Commit 7700386d by Guangbo Chen

fixed create nfs persistent volume

parent 5516dce3
kind: ClusterRoleBinding kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
metadata: metadata:
name: {{ template "nfs.fullname" . }}-run name: run-{{ template "nfs.fullname" . }}
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: {{ template "nfs.fullname" . }} name: {{ template "nfs.fullname" . }}
......
apiVersion: extensions/v1beta1
kind: DaemonSet kind: DaemonSet
apiVersion: extensions/v1beta1
metadata: metadata:
name: {{ template "nfs.fullname" . }} name: {{ template "nfs.fullname" . }}
labels: labels:
...@@ -36,7 +36,7 @@ spec: ...@@ -36,7 +36,7 @@ spec:
- DAC_READ_SEARCH - DAC_READ_SEARCH
- SYS_RESOURCE - SYS_RESOURCE
args: args:
- "-provisioner=rancher.io/nfs" - "-provisioner=local.net/{{ template "nfs.fullname" . }}"
env: env:
- name: POD_IP - name: POD_IP
valueFrom: valueFrom:
......
apiVersion: extensions/v1beta1
kind: PodSecurityPolicy
metadata:
name: {{ template "nfs.fullname" . }}
spec:
fsGroup:
rule: RunAsAny
allowedCapabilities:
- DAC_READ_SEARCH
- SYS_RESOURCE
runAsUser:
rule: RunAsAny
seLinux:
rule: RunAsAny
supplementalGroups:
rule: RunAsAny
volumes:
- configMap
- downwardAPI
- emptyDir
- persistentVolumeClaim
- secret
- hostPath
...@@ -11,4 +11,4 @@ metadata: ...@@ -11,4 +11,4 @@ metadata:
{{- end }} {{- end }}
labels: labels:
kubernetes.io/cluster-service: "true" kubernetes.io/cluster-service: "true"
provisioner: rancher.io/{{ template "nfs.fullname" . }} provisioner: local.net/{{ template "nfs.fullname" . }}
...@@ -10,5 +10,10 @@ nfs: ...@@ -10,5 +10,10 @@ nfs:
hostPort: 2049 hostPort: 2049
persistence: persistence:
# Set the NFS provisioner to be the default storage class.
defaultClass: true defaultClass: true
hostPath: /srv hostPath: /srv
# Toggle RBAC on and off
rbac:
enabled: true
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment