Repository navigation
Expand file tree
/
Copy pathprovisioning-tenant.yaml
More file actions
107 lines (100 loc) · 2.22 KB
/
Copy pathprovisioning-tenant.yaml
File metadata and controls
107 lines (100 loc) · 2.22 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
# Tenant provisioning example
#
# Demonstrates operator-managed RustFS policy, user, and bucket provisioning.
# Demo credentials are intentionally simple; replace them with externally
# managed Secrets before using this pattern outside a test cluster.
apiVersion: v1
kind: Secret
metadata:
name: provisioning-admin-creds
namespace: default
type: Opaque
stringData:
accesskey: admin123
secretkey: admin12345
---
apiVersion: v1
kind: ConfigMap
metadata:
name: provisioning-app-policy
namespace: default
data:
policy.json: |
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject"
],
"Resource": [
"arn:aws:s3:::provisioning-demo-data",
"arn:aws:s3:::provisioning-demo-data/*"
]
}
]
}
---
apiVersion: v1
kind: Secret
metadata:
name: rustfs-user-app-user
namespace: default
type: Opaque
stringData:
accesskey: appuser01
secretkey: appuser01secret
---
apiVersion: rustfs.com/v1alpha1
kind: Tenant
metadata:
name: provisioning-demo
namespace: default
spec:
image: rustfs/rustfs:1.0.0
credsSecret:
name: provisioning-admin-creds
pools:
- name: pool-0
servers: 1
persistence:
volumesPerServer: 4
policies:
- name: app-readwrite
document:
configMapKeyRef:
name: provisioning-app-policy
key: policy.json
users:
- name: app-user
credsSecret:
name: rustfs-user-app-user
policies:
- app-readwrite
buckets:
- name: provisioning-demo-data
versioning: true
objectLock: true
objectLockConfiguration:
mode: Compliance
days: 30
anonymous: Download
lifecycle:
state: Present
rules:
- id: expire-old-logs
status: Enabled
filter:
prefix: logs/
expiration:
days: 30
- id: cleanup-incomplete-uploads
status: Enabled
filter:
prefix: ""
abortIncompleteMultipartUpload:
daysAfterInitiation: 1