mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-29 14:37:00 +00:00
Update ports doc.
Fix.
This commit is contained in:
parent
6ff9e98fee
commit
629d6657fb
@ -50,14 +50,16 @@ variety of uses cases:
|
|||||||
operations on the apiserver. Currently, these have to run on the same
|
operations on the apiserver. Currently, these have to run on the same
|
||||||
host as the apiserver and use the Localhost Port.
|
host as the apiserver and use the Localhost Port.
|
||||||
4. Kubelets, which need to do read-write API operations and are necessarily
|
4. Kubelets, which need to do read-write API operations and are necessarily
|
||||||
on different machines than the apiserver. Currently, kubelets do not
|
on different machines than the apiserver. Kubelet uses the Secure Port
|
||||||
use the API.
|
to get their pods, to find the services that a pod can see, and to
|
||||||
|
write events. Credentials are distributed to kubelets at cluster
|
||||||
|
setup time.
|
||||||
|
|
||||||
## Expected Changes.
|
## Expected changes
|
||||||
The following changes to what is decribed above are planned:
|
- Policy will limit the actions kubelets can do via the authed port.
|
||||||
- Kubelets will soon begin using the Secure Port to get their pods and
|
- Kube-proxy currently uses the readonly port to read services and endpoints,
|
||||||
report events. Credentials will be distributed to kubelets at cluster
|
but will eventually use the auth port.
|
||||||
setup time initially. Policy will limit the actions kubelets can do.
|
- Kubelets may change from token-based authentication to cert-based-auth.
|
||||||
- Scheduler and Controller-manager will use the Secure Port too. They
|
- Scheduler and Controller-manager will use the Secure Port too. They
|
||||||
will then be able to run on different machines than the apiserver.
|
will then be able to run on different machines than the apiserver.
|
||||||
- A general mechanism will be provided for [giving credentials to
|
- A general mechanism will be provided for [giving credentials to
|
||||||
|
Loading…
Reference in New Issue
Block a user