Production-Grade Container Scheduling and Management
Go to file
Kubernetes Submit Queue 61892abc94
Merge pull request #62874 from dcbw/dockershim-SetUpPod-cleanup-on-failure
Automatic merge from submit-queue. If you want to cherry-pick this change to another branch, please follow the instructions <a href="https://github.com/kubernetes/community/blob/master/contributors/devel/cherry-picks.md">here</a>.

dockershim/sandbox: clean up pod network even if SetUpPod() failed

If the CNI network plugin completes successfully, but something fails
between that success and dockerhsim's sandbox setup code, plugin resources
may not be cleaned up. A non-trivial amount of code runs after the
plugin itself exits and the CNI driver's SetUpPod() returns, and any error
condition recognized by that code would cause this leakage.

The Kubernetes CRI RunPodSandbox() request does not attempt to clean
up on errors, since it cannot know how much (if any) networking
was actually set up. It depends on the CRI implementation to do
that cleanup for it.

In the dockershim case, a SetUpPod() failure means networkReady is
FALSE for the sandbox, and TearDownPod() will not be called later by
garbage collection even though networking was configured, because
dockershim can't know how far SetUpPod() got.

Concrete examples include if the sandbox's container is somehow
removed during during that time, or another OS error is encountered,
or the plugin returns a malformed result to the CNI driver.

Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1532965

```release-note
NONE
```
2018-04-24 21:48:01 -07:00
.github Link to vulnerabilitiy disclosure process from the issue template 2018-04-17 10:39:24 -07:00
api Merge pull request #62002 from k82cn/k8s_61410_1 2018-04-23 22:45:28 -07:00
build Remove examples directory 2018-04-24 19:45:43 +01:00
cluster Merge pull request #63074 from shyamjvs/fix-ip-alias-bug 2018-04-24 15:16:19 -07:00
cmd Merge pull request #62284 from DirectXMan12/bug/fix-use-rest-clients-help-line 2018-04-24 19:01:23 -07:00
docs Merge pull request #62002 from k82cn/k8s_61410_1 2018-04-23 22:45:28 -07:00
Godeps Update github.com/stretchr/testify to v1.2.1 2018-04-19 10:00:31 -04:00
hack Remove examples directory 2018-04-24 19:45:43 +01:00
logo
pkg Merge pull request #62874 from dcbw/dockershim-SetUpPod-cleanup-on-failure 2018-04-24 21:48:01 -07:00
plugin Merge pull request #62818 from mikedanese/selfdelete 2018-04-24 14:22:13 -07:00
staging Merge pull request #63084 from mikedanese/ctx 2018-04-24 19:01:17 -07:00
test Merge pull request #63010 from deads2k/api-04-metadataaccessor 2018-04-24 17:59:12 -07:00
third_party kazel: skip third_party/etcd.* 2018-04-11 16:46:36 -07:00
translations Merge pull request #61817 from xuhuilong/master 2018-04-11 10:41:24 -07:00
vendor Update github.com/stretchr/testify to v1.2.1 2018-04-19 10:00:31 -04:00
.bazelrc
.generated_files
.gitattributes
.gitignore
.kazelcfg.json
BUILD.bazel
CHANGELOG-1.2.md
CHANGELOG-1.3.md
CHANGELOG-1.4.md
CHANGELOG-1.5.md
CHANGELOG-1.6.md
CHANGELOG-1.7.md Update CHANGELOG-1.7.md for v1.7.16. 2018-04-04 13:07:30 +00:00
CHANGELOG-1.8.md Update CHANGELOG-1.8.md for v1.8.12. 2018-04-23 21:14:13 -07:00
CHANGELOG-1.9.md Update CHANGELOG-1.9.md for v1.9.7. 2018-04-19 12:19:02 -04:00
CHANGELOG-1.10.md Merge pull request #61891 from zhangxiaoyu-zidif/patch-9 2018-04-22 08:08:40 -07:00
CHANGELOG-1.11.md Add CHANGELOG-1.11.md for v1.11.0-alpha.1. 2018-04-19 20:10:59 +00:00
CHANGELOG.md Marks 1.10 as the current release 2018-03-26 17:08:54 -07:00
code-of-conduct.md
CONTRIBUTING.md
labels.yaml
LICENSE
Makefile
Makefile.generated_files
OWNERS root OWNERS: escape backslashes 2018-04-13 10:42:22 -07:00
OWNERS_ALIASES Merge pull request #62281 from juanvallejo/jvallejo/sig-cli-reviewers 2018-04-09 16:00:11 -07:00
README.md
SUPPORT.md
WORKSPACE

Kubernetes

Submit Queue Widget GoDoc Widget CII Best Practices


Kubernetes is an open source system for managing containerized applications across multiple hosts; providing basic mechanisms for deployment, maintenance, and scaling of applications.

Kubernetes builds upon a decade and a half of experience at Google running production workloads at scale using a system called Borg, combined with best-of-breed ideas and practices from the community.

Kubernetes is hosted by the Cloud Native Computing Foundation (CNCF). If you are a company that wants to help shape the evolution of technologies that are container-packaged, dynamically-scheduled and microservices-oriented, consider joining the CNCF. For details about who's involved and how Kubernetes plays a role, read the CNCF announcement.


To start using Kubernetes

See our documentation on kubernetes.io.

Try our interactive tutorial.

Take a free course on Scalable Microservices with Kubernetes.

To start developing Kubernetes

The community repository hosts all information about building Kubernetes from source, how to contribute code and documentation, who to contact about what, etc.

If you want to build Kubernetes right away there are two options:

You have a working Go environment.
$ go get -d k8s.io/kubernetes
$ cd $GOPATH/src/k8s.io/kubernetes
$ make
You have a working Docker environment.
$ git clone https://github.com/kubernetes/kubernetes
$ cd kubernetes
$ make quick-release

For the full story, head over to the developer's documentation.

Support

If you need support, start with the troubleshooting guide, and work your way through the process that we've outlined.

That said, if you have questions, reach out to us one way or another.

Analytics