#kubernetes (2022-11)
Archive: https://archive.sweetops.com/kubernetes/
2022-11-02
data:image/s3,"s3://crabby-images/279d9/279d967e82dbc5220558ad291666976a271ee383" alt="Mallikarjuna M avatar"
Hi Team, can someone help me with creating a service account in Kubernetes with a test namespace and access the resources based on service account kubeconfig file.
2022-11-03
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
How to construct a trust policy for allowing role assumption from multiple / all clusters in one account?
This is the docs example:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Federated": "arn:aws:iam::111122223333:oidc-provider/oidc.eks.region-code.amazonaws.com/id/EXAMPLED539D4633E53DE1B71EXAMPLE"
},
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringEquals": {
"oidc.eks.region-code.amazonaws.com/id/EXAMPLED539D4633E53DE1B71EXAMPLE:sub": "system:serviceaccount:default:my-service-account",
"oidc.eks.region-code.amazonaws.com/id/EXAMPLED539D4633E53DE1B71EXAMPLE:aud": "sts.amazonaws.com"
}
}
}
]
}
This is coupled to one particular OIDC provider i.e. one cluster.
I there are a way to make it cluster independent?
2022-11-07
2022-11-08
data:image/s3,"s3://crabby-images/c3eed/c3eedfa3176fd7ef5cc7756c8744d13a495e4b6c" alt="Nenad Strainovic avatar"
Hi everyone,
I’m trying to create K8s secret for Service Account (1.24+), with kubectl but I’m getting the following error:
error: failed to create secret Secret "admin2" is invalid: metadata.annotations[[kubernetes.io/service-account.name](http://kubernetes.io/service-account.name)]: Required value
This is commanand:
kubectl create secret generic admin2 --type='[kubernetes.io/service-account-token](http://kubernetes.io/service-account-token)'
Do you have any idea where to look? I didn’t find a way how to set annotations from the kubectl beside kubectl annotate which can be used on already created objects.
kubectl version 1.25.3 k8s version 1.24.7
Thanks!
data:image/s3,"s3://crabby-images/2c542/2c5428cb5f8a5bfd303be4b4c99320e0efcb7b39" alt="James avatar"
Hey Guys - I’m walking to the learning path of K8s and there’s one thing I need to understand.
In your own experience/idea, what is the use case of running multiple schedulers in the real-world?
2022-11-15
2022-11-19
data:image/s3,"s3://crabby-images/68e2f/68e2faea152619db914e1267b8c8468c55f93633" alt="Jim Park avatar"
Not sure who might want this in the future, but here’s something I put together to export a kubernetes namespace to disk.
2022-11-29
data:image/s3,"s3://crabby-images/3c499/3c499ee866f8c09684f6028c84d6009f3b048c4b" alt="Talal Ashraf avatar"
Hey Folks. Wondering if people using EKS have tried using Karpenter ? Can I simply replace the autoscaler with this ? The autoscaler unfortunately doesn’t consider volume node affinities
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
(re: affinities, we use EFS for this reason; not suitable for all workloads, but suitable for quite a lot)
data:image/s3,"s3://crabby-images/6ec4f/6ec4f2b4a71a61ef87c50415298c9508bc8544bf" alt="Hao Wang avatar"
I used Karpenter, much faster than HPA didn’t use volume affinity, it should support
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/77bdd/77bdd621bbae1f7b8ec7ec238c59e9adf630e9a7" alt="attachment image"
Posted in r/kubernetes by u/xrothgarx • 182 points and 44 comments
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Karpenter is rad, but I wouldn’t say it’s just as easy as replacing the autoscaler if you want to do it in a production configuration.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
You’ll still need compute capacity to run karpenter itself
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
We provision fargate profiles to run operators, then run karpenter on fargate, which manages the rest of the cluster.
data:image/s3,"s3://crabby-images/3c499/3c499ee866f8c09684f6028c84d6009f3b048c4b" alt="Talal Ashraf avatar"
EFS will become cost inhibitive for us. off the top of your head what are some consideration when swapping out autoscaler ?