apiVersion: apps/v1 kind: Deployment metadata: name: sish labels: app.kubernetes.io/name: sish spec: replicas: 1 # Host ports cannot be shared, so the old pod must be gone before the new one starts. strategy: type: Recreate selector: matchLabels: app.kubernetes.io/name: sish template: metadata: labels: app.kubernetes.io/name: sish spec: hostNetwork: true dnsPolicy: ClusterFirstWithHostNet enableServiceLinks: false automountServiceAccountToken: false # Binding :22/:80/:443 as non-root relies on the node sysctl # net.ipv4.ip_unprivileged_port_start=22 (talos/patches/unprivileged-ports.yaml). securityContext: runAsNonRoot: true runAsUser: 65534 runAsGroup: 65534 fsGroup: 65534 seccompProfile: type: RuntimeDefault containers: - name: sish image: docker.io/antoniomika/sish:v2.23.0 args: - --config=/config/config.yml envFrom: - configMapRef: name: sish-env optional: true ports: - name: ssh containerPort: 2222 - name: http containerPort: 80 - name: https containerPort: 443 securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: ["ALL"] resources: requests: cpu: 20m memory: 32Mi limits: memory: 256Mi readinessProbe: tcpSocket: port: ssh periodSeconds: 10 livenessProbe: tcpSocket: port: ssh initialDelaySeconds: 10 periodSeconds: 20 volumeMounts: - name: config mountPath: /config readOnly: true - name: hostkey mountPath: /keys readOnly: true - name: pubkeys mountPath: /pubkeys readOnly: true - name: tmp mountPath: /tmp volumes: - name: config configMap: name: sish-config - name: hostkey secret: secretName: sish-hostkey defaultMode: 0440 - name: pubkeys configMap: name: sish-pubkeys - name: tmp emptyDir: sizeLimit: 16Mi