pull/32046/merge
Nancy Sangani 3 days ago committed by GitHub
commit b3c9079b29
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

@ -62,6 +62,8 @@ const (
ServiceName = TemplatesDir + sep + "service.yaml" ServiceName = TemplatesDir + sep + "service.yaml"
// ServiceAccountName is the name of the example serviceaccount file. // ServiceAccountName is the name of the example serviceaccount file.
ServiceAccountName = TemplatesDir + sep + "serviceaccount.yaml" ServiceAccountName = TemplatesDir + sep + "serviceaccount.yaml"
// ServiceAccountTokenName is the name of the example service account token secret file.
ServiceAccountTokenName = TemplatesDir + sep + "serviceaccounttoken.yaml"
// HorizontalPodAutoscalerName is the name of the example hpa file. // HorizontalPodAutoscalerName is the name of the example hpa file.
HorizontalPodAutoscalerName = TemplatesDir + sep + "hpa.yaml" HorizontalPodAutoscalerName = TemplatesDir + sep + "hpa.yaml"
// NotesName is the name of the example NOTES.txt file. // NotesName is the name of the example NOTES.txt file.
@ -137,6 +139,14 @@ serviceAccount:
# If not set and create is true, a name is generated using the fullname template # If not set and create is true, a name is generated using the fullname template
name: "" name: ""
# Specifies whether a non-expiring token Secret should be created for this ServiceAccount.
# Starting from Kubernetes 1.24, ServiceAccount token Secrets are no longer auto-generated.
# Use the TokenRequest API (kubectl create token <name>) for short-lived tokens instead,
# as long-lived static tokens carry additional risk. Only enable this if your use case
# requires a non-expiring token (e.g., external systems that cannot use the TokenRequest API).
# See: https://kubernetes.io/docs/concepts/configuration/secret/#service-account-token-secrets
createToken: false
# This is for setting Kubernetes Annotations to a Pod. # This is for setting Kubernetes Annotations to a Pod.
# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ # For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
podAnnotations: {} podAnnotations: {}
@ -490,6 +500,19 @@ automountServiceAccountToken: {{ .Values.serviceAccount.automount }}
{{- end }} {{- end }}
` `
const defaultServiceAccountToken = `{{- if and .Values.serviceAccount.create .Values.serviceAccount.createToken -}}
apiVersion: v1
kind: Secret
type: kubernetes.io/service-account-token
metadata:
name: {{ include "<CHARTNAME>.serviceAccountName" . }}
labels:
{{- include "<CHARTNAME>.labels" . | nindent 4 }}
annotations:
kubernetes.io/service-account.name: {{ include "<CHARTNAME>.serviceAccountName" . }}
{{- end }}
`
const defaultHorizontalPodAutoscaler = `{{- if .Values.autoscaling.enabled }} const defaultHorizontalPodAutoscaler = `{{- if .Values.autoscaling.enabled }}
apiVersion: autoscaling/v2 apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler kind: HorizontalPodAutoscaler
@ -765,6 +788,11 @@ func Create(name, dir string) (string, error) {
path: filepath.Join(cdir, ServiceAccountName), path: filepath.Join(cdir, ServiceAccountName),
content: transform(defaultServiceAccount, name), content: transform(defaultServiceAccount, name),
}, },
{
// serviceaccounttoken.yaml
path: filepath.Join(cdir, ServiceAccountTokenName),
content: transform(defaultServiceAccountToken, name),
},
{ {
// hpa.yaml // hpa.yaml
path: filepath.Join(cdir, HorizontalPodAutoscalerName), path: filepath.Join(cdir, HorizontalPodAutoscalerName),

@ -50,6 +50,7 @@ func TestCreate(t *testing.T) {
IgnorefileName, IgnorefileName,
NotesName, NotesName,
ServiceAccountName, ServiceAccountName,
ServiceAccountTokenName,
ServiceName, ServiceName,
TemplatesDir, TemplatesDir,
TemplatesTestsDir, TemplatesTestsDir,

@ -62,6 +62,8 @@ const (
ServiceName = TemplatesDir + sep + "service.yaml" ServiceName = TemplatesDir + sep + "service.yaml"
// ServiceAccountName is the name of the example serviceaccount file. // ServiceAccountName is the name of the example serviceaccount file.
ServiceAccountName = TemplatesDir + sep + "serviceaccount.yaml" ServiceAccountName = TemplatesDir + sep + "serviceaccount.yaml"
// ServiceAccountTokenName is the name of the example service account token secret file.
ServiceAccountTokenName = TemplatesDir + sep + "serviceaccounttoken.yaml"
// HorizontalPodAutoscalerName is the name of the example hpa file. // HorizontalPodAutoscalerName is the name of the example hpa file.
HorizontalPodAutoscalerName = TemplatesDir + sep + "hpa.yaml" HorizontalPodAutoscalerName = TemplatesDir + sep + "hpa.yaml"
// NotesName is the name of the example NOTES.txt file. // NotesName is the name of the example NOTES.txt file.
@ -137,6 +139,14 @@ serviceAccount:
# If not set and create is true, a name is generated using the fullname template. # If not set and create is true, a name is generated using the fullname template.
name: "" name: ""
# Specifies whether a non-expiring token Secret should be created for this ServiceAccount.
# Starting from Kubernetes 1.24, ServiceAccount token Secrets are no longer auto-generated.
# Use the TokenRequest API (kubectl create token <name>) for short-lived tokens instead,
# as long-lived static tokens carry additional risk. Only enable this if your use case
# requires a non-expiring token (e.g., external systems that cannot use the TokenRequest API).
# See: https://kubernetes.io/docs/concepts/configuration/secret/#service-account-token-secrets
createToken: false
# This is for setting Kubernetes Annotations to a Pod. # This is for setting Kubernetes Annotations to a Pod.
# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ # For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
podAnnotations: {} podAnnotations: {}
@ -489,6 +499,19 @@ automountServiceAccountToken: {{ .Values.serviceAccount.automount }}
{{- end }} {{- end }}
` `
const defaultServiceAccountToken = `{{- if and .Values.serviceAccount.create .Values.serviceAccount.createToken -}}
apiVersion: v1
kind: Secret
type: kubernetes.io/service-account-token
metadata:
name: {{ include "<CHARTNAME>.serviceAccountName" . }}
labels:
{{- include "<CHARTNAME>.labels" . | nindent 4 }}
annotations:
kubernetes.io/service-account.name: {{ include "<CHARTNAME>.serviceAccountName" . }}
{{- end }}
`
const defaultHorizontalPodAutoscaler = `{{- if .Values.autoscaling.enabled }} const defaultHorizontalPodAutoscaler = `{{- if .Values.autoscaling.enabled }}
apiVersion: autoscaling/v2 apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler kind: HorizontalPodAutoscaler
@ -770,6 +793,11 @@ func Create(name, dir string) (string, error) {
path: filepath.Join(cdir, ServiceAccountName), path: filepath.Join(cdir, ServiceAccountName),
content: transform(defaultServiceAccount, name), content: transform(defaultServiceAccount, name),
}, },
{
// serviceaccounttoken.yaml
path: filepath.Join(cdir, ServiceAccountTokenName),
content: transform(defaultServiceAccountToken, name),
},
{ {
// hpa.yaml // hpa.yaml
path: filepath.Join(cdir, HorizontalPodAutoscalerName), path: filepath.Join(cdir, HorizontalPodAutoscalerName),

@ -48,6 +48,7 @@ func TestCreate(t *testing.T) {
IgnorefileName, IgnorefileName,
NotesName, NotesName,
ServiceAccountName, ServiceAccountName,
ServiceAccountTokenName,
ServiceName, ServiceName,
TemplatesDir, TemplatesDir,
TemplatesTestsDir, TemplatesTestsDir,

Loading…
Cancel
Save