forked from salesforce/native-submit-plugin
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathexample-deployment.yaml
More file actions
128 lines (126 loc) · 3.4 KB
/
Copy pathexample-deployment.yaml
File metadata and controls
128 lines (126 loc) · 3.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
apiVersion: apps/v1
kind: Deployment
metadata:
name: spark-operator-controller
namespace: spark-operator
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: spark-operator
app.kubernetes.io/name: spark-operator
template:
metadata:
labels:
app.kubernetes.io/component: controller
app.kubernetes.io/instance: spark-operator
app.kubernetes.io/name: spark-operator
spec:
containers:
- name: spark-operator-controller
image: ghcr.io/kubeflow/spark-operator/controller:2.2.1
args:
- controller
- start
- --zap-log-level=info
- --namespaces=default
- --controller-threads=10
- --enable-ui-service=true
- --enable-metrics=true
- --metrics-bind-address=:8080
- --metrics-endpoint=/metrics
- --leader-election=true
- --leader-election-lock-name=spark-operator-controller-lock
- --leader-election-lock-namespace=spark-operator
- --submitter-type=grpc
- --grpc-server-address=localhost:50051
- --grpc-submit-timeout=10s
ports:
- containerPort: 8080
name: metrics
protocol: TCP
livenessProbe:
httpGet:
path: /healthz
port: 8081
periodSeconds: 10
timeoutSeconds: 1
failureThreshold: 3
readinessProbe:
httpGet:
path: /readyz
port: 8081
periodSeconds: 10
timeoutSeconds: 1
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
privileged: false
readOnlyRootFilesystem: true
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
volumeMounts:
- mountPath: /tmp
name: tmp
# Native Submit Plugin Sidecar
- name: native-submit
image: your-registry/native-submit:latest
ports:
- containerPort: 50051
name: grpc
protocol: TCP
- containerPort: 9090
name: health
protocol: TCP
env:
- name: GRPC_PORT
value: "50051"
- name: HEALTH_PORT
value: "9090"
livenessProbe:
httpGet:
path: /healthz
port: 9090
initialDelaySeconds: 30
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /readyz
port: 9090
initialDelaySeconds: 5
periodSeconds: 5
timeoutSeconds: 3
failureThreshold: 3
resources:
requests:
memory: "64Mi"
cpu: "50m"
limits:
memory: "128Mi"
cpu: "100m"
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
privileged: false
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 185
runAsGroup: 185
seccompProfile:
type: RuntimeDefault
volumes:
- emptyDir:
sizeLimit: 1Gi
name: tmp
securityContext:
fsGroup: 185
serviceAccountName: spark-operator-controller