Advertisement
tatdat171

twistlock-denfender.yaml

Dec 12th, 2017
496
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
YAML 3.67 KB | None | 0 0
  1. apiVersion: extensions/v1beta1
  2. kind: DaemonSet
  3. metadata:
  4.   creationTimestamp: 2017-12-04T10:29:11Z
  5.   generation: 1
  6.   labels:
  7.     app: twistlock-defender
  8.   name: twistlock-defender-ds
  9.   namespace: twistlock
  10.   resourceVersion: "3397"
  11.   selfLink: /apis/extensions/v1beta1/namespaces/twistlock/daemonsets/twistlock-defender-ds
  12.   uid: f79387ae-d8dd-11e7-8227-42010a8a006c
  13. spec:
  14.   revisionHistoryLimit: 10
  15.   selector:
  16.     matchLabels:
  17.       app: twistlock-defender
  18.   template:
  19.     metadata:
  20.       creationTimestamp: null
  21.       labels:
  22.         app: twistlock-defender
  23.     spec:
  24.       containers:
  25.       - env:
  26.         - name: WS_ADDRESS
  27.           value: wss://35.197.52.108:8084
  28.         - name: DEFENDER_TYPE
  29.           value: daemonset
  30.         - name: DEFENDER_LISTENER_TYPE
  31.           value: unix
  32.         - name: LOG_PROD
  33.           value: "true"
  34.         - name: SYSLOG_ENABLED
  35.           value: "true"
  36.         - name: NETWORK_SCAN_ENABLED
  37.           value: "true"
  38.         - name: PROCESS_SCAN_ENABLED
  39.           value: "true"
  40.         - name: FILESYSTEM_SCAN_ENABLED
  41.           value: "true"
  42.         - name: SYSCALL_AUDIT_ENABLED
  43.           value: "true"
  44.         - name: LOCAL_DOCKER_AUDIT_ENABLED
  45.           value: "true"
  46.         - name: SYSTEMD_ENABLED
  47.           value: "false"
  48.         - name: DOCKER_CLIENT_ADDRESS
  49.           value: /var/run/docker.sock
  50.         - name: HTTP_PROXY
  51.         - name: HTTPS_PROXY
  52.         - name: NO_PROXY
  53.         image: us.gcr.io/flexdh-devops/twistlock/private:defender_2_2_100
  54.         imagePullPolicy: IfNotPresent
  55.         name: twistlock-defender-2-2-100
  56.         resources:
  57.           limits:
  58.             memory: 512M
  59.           requests:
  60.             cpu: 256m
  61.         securityContext:
  62.           capabilities:
  63.             add:
  64.            - NET_ADMIN
  65.             - SYS_ADMIN
  66.             - SYS_PTRACE
  67.             - AUDIT_CONTROL
  68.           privileged: true
  69.           readOnlyRootFilesystem: true
  70.         terminationMessagePath: /dev/termination-log
  71.         terminationMessagePolicy: File
  72.         volumeMounts:
  73.         - mountPath: /var/lib/twistlock/certificates
  74.           name: certificates
  75.         - mountPath: /var/lib/twistlock
  76.           name: data-folder
  77.         - mountPath: /var/run
  78.           name: docker-sock-folder
  79.         - mountPath: /etc/passwd
  80.           name: passwd
  81.           readOnly: true
  82.         - mountPath: /var/run/docker/netns
  83.           name: docker-netns
  84.           readOnly: true
  85.         - mountPath: /dev/log
  86.           name: syslog-socket
  87.         - mountPath: /run
  88.           name: iptables-lock
  89.       dnsPolicy: ClusterFirst
  90.       hostNetwork: true
  91.       hostPID: true
  92.       restartPolicy: Always
  93.       schedulerName: default-scheduler
  94.       securityContext: {}
  95.       serviceAccount: twistlock-service
  96.       serviceAccountName: twistlock-service
  97.       terminationGracePeriodSeconds: 30
  98.       volumes:
  99.       - name: certificates
  100.         secret:
  101.           defaultMode: 256
  102.           secretName: twistlock-secrets
  103.       - hostPath:
  104.           path: /dev/log
  105.         name: syslog-socket
  106.       - hostPath:
  107.           path: /var/lib/twistlock
  108.         name: data-folder
  109.       - hostPath:
  110.           path: /var/run/docker/netns
  111.         name: docker-netns
  112.       - hostPath:
  113.           path: /etc/passwd
  114.         name: passwd
  115.       - hostPath:
  116.           path: /var/run
  117.         name: docker-sock-folder
  118.       - hostPath:
  119.           path: /run
  120.         name: iptables-lock
  121.   templateGeneration: 1
  122.   updateStrategy:
  123.     type: OnDelete
  124. status:
  125.   currentNumberScheduled: 3
  126.   desiredNumberScheduled: 3
  127.   numberAvailable: 3
  128.   numberMisscheduled: 0
  129.   numberReady: 3
  130.   observedGeneration: 1
  131.   updatedNumberScheduled: 3
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement