Skip to content

Commit

Permalink
Update weave template to match source for 2.8.1 (#8013)
Browse files Browse the repository at this point in the history
  • Loading branch information
frankfil authored Sep 28, 2021
1 parent 8d3961e commit eee2eb1
Showing 1 changed file with 27 additions and 17 deletions.
44 changes: 27 additions & 17 deletions roles/network_plugin/weave/templates/weave-net.yml.j2
Original file line number Diff line number Diff line change
Expand Up @@ -27,28 +27,28 @@ items:
- list
- watch
- apiGroups:
- networking.k8s.io
- extensions
resources:
- networkpolicies
verbs:
- get
- list
- watch
- apiGroups:
- ''
- 'networking.k8s.io'
resources:
- nodes/status
- networkpolicies
verbs:
- patch
- update
- get
- list
- watch
- apiGroups:
- policy
resourceNames:
- privileged
- ''
resources:
- podsecuritypolicies
- nodes/status
verbs:
- use
- patch
- update
- apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
Expand All @@ -67,16 +67,16 @@ items:
kind: Role
metadata:
name: weave-net
namespace: kube-system
labels:
name: weave-net
namespace: kube-system
rules:
- apiGroups:
- ''
resourceNames:
- weave-net
resources:
- configmaps
resourceNames:
- weave-net
verbs:
- get
- update
Expand All @@ -90,9 +90,9 @@ items:
kind: RoleBinding
metadata:
name: weave-net
namespace: kube-system
labels:
name: weave-net
namespace: kube-system
roleRef:
kind: Role
name: weave-net
Expand All @@ -109,16 +109,16 @@ items:
name: weave-net
namespace: kube-system
spec:
minReadySeconds: 5
# Wait 5 seconds to let pod connect before rolling next pod
selector:
matchLabels:
name: weave-net
minReadySeconds: 5
template:
metadata:
labels:
name: weave-net
spec:
priorityClassName: system-node-critical
initContainers:
- name: weave-init
image: {{ weave_kube_image_repo }}:{{ weave_kube_image_tag }}
Expand Down Expand Up @@ -217,6 +217,9 @@ items:
- name: dbus
mountPath: /host/var/lib/dbus
readOnly: true
- mountPath: /host/etc/machine-id
name: cni-machine-id
readOnly: true
- name: xtables-lock
mountPath: /run/xtables.lock
readOnly: false
Expand Down Expand Up @@ -246,7 +249,10 @@ items:
seLinuxOptions: {}
serviceAccountName: weave-net
tolerations:
- operator: Exists
- effect: NoSchedule
operator: Exists
- effect: NoExecute
operator: Exists
volumes:
- name: weavedb
hostPath:
Expand All @@ -260,6 +266,9 @@ items:
- name: cni-conf
hostPath:
path: /etc
- name: cni-machine-id
hostPath:
path: /etc/machine-id
- name: dbus
hostPath:
path: /var/lib/dbus
Expand All @@ -270,6 +279,7 @@ items:
hostPath:
path: /run/xtables.lock
type: FileOrCreate
priorityClassName: system-node-critical
updateStrategy:
rollingUpdate:
maxUnavailable: {{ serial | default('20%') }}
Expand Down

0 comments on commit eee2eb1

Please sign in to comment.