@@ -30,16 +30,19 @@ spec:
30
30
prometheus.io/scheme : " http"
31
31
prometheus.io/scrape : " true"
32
32
spec :
33
- dnsPolicy : Default
34
33
automountServiceAccountToken : true
35
34
serviceAccountName : karpenter
36
35
securityContext :
37
36
fsGroup : 65532
37
+ runAsNonRoot : false
38
+ seccompProfile :
39
+ type : RuntimeDefault
38
40
priorityClassName : " {{ .Cluster.ConfigItems.system_priority_class }}"
39
41
dnsPolicy : ClusterFirst
40
42
containers :
41
43
- name : controller
42
44
securityContext :
45
+ privileged : false
43
46
runAsUser : 65532
44
47
runAsGroup : 65532
45
48
runAsNonRoot : true
@@ -50,11 +53,11 @@ spec:
50
53
drop :
51
54
- ALL
52
55
readOnlyRootFilesystem : true
53
- image : " container-registry.zalando.net/teapot/karpenter:1.4 .0-main-38 .patched"
56
+ image : " container-registry.zalando.net/teapot/karpenter:1.5 .0-main-39 .patched"
54
57
imagePullPolicy : IfNotPresent
55
58
env :
56
59
- name : KUBERNETES_MIN_VERSION
57
- value : 1.22 .0-0
60
+ value : 1.19 .0-0
58
61
- name : AWS_REGION
59
62
value : " {{ .Cluster.Region }}"
60
63
- name : CLUSTER_ENDPOINT
@@ -88,13 +91,11 @@ spec:
88
91
divisor : " 0"
89
92
resource : limits.memory
90
93
- name : FEATURE_GATES
91
- value : " Drift =false,SpotToSpotConsolidation=true,NodeRepair=false"
94
+ value : " ReservedCapacity =false,SpotToSpotConsolidation=true,NodeRepair=false"
92
95
- name : BATCH_MAX_DURATION
93
96
value : " 10s"
94
97
- name : BATCH_IDLE_DURATION
95
98
value : " 1s"
96
- - name : ASSUME_ROLE_DURATION
97
- value : " 15m"
98
99
- name : PREFERENCE_POLICY
99
100
value : " Respect"
100
101
- name : CLUSTER_NAME
@@ -153,13 +154,6 @@ spec:
153
154
matchLabels :
154
155
deployment : karpenter
155
156
topologyKey : kubernetes.io/hostname
156
- # topologySpreadConstraints:
157
- # - labelSelector:
158
- # matchLabels:
159
- # deployment: karpenter
160
- # maxSkew: 1
161
- # topologyKey: topology.kubernetes.io/zone
162
- # whenUnsatisfiable: ScheduleAnyway
163
157
tolerations :
164
158
- key : CriticalAddonsOnly
165
159
operator : Exists
0 commit comments