-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(charts)!: Update Helm release influxdb to 6.3.20 #2435
base: main
Are you sure you want to change the base?
Conversation
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
088df2f
to
30d079c
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
30d079c
to
bfad5ce
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
bfad5ce
to
a3faf9c
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
a3faf9c
to
cd39c9e
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
cd39c9e
to
fae594c
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
fae594c
to
2ae1340
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
2ae1340
to
4128d22
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
4128d22
to
eec665c
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
eec665c
to
059cf03
Compare
Path: @@ -5,12 +5,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +18,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +33,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +52,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +63,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +73,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +93,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +104,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +114,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -196,9 +205,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +227,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
79bab25
to
303ad32
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
303ad32
to
c52eba6
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
c52eba6
to
5ca73fc
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
5ca73fc
to
080c71d
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
080c71d
to
7025bec
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
7025bec
to
cc2f945
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
cc2f945
to
479bc5c
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
479bc5c
to
fc7ed5f
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
Signed-off-by: Danny Froberg <[email protected]>
fc7ed5f
to
9d46cbe
Compare
Path: @@ -1,3 +1,22 @@
+# Source: influxdb/templates/pdb.yaml
+apiVersion: policy/v1
+kind: PodDisruptionBudget
+metadata:
+ name: influxdb
+ namespace: "default"
+ labels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+spec:
+ maxUnavailable: 1
+ selector:
+ matchLabels:
+ app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
+---
# Source: influxdb/templates/serviceaccount.yaml
apiVersion: v1
kind: ServiceAccount
@@ -5,12 +24,11 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- annotations:
-automountServiceAccountToken: true
+automountServiceAccountToken: false
---
# Source: influxdb/templates/secrets.yaml
apiVersion: v1
@@ -19,9 +37,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
type: Opaque
data:
admin-user-password: "JHtTRUNSRVRfSU5GTFVYX0FETUlOX1BBU1NXT1JEfQ=="
@@ -34,9 +52,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
type: LoadBalancer
@@ -53,8 +71,8 @@
protocol: TCP
name: rpc
selector:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
---
# Source: influxdb/templates/deployment.yaml
@@ -64,9 +82,9 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
replicas: 1
@@ -74,20 +92,19 @@
type: RollingUpdate
selector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
template:
metadata:
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
spec:
imagePullSecrets:
- name: regcred
- - name: regcred
affinity:
podAffinity:
podAntiAffinity:
@@ -95,11 +112,9 @@
- podAffinityTerm:
labelSelector:
matchLabels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
+ app.kubernetes.io/name: influxdb
app.kubernetes.io/component: influxdb
- namespaces:
- - "default"
topologyKey: kubernetes.io/hostname
weight: 1
nodeAffinity:
@@ -108,6 +123,9 @@
worker: true
securityContext:
fsGroup: 1001
+ fsGroupChangePolicy: Always
+ supplementalGroups: []
+ sysctls: []
serviceAccountName: influxdb
initContainers:
containers:
@@ -115,8 +133,18 @@
image: docker.io/bitnami/influxdb:2.2.0-debian-10-r12
imagePullPolicy: "IfNotPresent"
securityContext:
+ allowPrivilegeEscalation: false
+ capabilities:
+ drop:
+ - ALL
+ privileged: false
+ readOnlyRootFilesystem: true
+ runAsGroup: 1001
runAsNonRoot: true
runAsUser: 1001
+ seLinuxOptions: {}
+ seccompProfile:
+ type: RuntimeDefault
env:
- name: BITNAMI_DEBUG
value: "false"
@@ -158,18 +186,9 @@
periodSeconds: 45
successThreshold: 1
timeoutSeconds: 45
- exec:
- command:
- - bash
- - -c
- - |
- . /opt/bitnami/scripts/libinfluxdb.sh
-
- influxdb_env
- export INFLUX_USERNAME="$INFLUXDB_ADMIN_USER"
- export INFLUX_PASSWORD="$INFLUXDB_ADMIN_USER_PASSWORD"
-
- timeout 44s influx ping --host http://$POD_IP:8086
+ httpGet:
+ port: http
+ path: /
readinessProbe:
failureThreshold: 6
initialDelaySeconds: 180
@@ -196,9 +215,17 @@
cpu: 50m
memory: 263M
volumeMounts:
+ - name: empty-dir
+ mountPath: /tmp
+ subPath: tmp-dir
+ - name: empty-dir
+ mountPath: /opt/bitnami/influxdb/etc
+ subPath: app-conf-dir
- name: data
mountPath: /bitnami/influxdb
volumes:
+ - name: empty-dir
+ emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: influx-db-v1
@@ -210,9 +237,10 @@
name: influxdb
namespace: "default"
labels:
- app.kubernetes.io/name: influxdb
app.kubernetes.io/instance: influxdb
app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: influxdb
+ app.kubernetes.io/component: influxdb
annotations:
kubernetes.io/tls-acme: "true"
traefik.ingress.kubernetes.io/router.entrypoints: websecure |
This PR contains the following updates:
5.4.6
->6.3.20
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
bitnami/charts (influxdb)
v6.3.20
v6.3.18
v6.3.17
v6.3.16
v6.3.15
v6.3.14
v6.3.13
v6.3.12
v6.3.11
v6.3.10
v6.3.9
v6.3.8
v6.3.7
v6.3.6
v6.3.5
v6.3.4
v6.3.2
v6.3.1
v6.3.0
v6.2.1
v6.2.0
v6.1.1
v6.1.0
v6.0.13
v6.0.12
v6.0.11
v6.0.10
v6.0.9
v6.0.8
v6.0.7
v6.0.6
v6.0.5
v6.0.4
v6.0.3
v6.0.2
v6.0.1
v6.0.0
v5.18.1
v5.18.0
v5.17.1
v5.17.0
v5.16.3
v5.16.2
v5.16.1
v5.15.0
v5.14.2
v5.14.1
v5.14.0
v5.13.6
v5.13.5
v5.13.4
v5.13.3
v5.13.2
v5.13.0
v5.12.1
v5.12.0
v5.11.4
v5.11.3
v5.11.2
v5.11.1
v5.11.0
v5.10.2
v5.10.1
v5.10.0
v5.9.11
v5.9.10
v5.9.9
v5.9.8
v5.9.7
v5.9.6
v5.9.5
v5.9.4
v5.9.3
v5.9.2
v5.9.1
v5.9.0
v5.8.3
v5.8.2
v5.8.1
v5.8.0
v5.7.3
v5.7.2
v5.7.1
v5.7.0
v5.6.2
v5.6.1
v5.5.2
v5.5.1
v5.4.23
v5.4.22
v5.4.21
v5.4.20
v5.4.19
v5.4.18
v5.4.17
v5.4.16
v5.4.15
v5.4.14
v5.4.13
v5.4.12
v5.4.11
v5.4.10
v5.4.9
v5.4.8
v5.4.7
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.