Browse Source

cleanup: replace node-role.kubernetes.io/master (#9627)

Signed-off-by: xin.li <xin.li@daocloud.io>

Signed-off-by: xin.li <xin.li@daocloud.io>
pull/9632/head
my-git9 1 year ago
committed by GitHub
parent
commit
85fa6af313
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 7 additions and 3 deletions
  1. 8
      roles/network_plugin/calico/templates/calico-apiserver.yml.j2
  2. 2
      roles/network_plugin/canal/templates/canal-calico-kube-controllers.yml.j2

8
roles/network_plugin/calico/templates/calico-apiserver.yml.j2

@ -1,4 +1,4 @@
# Policy to ensure the API server isn't cut off. Can be modified, but ensure
# Policy to ensure the API server isn't cut off. Can be modified, but ensure
# that the main API server is always able to reach the Calico API server.
kind: NetworkPolicy
apiVersion: networking.k8s.io/v1
@ -94,6 +94,8 @@ spec:
tolerations:
- effect: NoSchedule
key: node-role.kubernetes.io/master
- effect: NoSchedule
key: node-role.kubernetes.io/control-plane
volumes:
- name: calico-apiserver-certs
secret:
@ -104,8 +106,8 @@ spec:
apiVersion: v1
kind: ServiceAccount
metadata:
name: calico-apiserver
namespace: calico-apiserver
name: calico-apiserver
namespace: calico-apiserver
---

2
roles/network_plugin/canal/templates/canal-calico-kube-controllers.yml.j2

@ -31,6 +31,8 @@ spec:
operator: Exists
- key: node-role.kubernetes.io/master
effect: NoSchedule
- key: node-role.kubernetes.io/control-plane
effect: NoSchedule
serviceAccountName: calico-kube-controllers
priorityClassName: system-cluster-critical
# The controllers must run in the host network namespace so that

Loading…
Cancel
Save