From d8053756240bd07defce4b17488f59d832bd1095 Mon Sep 17 00:00:00 2001 From: windsonsea Date: Mon, 19 Aug 2024 09:38:06 +0800 Subject: [PATCH] [zh] Sync command-line-tools-reference/kube-proxy.md --- .../kube-proxy.md | 177 ++++++++---------- 1 file changed, 83 insertions(+), 94 deletions(-) diff --git a/content/zh-cn/docs/reference/command-line-tools-reference/kube-proxy.md b/content/zh-cn/docs/reference/command-line-tools-reference/kube-proxy.md index f368906fb5..8035ca6d1a 100644 --- a/content/zh-cn/docs/reference/command-line-tools-reference/kube-proxy.md +++ b/content/zh-cn/docs/reference/command-line-tools-reference/kube-proxy.md @@ -251,94 +251,87 @@ A set of key=value pairs that describe feature gates for alpha/experimental feat APIResponseCompression=true|false (BETA - default=true)
APIServerIdentity=true|false (BETA - default=true)
APIServerTracing=true|false (BETA - default=true)
-APIServingWithRoutine=true|false (BETA - default=true)
+APIServingWithRoutine=true|false (ALPHA - default=false)
AllAlpha=true|false (ALPHA - default=false)
AllBeta=true|false (BETA - default=false)
+AnonymousAuthConfigurableEndpoints=true|false (ALPHA - default=false)
AnyVolumeDataSource=true|false (BETA - default=true)
-AppArmor=true|false (BETA - default=true)
-AppArmorFields=true|false (BETA - default=true)
+AuthorizeNodeWithSelectors=true|false (ALPHA - default=false)
+AuthorizeWithSelectors=true|false (ALPHA - default=false)
CPUManagerPolicyAlphaOptions=true|false (ALPHA - default=false)
CPUManagerPolicyBetaOptions=true|false (BETA - default=true)
CPUManagerPolicyOptions=true|false (BETA - default=true)
CRDValidationRatcheting=true|false (BETA - default=true)
-CSIMigrationPortworx=true|false (BETA - default=false)
+CSIMigrationPortworx=true|false (BETA - default=true)
CSIVolumeHealth=true|false (ALPHA - default=false)
CloudControllerManagerWebhook=true|false (ALPHA - default=false)
ClusterTrustBundle=true|false (ALPHA - default=false)
ClusterTrustBundleProjection=true|false (ALPHA - default=false)
ComponentSLIs=true|false (BETA - default=true)
-ConsistentListFromCache=true|false (ALPHA - default=false)
+ConcurrentWatchObjectDecode=true|false (BETA - default=false)
+ConsistentListFromCache=true|false (BETA - default=true)
ContainerCheckpoint=true|false (BETA - default=true)
ContextualLogging=true|false (BETA - default=true)
+CoordinatedLeaderElection=true|false (ALPHA - default=false)
CronJobsScheduledAnnotation=true|false (BETA - default=true)
CrossNamespaceVolumeDataSource=true|false (ALPHA - default=false)
CustomCPUCFSQuotaPeriod=true|false (ALPHA - default=false)
-CustomResourceFieldSelectors=true|false (ALPHA - default=false)
-DevicePluginCDIDevices=true|false (BETA - default=true)
-DisableCloudProviders=true|false (BETA - default=true)
-DisableKubeletCloudCredentialProviders=true|false (BETA - default=true)
-DisableNodeKubeProxyVersion=true|false (ALPHA - default=false)
+CustomResourceFieldSelectors=true|false (BETA - default=true)
+DRAControlPlaneController=true|false (ALPHA - default=false)
+DisableAllocatorDualWrite=true|false (ALPHA - default=false)
+DisableNodeKubeProxyVersion=true|false (BETA - default=true)
DynamicResourceAllocation=true|false (ALPHA - default=false)
-ElasticIndexedJob=true|false (BETA - default=true)
EventedPLEG=true|false (ALPHA - default=false)
GracefulNodeShutdown=true|false (BETA - default=true)
GracefulNodeShutdownBasedOnPodPriority=true|false (BETA - default=true)
HPAScaleToZero=true|false (ALPHA - default=false)
-HonorPVReclaimPolicy=true|false (ALPHA - default=false)
+HonorPVReclaimPolicy=true|false (BETA - default=true)
ImageMaximumGCAge=true|false (BETA - default=true)
+ImageVolume=true|false (ALPHA - default=false)
InPlacePodVerticalScaling=true|false (ALPHA - default=false)
-InTreePluginAWSUnregister=true|false (ALPHA - default=false)
-InTreePluginAzureDiskUnregister=true|false (ALPHA - default=false)
-InTreePluginAzureFileUnregister=true|false (ALPHA - default=false)
-InTreePluginGCEUnregister=true|false (ALPHA - default=false)
-InTreePluginOpenStackUnregister=true|false (ALPHA - default=false)
InTreePluginPortworxUnregister=true|false (ALPHA - default=false)
-InTreePluginvSphereUnregister=true|false (ALPHA - default=false)
InformerResourceVersion=true|false (ALPHA - default=false)
JobBackoffLimitPerIndex=true|false (BETA - default=true)
JobManagedBy=true|false (ALPHA - default=false)
-JobPodFailurePolicy=true|false (BETA - default=true)
JobPodReplacementPolicy=true|false (BETA - default=true)
-JobSuccessPolicy=true|false (ALPHA - default=false)
-KubeProxyDrainingTerminatingNodes=true|false (BETA - default=true)
-KubeletCgroupDriverFromCRI=true|false (ALPHA - default=false)
+JobSuccessPolicy=true|false (BETA - default=true)
+KubeletCgroupDriverFromCRI=true|false (BETA - default=true)
KubeletInUserNamespace=true|false (ALPHA - default=false)
KubeletPodResourcesDynamicResources=true|false (ALPHA - default=false)
KubeletPodResourcesGet=true|false (ALPHA - default=false)
-KubeletSeparateDiskGC=true|false (ALPHA - default=false)
+KubeletSeparateDiskGC=true|false (BETA - default=true)
KubeletTracing=true|false (BETA - default=true)
LoadBalancerIPMode=true|false (BETA - default=true)
-LocalStorageCapacityIsolationFSQuotaMonitoring=true|false (ALPHA - default=false)
-LogarithmicScaleDown=true|false (BETA - default=true)
+LocalStorageCapacityIsolationFSQuotaMonitoring=true|false (BETA - default=false)
LoggingAlphaOptions=true|false (ALPHA - default=false)
LoggingBetaOptions=true|false (BETA - default=true)
-MatchLabelKeysInPodAffinity=true|false (ALPHA - default=false)
+MatchLabelKeysInPodAffinity=true|false (BETA - default=true)
MatchLabelKeysInPodTopologySpread=true|false (BETA - default=true)
MaxUnavailableStatefulSet=true|false (ALPHA - default=false)
MemoryManager=true|false (BETA - default=true)
MemoryQoS=true|false (ALPHA - default=false)
-MultiCIDRServiceAllocator=true|false (ALPHA - default=false)
+MultiCIDRServiceAllocator=true|false (BETA - default=false)
MutatingAdmissionPolicy=true|false (ALPHA - default=false)
-NFTablesProxyMode=true|false (ALPHA - default=false)
+NFTablesProxyMode=true|false (BETA - default=true)
NodeInclusionPolicyInPodTopologySpread=true|false (BETA - default=true)
NodeLogQuery=true|false (BETA - default=false)
NodeSwap=true|false (BETA - default=true)
OpenAPIEnums=true|false (BETA - default=true)
-PDBUnhealthyPodEvictionPolicy=true|false (BETA - default=true)
-PersistentVolumeLastPhaseTransitionTime=true|false (BETA - default=true)
PodAndContainerStatsFromCRI=true|false (ALPHA - default=false)
PodDeletionCost=true|false (BETA - default=true)
-PodDisruptionConditions=true|false (BETA - default=true)
PodIndexLabel=true|false (BETA - default=true)
PodLifecycleSleepAction=true|false (BETA - default=true)
PodReadyToStartContainersCondition=true|false (BETA - default=true)
-PortForwardWebsockets=true|false (ALPHA - default=false)
-ProcMountType=true|false (ALPHA - default=false)
+PortForwardWebsockets=true|false (BETA - default=true)
+ProcMountType=true|false (BETA - default=false)
QOSReserved=true|false (ALPHA - default=false)
RecoverVolumeExpansionFailure=true|false (ALPHA - default=false)
-RecursiveReadOnlyMounts=true|false (ALPHA - default=false)
+RecursiveReadOnlyMounts=true|false (BETA - default=true)
RelaxedEnvironmentVariableValidation=true|false (ALPHA - default=false)
-RetryGenerateName=true|false (ALPHA - default=false)
+ReloadKubeletServerCertificateFile=true|false (BETA - default=true)
+ResilientWatchCacheInitialization=true|false (BETA - default=true)
+ResourceHealthStatus=true|false (ALPHA - default=false)
+RetryGenerateName=true|false (BETA - default=true)
RotateKubeletServerCertificate=true|false (BETA - default=true)
RuntimeClassInImageCriApi=true|false (ALPHA - default=false)
SELinuxMount=true|false (ALPHA - default=false)
@@ -347,20 +340,22 @@ SchedulerQueueingHints=true|false (BETA - default=false)
SeparateCacheWatchRPC=true|false (BETA - default=true)
SeparateTaintEvictionController=true|false (BETA - default=true)
ServiceAccountTokenJTI=true|false (BETA - default=true)
-ServiceAccountTokenNodeBinding=true|false (ALPHA - default=false)
+ServiceAccountTokenNodeBinding=true|false (BETA - default=true)
ServiceAccountTokenNodeBindingValidation=true|false (BETA - default=true)
ServiceAccountTokenPodNodeInfo=true|false (BETA - default=true)
-ServiceTrafficDistribution=true|false (ALPHA - default=false)
+ServiceTrafficDistribution=true|false (BETA - default=true)
SidecarContainers=true|false (BETA - default=true)
SizeMemoryBackedVolumes=true|false (BETA - default=true)
StatefulSetAutoDeletePVC=true|false (BETA - default=true)
-StatefulSetStartOrdinal=true|false (BETA - default=true)
StorageNamespaceIndex=true|false (BETA - default=true)
StorageVersionAPI=true|false (ALPHA - default=false)
StorageVersionHash=true|false (BETA - default=true)
StorageVersionMigrator=true|false (ALPHA - default=false)
+StrictCostEnforcementForVAP=true|false (BETA - default=false)
+StrictCostEnforcementForWebhooks=true|false (BETA - default=false)
StructuredAuthenticationConfiguration=true|false (BETA - default=true)
StructuredAuthorizationConfiguration=true|false (BETA - default=true)
+SupplementalGroupsPolicy=true|false (ALPHA - default=false)
TopologyAwareHints=true|false (BETA - default=true)
TopologyManagerPolicyAlphaOptions=true|false (ALPHA - default=false)
TopologyManagerPolicyBetaOptions=true|false (BETA - default=true)
@@ -370,8 +365,9 @@ UnauthenticatedHTTP2DOSMitigation=true|false (BETA - default=true)
UnknownVersionInteroperabilityProxy=true|false (ALPHA - default=false)
UserNamespacesPodSecurityStandards=true|false (ALPHA - default=false)
UserNamespacesSupport=true|false (BETA - default=false)
-VolumeAttributesClass=true|false (ALPHA - default=false)
+VolumeAttributesClass=true|false (BETA - default=false)
VolumeCapacityPriority=true|false (ALPHA - default=false)
+WatchCacheInitializationPostStartHook=true|false (BETA - default=false)
WatchFromStorageWithoutResourceVersion=true|false (BETA - default=false)
WatchList=true|false (ALPHA - default=false)
WatchListClient=true|false (BETA - default=false)
@@ -384,95 +380,87 @@ This parameter is ignored if a config file is specified by --config. APIResponseCompression=true|false (BETA - 默认值=true)
APIServerIdentity=true|false (BETA - 默认值=true)
APIServerTracing=true|false (BETA - 默认值=true)
-APIServingWithRoutine=true|false (BETA - 默认值=true)
+APIServingWithRoutine=true|false (ALPHA - 默认值=false)
AllAlpha=true|false (ALPHA - 默认值=false)
AllBeta=true|false (BETA - 默认值=false)
+AnonymousAuthConfigurableEndpoints=true|false (ALPHA - 默认值=false)
AnyVolumeDataSource=true|false (BETA - 默认值=true)
-AppArmor=true|false (BETA - 默认值=true)
-AppArmorFields=true|false (BETA - 默认值=true)
+AuthorizeNodeWithSelectors=true|false (ALPHA - 默认值=false)
+AuthorizeWithSelectors=true|false (ALPHA - 默认值=false)
CPUManagerPolicyAlphaOptions=true|false (ALPHA - 默认值=false)
CPUManagerPolicyBetaOptions=true|false (BETA - 默认值=true)
CPUManagerPolicyOptions=true|false (BETA - 默认值=true)
CRDValidationRatcheting=true|false (BETA - 默认值=true)
-CSIMigrationPortworx=true|false (BETA - 默认值=false)
+CSIMigrationPortworx=true|false (BETA - 默认值=true)
CSIVolumeHealth=true|false (ALPHA - 默认值=false)
CloudControllerManagerWebhook=true|false (ALPHA - 默认值=false)
ClusterTrustBundle=true|false (ALPHA - 默认值=false)
ClusterTrustBundleProjection=true|false (ALPHA - 默认值=false)
ComponentSLIs=true|false (BETA - 默认值=true)
-ConsistentListFromCache=true|false (ALPHA - 默认值=false)
+ConcurrentWatchObjectDecode=true|false (BETA - 默认值=false)
+ConsistentListFromCache=true|false (BETA - 默认值=true)
ContainerCheckpoint=true|false (BETA - 默认值=true)
ContextualLogging=true|false (BETA - 默认值=true)
+CoordinatedLeaderElection=true|false (ALPHA - 默认值=false)
CronJobsScheduledAnnotation=true|false (BETA - 默认值=true)
CrossNamespaceVolumeDataSource=true|false (ALPHA - 默认值=false)
CustomCPUCFSQuotaPeriod=true|false (ALPHA - 默认值=false)
-CustomResourceFieldSelectors=true|false (ALPHA - 默认值=false)
-DevicePluginCDIDevices=true|false (BETA - 默认值=true)
-DisableCloudProviders=true|false (BETA - 默认值=true)
-DisableKubeletCloudCredentialProviders=true|false (BETA - 默认值=true)
-DisableNodeKubeProxyVersion=true|false (ALPHA - 默认值=false)
+CustomResourceFieldSelectors=true|false (BETA - 默认值=true)
+DRAControlPlaneController=true|false (ALPHA - 默认值=false)
+DisableAllocatorDualWrite=true|false (ALPHA - 默认值=false)
+DisableNodeKubeProxyVersion=true|false (BETA - 默认值=true)
DynamicResourceAllocation=true|false (ALPHA - 默认值=false)
-ElasticIndexedJob=true|false (BETA - 默认值=true)
EventedPLEG=true|false (ALPHA - 默认值=false)
GracefulNodeShutdown=true|false (BETA - 默认值=true)
GracefulNodeShutdownBasedOnPodPriority=true|false (BETA - 默认值=true)
HPAScaleToZero=true|false (ALPHA - 默认值=false)
-HonorPVReclaimPolicy=true|false (ALPHA - 默认值=false)
+HonorPVReclaimPolicy=true|false (BETA - 默认值=true)
ImageMaximumGCAge=true|false (BETA - 默认值=true)
+ImageVolume=true|false (ALPHA - 默认值=false)
InPlacePodVerticalScaling=true|false (ALPHA - 默认值=false)
-InTreePluginAWSUnregister=true|false (ALPHA - 默认值=false)
-InTreePluginAzureDiskUnregister=true|false (ALPHA - 默认值=false)
-InTreePluginAzureFileUnregister=true|false (ALPHA - 默认值=false)
-InTreePluginGCEUnregister=true|false (ALPHA - 默认值=false)
-InTreePluginOpenStackUnregister=true|false (ALPHA - 默认值=false)
InTreePluginPortworxUnregister=true|false (ALPHA - 默认值=false)
-InTreePluginvSphereUnregister=true|false (ALPHA - 默认值=false)
InformerResourceVersion=true|false (ALPHA - 默认值=false)
JobBackoffLimitPerIndex=true|false (BETA - 默认值=true)
JobManagedBy=true|false (ALPHA - 默认值=false)
-JobPodFailurePolicy=true|false (BETA - 默认值=true)
JobPodReplacementPolicy=true|false (BETA - 默认值=true)
-JobSuccessPolicy=true|false (ALPHA - 默认值=false)
-KubeProxyDrainingTerminatingNodes=true|false (BETA - 默认值=true)
-KubeProxyDrainingTerminatingNodes=true|false (ALPHA - 默认值=false)
-KubeletCgroupDriverFromCRI=true|false (ALPHA - 默认值=false)
+JobSuccessPolicy=true|false (BETA - 默认值=true)
+KubeletCgroupDriverFromCRI=true|false (BETA - 默认值=true)
KubeletInUserNamespace=true|false (ALPHA - 默认值=false)
KubeletPodResourcesDynamicResources=true|false (ALPHA - 默认值=false)
KubeletPodResourcesGet=true|false (ALPHA - 默认值=false)
-KubeletSeparateDiskGC=true|false (ALPHA - 默认值=false)
+KubeletSeparateDiskGC=true|false (BETA - 默认值=true)
KubeletTracing=true|false (BETA - 默认值=true)
LoadBalancerIPMode=true|false (BETA - 默认值=true)
-LocalStorageCapacityIsolationFSQuotaMonitoring=true|false (ALPHA - 默认值=false)
-LogarithmicScaleDown=true|false (BETA - 默认值=true)
+LocalStorageCapacityIsolationFSQuotaMonitoring=true|false (BETA - 默认值=false)
LoggingAlphaOptions=true|false (ALPHA - 默认值=false)
LoggingBetaOptions=true|false (BETA - 默认值=true)
-MatchLabelKeysInPodAffinity=true|false (ALPHA - 默认值=false)
+MatchLabelKeysInPodAffinity=true|false (BETA - 默认值=true)
MatchLabelKeysInPodTopologySpread=true|false (BETA - 默认值=true)
MaxUnavailableStatefulSet=true|false (ALPHA - 默认值=false)
MemoryManager=true|false (BETA - 默认值=true)
MemoryQoS=true|false (ALPHA - 默认值=false)
+MultiCIDRServiceAllocator=true|false (BETA - 默认值=false)
MutatingAdmissionPolicy=true|false (ALPHA - 默认值=false)
-MultiCIDRServiceAllocator=true|false (ALPHA - 默认值=false)
-NFTablesProxyMode=true|false (ALPHA - 默认值=false)
+NFTablesProxyMode=true|false (BETA - 默认值=true)
NodeInclusionPolicyInPodTopologySpread=true|false (BETA - 默认值=true)
NodeLogQuery=true|false (BETA - 默认值=false)
NodeSwap=true|false (BETA - 默认值=true)
OpenAPIEnums=true|false (BETA - 默认值=true)
-PDBUnhealthyPodEvictionPolicy=true|false (BETA - 默认值=true)
-PersistentVolumeLastPhaseTransitionTime=true|false (BETA - 默认值=true)
PodAndContainerStatsFromCRI=true|false (ALPHA - 默认值=false)
PodDeletionCost=true|false (BETA - 默认值=true)
-PodDisruptionConditions=true|false (BETA - 默认值=true)
PodIndexLabel=true|false (BETA - 默认值=true)
PodLifecycleSleepAction=true|false (BETA - 默认值=true)
PodReadyToStartContainersCondition=true|false (BETA - 默认值=true)
-PortForwardWebsockets=true|false (ALPHA - 默认值=false)
-ProcMountType=true|false (ALPHA - 默认值=false)
+PortForwardWebsockets=true|false (BETA - 默认值=true)
+ProcMountType=true|false (BETA - 默认值=false)
QOSReserved=true|false (ALPHA - 默认值=false)
RecoverVolumeExpansionFailure=true|false (ALPHA - 默认值=false)
-RecursiveReadOnlyMounts=true|false (ALPHA - 默认值=false)
+RecursiveReadOnlyMounts=true|false (BETA - 默认值=true)
RelaxedEnvironmentVariableValidation=true|false (ALPHA - 默认值=false)
-RetryGenerateName=true|false (ALPHA - 默认值=false)
+ReloadKubeletServerCertificateFile=true|false (BETA - 默认值=true)
+ResilientWatchCacheInitialization=true|false (BETA - 默认值=true)
+ResourceHealthStatus=true|false (ALPHA - 默认值=false)
+RetryGenerateName=true|false (BETA - 默认值=true)
RotateKubeletServerCertificate=true|false (BETA - 默认值=true)
RuntimeClassInImageCriApi=true|false (ALPHA - 默认值=false)
SELinuxMount=true|false (ALPHA - 默认值=false)
@@ -481,20 +469,22 @@ SchedulerQueueingHints=true|false (BETA - 默认值=false)
SeparateCacheWatchRPC=true|false (BETA - 默认值=true)
SeparateTaintEvictionController=true|false (BETA - 默认值=true)
ServiceAccountTokenJTI=true|false (BETA - 默认值=true)
-ServiceAccountTokenNodeBinding=true|false (ALPHA - 默认值=false)
+ServiceAccountTokenNodeBinding=true|false (BETA - 默认值=true)
ServiceAccountTokenNodeBindingValidation=true|false (BETA - 默认值=true)
ServiceAccountTokenPodNodeInfo=true|false (BETA - 默认值=true)
-ServiceTrafficDistribution=true|false (ALPHA - 默认值=false)
+ServiceTrafficDistribution=true|false (BETA - 默认值=true)
SidecarContainers=true|false (BETA - 默认值=true)
SizeMemoryBackedVolumes=true|false (BETA - 默认值=true)
StatefulSetAutoDeletePVC=true|false (BETA - 默认值=true)
-StatefulSetStartOrdinal=true|false (BETA - 默认值=true)
StorageNamespaceIndex=true|false (BETA - 默认值=true)
StorageVersionAPI=true|false (ALPHA - 默认值=false)
StorageVersionHash=true|false (BETA - 默认值=true)
StorageVersionMigrator=true|false (ALPHA - 默认值=false)
+StrictCostEnforcementForVAP=true|false (BETA - 默认值=false)
+StrictCostEnforcementForWebhooks=true|false (BETA - 默认值=false)
StructuredAuthenticationConfiguration=true|false (BETA - 默认值=true)
StructuredAuthorizationConfiguration=true|false (BETA - 默认值=true)
+SupplementalGroupsPolicy=true|false (ALPHA - 默认值=false)
TopologyAwareHints=true|false (BETA - 默认值=true)
TopologyManagerPolicyAlphaOptions=true|false (ALPHA - 默认值=false)
TopologyManagerPolicyBetaOptions=true|false (BETA - 默认值=true)
@@ -504,9 +494,9 @@ UnauthenticatedHTTP2DOSMitigation=true|false (BETA - 默认值=true)
UnknownVersionInteroperabilityProxy=true|false (ALPHA - 默认值=false)
UserNamespacesPodSecurityStandards=true|false (ALPHA - 默认值=false)
UserNamespacesSupport=true|false (BETA - 默认值=false)
-ValidatingAdmissionPolicy=true|false (BETA - 默认值=false)
-VolumeAttributesClass=true|false (ALPHA - 默认值=false)
+VolumeAttributesClass=true|false (BETA - 默认值=false)
VolumeCapacityPriority=true|false (ALPHA - 默认值=false)
+WatchCacheInitializationPostStartHook=true|false (BETA - 默认值=false)
WatchFromStorageWithoutResourceVersion=true|false (BETA - 默认值=false)
WatchList=true|false (ALPHA - 默认值=false)
WatchListClient=true|false (BETA - 默认值=false)
@@ -519,17 +509,15 @@ WindowsHostNetwork=true|false (ALPHA - 默认值=true)
---healthz-bind-address 0.0.0.0     默认值:0.0.0.0:10256 +--healthz-bind-address ipport     默认值:0.0.0.0:10256

-服务健康状态检查的 IP 地址和端口。 -如果 --bind-address 未设置或设置为 IPv4,则默认为 “0.0.0.0:10256”。 -如果 --bind-address 设置为 IPv6,则默认为 “[::]:10256”。 -设置为空则禁用。如果配置文件由 --config 指定,则忽略此参数。 +服务健康状态检查的 IP 地址和端口,默认为 “0.0.0.0:10256”。 +如果配置文件由 --config 指定,则忽略此参数。

@@ -646,7 +634,7 @@ A comma-separated list of CIDR's which the ipvs proxier should not touch when cl ---ipvs-min-sync-period duration +--ipvs-min-sync-period duration     默认值:1s

@@ -925,9 +913,10 @@ log to standard error instead of files

-如果使用 iptables 或 ipvs 代理模式,则对通过 Service 集群 IP 发送的所有流量进行 SNAT。 -这对某些 CNI 插件可能是必需的。 +对通过 Service 集群 IP 发送的所有流量进行 SNAT。 +这对某些 CNI 插件可能是必需的。仅支持 Linux。

@@ -951,11 +940,10 @@ Kubernetes API 服务器的地址(覆盖 kubeconfig 中的相关值)。

metrics 服务器要使用的 IP 地址和端口。 如果 --bind-address 未设置或设置为 IPv4,则默认为 "127.0.0.1:10249"。 -如果 --bind-address 设置为 IPv6,则默认为 "[::1]:10249"。 设置为 "0.0.0.0:10249" / "[::]:10249" 可以在所有接口上进行绑定。 设置为空则禁用。如果配置文件由 --config 指定,则忽略此参数。

@@ -968,10 +956,11 @@ metrics 服务器要使用的 IP 地址和端口。

-一个包含有效节点 IP 的 CIDR 范围列表。 -如果设置了,到 NodePort 服务的连接只会在节点 IP 在指定范围内时才会被接受。 +一个包含有效节点 IP 的 CIDR 范围列表,或者单个字符串 “primary”。 +如果设置为 CIDR 列表,则仅在某所给范围内的节点 IP 上接受对 NodePort 服务的连接。 +如果设置为 “primary”,则将根据 Node 对象仅在其主 IP 上接受对 NodePort 服务的连接。 如果不设置,则 NodePort 连接将在所有本地 IP 上被接受。 如果配置文件由 --config 指定,则忽略此参数。