Skip to content

Commit

Permalink
Fix sec context and resources for performance jobs (#14529)
Browse files Browse the repository at this point in the history
* fix sec ctx for performance jobs

* fix lint
  • Loading branch information
skonto authored Oct 19, 2023
1 parent 707d286 commit 9896079
Show file tree
Hide file tree
Showing 15 changed files with 181 additions and 4 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -75,3 +75,15 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
Original file line number Diff line number Diff line change
Expand Up @@ -75,4 +75,15 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
---
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
Original file line number Diff line number Diff line change
Expand Up @@ -75,4 +75,13 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
---
12 changes: 12 additions & 0 deletions test/performance/benchmarks/load-test/load-test-0-direct.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -77,4 +77,16 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
12 changes: 12 additions & 0 deletions test/performance/benchmarks/load-test/load-test-200-direct.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -77,4 +77,16 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
12 changes: 12 additions & 0 deletions test/performance/benchmarks/load-test/load-test-always-direct.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -77,4 +77,16 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
Original file line number Diff line number Diff line change
Expand Up @@ -78,4 +78,16 @@ spec:
requests:
cpu: 1000m
memory: 2Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
Original file line number Diff line number Diff line change
Expand Up @@ -49,9 +49,6 @@ spec:
args:
- "-duration=15m"
- "-frequency=5s"
resources:
requests:
cpu: 100m
env:
- name: KO_DOCKER_REPO
value: $KO_DOCKER_REPO
Expand Down Expand Up @@ -85,4 +82,20 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.uid
resources:
requests:
cpu: 100m
memory: 500Mi
limits:
cpu: 1000m
memory: 1Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
Original file line number Diff line number Diff line change
Expand Up @@ -76,4 +76,16 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
Original file line number Diff line number Diff line change
Expand Up @@ -76,4 +76,16 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
Original file line number Diff line number Diff line change
Expand Up @@ -76,4 +76,16 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
12 changes: 12 additions & 0 deletions test/performance/benchmarks/scale-from-zero/scale-from-zero-1.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -76,5 +76,17 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
---
Original file line number Diff line number Diff line change
Expand Up @@ -76,5 +76,17 @@ spec:
requests:
cpu: 1500m
memory: 6Gi
limits:
cpu: 1500m
memory: 6Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
---
Original file line number Diff line number Diff line change
Expand Up @@ -76,5 +76,17 @@ spec:
requests:
cpu: 1000m
memory: 4Gi
limits:
cpu: 1000m
memory: 4Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
---
12 changes: 12 additions & 0 deletions test/performance/benchmarks/scale-from-zero/scale-from-zero-5.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -76,5 +76,17 @@ spec:
requests:
cpu: 1000m
memory: 3Gi
limits:
cpu: 1000m
memory: 3Gi
securityContext:
seccompProfile:
type: RuntimeDefault
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
capabilities:
drop:
- ALL
restartPolicy: Never
---

0 comments on commit 9896079

Please sign in to comment.