--- # Dashboard credentials for local testing. Replace the values, or create the # Secret out-of-band, before applying. Keys map 1:1 to the operator env vars. apiVersion: v1 kind: Secret metadata: name: cephrgw-credentials namespace: cephrgw-system type: Opaque stringData: CEPH_DASHBOARD_URL: "https://dashboard.ceph.unkin.net" CEPH_DASHBOARD_USERNAME: "k8s-cephrgw-operator" CEPH_DASHBOARD_PASSWORD: "change-me" # Optional: the S3 endpoint written into credential Secrets for consumers. CEPH_RGW_ENDPOINT: "https://s3.ceph.unkin.net" # Optional: set to "true" to skip TLS verification (dev only). # CEPH_DASHBOARD_INSECURE: "true" --- apiVersion: apps/v1 kind: Deployment metadata: name: cephrgw-operator namespace: cephrgw-system labels: app.kubernetes.io/name: cephrgw-operator spec: replicas: 1 selector: matchLabels: app.kubernetes.io/name: cephrgw-operator template: metadata: labels: app.kubernetes.io/name: cephrgw-operator spec: serviceAccountName: cephrgw-operator securityContext: runAsNonRoot: true containers: - name: operator image: cephrgw-operator:dev imagePullPolicy: IfNotPresent args: - --metrics-bind-address=:8080 - --health-probe-bind-address=:8081 - --leader-elect envFrom: - secretRef: name: cephrgw-credentials ports: - containerPort: 8080 name: metrics - containerPort: 8081 name: health readinessProbe: httpGet: path: /readyz port: 8081 livenessProbe: httpGet: path: /healthz port: 8081 securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: ["ALL"] resources: requests: cpu: 50m memory: 64Mi limits: cpu: 500m memory: 256Mi