Skip to content

Commit 51abe03

Browse files
committed
placeholder
1 parent 52b69a5 commit 51abe03

14 files changed

+395
-13
lines changed

manifests/0000_50_olm_03-services.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ spec:
1717
- name: https-metrics
1818
port: 8443
1919
protocol: TCP
20-
targetPort: 8443
20+
targetPort: 9443
2121
selector:
2222
app: olm-operator
2323
---
@@ -40,6 +40,6 @@ spec:
4040
- name: https-metrics
4141
port: 8443
4242
protocol: TCP
43-
targetPort: 8443
43+
targetPort: 9443
4444
selector:
4545
app: catalog-operator

manifests/0000_50_olm_07-olm-operator.deployment.ibm-cloud-managed.yaml

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,9 @@ spec:
3838
secretName: pprof-cert
3939
- name: tmpfs
4040
emptyDir: {}
41+
- name: olm-operator-serving-cert
42+
secret:
43+
secretName: olm-operator-serving-cert
4144
containers:
4245
- name: olm-operator
4346
securityContext:
@@ -100,6 +103,37 @@ spec:
100103
requests:
101104
cpu: 10m
102105
memory: 160Mi
106+
- args:
107+
- --secure-listen-address=0.0.0.0:9443
108+
- --upstream=https://127.0.0.1:8443/
109+
- --tls-cert-file=/etc/tls/private/tls.crt
110+
- --tls-private-key-file=/etc/tls/private/tls.key
111+
- --upstream-ca-file=/srv-cert/tls.crt
112+
- --logtostderr=true
113+
image: quay.io/openshift/origin-kube-rbac-proxy:latest
114+
imagePullPolicy: IfNotPresent
115+
name: kube-rbac-proxy
116+
securityContext:
117+
allowPrivilegeEscalation: false
118+
readOnlyRootFilesystem: true
119+
capabilities:
120+
drop: ["ALL"]
121+
ports:
122+
- containerPort: 9443
123+
name: metrics
124+
protocol: TCP
125+
resources:
126+
requests:
127+
memory: 20Mi
128+
cpu: 10m
129+
terminationMessagePath: /dev/termination-log
130+
terminationMessagePolicy: FallbackToLogsOnError
131+
volumeMounts:
132+
- mountPath: /etc/tls/private
133+
name: olm-operator-serving-cert
134+
- mountPath: /srv-cert
135+
name: srv-cert
136+
readOnly: true
103137
nodeSelector:
104138
kubernetes.io/os: linux
105139
tolerations:

manifests/0000_50_olm_07-olm-operator.deployment.yaml

Lines changed: 35 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,9 @@ spec:
3737
secretName: pprof-cert
3838
- name: tmpfs
3939
emptyDir: {}
40+
- name: olm-operator-serving-cert
41+
secret:
42+
secretName: olm-operator-serving-cert
4043
containers:
4144
- name: olm-operator
4245
securityContext:
@@ -70,7 +73,7 @@ spec:
7073
- /profile-collector-cert/tls.crt
7174
- --protectedCopiedCSVNamespaces
7275
- openshift
73-
image: quay.io/operator-framework/olm@sha256:de396b540b82219812061d0d753440d5655250c621c753ed1dc67d6154741607
76+
image: registry.build10.ci.openshift.org/ci-ln-5v3wb5t/stable@sha256:1a9ff9f40ff184cb6cbfd41d64c0d33a8f6b385aaf8f534fe1bebf572e6e206d
7477
imagePullPolicy: IfNotPresent
7578
ports:
7679
- containerPort: 8443
@@ -99,6 +102,37 @@ spec:
99102
requests:
100103
cpu: 10m
101104
memory: 160Mi
105+
- args:
106+
- --secure-listen-address=0.0.0.0:9443
107+
- --upstream=https://127.0.0.1:8443/
108+
- --tls-cert-file=/etc/tls/private/tls.crt
109+
- --tls-private-key-file=/etc/tls/private/tls.key
110+
- --upstream-ca-file=/srv-cert/tls.crt
111+
- --logtostderr=true
112+
image: quay.io/openshift/origin-kube-rbac-proxy:latest
113+
imagePullPolicy: IfNotPresent
114+
name: kube-rbac-proxy
115+
securityContext:
116+
allowPrivilegeEscalation: false
117+
readOnlyRootFilesystem: true
118+
capabilities:
119+
drop: ["ALL"]
120+
ports:
121+
- containerPort: 9443
122+
name: metrics
123+
protocol: TCP
124+
resources:
125+
requests:
126+
memory: 20Mi
127+
cpu: 10m
128+
terminationMessagePath: /dev/termination-log
129+
terminationMessagePolicy: FallbackToLogsOnError
130+
volumeMounts:
131+
- mountPath: /etc/tls/private
132+
name: olm-operator-serving-cert
133+
- mountPath: /srv-cert
134+
name: srv-cert
135+
readOnly: true
102136
nodeSelector:
103137
kubernetes.io/os: linux
104138
node-role.kubernetes.io/master: ""

manifests/0000_50_olm_08-catalog-operator.deployment.ibm-cloud-managed.yaml

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,9 @@ spec:
3838
secretName: pprof-cert
3939
- name: tmpfs
4040
emptyDir: {}
41+
- name: catalog-operator-serving-cert
42+
secret:
43+
secretName: catalog-operator-serving-cert
4144
containers:
4245
- name: catalog-operator
4346
securityContext:
@@ -95,6 +98,37 @@ spec:
9598
env:
9699
- name: RELEASE_VERSION
97100
value: "0.0.1-snapshot"
101+
- args:
102+
- --secure-listen-address=0.0.0.0:9443
103+
- --upstream=https://127.0.0.1:8443/
104+
- --tls-cert-file=/etc/tls/private/tls.crt
105+
- --tls-private-key-file=/etc/tls/private/tls.key
106+
- --upstream-ca-file=/srv-cert/tls.crt
107+
- --logtostderr=true
108+
image: quay.io/openshift/origin-kube-rbac-proxy:latest
109+
imagePullPolicy: IfNotPresent
110+
name: kube-rbac-proxy
111+
securityContext:
112+
allowPrivilegeEscalation: false
113+
readOnlyRootFilesystem: true
114+
capabilities:
115+
drop: ["ALL"]
116+
ports:
117+
- containerPort: 9443
118+
name: metrics
119+
protocol: TCP
120+
resources:
121+
requests:
122+
memory: 20Mi
123+
cpu: 10m
124+
terminationMessagePath: /dev/termination-log
125+
terminationMessagePolicy: FallbackToLogsOnError
126+
volumeMounts:
127+
- mountPath: /etc/tls/private
128+
name: catalog-operator-serving-cert
129+
- mountPath: /srv-cert
130+
name: srv-cert
131+
readOnly: true
98132
nodeSelector:
99133
kubernetes.io/os: linux
100134
tolerations:

manifests/0000_50_olm_08-catalog-operator.deployment.yaml

Lines changed: 38 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,9 @@ spec:
3737
secretName: pprof-cert
3838
- name: tmpfs
3939
emptyDir: {}
40+
- name: catalog-operator-serving-cert
41+
secret:
42+
secretName: catalog-operator-serving-cert
4043
containers:
4144
- name: catalog-operator
4245
securityContext:
@@ -58,10 +61,10 @@ spec:
5861
args:
5962
- '--namespace'
6063
- openshift-marketplace
61-
- --configmapServerImage=quay.io/operator-framework/configmap-operator-registry:latest
62-
- --opmImage=quay.io/operator-framework/configmap-operator-registry:latest
64+
- --configmapServerImage=registry.build10.ci.openshift.org/ci-ln-5v3wb5t/stable@sha256:242e3ba4b4f17255a29e33eb0b2f8be4faf811053d8e4aaf5b3bd8dcfba2e475
65+
- --opmImage=registry.build10.ci.openshift.org/ci-ln-5v3wb5t/stable@sha256:242e3ba4b4f17255a29e33eb0b2f8be4faf811053d8e4aaf5b3bd8dcfba2e475
6366
- --util-image
64-
- quay.io/operator-framework/olm@sha256:de396b540b82219812061d0d753440d5655250c621c753ed1dc67d6154741607
67+
- registry.build10.ci.openshift.org/ci-ln-5v3wb5t/stable@sha256:1a9ff9f40ff184cb6cbfd41d64c0d33a8f6b385aaf8f534fe1bebf572e6e206d
6568
- --writeStatusName
6669
- operator-lifecycle-manager-catalog
6770
- --tls-cert
@@ -71,7 +74,7 @@ spec:
7174
- --client-ca
7275
- /profile-collector-cert/tls.crt
7376
- --set-workload-user-id=false
74-
image: quay.io/operator-framework/olm@sha256:de396b540b82219812061d0d753440d5655250c621c753ed1dc67d6154741607
77+
image: registry.build10.ci.openshift.org/ci-ln-5v3wb5t/stable@sha256:1a9ff9f40ff184cb6cbfd41d64c0d33a8f6b385aaf8f534fe1bebf572e6e206d
7578
imagePullPolicy: IfNotPresent
7679
ports:
7780
- containerPort: 8443
@@ -94,6 +97,37 @@ spec:
9497
env:
9598
- name: RELEASE_VERSION
9699
value: "0.0.1-snapshot"
100+
- args:
101+
- --secure-listen-address=0.0.0.0:9443
102+
- --upstream=https://127.0.0.1:8443/
103+
- --tls-cert-file=/etc/tls/private/tls.crt
104+
- --tls-private-key-file=/etc/tls/private/tls.key
105+
- --upstream-ca-file=/srv-cert/tls.crt
106+
- --logtostderr=true
107+
image: quay.io/openshift/origin-kube-rbac-proxy:latest
108+
imagePullPolicy: IfNotPresent
109+
name: kube-rbac-proxy
110+
securityContext:
111+
allowPrivilegeEscalation: false
112+
readOnlyRootFilesystem: true
113+
capabilities:
114+
drop: ["ALL"]
115+
ports:
116+
- containerPort: 9443
117+
name: metrics
118+
protocol: TCP
119+
resources:
120+
requests:
121+
memory: 20Mi
122+
cpu: 10m
123+
terminationMessagePath: /dev/termination-log
124+
terminationMessagePolicy: FallbackToLogsOnError
125+
volumeMounts:
126+
- mountPath: /etc/tls/private
127+
name: catalog-operator-serving-cert
128+
- mountPath: /srv-cert
129+
name: srv-cert
130+
readOnly: true
97131
nodeSelector:
98132
kubernetes.io/os: linux
99133
node-role.kubernetes.io/master: ""

microshift-manifests/0000_50_olm_03-services.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ spec:
1717
- name: https-metrics
1818
port: 8443
1919
protocol: TCP
20-
targetPort: 8443
20+
targetPort: 9443
2121
selector:
2222
app: olm-operator
2323
---
@@ -40,6 +40,6 @@ spec:
4040
- name: https-metrics
4141
port: 8443
4242
protocol: TCP
43-
targetPort: 8443
43+
targetPort: 9443
4444
selector:
4545
app: catalog-operator

microshift-manifests/0000_50_olm_07-olm-operator.deployment.ibm-cloud-managed.yaml

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,9 @@ spec:
3838
secretName: pprof-cert
3939
- name: tmpfs
4040
emptyDir: {}
41+
- name: olm-operator-serving-cert
42+
secret:
43+
secretName: olm-operator-serving-cert
4144
containers:
4245
- name: olm-operator
4346
securityContext:
@@ -100,6 +103,37 @@ spec:
100103
requests:
101104
cpu: 10m
102105
memory: 160Mi
106+
- args:
107+
- --secure-listen-address=0.0.0.0:9443
108+
- --upstream=https://127.0.0.1:8443/
109+
- --tls-cert-file=/etc/tls/private/tls.crt
110+
- --tls-private-key-file=/etc/tls/private/tls.key
111+
- --upstream-ca-file=/srv-cert/tls.crt
112+
- --logtostderr=true
113+
image: quay.io/openshift/origin-kube-rbac-proxy:latest
114+
imagePullPolicy: IfNotPresent
115+
name: kube-rbac-proxy
116+
securityContext:
117+
allowPrivilegeEscalation: false
118+
readOnlyRootFilesystem: true
119+
capabilities:
120+
drop: ["ALL"]
121+
ports:
122+
- containerPort: 9443
123+
name: metrics
124+
protocol: TCP
125+
resources:
126+
requests:
127+
memory: 20Mi
128+
cpu: 10m
129+
terminationMessagePath: /dev/termination-log
130+
terminationMessagePolicy: FallbackToLogsOnError
131+
volumeMounts:
132+
- mountPath: /etc/tls/private
133+
name: olm-operator-serving-cert
134+
- mountPath: /srv-cert
135+
name: srv-cert
136+
readOnly: true
103137
nodeSelector:
104138
kubernetes.io/os: linux
105139
tolerations:

microshift-manifests/0000_50_olm_07-olm-operator.deployment.yaml

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,9 @@ spec:
3737
secretName: pprof-cert
3838
- name: tmpfs
3939
emptyDir: {}
40+
- name: olm-operator-serving-cert
41+
secret:
42+
secretName: olm-operator-serving-cert
4043
containers:
4144
- name: olm-operator
4245
securityContext:
@@ -95,6 +98,37 @@ spec:
9598
requests:
9699
cpu: 10m
97100
memory: 160Mi
101+
- args:
102+
- --secure-listen-address=0.0.0.0:9443
103+
- --upstream=https://127.0.0.1:8443/
104+
- --tls-cert-file=/etc/tls/private/tls.crt
105+
- --tls-private-key-file=/etc/tls/private/tls.key
106+
- --upstream-ca-file=/srv-cert/tls.crt
107+
- --logtostderr=true
108+
image: quay.io/openshift/origin-kube-rbac-proxy:latest
109+
imagePullPolicy: IfNotPresent
110+
name: kube-rbac-proxy
111+
securityContext:
112+
allowPrivilegeEscalation: false
113+
readOnlyRootFilesystem: true
114+
capabilities:
115+
drop: ["ALL"]
116+
ports:
117+
- containerPort: 9443
118+
name: metrics
119+
protocol: TCP
120+
resources:
121+
requests:
122+
memory: 20Mi
123+
cpu: 10m
124+
terminationMessagePath: /dev/termination-log
125+
terminationMessagePolicy: FallbackToLogsOnError
126+
volumeMounts:
127+
- mountPath: /etc/tls/private
128+
name: olm-operator-serving-cert
129+
- mountPath: /srv-cert
130+
name: srv-cert
131+
readOnly: true
98132
nodeSelector:
99133
kubernetes.io/os: linux
100134
node-role.kubernetes.io/master: ""

0 commit comments

Comments
 (0)