From 01361b721759e562585bcd6c30ee43e7c440dfe7 Mon Sep 17 00:00:00 2001 From: Ivan Malison Date: Sun, 29 Sep 2024 17:28:42 -0600 Subject: [PATCH] [NixOS] Kubelet->gke kind of works but not really --- nixos/kubelet-client.crt | 23 ++++++++++++++++++ nixos/kubelet.nix | 7 +++--- .../secrets/api_service_account_key.json.age | Bin 4262 -> 4262 bytes 3 files changed, 27 insertions(+), 3 deletions(-) create mode 100644 nixos/kubelet-client.crt diff --git a/nixos/kubelet-client.crt b/nixos/kubelet-client.crt new file mode 100644 index 00000000..eb28f774 --- /dev/null +++ b/nixos/kubelet-client.crt @@ -0,0 +1,23 @@ +-----BEGIN CERTIFICATE----- +MIIDyTCCAjGgAwIBAgIRAMQBZiVjA5BGSkDldScI9cMwDQYJKoZIhvcNAQELBQAw +LzEtMCsGA1UEAxMkM2I2N2M2NzgtNzI5My00YTIzLTg3ZWItY2NiMTZjYWFkMzFm +MB4XDTI0MDkyOTIwNTAzNloXDTI5MDkyODIwNTIzNlowOTEVMBMGA1UEChMMc3lz +dGVtOm5vZGVzMSAwHgYDVQQDExdzeXN0ZW06bm9kZTpyeXplbi1zaGluZTCCASIw +DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANIOfbq05IIdgX2jXYLaEt66rkXp +NlqPNfh6v9nL1Aw6PSM3DEIWXVko8AyduRF4kXNO6xc6l/Rzk03w3qSvJpWpALGD +JjslgRL4VJWUC6/QydsCO9io7SoUEmXFtDcsW6DftFejosr+56ZnVFrz5MMzfUAL +Ix6n83NJvXZ8f9oHSX8TFW34ZClLxDq2fprFIs+D2QlFRE50Jr/Q8gPI2OSQDUBW +DFdQrjt81bLs6doQipUqvHb4/Ms49agHek1ceWIMf+KZWoao5KNQTBe6XL2BUgA/ +MS3ZvQppDDTygA0QkgdtOJyG2lsrAmd7LEXTr9ilsqLV3YQMMKhCifwINa0CAwEA +AaNWMFQwDgYDVR0PAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMAwGA1Ud +EwEB/wQCMAAwHwYDVR0jBBgwFoAUjvcbOeZ4QIk53EkATOaOFiAZUq0wDQYJKoZI +hvcNAQELBQADggGBAELWgmdmg9TKjDDqmF6pYr1j43gZYclXW4sB509itSiIeltX +Isrvn5R5ok0W5Jcl+7QMhpntqIKJi26OqbcdBhqlaVURkBkbrx8aegkWJfPO+Fzz +NyyiIpk7KQzGy6N5//jfMPZtJfQEQZwMenW0cj7F0QHOdVZy90+JNr2P3uV3Ad7u +WZuYpbOFjOeQg1hJsX8wEU4KJyptn/kXhM+CqAnQ4S+k2wpjECD8KpWKAmpJWZg0 +RaBPyHZSmWnbXqs4LU6ERaZJxZQG0ODuA18DmGfaAkUUUvE2J0ploc2Y8Xl4zUWW +Ivwslyx30YO3J9qI30d9tTQw/A0vHCoDNDbCg7lorZqP3TiTG9ANLndPqqg6inYU +yfj612//JrO8w/4qh7cxR03P35aK0paLC74FaKLtZ5CwPK3BAW/0Zhv5fH4io6hE +rfJmcjhbKD0Cwr9Dn6wVFz/a33H+0vMohHrVlDk4bSDIymbuJcZpYgR8n5WNQbGu +nwjiLXCnVxcVjkcj2w== +-----END CERTIFICATE----- diff --git a/nixos/kubelet.nix b/nixos/kubelet.nix index 802c031c..bf20bfca 100644 --- a/nixos/kubelet.nix +++ b/nixos/kubelet.nix @@ -6,16 +6,17 @@ makeEnable config "myModules.kubelet" false { kubeconfig = { server = "https://34.31.205.230"; caFile = ./railbird-kubernetes.crt; + certFile = ./kubelet-client.crt; keyFile = config.age.secrets."api_service_account_key.json.age".path; }; registerNode = true; cni = { - packages = [ pkgs.cni-plugins ]; + packages = [ pkgs.cni-plugins pkgs.calico-cni-plugin ]; }; extraOpts = '' --fail-swap-on=false - --container-runtime=remote - --container-runtime-endpoint=unix:///run/containerd/containerd.sock + # --container-runtime=remote + # --container-runtime-endpoint=unix:///run/containerd/containerd.sock ''; }; } diff --git a/nixos/secrets/api_service_account_key.json.age b/nixos/secrets/api_service_account_key.json.age index af53f5ff07c69f9a6b5c96a83b9ca117da1eb110..29aa33e763aa7295191f8da11e83c59fab5e572c 100644 GIT binary patch literal 4262 zcmZXV=bsaW+J+IN1w>FOQVwB75#y4XOp-}JftmE4Nir#;3#3dYeOi*q1Xx&C6p-d& z0asmQsj>Npf`SMLh~hz5iu5A*`r-Bc0Dr;td+y)$+;^BFE6H4x6PbLH z&JCeCN?rsdmBXbxpQt2b3Y7}fN(qYdv51rsy`nlDGn=hWb%yr)m7FKTWpL7=5#7EJ zf;t6nfYzpYZw`?75_&URfGw)DJ8o9T!|FmQK(Pje+y!t20}TuLm^|k+216kI2rZ1p zyp*)e7s{+EMWjka4VQz$C1)g=VX{_2i!+5{!NKMdZh;5G7>G&yDDKe6J$BGu4Cw4O zzM%8jogks1NP;Yr8mizTP@gO4F=`&6In0EZ5u^%@t5goL5R*iyK*n#w%OGsFn|);s z#Oh!h&a-YW;#b;~8A`&UOj1FxB$o?Ev$22$kc&K%MhIUK%d&z_8*|%Sb_ycY2E)U* z@fMs?Q__F}RnRtyH**=i#c2@oUexN0hfpB^Wf(;;SM=)1RM2h9>qC-g+{%>{4q3{D zdyG1F*bpjf&@_x-g|Lc_=ya)=M;=Moz(h3kFwK_>=LAgZ&gYDgEL1YY7|~ER1A<&G zSWRM#$|qSf1c|&iQE;aVAf_-#A`oRP$Pip6L@{U33NxSqQR+j0=;ShnL^7H82wK#@ z>$L**4~^r)QcAFv08A23i`lSC=fUJ@8dc^9r_aKoPKabpDz`DnM*~5aX3T!2F`r6n zO9E43IM@?*$fBqkQo==@#A?r@M#P!rJt8hDQ|X*tPub&Q7BLYnUkET!9y}KJh6660 z%dSho6bM?)eml#%Jce=!rZW5?-5m`}YkProD$r=l}O2(W=V{rPTrc@+p(nR8gU_KHTf@qwJ zAr5)M8dN!Dtb&L|QoIg#xq}E}HyP8U1S<&&PqG;OTP2!SYmKmpG0H)_6w)gqCcVy{ zK}yMpoI>p(pCYBxSePV+6+xa(>QcsFlt&~)$se%<@KiC7)G8dJPgQmiLFAvb|M|&~ z(L$RMsVu9`>2f+d1}FK!(XB9*ghTt0Kwl+Zj(vtjWhEl7D+(4tN=de#Z>rZATzl5URx zYM2~?p~b8sKr$)H7YJ}6A1+Bb&2}!4$8;1bcW5Y`)na3qJWG}eUO9jnNOL5KF#_R= zIHC{J(%z`0L`e${KWk!O(!wH2!pC4S2VB%B3XIhuA{Z1EOn{A~ykRDv#U(O=MO=^x zMq^eVmmqmm=>~bDRWBAYpfaozFm2J`COstYQa(&GmxEwgkZN$f!(oX)v<^3yElvmT zD%&mkLIJk=^IC;BLolA0%!~UNGcUpOX|sSAa)DU5WYQzNBdb>kb{KQzfgqT`tbl}_q7CrEbP07uoJ^$XmKSogN|_YWCNcygTFOA>MaUv4V7Rv! zM~o28b3ihy;e)h|)0b47hU0Q}G>HN+E}RS%;lK5LsJTH}5d;KjKCic9L8}o@X0^D? zXNu~4F;fsOvjD;*EDS27T}p+H(%7@KL?s%mR=qnIr<0`Jp@ijPB3ppuE^U+sJsBJC z@ufJenT%>h%fmDqrb^<7G{RA^0gW3HwsI6oxZGUSud`6BQzuyUML}NXp`4j;K*qQ) zD)EVcLz{)8xWOw#g3d$%m6M*lx?t8pr9eSm4ud*XK$CW;m`9o$v6<3(LF&TwkW6r- za2Jr_R2jnUX9&3-RdN=&%B)7cnAfWjL=^NUloCraWiM)Jx2P|16vx=Cu-n4~y|E%4 zu)yvj8w`hGb2%K$h9CJifb^$>Sy@YUL9u z5O=B!fJDe3I2bG|C@@aN(s_ANZ{m2bJLHxJ6@W;|-71DMhRiWl;So!;a;2LSq)bK* zW^h-6)1>Hxf#YQyttrKT0BMcW4j`3xIzfLVmq}<1yd+Pm{Th>pjfrB4g0cZRZFG@x zqdryEG8P!f7l1%n0m?;`e`F^pBn`;?V%7%8 zc;Jzq^f3SdVp2HiPnnaT!3uI5t5cOA9OR0mFQhB@xkNFbje8S-Pe4_W36sdYMl)i= zg9)$Bk@Hh3O*SLu?4kwC8B&lki^?MzpGO5l2ITJ~D=VcU3g_{1K8UFF6p%|0etX8r z%HjZnW=Y(hb)bGlhDU5FG+~h3vCjTZe7EyDL*p62| zcq9KuXy=z_yUv{a@4ue-%4)evd>e~3^?P~FQM3Q;_Vu>ySC1~c`SXZ`;n+Zb)8xGi z`_{LaH*Em^iGuv{*vu7EcAu(g41G4U=jm0i<6Bzonl`0F_wqYSsz>d(GElPq3;V5? zPhF|M9sG9K7VI6*mL5&fHHQ|658iB)!dI&Hv^hAq=hTz!&NZ(2DF#iv+_L%GCjZOj zF5%UdOD~?Tt(m@hNmG+l^5UCg%l$6uIN7RM^XE*tWclU5H-iT>?dsGxaP!`Yva{Pi zng7L8$L{P|GsyOA^MOlWrIx%V-B?lB=IgCEcf#H?{2M*{>J;G$NaGRd-li8 ztDvgr;uYP`+_~B3a#HrSX4J18b~k==t?k~w`t3Czslt)w%I6wQg<}j|8}; zE*;-EwqeHA5r!GB4m-8Ka@@M$xbS!Xt!w^c&@&Es71#aaUdQgxA8pxPZ+QOXD=mGW z9uevJU*G+E!QO8EbjypdY@ZNjpg@t>jZEJ?EPKlDwVed!BUEcf= z&%N92w>GLVzE+EF8#kW4InU9h2fwv;S7V*lc;-m&gKsX-XW3iJ(+wTQ-jVn2TUmG| z)9+Bz&tu#5p)WA;fjci0Z_S(W`IR5u`s_y6>d~t%9)I!h@NfC)6HAxI{qX6u_>8$L z_f3ie6W8|23HNWg2K0HozL56aM#VXu*Y5kzq6w|%O`fq}apUUEudmuXcR+GquOEM( z^5Ie%zVKV7tNqY~bwA94B(3g_8Pd|K2i!2DTT!=ATYjnYxf9b>+p4Rt8+Yom2YW5M z{ItE>+(NhX^wIo$2mNAQlGudO+~2=BC-fHLsjx#1rh z-ukA2Ha>WJ1F`en_rBk6$}j4+P%~ZrHdAU|?!ReXYd0-uH6iI?&%CrA?s)y+)NcIt z8U)H5Bo?uD0jo#0sV z#*Z`a24*q`*BlvdY~HcukHO5IT^B5aRxaO=Uq1E8)eWyK>;GZsixYzTzZP`Rdv5A`VQ9r@V>fp;ZMfi0)}v{zB=1*bWkTh->cKJVE1{echp^O zUU_Nv{hLV719hjS=lK^==Mn!ii~Ii7uXnn3-Tb#!7L%Fh&>>4F5xZ6K*?s&co30*2 z#+GkQ?R-1DX!^*m*ZLo9Ayz%!uy*U?@98U!-04tl@88n;;MI*ommMGc0Xwbb6{b2p zebo7?DU-9^=F-Ej-Kbp(H7y=aZrr`-%1_PgF1zIH){(VKb04>_{&W17pH{#N6odbB zxlMFg)sP+Do&P>|6mEyvPM;Z(^0a{WfZJ0B&E9)&^w`CToYOw^Tt)QNmu1i2?M@AN zvPM1e>Ye`d;V1hX6#CwK_U`mUk(#Pq?A~ijm}w8%4y~w7u6&|bp()Yju{#Sdr*~CO z)>kyV*-wA6_Q?wq+V0C_g4*{jof#7`QoYtbtd!5#@}}Je{RX> zfj4Fop^g1&Ccg1Py50YbYWaFidm}e^9lf8Q+_1m0ewoSW^wzceb?f_m$Vu$g*0&ce zd#4M!u*XGx&EAy*OW8dQ<5kNm)@>hx8!tTVe&KKlzk0TJed^}IxASXTA35ZIyLNx& z*sQU@AwSWo&#((M6%Rh`y}G^b?(gf5uj+g(o7hVf z)=uc(GUQHqd0l(Osa5P+17h(n{w<$-_^ceNl-)o2+@b)zfxJ z4}9GF+U&%Uc_ZH?y41~RJ)tu*^&UUpv~8$*w#k`LoUR4ysy@Q1N5ye@)7! zNcSeHZseXbWG6qeAHB5rUVh8rUn-v)+$`aC_^%kQ4QfR;uH68~H#{b+dZFd1uT}Lc pCG&{-uix6&FwT#Rn>eK0>%_NRemdIirE~i2(s=`_#yig&{}ZZvW+E^WU|4bIN2u4WSLC1i3nzyOx8&DvOk*vQ$O&R!80wKk{Ca}QB33-@ z0ZSY#2^-CZ5XTqgCX|tJ9#Je9HApgmiAkvhK$46oR8f`A#CfzdhdZ=R+>tUQfI`9% zXQ78^L2U%5#4Z|D22_mR;FOZ~XjtYVt)XyAsx*{@kTT&e@L9yB@|vZAQc_fOTZ&Q6 zH`9`^y#j8NcJQeT2_F#&%{Vz+w=Nw1}V>KSXI9B+p7coEos;&H{7aAOW-~ zm9!2iKqR3TC@;ts>4+2p9CXR7c7t{~k|O~rPl~jGY?7rzeki9>*i7CckqAXFfmTM~ zWVEOyF=dV;>_)~>NZ^oPYKn0squk@mnS+=DPr1BVkzELZnM_h)AWP<`31X(!vvn3@a4V>Xr(5Uxa-^%mF@7YH5_>2m%6 z6U)XFunJRg1Zwqpa}h+4qH>uc>&*&?SLYCK}o+SU6e&o zfs|)c7KxU@OXfm|3#<8<&*MWFr4{ErB1VGQ0}!9`5plK680SDo+V9WOm|D=05>k&! z18&5Ka1d@XJV;C8VKYyOAxX>zXgHWmIGlFWo{Y$F4~s`jvVvExEXD8J#z*fL37>Ff zL|ztA#)D}-rNk5R2y94uFbst<0!+rj8*@IjhM@Jj_woL3Zl4qs6p zENQcTvlX}da5EmJgD%3(YZFYCH%hG*91lj4kO;?dXH)}c0!5RIR|ial#x5w0G1MBe zvf+$f9ddc~w!Gay+<*H(m;R%q(;k!yR#WoA9vx!n1h4ODCtN(q@*+>^MjlifH9}b ztSmaio&+tG*{uQ>cSIf8kd81(HK06INH`U?0vk?+MUdAKO2>J#l(1SYcCVC6I0cNt zbcT?}X}~owfTjf~m(S@5&%?7R;vQHmHS-)=uB$>K(3P(B5}LbU}x|D4j^Pk zDIW1cWSHheq|Fq|xpElLVz)v<-K{O%_Rr^zi<9Y0Bl8) zdQNPKm{gijK&ys)GHnS`tNG>QaFkAQ;Ze&1p!amg(cxlmL=eJU}KW z8)@^BP}J)3rp)QIF%Zn@45$}P#LQ&!!P!6(R{*eB;Z8UTPJ^JctNl?4LTY(3=CLLy z51x+rguKSUKr&m{oiVx%qBMZUQ!sE4izcNPptF|pU2)$09W)+*CT6R6KvNafW;F%`|{@mL_>A%dhrpg|SL zyE%~#%P07p9|)`5R<+il)E1GviubB*T+t0%FqW`6R75W4OKR?46BQL=NywJZBr%Bx zq-@dqYXvx*q!dFug22dfRx0OqIZ**nq-hl>8ntMEWY2fiA9$~R()jtiH;j*uI@nMf+?zI)uU%2|VrfaL>rONS1QI|pb%{|9{Id$e{YkB8`|7jZ4 z_nh>(?O*CPYg-%)bSeIBQ6z&EgC$r|Atw0v|{6uW!SMLb1P?b8@Y6U3$0ZoXU%&%Ise1D?YEYXSX719 z4R_>L?7O?O-^wMW=(C;M>0$4(d#;|nT|K^GLkDnc51(6y@9sP+Dc!R5<(8*s{Ar$c zGj%gT?l7V=lYQC2&ymf;UY#^hvTbdj9u>~1Ro8X+>5Xgrp?sh3CkE@Awoj6;|Ijd@ zeb=DK-p@w=^kJR%{DeuJ>c_=~_#VB4Rcv}8{x^4f+J)+S-|PeS1fSMyXbBvy{%@cC zL%+zDw;XrhTOc-kvh5jROwR#3dQDsW%K`uVUdPrB{(FSu_RfX>+6}aB<1?P8s#ebH z$qDa$)f0NL?$G-3jdv}ZQgZ?gV^`fs7tgL?uC=dlJi7b#yk>c=c-9}E@kibs^5|;s zbe+nKc|Wcny+KsoEi<_7eEH2GrI!NzJ{dpZ2gOF+tW5RtWltRz4dj{C$9U}NJ1aS| z?A71jy*=r~U&6dQ{VQjFe>`7#cg@fdGp0YcW-MZSOQh;K)#B~$o*P+NTs&-N^j~Z0 zr?juRe7sk`+J+^2jr_7mR3;f4MF+}or+!lOrHS2kYkF-?!Jha#uwey_|vzDhKX zs%fXU9G-jhyVll)%|o8NDci=fJum#!eCOu1Z-Nu>jgzsSUPouF>b1ufU+*!AZmS-; zQvOtrll5<$n?v<$*>?JWeL9CqzVGiWtctwTt(D#?6tS&C5ANw-QPt!0b?DdKnprhn z5&5n2PyM(uZF9a^*KvJor&nI^!dnKenm^{rPu;7>{an3ZRj-pD?EcWz!tN;^_;2~P zD{t6CuYA-2w7s3m|DNv!_{PqV9J9YcHW1Nyzn(f5epcU4f0?NMp>kd)^1H@yD^J%n z{&J-y^zGaD8QTffPrXy!KNvn@SA{Uf^wR6|FTZrg{rnKR{NvWXUja*NR3E+eX<^fw zy@`70#9Mpn7Febc=D7{n*^$3Zz4nEDZEVZb-$VlDyy2Whq|lxxObg3E$CUl^w^6D`LSH{w?7Fh7xrGh-5}o5 zqb50UZFB9xX}@=6|2M@k&h>8>BiyS!P&58gg&ZALKL7mSnZ+N!c(H%SEs$3ik6PKPibp2K5utD3`bu&wQ@3ED7 z9~^k**UsfL8gI?|^*=Iq?K2Yq>fp}{%9cK}>C?*Y)qCFCHu?Jg;SGOSXG2{ZCtv(@ z@~Ls??Q?7O=`q8)AWg?7JML~BJ$ElRIdu2lM6+0Zd1`uHFsN_ecTGLKTf!@FBA{={>E+i$!)CswZd>*k3A9WS~ne=~OlgTe~esNaV@{(nkKj3592