* Add draft of Guide to Ingress NGINX Retirement
* Revise Guide to Ingress NGINX Retirement page for community
* Add note about version availability for Dual Mode migration option
Co-authored-by: Billy Tat <btat@suse.com>
* Update note on Rancher version availability
* Remove note in Downstream RKE2 clusters (provisioned by Rancher) section
---------
Co-authored-by: Billy Tat <btat@suse.com>
* Update the deprecated features table
* Update the CSP adapter compatibility matrix
* Update the Rancher:webhook version mapping table
* Update the versions table
* Update Resource Quota Type Reference page for support of all upstream Kubernetes ResourceQuota types
* Apply changes to v2.14 / zh files
* Apply suggestions from code review
Co-authored-by: Billy Tat <btat@suse.com>
* Apply feedback to other versions/zh, reword/reorder intro
* Add back zh content
---------
Co-authored-by: Billy Tat <btat@suse.com>
* Add v3 API token deprecation warning shared file / Add warning to applicable pages
* Update Deprecation of v3 API tokens warning
* Update shared-files/_v3-api-tokens-deprecation-warning.md
Co-authored-by: Billy Tat <btat@suse.com>
* Update src/theme/MDXComponents.js
Co-authored-by: Billy Tat <btat@suse.com>
* Fix/update typo in shared file name (v3APITokensDeprecationWarning)
* Fix wording in Deprecation of v3 API tokens warning
---------
Co-authored-by: Billy Tat <btat@suse.com>
* Add shared fle for OIDC Support for PKCE Extension
* Update OIDC pages
* Update shared-files/_oidc-pkce-support.md
Co-authored-by: Billy Tat <btat@suse.com>
* Reword OIDC PKCE support text
---------
Co-authored-by: Billy Tat <btat@suse.com>
- Updates `troubleshooting-etcd-nodes.md` to replace Docker-based commands with `crictl` and `etcdctl` for RKE2 and K3s.
- Replaces `curl` connectivity checks with `openssl s_client` to support etcd 3.5+ gRPC requirements and isolate transport layer testing.
- Adds prerequisites section with necessary environment exports.
- Updates all `etcdctl` commands to use explicit inline certificate paths for RKE2 and K3s.
- Replaces shell-dependent container commands with host-side processing to support distroless images.
- Updates log level configuration instructions for RKE2/K3s config files.
* Update the deprecated features table
* Update the CSP adapter compatibility matrix
* Update the Rancher:webhook version mapping table
* Update the versions table
* Update the CNI popularity table
* Update the deprecated features table
* Update the CSP adapter compatibility matrix
* Update the Rancher:webhook version mapping table
* Update the versions table
* Update the deprecated features table
* Update the CSP adapter compatibility matrix
* Update the Rancher:webhook version mapping table
* Update the versions table
* Update the deprecated features table
* Update the CSP adapter compatibility matrix
* Update the Rancher:webhook version mapping table
* Update the versions table
* Update src/pages/versions.md
Co-authored-by: Billy Tat <btat@suse.com>
---------
Co-authored-by: Billy Tat <btat@suse.com>
* Add Notification Banner page
* Remove notifications banner page
* Rename Notificaitons Center page to Notifications / Update Notifications page
* Undo change to canonical link
* Undo change to canonical link
* Update docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/notification-center.md
Co-authored-by: Billy Tat <btat@suse.com>
* Fix typo on v2.13/v2.14 page
---------
Co-authored-by: Billy Tat <btat@suse.com>
* tweak: paragraph describing how to go beyond the fixed builtin resources
* chore: formatting fixes (alignments)
tweak: added ref and explanations for `extended`
* fix: namespace limit of a namespace is nonsense. switched to cpu limits.
* tweak: added editing of extended via `edit yaml`
* add unit ref for memory/storage
* address comments
* updated to match the dashboard's new `custom` resource type.
* Update docs/how-to-guides/advanced-user-guides/manage-projects/manage-project-resource-quotas/manage-project-resource-quotas.md
Co-authored-by: Jonathan Crowther <jonathan.crowther@suse.com>
* Apply to v2.14 folder: 'Document the extended project resource quotas'
---------
Co-authored-by: Jonathan Crowther <jonathan.crowther@suse.com>
Co-authored-by: Billy Tat <btat@suse.com>
* Add SamlOpenLDAPGroupPermissions shared file
* Add SamlOpenLDAPGroupPermissions shared file to Configure Keycloak (SAML) page
* Add SamlOpenLDAPGroupPermissions shared file to Configure Okta (SAML) page
* Add SamlOpenLDAPGroupPermissions shared file to Configure PingIdentity (SAML) page
* Add SamlOpenLDAPGroupPermissions shared file to Configuring Rancher for Microsoft AD FS page
* Add SamlOpenLDAPGroupPermissions shared file to Group Permissions with Shibboleth and OpenLDAP page
* Add SamlOpenLDAPGroupPermissions shared file to other versions of Configure Keycloak (SAML) page
* Add SamlOpenLDAPGroupPermissions shared file to other versions of Configure Okta (SAML) page
* Add SamlOpenLDAPGroupPermissions shared file to other versions Configure PingIdentity (SAML) page
* Add SamlOpenLDAPGroupPermissions shared file to other versions of Configuring Rancher for Microsoft AD FS page
* Add SamlOpenLDAPGroupPermissions shared file to other versions of Group Permissions with Shibboleth and OpenLDAP page
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms).
## Where can I find out which features have been deprecated in Rancher?
Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features:
We have published our official deprecation policy in the support [terms of service](https://rancher.com/support-maintenance-terms).
## Where can I find out which features have been deprecated in Rancher?
Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features:
@@ -65,7 +65,7 @@ Kubernetes workers should open UDP port `8472` (VXLAN) and TCP port `9099` (heal

For more information, see the [Canal GitHub Page.](https://github.com/projectcalico/canal)
For more information, refer to the [Rancher maintained Canal source](https://github.com/rancher/rke2-charts/tree/main-source/packages/rke2-canal) and the [Canal GitHub Page](https://github.com/projectcalico/canal).
The community version of Rancher follows the same deprecation policy as Rancher Prime. The official deprecation policy is documented in the [Rancher Prime Deprecation Policy](https://www.suse.com/support/rancher-prime/#Rancher-Prime-Deprecation-Policy).
## Where can I find out which features have been deprecated in Rancher?
Rancher will publish deprecated features as part of the [release notes](https://github.com/rancher/rancher/releases) for Rancher found on GitHub. Please consult the following patch releases for deprecated features:
@@ -96,7 +96,8 @@ To enable draining each node during a cluster upgrade,
:::note
There is a [known issue](https://github.com/rancher/rancher/issues/25478) in which the Rancher UI doesn't show the state of etcd and controlplane as drained, even though they are being drained.
- There is a [known issue](https://github.com/rancher/rancher/issues/25478) in which the Rancher UI doesn't show the state of etcd and controlplane as drained, even though they are being drained.
- During an upgrade, nodes may be drained even when no user-visible YAML changes are present. This can occur if non-dynamic configuration files are updated or if a new `system-agent-installer` image is introduced. In such cases, Rancher generates a new upgrade plan, resulting in a new plan hash. When `Upgrade Strategy` is set to `Drain nodes`, this plan change can trigger node draining.
@@ -16,11 +16,15 @@ For configuration details, refer to the [official Kubernetes documentation](http
<Tabs groupId="k8s-distro">
<TabItem value="RKE2" default>
### Method 1 (Recommended): Set `audit-policy-file` in `machineGlobalConfig`
### Method 1 (Recommended): Set `audit-policy-file` in `machineGlobalConfig` or `machineSelectorConfig`
You can set `audit-policy-file` in the configuration file. Rancher delivers the file to the path `/var/lib/rancher/rke2/etc/config-files/audit-policy-file` in control plane nodes, and sets the proper options in the RKE2 server.
You can set `audit-policy-file` in the configuration file using either `machineGlobalConfig` or `machineSelectorConfig`.
Example:
When using `machineGlobalConfig`, Rancher delivers the file to the path `/var/lib/rancher/rke2/etc/config-files/audit-policy-file` on **all nodes** (both control plane and worker nodes), and sets the proper options in the RKE2 server. This may cause unwanted worker node reconciliation when the audit policy is modified.
To avoid worker node reconciliation, use `machineSelectorConfig` with a label selector to target only control plane nodes. This ensures that the audit policy file is only delivered to control plane nodes.
Example using `machineGlobalConfig`:
```yaml
apiVersion: provisioning.cattle.io/v1
kind: Cluster
@@ -38,6 +42,28 @@ spec:
- pods
```
Example using `machineSelectorConfig` (recommended to avoid worker node reconciliation):
```yaml
apiVersion: provisioning.cattle.io/v1
kind: Cluster
spec:
rkeConfig:
machineSelectorConfig:
- config:
audit-policy-file: |
apiVersion: audit.k8s.io/v1
kind: Policy
rules:
- level: RequestResponse
resources:
- group: ""
resources:
- pods
machineLabelSelector:
matchLabels:
rke.cattle.io/control-plane-role: 'true'
```
### Method 2: Use the Directives, `machineSelectorFiles` and `machineGlobalConfig`
:::note
@@ -103,12 +129,6 @@ spec:
rke.cattle.io/control-plane-role: 'true'
```
:::tip
You can also use the directive `machineSelectorConfig` with proper machineLabelSelectors to achieve the same effect.
:::
For more information about cluster configuration, refer to the [RKE2 cluster configuration reference](../../reference-guides/cluster-configuration/rancher-server-configuration/rke2-cluster-configuration.md) pages.
</TabItem>
@@ -178,12 +198,6 @@ spec:
rke.cattle.io/control-plane-role: 'true'
```
:::tip
You can also use the directive `machineSelectorConfig` with proper machineLabelSelectors to achieve the same effect.
:::
For more information about cluster configuration, refer to the [K3s cluster configuration reference](../../reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration.md) pages.
Some files were not shown because too many files have changed in this diff
Show More
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.