53 Commits (0865bef3821c0c0ef5b5d2618b6d3300870df176)

Author SHA1 Message Date
rongzhang 5a4352657d Fix install audit failed 6 years ago
Erwan Miran 80cfeea957 psp, roles and rbs for PodSecurityPolicy when podsecuritypolicy_enabled is true 6 years ago
Erwan Miran fc38b6d0ca Ability to define custom audit polcy rules 6 years ago
Erwan Miran c34900e569 Define apiserver flags directly instead of relying on auditPolicy section in order to have the ability to redirect audit log to stdout with kubeadm 6 years ago
Erwan Miran 58d4d65fab minor variable fix and reuse + handle auditlog redirected to stdout 6 years ago
rongzhang 2ffc1afe40 Support audit 6 years ago
Robert Everson 4eadf3228e Only add admission plugins if defined 6 years ago
Robert Everson 99c5aa5a02 Use k8s default plugin list 6 years ago
Robert Everson 6ed65d762b Separate out plugins into 2 variables 6 years ago
Matthew Mosesohn 07cc981971
refactor vault role (#2733) 6 years ago
Suzuka Asagiri f81e6d2ccf
Add oidc-user-prefix and oidc-group-prefix args 6 years ago
Marcelo Grebois 88765f62e6
Updating order 6 years ago
Marcelo Grebois 4c12b273ac
Enabling MutatingAdmissionWebhook for Istio Automatic sidecar injection 6 years ago
Wong Hoi Sing Edison 195d6d791a Integrate jetstack/cert-manager 0.2.3 to Kubespray 6 years ago
mirwan ee8f678010 Addition of the .creds extension to the credentials files generated by password lookup in order for Ansible not to consider them as inventory files with inventory_ignore_extensions set accordingly (#2446) 6 years ago
Andreas Krüger 3d6fd49179 Added option for encrypting secrets to etcd v.2 (#2428) 6 years ago
Ayaz Ahmed Khan 89847d5684 Explicitly defines the --kubelet-preferred-address-types parameter 7 years ago
Maxim Krasilnikov 03c61685fb
Added apiserver extra args variable for kubeadm config (#2291) 6 years ago
mlushpenko 4e61fb9cd3 Refactored kubeadm join process and fixed uncrodonng for master nodes 6 years ago
Maxim Krasilnikov 95b8ac5f62 Added optional controller and scheduler extra args to kubeadm config (#2205) 6 years ago
Virgil Chereches a4d142368b Renamed variable from disable_volume_zone_conflict to volume_cross_zone_attachment and removed cloud provider condition; fix identation 6 years ago
Virgil Chereches 3125f93b3f Added disable_volume_zone_conflict variable 6 years ago
Matthew Mosesohn 6bb46e3ecb
Fix param names in preparation for Kubernetes v1.9.0 (#2098) 7 years ago
Steven Hardy d39a88d63f Allow setting --bind-address for apiserver hyperkube (#1985) 7 years ago
Chiang Fong Lee 5dc56df64e Fix ordering of kube-apiserver admission control plug-ins (#1841) 7 years ago
Matthew Mosesohn d487b2f927 Security best practice fixes (#1783) 7 years ago
Matthew Mosesohn ef47a73382 Add new addon Istio (#1744) 7 years ago
Matthew Mosesohn 6744726089 kubeadm support (#1631) 7 years ago
Brad Beam 8b151d12b9 Adding yamllinter to ci steps (#1556) 7 years ago
jwfang 092bf07cbf basic rbac support 7 years ago
gbolo 49be805001
allow admission control plug-ins to be easily customized 7 years ago
Spencer Smith 94596388f7 add ability for custom flags 7 years ago
Matthew Mosesohn 80828a7c77 use etcd2 when upgrading unless forced 7 years ago
Matthew Mosesohn e9a294fd9c Significantly reduce memory requirements 7 years ago
Vincent Schwarzer 026da060f2 Granular authentication Control 7 years ago
Matthew Mosesohn 804e9a09c0 Migrate k8s data to etcd3 api store 7 years ago
Vincent Schwarzer b075960e3b Added Support for OpenID Connect Authentication 7 years ago
Sergii Golovatiuk 295103adc0 Allow to specify etcd backend for kube-api 7 years ago
Sergii Golovatiuk c07d60bc90 Kubernetes Reliability Improvements 7 years ago
Matthew Mosesohn fd30131dc2 Revert "Drop linux capabilities and rework users/groups" 7 years ago
Bogdan Dobrelya cb2e5ac776 Drop linux capabilities and rework users/groups 8 years ago
Bogdan Dobrelya a56d9de502 Systemd units, limits, and bin path fixes 8 years ago
Bogdan Dobrelya c75f394707 Address standalone kubelet config case 8 years ago
Maciej Filipiak cc2f26b8e9 Add service-node-port-range parameter for kube-apiserver 8 years ago
Matthew Mosesohn a32cd85eb7 Add etcd TLS support 8 years ago
Bogdan Dobrelya c59c3a1bcf Fix idempotency/recurrence of download and preinstall 8 years ago
Bogdan Dobrelya 422428908a Download containers and save all 8 years ago
Bogdan Dobrelya 8168689caa Refactor roles and hosts 8 years ago