Skip to content

Commit c3573df

Browse files
committed
fix required keys for apiserver
Keys --service-account-issuer --service-account-signing-key-file are now required. aenix-io/kubefarm#2
1 parent 23f8396 commit c3573df

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

deploy/helm/kubernetes/templates/apiserver-deployment.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -80,9 +80,9 @@ spec:
8080
- --tls-cert-file=/pki/apiserver-server/tls.crt
8181
- --tls-private-key-file=/pki/apiserver-server/tls.key
8282
- --egress-selector-config-file=/etc/kubernetes/egress-selector-configuration.yaml
83-
{{- if .Values.konnectivityAgent.enabled }}{{"\n"}}
84-
- --service-account-issuer=api
83+
- --service-account-issuer=https://kubernetes.default.svc.cluster.local
8584
- --service-account-signing-key-file=/pki/sa/tls.key
85+
{{- if .Values.konnectivityAgent.enabled }}{{"\n"}}
8686
- --api-audiences=system:konnectivity-server
8787
{{- end }}
8888
{{- if not (hasKey .Values.apiServer.extraArgs "advertise-address") }}

0 commit comments

Comments
 (0)