Skip to content

Commit 893e9cb

Browse files
authored
Merge pull request kubernetes-sigs#11471 from VannTen/feat/config_plugin_list
Update the list of admission plugins which needs config
2 parents 76c42b4 + 5b057c7 commit 893e9cb

File tree

2 files changed

+6
-10
lines changed

2 files changed

+6
-10
lines changed

roles/kubernetes/control-plane/tasks/kubeadm-setup.yml

-9
Original file line numberDiff line numberDiff line change
@@ -122,15 +122,6 @@
122122
- item in kube_apiserver_admission_plugins_needs_configuration
123123
loop: "{{ kube_apiserver_enable_admission_plugins }}"
124124

125-
- name: Kubeadm | Configure default cluster podnodeslector
126-
template:
127-
src: "podnodeselector.yaml.j2"
128-
dest: "{{ kube_config_dir }}/admission-controls/podnodeselector.yaml"
129-
mode: "0640"
130-
when:
131-
- kube_apiserver_admission_plugins_podnodeselector_default_node_selector is defined
132-
- kube_apiserver_admission_plugins_podnodeselector_default_node_selector | length > 0
133-
134125
- name: Kubeadm | Check apiserver.crt SANs
135126
vars:
136127
apiserver_ips: "{{ apiserver_sans | map('ansible.utils.ipaddr') | reject('equalto', False) | list }}"
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
11
---
22
# list of admission plugins that needs to be configured
3-
kube_apiserver_admission_plugins_needs_configuration: [EventRateLimit, PodSecurity]
3+
# https://kubernetes.io/docs/reference/access-authn-authz/admission-controllers/
4+
kube_apiserver_admission_plugins_needs_configuration:
5+
- EventRateLimit
6+
- ImagePolicyWebhook
7+
- PodSecurity
8+
- PodNodeSelector

0 commit comments

Comments
 (0)