This commit is contained in:
@@ -0,0 +1,64 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: authentik-worker
|
||||
namespace: security
|
||||
labels:
|
||||
app: authentik-worker
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: authentik-worker
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: authentik-worker
|
||||
spec:
|
||||
serviceAccountName: authentik-worker
|
||||
securityContext:
|
||||
runAsUser: 1000
|
||||
runAsGroup: 988
|
||||
containers:
|
||||
- name: worker
|
||||
image: ghcr.io/goauthentik/server:2026.2
|
||||
imagePullPolicy: IfNotPresent
|
||||
args:
|
||||
- worker
|
||||
env:
|
||||
- name: AUTHENTIK_POSTGRESQL__HOST
|
||||
value: shared-postgres-rw.data.svc.cluster.local
|
||||
- name: AUTHENTIK_POSTGRESQL__NAME
|
||||
value: authentik
|
||||
- name: AUTHENTIK_POSTGRESQL__USER
|
||||
value: authentik
|
||||
- name: AUTHENTIK_POSTGRESQL__PORT
|
||||
value: "5432"
|
||||
- name: AUTHENTIK_POSTGRESQL__SSLMODE
|
||||
value: disable
|
||||
- name: AUTHENTIK_POSTGRESQL__PASSWORD
|
||||
value: file:///run/secrets/db_password
|
||||
- name: AUTHENTIK_SECRET_KEY
|
||||
value: file:///run/secrets/secret_key
|
||||
- name: AUTHENTIK_ERROR_REPORTING__ENABLED
|
||||
value: "false"
|
||||
- name: AUTHENTIK_WORKER__THREADS
|
||||
value: "2"
|
||||
volumeMounts:
|
||||
- name: secrets
|
||||
mountPath: /run/secrets/db_password
|
||||
readOnly: true
|
||||
subPath: db_password
|
||||
- name: secrets
|
||||
mountPath: /run/secrets/secret_key
|
||||
readOnly: true
|
||||
subPath: secret_key
|
||||
- name: authentik-data
|
||||
mountPath: /data
|
||||
volumes:
|
||||
- name: secrets
|
||||
secret:
|
||||
secretName: authentik-secrets
|
||||
- name: authentik-data
|
||||
persistentVolumeClaim:
|
||||
claimName: authentik-data
|
||||
Reference in New Issue
Block a user