Version: v26.09

cluster-api-provider-bke Configuration Parameters ​

Common Configuration Scenarios Quick Reference ​

Table 1 Common Configuration Scenarios Quick Reference Table

Configuration ScenarioMain Configuration ItemsReference Section
Write BKECluster YAML via bke init --file/-f.metadata.name, spec.clusterConfig.*, spec.controlPlaneEndpoint.*This article's BKECluster CRD Configuration; for command-line flags see bkeadm Configuration Parameters.
Configure cluster version, image repository, system package source, and NTP.spec.clusterConfig.cluster.*, spec.clusterConfig.customExtra{}This article's BKECluster CRD Configuration, customExtra.
Configure addons and their parameters.spec.clusterConfig.addons[], addons[].paramThis article's addons[].param.
Declare target nodes and SSH connection information.metadata.name, spec.ip, spec.username, spec.password, spec.role[]This article's BKENode CRD.
Customize kubelet/containerd binary component configuration (KCT/CCT).spec.KubeletConfigRef, spec.clusterConfig.cluster.containerdConfigRefThis article's KCT and CCT Configuration and References; for field details and examples see Binary Component Custom Configuration.
Override containerd service, registry, or script configuration.ContainerdConfig.spec.service.*, spec.main.*, spec.registry.*, spec.script.*This article's ContainerdConfig CRD.
Override kubelet configuration, systemd service, extra files, or commands.KubeletConfig.spec.kubeletConfig{}, spec.kubeletService.*, spec.files[], spec.commands[]This article's KubeletConfig CRD.
Adjust controller behavior or troubleshoot the upgrade process.BKECluster annotations, Cluster API annotations, upgrade-related annotationsThis article's Annotations.

cluster-api-provider-bke ​

BKEControllerManager Runtime Parameters ​

Table 2 BKEControllerManager command Configuration Items Table

Configuration Item NameDefault ValueDescriptionSetting Method
--metrics-bind-address0metrics listen address; overridden to :8080 in deployment YAML, optional.flag/YAML
--health-probe-bind-address8081Health check listen address, optional.flag
--health-probe-schemehttpHealth check protocol, optional; this is the code default value, supports https (when enabled, starts a separate HTTPS service listening on --health-probe-port port, using certificates /etc/kubernetes/tls-server.crt/tls-server.key); deployment YAML can override, e.g., v1.4.3 manifest overrides to https.flag
--health-probe-port9444HTTPS health check port, optional.flag
--leader-electfalseLeader election switch; set to true in controller_manager_config.yaml, optional.flag/YAML
--webhook-cert-dir/tmp/k8s-webhook-server/serving-certs/Webhook TLS certificate directory; must match the mount path /tmp/k8s-webhook-server/serving-certs of bke-webhook-secret in the Deployment, optional.flag
--webhook-port9443Webhook port, optional.flag
--webhook-hostNoneWebhook host, optional.flag
--bke-cluster-concurrency10Number of concurrent BKECluster reconciles, optional.flag
--bke-machine-concurrency10Number of concurrent BKEMachine reconciles, optional.flag
--enable-internal-updatefalseInternal update switch, optional.flag
--oci-digest-check-interval300UpgradePath OCI digest check interval, in seconds, optional.flag
--oci-registry-usernameNoneOCI registry username, optional.flag
--oci-registry-passwordNoneOCI registry password, optional.flag
--oci-registry-insecure-skip-verifytrueSkip TLS verification when pulling from OCI, optional.flag
--enable-oci-digest-monitortrueUpgradePath digest monitor switch, optional.flag
--release-cache-dir/var/lib/bke/release-cacheLocal cache directory for release image bundle, optional.flag/hostPath
--helm-component-supportfalseGlobally enable yaml/helm component execution path; when cluster annotation cvo.openfuyao.cn/helm-component exists, the annotation takes precedence, optional.flag/YAML
--client-qps50Maximum requests per second for the Kubernetes API client.flag
--client-burst100Burst request peak for the Kubernetes API client.flag
--client-config-file/etc/bke/client-config.yamlClient configuration rate-limiting file path; can configure qps and burst.flag

Table 3 BKEControllerManager env Configuration Items Table

Configuration Item NameDefault ValueDescriptionSetting Method
env.containertrueIndicates running in a container, optional.YAML
env.OLOGGER_CONFIG/etc/openFuyao/ologger/ologger.yamlLogging configuration path, optional.YAML/env
env.OLOGGER_PATH/var/log/openFuyao/$(POD_NAME).logLog file path, optional.YAML/env

BKECluster CRD Configuration ​

When using these configurations via bke init --file/-f <BKECluster YAML>, also refer to the bke init flag descriptions in bkeadm Configuration Parameters.

icon Note:

  • BKECluster (kubectl short name bc) describes the version, repository, network, addons, kubelet/containerd references, etc. of the cluster to be created. Common commands: kubectl get bc -A, kubectl edit bc -n <namespace> <name>, kubectl describe bc -n <namespace> <name>.
  • The "Default Value" column in the table below lists the officially recommended configurations for the openFuyao platform (default values filled in by the controller/installer when the CRD is empty). For custom deployments, it is recommended to first follow the recommended values after confirming business constraints, and only override environment-related items such as repository addresses, node networks, and addon parameters as needed.
  • Related resources: For the fields and reference methods of KubeletConfig (kct) and ContainerdConfig (cct), see the subsequent sections of this article and Binary Component Custom Configuration.

Table 4 BKECluster CRD Configuration Items Table

Configuration Item NameDefault ValueDescriptionSetting Method
metadata.creationTimestampNoneCreation time; usually written by Kubernetes, can be left empty in user configuration, optional.CRD YAML
metadata.namebke-clusterBKECluster resource name, optional.CRD YAML
metadata.namespacebke-clusterNamespace where BKECluster resides, optional.CRD YAML
spec.KubeletConfigRef.namebke-kubeletName of the referenced KubeletConfig, optional.CRD YAML
spec.KubeletConfigRef.namespacebke-kubeletNamespace of the referenced KubeletConfig, optional.CRD YAML
spec.clusterConfig.addons[].nameNoneAddon name, required.CRD YAML
spec.clusterConfig.addons[].versionNoneAddon version, required.CRD YAML
spec.clusterConfig.addons[].param{}NoneAddon extended parameters (detail), optional.CRD YAML
spec.clusterConfig.addons[].blockNoneWhether to block and wait for addon installation to complete, optional.CRD YAML
spec.clusterConfig.cluster.agentHealthPortNonebkeagent health port: 1-65535, required.CRD YAML
spec.clusterConfig.cluster.apiServer.extraArgs{}authorization-mode=Node,RBACapiserver extra command-line arguments, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.certificatesDir/etc/kubernetes/pkiCertificate directory, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.chartRepo.domaincr.openfuyao.cnChart repo domain, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.chartRepo.port443/40443Chart repo access port; default public chart is 443, non-default domain is 40443, optional; must be consistent with the actual chart repo service port and avoid conflicts with other repository service ports on the same node.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.chartRepo.prefixchartChart repo prefix, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.containerRuntime.cricontainerdCRI, supports containerd, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.containerRuntime.param{}cgroupDriver=systemd
containerd data-root=/var/lib/containerd
Runtime extended parameters, such as data-root, cgroupDriver, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.containerRuntime.runtimeruncOCI runtime, supports runc, richrunc, kata, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.containerdConfigRef.namebke-containerdName of the referenced ContainerdConfig, required.CRD YAML
spec.clusterConfig.cluster.containerdConfigRef.namespacebke-containerdNamespace of the referenced ContainerdConfig, required.CRD YAML
spec.clusterConfig.cluster.containerdVersionv2.1.1containerd default version, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.controllerManager.extraArgs{}Nonecontroller-manager extra command-line arguments, optional.CRD YAML
spec.clusterConfig.cluster.etcd.dataDir/var/lib/openFuyao/etcdetcd data directory, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.etcdVersionv3.6.7-of.1etcd default version, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.httpRepo.domainhttp.bocloud.k8sSystem package source domain, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.httpRepo.ipNoneSystem package source IP, required.CRD YAML
spec.clusterConfig.cluster.httpRepo.port40080System package source port, optional; independent from image repository and chart repo service ports, must avoid conflicts when customized; in offline deployment, this is the same service port as bke init's --yumRepoPort.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.httpRepo.prefixNoneSystem package source prefix, required.CRD YAML
spec.clusterConfig.cluster.imageRepo.domaindeploy.bocloud.k8sImage repository domain, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.imageRepo.ipNoneImage repository IP, required.CRD YAML
spec.clusterConfig.cluster.imageRepo.port40443Image repository port, optional; it is a different service port from the system package source and chart repo, and must be kept separate when customizing.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.imageRepo.prefixkubernetesImage repository prefix, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.kubelet.extraArgs{}Nonekubelet extra command-line arguments, optional.CRD YAML
spec.clusterConfig.cluster.kubelet.extraVolumes.hostPath/var/lib/kubeletkubelet extra mounted hostpath, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.kubelet.extraVolumes.namekubelet-root-dirkubelet extra mounted volume name, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.kubernetesVersionv1.34.3-of.1Kubernetes default version, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.networking.dnsDomaincluster.localService DNS domain suffix, determines the full DNS name format of in-cluster services. For example, for a Service kube-system/kube-dns, the default full domain name is: kube-dns.kube-system.svc.cluster.local, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.networking.podSubnet10.250.0.0/16Pod CIDR, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.networking.serviceSubnet10.96.0.0/16Service CIDR, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.ntpServerNoneNTP server, required.CRD YAML
spec.clusterConfig.cluster.openFuyaoVersionv26.09openFuyao default version, optional.CRD YAML, default when CRD is empty
spec.clusterConfig.cluster.scheduler.extraArgs{}Nonescheduler extra command-line arguments, optional.CRD YAML
spec.clusterConfig.customExtra{}NoneExtended parameters, read by templates/plugins (more details), optional.CRD YAML
spec.controlPlaneEndpoint.hostNoneControl plane access entry host, required.CRD YAML
spec.controlPlaneEndpoint.portNoneControl plane access entry port, required.CRD YAML
spec.pauseNonePause reconcile, optional.CRD YAML
spec.resetfalseWhen set to true, triggers the deletion reconciliation process for this BKECluster. To thoroughly clean up target nodes, the annotation bke.bocloud.com/ignore-target-cluster-delete must also be set to "false". For operating steps see Cluster Uninstallation.CRD YAML

addons[].param ​

Addons generated by bkeadm by default:

Table 5 bkeadm Default Addon Parameters Table

addon nameDefault Versionbkeadm default paramRemarks
kubeproxyKubernetes version corresponding directory, e.g. v1.34.3-of.1clusterNetworkModeDefault value: calico.
calicov3.31.3calicoMode
ipAutoDetectionMethod
allowTypha
typhaReplicas
Default values:
calicoMode=vxlan
ipAutoDetectionMethod=skip-interface=nerdctl*
allowTypha=false
typhaReplicas=1.
corednsv1.12.2-of.1EnableAntiAffinitytrue/false
cluster-apiv1.4.3manage
offline
sandbox
replicas
containerdVersion
openFuyaoVersion
manifestsVersion
providerVersion
ntpServer
healthPort
openfuyao-system-controllerv26.9.0helmRepo
tagVersion

Commonly used addon names and parameters:

Table 6 Common Addon Parameters Table

addon nameAdopted VersionComponent-specific/overridable param keyRemarks
nodelocaldnsv1.26.4clusterDNS
DNSserver
domain
localdns
Note that it is domain, not dnsDomain.
numa-affinity-packagev0.0.2openfuyaoRepoNUMA affinity.
redis6.1.12nodeselectorThe key name is lowercase per template.
victoriametrics-controllerlatestgrafanaNodePort
useVMSingle
kubeStateMetricsAutoSharding
kubeStateMetricsCpuCount
kubeStateMetricsMemorySize
kubeStateMetricsReplicaCount
vmAgentAllowStatefulSet
vmAgentCpuCount
vmAgentMemorySize
vmAgentReplicaCount
vmAgentScrapeInterval
vmAgentShareCount
vmAgentStorageSize
vmAlertCpuCount
vmAlertMemorySize
vmAlertReplicaCount
vmAlertManagerCpuCount
vmAlertManagerMemorySize
vmAlertManagerReplicaCount
vmClusterReplicationFactor
vmClusterRetentionPeriod
vmInsertCpuCount
vmInsertMemorySize
vmInsertReplicaCount
vmSelectCpuCount
vmSelectMemorySize
vmSelectReplicaCount
vmSelectStorageSize
vmSingleStorageSize
vmStorageCPUCount
vmStorageMemorySize
vmStorageReplicaCount
vmStorageStorageSize
The webhook fills in default values for missing items and validates some replica/share relationships.

spec.clusterConfig.customExtra{} ​

Table 7 customExtra Configuration Items Table

Configuration Item NameDefault ValueDescriptionSetting Method
customExtra.chartRepoPort38080Local chart repo port, optional; corresponds to different local services from customExtra.imageRepoPort and customExtra.yumRepoPort respectively, and must be kept separate when customizing.CLI-derived/YAML
customExtra.clusterapi26.9.0cluster-api-provider-bke version, optional.CLI-derived/YAML
customExtra.containerdcontainerd-v2.1.1-linux-{.arch}.tar.gzcontainerd installation package template name, optional.Version artifacts/YAML
customExtra.domaindeploy.bocloud.k8sImage repository domain, optional.CLI-derived/YAML
customExtra.hostNoneBootstrap node IP, optional.Generated environment/YAML
customExtra.imageRepoPort40443Local image repository port, optional; independent from the chart repo and yum/http repo ports, and must be kept separate when customizing.CLI-derived/YAML
customExtra.nfsserverpath/NFS service path, optional.Code default/YAML
customExtra.onlineImageNoneOnline installation image, optional.CLI-derived/YAML
customExtra.otherChartNonePrivate chart repo address, optional.CLI-derived/YAML
customExtra.otherChartIpNonePrivate chart repo resolved IP, optional.Generation logic/YAML
customExtra.otherRepoNonePrivate image repository, optional.CLI-derived/YAML
customExtra.otherRepoIpNonePrivate image repository resolved IP, optional.Generation logic/YAML
customExtra.otherSourceNonePrivate system package source, optional.CLI-derived/YAML
customExtra.yumRepoPort40080Local system package source (HTTP repo) service port, optional; independent from image repository and chart repo ports, must avoid conflicts when customized; same service port as Cluster CRD's spec.clusterConfig.cluster.httpRepo.port.CLI-derived/YAML

Port relationships and conflict check: customExtra.imageRepoPort, customExtra.chartRepoPort, and customExtra.yumRepoPort are usually derived from the --imageRepoPort, --chartRepoPort, and --yumRepoPort flags of bke init, corresponding to three independent services: the local image repository, chart repo, and yum/http repo. When customizing, they must be configured as different ports, and must avoid the Kubernetes API, console ports, and ports already occupied on the host. The bke init preflight checks whether ports are already occupied on the host and filters out existing BKE management container ports; however, it does not explicitly check for duplicates among these parameters. If ports are duplicated, failures may occur during service startup or port publishing, and you need to adjust based on the port occupancy information in the logs and retry.

BKENode CRD ​

Table 8 BKENode CRD Configuration Items Table

Configuration Item NameDefault ValueDescriptionSetting Method
metadata.creationTimestampNoneCreation time; usually written by Kubernetes, can be left empty in user configuration, optional.CRD YAML
metadata.labels.cluster.x-k8s.io/cluster-namebke-clusterAssociated Cluster API cluster name, optional.CRD YAML
metadata.nameNoneBKENode resource name, required.CRD YAML
metadata.namespacebke-clusterNamespace where BKENode resides, optional.CRD YAML
spec.hostnameNoneNode hostname, required.CRD YAML
spec.ipNoneNode IP, required.CRD YAML
spec.passwordNoneSSH password, required.CRD YAML
spec.port22SSH port, example is "22", optional.CRD YAML
spec.role[]NoneNode role, e.g. master/node, etcd, node, required.CRD YAML
spec.usernamerootSSH username, optional.CRD YAML
spec.controlPlaneNoneNode-level control plane component override configuration, optional.CRD YAML
spec.kubeletNoneNode-level kubelet override configuration, optional.CRD YAML
spec.labels[]NoneNode-level label override configuration, optional.CRD YAML

ContainerdConfig CRD ​

Table 9 ContainerdConfig CRD Configuration Items Table

Configuration Item NameDefault ValueDescriptionSetting Method
spec.configTypecombinedConfiguration type, supports service/main/registry/combined, optional.CRD YAML
spec.descriptionNoneHuman-readable description, required.CRD YAML
spec.service.execStartNonesystemd ExecStart, required.CRD YAML
spec.service.slicesystem.slicesystemd slice, optional.CRD YAML
spec.service.killModeprocessKillMode, supports control-group/process/mixed/none, optional.CRD YAML
spec.service.restartalwaysRestart policy, optional.CRD YAML
spec.service.restartSec5sRestart wait time, optional.CRD YAML
spec.service.startLimitInterval10sStart rate-limit window, optional.CRD YAML
spec.service.startLimitBurst5Start rate-limit burst count, optional.CRD YAML
spec.service.timeoutStopSec90sStop timeout, optional.CRD YAML
spec.service.logging.standardOutputjournalstdout log destination, optional.CRD YAML
spec.service.logging.standardErrorjournalstderr log destination, optional.CRD YAML
spec.service.logging.syslogIdentifierNonesyslog identifier, required.CRD YAML
spec.service.logging.logLevelMaxNoneMaximum log level, optional.CRD YAML
spec.service.customExtra{}NoneService template extended variables, optional.CRD YAML
spec.main.metricsAddressNonecontainerd metrics address, required.CRD YAML
spec.main.root/var/lib/containerdcontainerd root, optional.CRD YAML
spec.main.state/run/containerdcontainerd state, optional.CRD YAML
spec.main.sandboxImageregistry.k8s.io/pause:3.9Pause image, optional.CRD YAML
spec.main.configPath/etc/containerd/certs.dRegistry configuration directory, optional.CRD YAML
spec.main.rawTOMLNoneRaw TOML, takes precedence when provided, optional.CRD YAML
spec.registry.configPath/etc/containerd/certs.dRegistry hosts configuration directory, optional.CRD YAML
spec.registry.configs{host}NoneRegistry host configuration mapping, optional.CRD YAML
registryHost.hostNoneSingle registry host address, required.CRD YAML
registryHost.capabilitiesNoneSingle registry host capabilities, optional.CRD YAML
registryHost.skipVerifyNoneSingle registry host skip verification, optional.CRD YAML
registryHost.plainHTTPNoneSingle registry host use plain HTTP, optional.CRD YAML
registryHost.insecureNoneSingle registry host insecure setting, optional.CRD YAML
registryHost.tls.caFileNoneTLS CA file, required.CRD YAML
registryHost.tls.certFileNoneTLS cert file, required.CRD YAML
registryHost.tls.keyFileNoneTLS key file, required.CRD YAML
registryHost.tls.insecureSkipVerifyNoneTLS skip certificate verification, optional. Must not be set to true in production environments; only allowed for temporary troubleshooting or isolated test environments for short periods.CRD YAML
registryHost.auth.usernameNoneRegistry authentication username, required.CRD YAML
registryHost.auth.passwordNoneRegistry authentication password, required.CRD YAML
registryHost.auth.authNoneRegistry auth field, optional.CRD YAML
registryHost.auth.identityTokenNoneRegistry identity token, optional.CRD YAML
registryHost.auth.registryTokenNoneRegistry token, optional.CRD YAML
registryHost.headerNoneAdditional header, optional.CRD YAML
registryHost.overridePathNonePath override, required.CRD YAML
spec.script.contentNoneShell script content, optional.CRD YAML
spec.script.pathNoneShell script path, optional.CRD YAML
spec.script.argsNoneShell script arguments, optional.CRD YAML
spec.script.interpreter/bin/bashShell script interpreter, optional.CRD YAML

KubeletConfig CRD ​

Table 10 KubeletConfig CRD Configuration Items Table

Configuration Item NameDefault ValueDescriptionSetting Method
spec.kubeletConfig{}Nonekubelet native configuration map, RawExtension, optional.CRD YAML
spec.kubeletService.enabledNoneWhether to create the kubelet service, optional.CRD YAML
spec.kubeletService.serviceNameNonesystemd service name, required.CRD YAML
spec.kubeletService.unit.descriptionNoneUnit description, optional.CRD YAML
spec.kubeletService.unit.documentationNoneUnit documentation, optional.CRD YAML
spec.kubeletService.unit.afterNoneUnit After dependency, optional.CRD YAML
spec.kubeletService.unit.wantsNoneUnit Wants dependency, optional.CRD YAML
spec.kubeletService.unit.requires[]NoneUnit Requires dependency, optional.CRD YAML
spec.kubeletService.service.execStartNonekubelet startup command, required.CRD YAML
spec.kubeletService.service.restartNoneService restart policy, required.CRD YAML
spec.kubeletService.service.startLimitIntervalNoneService start rate-limit window, required.CRD YAML
spec.kubeletService.service.restartSecNoneService restart wait time, required.CRD YAML
spec.kubeletService.service.environmentNoneService environment variables, optional.CRD YAML
spec.kubeletService.service.environmentFileNoneService environment variables file, optional.CRD YAML
spec.kubeletService.service.execStartPreNoneService pre-start command, optional.CRD YAML
spec.kubeletService.service.startLimitBurstNoneService start rate-limit burst count, required.CRD YAML
spec.kubeletService.service.killModeNoneService KillMode, required.CRD YAML
spec.kubeletService.service.standardOutputNonestdout log output setting, optional.CRD YAML
spec.kubeletService.service.standardErrorNonestderr log output setting, optional.CRD YAML
spec.kubeletService.service.syslogIdentifierNonesyslog identifier, required.CRD YAML
spec.kubeletService.service.workingDirectoryNoneService working directory, optional.CRD YAML
spec.kubeletService.service.userNoneService running user, optional.CRD YAML
spec.kubeletService.service.groupNoneService running user group, optional.CRD YAML
spec.kubeletService.service.customExtraNoneService template extended variables, optional.CRD YAML
spec.kubeletService.install.wantedByNoneInstall WantedBy configuration, optional.CRD YAML
spec.kubeletService.install.requiredBy[]NoneInstall RequiredBy configuration, optional.CRD YAML
spec.files[].pathNoneExtra file path, optional.CRD YAML
spec.files[].contentNoneExtra file content, optional.CRD YAML
spec.files[].permissionsNoneExtra file permissions, optional.CRD YAML
spec.files[].ownerNoneExtra file owner, optional.CRD YAML
spec.commands[].commandNoneExtra command, optional.CRD YAML
spec.commands[].argsNoneExtra command arguments, optional.CRD YAML
spec.commands[].workingDirNoneExtra command working directory, optional.CRD YAML

KCT and CCT Configuration and References ​

KCT (KubeletConfig) and CCT (ContainerdConfig) are custom resources on the management cluster, used to deliver kubelet and containerd configurations during the node bootstrap phase, without the need to log into nodes and manually edit files.

Table 11 KCT and CCT Comparison Table

AbbreviationCR TypeAPI Resource Namekubectl Short NameBKECluster Reference Field
KCTKubeletConfigkubeletconfigskctspec.KubeletConfigRef.name / namespace
CCTContainerdConfigcontainerdconfigscctspec.clusterConfig.cluster.containerdConfigRef.name / namespace

Usage Workflow

  1. Create KCT/CCT resources on the management cluster (the same cluster as BKECluster) and fill in the spec configuration.
  2. Point to the corresponding resources via the reference fields in the BKECluster YAML; the default cluster YAML generated by bke init already contains example references.
  3. After running bke create cluster, bkeagent reads and applies the configuration during the node bootstrap phase:
    • KCT: When KubeletConfigRef is not empty, bkeagent pulls the KubeletConfig from the management cluster and processes spec.files[], spec.kubeletConfig (writes to /var/lib/kubelet/config.yaml), spec.kubeletService (generates kubelet.service), and spec.commands[] in order; variable substitution (${EXPR|command|END}) is automatically enabled.
    • CCT: When containerdConfigRef is not empty, bkeagent passes it to the InstallContainerd plugin in namespace:name form, and renders the containerd configuration and restarts the service in the order spec.script → spec.service → spec.main → spec.registry.

KCT/CCT Configuration Example (BKECluster snippet)

yaml
spec:
  KubeletConfigRef:
    name: bke-kubelet
    namespace: bke-kubelet
  clusterConfig:
    cluster:
      containerdConfigRef:
        name: bke-containerd
        namespace: bke-containerd

For complete field descriptions, variable substitution examples, and YAML samples, see Binary Component Custom Configuration.

Annotations ​

Configurable Annotations ​

These annotations affect BKECluster behavior

Table 12 Configurable Annotations Table

keySemantics and ValuesDefault Value and Priority
bke.bocloud.com/retryAn empty value retries all nodes; a non-empty value is a comma-separated list of node IPs.Triggered when the key exists; deleted after consumption.
bke.bocloud.com/deep-restore-nodetrue enables deep recovery for node initialization and reset.Defaults to true; annotation takes precedence, and when missing it is also treated as true, with true written by default.
bke.bocloud.com/ignore-namespace-deleteOnly false allows namespace deletion; any other value skips it.Defaults to true; only an exact false enters the deletion branch.
bke.bocloud.com/ignore-target-cluster-deletetrue means the target cluster is not reset when deleting management plane objects.Defaults to true; only an exact false continues cleaning up target nodes. For complete uninstallation steps see Cluster Uninstallation Overview.
bke.bocloud.com/node-boot-wait-timeoutGo duration, e.g. 30s, 10m, 1h.Defaults to 10m; valid annotation takes precedence, falls back to 10m when missing or parsing fails.

Example scenarios for using the retry annotation:

  1. Pushing the Agent fails during the EnsureBKEAgent phase.

  2. The Agent is pushed successfully during the EnsureBKEAgent phase, but bkeagent fails to start on the corresponding node.

  3. kubelet installation fails on the corresponding node.

  4. The DNS resolution service on the corresponding node fails, causing image pull failures.

When encountering the above scenarios, users can manually fix the issue and then run the following command to add the retry annotation, so that the failed node re-executes the subsequent phases.

bash
# Note: When the value of the retry annotation is empty, all nodes will be retried.
kubectl annotate bc -n <cluster-namespace> <cluster-name>  bke.bocloud.com/retry="<failed-node-ip>"

Non-configurable Annotations ​

BKE Internal State, Process, and Operations Annotations (13) ​

Table 13 BKE Internal State, Process, and Operations Annotations Table

keySemantics and ValuesPriority and Lifecycle
bke.bocloud.com/collectdComma-separated base, agent, indicating that base information and agent information have been collected.The controller retains existing tokens and only appends missing tokens.
bke.bocloud.com/last-update-configurationSerialized object JSON, used as the last configuration snapshot.Internal three-way merge baseline, not part of the normal user override chain.
bke.bocloud.com/status-recordRequests StatusManager to record the current state once, usually an empty value.Triggered when the key exists; deleted after recording.
bke.bocloud.com/cluster-tracker-healthy-check-failedMarks ClusterTracker health check failure and triggers re-reconciliation.Takes effect when the key exists; deleted after recovering to Ready.
bke.bocloud.com/addon-boot-wait-timeoutDesigned to indicate the addon boot wait timeout.No production read or write points yet; current settings do not take effect.
bke.bocloud.com/eventMarks this as a regular BKE event.An empty value is written each time AnnotatedEventf creates an Event.
bke.bocloud.com/completeTogether with event, marks a process completion event.An empty value is written when a completion event is created.
bke.bocloud.com/bkeagent-listenercurrent means the agent listens to the current cluster; bkecluster means it is to be switched to BKECluster.Defaults to current when missing; bkecluster is written during the addon phase, and the process reverts to current after the switch is complete.
bke.bocloud.com/cluster-frombke, bocloud, other indicate the cluster source.Defaults to bke when missing or empty; different sources affect the configuration validation, full management, and certificate distribution branches.
bke.bocloud.com/cluster-api-manager-appliedtrue means 004-manage.yaml has been applied.Only executed when the target version exists, postprocess is complete, and the value is not true; writes true upon success.
etcd-cert-dirTemporarily stores the collected etcd certificate directory.Takes precedence over Kubernetes certificatesDir; deleted after agent information collection is complete.
deployActionFixed value k8s_upgrade, used for BOC compatibility process identification.Overridden to k8s_upgrade when missing or the value is not k8s_upgrade; no automatic cleanup seen in the code.
bke.openfuyao.cn/restartedAtRFC3339 timestamp, used to change the PodTemplate and trigger a Deployment rolling restart.Updated to the current time on each PatchDeploymentImage.

ClusterVersion, Upgrade Path, and ReleaseImage Annotations (6) ​

These keys are protocols between upgrade controllers. For parameter descriptions and collaboration relationships, see Backend Declarative Upgrade Guide#controller-parameters-and-upgrade-annotations.

Table 14 ClusterVersion, Upgrade Path, and ReleaseImage Annotations Table

keySemantics and ValuesPriority and Lifecycle
cvo.openfuyao.cn/upgrade-readyThe target version of the current upgrade hop, and also the execution gate for the declarative upgrade DAG.After trimming, a non-empty value allows DAG execution; its value is the current hop, not necessarily the final desiredVersion.
cvo.openfuyao.cn/cluster-versionThe name of the associated ClusterVersion object.Written and cleaned up together with upgrade-ready, not used as a gate on its own.
cvo.openfuyao.cn/upgrade-pathThe selected upgrade path, e.g. v1->v2,v2->v3.Written and cleaned up together with upgrade-ready.
cvo.openfuyao.cn/helm-componentWhen trimmed and case-insensitively equal to true, enables the yaml/helm component executor for this cluster.When the annotation exists, the annotation value takes precedence; when missing, falls back to the --helm-component-support global flag.
config.openfuyao.com/oci-digestSaves the UpgradePath OCI image digest and syncs it to status.lastDigest.Overwritten with the latest digest each time the path is refreshed from OCI.
cvo.openfuyao.cn/bkecluster-nameAssociates the ReleaseImage with the target BKECluster name.Read by the ReleaseImage controller, used to resolve and sync target cluster version information.

When the upgrade is completed, cancelled, or cleaned up, the controller removes upgrade-ready, cluster-version, and upgrade-path together.

Cluster API Standard Annotations (8) ​

The semantics of these keys are mainly defined by upstream Cluster API. This repository is responsible for setting, deleting, or consuming them, so they are also part of the actual annotation surface.

Table 15 Cluster API Standard Annotations Table

keySemantics and ValuesPriority and Lifecycle
cluster.x-k8s.io/cluster-nameIndicates the name of the Cluster to which the node belongs.Only maps to the corresponding BKECluster when present together with cluster-namespace.
cluster.x-k8s.io/cluster-namespaceIndicates the namespace of the Cluster to which the node belongs.No object mapping is performed when missing.
cluster.x-k8s.io/pausedThe presence of the key indicates pausing Cluster API object reconciliation.Either Cluster.spec.paused=true or the presence of this key on the object can pause; the value does not participate in the judgment.
cluster.x-k8s.io/delete-machineSets the annotated machine as a priority deletion candidate.Takes effect when the key exists, usually written as an empty value.
cluster.x-k8s.io/managed-byIndicates that the infrastructure object is managed by an external system, and this controller skips mapping.When the key exists, it is treated as externally managed.
machine.cluster.x-k8s.io/certificates-expiryRFC3339 certificate expiration time; currently written as the current time plus 100 years.Generated by the controller, used to avoid unnecessary behavior triggered by upstream due to short certificate periods.
controlplane.cluster.x-k8s.io/skip-kube-proxyRequires KCP to not be responsible for upgrading kube-proxy.Upstream judges based on whether the key exists; BKE manages the related components itself.
controlplane.cluster.x-k8s.io/skip-corednsRequires KCP to not be responsible for upgrading CoreDNS.Upstream judges based on whether the key exists; BKE manages the related components itself.

kubeadm, Kubernetes, and Static Pod Annotations (7) ​

Table 16 kubeadm, Kubernetes, and Static Pod Annotations Table

keySemantics and ValuesPriority and Lifecycle
kubeadm.kubernetes.io/etcd.advertise-client-urlsUsually node IP:2379, describes the etcd client advertise URL.During the onboarding phase, if the key already exists it is not overwritten; during the master upgrade phase, it is filled in when missing or empty.
bkeagent.bocloud.com/etcd.advertise-client-urlsDesigned to also be the etcd advertise client URL.The current production code actually uses the kubeadm key above.
kubeadm.alpha.kubernetes.io/cri-socketSaves the CRI socket used during init/join.This repository only has a constant definition, with no production read or write points.
kubeadm.kubernetes.io/kube-apiserver.advertise-address.endpointDescribes the API Server advertise address and port.This repository only has a constant definition, with no production read or write points.
kubeadm.kubernetes.io/component-config.hashSaves the component configuration SHA256, used to detect user modifications.This repository only has a constant definition, with no production read or write points.
kubernetes.io/service-account.nameIndicates which ServiceAccount this Secret belongs to, for the Kubernetes token controller to fill in the token.Fixed to the target ServiceAccount name when creating the Secret.
kubernetes.io/config.hashStatic Pod manifest content hash, used to determine whether the component Pod has been updated.BKE only reads and waits for the hash to change, and does not write.

Deployment Manifest and Generation Tool Annotations (5) ​

Table 17 Deployment Manifest and Generation Tool Annotations Table

keyPurposeConfiguration and Validation
controller-gen.kubebuilder.io/versionRecords the controller-gen version used to generate the CRD.Generated by controller-gen, used only for traceability, and does not control runtime business logic.
cert-manager.io/inject-ca-fromTells cert-manager to inject the caBundle from the Certificate/Secret source specified by namespace/name.The config contains Kustomize variables, which become the actual namespace/name after build; does not take effect when cert-manager is not deployed or the injector is not running.
kubectl.kubernetes.io/default-containerWhen kubectl logs/exec does not specify a container, manager is selected by default.Fixed string manager; only affects the kubectl usage experience.
prometheus.io/portTells the collector based on Prometheus annotation discovery to use port 8080.The value is the string 8080; does not take effect when the collection system does not enable annotation discovery.
prometheus.io/scrapetrue means scraping metrics by Prometheus based on annotation discovery is allowed.Interpreted by the collection system; Kubernetes itself does not validate it.