The controller uses leader election with replicas=1. During RollingUpdate, the new pod cannot acquire the leader lease (old pod holds it) and fails health checks, causing indefinite restart loops. Recreate strategy ensures the old pod terminates before the new one starts, allowing clean leader election transitions. Fixes: DEV-442 Co-Authored-By: Paperclip <noreply@paperclip.ing>
76 lines
1.9 KiB
YAML
76 lines
1.9 KiB
YAML
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: pangolin-controller
|
|
namespace: pangolin
|
|
labels:
|
|
app: pangolin-controller
|
|
component: controller
|
|
spec:
|
|
replicas: 1
|
|
strategy:
|
|
type: Recreate
|
|
selector:
|
|
matchLabels:
|
|
app: pangolin-controller
|
|
component: controller
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: pangolin-controller
|
|
component: controller
|
|
spec:
|
|
serviceAccountName: pangolin-controller
|
|
containers:
|
|
- name: controller
|
|
image: fosrl/pangolin-kube-controller:0.1.0-alpha.1
|
|
imagePullPolicy: IfNotPresent
|
|
envFrom:
|
|
- configMapRef:
|
|
name: pangolin-controller-config
|
|
env:
|
|
- name: CONFIG_AUTH_HEADER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: pangolin-controller-api-key
|
|
key: auth-header
|
|
ports:
|
|
- name: metrics
|
|
containerPort: 9090
|
|
protocol: TCP
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 128Mi
|
|
limits:
|
|
cpu: 500m
|
|
memory: 512Mi
|
|
livenessProbe:
|
|
httpGet:
|
|
path: /healthz
|
|
port: 9090
|
|
initialDelaySeconds: 15
|
|
periodSeconds: 20
|
|
timeoutSeconds: 5
|
|
failureThreshold: 3
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /readyz
|
|
port: 9090
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 10
|
|
timeoutSeconds: 5
|
|
failureThreshold: 3
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
runAsNonRoot: true
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 65532
|
|
runAsGroup: 65532
|
|
fsGroup: 65532
|
|
seccompProfile:
|
|
type: RuntimeDefault
|