nixos/kubernetes: use nix coredns package by default (#424296)
This commit is contained in:
@@ -20,7 +20,20 @@
|
||||
|
||||
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
|
||||
|
||||
- Create the first release note entry in this section!
|
||||
- `services.kubernetes.addons.dns.coredns` has been renamed to `services.kubernetes.addons.dns.corednsImage` and now expects a
|
||||
package instead of attrs. Now, by default, nixpkgs.coredns in conjunction with dockerTools.buildImage is used, instead
|
||||
of pulling the upstream container image from Docker Hub. If you want the old behavior, you can set:
|
||||
|
||||
```nix
|
||||
{
|
||||
services.kubernetes.addons.dns.corednsImage = pkgs.dockerTools.pullImage {
|
||||
imageName = "coredns/coredns";
|
||||
imageDigest = "sha256:af8c8d35a5d184b386c4a6d1a012c8b218d40d1376474c7d071bb6c07201f47d";
|
||||
finalImageTag = "v1.12.2";
|
||||
hash = "sha256-ZgXEyxVrdskQdgg0ONJ9sboAXEEHTgNsiptk5O945c0=";
|
||||
};
|
||||
}
|
||||
```
|
||||
|
||||
## Other Notable Changes {#sec-release-26.05-notable-changes}
|
||||
|
||||
|
||||
@@ -6,7 +6,6 @@
|
||||
...
|
||||
}:
|
||||
let
|
||||
version = "1.10.1";
|
||||
cfg = config.services.kubernetes.addons.dns;
|
||||
ports = {
|
||||
dns = 10053;
|
||||
@@ -15,6 +14,26 @@ let
|
||||
};
|
||||
in
|
||||
{
|
||||
imports = [
|
||||
(lib.mkRenamedOptionModuleWith {
|
||||
sinceRelease = 2605;
|
||||
from = [
|
||||
"services"
|
||||
"kubernetes"
|
||||
"addons"
|
||||
"dns"
|
||||
"coredns"
|
||||
];
|
||||
to = [
|
||||
"services"
|
||||
"kubernetes"
|
||||
"addons"
|
||||
"dns"
|
||||
"corednsImage"
|
||||
];
|
||||
})
|
||||
];
|
||||
|
||||
options.services.kubernetes.addons.dns = {
|
||||
enable = lib.mkEnableOption "kubernetes dns addon";
|
||||
|
||||
@@ -61,14 +80,12 @@ in
|
||||
];
|
||||
};
|
||||
|
||||
coredns = lib.mkOption {
|
||||
corednsImage = lib.mkOption {
|
||||
description = "Docker image to seed for the CoreDNS container.";
|
||||
type = lib.types.attrs;
|
||||
default = {
|
||||
imageName = "coredns/coredns";
|
||||
imageDigest = "sha256:a0ead06651cf580044aeb0a0feba63591858fb2e43ade8c9dea45a6a89ae7e5e";
|
||||
finalImageTag = version;
|
||||
sha256 = "0wg696920smmal7552a2zdhfncndn5kfammfa8bk8l7dz9bhk0y1";
|
||||
type = lib.types.package;
|
||||
default = pkgs.dockerTools.buildImage {
|
||||
name = "coredns";
|
||||
config.Entrypoint = [ "${pkgs.coredns}/bin/coredns" ];
|
||||
};
|
||||
};
|
||||
|
||||
@@ -116,9 +133,7 @@ in
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
services.kubernetes.kubelet.seedDockerImages = lib.singleton (
|
||||
pkgs.dockerTools.pullImage cfg.coredns
|
||||
);
|
||||
services.kubernetes.kubelet.seedDockerImages = lib.singleton (cfg.corednsImage);
|
||||
|
||||
services.kubernetes.addonManager.bootstrapAddons = {
|
||||
coredns-cr = {
|
||||
@@ -264,7 +279,7 @@ in
|
||||
"-conf"
|
||||
"/etc/coredns/Corefile"
|
||||
];
|
||||
image = with cfg.coredns; "${imageName}:${finalImageTag}";
|
||||
image = with cfg.corednsImage; "${imageName}:${imageTag}";
|
||||
imagePullPolicy = "Never";
|
||||
livenessProbe = {
|
||||
failureThreshold = 5;
|
||||
@@ -307,6 +322,7 @@ in
|
||||
securityContext = {
|
||||
allowPrivilegeEscalation = false;
|
||||
capabilities = {
|
||||
add = [ "NET_BIND_SERVICE" ];
|
||||
drop = [ "all" ];
|
||||
};
|
||||
readOnlyRootFilesystem = true;
|
||||
|
||||
Reference in New Issue
Block a user