mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
fix deployment
This commit is contained in:
@@ -117,21 +117,18 @@ func (b *baseManifestFactory) deployment() *appsv1.Deployment {
|
|||||||
// Command: []string{}, // Command must be patched
|
// Command: []string{}, // Command must be patched
|
||||||
VolumeMounts: []corev1.VolumeMount{
|
VolumeMounts: []corev1.VolumeMount{
|
||||||
{
|
{
|
||||||
Name: "webhook-certs",
|
Name: "cert",
|
||||||
MountPath: "/var/run/app/certs",
|
MountPath: "/etc/webhook/certs",
|
||||||
ReadOnly: false,
|
ReadOnly: true,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
Volumes: []corev1.Volume{
|
// Volumes: []corev1.Volume{ //Volumes must be patched
|
||||||
{
|
// {
|
||||||
Name: "webhook-certs",
|
// Name: "cert",
|
||||||
VolumeSource: corev1.VolumeSource{
|
// },
|
||||||
EmptyDir: &corev1.EmptyDirVolumeSource{},
|
// },
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|||||||
+3
-6
@@ -28,9 +28,6 @@ spec:
|
|||||||
# - --token-audience=sts.amazonaws.com
|
# - --token-audience=sts.amazonaws.com
|
||||||
# - --logtostderr
|
# - --logtostderr
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: webhook-certs
|
- name: cert
|
||||||
mountPath: /var/run/app/certs
|
mountPath: /etc/webhook/certs
|
||||||
readOnly: false
|
readOnly: true
|
||||||
volumes:
|
|
||||||
- name: webhook-certs
|
|
||||||
emptyDir: {}
|
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
|
|
||||||
"github.com/kkb0318/irsa-manager/internal/manifests"
|
"github.com/kkb0318/irsa-manager/internal/manifests"
|
||||||
|
corev1 "k8s.io/api/core/v1"
|
||||||
"k8s.io/apimachinery/pkg/types"
|
"k8s.io/apimachinery/pkg/types"
|
||||||
"sigs.k8s.io/controller-runtime/pkg/client"
|
"sigs.k8s.io/controller-runtime/pkg/client"
|
||||||
)
|
)
|
||||||
@@ -49,7 +50,7 @@ func myCertificate(base *baseManifestFactory) ([]client.Object, error) {
|
|||||||
deploy := base.deployment()
|
deploy := base.deployment()
|
||||||
deploy.Spec.Template.Spec.Containers[0].Command = []string{
|
deploy.Spec.Template.Spec.Containers[0].Command = []string{
|
||||||
"/webhook",
|
"/webhook",
|
||||||
"--in-cluster",
|
"--in-cluster=false",
|
||||||
fmt.Sprintf("--namespace=%s", WEBHOOK_NAMESPACE),
|
fmt.Sprintf("--namespace=%s", WEBHOOK_NAMESPACE),
|
||||||
fmt.Sprintf("--service-name=%s", base.serviceMeta.Name),
|
fmt.Sprintf("--service-name=%s", base.serviceMeta.Name),
|
||||||
fmt.Sprintf("--tls-secret=%s", secretNamespacedName.Name),
|
fmt.Sprintf("--tls-secret=%s", secretNamespacedName.Name),
|
||||||
@@ -57,6 +58,16 @@ func myCertificate(base *baseManifestFactory) ([]client.Object, error) {
|
|||||||
"--token-audience=sts.amazonaws.com",
|
"--token-audience=sts.amazonaws.com",
|
||||||
"--logtostderr",
|
"--logtostderr",
|
||||||
}
|
}
|
||||||
|
deploy.Spec.Template.Spec.Volumes = []corev1.Volume{
|
||||||
|
{
|
||||||
|
Name: "cert",
|
||||||
|
VolumeSource: corev1.VolumeSource{
|
||||||
|
Secret: &corev1.SecretVolumeSource{
|
||||||
|
SecretName: secretNamespacedName.Name,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}
|
||||||
mutate := base.mutatingWebhookConfiguration()
|
mutate := base.mutatingWebhookConfiguration()
|
||||||
mutate.Webhooks[0].ClientConfig.CABundle = []byte(tlsCredential.CaBundle())
|
mutate.Webhooks[0].ClientConfig.CABundle = []byte(tlsCredential.CaBundle())
|
||||||
resources = append(resources,
|
resources = append(resources,
|
||||||
|
|||||||
Reference in New Issue
Block a user