Skip to content

Commit 2c769b4

Browse files
feat: add controllerManager.kubeRbacProxy.enabled flag to disable proxy sidecar (#849)
Signed-off-by: Karan gupta <gupta.karan1.gh@gmail.com> Co-authored-by: Alex Jones <1235925+AlexsJones@users.noreply.github.com>
1 parent 8714798 commit 2c769b4

7 files changed

Lines changed: 61 additions & 3 deletions

File tree

‎chart/operator/README.md‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,27 @@ Automatic SRE Superpowers within your Kubernetes cluster
99

1010
The following table lists the configurable parameters of the K8sgpt-operator chart and their default values.
1111

12+
## Metrics Configuration
13+
14+
### kube-rbac-proxy
15+
16+
By default, the operator deploys a `kube-rbac-proxy` sidecar container to protect the metrics endpoint with Kubernetes RBAC authorization and HTTPS encryption.
17+
18+
#### Disabling kube-rbac-proxy
19+
20+
You can disable the proxy to expose metrics directly via HTTP:
21+
22+
```yaml
23+
controllerManager:
24+
kubeRbacProxy:
25+
enabled: false
26+
```
27+
28+
When disabled, the manager exposes /metrics directly over HTTP on port
29+
8080 without Kubernetes RBAC authorization. Ensure access is protected by
30+
appropriate network policies, service mesh policies, or other infrastructure
31+
controls.
32+
1233
<!---x-release-please-start-version-->
1334
| Parameter | Description | Default |
1435
| ------------------------ | ----------------------- |-------------------------------------------------------------------------------|
@@ -19,6 +40,7 @@ The following table lists the configurable parameters of the K8sgpt-operator cha
1940
| `grafanaDashboard.folder.name` | | `"ai"` |
2041
| `grafanaDashboard.label.key` | | `"grafana_dashboard"` |
2142
| `grafanaDashboard.label.value` | | `"1"` |
43+
| `controllerManager.kubeRbacProxy.enabled` | Enable kube-rbac-proxy for RBAC-protected HTTPS metrics | `true` |
2244
| `controllerManager.kubeRbacProxy.containerSecurityContext.allowPrivilegeEscalation` | | `false` |
2345
| `controllerManager.kubeRbacProxy.containerSecurityContext.capabilities.drop` | | `["ALL"]` |
2446
| `controllerManager.kubeRbacProxy.image.repository` | | `"gcr.io/kubebuilder/kube-rbac-proxy"` |

‎chart/operator/templates/controller-manager-metrics-monitor.yaml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,12 +20,18 @@ spec:
2020
- {{ include "k8sgpt-operator.namespace" . }}
2121
{{- end }}
2222
endpoints:
23+
{{- if .Values.controllerManager.kubeRbacProxy.enabled }}
2324
- bearerTokenFile: /var/run/secrets/kubernetes.io/serviceaccount/token
2425
path: /metrics
2526
port: https
2627
scheme: https
2728
tlsConfig:
2829
insecureSkipVerify: true
30+
{{- else }}
31+
- path: /metrics
32+
port: http
33+
scheme: http
34+
{{- end }}
2935
selector:
3036
matchLabels:
3137
control-plane: controller-manager

‎chart/operator/templates/deployment.yaml‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,7 @@ spec:
5959
values:
6060
- linux
6161
containers:
62+
{{- if .Values.controllerManager.kubeRbacProxy.enabled }}
6263
- args:
6364
- --secure-listen-address=0.0.0.0:8443
6465
- --upstream=http://127.0.0.1:8080/
@@ -78,9 +79,14 @@ spec:
7879
10 }}
7980
securityContext: {{- toYaml .Values.controllerManager.kubeRbacProxy.containerSecurityContext
8081
| nindent 10 }}
82+
{{- end }}
8183
- args:
8284
- --health-probe-bind-address=:8081
85+
{{- if .Values.controllerManager.kubeRbacProxy.enabled }}
8386
- --metrics-bind-address=127.0.0.1:8080
87+
{{- else }}
88+
- --metrics-bind-address=:8080
89+
{{- end }}
8490
- --leader-elect
8591
{{- if .Values.controllerManager.manager.enableResultLogging }}
8692
- --enable-result-logging
@@ -113,6 +119,12 @@ spec:
113119
}}
114120
securityContext: {{- toYaml .Values.controllerManager.manager.containerSecurityContext
115121
| nindent 10 }}
122+
{{- if not .Values.controllerManager.kubeRbacProxy.enabled }}
123+
ports:
124+
- containerPort: 8080
125+
name: metrics
126+
protocol: TCP
127+
{{- end }}
116128
{{- if .Values.controllerManager.podSecurityContext }}
117129
securityContext:
118130
{{- toYaml .Values.controllerManager.podSecurityContext | nindent 8 }}

‎chart/operator/templates/metrics-reader-rbac.yaml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
{{- if .Values.controllerManager.kubeRbacProxy.enabled }}
12
apiVersion: rbac.authorization.k8s.io/v1
23
kind: ClusterRole
34
metadata:
@@ -11,4 +12,5 @@ rules:
1112
- nonResourceURLs:
1213
- /metrics
1314
verbs:
14-
- get
15+
- get
16+
{{- end }}

‎chart/operator/templates/metrics-service.yaml‎

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,11 @@ kind: Service
33
metadata:
44
name: {{ include "chart.fullname" . | trunc 20}}-controller-manager-metrics-service
55
labels:
6+
{{- if .Values.controllerManager.kubeRbacProxy.enabled }}
67
app.kubernetes.io/component: kube-rbac-proxy
8+
{{- else }}
9+
app.kubernetes.io/component: metrics
10+
{{- end }}
711
app.kubernetes.io/created-by: k8sgpt-operator
812
app.kubernetes.io/part-of: k8sgpt-operator
913
control-plane: controller-manager
@@ -14,4 +18,11 @@ spec:
1418
control-plane: controller-manager
1519
{{- include "chart.selectorLabels" . | nindent 4 }}
1620
ports:
17-
{{- .Values.metricsService.ports | toYaml | nindent 2 -}}
21+
{{- if .Values.controllerManager.kubeRbacProxy.enabled }}
22+
{{- .Values.metricsService.ports | toYaml | nindent 2 }}
23+
{{- else }}
24+
- name: http
25+
port: 8080
26+
protocol: TCP
27+
targetPort: metrics
28+
{{- end }}

‎chart/operator/templates/proxy-rbac.yaml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
{{- if .Values.controllerManager.kubeRbacProxy.enabled }}
12
apiVersion: rbac.authorization.k8s.io/v1
23
kind: ClusterRole
34
metadata:
@@ -37,4 +38,5 @@ roleRef:
3738
subjects:
3839
- kind: ServiceAccount
3940
name: '{{ include "chart.fullname" . }}-controller-manager'
40-
namespace: '{{ .Release.Namespace }}'
41+
namespace: '{{ .Release.Namespace }}'
42+
{{- end }}

‎chart/operator/values.yaml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,9 @@ controllerManager:
3434
# Additional annotations to add to the controller manager deployment
3535
annotations: {}
3636
kubeRbacProxy:
37+
## When enabled (default), deploys kube-rbac-proxy sidecar for HTTPS and RBAC-protected metrics.
38+
## Set to false to expose metrics directly via HTTP without RBAC enforcement.
39+
enabled: true
3740
containerSecurityContext:
3841
allowPrivilegeEscalation: false
3942
capabilities:

0 commit comments

Comments
 (0)