mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-31 03:45:17 +00:00
NK-31: Changed DaemonSet to Deployment for kube-policy image
This commit is contained in:
parent
20d9fcd563
commit
dccb9e6f6e
1 changed files with 19 additions and 31 deletions
|
@ -159,12 +159,12 @@ spec:
|
||||||
targetPort: 443
|
targetPort: 443
|
||||||
selector:
|
selector:
|
||||||
app: kube-policy
|
app: kube-policy
|
||||||
#---
|
---
|
||||||
#apiVersion: v1
|
apiVersion: v1
|
||||||
#kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
#metadata:
|
metadata:
|
||||||
# name: kube-policy-service-account
|
name: kube-policy-service-account
|
||||||
# namespace: kube-system
|
namespace: kube-system
|
||||||
---
|
---
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
apiVersion: rbac.authorization.k8s.io/v1beta1
|
apiVersion: rbac.authorization.k8s.io/v1beta1
|
||||||
|
@ -176,41 +176,29 @@ roleRef:
|
||||||
name: cluster-admin
|
name: cluster-admin
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: default
|
name: kube-policy-service-account
|
||||||
namespace: kube-system
|
namespace: kube-system
|
||||||
---
|
---
|
||||||
apiVersion: extensions/v1beta1
|
apiVersion: extensions/v1beta1
|
||||||
kind: DaemonSet
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
|
namespace: kube-system
|
||||||
|
name: kube-policy-deployment
|
||||||
labels:
|
labels:
|
||||||
app: kube-policy
|
app: kube-policy
|
||||||
tier: node
|
|
||||||
name: kube-policy-daemon
|
|
||||||
namespace: kube-system
|
|
||||||
spec:
|
spec:
|
||||||
|
replicas: 1
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
app: kube-policy
|
app: kube-policy
|
||||||
tier: node
|
|
||||||
spec:
|
spec:
|
||||||
#serviceAccountName: kube-policy-service-account
|
serviceAccountName: kube-policy-service-account
|
||||||
#serviceAccount: kube-policy-service-account
|
|
||||||
containers:
|
containers:
|
||||||
- name: kube-policy
|
- name: kube-policy
|
||||||
image: nirmata/kube-policy:latest
|
image: nirmata/kube-policy:latest
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 443
|
- containerPort: 443
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
hostNetwork: true
|
|
||||||
tolerations:
|
|
||||||
- key: CriticalAddonsOnly
|
|
||||||
operator: Exists
|
|
||||||
- effect: NoSchedule
|
|
||||||
key: node-role.kubernetes.io/master
|
|
||||||
operator: Exists
|
|
||||||
- effect: NoSchedule
|
|
||||||
key: node.kubernetes.io/not-ready
|
|
||||||
operator: Exists
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue