当前位置: 首页 > news >正文

服装商店的网站建设要求window服务器如何做网站访问

服装商店的网站建设要求,window服务器如何做网站访问,搜索量最大的关键词,宁波市建设银行网站导语#xff1a; k8s通过psp限制nvidia-plugin插件的使用。刚开始接触psp 记录一下 后续投入生产测试了再完善。 通过apiserver开启psp 静态pod会自动更新 # PSP(Pod Security Policy) 在默认情况下并不会开启。通过将PodSecurityPolicy关键词添加到 --enbale-admission-plu…导语 k8s通过psp限制nvidia-plugin插件的使用。刚开始接触psp 记录一下 后续投入生产测试了再完善。 通过apiserver开启psp 静态pod会自动更新 # PSP(Pod Security Policy) 在默认情况下并不会开启。通过将PodSecurityPolicy关键词添加到 --enbale-admission-plugins 配置数组后可以开启PSP权限认证功能。 # /etc/kubernetes/manifests/kube-apiserver.yaml 在NodeRestriction后添加PodSecurityPolicy - --enable-admission-pluginsNodeRestriction,PodSecurityPolicy直接创建容器测试 lung.yaml apiVersion: apps/v1 kind: Deployment metadata:name: lunglabels:k8s-app: lungk8s-med-type: biz-internel spec:strategy:type: Recreatereplicas: 1selector:matchLabels:k8s-app: lungtemplate:metadata:labels:k8s-app: lungspec: # runtimeClassName: nvidia # hostPID: truecontainers:- name: lungimage: nvidia/cuda:11.3.0-base-ubi8command: [sh,-c,tail -f /dev/null ]#command: [sh,-c,for i in ls /srv/conf-drwise220531;do rm -rf /root/lung/$i/conf ln -s /srv/conf-drwise220531/$i/conf /root/lung/$i/ ;done rm -rf /root/lung/Release/path.conf /root/lung/path.conf ln -s /srv/conf-drwise220531/Release/path.conf /root/lung/Release/ ln -s /root/lung/Release/path.conf /root/lung/ sh /root/aiclassifier/startup.sh sh /root/lung/startup.sh ] # securityContext: # privileged: trueenv:- name: NVIDIA_DRIVER_CAPABILITIESvalue: compute,utility,video,graphics,display- name: NVIDIA_VISIBLE_DEVICESvalue: allvolumeMounts:- mountPath: /dev/shmname: dshmvolumes:- name: dshmemptyDir:medium: MemorysizeLimit: 1Gi #deepwise-operator # serviceAccountName: deepwise-operator# 创建deployment测试 发下会有psp的问题 # 注意开启PodSecurityPolicy功能后即使没有使用任何安全策略都会使得创建pods包括调度任务重新创建pods失败kubectl apply -f lung -n deepwise 创建对应的资源限制策略 4.nvidia-plugin.yaml # 显卡驱动的限制 apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata:name: psp-nvidia spec:privileged: falsefsGroup:rule: RunAsAnyrunAsUser:rule: RunAsAnyseLinux:rule: RunAsAnysupplementalGroups:rule: RunAsAnyvolumes:- *hostPID: falsehostIPC: falsehostNetwork: false--- apiVersion: v1 kind: ServiceAccount metadata:namespace: kube-systemname: nvidiaoperator--- kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata:name: psp-permissive-nvidianamespace: kube-system rules:- apiGroups:- extensionsresources:- podsecuritypoliciesresourceNames:- psp-nvidiaverbs:- use ---apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata:name: psp-permissive-nvidianamespace: kube-system roleRef:apiGroup: rbac.authorization.k8s.iokind: Rolename: psp-permissive-nvidia subjects:- kind: ServiceAccountname: nvidiaoperatornamespace: kube-system --- apiVersion: apps/v1 kind: DaemonSet metadata:name: nvidia-device-plugin-daemonsetnamespace: kube-system spec:selector:matchLabels:name: nvidia-device-plugin-dsupdateStrategy:type: RollingUpdatetemplate:metadata:# This annotation is deprecated. Kept here for backward compatibility# See https://kubernetes.io/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/annotations:scheduler.alpha.kubernetes.io/critical-pod: labels:name: nvidia-device-plugin-dsspec:runtimeClassName: nvidiatolerations:# This toleration is deprecated. Kept here for backward compatibility# See https://kubernetes.io/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/- key: CriticalAddonsOnlyoperator: Exists- key: nvidia.com/gpuoperator: Existseffect: NoSchedule# Mark this pod as a critical add-on; when enabled, the critical add-on# scheduler reserves resources for critical add-on pods so that they can# be rescheduled after a failure.# See https://kubernetes.io/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/priorityClassName: system-node-criticalcontainers:- image: harbor.deepwise.com/terra-k8s/k8s-device-plugin:v0.10.0name: nvidia-device-plugin-ctrargs: [--fail-on-init-errorfalse]securityContext:allowPrivilegeEscalation: falsecapabilities:drop: [ALL]volumeMounts:- name: device-pluginmountPath: /var/lib/kubelet/device-pluginsvolumes:- name: device-pluginhostPath:path: /var/lib/kubelet/device-pluginsserviceAccountName: nvidiaoperator5.nvida-psp.yaml apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata:name: psp-nvidia spec:privileged: falsefsGroup:rule: RunAsAnyrunAsUser:rule: RunAsAnyseLinux:rule: RunAsAnysupplementalGroups:rule: RunAsAnyvolumes:- *hostPID: falsehostIPC: falsehostNetwork: false--- apiVersion: v1 kind: ServiceAccount metadata:namespace: kube-systemname: nvidiaoperator--- kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata:name: psp-permissive-nvidianamespace: kube-system rules:- apiGroups:- extensionsresources:- podsecuritypoliciesresourceNames:- psp-nvidiaverbs:- use ---apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata:name: psp-permissive-nvidianamespace: kube-system roleRef:apiGroup: rbac.authorization.k8s.iokind: Rolename: psp-permissive-nvidia subjects:- kind: ServiceAccountname: nvidiaoperatornamespace: kube-system6.deepwise-psp.yaml # 用户的限制 apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata:name: psp-deepwise spec:privileged: falsefsGroup:rule: RunAsAnyrunAsUser:rule: RunAsAnyseLinux:rule: RunAsAnysupplementalGroups:rule: RunAsAnyvolumes:- *hostPID: falsehostIPC: falsehostNetwork: false--- apiVersion: v1 kind: ServiceAccount metadata:namespace: deepwisename: deepwise-operator--- kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata:name: psp-permissive-deepwisenamespace: deepwise rules:- apiGroups:- extensionsresources:- podsecuritypoliciesresourceNames:- psp-deepwiseverbs:- use ---apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata:name: psp-permissive-deepwisenamespace: deepwise roleRef:apiGroup: rbac.authorization.k8s.iokind: Rolename: psp-permissive-deepwise subjects:- kind: ServiceAccountname: deepwise-operatornamespace: deepwise7.runtimeclass.yaml apiVersion: node.k8s.io/v1 kind: RuntimeClass metadata:name: nvidia handler: nvidia如果是docker运行时handler需要调整为docker。使用containerd则不需要调整。参考https://opni.io/setup/gpu/ 重新创建lung的deployment # 加上runtimeClassName: nvidia # 加上serviceAccountName: deepwise-operator apiVersion: apps/v1 kind: Deployment metadata:name: lunglabels:k8s-app: lungk8s-med-type: biz-internel spec:strategy:type: Recreatereplicas: 1selector:matchLabels:k8s-app: lungtemplate:metadata:labels:k8s-app: lungspec:runtimeClassName: nvidia # hostPID: truecontainers:- name: lungimage: nvidia/cuda:11.3.0-base-ubi8command: [sh,-c,tail -f /dev/null ]#command: [sh,-c,for i in ls /srv/conf-drwise220531;do rm -rf /root/lung/$i/conf ln -s /srv/conf-drwise220531/$i/conf /root/lung/$i/ ;done rm -rf /root/lung/Release/path.conf /root/lung/path.conf ln -s /srv/conf-drwise220531/Release/path.conf /root/lung/Release/ ln -s /root/lung/Release/path.conf /root/lung/ sh /root/aiclassifier/startup.sh sh /root/lung/startup.sh ] # securityContext: # privileged: trueenv:- name: NVIDIA_DRIVER_CAPABILITIESvalue: compute,utility,video,graphics,display- name: NVIDIA_VISIBLE_DEVICESvalue: allvolumeMounts:- mountPath: /dev/shmname: dshmvolumes:- name: dshmemptyDir:medium: MemorysizeLimit: 1Gi #deepwise-operatorserviceAccountName: deepwise-operator参考文档 https://kubernetes.io/zh-cn/docs/reference/access-authn-authz/admission-controllers/ https://blog.csdn.net/tushanpeipei/article/details/121940757 https://blog.csdn.net/weixin_45081220/article/details/125407608
http://www.dnsts.com.cn/news/271376.html

相关文章:

  • python做爬虫和做网站网站开发合同缺陷
  • 网站建设使用的技术东莞网站建设方案企业
  • 网页设计与网站建设课程报告深圳网络品牌推广公司
  • 网站开发目的意义wordpress上图片不显示
  • 网站空间就是虚拟主机吗做网站的5要素
  • 网站建设后的专人维护网站建设html模板下载
  • 百度网站建设工资网络信息发布平台
  • 内江规划建设教育网站wordpress totalpoll
  • 兰州网站运营诊断wordpress怎么压缩
  • 张北县网站建设附近最好的装修公司
  • 求手机网站河北港网站建设
  • 网站开发公司选择网站是由多个网页组成的吗
  • 建设网站要多少页面响应式网站对seo
  • 网站新闻后台怎么做wordpress自动增加阅读量
  • 做美食推广的网站搜狗引擎搜索
  • 济源网站建设的公司图案logo设计
  • 佛山网站推广优化公司怎么做网站的seo排名知乎
  • 如何制作网站效果图做网站一定要域名嘛
  • 旅游网站建设风险网站开发的目的 实习报告
  • 做兼职女的网站北京本地网络推广平台
  • 南宁工程建设网站有哪些搜狗收录批量查询
  • 建设班级网站首页微信公众号怎么开店
  • 网站做抽奖活动网站后台登陆地址
  • 有做材料的网站吗上线了建站教程
  • 国外做的不错的网站石家庄网站建设开发
  • 做网站用什么需要好音乐网站制作教程步骤
  • 外贸电商平台哪个网站最好天猫入驻官网入口
  • 建网站支持设备是什么意思微网站怎么做微名片
  • 什么公司做企业网站深圳seo优化排名公司
  • 东莞企业建站程序学生个人网页制作html动态