kubespray/roles/kubernetes/control-plane/tasks
Nicolas Goudry c6fcbf6ee0
Remove access to cluster from anonymous users (#11016)
* feat: add user facing variable with default

* feat: remove rolebinding to anonymous users after init and upgrade

* feat: use file discovery for secondary control plane nodes

* feat: use file discovery for nodes

* fix: do not fail if rolebinding does not exist

* docs: add warning about kube_api_anonymous_auth

* style: improve readability of delegate_to parameter

* refactor: rename discovery kubeconfig file

* test: enable new variable in hardening and upgrade test cases

* docs: add option to config parameters

* test: multiple instances and upgrade
2024-04-02 23:54:12 -07:00
..
define-first-kube-control.yml Fix typo mistake in roles/kubernetes/control-plane/tasks/define-first-kube-control.yml 2024-01-24 13:39:39 +01:00
encrypt-at-rest.yml Fix: kube-apiserver tag will overwrite secrets-at-rest token if used independently (#10460) 2023-09-21 06:55:29 -07:00
kubeadm-backup.yml Move to Ansible 3.4.0 (#7672) 2021-07-12 00:00:47 -07:00
kubeadm-etcd.yml Install etcdutl file by default (#10385) 2023-08-23 07:04:22 -07:00
kubeadm-fix-apiserver.yml Revert "Update etcd-servers for apiserver (#8253)" (#10652) 2023-12-12 11:22:38 +01:00
kubeadm-secondary.yml Remove access to cluster from anonymous users (#11016) 2024-04-02 23:54:12 -07:00
kubeadm-setup.yml Remove access to cluster from anonymous users (#11016) 2024-04-02 23:54:12 -07:00
kubeadm-upgrade.yml Remove access to cluster from anonymous users (#11016) 2024-04-02 23:54:12 -07:00
kubelet-fix-client-cert-rotation.yml Fixup kubelet.conf to point to kubelet-client-current.pem (#7347) 2021-03-08 23:55:00 -08:00
main.yml Remove PodSecurityPolicy support and references (#10723) 2023-12-18 14:13:43 +01:00
pre-upgrade.yml project: fix var-spacing ansible rule (#10266) 2023-07-04 20:36:54 -07:00