Merge "k0: expose controller-manager and scheduler metrics"

changes/83/483/1
q3k 2020-10-10 20:40:35 +00:00 committed by Gerrit Code Review
commit b014a95e0a
2 changed files with 19 additions and 4 deletions

View File

@ -70,7 +70,9 @@ in rec {
ports = { ports = {
k8sAPIServerPlain = 4000; k8sAPIServerPlain = 4000;
k8sAPIServerSecure = 4001; k8sAPIServerSecure = 4001;
k8sControllerManagerPlain = 0; # 4002; do not serve plain http k8sControllerManagerPlain = 0; # would be 4002; do not serve plain http
k8sControllerManagerSecure = 4003; k8sControllerManagerSecure = 4003;
k8sSchedulerPlain = 0; # would be 4004; do not serve plain http
k8sSchedulerSecure = 4005;
}; };
} }

View File

@ -154,7 +154,10 @@ in rec {
''; '';
}; };
controllerManager = { controllerManager = let
top = config.services.kubernetes;
kubeconfig = top.lib.mkKubeConfig "controller-manager" pki.kube.controllermanager.config;
in {
enable = true; enable = true;
bindAddress = "0.0.0.0"; bindAddress = "0.0.0.0";
insecurePort = ports.k8sControllerManagerPlain; insecurePort = ports.k8sControllerManagerPlain;
@ -165,16 +168,26 @@ in rec {
--service-cluster-ip-range=10.10.12.0/24 \ --service-cluster-ip-range=10.10.12.0/24 \
--use-service-account-credentials=true \ --use-service-account-credentials=true \
--secure-port=${toString ports.k8sControllerManagerSecure}\ --secure-port=${toString ports.k8sControllerManagerSecure}\
--authentication-kubeconfig=${kubeconfig}\
--authorization-kubeconfig=${kubeconfig}\
''; '';
kubeconfig = pki.kube.controllermanager.config; kubeconfig = pki.kube.controllermanager.config;
}; };
scheduler = { scheduler = let
top = config.services.kubernetes;
kubeconfig = top.lib.mkKubeConfig "scheduler" pki.kube.controllermanager.config;
in {
enable = true; enable = true;
address = "0.0.0.0"; address = "0.0.0.0";
port = 0; port = ports.k8sSchedulerPlain;
leaderElect = true; leaderElect = true;
kubeconfig = pki.kube.scheduler.config; kubeconfig = pki.kube.scheduler.config;
extraOpts = ''
--secure-port=${toString ports.k8sSchedulerSecure}\
--authentication-kubeconfig=${kubeconfig}\
--authorization-kubeconfig=${kubeconfig}\
'';
}; };
proxy = { proxy = {