mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-29 14:38:50 +00:00
Simplify docs to install Istio on RKE2 with selinux
Signed-off-by: Bastian Hofmann <bashofmann@gmail.com>
This commit is contained in:
@@ -16,9 +16,17 @@ When installing or upgrading the Istio Helm chart through **Apps & Marketplace,*
|
|||||||
components:
|
components:
|
||||||
cni:
|
cni:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
k8s:
|
||||||
|
overlays:
|
||||||
|
- apiVersion: "apps/v1"
|
||||||
|
kind: "DaemonSet"
|
||||||
|
name: "istio-cni-node"
|
||||||
|
patches:
|
||||||
|
- path: spec.template.spec.containers.[name:install-cni].securityContext.privileged
|
||||||
|
value: true
|
||||||
values:
|
values:
|
||||||
cni:
|
cni:
|
||||||
image: rancher/istio-install-cni:1.7.3
|
image: rancher/mirrored-istio-install-cni:1.9.3
|
||||||
excludeNamespaces:
|
excludeNamespaces:
|
||||||
- istio-system
|
- istio-system
|
||||||
- kube-system
|
- kube-system
|
||||||
@@ -26,10 +34,5 @@ When installing or upgrading the Istio Helm chart through **Apps & Marketplace,*
|
|||||||
cniBinDir: /opt/cni/bin
|
cniBinDir: /opt/cni/bin
|
||||||
cniConfDir: /etc/cni/net.d
|
cniConfDir: /etc/cni/net.d
|
||||||
```
|
```
|
||||||
1. After installing or upgrading Istio, you'll notice the cni-node pods in the istio-system namespace in a CrashLoopBackoff error. Manually edit the `istio-cni-node` daemonset to include the following on the `install-cni` container:
|
|
||||||
```yaml
|
|
||||||
securityContext:
|
|
||||||
privileged: true
|
|
||||||
```
|
|
||||||
|
|
||||||
**Result:** Now you should be able to utilize Istio as desired, including sidecar injection and monitoring via Kiali.
|
**Result:** Now you should be able to utilize Istio as desired, including sidecar injection and monitoring via Kiali.
|
||||||
|
|||||||
Reference in New Issue
Block a user