Configure optional settings
Note
Consider this section as part of the Bootstrap v2 CLI procedure.
During creation of a management cluster, you can configure optional cluster
settings using the MOSK management API by modifying
cluster.yaml.template.
To configure optional cluster settings:
Technology Preview. Enable custom host names for cluster machines. When enabled, any machine host name in a particular region matches the related
Machineobject name. For example, instead of the defaultkaas-node-<UID>, a machine host name will bemaster-0. The custom naming format is more convenient and easier to operate with.Configuration for custom host names on the management and its future MOSK clusters
In
cluster.yaml.template, find thespec.providerSpec.value.kaas.regional.helmReleases.name: baremetal-providersection.Under
values.config, addcustomHostnamesEnabled: true:regional: - helmReleases: - name: baremetal-provider values: config: allInOneAllowed: false customHostnamesEnabled: true internalLoadBalancers: false provider: baremetal-provider
Optional. Technology Preview. Enable the Linux Audit daemon auditd to monitor activity of cluster processes and prevent potential malicious activity.
Configuration for auditd
In the
Clusterobject orcluster.yaml.template, add the auditd parameters:spec: providerSpec: value: audit: auditd: enabled: <bool> enabledAtBoot: <bool> backlogLimit: <int> maxLogFile: <int> maxLogFileAction: <string> maxLogFileKeep: <int> mayHaltSystem: <bool> presetRules: <string> customRules: <string> customRulesX32: <text> customRulesX64: <text>
Configuration parameters for auditd:
enabledBoolean, default -
false. Enables theauditdrole to install the auditd packages and configure rules.enabledAtBootBoolean, default -
false. Configures grub to audit processes that can be audited even if they start up prior to auditd startup.backlogLimitInteger, default - none. Configures the backlog to hold records. If during boot
audit=1is configured, the backlog holds 64 records. If more than 64 records are created during boot, auditd records will be lost with a potential malicious activity being undetected.maxLogFileInteger, default - none. Configures the maximum size of the audit log file. Once the log reaches the maximum size, it is rotated and a new log file is created.
maxLogFileActionString, default - none. Defines handling of the audit log file reaching the maximum file size. Allowed values:
keep_logs- rotate logs but never delete themrotate- add a cron job to compress rotated log files and keep maximum 5 compressed files.compress- compress log files and keep them under the/var/log/auditd/directory. Requiresauditd_max_log_file_keepto be enabled.
maxLogFileKeepInteger, default -
5. Defines the number of compressed log files to keep under the/var/log/auditd/directory. Requiresauditd_max_log_file_action=compress.mayHaltSystemBoolean, default -
false. Halts the system when the audit logs are full. Applies the following configuration:space_left_action = emailaction_mail_acct = rootadmin_space_left_action = halt
customRulesString, default - none. Base64-encoded content of the
60-custom.rulesfile for any architecture.customRulesX32String, default - none. Base64-encoded content of the
60-custom.rulesfile for thei386architecture.customRulesX64String, default - none. Base64-encoded content of the
60-custom.rulesfile for thex86_64architecture.presetRulesString, default - none. Comma-separated list of the following built-in preset rules:
accessactionsdeletedocker
identityimmutableloginsmac-policy
modulesmountsperm-modprivileged
scopesessionsystem-localetime-change
Since Container Cloud 2.28.0 (Cluster releases 17.3.0 and 16.3.0) in the Technology Preview scope, you can collect some of the preset rules indicated above as groups and use them in
presetRules:ubuntu-cis-rules- this group contains the following audit rules:scopeactionstime-changesystem-localeprivilegedaccessidentity
perm-modmountssessionloginsdeletemac-policymodules
docker-cis-rules- this group contains thedockeraudit rules for Docker files and directories.
You can also use two additional keywords inside
presetRules:none- select no built-in rules.all- select all built-in rules. When using this keyword, you can add the!prefix to a rule name to exclude some rules. You can use the!prefix for rules only if you add theallkeyword as the first rule. Place a rule with the!prefix only after theallkeyword.
Example configurations:
presetRules: none- disable all preset rulespresetRules: docker- enable only thedockerrulespresetRules: access,actions,logins- enable only theaccess,actions, andloginsrulespresetRules: ubuntu-cis-rules- enable all rules from theubuntu-cis-rulesgrouppresetRules: docker-cis-rules,actions- enable all rules from thedocker-cis-rulesgroup and theactionsrulepresetRules: all- enable all preset rulespresetRules: all,!immutable,!sessions- enable all preset rules exceptimmutableandsessions
Configure OIDC integration with LDAP or Google OAuth. For details, see Configure LDAP for IAM or Configure Google OAuth IdP for IAM.
Configure NTP server. You can disable NTP that is enabled by default. This option disables the management of
chronyconfiguration by MOSK to use your own system forchronymanagement. Otherwise, configure the regional NTP server parameters as described below.NTP configuration
Configure the regional NTP server parameters to be applied to all machines of MOSK clusters.
In
cluster.yaml.templateor theClusterobject, add thentp:serverssection with the list of required server names:spec: ... providerSpec: value: kaas: ... ntpEnabled: true regional: - helmReleases: - name: baremetal-provider values: config: lcm: ... ntp: servers: - 0.pool.ntp.org ... provider: baremetal ...
To disable NTP:
spec: ... providerSpec: value: ... ntpEnabled: false ...
Applies since MOSK management 2.26.0 (Cluster release 16.1.0). If you plan to deploy large MOSK clusters, enable dynamic IP allocation to increase the amount of bare-metal hosts to be provisioned in parallel. For details, see Enable dynamic IP allocation.
Now, proceed with completing the bootstrap process using the MOSK Bootstrap API as described in Deploy a management cluster.