apiVersion: apps/v1
kind: ReplicaSet
metadata:
  annotations:
    deployment.kubernetes.io/desired-replicas: "1"
    deployment.kubernetes.io/max-replicas: "2"
    deployment.kubernetes.io/revision: "3"
  creationTimestamp: "2026-04-06T12:19:00Z"
  generation: 2
  labels:
    component: barbican-api
    pod-template-hash: 57899578c6
    service: barbican
  name: barbican-api-57899578c6
  namespace: openstack
  ownerReferences:
  - apiVersion: apps/v1
    blockOwnerDeletion: true
    controller: true
    kind: Deployment
    name: barbican-api
    uid: 748ab4f6-14e7-4535-9bf0-34b412804855
  resourceVersion: "48375"
  uid: f3c5d0e6-0983-4c61-9492-8deade45b288
spec:
  replicas: 1
  selector:
    matchLabels:
      component: barbican-api
      pod-template-hash: 57899578c6
      service: barbican
  template:
    metadata:
      annotations:
        k8s.v1.cni.cncf.io/networks: '[]'
      creationTimestamp: null
      labels:
        component: barbican-api
        pod-template-hash: 57899578c6
        service: barbican
    spec:
      affinity:
        podAntiAffinity:
          preferredDuringSchedulingIgnoredDuringExecution:
          - podAffinityTerm:
              labelSelector:
                matchExpressions:
                - key: component
                  operator: In
                  values:
                  - barbican-api
              topologyKey: kubernetes.io/hostname
            weight: 100
      containers:
      - args:
        - --single-child
        - --
        - /usr/bin/tail
        - -n+1
        - -F
        - /var/log/barbican/barbican-api.log
        command:
        - /usr/bin/dumb-init
        env:
        - name: CONFIG_HASH
          value: n654h5d9h64fh676h7bh5c6h78hb9h65dh58h69h7dh67h5d9h68ch87h54ch5bfh56bh87h55dh5c4h57ch5c7h67fh88h68ch558h677h5c9hc6h566q
        - name: KOLLA_CONFIG_STRATEGY
          value: COPY_ALWAYS
        image: 38.102.83.94:5001/podified-master-centos10/openstack-barbican-api:watcher_latest
        imagePullPolicy: IfNotPresent
        livenessProbe:
          failureThreshold: 3
          httpGet:
            path: /healthcheck
            port: 9311
            scheme: HTTPS
          initialDelaySeconds: 5
          periodSeconds: 3
          successThreshold: 1
          timeoutSeconds: 5
        name: barbican-api-log
        readinessProbe:
          failureThreshold: 3
          httpGet:
            path: /healthcheck
            port: 9311
            scheme: HTTPS
          initialDelaySeconds: 5
          periodSeconds: 5
          successThreshold: 1
          timeoutSeconds: 5
        resources: {}
        securityContext:
          capabilities:
            drop:
            - MKNOD
          runAsGroup: 42403
          runAsUser: 42403
        terminationMessagePath: /dev/termination-log
        terminationMessagePolicy: File
        volumeMounts:
        - mountPath: /var/log/barbican
          name: logs
      - args:
        - -c
        - /usr/local/bin/kolla_start
        command:
        - /bin/bash
        env:
        - name: CONFIG_HASH
          value: n654h5d9h64fh676h7bh5c6h78hb9h65dh58h69h7dh67h5d9h68ch87h54ch5bfh56bh87h55dh5c4h57ch5c7h67fh88h68ch558h677h5c9hc6h566q
        - name: KOLLA_CONFIG_STRATEGY
          value: COPY_ALWAYS
        image: 38.102.83.94:5001/podified-master-centos10/openstack-barbican-api:watcher_latest
        imagePullPolicy: IfNotPresent
        livenessProbe:
          failureThreshold: 3
          httpGet:
            path: /healthcheck
            port: 9311
            scheme: HTTPS
          initialDelaySeconds: 5
          periodSeconds: 3
          successThreshold: 1
          timeoutSeconds: 5
        name: barbican-api
        readinessProbe:
          failureThreshold: 3
          httpGet:
            path: /healthcheck
            port: 9311
            scheme: HTTPS
          initialDelaySeconds: 5
          periodSeconds: 5
          successThreshold: 1
          timeoutSeconds: 5
        resources: {}
        securityContext:
          capabilities:
            drop:
            - MKNOD
          runAsGroup: 42403
          runAsUser: 42403
        terminationMessagePath: /dev/termination-log
        terminationMessagePolicy: File
        volumeMounts:
        - mountPath: /var/lib/config-data/default
          name: config-data
          readOnly: true
        - mountPath: /etc/my.cnf
          name: config-data
          readOnly: true
          subPath: my.cnf
        - mountPath: /etc/barbican/barbican.conf.d
          name: config-data-custom
          readOnly: true
        - mountPath: /var/lib/kolla/config_files/config.json
          name: config-data
          readOnly: true
          subPath: barbican-api-config.json
        - mountPath: /var/log/barbican
          name: logs
        - mountPath: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
          name: combined-ca-bundle
          readOnly: true
          subPath: tls-ca-bundle.pem
        - mountPath: /var/lib/config-data/tls/certs/internal.crt
          name: internal-tls-certs
          readOnly: true
          subPath: tls.crt
        - mountPath: /var/lib/config-data/tls/private/internal.key
          name: internal-tls-certs
          readOnly: true
          subPath: tls.key
        - mountPath: /var/lib/config-data/tls/certs/public.crt
          name: public-tls-certs
          readOnly: true
          subPath: tls.crt
        - mountPath: /var/lib/config-data/tls/private/public.key
          name: public-tls-certs
          readOnly: true
          subPath: tls.key
      dnsPolicy: ClusterFirst
      restartPolicy: Always
      schedulerName: default-scheduler
      securityContext: {}
      serviceAccount: barbican-barbican
      serviceAccountName: barbican-barbican
      terminationGracePeriodSeconds: 30
      volumes:
      - name: config-data
        secret:
          defaultMode: 420
          secretName: barbican-config-data
      - name: config-data-custom
        secret:
          defaultMode: 420
          secretName: barbican-api-config-data
      - emptyDir: {}
        name: logs
      - name: combined-ca-bundle
        secret:
          defaultMode: 292
          secretName: combined-ca-bundle
      - name: internal-tls-certs
        secret:
          defaultMode: 256
          secretName: cert-barbican-internal-svc
      - name: public-tls-certs
        secret:
          defaultMode: 256
          secretName: cert-barbican-public-svc
status:
  availableReplicas: 1
  fullyLabeledReplicas: 1
  observedGeneration: 2
  readyReplicas: 1
  replicas: 1
