master.yaml.v1.j2 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238
  1. admissionConfig:
  2. {% if 'admission_plugin_order' in openshift.master %}
  3. pluginOrderOverride:{{ openshift.master.admission_plugin_order | to_padded_yaml(level=2) }}
  4. {% endif %}
  5. {% if 'admission_plugin_config' in openshift.master %}
  6. pluginConfig:{{ openshift.master.admission_plugin_config | to_padded_yaml(level=2) }}
  7. {% endif %}
  8. apiLevels:
  9. {% if not openshift.common.version_gte_3_1_or_1_1 | bool %}
  10. - v1beta3
  11. {% endif %}
  12. - v1
  13. apiVersion: v1
  14. assetConfig:
  15. logoutURL: "{{ openshift.master.logout_url | default('') }}"
  16. masterPublicURL: {{ openshift.master.public_api_url }}
  17. publicURL: {{ openshift.master.public_console_url }}/
  18. {% if 'logging_public_url' in openshift.master %}
  19. loggingPublicURL: {{ openshift.master.logging_public_url }}
  20. {% endif %}
  21. {% if 'metrics_public_url' in openshift.master %}
  22. metricsPublicURL: {{ openshift.master.metrics_public_url }}
  23. {% endif %}
  24. {% if 'extension_scripts' in openshift.master %}
  25. extensionScripts: {{ openshift.master.extension_scripts | to_padded_yaml(1, 2) }}
  26. {% endif %}
  27. {% if 'extension_stylesheets' in openshift.master %}
  28. extensionStylesheets: {{ openshift.master.extension_stylesheets | to_padded_yaml(1, 2) }}
  29. {% endif %}
  30. {% if 'extensions' in openshift.master %}
  31. extensions: {{ openshift.master.extensions | to_padded_yaml(1, 2) }}
  32. {% endif %}
  33. servingInfo:
  34. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.console_port }}
  35. bindNetwork: tcp4
  36. certFile: master.server.crt
  37. clientCA: ""
  38. keyFile: master.server.key
  39. maxRequestsInFlight: 0
  40. requestTimeoutSeconds: 0
  41. {% if openshift_master_ha | bool %}
  42. {% if openshift.master.audit_config | default(none) is not none and openshift.common.version_gte_3_2_or_1_2 | bool %}
  43. auditConfig:{{ openshift.master.audit_config | to_padded_yaml(level=1) }}
  44. {% endif %}
  45. controllerLeaseTTL: {{ openshift.master.controller_lease_ttl | default('30') }}
  46. {% endif %}
  47. controllers: '*'
  48. corsAllowedOrigins:
  49. {% for origin in ['127.0.0.1', 'localhost', openshift.common.ip, openshift.common.public_ip] | union(openshift.common.all_hostnames) | unique %}
  50. - {{ origin }}
  51. {% endfor %}
  52. {% for custom_origin in openshift.master.custom_cors_origins | default("") %}
  53. - {{ custom_origin }}
  54. {% endfor %}
  55. {% if 'disabled_features' in openshift.master %}
  56. disabledFeatures: {{ openshift.master.disabled_features | to_json }}
  57. {% endif %}
  58. {% if openshift.master.embedded_dns | bool %}
  59. dnsConfig:
  60. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.dns_port }}
  61. bindNetwork: tcp4
  62. {% endif %}
  63. etcdClientInfo:
  64. ca: {{ "ca.crt" if (openshift.master.embedded_etcd | bool) else "master.etcd-ca.crt" }}
  65. certFile: master.etcd-client.crt
  66. keyFile: master.etcd-client.key
  67. urls:
  68. {% for etcd_url in openshift.master.etcd_urls %}
  69. - {{ etcd_url }}
  70. {% endfor %}
  71. {% if openshift.master.embedded_etcd | bool %}
  72. etcdConfig:
  73. address: {{ openshift.common.hostname }}:{{ openshift.master.etcd_port }}
  74. peerAddress: {{ openshift.common.hostname }}:7001
  75. peerServingInfo:
  76. bindAddress: {{ openshift.master.bind_addr }}:7001
  77. certFile: etcd.server.crt
  78. clientCA: ca.crt
  79. keyFile: etcd.server.key
  80. servingInfo:
  81. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.etcd_port }}
  82. certFile: etcd.server.crt
  83. clientCA: ca.crt
  84. keyFile: etcd.server.key
  85. storageDirectory: {{ openshift.common.data_dir }}/openshift.local.etcd
  86. {% endif %}
  87. etcdStorageConfig:
  88. kubernetesStoragePrefix: kubernetes.io
  89. kubernetesStorageVersion: v1
  90. openShiftStoragePrefix: openshift.io
  91. openShiftStorageVersion: v1
  92. imageConfig:
  93. format: {{ openshift.master.registry_url }}
  94. latest: false
  95. {% if 'image_policy_config' in openshift.master %}
  96. imagePolicyConfig:{{ openshift.master.image_policy_config | to_padded_yaml(level=1) }}
  97. {% endif %}
  98. kind: MasterConfig
  99. kubeletClientInfo:
  100. {# TODO: allow user specified kubelet port #}
  101. ca: ca.crt
  102. certFile: master.kubelet-client.crt
  103. keyFile: master.kubelet-client.key
  104. port: 10250
  105. {% if openshift.master.embedded_kube | bool %}
  106. kubernetesMasterConfig:
  107. {% if not openshift.common.version_gte_3_1_or_1_1 | bool %}
  108. apiLevels:
  109. - v1beta3
  110. - v1
  111. {% endif %}
  112. admissionConfig:
  113. {% if 'kube_admission_plugin_order' in openshift.master %}
  114. pluginOrderOverride:{{ openshift.master.kube_admission_plugin_order | to_padded_yaml(level=3) }}
  115. {% endif %}
  116. {% if 'kube_admission_plugin_config' in openshift.master %}
  117. pluginConfig:{{ openshift.master.kube_admission_plugin_config | to_padded_yaml(level=3) }}
  118. {% endif %}
  119. apiServerArguments: {{ openshift.master.api_server_args | default(None) | to_padded_yaml( level=2 ) }}
  120. controllerArguments: {{ openshift.master.controller_args | default(None) | to_padded_yaml( level=2 ) }}
  121. masterCount: {{ openshift.master.master_count if openshift.master.cluster_method | default(None) == 'native' else 1 }}
  122. masterIP: {{ openshift.common.ip }}
  123. podEvictionTimeout: {{ openshift.master.pod_eviction_timeout | default("") }}
  124. proxyClientInfo:
  125. certFile: master.proxy-client.crt
  126. keyFile: master.proxy-client.key
  127. schedulerConfigFile: {{ openshift_master_scheduler_conf }}
  128. servicesNodePortRange: ""
  129. servicesSubnet: {{ openshift.common.portal_net }}
  130. staticNodeNames: {{ openshift_node_ips | default([], true) }}
  131. {% endif %}
  132. masterClients:
  133. {# TODO: allow user to set externalKubernetesKubeConfig #}
  134. {% if openshift.common.version_gte_3_3_or_1_3 | bool %}
  135. externalKubernetesClientConnectionOverrides:
  136. acceptContentTypes: application/vnd.kubernetes.protobuf,application/json
  137. contentType: application/vnd.kubernetes.protobuf
  138. burst: 400
  139. qps: 200
  140. {% endif %}
  141. externalKubernetesKubeConfig: ""
  142. {% if openshift.common.version_gte_3_3_or_1_3 | bool %}
  143. openshiftLoopbackClientConnectionOverrides:
  144. acceptContentTypes: application/vnd.kubernetes.protobuf,application/json
  145. contentType: application/vnd.kubernetes.protobuf
  146. burst: 600
  147. qps: 300
  148. {% endif %}
  149. openshiftLoopbackKubeConfig: openshift-master.kubeconfig
  150. masterPublicURL: {{ openshift.master.public_api_url }}
  151. networkConfig:
  152. clusterNetworkCIDR: {{ openshift.master.sdn_cluster_network_cidr }}
  153. hostSubnetLength: {{ openshift.master.sdn_host_subnet_length }}
  154. {% if openshift.common.use_openshift_sdn or openshift.common.use_nuage %}
  155. networkPluginName: {{ openshift.common.sdn_network_plugin_name }}
  156. {% endif %}
  157. # serviceNetworkCIDR must match kubernetesMasterConfig.servicesSubnet
  158. serviceNetworkCIDR: {{ openshift.common.portal_net }}
  159. oauthConfig:
  160. {% if 'oauth_always_show_provider_selection' in openshift.master %}
  161. alwaysShowProviderSelection: {{ openshift.master.oauth_always_show_provider_selection }}
  162. {% endif %}
  163. {% if 'oauth_templates' in openshift.master %}
  164. templates:{{ openshift.master.oauth_templates | to_padded_yaml(level=2) }}
  165. {% endif %}
  166. assetPublicURL: {{ openshift.master.public_console_url }}/
  167. grantConfig:
  168. method: {{ openshift.master.oauth_grant_method }}
  169. identityProviders:
  170. {% for line in translated_identity_providers.splitlines() %}
  171. {{ line }}
  172. {% endfor %}
  173. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  174. masterCA: ca-bundle.crt
  175. {% else %}
  176. masterCA: ca.rt
  177. {% endif %}
  178. masterPublicURL: {{ openshift.master.public_api_url }}
  179. masterURL: {{ openshift.master.api_url }}
  180. sessionConfig:
  181. sessionMaxAgeSeconds: {{ openshift.master.session_max_seconds }}
  182. sessionName: {{ openshift.master.session_name }}
  183. {% if openshift.master.session_auth_secrets is defined and openshift.master.session_encryption_secrets is defined %}
  184. sessionSecretsFile: {{ openshift.master.session_secrets_file }}
  185. {% endif %}
  186. tokenConfig:
  187. accessTokenMaxAgeSeconds: {{ openshift.master.access_token_max_seconds }}
  188. authorizeTokenMaxAgeSeconds: {{ openshift.master.auth_token_max_seconds }}
  189. pauseControllers: false
  190. policyConfig:
  191. bootstrapPolicyFile: {{ openshift_master_policy }}
  192. openshiftInfrastructureNamespace: openshift-infra
  193. openshiftSharedResourcesNamespace: openshift
  194. projectConfig:
  195. defaultNodeSelector: "{{ openshift.master.default_node_selector }}"
  196. projectRequestMessage: "{{ openshift.master.project_request_message }}"
  197. projectRequestTemplate: "{{ openshift.master.project_request_template }}"
  198. securityAllocator:
  199. mcsAllocatorRange: "{{ openshift.master.mcs_allocator_range }}"
  200. mcsLabelsPerProject: {{ openshift.master.mcs_labels_per_project }}
  201. uidAllocatorRange: "{{ openshift.master.uid_allocator_range }}"
  202. routingConfig:
  203. subdomain: "{{ openshift.master.default_subdomain | default("") }}"
  204. serviceAccountConfig:
  205. limitSecretReferences: false
  206. managedNames:
  207. - default
  208. - builder
  209. - deployer
  210. {% if openshift.common.version_gte_3_2_or_1_2 | bool %}
  211. masterCA: ca-bundle.crt
  212. {% else %}
  213. masterCA: ca.rt
  214. {% endif %}
  215. privateKeyFile: serviceaccounts.private.key
  216. publicKeyFiles:
  217. - serviceaccounts.public.key
  218. servingInfo:
  219. bindAddress: {{ openshift.master.bind_addr }}:{{ openshift.master.api_port }}
  220. bindNetwork: tcp4
  221. certFile: master.server.crt
  222. clientCA: ca.crt
  223. keyFile: master.server.key
  224. maxRequestsInFlight: {{ openshift.master.max_requests_inflight }}
  225. requestTimeoutSeconds: 3600
  226. {% if openshift.master.named_certificates | default([]) | length > 0 %}
  227. namedCertificates:
  228. {% for named_certificate in openshift.master.named_certificates %}
  229. - certFile: {{ named_certificate['certfile'] }}
  230. keyFile: {{ named_certificate['keyfile'] }}
  231. names:
  232. {% for name in named_certificate['names'] %}
  233. - "{{ name }}"
  234. {% endfor %}
  235. {% endfor %}
  236. {% endif %}
  237. volumeConfig:
  238. dynamicProvisioningEnabled: {{ openshift.master.dynamic_provisioning_enabled }}