The Concepts section helps you learn about the parts of the Kubernetes system and the abstractions Kubernetes uses to represent your {{< glossary_tooltip text="cluster" term_id="cluster" length="all" >}}, and helps you obtain a deeper understanding of how Kubernetes works.
<!-- body -->
Cluster Architecture
A Kubernetes cluster consists of a control plane plus a set of worker machines, called nodes,
that run containerized applications. Every cluster needs at least one worker node in order to run Pods.
The worker node(s) host the Pods that are the components of the application workload.
The control plane manages the worker nodes and the Pods in the cluster. In production
environments, the control plane usually runs across multiple computers and a cluster
usually runs multiple nodes, providing fault-tolerance and high availability.
This document outlines the various components you need to have for a complete and working Kubernetes cluster.
{{< figure src="/images/docs/kubernetes-cluster-architecture.svg" alt="The control plane (kube-apiserver, etcd, kube-controller-manager, kube-scheduler) and several nodes. Each node is running a kubelet and kube-proxy." caption="Figure 1. Kubernetes cluster components." class="diagram-large" >}}
{{< details summary="About this architecture" >}}
The diagram in Figure 1 presents an example reference architecture for a Kubernetes cluster.
The actual distribution of components can vary based on specific cluster setups and requirements.
In the diagram, each node runs the kube-proxy component. You need a
network proxy component on each node to ensure that the
{{< glossary_tooltip text="Service" term_id="service">}} API and associated behaviors
are available on your cluster network. However, some network plugins provide their own,
third party implementation of proxying. When you use that kind of network plugin,
the node does not need to run kube-proxy.
{{< /details >}}
Control plane components
The control plane's components make global decisions about the cluster (for example, scheduling),
as well as detecting and responding to cluster events (for example, starting up a new
{{< glossary_tooltip text="pod" term_id="pod">}} when a Deployment's
{{< glossary_tooltip text="replicas" term_id="replica" >}} field is unsatisfied).
Control plane components can be run on any machine in the cluster. However, for simplicity, setup scripts
typically start all control plane components on the same machine, and do not run user containers on this machine.
See Creating Highly Available clusters with kubeadm
for an example control plane setup that runs across multiple machines.
245"install" your plugin by moving it to a directory in your $PATHp. 1013
246check that kubectl recognizes your pluginp. 1013
247test that calling your plugin via a "kubectl" command worksp. 1013
248even when additional arguments and flags are passed to yourp. 1013
250create a plugin containing an underscore in its filenamep. 1013
251move the plugin into your $PATHp. 1013
252You can now invoke your plugin via kubectl:p. 1013
253You can invoke your custom command with a dashp. 1013
266If the new Pod isn't yet healthy, rerun this command a few times.p. 1072
271Create a temporary interactive containerp. 1075
272Run these commands inside the Podp. 1075
273Note the rabbitmq-service has a DNS name, provided by Kubernetes:p. 1075
274run this check inside the Podp. 1075
275Run these commands inside the Podp. 1075
276In the next line, rabbitmq-service is the hostname where the rabbitmq-servicep. 1075
277can be reached. 5672 is the standard port for rabbitmq.p. 1075
278If you could not resolve "rabbitmq-service" in the previous step,p. 1075
279then use this command instead:p. 1075
280Now create a queue:p. 1075
283this assumes you downloaded and then edited the manifest alreadyp. 1076
285this assumes you downloaded and then edited the manifest alreadyp. 1080
287This uses the first approach (relying on $JOB_COMPLETION_INDEX)p. 1081
291Remove the Jobs you createdp. 1084
294Remove the Jobs you createdp. 1085
298last-applied-configuration valuep. 1104
299configuration file valuep. 1104
300live configurationp. 1104
302last-applied-configuration valuep. 1104
303configuration file valuep. 1104
304live configurationp. 1104
306...p. 1105
307...p. 1106
308last-applied-configurationp. 1106
309configuration filep. 1106
310live configurationp. 1106
312Create a application.properties filep. 1111
313Create a .env filep. 1112
315Create a password.txt filep. 1113
318Create a deployment.yaml filep. 1114
319Create a service.yaml filep. 1114
321Create a deployment.yaml filep. 1114
322Create a patch increase_replicas.yamlp. 1114
323Create another patch set_memory.yamlp. 1115
324Create a deployment.yaml filep. 1115
325Create a json patchp. 1115
326Create a kustomization.yamlp. 1116
327Create a deployment.yaml file (quoting the here doc delimiter)p. 1116
329Create a directory to hold the basep. 1117
330Create a base/deployment.yamlp. 1117
331Create a base/service.yaml filep. 1117
333Create a deployment.yaml filep. 1117
336Kubernetes-managed hosts file.p. 1127
339Point to the internal API server hostnamep. 1136
340Path to ServiceAccount tokenp. 1136
341Read this Pod's namespacep. 1136
342Read the ServiceAccount bearer tokenp. 1136
343Reference the internal certificate authority (CA)p. 1136
346Run this in a separate terminalp. 1144
347so that the load generation continues and you can carry on with the rest of the stepsp. 1144
354Start a new terminal, and leave this running.p. 1184
357Allocate storage and restrict accessp. 1199
358Create an encrypted device backed by the allocated storagep. 1199
359Format the swap spacep. 1199
360Activate the swap space for pagingp. 1199
361Allocate storage and restrict accessp. 1199
362Format the swap spacep. 1199
364Pick one Pod that belongs to the Deployment, and view its logsp. 1206
365You can leave the existing metadata as they are.p. 1206
367You can leave the existing metadata as they are.p. 1207
368The values you'll see won't exactly match these.p. 1208
369As the text explains, the output does NOT changep. 1208
370Trigger the rolloutp. 1208
371Wait for the rollout to completep. 1208
373this stays running in the backgroundp. 1209
374You can leave the existing metadata as they are.p. 1209
375The values you'll see won't exactly match these.p. 1209
377this stays running in the backgroundp. 1210
378You can leave the existing metadata as they are.p. 1210
379The values you'll see won't exactly match these.p. 1210
381Pick one Pod that belongs to the Deployment, and view its logsp. 1212
384Change 32373 to the port number you saw from "kubectl get service audit-pod"p. 1239
386The log path on your computer might be different from "/var/log/syslog"p. 1241
388Create a public private key pairp. 1246
390Run this in a shell on the node you want to query.p. 1251
391Run this inside the terminal from "kubectl run"p. 1251
393Run this locally on a node you choosep. 1253
395use this terminal to run commands that specify --watchp. 1255
397Do not start a new watch;p. 1255
399Run this in the dns-test container shellp. 1256
400Start a new watchp. 1256
401End this watch when you've seen that the delete is finishedp. 1256
402This should already be runningp. 1256
404End this watch when you've reached the end of the section.p. 1257
405At the start of "Scaling a StatefulSet" you'll start a new watch.p. 1258
407If you already have a watch running, you can continue using that.p. 1258
408Otherwise, start one.p. 1258
409End this watch when there are 5 healthy Pods for the StatefulSetp. 1258
411End this watch when there are only 3 Pods for the StatefulSetp. 1259
413End this watch when the rollout is completep. 1259
415The value of "partition" determines which ordinals a change applies top. 1260
416Make sure to use a number bigger than the last ordinal for thep. 1260
417StatefulSetp. 1261
419The value of "partition" should match the highest existing ordinal forp. 1261
420the StatefulSetp. 1261
421This should already be runningp. 1261
424End this watch when there are no Pods for the StatefulSetp. 1263
425Leave this watch running until the next time you start a watchp. 1263
427Leave this running until the next page sectionp. 1264
430sts is an abbreviation for statefulsetp. 1266
432Use this if you are able to apply cassandra-statefulset.yaml unmodifiedp. 1269
435clusters refers to the remote service.p. 1304
437# CAUTION: this is an example configuration.p. 1312
438Do not use this as-is for your own cluster!p. 1312
441# CAUTION: this is an example configuration.p. 1320
442Do not use this for your own cluster!p. 1320
443apiVersion: apiserver.config.k8s.io/v1p. 1320
444list of authenticators to authenticate Kubernetes users using JWT compliant tokens.p. 1320
446Kubernetes API versionp. 1326
447kind of the API objectp. 1326
448clusters refers to the remote service.p. 1326
449users refers to the API server's webhook configuration.p. 1326
451# CAUTION: this is an example configuration.p. 1332
452Check and amend this before you use it in your own cluster!p. 1332
454# DO NOT USE THE CONFIG AS IS. THIS IS AN EXAMPLE.p. 1343
457Deprecated in v1.17 in favor of apiserver.config.k8s.io/v1p. 1361
458name should be set to the DNS name of the service or the host (including port) of the URL the webhook is configured to speak to.p. 1361
459If a non-443 port is used for services, it must be included in the name when configuring 1.16+ API servers.p. 1361
460# For a webhook configured to speak to a service on the default port (443), specify the DNS name of the service:p. 1361
461- name: webhook1.ns1.svcp. 1361
462user: ...p. 1361
463# For a webhook configured to speak to a service on non-default port (e.g. 8443), specify the DNS name and port of the service in 1.16+:p. 1361
464- name: webhook1.ns1.svc:8443p. 1361
465user: ...p. 1361
466and optionally create a second stanza using only the DNS name of the service for compatibility with 1.15 API servers:p. 1361
467- name: webhook1.ns1.svcp. 1361
468user: ...p. 1361
469# For webhooks configured to speak to a URL, match the host (and port) specified in the webhook's URL. Examples:p. 1361
470A webhook with `url: https://www.example.com`:p. 1361
471- name: www.example.comp. 1361
472user: ...p. 1361
473# A webhook with `url: https://www.example.com:443`:p. 1361
474- name: www.example.com:443p. 1361
475user: ...p. 1361
476# A webhook with `url: https://www.example.com:8443`:p. 1361
477- name: www.example.com:8443p. 1361
478user: ...p. 1361
479- name: 'webhook1.ns1.svc'p. 1361
480The `name` supports using * to wildcard-match prefixing segments.p. 1361
482HELP apiserver_admission_webhook_rejection_count [ALPHA] Admission webhook rejection count, identified by name and broken out for each admission type (validating or admit) and operation. Additional labels specify an error type (calling_webhook_error or apiserver_internal_error if an error occurred; no_error otherwise) and optionally a non-zero rejection code if the webhook rejects the request with an HTTP status code (honored by the apiserver when the code is greater or equal to 400). Codes greater than 600 are truncated to 600, to keep the metrics cardinality bounded.p. 1373
485Approve all CSRs for the group "system:bootstrappers"p. 1380
487When you create the "monitoring-endpointslices" ClusterRole,p. 1394
490Can set "Impersonate-Extra-scopes" header and the "Impersonate-Uid" header.p. 1418
492Can impersonate the groups "developers" and "admins"p. 1418
493Can impersonate the extras field "scopes" with the values "view" and "development"p. 1418
496Kubernetes API versionp. 1432
497kind of the API objectp. 1432
498clusters refers to the remote service.p. 1433
499users refers to the API Server's webhook configuration.p. 1433
501You need to run "kubectl proxy" firstp. 1722
503HELP kubernetes_healthcheck [ALPHA] This metric records the result of a single healthcheck.p. 1722
504TYPE kubernetes_healthcheck gaugep. 1723
505HELP kubernetes_healthchecks_total [ALPHA] This metric records the results of all healthcheck.p. 1723
507Replace <node-name> with the name of a node in your clusterp. 1724
509Replace <node-name> with the name of a node in your clusterp. 1725
511Replace <node-name> with the name of a node in your clusterp. 1725
513Create a service using the definition in example-service.yaml.p. 1735
514Create a replication controller using the definition in example-controller.yaml.p. 1735
515Create the objects that are defined in any .yaml, .yml, or .json file within the <directory> directory.p. 1735
516List all pods in plain-text output format.p. 1735
517List all pods in plain-text output format and include additional information (such as node name).p. 1735
518List the replication controller with the specified name in plain-text output format. Tip: You can shorten and replace the 'replicationcontroller' resource type with the alias 'rc'.p. 1735
519List all replication controllers and services together in plain-text output format.p. 1735
520List all daemon sets in plain-text output format.p. 1735
521List all pods running on node server01p. 1735
522Display the details of the node with name <node-name>.p. 1735
523Display the details of the pod with name <pod-name>.p. 1735
524Display the details of all the pods that are managed by the replication controller named <rc-name>.p. 1735
525Remember: Any pods that are created by the replication controller get prefixed with the name of the replication controller.p. 1735
526Describe all podsp. 1735
527Delete a pod using the type and name specified in the pod.yaml file.p. 1735
528Delete all the pods and services that have the label '<label-key>=<label-value>'.p. 1735
529Delete all pods, including uninitialized ones.p. 1735
530Get output from running 'date' from pod <pod-name>. By default, output is from the first container.p. 1735
531Get output from running 'date' in container <container-name> of pod <pod-name>.p. 1735
532Get an interactive TTY and run /bin/bash from pod <pod-name>. By default, output is from the first container.p. 1735
533Return a snapshot of the logs from pod <pod-name>.p. 1735
534Start streaming the logs from pod <pod-name>. This is similar to the 'tail -f' Linux command.p. 1736
535Diff resources included in "pod.json".p. 1736
537create a simple plugin in any language and name the resulting executable filep. 1736
538so that it begins with the prefix "kubectl-"p. 1736
539this plugin prints the words "hello world"p. 1736
540and move it to a location in our PATHp. 1736
541You have now created and "installed" a kubectl plugin.p. 1736
542You can begin using this plugin by invoking it from kubectl as if it were a regular commandp. 1736
543You can "uninstall" a plugin, by removing it from the folder in yourp. 1736
544$PATH where you placed itp. 1736
545this plugin makes use of the `kubectl config` command in order to outputp. 1736
546information about the current user, based on the currently selected contextp. 1736
547make the file executablep. 1736
549start the pod running nginxp. 1737
550add env to nginx-appp. 1737
552exitp. 1738
555kubectl does not support regular expressions for JSONpath outputp. 1743
556The following command does not workp. 1743
559use multiple kubeconfig files at the same time and view merged configp. 1751
560Show merged kubeconfig settings and raw certificate data and exposed secretsp. 1751
561get the password for the e2e userp. 1751
562get the certificate for the e2e userp. 1752
563configure the URL to a proxy server to use for requests made by this client in the kubeconfigp. 1752
564add a new user to your kubeconf that supports basic authp. 1752
565permanently save the namespace for all subsequent kubectl commands in that context.p. 1752
566set a context utilizing a specific username and namespace.p. 1752
568create a Job which prints "Hello World"p. 1752
569create a CronJob that prints "Hello World" every minutep. 1752
570Create multiple YAML objects from stdinp. 1752
572Get commands with basic outputp. 1753
573Describe commands with verbose outputp. 1753
574List Services Sorted by Namep. 1753
575List pods Sorted by Restart Countp. 1753
576List PersistentVolumes sorted by capacityp. 1753
577Get the version label of all pods with label app=cassandrap. 1753
578Retrieve the value of a key with dots, e.g. 'ca.crt'p. 1753
579Retrieve a base64 encoded value with dashes instead of underscores.p. 1753
580Get all worker nodes (use a selector to exclude results that have a labelp. 1753