Robin Wallace
|
42fc71fafa
|
[PodSecurityPolicy] Move the install of psp (#8744)
|
2022-05-09 09:21:19 -07:00 |
|
Joel Seguillon
|
4c1e0b188d
|
Add .editorconfig file (#6307)
|
2020-06-29 12:39:59 -07:00 |
|
Wang Zhen
|
d62836f2ab
|
Replace seccomp profile docker/default with runtime/default (#6170)
Signed-off-by: Wang Zhen <lazybetrayer@gmail.com>
|
2020-05-27 14:02:02 -07:00 |
|
Pasquale Toscano
|
00efc63f74
|
Customize PodSecurityPolicies from inventory (#5920)
* Customize PodSecurityPolicies from inventory
* Fixed yaml indentation
|
2020-04-15 03:18:02 -07:00 |
|
Florian Ruynat
|
b5125e59ab
|
update rbac.authorization.k8s.io to non deprecated api-groups (#5517)
|
2020-04-14 13:14:04 -07:00 |
|
Anshul Sharma
|
79a6b72a13
|
Removed deprecated label kubernetes.io/cluster-service (#5372)
|
2020-03-30 01:19:53 -07:00 |
|
刘旭
|
de9443a694
|
remove unused code (#4981)
|
2019-07-16 01:39:24 -07:00 |
|
rptaylor
|
5bec2edaf7
|
remove namespace from ClusterRole (#4856)
|
2019-06-10 11:15:12 -07:00 |
|
Matthew Mosesohn
|
f504d0ea99
|
Remove invalid field dnsPolicy from podSecurityPolicy (#4863)
Change-Id: I02864011bf5fda5dbd35c7513c73875769036f87
|
2019-06-10 07:11:10 -07:00 |
|
Andreas Krüger
|
818aa7aeb1
|
Set dnsPolicy to ClusterFirstWithHostNet when hostNetwork is true (#4843)
|
2019-06-05 03:17:55 -07:00 |
|
Erwan Miran
|
b15e685a0b
|
sysctl related PodSecurityPolicy spec since 1.12 (#3743)
|
2018-11-26 00:13:51 -08:00 |
|
Erwan Miran
|
80cfeea957
|
psp, roles and rbs for PodSecurityPolicy when podsecuritypolicy_enabled is true
|
2018-08-22 18:16:13 +02:00 |
|
Matthew Mosesohn
|
03bcfa7ff5
|
Stop templating kube-system namespace and creating it (#2545)
Kubernetes makes this namespace automatically, so there is
no need for kubespray to manage it.
|
2018-03-30 14:29:13 +03:00 |
|
MQasimSarfraz
|
9a4aa4288c
|
Fix vsphere cloud_provider RBAC permissions
|
2018-03-12 18:07:08 +00:00 |
|
chadswen
|
b0ab92c921
|
Prefix system:node CRB
Change the name of `system:node` CRB to `kubespray:system:node` to avoid
conflicts with the auto-reconciled CRB also named `system:node`
Fixes #2121
|
2018-03-08 23:56:46 -06:00 |
|
Jonas Kongslund
|
585303ad66
|
Start with three dashes for consistency
|
2018-03-03 10:05:05 +04:00 |
|
Jonas Kongslund
|
a800ed094b
|
Added support for webhook authentication/authorization on the secure kubelet endpoint
|
2018-03-03 10:00:09 +04:00 |
|
Matthew Mosesohn
|
ec53b8b66a
|
Move cluster roles and system namespace to new role
This should be done after kubeconfig is set for admin and
before network plugins are up.
|
2017-10-26 14:36:05 +01:00 |
|