brainy-restaurant-25398
06/02/2023, 4:53 PMechoing-hair-74597
06/02/2023, 6:43 PMstraight-fountain-2279
06/03/2023, 11:00 AMimportant-mechanic-13296
06/03/2023, 12:46 PMkubectl --kubeconfig ~/.kube/user.config get nodes
Unable to connect to the server: dial tcp 10.1.2.100:443: connect: operation timed out
And then after a few more tries:
kubectl --kubeconfig ~/.kube/user.config get nodes
NAME STATUS ROLES AGE VERSION
node1 Ready control-plane 4h43m v1.25.6
node2 Ready control-plane 4h42m v1.25.6
node3 Ready control-plane 4h42m v1.25.6
delightful-dog-3772
06/03/2023, 4:10 PMmysterious-flag-18691
06/03/2023, 7:17 PMnerdctl
, but the first thing I needed to do already failed. docker import
. So this feature is not implemented?shy-exabyte-31531
06/03/2023, 9:42 PMshy-exabyte-31531
06/03/2023, 9:46 PMproud-postman-73044
06/05/2023, 3:51 AMkind-agency-73198
06/05/2023, 6:42 AMelegant-candle-74808
06/05/2023, 7:55 AMstale-pillow-58355
06/05/2023, 9:09 AMjolly-musician-25523
06/05/2023, 9:10 AMkube-reserved-cgroup
, I see node allocatable changed on each node. Is there any way to force this? So I can make sure the resource availability for kubelet
and other system services. ?
Rancher version: v2.7.3 (Installed using docker command).
apiVersion: <http://provisioning.cattle.io/v1|provisioning.cattle.io/v1>
kind: Cluster
metadata:
annotations:
<http://field.cattle.io/creatorId|field.cattle.io/creatorId>: user-8xmdj
finalizers:
- <http://wrangler.cattle.io/cloud-config-secret-remover|wrangler.cattle.io/cloud-config-secret-remover>
- <http://wrangler.cattle.io/provisioning-cluster-remove|wrangler.cattle.io/provisioning-cluster-remove>
- <http://wrangler.cattle.io/rke-cluster-remove|wrangler.cattle.io/rke-cluster-remove>
name: foo
namespace: fleet-default
uid: cf2c90a9-37c7-4290-8185-32e8c5042a4b
spec:
defaultPodSecurityAdmissionConfigurationTemplateName: rancher-restricted
kubernetesVersion: v1.25.9+rke2r1
localClusterAuthEndpoint: {}
rkeConfig:
additionalManifest: |-
---
apiVersion: <http://helm.cattle.io/v1|helm.cattle.io/v1>
kind: HelmChartConfig
metadata:
name: rke2-coredns
namespace: kube-system
spec:
valuesContent: |-
nodelocal:
enabled: true
chartValues:
rke2-canal: {}
etcd:
snapshotRetention: 5
snapshotScheduleCron: 0 */5 * * *
machineGlobalConfig:
cni: canal
disable:
- rke2-ingress-nginx
disable-kube-proxy: false
etcd-expose-metrics: false
kube-apiserver-arg:
- >-
admission-control-config-file=/etc/rancher/rke2/config/rancher-psact.yaml
- enable-admission-plugins=AlwaysPullImages
machineSelectorConfig:
- config:
kubelet-arg:
- cgroups-per-qos
- kube-reserved=cpu=200m,memory=256Mi,ephemeral-storage=5G
- kube-reserved-cgroup=runtime.slice
- system-reserved=cpu=200m,memory=256Mi,ephemeral-storage=10G
- system-reserved-cgroup=system.slice
- >-
eviction-hard=memory.available<256Mi,imagefs.available<5%,nodefs.available<5%
profile: cis-1.23
protect-kernel-defaults: true
machineSelectorFiles:
- fileSources:
- secret:
items:
- key: policy
path: /etc/rancher/rke2/audit-policy.yaml
name: foo-audit-policy
machineLabelSelector:
matchLabels:
<http://rke.cattle.io/control-plane-role|rke.cattle.io/control-plane-role>: 'true'
- fileSources:
- secret:
items:
- hash: nvQtuo8wEKrAHeiiWgF459YS45FPDtfvKh5D63okHnQ=
key: admission-config-psact
path: /etc/rancher/rke2/config/rancher-psact.yaml
name: foo-admission-configuration-psact
machineLabelSelector:
matchLabels:
<http://rke.cattle.io/control-plane-role|rke.cattle.io/control-plane-role>: 'true'
registries: {}
rotateCertificates:
generation: 1
services:
- api-server
upgradeStrategy:
controlPlaneConcurrency: '1'
controlPlaneDrainOptions:
deleteEmptyDirData: true
disableEviction: false
enabled: false
force: false
gracePeriod: -1
ignoreDaemonSets: true
ignoreErrors: false
postDrainHooks: null
preDrainHooks: null
skipWaitForDeleteTimeoutSeconds: 0
timeout: 120
workerConcurrency: '1'
workerDrainOptions:
deleteEmptyDirData: true
disableEviction: false
enabled: false
force: false
gracePeriod: -1
ignoreDaemonSets: true
ignoreErrors: false
postDrainHooks: null
preDrainHooks: null
skipWaitForDeleteTimeoutSeconds: 0
timeout: 120
boundless-wire-27557
06/05/2023, 9:24 AMgo: <http://github.com/BurntSushi/toml@v0.3.1|github.com/BurntSushi/toml@v0.3.1>: Get "https:<http://proxy.golang.org/GitHub.com/%21burnt%21sushi/toml/@v/v0.3.1mod|proxy.golang.org/GitHub.com/%21burnt%21sushi/toml/@v/v0.3.1mod>": x509 certificate signed by unknown authority.
Any help?
For reference:
which docker
/Users/myuser/.rd/bin/dockerfast-plumber-26155
06/05/2023, 11:59 AMwhite-branch-93180
06/05/2023, 12:51 PMcool-truck-28488
06/05/2023, 5:45 PMserver-url
in my rancher server, and it appears that did not update in all the places. for example, my oauth is redirecting to the wrong place.hallowed-cricket-74176
06/05/2023, 7:28 PMeager-hair-74809
06/05/2023, 9:38 PMswift-petabyte-68188
06/05/2023, 9:48 PMminiature-ambulance-98143
06/06/2023, 3:31 AMminiature-ambulance-98143
06/06/2023, 3:31 AMhigh-monitor-46613
06/06/2023, 8:27 AMpkg/mod/github.com/rancher/client-go@v1.24.0-rancher1/tools/cache/reflector.go:168: Failed to watch *v1beta1.CronJob: failed to list *v1beta1.CronJob: the server could not find the requested resource
.
Then I remembered that we upgraded to kubernets 1.26 on GCP. It seems that this API has been removed for 1.26.
Is there any possible workaround to solve this issue?freezing-hairdresser-79403
06/06/2023, 12:34 PMsquare-queen-28787
06/06/2023, 2:04 PMwhite-branch-93180
06/06/2023, 2:23 PMadorable-wolf-585
06/06/2023, 2:52 PMadorable-wolf-585
06/06/2023, 2:53 PMcolossal-dentist-5939
06/06/2023, 3:16 PMbroad-bird-4347
06/06/2023, 3:27 PM