{"id":39187,"date":"2019-10-31T22:28:20","date_gmt":"2019-10-31T19:28:20","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kak-rabotaet-kubectl-exec\/"},"modified":"2019-10-31T22:28:20","modified_gmt":"2019-10-31T19:28:20","slug":"kak-rabotaet-kubectl-exec","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-rabotaet-kubectl-exec","title":{"rendered":"Si funksionon kubectl exec?","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><i><b>\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.<\/b>: \u0430\u0432\u0442\u043e\u0440 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Erkan Erol, \u0438\u043d\u0436\u0435\u043d\u0435\u0440 \u0438\u0437 SAP \u2014 \u0434\u0435\u043b\u0438\u0442\u0441\u044f \u0441\u0432\u043e\u0438\u043c \u0438\u0437\u0443\u0447\u0435\u043d\u0438\u0435\u043c \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434\u044b <code>kubectl exec<\/code>, \u0441\u0442\u043e\u043b\u044c \u043f\u0440\u0438\u0432\u044b\u0447\u043d\u043e\u0439 \u0434\u043b\u044f \u0432\u0441\u0435\u0445, \u043a\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 Kubernetes. \u0412\u0435\u0441\u044c \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u043e\u043d \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u0435\u0442 \u043b\u0438\u0441\u0442\u0438\u043d\u0433\u0430\u043c\u0438 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 Kubernetes (\u0438 \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0440\u0430\u0437\u043e\u0431\u0440\u0430\u0442\u044c\u0441\u044f \u0432 \u0442\u0435\u043c\u0435 \u043d\u0430\u0441\u0442\u043e\u043b\u044c\u043a\u043e \u0433\u043b\u0443\u0431\u043e\u043a\u043e, \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u044d\u0442\u043e \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f.<\/i><\/p>\n<p><img decoding=\"async\" alt=\"\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec?\" src=\"\/wp-content\/uploads\/2019\/10\/97b11a479f38ddacedd1641dcea814bc.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u0412 \u043e\u0434\u043d\u0443 \u0438\u0437 \u043f\u044f\u0442\u043d\u0438\u0446 \u043a\u043e \u043c\u043d\u0435 \u043f\u043e\u0434\u043e\u0448\u0435\u043b \u043a\u043e\u043b\u043b\u0435\u0433\u0430 \u0438 \u043f\u043e\u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043e\u0432\u0430\u043b\u0441\u044f, \u043a\u0430\u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u043c\u0430\u043d\u0434\u0443 \u0432 pod&#8217;\u0435 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/client-go\">client-go<\/a><\/noindex>. \u042f \u043d\u0435 \u0441\u043c\u043e\u0433 \u0435\u043c\u0443 \u043e\u0442\u0432\u0435\u0442\u0438\u0442\u044c \u0438 \u0432\u043d\u0435\u0437\u0430\u043f\u043d\u043e \u043e\u0441\u043e\u0437\u043d\u0430\u043b, \u0447\u0442\u043e \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u0437\u043d\u0430\u044e \u043e \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0440\u0430\u0431\u043e\u0442\u044b <code>kubectl exec<\/code>. \u0414\u0430, \u0443 \u043c\u0435\u043d\u044f \u0431\u044b\u043b\u0438 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0435 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043e \u0435\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0435, \u043e\u0434\u043d\u0430\u043a\u043e \u044f \u043d\u0435 \u0431\u044b\u043b \u0443\u0432\u0435\u0440\u0435\u043d \u043d\u0430 100% \u0432 \u0438\u0445 \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0438 \u043f\u043e\u0442\u043e\u043c\u0443 \u0440\u0435\u0448\u0438\u043b \u0437\u0430\u043d\u044f\u0442\u044c\u0441\u044f \u044d\u0442\u0438\u043c \u0432\u043e\u043f\u0440\u043e\u0441\u043e\u043c. \u041f\u0440\u043e\u0448\u0442\u0443\u0434\u0438\u0440\u043e\u0432\u0430\u0432 \u0431\u043b\u043e\u0433\u0438, \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u044e \u0438 \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u0439 \u043a\u043e\u0434, \u0443\u0437\u043d\u0430\u043b \u043c\u043d\u043e\u0433\u043e \u043d\u043e\u0432\u043e\u0433\u043e, \u0438 \u0432 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u0445\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441\u0432\u043e\u0438\u043c\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u044f\u043c\u0438 \u0438 \u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u0435\u043c. \u0415\u0441\u043b\u0438 \u0447\u0442\u043e-\u0442\u043e \u043d\u0435 \u0442\u0430\u043a, \u043f\u043e\u0436\u0430\u043b\u0443\u0439\u0441\u0442\u0430, \u0441\u0432\u044f\u0436\u0438\u0442\u0435\u0441\u044c \u0441\u043e \u043c\u043d\u043e\u0439 \u0432 <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/erkan_erol_\">Twitter<\/a><\/noindex>.<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>\u041f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043a\u0430<\/h2>\n<p>\n\u0427\u0442\u043e\u0431\u044b \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043a\u043b\u0430\u0441\u0442\u0435\u0440 \u043d\u0430 MacBook&#8217;\u0435, \u044f \u0441\u043a\u043b\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043b <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ecomm-integration-ballerina\/kubernetes-cluster\">ecomm-integration-ballerina\/kubernetes-cluster<\/a><\/noindex>. \u0417\u0430\u0442\u0435\u043c \u043f\u043e\u043f\u0440\u0430\u0432\u0438\u043b IP-\u0430\u0434\u0440\u0435\u0441\u0430 \u0443\u0437\u043b\u043e\u0432 \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0435 kubelet\u2019\u0430, \u043f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043d\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0442\u044c <code>kubectl exec<\/code>. \u041f\u043e\u0434\u0440\u043e\u0431\u043d\u0435\u0435 \u043e\u0431 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u043f\u0440\u0438\u0447\u0438\u043d\u0435 \u0442\u043e\u043c\u0443 \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@joatmon08\/playing-with-kubeadm-in-vagrant-machines-part-2-bac431095706\">\u0437\u0434\u0435\u0441\u044c<\/a><\/noindex>.<\/p>\n<ul>\n<li> \u041b\u044e\u0431\u0430\u044f \u043c\u0430\u0448\u0438\u043d\u0430 = \u043c\u043e\u0439 MacBook<\/li>\n<li> IP master-\u0443\u0437\u043b\u0430 = 192.168.205.10<\/li>\n<li> IP worker-\u0443\u0437\u043b\u0430 = 192.168.205.11<\/li>\n<li> \u043f\u043e\u0440\u0442 API-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 = 6443<\/li>\n<\/ul>\n<p><\/p>\n<h2>\u041a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b<\/h2>\n<p>\n<img decoding=\"async\" alt=\"\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec?\" src=\"\/wp-content\/uploads\/2019\/10\/b5f867893c9aac6e1d974bbaf08a9cce.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<ul>\n<li> <b>kubectl exec process<\/b>: \u043a\u043e\u0433\u0434\u0430 \u043c\u044b \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c \u00abkubectl exec \u2026\u00bb, \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441. \u0414\u0435\u043b\u0430\u0442\u044c \u044d\u0442\u043e \u043c\u043e\u0436\u043d\u043e \u043d\u0430 \u043b\u044e\u0431\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 \u0434\u043e\u0441\u0442\u0443\u043f\u043e\u043c \u043a API-\u0441\u0435\u0440\u0432\u0435\u0440\u0443 K8s. <i>\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0414\u0430\u043b\u0435\u0435 \u0432 \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u044b\u0445 \u043b\u0438\u0441\u0442\u0438\u043d\u0433\u0430\u0445 \u0430\u0432\u0442\u043e\u0440 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0439 \u00abany machine\u00bb, \u043f\u043e\u0434\u0440\u0430\u0437\u0443\u043c\u0435\u0432\u0430\u044f, \u0447\u0442\u043e \u043f\u043e\u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b \u043c\u043e\u0436\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0442\u044c \u043d\u0430 \u043b\u044e\u0431\u044b\u0445 \u0442\u0430\u043a\u0438\u0445 \u043c\u0430\u0448\u0438\u043d\u0430\u0445 \u0441 \u0434\u043e\u0441\u0442\u0443\u043f\u043e\u043c \u043a Kubernetes.<\/i><\/li>\n<li> <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/overview\/components\/#kube-apiserver\"><b>api server<\/b><\/a><\/noindex>: \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442 \u043d\u0430 \u043c\u0430\u0441\u0442\u0435\u0440-\u0443\u0437\u043b\u0435, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a API Kubernetes. \u042d\u0442\u043e \u0444\u0440\u043e\u043d\u0442\u0435\u043d\u0434 \u0434\u043b\u044f control plane \u0432 Kubernetes.<\/li>\n<li> <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/overview\/components\/#kubelet\"><b>kubelet<\/b><\/a><\/noindex>: \u0430\u0433\u0435\u043d\u0442, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043d\u0430 \u043a\u0430\u0436\u0434\u043e\u043c \u0443\u0437\u043b\u0435 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435. \u041e\u043d \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u0440\u0430\u0431\u043e\u0442\u0443 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 \u0432 pod&#8217;\u0435.<\/li>\n<li> <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/overview\/components\/#container-runtime\"><b>container runtime<\/b><\/a><\/noindex> (\u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u0430\u044f \u0441\u0440\u0435\u0434\u0430 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430): \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0435 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u0435, \u043e\u0442\u0432\u0435\u0447\u0430\u044e\u0449\u0435\u0435 \u0437\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432. \u041f\u0440\u0438\u043c\u0435\u0440\u044b: Docker, CRI-O, containerd\u2026<\/li>\n<li> <b>kernel<\/b>: \u044f\u0434\u0440\u043e \u041e\u0421 \u043d\u0430 \u0440\u0430\u0431\u043e\u0447\u0435\u043c \u0443\u0437\u043b\u0435; \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0437\u0430 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438.<\/li>\n<li> <b>target<\/b> (\u0446\u0435\u043b\u0435\u0432\u043e\u0439) <b>container<\/b>: \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440, \u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u0447\u0430\u0441\u0442\u044c\u044e pod&#8217;\u0430 \u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u043d\u0430 \u043e\u0434\u043d\u043e\u043c \u0438\u0437 \u0440\u0430\u0431\u043e\u0447\u0438\u0445 \u0443\u0437\u043b\u043e\u0432.<\/li>\n<\/ul>\n<p><\/p>\n<h2>\u0427\u0442\u043e \u044f \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b<\/h2>\n<p><\/p>\n<h3>1. \u0410\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u043d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u043a\u043b\u0438\u0435\u043d\u0442\u0430<\/h3>\n<p>\n\u0421\u043e\u0437\u0434\u0430\u0435\u043c pod \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u0438\u043c\u0435\u043d <code>default<\/code>:<\/p>\n<pre><code class=\"bash\">\/\/ any machine\n$ kubectl run exec-test-nginx --image=nginx<\/code><\/pre>\n<p>\n\u0417\u0430\u0442\u0435\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c \u043a\u043e\u043c\u0430\u043d\u0434\u0443 exec \u0438 \u0436\u0434\u0435\u043c 5000 \u0441\u0435\u043a\u0443\u043d\u0434 \u0434\u043b\u044f \u0434\u0430\u043b\u044c\u043d\u0435\u0439\u0448\u0438\u0445 \u043d\u0430\u0431\u043b\u044e\u0434\u0435\u043d\u0438\u0439:<\/p>\n<pre><code class=\"bash\">\/\/ any machine\n$ kubectl exec -it exec-test-nginx-6558988d5-fgxgg -- sh\n# sleep 5000<\/code><\/pre>\n<p>\n\u041f\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441 kubectl (\u0441 pid=8507 \u0432 \u043d\u0430\u0448\u0435\u043c \u0441\u043b\u0443\u0447\u0430\u0435):<\/p>\n<pre><code class=\"bash\">\/\/ any machine\n$ ps -ef |grep kubectl\n501  8507  8409   0  7:19PM ttys000    0:00.13 kubectl exec -it exec-test-nginx-6558988d5-fgxgg -- sh<\/code><\/pre>\n<p>\n\u0415\u0441\u043b\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430, \u043c\u044b \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043c, \u0447\u0442\u043e \u0443 \u043d\u0435\u0433\u043e \u0435\u0441\u0442\u044c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a api-server&#8217;\u0443 (192.168.205.10.6443):<\/p>\n<pre><code class=\"bash\">\/\/ any machine\n$ netstat -atnv |grep 8507\ntcp4       0      0  192.168.205.1.51673    192.168.205.10.6443    ESTABLISHED 131072 131768   8507      0 0x0102 0x00000020\ntcp4       0      0  192.168.205.1.51672    192.168.205.10.6443    ESTABLISHED 131072 131768   8507      0 0x0102 0x00000028<\/code><\/pre>\n<p>\n\u0414\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u043d\u0430 \u043a\u043e\u0434. Kubectl \u0441\u043e\u0437\u0434\u0430\u0435\u0442 POST-\u0437\u0430\u043f\u0440\u043e\u0441 \u0441 \u0441\u0443\u0431\u0440\u0435\u0441\u0443\u0440\u0441\u043e\u043c exec \u0438 \u043f\u043e\u0441\u044b\u043b\u0430\u0435\u0442 REST-\u0437\u0430\u043f\u0440\u043e\u0441:<\/p>\n<pre><code class=\"go\">              req := restClient.Post().\n                        Resource(\"pods\").\n                        Name(pod.Name).\n                        Namespace(pod.Namespace).\n                        SubResource(\"exec\")\n                req.VersionedParams(&amp;corev1.PodExecOptions{\n                        Container: containerName,\n                        Command:   p.Command,\n                        Stdin:     p.Stdin,\n                        Stdout:    p.Out != nil,\n                        Stderr:    p.ErrOut != nil,\n                        TTY:       t.Raw,\n                }, scheme.ParameterCodec)\n\n                return p.Executor.Execute(\"POST\", req.URL(), p.Config, p.In, p.Out, p.ErrOut, t.Raw, sizeQueue)<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/a1f1f0b599e961a5c59b02c349c0ed818b1851a5\/staging\/src\/k8s.io\/kubectl\/pkg\/cmd\/exec\/exec.go#L345\">kubectl\/pkg\/cmd\/exec\/exec.go<\/a><\/noindex>)<\/i><\/p>\n<p><img decoding=\"async\" alt=\"\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec?\" src=\"\/wp-content\/uploads\/2019\/10\/694ae063992a5b81d28827b5647e7af1.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h3>2. \u0410\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u043d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u043c\u0430\u0441\u0442\u0435\u0440-\u0443\u0437\u043b\u0430<\/h3>\n<p>\n\u041c\u044b \u0442\u0430\u043a\u0436\u0435 \u043c\u043e\u0436\u0435\u043c \u043d\u0430\u0431\u043b\u044e\u0434\u0430\u0442\u044c \u0437\u0430\u043f\u0440\u043e\u0441 \u043d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 api-server&#8217;\u0430:<\/p>\n<pre><code class=\"bash\">handler.go:143] kube-apiserver: POST \"\/api\/v1\/namespaces\/default\/pods\/exec-test-nginx-6558988d5-fgxgg\/exec\" satisfied by gorestful with webservice \/api\/v1\nupgradeaware.go:261] Connecting to backend proxy (intercepting redirects) https:\/\/192.168.205.11:10250\/exec\/default\/exec-test-nginx-6558988d5-fgxgg\/exec-test-nginx?command=sh&amp;input=1&amp;output=1&amp;tty=1\nHeaders: map[Connection:[Upgrade] Content-Length:[0] Upgrade:[SPDY\/3.1] User-Agent:[kubectl\/v1.12.10 (darwin\/amd64) kubernetes\/e3c1340] X-Forwarded-For:[192.168.205.1] X-Stream-Protocol-Version:[v4.channel.k8s.io v3.channel.k8s.io v2.channel.k8s.io channel.k8s.io]]<\/code><\/pre>\n<p>\n<i>\u041e\u0431\u0440\u0430\u0442\u0438\u0442\u0435 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435, \u0447\u0442\u043e HTTP-\u0437\u0430\u043f\u0440\u043e\u0441 \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u0437\u0430\u043f\u0440\u043e\u0441 \u043d\u0430 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wikiwand.com\/en\/SPDY\">SPDY<\/a><\/noindex> \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043c\u0443\u043b\u044c\u0442\u0438\u043f\u043b\u0435\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0435 \u00ab\u043f\u043e\u0442\u043e\u043a\u0438\u00bb stdin\/stdout\/stderr\/spdy-error \u0447\u0435\u0440\u0435\u0437 \u0435\u0434\u0438\u043d\u043e\u0435 TCP-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435.<\/i><\/p>\n<p>API-\u0441\u0435\u0440\u0432\u0435\u0440 \u043f\u043e\u043b\u0443\u0447\u0430\u0435\u0442 \u0437\u0430\u043f\u0440\u043e\u0441 \u0438 \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u0443\u0435\u0442 \u0435\u0433\u043e \u0432 <code>PodExecOptions<\/code>:<\/p>\n<pre><code class=\"go\">\/\/ PodExecOptions is the query options to a Pod's remote exec call\ntype PodExecOptions struct {\n        metav1.TypeMeta\n\n        \/\/ Stdin if true indicates that stdin is to be redirected for the exec call\n        Stdin bool\n\n        \/\/ Stdout if true indicates that stdout is to be redirected for the exec call\n        Stdout bool\n\n        \/\/ Stderr if true indicates that stderr is to be redirected for the exec call\n        Stderr bool\n\n        \/\/ TTY if true indicates that a tty will be allocated for the exec call\n        TTY bool\n\n        \/\/ Container in which to execute the command.\n        Container string\n\n        \/\/ Command is the remote command to execute; argv array; not executed within a shell.\n        Command []string\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/a1f1f0b599e961a5c59b02c349c0ed818b1851a5\/pkg\/apis\/core\/types.go#L4127\">pkg\/apis\/core\/types.go<\/a><\/noindex>)<\/i><\/p>\n<p>\u0427\u0442\u043e\u0431\u044b \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0442\u0440\u0435\u0431\u0443\u0435\u043c\u044b\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f, api-server \u0434\u043e\u043b\u0436\u0435\u043d \u0437\u043d\u0430\u0442\u044c, \u0441 \u043a\u0430\u043a\u0438\u043c pod&#8217;\u043e\u043c \u0435\u043c\u0443 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0441\u0432\u044f\u0437\u0430\u0442\u044c\u0441\u044f:<\/p>\n<pre><code class=\"go\">\/\/ ExecLocation returns the exec URL for a pod container. If opts.Container is blank\n\/\/ and only one container is present in the pod, that container is used.\nfunc ExecLocation(\n        getter ResourceGetter,\n        connInfo client.ConnectionInfoGetter,\n        ctx context.Context,\n        name string,\n        opts *api.PodExecOptions,\n) (*url.URL, http.RoundTripper, error) {\n        return streamLocation(getter, connInfo, ctx, name, opts, opts.Container, \"exec\")\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/a1f1f0b599e961a5c59b02c349c0ed818b1851a5\/pkg\/registry\/core\/pod\/strategy.go#L457\">pkg\/registry\/core\/pod\/strategy.go<\/a><\/noindex>)<\/i><\/p>\n<p>\u041a\u043e\u043d\u0435\u0447\u043d\u043e, \u0434\u0430\u043d\u043d\u044b\u0435 \u043e\u0431 endpoint&#8217;\u0435 \u0431\u0435\u0440\u0443\u0442\u0441\u044f \u0438\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e\u0431 \u0443\u0437\u043b\u0435:<\/p>\n<pre><code class=\"go\">        nodeName := types.NodeName(pod.Spec.NodeName)\n        if len(nodeName) == 0 {\n                \/\/ If pod has not been assigned a host, return an empty location\n                return nil, nil, errors.NewBadRequest(fmt.Sprintf(\"pod %s does not have a host assigned\", name))\n        }\n        nodeInfo, err := connInfo.GetConnectionInfo(ctx, nodeName)<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/a1f1f0b599e961a5c59b02c349c0ed818b1851a5\/pkg\/registry\/core\/pod\/strategy.go#L348\">pkg\/registry\/core\/pod\/strategy.go<\/a><\/noindex>)<\/i><\/p>\n<p>\u0423\u0440\u0430! \u0423 kubelet&#8217;\u0430 \u0442\u0435\u043f\u0435\u0440\u044c \u0435\u0441\u0442\u044c \u043f\u043e\u0440\u0442 (<code>node.Status.DaemonEndpoints.KubeletEndpoint.Port<\/code>), \u043a \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f API-\u0441\u0435\u0440\u0432\u0435\u0440:<\/p>\n<pre><code class=\"go\">\/\/ GetConnectionInfo retrieves connection info from the status of a Node API object.\nfunc (k *NodeConnectionInfoGetter) GetConnectionInfo(ctx context.Context, nodeName types.NodeName) (*ConnectionInfo, error) {\n        node, err := k.nodes.Get(ctx, string(nodeName), metav1.GetOptions{})\n        if err != nil {\n                return nil, err\n        }\n\n        \/\/ Find a kubelet-reported address, using preferred address type\n        host, err := nodeutil.GetPreferredNodeAddress(node, k.preferredAddressTypes)\n        if err != nil {\n                return nil, err\n        }\n\n        \/\/ Use the kubelet-reported port, if present\n        port := int(node.Status.DaemonEndpoints.KubeletEndpoint.Port)\n        if port &lt;= 0 {\n                port = k.defaultPort\n        }\n\n        return &amp;ConnectionInfo{\n                Scheme:    k.scheme,\n                Hostname:  host,\n                Port:      strconv.Itoa(port),\n                Transport: k.transport,\n        }, nil\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/a1f1f0b599e961a5c59b02c349c0ed818b1851a5\/pkg\/kubelet\/client\/kubelet_client.go#L181\">pkg\/kubelet\/client\/kubelet_client.go<\/a><\/noindex>)<\/i><\/p>\n<blockquote><p>\u0418\u0437 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u0438 <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/architecture\/master-node-communication\/#apiserver-to-kubelet\">Master-Node Communication &gt; Master to Cluster &gt; apiserver to kubelet<\/a><\/noindex>:<\/p>\n<p>\u042d\u0442\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0437\u0430\u043c\u044b\u043a\u0430\u044e\u0442\u0441\u044f \u043d\u0430 HTTPS endpoint&#8217;\u0435 kubelet&#8217;\u0430. \u041f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e, apiserver \u043d\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 kubelet&#8217;\u0430, \u0447\u0442\u043e \u0434\u0435\u043b\u0430\u0435\u0442 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u043c \u043a \u00ab\u0430\u0442\u0430\u043a\u0430\u043c \u043f\u043e\u0441\u0440\u0435\u0434\u043d\u0438\u043a\u0430\u00bb (MITM) \u0438 <i><b>\u043d\u0435\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u044b\u043c<\/b><\/i> \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0432 \u043d\u0435\u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0445 \u0438\/\u0438\u043b\u0438 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0445 \u0441\u0435\u0442\u044f\u0445.<\/p><\/blockquote>\n<p>\n\u0422\u0435\u043f\u0435\u0440\u044c API-\u0441\u0435\u0440\u0432\u0435\u0440 \u0437\u043d\u0430\u0435\u0442 endpoint \u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435:<\/p>\n<pre><code class=\"go\">\/\/ Connect returns a handler for the pod exec proxy\nfunc (r *ExecREST) Connect(ctx context.Context, name string, opts runtime.Object, responder rest.Responder) (http.Handler, error) {\n        execOpts, ok := opts.(*api.PodExecOptions)\n        if !ok {\n                return nil, fmt.Errorf(\"invalid options object: %#v\", opts)\n        }\n        location, transport, err := pod.ExecLocation(r.Store, r.KubeletConn, ctx, name, execOpts)\n        if err != nil {\n                return nil, err\n        }\n        return newThrottledUpgradeAwareProxyHandler(location, transport, false, true, true, responder), nil\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/a1f1f0b599e961a5c59b02c349c0ed818b1851a5\/pkg\/registry\/core\/pod\/rest\/subresources.go#L96\">pkg\/registry\/core\/pod\/rest\/subresources.go<\/a><\/noindex>)<\/i><\/p>\n<p>\u0414\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u0447\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043d\u0430 \u043c\u0430\u0441\u0442\u0435\u0440-\u0443\u0437\u043b\u0435.<\/p>\n<p>\u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u0443\u0437\u043d\u0430\u0435\u043c IP \u0440\u0430\u0431\u043e\u0447\u0435\u0433\u043e \u0443\u0437\u043b\u0430. \u0412 \u043d\u0430\u0448\u0435\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u044d\u0442\u043e 192.168.205.11:<\/p>\n<pre><code class=\"bash\">\/\/ any machine\n$ kubectl get nodes k8s-node-1 -o wide\nNAME         STATUS   ROLES    AGE   VERSION   INTERNAL-IP      EXTERNAL-IP   OS-IMAGE             KERNEL-VERSION      CONTAINER-RUNTIME\nk8s-node-1   Ready    &lt;none&gt;   9h    v1.15.3   192.168.205.11   &lt;none&gt;        Ubuntu 16.04.6 LTS   4.4.0-159-generic   docker:\/\/17.3.3<\/code><\/pre>\n<p>\n\u0417\u0430\u0442\u0435\u043c \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043c \u043f\u043e\u0440\u0442 kubelet&#8217;\u0430 (10250 \u0432 \u043d\u0430\u0448\u0435\u043c \u0441\u043b\u0443\u0447\u0430\u0435):<\/p>\n<pre><code class=\"bash\">\/\/ any machine\n$ kubectl get nodes k8s-node-1 -o jsonpath='{.status.daemonEndpoints.kubeletEndpoint}'\nmap[Port:10250]<\/code><\/pre>\n<p>\n\u0422\u0435\u043f\u0435\u0440\u044c \u043f\u043e\u0440\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u0441\u0435\u0442\u044c. \u0415\u0441\u0442\u044c \u043b\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u043a \u0440\u0430\u0431\u043e\u0447\u0435\u043c\u0443 \u0443\u0437\u043b\u0443 (192.168.205.11)? \u041e\u043d\u043e \u0435\u0441\u0442\u044c! \u0415\u0441\u043b\u0438 \u00ab\u0443\u0431\u0438\u0442\u044c\u00bb \u043f\u0440\u043e\u0446\u0435\u0441\u0441 <code>exec<\/code>, \u043e\u043d\u043e \u0438\u0441\u0447\u0435\u0437\u043d\u0435\u0442, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u044f \u0437\u043d\u0430\u044e, \u0447\u0442\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043e api-server&#8217;\u043e\u043c \u043a\u0430\u043a \u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u043e\u0439 exec-\u043a\u043e\u043c\u0430\u043d\u0434\u044b.<\/p>\n<pre><code class=\"bash\">\/\/ master node\n$ netstat -atn |grep 192.168.205.11\ntcp        0      0 192.168.205.10:37870    192.168.205.11:10250    ESTABLISHED\n\u2026<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec?\" src=\"\/wp-content\/uploads\/2019\/10\/7175c8e70bb787693a2838c99631e63f.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u0421\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u043c\u0435\u0436\u0434\u0443 kubectl&#8217;\u043e\u043c \u0438 api-server&#8217;\u043e\u043c \u043f\u043e-\u043f\u0440\u0435\u0436\u043d\u0435\u043c\u0443 \u043e\u0442\u043a\u0440\u044b\u0442\u043e. \u041a\u0440\u043e\u043c\u0435 \u0442\u043e\u0433\u043e, \u0435\u0441\u0442\u044c \u0435\u0449\u0435 \u043e\u0434\u043d\u043e \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435, \u0441\u0432\u044f\u0437\u044b\u0432\u0430\u044e\u0449\u0435\u0435 api-server \u0438 kubelet.<\/p>\n<h3>3. \u0410\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u043d\u0430 \u0440\u0430\u0431\u043e\u0447\u0435\u043c \u0443\u0437\u043b\u0435<\/h3>\n<p>\n\u0422\u0435\u043f\u0435\u0440\u044c \u0434\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u043c\u0441\u044f \u043a worker-\u0443\u0437\u043b\u0443 \u0438 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u0447\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043d\u0430 \u043d\u0435\u043c. <\/p>\n<p>\u041f\u0440\u0435\u0436\u0434\u0435 \u0432\u0441\u0435\u0433\u043e \u043c\u044b \u0432\u0438\u0434\u0438\u043c, \u0447\u0442\u043e \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0441 \u043d\u0438\u043c \u0442\u0430\u043a\u0436\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043e (\u0432\u0442\u043e\u0440\u0430\u044f \u0441\u0442\u0440\u043e\u043a\u0430); 192.168.205.10 \u2014 \u044d\u0442\u043e IP master-\u0443\u0437\u043b\u0430:<\/p>\n<pre><code class=\"bash\"> \/\/ worker node\n  $ netstat -atn |grep 10250\n  tcp6       0      0 :::10250                :::*                    LISTEN\n  tcp6       0      0 192.168.205.11:10250    192.168.205.10:37870    ESTABLISHED<\/code><\/pre>\n<p>\n\u0410 \u043a\u0430\u043a \u043d\u0430\u0441\u0447\u0435\u0442 \u043d\u0430\u0448\u0435\u0439 \u043a\u043e\u043c\u0430\u043d\u0434\u044b <code>sleep<\/code>? \u0423\u0440\u0430, \u043e\u043d\u0430 \u0442\u043e\u0436\u0435 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442!<\/p>\n<pre><code class=\"bash\"> \/\/ worker node\n  $ ps -afx\n  ...\n  31463 ?        Sl     0:00      _ docker-containerd-shim 7d974065bbb3107074ce31c51f5ef40aea8dcd535ae11a7b8f2dd180b8ed583a \/var\/run\/docker\/libcontainerd\/7d974065bbb3107074ce31c51\n  31478 pts\/0    Ss     0:00          _ sh\n  31485 pts\/0    S+     0:00              _ sleep 5000\n  \u2026<\/code><\/pre>\n<p>\n\u041d\u043e \u043f\u043e\u0441\u0442\u043e\u0439\u0442\u0435: \u043a\u0430\u043a kubelet \u043f\u0440\u043e\u0432\u0435\u0440\u043d\u0443\u043b \u044d\u0442\u043e? \u0412 kubelet \u0435\u0441\u0442\u044c \u0434\u0435\u043c\u043e\u043d, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u0442 \u0434\u043e\u0441\u0442\u0443\u043f \u043a API \u0447\u0435\u0440\u0435\u0437 \u043f\u043e\u0440\u0442 \u0434\u043b\u044f \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 api-server&#8217;\u0430:<\/p>\n<pre><code class=\"go\">\/\/ Server is the library interface to serve the stream requests.\ntype Server interface {\n        http.Handler\n\n        \/\/ Get the serving URL for the requests.\n        \/\/ Requests must not be nil. Responses may be nil iff an error is returned.\n        GetExec(*runtimeapi.ExecRequest) (*runtimeapi.ExecResponse, error)\n        GetAttach(req *runtimeapi.AttachRequest) (*runtimeapi.AttachResponse, error)\n        GetPortForward(*runtimeapi.PortForwardRequest) (*runtimeapi.PortForwardResponse, error)\n\n        \/\/ Start the server.\n        \/\/ addr is the address to serve on (address:port) stayUp indicates whether the server should\n        \/\/ listen until Stop() is called, or automatically stop after all expected connections are\n        \/\/ closed. Calling Get{Exec,Attach,PortForward} increments the expected connection count.\n        \/\/ Function does not return until the server is stopped.\n        Start(stayUp bool) error\n        \/\/ Stop the server, and terminate any open connections.\n        Stop() error\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/pkg\/kubelet\/server\/streaming\/server.go#L42\">pkg\/kubelet\/server\/streaming\/server.go<\/a><\/noindex>)<\/i><\/p>\n<p>Kubelet \u0432\u044b\u0447\u0438\u0441\u043b\u044f\u0435\u0442 \u043e\u0442\u0432\u0435\u0442\u043d\u044b\u0439 endpoint \u0434\u043b\u044f exec-\u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432:<\/p>\n<pre><code class=\"go\">func (s *server) GetExec(req *runtimeapi.ExecRequest) (*runtimeapi.ExecResponse, error) {\n        if err := validateExecRequest(req); err != nil {\n                return nil, err\n        }\n        token, err := s.cache.Insert(req)\n        if err != nil {\n                return nil, err\n        }\n        return &amp;runtimeapi.ExecResponse{\n                Url: s.buildURL(\"exec\", token),\n        }, nil\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/pkg\/kubelet\/server\/streaming\/server.go#L179\">pkg\/kubelet\/server\/streaming\/server.go<\/a><\/noindex>)<\/i><\/p>\n<p>\u041d\u0435 \u043f\u0435\u0440\u0435\u043f\u0443\u0442\u0430\u0439\u0442\u0435. \u041e\u043d \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u043d\u0435 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442 \u043a\u043e\u043c\u0430\u043d\u0434\u044b, \u0430 endpoint \u0434\u043b\u044f \u0441\u0432\u044f\u0437\u0438:<\/p>\n<pre><code class=\"go\">type ExecResponse struct {\n        \/\/ Fully qualified URL of the exec streaming server.\n        Url                  string   `protobuf:\"bytes,1,opt,name=url,proto3\" json:\"url,omitempty\"`\n        XXX_NoUnkeyedLiteral struct{} `json:\"-\"`\n        XXX_sizecache        int32    `json:\"-\"`\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/staging\/src\/k8s.io\/cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go#L4535\">cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go<\/a><\/noindex>)<\/i><\/p>\n<p>Kubelet \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u0442 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 <code>RuntimeServiceClient<\/code>, \u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u0447\u0430\u0441\u0442\u044c\u044e Container Runtime Interface <i>(\u043f\u043e\u0434\u0440\u043e\u0431\u043d\u0435\u0435 \u043e \u043d\u0451\u043c \u043c\u044b \u043f\u0438\u0441\u0430\u043b\u0438, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/414875\/\">\u0437\u0434\u0435\u0441\u044c<\/a><\/noindex> \u2014 \u043f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.)<\/i>:<\/p>\n<p><b class=\"spoiler_title\">\u0414\u043b\u0438\u043d\u043d\u044b\u0439 \u043b\u0438\u0441\u0442\u0438\u043d\u0433 \u0438\u0437 cri-api \u0432 kubernetes\/kubernetes<\/b><\/p>\n<pre><code class=\"go\">\/\/ For semantics around ctx use and closing\/ending streaming RPCs, please refer to https:\/\/godoc.org\/google.golang.org\/grpc#ClientConn.NewStream.\ntype RuntimeServiceClient interface {\n        \/\/ Version returns the runtime name, runtime version, and runtime API version.\n        Version(ctx context.Context, in *VersionRequest, opts ...grpc.CallOption) (*VersionResponse, error)\n        \/\/ RunPodSandbox creates and starts a pod-level sandbox. Runtimes must ensure\n        \/\/ the sandbox is in the ready state on success.\n        RunPodSandbox(ctx context.Context, in *RunPodSandboxRequest, opts ...grpc.CallOption) (*RunPodSandboxResponse, error)\n        \/\/ StopPodSandbox stops any running process that is part of the sandbox and\n        \/\/ reclaims network resources (e.g., IP addresses) allocated to the sandbox.\n        \/\/ If there are any running containers in the sandbox, they must be forcibly\n        \/\/ terminated.\n        \/\/ This call is idempotent, and must not return an error if all relevant\n        \/\/ resources have already been reclaimed. kubelet will call StopPodSandbox\n        \/\/ at least once before calling RemovePodSandbox. It will also attempt to\n        \/\/ reclaim resources eagerly, as soon as a sandbox is not needed. Hence,\n        \/\/ multiple StopPodSandbox calls are expected.\n        StopPodSandbox(ctx context.Context, in *StopPodSandboxRequest, opts ...grpc.CallOption) (*StopPodSandboxResponse, error)\n        \/\/ RemovePodSandbox removes the sandbox. If there are any running containers\n        \/\/ in the sandbox, they must be forcibly terminated and removed.\n        \/\/ This call is idempotent, and must not return an error if the sandbox has\n        \/\/ already been removed.\n        RemovePodSandbox(ctx context.Context, in *RemovePodSandboxRequest, opts ...grpc.CallOption) (*RemovePodSandboxResponse, error)\n        \/\/ PodSandboxStatus returns the status of the PodSandbox. If the PodSandbox is not\n        \/\/ present, returns an error.\n        PodSandboxStatus(ctx context.Context, in *PodSandboxStatusRequest, opts ...grpc.CallOption) (*PodSandboxStatusResponse, error)\n        \/\/ ListPodSandbox returns a list of PodSandboxes.\n        ListPodSandbox(ctx context.Context, in *ListPodSandboxRequest, opts ...grpc.CallOption) (*ListPodSandboxResponse, error)\n        \/\/ CreateContainer creates a new container in specified PodSandbox\n        CreateContainer(ctx context.Context, in *CreateContainerRequest, opts ...grpc.CallOption) (*CreateContainerResponse, error)\n        \/\/ StartContainer starts the container.\n        StartContainer(ctx context.Context, in *StartContainerRequest, opts ...grpc.CallOption) (*StartContainerResponse, error)\n        \/\/ StopContainer stops a running container with a grace period (i.e., timeout).\n        \/\/ This call is idempotent, and must not return an error if the container has\n        \/\/ already been stopped.\n        \/\/ TODO: what must the runtime do after the grace period is reached?\n        StopContainer(ctx context.Context, in *StopContainerRequest, opts ...grpc.CallOption) (*StopContainerResponse, error)\n        \/\/ RemoveContainer removes the container. If the container is running, the\n        \/\/ container must be forcibly removed.\n        \/\/ This call is idempotent, and must not return an error if the container has\n        \/\/ already been removed.\n        RemoveContainer(ctx context.Context, in *RemoveContainerRequest, opts ...grpc.CallOption) (*RemoveContainerResponse, error)\n        \/\/ ListContainers lists all containers by filters.\n        ListContainers(ctx context.Context, in *ListContainersRequest, opts ...grpc.CallOption) (*ListContainersResponse, error)\n        \/\/ ContainerStatus returns status of the container. If the container is not\n        \/\/ present, returns an error.\n        ContainerStatus(ctx context.Context, in *ContainerStatusRequest, opts ...grpc.CallOption) (*ContainerStatusResponse, error)\n        \/\/ UpdateContainerResources updates ContainerConfig of the container.\n        UpdateContainerResources(ctx context.Context, in *UpdateContainerResourcesRequest, opts ...grpc.CallOption) (*UpdateContainerResourcesResponse, error)\n        \/\/ ReopenContainerLog asks runtime to reopen the stdout\/stderr log file\n        \/\/ for the container. This is often called after the log file has been\n        \/\/ rotated. If the container is not running, container runtime can choose\n        \/\/ to either create a new log file and return nil, or return an error.\n        \/\/ Once it returns error, new container log file MUST NOT be created.\n        ReopenContainerLog(ctx context.Context, in *ReopenContainerLogRequest, opts ...grpc.CallOption) (*ReopenContainerLogResponse, error)\n        \/\/ ExecSync runs a command in a container synchronously.\n        ExecSync(ctx context.Context, in *ExecSyncRequest, opts ...grpc.CallOption) (*ExecSyncResponse, error)\n        \/\/ Exec prepares a streaming endpoint to execute a command in the container.\n        Exec(ctx context.Context, in *ExecRequest, opts ...grpc.CallOption) (*ExecResponse, error)\n        \/\/ Attach prepares a streaming endpoint to attach to a running container.\n        Attach(ctx context.Context, in *AttachRequest, opts ...grpc.CallOption) (*AttachResponse, error)\n        \/\/ PortForward prepares a streaming endpoint to forward ports from a PodSandbox.\n        PortForward(ctx context.Context, in *PortForwardRequest, opts ...grpc.CallOption) (*PortForwardResponse, error)\n        \/\/ ContainerStats returns stats of the container. If the container does not\n        \/\/ exist, the call returns an error.\n        ContainerStats(ctx context.Context, in *ContainerStatsRequest, opts ...grpc.CallOption) (*ContainerStatsResponse, error)\n        \/\/ ListContainerStats returns stats of all running containers.\n        ListContainerStats(ctx context.Context, in *ListContainerStatsRequest, opts ...grpc.CallOption) (*ListContainerStatsResponse, error)\n        \/\/ UpdateRuntimeConfig updates the runtime configuration based on the given request.\n        UpdateRuntimeConfig(ctx context.Context, in *UpdateRuntimeConfigRequest, opts ...grpc.CallOption) (*UpdateRuntimeConfigResponse, error)\n        \/\/ Status returns the status of the runtime.\n        Status(ctx context.Context, in *StatusRequest, opts ...grpc.CallOption) (*StatusResponse, error)\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/staging\/src\/k8s.io\/cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go#L7156\">cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go<\/a><\/noindex>)<\/i><br \/>\n\u041e\u043d \u043f\u0440\u043e\u0441\u0442\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 gRPC \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043c\u0435\u0442\u043e\u0434\u0430 \u0447\u0435\u0440\u0435\u0437 Container Runtime Interface:<\/p>\n<pre><code class=\"go\">type runtimeServiceClient struct {\n        cc *grpc.ClientConn\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/staging\/src\/k8s.io\/cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go#L7231\">cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go<\/a><\/noindex>)<\/i><\/p>\n<pre><code class=\"go\">func (c *runtimeServiceClient) Exec(ctx context.Context, in *ExecRequest, opts ...grpc.CallOption) (*ExecResponse, error) {\n        out := new(ExecResponse)\n        err := c.cc.Invoke(ctx, \"\/runtime.v1alpha2.RuntimeService\/Exec\", in, out, opts...)\n        if err != nil {\n                return nil, err\n        }\n        return out, nil\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/staging\/src\/k8s.io\/cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go#L7374\">cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go<\/a><\/noindex>)<\/i><\/p>\n<p>Container Runtime \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0437\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e <code>RuntimeServiceServer<\/code>:<\/p>\n<p><b class=\"spoiler_title\">\u0414\u043b\u0438\u043d\u043d\u044b\u0439 \u043b\u0438\u0441\u0442\u0438\u043d\u0433 \u0438\u0437 cri-api \u0432 kubernetes\/kubernetes<\/b><\/p>\n<pre><code class=\"go\">\/\/ RuntimeServiceServer is the server API for RuntimeService service.\ntype RuntimeServiceServer interface {\n        \/\/ Version returns the runtime name, runtime version, and runtime API version.\n        Version(context.Context, *VersionRequest) (*VersionResponse, error)\n        \/\/ RunPodSandbox creates and starts a pod-level sandbox. Runtimes must ensure\n        \/\/ the sandbox is in the ready state on success.\n        RunPodSandbox(context.Context, *RunPodSandboxRequest) (*RunPodSandboxResponse, error)\n        \/\/ StopPodSandbox stops any running process that is part of the sandbox and\n        \/\/ reclaims network resources (e.g., IP addresses) allocated to the sandbox.\n        \/\/ If there are any running containers in the sandbox, they must be forcibly\n        \/\/ terminated.\n        \/\/ This call is idempotent, and must not return an error if all relevant\n        \/\/ resources have already been reclaimed. kubelet will call StopPodSandbox\n        \/\/ at least once before calling RemovePodSandbox. It will also attempt to\n        \/\/ reclaim resources eagerly, as soon as a sandbox is not needed. Hence,\n        \/\/ multiple StopPodSandbox calls are expected.\n        StopPodSandbox(context.Context, *StopPodSandboxRequest) (*StopPodSandboxResponse, error)\n        \/\/ RemovePodSandbox removes the sandbox. If there are any running containers\n        \/\/ in the sandbox, they must be forcibly terminated and removed.\n        \/\/ This call is idempotent, and must not return an error if the sandbox has\n        \/\/ already been removed.\n        RemovePodSandbox(context.Context, *RemovePodSandboxRequest) (*RemovePodSandboxResponse, error)\n        \/\/ PodSandboxStatus returns the status of the PodSandbox. If the PodSandbox is not\n        \/\/ present, returns an error.\n        PodSandboxStatus(context.Context, *PodSandboxStatusRequest) (*PodSandboxStatusResponse, error)\n        \/\/ ListPodSandbox returns a list of PodSandboxes.\n        ListPodSandbox(context.Context, *ListPodSandboxRequest) (*ListPodSandboxResponse, error)\n        \/\/ CreateContainer creates a new container in specified PodSandbox\n        CreateContainer(context.Context, *CreateContainerRequest) (*CreateContainerResponse, error)\n        \/\/ StartContainer starts the container.\n        StartContainer(context.Context, *StartContainerRequest) (*StartContainerResponse, error)\n        \/\/ StopContainer stops a running container with a grace period (i.e., timeout).\n        \/\/ This call is idempotent, and must not return an error if the container has\n        \/\/ already been stopped.\n        \/\/ TODO: what must the runtime do after the grace period is reached?\n        StopContainer(context.Context, *StopContainerRequest) (*StopContainerResponse, error)\n        \/\/ RemoveContainer removes the container. If the container is running, the\n        \/\/ container must be forcibly removed.\n        \/\/ This call is idempotent, and must not return an error if the container has\n        \/\/ already been removed.\n        RemoveContainer(context.Context, *RemoveContainerRequest) (*RemoveContainerResponse, error)\n        \/\/ ListContainers lists all containers by filters.\n        ListContainers(context.Context, *ListContainersRequest) (*ListContainersResponse, error)\n        \/\/ ContainerStatus returns status of the container. If the container is not\n        \/\/ present, returns an error.\n        ContainerStatus(context.Context, *ContainerStatusRequest) (*ContainerStatusResponse, error)\n        \/\/ UpdateContainerResources updates ContainerConfig of the container.\n        UpdateContainerResources(context.Context, *UpdateContainerResourcesRequest) (*UpdateContainerResourcesResponse, error)\n        \/\/ ReopenContainerLog asks runtime to reopen the stdout\/stderr log file\n        \/\/ for the container. This is often called after the log file has been\n        \/\/ rotated. If the container is not running, container runtime can choose\n        \/\/ to either create a new log file and return nil, or return an error.\n        \/\/ Once it returns error, new container log file MUST NOT be created.\n        ReopenContainerLog(context.Context, *ReopenContainerLogRequest) (*ReopenContainerLogResponse, error)\n        \/\/ ExecSync runs a command in a container synchronously.\n        ExecSync(context.Context, *ExecSyncRequest) (*ExecSyncResponse, error)\n        \/\/ Exec prepares a streaming endpoint to execute a command in the container.\n        Exec(context.Context, *ExecRequest) (*ExecResponse, error)\n        \/\/ Attach prepares a streaming endpoint to attach to a running container.\n        Attach(context.Context, *AttachRequest) (*AttachResponse, error)\n        \/\/ PortForward prepares a streaming endpoint to forward ports from a PodSandbox.\n        PortForward(context.Context, *PortForwardRequest) (*PortForwardResponse, error)\n        \/\/ ContainerStats returns stats of the container. If the container does not\n        \/\/ exist, the call returns an error.\n        ContainerStats(context.Context, *ContainerStatsRequest) (*ContainerStatsResponse, error)\n        \/\/ ListContainerStats returns stats of all running containers.\n        ListContainerStats(context.Context, *ListContainerStatsRequest) (*ListContainerStatsResponse, error)\n        \/\/ UpdateRuntimeConfig updates the runtime configuration based on the given request.\n        UpdateRuntimeConfig(context.Context, *UpdateRuntimeConfigRequest) (*UpdateRuntimeConfigResponse, error)\n        \/\/ Status returns the status of the runtime.\n        Status(context.Context, *StatusRequest) (*StatusResponse, error)\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/kubernetes\/blob\/master\/staging\/src\/k8s.io\/cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go#L7437\">cri-api\/pkg\/apis\/runtime\/v1alpha2\/api.pb.go<\/a><\/noindex>)<\/i><br \/>\n<img decoding=\"async\" alt=\"\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec?\" src=\"\/wp-content\/uploads\/2019\/10\/e0abd308683f2c4775d73fc5a75b43bb.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u0415\u0441\u043b\u0438 \u044d\u0442\u043e \u0442\u0430\u043a, \u043c\u044b \u0434\u043e\u043b\u0436\u043d\u044b \u0432\u0438\u0434\u0435\u0442\u044c \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u043c\u0435\u0436\u0434\u0443 kubelet&#8217;\u043e\u043c \u0438 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0439 \u0441\u0440\u0435\u0434\u043e\u0439 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430, \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e? \u0414\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043c.<\/p>\n<p>\u0412\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u0435 \u044d\u0442\u0443 \u043a\u043e\u043c\u0430\u043d\u0434\u0443 \u0434\u043e \u0438 \u043f\u043e\u0441\u043b\u0435 exec-\u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0438 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u0442\u0435 \u043d\u0430 \u043e\u0442\u043b\u0438\u0447\u0438\u044f. \u0412 \u043c\u043e\u0435\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u0440\u0430\u0437\u043d\u0438\u0446\u0430 \u0442\u0430\u043a\u043e\u0432\u0430:<\/p>\n<pre><code class=\"bash\">\/\/ worker node\n$ ss -a -p |grep kubelet\n...\nu_str  ESTAB      0      0       * 157937                * 157387                users:((\"kubelet\",pid=5714,fd=33))\n...<\/code><\/pre>\n<p>\n\u0425\u043c-\u043c-\u043c\u2026 \u041d\u043e\u0432\u043e\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0447\u0435\u0440\u0435\u0437 unix-\u0441\u043e\u043a\u0435\u0442\u044b \u043c\u0435\u0436\u0434\u0443 kubelet&#8217;\u043e\u043c (pid=5714) \u0438 \u0447\u0435\u043c-\u0442\u043e \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c. \u0427\u0442\u043e \u0436\u0435 \u044d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c? \u041f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e, \u044d\u0442\u043e Docker (pid=1186)!<\/p>\n<pre><code class=\"bash\">\/\/ worker node\n$ ss -a -p |grep 157387\n...\nu_str  ESTAB      0      0       * 157937                * 157387                users:((\"kubelet\",pid=5714,fd=33))\nu_str  ESTAB      0      0      \/var\/run\/docker.sock 157387                * 157937                users:((\"dockerd\",pid=1186,fd=14))\n...<\/code><\/pre>\n<p>\n\u041a\u0430\u043a \u0432\u044b \u043f\u043e\u043c\u043d\u0438\u0442\u0435, \u044d\u0442\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441 docker-\u0434\u0435\u043c\u043e\u043d\u0430 (pid=1186), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043d\u0430\u0448\u0443 \u043a\u043e\u043c\u0430\u043d\u0434\u0443:<\/p>\n<pre><code class=\"bash\">\/\/ worker node\n$ ps -afx\n...\n 1186 ?        Ssl    0:55 \/usr\/bin\/dockerd -H fd:\/\/\n17784 ?        Sl     0:00      _ docker-containerd-shim 53a0a08547b2f95986402d7f3b3e78702516244df049ba6c5aa012e81264aa3c \/var\/run\/docker\/libcontainerd\/53a0a08547b2f95986402d7f3\n17801 pts\/2    Ss     0:00          _ sh\n17827 pts\/2    S+     0:00              _ sleep 5000\n...<\/code><\/pre>\n<p><\/p>\n<h3>4. \u0410\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u044c \u0432 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0439 \u0441\u0440\u0435\u0434\u0435 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430<\/h3>\n<p>\n\u0414\u0430\u0432\u0430\u0439\u0442\u0435 \u0438\u0437\u0443\u0447\u0438\u043c \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u0439 \u043a\u043e\u0434 CRI-O, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u043d\u044f\u0442\u044c, \u0447\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442. \u0412 Docker&#8217;\u0435 \u043b\u043e\u0433\u0438\u043a\u0430 \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u043d\u0430\u044f.<\/p>\n<p>\u0418\u043c\u0435\u0435\u0442\u0441\u044f \u0441\u0435\u0440\u0432\u0435\u0440, \u043e\u0442\u0432\u0435\u0447\u0430\u044e\u0449\u0438\u0439 \u0437\u0430 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e <code>RuntimeServiceServer<\/code>:<\/p>\n<pre><code class=\"go\">\/\/ Server implements the RuntimeService and ImageService\ntype Server struct {\n        config          libconfig.Config\n        seccompProfile  *seccomp.Seccomp\n        stream          StreamService\n        netPlugin       ocicni.CNIPlugin\n        hostportManager hostport.HostPortManager\n\n        appArmorProfile string\n        hostIP          string\n        bindAddress     string\n\n        *lib.ContainerServer\n        monitorsChan      chan struct{}\n        defaultIDMappings *idtools.IDMappings\n        systemContext     *types.SystemContext \/\/ Never nil\n\n        updateLock sync.RWMutex\n\n        seccompEnabled  bool\n        appArmorEnabled bool\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/cri-o\/cri-o\/blob\/master\/server\/server.go#L62\">cri-o\/server\/server.go<\/a><\/noindex>)<\/i><\/p>\n<pre><code class=\"go\">\/\/ Exec prepares a streaming endpoint to execute a command in the container.\nfunc (s *Server) Exec(ctx context.Context, req *pb.ExecRequest) (resp *pb.ExecResponse, err error) {\n        const operation = \"exec\"\n        defer func() {\n                recordOperation(operation, time.Now())\n                recordError(operation, err)\n        }()\n\n        resp, err = s.getExec(req)\n        if err != nil {\n                return nil, fmt.Errorf(\"unable to prepare exec endpoint: %v\", err)\n        }\n\n        return resp, nil\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/cri-o\/cri-o\/blob\/master\/server\/container_exec.go#L14\">cri-o\/erver\/container_exec.go<\/a><\/noindex>)<\/i><\/p>\n<p>\u0412 \u043a\u043e\u043d\u0446\u0435 \u0446\u0435\u043f\u043e\u0447\u043a\u0438 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u0430\u044f \u0441\u0440\u0435\u0434\u0430 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043a\u043e\u043c\u0430\u043d\u0434\u0443 \u043d\u0430 \u0440\u0430\u0431\u043e\u0447\u0435\u043c \u0443\u0437\u043b\u0435:<\/p>\n<pre><code class=\"go\">\/\/ ExecContainer prepares a streaming endpoint to execute a command in the container.\nfunc (r *runtimeOCI) ExecContainer(c *Container, cmd []string, stdin io.Reader, stdout, stderr io.WriteCloser, tty bool, resize &lt;-chan remotecommand.TerminalSize) error {\n        processFile, err := prepareProcessExec(c, cmd, tty)\n        if err != nil {\n                return err\n        }\n        defer os.RemoveAll(processFile.Name())\n\n        args := []string{rootFlag, r.root, \"exec\"}\n        args = append(args, \"--process\", processFile.Name(), c.ID())\n        execCmd := exec.Command(r.path, args...)\n        if v, found := os.LookupEnv(\"XDG_RUNTIME_DIR\"); found {\n                execCmd.Env = append(execCmd.Env, fmt.Sprintf(\"XDG_RUNTIME_DIR=%s\", v))\n        }\n        var cmdErr, copyError error\n        if tty {\n                cmdErr = ttyCmd(execCmd, stdin, stdout, resize)\n        } else {\n                if stdin != nil {\n                        \/\/ Use an os.Pipe here as it returns true *os.File objects.\n                        \/\/ This way, if you run 'kubectl exec &lt;pod&gt; -i bash' (no tty) and type 'exit',\n                        \/\/ the call below to execCmd.Run() can unblock because its Stdin is the read half\n                        \/\/ of the pipe.\n                        r, w, err := os.Pipe()\n                        if err != nil {\n                                return err\n                        }\n                        go func() { _, copyError = pools.Copy(w, stdin) }()\n\n                        execCmd.Stdin = r\n                }\n                if stdout != nil {\n                        execCmd.Stdout = stdout\n                }\n                if stderr != nil {\n                        execCmd.Stderr = stderr\n                }\n\n                cmdErr = execCmd.Run()\n        }\n\n        if copyError != nil {\n                return copyError\n        }\n        if exitErr, ok := cmdErr.(*exec.ExitError); ok {\n                return &amp;utilexec.ExitErrorWrapper{ExitError: exitErr}\n        }\n        return cmdErr\n}<\/code><\/pre>\n<p>\n<i>(<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/cri-o\/cri-o\/blob\/master\/internal\/oci\/runtime_oci.go#L294\">cri-o\/internal\/oci\/runtime_oci.go<\/a><\/noindex>)<\/i><\/p>\n<p><img decoding=\"async\" alt=\"\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec?\" src=\"\/wp-content\/uploads\/2019\/10\/c85c16fa6929d132e020c87832bc9b9c.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u041d\u0430\u043a\u043e\u043d\u0435\u0446, \u044f\u0434\u0440\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043a\u043e\u043c\u0430\u043d\u0434\u044b:<\/p>\n<p><img decoding=\"async\" alt=\"\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec?\" src=\"\/wp-content\/uploads\/2019\/10\/528aa3ffed8a72a916220a73b0f5a592.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h2>\u041d\u0430\u043f\u043e\u043c\u0438\u043d\u0430\u043d\u0438\u044f<\/h2>\n<p><\/p>\n<ul>\n<li> API Server \u0442\u0430\u043a\u0436\u0435 \u043c\u043e\u0436\u0435\u0442 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0441 kubelet&#8217;\u043e\u043c.<\/li>\n<li> \u0421\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u044f\u044e\u0442\u0441\u044f \u0434\u043e \u043e\u043a\u043e\u043d\u0447\u0430\u043d\u0438\u044f \u0438\u043d\u0442\u0435\u0440\u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0433\u043e exec-\u0441\u0435\u0430\u043d\u0441\u0430:\n<ul>\n<li> \u043c\u0435\u0436\u0434\u0443 kubectl \u0438 api-server&#8217;\u043e\u043c;<\/li>\n<li> \u043c\u0435\u0436\u0434\u0443 api-server&#8217;\u043e\u043c \u0438 kubectl;<\/li>\n<li> \u043c\u0435\u0436\u0434\u0443 kubelet&#8217;\u043e\u043c \u0438 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0439 \u0441\u0440\u0435\u0434\u043e\u0439 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430.<\/li>\n<\/ul>\n<\/li>\n<li> Kubectl \u0438\u043b\u0438 api-server \u043d\u0435 \u043c\u043e\u0433\u0443\u0442 \u043d\u0438\u0447\u0435\u0433\u043e \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043d\u0430 \u0440\u0430\u0431\u043e\u0447\u0438\u0445 \u0443\u0437\u043b\u0430\u0445. Kubelet \u043c\u043e\u0436\u0435\u0442 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c, \u043d\u043e \u0434\u043b\u044f \u044d\u0442\u0438\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439 \u043e\u043d \u0442\u0430\u043a\u0436\u0435 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0443\u0435\u0442 \u0441 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0439 \u0441\u0440\u0435\u0434\u043e\u0439 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430.<\/li>\n<\/ul>\n<p><\/p>\n<h2>\u0420\u0435\u0441\u0443\u0440\u0441\u044b<\/h2>\n<p><\/p>\n<ul>\n<li> \u041e\u0431\u0441\u0443\u0436\u0434\u0435\u043d\u0438\u0435 \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/groups.google.com\/forum\/#!topic\/kubernetes-dev\/Cjia36v39vM\">How does \u00abkubectl exec\u00bb work<\/a><\/noindex>\u00bb \u0432 kubernetes-dev;<\/li>\n<li> \u0421\u0442\u0430\u0442\u044c\u044f \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@joatmon08\/playing-with-kubeadm-in-vagrant-machines-part-2-bac431095706\">Playing with kubeadm in Vagrant Machines, Part 2<\/a><\/noindex>\u00bb;<\/li>\n<li> \u041e\u0431\u0441\u0443\u0436\u0434\u0435\u043d\u0438\u0435 \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/serverfault.com\/questions\/252723\/how-to-find-other-end-of-unix-socket-connection\">How to find other end of unix socket connection?<\/a><\/noindex>\u00bb \u043d\u0430 Server Fault.<\/li>\n<\/ul>\n<p><\/p>\n<h2>P.S. \u043e\u0442 \u043f\u0435\u0440\u0435\u0432\u043e\u0434\u0447\u0438\u043a\u0430<\/h2>\n<p>\n\u0427\u0438\u0442\u0430\u0439\u0442\u0435 \u0442\u0430\u043a\u0436\u0435 \u0432 \u043d\u0430\u0448\u0435\u043c \u0431\u043b\u043e\u0433\u0435:<\/p>\n<ul>\n<li> \u00ab\u0427\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0432 Kubernetes \u043f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 kubectl run?\u00bb <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/342658\/\">\u0427\u0430\u0441\u0442\u044c 1<\/a><\/noindex> \u0438 <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/342822\/\">\u0447\u0430\u0441\u0442\u044c 2<\/a><\/noindex>;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/427819\/\">\u0422\u0430\u043a \u0447\u0442\u043e \u0436\u0435 \u0442\u0430\u043a\u043e\u0435 pod \u0432 Kubernetes?<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/342658\/\">\u041a\u0430\u043a \u043d\u0430 \u0441\u0430\u043c\u043e\u043c \u0434\u0435\u043b\u0435 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043f\u043b\u0430\u043d\u0438\u0440\u043e\u0432\u0449\u0438\u043a Kubernetes?<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/427283\/\">\u041a\u0430\u043a \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432\u044b\u0441\u043e\u043a\u0430\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e\u0441\u0442\u044c \u0432 Kubernetes<\/a><\/noindex>\u00bb.<\/li>\n<\/ul>\n<p>\u0418\u0441\u0442\u043e\u0447\u043d\u0438\u043a: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/466093\/\">habr.com<\/a><\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0430\u0432\u0442\u043e\u0440 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Erkan Erol, \u0438\u043d\u0436\u0435\u043d\u0435\u0440 \u0438\u0437 SAP \u2014 \u0434\u0435\u043b\u0438\u0442\u0441\u044f \u0441\u0432\u043e\u0438\u043c \u0438\u0437\u0443\u0447\u0435\u043d\u0438\u0435\u043c \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434\u044b kubectl exec, \u0441\u0442\u043e\u043b\u044c \u043f\u0440\u0438\u0432\u044b\u0447\u043d\u043e\u0439 \u0434\u043b\u044f \u0432\u0441\u0435\u0445, \u043a\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 Kubernetes. \u0412\u0435\u0441\u044c \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u043e\u043d \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u0435\u0442 \u043b\u0438\u0441\u0442\u0438\u043d\u0433\u0430\u043c\u0438 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 Kubernetes (\u0438 \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0440\u0430\u0437\u043e\u0431\u0440\u0430\u0442\u044c\u0441\u044f \u0432 \u0442\u0435\u043c\u0435 \u043d\u0430\u0441\u0442\u043e\u043b\u044c\u043a\u043e \u0433\u043b\u0443\u0431\u043e\u043a\u043e, \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u044d\u0442\u043e \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f. \u0412 \u043e\u0434\u043d\u0443 \u0438\u0437 \u043f\u044f\u0442\u043d\u0438\u0446 \u043a\u043e \u043c\u043d\u0435 \u043f\u043e\u0434\u043e\u0448\u0435\u043b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":29409,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-39187","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0430\u0432\u0442\u043e\u0440 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Erkan Erol, \u0438\u043d\u0436\u0435\u043d\u0435\u0440 \u0438\u0437 SAP \u2014 \u0434\u0435\u043b\u0438\u0442\u0441\u044f \u0441\u0432\u043e\u0438\u043c \u0438\u0437\u0443\u0447\u0435\u043d\u0438\u0435\u043c \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434\u044b kubectl exec, \u0441\u0442\u043e\u043b\u044c \u043f\u0440\u0438\u0432\u044b\u0447\u043d\u043e\u0439 \u0434\u043b\u044f \u0432\u0441\u0435\u0445, \u043a\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 Kubernetes.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-rabotaet-kubectl-exec\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec? | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0430\u0432\u0442\u043e\u0440 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Erkan Erol, \u0438\u043d\u0436\u0435\u043d\u0435\u0440 \u0438\u0437 SAP \u2014 \u0434\u0435\u043b\u0438\u0442\u0441\u044f \u0441\u0432\u043e\u0438\u043c \u0438\u0437\u0443\u0447\u0435\u043d\u0438\u0435\u043c \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434\u044b kubectl exec, \u0441\u0442\u043e\u043b\u044c \u043f\u0440\u0438\u0432\u044b\u0447\u043d\u043e\u0439 \u0434\u043b\u044f \u0432\u0441\u0435\u0445, \u043a\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 Kubernetes.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-rabotaet-kubectl-exec\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:28:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:28:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Si funksionon kubectl exec? | ProHoster","description":"Sh\u00ebnim. p\u00ebrk.: autori i artikullit \u2014 Erkan Erol, inxhinier n\u00eb SAP \u2014 ndan studimin e tij mbi mekanizmat e funksionimit t\u00eb komand\u00ebs kubectl exec, kaq t\u00eb njohur p\u00ebr t\u00eb gjith\u00eb ata q\u00eb punojn\u00eb me Kubernetes.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-rabotaet-kubectl-exec","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 kubectl exec? | ProHoster","og:description":"\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0430\u0432\u0442\u043e\u0440 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Erkan Erol, \u0438\u043d\u0436\u0435\u043d\u0435\u0440 \u0438\u0437 SAP \u2014 \u0434\u0435\u043b\u0438\u0442\u0441\u044f \u0441\u0432\u043e\u0438\u043c \u0438\u0437\u0443\u0447\u0435\u043d\u0438\u0435\u043c \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434\u044b kubectl exec, \u0441\u0442\u043e\u043b\u044c \u043f\u0440\u0438\u0432\u044b\u0447\u043d\u043e\u0439 \u0434\u043b\u044f \u0432\u0441\u0435\u0445, \u043a\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0441 Kubernetes.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-rabotaet-kubectl-exec","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:28:20+00:00","article:modified_time":"2019-10-31T19:28:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"39187","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 01:11:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 23:11:24","updated":"2026-01-24 01:11:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/39187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=39187"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/39187\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/29409"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=39187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=39187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=39187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}