Skip to content
Snippets Groups Projects
  1. May 30, 2018
  2. Apr 26, 2018
  3. Apr 23, 2018
  4. Apr 11, 2018
  5. Apr 01, 2018
    • woopstar's avatar
      Etcd cluster setup makeover · 86e3506a
      woopstar authored
      The current way to setup the etc cluster is messy and buggy.
      
      - It checks for cluster is healthy before the cluster is even created.
      - The unit files are started on handlers, not in the task, so you mess with "flush handlers".
      - The join_member.yml is not used.
      - etcd events cluster is not configured for kubeadm
      - remove duplicate runs between running the role on etcd nodes and k8s nodes
      86e3506a
  6. Mar 31, 2018
  7. Mar 01, 2018
  8. Feb 12, 2018
  9. Jan 29, 2018
  10. Jan 09, 2018
  11. Jan 02, 2018
  12. Nov 14, 2017
  13. Nov 08, 2017
  14. Oct 26, 2017
  15. Oct 20, 2017
  16. Oct 12, 2017
  17. Oct 11, 2017
  18. Oct 05, 2017
  19. Oct 04, 2017
  20. Sep 25, 2017
  21. Sep 22, 2017
  22. Sep 14, 2017
  23. Sep 13, 2017
    • Matthew Mosesohn's avatar
      kubeadm support (#1631) · 67447260
      Matthew Mosesohn authored
      * kubeadm support
      
      * move k8s master to a subtask
      * disable k8s secrets when using kubeadm
      * fix etcd cert serial var
      * move simple auth users to master role
      * make a kubeadm-specific env file for kubelet
      * add non-ha CI job
      
      * change ci boolean vars to json format
      
      * fixup
      
      * Update create-gce.yml
      
      * Update create-gce.yml
      
      * Update create-gce.yml
      67447260
  24. Sep 10, 2017
  25. Sep 05, 2017
    • mkrasilnikov's avatar
      Vault role updates: · bf0af1cd
      mkrasilnikov authored
        * using separated vault roles for generate certs with different `O` (Organization) subject field;
        * configure vault roles for issuing certificates with different `CN` (Common name) subject field;
        * set `CN` and `O` to `kubernetes` and `etcd` certificates;
        * vault/defaults vars definition was simplified;
        * vault dirs variables defined in kubernetes-defaults foles for using
        shared tasks in etcd and kubernetes/secrets roles;
        * upgrade vault to 0.8.1;
        * generate random vault user password for each role by default;
        * fix `serial` file name for vault certs;
        * move vault auth request to issue_cert tasks;
        * enable `RBAC` in vault CI;
      bf0af1cd
  26. Sep 01, 2017
  27. Aug 30, 2017
    • Maxim Krasilnikov's avatar
      Change single Vault pki mount to multi pki mounts paths for etcd and kube CA`s (#1552) · 6eb22c5d
      Maxim Krasilnikov authored
      * Added update CA trust step for etcd and kube/secrets roles
      
      * Added load_balancer_domain_name to certificate alt names if defined. Reset CA's in RedHat os.
      
      * Rename kube-cluster-ca.crt to vault-ca.crt, we need separated CA`s for vault, etcd and kube.
      
      * Vault role refactoring, remove optional cert vault auth because not not used and worked. Create separate CA`s fro vault and etcd.
      
      * Fixed different certificates set for vault cert_managment
      
      * Update doc/vault.md
      
      * Fixed condition create vault CA, wrong group
      
      * Fixed missing etcd_cert_path mount for rkt deployment type. Distribute vault roles for all vault hosts
      
      * Removed wrong when condition in create etcd role vault tasks.
      6eb22c5d
  28. Aug 24, 2017
    • Brad Beam's avatar
      Adding yamllinter to ci steps (#1556) · 8b151d12
      Brad Beam authored
      * Adding yaml linter to ci check
      
      * Minor linting fixes from yamllint
      
      * Changing CI to install python pkgs from requirements.txt
      
      - adding in a secondary requirements.txt for tests
      - moving yamllint to tests requirements
      8b151d12
  29. Aug 20, 2017
    • Maxim Krasilnikov's avatar
      Fixed deploy cluster with vault cert manager (#1548) · 2ba285a5
      Maxim Krasilnikov authored
      * Added custom ips to etcd vault distributed certificates
      
      * Added custom ips to kube-master vault distributed certificates
      
      * Added comment about issue_cert_copy_ca var in vault/issue_cert role file
      
      * Generate kube-proxy, controller-manager and scheduler certificates by vault
      
      * Revert "Disable vault from CI (#1546)"
      
      This reverts commit 781f31d2.
      
      * Fixed upgrade cluster with vault cert manager
      
      * Remove vault dir in reset playbook
      2ba285a5
  30. Aug 18, 2017
    • Matthew Mosesohn's avatar
      Fix vault setup partially (#1531) · 2645e88b
      Matthew Mosesohn authored
      This does not address per-node certs and scheduler/proxy/controller-manager
      component certs which are now required. This should be handled in a
      follow-up patch.
      2645e88b
  31. Jul 28, 2017
  32. Jul 27, 2017
  33. Jun 29, 2017
  34. Jun 09, 2017
  35. Apr 13, 2017
  36. Mar 31, 2017
  37. Mar 24, 2017
Loading