Skip to content

Commit dd0785d

Browse files
Merge pull request #305 from stbenjam/revert-304-1701485835362
TRT-1378: Revert #304 "Undo TRT-1374: Revert for \"OCPCLOUD-2278: Add kube-rbac-proxy container & ensure metrics are only available via HTTPS\""
2 parents e6cba2b + 43387bd commit dd0785d

3 files changed

Lines changed: 2 additions & 74 deletions

manifests/0000_26_cloud-controller-manager-operator_05_metrics-service.yaml

Lines changed: 0 additions & 21 deletions
This file was deleted.

manifests/0000_26_cloud-controller-manager-operator_06_kube-rbac-proxy-config.yaml

Lines changed: 0 additions & 17 deletions
This file was deleted.

manifests/0000_26_cloud-controller-manager-operator_11_deployment.yaml

Lines changed: 2 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -46,10 +46,10 @@ spec:
4646
--leader-elect-retry-period=26s \
4747
--leader-elect-resource-namespace=openshift-cloud-controller-manager-operator \
4848
"--images-json=/etc/cloud-controller-manager-config/images.json" \
49-
--metrics-bind-address=127.0.0.1:9257 \
49+
--metrics-bind-address=:9258 \
5050
--health-addr=127.0.0.1:9259
5151
ports:
52-
- containerPort: 9257
52+
- containerPort: 9258
5353
name: metrics
5454
protocol: TCP
5555
- containerPort: 9259
@@ -103,33 +103,6 @@ spec:
103103
- mountPath: /etc/kubernetes
104104
name: host-etc-kube
105105
readOnly: true
106-
- args:
107-
- --secure-listen-address=0.0.0.0:9258
108-
- --upstream=http://127.0.0.1:9257/
109-
- --tls-cert-file=/etc/tls/private/tls.crt
110-
- --tls-private-key-file=/etc/tls/private/tls.key
111-
- --config-file=/etc/kube-rbac-proxy/config-file.yaml
112-
- --tls-cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
113-
- --logtostderr=true
114-
- --v=3
115-
image: quay.io/openshift/origin-kube-rbac-proxy:4.2.0
116-
imagePullPolicy: IfNotPresent
117-
name: kube-rbac-proxy
118-
ports:
119-
- containerPort: 9258
120-
name: https
121-
protocol: TCP
122-
terminationMessagePath: /dev/termination-log
123-
terminationMessagePolicy: File
124-
resources:
125-
requests:
126-
memory: 20Mi
127-
cpu: 10m
128-
volumeMounts:
129-
- mountPath: /etc/kube-rbac-proxy
130-
name: auth-proxy-config
131-
- mountPath: /etc/tls/private
132-
name: cloud-controller-manager-operator-tls
133106
hostNetwork: true
134107
nodeSelector:
135108
node-role.kubernetes.io/master: ""
@@ -166,10 +139,3 @@ spec:
166139
hostPath:
167140
path: /etc/kubernetes
168141
type: Directory
169-
- configMap:
170-
name: kube-rbac-proxy
171-
name: auth-proxy-config
172-
- name: cloud-controller-manager-operator-tls
173-
secret:
174-
secretName: cloud-controller-manager-operator-tls
175-
optional: true

0 commit comments

Comments
 (0)