Derek Nola
f11f0748e9
Enable logging on all subcommands ( #4921 ) ( #4932 )
...
Signed-off-by: Derek Nola <derek.nola@suse.com >
2022-01-14 09:21:22 -08:00
Brad Davidson
be3c430985
Move ClusterResetRestore handling ControlConfig setup
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2022-01-12 12:09:55 -08:00
Brad Davidson
4b3f5be45d
Fix use of agent creds for secrets-encrypt and config validate
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2022-01-06 14:17:27 -08:00
Hussein Galal
7e9ac115f4
[Release-1.21] Close agentReady channel only in k3s ( #4794 )
...
* Close agentReady channel only in k3s
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* codespell check
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2021-12-21 20:29:09 +02:00
Hussein Galal
0d065c8491
Fix snapshot restoration on fresh nodes ( #4737 )
...
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
Signed-off-by: Brian Downs <brian.downs@gmail.com >
2021-12-13 18:13:59 -07:00
Hussein Galal
3024462196
Add validation to certificate rotation ( #4697 )
...
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2021-12-09 02:45:45 +02:00
Derek Nola
1055837e4f
Backport secrets-encrypte command ( #4658 )
...
Signed-off-by: Derek Nola <derek.nola@suse.com >
2021-12-07 17:21:10 -08:00
Hussein Galal
7b62900836
[Release-1.21] Add cert rotation command ( #4632 )
...
* Add cert rotation command (#4495 )
* Add cert rotation command
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* add function to check for dynamic listener file
Signed-off-by: Brian Downs <brian.downs@gmail.com >
* Add dynamiclistener cert rotation support
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fixes to the cert rotation
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fix ci tests
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fixes to certificate rotation command
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* more fixes
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
Co-authored-by: Brian Downs <brian.downs@gmail.com >
* Upgrade dynamic listener
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* go mod tidy
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
Co-authored-by: Brian Downs <brian.downs@gmail.com >
2021-12-06 19:45:21 +02:00
Chris Kim
a622dd57f3
[release-1.21] etcd snapshot functionality enhancements ( #4606 )
...
* etcd snapshot functionality enhancements (#4453 )
Signed-off-by: Chris Kim <oats87g@gmail.com >
* feat: add option to disable s3 over https
Signed-off-by: Chris Kim <oats87g@gmail.com >
* Prevent snapshot commands from creating empty snapshot directory (#3783 )
Signed-off-by: Chris Kim <oats87g@gmail.com >
Co-authored-by: Devin Buhl <devin.kray@gmail.com >
Co-authored-by: Derek Nola <derek.nola@suse.com >
2021-11-29 13:30:00 -08:00
Hussein Galal
1847a711e7
Fix regression with cluster reset ( #4524 )
...
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2021-11-18 19:21:52 +02:00
Manuel Buil
fd71ed9f4a
Allow svclb pod to enable ipv6 forwarding
...
Signed-off-by: Manuel Buil <mbuil@suse.com >
2021-11-17 19:50:00 +01:00
Manuel Buil
6854470a14
Merge pull request #4503 from manuelbuil/fix_dualStack_bug
...
[Release 1.21] Fix bug in dual-stack
2021-11-16 10:30:04 +01:00
Manuel Buil
7de34a0059
Fix bug in dual-stack
...
We forgot to remove the check to allow dual-stack and flannel
Signed-off-by: Manuel Buil <mbuil@suse.com >
2021-11-16 09:11:56 +01:00
Derek Nola
119b1aeb25
[Release-1.21] etcd-snapshot loading config fails with "flag provided but not defined" ( #4482 )
...
* Match to last After keyword for parser (#4383 )
* Fix to allow etcd-snapshot to use config file with flags that are only used with k3s server. (#4464 )
Signed-off-by: Derek Nola <derek.nola@suse.com >
2021-11-12 11:10:37 -08:00
Chris Kim
334eae119a
[release-1.21] Add etcd extra args support for K3s ( #4471 )
...
* Export cli server flags and etcd restoration functions (#3527 )
* Export cli server flags and etfd restoration functions
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* export S3
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
Signed-off-by: Chris Kim <oats87g@gmail.com >
* Add etcd extra args support for K3s
Signed-off-by: Chris Kim <oats87g@gmail.com >
* Remove integration test
Signed-off-by: Chris Kim <oats87g@gmail.com >
Co-authored-by: Hussein Galal <galal-hussein@users.noreply.github.com >
2021-11-11 20:36:17 -08:00
Brian Downs
864e800896
[Release-1.21] All bootstrap backport ( #4452 )
...
Add ability to reconcile bootstrap data between datastore and disk (#3398 )
2021-11-10 16:20:46 -07:00
Brad Davidson
df033fa248
Fix log/reap reexec
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2021-11-01 14:59:08 -07:00
Brad Davidson
bb50c45a6f
Revert "Backport bootstrap release 1.21 ( #4313 )"
...
This reverts commit
f0ea0a0946
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2021-10-27 14:17:22 -07:00
Brian Downs
f0ea0a0946
Backport bootstrap release 1.21 ( #4313 )
2021-10-25 13:03:21 -07:00
Derek Nola
50fb1ce065
Added configuration input to etcd-snapshot ( #4280 ) ( #4282 )
...
Signed-off-by: dereknola <derek.nola@suse.com >
2021-10-22 13:08:22 -07:00
Brad Davidson
a18c2efb4c
Refactor log and reaper exec to omit MAINPID
...
Using MAINPID breaks systemd's exit detection, as it stops watching the
original pid, but is unable to watch the new pid as it is not a child
of systemd itself. The best we can do is just notify when execing the child
process.
We also need to consolidate forking into a sigle place so that we don't
end up with multiple levels of child processes if both redirecting log
output and reaping child processes.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit dc18ef2e51 )
2021-10-20 14:36:54 -07:00
Brad Davidson
504e249a5e
Add containerd ready channel to delay etcd node join
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 88178ae65e )
2021-10-20 11:06:12 -07:00
Brian Downs
4aa9553978
[Release-1.21] - Add etcd s3 timeout ( #4207 ) ( #4228 )
2021-10-18 10:45:38 -07:00
Hussein Galal
22f7f1c41a
Make sure there are no duplicates in etcd member list ( #4025 ) ( #4213 )
...
* Make sure there are no duplicates in etcd member list
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fix node names with hyphens
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* use full server name for etcd node name
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2021-10-14 23:39:24 +02:00
Derek Nola
3ee5098225
Add "etcd-" prefix to etcd-snapshot commands as aliases ( #4161 ) ( #4171 )
...
* Add "etcd-" prefix to etcd-snapshot commands as alias
Signed-off-by: dereknola <derek.nola@suse.com >
2021-10-07 12:26:36 -07:00
Brad Davidson
69a9f46bce
Don't evacuate the root cgroup when rootless
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2021-10-01 16:19:07 -07:00
Brad Davidson
38ddda587a
Properly handle operation as init process
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2021-09-28 11:33:45 -07:00
dereknola
8c2f7ac41c
Remove experimental from cluster commands
...
Signed-off-by: dereknola <derek.nola@suse.com >
2021-09-17 15:37:45 -07:00
Brad Davidson
a8a6edfb0d
Add missing node name entry to apiserver SAN list
...
Also honor node-ip when adding the node address to the SAN list, instead
of hardcoding the autodetected IP address.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2021-09-01 13:22:50 -07:00
Hussein Galal
656c190629
Reset load balancer state during restoraion ( #3878 )
...
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
Reset load balancer state during restoraion
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2021-08-18 18:59:03 +02:00
Hussein Galal
cc694b1f09
Notify systemd for etcd only node ( #3733 )
...
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2021-07-30 00:41:52 +02:00
Hussein Galal
9859ec7a81
[release-1.21] - Backport Fix storing bootstrap data with empty token string ( #3514 )
...
* Fix storing bootstrap data with empty token string (#3422 )
* Fix storing bootstrap data with empty token string
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* delete node password secret after restoration
fixes to bootstrap key
vendor update
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fix comment
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fix typo
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* more fixes
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fixes
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fixes
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* typos
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* Removing dynamic listener file after restoration
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* go mod tidy
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* fix a runtime core panic
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* update kine
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
* Fix calling delete in kine
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2021-07-13 22:28:38 +02:00
Brian Downs
c3d134a405
prevent snapshot save when snapshots are disabled ( #3475 ) ( #3610 )
...
* prevent snapshot save when snapshots are disabled
2021-07-09 12:09:35 -07:00
Chris Kim
42ab13a869
Update etcd snapshot error message to be more informative when etcd database is not found ( #3592 )
...
Signed-off-by: Chris Kim <oats87g@gmail.com >
2021-07-08 15:01:05 -07:00
Brian Downs
8651d6af5f
Send systemd notifications for both server and agent ( #3430 ) ( #3460 )
...
* update agent to sent systemd notify after everything starts
2021-06-15 12:16:15 -07:00
Brian Downs
69795277be
add retention default and wire in s3 prune
...
Signed-off-by: Brian Downs <brian.downs@gmail.com >
2021-05-19 14:49:44 -07:00
Brian Downs
58649c5e85
add etcd snapshot save subcommand
...
Signed-off-by: Brian Downs <brian.downs@gmail.com >
2021-05-19 14:49:38 -07:00
Brian Downs
6ee28214fa
Add the ability to prune etcd snapshots ( #3310 )
...
* add prune subcommand to force rentention policy enforcement
2021-05-13 13:36:33 -07:00
MonzElmasry
24474c5734
change --disable-apiserver flag
...
Signed-off-by: MonzElmasry <menna.elmasry@rancher.com >
2021-05-13 00:00:11 +02:00
Brian Downs
bcd8b67db4
Add the ability to list etcd snapshots ( #3303 )
...
* add ability to list local and s3 etcd snapshots
2021-05-11 16:59:33 -07:00
Brad Davidson
02a5bee62f
Add system-default-registry support and remove shared code ( #3285 )
...
* Move registries.yaml handling out to rancher/wharfie
* Add system-default-registry support
* Add CLI support for kubelet image credential providers
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2021-05-10 15:58:41 -07:00
Brian Downs
e998cd110d
Add the ability to delete an etcd snapshot locally or from S3 ( #3277 )
...
* Add the ability to delete a given set of etcd snapshots from the CLI for locally stored and S3 store snapshots.
2021-05-07 16:10:04 -07:00
Hussein Galal
f410fc7d1e
Invoke cluster reset function when only reset flag is passed ( #3276 )
...
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2021-05-05 17:40:04 +02:00
Brian Downs
c5ad71ce0b
Collect and Store etcd Snapshots and Metadata ( #3239 )
...
* Add the ability to store local etcd snapshots and etcd snapshots stored in an S3 compatible object store in a ConfigMap.
2021-04-30 18:26:39 -07:00
Brad Davidson
2705431d96
Add support for dual-stack Pod/Service CIDRs and node IP addresses ( #3212 )
...
* Add support for dual-stack cluster/service CIDRs and node addresses
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2021-04-21 15:56:20 -07:00
Brian Downs
80e4baf525
add hidden attribute to disable flags
...
Signed-off-by: Brian Downs <brian.downs@gmail.com >
2021-04-13 14:30:47 -07:00
Brian Downs
4a49b9e40b
delete nocluster file and remove build tag
...
Signed-off-by: Brian Downs <brian.downs@gmail.com >
2021-04-07 12:16:28 -07:00
Brian Downs
3ed9b0a997
remove hidden attribute from cluster flags and related code
...
Signed-off-by: Brian Downs <brian.downs@gmail.com >
2021-04-07 11:36:02 -07:00
Chris Kim
69f96d6225
Define a Controllers and LeaderControllers on the server config ( #3043 )
...
Signed-off-by: Chris Kim <oats87g@gmail.com >
2021-03-11 10:39:00 -08:00
Brad Davidson
7cdfaad6ce
Always use static ports for client load-balancers ( #3026 )
...
* Always use static ports for the load-balancers
This fixes an issue where RKE2 kube-proxy daemonset pods were failing to
communicate with the apiserver when RKE2 was restarted because the
load-balancer used a different port every time it started up.
This also changes the apiserver load-balancer port to be 1 below the
supervisor port instead of 1 above it. This makes the apiserver port
consistent at 6443 across servers and agents on RKE2.
Additional fixes below were required to successfully test and use this change
on etcd-only nodes.
* Actually add lb-server-port flag to CLI
* Fix nil pointer when starting server with --disable-etcd but no --server
* Don't try to use full URI as initial load-balancer endpoint
* Fix etcd load-balancer pool updates
* Update dynamiclistener to fix cert updates on etcd-only nodes
* Handle recursive initial server URL in load balancer
* Don't run the deploy controller on etcd-only nodes
2021-03-06 02:29:57 -08:00