Skip to main content

Pods

By default, this is enabled.

Sync all Pod resources, including ephemeral containers, from the virtual cluster to the host cluster.

Automatically apply tolerations to all pods synced by vCluster

Kubernetes has a concept of Taints and Tolerations, which is used for controlling scheduling. If you have a use case that requires vCluster to sync all pods and automatically set a toleration on those pods, then you can achieve this with the enforceTolerations option. You can pass multiple toleration expressions, and the syncer adds them to every new pod that vCluster syncs.

sync:
toHost:
pods:
enabled: true
enforceTolerations:
- key: "example-key"
operator: "Equal"
value: "example-value"
effect: "NoSchedule"
- key: "another-key"
operator: "Exists"
effect: "PreferNoSchedule"
info

vCluster does not support setting the tolerationSeconds field of a toleration. If your use case requires this, open an issue in the vCluster repo on GitHub.

Replace container images when pods are synced

If certain images used within the virtual cluster are not accessible in the host cluster due to registry restrictions or security policies, translateImage can map these to equivalent, permitted images in the host cluster's registry.

sync:
toHost:
pods:
enabled: true
translateImage:
"virtualcluster/image:tag": "hostcluster/alternative-image:tag"

Use secrets for ServiceAccount tokens

A host Pod requires a ServiceAccount token to communicate with the virtual clusters API. If you don't want to create these secrets in the host cluster, disable this option. vCluster then adds annotations to the pods.

Config reference

Do Not Disable

Disabling the syncing of this resource could cause the vCluster to not work properly.

pods required object pro

Pods defines if pods created within the virtual cluster should get synced to the host cluster.

enabled required boolean pro

Enabled defines if pod syncing should be enabled.

translateImage required object pro

TranslateImage maps an image to another image that should be used instead. For example this can be used to rewrite a certain image that is used within the virtual cluster to be another image on the host cluster

enforceTolerations required string[] pro

EnforceTolerations will add the specified tolerations to all pods synced by the virtual cluster.

useSecretsForSATokens required boolean pro

UseSecretsForSATokens will use secrets to save the generated service account tokens by virtual cluster instead of using a pod annotation.

rewriteHosts required object pro

RewriteHosts is a special option needed to rewrite statefulset containers to allow the correct FQDN. virtual cluster will add a small container to each stateful set pod that will initially rewrite the /etc/hosts file to match the FQDN expected by the virtual cluster.

enabled required boolean pro

Enabled specifies if rewriting stateful set pods should be enabled.

initContainer required object pro

InitContainer holds extra options for the init container used by vCluster to rewrite the FQDN for stateful set pods.

image required string pro

Image is the image virtual cluster should use to rewrite this FQDN.

resources required object pro

Resources are the resources that should be assigned to the init container for each stateful set init container.

limits required object pro

Limits are resource limits for the container

requests required object pro

Requests are minimal resources that will be consumed by the container