48e77cd8bb
* Drop linux capabilities for unprivileged containerized worlkoads Kargo configures for deployments. * Configure required securityContext/user/group/groups for kube components' static manifests, etcd, calico-rr and k8s apps, like dnsmasq daemonset. * Rework cloud-init (etcd) users creation for CoreOS. * Fix nologin paths, adjust defaults for addusers role and ensure supplementary groups membership added for users. * Add netplug user for network plugins (yet unused by privileged networking containers though). * Grant the kube and netplug users read access for etcd certs via the etcd certs group. * Grant group read access to kube certs via the kube cert group. * Remove priveleged mode for calico-rr and run it under its uid/gid and supplementary etcd_cert group. * Adjust docs. * Align cpu/memory limits and dropped caps with added rkt support for control plane. Signed-off-by: Bogdan Dobrelya <bogdando@mail.ru>
42 lines
1 KiB
YAML
42 lines
1 KiB
YAML
---
|
|
- include: pre_upgrade.yml
|
|
tags: etcd-pre-upgrade
|
|
- include: set_facts.yml
|
|
tags: [bootstrap-os, facts]
|
|
- include: check_certs.yml
|
|
tags: [etcd-secrets, facts]
|
|
- include: gen_certs.yml
|
|
tags: etcd-secrets
|
|
- include: "install_{{ etcd_deployment_type }}.yml"
|
|
when: is_etcd_master
|
|
tags: upgrade
|
|
- include: set_cluster_health.yml
|
|
when: is_etcd_master
|
|
- include: configure.yml
|
|
when: is_etcd_master
|
|
- include: refresh_config.yml
|
|
when: is_etcd_master
|
|
|
|
- name: Restart etcd if binary or certs changed
|
|
command: /bin/true
|
|
notify: restart etcd
|
|
when: etcd_deployment_type == "host" and etcd_copy.stdout_lines and is_etcd_master
|
|
or etcd_secret_changed|default(false)
|
|
|
|
# reload-systemd
|
|
- meta: flush_handlers
|
|
|
|
- name: Ensure etcd is running
|
|
service:
|
|
name: etcd
|
|
state: started
|
|
enabled: yes
|
|
when: is_etcd_master
|
|
|
|
# After etcd cluster is assembled, make sure that
|
|
# initial state of the cluster is in `existing`
|
|
# state insted of `new`.
|
|
- include: set_cluster_health.yml
|
|
when: is_etcd_master
|
|
- include: refresh_config.yml
|
|
when: is_etcd_master
|