Skip to content

Commit

Permalink
Use ${} form for onessl envsubst
Browse files Browse the repository at this point in the history
  • Loading branch information
tamalsaha committed Feb 12, 2018
1 parent a6a0a3e commit fedfa74
Show file tree
Hide file tree
Showing 3 changed files with 19 additions and 19 deletions.
2 changes: 1 addition & 1 deletion hack/deploy/admission.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ webhooks:
namespace: default
name: kubernetes
path: /apis/admission.stash.appscode.com/v1alpha1/admissionreviews
caBundle: $KUBE_CA
caBundle: ${KUBE_CA}
rules:
- operations:
- CREATE
Expand Down
24 changes: 12 additions & 12 deletions hack/deploy/operator.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ apiVersion: apps/v1beta1
kind: Deployment
metadata:
name: stash-operator
namespace: $STASH_NAMESPACE
namespace: ${STASH_NAMESPACE}
labels:
app: stash
initializers:
Expand All @@ -19,20 +19,20 @@ spec:
annotations:
scheduler.alpha.kubernetes.io/critical-pod: ''
spec:
serviceAccountName: $STASH_SERVICE_ACCOUNT
imagePullSecrets: [$STASH_IMAGE_PULL_SECRET]
serviceAccountName: ${STASH_SERVICE_ACCOUNT}
imagePullSecrets: [${STASH_IMAGE_PULL_SECRET}]
containers:
- name: operator
args:
- run
- --v=3
- --rbac=$STASH_ENABLE_RBAC
- --docker-registry=$STASH_DOCKER_REGISTRY
- --rbac=${STASH_ENABLE_RBAC}
- --docker-registry=${STASH_DOCKER_REGISTRY}
- --secure-port=8443
- --audit-log-path=-
- --tls-cert-file=/var/serving-cert/tls.crt
- --tls-private-key-file=/var/serving-cert/tls.key
image: $STASH_DOCKER_REGISTRY/stash:0.7.0-alpha.0
image: ${STASH_DOCKER_REGISTRY}/stash:0.7.0-alpha.0
ports:
- containerPort: 8443
- containerPort: 56790
Expand Down Expand Up @@ -76,20 +76,20 @@ apiVersion: v1
kind: Secret
metadata:
name: stash-apiserver-cert
namespace: $STASH_NAMESPACE
namespace: ${STASH_NAMESPACE}
labels:
app: stash
type: kubernetes.io/tls
data:
tls.crt: $TLS_SERVING_CERT
tls.key: $TLS_SERVING_KEY
tls.crt: ${TLS_SERVING_CERT}
tls.key: ${TLS_SERVING_KEY}
---
# to be able to expose TSB inside the cluster
apiVersion: v1
kind: Service
metadata:
name: stash-operator
namespace: $STASH_NAMESPACE
namespace: ${STASH_NAMESPACE}
labels:
app: stash
spec:
Expand All @@ -114,11 +114,11 @@ metadata:
labels:
app: stash
spec:
caBundle: $SERVICE_SERVING_CERT_CA
caBundle: ${SERVICE_SERVING_CERT_CA}
group: admission.stash.appscode.com
groupPriorityMinimum: 1000
versionPriority: 15
service:
name: stash-operator
namespace: $STASH_NAMESPACE
namespace: ${STASH_NAMESPACE}
version: v1alpha1
12 changes: 6 additions & 6 deletions hack/deploy/rbac-list.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -88,8 +88,8 @@ roleRef:
name: stash-operator
subjects:
- kind: ServiceAccount
name: $STASH_SERVICE_ACCOUNT
namespace: $STASH_NAMESPACE
name: ${STASH_SERVICE_ACCOUNT}
namespace: ${STASH_NAMESPACE}
# to read the config for terminating authentication
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: RoleBinding
Expand All @@ -102,8 +102,8 @@ roleRef:
name: extension-apiserver-authentication-reader
subjects:
- kind: ServiceAccount
name: $STASH_SERVICE_ACCOUNT
namespace: $STASH_NAMESPACE
name: ${STASH_SERVICE_ACCOUNT}
namespace: ${STASH_NAMESPACE}
---
# to delegate authentication and authorization
apiVersion: rbac.authorization.k8s.io/v1beta1
Expand All @@ -118,5 +118,5 @@ roleRef:
name: system:auth-delegator
subjects:
- kind: ServiceAccount
name: $STASH_SERVICE_ACCOUNT
namespace: $STASH_NAMESPACE
name: ${STASH_SERVICE_ACCOUNT}
namespace: ${STASH_NAMESPACE}

0 comments on commit fedfa74

Please sign in to comment.