@@ -869,7 +869,9 @@ spec:
869
869
- create
870
870
serviceAccountName : openshift-gitops-operator-controller-manager
871
871
deployments :
872
- - name : openshift-gitops-operator-controller-manager
872
+ - label :
873
+ control-plane : gitops-operator
874
+ name : openshift-gitops-operator-controller-manager
873
875
spec :
874
876
replicas : 1
875
877
selector :
@@ -882,7 +884,39 @@ spec:
882
884
control-plane : gitops-operator
883
885
spec :
884
886
containers :
885
- - command :
887
+ - args :
888
+ - --secure-listen-address=0.0.0.0:8443
889
+ - --upstream=http://127.0.0.1:8080
890
+ - --tls-cert-file=/etc/tls/private/tls.crt
891
+ - --tls-private-key-file=/etc/tls/private/tls.key
892
+ - --logtostderr=true
893
+ - --allow-paths=/metrics
894
+ image : registry.redhat.io/openshift4/ose-kube-rbac-proxy@sha256:da5d5061dbc2ec5082cf14b6c600fb5400b83cf91d7ccebfa80680a238d275db
895
+ name : kube-rbac-proxy
896
+ ports :
897
+ - containerPort : 8443
898
+ name : metrics
899
+ resources :
900
+ limits :
901
+ cpu : 500m
902
+ memory : 128Mi
903
+ requests :
904
+ cpu : 1m
905
+ memory : 15Mi
906
+ securityContext :
907
+ allowPrivilegeEscalation : false
908
+ capabilities :
909
+ drop :
910
+ - ALL
911
+ volumeMounts :
912
+ - mountPath : /etc/tls/private
913
+ name : kube-rbac-proxy-tls
914
+ readOnly : true
915
+ - args :
916
+ - --health-probe-bind-address=:8081
917
+ - --metrics-bind-address=127.0.0.1:8080
918
+ - --leader-elect
919
+ command :
886
920
- /usr/local/bin/manager
887
921
env :
888
922
- name : ARGOCD_CLUSTER_CONFIG_NAMESPACES
@@ -915,6 +949,10 @@ spec:
915
949
runAsNonRoot : true
916
950
serviceAccountName : openshift-gitops-operator-controller-manager
917
951
terminationGracePeriodSeconds : 10
952
+ volumes :
953
+ - name : kube-rbac-proxy-tls
954
+ secret :
955
+ secretName : kube-rbac-proxy-tls
918
956
permissions :
919
957
- rules :
920
958
- apiGroups :
0 commit comments