Skip to content

Commit 92df8ef

Browse files
seccomp profile
1 parent 9dcc72f commit 92df8ef

File tree

4 files changed

+12
-0
lines changed

4 files changed

+12
-0
lines changed

charts/primary-site/templates/cronjobs/garbage-collector.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,10 +34,16 @@ spec:
3434
- name: garbage-collector
3535
image: {{ .Values.garbageCollector.deployment.image }}:{{ .Chart.AppVersion }}
3636
securityContext:
37+
readOnlyRootFilesystem: true
38+
capabilities:
39+
drop:
40+
- ALL
3741
allowPrivilegeEscalation: false
3842
runAsNonRoot: true
3943
runAsUser: 65534
4044
runAsGroup: 65534
45+
seccompProfile:
46+
type: RuntimeDefault
4147
volumeMounts:
4248
- mountPath: /secrets
4349
name: cloud-credentials

charts/primary-site/templates/deployments/_inbox-container.tpl

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,8 @@ template:
4949
runAsNonRoot: true
5050
runAsUser: 65534
5151
runAsGroup: 65534
52+
seccompProfile:
53+
type: RuntimeDefault
5254
resources:
5355
requests:
5456
cpu: {{ .Values.inboxListener.deployment.resources.requests.cpu }}

charts/primary-site/templates/deployments/query-server.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -52,6 +52,8 @@ spec:
5252
runAsNonRoot: true
5353
runAsUser: 65534
5454
runAsGroup: 65534
55+
seccompProfile:
56+
type: RuntimeDefault
5557
resources:
5658
requests:
5759
cpu: {{ $values.deployment.resources.requests.cpu }}

charts/primary-site/templates/deployments/site-controller.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,8 @@ spec:
4444
runAsNonRoot: true
4545
runAsUser: 65534
4646
runAsGroup: 65534
47+
seccompProfile:
48+
type: RuntimeDefault
4749
resources:
4850
requests:
4951
cpu: {{ .Values.siteController.deployment.resources.requests.cpu }}

0 commit comments

Comments
 (0)