# Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. {{- $envAll := . }} {{- $dependencies := .Values.dependencies.api }} {{- $mounts_barbican_api := .Values.mounts.barbican_api.barbican_api }} {{- $mounts_barbican_api_init := .Values.mounts.barbican_api.init_container }} apiVersion: extensions/v1beta1 kind: Deployment metadata: name: barbican-api spec: replicas: {{ .Values.replicas.api }} revisionHistoryLimit: {{ .Values.upgrades.revision_history }} strategy: type: {{ .Values.upgrades.pod_replacement_strategy }} {{ if eq .Values.upgrades.pod_replacement_strategy "RollingUpdate" }} rollingUpdate: maxUnavailable: {{ .Values.upgrades.rolling_update.max_unavailable }} maxSurge: {{ .Values.upgrades.rolling_update.max_surge }} {{ end }} template: metadata: labels: app: barbican-api annotations: configmap-bin-hash: {{ tuple "configmap-bin.yaml" . | include "helm-toolkit.hash" }} configmap-etc-hash: {{ tuple "configmap-etc.yaml" . | include "helm-toolkit.hash" }} pod.beta.kubernetes.io/init-containers: '[ {{ tuple $envAll $dependencies $mounts_barbican_api_init | include "helm-toolkit.kubernetes_entrypoint_init_container" | indent 10 }} ]' spec: nodeSelector: {{ .Values.labels.node_selector_key }}: {{ .Values.labels.node_selector_value }} containers: - name: barbican-api image: {{ .Values.images.api }} imagePullPolicy: {{ .Values.images.pull_policy }} {{- if .Values.resources.enabled }} resources: limits: cpu: {{ .Values.resources.api.limits.cpu | quote }} memory: {{ .Values.resources.api.limits.memory | quote }} requests: cpu: {{ .Values.resources.api.requests.cpu | quote }} memory: {{ .Values.resources.api.requests.memory | quote }} {{- end }} command: - bash - /tmp/start.sh ports: - containerPort: {{ .Values.conf.barbican.barbican_api.barbican.config.bind_port }} readinessProbe: tcpSocket: port: {{ .Values.conf.barbican.barbican_api.barbican.config.bind_port }} volumeMounts: - name: etcbarbican mountPath: /etc/barbican - name: barbican-etc mountPath: /etc/barbican/vassals/barbican-api.ini subPath: vassals/barbican-api.ini readOnly: true - name: barbican-etc mountPath: /etc/barbican/barbican.conf subPath: barbican.conf readOnly: true - name: barbican-etc mountPath: /etc/barbican/api_audit_map.conf subPath: api_audit_map.conf readOnly: true - name: barbican-etc mountPath: /etc/barbican/barbican-api-paste.ini subPath: barbican-api-paste.ini readOnly: true - name: barbican-etc mountPath: /etc/barbican/policy.json subPath: policy.json readOnly: true - name: barbican-bin mountPath: /tmp/start.sh subPath: start.sh readOnly: true {{ if $mounts_barbican_api.volumeMounts }}{{ toYaml $mounts_barbican_api.volumeMounts | indent 12 }}{{ end }} volumes: - name: etcbarbican emptyDir: {} - name: barbican-etc configMap: name: barbican-etc - name: barbican-bin configMap: name: barbican-bin {{ if $mounts_barbican_api.volumes }}{{ toYaml $mounts_barbican_api.volumes | indent 8 }}{{ end }}