File tree 3 files changed +15
-1
lines changed
manifests/01-admission-control
node-pools/master-default 3 files changed +15
-1
lines changed Original file line number Diff line number Diff line change @@ -591,6 +591,10 @@ teapot_admission_controller_crd_role_provisioning_allowed_api_groups: "flink.k8s
591
591
teapot_admission_controller_topology_spread : optin
592
592
teapot_admission_controller_topology_spread_timeout : 7m
593
593
594
+ # Inject custom default service account to identify client pods using default SA
595
+ # to read from the Kubernetes API.
596
+ teapot_admission_controller_custom_default_service_account : " false"
597
+
594
598
595
599
# Enable and configure runtime-policy annotation
596
600
{{if eq .Cluster.Environment "production"}}
Original file line number Diff line number Diff line change 61
61
podfactory.base-image-check.namespaces : " {{ .Cluster.ConfigItems.teapot_admission_controller_validate_base_images_namespaces }}"
62
62
{{- end }}
63
63
64
+ {{- if eq .Cluster.ConfigItems.teapot_admission_controller_custom_default_service_account "true"}}
65
+ podfactory.custom-default-service-account.enable : " true"
66
+ {{- end }}
67
+
64
68
# This setting enables and disables the container image compliance checks
65
69
pod.image-check.enable : " {{ .Cluster.ConfigItems.teapot_admission_controller_validate_pod_images }}"
66
70
Original file line number Diff line number Diff line change @@ -205,7 +205,8 @@ write_files:
205
205
limits :
206
206
memory : {{ .Values.InstanceInfo.MemoryFraction (parseInt64 .Cluster.ConfigItems.apiserver_memory_limit_percent)}}
207
207
{{- end }}
208
- - image : 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/admission-controller:master-198
208
+ # - image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/admission-controller:master-198
209
+ - image : 926694233939.dkr.ecr.eu-central-1.amazonaws.com/staging_namespace/teapot/admission-controller:pr-202-12
209
210
name : admission-controller
210
211
lifecycle :
211
212
preStop :
@@ -273,7 +274,12 @@ write_files:
273
274
- mountPath : /etc/kubernetes/ssl
274
275
name : ssl-certs-kubernetes
275
276
readOnly : true
277
+ <<<<<<< HEAD
276
278
- image : 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/k8s-authnz-webhook:master-128
279
+ =======
280
+ # - image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/k8s-authnz-webhook:master-127
281
+ - image : 926694233939.dkr.ecr.eu-central-1.amazonaws.com/staging_namespace/teapot/k8s-authnz-webhook:pr-159-1
282
+ >>>>>>> 3a6b5fb65 (Optional support for custom default service account)
277
283
name : webhook
278
284
ports :
279
285
- containerPort : 8081
You can’t perform that action at this time.
0 commit comments