adding security context to kube-rbac-proxy (#450)

* adding security context to kube-rbac-proxy

* make clean generate-in-docker

* Revert "make clean generate-in-docker"

This reverts commit ed136f1e37fde3289b9560493a585c6edefaba94.

* make clean generate-in-docker

Co-authored-by: Latch M <latch_mihaylov@homedepot.com>
This commit is contained in:
Latch Mihay 2020-03-18 02:52:26 -04:00 committed by GitHub
parent 502f81b235
commit c4561b3206
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 5 additions and 0 deletions

View File

@ -35,6 +35,7 @@ local containerPort = container.portsType;
spec+: {
containers+: [
container.new(krp.config.kubeRbacProxy.name, krp.config.kubeRbacProxy.image) +
container.mixin.securityContext.withRunAsUser(65534) +
container.withArgs([
'--logtostderr',
'--secure-listen-address=' + krp.config.kubeRbacProxy.secureListenAddress,

View File

@ -37,6 +37,8 @@ spec:
ports:
- containerPort: 8443
name: https-main
securityContext:
runAsUser: 65534
- args:
- --logtostderr
- --secure-listen-address=:9443
@ -47,6 +49,8 @@ spec:
ports:
- containerPort: 9443
name: https-self
securityContext:
runAsUser: 65534
nodeSelector:
kubernetes.io/os: linux
serviceAccountName: kube-state-metrics