maintenance: spread auth helpers off quarantined workers

This commit is contained in:
jenkins 2026-10-04 05:38:32 -05:00
parent 63eafdd3db
commit 82a0930d9f
2 changed files with 20 additions and 0 deletions

View File

@ -34,6 +34,7 @@ spec:
app: oauth2-proxy-metis
annotations:
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-requests-cpu: "25m"
vault.hashicorp.com/role: "maintenance"
vault.hashicorp.com/agent-inject-secret-oidc-config: "kv/data/atlas/maintenance/metis-oidc"
vault.hashicorp.com/agent-inject-template-oidc-config: |
@ -54,6 +55,9 @@ spec:
- key: kubernetes.io/arch
operator: In
values: ["amd64","arm64"]
- key: kubernetes.io/hostname
operator: NotIn
values: [titan-04, titan-05, titan-06, titan-08, titan-11, titan-14, titan-18]
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
preference:
@ -67,6 +71,12 @@ spec:
- key: kubernetes.io/hostname
operator: NotIn
values: ["titan-13","titan-15","titan-17","titan-19"]
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
matchLabels:
app: oauth2-proxy-metis
topologyKey: kubernetes.io/hostname
containers:
- name: oauth2-proxy
image: quay.io/oauth2-proxy/oauth2-proxy:v7.6.0

View File

@ -34,6 +34,7 @@ spec:
app: oauth2-proxy-soteria
annotations:
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-requests-cpu: "25m"
vault.hashicorp.com/role: "maintenance"
vault.hashicorp.com/agent-inject-secret-oidc-config: "kv/data/atlas/maintenance/soteria-oidc"
vault.hashicorp.com/agent-inject-template-oidc-config: |
@ -54,6 +55,9 @@ spec:
- key: kubernetes.io/arch
operator: In
values: ["amd64","arm64"]
- key: kubernetes.io/hostname
operator: NotIn
values: [titan-04, titan-05, titan-06, titan-08, titan-11, titan-14, titan-18]
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
preference:
@ -67,6 +71,12 @@ spec:
- key: kubernetes.io/hostname
operator: NotIn
values: ["titan-13","titan-15","titan-17","titan-19"]
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
matchLabels:
app: oauth2-proxy-soteria
topologyKey: kubernetes.io/hostname
containers:
- name: oauth2-proxy
image: quay.io/oauth2-proxy/oauth2-proxy:v7.6.0