Last active
September 14, 2019 22:51
-
-
Save kondor6c/7a3b5c74a04d9ebce180145c0535b06f to your computer and use it in GitHub Desktop.
Since I am getting a 403 currently, I am trying to mirror the content that was available
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
apiVersion: v1 | |
kind: ServiceAccount | |
metadata: | |
name: coredns | |
namespace: kube-system | |
--- | |
apiVersion: rbac.authorization.k8s.io/v1beta1 | |
kind: ClusterRole | |
metadata: | |
labels: | |
kubernetes.io/bootstrapping: rbac-defaults | |
name: system:coredns | |
rules: | |
- apiGroups: | |
- "" | |
resources: | |
- endpoints | |
- services | |
- pods | |
- namespaces | |
verbs: | |
- list | |
- watch | |
--- | |
apiVersion: rbac.authorization.k8s.io/v1beta1 | |
kind: ClusterRoleBinding | |
metadata: | |
annotations: | |
rbac.authorization.kubernetes.io/autoupdate: "true" | |
labels: | |
kubernetes.io/bootstrapping: rbac-defaults | |
name: system:coredns | |
roleRef: | |
apiGroup: rbac.authorization.k8s.io | |
kind: ClusterRole | |
name: system:coredns | |
subjects: | |
- kind: ServiceAccount | |
name: coredns | |
namespace: kube-system | |
--- | |
apiVersion: v1 | |
kind: ConfigMap | |
metadata: | |
name: coredns | |
namespace: kube-system | |
data: | |
Corefile: | | |
.:53 { | |
errors | |
health | |
kubernetes cluster.local in-addr.arpa ip6.arpa { | |
pods insecure | |
upstream | |
fallthrough in-addr.arpa ip6.arpa | |
} | |
prometheus :9153 | |
proxy . /etc/resolv.conf | |
cache 30 | |
loop | |
reload | |
loadbalance | |
} | |
--- | |
apiVersion: extensions/v1beta1 | |
kind: Deployment | |
metadata: | |
name: coredns | |
namespace: kube-system | |
labels: | |
k8s-app: kube-dns | |
kubernetes.io/name: "CoreDNS" | |
spec: | |
replicas: 2 | |
strategy: | |
type: RollingUpdate | |
rollingUpdate: | |
maxUnavailable: 1 | |
selector: | |
matchLabels: | |
k8s-app: kube-dns | |
template: | |
metadata: | |
labels: | |
k8s-app: kube-dns | |
spec: | |
serviceAccountName: coredns | |
tolerations: | |
- key: node-role.kubernetes.io/master | |
effect: NoSchedule | |
- key: "CriticalAddonsOnly" | |
operator: "Exists" | |
containers: | |
- name: coredns | |
image: coredns/coredns:1.2.2 | |
imagePullPolicy: IfNotPresent | |
resources: | |
limits: | |
memory: 170Mi | |
requests: | |
cpu: 100m | |
memory: 70Mi | |
args: [ "-conf", "/etc/coredns/Corefile" ] | |
volumeMounts: | |
- name: config-volume | |
mountPath: /etc/coredns | |
readOnly: true | |
ports: | |
- containerPort: 53 | |
name: dns | |
protocol: UDP | |
- containerPort: 53 | |
name: dns-tcp | |
protocol: TCP | |
- containerPort: 9153 | |
name: metrics | |
protocol: TCP | |
securityContext: | |
allowPrivilegeEscalation: false | |
capabilities: | |
add: | |
- NET_BIND_SERVICE | |
drop: | |
- all | |
readOnlyRootFilesystem: true | |
livenessProbe: | |
httpGet: | |
path: /health | |
port: 8080 | |
scheme: HTTP | |
initialDelaySeconds: 60 | |
timeoutSeconds: 5 | |
successThreshold: 1 | |
failureThreshold: 5 | |
dnsPolicy: Default | |
volumes: | |
- name: config-volume | |
configMap: | |
name: coredns | |
items: | |
- key: Corefile | |
path: Corefile | |
--- | |
apiVersion: v1 | |
kind: Service | |
metadata: | |
name: kube-dns | |
namespace: kube-system | |
annotations: | |
prometheus.io/port: "9153" | |
prometheus.io/scrape: "true" | |
labels: | |
k8s-app: kube-dns | |
kubernetes.io/cluster-service: "true" | |
kubernetes.io/name: "CoreDNS" | |
spec: | |
selector: | |
k8s-app: kube-dns | |
clusterIP: 10.32.0.10 | |
ports: | |
- name: dns | |
port: 53 | |
protocol: UDP | |
- name: dns-tcp | |
port: 53 | |
protocol: TCP |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment