mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
deployment image
This commit is contained in:
@@ -18,6 +18,7 @@ package controller
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
|
||||
"k8s.io/apimachinery/pkg/runtime"
|
||||
ctrl "sigs.k8s.io/controller-runtime"
|
||||
@@ -152,7 +153,9 @@ func (r *IRSASetupReconciler) reconcileDelete(ctx context.Context, obj *irsav1al
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
controllerutil.RemoveFinalizer(obj, irsamanagerFinalizer)
|
||||
if !controllerutil.RemoveFinalizer(obj, irsamanagerFinalizer) {
|
||||
return errors.New("failed to remove finalizer")
|
||||
}
|
||||
return r.Update(ctx, obj)
|
||||
}
|
||||
|
||||
@@ -185,17 +188,14 @@ func reconcileSelfhosted(ctx context.Context, obj *irsav1alpha1.IRSASetup, awsCl
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
kubeHandler := handler.NewKubernetesHandler(kubeClient)
|
||||
kubeHandler.Append(secret)
|
||||
kubeHandlerForOidc := handler.NewKubernetesHandler(kubeClient)
|
||||
kubeHandlerForOidc.Append(secret)
|
||||
|
||||
// for webhook setup
|
||||
webhookSetup, err := webhook.NewWebHookSetup()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
for _, r := range webhookSetup.Resources() {
|
||||
kubeHandler.Append(r)
|
||||
}
|
||||
|
||||
var e error
|
||||
var reason irsav1alpha1.SelfHostedReason
|
||||
@@ -217,15 +217,26 @@ func reconcileSelfhosted(ctx context.Context, obj *irsav1alpha1.IRSASetup, awsCl
|
||||
return err
|
||||
}
|
||||
if forceUpdate {
|
||||
err = kubeHandler.ApplyAll(ctx)
|
||||
err = kubeHandlerForOidc.ApplyAll(ctx)
|
||||
} else {
|
||||
err = kubeHandler.CreateAll(ctx)
|
||||
err = kubeHandlerForOidc.CreateAll(ctx)
|
||||
}
|
||||
if err != nil {
|
||||
e = err
|
||||
reason = irsav1alpha1.SelfHostedReasonFailedKeys
|
||||
return err
|
||||
}
|
||||
// for webhook update
|
||||
kubeHandlerForWebhook := handler.NewKubernetesHandler(kubeClient)
|
||||
for _, r := range webhookSetup.Resources() {
|
||||
kubeHandlerForWebhook.Append(r)
|
||||
}
|
||||
err = kubeHandlerForWebhook.ApplyAll(ctx)
|
||||
if err != nil {
|
||||
e = err
|
||||
reason = irsav1alpha1.SelfHostedReasonFailedWebhook
|
||||
return err
|
||||
}
|
||||
*obj = irsav1alpha1.SetupSelfHostedStatusReady(*obj, string(irsav1alpha1.SelfHostedReasonReady), "successfully setup resources for self-hosted")
|
||||
log.Info("the self-hosted resources have successfully set up")
|
||||
return nil
|
||||
|
||||
@@ -111,8 +111,9 @@ func (b *baseManifestFactory) deployment() *appsv1.Deployment {
|
||||
ServiceAccountName: b.serviceAccountMeta.Name,
|
||||
Containers: []corev1.Container{
|
||||
{
|
||||
Name: "pod-identity-webhook",
|
||||
Image: "quay.io/amis/pod-identity-webhook:v0.0.1",
|
||||
Name: "pod-identity-webhook",
|
||||
Image: "amazon/amazon-eks-pod-identity-webhook:latest",
|
||||
|
||||
ImagePullPolicy: corev1.PullAlways,
|
||||
// Command: []string{}, // Command must be patched
|
||||
VolumeMounts: []corev1.VolumeMount{
|
||||
|
||||
+5
-1
@@ -16,7 +16,7 @@ spec:
|
||||
serviceAccountName: pod-identity-webhook
|
||||
containers:
|
||||
- name: pod-identity-webhook
|
||||
image: quay.io/amis/pod-identity-webhook:v0.0.1
|
||||
image: amazon/amazon-eks-pod-identity-webhook:latest
|
||||
imagePullPolicy: Always
|
||||
# command:
|
||||
# - /webhook
|
||||
@@ -31,3 +31,7 @@ spec:
|
||||
- name: cert
|
||||
mountPath: /etc/webhook/certs
|
||||
readOnly: true
|
||||
# volumes:
|
||||
# - name: cert
|
||||
# secret:
|
||||
# secretName: pod-identity-webhook
|
||||
|
||||
Reference in New Issue
Block a user