56 lines
1.7 KiB
Smarty
56 lines
1.7 KiB
Smarty
# Cluster shape: three nodes, apiserver audit ON. Used by the `client` profile —
|
|
# the regulated-estate shape.
|
|
#
|
|
# Multi-node so taints, affinity and topology spread are real rather than
|
|
# vacuously satisfied by a single node. It costs roughly 4-6 GB; run
|
|
# `make cluster list` before starting this alongside other work.
|
|
#
|
|
# Substituted by ctrl/cluster.sh: CLUSTER, NODE_IMAGE, HTTP_PORT, HOST_WORKDIR
|
|
# (named without the ${...} braces so this line survives the substitution)
|
|
kind: Cluster
|
|
apiVersion: kind.x-k8s.io/v1alpha4
|
|
name: ${CLUSTER}
|
|
|
|
containerdConfigPatches:
|
|
- |-
|
|
[plugins."io.containerd.grpc.v1.cri".registry]
|
|
config_path = "/etc/containerd/certs.d"
|
|
|
|
kubeadmConfigPatches:
|
|
- |
|
|
kind: ClusterConfiguration
|
|
apiServer:
|
|
extraArgs:
|
|
- name: audit-policy-file
|
|
value: /etc/kubernetes/audit/policy.yaml
|
|
- name: audit-log-path
|
|
value: /var/log/kubernetes/audit.log
|
|
- name: audit-log-maxage
|
|
value: "7"
|
|
extraVolumes:
|
|
- name: audit-policy
|
|
hostPath: /etc/kubernetes/audit
|
|
mountPath: /etc/kubernetes/audit
|
|
readOnly: true
|
|
- name: audit-log
|
|
hostPath: /var/log/kubernetes
|
|
mountPath: /var/log/kubernetes
|
|
readOnly: false
|
|
|
|
nodes:
|
|
- role: control-plane
|
|
image: ${NODE_IMAGE}
|
|
extraMounts:
|
|
- hostPath: ${HOST_WORKDIR}/ctrl/k8s/audit-policy.yaml
|
|
containerPath: /etc/kubernetes/audit/policy.yaml
|
|
readOnly: true
|
|
extraPortMappings:
|
|
- containerPort: 30080
|
|
hostPort: ${HTTP_PORT}
|
|
listenAddress: "0.0.0.0"
|
|
protocol: TCP
|
|
- role: worker
|
|
image: ${NODE_IMAGE}
|
|
- role: worker
|
|
image: ${NODE_IMAGE}
|