mirror of
https://github.com/kubernetes-sigs/kubespray.git
synced 2026-02-28 09:39:12 +03:00
Revert "Drop linux capabilities and rework users/groups"
This commit is contained in:
@@ -1,40 +1,24 @@
|
||||
---
|
||||
addusers:
|
||||
etcd:
|
||||
name: "{{ etcd_user }}"
|
||||
name: etcd
|
||||
comment: "Etcd user"
|
||||
createhome: >-
|
||||
{% if ansible_os_family in ["CoreOS", "Container Linux by CoreOS"] %}no{% else %}yes{% endif %}
|
||||
createhome: yes
|
||||
home: "/var/lib/etcd"
|
||||
system: yes
|
||||
shell: /usr/sbin/nologin
|
||||
group: "{{ etcd_group }}"
|
||||
groups: "{{ etcd_cert_group }}"
|
||||
type: >-
|
||||
{% if ansible_os_family in ["CoreOS", "Container Linux by CoreOS"] %}cloud-init{% endif %}
|
||||
shell: /bin/nologin
|
||||
kube:
|
||||
name: "{{ kubelet_user }}"
|
||||
name: kube
|
||||
comment: "Kubernetes user"
|
||||
shell: /usr/sbin/nologin
|
||||
shell: /sbin/nologin
|
||||
system: yes
|
||||
group: "{{ kubelet_group }}"
|
||||
groups: "{{ etcd_cert_group }},{{ kube_cert_group }}"
|
||||
group: "{{ kube_cert_group }}"
|
||||
createhome: no
|
||||
netplug:
|
||||
name: "{{ netplug_user }}"
|
||||
comment: "Network plugin user"
|
||||
createhome: no
|
||||
system: yes
|
||||
shell: /usr/sbin/nologin
|
||||
group: "{{ netplug_group }}"
|
||||
groups: "{{ etcd_cert_group }}"
|
||||
|
||||
adduser:
|
||||
name: "{{ user.name }}"
|
||||
group: "{{ user.name|default(None) }}"
|
||||
groups: "{{ user.groups|default(None) }}"
|
||||
comment: "{{ user.comment|default(None) }}"
|
||||
shell: "{{ user.shell|default(None) }}"
|
||||
system: "{{ user.system|default(None) }}"
|
||||
createhome: "{{ user.createhome|default(None) }}"
|
||||
type: "{{ user.type|default(None) }}"
|
||||
|
||||
Reference in New Issue
Block a user