File tree 1 file changed +5
-1
lines changed
salt/metalk8s/kubernetes/apiserver
1 file changed +5
-1
lines changed Original file line number Diff line number Diff line change @@ -85,17 +85,21 @@ Create kube-apiserver Pod manifest:
85
85
- kube- apiserver
86
86
- -- advertise- address={{ host }}
87
87
- -- allow- privileged=true
88
+ - -- anonymous- auth=false
88
89
- -- authorization- mode=Node,RBAC
89
90
- -- client- ca- file =/ etc/ kubernetes/ pki/ ca.crt
90
- - -- enable- admission- plugins=NodeRestriction
91
+ - -- disable- admission- plugins=DenyServiceExternalIPs
92
+ - -- enable- admission- plugins=NodeRestriction,AlwaysPullImages
91
93
- -- enable- bootstrap- token- auth=true
92
94
- -- etcd- cafile=/ etc/ kubernetes/ pki/ etcd/ ca.crt
93
95
- -- etcd- certfile={{ certificates.client.files[' apiserver-etcd' ].path }}
94
96
- -- etcd- keyfile=/ etc/ kubernetes/ pki/ apiserver- etcd- client.key
95
97
- -- etcd- servers={{ etcd_servers | join(" ," ) }}
98
+ - -- kubelet- certificate- authority=/ etc/ kubernetes/ pki/ ca.crt
96
99
- -- kubelet- client- certificate={{ certificates.client.files[' apiserver-kubelet' ].path }}
97
100
- -- kubelet- client- key=/ etc/ kubernetes/ pki/ apiserver- kubelet- client.key
98
101
- -- kubelet- preferred- address- types=InternalIP,ExternalIP,Hostname
102
+ - -- profiling=false
99
103
- -- proxy- client- cert- file ={{ certificates.client.files[' front-proxy' ].path }}
100
104
- -- proxy- client- key- file =/ etc/ kubernetes/ pki/ front- proxy- client.key
101
105
- -- requestheader- allowed- names=front- proxy- client
You can’t perform that action at this time.
0 commit comments