Purely 'cos I know I'll need this again: -
for i in `crictl pods | grep NotReady | awk '{print $1}'`; do crictl rmp $i; done
Geeking in technology since 1985, with IBM Development, focused upon Docker and Kubernetes on the IBM Z LinuxONE platform In the words of Dr Cathy Ryan, "If you don't write it down, it never happened". To paraphrase one of my clients, "Every day is a school day". I do, I learn, I share. The postings on this site are my own and don’t necessarily represent IBM’s positions, strategies or opinions. Remember, YMMV https://infosec.exchange/@davehay
Purely 'cos I know I'll need this again: -
for i in `crictl pods | grep NotReady | awk '{print $1}'`; do crictl rmp $i; done
Following on from my earlier post: -
Homebrew on macOS - Docker says "No" - well, kinda
I hit a related problem post the installation of Minikube etc.
When I tried to log into Docker Hub: -
docker login -u davidhay1969
I saw this: -
Password:
Error saving credentials: error storing credentials - err: exec: "docker-credential-desktop": executable file not found in $PATH, out: ``
This post: -
docker-credential-desktop not installed or not available in PATH
gave me the "solution" - it was another hangover from having Docker Desktop installed, namely this file: -
~/.docker/config.json
For whatever good reason, it was necessary to edit it, and replace credsStore with credStore.
Whilst helping out a friend, I was running through a process to get Docker running without Docker Desktop, as per this: -
Run Docker without Docker Desktop on macOS
which makes heavy use of Homebrew.
This has one install stuff such as hyperkit and minikube : -
brew install hyperkit
brew install minikube
which is nice.
However, I was seeing interesting results from Homebrew in general ...
As an example when I ran brew upgrade or brew install hyperkit I was seeing errors such as: -
Error: Permission denied @ apply2files - /usr/local/lib/docker/cli-plugins
and: -
==> Pouring kubernetes-cli--1.22.1.big_sur.bottle.tar.gz
Error: The `brew link` step did not complete successfully
The formula built, but is not symlinked into /usr/local
Could not symlink bin/kubectl
Target /usr/local/bin/kubectl
already exists. You may want to remove it:
rm '/usr/local/bin/kubectl'
This on macOS 11.6 on my good ole 2014 Mac mini ...
The solution was relatively simple ...
At some point in the past, I'd had Docker Desktop installed, which was obviously running as root via sudo etc.
Therefore, having removed Docker Desktop, I needed to clean up the permissions : -
sudo chown -R davidhay:admin /usr/local/lib
So I'm tinkering with a GitHub project and, having cloned it, was trying to build it using the Makefile: -
cd etcd-operator/
make
which fairly quickly tried/failed to pull in a submodule: -
Now I have hit this many times before ...
And there is a solution ....
But I couldn't quite remember it ...
Thankfully, Google had the answer, Google is my friend: -
The solution was to update my Git config: -
git config --global url."git@github.com:".insteadOf "https://github.com"
So I've started to make more use of cat and tee and the EOF symbol when creating documentation describing how one can create various different artefacts from, say, Bash on Linux and macOS.
Typically, I'm focusing upon configuration files e.g. files with .conf and .yaml but, a few days back, I wanted to create a Bash script.
Here's an example of what I'd do for a containerd.conf configuration file: -
Nice and simple, right ?
I then tried the same for a Bash script, here's a trivial example that munges a JSON document - me.json : -
called ./hello.sh created thusly: -
Having written: -
And there's more - munging base64 in JSON for etcd
I forgot to mention that base64 isn't the only way to write to / read from etcd ...
The encoding is required where we choose to use the gRPC route to etcd via its REST APIs : -
However, the etcdctl tool does NOT need to use base64 encoding.
Building upon my previous example, where I used the following command: -
jq -r '.[] |= @base64' dave.json > dave_encoded.json
to encode the key and value elements of a JSON document - dave.json - which looks like this: -
and produce an alternate version - dave_encoded.json - with the base64 encoded elements therein, and then fed etcd using that encoded document: -
curl -X POST --silent --cacert /root/ssl/ca-cert.pem --cert /root/ssl/client-cert.pem --key /root/ssl/client-key.pem https://localhost:2379/v3/kv/put -d @dave_encoded.json | jq
and then use the encoded key - MDEyMzQ1 - to query etcd and pull the data back out: -
curl -X POST --silent --cacert /root/ssl/ca-cert.pem --cert /root/ssl/client-cert.pem --key /root/ssl/client-key.pem https://localhost:2379/v3/kv/range -d '{"key":"MDEyMzQ1"}' | jq -r .kvs[].value | base64 -d | jq
Well, there is an alternate approach, using etcdctl which is further described here: -
So, given that I know the key ID of 012345 I can quite simply ask etcd to provide the value: -
etcdctl --endpoints=localhost:2379 --cacert="/root/ssl/ca-cert.pem" --cert="/root/ssl/client-cert.pem" --key="/root/ssl/client-key.pem" get 012345 | jq
which, I think you'll agree, is way simpler.
Bottom line, knowing that the gRPC APIs use base64 is crucial; knowing that etcdctl exists is also rather neat-o.
Following on from my earlier post: -
I dug into jq more, and found this: -
specifically this comment: -
dating back to 2018.
This led me to a neat-o mechanism to encode the key and value of my JSON document: -
cat dave.json
jq -r '.[] |= @base64' dave.json
I then used this to generate a new JSON document: -
jq -r '.[] |= @base64' dave.json > dave_encoded.json
which I then fed into etcd: -
curl -X POST --silent --cacert /root/ssl/ca-cert.pem --cert /root/ssl/client-cert.pem --key /root/ssl/client-key.pem https://localhost:2379/v3/kv/put -d @dave_encoded.json | jq
and then confirmed that I could pull the data back out: -
curl -X POST --silent --cacert /root/ssl/ca-cert.pem --cert /root/ssl/client-cert.pem --key /root/ssl/client-key.pem https://localhost:2379/v3/kv/range -d '{"key":"MDEyMzQ1"}' | jq -r .kvs[].value | base64 -d | jq
{
which is nice
See, I told you I'd find a way .....
Whilst trying to hit my NAS from Firefox on my Mac, I kept seeing errors such as:- Unable to connect Firefox can’t establish a connection t...