-
- Downloads
Move calico-policy-controller into separate role
By default Calico CNI does not create any network access policies or profiles if 'policy' is enabled in CNI config. And without any policies/profiles network access to/from PODs is blocked. K8s related policies are created by calico-policy-controller in such case. So we need to start it as soon as possible, before any real workloads. This patch also fixes kube-api port in calico-policy-controller yaml template. Closes #1132
Showing
- cluster.yml 1 addition, 0 deletionscluster.yml
- inventory/group_vars/k8s-cluster.yml 3 additions, 0 deletionsinventory/group_vars/k8s-cluster.yml
- roles/kubernetes-apps/ansible/defaults/main.yml 0 additions, 7 deletionsroles/kubernetes-apps/ansible/defaults/main.yml
- roles/kubernetes-apps/ansible/tasks/main.yml 0 additions, 5 deletionsroles/kubernetes-apps/ansible/tasks/main.yml
- roles/kubernetes-apps/meta/main.yml 0 additions, 5 deletionsroles/kubernetes-apps/meta/main.yml
- roles/kubernetes-apps/policy_controller/calico/defaults/main.yml 9 additions, 0 deletions...ubernetes-apps/policy_controller/calico/defaults/main.yml
- roles/kubernetes-apps/policy_controller/calico/tasks/main.yml 3 additions, 2 deletions...s/kubernetes-apps/policy_controller/calico/tasks/main.yml
- roles/kubernetes-apps/policy_controller/calico/templates/calico-policy-controller.yml.j2 1 addition, 1 deletion...ntroller/calico/templates/calico-policy-controller.yml.j2
- roles/kubernetes-apps/policy_controller/meta/main.yml 14 additions, 0 deletionsroles/kubernetes-apps/policy_controller/meta/main.yml
- roles/kubernetes/master/templates/manifests/kube-apiserver.manifest.j2 1 addition, 1 deletion...tes/master/templates/manifests/kube-apiserver.manifest.j2
- roles/network_plugin/calico/templates/cni-calico.conf.j2 1 addition, 1 deletionroles/network_plugin/calico/templates/cni-calico.conf.j2
Please register or sign in to comment