Kubernetes 1.7: Security Hardening, Stateful Application Updates and Extensibility
blog.kubernetes.io
blog.kubernetes.io
The second major one is "third-party resources" which has now been renamed to custom resource definitions. These power a number of software systems[2] today and the changes are explained in this blog post[3].
[1]: https://github.com/kubernetes-incubator/apiserver-builder
[2]: https://github.com/coreos/awesome-kubernetes-extensions
I was looking at service-catalog, and I got thinking, wow, K8S rapidly catching up to CloudFoundry. It may not be long before it starts overtaking it.
I still wonder how the pre-container generation of DevOps tools will work with this -- Puppet, Chef, Ansible, etc. It seems to me that all the older-generation devops "infrastructure as code" tooling are one move behind Kubernetes.
Kubernetes is, conceptually, MVC. There's a data store of objects that describe what the world should look like, then a bunch of controllers that use this store to continually "converge" and "repair" the world so it looks like the description, plus APIs to perform specific actions such as perform a rollout or undo.
With this new addition, you get closer to erasing the conceptual distinction between "core" Kubernetes and everything else, which is great.
On the other hand, Operators are essentially non-core controllers. They can be highly specialized to a specific system (etcd, kafka, postgresql, etc.) Same with service catalogs.
(They've fortunately taken some steps to pull out the client into separate repos, so you no longer have to link your project against the entire Kubernetes codebase.)
0 - http://blog.kubernetes.io/2016/12/container-runtime-interfac...
So it'd be nice to be able to proxy the call to docker to inject our own config before hitting docker. It looks like CRI is exactly what we'd need, possibly maintaining our own fork of the docker shim? Trying to figure out if there is a way to put in arbitrary data in the config sent to the docker shim[0]
[0] https://github.com/kubernetes/kubernetes/blob/master/pkg/kub...
Edit: I think it's a mistake. Reported here: https://github.com/kubernetes/release/issues/358
K8s 1.6 was released on March 28 and GKE made that version available on April 4. I would expect a similar wait time to 1.7.
0 - https://cloud.google.com/container-engine/release-notes#supp...
> There will be no release for the week of July 3rd, since this is a holiday in the US. The next release is planned for the week of July 10th.