# Cluster shape: one node, apiserver audit ON. Used by the `offline` profile. # # Audit is an apiserver flag, so it is fixed when the cluster is created — # changing it means `make cluster reset`, not a re-apply. That is why it is a # property of the cluster file rather than something switched at runtime. # # k8s >= 1.31 uses kubeadm v1beta4, where extraArgs is a LIST of name/value # pairs. The older map form is silently ignored — it does not error, audit # simply never turns on. # # Substituted by ctrl/cluster.sh: CLUSTER, NODE_IMAGE, HTTP_PORT, HOST_WORKDIR # (named without the ${...} braces so this line survives the substitution) kind: Cluster apiVersion: kind.x-k8s.io/v1alpha4 name: ${CLUSTER} containerdConfigPatches: - |- [plugins."io.containerd.grpc.v1.cri".registry] config_path = "/etc/containerd/certs.d" kubeadmConfigPatches: - | kind: ClusterConfiguration apiServer: extraArgs: - name: audit-policy-file value: /etc/kubernetes/audit/policy.yaml - name: audit-log-path value: /var/log/kubernetes/audit.log - name: audit-log-maxage value: "7" extraVolumes: - name: audit-policy hostPath: /etc/kubernetes/audit mountPath: /etc/kubernetes/audit readOnly: true - name: audit-log hostPath: /var/log/kubernetes mountPath: /var/log/kubernetes readOnly: false nodes: - role: control-plane image: ${NODE_IMAGE} # hostPath is resolved by the HOST dockerd, so this must be a host path even # when cluster.sh runs inside the installer container. HOST_WORKDIR says where # this rig lives on the host; bare on a host it is just the repo root. extraMounts: - hostPath: ${HOST_WORKDIR}/ctrl/k8s/audit-policy.yaml containerPath: /etc/kubernetes/audit/policy.yaml readOnly: true extraPortMappings: - containerPort: 30080 hostPort: ${HTTP_PORT} listenAddress: "0.0.0.0" protocol: TCP