Update a Deployment Without Downtime | Kubernetes
This page shows how to update a running Deployment to a new version using a rolling update. A rolling update gradually replaces old Pods with new ones, so your application remains available throughout the process. Objectives Trigger a rolling update on a Deployment. Monitor rollout progress. Pause and resume the…
Auditing | Kubernetes
Kubernetes auditing provides a security-relevant, chronological set of records documenting the sequence of actions in a cluster. The cluster audits the activities generated by users, by applications that use the Kubernetes API, and by the control plane itself. Auditing allows cluster administrators to answer the…
Configure Service Accounts for Pods | Kubernetes
Kubernetes offers two distinct ways for clients that run within your cluster, or that otherwise have a relationship to your cluster's control plane to authenticate to the API server. A service account provides an identity for processes that run in a Pod, and maps to a ServiceAccount object. When you authenticate to…
Configure a Security Context for a Pod or Container | Kubernetes
A security context defines privilege and access control settings for a Pod or Container. Security context settings include, but are not limited to: Discretionary Access Control: Permission to access an object, like a file, is based on user ID (UID) and group ID (GID). Security Enhanced Linux (SELinux): Objects are…
Resize CPU and Memory Resources assigned to Pods | Kubernetes
Feature state: Beta since Kubernetes v1.36; enabled by default This page explains how to change the CPU and memory resources set at the Pod level without recreating the Pod. The In-place Pod Resize feature allows modifying resource allocations for a running Pod, avoiding application disruption. The process for…