Skip to content

Commit

Permalink
Merge pull request kubernetes-sigs#1585 from mattymo/canal_upgrade
Browse files Browse the repository at this point in the history
Fix upgrade for canal and apiserver cert
  • Loading branch information
bradbeam authored Aug 29, 2017
2 parents 80a7ae9 + 13d08af commit 72a0d78
Show file tree
Hide file tree
Showing 3 changed files with 11 additions and 15 deletions.
12 changes: 0 additions & 12 deletions roles/kubernetes-apps/network_plugin/canal/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,18 +8,6 @@
resource: "configmap"
namespace: "{{system_namespace}}"

# FIXME: remove if kubernetes/features#124 is implemented
- name: Purge old flannel and canal-node
run_once: true
kube:
name: "canal-node"
kubectl: "{{ bin_dir }}/kubectl"
filename: "{{ kube_config_dir }}/canal-node.yaml"
resource: "ds"
namespace: "{{system_namespace}}"
state: absent
when: inventory_hostname == groups['kube-master'][0] and canal_node_manifest.changed

- name: Start flannel and calico-node
run_once: true
kube:
Expand Down
9 changes: 6 additions & 3 deletions roles/kubernetes/secrets/files/make-ssl.sh
Original file line number Diff line number Diff line change
Expand Up @@ -82,10 +82,13 @@ gen_key_and_cert() {

# Admins
if [ -n "$MASTERS" ]; then
# If any host requires new certs, just regenerate all master certs
# kube-apiserver
gen_key_and_cert "apiserver" "/CN=kube-apiserver"
cat ca.pem >> apiserver.pem
# Generate only if we don't have existing ca and apiserver certs
if ! [ -e "$SSLDIR/ca-key.pem" ] || ! [ -e "$SSLDIR/apiserver-key.pem" ]; then
gen_key_and_cert "apiserver" "/CN=kube-apiserver"
cat ca.pem >> apiserver.pem
fi
# If any host requires new certs, just regenerate scheduler and controller-manager master certs
# kube-scheduler
gen_key_and_cert "kube-scheduler" "/CN=system:kube-scheduler"
# kube-controller-manager
Expand Down
5 changes: 5 additions & 0 deletions roles/network_plugin/canal/templates/canal-node.yml.j2
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ kind: DaemonSet
apiVersion: extensions/v1beta1
metadata:
name: canal-node
namespace: {{ system_namespace }}
labels:
k8s-app: canal-node
spec:
Expand Down Expand Up @@ -180,3 +181,7 @@ spec:
- name: "canal-certs"
mountPath: "{{ canal_cert_dir }}"
readOnly: true
updateStrategy:
rollingUpdate:
maxUnavailable: 1
type: RollingUpdate

0 comments on commit 72a0d78

Please sign in to comment.