Skip to content

Commit

Permalink
fix: added missing securityContext to tunnel container
Browse files Browse the repository at this point in the history
  • Loading branch information
fbuchmeier committed Nov 3, 2022
1 parent 3450b16 commit e78f196
Show file tree
Hide file tree
Showing 6 changed files with 42 additions and 0 deletions.
2 changes: 2 additions & 0 deletions templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -108,6 +108,8 @@ spec:
{{- end }}
{{- if .Values.headlessclient.enabled }}
- name: tunnel
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: "{{ .Values.tunnel.image.repository }}:{{ .Values.tunnel.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
Expand Down
8 changes: 8 additions & 0 deletions test-fixtures/ephemeral.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -716,6 +716,14 @@ spec:
mountPath: /opt/rsyncd
readOnly: false
- name: tunnel
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 433
runAsNonRoot: true
runAsUser: 431
image: "envoyproxy/envoy:v1.24-latest"
imagePullPolicy: IfNotPresent
ports:
Expand Down
8 changes: 8 additions & 0 deletions test-fixtures/production.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -787,6 +787,14 @@ spec:
mountPath: /opt/rsyncd
readOnly: false
- name: tunnel
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 433
runAsNonRoot: true
runAsUser: 431
image: "envoyproxy/envoy:v1.24-latest"
imagePullPolicy: IfNotPresent
ports:
Expand Down
8 changes: 8 additions & 0 deletions test-fixtures/rwo-rwo.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -773,6 +773,14 @@ spec:
mountPath: /opt/rsyncd
readOnly: false
- name: tunnel
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 433
runAsNonRoot: true
runAsUser: 431
image: "envoyproxy/envoy:v1.24-latest"
imagePullPolicy: IfNotPresent
ports:
Expand Down
8 changes: 8 additions & 0 deletions test-fixtures/rwo-rwx.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -773,6 +773,14 @@ spec:
mountPath: /opt/rsyncd
readOnly: false
- name: tunnel
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 433
runAsNonRoot: true
runAsUser: 431
image: "envoyproxy/envoy:v1.24-latest"
imagePullPolicy: IfNotPresent
ports:
Expand Down
8 changes: 8 additions & 0 deletions test-fixtures/sharedfilesystem.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -688,6 +688,14 @@ spec:
readOnly: false
containers:
- name: tunnel
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 433
runAsNonRoot: true
runAsUser: 431
image: "envoyproxy/envoy:v1.24-latest"
imagePullPolicy: IfNotPresent
ports:
Expand Down

0 comments on commit e78f196

Please sign in to comment.