Merge "Fix api-cert-manager=true blocking cluster creation" into stable/train
This commit is contained in:
commit
4e3415e0b3
|
@ -10,7 +10,7 @@ if [ "$(echo $CERT_MANAGER_API | tr '[:upper:]' '[:lower:]')" != "false" ]; then
|
|||
|
||||
echo -e "$CA_KEY" > ${cert_dir}/ca.key
|
||||
|
||||
chown kube.kube ${cert_dir}/ca.key
|
||||
# chown kube:kube ${cert_dir}/ca.key
|
||||
chmod 400 ${cert_dir}/ca.key
|
||||
fi
|
||||
|
||||
|
|
|
@ -1147,10 +1147,6 @@ resources:
|
|||
list_join:
|
||||
- "\n"
|
||||
-
|
||||
- str_replace:
|
||||
template: {get_file: ../../common/templates/kubernetes/fragments/enable-cert-api-manager.sh}
|
||||
params:
|
||||
"$CA_KEY": {get_param: ca_key}
|
||||
- get_file: ../../common/templates/kubernetes/fragments/kube-apiserver-to-kubelet-role.sh
|
||||
- get_file: ../../common/templates/kubernetes/fragments/core-dns-service.sh
|
||||
- get_file: ../../common/templates/kubernetes/fragments/calico-service.sh
|
||||
|
|
|
@ -745,6 +745,10 @@ resources:
|
|||
"$NODEGROUP_NAME": {get_param: nodegroup_name}
|
||||
"$USE_PODMAN": {get_param: use_podman}
|
||||
- get_file: ../../common/templates/kubernetes/fragments/make-cert.sh
|
||||
- str_replace:
|
||||
template: {get_file: ../../common/templates/kubernetes/fragments/enable-cert-api-manager.sh}
|
||||
params:
|
||||
"$CA_KEY": {get_param: ca_key}
|
||||
- get_file: ../../common/templates/kubernetes/fragments/configure-etcd.sh
|
||||
- get_file: ../../common/templates/kubernetes/fragments/write-kube-os-config.sh
|
||||
- get_file: ../../common/templates/kubernetes/fragments/configure-kubernetes-master.sh
|
||||
|
|
|
@ -1151,10 +1151,6 @@ resources:
|
|||
list_join:
|
||||
- "\n"
|
||||
-
|
||||
- str_replace:
|
||||
template: {get_file: ../../common/templates/kubernetes/fragments/enable-cert-api-manager.sh}
|
||||
params:
|
||||
"$CA_KEY": {get_param: ca_key}
|
||||
- get_file: ../../common/templates/kubernetes/fragments/kube-apiserver-to-kubelet-role.sh
|
||||
- get_file: ../../common/templates/kubernetes/fragments/core-dns-service.sh
|
||||
- get_file: ../../common/templates/kubernetes/fragments/calico-service.sh
|
||||
|
|
|
@ -758,6 +758,10 @@ resources:
|
|||
"$USE_PODMAN": {get_param: use_podman}
|
||||
"$KUBE_IMAGE_DIGEST": {get_param: kube_image_digest}
|
||||
- get_file: ../../common/templates/kubernetes/fragments/make-cert.sh
|
||||
- str_replace:
|
||||
template: {get_file: ../../common/templates/kubernetes/fragments/enable-cert-api-manager.sh}
|
||||
params:
|
||||
"$CA_KEY": {get_param: ca_key}
|
||||
- get_file: ../../common/templates/kubernetes/fragments/configure-etcd.sh
|
||||
- get_file: ../../common/templates/kubernetes/fragments/write-kube-os-config.sh
|
||||
- get_file: ../../common/templates/kubernetes/fragments/configure-kubernetes-master.sh
|
||||
|
|
|
@ -0,0 +1,5 @@
|
|||
---
|
||||
fixes:
|
||||
- |
|
||||
Fixed the usage of cert_manager_api=true making cluster creation fail
|
||||
due to a logic lock between kubemaster.yaml and kubecluster.yaml
|
Loading…
Reference in New Issue