Skip to content

Commit

Permalink
fix: allow running as non-root
Browse files Browse the repository at this point in the history
  • Loading branch information
fbuchmeier committed Oct 1, 2022
1 parent d90aca1 commit 4988cfe
Show file tree
Hide file tree
Showing 2 changed files with 13 additions and 1 deletion.
2 changes: 1 addition & 1 deletion templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ spec:
{{- if (include "rsyncEnabled" .) }}
- name: rsyncd
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
{{- toYaml .Values.rsync.securityContext | nindent 12 }}
image: "{{ .Values.rsync.image.repository }}:{{ .Values.rsync.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.rsync.image.pullPolicy }}
env:
Expand Down
12 changes: 12 additions & 0 deletions values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -215,6 +215,18 @@ rsync:
# cpu: 50m
# memory: 128Mi

securityContext:
capabilities:
drop:
- ALL
add:
# rsync: [Receiver] chroot /arma3 failed: Operation not permitted (1)
- SYS_CHROOT
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 431
runAsGroup: 433

missions:
antistasi:
version: 2.5.5

0 comments on commit 4988cfe

Please sign in to comment.