feat(kanidm): 3 replicas, PDB maxUnavailable=1, host anti-affinity
- Increase replicas from 2 to 3 - Add kanidm-2 headless DNS SAN to TLS certificate - Add PodDisruptionBudget (maxUnavailable: 1) to maintain quorum during node drains - Add requiredDuringSchedulingIgnoredDuringExecution pod anti-affinity on kubernetes.io/hostname to spread replicas across distinct hosts - Update replication peers comment to include kanidm-2 cert exchange step
This commit is contained in:
@@ -20,6 +20,7 @@ spec:
|
||||
- kanidm.kanidm.svc.cluster.local
|
||||
- kanidm-0.kanidm-headless.kanidm.svc.cluster.local
|
||||
- kanidm-1.kanidm-headless.kanidm.svc.cluster.local
|
||||
- kanidm-2.kanidm-headless.kanidm.svc.cluster.local
|
||||
privateKey:
|
||||
algorithm: RSA
|
||||
size: 4096
|
||||
|
||||
Reference in New Issue
Block a user