@@ -54,18 +54,18 @@ spec:
5454 command:
5555 - ./hyperkube
5656 - kubelet
57- - --network-plugin=cni
58- - --cni-conf-dir=/etc/kubernetes/cni/net.d
59- - --cni-bin-dir=/opt/cni/bin
60- - --pod-manifest-path=/etc/kubernetes/manifests
6157 - --allow-privileged
62- - --hostname-override=$(NODE_NAME)
6358 - --cluster-dns={{ .DNSServiceIP }}
6459 - --cluster-domain=cluster.local
60+ - --cni-conf-dir=/etc/kubernetes/cni/net.d
61+ - --cni-bin-dir=/opt/cni/bin
62+ - --containerized
63+ - --hostname-override=$(NODE_NAME)
6564 - --kubeconfig=/etc/kubernetes/kubeconfig
66- - --require-kubeconfig
6765 - --lock-file=/var/run/lock/kubelet.lock
68- - --containerized
66+ - --network-plugin=cni
67+ - --pod-manifest-path=/etc/kubernetes/manifests
68+ - --require-kubeconfig
6969 env:
7070 - name: NODE_NAME
7171 valueFrom:
@@ -155,25 +155,25 @@ spec:
155155 - /var/lock/api-server.lock
156156 - /hyperkube
157157 - apiserver
158- - --bind-address=0.0.0.0
159- - --secure-port=443
160- - --insecure-port=8080
158+ - --admission-control=NamespaceLifecycle,LimitRanger,ServiceAccount,ResourceQuota
161159 - --advertise-address=$(POD_IP)
162- - --etcd-servers={{ range $i, $e := .EtcdServers }}{{ if $i }},{{end}}{{ $e }}{{end}}
163- - --storage-backend=etcd3
164160 - --allow-privileged=true
165- - --service-cluster-ip-range={{ .ServiceCIDR }}
166- - --admission-control=NamespaceLifecycle,LimitRanger,ServiceAccount,ResourceQuota
167- - --runtime-config=api/all=true
168- - --tls-cert-file=/etc/kubernetes/secrets/apiserver.crt
169- - --tls-private-key-file=/etc/kubernetes/secrets/apiserver.key
161+ - --anonymous-auth=false
162+ - --authorization-mode=RBAC
163+ - --bind-address=0.0.0.0
164+ - --client-ca-file=/etc/kubernetes/secrets/ca.crt
165+ - --cloud-provider={{ .CloudProvider }}
166+ - --etcd-servers={{ range $i, $e := .EtcdServers }}{{ if $i }},{{end}}{{ $e }}{{end}}
167+ - --insecure-port=8080
170168 - --kubelet-client-certificate=/etc/kubernetes/secrets/apiserver.crt
171169 - --kubelet-client-key=/etc/kubernetes/secrets/apiserver.key
170+ - --runtime-config=api/all=true
171+ - --secure-port=443
172172 - --service-account-key-file=/etc/kubernetes/secrets/service-account.pub
173- - --client-ca-file=/etc/kubernetes/secrets/ca.crt
174- - --authorization-mode=RBAC
175- - --cloud-provider={{ .CloudProvider }}
176- - --anonymous-auth=false
173+ - --service-cluster-ip-range={{ .ServiceCIDR }}
174+ - --storage-backend=etcd3
175+ - --tls-cert-file=/etc/kubernetes/secrets/apiserver.crt
176+ - --tls-private-key-file=/etc/kubernetes/secrets/apiserver.key
177177 env:
178178 - name: POD_IP
179179 valueFrom:
@@ -297,12 +297,12 @@ spec:
297297 - ./hyperkube
298298 - controller-manager
299299 - --allocate-node-cidrs=true
300- - --configure- cloud-routes=false
300+ - --cloud-provider={{ .CloudProvider }}
301301 - --cluster-cidr={{ .PodCIDR }}
302+ - --configure-cloud-routes=false
303+ - --leader-elect=true
302304 - --root-ca-file=/etc/kubernetes/secrets/ca.crt
303305 - --service-account-private-key-file=/etc/kubernetes/secrets/service-account.key
304- - --leader-elect=true
305- - --cloud-provider={{ .CloudProvider }}
306306 livenessProbe:
307307 httpGet:
308308 path: /healthz
@@ -398,10 +398,10 @@ spec:
398398 command:
399399 - /hyperkube
400400 - proxy
401+ - --cluster-cidr={{ .PodCIDR }}
402+ - --hostname-override=$(NODE_NAME)
401403 - --kubeconfig=/etc/kubernetes/kubeconfig
402404 - --proxy-mode=iptables
403- - --hostname-override=$(NODE_NAME)
404- - --cluster-cidr={{ .PodCIDR }}
405405 env:
406406 - name: NODE_NAME
407407 valueFrom:
0 commit comments