Commit Graph

4602 Commits

Author SHA1 Message Date
Ole Markus With 22687c48c2 Bump tests to supported k8s version 2022-09-17 20:17:15 +02:00
Ole Markus With 16c60a1a0c Change mock region/subnet names to match mockCloud 2022-09-17 13:14:30 +02:00
justinsb 4b2f773748 rolling-update: don't deregister our only apiserver
If we do, we can't drain the node afterwards.  We also are going to
have dropped connections in this case anyway.
2022-09-15 09:16:57 -04:00
Kubernetes Prow Robot f8148d7cb0
Merge pull request #14251 from olemarkus/warmpool-asg-scaled-to-zero
Warm pool-enabled ASGs scaled to zero will no longer panic
2022-09-12 21:29:04 -07:00
Kubernetes Prow Robot 34e086ff4a
Merge pull request #14260 from olemarkus/deverbose
Bump verbosity level for some log statements
2022-09-11 07:57:23 -07:00
Ole Markus With 33fa4de890 Bump verbosity level for some log statements 2022-09-11 16:15:28 +02:00
Kubernetes Prow Robot d705765426
Merge pull request #14253 from olemarkus/missing-legacy-ccm-permissions
Add back missing permissions for legacy CCM. Again.
2022-09-10 23:55:24 -07:00
John Gardiner Myers 34e32a41c8 AWS LBC needs ec2:DescribeVpcPeeringConnections for IPv6 2022-09-10 14:55:27 -07:00
Ole Markus With f226b03abf Add back missing permissions for legacy CCM. Again. 2022-09-10 19:54:49 +02:00
Ole Markus With 36bd9e6ff1 kOps managed OIDC provider is no longer needed for IRSA
It's assumed users will manage the OIDC provider themselves in that case
2022-09-09 21:12:53 +02:00
Ole Markus With 1ea5243406 Warm pool-enabled ASGs scaled to zero will no longer panic 2022-09-09 11:08:00 +02:00
Kubernetes Prow Robot 3980383aa1
Merge pull request #13853 from akkina2107/Truncate-cluster-name
Fix openstack tag limitation
2022-09-06 12:56:23 -07:00
Daniel Franca cdd0013b1f
Add support to --cordon-node-before-terminating on the cluster autoscaler addon (CordonNodeBeforeTerminating) 2022-09-06 17:03:24 +02:00
Kubernetes Prow Robot d4b72f394a
Merge pull request #14229 from olemarkus/cert-manager-hostedzones
Allow cert-manager the privileges needed to resolve dns-01 challenges
2022-09-06 00:24:56 -07:00
Kubernetes Prow Robot 159bc6a484
Merge pull request #14235 from olemarkus/bump-cas-125
Bump cluster-autoscaler images
2022-09-05 23:12:54 -07:00
Ole Markus With 5604fe1ad8 Bump cluster-autoscaler images 2022-09-05 21:35:24 +02:00
justinsb 039ca01cc9 applylib: Better health checking
Add a few objects that are well-known as not having status, so that we
avoid/reduce logspam.
2022-09-05 13:59:18 -04:00
Ole Markus With 6548ca6ca7 Don't add add IAM vars to manifest if service account is not being created
In the case IRSA is optional for an addon, we shouldn't unconditinally add the IRSA bits to the manifest.
This is also a clean up. We no longer need to expand the list of well-known SAs as we already know which roles are being built
2022-09-04 08:28:32 +02:00
Ole Markus With 3518182e44 Add support for cert-manager dns-01 challenges 2022-09-04 08:19:22 +02:00
Kubernetes Prow Robot 9faeb5b8a9
Merge pull request #14203 from olemarkus/dcgm
Add support for installing dcgm exporter
2022-09-02 09:22:05 -07:00
justinsb 90a484f049 AWS IAM Role listing: don't ignore "other" errors
If the error was an AWS error, but not one of the recognized ones, we
ignored it.
2022-09-01 07:57:03 -04:00
Ciprian Hacman 8b83dedf24
Release 1.25.0-beta.1 (#14210) 2022-08-31 03:43:00 -07:00
Kubernetes Prow Robot f4144b434e
Merge pull request #14207 from olemarkus/ccm-v125
Bumping AWS CCM to 1.25
2022-08-31 02:57:00 -07:00
Ole Markus With 24a5046cee Bumping AWS CCM to 1.25 2022-08-31 10:02:46 +02:00
Ciprian Hacman cf5e48c912 Run hack/update-expected.sh 2022-08-31 09:21:40 +03:00
Ciprian Hacman 6dbe334494 Update etcd-manager to v3.0.20220831 2022-08-31 09:16:15 +03:00
Ciprian Hacman 9fa7cf6741 Show the reason for which an AWS image is invalid 2022-08-31 08:26:23 +03:00
Ole Markus With 98cd242673 Add support for installing dcgm exporter 2022-08-30 14:54:13 +02:00
Kubernetes Prow Robot 5710b1ef2e
Merge pull request #14181 from hakman/hetzner_etcd-manager_ig
Run etcd-manager with instance group name as volume name tag for Hetzner
2022-08-30 05:19:02 -07:00
Nagaraju Akkina bb934447fd Fix openstack tag limitation
Openstack is not allowing object tag size of more than 60 characters, as
we can not rename a cluster we have to truncate and limit length to 42
for the tag value.
2022-08-30 10:03:30 +02:00
Kubernetes Prow Robot 4901e9f685
Merge pull request #14175 from seh/tolerate-extra-service-account-keyset-items
OIDC: Tolerate extra service-account key set items
2022-08-26 03:24:25 -07:00
Kubernetes Prow Robot cddf2af026
Merge pull request #14187 from olemarkus/bump-nldc-125
Bump node local dns cache to 1.22.8
2022-08-26 01:00:25 -07:00
Ciprian Hacman 0aedf0bbef Update runc to v1.1.4 2022-08-26 03:31:16 +03:00
Ole Markus With 1a8236290d Bump node local dns cache to 1.22.8 2022-08-25 19:03:14 +02:00
Ole Markus With 79a56643be Bump nvidia driver to 515 2022-08-25 17:17:44 +02:00
Ciprian Hacman 13f768f50b Run etcd-manager with instance group name as volume name tag for Hetzner 2022-08-25 12:43:14 +03:00
Kubernetes Prow Robot e23b852aa7
Merge pull request #14114 from olemarkus/merge-kubelet-earlier
Merge kubeletConfigs earlier
2022-08-25 00:36:08 -07:00
Kubernetes Prow Robot fa377131b2
Merge pull request #14177 from olemarkus/bump-nth-125
Bump node termination handler to 1.17.0
2022-08-24 19:12:05 -07:00
Ole Markus With 0cd110d723 Bump node termination handler to 1.17.1 2022-08-24 21:52:52 +02:00
Kubernetes Prow Robot 32e2ac55f1
Merge pull request #14164 from torredil/external-csi-driver
Allow self-managed aws-ebs-csi-driver
2022-08-24 12:21:49 -07:00
torredil 230ff7eb57 Allow self-managed aws-ebs-csi-driver
Signed-off-by: torredil <torredil@amazon.com>
2022-08-24 18:40:27 +00:00
Steven E. Harris 17e9c6eca2
OIDC: Tolerate extra service-account key set items
When reading the kOps "service-account" key set in preparation for
publishing the OIDC JWKS file (such as to S3 alongside the discovery
document), in some cases the set contains items that either lack an
X.509 certificate or contain such a certificate issued for a subject
with common name other than "service-account." Ignore these extra key
set items and instead only project JWKS keys for those with an X.509
certificate with the expected subject common name.
2022-08-24 10:07:20 -04:00
Kubernetes Prow Robot 939a62e424
Merge pull request #14173 from olemarkus/karpenter-16
Bump karpenter to 0.16
2022-08-24 06:22:03 -07:00
Ole Markus With 7ab7cfda69 Don't explicitly set karpenter provisioner label
It's past on as other labels through the CAS cloud labels
2022-08-24 12:39:52 +02:00
Peter Rifel f79a126bd2
Add service account tags to IAM Roles 2022-08-23 19:13:51 -05:00
Ole Markus With eb003a19b1 Fix bugs and typo in iam resource deletion logic 2022-08-21 20:01:20 +02:00
Ole Markus With 084ecac2bb Fix no such entity check for iam profiles and roles 2022-08-21 07:29:30 +02:00
Kubernetes Prow Robot 87de208fcd
Merge pull request #14153 from olemarkus/ignore-404-deletion
Ignore entities not found when deleting IAM roles and profiles
2022-08-20 10:45:35 -07:00
Ole Markus With 578e27bb5f Ignore entities not found when deleting IAM roles and profiles 2022-08-20 18:58:04 +02:00
Kubernetes Prow Robot 3d84f3ca87
Merge pull request #14030 from justinsb/applylib
Introduce library for applying objects
2022-08-20 07:21:35 -07:00