Skip to content

Commit 567046c

Browse files
committed
fix: Use BoundServceAccountTokenVolume dy default
1 parent 604d31c commit 567046c

File tree

1 file changed

+0
-22
lines changed

1 file changed

+0
-22
lines changed

manifests/0000_25_kube-controller-manager-operator_06_deployment.yaml

Lines changed: 0 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,6 @@ spec:
2929
runAsUser: 65534
3030
seccompProfile:
3131
type: RuntimeDefault
32-
automountServiceAccountToken: false
3332
serviceAccountName: kube-controller-manager-operator
3433
containers:
3534
- name: kube-controller-manager-operator
@@ -56,9 +55,6 @@ spec:
5655
name: config
5756
- mountPath: /var/run/secrets/serving-cert
5857
name: serving-cert
59-
- mountPath: /var/run/secrets/kubernetes.io/serviceaccount
60-
name: kube-api-access
61-
readOnly: true
6258
- mountPath: /tmp
6359
name: tmp-dir
6460
env:
@@ -87,24 +83,6 @@ spec:
8783
- name: config
8884
configMap:
8985
name: kube-controller-manager-operator-config
90-
- name: kube-api-access
91-
projected:
92-
defaultMode: 420
93-
sources:
94-
- serviceAccountToken:
95-
expirationSeconds: 3600
96-
path: token
97-
- configMap:
98-
items:
99-
- key: ca.crt
100-
path: ca.crt
101-
name: kube-root-ca.crt
102-
- downwardAPI:
103-
items:
104-
- fieldRef:
105-
apiVersion: v1
106-
fieldPath: metadata.namespace
107-
path: namespace
10886
- name: tmp-dir
10987
emptyDir: {}
11088
nodeSelector:

0 commit comments

Comments
 (0)