Skip to content
Snippets Groups Projects
Commit fb0ee9d8 authored by Aleksandr Didenko's avatar Aleksandr Didenko
Browse files

Add support for --masquerade-all in kube-proxy

New boolean var `kube_proxy_masquerade_all` which enables/disables
`--masquerade-all` argument for kube-proxy.

Closes #524
parent 016b7893
No related branches found
No related tags found
No related merge requests found
...@@ -8,6 +8,9 @@ kube_resolv_conf: "/etc/resolv.conf" ...@@ -8,6 +8,9 @@ kube_resolv_conf: "/etc/resolv.conf"
kube_proxy_mode: iptables kube_proxy_mode: iptables
# If using the pure iptables proxy, SNAT everything
kube_proxy_masquerade_all: true
# kube_api_runtime_config: # kube_api_runtime_config:
# - extensions/v1beta1/daemonsets=true # - extensions/v1beta1/daemonsets=true
# - extensions/v1beta1/deployments=true # - extensions/v1beta1/deployments=true
...@@ -18,6 +18,9 @@ spec: ...@@ -18,6 +18,9 @@ spec:
{% endif %} {% endif %}
- --bind-address={{ ip | default(ansible_default_ipv4.address) }} - --bind-address={{ ip | default(ansible_default_ipv4.address) }}
- --proxy-mode={{ kube_proxy_mode }} - --proxy-mode={{ kube_proxy_mode }}
{% if kube_proxy_masquerade_all and kube_proxy_mode == "iptables" %}
- --masquerade-all
{% endif %}
securityContext: securityContext:
privileged: true privileged: true
volumeMounts: volumeMounts:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment