apiVersion: apps/v1 kind: Deployment metadata: name: flex-auth-tenant-engine namespace: flex-auth spec: replicas: 1 selector: matchLabels: app.kubernetes.io/name: flex-auth-tenant-engine template: metadata: labels: app.kubernetes.io/name: flex-auth-tenant-engine spec: automountServiceAccountToken: false containers: - args: - serve - --addr - 0.0.0.0:8080 - --registry - /opt/flex-auth/examples/tenant-engine/registry_snapshot.json - --policy - /opt/flex-auth/examples/tenant-engine/policy_package.md image: forgejo.coulomb.social/coulomb/flex-auth@sha256:1bf060e61122693ce98359c167cc5fe8bdafc84e097e090eaa71af94d0f27cbc livenessProbe: httpGet: path: /healthz port: http periodSeconds: 20 name: flex-auth ports: - containerPort: 8080 name: http readinessProbe: httpGet: path: /healthz port: http periodSeconds: 5 resources: limits: cpu: 300m memory: 192Mi requests: cpu: 25m memory: 32Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: true securityContext: runAsNonRoot: true seccompProfile: type: RuntimeDefault --- apiVersion: v1 kind: Service metadata: name: flex-auth-tenant-engine namespace: flex-auth spec: ports: - name: http port: 8080 targetPort: http selector: app.kubernetes.io/name: flex-auth-tenant-engine --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: flex-auth-tenant-engine namespace: flex-auth spec: egress: [] ingress: - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: tenant-engine podSelector: matchLabels: app.kubernetes.io/name: tenant-engine ports: - port: 8080 protocol: TCP podSelector: matchLabels: app.kubernetes.io/name: flex-auth-tenant-engine policyTypes: - Ingress - Egress