Skip to content
Snippets Groups Projects
Commit 0217e08b authored by OZG-Cloud Team's avatar OZG-Cloud Team
Browse files

add securityContext fsGroup

parent 2d6f1474
Branches
Tags
No related merge requests found
...@@ -139,9 +139,6 @@ spec: ...@@ -139,9 +139,6 @@ spec:
{{- with (.Values.securityContext).runAsGroup }} {{- with (.Values.securityContext).runAsGroup }}
runAsGroup: {{ . }} runAsGroup: {{ . }}
{{- end }} {{- end }}
{{- with (.Values.securityContext).fsGroup }}
fsGroup: {{ . }}
{{- end }}
{{- with (.Values.securityContext).capabilities }} {{- with (.Values.securityContext).capabilities }}
capabilities: capabilities:
{{ toYaml . | indent 12 }} {{ toYaml . | indent 12 }}
...@@ -170,5 +167,10 @@ spec: ...@@ -170,5 +167,10 @@ spec:
{{ toYaml . | indent 8 }} {{ toYaml . | indent 8 }}
{{- end }} {{- end }}
schedulerName: default-scheduler schedulerName: default-scheduler
{{- if (.Values.securityContext).fsGroup }}
securityContext:
fsGroup: {{ (.Values.securityContext).fsGroup }}
{{- else }}
securityContext: {} securityContext: {}
{{- end }}
terminationGracePeriodSeconds: 30 terminationGracePeriodSeconds: 30
\ No newline at end of file
...@@ -50,7 +50,7 @@ tests: ...@@ -50,7 +50,7 @@ tests:
- isNull: - isNull:
path: spec.template.spec.containers[0].securityContext.runAsGroup path: spec.template.spec.containers[0].securityContext.runAsGroup
- isNull: - isNull:
path: spec.template.spec.containers[0].securityContext.fsGroup path: spec.template.spec.securityContext.fsGroup
- isNull: - isNull:
path: spec.template.spec.containers[0].securityContext.capabilities path: spec.template.spec.containers[0].securityContext.capabilities
- it: check runAsUser - it: check runAsUser
...@@ -72,7 +72,7 @@ tests: ...@@ -72,7 +72,7 @@ tests:
securityContext.fsGroup: 1000 securityContext.fsGroup: 1000
asserts: asserts:
- equal: - equal:
path: spec.template.spec.containers[0].securityContext.fsGroup path: spec.template.spec.securityContext.fsGroup
value: 1000 value: 1000
- it: check capabilities - it: check capabilities
set: set:
......
...@@ -111,9 +111,6 @@ spec: ...@@ -111,9 +111,6 @@ spec:
{{- with (.Values.securityContext).runAsGroup }} {{- with (.Values.securityContext).runAsGroup }}
runAsGroup: {{ . }} runAsGroup: {{ . }}
{{- end }} {{- end }}
{{- with (.Values.securityContext).fsGroup }}
fsGroup: {{ . }}
{{- end }}
{{- with (.Values.securityContext).capabilities }} {{- with (.Values.securityContext).capabilities }}
capabilities: capabilities:
{{ toYaml . | indent 18 }} {{ toYaml . | indent 18 }}
...@@ -171,3 +168,9 @@ spec: ...@@ -171,3 +168,9 @@ spec:
{{ else }} {{ else }}
- name: {{ include "app.name" . }}-image-pull-secret - name: {{ include "app.name" . }}-image-pull-secret
{{- end }} {{- end }}
{{- if (.Values.securityContext).fsGroup }}
securityContext:
fsGroup: {{ (.Values.securityContext).fsGroup }}
{{- else }}
securityContext: {}
{{- end }}
\ No newline at end of file
...@@ -105,7 +105,7 @@ tests: ...@@ -105,7 +105,7 @@ tests:
- isNull: - isNull:
path: spec.jobTemplate.spec.template.spec.containers[0].securityContext.runAsGroup path: spec.jobTemplate.spec.template.spec.containers[0].securityContext.runAsGroup
- isNull: - isNull:
path: spec.jobTemplate.spec.template.spec.containers[0].securityContext.fsGroup path: spec.jobTemplate.spec.template.spec.securityContext.fsGroup
- isNull: - isNull:
path: spec.jobTemplate.spec.template.spec.containers[0].securityContext.capabilities path: spec.jobTemplate.spec.template.spec.containers[0].securityContext.capabilities
- it: check runAsUser - it: check runAsUser
...@@ -135,7 +135,7 @@ tests: ...@@ -135,7 +135,7 @@ tests:
securityContext.fsGroup: 1000 securityContext.fsGroup: 1000
asserts: asserts:
- equal: - equal:
path: spec.jobTemplate.spec.template.spec.containers[0].securityContext.fsGroup path: spec.jobTemplate.spec.template.spec.securityContext.fsGroup
value: 1000 value: 1000
- it: check capabilities - it: check capabilities
set: set:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment