Files
content-ingestion-agent/k8s/deployment.yaml

69 lines
1.9 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: content-ingestion-agent
labels:
app.kubernetes.io/name: content-ingestion-agent
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: content-ingestion-agent
template:
metadata:
labels:
app.kubernetes.io/name: content-ingestion-agent
spec:
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: agent
image: content-ingestion-agent:latest
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 8080
envFrom:
- configMapRef:
name: content-ingestion-agent-config
- secretRef:
name: content-ingestion-agent-secrets
env:
- name: GITHUB_TOKEN
valueFrom:
secretKeyRef:
name: content-ingestion-agent-secrets
key: github-token
- name: SHAREPOINT_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: content-ingestion-agent-secrets
key: sharepoint-client-secret
readinessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 15
periodSeconds: 20
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: [ALL]