Skip to content

Commit

Permalink
Add containerd_extra_args (kubernetes-sigs#7461)
Browse files Browse the repository at this point in the history
* Add containerd_extra_args

This is useful for custom containerd config, e.g. auth

Signed-off-by: Zhong Jianxin <[email protected]>

* Make containerd config.toml mode 0640

It may contain sensitive information like password

Signed-off-by: Zhong Jianxin <[email protected]>
  • Loading branch information
azuwis authored Apr 12, 2021
1 parent 90c643f commit 420a412
Show file tree
Hide file tree
Showing 3 changed files with 8 additions and 1 deletion.
3 changes: 3 additions & 0 deletions roles/container-engine/containerd/defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -64,3 +64,6 @@ containerd_fedora_repo_base_url: "https://download.docker.com/linux/fedora/{{ an
containerd_fedora_repo_gpgkey: "https://download.docker.com/linux/fedora/gpg"
containerd_fedora_repo_repokey: "9DC858229FC7DD38854AE2D88D81803C0EBFCD88"
containerd_fedora_repo_component: "stable"

# Extra config to be put in {{ containerd_cfg_dir }}/config.toml literally
containerd_extra_args: ''
2 changes: 1 addition & 1 deletion roles/container-engine/containerd/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,7 +79,7 @@
src: config.toml.j2
dest: "{{ containerd_cfg_dir }}/config.toml"
owner: "root"
mode: 0644
mode: 0640
notify: restart containerd

# This is required to ensure any apt upgrade will not break kubernetes
Expand Down
4 changes: 4 additions & 0 deletions roles/container-engine/containerd/templates/config.toml.j2
Original file line number Diff line number Diff line change
Expand Up @@ -39,3 +39,7 @@ version = 2
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."{{ registry }}"]
endpoint = ["{{ ([ addr ] | flatten ) | join('","') }}"]
{% endfor %}

{% if containerd_extra_args is defined %}
{{ containerd_extra_args }}
{% endif %}

0 comments on commit 420a412

Please sign in to comment.