Merge pull request 'feat: migration to v5 accounts' (#6652) from tmp/service-account into main
Reviewed-on: #6652
This commit was merged in pull request #6652.
This commit is contained in:
@@ -8,8 +8,6 @@ homepage:
|
|||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
annotations:
|
annotations:
|
||||||
reloader.stakater.com/auto: "true"
|
reloader.stakater.com/auto: "true"
|
||||||
serviceAccount:
|
|
||||||
name: homepage
|
|
||||||
pod:
|
pod:
|
||||||
automountServiceAccountToken: true
|
automountServiceAccountToken: true
|
||||||
containers:
|
containers:
|
||||||
@@ -27,10 +25,6 @@ homepage:
|
|||||||
requests:
|
requests:
|
||||||
cpu: 1m
|
cpu: 1m
|
||||||
memory: 128Mi
|
memory: 128Mi
|
||||||
serviceAccount:
|
|
||||||
homepage:
|
|
||||||
enabled: true
|
|
||||||
staticToken: true
|
|
||||||
configMaps:
|
configMaps:
|
||||||
config:
|
config:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
|||||||
@@ -4,8 +4,8 @@ immich:
|
|||||||
type: deployment
|
type: deployment
|
||||||
replicas: 1
|
replicas: 1
|
||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
serviceAccount:
|
pod:
|
||||||
name: immich
|
automountServiceAccountToken: true
|
||||||
containers:
|
containers:
|
||||||
main:
|
main:
|
||||||
image:
|
image:
|
||||||
@@ -88,10 +88,6 @@ immich:
|
|||||||
gpu.intel.com/i915: 1
|
gpu.intel.com/i915: 1
|
||||||
cpu: 10m
|
cpu: 10m
|
||||||
memory: 500Mi
|
memory: 500Mi
|
||||||
serviceAccount:
|
|
||||||
immich:
|
|
||||||
enabled: true
|
|
||||||
staticToken: true
|
|
||||||
service:
|
service:
|
||||||
main:
|
main:
|
||||||
controller: main
|
controller: main
|
||||||
|
|||||||
@@ -4,8 +4,8 @@ isponsorblocktv:
|
|||||||
type: deployment
|
type: deployment
|
||||||
replicas: 1
|
replicas: 1
|
||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
serviceAccount:
|
pod:
|
||||||
name: isponsorblocktv
|
automountServiceAccountToken: true
|
||||||
containers:
|
containers:
|
||||||
main:
|
main:
|
||||||
image:
|
image:
|
||||||
@@ -15,10 +15,6 @@ isponsorblocktv:
|
|||||||
requests:
|
requests:
|
||||||
cpu: 1m
|
cpu: 1m
|
||||||
memory: 20Mi
|
memory: 20Mi
|
||||||
serviceAccount:
|
|
||||||
isponsorblocktv:
|
|
||||||
enabled: true
|
|
||||||
staticToken: true
|
|
||||||
persistence:
|
persistence:
|
||||||
config:
|
config:
|
||||||
type: custom
|
type: custom
|
||||||
|
|||||||
@@ -121,17 +121,13 @@ ntfy-alertmanager:
|
|||||||
type: deployment
|
type: deployment
|
||||||
replicas: 1
|
replicas: 1
|
||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
serviceAccount:
|
pod:
|
||||||
name: ntfy-alertmanager
|
automountServiceAccountToken: true
|
||||||
containers:
|
containers:
|
||||||
main:
|
main:
|
||||||
image:
|
image:
|
||||||
repository: xenrox/ntfy-alertmanager
|
repository: xenrox/ntfy-alertmanager
|
||||||
tag: 1.0.0@sha256:81788c7905774b7b0b2ed6833b2bc4826a90a42e4b738706edcedd5f489e7a73
|
tag: 1.0.0@sha256:81788c7905774b7b0b2ed6833b2bc4826a90a42e4b738706edcedd5f489e7a73
|
||||||
serviceAccount:
|
|
||||||
ntfy-alertmanager:
|
|
||||||
enabled: true
|
|
||||||
staticToken: true
|
|
||||||
service:
|
service:
|
||||||
main:
|
main:
|
||||||
controller: main
|
controller: main
|
||||||
|
|||||||
@@ -29,8 +29,6 @@ kubelet-serving-cert-approver:
|
|||||||
type: deployment
|
type: deployment
|
||||||
replicas: 1
|
replicas: 1
|
||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
serviceAccount:
|
|
||||||
name: kubelet-serving-cert-approver
|
|
||||||
pod:
|
pod:
|
||||||
automountServiceAccountToken: true
|
automountServiceAccountToken: true
|
||||||
containers:
|
containers:
|
||||||
@@ -57,10 +55,6 @@ kubelet-serving-cert-approver:
|
|||||||
privileged: false
|
privileged: false
|
||||||
readOnlyRootFilesystem: true
|
readOnlyRootFilesystem: true
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
serviceAccount:
|
|
||||||
kubelet-serving-cert-approver:
|
|
||||||
enabled: true
|
|
||||||
staticToken: true
|
|
||||||
service:
|
service:
|
||||||
main:
|
main:
|
||||||
controller: main
|
controller: main
|
||||||
|
|||||||
@@ -176,8 +176,6 @@ matrix-hookshot:
|
|||||||
type: deployment
|
type: deployment
|
||||||
replicas: 1
|
replicas: 1
|
||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
serviceAccount:
|
|
||||||
name: matrix-synapse
|
|
||||||
containers:
|
containers:
|
||||||
main:
|
main:
|
||||||
image:
|
image:
|
||||||
|
|||||||
@@ -130,8 +130,8 @@ qbittorrent:
|
|||||||
reloader.stakater.com/auto: "true"
|
reloader.stakater.com/auto: "true"
|
||||||
replicas: 1
|
replicas: 1
|
||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
serviceAccount:
|
pod:
|
||||||
name: qbittorrent
|
automountServiceAccountToken: true
|
||||||
initContainers:
|
initContainers:
|
||||||
init-copy-config:
|
init-copy-config:
|
||||||
image:
|
image:
|
||||||
@@ -229,10 +229,6 @@ qbittorrent:
|
|||||||
requests:
|
requests:
|
||||||
cpu: 10m
|
cpu: 10m
|
||||||
memory: 70Mi
|
memory: 70Mi
|
||||||
serviceAccount:
|
|
||||||
qbittorrent:
|
|
||||||
enabled: true
|
|
||||||
staticToken: true
|
|
||||||
service:
|
service:
|
||||||
main:
|
main:
|
||||||
controller: main
|
controller: main
|
||||||
|
|||||||
@@ -4,8 +4,8 @@ searxng:
|
|||||||
type: deployment
|
type: deployment
|
||||||
replicas: 1
|
replicas: 1
|
||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
serviceAccount:
|
pod:
|
||||||
name: searxng
|
automountServiceAccountToken: true
|
||||||
containers:
|
containers:
|
||||||
main:
|
main:
|
||||||
image:
|
image:
|
||||||
@@ -63,6 +63,7 @@ searxng:
|
|||||||
serviceAccount:
|
serviceAccount:
|
||||||
searxng:
|
searxng:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
staticToken: true
|
||||||
service:
|
service:
|
||||||
api:
|
api:
|
||||||
controller: api
|
controller: api
|
||||||
|
|||||||
@@ -4,9 +4,8 @@ slskd:
|
|||||||
type: deployment
|
type: deployment
|
||||||
replicas: 1
|
replicas: 1
|
||||||
strategy: Recreate
|
strategy: Recreate
|
||||||
serviceAccount:
|
|
||||||
name: slskd
|
|
||||||
pod:
|
pod:
|
||||||
|
automountServiceAccountToken: true
|
||||||
securityContext:
|
securityContext:
|
||||||
fsGroup: 1000
|
fsGroup: 1000
|
||||||
fsGroupChangePolicy: OnRootMismatch
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
@@ -109,9 +108,6 @@ slskd:
|
|||||||
devic.es/tun: "1"
|
devic.es/tun: "1"
|
||||||
requests:
|
requests:
|
||||||
devic.es/tun: "1"
|
devic.es/tun: "1"
|
||||||
serviceAccount:
|
|
||||||
slskd:
|
|
||||||
enabled: true
|
|
||||||
service:
|
service:
|
||||||
main:
|
main:
|
||||||
controller: main
|
controller: main
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ etcd-backup:
|
|||||||
local:
|
local:
|
||||||
type: cronjob
|
type: cronjob
|
||||||
pod:
|
pod:
|
||||||
|
automountServiceAccountToken: true
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
node-role.kubernetes.io/control-plane: ""
|
node-role.kubernetes.io/control-plane: ""
|
||||||
tolerations:
|
tolerations:
|
||||||
@@ -15,8 +16,6 @@ etcd-backup:
|
|||||||
schedule: 0 2 * * *
|
schedule: 0 2 * * *
|
||||||
backoffLimit: 3
|
backoffLimit: 3
|
||||||
parallelism: 1
|
parallelism: 1
|
||||||
serviceAccount:
|
|
||||||
name: talos-backup
|
|
||||||
containers:
|
containers:
|
||||||
backup:
|
backup:
|
||||||
image:
|
image:
|
||||||
@@ -91,6 +90,7 @@ etcd-backup:
|
|||||||
remote:
|
remote:
|
||||||
type: cronjob
|
type: cronjob
|
||||||
pod:
|
pod:
|
||||||
|
automountServiceAccountToken: true
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
node-role.kubernetes.io/control-plane: ""
|
node-role.kubernetes.io/control-plane: ""
|
||||||
tolerations:
|
tolerations:
|
||||||
@@ -103,8 +103,6 @@ etcd-backup:
|
|||||||
schedule: 0 3 * * *
|
schedule: 0 3 * * *
|
||||||
backoffLimit: 3
|
backoffLimit: 3
|
||||||
parallelism: 1
|
parallelism: 1
|
||||||
serviceAccount:
|
|
||||||
name: talos-backup
|
|
||||||
containers:
|
containers:
|
||||||
backup:
|
backup:
|
||||||
image:
|
image:
|
||||||
@@ -179,6 +177,7 @@ etcd-backup:
|
|||||||
external:
|
external:
|
||||||
type: cronjob
|
type: cronjob
|
||||||
pod:
|
pod:
|
||||||
|
automountServiceAccountToken: true
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
node-role.kubernetes.io/control-plane: ""
|
node-role.kubernetes.io/control-plane: ""
|
||||||
tolerations:
|
tolerations:
|
||||||
@@ -191,8 +190,6 @@ etcd-backup:
|
|||||||
schedule: 0 4 * * *
|
schedule: 0 4 * * *
|
||||||
backoffLimit: 3
|
backoffLimit: 3
|
||||||
parallelism: 1
|
parallelism: 1
|
||||||
serviceAccount:
|
|
||||||
name: talos-backup
|
|
||||||
containers:
|
containers:
|
||||||
backup:
|
backup:
|
||||||
image:
|
image:
|
||||||
@@ -387,6 +384,7 @@ etcd-defrag:
|
|||||||
defrag-1:
|
defrag-1:
|
||||||
type: cronjob
|
type: cronjob
|
||||||
pod:
|
pod:
|
||||||
|
automountServiceAccountToken: true
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
node-role.kubernetes.io/control-plane: ""
|
node-role.kubernetes.io/control-plane: ""
|
||||||
tolerations:
|
tolerations:
|
||||||
@@ -399,8 +397,6 @@ etcd-defrag:
|
|||||||
schedule: 0 0 * * 0
|
schedule: 0 0 * * 0
|
||||||
backoffLimit: 3
|
backoffLimit: 3
|
||||||
parallelism: 1
|
parallelism: 1
|
||||||
serviceAccount:
|
|
||||||
name: talos-defrag
|
|
||||||
containers:
|
containers:
|
||||||
main:
|
main:
|
||||||
image:
|
image:
|
||||||
@@ -417,6 +413,7 @@ etcd-defrag:
|
|||||||
defrag-2:
|
defrag-2:
|
||||||
type: cronjob
|
type: cronjob
|
||||||
pod:
|
pod:
|
||||||
|
automountServiceAccountToken: true
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
node-role.kubernetes.io/control-plane: ""
|
node-role.kubernetes.io/control-plane: ""
|
||||||
tolerations:
|
tolerations:
|
||||||
@@ -429,8 +426,6 @@ etcd-defrag:
|
|||||||
schedule: 10 0 * * 0
|
schedule: 10 0 * * 0
|
||||||
backoffLimit: 3
|
backoffLimit: 3
|
||||||
parallelism: 1
|
parallelism: 1
|
||||||
serviceAccount:
|
|
||||||
name: talos-defrag
|
|
||||||
containers:
|
containers:
|
||||||
main:
|
main:
|
||||||
image:
|
image:
|
||||||
@@ -447,6 +442,7 @@ etcd-defrag:
|
|||||||
defrag-3:
|
defrag-3:
|
||||||
type: cronjob
|
type: cronjob
|
||||||
pod:
|
pod:
|
||||||
|
automountServiceAccountToken: true
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
node-role.kubernetes.io/control-plane: ""
|
node-role.kubernetes.io/control-plane: ""
|
||||||
tolerations:
|
tolerations:
|
||||||
@@ -459,8 +455,6 @@ etcd-defrag:
|
|||||||
schedule: 20 0 * * 0
|
schedule: 20 0 * * 0
|
||||||
backoffLimit: 3
|
backoffLimit: 3
|
||||||
parallelism: 1
|
parallelism: 1
|
||||||
serviceAccount:
|
|
||||||
name: talos-defrag
|
|
||||||
containers:
|
containers:
|
||||||
main:
|
main:
|
||||||
image:
|
image:
|
||||||
|
|||||||
@@ -101,14 +101,14 @@ snapshot:
|
|||||||
controllers:
|
controllers:
|
||||||
snapshot:
|
snapshot:
|
||||||
type: cronjob
|
type: cronjob
|
||||||
|
pod:
|
||||||
|
automountServiceAccountToken: true
|
||||||
cronjob:
|
cronjob:
|
||||||
suspend: false
|
suspend: false
|
||||||
timeZone: America/Chicago
|
timeZone: America/Chicago
|
||||||
schedule: 0 4 * * *
|
schedule: 0 4 * * *
|
||||||
backoffLimit: 3
|
backoffLimit: 3
|
||||||
parallelism: 1
|
parallelism: 1
|
||||||
serviceAccount:
|
|
||||||
name: vault
|
|
||||||
initContainers:
|
initContainers:
|
||||||
snapshot:
|
snapshot:
|
||||||
image:
|
image:
|
||||||
|
|||||||
Reference in New Issue
Block a user