summaryrefslogtreecommitdiffstats
path: root/roles/openshift_service_catalog/templates/controller_manager.j2
blob: e5e5f6b507b543161c5f60b2d7b8c6fb646c5b47 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
apiVersion: extensions/v1beta1
kind: DaemonSet
metadata:
  labels:
    app: controller-manager
  name: controller-manager
spec:
  selector:
    matchLabels:
      app: controller-manager
  strategy:
    rollingUpdate:
      maxUnavailable: 1
    type: RollingUpdate
  template:
    metadata:
      labels:
        app: controller-manager
    spec:
      serviceAccountName: service-catalog-controller
      nodeSelector:
{% for key, value in node_selector.iteritems() %}
        {{key}}: "{{value}}"
{% endfor %}
      containers:
      - env:
        - name: K8S_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
        args:
        - controller-manager
        - -v
        - "5"
        - --leader-election-namespace
        - kube-service-catalog
        - --broker-relist-interval
        - "5m"
        - --feature-gates
        - OriginatingIdentity=true
        image: {{ openshift_service_catalog_image_prefix }}service-catalog:{{ openshift_service_catalog_image_version }}
        command: ["/usr/bin/service-catalog"]
        imagePullPolicy: Always
        name: controller-manager
        ports:
        - containerPort: 8080
          protocol: TCP
        resources: {}
        terminationMessagePath: /dev/termination-log
        volumeMounts:
        - mountPath: /var/run/kubernetes-service-catalog
          name: service-catalog-ssl
          readOnly: true
      dnsPolicy: ClusterFirst
      restartPolicy: Always
      securityContext: {}
      terminationGracePeriodSeconds: 30
      volumes:
      - name: service-catalog-ssl
        secret:
          defaultMode: 420
          items:
          - key: tls.crt
            path: apiserver.crt
          secretName: apiserver-ssl