handsome-autumn-77266
02/20/2024, 7:49 PMrhythmic-bird-59419
02/20/2024, 10:16 PMearly-lighter-84590
02/23/2024, 12:56 PMbreezy-stone-56170
02/23/2024, 6:38 PMfreezing-photographer-84070
02/24/2024, 10:34 PMIngressRouteTCP
for that, but it does not seem to work, as I think I also need to map the port of the entrypoint to the container, and map that same port to the service, but since it's a LoadBalancer, I would need the nodePort, but I have no idea on what to set this as. (I asked on #k3d but this channel seems more active)busy-teacher-96897
02/26/2024, 3:18 PMdamp-garden-32505
02/27/2024, 4:18 PMquiet-dentist-43250
02/27/2024, 8:56 PMnftables
. I see that in the known issues there is mention of some compatibility issues, but does K3s support use of nftables on a system without iptables?brash-controller-15153
02/28/2024, 9:14 AMrpcbind
is needed by k3s? I received an alert from my cloud provider where they say I need to remove the package via apt-get remove rpcbind
in order to avoid being misused by DDOS programs. Is it safe to remove that package?quick-dentist-45681
02/28/2024, 12:15 PMglamorous-afternoon-50134
02/28/2024, 4:28 PMFailed to pull image "my.registry.com/devops/external-docker/nginx:v0.111": failed to pull and unpack image "my.registry.com/devops/external-docker/nginx:v0.111": failed to resolve reference "my.registry.com/devops/external-docker/nginx:v0.111": unexpected status from HEAD request to https://127.0.0.1:6443/v2/devops/external-docker/nginx/manifests/v0.111?ns=my.registry.com: 500 Internal Server Error"my.registry.com" is indeed present in the "registries.yaml" config as per the docs. Does anyone have an idea why this would not work or how I could debug it? Thanks!
worried-pharmacist-7292
02/29/2024, 6:05 AM1.27.x
:
I would like to enable the following features in the kubelet.
• --kube-reserved
• --system-reserved
• --eviction-hard
I'm trying to reserve and allocate a predefined set of resources for the Kubernetes components and system components so that my nodes will never go unresponsive due to high load/resource utilisation.
I understood that I have to add these arguments in the cluster.yml
file under kubelet
-> extra_args
section. I have the following questions:
1. Since all the Kubernetes components are running as static pods on each node, will these extra_args
for kube-reserved
will work?
2. There is two more options --system-reserved-cgroup
and --kube-reserved-cgroup
mentioned in the documentation. For --system-reserved-cgroup
the default value is system.slice
what would be the right value for --kube-reserved-cgroup
since the components are running as static pods and not as systemd service, can we ignore this option?
I'd appreciate, any help/suggestions..
PS: I've posted the same in the #rke channel as well, posting in this #k3s channel as well just to reach more people for help. If duplication across channels is not allowed, kindly delete this message from the channel. Thank you.acoustic-sunset-13848
03/01/2024, 3:26 PMv1.26.6+k3s1
. Curious if this is a known issue? others have seen in? fixed in a newer version?average-grass-21436
03/03/2024, 12:34 PMmelodic-school-41947
03/04/2024, 5:29 AMabundant-hair-58573
03/04/2024, 3:47 PMleaderelection.go Failed to update lock: Put <https://10.43.0.1:443/api/v1/namespaces/kube-system/endpoints/rancher.io-local-path:EOF>
leaderelection.go failed to renew lease kube-system/rancher.io-local-path: timed out waiting for condition
I tried deleting that pod so it'd start fresh but it hasn't tried to restart yet. I did that first in a test environment and it started right back up.
Looking at the fleet-agent logs I see this at then end
error syncing 'cluster-fleet-local.... : handler bundle-deploy: another operation (install/upgrade/rollback) is in progress
error syncing cluster-fleet-local... |handler bundle-deploy: contents.fleet.cattle.io "<long-string>" is forbidden: User system:serviceaccount:cluster-fleet-... : request... cannot get rsource contents in API group fleet.cattle.io at the cluster scope, requeing
leaderelection.go Failed to update lock: configmaps "fleet-agent-lock" is forbidden : User "system:serviceaccount:cattle-fleet-local-system:fleet-agent" cannot update resource "configmaps" in API group "" in the namespace "cattle-fleet-local-system"
Not quite sure where to go from here. I added a new k3s management node and it joined fine, but no pods are running on itabundant-hair-58573
03/04/2024, 3:51 PMabundant-hair-58573
03/04/2024, 4:22 PMkubectl get nodes
but running kubectl get pods -A -o wide
shows all of the pods still in Running status on that nodeabundant-hair-58573
03/04/2024, 8:32 PMleaderelection.go:325 error retrieving resource lock kube-system/kube-controller-manager: Get <https://127.0.0.1:644/apis/coordination.k8s.io/v1/namespaces/kube-system/leases/kube-controller/manager?timeout=10s>": context deadline exceeded
.abundant-hair-58573
03/04/2024, 8:43 PMmany-gold-38441
03/05/2024, 9:15 AMmany-gold-38441
03/05/2024, 9:16 AMmany-gold-38441
03/05/2024, 9:16 AMrough-hospital-75942
03/07/2024, 1:51 PMstale-kite-82189
03/08/2024, 10:08 AMcool-lion-76179
03/08/2024, 2:54 PMstale-orange-31544
03/08/2024, 8:14 PMlate-breakfast-52642
03/14/2024, 12:27 PMMaster:
curl -sfL <https://get.k3s.io> | INSTALL_K3S_EXEC='server --cluster-init --tls-san <public-ip> --data-dir /application-volume/k3s --write-kubeconfig-mode 644 --etcd-arg=--data-dir=/var/lib/etcd --etcd-arg=--debug --disable traefik' INSTALL_K3S_VERSION='v1.28.4+k3s1' sh -
Master Join:
curl -sfL <https://get.k3s.io> | INSTALL_K3S_EXEC='server --server https://<master-private-ip>:6443 --token <k3s-token> --tls-san <public-ip-of-current-node> --data-dir /application-volume/k3s --write-kubeconfig-mode 644 --etcd-arg=--data-dir=/var/lib/etcd --etcd-arg=--debug --disable traefik' INSTALL_K3S_VERSION='v1.28.4+k3s1' sh -
now i need to upgrade 1.29 version in all 3 nodes , how to do ??
the above cli itself will work with updated version or https://docs.k3s.io/upgrades/manual as per k3s doc ->
curl -sfL <https://get.k3s.io> | INSTALL_K3S_VERSION=vX.Y.Z-rc1 <EXISTING_K3S_ENV> sh -s - <EXISTING_K3S_ARGS>
this will work ?
any one can help on this,
thank you in advance !!!tall-kitchen-12272
03/14/2024, 1:37 PMExternalName
Service (https://kubernetes.io/docs/concepts/services-networking/service/#externalname), but that only seems to work when the service binds to the external interface. I am guessing this is by design in upstream k8s. I thought I would check here to see if anyone has ideas, since it's something some k3s users might want to do.early-potato-21831
03/15/2024, 3:50 AM