Commit Graph
100 Commits
Author SHA1 Message Date
yeasy 2185211041 fix(07): note FROM uses pre-FROM ARG, not ENV, for variable substitution 2026-05-28 11:38:27 -07:00
yeasy f09e800020 fix(content): harden copy-paste safety examples 2026-05-27 18:17:24 -07:00
yeasy 3a9ee19d22 docs(content): refresh Kubernetes helper versions 2026-05-26 00:45:20 -07:00
yeasy ea26f96297 fix(content): remove demo registry credential 2026-05-25 01:13:10 -07:00
yeasy 30f26d9195 chore(17): remove obsolete coreos_README.md leftover
This 7-line file was never in SUMMARY.md and its content is a strict
subset of the current 17.1_coreos_intro.md. It looks like a draft
that survived the chapter rename to NN.M_topic.md convention.
Removed so the directory only contains files reachable from the ToC.
2026-05-24 12:56:55 -07:00
yeasy fb361bb1f0 fix(appendix): use H2 for 附录七 to match sibling appendix files
The other appendix entries (附录四 best_practices, 附录五 debug,
附录六 resources, 附录八 learning_roadmap) all use H2. glossary.md
was the lone H1, which broke the table-of-contents nesting in
GitBook. Demoted to H2 to align.
2026-05-24 01:03:34 -07:00
yeasy 036f0486db fix(content): tighten safety guidance 2026-05-24 00:57:03 -07:00
yeasy 28c23d003e fix(content): harden Docker examples 2026-05-23 21:28:59 -07:00
yeasy 6a55219310 fix(11.3): use COPY (not ADD) in Flask/Redis intro Dockerfile
§7.3 of this book explicitly recommends COPY over ADD for simple
file copies ("在大多数情况下,你应该使用 COPY,而不是 ADD"). The intro
Compose example showed ADD without needing tar extraction or URL
download, contradicting the canonical guidance. Switched to COPY
so the first Dockerfile readers see matches the rule the book
teaches a few chapters later.
2026-05-23 21:27:01 -07:00
yeasy 8f4d88e350 docs: refine Buildx guidance 2026-05-22 07:58:38 -07:00
yeasy 7f83abc53b fix(content): correct Docker Engine 29.0.0 date and align login-action version
Docker Engine 29.0.0 was released 2025-11-10 per docs.docker.com release
notes, not 2025-11-11 (off by one day). Also bring docker/login-action
reference in 18.6 up to v4 to match the 21.2 example (v4 has been current
since 2026-03-04).
2026-05-22 03:19:37 -07:00
yeasy ec0fa15835 docs(content): harden Kubernetes and supply-chain examples 2026-05-22 00:53:38 -07:00
yeasy 8b9e4518c8 docs(content): add Mac alternatives, K8s transition guide, CI/CD registry push example
- Add OrbStack/Colima comparison table to Mac install chapter (3.7.4)
- Add Docker→K8s concept mapping paragraph to Ch13 intro
- Add KubeKey/RKE2 deployment tool notes to Ch14
- Add production image checklist to Dockerfile chapter summary
- Add build-and-push-to-registry workflow example to GitHub Actions section
- Expand Ch18 security summary with dimension table
2026-05-21 21:33:58 -07:00
yeasy dae0af9ae7 fix(content): DCT expiry tense + bundle buildx --check additions 2026-05-21 20:49:42 -07:00
yeasy 10b09f35eb fix(content): update DCT expiry tense and prefer named multistage COPY 2026-05-21 20:49:19 -07:00
yeasy e17bef96d2 docs(content): update Compose and safety guidance 2026-05-21 20:13:39 -07:00
yeasy a3567ff6a0 docs: use digest-based cosign signing 2026-05-21 19:14:33 -07:00
yeasy 9ef842ebb3 docs: update distro caveats 2026-05-21 18:25:54 -07:00
yeasy 2e625a3cdf fix(content): harden install and security guidance 2026-05-21 01:23:44 -07:00
yeasy d47afa7e75 docs: harden Docker practice security examples 2026-05-20 15:58:46 -07:00
yeasy 1b651e5f8c fix(content): refresh Docker and Kubernetes guidance 2026-05-20 09:16:36 -07:00
yeasy e91fe87822 fix(content): harden kubernetes and signing examples 2026-05-20 08:49:28 -07:00
yeasy bb97d5a46a fix(13.2): remove incorrect "Node lifecycle" (Pending/Running/Terminated)
The "节点周期" subsection listed `Pending`/`Running`/`Terminated` as
node phases, but those are **Pod** phases (pod.status.phase). Kubernetes
nodes use Conditions (Ready/MemoryPressure/DiskPressure/PIDPressure)
not phases; there is no "Terminated" node state. Removed the
misleading subsection and clarified the surviving "节点状态" section
with an explicit note distinguishing Pod phases from node conditions,
and added the eviction behavior when a node becomes Unknown.
2026-05-20 08:37:43 -07:00
yeasy 1f69884c8f Fix Chinese quote formatting 2026-05-20 08:02:42 -07:00
yeasy 4f92b3aa70 fix(19.3): add security trade-off note for cAdvisor privileged: true
The cAdvisor compose examples in 19.3.3 use `privileged: true`, which
contradicts the minimum-privilege / cap_drop=all guidance in chapter 18.
Add an explicit trade-off note before the first cAdvisor snippet
explaining the inconsistency and pointing to 18.4 for capability-based
hardening alternatives (cap_add: [SYS_ADMIN] + device_cgroup_rules
instead of full privileged mode).

This addresses the Round 1 review finding about pedagogical conflict
between the monitoring and security chapters.
2026-05-20 00:18:37 -07:00
yeasy 58504e9316 fix(review-fixes): surgical content corrections from web-verified library deep review 2026-05-19 19:45:02 -07:00
yeasy 4075330dba Fix architecture mermaid and MySQL version 2026-05-19 18:43:11 -07:00
yeasy e6bf228066 docs: update image signing and login guidance 2026-05-19 15:29:26 -07:00
yeasy 1b15b65bc5 Clarify AKS pricing tiers 2026-05-19 08:20:49 -07:00
yeasy 26da467052 docs: link deployment engineering guide 2026-05-18 22:37:02 -07:00
yeasy 7abaff237a test: add project rules check 2026-05-18 22:37:02 -07:00
yeasy 1c4e0538d8 Fix CI PDF order 2026-05-18 08:06:51 -07:00
yeasy 0b8f6e9b60 Refresh metadata and workflows 2026-05-18 07:38:58 -07:00
yeasy 5650315cb4 Remove demo TLS key 2026-05-17 20:28:01 -07:00
yeasy e21794ebde Fix stale image facts 2026-05-17 20:28:01 -07:00
yeasy 78ca8f6d19 Refresh Docker ecosystem 2026-05-16 14:09:31 -07:00
yeasy 1ba904a9ff Fix markdown format issues 2026-05-15 09:58:19 -07:00
yeasy 705d162f05 Fix image docs typos 2026-05-15 09:16:33 -07:00
yeasy 92be0050fd Fix docker debug note, Go modules, Compose V2, CentOS Quay migration 2026-05-15 08:11:38 +00:00
yeasy a20d1b19c4 Fix 3 broken external links in appendix 2026-05-14 02:27:32 +00:00
yeasy 9f481e88ca Fix go mod, Docker Hub rate limit, Compose verbose, docker debug, htpasswd security 2026-05-13 08:30:20 +00:00
yeasy ef5a97fa09 Fix VirtioFS note, cri-socket, componentstatuses, ES version and typo 2026-05-13 08:26:24 +00:00
yeasy 3c5c5911b0 Fix nginx version, IPVS removal, cgroups v2 and Redis config 2026-05-13 08:22:20 +00:00
yeasy e2742313f2 Fix typo in Fedora install guide 2026-05-08 21:20:03 +00:00
yeasy 2cea196860 Replace chromium-browser snap with setup-chrome 2026-05-08 04:19:18 +00:00
yeasy 13fc8b34f0 Explain why docker run overrides crashing CMD 2026-05-08 04:13:09 +00:00
yeasy 29742c8f74 Clarify interactive debug uses new container 2026-05-08 04:10:38 +00:00
yeasy 7cae0b6bb3 Fix deprecated TLS protocols and mongo CLI 2026-05-03 15:20:57 +00:00
yeasy 10381deee4 Add healthcheck to Rails Compose example 2026-05-03 05:23:12 +00:00
yeasy 625d209fa8 Fix Docker Engine 29 release date and Rootless mode history 2026-05-02 22:26:19 +00:00
yeasy b148d9efa9 Update nginx to 1.30 stable, add IPVS deprecation note 2026-05-02 18:18:48 +00:00
yeasy 4cb91a75f3 Update etcd cluster demo to v3.5.29, Node to 22 LTS 2026-05-02 16:16:59 +00:00
yeasy bf3107b775 Update MySQL 8.0 to 8.4 LTS, fix Trivy tag count 2026-05-02 15:22:58 +00:00
yeasy 7e3f90b522 Update Node base images to 22 LTS 2026-05-01 10:24:43 +00:00
yeasy e6527ae769 Fix Docker Engine 29 release date 2026-05-01 07:17:56 +00:00
yeasy 9c378b1ef9 Use straight quotes in kubectl annotate examples 2026-04-30 19:18:49 +00:00
yeasy 340c8c9e61 Document ipvlan driver and update etcdctl v3 options 2026-04-30 09:20:59 +00:00
yeasy 89c2690a62 Correct Docker Engine 29 release date 2026-04-29 10:24:06 +00:00
yeasy c554799b08 Restore nginx 1.30 stable references 2026-04-29 07:53:31 +00:00
yeasy 99c56217f5 Fix Chinese curly quote direction 2026-04-29 05:21:02 +00:00
yeasy 9c98e35c62 Fix nginx version to 1.28 stable 2026-04-28 16:15:39 +00:00
yeasy 0e0afbd4d3 Update nginx to 1.30 and version references 2026-04-28 14:15:13 +00:00
yeasy 30f0115cb9 Update nginx, OS, Buildx, etcd and K8s refs 2026-04-28 12:22:57 +00:00
yeasy 62f48c1417 Update nginx, Debian, Ubuntu, Fedora, Docker versions 2026-04-28 11:14:55 +00:00
yeasy fab4e41587 Update OS examples to Debian 13, Ubuntu 26.04, Fedora 43 2026-04-28 09:24:17 +00:00
yeasy 229aec2f1e Update Kubernetes node status conditions terminology 2026-04-28 09:24:17 +00:00
yeasy 8ebf284f9e Update nginx references from 1.25 to 1.30 2026-04-28 09:24:03 +00:00
yeasy a89f7285c7 Fix typos and update Docker Hub limits and versions 2026-04-28 09:15:40 +00:00
yeasy 15c7fe1dc2 Update Docker Hub rate limits and version refs 2026-04-28 08:20:21 +00:00
yeasy 4d1e323faf Fix seccomp typo, postgres path and DCA exam details 2026-04-28 04:21:10 +00:00
yeasy 16203c5018 Complete Dockerfile instruction reference list 2026-04-27 23:17:39 +00:00
yeasy 3d3befa16a Add ipvlan driver and update EKS pricing 2026-04-27 22:45:17 +00:00
yeasy 09fd556c18 Refresh image CLI docs 2026-04-27 09:15:19 -07:00
yeasy 37e376d578 Fix mongosh, DCA price, compose healthcheck and cleanup 2026-04-27 14:17:57 +00:00
yeasy 04fd53ea3c Update Docker image tags and etcd commands 2026-04-27 11:18:08 +00:00
yeasy b1cd2f0878 Fix Docker Hub rate limits and etcdctl API version 2026-04-27 05:13:02 +00:00
yeasy e416a1be7e Fix Docker Hub rate limits, DCT timeline, image tags, etcd and Alertmanager 2026-04-27 01:15:52 +00:00
yeasy e406ed9185 Update Gateway API docs and image security practices 2026-04-26 00:18:39 +00:00
yeasy c36c420c7e Add nftables support and Time namespace documentation 2026-04-26 00:18:39 +00:00
yeasy 72513eb673 更新 Namespace/Gateway API/nftables/DCT 退役时间线
- ch12: 添加 TIME namespace (Linux 5.6+),内核 namespace 类型从 7 更新为 8
- ch12: 补充 Docker Engine v29.x 实���性 nftables 支持
- ch13: Ingress-NGINX 退役通知,添加 Gateway API 推荐方案和示例
- ch13: 添加 Pod Security Standards 章节(替代已移除的 PSP)
- ch18: 补充 DCT 退役时间线(2028-03-31 完全移除)和迁移建议
2026-04-26 00:12:59 +00:00
yeasy 8ea52620cc Update Prometheus to v3.11.2, fix etcdctl version 2026-04-25 22:39:33 +00:00
yeasy 22dd236122 Fix network IPs, compose healthcheck, update GH Actions versions 2026-04-25 21:11:50 +00:00
yeasy 98f4f7b1e5 Add official doc links to install guides 2026-04-25 21:11:50 +00:00
yeasy 87bb4b2ceb Add version notes and image tag best practices 2026-04-25 21:11:50 +00:00
yeasy dad26ccb28 Update docker0 default subnet to 172.17.0.0/16 2026-04-25 21:03:39 +00:00
yeasy 84a801f3ac Document depends_on condition and healthcheck 2026-04-25 21:03:39 +00:00
yeasy 420a5776ce Accurate cgroup v2 description, update Actions versions 2026-04-25 20:42:35 +00:00
yeasy b2839f735c Fix broken code block in laravel multistage Dockerfile 2026-04-25 20:42:18 +00:00
yeasy 98e299a38e Add version notes and official doc links 2026-04-25 15:58:42 +00:00
Baohua Yang aa204fb454 chore: lint cleanup and version corrections
- Accept benign linter changes (version notes, explicit tags, formatting)
- Fix incorrect version downgrades introduced by linter:
  - golang:1.22→1.26 (restored)
  - rust:1.82→1.95 (restored)
- 23 files updated
2026-04-25 15:58:27 +00:00
yeasy 1e9cdeea3f Update Grafana to v13, add version notes 2026-04-25 15:50:13 +00:00
yeasy 515ba9f64a Add blank lines before lists per CommonMark 2026-04-25 15:13:27 +00:00
yeasy 9abc1cbb69 Update Kubernetes to v1.36, build-push-action to v7 2026-04-25 15:10:51 +00:00
yeasy 839a63f5af Update versions and fix formatting issues 2026-04-25 15:10:43 +00:00
yeasy 20a3479f8a Add Docker Scout, remove deprecated type_name 2026-04-25 15:02:24 +00:00
yeasy 52329fee5a Update etcd to v3.5.29 2026-04-25 15:00:47 +00:00
yeasy 8093b198ce Update node-exporter to v1.11.1, fcct to butane 2026-04-25 14:58:40 +00:00
yeasy 77a537df54 Add blank lines before lists per CommonMark 2026-04-25 14:57:09 +00:00
yeasy e414d9475b Update containerd config path for 2.x 2026-04-25 14:22:55 +00:00
yeasy 037591e5af Update content and fix issues 2026-04-25 02:14:58 +00:00