66 Commits (361a5eac7e74b143f7261f0d86d9c5cfe35ae5b7)

Author SHA1 Message Date
Sergii Golovatiuk 674b71b535 Ansible 2.3 support 7 years ago
Matthew Mosesohn ae7f59e249 Skip vault cert task evaluation completely when using script cert generation 7 years ago
Matthew Mosesohn 5a5707159a Fix multiline condition for k8s check certs 7 years ago
Matthew Mosesohn a3f568fc64 restart scheduler and controller-manager too 7 years ago
Matthew Mosesohn 1887e984a0 Change wait for dnsmasq to skip if there are no kube-nodes in play 7 years ago
Matthew Mosesohn a422ad0d50 More idempotency fixes 7 years ago
Vincent Schwarzer 026da060f2 Granular authentication Control 7 years ago
Cesarini, Daniele 69636d2453 Adding /O=system:masters to admin certificate 7 years ago
Matthew Mosesohn 45274560ec Disable vault role properly on ansible 2.2.0 7 years ago
Matthew Mosesohn d176818c44 Use find module for checking for certificates 7 years ago
Sergii Golovatiuk 00cfead9bb Increase SSL TTL to 3650 days 7 years ago
Bogdan Dobrelya 712872efba Rework inventory all by real groups' vars 8 years ago
Matthew Mosesohn a21eb036ee Add no_log to cert tar tasks 7 years ago
Andrew Greenwood ca9ea097df Cleanup legacy syntax, spacing, files all to yml 7 years ago
Matthew Mosesohn 80c0e747a7 Fix references to CoreOS and Container Linux by CoreOS 7 years ago
Vladimir Rutsky a1ec6f401c fix load balancer DNS name index evaluation in openssl.conf 7 years ago
Vladimir Rutsky 09847567ae set "check_mode: no" for read-only "shell" steps that registers result 7 years ago
Josh Conant 245e05ce61 Vault security hardening and role isolation 7 years ago
Matthew Mosesohn e5779ab786 Fix check for node-NODEID certs existence 7 years ago
Matthew Mosesohn fd30131dc2 Revert "Drop linux capabilities and rework users/groups" 7 years ago
Sergii Golovatiuk 585afef945 Remove nsenter workaround 7 years ago
Matthew Mosesohn 08822ec684 Fix cert distribution at scale 7 years ago
Bogdan Dobrelya cb2e5ac776 Drop linux capabilities and rework users/groups 8 years ago
Greg Althaus 0d44599a63 Add explicit name printing in task names for deletgated task during 7 years ago
Greg Althaus 6c69da1573 This PR adds/or modifies a few tasks to allow for the playbook to 7 years ago
Greg Althaus 95bf380d07 If the inventory name of the host exceeds 63 characters, 7 years ago
Matthew Mosesohn 80703010bd Use only one certificate for all apiservers 7 years ago
Matthew Mosesohn 3f274115b0 Generate individual certificates for k8s hosts 8 years ago
Bogdan Dobrelya 5af2c42bde Better fix for different CoreOS os family facts 7 years ago
Bogdan Dobrelya f7447837c5 Rename CoreOS fact 7 years ago
Matthew Mosesohn 6d9cd2d720 Fix calico-rr to use etcd certs instead of kube certs 8 years ago
Aleksandr Didenko d57c27ffcf Add calico/routereflector support 8 years ago
Bogdan Dobrelya c75f394707 Address standalone kubelet config case 8 years ago
Bogdan Dobrelya 8cc84e132a Add tags 8 years ago
Matthew Mosesohn 46ee9faca9 Fix ca certificate loading on CoreOS 8 years ago
Matthew Mosesohn f106bf5bc4 adds ability to have hosts with no floating ips on terraform/openstack (+8 squashed commits) 8 years ago
Matthew Mosesohn c7b00caeaa Use tar+register instead of copy/slurp for distributing tokens and certs 8 years ago
Bogdan Dobrelya c59c3a1bcf Fix idempotency/recurrence of download and preinstall 8 years ago
Matthew Mosesohn 0e9d1e09e3 Sync master tokens only with those in play_hosts 8 years ago
Matthew Mosesohn 84052ff0b6 use nginx proxy on non-master nodes to proxy apiserver traffic 8 years ago
Matthew Mosesohn d9641771ed add kube-masters to SSL certificate 8 years ago
Bogdan Dobrelya 8168689caa Refactor roles and hosts 8 years ago
Paul Czarkowski d8bebcd201 Fix issue with check_certs playbook 8 years ago
Smana ae5ff890d4 fix flannel deployment, remove docker bridge before restarting 8 years ago
Smana 1884d89d3b fixes the certs issue when masters or not in the kube-node group 8 years ago
Spencer Smith 9f8466a186 ensure ALL certs are synced between masters 8 years ago
Spencer Smith 743ad0eb5c s/sync_certs/sync_tokens 8 years ago
Spencer Smith 5253b3ec13 ensure ca.pem makes it to multi-masters 8 years ago
Paul Czarkowski 5f2fa6d76f revert .gitignore for secrets 8 years ago
Paul Czarkowski 8f4e879ca7 Add native Vagrant support 8 years ago