apiVersion: v1 kind: ServiceAccount metadata: name: csi-s3 namespace: {{ .Release.Namespace }} --- kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: name: csi-s3 --- kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: csi-s3 subjects: - kind: ServiceAccount name: csi-s3 namespace: {{ .Release.Namespace }} roleRef: kind: ClusterRole name: csi-s3 apiGroup: rbac.authorization.k8s.io --- kind: DaemonSet apiVersion: apps/v1 metadata: name: csi-s3 namespace: {{ .Release.Namespace }} spec: selector: matchLabels: app: csi-s3 template: metadata: labels: app: csi-s3 spec: tolerations: {{- if .Values.tolerations.all }} - operator: Exists {{- else }} - key: CriticalAddonsOnly operator: Exists - operator: Exists effect: NoExecute tolerationSeconds: 300 {{- end }} {{- with .Values.tolerations.node }} {{- toYaml . | nindent 8 }} {{- end }} serviceAccount: csi-s3 hostNetwork: true containers: - name: driver-registrar image: {{ .Values.images.registrar }} args: - "--kubelet-registration-path=$(DRIVER_REG_SOCK_PATH)" - "--v=4" - "--csi-address=$(ADDRESS)" env: - name: ADDRESS value: /csi/csi.sock - name: DRIVER_REG_SOCK_PATH value: {{ .Values.kubeletPath }}/plugins/ru.yandex.s3.csi/csi.sock - name: KUBE_NODE_NAME valueFrom: fieldRef: fieldPath: spec.nodeName volumeMounts: - name: plugin-dir mountPath: /csi - name: registration-dir mountPath: /registration/ - name: csi-s3 securityContext: privileged: true capabilities: add: ["SYS_ADMIN"] allowPrivilegeEscalation: true image: {{ .Values.images.csi }} imagePullPolicy: IfNotPresent args: - "--endpoint=$(CSI_ENDPOINT)" - "--nodeid=$(NODE_ID)" - "--v=4" env: - name: CSI_ENDPOINT value: unix:///csi/csi.sock - name: NODE_ID valueFrom: fieldRef: fieldPath: spec.nodeName volumeMounts: - name: plugin-dir mountPath: /csi - name: pods-mount-dir mountPath: {{ .Values.kubeletPath }}/pods mountPropagation: "Bidirectional" - name: fuse-device mountPath: /dev/fuse volumes: - name: registration-dir hostPath: path: {{ .Values.kubeletPath }}/plugins_registry/ type: DirectoryOrCreate - name: plugin-dir hostPath: path: {{ .Values.kubeletPath }}/plugins/ru.yandex.s3.csi type: DirectoryOrCreate - name: pods-mount-dir hostPath: path: {{ .Values.kubeletPath }}/pods type: Directory - name: fuse-device hostPath: path: /dev/fuse