Production-Grade Container Scheduling and Management
Go to file
Kubernetes Submit Queue 06472a054a
Merge pull request #58930 from smarterclayton/background_rotate
Automatic merge from submit-queue. If you want to cherry-pick this change to another branch, please follow the instructions <a href="https://github.com/kubernetes/community/blob/master/contributors/devel/cherry-picks.md">here</a>.

Only rotate certificates in the background

Change the Kubelet to not block until the first certs have rotated (we didn't act on it anyway) and fall back to the bootstrap cert if the most recent rotated cert is expired on startup.

The certificate manager originally had a "block on startup" rotation behavior to ensure at least one rotation happened on startup. However, since rotation may not succeed within the first time window the code was changed to simply print the error rather than return it. This meant that the blocking rotation has no purpose - it cannot cause the kubelet to fail, and it *does* block the kubelet from starting static pods before the api server becomes available.

The current block behavior causes a bootstrapped kubelet that is also set to run static pods to wait several minutes before actually launching the static pods, which means self-hosted masters using static pods have a pointless delay on startup.

Since blocking rotation has no benefit and can't actually fail startup, this commit removes the blocking behavior and simplifies the code at the same time. The goroutine for rotation now completely owns the deadline, the shouldRotate() method is removed, and the method that sets rotationDeadline now returns it. We also explicitly guard against a negative sleep interval and omit the message.

Should have no impact on bootstrapping except the removal of a long delay on startup before static pods start.

The other change is that an expired certificate from the cert manager is *not* considered a valid cert, which triggers an immediate rotation.  This causes the cert manager to fall back to the original bootstrap certificate until a new certificate is issued.  This allows the bootstrap certificate on masters to be "higher powered" and allow the node to function prior to initial approval, which means someone configuring the masters with a pre-generated client cert can be guaranteed that the kubelet will be able to communicate to report self-hosted static pod status, even if the first client rotation hasn't happened.  This makes master self-hosting more predictable for static configuration environments.

```release-note
When using client or server certificate rotation, the Kubelet will no longer wait until the initial rotation succeeds or fails before starting static pods.  This makes running self-hosted masters with rotation more predictable.
```
2018-02-01 12:05:15 -08:00
.github Merge pull request #54114 from xiangpengzhao/fix-pr-template 2017-10-30 18:37:06 -07:00
api Merge pull request #57938 from dims/add-binary-configmap 2018-01-26 04:34:33 -08:00
build Merge pull request #59012 from ixdy/update-to-go1.9.3 2018-01-30 00:01:32 -08:00
cluster Merge pull request #59116 from hyperbolic2346/mwilson/priv-typo-fix 2018-02-01 07:04:37 -08:00
cmd Merge pull request #59099 from karataliu/credflag 2018-02-01 10:43:35 -08:00
docs Merge pull request #57938 from dims/add-binary-configmap 2018-01-26 04:34:33 -08:00
examples Remove apiVersion from scheduler extender example configuration 2018-01-18 14:41:53 -08:00
Godeps godep: vendor gopkg.in/square/go-jose.v2/jwt 2018-01-23 14:47:25 -08:00
hack Merge pull request #58728 from dashpole/cadvisor_testing 2018-02-01 07:04:40 -08:00
logo Don't use strokes in the logo SVG 2017-10-12 09:38:56 -07:00
pkg Merge pull request #58930 from smarterclayton/background_rotate 2018-02-01 12:05:15 -08:00
plugin Merge pull request #58485 from k82cn/k8s_58471 2018-01-26 12:23:00 -08:00
staging Merge pull request #58930 from smarterclayton/background_rotate 2018-02-01 12:05:15 -08:00
test Merge pull request #58728 from dashpole/cadvisor_testing 2018-02-01 07:04:40 -08:00
third_party Add brackets and quotes where needed 2018-01-26 15:11:53 -08:00
translations Generate bindata.go and k8s.mo 2018-01-20 01:56:49 +00:00
vendor godep: vendor gopkg.in/square/go-jose.v2/jwt 2018-01-23 14:47:25 -08:00
.bazelrc move build related files out of the root directory 2017-05-15 15:53:54 -07:00
.generated_files
.gitattributes Hide generated files only on github 2018-01-22 10:58:48 +01:00
.gitignore make clean will remove all gitignored files 2017-09-04 11:04:09 -07:00
.kazelcfg.json Switch from gazel to kazel, and move kazelcfg into build/root 2017-07-18 12:48:51 -07:00
BUILD.bazel move build related files out of the root directory 2017-05-15 15:53:54 -07:00
CHANGELOG-1.2.md Update TOC of CHANGELOG 2017-09-09 13:38:29 +08:00
CHANGELOG-1.3.md Move 1.3.* release notes out of CHANGELOG.md 2017-09-15 11:21:25 +08:00
CHANGELOG-1.4.md Revert k8s.gcr.io vanity domain 2017-12-22 14:36:16 -08:00
CHANGELOG-1.5.md Revert k8s.gcr.io vanity domain 2017-12-22 14:36:16 -08:00
CHANGELOG-1.6.md Revert k8s.gcr.io vanity domain 2017-12-22 14:36:16 -08:00
CHANGELOG-1.7.md Update CHANGELOG-1.7.md for v1.7.12. 2017-12-29 13:42:49 +01:00
CHANGELOG-1.8.md CHANGELOG: feature flag is "AdvancedAuditing" not "AdvancedAudit" 2018-01-18 14:19:39 -08:00
CHANGELOG-1.9.md Update CHANGELOG-1.9.md for v1.9.2. 2018-01-18 13:46:38 -06:00
CHANGELOG-1.10.md Update CHANGELOG-1.10.md for v1.10.0-alpha.2. 2018-01-26 14:24:30 -05:00
CHANGELOG.md Update release note links for 1.10 2018-01-17 22:45:12 +01:00
code-of-conduct.md Update code-of-conduct.md 2017-12-20 13:33:36 -05:00
CONTRIBUTING.md Pointed to community/contributors/guide/README.md 2017-12-15 22:08:34 +05:30
labels.yaml Merge pull request #51848 from xiangpengzhao/milestone-label 2017-09-05 15:46:19 -07:00
LICENSE
Makefile move build related files out of the root directory 2017-05-15 15:53:54 -07:00
Makefile.generated_files move build related files out of the root directory 2017-05-15 15:53:54 -07:00
OWNERS Fix my incorrect username in #46649 2017-08-10 11:59:54 -07:00
OWNERS_ALIASES fabiano no longer a thing 2017-12-19 16:37:12 -02:00
README.md Update README.md with punctuation improvements 2018-01-23 10:16:37 -06:00
SUPPORT.md Add a SUPPORT.md file for github 2017-08-11 14:42:36 -04:00
WORKSPACE move build related files out of the root directory 2017-05-15 15:53:54 -07:00

Kubernetes

Submit Queue Widget GoDoc Widget CII Best Practices


Kubernetes is an open source system for managing containerized applications across multiple hosts; providing basic mechanisms for deployment, maintenance, and scaling of applications.

Kubernetes builds upon a decade and a half of experience at Google running production workloads at scale using a system called Borg, combined with best-of-breed ideas and practices from the community.

Kubernetes is hosted by the Cloud Native Computing Foundation (CNCF). If you are a company that wants to help shape the evolution of technologies that are container-packaged, dynamically-scheduled and microservices-oriented, consider joining the CNCF. For details about who's involved and how Kubernetes plays a role, read the CNCF announcement.


To start using Kubernetes

See our documentation on kubernetes.io.

Try our interactive tutorial.

Take a free course on Scalable Microservices with Kubernetes.

To start developing Kubernetes

The community repository hosts all information about building Kubernetes from source, how to contribute code and documentation, who to contact about what, etc.

If you want to build Kubernetes right away there are two options:

You have a working Go environment.
$ go get -d k8s.io/kubernetes
$ cd $GOPATH/src/k8s.io/kubernetes
$ make
You have a working Docker environment.
$ git clone https://github.com/kubernetes/kubernetes
$ cd kubernetes
$ make quick-release

For the full story, head over to the developer's documentation.

Support

If you need support, start with the troubleshooting guide, and work your way through the process that we've outlined.

That said, if you have questions, reach out to us one way or another.

Analytics