typhoon/bare-metal/fedora-coreos/kubernetes
Bo Huang aafa38476a
Fix SELinux race condition on non-bootstrap controllers in multi-controller (#808)
* Fix race condition for bootstrap-secrets SELinux context on non-bootstrap controllers in multi-controller FCOS clusters
* On first boot from disk on non-bootstrap controllers, adding bootstrap-secrets races with kubelet.service starting, which can cause the secrets assets to have the wrong label until kubelet.service restarts (service, reboot, auto-update)
* This can manifest as `kube-apiserver`, `kube-controller-manager`, and `kube-scheduler` pods crashlooping on spare controllers on first cluster creation
2020-08-19 21:18:10 -07:00
..
fcc Fix SELinux race condition on non-bootstrap controllers in multi-controller (#808) 2020-08-19 21:18:10 -07:00
bootstrap.tf Update Kubernetes from v1.18.6 to v1.18.8 2020-08-13 20:47:43 -07:00
groups.tf Introduce list of detail objects for bare-metal machines 2019-10-06 20:22:45 -07:00
LICENSE Add docs for Fedora CoreOS AWS and bare-metal 2019-07-18 00:55:22 -07:00
outputs.tf Rename bootkube modules to bootstrap 2019-09-14 16:24:32 -07:00
profiles.tf Fix terraform fmt 2020-03-31 21:42:51 -07:00
README.md Update Kubernetes from v1.18.6 to v1.18.8 2020-08-13 20:47:43 -07:00
ssh.tf Rename CLC files and favor Terraform list index syntax 2019-12-28 12:14:01 -08:00
variables.tf Fix terraform fmt 2020-03-31 21:42:51 -07:00
versions.tf Migrate from Terraform v0.12.x to v0.13.x 2020-08-12 01:54:32 -07:00

Typhoon

Typhoon is a minimal and free Kubernetes distribution.

  • Minimal, stable base Kubernetes distribution
  • Declarative infrastructure and configuration
  • Free (freedom and cost) and privacy-respecting
  • Practical for labs, datacenters, and clouds

Typhoon distributes upstream Kubernetes, architectural conventions, and cluster addons, much like a GNU/Linux distribution provides the Linux kernel and userspace components.

Features

  • Kubernetes v1.18.8 (upstream)
  • Single or multi-master, Calico or Cilium or flannel networking
  • On-cluster etcd with TLS, RBAC-enabled, network policy, SELinux enforcing
  • Advanced features like snippets customization
  • Ready for Ingress, Prometheus, Grafana, and other optional addons

Docs

Please see the official docs and the bare-metal tutorial.