Compare commits

...
Author SHA1 Message Date
Lucas Saintarbor e30e3a4d18 v2.12.8 - Rancher Manager Release Maintenance (#2242) (#2253)
* Update the deprecated features table

* Update the CSP adapter compatibility matrix

* Update the Rancher:webhook version mapping table

* Update the versions table
2026-03-25 20:11:25 -07:00
Lucas Saintarbor ebcf5ee71f Merge pull request #2252 from rancher/v2.11.12
Merge release v2.11.12 to main
2026-03-25 20:10:45 -07:00
MaryandPetr Kovar 6913cccd17 Update GitHub link to point to main branch (#2136)
* Update GitHub link to point to main branch

related to https://github.com/rancher/rancher/issues/51277

* changing master to main on user-cluster.sh script

* updating 2.14

---------

Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-03-24 13:28:46 -07:00
hridyesh bisht 877b9cbf9d Merge pull request #2248 from kakabisht/feat-add-info-fleet-resource
Adding information about Fleet resource limits
2026-03-23 23:29:18 +05:30
hridyesh bishtandLucas Saintarbor 1ea3682342 Update docs/integrations-in-rancher/fleet/overview.md
Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>
2026-03-23 22:43:55 +05:30
hridyesh bisht 333dcfe06c Adding information in docs 2026-03-23 14:24:18 +05:30
hridyesh bishtandLucas Saintarbor 5be76d49c9 Update versioned_docs/version-2.14/integrations-in-rancher/fleet/overview.md
Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>
2026-03-23 14:07:03 +05:30
hridyesh bishtandLucas Saintarbor cdd40292a4 Update versioned_docs/version-2.14/integrations-in-rancher/fleet/overview.md
Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>
2026-03-23 14:06:56 +05:30
Lucas Saintarbor 8485d73025 v2.12.8 - Rancher Manager Release Maintenance (#2242)
* Update the deprecated features table

* Update the CSP adapter compatibility matrix

* Update the Rancher:webhook version mapping table

* Update the versions table
2026-03-20 12:00:22 -07:00
Lucas SaintarborandBilly Tat d6460bbf45 v2.11.12 - Rancher Manager Release Maintenance (#2241)
* Update the deprecated features table

* Update the CSP adapter compatibility matrix

* Update the Rancher:webhook version mapping table

* Update the versions table

* Update src/pages/versions.md

Co-authored-by: Billy Tat <btat@suse.com>

---------

Co-authored-by: Billy Tat <btat@suse.com>
2026-03-20 12:00:02 -07:00
hridyesh bisht 56ca46001c Adding information about Fleet resource limits 2026-03-20 16:37:01 +05:30
Lucas Saintarbor 8390518777 Merge pull request #2245 from rancher/main
Sync main to v2.12.8
2026-03-19 16:40:57 -07:00
Lucas Saintarbor f21c904c75 Merge pull request #2244 from rancher/main
Sync main to v2.11.12
2026-03-19 16:40:49 -07:00
Sunil Singh 2b7f6179cd Merge pull request #2238 from sunilarjun/update-ingress
Update ingress-nginx pt 1
2026-03-19 16:06:15 -07:00
Sunil Singh 8c8f8a5f2e Fixing anchors
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 15:32:38 -07:00
Sunil Singh 50c0b2901e Update dns.md after review
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 15:20:49 -07:00
Sunil Singh ff518c995c Update vsphere-storage.md after review
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 15:20:24 -07:00
Sunil Singh b124e543ab Updating sidebars wrt removed page
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 14:28:26 -07:00
Sunil Singh 00e60c489c Removing links to removed RKE1 page from latest-v2.12.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 14:17:10 -07:00
Sunil Singh 5856a33216 Updating load-balancer-and-ingress-controller.md across versions
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 13:38:12 -07:00
Sunil Singh 8abdff2e16 Updating ingress-configurations.md across versions
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 13:26:41 -07:00
Sunil Singh 27c40e5b37 Updating layer-4-and-layer-7-load-balancing.md, adding note v2.10/v2.11 as RKE still applicable
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 13:25:20 -07:00
Sunil Singh 0a206c2a71 Updating how-monitoring-works.md across versions
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 12:54:23 -07:00
Sunil Singh 0035f604cf Removing rke1-cluster-configuration.md - includes nginx/part of RKE1 removal
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 11:23:11 -07:00
Billy Tat b6192dee43 Ingress nginx replacement (#2237)
* Replace/remove ingress-nginx references

* Add links to annotations + remove example using unsupported annotation
2026-03-19 11:14:14 -07:00
Sunil Singh a572532618 Updating kubernetes-resources.md after review
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 11:01:37 -07:00
Sunil Singh 4ed8b39eca Update HA example output rke2-for-rancher.md after review
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-19 10:59:59 -07:00
Sunil Singh 4174efc9b6 Updating nginx to traefik - kubernetes-resources.md
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-18 08:57:33 -07:00
Sunil Singh eef73d106d Reverting changes to troubleshooting.md as handled in related PR.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-17 16:28:53 -07:00
Sunil Singh 946b9fc10a Removing nginx-ingress, updating some phrasing regarding Traefik Ingress usage.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-17 15:54:04 -07:00
Petr Kovar 8fbc785b2c Merge pull request #2195 from swastik959/ipv6
[main] Updated docs for ipv6/dual-stack cluster provisioning on rancher
2026-03-17 19:13:34 +01:00
Lucas Saintarbor 2386faad52 Move Configuring OIDC Single Logout (SLO) section on relevant pages (#2233) 2026-03-16 11:37:28 -07:00
swastik959 20d9e00055 Update docs for ipv6/dual-stack and backport to v2.14 2026-03-16 17:11:19 +05:30
Sunil Singh a91e98aeed Merge pull request #2224 from sunilarjun/update-ns
Updating ns exemptions
2026-03-12 14:12:46 -07:00
Sunil Singh dd90555a64 Removing ingress-nginx due to deprecation and replacing with traefik.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-12 11:12:28 -07:00
MezaandLucas Saintarbor fc747f457a [main] Replace references to deprecated Helm chart values (#2221)
* [main] Replace references to deprecated Helm chart values

Signed-off-by: Meza <meza-xyz@proton.me>

---------

Signed-off-by: Meza <meza-xyz@proton.me>
Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>
2026-03-12 10:21:03 -07:00
Manuel BuilandPetr Kovar e88572c810 Add Traefik migration to docs and backports (#2184)
Signed-off-by: Manuel Buil <mbuil@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-03-12 09:11:56 -07:00
Lucas Saintarbor 50736e012a Explain SAML and OpenLDAP Group Permissions (#2225)
* Add SamlOpenLDAPGroupPermissions shared file

* Add SamlOpenLDAPGroupPermissions shared file to Configure Keycloak (SAML) page

* Add SamlOpenLDAPGroupPermissions shared file to Configure Okta (SAML) page

* Add SamlOpenLDAPGroupPermissions shared file to Configure PingIdentity (SAML) page

* Add SamlOpenLDAPGroupPermissions shared file to Configuring Rancher for Microsoft AD FS page

* Add SamlOpenLDAPGroupPermissions shared file to Group Permissions with Shibboleth and OpenLDAP page

* Add SamlOpenLDAPGroupPermissions shared file to other versions of Configure Keycloak (SAML) page

* Add SamlOpenLDAPGroupPermissions shared file to other versions of Configure Okta (SAML) page

* Add SamlOpenLDAPGroupPermissions shared file to other versions Configure PingIdentity (SAML) page

* Add SamlOpenLDAPGroupPermissions shared file to other versions of  Configuring Rancher for Microsoft AD FS page

* Add SamlOpenLDAPGroupPermissions shared file to other versions of Group Permissions with Shibboleth and OpenLDAP page
2026-03-12 08:46:15 -07:00
Billy Tat 85021d6a4d Merge pull request #2229 from btat/version-status
Update banners to reflect current version status
2026-03-11 16:50:29 -07:00
Billy Tat b336f5f47c Update banners to reflect current version status
v2.10 will be EOL 2026-06
v2.11 EOM 2025-10 and will be EOL 2026-10
v2.12 EOM 2026-02
2026-03-11 15:56:19 -07:00
Siva Kanakala 94c60502ea Merge pull request #2208 from skanakal/upgrade-doc-2204
Add subsection to review Rancher feature chart versions before Rancher upgrade
2026-03-11 14:08:55 +05:30
Siva Kanakala cc2e26e03e upgrade-feature-charts 2026-03-10 21:02:39 +05:30
Sunil Singh 473eea4b41 Update code block after review
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-09 14:16:40 -07:00
Sunil Singh a5e6676adb Merge branch 'main' into update-ns 2026-03-06 15:10:54 -08:00
Sunil Singh a7a0a05827 Merge pull request #2223 from LucasSaintarbor/increase-max-old-space-size
Increase max-old-space-size in test deployment
2026-03-06 15:08:06 -08:00
Sunil Singh b531d54872 Updating ns exemption list in sample configurations.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-03-06 14:21:52 -08:00
LucasSaintarbor 860d55373c Increase max-old-space-size to 10240 bytes 2026-03-06 13:32:27 -08:00
LucasSaintarbor ad82b388e9 Increase max-old-space-size to 9216 bytes 2026-03-06 12:40:53 -08:00
LucasSaintarbor 4d915c71c7 Increase max-old-space-size to 8192 bytes 2026-03-06 12:04:46 -08:00
Lucas Saintarbor 2dcfa6f6b8 Add v2.14 preview docs (#2212) 2026-03-05 12:30:57 -08:00
Lucas Saintarbor 4a0d71b3f3 Archive v2.9 docs (#2219)
* Archive v2.9 content files / add archive notice

* Update config / sidebar

* Remove v2.9 redirects

* Fix typo in config

* Update versions listing page

* Fix typo in notice files

* Fix typo in versions listing page
2026-03-04 16:54:35 -08:00
Billy Tat 917fb71cc6 Merge pull request #2218 from btat/remove-workflow
Remove workflow
2026-03-04 11:54:31 -08:00
Billy Tat 968b17b439 Remove workflow 2026-03-04 11:21:47 -08:00
Lucas SaintarborandPetr Kovar 837642ac0a v2.13.2 - Rancher Manager Release Maintenance (#2201)
Helps #2187.

Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-02-25 15:46:35 -08:00
Lucas SaintarborandPetr Kovar ce8a2066c6 v2.12.7 - Rancher Manager Release Maintenance (#2200)
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-02-25 15:46:27 -08:00
Lucas SaintarborandPetr Kovar dd56eb8dfa v2.11.11 - Rancher Manager Release Maintenance (#2199)
Helps #2185.

Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-02-25 15:46:17 -08:00
Billy Tat 55eaa901b9 Merge pull request #2074 from andreas-kupries/rancher-45110-global-resource-docs
initial page listing some of rancher's global resources
2026-02-24 08:59:10 -08:00
Billy Tat f8442a4de8 Backport changes to v2.9-v2.12 2026-02-24 08:25:06 -08:00
Petr Kovar ba36e5a3cc Merge pull request #2167 from rancher/copilot/clarify-audit-policy-delivery
Clarify audit-policy-file delivery scope and recommend machineSelectorConfig
2026-02-24 16:52:56 +01:00
Billy Tat 1d573ebad8 Merge pull request #2191 from LucasSaintarbor/remove-deprecation-policy
Remove deprecated policy section from Deprecated Features in Rancher page
2026-02-20 08:50:01 -08:00
LucasSaintarbor 6d1b2bfaa1 Remove deprecated policy section from Deprecated Features in Rancher page 2026-02-20 08:11:54 -08:00
Sunil Singh fb61897f02 Merge pull request #2179 from apoorvajagtap/nodedrain-2178
Documents node draining behvaiour during Rancher upgrades
2026-02-10 15:17:47 -08:00
Petr Kovar ec6ca0421f Merge pull request #2180 from axeal/air-gapped-migration-docs
Improve air-gapped migration documentation
2026-02-10 17:25:54 +01:00
Alex Seymour 3850db7f7a Update indentation for air-gapped note 2026-02-10 14:32:40 +01:00
Sunil Singh a71cd82b3b Combining the note admonitions to decrease repetition.
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-02-09 10:46:44 -08:00
Sunil Singh 10c050251f Merge pull request #2172 from sunilarjun/port-pr-699-prod-docs
Sync Product PR #699 (Updating CNI - Canal Section)
2026-02-09 10:45:27 -08:00
Apoorva Jagtap 0ee6a3b95a adds note for node-drain behavior 2026-02-06 12:14:50 +05:30
Petr Kovar aab097c91f Merge pull request #2181 from pmkovar/security-advisories-and-cves.md
Remove leftover reference
2026-02-05 21:26:37 +01:00
Petr Kovar ce270291b4 Remove leftover reference 2026-02-05 20:56:52 +01:00
Alex Seymour 7302475fb7 Update air-gapped migration instructions for Rancher backup and restore 2026-02-05 15:05:12 +01:00
Alex Seymour 0c4649c273 Clarify outbound connectivity requirements for rancher-backup installation in air-gapped environments 2026-02-05 15:05:01 +01:00
Alex Seymour ee021062c6 Enhance air-gapped migration instructions for Rancher backup and restore 2026-02-05 15:00:08 +01:00
Lucas Saintarbor 20fab76cfc Update CVE pages (#2174) 2026-01-29 15:43:33 -08:00
a94f94128a Merge release v2.13.2 to main (#2164)
* Sync changes from main to v2.13.2 (#2156)

* Fixed links to images

* Added documentation for using the keywords option in Chart.yaml

* Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)

* Revert image link change, it would break the docs website

* Fixed some typos and backported docs

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>

* v2.13.2 - Rancher Manager Release Maintenance (#2160)

* Update the versions table

* Update the Rancher:webhook version mapping table

* Update the CSP adapter compatibility matrix

* Update the deprecated features table

* Update release date (#2171)

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-01-29 12:58:11 -08:00
5b60dca51d Merge release v2.12.6 to main (#2163)
* Sync changes from main to v2.12.6 (#2155)

* Fixed links to images

* Added documentation for using the keywords option in Chart.yaml

* Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)

* Revert image link change, it would break the docs website

* Fixed some typos and backported docs

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>

* v2.12.6 - Rancher Manager Release Maintenance (#2159)

* Update the versions table

* Update the Rancher:webhook version mapping table

* Update the CSP adapter compatibility matrix

* Update the deprecated features table

* Update release date (#2170)

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-01-29 12:57:59 -08:00
78f538b5c3 Merge release v2.11.10 to main (#2162)
* Sync changes from main to v2.11.10 (#2154)

* Fixed links to images

* Added documentation for using the keywords option in Chart.yaml

* Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)

* Revert image link change, it would break the docs website

* Fixed some typos and backported docs

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>

* v2.11.10 - Rancher Manager Release Maintenance (#2158)

* Update the versions table

* Update the Rancher:webhook version mapping table

* Update the CSP adapter compatibility matrix

* Update the deprecated features table

* Update release date (#2169)

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-01-29 12:57:48 -08:00
b6a5fcc2af Merge release v2.10.11 to main (#2173)
* Sync changes from main to v2.10.11 (#2153)

* Fixed links to images

* Added documentation for using the keywords option in Chart.yaml

* Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)

* Revert image link change, it would break the docs website

* Fixed some typos and backported docs

---------

Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>

* v2.10.11 - Rancher Manager Release Maintenance (#2157)

* Update the Rancher:webhook version mapping table

* Update the CNI popularity table

* Update the versions table

* Update the CSP adapter compatibility matrix

* Update the deprecated features table

* Update release date (#2168)

---------

Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>
Co-authored-by: mschroeder-fzj <m.schroeder@fz-juelich.de>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
2026-01-29 12:57:36 -08:00
Sunil Singh 5fa51c65b8 Porting product docs PR #699 https://github.com/rancher/rancher-product-docs/pull/699
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2026-01-29 11:24:00 -08:00
copilot-swe-agent[bot]andjiaqiluo a649d9bff4 Remove redundant machineSelectorConfig tips from Method 2
Co-authored-by: jiaqiluo <6218999+jiaqiluo@users.noreply.github.com>
2026-01-29 19:19:22 +00:00
copilot-swe-agent[bot]andsnasovich 9cbbe1fe64 Update audit-policy-file documentation to clarify delivery and recommend machineSelectorConfig
Co-authored-by: snasovich <85187633+snasovich@users.noreply.github.com>
2026-01-29 16:27:48 +00:00
copilot-swe-agent[bot] f68384825a Initial plan 2026-01-29 16:25:14 +00:00
Petr Kovar ab234cc365 Merge pull request #2113 from mschroeder-fzj/main
Creating Apps: Added doc for `keywords`
2026-01-27 16:26:47 +01:00
Marcel Schröder 6dc122f0f9 Fixed some typos and backported docs 2026-01-26 07:27:35 +01:00
Marcel Schröder 2c2d1fd70c Revert image link change, it would break the docs website 2026-01-26 07:14:59 +01:00
mschroeder-fzj 385a493e52 Merge branch 'rancher:main' into main 2026-01-26 07:03:54 +01:00
Billy Tat d870a1a12a Merge pull request #2148 from btat/product-sync/pr587-ec2-permissions
Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions)
2026-01-23 09:48:39 -08:00
Andreas Kupries 9b6e8a64e7 address comment, rephrase for clarity 2026-01-23 09:30:25 +01:00
Andreas Kupries 3e550789b5 address comments 2026-01-23 09:30:25 +01:00
Andreas Kupries 69e366256f initial page listing some of rancher's global resources
(known incomplete)
2026-01-23 09:30:25 +01:00
Petr Kovar 3d9908ed90 Merge branch 'main' into main 2026-01-20 16:26:50 +01:00
Billy Tat be7c002fc6 Merge pull request #2150 from rancher/revert-2146-add-fossa-workflow
Revert "Add FOSSA scanning workflow"
2026-01-16 13:45:09 -08:00
Billy Tat c5aac3c2ea Revert "Add FOSSA scanning workflow" 2026-01-16 13:10:12 -08:00
Billy Tat 2a925479f5 Sync Product PR #587 (Add ec2:DescribeAvailabilityZones to control plane and etcd/worker permissions) 2026-01-15 16:14:25 -08:00
Sunil Singh 3db5dcfe5b Merge pull request #2146 from macedogm/add-fossa-workflow
Add FOSSA scanning workflow
2026-01-14 08:34:53 -08:00
Guilherme Macedo 493918ef4b Add FOSSA scanning workflow
Signed-off-by: Guilherme Macedo <guilherme@gmacedo.com>
2026-01-13 23:08:44 -03:00
Billy Tat b9dc7cf45f Merge pull request #2117 from axeal/patch-2
Clarify JSON array format for OIDC groups and full_group_path claims
2026-01-13 15:56:16 -08:00
Billy Tat 50a89fceea Apply to other versions 2026-01-13 15:22:44 -08:00
Alex Seymour c13e9c7023 Clarify JSON array format for OIDC groups and full_group_path claims
Clarify JSON array format for OIDC groups and full_group_path claims, after a recent case where an issue occurred as a result of the groups claim formatted as a comma-separated string
2026-01-13 15:15:41 -08:00
Billy Tat 86ce745693 Merge pull request #2139 from btat/copyright
Bump copyright year
2026-01-12 16:24:10 -08:00
Billy Tat ea4b542e49 Bump copyright year 2026-01-12 15:02:56 -08:00
mschroeder-fzj 5519e07a14 Merge branch 'rancher:main' into main 2026-01-12 09:29:20 +01:00
Petr Kovar 607605ef8c Merge pull request #2119 from rancher/copilot/update-deprecation-policy-links
Fix deprecated deprecation policy link in FAQ
2026-01-08 20:35:04 +01:00
Petr Kovar 6c6d269350 Merge branch 'main' into copilot/update-deprecation-policy-links 2026-01-08 20:00:00 +01:00
mschroeder-fzj 4bb5fd9918 Merge branch 'rancher:main' into main 2026-01-05 11:42:24 +01:00
Billy Tat 1db0a99873 Merge pull request #2133 from btat/fix-checkmark
Fix checkmark entity
2025-12-30 09:21:16 -08:00
Billy Tat 613ac34951 Fix checkmark entity 2025-12-30 08:29:25 -08:00
Billy Tat 8d0683cf27 Merge pull request #2130 from jmeza-xyz/etcd-tuning-fix-typo
[docs] etcd tuning fix typo etcd-args
2025-12-19 16:18:50 -08:00
Sunil Singh 8c8388e576 Merge pull request #2131 from sunilarjun/v2.13.1-registry-note
Adding admonition for registry issue v2.13.1
2025-12-19 15:13:48 -08:00
Sunil Singh 8b903fb7e6 Adding admonition for registry issue v2.13.1
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
2025-12-19 14:37:40 -08:00
Meza e4ef173aef [docs] etcd tuning fix typos etcd-args
Signed-off-by: Meza <meza-xyz@proton.me>
2025-12-19 15:39:32 -05:00
Meza 941e23dbc5 [docs] Update etcd tuning with incorrect RKE1 references (#2128)
* [docs] Update etcd tuning with incorrect RKE1 references

Signed-off-by: Meza <meza-xyz@proton.me>

* Update versioned 2.12/2.13 and zh docs

Signed-off-by: Meza <meza-xyz@proton.me>

* Updated zh current doc

Signed-off-by: Meza <meza-xyz@proton.me>

---------

Signed-off-by: Meza <meza-xyz@proton.me>
2025-12-19 10:21:40 -08:00
Sunil Singh 50de72dac8 Merge pull request #2127 from rancher/v2.13.1
Merge release v2.13.1 into main
2025-12-18 19:28:07 -08:00
Sunil Singh bd5ce6a698 Merge pull request #2126 from rancher/v2.12.5
Merge release v2.12.5 into main
2025-12-18 19:27:48 -08:00
Sunil Singh 6b578c03b8 Merge pull request #2125 from rancher/v2.11.9
Merge release v2.11.9 into main
2025-12-18 19:27:32 -08:00
Petr Kovar 3e84995a70 Merge pull request #2123 from pmkovar/v2.11.9-maintenance
v2.11.9 - Rancher Manager Release Maintenance
2025-12-18 18:03:09 +01:00
Petr Kovar 73eba84c8f Merge pull request #2122 from pmkovar/v2.12.5-maintenance
v2.12.5 - Rancher Manager Release Maintenance
2025-12-18 18:02:29 +01:00
Petr Kovar 83169414e0 Merge pull request #2121 from pmkovar/v2.13.1-maintenance
v2.13.1 - Rancher Manager Release Maintenance
2025-12-18 18:01:58 +01:00
Petr Kovar 59c6d18303 Apply suggestions from code review 2025-12-18 16:19:48 +01:00
Petr Kovar cc971f12cd Apply suggestions from code review 2025-12-18 16:18:45 +01:00
Petr Kovar 56217388e0 Apply suggestions from code review 2025-12-18 16:17:39 +01:00
Petr Kovar 4038b6b6a0 Update _cni-popularity.md 2025-12-16 20:13:07 +01:00
Petr Kovar f3ebddde6e v2.11.9 - Rancher Manager Release Maintenance
Helps #2106.
2025-12-16 19:35:49 +01:00
Petr Kovar 8dc10af3d1 v2.12.5 - Rancher Manager Release Maintenance
Helps #2107.
2025-12-16 19:22:53 +01:00
Petr Kovar 8a705b1d66 v2.13.1 - Rancher Manager Release Maintenance
Helps #2108.
2025-12-16 17:44:38 +01:00
Silvio Moioli 7aabf39e2c Merge branch 'main' into copilot/update-deprecation-policy-links 2025-12-16 08:57:52 +01:00
Jonathan Crowther 033a6ecb52 Make the projects workflow page reference the backingNamespace field (#2075)
* Make the projects workflow page reference the backingNamespace field

* Add suggestions

* Fix typo
2025-12-15 12:56:35 -08:00
copilot-swe-agent[bot]andmoio d5155ccdee Update deprecation policy links to SUSE Rancher Prime page
Co-authored-by: moio <250541+moio@users.noreply.github.com>
2025-12-12 09:29:25 +00:00
copilot-swe-agent[bot] 8e43347812 Initial plan 2025-12-12 09:25:21 +00:00
mschroeder-fzj d8c3493599 Merge branch 'rancher:main' into main 2025-12-09 08:14:00 +01:00
Billy Tat d69bad7fd4 Merge pull request #2114 from btat/self-ref-link
Remove self-referencing link
2025-12-03 09:09:46 -08:00
Billy Tat cb8c124163 Remove self-referencing link 2025-11-28 16:38:25 -08:00
mschroeder-fzj 3eb8905153 Added documentation for using the keywords option in Chart.yaml 2025-11-27 09:36:51 +01:00
mschroeder-fzj 66a6f2019d Fixed links to images 2025-11-27 09:36:16 +01:00
Jake Hyde abf80148ac Add docs for tls-additional (#1981)
* Add docs for tls-additional

* Address review comments

* Add tls-additional docs to previous versions
2025-11-26 15:15:30 -08:00
Meza 49fa9264c4 Fix broken indentation in api workflow docs (#2110)
Signed-off-by: Meza <meza-xyz@proton.me>
2025-11-26 11:32:19 -08:00
+4 24fc5a657c Merge release v2.13.0 to main (#2091)
* Sync main to v2.13.0 (#2065)

* It's bad form to ask users to pass something they just curled from the internet directly to sh

Updated the instructions for uninstalling the rancher-system-agent to use a temporary script file instead of piping directly to sh.

* doc(rancher-security): improve structure and content to latest, v2.13-preview and v2.12 (#2024)

- add Rancher Kubernetes Distributions (K3s/RKE2) Self-Assessment and Hardening Guide section
- add kubernetes cluster security best practices link to rancher-security section
- add k3s-selinux and update selinux-rpm details
- remove rhel/centos 7 support

Signed-off-by: Andy Pitcher <andy.pitcher@suse.com>

* Updating across supported versions and translations.

Signed-off-by: Sunil Singh <sunil.singh@suse.com>

---------

Signed-off-by: Andy Pitcher <andy.pitcher@suse.com>
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
Co-authored-by: Tejeev <tj@rancher.com>
Co-authored-by: Andy Pitcher <andy.pitcher@suse.com>
Co-authored-by: Sunil Singh <sunil.singh@suse.com>

* Update roletemplate aggregation doc and version information

* Add versioned docs

* Remove ext token and kubeconfig feature flag sections and document bearer Token

* Update corresponding v2.13 pages

* update doc for pni in gke

* Adding reverted session idle information from PR 1653

Signed-off-by: Sunil Singh <sunil.singh@suse.com>

* [2.13.0] Add versions table entry

* [2.13.0] Add webhook version

* [2.13.0] Add CSP Adapter version

* [2.13.0] Add deprecated feature table entry

* [2.13.0] Update CNI popularity stats

* Update GKE Cluster Configuration for Project Network Isolation instructions

* Fix link and port to 2.13

* [2.13.0] Add Swagger JSON

* [v2.13.0] Add info about Azure AD Roles claims (#2079)

* Add info about Azure AD roles claims compatibility

* Apply suggestions from code review

Co-authored-by: Sunil Singh <sunil.singh@suse.com>

* Add suggestions to v2.13

---------

Co-authored-by: Sunil Singh <sunil.singh@suse.com>

* [2.13.0] Remove preview designation

* user public api docs (#2069)

* user public api docs

* Apply suggestions from code review

Co-authored-by: Andreas Kupries <akupries@suse.com>

* Apply suggestions from code review

Co-authored-by: Peter Matseykanets <pmatseykanets@gmail.com>

* explain plaintext is never stored

* add users 2.13 versioned docs

* remove extra ```

* Apply suggestions from code review

Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>

* add space before code block

---------

Co-authored-by: Andreas Kupries <akupries@suse.com>
Co-authored-by: Peter Matseykanets <pmatseykanets@gmail.com>
Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>

* support IPv6 (#2041)

* [v2.13.0] Add Configure GitHub App page (#2081)

* Add Configure GitHub App page

* Apply suggestions from code review

Co-authored-by: Billy Tat <btat@suse.com>

* Fix header/GH URL & add suggestions to v2.13

* Apply suggestions from code review

Co-authored-by: Petr Kovar <pknbe@volny.cz>

* Apply suggestions from code review to v2.13

* Add note describing why to use Installation ID

* Apply suggestions from code review

Co-authored-by: Billy Tat <btat@suse.com>

---------

Co-authored-by: Billy Tat <btat@suse.com>
Co-authored-by: Petr Kovar <pknbe@volny.cz>

* [v2.13.0] Add info about Generic OIDC Custom Mapping (#2080)

* Add info about Generic OIDC Custom Mapping

* Apply suggestions from code review

Co-authored-by: Sunil Singh <sunil.singh@suse.com>
Co-authored-by: Billy Tat <btat@suse.com>

* Apply suggestions from code review

Co-authored-by: Sunil Singh <sunil.singh@suse.com>
Co-authored-by: Billy Tat <btat@suse.com>

* Add suggestions to v2.13

* Remove repetitive statement in intro

* Move Prereq intro/note to appropriate section

* Fix formatting, UI typo, add Custom Claims section under Configuration Reference section

* Add section about how a custom groups claim works / note about search limitations for groups in RBAC

---------

Co-authored-by: Sunil Singh <sunil.singh@suse.com>
Co-authored-by: Billy Tat <btat@suse.com>

* [v2.13.0] Add info about OIDC SLO support (#2086)

* Add shared file covering OIDC SLO support to OIDC auth pages

* Ad How to get the End Session Endpoint steps

* Add generic curl exampleto retrieve end_session_endpoint

* [2.13.0] Bump release date

---------

Signed-off-by: Andy Pitcher <andy.pitcher@suse.com>
Signed-off-by: Sunil Singh <sunil.singh@suse.com>
Co-authored-by: Lucas Saintarbor <lucas.saintarbor@suse.com>
Co-authored-by: Tejeev <tj@rancher.com>
Co-authored-by: Andy Pitcher <andy.pitcher@suse.com>
Co-authored-by: Sunil Singh <sunil.singh@suse.com>
Co-authored-by: Jonathan Crowther <jonathan.crowther@suse.com>
Co-authored-by: Peter Matseykanets <peter.matseykanets@suse.com>
Co-authored-by: Petr Kovar <petr.kovar@suse.com>
Co-authored-by: Krunal Hingu <krunal.hingu222@gmail.com>
Co-authored-by: Raul Cabello Martin <raul.cabello@suse.com>
Co-authored-by: Andreas Kupries <akupries@suse.com>
Co-authored-by: Peter Matseykanets <pmatseykanets@gmail.com>
Co-authored-by: Jack Luo <jiaqi.luo@suse.com>
Co-authored-by: Petr Kovar <pknbe@volny.cz>
2025-11-25 10:51:39 -08:00
2327 changed files with 106961 additions and 6883 deletions
-29
View File
@@ -1,29 +0,0 @@
name: Create issue to track porting between Community and Product docs
on:
pull_request_target:
types:
- closed
paths-ignore:
- '**/README.md'
permissions:
issues: write
pull-requests: read
jobs:
create_issue:
if: github.event.pull_request.merged == true && contains( github.event.pull_request.labels.*.name, 'port/community-product')
runs-on: ubuntu-latest
steps:
- name: Create issue
env:
GH_TOKEN: ${{ github.token }}
REPO_TYPE: ${{ contains( github.repository, 'product-docs') && 'Product' || 'Community' }}
PR_TITLE: ${{ github.event.pull_request.title }}
run: |
gh issue create \
--repo ${{ github.repository }} \
--title "Port $REPO_TYPE docs PR #${{ github.event.pull_request.number }}: $PR_TITLE" \
--body "Reference: https://github.com/${{ github.repository }}/pull/${{ github.event.pull_request.number }}" \
--label port/community-product
+1 -1
View File
@@ -25,7 +25,7 @@ jobs:
run: yarn install --frozen-lockfile run: yarn install --frozen-lockfile
- name: Build website - name: Build website
env: env:
NODE_OPTIONS: "--max_old_space_size=8192" NODE_OPTIONS: "--max_old_space_size=10240"
run: yarn build --no-minify run: yarn build --no-minify
- name: Upload Build Artifact - name: Upload Build Artifact
+1 -1
View File
@@ -27,5 +27,5 @@ jobs:
run: yarn run remark --quiet --use remark-lint-no-dead-urls ./docs run: yarn run remark --quiet --use remark-lint-no-dead-urls ./docs
- name: Test build website - name: Test build website
env: env:
NODE_OPTIONS: "--max_old_space_size=7168" NODE_OPTIONS: "--max_old_space_size=10240"
run: yarn build --no-minify run: yarn build --no-minify
+1 -1
View File
@@ -93,7 +93,7 @@ Subsequent executions will check for updated dependencies, if there are none, it
License License
======= =======
Copyright (c) 2014-2025 [SUSE, LLC.](https://www.suse.com/) Copyright (c) 2014-2026 [SUSE, LLC.](https://www.suse.com/)
Licensed under the Apache License, Version 2.0 (the "License"); Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License. you may not use this file except in compliance with the License.
@@ -6,10 +6,6 @@ title: Deprecated Features in Rancher
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/faq/deprecated-features"/> <link rel="canonical" href="https://ranchermanager.docs.rancher.com/faq/deprecated-features"/>
</head> </head>
## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features: Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features:
@@ -6,10 +6,6 @@ title: Deprecated Features in Rancher
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/faq/deprecated-features"/> <link rel="canonical" href="https://ranchermanager.docs.rancher.com/faq/deprecated-features"/>
</head> </head>
## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features: Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features:
@@ -37,8 +37,7 @@ apiVersion: management.cattle.io/v3
kind: Project kind: Project
metadata: metadata:
annotations: annotations:
field.cattle.io/creatorId: field.cattle.io/creatorId: user-id
user-id
generateName: p- generateName: p-
namespace: c-m-abcde namespace: c-m-abcde
spec: spec:
@@ -25,11 +25,15 @@ spec:
EOF EOF
``` ```
Use `metadata.generateName` to ensure a unique project ID, but note that `kubectl apply` does not work with `metadata.generateName`, so `kubectl create` must be used instead. When creating a new project, you have two primary options for setting the name:
- **Automatic Generation:** Use `metadata.generateName` to ensure a unique project ID. However, note that you must use `kubectl create` (instead of `kubectl apply`) with this option, as `kubectl apply` does not support it.
- **Manual Naming:** You can explicitly set the project ID using `metadata.name`. If a project with that exact name already exists, the name request is denied.
The display name seen in the UI is set by `spec.displayName`. If `spec.displayName` is not provided, the field `metadata.name` is used instead.
Set `metadata.namespace` and `spec.clusterName` to the ID for the cluster the project belongs to. Set `metadata.namespace` and `spec.clusterName` to the ID for the cluster the project belongs to.
If you create a project through a cluster member account, you must include the annotation, `field.cattle.io/creatorId`, and set it to the cluster member account's user ID. If you create a project through a cluster member account and want that account to be able to access the project, you must include the annotation `field.cattle.io/creatorId`, and set it to the cluster member account's user ID.
```bash ```bash
kubectl create -f - <<EOF kubectl create -f - <<EOF
@@ -37,8 +41,7 @@ apiVersion: management.cattle.io/v3
kind: Project kind: Project
metadata: metadata:
annotations: annotations:
field.cattle.io/creatorId: field.cattle.io/creatorId: user-id
user-id
generateName: p- generateName: p-
namespace: c-m-abcde namespace: c-m-abcde
spec: spec:
@@ -47,7 +50,11 @@ spec:
EOF EOF
``` ```
Setting the `field.cattle.io/creatorId` field allows the cluster member account to see project resources with the `get` command and view the project in the Rancher UI. Cluster owner and admin accounts don't need to set this annotation to perform these tasks. Setting the `field.cattle.io/creatorId` field creates a `ProjectRoleTemplateBinding` that grants the specified user the ability to see project resources with the `get` command and view the project in the Rancher UI. Cluster owner and admin accounts don't need to set this annotation to perform these tasks.
Setting the `field.cattle.io/creator-principal-name` annotation to the user's principal preserves it in a projectroletemplatebinding automatically created for the project owner.
If you don't want the creator to be added as the owner member (e.g. if the creator is a cluster administrator) to the project you may set the `field.cattle.io/no-creator-rbac` annotation to `true`, which will prevent the corresponding projectroletemplatebinding from being created.
### Creating a Project With a Resource Quota ### Creating a Project With a Resource Quota
@@ -94,9 +101,13 @@ spec:
EOF EOF
``` ```
### Backing Namespace
After creating the project, the field `status.backingNamespace` gets populated. This represents the namespace in the management cluster that is created to manage project related resources. Examples of resources stored in the backing namespace are [project scoped secrets](../../how-to-guides/new-user-guides/kubernetes-resources-setup/secrets.md#creating-secrets-in-projects) and [project role template bindings](../../how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/manage-role-based-access-control-rbac/cluster-and-project-roles.md#project-roles).
## Adding a Member to a Project ## Adding a Member to a Project
Look up the project ID to specify the `metadata.namespace` field and `projectName` field values. Look up the project's [backing namespace](#backing-namespace) to specify the `metadata.namespace` field value and look up the project's ID to specify the `projectName` field value.
```bash ```bash
kubectl --namespace c-m-abcde get projects kubectl --namespace c-m-abcde get projects
@@ -116,7 +127,7 @@ apiVersion: management.cattle.io/v3
kind: ProjectRoleTemplateBinding kind: ProjectRoleTemplateBinding
metadata: metadata:
generateName: prtb- generateName: prtb-
namespace: p-vwxyz namespace: c-m-abcde-p-vwxyz
projectName: c-m-abcde:p-vwxyz projectName: c-m-abcde:p-vwxyz
roleTemplateName: project-member roleTemplateName: project-member
userPrincipalName: keycloak_user://user userPrincipalName: keycloak_user://user
@@ -142,16 +153,16 @@ Create a projectroletemplatebinding for each role you want to assign to the proj
## Listing Project Members ## Listing Project Members
Look up the project ID: Look up the project backing namespace:
```bash ```bash
kubectl --namespace c-m-abcde get projects kubectl --namespace c-m-abcde get projects
``` ```
to list projectroletemplatebindings in the project's namespace: To list projectroletemplatebindings in the project's backing namespace:
```bash ```bash
kubectl --namespace p-vwxyz get projectroletemplatebindings kubectl --namespace c-m-abcde-p-vwxyz get projectroletemplatebindings
``` ```
## Deleting a Member From a Project ## Deleting a Member From a Project
@@ -161,14 +172,14 @@ Lookup the projectroletemplatebinding IDs containing the member in the project's
Delete the projectroletemplatebinding from the project's namespace: Delete the projectroletemplatebinding from the project's namespace:
```bash ```bash
kubectl --namespace p-vwxyz delete projectroletemplatebindings prtb-qx874 prtb-7zw7s kubectl --namespace c-m-abcde-p-vwxyz delete projectroletemplatebindings prtb-qx874 prtb-7zw7s
``` ```
## Creating a Namespace in a Project ## Creating a Namespace in a Project
The Project resource resides in the management cluster, even if the Project is for a managed cluster. The namespaces under the project reside in the managed cluster. The Project resource resides in the management cluster, even if the Project is for a managed cluster. The namespaces under the project reside in the managed cluster.
On the management cluster, look up the project ID for the cluster you are administrating since it generated using `metadata.generateName`: On the management cluster, look up the project ID for the cluster you are administrating if generated using `metadata.generateName`:
```bash ```bash
kubectl --namespace c-m-abcde get projects kubectl --namespace c-m-abcde get projects
@@ -204,3 +215,5 @@ kubectl --namespace c-m-abcde delete project p-vwxyz
``` ```
Note that this command doesn't delete the namespaces and resources that formerly belonged to the project. Note that this command doesn't delete the namespaces and resources that formerly belonged to the project.
It does delete all project role template bindings for the projects, so recreating the project will not restore members added to the project, and you have to add users as members again.
@@ -65,7 +65,7 @@ Kubernetes workers should open UDP port `8472` (VXLAN) and TCP port `9099` (heal
![](/img/canal-diagram.png) ![](/img/canal-diagram.png)
For more information, see the [Canal GitHub Page.](https://github.com/projectcalico/canal) For more information, refer to the [Rancher maintained Canal source](https://github.com/rancher/rke2-charts/tree/main-source/packages/rke2-canal) and the [Canal GitHub Page](https://github.com/projectcalico/canal).
#### Flannel #### Flannel
@@ -6,10 +6,6 @@ title: Deprecated Features in Rancher
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/faq/deprecated-features"/> <link rel="canonical" href="https://ranchermanager.docs.rancher.com/faq/deprecated-features"/>
</head> </head>
## What is Rancher's deprecation policy?
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms).
## Where can I find out which features have been deprecated in Rancher? ## Where can I find out which features have been deprecated in Rancher?
Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features: Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features:
@@ -42,8 +42,24 @@ kubectl -n cattle-system create secret generic tls-ca \
The configured `tls-ca` secret is retrieved when Rancher starts. On a running Rancher installation the updated CA will take effect after new Rancher pods are started. The configured `tls-ca` secret is retrieved when Rancher starts. On a running Rancher installation the updated CA will take effect after new Rancher pods are started.
The certificate chain must be properly formatted, or components may fail to download resources from the Rancher server.
::: :::
## Adding Additional CA Certificates
If you are using a node driver that makes API requests with a different CA than the one configured for Rancher, you can add additional root certificates and certificate chains.
Create a unique file ending in `.pem` for each certificate that is required, and use kubectl to create the
`tls-additional` secret in the `cattle-system` namespace.
```console
kubectl -n cattle-system create secret generic tls-additional \
--from-file=cacerts1.pem=cacerts1.pem --from-file=cacerts2.pem=cacerts2.pem
```
Rancher mounts these CA root certificates and certificate chains into the node driver pod during provisioning.
## Updating a Private CA Certificate ## Updating a Private CA Certificate
Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate. Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate.
@@ -96,7 +96,8 @@ To enable draining each node during a cluster upgrade,
:::note :::note
There is a [known issue](https://github.com/rancher/rancher/issues/25478) in which the Rancher UI doesn't show the state of etcd and controlplane as drained, even though they are being drained. - There is a [known issue](https://github.com/rancher/rancher/issues/25478) in which the Rancher UI doesn't show the state of etcd and controlplane as drained, even though they are being drained.
- During an upgrade, nodes may be drained even when no user-visible YAML changes are present. This can occur if non-dynamic configuration files are updated or if a new `system-agent-installer` image is introduced. In such cases, Rancher generates a new upgrade plan, resulting in a new plan hash. When `Upgrade Strategy` is set to `Drain nodes`, this plan change can trigger node draining.
::: :::
@@ -16,11 +16,15 @@ For configuration details, refer to the [official Kubernetes documentation](http
<Tabs groupId="k8s-distro"> <Tabs groupId="k8s-distro">
<TabItem value="RKE2" default> <TabItem value="RKE2" default>
### Method 1 (Recommended): Set `audit-policy-file` in `machineGlobalConfig` ### Method 1 (Recommended): Set `audit-policy-file` in `machineGlobalConfig` or `machineSelectorConfig`
You can set `audit-policy-file` in the configuration file. Rancher delivers the file to the path `/var/lib/rancher/rke2/etc/config-files/audit-policy-file` in control plane nodes, and sets the proper options in the RKE2 server. You can set `audit-policy-file` in the configuration file using either `machineGlobalConfig` or `machineSelectorConfig`.
Example: When using `machineGlobalConfig`, Rancher delivers the file to the path `/var/lib/rancher/rke2/etc/config-files/audit-policy-file` on **all nodes** (both control plane and worker nodes), and sets the proper options in the RKE2 server. This may cause unwanted worker node reconciliation when the audit policy is modified.
To avoid worker node reconciliation, use `machineSelectorConfig` with a label selector to target only control plane nodes. This ensures that the audit policy file is only delivered to control plane nodes.
Example using `machineGlobalConfig`:
```yaml ```yaml
apiVersion: provisioning.cattle.io/v1 apiVersion: provisioning.cattle.io/v1
kind: Cluster kind: Cluster
@@ -38,6 +42,28 @@ spec:
- pods - pods
``` ```
Example using `machineSelectorConfig` (recommended to avoid worker node reconciliation):
```yaml
apiVersion: provisioning.cattle.io/v1
kind: Cluster
spec:
rkeConfig:
machineSelectorConfig:
- config:
audit-policy-file: |
apiVersion: audit.k8s.io/v1
kind: Policy
rules:
- level: RequestResponse
resources:
- group: ""
resources:
- pods
machineLabelSelector:
matchLabels:
rke.cattle.io/control-plane-role: 'true'
```
### Method 2: Use the Directives, `machineSelectorFiles` and `machineGlobalConfig` ### Method 2: Use the Directives, `machineSelectorFiles` and `machineGlobalConfig`
:::note :::note
@@ -103,12 +129,6 @@ spec:
rke.cattle.io/control-plane-role: 'true' rke.cattle.io/control-plane-role: 'true'
``` ```
:::tip
You can also use the directive `machineSelectorConfig` with proper machineLabelSelectors to achieve the same effect.
:::
For more information about cluster configuration, refer to the [RKE2 cluster configuration reference](../../reference-guides/cluster-configuration/rancher-server-configuration/rke2-cluster-configuration.md) pages. For more information about cluster configuration, refer to the [RKE2 cluster configuration reference](../../reference-guides/cluster-configuration/rancher-server-configuration/rke2-cluster-configuration.md) pages.
</TabItem> </TabItem>
@@ -178,12 +198,6 @@ spec:
rke.cattle.io/control-plane-role: 'true' rke.cattle.io/control-plane-role: 'true'
``` ```
:::tip
You can also use the directive `machineSelectorConfig` with proper machineLabelSelectors to achieve the same effect.
:::
For more information about cluster configuration, refer to the [K3s cluster configuration reference](../../reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration.md) pages. For more information about cluster configuration, refer to the [K3s cluster configuration reference](../../reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration.md) pages.
</TabItem> </TabItem>

Some files were not shown because too many files have changed in this diff Show More