From 3d07dab404153d762823cbdafb48612b95e1079c Mon Sep 17 00:00:00 2001 From: kkb0318 Date: Thu, 30 May 2024 21:53:46 +0900 Subject: [PATCH] set aws access key --- config/manager/kustomization.yaml | 6 +++ config/manager/manager.yaml | 89 ++++++++++++++++++++----------- 2 files changed, 63 insertions(+), 32 deletions(-) diff --git a/config/manager/kustomization.yaml b/config/manager/kustomization.yaml index 5c5f0b8..4b9bfd7 100644 --- a/config/manager/kustomization.yaml +++ b/config/manager/kustomization.yaml @@ -1,2 +1,8 @@ resources: - manager.yaml +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +images: +- name: controller + newName: ghcr.io/kkb0318/irsa-manager + newTag: latest diff --git a/config/manager/manager.yaml b/config/manager/manager.yaml index d30fc25..fab3d50 100644 --- a/config/manager/manager.yaml +++ b/config/manager/manager.yaml @@ -66,37 +66,62 @@ spec: # seccompProfile: # type: RuntimeDefault containers: - - command: - - /manager - args: - - --leader-elect - image: controller:latest - name: manager - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - "ALL" - livenessProbe: - httpGet: - path: /healthz - port: 8081 - initialDelaySeconds: 15 - periodSeconds: 20 - readinessProbe: - httpGet: - path: /readyz - port: 8081 - initialDelaySeconds: 5 - periodSeconds: 10 - # TODO(user): Configure the resources accordingly based on the project requirements. - # More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ - resources: - limits: - cpu: 500m - memory: 128Mi - requests: - cpu: 10m - memory: 64Mi + - command: + - /manager + args: + - --leader-elect + image: controller:latest + env: + - name: AWS_ACCESS_KEY_ID + valueFrom: + secretKeyRef: + name: aws-secret + key: aws-access-key-id + optional: true + - name: AWS_SECRET_ACCESS_KEY + valueFrom: + secretKeyRef: + name: aws-secret + key: aws-secret-access-key + optional: true + - name: AWS_REGION + valueFrom: + secretKeyRef: + name: aws-secret + key: aws-region + optional: true + - name: AWS_ROLE_ARN + valueFrom: + secretKeyRef: + name: aws-secret + key: aws-role-arn + optional: true + name: manager + securityContext: + allowPrivilegeEscalation: false + capabilities: + drop: + - "ALL" + livenessProbe: + httpGet: + path: /healthz + port: 8081 + initialDelaySeconds: 15 + periodSeconds: 20 + readinessProbe: + httpGet: + path: /readyz + port: 8081 + initialDelaySeconds: 5 + periodSeconds: 10 + # TODO(user): Configure the resources accordingly based on the project requirements. + # More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ + resources: + limits: + cpu: 500m + memory: 128Mi + requests: + cpu: 10m + memory: 64Mi serviceAccountName: controller-manager terminationGracePeriodSeconds: 10