Browse Source

Merge pull request #1137 from holser/bug/1135

Turn on iptables for flannel
pull/1278/head
Matthew Mosesohn 8 years ago
committed by GitHub
parent
commit
096d96e344
3 changed files with 3 additions and 3 deletions
  1. 2
      inventory/group_vars/k8s-cluster.yml
  2. 2
      roles/docker/templates/docker-options.conf.j2
  3. 2
      roles/kargo-defaults/defaults/main.yaml

2
inventory/group_vars/k8s-cluster.yml

@ -121,7 +121,7 @@ docker_daemon_graph: "/var/lib/docker"
## This string should be exactly as you wish it to appear.
## An obvious use case is allowing insecure-registry access
## to self hosted registries like so:
docker_options: "--insecure-registry={{ kube_service_addresses }} --graph={{ docker_daemon_graph }} --iptables=false"
docker_options: "--insecure-registry={{ kube_service_addresses }} --graph={{ docker_daemon_graph }}"
docker_bin_dir: "/usr/bin"
# Settings for containerized control plane (etcd/kubelet/secrets)

2
roles/docker/templates/docker-options.conf.j2

@ -1,2 +1,2 @@
[Service]
Environment="DOCKER_OPTS={% if docker_options is defined %}{{ docker_options }}{% endif %}"
Environment="DOCKER_OPTS={% if docker_options is defined %}{{ docker_options }}{% endif %} --iptables={% if kube_network_plugin == 'flannel' %}true{% else %}false{% endif %}"

2
roles/kargo-defaults/defaults/main.yaml

@ -101,7 +101,7 @@ docker_daemon_graph: "/var/lib/docker"
## This string should be exactly as you wish it to appear.
## An obvious use case is allowing insecure-registry access
## to self hosted registries like so:
docker_options: "--insecure-registry={{ kube_service_addresses }} --graph={{ docker_daemon_graph }} --iptables=false"
docker_options: "--insecure-registry={{ kube_service_addresses }} --graph={{ docker_daemon_graph }}"
# Settings for containerized control plane (etcd/kubelet/secrets)
etcd_deployment_type: docker

Loading…
Cancel
Save