Browse Source

Add containerd_extra_args (#7461)

* Add containerd_extra_args

This is useful for custom containerd config, e.g. auth

Signed-off-by: Zhong Jianxin <azuwis@gmail.com>

* Make containerd config.toml mode 0640

It may contain sensitive information like password

Signed-off-by: Zhong Jianxin <azuwis@gmail.com>
pull/7492/head
Zhong Jianxin 4 years ago
committed by GitHub
parent
commit
420a412234
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 8 additions and 1 deletions
  1. 3
      roles/container-engine/containerd/defaults/main.yml
  2. 2
      roles/container-engine/containerd/tasks/main.yml
  3. 4
      roles/container-engine/containerd/templates/config.toml.j2

3
roles/container-engine/containerd/defaults/main.yml

@ -64,3 +64,6 @@ containerd_fedora_repo_base_url: "https://download.docker.com/linux/fedora/{{ an
containerd_fedora_repo_gpgkey: "https://download.docker.com/linux/fedora/gpg"
containerd_fedora_repo_repokey: "9DC858229FC7DD38854AE2D88D81803C0EBFCD88"
containerd_fedora_repo_component: "stable"
# Extra config to be put in {{ containerd_cfg_dir }}/config.toml literally
containerd_extra_args: ''

2
roles/container-engine/containerd/tasks/main.yml

@ -79,7 +79,7 @@
src: config.toml.j2
dest: "{{ containerd_cfg_dir }}/config.toml"
owner: "root"
mode: 0644
mode: 0640
notify: restart containerd
# This is required to ensure any apt upgrade will not break kubernetes

4
roles/container-engine/containerd/templates/config.toml.j2

@ -39,3 +39,7 @@ version = 2
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."{{ registry }}"]
endpoint = ["{{ ([ addr ] | flatten ) | join('","') }}"]
{% endfor %}
{% if containerd_extra_args is defined %}
{{ containerd_extra_args }}
{% endif %}
Loading…
Cancel
Save