Add more security to k3s installation
This commit is contained in:
parent
3c077f7baf
commit
b45abf84be
1 changed files with 14 additions and 0 deletions
|
|
@ -108,6 +108,20 @@
|
||||||
with_items:
|
with_items:
|
||||||
- { name: var_lib_k3s, vg: vg_sys, size: 10g, mount_point: /var/lib/rancher/k3s, mount_opts: "discard"}
|
- { name: var_lib_k3s, vg: vg_sys, size: 10g, mount_point: /var/lib/rancher/k3s, mount_opts: "discard"}
|
||||||
|
|
||||||
|
- name: Ensure protect-kernel-defaults is set
|
||||||
|
ansible.posix.sysctl:
|
||||||
|
name: "{{ item.name }}"
|
||||||
|
value: "{{ item.value }}"
|
||||||
|
sysctl_file: /etc/sysctl.d/90-kubelet.conf
|
||||||
|
reload: true
|
||||||
|
with_items:
|
||||||
|
- { name: "vm.panic_on_oom", value: "0" }
|
||||||
|
- { name: "vm.overcommit_memory", value: "1" }
|
||||||
|
- { name: "kernel.panic", value: "10" }
|
||||||
|
- { name: "kernel.panic_on_oops", value: "1" }
|
||||||
|
when:
|
||||||
|
- kubernetes_server|bool
|
||||||
|
|
||||||
- name: Audit policies directory
|
- name: Audit policies directory
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "/etc/kubernetes/policies"
|
path: "/etc/kubernetes/policies"
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue