Skip to content

Commit

Permalink
Allow tailscale to write pod events
Browse files Browse the repository at this point in the history
  • Loading branch information
zegl committed Feb 6, 2025
1 parent 98fb257 commit 5dd8bc7
Show file tree
Hide file tree
Showing 9 changed files with 68 additions and 1 deletion.
8 changes: 8 additions & 0 deletions kubernetes/ingress/caddy-argocd.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,14 @@ spec:
value: --hostname=argocd
- name: TS_SOCKET
value: /var/run/tailscale/tailscaled.sock
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
capabilities:
add:
Expand Down
8 changes: 8 additions & 0 deletions kubernetes/ingress/caddy-grafana.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,14 @@ spec:
value: --hostname=grafana
- name: TS_SOCKET
value: /var/run/tailscale/tailscaled.sock
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
capabilities:
add:
Expand Down
8 changes: 8 additions & 0 deletions kubernetes/ingress/caddy-immich.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,14 @@ spec:
value: --hostname=immich
- name: TS_SOCKET
value: /var/run/tailscale/tailscaled.sock
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
capabilities:
add:
Expand Down
8 changes: 8 additions & 0 deletions kubernetes/ingress/caddy-meta.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -102,6 +102,14 @@ spec:
value: --hostname=meta
- name: TS_SOCKET
value: /var/run/tailscale/tailscaled.sock
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
capabilities:
add:
Expand Down
8 changes: 8 additions & 0 deletions kubernetes/ingress/caddy-prometheus.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,14 @@ spec:
value: --hostname=prometheus
- name: TS_SOCKET
value: /var/run/tailscale/tailscaled.sock
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
capabilities:
add:
Expand Down
10 changes: 9 additions & 1 deletion kubernetes/ingress/caddy-registry.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,14 @@ spec:
value: --hostname=registry
- name: TS_SOCKET
value: /var/run/tailscale/tailscaled.sock
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
capabilities:
add:
Expand Down Expand Up @@ -148,4 +156,4 @@ spec:
ports:
- protocol: TCP
port: 443
targetPort: 443
targetPort: 443
8 changes: 8 additions & 0 deletions kubernetes/ingress/caddy-sonos.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,14 @@ spec:
value: --hostname=sonos
- name: TS_SOCKET
value: /var/run/tailscale/tailscaled.sock
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
capabilities:
add:
Expand Down
8 changes: 8 additions & 0 deletions kubernetes/ingress/caddy-zigbee2mqtt.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,14 @@ spec:
value: --hostname=zigbee2mqtt
- name: TS_SOCKET
value: /var/run/tailscale/tailscaled.sock
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
capabilities:
add:
Expand Down
3 changes: 3 additions & 0 deletions kubernetes/ingress/tailscale-rbac.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,9 @@ rules:
]
resources: ["secrets"]
verbs: ["get", "update", "patch"]
- apiGroups: [""]
resources: ["events"]
verbs: ["get", "update", "patch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
Expand Down

0 comments on commit 5dd8bc7

Please sign in to comment.