Merge pull request #2422 from philipgough/ci-fix
ci: Add runAsGroup for blackbox exporter containers
This commit is contained in:
@@ -183,6 +183,7 @@ function(params) {
|
|||||||
} else {
|
} else {
|
||||||
runAsNonRoot: true,
|
runAsNonRoot: true,
|
||||||
runAsUser: 65534,
|
runAsUser: 65534,
|
||||||
|
runAsGroup: 65534,
|
||||||
allowPrivilegeEscalation: false,
|
allowPrivilegeEscalation: false,
|
||||||
readOnlyRootFilesystem: true,
|
readOnlyRootFilesystem: true,
|
||||||
capabilities: { drop: ['ALL'] },
|
capabilities: { drop: ['ALL'] },
|
||||||
@@ -205,6 +206,7 @@ function(params) {
|
|||||||
securityContext: {
|
securityContext: {
|
||||||
runAsNonRoot: true,
|
runAsNonRoot: true,
|
||||||
runAsUser: 65534,
|
runAsUser: 65534,
|
||||||
|
runAsGroup: 65534,
|
||||||
allowPrivilegeEscalation: false,
|
allowPrivilegeEscalation: false,
|
||||||
readOnlyRootFilesystem: true,
|
readOnlyRootFilesystem: true,
|
||||||
capabilities: { drop: ['ALL'] },
|
capabilities: { drop: ['ALL'] },
|
||||||
|
|||||||
@@ -48,6 +48,7 @@ spec:
|
|||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
readOnlyRootFilesystem: true
|
readOnlyRootFilesystem: true
|
||||||
|
runAsGroup: 65534
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
runAsUser: 65534
|
runAsUser: 65534
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
@@ -72,6 +73,7 @@ spec:
|
|||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
readOnlyRootFilesystem: true
|
readOnlyRootFilesystem: true
|
||||||
|
runAsGroup: 65534
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
runAsUser: 65534
|
runAsUser: 65534
|
||||||
terminationMessagePath: /dev/termination-log
|
terminationMessagePath: /dev/termination-log
|
||||||
|
|||||||
Reference in New Issue
Block a user