2014-06-16 05:06:55 +00:00
|
|
|
#!/bin/bash
|
|
|
|
|
2016-06-03 00:25:58 +00:00
|
|
|
# Copyright 2014 The Kubernetes Authors.
|
2014-06-16 05:06:55 +00:00
|
|
|
#
|
|
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
# you may not use this file except in compliance with the License.
|
|
|
|
# You may obtain a copy of the License at
|
|
|
|
#
|
|
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
#
|
|
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
# See the License for the specific language governing permissions and
|
|
|
|
# limitations under the License.
|
|
|
|
|
2016-12-09 15:56:50 +00:00
|
|
|
KUBE_ROOT=$(dirname "${BASH_SOURCE}")/..
|
|
|
|
|
2017-01-03 15:41:21 +00:00
|
|
|
# This command builds and runs a local kubernetes cluster.
|
2016-11-07 02:08:34 +00:00
|
|
|
# You may need to run this as root to allow kubelet to open docker's socket,
|
|
|
|
# and to write the test CA in /var/run/kubernetes.
|
2014-11-26 21:51:29 +00:00
|
|
|
DOCKER_OPTS=${DOCKER_OPTS:-""}
|
|
|
|
DOCKER=(docker ${DOCKER_OPTS})
|
2015-05-05 21:12:00 +00:00
|
|
|
DOCKERIZE_KUBELET=${DOCKERIZE_KUBELET:-""}
|
2015-06-08 06:02:55 +00:00
|
|
|
ALLOW_PRIVILEGED=${ALLOW_PRIVILEGED:-""}
|
2015-10-05 15:55:42 +00:00
|
|
|
ALLOW_SECURITY_CONTEXT=${ALLOW_SECURITY_CONTEXT:-""}
|
2016-09-20 10:59:55 +00:00
|
|
|
PSP_ADMISSION=${PSP_ADMISSION:-""}
|
2015-08-26 10:19:27 +00:00
|
|
|
RUNTIME_CONFIG=${RUNTIME_CONFIG:-""}
|
2016-11-06 17:50:54 +00:00
|
|
|
KUBELET_AUTHORIZATION_WEBHOOK=${KUBELET_AUTHORIZATION_WEBHOOK:-""}
|
|
|
|
KUBELET_AUTHENTICATION_WEBHOOK=${KUBELET_AUTHENTICATION_WEBHOOK:-""}
|
2017-02-01 20:17:51 +00:00
|
|
|
POD_MANIFEST_PATH=${POD_MANIFEST_PATH:-"/var/run/kubernetes/static-pods"}
|
2017-02-10 05:14:10 +00:00
|
|
|
KUBELET_FLAGS=${KUBELET_FLAGS:-""}
|
2016-10-24 21:59:36 +00:00
|
|
|
# Name of the network plugin, eg: "kubenet"
|
2015-12-16 23:31:10 +00:00
|
|
|
NET_PLUGIN=${NET_PLUGIN:-""}
|
2016-10-24 21:59:36 +00:00
|
|
|
# Place the binaries required by NET_PLUGIN in this directory, eg: "/home/kubernetes/bin".
|
2016-04-29 03:48:11 +00:00
|
|
|
NET_PLUGIN_DIR=${NET_PLUGIN_DIR:-""}
|
2016-08-16 20:43:31 +00:00
|
|
|
SERVICE_CLUSTER_IP_RANGE=${SERVICE_CLUSTER_IP_RANGE:-10.0.0.0/24}
|
2017-02-15 18:01:13 +00:00
|
|
|
FIRST_SERVICE_CLUSTER_IP=${FIRST_SERVICE_CLUSTER_IP:-10.0.0.1}
|
2016-10-17 17:23:48 +00:00
|
|
|
# if enabled, must set CGROUP_ROOT
|
2017-02-20 17:05:06 +00:00
|
|
|
CGROUPS_PER_QOS=${CGROUPS_PER_QOS:-true}
|
2016-10-17 17:23:48 +00:00
|
|
|
# name of the cgroup driver, i.e. cgroupfs or systemd
|
|
|
|
CGROUP_DRIVER=${CGROUP_DRIVER:-""}
|
2017-02-17 02:08:46 +00:00
|
|
|
# owner of client certs, default to current user if not specified
|
|
|
|
USER=${USER:-$(whoami)}
|
2016-10-17 17:23:48 +00:00
|
|
|
|
2017-02-08 17:58:02 +00:00
|
|
|
# enables testing eviction scenarios locally.
|
|
|
|
EVICTION_HARD=${EVICTION_HARD:-"memory.available<100Mi"}
|
|
|
|
EVICTION_SOFT=${EVICTION_SOFT:-""}
|
|
|
|
EVICTION_PRESSURE_TRANSITION_PERIOD=${EVICTION_PRESSURE_TRANSITION_PERIOD:-"1m"}
|
|
|
|
|
2016-03-03 22:59:40 +00:00
|
|
|
# We disable cluster DNS by default because this script uses docker0 (or whatever
|
|
|
|
# container bridge docker is currently using) and we don't know the IP of the
|
|
|
|
# DNS pod to pass in as --cluster-dns. To set this up by hand, set this flag
|
|
|
|
# and change DNS_SERVER_IP to the appropriate IP.
|
|
|
|
ENABLE_CLUSTER_DNS=${KUBE_ENABLE_CLUSTER_DNS:-false}
|
2015-12-30 22:48:00 +00:00
|
|
|
DNS_SERVER_IP=${KUBE_DNS_SERVER_IP:-10.0.0.10}
|
|
|
|
DNS_DOMAIN=${KUBE_DNS_NAME:-"cluster.local"}
|
|
|
|
KUBECTL=${KUBECTL:-cluster/kubectl.sh}
|
|
|
|
WAIT_FOR_URL_API_SERVER=${WAIT_FOR_URL_API_SERVER:-10}
|
|
|
|
ENABLE_DAEMON=${ENABLE_DAEMON:-false}
|
2016-02-18 20:47:58 +00:00
|
|
|
HOSTNAME_OVERRIDE=${HOSTNAME_OVERRIDE:-"127.0.0.1"}
|
2016-05-07 16:57:58 +00:00
|
|
|
CLOUD_PROVIDER=${CLOUD_PROVIDER:-""}
|
2016-06-16 18:16:58 +00:00
|
|
|
CLOUD_CONFIG=${CLOUD_CONFIG:-""}
|
2016-09-26 17:15:34 +00:00
|
|
|
FEATURE_GATES=${FEATURE_GATES:-"AllAlpha=true"}
|
2017-03-22 21:33:34 +00:00
|
|
|
STORAGE_BACKEND=${STORAGE_BACKEND:-"etcd3"}
|
2017-02-16 01:58:34 +00:00
|
|
|
# enable swagger ui
|
|
|
|
ENABLE_SWAGGER_UI=${ENABLE_SWAGGER_UI:-false}
|
|
|
|
|
2017-03-02 01:18:37 +00:00
|
|
|
# enable audit log
|
|
|
|
ENABLE_APISERVER_BASIC_AUDIT=${ENABLE_APISERVER_BASIC_AUDIT:-false}
|
|
|
|
|
2016-12-02 03:04:25 +00:00
|
|
|
# RBAC Mode options
|
|
|
|
ALLOW_ANY_TOKEN=${ALLOW_ANY_TOKEN:-false}
|
|
|
|
ENABLE_RBAC=${ENABLE_RBAC:-false}
|
|
|
|
KUBECONFIG_TOKEN=${KUBECONFIG_TOKEN:-""}
|
|
|
|
AUTH_ARGS=${AUTH_ARGS:-""}
|
|
|
|
|
2017-02-16 09:28:29 +00:00
|
|
|
# Install a default storage class (enabled by default)
|
|
|
|
DEFAULT_STORAGE_CLASS=${KUBE_DEFAULT_STORAGE_CLASS:-true}
|
|
|
|
|
2016-06-21 14:26:38 +00:00
|
|
|
# start the cache mutation detector by default so that cache mutators will be found
|
|
|
|
KUBE_CACHE_MUTATION_DETECTOR="${KUBE_CACHE_MUTATION_DETECTOR:-true}"
|
|
|
|
export KUBE_CACHE_MUTATION_DETECTOR
|
|
|
|
|
2017-02-18 17:10:22 +00:00
|
|
|
ADMISSION_CONTROL_CONFIG_FILE=${ADMISSION_CONTROL_CONFIG_FILE:-""}
|
2016-06-21 14:26:38 +00:00
|
|
|
|
2016-08-31 19:36:54 +00:00
|
|
|
# START_MODE can be 'all', 'kubeletonly', or 'nokubelet'
|
|
|
|
START_MODE=${START_MODE:-"all"}
|
|
|
|
|
2016-06-16 18:16:58 +00:00
|
|
|
# sanity check for OpenStack provider
|
|
|
|
if [ "${CLOUD_PROVIDER}" == "openstack" ]; then
|
|
|
|
if [ "${CLOUD_CONFIG}" == "" ]; then
|
|
|
|
echo "Missing CLOUD_CONFIG env for OpenStack provider!"
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
if [ ! -f "${CLOUD_CONFIG}" ]; then
|
2017-01-03 15:41:21 +00:00
|
|
|
echo "Cloud config ${CLOUD_CONFIG} doesn't exist"
|
2016-06-16 18:16:58 +00:00
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
fi
|
2015-12-30 22:48:00 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
if [ "$(id -u)" != "0" ]; then
|
2015-09-14 22:39:53 +00:00
|
|
|
echo "WARNING : This script MAY be run as root for docker socket / iptables functionality; if failures occur, retry as root." 2>&1
|
2015-06-10 00:26:18 +00:00
|
|
|
fi
|
|
|
|
|
2014-11-03 03:43:34 +00:00
|
|
|
# Stop right away if the build fails
|
|
|
|
set -e
|
|
|
|
|
|
|
|
source "${KUBE_ROOT}/hack/lib/init.sh"
|
2015-06-10 00:26:18 +00:00
|
|
|
|
2015-06-15 23:34:41 +00:00
|
|
|
function usage {
|
|
|
|
echo "This script starts a local kube cluster. "
|
2016-12-13 17:29:47 +00:00
|
|
|
echo "Example 0: hack/local-up-cluster.sh -h (this 'help' usage description)"
|
2015-06-15 23:34:41 +00:00
|
|
|
echo "Example 1: hack/local-up-cluster.sh -o _output/dockerized/bin/linux/amd64/ (run from docker output)"
|
2016-10-17 16:33:33 +00:00
|
|
|
echo "Example 2: hack/local-up-cluster.sh -O (auto-guess the bin path for your platform)"
|
|
|
|
echo "Example 3: hack/local-up-cluster.sh (build a local copy of the source)"
|
|
|
|
}
|
|
|
|
|
|
|
|
# This function guesses where the existing cached binary build is for the `-O`
|
|
|
|
# flag
|
|
|
|
function guess_built_binary_path {
|
|
|
|
local hyperkube_path=$(kube::util::find-binary "hyperkube")
|
|
|
|
if [[ -z "${hyperkube_path}" ]]; then
|
|
|
|
return
|
|
|
|
fi
|
|
|
|
echo -n "$(dirname "${hyperkube_path}")"
|
2015-06-15 23:34:41 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
### Allow user to supply the source directory.
|
2016-12-09 15:56:50 +00:00
|
|
|
GO_OUT=${GO_OUT:-}
|
2016-12-13 17:29:47 +00:00
|
|
|
while getopts "ho:O" OPTION
|
2015-06-15 23:34:41 +00:00
|
|
|
do
|
|
|
|
case $OPTION in
|
2015-08-26 10:19:27 +00:00
|
|
|
o)
|
2015-06-15 23:34:41 +00:00
|
|
|
echo "skipping build"
|
|
|
|
GO_OUT="$OPTARG"
|
2016-10-17 16:33:33 +00:00
|
|
|
echo "using source $GO_OUT"
|
|
|
|
;;
|
|
|
|
O)
|
|
|
|
GO_OUT=$(guess_built_binary_path)
|
2015-06-15 23:34:41 +00:00
|
|
|
if [ $GO_OUT == "" ]; then
|
2016-10-17 16:33:33 +00:00
|
|
|
echo "Could not guess the correct output directory to use."
|
|
|
|
exit 1
|
2015-06-15 23:34:41 +00:00
|
|
|
fi
|
|
|
|
;;
|
2016-12-13 17:29:47 +00:00
|
|
|
h)
|
|
|
|
usage
|
|
|
|
exit
|
|
|
|
;;
|
2015-06-15 23:34:41 +00:00
|
|
|
?)
|
2015-08-26 10:19:27 +00:00
|
|
|
usage
|
2015-06-15 23:34:41 +00:00
|
|
|
exit
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
|
|
|
|
if [ "x$GO_OUT" == "x" ]; then
|
2017-03-10 18:51:02 +00:00
|
|
|
make -C "${KUBE_ROOT}" WHAT="cmd/kubectl cmd/hyperkube"
|
2015-06-15 23:34:41 +00:00
|
|
|
else
|
|
|
|
echo "skipped the build."
|
|
|
|
fi
|
2014-06-16 05:06:55 +00:00
|
|
|
|
2016-11-04 08:56:47 +00:00
|
|
|
function test_rkt {
|
|
|
|
if [[ -n "${RKT_PATH}" ]]; then
|
|
|
|
${RKT_PATH} list 2> /dev/null 1> /dev/null
|
|
|
|
if [ "$?" != "0" ]; then
|
|
|
|
echo "Failed to successfully run 'rkt list', please verify that ${RKT_PATH} is the path of rkt binary."
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
else
|
|
|
|
rkt list 2> /dev/null 1> /dev/null
|
|
|
|
if [ "$?" != "0" ]; then
|
|
|
|
echo "Failed to successfully run 'rkt list', please verify that rkt is in \$PATH."
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
2016-05-07 16:59:17 +00:00
|
|
|
|
2014-06-16 05:06:55 +00:00
|
|
|
# Shut down anyway if there's an error.
|
|
|
|
set +e
|
|
|
|
|
2014-07-27 19:38:12 +00:00
|
|
|
API_PORT=${API_PORT:-8080}
|
2016-10-06 19:59:14 +00:00
|
|
|
API_SECURE_PORT=${API_SECURE_PORT:-6443}
|
|
|
|
API_HOST=${API_HOST:-localhost}
|
|
|
|
API_HOST_IP=${API_HOST_IP:-"127.0.0.1"}
|
2016-10-06 21:30:29 +00:00
|
|
|
API_BIND_ADDR=${API_BIND_ADDR:-"0.0.0.0"}
|
2016-05-27 18:13:24 +00:00
|
|
|
KUBELET_HOST=${KUBELET_HOST:-"127.0.0.1"}
|
2014-09-03 18:33:52 +00:00
|
|
|
# By default only allow CORS for requests on localhost
|
2016-08-16 20:43:31 +00:00
|
|
|
API_CORS_ALLOWED_ORIGINS=${API_CORS_ALLOWED_ORIGINS:-/127.0.0.1(:[0-9]+)?$,/localhost(:[0-9]+)?$}
|
2014-07-27 19:38:12 +00:00
|
|
|
KUBELET_PORT=${KUBELET_PORT:-10250}
|
2014-10-07 06:46:52 +00:00
|
|
|
LOG_LEVEL=${LOG_LEVEL:-3}
|
2017-03-31 19:11:41 +00:00
|
|
|
LOG_DIR=${LOG_DIR:-"/tmp"}
|
2015-05-05 21:00:58 +00:00
|
|
|
CONTAINER_RUNTIME=${CONTAINER_RUNTIME:-"docker"}
|
2016-08-24 10:49:25 +00:00
|
|
|
CONTAINER_RUNTIME_ENDPOINT=${CONTAINER_RUNTIME_ENDPOINT:-""}
|
|
|
|
IMAGE_SERVICE_ENDPOINT=${IMAGE_SERVICE_ENDPOINT:-""}
|
2017-03-01 07:21:13 +00:00
|
|
|
ENABLE_CRI=${ENABLE_CRI:-"true"}
|
2015-09-01 21:32:52 +00:00
|
|
|
RKT_PATH=${RKT_PATH:-""}
|
|
|
|
RKT_STAGE1_IMAGE=${RKT_STAGE1_IMAGE:-""}
|
2015-04-11 16:45:45 +00:00
|
|
|
CHAOS_CHANCE=${CHAOS_CHANCE:-0.0}
|
2016-08-22 21:35:49 +00:00
|
|
|
CPU_CFS_QUOTA=${CPU_CFS_QUOTA:-true}
|
2015-10-12 18:27:49 +00:00
|
|
|
ENABLE_HOSTPATH_PROVISIONER=${ENABLE_HOSTPATH_PROVISIONER:-"false"}
|
2016-06-15 13:25:55 +00:00
|
|
|
CLAIM_BINDER_SYNC_PERIOD=${CLAIM_BINDER_SYNC_PERIOD:-"15s"} # current k8s default
|
2016-08-31 19:36:54 +00:00
|
|
|
ENABLE_CONTROLLER_ATTACH_DETACH=${ENABLE_CONTROLLER_ATTACH_DETACH:-"true"} # current default
|
2016-11-07 02:08:34 +00:00
|
|
|
# This is the default dir and filename where the apiserver will generate a self-signed cert
|
|
|
|
# which should be able to be used as the CA to verify itself
|
2016-10-06 19:59:14 +00:00
|
|
|
CERT_DIR=${CERT_DIR:-"/var/run/kubernetes"}
|
2017-02-01 20:17:51 +00:00
|
|
|
ROOT_CA_FILE=${CERT_DIR}/server-ca.crt
|
2016-12-02 16:19:06 +00:00
|
|
|
|
2017-02-03 22:28:23 +00:00
|
|
|
# name of the cgroup driver, i.e. cgroupfs or systemd
|
|
|
|
if [[ ${CONTAINER_RUNTIME} == "docker" ]]; then
|
|
|
|
# default cgroup driver to match what is reported by docker to simplify local development
|
|
|
|
if [[ -z ${CGROUP_DRIVER} ]]; then
|
|
|
|
# match driver with docker runtime reported value (they must match)
|
|
|
|
CGROUP_DRIVER=$(docker info | grep "Cgroup Driver:" | cut -f3- -d' ')
|
|
|
|
echo "Kubelet cgroup driver defaulted to use: ${CGROUP_DRIVER}"
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
2016-10-06 19:59:14 +00:00
|
|
|
|
2016-11-24 09:23:23 +00:00
|
|
|
# Ensure CERT_DIR is created for auto-generated crt/key and kubeconfig
|
|
|
|
mkdir -p "${CERT_DIR}" &>/dev/null || sudo mkdir -p "${CERT_DIR}"
|
|
|
|
CONTROLPLANE_SUDO=$(test -w "${CERT_DIR}" || echo "sudo -E")
|
2014-06-16 05:06:55 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
function test_apiserver_off {
|
|
|
|
# For the common local scenario, fail fast if server is already running.
|
|
|
|
# this can happen if you run local-up-cluster.sh twice and kill etcd in between.
|
2016-10-06 19:59:14 +00:00
|
|
|
if [[ "${API_PORT}" -gt "0" ]]; then
|
|
|
|
curl --silent -g $API_HOST:$API_PORT
|
|
|
|
if [ ! $? -eq 0 ]; then
|
|
|
|
echo "API SERVER insecure port is free, proceeding..."
|
|
|
|
else
|
|
|
|
echo "ERROR starting API SERVER, exiting. Some process on $API_HOST is serving already on $API_PORT"
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
curl --silent -k -g $API_HOST:$API_SECURE_PORT
|
2015-06-10 00:26:18 +00:00
|
|
|
if [ ! $? -eq 0 ]; then
|
2016-10-06 19:59:14 +00:00
|
|
|
echo "API SERVER secure port is free, proceeding..."
|
2015-06-10 00:26:18 +00:00
|
|
|
else
|
2016-10-06 19:59:14 +00:00
|
|
|
echo "ERROR starting API SERVER, exiting. Some process on $API_HOST is serving already on $API_SECURE_PORT"
|
2015-06-10 00:26:18 +00:00
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
}
|
2014-11-03 03:43:34 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
function detect_binary {
|
|
|
|
# Detect the OS name/arch so that we can find our binary
|
|
|
|
case "$(uname -s)" in
|
|
|
|
Darwin)
|
|
|
|
host_os=darwin
|
|
|
|
;;
|
|
|
|
Linux)
|
|
|
|
host_os=linux
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
echo "Unsupported host OS. Must be Linux or Mac OS X." >&2
|
|
|
|
exit 1
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
|
|
|
case "$(uname -m)" in
|
|
|
|
x86_64*)
|
|
|
|
host_arch=amd64
|
|
|
|
;;
|
|
|
|
i?86_64*)
|
|
|
|
host_arch=amd64
|
|
|
|
;;
|
|
|
|
amd64*)
|
|
|
|
host_arch=amd64
|
|
|
|
;;
|
2016-05-15 13:38:11 +00:00
|
|
|
aarch64*)
|
|
|
|
host_arch=arm64
|
|
|
|
;;
|
|
|
|
arm64*)
|
|
|
|
host_arch=arm64
|
|
|
|
;;
|
2015-06-10 00:26:18 +00:00
|
|
|
arm*)
|
|
|
|
host_arch=arm
|
|
|
|
;;
|
|
|
|
i?86*)
|
|
|
|
host_arch=x86
|
|
|
|
;;
|
2015-11-02 10:29:24 +00:00
|
|
|
s390x*)
|
|
|
|
host_arch=s390x
|
|
|
|
;;
|
2015-12-09 06:42:13 +00:00
|
|
|
ppc64le*)
|
|
|
|
host_arch=ppc64le
|
|
|
|
;;
|
2015-06-10 00:26:18 +00:00
|
|
|
*)
|
2016-05-15 13:38:11 +00:00
|
|
|
echo "Unsupported host arch. Must be x86_64, 386, arm, arm64, s390x or ppc64le." >&2
|
2015-06-10 00:26:18 +00:00
|
|
|
exit 1
|
|
|
|
;;
|
|
|
|
esac
|
2015-06-15 23:34:41 +00:00
|
|
|
|
|
|
|
GO_OUT="${KUBE_ROOT}/_output/local/bin/${host_os}/${host_arch}"
|
2015-06-10 00:26:18 +00:00
|
|
|
}
|
2015-05-05 21:12:00 +00:00
|
|
|
|
|
|
|
cleanup_dockerized_kubelet()
|
|
|
|
{
|
2015-08-26 10:19:27 +00:00
|
|
|
if [[ -e $KUBELET_CIDFILE ]]; then
|
2015-05-05 21:12:00 +00:00
|
|
|
docker kill $(<$KUBELET_CIDFILE) > /dev/null
|
|
|
|
rm -f $KUBELET_CIDFILE
|
|
|
|
fi
|
|
|
|
}
|
2014-06-16 05:06:55 +00:00
|
|
|
|
2015-02-12 22:29:55 +00:00
|
|
|
cleanup()
|
|
|
|
{
|
2015-05-14 03:26:08 +00:00
|
|
|
echo "Cleaning up..."
|
2015-12-30 22:48:00 +00:00
|
|
|
# delete running images
|
|
|
|
# if [[ "${ENABLE_CLUSTER_DNS}" = true ]]; then
|
|
|
|
# Still need to figure why this commands throw an error: Error from server: client: etcd cluster is unavailable or misconfigured
|
|
|
|
# ${KUBECTL} --namespace=kube-system delete service kube-dns
|
|
|
|
# And this one hang forever:
|
|
|
|
# ${KUBECTL} --namespace=kube-system delete rc kube-dns-v10
|
|
|
|
# fi
|
|
|
|
|
2015-05-14 03:26:08 +00:00
|
|
|
# Check if the API server is still running
|
2015-05-18 18:51:00 +00:00
|
|
|
[[ -n "${APISERVER_PID-}" ]] && APISERVER_PIDS=$(pgrep -P ${APISERVER_PID} ; ps -o pid= -p ${APISERVER_PID})
|
2015-05-14 03:26:08 +00:00
|
|
|
[[ -n "${APISERVER_PIDS-}" ]] && sudo kill ${APISERVER_PIDS}
|
|
|
|
|
|
|
|
# Check if the controller-manager is still running
|
2015-05-18 18:51:00 +00:00
|
|
|
[[ -n "${CTLRMGR_PID-}" ]] && CTLRMGR_PIDS=$(pgrep -P ${CTLRMGR_PID} ; ps -o pid= -p ${CTLRMGR_PID})
|
2015-05-14 03:26:08 +00:00
|
|
|
[[ -n "${CTLRMGR_PIDS-}" ]] && sudo kill ${CTLRMGR_PIDS}
|
|
|
|
|
|
|
|
if [[ -n "$DOCKERIZE_KUBELET" ]]; then
|
|
|
|
cleanup_dockerized_kubelet
|
|
|
|
else
|
|
|
|
# Check if the kubelet is still running
|
2015-05-18 18:51:00 +00:00
|
|
|
[[ -n "${KUBELET_PID-}" ]] && KUBELET_PIDS=$(pgrep -P ${KUBELET_PID} ; ps -o pid= -p ${KUBELET_PID})
|
2015-05-14 03:26:08 +00:00
|
|
|
[[ -n "${KUBELET_PIDS-}" ]] && sudo kill ${KUBELET_PIDS}
|
|
|
|
fi
|
|
|
|
|
|
|
|
# Check if the proxy is still running
|
2015-05-18 18:51:00 +00:00
|
|
|
[[ -n "${PROXY_PID-}" ]] && PROXY_PIDS=$(pgrep -P ${PROXY_PID} ; ps -o pid= -p ${PROXY_PID})
|
2015-05-14 03:26:08 +00:00
|
|
|
[[ -n "${PROXY_PIDS-}" ]] && sudo kill ${PROXY_PIDS}
|
|
|
|
|
|
|
|
# Check if the scheduler is still running
|
2015-05-18 18:51:00 +00:00
|
|
|
[[ -n "${SCHEDULER_PID-}" ]] && SCHEDULER_PIDS=$(pgrep -P ${SCHEDULER_PID} ; ps -o pid= -p ${SCHEDULER_PID})
|
2015-05-14 03:26:08 +00:00
|
|
|
[[ -n "${SCHEDULER_PIDS-}" ]] && sudo kill ${SCHEDULER_PIDS}
|
|
|
|
|
|
|
|
# Check if the etcd is still running
|
|
|
|
[[ -n "${ETCD_PID-}" ]] && kube::etcd::stop
|
|
|
|
[[ -n "${ETCD_DIR-}" ]] && kube::etcd::clean_etcd_dir
|
|
|
|
|
|
|
|
exit 0
|
2015-02-12 22:29:55 +00:00
|
|
|
}
|
|
|
|
|
2017-01-26 20:57:58 +00:00
|
|
|
function warning {
|
|
|
|
message=$1
|
|
|
|
|
|
|
|
echo $(tput bold)$(tput setaf 1)
|
|
|
|
echo "WARNING: ${message}"
|
|
|
|
echo $(tput sgr0)
|
|
|
|
}
|
|
|
|
|
2016-08-31 19:36:54 +00:00
|
|
|
function start_etcd {
|
2015-06-10 00:26:18 +00:00
|
|
|
echo "Starting etcd"
|
|
|
|
kube::etcd::start
|
|
|
|
}
|
2015-05-01 16:02:38 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
function set_service_accounts {
|
|
|
|
SERVICE_ACCOUNT_LOOKUP=${SERVICE_ACCOUNT_LOOKUP:-false}
|
2016-08-16 20:43:31 +00:00
|
|
|
SERVICE_ACCOUNT_KEY=${SERVICE_ACCOUNT_KEY:-/tmp/kube-serviceaccount.key}
|
2015-06-10 00:26:18 +00:00
|
|
|
# Generate ServiceAccount key if needed
|
|
|
|
if [[ ! -f "${SERVICE_ACCOUNT_KEY}" ]]; then
|
|
|
|
mkdir -p "$(dirname ${SERVICE_ACCOUNT_KEY})"
|
|
|
|
openssl genrsa -out "${SERVICE_ACCOUNT_KEY}" 2048 2>/dev/null
|
|
|
|
fi
|
|
|
|
}
|
2015-04-10 19:50:33 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
function start_apiserver {
|
2016-09-20 10:59:55 +00:00
|
|
|
security_admission=""
|
2015-10-05 15:55:42 +00:00
|
|
|
if [[ -z "${ALLOW_SECURITY_CONTEXT}" ]]; then
|
2016-09-20 10:59:55 +00:00
|
|
|
security_admission=",SecurityContextDeny"
|
|
|
|
fi
|
|
|
|
if [[ -n "${PSP_ADMISSION}" ]]; then
|
|
|
|
security_admission=",PodSecurityPolicy"
|
2015-10-05 15:55:42 +00:00
|
|
|
fi
|
2016-09-20 10:59:55 +00:00
|
|
|
|
|
|
|
# Admission Controllers to invoke prior to persisting objects in cluster
|
2017-02-21 15:30:05 +00:00
|
|
|
ADMISSION_CONTROL=NamespaceLifecycle,LimitRanger,ServiceAccount${security_admission},ResourceQuota,DefaultStorageClass,DefaultTolerationSeconds
|
2016-09-20 10:59:55 +00:00
|
|
|
|
2015-07-15 03:57:36 +00:00
|
|
|
# This is the default dir and filename where the apiserver will generate a self-signed cert
|
|
|
|
# which should be able to be used as the CA to verify itself
|
|
|
|
|
2017-03-02 01:18:37 +00:00
|
|
|
audit_arg=""
|
|
|
|
APISERVER_BASIC_AUDIT_LOG=""
|
|
|
|
if [[ "${ENABLE_APISERVER_BASIC_AUDIT:-}" = true ]]; then
|
|
|
|
# We currently only support enabling with a fixed path and with built-in log
|
|
|
|
# rotation "disabled" (large value) so it behaves like kube-apiserver.log.
|
|
|
|
# External log rotation should be set up the same as for kube-apiserver.log.
|
|
|
|
APISERVER_BASIC_AUDIT_LOG=/tmp/kube-apiserver-audit.log
|
|
|
|
audit_arg=" --audit-log-path=${APISERVER_BASIC_AUDIT_LOG}"
|
|
|
|
audit_arg+=" --audit-log-maxage=0"
|
|
|
|
audit_arg+=" --audit-log-maxbackup=0"
|
|
|
|
# Lumberjack doesn't offer any way to disable size-based rotation. It also
|
|
|
|
# has an in-memory counter that doesn't notice if you truncate the file.
|
|
|
|
# 2000000000 (in MiB) is a large number that fits in 31 bits. If the log
|
|
|
|
# grows at 10MiB/s (~30K QPS), it will rotate after ~6 years if apiserver
|
|
|
|
# never restarts. Please manually restart apiserver before this time.
|
|
|
|
audit_arg+=" --audit-log-maxsize=2000000000"
|
|
|
|
fi
|
|
|
|
|
2017-02-16 01:58:34 +00:00
|
|
|
swagger_arg=""
|
|
|
|
if [[ "${ENABLE_SWAGGER_UI}" = true ]]; then
|
|
|
|
swagger_arg="--enable-swagger-ui=true "
|
|
|
|
fi
|
|
|
|
|
2016-09-23 16:35:31 +00:00
|
|
|
anytoken_arg=""
|
2016-12-02 03:04:25 +00:00
|
|
|
if [[ "${ALLOW_ANY_TOKEN}" = true ]]; then
|
2016-09-23 16:35:31 +00:00
|
|
|
anytoken_arg="--insecure-allow-any-token "
|
2016-12-09 07:21:17 +00:00
|
|
|
KUBECONFIG_TOKEN="${KUBECONFIG_TOKEN:-system:admin/system:masters}"
|
2016-09-23 16:35:31 +00:00
|
|
|
fi
|
2016-10-12 15:32:09 +00:00
|
|
|
authorizer_arg=""
|
2016-12-02 03:04:25 +00:00
|
|
|
if [[ "${ENABLE_RBAC}" = true ]]; then
|
2016-10-12 15:32:09 +00:00
|
|
|
authorizer_arg="--authorization-mode=RBAC "
|
|
|
|
fi
|
2015-06-10 00:26:18 +00:00
|
|
|
priv_arg=""
|
|
|
|
if [[ -n "${ALLOW_PRIVILEGED}" ]]; then
|
|
|
|
priv_arg="--allow-privileged "
|
|
|
|
fi
|
2015-08-26 10:19:27 +00:00
|
|
|
runtime_config=""
|
|
|
|
if [[ -n "${RUNTIME_CONFIG}" ]]; then
|
2015-09-09 15:23:39 +00:00
|
|
|
runtime_config="--runtime-config=${RUNTIME_CONFIG}"
|
2015-08-26 10:19:27 +00:00
|
|
|
fi
|
2015-06-10 00:26:18 +00:00
|
|
|
|
2016-12-07 10:12:14 +00:00
|
|
|
# Let the API server pick a default address when API_HOST_IP
|
2016-07-22 01:42:22 +00:00
|
|
|
# is set to 127.0.0.1
|
|
|
|
advertise_address=""
|
2016-12-07 10:12:14 +00:00
|
|
|
if [[ "${API_HOST_IP}" != "127.0.0.1" ]]; then
|
2016-09-27 16:52:07 +00:00
|
|
|
advertise_address="--advertise_address=${API_HOST_IP}"
|
2016-07-22 01:42:22 +00:00
|
|
|
fi
|
|
|
|
|
2017-02-01 20:17:51 +00:00
|
|
|
# Create CA signers
|
|
|
|
kube::util::create_signing_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" server '"server auth"'
|
2016-12-09 15:56:50 +00:00
|
|
|
kube::util::create_signing_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" client '"client auth"'
|
2017-02-01 20:17:51 +00:00
|
|
|
# Create auth proxy client ca
|
|
|
|
kube::util::create_signing_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" request-header '"client auth"'
|
|
|
|
|
|
|
|
# serving cert for kube-apiserver
|
2017-02-15 18:01:13 +00:00
|
|
|
kube::util::create_serving_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" "server-ca" kube-apiserver kubernetes.default kubernetes.default.svc "localhost" ${API_HOST_IP} ${API_HOST} ${FIRST_SERVICE_CLUSTER_IP}
|
2016-11-12 22:09:04 +00:00
|
|
|
|
|
|
|
# Create client certs signed with client-ca, given id, given CN and a number of groups
|
2016-12-09 15:56:50 +00:00
|
|
|
kube::util::create_client_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" 'client-ca' kubelet system:node:${HOSTNAME_OVERRIDE} system:nodes
|
|
|
|
kube::util::create_client_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" 'client-ca' kube-proxy system:kube-proxy system:nodes
|
2017-02-08 15:16:46 +00:00
|
|
|
kube::util::create_client_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" 'client-ca' controller system:kube-controller-manager
|
2017-02-11 21:12:53 +00:00
|
|
|
kube::util::create_client_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" 'client-ca' scheduler system:kube-scheduler
|
2016-12-09 15:56:50 +00:00
|
|
|
kube::util::create_client_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" 'client-ca' admin system:admin system:masters
|
2016-10-06 19:59:14 +00:00
|
|
|
|
2017-02-01 20:17:51 +00:00
|
|
|
# Create matching certificates for kube-aggregator
|
|
|
|
kube::util::create_serving_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" "server-ca" kube-aggregator api.kube-public.svc "localhost" ${API_HOST_IP}
|
2016-12-09 15:56:50 +00:00
|
|
|
kube::util::create_client_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" request-header-ca auth-proxy system:auth-proxy
|
2017-02-01 20:17:51 +00:00
|
|
|
# TODO remove masters and add rolebinding
|
|
|
|
kube::util::create_client_certkey "${CONTROLPLANE_SUDO}" "${CERT_DIR}" 'client-ca' kube-aggregator system:kube-aggregator system:masters
|
|
|
|
kube::util::write_client_kubeconfig "${CONTROLPLANE_SUDO}" "${CERT_DIR}" "${ROOT_CA_FILE}" "${API_HOST}" "${API_SECURE_PORT}" kube-aggregator
|
|
|
|
|
2016-11-15 14:54:12 +00:00
|
|
|
|
2017-03-31 19:11:41 +00:00
|
|
|
APISERVER_LOG=${LOG_DIR}/kube-apiserver.log
|
2017-03-02 01:18:37 +00:00
|
|
|
${CONTROLPLANE_SUDO} "${GO_OUT}/hyperkube" apiserver ${swagger_arg} ${audit_arg} ${anytoken_arg} ${authorizer_arg} ${priv_arg} ${runtime_config}\
|
2016-07-22 01:42:22 +00:00
|
|
|
${advertise_address} \
|
2015-06-10 00:26:18 +00:00
|
|
|
--v=${LOG_LEVEL} \
|
2015-07-04 23:23:32 +00:00
|
|
|
--cert-dir="${CERT_DIR}" \
|
2016-12-05 20:30:13 +00:00
|
|
|
--client-ca-file="${CERT_DIR}/client-ca.crt" \
|
2015-07-04 23:23:32 +00:00
|
|
|
--service-account-key-file="${SERVICE_ACCOUNT_KEY}" \
|
|
|
|
--service-account-lookup="${SERVICE_ACCOUNT_LOOKUP}" \
|
|
|
|
--admission-control="${ADMISSION_CONTROL}" \
|
2017-02-18 17:10:22 +00:00
|
|
|
--admission-control-config-file="${ADMISSION_CONTROL_CONFIG_FILE}" \
|
2016-05-27 19:38:44 +00:00
|
|
|
--bind-address="${API_BIND_ADDR}" \
|
2016-10-06 19:59:14 +00:00
|
|
|
--secure-port="${API_SECURE_PORT}" \
|
2017-02-01 20:17:51 +00:00
|
|
|
--tls-cert-file="${CERT_DIR}/serving-kube-apiserver.crt" \
|
|
|
|
--tls-private-key-file="${CERT_DIR}/serving-kube-apiserver.key" \
|
|
|
|
--tls-ca-file="${CERT_DIR}/server-ca.crt" \
|
2016-05-27 19:38:44 +00:00
|
|
|
--insecure-bind-address="${API_HOST_IP}" \
|
2015-08-26 10:19:27 +00:00
|
|
|
--insecure-port="${API_PORT}" \
|
2017-03-22 21:33:34 +00:00
|
|
|
--storage-backend=${STORAGE_BACKEND} \
|
2016-05-27 18:13:24 +00:00
|
|
|
--etcd-servers="http://${ETCD_HOST}:${ETCD_PORT}" \
|
2016-09-16 22:41:41 +00:00
|
|
|
--service-cluster-ip-range="${SERVICE_CLUSTER_IP_RANGE}" \
|
2016-09-26 17:15:34 +00:00
|
|
|
--feature-gates="${FEATURE_GATES}" \
|
2016-05-07 16:57:58 +00:00
|
|
|
--cloud-provider="${CLOUD_PROVIDER}" \
|
2016-06-16 18:16:58 +00:00
|
|
|
--cloud-config="${CLOUD_CONFIG}" \
|
2016-12-05 19:22:11 +00:00
|
|
|
--requestheader-username-headers=X-Remote-User \
|
|
|
|
--requestheader-group-headers=X-Remote-Group \
|
|
|
|
--requestheader-extra-headers-prefix=X-Remote-Extra- \
|
2016-12-09 15:56:50 +00:00
|
|
|
--requestheader-client-ca-file="${CERT_DIR}/request-header-ca.crt" \
|
2016-12-05 19:22:11 +00:00
|
|
|
--requestheader-allowed-names=system:auth-proxy \
|
2017-03-10 18:51:02 +00:00
|
|
|
--proxy-client-cert-file="${CERT_DIR}/client-auth-proxy.crt" \
|
|
|
|
--proxy-client-key-file="${CERT_DIR}/client-auth-proxy.key" \
|
2015-07-04 23:23:32 +00:00
|
|
|
--cors-allowed-origins="${API_CORS_ALLOWED_ORIGINS}" >"${APISERVER_LOG}" 2>&1 &
|
2015-06-10 00:26:18 +00:00
|
|
|
APISERVER_PID=$!
|
|
|
|
|
|
|
|
# Wait for kube-apiserver to come up before launching the rest of the components.
|
|
|
|
echo "Waiting for apiserver to come up"
|
2016-12-13 13:00:26 +00:00
|
|
|
# this uses the API port because if you don't have any authenticator, you can't seem to use the secure port at all.
|
|
|
|
# this matches what happened with the combination in 1.4.
|
|
|
|
# TODO change this conditionally based on whether API_PORT is on or off
|
2017-02-24 19:12:34 +00:00
|
|
|
kube::util::wait_for_url "http://${API_HOST_IP}:${API_SECURE_PORT}/healthz" "apiserver: " 1 ${WAIT_FOR_URL_API_SERVER} \
|
2017-02-03 00:47:15 +00:00
|
|
|
|| { echo "check apiserver logs: ${APISERVER_LOG}" ; exit 1 ; }
|
2016-11-12 22:09:04 +00:00
|
|
|
|
|
|
|
# Create kubeconfigs for all components, using client certs
|
2016-12-09 15:56:50 +00:00
|
|
|
kube::util::write_client_kubeconfig "${CONTROLPLANE_SUDO}" "${CERT_DIR}" "${ROOT_CA_FILE}" "${API_HOST}" "${API_SECURE_PORT}" admin
|
2017-02-06 22:07:06 +00:00
|
|
|
${CONTROLPLANE_SUDO} chown "${USER}" "${CERT_DIR}/client-admin.key" # make readable for kubectl
|
2016-12-09 15:56:50 +00:00
|
|
|
kube::util::write_client_kubeconfig "${CONTROLPLANE_SUDO}" "${CERT_DIR}" "${ROOT_CA_FILE}" "${API_HOST}" "${API_SECURE_PORT}" kubelet
|
|
|
|
kube::util::write_client_kubeconfig "${CONTROLPLANE_SUDO}" "${CERT_DIR}" "${ROOT_CA_FILE}" "${API_HOST}" "${API_SECURE_PORT}" kube-proxy
|
|
|
|
kube::util::write_client_kubeconfig "${CONTROLPLANE_SUDO}" "${CERT_DIR}" "${ROOT_CA_FILE}" "${API_HOST}" "${API_SECURE_PORT}" controller
|
|
|
|
kube::util::write_client_kubeconfig "${CONTROLPLANE_SUDO}" "${CERT_DIR}" "${ROOT_CA_FILE}" "${API_HOST}" "${API_SECURE_PORT}" scheduler
|
2016-12-02 03:04:25 +00:00
|
|
|
|
2017-02-06 01:23:01 +00:00
|
|
|
if [[ -z "${AUTH_ARGS}" ]]; then
|
|
|
|
if [[ "${ALLOW_ANY_TOKEN}" = true ]]; then
|
2016-12-02 03:04:25 +00:00
|
|
|
# use token authentication
|
2017-02-06 01:23:01 +00:00
|
|
|
if [[ -n "${KUBECONFIG_TOKEN}" ]]; then
|
2016-12-02 03:04:25 +00:00
|
|
|
AUTH_ARGS="--token=${KUBECONFIG_TOKEN}"
|
|
|
|
else
|
|
|
|
AUTH_ARGS="--token=system:admin/system:masters"
|
|
|
|
fi
|
|
|
|
else
|
2017-02-06 01:23:01 +00:00
|
|
|
# default to the admin client cert/key
|
2017-02-03 15:22:01 +00:00
|
|
|
AUTH_ARGS="--client-key=${CERT_DIR}/client-admin.key --client-certificate=${CERT_DIR}/client-admin.crt"
|
2016-12-02 03:04:25 +00:00
|
|
|
fi
|
|
|
|
fi
|
2017-02-01 20:17:51 +00:00
|
|
|
|
|
|
|
${CONTROLPLANE_SUDO} cp "${CERT_DIR}/admin.kubeconfig" "${CERT_DIR}/admin-kube-aggregator.kubeconfig"
|
|
|
|
${CONTROLPLANE_SUDO} chown $(whoami) "${CERT_DIR}/admin-kube-aggregator.kubeconfig"
|
2017-02-15 18:01:13 +00:00
|
|
|
${KUBECTL} config set-cluster local-up-cluster --kubeconfig="${CERT_DIR}/admin-kube-aggregator.kubeconfig" --server="https://${API_HOST_IP}:31090"
|
2017-02-01 20:17:51 +00:00
|
|
|
echo "use 'kubectl --kubeconfig=${CERT_DIR}/admin-kube-aggregator.kubeconfig' to use the aggregated API server"
|
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
}
|
2015-06-08 06:02:55 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
function start_controller_manager {
|
2015-12-16 23:31:10 +00:00
|
|
|
node_cidr_args=""
|
|
|
|
if [[ "${NET_PLUGIN}" == "kubenet" ]]; then
|
|
|
|
node_cidr_args="--allocate-node-cidrs=true --cluster-cidr=10.1.0.0/16 "
|
|
|
|
fi
|
|
|
|
|
2017-03-31 19:11:41 +00:00
|
|
|
CTLRMGR_LOG=${LOG_DIR}/kube-controller-manager.log
|
2016-11-24 09:23:23 +00:00
|
|
|
${CONTROLPLANE_SUDO} "${GO_OUT}/hyperkube" controller-manager \
|
2015-06-10 00:26:18 +00:00
|
|
|
--v=${LOG_LEVEL} \
|
2015-07-04 23:23:32 +00:00
|
|
|
--service-account-private-key-file="${SERVICE_ACCOUNT_KEY}" \
|
|
|
|
--root-ca-file="${ROOT_CA_FILE}" \
|
2015-10-12 18:27:49 +00:00
|
|
|
--enable-hostpath-provisioner="${ENABLE_HOSTPATH_PROVISIONER}" \
|
2015-12-16 23:31:10 +00:00
|
|
|
${node_cidr_args} \
|
2016-04-22 16:51:02 +00:00
|
|
|
--pvclaimbinder-sync-period="${CLAIM_BINDER_SYNC_PERIOD}" \
|
2016-09-26 17:15:34 +00:00
|
|
|
--feature-gates="${FEATURE_GATES}" \
|
2016-05-07 16:57:58 +00:00
|
|
|
--cloud-provider="${CLOUD_PROVIDER}" \
|
2016-06-16 18:16:58 +00:00
|
|
|
--cloud-config="${CLOUD_CONFIG}" \
|
2016-11-12 22:09:04 +00:00
|
|
|
--kubeconfig "$CERT_DIR"/controller.kubeconfig \
|
2017-02-08 15:16:46 +00:00
|
|
|
--use-service-account-credentials \
|
2016-10-06 19:59:14 +00:00
|
|
|
--master="https://${API_HOST}:${API_SECURE_PORT}" >"${CTLRMGR_LOG}" 2>&1 &
|
2015-06-10 00:26:18 +00:00
|
|
|
CTLRMGR_PID=$!
|
|
|
|
}
|
2014-06-16 05:06:55 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
function start_kubelet {
|
2017-03-31 19:11:41 +00:00
|
|
|
KUBELET_LOG=${LOG_DIR}/kubelet.log
|
2017-02-01 20:17:51 +00:00
|
|
|
mkdir -p ${POD_MANIFEST_PATH} || true
|
2015-11-03 20:00:43 +00:00
|
|
|
|
2016-08-31 19:36:54 +00:00
|
|
|
priv_arg=""
|
|
|
|
if [[ -n "${ALLOW_PRIVILEGED}" ]]; then
|
|
|
|
priv_arg="--allow-privileged "
|
|
|
|
fi
|
|
|
|
|
2015-11-03 20:00:43 +00:00
|
|
|
mkdir -p /var/lib/kubelet
|
2015-06-10 00:26:18 +00:00
|
|
|
if [[ -z "${DOCKERIZE_KUBELET}" ]]; then
|
2015-12-30 22:48:00 +00:00
|
|
|
# Enable dns
|
|
|
|
if [[ "${ENABLE_CLUSTER_DNS}" = true ]]; then
|
|
|
|
dns_args="--cluster-dns=${DNS_SERVER_IP} --cluster-domain=${DNS_DOMAIN}"
|
|
|
|
else
|
2016-03-03 22:59:40 +00:00
|
|
|
# To start a private DNS server set ENABLE_CLUSTER_DNS and
|
|
|
|
# DNS_SERVER_IP/DOMAIN. This will at least provide a working
|
|
|
|
# DNS server for real world hostnames.
|
|
|
|
dns_args="--cluster-dns=8.8.8.8"
|
2015-12-30 22:48:00 +00:00
|
|
|
fi
|
2015-11-03 20:00:43 +00:00
|
|
|
|
2015-12-16 23:31:10 +00:00
|
|
|
net_plugin_args=""
|
|
|
|
if [[ -n "${NET_PLUGIN}" ]]; then
|
|
|
|
net_plugin_args="--network-plugin=${NET_PLUGIN}"
|
|
|
|
fi
|
2016-09-26 17:15:34 +00:00
|
|
|
|
2016-11-03 05:13:00 +00:00
|
|
|
auth_args=""
|
2016-11-07 02:08:34 +00:00
|
|
|
if [[ -n "${KUBELET_AUTHORIZATION_WEBHOOK:-}" ]]; then
|
2016-11-03 05:13:00 +00:00
|
|
|
auth_args="${auth_args} --authorization-mode=Webhook"
|
|
|
|
fi
|
2016-11-07 02:08:34 +00:00
|
|
|
if [[ -n "${KUBELET_AUTHENTICATION_WEBHOOK:-}" ]]; then
|
2016-11-03 05:13:00 +00:00
|
|
|
auth_args="${auth_args} --authentication-token-webhook"
|
|
|
|
fi
|
|
|
|
if [[ -n "${CLIENT_CA_FILE:-}" ]]; then
|
|
|
|
auth_args="${auth_args} --client-ca-file=${CLIENT_CA_FILE}"
|
|
|
|
fi
|
|
|
|
|
2016-04-29 03:48:11 +00:00
|
|
|
net_plugin_dir_args=""
|
|
|
|
if [[ -n "${NET_PLUGIN_DIR}" ]]; then
|
|
|
|
net_plugin_dir_args="--network-plugin-dir=${NET_PLUGIN_DIR}"
|
|
|
|
fi
|
2015-12-16 23:31:10 +00:00
|
|
|
|
2016-08-24 10:49:25 +00:00
|
|
|
container_runtime_endpoint_args=""
|
|
|
|
if [[ -n "${CONTAINER_RUNTIME_ENDPOINT}" ]]; then
|
|
|
|
container_runtime_endpoint_args="--container-runtime-endpoint=${CONTAINER_RUNTIME_ENDPOINT}"
|
|
|
|
fi
|
|
|
|
|
|
|
|
image_service_endpoint_args=""
|
|
|
|
if [[ -n "${IMAGE_SERVICE_ENDPOINT}" ]]; then
|
2016-11-07 02:08:34 +00:00
|
|
|
image_service_endpoint_args="--image-service-endpoint=${IMAGE_SERVICE_ENDPOINT}"
|
2016-08-24 10:49:25 +00:00
|
|
|
fi
|
|
|
|
|
2016-05-15 13:38:11 +00:00
|
|
|
sudo -E "${GO_OUT}/hyperkube" kubelet ${priv_arg}\
|
2017-03-01 07:21:13 +00:00
|
|
|
--enable-cri="${ENABLE_CRI}" \
|
2015-06-10 00:26:18 +00:00
|
|
|
--v=${LOG_LEVEL} \
|
2015-07-04 23:23:32 +00:00
|
|
|
--chaos-chance="${CHAOS_CHANCE}" \
|
|
|
|
--container-runtime="${CONTAINER_RUNTIME}" \
|
2015-09-01 21:32:52 +00:00
|
|
|
--rkt-path="${RKT_PATH}" \
|
|
|
|
--rkt-stage1-image="${RKT_STAGE1_IMAGE}" \
|
2016-02-18 20:47:58 +00:00
|
|
|
--hostname-override="${HOSTNAME_OVERRIDE}" \
|
2016-05-07 16:57:58 +00:00
|
|
|
--cloud-provider="${CLOUD_PROVIDER}" \
|
2016-06-16 18:16:58 +00:00
|
|
|
--cloud-config="${CLOUD_CONFIG}" \
|
2016-05-27 18:13:24 +00:00
|
|
|
--address="${KUBELET_HOST}" \
|
2016-10-06 19:59:14 +00:00
|
|
|
--require-kubeconfig \
|
2016-11-12 22:09:04 +00:00
|
|
|
--kubeconfig "$CERT_DIR"/kubelet.kubeconfig \
|
2016-09-26 17:15:34 +00:00
|
|
|
--feature-gates="${FEATURE_GATES}" \
|
2015-09-22 20:28:22 +00:00
|
|
|
--cpu-cfs-quota=${CPU_CFS_QUOTA} \
|
2016-08-31 19:36:54 +00:00
|
|
|
--enable-controller-attach-detach="${ENABLE_CONTROLLER_ATTACH_DETACH}" \
|
2017-02-03 22:28:23 +00:00
|
|
|
--cgroups-per-qos=${CGROUPS_PER_QOS} \
|
2016-10-17 17:23:48 +00:00
|
|
|
--cgroup-driver=${CGROUP_DRIVER} \
|
2016-11-21 16:48:50 +00:00
|
|
|
--keep-terminated-pod-volumes=true \
|
2017-02-08 17:58:02 +00:00
|
|
|
--eviction-hard=${EVICTION_HARD} \
|
|
|
|
--eviction-soft=${EVICTION_SOFT} \
|
|
|
|
--eviction-pressure-transition-period=${EVICTION_PRESSURE_TRANSITION_PERIOD} \
|
2017-02-08 15:11:25 +00:00
|
|
|
--pod-manifest-path="${POD_MANIFEST_PATH}" \
|
2016-11-03 05:13:00 +00:00
|
|
|
${auth_args} \
|
2015-12-30 22:48:00 +00:00
|
|
|
${dns_args} \
|
2016-04-29 03:48:11 +00:00
|
|
|
${net_plugin_dir_args} \
|
2015-12-16 23:31:10 +00:00
|
|
|
${net_plugin_args} \
|
2016-08-24 10:49:25 +00:00
|
|
|
${container_runtime_endpoint_args} \
|
|
|
|
${image_service_endpoint_args} \
|
2017-02-10 05:14:10 +00:00
|
|
|
--port="$KUBELET_PORT" \
|
|
|
|
${KUBELET_FLAGS} >"${KUBELET_LOG}" 2>&1 &
|
2015-06-10 00:26:18 +00:00
|
|
|
KUBELET_PID=$!
|
2016-11-16 19:49:19 +00:00
|
|
|
# Quick check that kubelet is running.
|
|
|
|
if ps -p $KUBELET_PID > /dev/null ; then
|
|
|
|
echo "kubelet ( $KUBELET_PID ) is running."
|
|
|
|
else
|
|
|
|
cat ${KUBELET_LOG} ; exit 1
|
|
|
|
fi
|
2015-06-10 00:26:18 +00:00
|
|
|
else
|
|
|
|
# Docker won't run a container with a cidfile (container id file)
|
|
|
|
# unless that file does not already exist; clean up an existing
|
|
|
|
# dockerized kubelet that might be running.
|
|
|
|
cleanup_dockerized_kubelet
|
2016-06-16 18:16:58 +00:00
|
|
|
cred_bind=""
|
2016-11-04 08:56:47 +00:00
|
|
|
# path to cloud credentials.
|
2016-06-16 18:16:58 +00:00
|
|
|
cloud_cred=""
|
|
|
|
if [ "${CLOUD_PROVIDER}" == "aws" ]; then
|
|
|
|
cloud_cred="${HOME}/.aws/credentials"
|
|
|
|
fi
|
|
|
|
if [ "${CLOUD_PROVIDER}" == "gce" ]; then
|
|
|
|
cloud_cred="${HOME}/.config/gcloud"
|
|
|
|
fi
|
|
|
|
if [ "${CLOUD_PROVIDER}" == "openstack" ]; then
|
|
|
|
cloud_cred="${CLOUD_CONFIG}"
|
|
|
|
fi
|
|
|
|
if [[ -n "${cloud_cred}" ]]; then
|
|
|
|
cred_bind="--volume=${cloud_cred}:${cloud_cred}:ro"
|
|
|
|
fi
|
2015-06-10 00:26:18 +00:00
|
|
|
|
|
|
|
docker run \
|
|
|
|
--volume=/:/rootfs:ro \
|
|
|
|
--volume=/var/run:/var/run:rw \
|
|
|
|
--volume=/sys:/sys:ro \
|
|
|
|
--volume=/var/lib/docker/:/var/lib/docker:ro \
|
2016-10-24 16:23:38 +00:00
|
|
|
--volume=/var/lib/kubelet/:/var/lib/kubelet:rw \
|
2016-06-16 18:16:58 +00:00
|
|
|
--volume=/dev:/dev \
|
|
|
|
${cred_bind} \
|
2015-06-10 00:26:18 +00:00
|
|
|
--net=host \
|
|
|
|
--privileged=true \
|
|
|
|
-i \
|
|
|
|
--cidfile=$KUBELET_CIDFILE \
|
|
|
|
gcr.io/google_containers/kubelet \
|
2017-02-08 15:11:25 +00:00
|
|
|
/kubelet --v=${LOG_LEVEL} --containerized ${priv_arg}--chaos-chance="${CHAOS_CHANCE}" --pod-manifest-path="${POD_MANIFEST_PATH}" --hostname-override="${HOSTNAME_OVERRIDE}" --cloud-provider="${CLOUD_PROVIDER}" --cloud-config="${CLOUD_CONFIG}" \ --address="127.0.0.1" --require-kubeconfig --kubeconfig "$CERT_DIR"/kubelet.kubeconfig --api-servers="https://${API_HOST}:${API_SECURE_PORT}" --port="$KUBELET_PORT" --enable-controller-attach-detach="${ENABLE_CONTROLLER_ATTACH_DETACH}" &> $KUBELET_LOG &
|
2015-06-10 00:26:18 +00:00
|
|
|
fi
|
|
|
|
}
|
2014-06-16 05:06:55 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
function start_kubeproxy {
|
2017-03-31 19:11:41 +00:00
|
|
|
PROXY_LOG=${LOG_DIR}/kube-proxy.log
|
2016-11-24 09:23:23 +00:00
|
|
|
sudo "${GO_OUT}/hyperkube" proxy \
|
2015-06-10 00:26:18 +00:00
|
|
|
--v=${LOG_LEVEL} \
|
2016-02-18 20:47:58 +00:00
|
|
|
--hostname-override="${HOSTNAME_OVERRIDE}" \
|
2016-09-26 17:15:34 +00:00
|
|
|
--feature-gates="${FEATURE_GATES}" \
|
2016-11-12 22:09:04 +00:00
|
|
|
--kubeconfig "$CERT_DIR"/kube-proxy.kubeconfig \
|
2016-10-06 19:59:14 +00:00
|
|
|
--master="https://${API_HOST}:${API_SECURE_PORT}" >"${PROXY_LOG}" 2>&1 &
|
2015-06-10 00:26:18 +00:00
|
|
|
PROXY_PID=$!
|
|
|
|
|
2017-03-31 19:11:41 +00:00
|
|
|
SCHEDULER_LOG=${LOG_DIR}/kube-scheduler.log
|
2016-11-24 09:23:23 +00:00
|
|
|
${CONTROLPLANE_SUDO} "${GO_OUT}/hyperkube" scheduler \
|
2015-06-10 00:26:18 +00:00
|
|
|
--v=${LOG_LEVEL} \
|
2016-11-12 22:09:04 +00:00
|
|
|
--kubeconfig "$CERT_DIR"/scheduler.kubeconfig \
|
2016-10-06 19:59:14 +00:00
|
|
|
--master="https://${API_HOST}:${API_SECURE_PORT}" >"${SCHEDULER_LOG}" 2>&1 &
|
2015-06-10 00:26:18 +00:00
|
|
|
SCHEDULER_PID=$!
|
|
|
|
}
|
2014-08-29 00:48:36 +00:00
|
|
|
|
2015-12-30 22:48:00 +00:00
|
|
|
function start_kubedns {
|
|
|
|
if [[ "${ENABLE_CLUSTER_DNS}" = true ]]; then
|
|
|
|
echo "Creating kube-system namespace"
|
2016-12-13 23:16:34 +00:00
|
|
|
sed -e "s/{{ pillar\['dns_domain'\] }}/${DNS_DOMAIN}/g" "${KUBE_ROOT}/cluster/addons/dns/kubedns-controller.yaml.in" >| kubedns-deployment.yaml
|
2016-06-27 21:44:32 +00:00
|
|
|
if [[ "${FEDERATION:-}" == "true" ]]; then
|
|
|
|
FEDERATIONS_DOMAIN_MAP="${FEDERATIONS_DOMAIN_MAP:-}"
|
|
|
|
if [[ -z "${FEDERATIONS_DOMAIN_MAP}" && -n "${FEDERATION_NAME:-}" && -n "${DNS_ZONE_NAME:-}" ]]; then
|
|
|
|
FEDERATIONS_DOMAIN_MAP="${FEDERATION_NAME}=${DNS_ZONE_NAME}"
|
|
|
|
fi
|
|
|
|
if [[ -n "${FEDERATIONS_DOMAIN_MAP}" ]]; then
|
2016-12-13 23:16:34 +00:00
|
|
|
sed -i -e "s/{{ pillar\['federations_domain_map'\] }}/- --federations=${FEDERATIONS_DOMAIN_MAP}/g" kubedns-deployment.yaml
|
2016-06-27 21:44:32 +00:00
|
|
|
else
|
2016-12-13 23:16:34 +00:00
|
|
|
sed -i -e "/{{ pillar\['federations_domain_map'\] }}/d" kubedns-deployment.yaml
|
2016-06-27 21:44:32 +00:00
|
|
|
fi
|
|
|
|
else
|
2016-12-13 23:16:34 +00:00
|
|
|
sed -i -e "/{{ pillar\['federations_domain_map'\] }}/d" kubedns-deployment.yaml
|
2016-06-27 21:44:32 +00:00
|
|
|
fi
|
2016-12-12 13:55:08 +00:00
|
|
|
sed -e "s/{{ pillar\['dns_server'\] }}/${DNS_SERVER_IP}/g" "${KUBE_ROOT}/cluster/addons/dns/kubedns-svc.yaml.in" >| kubedns-svc.yaml
|
2016-12-08 19:19:05 +00:00
|
|
|
|
|
|
|
# TODO update to dns role once we have one.
|
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" create clusterrolebinding system:kube-dns --clusterrole=cluster-admin --serviceaccount=kube-system:default
|
2017-01-08 00:33:28 +00:00
|
|
|
# use kubectl to create kubedns deployment and service
|
2016-12-15 14:52:56 +00:00
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" --namespace=kube-system create -f ${KUBE_ROOT}/cluster/addons/dns/kubedns-sa.yaml
|
2017-03-09 00:45:22 +00:00
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" --namespace=kube-system create -f ${KUBE_ROOT}/cluster/addons/dns/kubedns-cm.yaml
|
2016-12-13 23:16:34 +00:00
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" --namespace=kube-system create -f kubedns-deployment.yaml
|
2016-12-12 13:55:08 +00:00
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" --namespace=kube-system create -f kubedns-svc.yaml
|
2017-01-08 00:33:28 +00:00
|
|
|
echo "Kube-dns deployment and service successfully deployed."
|
2016-12-13 23:16:34 +00:00
|
|
|
rm kubedns-deployment.yaml kubedns-svc.yaml
|
2015-12-30 22:48:00 +00:00
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
2016-12-29 08:08:42 +00:00
|
|
|
function create_psp_policy {
|
|
|
|
echo "Create podsecuritypolicy policies for RBAC."
|
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" create -f ${KUBE_ROOT}/examples/podsecuritypolicy/rbac/policies.yaml
|
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" create -f ${KUBE_ROOT}/examples/podsecuritypolicy/rbac/roles.yaml
|
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" create -f ${KUBE_ROOT}/examples/podsecuritypolicy/rbac/bindings.yaml
|
|
|
|
}
|
|
|
|
|
2017-02-16 09:28:29 +00:00
|
|
|
function create_storage_class {
|
|
|
|
if [ -z "$CLOUD_PROVIDER" ]; then
|
|
|
|
# No cloud provider -> no default storage class
|
|
|
|
return
|
|
|
|
fi
|
|
|
|
|
|
|
|
CLASS_FILE=${KUBE_ROOT}/cluster/addons/storage-class/${CLOUD_PROVIDER}/default.yaml
|
|
|
|
if [ -e $CLASS_FILE ]; then
|
|
|
|
echo "Create default storage class for $CLOUD_PROVIDER"
|
|
|
|
${KUBECTL} --kubeconfig="${CERT_DIR}/admin.kubeconfig" create -f $CLASS_FILE
|
|
|
|
else
|
|
|
|
echo "No storage class available for $CLOUD_PROVIDER."
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
function print_success {
|
2016-08-31 19:36:54 +00:00
|
|
|
if [[ "${START_MODE}" != "kubeletonly" ]]; then
|
|
|
|
cat <<EOF
|
2014-12-16 22:21:22 +00:00
|
|
|
Local Kubernetes cluster is running. Press Ctrl-C to shut it down.
|
|
|
|
|
|
|
|
Logs:
|
2016-08-31 19:36:54 +00:00
|
|
|
${APISERVER_LOG:-}
|
|
|
|
${CTLRMGR_LOG:-}
|
|
|
|
${PROXY_LOG:-}
|
|
|
|
${SCHEDULER_LOG:-}
|
|
|
|
EOF
|
|
|
|
fi
|
2014-12-16 22:21:22 +00:00
|
|
|
|
2017-03-02 01:18:37 +00:00
|
|
|
if [[ "${ENABLE_APISERVER_BASIC_AUDIT:-}" = true ]]; then
|
|
|
|
echo " ${APISERVER_BASIC_AUDIT_LOG}"
|
|
|
|
fi
|
|
|
|
|
2016-08-31 19:36:54 +00:00
|
|
|
if [[ "${START_MODE}" == "all" ]]; then
|
|
|
|
echo " ${KUBELET_LOG}"
|
|
|
|
elif [[ "${START_MODE}" == "nokubelet" ]]; then
|
|
|
|
echo
|
|
|
|
echo "No kubelet was started because you set START_MODE=nokubelet"
|
|
|
|
echo "Run this script again with START_MODE=kubeletonly to run a kubelet"
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [[ "${START_MODE}" != "kubeletonly" ]]; then
|
|
|
|
echo
|
|
|
|
cat <<EOF
|
2017-02-06 01:23:01 +00:00
|
|
|
To start using your cluster, you can open up another terminal/tab and run:
|
|
|
|
|
|
|
|
export KUBECONFIG=${CERT_DIR}/admin.kubeconfig
|
|
|
|
cluster/kubectl.sh
|
|
|
|
|
|
|
|
Alternatively, you can write to the default kubeconfig:
|
2014-12-16 22:21:22 +00:00
|
|
|
|
2016-06-23 10:59:41 +00:00
|
|
|
export KUBERNETES_PROVIDER=local
|
|
|
|
|
2016-10-06 19:59:14 +00:00
|
|
|
cluster/kubectl.sh config set-cluster local --server=https://${API_HOST}:${API_SECURE_PORT} --certificate-authority=${ROOT_CA_FILE}
|
2016-12-02 03:04:25 +00:00
|
|
|
cluster/kubectl.sh config set-credentials myself ${AUTH_ARGS}
|
2016-10-06 19:59:14 +00:00
|
|
|
cluster/kubectl.sh config set-context local --cluster=local --user=myself
|
2015-02-12 23:04:00 +00:00
|
|
|
cluster/kubectl.sh config use-context local
|
2014-12-16 22:21:22 +00:00
|
|
|
cluster/kubectl.sh
|
|
|
|
EOF
|
2016-09-26 17:15:34 +00:00
|
|
|
else
|
2016-08-31 19:36:54 +00:00
|
|
|
cat <<EOF
|
|
|
|
The kubelet was started.
|
|
|
|
|
|
|
|
Logs:
|
|
|
|
${KUBELET_LOG}
|
|
|
|
EOF
|
|
|
|
fi
|
2015-06-10 00:26:18 +00:00
|
|
|
}
|
|
|
|
|
2016-12-13 17:29:47 +00:00
|
|
|
# validate that etcd is: not running, in path, and has minimum required version.
|
|
|
|
kube::etcd::validate
|
|
|
|
|
|
|
|
if [ "${CONTAINER_RUNTIME}" == "docker" ] && ! kube::util::ensure_docker_daemon_connectivity; then
|
|
|
|
exit 1
|
2016-11-04 08:56:47 +00:00
|
|
|
fi
|
|
|
|
|
|
|
|
if [[ "${CONTAINER_RUNTIME}" == "rkt" ]]; then
|
|
|
|
test_rkt
|
|
|
|
fi
|
2016-08-31 19:36:54 +00:00
|
|
|
|
|
|
|
if [[ "${START_MODE}" != "kubeletonly" ]]; then
|
|
|
|
test_apiserver_off
|
|
|
|
fi
|
|
|
|
|
2016-12-09 15:56:50 +00:00
|
|
|
kube::util::test_openssl_installed
|
|
|
|
kube::util::test_cfssl_installed
|
2015-06-15 23:34:41 +00:00
|
|
|
|
|
|
|
### IF the user didn't supply an output/ for the build... Then we detect.
|
2015-08-26 10:19:27 +00:00
|
|
|
if [ "$GO_OUT" == "" ]; then
|
2017-02-06 01:23:01 +00:00
|
|
|
detect_binary
|
2015-06-15 23:34:41 +00:00
|
|
|
fi
|
2015-06-10 00:26:18 +00:00
|
|
|
echo "Detected host and ready to start services. Doing some housekeeping first..."
|
2015-06-15 23:34:41 +00:00
|
|
|
echo "Using GO_OUT $GO_OUT"
|
2015-06-10 00:26:18 +00:00
|
|
|
KUBELET_CIDFILE=/tmp/kubelet.cid
|
2015-12-30 22:48:00 +00:00
|
|
|
if [[ "${ENABLE_DAEMON}" = false ]]; then
|
2017-02-06 01:23:01 +00:00
|
|
|
trap cleanup EXIT
|
2015-12-30 22:48:00 +00:00
|
|
|
fi
|
2016-08-31 19:36:54 +00:00
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
echo "Starting services now!"
|
2016-08-31 19:36:54 +00:00
|
|
|
if [[ "${START_MODE}" != "kubeletonly" ]]; then
|
|
|
|
start_etcd
|
|
|
|
set_service_accounts
|
|
|
|
start_apiserver
|
|
|
|
start_controller_manager
|
|
|
|
start_kubeproxy
|
|
|
|
start_kubedns
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [[ "${START_MODE}" != "nokubelet" ]]; then
|
2017-01-26 20:57:58 +00:00
|
|
|
## TODO remove this check if/when kubelet is supported on darwin
|
2017-01-26 21:11:27 +00:00
|
|
|
# Detect the OS name/arch and display appropriate error.
|
2017-01-26 20:57:58 +00:00
|
|
|
case "$(uname -s)" in
|
|
|
|
Darwin)
|
|
|
|
warning "kubelet is not currently supported in darwin, kubelet aborted."
|
|
|
|
KUBELET_LOG=""
|
|
|
|
;;
|
|
|
|
Linux)
|
|
|
|
start_kubelet
|
|
|
|
;;
|
|
|
|
*)
|
2017-01-26 21:11:27 +00:00
|
|
|
warning "Unsupported host OS. Must be Linux or Mac OS X, kubelet aborted."
|
2017-01-26 20:57:58 +00:00
|
|
|
;;
|
|
|
|
esac
|
2016-09-26 17:15:34 +00:00
|
|
|
fi
|
2016-08-31 19:36:54 +00:00
|
|
|
|
2016-12-29 08:08:42 +00:00
|
|
|
if [[ -n "${PSP_ADMISSION}" && "${ENABLE_RBAC}" = true ]]; then
|
2017-02-06 01:23:01 +00:00
|
|
|
create_psp_policy
|
2016-12-29 08:08:42 +00:00
|
|
|
fi
|
|
|
|
|
2017-02-16 09:28:29 +00:00
|
|
|
if [[ "$DEFAULT_STORAGE_CLASS" = "true" ]]; then
|
|
|
|
create_storage_class
|
|
|
|
fi
|
|
|
|
|
2015-06-10 00:26:18 +00:00
|
|
|
print_success
|
2014-06-25 19:19:37 +00:00
|
|
|
|
2015-12-30 22:48:00 +00:00
|
|
|
if [[ "${ENABLE_DAEMON}" = false ]]; then
|
2017-02-06 01:23:01 +00:00
|
|
|
while true; do sleep 1; done
|
2015-12-30 22:48:00 +00:00
|
|
|
fi
|
2017-01-26 20:57:58 +00:00
|
|
|
|
|
|
|
|