2016-08-25 17:16:14 +08:00
|
|
|
# This is where all the cert scripts and certs will be located
|
|
|
|
kube_cert_dir: "{{ kube_config_dir }}/ssl"
|
|
|
|
|
|
|
|
# This is where all of the bearer tokens will be stored
|
|
|
|
kube_token_dir: "{{ kube_config_dir }}/tokens"
|
|
|
|
|
|
|
|
# This is where to save basic auth file
|
|
|
|
kube_users_dir: "{{ kube_config_dir }}/users"
|
|
|
|
|
|
|
|
# An experimental dev/test only dynamic volumes provisioner,
|
|
|
|
# for PetSets. Works for kube>=v1.3 only.
|
|
|
|
kube_hostpath_dynamic_provisioner: "false"
|
2016-10-24 21:11:52 +08:00
|
|
|
|
|
|
|
# This is where you can drop yaml/json files and the kubelet will run those
|
|
|
|
# pods on startup
|
|
|
|
kube_manifest_dir: "{{ kube_config_dir }}/manifests"
|
|
|
|
|
|
|
|
# This directory is where all the additional config stuff goes
|
|
|
|
# the kubernetes normally puts in /srv/kubernets.
|
|
|
|
# This puts them in a sane location.
|
|
|
|
# Editting this value will almost surely break something. Don't
|
|
|
|
# change it. Things like the systemd scripts are hard coded to
|
|
|
|
# look in here. Don't do it.
|
|
|
|
kube_config_dir: /etc/kubernetes
|
|
|
|
|
|
|
|
# change to 0.0.0.0 to enable insecure access from anywhere (not recommended)
|
|
|
|
kube_apiserver_insecure_bind_address: 127.0.0.1
|
|
|
|
|
2016-11-18 20:56:55 +08:00
|
|
|
# A port range to reserve for services with NodePort visibility.
|
|
|
|
# Inclusive at both ends of the range.
|
|
|
|
kube_apiserver_node_port_range: "30000-32767"
|
|
|
|
|
2016-10-24 21:11:52 +08:00
|
|
|
# Logging directory (sysvinit systems)
|
|
|
|
kube_log_dir: "/var/log/kubernetes"
|
2016-11-09 18:44:41 +08:00
|
|
|
|
|
|
|
# ETCD cert dir for connecting apiserver to etcd
|
|
|
|
etcd_config_dir: /etc/ssl/etcd
|
|
|
|
etcd_cert_dir: "{{ etcd_config_dir }}/ssl"
|
|
|
|
|
|
|
|
|