Merge pull request #2427 from philipgough/ci-fix-ksm
ci: Add runAsGroup for kube-state-metrics
This commit is contained in:
@@ -164,6 +164,9 @@ function(params) (import 'github.com/kubernetes/kube-state-metrics/jsonnet/kube-
|
|||||||
ports:: null,
|
ports:: null,
|
||||||
livenessProbe:: null,
|
livenessProbe:: null,
|
||||||
readinessProbe:: null,
|
readinessProbe:: null,
|
||||||
|
securityContext+: {
|
||||||
|
runAsGroup: 65534,
|
||||||
|
},
|
||||||
args: ['--host=127.0.0.1', '--port=8081', '--telemetry-host=127.0.0.1', '--telemetry-port=8082'],
|
args: ['--host=127.0.0.1', '--port=8081', '--telemetry-host=127.0.0.1', '--telemetry-port=8082'],
|
||||||
resources: ksm._config.resources,
|
resources: ksm._config.resources,
|
||||||
}, super.containers) + [kubeRbacProxyMain, kubeRbacProxySelf],
|
}, super.containers) + [kubeRbacProxyMain, kubeRbacProxySelf],
|
||||||
|
|||||||
@@ -47,6 +47,7 @@ spec:
|
|||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
readOnlyRootFilesystem: true
|
readOnlyRootFilesystem: true
|
||||||
|
runAsGroup: 65534
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
runAsUser: 65534
|
runAsUser: 65534
|
||||||
seccompProfile:
|
seccompProfile:
|
||||||
|
|||||||
Reference in New Issue
Block a user