This commit is contained in:
parent
1e4d82d403
commit
7f36b6eae6
3 changed files with 39 additions and 20 deletions
|
|
@ -98,6 +98,25 @@
|
||||||
with_items:
|
with_items:
|
||||||
- { name: var_lib_k3s, vg: vg_sys, size: 10g, mount_point: /var/lib/rancher/k3s, mount_opts: "discard"}
|
- { name: var_lib_k3s, vg: vg_sys, size: 10g, mount_point: /var/lib/rancher/k3s, mount_opts: "discard"}
|
||||||
|
|
||||||
|
- name: Audit policies directory
|
||||||
|
file:
|
||||||
|
path: "/etc/kubernetes/policies"
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: 0700
|
||||||
|
when:
|
||||||
|
- kubernetes_master|bool
|
||||||
|
|
||||||
|
- name: Configure audit policy
|
||||||
|
copy:
|
||||||
|
src: "etc/kubernetes/policies/audit-policy.yaml"
|
||||||
|
dest: "/etc/kubernetes/policies/audit-policy.yaml"
|
||||||
|
group: root
|
||||||
|
owner: root
|
||||||
|
mode: 0644
|
||||||
|
when:
|
||||||
|
- kubernetes_master|bool
|
||||||
|
|
||||||
# Check controlers
|
# Check controlers
|
||||||
- name: Check if /etc/rancher/k3s/k3s.yaml already existe
|
- name: Check if /etc/rancher/k3s/k3s.yaml already existe
|
||||||
|
|
|
||||||
|
|
@ -158,6 +158,26 @@
|
||||||
state: started
|
state: started
|
||||||
enabled: yes
|
enabled: yes
|
||||||
|
|
||||||
|
- name: Audit policies directory
|
||||||
|
file:
|
||||||
|
path: "/etc/kubernetes/policies"
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: 0700
|
||||||
|
when:
|
||||||
|
- kubernetes_master|bool
|
||||||
|
|
||||||
|
- name: Configure audit policy
|
||||||
|
copy:
|
||||||
|
src: "etc/kubernetes/policies/audit-policy.yaml"
|
||||||
|
dest: "/etc/kubernetes/policies/audit-policy.yaml"
|
||||||
|
group: root
|
||||||
|
owner: root
|
||||||
|
mode: 0644
|
||||||
|
when:
|
||||||
|
- kubernetes_master|bool
|
||||||
|
|
||||||
# First controler
|
# First controler
|
||||||
- name: Check if /etc/kubernetes/admin.conf already existe
|
- name: Check if /etc/kubernetes/admin.conf already existe
|
||||||
stat:
|
stat:
|
||||||
|
|
|
||||||
|
|
@ -21,26 +21,6 @@
|
||||||
- kubernetes_master|bool
|
- kubernetes_master|bool
|
||||||
- groups['KubernetesMasters'] | length > 1
|
- groups['KubernetesMasters'] | length > 1
|
||||||
|
|
||||||
- name: Audit policies directory
|
|
||||||
file:
|
|
||||||
path: "/etc/kubernetes/policies"
|
|
||||||
state: directory
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0700
|
|
||||||
when:
|
|
||||||
- kubernetes_master|bool
|
|
||||||
|
|
||||||
- name: Configure audit policy
|
|
||||||
copy:
|
|
||||||
src: "etc/kubernetes/policies/audit-policy.yaml"
|
|
||||||
dest: "/etc/kubernetes/policies/audit-policy.yaml"
|
|
||||||
group: root
|
|
||||||
owner: root
|
|
||||||
mode: 0644
|
|
||||||
when:
|
|
||||||
- kubernetes_master|bool
|
|
||||||
|
|
||||||
- name: Kubernetes cluster with kubeadm
|
- name: Kubernetes cluster with kubeadm
|
||||||
include_tasks: "cluster_kubeadm.yml"
|
include_tasks: "cluster_kubeadm.yml"
|
||||||
when:
|
when:
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue