Fix oidc health check using using scratch images

Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
Marco Franssen
2023-02-18 13:04:04 +01:00
committed by Marco Franssen
parent 765a4edaf8
commit ec61c387b0
2 changed files with 28 additions and 17 deletions
+16 -11
View File
@@ -40,8 +40,10 @@ spec:
args:
- -config
- /run/spire/oidc/config/oidc-discovery-provider.conf
{{- if not .Values.oidc.insecureScheme.enabled }}
ports:
- containerPort: 8008
name: health
{{- if not .Values.oidc.insecureScheme.enabled }}
- containerPort: 443
name: https
{{- end }}
@@ -55,16 +57,19 @@ spec:
- name: spire-oidc-config
mountPath: /run/spire/oidc/config/
readOnly: true
readinessProbe:
exec:
command: ["/bin/ps", "aux", "|", "grep", "oidc-discovery-provider -config /run/spire/oidc/config/oidc-discovery-provider.conf"]
initialDelaySeconds: 5
periodSeconds: 5
livenessProbe:
exec:
command: ["/bin/ps", "aux", "|", "grep", "oidc-discovery-provider -config /run/spire/oidc/config/oidc-discovery-provider.conf"]
initialDelaySeconds: 5
periodSeconds: 5
# Needs new release of spire to fix the http healthchecks
# readinessProbe:
# httpGet:
# path: /ready
# port: health
# initialDelaySeconds: 5
# periodSeconds: 5
# livenessProbe:
# httpGet:
# path: /live
# port: health
# initialDelaySeconds: 5
# periodSeconds: 5
resources:
{{- toYaml .Values.oidc.resources | nindent 12 }}
{{- if .Values.oidc.insecureScheme.enabled }}
@@ -28,6 +28,12 @@ data:
socket_path = "/run/spire/agent-sockets/agent.sock"
trust_domain = "{{ .Values.spire.trustDomain }}"
}
health_checks {
bind_port = "8008"
ready_path = "/ready"
live_path = "/live"
}
{{- if .Values.oidc.insecureScheme.enabled }}
default.conf.template: |
upstream oidc {