--- apiVersion: apps/v1 kind: Deployment metadata: name: cephrgw-operator namespace: cephrgw-system labels: app.kubernetes.io/name: cephrgw-operator annotations: # Restart the operator when the credentials Secret rotates. reloader.stakater.com/auto: "true" spec: replicas: 1 selector: matchLabels: app.kubernetes.io/name: cephrgw-operator template: metadata: labels: app.kubernetes.io/name: cephrgw-operator spec: serviceAccountName: cephrgw-operator securityContext: runAsNonRoot: true containers: - name: operator image: git.unkin.net/unkin/cephrgw-operator:v0.3.1 args: - --metrics-bind-address=:8080 - --health-probe-bind-address=:8081 - --leader-elect envFrom: # Provides CEPH_RGW_ACCESS_KEY/SECRET_KEY and the endpoints # (CEPH_RGW_ENDPOINT / CEPH_RGW_ADMIN_ENDPOINT), plus optional # CEPH_RGW_REGION / CEPH_RGW_CA / CEPH_RGW_INSECURE. Rendered from # Vault per docs/ceph-setup.md; not managed in GitOps. - secretRef: name: cephrgw-credentials env: # Trust the internal unkin.net (Vault PKI) CA so the operator can # verify radosgw's TLS cert. vault-ca-cert is reflected into every # namespace from the certificates namespace. - name: CEPH_RGW_CA_FILE value: /etc/vault-ca/ca.crt volumeMounts: - name: vault-ca-cert mountPath: /etc/vault-ca/ca.crt subPath: ca.crt readOnly: true ports: - containerPort: 8080 name: metrics - containerPort: 8081 name: health readinessProbe: httpGet: path: /readyz port: 8081 initialDelaySeconds: 5 periodSeconds: 10 livenessProbe: httpGet: path: /healthz port: 8081 initialDelaySeconds: 15 periodSeconds: 20 securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: ["ALL"] resources: requests: cpu: 50m memory: 64Mi limits: cpu: 500m memory: 256Mi volumes: - name: vault-ca-cert secret: secretName: vault-ca-cert