@ -69,6 +69,7 @@ k3s:
|
|||||||
kind: Policy
|
kind: Policy
|
||||||
rules:
|
rules:
|
||||||
- level: Request
|
- level: Request
|
||||||
|
when: "{{ kubernetes_config.cluster.prime.name == inventory_hostname }}"
|
||||||
|
|
||||||
- name: 90-kubelet.conf
|
- name: 90-kubelet.conf
|
||||||
path: /etc/sysctl.d
|
path: /etc/sysctl.d
|
||||||
@ -100,6 +101,7 @@ k3s:
|
|||||||
# usernames: []
|
# usernames: []
|
||||||
# runtimeClasses: []
|
# runtimeClasses: []
|
||||||
# namespaces: [kube-system]
|
# namespaces: [kube-system]
|
||||||
|
when: "{{ kubernetes_config.cluster.prime.name == inventory_hostname }}"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@ -9,6 +9,7 @@
|
|||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
loop: "{{ k3s.files }}"
|
loop: "{{ k3s.files }}"
|
||||||
|
when: item.when | default(false) | bool
|
||||||
|
|
||||||
|
|
||||||
- name: Copy Templates
|
- name: Copy Templates
|
||||||
@ -20,13 +21,14 @@
|
|||||||
force: true
|
force: true
|
||||||
notify: "{{ item.notify | default(omit) }}"
|
notify: "{{ item.notify | default(omit) }}"
|
||||||
loop: "{{ templates_to_apply }}"
|
loop: "{{ templates_to_apply }}"
|
||||||
|
when: item.when | default(true) | bool
|
||||||
vars:
|
vars:
|
||||||
templates_to_apply:
|
templates_to_apply:
|
||||||
|
|
||||||
- src: kubernetes-manifest-rbac.yaml.j2
|
- src: kubernetes-manifest-rbac.yaml.j2
|
||||||
dest: /var/lib/rancher/k3s/server/manifests/rbac-authorization-common.yaml
|
dest: /var/lib/rancher/k3s/server/manifests/rbac-authorization-common.yaml
|
||||||
|
when: "{{ kubernetes_config.cluster.prime.name == inventory_hostname }}"
|
||||||
|
|
||||||
- src: iptables-kubernetes.rules.j2
|
- src: iptables-kubernetes.rules.j2
|
||||||
dest: "/etc/iptables.rules.d/iptables-kubernetes.rules"
|
dest: "/etc/iptables.rules.d/iptables-kubernetes.rules"
|
||||||
notify: firewall_reloader
|
notify: firewall_reloader
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user