Production-Grade Container Scheduling and Management
Go to file
Mitsuru Kariya 20cecaee97
Add Watch to controller roles (#130405)
* Add Watch to controller roles

Starting from version 1.32, the client feature `WatchListClient` has been
set to `true` in `kube-controller-manager`.
(commit 06a15c5cf9)

As a result, when the `kube-controller-manager` executes the `List` method,
it utilizes `Watch`. However, there are some existing controller roles that
include `List` but do not include `Watch`. Therefore, when processes using
these controller roles execute the `List` method, `Watch` is executed first,
but due to permission errors, it falls back to `List`.

This PR adds `Watch` to the controller roles that include `List` but do not
include `Watch`.

The affected roles are as follows (prefixed with `system:controller:`):

- `cronjob-controller`
- `endpoint-controller`
- `endpointslice-controller`
- `endpointslicemirroring-controller`
- `horizontal-pod-autoscaler`
- `node-controller`
- `pod-garbage-collector`
- `storage-version-migrator-controller`

Signed-off-by: Mitsuru Kariya <mitsuru.kariya@nttdata.com>

* Fix Fixture Data

I apologize, the Fixture Data modifications were missed.

Signed-off-by: Mitsuru Kariya <mitsuru.kariya@nttdata.com>

* Add ControllerRoles Test

Added a test to check that if a controller role includes `List`, it also includes `Watch`.

Signed-off-by: Mitsuru Kariya <mitsuru.kariya@nttdata.com>

* Fix typo

Co-authored-by: Jordan Liggitt <jordan@liggitt.net>

* Add Additional Tests

Added tests to check that if NodeRules, ClusterRoles, and NamespaceRoles
include `List`, it also include `Watch`.

Signed-off-by: Mitsuru Kariya <mitsuru.kariya@nttdata.com>

---------

Signed-off-by: Mitsuru Kariya <mitsuru.kariya@nttdata.com>
Co-authored-by: Jordan Liggitt <jordan@liggitt.net>
2025-02-26 08:24:38 -08:00
.github
api Merge pull request #130298 from thockin/max_of_of 2025-02-20 15:00:34 -08:00
build Bump etcd v3.6.0-rc.1 image 2025-02-25 19:46:33 +00:00
CHANGELOG CHANGELOG: Update directory for v1.33.0-alpha.2 release 2025-02-18 18:58:13 +00:00
cluster Bump etcd v3.6.0-rc.1 image 2025-02-25 19:46:33 +00:00
cmd Merge pull request #130325 from pohly/test-integration-apiserver-defaults 2025-02-25 11:08:30 -08:00
docs
hack Merge pull request #130359 from my-git9/assertion1 2025-02-24 05:18:34 -08:00
LICENSES update github.com/coreos/go-oidc to v2.3.0 2025-01-22 15:27:54 -05:00
logo
pkg Merge pull request #129905 from ania-borowiec/129778_replace_equal 2025-02-26 08:24:30 -08:00
plugin Add Watch to controller roles (#130405) 2025-02-26 08:24:38 -08:00
staging Merge pull request #130443 from serathius/watchcache-limit 2025-02-26 05:12:30 -08:00
test Merge pull request #130325 from pohly/test-integration-apiserver-defaults 2025-02-25 11:08:30 -08:00
third_party Revert "tests: include stdout of failed commands in JUnit" 2025-01-22 23:36:50 +01:00
vendor Merge pull request #130118 from lucasrattz/update-anp 2025-02-24 07:26:28 -08:00
.generated_files
.gitattributes
.gitignore
.go-version Bump images, dependencies and versions to go 1.23.6 and distroless iptables 2025-02-10 14:04:37 -06:00
CHANGELOG.md
code-of-conduct.md
CONTRIBUTING.md
go.mod Merge pull request #130118 from lucasrattz/update-anp 2025-02-24 07:26:28 -08:00
go.sum Merge pull request #130118 from lucasrattz/update-anp 2025-02-24 07:26:28 -08:00
go.work Drop winsymlink go 1.23 workaround 2025-02-21 18:02:28 -05:00
go.work.sum Update to latest kustomize/v5.6.0 2025-01-14 13:12:48 -05:00
LICENSE
Makefile
OWNERS
OWNERS_ALIASES update sig cl owners in k/k 2025-02-12 11:04:11 +02:00
README.md
SECURITY_CONTACTS
SUPPORT.md

Kubernetes (K8s)

CII Best Practices Go Report Card GitHub release (latest SemVer)


Kubernetes, also known as K8s, is an open source system for managing containerized applications across multiple hosts. It provides basic mechanisms for the deployment, maintenance, and scaling of applications.

Kubernetes builds upon a decade and a half of experience at Google running production workloads at scale using a system called Borg, combined with best-of-breed ideas and practices from the community.

Kubernetes is hosted by the Cloud Native Computing Foundation (CNCF). If your company wants to help shape the evolution of technologies that are container-packaged, dynamically scheduled, and microservices-oriented, consider joining the CNCF. For details about who's involved and how Kubernetes plays a role, read the CNCF announcement.


To start using K8s

See our documentation on kubernetes.io.

Take a free course on Scalable Microservices with Kubernetes.

To use Kubernetes code as a library in other applications, see the list of published components. Use of the k8s.io/kubernetes module or k8s.io/kubernetes/... packages as libraries is not supported.

To start developing K8s

The community repository hosts all information about building Kubernetes from source, how to contribute code and documentation, who to contact about what, etc.

If you want to build Kubernetes right away there are two options:

You have a working Go environment.
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
make
You have a working Docker environment.
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
make quick-release

For the full story, head over to the developer's documentation.

Support

If you need support, start with the troubleshooting guide, and work your way through the process that we've outlined.

That said, if you have questions, reach out to us one way or another.

Community Meetings

The Calendar has the list of all the meetings in the Kubernetes community in a single location.

Adopters

The User Case Studies website has real-world use cases of organizations across industries that are deploying/migrating to Kubernetes.

Governance

Kubernetes project is governed by a framework of principles, values, policies and processes to help our community and constituents towards our shared goals.

The Kubernetes Community is the launching point for learning about how we organize ourselves.

The Kubernetes Steering community repo is used by the Kubernetes Steering Committee, which oversees governance of the Kubernetes project.

Roadmap

The Kubernetes Enhancements repo provides information about Kubernetes releases, as well as feature tracking and backlogs.