Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
K
Kubespray
Manage
Activity
Members
Code
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Deploy
Model registry
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
Mirror
Kubespray
Commits
b974b144
Commit
b974b144
authored
7 years ago
by
rong.zhang
Browse files
Options
Downloads
Patches
Plain Diff
Add RBAC to binding Dahsboard UI
parent
0771cd85
No related branches found
No related tags found
No related merge requests found
Changes
2
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
roles/kubernetes-apps/ansible/defaults/main.yml
+9
-0
9 additions, 0 deletions
roles/kubernetes-apps/ansible/defaults/main.yml
roles/kubernetes-apps/ansible/templates/dashboard.yml.j2
+43
-0
43 additions, 0 deletions
roles/kubernetes-apps/ansible/templates/dashboard.yml.j2
with
52 additions
and
0 deletions
roles/kubernetes-apps/ansible/defaults/main.yml
+
9
−
0
View file @
b974b144
...
@@ -42,6 +42,8 @@ netchecker_server_memory_requests: 64M
...
@@ -42,6 +42,8 @@ netchecker_server_memory_requests: 64M
dashboard_enabled
:
true
dashboard_enabled
:
true
dashboard_image_repo
:
gcr.io/google_containers/kubernetes-dashboard-amd64
dashboard_image_repo
:
gcr.io/google_containers/kubernetes-dashboard-amd64
dashboard_image_tag
:
v1.8.0
dashboard_image_tag
:
v1.8.0
dashboard_init_image_repo
:
gcr.io/google_containers/kubernetes-dashboard-init-amd64
dashboard_init_image_tag
:
v1.0.1
# Limits for dashboard
# Limits for dashboard
dashboard_cpu_limit
:
100m
dashboard_cpu_limit
:
100m
...
@@ -53,6 +55,13 @@ dashboard_memory_requests: 64M
...
@@ -53,6 +55,13 @@ dashboard_memory_requests: 64M
etcd_cert_dir
:
"
/etc/ssl/etcd/ssl"
etcd_cert_dir
:
"
/etc/ssl/etcd/ssl"
canal_cert_dir
:
"
/etc/canal/certs"
canal_cert_dir
:
"
/etc/canal/certs"
# Set dashboard_use_custom_certs to true if overriding dashboard_certs_secret_name with a secret that
# contains dashboard_tls_key_file and dashboard_tls_cert_file instead of using the initContainer provisioned certs
dashboard_use_custom_certs
:
false
dashboard_certs_secret_name
:
kubernetes-dashboard-certs
dashboard_tls_key_file
:
dashboard.key
dashboard_tls_cert_file
:
dashboard.crt
rbac_resources
:
rbac_resources
:
-
sa
-
sa
-
clusterrole
-
clusterrole
...
...
This diff is collapsed.
Click to expand it.
roles/kubernetes-apps/ansible/templates/dashboard.yml.j2
+
43
−
0
View file @
b974b144
...
@@ -91,6 +91,34 @@ subjects:
...
@@ -91,6 +91,34 @@ subjects:
name: kubernetes-dashboard
name: kubernetes-dashboard
namespace: {{ system_namespace }}
namespace: {{ system_namespace }}
---
# ------------------- Gross Hack For anonymous auth through api proxy ------------------- #
# Allows users to reach login page and other proxied dashboard URLs
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: kubernetes-dashboard-anonymous
rules:
- apiGroups: [""]
resources: ["services/proxy"]
resourceNames: ["https:kubernetes-dashboard:"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- nonResourceURLs: ["/ui", "/ui/*", "/api/v1/namespaces/{{ system_namespace }}/services/https:kubernetes-dashboard:/proxy/*"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: kubernetes-dashboard-anonymous
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: kubernetes-dashboard-anonymous
subjects:
- kind: User
name: system:anonymous
---
---
# ------------------- Dashboard Deployment ------------------- #
# ------------------- Dashboard Deployment ------------------- #
...
@@ -112,6 +140,14 @@ spec:
...
@@ -112,6 +140,14 @@ spec:
labels:
labels:
k8s-app: kubernetes-dashboard
k8s-app: kubernetes-dashboard
spec:
spec:
{% if not dashboard_use_custom_certs %}
initContainers:
- name: kubernetes-dashboard-init
image: {{ dashboard_init_image_repo }}:{{ dashboard_init_image_tag }}
volumeMounts:
- name: kubernetes-dashboard-certs
mountPath: /certs
{% endif %}
containers:
containers:
- name: kubernetes-dashboard
- name: kubernetes-dashboard
image: {{ dashboard_image_repo }}:{{ dashboard_image_tag }}
image: {{ dashboard_image_repo }}:{{ dashboard_image_tag }}
...
@@ -127,7 +163,14 @@ spec:
...
@@ -127,7 +163,14 @@ spec:
- containerPort: 8443
- containerPort: 8443
protocol: TCP
protocol: TCP
args:
args:
{% if not dashboard_use_custom_certs %}
- --tls-key-file=/certs/{{ dashboard_tls_key_file }}
- --tls-cert-file=/certs/{{ dashboard_tls_cert_file }}
- --authentication-mode=token{% if kube_basic_auth|default(false) %},basic{% endif %}
{% else %}
- --auto-generate-certificates
- --auto-generate-certificates
{% endif %}
{% endif %}
# Uncomment the following line to manually specify Kubernetes API server Host
# Uncomment the following line to manually specify Kubernetes API server Host
# If not specified, Dashboard will attempt to auto discover the API server and connect
# If not specified, Dashboard will attempt to auto discover the API server and connect
# to it. Uncomment only if the default does not work.
# to it. Uncomment only if the default does not work.
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment