File tree Expand file tree Collapse file tree
helm/designate-certmanager-webhook Expand file tree Collapse file tree Original file line number Diff line number Diff line change 2424 {{- toYaml . | nindent 8 }}
2525 {{- end }}
2626 serviceAccountName : {{ include "designate-certmanager-webhook.fullname" . }}
27+ securityContext :
28+ {{- toYaml .Values.podSecurityContext | nindent 8 }}
2729 initContainers :
2830 - name : wait-for-tls-secret
2931 image : " {{ .Values.image.alpine.repository }}:{{ .Values.image.alpine.tag }}"
3739 args :
3840 - -c
3941 - " while [ ! -f /tls/tls.key ]; do sleep 5; done"
42+ securityContext :
43+ {{- toYaml .Values.securityContext | nindent 12 }}
4044 - name : add-apiservice
4145 image : " {{ .Values.image.kubectl.repository }}:{{ .Values.image.kubectl.tag }}"
4246 imagePullPolicy : {{ .Values.image.pullPolicy }}
5054 - apply
5155 - -f
5256 - /config/apiservice.yaml
57+ securityContext :
58+ {{- toYaml .Values.securityContext | nindent 12 }}
5359 containers :
5460 - name : {{ .Chart.Name }}
5561 image : " {{ .Values.image.repository }}:{{ .Values.image.tag }}"
8086 readOnly : true
8187 resources :
8288{{ toYaml .Values.resources | indent 12 }}
89+ securityContext :
90+ {{- toYaml .Values.securityContext | nindent 12 }}
8391 volumes :
8492 - name : apiservice-config
8593 configMap :
Original file line number Diff line number Diff line change @@ -40,6 +40,19 @@ service:
4040 type : ClusterIP
4141 port : 443
4242
43+ podSecurityContext :
44+ fsGroup : 2000
45+ runAsNonRoot : true
46+ runAsUser : 1000
47+
48+ securityContext :
49+ # capabilities:
50+ # drop:
51+ # - ALL
52+ # readOnlyRootFilesystem: true
53+ runAsNonRoot : true
54+ runAsUser : 1000
55+
4356resources : {}
4457 # limits:
4558 # cpu: 100m
You can’t perform that action at this time.
0 commit comments