Brad Davidson
c86147c467
Use existing server-CA and hash if available
...
Also wraps errors along the cluster prepare path to improve tracability.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 244bfd0c35 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-03-07 14:46:05 -08:00
Brad Davidson
6f2e1a6d38
Serve HTTP bootstrap data from datastore before disk
...
Fixes issue where CA rotation would fail on servers with join URL set due to using old data from disk on other server
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 53fcadc028 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-03-07 14:46:05 -08:00
Brad Davidson
4420e6560b
Move CR APIs to k3s-io/api
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 5894af30ff )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-03-07 14:46:05 -08:00
Brad Davidson
0123137a67
Add etcd snapshot metrics
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 6199b79f4b )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-03-07 14:46:05 -08:00
Roberto Bonafiglia
2405ceaf24
Revert "Add ability to pass configuration options to flannel backend"
...
This reverts commit 8643576985 .
Signed-off-by: Roberto Bonafiglia <roberto.bonafiglia@suse.com >
2025-03-05 08:06:13 +01:00
Brad Davidson
4b44c0b511
Fix missing migration for containerd registry.configs plugin namespace
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-20 18:07:17 -08:00
Brad Davidson
d02b1bd8e1
Render CNI dir config whenever vars are set
...
RKE2 on Windows sets CNI bin dirs in node config even though embedded flannel is disabled (NoFlannel=true). We need to gate rendering this config on the vars being, set NOT on NoFlannel being false.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-20 18:07:17 -08:00
Brad Davidson
3b90bf6532
Update containerd config schema to version 3
...
Ref: https://github.com/containerd/containerd/blob/release/2.0/docs/cri/config.md
Since this is a breaking change, add support for a new v3 template file. If no v3 template is present, fall back to checking for the legacy v2 template and render the old structure.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit bc45972398 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
8a3086bd11
Upgrade containerd to v2.0.2
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 124e46bccf )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
37ebcd9351
Bump traefik to 3.3.2
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 77cf99aa5f )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
7794369e73
Skip netpol startup on windows instead of panicing
...
Netpol startup is skipped with a warning on linux if ipset support is missing, we should do the same on windows
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 96c2dd3865 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
fd1d05928b
Add linux nodeSelector to local-storage and metrics-server
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 99f4f5ad12 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
cb92e8a523
Fix default pause image on windows
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 85987ac23f )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
408326a900
Add missing windows runtime type definition
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 50326c8bca )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
7d46ef10e0
Fix windows path quoting/escaping in containerd config template
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 8aa412ed66 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
4aefe795fa
Fix containerd hosts.toml path on windows
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit bf97b8facc )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
9b9e7b9b74
Fix permissions checks on windows
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 838d68777f )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
f9ccb7281a
Replace hardcoded unix-style paths in test
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit b2418ba354 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
78adfd50a1
Remove broken unused windows test
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 8f85ee3c60 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
2ef0bcb84d
Make etcd test linux-only
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 4cacf6e1c0 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
0efd5d7758
Fix linux-specific clientaccess test
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 0d15457c77 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
42277f292c
Consolidate linux and windows containerd config templates
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 85b3775071 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
6448057e9f
Add support for AWS shared credentials file
...
Also adds a CLI flag and fields for session token, which must be passed
alongside the access key and secret when using temporary credentials.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 0d028a2283 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
github-actions[bot]
0705404f4a
Bump Local Path Provisioner version ( #11657 )
...
* chore: Bump Local Path Provisioner version
Made with ❤️ ️ by updatecli
* chore: Bump Local Path Provisioner version
Made with ❤️ ️ by updatecli
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
(cherry picked from commit 28300ea154 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
b1b140ea39
Update p2p boostrap helpers for Spegel v0.0.30
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 95700aa6b3 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Brad Davidson
3952d1b3a9
Disable s3 transport transparent compression/decompression
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit fd8348324d )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Derek Nola
6fe2bea9de
chore: Bump klipper-lb and klipper-helm ( #11595 )
...
* Bump klipper-lb to v0.4.10
Bump klipper-helm to v0.9.4
Signed-off-by: Derek Nola <derek.nola@suse.com >
* Bump helm-controller
Signed-off-by: Derek Nola <derek.nola@suse.com >
---------
Signed-off-by: Derek Nola <derek.nola@suse.com >
(cherry picked from commit 08c30f5ae6 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
Maja Bojarska
0c593777a1
Align etcd-snapshot-dir default path description
...
The effective snapshot dir is "${data-dir}/server/db/snapshots". The
server segment is missing in the CLI-reported default path, potentially
misleading the user about the actual default snapshot destination.
Signed-off-by: Maja Bojarska <majabojarska98@gmail.com >
(cherry picked from commit 646e3135bc )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-02-10 10:16:03 -08:00
manuelbuil
0deab52cd9
Correct the k3s token command help
...
Signed-off-by: manuelbuil <mbuil@suse.com >
2025-01-30 12:08:45 +01:00
Brad Davidson
6a322f1227
Update tests
...
Also add an ordinal to subtests so its easier to figure out which one is failing
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-23 19:18:50 -08:00
Brad Davidson
4070db6b6a
Remove local restriction for deferred node password validation
...
Restricting deferred node password validation to only requests from the local node is not possible without breaking split-role cluster cold start. There are too many cases where node password secrets may not yet be available due to the apiserver not being up.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-23 19:18:50 -08:00
Brad Davidson
9548f9b6c9
Fix local password validation when bind-address is set
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit d0ea741b13 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-15 14:41:15 -08:00
Derek Nola
f31b3d3780
Add "k3s certificate check" clause for better test coverage ( #11485 )
...
* Add "k3s certificate check" clause for better test coverage
Signed-off-by: Derek Nola <derek.nola@suse.com >
* Add table support to cert check
Signed-off-by: Derek Nola <derek.nola@suse.com >
---------
Signed-off-by: Derek Nola <derek.nola@suse.com >
2025-01-13 12:16:36 -08:00
Vitor Savian
39f4cbb336
Add auto import images for containerd image store
...
* Add auto import images for containerd image store
* Add auto import images
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Fix EOF error log when importing tarball files
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Delaying queue
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Add parse for images
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
---------
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
2025-01-11 01:59:00 -03:00
Brad Davidson
9d311068fc
Improve flannel RBAC changes
...
Only wait for k3s-controller RBAC when AuthorizeNodeWithSelectors blocks kubelet from listing nodes
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
muicoder
a02dd637eb
Update Traefik to v2.11.18
...
#11501
Signed-off-by: muicoder <muicoder@gmail.com >
(cherry picked from commit 0144d9b749 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
dc7ff9fcdc
Add tests for supervisor request handlers
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit f345697c0a )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
fbb971c442
Replace *core.Factory with CoreFactory interface
...
Make this field an interface instead of pointer to allow mocking. Not sure why wrangler has a type that returns an interface instead of just making it an interface itself. Wrangler in general is hard to mock for testing.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit e6327652f0 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
4c2fd2e379
Move additional core/v1 mocks into tests package
...
Convert nodepassword tests to use shared mocks
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit c20c06373a )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
5cd9c9bea8
Move core/v1 mock into tests package for reuse
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 8f8cfb56b5 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
52480ca1d5
Add test for join existing cluster
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit f8271d8506 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
5b8f9aba52
Handle cluster join as create if we're the only member
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 365372441b )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
11b9afb167
Add client-side certificate generation support
...
Clients now generate keys client-side and send CSRs. If the server is down-level and sends a cert+key instead of just responding with a cert signed with the client's public key, we use the key from the server instead.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit caeebc52b7 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
46a60cc4ab
Remove unused Certificate field from Node struct
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 5b1d57f7b9 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Brad Davidson
e9f02cd267
Move request handlers out of server package
...
The servers package, and router.go in particular, had become quite
large. Address this by moving some things out to separate packages:
* http request handlers all move to pkg/server/handlers.
* node password bootstrap auth handler goes into pkg/nodepassword with
the other nodepassword code.
While we're at it, also be more consistent about calling variables that
hold a config.Control struct or reference `control` instead of `config` or `server`.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
(cherry picked from commit 2e4e7cf2c1 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
muicoder
50036935cf
Update Traefik to v2.11.17 ( #11502 )
...
#11501
Signed-off-by: muicoder <muicoder@gmail.com >
(cherry picked from commit 056cee8290 )
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-01-10 17:18:12 -08:00
Hussein Galal
cca8facaa3
Load kernel modules for nft in agent setup ( #11527 )
...
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
2025-01-07 19:13:09 +02:00
Brad Davidson
6381ae93e7
Switch to using kubelet config files instead of CLI args
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2024-12-20 14:41:40 -08:00
Hussein Galal
763188d642
V1.32.0+k3s1 ( #11478 )
...
* Update libraries and codegen for k8s 1.32
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
* Fixes for 1.32
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
* Disable tests with down-rev agents
These are broken by AuthorizeNodeWithSelectors being on by default. All
agents must be upgraded to v1.32 or newer to work properly, until we
backport RBAC changes to older branches.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
---------
Signed-off-by: galal-hussein <hussein.galal.ahmed.11@gmail.com >
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
Co-authored-by: Brad Davidson <brad.davidson@rancher.com >
2024-12-20 23:17:14 +02:00
Reinhard Nägele
124be7472b
Update coredns to 1.12.0 ( #11387 )
...
* Update to coredns 1.12.0
Signed-off-by: Reinhard Nägele <unguiculus@gmail.com >
2024-12-10 10:09:27 -08:00