Files
my-rook-config/tests/scripts/webhook-config.yaml
T
Sébastien Han 128dc4cb79 Merge pull request #7325 from subhamkrai/cert-manager
ceph: use cert-manager for admission webhooks
2021-03-09 10:38:27 +01:00

53 lines
1.9 KiB
YAML

apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingWebhookConfiguration
metadata:
name: ${WEBHOOK_CONFIG_NAME}
annotations:
cert-manager.io/inject-ca-from: ${NAMESPACE}/rook-admission-controller-cert
webhooks:
- name: cephcluster-wh-${SERVICE_NAME}-${NAMESPACE}.rook.io
rules:
- apiGroups: ["ceph.rook.io"]
apiVersions: ["v1"]
operations: ["CREATE","UPDATE","DELETE"]
resources: ["cephclusters"]
clientConfig:
service:
name: ${SERVICE_NAME}
namespace: ${NAMESPACE}
path: /validate-ceph-rook-io-v1-cephcluster
caBundle: ${CA_BUNDLE}
admissionReviewVersions: ["v1", "v1beta1"] # API server will try to use first version in the list which it supports.
sideEffects: None
timeoutSeconds: 5
- name: cephblockpool-wh-${SERVICE_NAME}-${NAMESPACE}.rook.io
rules:
- apiGroups: ["ceph.rook.io"]
apiVersions: ["v1"]
operations: ["CREATE","UPDATE","DELETE"]
resources: ["cephblockpools"]
clientConfig:
service:
name: ${SERVICE_NAME}
namespace: ${NAMESPACE}
path: /validate-ceph-rook-io-v1-cephblockpool
caBundle: ${CA_BUNDLE}
admissionReviewVersions: ["v1", "v1beta1"] # API server will try to use first version in the list which it supports.
sideEffects: None
timeoutSeconds: 5
- name: cephobjectstore-wh-${SERVICE_NAME}-${NAMESPACE}.rook.io
rules:
- apiGroups: ["ceph.rook.io"]
apiVersions: ["v1"]
operations: ["CREATE","UPDATE","DELETE"]
resources: ["cephobjectstores"]
clientConfig:
service:
name: ${SERVICE_NAME}
namespace: ${NAMESPACE}
path: /validate-ceph-rook-io-v1-cephobjectstore
caBundle: ${CA_BUNDLE}
admissionReviewVersions: ["v1", "v1beta1"] # API server will try to use first version in the list which it supports.
sideEffects: None
timeoutSeconds: 5