apiVersion: apps/v1beta1 kind: Deployment metadata: creationTimestamp: null name: inject-test-terminus spec: selector: matchLabels: app: inject-test-terminus strategy: {} template: metadata: annotations: config.linkerd.io/admin-port: "789" config.linkerd.io/control-port: "123" config.linkerd.io/disable-identity: "true" config.linkerd.io/disable-tap: "true" config.linkerd.io/enable-external-profiles: "true" config.linkerd.io/image-pull-policy: Never config.linkerd.io/inbound-port: "678" config.linkerd.io/init-image: init-image config.linkerd.io/outbound-port: "890" config.linkerd.io/proxy-cpu-limit: 20m config.linkerd.io/proxy-cpu-request: 10m config.linkerd.io/proxy-image: proxy-image config.linkerd.io/proxy-log-level: warn config.linkerd.io/proxy-memory-limit: 20Mi config.linkerd.io/proxy-memory-request: 10Mi config.linkerd.io/proxy-uid: "1337" config.linkerd.io/proxy-version: proxy-version config.linkerd.io/skip-inbound-ports: 234,345 config.linkerd.io/skip-outbound-ports: 456,567 linkerd.io/created-by: fake # this gets removed during testing linkerd.io/identity-mode: disabled linkerd.io/proxy-version: fake # this gets removed during testing creationTimestamp: null labels: app: inject-test-terminus linkerd.io/control-plane-ns: fake-ns linkerd.io/proxy-deployment: inject-test-terminus spec: containers: - args: - terminus - --grpc-server-port - "9090" - --response-text - BANANA image: buoyantio/bb:v0.0.5 name: bb-terminus ports: - containerPort: 9090 resources: {} - env: - name: LINKERD2_PROXY_LOG value: warn - name: LINKERD2_PROXY_DESTINATION_SVC_ADDR value: linkerd-destination.fake-ns.svc.cluster.local:8086 - name: LINKERD2_PROXY_CONTROL_LISTEN_ADDR value: 0.0.0.0:123 - name: LINKERD2_PROXY_ADMIN_LISTEN_ADDR value: 0.0.0.0:789 - name: LINKERD2_PROXY_OUTBOUND_LISTEN_ADDR value: 127.0.0.1:890 - name: LINKERD2_PROXY_INBOUND_LISTEN_ADDR value: 0.0.0.0:678 - name: LINKERD2_PROXY_DESTINATION_PROFILE_SUFFIXES value: . - name: LINKERD2_PROXY_INBOUND_ACCEPT_KEEPALIVE value: 10000ms - name: LINKERD2_PROXY_OUTBOUND_CONNECT_KEEPALIVE value: 10000ms - name: _pod_ns valueFrom: fieldRef: fieldPath: metadata.namespace - name: LINKERD2_PROXY_DESTINATION_CONTEXT value: ns:$(_pod_ns) - name: LINKERD2_PROXY_TAP_DISABLED value: "true" - name: LINKERD2_PROXY_IDENTITY_DISABLED value: disabled image: proxy-image:proxy-version imagePullPolicy: Never livenessProbe: httpGet: path: /metrics port: 789 initialDelaySeconds: 10 name: linkerd-proxy ports: - containerPort: 678 name: linkerd-proxy - containerPort: 789 name: linkerd-admin readinessProbe: httpGet: path: /ready port: 789 initialDelaySeconds: 2 resources: limits: cpu: 20m memory: 20Mi requests: cpu: 10m memory: 10Mi securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true runAsUser: 1337 terminationMessagePolicy: FallbackToLogsOnError initContainers: - args: - --incoming-proxy-port - "678" - --outgoing-proxy-port - "890" - --proxy-uid - "1337" - --inbound-ports-to-ignore - 234,345,123,789 - --outbound-ports-to-ignore - 456,567 image: init-image:fake # this is replaced during testing imagePullPolicy: Never name: linkerd-init resources: limits: cpu: 100m memory: 50Mi requests: cpu: 10m memory: 10Mi securityContext: allowPrivilegeEscalation: false capabilities: add: - NET_ADMIN privileged: false readOnlyRootFilesystem: true runAsNonRoot: false runAsUser: 0 terminationMessagePolicy: FallbackToLogsOnError status: {} ---