Skip to content

Commit 81f3bb5

Browse files
committed
install/servicemonitor: Instruct Prometheus to use mTLS instead of bearer token
The paths are specified at [1]. [1]: https://github.com/openshift/enhancements/blob/master/CONVENTIONS.md
1 parent 622e335 commit 81f3bb5

1 file changed

Lines changed: 3 additions & 2 deletions

File tree

install/0000_90_cluster-version-operator_02_servicemonitor.yaml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,13 +11,14 @@ metadata:
1111
include.release.openshift.io/self-managed-high-availability: "true"
1212
spec:
1313
endpoints:
14-
- bearerTokenFile: /var/run/secrets/kubernetes.io/serviceaccount/token
15-
interval: 30s
14+
- interval: 30s
1615
port: metrics
1716
scheme: https
1817
tlsConfig:
1918
caFile: /etc/prometheus/configmaps/serving-certs-ca-bundle/service-ca.crt
2019
serverName: cluster-version-operator.openshift-cluster-version.svc
20+
certFile: /etc/prometheus/secrets/metrics-client-certs/tls.crt
21+
keyFile: /etc/prometheus/secrets/metrics-client-certs/tls.key
2122
namespaceSelector:
2223
matchNames:
2324
- openshift-cluster-version

0 commit comments

Comments
 (0)