commit d79fb45ba3f08980d42b9cde57ac53112b5f26cd Author: Feilong Wang Date: Tue Sep 1 06:56:09 2020 +1200 Remove cloud-config from k8s worker node Now Magnum is not deploying any service or workload on k8s worker nodes which need to get credentials from local to talk to Magnum control plane. So the cloud-config file should be removed from worker nodes to reduce the attach surface from a security point of view. Task: 40791 Story: 2008090 Change-Id: I72e418491cbd19291527bbe4b504d599c740fea9 (cherry picked from commit c84653cd74d4981430096d4a9494ba8827a34caa) diff --git a/magnum/drivers/k8s_fedora_coreos_v1/templates/kubeminion.yaml b/magnum/drivers/k8s_fedora_coreos_v1/templates/kubeminion.yaml index 1e34d80..3e4f040 100644 --- a/magnum/drivers/k8s_fedora_coreos_v1/templates/kubeminion.yaml +++ b/magnum/drivers/k8s_fedora_coreos_v1/templates/kubeminion.yaml @@ -480,7 +480,6 @@ resources: $CONTAINERD_TARBALL_SHA256: {get_param: containerd_tarball_sha256} - get_file: ../../common/templates/kubernetes/fragments/install-cri.sh - get_file: ../../common/templates/kubernetes/fragments/install-clients.sh - - get_file: ../../common/templates/kubernetes/fragments/write-kube-os-config.sh - get_file: ../../common/templates/kubernetes/fragments/make-cert-client.sh - get_file: ../../common/templates/fragments/configure-docker-registry.sh - get_file: ../../common/templates/kubernetes/fragments/configure-kubernetes-minion.sh