Files
rancher-docs/faq/technical-items.html
T

17 lines
42 KiB
HTML
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!doctype html>
<html lang="en" dir="ltr" class="docs-wrapper docs-doc-page docs-version-current plugin-docs plugin-id-default docs-doc-id-faq/technical-items">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<meta name="generator" content="Docusaurus v2.0.0-beta.21">
<link rel="search" type="application/opensearchdescription+xml" title="Rancher Manager" href="/opensearch.xml"><title data-rh="true">Technical | Rancher Manager</title><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="http://docs.ranchermanager.rancher.io//faq/technical-items"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="Technical | Rancher Manager"><meta data-rh="true" name="description" content="How can I reset the administrator password?"><meta data-rh="true" property="og:description" content="How can I reset the administrator password?"><link data-rh="true" rel="icon" href="/img/favicon.png"><link data-rh="true" rel="canonical" href="http://docs.ranchermanager.rancher.io//faq/technical-items"><link data-rh="true" rel="alternate" href="http://docs.ranchermanager.rancher.io//faq/technical-items" hreflang="en"><link data-rh="true" rel="alternate" href="http://docs.ranchermanager.rancher.io//faq/technical-items" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link rel="stylesheet" href="/assets/css/styles.31d3122a.css">
<link rel="preload" href="/assets/js/runtime~main.d2604d48.js" as="script">
<link rel="preload" href="/assets/js/main.aa78001f.js" as="script">
</head>
<body class="navigation-with-keyboard">
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
<div role="region"><a href="#" class="skipToContent_fXgn">Skip to main content</a></div><nav class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Navigation bar toggle" class="navbar__toggle clean-btn" type="button" tabindex="0"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/">v2.6</a><ul class="dropdown__menu"><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/faq/technical-items">v2.6</a></li><li><a class="dropdown__link" href="/v2.5/faq/technical-items">v2.5</a></li><li><a class="dropdown__link" href="/v2.0-v2.4/faq/technical-items">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/versions">All versions</a></li></ul></div></div><div class="navbar__items navbar__items--right"><a aria-current="page" class="navbar__item navbar__link navbar__docs navbar__link--active" href="/">Docs</a><a href="https://github.com/rancher/" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link navbar__github btn btn-secondary icon-github">GitHub<svg width="13.5" height="13.5" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_lCJq"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div class="main-wrapper docsWrapper_BCFX"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebar_njMd"><nav class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/">Rancher 2.6</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" href="/getting-started">Getting Started</a><button aria-label="Toggle the collapsible sidebar category &#x27;Getting Started&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" href="/how-to-guides">How-to Guides</a><button aria-label="Toggle the collapsible sidebar category &#x27;How-to Guides&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" href="/reference-guides">Reference Guides</a><button aria-label="Toggle the collapsible sidebar category &#x27;Reference Guides&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" href="/explanations">Explanations</a><button aria-label="Toggle the collapsible sidebar category &#x27;Explanations&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--active" aria-expanded="true" href="/faq">FAQ</a><button aria-label="Toggle the collapsible sidebar category &#x27;FAQ&#x27;" type="button" class="clean-btn menu__caret"></button></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/deprecated-features-in-v2.5">Deprecated Features in Rancher</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/install-and-configure-kubectl">Installing and Configuring kubectl</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/dockershim">Dockershim</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/faq/technical-items">Technical</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/security">Security</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/telemetry">Telemetry</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/container-network-interface-providers">Container Network Interface (CNI) Providers</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/rancher-is-no-longer-needed">Rancher is No Longer Needed</a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" href="/troubleshooting">Troubleshooting</a><button aria-label="Toggle the collapsible sidebar category &#x27;Troubleshooting&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/contribute-to-rancher">Contributing to Rancher</a></li></ul></nav></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_GujU"><div class="docItemContainer_Adtb"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_OVgt"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item"><a class="breadcrumbs__link" itemprop="item" href="/faq"><span itemprop="name">FAQ</span></a><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">Technical</span><meta itemprop="position" content="2"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">Version: v2.6</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_aoJ5"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>Technical</h1></header><h3 class="anchor anchorWithStickyNavbar_LWe7" id="how-can-i-reset-the-administrator-password">How can I reset the administrator password?<a class="hash-link" href="#how-can-i-reset-the-administrator-password" title="Direct link to heading">​</a></h3><p>Docker Install:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">$ docker exec -ti &lt;container_id&gt; reset-password</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">New password for default administrator (user-xxxxx):</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">&lt;new_password&gt;</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p>Kubernetes install (Helm):</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">$ KUBECONFIG=./kube_config_cluster.yml</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">$ kubectl --kubeconfig $KUBECONFIG -n cattle-system exec $(kubectl --kubeconfig $KUBECONFIG -n cattle-system get pods -l app=rancher --no-headers | head -1 | awk &#x27;{ print $1 }&#x27;) -c rancher -- reset-password</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">New password for default administrator (user-xxxxx):</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">&lt;new_password&gt;</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><h3 class="anchor anchorWithStickyNavbar_LWe7" id="i-deleteddeactivated-the-last-admin-how-can-i-fix-it">I deleted/deactivated the last admin, how can I fix it?<a class="hash-link" href="#i-deleteddeactivated-the-last-admin-how-can-i-fix-it" title="Direct link to heading">​</a></h3><p>Docker Install:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">$ docker exec -ti &lt;container_id&gt; ensure-default-admin</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">New default administrator (user-xxxxx)</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">New password for default administrator (user-xxxxx):</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">&lt;new_password&gt;</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p>Kubernetes install (Helm):</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">$ KUBECONFIG=./kube_config_cluster.yml</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">$ kubectl --kubeconfig $KUBECONFIG -n cattle-system exec $(kubectl --kubeconfig $KUBECONFIG -n cattle-system get pods -l app=rancher | grep &#x27;1/1&#x27; | head -1 | awk &#x27;{ print $1 }&#x27;) -- ensure-default-admin</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">New password for default administrator (user-xxxxx):</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">&lt;new_password&gt;</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><h3 class="anchor anchorWithStickyNavbar_LWe7" id="how-can-i-enable-debug-logging">How can I enable debug logging?<a class="hash-link" href="#how-can-i-enable-debug-logging" title="Direct link to heading">​</a></h3><p>See <a href="/troubleshooting/other-troubleshooting-tips/logging">Troubleshooting: Logging</a></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="my-clusterip-does-not-respond-to-ping">My ClusterIP does not respond to ping<a class="hash-link" href="#my-clusterip-does-not-respond-to-ping" title="Direct link to heading">​</a></h3><p>ClusterIP is a virtual IP, which will not respond to ping. Best way to test if the ClusterIP is configured correctly, is by using <code>curl</code> to access the IP and port to see if it responds.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="where-can-i-manage-node-templates">Where can I manage Node Templates?<a class="hash-link" href="#where-can-i-manage-node-templates" title="Direct link to heading">​</a></h3><p>Node Templates can be accessed by opening your account menu (top right) and selecting <code>Node Templates</code>.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="why-is-my-layer-4-load-balancer-in-pending-state">Why is my Layer-4 Load Balancer in <code>Pending</code> state?<a class="hash-link" href="#why-is-my-layer-4-load-balancer-in-pending-state" title="Direct link to heading">​</a></h3><p>The Layer-4 Load Balancer is created as <code>type: LoadBalancer</code>. In Kubernetes, this needs a cloud provider or controller that can satisfy these requests, otherwise these will be in <code>Pending</code> state forever. More information can be found on <a href="/pages-for-subheaders/set-up-cloud-providers">Cloud Providers</a> or <a href="https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/" target="_blank" rel="noopener noreferrer">Create External Load Balancer</a></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="where-is-the-state-of-rancher-stored">Where is the state of Rancher stored?<a class="hash-link" href="#where-is-the-state-of-rancher-stored" title="Direct link to heading">​</a></h3><ul><li>Docker Install: in the embedded etcd of the <code>rancher/rancher</code> container, located at <code>/var/lib/rancher</code>.</li><li>Kubernetes install: in the etcd of the RKE cluster created to run Rancher.</li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="how-are-the-supported-docker-versions-determined">How are the supported Docker versions determined?<a class="hash-link" href="#how-are-the-supported-docker-versions-determined" title="Direct link to heading">​</a></h3><p>We follow the validated Docker versions for upstream Kubernetes releases. The validated versions can be found under <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG-1.10.md#external-dependencies" target="_blank" rel="noopener noreferrer">External Dependencies</a> in the Kubernetes release CHANGELOG.md.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="how-can-i-access-nodes-created-by-rancher">How can I access nodes created by Rancher?<a class="hash-link" href="#how-can-i-access-nodes-created-by-rancher" title="Direct link to heading">​</a></h3><p>SSH keys to access the nodes created by Rancher can be downloaded via the <strong>Nodes</strong> view. Choose the node which you want to access and click on the vertical ⋮ button at the end of the row, and choose <strong>Download Keys</strong> as shown in the picture below.</p><p><img loading="lazy" alt="Download Keys" src="/assets/images/downloadsshkeys-617979ebc3df306cf60b60325923b283.png" width="442" height="426" class="img_ev3q"></p><p>Unzip the downloaded zip file, and use the file <code>id_rsa</code> to connect to you host. Be sure to use the correct username (<code>rancher</code> or <code>docker</code> for RancherOS, <code>ubuntu</code> for Ubuntu, <code>ec2-user</code> for Amazon Linux)</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">$ ssh -i id_rsa user@ip_of_node</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><h3 class="anchor anchorWithStickyNavbar_LWe7" id="how-can-i-automate-task-x-in-rancher">How can I automate task X in Rancher?<a class="hash-link" href="#how-can-i-automate-task-x-in-rancher" title="Direct link to heading">​</a></h3><p>The UI consists of static files, and works based on responses of the API. That means every action/task that you can execute in the UI, can be automated via the API. There are 2 ways to do this:</p><ul><li>Visit <code>https://your_rancher_ip/v3</code> and browse the API options.</li><li>Capture the API calls when using the UI (Most commonly used for this is <a href="https://developers.google.com/web/tools/chrome-devtools/#network" target="_blank" rel="noopener noreferrer">Chrome Developer Tools</a> but you can use anything you like)</li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="the-ip-address-of-a-node-changed-how-can-i-recover">The IP address of a node changed, how can I recover?<a class="hash-link" href="#the-ip-address-of-a-node-changed-how-can-i-recover" title="Direct link to heading">​</a></h3><p>A node is required to have a static IP configured (or a reserved IP via DHCP). If the IP of a node has changed, you will have to remove it from the cluster and readd it. After it is removed, Rancher will update the cluster to the correct state. If the cluster is no longer in <code>Provisioning</code> state, the node is removed from the cluster.</p><p>When the IP address of the node changed, Rancher lost connection to the node, so it will be unable to clean the node properly. See <a href="/how-to-guides/advanced-user-guides/manage-clusters/clean-cluster-nodes">Cleaning cluster nodes</a> to clean the node.</p><p>When the node is removed from the cluster, and the node is cleaned, you can readd the node to the cluster.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="how-can-i-add-additional-argumentsbindsenvironment-variables-to-kubernetes-components-in-a-rancher-launched-kubernetes-cluster">How can I add additional arguments/binds/environment variables to Kubernetes components in a Rancher Launched Kubernetes cluster?<a class="hash-link" href="#how-can-i-add-additional-argumentsbindsenvironment-variables-to-kubernetes-components-in-a-rancher-launched-kubernetes-cluster" title="Direct link to heading">​</a></h3><p>You can add additional arguments/binds/environment variables via the <a href="/reference-guides/cluster-configuration/rancher-server-configuration/rke1-cluster-configuration#cluster-config-file">Config File</a> option in Cluster Options. For more information, see the <a href="https://rancher.com/docs/rke/latest/en/config-options/services/services-extras/" target="_blank" rel="noopener noreferrer">Extra Args, Extra Binds, and Extra Environment Variables</a> in the RKE documentation or browse the <a href="https://rancher.com/docs/rke/latest/en/example-yamls/" target="_blank" rel="noopener noreferrer">Example Cluster.ymls</a>.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="how-do-i-check-if-my-certificate-chain-is-valid">How do I check if my certificate chain is valid?<a class="hash-link" href="#how-do-i-check-if-my-certificate-chain-is-valid" title="Direct link to heading">​</a></h3><p>Use the <code>openssl verify</code> command to validate your certificate chain:</p><div class="admonition admonition-tip alert alert--success"><div class="admonition-heading"><h5><span class="admonition-icon"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="16" viewBox="0 0 12 16"><path fill-rule="evenodd" d="M6.5 0C3.48 0 1 2.19 1 5c0 .92.55 2.25 1 3 1.34 2.25 1.78 2.78 2 4v1h5v-1c.22-1.22.66-1.75 2-4 .45-.75 1-2.08 1-3 0-2.81-2.48-5-5.5-5zm3.64 7.48c-.25.44-.47.8-.67 1.11-.86 1.41-1.25 2.06-1.45 3.23-.02.05-.02.11-.02.17H5c0-.06 0-.13-.02-.17-.2-1.17-.59-1.83-1.45-3.23-.2-.31-.42-.67-.67-1.11C2.44 6.78 2 5.65 2 5c0-2.2 2.02-4 4.5-4 1.22 0 2.36.42 3.22 1.19C10.55 2.94 11 3.94 11 5c0 .66-.44 1.78-.86 2.48zM4 14h5c-.23 1.14-1.3 2-2.5 2s-2.27-.86-2.5-2z"></path></svg></span>tip</h5></div><div class="admonition-content"><p>Configure <code>SSL_CERT_DIR</code> and <code>SSL_CERT_FILE</code> to a dummy location to make sure the OS-installed certificates are not used when verifying manually.</p></div></div><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">SSL_CERT_DIR=/dummy SSL_CERT_FILE=/dummy openssl verify -CAfile ca.pem rancher.yourdomain.com.pem</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">rancher.yourdomain.com.pem: OK</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p>If you receive the error <code>unable to get local issuer certificate</code>, the chain is incomplete. This usually means that there is an intermediate CA certificate that issued your server certificate. If you already have this certificate, you can use it in the verification of the certificate like shown below:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">SSL_CERT_DIR=/dummy SSL_CERT_FILE=/dummy openssl verify -CAfile ca.pem -untrusted intermediate.pem rancher.yourdomain.com.pem</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">rancher.yourdomain.com.pem: OK</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p>If you have successfully verified your certificate chain, you should include needed intermediate CA certificates in the server certificate to complete the certificate chain for any connection made to Rancher (for example, by the Rancher agent). The order of the certificates in the server certificate file should be first the server certificate itself (contents of <code>rancher.yourdomain.com.pem</code>), followed by intermediate CA certificate(s) (contents of <code>intermediate.pem</code>).</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">-----BEGIN CERTIFICATE-----</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">%YOUR_CERTIFICATE%</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">-----END CERTIFICATE-----</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">-----BEGIN CERTIFICATE-----</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">%YOUR_INTERMEDIATE_CERTIFICATE%</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">-----END CERTIFICATE-----</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p>If you still get errors during verification, you can retrieve the subject and the issuer of the server certificate using the following command:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">openssl x509 -noout -subject -issuer -in rancher.yourdomain.com.pem</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">subject= /C=GB/ST=England/O=Alice Ltd/CN=rancher.yourdomain.com</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">issuer= /C=GB/ST=England/O=Alice Ltd/CN=Alice Intermediate CA</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><h3 class="anchor anchorWithStickyNavbar_LWe7" id="how-do-i-check-common-name-and-subject-alternative-names-in-my-server-certificate">How do I check <code>Common Name</code> and <code>Subject Alternative Names</code> in my server certificate?<a class="hash-link" href="#how-do-i-check-common-name-and-subject-alternative-names-in-my-server-certificate" title="Direct link to heading">​</a></h3><p>Although technically an entry in <code>Subject Alternative Names</code> is required, having the hostname in both <code>Common Name</code> and as entry in <code>Subject Alternative Names</code> gives you maximum compatibility with older browser/applications.</p><p>Check <code>Common Name</code>:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">openssl x509 -noout -subject -in cert.pem</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">subject= /CN=rancher.my.org</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p>Check <code>Subject Alternative Names</code>:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">openssl x509 -noout -in cert.pem -text | grep DNS</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> DNS:rancher.my.org</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><h3 class="anchor anchorWithStickyNavbar_LWe7" id="why-does-it-take-5-minutes-for-a-pod-to-be-rescheduled-when-a-node-has-failed">Why does it take 5+ minutes for a pod to be rescheduled when a node has failed?<a class="hash-link" href="#why-does-it-take-5-minutes-for-a-pod-to-be-rescheduled-when-a-node-has-failed" title="Direct link to heading">​</a></h3><p>This is due to a combination of the following default Kubernetes settings:</p><ul><li>kubelet<ul><li><code>node-status-update-frequency</code>: Specifies how often kubelet posts node status to master (default 10s)</li></ul></li><li>kube-controller-manager<ul><li><code>node-monitor-period</code>: The period for syncing NodeStatus in NodeController (default 5s)</li><li><code>node-monitor-grace-period</code>: Amount of time which we allow running Node to be unresponsive before marking it unhealthy (default 40s)</li><li><code>pod-eviction-timeout</code>: The grace period for deleting pods on failed nodes (default 5m0s)</li></ul></li></ul><p>See <a href="https://kubernetes.io/docs/reference/command-line-tools-reference/kubelet/" target="_blank" rel="noopener noreferrer">Kubernetes: kubelet</a> and <a href="https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/" target="_blank" rel="noopener noreferrer">Kubernetes: kube-controller-manager</a> for more information on these settings.</p><p>In Kubernetes v1.13, the <code>TaintBasedEvictions</code> feature is enabled by default. See <a href="https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/#taint-based-evictions" target="_blank" rel="noopener noreferrer">Kubernetes: Taint based Evictions</a> for more information.</p><ul><li>kube-apiserver (Kubernetes v1.13 and up)<ul><li><code>default-not-ready-toleration-seconds</code>: Indicates the tolerationSeconds of the toleration for notReady:NoExecute that is added by default to every pod that does not already have such a toleration.</li><li><code>default-unreachable-toleration-seconds</code>: Indicates the tolerationSeconds of the toleration for unreachable:NoExecute that is added by default to every pod that does not already have such a toleration.</li></ul></li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="can-i-use-keyboard-shortcuts-in-the-ui">Can I use keyboard shortcuts in the UI?<a class="hash-link" href="#can-i-use-keyboard-shortcuts-in-the-ui" title="Direct link to heading">​</a></h3><p>Yes, most parts of the UI can be reached using keyboard shortcuts. For an overview of the available shortcuts, press <code>?</code> anywhere in the UI.</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/docs/faq/technical-items.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_eYIM" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_vbeJ"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2022-09-10T07:31:45.000Z">9/10/2022</time></b></span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="Docs pages navigation"><a class="pagination-nav__link pagination-nav__link--prev" href="/faq/dockershim"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">Dockershim</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/faq/security"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">Security</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#how-can-i-reset-the-administrator-password" class="table-of-contents__link toc-highlight">How can I reset the administrator password?</a></li><li><a href="#i-deleteddeactivated-the-last-admin-how-can-i-fix-it" class="table-of-contents__link toc-highlight">I deleted/deactivated the last admin, how can I fix it?</a></li><li><a href="#how-can-i-enable-debug-logging" class="table-of-contents__link toc-highlight">How can I enable debug logging?</a></li><li><a href="#my-clusterip-does-not-respond-to-ping" class="table-of-contents__link toc-highlight">My ClusterIP does not respond to ping</a></li><li><a href="#where-can-i-manage-node-templates" class="table-of-contents__link toc-highlight">Where can I manage Node Templates?</a></li><li><a href="#why-is-my-layer-4-load-balancer-in-pending-state" class="table-of-contents__link toc-highlight">Why is my Layer-4 Load Balancer in <code>Pending</code> state?</a></li><li><a href="#where-is-the-state-of-rancher-stored" class="table-of-contents__link toc-highlight">Where is the state of Rancher stored?</a></li><li><a href="#how-are-the-supported-docker-versions-determined" class="table-of-contents__link toc-highlight">How are the supported Docker versions determined?</a></li><li><a href="#how-can-i-access-nodes-created-by-rancher" class="table-of-contents__link toc-highlight">How can I access nodes created by Rancher?</a></li><li><a href="#how-can-i-automate-task-x-in-rancher" class="table-of-contents__link toc-highlight">How can I automate task X in Rancher?</a></li><li><a href="#the-ip-address-of-a-node-changed-how-can-i-recover" class="table-of-contents__link toc-highlight">The IP address of a node changed, how can I recover?</a></li><li><a href="#how-can-i-add-additional-argumentsbindsenvironment-variables-to-kubernetes-components-in-a-rancher-launched-kubernetes-cluster" class="table-of-contents__link toc-highlight">How can I add additional arguments/binds/environment variables to Kubernetes components in a Rancher Launched Kubernetes cluster?</a></li><li><a href="#how-do-i-check-if-my-certificate-chain-is-valid" class="table-of-contents__link toc-highlight">How do I check if my certificate chain is valid?</a></li><li><a href="#how-do-i-check-common-name-and-subject-alternative-names-in-my-server-certificate" class="table-of-contents__link toc-highlight">How do I check <code>Common Name</code> and <code>Subject Alternative Names</code> in my server certificate?</a></li><li><a href="#why-does-it-take-5-minutes-for-a-pod-to-be-rescheduled-when-a-node-has-failed" class="table-of-contents__link toc-highlight">Why does it take 5+ minutes for a pod to be rescheduled when a node has failed?</a></li><li><a href="#can-i-use-keyboard-shortcuts-in-the-ui" class="table-of-contents__link toc-highlight">Can I use keyboard shortcuts in the UI?</a></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2022 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
<script src="/assets/js/runtime~main.d2604d48.js"></script>
<script src="/assets/js/main.aa78001f.js"></script>
</body>
</html>