forked from hswaw/hscloud
Sergiusz Bazanski
73cef11c85
This pretty large change does the following: - moves nix from bootstrap.hswaw.net to nix/ - changes clustercfg to use cfssl and moves it to cluster/clustercfg - changes clustercfg to source information about target location of certs from nix - changes clustercfg to push nix config - changes tls certs to have more than one CA - recalculates all TLS certs (it keeps the old serviceaccoutns key, otherwise we end up with invalid serviceaccounts - the cert doesn't match, but who cares, it's not used anyway) |
||
---|---|---|
.. | ||
ca-etcd.crt | ||
ca-etcdpeer.crt | ||
ca-kube.crt | ||
ca-kubefront.crt | ||
etcd-bc01n01.hswaw.net.cert | ||
etcd-bc01n02.hswaw.net.cert | ||
etcd-bc01n03.hswaw.net.cert | ||
etcd-calico.cert | ||
etcd-kube.cert | ||
etcd-root.cert | ||
etcdpeer-bc01n01.hswaw.net.cert | ||
etcdpeer-bc01n02.hswaw.net.cert | ||
etcdpeer-bc01n03.hswaw.net.cert | ||
kube-apiserver.cert | ||
kube-controllermanager.cert | ||
kube-kubelet-bc01n01.hswaw.net.cert | ||
kube-kubelet-bc01n02.hswaw.net.cert | ||
kube-kubelet-bc01n03.hswaw.net.cert | ||
kube-proxy.cert | ||
kube-scheduler.cert | ||
kube-serviceaccounts.cert | ||
kubefront-apiserver.cert |