2016-08-25 11:16:14 +02:00
|
|
|
# An experimental dev/test only dynamic volumes provisioner,
|
|
|
|
# for PetSets. Works for kube>=v1.3 only.
|
|
|
|
kube_hostpath_dynamic_provisioner: "false"
|
2016-10-24 15:11:52 +02:00
|
|
|
|
|
|
|
# change to 0.0.0.0 to enable insecure access from anywhere (not recommended)
|
|
|
|
kube_apiserver_insecure_bind_address: 127.0.0.1
|
|
|
|
|
2016-11-18 13:56:55 +01:00
|
|
|
# A port range to reserve for services with NodePort visibility.
|
|
|
|
# Inclusive at both ends of the range.
|
|
|
|
kube_apiserver_node_port_range: "30000-32767"
|
|
|
|
|
2016-11-09 13:44:41 +03:00
|
|
|
# ETCD cert dir for connecting apiserver to etcd
|
|
|
|
etcd_config_dir: /etc/ssl/etcd
|
|
|
|
etcd_cert_dir: "{{ etcd_config_dir }}/ssl"
|
|
|
|
|
2017-03-06 13:22:13 +03:00
|
|
|
# ETCD backend for k8s data
|
|
|
|
kube_apiserver_storage_backend: etcd3
|
|
|
|
|
2017-03-30 17:08:13 +04:00
|
|
|
# By default, force back to etcd2. Set to true to force etcd3 (experimental!)
|
|
|
|
force_etcd3: false
|
|
|
|
|
2016-12-23 15:44:44 +01:00
|
|
|
# Limits for kube components
|
|
|
|
kube_controller_memory_limit: 512M
|
|
|
|
kube_controller_cpu_limit: 250m
|
2017-03-23 12:11:30 +03:00
|
|
|
kube_controller_memory_requests: 100M
|
2016-12-23 15:44:44 +01:00
|
|
|
kube_controller_cpu_requests: 100m
|
2017-02-07 15:01:02 +01:00
|
|
|
kube_controller_node_monitor_grace_period: 40s
|
|
|
|
kube_controller_node_monitor_period: 5s
|
|
|
|
kube_controller_pod_eviction_timeout: 5m0s
|
2016-12-23 15:44:44 +01:00
|
|
|
kube_scheduler_memory_limit: 512M
|
|
|
|
kube_scheduler_cpu_limit: 250m
|
|
|
|
kube_scheduler_memory_requests: 170M
|
2017-03-23 12:11:30 +03:00
|
|
|
kube_scheduler_cpu_requests: 80m
|
2016-12-23 15:44:44 +01:00
|
|
|
kube_apiserver_memory_limit: 2000M
|
|
|
|
kube_apiserver_cpu_limit: 800m
|
|
|
|
kube_apiserver_memory_requests: 256M
|
2017-03-23 12:11:30 +03:00
|
|
|
kube_apiserver_cpu_requests: 100m
|
2017-02-27 13:24:21 +01:00
|
|
|
|
2017-04-16 22:03:45 -04:00
|
|
|
# Admission control plug-ins
|
|
|
|
kube_apiserver_admission_control:
|
|
|
|
- NamespaceLifecycle
|
|
|
|
- LimitRanger
|
|
|
|
- ServiceAccount
|
|
|
|
- DefaultStorageClass
|
|
|
|
- ResourceQuota
|
2017-02-27 14:15:50 +01:00
|
|
|
|
|
|
|
## Enable/Disable Kube API Server Authentication Methods
|
|
|
|
kube_basic_auth: true
|
|
|
|
kube_token_auth: true
|
|
|
|
kube_oidc_auth: false
|
|
|
|
|
2017-02-27 13:24:21 +01:00
|
|
|
## Variables for OpenID Connect Configuration https://kubernetes.io/docs/admin/authentication/
|
|
|
|
## To use OpenID you have to deploy additional an OpenID Provider (e.g Dex, Keycloak, ...)
|
2017-02-27 14:15:50 +01:00
|
|
|
|
2017-02-27 13:24:21 +01:00
|
|
|
#kube_oidc_url: https:// ...
|
|
|
|
# kube_oidc_client_id: kubernetes
|
|
|
|
## Optional settings for OIDC
|
|
|
|
# kube_oidc_ca_file: {{ kube_cert_dir }}/ca.pem
|
|
|
|
# kube_oidc_username_claim: sub
|
|
|
|
# kube_oidc_groups_claim: groups
|
2017-04-14 17:33:04 -04:00
|
|
|
|
|
|
|
##Variables for custom flags
|
|
|
|
apiserver_custom_flags: []
|
|
|
|
|
|
|
|
controller_mgr_custom_flags: []
|
|
|
|
|
|
|
|
scheduler_custom_flags: []
|