Rohith
b62d6df115
Admission Controller Fix
...
A previous PR https://github.com/kubernetes/kops/pull/5221/ introduced the --enable-admission-plugins for >= 1.10.0 as recommended, it does however cause an issue if you already have AdmissionControl is specified in the Spec as both flags get rendered
2018-06-02 19:46:55 +01:00
Rohith
f31f544ff2
File Permissions Private Key
...
- adjusting the file permissions on the heptio authenticator to 0600
2018-06-01 15:34:37 +01:00
k8s-ci-robot
775b877a10
Merge pull request #5197 from rdrgmnzs/heptio_authenticator
...
Setup heptio authenticator
2018-06-01 07:12:55 -07:00
Rodrigo Menezes
f0476776b1
fix file perms
2018-05-31 21:11:06 -07:00
AdamDang
918d510909
Typo fix: are be->are
...
are be->are
2018-06-01 08:54:36 +08:00
k8s-ci-robot
e323fa918f
Merge pull request #5126 from justinsb/optional_etcd_manager
...
Support (optional) etcd-manager
2018-05-25 15:45:32 -07:00
Justin Santa Barbara
ba87c36f73
Support (optional) etcd-manager
2018-05-25 16:01:22 -04:00
Rodrigo Menezes
5ce8f9e712
Setup heptio authenticator
2018-05-23 17:48:33 -07:00
Rohith
c6c842112e
CA Key File Permissions
...
- locking down the ca.key somewhat by forcing the file permissions to 0600
2018-05-23 21:06:27 +01:00
k8s-ci-robot
31222ec1cc
Merge pull request #5042 from Cryptophobia/add-docker-17.09-for-debian-9
...
Add docker 17.09.0 version for Debian 9
2018-04-19 17:32:59 -07:00
Cryptophobia
c9cf51f5ad
Add docker 17.09.0 version for Debian 9
2018-04-19 12:17:07 -04:00
sonal
619ef0da8e
Treat Amazon Linux 2 as CentOS 7
2018-04-18 08:55:50 -04:00
Justin Santa Barbara
b1384b3bc0
Only do etcd backups on main
...
Because our implementation can't actually differentiate settings for
events & main, we only support backup of main for now.
2018-04-10 18:52:08 -04:00
Kashif Saadat
3d1203f0f4
Disable locksmithd on CoreOS if UpdatePolicy set
2018-04-10 13:05:00 +01:00
AdamDang
71d8d23982
Typo fix an->and
...
Typo fix an->and
2018-04-06 10:13:57 +08:00
andrewsykim
89960aff67
coreos/containeros: restart kops-configuration service after docker drop-in is loaded
2018-04-03 12:47:19 -04:00
andrewsykim
27e8902016
digitalocean: add nodeup support
2018-04-01 10:11:07 -04:00
k8s-ci-robot
cebc7017bc
Merge pull request #4760 from louismunro/add_AfterFiles_dependencies
...
Add AfterFiles dependencies to File tasks
2018-03-30 15:20:03 -07:00
Louis Munro
487dc33b7e
Adds an AfterFiles field to nodetasks.File and makes sure CoreOS uses it
2018-03-26 18:30:36 +00:00
k8s-ci-robot
fc1bed4353
Merge pull request #4224 from nebril/cilium-support
...
Add Cilium as CNI plugin
2018-03-26 07:49:02 -07:00
k8s-ci-robot
84b75cc7ec
Merge pull request #4744 from locationlabs/ca_bundle_fix
...
use the primary cert from the ca cert bundle
2018-03-21 19:27:05 -07:00
k8s-ci-robot
8d8e35aeae
Merge pull request #4575 from erks/admin_token_access
...
add system:masters group to admin user in static token file
2018-03-20 19:21:13 -07:00
Chris Phillips
bce2c346c3
use the primary cert from cert bundles
...
If the ca cert bundle has multiple certs, some things (kube-controller-manager in particular) will fail to startup correctly
2018-03-20 19:20:12 -07:00
Justin Santa Barbara
e93d88ecc2
Mount the iptables lock file
...
We only do this for >= 1.9 so we don't change existing clusters.
Equivalent of https://github.com/kubernetes/kubernetes/pull/46259
2018-03-20 18:07:17 -04:00
Maciej Kwiek
bca52dede9
Add Cilium as CNI plugin
...
Signed-off-by: Maciej Kwiek <maciej@covalent.io>
2018-03-20 13:07:26 +01:00
Leon Waldman
1fa6bfb612
Fix kubeScheduler.usePolicyConfigMap - missing namespace flag
2018-03-19 19:42:27 -03:00
Justin Santa Barbara
90ac573594
Centos: add selinux package dependencies
...
Issue #4091
2018-03-18 17:49:45 -04:00
Touch Ungboriboonpisal
eddf4ae7a0
make admin user in token auth have the same group (system:masters) as basic auth.
...
this should fix https://github.com/kubernetes/kops/issues/4369
2018-03-04 16:46:17 -08:00
k8s-ci-robot
e634143c43
Merge pull request #4417 from dezmodue/amazon-vpc-cni
...
Bind the kubelet to the local ipv4 address
2018-03-02 15:22:54 -08:00
Rohith
23f9c63bf3
Kube Proxy IPVS Kernel Module
...
- fixing the the 'Could not get ipvs family information from the kernel. It is possible that ipvs is not enabled in your kernel. Native loadbalancing will not work until this is fixed.' error
2018-03-02 15:05:22 +00:00
Simone Sciarrati
fcd08f1535
add BUILD.bazel
2018-03-01 18:05:15 +01:00
Simone Sciarrati
e406dbf501
Bind the kubelet to the local ipv4 address if the cni plugin is AmazonVPC - #4218
2018-03-01 17:47:54 +01:00
Horace Heaven
13244a5ce8
Kube-proxy API to accept cpu: limit, mem: request and limit
2018-02-28 15:26:19 -04:00
k8s-ci-robot
37d4b53d0d
Merge pull request #4010 from gambol99/etcd_options
...
Etcd TLS Peer & CLient Auth
2018-02-27 22:27:56 -08:00
Mike Splain
45a57915e2
Fix bazel deprecation notice
2018-02-26 09:36:13 -05:00
Rohith
a140d5b7f1
- fixing the protokube flag issue
2018-02-24 10:03:43 +00:00
Rohith
d065111453
Etcd TLS Peer & CLient Auth
2018-02-24 10:02:41 +00:00
Justin Santa Barbara
b68f58d746
Change NewAssetBuilder to take a kops.Cluseter
2018-02-22 21:42:40 -08:00
Justin Santa Barbara
dde7600dae
Initial support for standalone etcd-manager backups
...
The etcd-manager will (ideally) take over etcd management. To provide a
nice migration path, and because we want etcd backups, we're creating a
standalone image that just backs up etcd in the etcd-manager format.
This isn't really ready for actual usage, but should be harmless because
it runs as a sidecar container.
2018-02-20 20:06:08 -05:00
k8s-ci-robot
4b8db1eee0
Merge pull request #4137 from thockin-tmp/gcr-vanity
...
Convert registry to k8s.gcr.io
2018-02-20 08:54:39 -08:00
chrislovecnm
3b0702eb1c
updating bazel BUILD file
2018-02-18 15:33:18 -07:00
Rohith
c8e4a1caf8
Kubernetes Calico TLS
...
The current implementation when Etcd TLS was added does not support using calico as the configuration and client certificates are not present. This PR updates the calico manifests and adds the distribution of the client certificate
2018-02-14 23:41:45 +00:00
Tim Hockin
79d5f793e7
Convert registry to k8s.gcr.io
2018-02-14 10:08:41 -08:00
k8s-ci-robot
2b1ecba8e1
Merge pull request #4395 from ihoegen/master
...
Add max-requests-inflight parameter
2018-02-13 22:59:51 -08:00
Ian Hoegen
37c3ac3784
Add max-requests-inflight flag, along with docs
2018-02-13 13:34:48 -08:00
Mike Splain
f40dc50a25
Update BUILD files to account for some recent changes
2018-02-12 17:16:33 -05:00
Kashif Saadat
ac25853cd5
- Add etcdClusterSpec Image & Version in bootstrap data for Master nodes
...
- Reuse execWithTee fn for ETCD Command (tee & mkfifo in different path for newer image versions)
2018-02-10 12:14:36 +00:00
k8s-ci-robot
6cce2427b3
Merge pull request #4286 from justinsb/exec_with_bin_sh
...
exec target command, but still pipe it to tee
2018-01-29 04:56:33 -08:00
Justin Santa Barbara
7ca593b994
exec target command, but still pipe it to tee
...
Equivalent of https://github.com/kubernetes/kubernetes/pull/57756
2018-01-25 10:15:24 -05:00
Otto Yiu
2b12b59d75
add ability to override etcd image and update apimachinery generated files from EtcdClusterSpec changes
2018-01-10 13:39:07 -08:00