0
|
1 apiVersion: batch/v1
|
|
2 kind: Job
|
|
3 metadata:
|
|
4 labels:
|
|
5 app.kubernetes.io/name: pomerium
|
|
6 name: pomerium-gen-secrets
|
|
7 namespace: pomerium
|
|
8 spec:
|
|
9 template:
|
|
10 metadata:
|
|
11 labels:
|
|
12 app.kubernetes.io/name: pomerium
|
|
13 name: pomerium-gen-secrets
|
|
14 spec:
|
|
15 containers:
|
|
16 - args:
|
|
17 - gen-secrets
|
|
18 - --secrets=$(POD_NAMESPACE)/bootstrap
|
|
19 env:
|
|
20 - name: POD_NAMESPACE
|
|
21 valueFrom:
|
|
22 fieldRef:
|
|
23 fieldPath: metadata.namespace
|
8
|
24 image: pomerium/ingress-controller:sha-efe2d11
|
0
|
25 imagePullPolicy: IfNotPresent
|
|
26 name: gen-secrets
|
|
27 securityContext:
|
|
28 allowPrivilegeEscalation: false
|
|
29 nodeSelector:
|
|
30 kubernetes.io/os: linux
|
|
31 restartPolicy: OnFailure
|
|
32 securityContext:
|
|
33 fsGroup: 1000
|
|
34 runAsNonRoot: true
|
|
35 runAsUser: 1000
|
|
36 serviceAccountName: pomerium-gen-secrets
|