| apiVersion: batch/v2alpha1 |
| kind: CronJob |
| metadata: |
| creationTimestamp: null |
| name: hello |
| spec: |
| jobTemplate: |
| metadata: |
| annotations: |
| sidecar.istio.io/status: '{"version":"","initContainers":["istio-init"],"containers":["istio-proxy"],"volumes":["istio-envoy","istio-certs"],"imagePullSecrets":null}' |
| creationTimestamp: null |
| labels: |
| app: hello |
| spec: |
| template: |
| metadata: |
| creationTimestamp: null |
| spec: |
| containers: |
| - args: |
| - /bin/sh |
| - -c |
| - date; echo Hello from the Kubernetes cluster |
| image: busybox |
| name: hello |
| resources: {} |
| - args: |
| - proxy |
| - sidecar |
| - --configPath |
| - /etc/istio/proxy |
| - --binaryPath |
| - /usr/local/bin/envoy |
| - --serviceCluster |
| - hello.default |
| - --drainDuration |
| - 45s |
| - --parentShutdownDuration |
| - 1m0s |
| - --discoveryAddress |
| - istio-pilot:15010 |
| - --connectTimeout |
| - 1s |
| - --statsdUdpAddress |
| - "" |
| - --proxyAdminPort |
| - "15000" |
| - --controlPlaneAuthPolicy |
| - NONE |
| - --concurrency |
| - "1" |
| env: |
| - name: POD_NAME |
| valueFrom: |
| fieldRef: |
| fieldPath: metadata.name |
| - name: POD_NAMESPACE |
| valueFrom: |
| fieldRef: |
| fieldPath: metadata.namespace |
| - name: INSTANCE_IP |
| valueFrom: |
| fieldRef: |
| fieldPath: status.podIP |
| - name: SERVICE_ACCOUNT |
| valueFrom: |
| fieldRef: |
| fieldPath: spec.serviceAccountName |
| - name: ISTIO_META_POD_NAME |
| valueFrom: |
| fieldRef: |
| fieldPath: metadata.name |
| - name: ISTIO_META_INTERCEPTION_MODE |
| value: REDIRECT |
| image: docker.io/istio/proxyv2:unittest |
| imagePullPolicy: IfNotPresent |
| name: istio-proxy |
| resources: |
| requests: |
| cpu: 10m |
| memory: 30Mi |
| securityContext: |
| allowPrivilegeEscalation: false |
| capabilities: |
| drop: |
| - ALL |
| privileged: false |
| readOnlyRootFilesystem: true |
| runAsGroup: 1337 |
| runAsNonRoot: true |
| runAsUser: 1337 |
| volumeMounts: |
| - mountPath: /etc/istio/proxy |
| name: istio-envoy |
| - mountPath: /etc/certs/ |
| name: istio-certs |
| readOnly: true |
| initContainers: |
| - args: |
| - -p |
| - "15001" |
| - -u |
| - "1337" |
| - -m |
| - REDIRECT |
| - -i |
| - '*' |
| - -x |
| - "" |
| - -b |
| - "" |
| - -d |
| - "" |
| image: docker.io/istio/proxy_init:unittest |
| imagePullPolicy: IfNotPresent |
| name: istio-init |
| resources: {} |
| securityContext: |
| allowPrivilegeEscalation: false |
| capabilities: |
| add: |
| - NET_ADMIN |
| - NET_RAW |
| drop: |
| - ALL |
| privileged: false |
| readOnlyRootFilesystem: false |
| runAsGroup: 0 |
| runAsNonRoot: false |
| runAsUser: 0 |
| restartPolicy: OnFailure |
| volumes: |
| - emptyDir: |
| medium: Memory |
| name: istio-envoy |
| - name: istio-certs |
| secret: |
| optional: true |
| secretName: istio.default |
| schedule: '*/1 * * * *' |
| status: {} |
| --- |