From 84972373d438294c9c2d91cbecc487b851afcc53 Mon Sep 17 00:00:00 2001 From: Dalton Hubble Date: Wed, 2 Dec 2020 23:13:53 -0800 Subject: [PATCH] Rename bootstrap-secrets directory to pki * Change control plane static pods to mount `/etc/kubernetes/pki`, instead of `/etc/kubernetes/bootstrap-secrets` to better reflect their purpose and match some loose conventions upstream * Require TLS assets to be placed at `/etc/kubernetes/pki`, instead of `/etc/kubernetes/bootstrap-secrets` on hosts (breaking) * Mount to `/etc/kubernetes/pki` to match the host (less surprise) * https://kubernetes.io/docs/setup/best-practices/certificates/ --- manifests.tf | 6 ++--- .../static-manifests/kube-apiserver.yaml | 24 +++++++++---------- .../kube-controller-manager.yaml | 16 ++++++------- .../static-manifests/kube-scheduler.yaml | 6 ++--- 4 files changed, 26 insertions(+), 26 deletions(-) diff --git a/manifests.tf b/manifests.tf index e4c659a..205d66c 100644 --- a/manifests.tf +++ b/manifests.tf @@ -46,9 +46,9 @@ locals { locals { aggregation_flags = <