Merge pull request #4198 from zhzhuang-zju/tls1.3
set MinVersion to VersionTLS13 for tlsconfig
This commit is contained in:
commit
98e655fc55
|
@ -46,6 +46,7 @@ spec:
|
||||||
- --feature-gates=APIPriorityAndFairness=false
|
- --feature-gates=APIPriorityAndFairness=false
|
||||||
- --audit-log-maxage=0
|
- --audit-log-maxage=0
|
||||||
- --audit-log-maxbackup=0
|
- --audit-log-maxbackup=0
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 100m
|
cpu: 100m
|
||||||
|
|
|
@ -62,6 +62,7 @@ spec:
|
||||||
- --requestheader-username-headers=X-Remote-User
|
- --requestheader-username-headers=X-Remote-User
|
||||||
- --tls-cert-file=/etc/karmada/pki/apiserver.crt
|
- --tls-cert-file=/etc/karmada/pki/apiserver.crt
|
||||||
- --tls-private-key-file=/etc/karmada/pki/apiserver.key
|
- --tls-private-key-file=/etc/karmada/pki/apiserver.key
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
name: karmada-apiserver
|
name: karmada-apiserver
|
||||||
image: registry.k8s.io/kube-apiserver:v1.25.4
|
image: registry.k8s.io/kube-apiserver:v1.25.4
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
|
|
|
@ -42,6 +42,7 @@ spec:
|
||||||
- --audit-log-path=-
|
- --audit-log-path=-
|
||||||
- --audit-log-maxage=0
|
- --audit-log-maxage=0
|
||||||
- --audit-log-maxbackup=0
|
- --audit-log-maxbackup=0
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
path: /readyz
|
path: /readyz
|
||||||
|
|
|
@ -46,6 +46,7 @@ spec:
|
||||||
- --feature-gates=APIPriorityAndFairness=false
|
- --feature-gates=APIPriorityAndFairness=false
|
||||||
- --audit-log-maxage=0
|
- --audit-log-maxage=0
|
||||||
- --audit-log-maxbackup=0
|
- --audit-log-maxbackup=0
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
livenessProbe:
|
livenessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
path: /livez
|
path: /livez
|
||||||
|
|
|
@ -65,6 +65,7 @@ spec:
|
||||||
- --feature-gates=APIPriorityAndFairness=false
|
- --feature-gates=APIPriorityAndFairness=false
|
||||||
- --audit-log-maxage=0
|
- --audit-log-maxage=0
|
||||||
- --audit-log-maxbackup=0
|
- --audit-log-maxbackup=0
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.aggregatedApiServer.resources | nindent 12 }}
|
{{- toYaml .Values.aggregatedApiServer.resources | nindent 12 }}
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
|
|
|
@ -73,6 +73,7 @@ spec:
|
||||||
- --tls-private-key-file=/etc/kubernetes/pki/karmada.key
|
- --tls-private-key-file=/etc/kubernetes/pki/karmada.key
|
||||||
- --max-requests-inflight={{ .Values.apiServer.maxRequestsInflight }}
|
- --max-requests-inflight={{ .Values.apiServer.maxRequestsInflight }}
|
||||||
- --max-mutating-requests-inflight={{ .Values.apiServer.maxMutatingRequestsInflight }}
|
- --max-mutating-requests-inflight={{ .Values.apiServer.maxMutatingRequestsInflight }}
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
ports:
|
ports:
|
||||||
- name: http
|
- name: http
|
||||||
containerPort: 5443
|
containerPort: 5443
|
||||||
|
|
|
@ -78,6 +78,7 @@ spec:
|
||||||
- --feature-gates=APIPriorityAndFairness=false
|
- --feature-gates=APIPriorityAndFairness=false
|
||||||
- --audit-log-maxage=0
|
- --audit-log-maxage=0
|
||||||
- --audit-log-maxbackup=0
|
- --audit-log-maxbackup=0
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
livenessProbe:
|
livenessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
path: /livez
|
path: /livez
|
||||||
|
|
|
@ -59,6 +59,7 @@ spec:
|
||||||
- --max-requests-inflight=1500
|
- --max-requests-inflight=1500
|
||||||
- --max-mutating-requests-inflight=500
|
- --max-mutating-requests-inflight=500
|
||||||
- --v=4
|
- --v=4
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
livenessProbe:
|
livenessProbe:
|
||||||
failureThreshold: 8
|
failureThreshold: 8
|
||||||
httpGet:
|
httpGet:
|
||||||
|
@ -171,6 +172,7 @@ spec:
|
||||||
- --feature-gates=APIPriorityAndFairness=false
|
- --feature-gates=APIPriorityAndFairness=false
|
||||||
- --audit-log-maxage=0
|
- --audit-log-maxage=0
|
||||||
- --audit-log-maxbackup=0
|
- --audit-log-maxbackup=0
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- mountPath: /etc/karmada/kubeconfig
|
- mountPath: /etc/karmada/kubeconfig
|
||||||
name: kubeconfig
|
name: kubeconfig
|
||||||
|
|
|
@ -40,6 +40,7 @@ spec:
|
||||||
- --audit-log-path=-
|
- --audit-log-path=-
|
||||||
- --audit-log-maxage=0
|
- --audit-log-maxage=0
|
||||||
- --audit-log-maxbackup=0
|
- --audit-log-maxbackup=0
|
||||||
|
- --tls-min-version=VersionTLS13
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: kubeconfig
|
- name: kubeconfig
|
||||||
subPath: kubeconfig
|
subPath: kubeconfig
|
||||||
|
|
Loading…
Reference in New Issue