Skip to content

Commit 4cb200a

Browse files
authored
Merge pull request #1424 from umagnus/security-context
fix: shield guard issues
2 parents 29948fb + a18b81c commit 4cb200a

File tree

2 files changed

+16
-0
lines changed

2 files changed

+16
-0
lines changed
25 Bytes
Binary file not shown.

charts/latest/blob-csi-driver/templates/csi-blob-controller.yaml

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -82,6 +82,10 @@ spec:
8282
- mountPath: /csi
8383
name: socket-dir
8484
resources: {{- toYaml .Values.controller.resources.csiProvisioner | nindent 12 }}
85+
securityContext:
86+
capabilities:
87+
drop:
88+
- ALL
8589
- name: liveness-probe
8690
{{- if hasPrefix "/" .Values.image.livenessProbe.repository }}
8791
image: "{{ .Values.image.baseRepo }}{{ .Values.image.livenessProbe.repository }}:{{ .Values.image.livenessProbe.tag }}"
@@ -101,6 +105,10 @@ spec:
101105
- name: socket-dir
102106
mountPath: /csi
103107
resources: {{- toYaml .Values.controller.resources.livenessProbe | nindent 12 }}
108+
securityContext:
109+
capabilities:
110+
drop:
111+
- ALL
104112
- name: blob
105113
{{- if hasPrefix "/" .Values.image.blob.repository }}
106114
image: "{{ .Values.image.baseRepo }}{{ .Values.image.blob.repository }}:{{ .Values.image.blob.tag }}"
@@ -182,6 +190,10 @@ spec:
182190
readOnly: true
183191
{{- end }}
184192
resources: {{- toYaml .Values.controller.resources.blob | nindent 12 }}
193+
securityContext:
194+
capabilities:
195+
drop:
196+
- ALL
185197
- name: csi-resizer
186198
{{- if hasPrefix "/" .Values.image.csiResizer.repository }}
187199
image: "{{ .Values.image.baseRepo }}{{ .Values.image.csiResizer.repository }}:{{ .Values.image.csiResizer.tag }}"
@@ -202,6 +214,10 @@ spec:
202214
- name: socket-dir
203215
mountPath: /csi
204216
resources: {{- toYaml .Values.controller.resources.csiResizer | nindent 12 }}
217+
securityContext:
218+
capabilities:
219+
drop:
220+
- ALL
205221
volumes:
206222
- name: socket-dir
207223
emptyDir: {}

0 commit comments

Comments
 (0)