Files
kubernetes/federation
Kubernetes Submit Queue c46bc88f04 Merge pull request #31491 from dims/fixes-issue-13598
Automatic merge from submit-queue

Allow secure access to apiserver from Admission Controllers

* Allow options.InsecurePort to be set to 0 to switch off insecure access
* In NewSelfClient, Set the TLSClientConfig to the cert and key files
  if InsecurePort is switched off
* Mint a bearer token that allows the client(s) created in NewSelfClient
  to talk to the api server
* Add a new authenticator that checks for this specific bearer token

Fixes #13598
2016-09-21 21:31:56 -07:00
..
2016-09-19 09:57:19 -04:00
2016-09-14 11:27:29 +02:00
2016-09-21 15:49:38 -07:00
2016-06-27 13:16:43 -07:00
2016-08-29 10:49:20 -07:00

Cluster Federation

Kubernetes Cluster Federation enables users to federate multiple Kubernetes clusters. Please see the user guide and the admin guide for more details about setting up and using the Cluster Federation.

Building Kubernetes Cluster Federation

Please see the Kubernetes Development Guide for initial setup. Once you have the development environment setup as explained in that guide, you also need to install jq

Building cluster federation artifacts should be as simple as running:

make build

You can specify the docker registry to tag the image using the KUBE_REGISTRY environment variable. Please make sure that you use the same value in all the subsequent commands.

To push the built docker images to the registry, run:

make push

To initialize the deployment run:

(This pull the installer images)

make init

To deploy the clusters and install the federation components, edit the ${KUBE_ROOT}/_output/federation/config.json file to describe your clusters and run:

make deploy

To turn down the federation components and tear down the clusters run:

make destroy

Ideas for improvement

  1. Split the build phase (make recipe) into multiple phases:

    1. init: pull installer images
    2. build-binaries
    3. build-docker
    4. build: build-binary + build-docker
    5. push: to push the built images
    6. genconfig
    7. deploy-clusters
    8. deploy-federation
    9. deploy: deploy-clusters + deploy-federation
    10. destroy-federation
    11. destroy-clusters
    12. destroy: destroy-federation + destroy-clusters
    13. redeploy-federation: just redeploys the federation components.
  2. Continue with destroy phase even in the face of errors.

    The bash script sets set -e errexit which causes the script to exit at the very first error. This should be the default mode for deploying components but not for destroying/cleanup.

Analytics