chore(helm): Adding security context to pods

This commit is contained in:
rjshrjndrn 2022-11-03 04:00:12 +01:00
parent 2abf063ba2
commit f64582c173
17 changed files with 158 additions and 32 deletions

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -43,10 +43,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,14 +25,16 @@ serviceAccount:
podAnnotations: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# fsGroup: 2000
securityContext: {}
#securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -25,14 +25,16 @@ serviceAccount:
podAnnotations: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# fsGroup: 2000
securityContext: {}
#securityContext: {}
# capabilities:
# drop:
# - ALL

View file

@ -84,3 +84,13 @@ fullnameOverride: "utilities-openreplay"
# refer: https://crontab.guru/#5_3_*_*_1
cron: "5 3 */3 * *"
# Pod configurations
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"

View file

@ -25,10 +25,18 @@ serviceAccount:
podAnnotations: {}
podSecurityContext: {}
securityContext:
runAsUser: 1001
runAsGroup: 1001
podSecurityContext:
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
fsGroupChangePolicy: "OnRootMismatch"
# podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# securityContext: {}
# capabilities:
# drop:
# - ALL