Skip to content

Commit 98e655f

Browse files
authored
Merge pull request #4198 from zhzhuang-zju/tls1.3
set MinVersion to VersionTLS13 for tlsconfig
2 parents a4b1444 + 9ee49a5 commit 98e655f

File tree

9 files changed

+10
-0
lines changed

9 files changed

+10
-0
lines changed

artifacts/deploy/karmada-aggregated-apiserver.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,7 @@ spec:
4646
- --feature-gates=APIPriorityAndFairness=false
4747
- --audit-log-maxage=0
4848
- --audit-log-maxbackup=0
49+
- --tls-min-version=VersionTLS13
4950
resources:
5051
requests:
5152
cpu: 100m

artifacts/deploy/karmada-apiserver.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -62,6 +62,7 @@ spec:
6262
- --requestheader-username-headers=X-Remote-User
6363
- --tls-cert-file=/etc/karmada/pki/apiserver.crt
6464
- --tls-private-key-file=/etc/karmada/pki/apiserver.key
65+
- --tls-min-version=VersionTLS13
6566
name: karmada-apiserver
6667
image: registry.k8s.io/kube-apiserver:v1.25.4
6768
imagePullPolicy: IfNotPresent

artifacts/deploy/karmada-metrics-adapter.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,7 @@ spec:
4242
- --audit-log-path=-
4343
- --audit-log-maxage=0
4444
- --audit-log-maxbackup=0
45+
- --tls-min-version=VersionTLS13
4546
readinessProbe:
4647
httpGet:
4748
path: /readyz

artifacts/deploy/karmada-search.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,7 @@ spec:
4646
- --feature-gates=APIPriorityAndFairness=false
4747
- --audit-log-maxage=0
4848
- --audit-log-maxbackup=0
49+
- --tls-min-version=VersionTLS13
4950
livenessProbe:
5051
httpGet:
5152
path: /livez

charts/karmada/templates/karmada-aggregated-apiserver.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,7 @@ spec:
6565
- --feature-gates=APIPriorityAndFairness=false
6666
- --audit-log-maxage=0
6767
- --audit-log-maxbackup=0
68+
- --tls-min-version=VersionTLS13
6869
resources:
6970
{{- toYaml .Values.aggregatedApiServer.resources | nindent 12 }}
7071
readinessProbe:

charts/karmada/templates/karmada-apiserver.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -73,6 +73,7 @@ spec:
7373
- --tls-private-key-file=/etc/kubernetes/pki/karmada.key
7474
- --max-requests-inflight={{ .Values.apiServer.maxRequestsInflight }}
7575
- --max-mutating-requests-inflight={{ .Values.apiServer.maxMutatingRequestsInflight }}
76+
- --tls-min-version=VersionTLS13
7677
ports:
7778
- name: http
7879
containerPort: 5443

charts/karmada/templates/karmada-search.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -78,6 +78,7 @@ spec:
7878
- --feature-gates=APIPriorityAndFairness=false
7979
- --audit-log-maxage=0
8080
- --audit-log-maxbackup=0
81+
- --tls-min-version=VersionTLS13
8182
livenessProbe:
8283
httpGet:
8384
path: /livez

operator/pkg/controlplane/apiserver/mainfests.go

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,7 @@ spec:
5959
- --max-requests-inflight=1500
6060
- --max-mutating-requests-inflight=500
6161
- --v=4
62+
- --tls-min-version=VersionTLS13
6263
livenessProbe:
6364
failureThreshold: 8
6465
httpGet:
@@ -171,6 +172,7 @@ spec:
171172
- --feature-gates=APIPriorityAndFairness=false
172173
- --audit-log-maxage=0
173174
- --audit-log-maxbackup=0
175+
- --tls-min-version=VersionTLS13
174176
volumeMounts:
175177
- mountPath: /etc/karmada/kubeconfig
176178
name: kubeconfig

operator/pkg/controlplane/metricsadapter/mainfests.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,7 @@ spec:
4040
- --audit-log-path=-
4141
- --audit-log-maxage=0
4242
- --audit-log-maxbackup=0
43+
- --tls-min-version=VersionTLS13
4344
volumeMounts:
4445
- name: kubeconfig
4546
subPath: kubeconfig

0 commit comments

Comments
 (0)