k3s/cluster
Kubernetes Submit Queue 96d81fe688
Merge pull request #52367 from tallclair/psp-config
Automatic merge from submit-queue (batch tested with PRs 52367, 53363, 54989, 54872, 54643). If you want to cherry-pick this change to another branch, please follow the instructions <a href="https://github.com/kubernetes/community/blob/master/contributors/devel/cherry-picks.md">here</a>.

Basic GCE PodSecurityPolicy Config

**What this PR does / why we need it**:

This PR lays the foundation for enabling PodSecurityPolicy in GCE and other default deployments. The 3 commits are:

1. Add policies, roles & bindings for the default addons on GCE.
2. Enable the PSP admission controller & load the addon policies when the`ENABLE_POD_SECURITY_POLICY=true` environment variable is set.
3. Support the PodSecurityPolicy in the E2E environment & add PSP tests.

NOTES:

- ~~Depends on https://github.com/kubernetes/kubernetes/pull/52301 for privileged capabilities~~
- ~~Depends on https://github.com/kubernetes/kubernetes/pull/52849 for sane mutations~~
- ~~Depends on https://github.com/kubernetes/kubernetes/pull/53479 for aggregator tests to pass~~
- ~~Depends on https://github.com/kubernetes/kubernetes/pull/54175 for dedicated fluentd service~~ account
- This PR is a fork of https://github.com/kubernetes/kubernetes/pull/46064, credit to @Q-Lee

**Which issue this PR fixes**: #43538

**Release note**:
```release-note
Add support for PodSecurityPolicy on GCE: `ENABLE_POD_SECURITY_POLICY=true` enables the admission controller, and installs policies for default addons.
```
2017-11-02 12:59:13 -07:00
..
addons Add GCP addon PodSecurityPolicies & Bindings 2017-11-01 14:03:05 -07:00
aws hack/cluster: consolidate cluster/ utils to hack/lib/util.sh 2017-03-30 22:34:46 -05:00
centos Merge pull request #54356 from zouyee/centos-1 2017-10-24 19:02:25 -07:00
gce Merge pull request #52367 from tallclair/psp-config 2017-11-02 12:59:13 -07:00
images Merge pull request #54250 from ixdy/debian-hyperkube-base-ssh 2017-10-27 14:38:23 -07:00
juju Changing the way we clear the certificate written flag to use a helper function in the tls layer. 2017-11-01 17:53:29 -04:00
kubemark Merge pull request #53974 from shyamjvs/auto-calculate-kubemark-disk 2017-10-16 07:35:32 -07:00
kubernetes-anywhere Fix log collection for kubeadm-gce tests 2017-10-26 07:57:42 -04:00
lib Remove kubectl's dependence on schema file in pkg/api/validation. 2017-08-16 16:38:28 -07:00
libvirt-coreos fix kubemark, juju, and libvirt-coreos README.md (from minion to node) 2017-10-10 06:45:15 +00:00
local
log-dump Fix log collection for kubeadm-gce tests 2017-10-26 07:57:42 -04:00
openstack-heat Providing kubeconfig file is now the switch for standalone mode 2017-07-24 11:03:00 -07:00
photon-controller fix typos: remove duplicated word in comments 2017-09-16 14:38:10 +08:00
pre-existing Launch kubemark with an existing Kubemark Master 2017-07-05 09:14:53 -04:00
saltbase Merge pull request #52367 from tallclair/psp-config 2017-11-02 12:59:13 -07:00
skeleton Conditionally run detect-project in log-dump 2017-09-21 13:41:30 +08:00
vagrant Remove all traces of federation 2017-10-26 13:37:37 -07:00
vsphere
windows
BUILD Merge pull request #53034 from tallclair/gce-addons 2017-10-31 09:12:55 -07:00
OWNERS
README.md Update docs/ URLs to point to proper locations 2017-06-05 22:13:54 -07:00
clientbin.sh Add some initial shell parsing tests. 2017-08-31 14:32:01 -07:00
common.sh GCP PodSecurityPolicy configuration 2017-11-01 14:03:09 -07:00
get-kube-binaries.sh Make get-kube.sh work properly the "ci/latest" pointer 2017-04-05 15:02:10 -07:00
get-kube-local.sh Providing kubeconfig file is now the switch for standalone mode 2017-07-24 11:03:00 -07:00
get-kube.sh remove rackspace related code 2017-09-22 18:06:50 +08:00
kube-down.sh
kube-push.sh
kube-up.sh add some more deprecation warnings to cluster 2017-07-19 09:43:05 -07:00
kube-util.sh Do not clobber KUBERNETES_PROVIDER - fix kubeadm/gce log collection 2017-10-30 17:33:08 -04:00
kubeadm.sh
kubectl.sh
options.md
restore-from-backup.sh Fix restore-from-backup.sh script 2017-03-21 11:58:13 +01:00
test-e2e.sh
test-network.sh
test-smoke.sh
update-storage-objects.sh Change RBAC storage version to v1 for 1.9 2017-09-25 10:02:21 -04:00
validate-cluster.sh Switch away from gcloud deprecated flags in compute resource listings 2017-08-30 06:41:09 +01:00

README.md

Cluster Configuration

Deprecation Notice: This directory has entered maintenance mode and will not be accepting new providers. Please submit new automation deployments to kube-deploy. Deployments in this directory will continue to be maintained and supported at their current level of support.

The scripts and data in this directory automate creation and configuration of a Kubernetes cluster, including networking, DNS, nodes, and master components.

See the getting-started guides for examples of how to use the scripts.

cloudprovider/config-default.sh contains a set of tweakable definitions/parameters for the cluster.

The heavy lifting of configuring the VMs is done by SaltStack.

Analytics