imfreedom/k8s-cluster
Clone
Summary
Browse
Changes
Graph
Add pidgin 2.x.y docs and antiaffinity rules for all deployments with more than 1 replica
2019-05-24, Gary Kramlich
50c362864102
Add pidgin 2.x.y docs and antiaffinity rules for all deployments with more than 1 replica
apiVersion
:
v1
kind
:
ConfigMap
metadata
:
name
:
ingress-tcp-services
namespace
:
kube-public
labels
:
app
:
ingress
role
:
controller
data
:
54663
:
pidgin/bamboo-agent:54663
---
apiVersion
:
v1
kind
:
ConfigMap
metadata
:
name
:
ingress-configuration
namespace
:
kube-public
labels
:
app
:
ingress
role
:
controller
---
apiVersion
:
v1
kind
:
ServiceAccount
metadata
:
name
:
ingress-serviceaccount
namespace
:
kube-public
labels
:
app
:
ingress
role
:
controller
---
apiVersion
:
rbac.authorization.k8s.io/v1beta1
kind
:
ClusterRole
metadata
:
name
:
ingress-clusterrole
labels
:
app
:
ingress
role
:
controller
rules
:
-
apiGroups
:
-
""
resources
:
-
configmaps
-
endpoints
-
nodes
-
pods
-
secrets
verbs
:
-
list
-
watch
-
apiGroups
:
-
""
resources
:
-
nodes
verbs
:
-
get
-
apiGroups
:
-
""
resources
:
-
services
verbs
:
-
get
-
list
-
watch
-
apiGroups
:
-
"extensions"
resources
:
-
ingresses
verbs
:
-
get
-
list
-
watch
-
apiGroups
:
-
""
resources
:
-
events
verbs
:
-
create
-
patch
-
apiGroups
:
-
"extensions"
resources
:
-
ingresses/status
verbs
:
-
update
---
apiVersion
:
rbac.authorization.k8s.io/v1beta1
kind
:
ClusterRoleBinding
metadata
:
name
:
ingress-clusterrole-nisa-binding
labels
:
app
:
ingress
role
:
controller
roleRef
:
apiGroup
:
rbac.authorization.k8s.io
kind
:
ClusterRole
name
:
ingress-clusterrole
subjects
:
-
kind
:
ServiceAccount
name
:
ingress-serviceaccount
namespace
:
kube-public
---
apiVersion
:
rbac.authorization.k8s.io/v1beta1
kind
:
Role
metadata
:
name
:
ingress-role
namespace
:
kube-public
labels
:
app
:
ingress
role
:
controller
rules
:
-
apiGroups
:
-
""
resources
:
-
configmaps
-
pods
-
secrets
-
namespaces
verbs
:
-
get
-
apiGroups
:
-
""
resources
:
-
configmaps
resourceNames
:
# Defaults to "<election-id>-<ingress-class>"
# Here: "<ingress-controller-leader>-<nginx>"
# This has to be adapted if you change either parameter
# when launching the nginx-ingress-controller.
-
"ingress-controller-leader-nginx"
verbs
:
-
get
-
update
-
apiGroups
:
-
""
resources
:
-
configmaps
verbs
:
-
create
-
apiGroups
:
-
""
resources
:
-
endpoints
verbs
:
-
get
---
apiVersion
:
rbac.authorization.k8s.io/v1beta1
kind
:
RoleBinding
metadata
:
name
:
ingress-role-nisa-binding
namespace
:
kube-public
labels
:
app
:
ingress
role
:
controller
roleRef
:
apiGroup
:
rbac.authorization.k8s.io
kind
:
Role
name
:
ingress-role
subjects
:
-
kind
:
ServiceAccount
name
:
ingress-serviceaccount
namespace
:
kube-public
---
apiVersion
:
extensions/v1beta1
kind
:
Deployment
metadata
:
name
:
ingress-controller
namespace
:
kube-public
labels
:
app
:
ingress
role
:
public
spec
:
replicas
:
2
selector
:
matchLabels
:
app
:
ingress
role
:
controller
template
:
metadata
:
labels
:
app
:
ingress
role
:
controller
spec
:
serviceAccountName
:
ingress-serviceaccount
containers
:
-
name
:
nginx-ingress-controller
image
:
quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.20.0
args
:
-
/nginx-ingress-controller
-
--configmap=$(POD_NAMESPACE)/ingress-configuration
-
--publish-service=$(POD_NAMESPACE)/ingress
-
--annotations-prefix=nginx.ingress.kubernetes.io
-
--tcp-services-configmap=$(POD_NAMESPACE)/ingress-tcp-services
securityContext
:
capabilities
:
drop
:
-
ALL
add
:
-
NET_BIND_SERVICE
# www-data -> 33
runAsUser
:
33
env
:
-
name
:
POD_NAME
valueFrom
:
fieldRef
:
fieldPath
:
metadata.name
-
name
:
POD_NAMESPACE
valueFrom
:
fieldRef
:
fieldPath
:
metadata.namespace
ports
:
-
name
:
http
containerPort
:
80
-
name
:
https
containerPort
:
443
-
name
:
bamboo-agent
containerPort
:
54663
livenessProbe
:
failureThreshold
:
3
httpGet
:
path
:
/healthz
port
:
10254
scheme
:
HTTP
initialDelaySeconds
:
10
periodSeconds
:
10
successThreshold
:
1
timeoutSeconds
:
1
readinessProbe
:
failureThreshold
:
3
httpGet
:
path
:
/healthz
port
:
10254
scheme
:
HTTP
periodSeconds
:
10
successThreshold
:
1
timeoutSeconds
:
1
---
apiVersion
:
v1
kind
:
Service
metadata
:
name
:
ingress
namespace
:
kube-public
labels
:
app
:
ingress
role
:
controller
spec
:
type
:
LoadBalancer
selector
:
app
:
ingress
role
:
controller
ports
:
-
name
:
http
port
:
80
targetPort
:
http
-
name
:
https
port
:
443
targetPort
:
https
-
name
:
bamboo-agent
port
:
54663
targetPort
:
bamboo-agent
---