Repository navigation
Expand file tree
/
Copy pathmanager_auth_proxy_patch.yaml
More file actions
45 lines (45 loc) · 2.02 KB
/
Copy pathmanager_auth_proxy_patch.yaml
File metadata and controls
45 lines (45 loc) · 2.02 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
# This patch inject a sidecar container which is a HTTP proxy for the
# controller manager, it performs RBAC authorization against the Kubernetes API using SubjectAccessReviews.
apiVersion: apps/v1
kind: Deployment
metadata:
name: manager
namespace: system
spec:
template:
spec:
containers:
- name: kube-rbac-proxy
image: gcr.io/kubebuilder/kube-rbac-proxy:v0.8.0
args:
- "--secure-listen-address=0.0.0.0:8443"
- "--upstream=http://127.0.0.1:8080/"
- "--logtostderr=true"
- "--v=10"
ports:
- containerPort: 8443
protocol: TCP
name: https
- name: manager
args:
- "--health-probe-bind-address=:8081"
- "--metrics-bind-address=127.0.0.1:8080"
# Required for the kube-rbac-proxy sidecar above to be able to scrape
# this manager at all. --metrics-secure defaults to TRUE, which makes
# controller-runtime serve the metrics endpoint over TLS *and* wrap it
# in its own authn/authz filter — while the sidecar is configured with
# "--upstream=http://127.0.0.1:8080/", plain HTTP. Left at the default
# the proxy speaks HTTP to a TLS listener and /metrics is unreachable
# through the only path the Service exposes.
#
# Plain HTTP on loopback is the intended kube-rbac-proxy arrangement,
# not a weakening of it: the endpoint is bound to 127.0.0.1 so nothing
# outside the pod can reach it directly, and the sidecar is what
# terminates TLS on 8443 and authorizes callers by SubjectAccessReview.
- "--metrics-secure=false"
- "--leader-elect"
- "--log-level=debug"
- "--rbac-resource-prefix=kubeslice-rbac"
- "--project-namespace-prefix=kubeslice"
- "--controller-end-point=https://127.0.0.1:36515"
- "--ovpn-job-image=aveshasystems/gateway-certs-generator:latest"