File tree Expand file tree Collapse file tree 5 files changed +20
-13
lines changed
assets/manifests/istio-cni Expand file tree Collapse file tree 5 files changed +20
-13
lines changed Original file line number Diff line number Diff line change @@ -111,6 +111,7 @@ spec:
111
111
name : cni-log-dir
112
112
{{ include "toYamlIf" (dict "value" .Values.cni.volumeMounts) | indent 12 }}
113
113
{{ include "toYamlIf" (dict "value" .Values.cni.resources "key" "resources" "indent" 2) | indent 10 }}
114
+ {{ include "toYamlIf" (dict "value" .Values.cni.securityContext "key" "securityContext" "indent" 2) | indent 10 }}
114
115
{{- if .Values.cni.taint.enabled }}
115
116
- name : taint-controller
116
117
{{- include "dockerImage" (dict "image" .Values.cni.taint.image "hub" .Values.global.hub "tag" .Values.global.tag) | indent 10 -}}
Original file line number Diff line number Diff line change 44
44
# Experimental taint controller for further race condition mitigation
45
45
taint :
46
46
enabled : false
47
+ securityContext :
48
+ runAsUser : 1337
49
+ runAsGroup : 1337
50
+ runAsNonRoot : true
47
51
48
52
resourceQuotas :
49
53
enabled : true
70
74
volumes : []
71
75
volumeMounts : []
72
76
resources : {}
73
- securityContext : {}
77
+ securityContext :
78
+ runAsGroup : 0
79
+ runAsUser : 0
80
+ runAsNonRoot : false
81
+
74
82
priorityClassName : system-node-critical
75
83
76
84
# Revision is set as 'version' label and part of the resource names when installing multiple control planes.
Original file line number Diff line number Diff line change @@ -320,6 +320,11 @@ spec:
320
320
requests :
321
321
cpu : 100m
322
322
memory : 128Mi
323
+ securityContext :
324
+ runAsGroup : 0
325
+ runAsUser : 0
326
+ runAsNonRoot : false
327
+ allowPrivilegeEscalation : false
323
328
- name : taint-controller
324
329
image : " gcr.io/istio-testing/install-cni-taint:latest"
325
330
imagePullPolicy : Always
@@ -348,6 +353,7 @@ spec:
348
353
runAsGroup : 1337
349
354
runAsNonRoot : true
350
355
runAsUser : 1337
356
+ allowPrivilegeEscalation : false
351
357
nodeSelector :
352
358
kubernetes.io/os : linux
353
359
disktype : ssd
Original file line number Diff line number Diff line change 42
42
- name : taint-config-vol
43
43
mountPath : /etc/config
44
44
securityContext :
45
- runAsGroup : 1337
46
- runAsNonRoot : true
47
- runAsUser : 1337
45
+ allowPrivilegeEscalation : false
48
46
metadata :
49
47
annotations :
50
48
daemonset-annotation : value
113
111
cpu : 100m
114
112
memory : 128Mi
115
113
securityContext :
116
- runAsGroup : 1337
117
- runAsNonRoot : true
118
- runAsUser : 1337
114
+ allowPrivilegeEscalation : false
119
115
priorityClassName : system-node-critical
120
116
global :
121
117
hub : gcr.io/istio-testing
Original file line number Diff line number Diff line change 48
48
cpu : 100m
49
49
memory : 128Mi
50
50
securityContext :
51
- runAsUser : 1337
52
- runAsGroup : 1337
53
- runAsNonRoot : true
51
+ allowPrivilegeEscalation : false
54
52
volumeMounts :
55
53
- name : taint-config-vol
56
54
mountPath : /etc/config
@@ -133,7 +131,5 @@ spec:
133
131
cpu : 100m
134
132
memory : 128Mi
135
133
securityContext :
136
- runAsUser : 1337
137
- runAsGroup : 1337
138
- runAsNonRoot : true
134
+ allowPrivilegeEscalation : false
139
135
priorityClassName : system-node-critical
You can’t perform that action at this time.
0 commit comments