summary refs log tree commit diff
path: root/nixos/tests/kubernetes/kubernetes-master.nix
blob: b9577fa0964b1a6095a5003fa3afbb56079af174 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
{ config, pkgs, certs }:
let
  etcd_key = "${certs}/etcd-key.pem";
  etcd_cert = "${certs}/etcd.pem";
  ca_pem = "${certs}/ca.pem";
  etcd_client_cert = "${certs}/etcd-client.crt";
  etcd_client_key = "${certs}/etcd-client-key.pem";

  apiserver_key = "${certs}/apiserver-key.pem";
  apiserver_cert = "${certs}/apiserver.pem";
  worker_key = "${certs}/worker-key.pem";
  worker_cert = "${certs}/worker.pem";


  rootCaFile = pkgs.writeScript "rootCaFile.pem" ''
    ${pkgs.lib.readFile "${certs}/ca.pem"}

    ${pkgs.lib.readFile ("${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt")}
  '';
in
{
  networking = {
    firewall = {
      enable = true;
      allowPing = true;
      allowedTCPPorts = [
        2379 2380  # etcd
        4443  # kubernetes
      ];
    };
  };

  services.etcd = {
    enable = pkgs.lib.mkForce true;
    keyFile = etcd_key;
    certFile = etcd_cert;
    trustedCaFile = rootCaFile;
    peerClientCertAuth = true;
    listenClientUrls = ["https://0.0.0.0:2379"];
    listenPeerUrls = ["https://0.0.0.0:2380"];

    advertiseClientUrls = ["https://etcd.kubernetes.nixos.xyz:2379"];
    initialCluster = ["master=https://etcd.kubernetes.nixos.xyz:2380"];
    initialAdvertisePeerUrls = ["https://etcd.kubernetes.nixos.xyz:2380"];
  };
  services.kubernetes = {
    roles = ["master"];
    scheduler.leaderElect = true;
    controllerManager.leaderElect = true;
    controllerManager.rootCaFile = rootCaFile;
    controllerManager.serviceAccountKeyFile = apiserver_key;
    apiserver = {
      securePort = 4443;
      publicAddress = "192.168.1.1";
      advertiseAddress = "192.168.1.1";
      tlsKeyFile = apiserver_key;
      tlsCertFile = apiserver_cert;
      clientCaFile = rootCaFile;
      kubeletClientCaFile = rootCaFile;
      kubeletClientKeyFile = worker_key;
      kubeletClientCertFile = worker_cert;
      portalNet = "10.1.10.0/24";  # --service-cluster-ip-range
      runtimeConfig = "";
      /*extraOpts = "--v=2";*/
      authorizationMode = ["ABAC"];
      authorizationPolicy = [
        {
          apiVersion = "abac.authorization.kubernetes.io/v1beta1";
          kind = "Policy";
          spec = {
            user  = "kubecfg";
            namespace = "*";
            resource = "*";
            apiGroup = "*";
            nonResourcePath = "*";
          };
        }
        {
          apiVersion = "abac.authorization.kubernetes.io/v1beta1";
          kind = "Policy";
          spec = {
            user  = "kubelet";
            namespace = "*";
            resource = "*";
            apiGroup = "*";
            nonResourcePath = "*";
          };
        }
        {
          apiVersion = "abac.authorization.kubernetes.io/v1beta1";
          kind = "Policy";
          spec = {
            user  = "kube-worker";
            namespace = "*";
            resource = "*";
            apiGroup = "*";
            nonResourcePath = "*";
          };
        }
        {
          apiVersion = "abac.authorization.kubernetes.io/v1beta1";
          kind = "Policy";
          spec = {
            user  = "kube_proxy";
            namespace = "*";
            resource = "*";
            apiGroup = "*";
            nonResourcePath = "*";
          };
        }
        {
          apiVersion = "abac.authorization.kubernetes.io/v1beta1";
          kind = "Policy";
          spec = {
            user  = "client";
            namespace = "*";
            resource = "*";
            apiGroup = "*";
            nonResourcePath = "*";
          };
        }
        {
          apiVersion = "abac.authorization.kubernetes.io/v1beta1";
          kind = "Policy";
          spec = {
            group  = "system:serviceaccounts";
            namespace = "*";
            resource = "*";
            apiGroup = "*";
            nonResourcePath = "*";
          };
        }
        {
          apiVersion = "abac.authorization.kubernetes.io/v1beta1";
          kind = "Policy";
          spec = {
            group  = "system:authenticated";
            readonly = true;
            namespace = "*";
            resource = "*";
            apiGroup = "*";
            nonResourcePath = "*";
          };
        }
      ];
    };
  };
}