Skip to content
Snippets Groups Projects
  1. Mar 01, 2018
  2. Feb 12, 2018
  3. Jan 29, 2018
  4. Jan 09, 2018
  5. Jan 02, 2018
  6. Nov 14, 2017
  7. Nov 08, 2017
  8. Oct 26, 2017
  9. Oct 20, 2017
  10. Oct 12, 2017
  11. Oct 11, 2017
  12. Oct 05, 2017
  13. Oct 04, 2017
  14. Sep 25, 2017
  15. Sep 22, 2017
  16. Sep 14, 2017
  17. Sep 13, 2017
    • Matthew Mosesohn's avatar
      kubeadm support (#1631) · 67447260
      Matthew Mosesohn authored
      * kubeadm support
      
      * move k8s master to a subtask
      * disable k8s secrets when using kubeadm
      * fix etcd cert serial var
      * move simple auth users to master role
      * make a kubeadm-specific env file for kubelet
      * add non-ha CI job
      
      * change ci boolean vars to json format
      
      * fixup
      
      * Update create-gce.yml
      
      * Update create-gce.yml
      
      * Update create-gce.yml
      67447260
  18. Sep 10, 2017
  19. Sep 05, 2017
    • mkrasilnikov's avatar
      Vault role updates: · bf0af1cd
      mkrasilnikov authored
        * using separated vault roles for generate certs with different `O` (Organization) subject field;
        * configure vault roles for issuing certificates with different `CN` (Common name) subject field;
        * set `CN` and `O` to `kubernetes` and `etcd` certificates;
        * vault/defaults vars definition was simplified;
        * vault dirs variables defined in kubernetes-defaults foles for using
        shared tasks in etcd and kubernetes/secrets roles;
        * upgrade vault to 0.8.1;
        * generate random vault user password for each role by default;
        * fix `serial` file name for vault certs;
        * move vault auth request to issue_cert tasks;
        * enable `RBAC` in vault CI;
      bf0af1cd
  20. Sep 01, 2017
  21. Aug 30, 2017
    • Maxim Krasilnikov's avatar
      Change single Vault pki mount to multi pki mounts paths for etcd and kube CA`s (#1552) · 6eb22c5d
      Maxim Krasilnikov authored
      * Added update CA trust step for etcd and kube/secrets roles
      
      * Added load_balancer_domain_name to certificate alt names if defined. Reset CA's in RedHat os.
      
      * Rename kube-cluster-ca.crt to vault-ca.crt, we need separated CA`s for vault, etcd and kube.
      
      * Vault role refactoring, remove optional cert vault auth because not not used and worked. Create separate CA`s fro vault and etcd.
      
      * Fixed different certificates set for vault cert_managment
      
      * Update doc/vault.md
      
      * Fixed condition create vault CA, wrong group
      
      * Fixed missing etcd_cert_path mount for rkt deployment type. Distribute vault roles for all vault hosts
      
      * Removed wrong when condition in create etcd role vault tasks.
      6eb22c5d
  22. Aug 24, 2017
    • Brad Beam's avatar
      Adding yamllinter to ci steps (#1556) · 8b151d12
      Brad Beam authored
      * Adding yaml linter to ci check
      
      * Minor linting fixes from yamllint
      
      * Changing CI to install python pkgs from requirements.txt
      
      - adding in a secondary requirements.txt for tests
      - moving yamllint to tests requirements
      8b151d12
  23. Aug 20, 2017
    • Maxim Krasilnikov's avatar
      Fixed deploy cluster with vault cert manager (#1548) · 2ba285a5
      Maxim Krasilnikov authored
      * Added custom ips to etcd vault distributed certificates
      
      * Added custom ips to kube-master vault distributed certificates
      
      * Added comment about issue_cert_copy_ca var in vault/issue_cert role file
      
      * Generate kube-proxy, controller-manager and scheduler certificates by vault
      
      * Revert "Disable vault from CI (#1546)"
      
      This reverts commit 781f31d2.
      
      * Fixed upgrade cluster with vault cert manager
      
      * Remove vault dir in reset playbook
      2ba285a5
  24. Aug 18, 2017
    • Matthew Mosesohn's avatar
      Fix vault setup partially (#1531) · 2645e88b
      Matthew Mosesohn authored
      This does not address per-node certs and scheduler/proxy/controller-manager
      component certs which are now required. This should be handled in a
      follow-up patch.
      2645e88b
  25. Jul 28, 2017
  26. Jul 27, 2017
  27. Jun 29, 2017
  28. Jun 09, 2017
  29. Apr 13, 2017
  30. Mar 31, 2017
  31. Mar 24, 2017
  32. Mar 15, 2017
    • Matthew Mosesohn's avatar
      More idempotency fixes · a422ad0d
      Matthew Mosesohn authored
      Fixed sync_tokens fact
      Fixed sync_certs for k8s tokens fact
      Disabled register docker images changability
      Fixed CNI dir permission
      Fix idempotency for etcd pre upgrade checks
      a422ad0d
  33. Mar 14, 2017
  34. Mar 04, 2017
  35. Mar 03, 2017
  36. Feb 20, 2017
  37. Feb 18, 2017
Loading