Skip to content

Commit 6510a9d

Browse files
committed
helm: force app creds in GCP CCM (#3822)
1 parent 3705694 commit 6510a9d

File tree

2 files changed

+8
-2
lines changed
  • internal/constellation/helm
    • charts/edgeless/constellation-services/charts/ccm/templates
    • testdata/GCP/constellation-services/charts/ccm/templates

2 files changed

+8
-2
lines changed

internal/constellation/helm/charts/edgeless/constellation-services/charts/ccm/templates/gcp-cm.yaml

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,5 +5,11 @@ metadata:
55
name: gceconf
66
namespace: {{ .Release.Namespace }}
77
data:
8-
gce.conf: "[global]\nproject-id = {{.Values.GCP.projectID }}\nuse-metadata-server = true\nnode-tags = constellation-{{ .Values.GCP.uid }}\nregional = true\n"
8+
gce.conf: |
9+
[global]
10+
project-id = {{.Values.GCP.projectID }}
11+
use-metadata-server = true
12+
node-tags = constellation-{{ .Values.GCP.uid }}
13+
regional = true
14+
token-url = nil # This forces use of GOOGLE_APPLICATION_CREDENTIALS.
915
{{- end -}}

internal/constellation/helm/testdata/GCP/constellation-services/charts/ccm/templates/gcp-cm.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,4 +4,4 @@ metadata:
44
name: gceconf
55
namespace: testNamespace
66
data:
7-
gce.conf: "[global]\nproject-id = 42424242424242\nuse-metadata-server = true\nnode-tags = constellation-242424242424\nregional = true\n"
7+
gce.conf: "[global]\nproject-id = 42424242424242\nuse-metadata-server = true\nnode-tags = constellation-242424242424\nregional = true\ntoken-url = nil # This forces use of GOOGLE_APPLICATION_CREDENTIALS."

0 commit comments

Comments
 (0)