Repository navigation
Add kubelet serving certificate readiness example - #365
kubernetes-prow[bot] merged 5 commits into
Conversation
✅ Deploy Preview for node-readiness-controller canceled.
|
|
Looks like the prow job failed on the docs link check. I verified the files are present in this PR and the failure seems to be because the links point to main where these new files don't exist yet |
|
@arnab-logs could you please update the PR and fix the failing test. Thank you. |
…ntation Updated links to fix prow failures and point to the specific commit for kubelet-cert-readiness manifests and kind-config.yaml.
Updated links in kubelet-cert-readiness.md to point to the latest commit.
|
@Karthik-K-N Fixed the failing test, PR is ready to be merged. PTAL! |
| else | ||
| echo "kubelet serving certificate not yet present at $CERT_PATH" | ||
| exit 1 | ||
| fi No newline at end of file |
There was a problem hiding this comment.
Can we add the missing new lines to all the manifest files.
There was a problem hiding this comment.
I made the necessary changes needed here.
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ajaysundark, arnab-logs The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
7785374 to
d123bf2
Compare
d123bf2 to
310d423
Compare
Karthik-K-N
left a comment
There was a problem hiding this comment.
Thank you
/lgtm
If possible please squash the commits
This PR adds a new example demonstrating how to use NRC to prevent workloads from scheduling on a node until kubelet has obtained its TLS serving certificate.
Includes:
examples/kubelet-cert-readiness/: kind cluster config and manifests (RBAC, NPD ConfigMaps, NPD DaemonSet, NodeReadinessRule)docs/book/src/examples/kubelet-cert-readiness.md: mdBook documentation pagedocs/book/src/SUMMARY.md: adds the new page to the site navigationUse Case
This is in reference to a slack discussion raised in the NRC community. When a node is marked
Ready,kubectl execandkubectl logsmay still fail because kubelet has not yet received its TLS serving certificate, the certificate is issued separately via a CSR and its approval can be delayed on some providers.This causes visible failures in CI/CD environments: GitLab Runner marks jobs as failed when it cannot exec into pods on a new node, and Fluentbit fails to collect logs from kubelet before the certificate is in place.
How to test
Create kind cluster
Install the CRDs and Controller
See the Installation Guide for details
Deploy the Example
Check the startup taint is applied
Check the node condition
Approve the worker's pending CSR to simulate the certificate being issued
kubectl get csr # find the entry with SIGNERNAME kubernetes.io/kubelet-serving and REQUESTOR system:node:<worker-name> kubectl certificate approve <worker-csr-name>Check the condition again
Check taint removal
Confirm
kubectl execworks