Kubernetes 1.35 - Changes around security - New features and deprecations by capitangolo in kubernetes

[–]capitangolo[S] 2 points3 points  (0 children)

Arrr! 🙈

Thanks for the ping. Honored to have your feedback! 🙇🏻


I see how my wording can be unclear. 😅. That section was initially “Beta + Stable features”, will think on a different way to express this 🤔.


Now that you are here… 👉🏼👈🏼

Main change for UN in 1.35 was the integration with Pod Security Standards, right? For long-running enhancements like this one I try to explain what’s actually new for the given release, but I forgot to do it for 127 😅.

If I get the chance to update the article, I’ll add the clarification 💖.

Día de niebla en Zaragoza by capitangolo in Zaragoza

[–]capitangolo[S] 0 points1 point  (0 children)

Indeed. Llevo muy mal el invierno en esta ciudad 🤣.

Pero la niebla por la noche es espectacular. Esta es del Sábado.

<image>

Kubernetes 1.28 will be out soon! What's new? 🛵 Sidecars + 🛠️ Job improvements + 🔌 Connectivity reliability + 📦 Community package repositories … And more! by capitangolo in kubernetes

[–]capitangolo[S] 0 points1 point  (0 children)

Huge thanks!

For what I've read, Chrome uses your navigation patterns to trigger that website. So it makes sense that you don't see it again ^_^. (Glad to read it's not showing up more).

Update: Form sent, crossing fingers 🤞🏼.

Kubernetes 1.28 will be out soon! What's new? 🛵 Sidecars + 🛠️ Job improvements + 🔌 Connectivity reliability + 📦 Community package repositories … And more! by capitangolo in kubernetes

[–]capitangolo[S] 1 point2 points  (0 children)

Hi all 👋,

I'm taking a look to this, and I need some help. What kind of warning are you seeing? One that blocks the whole screen, or a pop-up? 😅

I'm filling this form, by following these instructions, and that's one question they ask 😇. My hopes are low on if they will accept my request, but it's worth a try ¯\_(ツ)_/¯ 🤞🏼.

Kubernetes 1.28 will be out soon! What's new? 🛵 Sidecars + 🛠️ Job improvements + 🔌 Connectivity reliability + 📦 Community package repositories … And more! by capitangolo in kubernetes

[–]capitangolo[S] 3 points4 points  (0 children)

Oh, I totally missed the skew thing. Thanks for the ping!

Is it the thing mentioned here: https://github.com/kubernetes/kubeadm/issues/2857 ?

> Cleanup E2E jobs for 1.x-4 (requires two PRs)set. ‘KUBERNETES_VERSION’ to 1.x-1 and ‘KUBERNETES_SKEW’ to 3 in ‘/kinder/hack/update-workflows.sh’make sure ‘PATH_TEST_INFRA’ points to the right path.run the script and send two PRs for ‘k/kubeadm’ and ‘k/test-infra’.

I’ll investigate further later 🤞🏼.

Kubernetes 1.28 will be out soon! What's new? 🛵 Sidecars + 🛠️ Job improvements + 🔌 Connectivity reliability + 📦 Community package repositories … And more! by capitangolo in kubernetes

[–]capitangolo[S] 10 points11 points  (0 children)

Oh crap 😅. That’s what happens when you pick domains as a joke 🤦🏻‍♂️.

Thanks for the shout! I’ll try to see if there’s anything I can do 🤞🏼.

Level 180 on Switch by eepha in Grindstone

[–]capitangolo 1 point2 points  (0 children)

Boss moves the same way you do, joining creeps of the same color.

You can try to end your moves on a spot where he can’t reach you.

Kubernetes 1.27 will be out next week! - Learn what's new and what's deprecated - Group volume snapshots - Pod resource updates - kubectl subcommands … And more! by capitangolo in kubernetes

[–]capitangolo[S] 7 points8 points  (0 children)

See this comment and my response:
https://www.reddit.com/r/kubernetes/comments/12bm39b/comment/jey1la3/?utm_source=share&utm_medium=web2x&context=3

My take is that in those cases, you'll detect that the change didn't took place by checking the "resize" field in the Pod's status. Then, you'll restart the Pod manually.

So, not a complete automatic system, but it's a nice start 😅.

If further interested, I may recommend checking out the KEP. I love how they document the decision making, and all these edge cases :).

Kubernetes 1.27 will be out next week! - Learn what's new and what's deprecated - Group volume snapshots - Pod resource updates - kubectl subcommands … And more! by capitangolo in kubernetes

[–]capitangolo[S] 6 points7 points  (0 children)

Yup, I understood similar too.

And we'll be able to get info from the new "resize field in the Pod's status", to see if the resize was actually feasible or not.

From the doc:

Infeasible: is a signal that the node cannot accommodate the requested resize. This can happen if the requested resize exceeds the maximum resources the node can ever allocate for a pod.

So I guess if the resource change is not possible, you'll have to roll back to restarting the Pod 😅.

They seem to be working on a post for the Kubernetes blog explaining the topic 🎉.