{"version": "2.0","statement": [{"effect": "allow","action": ["dnspod:ModifyRecord","dnspod:DeleteRecord","dnspod:CreateRecord","dnspod:DescribeRecordList","dnspod:DescribeDomainList"],"resource": ["*"]},{"effect": "allow","action": ["privatedns:DescribePrivateZoneList","privatedns:DescribePrivateZoneRecordList","privatedns:CreatePrivateZoneRecord","privatedns:DeletePrivateZoneRecord","privatedns:ModifyPrivateZoneRecord"],"resource": ["*"]}]}
apiVersion: v1kind: ServiceAccountmetadata:name: external-dns---apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata:name: external-dnsrules:- apiGroups: [""]resources: ["services","endpoints","pods"]verbs: ["get","watch","list"]- apiGroups: ["extensions","networking.k8s.io"]resources: ["ingresses"]verbs: ["get","watch","list"]- apiGroups: [""]resources: ["nodes"]verbs: ["list"]---apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:name: external-dns-viewerroleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: external-dnssubjects:- kind: ServiceAccountname: external-dnsnamespace: default---apiVersion: v1kind: ConfigMapmetadata:name: external-dnsdata:tencent-cloud.json: |{"regionId": "ap-shanghai", # 必填项,集群所在地域的 ID"secretId": "******","secretKey": "******","vpcId": "vpc-******", # 必填项,集群所在 VPC 的 ID"internetEndpoint": false # 腾讯云API入口。如果需要在非腾讯云的环境部署,改为true,走公网访问。}---apiVersion: apps/v1kind: Deploymentmetadata:name: external-dnsspec:strategy:type: Recreateselector:matchLabels:app: external-dnstemplate:metadata:labels:app: external-dnsspec:containers:- args:- --source=service- --source=ingress- --domain-filter=external-dns-test.com # 将使 ExternalDNS 仅看到与提供的域匹配的托管区域,省略以处理所有可用的托管区域- --provider=tencentcloud- --policy=sync # 设置“upsert-only”将阻止 ExternalDNS 删除任何记录- --tencent-cloud-zone-type=private # 仅管理私有托管区域。设置“public”以使用公网 DNS 服务- --tencent-cloud-config-file=/etc/kubernetes/tencent-cloud.jsonimage: ccr.ccs.tencentyun.com/tke-market/external-dns:v1.1.0imagePullPolicy: Alwaysname: external-dnsresources: {}terminationMessagePath: /dev/termination-logterminationMessagePolicy: FilevolumeMounts:- mountPath: /etc/kubernetesname: config-volumereadOnly: truednsPolicy: ClusterFirstrestartPolicy: AlwaysschedulerName: default-schedulersecurityContext: {}serviceAccount: external-dnsserviceAccountName: external-dnsterminationGracePeriodSeconds: 30volumes:- configMap:defaultMode: 420items:- key: tencent-cloud.jsonpath: tencent-cloud.jsonname: external-dnsname: config-volume
apiVersion: v1kind: Servicemetadata:name: nginxannotations:external-dns.alpha.kubernetes.io/hostname: nginx.external-dns-test.com # 公网域名地址external-dns.alpha.kubernetes.io/internal-hostname: nginx-internal.external-dns-test.com # 内网域名地址external-dns.alpha.kubernetes.io/ttl: "600"spec:type: LoadBalancerports:- port: 80name: httptargetPort: 80selector:app: nginx---apiVersion: apps/v1kind: Deploymentmetadata:name: nginxspec:selector:matchLabels:app: nginxtemplate:metadata:labels:app: nginxspec:containers:- image: nginxname: nginxports:- containerPort: 80name: http


文档反馈