# Cluster shape: three nodes, apiserver audit ON. Used by the `client` profile — # the regulated-estate shape. # # Multi-node so taints, affinity and topology spread are real rather than # vacuously satisfied by a single node. It costs roughly 4-6 GB; run # `make cluster list` before starting this alongside other work. # # Substituted by ctrl/cluster.sh: CLUSTER, NODE_IMAGE, HTTP_PORT, HOST_WORKDIR # (named without the ${...} braces so this line survives the substitution) kind: Cluster apiVersion: kind.x-k8s.io/v1alpha4 name: ${CLUSTER} containerdConfigPatches: - |- [plugins."io.containerd.grpc.v1.cri".registry] config_path = "/etc/containerd/certs.d" kubeadmConfigPatches: - | kind: ClusterConfiguration apiServer: extraArgs: - name: audit-policy-file value: /etc/kubernetes/audit/policy.yaml - name: audit-log-path value: /var/log/kubernetes/audit.log - name: audit-log-maxage value: "7" extraVolumes: - name: audit-policy hostPath: /etc/kubernetes/audit mountPath: /etc/kubernetes/audit readOnly: true - name: audit-log hostPath: /var/log/kubernetes mountPath: /var/log/kubernetes readOnly: false nodes: - role: control-plane image: ${NODE_IMAGE} extraMounts: - hostPath: ${HOST_WORKDIR}/ctrl/k8s/audit-policy.yaml containerPath: /etc/kubernetes/audit/policy.yaml readOnly: true extraPortMappings: - containerPort: 30080 hostPort: ${HTTP_PORT} listenAddress: "0.0.0.0" protocol: TCP - role: worker image: ${NODE_IMAGE} - role: worker image: ${NODE_IMAGE}