Production-Grade Container Scheduling and Management
Go to file
Antonio Ojea 933bcc123b only drop invalid cstate packets if non liberal
Conntrack invalid packets may cause unexpected and subtle bugs
on esblished connections, because of that we install by default an
iptables rules that drops the packets with this conntrack state.

However, there are network scenarios, specially those that use multihoming
nodes, that may have legit traffic that is detected by conntrack as
invalid, hence these iptables rules are causing problems dropping this
traffic.

An alternative to solve the spurious problems caused by the invalid
connectrack packets is to set the sysctl nf_conntrack_tcp_be_liberal
option, but this is a system wide setting and we don't want kube-proxy
to be opinionated about the whole node networking configuration.

Kube-proxy will only install the DROP rules for invalid conntrack states
if the nf_conntrack_tcp_be_liberal is not set.

Change-Id: I5eb326931ed915f5ae74d210f0a375842b6a790e
2023-09-05 14:16:17 +00:00
.github
api apf: remove v1alpha1 API 2023-08-30 20:48:42 +08:00
build Update distroless-iptables image version to v0.3.1 2023-09-01 13:10:15 +02:00
CHANGELOG CHANGELOG: Update directory for v1.28.1 release 2023-08-24 13:41:18 +00:00
cluster Set external credential provider to true by default in kube-up.sh 2023-09-03 15:39:53 -04:00
cmd Merge pull request #120381 from my-git9/dnsut1 2023-09-03 20:21:47 -07:00
docs
hack Add unwanted cloud deps to track 2023-09-01 08:58:21 -04:00
LICENSES New repo who dis? distribution/reference 2023-08-31 21:53:40 -04:00
logo
pkg only drop invalid cstate packets if non liberal 2023-09-05 14:16:17 +00:00
plugin api: introduce separate VolumeResourceRequirements struct 2023-08-21 15:31:28 +02:00
staging Merge pull request #120119 from Ithrael/fix/kubectl-events-doesnt-filter-events-by-GroupVersion-for-resource-with-full-name 2023-09-04 06:45:48 -07:00
test Merge pull request #120119 from Ithrael/fix/kubectl-events-doesnt-filter-events-by-GroupVersion-for-resource-with-full-name 2023-09-04 06:45:48 -07:00
third_party verify: nicer failure message rendering in Prow 2023-06-02 15:39:27 +02:00
vendor Merge pull request #120316 from dims/move-to-new-repo-for-reference 2023-09-02 21:05:11 -07:00
.generated_files
.gitattributes
.gitignore Add go.work and go.work.sum to .gitignore 2023-05-05 11:16:23 -04:00
.go-version [go] Bump images, versions and deps to use Go 1.20.7 2023-08-07 13:25:59 -06:00
CHANGELOG.md
code-of-conduct.md
CONTRIBUTING.md
go.mod New repo who dis? distribution/reference 2023-08-31 21:53:40 -04:00
go.sum New repo who dis? distribution/reference 2023-08-31 21:53:40 -04:00
LICENSE
Makefile
OWNERS
OWNERS_ALIASES Prune sig-auth-encryption-at-rest-reviewers and drop lavalamp across aliases 2023-08-29 09:02:08 -04:00
README.md Merge pull request #116709 from R3DRUN3/master 2023-05-03 12:02:09 -07:00
SECURITY_CONTACTS
SUPPORT.md

Kubernetes (K8s)

CII Best Practices Go Report Card GitHub release (latest SemVer)


Kubernetes, also known as K8s, is an open source system for managing containerized applications across multiple hosts. It provides basic mechanisms for the deployment, maintenance, and scaling of applications.

Kubernetes builds upon a decade and a half of experience at Google running production workloads at scale using a system called Borg, combined with best-of-breed ideas and practices from the community.

Kubernetes is hosted by the Cloud Native Computing Foundation (CNCF). If your company wants to help shape the evolution of technologies that are container-packaged, dynamically scheduled, and microservices-oriented, consider joining the CNCF. For details about who's involved and how Kubernetes plays a role, read the CNCF announcement.


To start using K8s

See our documentation on kubernetes.io.

Take a free course on Scalable Microservices with Kubernetes.

To use Kubernetes code as a library in other applications, see the list of published components. Use of the k8s.io/kubernetes module or k8s.io/kubernetes/... packages as libraries is not supported.

To start developing K8s

The community repository hosts all information about building Kubernetes from source, how to contribute code and documentation, who to contact about what, etc.

If you want to build Kubernetes right away there are two options:

You have a working Go environment.
mkdir -p $GOPATH/src/k8s.io
cd $GOPATH/src/k8s.io
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
make
You have a working Docker environment.
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
make quick-release

For the full story, head over to the developer's documentation.

Support

If you need support, start with the troubleshooting guide, and work your way through the process that we've outlined.

That said, if you have questions, reach out to us one way or another.

Community Meetings

The Calendar has the list of all the meetings in the Kubernetes community in a single location.

Adopters

The User Case Studies website has real-world use cases of organizations across industries that are deploying/migrating to Kubernetes.

Governance

Kubernetes project is governed by a framework of principles, values, policies and processes to help our community and constituents towards our shared goals.

The Kubernetes Community is the launching point for learning about how we organize ourselves.

The Kubernetes Steering community repo is used by the Kubernetes Steering Committee, which oversees governance of the Kubernetes project.

Roadmap

The Kubernetes Enhancements repo provides information about Kubernetes releases, as well as feature tracking and backlogs.