Merge pull request #4033 from chaosi-zju/helm

remove insecureSkipTLSVerify in helm chart
This commit is contained in:
karmada-bot 2023-09-11 21:40:52 +08:00 committed by GitHub
commit b37902378a
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 11 additions and 3 deletions

View File

@ -213,6 +213,15 @@ app: {{$name}}
{{- end }} {{- end }}
{{- end -}} {{- end -}}
{{- define "karmada.apiserver.caBundle" -}}
{{- if eq .Values.certs.mode "auto" }}
caBundle: {{ print "{{ ca_crt }}" }}
{{- end }}
{{- if eq .Values.certs.mode "custom" }}
caBundle: {{ b64enc .Values.certs.custom.caCrt }}
{{- end }}
{{- end -}}
{{- define "karmada.webhook.caBundle" -}} {{- define "karmada.webhook.caBundle" -}}
{{- if eq .Values.certs.mode "auto" }} {{- if eq .Values.certs.mode "auto" }}
caBundle: {{ print "{{ ca_crt }}" }} caBundle: {{ print "{{ ca_crt }}" }}

View File

@ -11,7 +11,7 @@ metadata:
app: {{ $name }}-aggregated-apiserver app: {{ $name }}-aggregated-apiserver
apiserver: "true" apiserver: "true"
spec: spec:
insecureSkipTLSVerify: true {{- include "karmada.apiserver.caBundle" . | nindent 2 }}
group: cluster.karmada.io group: cluster.karmada.io
groupPriorityMinimum: 2000 groupPriorityMinimum: 2000
service: service:
@ -39,7 +39,7 @@ metadata:
app: {{ $name }}-search app: {{ $name }}-search
apiserver: "true" apiserver: "true"
spec: spec:
insecureSkipTLSVerify: true {{- include "karmada.apiserver.caBundle" . | nindent 2 }}
group: search.karmada.io group: search.karmada.io
groupPriorityMinimum: 2000 groupPriorityMinimum: 2000
service: service:

View File

@ -212,7 +212,6 @@ data:
clusters: clusters:
- cluster: - cluster:
certificate-authority-data: {{ print "{{ ca_crt }}" }} certificate-authority-data: {{ print "{{ ca_crt }}" }}
insecure-skip-tls-verify: false
server: https://{{ $name }}-apiserver.{{ $namespace }}.svc.{{ .Values.clusterDomain }}:5443 server: https://{{ $name }}-apiserver.{{ $namespace }}.svc.{{ .Values.clusterDomain }}:5443
name: {{ $name }}-apiserver name: {{ $name }}-apiserver
users: users: