Commit Graph

3675 Commits (aae228c0377a677b59df6543f0b51cd21fcab176)

Author SHA1 Message Date
Micah Hausler 81e6c94293 Fix example KMS configuration documentation
Updated example configuration to specify separate unix domain socket
paths.

Signed-off-by: Micah Hausler <mhausler@amazon.com>
2024-05-16 15:32:39 -05:00
Sohan Kunkerkar e823cf9e5c Fix drop-in dir logic explaination
Signed-off-by: Sohan Kunkerkar <sohank2602@gmail.com>
2024-05-15 10:17:23 -04:00
Kubernetes Prow Robot 8901aa537e
Merge pull request #46113 from nilekhc/clarify-automatic-reloading
docs: updates automatics reloading behaviour.
2024-05-14 10:19:11 -07:00
Vishal Bidwe 0144870f60
- Removed .md typo formatting to render the webpage. 2024-05-09 17:27:46 +05:30
Nilekh Chaudhari 87a912068c
docs: updates automatics reloading behaviour.
Signed-off-by: Nilekh Chaudhari <1626598+nilekhc@users.noreply.github.com>
2024-05-08 16:10:19 +00:00
Aditya Samant cd6148bc97
Change the host for the ingress tutorial, to mitigate a security risk. 2024-05-07 13:50:32 +05:30
Michael 06113101af Make the markdown prettier: storage-version-migration.md 2024-05-05 18:52:57 +08:00
Kubernetes Prow Robot 7c5585e1a6
Merge pull request #45900 from city2011/patch-3
Update define-command-argument-container.md
2024-05-04 16:45:05 -07:00
Tim Bannister 085c4cd168 Reword advice about replicated encryption configuration 2024-05-01 12:29:11 +01:00
Tim Bannister 47f15991d9 Revise callouts in encryption-at-rest task page 2024-05-01 12:29:11 +01:00
windsonsea 9647701853 Clean up a task: kubelet-config-file 2024-04-29 22:01:31 +08:00
City 631e9a23e4 Update define-command-argument-container.md
use uppercase letter in not and add args corresponding description

fix grammatical
2024-04-24 17:29:01 +08:00
Kubernetes Prow Robot 305078d22e
Merge pull request #45778 from mrgiles/45539_shell_access_to_node_before_upgrade
Add shell access prereq to node upgrade cluster task
2024-04-22 15:34:40 -07:00
Kubernetes Prow Robot a2d0b70c97
Merge pull request #45350 from dshebib/podResourceInPlaceExampleFix
Add feature gate to pod vertical resource scaling example
2024-04-22 13:48:28 -07:00
Kubernetes Prow Robot a47f72b372
Merge pull request #45225 from sftim/20240220_auto_calculate_more_feature_states
Switch more feature-state shortcodes to be data driven
2024-04-22 13:33:11 -07:00
Kubernetes Prow Robot 67e3bb86a4
Merge pull request #45916 from tengqm/configapi-ref-v1.30
Config API reference for v1.30
2024-04-22 13:27:42 -07:00
Kubernetes Prow Robot f94825a663
Merge pull request #45071 from adityasamant25/issue-44651
Instructions to access Service and Ingress Resource through a minikube tunnel
2024-04-22 12:43:05 -07:00
Tim Bannister 7b6866063f Switch more feature-state shortcodes to be data driven
When the feature gates graduate (or get deprecated), the associated
shortcode will update automatically.
2024-04-22 13:02:28 +01:00
wushka00 6ea106744e
Update troubleshoot-kubectl.md
Included reference to additional tools in TLS problems.
2024-04-21 14:37:30 +10:00
Qiming Teng 6fa7b80ae3 Config API reference for v1.30 2024-04-18 19:57:27 +08:00
Kubernetes Prow Robot 61f8737cbd
Merge pull request #44540 from adityasamant25/configmaps-secrets
Document updating configuration via a ConfigMap
2024-04-17 14:13:26 -07:00
drewhagen 4c6ba12390 Merge main into dev-1.30 to keep in sync 2024-04-16 15:55:38 -05:00
Kubernetes Prow Robot fbbfe20ad0
Merge pull request #45837 from spurin/switch_liveness_to_multi_arch_image
Switch liveness image to multi-arch agnhost container image
2024-04-14 08:26:33 -07:00
James Spurin 2a6ec81df0
Update configure-liveness-readiness-startup-probes.md
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2024-04-13 19:27:21 +01:00
John.C 777987abbc
Update verify-kubectl.md 2024-04-12 15:21:26 +01:00
James Spurin b8c079794a update image reference 2024-04-11 18:40:56 +01:00
Vyom-Yadav 37b0b3ed72
Merge remote-tracking branch 'upstream/main' into dev-1.30 2024-04-10 23:04:57 +05:30
Kubernetes Prow Robot 97d1b81753
Merge pull request #45775 from tuladhar/helm-deploy-dashboard
Update Kubernetes Dashboard deployment to Helm-based installation
2024-04-10 10:05:48 -07:00
lorenzogrv 3325f2e759
kubectl debian install guide
On a bare-metal Debian 12 clean install, gnupg is needed. Maybe it should be noted with prose
2024-04-10 06:13:16 +02:00
Kubernetes Prow Robot caaaefb6f5
Merge pull request #44680 from fbauzac/patch-1
install-kubectl-linux.md: add chmods
2024-04-09 11:34:27 -07:00
Aditya Samant af7e2ad33c
Added instructions for MacOS and Windows that enable accessing services using minikube tunnel.
Co-authored-by: Dipesh Rawat <rawat.dipesh@gmail.com>
2024-04-06 20:30:15 +05:30
Marcelo Giles 7a91dcc078
Add shell access prereq to node upgrade cluster task
Add shell access prereq to node upgrade task
2024-04-05 11:50:25 -07:00
Puru 6c409b3e75 Update web-ui-dashboard.md 2024-04-05 23:17:13 +05:45
Puru dab6fcfd5c Wrap lines 2024-04-05 14:53:56 +05:45
Aditya Samant 3efc5cde2f
Updating Configuration via a Configmap
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2024-04-05 09:16:51 +05:30
Puru 4912e74f05
Update 2024-04-05 00:44:09 +05:45
Puru 6eec18bddc
Update web-ui-dashboard.md 2024-04-05 00:30:58 +05:45
drewhagen 2a0b55d3c7 docs: KEP-4192 PR feedback - feature gates don't match the code 2024-04-04 12:22:42 -05:00
Kubernetes Prow Robot 0086fc6d55
Merge pull request #45757 from drewhagen/kep_4192_svm_v1alpha1_docs_v1.30_dh
docs: incorporating more PR feedback on storage version migration
2024-04-02 08:10:11 -07:00
drewhagen 6f8db3bf48 docs: incorporating more PR feedback on storage version migration 2024-04-02 09:43:31 -05:00
Kubernetes Prow Robot 69a380930b
Merge pull request #45714 from drewhagen/kep_4192_svm_v1alpha1_docs_v1.30_dh
docs: adds documentation for Storage Version Migration
2024-03-28 00:24:26 -07:00
drewhagen 048f53da02 docs: PR feedback for documentation on Storage Version Migration 2024-03-27 22:12:57 -05:00
Tim Bannister e741392f76 Fix broken hyperlink 2024-03-27 11:33:50 +00:00
Kubernetes Prow Robot 56863852ba
Merge pull request #45675 from Princesso/merged-main-dev-1.30
Merge main branch into dev-1.30
2024-03-27 03:12:53 -07:00
Kubernetes Prow Robot 004553eb84
Merge pull request #45665 from haircommander/update-kep-3983
[dev-1.30] docs: Update KubeletConfigDropinDir doc information
2024-03-26 19:58:52 -07:00
Kubernetes Prow Robot 5145a6a4e1
Merge pull request #45152 from haircommander/proc-mount-beta-1.30
ProcMount 1.30 update
2024-03-26 14:11:05 -07:00
Kubernetes Prow Robot 78956f85d9
Merge pull request #45264 from alexzielenski/4008-beta2
KEP-4008: CRDValidationRacheting - Beta Docs
2024-03-26 13:31:07 -07:00
Alexander Zielenski 251c4706e0 update ratcheting docs for beta 2024-03-26 10:39:30 -07:00
Sohan Kunkerkar c306367734 docs: Update KubeletConfigDropinDir doc information
Signed-off-by: Sohan Kunkerkar <sohank2602@gmail.com>
Signed-off-by: Peter Hunt <pehunt@redhat.com>
2024-03-26 10:43:27 -04:00
Peter Hunt c3e2106694 add documentation for the ProcMount field, originally introduced in 1.12
Signed-off-by: Peter Hunt <pehunt@redhat.com>
2024-03-26 10:04:06 -04:00
Oluebube Princes Egbuna 0568c8af60 Merge remote-tracking branch 'upstream/main' into dev-1.30 2024-03-26 08:40:45 +01:00
Kubernetes Prow Robot 3d33323801
Merge pull request #45125 from HirazawaUi/allow-special-characters
Document option to allow almost all printable ASCII characters in environment variables
2024-03-25 19:43:19 -07:00
HirazawaUi 0c1b3e3d03 Allow almost all printable ASCII characters in environment variables 2024-03-26 09:49:11 +08:00
Kubernetes Prow Robot 7ee320764a
Merge pull request #45197 from sftim/20240218_document_cluster_autoscaling
Add concept page about cluster autoscaling
2024-03-25 07:37:02 -07:00
Kubernetes Prow Robot a7c220cae9
Merge pull request #45176 from tallclair/apparmor-1.30
Apparmor 1.30
2024-03-23 03:12:39 -07:00
Kubernetes Prow Robot 8e761315d1
Merge pull request #45504 from network-charles/network-charles-patch-2
Update resource-usage-monitoring.md
2024-03-22 17:41:27 -07:00
Anirudh 20b2d064c9
Added a link to the minikube installation website
Hi, I was trying to install Kubernetes on my local machine and I noticed that suggestion to install Minikube did not have a hyperlink to it. So I added a link at the mention of install Minikube so it's convenient for people trying to install it on their local machine.
2024-03-22 00:35:17 -04:00
Daniel Chan b06db3c244 Merge remote-tracking branch 'upstream/main' into dev-1.30
Merge main into dev-1.30 to keep in sync
2024-03-21 10:48:00 -04:00
Kubernetes Prow Robot c7cd6c5644
Merge pull request #45178 from kinvolk/rata/userns-1.30
User namespaces doc changes for 1.30
2024-03-21 01:46:52 -07:00
Tim Allclair 4f11f83a45 AppArmor v1.30 docs update 2024-03-19 14:25:06 -07:00
Charles Uneze d77e68f2fd
Update resource-usage-monitoring.md 2024-03-19 18:26:54 +01:00
Rodrigo Campos 69b9e71ff6 content: hostUsers can't be ignored from 1.30
Now the kubelet asks the runtime for the features it supports and if it
doesn't report user namespaces support, then the kubelet will fail the
pod creation.

Therefore, it is no longer possible for the field to be ignored.

Signed-off-by: Rodrigo Campos <rodrigoca@microsoft.com>
2024-03-19 14:59:40 +01:00
Rodrigo Campos b327397fc6 content: Fix typo in userns example
We were showing 4294967295 for the uid_map file, that is how it looks on
the host (not the container). Let's fix that.

While we are there, let's improve the explanation too.

Signed-off-by: Rodrigo Campos <rodrigoca@microsoft.com>
2024-03-19 14:59:39 +01:00
Rodrigo Campos 271bb1a8fb content: Mark userns as beta in 1.30
Signed-off-by: Rodrigo Campos <rodrigoca@microsoft.com>
2024-03-19 14:59:39 +01:00
Kubernetes Prow Robot 3b6274d696
Merge pull request #45155 from jpbetz/crd-field-selectors
Add docs for CRD field selection
2024-03-18 08:24:50 -07:00
Joe Betz 8c0a57a1e1 Add docs for CRD field selection 2024-03-18 11:09:04 -04:00
Walid Ghallab bed970676c Fix documentation for parallel processing work queue tasks.
Changes in details:
- Add instructions to run redis server, since without it the rest of the steps won't work.
- For work-queue jobs, instruct the user to leave the completions number unset (as setting it to 1 won't run more than one job in parallel, and is different when left unset).
- Change the package installation to python3, as python package is no longer available
2024-03-18 02:48:50 +01:00
Vyom-Yadav 1eb315a43a
Merge remote-tracking branch 'upstream/main' into dev-1.30 2024-03-15 16:42:11 +05:30
Kubernetes Prow Robot b8ec2eb353
Merge pull request #45280 from jsafrane/selinux-rwx-alpha
Document SELinuxMount feature gate
2024-03-15 00:38:24 -07:00
Nilekh Chaudhari 48fdee2334
docs: adds documentation for Storage Version Migration
Signed-off-by: Nilekh Chaudhari <1626598+nilekhc@users.noreply.github.com>
2024-03-14 17:56:42 +00:00
fbauzac d798896198
Update content/en/docs/tasks/tools/install-kubectl-linux.md
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2024-03-13 15:17:35 +01:00
fbauzac 9319773960
Update content/en/docs/tasks/tools/install-kubectl-linux.md
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2024-03-13 15:17:26 +01:00
Daniel Shebib e64910f778 Add feature gate to example 2024-03-12 14:41:25 -05:00
Jan Safranek 6a1761c33a Document SELinuxMount feature gate
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2024-03-12 16:51:54 +01:00
Charles Uneze faeb20fab9
Update resource-usage-monitoring.md 2024-03-11 17:06:57 +01:00
Kubernetes Prow Robot 4d804f9417
Merge pull request #45469 from Kheiden/patch-1
Update install-kubectl-windows.md
2024-03-11 04:10:55 -07:00
Nick Neisen fe501f8bfa
Change cri-dockerd links to official docs in the english content 2024-03-08 11:46:54 -07:00
Kurt Heiden 6d3a106bc0
Update install-kubectl-windows.md 2024-03-07 12:36:39 -07:00
Tim Bannister b39e01b971 Add concept page about cluster autoscaling
Co-Authored-By: Niranjan Darshann <niranjan.darshan@india.nec.com>
2024-03-05 10:46:37 +00:00
Kensei Nakada 98f0a91e95
graduate HPAContainerMetrics to stable 2024-03-02 14:03:22 +09:00
Celeste Horgan f000899edf Merge remote-tracking branch 'upstream/main' into dev-1.30 2024-02-29 17:57:20 +01:00
varadaprasanth 3ac8160b85
Update service-access-application-cluster.md
Formatted for the documentation standards
2024-02-29 17:51:06 +05:30
Kubernetes Prow Robot fc52c54fcd
Merge pull request #44693 from adityasamant25/issue-44687
Remove hostPort field from the liveness probe examples to align with Kubernetes best practices.
2024-02-28 08:23:49 -08:00
Kubernetes Prow Robot f3193b5116
Merge pull request #45377 from drewhagen/merged-main-dev-1.30
Merge main branch into dev-1.30
2024-02-28 02:30:30 -08:00
Kubernetes Prow Robot 6d5a60c089
Merge pull request #45307 from eaudetcobello/patch-1
Fix wording in configure-upgrade-etcd.md
2024-02-27 13:36:21 -08:00
Bart Jeukendrup ea6624ee62
Clarify in the documentation that 27017 is the official TCP port for MongoDB 2024-02-26 17:12:05 +01:00
Kubernetes Prow Robot bb24ce5ab8
Merge pull request #45095 from clementnuss/patch-3
docs(kubeadm-upgrade): add consideration on etcd upgrade impact
2024-02-23 21:33:25 -08:00
Oluebube Princes Egbuna 1710de7e11 Merge remote-tracking branch 'upstream/main' into dev-1.30 2024-02-23 21:33:57 +01:00
eaudetcobello a8ec490629 Various wording improvements throughout the file. 2024-02-23 16:23:13 +00:00
cShirley14 d6459c1823
Update content/en/docs/tasks/administer-cluster/network-policy-provider/weave-network-policy.md
Co-authored-by: Bryan Boreham <bjboreham@gmail.com>
2024-02-22 11:32:53 -06:00
Chantal Shirley 713d621b60 fix: update broken links 2024-02-21 12:56:16 -06:00
Oluebube Princes Egbuna e1465e035a Merge remote-tracking branch 'upstream/main' into dev-1.30 2024-02-20 11:46:04 +01:00
Kubernetes Prow Robot 51b0ebc934
Merge pull request #45073 from neolit123/1.30-add-external-ca-notes
kubeadm-certs: add notes about different external CA approaches
2024-02-16 09:53:39 -08:00
Kubernetes Prow Robot 217f88267f
Merge pull request #44832 from adityasamant25/kubeadm-upgrade
Use sudo for elevated permissions while upgrading clusters using kubeadm
2024-02-15 12:24:12 -08:00
Clément Nussbaumer 2dc571df77
docs(kubeadm-upgrade): add consideration on etcd upgrade impact
relates to https://github.com/kubernetes/kubeadm/issues/2991#issuecomment-1932337556

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>

Signed-off-by: Clément Nussbaumer <clement.nussbaumer@postfinance.ch>
2024-02-14 08:03:53 +01:00
Kubernetes Prow Robot fd764e39ae
Merge pull request #44951 from sftim/20240130_revise_encryption_at_rest
Reword advice about encryption-at-rest opt outs
2024-02-13 22:48:21 -08:00
wushka00 85fe916165
Update content/en/docs/tasks/debug/debug-cluster/troubleshoot-kubectl.md
Thanks and agreed regarding format change.

Co-authored-by: Sean McGinnis <sean.mcginnis@gmail.com>
2024-02-14 08:54:50 +11:00
wushka00 71d493bf94
Update troubleshoot-kubectl.md
In this section - I found the provided commands didn't generate the desired results.

The proposed commands seem to work for me.

Validated with:

kubectl version
Client Version: v1.28.6
Kustomize Version: v5.0.4-0.20230601165947-6ce0bf390ce3
Server Version: v1.28.6

openssl version
OpenSSL 3.0.2 15 Mar 2022 (Library: OpenSSL 3.0.2 15 Mar 2022)

base64 (GNU coreutils) 8.32
2024-02-14 08:00:15 +11:00
Puru 69706582d4
Fix mermaid syntax error 2024-02-13 14:14:10 +05:45
steve-hardman 0290715170
Fix path for example yaml in 'Coarse Parallel Processing Using a Work Queue' task page (#45022)
* Fix link for example yaml

* Fix link for example yaml

Co-authored-by: Dipesh Rawat <rawat.dipesh@gmail.com>

---------

Co-authored-by: Dipesh Rawat <rawat.dipesh@gmail.com>
2024-02-12 11:12:06 -08:00
Lubomir I. Ivanov 9593771ee9 kubeadm-certs: add notes about different external CA approaches
There are multiple ways to prepare the credentials for use
with "external CA" mode:
- manual
- using kubeadm CSRs
- using kubeadm phases
2024-02-09 12:23:03 +02:00
drewhagen e4da56ebcb Merge remote-tracking branch 'upstream/main' into merged-main-dev-1.30 2024-02-02 09:19:40 -06:00
Kubernetes Prow Robot 74aea8146b
Merge pull request #44800 from sftim/20240118_improve_sidecar_container_docs
Update docs around sidecar containers
2024-02-01 09:24:48 -08:00
Tim Bannister 6d6b17abd1 Reword advice about encryption-at-rest opt outs
Co-authored-by: Shannon Kularathna <ax3shannonkularathna@gmail.com>
2024-01-31 15:59:25 +00:00
Tim Bannister 5a859a79d8 Fix highlighting for added lines 2024-01-30 17:48:46 +00:00
Tim Bannister 07b14de027
Fix highlighting 2024-01-30 17:02:25 +00:00
Carlos Eduardo Arango Gutierrez c4937ba3a4
Document NFD for GPU Labeling
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
2024-01-30 17:23:54 +01:00
Aditya Samant ede616833a Changed the context of the remark for the usage of etcdctl for restoring. As per the review comments to the original PR.
PR rebased.
2024-01-30 09:12:49 +05:30
Aditya Samant 7bca5a7297 Used etcdutl instead of etcdctl for restoring an etcd cluster. 2024-01-30 09:06:21 +05:30
Kubernetes Prow Robot 54ab2e8149
Merge pull request #44897 from mengjiao-liu/fix-dns-autoscaler-name
Fix Deployment and ConfigMap name in the dns-horizontal-autoscaling page
2024-01-26 17:46:31 +01:00
Kubernetes Prow Robot 6089916922
Merge pull request #44801 from sftim/20240118_revise_encryption_at_rest
Revise introduction to encryption at rest page
2024-01-26 17:27:42 +01:00
Kubernetes Prow Robot 54145dd9cb
Merge pull request #43824 from ptrovatelli/patch-1
Update configure-upgrade-etcd.md
2024-01-26 02:47:03 +01:00
Mengjiao Liu 7e2f696572 Fix Deployment and ConfigMap name in the dns-horizontal-autoscaling page 2024-01-25 15:51:03 +08:00
Aditya Samant c6e210f8f1 Added sudo permissions as necessary. 2024-01-24 15:32:46 +05:30
pegasas d265f98ca9 Add Liveness, Readiness, and Startup Probes Concepts and supply clean up example 2024-01-24 12:19:14 +08:00
Kubernetes Prow Robot 1ab49249ab
Merge pull request #44823 from my-git9/patch-13962
Correct incorrect expressions for debug-pods
2024-01-23 14:20:48 +01:00
Kubernetes Prow Robot ca81744686
Merge pull request #44831 from 1000Delta/fix_access-cluster-services
Fix access-cluster-services.md list indent
2024-01-23 14:17:48 +01:00
Abel Lu cfc9eb01da
Additional links to "What's next" in determine-reason-pod-failure.md (#44288)
Issue #44207
2024-01-22 04:31:23 +01:00
DeltaX 586fd88b02 Fix access-cluster-services.md list indent 2024-01-21 15:58:46 +08:00
xin.li 5fcc71ad51 [en] Correct incorrect expressions
Signed-off-by: xin.li <xin.li@daocloud.io>
2024-01-20 23:44:36 +08:00
Kubernetes Prow Robot fbf9b4fd7c
Merge pull request #44776 from BRONSOLO/patch-1
Update encrypt-data.md
2024-01-19 23:22:41 +01:00
Tim Bannister dd7e3966ef Revise introduction to encryption at rest page
Help readers check if they need to follow the task.
2024-01-19 00:23:25 +00:00
Tim Bannister 5bbb5ace30 Update docs around sidecar containers 2024-01-18 23:57:04 +00:00
Cintia Sanchez Garcia 26e760da6e Update references to CNCF landscape (v2)
This PR updates all the references to the CNCF landscape (v2). This includes migrating to the new embeddable views that the new landscape provides, changing how iframe-resizer is used and updating a few links.

Related to #44022

Signed-off-by: Cintia Sanchez Garcia <cynthiasg@icloud.com>
2024-01-18 12:36:45 +01:00
Christine K 09e79db506
Add example command to create /etc/apt/keyrings directory (#43626)
* create folder for key

The following command will fail without the folder created manually beforhand.
```
curl -fsSL https://dl.k8s.io/apt/doc/apt-key.gpg | sudo gpg --dearmor -o /etc/apt/keyrings/kubernetes-archive-keyring.gpg
```

* updated instruction

updated according to the comment in the PR

* updated mkdir part

* Updated mkdir
2024-01-17 17:01:14 +01:00
Kubernetes Prow Robot ef9194bdf3
Merge pull request #44721 from sftim/20240112_revise_encryption_at_rest
Recommend replicating encryption key for API data encryption at rest
2024-01-17 16:56:30 +01:00
Chuck Bronson b1929ab8a8
Update encrypt-data.md
Fix as ---> at typo
2024-01-17 10:40:02 -05:00
Aditya Samant 5799e6e4c6 Fix the links in the ConfigMap documentation related to projection of keys and file permissions. 2024-01-15 14:17:34 +05:30
PrashantDesale2004 0f9ab60a3c
Update CoreDNS installation docs
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2024-01-14 20:29:41 +05:30
PrashantDesale2004 5ee30f167a fixed installation guide in using CoreDNS for Service Discovery page 2024-01-14 19:41:35 +05:30
Kubernetes Prow Robot cb27724d3e
Merge pull request #43247 from srm09/patch-1
Fixes comment for webhook conversion strategy
2024-01-13 07:06:22 +01:00
Tim Bannister 0e05396f1b Recommend replicating encryption key
When using API encryption at rest without KMS, the same encryption key
must be securely replicated to all the hosts that run a kube-apiserver.

Document that.
2024-01-12 14:38:25 +00:00
Aditya Samant 05a4ab128a Remove hostPort field from the liveness probe examples to align with Kubernetes best practices. 2024-01-10 08:59:02 +05:30
John Huang 8106c6e092
Add notes on kubeadm clusters version (#44683)
* Add notes on kubeadm clusters version

Update content/en/docs/tasks/administer-cluster/kubeadm/kubeadm-upgrade.md

Co-authored-by: Dipesh Rawat <rawat.dipesh@gmail.com>

move into additional information

* Update content/en/docs/tasks/administer-cluster/kubeadm/kubeadm-upgrade.md

Co-authored-by: Tim Bannister <tim@scalefactory.com>

---------

Co-authored-by: Tim Bannister <tim@scalefactory.com>
2024-01-09 18:07:50 +01:00
fbauzac e15b943a5a
install-kubectl-linux.md: add chmods
The keyring needs to be readable by _apt, otherwise "apt update" prints the following kind of error:

W: GPG error: https://prod-cdn.packages.k8s.io/repositories/isv:/kubernetes:/core:/stable:/v1.29/deb  InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 234654DA9A296436
E: The repository 'https://pkgs.k8s.io/core:/stable:/v1.29/deb  InRelease' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.

kubernetes.list needs to be world-readable, otherwise command-not-found prints warnings such as:

WARNING:root:could not open file '/etc/apt/sources.list.d/kubernetes.list'
2024-01-09 10:01:10 +01:00
Tim Bannister bfbe2db97b Highlight initial comment
Make the initial comment extra obvious to readers.
2024-01-08 17:55:46 +00:00
Kubernetes Prow Robot ec8a3cb52d
Merge pull request #44532 from sftim/20231226_encryption_at_rest
Improve docs around API data encryption at rest
2024-01-08 18:32:23 +01:00
Kubernetes Prow Robot cca14eff62
Merge pull request #44571 from hunshcn/fix/link
fix outdated link/anchor
2024-01-07 23:15:35 +01:00
Kubernetes Prow Robot a416215bbf
Merge pull request #42446 from pacoxu/pacoxu-patch-1
Make image registry hostname more obvious in example
2024-01-07 23:06:53 +01:00
Kubernetes Prow Robot f646fb0627
Merge pull request #43808 from morhook/patch-1
Add a clarification for autoscaling on minikube
2024-01-05 10:26:43 +01:00
hunshcn bcc55ae7c9
fix outdated link/anchor
Signed-off-by: hunshcn <hunsh.cn@gmail.com>
2024-01-03 15:00:11 +08:00
Kubernetes Prow Robot e2509cb624
Merge pull request #44506 from Takashiidobe/fix-typos
fix typos
2024-01-02 19:29:55 +01:00
Tim Bannister e17cd06c3d Revise guidance for rotating a decryption key 2024-01-02 11:14:30 +00:00
Tim Bannister b749f91f12 Document avoiding plain text retrieval
When you have set up your cluster for encryption at rest, you can take
this defence in depth measure to make sure that anything held without
encryption causes a retrieval error (which is then more likely to flag
that there is a problem).
2024-01-02 11:14:30 +00:00
Qiming Teng 8b46ec4047 Fix several link errors 2024-01-01 21:15:50 +08:00
hunshcn 6a7240f55b
fix serviceaccount-token-volume-projection link 2023-12-28 21:39:19 +08:00
Kubernetes Prow Robot c807f97145
Merge pull request #44355 from hunshcn/sysctl
update safe sysctls (v1.29)
2023-12-27 12:44:29 +01:00
Kubernetes Prow Robot 0f285fd32d
Merge pull request #44085 from sftim/20231125_explain_protection_encryption_keys
Explain more about protection for encryption keys (API data encryption at rest)
2023-12-26 07:18:49 +01:00
hunshcn fc8e79b96c
update safe sysctl
Signed-off-by: hunshcn <hunsh.cn@gmail.com>
2023-12-25 10:47:54 +08:00
Takashiidobe d536e46dbd fix typos 2023-12-24 21:00:53 -05:00
Tim Bannister ada845e5e1 Link to KMS setup doc 2023-12-22 11:33:36 +00:00
Tim Bannister 9f8b35d93f Redo API encryption at rest explanation
- Explain importance of protecting keys and other material that can be
  used to decrypt data in etcd
- Revise the explanation for a non-KMS setup example
2023-12-22 11:33:36 +00:00
Kubernetes Prow Robot bd4d92763f
Merge pull request #44043 from steve-hardman/fix-kubectl-mac-step
Fix cleanup instruction in macOS kubectl installation page
2023-12-22 07:45:54 +01:00
Kubernetes Prow Robot 967593f3dd
Merge pull request #44266 from adityasamant25/issue-32835
Changes to reflect the deprecation of pod-manifest-path argument
2023-12-22 07:43:12 +01:00
Kubernetes Prow Robot 7b3ebb32fb
Merge pull request #43634 from able8/patch-1
Fixed a typo on page "Create an External Load Balancer"
2023-12-22 03:56:37 +01:00
Paco Xu 9e097396b9 use image from DUMMY_SERVER in the example 2023-12-22 10:31:25 +08:00
Kubernetes Prow Robot 057c9633a3
Merge pull request #44227 from windsonsea/changey
Clean up change-default-storage-class and access-cluster-api tasks
2023-12-22 02:21:22 +01:00
Kubernetes Prow Robot 28c702a195
Merge pull request #44095 from sftim/20231126_improve_job_tutorials
Improve tutorials for Job
2023-12-21 18:21:31 +01:00
giiiiiithub 5605ae7b99
fix the Chinese single quotes in the code to English single quotes 2023-12-20 17:06:26 +08:00
Kubernetes Prow Robot 74f94da59e
Merge pull request #44408 from testwill/patch-3
fix: container not sandbox
2023-12-20 09:40:21 +01:00
steve-hardman 242296af2a
Remove extra character
Co-authored-by: Dipesh Rawat <rawat.dipesh@gmail.com>
2023-12-20 00:34:51 +00:00
steve-hardman 80353185f5
Remove extra character 2023-12-19 23:17:19 +00:00
windsonsea d1d6eda640 Clean up change-default-storage-class.md 2023-12-19 08:57:48 +08:00
Tobias 7ffd84798f
Fix broken hyperlink for 'Cosign Keyless Signatures' in "Verify Signed Kubernetes Artifacts" guide (#44235)
* fix broken links to cosign signing page

* remove changes to zn translation

* change link to https://docs.sigstore.dev/signing/overview/
2023-12-18 11:08:33 +01:00
guangwu 9b28c20c8b
fix: container not sandbox 2023-12-18 10:45:01 +08:00
windsonsea e9c2827477 Fix a link in custom-resource-definitions task 2023-12-15 09:07:10 +08:00
Kubernetes Prow Robot 119a085a55
Merge pull request #44086 from sftim/20231125_link_to_decrypt_task
Link to existing task about decrypting at rest
2023-12-14 09:32:58 +01:00
Kubernetes Prow Robot 674448db34
Merge pull request #44349 from tengqm/configapi-1.29
Config API for v1.29
2023-12-14 09:12:39 +01:00
Kubernetes Prow Robot 98dcbddc6b
Merge pull request #44322 from adityasamant25/issue-44321
Add user guidance comment for executing drain and uncordon on control plane
2023-12-14 03:29:00 +01:00
Qiming Teng 2fe79a7c28 Update references to the config APIs 2023-12-14 09:24:12 +08:00
Aditya Samant 3a13717a34 Issue 44321 - added comments to emphasize that the drain and uncordon commands must be executed on a control plane node.
Apply suggestions from code review

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>
2023-12-13 16:52:08 +05:30
Tim Bannister e57cf329a6 Merge 'dev-1.29' with main 2023-12-11 17:11:37 +00:00
Kubernetes Prow Robot 0c5cb411ea
Merge pull request #43871 from neolit123/1.29-add-task-for-kubeadm-generate-csr
kubeadm: add section on how to use the "generate-csr" command
2023-12-11 17:39:47 +01:00
Aditya Samant 8a0a983d32 Changes to reflect the deprecation of pod-manifest-path argument
Changes to reflect the deprecation of pod-manifest-path argument

Update content/en/docs/tasks/configure-pod-container/static-pod.md

Review comments implemented.

Co-authored-by: Dipesh Rawat <rawat.dipesh@gmail.com>

Review comments implemented.
2023-12-10 08:25:11 +05:30
Tim Bannister 0f9c965105 Merge branch 'main' into dev-1.29 2023-12-09 20:20:23 +00:00
Kubernetes Prow Robot db823732b5
Merge pull request #43668 from pegasas/stringdata
Document snag with Secrets, stringData, and server-side apply
2023-12-08 03:31:14 +01:00
Tim Bannister 7e75688d69 Improve tutorials for Job
Co-authored-by: Kundan Kumar <kundan.kumar@india.nec.com>
2023-12-07 19:49:24 +00:00
Kat Cosgrove 45fb394ca7
Merge main into dev-1.29 to maintain sync 2023-12-07 15:59:56 +00:00
Kubernetes Prow Robot 636d7fee9b
Merge pull request #44153 from Rajdeep1311/patch-1
Minor text changes to the index of tasks/debug/debug-cluster
2023-12-07 14:22:36 +01:00
Kubernetes Prow Robot 5e5e9fc252
Merge pull request #44170 from hunshcn/sysctl
update safe sysctls
2023-12-07 14:15:01 +01:00
Kubernetes Prow Robot 08108c79cc
Merge pull request #44075 from tamilselvan1102/k8s-doc-web-20231124-1
Fix broken Telepresence link in the debugging guide
2023-12-05 01:31:39 +01:00
Kubernetes Prow Robot 4506d77590
Merge pull request #44162 from my-git9/verify-kubectl-en1
improve format for included/verify-kubectl.md
2023-12-05 01:29:11 +01:00
steve-hardman 7b2723fba7
FIx the remove step
Co-authored-by: Dipesh Rawat <rawat.dipesh@gmail.com>
2023-12-03 19:17:24 +00:00
hunshcn bb2cb5fa86
update sysctl-cluster.md, pod-security-standards.md
Signed-off-by: hunshcn <hunsh.cn@gmail.com>
2023-12-01 14:47:36 +08:00
Dipesh Rawat b91eca6be2
Fix rendering issue in tab layout 2023-12-01 01:20:33 +00:00
xin.li 5acc639bef improve format for included/verify-kubectl.md
Signed-off-by: xin.li <xin.li@daocloud.io>
2023-11-30 22:36:41 +08:00
Denis GERMAIN 812e0f8b85 Add details in kubeadm-reconfigure.md for etcd
The kubeadm init phase doesn't permit to reconfigure the etcd yaml manifest (when etcd is in local mode)
Adding the right command when etcd needs to be reconfigured

Co-authored-by: Lubomir I. Ivanov <neolit123@gmail.com>
2023-11-30 14:08:05 +01:00
Rajdeep Pal df789a5e48
Update _index.md 2023-11-30 12:48:49 +05:30
drewhagen deaf1b920a Merge remote-tracking branch 'upstream/main' into dev-1.29 2023-11-29 15:33:49 -06:00
Suruchi Kumari 1efeb86821
Update verify-kubectl.md 2023-11-29 21:43:11 +05:30
Suruchi Kumari 708220bb13
Update content
Co-authored-by: Tim Bannister <tim@scalefactory.com>
2023-11-29 19:40:47 +05:30
Suruchi Kumari c0a72d25d8
added doc for setting up cloud provider kubectl auth via plugin
Signed-off-by: GitHub <noreply@github.com>
2023-11-29 13:26:04 +00:00
Antonio Ojea dff94b84bc KEP-1880 Multiple ServiceCIDR 2023-11-29 00:19:38 +00:00
Suruchi Kumari f10369c1f5
changes done as per reviews
Signed-off-by: GitHub <noreply@github.com>
2023-11-28 05:58:17 +00:00
steve-hardman d0f79ad397
Fix the remove step
Co-authored-by: Dipesh Rawat <rawat.dipesh@gmail.com>
2023-11-27 17:59:34 +00:00
Kubernetes Prow Robot fdcd1f6a49
Merge pull request #43560 from alexzielenski/4008-beta
KEP-4008: CRD Validation Ratcheting - Alpha 2 Docs
2023-11-27 18:23:40 +01:00
Alex Zielenski 6f44e15b56 typo fix 2023-11-27 09:17:40 -08:00
Alex Zielenski 41e0c2f21b jpbetz feedback 2023-11-27 09:08:09 -08:00
Suruchi Kumari 02aa31cc33
changes
Signed-off-by: GitHub <noreply@github.com>
2023-11-27 15:24:26 +00:00
Suruchi Kumari 70e2beb2f5
added note for redirect of http probe
Signed-off-by: GitHub <noreply@github.com>
2023-11-27 05:53:41 +00:00