apiVersion: apps/v1 kind: Deployment metadata: name: identity-provisioner namespace: sso labels: &labels app.kubernetes.io/name: identity-provisioner app.kubernetes.io/component: directory-lifecycle app.kubernetes.io/part-of: net-kingdom-sso-mfa spec: replicas: 1 selector: matchLabels: {app.kubernetes.io/name: identity-provisioner} template: metadata: labels: *labels spec: automountServiceAccountToken: false securityContext: runAsNonRoot: true runAsUser: 10001 runAsGroup: 10001 seccompProfile: {type: RuntimeDefault} containers: - name: provisioner image: identity-provisioner:dbf7cfd imagePullPolicy: Never ports: [{name: http, containerPort: 8080}] env: - {name: LLDAP_URL, value: "http://lldap.sso.svc.cluster.local:17170"} - name: LLDAP_ADMIN_PASSWORD valueFrom: secretKeyRef: {name: lldap-secrets, key: LLDAP_LDAP_USER_PASS} - name: PROVISIONER_SERVICE_TOKEN valueFrom: secretKeyRef: {name: identity-provisioner-token, key: token} securityContext: allowPrivilegeEscalation: false capabilities: {drop: ["ALL"]} readOnlyRootFilesystem: true resources: requests: {cpu: 25m, memory: 32Mi} limits: {cpu: 250m, memory: 128Mi} readinessProbe: httpGet: {path: /healthz, port: http} periodSeconds: 10 livenessProbe: httpGet: {path: /healthz, port: http} periodSeconds: 20 --- apiVersion: v1 kind: Service metadata: name: identity-provisioner namespace: sso spec: selector: {app.kubernetes.io/name: identity-provisioner} ports: [{name: http, port: 8080, targetPort: http}] --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: identity-provisioner namespace: sso spec: podSelector: matchLabels: {app.kubernetes.io/name: identity-provisioner} policyTypes: [Ingress, Egress] ingress: - from: - namespaceSelector: matchLabels: {kubernetes.io/metadata.name: user-engine} podSelector: matchLabels: {app.kubernetes.io/name: user-engine} ports: [{protocol: TCP, port: 8080}] egress: - to: - podSelector: matchLabels: {app.kubernetes.io/name: lldap} ports: [{protocol: TCP, port: 17170}] - to: - namespaceSelector: matchLabels: {kubernetes.io/metadata.name: kube-system} ports: [{protocol: UDP, port: 53}, {protocol: TCP, port: 53}] --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-identity-provisioner-to-lldap namespace: sso spec: podSelector: matchLabels: {app.kubernetes.io/name: lldap} policyTypes: [Ingress] ingress: - from: - podSelector: matchLabels: {app.kubernetes.io/name: identity-provisioner} ports: [{protocol: TCP, port: 17170}]