From 1d262699935343790b4636e3ad8e2e1f75105d34 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard Date: Tue, 25 Mar 2025 02:08:57 +0400 Subject: [PATCH] chore: helm generate --- .../templates/deployment.yaml | 2 +- .../templates/infisicaldynamicsecret-crd.yaml | 2 +- .../templates/infisicalpushsecret-crd.yaml | 2 +- .../templates/infisicalsecret-crd.yaml | 3 +- .../templates/leader-election-rbac.yaml | 2 +- .../templates/manager-rbac.yaml | 11 +++++- .../templates/metrics-reader-rbac.yaml | 3 +- .../templates/metrics-service.yaml | 2 +- .../templates/proxy-rbac.yaml | 3 +- .../templates/serviceaccount.yaml | 2 +- helm-charts/secrets-operator/values.yaml | 34 +++++++++---------- 11 files changed, 38 insertions(+), 28 deletions(-) diff --git a/helm-charts/secrets-operator/templates/deployment.yaml b/helm-charts/secrets-operator/templates/deployment.yaml index e67db7b3f..8a1db0518 100644 --- a/helm-charts/secrets-operator/templates/deployment.yaml +++ b/helm-charts/secrets-operator/templates/deployment.yaml @@ -88,4 +88,4 @@ spec: serviceAccountName: {{ include "secrets-operator.fullname" . }}-controller-manager terminationGracePeriodSeconds: 10 nodeSelector: {{ toYaml .Values.controllerManager.nodeSelector | nindent 8 }} - tolerations: {{ toYaml .Values.controllerManager.tolerations | nindent 8 }} \ No newline at end of file + tolerations: {{ toYaml .Values.controllerManager.tolerations | nindent 8 }} diff --git a/helm-charts/secrets-operator/templates/infisicaldynamicsecret-crd.yaml b/helm-charts/secrets-operator/templates/infisicaldynamicsecret-crd.yaml index dbd622b57..9030680e7 100644 --- a/helm-charts/secrets-operator/templates/infisicaldynamicsecret-crd.yaml +++ b/helm-charts/secrets-operator/templates/infisicaldynamicsecret-crd.yaml @@ -309,4 +309,4 @@ status: plural: "" conditions: [] storedVersions: [] -{{- end }} \ No newline at end of file +{{- end }} diff --git a/helm-charts/secrets-operator/templates/infisicalpushsecret-crd.yaml b/helm-charts/secrets-operator/templates/infisicalpushsecret-crd.yaml index 771d6db82..8491df01c 100644 --- a/helm-charts/secrets-operator/templates/infisicalpushsecret-crd.yaml +++ b/helm-charts/secrets-operator/templates/infisicalpushsecret-crd.yaml @@ -266,4 +266,4 @@ status: plural: "" conditions: [] storedVersions: [] -{{- end }} \ No newline at end of file +{{- end }} diff --git a/helm-charts/secrets-operator/templates/infisicalsecret-crd.yaml b/helm-charts/secrets-operator/templates/infisicalsecret-crd.yaml index 8c78261a0..da6edab68 100644 --- a/helm-charts/secrets-operator/templates/infisicalsecret-crd.yaml +++ b/helm-charts/secrets-operator/templates/infisicalsecret-crd.yaml @@ -504,5 +504,4 @@ status: plural: "" conditions: [] storedVersions: [] - -{{- end }} \ No newline at end of file +{{- end }} diff --git a/helm-charts/secrets-operator/templates/leader-election-rbac.yaml b/helm-charts/secrets-operator/templates/leader-election-rbac.yaml index dc41acf14..8299d35f6 100644 --- a/helm-charts/secrets-operator/templates/leader-election-rbac.yaml +++ b/helm-charts/secrets-operator/templates/leader-election-rbac.yaml @@ -56,4 +56,4 @@ roleRef: subjects: - kind: ServiceAccount name: '{{ include "secrets-operator.fullname" . }}-controller-manager' - namespace: '{{ .Release.Namespace }}' \ No newline at end of file + namespace: '{{ .Release.Namespace }}' diff --git a/helm-charts/secrets-operator/templates/manager-rbac.yaml b/helm-charts/secrets-operator/templates/manager-rbac.yaml index 1cf2316aa..f47ebd64c 100644 --- a/helm-charts/secrets-operator/templates/manager-rbac.yaml +++ b/helm-charts/secrets-operator/templates/manager-rbac.yaml @@ -53,6 +53,15 @@ rules: - list - update - watch +- apiGroups: + - apps + resources: + - deployments + verbs: + - get + - list + - update + - watch - apiGroups: - secrets.infisical.com resources: @@ -159,4 +168,4 @@ roleRef: subjects: - kind: ServiceAccount name: '{{ include "secrets-operator.fullname" . }}-controller-manager' - namespace: '{{ .Release.Namespace }}' \ No newline at end of file + namespace: '{{ .Release.Namespace }}' diff --git a/helm-charts/secrets-operator/templates/metrics-reader-rbac.yaml b/helm-charts/secrets-operator/templates/metrics-reader-rbac.yaml index eec9e5bee..7843dac3d 100644 --- a/helm-charts/secrets-operator/templates/metrics-reader-rbac.yaml +++ b/helm-charts/secrets-operator/templates/metrics-reader-rbac.yaml @@ -13,4 +13,5 @@ rules: - /metrics verbs: - get -{{- end }} \ No newline at end of file + +{{- end }} diff --git a/helm-charts/secrets-operator/templates/metrics-service.yaml b/helm-charts/secrets-operator/templates/metrics-service.yaml index 983b8a861..fab9523cf 100644 --- a/helm-charts/secrets-operator/templates/metrics-service.yaml +++ b/helm-charts/secrets-operator/templates/metrics-service.yaml @@ -14,4 +14,4 @@ spec: control-plane: controller-manager {{- include "secrets-operator.selectorLabels" . | nindent 4 }} ports: - {{- .Values.metricsService.ports | toYaml | nindent 2 }} \ No newline at end of file + {{- .Values.metricsService.ports | toYaml | nindent 2 }} diff --git a/helm-charts/secrets-operator/templates/proxy-rbac.yaml b/helm-charts/secrets-operator/templates/proxy-rbac.yaml index 28b8f4e7d..cc23b0856 100644 --- a/helm-charts/secrets-operator/templates/proxy-rbac.yaml +++ b/helm-charts/secrets-operator/templates/proxy-rbac.yaml @@ -39,4 +39,5 @@ subjects: - kind: ServiceAccount name: '{{ include "secrets-operator.fullname" . }}-controller-manager' namespace: '{{ .Release.Namespace }}' -{{- end }} \ No newline at end of file + +{{- end }} diff --git a/helm-charts/secrets-operator/templates/serviceaccount.yaml b/helm-charts/secrets-operator/templates/serviceaccount.yaml index 3e014ced3..57af4c162 100644 --- a/helm-charts/secrets-operator/templates/serviceaccount.yaml +++ b/helm-charts/secrets-operator/templates/serviceaccount.yaml @@ -8,4 +8,4 @@ metadata: app.kubernetes.io/part-of: k8-operator {{- include "secrets-operator.labels" . | nindent 4 }} annotations: - {{- toYaml .Values.controllerManager.serviceAccount.annotations | nindent 4 }} \ No newline at end of file + {{- toYaml .Values.controllerManager.serviceAccount.annotations | nindent 4 }} diff --git a/helm-charts/secrets-operator/values.yaml b/helm-charts/secrets-operator/values.yaml index 325c0de58..897670c46 100644 --- a/helm-charts/secrets-operator/values.yaml +++ b/helm-charts/secrets-operator/values.yaml @@ -1,15 +1,15 @@ controllerManager: kubeRbacProxy: args: - - --secure-listen-address=0.0.0.0:8443 - - --upstream=http://127.0.0.1:8080/ - - --logtostderr=true - - --v=0 + - --secure-listen-address=0.0.0.0:8443 + - --upstream=http://127.0.0.1:8080/ + - --logtostderr=true + - --v=0 containerSecurityContext: allowPrivilegeEscalation: false capabilities: drop: - - ALL + - ALL image: repository: gcr.io/kubebuilder/kube-rbac-proxy tag: v0.15.0 @@ -22,17 +22,17 @@ controllerManager: memory: 64Mi manager: args: - - --health-probe-bind-address=:8081 - - --metrics-bind-address=127.0.0.1:8080 - - --leader-elect + - --health-probe-bind-address=:8081 + - --metrics-bind-address=127.0.0.1:8080 + - --leader-elect containerSecurityContext: allowPrivilegeEscalation: false capabilities: drop: - - ALL + - ALL image: repository: infisical/kubernetes-operator - tag: v0.8.15 + tag: resources: limits: cpu: 500m @@ -45,14 +45,14 @@ controllerManager: annotations: {} nodeSelector: {} tolerations: [] +metricsService: + ports: + - name: https + port: 8443 + protocol: TCP + targetPort: https + type: ClusterIP kubernetesClusterDomain: cluster.local scopedNamespace: "" scopedRBAC: false installCRDs: true -metricsService: - ports: - - name: https - port: 8443 - protocol: TCP - targetPort: https - type: ClusterIP