kubernetes/cluster
Taahir Ahmed 9702c6e6e9 GCP config: gke-exec-auth-plugin for ValidatingAdmissionWebhook
This commit adds support for using `gke-exec-auth-plugin` (vTPM-based
certificates for mTLS) for webhooks when calling endpoints matching
`*.googleapis.com`, and integrates this support with
ValidatingAdmissionWebhook.

To enable it, request ValidatingAdmissionWebhook with
`ADMISSION_CONTROL=...,ValidatingAdmissionWebhook,...` (default) and
opt in to `gke-exec-auth-plugin` using `WEBHOOK_GKE_EXEC_AUTH=true`
during the configuration process.

If you don't opt-in, ValidatingAdmissionWebhook will be deployed as
before.

Requesting `WEBHOOK_GKE_EXEC_AUTH=true` will fail if you have not
provided other configuration variables:

  * `EXEC_AUTH_PLUGIN_URL`: controls whether `gke-exec-auth-plugin` is
    downloaded during the installation step.  A prerequisite for
    actually using the plugin.

  * `TOKEN_URL`, `TOKEN_BODY`, and `TOKEN_BODY_UNQUOTED`:
    configuration values used when calling the plugin.  `TOKEN_URL`
    and `TOKEN_BODY` have existing usage. `TOKEN_BODY_UNQUOTED` is a
    new variable that is meant to sidestep the problem of inverting
    `strconv.Quote` in Bash.

The existing configuration process for ImagePolicyWebhook has been
reworked to make it play nicely with ValidatingAdmissionWebhook under
`WEBHOOK_GKE_EXEC_AUTH=true`.

  * It originally placed the ImagePolicyWebhook configuration object
    at the top-level of the file specified by
    `--admission-control-config-file`.  I can't see why this worked;
    it must have been hitting some sort of lucky path through the
    various config file loading mechanisms.  Now, it places its
    configuration in a sub-field of that file, which is shared among
    all admission control plugins.

  * It mounted its various config files read-write.  I reviewed the
    code and couldn't see why it was necessary, so I moved the config
    files into the existing read-only mount at `/etc/srv/kubernetes`.

  * It now checks that all the configuration values it requires have
    been provided.

Co-authored-by: Mike Danese <mikedanese@google.com>
Co-authored-by: Taahir Ahmed <taahm@google.com>
2019-07-22 16:01:37 -07:00
..
addons Revert "feat: cleanup pod critical pod annotations feature" 2019-07-18 13:31:12 +08:00
gce GCP config: gke-exec-auth-plugin for ValidatingAdmissionWebhook 2019-07-22 16:01:37 -07:00
images Update revision number for the image 2019-07-11 21:20:37 -04:00
juju re-home juju related source 2019-04-15 16:19:09 -05:00
kubemark Migrate kubemark to e2e-up/e2e/down scripts. 2019-07-10 11:23:55 +02:00
kubernetes-anywhere
log-dump Avoid truncating long log messages 2019-07-11 10:50:11 -07:00
pre-existing fix some shellcheck failures of cluster/*.sh 2019-04-04 23:20:52 +08:00
skeleton fix issue that e2e script exits due to unbound variables 2018-10-12 17:54:20 -07:00
BUILD Update repo-infra, bazel-skylib, rules_docker, and rules_go dependencies 2019-02-12 17:55:10 -08:00
clientbin.sh fix shellcheck failures of cluster/clientbin.sh 2019-04-26 18:43:33 +08:00
common.sh Revert "override ETCD_SERVER with https instead http when mTLS is enabled" 2019-04-27 06:50:20 +02:00
get-kube-binaries.sh get-kube-binaries: use GCE token to fetch artifacts from GCS 2019-06-12 17:13:59 -07:00
get-kube-local.sh Remove deprecated Kubelet security controls 2019-05-16 13:33:52 -04:00
get-kube.sh fix get-kube.sh 2019-01-16 14:29:17 -08:00
kube-down.sh fix shellcheck failures on kube-down.sh kubeadm.sh get-build.sh 2019-02-14 15:12:08 +08:00
kube-up.sh Remove deprecated centos/local support 2019-04-17 11:03:34 -04:00
kube-util.sh aaa 2019-02-18 17:50:55 -05:00
kubeadm.sh fix shellcheck failures on kube-down.sh kubeadm.sh get-build.sh 2019-02-14 15:12:08 +08:00
kubectl.sh Merge pull request #74449 from xichengliudui/fix190223 2019-02-23 12:52:34 -08:00
OWNERS Promote spiffxp to approver for cluster/ 2019-02-22 09:25:31 -08:00
README.md Cleaning up the cluster directory deprecation notice. 2018-09-05 02:00:05 -07:00
restore-from-backup.sh Remove support for etcd2 from cluster/images/etcd image 2019-07-11 21:20:24 -04:00
test-e2e.sh fix some shellcheck failures of cluster/*.sh 2019-04-04 23:20:52 +08:00
test-network.sh fix shellcheck in test-smoke.sh and test-network.sh 2019-04-19 16:15:10 -04:00
test-smoke.sh fix shellcheck in test-smoke.sh and test-network.sh 2019-04-19 16:15:10 -04:00
update-storage-objects.sh ingress: use networking api group for default storage of ingress 2019-05-01 15:14:11 -04:00
validate-cluster.sh Modify kube-up to support cluster without nodes. 2019-07-01 15:29:45 +02:00

Cluster Configuration

Deprecation Notice: This directory has entered maintenance mode and will not be accepting new providers. Deployments in this directory will continue to be maintained and supported at their current level of support.

The scripts and data in this directory automate creation and configuration of a Kubernetes cluster, including networking, DNS, nodes, and control plane components.

See the getting-started guides for examples of how to use the scripts.

cloudprovider/config-default.sh contains a set of tweakable definitions/parameters for the cluster.

Analytics