Jesse Haka
3b9c893bae
add permission to create sa tokens
2021-05-03 16:01:57 +03:00
Kubernetes Prow Robot
b054fb37b7
Merge pull request #11016 from olemarkus/irsa-custom
...
user-configurable IAM roles for ServiceAccounts
2021-05-02 11:16:01 -07:00
Kubernetes Prow Robot
fdce6638dd
Merge pull request #11369 from hakman/needupdate_after_etcd-manager_changes
...
Mark control-plane node for update when etcd manager config changes
2021-05-02 09:54:01 -07:00
Ole Markus With
6199174d78
Apply suggestions from code review
...
Co-authored-by: John Gardiner Myers <jgmyers@proofpoint.com>
2021-05-02 07:56:57 +02:00
Ciprian Hacman
689b76d0ff
Mark control-plane node for update when etcd manager config changes
2021-05-02 08:50:42 +03:00
Ciprian Hacman
62c47d23d4
Add integration test for etcd
2021-05-02 08:48:46 +03:00
Ole Markus With
6f8b3647cf
Add support for IRSA in he api
...
Apply suggestions from code review
Co-authored-by: John Gardiner Myers <jgmyers@proofpoint.com>
2021-05-01 16:03:42 +02:00
Kubernetes Prow Robot
03786fc5ec
Merge pull request #11365 from hakman/needupdate_after_etcd_vol_resize
...
Mark control-plane node for update when etcd volume size changes
2021-05-01 05:13:59 -07:00
Ciprian Hacman
d64cfba365
Mark control-plane node for update when etcd volume size changes
...
etcd-manager expands the data volume on restart to the max available.
2021-05-01 12:06:22 +03:00
Kubernetes Prow Robot
3704ffd2c9
Merge pull request #11354 from codablock/external-cert-manager
...
Allow cert-manager to be provisioned externally
2021-04-30 13:45:59 -07:00
Kubernetes Prow Robot
a304dc4323
Merge pull request #11362 from olemarkus/oidc-location
...
Use VFS as service account issuer if configured
2021-04-30 12:43:58 -07:00
Ole Markus With
5ca7c9b5d7
Use VFS as service account issuer if configured
...
Also add an integration test that uses VFS
2021-04-30 21:02:30 +02:00
Kubernetes Prow Robot
1da39a3fe1
Merge pull request #11361 from olemarkus/oidc-awsidcprovider
...
Configure aws oidc provider
2021-04-30 11:41:59 -07:00
Alexander Block
d1ab0af511
Allow cert-manager to be provisioned externally
2021-04-30 20:33:59 +02:00
Kubernetes Prow Robot
d8de9fcad6
Merge pull request #11314 from olemarkus/cilium-fix-hubble
...
Expose hubble agent when hubble is enabled
2021-04-30 10:59:59 -07:00
Ole Markus With
75933682ed
Rename serviceaccountissuerdiscovery struct
2021-04-30 19:19:06 +02:00
Ole Markus With
460586833b
Add toggle for AWS OIDC provider. Free it from any feature flag
2021-04-30 19:19:06 +02:00
Ole Markus With
25b5f0cfb2
Move publicDataStore to serviceAccountIssuerDiscovery.discoveryStore
2021-04-30 19:19:06 +02:00
Kubernetes Prow Robot
e9747269de
Merge pull request #11359 from olemarkus/oidc-split-builder
...
Split oidc_provider
2021-04-30 09:55:58 -07:00
Ole Markus With
0f545f8659
Split oidc_provider
...
* one builder concerned with publishing issuer discovery metadata
* one builder concerned with creating aws oidc provider
2021-04-30 18:05:20 +02:00
Ole Markus With
7c0be997e1
Expose hubble agent when hubble is enabled
...
Also enables PKI for the addon
2021-04-30 17:52:19 +02:00
Kubernetes Prow Robot
7a63ed8f5c
Merge pull request #11360 from dntosas/nth-resources
...
[addons/nth] Add capability to define resources
2021-04-30 07:53:58 -07:00
Kubernetes Prow Robot
6e8e8e8456
Merge pull request #11358 from hakman/refactor-awsmodel
...
Move firewall, iam, network and sshkey to awsmodel
2021-04-30 07:09:58 -07:00
Kubernetes Prow Robot
6d23e31c8c
Merge pull request #11349 from rajatjindal/ignore-detached-validate-cluster
...
Ignore detached nodes when doing validate cluster
2021-04-30 05:43:58 -07:00
Ciprian Hacman
4a0fa78b20
Run hack/update-bazel.sh
2021-04-30 14:50:46 +03:00
Ciprian Hacman
0e651dd8fc
Use AWSModelContext in remaining awsmodel files
2021-04-30 14:50:46 +03:00
Ciprian Hacman
137fe6c2bb
Move firewall to awsmodel
2021-04-30 14:50:46 +03:00
dntosas
7e20f87822
[addons/nth] Add capability to define resources
...
Node termination handler as all daemonSets may play a critical role in
capacity planning, define resource policy for chosing instanceType etc.
In this commit, we enable users to define resources themselves to meet
their needs and also removed limits to convey with the chosen strategy
to avoid limits on such components.
Signed-off-by: dntosas <ntosas@gmail.com>
2021-04-30 14:13:11 +03:00
Kubernetes Prow Robot
b386dbcb16
Merge pull request #11357 from zetaab/updatedeppps
...
Update deps
2021-04-30 02:55:58 -07:00
Ciprian Hacman
fcba0043d0
Move iam to awsmodel
2021-04-30 12:37:28 +03:00
Ciprian Hacman
4dfe58de7a
Move network to awsmodel
2021-04-30 12:04:06 +03:00
Ciprian Hacman
ca02c04793
Move sshkey to awsmodel
2021-04-30 12:04:06 +03:00
Jesse Haka
960a52d6b2
Update deps
2021-04-30 11:39:01 +03:00
Ciprian Hacman
c49b71feb5
Use same method receiver names everywhere
2021-04-30 11:31:14 +03:00
Ciprian Hacman
bd7176f45f
Replace convenience functions with fi.* alternatives
2021-04-30 11:26:48 +03:00
Kubernetes Prow Robot
8f0aa33131
Merge pull request #11352 from hakman/mount-run-etcd
...
Mount /run inside etcd-manager pods for systemd mounts
2021-04-29 02:04:50 -07:00
Ciprian Hacman
75047c6513
Mount /run inside etcd-manager pods for systemd mounts
2021-04-29 10:15:58 +03:00
Kubernetes Prow Robot
2de1342abf
Merge pull request #11351 from rifelpet/kubetest2
...
Fix kubetest2 panic inheriting env vars
2021-04-28 20:46:50 -07:00
Peter Rifel
6afaaa3161
Fix kubetest2 panic inheriting env vars
...
Fixes `panic: runtime error: slice bounds out of range [:-1]` found here: https://prow.k8s.io/view/gs/kubernetes-jenkins/logs/e2e-kops-grid-scenario-aws-cloud-controller-manager/1387534126441041920
Also fixes a logging statement to include the cluster name (empty cluster name is seen in those same logs)
2021-04-28 21:47:17 -05:00
Kubernetes Prow Robot
a42edc4f0d
Merge pull request #11350 from rifelpet/kubetest2
...
Fix upgrade scenario kubetest2 install
2021-04-28 16:56:50 -07:00
Peter Rifel
7cb31fb500
Fix upgrade scenario kubetest2 install
2021-04-28 17:20:04 -05:00
Rajat Jindal
0ca28d986c
do not validate detached nodes
2021-04-28 21:30:46 +05:30
Rajat Jindal
1fed9c7711
add testcase demonstrating detached nodes getting validated
2021-04-28 21:30:46 +05:30
Kubernetes Prow Robot
06f2f25623
Merge pull request #11344 from olemarkus/bump-cilium
...
Bump cilium to 1.9.6
2021-04-28 01:48:49 -07:00
Ole Markus With
01ccf4590f
Bump cilium to 1.9.6
2021-04-28 10:06:13 +02:00
Kubernetes Prow Robot
021f0e5f55
Merge pull request #11338 from rifelpet/kubetest2
...
Update kubetest2 dependency and fix install method for upgrade scenario
2021-04-28 00:40:49 -07:00
Kubernetes Prow Robot
109f4bbb08
Merge pull request #11328 from olemarkus/channels-pki-set-san
...
Set SAN for addon CAs
2021-04-27 23:58:49 -07:00
Kubernetes Prow Robot
f79d6b43d5
Merge pull request #11342 from hakman/controller-runtime-0.9.0-beta.0
...
Update controller-runtime to v0.9.0-beta.0
2021-04-27 23:12:50 -07:00
Kubernetes Prow Robot
942f183157
Merge pull request #11336 from olemarkus/sqs-fix-flap
...
Fix SQS resource flapping
2021-04-27 22:08:49 -07:00
Ciprian Hacman
39fe0175aa
Update controller-runtime to v0.9.0-beta.0
2021-04-28 07:49:24 +03:00