kubernetes-the-hard-way/deployments/kubedns.yaml

166 lines
5.2 KiB
YAML
Raw Normal View History

2016-07-09 10:48:08 +03:00
# Copyright 2016 The Kubernetes Authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
2016-09-11 16:20:02 +03:00
apiVersion: extensions/v1beta1
kind: Deployment
2016-07-09 10:48:08 +03:00
metadata:
2017-03-24 18:31:17 +03:00
name: kube-dns
2016-07-09 10:48:08 +03:00
namespace: kube-system
labels:
k8s-app: kube-dns
kubernetes.io/cluster-service: "true"
spec:
2017-03-24 18:31:17 +03:00
# replicas: not specified here:
# 1. In order to make Addon Manager do not reconcile this replicas parameter.
# 2. Default is 1.
# 3. Will be tuned in real time if DNS horizontal auto-scaling is turned on.
strategy:
rollingUpdate:
maxSurge: 10%
maxUnavailable: 0
2016-07-09 10:48:08 +03:00
selector:
2016-09-11 16:20:02 +03:00
matchLabels:
k8s-app: kube-dns
2016-07-09 10:48:08 +03:00
template:
metadata:
labels:
k8s-app: kube-dns
2016-09-11 16:20:02 +03:00
annotations:
scheduler.alpha.kubernetes.io/critical-pod: ''
scheduler.alpha.kubernetes.io/tolerations: '[{"key":"CriticalAddonsOnly", "operator":"Exists"}]'
2016-07-09 10:48:08 +03:00
spec:
containers:
- name: kubedns
2017-03-24 18:31:17 +03:00
image: gcr.io/google_containers/kubedns-amd64:1.9
2016-07-09 10:48:08 +03:00
resources:
# TODO: Set memory limits when we've profiled the container for large
# clusters, then set request = limit to keep this container in
# guaranteed class. Currently, this container falls into the
# "burstable" category so the kubelet doesn't backoff from restarting it.
limits:
2016-09-11 16:20:02 +03:00
memory: 170Mi
2016-07-09 10:48:08 +03:00
requests:
cpu: 100m
2016-09-11 16:20:02 +03:00
memory: 70Mi
2016-07-09 10:48:08 +03:00
livenessProbe:
httpGet:
2016-10-06 21:39:21 +03:00
path: /healthz-kubedns
2016-07-09 10:48:08 +03:00
port: 8080
scheme: HTTP
initialDelaySeconds: 60
timeoutSeconds: 5
successThreshold: 1
failureThreshold: 5
readinessProbe:
httpGet:
path: /readiness
port: 8081
scheme: HTTP
# we poll on pod startup for the Kubernetes master service and
# only setup the /readiness HTTP server once that's available.
2016-10-06 21:39:21 +03:00
initialDelaySeconds: 3
2016-07-09 10:48:08 +03:00
timeoutSeconds: 5
args:
2017-03-24 18:31:17 +03:00
- --domain=cluster.local.
2016-07-09 10:48:08 +03:00
- --dns-port=10053
2017-03-24 18:31:17 +03:00
- --config-map=kube-dns
# This should be set to v=2 only after the new image (cut from 1.5) has
# been released, otherwise we will flood the logs.
- --v=0
env:
- name: PROMETHEUS_PORT
value: "10055"
2016-07-09 10:48:08 +03:00
ports:
- containerPort: 10053
name: dns-local
protocol: UDP
- containerPort: 10053
name: dns-tcp-local
protocol: TCP
2017-03-24 18:31:17 +03:00
- containerPort: 10055
name: metrics
protocol: TCP
2016-07-09 10:48:08 +03:00
- name: dnsmasq
2016-10-06 21:39:21 +03:00
image: gcr.io/google_containers/kube-dnsmasq-amd64:1.4
livenessProbe:
httpGet:
path: /healthz-dnsmasq
port: 8080
scheme: HTTP
initialDelaySeconds: 60
timeoutSeconds: 5
successThreshold: 1
failureThreshold: 5
2016-07-09 10:48:08 +03:00
args:
- --cache-size=1000
- --no-resolv
- --server=127.0.0.1#10053
2016-10-06 21:39:21 +03:00
- --log-facility=-
2016-07-09 10:48:08 +03:00
ports:
- containerPort: 53
name: dns
protocol: UDP
- containerPort: 53
name: dns-tcp
protocol: TCP
2017-03-24 18:31:17 +03:00
# see: https://github.com/kubernetes/kubernetes/issues/29055 for details
resources:
requests:
cpu: 150m
memory: 10Mi
- name: dnsmasq-metrics
image: gcr.io/google_containers/dnsmasq-metrics-amd64:1.0
livenessProbe:
httpGet:
path: /metrics
port: 10054
scheme: HTTP
initialDelaySeconds: 60
timeoutSeconds: 5
successThreshold: 1
failureThreshold: 5
args:
- --v=2
- --logtostderr
ports:
- containerPort: 10054
name: metrics
protocol: TCP
resources:
requests:
memory: 10Mi
2016-07-09 10:48:08 +03:00
- name: healthz
2016-10-06 21:39:21 +03:00
image: gcr.io/google_containers/exechealthz-amd64:1.2
2016-07-09 10:48:08 +03:00
resources:
limits:
2016-09-11 16:20:02 +03:00
memory: 50Mi
2016-07-09 10:48:08 +03:00
requests:
cpu: 10m
2017-03-24 18:31:17 +03:00
# Note that this container shouldn't really need 50Mi of memory. The
# limits are set higher than expected pending investigation on #29688.
# The extra memory was stolen from the kubedns container to keep the
# net memory requested by the pod constant.
2016-09-11 16:20:02 +03:00
memory: 50Mi
2016-07-09 10:48:08 +03:00
args:
2016-10-06 21:39:21 +03:00
- --cmd=nslookup kubernetes.default.svc.cluster.local 127.0.0.1 >/dev/null
- --url=/healthz-dnsmasq
- --cmd=nslookup kubernetes.default.svc.cluster.local 127.0.0.1:10053 >/dev/null
- --url=/healthz-kubedns
- --port=8080
- --quiet
2016-07-09 10:48:08 +03:00
ports:
- containerPort: 8080
protocol: TCP
dnsPolicy: Default # Don't use cluster DNS.