zhengtianbao
2 years ago
committed by
GitHub
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
7 changed files with 1 additions and 142 deletions
Split View
Diff Options
-
11roles/download/defaults/main.yml
-
7roles/kubernetes-apps/registry/tasks/main.yml
-
15roles/kubernetes-apps/registry/templates/registry-proxy-cr.yml.j2
-
13roles/kubernetes-apps/registry/templates/registry-proxy-crb.yml.j2
-
36roles/kubernetes-apps/registry/templates/registry-proxy-ds.yml.j2
-
56roles/kubernetes-apps/registry/templates/registry-proxy-psp.yml.j2
-
5roles/kubernetes-apps/registry/templates/registry-proxy-sa.yml.j2
@ -1,15 +0,0 @@ |
|||
--- |
|||
apiVersion: rbac.authorization.k8s.io/v1 |
|||
kind: ClusterRole |
|||
metadata: |
|||
name: psp:registry-proxy |
|||
namespace: {{ registry_namespace }} |
|||
rules: |
|||
- apiGroups: |
|||
- policy |
|||
resourceNames: |
|||
- registry-proxy |
|||
resources: |
|||
- podsecuritypolicies |
|||
verbs: |
|||
- use |
@ -1,13 +0,0 @@ |
|||
kind: RoleBinding |
|||
apiVersion: rbac.authorization.k8s.io/v1 |
|||
metadata: |
|||
name: psp:registry-proxy |
|||
namespace: {{ registry_namespace }} |
|||
subjects: |
|||
- kind: ServiceAccount |
|||
name: registry-proxy |
|||
namespace: {{ registry_namespace }} |
|||
roleRef: |
|||
kind: ClusterRole |
|||
name: psp:registry-proxy |
|||
apiGroup: rbac.authorization.k8s.io |
@ -1,36 +0,0 @@ |
|||
--- |
|||
apiVersion: apps/v1 |
|||
kind: DaemonSet |
|||
metadata: |
|||
name: registry-proxy |
|||
namespace: {{ registry_namespace }} |
|||
labels: |
|||
k8s-app: registry-proxy |
|||
version: v{{ registry_proxy_image_tag }} |
|||
spec: |
|||
selector: |
|||
matchLabels: |
|||
k8s-app: registry-proxy |
|||
version: v{{ registry_proxy_image_tag }} |
|||
template: |
|||
metadata: |
|||
labels: |
|||
k8s-app: registry-proxy |
|||
kubernetes.io/name: "registry-proxy" |
|||
version: v{{ registry_proxy_image_tag }} |
|||
spec: |
|||
priorityClassName: {% if registry_namespace == 'kube-system' %}system-node-critical{% else %}k8s-cluster-critical{% endif %}{{''}} |
|||
serviceAccountName: registry-proxy |
|||
containers: |
|||
- name: registry-proxy |
|||
image: {{ registry_proxy_image_repo }}:{{ registry_proxy_image_tag }} |
|||
imagePullPolicy: {{ k8s_image_pull_policy }} |
|||
env: |
|||
- name: REGISTRY_HOST |
|||
value: registry.{{ registry_namespace }}.svc.{{ dns_domain }} |
|||
- name: REGISTRY_PORT |
|||
value: "{{ registry_port }}" |
|||
ports: |
|||
- name: registry |
|||
containerPort: 80 |
|||
hostPort: {{ registry_port }} |
@ -1,56 +0,0 @@ |
|||
--- |
|||
apiVersion: policy/v1beta1 |
|||
kind: PodSecurityPolicy |
|||
metadata: |
|||
name: registry-proxy |
|||
annotations: |
|||
seccomp.security.alpha.kubernetes.io/defaultProfileName: 'runtime/default' |
|||
seccomp.security.alpha.kubernetes.io/allowedProfileNames: 'runtime/default' |
|||
{% if apparmor_enabled %} |
|||
apparmor.security.beta.kubernetes.io/defaultProfileName: 'runtime/default' |
|||
apparmor.security.beta.kubernetes.io/allowedProfileNames: 'runtime/default' |
|||
{% endif %} |
|||
labels: |
|||
addonmanager.kubernetes.io/mode: Reconcile |
|||
spec: |
|||
privileged: false |
|||
allowPrivilegeEscalation: false |
|||
requiredDropCapabilities: |
|||
- SETPCAP |
|||
- MKNOD |
|||
- AUDIT_WRITE |
|||
- NET_RAW |
|||
- DAC_OVERRIDE |
|||
- FOWNER |
|||
- FSETID |
|||
- KILL |
|||
- SYS_CHROOT |
|||
- SETFCAP |
|||
volumes: |
|||
- 'configMap' |
|||
- 'emptyDir' |
|||
- 'projected' |
|||
- 'secret' |
|||
- 'downwardAPI' |
|||
- 'persistentVolumeClaim' |
|||
hostNetwork: true |
|||
hostPorts: |
|||
- min: {{ registry_port }} |
|||
max: {{ registry_port }} |
|||
hostIPC: false |
|||
hostPID: false |
|||
runAsUser: |
|||
rule: 'RunAsAny' |
|||
seLinux: |
|||
rule: 'RunAsAny' |
|||
supplementalGroups: |
|||
rule: 'MustRunAs' |
|||
ranges: |
|||
- min: 1 |
|||
max: 65535 |
|||
fsGroup: |
|||
rule: 'MustRunAs' |
|||
ranges: |
|||
- min: 1 |
|||
max: 65535 |
|||
readOnlyRootFilesystem: false |
@ -1,5 +0,0 @@ |
|||
apiVersion: v1 |
|||
kind: ServiceAccount |
|||
metadata: |
|||
name: registry-proxy |
|||
namespace: {{ registry_namespace }} |
Write
Preview
Loading…
Cancel
Save