Skip to content

Commit 11a525b

Browse files
committed
fix: Use BoundServceAccountTokenVolume dy default
1 parent 395de96 commit 11a525b

File tree

1 file changed

+0
-22
lines changed

1 file changed

+0
-22
lines changed

manifests/0000_25_kube-controller-manager-operator_06_deployment.yaml

Lines changed: 0 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,6 @@ spec:
3232
fsGroup: 1000
3333
seccompProfile:
3434
type: RuntimeDefault
35-
automountServiceAccountToken: false
3635
serviceAccountName: kube-controller-manager-operator
3736
containers:
3837
- name: kube-controller-manager-operator
@@ -59,9 +58,6 @@ spec:
5958
name: config
6059
- mountPath: /var/run/secrets/serving-cert
6160
name: serving-cert
62-
- mountPath: /var/run/secrets/kubernetes.io/serviceaccount
63-
name: kube-api-access
64-
readOnly: true
6561
- mountPath: /tmp
6662
name: tmp-dir
6763
env:
@@ -90,24 +86,6 @@ spec:
9086
- name: config
9187
configMap:
9288
name: kube-controller-manager-operator-config
93-
- name: kube-api-access
94-
projected:
95-
defaultMode: 420
96-
sources:
97-
- serviceAccountToken:
98-
expirationSeconds: 3600
99-
path: token
100-
- configMap:
101-
items:
102-
- key: ca.crt
103-
path: ca.crt
104-
name: kube-root-ca.crt
105-
- downwardAPI:
106-
items:
107-
- fieldRef:
108-
apiVersion: v1
109-
fieldPath: metadata.namespace
110-
path: namespace
11189
- name: tmp-dir
11290
emptyDir: {}
11391
nodeSelector:

0 commit comments

Comments
 (0)