377 Commits (2d65554cb9212ab9d0f3af3cd774635c567d9ce8)

Author SHA1 Message Date
Sergii Golovatiuk 5f4cc3e1de Replace always_run with check_mode 7 years ago
Sergii Golovatiuk aeadaa1184 Set ssl_ca_dirs for rkt based on fact 7 years ago
Matthew Mosesohn 2c532cb74d Disable kube_proxy_masquerade_all 7 years ago
Sergii Golovatiuk c07d60bc90 Kubernetes Reliability Improvements 7 years ago
Greg Althaus 3f0c13af8a Make kubelet_load_modules always present but false. 7 years ago
Greg Althaus fcd78eb1f7 Due to the nsenter and other reworks, it appears that 7 years ago
Mark Lee e414c25fd7 follow sysctl.conf file symlink if linked 7 years ago
Mark Lee 34a71554ae use ansible sysctl module for config ip forwarding 7 years ago
Josh Conant 245e05ce61 Vault security hardening and role isolation 7 years ago
Alexander Block 010fe30b53 Host mount /dev for kubelet 7 years ago
Matthew Mosesohn e5779ab786 Fix check for node-NODEID certs existence 7 years ago
Aleksandr Didenko 54af533b31 Update playbooks to support new netchecker 7 years ago
Matthew Mosesohn f3a0f73588 Prevent dynamic port allocation in nodePort range 7 years ago
Matthew Mosesohn fd30131dc2 Revert "Drop linux capabilities and rework users/groups" 7 years ago
Sergii Golovatiuk 585afef945 Remove nsenter workaround 7 years ago
Greg Althaus 923057c1a8 This continues the DHCP hook checks. Also protect the create side 7 years ago
Matthew Mosesohn 08822ec684 Fix cert distribution at scale 7 years ago
Tyler Britten f8ffa1601d Fixed for non-null output 7 years ago
Tyler Britten da01bc1fbb Updated OpenStack vars to check for tenant_id (v2) and project_id (v3) 7 years ago
Xavier Lange e5fdc63bdd Bugfix: skip cloud_config on etcd 7 years ago
Bogdan Dobrelya cb2e5ac776 Drop linux capabilities and rework users/groups 8 years ago
Greg Althaus 0d44599a63 Add explicit name printing in task names for deletgated task during 7 years ago
Matthew Mosesohn b6c3e61603 Fix setting resolvconf when using rkt deploy mode 7 years ago
Matthew Mosesohn b2a27ed089 Fix bash completion installation 7 years ago
Greg Althaus 6905edbeb6 Add a variable that defaults to kube_apiserver_port that defines 7 years ago
Greg Althaus 6c69da1573 This PR adds/or modifies a few tasks to allow for the playbook to 7 years ago
Greg Althaus 95bf380d07 If the inventory name of the host exceeds 63 characters, 7 years ago
Matthew Mosesohn 80703010bd Use only one certificate for all apiservers 7 years ago
Alexander Block 1054f37765 Don't try to delete kargo specific config from dhclient when file does not exist 7 years ago
Greg Althaus f77257cf79 When running on CentOS7 image in AWS with selinux on, the order of 7 years ago
Alexander Block a7bf7867d7 Add tasks to undo changes to hosts /etc/resolv.conf and dhclient configs 7 years ago
Matthew Mosesohn 3f274115b0 Generate individual certificates for k8s hosts 8 years ago
Brad Beam db8173da28 Adding /opt/cni /etc/cni to rkt run kubelet 7 years ago
Matthew Mosesohn e22f938ae5 Bind nginx localhost proxy to localhost 7 years ago
Alexander Block 1d2a18b355 Introduce dns_mode and resolvconf_mode and implement docker_dns mode 8 years ago
Spencer Smith 4a59340182 remove assertion for family not being CoreOS 7 years ago
Bogdan Dobrelya 5af2c42bde Better fix for different CoreOS os family facts 7 years ago
Bogdan Dobrelya f7447837c5 Rename CoreOS fact 7 years ago
Brad Beam 4b6f29d5e1 Adding kubelet in rkt 8 years ago
Alexander Block ab7df10a7d Upgrade docker version and do some cleanups for unsupported distros/docker versions 7 years ago
Bogdan Dobrelya 97f96a6376 Fix etc hosts for cluster nodes 7 years ago
Bogdan Dobrelya 58062be2a3 Drop non systemd OS types support 7 years ago
Bogdan Dobrelya a56d9de502 Systemd units, limits, and bin path fixes 8 years ago
Matthew Mosesohn 6d9cd2d720 Fix calico-rr to use etcd certs instead of kube certs 8 years ago
Bogdan Dobrelya 79996b557b Rework ignore_errors to report no reds 8 years ago
Bogdan Dobrelya bb0c3537cb Do not forward bogus domains for upstream resolvers 8 years ago
Matthew Mosesohn ad796d188d Individual etcd ssl certs 8 years ago
Alexander Block 8e4e3998dd Fix wrong path of dhclient on CentOS+Azure 8 years ago
Alexander Block fe150d4e4d Register master node as unschedulable 8 years ago
Bogdan Dobrelya 1782d19e1f Fallback to default resolver if no nameservers 8 years ago