kubernetes/cluster/addons
Kubernetes Submit Queue c0a3d26746 Merge pull request #46750 from cjcullen/grabbag
Automatic merge from submit-queue

Remove e2e-rbac-bindings.

Replace todo-grabbag binding w/ more specific heapster roles/bindings.
Move kubelet binding.

**What this PR does / why we need it**:
The "e2e-rbac-bindings" held 2 leftovers from the 1.6 RBAC rollout process:
 - One is the "kubelet-binding" which grants the "system:node" role to kubelet. This is needed until we enable the node authorizer. I moved this to the folder w/ some other kubelet related bindings.
 - The other is the "todo-remove-grabbag-cluster-admin" binding, which grants the cluster-admin role to the default service account in the kube-system namespace. This appears to only be required for heapster. Heapster will instead use a "heapster" service account, bound to a "system:heapster" role on the cluster (no write perms), and a "system:pod-nanny" role in the kube-system namespace.

**Which issue this PR fixes**: Addresses part of #39990

**Release Note**: 
```release-note
New and upgraded 1.7 GCE/GKE clusters no longer have an RBAC ClusterRoleBinding that grants the `cluster-admin` ClusterRole to the `default` service account in the `kube-system` namespace.
If this permission is still desired, run the following command to explicitly grant it, either before or after upgrading to 1.7:
    kubectl create clusterrolebinding kube-system-default --serviceaccount=kube-system:default --clusterrole=cluster-admin
```
2017-06-09 13:06:30 -07:00
..
addon-manager Merge pull request #42668 from ixdy/build-silence-docker-rmi 2017-03-30 23:36:24 -07:00
calico-policy-controller Move tolerations to PodSpec for calico-node.yaml. 2017-06-01 09:57:03 +08:00
cluster-loadbalancing Update docs/ URLs to point to proper locations 2017-06-05 22:13:54 -07:00
cluster-monitoring Replace todo-grabbag binding w/ more specific heapster roles/bindings. 2017-06-06 09:03:09 -07:00
dashboard Update dashboard-controller.yaml 2017-05-17 14:12:12 +02:00
dns Update kube-dns version to 1.14.2 2017-05-11 12:29:00 -07:00
dns-horizontal-autoscaler Bump cluster-proportional-autoscaler to 1.1.2 2017-06-01 14:23:43 -07:00
etcd-empty-dir-cleanup Bump etcd-empty-dir-cleanup to 3.0.14.0 2017-02-22 13:22:04 -08:00
fluentd-elasticsearch Update fluentd-es-ds.yaml 2017-05-29 19:09:57 +02:00
fluentd-gcp Merge pull request #46787 from crassirostris/fluentd-gcp-update 2017-06-06 01:53:40 -07:00
ip-masq-agent Merge pull request #46782 from dnardo/ip-masq-agent 2017-06-03 12:28:27 -07:00
metadata-proxy Adding a metadata proxy addon to gce 2017-05-31 16:23:11 -07:00
node-problem-detector Bump up npd version to v0.4.0 2017-06-06 16:30:02 -07:00
podsecuritypolicies default policy 2016-05-11 18:07:36 -04:00
python-image Always --pull in docker build to ensure recent base images 2017-01-10 16:21:05 -08:00
rbac Replace todo-grabbag binding w/ more specific heapster roles/bindings. 2017-06-06 09:03:09 -07:00
registry Update docs/ URLs to point to proper locations 2017-06-05 22:13:54 -07:00
storage-class Support running StatefulSetBasic e2e tests with local-up-cluster 2017-04-28 15:10:22 -04:00
BUILD Replace git_repository with http_archive and use ixdy's fork of bazel tools for pkg_tar 2017-05-03 10:13:06 -07:00
README.md Updates READMEs regarding the new behavior of addon-manager 2017-02-24 16:42:41 -08:00

Cluster add-ons

Overview

Cluster add-ons are resources like Services and Deployments (with pods) that are shipped with the Kubernetes binaries and are considered an inherent part of the Kubernetes clusters.

There are currently two classes of add-ons:

  • Add-ons that will be reconciled.
  • Add-ons that will be created if they don't exist.

More details could be found in addon-manager/README.md.

Cooperating Horizontal / Vertical Auto-Scaling with "reconcile class addons"

"Reconcile" class addons will be periodically reconciled to the original state given by the initial config. In order to make Horizontal / Vertical Auto-scaling functional, the related fields in config should be left unset. More specifically, leave replicas in ReplicationController / Deployment / ReplicaSet unset for Horizontal Scaling, leave resources for container unset for Vertical Scaling. The periodic reconcile won't clobbered these fields, hence they could be managed by Horizontal / Vertical Auto-scaler.

Add-on naming

The suggested naming for most of the resources is <basename> (with no version number). Though resources like Pod, ReplicationController and DaemonSet are exceptional. It would be hard to update Pod because many fields in Pod are immutable. For ReplicationController and DaemonSet, in-place update may not trigger the underlying pods to be re-created. You probably need to change their names during update to trigger a complete deletion and creation.

Analytics