John Gardiner Myers
1001f1fbd7
Upgrade amazonvpc to v0.10.1
2021-11-15 18:54:24 -08:00
John Gardiner Myers
8c8455b8f4
Upgrade external-dns to 0.10.1 for Kubernetes >= 1.19
2021-11-13 23:02:10 -08:00
zhengtianbao
55c3120ff6
Fix render template cilium AgentPrometheusPort into a UNICODE char
2021-11-12 14:45:45 +08:00
Kubernetes Prow Robot
7fe3d21c24
Merge pull request #12716 from rifelpet/authenticator-crdv1
...
Add missing status fields to IAMIdentityMapping v1 CRD
2021-11-11 20:42:29 -08:00
Kubernetes Prow Robot
4c4d616948
Merge pull request #12713 from estahn/patch-1
...
set calico-node readiness/liveness timeout to 10s
2021-11-11 19:36:28 -08:00
Kubernetes Prow Robot
88ffb9fd8f
Merge pull request #12682 from zhengtianbao/ipforwarding
...
[calico] Add support for allow_ip_forwarding field
2021-11-11 18:54:28 -08:00
Peter Rifel
b401ec55a3
Add missing status fields to IAMIdentityMapping v1 CRD
2021-11-11 20:28:59 -06:00
Enrico Stahn
afa7f5ba44
set calico-node readiness/liveness timeout to 10s
...
Provide calico-node with more time to come up.
2021-11-12 10:34:40 +11:00
liranp
5cd11ba326
feat(spot/addon): bump spotinst/ocean-controller to v1.0.79
2021-11-10 12:48:17 +02:00
zhengtianbao
976e3c1f13
Add option to set allow_ip_forwarding for the calico network
2021-11-04 14:26:27 +08:00
John Gardiner Myers
3a97dbaa8d
Release 1.23.0-alpha.2
2021-10-31 13:46:07 -07:00
Ciprian Hacman
b6565d86a2
Apply suggestions from code review
2021-10-30 20:57:40 +03:00
Ciprian Hacman
76898881cb
Use prefixes for IPv6 with Calico
2021-10-30 20:57:40 +03:00
Kubernetes Prow Robot
5bfdefb43c
Merge pull request #12623 from johngmyers/cilium-ipv6-ipam
...
Never masquerade IPv6 with Cilium
2021-10-29 05:56:51 -07:00
Kubernetes Prow Robot
59a637e6de
Merge pull request #12538 from hierynomus/issue-12205
...
Configure aws-iam-authenticator using identityMappings defined in cluster.yaml
2021-10-29 03:10:51 -07:00
Jeroen van Erp
353be50f9b
Configure aws-iam-authenticator using identityMappings defined in cluster.yaml
...
Signed-off-by: Jeroen van Erp <jeroen@hierynomus.com>
2021-10-29 10:30:44 +02:00
Ole Markus With
ac3c22b431
Use InternalIP as preferred kubelet address only in ivp6 mode
...
As metrics-server rolls before the worker nodes, and worker nodes do not yet have IP SANs, upgrade breaks if InternalIP is used.
IPv6 never worked with hostnames, so there is no BC break there.
2021-10-28 16:06:40 +02:00
John Gardiner Myers
7cb4fbe91e
Never masquerade IPv6 with Cilium
2021-10-27 23:40:02 -07:00
John Gardiner Myers
fdc128fda4
Remove vestigial Cilium ContainerRuntimeLabels code
2021-10-26 16:10:21 -07:00
Ciprian Hacman
35c3dfcbc5
Update handling of bool values for Canal
2021-10-24 12:25:42 +03:00
Ciprian Hacman
77772b6441
Move FELIX_LOGSEVERITYSCREEN to custom section for Canal
2021-10-24 12:25:42 +03:00
Ciprian Hacman
6b09f8de1e
Update typha_service_name comment for Canal
2021-10-24 12:25:42 +03:00
Ciprian Hacman
79a65f116a
Update calico/typha version for Canal
2021-10-24 12:25:42 +03:00
Ciprian Hacman
e350227c11
Enable MTU auto-detection for Canal
2021-10-24 12:25:42 +03:00
Ciprian Hacman
f2d5af57da
Add calico-kube-controllers for Canal
2021-10-24 08:49:35 +03:00
Peter Rifel
04f401fbb9
Add canal 3.20 with k8s 1.22 support
2021-10-23 18:01:44 -06:00
Kubernetes Prow Robot
f8ba8b11f7
Merge pull request #12437 from olemarkus/cas-delay
...
Make it possible to set CAS max-node-provision-time
2021-10-22 09:34:38 -07:00
Peter Rifel
477d930348
Upgrade AWS VPC CNI to 1.9.3 w/ k8s 1.22 support
2021-10-20 22:29:54 -07:00
Ole Markus With
11e68308d1
Disable CNP status updates by default
2021-10-20 14:01:48 +02:00
Ole Markus With
258fd4f9d9
Make it possible to set CAS max-node-provision-time
2021-10-20 13:53:37 +02:00
Kubernetes Prow Robot
f8a8c015ef
Merge pull request #12524 from dntosas/cilium-bpf-lb-sock-hostns-only
...
[cilium] Add support for bpf-lb-sock-hostns-only field
2021-10-19 03:56:38 -07:00
dntosas
7296597a17
[cilium] Add support for bpf-lb-sock-hostns-only field
...
This is a needed configuration option for users that want to combine
Cilium alongside with a ServiceMesh. Cilium by default will LB requests
at CNI layer meaning that the Sidecars of ServiceMesh Proxy are not able
to apply LB by themselves thus loosing the capability of applying their
features for traffic management.
Ref issue: https://github.com/istio/istio/issues/35531
Signed-off-by: dntosas <ntosas@gmail.com>
2021-10-12 08:33:57 +03:00
liranp
e84f35277f
feat(spot/addon): update clusterrole
2021-10-11 19:59:03 +03:00
Ciprian Hacman
d215a12103
Update coredns to v1.8.5
2021-10-11 10:00:59 +03:00
Kubernetes Prow Robot
a0099edb57
Merge pull request #12491 from hakman/calico-v3.20.2
...
Update Calico to v3.20.2
2021-10-05 20:42:33 -07:00
Ciprian Hacman
036c450093
Update Calico to v3.20.2
2021-10-06 05:39:26 +03:00
Kubernetes Prow Robot
c0efde15ac
Merge pull request #12414 from sterchelen/feature/cilium_annotations
...
Add Cilium agent pod annotations support to improve personalization
2021-10-05 01:13:09 -07:00
Nicolas Sterchele
103a98d060
Add Cilium agent pod annotations support to improve personalization
...
Annotations is pretty useful when you need third-party tool to add additional behavior
for a k8s resource.
Lots of auto-discovery tools are based on this annotations.
2021-10-04 15:49:51 +02:00
liranp
2585dd6784
feat(spot/addon): bump spotinst/ocean-controller to v1.0.78
2021-10-04 10:28:04 +03:00
Moshe Shitrit
dc08f5d996
Bump aws-cni to version 1.9.1
2021-10-01 00:47:43 -04:00
Kubernetes Prow Robot
2006cc1b77
Merge pull request #12425 from rifelpet/awsiam-v1
...
Fix AWS IAM Authenticator support for k8s 1.22
2021-09-29 12:23:21 -07:00
Kubernetes Prow Robot
8f91247b59
Merge pull request #12234 from hierynomus/coredns-affinity-tolerations
...
Add ability to provide custom CoreDNS tolerations and affinity
2021-09-28 15:10:34 -07:00
Jeroen van Erp
c30ec8e310
Add ability to provide custom CoreDNS Tolerations and Affinity
...
Signed-off-by: Jeroen van Erp <jeroen@hierynomus.com>
2021-09-28 17:05:48 +02:00
Kubernetes Prow Robot
b9d5e37e1f
Merge pull request #12431 from olemarkus/cilium-al2
...
Mount cgroupv2 for cilium at a custom location
2021-09-28 07:14:43 -07:00
Peter Rifel
1c25193dc7
Upgrade aws-iam-authenticator to 0.5.3
2021-09-28 08:29:39 -05:00
Peter Rifel
bb46e73ade
aws-iam-authenticator - use v1 CRD API for k8s 1.22 support
2021-09-28 08:29:39 -05:00
Ole Markus With
39178703c8
Mount cgroupv2 for cilium at a custom location
2021-09-27 19:29:36 +02:00
Peter Rifel
42ecabae28
Allow aws-iam-authenticator to be scheduled onto dedicated apiserver nodes
2021-09-26 11:09:30 -05:00
Kubernetes Prow Robot
ef22270b3f
Merge pull request #12394 from ReillyBrogan/reilly/ciliumBidirectionalMount
...
Add bidirectional BPF mount for Cilium >= 1.9.10 or >= 1.10.4
2021-09-25 09:42:21 -07:00
Anthony Hausman
5e814f465d
Add support to configure Cilium CNI chaining
...
CNI chaining allows to use Cilium in combination with other CNI plugins.
With Cilium CNI chaining, the base network connectivity and IP address management is managed by the non-Cilium CNI plugin, but Cilium attaches eBPF programs to the network devices created by the non-Cilium plugin to provide L3/L4 network visibility, policy enforcement and other advanced features.
https://docs.cilium.io/en/v1.9/gettingstarted/cni-chaining/#cni-chaining
In our case, to be able to use the `HostPort` feature in our cluster, we need to enable the `portmap` plugin.
2021-09-24 10:39:22 +02:00