mirror of
				https://github.com/prometheus-operator/kube-prometheus.git
				synced 2025-11-04 01:51:01 +01:00 
			
		
		
		
	Merge pull request #1608 from ArthurSens/as/fixme
This commit is contained in:
		
						commit
						6bfb07aac2
					
				@ -118,9 +118,6 @@ function(params) (import 'github.com/kubernetes/kube-state-metrics/jsonnet/kube-
 | 
				
			|||||||
    image: ksm._config.kubeRbacProxyImage,
 | 
					    image: ksm._config.kubeRbacProxyImage,
 | 
				
			||||||
  }),
 | 
					  }),
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  // FIXME(ArthurSens): The securityContext overrides can be removed after some PRs get merged
 | 
					 | 
				
			||||||
  // 'allowPrivilegeEscalation: false' can be deleted when https://github.com/kubernetes/kube-state-metrics/pull/1668 gets merged.
 | 
					 | 
				
			||||||
  // 'readOnlyRootFilesystem: true' can be deleted when https://github.com/kubernetes/kube-state-metrics/pull/1671 gets merged.
 | 
					 | 
				
			||||||
  deployment+: {
 | 
					  deployment+: {
 | 
				
			||||||
    spec+: {
 | 
					    spec+: {
 | 
				
			||||||
      template+: {
 | 
					      template+: {
 | 
				
			||||||
@ -136,10 +133,6 @@ function(params) (import 'github.com/kubernetes/kube-state-metrics/jsonnet/kube-
 | 
				
			|||||||
            readinessProbe:: null,
 | 
					            readinessProbe:: null,
 | 
				
			||||||
            args: ['--host=127.0.0.1', '--port=8081', '--telemetry-host=127.0.0.1', '--telemetry-port=8082'],
 | 
					            args: ['--host=127.0.0.1', '--port=8081', '--telemetry-host=127.0.0.1', '--telemetry-port=8082'],
 | 
				
			||||||
            resources: ksm._config.resources,
 | 
					            resources: ksm._config.resources,
 | 
				
			||||||
            securityContext+: {
 | 
					 | 
				
			||||||
              allowPrivilegeEscalation: false,
 | 
					 | 
				
			||||||
              readOnlyRootFilesystem: true,
 | 
					 | 
				
			||||||
            },
 | 
					 | 
				
			||||||
          }, super.containers) + [kubeRbacProxyMain, kubeRbacProxySelf],
 | 
					          }, super.containers) + [kubeRbacProxyMain, kubeRbacProxySelf],
 | 
				
			||||||
        },
 | 
					        },
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
 | 
				
			|||||||
@ -125,17 +125,11 @@ function(params)
 | 
				
			|||||||
      image: po._config.kubeRbacProxyImage,
 | 
					      image: po._config.kubeRbacProxyImage,
 | 
				
			||||||
    }),
 | 
					    }),
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    // FIXME(ArthurSens): The securityContext overrides can be removed after some PRs get merged
 | 
					 | 
				
			||||||
    // 'readOnlyRootFilesystem: true' can be deleted when https://github.com/prometheus-operator/prometheus-operator/pull/4531 gets merged.
 | 
					 | 
				
			||||||
    deployment+: {
 | 
					    deployment+: {
 | 
				
			||||||
      spec+: {
 | 
					      spec+: {
 | 
				
			||||||
        template+: {
 | 
					        template+: {
 | 
				
			||||||
          spec+: {
 | 
					          spec+: {
 | 
				
			||||||
            containers: std.map(function(c) c {
 | 
					            containers+: [kubeRbacProxy],
 | 
				
			||||||
              securityContext+: {
 | 
					 | 
				
			||||||
                readOnlyRootFilesystem: true,
 | 
					 | 
				
			||||||
              },
 | 
					 | 
				
			||||||
            }, super.containers) + [kubeRbacProxy],
 | 
					 | 
				
			||||||
          },
 | 
					          },
 | 
				
			||||||
        },
 | 
					        },
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
 | 
				
			|||||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user