blob: cb2425c3de3e748f4fdddb09252595521cb655e6 [file] [log] [blame]
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +04001apiVersion: apps/v1
2kind: Deployment
3metadata:
4 name: {{ include "webhook.fullname" . }}
5 namespace: {{ include "cert-manager.namespace" . }}
6 labels:
7 app: {{ include "webhook.name" . }}
8 app.kubernetes.io/name: {{ include "webhook.name" . }}
9 app.kubernetes.io/instance: {{ .Release.Name }}
10 app.kubernetes.io/component: "webhook"
11 {{- include "labels" . | nindent 4 }}
12 {{- with .Values.webhook.deploymentAnnotations }}
13 annotations:
14 {{- toYaml . | nindent 4 }}
15 {{- end }}
16spec:
17 replicas: {{ .Values.webhook.replicaCount }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040018 {{- /* The if statement below is equivalent to {{- if $value }} but will also return true for 0. */ -}}
19 {{- if not (has (quote .Values.global.revisionHistoryLimit) (list "" (quote ""))) }}
20 revisionHistoryLimit: {{ .Values.global.revisionHistoryLimit }}
21 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +040022 selector:
23 matchLabels:
24 app.kubernetes.io/name: {{ include "webhook.name" . }}
25 app.kubernetes.io/instance: {{ .Release.Name }}
26 app.kubernetes.io/component: "webhook"
27 {{- with .Values.webhook.strategy }}
28 strategy:
29 {{- toYaml . | nindent 4 }}
30 {{- end }}
31 template:
32 metadata:
33 labels:
34 app: {{ include "webhook.name" . }}
35 app.kubernetes.io/name: {{ include "webhook.name" . }}
36 app.kubernetes.io/instance: {{ .Release.Name }}
37 app.kubernetes.io/component: "webhook"
38 {{- include "labels" . | nindent 8 }}
39 {{- with .Values.webhook.podLabels }}
40 {{- toYaml . | nindent 8 }}
41 {{- end }}
42 {{- with .Values.webhook.podAnnotations }}
43 annotations:
44 {{- toYaml . | nindent 8 }}
45 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040046 {{- if and .Values.prometheus.enabled (not (or .Values.prometheus.servicemonitor.enabled .Values.prometheus.podmonitor.enabled)) }}
47 {{- if not .Values.webhook.podAnnotations }}
48 annotations:
49 {{- end }}
50 prometheus.io/path: "/metrics"
51 prometheus.io/scrape: 'true'
52 prometheus.io/port: '9402'
53 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +040054 spec:
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040055 {{- if not .Values.webhook.serviceAccount.create }}
56 {{- with .Values.global.imagePullSecrets }}
57 imagePullSecrets:
58 {{- toYaml . | nindent 8 }}
59 {{- end }}
60 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +040061 serviceAccountName: {{ template "webhook.serviceAccountName" . }}
62 {{- if hasKey .Values.webhook "automountServiceAccountToken" }}
63 automountServiceAccountToken: {{ .Values.webhook.automountServiceAccountToken }}
64 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040065 enableServiceLinks: {{ .Values.webhook.enableServiceLinks }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +040066 {{- with .Values.global.priorityClassName }}
67 priorityClassName: {{ . | quote }}
68 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040069 {{- if (hasKey .Values.global "hostUsers") }}
70 hostUsers: {{ .Values.global.hostUsers }}
71 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +040072 {{- with .Values.webhook.securityContext }}
73 securityContext:
74 {{- toYaml . | nindent 8 }}
75 {{- end }}
76 {{- if .Values.webhook.hostNetwork }}
77 hostNetwork: true
78 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040079 {{- if .Values.webhook.hostNetwork }}
80 dnsPolicy: ClusterFirstWithHostNet
81 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +040082 containers:
83 - name: {{ .Chart.Name }}-webhook
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040084 image: "{{ template "cert-manager.image" (tuple .Values.webhook.image .Values.imageRegistry .Values.imageNamespace (printf ":%s" .Chart.AppVersion)) }}"
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +040085 imagePullPolicy: {{ .Values.webhook.image.pullPolicy }}
86 args:
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040087 {{- /* The if statement below is equivalent to {{- if $value }} but will also return true for 0. */ -}}
88 {{- if not (has (quote .Values.global.logLevel) (list "" (quote ""))) }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +040089 - --v={{ .Values.global.logLevel }}
90 {{- end }}
91 {{- if .Values.webhook.config }}
92 - --config=/var/cert-manager/config/config.yaml
93 {{- end }}
94 {{- $config := default .Values.webhook.config "" }}
95 {{ if not $config.securePort -}}
96 - --secure-port={{ .Values.webhook.securePort }}
97 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +040098 {{- if .Values.webhook.featureGates }}
99 - --feature-gates={{ .Values.webhook.featureGates }}
100 {{- end }}
101 {{- if .Values.webhook.enableClientVerification }}
102 - --enable-client-verification={{ .Values.webhook.enableClientVerification }}
103 {{- end }}
104 {{- if .Values.webhook.clientCAFile }}
105 - --client-ca-path={{ .Values.webhook.clientCAFile }}
106 {{- end }}
107 {{- if .Values.webhook.apiserverClientCertSubjects }}
108 - --client-subject-names={{ .Values.webhook.apiserverClientCertSubjects }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400109 {{- end }}
110 {{- $tlsConfig := default $config.tlsConfig "" }}
111 {{ if or (not $config.tlsConfig) (and (not $tlsConfig.dynamic) (not $tlsConfig.filesystem) ) -}}
112 - --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE)
113 - --dynamic-serving-ca-secret-name={{ template "webhook.fullname" . }}-ca
114 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}
115 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}.$(POD_NAMESPACE)
116 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}.$(POD_NAMESPACE).svc
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400117 {{- if .Values.webhook.url.host }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400118 - --dynamic-serving-dns-names={{ .Values.webhook.url.host }}
119 {{- end }}
120 {{- end }}
121 {{- with .Values.webhook.extraArgs }}
122 {{- toYaml . | nindent 10 }}
123 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400124 {{- if not .Values.prometheus.enabled }}
125 - --metrics-listen-address=0
126 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400127 ports:
128 - name: https
129 protocol: TCP
130 {{- if $config.securePort }}
131 containerPort: {{ $config.securePort }}
132 {{- else if .Values.webhook.securePort }}
133 containerPort: {{ .Values.webhook.securePort }}
134 {{- else }}
135 containerPort: 6443
136 {{- end }}
137 - name: healthcheck
138 protocol: TCP
139 {{- if $config.healthzPort }}
140 containerPort: {{ $config.healthzPort }}
141 {{- else }}
142 containerPort: 6080
143 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400144 {{- if .Values.prometheus.enabled }}
145 - containerPort: 9402
146 name: http-metrics
147 protocol: TCP
148 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400149 livenessProbe:
150 httpGet:
151 path: /livez
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400152 port: healthcheck
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400153 scheme: HTTP
154 initialDelaySeconds: {{ .Values.webhook.livenessProbe.initialDelaySeconds }}
155 periodSeconds: {{ .Values.webhook.livenessProbe.periodSeconds }}
156 timeoutSeconds: {{ .Values.webhook.livenessProbe.timeoutSeconds }}
157 successThreshold: {{ .Values.webhook.livenessProbe.successThreshold }}
158 failureThreshold: {{ .Values.webhook.livenessProbe.failureThreshold }}
159 readinessProbe:
160 httpGet:
161 path: /healthz
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400162 port: healthcheck
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400163 scheme: HTTP
164 initialDelaySeconds: {{ .Values.webhook.readinessProbe.initialDelaySeconds }}
165 periodSeconds: {{ .Values.webhook.readinessProbe.periodSeconds }}
166 timeoutSeconds: {{ .Values.webhook.readinessProbe.timeoutSeconds }}
167 successThreshold: {{ .Values.webhook.readinessProbe.successThreshold }}
168 failureThreshold: {{ .Values.webhook.readinessProbe.failureThreshold }}
169 {{- with .Values.webhook.containerSecurityContext }}
170 securityContext:
171 {{- toYaml . | nindent 12 }}
172 {{- end }}
173 env:
174 - name: POD_NAMESPACE
175 valueFrom:
176 fieldRef:
177 fieldPath: metadata.namespace
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400178 {{- with .Values.webhook.extraEnv }}
179 {{- toYaml . | nindent 10 }}
180 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400181 {{- with .Values.webhook.resources }}
182 resources:
183 {{- toYaml . | nindent 12 }}
184 {{- end }}
185 {{- if or .Values.webhook.config .Values.webhook.volumeMounts }}
186 volumeMounts:
187 {{- if .Values.webhook.config }}
188 - name: config
189 mountPath: /var/cert-manager/config
190 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400191 {{- with .Values.webhook.volumeMounts }}
192 {{- toYaml . | nindent 12 }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400193 {{- end }}
194 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400195 {{- $nodeSelector := .Values.global.nodeSelector | default dict }}
196 {{- $nodeSelector = merge $nodeSelector (.Values.webhook.nodeSelector | default dict) }}
197 {{- with $nodeSelector }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400198 nodeSelector:
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400199 {{- range $key, $value := . }}
200 {{ $key }}: {{ $value | quote }}
201 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400202 {{- end }}
203 {{- with .Values.webhook.affinity }}
204 affinity:
205 {{- toYaml . | nindent 8 }}
206 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400207 {{- if .Values.webhook.runtimeClassName }}
208 runtimeClassName: {{ .Values.webhook.runtimeClassName | quote }}
209 {{- else if .Values.global.runtimeClassName }}
210 runtimeClassName: {{ .Values.global.runtimeClassName | quote }}
211 {{- end }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400212 {{- with .Values.webhook.tolerations }}
213 tolerations:
214 {{- toYaml . | nindent 8 }}
215 {{- end }}
216 {{- with .Values.webhook.topologySpreadConstraints }}
217 topologySpreadConstraints:
218 {{- toYaml . | nindent 8 }}
219 {{- end }}
220 {{- if or .Values.webhook.config .Values.webhook.volumes }}
221 volumes:
222 {{- if .Values.webhook.config }}
223 - name: config
224 configMap:
225 name: {{ include "webhook.fullname" . }}
226 {{- end }}
Giorgi Lekveishviliea328da2026-07-29 12:15:15 +0400227 {{- with .Values.webhook.volumes }}
228 {{- toYaml . | nindent 8 }}
Giorgi Lekveishvili4ec4c022024-08-17 15:09:24 +0400229 {{- end }}
230 {{- end }}