Browse Source
cleanup: replace node-role.kubernetes.io/master (#9627)
Signed-off-by: xin.li <xin.li@daocloud.io>
Signed-off-by: xin.li <xin.li@daocloud.io>
pull/9632/head
my-git9
1 year ago
committed by
GitHub
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with
7 additions and
3 deletions
-
roles/network_plugin/calico/templates/calico-apiserver.yml.j2
-
roles/network_plugin/canal/templates/canal-calico-kube-controllers.yml.j2
|
|
@ -1,4 +1,4 @@ |
|
|
|
# Policy to ensure the API server isn't cut off. Can be modified, but ensure |
|
|
|
# Policy to ensure the API server isn't cut off. Can be modified, but ensure |
|
|
|
# that the main API server is always able to reach the Calico API server. |
|
|
|
kind: NetworkPolicy |
|
|
|
apiVersion: networking.k8s.io/v1 |
|
|
@ -94,6 +94,8 @@ spec: |
|
|
|
tolerations: |
|
|
|
- effect: NoSchedule |
|
|
|
key: node-role.kubernetes.io/master |
|
|
|
- effect: NoSchedule |
|
|
|
key: node-role.kubernetes.io/control-plane |
|
|
|
volumes: |
|
|
|
- name: calico-apiserver-certs |
|
|
|
secret: |
|
|
@ -104,8 +106,8 @@ spec: |
|
|
|
apiVersion: v1 |
|
|
|
kind: ServiceAccount |
|
|
|
metadata: |
|
|
|
name: calico-apiserver |
|
|
|
namespace: calico-apiserver |
|
|
|
name: calico-apiserver |
|
|
|
namespace: calico-apiserver |
|
|
|
|
|
|
|
--- |
|
|
|
|
|
|
|
|
|
@ -31,6 +31,8 @@ spec: |
|
|
|
operator: Exists |
|
|
|
- key: node-role.kubernetes.io/master |
|
|
|
effect: NoSchedule |
|
|
|
- key: node-role.kubernetes.io/control-plane |
|
|
|
effect: NoSchedule |
|
|
|
serviceAccountName: calico-kube-controllers |
|
|
|
priorityClassName: system-cluster-critical |
|
|
|
# The controllers must run in the host network namespace so that |
|
|
|