chore: Update manifests after change
This commit is contained in:
@@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: "cilium.io/v2alpha1"
|
||||||
|
kind: CiliumL2AnnouncementPolicy
|
||||||
|
metadata:
|
||||||
|
name: node-gateway-l2-policy
|
||||||
|
namespace: kube-system
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: node-gateway-l2-policy
|
||||||
|
app.kubernetes.io/instance: cilium
|
||||||
|
app.kubernetes.io/part-of: cilium
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
matchLabels:
|
||||||
|
kubernetes.io/hostname: talos-ix7-xku
|
||||||
|
interfaces:
|
||||||
|
- "^enp.*"
|
||||||
|
externalIPs: true
|
||||||
|
loadBalancerIPs: true
|
||||||
@@ -9,7 +9,5 @@ metadata:
|
|||||||
app.kubernetes.io/part-of: cilium
|
app.kubernetes.io/part-of: cilium
|
||||||
spec:
|
spec:
|
||||||
blocks:
|
blocks:
|
||||||
- start: "10.232.1.21"
|
|
||||||
stop: "10.232.1.23"
|
|
||||||
- start: "10.232.2.21"
|
- start: "10.232.2.21"
|
||||||
stop: "10.232.2.23"
|
stop: "10.232.2.23"
|
||||||
|
|||||||
@@ -33,6 +33,16 @@ rules:
|
|||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- coordination.k8s.io
|
||||||
|
resources:
|
||||||
|
- leases
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- update
|
||||||
|
- list
|
||||||
|
- delete
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- apiextensions.k8s.io
|
- apiextensions.k8s.io
|
||||||
resources:
|
resources:
|
||||||
|
|||||||
@@ -71,7 +71,7 @@ data:
|
|||||||
iptables-random-fully: "false"
|
iptables-random-fully: "false"
|
||||||
auto-direct-node-routes: "false"
|
auto-direct-node-routes: "false"
|
||||||
direct-routing-skip-unreachable: "false"
|
direct-routing-skip-unreachable: "false"
|
||||||
devices: "end0 enp6s0"
|
devices: "^(enp|end|eth)[0-9a-z]*"
|
||||||
kube-proxy-replacement: "true"
|
kube-proxy-replacement: "true"
|
||||||
kube-proxy-replacement-healthz-bind-address: ""
|
kube-proxy-replacement-healthz-bind-address: ""
|
||||||
bpf-lb-sock: "true"
|
bpf-lb-sock: "true"
|
||||||
@@ -115,6 +115,7 @@ data:
|
|||||||
vtep-mask: ""
|
vtep-mask: ""
|
||||||
vtep-mac: ""
|
vtep-mac: ""
|
||||||
enable-k8s-endpoint-slice: "true"
|
enable-k8s-endpoint-slice: "true"
|
||||||
|
enable-l2-announcements: "true"
|
||||||
procfs: "/host/proc"
|
procfs: "/host/proc"
|
||||||
bpf-root: "/sys/fs/bpf"
|
bpf-root: "/sys/fs/bpf"
|
||||||
cgroup-root: "/sys/fs/cgroup"
|
cgroup-root: "/sys/fs/cgroup"
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ spec:
|
|||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
annotations:
|
annotations:
|
||||||
cilium.io/cilium-configmap-checksum: "9f67de7f01bb2bf87c953f3042be7aa5cb195bedc250957e485cd90aeb6c80ea"
|
cilium.io/cilium-configmap-checksum: "97776673c7ef207c96f208950b68ee9a8c427feec66a73ba0455eb366844f835"
|
||||||
kubectl.kubernetes.io/default-container: cilium-agent
|
kubectl.kubernetes.io/default-container: cilium-agent
|
||||||
labels:
|
labels:
|
||||||
k8s-app: cilium
|
k8s-app: cilium
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ spec:
|
|||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
annotations:
|
annotations:
|
||||||
cilium.io/cilium-configmap-checksum: "9f67de7f01bb2bf87c953f3042be7aa5cb195bedc250957e485cd90aeb6c80ea"
|
cilium.io/cilium-configmap-checksum: "97776673c7ef207c96f208950b68ee9a8c427feec66a73ba0455eb366844f835"
|
||||||
labels:
|
labels:
|
||||||
io.cilium/app: operator
|
io.cilium/app: operator
|
||||||
name: cilium-operator
|
name: cilium-operator
|
||||||
|
|||||||
@@ -0,0 +1,46 @@
|
|||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: Gateway
|
||||||
|
metadata:
|
||||||
|
name: cilium-tls-gateway
|
||||||
|
namespace: kube-system
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: cilium-tls-gateway
|
||||||
|
app.kubernetes.io/instance: cilium
|
||||||
|
app.kubernetes.io/part-of: cilium
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/cluster-issuer: letsencrypt-issuer
|
||||||
|
io.cilium/lb-ipam-ips: "10.232.1.23"
|
||||||
|
spec:
|
||||||
|
addresses:
|
||||||
|
- type: IPAddress
|
||||||
|
value: 10.232.1.23
|
||||||
|
gatewayClassName: cilium
|
||||||
|
listeners:
|
||||||
|
- allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: All
|
||||||
|
hostname: '*.alexlebens.net'
|
||||||
|
name: https
|
||||||
|
port: 443
|
||||||
|
protocol: HTTPS
|
||||||
|
tls:
|
||||||
|
certificateRefs:
|
||||||
|
- group: ''
|
||||||
|
kind: Secret
|
||||||
|
name: https-gateway-cert
|
||||||
|
namespace: kube-system
|
||||||
|
mode: Terminate
|
||||||
|
- allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: All
|
||||||
|
hostname: 'alexlebens.net'
|
||||||
|
name: https-domain
|
||||||
|
port: 443
|
||||||
|
protocol: HTTPS
|
||||||
|
tls:
|
||||||
|
certificateRefs:
|
||||||
|
- group: ''
|
||||||
|
kind: Secret
|
||||||
|
name: https-gateway-cert
|
||||||
|
namespace: kube-system
|
||||||
|
mode: Terminate
|
||||||
Reference in New Issue
Block a user