apiVersion: apps/v1 kind: Deployment metadata: name: pod-identity-webhook namespace: kube-system spec: replicas: 1 selector: matchLabels: app: pod-identity-webhook template: metadata: labels: app: pod-identity-webhook spec: serviceAccountName: pod-identity-webhook containers: - name: pod-identity-webhook image: quay.io/amis/pod-identity-webhook:v0.0.1 imagePullPolicy: Always command: - /webhook - --in-cluster - --namespace=kube-system - --service-name=pod-identity-webhook - --tls-secret=pod-identity-webhook - --annotation-prefix=eks.amazonaws.com - --token-audience=sts.amazonaws.com - --logtostderr volumeMounts: - name: webhook-certs mountPath: /var/run/app/certs readOnly: false volumes: - name: webhook-certs emptyDir: {}