TKE 版本 | kube-proxy iptables | 推荐 kube-router 版本 | 说明 |
1.12~1.30 | v1.8.7 (nft) | <= v1.5.1 | iptables 都是低版本,无兼容性问题。 |
1.32~1.34 | v1.8.9 (nft) | v1.5.2+(推荐最新版) | iptables 都是高版本,无兼容性问题。 |
Kubernetes 对象名称 | 类型 | 请求资源 | 所属 Namespace |
networkpolicy | DaemonSet | 每个实例CPU:250m,Memory:250Mi | kube-system |
networkpolicy | ClusterRole | - | kube-system |
networkpolicy | ClusterRoleBinding | - | kube-system |
networkpolicy | ServiceAccount | - | kube-system |
kind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:name: networkpolicyrules:- apiGroups:- ""resources:- namespaces- pods- services- nodes- endpointsverbs:- list- get- watch- apiGroups:- "networking.k8s.io"resources:- networkpoliciesverbs:- list- get- watch- apiGroups:- extensionsresources:- networkpoliciesverbs:- get- list- watch
文档反馈