UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects
gotk-components.yaml 191 KiB
Newer Older
runyontr's avatar
runyontr committed
            memory: 1Gi
          requests:
runyontr's avatar
runyontr committed
        securityContext:
          allowPrivilegeEscalation: false
bigbang bot's avatar
bigbang bot committed
          capabilities:
            drop:
            - ALL
runyontr's avatar
runyontr committed
          readOnlyRootFilesystem: true
bigbang bot's avatar
bigbang bot committed
          runAsNonRoot: true
          seccompProfile:
            type: RuntimeDefault
runyontr's avatar
runyontr committed
        volumeMounts:
        - mountPath: /tmp
          name: temp
bigbang bot's avatar
bigbang bot committed
      nodeSelector:
        kubernetes.io/os: linux
runyontr's avatar
runyontr committed
      serviceAccountName: helm-controller
      terminationGracePeriodSeconds: 600
      volumes:
      - emptyDir: {}
        name: temp
---
apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.27.3
    control-plane: controller
runyontr's avatar
runyontr committed
  name: kustomize-controller
  namespace: flux-system
spec:
runyontr's avatar
runyontr committed
  replicas: 1
  selector:
runyontr's avatar
runyontr committed
    matchLabels:
      app: kustomize-controller
  template:
    metadata:
      annotations:
        prometheus.io/port: "8080"
        prometheus.io/scrape: "true"
      labels:
        app: kustomize-controller
    spec:
      containers:
      - args:
bigbang bot's avatar
bigbang bot committed
        - --events-addr=http://notification-controller.flux-system.svc.cluster.local/
        - --watch-all-namespaces=true
runyontr's avatar
runyontr committed
        - --log-level=info
        - --log-encoding=json
        - --enable-leader-election
        env:
        - name: RUNTIME_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
bigbang bot's avatar
bigbang bot committed
        image: ghcr.io/fluxcd/kustomize-controller:v0.21.1
runyontr's avatar
runyontr committed
        imagePullPolicy: IfNotPresent
        livenessProbe:
          httpGet:
            path: /healthz
            port: healthz
        name: manager
        ports:
        - containerPort: 8080
          name: http-prom
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        - containerPort: 9440
          name: healthz
          protocol: TCP
        readinessProbe:
          httpGet:
            path: /readyz
            port: healthz
        resources:
          limits:
            cpu: 1000m
            memory: 1Gi
          requests:
runyontr's avatar
runyontr committed
        securityContext:
          allowPrivilegeEscalation: false
bigbang bot's avatar
bigbang bot committed
          capabilities:
            drop:
            - ALL
runyontr's avatar
runyontr committed
          readOnlyRootFilesystem: true
bigbang bot's avatar
bigbang bot committed
          runAsNonRoot: true
          seccompProfile:
            type: RuntimeDefault
runyontr's avatar
runyontr committed
        volumeMounts:
        - mountPath: /tmp
          name: temp
bigbang bot's avatar
bigbang bot committed
      nodeSelector:
        kubernetes.io/os: linux
runyontr's avatar
runyontr committed
      securityContext:
        fsGroup: 1337
      serviceAccountName: kustomize-controller
      terminationGracePeriodSeconds: 60
      volumes:
      - emptyDir: {}
        name: temp
---
apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.27.3
    control-plane: controller
  name: notification-controller
  namespace: flux-system
spec:
  replicas: 1
  selector:
    matchLabels:
      app: notification-controller
  template:
    metadata:
      annotations:
        prometheus.io/port: "8080"
        prometheus.io/scrape: "true"
      labels:
        app: notification-controller
    spec:
      containers:
      - args:
bigbang bot's avatar
bigbang bot committed
        - --watch-all-namespaces=true
        - --log-level=info
runyontr's avatar
runyontr committed
        - --log-encoding=json
        - --enable-leader-election
        env:
        - name: RUNTIME_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
bigbang bot's avatar
bigbang bot committed
        image: ghcr.io/fluxcd/notification-controller:v0.22.2
        imagePullPolicy: IfNotPresent
        livenessProbe:
          httpGet:
Jeff McCoy's avatar
Jeff McCoy committed
            path: /healthz
            port: healthz
        name: manager
        ports:
        - containerPort: 9090
          name: http
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
        - containerPort: 9292
          name: http-webhook
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
        - containerPort: 8080
          name: http-prom
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
        - containerPort: 9440
          name: healthz
          protocol: TCP
Jeff McCoy's avatar
Jeff McCoy committed
        readinessProbe:
          httpGet:
            path: /readyz
            port: healthz
        resources:
          limits:
            cpu: 1000m
            memory: 1Gi
          requests:
        securityContext:
          allowPrivilegeEscalation: false
bigbang bot's avatar
bigbang bot committed
          capabilities:
            drop:
            - ALL
          readOnlyRootFilesystem: true
bigbang bot's avatar
bigbang bot committed
          runAsNonRoot: true
          seccompProfile:
            type: RuntimeDefault
        volumeMounts:
        - mountPath: /tmp
          name: temp
bigbang bot's avatar
bigbang bot committed
      nodeSelector:
        kubernetes.io/os: linux
runyontr's avatar
runyontr committed
      serviceAccountName: notification-controller
      terminationGracePeriodSeconds: 10
      volumes:
      - emptyDir: {}
        name: temp
---
runyontr's avatar
runyontr committed
apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.27.3
runyontr's avatar
runyontr committed
    control-plane: controller
  name: source-controller
  namespace: flux-system
spec:
  replicas: 1
  selector:
    matchLabels:
      app: source-controller
  strategy:
    type: Recreate
  template:
    metadata:
      annotations:
        prometheus.io/port: "8080"
        prometheus.io/scrape: "true"
      labels:
        app: source-controller
    spec:
      containers:
      - args:
bigbang bot's avatar
bigbang bot committed
        - --events-addr=http://notification-controller.flux-system.svc.cluster.local/
        - --watch-all-namespaces=true
runyontr's avatar
runyontr committed
        - --log-level=info
        - --log-encoding=json
        - --enable-leader-election
        - --storage-path=/data
        - --storage-adv-addr=source-controller.$(RUNTIME_NAMESPACE).svc.cluster.local.
        env:
        - name: RUNTIME_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
        image: ghcr.io/fluxcd/source-controller:v0.21.2
runyontr's avatar
runyontr committed
        imagePullPolicy: IfNotPresent
        livenessProbe:
          httpGet:
            path: /healthz
            port: healthz
        name: manager
        ports:
        - containerPort: 9090
          name: http
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        - containerPort: 8080
          name: http-prom
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        - containerPort: 9440
          name: healthz
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        readinessProbe:
          httpGet:
            path: /
            port: http
        resources:
          limits:
            cpu: 1000m
            memory: 1Gi
          requests:
runyontr's avatar
runyontr committed
        securityContext:
          allowPrivilegeEscalation: false
bigbang bot's avatar
bigbang bot committed
          capabilities:
            drop:
            - ALL
runyontr's avatar
runyontr committed
          readOnlyRootFilesystem: true
bigbang bot's avatar
bigbang bot committed
          runAsNonRoot: true
          seccompProfile:
            type: RuntimeDefault
runyontr's avatar
runyontr committed
        volumeMounts:
        - mountPath: /data
          name: data
        - mountPath: /tmp
          name: tmp
bigbang bot's avatar
bigbang bot committed
      nodeSelector:
        kubernetes.io/os: linux
runyontr's avatar
runyontr committed
      securityContext:
        fsGroup: 1337
      serviceAccountName: source-controller
      terminationGracePeriodSeconds: 10
      volumes:
      - emptyDir: {}
        name: data
      - emptyDir: {}
        name: tmp
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.27.3
runyontr's avatar
runyontr committed
  namespace: flux-system
spec:
runyontr's avatar
runyontr committed
  ingress:
  - from:
runyontr's avatar
runyontr committed
  podSelector: {}
  policyTypes:
  - Ingress
runyontr's avatar
runyontr committed
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.27.3
  name: allow-scraping
runyontr's avatar
runyontr committed
  namespace: flux-system
spec:
  ingress:
  - from:
    - namespaceSelector: {}
    ports:
    - port: 8080
      protocol: TCP
  podSelector: {}
runyontr's avatar
runyontr committed
  policyTypes:
  - Ingress
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.27.3
  name: allow-webhooks
runyontr's avatar
runyontr committed
  namespace: flux-system
spec:
  ingress:
  - from:
    - namespaceSelector: {}
  podSelector:
    matchLabels:
      app: notification-controller
runyontr's avatar
runyontr committed
  policyTypes:
  - Ingress