-
Notifications
You must be signed in to change notification settings - Fork 93
Expand file tree
/
Copy pathoperator.yaml
More file actions
133 lines (133 loc) · 3.6 KB
/
Copy pathoperator.yaml
File metadata and controls
133 lines (133 loc) · 3.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
apiVersion: apps/v1
kind: Deployment
metadata:
name: redis-enterprise-operator
labels:
app: redis-enterprise
spec:
replicas: 1
selector:
matchLabels:
name: redis-enterprise-operator
strategy:
type: Recreate
template:
metadata:
labels:
name: redis-enterprise-operator
app: redis-enterprise
spec:
securityContext:
seccompProfile:
type: RuntimeDefault
runAsNonRoot: true
serviceAccountName: redis-enterprise-operator
containers:
- name: redis-enterprise-operator
image: redislabs/operator:7.2.4-15
command:
- operator-root
- operator
imagePullPolicy: Always
envFrom:
- configMapRef:
name: operator-environment-config
optional: true
ports:
- containerPort: 8080
env:
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: WATCH_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: OPERATOR_NAME
value: "redis-enterprise-operator"
resources:
limits:
cpu: 4000m
memory: 512Mi
requests:
cpu: 500m
memory: 256Mi
livenessProbe:
failureThreshold: 3
successThreshold: 1
periodSeconds: 10
timeoutSeconds: 5
httpGet:
path: /healthz
port: 8080
scheme: HTTP
securityContext:
privileged: false
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
- name: admission
image: redislabs/operator:7.2.4-15
command:
- operator-root
- admission
imagePullPolicy: Always
envFrom:
- configMapRef:
name: operator-environment-config
optional: true
ports:
- containerPort: 8443
env:
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: WATCH_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
resources:
limits:
cpu: 1000m
memory: 512Mi
requests:
cpu: 250m
memory: 256Mi
readinessProbe:
failureThreshold: 3
successThreshold: 1
periodSeconds: 10
timeoutSeconds: 5
httpGet:
path: /healthz
port: 8443
scheme: HTTPS
livenessProbe:
failureThreshold: 3
successThreshold: 1
periodSeconds: 10
timeoutSeconds: 5
initialDelaySeconds: 15
httpGet:
path: /liveness
port: 8443
scheme: HTTPS
securityContext:
privileged: false
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL