Configure ACS computing power with the eci-profile ConfigMap
Define cluster-level defaults such as vSwitches, security groups, and DNS resolution in the eci-profile ConfigMap to minimize per-pod YAML changes.
Overview
The eci-profile ConfigMap automatically injects pod configurations such as vSwitches, security groups, and DNS resolution modes. You can also update these configurations as needed.
You do not need to restart the acs-virtual-node component to update the configurations.
The updated configurations are immediately applied to newly created ACS pods, but are applied to existing ACS pods only after rolling releases are performed on the pods.
Usage notes
During pod creation, the system reads the eci-profile ConfigMap in the kube-system namespace and applies its configurations. View the eci-profile YAML:
kubectl get cm -n kube-system eci-profile -o yamlExample eci-profile YAML:
apiVersion: v1
kind: ConfigMap
metadata:
name: eci-profile
namespace: kube-system
data:
enablePrivateZone: "false"
securityGroupId: sg-2zeeyaaxlkq9sppl****
vSwitchIds: vsw-2ze23nqzig8inprou****,vsw-2ze94pjtfuj9vaymf****
vpcId: vpc-2zeghwzptn5zii0w7****
selectors: ""To modify the eci-profile, use one of the following methods:
Run the kubectl edit command:
kubectl edit configmap eci-profile -n kube-systemUse the ACS console:
-
Log on to the ACK console. In the left navigation pane, click Clusters.
-
On the Clusters page, click the name of your cluster. In the left navigation pane, click .
On the ConfigMap page, select the kube-system from the Namespace drop-down list. Find the eci-profile ConfigMap and click Edit YAML in the Actions column.
NoteIf the modified eci-profile contains a formatting error, the configuration does not take effect. View the error by running the following command:
kubectl -n kube-system get event --field-selector involvedObject.namespace=kube-system,involvedObject.name=eci-profile
-
Update cluster parameters
The eci-profile ConfigMap contains cluster parameters such as vpcId (VPC) and vSwitchIds (vSwitches). You can update these parameters as needed, and changes take effect immediately. The following table lists the configurable parameters.
Parameter | Example | Description |
|
| The security group that ACS pods belong to. Controls inbound and outbound traffic rules for all pods using this profile. |
|
| The vSwitch IDs to associate with ACS pods. Separate multiple IDs with commas. Determines which subnets pods are launched into. |
|
| The virtual private cloud (VPC) where ACS pods are deployed. Must match the VPC of the specified vSwitches. |
|
| Whether to use PrivateZone for domain name resolution. Set to |
These parameters are cluster-level defaults. If you do not override them when creating a pod, the system applies the eci-profile defaults.
Configure selectors
Selectors let you inject additional annotations and labels into specific pods based on their namespace or pod labels, without modifying those pods' YAML files.
When ACS creates a pod, it evaluates each selector in order. For each selector whose criteria match the pod, ACS merges the effect settings (annotations and labels) into the pod. Annotations and labels already present on the pod are never overwritten.
Parameter | Required | Description |
| Yes | A unique name for the selector. |
| No | Filters pods by the labels on their namespace. |
| No | Match rule in |
| No | List of selector requirements. Valid operators: |
| No | Filters pods by the labels on the pod itself. |
| No | Match rule in |
| No | List of selector requirements. Same operators as |
| No | The annotations and labels to inject into matching pods. |
Example selector configuration:
apiVersion: v1
kind: ConfigMap
metadata:
name: eci-profile
namespace: kube-system
data:
selectors: |
[
{
"name": "selector-demo1",
"namespaceSelector": {
"matchLabels": {
"kubernetes.io/metadata.name": "dev-ns"
}
},
"objectSelector": {
"matchLabels": {
"acs": "true"
},
"matchExpressions": [
{
"key": "usage",
"operator": "In",
"values": ["testing"]
}
]
},
"effect": {
"annotations": {
"network.alibabacloud.com/custom-dnsconfig": "{\"servers\":[\"114.114.114.114\",\"8.8.8.8\"],\"searches\":[\"xx.com\",\"yy.com\"],\"options\":[\"ndots:2\",\"edns0\"]}"
},
"labels": {
"created-by-acs": "true"
}
}
}
]The selector-demo1 selector provides these capabilities:
What this selector does: Any pod in the dev-ns namespace that has both the acs=true label and usage=testing label receives:
Annotation:
network.alibabacloud.com/custom-dnsconfigwith DNS servers114.114.114.114and8.8.8.8, search domainsxx.comandyy.com, and optionsndots:2andedns0Label:
created-by-acs=true
namespaceSelector and objectSelector use AND logic — when both are configured, a pod must satisfy both conditions to match. Configure at least one of them for each selector. If neither is configured but effect is set, the effect applies to all ACS pods in the cluster.
If multiple selectors match the same pod, ACS applies them in the order they appear in the selectors array. The injected annotations and labels follow this priority:
Existing annotations and labels on the pod (highest priority — never overwritten)
The
effectsettings of the first-matched selectorThe
effectsettings of subsequent matched selectors
Examples
Create a Deployment that matches the selector-demo1 conditions:
apiVersion: v1 kind: Pod metadata: name: nginx namespace: dev-ns labels: alibabacloud.com/acs: 'true' alibabacloud.com/compute-class: general-purpose alibabacloud.com/compute-qos: default acs: "true" usage: "testing" spec: containers: - name: nginx image: anolis-registry.cn-zhangjiakou.cr.aliyuncs.com/openanolis/nginx:1.14.1-8.6 command: ["sleep", "infinity"] ports: - containerPort: 80After creating the Deployment, view the pod information in the ACS console.
The Pod details page shows the basic information of the Pod: the name is nginx, the namespace is dev-ns, the status is Running, the node is virtual-kubelet-cn-hangzhou-h, and the Pod IP is
192.168.8.30. The labels includecreated-by-acs: true, which indicates that the Pod is created by ACS. The value of thenetwork.alibabacloud.com/custom-dnsconfigAnnotation contains the custom DNS configuration, where servers is["114.114.114.114", "8.8.8.8"].