blob: 28cce6ea65346b9e2f33ee35402cae91d96b732d (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
|
{ config, pkgs, certs }:
let
etcd_key = "${certs}/etcd-key.pem";
etcd_cert = "${certs}/etcd.pem";
ca_pem = "${certs}/ca.pem";
etcd_client_cert = "${certs}/etcd-client.crt";
etcd_client_key = "${certs}/etcd-client-key.pem";
apiserver_key = "${certs}/apiserver-key.pem";
apiserver_cert = "${certs}/apiserver.pem";
worker_key = "${certs}/worker-key.pem";
worker_cert = "${certs}/worker.pem";
rootCaFile = pkgs.writeScript "rootCaFile.pem" ''
${pkgs.lib.readFile "${certs}/ca.pem"}
${pkgs.lib.readFile ("${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt")}
'';
in
{
networking = {
firewall = {
enable = true;
allowPing = true;
allowedTCPPorts = [
2379 2380 # etcd
443 # kubernetes apiserver
];
};
};
services.etcd = {
enable = pkgs.lib.mkForce true;
keyFile = etcd_key;
certFile = etcd_cert;
trustedCaFile = rootCaFile;
peerClientCertAuth = true;
listenClientUrls = ["https://0.0.0.0:2379"];
listenPeerUrls = ["https://0.0.0.0:2380"];
advertiseClientUrls = ["https://etcd.kubernetes.nixos.xyz:2379"];
initialCluster = ["master=https://etcd.kubernetes.nixos.xyz:2380"];
initialAdvertisePeerUrls = ["https://etcd.kubernetes.nixos.xyz:2380"];
};
services.kubernetes = {
roles = ["master"];
scheduler.leaderElect = true;
controllerManager.rootCaFile = rootCaFile;
controllerManager.serviceAccountKeyFile = apiserver_key;
apiserver = {
publicAddress = "192.168.1.1";
advertiseAddress = "192.168.1.1";
tlsKeyFile = apiserver_key;
tlsCertFile = apiserver_cert;
clientCaFile = rootCaFile;
kubeletClientCaFile = rootCaFile;
kubeletClientKeyFile = worker_key;
kubeletClientCertFile = worker_cert;
};
};
}
|