mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-23 11:50:44 +00:00
cloud-controller-manager: enable secure ports 10258, deprecate insecure port
This commit is contained in:
parent
2548fb08cd
commit
f35c3f1836
@ -102,10 +102,7 @@ func NewCloudControllerManagerOptions() (*CloudControllerManagerOptions, error)
|
|||||||
|
|
||||||
s.SecureServing.ServerCert.CertDirectory = "/var/run/kubernetes"
|
s.SecureServing.ServerCert.CertDirectory = "/var/run/kubernetes"
|
||||||
s.SecureServing.ServerCert.PairName = "cloud-controller-manager"
|
s.SecureServing.ServerCert.PairName = "cloud-controller-manager"
|
||||||
|
s.SecureServing.BindPort = ports.CloudControllerManagerPort
|
||||||
// disable secure serving for now
|
|
||||||
// TODO: enable HTTPS by default
|
|
||||||
s.SecureServing.BindPort = 0
|
|
||||||
|
|
||||||
return &s, nil
|
return &s, nil
|
||||||
}
|
}
|
||||||
@ -263,6 +260,10 @@ func (o *CloudControllerManagerOptions) Config() (*cloudcontrollerconfig.Config,
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if err := o.SecureServing.MaybeDefaultWithSelfSignedCerts("localhost", nil, []net.IP{net.ParseIP("127.0.0.1")}); err != nil {
|
||||||
|
return nil, fmt.Errorf("error creating self-signed certificates: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
c := &cloudcontrollerconfig.Config{}
|
c := &cloudcontrollerconfig.Config{}
|
||||||
if err := o.ApplyTo(c, CloudControllerManagerUserAgent); err != nil {
|
if err := o.ApplyTo(c, CloudControllerManagerUserAgent); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
|
@ -32,6 +32,7 @@ const (
|
|||||||
InsecureKubeControllerManagerPort = 10252
|
InsecureKubeControllerManagerPort = 10252
|
||||||
// InsecureCloudControllerManagerPort is the default port for the cloud controller manager server.
|
// InsecureCloudControllerManagerPort is the default port for the cloud controller manager server.
|
||||||
// This value may be overridden by a flag at startup.
|
// This value may be overridden by a flag at startup.
|
||||||
|
// Deprecated: use the secure CloudControllerManagerPort instead.
|
||||||
InsecureCloudControllerManagerPort = 10253
|
InsecureCloudControllerManagerPort = 10253
|
||||||
// KubeletReadOnlyPort exposes basic read-only services from the kubelet.
|
// KubeletReadOnlyPort exposes basic read-only services from the kubelet.
|
||||||
// May be overridden by a flag at startup.
|
// May be overridden by a flag at startup.
|
||||||
@ -45,4 +46,7 @@ const (
|
|||||||
// KubeControllerManagerPort is the default port for the controller manager status server.
|
// KubeControllerManagerPort is the default port for the controller manager status server.
|
||||||
// May be overridden by a flag at startup.
|
// May be overridden by a flag at startup.
|
||||||
KubeControllerManagerPort = 10257
|
KubeControllerManagerPort = 10257
|
||||||
|
// CloudControllerManagerPort is the default port for the cloud controller manager server.
|
||||||
|
// This value may be overridden by a flag at startup.
|
||||||
|
CloudControllerManagerPort = 10258
|
||||||
)
|
)
|
||||||
|
Loading…
Reference in New Issue
Block a user