···4343and [](#opt-services.kubernetes.easyCerts)
4444to true. This sets up flannel as CNI and activates automatic PKI bootstrapping.
45454646-As of kubernetes 1.10.X it has been deprecated to open non-tls-enabled
4747-ports on kubernetes components. Thus, from NixOS 19.03 all plain HTTP
4848-ports have been disabled by default. While opening insecure ports is
4949-still possible, it is recommended not to bind these to other interfaces
5050-than loopback. To re-enable the insecure port on the apiserver, see options:
5151-[](#opt-services.kubernetes.apiserver.insecurePort) and
5252-[](#opt-services.kubernetes.apiserver.insecureBindAddress)
5353-5446::: {.note}
5547As of NixOS 19.03, it is mandatory to configure:
5648[](#opt-services.kubernetes.masterAddress).
···4747 <xref linkend="opt-services.kubernetes.easyCerts" /> to true. This
4848 sets up flannel as CNI and activates automatic PKI bootstrapping.
4949 </para>
5050- <para>
5151- As of kubernetes 1.10.X it has been deprecated to open
5252- non-tls-enabled ports on kubernetes components. Thus, from NixOS
5353- 19.03 all plain HTTP ports have been disabled by default. While
5454- opening insecure ports is still possible, it is recommended not to
5555- bind these to other interfaces than loopback. To re-enable the
5656- insecure port on the apiserver, see options:
5757- <xref linkend="opt-services.kubernetes.apiserver.insecurePort" />
5858- and
5959- <xref linkend="opt-services.kubernetes.apiserver.insecureBindAddress" />
6060- </para>
6150 <note>
6251 <para>
6352 As of NixOS 19.03, it is mandatory to configure: