KubeZero/charts/kubeadm/templates/ClusterConfiguration.yaml

94 lines
3.8 KiB
YAML
Raw Normal View History

2021-01-03 15:33:13 +00:00
apiVersion: kubeadm.k8s.io/v1beta2
kind: ClusterConfiguration
metadata:
name: kubezero-clusterconfiguration
2021-05-28 15:16:36 +00:00
kubernetesVersion: {{ .Chart.Version }}
2021-01-03 15:33:13 +00:00
clusterName: {{ .Values.clusterName }}
2021-05-28 15:16:36 +00:00
controlPlaneEndpoint: {{ .Values.api.endpoint }}
2021-01-03 15:33:13 +00:00
networking:
podSubnet: 10.244.0.0/16
etcd:
local:
extraArgs:
2021-05-28 15:16:36 +00:00
### DNS discovery
#discovery-srv: {{ .Values.domain }}
#discovery-srv-name: {{ .Values.clusterName }}
#initial-cluster:
initial-cluster-token: etcd-{{ .Values.clusterName }}
listen-metrics-urls: "http://{{ .Values.listenAddress }}:2381"
logger: "zap"
# log-level: "warn"
2021-05-28 15:16:36 +00:00
{{- with .Values.etcd.extraArgs }}
2021-01-03 15:33:13 +00:00
{{- toYaml . | nindent 6 }}
{{- end }}
2021-05-28 15:16:36 +00:00
# These will only be used to create the etcd certs but removed for Init/Join kudeadm calls allowing us to sneak in aliases for etcd nodes
serverCertSANs:
- "{{ .Values.listenAddress }}"
2021-05-28 15:16:36 +00:00
- "{{ .Values.etcd.nodeName }}"
- "{{ .Values.etcd.nodeName }}.{{ .Values.domain }}"
- "{{ .Values.domain }}"
peerCertSANs:
- "{{ .Values.listenAddress }}"
2021-05-28 15:16:36 +00:00
- "{{ .Values.etcd.nodeName }}"
- "{{ .Values.etcd.nodeName }}.{{ .Values.domain }}"
- "{{ .Values.domain }}"
2021-01-03 15:33:13 +00:00
controllerManager:
extraArgs:
profiling: "false"
bind-address: {{ .Values.listenAddress }}
2021-01-03 15:33:13 +00:00
terminated-pod-gc-threshold: "300"
2021-06-29 15:39:44 +00:00
# leader-elect: {{ .Values.highAvailable | quote }}
logging-format: json
feature-gates: {{ include "kubeadm.featuregates" ( dict "return" "csv" "platform" .Values.platform ) | trimSuffix "," | quote }}
2021-01-03 15:33:13 +00:00
scheduler:
extraArgs:
profiling: "false"
bind-address: {{ .Values.listenAddress }}
2021-06-29 15:39:44 +00:00
# leader-elect: {{ .Values.highAvailable | quote }}
logging-format: json
feature-gates: {{ include "kubeadm.featuregates" ( dict "return" "csv" "platform" .Values.platform ) | trimSuffix "," | quote }}
2021-01-03 15:33:13 +00:00
apiServer:
certSANs:
2021-05-28 15:16:36 +00:00
- {{ regexSplit ":" .Values.api.endpoint -1 | first }}
2021-01-03 15:33:13 +00:00
extraArgs:
2021-06-29 15:39:44 +00:00
etcd-servers: {{ .Values.api.allEtcdEndpoints }}
2021-01-03 15:33:13 +00:00
profiling: "false"
audit-log-path: "/var/log/kubernetes/audit.log"
audit-policy-file: /etc/kubernetes/apiserver/audit-policy.yaml
audit-log-maxage: "7"
audit-log-maxsize: "100"
audit-log-maxbackup: "3"
audit-log-compress: "true"
bind-address: {{ .Values.listenAddress }}
2021-01-03 15:33:13 +00:00
tls-cipher-suites: "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
admission-control-config-file: /etc/kubernetes/apiserver/admission-configuration.yaml
{{- if eq .Values.platform "aws" }}
2021-06-29 15:39:44 +00:00
service-account-issuer: "{{ .Values.serviceAccountIssuer }}"
service-account-jwks-uri: "{{ .Values.serviceAccountIssuer }}/openid/v1/jwks"
api-audiences: "istio-ca,sts.amazonaws.com"
2021-01-04 14:56:41 +00:00
authentication-token-webhook-config-file: /etc/kubernetes/apiserver/aws-iam-authenticator.yaml
2021-06-29 15:39:44 +00:00
{{- else }}
api-audiences: "istio-ca"
{{- end }}
feature-gates: {{ include "kubeadm.featuregates" ( dict "return" "csv" "platform" .Values.platform ) | trimSuffix "," | quote }}
# for 1.21
# enable-admission-plugins: DenyServiceExternalIPs,NodeRestriction,EventRateLimit
2021-01-03 15:33:13 +00:00
enable-admission-plugins: NodeRestriction,EventRateLimit
2021-06-29 15:39:44 +00:00
# {{- if .Values.highAvailable }}
# goaway-chance: ".001"
# {{- end }}
logging-format: json
2021-05-28 15:16:36 +00:00
{{- with .Values.api.extraArgs }}
2021-01-03 15:33:13 +00:00
{{- toYaml . | nindent 4 }}
{{- end }}
extraVolumes:
- name: kubezero-apiserver
hostPath: /etc/kubernetes/apiserver
mountPath: /etc/kubernetes/apiserver
readOnly: true
pathType: DirectoryOrCreate
- name: audit-log
hostPath: /var/log/kubernetes
mountPath: /var/log/kubernetes
pathType: DirectoryOrCreate