-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
sig-node: Kubelet-in-UserNS, aka Rootless mode #2033
Comments
/sig node |
Thanks for opening this @AkihiroSuda ! As a reminder Enhancements Freeze is next Tuesday October 6th, by which time KEPs must be merged in an implementable state (you have this), have test plans(you have this) and graduation criteria (you have this). |
Hi @AkihiroSuda , Just a reminder that the outstanding PR (#1371) must be merged by EOD PST tomorrow (10/6) for this KEP to be included in the Enhancements Freeze for the 1.20 release. After that time you will need to request an Exception to be included in the 1.20 Release. Best, |
Hi @AkihiroSuda Enhancements Freeze is now in effect. Unfortunately, your KEP PR did not merge. If you wish to be included in the 1.20 Release, please submit an Exception Request as soon as possible. Best, |
Issues go stale after 90d of inactivity. If this issue is safe to close now please do so with Send feedback to sig-testing, kubernetes/test-infra and/or fejta. |
/remove-lifecycle stale |
Issues go stale after 90d of inactivity. If this issue is safe to close now please do so with Send feedback to sig-contributor-experience at kubernetes/community. |
/remove-lifecycle stale |
/remove-lifecycle stale |
Hi @AkihiroSuda 👋 1.22 Enhancement shadow here. This enhancement is well on its way, some minor change requests in light of Enhancement Freeze on Thursday May 13th:
Thanks 😊 |
/remove-lifecycle stale |
/milestone clear |
The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs. This bot triages issues and PRs according to the following rules:
You can:
Please send feedback to sig-contributor-experience at kubernetes/community. /lifecycle stale |
/remove-lifecycle stale |
The Kubernetes project currently lacks enough active contributors to adequately respond to all issues and PRs. This bot triages issues and PRs according to the following rules:
You can:
Please send feedback to sig-contributor-experience at kubernetes/community. /lifecycle rotten |
/remove-lifecycle rotten |
The Kubernetes project currently lacks enough contributors to adequately respond to all issues. This bot triages un-triaged issues according to the following rules:
You can:
Please send feedback to sig-contributor-experience at kubernetes/community. /lifecycle stale |
/remove-lifecycle stale |
EDIT (Oct 17, 2023): the current plan is to spawn AWS or GCP VMs via kubetest2: kubernetes/test-infra#30744 (comment) |
Now all the Not integrated to prow yet though |
PR for prow: EDIT (Nov 30, 2023): failing due to: |
With cgroup v2 promoted to GA, should we consider promoting this KEP to beta? Esp with usernamespaces being promoted to beta in 1.30. |
Yes, let me try it in the v1.31 window |
↑ |
@AkihiroSuda will you be able to work on this for v1.32? I'm going to mark this as proposed for consideration. |
Enhancement Description
One-line enhancement description (can be used as a release note):
Allow running the entire Kubernetes components (kubelet, CRI, OCI, CNI, and all
kube-*
) as a non-root user on the host.Kubernetes Enhancement Proposal: https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/2033-kubelet-in-userns-aka-rootless
Discussion Link:
kind
repo: Support Rootless Docker / Kubernetes kubernetes-sigs/kind#1797minikube
repo: add support for rootless Docker minikube#10836KubeletInUserNamespace
feature gate website#28827Primary contact (assignee):
@AkihiroSuda
Responsible SIGs:
SIG-node
Enhancement target (which target equals to which milestone):
The text was updated successfully, but these errors were encountered: