Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion dashboard/main.yml → app/dashboard/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -303,4 +303,4 @@ spec:
effect: NoSchedule
volumes:
- name: tmp-volume
emptyDir: {}
emptyDir: {}
172 changes: 172 additions & 0 deletions app/headlamp/main.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,172 @@
# Copyright 2017 The Kubernetes Authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

apiVersion: v1
kind: Namespace
metadata:
name: headlamp

---

apiVersion: v1
kind: ServiceAccount
metadata:
labels:
k8s-app: headlamp
name: headlamp
namespace: headlamp

---

kind: Service
apiVersion: v1
metadata:
labels:
k8s-app: headlamp
name: headlamp
namespace: headlamp
spec:
ports:
- name: http
port: 80
targetPort: 4466
selector:
k8s-app: headlamp

---

apiVersion: v1
kind: Secret
metadata:
labels:
k8s-app: headlamp
name: headlamp-token
namespace: headlamp
annotations:
kubernetes.io/service-account.name: headlamp
type: kubernetes.io/service-account-token

---

kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
labels:
k8s-app: headlamp
name: headlamp
rules:
- apiGroups: [""]
resources: ["pods", "pods/log", "services", "configmaps", "secrets", "nodes", "namespaces", "events"]
verbs: ["get", "list", "watch"]
- apiGroups: ["apps"]
resources: ["deployments", "replicasets", "daemonsets", "statefulsets"]
verbs: ["get", "list", "watch"]
- apiGroups: ["batch"]
resources: ["jobs", "cronjobs"]
verbs: ["get", "list", "watch"]
- apiGroups: ["metrics.k8s.io"]
resources: ["pods", "nodes"]
verbs: ["get", "list", "watch"]
- apiGroups: ["networking.k8s.io"]
resources: ["ingresses", "networkpolicies"]
verbs: ["get", "list", "watch"]
- apiGroups: ["rbac.authorization.k8s.io"]
resources: ["roles", "rolebindings", "clusterroles", "clusterrolebindings"]
verbs: ["get", "list", "watch"]

---

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
labels:
k8s-app: headlamp
name: headlamp
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: headlamp
subjects:
- kind: ServiceAccount
name: headlamp
namespace: headlamp

---

kind: Deployment
apiVersion: apps/v1
metadata:
labels:
k8s-app: headlamp
name: headlamp
namespace: headlamp
spec:
replicas: 1
revisionHistoryLimit: 10
selector:
matchLabels:
k8s-app: headlamp
template:
metadata:
labels:
k8s-app: headlamp
spec:
securityContext:
seccompProfile:
type: RuntimeDefault
serviceAccountName: headlamp
hostNetwork: true
dnsPolicy: ClusterFirstWithHostNet
nodeSelector:
"kubernetes.io/os": linux
tolerations:
- key: node-role.kubernetes.io/master
effect: NoSchedule
containers:
- name: headlamp
image: ghcr.io/headlamp-k8s/headlamp:v0.43.0
imagePullPolicy: IfNotPresent
args:
- -in-cluster
- -plugins-dir=/headlamp/plugins
- -base-url=/headlamp
ports:
- containerPort: 4466
name: http
protocol: TCP
readinessProbe:
httpGet:
scheme: HTTP
path: /headlamp/
port: 4466
initialDelaySeconds: 30
timeoutSeconds: 30
livenessProbe:
httpGet:
scheme: HTTP
path: /headlamp/
port: 4466
initialDelaySeconds: 30
timeoutSeconds: 30
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
volumeMounts:
- mountPath: /tmp
name: tmp-volume
volumes:
- name: tmp-volume
emptyDir: {}
14 changes: 11 additions & 3 deletions metrics-server/main.yml → app/metrics-server/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,8 @@ metadata:
namespace: kube-system
spec:
ports:
- name: https
- appProtocol: https
name: https
port: 443
protocol: TCP
targetPort: https
Expand All @@ -130,6 +131,8 @@ spec:
labels:
k8s-app: metrics-server
spec:
hostNetwork: true
dnsPolicy: ClusterFirstWithHostNet
containers:
- args:
- --cert-dir=/tmp
Expand All @@ -138,7 +141,7 @@ spec:
- --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname
- --kubelet-use-node-status-port
- --metric-resolution=15s
image: registry.k8s.io/metrics-server/metrics-server:v0.6.4
image: registry.k8s.io/metrics-server/metrics-server:v0.8.1
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
Expand Down Expand Up @@ -166,9 +169,14 @@ spec:
memory: 200Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
volumeMounts:
- mountPath: /tmp
name: tmp-dir
Expand All @@ -194,4 +202,4 @@ spec:
name: metrics-server
namespace: kube-system
version: v1beta1
versionPriority: 100
versionPriority: 100
2 changes: 1 addition & 1 deletion cluster-role/binding/noc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ metadata:
subjects:
- kind: ServiceAccount
name: web
namespace: kubernetes-dashboard
namespace: headlamp
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
Expand Down
1 change: 1 addition & 0 deletions role/binding/noc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: noc
namespace: headlamp
subjects:
- apiGroup: rbac.authorization.k8s.io
kind: User
Expand Down
4 changes: 4 additions & 0 deletions role/noc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,15 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: noc
namespace: headlamp
rules:
- apiGroups:
- ''
resources:
- services
- services/proxy
- pods
- pods/portforward
verbs:
- get
- list
Expand Down
2 changes: 1 addition & 1 deletion service-account/web.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,4 @@ apiVersion: v1
kind: ServiceAccount
metadata:
name: web
namespace: kubernetes-dashboard
namespace: headlamp