Merge pull request #72727 from bart0sh/PR0057-kubeadm-selfhosting-pivot-controller-manager-add-front-proxy-ca

kubeadm: add front-proxy CA certificate to selfhosting controller-manager
pull/564/head
Kubernetes Prow Robot 2019-01-10 05:06:57 -08:00 committed by GitHub
commit 3d9c6eb9e6
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 15 additions and 0 deletions

View File

@ -225,6 +225,7 @@ spec:
- --cluster-signing-key-file=/etc/kubernetes/pki/ca.key - --cluster-signing-key-file=/etc/kubernetes/pki/ca.key
- --bind-address=127.0.0.1 - --bind-address=127.0.0.1
- --use-service-account-credentials=true - --use-service-account-credentials=true
- --requestheader-client-ca-file=/etc/kubernetes/pki/front-proxy-ca.crt
image: k8s.gcr.io/kube-controller-manager-amd64:v1.7.4 image: k8s.gcr.io/kube-controller-manager-amd64:v1.7.4
livenessProbe: livenessProbe:
failureThreshold: 8 failureThreshold: 8
@ -300,6 +301,7 @@ spec:
- --cluster-signing-key-file=/etc/kubernetes/pki/ca.key - --cluster-signing-key-file=/etc/kubernetes/pki/ca.key
- --bind-address=127.0.0.1 - --bind-address=127.0.0.1
- --use-service-account-credentials=true - --use-service-account-credentials=true
- --requestheader-client-ca-file=/etc/kubernetes/pki/front-proxy-ca.crt
image: k8s.gcr.io/kube-controller-manager-amd64:v1.7.4 image: k8s.gcr.io/kube-controller-manager-amd64:v1.7.4
livenessProbe: livenessProbe:
failureThreshold: 8 failureThreshold: 8

View File

@ -202,6 +202,19 @@ func controllerManagerCertificatesVolumeSource() v1.VolumeSource {
}, },
}, },
}, },
{
Secret: &v1.SecretProjection{
LocalObjectReference: v1.LocalObjectReference{
Name: kubeadmconstants.FrontProxyCACertAndKeyBaseName,
},
Items: []v1.KeyToPath{
{
Key: v1.TLSCertKey,
Path: kubeadmconstants.FrontProxyCACertName,
},
},
},
},
}, },
}, },
} }