Skip to content

Commit 78d4757

Browse files
authored
Merge pull request #17354 from ameukam/admission-controllers
Enable more admission controllers
2 parents 92cb98b + 4576e21 commit 78d4757

File tree

267 files changed

+1108
-774
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

267 files changed

+1108
-774
lines changed

nodeup/pkg/model/tests/golden/audit/tasks-kube-apiserver.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ contents: |
3434
- --client-ca-file=/srv/kubernetes/ca.crt
3535
- --cloud-config=/etc/kubernetes/in-tree-cloud.config
3636
- --cloud-provider=external
37-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
37+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
3838
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
3939
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
4040
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

nodeup/pkg/model/tests/golden/awsiam/tasks-kube-apiserver.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ contents: |
4848
- --client-ca-file=/srv/kubernetes/ca.crt
4949
- --cloud-config=/etc/kubernetes/in-tree-cloud.config
5050
- --cloud-provider=external
51-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
51+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
5252
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
5353
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
5454
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

nodeup/pkg/model/tests/golden/dedicated-apiserver/tasks-kube-apiserver.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ contents: |
2626
- --client-ca-file=/srv/kubernetes/ca.crt
2727
- --cloud-config=/etc/kubernetes/in-tree-cloud.config
2828
- --cloud-provider=external
29-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
29+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
3030
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
3131
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
3232
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

nodeup/pkg/model/tests/golden/envvars/tasks-kube-apiserver.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ contents: |
2626
- --client-ca-file=/srv/kubernetes/ca.crt
2727
- --cloud-config=/etc/kubernetes/in-tree-cloud.config
2828
- --cloud-provider=external
29-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
29+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
3030
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
3131
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
3232
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

nodeup/pkg/model/tests/golden/minimal/tasks-kube-apiserver.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ contents: |
2424
- --authorization-mode=AlwaysAllow
2525
- --bind-address=0.0.0.0
2626
- --client-ca-file=/srv/kubernetes/ca.crt
27-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
27+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
2828
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
2929
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
3030
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

nodeup/pkg/model/tests/golden/oidc/tasks-kube-apiserver.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ contents: |
2626
- --client-ca-file=/srv/kubernetes/ca.crt
2727
- --cloud-config=/etc/kubernetes/in-tree-cloud.config
2828
- --cloud-provider=external
29-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
29+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
3030
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
3131
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
3232
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

nodeup/pkg/model/tests/golden/side-loading/tasks-kube-apiserver-amd64.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ contents: |
2626
- --client-ca-file=/srv/kubernetes/ca.crt
2727
- --cloud-config=/etc/kubernetes/in-tree-cloud.config
2828
- --cloud-provider=external
29-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
29+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
3030
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
3131
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
3232
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

nodeup/pkg/model/tests/golden/side-loading/tasks-kube-apiserver-arm64.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ contents: |
2626
- --client-ca-file=/srv/kubernetes/ca.crt
2727
- --cloud-config=/etc/kubernetes/in-tree-cloud.config
2828
- --cloud-provider=external
29-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
29+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
3030
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
3131
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
3232
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

nodeup/pkg/model/tests/golden/without-etcd-events/tasks-kube-apiserver.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ contents: |
2626
- --client-ca-file=/srv/kubernetes/ca.crt
2727
- --cloud-config=/etc/kubernetes/in-tree-cloud.config
2828
- --cloud-provider=external
29-
- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,NodeRestriction,ResourceQuota
29+
- --enable-admission-plugins=DefaultStorageClass,DefaultTolerationSeconds,LimitRanger,MutatingAdmissionWebhook,NamespaceLifecycle,NodeRestriction,ResourceQuota,RuntimeClass,ServiceAccount,ValidatingAdmissionPolicy,ValidatingAdmissionWebhook
3030
- --etcd-cafile=/srv/kubernetes/kube-apiserver/etcd-ca.crt
3131
- --etcd-certfile=/srv/kubernetes/kube-apiserver/etcd-client.crt
3232
- --etcd-keyfile=/srv/kubernetes/kube-apiserver/etcd-client.key

pkg/model/components/apiserver.go

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -147,21 +147,21 @@ func (b *KubeAPIServerOptionsBuilder) BuildOptions(cluster *kops.Cluster) error
147147
}
148148
}
149149

150-
// TODO: We can probably rewrite these more clearly in descending order
151150
// Based on recommendations from:
152-
// https://kubernetes.io/docs/admin/admission-controllers/#is-there-a-recommended-set-of-admission-controllers-to-use
151+
// https://kubernetes.io/docs/reference/access-authn-authz/admission-controllers/
153152
{
154153
c.EnableAdmissionPlugins = []string{
155-
"NamespaceLifecycle",
156-
"LimitRanger",
157-
"ServiceAccount",
158-
//"PersistentVolumeLabel",
159154
"DefaultStorageClass",
160155
"DefaultTolerationSeconds",
156+
"LimitRanger",
161157
"MutatingAdmissionWebhook",
162-
"ValidatingAdmissionWebhook",
158+
"NamespaceLifecycle",
163159
"NodeRestriction",
164160
"ResourceQuota",
161+
"RuntimeClass",
162+
"ServiceAccount",
163+
"ValidatingAdmissionPolicy",
164+
"ValidatingAdmissionWebhook",
165165
}
166166
c.EnableAdmissionPlugins = append(c.EnableAdmissionPlugins, c.AppendAdmissionPlugins...)
167167
}

tests/integration/update_cluster/additionalobjects/data/aws_launch_template_master-us-test-1a.masters.additionalobjects.example.com_user_data

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ ClusterName: additionalobjects.example.com
130130
ConfigBase: memfs://tests/additionalobjects.example.com
131131
InstanceGroupName: master-us-test-1a
132132
InstanceGroupRole: ControlPlane
133-
NodeupConfigHash: Fs2hbQ1UTITDVKZyfQgIjd55UiUucLBjwNrWgCrMXT8=
133+
NodeupConfigHash: 0meC2r1xzntznUBmhrowlZ15R1orWyhfcqnQO/L7fzo=
134134
135135
__EOF_KUBE_ENV
136136

tests/integration/update_cluster/additionalobjects/data/aws_s3_object_cluster-completed.spec_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -71,15 +71,17 @@ spec:
7171
bindAddress: 0.0.0.0
7272
cloudProvider: external
7373
enableAdmissionPlugins:
74-
- NamespaceLifecycle
75-
- LimitRanger
76-
- ServiceAccount
7774
- DefaultStorageClass
7875
- DefaultTolerationSeconds
76+
- LimitRanger
7977
- MutatingAdmissionWebhook
80-
- ValidatingAdmissionWebhook
78+
- NamespaceLifecycle
8179
- NodeRestriction
8280
- ResourceQuota
81+
- RuntimeClass
82+
- ServiceAccount
83+
- ValidatingAdmissionPolicy
84+
- ValidatingAdmissionWebhook
8385
etcdServers:
8486
- https://127.0.0.1:4001
8587
etcdServersOverrides:

tests/integration/update_cluster/additionalobjects/data/aws_s3_object_nodeupconfig-master-us-test-1a_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,15 +13,17 @@ APIServerConfig:
1313
bindAddress: 0.0.0.0
1414
cloudProvider: external
1515
enableAdmissionPlugins:
16-
- NamespaceLifecycle
17-
- LimitRanger
18-
- ServiceAccount
1916
- DefaultStorageClass
2017
- DefaultTolerationSeconds
18+
- LimitRanger
2119
- MutatingAdmissionWebhook
22-
- ValidatingAdmissionWebhook
20+
- NamespaceLifecycle
2321
- NodeRestriction
2422
- ResourceQuota
23+
- RuntimeClass
24+
- ServiceAccount
25+
- ValidatingAdmissionPolicy
26+
- ValidatingAdmissionWebhook
2527
etcdServers:
2628
- https://127.0.0.1:4001
2729
etcdServersOverrides:

tests/integration/update_cluster/apiservernodes/data/aws_launch_template_apiserver.apiservers.minimal.example.com_user_data

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ ClusterName: minimal.example.com
130130
ConfigBase: memfs://clusters.example.com/minimal.example.com
131131
InstanceGroupName: apiserver
132132
InstanceGroupRole: APIServer
133-
NodeupConfigHash: DGxbW0XRm7D5zB9YwjGlYU7alrRcRG85ySGSp39Mk1E=
133+
NodeupConfigHash: AgCyoFYOQwCZEOAgf2qNhCsimY8Uec8L91X/tYvfK/w=
134134
135135
__EOF_KUBE_ENV
136136

tests/integration/update_cluster/apiservernodes/data/aws_launch_template_master-us-test-1a.masters.minimal.example.com_user_data

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ ClusterName: minimal.example.com
130130
ConfigBase: memfs://clusters.example.com/minimal.example.com
131131
InstanceGroupName: master-us-test-1a
132132
InstanceGroupRole: ControlPlane
133-
NodeupConfigHash: oat4TLWZZOwj65R6CKin5eR7GMvLjjtMZK541q480iE=
133+
NodeupConfigHash: P8AZpsNu0IcynnqI+pa1TYDzCrWTi7Lmiydk+eADVUg=
134134
135135
__EOF_KUBE_ENV
136136

tests/integration/update_cluster/apiservernodes/data/aws_s3_object_cluster-completed.spec_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -64,15 +64,17 @@ spec:
6464
bindAddress: 0.0.0.0
6565
cloudProvider: external
6666
enableAdmissionPlugins:
67-
- NamespaceLifecycle
68-
- LimitRanger
69-
- ServiceAccount
7067
- DefaultStorageClass
7168
- DefaultTolerationSeconds
69+
- LimitRanger
7270
- MutatingAdmissionWebhook
73-
- ValidatingAdmissionWebhook
71+
- NamespaceLifecycle
7472
- NodeRestriction
7573
- ResourceQuota
74+
- RuntimeClass
75+
- ServiceAccount
76+
- ValidatingAdmissionPolicy
77+
- ValidatingAdmissionWebhook
7678
etcdServers:
7779
- https://127.0.0.1:4001
7880
etcdServersOverrides:

tests/integration/update_cluster/apiservernodes/data/aws_s3_object_nodeupconfig-apiserver_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,15 +13,17 @@ APIServerConfig:
1313
bindAddress: 0.0.0.0
1414
cloudProvider: external
1515
enableAdmissionPlugins:
16-
- NamespaceLifecycle
17-
- LimitRanger
18-
- ServiceAccount
1916
- DefaultStorageClass
2017
- DefaultTolerationSeconds
18+
- LimitRanger
2119
- MutatingAdmissionWebhook
22-
- ValidatingAdmissionWebhook
20+
- NamespaceLifecycle
2321
- NodeRestriction
2422
- ResourceQuota
23+
- RuntimeClass
24+
- ServiceAccount
25+
- ValidatingAdmissionPolicy
26+
- ValidatingAdmissionWebhook
2527
etcdServers:
2628
- https://127.0.0.1:4001
2729
etcdServersOverrides:

tests/integration/update_cluster/apiservernodes/data/aws_s3_object_nodeupconfig-master-us-test-1a_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,15 +13,17 @@ APIServerConfig:
1313
bindAddress: 0.0.0.0
1414
cloudProvider: external
1515
enableAdmissionPlugins:
16-
- NamespaceLifecycle
17-
- LimitRanger
18-
- ServiceAccount
1916
- DefaultStorageClass
2017
- DefaultTolerationSeconds
18+
- LimitRanger
2119
- MutatingAdmissionWebhook
22-
- ValidatingAdmissionWebhook
20+
- NamespaceLifecycle
2321
- NodeRestriction
2422
- ResourceQuota
23+
- RuntimeClass
24+
- ServiceAccount
25+
- ValidatingAdmissionPolicy
26+
- ValidatingAdmissionWebhook
2527
etcdServers:
2628
- https://127.0.0.1:4001
2729
etcdServersOverrides:

tests/integration/update_cluster/aws-lb-controller/data/aws_launch_template_master-us-test-1a.masters.minimal.example.com_user_data

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ ClusterName: minimal.example.com
130130
ConfigBase: memfs://clusters.example.com/minimal.example.com
131131
InstanceGroupName: master-us-test-1a
132132
InstanceGroupRole: ControlPlane
133-
NodeupConfigHash: hwe4qrB8lrpQUByJDxUeDm6WzYWNuE7nQHAfP5g5nQo=
133+
NodeupConfigHash: kaj//kni7EON1tJan0zbwiVDX7DJH7p7u+F5gzQWU+M=
134134
135135
__EOF_KUBE_ENV
136136

tests/integration/update_cluster/aws-lb-controller/data/aws_s3_object_cluster-completed.spec_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -69,15 +69,17 @@ spec:
6969
bindAddress: 0.0.0.0
7070
cloudProvider: external
7171
enableAdmissionPlugins:
72-
- NamespaceLifecycle
73-
- LimitRanger
74-
- ServiceAccount
7572
- DefaultStorageClass
7673
- DefaultTolerationSeconds
74+
- LimitRanger
7775
- MutatingAdmissionWebhook
78-
- ValidatingAdmissionWebhook
76+
- NamespaceLifecycle
7977
- NodeRestriction
8078
- ResourceQuota
79+
- RuntimeClass
80+
- ServiceAccount
81+
- ValidatingAdmissionPolicy
82+
- ValidatingAdmissionWebhook
8183
etcdServers:
8284
- https://127.0.0.1:4001
8385
etcdServersOverrides:

tests/integration/update_cluster/aws-lb-controller/data/aws_s3_object_nodeupconfig-master-us-test-1a_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,15 +13,17 @@ APIServerConfig:
1313
bindAddress: 0.0.0.0
1414
cloudProvider: external
1515
enableAdmissionPlugins:
16-
- NamespaceLifecycle
17-
- LimitRanger
18-
- ServiceAccount
1916
- DefaultStorageClass
2017
- DefaultTolerationSeconds
18+
- LimitRanger
2119
- MutatingAdmissionWebhook
22-
- ValidatingAdmissionWebhook
20+
- NamespaceLifecycle
2321
- NodeRestriction
2422
- ResourceQuota
23+
- RuntimeClass
24+
- ServiceAccount
25+
- ValidatingAdmissionPolicy
26+
- ValidatingAdmissionWebhook
2527
etcdServers:
2628
- https://127.0.0.1:4001
2729
etcdServersOverrides:

tests/integration/update_cluster/bastionadditional_user-data/data/aws_launch_template_master-us-test-1a.masters.bastionuserdata.example.com_user_data

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ ClusterName: bastionuserdata.example.com
130130
ConfigBase: memfs://clusters.example.com/bastionuserdata.example.com
131131
InstanceGroupName: master-us-test-1a
132132
InstanceGroupRole: ControlPlane
133-
NodeupConfigHash: /CMrJEa3vry2ndHUBbapU9y1w15UKdldYMHe4/Il0ic=
133+
NodeupConfigHash: esf5IJa5KiGsVm/r4EJ1yLqsGLtxhDSebXYvFY8+g2c=
134134
135135
__EOF_KUBE_ENV
136136

tests/integration/update_cluster/bastionadditional_user-data/data/aws_s3_object_cluster-completed.spec_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -66,15 +66,17 @@ spec:
6666
bindAddress: 0.0.0.0
6767
cloudProvider: external
6868
enableAdmissionPlugins:
69-
- NamespaceLifecycle
70-
- LimitRanger
71-
- ServiceAccount
7269
- DefaultStorageClass
7370
- DefaultTolerationSeconds
71+
- LimitRanger
7472
- MutatingAdmissionWebhook
75-
- ValidatingAdmissionWebhook
73+
- NamespaceLifecycle
7674
- NodeRestriction
7775
- ResourceQuota
76+
- RuntimeClass
77+
- ServiceAccount
78+
- ValidatingAdmissionPolicy
79+
- ValidatingAdmissionWebhook
7880
etcdServers:
7981
- https://127.0.0.1:4001
8082
etcdServersOverrides:

tests/integration/update_cluster/bastionadditional_user-data/data/aws_s3_object_nodeupconfig-master-us-test-1a_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,15 +12,17 @@ APIServerConfig:
1212
bindAddress: 0.0.0.0
1313
cloudProvider: external
1414
enableAdmissionPlugins:
15-
- NamespaceLifecycle
16-
- LimitRanger
17-
- ServiceAccount
1815
- DefaultStorageClass
1916
- DefaultTolerationSeconds
17+
- LimitRanger
2018
- MutatingAdmissionWebhook
21-
- ValidatingAdmissionWebhook
19+
- NamespaceLifecycle
2220
- NodeRestriction
2321
- ResourceQuota
22+
- RuntimeClass
23+
- ServiceAccount
24+
- ValidatingAdmissionPolicy
25+
- ValidatingAdmissionWebhook
2426
etcdServers:
2527
- https://127.0.0.1:4001
2628
etcdServersOverrides:

tests/integration/update_cluster/cluster-autoscaler-priority-expander-custom/data/aws_launch_template_master-us-test-1a.masters.cas-priority-expander-custom.example.com_user_data

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ ClusterName: cas-priority-expander-custom.example.com
130130
ConfigBase: memfs://clusters.example.com/cas-priority-expander-custom.example.com
131131
InstanceGroupName: master-us-test-1a
132132
InstanceGroupRole: ControlPlane
133-
NodeupConfigHash: lqrSzC/HkARFePSIR7bgPBUBlM3HsZGxpFrTx66sn1k=
133+
NodeupConfigHash: V9jtpA9K9rCvzZnOmyUyTwnWRstkveohbN39ZDuT8TA=
134134
135135
__EOF_KUBE_ENV
136136

tests/integration/update_cluster/cluster-autoscaler-priority-expander-custom/data/aws_s3_object_cluster-completed.spec_content

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -88,15 +88,17 @@ spec:
8888
bindAddress: 0.0.0.0
8989
cloudProvider: external
9090
enableAdmissionPlugins:
91-
- NamespaceLifecycle
92-
- LimitRanger
93-
- ServiceAccount
9491
- DefaultStorageClass
9592
- DefaultTolerationSeconds
93+
- LimitRanger
9694
- MutatingAdmissionWebhook
97-
- ValidatingAdmissionWebhook
95+
- NamespaceLifecycle
9896
- NodeRestriction
9997
- ResourceQuota
98+
- RuntimeClass
99+
- ServiceAccount
100+
- ValidatingAdmissionPolicy
101+
- ValidatingAdmissionWebhook
100102
etcdServers:
101103
- https://127.0.0.1:4001
102104
etcdServersOverrides:

0 commit comments

Comments
 (0)