typhoon/aws/fedora-coreos/kubernetes
Dalton Hubble feac94605a Fix bootstrap mount to use shared volume SELinux label
* Race: During initial bootstrap, static control plane pods
could hang with Permission denied to bootstrap secrets. A
manual fix involved restarting Kubelet, which relabeled mounts
The race had no effect on subsequent reboots.
* bootstrap.service runs podman with a private unshared mount
of /etc/kubernetes/bootstrap-secrets which uses an SELinux MCS
label with a category pair. However, bootstrap-secrets should
be shared as its mounted by Docker pods kube-apiserver,
kube-scheduler, and kube-controller-manager. Restarting Kubelet
was a manual fix because Kubelet relabels all /etc/kubernetes
* Fix bootstrap Pod to use the shared volume label, which leaves
bootstrap-secrets files with SELinux level s0 without MCS
* Also allow failed bootstrap.service to be re-applied. This was
missing on bare-metal and AWS
2020-04-19 16:31:32 -07:00
..
fcc Fix bootstrap mount to use shared volume SELinux label 2020-04-19 16:31:32 -07:00
workers Update Kubernetes from v1.18.1 to v1.18.2 2020-04-16 23:40:52 -07:00
LICENSE Port Typhoon Fedora CoreOS support to AWS 2019-07-18 00:55:22 -07:00
README.md Update Kubernetes from v1.18.1 to v1.18.2 2020-04-16 23:40:52 -07:00
ami.tf Fix Fedora CoreOS AMI to filter for stable images 2020-03-28 12:57:45 -07:00
bootstrap.tf Update Kubernetes from v1.18.1 to v1.18.2 2020-04-16 23:40:52 -07:00
controllers.tf Rename bootkube modules to bootstrap 2019-09-14 16:24:32 -07:00
network.tf Fix terraform fmt 2020-03-31 21:42:51 -07:00
nlb.tf Port Typhoon Fedora CoreOS support to AWS 2019-07-18 00:55:22 -07:00
outputs.tf Rename bootkube modules to bootstrap 2019-09-14 16:24:32 -07:00
security.tf Enable kube-proxy metrics and allow Prometheus scrapes 2020-01-06 21:11:18 -08:00
ssh.tf Rename CLC files and favor Terraform list index syntax 2019-12-28 12:14:01 -08:00
variables.tf Change `container-linux` module preference to Flatcar Linux 2020-04-11 14:52:30 -07:00
versions.tf Adopt Terraform v0.12 templatefile function 2019-11-13 16:33:36 -08:00
workers.tf Add node_labels variable in workers modules to set initial node labels (#550) 2019-09-28 14:59:24 -07:00

README.md

Typhoon

Typhoon is a minimal and free Kubernetes distribution.

  • Minimal, stable base Kubernetes distribution
  • Declarative infrastructure and configuration
  • Free (freedom and cost) and privacy-respecting
  • Practical for labs, datacenters, and clouds

Typhoon distributes upstream Kubernetes, architectural conventions, and cluster addons, much like a GNU/Linux distribution provides the Linux kernel and userspace components.

Features

Docs

Please see the official docs and the AWS tutorial.