Red Hat Training

A Red Hat training course is available for OpenShift Container Platform

Chapter 39. Revision History: Cluster Administration

39.1. Tues Mar 06 2018

Affected TopicDescription of Change

Managing Security Context Constraints

Added a new Example Security Context Constraints Settings section.

39.2. Fri Feb 23 2018

Affected TopicDescription of Change

Default Scheduling

Reorganized topic and updated the list of predicates and policies in the Scheduler Policy section.

Controlling Pod Placement

Created new topic from the Controlling Pod Placement section of the Default Scheduling topic. No change to the content.

Managing Security Context Constraints

Noted the importance of -z flag usage when granting access to service accounts.

Configuring Service Accounts

Noted the importance of -z flag usage when granting access to service accounts.

39.3. Tues Feb 20 2018

Affected TopicDescription of Change

Managing Nodes

Replaced outdated oadm manage-node --evacuate commands with oc adm drain commands.

39.4. Fri Feb 16 2018

Affected TopicDescription of Change

Handling Out of Resource Errors

Adjusted the math in the Example Scenario.

Garbage Collection

Added clarifying details about the default behavior of garbage collection.

39.5. Tue Feb 06 2018

Affected TopicDescription of Change

Managing Networking

Changed the Disabling Host Name Collision Prevention For Routes and Ingress Objects section to mention the ability to give users the rights to edits host names on routes and ingress objects.

39.6. Tue Nov 21 2017

Affected TopicDescription of Change

Manging Nodes

Added new section on Resetting Docker Storage to free up space on nodes.

39.7. Fri Nov 10 2017

Affected TopicDescription of Change

Service Accounts

Changed serviceaccounts to serviceaccount in the User Names and Groups section.

39.8. Fri Nov 03 2017

Affected TopicDescription of Change

Encrypting Data at Datastore Layer

Added a note that etcd v3 or later is required in order to use data encyption.

39.9. Tue Oct 24 2017

Affected TopicDescription of Change

Backup and Restore

Added a new Containerized etcd Deployments section.

39.10. Wed Oct 11 2017

Affected TopicDescription of Change

Pruning Objects

Added details on secure versus insecure image pruning.

Backup and Restore

Added a new Registry Certificates Backup section.

39.11. Mon Oct 02 2017

Affected TopicDescription of Change

Managing Networking

Added more information to the VMWare vSphere section.

Encrypting Data at Datastore Layer

Removed the "experimental support" language for the data encryption feature, as the feature is fully supported as of v3.6.

39.12. Mon Sep 18 2017

Affected TopicDescription of Change

Diagnostics Tool

Added more information about tool usage to the Using the Diagnostics Tool section.

Opaque Integer Resources

Moved information on opaque integer resources to Administrator Guide

Setting Limit Ranges

Added link to information on how CPU and memory are calculated.

39.13. Fri Sep 08 2017

Affected TopicDescription of Change

Encrypting Data at Datastore Layer

New topic on how to enable and configure encryption of secret data at the datastore layer.

39.14. Tue Aug 29 2017

Affected TopicDescription of Change

Image Policy

Added note clarifying the need for the image prefix to set the default registry string in the Configuring the ImagePolicy Admission Plug-in section.

Pruning Objects

Added valid units of measurement for --keep-younger-than.

Troubleshooting OpenShift SDN

Changed the Further Help section to Finding Network Issues Using the Diagnostics Tool and added information about the Diagnostic Tool.

Troubleshooting OpenShift SDN

Corrected vxlan0 to vxlan_sys_4789 in the Debugging Local Networking section.

39.15. Tue Aug 22 2017

Affected TopicDescription of Change

Managing Networking

Added admonition to the Using an Egress Router to Allow External Resources to Recognize Pod Traffic section about Amazon AWS not working with the egress router.

Diagnostics Tool

Enhanced the Ansible-based Health Checks section with information on running via ansible-playbook or Docker CLI.

39.16. Mon Aug 14 2017

Affected TopicDescription of Change

Garbage Collection

Changed the image-gc-high-threshold default value to 85 from 90.

High Availability

Added verbiage clarifying the example outlined in the Configuring a Highly-available Service section.

39.17. Wed Aug 09 2017

OpenShift Container Platform 3.6 Initial Release

Affected TopicDescription of Change

Managing Pods

Added information about allowing domain names in EgressNetworkPolicy.

Managing Networking

Added an admonition about DNS and egress network policy to the Using an Egress Firewall to Limit Access to External Resources section.

Added procedure to the Enabling NetworkPolicy section.

Removed the Technology Preview designation for SDN Multicast.

Added the Using iptables Rules to Limit Access to External Resources section, and various edits.

Added a note about limitations with the egress network policy.

Added the Egress Router Modes, Redirecting to Multiple Destinations, Using a ConfigMap to specify EGRESS_DESTINATION, and Deploying an Egress Router Pod in Redirect Mode sections, as well as various content changes.

Added the Disabling Host Name Collision Prevention For Ingress Objects section.

Image Policy

Added details about using image streams in Kubernetes resources.

Image Signatures

Added the Verifying Image Signatures Using OpenShift CLI section.

Scheduling

Added subsections for new scheduling features. Moved the current Scheduling topic into section as Default Scheduling.

Setting Quotas

Added list of storage resources that can be managed by quota to the Resources Managed by Quota section and added gold and bronze storage classes to storage-consumption.yaml example.

Pruning Objects

Added note to Pruning Builds linking to the Build Pruning section.

Overcommitting

Added the Tune Buffer Chunk Limit section.

Added new section on reserving resources for pods based on QOS level.

Monitoring and Debugging Routers

Described the ROUTER_SYSLOG_FORMAT environment variable.

Diagnostics Tool

Added Additional Diagnostic Checks via Ansible section.

Analyzing Cluster Capacity

Added the Analyzing Cluster Capacity file.