forked from tim/k3s-ansible
249238c7a4
- Correct the Deploy metallb manifest/pool when condition so MetalLB is installed whenever kube-vip does not own the VIP range and Cilium BGP is disabled - The previous guard (cilium_bgp is not defined or cilium_iface is not defined) skipped MetalLB whenever cilium_iface was set, breaking the cilium + MetalLB scenario - Use cilium_bgp | default(false) | bool to stay safe when Cilium vars are not in scope (#644) while still deploying MetalLB for non-BGP Cilium - Retry the converge-side MetalLB resource wait so a transient kube API ServiceUnavailable does not abort the converge play - Add a regression test that evaluates both when conditions across flannel, calico, non-BGP cilium, BGP cilium, and kube-vip scenarios ci: skip CI for Dependabot pull requests - Add an actor guard to the CI workflow jobs so automatic Dependabot PRs do not consume the shared self-hosted runner - Dependabot CI runs need maintainer approval instead of auto-running
42 lines
1.1 KiB
YAML
42 lines
1.1 KiB
YAML
---
|
|
k3s_kubectl_binary: k3s kubectl
|
|
|
|
bpf_lb_algorithm: maglev
|
|
bpf_lb_mode: hybrid
|
|
|
|
calico_blockSize: 26 # noqa var-naming
|
|
calico_ebpf: false
|
|
calico_encapsulation: VXLANCrossSubnet
|
|
calico_natOutgoing: Enabled # noqa var-naming
|
|
calico_nodeSelector: all() # noqa var-naming
|
|
calico_tag: v3.32.1
|
|
|
|
cilium_bgp: false
|
|
cilium_exportPodCIDR: true # noqa var-naming
|
|
cilium_bgp_my_asn: 64513
|
|
cilium_bgp_peer_asn: 64512
|
|
cilium_bgp_neighbors: []
|
|
cilium_bgp_neighbors_groups: ['k3s_all']
|
|
cilium_bgp_lb_cidr: 192.168.31.0/24
|
|
cilium_hubble: true
|
|
cilium_mode: native
|
|
cilium_tag: v1.20.0
|
|
cilium_cli_tag: v0.19.7
|
|
|
|
# Shared retry/delay for remote manifest, asset downloads, and waiting on
|
|
# Kubernetes resources. The CI runner's resolver intermittently times out on
|
|
# GitHub-hosted domains and the kube API can transiently return
|
|
# ServiceUnavailable, so retry transient DNS/network/API failures.
|
|
download_retries: 5
|
|
download_delay: 10
|
|
|
|
cluster_cidr: 10.52.0.0/16
|
|
enable_bpf_masquerade: true
|
|
kube_proxy_replacement: true
|
|
group_name_master: master
|
|
|
|
metal_lb_mode: layer2
|
|
metal_lb_available_timeout: 240s
|
|
metal_lb_controller_tag_version: v0.16.0
|
|
metal_lb_ip_range: 192.168.30.80-192.168.30.90
|