Advertisement
Guest User

Untitled

a guest
Oct 9th, 2019
319
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
YAML 6.40 KB | None | 0 0
  1. admissionConfig:
  2.   pluginConfig:
  3.     BuildDefaults:
  4.       configuration:
  5.         apiVersion: v1
  6.         env: []
  7.         kind: BuildDefaultsConfig
  8.         resources:
  9.           limits: {}
  10.           requests: {}
  11.     BuildOverrides:
  12.       configuration:
  13.         apiVersion: v1
  14.         kind: BuildOverridesConfig
  15.     PodPreset:
  16.       configuration:
  17.         apiVersion: v1
  18.         disable: false
  19.         kind: DefaultAdmissionConfig
  20.     PodNodeConstraints:
  21.       configuration:
  22.         apiversion: v1
  23.         kind: PodNodeConstraintsConfig
  24.         nodeSelectorLabelBlacklist:
  25.          - processor=gpu      
  26.     openshift.io/ImagePolicy:
  27.       configuration:
  28.         apiVersion: v1
  29.         executionRules:
  30.         - matchImageAnnotations:
  31.           - key: images.openshift.io/deny-execution
  32.             value: 'true'
  33.           name: execution-denied
  34.           onResources:
  35.           - resource: pods
  36.           - resource: builds
  37.           reject: true
  38.           skipOnResolutionFailure: true
  39.         kind: ImagePolicyConfig
  40.    
  41. aggregatorConfig:
  42.   proxyClientInfo:
  43.     certFile: aggregator-front-proxy.crt
  44.     keyFile: aggregator-front-proxy.key
  45. apiLevels:
  46. - v1
  47. apiVersion: v1
  48. authConfig:
  49.   requestHeader:
  50.     clientCA: front-proxy-ca.crt
  51.     clientCommonNames:
  52.    - aggregator-front-proxy
  53.     extraHeaderPrefixes:
  54.    - X-Remote-Extra-
  55.     groupHeaders:
  56.    - X-Remote-Group
  57.     usernameHeaders:
  58.    - X-Remote-User
  59. controllerConfig:
  60.   election:
  61.     lockName: openshift-master-controllers
  62.   serviceServingCert:
  63.     signer:
  64.       certFile: service-signer.crt
  65.       keyFile: service-signer.key
  66. controllers: '*'
  67. corsAllowedOrigins:
  68. - (?i)//127\.0\.0\.1(:|\z)
  69. - (?i)//localhost(:|\z)
  70. - (?i)//192\.168\.1\.10(:|\z)
  71. - (?i)//195\.201\.246\.239(:|\z)
  72. - (?i)//openshift\.default\.svc(:|\z)
  73. - (?i)//172\.30\.0\.1(:|\z)
  74. - (?i)//kubernetes\.default\.svc\.cluster\.local(:|\z)
  75. - (?i)//kubernetes(:|\z)
  76. - (?i)//os\-master(:|\z)
  77. - (?i)//os\-master\.xxxxxxx\.com(:|\z)
  78. - (?i)//openshift\.default(:|\z)
  79. - (?i)//kubernetes\.default(:|\z)
  80. - (?i)//openshift\.default\.svc\.cluster\.local(:|\z)
  81. - (?i)//kubernetes\.default\.svc(:|\z)
  82. - (?i)//openshift(:|\z)
  83. dnsConfig:
  84.   bindAddress: 0.0.0.0:8053
  85.   bindNetwork: tcp4
  86. etcdClientInfo:
  87.   ca: master.etcd-ca.crt
  88.   certFile: master.etcd-client.crt
  89.   keyFile: master.etcd-client.key
  90.   urls:
  91.  - https://os-master:2379
  92. etcdStorageConfig:
  93.   kubernetesStoragePrefix: kubernetes.io
  94.   kubernetesStorageVersion: v1
  95.   openShiftStoragePrefix: openshift.io
  96.   openShiftStorageVersion: v1
  97. imageConfig:
  98.   format: openshift/origin-${component}:${version}
  99.   latest: false
  100. imagePolicyConfig:
  101.   MaxScheduledImageImportsPerMinute: 10
  102.   ScheduledImageImportMinimumIntervalSeconds: 1800
  103.   disableScheduledImport: false
  104.   maxImagesBulkImportedPerRepository: 3
  105. kind: MasterConfig
  106. kubeletClientInfo:
  107.   ca: ca-bundle.crt
  108.   certFile: master.kubelet-client.crt
  109.   keyFile: master.kubelet-client.key
  110.   port: 10250
  111. kubernetesMasterConfig:
  112.   apiServerArguments:
  113.     feature-gates:
  114.    - ExpandPersistentVolumes=true
  115.     runtime-config:
  116.    - apis/settings.k8s.io/v1alpha1=true
  117.     storage-backend:
  118.    - etcd3
  119.     storage-media-type:
  120.    - application/vnd.kubernetes.protobuf
  121.   controllerArguments:
  122.   feature-gates:
  123.  - ExpandPersistentVolumes=true
  124.   masterCount: 1
  125.   masterIP: 192.168.1.10
  126.   podEvictionTimeout:
  127.   proxyClientInfo:
  128.     certFile: master.proxy-client.crt
  129.     keyFile: master.proxy-client.key
  130.   schedulerArguments:
  131.   schedulerConfigFile: /etc/origin/master/scheduler.json
  132.   servicesNodePortRange: ""
  133.   servicesSubnet: 172.30.0.0/16
  134.   staticNodeNames: []
  135. masterClients:
  136.   externalKubernetesClientConnectionOverrides:
  137.     acceptContentTypes: application/vnd.kubernetes.protobuf,application/json
  138.     burst: 400
  139.     contentType: application/vnd.kubernetes.protobuf
  140.     qps: 200
  141.   externalKubernetesKubeConfig: ""
  142.   openshiftLoopbackClientConnectionOverrides:
  143.     acceptContentTypes: application/vnd.kubernetes.protobuf,application/json
  144.     burst: 600
  145.     contentType: application/vnd.kubernetes.protobuf
  146.     qps: 300
  147.   openshiftLoopbackKubeConfig: openshift-master.kubeconfig
  148. masterPublicURL: https://xxxxxxx
  149. networkConfig:
  150.   clusterNetworkCIDR: 10.128.0.0/14
  151.   clusterNetworks:
  152.   - cidr: 10.128.0.0/14
  153.     hostSubnetLength: 9
  154.   externalIPNetworkCIDRs:
  155.  - 0.0.0.0/0
  156.   hostSubnetLength: 9
  157.   networkPluginName: redhat/openshift-ovs-subnet
  158.   serviceNetworkCIDR: 172.30.0.0/16
  159. oauthConfig:
  160.   assetPublicURL: xxxxxxxxxxxx
  161.   grantConfig:
  162.     method: auto
  163.   identityProviders:
  164.   - challenge: true
  165.     login: true
  166.     mappingMethod: claim
  167.     name: Active_Directory
  168.     provider:
  169.       apiVersion: v1
  170.       attributes:
  171.         email:
  172.        - mail
  173.         id:
  174.        - dn
  175.         name:
  176.        - cn
  177.         preferredUsername:
  178.        - userPrincipalName
  179.       bindDN: xxxxxxxx
  180.       bindPassword: xxxxxxxxxxxx
  181.       ca: /etc/ssl/certs/xxxxxxx
  182.       insecure: false
  183.       kind: LDAPPasswordIdentityProvider
  184.       url: xxxxxxxxxxxxxx
  185.   masterCA: ca-bundle.crt
  186.   masterPublicURL: https://xxxxxxxxxx
  187.   masterURL: https://os-master:8443
  188.   sessionConfig:
  189.     sessionMaxAgeSeconds: 3600
  190.     sessionName: ssn
  191.     sessionSecretsFile: /etc/origin/master/session-secrets.yaml
  192.   tokenConfig:
  193.     accessTokenMaxAgeSeconds: 86400
  194.     authorizeTokenMaxAgeSeconds: 500
  195. pauseControllers: false
  196. policyConfig:
  197.   bootstrapPolicyFile: /etc/origin/master/policy.json
  198.   openshiftInfrastructureNamespace: openshift-infra
  199.   openshiftSharedResourcesNamespace: openshift
  200. projectConfig:
  201.   defaultNodeSelector: "region=primary"
  202.   projectRequestMessage: ""
  203.   projectRequestTemplate: ""
  204.   securityAllocator:
  205.     mcsAllocatorRange: s0:/2
  206.     mcsLabelsPerProject: 5
  207.     uidAllocatorRange: 1000000000-1999999999/10000
  208. routingConfig:
  209.   subdomain: xxxx
  210. serviceAccountConfig:
  211.   limitSecretReferences: false
  212.   managedNames:
  213.  - default
  214.   - builder
  215.   - deployer
  216.   masterCA: ca-bundle.crt
  217.   privateKeyFile: serviceaccounts.private.key
  218.   publicKeyFiles:
  219.  - serviceaccounts.public.key
  220. servingInfo:
  221.   bindAddress: 0.0.0.0:8443
  222.   bindNetwork: tcp4
  223.   certFile: master.server.crt
  224.   clientCA: ca.crt
  225.   keyFile: master.server.key
  226.   maxRequestsInFlight: 500
  227.   namedCertificates:
  228.   - certFile: /etc/ssl/wild-certs/fullchain.pem
  229.     keyFile: /etc/ssl/wild-certs/privkey.pem
  230.     names:
  231.    - xxxxxx
  232.   requestTimeoutSeconds: 3600
  233. volumeConfig:
  234.   dynamicProvisioningEnabled: true
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement