blob: f237c2d9760ec9e1eb962792c0ad9735d50f1e04 [file] [log] [blame]
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +04001apiVersion: apps/v1
2kind: Deployment
3metadata:
4 name: {{ include "webhook.fullname" . }}
5 namespace: {{ include "cert-manager.namespace" . }}
6 labels:
7 app: {{ include "webhook.name" . }}
8 app.kubernetes.io/name: {{ include "webhook.name" . }}
9 app.kubernetes.io/instance: {{ .Release.Name }}
10 app.kubernetes.io/component: "webhook"
11 {{- include "labels" . | nindent 4 }}
12 {{- with .Values.webhook.deploymentAnnotations }}
13 annotations:
14 {{- toYaml . | nindent 4 }}
15 {{- end }}
16spec:
17 replicas: {{ .Values.webhook.replicaCount }}
gio33d62932026-07-23 16:39:35 +040018 {{- /* The if statement below is equivalent to {{- if $value }} but will also return true for 0. */ -}}
19 {{- if not (has (quote .Values.global.revisionHistoryLimit) (list "" (quote ""))) }}
20 revisionHistoryLimit: {{ .Values.global.revisionHistoryLimit }}
21 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +040022 selector:
23 matchLabels:
24 app.kubernetes.io/name: {{ include "webhook.name" . }}
25 app.kubernetes.io/instance: {{ .Release.Name }}
26 app.kubernetes.io/component: "webhook"
27 {{- with .Values.webhook.strategy }}
28 strategy:
29 {{- toYaml . | nindent 4 }}
30 {{- end }}
31 template:
32 metadata:
33 labels:
34 app: {{ include "webhook.name" . }}
35 app.kubernetes.io/name: {{ include "webhook.name" . }}
36 app.kubernetes.io/instance: {{ .Release.Name }}
37 app.kubernetes.io/component: "webhook"
38 {{- include "labels" . | nindent 8 }}
39 {{- with .Values.webhook.podLabels }}
40 {{- toYaml . | nindent 8 }}
41 {{- end }}
42 {{- with .Values.webhook.podAnnotations }}
43 annotations:
44 {{- toYaml . | nindent 8 }}
45 {{- end }}
gio33d62932026-07-23 16:39:35 +040046 {{- if and .Values.prometheus.enabled (not (or .Values.prometheus.servicemonitor.enabled .Values.prometheus.podmonitor.enabled)) }}
47 {{- if not .Values.webhook.podAnnotations }}
48 annotations:
49 {{- end }}
50 prometheus.io/path: "/metrics"
51 prometheus.io/scrape: 'true'
52 prometheus.io/port: '9402'
53 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +040054 spec:
gio33d62932026-07-23 16:39:35 +040055 {{- if not .Values.webhook.serviceAccount.create }}
56 {{- with .Values.global.imagePullSecrets }}
57 imagePullSecrets:
58 {{- toYaml . | nindent 8 }}
59 {{- end }}
60 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +040061 serviceAccountName: {{ template "webhook.serviceAccountName" . }}
62 {{- if hasKey .Values.webhook "automountServiceAccountToken" }}
63 automountServiceAccountToken: {{ .Values.webhook.automountServiceAccountToken }}
64 {{- end }}
gio33d62932026-07-23 16:39:35 +040065 enableServiceLinks: {{ .Values.webhook.enableServiceLinks }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +040066 {{- with .Values.global.priorityClassName }}
67 priorityClassName: {{ . | quote }}
68 {{- end }}
69 {{- with .Values.webhook.securityContext }}
70 securityContext:
71 {{- toYaml . | nindent 8 }}
72 {{- end }}
73 {{- if .Values.webhook.hostNetwork }}
74 hostNetwork: true
75 {{- end }}
gio33d62932026-07-23 16:39:35 +040076 {{- if .Values.webhook.hostNetwork }}
77 dnsPolicy: ClusterFirstWithHostNet
78 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +040079 containers:
80 - name: {{ .Chart.Name }}-webhook
gio33d62932026-07-23 16:39:35 +040081 image: "{{ template "image" (tuple .Values.webhook.image $.Chart.AppVersion) }}"
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +040082 imagePullPolicy: {{ .Values.webhook.image.pullPolicy }}
83 args:
gio33d62932026-07-23 16:39:35 +040084 {{- /* The if statement below is equivalent to {{- if $value }} but will also return true for 0. */ -}}
85 {{- if not (has (quote .Values.global.logLevel) (list "" (quote ""))) }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +040086 - --v={{ .Values.global.logLevel }}
87 {{- end }}
88 {{- if .Values.webhook.config }}
89 - --config=/var/cert-manager/config/config.yaml
90 {{- end }}
91 {{- $config := default .Values.webhook.config "" }}
92 {{ if not $config.securePort -}}
93 - --secure-port={{ .Values.webhook.securePort }}
94 {{- end }}
gio33d62932026-07-23 16:39:35 +040095 {{- if .Values.webhook.featureGates }}
96 - --feature-gates={{ .Values.webhook.featureGates }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +040097 {{- end }}
98 {{- $tlsConfig := default $config.tlsConfig "" }}
99 {{ if or (not $config.tlsConfig) (and (not $tlsConfig.dynamic) (not $tlsConfig.filesystem) ) -}}
100 - --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE)
101 - --dynamic-serving-ca-secret-name={{ template "webhook.fullname" . }}-ca
102 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}
103 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}.$(POD_NAMESPACE)
104 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}.$(POD_NAMESPACE).svc
105 {{ if .Values.webhook.url.host }}
106 - --dynamic-serving-dns-names={{ .Values.webhook.url.host }}
107 {{- end }}
108 {{- end }}
109 {{- with .Values.webhook.extraArgs }}
110 {{- toYaml . | nindent 10 }}
111 {{- end }}
gio33d62932026-07-23 16:39:35 +0400112 {{- if not .Values.prometheus.enabled }}
113 - --metrics-listen-address=0
114 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400115 ports:
116 - name: https
117 protocol: TCP
118 {{- if $config.securePort }}
119 containerPort: {{ $config.securePort }}
120 {{- else if .Values.webhook.securePort }}
121 containerPort: {{ .Values.webhook.securePort }}
122 {{- else }}
123 containerPort: 6443
124 {{- end }}
125 - name: healthcheck
126 protocol: TCP
127 {{- if $config.healthzPort }}
128 containerPort: {{ $config.healthzPort }}
129 {{- else }}
130 containerPort: 6080
131 {{- end }}
gio33d62932026-07-23 16:39:35 +0400132 {{- if .Values.prometheus.enabled }}
133 - containerPort: 9402
134 name: http-metrics
135 protocol: TCP
136 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400137 livenessProbe:
138 httpGet:
139 path: /livez
giob6e9f2f2026-07-23 16:53:10 +0400140 port: healthcheck
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400141 scheme: HTTP
142 initialDelaySeconds: {{ .Values.webhook.livenessProbe.initialDelaySeconds }}
143 periodSeconds: {{ .Values.webhook.livenessProbe.periodSeconds }}
144 timeoutSeconds: {{ .Values.webhook.livenessProbe.timeoutSeconds }}
145 successThreshold: {{ .Values.webhook.livenessProbe.successThreshold }}
146 failureThreshold: {{ .Values.webhook.livenessProbe.failureThreshold }}
147 readinessProbe:
148 httpGet:
149 path: /healthz
giob6e9f2f2026-07-23 16:53:10 +0400150 port: healthcheck
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400151 scheme: HTTP
152 initialDelaySeconds: {{ .Values.webhook.readinessProbe.initialDelaySeconds }}
153 periodSeconds: {{ .Values.webhook.readinessProbe.periodSeconds }}
154 timeoutSeconds: {{ .Values.webhook.readinessProbe.timeoutSeconds }}
155 successThreshold: {{ .Values.webhook.readinessProbe.successThreshold }}
156 failureThreshold: {{ .Values.webhook.readinessProbe.failureThreshold }}
157 {{- with .Values.webhook.containerSecurityContext }}
158 securityContext:
159 {{- toYaml . | nindent 12 }}
160 {{- end }}
161 env:
162 - name: POD_NAMESPACE
163 valueFrom:
164 fieldRef:
165 fieldPath: metadata.namespace
gio33d62932026-07-23 16:39:35 +0400166 {{- with .Values.webhook.extraEnv }}
167 {{- toYaml . | nindent 10 }}
168 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400169 {{- with .Values.webhook.resources }}
170 resources:
171 {{- toYaml . | nindent 12 }}
172 {{- end }}
Giorgi Lekveishvili0048a782023-06-20 18:32:21 +0400173 {{- if or .Values.webhook.config .Values.webhook.volumeMounts }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400174 volumeMounts:
Giorgi Lekveishvili0048a782023-06-20 18:32:21 +0400175 {{- if .Values.webhook.config }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400176 - name: config
177 mountPath: /var/cert-manager/config
Giorgi Lekveishvili0048a782023-06-20 18:32:21 +0400178 {{- end }}
gio33d62932026-07-23 16:39:35 +0400179 {{- with .Values.webhook.volumeMounts }}
180 {{- toYaml . | nindent 12 }}
Giorgi Lekveishvili0048a782023-06-20 18:32:21 +0400181 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400182 {{- end }}
183 {{- with .Values.webhook.nodeSelector }}
184 nodeSelector:
giob6e9f2f2026-07-23 16:53:10 +0400185 {{- range $key, $value := . }}
186 {{ $key }}: {{ $value | quote }}
187 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400188 {{- end }}
189 {{- with .Values.webhook.affinity }}
190 affinity:
191 {{- toYaml . | nindent 8 }}
192 {{- end }}
193 {{- with .Values.webhook.tolerations }}
194 tolerations:
195 {{- toYaml . | nindent 8 }}
196 {{- end }}
197 {{- with .Values.webhook.topologySpreadConstraints }}
198 topologySpreadConstraints:
199 {{- toYaml . | nindent 8 }}
200 {{- end }}
Giorgi Lekveishvili0048a782023-06-20 18:32:21 +0400201 {{- if or .Values.webhook.config .Values.webhook.volumes }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400202 volumes:
Giorgi Lekveishvili0048a782023-06-20 18:32:21 +0400203 {{- if .Values.webhook.config }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400204 - name: config
205 configMap:
206 name: {{ include "webhook.fullname" . }}
Giorgi Lekveishvili0048a782023-06-20 18:32:21 +0400207 {{- end }}
gio33d62932026-07-23 16:39:35 +0400208 {{- with .Values.webhook.volumes }}
209 {{- toYaml . | nindent 8 }}
Giorgi Lekveishvili0048a782023-06-20 18:32:21 +0400210 {{- end }}
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +0400211 {{- end }}