Simplify kubelet-config template

Remove system|kube_master_<resource>_reserved variables.
Those variables are unnecessary because users can simply use the
variables in group_vars if they which to differentiate control plane
nodes from other nodes.

Set conservative defaults for ephemeral-storage and pids for both kube
and system reserved resources.
pull/10643/head
Max Gautier 2023-11-23 17:18:47 +01:00
parent 872d717105
commit 1bc61c9f35
No known key found for this signature in database
2 changed files with 17 additions and 67 deletions

View File

@ -37,29 +37,19 @@ kubelet_secure_addresses: "localhost link-local {{ kube_pods_subnet }} {{ kube_n
# Whether to run kubelet and container-engine daemons in a dedicated cgroup. (Not required for resource reservations). # Whether to run kubelet and container-engine daemons in a dedicated cgroup. (Not required for resource reservations).
kube_reserved: false kube_reserved: false
kube_reserved_cgroups: "/{{ kube_reserved_cgroups_for_service_slice }}" kube_reserved_cgroups: "/{{ kube_reserved_cgroups_for_service_slice }}"
kube_memory_reserved: 256Mi kube_memory_reserved: "256Mi"
kube_cpu_reserved: 100m kube_cpu_reserved: "100m"
# kube_ephemeral_storage_reserved: 2Gi kube_ephemeral_storage_reserved: "500Mi"
# kube_pid_reserved: "1000" kube_pid_reserved: "1000"
# Reservation for control plane hosts
kube_master_memory_reserved: 512Mi
kube_master_cpu_reserved: 200m
# kube_master_ephemeral_storage_reserved: 2Gi
# kube_master_pid_reserved: "1000"
# Set to true to reserve resources for system daemons # Set to true to reserve resources for system daemons
system_reserved: false system_reserved: false
system_reserved_cgroups_for_service_slice: system.slice system_reserved_cgroups_for_service_slice: system.slice
system_reserved_cgroups: "/{{ system_reserved_cgroups_for_service_slice }}" system_reserved_cgroups: "/{{ system_reserved_cgroups_for_service_slice }}"
system_memory_reserved: 512Mi system_memory_reserved: "512Mi"
system_cpu_reserved: 500m system_cpu_reserved: "500m"
# system_ephemeral_storage_reserved: 2Gi system_ephemeral_storage_reserved: "500Mi"
# system_pid_reserved: "1000" system_pid_reserved: 1000
# Reservation for control plane hosts
system_master_memory_reserved: 256Mi
system_master_cpu_reserved: 250m
# system_master_ephemeral_storage_reserved: 2Gi
# system_master_pid_reserved: "1000"
## Eviction Thresholds to avoid system OOMs ## Eviction Thresholds to avoid system OOMs
# https://kubernetes.io/docs/tasks/administer-cluster/reserve-compute-resources/#eviction-thresholds # https://kubernetes.io/docs/tasks/administer-cluster/reserve-compute-resources/#eviction-thresholds

View File

@ -60,56 +60,16 @@ clusterDNS:
- {{ dns_address }} - {{ dns_address }}
{% endfor %} {% endfor %}
{# Node reserved CPU/memory #} {# Node reserved CPU/memory #}
{% if kube_reserved | bool %} {% for scope in "kube", "system" %}
kubeReservedCgroup: {{ kube_reserved_cgroups }} {% if lookup('ansible.builtin.vars', scope + "_reserved") | bool %}
{{ scope }}ReservedCgroup: {{ lookup('ansible.builtin.vars', scope + '_reserved_cgroups') }}
{% endif %} {% endif %}
kubeReserved: {{ scope }}Reserved:
{% if 'kube_control_plane' in group_names %} {% for resource in "cpu", "memory", "ephemeral-storage", "pid" %}
cpu: "{{ kube_master_cpu_reserved }}" {{ resource }}: "{{ lookup('ansible.builtin.vars', scope + '_' ~ (resource | replace('-', '_')) + '_reserved') }}"
memory: {{ kube_master_memory_reserved }} {% endfor %}
{% if kube_master_ephemeral_storage_reserved is defined %} {% endfor %}
ephemeral-storage: {{ kube_master_ephemeral_storage_reserved }} {% if eviction_hard is defined and eviction_hard %}
{% endif %}
{% if kube_master_pid_reserved is defined %}
pid: "{{ kube_master_pid_reserved }}"
{% endif %}
{% else %}
cpu: "{{ kube_cpu_reserved }}"
memory: {{ kube_memory_reserved }}
{% if kube_ephemeral_storage_reserved is defined %}
ephemeral-storage: {{ kube_ephemeral_storage_reserved }}
{% endif %}
{% if kube_pid_reserved is defined %}
pid: "{{ kube_pid_reserved }}"
{% endif %}
{% endif %}
{% if system_reserved | bool %}
systemReservedCgroup: {{ system_reserved_cgroups }}
systemReserved:
{% if 'kube_control_plane' in group_names %}
cpu: "{{ system_master_cpu_reserved }}"
memory: {{ system_master_memory_reserved }}
{% if system_master_ephemeral_storage_reserved is defined %}
ephemeral-storage: {{ system_master_ephemeral_storage_reserved }}
{% endif %}
{% if system_master_pid_reserved is defined %}
pid: "{{ system_master_pid_reserved }}"
{% endif %}
{% else %}
cpu: "{{ system_cpu_reserved }}"
memory: {{ system_memory_reserved }}
{% if system_ephemeral_storage_reserved is defined %}
ephemeral-storage: {{ system_ephemeral_storage_reserved }}
{% endif %}
{% if system_pid_reserved is defined %}
pid: "{{ system_pid_reserved }}"
{% endif %}
{% endif %}
{% endif %}
{% if ('kube_control_plane' in group_names) and (eviction_hard_control_plane is defined) and eviction_hard_control_plane %}
evictionHard:
{{ eviction_hard_control_plane | to_nice_yaml(indent=2) | indent(2) }}
{% elif ('kube_control_plane' not in group_names) and (eviction_hard is defined) and eviction_hard %}
evictionHard: evictionHard:
{{ eviction_hard | to_nice_yaml(indent=2) | indent(2) }} {{ eviction_hard | to_nice_yaml(indent=2) | indent(2) }}
{% endif %} {% endif %}