Merge pull request #4198 from zhzhuang-zju/tls1.3

set MinVersion to VersionTLS13 for tlsconfig
This commit is contained in:
karmada-bot 2023-11-16 16:48:48 +08:00 committed by GitHub
commit 98e655fc55
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
9 changed files with 10 additions and 0 deletions

View File

@ -46,6 +46,7 @@ spec:
- --feature-gates=APIPriorityAndFairness=false - --feature-gates=APIPriorityAndFairness=false
- --audit-log-maxage=0 - --audit-log-maxage=0
- --audit-log-maxbackup=0 - --audit-log-maxbackup=0
- --tls-min-version=VersionTLS13
resources: resources:
requests: requests:
cpu: 100m cpu: 100m

View File

@ -62,6 +62,7 @@ spec:
- --requestheader-username-headers=X-Remote-User - --requestheader-username-headers=X-Remote-User
- --tls-cert-file=/etc/karmada/pki/apiserver.crt - --tls-cert-file=/etc/karmada/pki/apiserver.crt
- --tls-private-key-file=/etc/karmada/pki/apiserver.key - --tls-private-key-file=/etc/karmada/pki/apiserver.key
- --tls-min-version=VersionTLS13
name: karmada-apiserver name: karmada-apiserver
image: registry.k8s.io/kube-apiserver:v1.25.4 image: registry.k8s.io/kube-apiserver:v1.25.4
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent

View File

@ -42,6 +42,7 @@ spec:
- --audit-log-path=- - --audit-log-path=-
- --audit-log-maxage=0 - --audit-log-maxage=0
- --audit-log-maxbackup=0 - --audit-log-maxbackup=0
- --tls-min-version=VersionTLS13
readinessProbe: readinessProbe:
httpGet: httpGet:
path: /readyz path: /readyz

View File

@ -46,6 +46,7 @@ spec:
- --feature-gates=APIPriorityAndFairness=false - --feature-gates=APIPriorityAndFairness=false
- --audit-log-maxage=0 - --audit-log-maxage=0
- --audit-log-maxbackup=0 - --audit-log-maxbackup=0
- --tls-min-version=VersionTLS13
livenessProbe: livenessProbe:
httpGet: httpGet:
path: /livez path: /livez

View File

@ -65,6 +65,7 @@ spec:
- --feature-gates=APIPriorityAndFairness=false - --feature-gates=APIPriorityAndFairness=false
- --audit-log-maxage=0 - --audit-log-maxage=0
- --audit-log-maxbackup=0 - --audit-log-maxbackup=0
- --tls-min-version=VersionTLS13
resources: resources:
{{- toYaml .Values.aggregatedApiServer.resources | nindent 12 }} {{- toYaml .Values.aggregatedApiServer.resources | nindent 12 }}
readinessProbe: readinessProbe:

View File

@ -73,6 +73,7 @@ spec:
- --tls-private-key-file=/etc/kubernetes/pki/karmada.key - --tls-private-key-file=/etc/kubernetes/pki/karmada.key
- --max-requests-inflight={{ .Values.apiServer.maxRequestsInflight }} - --max-requests-inflight={{ .Values.apiServer.maxRequestsInflight }}
- --max-mutating-requests-inflight={{ .Values.apiServer.maxMutatingRequestsInflight }} - --max-mutating-requests-inflight={{ .Values.apiServer.maxMutatingRequestsInflight }}
- --tls-min-version=VersionTLS13
ports: ports:
- name: http - name: http
containerPort: 5443 containerPort: 5443

View File

@ -78,6 +78,7 @@ spec:
- --feature-gates=APIPriorityAndFairness=false - --feature-gates=APIPriorityAndFairness=false
- --audit-log-maxage=0 - --audit-log-maxage=0
- --audit-log-maxbackup=0 - --audit-log-maxbackup=0
- --tls-min-version=VersionTLS13
livenessProbe: livenessProbe:
httpGet: httpGet:
path: /livez path: /livez

View File

@ -59,6 +59,7 @@ spec:
- --max-requests-inflight=1500 - --max-requests-inflight=1500
- --max-mutating-requests-inflight=500 - --max-mutating-requests-inflight=500
- --v=4 - --v=4
- --tls-min-version=VersionTLS13
livenessProbe: livenessProbe:
failureThreshold: 8 failureThreshold: 8
httpGet: httpGet:
@ -171,6 +172,7 @@ spec:
- --feature-gates=APIPriorityAndFairness=false - --feature-gates=APIPriorityAndFairness=false
- --audit-log-maxage=0 - --audit-log-maxage=0
- --audit-log-maxbackup=0 - --audit-log-maxbackup=0
- --tls-min-version=VersionTLS13
volumeMounts: volumeMounts:
- mountPath: /etc/karmada/kubeconfig - mountPath: /etc/karmada/kubeconfig
name: kubeconfig name: kubeconfig

View File

@ -40,6 +40,7 @@ spec:
- --audit-log-path=- - --audit-log-path=-
- --audit-log-maxage=0 - --audit-log-maxage=0
- --audit-log-maxbackup=0 - --audit-log-maxbackup=0
- --tls-min-version=VersionTLS13
volumeMounts: volumeMounts:
- name: kubeconfig - name: kubeconfig
subPath: kubeconfig subPath: kubeconfig