parent
eb00693325
commit
da86457cda
2 changed files with 0 additions and 12 deletions
|
@ -95,17 +95,6 @@ kube_apiserver_memory_requests: 256M
|
||||||
kube_apiserver_cpu_requests: 100m
|
kube_apiserver_cpu_requests: 100m
|
||||||
kube_apiserver_request_timeout: "1m0s"
|
kube_apiserver_request_timeout: "1m0s"
|
||||||
|
|
||||||
# 1.9 and below Admission control plug-ins
|
|
||||||
kube_apiserver_admission_control:
|
|
||||||
- NamespaceLifecycle
|
|
||||||
- LimitRanger
|
|
||||||
- ServiceAccount
|
|
||||||
- DefaultStorageClass
|
|
||||||
- PersistentVolumeClaimResize
|
|
||||||
- MutatingAdmissionWebhook
|
|
||||||
- ValidatingAdmissionWebhook
|
|
||||||
- ResourceQuota
|
|
||||||
|
|
||||||
# 1.10+ admission plugins
|
# 1.10+ admission plugins
|
||||||
kube_apiserver_enable_admission_plugins: []
|
kube_apiserver_enable_admission_plugins: []
|
||||||
|
|
||||||
|
|
|
@ -61,7 +61,6 @@
|
||||||
|
|
||||||
- name: Disable SecurityContextDeny admission-controller and enable PodSecurityPolicy
|
- name: Disable SecurityContextDeny admission-controller and enable PodSecurityPolicy
|
||||||
set_fact:
|
set_fact:
|
||||||
kube_apiserver_admission_control: "{{ kube_apiserver_admission_control | default([]) | difference(['SecurityContextDeny']) | union(['PodSecurityPolicy']) | unique }}"
|
|
||||||
kube_apiserver_enable_admission_plugins: "{{ kube_apiserver_enable_admission_plugins | difference(['SecurityContextDeny']) | union(['PodSecurityPolicy']) | unique }}"
|
kube_apiserver_enable_admission_plugins: "{{ kube_apiserver_enable_admission_plugins | difference(['SecurityContextDeny']) | union(['PodSecurityPolicy']) | unique }}"
|
||||||
when: podsecuritypolicy_enabled
|
when: podsecuritypolicy_enabled
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue