From 16d6ba8a9db941b88ca4e3098a7772f49b326730 Mon Sep 17 00:00:00 2001 From: Justin Santa Barbara Date: Fri, 12 Jun 2015 11:46:03 -0400 Subject: [PATCH] AWS: Stop the master kubelet from registering as a node (like GCE does) --- cluster/saltbase/salt/kubelet/default | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/cluster/saltbase/salt/kubelet/default b/cluster/saltbase/salt/kubelet/default index 9a914ef198e..76eb4497b4d 100644 --- a/cluster/saltbase/salt/kubelet/default +++ b/cluster/saltbase/salt/kubelet/default @@ -22,13 +22,13 @@ {% set api_servers_with_port = api_servers + ":6443" -%} {% endif -%} -# Disable registration for the kubelet running on the master on GCE. Also disable +# Disable registration for the kubelet running on the master on AWS, GCE, Vagrant. Also disable # the debugging handlers (/run and /exec) to prevent arbitrary code execution on # the master. # TODO(roberthbailey): Make this configurable via an env var in config-default.sh {% set debugging_handlers = "--enable-debugging-handlers=true" -%} -{% if grains.cloud in ['gce', 'vagrant'] -%} +{% if grains.cloud in ['aws', 'gce', 'vagrant'] -%} {% if grains['roles'][0] == 'kubernetes-master' -%} {% set api_servers_with_port = "" -%} {% set debugging_handlers = "--enable-debugging-handlers=false" -%}