Add HA/LB endpoints for kube-apiserver
* Add auto-evaluated internal endpoints and clarify the loadbalancer_apiserver
vars and usecases.
* Add loadbalancer_apiserver_localhost (default false). If enabled, override
the external LB and expect localhost:443/8080 to be new internal only frontends.
* Add kube_apiserver_multiaccess to ignore loadbalancers, and make clients
to access the apiservers as a comma-separated list of access_ip/ip/ansible ip
(a default mode). When disabled, allow clients to use the given loadbalancers.
* Define connections security mode for kube controllers, schedulers, proxies.
It is insecure be default, which is the current deployment choice.
* Rework the groups['kube-master'][0] hardcode defining the apiserver
endpoints.
* Improve grouping of vars and add facts for kube_apiserver.
* Define kube_apiserver_insecure_bind_address as a fact, add more
facts for ease of use.
Signed-off-by:
Bogdan Dobrelya <bdobrelia@mirantis.com>
Showing
- inventory/group_vars/all.yml 53 additions, 24 deletionsinventory/group_vars/all.yml
- roles/kubernetes/master/templates/kube-apiserver.j2 2 additions, 2 deletionsroles/kubernetes/master/templates/kube-apiserver.j2
- roles/kubernetes/master/templates/kubectl-kubeconfig.yaml.j2 1 addition, 1 deletionroles/kubernetes/master/templates/kubectl-kubeconfig.yaml.j2
- roles/kubernetes/master/templates/manifests/kube-controller-manager.manifest.j2 5 additions, 1 deletion...r/templates/manifests/kube-controller-manager.manifest.j2
- roles/kubernetes/master/templates/manifests/kube-scheduler.manifest.j2 5 additions, 1 deletion...tes/master/templates/manifests/kube-scheduler.manifest.j2
- roles/kubernetes/node/templates/kubelet.j2 1 addition, 1 deletionroles/kubernetes/node/templates/kubelet.j2
- roles/kubernetes/node/templates/manifests/kube-proxy.manifest.j2 3 additions, 7 deletions...ubernetes/node/templates/manifests/kube-proxy.manifest.j2
- roles/kubernetes/preinstall/tasks/set_facts.yml 34 additions, 0 deletionsroles/kubernetes/preinstall/tasks/set_facts.yml
Please register or sign in to comment