diff --git a/templates/elasticsearch.yaml b/templates/elasticsearch.yaml index f0be1aa5c14f7ff7f6be2103857103fbf3adcf02..1c905f0868ffddc6574c3825a5f923d1336ae01b 100644 --- a/templates/elasticsearch.yaml +++ b/templates/elasticsearch.yaml @@ -206,6 +206,15 @@ metadata: spec: selfSigned: {} --- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: issuer-reader +rules: +- apiGroups: ["cert-manager.io"] + resources: ["issuers"] + verbs: ["get", "list", "watch"] +--- apiVersion: cert-manager.io/v1 kind: Certificate metadata: diff --git a/templates/filebeat.yaml b/templates/filebeat.yaml index 3119d4e368f7931698f43e1710c095e1fb413aa8..358edd05c2ff0452e7ad37f8cc22872639920158 100644 --- a/templates/filebeat.yaml +++ b/templates/filebeat.yaml @@ -10,9 +10,6 @@ spec: name: {{ .Release.Name }}-elasticsearch daemonSet: podTemplate: - metadata: - labels: - stack-namespace: {{ .Release.Namespace }} spec: securityContext: runAsUser: 0 @@ -113,6 +110,25 @@ data: count=$((count + 1)) done --- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: filebeat + namespace: {{ .Release.Namespace }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: filebeat-issuer +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: issuer-reader +subjects: +- kind: ServiceAccount + name: filebeat + namespace: {{ .Release.Namespace }} +--- apiVersion: cert-manager.io/v1 kind: Certificate metadata: @@ -126,4 +142,7 @@ spec: - "{{ template "filebeat.dns" . }}" issuerRef: name: internal-issuer - kind: Issuer \ No newline at end of file + kind: Issuer + group: cert-manager.io +--- + diff --git a/values/dev/observability/values.yaml b/values/dev/observability/values.yaml index d4feb65243c2bd27aac293a3d403c1d4374a2247..be71f5a7a0e6e67b7c5732f44b0f1c0fb4bbff1b 100644 --- a/values/dev/observability/values.yaml +++ b/values/dev/observability/values.yaml @@ -6,10 +6,10 @@ envTag: "dev" # This suffix will be used to create subdomain of following template: # kibana.NAMESPACE_TAG.DOMAIN_SUFFIX -domainSuffix: "dev" +domainSuffix: "simpl-europe.eu" # This value is used to create unique dns for each deployment. By default it equals to namespace. -namespaceTag: "" +namespaceTag: "dev" # Spread pods evenly between subnets