Skip to content
  1. Mar 31, 2018
  2. Mar 30, 2018
  3. Mar 28, 2018
  4. Mar 26, 2018
  5. Mar 14, 2018
  6. Mar 06, 2018
  7. Mar 01, 2018
  8. Feb 22, 2018
  9. Feb 21, 2018
  10. Feb 12, 2018
  11. Feb 09, 2018
    • Damian Nowak's avatar
      Enable OOM killing · f8a59446
      Damian Nowak authored
      When etcd exceeds its memory limit, it becomes useless but keeps running.
      We should let OOM killer kill etcd process in the container, so systemd can spot
      the problem and restart etcd according to "Restart" setting in etcd.service unit file.
      If OOME problem keep repeating, i.e. it happens every single restart,
      systemd will eventually back off and stop restarting it anyway.
      
      --restart=on-failure:5 in this file has no effect because memory allocation error
      doesn't by itself cause the process to die
      
      Related: https://github.com/kubernetes-incubator/kubespray/blob/master/roles/etcd/templates/etcd-docker.service.j2
      
      This kind of reverts a change introduced in #1860.
      f8a59446
  12. Jan 30, 2018
  13. Jan 29, 2018
  14. Jan 09, 2018
  15. Jan 02, 2018
  16. Nov 23, 2017
    • Bogdan Dobrelya's avatar
      Defaults for apiserver_loadbalancer_domain_name (#1993) · 8aafe643
      Bogdan Dobrelya authored
      
      
      * Defaults for apiserver_loadbalancer_domain_name
      
      When loadbalancer_apiserver is defined, use the
      apiserver_loadbalancer_domain_name with a given default value.
      
      Fix unconsistencies for checking if apiserver_loadbalancer_domain_name
      is defined AND using it with a default value provided at once.
      
      Signed-off-by: default avatarBogdan Dobrelya <bogdando@mail.ru>
      
      * Define defaults for LB modes in common defaults
      
      Adjust the defaults for apiserver_loadbalancer_domain_name and
      loadbalancer_apiserver_localhost to come from a single source, which is
      kubespray-defaults. Removes some confusion and simplefies the code.
      
      Signed-off-by: default avatarBogdan Dobrelya <bogdando@mail.ru>
      8aafe643
  17. Nov 14, 2017
  18. Nov 08, 2017
  19. Oct 26, 2017
  20. Oct 25, 2017
  21. Oct 20, 2017
  22. Oct 19, 2017
  23. Oct 12, 2017
  24. Oct 11, 2017
  25. Oct 09, 2017
  26. Oct 05, 2017
  27. Oct 04, 2017
  28. Sep 25, 2017
  29. Sep 22, 2017
  30. Sep 14, 2017
  31. Sep 13, 2017
    • Matthew Mosesohn's avatar
      kubeadm support (#1631) · 67447260
      Matthew Mosesohn authored
      * kubeadm support
      
      * move k8s master to a subtask
      * disable k8s secrets when using kubeadm
      * fix etcd cert serial var
      * move simple auth users to master role
      * make a kubeadm-specific env file for kubelet
      * add non-ha CI job
      
      * change ci boolean vars to json format
      
      * fixup
      
      * Update create-gce.yml
      
      * Update create-gce.yml
      
      * Update create-gce.yml
      67447260
  32. Sep 10, 2017
  33. Sep 05, 2017
    • mkrasilnikov's avatar
      Vault role updates: · bf0af1cd
      mkrasilnikov authored
        * using separated vault roles for generate certs with different `O` (Organization) subject field;
        * configure vault roles for issuing certificates with different `CN` (Common name) subject field;
        * set `CN` and `O` to `kubernetes` and `etcd` certificates;
        * vault/defaults vars definition was simplified;
        * vault dirs variables defined in kubernetes-defaults foles for using
        shared tasks in etcd and kubernetes/secrets roles;
        * upgrade vault to 0.8.1;
        * generate random vault user password for each role by default;
        * fix `serial` file name for vault certs;
        * move vault auth request to issue_cert tasks;
        * enable `RBAC` in vault CI;
      bf0af1cd
  34. Sep 01, 2017
  35. Aug 31, 2017
  36. Aug 30, 2017
    • Maxim Krasilnikov's avatar
      Change single Vault pki mount to multi pki mounts paths for etcd and kube CA`s (#1552) · 6eb22c5d
      Maxim Krasilnikov authored
      * Added update CA trust step for etcd and kube/secrets roles
      
      * Added load_balancer_domain_name to certificate alt names if defined. Reset CA's in RedHat os.
      
      * Rename kube-cluster-ca.crt to vault-ca.crt, we need separated CA`s for vault, etcd and kube.
      
      * Vault role refactoring, remove optional cert vault auth because not not used and worked. Create separate CA`s fro vault and etcd.
      
      * Fixed different certificates set for vault cert_managment
      
      * Update doc/vault.md
      
      * Fixed condition create vault CA, wrong group
      
      * Fixed missing etcd_cert_path mount for rkt deployment type. Distribute vault roles for all vault hosts
      
      * Removed wrong when condition in create etcd role vault tasks.
      6eb22c5d
Loading