ResourceQuota should be last admission controller

This commit is contained in:
derekwaynecarr
2016-04-04 14:47:44 -04:00
parent 6ff05bb9e1
commit e3d58499db
7 changed files with 13 additions and 6 deletions

View File

@@ -41,7 +41,8 @@ export SERVICE_CLUSTER_IP_RANGE=${SERVICE_CLUSTER_IP_RANGE:-"192.168.3.0/24"}
export FLANNEL_NET=${FLANNEL_NET:-"172.16.0.0/16"}
# Admission Controllers to invoke prior to persisting objects in cluster
export ADMISSION_CONTROL=NamespaceLifecycle,NamespaceExists,LimitRanger,ServiceAccount,ResourceQuota,SecurityContextDeny
# If we included ResourceQuota, we should keep it at the end of the list to prevent incremeting quota usage prematurely.
export ADMISSION_CONTROL=NamespaceLifecycle,NamespaceExists,LimitRanger,ServiceAccount,SecurityContextDeny,ResourceQuota
# Extra options to set on the Docker command line.
# This is useful for setting --insecure-registry for local registries.