mirror of
https://github.com/outbackdingo/matchbox.git
synced 2026-01-27 10:19:35 +00:00
scripts: Remove unused static k8s generation scripts
* Remove static rktnetes cluster docs * Bump devnet matchbox version
This commit is contained in:
@@ -91,7 +91,7 @@ function create {
|
||||
--volume config,kind=host,source=$CONFIG_DIR,readOnly=true \
|
||||
--mount volume=data,target=/var/lib/matchbox \
|
||||
$DATA_MOUNT \
|
||||
quay.io/coreos/matchbox:v0.6.0 -- -address=0.0.0.0:8080 -log-level=debug $MATCHBOX_ARGS
|
||||
quay.io/coreos/matchbox:ed6dde528a0146fe55551a317cc55849cec6ec80 -- -address=0.0.0.0:8080 -log-level=debug $MATCHBOX_ARGS
|
||||
|
||||
echo "Starting dnsmasq to provide DHCP/TFTP/DNS services"
|
||||
rkt rm --uuid-file=/var/run/dnsmasq-pod.uuid > /dev/null 2>&1
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
set -eu
|
||||
|
||||
DEST=${1:-"bin"}
|
||||
VERSION="v1.5.5"
|
||||
VERSION="v1.6.4"
|
||||
|
||||
URL="https://storage.googleapis.com/kubernetes-release/release/${VERSION}/bin/linux/amd64/kubectl"
|
||||
|
||||
|
||||
@@ -1,42 +0,0 @@
|
||||
#!/bin/bash -e
|
||||
|
||||
USAGE="Usage: $(basename $0)
|
||||
Options:
|
||||
-d DEST Destination for generated files (default: .examples/assets/tls)
|
||||
-s SERVER Reachable Server IP for kubeconfig (e.g. node1.example.com)
|
||||
-m MASTERS Controller Node Names/Addresses in SAN format (e.g. IP.1=10.3.0.1,DNS.1=node1.example.com)
|
||||
-w WORKERS Worker Node Names/Addresses in SAN format (e.g. DNS.1=node2.example.com,DNS.2=node3.example.com)
|
||||
-h Show help
|
||||
"
|
||||
|
||||
DEST="./examples/assets/tls"
|
||||
SERVER="node1.example.com"
|
||||
MASTERS="IP.1=10.3.0.1,DNS.1=node1.example.com"
|
||||
WORKERS="DNS.1=node2.example.com,DNS.2=node3.example.com"
|
||||
|
||||
while getopts "d:s:m:w:vh" opt; do
|
||||
case $opt in
|
||||
d) DEST="$OPTARG" ;;
|
||||
s) SERVER="$OPTARG" ;;
|
||||
m) MASTERS="$OPTARG" ;;
|
||||
w) WORKERS="$OPTARG" ;;
|
||||
h) echo "$USAGE"; exit;;
|
||||
*) exit 1;;
|
||||
esac
|
||||
done
|
||||
|
||||
if [ ! -d "$DEST" ]; then
|
||||
echo "Creating directory $DEST"
|
||||
mkdir -p $DEST
|
||||
fi
|
||||
|
||||
# create root CA
|
||||
./scripts/tls/root-ca $DEST
|
||||
|
||||
# create Kubernetes master and worker certificates
|
||||
./scripts/tls/kubernetes-cert $DEST admin kube-admin
|
||||
./scripts/tls/kubernetes-cert $DEST apiserver kube-apiserver $MASTERS
|
||||
./scripts/tls/kubernetes-cert $DEST worker kube-worker $WORKERS
|
||||
|
||||
# create a kubeconfig
|
||||
./scripts/tls/kube-conf $DEST $SERVER
|
||||
@@ -1,52 +0,0 @@
|
||||
#!/bin/bash -e
|
||||
|
||||
function usage {
|
||||
echo "USAGE: $0 DEST MASTER_IP"
|
||||
echo "example: $0 dest/path 192.168.1.21"
|
||||
}
|
||||
|
||||
function base64_encode {
|
||||
if [[ "$OSTYPE" == darwin* ]]; then
|
||||
base64 $1
|
||||
else
|
||||
base64 -w 0 $1
|
||||
fi
|
||||
}
|
||||
|
||||
if [ -z "$1" ] || [ -z "$2" ]; then
|
||||
usage
|
||||
exit 1
|
||||
fi
|
||||
|
||||
DEST="$1"
|
||||
MASTER_IP="$2"
|
||||
ADMIN_CERT_BASE64=$(base64_encode $DEST/admin.pem)
|
||||
ADMIN_KEY_BASE64="$(base64_encode $DEST/admin-key.pem)"
|
||||
CA_CERT_BASE64="$(base64_encode $DEST/ca.pem)"
|
||||
|
||||
if [ -f "$DEST/kubeconfig" ]; then
|
||||
echo "$DEST/kubeconfig already exists"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
cat << EOF > $DEST/kubeconfig
|
||||
apiVersion: v1
|
||||
kind: Config
|
||||
users:
|
||||
- name: matchbox-user
|
||||
user:
|
||||
client-certificate-data: ${ADMIN_CERT_BASE64}
|
||||
client-key-data: ${ADMIN_KEY_BASE64}
|
||||
clusters:
|
||||
- name: matchbox-cluster
|
||||
cluster:
|
||||
certificate-authority-data: ${CA_CERT_BASE64}
|
||||
server: https://${MASTER_IP}:443
|
||||
contexts:
|
||||
- context:
|
||||
cluster: matchbox-cluster
|
||||
user: matchbox-user
|
||||
name: matchbox-context
|
||||
current-context: matchbox-context
|
||||
EOF
|
||||
echo "Wrote kubeconfig to $DEST/kubeconfig"
|
||||
@@ -1,74 +0,0 @@
|
||||
#!/bin/bash -e
|
||||
|
||||
# define location of openssl binary manually since running this
|
||||
# script under Vagrant fails on some systems without it
|
||||
OPENSSL=/usr/bin/openssl
|
||||
|
||||
function usage {
|
||||
echo "USAGE: $0 <output-dir> <cert-base-name> <CN> [SAN,SAN,SAN]"
|
||||
echo " example: $0 ./ssl/ worker kube-worker IP.1=127.0.0.1,IP.2=10.0.0.1"
|
||||
}
|
||||
|
||||
if [ -z "$1" ] || [ -z "$2" ] || [ -z "$3" ]; then
|
||||
usage
|
||||
exit 1
|
||||
fi
|
||||
|
||||
OUTDIR="$1"
|
||||
CERTBASE="$2"
|
||||
CN="$3"
|
||||
SANS="$4"
|
||||
|
||||
if [ ! -d $OUTDIR ]; then
|
||||
echo "ERROR: output directory does not exist: $OUTDIR"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
OUTFILE="$OUTDIR/$CN.tar"
|
||||
|
||||
if [ -f "$OUTFILE" ];then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
CNF_TEMPLATE="
|
||||
[req]
|
||||
req_extensions = v3_req
|
||||
distinguished_name = req_distinguished_name
|
||||
|
||||
[req_distinguished_name]
|
||||
|
||||
[ v3_req ]
|
||||
basicConstraints = CA:FALSE
|
||||
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
|
||||
subjectAltName = @alt_names
|
||||
|
||||
[alt_names]
|
||||
DNS.101 = kubernetes
|
||||
DNS.102 = kubernetes.default
|
||||
DNS.103 = kubernetes.default.svc
|
||||
DNS.104 = kubernetes.default.svc.cluster.local
|
||||
"
|
||||
echo "Generating SSL artifacts in $OUTDIR"
|
||||
|
||||
|
||||
CONFIGFILE="$OUTDIR/$CERTBASE-req.cnf"
|
||||
CAFILE="$OUTDIR/ca.pem"
|
||||
CAKEYFILE="$OUTDIR/ca-key.pem"
|
||||
KEYFILE="$OUTDIR/$CERTBASE-key.pem"
|
||||
CSRFILE="$OUTDIR/$CERTBASE.csr"
|
||||
PEMFILE="$OUTDIR/$CERTBASE.pem"
|
||||
|
||||
CONTENTS="${CAFILE} ${KEYFILE} ${PEMFILE}"
|
||||
|
||||
|
||||
# Add SANs to openssl config
|
||||
echo "$CNF_TEMPLATE$(echo $SANS | tr ',' '\n')" > "$CONFIGFILE"
|
||||
|
||||
$OPENSSL genrsa -out "$KEYFILE" 2048
|
||||
$OPENSSL req -new -key "$KEYFILE" -out "$CSRFILE" -subj "/CN=$CN" -config "$CONFIGFILE"
|
||||
$OPENSSL x509 -req -in "$CSRFILE" -CA "$CAFILE" -CAkey "$CAKEYFILE" -CAcreateserial -out "$PEMFILE" -days 365 -extensions v3_req -extfile "$CONFIGFILE"
|
||||
|
||||
tar -cf $OUTFILE -C $OUTDIR $(for f in $CONTENTS;do printf "$(basename $f) ";done)
|
||||
|
||||
echo "Bundled SSL artifacts into $OUTFILE"
|
||||
echo "$CONTENTS"
|
||||
@@ -1,32 +0,0 @@
|
||||
#!/bin/bash -e
|
||||
|
||||
# define location of openssl binary manually since running this
|
||||
# script under Vagrant fails on some systems without it
|
||||
OPENSSL=/usr/bin/openssl
|
||||
|
||||
function usage {
|
||||
echo "USAGE: $0 <output-dir>"
|
||||
echo " example: $0 ./ssl/ca.pem"
|
||||
}
|
||||
|
||||
if [ -z "$1" ]; then
|
||||
usage
|
||||
exit 1
|
||||
fi
|
||||
|
||||
OUTDIR="$1"
|
||||
|
||||
if [ ! -d $OUTDIR ]; then
|
||||
echo "ERROR: output directory does not exist: $OUTDIR"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
OUTFILE="$OUTDIR/ca.pem"
|
||||
|
||||
if [ -f "$OUTFILE" ];then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# establish cluster CA and self-sign a cert
|
||||
$OPENSSL genrsa -out "$OUTDIR/ca-key.pem" 2048
|
||||
$OPENSSL req -x509 -new -nodes -key "$OUTDIR/ca-key.pem" -days 10000 -out "$OUTFILE" -subj "/CN=kube-ca"
|
||||
Reference in New Issue
Block a user