449 Commits (57ee3042603bdc92737496dd51672c9f79a49819)

Author SHA1 Message Date
Aleksandr Didenko 3a39904011 Move calico-policy-controller into separate role 7 years ago
Matthew Mosesohn a52064184e Condense resolvconf sources before starting loop 7 years ago
Matthew Mosesohn a422ad0d50 More idempotency fixes 7 years ago
Matthew Mosesohn f6b72fa830 Make resolvconf preinstall idempotent 7 years ago
Vincent Schwarzer 026da060f2 Granular authentication Control 7 years ago
Matthew Mosesohn 804e9a09c0 Migrate k8s data to etcd3 api store 7 years ago
Matthew Mosesohn 52a6dd5427 Explicitly set cni-bin-dir 7 years ago
Brad Beam d04fbf3f78 Removing cloud_provider tag to fix scenario where cloud_provider is not defined 7 years ago
Matthew Mosesohn 54207877bd Add node labels in kubelet 7 years ago
Vincent Schwarzer b075960e3b Added Support for OpenID Connect Authentication 7 years ago
Matthew Mosesohn 45274560ec Disable vault role properly on ansible 2.2.0 7 years ago
Matthew Mosesohn d176818c44 Use find module for checking for certificates 7 years ago
Vincent Schwarzer 68e8d74545 Changes based on feedback (additional ansible checks) 7 years ago
Vincent Schwarzer fc054e21f6 Modified how adding LB for the Kube API is handled (AWS) 7 years ago
Vijay Katam a0b1eda1d0 Add support for atomic host 7 years ago
Sergii Golovatiuk 295103adc0 Allow to specify etcd backend for kube-api 7 years ago
Brad Beam bfff06d402 Adding KUBELET_CLOUDPROVIDER to kubelet.rkt.service 7 years ago
Brad Beam 30a9899262 Making openstack domain name optional 7 years ago
Xavier Lange dd10b8a27c Bug fix: support kilo's keystone requirement for domain-name, extracts from ENV var 7 years ago
Brad Beam dbf13290f5 Updating vsphere cloud provider support 7 years ago
Jan Jungnickel df476b0088 Initial support for vsphere as cloud provider 8 years ago
Brad Beam 56664b34a6 Lower default memory requests 7 years ago
Sergii Golovatiuk 00cfead9bb Increase SSL TTL to 3650 days 7 years ago
Bogdan Dobrelya f2a4619c57 Align LB defaults with the HA docs 7 years ago
Bogdan Dobrelya 712872efba Rework inventory all by real groups' vars 8 years ago
Ivan Shvedunov 0006e5ab45 Fix shell special vars 7 years ago
Abel Lopez 0bfc2d0f2f
Safe disable SELinux 7 years ago
Matthew Mosesohn a21eb036ee Add no_log to cert tar tasks 7 years ago
Andrew Greenwood ca9ea097df Cleanup legacy syntax, spacing, files all to yml 7 years ago
Vladimir Rutsky bff955ff7e Mount host's /var/log into kubelet container 7 years ago
Matthew Mosesohn 80c0e747a7 Fix references to CoreOS and Container Linux by CoreOS 7 years ago
Vladimir Rutsky a1ec6f401c fix load balancer DNS name index evaluation in openssl.conf 7 years ago
Brad Beam 4c891b8bb0 Adding support for proxy w/ rkt kubelet 7 years ago
Vladimir Rutsky 09847567ae set "check_mode: no" for read-only "shell" steps that registers result 7 years ago
Greg Althaus 2b10376339 When resolv.conf changes during host_resolvconf mode, we need to 7 years ago
Sergii Golovatiuk 5f4cc3e1de Replace always_run with check_mode 7 years ago
Sergii Golovatiuk aeadaa1184 Set ssl_ca_dirs for rkt based on fact 7 years ago
Matthew Mosesohn 2c532cb74d Disable kube_proxy_masquerade_all 7 years ago
Sergii Golovatiuk c07d60bc90 Kubernetes Reliability Improvements 7 years ago
Greg Althaus 3f0c13af8a Make kubelet_load_modules always present but false. 7 years ago
Greg Althaus fcd78eb1f7 Due to the nsenter and other reworks, it appears that 7 years ago
Mark Lee e414c25fd7 follow sysctl.conf file symlink if linked 7 years ago
Mark Lee 34a71554ae use ansible sysctl module for config ip forwarding 7 years ago
Josh Conant 245e05ce61 Vault security hardening and role isolation 7 years ago
Alexander Block 010fe30b53 Host mount /dev for kubelet 7 years ago
Matthew Mosesohn e5779ab786 Fix check for node-NODEID certs existence 7 years ago
Aleksandr Didenko 54af533b31 Update playbooks to support new netchecker 7 years ago
Matthew Mosesohn f3a0f73588 Prevent dynamic port allocation in nodePort range 7 years ago
Matthew Mosesohn fd30131dc2 Revert "Drop linux capabilities and rework users/groups" 7 years ago
Sergii Golovatiuk 585afef945 Remove nsenter workaround 7 years ago