Erik Wilson
026584e1f7
Merge pull request #2103 from brandond/fix_2102
...
Fix removal of /run directories
4 years ago
Brad Davidson
0291bd770e
Fix removal of /run directories
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
Jacob Blain Christen
97ff5affab
Merge pull request #2065 from dweomer/containerd/v1.3.6-selinux
...
updated containerd/cri selinux support
4 years ago
Craig Jellick
4aaebd35f6
etcd mgmt is a work in progress
4 years ago
Craig Jellick
dbf59b46f2
Clarify K3s's positioning, goals, intentions, and components
4 years ago
Thorsten Klein
cf8c101b70
registry template: add insecure_skip_verify field
...
Signed-off-by: Thorsten Klein <iwilltry42@gmail.com>
4 years ago
Brad Davidson
9137c45cdb
Merge pull request #1614 from sen-subhabrata/master
...
install.sh: cleanup /run on uninstall
4 years ago
Brad Davidson
3f2551ec05
Merge pull request #1848 from euank/insecure-on-lo
...
Listen insecurely on localhost only
4 years ago
Brad Davidson
d11570fbdb
Merge pull request #2096 from AkihiroSuda/bump-up-rootlesskit
...
update rootlesskit to v0.10.0
4 years ago
Euan Kemp
4808c4e7d5
Listen insecurely on localhost only
...
Before this change, k3s configured the scheduler and controller's
insecure ports to listen on 0.0.0.0. Those ports include pprof, which
provides a DoS vector at the very least.
These ports are only enabled for componentstatus checks in the first
place, and componentstatus is hardcoded to only do the check on
localhost anyway (see
https://github.com/kubernetes/kubernetes/blob/v1.18.2/pkg/registry/core/rest/storage_core.go#L341-L344 ),
so there shouldn't be any downside to switching them to listen only on
localhost.
4 years ago
Akihiro Suda
a70cdac356
update rootlesskit to v0.10.0
...
Fix intermittent "Connection reset by peer" error during port forwarding
https://github.com/rootless-containers/rootlesskit/issues/153
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
4 years ago
Brad Davidson
c8282f4939
Merge pull request #2053 from brandond/update_dynamiclistener
...
Update dynamiclistener
4 years ago
Brad Davidson
3e8141dc65
Update dynamiclistener
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
Brian Downs
6fcec6aea9
Merge pull request #1754 from briandowns/add_pr_template
...
add pull request template
4 years ago
Hussein Galal
169ee63907
Add etcd members as learners ( #2066 )
...
* Add etcd members as learners
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com>
* Ignore errors in promote member
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com>
4 years ago
Brad Davidson
a33494802b
Merge pull request #2072 from brandond/setproctitle
...
Call setproctitle to conceal node args in ps output
4 years ago
Brad Davidson
1eec7348a5
Call setproctitle to conceal node args in ps output
...
This is related to #2014 .
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
Brad Davidson
375c68524b
Merge pull request #2073 from brandond/update_docker_baseimage
...
Update base image version in Dockerfiles
4 years ago
Brad Davidson
1b78715903
Update base image version in Dockerfiles
...
Should hopefully fix issues that cropped up with arm builds failing due
to the sqlite libs from alpine 3.10 no longer being compatible with
alpine edge, which was probably never a safe assumption to begin with.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
Brad Davidson
361e218fef
Merge pull request #2064 from brandond/write_kubeconfig_claim
...
Correctly report and propagate kubeconfig write failures
4 years ago
Jacob Blain Christen
371bee82f9
containerd: bump to v1.3.6
...
Remove $NOTIFY_SOCKET, if present, from env when invoking containerd to
prevent gratuitous notifications sent to systemd.
Signed-off-by: Jacob Blain Christen <jacob@rancher.com>
4 years ago
Brad Davidson
118d3256b5
Merge pull request #2056 from mcsaucy/http
...
Always validate K3S_URL if running agent.
4 years ago
Chris Kim
79931c73bc
Merge pull request #2063 from Oats87/bump-k3s-root-v060-rc3
...
Bump k3s-root to v0.6.0-rc3
4 years ago
Brad Davidson
dfd0f9d1a6
Correctly report and propagate kubeconfig write failures
...
As seen in issues such as #15 #155 #518 #570 there are situations where
k3s will fail to write the kubeconfig file, but reports that it wrote it
anyway as the success message is printed unconditionally. Also, secondary
actions like setting file mode and creating a symlink are also attempted
even if the file was not created.
This change skips attempting additional actions, and propagates the
failure back upwards.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
Chris Kim
b5e57a10d5
Bump k3s-root to v0.6.0-rc3 for https://github.com/rancher/k3s/issues/1812
...
Signed-off-by: Chris Kim <oats87g@gmail.com>
4 years ago
Josh McSavaney
265bd9848b
Always validate K3S_URL.
...
Also move K3S_URL validation to its own function.
Signed-off-by: Josh McSavaney <mcsaucy@csh.rit.edu>
4 years ago
Brad Davidson
4eb88a2fd3
Merge pull request #2042 from brandond/coredns_sync_1919-master
...
Update coredns version for master
4 years ago
Brad Davidson
77bfe47627
Merge pull request #2037 from brandond/update_k3s-root_slirp4netns
...
Update k3s-root to pull in updated slirp4netns
4 years ago
Brad Davidson
9da8dc4f61
Update coredns version to 1.6.9 for master
...
Needed for #1844
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
Brian Downs
04f57e5e1d
Merge pull request #2044 from briandowns/add_cis_server_flag
...
update cis flag implementation to propogate the rest of the way
4 years ago
Brian Downs
5a81fdbdc5
update cis flag implementation to propogate the rest of the way through to kubelet
...
Signed-off-by: Brian Downs <brian.downs@gmail.com>
4 years ago
Hussein Galal
6d59b81479
Fix cli in main.go ( #2043 )
4 years ago
Erik Wilson
1b62c2802b
Merge pull request #1983 from erikwilson/upgrade-flannel
...
Update flannel to v0.12.0-k3s1
4 years ago
Brad Davidson
1de58904ad
Update flannel to v0.12.0-k3s1
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
Brad Davidson
9e00f6dc73
Update k3s-root to pull in updated slirp4netns
...
Related to #1709
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
Jason
e3f8789114
Add containerd snapshotter flag ( #1991 )
...
* Add containerd snapshotter flag
Signed-off-by: Jason-ZW <zhenyang@rancher.com>
* Fix CamelCase nit and option description
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
Signed-off-by: Jason-ZW <zhenyang@rancher.com>
Co-authored-by: Brad Davidson <brad@oatmail.org>
4 years ago
Brad Davidson
206accbe8d
Update to v1.18.6-k3s1 ( #2035 )
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
4 years ago
David Nuzik
186c4a1c6b
Merge pull request #2022 from davidnuzik/mark-v1.18.6-stable
...
Set v1.18.6 as stable in channel server
4 years ago
Brian Downs
f7dae176e9
Merge pull request #2023 from briandowns/add_kubelet_cis_flag
...
add protect-kernel-defaults to kubelet
4 years ago
Brian Downs
abb2d9aad1
add flag usage
...
Signed-off-by: Brian Downs <brian.downs@gmail.com>
4 years ago
Brian Downs
57a6319fac
add protect-kernel-defaults to kubelet
...
Signed-off-by: Brian Downs <brian.downs@gmail.com>
4 years ago
David Nuzik
cecce93ee1
Set v1.18.6 as stable in channel server
...
Signed-off-by: David Nuzik <david.nuzik@rancher.com>
4 years ago
Erik Wilson
66a8c2ad7f
Merge pull request #1899 from erikwilson/config-file
...
Add config file support
4 years ago
Brad Davidson
5e01bd3558
Merge pull request #1957 from mcsaucy/http
...
Perform basic validation on K3S_URL in install.sh
4 years ago
Erik Wilson
466f093943
Stat build to show file size
4 years ago
Erik Wilson
d088adf9c4
Merge pull request #2012 from erikwilson/vagrant-update
...
Update Vagrant dev environment
4 years ago
Erik Wilson
176bfdbbb6
Update Vagrant dev environment
4 years ago
Brad Davidson
6b541e6676
Merge pull request #2009 from brandond/fix_1999
...
Update sonobuoy version for k8s 1.18 support
4 years ago
Brian Downs
6a21599f39
Merge pull request #2011 from briandowns/add_profile_flag_to_controller_manager
...
add profiling flag with default value of false
4 years ago
Brian Downs
ebac755da1
add profiling flag with default value of false
...
Signed-off-by: Brian Downs <brian.downs@gmail.com>
4 years ago