-
Notifications
You must be signed in to change notification settings - Fork 38.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[KEP-2395] Phase 4 - Disabling In-Tree Providers #117503
[KEP-2395] Phase 4 - Disabling In-Tree Providers #117503
Conversation
/assign @andrewsykim @nckturner |
/sig cloud-provider |
/priority important-soon |
There's "unit tests" for these scripts that will need tweaking So this generally means CI will not be covering them now? |
e1ae4f5
to
68c59fc
Compare
@BenTheElder that's what i am trying to figure out here, which tests we will fail and will need another place/way to test. so far it seems to be just |
68c59fc
to
a7901cd
Compare
a7901cd
to
aa9a7ec
Compare
/cc @ruiwen-zhao |
cebdf42
to
ceaed50
Compare
Done! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
LGTM label has been added. Git tree hash: 64f2e107fa5e87e05b8de031e282e4fa89135e28
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: dims, tzneal The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Thanks dims |
cc: @andrewsykim @liggitt |
there are more failures in other components
it seems to be a more general rbac problem |
the kube-addong-manager is not able to register
|
the kube-master-configuration scripts fails
|
export FEATURE_GATES="${FEATURE_GATES},DisableKubeletCloudCredentialProviders=True,DisableCloudProviders=True" | ||
fi | ||
fi | ||
export ENABLE_AUTH_PROVIDER_GCP="${ENABLE_AUTH_PROVIDER_GCP:-false}" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
if [[ "${CLOUD_PROVIDER_FLAG:-}" == "external" ]]; then
export ENABLE_AUTH_PROVIDER_GCP=true
/triage accepted |
Changelog suggestion -In tree cloud providers are now switched off by default. Please use DisableCloudProviders and DisableKubeletCloudCredentialProvider feature flags if you still need this functionality.
+In-tree cloud provider integrations are now switched off by default. Please use the `DisableCloudProviders` and `DisableKubeletCloudCredentialProvider` feature flags if you still need this functionality. |
Relevant to kubernetes/enhancements#2395 |
KEP-2395 states that Beta was targeted for v1.26, So we missed the boat and now it's
v1.28v1.29 cycle :) Let's see if we can land this now and adjust the CI jobs as needed.https://github.com/kubernetes/enhancements/tree/master/keps/sig-cloud-provider/2395-removing-in-tree-cloud-providers#phase-4---disabling-in-tree-providers
DisableCloudProviders - this feature gate will disable any functionality in kube-apiserver, kube-controller-manager and kubelet related to the --cloud-provider component flag.
DisableKubeletCloudCredentialProvider - this feature gate will disable in-tree functionality in the kubelet to authenticate to the Azure and GCP container registries for image pull credentials.
KEP metadata update in https://github.com/kubernetes/enhancements/pull/4171/files
What type of PR is this?
/kind feature
What this PR does / why we need it:
Which issue(s) this PR fixes:
Fixes #
Special notes for your reviewer:
Does this PR introduce a user-facing change?
Additional documentation e.g., KEPs (Kubernetes Enhancement Proposals), usage docs, etc.: