Skip to content

Commit 1b12fcc

Browse files
authored
23.1.0+1.28.5 (#58)
* fix permissions for temporary directory * Molecule: adjust common names for certificates / change algo to ecdsa and algo size * Molecule: change to Ubuntu 22.04 for test-assets VM * update CHANGELOG
1 parent b3ba496 commit 1b12fcc

File tree

4 files changed

+60
-7
lines changed

4 files changed

+60
-7
lines changed

CHANGELOG.md

+12
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,17 @@
11
# Changelog
22

3+
## 23.1.0+1.28.5
4+
5+
### MOLECULE
6+
7+
- Change to Ubuntu 22.04 for test-assets VM
8+
- Adjust common names for certificates / change algo to ecdsa and algo size
9+
10+
### OTHER CHANGES
11+
12+
- fix permissions for temporary directory
13+
- adjust Github action because of Ansible Galaxy changes
14+
315
## 23.0.0+1.28.5
416

517
### UPDATE

molecule/default/group_vars/all.yml

+38-6
Original file line numberDiff line numberDiff line change
@@ -154,16 +154,48 @@ runc_bin_directory: "/usr/local/sbin"
154154

155155
# Common name for "etcd" certificate authority certificates.
156156
ca_etcd_csr_cn: "etcd"
157+
ca_etcd_csr_key_algo: "ecdsa"
158+
ca_etcd_csr_key_size: "384"
157159

158160
# Common name for "kube-apiserver" certificate authority certificate.
159161
ca_k8s_apiserver_csr_cn: "kubernetes"
162+
ca_k8s_apiserver_csr_key_algo: "ecdsa"
163+
ca_k8s_apiserver_csr_key_size: "384"
160164

161165
# Common names for "etcd" server, peer and client certificates.
162-
etcd_server_csr_cn: "etcd"
163-
etcd_peer_csr_cn: "etcd"
164-
etcd_client_csr_cn_prefix: "etcd"
166+
etcd_server_csr_cn: "etcd-server"
167+
etcd_server_csr_key_algo: "ecdsa"
168+
etcd_server_csr_key_size: "384"
169+
170+
etcd_peer_csr_cn: "etcd-peer"
171+
etcd_peer_csr_key_algo: "ecdsa"
172+
etcd_peer_csr_key_size: "384"
173+
174+
etcd_client_csr_cn_prefix: "etcd-client"
175+
etcd_client_csr_key_algo: "ecdsa"
176+
etcd_client_csr_key_size: "384"
165177

166178
# Common names for kube-apiserver, admin and kube-controller-manager certificates.
167-
k8s_apiserver_csr_cn: "kubernetes"
168-
k8s_admin_csr_cn: "admin"
169-
k8s_controller_manager_sa_csr_cn: "service-accounts"
179+
k8s_apiserver_csr_cn: "k8s-apiserver"
180+
k8s_apiserver_csr_key_algo: "ecdsa"
181+
k8s_apiserver_csr_key_size: "384"
182+
183+
k8s_admin_csr_cn: "k8s-admin"
184+
k8s_admin_csr_key_algo: "ecdsa"
185+
k8s_admin_csr_key_size: "384"
186+
187+
k8s_worker_csr_key_algo: "ecdsa"
188+
k8s_worker_csr_key_size: "384"
189+
190+
k8s_controller_manager_csr_key_algo: "ecdsa"
191+
k8s_controller_manager_csr_key_size: "384"
192+
193+
k8s_scheduler_csr_key_algo: "ecdsa"
194+
k8s_scheduler_csr_key_size: "384"
195+
196+
k8s_controller_manager_sa_csr_cn: "k8s-service-accounts"
197+
k8s_controller_manager_sa_csr_key_algo: "ecdsa"
198+
k8s_controller_manager_sa_csr_key_size: "384"
199+
200+
k8s_kube_proxy_csr_key_algo: "ecdsa"
201+
k8s_kube_proxy_csr_key_size: "384"

molecule/default/molecule.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ driver:
1313

1414
platforms:
1515
- name: test-assets
16-
box: generic/ubuntu2004
16+
box: generic/ubuntu2204
1717
memory: 2048
1818
cpus: 2
1919
groups:

tasks/main.yml

+9
Original file line numberDiff line numberDiff line change
@@ -304,6 +304,15 @@
304304
delegate_to: "{{ k8s_ctl_delegate_to }}"
305305
changed_when: false
306306

307+
- name: Change temporary directory permissions
308+
ansible.builtin.file:
309+
path: "{{ k8s_ctl__tmp_dir.path }}"
310+
state: directory
311+
mode: "0755"
312+
run_once: true
313+
delegate_to: "{{ k8s_ctl_delegate_to }}"
314+
changed_when: false
315+
307316
- name: Copy kube-apiserver-to-kubelet ClusterRole
308317
ansible.builtin.copy:
309318
src: "files/kube-apiserver-to-kubelet_cluster_role.yaml"

0 commit comments

Comments
 (0)