mirror of https://github.com/kubernetes/kops.git
Enable wireguard in calico-node if it is enabled
This commit is contained in:
parent
4e4c4a1e16
commit
7ad4815fc9
|
|
@ -13100,6 +13100,9 @@ spec:
|
||||||
# Enable / Disable source/destination checks in AWS
|
# Enable / Disable source/destination checks in AWS
|
||||||
- name: FELIX_AWSSRCDSTCHECK
|
- name: FELIX_AWSSRCDSTCHECK
|
||||||
value: "{{- if and (eq .CloudProvider "aws") (.Networking.Calico.CrossSubnet) -}}Disable{{- else -}} {{- or .Networking.Calico.AwsSrcDstCheck "DoNothing" -}} {{- end -}}"
|
value: "{{- if and (eq .CloudProvider "aws") (.Networking.Calico.CrossSubnet) -}}Disable{{- else -}} {{- or .Networking.Calico.AwsSrcDstCheck "DoNothing" -}} {{- end -}}"
|
||||||
|
# Enable WireGuard encryption for all on-the-wire pod-to-pod traffic
|
||||||
|
- name: FELIX_WIREGUARDENABLED
|
||||||
|
value: "{{ .Networking.Calico.WireguardEnabled }}"
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
resources:
|
resources:
|
||||||
|
|
|
||||||
|
|
@ -3937,6 +3937,9 @@ spec:
|
||||||
# Enable / Disable source/destination checks in AWS
|
# Enable / Disable source/destination checks in AWS
|
||||||
- name: FELIX_AWSSRCDSTCHECK
|
- name: FELIX_AWSSRCDSTCHECK
|
||||||
value: "{{- if and (eq .CloudProvider "aws") (.Networking.Calico.CrossSubnet) -}}Disable{{- else -}} {{- or .Networking.Calico.AwsSrcDstCheck "DoNothing" -}} {{- end -}}"
|
value: "{{- if and (eq .CloudProvider "aws") (.Networking.Calico.CrossSubnet) -}}Disable{{- else -}} {{- or .Networking.Calico.AwsSrcDstCheck "DoNothing" -}} {{- end -}}"
|
||||||
|
# Enable WireGuard encryption for all on-the-wire pod-to-pod traffic
|
||||||
|
- name: FELIX_WIREGUARDENABLED
|
||||||
|
value: "{{ .Networking.Calico.WireguardEnabled }}"
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
resources:
|
resources:
|
||||||
|
|
|
||||||
|
|
@ -858,7 +858,7 @@ func (b *BootstrapChannelBuilder) buildAddons(c *fi.ModelBuilderContext) (*chann
|
||||||
"k8s-1.7": "2.6.12-kops.1",
|
"k8s-1.7": "2.6.12-kops.1",
|
||||||
"k8s-1.7-v3": "3.8.0-kops.2",
|
"k8s-1.7-v3": "3.8.0-kops.2",
|
||||||
"k8s-1.12": "3.9.6-kops.1",
|
"k8s-1.12": "3.9.6-kops.1",
|
||||||
"k8s-1.16": "3.16.3-kops.1",
|
"k8s-1.16": "3.16.3-kops.2",
|
||||||
}
|
}
|
||||||
|
|
||||||
{
|
{
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue