Skip to content

Commit

Permalink
feat(k8s): opt-in to support tls for GAPI in other namespaces than sy…
Browse files Browse the repository at this point in the history
…stem

Signed-off-by: Jakub Dyszkiewicz <[email protected]>
  • Loading branch information
jakubdyszkiewicz committed Apr 19, 2024
1 parent 4eb5103 commit 34c2b77
Show file tree
Hide file tree
Showing 33 changed files with 206 additions and 30 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -103,11 +103,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7907,11 +7907,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -321,6 +321,10 @@ controlPlane:
containerSecurityContext:
readOnlyRootFilesystem: true

# -- If true, then control plane can support TLS secrets for builtin gateway outside of mesh system namespace.
# The downside is that control plane requires permission to read Secrets in all namespaces.
supportAllGatewaySecrets: false

cni:
# -- Install Kuma with CNI instead of proxy init container
enabled: false
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7907,11 +7907,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -58,11 +58,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7927,11 +7927,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -58,11 +58,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -65,11 +65,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,11 +62,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -123,11 +123,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -68,11 +68,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -51,11 +51,17 @@ rules:
- pods
- configmaps
- nodes
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- secret
verbs:
- list
- watch
- apiGroups:
- "apps"
resources:
Expand Down
Loading

0 comments on commit 34c2b77

Please sign in to comment.