leaderElection fix
This commit is contained in:
@@ -13143,6 +13143,38 @@ metadata:
|
|||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: Role
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: cainjector
|
||||||
|
app.kubernetes.io/component: cainjector
|
||||||
|
app.kubernetes.io/instance: cert-manager
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/name: cainjector
|
||||||
|
app.kubernetes.io/version: v1.19.1
|
||||||
|
helm.sh/chart: cert-manager-v1.19.1
|
||||||
|
name: cert-manager-cainjector:leaderelection
|
||||||
|
namespace: cert-manager
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- coordination.k8s.io
|
||||||
|
resourceNames:
|
||||||
|
- cert-manager-cainjector-leader-election
|
||||||
|
- cert-manager-cainjector-leader-election-core
|
||||||
|
resources:
|
||||||
|
- leases
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- coordination.k8s.io
|
||||||
|
resources:
|
||||||
|
- leases
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
metadata:
|
metadata:
|
||||||
annotations:
|
annotations:
|
||||||
helm.sh/hook: post-install
|
helm.sh/hook: post-install
|
||||||
@@ -13223,38 +13255,6 @@ rules:
|
|||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: Role
|
kind: Role
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cainjector
|
|
||||||
app.kubernetes.io/component: cainjector
|
|
||||||
app.kubernetes.io/instance: cert-manager
|
|
||||||
app.kubernetes.io/managed-by: Helm
|
|
||||||
app.kubernetes.io/name: cainjector
|
|
||||||
app.kubernetes.io/version: v1.19.1
|
|
||||||
helm.sh/chart: cert-manager-v1.19.1
|
|
||||||
name: cert-manager-cainjector:leaderelection
|
|
||||||
namespace: kube-system
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- coordination.k8s.io
|
|
||||||
resourceNames:
|
|
||||||
- cert-manager-cainjector-leader-election
|
|
||||||
- cert-manager-cainjector-leader-election-core
|
|
||||||
resources:
|
|
||||||
- leases
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- update
|
|
||||||
- patch
|
|
||||||
- apiGroups:
|
|
||||||
- coordination.k8s.io
|
|
||||||
resources:
|
|
||||||
- leases
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
app: cert-manager
|
app: cert-manager
|
||||||
@@ -13265,7 +13265,7 @@ metadata:
|
|||||||
app.kubernetes.io/version: v1.19.1
|
app.kubernetes.io/version: v1.19.1
|
||||||
helm.sh/chart: cert-manager-v1.19.1
|
helm.sh/chart: cert-manager-v1.19.1
|
||||||
name: cert-manager:leaderelection
|
name: cert-manager:leaderelection
|
||||||
namespace: kube-system
|
namespace: cert-manager
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- coordination.k8s.io
|
- coordination.k8s.io
|
||||||
@@ -13962,6 +13962,28 @@ rules:
|
|||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: cainjector
|
||||||
|
app.kubernetes.io/component: cainjector
|
||||||
|
app.kubernetes.io/instance: cert-manager
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/name: cainjector
|
||||||
|
app.kubernetes.io/version: v1.19.1
|
||||||
|
helm.sh/chart: cert-manager-v1.19.1
|
||||||
|
name: cert-manager-cainjector:leaderelection
|
||||||
|
namespace: cert-manager
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: cert-manager-cainjector:leaderelection
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: cert-manager-cainjector
|
||||||
|
namespace: cert-manager
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
annotations:
|
annotations:
|
||||||
helm.sh/hook: post-install
|
helm.sh/hook: post-install
|
||||||
@@ -14032,28 +14054,6 @@ subjects:
|
|||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cainjector
|
|
||||||
app.kubernetes.io/component: cainjector
|
|
||||||
app.kubernetes.io/instance: cert-manager
|
|
||||||
app.kubernetes.io/managed-by: Helm
|
|
||||||
app.kubernetes.io/name: cainjector
|
|
||||||
app.kubernetes.io/version: v1.19.1
|
|
||||||
helm.sh/chart: cert-manager-v1.19.1
|
|
||||||
name: cert-manager-cainjector:leaderelection
|
|
||||||
namespace: kube-system
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: cert-manager-cainjector:leaderelection
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: cert-manager-cainjector
|
|
||||||
namespace: cert-manager
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
app: cert-manager
|
app: cert-manager
|
||||||
@@ -14064,7 +14064,7 @@ metadata:
|
|||||||
app.kubernetes.io/version: v1.19.1
|
app.kubernetes.io/version: v1.19.1
|
||||||
helm.sh/chart: cert-manager-v1.19.1
|
helm.sh/chart: cert-manager-v1.19.1
|
||||||
name: cert-manager:leaderelection
|
name: cert-manager:leaderelection
|
||||||
namespace: kube-system
|
namespace: cert-manager
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: Role
|
kind: Role
|
||||||
@@ -14401,7 +14401,7 @@ spec:
|
|||||||
- args:
|
- args:
|
||||||
- --v=2
|
- --v=2
|
||||||
- --cluster-resource-namespace=$(POD_NAMESPACE)
|
- --cluster-resource-namespace=$(POD_NAMESPACE)
|
||||||
- --leader-election-namespace=kube-system
|
- --leader-election-namespace=cert-manager
|
||||||
- --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.19.1
|
- --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.19.1
|
||||||
- --max-concurrent-challenges=60
|
- --max-concurrent-challenges=60
|
||||||
env:
|
env:
|
||||||
@@ -14482,7 +14482,7 @@ spec:
|
|||||||
containers:
|
containers:
|
||||||
- args:
|
- args:
|
||||||
- --v=2
|
- --v=2
|
||||||
- --leader-election-namespace=kube-system
|
- --leader-election-namespace=cert-manager
|
||||||
env:
|
env:
|
||||||
- name: POD_NAMESPACE
|
- name: POD_NAMESPACE
|
||||||
valueFrom:
|
valueFrom:
|
||||||
|
|||||||
@@ -70,7 +70,7 @@ global:
|
|||||||
|
|
||||||
leaderElection:
|
leaderElection:
|
||||||
# Override the namespace used for the leader election lease.
|
# Override the namespace used for the leader election lease.
|
||||||
namespace: "kube-system"
|
namespace: "cert-manager"
|
||||||
|
|
||||||
# The duration that non-leader candidates will wait after observing a
|
# The duration that non-leader candidates will wait after observing a
|
||||||
# leadership renewal until attempting to acquire leadership of a led but
|
# leadership renewal until attempting to acquire leadership of a led but
|
||||||
|
|||||||
Reference in New Issue
Block a user