Commit Graph

13813 Commits

Author SHA1 Message Date
Jesse Haka 3b9c893bae add permission to create sa tokens 2021-05-03 16:01:57 +03:00
Kubernetes Prow Robot b054fb37b7
Merge pull request #11016 from olemarkus/irsa-custom
user-configurable IAM roles for ServiceAccounts
2021-05-02 11:16:01 -07:00
Kubernetes Prow Robot fdce6638dd
Merge pull request #11369 from hakman/needupdate_after_etcd-manager_changes
Mark control-plane node for update when etcd manager config changes
2021-05-02 09:54:01 -07:00
Ole Markus With 6199174d78 Apply suggestions from code review
Co-authored-by: John Gardiner Myers <jgmyers@proofpoint.com>
2021-05-02 07:56:57 +02:00
Ciprian Hacman 689b76d0ff Mark control-plane node for update when etcd manager config changes 2021-05-02 08:50:42 +03:00
Ciprian Hacman 62c47d23d4 Add integration test for etcd 2021-05-02 08:48:46 +03:00
Ole Markus With 6f8b3647cf Add support for IRSA in he api
Apply suggestions from code review

Co-authored-by: John Gardiner Myers <jgmyers@proofpoint.com>
2021-05-01 16:03:42 +02:00
Kubernetes Prow Robot 03786fc5ec
Merge pull request #11365 from hakman/needupdate_after_etcd_vol_resize
Mark control-plane node for update when etcd volume size changes
2021-05-01 05:13:59 -07:00
Ciprian Hacman d64cfba365 Mark control-plane node for update when etcd volume size changes
etcd-manager expands the data volume on restart to the max available.
2021-05-01 12:06:22 +03:00
Kubernetes Prow Robot 3704ffd2c9
Merge pull request #11354 from codablock/external-cert-manager
Allow cert-manager to be provisioned externally
2021-04-30 13:45:59 -07:00
Kubernetes Prow Robot a304dc4323
Merge pull request #11362 from olemarkus/oidc-location
Use VFS as service account issuer if configured
2021-04-30 12:43:58 -07:00
Ole Markus With 5ca7c9b5d7 Use VFS as service account issuer if configured
Also add an integration test that uses VFS
2021-04-30 21:02:30 +02:00
Kubernetes Prow Robot 1da39a3fe1
Merge pull request #11361 from olemarkus/oidc-awsidcprovider
Configure aws oidc provider
2021-04-30 11:41:59 -07:00
Alexander Block d1ab0af511 Allow cert-manager to be provisioned externally 2021-04-30 20:33:59 +02:00
Kubernetes Prow Robot d8de9fcad6
Merge pull request #11314 from olemarkus/cilium-fix-hubble
Expose hubble agent when hubble is enabled
2021-04-30 10:59:59 -07:00
Ole Markus With 75933682ed Rename serviceaccountissuerdiscovery struct 2021-04-30 19:19:06 +02:00
Ole Markus With 460586833b Add toggle for AWS OIDC provider. Free it from any feature flag 2021-04-30 19:19:06 +02:00
Ole Markus With 25b5f0cfb2 Move publicDataStore to serviceAccountIssuerDiscovery.discoveryStore 2021-04-30 19:19:06 +02:00
Kubernetes Prow Robot e9747269de
Merge pull request #11359 from olemarkus/oidc-split-builder
Split oidc_provider
2021-04-30 09:55:58 -07:00
Ole Markus With 0f545f8659 Split oidc_provider
* one builder concerned with publishing issuer discovery metadata
* one builder concerned with creating aws oidc provider
2021-04-30 18:05:20 +02:00
Ole Markus With 7c0be997e1 Expose hubble agent when hubble is enabled
Also enables PKI for the addon
2021-04-30 17:52:19 +02:00
Kubernetes Prow Robot 7a63ed8f5c
Merge pull request #11360 from dntosas/nth-resources
[addons/nth] Add capability to define resources
2021-04-30 07:53:58 -07:00
Kubernetes Prow Robot 6e8e8e8456
Merge pull request #11358 from hakman/refactor-awsmodel
Move firewall, iam, network and sshkey to awsmodel
2021-04-30 07:09:58 -07:00
Kubernetes Prow Robot 6d23e31c8c
Merge pull request #11349 from rajatjindal/ignore-detached-validate-cluster
Ignore detached nodes when doing validate cluster
2021-04-30 05:43:58 -07:00
Ciprian Hacman 4a0fa78b20 Run hack/update-bazel.sh 2021-04-30 14:50:46 +03:00
Ciprian Hacman 0e651dd8fc Use AWSModelContext in remaining awsmodel files 2021-04-30 14:50:46 +03:00
Ciprian Hacman 137fe6c2bb Move firewall to awsmodel 2021-04-30 14:50:46 +03:00
dntosas 7e20f87822
[addons/nth] Add capability to define resources
Node termination handler as all daemonSets may play a critical role in
capacity planning, define resource policy for chosing instanceType etc.

In this commit, we enable users to define resources themselves to meet
their needs and also removed limits to convey with the chosen strategy
to avoid limits on such components.

Signed-off-by: dntosas <ntosas@gmail.com>
2021-04-30 14:13:11 +03:00
Kubernetes Prow Robot b386dbcb16
Merge pull request #11357 from zetaab/updatedeppps
Update deps
2021-04-30 02:55:58 -07:00
Ciprian Hacman fcba0043d0 Move iam to awsmodel 2021-04-30 12:37:28 +03:00
Ciprian Hacman 4dfe58de7a Move network to awsmodel 2021-04-30 12:04:06 +03:00
Ciprian Hacman ca02c04793 Move sshkey to awsmodel 2021-04-30 12:04:06 +03:00
Jesse Haka 960a52d6b2 Update deps 2021-04-30 11:39:01 +03:00
Ciprian Hacman c49b71feb5 Use same method receiver names everywhere 2021-04-30 11:31:14 +03:00
Ciprian Hacman bd7176f45f Replace convenience functions with fi.* alternatives 2021-04-30 11:26:48 +03:00
Kubernetes Prow Robot 8f0aa33131
Merge pull request #11352 from hakman/mount-run-etcd
Mount /run inside etcd-manager pods for systemd mounts
2021-04-29 02:04:50 -07:00
Ciprian Hacman 75047c6513 Mount /run inside etcd-manager pods for systemd mounts 2021-04-29 10:15:58 +03:00
Kubernetes Prow Robot 2de1342abf
Merge pull request #11351 from rifelpet/kubetest2
Fix kubetest2 panic inheriting env vars
2021-04-28 20:46:50 -07:00
Peter Rifel 6afaaa3161
Fix kubetest2 panic inheriting env vars
Fixes `panic: runtime error: slice bounds out of range [:-1]` found here: https://prow.k8s.io/view/gs/kubernetes-jenkins/logs/e2e-kops-grid-scenario-aws-cloud-controller-manager/1387534126441041920

Also fixes a logging statement to include the cluster name (empty cluster name is seen in those same logs)
2021-04-28 21:47:17 -05:00
Kubernetes Prow Robot a42edc4f0d
Merge pull request #11350 from rifelpet/kubetest2
Fix upgrade scenario kubetest2 install
2021-04-28 16:56:50 -07:00
Peter Rifel 7cb31fb500
Fix upgrade scenario kubetest2 install 2021-04-28 17:20:04 -05:00
Rajat Jindal 0ca28d986c do not validate detached nodes 2021-04-28 21:30:46 +05:30
Rajat Jindal 1fed9c7711 add testcase demonstrating detached nodes getting validated 2021-04-28 21:30:46 +05:30
Kubernetes Prow Robot 06f2f25623
Merge pull request #11344 from olemarkus/bump-cilium
Bump cilium to 1.9.6
2021-04-28 01:48:49 -07:00
Ole Markus With 01ccf4590f Bump cilium to 1.9.6 2021-04-28 10:06:13 +02:00
Kubernetes Prow Robot 021f0e5f55
Merge pull request #11338 from rifelpet/kubetest2
Update kubetest2 dependency and fix install method for upgrade scenario
2021-04-28 00:40:49 -07:00
Kubernetes Prow Robot 109f4bbb08
Merge pull request #11328 from olemarkus/channels-pki-set-san
Set SAN for addon CAs
2021-04-27 23:58:49 -07:00
Kubernetes Prow Robot f79d6b43d5
Merge pull request #11342 from hakman/controller-runtime-0.9.0-beta.0
Update controller-runtime to v0.9.0-beta.0
2021-04-27 23:12:50 -07:00
Kubernetes Prow Robot 942f183157
Merge pull request #11336 from olemarkus/sqs-fix-flap
Fix SQS resource flapping
2021-04-27 22:08:49 -07:00
Ciprian Hacman 39fe0175aa Update controller-runtime to v0.9.0-beta.0 2021-04-28 07:49:24 +03:00