diff --git a/docs/advanced_sample_inventory/files/pod-security-admission-config.yaml b/docs/advanced_sample_inventory/files/pod-security-admission-config.yaml index 6aaaa5a..fbde7fa 100644 --- a/docs/advanced_sample_inventory/files/pod-security-admission-config.yaml +++ b/docs/advanced_sample_inventory/files/pod-security-admission-config.yaml @@ -1,8 +1,3 @@ -# This sample list was generated from: -# https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/psa-config-templates#exempting-required-rancher-namespaces -# For security reasons, this list should be as concise as possible -# only include active namespaces that need to be except from a restricted profile. - --- apiVersion: apiserver.config.k8s.io/v1 kind: AdmissionConfiguration diff --git a/docs/advanced_sample_inventory/group_vars/all.yaml b/docs/advanced_sample_inventory/group_vars/all.yaml index 64107ab..1ee2ec2 100644 --- a/docs/advanced_sample_inventory/group_vars/all.yaml +++ b/docs/advanced_sample_inventory/group_vars/all.yaml @@ -1,3 +1,4 @@ -rke2_install_version: v1.29.12+rke2r1 +--- +rke2_install_version: v1.29.12+rke2r1 cluster_rke2_config: - selinux: true \ No newline at end of file + selinux: true diff --git a/docs/advanced_sample_inventory/group_vars/rke2_servers.yaml b/docs/advanced_sample_inventory/group_vars/rke2_servers.yaml index 6f19fa8..b4928a8 100644 --- a/docs/advanced_sample_inventory/group_vars/rke2_servers.yaml +++ b/docs/advanced_sample_inventory/group_vars/rke2_servers.yaml @@ -1,3 +1,4 @@ +--- rke2_pod_security_admission_config_file_path: "{{ playbook_dir }}/docs/advanced_sample_inventory/files/pod-security-admission-config.yaml" rke2_audit_policy_config_file_path: "{{ playbook_dir }}/docs/advanced_sample_inventory/files/audit-policy.yaml" rke2_manifest_config_directory: "{{ playbook_dir }}/docs/advanced_sample_inventory/pre-deploy-manifests/" @@ -9,9 +10,9 @@ group_rke2_config: - cilium # Cilium will replace this disable-kube-proxy: true - profile: cis - pod-security-admission-config-file: /etc/rancher/rke2/pod-security-admission-config.yaml + profile: cis + pod-security-admission-config-file: /etc/rancher/rke2/pod-security-admission-config.yaml audit-policy-file: /etc/rancher/rke2/audit-policy.yaml kube-apiserver-arg: - audit-policy-file=/etc/rancher/rke2/audit-policy.yaml - - audit-log-path=/var/lib/rancher/rke2/server/logs/audit.log \ No newline at end of file + - audit-log-path=/var/lib/rancher/rke2/server/logs/audit.log diff --git a/docs/advanced_sample_inventory/post-deploy-manifests/cert-manager.yaml b/docs/advanced_sample_inventory/post-deploy-manifests/cert-manager.yaml index 408af96..332c0a2 100644 --- a/docs/advanced_sample_inventory/post-deploy-manifests/cert-manager.yaml +++ b/docs/advanced_sample_inventory/post-deploy-manifests/cert-manager.yaml @@ -1,3 +1,4 @@ +--- apiVersion: helm.cattle.io/v1 kind: HelmChart metadata: diff --git a/docs/advanced_sample_inventory/pre-deploy-manifests/cilium.yaml b/docs/advanced_sample_inventory/pre-deploy-manifests/cilium.yaml index cb5a7a5..7295e61 100644 --- a/docs/advanced_sample_inventory/pre-deploy-manifests/cilium.yaml +++ b/docs/advanced_sample_inventory/pre-deploy-manifests/cilium.yaml @@ -14,4 +14,3 @@ spec: preallocateMaps: true tproxy: true bpfClockProbe: true - diff --git a/docs/tarball_install_sample/group_vars/all.yaml b/docs/tarball_install_sample/group_vars/all.yaml index 9b641c5..cee1439 100644 --- a/docs/tarball_install_sample/group_vars/all.yaml +++ b/docs/tarball_install_sample/group_vars/all.yaml @@ -1,3 +1,4 @@ +--- rke2_install_local_tarball_path: "{{ playbook_dir }}/docs/tarball_install_sample/files/rke2.linux-amd64.tar.gz" -rke2_images_local_tarball_path: - - "{{ playbook_dir }}/docs/tarball_install_sample/files/rke2.linux-amd64.tar.gz" \ No newline at end of file +rke2_images_local_tarball_path: + - "{{ playbook_dir }}/docs/tarball_install_sample/files/rke2.linux-amd64.tar.gz"