hosts, execute the
- image: busybox:1.28 - image: busybox:1.28
imagePullPolicy: Always imagePullPolicy: Always
name: alpine name: alpine
command: ["sh", "-c", "tail -f /dev/null"] command: ["sleep", "infinity"]
terminationMessagePath: /dev/termination-log terminationMessagePath: /dev/termination-log
``` ```
@@ -43,7 +43,7 @@ To test the overlay network, you can launch the following `DaemonSet` definition
- image: rancherlabs/swiss-army-knife - image: rancherlabs/swiss-army-knife
imagePullPolicy: Always imagePullPolicy: Always
name: overlaytest name: overlaytest
command: ["sh", "-c", "tail -f /dev/null"] command: ["sleep", "infinity"]
terminationMessagePath: /dev/termination-log terminationMessagePath: /dev/termination-log
``` ```
@@ -74,7 +74,7 @@ To see the Prometheus Targets, install `rancher-monitoring`. Then go to the **Cl
### Viewing the PrometheusRules ### Viewing the PrometheusRules
When you define a Rule (which is declared within a RuleGroup in a PrometheusRule resource), the [spec of the Rule itself](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#rule) contains labels that are used by Alertmanager to figure out which Route should receive a certain Alert. When you define a Rule (which is declared within a RuleGroup in a PrometheusRule resource), the [spec of the Rule itself](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#rule) contains labels that are used by Alertmanager to figure out which Route should receive a certain Alert.
To see the PrometheusRules, install `rancher-monitoring`. Then go to the **Cluster Explorer.** In the top left corner, click **Cluster Explorer > Monitoring.** Then click **Prometheus Rules.** To see the PrometheusRules, install `rancher-monitoring`. Then go to the **Cluster Explorer.** In the top left corner, click **Cluster Explorer > Monitoring.** Then click **Prometheus Rules.**
@@ -85,7 +85,7 @@ A PrometheusRule allows you to define one or more RuleGroups. Each RuleGroup con
- Labels that should be attached to the alert or record that identify it (e.g. cluster name or severity) - Labels that should be attached to the alert or record that identify it (e.g. cluster name or severity)
- Annotations that encode any additional important pieces of information that need to be displayed on the notification for an alert (e.g. summary, description, message, runbook URL, etc.). This field is not required for recording rules. - Annotations that encode any additional important pieces of information that need to be displayed on the notification for an alert (e.g. summary, description, message, runbook URL, etc.). This field is not required for recording rules.
Upon evaluating a [rule](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#rule), Prometheus runs the provided PromQL query, adds the provided labels, and runs the appropriate action for the rule. If the rule triggers an alert, Prometheus also adds the provided annotations. For example, an Alerting Rule that adds `team: front-end` as a label to the provided PromQL query will append that label to the fired alert, which will allow Alertmanager to forward the alert to the correct Receiver. Upon evaluating a [rule](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#rule), Prometheus runs the provided PromQL query, adds the provided labels, and runs the appropriate action for the rule. If the rule triggers an alert, Prometheus also adds the provided annotations. For example, an Alerting Rule that adds `team: front-end` as a label to the provided PromQL query will append that label to the fired alert, which will allow Alertmanager to forward the alert to the correct Receiver.
### Alerting and Recording Rules ### Alerting and Recording Rules
@@ -183,7 +183,7 @@ Refer to [Scraping Metrics with PushProx](#scraping-metrics-with-pushprox) for m
### Defining what Metrics are Scraped ### Defining what Metrics are Scraped
ServiceMonitors and PodMonitors define targets that are intended for Prometheus to scrape. The [Prometheus custom resource](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/design.md#prometheus) tells Prometheus which ServiceMonitors or PodMonitors it should use to find out where to scrape metrics from. ServiceMonitors and PodMonitors define targets that are intended for Prometheus to scrape. The [Prometheus custom resource](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/getting-started/design.md#prometheus) tells Prometheus which ServiceMonitors or PodMonitors it should use to find out where to scrape metrics from.
The Prometheus Operator observes the ServiceMonitors and PodMonitors. When it observes that they are created or updated, it calls the Prometheus API to update the scrape configuration in the Prometheus custom resource and keep it in sync with the scrape configuration in the ServiceMonitors or PodMonitors. This scrape configuration tells Prometheus which endpoints to scrape metrics from and how it will label the metrics from those endpoints. The Prometheus Operator observes the ServiceMonitors and PodMonitors. When it observes that they are created or updated, it calls the Prometheus API to update the scrape configuration in the Prometheus custom resource and keep it in sync with the scrape configuration in the ServiceMonitors or PodMonitors. This scrape configuration tells Prometheus which endpoints to scrape metrics from and how it will label the metrics from those endpoints.
@@ -16,12 +16,13 @@ The following steps quickly deploy a Rancher Server with a single node cluster a
- [Virtualbox](https://www.virtualbox.org): The virtual machines that Vagrant provisions need to be provisioned to VirtualBox. - [Virtualbox](https://www.virtualbox.org): The virtual machines that Vagrant provisions need to be provisioned to VirtualBox.
- At least 4GB of free RAM. - At least 4GB of free RAM.
### Note :::note
- Vagrant will require plugins to create VirtualBox VMs. Install them with the following commands:
`vagrant plugin install vagrant-vboxmanage` Vagrant requires plugins to create VirtualBox VMs. Install them with the following commands:
- `vagrant plugin install vagrant-vboxmanage`
- `vagrant plugin install vagrant-vbguest`
`vagrant plugin install vagrant-vbguest` :::
## Getting Started ## Getting Started
@@ -164,7 +164,7 @@ If you are experiencing issues while testing the connection to the Keycloak serv
When you click on **Authenticate with Keycloak**, you are not redirected to your IdP. When you click on **Authenticate with Keycloak**, you are not redirected to your IdP.
* Verify your Keycloak client configuration. * Verify your Keycloak client configuration.
* Make sure `Force Post Binding` set to `OFF`. * Make sure `Force Post Binding` is set to `OFF`.
### Forbidden message displayed after IdP login ### Forbidden message displayed after IdP login
@@ -10,7 +10,7 @@ After installation, the [system administrator](manage-role-based-access-control-
## First Log In ## First Log In
After you log into Rancher for the first time, Rancher will prompt you for a **Rancher Server URL**.You should set the URL to the main entry point to the Rancher Server. When a load balancer sits in front a Rancher Server cluster, the URL should resolve to the load balancer. The system will automatically try to infer the Rancher Server URL from the IP address or host name of the host running the Rancher Server. This is only correct if you are running a single node Rancher Server installation. In most cases, therefore, you need to set the Rancher Server URL to the correct value yourself. After you log into Rancher for the first time, Rancher will prompt you for a **Rancher Server URL**. You should set the URL to the main entry point to the Rancher Server. When a load balancer sits in front a Rancher Server cluster, the URL should resolve to the load balancer. The system will automatically try to infer the Rancher Server URL from the IP address or host name of the host running the Rancher Server. This is only correct if you are running a single node Rancher Server installation. In most cases, therefore, you need to set the Rancher Server URL to the correct value yourself.
>**Important!** After you set the Rancher Server URL, we do not support updating it. Set the URL with extreme care. >**Important!** After you set the Rancher Server URL, we do not support updating it. Set the URL with extreme care.
@@ -36,7 +36,7 @@ These methods of communicating with downstream Kubernetes clusters are also expl
### About the kube-api-auth Authentication Webhook ### About the kube-api-auth Authentication Webhook
The `kube-api-auth` microservice is deployed to provide the user authentication functionality for the [authorized cluster endpoint,](../../../../reference-guides/rancher-manager-architecture/communicating-with-downstream-user-clusters.md#4-authorized-cluster-endpoint) which is only available for [RKE clusters.](../../../new-user-guides/kubernetes-clusters-in-rancher-setup/launch-kubernetes-with-rancher/launch-kubernetes-with-rancher.md) When you access the user cluster using `kubectl`, the cluster's Kubernetes API server authenticates you by using the `kube-api-auth` service as a webhook. The `kube-api-auth` microservice is deployed to provide the user authentication functionality for the [authorized cluster endpoint](../../../../reference-guides/rancher-manager-architecture/communicating-with-downstream-user-clusters.md#4-authorized-cluster-endpoint) which is only available for [RKE clusters.](../../../new-user-guides/kubernetes-clusters-in-rancher-setup/launch-kubernetes-with-rancher/launch-kubernetes-with-rancher.md) When you access the user cluster using `kubectl`, the cluster's Kubernetes API server authenticates you by using the `kube-api-auth` service as a webhook.
During cluster provisioning, the file `/etc/kubernetes/kube-api-authn-webhook.yaml` is deployed and `kube-apiserver` is configured with `--authentication-token-webhook-config-file=/etc/kubernetes/kube-api-authn-webhook.yaml`. This configures the `kube-apiserver` to query `http://127.0.0.1:6440/v1/authenticate` to determine authentication for bearer tokens. During cluster provisioning, the file `/etc/kubernetes/kube-api-authn-webhook.yaml` is deployed and `kube-apiserver` is configured with `--authentication-token-webhook-config-file=/etc/kubernetes/kube-api-authn-webhook.yaml`. This configures the `kube-apiserver` to query `http://127.0.0.1:6440/v1/authenticate` to determine authentication for bearer tokens.
@@ -28,7 +28,7 @@ To create rule groups in the Rancher UI,
## About the PrometheusRule Custom Resource ## About the PrometheusRule Custom Resource
When you define a Rule (which is declared within a RuleGroup in a PrometheusRule resource), the [spec of the Rule itself](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#rule) contains labels that are used by Alertmanager to figure out which Route should receive this Alert. For example, an Alert with the label `team: front-end` will be sent to all Routes that match on that label. When you define a Rule (which is declared within a RuleGroup in a PrometheusRule resource), the [spec of the Rule itself](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#rule) contains labels that are used by Alertmanager to figure out which Route should receive this Alert. For example, an Alert with the label `team: front-end` will be sent to all Routes that match on that label.
Prometheus rule files are held in PrometheusRule custom resources. A PrometheusRule allows you to define one or more RuleGroups. Each RuleGroup consists of a set of Rule objects that can each represent either an alerting or a recording rule with the following fields: Prometheus rule files are held in PrometheusRule custom resources. A PrometheusRule allows you to define one or more RuleGroups. Each RuleGroup consists of a set of Rule objects that can each represent either an alerting or a recording rule with the following fields:
@@ -37,7 +37,7 @@ Prometheus rule files are held in PrometheusRule custom resources. A PrometheusR
- Labels that should be attached to the alert or record that identify it (e.g. cluster name or severity) - Labels that should be attached to the alert or record that identify it (e.g. cluster name or severity)
- Annotations that encode any additional important pieces of information that need to be displayed on the notification for an alert (e.g. summary, description, message, runbook URL, etc.). This field is not required for recording rules. - Annotations that encode any additional important pieces of information that need to be displayed on the notification for an alert (e.g. summary, description, message, runbook URL, etc.). This field is not required for recording rules.
For more information on what fields can be specified, please look at the [Prometheus Operator spec.](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#prometheusrulespec) For more information on what fields can be specified, please look at the [Prometheus Operator spec.](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#prometheusrulespec)
Use the label selector field `ruleSelector` in the Prometheus object to define the rule files that you want to be mounted into Prometheus. Use the label selector field `ruleSelector` in the Prometheus object to define the rule files that you want to be mounted into Prometheus.
@@ -8,7 +8,7 @@ title: Monitoring V2 Configuration Guides
This page captures some of the most important options for configuring Monitoring V2 in the Rancher UI. This page captures some of the most important options for configuring Monitoring V2 in the Rancher UI.
For information on configuring custom scrape targets and rules for Prometheus, please refer to the upstream documentation for the [Prometheus Operator.](https://github.com/prometheus-operator/prometheus-operator) Some of the most important custom resources are explained in the Prometheus Operator [design documentation.](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/design.md) The Prometheus Operator documentation can help also you set up RBAC, Thanos, or custom configuration. For information on configuring custom scrape targets and rules for Prometheus, please refer to the upstream documentation for the [Prometheus Operator.](https://github.com/prometheus-operator/prometheus-operator) Some of the most important custom resources are explained in the Prometheus Operator [design documentation.](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/getting-started/design.md) The Prometheus Operator documentation can help also you set up RBAC, Thanos, or custom configuration.
## Setting Resource Limits and Requests ## Setting Resource Limits and Requests
@@ -160,10 +160,11 @@ You may terminate the SSL/TLS on a L7 load balancer external to the Rancher clus
Your load balancer must support long lived websocket connections and will need to insert proxy headers so Rancher can route links correctly. Your load balancer must support long lived websocket connections and will need to insert proxy headers so Rancher can route links correctly.
### Configuring Ingress for External TLS when Using NGINX v0.25 ### Configuring Ingress for External TLS when Using NGINX v0.22
In NGINX v0.25, the behavior of NGINX has [changed](https://github.com/kubernetes/ingress-nginx/blob/master/Changelog.md#0220) regarding forwarding headers and external TLS termination. Therefore, in the scenario that you are using external TLS termination configuration with NGINX v0.25, you must edit the `cluster.yml` to enable the `use-forwarded-headers` option for ingress: In NGINX v0.22, the behavior of NGINX has [changed](https://github.com/kubernetes/ingress-nginx/blob/06efac9f0b6f8f84b553f58ccecf79dc42c75cc6/Changelog.md) regarding forwarding headers and external TLS termination. Therefore, in the scenario that you are using external TLS termination configuration with NGINX v0.22, you must enable the `use-forwarded-headers` option for ingress:
For RKE installations, edit the `cluster.yml` to add the following settings.
```yaml ```yaml
ingress: ingress:
provider: nginx provider: nginx
@@ -171,6 +172,22 @@ ingress:
use-forwarded-headers: 'true' use-forwarded-headers: 'true'
``` ```
For RKE2 installations, you can create a custom `rke2-ingress-nginx-config.yaml` file at `/var/lib/rancher/rke2/server/manifests/rke2-ingress-nginx-config.yaml` containing this required setting to enable using forwarded headers with external TLS termination. Without this required setting applied, the external LB will continuously respond with redirect loops it receives from the ingress controller. (This can be created before or after rancher is installed, rke2 server agent will notice this addition and automatically apply it.)
```yaml
---
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
name: rke2-ingress-nginx
namespace: kube-system
spec:
valuesContent: |-
controller:
config:
use-forwarded-headers: "true"
```
### Required Headers ### Required Headers
- `Host` - `Host`
@@ -8,7 +8,7 @@ title: Monitoring V2 Configuration Examples
## ServiceMonitor ## ServiceMonitor
See the official prometheus-operator GitHub repo for an example [ServiceMonitor](https://github.com/prometheus-operator/prometheus-operator/blob/master/example/prometheus-operator-crd/monitoring.coreos.com_servicemonitors.yaml) YAML. See the official prometheus-operator GitHub repo for an example [ServiceMonitor](https://github.com/prometheus-operator/prometheus-operator/blob/main/example/prometheus-operator-crd/monitoring.coreos.com_servicemonitors.yaml) YAML.
## PodMonitor ## PodMonitor
@@ -20,9 +20,9 @@ This pseudo-CRD maps to a section of the Prometheus custom resource configuratio
When a ServiceMonitor is created, the Prometheus Operator updates the Prometheus scrape configuration to include the ServiceMonitor configuration. Then Prometheus begins scraping metrics from the endpoint defined in the ServiceMonitor. When a ServiceMonitor is created, the Prometheus Operator updates the Prometheus scrape configuration to include the ServiceMonitor configuration. Then Prometheus begins scraping metrics from the endpoint defined in the ServiceMonitor.
Any Services in your cluster that match the labels located within the ServiceMonitor `selector` field will be monitored based on the `endpoints` specified on the ServiceMonitor. For more information on what fields can be specified, please look at the [spec](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#servicemonitor) provided by Prometheus Operator. Any Services in your cluster that match the labels located within the ServiceMonitor `selector` field will be monitored based on the `endpoints` specified on the ServiceMonitor. For more information on what fields can be specified, please look at the [spec](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#servicemonitor) provided by Prometheus Operator.
For more information about how ServiceMonitors work, refer to the [Prometheus Operator documentation.](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/user-guides/running-exporters.md) For more information about how ServiceMonitors work, refer to the [Prometheus Operator documentation.](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/user-guides/running-exporters.md)
## PodMonitors ## PodMonitors
@@ -30,4 +30,4 @@ This pseudo-CRD maps to a section of the Prometheus custom resource configuratio
When a PodMonitor is created, the Prometheus Operator updates the Prometheus scrape configuration to include the PodMonitor configuration. Then Prometheus begins scraping metrics from the endpoint defined in the PodMonitor. When a PodMonitor is created, the Prometheus Operator updates the Prometheus scrape configuration to include the PodMonitor configuration. Then Prometheus begins scraping metrics from the endpoint defined in the PodMonitor.
Any Pods in your cluster that match the labels located within the PodMonitor `selector` field will be monitored based on the `podMetricsEndpoints` specified on the PodMonitor. For more information on what fields can be specified, please look at the [spec](https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#podmonitorspec) provided by Prometheus Operator. Any Pods in your cluster that match the labels located within the PodMonitor `selector` field will be monitored based on the `podMetricsEndpoints` specified on the PodMonitor. For more information on what fields can be specified, please look at the [spec](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#podmonitor) provided by Prometheus Operator.
@@ -100,7 +100,7 @@ If you want to check resolving of domain names on all of the hosts, execute the
- image: busybox:1.28 - image: busybox:1.28
imagePullPolicy: Always imagePullPolicy: Always
name: alpine name: alpine
command: ["sh", "-c", "tail -f /dev/null"] command: ["sleep", "infinity"]
terminationMessagePath: /dev/termination-log terminationMessagePath: /dev/termination-log
``` ```
@@ -43,7 +43,7 @@ To test the overlay network, you can launch the following `DaemonSet` definition
- image: rancherlabs/swiss-army-knife - image: rancherlabs/swiss-army-knife
imagePullPolicy: Always imagePullPolicy: Always
name: overlaytest name: overlaytest
command: ["sh", "-c", "tail -f /dev/null"] command: ["sleep", "infinity"]
terminationMessagePath: /dev/termination-log terminationMessagePath: /dev/termination-log
``` ```
@@ -31,7 +31,7 @@ Note that upgrades _to_ or _from_ any chart in the [rancher-alpha repository](..
The upgrade instructions assume you are using Helm 3. The upgrade instructions assume you are using Helm 3.
For migration of installs started with Helm 2, refer to the official [Helm 2 to 3 migration docs.](https://helm.sh/blog/migrate-from-helm-v2-to-helm-v3/) The [Helm 2 upgrade page here](https://github.com/rancher/rancher-docs/tree/main/archived_docs/en/version-2.0-2.4/getting-started/installation-and-upgrade/install-upgrade-on-a-kubernetes-cluster/upgrades/helm2.md)provides a copy of the older upgrade instructions that used Helm 2, and it is intended to be used if upgrading to Helm 3 is not feasible. For migration of installs started with Helm 2, refer to the official [Helm 2 to 3 migration docs.](https://helm.sh/blog/migrate-from-helm-v2-to-helm-v3/) The [Helm 2 upgrade page here](https://github.com/rancher/rancher-docs/tree/main/archived_docs/en/version-2.0-2.4/getting-started/installation-and-upgrade/install-upgrade-on-a-kubernetes-cluster/upgrades/helm2.md) provides a copy of the older upgrade instructions that used Helm 2, and it is intended to be used if upgrading to Helm 3 is not feasible.
### For air-gapped installs: Populate private registry ### For air-gapped installs: Populate private registry
@@ -209,10 +209,11 @@ If you are using a Private CA signed certificate, add `--set privateCA=true` and
Your load balancer must support long lived websocket connections and will need to insert proxy headers so Rancher can route links correctly. Your load balancer must support long lived websocket connections and will need to insert proxy headers so Rancher can route links correctly.
### Configuring Ingress for External TLS when Using NGINX v0.25 ### Configuring Ingress for External TLS when Using NGINX v0.22
In NGINX v0.25, the behavior of NGINX has [changed](https://github.com/kubernetes/ingress-nginx/blob/master/Changelog.md#0220) regarding forwarding headers and external TLS termination. Therefore, in the scenario that you are using external TLS termination configuration with NGINX v0.25, you must edit the `cluster.yml` to enable the `use-forwarded-headers` option for ingress: In NGINX v0.22, the behavior of NGINX has [changed](https://github.com/kubernetes/ingress-nginx/blob/06efac9f0b6f8f84b553f58ccecf79dc42c75cc6/Changelog.md) regarding forwarding headers and external TLS termination. Therefore, in the scenario that you are using external TLS termination configuration with NGINX v0.22, you must enable the `use-forwarded-headers` option for ingress:
For RKE installations, edit the `cluster.yml` to add the following settings.
```yaml ```yaml
ingress: ingress:
provider: nginx provider: nginx
@@ -220,6 +221,22 @@ ingress:
use-forwarded-headers: 'true' use-forwarded-headers: 'true'
``` ```
For RKE2 installations, you can create a custom `rke2-ingress-nginx-config.yaml` file at `/var/lib/rancher/rke2/server/manifests/rke2-ingress-nginx-config.yaml` containing this required setting to enable using forwarded headers with external TLS termination. Without this required setting applied, the external LB will continuously respond with redirect loops it receives from the ingress controller. (This can be created before or after rancher is installed, rke2 server agent will notice this addition and automatically apply it.)
```yaml
---
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
name: rke2-ingress-nginx
namespace: kube-system
spec:
valuesContent: |-
controller:
config:
use-forwarded-headers: "true"
```
### Required Headers ### Required Headers
- `Host` - `Host`
@@ -27,15 +27,13 @@ This Quick Start Guide is divided into different tasks for easier consumption.
## Prerequisites ## Prerequisites
- An [Equinix Metal account](https://metal.equinix.com/developers/docs/accounts/users/) - An [Equinix Metal account](https://deploy.equinix.com/developers/docs/metal/identity-access-management/users/)
- An [Equinix Metal project](https://metal.equinix.com/developers/docs/accounts/projects/) - An [Equinix Metal project](https://deploy.equinix.com/developers/docs/metal/projects/creating-a-project/)
### 1. Provision a Equinix Metal Host ### 1. Provision a Equinix Metal Host
Begin deploying an Equinix Metal Host. Equinix Metal Servers can be provisioned from either the Equinix Metal console, CLI, or API. You can find instructions for each deployment type on the [Equinix Metal deployment documentation](https://metal.equinix.com/developers/docs/deploy/on-demand/). You can find additional documentation on Equinix Metal server types and prices below: Begin deploying an Equinix Metal Host. Equinix Metal Servers can be provisioned from either the Equinix Metal console, CLI, or API. You can find instructions for each deployment type on the [Equinix Metal deployment documentation](https://deploy.equinix.com/developers/docs/metal/deploy/on-demand/). You can find additional information on Equinix Metal server types in the [Equinix Metal Documentation](https://deploy.equinix.com/developers/docs/metal/hardware/standard-servers/).
- [Equinix Metal Server Types](https://metal.equinix.com/developers/docs/servers/about/)
- [Equinix Metal Pricing](https://metal.equinix.com/developers/docs/servers/server-specs/)
:::note Notes: :::note Notes:
@@ -20,12 +20,13 @@ The intent of these guides is to quickly launch a sandbox that you can use to ev
- [Virtualbox](https://www.virtualbox.org): The virtual machines that Vagrant provisions need to be provisioned to VirtualBox. - [Virtualbox](https://www.virtualbox.org): The virtual machines that Vagrant provisions need to be provisioned to VirtualBox.
- At least 4GB of free RAM. - At least 4GB of free RAM.
### Note :::note
- Vagrant will require plugins to create VirtualBox VMs. Install them with the following commands:
`vagrant plugin install vagrant-vboxmanage` Vagrant requires plugins to create VirtualBox VMs. Install them with the following commands:
- `vagrant plugin install vagrant-vboxmanage`
- `vagrant plugin install vagrant-vbguest`
`vagrant plugin install vagrant-vbguest` :::
## Getting Started ## Getting Started

Some files were not shown because too many files have changed in this diff Show More