26 Commits (99c139dd5abde26b621c938cd6869cdc86a2a015)

Author SHA1 Message Date
Erwan Miran 2ab2f3a0a3 Ability to define SSL certificates duration and SSL key size (#3482) 6 years ago
Dylan 30132d8c35 Removed hostname truncation. (#3409) 6 years ago
Chad Swenson d87b6fd9f3 Use dedicated front-proxy-ca for front-proxy-client 6 years ago
georgejdli c8f857eae4 configure kubespray to sign service account tokens with a dedicated and stable key 6 years ago
Sergey Bondarev f8fed0f308 change expirations period for generated certificate from 10 years to 100 years 6 years ago
woopstar 4dab92ce69 Rename from aggregator-proxy-client to front-proxy-client to match kubeadm design. Added kubeadm support too. Changed to use variables set and not hardcode paths. Still missing cert generation for Vault 6 years ago
woopstar b2d30d68e7 Rename CN for aggreator back. Add flags to apiserver when version is >= 1.9 6 years ago
woopstar 82d10b882c Added fixes from whereismyjetpack 6 years ago
woopstar 0b4168cad4 WIP. Adding metrics-server support for K8s version 1.9 6 years ago
Matthew Mosesohn fe81bba08d Force kubelet certificates to be generated as lowercase (#1886) 7 years ago
neith00 77f1d4b0f1 Revert "Update roadmap" (#1809) 7 years ago
Matthew Mosesohn d9879d8026 Update roadmap (#1795) 7 years ago
Matthew Mosesohn f14f04c5ea Upgrade to kubernetes v1.8.0 (#1730) 7 years ago
Matthew Mosesohn 13d08af054 Fix upgrade for canal and apiserver cert 7 years ago
Matthew Mosesohn df28db0066 Fix cert and netchecker upgrade issues (#1543) 7 years ago
jwfang 092bf07cbf basic rbac support 7 years ago
Cesarini, Daniele 69636d2453 Adding /O=system:masters to admin certificate 7 years ago
Sergii Golovatiuk 00cfead9bb Increase SSL TTL to 3650 days 7 years ago
Matthew Mosesohn fd30131dc2 Revert "Drop linux capabilities and rework users/groups" 7 years ago
Bogdan Dobrelya cb2e5ac776 Drop linux capabilities and rework users/groups 8 years ago
Greg Althaus 95bf380d07 If the inventory name of the host exceeds 63 characters, 8 years ago
Matthew Mosesohn 80703010bd Use only one certificate for all apiservers 8 years ago
Matthew Mosesohn 3f274115b0 Generate individual certificates for k8s hosts 8 years ago
Matthew Mosesohn 84052ff0b6 use nginx proxy on non-master nodes to proxy apiserver traffic 8 years ago
Paul Czarkowski 5f2fa6d76f revert .gitignore for secrets 8 years ago
Paul Czarkowski 8f4e879ca7 Add native Vagrant support 8 years ago
Smana 4f627baf71 generate secrets on first master 8 years ago
Smana 91fca69aa0 generate secrets on deployment machine 8 years ago