adding security context to kube-rbac-proxy (#450)
* adding security context to kube-rbac-proxy
* make clean generate-in-docker
* Revert "make clean generate-in-docker"
This reverts commit ed136f1e37.
* make clean generate-in-docker
Co-authored-by: Latch M <latch_mihaylov@homedepot.com>
This commit is contained in:
@@ -35,6 +35,7 @@ local containerPort = container.portsType;
|
|||||||
spec+: {
|
spec+: {
|
||||||
containers+: [
|
containers+: [
|
||||||
container.new(krp.config.kubeRbacProxy.name, krp.config.kubeRbacProxy.image) +
|
container.new(krp.config.kubeRbacProxy.name, krp.config.kubeRbacProxy.image) +
|
||||||
|
container.mixin.securityContext.withRunAsUser(65534) +
|
||||||
container.withArgs([
|
container.withArgs([
|
||||||
'--logtostderr',
|
'--logtostderr',
|
||||||
'--secure-listen-address=' + krp.config.kubeRbacProxy.secureListenAddress,
|
'--secure-listen-address=' + krp.config.kubeRbacProxy.secureListenAddress,
|
||||||
|
|||||||
@@ -37,6 +37,8 @@ spec:
|
|||||||
ports:
|
ports:
|
||||||
- containerPort: 8443
|
- containerPort: 8443
|
||||||
name: https-main
|
name: https-main
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 65534
|
||||||
- args:
|
- args:
|
||||||
- --logtostderr
|
- --logtostderr
|
||||||
- --secure-listen-address=:9443
|
- --secure-listen-address=:9443
|
||||||
@@ -47,6 +49,8 @@ spec:
|
|||||||
ports:
|
ports:
|
||||||
- containerPort: 9443
|
- containerPort: 9443
|
||||||
name: https-self
|
name: https-self
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 65534
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
kubernetes.io/os: linux
|
kubernetes.io/os: linux
|
||||||
serviceAccountName: kube-state-metrics
|
serviceAccountName: kube-state-metrics
|
||||||
|
|||||||
Reference in New Issue
Block a user