Skip to content
Snippets Groups Projects
  1. Feb 07, 2018
  2. Feb 05, 2018
  3. Oct 27, 2017
  4. Oct 16, 2017
    • neith00's avatar
      Revert "Update roadmap" (#1809) · 77f1d4b0
      neith00 authored
      * Revert "Debian jessie docs (#1806)"
      
      This reverts commit d78577c8.
      
      * Revert "[contrib/network-storage/glusterfs] adds service for glusterfs endpoint (#1800)"
      
      This reverts commit 5fb6b2ea.
      
      * Revert "[contrib/network-storage/glusterfs] bootstrap for glusterfs nodes (#1799)"
      
      This reverts commit 404caa11.
      
      * Revert "Fixed kubelet standard log environment (#1780)"
      
      This reverts commit b8384685.
      
      * Revert "Add support for fedora atomic host (#1779)"
      
      This reverts commit f2235be1.
      
      * Revert "Update network-plugins to use portmap plugin (#1763)"
      
      This reverts commit 6ec45b10.
      
      * Revert "Update roadmap (#1795)"
      
      This reverts commit d9879d80.
      77f1d4b0
    • Matthew Mosesohn's avatar
      Update roadmap (#1795) · d9879d80
      Matthew Mosesohn authored
      d9879d80
  5. Oct 05, 2017
  6. Aug 30, 2017
  7. Aug 18, 2017
    • Matthew Mosesohn's avatar
      Fix cert and netchecker upgrade issues (#1543) · df28db00
      Matthew Mosesohn authored
      * Bump tag for upgrade CI, fix netchecker upgrade
      
      netchecker-server was changed from pod to deployment, so
      we need an upgrade hook for it.
      
      CI now uses v2.1.1 as a basis for upgrade.
      
      * Fix upgrades for certs from non-rbac to rbac
      df28db00
  8. Jul 17, 2017
  9. Mar 08, 2017
    • Cesarini, Daniele's avatar
      Adding /O=system:masters to admin certificate · 69636d24
      Cesarini, Daniele authored
      Issue #1125. Make RBAC authorization plugin work out of the box.
      "When bootstrapping, superuser credentials should include the system:masters group, for example by creating a client cert with /O=system:masters. This gives those credentials full access to the API and allows an admin to then set up bindings for other users."
      69636d24
  10. Feb 24, 2017
  11. Feb 06, 2017
  12. Jan 20, 2017
    • Bogdan Dobrelya's avatar
      Drop linux capabilities and rework users/groups · cb2e5ac7
      Bogdan Dobrelya authored
      
      * Drop linux capabilities for unprivileged containerized
        worlkoads Kargo configures for deployments.
      * Configure required securityContext/user/group/groups for kube
        components' static manifests, etcd, calico-rr and k8s apps,
        like dnsmasq daemonset.
      * Rework cloud-init (etcd) users creation for CoreOS.
      * Fix nologin paths, adjust defaults for addusers role and ensure
        supplementary groups membership added for users.
      * Add netplug user for network plugins (yet unused by privileged
        networking containers though).
      * Grant the kube and netplug users read access for etcd certs via
        the etcd certs group.
      * Grant group read access to kube certs via the kube cert group.
      * Remove priveleged mode for calico-rr and run it under its uid/gid
        and supplementary etcd_cert group.
      * Adjust docs.
      * Align cpu/memory limits and dropped caps with added rkt support
        for control plane.
      
      Signed-off-by: default avatarBogdan Dobrelya <bogdando@mail.ru>
      cb2e5ac7
  13. Jan 13, 2017
  14. Jan 11, 2017
  15. Oct 05, 2016
  16. May 07, 2016
  17. Feb 19, 2016
  18. Feb 13, 2016
  19. Dec 12, 2015
Loading