Added annotations for the service account (#18391)

Signed-off-by: Stijn De Haes <stijndehaes@gmail.com>
This commit is contained in:
Stijn De Haes
2019-12-01 22:29:03 -08:00
committed by Kubernetes Prow Robot
parent 62011e8207
commit 1200cc496d
4 changed files with 38 additions and 30 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
apiVersion: v1
name: fluentd-cloudwatch
version: 0.11.1
version: 0.12.0
appVersion: v1.7.3-debian-cloudwatch-1.0
description: A Fluentd CloudWatch Helm chart for Kubernetes.
home: https://www.fluentd.org/
+30 -29
View File
@@ -46,35 +46,36 @@ The command removes all the Kubernetes components associated with the chart and
The following table lists the configurable parameters of the Fluentd Cloudwatch chart and their default values.
| Parameter | Description | Default |
| ---------------------------- | ------------------------------------------------------------------------------- | --------------------------------------|
| `image.repository` | Image repository | `fluent/fluentd-kubernetes-daemonset` |
| `image.tag` | Image tag | `v1.3.3-debian-cloudwatch-1.0` |
| `image.pullPolicy` | Image pull policy | `IfNotPresent` |
| `resources.limits.cpu` | CPU limit | `100m` |
| `resources.limits.memory` | Memory limit | `200Mi` |
| `resources.requests.cpu` | CPU request | `100m` |
| `resources.requests.memory` | Memory request | `200Mi` |
| `hostNetwork` | Host network | `false` |
| `podAnnotations` | Annotations | `{}` |
| `podSecurityContext` | Security Context | `{}` |
| `awsRegion` | AWS Cloudwatch region | `us-east-1` |
| `awsRole` | AWS IAM Role To Use | `nil` |
| `awsAccessKeyId` | AWS Access Key Id of a AWS user with a policy to access Cloudwatch | `nil` |
| `awsSecretAccessKey` | AWS Secret Access Key of a AWS user with a policy to access Cloudwatch | `nil` |
| `data` | Fluentd ConfigMap values. The main configuration is defined under `fluent.conf` | `example configuration` |
| `logGroupName` | AWS Cloudwatch log group | `kubernetes` |
| `rbac.create` | If true, create & use RBAC resources | `false` |
| `rbac.serviceAccountName` | existing ServiceAccount to use (ignored if rbac.create=true) | `default` |
| `rbac.pspEnabled` | PodSecuritypolicy | `false` |
| `tolerations` | Add tolerations | `[]` |
| `extraVars` | Add pod environment variables (must be specified as a single line object) | `[]` |
| `updateStrategy` | Define daemonset update strategy | `OnDelete` |
| `nodeSelector` | Node labels for pod assignment | `{}` |
| `affinity` | Node affinity for pod assignment | `{}` |
| `priorityClassName` | Set priority class for daemon set | `nil` |
| `busybox.repository` | Image repository of busybox | `busybox` |
| `busybox.tag` | Image tag of busybox | `1.31.0` |
| Parameter | Description | Default |
| ------------------------------- | ------------------------------------------------------------------------------- | --------------------------------------|
| `image.repository` | Image repository | `fluent/fluentd-kubernetes-daemonset` |
| `image.tag` | Image tag | `v1.3.3-debian-cloudwatch-1.0` |
| `image.pullPolicy` | Image pull policy | `IfNotPresent` |
| `resources.limits.cpu` | CPU limit | `100m` |
| `resources.limits.memory` | Memory limit | `200Mi` |
| `resources.requests.cpu` | CPU request | `100m` |
| `resources.requests.memory` | Memory request | `200Mi` |
| `hostNetwork` | Host network | `false` |
| `podAnnotations` | Annotations | `{}` |
| `podSecurityContext` | Security Context | `{}` |
| `awsRegion` | AWS Cloudwatch region | `us-east-1` |
| `awsRole` | AWS IAM Role To Use | `nil` |
| `awsAccessKeyId` | AWS Access Key Id of a AWS user with a policy to access Cloudwatch | `nil` |
| `awsSecretAccessKey` | AWS Secret Access Key of a AWS user with a policy to access Cloudwatch | `nil` |
| `data` | Fluentd ConfigMap values. The main configuration is defined under `fluent.conf` | `example configuration` |
| `logGroupName` | AWS Cloudwatch log group | `kubernetes` |
| `rbac.create` | If true, create & use RBAC resources | `false` |
| `rbac.serviceAccountName` | existing ServiceAccount to use (ignored if rbac.create=true) | `default` |
| `rbac.pspEnabled` | PodSecuritypolicy | `false` |
| `rbac.serviceAccountAnnotations`| Additional Service Account annotations | `{}` |
| `tolerations` | Add tolerations | `[]` |
| `extraVars` | Add pod environment variables (must be specified as a single line object) | `[]` |
| `updateStrategy` | Define daemonset update strategy | `OnDelete` |
| `nodeSelector` | Node labels for pod assignment | `{}` |
| `affinity` | Node affinity for pod assignment | `{}` |
| `priorityClassName` | Set priority class for daemon set | `nil` |
| `busybox.repository` | Image repository of busybox | `busybox` |
| `busybox.tag` | Image tag of busybox | `1.31.0` |
If using fluentd-kubernetes-daemonset v0.12.43-cloudwatch, the container runs as user fluentd. To be able to write pos files to the host system, you'll need to run fluentd as root. Add the following extraVars value to run as root.
@@ -9,3 +9,7 @@ metadata:
release: "{{ .Release.Name }}"
heritage: "{{ .Release.Service }}"
{{- end }}
{{- if .Values.rbac.serviceAccountAnnotations }}
annotations:
{{ toYaml .Values.rbac.serviceAccountAnnotations | nindent 4 }}
{{- end }}
+3
View File
@@ -68,6 +68,9 @@ rbac:
## Ignored if rbac.create is true
serviceAccountName: default
## Annotations for the Service Account
##
serviceAccountAnnotations: {}
# Add extra environment variables if specified (must be specified as a single line object and be quoted)
extraVars: []
# - "{ name: NODE_NAME, valueFrom: { fieldRef: { fieldPath: spec.nodeName } } }"