Commit Graph

9822 Commits

Author SHA1 Message Date
Jeremy Edwards
3cb4f3e1bf GCE Windows: Upgrade to fluent-bit 1.7.7, 1.7.6 had a major regression. 2021-06-01 16:25:21 +00:00
Kubernetes Prow Robot
bc8acbc43e
Merge pull request #102328 from lentzi90/update-cni-plugins
Update CNI plugins v0.9.1
2021-05-28 10:16:46 -07:00
jornshen
c9fe8ddf68 bump calico to v3.19.1 2021-05-28 10:29:44 +08:00
David Ashpole
3813ed1ef7 fix prometheus-to-sd image for fluentbit 2021-05-27 10:54:10 -07:00
Jakub Sroka
ac17d03e76
Remove set errexit from etcd manifest
There were cases where this caused etcd to crashloop. It seems lesser evil to let migrator fail instead.
2021-05-27 14:25:35 +02:00
Kubernetes Prow Robot
d541872f9a
Merge pull request #102239 from Haleygo/clean-up-AlgorithmProvider-flag-and-pkg
clean up algorithmprovider pkg and remove scheduler deprecated algorithm-provider flag
2021-05-27 00:54:23 -07:00
Lennart Jern
507710b50f
Update CNI plugins v0.9.1
ref: https://github.com/containernetworking/plugins/releases/tag/v0.9.1
Signed-off-by: Lennart Jern <lennart.jern@est.tech>
2021-05-26 11:02:04 +03:00
Haleygo
2769e99dba remove scheduler deprecated algorithm-provider flag and clean up algorithmprovider pkg 2021-05-26 13:19:44 +08:00
Marko Mudrinić
80fa50e0d7
Update etcd image revision
Signed-off-by: Marko Mudrinić <mudrinic.mare@gmail.com>
2021-05-25 22:49:20 +02:00
Marko Mudrinić
33fe4bb076
Update debian-base to buster-v1.7.0
Signed-off-by: Marko Mudrinić <mudrinic.mare@gmail.com>
2021-05-25 22:49:03 +02:00
Kubernetes Prow Robot
fd82c69957
Merge pull request #102277 from serathius/etcd-image
Update etcd makefile to build v3.5.0-beta.3 image
2021-05-25 13:46:54 -07:00
Marek Siarkowicz
e862421c2b Update etcd makefile to build v3.5.0-beta.3 image 2021-05-25 15:37:22 +02:00
Sascha Grunert
b167fc24d7
Update pause image to v3.5
Update dependencies and the test images to use pause 3.5. We also
provide a changelog entry for the new container image version.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2021-05-25 09:04:46 +02:00
Kubernetes Prow Robot
b876623070
Merge pull request #102264 from jeremyje/fb176
Upgrade Fluent-Bit 1.7.6.
2021-05-24 21:49:29 -07:00
Kubernetes Prow Robot
06d44d2f42
Merge pull request #101168 from mikedanese/warning
add a warning about the filter table
2021-05-24 21:48:40 -07:00
walter
13ab65d356 Upgrade konnectivity-client for GRPC connection fixes
The v0.0.19 Konnectivity client includes several
significant fixes to prevent the GRPC tunnel between
the KAS and the APIServer Network Proxy from becoming
blocked/wedged.
Importantly it picks up the fix for kubernetes-sigs/apiserver-network-proxy#167.
We believe this will also fix many of the failures currently seen on
https://testgrid.k8s.io/sig-api-machinery-network-proxy#ci-kubernetes-e2e-gci-gce-network-proxy-grpc&width=5.
2021-05-24 14:53:30 -07:00
Kubernetes Prow Robot
ccbb7dbe54
Merge pull request #102070 from bskiba/master
Update addon resizer to 1.8.13
2021-05-24 13:38:41 -07:00
Kubernetes Prow Robot
0d46e728dd
Merge pull request #101486 from dashpole/updates_images
Update event-exporter and prometheus-to-sd versions in cluster addons
2021-05-24 13:38:32 -07:00
Jeremy Edwards
54f3eb42e9 Upgrade Fluent-Bit 1.7.6. 2021-05-24 19:51:00 +00:00
Kubernetes Prow Robot
77937b1e8e
Merge pull request #101628 from bobbypage/addon-termination-handler
Remove node termination handler addon
2021-05-24 11:31:39 -07:00
Beata Lach (Skiba)
7d2e6d7ba9 Update addon resizer to 1.8.13
Needed to fix https://github.com/kubernetes/autoscaler/issues/3567
2021-05-24 18:58:08 +02:00
Kubernetes Prow Robot
d7903669c4
Merge pull request #96299 from ggriffiths/snapshot_controller_metrics_e2e_tests
Add Snapshot Controller e2e metric tests
2021-05-23 03:33:37 -07:00
Kubernetes Prow Robot
fb3273774a
Merge pull request #99178 from wilsonehusin/distroless-conformance
Use distroless to build Conformance image
2021-05-21 13:32:11 -07:00
Grant Griffiths
564e531aa7 Add Snapshot Controller e2e metric tests
Signed-off-by: Grant Griffiths <ggriffiths@purestorage.com>
2021-05-20 23:29:23 -07:00
Kubernetes Prow Robot
3cc0ca0988
Merge pull request #102129 from SataQiu/clean-critical-pod-annotation
Cleanup useless 'scheduler.alpha.kubernetes.io/critical-pod' annotation
2021-05-19 15:25:31 -07:00
Kubernetes Prow Robot
8c0d06aad8
Merge pull request #101869 from olagacek/master
Set poll period of metrics server nanny to 30s
2021-05-19 11:14:51 -07:00
SataQiu
ff18e391e9 cleanup useless 'scheduler.alpha.kubernetes.io/critical-pod' annotation 2021-05-19 17:46:35 +08:00
Kubernetes Prow Robot
e830610854
Merge pull request #101539 from jeremyje/installnpd
Install Node Problem Detector on GCE Windows nodes
2021-05-18 20:16:50 -07:00
Kubernetes Prow Robot
75ec50bc10
Merge pull request #102024 from jeremyje/upgradefb
GCE Windows: Fix Fluent-bit crashloop on Windows Event Log Ingestion
2021-05-18 19:14:50 -07:00
Jeremy Edwards
09f9537338 Install Node Problem Detector on GCE Windows nodes 2021-05-15 16:14:17 +00:00
Geon-Ju Kim
181485212b Remove unnecessary quotes from get-kube scripts 2021-05-15 13:27:09 +09:00
Jeremy Edwards
2f87f280fe GCE Windows: Upgrade to fluent-bit 1.7.5 2021-05-14 21:23:30 +00:00
André Bauer
ccedb1cd64 remove kibana system:anonymous rbac
Signed-off-by: André Bauer <monotek23@gmail.com>
2021-05-14 19:10:45 +02:00
Kubernetes Prow Robot
ee9f365c51
Merge pull request #100169 from coffeepac/pc/es-7.10.2
rev ES and allow anonymous access to kibana
2021-05-14 03:58:04 -07:00
Kubernetes Prow Robot
e8cf412e5e
Merge pull request #101881 from vinayakankugoyal/konnectivity
Update konnectivity network proxy server to run as non-root, by defau…
2021-05-13 23:16:04 -07:00
Vinayak Goyal
b951b9349f Update konnectivity network proxy server to run as non-root, by default in kube-up. 2021-05-13 12:35:34 -07:00
David Ashpole
febf9d9366 update event-exporter and prometheus-to-sd versions in cluster addons 2021-05-13 11:40:41 -07:00
Pat Christopher
aba965b559
rev ES and allow anonymous access to kibana 2021-05-12 19:23:04 -07:00
Avritt Rohwer
0a5a697882 Fix bug in retry-forever usage.
- Push retry-forever wrapping to curl invocations.
- Collect curl retry flags into a single variable.
- Remove 'sudo: false' in master.yaml, is unnecessary and breaks older
  cloud-init versions.
- Change log-error status reason to be more accurate.
- Fix the some 'python' invocations to 'python3'.
2021-05-12 09:22:20 -07:00
Kubernetes Prow Robot
1bd00776b5
Merge pull request #101874 from tallclair/owners
Remove tallclair for gce owners
2021-05-10 13:49:48 -07:00
Kubernetes Prow Robot
7563d3092e
Merge pull request #96216 from knight42/refactor/disable-insecure-port-in-ctrler-mgr
refactor: disable insecure serving in controller-manager
2021-05-10 13:49:36 -07:00
Tim Allclair
9d349b6d21 Remove tallclair for gce owners 2021-05-10 10:21:17 -07:00
olagacek
a492762995
Set poll period of metrics server nanny to 30s
Set poll period of fetching changes from k8s api of metrics server nanny to 30s. 
This will enable faster scaling of metrics server
2021-05-10 15:59:31 +02:00
Kubernetes Prow Robot
8ddabd0da5
Merge pull request #101810 from caseydavenport/casey-fix-calico-crds
Fix improperly formatted Calico CRD files
2021-05-07 21:29:29 -07:00
Casey Davenport
e22773bc30 Fix improperly formatted Calico CRD files 2021-05-07 13:48:43 -07:00
Stephen Augustus
5b530da51f [go1.16] Update to go1.16.4
Signed-off-by: Stephen Augustus <foo@auggie.dev>
2021-05-07 15:47:54 -04:00
Kubernetes Prow Robot
8b1c82a34c
Merge pull request #101772 from swetharepakula/bump-glbc-image
Update glbc image to v1.12.0
2021-05-06 22:05:02 -07:00
Kubernetes Prow Robot
ca0c04e4d3
Merge pull request #101164 from vinayakankugoyal/apiservernonroot
Run control-plane as non root in kube-up.
2021-05-06 17:33:14 -07:00
Swetha Repakula
8c8db0d8e9 Update glbc image to v1.12.0
- glbc now uses networking.k8s.io/v1 Ingress
2021-05-06 15:20:05 -07:00
Kubernetes Prow Robot
1f3fd1cb80
Merge pull request #101751 from vinayakankugoyal/sshproxy
Recursive chown the /etc/srv/sshproxy if kube-apiserver is running as…
2021-05-06 15:15:51 -07:00
Kubernetes Prow Robot
8955f55fcf
Merge pull request #101678 from vinayakankugoyal/goodbye-basicauth
Remove remnants of basic auth from cluster bootstrap.
2021-05-06 14:14:14 -07:00
Vinayak Goyal
6aa495ddc6 Revert - Recursive chown the /etc/srv/sshproxy if kube-apiserver is running as non root. This way if a key already exists we will be able to read it. 2021-05-06 14:02:53 -07:00
Wilson E. Husin
a893521948 Add deadline for deprecation 2021-05-06 11:44:59 -07:00
pacoxu
6d86fc6a15 removed deprecated apiextensions.k8s.io/v1beta1; use extension v1.
Signed-off-by: pacoxu <paco.xu@daocloud.io>
2021-05-06 11:27:58 +08:00
Kubernetes Prow Robot
add13090e2
Merge pull request #101732 from spencer-p/master
Promote kube-addon-manager to v9.1.5
2021-05-05 18:49:17 -07:00
Vinayak Goyal
487583bd0a Recursive chown the /etc/srv/sshproxy if kube-apiserver is running as non root. This way if a key already exists we will be able to read it. 2021-05-05 15:23:04 -07:00
Vinayak Goyal
406ceae991 Recursive chown the /etc/srv/sshproxy if kube-apiserver is running as non root. This way if a key already exists we will be able to read it. 2021-05-05 14:49:59 -07:00
Vinayak Goyal
5d8c89b164 Run control-plane as non root in kube-up. 2021-05-05 14:46:28 -07:00
Jeremy Edwards
daa5be1d01 GCE Windows: Do not install docker when containerd CRI is selected. 2021-05-05 21:06:33 +00:00
Kubernetes Prow Robot
7d176851f2
Merge pull request #100612 from pacoxu/patch-8
kubeadm: upgrade etcd to 3.4.13-3
2021-05-05 07:11:27 -07:00
Spencer Peterson
a119b767d0 Promote kube-addon-manager to v9.1.5
Change-Id: Iffebad61634831b0c34eb54517a2543c75c55d68
2021-05-04 12:14:52 -07:00
David Porter
dac06aefb0 Revert "Revert "cluster: Use python3 everywhere""
This reverts commit 7038338e0f.
2021-05-03 21:43:15 -07:00
Jian Zeng
e481d99965
refactor: disable insecure serving in controller-manager
Now the following flags have no effect and would be removed in v1.24:
* `--port`
* `--address`

The insecure port flags `--port` may only be set to 0 now.

Signed-off-by: Jian Zeng <zengjian.zj@bytedance.com>
2021-05-03 00:01:49 +08:00
Kubernetes Prow Robot
c5b900b69c
Merge pull request #97399 from davidxia/comment-typo
Fix typo in comment
2021-05-01 04:57:59 -07:00
Vinayak Goyal
b87762966d Remove remnants of basic auth from cluster bootstrap. 2021-04-30 11:23:14 -07:00
Kubernetes Prow Robot
f235adc4d2
Merge pull request #101621 from jeremyje/fixfb
GCE Windows: mkdir -p fluent-bit pos-files directory.
2021-04-30 10:24:39 -07:00
Daniel Kłobuszewski
447b0ca705 Bump metrics server to use 0.4.4 image. 2021-04-30 09:13:39 +02:00
Kubernetes Prow Robot
663b425e21
Merge pull request #101417 from pacoxu/node-local-dns-docs
update node local dns readme for ipv6 and 1.18 GA
2021-04-29 18:10:19 -07:00
Kubernetes Prow Robot
551ef71b64
Merge pull request #100256 from sarandia/metricsserverarch
bump metrics server version to v0.3.7 and make it multi-arch
2021-04-29 18:09:58 -07:00
Jeremy Edwards
5c713379a0 GCE Windows: mkdir -p fluent-bit pos-files directory. 2021-04-29 22:52:38 +00:00
David Porter
e02ff0687e Remove node termination handler addon 2021-04-29 14:42:23 -07:00
Kubernetes Prow Robot
06eeec737a
Merge pull request #101439 from prameshj/update-kubedns
Update to using kubedns 1.17.3 image.
2021-04-29 09:01:04 -07:00
Kubernetes Prow Robot
f631c0e520
Merge pull request #101271 from jeremyje/fixfb
Fix fluent-bit configuration for GCE Windows.
2021-04-27 19:06:49 -07:00
Ziyuan Chen
7a5508c0a7 bump metrics server version to v0.3.7 and make it multi-arch
Bumping the metrics-server version to v0.3.7. In this version,
metrics-server started building multi-arch images. To properly support
non-amd64 nodes, we should bump the version and remove the -amd64 in the
image path. (https://github.com/kubernetes-sigs/metrics-server/pull/492)

```release-note
metrics-server now uses v0.3.7 and supports multi-arch Kubernetes nodes.
```
2021-04-27 20:48:21 +00:00
Kubernetes Prow Robot
2f753ec4c8
Merge pull request #101473 from pacoxu/revert-101437-python3
Revert "cluster: Use python3 everywhere"
2021-04-26 12:54:37 -07:00
Paco Xu
7038338e0f
Revert "cluster: Use python3 everywhere" 2021-04-26 11:21:44 +08:00
songxiao-wang87
4f254674fa Making a run test.
Signed-off-by: songxiao-wang87 <wang.xiaosong23@zte.com.cn>
2021-04-25 10:46:18 +08:00
Pavithra Ramesh
2c2dd6b072 Update to using kubedns 1.17.3 image. 2021-04-23 14:59:38 -07:00
David Porter
3f87f4f278 Use python3 everywhere 2021-04-23 14:33:58 -07:00
pacoxu
58114e293f update node local dns readme for ipv6 and 1.18 GA 2021-04-23 17:04:55 +08:00
Kubernetes Prow Robot
ae35c6f10c
Merge pull request #101255 from basantsa1989/stack-type
Adding stack-type to gce cloud config (to be used for dual stack in legacy-cloud-providers gce code)
2021-04-22 15:55:28 -07:00
Jeremy Edwards
e62301c87d Fix fluent-bit configuration for GCE Windows. 2021-04-22 20:04:54 +00:00
Kubernetes Prow Robot
6aa683e9cf
Merge pull request #100639 from zshihang/proxy
dnat to 169.254.169.252 for metadata server traffic
2021-04-21 11:15:51 -07:00
Kubernetes Prow Robot
3cc043cfd2
Merge pull request #101262 from spencer-p/master
Upgrade addon-manager baseimage to debian-base v1.0.1
2021-04-20 20:36:22 -07:00
Kubernetes Prow Robot
41505f7109
Merge pull request #101176 from jkh52/master
kube-master-installation: improve systemd cross-unit robustness.
2021-04-20 00:42:45 -07:00
Spencer Peterson
530072a38f Addon-manager baseimage upgrade debian-base v1.0.1
The previous base image, debian-base:v1.0.0, is affected by
CVE-2017-14062. This change upgrades to the most recent Debian stretch
image from the following command:

```
$ gcloud container images list-tags k8s.gcr.io/debian-base-amd64
DIGEST        TAGS    TIMESTAMP
7e9f2f88b813  v1.0.1  2020-02-18T13:18:50
d7be39e143d4  v2.0.0  2019-11-01T13:14:18
5f25d97ece90  v1.0.0  2019-03-25T10:59:09
dddca919baec  1.0.0   2019-03-25T09:43:09
```

This marks kube-addon-manager version 9.1.5.

Change-Id: I02321a781fb19dd33c0a19671b56c0b12d9b52fd
2021-04-19 20:36:44 -07:00
Kubernetes Prow Robot
46b0ad1327
Merge pull request #101207 from vinayakankugoyal/sshproxy
If kube-apiserver is running as non-root then set the permissions of …
2021-04-19 17:24:33 -07:00
Joseph Anttila Hall
05bcc72dc2 kube-master-installation: reboot on failure.
Also some minor reliability tweaks.
2021-04-19 17:16:21 -07:00
Vinayak Goyal
94e34da471 If kube-apiserver is running as non-root then set the permissions of /etc/srv/sshproxy accordingly. 2021-04-19 13:16:06 -07:00
Basant Amarkhed
e15d811652 Adding stack-type to cloud config (to be used for dual stack in legacy-cloud-providers code) 2021-04-19 19:06:55 +00:00
Shihang Zhang
297ad30610 dnat to 169.254.169.252 for metadata server traffic 2021-04-19 10:47:51 -07:00
Kubernetes Prow Robot
4925cb66c9
Merge pull request #101238 from loburm/move_deprecated
Add required fields to fluentd-gcp-scaler-policy CRD.
2021-04-19 08:02:36 -07:00
Marian Lobur
41e39dd1fa Add required fields to fluentd-gcp-scaler-policy CRD. 2021-04-19 16:01:46 +02:00
Stephen Augustus
fac97f8a9b [go1.16] Update to go1.16.3
Signed-off-by: Stephen Augustus <foo@auggie.dev>
2021-04-16 19:56:51 -04:00
Kubernetes Prow Robot
3ed71cf190
Merge pull request #100976 from jindijamie/master
releng: Update debian-base and debian-iptables to buster-v1.6.0 to patch base image CVEs
2021-04-16 12:56:34 -07:00
Kubernetes Prow Robot
28c877dcb6
Merge pull request #101043 from benhxy/tls-2
Use GKE specific configuration for kubeconfig file generation
2021-04-16 11:54:51 -07:00
Kubernetes Prow Robot
7ecd93ea1e
Merge pull request #100764 from benhxy/tls
Use GKE specific configuration for kube-apiserver SNI cert
2021-04-15 19:52:22 -07:00
Jeremy Edwards
c22f001a1b GCE Windows: Use authenticated HTTP GET against GCS if VM has cloud-platform scope. 2021-04-15 23:30:19 +00:00
Mike Danese
ba3fc65072 add a warning about the filter table 2021-04-15 16:22:28 -07:00
Kubernetes Prow Robot
0d0d1889ed
Merge pull request #100930 from swetharepakula/update-glbc-image
Update glbc image in glbc addon
2021-04-15 12:59:01 -07:00