1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-31 03:45:17 +00:00

NK-31: Changed DaemonSet to Deployment for kube-policy image

This commit is contained in:
belyshevdenis 2019-03-21 17:25:36 +02:00
parent 20d9fcd563
commit dccb9e6f6e

View file

@ -159,12 +159,12 @@ spec:
targetPort: 443
selector:
app: kube-policy
#---
#apiVersion: v1
#kind: ServiceAccount
#metadata:
# name: kube-policy-service-account
# namespace: kube-system
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: kube-policy-service-account
namespace: kube-system
---
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1beta1
@ -176,26 +176,24 @@ roleRef:
name: cluster-admin
subjects:
- kind: ServiceAccount
name: default
name: kube-policy-service-account
namespace: kube-system
---
apiVersion: extensions/v1beta1
kind: DaemonSet
kind: Deployment
metadata:
namespace: kube-system
name: kube-policy-deployment
labels:
app: kube-policy
tier: node
name: kube-policy-daemon
namespace: kube-system
spec:
replicas: 1
template:
metadata:
labels:
app: kube-policy
tier: node
spec:
#serviceAccountName: kube-policy-service-account
#serviceAccount: kube-policy-service-account
serviceAccountName: kube-policy-service-account
containers:
- name: kube-policy
image: nirmata/kube-policy:latest
@ -204,13 +202,3 @@ spec:
- containerPort: 443
securityContext:
privileged: true
hostNetwork: true
tolerations:
- key: CriticalAddonsOnly
operator: Exists
- effect: NoSchedule
key: node-role.kubernetes.io/master
operator: Exists
- effect: NoSchedule
key: node.kubernetes.io/not-ready
operator: Exists