This repository has been archived on 2026-07-10. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
authentik/manifest/base/worker-deployment.yaml
olb042 144bc81001
Validate manifests / validate (push) Failing after 35s
shutdown
2026-04-20 01:46:41 +01:00

72 lines
2.1 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: authentik-worker
namespace: security
labels:
app: authentik-worker
spec:
replicas: 0
selector:
matchLabels:
app: authentik-worker
template:
metadata:
labels:
app: authentik-worker
spec:
serviceAccountName: authentik-worker
affinity:
podAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
matchLabels:
app: authentik-server
topologyKey: kubernetes.io/hostname
securityContext:
runAsUser: 1000
runAsGroup: 988
containers:
- name: worker
image: ghcr.io/goauthentik/server:2026.2
imagePullPolicy: IfNotPresent
args:
- worker
env:
- name: AUTHENTIK_POSTGRESQL__HOST
value: shared-postgres-rw.data.svc.cluster.local
- name: AUTHENTIK_POSTGRESQL__NAME
value: authentik
- name: AUTHENTIK_POSTGRESQL__USER
value: authentik
- name: AUTHENTIK_POSTGRESQL__PORT
value: "5432"
- name: AUTHENTIK_POSTGRESQL__SSLMODE
value: disable
- name: AUTHENTIK_POSTGRESQL__PASSWORD
value: file:///run/secrets/db_password
- name: AUTHENTIK_SECRET_KEY
value: file:///run/secrets/secret_key
- name: AUTHENTIK_ERROR_REPORTING__ENABLED
value: "false"
- name: AUTHENTIK_WORKER__THREADS
value: "2"
volumeMounts:
- name: secrets
mountPath: /run/secrets/db_password
readOnly: true
subPath: db_password
- name: secrets
mountPath: /run/secrets/secret_key
readOnly: true
subPath: secret_key
- name: authentik-data
mountPath: /data
volumes:
- name: secrets
secret:
secretName: authentik-secrets
- name: authentik-data
persistentVolumeClaim:
claimName: authentik-data