Skip to content

Commit cee2c1d

Browse files
Fix pss restricted warnings (kserve#4327)
Signed-off-by: Harshvir Potpose <hpotpose62@gmail.com> Co-authored-by: Sivanantham <90966311+sivanantha321@users.noreply.github.com>
1 parent 6f9057d commit cee2c1d

File tree

6 files changed

+11
-1
lines changed

6 files changed

+11
-1
lines changed

charts/kserve-resources/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ $ helm install kserve oci://ghcr.io/kserve/charts/kserve --version v0.15.2
5757
| kserve.controller.rbacProxy.securityContext.runAsNonRoot | bool | `true` | |
5858
| kserve.controller.rbacProxyImage | string | `"quay.io/brancz/kube-rbac-proxy:v0.18.0"` | KServe controller manager rbac proxy contrainer image |
5959
| kserve.controller.resources | object | `{"limits":{"cpu":"100m","memory":"300Mi"},"requests":{"cpu":"100m","memory":"300Mi"}}` | Resources to provide to the kserve controller pod. For example: requests: cpu: 10m memory: 32Mi For more information, see [Resource Management for Pods and Containers](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/). |
60-
| kserve.controller.securityContext | object | `{"runAsNonRoot":true}` | Pod Security Context. For more information, see [Configure a Security Context for a Pod or Container](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/). |
60+
| kserve.controller.securityContext | object | `{"runAsNonRoot":true,"seccompProfile":{"type":"RuntimeDefault"}}` | Pod Security Context. For more information, see [Configure a Security Context for a Pod or Container](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/). |
6161
| kserve.controller.serviceAnnotations | object | `{}` | Optional additional annotations to add to the controller service. |
6262
| kserve.controller.tag | string | `"v0.15.2"` | KServe controller contrainer image tag. |
6363
| kserve.controller.tolerations | list | `[]` | A list of Kubernetes Tolerations, if required. For more information, see [Toleration v1 core](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#toleration-v1-core). For example: tolerations: - key: foo.bar.com/role operator: Equal value: master effect: NoSchedule |

charts/kserve-resources/templates/localmodel/deployment.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,8 @@ spec:
2626
serviceAccountName: kserve-localmodel-controller-manager
2727
securityContext:
2828
runAsNonRoot: true
29+
seccompProfile:
30+
type: RuntimeDefault
2931
containers:
3032
- command:
3133
- /manager

charts/kserve-resources/values.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -129,6 +129,8 @@ kserve:
129129
# For more information, see [Configure a Security Context for a Pod or Container](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/).
130130
securityContext:
131131
runAsNonRoot: true
132+
seccompProfile:
133+
type: RuntimeDefault
132134

133135
# -- Container Security Context to be set on the controller component container.
134136
# For more information, see [Configure a Security Context for a Pod or Container](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/).

config/localmodelnodes/manager.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,8 @@ spec:
2626
serviceAccountName: kserve-localmodelnode-agent
2727
securityContext:
2828
runAsNonRoot: true
29+
seccompProfile:
30+
type: RuntimeDefault
2931
containers:
3032
- command:
3133
- /manager

config/localmodels/manager.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,8 @@ spec:
2424
serviceAccountName: kserve-localmodel-controller-manager
2525
securityContext:
2626
runAsNonRoot: true
27+
seccompProfile:
28+
type: RuntimeDefault
2729
containers:
2830
- command:
2931
- /manager

config/manager/manager.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,8 @@ spec:
2424
serviceAccountName: kserve-controller-manager
2525
securityContext:
2626
runAsNonRoot: true
27+
seccompProfile:
28+
type: RuntimeDefault
2729
containers:
2830
- command:
2931
- /manager

0 commit comments

Comments
 (0)