Skip to content
Snippets Groups Projects
  1. Jan 20, 2017
    • Bogdan Dobrelya's avatar
      Drop linux capabilities and rework users/groups · cb2e5ac7
      Bogdan Dobrelya authored
      
      * Drop linux capabilities for unprivileged containerized
        worlkoads Kargo configures for deployments.
      * Configure required securityContext/user/group/groups for kube
        components' static manifests, etcd, calico-rr and k8s apps,
        like dnsmasq daemonset.
      * Rework cloud-init (etcd) users creation for CoreOS.
      * Fix nologin paths, adjust defaults for addusers role and ensure
        supplementary groups membership added for users.
      * Add netplug user for network plugins (yet unused by privileged
        networking containers though).
      * Grant the kube and netplug users read access for etcd certs via
        the etcd certs group.
      * Grant group read access to kube certs via the kube cert group.
      * Remove priveleged mode for calico-rr and run it under its uid/gid
        and supplementary etcd_cert group.
      * Adjust docs.
      * Align cpu/memory limits and dropped caps with added rkt support
        for control plane.
      
      Signed-off-by: default avatarBogdan Dobrelya <bogdando@mail.ru>
      cb2e5ac7
  2. Jan 19, 2017
  3. Jan 17, 2017
  4. Jan 15, 2017
    • Greg Althaus's avatar
      This PR adds/or modifies a few tasks to allow for the playbook to · 6c69da15
      Greg Althaus authored
      be run by limit on each node without regard for order.
      
      The changes make sure that all of the directories needed to do
      certificate management are on the master[0] or etcd[0] node regardless
      of when the playbook gets run on each node.  This allows for separate
      ansible playbook runs in parallel that don't have to be synchronized.
      6c69da15
  5. Jan 09, 2017
  6. Jan 05, 2017
  7. Jan 03, 2017
  8. Jan 02, 2017
  9. Dec 30, 2016
  10. Dec 28, 2016
  11. Dec 27, 2016
  12. Dec 22, 2016
  13. Dec 19, 2016
  14. Dec 15, 2016
  15. Dec 09, 2016
  16. Nov 14, 2016
  17. Nov 09, 2016
  18. Oct 20, 2016
  19. Sep 15, 2016
  20. Sep 13, 2016
  21. Aug 29, 2016
  22. Jul 20, 2016
  23. Jul 19, 2016
    • Bogdan Dobrelya's avatar
      Add etcd proxy support · 32cd6e99
      Bogdan Dobrelya authored
      
      * Enforce a etcd-proxy role to a k8s-cluster group members. This
      provides an HA layout for all of the k8s cluster internal clients.
      * Proxies to be run on each node in the group as a separate etcd
      instances with a readwrite proxy mode and listen the given endpoint,
      which is either the access_ip:2379 or the localhost:2379.
      * A notion for the 'kube_etcd_multiaccess' is: ignore endpoints and
      loadbalancers and use the etcd members IPs as a comma-separated
      list. Otherwise, clients shall use the local endpoint provided by a
      etcd-proxy instances on each etcd node. A Netwroking plugins always
      use that access mode.
      * Fix apiserver's etcd servers args to use the etcd_access_endpoint.
      * Fix networking plugins flannel/calico to use the etcd_endpoint.
      * Fix name env var for non masters to be set as well.
      * Fix etcd_client_url was not used anywhere and other etcd_* facts
      evaluation was duplicated in a few places.
      * Define proxy modes only in the env file, if not a master. Del
      an automatic proxy mode decisions for etcd nodes in init/unit scripts.
      * Use Wants= instead of Requires= as "This is the recommended way to
      hook start-up of one unit to the start-up of another unit"
      * Make apiserver/calico Wants= etcd-proxy to keep it always up
      
      Signed-off-by: default avatarBogdan Dobrelya <bdobrelia@mirantis.com>
      Co-authored-by: default avatarMatthew Mosesohn <mmosesohn@mirantis.com>
      32cd6e99
  24. Jul 14, 2016
  25. Jul 07, 2016
  26. May 31, 2016
    • Evgeny L's avatar
      Scale-up functionality for etcd cluster · 0500f27d
      Evgeny L authored
      * Set ETCD_INITIAL_CLUSTER_STATE from `new` to `existing`,
      because parameter `new` makes sense only on cluster assembly
      stage.
      * If cluster exists and current node is not a part
      of the cluster, add it with command `etcdctl add member name url`.
      
      Closes kubespray/kargo/#270
      0500f27d
  27. Feb 21, 2016
  28. Feb 13, 2016
  29. Jan 26, 2016
  30. Jan 25, 2016
  31. Jan 23, 2016
  32. Jan 22, 2016
Loading