2018-08-10 01:53:11 +08:00
|
|
|
---
|
2020-04-11 14:51:47 +08:00
|
|
|
|
2020-08-01 15:33:48 +08:00
|
|
|
crio_cgroup_manager: "{{ kubelet_cgroup_driver | default('systemd') }}"
|
2020-04-24 16:18:07 +08:00
|
|
|
crio_conmon: "/usr/bin/conmon"
|
2020-08-01 15:33:48 +08:00
|
|
|
crio_enable_metrics: false
|
|
|
|
crio_log_level: "info"
|
|
|
|
crio_metrics_port: "9090"
|
|
|
|
crio_pause_image: "{{ pod_infra_image_repo }}:{{ pod_infra_version }}"
|
2020-08-28 00:09:53 +08:00
|
|
|
|
|
|
|
# Trusted registries to pull unqualified images (e.g. alpine:latest) from
|
|
|
|
# By default unqualified images are not allowed for security reasons
|
|
|
|
crio_registries: []
|
|
|
|
|
2020-08-01 15:33:48 +08:00
|
|
|
crio_seccomp_profile: ""
|
|
|
|
crio_selinux: "{{ (preinstall_selinux_state == 'enforcing')|lower }}"
|
|
|
|
crio_signature_policy: "{% if ansible_os_family == 'ClearLinux' %}/usr/share/defaults/crio/policy.json{% endif %}"
|
2020-09-10 20:29:45 +08:00
|
|
|
|
|
|
|
# Override system default for storage driver
|
|
|
|
# crio_storage_driver: "overlay"
|
|
|
|
|
2020-08-01 15:33:48 +08:00
|
|
|
crio_stream_port: "10010"
|
2020-04-24 16:18:07 +08:00
|
|
|
|
|
|
|
crio_required_version: "{{ kube_version | regex_replace('^v(?P<major>\\d+).(?P<minor>\\d+).(?P<patch>\\d+)$', '\\g<major>.\\g<minor>') }}"
|
|
|
|
|
|
|
|
crio_kubernetes_version_matrix:
|
2020-10-13 17:08:26 +08:00
|
|
|
"1.19": "1.19"
|
2020-05-28 15:42:15 +08:00
|
|
|
"1.18": "1.18"
|
2020-04-24 16:18:07 +08:00
|
|
|
"1.17": "1.17"
|
|
|
|
|
2020-10-13 17:08:26 +08:00
|
|
|
crio_version: "{{ crio_kubernetes_version_matrix[crio_required_version] | default('1.19') }}"
|
2020-10-23 18:07:46 +08:00
|
|
|
|
|
|
|
# The crio_runtimes variable defines a list of OCI compatible runtimes.
|
|
|
|
crio_runtimes:
|
|
|
|
- name: runc
|
|
|
|
path: /usr/bin/runc
|
|
|
|
type: oci
|
|
|
|
root: /run/runc
|
|
|
|
|
|
|
|
# Kata Containers is an OCI runtime, where containers are run inside lightweight
|
|
|
|
# VMs. Kata provides additional isolation towards the host, minimizing the host attack
|
|
|
|
# surface and mitigating the consequences of containers breakout.
|
|
|
|
kata_runtimes:
|
|
|
|
# Kata Containers with the default configured VMM
|
|
|
|
- name: kata-runtime
|
|
|
|
path: /opt/kata/bin/kata-runtime
|
|
|
|
type: oci
|
|
|
|
root: /run/kata-containers
|
|
|
|
# Kata Containers with the QEMU VMM
|
|
|
|
- name: kata-qemu
|
|
|
|
path: /opt/kata/bin/kata-qemu
|
|
|
|
type: oci
|
|
|
|
root: /run/kata-containers
|