Add protectKernelDefaults option (default true) to kubelet config file (#6611)

This commit is contained in:
Florian Ruynat
2020-09-03 16:41:41 +02:00
committed by GitHub
parent c1ba8e1b3a
commit f1566cb8c2
3 changed files with 19 additions and 0 deletions

View File

@@ -61,3 +61,16 @@
value: 1
state: present
reload: yes
- name: Ensure kube-bench parameters are set
sysctl:
sysctl_file: /etc/sysctl.d/bridge-nf-call.conf
name: "{{ item.name }}"
value: "{{ item.value }}"
state: present
reload: yes
with_items:
- { name: vm.overcommit_memory, value: 1 }
- { name: kernel.panic, value: 10 }
- { name: kernel.panic_on_oops, value: 1 }
when: kubelet_protect_kernel_defaults|bool