manifests/drone/drone-runner.yaml

74 lines
1.5 KiB
YAML

# Copied from https://docs.drone.io/runner/kubernetes/installation/
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
namespace: drone
name: drone-runner
rules:
- apiGroups:
- ""
resources:
- secrets
verbs:
- create
- delete
- apiGroups:
- ""
resources:
- pods
- pods/log
verbs:
- get
- create
- delete
- list
- watch
- update
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: drone-runner
namespace: drone
subjects:
- kind: ServiceAccount
name: default
namespace: drone
roleRef:
kind: Role
name: drone-runner
apiGroup: rbac.authorization.k8s.io
---
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: drone
name: drone-runner
labels:
app.kubernetes.io/name: drone-runner
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: drone-runner
template:
metadata:
labels:
app.kubernetes.io/name: drone-runner
spec:
containers:
- name: drone-runner
image: drone/drone-runner-kube:latest
ports:
- containerPort: 3000
env:
- name: DRONE_RPC_HOST
valueFrom:
configMapKeyRef: {"name": "drone-server-config", "key": "DRONE_SERVER_HOST"}
- name: DRONE_RPC_PROTO
valueFrom:
configMapKeyRef: {"name": "drone-server-config", "key": "DRONE_SERVER_PROTO"}
- name: DRONE_RPC_SECRET
valueFrom:
secretKeyRef: {"name": "drone-server-secret", "key": "DRONE_RPC_SECRET"}