apiVersion: apps/v1 kind: Deployment metadata: name: demo-target namespace: test-automation labels: app: demo-target spec: replicas: 1 selector: matchLabels: app: demo-target template: metadata: labels: app: demo-target spec: containers: - name: ubuntu image: ubuntu:24.04 imagePullPolicy: IfNotPresent command: ["/bin/bash", "-c"] args: - | set -e export DEBIAN_FRONTEND=noninteractive apt-get update apt-get install -y --no-install-recommends nginx openssh-server openssl python3 mkdir -p /run/sshd /etc/nginx/tls id auditor >/dev/null 2>&1 || useradd --create-home --shell /bin/bash auditor echo 'auditor:DemoPassword1!' | chpasswd printf '\nPasswordAuthentication yes\nPermitRootLogin no\n' >> /etc/ssh/sshd_config openssl req -x509 -newkey rsa:2048 -nodes -days 30 -subj '/CN=demo-target' -keyout /etc/nginx/tls/server.key -out /etc/nginx/tls/server.crt cp /config/nginx.conf /etc/nginx/sites-enabled/default cp /config/index.html /var/www/html/index.html /usr/sbin/sshd exec nginx -g 'daemon off;' ports: - name: ssh containerPort: 22 - name: https containerPort: 443 readinessProbe: tcpSocket: port: https initialDelaySeconds: 5 periodSeconds: 3 resources: requests: cpu: 100m memory: 128Mi limits: cpu: "1" memory: 512Mi volumeMounts: - name: config mountPath: /config volumes: - name: config configMap: name: demo-target-config --- apiVersion: v1 kind: Service metadata: name: demo-target namespace: test-automation spec: selector: app: demo-target ports: - name: ssh port: 22 targetPort: ssh - name: https port: 443 targetPort: https