mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-27 13:37:30 +00:00
Symbol links of key and cert are no longer used.
This commit is contained in:
parent
11fc906c2b
commit
d5d4b4007c
@ -66,10 +66,6 @@ function create-node-pki {
|
|||||||
KUBELET_KEY_PATH="${pki_dir}/kubelet.key"
|
KUBELET_KEY_PATH="${pki_dir}/kubelet.key"
|
||||||
echo "${KUBELET_KEY}" | base64 --decode > "${KUBELET_KEY_PATH}"
|
echo "${KUBELET_KEY}" | base64 --decode > "${KUBELET_KEY_PATH}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# TODO(mikedanese): remove this when we don't support downgrading to versions
|
|
||||||
# < 1.6.
|
|
||||||
ln -sf "${CA_CERT_BUNDLE_PATH}" /etc/kubernetes/ca.crt
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# A hookpoint for setting up local devices
|
# A hookpoint for setting up local devices
|
||||||
|
@ -244,10 +244,6 @@ function create-node-pki {
|
|||||||
KUBELET_KEY_PATH="${pki_dir}/kubelet.key"
|
KUBELET_KEY_PATH="${pki_dir}/kubelet.key"
|
||||||
write-pki-data "${KUBELET_KEY}" "${KUBELET_KEY_PATH}"
|
write-pki-data "${KUBELET_KEY}" "${KUBELET_KEY_PATH}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# TODO(mikedanese): remove this when we don't support downgrading to versions
|
|
||||||
# < 1.6.
|
|
||||||
ln -sf "${CA_CERT_BUNDLE_PATH}" /etc/srv/kubernetes/ca.crt
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function create-master-pki {
|
function create-master-pki {
|
||||||
@ -298,11 +294,6 @@ function create-master-pki {
|
|||||||
SERVICEACCOUNT_KEY_PATH="${pki_dir}/serviceaccount.key"
|
SERVICEACCOUNT_KEY_PATH="${pki_dir}/serviceaccount.key"
|
||||||
write-pki-data "${SERVICEACCOUNT_KEY}" "${SERVICEACCOUNT_KEY_PATH}"
|
write-pki-data "${SERVICEACCOUNT_KEY}" "${SERVICEACCOUNT_KEY_PATH}"
|
||||||
|
|
||||||
# TODO(mikedanese): remove this when we don't support downgrading to versions
|
|
||||||
# < 1.6.
|
|
||||||
ln -sf "${APISERVER_SERVER_KEY_PATH}" /etc/srv/kubernetes/server.key
|
|
||||||
ln -sf "${APISERVER_SERVER_CERT_PATH}" /etc/srv/kubernetes/server.cert
|
|
||||||
|
|
||||||
if [[ ! -z "${REQUESTHEADER_CA_CERT:-}" ]]; then
|
if [[ ! -z "${REQUESTHEADER_CA_CERT:-}" ]]; then
|
||||||
AGGREGATOR_CA_KEY_PATH="${pki_dir}/aggr_ca.key"
|
AGGREGATOR_CA_KEY_PATH="${pki_dir}/aggr_ca.key"
|
||||||
write-pki-data "${AGGREGATOR_CA_KEY}" "${AGGREGATOR_CA_KEY_PATH}"
|
write-pki-data "${AGGREGATOR_CA_KEY}" "${AGGREGATOR_CA_KEY_PATH}"
|
||||||
|
Loading…
Reference in New Issue
Block a user