remove insecureSkipTLSVerify in helm chart

Signed-off-by: chaosi-zju <chaosi@zju.edu.cn>
This commit is contained in:
chaosi-zju 2023-09-05 21:44:49 +08:00
parent 7c96e0db54
commit 18f21a1677
3 changed files with 11 additions and 3 deletions

View File

@ -213,6 +213,15 @@ app: {{$name}}
{{- end }} {{- end }}
{{- end -}} {{- end -}}
{{- define "karmada.apiserver.caBundle" -}}
{{- if eq .Values.certs.mode "auto" }}
caBundle: {{ print "{{ ca_crt }}" }}
{{- end }}
{{- if eq .Values.certs.mode "custom" }}
caBundle: {{ b64enc .Values.certs.custom.caCrt }}
{{- end }}
{{- end -}}
{{- define "karmada.webhook.caBundle" -}} {{- define "karmada.webhook.caBundle" -}}
{{- if eq .Values.certs.mode "auto" }} {{- if eq .Values.certs.mode "auto" }}
caBundle: {{ print "{{ ca_crt }}" }} caBundle: {{ print "{{ ca_crt }}" }}

View File

@ -11,7 +11,7 @@ metadata:
app: {{ $name }}-aggregated-apiserver app: {{ $name }}-aggregated-apiserver
apiserver: "true" apiserver: "true"
spec: spec:
insecureSkipTLSVerify: true {{- include "karmada.apiserver.caBundle" . | nindent 2 }}
group: cluster.karmada.io group: cluster.karmada.io
groupPriorityMinimum: 2000 groupPriorityMinimum: 2000
service: service:
@ -39,7 +39,7 @@ metadata:
app: {{ $name }}-search app: {{ $name }}-search
apiserver: "true" apiserver: "true"
spec: spec:
insecureSkipTLSVerify: true {{- include "karmada.apiserver.caBundle" . | nindent 2 }}
group: search.karmada.io group: search.karmada.io
groupPriorityMinimum: 2000 groupPriorityMinimum: 2000
service: service:

View File

@ -212,7 +212,6 @@ data:
clusters: clusters:
- cluster: - cluster:
certificate-authority-data: {{ print "{{ ca_crt }}" }} certificate-authority-data: {{ print "{{ ca_crt }}" }}
insecure-skip-tls-verify: false
server: https://{{ $name }}-apiserver.{{ $namespace }}.svc.{{ .Values.clusterDomain }}:5443 server: https://{{ $name }}-apiserver.{{ $namespace }}.svc.{{ .Values.clusterDomain }}:5443
name: {{ $name }}-apiserver name: {{ $name }}-apiserver
users: users: