File tree Expand file tree Collapse file tree
helm/designate-certmanager-webhook Expand file tree Collapse file tree Original file line number Diff line number Diff line change 2424 {{- toYaml . | nindent 8 }}
2525 {{- end }}
2626 serviceAccountName : {{ include "designate-certmanager-webhook.fullname" . }}
27+ securityContext :
28+ {{- toYaml .Values.podSecurityContext | nindent 8 }}
2729 initContainers :
2830 - name : wait-for-tls-secret
2931 image : " {{ .Values.alpine.image.repository }}:{{ .Values.alpine.image.tag }}"
3739 args :
3840 - -c
3941 - " while [ ! -f /tls/tls.key ]; do sleep 5; done"
42+ securityContext :
43+ {{- toYaml .Values.securityContext | nindent 12 }}
4044 - name : add-apiservice
4145 image : " {{ .Values.kubectl.image.repository }}:{{ .Values.kubectl.image.tag }}"
4246 imagePullPolicy : {{ .Values.image.pullPolicy }}
5054 - apply
5155 - -f
5256 - /config/apiservice.yaml
57+ securityContext :
58+ {{- toYaml .Values.securityContext | nindent 12 }}
5359 containers :
5460 - name : {{ .Chart.Name }}
5561 image : " {{ .Values.image.repository }}:{{ .Values.image.tag }}"
8086 readOnly : true
8187 resources :
8288{{ toYaml .Values.resources | indent 12 }}
89+ securityContext :
90+ {{- toYaml .Values.securityContext | nindent 12 }}
8391 volumes :
8492 - name : apiservice-config
8593 configMap :
Original file line number Diff line number Diff line change @@ -45,6 +45,19 @@ service:
4545 type : ClusterIP
4646 port : 443
4747
48+ podSecurityContext :
49+ fsGroup : 2000
50+ runAsNonRoot : true
51+ runAsUser : 1000
52+
53+ securityContext :
54+ # capabilities:
55+ # drop:
56+ # - ALL
57+ # readOnlyRootFilesystem: true
58+ runAsNonRoot : true
59+ runAsUser : 1000
60+
4861resources : {}
4962 # limits:
5063 # cpu: 100m
You can’t perform that action at this time.
0 commit comments