c12s-kubespray/roles/kubernetes-apps/efk/elasticsearch/templates/elasticsearch-deployment.yml.j2

64 lines
1.9 KiB
Text
Raw Normal View History

2017-01-26 23:33:01 +00:00
---
2018-05-11 16:22:44 +00:00
# https://raw.githubusercontent.com/kubernetes/kubernetes/v1.10.2/cluster/addons/fluentd-elasticsearch/es-statefulset.yaml
apiVersion: apps/v1
kind: StatefulSet
2017-01-26 23:33:01 +00:00
metadata:
2018-05-11 16:22:44 +00:00
name: elasticsearch-logging
namespace: kube-system
2017-01-26 23:33:01 +00:00
labels:
k8s-app: elasticsearch-logging
version: "{{ elasticsearch_image_tag }}"
kubernetes.io/cluster-service: "true"
2018-05-11 16:22:44 +00:00
addonmanager.kubernetes.io/mode: Reconcile
2017-01-26 23:33:01 +00:00
spec:
replicas: 2
selector:
matchLabels:
k8s-app: elasticsearch-logging
version: "{{ elasticsearch_image_tag }}"
2017-01-26 23:33:01 +00:00
template:
metadata:
labels:
k8s-app: elasticsearch-logging
version: "{{ elasticsearch_image_tag }}"
kubernetes.io/cluster-service: "true"
spec:
containers:
- image: "{{ elasticsearch_image_repo }}:{{ elasticsearch_image_tag }}"
name: elasticsearch-logging
resources:
# need more cpu upon initialization, therefore burstable class
limits:
cpu: {{ elasticsearch_cpu_limit }}
{% if elasticsearch_mem_limit is defined and elasticsearch_mem_limit != "0M" %}
memory: "{{ elasticsearch_mem_limit }}"
2017-01-26 23:33:01 +00:00
{% endif %}
requests:
cpu: {{ elasticsearch_cpu_requests }}
{% if elasticsearch_mem_requests is defined and elasticsearch_mem_requests != "0M" %}
memory: "{{ elasticsearch_mem_requests }}"
2017-01-26 23:33:01 +00:00
{% endif %}
ports:
- containerPort: 9200
name: db
protocol: TCP
- containerPort: 9300
name: transport
protocol: TCP
volumeMounts:
- name: es-persistent-storage
mountPath: /data
volumes:
- name: es-persistent-storage
emptyDir: {}
{% if rbac_enabled %}
serviceAccountName: efk
{% endif %}
2018-05-11 16:22:44 +00:00
initContainers:
- image: alpine:3.6
command: ["/sbin/sysctl", "-w", "vm.max_map_count=262144"]
name: elasticsearch-logging-init
securityContext:
privileged: true