From 20d53d388f715f3d9e08d038ed1eebbdb06d5ed8 Mon Sep 17 00:00:00 2001 From: Vadim Rutkovsky Date: Mon, 1 Jul 2024 18:20:35 +0200 Subject: [PATCH] bootkube: create openshift-config / openshift-config-managed namespaces This should make bootstrap cleaner, as this namespace is created by CVO late in bootstrap phase, but can be created early by cluster-bootstrap --- .../manifests/00_openshift-config-managed-ns.yaml | 12 ++++++++++++ .../bootkube/manifests/00_openshift-config-ns.yaml | 12 ++++++++++++ 2 files changed, 24 insertions(+) create mode 100644 bindata/bootkube/manifests/00_openshift-config-managed-ns.yaml create mode 100644 bindata/bootkube/manifests/00_openshift-config-ns.yaml diff --git a/bindata/bootkube/manifests/00_openshift-config-managed-ns.yaml b/bindata/bootkube/manifests/00_openshift-config-managed-ns.yaml new file mode 100644 index 0000000000..a978e790a7 --- /dev/null +++ b/bindata/bootkube/manifests/00_openshift-config-managed-ns.yaml @@ -0,0 +1,12 @@ +apiVersion: v1 +kind: Namespace +metadata: + annotations: + openshift.io/node-selector: "" + workload.openshift.io/allowed: "management" + labels: + openshift.io/run-level: "0" + pod-security.kubernetes.io/audit: restricted + pod-security.kubernetes.io/enforce: restricted + pod-security.kubernetes.io/warn: restricted + name: openshift-config-managed diff --git a/bindata/bootkube/manifests/00_openshift-config-ns.yaml b/bindata/bootkube/manifests/00_openshift-config-ns.yaml new file mode 100644 index 0000000000..383ac3d759 --- /dev/null +++ b/bindata/bootkube/manifests/00_openshift-config-ns.yaml @@ -0,0 +1,12 @@ +apiVersion: v1 +kind: Namespace +metadata: + annotations: + openshift.io/node-selector: "" + workload.openshift.io/allowed: "management" + labels: + openshift.io/run-level: "0" + pod-security.kubernetes.io/audit: restricted + pod-security.kubernetes.io/enforce: restricted + pod-security.kubernetes.io/warn: restricted + name: openshift-config