blob: 66d6ead04ebee833b7c04cc99b66e48bee5581dd [file] [log] [blame]
gioc895c1d2026-07-23 17:18:25 +04001apiVersion: apps/v1
2kind: Deployment
3metadata:
4 name: {{ include "webhook.fullname" . }}
5 namespace: {{ include "cert-manager.namespace" . }}
6 labels:
7 app: {{ include "webhook.name" . }}
8 app.kubernetes.io/name: {{ include "webhook.name" . }}
9 app.kubernetes.io/instance: {{ .Release.Name }}
10 app.kubernetes.io/component: "webhook"
11 {{- include "labels" . | nindent 4 }}
12 {{- with .Values.webhook.deploymentAnnotations }}
13 annotations:
14 {{- toYaml . | nindent 4 }}
15 {{- end }}
16spec:
17 replicas: {{ .Values.webhook.replicaCount }}
18 {{- /* The if statement below is equivalent to {{- if $value }} but will also return true for 0. */ -}}
19 {{- if not (has (quote .Values.global.revisionHistoryLimit) (list "" (quote ""))) }}
20 revisionHistoryLimit: {{ .Values.global.revisionHistoryLimit }}
21 {{- end }}
22 selector:
23 matchLabels:
24 app.kubernetes.io/name: {{ include "webhook.name" . }}
25 app.kubernetes.io/instance: {{ .Release.Name }}
26 app.kubernetes.io/component: "webhook"
27 {{- with .Values.webhook.strategy }}
28 strategy:
29 {{- toYaml . | nindent 4 }}
30 {{- end }}
31 template:
32 metadata:
33 labels:
34 app: {{ include "webhook.name" . }}
35 app.kubernetes.io/name: {{ include "webhook.name" . }}
36 app.kubernetes.io/instance: {{ .Release.Name }}
37 app.kubernetes.io/component: "webhook"
38 {{- include "labels" . | nindent 8 }}
39 {{- with .Values.webhook.podLabels }}
40 {{- toYaml . | nindent 8 }}
41 {{- end }}
42 {{- with .Values.webhook.podAnnotations }}
43 annotations:
44 {{- toYaml . | nindent 8 }}
45 {{- end }}
46 {{- if and .Values.prometheus.enabled (not (or .Values.prometheus.servicemonitor.enabled .Values.prometheus.podmonitor.enabled)) }}
47 {{- if not .Values.webhook.podAnnotations }}
48 annotations:
49 {{- end }}
50 prometheus.io/path: "/metrics"
51 prometheus.io/scrape: 'true'
52 prometheus.io/port: '9402'
53 {{- end }}
54 spec:
55 {{- if not .Values.webhook.serviceAccount.create }}
56 {{- with .Values.global.imagePullSecrets }}
57 imagePullSecrets:
58 {{- toYaml . | nindent 8 }}
59 {{- end }}
60 {{- end }}
61 serviceAccountName: {{ template "webhook.serviceAccountName" . }}
62 {{- if hasKey .Values.webhook "automountServiceAccountToken" }}
63 automountServiceAccountToken: {{ .Values.webhook.automountServiceAccountToken }}
64 {{- end }}
65 enableServiceLinks: {{ .Values.webhook.enableServiceLinks }}
66 {{- with .Values.global.priorityClassName }}
67 priorityClassName: {{ . | quote }}
68 {{- end }}
69 {{- if (hasKey .Values.global "hostUsers") }}
70 hostUsers: {{ .Values.global.hostUsers }}
71 {{- end }}
72 {{- with .Values.webhook.securityContext }}
73 securityContext:
74 {{- toYaml . | nindent 8 }}
75 {{- end }}
76 {{- if .Values.webhook.hostNetwork }}
77 hostNetwork: true
78 {{- end }}
79 {{- if .Values.webhook.hostNetwork }}
80 dnsPolicy: ClusterFirstWithHostNet
81 {{- end }}
82 containers:
83 - name: {{ .Chart.Name }}-webhook
84 image: "{{ template "image" (tuple .Values.webhook.image .Values.imageRegistry .Values.imageNamespace (printf ":%s" .Chart.AppVersion)) }}"
85 imagePullPolicy: {{ .Values.webhook.image.pullPolicy }}
86 args:
87 {{- /* The if statement below is equivalent to {{- if $value }} but will also return true for 0. */ -}}
88 {{- if not (has (quote .Values.global.logLevel) (list "" (quote ""))) }}
89 - --v={{ .Values.global.logLevel }}
90 {{- end }}
91 {{- if .Values.webhook.config }}
92 - --config=/var/cert-manager/config/config.yaml
93 {{- end }}
94 {{- $config := default .Values.webhook.config "" }}
95 {{ if not $config.securePort -}}
96 - --secure-port={{ .Values.webhook.securePort }}
97 {{- end }}
98 {{- if .Values.webhook.featureGates }}
99 - --feature-gates={{ .Values.webhook.featureGates }}
100 {{- end }}
101 {{- if .Values.webhook.enableClientVerification }}
102 - --enable-client-verification={{ .Values.webhook.enableClientVerification }}
103 {{- end }}
104 {{- if .Values.webhook.clientCAFile }}
105 - --client-ca-path={{ .Values.webhook.clientCAFile }}
106 {{- end }}
107 {{- if .Values.webhook.apiserverClientCertSubjects }}
108 - --client-subject-names={{ .Values.webhook.apiserverClientCertSubjects }}
109 {{- end }}
110 {{- $tlsConfig := default $config.tlsConfig "" }}
111 {{ if or (not $config.tlsConfig) (and (not $tlsConfig.dynamic) (not $tlsConfig.filesystem) ) -}}
112 - --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE)
113 - --dynamic-serving-ca-secret-name={{ template "webhook.fullname" . }}-ca
114 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}
115 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}.$(POD_NAMESPACE)
116 - --dynamic-serving-dns-names={{ template "webhook.fullname" . }}.$(POD_NAMESPACE).svc
117 {{- if .Values.webhook.url.host }}
118 - --dynamic-serving-dns-names={{ .Values.webhook.url.host }}
119 {{- end }}
120 {{- end }}
121 {{- with .Values.webhook.extraArgs }}
122 {{- toYaml . | nindent 10 }}
123 {{- end }}
124 {{- if not .Values.prometheus.enabled }}
125 - --metrics-listen-address=0
126 {{- end }}
127 ports:
128 - name: https
129 protocol: TCP
130 {{- if $config.securePort }}
131 containerPort: {{ $config.securePort }}
132 {{- else if .Values.webhook.securePort }}
133 containerPort: {{ .Values.webhook.securePort }}
134 {{- else }}
135 containerPort: 6443
136 {{- end }}
137 - name: healthcheck
138 protocol: TCP
139 {{- if $config.healthzPort }}
140 containerPort: {{ $config.healthzPort }}
141 {{- else }}
142 containerPort: 6080
143 {{- end }}
144 {{- if .Values.prometheus.enabled }}
145 - containerPort: 9402
146 name: http-metrics
147 protocol: TCP
148 {{- end }}
149 livenessProbe:
150 httpGet:
151 path: /livez
152 port: healthcheck
153 scheme: HTTP
154 initialDelaySeconds: {{ .Values.webhook.livenessProbe.initialDelaySeconds }}
155 periodSeconds: {{ .Values.webhook.livenessProbe.periodSeconds }}
156 timeoutSeconds: {{ .Values.webhook.livenessProbe.timeoutSeconds }}
157 successThreshold: {{ .Values.webhook.livenessProbe.successThreshold }}
158 failureThreshold: {{ .Values.webhook.livenessProbe.failureThreshold }}
159 readinessProbe:
160 httpGet:
161 path: /healthz
162 port: healthcheck
163 scheme: HTTP
164 initialDelaySeconds: {{ .Values.webhook.readinessProbe.initialDelaySeconds }}
165 periodSeconds: {{ .Values.webhook.readinessProbe.periodSeconds }}
166 timeoutSeconds: {{ .Values.webhook.readinessProbe.timeoutSeconds }}
167 successThreshold: {{ .Values.webhook.readinessProbe.successThreshold }}
168 failureThreshold: {{ .Values.webhook.readinessProbe.failureThreshold }}
169 {{- with .Values.webhook.containerSecurityContext }}
170 securityContext:
171 {{- toYaml . | nindent 12 }}
172 {{- end }}
173 env:
174 - name: POD_NAMESPACE
175 valueFrom:
176 fieldRef:
177 fieldPath: metadata.namespace
178 {{- with .Values.webhook.extraEnv }}
179 {{- toYaml . | nindent 10 }}
180 {{- end }}
181 {{- with .Values.webhook.resources }}
182 resources:
183 {{- toYaml . | nindent 12 }}
184 {{- end }}
185 {{- if or .Values.webhook.config .Values.webhook.volumeMounts }}
186 volumeMounts:
187 {{- if .Values.webhook.config }}
188 - name: config
189 mountPath: /var/cert-manager/config
190 {{- end }}
191 {{- with .Values.webhook.volumeMounts }}
192 {{- toYaml . | nindent 12 }}
193 {{- end }}
194 {{- end }}
195 {{- $nodeSelector := .Values.global.nodeSelector | default dict }}
196 {{- $nodeSelector = merge $nodeSelector (.Values.webhook.nodeSelector | default dict) }}
197 {{- with $nodeSelector }}
198 nodeSelector:
199 {{- range $key, $value := . }}
200 {{ $key }}: {{ $value | quote }}
201 {{- end }}
202 {{- end }}
203 {{- with .Values.webhook.affinity }}
204 affinity:
205 {{- toYaml . | nindent 8 }}
206 {{- end }}
207 {{- with .Values.webhook.tolerations }}
208 tolerations:
209 {{- toYaml . | nindent 8 }}
210 {{- end }}
211 {{- with .Values.webhook.topologySpreadConstraints }}
212 topologySpreadConstraints:
213 {{- toYaml . | nindent 8 }}
214 {{- end }}
215 {{- if or .Values.webhook.config .Values.webhook.volumes }}
216 volumes:
217 {{- if .Values.webhook.config }}
218 - name: config
219 configMap:
220 name: {{ include "webhook.fullname" . }}
221 {{- end }}
222 {{- with .Values.webhook.volumes }}
223 {{- toYaml . | nindent 8 }}
224 {{- end }}
225 {{- end }}