apiVersion: v1 kind: Namespace metadata: labels: control-plane: controller-manager manager: intel-deviceplugin-operator name: system --- apiVersion: apps/v1 kind: Deployment metadata: name: controller-manager namespace: system labels: control-plane: controller-manager manager: intel-deviceplugin-operator spec: selector: matchLabels: control-plane: controller-manager manager: intel-deviceplugin-operator replicas: 1 template: metadata: labels: control-plane: controller-manager manager: intel-deviceplugin-operator spec: containers: - image: docker.io/intel/intel-deviceplugin-operator:devel imagePullPolicy: IfNotPresent name: manager livenessProbe: httpGet: path: /healthz port: 8081 initialDelaySeconds: 15 periodSeconds: 20 readinessProbe: httpGet: path: /readyz port: 8081 initialDelaySeconds: 5 periodSeconds: 10 resources: limits: cpu: 100m memory: 120Mi requests: cpu: 100m memory: 100Mi securityContext: runAsNonRoot: true runAsUser: 65532 runAsGroup: 65532 readOnlyRootFilesystem: true allowPrivilegeEscalation: false capabilities: drop: ["ALL"] seccompProfile: type: RuntimeDefault env: - name: DEVICEPLUGIN_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace serviceAccountName: default terminationGracePeriodSeconds: 120