Quintin Lee
b886897f9d
Prepend the metadata firewall in gce, so it isn't superceded.
2017-06-16 10:08:48 -07:00
Kubernetes Submit Queue
4c7e1590ee
Merge pull request #40760 from mikedanese/gce
...
Automatic merge from submit-queue (batch tested with PRs 40760, 46706, 46783, 46742, 46751)
enable kubelet csr bootstrap in GCE/GKE
@jcbsmpsn @pipejakob
Fixes https://github.com/kubernetes/kubernetes/issues/31168
```release-note
Enable kubelet csr bootstrap in GCE/GKE
```
2017-06-03 18:30:38 -07:00
Mike Danese
ae91ecb62e
enable tls bootstrap in GCE/GKE
2017-06-01 09:17:32 -07:00
Quintin Lee
1bfed01480
Adding a metadata proxy addon to gce
2017-05-31 16:23:11 -07:00
Bowei Du
345c65847f
Add KUBE_GCE_ENABLE_IP_ALIASES flag to the cluster turn up scripts.
...
KUBE_GCE_ENABLE_IP_ALIASES=true will enable allocation of PodCIDR ips
using the ip alias mechanism rather than using routes.
NODE_IP_RANGE will control the node instance IP cidr
KUBE_GCE_IP_ALIAS_SIZE controls the size of each podCIDR
IP_ALIAS_SUBNETWORK controls the name of the subnet created for the cluster
2017-04-11 14:07:50 -07:00
Mike Danese
e2d7e2c866
make salt return non-zero exit code on failure
2017-04-06 13:57:33 -07:00
Kubernetes Submit Queue
b41e415ebd
Merge pull request #43137 from shashidharatd/federation-domain
...
Automatic merge from submit-queue
[Federation] Remove FEDERATIONS_DOMAIN_MAP references
Remove all references to FEDERATIONS_DOMAIN_MAP as this method is no longer is used and is replaced by adding federation domain map to kube-dns configmap.
cc @madhusudancs @kubernetes/sig-federation-pr-reviews
**Release note**:
```
[Federation] Mechanism of adding `federation domain maps` to kube-dns deployment via `--federations` flag is superseded by adding/updating `federations` key in `kube-system/kube-dns` configmap. If user is using kubefed tool to join cluster federation, adding federation domain maps to kube-dns is already taken care by `kubefed join` and does not need further action.
```
2017-04-06 02:05:42 -07:00
Matt Liggett
c79d74f382
Force create symlinks.
2017-03-15 14:03:46 -07:00
shashidharatd
b09b20b598
Remove FEDERATIONS_DOMAIN_MAP references
2017-03-15 23:06:16 +05:30
Mike Danese
361c40cc66
add a compatibility shim for certs to support a cluster downgrade
2017-03-14 09:25:50 -07:00
Kubernetes Submit Queue
097755fbd9
Merge pull request #41666 from mikedanese/cvm-master
...
Automatic merge from submit-queue (batch tested with PRs 41306, 42187, 41666, 42275, 42266)
remove support for debian masters in GCE
Asked about this on the mailing list and no one objects.
@zmerlynn @roberthbailey
```release-note
Remove support for debian masters in GCE kube-up.
```
2017-03-03 10:54:42 -08:00
Kubernetes Submit Queue
1864e0516d
Merge pull request #42192 from mikedanese/mds-block
...
Automatic merge from submit-queue (batch tested with PRs 41980, 42192, 42223, 41822, 42048)
add kube-env variable to block traffic to metadataserver
@Q-Lee @thockin
2017-03-02 00:59:16 -08:00
Mike Danese
90b26465d7
fix upgrades
2017-02-28 14:52:37 -08:00
Mike Danese
cb9bdb8813
remove support for debian masters in GCE
2017-02-28 09:54:07 -08:00
Mike Danese
34e02c9989
add kube-env variable to block traffic to metadataserver
2017-02-27 16:54:44 -08:00
Mike Danese
192392bddd
refactor certs in GCE
2017-02-23 10:12:31 -08:00
Wojciech Tyczynski
3695e85b34
Expose storage media type as env variable
2017-02-17 14:16:55 +01:00
Jerzy Szczepkowski
80e57b7016
Added configurable etcd initial-cluster-state to kube-up script.
...
Added configurable etcd initial-cluster-state to kube-up script. This
allows creation of multi-master cluster from scratch. This is a
cherry-pick of #41320 from 1.5 branch.
2017-02-13 16:10:47 +01:00
Mike Danese
c8ce55fef4
Revert "Merge pull request #41132 from kubernetes/revert-40893-kubelet-auth"
...
This reverts commit fd56078298
, reversing
changes made to d953402cdf
.
2017-02-09 15:55:12 -08:00
Aleksandra Malinowska
1841e5b2e0
Revert "remove second CA used for kubelet auth in favor of webhook auth"
2017-02-08 13:22:10 +01:00
Mike Danese
86d9493747
remove second CA used for kubelet auth in favor of webhook auth
2017-02-07 13:22:01 -08:00
CJ Cullen
d0997a3d1f
Generate a kubelet CA and kube-apiserver cert-pair for kubelet auth.
...
Plumb through to kubelet/kube-apiserver on gci & cvm.
2017-01-03 14:30:45 -08:00
Justin Santa Barbara
ca22a75015
kube-up: Only specify ETCD_QUORUM_READ if non-empty
...
Fix #38290
2016-12-07 09:45:24 -05:00
Dawn Chen
38a63e388d
Set kernel.softlockup_panic =1 based on the flag.
2016-12-02 16:09:16 -08:00
Kubernetes Submit Queue
1570aad238
Merge pull request #37451 from jszczepkowski/ha-read-quorum
...
Automatic merge from submit-queue
Added setting etcd read quorum flag
2016-12-01 06:31:24 -08:00
Jerzy Szczepkowski
02542cae06
Added setting etcd read quorum flag.
...
Added setting etcd read quorum flag in kube-up scripts. Required for HA master.
2016-11-25 13:53:11 +01:00
Jan Safranek
b52d971aee
stash
2016-11-21 10:16:29 +01:00
Jerzy Szczepkowski
ab7266bf19
SSL certificates for etcd cluster.
...
Added generation of SSL certificates for etcd cluster internal
communication. Turned on on gci & trusty.
2016-11-10 15:26:03 +01:00
Zihong Zheng
b26faae7fc
Migrates addons from using ReplicationControllers to Deployments
2016-11-09 09:17:05 -08:00
Kubernetes Submit Queue
a0c34eee35
Merge pull request #33239 from MrHohn/dns-autoscaler
...
Automatic merge from submit-queue
Deploy kube-dns with cluster-proportional-autoscaler
This PR integrates [cluster-proportional-autoscaler](https://github.com/kubernetes-incubator/cluster-proportional-autoscaler ) with kube-dns for DNS horizontal autoscaling.
Fixes #28648 and #27781 .
2016-11-07 19:31:31 -08:00
Zihong Zheng
d961190e6f
Deployed DNS horizontal autoscaler as an addon
...
DNS horizontal autoscaling feature is turned on by default on gce.
The corresponding env var is piped into almost all other cloud
providers.
2016-11-07 10:44:44 -08:00
Kubernetes Submit Queue
182a09c3c7
Merge pull request #35526 from justinsb/fix_35521_b
...
Automatic merge from submit-queue
kubelet bootstrap: start hostNetwork pods before we have PodCIDR
Network readiness was checked in the pod admission phase, but pods that
fail admission are not retried. Move the check to the pod start phase.
Issue #35409
Issue #35521
2016-11-06 12:53:14 -08:00
Wojciech Tyczynski
3ca1f06149
Prepare for easy change to etcd3 storage backend
2016-11-04 13:46:01 +01:00
Justin Santa Barbara
68c0b4268b
Update bringup: don't pass in dummy pod-cidr
...
We no longer pass in a "dummy" pod-cidr (10.123.45.0/29), and rely on
reconcile-cidr=true instead (which is the default).
2016-11-04 00:11:55 -04:00
Wojciech Tyczynski
c2248324c1
Expose etcd version.
2016-11-02 17:03:13 +01:00
Wojciech Tyczynski
7ee7b55c5e
Rename TEST_ETCD_VERSION to ETCD_VERSION
2016-10-28 13:56:59 +02:00
Yu-Ju Hong
94f580ef03
Revert "bootstrap: Start hostNetwork pods even if network plugin not ready"
2016-10-25 08:38:59 -07:00
Justin Santa Barbara
6465742da1
Update bringup: don't pass in dummy pod-cidr
...
We no longer pass in a "dummy" pod-cidr (10.123.45.0/29), and rely on
reconcile-cidr=true instead (which is the default).
2016-10-22 11:16:19 -04:00
Mike Danese
51ec7c2845
retry salt-call in configure-vm.sh
2016-10-12 10:25:32 -07:00
Minhan Xia
879a2dcdbd
bump master cidr range from /30 to /29
2016-09-16 13:41:58 -07:00
Jeff Lowdermilk
e7c42280f8
fix feature_gates salt plumbing
2016-08-25 17:34:41 -07:00
Kubernetes Submit Queue
6e75fa9745
Merge pull request #31103 from mwielgus/scheduling-alg-provider-flag
...
Automatic merge from submit-queue
Scheduling algorithm provider flag in kube-up.sh
Follow up of:
#30274 #30992
cc: @piosz @wojtek-t @davidopp
2016-08-23 01:44:54 -07:00
Quintin Lee
182a4fd0ac
Scripts to configure image verification admission controller for gce.
2016-08-22 16:54:03 -07:00
Marcin Wielgus
11fabd7176
Scheduling algorithm provider flag in kube-up.sh
2016-08-22 17:49:00 +02:00
Kubernetes Submit Queue
9030a3234f
Merge pull request #30859 from wojtek-t/allow_custom_etcd_in_e2e
...
Automatic merge from submit-queue
Add possibility to run non-default etcd image in tests
Ref #20504
@lavalamp @hongchaodeng @timothysc - FYI
2016-08-20 09:32:35 -07:00
Jeff Lowdermilk
51198f59da
Add --feature-gates to kube-system components
...
apiserver,scheduler,controller-manager,proxy,kubelet all get
flag. Using one variable to plumb through config via salt/init
scripts for GCE and GKE
2016-08-19 09:07:43 -07:00
Piotr Szczesniak
1f3fdab063
Salt configuration for Rescheduler
2016-08-18 12:24:09 +02:00
Wojciech Tyczynski
315d9f3689
Allow non-default etcd
2016-08-18 11:56:01 +02:00
Wojciech Tyczynski
679afea360
etcd3 support
2016-08-10 13:33:35 +02:00
Zach Loafman
963a05ec72
AWS/GCE: Rework use of master name
...
* Add a pillar for hostname (because even if there's a good Salt
function for it, I don't trust it to return the short hostname)
* Move INITIAL_ETCD_CLUSTER to just the GCE turn-up
* Remove the master_name, which isn't needed as a pillar
2016-08-04 08:46:36 -07:00