58 lines
2.0 KiB
Smarty
58 lines
2.0 KiB
Smarty
# Cluster shape: one node, apiserver audit ON. Used by the `offline` profile.
|
|
#
|
|
# Audit is an apiserver flag, so it is fixed when the cluster is created —
|
|
# changing it means `make cluster reset`, not a re-apply. That is why it is a
|
|
# property of the cluster file rather than something switched at runtime.
|
|
#
|
|
# k8s >= 1.31 uses kubeadm v1beta4, where extraArgs is a LIST of name/value
|
|
# pairs. The older map form is silently ignored — it does not error, audit
|
|
# simply never turns on.
|
|
#
|
|
# Substituted by ctrl/cluster.sh: CLUSTER, NODE_IMAGE, HTTP_PORT, HOST_WORKDIR
|
|
# (named without the ${...} braces so this line survives the substitution)
|
|
kind: Cluster
|
|
apiVersion: kind.x-k8s.io/v1alpha4
|
|
name: ${CLUSTER}
|
|
|
|
containerdConfigPatches:
|
|
- |-
|
|
[plugins."io.containerd.grpc.v1.cri".registry]
|
|
config_path = "/etc/containerd/certs.d"
|
|
|
|
kubeadmConfigPatches:
|
|
- |
|
|
kind: ClusterConfiguration
|
|
apiServer:
|
|
extraArgs:
|
|
- name: audit-policy-file
|
|
value: /etc/kubernetes/audit/policy.yaml
|
|
- name: audit-log-path
|
|
value: /var/log/kubernetes/audit.log
|
|
- name: audit-log-maxage
|
|
value: "7"
|
|
extraVolumes:
|
|
- name: audit-policy
|
|
hostPath: /etc/kubernetes/audit
|
|
mountPath: /etc/kubernetes/audit
|
|
readOnly: true
|
|
- name: audit-log
|
|
hostPath: /var/log/kubernetes
|
|
mountPath: /var/log/kubernetes
|
|
readOnly: false
|
|
|
|
nodes:
|
|
- role: control-plane
|
|
image: ${NODE_IMAGE}
|
|
# hostPath is resolved by the HOST dockerd, so this must be a host path even
|
|
# when cluster.sh runs inside the installer container. HOST_WORKDIR says where
|
|
# this rig lives on the host; bare on a host it is just the repo root.
|
|
extraMounts:
|
|
- hostPath: ${HOST_WORKDIR}/ctrl/k8s/audit-policy.yaml
|
|
containerPath: /etc/kubernetes/audit/policy.yaml
|
|
readOnly: true
|
|
extraPortMappings:
|
|
- containerPort: 30080
|
|
hostPort: ${HTTP_PORT}
|
|
listenAddress: "0.0.0.0"
|
|
protocol: TCP
|