fix(templates): add clause to filter for prime master only

!5
This commit is contained in:
2023-11-02 10:26:45 +09:30
parent 4465bcd2c4
commit 89b6573247
2 changed files with 5 additions and 1 deletions

View File

@ -69,6 +69,7 @@ k3s:
kind: Policy kind: Policy
rules: rules:
- level: Request - level: Request
when: "{{ kubernetes_config.cluster.prime.name == inventory_hostname }}"
- name: 90-kubelet.conf - name: 90-kubelet.conf
path: /etc/sysctl.d path: /etc/sysctl.d
@ -100,6 +101,7 @@ k3s:
# usernames: [] # usernames: []
# runtimeClasses: [] # runtimeClasses: []
# namespaces: [kube-system] # namespaces: [kube-system]
when: "{{ kubernetes_config.cluster.prime.name == inventory_hostname }}"

View File

@ -9,6 +9,7 @@
owner: root owner: root
group: root group: root
loop: "{{ k3s.files }}" loop: "{{ k3s.files }}"
when: item.when | default(false) | bool
- name: Copy Templates - name: Copy Templates
@ -20,13 +21,14 @@
force: true force: true
notify: "{{ item.notify | default(omit) }}" notify: "{{ item.notify | default(omit) }}"
loop: "{{ templates_to_apply }}" loop: "{{ templates_to_apply }}"
when: item.when | default(true) | bool
vars: vars:
templates_to_apply: templates_to_apply:
- src: kubernetes-manifest-rbac.yaml.j2 - src: kubernetes-manifest-rbac.yaml.j2
dest: /var/lib/rancher/k3s/server/manifests/rbac-authorization-common.yaml dest: /var/lib/rancher/k3s/server/manifests/rbac-authorization-common.yaml
when: "{{ kubernetes_config.cluster.prime.name == inventory_hostname }}"
- src: iptables-kubernetes.rules.j2 - src: iptables-kubernetes.rules.j2
dest: "/etc/iptables.rules.d/iptables-kubernetes.rules" dest: "/etc/iptables.rules.d/iptables-kubernetes.rules"
notify: firewall_reloader notify: firewall_reloader