kubectl-dba dc-dr pin-standby

Pin this data center as a standby (standby-hold): it never promotes

Synopsis

Creates the human-owned standby-hold ConfigMap -standby-hold in the coordination namespace of the CURRENT cluster, which must be the data center you are holding down.

While it exists that DC never contends for the scope’s primary-DC Lease, never promotes (it refuses even an explicit handoff naming it), and its coordinator refuses destructive cross-DC rewinds or re-seeds of the data it holds. It fails CLOSED: if the ConfigMap cannot be read the hold is assumed, so a flaky apiserver never silently drops the protection.

It is deliberately ignored on the data center that is currently ACTIVE, because demoting the active DC without a quiesce is unsafe; move the primary away with a planned switchover first.

KUBECONFIG: the SPOKE of the data center being held.

kubectl-dba dc-dr pin-standby (--scope LEASE | --db DB_NAME) [flags]

Examples

  # Never let dc-a take the primary role for this scope (run against dc-a)
  kubectl dba dc-dr pin-standby --scope primary-dc --yes --kubeconfig ~/.kube/dc-a.yaml
  
  # Release it
  kubectl dba dc-dr pin-standby --scope primary-dc --remove --yes --kubeconfig ~/.kube/dc-a.yaml

Options

      --coord-namespace string   Namespace on this spoke that holds the marker ConfigMaps (default "dc-failover")
      --db string                Resolve the scope from this database instead (requires the kubeconfig to reach the hub)
  -h, --help                     help for pin-standby
      --remove                   Remove the pin instead of creating it
      --scope string             Primary-DC Lease name of the scope (for example primary-dc or primary-dc-orders)
      --yes                      Confirm

Options inherited from parent commands

      --as string                             Username to impersonate for the operation. User could be a regular user or a service account in a namespace.
      --as-group stringArray                  Group to impersonate for the operation, this flag can be repeated to specify multiple groups.
      --as-uid string                         UID to impersonate for the operation.
      --cache-dir string                      Default cache directory (default "/home/runner/.kube/cache")
      --certificate-authority string          Path to a cert file for the certificate authority
      --client-certificate string             Path to a client certificate file for TLS
      --client-key string                     Path to a client key file for TLS
      --cluster string                        The name of the kubeconfig cluster to use
      --context string                        The name of the kubeconfig context to use
      --default-seccomp-profile-type string   Default seccomp profile
      --disable-compression                   If true, opt-out of response compression for all requests to the server
      --insecure-skip-tls-verify              If true, the server's certificate will not be checked for validity. This will make your HTTPS connections insecure
      --kubeconfig string                     Path to the kubeconfig file to use for CLI requests.
      --match-server-version                  Require server version to match client version
  -n, --namespace string                      If present, the namespace scope for this CLI request
      --password string                       Password for basic authentication to the API server
      --request-timeout string                The length of time to wait before giving up on a single server request. Non-zero values should contain a corresponding time unit (e.g. 1s, 2m, 3h). A value of zero means don't timeout requests. (default "0")
  -s, --server string                         The address and port of the Kubernetes API server
      --tls-server-name string                Server name to use for server certificate validation. If it is not provided, the hostname used to contact the server is used
      --token string                          Bearer token for authentication to the API server
      --user string                           The name of the kubeconfig user to use
      --username string                       Username for basic authentication to the API server

SEE ALSO

  • kubectl-dba dc-dr - Cross data center DR operations: switchover, failover, pins, and diagnosis