|
|
|
@@ -1,71 +1,5 @@
|
|
|
|
|
---
|
|
|
|
|
apiVersion: v1
|
|
|
|
|
kind: ServiceAccount
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
---
|
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
|
|
|
kind: Role
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node-configmap
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
rules:
|
|
|
|
|
- apiGroups: [""]
|
|
|
|
|
resources: ["configmaps"]
|
|
|
|
|
verbs: ["get", "list", "create", "update", "patch"]
|
|
|
|
|
- apiGroups: ["cert-manager.io"]
|
|
|
|
|
resources: ["certificates"]
|
|
|
|
|
verbs: ["get", "list", "create", "update", "patch", "delete"]
|
|
|
|
|
- apiGroups: [""]
|
|
|
|
|
resources: ["secrets"]
|
|
|
|
|
verbs: ["get", "list"]
|
|
|
|
|
- apiGroups: [""]
|
|
|
|
|
resources: ["services", "endpoints"]
|
|
|
|
|
verbs: ["get", "list", "create", "update", "patch", "delete"]
|
|
|
|
|
---
|
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
|
|
|
kind: RoleBinding
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node-configmap
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
roleRef:
|
|
|
|
|
apiGroup: rbac.authorization.k8s.io
|
|
|
|
|
kind: Role
|
|
|
|
|
name: pasarguard-node-configmap
|
|
|
|
|
subjects:
|
|
|
|
|
- kind: ServiceAccount
|
|
|
|
|
name: pasarguard-node
|
|
|
|
|
---
|
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
|
|
|
kind: ClusterRole
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node-reader
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
rules:
|
|
|
|
|
- apiGroups: [""]
|
|
|
|
|
resources: ["nodes"]
|
|
|
|
|
verbs: ["get", "list"]
|
|
|
|
|
---
|
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
|
|
|
kind: ClusterRoleBinding
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node-reader
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
roleRef:
|
|
|
|
|
apiGroup: rbac.authorization.k8s.io
|
|
|
|
|
kind: ClusterRole
|
|
|
|
|
name: pasarguard-node-reader
|
|
|
|
|
subjects:
|
|
|
|
|
- kind: ServiceAccount
|
|
|
|
|
name: pasarguard-node
|
|
|
|
|
namespace: pasarguard
|
|
|
|
|
---
|
|
|
|
|
image: &image 'pasarguard/node:v0.4.0'
|
|
|
|
|
apiVersion: apps/v1
|
|
|
|
|
kind: DaemonSet
|
|
|
|
|
metadata:
|
|
|
|
@@ -113,7 +47,7 @@ spec:
|
|
|
|
|
mountPath: /scripts
|
|
|
|
|
containers:
|
|
|
|
|
- name: pasarguard-node
|
|
|
|
|
image: 'pasarguard/node:v0.3.0'
|
|
|
|
|
image: *image
|
|
|
|
|
imagePullPolicy: Always
|
|
|
|
|
command:
|
|
|
|
|
- /bin/sh
|
|
|
|
@@ -219,3 +153,71 @@ spec:
|
|
|
|
|
configMap:
|
|
|
|
|
name: pasarguard-scripts
|
|
|
|
|
defaultMode: 0755
|
|
|
|
|
|
|
|
|
|
---
|
|
|
|
|
apiVersion: v1
|
|
|
|
|
kind: ServiceAccount
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
---
|
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
|
|
|
kind: Role
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node-configmap
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
rules:
|
|
|
|
|
- apiGroups: [""]
|
|
|
|
|
resources: ["configmaps"]
|
|
|
|
|
verbs: ["get", "list", "create", "update", "patch"]
|
|
|
|
|
- apiGroups: ["cert-manager.io"]
|
|
|
|
|
resources: ["certificates"]
|
|
|
|
|
verbs: ["get", "list", "create", "update", "patch", "delete"]
|
|
|
|
|
- apiGroups: [""]
|
|
|
|
|
resources: ["secrets"]
|
|
|
|
|
verbs: ["get", "list"]
|
|
|
|
|
- apiGroups: [""]
|
|
|
|
|
resources: ["services", "endpoints"]
|
|
|
|
|
verbs: ["get", "list", "create", "update", "patch", "delete"]
|
|
|
|
|
---
|
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
|
|
|
kind: RoleBinding
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node-configmap
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
roleRef:
|
|
|
|
|
apiGroup: rbac.authorization.k8s.io
|
|
|
|
|
kind: Role
|
|
|
|
|
name: pasarguard-node-configmap
|
|
|
|
|
subjects:
|
|
|
|
|
- kind: ServiceAccount
|
|
|
|
|
name: pasarguard-node
|
|
|
|
|
---
|
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
|
|
|
kind: ClusterRole
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node-reader
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
rules:
|
|
|
|
|
- apiGroups: [""]
|
|
|
|
|
resources: ["nodes"]
|
|
|
|
|
verbs: ["get", "list"]
|
|
|
|
|
---
|
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
|
|
|
kind: ClusterRoleBinding
|
|
|
|
|
metadata:
|
|
|
|
|
name: pasarguard-node-reader
|
|
|
|
|
labels:
|
|
|
|
|
app: pasarguard-node
|
|
|
|
|
roleRef:
|
|
|
|
|
apiGroup: rbac.authorization.k8s.io
|
|
|
|
|
kind: ClusterRole
|
|
|
|
|
name: pasarguard-node-reader
|
|
|
|
|
subjects:
|
|
|
|
|
- kind: ServiceAccount
|
|
|
|
|
name: pasarguard-node
|
|
|
|
|
namespace: pasarguard
|