master.yaml.v1.j2 9.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230
  1. kind: MasterConfig
  2. apiVersion: v1
  3. admissionConfig:
  4. {% if 'admission_plugin_config' in openshift.master %}
  5. pluginConfig:{{ openshift.master.admission_plugin_config | lib_utils_to_padded_yaml(level=2) }}
  6. {% endif %}
  7. apiLevels:
  8. - v1
  9. {% if not openshift_version_gte_3_9 %}
  10. assetConfig:
  11. logoutURL: "{{ openshift.master.logout_url | default('') }}"
  12. masterPublicURL: {{ openshift.master.public_api_url }}
  13. publicURL: {{ openshift.master.public_console_url }}/
  14. {% if 'logging_public_url' in openshift.master %}
  15. loggingPublicURL: {{ openshift.master.logging_public_url }}
  16. {% endif %}
  17. {% if openshift_hosted_metrics_deploy_url is defined %}
  18. metricsPublicURL: {{ openshift_hosted_metrics_deploy_url }}
  19. {% endif %}
  20. {% if 'extension_scripts' in openshift.master %}
  21. extensionScripts: {{ openshift.master.extension_scripts | lib_utils_to_padded_yaml(1, 2) }}
  22. {% endif %}
  23. {% if 'extension_stylesheets' in openshift.master %}
  24. extensionStylesheets: {{ openshift.master.extension_stylesheets | lib_utils_to_padded_yaml(1, 2) }}
  25. {% endif %}
  26. {% if 'extensions' in openshift.master %}
  27. extensions: {{ openshift.master.extensions | lib_utils_to_padded_yaml(1, 2) }}
  28. {% endif %}
  29. servingInfo:
  30. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.console_port }}
  31. bindNetwork: tcp4
  32. certFile: master.server.crt
  33. clientCA: ""
  34. keyFile: master.server.key
  35. maxRequestsInFlight: 0
  36. requestTimeoutSeconds: 0
  37. {% if openshift_master_min_tls_version is defined %}
  38. minTLSVersion: {{ openshift_master_min_tls_version }}
  39. {% endif %}
  40. {% if openshift_master_cipher_suites is defined %}
  41. cipherSuites:
  42. {% for cipher_suite in openshift_master_cipher_suites %}
  43. - {{ cipher_suite }}
  44. {% endfor %}
  45. {% endif %}
  46. # assetconfig end
  47. {% endif %}
  48. {% if openshift.master.audit_config | default(none) is not none %}
  49. auditConfig:{{ openshift.master.audit_config | lib_utils_to_padded_yaml(level=1) }}
  50. {% endif %}
  51. controllerConfig:
  52. election:
  53. lockName: openshift-master-controllers
  54. serviceServingCert:
  55. signer:
  56. certFile: service-signer.crt
  57. keyFile: service-signer.key
  58. controllers: '*'
  59. corsAllowedOrigins:
  60. # anchor with start (\A) and end (\z) of the string, make the check case insensitive ((?i)) and escape hostname
  61. {% for origin in ['127.0.0.1', 'localhost', openshift.common.ip, openshift.common.public_ip] | union(openshift.common.all_hostnames) | unique %}
  62. - (?i)//{{ origin | regex_escape() }}(:|\z)
  63. {% endfor %}
  64. {% for custom_origin in openshift.master.custom_cors_origins | default("") %}
  65. - (?i)//{{ custom_origin | regex_escape() }}(:|\z)
  66. {% endfor %}
  67. {% if 'disabled_features' in openshift.master %}
  68. disabledFeatures: {{ openshift.master.disabled_features | to_json }}
  69. {% endif %}
  70. {% if openshift.master.embedded_dns | bool %}
  71. dnsConfig:
  72. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift_master_dns_port }}
  73. bindNetwork: tcp4
  74. {% endif %}
  75. etcdClientInfo:
  76. ca: master.etcd-ca.crt
  77. certFile: master.etcd-client.crt
  78. keyFile: master.etcd-client.key
  79. urls:
  80. {% for etcd_url in openshift.master.etcd_urls %}
  81. - {{ etcd_url }}
  82. {% endfor %}
  83. etcdStorageConfig:
  84. kubernetesStoragePrefix: kubernetes.io
  85. kubernetesStorageVersion: v1
  86. openShiftStoragePrefix: openshift.io
  87. openShiftStorageVersion: v1
  88. imageConfig:
  89. format: {{ l_os_registry_url }}
  90. latest: {{ openshift_master_image_config_latest }}
  91. imagePolicyConfig:{{ openshift.master.image_policy_config | default({"internalRegistryHostname":"docker-registry.default.svc:5000"}) | lib_utils_to_padded_yaml(level=1) }}
  92. kubeletClientInfo:
  93. {# TODO: allow user specified kubelet port #}
  94. ca: ca-bundle.crt
  95. certFile: master.kubelet-client.crt
  96. keyFile: master.kubelet-client.key
  97. port: 10250
  98. {% if openshift.master.embedded_kube | bool %}
  99. kubernetesMasterConfig:
  100. apiServerArguments: {{ openshift.master.api_server_args | default(None) | lib_utils_to_padded_yaml( level=2 ) }}
  101. storage-backend:
  102. - etcd3
  103. storage-media-type:
  104. - application/vnd.kubernetes.protobuf
  105. controllerArguments: {{ openshift.master.controller_args | default(None) | lib_utils_to_padded_yaml( level=2 ) }}
  106. masterCount: {{ openshift.master.master_count }}
  107. masterIP: {{ openshift.common.ip }}
  108. podEvictionTimeout: {{ openshift.master.pod_eviction_timeout | default("") }}
  109. proxyClientInfo:
  110. certFile: master.proxy-client.crt
  111. keyFile: master.proxy-client.key
  112. schedulerArguments: {{ openshift_master_scheduler_args | default(None) | lib_utils_to_padded_yaml( level=3 ) }}
  113. schedulerConfigFile: {{ openshift_master_scheduler_conf }}
  114. servicesNodePortRange: "{{ openshift_node_port_range | default("") }}"
  115. servicesSubnet: {{ openshift.common.portal_net }}
  116. staticNodeNames: {{ openshift_node_ips | default([], true) }}
  117. {% endif %}
  118. masterClients:
  119. {# TODO: allow user to set externalKubernetesKubeConfig #}
  120. externalKubernetesClientConnectionOverrides:
  121. acceptContentTypes: application/vnd.kubernetes.protobuf,application/json
  122. contentType: application/vnd.kubernetes.protobuf
  123. burst: {{ openshift_master_external_ratelimit_burst | default(400) }}
  124. qps: {{ openshift_master_external_ratelimit_qps | default(200) }}
  125. externalKubernetesKubeConfig: ""
  126. openshiftLoopbackClientConnectionOverrides:
  127. acceptContentTypes: application/vnd.kubernetes.protobuf,application/json
  128. contentType: application/vnd.kubernetes.protobuf
  129. burst: {{ openshift_master_loopback_ratelimit_burst | default(600) }}
  130. qps: {{ openshift_master_loopback_ratelimit_qps | default(300) }}
  131. openshiftLoopbackKubeConfig: openshift-master.kubeconfig
  132. masterPublicURL: {{ openshift.master.public_api_url }}
  133. networkConfig:
  134. clusterNetworkCIDR: {{ openshift.master.sdn_cluster_network_cidr }}
  135. hostSubnetLength: {{ openshift.master.sdn_host_subnet_length }}
  136. {% if openshift_version_gte_3_7 | bool %}
  137. clusterNetworks:
  138. - cidr: {{ openshift.master.sdn_cluster_network_cidr }}
  139. hostSubnetLength: {{ openshift.master.sdn_host_subnet_length }}
  140. {% endif %}
  141. {% if r_openshift_master_use_openshift_sdn or r_openshift_master_use_nuage or r_openshift_master_use_contiv or r_openshift_master_use_kuryr or r_openshift_master_sdn_network_plugin_name == 'cni' %}
  142. networkPluginName: {{ r_openshift_master_sdn_network_plugin_name_default }}
  143. {% endif %}
  144. # serviceNetworkCIDR must match kubernetesMasterConfig.servicesSubnet
  145. serviceNetworkCIDR: {{ openshift.common.portal_net }}
  146. externalIPNetworkCIDRs: {{ openshift_master_external_ip_network_cidrs | default(["0.0.0.0/0"]) | lib_utils_to_padded_yaml(1,2) }}
  147. {% if openshift_master_ingress_ip_network_cidr is defined %}
  148. ingressIPNetworkCIDR: {{ openshift_master_ingress_ip_network_cidr }}
  149. {% endif %}
  150. oauthConfig:
  151. {% if 'oauth_always_show_provider_selection' in openshift.master %}
  152. alwaysShowProviderSelection: {{ openshift.master.oauth_always_show_provider_selection }}
  153. {% endif %}
  154. {% if l_openshift_master_oauth_templates %}
  155. templates:{{ l_openshift_master_oauth_templates | lib_utils_to_padded_yaml(level=2) }}
  156. {% endif %}
  157. assetPublicURL: {{ openshift.master.public_console_url }}/
  158. grantConfig:
  159. method: {{ openshift.master.oauth_grant_method }}
  160. identityProviders:
  161. {% for line in translated_identity_providers.splitlines() %}
  162. {{ line }}
  163. {% endfor %}
  164. masterCA: ca-bundle.crt
  165. masterPublicURL: {{ openshift.master.public_api_url }}
  166. masterURL: {{ openshift.master.api_url }}
  167. sessionConfig:
  168. sessionMaxAgeSeconds: {{ openshift.master.session_max_seconds }}
  169. sessionName: {{ openshift.master.session_name }}
  170. {% if openshift.master.session_auth_secrets is defined and openshift.master.session_encryption_secrets is defined %}
  171. sessionSecretsFile: {{ openshift.master.session_secrets_file }}
  172. {% endif %}
  173. tokenConfig:
  174. accessTokenMaxAgeSeconds: {{ openshift.master.access_token_max_seconds }}
  175. authorizeTokenMaxAgeSeconds: {{ openshift.master.auth_token_max_seconds }}
  176. pauseControllers: false
  177. policyConfig:
  178. bootstrapPolicyFile: {{ openshift_master_policy }}
  179. openshiftInfrastructureNamespace: openshift-infra
  180. openshiftSharedResourcesNamespace: openshift
  181. projectConfig:
  182. defaultNodeSelector: "{{ osm_default_node_selector }}"
  183. projectRequestMessage: "{{ osm_project_request_message }}"
  184. projectRequestTemplate: "{{ osm_project_request_template }}"
  185. securityAllocator:
  186. mcsAllocatorRange: "{{ osm_mcs_allocator_range }}"
  187. mcsLabelsPerProject: {{ osm_mcs_labels_per_project }}
  188. uidAllocatorRange: "{{ osm_uid_allocator_range }}"
  189. routingConfig:
  190. subdomain: "{{ openshift_master_default_subdomain }}"
  191. serviceAccountConfig:
  192. limitSecretReferences: {{ openshift_master_saconfig_limitsecretreferences | default(false) }}
  193. managedNames:
  194. - default
  195. - builder
  196. - deployer
  197. masterCA: ca-bundle.crt
  198. privateKeyFile: serviceaccounts.private.key
  199. publicKeyFiles:
  200. - serviceaccounts.public.key
  201. servingInfo:
  202. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.api_port }}
  203. bindNetwork: tcp4
  204. certFile: master.server.crt
  205. clientCA: ca.crt
  206. keyFile: master.server.key
  207. maxRequestsInFlight: {{ openshift.master.max_requests_inflight }}
  208. requestTimeoutSeconds: 3600
  209. {% if openshift.master.named_certificates | default([]) | length > 0 %}
  210. namedCertificates:
  211. {% for named_certificate in openshift.master.named_certificates %}
  212. - certFile: {{ named_certificate['certfile'] }}
  213. keyFile: {{ named_certificate['keyfile'] }}
  214. names:
  215. {% for name in named_certificate['names'] %}
  216. - "{{ name }}"
  217. {% endfor %}
  218. {% endfor %}
  219. {% endif %}
  220. {% if openshift_master_min_tls_version is defined %}
  221. minTLSVersion: {{ openshift_master_min_tls_version }}
  222. {% endif %}
  223. {% if openshift_master_cipher_suites is defined %}
  224. cipherSuites:
  225. {% for cipher_suite in openshift_master_cipher_suites %}
  226. - {{ cipher_suite }}
  227. {% endfor %}
  228. {% endif %}
  229. volumeConfig:
  230. dynamicProvisioningEnabled: {{ openshift.master.dynamic_provisioning_enabled }}