Skip to content

Instantly share code, notes, and snippets.

@weinong
Last active June 8, 2025 19:22
Show Gist options
  • Select an option

  • Save weinong/9937b428f80ef08d090e981534499480 to your computer and use it in GitHub Desktop.

Select an option

Save weinong/9937b428f80ef08d090e981534499480 to your computer and use it in GitHub Desktop.
ubuntu deployment spec
apiVersion: v1
kind: Pod
metadata:
name: az-cli
spec:
containers:
- image: mcr.microsoft.com/azure-cli
name: oidc
command:
- sleep
- "6000"
apiVersion: v1
kind: Pod
metadata:
name: bash
labels:
app: bash
spec:
securityContext:
seccompProfile:
type: RuntimeDefault
containers:
- name: bash
image: bash
command: [ "/usr/local/bin/bash", "-c", "--" ]
args: [ "trap : TERM INT; sleep 9999999999d & wait" ]
apiVersion: v1
kind: Pod
metadata:
name: pod-shell
spec:
containers:
- image: mcr.microsoft.com/cbl-mariner/base/core:2.0
name: pod-shell
command:
- sleep
- "6000"
apiVersion: v1
kind: ServiceAccount
metadata:
name: test-sa
---
apiVersion: v1
kind: Pod
metadata:
name: mariner
spec:
serviceAccountName: test-sa
containers:
- name: shell
image: mcr.microsoft.com/cbl-mariner/base/core:2.0
command: ["bash", "-c", "--"]
args: ["trap : TERM INT; sleep 9999999999d & wait"]
volumeMounts:
- name: token-vol
mountPath: "/var/run/secrets/tokens"
readOnly: true
volumes:
- name: token-vol
projected:
sources:
- serviceAccountToken:
path: test-sa
expirationSeconds: 7200
audience: api://AzureADTokenExchange
apiVersion: apps/v1
kind: Deployment
metadata:
name: ubuntu-priv
spec:
selector:
matchLabels:
app: ubuntu-priv
replicas: 1
template:
metadata:
labels:
app: ubuntu-priv
spec:
containers:
- name: ubuntu-priv
image: ubuntu
command: [ "/bin/bash", "-c", "--" ]
args: [ "trap : TERM INT; sleep 9999999999d & wait" ]
securityContext:
privileged: true
apiVersion: apps/v1
kind: Deployment
metadata:
name: ubuntu
spec:
selector:
matchLabels:
app: ubuntu
replicas: 1
template:
metadata:
labels:
app: ubuntu
spec:
containers:
- name: ubuntu
image: ubuntu
command: [ "/bin/bash", "-c", "--" ]
args: [ "trap : TERM INT; sleep 9999999999d & wait" ]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment