# Copyright (c) 2022 Tailscale Inc & AUTHORS All rights reserved. # Use of this source code is governed by a BSD-style # license that can be found in the LICENSE file. apiVersion: v1 kind: Pod metadata: name: nginx spec: serviceAccountName: "{{SA_NAME}}" containers: - name: nginx image: nginx - name: ts-sidecar imagePullPolicy: Always image: "ghcr.io/tailscale/tailscale:latest" env: # Store the state in a k8s secret - name: TS_KUBE_SECRET value: "{{TS_KUBE_SECRET}}" - name: TS_USERSPACE value: "false" - name: TS_AUTHKEY valueFrom: secretKeyRef: name: tailscale-auth key: TS_AUTHKEY optional: true securityContext: capabilities: add: - NET_ADMIN