|
1 | 1 | - op: add |
2 | | - path: /status |
3 | | - value: {} |
| 2 | + path: /metadata/creationTimestamp |
| 3 | + value: null |
4 | 4 | - op: add |
5 | | - path: /spec/template/spec/securityContext |
6 | | - value: |
7 | | - fsGroup: 1337 |
| 5 | + path: /spec/template/metadata/annotations/kubectl.kubernetes.io~1default-container |
| 6 | + value: backend |
8 | 7 | - op: add |
9 | | - path: /spec/template/spec/volumes |
10 | | - value: |
11 | | - - emptyDir: |
12 | | - medium: Memory |
13 | | - name: istio-envoy |
14 | | - - emptyDir: {} |
15 | | - name: istio-data |
16 | | - - downwardAPI: |
17 | | - items: |
18 | | - - fieldRef: |
19 | | - fieldPath: metadata.labels |
20 | | - path: labels |
21 | | - - fieldRef: |
22 | | - fieldPath: metadata.annotations |
23 | | - path: annotations |
24 | | - name: istio-podinfo |
25 | | - - name: istio-token |
26 | | - projected: |
27 | | - sources: |
28 | | - - serviceAccountToken: |
29 | | - audience: istio-ca |
30 | | - expirationSeconds: 43200 |
31 | | - path: istio-token |
32 | | - - configMap: |
33 | | - name: istio-ca-root-cert |
34 | | - name: istiod-ca-cert |
| 8 | + path: /spec/template/metadata/annotations/kubectl.kubernetes.io~1default-logs-container |
| 9 | + value: backend |
35 | 10 | - op: add |
36 | | - path: /spec/template/spec/initContainers |
37 | | - value: |
38 | | - - args: |
39 | | - - istio-iptables |
40 | | - - -p |
41 | | - - "15001" |
42 | | - - -z |
43 | | - - "15006" |
44 | | - - -u |
45 | | - - "1337" |
46 | | - - -m |
47 | | - - REDIRECT |
48 | | - - -i |
49 | | - - '*' |
50 | | - - -x |
51 | | - - "" |
52 | | - - -b |
53 | | - - '*' |
54 | | - - -d |
55 | | - - 15090,15021,15020 |
56 | | - image: docker.io/istio/proxyv2:1.13.3 |
57 | | - name: istio-init |
58 | | - resources: |
59 | | - limits: |
60 | | - cpu: "2" |
61 | | - memory: 1Gi |
62 | | - requests: |
63 | | - cpu: 10m |
64 | | - memory: 16Mi |
65 | | - securityContext: |
66 | | - allowPrivilegeEscalation: false |
67 | | - capabilities: |
68 | | - add: |
69 | | - - NET_ADMIN |
70 | | - - NET_RAW |
71 | | - drop: |
72 | | - - ALL |
73 | | - privileged: false |
74 | | - readOnlyRootFilesystem: false |
75 | | - runAsGroup: 0 |
76 | | - runAsNonRoot: false |
77 | | - runAsUser: 0 |
| 11 | + path: /spec/template/metadata/annotations/prometheus.io~1path |
| 12 | + value: /stats/prometheus |
| 13 | +- op: add |
| 14 | + path: /spec/template/metadata/annotations/prometheus.io~1port |
| 15 | + value: "15020" |
| 16 | +- op: add |
| 17 | + path: /spec/template/metadata/annotations/sidecar.istio.io~1status |
| 18 | + value: '{"initContainers":["istio-init"],"containers":["istio-proxy"],"volumes":["istio-envoy","istio-data","istio-podinfo","istio-token","istiod-ca-cert"],"imagePullSecrets":null,"revision":"default"}' |
| 19 | +- op: add |
| 20 | + path: /spec/template/metadata/creationTimestamp |
| 21 | + value: null |
| 22 | +- op: add |
| 23 | + path: /spec/template/metadata/labels/security.istio.io~1tlsMode |
| 24 | + value: istio |
| 25 | +- op: add |
| 26 | + path: /spec/template/metadata/labels/service.istio.io~1canonical-name |
| 27 | + value: backend |
| 28 | +- op: add |
| 29 | + path: /spec/template/metadata/labels/service.istio.io~1canonical-revision |
| 30 | + value: latest |
78 | 31 | - op: replace |
79 | 32 | path: /spec/template/spec/containers/0/resources/limits/cpu |
80 | 33 | value: "2" |
|
185 | 138 | - mountPath: /etc/istio/pod |
186 | 139 | name: istio-podinfo |
187 | 140 | - op: add |
188 | | - path: /spec/template/metadata/creationTimestamp |
189 | | - value: null |
190 | | -- op: add |
191 | | - path: /spec/template/metadata/labels/security.istio.io~1tlsMode |
192 | | - value: istio |
193 | | -- op: add |
194 | | - path: /spec/template/metadata/labels/service.istio.io~1canonical-name |
195 | | - value: backend |
196 | | -- op: add |
197 | | - path: /spec/template/metadata/labels/service.istio.io~1canonical-revision |
198 | | - value: latest |
199 | | -- op: add |
200 | | - path: /spec/template/metadata/annotations/kubectl.kubernetes.io~1default-logs-container |
201 | | - value: backend |
202 | | -- op: add |
203 | | - path: /spec/template/metadata/annotations/sidecar.istio.io~1status |
204 | | - value: '{"initContainers":["istio-init"],"containers":["istio-proxy"],"volumes":["istio-envoy","istio-data","istio-podinfo","istio-token","istiod-ca-cert"],"imagePullSecrets":null,"revision":"default"}' |
205 | | -- op: add |
206 | | - path: /spec/template/metadata/annotations/prometheus.io~1path |
207 | | - value: /stats/prometheus |
| 141 | + path: /spec/template/spec/initContainers |
| 142 | + value: |
| 143 | + - args: |
| 144 | + - istio-iptables |
| 145 | + - -p |
| 146 | + - "15001" |
| 147 | + - -z |
| 148 | + - "15006" |
| 149 | + - -u |
| 150 | + - "1337" |
| 151 | + - -m |
| 152 | + - REDIRECT |
| 153 | + - -i |
| 154 | + - '*' |
| 155 | + - -x |
| 156 | + - "" |
| 157 | + - -b |
| 158 | + - '*' |
| 159 | + - -d |
| 160 | + - 15090,15021,15020 |
| 161 | + image: docker.io/istio/proxyv2:1.13.3 |
| 162 | + name: istio-init |
| 163 | + resources: |
| 164 | + limits: |
| 165 | + cpu: "2" |
| 166 | + memory: 1Gi |
| 167 | + requests: |
| 168 | + cpu: 10m |
| 169 | + memory: 16Mi |
| 170 | + securityContext: |
| 171 | + allowPrivilegeEscalation: false |
| 172 | + capabilities: |
| 173 | + add: |
| 174 | + - NET_ADMIN |
| 175 | + - NET_RAW |
| 176 | + drop: |
| 177 | + - ALL |
| 178 | + privileged: false |
| 179 | + readOnlyRootFilesystem: false |
| 180 | + runAsGroup: 0 |
| 181 | + runAsNonRoot: false |
| 182 | + runAsUser: 0 |
208 | 183 | - op: add |
209 | | - path: /spec/template/metadata/annotations/prometheus.io~1port |
210 | | - value: "15020" |
| 184 | + path: /spec/template/spec/securityContext |
| 185 | + value: |
| 186 | + fsGroup: 1337 |
211 | 187 | - op: add |
212 | | - path: /spec/template/metadata/annotations/kubectl.kubernetes.io~1default-container |
213 | | - value: backend |
| 188 | + path: /spec/template/spec/volumes |
| 189 | + value: |
| 190 | + - emptyDir: |
| 191 | + medium: Memory |
| 192 | + name: istio-envoy |
| 193 | + - emptyDir: {} |
| 194 | + name: istio-data |
| 195 | + - downwardAPI: |
| 196 | + items: |
| 197 | + - fieldRef: |
| 198 | + fieldPath: metadata.labels |
| 199 | + path: labels |
| 200 | + - fieldRef: |
| 201 | + fieldPath: metadata.annotations |
| 202 | + path: annotations |
| 203 | + name: istio-podinfo |
| 204 | + - name: istio-token |
| 205 | + projected: |
| 206 | + sources: |
| 207 | + - serviceAccountToken: |
| 208 | + audience: istio-ca |
| 209 | + expirationSeconds: 43200 |
| 210 | + path: istio-token |
| 211 | + - configMap: |
| 212 | + name: istio-ca-root-cert |
| 213 | + name: istiod-ca-cert |
214 | 214 | - op: add |
215 | | - path: /metadata/creationTimestamp |
216 | | - value: null |
| 215 | + path: /status |
| 216 | + value: {} |
0 commit comments