headlamp auth
This commit is contained in:
@@ -15,17 +15,26 @@ spec:
|
|||||||
config:
|
config:
|
||||||
inCluster: true
|
inCluster: true
|
||||||
|
|
||||||
# Verwende den headlamp-admin ServiceAccount
|
|
||||||
serviceAccount:
|
serviceAccount:
|
||||||
create: false
|
create: false
|
||||||
name: headlamp-admin
|
name: headlamp-admin
|
||||||
|
|
||||||
# Keine separate ClusterRoleBinding erstellen
|
|
||||||
clusterRoleBinding:
|
clusterRoleBinding:
|
||||||
create: false
|
create: false
|
||||||
|
|
||||||
# Wichtig: automountServiceAccountToken muss true sein
|
# Deaktiviere das automatische Token-Mounting
|
||||||
automountServiceAccountToken: true
|
automountServiceAccountToken: false
|
||||||
|
|
||||||
|
# Mounte stattdessen unser langlebiges Token
|
||||||
|
volumes:
|
||||||
|
- name: sa-token
|
||||||
|
secret:
|
||||||
|
secretName: headlamp-admin-token
|
||||||
|
|
||||||
|
volumeMounts:
|
||||||
|
- name: sa-token
|
||||||
|
mountPath: /var/run/secrets/kubernetes.io/serviceaccount
|
||||||
|
readOnly: true
|
||||||
|
|
||||||
ingress:
|
ingress:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
|||||||
Reference in New Issue
Block a user