Compare commits
3 commits
53b703819c
...
4405997876
| Author | SHA1 | Date | |
|---|---|---|---|
| 4405997876 | |||
| 66d6fe4426 | |||
| db9867f3c9 |
8 changed files with 84 additions and 8 deletions
|
|
@ -36,6 +36,9 @@ for i in do-block-storage-StorageClass.yaml do-block-storage-VolumeSnapshotClass
|
||||||
done
|
done
|
||||||
rm -fr files/digitalocean.old
|
rm -fr files/digitalocean.old
|
||||||
|
|
||||||
|
if [ ! -d files/secrets-provider-gopass ]; then mkdir files/secrets-provider-gopass; fi
|
||||||
|
wget https://github.com/camptocamp/secrets-store-csi-driver-provider-gopass/raw/master/deployment/provider-gopass-installer.yaml && \
|
||||||
|
\mv provider-gopass-installer.yaml files/secrets-provider-gopass/
|
||||||
|
|
||||||
|
|
||||||
#https://github.com/scaleway/scaleway-csi
|
#https://github.com/scaleway/scaleway-csi
|
||||||
|
|
|
||||||
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: external-attacher-runner
|
name: external-attacher-role
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: csi-controller-sa
|
name: csi-controller-sa
|
||||||
|
|
|
||||||
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: external-provisioner-runner
|
name: external-provisioner-role
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: csi-controller-sa
|
name: csi-controller-sa
|
||||||
|
|
|
||||||
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: external-resizer-runner
|
name: external-resizer-role
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: csi-controller-sa
|
name: csi-controller-sa
|
||||||
|
|
|
||||||
|
|
@ -78,7 +78,7 @@ spec:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
key: token
|
key: token
|
||||||
name: linode
|
name: linode
|
||||||
image: linode/linode-blockstorage-csi-driver:v0.4.0
|
image: linode/linode-blockstorage-csi-driver:v0.4.1
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
name: linode-csi-plugin
|
name: linode-csi-plugin
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
|
|
|
||||||
|
|
@ -56,7 +56,7 @@ spec:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
key: token
|
key: token
|
||||||
name: linode
|
name: linode
|
||||||
image: linode/linode-blockstorage-csi-driver:v0.4.0
|
image: linode/linode-blockstorage-csi-driver:v0.4.1
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
name: csi-linode-plugin
|
name: csi-linode-plugin
|
||||||
securityContext:
|
securityContext:
|
||||||
|
|
@ -94,6 +94,13 @@ spec:
|
||||||
- mountPath: /scripts
|
- mountPath: /scripts
|
||||||
name: get-linode-id
|
name: get-linode-id
|
||||||
serviceAccount: csi-node-sa
|
serviceAccount: csi-node-sa
|
||||||
|
tolerations:
|
||||||
|
- effect: NoSchedule
|
||||||
|
operator: Exists
|
||||||
|
- key: CriticalAddonsOnly
|
||||||
|
operator: Exists
|
||||||
|
- effect: NoExecute
|
||||||
|
operator: Exists
|
||||||
volumes:
|
volumes:
|
||||||
- emptyDir: {}
|
- emptyDir: {}
|
||||||
name: linode-info
|
name: linode-info
|
||||||
|
|
|
||||||
42
files/secrets-provider-gopass/provider-gopass-installer.yaml
Normal file
42
files/secrets-provider-gopass/provider-gopass-installer.yaml
Normal file
|
|
@ -0,0 +1,42 @@
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: DaemonSet
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: csi-secrets-store-provider-gopass
|
||||||
|
name: csi-secrets-store-provider-gopass
|
||||||
|
spec:
|
||||||
|
updateStrategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: csi-secrets-store-provider-gopass
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: csi-secrets-store-provider-gopass
|
||||||
|
spec:
|
||||||
|
tolerations:
|
||||||
|
containers:
|
||||||
|
- name: provider-gopass-installer
|
||||||
|
image: camptocamp/secrets-store-csi-driver-provider-gopass:0.0.1
|
||||||
|
imagePullPolicy: Always
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 100Mi
|
||||||
|
limits:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 100Mi
|
||||||
|
env:
|
||||||
|
# set TARGET_DIR env var and mount the same directory to to the container
|
||||||
|
- name: TARGET_DIR
|
||||||
|
value: "/etc/kubernetes/secrets-store-csi-providers"
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: "/etc/kubernetes/secrets-store-csi-providers"
|
||||||
|
name: providervol
|
||||||
|
volumes:
|
||||||
|
- name: providervol
|
||||||
|
hostPath:
|
||||||
|
path: "/etc/kubernetes/secrets-store-csi-providers"
|
||||||
|
nodeSelector:
|
||||||
|
beta.kubernetes.io/os: linux
|
||||||
|
|
@ -17,19 +17,43 @@
|
||||||
- name: Defined Secrets Store repository
|
- name: Defined Secrets Store repository
|
||||||
kubernetes.core.helm_repository:
|
kubernetes.core.helm_repository:
|
||||||
name: secrets-store-csi-driver
|
name: secrets-store-csi-driver
|
||||||
repo_url: "https://raw.githubusercontent.com/kubernetes-sigs/secrets-store-csi-driver/master/charts"
|
repo_url: "https://kubernetes-sigs.github.io/secrets-store-csi-driver/charts"
|
||||||
|
|
||||||
- name: Deploy Secrets Store chart
|
- name: Deploy Secrets Store chart
|
||||||
kubernetes.core.helm:
|
kubernetes.core.helm:
|
||||||
context: "{{ my_context }}"
|
context: "{{ my_context }}"
|
||||||
state: "{{ storage_secrets_store_state }}"
|
state: "{{ storage_secrets_store_state }}"
|
||||||
name: csi-secrets-store
|
name: csi-secrets-store
|
||||||
|
namespace: "kube-system"
|
||||||
chart_ref: secrets-store-csi-driver/secrets-store-csi-driver
|
chart_ref: secrets-store-csi-driver/secrets-store-csi-driver
|
||||||
|
|
||||||
|
# https://github.com/camptocamp/secrets-store-csi-driver-provider-gopass
|
||||||
|
- name: Deploy Secrets Store CSI driver provider gopass
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
state: "{{ storage_secrets_store_state }}"
|
||||||
|
context: "{{ my_context }}"
|
||||||
|
namespace: "kube-system"
|
||||||
|
apply: true
|
||||||
|
resource_definition: "{{ lookup('file', 'secrets-provider-gopass/provider-gopass-installer.yaml') | from_yaml }}"
|
||||||
|
|
||||||
|
# https://github.com/Azure/secrets-store-csi-driver-provider-azure
|
||||||
|
- name: Deploy Secrets Store CSI driver provider azure
|
||||||
|
kubernetes.core.helm_repository:
|
||||||
|
name: csi-secrets-store-provider-azure
|
||||||
|
repo_url: "https://raw.githubusercontent.com/Azure/secrets-store-csi-driver-provider-azure/master/charts"
|
||||||
|
- name: Deploy Secrets Store chart
|
||||||
|
kubernetes.core.helm:
|
||||||
|
context: "{{ my_context }}"
|
||||||
|
state: "{{ storage_secrets_store_state }}"
|
||||||
|
name: csi-secrets-store-provider-azure
|
||||||
|
namespace: "kube-system"
|
||||||
|
chart_ref: csi-secrets-store-provider-azure/csi-secrets-store-provider-azure
|
||||||
|
values:
|
||||||
|
secrets-store-csi-driver:
|
||||||
|
install: false
|
||||||
|
|
||||||
tags:
|
tags:
|
||||||
- storage
|
- storage
|
||||||
- secrets-store
|
- secrets-store
|
||||||
|
|
||||||
# https://github.com/camptocamp/secrets-store-csi-driver-provider-gopass
|
|
||||||
# https://github.com/hashicorp/vault-csi-provider
|
# https://github.com/hashicorp/vault-csi-provider
|
||||||
# https://github.com/Azure/secrets-store-csi-driver-provider-azure
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue