vault: keep injector replicas on separate workers
This commit is contained in:
parent
440244f3ab
commit
5f3f31849c
@ -39,6 +39,13 @@ spec:
|
||||
# never finds /vault/secrets, and crash-loops indefinitely with no
|
||||
# indication that injection was skipped. Observed twice on ariadne.
|
||||
replicas: 2
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 256Mi
|
||||
agentImage:
|
||||
repository: hashicorp/vault
|
||||
tag: "1.17.6"
|
||||
@ -49,6 +56,15 @@ spec:
|
||||
nodeSelector:
|
||||
node-role.kubernetes.io/worker: "true"
|
||||
affinity:
|
||||
# Preserve the chart's spreading rule when adding node preferences.
|
||||
podAntiAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
- topologyKey: kubernetes.io/hostname
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/instance: vault-injector
|
||||
app.kubernetes.io/name: vault-agent-injector
|
||||
component: webhook
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
|
||||
@ -3,3 +3,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- helmrelease.yaml
|
||||
- poddisruptionbudget.yaml
|
||||
|
||||
13
infrastructure/vault-injector/poddisruptionbudget.yaml
Normal file
13
infrastructure/vault-injector/poddisruptionbudget.yaml
Normal file
@ -0,0 +1,13 @@
|
||||
# infrastructure/vault-injector/poddisruptionbudget.yaml
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: vault-injector
|
||||
namespace: vault
|
||||
spec:
|
||||
minAvailable: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/instance: vault-injector
|
||||
app.kubernetes.io/name: vault-agent-injector
|
||||
component: webhook
|
||||
Loading…
x
Reference in New Issue
Block a user