Skip to content

Commit

Permalink
wip on cilium, squash
Browse files Browse the repository at this point in the history
  • Loading branch information
arichtman committed Apr 27, 2024
1 parent 4d3ed60 commit 3179de1
Show file tree
Hide file tree
Showing 3 changed files with 16 additions and 0 deletions.
5 changes: 5 additions & 0 deletions cilium.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
cni:
confPath: /run/cni/net.d
# ipv6:
# enbabled: true
kubeProxyReplacement: "true"
8 changes: 8 additions & 0 deletions modules/nixos/worker-node/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,9 @@ in
networking.firewall.allowedTCPPorts = [
# Kubelet access
10250
# Cilium
# 4245
# 4240
];
services = {
kubernetes = {
Expand All @@ -31,13 +34,18 @@ in
--rotate-server-certificates \
--rotate-certificates \
'';
# Cilium
# cni.configDir = "/run/cni/net.d";
# cni.config = [];
kubeconfig = {
certFile = "${config.services.kubernetes.secretsPath}/kubelet-apiserver-client.pem";
keyFile = "${config.services.kubernetes.secretsPath}/kubelet-apiserver-client-key.pem";
caFile = config.services.kubernetes.caFile;
};
};
proxy = {
# Cilium
# enable = false;
kubeconfig = {
certFile = "${config.services.kubernetes.secretsPath}/proxy-apiserver-client.pem";
keyFile = "${config.services.kubernetes.secretsPath}/proxy-apiserver-client-key.pem";
Expand Down
3 changes: 3 additions & 0 deletions shells/myshell/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,9 @@ mkShell {
kubectl
kubectx
kubernetes-helm
# Cilium
# cilium-cli
# hubble
# Certificates and secrets
xkcdpass
step-cli
Expand Down

0 comments on commit 3179de1

Please sign in to comment.