# Monidori agent — read-only access to your cluster, from inside it.
#
# Install:
#   1. kubectl apply -f https://monidori.com/agent/v1/install.yaml
#   2. kubectl -n monidori-system create secret generic monidori-agent --from-literal=token=<YOUR AGENT TOKEN>
#      (the pod starts as soon as the secret exists)
#
# What it can do: read nodes, namespaces, pods, events, volume claims, deployments, CronJobs and Jobs, read pod
# logs, and read node volume statistics. It cannot change, delete or run anything, and it has no access to Secrets.
# It only makes outbound HTTPS connections to monidori.com (and to your nodes' kubelet port 10250 for disk usage).
# Remove it with: kubectl delete -f https://monidori.com/agent/v1/install.yaml
apiVersion: v1
kind: Namespace
metadata:
  name: monidori-system
---
apiVersion: v1
kind: ServiceAccount
metadata:
  name: monidori-agent
  namespace: monidori-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: monidori-agent
rules:
  - apiGroups: [""]
    resources: ["nodes", "namespaces", "pods", "events", "persistentvolumeclaims"]
    verbs: ["get", "list"]
  - apiGroups: [""]
    resources: ["pods/log"]
    verbs: ["get"]
  # Disk usage of volumes, read from each node's kubelet
  - apiGroups: [""]
    resources: ["nodes/stats"]
    verbs: ["get"]
  - apiGroups: ["apps"]
    resources: ["deployments"]
    verbs: ["get", "list"]
  - apiGroups: ["batch"]
    resources: ["cronjobs", "jobs"]
    verbs: ["get", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: monidori-agent
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: monidori-agent
subjects:
  - kind: ServiceAccount
    name: monidori-agent
    namespace: monidori-system
---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: monidori-agent
  namespace: monidori-system
  labels:
    app.kubernetes.io/name: monidori-agent
spec:
  replicas: 1
  strategy:
    type: Recreate # never two agents pushing for the same cluster
  selector:
    matchLabels:
      app.kubernetes.io/name: monidori-agent
  template:
    metadata:
      labels:
        app.kubernetes.io/name: monidori-agent
    spec:
      serviceAccountName: monidori-agent
      securityContext:
        runAsNonRoot: true
        runAsUser: 65532
        runAsGroup: 65532
        seccompProfile:
          type: RuntimeDefault
      nodeSelector:
        kubernetes.io/os: linux
      containers:
        - name: agent
          image: ghcr.io/dorianjames/monidori-agent:0.2.1
          imagePullPolicy: IfNotPresent
          env:
            - name: MONIDORI_URL
              value: "https://monidori.com"
            - name: MONIDORI_TOKEN
              valueFrom:
                secretKeyRef:
                  name: monidori-agent
                  key: token
          securityContext:
            allowPrivilegeEscalation: false
            readOnlyRootFilesystem: true
            capabilities:
              drop: ["ALL"]
          resources:
            requests:
              cpu: 20m
              memory: 96Mi
            limits:
              cpu: 500m
              memory: 384Mi
