From a71347e3284c096297b789fe822be4e9f541073a Mon Sep 17 00:00:00 2001 From: Jerome Petazzoni Date: Mon, 3 Sep 2018 11:16:54 -0500 Subject: [PATCH] Add owners and dependents And explain how to find orphan resources. --- slides/k8s/owners-and-dependents.md | 157 ++++++++++++++++++++++++++++ slides/new-content.yml | 1 + 2 files changed, 158 insertions(+) create mode 100644 slides/k8s/owners-and-dependents.md diff --git a/slides/k8s/owners-and-dependents.md b/slides/k8s/owners-and-dependents.md new file mode 100644 index 00000000..098be384 --- /dev/null +++ b/slides/k8s/owners-and-dependents.md @@ -0,0 +1,157 @@ +# Owners and dependents + +- Some objects are created by other objects + + (example: pods created by replica sets, themselves created by deployments) + +- When an *owner* object is deleted, its *dependents* are deleted + + (this is the default behavior; it can be changed) + +- We can delete a dependent directly if we want + + (but generally, the owner will recreate another right away) + +- An object can have multiple owners + +--- + +## Finding out the owners of an object + +- The owners are recorded in the field `ownerReferences` in the `metadata` block + +.exercise[ + +- Let's start a replicated `nginx` deployment: + ```bash + kubectl run yanginx --image=nginx --replicas=3 + ``` + +- Once it's up, check the corresponding pods: + ```bash + kuebectl get pods -l run=yanginx -o yaml | head -n 25 + ``` + +] + +These pods are owned by a ReplicaSet named yanginx-xxxxxxxxxx. + +--- + +## Listing objects with their owners + +- This is a good opportunity to try the `custom-columns` output! + +.exercise[ + +- Show all pods with their owners: + ```bash + kubectl get pod -o custom-columns=\ + NAME:.metadata.name,\ + OWNER-KIND:.metadata.ownerReferences[0].kind,\ + OWNER-NAME:.metadata.ownerReferences[0].name + ``` + +] + +Note: the `custom-columns` option should be one long option (without spaces), +so the lines should not be indented (otherwise the indentation will insert spaces). + +--- + +## Deletion policy + +- When deleting an object through the API, three policies are available: + + - foreground (API call returns after all dependents are deleted) + + - background (API call returns immediately; dependents are scheduled for deletion) + + - orphan (the dependents are not deleted) + +- When deleting an object with `kubectl`, this is selected with `--cascade`: + + - `--cascade=true` deletes all dependent objects (default) + + - `--cascade=false` orphans dependent objects + +--- + +## What happens when an object is deleted + +- It is removed from the list of owners of its dependents + +- If, for one of these dependents, the list of owners becomes empty ... + + - if the policy is "orphan", the object stays + + - otherwise, the object is deleted + +--- + +## Orphaning pods + +- We are going to delete the Deployment and Replica Set that we created + +- ... without deleting the corresponding pods! + +.exercise[ + +- Delete the Deployment: + ```bash + kubectl delete deployment -l run=yanginx --cascade=false + ``` + +- Delete the Replica Set: + ```bash + kubectl delete replicaset -l run=yanginx --cascade=false + ``` + +- Check that the pods are still here: + ```bash + kubectl get pods + ``` + +] + +--- + +## Finding orphan objects + +- We're going to output all pods in JSON format + +- Then we will use `jq` to keep only the ones *without* an owner + +- And we will display their name + +.exercise[ + +- List all pods that *do not* have an owner: + ```bash + kubectl get pod -o json | jq -r " + .items[] + | select(.metadata.ownerReferences|not) + | .metadata.name" + ``` + +] + +--- + +## Deleting orphan pods + +- Now that we can list orphan pods, deleting them is easy + +.exercise[ + +- Add `| xargs kubectl delete pod` to the previous command: + ```bash + kubectl get pod -o json | jq -r " + .items[] + | select(.metadata.ownerReferences|not) + | .metadata.name" | xargs kubectl delete pod + ``` + +] + +As always, the [doc](https://kubernetes.io/docs/concepts/workloads/controllers/garbage-collection/) has useful extra information and pointers. \ No newline at end of file diff --git a/slides/new-content.yml b/slides/new-content.yml index 7fb6eb45..e034b243 100644 --- a/slides/new-content.yml +++ b/slides/new-content.yml @@ -12,6 +12,7 @@ chapters: - k8s/build-with-docker.md - k8s/build-with-kaniko.md - k8s/configuration.md + - k8s/owners-and-dependents.md - k8s/statefulsets.md - k8s/portworx.md - - k8s/authn-authz.md