Skip to content

Commit 751bf09

Browse files
authored
Merge pull request #978 from NVIDIA/no-privileged-toolkit-validation
disable privileged mode for toolkit-validation init containers
2 parents 5b18e60 + dc1ea09 commit 751bf09

File tree

7 files changed

+1
-15
lines changed

7 files changed

+1
-15
lines changed

assets/gpu-feature-discovery/0500_daemonset.yaml

+1-3
Original file line numberDiff line numberDiff line change
@@ -30,12 +30,10 @@ spec:
3030
image: "FILLED BY THE OPERATOR"
3131
command: ['sh', '-c']
3232
args: ["until [ -f /run/nvidia/validations/toolkit-ready ]; do echo waiting for nvidia container stack to be setup; sleep 5; done"]
33-
securityContext:
34-
privileged: true
3533
volumeMounts:
3634
- name: run-nvidia
3735
mountPath: /run/nvidia
38-
mountPropagation: Bidirectional
36+
mountPropagation: HostToContainer
3937
- name: config-manager-init
4038
image: "FILLED BY THE OPERATOR"
4139
command: ["config-manager"]

assets/state-dcgm-exporter/0900_daemonset.yaml

-2
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,6 @@ spec:
2929
image: "FILLED BY THE OPERATOR"
3030
command: ['sh', '-c']
3131
args: ["until [ -f /run/nvidia/validations/toolkit-ready ]; do echo waiting for nvidia container stack to be setup; sleep 5; done"]
32-
securityContext:
33-
privileged: true
3432
volumeMounts:
3533
- name: run-nvidia
3634
mountPath: "/run/nvidia"

assets/state-dcgm/0400_dcgm.yml

-2
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,6 @@ spec:
2929
image: "FILLED BY THE OPERATOR"
3030
command: ['sh', '-c']
3131
args: ["until [ -f /run/nvidia/validations/toolkit-ready ]; do echo waiting for nvidia container stack to be setup; sleep 5; done"]
32-
securityContext:
33-
privileged: true
3432
volumeMounts:
3533
- name: run-nvidia
3634
mountPath: /run/nvidia

assets/state-device-plugin/0500_daemonset.yaml

-2
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,6 @@ spec:
2929
name: toolkit-validation
3030
command: ['sh', '-c']
3131
args: ["until [ -f /run/nvidia/validations/toolkit-ready ]; do echo waiting for nvidia container stack to be setup; sleep 5; done"]
32-
securityContext:
33-
privileged: true
3432
volumeMounts:
3533
- name: run-nvidia-validations
3634
mountPath: /run/nvidia/validations

assets/state-mig-manager/0600_daemonset.yaml

-2
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,6 @@ spec:
2929
image: "FILLED BY THE OPERATOR"
3030
command: ['sh', '-c']
3131
args: ["until [ -f /run/nvidia/validations/toolkit-ready ]; do echo waiting for nvidia container toolkit to be setup; sleep 5; done"]
32-
securityContext:
33-
privileged: true
3432
volumeMounts:
3533
- name: run-nvidia-validations
3634
mountPath: /run/nvidia/validations

assets/state-mps-control-daemon/0400_daemonset.yaml

-2
Original file line numberDiff line numberDiff line change
@@ -30,8 +30,6 @@ spec:
3030
name: toolkit-validation
3131
command: ['sh', '-c']
3232
args: ["until [ -f /run/nvidia/validations/toolkit-ready ]; do echo waiting for nvidia container stack to be setup; sleep 5; done"]
33-
securityContext:
34-
privileged: true
3533
volumeMounts:
3634
- name: run-nvidia
3735
mountPath: /run/nvidia

assets/state-sandbox-device-plugin/0500_daemonset.yaml

-2
Original file line numberDiff line numberDiff line change
@@ -35,8 +35,6 @@ spec:
3535
env:
3636
- name: NVIDIA_VISIBLE_DEVICES
3737
value: void
38-
securityContext:
39-
privileged: true
4038
volumeMounts:
4139
- name: run-nvidia-validations
4240
mountPath: /run/nvidia/validations

0 commit comments

Comments
 (0)