diff --git a/dashboard/main.yml b/app/dashboard/main.yml similarity index 99% rename from dashboard/main.yml rename to app/dashboard/main.yml index 0e626a7..f4a5473 100644 --- a/dashboard/main.yml +++ b/app/dashboard/main.yml @@ -303,4 +303,4 @@ spec: effect: NoSchedule volumes: - name: tmp-volume - emptyDir: {} + emptyDir: {} \ No newline at end of file diff --git a/app/headlamp/main.yml b/app/headlamp/main.yml new file mode 100644 index 0000000..da451ea --- /dev/null +++ b/app/headlamp/main.yml @@ -0,0 +1,172 @@ +# Copyright 2017 The Kubernetes Authors. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +apiVersion: v1 +kind: Namespace +metadata: + name: headlamp + +--- + +apiVersion: v1 +kind: ServiceAccount +metadata: + labels: + k8s-app: headlamp + name: headlamp + namespace: headlamp + +--- + +kind: Service +apiVersion: v1 +metadata: + labels: + k8s-app: headlamp + name: headlamp + namespace: headlamp +spec: + ports: + - name: http + port: 80 + targetPort: 4466 + selector: + k8s-app: headlamp + +--- + +apiVersion: v1 +kind: Secret +metadata: + labels: + k8s-app: headlamp + name: headlamp-token + namespace: headlamp + annotations: + kubernetes.io/service-account.name: headlamp +type: kubernetes.io/service-account-token + +--- + +kind: ClusterRole +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + labels: + k8s-app: headlamp + name: headlamp +rules: +- apiGroups: [""] + resources: ["pods", "pods/log", "services", "configmaps", "secrets", "nodes", "namespaces", "events"] + verbs: ["get", "list", "watch"] +- apiGroups: ["apps"] + resources: ["deployments", "replicasets", "daemonsets", "statefulsets"] + verbs: ["get", "list", "watch"] +- apiGroups: ["batch"] + resources: ["jobs", "cronjobs"] + verbs: ["get", "list", "watch"] +- apiGroups: ["metrics.k8s.io"] + resources: ["pods", "nodes"] + verbs: ["get", "list", "watch"] +- apiGroups: ["networking.k8s.io"] + resources: ["ingresses", "networkpolicies"] + verbs: ["get", "list", "watch"] +- apiGroups: ["rbac.authorization.k8s.io"] + resources: ["roles", "rolebindings", "clusterroles", "clusterrolebindings"] + verbs: ["get", "list", "watch"] + +--- + +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + labels: + k8s-app: headlamp + name: headlamp +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: headlamp +subjects: +- kind: ServiceAccount + name: headlamp + namespace: headlamp + +--- + +kind: Deployment +apiVersion: apps/v1 +metadata: + labels: + k8s-app: headlamp + name: headlamp + namespace: headlamp +spec: + replicas: 1 + revisionHistoryLimit: 10 + selector: + matchLabels: + k8s-app: headlamp + template: + metadata: + labels: + k8s-app: headlamp + spec: + securityContext: + seccompProfile: + type: RuntimeDefault + serviceAccountName: headlamp + hostNetwork: true + dnsPolicy: ClusterFirstWithHostNet + nodeSelector: + "kubernetes.io/os": linux + tolerations: + - key: node-role.kubernetes.io/master + effect: NoSchedule + containers: + - name: headlamp + image: ghcr.io/headlamp-k8s/headlamp:v0.43.0 + imagePullPolicy: IfNotPresent + args: + - -in-cluster + - -plugins-dir=/headlamp/plugins + - -base-url=/headlamp + ports: + - containerPort: 4466 + name: http + protocol: TCP + readinessProbe: + httpGet: + scheme: HTTP + path: /headlamp/ + port: 4466 + initialDelaySeconds: 30 + timeoutSeconds: 30 + livenessProbe: + httpGet: + scheme: HTTP + path: /headlamp/ + port: 4466 + initialDelaySeconds: 30 + timeoutSeconds: 30 + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + runAsNonRoot: true + runAsUser: 1000 + volumeMounts: + - mountPath: /tmp + name: tmp-volume + volumes: + - name: tmp-volume + emptyDir: {} \ No newline at end of file diff --git a/metrics-server/main.yml b/app/metrics-server/main.yml similarity index 94% rename from metrics-server/main.yml rename to app/metrics-server/main.yml index f030131..12d65ff 100644 --- a/metrics-server/main.yml +++ b/app/metrics-server/main.yml @@ -104,7 +104,8 @@ metadata: namespace: kube-system spec: ports: - - name: https + - appProtocol: https + name: https port: 443 protocol: TCP targetPort: https @@ -130,6 +131,8 @@ spec: labels: k8s-app: metrics-server spec: + hostNetwork: true + dnsPolicy: ClusterFirstWithHostNet containers: - args: - --cert-dir=/tmp @@ -138,7 +141,7 @@ spec: - --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname - --kubelet-use-node-status-port - --metric-resolution=15s - image: registry.k8s.io/metrics-server/metrics-server:v0.6.4 + image: registry.k8s.io/metrics-server/metrics-server:v0.8.1 imagePullPolicy: IfNotPresent livenessProbe: failureThreshold: 3 @@ -166,9 +169,14 @@ spec: memory: 200Mi securityContext: allowPrivilegeEscalation: false + capabilities: + drop: + - ALL readOnlyRootFilesystem: true runAsNonRoot: true runAsUser: 1000 + seccompProfile: + type: RuntimeDefault volumeMounts: - mountPath: /tmp name: tmp-dir @@ -194,4 +202,4 @@ spec: name: metrics-server namespace: kube-system version: v1beta1 - versionPriority: 100 + versionPriority: 100 \ No newline at end of file diff --git a/cluster-role/binding/noc.yml b/cluster-role/binding/noc.yml index 94afdb4..4d0e8de 100644 --- a/cluster-role/binding/noc.yml +++ b/cluster-role/binding/noc.yml @@ -5,7 +5,7 @@ metadata: subjects: - kind: ServiceAccount name: web - namespace: kubernetes-dashboard + namespace: headlamp roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole diff --git a/role/binding/noc.yml b/role/binding/noc.yml index 4f643e0..5b0b8f3 100644 --- a/role/binding/noc.yml +++ b/role/binding/noc.yml @@ -2,6 +2,7 @@ apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: noc + namespace: headlamp subjects: - apiGroup: rbac.authorization.k8s.io kind: User diff --git a/role/noc.yml b/role/noc.yml index 15bda59..ef39933 100644 --- a/role/noc.yml +++ b/role/noc.yml @@ -2,11 +2,15 @@ apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: noc + namespace: headlamp rules: - apiGroups: - '' resources: + - services - services/proxy + - pods + - pods/portforward verbs: - get - list diff --git a/service-account/web.yml b/service-account/web.yml index 6587c0e..6f9d752 100644 --- a/service-account/web.yml +++ b/service-account/web.yml @@ -2,4 +2,4 @@ apiVersion: v1 kind: ServiceAccount metadata: name: web - namespace: kubernetes-dashboard + namespace: headlamp