Sitelet https://github.com/kubernetes/kops/commit/8b9ba8293bfe15b8fa771be9f08a5b8bc4b18fd9
Skip to content

Commit 8b9ba82

Browse files
Merge pull request #18679 from hakman/coredns-pdb-max-unavailable
coredns: Tighten PDB to maxUnavailable 33% and always allow unhealthy pod eviction
2 parents 548dc75 + 9a55aa0 commit 8b9ba82

167 files changed

Lines changed: 246 additions & 166 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎docs/releases/1.37-NOTES.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,8 @@ As part of this removal, the `protokube` component, whose only remaining respons
3838

3939
* Private cluster asset repositories now also support Azure `azureblob://<account>/<container>/<prefix>` URLs, both for `KOPS_BASE_URL` (nodeup download) and `spec.assets.fileRepository`. Nodes authenticate with their system-assigned managed identity, which has to be granted the `Storage Blob Data Reader` role on the assets container; see the [asset repository documentation](https://kops.sigs.k8s.io/operations/asset-repository/) for the details and warnings.
4040

41+
* The CoreDNS `PodDisruptionBudget` now defaults to `maxUnavailable: 33%` instead of `50%`, so that voluntary disruptions (node drains, rolling updates) always leave at least two DNS pods running when three or more replicas are deployed. The budget also sets `unhealthyPodEvictionPolicy: AlwaysAllow`, allowing CoreDNS pods that are running but not ready to be evicted during node drains instead of blocking them.
42+
4143
# Breaking changes
4244

4345
* Support for AWS Classic Load Balancer (CLB) for the API has been removed. Clusters with `spec.api.loadBalancer.class: Classic` (or with no explicit `class`, which previously defaulted to Classic) fail validation, and the long-deprecated `kops create cluster --api-loadbalancer-class` flag has been removed. Existing clusters using a CLB must migrate to a Network Load Balancer (NLB) using kOps 1.36 or earlier before upgrading to kOps 1.37, following the [CLB to NLB migration guide](https://github.com/kubernetes/kops/blob/master/permalinks/acm_nlb.md). Attaching instance groups to externally-managed Classic Load Balancers via `spec.externalLoadBalancers[].loadBalancerName` remains supported.

‎tests/integration/update_cluster/additionalobjects/data/aws_s3_object_additionalobjects.example.com-addons-bootstrap_content‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ spec:
1212
k8s-addon: kops-controller.addons.k8s.io
1313
- id: k8s-1.12
1414
manifest: coredns.addons.k8s.io/k8s-1.12.yaml
15-
manifestHash: c89f00f91983d51347e920cada21c0d48792dfa4ae32f3eef9e4ebf45495250c
15+
manifestHash: 0b180b32473059784ae4bc805d19bc5596a25a86a84041755b792a4766501627
1616
name: coredns.addons.k8s.io
1717
selector:
1818
k8s-addon: coredns.addons.k8s.io

‎tests/integration/update_cluster/additionalobjects/data/aws_s3_object_additionalobjects.example.com-addons-coredns.addons.k8s.io-k8s-1.12_content‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -249,10 +249,11 @@ metadata:
249249
name: kube-dns
250250
namespace: kube-system
251251
spec:
252-
maxUnavailable: 50%
252+
maxUnavailable: 33%
253253
selector:
254254
matchLabels:
255255
k8s-app: kube-dns
256+
unhealthyPodEvictionPolicy: AlwaysAllow
256257

257258
---
258259

‎tests/integration/update_cluster/apiservernodes/data/aws_s3_object_minimal.example.com-addons-bootstrap_content‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ spec:
1212
k8s-addon: kops-controller.addons.k8s.io
1313
- id: k8s-1.12
1414
manifest: coredns.addons.k8s.io/k8s-1.12.yaml
15-
manifestHash: c89f00f91983d51347e920cada21c0d48792dfa4ae32f3eef9e4ebf45495250c
15+
manifestHash: 0b180b32473059784ae4bc805d19bc5596a25a86a84041755b792a4766501627
1616
name: coredns.addons.k8s.io
1717
selector:
1818
k8s-addon: coredns.addons.k8s.io

‎tests/integration/update_cluster/apiservernodes/data/aws_s3_object_minimal.example.com-addons-coredns.addons.k8s.io-k8s-1.12_content‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -249,10 +249,11 @@ metadata:
249249
name: kube-dns
250250
namespace: kube-system
251251
spec:
252-
maxUnavailable: 50%
252+
maxUnavailable: 33%
253253
selector:
254254
matchLabels:
255255
k8s-app: kube-dns
256+
unhealthyPodEvictionPolicy: AlwaysAllow
256257

257258
---
258259

‎tests/integration/update_cluster/aws-lb-controller/data/aws_s3_object_minimal.example.com-addons-bootstrap_content‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ spec:
1212
k8s-addon: kops-controller.addons.k8s.io
1313
- id: k8s-1.12
1414
manifest: coredns.addons.k8s.io/k8s-1.12.yaml
15-
manifestHash: c89f00f91983d51347e920cada21c0d48792dfa4ae32f3eef9e4ebf45495250c
15+
manifestHash: 0b180b32473059784ae4bc805d19bc5596a25a86a84041755b792a4766501627
1616
name: coredns.addons.k8s.io
1717
selector:
1818
k8s-addon: coredns.addons.k8s.io

‎tests/integration/update_cluster/aws-lb-controller/data/aws_s3_object_minimal.example.com-addons-coredns.addons.k8s.io-k8s-1.12_content‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -249,10 +249,11 @@ metadata:
249249
name: kube-dns
250250
namespace: kube-system
251251
spec:
252-
maxUnavailable: 50%
252+
maxUnavailable: 33%
253253
selector:
254254
matchLabels:
255255
k8s-app: kube-dns
256+
unhealthyPodEvictionPolicy: AlwaysAllow
256257

257258
---
258259

‎tests/integration/update_cluster/bastionadditional_user-data/data/aws_s3_object_bastionuserdata.example.com-addons-bootstrap_content‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ spec:
1212
k8s-addon: kops-controller.addons.k8s.io
1313
- id: k8s-1.12
1414
manifest: coredns.addons.k8s.io/k8s-1.12.yaml
15-
manifestHash: c89f00f91983d51347e920cada21c0d48792dfa4ae32f3eef9e4ebf45495250c
15+
manifestHash: 0b180b32473059784ae4bc805d19bc5596a25a86a84041755b792a4766501627
1616
name: coredns.addons.k8s.io
1717
selector:
1818
k8s-addon: coredns.addons.k8s.io

‎tests/integration/update_cluster/bastionadditional_user-data/data/aws_s3_object_bastionuserdata.example.com-addons-coredns.addons.k8s.io-k8s-1.12_content‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -249,10 +249,11 @@ metadata:
249249
name: kube-dns
250250
namespace: kube-system
251251
spec:
252-
maxUnavailable: 50%
252+
maxUnavailable: 33%
253253
selector:
254254
matchLabels:
255255
k8s-app: kube-dns
256+
unhealthyPodEvictionPolicy: AlwaysAllow
256257

257258
---
258259

‎tests/integration/update_cluster/cluster-autoscaler-priority-expander-custom/data/aws_s3_object_cas-priority-expander-custom.example.com-addons-bootstrap_content‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ spec:
1212
k8s-addon: kops-controller.addons.k8s.io
1313
- id: k8s-1.12
1414
manifest: coredns.addons.k8s.io/k8s-1.12.yaml
15-
manifestHash: c89f00f91983d51347e920cada21c0d48792dfa4ae32f3eef9e4ebf45495250c
15+
manifestHash: 0b180b32473059784ae4bc805d19bc5596a25a86a84041755b792a4766501627
1616
name: coredns.addons.k8s.io
1717
selector:
1818
k8s-addon: coredns.addons.k8s.io

0 commit comments

Comments
 (0)