Configure ACS computing power with the eci-profile ConfigMap

Updated at:

Define cluster-level defaults such as vSwitches, security groups, and DNS resolution in the eci-profile ConfigMap to minimize per-pod YAML changes.

Overview

The eci-profile ConfigMap automatically injects pod configurations such as vSwitches, security groups, and DNS resolution modes. You can also update these configurations as needed.

  • You do not need to restart the acs-virtual-node component to update the configurations.

  • The updated configurations are immediately applied to newly created ACS pods, but are applied to existing ACS pods only after rolling releases are performed on the pods.

Usage notes

During pod creation, the system reads the eci-profile ConfigMap in the kube-system namespace and applies its configurations. View the eci-profile YAML:

kubectl get cm -n kube-system eci-profile -o yaml

Example eci-profile YAML:

apiVersion: v1
kind: ConfigMap
metadata:
  name: eci-profile
  namespace: kube-system
data:
  enablePrivateZone: "false"
  securityGroupId: sg-2zeeyaaxlkq9sppl****
  vSwitchIds: vsw-2ze23nqzig8inprou****,vsw-2ze94pjtfuj9vaymf****
  vpcId: vpc-2zeghwzptn5zii0w7****
  selectors: ""

To modify the eci-profile, use one of the following methods:

  • Run the kubectl edit command:

    kubectl edit configmap eci-profile -n kube-system
  • Use the ACS console:

    1. Log on to the ACK console. In the left navigation pane, click Clusters.

    2. On the Clusters page, click the name of your cluster. In the left navigation pane, click Configurations > ConfigMaps.

    3. On the ConfigMap page, select the kube-system from the Namespace drop-down list. Find the eci-profile ConfigMap and click Edit YAML in the Actions column.

      Note

      If the modified eci-profile contains a formatting error, the configuration does not take effect. View the error by running the following command:

      kubectl -n kube-system get event --field-selector involvedObject.namespace=kube-system,involvedObject.name=eci-profile

Update cluster parameters

The eci-profile ConfigMap contains cluster parameters such as vpcId (VPC) and vSwitchIds (vSwitches). You can update these parameters as needed, and changes take effect immediately. The following table lists the configurable parameters.

Parameter

Example

Description

securityGroupId

sg-2ze0b9o8pjjzts4h****

The security group that ACS pods belong to. Controls inbound and outbound traffic rules for all pods using this profile.

vSwitchIds

vsw-2zeet2ksvw7f14ryz****

The vSwitch IDs to associate with ACS pods. Separate multiple IDs with commas. Determines which subnets pods are launched into.

vpcId

vpc-2zeghwzptn5zii0w7****

The virtual private cloud (VPC) where ACS pods are deployed. Must match the VPC of the specified vSwitches.

enablePrivateZone

"false"

Whether to use PrivateZone for domain name resolution. Set to "true" if your pods need to resolve private DNS records.

Note

These parameters are cluster-level defaults. If you do not override them when creating a pod, the system applies the eci-profile defaults.

Configure selectors

Selectors let you inject additional annotations and labels into specific pods based on their namespace or pod labels, without modifying those pods' YAML files.

When ACS creates a pod, it evaluates each selector in order. For each selector whose criteria match the pod, ACS merges the effect settings (annotations and labels) into the pod. Annotations and labels already present on the pod are never overwritten.

Parameter

Required

Description

name

Yes

A unique name for the selector.

namespaceSelector

No

Filters pods by the labels on their namespace.

namespaceSelector.matchLabels

No

Match rule in {key: value} format.

namespaceSelector.matchExpressions

No

List of selector requirements. Valid operators: In, NotIn, Exists, DoesNotExist. For In and NotIn, values must be non-empty.

objectSelector

No

Filters pods by the labels on the pod itself.

objectSelector.matchLabels

No

Match rule in {key: value} format.

objectSelector.matchExpressions

No

List of selector requirements. Same operators as namespaceSelector.matchExpressions.

effect

No

The annotations and labels to inject into matching pods.

Example selector configuration:

apiVersion: v1
kind: ConfigMap
metadata:
  name: eci-profile
  namespace: kube-system
data:
  selectors: |
    [
      {
        "name": "selector-demo1",
        "namespaceSelector": {
          "matchLabels": {
            "kubernetes.io/metadata.name": "dev-ns"
          }
        },
        "objectSelector": {
          "matchLabels": {
            "acs": "true"
          },
          "matchExpressions": [
            {
              "key": "usage",
              "operator": "In",
              "values": ["testing"]
            }
          ]
        },
        "effect": {
          "annotations": {
            "network.alibabacloud.com/custom-dnsconfig": "{\"servers\":[\"114.114.114.114\",\"8.8.8.8\"],\"searches\":[\"xx.com\",\"yy.com\"],\"options\":[\"ndots:2\",\"edns0\"]}"
          },
          "labels": {
            "created-by-acs": "true"
          }
        }
      }
    ]

The selector-demo1 selector provides these capabilities:

What this selector does: Any pod in the dev-ns namespace that has both the acs=true label and usage=testing label receives:

  • Annotation: network.alibabacloud.com/custom-dnsconfig with DNS servers 114.114.114.114 and 8.8.8.8, search domains xx.com and yy.com, and options ndots:2 and edns0

  • Label: created-by-acs=true

Important

namespaceSelector and objectSelector use AND logic — when both are configured, a pod must satisfy both conditions to match. Configure at least one of them for each selector. If neither is configured but effect is set, the effect applies to all ACS pods in the cluster.

If multiple selectors match the same pod, ACS applies them in the order they appear in the selectors array. The injected annotations and labels follow this priority:

  1. Existing annotations and labels on the pod (highest priority — never overwritten)

  2. The effect settings of the first-matched selector

  3. The effect settings of subsequent matched selectors

Examples

  1. Create a Deployment that matches the selector-demo1 conditions:

    apiVersion: v1
    kind: Pod
    metadata:
      name: nginx
      namespace: dev-ns
      labels:
        alibabacloud.com/acs: 'true'
        alibabacloud.com/compute-class: general-purpose
        alibabacloud.com/compute-qos: default  
        acs: "true"
        usage: "testing"
    spec:
      containers:
      - name: nginx
        image: anolis-registry.cn-zhangjiakou.cr.aliyuncs.com/openanolis/nginx:1.14.1-8.6
        command: ["sleep", "infinity"]
        ports:
        - containerPort: 80
  2. After creating the Deployment, view the pod information in the ACS console.

    The Pod details page shows the basic information of the Pod: the name is nginx, the namespace is dev-ns, the status is Running, the node is virtual-kubelet-cn-hangzhou-h, and the Pod IP is 192.168.8.30. The labels include created-by-acs: true, which indicates that the Pod is created by ACS. The value of the network.alibabacloud.com/custom-dnsconfig Annotation contains the custom DNS configuration, where servers is ["114.114.114.114", "8.8.8.8"].