diff --git a/plans/k3s-upgrade-plans.yaml b/plans/k3s-upgrade-plans.yaml index cbf64b5..2d8d2ea 100644 --- a/plans/k3s-upgrade-plans.yaml +++ b/plans/k3s-upgrade-plans.yaml @@ -31,6 +31,10 @@ spec: matchExpressions: - key: node-role.kubernetes.io/control-plane operator: DoesNotExist + - key: kubernetes.io/hostname + operator: NotIn + values: + - robin prepare: args: - prepare diff --git a/services/vault/vault-statefulset.yaml b/services/vault/vault-statefulset.yaml index 156ff35..6d52753 100644 --- a/services/vault/vault-statefulset.yaml +++ b/services/vault/vault-statefulset.yaml @@ -18,12 +18,12 @@ spec: terminationGracePeriodSeconds: 10 affinity: # 1. Pin the pods strictly to K3s server nodes - # nodeAffinity: - # requiredDuringSchedulingIgnoredDuringExecution: - # nodeSelectorTerms: - # - matchExpressions: - # - key: node-role.kubernetes.io/control-plane - # operator: Exists + nodeAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + nodeSelectorTerms: + - matchExpressions: + - key: node-role.kubernetes.io/control-plane + operator: Exists # 2. Force those pods onto different physical server nodes podAntiAffinity: