Compare commits

..

5 Commits

2 changed files with 39 additions and 41 deletions

View File

@ -2,7 +2,6 @@ apiVersion: apps/v1
kind: Deployment kind: Deployment
metadata: metadata:
name: hydra-ldap name: hydra-ldap
namespace: default
labels: labels:
app.kubernetes.io/name: hydra-ldap app.kubernetes.io/name: hydra-ldap
app.kubernetes.io/version: "v1.2.2" app.kubernetes.io/version: "v1.2.2"
@ -18,34 +17,34 @@ spec:
app.kubernetes.io/version: "v1.2.2" app.kubernetes.io/version: "v1.2.2"
spec: spec:
containers: containers:
- name: werther - name: werther
image: reg.cadoles.com/cadoles/hydra-werther:2023.12.6-stable.1421.15a4717 image: reg.cadoles.com/cadoles/hydra-werther:2023.12.6-stable.1421.15a4717
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
envFrom: envFrom:
- configMapRef: - configMapRef:
name: hydra-ldap-env name: hydra-ldap-env
env: env:
- name: WERTHER_WEB_DIR - name: WERTHER_WEB_DIR
value: "/usr/share/werther/login/" value: "/usr/share/werther/login/"
- name: WERTHER_LDAP_BINDDN - name: WERTHER_LDAP_BINDDN
valueFrom: valueFrom:
secretKeyRef: secretKeyRef:
name: hydra-ldap-sc name: hydra-ldap-sc
key: WERTHER_LDAP_BINDDN key: WERTHER_LDAP_BINDDN
- name: WERTHER_LDAP_BINDPW - name: WERTHER_LDAP_BINDPW
valueFrom: valueFrom:
secretKeyRef: secretKeyRef:
name: hydra-ldap-sc name: hydra-ldap-sc
key: WERTHER_LDAP_BINDPW key: WERTHER_LDAP_BINDPW
ports: ports:
- containerPort: 8080 - containerPort: 8080
name: hydra-ldap-http name: hydra-ldap-http
securityContext: securityContext:
allowPrivilegeEscalation: false allowPrivilegeEscalation: false
capabilities: capabilities:
drop: drop:
- ALL - ALL
privileged: false privileged: false
readOnlyRootFilesystem: true readOnlyRootFilesystem: true
runAsNonRoot: true runAsNonRoot: true
runAsUser: 100 runAsUser: 100

View File

@ -2,14 +2,13 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- ./resources/hydra-maester-deployment.yaml - ./resources/hydra-maester-deployment.yaml
- ./resources/hydra-maester-rbac.yaml - ./resources/hydra-maester-rbac.yaml
- https://raw.githubusercontent.com/ory/k8s/v0.28.2/helm/charts/hydra-maester/crds/crd-oauth2clients.yaml
configMapGenerator: configMapGenerator:
- name: hydra-maester-env - name: hydra-maester-env
literals: literals:
- APP_ENV=prod - APP_ENV=prod
- APP_DEBUG=false - APP_DEBUG=false
- HYDRA_ADMIN_BASE_URL=http://hydra - HYDRA_ADMIN_BASE_URL=http://hydra
- HYDRA_ADMIN_PORT=4445 - HYDRA_ADMIN_PORT=4445