apiVersion: v1
kind: Secret
metadata:
labels:
k8s-app: kubernetes-dashboard
name: kubernetes-dashboard-certs
namespace: kube-system
type: Opaque
---
apiVersion: v1
kind: ServiceAccount
metadata:
labels:
k8s-app: kubernetes-dashboard
name: kubernetes-dashboard
namespace: kube-system
---
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: kubernetes-dashboard-minimal
namespace: kube-system
rules:
- apiGroups: [""]
resources: ["secrets"]
verbs: ["create"]
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["create"]
- apiGroups: [""]
resources: ["secrets"]
resourceNames: ["kubernetes-dashboard-key-holder", "kubernetes-dashboard-certs"]
verbs: ["get", "update", "delete"]
- apiGroups: [""]
resources: ["configmaps"]
resourceNames: ["kubernetes-dashboard-settings"]
verbs: ["get", "update"]
- apiGroups: [""]
resources: ["services"]
resourceNames: ["heapster"]
verbs: ["proxy"]
- apiGroups: [""]
resources: ["services/proxy"]
resourceNames: ["heapster", "http:heapster:", "https:heapster:"]
verbs: ["get"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: kubernetes-dashboard-minimal
namespace: kube-system
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: kubernetes-dashboard-minimal
subjects:
- kind: ServiceAccount
name: kubernetes-dashboard
namespace: kube-system
---
kind: Deployment
apiVersion: apps/v1beta2
metadata:
labels:
k8s-app: kubernetes-dashboard
name: kubernetes-dashboard
namespace: kube-system
spec:
replicas: 1
revisionHistoryLimit: 10
selector:
matchLabels:
k8s-app: kubernetes-dashboard
template:
metadata:
labels:
k8s-app: kubernetes-dashboard
spec:
containers:
- name: kubernetes-dashboard
image: k8s.gcr.io/kubernetes-dashboard-amd64:v1.10.0
ports:
- containerPort: 8443
protocol: TCP
args:
- --auto-generate-certificates
volumeMounts:
- name: kubernetes-dashboard-certs
mountPath: /certs
- mountPath: /tmp
name: tmp-volume
livenessProbe:
httpGet:
scheme: HTTPS
path: /
port: 8443
initialDelaySeconds: 30
timeoutSeconds: 30
volumes:
- name: kubernetes-dashboard-certs
secret:
secretName: kubernetes-dashboard-certs
- name: tmp-volume
emptyDir: {}
serviceAccountName: kubernetes-dashboard
tolerations:
- key: node-role.kubernetes.io/master
effect: NoSchedule
---
kind: Service
apiVersion: v1
metadata:
labels:
k8s-app: kubernetes-dashboard
name: kubernetes-dashboard
namespace: kube-system
spec:
ports:
- port: 443
targetPort: 8443
selector:
k8s-app: kubernetes-dashboard
kubernetes-dashboard.yaml
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請聯(lián)系作者
- 文/潘曉璐 我一進店門芳肌,熙熙樓的掌柜王于貴愁眉苦臉地迎上來,“玉大人肋层,你說我怎么就攤上這事亿笤。” “怎么了栋猖?”我有些...
- 文/不壞的土叔 我叫張陵净薛,是天一觀的道長。 經(jīng)常有香客問我蒲拉,道長肃拜,這世上最難降的妖魔是什么舱权? 我笑而不...
- 正文 為了忘掉前任望蜡,我火速辦了婚禮,結(jié)果婚禮上遮婶,老公的妹妹穿的比我還像新娘锦援。我一直安慰自己猛蔽,他們只是感情好,可當我...
- 文/花漫 我一把揭開白布。 她就那樣靜靜地躺著曼库,像睡著了一般区岗。 火紅的嫁衣襯著肌膚如雪。 梳的紋絲不亂的頭發(fā)上毁枯,一...
- 文/蒼蘭香墨 我猛地睜開眼,長吁一口氣:“原來是場噩夢啊……” “哼右锨!你這毒婦竟也來了括堤?” 一聲冷哼從身側(cè)響起,我...
- 正文 年R本政府宣布穷躁,位于F島的核電站,受9級特大地震影響因妇,放射性物質(zhì)發(fā)生泄漏问潭。R本人自食惡果不足惜,卻給世界環(huán)境...
- 文/蒙蒙 一沙峻、第九天 我趴在偏房一處隱蔽的房頂上張望睦授。 院中可真熱鬧,春花似錦摔寨、人聲如沸去枷。這莊子的主人今日做“春日...
- 文/蒼蘭香墨 我抬頭看了看天上的太陽删顶。三九已至竖螃,卻和暖如春,著一層夾襖步出監(jiān)牢的瞬間逗余,已是汗流浹背特咆。 一陣腳步聲響...
推薦閱讀更多精彩內(nèi)容
- 以書中的yaml-tomcat文件為例子: 一.創(chuàng)建tomcat-rc.yaml 大部分和mysql-rc.yam...
- 在閱讀本文前你需要: 有一個可以操作的 kubernetes 集群 熟悉 kubectl 命令旗闽,比如 get酬核,lo...
- 簡介: Kubernetes(k8s)是自動化容器操作的開源平臺,這些操作包括部署适室,調(diào)度和節(jié)點集群間擴展嫡意。如果你曾...
- 升級了新版本的Dashboard(這里使用的v1.8.3),使用了較為復(fù)雜的雙因子登錄捣辆,正確輸入用戶名和密碼之后還...
- 就是為神馬利用k8s創(chuàng)建pod時蔬螟,會一直遠程拉取鏡像? 1. 查看kubelet日志或者docker日志 2. 分...