Skip to content

Commit 08c8a6b

Browse files
committed
fix: use BoundServceAccountTokenVolume de default
1 parent 05014ca commit 08c8a6b

File tree

1 file changed

+0
-22
lines changed

1 file changed

+0
-22
lines changed

manifests/0000_20_kube-apiserver-operator_06_deployment.yaml

Lines changed: 0 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,6 @@ spec:
2929
runAsUser: 65534
3030
seccompProfile:
3131
type: RuntimeDefault
32-
automountServiceAccountToken: false # here to prevent deadlock, remove in 4.9
3332
serviceAccountName: kube-apiserver-operator
3433
containers:
3534
- name: kube-apiserver-operator
@@ -55,9 +54,6 @@ spec:
5554
name: config
5655
- mountPath: /var/run/secrets/serving-cert
5756
name: serving-cert
58-
- mountPath: /var/run/secrets/kubernetes.io/serviceaccount
59-
name: kube-api-access
60-
readOnly: true
6157
env:
6258
- name: IMAGE
6359
value: quay.io/openshift/origin-hyperkube:v4.0
@@ -80,24 +76,6 @@ spec:
8076
- name: config
8177
configMap:
8278
name: kube-apiserver-operator-config
83-
- name: kube-api-access
84-
projected:
85-
defaultMode: 420
86-
sources:
87-
- serviceAccountToken:
88-
expirationSeconds: 3600
89-
path: token
90-
- configMap:
91-
items:
92-
- key: ca.crt
93-
path: ca.crt
94-
name: kube-root-ca.crt
95-
- downwardAPI:
96-
items:
97-
- fieldRef:
98-
apiVersion: v1
99-
fieldPath: metadata.namespace
100-
path: namespace
10179
nodeSelector:
10280
node-role.kubernetes.io/master: ""
10381
priorityClassName: "system-cluster-critical"

0 commit comments

Comments
 (0)