UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects
gotk-components.yaml 253 KiB
Newer Older
runyontr's avatar
runyontr committed
- apiGroups:
  - helm.toolkit.fluxcd.io
  resources:
  - '*'
  verbs:
  - '*'
- apiGroups:
  - notification.toolkit.fluxcd.io
  resources:
  - '*'
  verbs:
  - '*'
- apiGroups:
  - image.toolkit.fluxcd.io
  resources:
  - '*'
  verbs:
  - '*'
- apiGroups:
  - ""
  resources:
Micah Nagel's avatar
Micah Nagel committed
  - namespaces
runyontr's avatar
runyontr committed
  - secrets
bigbang bot's avatar
bigbang bot committed
  - configmaps
  - serviceaccounts
runyontr's avatar
runyontr committed
  verbs:
  - get
  - list
  - watch
- apiGroups:
  - ""
  resources:
  - events
  verbs:
  - create
  - patch
- apiGroups:
  - ""
  resources:
  - configmaps
  verbs:
  - get
  - list
  - watch
  - create
  - update
  - patch
  - delete
bigbang bot's avatar
bigbang bot committed
- apiGroups:
  - ""
  resources:
  - configmaps/status
  verbs:
  - get
  - update
  - patch
runyontr's avatar
runyontr committed
- apiGroups:
  - coordination.k8s.io
  resources:
  - leases
  verbs:
  - get
  - list
  - watch
  - create
  - update
  - patch
  - delete
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
bigbang bot's avatar
bigbang bot committed
  name: cluster-reconciler-flux-system
runyontr's avatar
runyontr committed
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: cluster-admin
subjects:
- kind: ServiceAccount
  name: kustomize-controller
  namespace: flux-system
- kind: ServiceAccount
  name: helm-controller
  namespace: flux-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
bigbang bot's avatar
bigbang bot committed
  name: crd-controller-flux-system
runyontr's avatar
runyontr committed
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
bigbang bot's avatar
bigbang bot committed
  name: crd-controller-flux-system
runyontr's avatar
runyontr committed
subjects:
- kind: ServiceAccount
  name: kustomize-controller
  namespace: flux-system
- kind: ServiceAccount
  name: helm-controller
  namespace: flux-system
- kind: ServiceAccount
  name: source-controller
  namespace: flux-system
- kind: ServiceAccount
  name: notification-controller
  namespace: flux-system
bigbang bot's avatar
bigbang bot committed
- kind: ServiceAccount
  name: image-reflector-controller
  namespace: flux-system
- kind: ServiceAccount
  name: image-automation-controller
  namespace: flux-system
runyontr's avatar
runyontr committed
---
apiVersion: v1
kind: Service
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
    control-plane: controller
  name: notification-controller
  namespace: flux-system
spec:
  ports:
  - name: http
    port: 80
    protocol: TCP
    targetPort: http
  selector:
    app: notification-controller
  type: ClusterIP
---
runyontr's avatar
runyontr committed
apiVersion: v1
kind: Service
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
runyontr's avatar
runyontr committed
    control-plane: controller
  name: source-controller
  namespace: flux-system
spec:
  ports:
  - name: http
    port: 80
    protocol: TCP
    targetPort: http
  selector:
    app: source-controller
  type: ClusterIP
---
apiVersion: v1
kind: Service
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
runyontr's avatar
runyontr committed
    control-plane: controller
  name: webhook-receiver
  namespace: flux-system
spec:
  ports:
  - name: http
    port: 80
    protocol: TCP
    targetPort: http-webhook
  selector:
    app: notification-controller
  type: ClusterIP
---
apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
runyontr's avatar
runyontr committed
    control-plane: controller
  name: helm-controller
  namespace: flux-system
spec:
  replicas: 1
  selector:
    matchLabels:
      app: helm-controller
  template:
    metadata:
      annotations:
        prometheus.io/port: "8080"
        prometheus.io/scrape: "true"
      labels:
        app: helm-controller
    spec:
      containers:
      - args:
bigbang bot's avatar
bigbang bot committed
        - --events-addr=http://notification-controller.flux-system.svc.cluster.local./
bigbang bot's avatar
bigbang bot committed
        - --watch-all-namespaces=true
runyontr's avatar
runyontr committed
        - --log-level=info
        - --log-encoding=json
        - --enable-leader-election
        env:
        - name: RUNTIME_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
bigbang bot's avatar
bigbang bot committed
        image: ghcr.io/fluxcd/helm-controller:v0.22.2
runyontr's avatar
runyontr committed
        imagePullPolicy: IfNotPresent
        livenessProbe:
          httpGet:
            path: /healthz
            port: healthz
        name: manager
        ports:
        - containerPort: 8080
          name: http-prom
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        - containerPort: 9440
          name: healthz
          protocol: TCP
        readinessProbe:
          httpGet:
            path: /readyz
            port: healthz
        resources:
          limits:
            cpu: 1000m
            memory: 1Gi
          requests:
runyontr's avatar
runyontr committed
        securityContext:
          allowPrivilegeEscalation: false
bigbang bot's avatar
bigbang bot committed
          capabilities:
            drop:
            - ALL
runyontr's avatar
runyontr committed
          readOnlyRootFilesystem: true
bigbang bot's avatar
bigbang bot committed
          runAsNonRoot: true
          seccompProfile:
            type: RuntimeDefault
runyontr's avatar
runyontr committed
        volumeMounts:
        - mountPath: /tmp
          name: temp
bigbang bot's avatar
bigbang bot committed
      nodeSelector:
        kubernetes.io/os: linux
bigbang bot's avatar
bigbang bot committed
      securityContext:
        fsGroup: 1337
runyontr's avatar
runyontr committed
      serviceAccountName: helm-controller
      terminationGracePeriodSeconds: 600
      volumes:
      - emptyDir: {}
        name: temp
---
apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
    control-plane: controller
runyontr's avatar
runyontr committed
  name: kustomize-controller
  namespace: flux-system
spec:
runyontr's avatar
runyontr committed
  replicas: 1
  selector:
runyontr's avatar
runyontr committed
    matchLabels:
      app: kustomize-controller
  template:
    metadata:
      annotations:
        prometheus.io/port: "8080"
        prometheus.io/scrape: "true"
      labels:
        app: kustomize-controller
    spec:
      containers:
      - args:
bigbang bot's avatar
bigbang bot committed
        - --events-addr=http://notification-controller.flux-system.svc.cluster.local./
bigbang bot's avatar
bigbang bot committed
        - --watch-all-namespaces=true
runyontr's avatar
runyontr committed
        - --log-level=info
        - --log-encoding=json
        - --enable-leader-election
        env:
        - name: RUNTIME_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
bigbang bot's avatar
bigbang bot committed
        image: ghcr.io/fluxcd/kustomize-controller:v0.26.3
runyontr's avatar
runyontr committed
        imagePullPolicy: IfNotPresent
        livenessProbe:
          httpGet:
            path: /healthz
            port: healthz
        name: manager
        ports:
        - containerPort: 8080
          name: http-prom
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        - containerPort: 9440
          name: healthz
          protocol: TCP
        readinessProbe:
          httpGet:
            path: /readyz
            port: healthz
        resources:
          limits:
            cpu: 1000m
            memory: 1Gi
          requests:
runyontr's avatar
runyontr committed
        securityContext:
          allowPrivilegeEscalation: false
bigbang bot's avatar
bigbang bot committed
          capabilities:
            drop:
            - ALL
runyontr's avatar
runyontr committed
          readOnlyRootFilesystem: true
bigbang bot's avatar
bigbang bot committed
          runAsNonRoot: true
          seccompProfile:
            type: RuntimeDefault
runyontr's avatar
runyontr committed
        volumeMounts:
        - mountPath: /tmp
          name: temp
bigbang bot's avatar
bigbang bot committed
      nodeSelector:
        kubernetes.io/os: linux
runyontr's avatar
runyontr committed
      securityContext:
        fsGroup: 1337
      serviceAccountName: kustomize-controller
      terminationGracePeriodSeconds: 60
      volumes:
      - emptyDir: {}
        name: temp
---
apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
    control-plane: controller
  name: notification-controller
  namespace: flux-system
spec:
  replicas: 1
  selector:
    matchLabels:
      app: notification-controller
  template:
    metadata:
      annotations:
        prometheus.io/port: "8080"
        prometheus.io/scrape: "true"
      labels:
        app: notification-controller
    spec:
      containers:
      - args:
bigbang bot's avatar
bigbang bot committed
        - --watch-all-namespaces=true
        - --log-level=info
runyontr's avatar
runyontr committed
        - --log-encoding=json
        - --enable-leader-election
        env:
        - name: RUNTIME_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
bigbang bot's avatar
bigbang bot committed
        image: ghcr.io/fluxcd/notification-controller:v0.24.1
        imagePullPolicy: IfNotPresent
        livenessProbe:
          httpGet:
Jeff McCoy's avatar
Jeff McCoy committed
            path: /healthz
            port: healthz
        name: manager
        ports:
        - containerPort: 9090
          name: http
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
        - containerPort: 9292
          name: http-webhook
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
        - containerPort: 8080
          name: http-prom
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
        - containerPort: 9440
          name: healthz
          protocol: TCP
Jeff McCoy's avatar
Jeff McCoy committed
        readinessProbe:
          httpGet:
            path: /readyz
            port: healthz
        resources:
          limits:
            cpu: 1000m
            memory: 1Gi
          requests:
        securityContext:
          allowPrivilegeEscalation: false
bigbang bot's avatar
bigbang bot committed
          capabilities:
            drop:
            - ALL
          readOnlyRootFilesystem: true
bigbang bot's avatar
bigbang bot committed
          runAsNonRoot: true
          seccompProfile:
            type: RuntimeDefault
        volumeMounts:
        - mountPath: /tmp
          name: temp
bigbang bot's avatar
bigbang bot committed
      nodeSelector:
        kubernetes.io/os: linux
bigbang bot's avatar
bigbang bot committed
      securityContext:
        fsGroup: 1337
runyontr's avatar
runyontr committed
      serviceAccountName: notification-controller
      terminationGracePeriodSeconds: 10
      volumes:
      - emptyDir: {}
        name: temp
---
runyontr's avatar
runyontr committed
apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
runyontr's avatar
runyontr committed
    control-plane: controller
  name: source-controller
  namespace: flux-system
spec:
  replicas: 1
  selector:
    matchLabels:
      app: source-controller
  strategy:
    type: Recreate
  template:
    metadata:
      annotations:
        prometheus.io/port: "8080"
        prometheus.io/scrape: "true"
      labels:
        app: source-controller
    spec:
      containers:
      - args:
bigbang bot's avatar
bigbang bot committed
        - --events-addr=http://notification-controller.flux-system.svc.cluster.local./
bigbang bot's avatar
bigbang bot committed
        - --watch-all-namespaces=true
runyontr's avatar
runyontr committed
        - --log-level=info
        - --log-encoding=json
        - --enable-leader-election
        - --storage-path=/data
        - --storage-adv-addr=source-controller.$(RUNTIME_NAMESPACE).svc.cluster.local.
        env:
        - name: RUNTIME_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
bigbang bot's avatar
bigbang bot committed
        image: ghcr.io/fluxcd/source-controller:v0.25.11
runyontr's avatar
runyontr committed
        imagePullPolicy: IfNotPresent
        livenessProbe:
          httpGet:
            path: /healthz
            port: healthz
        name: manager
        ports:
        - containerPort: 9090
          name: http
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        - containerPort: 8080
          name: http-prom
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        - containerPort: 9440
          name: healthz
bigbang bot's avatar
bigbang bot committed
          protocol: TCP
runyontr's avatar
runyontr committed
        readinessProbe:
          httpGet:
            path: /
            port: http
        resources:
          limits:
            cpu: 1000m
            memory: 1Gi
          requests:
runyontr's avatar
runyontr committed
        securityContext:
          allowPrivilegeEscalation: false
bigbang bot's avatar
bigbang bot committed
          capabilities:
            drop:
            - ALL
runyontr's avatar
runyontr committed
          readOnlyRootFilesystem: true
bigbang bot's avatar
bigbang bot committed
          runAsNonRoot: true
          seccompProfile:
            type: RuntimeDefault
runyontr's avatar
runyontr committed
        volumeMounts:
        - mountPath: /data
          name: data
        - mountPath: /tmp
          name: tmp
bigbang bot's avatar
bigbang bot committed
      nodeSelector:
        kubernetes.io/os: linux
runyontr's avatar
runyontr committed
      securityContext:
        fsGroup: 1337
      serviceAccountName: source-controller
      terminationGracePeriodSeconds: 10
      volumes:
      - emptyDir: {}
        name: data
      - emptyDir: {}
        name: tmp
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
runyontr's avatar
runyontr committed
  namespace: flux-system
spec:
runyontr's avatar
runyontr committed
  ingress:
  - from:
runyontr's avatar
runyontr committed
  podSelector: {}
  policyTypes:
  - Ingress
runyontr's avatar
runyontr committed
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
  name: allow-scraping
runyontr's avatar
runyontr committed
  namespace: flux-system
spec:
  ingress:
  - from:
    - namespaceSelector: {}
    ports:
    - port: 8080
      protocol: TCP
  podSelector: {}
runyontr's avatar
runyontr committed
  policyTypes:
  - Ingress
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  labels:
    app.kubernetes.io/instance: flux-system
    app.kubernetes.io/part-of: flux
bigbang bot's avatar
bigbang bot committed
    app.kubernetes.io/version: v0.31.5
  name: allow-webhooks
runyontr's avatar
runyontr committed
  namespace: flux-system
spec:
  ingress:
  - from:
    - namespaceSelector: {}
  podSelector:
    matchLabels:
      app: notification-controller
runyontr's avatar
runyontr committed
  policyTypes:
  - Ingress