关于kubelet参数配置

环境信息:
RKE2 版本:
v1.34.7+rke2r1

节点 CPU 架构、操作系统和版本:

  • OS: Rocky Linux 8.10 (Green Obsidian)
  • Kernel: 4.18.0-553.146.1.el8_10.x86_64

集群配置:

3master 3etcd 6node

问题描述:
我在 RKE2 集群中想配置 kubelet 的节点驱逐、资源预留、镜像 GC 等相关参数,例如:

  • eviction-hard
  • eviction-soft
  • eviction-soft-grace-period
  • eviction-max-pod-grace-period
  • eviction-pressure-transition-period
  • kube-reserved
  • system-reserved
  • image-gc-high-threshold
  • image-gc-low-threshold
  • minimum-image-ttl-duration

根据 RKE2 官方文档,目前比较直接的方式是通过 kubelet-arg 在 /etc/rancher/rke2/config.yaml 中向 kubelet 透传参数。

但是实际配置完成并重启 RKE2 后,kubelet 日志中会打印大量 deprecated 警告,提示这些参数不建议再通过 flag 方式传递,而应该通过 kubelet 的 --config 指定配置文件方式设置。

所以想问一下:在 RKE2 中,后续是否有计划支持生成并配置config文件
还有对于 eviction、reserved、image gc 这类 kubelet 参数,RKE2 当前推荐的标准配置方式到底是什么。

重现步骤:

  1. 安装 RKE2
  2. 在 /etc/rancher/rke2/config.yaml 中通过 kubelet-arg 配置相关 kubelet 参数
  3. 重启 rke2-server 或 rke2-agent
  4. 查看 kubelet 启动日志
  • 安装 RKE2 的命令:
<!-- 填写你的实际安装命令 -->
  • 配置示例:
kubelet-arg:
  - "eviction-hard=memory.available<10%,nodefs.available<10%,imagefs.available<15%"
  - "eviction-soft=memory.available<15%"
  - "eviction-soft-grace-period=memory.available=1m30s"
  - "eviction-max-pod-grace-period=60"
  - "eviction-pressure-transition-period=5m"
  - "kube-reserved=cpu=500m,memory=1Gi,ephemeral-storage=1Gi"
  - "system-reserved=cpu=500m,memory=1Gi,ephemeral-storage=1Gi"
  - "image-gc-high-threshold=70"
  - "image-gc-low-threshold=60"
  - "minimum-image-ttl-duration=10m"
  • 重启命令:
systemctl restart rke2-server
# 或
systemctl restart rke2-agent
  • 查看日志:
journalctl -u rke2-server -b
# 或
journalctl -u rke2-agent -b

预期结果:
希望 RKE2 对 kubelet 这类参数的推荐配置方式有更清晰一致的说明。

如果 kubelet-arg 仍然是当前支持的标准方式,希望文档中能明确说明这些 deprecated 警告属于预期现象,用户可以如何理解和处理。

如果后续推荐改为 kubelet config file 方式,也希望 RKE2 能提供明确的迁移路径和配置示例。

实际结果:
RKE2 可以正常启动,参数看起来也能生效,但 kubelet 日志中会持续输出多条 deprecated 警告,例如:

  • Flag --eviction-hard has been deprecated
  • Flag --eviction-soft has been deprecated
  • Flag --kube-reserved has been deprecated
  • Flag --system-reserved has been deprecated
  • Flag --image-gc-high-threshold has been deprecated

这些日志提示应该改为通过 kubelet 的 --config 指定配置文件方式设置,但从 RKE2 使用角度看,目前不太清楚官方推荐的替代配置路径是什么。

补充说明:
从功能上看,这些参数似乎是生效的,但日志中的 deprecated 提示会让用户不确定这种方式是否仍然安全、长期可用,因此希望确认 RKE2 官方推荐的最佳实践。

日志
Flag --volume-plugin-dir has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --file-check-frequency has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --sync-frequency has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --containerd has been deprecated, This is a cadvisor flag that was mistakenly registered with the Kubelet. Due to legacy concerns, it will follow the standard CLI deprecation timeline before being removed.
Flag --eviction-hard has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --eviction-max-pod-grace-period has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --eviction-pressure-transition-period has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --eviction-soft has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --eviction-soft-grace-period has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --image-gc-high-threshold has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --image-gc-low-threshold has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --kube-reserved has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --minimum-image-ttl-duration has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --read-only-port has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --system-reserved has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.
Flag --volume-plugin-dir has been deprecated, This parameter should be set via the config file specified by the Kubelet's --config flag. See `https://kubernetes.io/docs/tasks/administer-cluster/kubelet-config-file/` for more information.