- Sort Score
- Result 10 results
- Languages All
Results 1 - 10 of 51 for locked (0.16 sec)
-
cni/pkg/nodeagent/netns_linux.go
} defer func() { err := threadNS.Set() // switch back if err == nil { // Unlock the current thread only when we successfully switched back // to the original namespace; otherwise leave the thread locked which // will force the runtime to scrap the current thread, that is maybe // not as optimal but at least always safe to do. runtime.UnlockOSThread() } }() return toRun() }
Go - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Wed Jan 31 10:05:36 GMT 2024 - 2.7K bytes - Viewed (0) -
manifests/charts/README.md
It is strongly recommended that different namespaces are used, with different service accounts. In particular access to the security-critical production components (root CA, policy, control) should be locked down and restricted. The new installer allows multiple instances of policy/control/telemetry - so testing/staging of new settings and versions can be performed by a different role than the prod version.
Plain Text - Registered: Wed Apr 24 22:53:08 GMT 2024 - Last Modified: Wed Feb 07 17:53:24 GMT 2024 - 6.7K bytes - Viewed (0) -
istioctl/pkg/kubeinject/testdata/inject-config-inline.yaml
spec: initContainers: - name: istio-init image: docker.io/istio/proxy_init:unittest-{{.Values.global.suffix}} containers: - name: istio-proxy
Others - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Thu Jun 15 15:02:17 GMT 2023 - 202 bytes - Viewed (0) -
bin/update_deps.sh
# shellcheck disable=SC1001 LATEST_IPTABLES_DISTROLESS_SHA256=$(crane digest gcr.io/istio-release/iptables | awk -F\: '{print $2}') sed -i -E "s/sha256:[a-z0-9]+/sha256:${LATEST_IPTABLES_DISTROLESS_SHA256}/g" pilot/docker/Dockerfile.proxyv2
Shell Script - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Tue Sep 12 14:07:30 GMT 2023 - 2K bytes - Viewed (0) -
manifests/charts/base/values.yaml
# ImagePullSecrets for control plane ServiceAccount, list of secrets in the same namespace # to use for pulling any images in pods that reference this ServiceAccount. # Must be set for any cluster configured with private docker registry. imagePullSecrets: [] # Used to locate istiod. istioNamespace: istio-system externalIstiod: false remotePilotAddress: ""
Others - Registered: Wed Apr 24 22:53:08 GMT 2024 - Last Modified: Mon Apr 22 22:00:40 GMT 2024 - 1.3K bytes - Viewed (0) -
cni/pkg/nodeagent/informers_test.go
waitForMockCalls() // wait until pod add was called mt.Assert(EventTotals.Name(), map[string]string{"type": "add"}, monitortest.AtLeast(1)) assertPodAnnotated(t, client, pod) // check expectations on mocked calls fs.AssertExpectations(t) } func assertPodAnnotated(t *testing.T, client kube.Client, pod *corev1.Pod) { for i := 0; i < 5; i++ {
Go - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Thu Feb 08 01:03:24 GMT 2024 - 15.8K bytes - Viewed (0) -
cni/test/install_cni.go
} } t.Logf("PASS: All temporary files removed from %v", tempCNIConfDir) } // doTest sets up necessary environment variables, runs the Docker installation // container and verifies output file correctness. func doTest(t *testing.T, chainedCNIPlugin bool, wd, preConfFile, resultFileName, delayedConfFile, expectedOutputFile,
Go - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Fri Jan 26 20:34:28 GMT 2024 - 12.5K bytes - Viewed (0) -
cni/pkg/iptables/iptables.go
// // We want to do the same thing in ambient but can't rely on podSpec injection. So, do effectively the same thing, // but with iptables rules - use `--socket-exists` as a proxy for "is this a forwarded packet" vs "is this originating from // a local node socket". If the latter, outside the pod in the host netns, redirect that traffic to a hardcoded/custom proxy
Go - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 19.6K bytes - Viewed (0) -
common/scripts/metallb-native.yaml
name: metallb-system:speaker subjects: - kind: ServiceAccount name: speaker namespace: metallb-system --- apiVersion: v1 data: excludel2.yaml: | announcedInterfacesToExclude: ["^docker.*", "^cbr.*", "^dummy.*", "^virbr.*", "^lxcbr.*", "^veth.*", "^lo$", "^cali.*", "^tunl.*", "^flannel.*", "^kube-ipvs.*", "^cni.*", "^nodelocaldns.*"] kind: ConfigMap metadata: name: metallb-excludel2
Others - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Fri Feb 23 23:56:31 GMT 2024 - 63.9K bytes - Viewed (0) -
common-protos/k8s.io/api/core/v1/generated.proto
map<string, string> options = 5; } // Represents a Flocker volume mounted by the Flocker agent. // One and only one of datasetName and datasetUUID should be set. // Flocker volumes do not support ownership management or SELinux relabeling. message FlockerVolumeSource { // datasetName is Name of the dataset stored as metadata -> name on the dataset for Flocker // should be considered as deprecated // +optional
Plain Text - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Mon Mar 11 18:43:24 GMT 2024 - 255.8K bytes - Viewed (0)