diff --git a/charts/sn-operator/templates/sa.yaml b/charts/sn-operator/templates/sa.yaml index 7267a84..c5e4927 100644 --- a/charts/sn-operator/templates/sa.yaml +++ b/charts/sn-operator/templates/sa.yaml @@ -10,4 +10,5 @@ metadata: annotations: {{- toYaml . | nindent 4 }} {{- end }} -{{- end }} \ No newline at end of file +automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }} +{{- end }} diff --git a/charts/sn-operator/values.yaml b/charts/sn-operator/values.yaml index bfc3bb6..a5d1d72 100644 --- a/charts/sn-operator/values.yaml +++ b/charts/sn-operator/values.yaml @@ -42,6 +42,10 @@ serviceAccount: # -- Specifies whether a service account should be created # if set to false, pre-create service account and specify the sa name, so the chart will bind the role/clusterrole to the sa. create: true + # -- Controls whether Kubernetes automatically mounts API credentials into pods using this service account. + # The operator requires Kubernetes API credentials. When set to false, configure + # volumeMounts and volumes below to project the service account credentials manually. + automountServiceAccountToken: true # Annotations to add to the service account annotations: {} # The name of the service account to use. @@ -70,6 +74,35 @@ securityContext: {} # runAsNonRoot: true # runAsUser: 1000 +# -- Additional volume mounts for the operator container. +# When serviceAccount.automountServiceAccountToken is false, the following example +# mounts the credentials required by the operator at the standard in-cluster path. +volumeMounts: [] + # - name: kube-api-access + # mountPath: /var/run/secrets/kubernetes.io/serviceaccount + # readOnly: true + +# -- Additional volumes for the operator pod. +volumes: [] + # - name: kube-api-access + # projected: + # defaultMode: 420 + # sources: + # - serviceAccountToken: + # expirationSeconds: 3607 + # path: token + # - configMap: + # name: kube-root-ca.crt + # items: + # - key: ca.crt + # path: ca.crt + # - downwardAPI: + # items: + # - path: namespace + # fieldRef: + # apiVersion: v1 + # fieldPath: metadata.namespace + # -- Add resource limits and requests resources: {} # We usually recommend not to specify default resources and to leave this as a conscious