Skip to content

Commit e816c11

Browse files
Merge pull request #660 from wking/explicit-kube-api-access-volume
Bug 2005581: install/0000_00_cluster-version-operator_03_deployment: Explicit kube-api-access
2 parents e4eefca + 97289cc commit e816c11

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed

install/0000_00_cluster-version-operator_03_deployment.yaml

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,7 @@ spec:
2020
labels:
2121
k8s-app: cluster-version-operator
2222
spec:
23+
automountServiceAccountToken: false
2324
containers:
2425
- name: cluster-version-operator
2526
image: {{.ReleaseImage}}
@@ -48,6 +49,9 @@ spec:
4849
- mountPath: /etc/tls/serving-cert
4950
name: serving-cert
5051
readOnly: true
52+
- mountPath: /var/run/secrets/kubernetes.io/serviceaccount
53+
name: kube-api-access
54+
readOnly: true
5155
env:
5256
- name: KUBERNETES_SERVICE_PORT # allows CVO to communicate with apiserver directly on same host. Is substituted with port from infrastructures.status.apiServerInternalURL if available.
5357
value: "6443"
@@ -92,3 +96,21 @@ spec:
9296
- name: serving-cert
9397
secret:
9498
secretName: cluster-version-operator-serving-cert
99+
- name: kube-api-access
100+
projected:
101+
defaultMode: 420
102+
sources:
103+
- serviceAccountToken:
104+
expirationSeconds: 3600
105+
path: token
106+
- configMap:
107+
items:
108+
- key: ca.crt
109+
path: ca.crt
110+
name: kube-root-ca.crt
111+
- downwardAPI:
112+
items:
113+
- fieldRef:
114+
apiVersion: v1
115+
fieldPath: metadata.namespace
116+
path: namespace

0 commit comments

Comments
 (0)