Browse Source

Revert "no need to patch system:kube-dns"

This reverts commit c2ea8c588a.
pull/1382/head
jwfang 7 years ago
parent
commit
83deecb9e9
1 changed files with 17 additions and 0 deletions
  1. 17
      roles/kubernetes-apps/ansible/tasks/main.yml

17
roles/kubernetes-apps/ansible/tasks/main.yml

@ -26,6 +26,23 @@
- rbac_enabled or item.type not in kubedns_rbac_resources
tags: dnsmasq
# see https://github.com/kubernetes/kubernetes/issues/45084
# TODO: this is only needed for "old" kube-dns
- name: Kubernetes Apps | Patch system:kube-dns ClusterRole
command: >
{{bin_dir}}/kubectl patch clusterrole system:kube-dns
--patch='{
"rules": [
{
"apiGroups" : [""],
"resources" : ["endpoints", "services"],
"verbs": ["list", "watch", "get"]
}
]
}'
when: dns_mode != 'none' and inventory_hostname == groups['kube-master'][0] and rbac_enabled
tags: dnsmasq
- name: Kubernetes Apps | Start Resources
kube:
name: "{{item.item.name}}"

Loading…
Cancel
Save