Files

78 lines
2.1 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: demo-target
namespace: test-automation
labels:
app: demo-target
spec:
replicas: 1
selector:
matchLabels:
app: demo-target
template:
metadata:
labels:
app: demo-target
spec:
containers:
- name: ubuntu
image: ubuntu:24.04
imagePullPolicy: IfNotPresent
command: ["/bin/bash", "-c"]
args:
- |
set -e
export DEBIAN_FRONTEND=noninteractive
apt-get update
apt-get install -y --no-install-recommends nginx openssh-server openssl python3
mkdir -p /run/sshd /etc/nginx/tls
id auditor >/dev/null 2>&1 || useradd --create-home --shell /bin/bash auditor
echo 'auditor:DemoPassword1!' | chpasswd
printf '\nPasswordAuthentication yes\nPermitRootLogin no\n' >> /etc/ssh/sshd_config
openssl req -x509 -newkey rsa:2048 -nodes -days 30 -subj '/CN=demo-target' -keyout /etc/nginx/tls/server.key -out /etc/nginx/tls/server.crt
cp /config/nginx.conf /etc/nginx/sites-enabled/default
cp /config/index.html /var/www/html/index.html
/usr/sbin/sshd
exec nginx -g 'daemon off;'
ports:
- name: ssh
containerPort: 22
- name: https
containerPort: 443
readinessProbe:
tcpSocket:
port: https
initialDelaySeconds: 5
periodSeconds: 3
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: "1"
memory: 512Mi
volumeMounts:
- name: config
mountPath: /config
volumes:
- name: config
configMap:
name: demo-target-config
---
apiVersion: v1
kind: Service
metadata:
name: demo-target
namespace: test-automation
spec:
selector:
app: demo-target
ports:
- name: ssh
port: 22
targetPort: ssh
- name: https
port: 443
targetPort: https