Move the spiffe-csi-driver into a sub chart
Signed-off-by: Marco Franssen <[email protected]> Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
@@ -69,69 +69,6 @@ spec:
|
||||
periodSeconds: 60
|
||||
resources:
|
||||
{{- toYaml .Values.agent.resources | nindent 12 }}
|
||||
# This is the container which runs the SPIFFE CSI driver.
|
||||
- name: spiffe-csi-driver
|
||||
image: {{ template "spire.image" .Values.csiDriver }}
|
||||
imagePullPolicy: {{ .Values.csiDriver.image.pullPolicy }}
|
||||
args: [
|
||||
"-workload-api-socket-dir", "/spire-agent-socket",
|
||||
"-csi-socket-path", "/spiffe-csi/csi.sock",
|
||||
]
|
||||
env:
|
||||
# The CSI driver needs a unique node ID. The node name can be
|
||||
# used for this purpose.
|
||||
- name: MY_NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.nodeName
|
||||
volumeMounts:
|
||||
# The volume containing the SPIRE agent socket. The SPIFFE CSI
|
||||
# driver will mount this directory into containers.
|
||||
- mountPath: /spire-agent-socket
|
||||
name: spire-agent-socket-dir
|
||||
readOnly: true
|
||||
# The volume that will contain the CSI driver socket shared
|
||||
# with the kubelet and the driver registrar.
|
||||
- mountPath: /spiffe-csi
|
||||
name: spiffe-csi-socket-dir
|
||||
# The volume containing mount points for containers.
|
||||
- mountPath: /var/lib/kubelet/pods
|
||||
mountPropagation: Bidirectional
|
||||
name: mountpoint-dir
|
||||
securityContext:
|
||||
privileged: true
|
||||
resources:
|
||||
{{- toYaml .Values.csiDriver.resources | nindent 12 }}
|
||||
# This container runs the CSI Node Driver Registrar which takes care
|
||||
# of all the little details required to register a CSI driver with
|
||||
# the kubelet.
|
||||
- name: node-driver-registrar
|
||||
image: {{ template "spire.image" .Values.nodeDriverRegistrar }}
|
||||
imagePullPolicy: {{ .Values.nodeDriverRegistrar.image.pullPolicy }}
|
||||
args: [
|
||||
"-csi-address", "/spiffe-csi/csi.sock",
|
||||
"-kubelet-registration-path", "/var/lib/kubelet/plugins/csi.spiffe.io/csi.sock",
|
||||
"-health-port", "9809"
|
||||
]
|
||||
volumeMounts:
|
||||
# The registrar needs access to the SPIFFE CSI driver socket
|
||||
- mountPath: /spiffe-csi
|
||||
name: spiffe-csi-socket-dir
|
||||
# The registrar needs access to the Kubelet plugin registration
|
||||
# directory
|
||||
- name: kubelet-plugin-registration-dir
|
||||
mountPath: /registration
|
||||
ports:
|
||||
- containerPort: 9809
|
||||
name: healthz
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: healthz
|
||||
initialDelaySeconds: 5
|
||||
timeoutSeconds: 5
|
||||
resources:
|
||||
{{- toYaml .Values.nodeDriverRegistrar.resources | nindent 12 }}
|
||||
volumes:
|
||||
- name: spire-config
|
||||
configMap:
|
||||
@@ -154,19 +91,3 @@ spec:
|
||||
hostPath:
|
||||
path: {{ dir .Values.agent.config.socketPath }}
|
||||
type: DirectoryOrCreate
|
||||
# This volume is where the socket for kubelet->driver communication lives
|
||||
- name: spiffe-csi-socket-dir
|
||||
hostPath:
|
||||
path: /var/lib/kubelet/plugins/csi.spiffe.io
|
||||
type: DirectoryOrCreate
|
||||
# This volume is where the SPIFFE CSI driver mounts volumes
|
||||
- name: mountpoint-dir
|
||||
hostPath:
|
||||
path: /var/lib/kubelet/pods
|
||||
type: Directory
|
||||
# This volume is where the node-driver-registrar registers the plugin
|
||||
# with kubelet
|
||||
- name: kubelet-plugin-registration-dir
|
||||
hostPath:
|
||||
path: /var/lib/kubelet/plugins_registry
|
||||
type: Directory
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: CSIDriver
|
||||
metadata:
|
||||
name: "csi.spiffe.io"
|
||||
spec:
|
||||
# Only ephemeral, inline volumes are supported. There is no need for a
|
||||
# controller to provision and attach volumes.
|
||||
attachRequired: false
|
||||
|
||||
# Request the pod information which the CSI driver uses to verify that an
|
||||
# ephemeral mount was requested.
|
||||
podInfoOnMount: true
|
||||
|
||||
# Don't change ownership on the contents of the mount since the Workload API
|
||||
# Unix Domain Socket is typically open to all (i.e. 0777).
|
||||
fsGroupPolicy: None
|
||||
|
||||
# Declare support for ephemeral volumes only.
|
||||
volumeLifecycleModes:
|
||||
- Ephemeral
|
||||
Reference in New Issue
Block a user