Skip to content
Snippets Groups Projects
Commit 75537658 authored by OZGCloud's avatar OZGCloud
Browse files

add securityContext fsGroup and capabilities

parent aa7b6454
No related branches found
No related tags found
No related merge requests found
......@@ -183,6 +183,13 @@ spec:
{{- with (.Values.securityContext).runAsGroup }}
runAsGroup: {{ . }}
{{- end }}
{{- with (.Values.securityContext).fsGroup }}
fsGroup: {{ . }}
{{- end }}
{{- with (.Values.securityContext).capabilities }}
capabilities:
{{ toYaml . | indent 12 }}
{{- end }}
stdin: true
terminationMessagePath: /dev/termination-log
terminationMessagePolicy: File
......
......@@ -56,6 +56,10 @@ tests:
path: spec.template.spec.containers[0].securityContext.runAsUser
- isNull:
path: spec.template.spec.containers[0].securityContext.runAsGroup
- isNull:
path: spec.template.spec.containers[0].securityContext.fsGroup
- isNull:
path: spec.template.spec.containers[0].securityContext.capabilities
- it: check runAsUser
set:
securityContext.runAsUser: 1000
......@@ -69,4 +73,23 @@ tests:
asserts:
- equal:
path: spec.template.spec.containers[0].securityContext.runAsGroup
value: 1000
\ No newline at end of file
value: 1000
- it: check fsGroup
set:
securityContext.fsGroup: 1000
asserts:
- equal:
path: spec.template.spec.containers[0].securityContext.fsGroup
value: 1000
- it: check capabilities
set:
securityContext:
capabilities:
drop:
- ALL
asserts:
- equal:
path: spec.template.spec.containers[0].securityContext.capabilities
value:
drop:
- ALL
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment