You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

41 lines
1.1 KiB

  1. ---
  2. # Instance settings
  3. cloud_image: centos-7
  4. mode: ha
  5. # Kubespray settings
  6. kubeadm_certificate_key: 3998c58db6497dd17d909394e62d515368c06ec617710d02edea31c06d741085
  7. kube_proxy_mode: iptables
  8. kube_network_plugin: flannel
  9. download_localhost: false
  10. download_run_once: true
  11. helm_enabled: true
  12. krew_enabled: true
  13. kubernetes_audit: true
  14. container_manager: containerd
  15. etcd_events_cluster_enabled: true
  16. local_volume_provisioner_enabled: true
  17. etcd_deployment_type: host
  18. deploy_netchecker: true
  19. dns_min_replicas: 1
  20. kube_encrypt_secret_data: true
  21. ingress_nginx_enabled: true
  22. cert_manager_enabled: true
  23. # Disable as health checks are still unstable and slow to respond.
  24. metrics_server_enabled: false
  25. metrics_server_kubelet_insecure_tls: true
  26. kube_token_auth: true
  27. enable_nodelocaldns: false
  28. kubelet_rotate_server_certificates: true
  29. kube_oidc_url: https://accounts.google.com/.well-known/openid-configuration
  30. kube_oidc_client_id: kubespray-example
  31. tls_min_version: "VersionTLS12"
  32. tls_cipher_suites:
  33. - TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  34. # test etcd tls cipher suites
  35. etcd_tls_cipher_suites:
  36. - TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  37. - TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384