From a3a6daeed98af8388d04d07a3448e9d064b0d1ab Mon Sep 17 00:00:00 2001 From: "lan.tian" Date: Tue, 2 Dec 2025 11:18:47 +0800 Subject: [PATCH] Use BoundServceAccountTokenVolume dy default --- ...kube-apiserver-operator_06_deployment.yaml | 22 ------------------- 1 file changed, 22 deletions(-) diff --git a/manifests/0000_20_kube-apiserver-operator_06_deployment.yaml b/manifests/0000_20_kube-apiserver-operator_06_deployment.yaml index d568201e8..95761c9cd 100644 --- a/manifests/0000_20_kube-apiserver-operator_06_deployment.yaml +++ b/manifests/0000_20_kube-apiserver-operator_06_deployment.yaml @@ -32,7 +32,6 @@ spec: fsGroup: 1000 seccompProfile: type: RuntimeDefault - automountServiceAccountToken: false # here to prevent deadlock, remove in 4.9 serviceAccountName: kube-apiserver-operator containers: - name: kube-apiserver-operator @@ -59,9 +58,6 @@ spec: name: config - mountPath: /var/run/secrets/serving-cert name: serving-cert - - mountPath: /var/run/secrets/kubernetes.io/serviceaccount - name: kube-api-access - readOnly: true - mountPath: /tmp name: tmp-dir env: @@ -86,24 +82,6 @@ spec: - name: config configMap: name: kube-apiserver-operator-config - - name: kube-api-access - projected: - defaultMode: 420 - sources: - - serviceAccountToken: - expirationSeconds: 3600 - path: token - - configMap: - items: - - key: ca.crt - path: ca.crt - name: kube-root-ca.crt - - downwardAPI: - items: - - fieldRef: - apiVersion: v1 - fieldPath: metadata.namespace - path: namespace - name: tmp-dir emptyDir: {} nodeSelector: