Skip to content

Commit

Permalink
fix
Browse files Browse the repository at this point in the history
  • Loading branch information
cvvz committed Feb 22, 2023
1 parent 6a866db commit 7e84f91
Show file tree
Hide file tree
Showing 3 changed files with 11 additions and 12 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -193,11 +193,11 @@ spec:
timeoutSeconds: 10
periodSeconds: 30
env:
{{- if .Values.federatedWorkloadIdentity.enabled }}
{{- if and .Values.workloadIdentity.clientID .Values.workloadIdentity.tenantID}}
- name: AZURE_CLIENT_ID
value: {{ .Values.federatedWorkloadIdentity.clientID }}
value: {{ .Values.workloadIdentity.clientID }}
- name: AZURE_TENANT_ID
value: {{ .Values.federatedWorkloadIdentity.tenantID }}
value: {{ .Values.workloadIdentity.tenantID }}
- name: AZURE_FEDERATED_TOKEN_FILE
value: /var/run/secrets/tokens/azure-identity-token
- name: AZURE_AUTHORITY_HOST
Expand All @@ -223,7 +223,7 @@ spec:
value: {{ .Values.driver.azureGoSDKLogLevel }}
imagePullPolicy: {{ .Values.image.azurefile.pullPolicy }}
volumeMounts:
{{- if .Values.federatedWorkloadIdentity.enabled }}
{{- if and .Values.workloadIdentity.clientID .Values.workloadIdentity.tenantID}}
- mountPath: /var/run/secrets/tokens
name: azure-identity-token
readOnly: true
Expand All @@ -242,7 +242,7 @@ spec:
{{- end }}
resources: {{- toYaml .Values.controller.resources.azurefile | nindent 12 }}
volumes:
{{- if .Values.federatedWorkloadIdentity.enabled }}
{{- if and .Values.workloadIdentity.clientID .Values.workloadIdentity.tenantID}}
- name: azure-identity-token
projected:
defaultMode: 420
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -140,11 +140,11 @@ spec:
timeoutSeconds: 10
periodSeconds: 30
env:
{{- if .Values.federatedWorkloadIdentity.enabled }}
{{- if and .Values.workloadIdentity.clientID .Values.workloadIdentity.tenantID}}
- name: AZURE_CLIENT_ID
value: {{ .Values.federatedWorkloadIdentity.clientID }}
value: {{ .Values.workloadIdentity.clientID }}
- name: AZURE_TENANT_ID
value: {{ .Values.federatedWorkloadIdentity.tenantID }}
value: {{ .Values.workloadIdentity.tenantID }}
- name: AZURE_FEDERATED_TOKEN_FILE
value: /var/run/secrets/tokens/azure-identity-token
- name: AZURE_AUTHORITY_HOST
Expand Down Expand Up @@ -177,7 +177,7 @@ spec:
securityContext:
privileged: true
volumeMounts:
{{- if .Values.federatedWorkloadIdentity.enabled }}
{{- if and .Values.workloadIdentity.clientID .Values.workloadIdentity.tenantID}}
- mountPath: /var/run/secrets/tokens
name: azure-identity-token
readOnly: true
Expand All @@ -201,7 +201,7 @@ spec:
{{- end }}
resources: {{- toYaml .Values.linux.resources.azurefile | nindent 12 }}
volumes:
{{- if .Values.federatedWorkloadIdentity.enabled }}
{{- if and .Values.workloadIdentity.clientID .Values.workloadIdentity.tenantID}}
- name: azure-identity-token
projected:
defaultMode: 420
Expand Down
3 changes: 1 addition & 2 deletions charts/latest/azurefile-csi-driver/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -253,8 +253,7 @@ windows:
values:
- virtual-kubelet

federatedWorkloadIdentity:
enabled: false
workloadIdentity:
# if using Azure AD Application: APPLICATION_CLIENT_ID="$(az ad sp list --display-name "${APPLICATION_NAME}" --query '[0].appId' -otsv)"
# if using user-assigned managed identity: export USER_ASSIGNED_IDENTITY_CLIENT_ID="$(az identity show --name "${USER_ASSIGNED_IDENTITY_NAME}" --resource-group "${RESOURCE_GROUP}" --query 'clientId' -otsv)"
clientID: ""
Expand Down

0 comments on commit 7e84f91

Please sign in to comment.