mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
Auto import kubernetes template in Helm charts (#3550)
This commit is contained in:
@@ -44,6 +44,12 @@ coder:
|
||||
name: coder-db-url
|
||||
key: url
|
||||
|
||||
# This env variable controls whether or not to auto-import the "kubernetes"
|
||||
# template on first startup. This will not work unless
|
||||
# coder.serviceAccount.workspacePerms is true.
|
||||
- name: CODER_TEMPLATE_AUTOIMPORT
|
||||
value: "kubernetes"
|
||||
|
||||
tls:
|
||||
secretName: my-tls-secret-name
|
||||
```
|
||||
|
||||
@@ -1,3 +1,10 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: coder
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
@@ -17,6 +24,7 @@ spec:
|
||||
labels:
|
||||
{{- include "coder.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
serviceAccountName: coder
|
||||
restartPolicy: Always
|
||||
terminationGracePeriodSeconds: 60
|
||||
containers:
|
||||
@@ -0,0 +1,27 @@
|
||||
{{- if .Values.coder.serviceAccount.workspacePerms }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: coder-workspace-perms
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["pods"]
|
||||
verbs: ["*"]
|
||||
- apiGroups: [""]
|
||||
resources: ["persistentvolumeclaims"]
|
||||
verbs: ["*"]
|
||||
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: coder
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: coder
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: coder-workspace-perms
|
||||
{{- end }}
|
||||
@@ -16,6 +16,18 @@ coder:
|
||||
# https://kubernetes.io/docs/concepts/containers/images/#image-pull-policy
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
# coder.serviceAccount -- Configuration for the automatically created service
|
||||
# account. Creation of the service account cannot be disabled.
|
||||
serviceAccount:
|
||||
# coder.serviceAccount.workspacePerms -- Whether or not to grant the coder
|
||||
# service account permissions to manage workspaces. This includes
|
||||
# permission to manage pods and persistent volume claims in the deployment
|
||||
# namespace.
|
||||
#
|
||||
# It is recommended to keep this on if you are using Kubernetes templates
|
||||
# within Coder.
|
||||
workspacePerms: true
|
||||
|
||||
# coder.env -- The environment variables to set for Coder. These can be used
|
||||
# to configure all aspects of `coder server`. Please see `coder server --help`
|
||||
# for information about what environment variables can be set.
|
||||
|
||||
Reference in New Issue
Block a user