This repository has been archived on 2023-04-02. You can view files and clone it, but cannot push or open issues or pull requests.
gitops-tbrnt/sealed-secrets/controller.yaml

243 lines
4.7 KiB
YAML
Raw Normal View History

2020-01-25 19:13:41 +00:00
---
2021-04-15 18:57:27 +00:00
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: RoleBinding
metadata:
annotations: {}
labels:
name: sealed-secrets-service-proxier
name: sealed-secrets-service-proxier
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets
2021-04-15 18:57:27 +00:00
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: sealed-secrets-service-proxier
subjects:
- apiGroup: rbac.authorization.k8s.io
kind: Group
name: system:authenticated
---
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: Role
metadata:
annotations: {}
labels:
name: sealed-secrets-key-admin
name: sealed-secrets-key-admin
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets
2021-04-15 18:57:27 +00:00
rules:
- apiGroups:
- ""
resources:
- secrets
verbs:
- create
- list
---
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: ClusterRole
metadata:
annotations: {}
labels:
name: secrets-unsealer
name: secrets-unsealer
rules:
- apiGroups:
- bitnami.com
resources:
- sealedsecrets
verbs:
- get
- list
- watch
- apiGroups:
- bitnami.com
resources:
- sealedsecrets/status
verbs:
- update
- apiGroups:
- ""
resources:
- secrets
verbs:
- get
- create
- update
- delete
- apiGroups:
- ""
resources:
- events
verbs:
- create
- patch
---
2020-01-25 19:13:41 +00:00
apiVersion: apps/v1
kind: Deployment
metadata:
annotations: {}
labels:
name: sealed-secrets-controller
name: sealed-secrets-controller
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets
2020-01-25 19:13:41 +00:00
spec:
minReadySeconds: 30
replicas: 1
revisionHistoryLimit: 10
selector:
matchLabels:
name: sealed-secrets-controller
strategy:
rollingUpdate:
maxSurge: 25%
maxUnavailable: 25%
type: RollingUpdate
template:
metadata:
annotations: {}
labels:
name: sealed-secrets-controller
spec:
containers:
2021-04-16 18:11:31 +00:00
- args:
- --update-status
2020-01-25 19:13:41 +00:00
command:
- controller
env: []
2021-04-15 18:57:27 +00:00
image: quay.io/bitnami/sealed-secrets-controller:v0.15.0
2020-01-25 19:13:41 +00:00
imagePullPolicy: Always
livenessProbe:
httpGet:
path: /healthz
port: http
name: sealed-secrets-controller
ports:
- containerPort: 8080
name: http
readinessProbe:
httpGet:
path: /healthz
port: http
securityContext:
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1001
stdin: false
tty: false
volumeMounts:
- mountPath: /tmp
name: tmp
imagePullSecrets: []
initContainers: []
2020-08-19 18:37:48 +00:00
securityContext:
fsGroup: 65534
2020-01-25 19:13:41 +00:00
serviceAccountName: sealed-secrets-controller
terminationGracePeriodSeconds: 30
volumes:
- emptyDir: {}
name: tmp
---
2021-04-15 18:57:27 +00:00
apiVersion: apiextensions.k8s.io/v1
2020-01-25 19:13:41 +00:00
kind: CustomResourceDefinition
metadata:
name: sealedsecrets.bitnami.com
spec:
group: bitnami.com
names:
kind: SealedSecret
listKind: SealedSecretList
plural: sealedsecrets
singular: sealedsecret
scope: Namespaced
2021-04-15 18:57:27 +00:00
versions:
- name: v1alpha1
schema:
openAPIV3Schema:
properties:
spec:
type: object
x-kubernetes-preserve-unknown-fields: true
type: object
served: true
storage: true
subresources:
status: {}
2020-08-19 18:37:48 +00:00
---
apiVersion: v1
kind: Service
metadata:
annotations: {}
labels:
name: sealed-secrets-controller
name: sealed-secrets-controller
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets
2020-08-19 18:37:48 +00:00
spec:
ports:
- port: 8080
targetPort: 8080
selector:
name: sealed-secrets-controller
type: ClusterIP
---
apiVersion: rbac.authorization.k8s.io/v1beta1
2021-04-15 18:57:27 +00:00
kind: ClusterRoleBinding
2020-08-19 18:37:48 +00:00
metadata:
annotations: {}
labels:
2021-04-15 18:57:27 +00:00
name: sealed-secrets-controller
name: sealed-secrets-controller
2020-08-19 18:37:48 +00:00
roleRef:
apiGroup: rbac.authorization.k8s.io
2021-04-15 18:57:27 +00:00
kind: ClusterRole
name: secrets-unsealer
2020-08-19 18:37:48 +00:00
subjects:
2021-04-15 18:57:27 +00:00
- kind: ServiceAccount
name: sealed-secrets-controller
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets
2020-08-19 18:37:48 +00:00
---
2021-04-15 18:57:27 +00:00
apiVersion: v1
kind: ServiceAccount
2020-01-25 19:13:41 +00:00
metadata:
annotations: {}
labels:
name: sealed-secrets-controller
name: sealed-secrets-controller
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets
2020-08-19 18:37:48 +00:00
---
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: Role
metadata:
annotations: {}
labels:
2021-04-15 18:57:27 +00:00
name: sealed-secrets-service-proxier
name: sealed-secrets-service-proxier
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets
2020-08-19 18:37:48 +00:00
rules:
- apiGroups:
- ""
2021-04-15 18:57:27 +00:00
resourceNames:
- 'http:sealed-secrets-controller:'
- sealed-secrets-controller
2020-08-19 18:37:48 +00:00
resources:
2021-04-15 18:57:27 +00:00
- services/proxy
2020-08-19 18:37:48 +00:00
verbs:
- create
2021-04-15 18:57:27 +00:00
- get
2020-08-19 18:37:48 +00:00
---
apiVersion: rbac.authorization.k8s.io/v1beta1
2021-04-15 18:57:27 +00:00
kind: RoleBinding
2020-08-19 18:37:48 +00:00
metadata:
annotations: {}
labels:
name: sealed-secrets-controller
name: sealed-secrets-controller
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets
2020-08-19 18:37:48 +00:00
roleRef:
apiGroup: rbac.authorization.k8s.io
2021-04-15 18:57:27 +00:00
kind: Role
name: sealed-secrets-key-admin
2020-08-19 18:37:48 +00:00
subjects:
- kind: ServiceAccount
name: sealed-secrets-controller
2021-04-15 18:59:52 +00:00
namespace: sealed-secrets