Compare commits

..
66 Commits
Author SHA1 Message Date
yeasy 6080b09a83 Complete Dockerfile instruction reference list 2026-04-27 23:17:39 +00:00
yeasy 11ad9720bc Add ipvlan driver and update EKS pricing 2026-04-27 22:45:17 +00:00
yeasy cb117e017f Refresh image CLI docs 2026-04-27 09:15:19 -07:00
yeasy 2bed4cdb09 Fix mongosh, DCA price, compose healthcheck and cleanup 2026-04-27 14:17:57 +00:00
yeasy 31c2a515dd Update Docker image tags and etcd commands 2026-04-27 11:18:08 +00:00
yeasy b9901aaa1c Fix Docker Hub rate limits and etcdctl API version 2026-04-27 05:13:02 +00:00
yeasy be6f77231e Fix Docker Hub rate limits, DCT timeline, image tags, etcd and Alertmanager 2026-04-27 01:15:52 +00:00
yeasy 5929053959 Update Gateway API docs and image security practices 2026-04-26 00:18:39 +00:00
yeasy 8c438f000f Add nftables support and Time namespace documentation 2026-04-26 00:18:39 +00:00
yeasy 78f52701b0 更新 Namespace/Gateway API/nftables/DCT 退役时间线
- ch12: 添加 TIME namespace (Linux 5.6+),内核 namespace 类型从 7 更新为 8
- ch12: 补充 Docker Engine v29.x 实���性 nftables 支持
- ch13: Ingress-NGINX 退役通知,添加 Gateway API 推荐方案和示例
- ch13: 添加 Pod Security Standards 章节(替代已移除的 PSP)
- ch18: 补充 DCT 退役时间线(2028-03-31 完全移除)和迁移建议
2026-04-26 00:12:59 +00:00
yeasy b409945aea Update Prometheus to v3.11.2, fix etcdctl version 2026-04-25 22:39:33 +00:00
yeasy d667936a87 Fix network IPs, compose healthcheck, update GH Actions versions 2026-04-25 21:11:50 +00:00
yeasy 693124672f Add official doc links to install guides 2026-04-25 21:11:50 +00:00
yeasy 619883f87e Add version notes and image tag best practices 2026-04-25 21:11:50 +00:00
yeasy cff1476270 Update docker0 default subnet to 172.17.0.0/16 2026-04-25 21:03:39 +00:00
yeasy dfb5d3fec3 Document depends_on condition and healthcheck 2026-04-25 21:03:39 +00:00
yeasy c4fac49ae7 Accurate cgroup v2 description, update Actions versions 2026-04-25 20:42:35 +00:00
yeasy aa7ab1f20d Fix broken code block in laravel multistage Dockerfile 2026-04-25 20:42:18 +00:00
yeasy 7a826d56dd Add version notes and official doc links 2026-04-25 15:58:42 +00:00
Baohua Yang 016539c86a chore: lint cleanup and version corrections
- Accept benign linter changes (version notes, explicit tags, formatting)
- Fix incorrect version downgrades introduced by linter:
  - golang:1.22→1.26 (restored)
  - rust:1.82→1.95 (restored)
- 23 files updated
2026-04-25 15:58:27 +00:00
yeasy ec4ab5232b Update Grafana to v13, add version notes 2026-04-25 15:50:13 +00:00
yeasy 81b49cb00c Add blank lines before lists per CommonMark 2026-04-25 15:13:27 +00:00
yeasy 1069a8562a Update Kubernetes to v1.36, build-push-action to v7 2026-04-25 15:10:51 +00:00
yeasy d2ae7f3a78 Update versions and fix formatting issues 2026-04-25 15:10:43 +00:00
yeasy 1752249b38 Add Docker Scout, remove deprecated type_name 2026-04-25 15:02:24 +00:00
yeasy f23900a526 Update etcd to v3.5.29 2026-04-25 15:00:47 +00:00
yeasy 83744eec32 Update node-exporter to v1.11.1, fcct to butane 2026-04-25 14:58:40 +00:00
yeasy db2f015ba7 Add blank lines before lists per CommonMark 2026-04-25 14:57:09 +00:00
yeasy 28864a3349 Update containerd config path for 2.x 2026-04-25 14:22:55 +00:00
yeasy ef78056e41 Update content and fix issues 2026-04-25 02:14:58 +00:00
yeasy b2218f7728 Clarify image build semantics 2026-04-24 10:51:49 -07:00
yeasy 2e7f7d7227 Fix straight quotes to curly quotes in mirror doc 2026-04-24 13:24:52 +00:00
yeasy 7781e53725 Fix Ubuntu codenames and containerd LTS description 2026-04-24 03:16:05 +00:00
yeasy d9f49e55fe Fix apt cache cleanup path in Dockerfile example 2026-04-23 13:16:21 -07:00
yeasy ae7aaaab1b Pin Prometheus and Grafana image versions 2026-04-22 12:24:31 -07:00
yeasy 4b4fe377dc Add runC CVEs and AuthZ plugin guidance 2026-04-22 12:24:31 -07:00
yeasy 985a9fa8b3 Add section numbers to ecosystem headings 2026-04-22 12:24:30 -07:00
yeasy adbb6f4406 Update nginx version and K8s dashboard date 2026-04-22 12:24:30 -07:00
yeasy 0ba22eb779 Fix Debian dates and FAQ template syntax 2026-04-22 08:43:48 -07:00
yeasy e42b004bdd Refresh install guidance
# Conflicts:
#	03_install/3.1_ubuntu.md
#	03_install/3.2_debian.md
#	03_install/3.3_fedora.md
#	03_install/3.9_mirror.md
2026-04-22 08:24:38 -07:00
yeasy 9a06a18f92 Refresh k8s docker versions and references 2026-04-21 20:57:33 -07:00
yeasy 318de33fd4 Refine Docker concepts 2026-04-21 14:39:41 -07:00
yeasy 56645ca150 Add new content and update versions 2026-04-19 22:35:33 -07:00
yeasy 0435cfb90f Drop legacy plugins 2026-04-19 20:14:36 -07:00
yeasy 292ce02df2 Clarify intro chapter 2026-04-18 20:25:29 -07:00
yeasy c6e1485798 Update software versions and fix security refs 2026-04-18 19:04:14 -07:00
yeasy c6f91f987c Fix mermaid syntax and update K8s taint labels 2026-04-18 15:17:56 -07:00
yeasy 139057640e Update Kind v0.31.0 and Flannel v0.28.2 2026-04-18 13:31:43 -07:00
yeasy fc2212044c Restructure README with badges and cover 2026-04-17 21:51:38 -07:00
yeasy 808afe5b4d Add Ubuntu 20.04 EOL exact date 2026-04-17 21:19:32 -07:00
yeasy 618a808989 Update versions and fix stale data 2026-04-17 21:17:12 -07:00
github-actions[bot]andGitHub 0befead941 Merge pull request #564 from yeasy/dependabot/github_actions/dependencies-8fe05ed821
chore(deps): bump the dependencies group with 2 updates
2026-04-15 18:46:57 +00:00
dependabot[bot]andGitHub 8999830f87 chore(deps): bump the dependencies group with 2 updates
Bumps the dependencies group with 2 updates: [softprops/action-gh-release](https://github.com/softprops/action-gh-release) and [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).


Updates `softprops/action-gh-release` from 2 to 3
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](https://github.com/softprops/action-gh-release/compare/v2...v3)

Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](https://github.com/dependabot/fetch-metadata/compare/v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: dependabot/fetch-metadata
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-15 18:46:44 +00:00
yeasy cb2287376b Fix Chinese curly quotes in prose text 2026-04-14 20:29:35 -07:00
yeasy f788740f47 Fix figure caption punctuation and table formatting 2026-04-13 18:37:00 -07:00
yeasy 8a1801f89e Fix figure caption format 2026-04-09 09:02:44 -07:00
yeasy 69dd935053 Add section numbering and archive notice 2026-04-08 22:40:15 -07:00
yeasy d1399c2fa5 Fix bash comment style to single hash 2026-04-08 22:39:51 -07:00
yeasy a699ab2e44 Fix mdpress port 4000 to 9000 2026-04-05 13:39:46 -07:00
yeasy 0cbd7cf712 Fix typo in offline install image alt text 2026-04-05 12:59:09 -07:00
yeasy 9c65552931 Remove time annotation in install docs 2026-04-05 12:58:42 -07:00
yeasy 5add3d1918 Remove duplicate release-pdf workflow 2026-04-05 08:55:52 -07:00
yeasy de330b0c8a Add release-pdf CI workflow for automated PDF builds 2026-04-05 08:29:11 -07:00
yeasy 41819cb474 Replace defunct AtomHub mirror with docker.1ms.run 2026-04-05 08:16:08 -07:00
yeasy a5c1d25127 ci: add auto-release.yml, remove release-pdf.yml, limit CI trigger to master 2026-04-05 07:57:56 -07:00
Baohua Yang a9caffe7d8 Add recommended reading paths table to README 2026-04-04 22:31:23 -07:00
18 changed files with 160 additions and 51 deletions
+1 -1
View File
@@ -255,7 +255,7 @@ someuser/myapp # ⚠️ 需要评估
#### 镜像签名
当前更推荐使用 Sigstore / Notation 体系进行镜像签名与验证`Docker Content Trust (DCT)` 2025 8 8 开始停用官方 Docker 镜像已停止 DCT 签名2028 3 31 日将完全删除此功能不建议作为新项目方案
当前更推荐使用 Sigstore / Notation 体系进行镜像签名与验证`Docker Content Trust (DCT)` 进入弃用阶段2025 8 8 起最早的 DCT 签名证书开始过期2025 9 30 日起不能在新 Registry 启用 DCT2028 3 31 日将完全删除此功能不建议作为新项目方案
> 注意Cosign 默认会把签名推送回镜像所在仓库请使用你有推送权限的镜像地址
+4 -4
View File
@@ -67,15 +67,15 @@ $ docker push username/myapp:v1
#### 镜像拉取限制
Docker Hub 对不同类型用户实施拉取速率限制2025 4 月起更新
Docker Hub 对不同类型用户实施拉取速率限制基于 6 小时周期
| 用户类型 | 限制 |
|---------|------|
| **匿名用户** (未登录) | 每小时 10 次请求 |
| **免费账户** (已登录) | 每小时 100 次请求 |
| **匿名用户** (未登录) | 6 小时 100 次请求 |
| **免费账户** (已登录) | 6 小时 200 次请求 |
| **Pro/Team/Business 账户** | 无限制公平使用政策 |
> **注意**2025 4 月前的旧限制为匿名用户每 6 小时 100 免费账户每 6 小时 200 新政策大幅收紧了匿名拉取额度建议在 CI/CD 环境中始终配置 `docker login`
> **注意** 2025 4 月起所有付费订阅用户享有无限制拉取额度匿名用户和免费账户的限制保持不变建议在 CI/CD 环境中始终配置 `docker login` 以获得更高的拉取额度
#### 滥用限流
+13 -5
View File
@@ -14,12 +14,20 @@ Dockerfile 中的常用指令包括:
- **FROM**: 指定基础镜像必须是第一条指令
- **RUN**: 在镜像中执行命令用于安装软件包等
- **WORKDIR**: 设置工作目录
- **COPY/ADD**: 复制文件到镜像中
- **EXPOSE**: 声明容器监听的端口
- **ENV**: 设置环境变量
- **ENTRYPOINT**: 容器启动时的入口点
- **COPY**: 复制文件到镜像中
- **ADD**: 更高级的复制文件支持 URL 和自动解压
- **CMD**: 容器默认执行的命令
- **ENTRYPOINT**: 容器启动时的入口点
- **ENV**: 设置环境变量
- **ARG**: 构建时的参数变量
- **VOLUME**: 定义匿名卷挂载点
- **EXPOSE**: 声明容器监听的端口
- **WORKDIR**: 设置工作目录
- **USER**: 指定运行容器时的用户
- **HEALTHCHECK**: 配置容器健康检查
- **ONBUILD**: 设置触发器指令在子镜像构建时执行
- **LABEL**: 为镜像添加元数据标签
- **SHELL**: 指定 RUN 等指令使用的 shell
### 最佳实践建议
+3 -3
View File
@@ -68,7 +68,7 @@ RUN go get -d -v github.com/go-sql-driver/mysql \
编写 `Dockerfile.copy` 文件
```docker
FROM alpine:latest
FROM alpine:3
RUN apk --no-cache add ca-certificates
@@ -131,7 +131,7 @@ COPY app.go .
RUN CGO_ENABLED=0 GOOS=linux go build -a -installsuffix cgo -o app .
FROM alpine:latest as prod
FROM alpine:3 as prod
RUN apk --no-cache add ca-certificates
@@ -176,5 +176,5 @@ $ docker build --target builder -t username/imagename:tag .
上面例子中我们使用 `COPY --from=0 /go/src/github.com/go/helloworld/app .` 从上一阶段的镜像中复制文件我们也可以复制任意镜像中的文件
```docker
COPY --from=nginx:latest /etc/nginx/nginx.conf /nginx.conf
COPY --from=nginx:1.25-alpine /etc/nginx/nginx.conf /nginx.conf
```
@@ -61,7 +61,7 @@ server {
```docker
# 注:node 镜像推荐使用具体的版本标签(如 node:20-alpine
FROM node:alpine as frontend
FROM node:20-alpine as frontend
COPY package.json /app/
@@ -83,7 +83,7 @@ RUN set -x ; cd /app \
```docker
# 注:composer 镜像推荐使用具体的版本标签(如 composer:2.x
FROM composer as composer
FROM composer:2 as composer
COPY database/ /app/database/
COPY composer.json composer.lock /app/
@@ -129,7 +129,7 @@ RUN set -x ; cd ${LARAVEL_PATH} \
```docker
# 注:nginx 镜像推荐使用具体的版本标签(如 nginx:1.25-alpine
FROM nginx:alpine as nginx
FROM nginx:1.25-alpine as nginx
ARG LARAVEL_PATH=/app/laravel
@@ -180,7 +180,7 @@ $ docker run -dit --rm --network=laravel -p 8080:80 my/nginx
```docker
# 注:生产环境推荐使用具体的版本标签,如 node:20-alpine、composer:2.x、php:8.3-fpm-alpine、nginx:1.25-alpine
FROM node:alpine as frontend
FROM node:20-alpine as frontend
COPY package.json /app/
@@ -195,7 +195,7 @@ RUN set -x ; cd /app \
&& mkdir -p public \
&& npm run production
FROM composer as composer
FROM composer:2 as composer
COPY database/ /app/database/
COPY composer.json composer.lock /app/
@@ -229,8 +229,7 @@ RUN set -x ; cd ${LARAVEL_PATH} \
&& chmod -R 777 storage \
&& php artisan package:discover
FROM nginx:alpine as nginx
```
FROM nginx:1.25-alpine as nginx
ARG LARAVEL_PATH=/app/laravel
@@ -1,4 +1,4 @@
FROM node:alpine as frontend
FROM node:20-alpine as frontend
COPY package.json /app/
@@ -13,7 +13,7 @@ RUN set -x ; cd /app \
&& mkdir -p public \
&& npm run production
FROM composer as composer
FROM composer:2 as composer
COPY database/ /app/database/
COPY composer.json /app/
@@ -47,7 +47,7 @@ RUN set -x ; cd ${LARAVEL_PATH} \
&& chmod -R 777 storage \
&& php artisan package:discover
FROM nginx:alpine as nginx
FROM nginx:1.25-alpine as nginx
ARG LARAVEL_PATH=/app/laravel
+37 -1
View File
@@ -132,7 +132,43 @@ services:
db:
image: postgres
```
> 注意`web` 服务不会等待 `redis` `db` 完全启动 之后才启动
> 注意上述简写形式中`web` 服务不会等待 `redis` `db` 完全启动 之后才启动
如果需要等待依赖服务就绪可以使用 `condition` 字段配合 `healthcheck`
```yaml
services:
web:
build: .
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
redis:
image: redis
healthcheck:
test: [“CMD”, “redis-cli”, “ping”]
interval: 5s
timeout: 3s
retries: 5
db:
image: postgres
healthcheck:
test: [“CMD-SHELL”, “pg_isready -U postgres”]
interval: 5s
timeout: 3s
retries: 5
```
`condition` 支持三个值
* `service_started`容器启动即满足默认
* `service_healthy`容器的 `healthcheck` 状态为 healthy 时满足
* `service_completed_successfully`容器成功退出退出码为 0时满足适用于初始化任务等一次性容器
### 11.5.10 `dns`
+1
View File
@@ -101,6 +101,7 @@ flowchart TD
- **Containerd 镜像存储 (Image Store)** v29.x 的新安装场景中默认启用Docker 直接使用 Containerd 的镜像管理能力不再维护自己的一套 graphdriver
- **优势**多平台镜像支持更好镜像拉取更快 (lazy pulling) K8s 共享镜像
- **实验性 nftables 支持**随着主流 Linux 发行版逐步弃用 iptablesDocker v29.x 引入了实验性 nftables 后端启用方式为 `dockerd --firewall-backend=nftables`可直接创建 nftables 规则而无需依赖 iptables-nft 转换层生产环境请谨慎使用
---
+3 -2
View File
@@ -28,7 +28,7 @@ flowchart LR
### 12.2.2 Namespace 的类型
Linux 内核提供了以下几 NamespaceDocker 容器使用了全部
Linux 内核5.6+共提供 8 NamespaceDocker 容器默认使用其中 7 不含 Time
| Namespace | 隔离内容 | 容器中的效果 |
|-----------|---------|-------------|
@@ -39,6 +39,7 @@ Linux 内核提供了以下几种 Namespace,Docker 容器使用了全部:
| **IPC** | 进程间通信 | 独立的信号量消息队列共享内存 |
| **USER** | 用户/ ID | 容器内的 root 可以映射为宿主机的普通用户 |
| **Cgroup** | Cgroup 根目录 | 隔离 cgroup 层级视图 (Linux 4.6+)|
| **Time** | 系统时钟 | 隔离 CLOCK_MONOTONIC CLOCK_BOOTTIME (Linux 5.6+)|
---
@@ -290,7 +291,7 @@ Namespace 提供了隔离但不是安全边界:
| 方面 | 说明 |
|------|------|
| **共享内核** | 所有容器共享宿主机内核内核漏洞可能影响所有容器 |
| **部分资源未隔离** | /proc/sys 部分内容仍可见时间无法隔离 |
| **部分资源未隔离** | /proc/sys 部分内容仍可见Time Namespace (Linux 5.6+) 虽已可用 Docker 默认不启用 |
| **非虚拟化** | 比虚拟机隔离性弱 |
> 需要更强隔离时可考虑 gVisorKata Containers 等安全容器方案
+3 -3
View File
@@ -50,7 +50,7 @@ $ sudo ln -s /proc/$pid/ns/net /var/run/netns/$pid
```bash
$ ip addr show docker0
21: docker0: ...
inet 172.17.42.1/16 scope global docker0
inet 172.17.0.1/16 scope global docker0
...
```
创建一对 veth pair 接口 A B绑定 A 到网桥 `docker0`并启用它
@@ -64,8 +64,8 @@ $ sudo ip link set A up
$ sudo ip link set B netns $pid
$ sudo ip netns exec $pid ip link set dev B name eth0
$ sudo ip netns exec $pid ip link set eth0 up
$ sudo ip netns exec $pid ip addr add 172.17.42.99/16 dev eth0
$ sudo ip netns exec $pid ip route add default via 172.17.42.1
$ sudo ip netns exec $pid ip addr add 172.17.0.99/16 dev eth0
$ sudo ip netns exec $pid ip route add default via 172.17.0.1
```
以上就是 Docker 配置网络的具体过程
+61 -6
View File
@@ -10,16 +10,51 @@
* **版本管理**轻松回滚应用的发布版本
* **模板化**支持复杂的应用部署逻辑配置
### 13.4.2 Ingress - 服务的入口
### 13.4.2 Gateway API Ingress
Service 虽然提供了负载均衡但通常是 4 (TCP/UDP)**Ingress** 提供了 7 (HTTP/HTTPS) 路由能力充当集群的网关
Service 虽然提供了负载均衡但通常是 4 (TCP/UDP)集群需要 7 (HTTP/HTTPS) 路由能力来充当网关
* **域名路由**基于 Host 将请求转发不同服务 (api.example.com -> api-svcweb.example.com -> web-svc)
* **路径路由**基于 Path 将请求转发 (/api -> api-svc / -> web-svc)
#### Gateway API推荐
> **重要**Kubernetes 社区推荐使用 [Gateway API](https://gateway-api.sigs.k8s.io/) 作为新一代流量管理标准。原 `kubernetes/ingress-nginx` 项目已于 2026 年 3 月退役停止维护,不再接收安全更新。
Gateway API 基于 CRD 实现提供了比 Ingress 更强大和标准化的流量管理能力
* **GatewayClass**定义网关实现类似 IngressClass
* **Gateway**定义监听端口和协议由基础设施团队管理
* **HTTPRoute**定义 HTTP 路由规则由应用团队管理
* **职责分离**基础设施集群运维和应用开发者各管各的资源
```yaml
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: my-route
spec:
parentRefs:
- name: my-gateway
hostnames:
- "api.example.com"
rules:
- matches:
- path:
type: PathPrefix
value: /api
backendRefs:
- name: api-svc
port: 80
```
常见的 Gateway API 实现有 Envoy GatewayIstioCiliumTraefikKong
#### Ingress传统方案
Ingress 资源仍可正常使用但建议新项目直接采用 Gateway API已有 Ingress 配置可按需逐步迁移
* **域名路由**基于 Host 将请求转发不同服务
* **路径路由**基于 Path 将请求转发
* **SSL/TLS**集中管理证书
常见的 Ingress Controller Nginx Ingress ControllerTraefikIstio Gateway
### 13.4.3 Persistent Volume StorageClass
容器内的文件是临时的对于有状态应用 (如数据库)需要持久化存储
@@ -59,3 +94,23 @@ spec:
* **Secret**存储机密数据 (密码Token证书) Etcd 中加密存储
通过将配置与镜像分离保证了容器的可移植性
### 13.4.6 Pod Security Standards
> **注意**PodSecurityPolicy (PSP) 已在 Kubernetes 1.25 中完全移除
Kubernetes 使用 **Pod Security Standards** 定义三个安全级别通过内置的 Pod Security Admission 控制器在命名空间级别执行
* **Privileged**不受限制适用于系统级和基础设施工作负载
* **Baseline**防止已知的权限提升适用于大多数工作负载
* **Restricted**严格限制遵循 Pod 安全加固最佳实践
```yaml
apiVersion: v1
kind: Namespace
metadata:
name: my-app
labels:
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/warn: restricted
```
+2 -2
View File
@@ -105,13 +105,13 @@ $ sudo modprobe br_netfilter
#### cgroup v2 要求必须
Kubernetes v1.36 要求节点使用 cgroup v2不再支持 cgroup v1kubelet cgroup v1 节点上会拒绝启动验证节点是否支持 cgroup v2
Kubernetes v1.36 默认要求节点使用 cgroup v2kubelet cgroup v1 节点上默认会拒绝启动但管理员可以在 kubelet 配置中设置 `failCgroupV1: false` 来兼容 cgroup v1仅建议用于遗留系统过渡期验证节点是否支持 cgroup v2
```bash
$ mount | grep cgroup2
```
如果输出包含 `cgroup2`则系统已支持 cgroup v2对于仍在使用 cgroup v1 的系统如较旧的 RHEL 8需要升级内核或更新系统配置
如果输出包含 `cgroup2`则系统已支持 cgroup v2对于仍在使用 cgroup v1 的系统如较旧的 RHEL 8建议升级内核或更新系统配置以启用 cgroup v2
#### 禁用 swap必须
+2 -2
View File
@@ -122,13 +122,13 @@ $ sudo yum install -y kubelet kubeadm kubectl
#### cgroup v2 要求必须
Kubernetes v1.36 要求节点使用 cgroup v2不再支持 cgroup v1kubelet cgroup v1 节点上会拒绝启动验证节点是否支持 cgroup v2
Kubernetes v1.36 默认要求节点使用 cgroup v2kubelet cgroup v1 节点上默认会拒绝启动但管理员可以在 kubelet 配置中设置 `failCgroupV1: false` 来兼容 cgroup v1仅建议用于遗留系统过渡期验证节点是否支持 cgroup v2
```bash
$ mount | grep cgroup2
```
如果输出包含 `cgroup2`则系统已支持 cgroup v2对于仍在使用 cgroup v1 的系统如较旧的 RHEL 8需要升级内核或更新系统配置
如果输出包含 `cgroup2`则系统已支持 cgroup v2对于仍在使用 cgroup v1 的系统如较旧的 RHEL 8建议升级内核或更新系统配置以启用 cgroup v2
#### 加载内核模块
+2 -2
View File
@@ -51,7 +51,7 @@ $ ETCDCTL_API=3 etcdctl member list
$ ETCDCTL_API=3 etcdctl put testkey "hello world"
OK
$ etcdctl get testkey
$ ETCDCTL_API=3 etcdctl get testkey
testkey
hello world
```
@@ -96,5 +96,5 @@ $ brew install etcd
$ etcd
$ etcdctl member list
$ ETCDCTL_API=3 etcdctl member list
```
+1 -1
View File
@@ -16,7 +16,7 @@ USAGE:
etcdctl
VERSION:
3.5.21
3.5.29
API VERSION:
3.5
+14 -5
View File
@@ -270,7 +270,16 @@ cosign verify myregistry.com/myapp:v1.0.0 \
#### Docker Content Trust Notary
Docker Content Trust 使用 Notary 实现镜像签名 Docker 官方的签名解决方案
> **注意DCT 退役时间线**
>
> Docker 已宣布[退役 Content Trust](https://www.docker.com/blog/retiring-docker-content-trust/)。关键节点:
> - 2025 8 月起最早一批 DCT 签名证书开始过期
> - 2025 9 30 日起新注册表不可再启用 DCT
> - **2028 3 31 **DCT 完全移除所有 DCT 数据永久删除
>
> 建议新项目直接使用上文介绍的 **Cosign (Sigstore)** 进行镜像签名现有 DCT 用户应尽早制定迁移计划
Docker Content Trust 使用 Notary 实现镜像签名 Docker 官方的传统签名解决方案
**启用 DCT**
@@ -411,13 +420,13 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v6
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@v4
- name: Build Docker image
uses: docker/build-push-action@v6
uses: docker/build-push-action@v7
with:
context: .
push: false
@@ -467,7 +476,7 @@ jobs:
password: ${{ secrets.GITHUB_TOKEN }}
- name: Push image
uses: docker/build-push-action@v6
uses: docker/build-push-action@v7
with:
context: .
push: true
+2 -2
View File
@@ -60,7 +60,7 @@ rule_files:
```yaml
services:
prometheus:
image: prom/prometheus:v3.11.0
image: prom/prometheus:v3.11.2
volumes:
- ./prometheus.yml:/etc/prometheus/prometheus.yml
- ./rules.yml:/etc/prometheus/rules.yml
@@ -245,7 +245,7 @@ receivers:
```yaml
alertmanager:
image: prom/alertmanager:v0.27.0
image: prom/alertmanager:v0.32.0
volumes:
- ./alertmanager.yml:/etc/alertmanager/alertmanager.yml
ports:
@@ -164,12 +164,12 @@ scrape_configs:
**完整监控栈部署**
> [!TIP]
> 以下示例中的镜像标签 `prom/prometheus:v3.11.0``prom/node-exporter:v1.11.1``ghcr.io/google/cadvisor:v0.56.2``grafana/grafana:13.0.1`仅为参考在生产环境部署前请访问各项目的官方发布页或文档获取最新版本号
> 以下示例中的镜像标签 `prom/prometheus:v3.11.2``prom/node-exporter:v1.11.1``ghcr.io/google/cadvisor:v0.56.2``grafana/grafana:13.0.1`仅为参考在生产环境部署前请访问各项目的官方发布页或文档获取最新版本号
```yaml
services:
prometheus:
image: prom/prometheus:v3.11.0
image: prom/prometheus:v3.11.2
container_name: prometheus
ports:
- "9090:9090"