Skip to content

Commit f855d69

Browse files
committed
Add rolebinding and test deploy
1 parent d6650c8 commit f855d69

7 files changed

Lines changed: 132 additions & 0 deletions

File tree

k8s/base/kustomization.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
---
22
resources:
33
- namespace.yaml
4+
- rolebinding.yaml
45
- openstack-api-backup-cron.yaml

k8s/base/rolebinding.yaml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
apiVersion: rbac.authorization.k8s.io/v1
2+
kind: RoleBinding
3+
metadata:
4+
name: system:openshift:scc:anyuid
5+
namespace: openstack-api-backup
6+
roleRef:
7+
apiGroup: rbac.authorization.k8s.io
8+
kind: ClusterRole
9+
name: system:openshift:scc:anyuid
10+
subjects:
11+
- kind: ServiceAccount
12+
name: default
13+
namespace: openstack-api-backup
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
namespace: openstack-api-backup
3+
resources:
4+
- ../../base
5+
- secrets
6+
- pvc.yaml
7+
8+
patchesStrategicMerge:
9+
- patches/patch-openstack-api-backup-cron.yaml
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
---
2+
apiVersion: batch/v1
3+
kind: CronJob
4+
metadata:
5+
name: openstack-api-backup
6+
namespace: openstack-api-backup
7+
spec:
8+
schedule: 35 * * * *
9+
jobTemplate:
10+
spec:
11+
template:
12+
spec:
13+
containers:
14+
- name: openstack-api-backup
15+
env:
16+
- name: S3_ENDPOINT
17+
valueFrom:
18+
$patch: replace
19+
secretKeyRef:
20+
name: openstack-api-backup
21+
key: s3_endpoint
22+
- name: S3_BUCKET_URI
23+
valueFrom:
24+
$patch: replace
25+
secretKeyRef:
26+
name: openstack-api-backup
27+
key: s3_bucket_uri
28+
- name: BACKUP_ROTATE
29+
valueFrom:
30+
$patch: replace
31+
secretKeyRef:
32+
name: openstack-api-backup
33+
key: backup_rotate
34+
- name: OS_AUTH_TYPE
35+
value: v3applicationcredential
36+
- name: OS_AUTH_URL
37+
valueFrom:
38+
$patch: replace
39+
secretKeyRef:
40+
name: openstack-api-backup
41+
key: os_auth_url
42+
- name: OS_APPLICATION_CREDENTIAL_ID
43+
valueFrom:
44+
$patch: replace
45+
secretKeyRef:
46+
name: openstack-api-backup
47+
key: os_application_credential_id
48+
- name: OS_APPLICATION_CREDENTIAL_SECRET
49+
valueFrom:
50+
$path: replace
51+
secretKeyRef:
52+
name: openstack-api-backup
53+
key: os_application_credential_secret

k8s/overlays/ocp-aa-test1/pvc.yaml

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
---
2+
apiVersion: v1
3+
kind: PersistentVolumeClaim
4+
metadata:
5+
name: openstack-api-backup
6+
spec:
7+
accessModes:
8+
- ReadWriteOnce
9+
resources:
10+
requests:
11+
storage: 2Gi
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
---
2+
resources:
3+
- openstack-api-backup.yaml
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
---
2+
apiVersion: external-secrets.io/v1alpha1
3+
kind: ExternalSecret
4+
metadata:
5+
name: openstack-api-backup
6+
namespace: openstack-api-backup
7+
spec:
8+
refreshInterval: "15s"
9+
secretStoreRef:
10+
name: vault-backend
11+
kind: ClusterSecretStore
12+
target:
13+
name: openstack-api-backup
14+
data:
15+
- secretKey: aws_credentials
16+
remoteRef:
17+
key: accounts/holecs
18+
property: awscli_credentials
19+
- secretKey: backup_rotate
20+
remoteRef:
21+
key: openstack-api-backup/config
22+
property: backup_rotate
23+
- secretKey: s3_endpoint
24+
remoteRef:
25+
key: openstack-api-backup/config
26+
property: s3_endpoint
27+
- secretKey: s3_bucket_uri
28+
remoteRef:
29+
key: openstack-api-backup/config
30+
property: s3_bucket_uri
31+
- secretKey: os_auth_url
32+
remoteRef:
33+
key: openstack-api-backup/config
34+
property: os_auth_url
35+
- secretKey: os_application_credential_id
36+
remoteRef:
37+
key: openstack-api-backup/config
38+
property: os_application_credential_id
39+
- secretKey: os_application_credential_secret
40+
remoteRef:
41+
key: openstack-api-backup/config
42+
property: os_application_credential_secret

0 commit comments

Comments
 (0)