|
|
@ -55,7 +55,7 @@ |
|
|
|
|
|
|
|
- name: kubeadm | aggregate all SANs |
|
|
|
set_fact: |
|
|
|
apiserver_sans: "{{ (sans_base + groups['kube-master'] + sans_lb + sans_lb_ip + sans_supp + sans_access_ip + sans_ip + sans_address) | unique }}" |
|
|
|
apiserver_sans: "{{ (sans_base + groups['kube-master'] + sans_lb + sans_lb_ip + sans_supp + sans_access_ip + sans_ip + sans_address + sans_override) | unique }}" |
|
|
|
vars: |
|
|
|
sans_base: |
|
|
|
- "kubernetes" |
|
|
@ -71,6 +71,7 @@ |
|
|
|
sans_access_ip: "{{ groups['kube-master'] | map('extract', hostvars, 'access_ip') | list | select('defined') | list }}" |
|
|
|
sans_ip: "{{ groups['kube-master'] | map('extract', hostvars, 'ip') | list | select('defined') | list }}" |
|
|
|
sans_address: "{{ groups['kube-master'] | map('extract', hostvars, ['ansible_default_ipv4', 'address']) | list | select('defined') | list }}" |
|
|
|
sans_override: "{{ [kube_override_hostname] if kube_override_hostname is defined else [] }}" |
|
|
|
tags: facts |
|
|
|
|
|
|
|
- name: Create audit-policy directory |
|
|
|