This commit is contained in:
parent
1e4d82d403
commit
7f36b6eae6
3 changed files with 39 additions and 20 deletions
|
|
@ -98,6 +98,25 @@
|
|||
with_items:
|
||||
- { name: var_lib_k3s, vg: vg_sys, size: 10g, mount_point: /var/lib/rancher/k3s, mount_opts: "discard"}
|
||||
|
||||
- name: Audit policies directory
|
||||
file:
|
||||
path: "/etc/kubernetes/policies"
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: 0700
|
||||
when:
|
||||
- kubernetes_master|bool
|
||||
|
||||
- name: Configure audit policy
|
||||
copy:
|
||||
src: "etc/kubernetes/policies/audit-policy.yaml"
|
||||
dest: "/etc/kubernetes/policies/audit-policy.yaml"
|
||||
group: root
|
||||
owner: root
|
||||
mode: 0644
|
||||
when:
|
||||
- kubernetes_master|bool
|
||||
|
||||
# Check controlers
|
||||
- name: Check if /etc/rancher/k3s/k3s.yaml already existe
|
||||
|
|
|
|||
|
|
@ -158,6 +158,26 @@
|
|||
state: started
|
||||
enabled: yes
|
||||
|
||||
- name: Audit policies directory
|
||||
file:
|
||||
path: "/etc/kubernetes/policies"
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: 0700
|
||||
when:
|
||||
- kubernetes_master|bool
|
||||
|
||||
- name: Configure audit policy
|
||||
copy:
|
||||
src: "etc/kubernetes/policies/audit-policy.yaml"
|
||||
dest: "/etc/kubernetes/policies/audit-policy.yaml"
|
||||
group: root
|
||||
owner: root
|
||||
mode: 0644
|
||||
when:
|
||||
- kubernetes_master|bool
|
||||
|
||||
# First controler
|
||||
- name: Check if /etc/kubernetes/admin.conf already existe
|
||||
stat:
|
||||
|
|
|
|||
|
|
@ -21,26 +21,6 @@
|
|||
- kubernetes_master|bool
|
||||
- groups['KubernetesMasters'] | length > 1
|
||||
|
||||
- name: Audit policies directory
|
||||
file:
|
||||
path: "/etc/kubernetes/policies"
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: 0700
|
||||
when:
|
||||
- kubernetes_master|bool
|
||||
|
||||
- name: Configure audit policy
|
||||
copy:
|
||||
src: "etc/kubernetes/policies/audit-policy.yaml"
|
||||
dest: "/etc/kubernetes/policies/audit-policy.yaml"
|
||||
group: root
|
||||
owner: root
|
||||
mode: 0644
|
||||
when:
|
||||
- kubernetes_master|bool
|
||||
|
||||
- name: Kubernetes cluster with kubeadm
|
||||
include_tasks: "cluster_kubeadm.yml"
|
||||
when:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue