Mathieu Parent
09f3caedaa
[download] Don't fail on 304 Not Modified ( #10452 )
...
i.e when file was not modified since last download
2023-09-21 00:20:20 -07:00
Mohamed Omar Zaian
fe4b1f6dee
[ingress-nginx] upgrade to 1.8.2 ( #10455 )
2023-09-20 19:17:56 -07:00
Mohamed Omar Zaian
bc5e33791f
[vsphere_csi] Update to 3.1.0 ( #10451 )
2023-09-20 04:56:00 -07:00
Romain
a81c6d5448
Add a way to configure reseted networking service name. ( #10428 )
2023-09-20 02:28:01 -07:00
Mohamed Omar Zaian
6b34e3ef08
[calico] Make version 3.26.1 default ( #10416 )
...
* [calico] Make version 3.26.1 default
* [calico] Separate calico-node and calico-cni-plugin service accounts
See: https://github.com/projectcalico/calico/pull/7106
2023-09-19 02:49:06 -07:00
Mohamed Omar Zaian
dbdc4d4123
[kubernetes] Add hashes for kubernetes 1.28.2, 1.27.6, 1.26.9 ( #10435 )
2023-09-18 05:40:32 -07:00
Mohamed Omar Zaian
c24c279df7
[containerd] add hashes for version 1.7.6, 1.6.24 ( #10439 )
2023-09-18 05:28:31 -07:00
Qasim Mehmood
0f243d751f
Use correct env var name for kube-vip per service leader election ( #10433 )
2023-09-14 02:22:17 -07:00
Toon Albers
31f6d38cd2
[cilium] fix: invalid hubble yaml if cilium_hubble_tls_generate is enabled ( #10430 )
2023-09-13 04:16:15 -07:00
Takuya Murakami
748b0b294d
[kubernetes] support 1.28.0 / 1.28.1 ( #10376 ) ( #10390 )
...
* [kubernetes] support 1.28.0/1.28.1 (#10376 )
* [kubernetes] Make 1.28.1 default (#10376 )
2023-09-11 19:42:12 -07:00
NierYYDS
af8210dfea
fix: add kubelet tag in task of fetch facts to avoid kubelet config inconsistencies ( #10423 )
...
when people run playbook with option `--tags=kubelet`, the kubelet config may changed, because some variables used in task populating `kubelet-config.yml` could be different with running task(`Fetch facts`)
2023-09-11 05:12:11 -07:00
Florian Ruynat
493969588e
Use cluster_name variable instead of hardcoded value in cinder-csi controller plugin ( #10422 )
2023-09-08 07:18:16 -07:00
Kay Yan
5ffdb7355a
cleanup-for-2.23.0 ( #10420 )
2023-09-08 04:40:13 -07:00
Kay Yan
c33e4d7bb7
fix-resolv.conf-nameserver-inline-comments ( #10415 )
2023-09-07 05:34:59 -07:00
Mohamed Omar Zaian
24b82917d1
[calico] add v3.25.2 and make it default ( #10414 )
2023-09-06 19:50:56 -07:00
Florian Ruynat
9696936b59
Fixup recover control plane playbook + add debian12/cilium test ( #10411 )
...
* Add debian12 cilium testing
* Fixup recover control plane playbook
2023-09-05 10:42:52 -07:00
NierYYDS
8fef156e8f
fix: specify owner to kube_owner in task of copy cni plugins ( #10407 )
...
if not set owner to kube_owner in unarchive module, the owner of /opt/cni/bin will changed to root, which is inconsistent with the previous task.
2023-09-04 02:29:49 -07:00
Kay Yan
8497528240
update-load-balancers-versions ( #10409 )
2023-09-03 23:57:49 -07:00
蔣 航
ebd71f6ad7
Fix Typo kubelet_topology_manager_policy ( #10384 )
...
Signed-off-by: hang.jiang <hang.jiang@daocloud.io >
2023-09-03 23:39:48 -07:00
Mohamed Omar Zaian
d646053c0e
[feat] Update metrics server to v0.6.4 ( #10400 )
2023-08-30 00:44:47 -07:00
Mohamed Omar Zaian
e84c1004df
[containerd] add hashes for 1.7.4-5 ( #10397 )
2023-08-28 19:29:20 -07:00
Daniel Strufe
e573a2f6d4
Add huawei cloud controller ( #10198 )
...
* Add huaweicloud as external cloud controller
* Add huaweicloud example config
* Rename AK,SK to ACCESS_KEY and SECRET_KEY
* Add reference to huaweicloud
* Fix variable naming
* Fix env var name
* Update example
* Fix variable naming
* Fix cloud_config path
* Add namespace for leader election
* Revert reviewers
* Delete OWNERS
Delete owners who are not responsible here.
* Fix build validation
2023-08-24 18:55:17 -07:00
Mohamed Omar Zaian
52c1826423
[kubernetes] Make 1.27.5 default ( #10392 )
...
* Add hashes for 1.27.5 1.26.8, 1.25.13
* Address CVE-2023-3955 , CVE-2023-3676
* Make kubernetes v1.27.5 default
2023-08-24 18:51:17 -07:00
Samuel Liu
e1881fae02
Install etcdutl file by default ( #10385 )
2023-08-23 07:04:22 -07:00
Victor Morales
5ed85094c2
Update checksum values ( #10369 )
...
The following binaries has been updated:
* crio
* krew
* runc
* crun
* gvisor
* nerdctl
* skopeo
* yq
Signed-off-by: Victor Morales <chipahuac@hotmail.com >
2023-08-18 09:46:29 -07:00
tenni
bf29ea55cf
fix: flatcar bootstrap ( #10363 )
2023-08-18 08:14:29 -07:00
Louis Tu
cafe4f1352
Add kubelet topology manager policy on the node ( #10370 )
...
Signed-off-by: tu1h <lihai.tu@daocloud.io >
2023-08-18 01:26:28 -07:00
Florian Ruynat
a8c1bccdd5
Move runroot from crio.conf to storage.conf ( #10372 )
2023-08-17 10:17:22 -07:00
Mohamed Omar Zaian
71cf553aa8
[containerd] add hashes for 1.7.3 , 1.6.22 , 1.6.23 ( #10368 )
2023-08-17 05:05:24 -07:00
Mohamed Omar Zaian
a894a5e29b
[argocd] update argocd to v2.8.0 ( #10364 )
2023-08-16 21:38:20 -07:00
Mohamed Omar Zaian
9bc7492ff2
[kubernetes] Make 1.27.4 default ( #10359 )
2023-08-16 21:12:19 -07:00
yun
77bda0df1c
Fix containerd config_path mirrors and remove nerdctl insecure_registry ( #10196 )
...
* Fix containerd_registries in config_path for mirrors and remove nerdctl global insecure_registry setting
* Make containerd hosts.toml mode 0640
* Add containerd_registries_mirrors and keep containerd_registries to pass packet_debian11-calico-upgrade
2023-08-16 05:18:27 -07:00
cortex3
4c37399c75
fix hcloud-cloud-controller-manager not working in certain setups ( #10297 )
2023-08-16 05:14:27 -07:00
Mohamed Omar Zaian
cd69283184
[helm] upgrade to 3.12.3 ( #10365 )
2023-08-16 05:10:29 -07:00
R. P. Taylor
cf3b3ca6fd
clean up /etc/hosts file if populate_inventory_to_hosts_file is false ( #10144 )
...
* de-populate hosts file if populate_inventory_to_hosts_file is false
keep newline
* fix when condition
2023-08-15 20:22:28 -07:00
charlychiu
3b68d63643
fix: not mount tls when disable ( #10357 )
2023-08-11 09:01:27 -07:00
Arthur Outhenin-Chalandre
d21bfb84ad
project: resolve ansible-lint key-order rule ( #10314 )
...
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
2023-08-10 00:57:27 -07:00
Nicolas Goudry
2a7c9d27b2
fix(multus): loop_control template error when item is None ( #10347 )
2023-08-09 20:51:26 -07:00
Francisco Orselli
7295d13d60
[EOS-11830] Use ETCD port 2381 for metrics ( #10332 )
2023-08-08 11:06:16 -07:00
ERIK
2fbbb70baa
Fix youki binary download url ( #10337 )
...
Signed-off-by: bo.jiang <bo.jiang@daocloud.io >
2023-08-08 06:12:15 -07:00
Nico
b5ce69cf3c
Set owner/group to root/root when unarchiving kata-containers ( #10338 )
...
Set owner/group to root/root when unarchiving kata-containers binary to prevent kata-containers binaries/directories and especially / from getting chowned to 1001:123, the file owner specified in the kata-containers archive
2023-08-08 05:06:15 -07:00
Arthur Outhenin-Chalandre
9613ed8782
Use supported version of fedora in CI ( #10108 )
...
* tests: replace fedora35 with fedora37
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* tests: replace fedora36 with fedora38
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* docs: update fedora version in docs
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* molecule: upgrade fedora version
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* tests: upgrade fedora images for vagrant and kubevirt
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* vagrant: workaround to fix private network ip address in fedora
Fedora stop supporting syconfig network script so we added a workaround
here
https://github.com/hashicorp/vagrant/issues/12762#issuecomment-1535957837
to fix it.
* netowrkmanager: do not configure dns if using systemd-resolved
We should not configure dns if we point to systemd-resolved.
Systemd-resolved is using NetworkManager to infer the upstream DNS
server so if we set NetworkManager to 127.0.0.53 it will prevent
systemd-resolved to get the correct network DNS server.
Thus if we are in this case we just don't set this setting.
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* image-builder: update centos7 image
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* gitlab-ci: mark fedora packet jobs as allow failure
Fedora networking is still broken on Packet, let's mark it as allow
failure for now.
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
---------
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
2023-08-08 00:50:12 -07:00
Arthur Outhenin-Chalandre
36e5d742dc
Resolve ansible-lint name errors ( #10253 )
...
* project: fix ansible-lint name
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* project: ignore jinja template error in names
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* project: capitalize ansible name
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
* project: update notify after name capitalization
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
---------
Signed-off-by: Arthur Outhenin-Chalandre <arthur.outhenin-chalandre@proton.ch >
2023-07-26 07:36:22 -07:00
Kay Yan
b9e3861385
add-cpuManagerPolicy ( #10309 )
2023-07-25 13:12:20 -07:00
satandyh
050bd0527f
enchance security with CIS Kubernetes V1.23 ( #10304 )
...
Benchmark item number 4.1.9
2023-07-23 19:24:11 -07:00
Mohamed Omar Zaian
fe32de94b9
[kubernetes] Add hashes for kubernetes 1.27.4, 1.26.7, 1.25.12 ( #10300 )
2023-07-23 19:20:10 -07:00
Louis Tu
d2383d27a9
Bump versions ( #10295 )
...
The following applications have been upgraded:
* helm
* skopeo
* yq
Signed-off-by: tu1h <lihai.tu@daocloud.io >
2023-07-19 00:26:03 -07:00
yangsenzk
13aa32278a
bugfix: fix grep command without -w option causing prefix matched while adding one etcd member ( #10291 )
2023-07-13 21:43:29 -07:00
Mohamed Omar Zaian
38ce02c610
[ingress-nginx] upgrade to 1.8.1 ( #10281 )
2023-07-10 21:05:12 -07:00
yun
1d86919883
Clean up calicoctl_alternate_download_url ( #10271 )
2023-07-05 08:16:57 -07:00