diff --git a/nixos/modules/services/cluster/kubernetes/apiserver.nix b/nixos/modules/services/cluster/kubernetes/apiserver.nix
index 55d0ab9b0044..fc98a4867494 100644
--- a/nixos/modules/services/cluster/kubernetes/apiserver.nix
+++ b/nixos/modules/services/cluster/kubernetes/apiserver.nix
@@ -49,312 +49,327 @@ in
];
###### interface
- options.services.kubernetes.apiserver = let inherit (lib.types) nullOr str bool listOf enum attrs path separatedString attrsOf int; in {
+ options.services.kubernetes.apiserver =
+ let
+ inherit (lib.types)
+ nullOr
+ str
+ bool
+ listOf
+ enum
+ attrs
+ path
+ separatedString
+ attrsOf
+ int
+ ;
+ in
+ {
- advertiseAddress = lib.mkOption {
- description = ''
- Kubernetes apiserver IP address on which to advertise the apiserver
- to members of the cluster. This address must be reachable by the rest
- of the cluster.
- '';
- default = null;
- type = nullOr str;
- };
-
- allowPrivileged = lib.mkOption {
- description = "Whether to allow privileged containers on Kubernetes.";
- default = false;
- type = bool;
- };
-
- authorizationMode = lib.mkOption {
- description = ''
- Kubernetes apiserver authorization mode (AlwaysAllow/AlwaysDeny/ABAC/Webhook/RBAC/Node). See
-
- '';
- default = [
- "RBAC"
- "Node"
- ]; # Enabling RBAC by default, although kubernetes default is AllowAllow
- type = listOf (enum [
- "AlwaysAllow"
- "AlwaysDeny"
- "ABAC"
- "Webhook"
- "RBAC"
- "Node"
- ]);
- };
-
- authorizationPolicy = lib.mkOption {
- description = ''
- Kubernetes apiserver authorization policy file. See
-
- '';
- default = [ ];
- type = listOf attrs;
- };
-
- basicAuthFile = lib.mkOption {
- description = ''
- Kubernetes apiserver basic authentication file. See
-
- '';
- default = null;
- type = nullOr path;
- };
-
- bindAddress = lib.mkOption {
- description = ''
- The IP address on which to listen for the --secure-port port.
- The associated interface(s) must be reachable by the rest
- of the cluster, and by CLI/web clients.
- '';
- default = "0.0.0.0";
- type = str;
- };
-
- clientCaFile = lib.mkOption {
- description = "Kubernetes apiserver CA file for client auth.";
- default = top.caFile;
- defaultText = lib.literalExpression "config.${otop.caFile}";
- type = nullOr path;
- };
-
- disableAdmissionPlugins = lib.mkOption {
- description = ''
- Kubernetes admission control plugins to disable. See
-
- '';
- default = [ ];
- type = listOf str;
- };
-
- enable = lib.mkEnableOption "Kubernetes apiserver";
-
- enableAdmissionPlugins = lib.mkOption {
- description = ''
- Kubernetes admission control plugins to enable. See
-
- '';
- default = [
- "NamespaceLifecycle"
- "LimitRanger"
- "ServiceAccount"
- "ResourceQuota"
- "DefaultStorageClass"
- "DefaultTolerationSeconds"
- "NodeRestriction"
- ];
- example = [
- "NamespaceLifecycle"
- "NamespaceExists"
- "LimitRanger"
- "SecurityContextDeny"
- "ServiceAccount"
- "ResourceQuota"
- "PodSecurityPolicy"
- "NodeRestriction"
- "DefaultStorageClass"
- ];
- type = listOf str;
- };
-
- etcd = {
- servers = lib.mkOption {
- description = "List of etcd servers.";
- default = [ "http://127.0.0.1:2379" ];
- type = listOf str;
+ advertiseAddress = lib.mkOption {
+ description = ''
+ Kubernetes apiserver IP address on which to advertise the apiserver
+ to members of the cluster. This address must be reachable by the rest
+ of the cluster.
+ '';
+ default = null;
+ type = nullOr str;
};
- keyFile = lib.mkOption {
- description = "Etcd key file.";
+ allowPrivileged = lib.mkOption {
+ description = "Whether to allow privileged containers on Kubernetes.";
+ default = false;
+ type = bool;
+ };
+
+ authorizationMode = lib.mkOption {
+ description = ''
+ Kubernetes apiserver authorization mode (AlwaysAllow/AlwaysDeny/ABAC/Webhook/RBAC/Node). See
+
+ '';
+ default = [
+ "RBAC"
+ "Node"
+ ]; # Enabling RBAC by default, although kubernetes default is AllowAllow
+ type = listOf (enum [
+ "AlwaysAllow"
+ "AlwaysDeny"
+ "ABAC"
+ "Webhook"
+ "RBAC"
+ "Node"
+ ]);
+ };
+
+ authorizationPolicy = lib.mkOption {
+ description = ''
+ Kubernetes apiserver authorization policy file. See
+
+ '';
+ default = [ ];
+ type = listOf attrs;
+ };
+
+ basicAuthFile = lib.mkOption {
+ description = ''
+ Kubernetes apiserver basic authentication file. See
+
+ '';
default = null;
type = nullOr path;
};
- certFile = lib.mkOption {
- description = "Etcd cert file.";
- default = null;
- type = nullOr path;
+ bindAddress = lib.mkOption {
+ description = ''
+ The IP address on which to listen for the --secure-port port.
+ The associated interface(s) must be reachable by the rest
+ of the cluster, and by CLI/web clients.
+ '';
+ default = "0.0.0.0";
+ type = str;
};
- caFile = lib.mkOption {
- description = "Etcd ca file.";
+ clientCaFile = lib.mkOption {
+ description = "Kubernetes apiserver CA file for client auth.";
default = top.caFile;
defaultText = lib.literalExpression "config.${otop.caFile}";
type = nullOr path;
};
- };
- extraOpts = lib.mkOption {
- description = "Kubernetes apiserver extra command line options.";
- default = "";
- type = separatedString " ";
- };
+ disableAdmissionPlugins = lib.mkOption {
+ description = ''
+ Kubernetes admission control plugins to disable. See
+
+ '';
+ default = [ ];
+ type = listOf str;
+ };
- extraSANs = lib.mkOption {
- description = "Extra x509 Subject Alternative Names to be added to the kubernetes apiserver tls cert.";
- default = [ ];
- type = listOf str;
- };
+ enable = lib.mkEnableOption "Kubernetes apiserver";
- featureGates = lib.mkOption {
- description = "Attribute set of feature gates.";
- default = top.featureGates;
- defaultText = lib.literalExpression "config.${otop.featureGates}";
- type = attrsOf bool;
- };
+ enableAdmissionPlugins = lib.mkOption {
+ description = ''
+ Kubernetes admission control plugins to enable. See
+
+ '';
+ default = [
+ "NamespaceLifecycle"
+ "LimitRanger"
+ "ServiceAccount"
+ "ResourceQuota"
+ "DefaultStorageClass"
+ "DefaultTolerationSeconds"
+ "NodeRestriction"
+ ];
+ example = [
+ "NamespaceLifecycle"
+ "NamespaceExists"
+ "LimitRanger"
+ "SecurityContextDeny"
+ "ServiceAccount"
+ "ResourceQuota"
+ "PodSecurityPolicy"
+ "NodeRestriction"
+ "DefaultStorageClass"
+ ];
+ type = listOf str;
+ };
- kubeletClientCaFile = lib.mkOption {
- description = "Path to a cert file for connecting to kubelet.";
- default = top.caFile;
- defaultText = lib.literalExpression "config.${otop.caFile}";
- type = nullOr path;
- };
+ etcd = {
+ servers = lib.mkOption {
+ description = "List of etcd servers.";
+ default = [ "http://127.0.0.1:2379" ];
+ type = listOf str;
+ };
- kubeletClientCertFile = lib.mkOption {
- description = "Client certificate to use for connections to kubelet.";
- default = null;
- type = nullOr path;
- };
+ keyFile = lib.mkOption {
+ description = "Etcd key file.";
+ default = null;
+ type = nullOr path;
+ };
- kubeletClientKeyFile = lib.mkOption {
- description = "Key to use for connections to kubelet.";
- default = null;
- type = nullOr path;
- };
+ certFile = lib.mkOption {
+ description = "Etcd cert file.";
+ default = null;
+ type = nullOr path;
+ };
- preferredAddressTypes = lib.mkOption {
- description = "List of the preferred NodeAddressTypes to use for kubelet connections.";
- type = nullOr str;
- default = null;
- };
+ caFile = lib.mkOption {
+ description = "Etcd ca file.";
+ default = top.caFile;
+ defaultText = lib.literalExpression "config.${otop.caFile}";
+ type = nullOr path;
+ };
+ };
- proxyClientCertFile = lib.mkOption {
- description = "Client certificate to use for connections to proxy.";
- default = null;
- type = nullOr path;
- };
+ extraOpts = lib.mkOption {
+ description = "Kubernetes apiserver extra command line options.";
+ default = "";
+ type = separatedString " ";
+ };
- proxyClientKeyFile = lib.mkOption {
- description = "Key to use for connections to proxy.";
- default = null;
- type = nullOr path;
- };
+ extraSANs = lib.mkOption {
+ description = "Extra x509 Subject Alternative Names to be added to the kubernetes apiserver tls cert.";
+ default = [ ];
+ type = listOf str;
+ };
- runtimeConfig = lib.mkOption {
- description = ''
- Api runtime configuration. See
-
- '';
- default = "authentication.k8s.io/v1beta1=true";
- example = "api/all=false,api/v1=true";
- type = str;
- };
+ featureGates = lib.mkOption {
+ description = "Attribute set of feature gates.";
+ default = top.featureGates;
+ defaultText = lib.literalExpression "config.${otop.featureGates}";
+ type = attrsOf bool;
+ };
- storageBackend = lib.mkOption {
- description = ''
- Kubernetes apiserver storage backend.
- '';
- default = "etcd3";
- type = enum [
- "etcd2"
- "etcd3"
- ];
- };
+ kubeletClientCaFile = lib.mkOption {
+ description = "Path to a cert file for connecting to kubelet.";
+ default = top.caFile;
+ defaultText = lib.literalExpression "config.${otop.caFile}";
+ type = nullOr path;
+ };
- securePort = lib.mkOption {
- description = "Kubernetes apiserver secure port.";
- default = 6443;
- type = int;
- };
+ kubeletClientCertFile = lib.mkOption {
+ description = "Client certificate to use for connections to kubelet.";
+ default = null;
+ type = nullOr path;
+ };
- apiAudiences = lib.mkOption {
- description = ''
- Kubernetes apiserver ServiceAccount issuer.
- '';
- default = "api,https://kubernetes.default.svc";
- type = str;
- };
+ kubeletClientKeyFile = lib.mkOption {
+ description = "Key to use for connections to kubelet.";
+ default = null;
+ type = nullOr path;
+ };
- serviceAccountIssuer = lib.mkOption {
- description = ''
- Kubernetes apiserver ServiceAccount issuer.
- '';
- default = "https://kubernetes.default.svc";
- type = str;
- };
+ preferredAddressTypes = lib.mkOption {
+ description = "List of the preferred NodeAddressTypes to use for kubelet connections.";
+ type = nullOr str;
+ default = null;
+ };
- serviceAccountSigningKeyFile = lib.mkOption {
- description = ''
- Path to the file that contains the current private key of the service
- account token issuer. The issuer will sign issued ID tokens with this
- private key.
- '';
- type = path;
- };
+ proxyClientCertFile = lib.mkOption {
+ description = "Client certificate to use for connections to proxy.";
+ default = null;
+ type = nullOr path;
+ };
- serviceAccountKeyFile = lib.mkOption {
- description = ''
- File containing PEM-encoded x509 RSA or ECDSA private or public keys,
- used to verify ServiceAccount tokens. The specified file can contain
- multiple keys, and the flag can be specified multiple times with
- different files. If unspecified, --tls-private-key-file is used.
- Must be specified when --service-account-signing-key is provided
- '';
- type = path;
- };
+ proxyClientKeyFile = lib.mkOption {
+ description = "Key to use for connections to proxy.";
+ default = null;
+ type = nullOr path;
+ };
- serviceClusterIpRange = lib.mkOption {
- description = ''
- A CIDR notation IP range from which to assign service cluster IPs.
- This must not overlap with any IP ranges assigned to nodes for pods.
- '';
- default = "10.0.0.0/24";
- type = str;
- };
+ runtimeConfig = lib.mkOption {
+ description = ''
+ Api runtime configuration. See
+
+ '';
+ default = "authentication.k8s.io/v1beta1=true";
+ example = "api/all=false,api/v1=true";
+ type = str;
+ };
- tlsCertFile = lib.mkOption {
- description = "Kubernetes apiserver certificate file.";
- default = null;
- type = nullOr path;
- };
+ storageBackend = lib.mkOption {
+ description = ''
+ Kubernetes apiserver storage backend.
+ '';
+ default = "etcd3";
+ type = enum [
+ "etcd2"
+ "etcd3"
+ ];
+ };
- tlsKeyFile = lib.mkOption {
- description = "Kubernetes apiserver private key file.";
- default = null;
- type = nullOr path;
- };
+ securePort = lib.mkOption {
+ description = "Kubernetes apiserver secure port.";
+ default = 6443;
+ type = int;
+ };
- tokenAuthFile = lib.mkOption {
- description = ''
- Kubernetes apiserver token authentication file. See
-
- '';
- default = null;
- type = nullOr path;
- };
+ apiAudiences = lib.mkOption {
+ description = ''
+ Kubernetes apiserver ServiceAccount issuer.
+ '';
+ default = "api,https://kubernetes.default.svc";
+ type = str;
+ };
- verbosity = lib.mkOption {
- description = ''
- Optional glog verbosity level for logging statements. See
-
- '';
- default = null;
- type = nullOr int;
- };
+ serviceAccountIssuer = lib.mkOption {
+ description = ''
+ Kubernetes apiserver ServiceAccount issuer.
+ '';
+ default = "https://kubernetes.default.svc";
+ type = str;
+ };
- webhookConfig = lib.mkOption {
- description = ''
- Kubernetes apiserver Webhook config file. It uses the kubeconfig file format.
- See
- '';
- default = null;
- type = nullOr path;
- };
+ serviceAccountSigningKeyFile = lib.mkOption {
+ description = ''
+ Path to the file that contains the current private key of the service
+ account token issuer. The issuer will sign issued ID tokens with this
+ private key.
+ '';
+ type = path;
+ };
- };
+ serviceAccountKeyFile = lib.mkOption {
+ description = ''
+ File containing PEM-encoded x509 RSA or ECDSA private or public keys,
+ used to verify ServiceAccount tokens. The specified file can contain
+ multiple keys, and the flag can be specified multiple times with
+ different files. If unspecified, --tls-private-key-file is used.
+ Must be specified when --service-account-signing-key is provided
+ '';
+ type = path;
+ };
+
+ serviceClusterIpRange = lib.mkOption {
+ description = ''
+ A CIDR notation IP range from which to assign service cluster IPs.
+ This must not overlap with any IP ranges assigned to nodes for pods.
+ '';
+ default = "10.0.0.0/24";
+ type = str;
+ };
+
+ tlsCertFile = lib.mkOption {
+ description = "Kubernetes apiserver certificate file.";
+ default = null;
+ type = nullOr path;
+ };
+
+ tlsKeyFile = lib.mkOption {
+ description = "Kubernetes apiserver private key file.";
+ default = null;
+ type = nullOr path;
+ };
+
+ tokenAuthFile = lib.mkOption {
+ description = ''
+ Kubernetes apiserver token authentication file. See
+
+ '';
+ default = null;
+ type = nullOr path;
+ };
+
+ verbosity = lib.mkOption {
+ description = ''
+ Optional glog verbosity level for logging statements. See
+
+ '';
+ default = null;
+ type = nullOr int;
+ };
+
+ webhookConfig = lib.mkOption {
+ description = ''
+ Kubernetes apiserver Webhook config file. It uses the kubeconfig file format.
+ See
+ '';
+ default = null;
+ type = nullOr path;
+ };
+
+ };
###### implementation
config = lib.mkMerge [