Auto import kubernetes template in Helm charts (#3550)

This commit is contained in:
Dean Sheather
2022-08-26 05:32:35 +10:00
committed by GitHub
parent 94e96fa40b
commit 14a9576b77
15 changed files with 423 additions and 41 deletions
+6
View File
@@ -44,6 +44,12 @@ coder:
name: coder-db-url
key: url
# This env variable controls whether or not to auto-import the "kubernetes"
# template on first startup. This will not work unless
# coder.serviceAccount.workspacePerms is true.
- name: CODER_TEMPLATE_AUTOIMPORT
value: "kubernetes"
tls:
secretName: my-tls-secret-name
```
@@ -1,3 +1,10 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: coder
---
apiVersion: apps/v1
kind: Deployment
metadata:
@@ -17,6 +24,7 @@ spec:
labels:
{{- include "coder.selectorLabels" . | nindent 8 }}
spec:
serviceAccountName: coder
restartPolicy: Always
terminationGracePeriodSeconds: 60
containers:
+27
View File
@@ -0,0 +1,27 @@
{{- if .Values.coder.serviceAccount.workspacePerms }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: coder-workspace-perms
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["*"]
- apiGroups: [""]
resources: ["persistentvolumeclaims"]
verbs: ["*"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: coder
subjects:
- kind: ServiceAccount
name: coder
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: coder-workspace-perms
{{- end }}
+12
View File
@@ -16,6 +16,18 @@ coder:
# https://kubernetes.io/docs/concepts/containers/images/#image-pull-policy
pullPolicy: IfNotPresent
# coder.serviceAccount -- Configuration for the automatically created service
# account. Creation of the service account cannot be disabled.
serviceAccount:
# coder.serviceAccount.workspacePerms -- Whether or not to grant the coder
# service account permissions to manage workspaces. This includes
# permission to manage pods and persistent volume claims in the deployment
# namespace.
#
# It is recommended to keep this on if you are using Kubernetes templates
# within Coder.
workspacePerms: true
# coder.env -- The environment variables to set for Coder. These can be used
# to configure all aspects of `coder server`. Please see `coder server --help`
# for information about what environment variables can be set.