1 # This patch inject a sidecar container which is a HTTP proxy for the
2 # controller manager, it performs RBAC authorization against the Kubernetes API using SubjectAccessReviews.
6 name: controller-manager
12 - name: kube-rbac-proxy
13 image: gcr.io/kubebuilder/kube-rbac-proxy:v0.8.0
15 - "--secure-listen-address=0.0.0.0:8443"
16 - "--upstream=http://127.0.0.1:8085/"
17 - "--logtostderr=true"
24 - "--metrics-addr=127.0.0.1:8085"
25 - "--enable-leader-election"