master.yaml.v1.j2 10 KB


  1. admissionConfig:
  2. {% if 'admission_plugin_config' in openshift.master %}
  3. pluginConfig:{{ openshift.master.admission_plugin_config | to_padded_yaml(level=2) }}
  4. {% endif %}
  5. apiLevels:
  6. {% if not openshift.common.version_gte_3_1_or_1_1 | bool %}
  7. - v1beta3
  8. {% endif %}
  9. - v1
  10. apiVersion: v1
  11. assetConfig:
  12. logoutURL: "{{ openshift.master.logout_url | default('') }}"
  13. masterPublicURL: {{ openshift.master.public_api_url }}
  14. publicURL: {{ openshift.master.public_console_url }}/
  15. {% if 'logging_public_url' in openshift.master %}
  16. loggingPublicURL: {{ openshift.master.logging_public_url }}
  17. {% endif %}
  18. {% if openshift_hosted_metrics_deploy_url is defined %}
  19. metricsPublicURL: {{ openshift_hosted_metrics_deploy_url }}
  20. {% endif %}
  21. {% if 'extension_scripts' in openshift.master %}
  22. extensionScripts: {{ openshift.master.extension_scripts | to_padded_yaml(1, 2) }}
  23. {% endif %}
  24. {% if 'extension_stylesheets' in openshift.master %}
  25. extensionStylesheets: {{ openshift.master.extension_stylesheets | to_padded_yaml(1, 2) }}
  26. {% endif %}
  27. {% if 'extensions' in openshift.master %}
  28. extensions: {{ openshift.master.extensions | to_padded_yaml(1, 2) }}
  29. {% endif %}
  30. servingInfo:
  31. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.console_port }}
  32. bindNetwork: tcp4
  33. certFile: master.server.crt
  34. clientCA: ""
  35. keyFile: master.server.key
  36. maxRequestsInFlight: 0
  37. requestTimeoutSeconds: 0
  38. {% if openshift_master_ha | bool %}
  39. {% if openshift.master.audit_config | default(none) is not none and openshift.common.version_gte_3_2_or_1_2 | bool %}
  40. auditConfig:{{ openshift.master.audit_config | to_padded_yaml(level=1) }}
  41. {% endif %}
  42. controllerLeaseTTL: {{ openshift.master.controller_lease_ttl | default('30') }}
  43. {% endif %}
  44. {% if openshift.common.version_gte_3_3_or_1_3 | bool %}
  45. controllerConfig:
  46. serviceServingCert:
  47. signer:
  48. certFile: service-signer.crt
  49. keyFile: service-signer.key
  50. {% endif %}
  51. controllers: '*'
  52. corsAllowedOrigins:
  53. {% for origin in ['127.0.0.1', 'localhost', openshift.common.ip, openshift.common.public_ip] | union(openshift.common.all_hostnames) | unique %}
  54. - {{ origin }}
  55. {% endfor %}
  56. {% for custom_origin in openshift.master.custom_cors_origins | default("") %}
  57. - {{ custom_origin }}
  58. {% endfor %}
  59. {% if 'disabled_features' in openshift.master %}
  60. disabledFeatures: {{ openshift.master.disabled_features | to_json }}
  61. {% endif %}
  62. {% if openshift.master.embedded_dns | bool %}
  63. dnsConfig:
  64. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.dns_port }}
  65. bindNetwork: tcp4
  66. {% endif %}
  67. etcdClientInfo:
  68. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  69. ca: {{ "ca-bundle.crt" if (openshift.master.embedded_etcd | bool) else "master.etcd-ca.crt" }}
  70. {% else %}
  71. ca: {{ "ca.crt" if (openshift.master.embedded_etcd | bool) else "master.etcd-ca.crt" }}
  72. {% endif %}
  73. certFile: master.etcd-client.crt
  74. keyFile: master.etcd-client.key
  75. urls:
  76. {% for etcd_url in openshift.master.etcd_urls %}
  77. - {{ etcd_url }}
  78. {% endfor %}
  79. {% if openshift.master.embedded_etcd | bool %}
  80. etcdConfig:
  81. address: {{ openshift.common.hostname }}:{{ openshift.master.etcd_port }}
  82. peerAddress: {{ openshift.common.hostname }}:7001
  83. peerServingInfo:
  84. bindAddress: {{ openshift.master.bind_addr }}:7001
  85. certFile: etcd.server.crt
  86. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  87. clientCA: ca-bundle.crt
  88. {% else %}
  89. clientCA: ca.crt
  90. {% endif %}
  91. keyFile: etcd.server.key
  92. servingInfo:
  93. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.etcd_port }}
  94. certFile: etcd.server.crt
  95. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  96. clientCA: ca-bundle.crt
  97. {% else %}
  98. clientCA: ca.crt
  99. {% endif %}
  100. keyFile: etcd.server.key
  101. storageDirectory: {{ openshift.common.data_dir }}/openshift.local.etcd
  102. {% endif %}
  103. etcdStorageConfig:
  104. kubernetesStoragePrefix: kubernetes.io
  105. kubernetesStorageVersion: v1
  106. openShiftStoragePrefix: openshift.io
  107. openShiftStorageVersion: v1
  108. imageConfig:
  109. format: {{ openshift.master.registry_url }}
  110. latest: false
  111. {% if 'image_policy_config' in openshift.master %}
  112. imagePolicyConfig:{{ openshift.master.image_policy_config | to_padded_yaml(level=1) }}
  113. {% endif %}
  114. kind: MasterConfig
  115. kubeletClientInfo:
  116. {# TODO: allow user specified kubelet port #}
  117. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  118. ca: ca-bundle.crt
  119. {% else %}
  120. ca: ca.crt
  121. {% endif %}
  122. certFile: master.kubelet-client.crt
  123. keyFile: master.kubelet-client.key
  124. port: 10250
  125. {% if openshift.master.embedded_kube | bool %}
  126. kubernetesMasterConfig:
  127. {% if not openshift.common.version_gte_3_1_or_1_1 | bool %}
  128. apiLevels:
  129. - v1beta3
  130. - v1
  131. {% endif %}
  132. apiServerArguments: {{ openshift.master.api_server_args | default(None) | to_padded_yaml( level=2 ) }}
  133. controllerArguments: {{ openshift.master.controller_args | default(None) | to_padded_yaml( level=2 ) }}
  134. masterCount: {{ openshift.master.master_count if openshift.master.cluster_method | default(None) == 'native' else 1 }}
  135. masterIP: {{ openshift.common.ip }}
  136. podEvictionTimeout: {{ openshift.master.pod_eviction_timeout | default("") }}
  137. proxyClientInfo:
  138. certFile: master.proxy-client.crt
  139. keyFile: master.proxy-client.key
  140. schedulerArguments: {{ openshift_master_scheduler_args | default(None) | to_padded_yaml( level=3 ) }}
  141. schedulerConfigFile: {{ openshift_master_scheduler_conf }}
  142. servicesNodePortRange: "{{ openshift_node_port_range | default("") }}"
  143. servicesSubnet: {{ openshift.common.portal_net }}
  144. staticNodeNames: {{ openshift_node_ips | default([], true) }}
  145. {% endif %}
  146. masterClients:
  147. {# TODO: allow user to set externalKubernetesKubeConfig #}
  148. {% if openshift.common.version_gte_3_3_or_1_3 | bool %}
  149. externalKubernetesClientConnectionOverrides:
  150. acceptContentTypes: application/vnd.kubernetes.protobuf,application/json
  151. contentType: application/vnd.kubernetes.protobuf
  152. burst: 400
  153. qps: 200
  154. {% endif %}
  155. externalKubernetesKubeConfig: ""
  156. {% if openshift.common.version_gte_3_3_or_1_3 | bool %}
  157. openshiftLoopbackClientConnectionOverrides:
  158. acceptContentTypes: application/vnd.kubernetes.protobuf,application/json
  159. contentType: application/vnd.kubernetes.protobuf
  160. burst: 600
  161. qps: 300
  162. {% endif %}
  163. openshiftLoopbackKubeConfig: openshift-master.kubeconfig
  164. masterPublicURL: {{ openshift.master.public_api_url }}
  165. networkConfig:
  166. clusterNetworkCIDR: {{ openshift.master.sdn_cluster_network_cidr }}
  167. hostSubnetLength: {{ openshift.master.sdn_host_subnet_length }}
  168. {% if openshift.common.use_openshift_sdn or openshift.common.use_nuage or openshift.common.use_contiv or openshift.common.sdn_network_plugin_name == 'cni' %}
  169. networkPluginName: {{ openshift.common.sdn_network_plugin_name }}
  170. {% endif %}
  171. # serviceNetworkCIDR must match kubernetesMasterConfig.servicesSubnet
  172. serviceNetworkCIDR: {{ openshift.common.portal_net }}
  173. externalIPNetworkCIDRs: {{ openshift_master_external_ip_network_cidrs | default(["0.0.0.0/0"]) | to_padded_yaml(1,2) }}
  174. {% if openshift_master_ingress_ip_network_cidr is defined %}
  175. ingressIPNetworkCIDR: {{ openshift_master_ingress_ip_network_cidr }}
  176. {% endif %}
  177. oauthConfig:
  178. {% if 'oauth_always_show_provider_selection' in openshift.master %}
  179. alwaysShowProviderSelection: {{ openshift.master.oauth_always_show_provider_selection }}
  180. {% endif %}
  181. {% if 'oauth_templates' in openshift.master %}
  182. templates:{{ openshift.master.oauth_templates | to_padded_yaml(level=2) }}
  183. {% endif %}
  184. assetPublicURL: {{ openshift.master.public_console_url }}/
  185. grantConfig:
  186. method: {{ openshift.master.oauth_grant_method }}
  187. identityProviders:
  188. {% for line in translated_identity_providers.splitlines() %}
  189. {{ line }}
  190. {% endfor %}
  191. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  192. masterCA: ca-bundle.crt
  193. {% else %}
  194. masterCA: ca.crt
  195. {% endif %}
  196. masterPublicURL: {{ openshift.master.public_api_url }}
  197. masterURL: {{ openshift.master.api_url }}
  198. sessionConfig:
  199. sessionMaxAgeSeconds: {{ openshift.master.session_max_seconds }}
  200. sessionName: {{ openshift.master.session_name }}
  201. {% if openshift.master.session_auth_secrets is defined and openshift.master.session_encryption_secrets is defined %}
  202. sessionSecretsFile: {{ openshift.master.session_secrets_file }}
  203. {% endif %}
  204. tokenConfig:
  205. accessTokenMaxAgeSeconds: {{ openshift.master.access_token_max_seconds }}
  206. authorizeTokenMaxAgeSeconds: {{ openshift.master.auth_token_max_seconds }}
  207. pauseControllers: false
  208. policyConfig:
  209. bootstrapPolicyFile: {{ openshift_master_policy }}
  210. openshiftInfrastructureNamespace: openshift-infra
  211. openshiftSharedResourcesNamespace: openshift
  212. projectConfig:
  213. defaultNodeSelector: "{{ openshift.master.default_node_selector }}"
  214. projectRequestMessage: "{{ openshift.master.project_request_message }}"
  215. projectRequestTemplate: "{{ openshift.master.project_request_template }}"
  216. securityAllocator:
  217. mcsAllocatorRange: "{{ openshift.master.mcs_allocator_range }}"
  218. mcsLabelsPerProject: {{ openshift.master.mcs_labels_per_project }}
  219. uidAllocatorRange: "{{ openshift.master.uid_allocator_range }}"
  220. routingConfig:
  221. subdomain: "{{ openshift_master_default_subdomain | default("") }}"
  222. serviceAccountConfig:
  223. limitSecretReferences: false
  224. managedNames:
  225. - default
  226. - builder
  227. - deployer
  228. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  229. masterCA: ca-bundle.crt
  230. {% else %}
  231. masterCA: ca.crt
  232. {% endif %}
  233. privateKeyFile: serviceaccounts.private.key
  234. publicKeyFiles:
  235. - serviceaccounts.public.key
  236. servingInfo:
  237. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.api_port }}
  238. bindNetwork: tcp4
  239. certFile: master.server.crt
  240. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  241. clientCA: ca-bundle.crt
  242. {% else %}
  243. clientCA: ca.crt
  244. {% endif %}
  245. keyFile: master.server.key
  246. maxRequestsInFlight: {{ openshift.master.max_requests_inflight }}
  247. requestTimeoutSeconds: 3600
  248. {% if openshift.master.named_certificates | default([]) | length > 0 %}
  249. namedCertificates:
  250. {% for named_certificate in openshift.master.named_certificates %}
  251. - certFile: {{ named_certificate['certfile'] }}
  252. keyFile: {{ named_certificate['keyfile'] }}
  253. names:
  254. {% for name in named_certificate['names'] %}
  255. - "{{ name }}"
  256. {% endfor %}
  257. {% endfor %}
  258. {% endif %}
  259. volumeConfig:
  260. dynamicProvisioningEnabled: {{ openshift.master.dynamic_provisioning_enabled }}