Brad Davidson
d08bf6c9b6
Wire up remotedialer metrics
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-27 13:42:17 -07:00
Brad Davidson
f1c82392d0
Fix etcd join timeout handling
...
Error is deadline exceeded, not cancelled
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-27 13:41:54 -07:00
Brad Davidson
795091a809
Wire up kine metrics
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-27 13:41:16 -07:00
Brad Davidson
068a01351a
Retry CRD creation in case of conflict
...
Also cleans up some of the server.Context factory creation stuff to eliminate unused code paths and avoid registering the Helm controller when helm is disabled.
As of fe465cc832 we no longer call NewContext outside pkg/server, so the isServer bool flag to use the supervisor kubeconfig and create an event recorder is unnecessary.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-26 12:29:36 -07:00
Brad Davidson
e47c497a3e
Bump containerd to v2.1.4
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-26 10:15:38 -07:00
Brad Davidson
a9016f3dcb
Add retry on etcd MemberAdd timeout
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-26 09:35:48 -07:00
Brad Davidson
0ec47408e9
Do not bootstrap etcd-only nodes from existing supervisor
...
Changes to how we bootstrap the agent and apiserver address list have
made this unnecessary since 5014c9e was merged, and it is creating
problems due to only etcd-only nodes not using their own config.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-25 22:16:48 -07:00
Brad Davidson
0254ca3f14
Update to runc v1.3.0
...
Requires switch from github.com/opencontainers/runc/libcontainer/cgroups -> github.com/opencontainers/cgroups
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-25 14:50:22 -07:00
Brad Davidson
356bd5d298
Fix spegel logging and startup sequence
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-25 11:02:30 -07:00
Brad Davidson
6ab8b424dd
Wire cri-dockerd --log-level=debug up to k3s --debug flag
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-22 10:23:30 -07:00
Brad Davidson
3d4c2cf2cf
Fix cert startup check events
...
Ensure that cert checks don't run until after the apiserver is ready to receive events
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-12 11:56:15 -07:00
Brad Davidson
3bae735fb5
Fix --docker with --container-runtime-endpoint
...
The container runtime endpoint value is passed into cri-dockerd as the docker socket address, so we need to check for --docker BEFORE checking for non-nil --container-runtime-endpoint.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-01 13:54:46 -07:00
Brad Davidson
fb222e9a68
Fix fallback DNS for IMDS and IPV6-only
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-08-01 11:18:06 -07:00
muicoder
8fff7f573b
refactor: replace go-bindata with native embed package
...
Signed-off-by: muicoder <muicoder@gmail.com >
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-07-31 11:53:06 -07:00
Vitor Savian
a238f33cdd
Add retention flag specific for s3
...
* Add retention flag specific for s3
* Add retention for the unit tests:
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
2025-07-28 13:42:09 -03:00
Brad Davidson
1d2967e3f4
Remove master toleration from manifests
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-07-21 13:32:09 -07:00
Brad Davidson
3a428ff02c
Update metric help to be more descriptive.
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-07-17 11:24:17 -07:00
Brad Davidson
17b43b63db
Emit certs OK event on startup, if no certs need renewal
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-07-16 10:51:01 -07:00
Brad Davidson
5ce3db779d
Update kine and use config defaults helper
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-07-11 10:10:13 -07:00
Vitor Savian
66102c5651
Refac shell completion to a better command structure
...
* Refac for shell completion
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Change FLAGS to OPTIONS
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Refac bash and zsh func names
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Refac bash and zsh func names
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
---------
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
2025-07-10 13:38:54 -03:00
Derek Nola
1b8ee398c7
Add basic fuzz test
...
Signed-off-by: Derek Nola <derek.nola@suse.com >
2025-07-10 09:38:18 -07:00
Brad Davidson
7ab7865530
Update to new CRDs
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-07-07 15:31:55 -07:00
Manuel Buil
e6e301959f
Add usage description for etcd-snapshot ( #12557 )
2025-07-02 09:24:13 -07:00
bo.jiang
db778faaf3
fix: Remove unused legacy certificates
...
Signed-off-by: bo.jiang <bo.jiang@daocloud.io >
2025-06-24 12:31:47 -07:00
Roberto Bonafiglia
573da0d41c
Update network components
...
Signed-off-by: Roberto Bonafiglia <roberto.bonafiglia@suse.com >
2025-06-16 16:04:25 +02:00
Brad Davidson
5cc51edafa
Fix sqlite-etcd migration
...
Forgot to add new config to temporary kine in #12293
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-06-12 17:17:49 -07:00
Brad Davidson
db5390511e
Switch from endpoints to endpointslices
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-06-09 11:28:02 -07:00
Zero King
490588e86b
Add new topologySpreadConstraints to coredns
...
Prefer scaling across zones if multiple zones are available.
2025-06-05 13:02:17 -07:00
bo.jiang
b5f4fd1d73
Fix K3s not validating datastore connection when no token is set
...
Signed-off-by: bo.jiang <bo.jiang@daocloud.io >
2025-06-05 12:49:26 -07:00
haruna
d256968ee4
Improve shebang of bash completion script
...
Signed-off-by: haruna <w10776e8w@yahoo.co.jp >
2025-05-30 10:18:42 -07:00
bo.jiang
f7f546a23e
Fix secrets encryption rotation timeout causing false failures
...
Signed-off-by: bo.jiang <bo.jiang@daocloud.io >
2025-05-30 10:16:34 -07:00
Caio Torres
729403345b
feat: remove master role labels ( #12395 )
...
Signed-off-by: Caio Torres <caio.torres@suse.com >
2025-05-28 12:41:35 -07:00
Brad Davidson
dad64705d3
Fix startuphooks race condition panic
...
Ensure startup hooks WaitGroup is initialized before starting goroutine that will wait on it
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-05-15 14:27:40 -07:00
Brad Davidson
0dd6f17797
Fix secretsencryption request handler panic
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-05-15 14:27:40 -07:00
Brad Davidson
cb889d41f2
Fix authorization-config/authentication-config handling
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-05-15 13:38:49 -07:00
Brad Davidson
10e3d40bf3
Sync datastore config defaults with kine CLI
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-05-09 15:32:53 -07:00
Richard Hansen
925726c84d
flannel: Use custom type for network mode (IPv4, IPv6, dual-stack)
...
Move the `ipv4` and `ipv6` constants to their own constant
declaration. This ensures that the `iota` expression for the `ipv4`
constant evaluates to 0, not some arbitrary value. (`iota` evaluates
to N for the Nth constant in the constant declaration; see
<https://go.dev/ref/spec#Iota >.) This is also more idiomatic, which
improves readability.
Also switch from incremental integers to bit flags, and use bitwise
operators for checking. This is more idiomatic (the integer is
treated like a set of booleans), it avoids some code duplication, and
it is necessary to avoid ambiguity. Consider the following:
const (
ipv4 = iota
ipv6
)
In the above, `ipv4` would have the value 0 and `ipv6` would have the
value 1. This would make it impossible to distinguish an IPv6-only
stack from a dual-stack configuration because `ipv6` would equal
`ipv4 + ipv6`. With bit flags this problem doesn't exist.
And put the integer holding the bit flags in a custom type with
convenience methods to improve readability.
Signed-off-by: Richard Hansen <rhansen@rhansen.org >
2025-05-09 12:51:48 -07:00
Vitor Savian
53de968676
Add generation for kube-scheduler and kube-controller-manager certs ( #12285 )
...
* Add generation for kube-scheduler and kube-controller-manager certs
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Add new certs to the tests
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Change cert-dir to tls-cert-file and tls-private-key-file
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Address altName structure
Co-authored-by: Brad Davidson <brad@oatmail.org >
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
---------
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
Co-authored-by: Brad Davidson <brad@oatmail.org >
2025-05-09 16:25:44 -03:00
bo.jiang
4c1f014d27
Optimize certificate status check
...
Signed-off-by: bo.jiang <bo.jiang@daocloud.io >
2025-05-08 11:57:29 -07:00
Brad Davidson
67291090ca
Add support for conditional image tarball imports
...
Normally K3s will import all tarballs in the image dir on startup, and
re-import any tarballs that change while it is running.
This change allows users to opt into only importing tarballs that have
changed since they were last imported, even across restarts.
This behavior is opted into by touching a `.cache.json` file in the
images dir. This file is used to track the size and mtime of the image
files when they are imported.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-05-07 15:06:14 -07:00
Brad Davidson
a8f0acbe52
Add CLI flag and config file for s3 bucket lookup type
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-05-07 11:50:22 -07:00
Brad Davidson
921e502918
Add anonymous-auth to flags gated on empty authorization-config value
...
Also warn if default flags are not set due to user provided config
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-05-07 10:59:27 -07:00
Brad Davidson
b15af84e4a
Bump containerd/cri-dockerd/spegel/runc
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-05-07 10:20:40 -07:00
Vitor Savian
0b48e363b5
Update certification renew alert to 120 days
...
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
2025-05-02 15:17:12 -03:00
Vitor Savian
dc03cb4b3f
Update k8s version to 1.33
...
* Update to 1.33
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Fix prints that broke unit tests
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Change binary max size to 75
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Change containerd version to fix misspelling
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Address binary size comment
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Update Dependencies
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
* Remove dependencie not used anymore
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
---------
Signed-off-by: Vitor Savian <vitor.savian@suse.com >
2025-04-30 04:43:37 -03:00
Brad Davidson
396f1366cc
Bump spegel to v0.1.1
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-04-24 16:31:24 -07:00
Brad Davidson
9604f271bc
Bump traefik to v3.3.6
...
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-04-21 16:11:56 -07:00
Brad Davidson
b8a705d9c2
Fix handler panic when bootstrapper returned empty peer list
...
Panic gets rescued by the http server, and was only visible when running in debug mode, but should be handled properly.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-04-18 10:20:15 -07:00
Brad Davidson
4f17e626f3
Fix chainingBootstrapper to return the first successful address list
...
Avoids infinite recursion when the chain includes an agentBootstrapper with a server address that points back at this node (via join address loop or external LB)
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-04-17 14:20:39 -07:00
Brad Davidson
3f7e6a30ce
Move delegating auth middleware into common package and add MaxInFlight
...
Adds maximum in-flight request limits to agent join and p2p peer info
request request handlers.
Signed-off-by: Brad Davidson <brad.davidson@rancher.com >
2025-04-17 14:20:39 -07:00