Ilya Margolin
262c96ec0b
Remove duplication in template ( #9301 )
by concatenating default and additional runtimes
2 years ago
Mohamed Zaian
2acdc33aa1
[helm] upgrade to 3.9.4 ( #9298 )
2 years ago
Krystian Młynek
8acd33d0df
Calico: add wireguard support for Rocky Linux 9 ( #9287 )
2 years ago
pingrulkin
a2e23c1a71
vsphere-csi: add nodeAffinity to daemonset ( #9293 )
2 years ago
rtsp
1b5cc175b9
[cert-manager] Upgrade to v1.9.1 ( #9295 )
2 years ago
Mohamed Zaian
a71da25b57
[argocd] update argocd to v2.4.12 ( #9297 )
2 years ago
Vadim
5ac614f97d
fix duplicate field in ingress-nginx template ( #9285 )
2 years ago
ErmalKristo
b8b8b82ff4
Adds support for multiple architectures to yq ( #9288 )
2 years ago
Necatican Yıldırım
7da3dbcb39
Cilium 1.12 Upgrade ( #9225 )
* Drop support for Cilium < 1.10
Signed-off-by: necatican <necaticanyildirim@gmail.com>
* Synchronize Cilium templates for 1.11.7
Signed-off-by: necatican <contact@necatican.com>
* Set Cilium v1.12.1 as the default version
Signed-off-by: necatican <contact@necatican.com>
Signed-off-by: necatican <necaticanyildirim@gmail.com>
Signed-off-by: necatican <contact@necatican.com>
2 years ago
Mohamed Zaian
680293e79c
[kubernetes] Add hashes for 1.24.5, 1.22.14, 1.23.11 and make v1.24.5 default ( #9286 )
2 years ago
Mahdi Abbasi
023b16349e
Add variable for the vsphere-csi namespace ( #9278 )
2 years ago
lijin-union
c4976437a8
Fix typos in docs ( #9276 )
2 years ago
Kay Yan
97ca2f3c78
add-timezone-support ( #9263 )
2 years ago
niesel
e76385e7cd
Update offline.yml ( #9274 )
Change "ubuntu_repo" to "debian_repo" for containerd_debian_repo_base_url and containerd_debian_repo_gpgkey
2 years ago
ERIK
7c2fb227f4
Add LimitMEMLOCK parameter configuration in containerd.service ( #9269 )
Signed-off-by: bo.jiang <bo.jiang@daocloud.io>
Signed-off-by: bo.jiang <bo.jiang@daocloud.io>
2 years ago
ghostloda
08bfa0b18f
Upgrade ingress nginx webhook to 1.3.0 ( #9271 )
2 years ago
Ho Kim
952cad8d63
Remove mutual exclusivity in calico: NAT and router mode ( #9255 )
* Add optional NAT support in calico router mode
* Add a blank line in front of lists
* Remove mutual exclusivity: NAT and router mode
* Ignore router mode from NAT
* Update calico doc
2 years ago
rptaylor
5bce39abf8
add optional parameter extra_groups for k8s_nodes ( #9211 )
2 years ago
cleverhu
fc57c0b27e
fix number node name can't be added ( #9266 )
Signed-off-by: cleverhu <shouping.hu@daocloud.io>
Signed-off-by: cleverhu <shouping.hu@daocloud.io>
2 years ago
Samuel Liu
dd4bc5fbfe
[etcd] Sometimes, we do not need to run etcd role on all nodes. ( #9173 )
* WIP: sometimes,we not run etcd
* fix ansible lint
* like calico(kdd) cni, no need run etcd
2 years ago
Mohamed Zaian
d2a7434c67
[ingress-nginx] upgrade to 1.3.1 ( #9264 )
2 years ago
Kenichi Omichi
5fa885b150
Remove unused cri_dockerd_enabled configuration ( #9259 )
Since the commit fad296616c
cri_dockerd_enabled
has not been used. But the packet_ubuntu22-aio-docker.yml still contains
the configuration and causes confusions.
This removes the configuration for cleanup.
2 years ago
ghostloda
f3fb758f0c
Remove useless file ( #9258 )
2 years ago
Krystian Młynek
6386ec029c
add retries for restart of kube-apiserver ( #9256 )
* add retries for restart of kube-apiserver
* change var name
2 years ago
Ho Kim
ad7cefa352
Ignore deleting nodes that are not in cluster ( #9244 )
2 years ago
Ho Kim
09d9bc910e
Fix typos in calico comments ( #9254 )
2 years ago
Kay Yan
e2f1f8d69d
add-Rocky-9-support ( #9212 )
2 years ago
Michael Schmitz
be2bfd867c
Add Support for Rewrite Plugin to CoreDNS/NodelocalDNS ( #9245 )
2 years ago
lou-lan
133a7a0e1b
Add featureDetectOverride configration of calico ( #9249 )
2 years ago
ERIK
efb47edb9f
Update kubespray version to v2.19.1 ( #9241 )
Signed-off-by: bo.jiang <bo.jiang@daocloud.io>
Signed-off-by: bo.jiang <bo.jiang@daocloud.io>
2 years ago
Kay Yan
36bec19a84
add-yankay-to-reviewers ( #9247 )
2 years ago
Cristian Calin
6db6c8678c
disable kubelet_authorization_mode_webhook by default ( #9238 )
2 years ago
Florian Ruynat
5603f9f374
Update security contacts file ( #9235 )
2 years ago
蒋航
7ebb8c3f2e
make calico installation more stable ( #9227 )
Signed-off-by: hang.jiang <hang.jiang@daocloud.io>
Signed-off-by: hang.jiang <hang.jiang@daocloud.io>
2 years ago
Alessio Greggi
acb6f243fd
feat: add kubelet systemd service hardening option ( #9194 )
* feat: add kubelet systemd service hardening option
* refactor: move variable name to kubelet_secure_addresses
Co-authored-by: Cristian Calin <6627509+cristicalin@users.noreply.github.com>
* docs: add diagram about kubelet_secure_addresses variable
Co-authored-by: Cristian Calin <6627509+cristicalin@users.noreply.github.com>
2 years ago
tasekida
220f149299
Fix abort because calicoctl.sh is not a full path ( #9217 )
2 years ago
Florian Ruynat
1baabb3c05
Fix cloud_init files for different distros ( #9232 )
2 years ago
Florian Ruynat
617b17ad46
Fix kube_ovn_hw_offload value ( #9218 )
2 years ago
lijin-union
8af86e4c1e
Fix typo.
2 years ago
kakkotetsu
9dc9a670a5
add runc v1.1.4 ( #9230 )
2 years ago
Kay Yan
b46ddf35fc
kube-vip shoud fail if kube_proxy_strict_arp is false in arp mod ( #9223 )
* fix-kube-vip-strict-arp
* fix-kube-vip-strict-arp
2 years ago
Chad Swenson
de762400ad
Fixes for calico_datastore: etcd ( #9228 )
It seems that PR #8839 broke `calico_datastore: etcd` when it removed ipamconfig support for etcd mode.
This PR fixes some failing tasks when `calico_datastore == etcd`, but it does not restore ipamconfig support for calico in etcd mode. If someone wants to restore ipamconfig support for `calico_datastore: etcd` please submit a follow up PR for that.
2 years ago
Cristian Calin
e60ece2b5e
[CI] remove opensuse Leap from molecule test blocking CI ( #9229 )
2 years ago
Cristian Calin
e6976a54e1
add pre-commit hook to facilitate local testing ( #9158 )
* add pre-commit hook configuration
* add tmp.md to .gitignore
* describe the use of pre-commit hook in CONTRIBUTING.md
* fix docs/integration.md errors identified by markdownlint
* fix docs/<file>.md errors identified by markdownlint
* docs/azure-csi.md
* docs/azure.md
* docs/bootstrap-os.md
* docs/calico.md
* docs/debian.md
* docs/fcos.md
* docs/vagrant.md
* docs/gcp-lb.md
* docs/kubernetes-apps/registry.md
* docs/setting-up-your-first-cluster.md
* docs/vagrant.md
* docs/vars.md
* fix contrib/<file>.md errors identified by markdownlint
2 years ago
Krystian Młynek
64daaf1887
cri-dockerd: add restart of docker.service ( #9205 )
* cri-dockerd: add restart of docker.service
* remove enabling of cri-dockerd.socket
2 years ago
Sergey
1c75ec9ec1
do not run etcd role in scale.yml playbook when etcd installed by kubeadm ( #9210 )
2 years ago
Shelming.Song
c8a61ec98c
optimize the format of evictionHard in kubelet-config.yaml template ( #9204 )
2 years ago
Bishal das
aeeae76750
Update vars.md ( #9172 )
2 years ago
Shelming.Song
30b062fd43
fix one bug in docs/nodes ( #9203 )
2 years ago
Pavel Chekin
8f899a1101
Fix containerd (<1.7) configuration for insecure registries ( #9207 )
For the following configuration
```
containerd_insecure_registries:
docker.io:
- dockerhubcache.example.com
```
the rendered /etc/containerd/config.toml contains
```
[plugins."io.containerd.grpc.v1.cri".registry.configs."docker.io".tls]
insecure_skip_verify = true
```
but it needs to be
```
[plugins."io.containerd.grpc.v1.cri".registry.configs."dockerhubcache.example.com".tls]
insecure_skip_verify = true
```
2 years ago