PR
ãã®äœæ¥ã¯@ pweil-ã«ãã£ãŠè¡ããã@ derekwaynecarrã«ãã£ãŠã¬ãã¥ãŒããã@ kubernetes / sig-nodeã«ãã£ãŠåŸæŽãããŠããŸãã
@derekwaynecarrãã®æ©èœã®ãŠãŒã¶ãŒã¹ããŒãªãŒã«ãŒãã®äœæãæäŒã£ãŠããããŸããïŒ
@derekwaynecarrãã®æ©èœã1.5ã®ã¢ã«ãã¡ãã¿ãŒã²ããã«ããŠããããšã確èªã§ããŸããïŒ
@derekwaynecarrãã®æ©èœã1.5ã®ã¢ã«ãã¡ãã¿ãŒã²ããã«ããŠããããšã確èªã§ããŸããïŒ
ã¯ãããã®æ©èœã¯å®éšçãªãã®ã§ãããããã¢ã«ãã¡çãšèŠãªãããŸãã
@ derekwaynecarr @ pweil-ãã®ã¢ã€ãã ã1.6ã®ããŒã¿çãã¿ãŒã²ããã«ããŠããããšã確èªã§ããŸããïŒ
@derekwaynecarr ãææ¡https://github.com/kubernetes/kubernetes/pull/34569ã¯ãéã¢ã¯ãã£ãã®ããã«ãããã«ãã£ãŠéããããŸããã
@ pweil-ã httpsïŒ //github.com/kubernetes/kubernetes/pull/34569#issuecomment -273531120ã§ãã°ã«ãŒããå€æŽããã¢ãããŒãhttps://github.com/pweil-/kubernetes/commit/16f29ebb076dfa3c44c7c4669d55fe21c206e149ãææ¡ããŸããåããããããã«ãŒãã°ã«ãŒããžã®/var/lib/kubelet/pods
ã®ã ãããçŸåšã©ã®ãã«ãªã¯ãšã¹ãã§ã远跡ãããŠããªãããšãæ£ããç解ããŠããŸããïŒ
@ pweil-ã --userns-remap
ã䜿çšããå Žåã®dockerã®/var/lib/docker/<uid>.<gid>
ã¢ãããŒããšåæ§ã«ã /var/lib/kubelet/pods-<uid>.<gid>
ã䜿çšããŠããããã®ãµããã£ã¬ã¯ããªå
ã®ãã¹ãŠãchown / chgroupããã®ãçã«ããªã£ãŠããã®ã§ã¯ãªãããšæããŸããåãããããã<uid>.<gid>
ã ãªãããªãã¯å®å
šãªchownã§ã¯ãªãchgrpã ããéžãã ã®ã§ããïŒ
çµå±ã®ãšããã @ adeltonã¯ããããKubernetesã«å¯ŸããŠééçã«ããããšãæ£ããã¢ãããŒãã ãšæããŸãã ãããshiftfsã®ãããªãã®ã§ããããCRIïŒhttps://github.com/moby/moby/issues/28593ïŒã§ã®å®è£ ã§ãããã©ããã ç§ã®æ¢åã®ææ¡ã¯çŸåšãªãŒãã³PRã§è¿œè·¡ãããŠããªããšããã®ã¯æ£ããã§ãã
chgrpã䜿çšããçç±ã¯ãuidã¢ã¯ã»ã¹ã§ã¯ãªãã°ã«ãŒãã¢ã¯ã»ã¹ã確ä¿ãããšããfsgroup
æŠç¥ã«åŸãããšã§ããã
ããããšã@ pweil-ã
ééçãšã¯ã userns-remap
ã䜿çšããŠDockerã§å®è¡ã§ããããã«ããããã«ãã³ãŒããKubernetesåŽã®æ§æã«äœãè¿œå ããå¿
èŠããªãããšãæå³ããŸãã
fsgroup
æŠç¥ã«ã€ããŠã¯ã httpsïŒ//kubernetes.io/docs/concepts/policy/pod-security-policy/#fsgroupãŸãã¯Kuberneteså
ã®äžè¬çãªæ¹æ³è«ãæå³ããŸããïŒ
åããããããuid / gidãæ瀺çãªãªãã·ã§ã³ã«ãããããã®å€ã䜿çšããŠå¿ èŠãªãã£ã¬ã¯ããªãchown / chgrpãã代æ¿ã¢ãããŒããšããŠã httpsïŒ//github.com/kubernetes/kubernetes/pull/55707ãæåºããŸããã
ééçãšã¯ãuserns-remapã䜿çšããŠdockerã§å®è¡ã§ããããã«ããããã«ãã³ãŒããKubernetesåŽã®æ§æã«äœãè¿œå ããå¿ èŠããªãããšãæå³ããŸãã
ãããçæ³çã§ãã ãããå®è¡å¯èœãã©ããïŒãŸãã¯ãããå¯èœæ§ãé«ãã®ã¯ã蚱容å¯èœãªæéæ ã§å®è¡å¯èœãã©ããïŒã¯ãå¥ã®è³ªåã§ãïŒsmileïŒ
fsgroupæŠç¥ã«é¢ããŠã¯ã httpsïŒ //kubernetes.io/docs/concepts/policy/pod-security-policy/#fsgroupãŸãã¯Kuberneteså ã®äžè¬çãªæ¹æ³è«ãæå³ããŸããïŒ
ã¯ã
åããããããuid / gidãæ瀺çãªãªãã·ã§ã³ã«ãããããã®å€ã䜿çšããŠå¿ èŠãªãã£ã¬ã¯ããªãchown / chgrpãã代æ¿ã¢ãããŒããšããŠãkubernetes / kubernetesïŒ55707ãæåºããŸããã
ïŒ+1ïŒãµãã¹ã¯ã©ã€ã
ééçãšã¯ãuserns-remapã䜿çšããŠdockerã§å®è¡ã§ããããã«ããããã«ãã³ãŒããKubernetesåŽã®æ§æã«äœãè¿œå ããå¿ èŠããªãããšãæå³ããŸãã
ãããçæ³çã§ãã ãããå®è¡å¯èœãã©ããïŒãŸãã¯ãããå¯èœæ§ãé«ãã®ã¯ã蚱容å¯èœãªæéæ ã§å®è¡å¯èœãã©ããïŒã¯å¥ã®è³ªåã§ã
çæ³çã«ã¯ããããã¯å¿ èŠãªåå¥ã®uid / gidã®æ°/ã³ã³ãããŒå ã«è¡šç€ºããuidã®ãªã¹ããæå®ããdockerãŸãã¯å¥ã®ã³ã³ãããŒã©ã³ã¿ã€ã ãããã«å¿ããŠãŠãŒã¶ãŒåå空éãèšå®ããŸãã ãã ããDockerãã³ã³ãããŒã«ããŠã³ããããããªã¥ãŒã ã®æææš©ãå€æŽããªãéããKubernetesã¯ã»ããã¢ããã®äžéšãšããŠãããè¡ãå¿ èŠããããŸãã
@ pwel-ã httpsïŒ//github.com/kubernetes/kubernetes/pull/55707ã§ã¬ãã¥ãŒãšã³ã¡ã³ããååŸããŠãããŒãžå¯èœãªç¶æ ã«è¿ã¥ããããã®æè¯ã®æ¹æ³ã¯äœã§ããïŒ
@ pweil- ^
@adeltonç«ææ¥ã®äŒè°ãŸãã¯Slackã®ããããã§sig-nodeã®äººã ãšäº€æµããããšããŸãïŒ https ïŒ//github.com/kubernetes/community/tree/master/sig-node
@ derekwaynecarr ã httpsïŒ//github.com/kubernetes/kubernetes/pull/55707ãsig-nodeã®ã¬ãŒããŒã«æã£ãŠããŠããã ããŸãããã
@ pweil- @ derekwaynecarrãã®æ©èœã®é²æ©ã¯æåŸ ãããŠããŸããïŒ
ãã®ãããã¯ã¯ãsig-nodeã®k8s1.11èšç»ã§åãäžããŸãã
ããã«ã¡ã¢ãæ®ãã ãã§ãã
ã»ãšãã©ã®Kubernetesãããã€ã¡ã³ãã«ã¯ããã¹ãã§ã®ã«ãŒãæš©éãå¿
èŠãšããkubeã·ã¹ãã ãµãŒãã¹ïŒãªãŒããŒã¬ã€ãããã¯ãŒã¯ãªã©ïŒãããããã --userns=host
ããµããŒãããPodSecurityPoliciesããã®äœ¿çšæ³ã®äœ¿çšã«é¢ããæš©éã§æ¡åŒµããå¿
èŠããããŸãã
ç·šéïŒ pid=host
ãèš±å¯ãããšã userns=host
ãèš±å¯ããããšæããŸããã
ç·šéïŒããããŸãããããã¯å®éã«ã¯æ£ç¢ºã§ãïŒ httpsïŒ//github.com/kubernetes/kubernetes/pull/31169ã
--userns = hostããµããŒãããPodSecurityPoliciesããã®äœ¿çšæ³ã®äœ¿çšã«é¢ããã¢ã¯ã»ã¹èš±å¯ã§æ¡åŒµããå¿ èŠããããŸã
PSPã¯ãã§ã«ãã®ãããªãµããŒããæã£ãŠããŸãïŒ HostNetwork
ãåç
§ããŠãã ãã
@ pweil- @ derekwaynecarr
1.11ã§ããã«ã€ããŠäœãèšç»ã¯ãããŸããïŒ
ãããããªããããªãã¯ãã®æ©èœãé©åãªãã®ã§ææ°ã§ããããšã確èªããŠãã ããïŒ
stage/{alpha,beta,stable}
sig/*
kind/feature
cc @idvoretskyi
@justaugustusç§ã¯ããã«ç©æ¥µçã«åãçµãã§ããªãã®ã§ã@ adeltonã«ä»»ããŸãã @adeltonããã§ããŒããããã«ã€ããŠã³ã¡ã³ãã§ããŸããïŒ ããããšãïŒ
sig-nodeã®KEPã«åãçµãã§ããŸãã
@justaugustus
ç§ã¯æ¬¡ã®ããšãããŸããïŒ
@derekwaynecarrã¢ããããŒãããŠãããŠããããšãïŒ
@ derekwaynecarr ãhttpsïŒ//github.com/kubernetes/community/pull/2042ã¯https://github.com/kubernetes/community/pull/2067ã«çœ®ãæããããŸããã
@ derekwaynecarr ãkubernetes / communityïŒ2042ã¯kubernetes / communityïŒ2067ã«çœ®ãæããããŸããã
@adeltonã«æè¬ããŸããç§ã¯ãããåæ ããããã«èª¬æãæŽæ°ããŸããã
@derekwaynecarrã®é©åãªé
ç®ã«èšå
¥ããŠãã ãã
1.11æ©èœè¿œè·¡ã¹ãã¬ããã·ãŒã
ã«å¯ŸããŠãã¬ãŒã¹ãã«ããŒããã¥ã¡ã³ãPRãéããŸã
release-1.11
ãã©ã³ã
2018幎5æ25æ¥ãŸã§ã«ïŒç§ããããæžããŠããææ¥ïŒãæ°ããããã¥ã¡ã³ããŸãã¯ããã¥ã¡ã³ãã®å€æŽã
å¿
èŠã§ãããé¢é£ããPRã¯ãŸã éãããŠããŸããã
@ derekwaynecarr-ãã®æ©èœã®çŸåšã®ã¹ããŒã¿ã¹ã¯äœã§ããïŒ
äžéšã®ã¢ã€ãã ã«ã€ããŠã¯ãé£çµ¡ãå·®ãäžããŠããªãããããã®æ©èœã¯1.11æ©èœè¿œè·¡ã¹ãã¬ããã·ãŒãå
ã®Milestone risks
ã·ãŒãã«ç§»åãããŸããã
Milestone risks
ã·ãŒãã®ãã®æ©èœã®ã©ã€ã³ã¢ã€ãã ãã§ããã ãæ©ãæŽæ°ããèªåèªèº«ãš@idvoretskyiã«pingãéä¿¡ããŠãã ãããæ©èœã®ã¹ããŒã¿ã¹ãè©äŸ¡ã§ãããããã€ã«ã¹ããŒã³ããæ£åŒã«åé€ããå¿
èŠããããŸãã
@justaugustus @mistyhacksPRã¯ã»ãŒçµ±åãããŠããŸãhttps://github.com/kubernetes/kubernetes/pull/64005
ããªãŒãºããåã«å¿ èŠãªAPIã®æ¿èªãå¿ èŠã§ãã
@sjenningããã¥ã¡ã³ãã®ã¹ããŒã¿ã¹ã¯äœã§ããïŒ ãããããã®æ©èœãçŸåšAt Risk
ãšããŠãªã¹ããããŠããçç±ã§ãã
@justaugustusã®ããã¥ã¡ã³ããæ°æ¥äžã«æŽæ°ãããŸãã
@ vikaschoudhary16æŽæ°ããŠããã ãããããšãããããŸãã
ãã®æ©èœã¯ãæ©èœè¿œè·¡ã¹ãã¬ããã·ãŒãã®ããã¥ã¡ã³ãåãæŽæ°ããããŸã§ã Milestone Risks
ã·ãŒãã«æ®ããŸãã
@ idvoretskyi ã @ mistyhacks ãããã³ç§ã«pingãéä¿¡ããŠããããæŽæ°ããããéç¥ããŠãã ããããªãªãŒã¹ã®ããã«ã¯ãªã¢ã§ããŸãã
ããã¯kubernetes / kubernetesïŒ64005ãã1.12ã«ã¹ãªããããŠããããã§ã
ãã®ã³ã¡ã³ãã«åºã¥ããŠãããã1.11ãã移åããŸãã
@derekwaynecarr @ pweil- @ sjenning @ kubernetes / sig-node-feature-requests-
ãã®æ©èœã¯ä»¥åã®ãã€ã«ã¹ããŒã³ããåé€ãããããããã§ãã¯ã€ã³ããŠãKubernetes1.12ã§ãã®æ©èœã®èšç»ããããã©ããã確èªããããšæããŸãã
ãã®å Žåã¯ããã®åé¡ãææ°ã§ããã次ã®ãã¹ãŠã®æ å ±ãå«ãŸããŠããããšã確èªããŠãã ããã
ããããŒã·ããïŒ
/ cc @justaugustus @ kacole2 @robertsandoval @ rajendar38
çŸåšã®ãã®æ©èœã«ã¯ãã€ã«ã¹ããŒã³ããªãããããã§ãã¯ã€ã³ããŠãKubernetes1.12ã§ããã«é¢ããèšç»ããããã©ããã確èªããããšæããŸãã
ãã®å Žåã¯ããã®åé¡ãææ°ã§ããã次ã®ãã¹ãŠã®æ å ±ãå«ãŸããŠããããšã確èªããŠãã ããã
以äžãèšå®ããŸãã
ãã®æ©èœãé©åã«æŽæ°ããããã@ justaugustusã@ kacole2 ã @ robertsandoval ã @ rajendar38ã«æ瀺çã«pingãå®è¡ããŠãKubernetes1.12ã®æ©èœè¿œè·¡ã¹ãã¬ããã·ãŒãã«å«ããæºåãã§ããŠããããšã確èªããŠãã ããã
æ©èœã®ãã¹ãŠã®PRã«ãé¢é£ãããªãªãŒã¹ããŒããå«ãŸããŠããããšã確èªããŠãã ããã
ããããŒã·ããïŒ
PSããã¯èªååã«ãã£ãŠéä¿¡ãããŸãã
ããã¯1.12ã§èšç»ããŠããŸãã
ããããšãã 1.12ãã©ããã³ã°ã·ãŒãã«è¿œå ãããŸããã
説æãæŽæ°ããŠã1.11ã¹ãªãããã1.12ã§ã¢ã«ãã¡ãšããŠè¿œè·¡ãããŠããããšããã£ããã£ããŸããã
ã¡ãã£ãšãããïŒ @derekwaynecarrç§ã¯ãã®ãªãªãŒã¹ã®ããã¥ã¡ã³ãã®ã©ã³ã°ã©ãŒã§ãã ãã¬ãŒã¹ãã«ããŒãšããŠrelease-1.12ãã©ã³ãã«å¯ŸããŠããã¥ã¡ã³ãPRãéãããšãã§ããå¯èœæ§ã¯ãããŸããïŒ ããã«ããããã®ãªãªãŒã¹ã§ã®æ©èœã®åºè·ã«èªä¿¡ãæãŠãããã«ãªããã¬ãã¥ãŒ/ç·šéãéå§ãããšãã«äœæ¥ã§ããããã«ãªããŸãã ããããšãïŒ ãã®æ©èœã«ããã¥ã¡ã³ããå¿ èŠãªãå Žåã¯ãæ©èœè¿œè·¡ã¹ãã¬ããã·ãŒããæŽæ°ããŠåæ ããŠãã ããã
PRã¯ãŸã @ vikaschoudhary16ããã¬ãã¥ãŒäžã§ããã圌ã¯ã§ããã¯ãã§ã
ãã¬ãŒã¹ãã«ããŒããã¥ã¡ã³ããéããŸãã
2018幎8æ20æ¥æææ¥ååŸ4æ32å[email protected]
æžããŸããïŒ
ã¡ãã£ãšãããïŒ @derekwaynecarrhttps ïŒ//github.com/derekwaynecarrç§ã¯
ãã®ãªãªãŒã¹ã®ããã¥ã¡ã³ãã®ã©ã³ã°ã©ãŒã ç§ãããªããè¿ããããšãã§ããå¯èœæ§ã¯ãããŸãã
ãã¬ãŒã¹ãã«ããŒãšããŠrelease-1.12ãã©ã³ãã«å¯ŸããŠããã¥ã¡ã³ãPRãéããŸããïŒ ããã
ãã®ãªãªãŒã¹ã§ã®æ©èœã®åºè·ã«èªä¿¡ãæãŠãããã«ãªãã
ã¬ãã¥ãŒãç·šéãå§ãããšãã«äžç·ã«ä»äºãããããšãã§ããŸãã ããããšãïŒ ããã
ãã®æ©èœã«ã¯ããã¥ã¡ã³ãã¯å¿ èŠãããŸãããæ©èœãæŽæ°ããŠãã ããã
ãããåæ ããããã«ã¹ãã¬ããã·ãŒãã远跡ããŸããïŒâ
ããªããèšåãããã®ã§ãããªãã¯ãããåãåã£ãŠããŸãã
ãã®ã¡ãŒã«ã«çŽæ¥è¿ä¿¡ããGitHubã§è¡šç€ºããŠãã ãã
https://github.com/kubernetes/features/issues/127#issuecomment-414453281 ã
ãŸãã¯ã¹ã¬ããããã¥ãŒãããŸã
https://github.com/notifications/unsubscribe-auth/AF8dbP-2qZQZKSn9g9FCfYpxnO8iy9koks5uSxzqgaJpZM4KS4jV
ã
ããããšãïŒ @ vikaschoudhary16PRãäžãã£ããæããŠãã ããã ð
@ vikaschoudhary16 @derekwaynecarr @ mrunalp-
ãã®æ©èœã®ããã¥ã¡ã³ãã¹ããŒã¿ã¹ã«é¢ããæŽæ°ã¯ãããŸããïŒ ãŸã 1.12ã§çéžããäºå®ã§ããïŒ
ãã®æç¹ã§ãã³ãŒãã®ããªãŒãºãçºçããŠãããããã¥ã¡ã³ãã®æéã¯9/7ïŒ2æ¥ïŒã§ãã
ãã®æ©èœã«ã€ããŠã§ããã ãæ©ãããã«æ»ã£ãŠããªãå Žåã¯ããã€ã«ã¹ããŒã³ããåé€ããå¿
èŠããããŸãã
ccïŒ @zparnold @jimangel @tfogo
1.13ãã€ã«ã¹ããŒã³ã«ç§»è¡ããŸãã
@derekwaynecarrããã1.13ã®æéã«éãããšç¢ºä¿¡ããŠããŸããïŒ ãã®ãªãªãŒã¹ã¯ããããå®å®ããããã®ãç®æšãšããŠãããç©æ¥µçãªã¿ã€ã ã©ã€ã³ããããŸãã 次ã®æéã«éã«åããšç¢ºä¿¡ã§ããå Žåã«ã®ã¿ããã®æ¡åŒµæ©èœãå«ããŠãã ããã
ããããšãïŒ
@derekwaynecarr
1.13ã®ããã¥ã¡ã³ããšã¹ããŒã¿ã¹ã«ã€ããŠã®ãããããããªãã€ã³ããŒã§ãã ããããšãïŒ
ccïŒ@ vikaschoudhary16
@derekwaynecarr
ãµãŒãããŒãã£ã®ã³ã³ããã®å®è¡ãå¯èœã«ããk8sã¯ã©ã¹ã¿ãŒãéçšããŠããŸãã ã»ãã¥ãªãã£ã®èŠ³ç¹ãããããã¯ç§ãã¡ããã°ããåŸ
ã£ãŠããéèŠãªæ©èœã§ãã ãããåªå
床ã®é«ãã»ãã¥ãªãã£æ©èœãšèŠãªããv1.13ãªãªãŒã¹ã§å©çšã§ããããã«ããŠãã ããã
@derekwaynecarrã¹ããŒã¿ã¹ã«é¢ããé£çµ¡ã¯ãããŸãããã@ spiffxpãçŸåšã®k / kPRãæ·»ä»ããŠããããã§ãã ãããv1.13ã®ãã€ã«ã¹ããŒã³ã«ãªããšç¢ºä¿¡ããŠããŸããïŒ ãšã³ãã³ã¹ã¡ã³ãããªãŒãºã¯ææ¥ã®COBã§ãã ãã®åé¡ãPRã§ã®æŽ»åã«ã€ããŠã®é£çµ¡ããªãå Žåãããã¯ãå®å®æ§ãã®ããŒãã«é©åããªãããããã€ã«ã¹ããŒã³ããå€ãããŸãã ææ¥ã®COBåŸã«é£çµ¡ããªãå Žåã¯ããã€ã«ã¹ããŒã³ã«è¿œå ããããã«äŸå€ãå¿ èŠã«ãªããŸãã ç§ãã¡ã®ç«å ŽãæããŠãã ããã ããããšãïŒ
éä¿¡ãäžè¶³ããŠãããããããã¯1.13远跡ããåé€ãããŠããŸãã
/ãã€ã«ã¹ããŒã³ã¯ãªã¢
@derekwaynecarrãã®æ¡åŒµæ©èœã¯ããããçéžãããŸã§ã«äœãä¿çãããŠããããæ確ã§ãªãããã1.13ãã移åãããŸããã çŸåšãæ£åŒã«ãšã³ãã³ã¹ã¡ã³ãããªãŒãºäžã§ãã ãããè¿œå ãçŽãå¿ èŠã®ããéèŠãªæ¡åŒµæ©èœã§ããå Žåã¯ãããã«æŠèª¬ãããŠãã詳现ãå«ãäŸå€ãæåºããå¿ èŠããããŸãã
ïŒç§ããã¹ãããŠããèªååã®äžã«ã¯ãæ··ä¹±ãé¿ããããã«åé€ããã³ã¡ã³ãã誀ã£ãŠéä¿¡ãããã®ããããŸããç³ãèš³ãããŸããïŒïŒ
ããã¯ãŸã 解決ããããã«äºæ³ãããé·ãè°è«ã®äžã«ããã
ä»ã®ãšããè¡ãè©°ãŸã£ãŠããŸãã ããŸãããã°ã1.14ã§ãã®åé¡ãä¹ãè¶ããããšãã§ããŸãã
2018幎11æ19æ¥æææ¥ååŸ10æ57åã¹ãã£ãŒãã³ãªãŒã¬ã¹ã¿ã¹[email protected]
æžããŸããïŒ
ïŒç§ããã¹ãããŠããèªååã®äžã«ã¯ã誀ã£ãŠã³ã¡ã³ããéä¿¡ãããã®ããããŸãã
æ··ä¹±ããªãããã«åé€ããŸããã ãããïŒïŒâ
ããªããèšåãããã®ã§ãããªãã¯ãããåãåã£ãŠããŸãã
ãã®ã¡ãŒã«ã«çŽæ¥è¿ä¿¡ããGitHubã§è¡šç€ºããŠãã ãã
https://github.com/kubernetes/enhancements/issues/127#issuecomment-440129579 ã
ãŸãã¯ã¹ã¬ããããã¥ãŒãããŸã
https://github.com/notifications/unsubscribe-auth/AF8dbAvKBPUb9GC9Us-4mJdS7pB0ds8tks5uw32ygaJpZM4KS4jV
ã
äœããæäŒãã§ããããšã¯ãããŸããïŒ ãŠãŒã¶ãŒã«rootæš©éãäžããã«ã¯ãgitpod.ioã«ãã®æ©èœãæ¬åœã«å¿ èŠã§ãã
@svenefftingeå®è£
PRã確èªããŠãã ããã httpsïŒ//github.com/kubernetes/kubernetes/pull/64005
1.14ã§ããŒãžãããããšãæãã§ããŸã
@derekwaynecarrããã«ã¡ã¯-ç§ã¯1.14ã®æ¡åŒµæ©èœã®ãªãŒããŒã§ããããã®åé¡ããã§ãã¯ããŠã1.14ãªãªãŒã¹ã§èšç»ãããŠããäœæ¥ïŒããå ŽåïŒã確èªããŠããŸãã æ¡åŒµæ©èœã®ããªãŒãºã¯1æ29æ¥ã§ããããã¹ãŠã®æ¡åŒµæ©èœã«ã¯KEPãå¿ èŠã§ããããšãæãåºããŠãã ããã
ããã«ã¡ã¯@ claurence-ãã®ããã®KEPïŒææ¡ïŒã¯ãã§ã«ããŒãžãããŠããŸããkubernetes / communityïŒ2067ã 次ã®å®è£
PRã1.14ã«ããŒãžããããšãæãã§ããŸãïŒ
kubernetes / kubernetesïŒ64005
å
ã®èšèšææ¡ã®æŽæ°ã«å ããŠïŒ
https://github.com/kubernetes/community/pull/2595
ããããšã@ vikaschoudhary16-ããã¯1.14ã§ã¢ã«ãã¡ãšããŠå®è£ ãããŸããïŒ ã¿ã°ä»ãã«åºã¥ããŠããŸã ã¢ã«ãã¡ã©ãã«ãä»ããŠããŸããããããæ£ãããªãå Žåã¯ãç¥ãããã ããã
@ vikaschoudhary16ããã«ã¡ã¯-ãã®æ¡åŒµæ©èœã®KEPãžã®ãªã³ã¯ã¯ãããŸããïŒ PRããŒãžãžã®ãªã³ã¯ã衚瀺ãããŸãããKEPãèŠã€ããã®ã«åé¡ããããŸã
ããã«ã1.14ã®å Žåããã®ãªãªãŒã¹ã§ããŒãžããå¿ èŠã®ãããªãŒãã³PRã¯ãããŸããïŒ ãããããªããç§ãã¡ãããããç§ãã¡ã®ã·ãŒãã«è¿œå ã§ããããã«ç§ã«ç¥ãããŠãã ããã
ããã«ã¡ã¯@ vikaschoudhary16 @derekwaynecarrðç§ã¯v1.14ããã¥ã¡ã³ãã®ãªãªãŒã¹ãªãŒãã§ãã 3æ1æ¥éææ¥ãŸã§ã«äºå®ãããŠããk / websiteïŒãã©ã³ãdev-1.14ïŒã«å¯ŸããPRãæ¢ããŠããŸããå®å šãªããã¥ã¡ã³ãã®å§ãŸãã§ããã°çŽ æŽããããšæããŸããããã¬ãŒã¹ãã«ããŒPRã§ãããŸããŸããã ãäžæãªç¹ãããããŸããããç¥ãããã ããã
@ claurence @ jimangelå®è£ ãšèšèšã®éãè¡ã£ããæ¥ããããŠããŸãã äžèšã®ã³ã¡ã³ãã§è¿°ã¹ãããã«ãkubernetes / communityïŒ2595ã¯ãããŒãžããããšããŠããèšèšææ¡PRã§ãããããã«åºã¥ããŠå®è£ PRãkubernetes / kubernetesïŒ64005ãæŽæ°ããŸãã
@ vikaschoudhary16 KEPãžã®ãªã³ã¯ã¯ãããŸããïŒ KEPãã©ã«ããŒã«èŠã€ããããšãã§ãããã®ã¯ãããŸãã-httpsïŒ//github.com/kubernetes/enhancements/tree/master/keps
@ vikaschoudhary16ãªã³ã¯ãããææ¡ã¯KEPã§ã¯ãããŸããã ãã¹ãèšç»ããªãããªãªãŒã¹ããŒã ã䜿çšã§ãããã§ãã¯ãªã¹ã圢åŒã®åæ¥åºæºããªããã¢ããã°ã¬ãŒã/ããŠã³ã°ã¬ãŒãã®èæ ®äºé ã«ã€ããŠã®è°è«ããããŸããã KEPãå¿ èŠã§ãã å ã®ãã¶ã€ã³ææ¡ããªã³ã¯ãŸãã¯åç §ããŠãåæ©ããã¶ã€ã³ãªã©ã«é¢ããèšèã®äžéšãèšå ¥ããããšãã§ããŸãããããã§ãªã¹ããããã®ãæ瀺çã«ç¶Žãå¿ èŠããããŸãã
ææ¡ã®æŽæ°ã«ã€ããŠã¯æªè§£æ±ºã®è°è«ãç¶ããŠããããã§ãïŒåç §ïŒhttpsïŒ//github.com/kubernetes/community/pull/2595ïŒ
KEPãååšããäŸå€ããã»ã¹ãéããŠéä¿¡ããããŸã§ããªãªãŒã¹ããŒã ãv1.14ã§ã®ãã®çéžã«é¢é£ãããã¹ãŠã®ãã®ããããã¯ããããšãææ¡ããåŸåããããŸã
@ vikaschoudhary16ãã®åé¡ã«é¢ããKEPã®æŽæ°ã¯ãããŸããïŒ çŸåšããã¹ããã©ã³ã§KEPãèŠã€ããããšãã§ããªãããããã®åé¡ã¯1.14ãªãªãŒã¹ã®ãªã¹ã¯ã«ãããããŠããŸãã ãã®åé¡ã®ãã¹ãèšç»ãšåæ¥åºæºãæããŠãã ããã
ããã1.14ã«ãªãããšãæ¬åœã«æãã§ããŸãã Minikubeã§ãããããµããŒãããäºå®ã¯ãããŸããïŒ
äžèšã®è³ªåã«å¯Ÿããåçã2é±é以äžãªããsig-node slackãã£ãã«ã§è³ªåããããšãã«slackã§ã®å¿çããªãããããã®ã¢ã€ãã ã¯1.14ãã€ã«ã¹ããŒã³ããåé€ãããŸãã
runc
CVE-2019-5736ã®çµæãšããŠããã®æ©èœã¯çŸåšéåžžã«é¢é£æ§ãé«ãããã§ãã éã«ãŒããšããŠå®è¡ããããã«æ¢åã®ã€ã¡ãŒãžãåæ§ç¯ããïŒãããŠãã®å€æŽããçãããã¹ãŠã®åé¡ã«å¯ŸåŠããïŒããšã¯ãUID0ãããŒãäžã®ä»ã®éç¹æš©ãŠãŒã¶ãŒã«ãããããåäžã®æ§æãªãã·ã§ã³ãèšå®ããããã_å®è³ªçã«_ããå€ãã®ãªããã§ãã
ããŒã«ãåã³è»¢ããã«ã¯äœãããå¿ èŠããããŸããïŒ
ç§ã¯1.15ã®ãšã³ãã³ã¹ã¡ã³ããªãŒãã§ãã ãã®åé¡ã«ãã®ãªãªãŒã¹ãµã€ã¯ã«ã«é¢é£ããäœæ¥ããããã©ããããç¥ãããã ãããå ã®æçš¿ã«ãããåæ ãããŠæŽæ°ããŠãã ããã ãã以å€ã®å Žåããã©ããã³ã°ã·ãŒãã«è¿œå ãããããšã¯ãããŸããã ããããšãïŒ
ããã«ã¡ã¯@ vikaschoudhary16 ãç§ã¯1.16ãšã³ãã³ã¹ã¡ã³ããªãŒã/ã·ã£ããŠã§ãã ãã®æ©èœã¯1.16ã§ã¢ã«ãã¡/ããŒã¿/å®å®ã¹ããŒãžãåæ¥ããäºå®ã§ããïŒ 1.16ãã©ããã³ã°ã¹ãã¬ããã·ãŒãã«è¿œå ã§ããããã«ãç¥ãããã ããã åæ¥ããŠããªãå Žåã¯ããã€ã«ã¹ããŒã³ããåé€ãã远跡ã©ãã«ãå€æŽããŸãã
ã³ãŒãã£ã³ã°ãéå§ããããããŸãã¯ãã§ã«ããå Žåã¯ãé©åã«è¿œè·¡ã§ããããã«ããã®å·ã«é¢é£ãããã¹ãŠã®k / kPRããªã¹ãããŠãã ããã
ãã€ã«ã¹ããŒã³ã®æ¥ä»ã¯ãEnhancement Freeze7 / 30ããã³CodeFreeze8 / 29ã§ãã
ããããšãã
@ kacole2ãŸã ã¢ãããŒããè¡ãè©°ãŸã£ãŠããã®ã§ã1.16ã§ãããããã«é²å±ãããšã¯æããªãã
ïŒããã«ãåæçš¿ïŒ
åèšuserNSãããã³ã°ãå®è£
ãããŠããå Žåã§ãããrunInHostUserNSããã©ã°ãèšå®ãããšåœ¹ç«ã¡ãŸããå®å
šãªãœãªã¥ãŒã·ã§ã³ã«ã¯ããšã«ãããããå¿
èŠã§ãããšç§ã¯äž»åŒµããŸãã
userNSãµããŒããªãã§ãã©ã°ãèšå®ãããšãå°ãªããšãæ¢åã®ããŒãã¬ãã«ã®DockerïŒä»ã®ã©ã³ã¿ã€ã ã«ã€ããŠã¯äžæïŒã®UID / GIDåãããã³ã°æ©èœã䜿çšã§ããããã«ãªããŸãã çŸåšã®åé¡ã¯ããã¹ããããã¯ãŒã¯ã®åå空éã§å®è¡ãããã®ãšçžäºã«æä»çã§ãããšããããšã§ãããäžéšã®ã€ã³ãã©ã³ã³ããã¯ããã§å®è¡ããå¿
èŠããããŸãïŒäŸïŒkube-proxyïŒ
ãã®æç¹ã§ã®IMOã¯ããŠãŒã¶ãŒã®ãµããŒããå¿
èŠãã©ããã¯åé¡ã§ã¯ãããŸãããå¯äžã®åé¡ã¯ãã©ã®ãããã®æéãã©ã®ãããªåœ¢åŒã§ãããã§ã:)
https://twitter.com/ChaosDatumz/status/1158556519623024642
ãããä»æ§ã®æ§æå¯èœãªrun-in-host-user-nsãã©ã°ãæã¡ããããæ¢åã®ã©ã³ã¿ã€ã ã¬ãã«ã®æ©èœãšäžç·ã«äœ¿çšãããšãå®éã®ååŒãå°å
¥ããããŸã§äžæçãªããªããžãœãªã¥ãŒã·ã§ã³ãšããŠæ©èœããå¯èœæ§ããããŸããé·æçã«ãç¡é§ãªåªå
ãã®æ©èœãåé²ãããæ¹æ³ã¯ãããŸããïŒ
ããã«ã¡ã¯@ derekwaynecarr ã1.17æ¡åŒµæ©èœã¯ããã«åœ±ãèœãšããŸãã ãã§ãã¯ã€ã³ããŠããã®æ¡åŒµæ©èœã1.17ã§ã¢ã«ãã¡/ããŒã¿/å®å®ã«ç§»è¡ãããšæããããã©ããã確èªããããšæããŸãã
çŸåšã®ãªãªãŒã¹ã¹ã±ãžã¥ãŒã«ã¯æ¬¡ã®ãšããã§ãã
ãã®å Žåã¯ã1.17ãã©ããã³ã°ã·ãŒãïŒhttps://bit.ly/k8s117-enhancement-trackingïŒã«è¿œå ããŸãã ã³ãŒãã£ã³ã°ãéå§ãããããé©åã«è¿œè·¡ã§ããããã«ããã®å·ã«é¢é£ãããã¹ãŠã®k / kPRããªã¹ãããŠãã ããã ð
ãã¹ãŠã®æ¡åŒµæ©èœã«ã¯KEPãå¿ èŠã§ãããKEP PRã¯ããŒãžãããKEPã¯å®è£ å¯èœãªç¶æ ã«ããããã¹ãèšç»ãšåæ¥åºæºãå¿ èŠã§ããããšã«æ³šæããŠãã ããã
ããããšãïŒ
90æ¥éæäœããªããšãåé¡ã¯å€ããªããŸãã
/remove-lifecycle stale
ã䜿çšããŠãåé¡ãæ°èŠãšããŠããŒã¯ããŸãã
å€ãåé¡ã¯ãããã«30æ¥ééã¢ã¯ãã£ãã«ãªããšè
æããæçµçã«ã¯éããŸãã
ãã®åé¡ãä»ãã解決ã§ããå Žåã¯ã /close
ã䜿çšããŠè§£æ±ºããŠãã ããã
sig-testingãkubernetes / test-infraã fejtaã«ãã£ãŒãããã¯ãéä¿¡ããŸãã
/ lifecycle stale
/ remove-lifecycle stale
ããã¯æ»ãã§ããããã«èŠããŸãã ã¹ããŒã¿ã¹ã¯ã©ãã§ããïŒ
ãããæãéããããã«è€æ°ã®è©Šã¿ããããŸãããããŸã ãããŸããã ã¯ãããã®æ©èœãå¿ èŠã§ãã éããªãã§ãã ããã
ããã«ã¡ã¯@ prbinu @ derekwaynecarr -1.18æ¡åŒµæ©èœã®ã·ã£ããŠã¯ããã«ãããŸãã ãã§ãã¯ã€ã³ããŠããã®æ¡åŒµæ©èœã1.18ã§ã¢ã«ãã¡çã«ç§»è¡ãããšæããããã©ããã確èªããããšæããŸãã
çŸåšã®ãªãªãŒã¹ã¹ã±ãžã¥ãŒã«ã¯æ¬¡ã®ãšããã§ãã
1æ6æ¥æææ¥-ãªãªãŒã¹ãµã€ã¯ã«ãå§ãŸããŸã
1æ28æ¥ç«ææ¥EODPST-æ¡åŒµæ©èœã®ããªãŒãº
3æ5æ¥æšææ¥ãEODPST-ã³ãŒãããªãŒãº
3æ16æ¥æææ¥-ããã¥ã¡ã³ããå®æãããŠç¢ºèªããå¿
èŠããããŸã
3æ24æ¥ç«ææ¥-Kubernetes1.18.0ããªãªãŒã¹ãããŸãã
ãªãªãŒã¹ã«å«ããã«ã¯ããã®æ¡åŒµæ©èœã®KEPãimplementable
ã¹ããŒã¿ã¹ã«ããŒãžãããŠããå¿
èŠããããŸãã KEPã«ã¯ãåæ¥åºæºãšãã¹ãèšç»ãå®çŸ©ãããŠããå¿
èŠããããŸãã
ãã®æ¡åŒµæ©èœãå«ãããå Žåã¯ãã³ãŒãã£ã³ã°ãéå§ãããããé©åã«è¿œè·¡ã§ããããã«ããã®åé¡ã«é¢é£ãããã¹ãŠã®k / kPRããªã¹ãããŠãã ããã ð
ããã§æ¡åŒµæ©èœã远跡ããŸãïŒhttpïŒ //bit.ly/k8s-1-18-enhancements
ããããšãïŒ
ãªãã€ã³ããŒãšããŠ@ prbinu @ derekwaynecarr ã
1æ28æ¥ç«ææ¥EODPST-æ¡åŒµæ©èœã®ããªãŒãº
æ¡åŒµæ©èœããªãŒãºã¯7æ¥ä»¥å ã§ãã 1.18ã«å«ããããšãåžæããå Žåã¯ãäžèšã®èŠæ±ã«åŸã£ãŠæŽæ°ããŠãã ããã
ããããšãïŒ
90æ¥éæäœããªããšãåé¡ã¯å€ããªããŸãã
/remove-lifecycle stale
ã䜿çšããŠãåé¡ãæ°èŠãšããŠããŒã¯ããŸãã
å€ãåé¡ã¯ãããã«30æ¥ééã¢ã¯ãã£ãã«ãªããšè
æããæçµçã«ã¯éããŸãã
ãã®åé¡ãä»ãã解決ã§ããå Žåã¯ã /close
ã䜿çšããŠè§£æ±ºããŠãã ããã
sig-testingãkubernetes / test-infraã fejtaã«ãã£ãŒãããã¯ãéä¿¡ããŸãã
/ lifecycle stale
/ remove-lifecycle stale
ããã«ã¡ã¯@ vikaschoudhary16-1.19æ¡åŒµæ©èœã¯ããã«åœ±ãèœãšããŸãã ãã§ãã¯ã€ã³ããŠããã®æ¡åŒµæ©èœã1.19ã§åæ¥ãããšæããã©ããã確èªãããã£ãã®ã§ããã
ãªãªãŒã¹ã®ãã®éšåã䜿çšããã«ã¯ã次ã®ããã«ããŸãã
çŸåšã®ãªãªãŒã¹ã¹ã±ãžã¥ãŒã«ã¯æ¬¡ã®ãšããã§ãã
ãã®å Žåã¯ã1.19ãã©ããã³ã°ã·ãŒãïŒhttp://bit.ly/k8s-1-19-enhancementsïŒã«è¿œå ããŸãã ã³ãŒãã£ã³ã°ãéå§ãããããé©åã«è¿œè·¡ã§ããããã«ããã®å·ã«é¢é£ãããã¹ãŠã®k / kPRããªã¹ãããŠãã ããã ð
ããããšãïŒ
ããã«ã¡ã¯@ derekwaynecarr ã @ vikaschoudhary16 ã
äžèšã®ç§ã®è³ªåã«ã€ããŠã®èŠªåãªãªãã€ã³ããŒã
ããããã
ãã¬ãã¯
ããã«ã¡ã¯@ derekwaynecarr ã @ vikaschoudhary16 ã
äžèšã®ç§ã®è³ªåã«ã€ããŠã®èŠªåãªãªãã€ã³ããŒã
ããããã
ãã¬ãã¯
@msedzinsããã«ã¡ã¯ãç§ã¯çŸåšãã®æ©èœåŒ·åã«åãçµãã§ããŸãã ãã®æ¡åŒµæ©èœã¯ãŸã éçºããã³ãã¹ãäžã§ããããã1.19ã«æ®µéçã«ç§»è¡ããããšã¯ãããŸããã ããããšãã
@ mohammad-yazdaniæããŠãããŠããããšãïŒ
90æ¥éæäœããªããšãåé¡ã¯å€ããªããŸãã
/remove-lifecycle stale
ã䜿çšããŠãåé¡ãæ°èŠãšããŠããŒã¯ããŸãã
å€ãåé¡ã¯ãããã«30æ¥ééã¢ã¯ãã£ãã«ãªããšè
æããæçµçã«ã¯éããŸãã
ãã®åé¡ãä»ãã解決ã§ããå Žåã¯ã /close
ã䜿çšããŠè§£æ±ºããŠãã ããã
sig-testingãkubernetes / test-infraã fejtaã«ãã£ãŒãããã¯ãéä¿¡ããŸãã
/ lifecycle stale
/ remove-lifecycle stale
ããã«ã¡ã¯@ derekwaynecarr @ mauriciovasquezbernal @mohamedsgap
æ¡åŒµæ©èœã¯ããããªãŒãããŸãã ããã1.20ã§ã¢ã«ãã¡/ããŒã¿/å®å®ãããèšç»ã¯ãããŸããïŒ
ããããšãïŒ
ãã«ã¹ãã³
ããã«ã¡ã¯@ kikisdeliveryservice ãsig-nodeãšããã«è©±ãåã£ãããææ°æ å ±ããç¥ããããŸãã
ããããšãã
ããŠãªã·ãªã
æãåèã«ãªãã³ã¡ã³ã
@derekwaynecarr
ãµãŒãããŒãã£ã®ã³ã³ããã®å®è¡ãå¯èœã«ããk8sã¯ã©ã¹ã¿ãŒãéçšããŠããŸãã ã»ãã¥ãªãã£ã®èŠ³ç¹ãããããã¯ç§ãã¡ããã°ããåŸ ã£ãŠããéèŠãªæ©èœã§ãã ãããåªå 床ã®é«ãã»ãã¥ãªãã£æ©èœãšèŠãªããv1.13ãªãªãŒã¹ã§å©çšã§ããããã«ããŠãã ããã