upgrade
기존 Linkerd 컨트롤 플레인을 업그레이드하기 위한 Kubernetes 구성을 출력해요.
이 명령의 기본 플래그 값은 Linkerd 컨트롤 플레인에서 가져온다는 점에 유의하세요. 아래 Flags 섹션에 표시된 기본값은 install 명령에만 적용돼요.
업그레이드는 –set, –values, –set-string, –set-file 플래그로 구성할 수 있어요. 구성 가능한 값의 전체 목록은 https://www.github.com/linkerd/linkerd2/tree/main/charts/linkerd-control-plane/values.yaml 에서 찾을 수 있어요.
예시 (Examples)
`# Upgrade CRDs first
linkerd upgrade --crds | kubectl apply -f -
# Then upgrade the control plane
linkerd upgrade | kubectl apply -f -
# And lastly, remove linkerd resources that no longer exist in the current version
linkerd prune | kubectl delete -f -`
플래그 (Flags)
| Flag | Usage |
|---|---|
| Flag | Usage |
| --admin-port | Proxy port to serve metrics on |
| --control-port | Proxy port to use for control |
| --controller-gid | Run the control plane components under this group ID |
| --controller-log-level | Log level for the controller and web components |
| --controller-replicas | Replicas of the controller to deploy |
| --controller-uid | Run the control plane components under this user ID |
| --crds | Upgrade Linkerd CRDs |
| --default-inbound-policy | Inbound policy to use to control inbound access to the proxy |
| --disable-h2-upgrade | Prevents the controller from instructing proxies to perform transparent HTTP/2 upgrading (default false) |
| --disable-heartbeat | Disables the heartbeat cronjob (default false) |
| --enable-endpoint-slices | Enables the usage of EndpointSlice informers and resources for destination service |
| --enable-external-profiles | Enable service profiles for non-Kubernetes services |
| --force | Force upgrade operation even when issuer certificate does not work with the trust anchors of all proxies |
| --from-manifests | Read config from a Linkerd install YAML rather than from Kubernetes |
| --ha | Enable HA deployment config for the control plane (default false) |
| --identity-clock-skew-allowance | The amount of time to allow for clock skew within a Linkerd cluster |
| --identity-issuance-lifetime | The amount of time for which the Identity issuer should certify identity |
| --identity-issuer-certificate-file | A path to a PEM-encoded file containing the Linkerd Identity issuer certificate (generated by default) |
| --identity-issuer-key-file | A path to a PEM-encoded file containing the Linkerd Identity issuer private key (generated by default) |
| --identity-trust-anchors-file | A path to a PEM-encoded file containing Linkerd Identity trust anchors (generated by default) |
| --image-pull-policy | Docker image pull policy |
| --inbound-port | Proxy port to use for inbound traffic |
| --linkerd-cni-enabled | Omit the NET_ADMIN capability in the PSP and the proxy-init container when injecting the proxy; requires the linkerd-cni plugin to already be installed |
| --outbound-port | Proxy port to use for outbound traffic |
| --output-o | Output format. One of: json|yaml |
| --proxy-cpu | Amount of CPU units that the proxy sidecar requests |
| --proxy-cpu-limit | Maximum amount of CPU units that the proxy sidecar can use |
| --proxy-cpu-request | Amount of CPU units that the proxy sidecar requests |
| --proxy-gid | Run the proxy under this group ID |
| --proxy-image | Linkerd proxy container image name |
| --proxy-log-level | Log level for the proxy |
| --proxy-memory | Amount of Memory that the proxy sidecar requests |
| --proxy-memory-limit | Maximum amount of Memory that the proxy sidecar can use |
| --proxy-memory-request | Amount of Memory that the proxy sidecar requests |
| --proxy-uid | Run the proxy under this user ID |
| --proxy-version-v | Tag to be used for the Linkerd proxy images |
| --registry | Docker registry to pull images from ($LINKERD_DOCKER_REGISTRY) |
| --set | set values on the command line (can specify multiple or separate values with commas: key1=val1,key2=val2) |
| --set-file | set values from respective files specified via the command line (can specify multiple or separate values with commas: key1=path1,key2=path2) |
| --set-string | set STRING values on the command line (can specify multiple or separate values with commas: key1=val1,key2=val2) |
| --skip-inbound-ports | Ports and/or port ranges (inclusive) that should skip the proxy and send directly to the application |
| --skip-outbound-ports | Outbound ports and/or port ranges (inclusive) that should skip the proxy |
| --values-f | specify values in a YAML file or a URL (can specify multiple) |
출처: Linkerd upgrade
본문
linkerd upgrade 명령은 기존 Linkerd 컨트롤 플레인을 업그레이드하기 위한 Kubernetes 구성을 생성해요. 이 명령의 기본 플래그 값은 Linkerd 컨트롤 플레인에서 가져오며, 위 Flags 섹션의 기본값은 install 명령에만 적용돼요.
업그레이드는 --set, --values, --set-string, --set-file 플래그로 구성할 수 있으며, 구성 가능한 값의 전체 목록은 charts/linkerd-control-plane/values.yaml 에서 확인할 수 있어요.
일반적인 업그레이드 흐름은: 먼저 linkerd upgrade --crds로 CRD를 업그레이드하고, 그다음 linkerd upgrade로 컨트롤 플레인을 업그레이드한 후, 마지막으로 linkerd prune으로 현재 버전에서 더 이상 존재하지 않는 리소스를 제거해요.