Skip to content

Commit

Permalink
Merge pull request #9899 from olemarkus/remove-insecure-bind-address
Browse files Browse the repository at this point in the history
Don't explicitly set insecure-bind-address on newer k8s
  • Loading branch information
k8s-ci-robot authored Sep 9, 2020
2 parents ddde1b8 + 886b4c9 commit 4604fa5
Show file tree
Hide file tree
Showing 7 changed files with 2 additions and 7 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,6 @@ contents: |
- --etcd-keyfile=/etc/kubernetes/pki/kube-apiserver/etcd-client.key
- --etcd-servers-overrides=/events#https://127.0.0.1:4002
- --etcd-servers=https://127.0.0.1:4001
- --insecure-bind-address=127.0.0.1
- --insecure-port=0
- --kubelet-client-certificate=/srv/kubernetes/kubelet-api.crt
- --kubelet-client-key=/srv/kubernetes/kubelet-api.key
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,6 @@ contents: |
- --etcd-keyfile=/etc/kubernetes/pki/kube-apiserver/etcd-client.key
- --etcd-servers-overrides=/events#https://127.0.0.1:4002
- --etcd-servers=https://127.0.0.1:4001
- --insecure-bind-address=127.0.0.1
- --insecure-port=0
- --kubelet-client-certificate=/srv/kubernetes/kubelet-api.crt
- --kubelet-client-key=/srv/kubernetes/kubelet-api.key
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,6 @@ contents: |
- --etcd-keyfile=/etc/kubernetes/pki/kube-apiserver/etcd-client.key
- --etcd-servers-overrides=/events#https://127.0.0.1:4002
- --etcd-servers=https://127.0.0.1:4001
- --insecure-bind-address=127.0.0.1
- --insecure-port=0
- --kubelet-client-certificate=/srv/kubernetes/kubelet-api.crt
- --kubelet-client-key=/srv/kubernetes/kubelet-api.key
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,6 @@ contents: |
- --etcd-keyfile=/etc/kubernetes/pki/kube-apiserver/etcd-client.key
- --etcd-servers-overrides=/events#https://127.0.0.1:4002
- --etcd-servers=https://127.0.0.1:4001
- --insecure-bind-address=127.0.0.1
- --insecure-port=0
- --kubelet-client-certificate=/srv/kubernetes/kubelet-api.crt
- --kubelet-client-key=/srv/kubernetes/kubelet-api.key
Expand Down
3 changes: 2 additions & 1 deletion pkg/model/components/apiserver.go
Original file line number Diff line number Diff line change
Expand Up @@ -162,7 +162,6 @@ func (b *KubeAPIServerOptionsBuilder) BuildOptions(o interface{}) error {
c.SecurePort = 443

c.BindAddress = "0.0.0.0"
c.InsecureBindAddress = "127.0.0.1"

c.AllowPrivileged = fi.Bool(true)
c.ServiceClusterIPRange = clusterSpec.ServiceClusterIPRange
Expand Down Expand Up @@ -217,9 +216,11 @@ func (b *KubeAPIServerOptionsBuilder) BuildOptions(o interface{}) error {

if b.IsKubernetesGTE("1.17") {
// We query via the kube-apiserver-healthcheck proxy, which listens on port 3990
c.InsecureBindAddress = ""
c.InsecurePort = 0
} else {
// Older versions of kubernetes continue to rely on the insecure port: kubernetes issue #43784
c.InsecureBindAddress = "127.0.0.1"
c.InsecurePort = 8080
}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -195,7 +195,6 @@ Resources.AWSEC2LaunchTemplatemasterustest1amastersprivatecalicoexamplecom.Prope
etcdServersOverrides:
- /events#http://127.0.0.1:4002
image: k8s.gcr.io/kube-apiserver:v1.18.0
insecureBindAddress: 127.0.0.1
kubeletPreferredAddressTypes:
- InternalIP
- Hostname
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -193,7 +193,6 @@ kubeAPIServer:
etcdServersOverrides:
- /events#http://127.0.0.1:4002
image: k8s.gcr.io/kube-apiserver:v1.18.0
insecureBindAddress: 127.0.0.1
kubeletPreferredAddressTypes:
- InternalIP
- Hostname
Expand Down

0 comments on commit 4604fa5

Please sign in to comment.