Skip to content

Commit 882c8b4

Browse files
authored
Merge pull request #1433 from umagnus/version_security_context
fix: shield guard issues in latest 2 versions
2 parents d4ab2f0 + 7228ba2 commit 882c8b4

File tree

7 files changed

+80
-0
lines changed

7 files changed

+80
-0
lines changed
30 Bytes
Binary file not shown.

charts/v1.22.6/blob-csi-driver/templates/csi-blob-controller.yaml

+16
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,10 @@ spec:
8181
- mountPath: /csi
8282
name: socket-dir
8383
resources: {{- toYaml .Values.controller.resources.csiProvisioner | nindent 12 }}
84+
securityContext:
85+
capabilities:
86+
drop:
87+
- ALL
8488
- name: liveness-probe
8589
{{- if hasPrefix "/" .Values.image.livenessProbe.repository }}
8690
image: "{{ .Values.image.baseRepo }}{{ .Values.image.livenessProbe.repository }}:{{ .Values.image.livenessProbe.tag }}"
@@ -96,6 +100,10 @@ spec:
96100
- name: socket-dir
97101
mountPath: /csi
98102
resources: {{- toYaml .Values.controller.resources.livenessProbe | nindent 12 }}
103+
securityContext:
104+
capabilities:
105+
drop:
106+
- ALL
99107
- name: blob
100108
{{- if hasPrefix "/" .Values.image.blob.repository }}
101109
image: "{{ .Values.image.baseRepo }}{{ .Values.image.blob.repository }}:{{ .Values.image.blob.tag }}"
@@ -170,6 +178,10 @@ spec:
170178
readOnly: true
171179
{{- end }}
172180
resources: {{- toYaml .Values.controller.resources.blob | nindent 12 }}
181+
securityContext:
182+
capabilities:
183+
drop:
184+
- ALL
173185
- name: csi-resizer
174186
{{- if hasPrefix "/" .Values.image.csiResizer.repository }}
175187
image: "{{ .Values.image.baseRepo }}{{ .Values.image.csiResizer.repository }}:{{ .Values.image.csiResizer.tag }}"
@@ -190,6 +202,10 @@ spec:
190202
- name: socket-dir
191203
mountPath: /csi
192204
resources: {{- toYaml .Values.controller.resources.csiResizer | nindent 12 }}
205+
securityContext:
206+
capabilities:
207+
drop:
208+
- ALL
193209
volumes:
194210
- name: socket-dir
195211
emptyDir: {}
27 Bytes
Binary file not shown.

charts/v1.24.1/blob-csi-driver/templates/csi-blob-controller.yaml

+16
Original file line numberDiff line numberDiff line change
@@ -82,6 +82,10 @@ spec:
8282
- mountPath: /csi
8383
name: socket-dir
8484
resources: {{- toYaml .Values.controller.resources.csiProvisioner | nindent 12 }}
85+
securityContext:
86+
capabilities:
87+
drop:
88+
- ALL
8589
- name: liveness-probe
8690
{{- if hasPrefix "/" .Values.image.livenessProbe.repository }}
8791
image: "{{ .Values.image.baseRepo }}{{ .Values.image.livenessProbe.repository }}:{{ .Values.image.livenessProbe.tag }}"
@@ -101,6 +105,10 @@ spec:
101105
- name: socket-dir
102106
mountPath: /csi
103107
resources: {{- toYaml .Values.controller.resources.livenessProbe | nindent 12 }}
108+
securityContext:
109+
capabilities:
110+
drop:
111+
- ALL
104112
- name: blob
105113
{{- if hasPrefix "/" .Values.image.blob.repository }}
106114
image: "{{ .Values.image.baseRepo }}{{ .Values.image.blob.repository }}:{{ .Values.image.blob.tag }}"
@@ -182,6 +190,10 @@ spec:
182190
readOnly: true
183191
{{- end }}
184192
resources: {{- toYaml .Values.controller.resources.blob | nindent 12 }}
193+
securityContext:
194+
capabilities:
195+
drop:
196+
- ALL
185197
- name: csi-resizer
186198
{{- if hasPrefix "/" .Values.image.csiResizer.repository }}
187199
image: "{{ .Values.image.baseRepo }}{{ .Values.image.csiResizer.repository }}:{{ .Values.image.csiResizer.tag }}"
@@ -202,6 +214,10 @@ spec:
202214
- name: socket-dir
203215
mountPath: /csi
204216
resources: {{- toYaml .Values.controller.resources.csiResizer | nindent 12 }}
217+
securityContext:
218+
capabilities:
219+
drop:
220+
- ALL
205221
volumes:
206222
- name: socket-dir
207223
emptyDir: {}

deploy/csi-blob-controller.yaml

+16
Original file line numberDiff line numberDiff line change
@@ -57,6 +57,10 @@ spec:
5757
requests:
5858
cpu: 10m
5959
memory: 20Mi
60+
securityContext:
61+
capabilities:
62+
drop:
63+
- ALL
6064
- name: liveness-probe
6165
image: mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.12.0
6266
args:
@@ -72,6 +76,10 @@ spec:
7276
requests:
7377
cpu: 10m
7478
memory: 20Mi
79+
securityContext:
80+
capabilities:
81+
drop:
82+
- ALL
7583
- name: blob
7684
image: mcr.microsoft.com/k8s/csi/blob-csi:latest
7785
imagePullPolicy: IfNotPresent
@@ -113,6 +121,10 @@ spec:
113121
requests:
114122
cpu: 10m
115123
memory: 20Mi
124+
securityContext:
125+
capabilities:
126+
drop:
127+
- ALL
116128
- name: csi-resizer
117129
image: mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.10.1
118130
args:
@@ -133,6 +145,10 @@ spec:
133145
requests:
134146
cpu: 10m
135147
memory: 20Mi
148+
securityContext:
149+
capabilities:
150+
drop:
151+
- ALL
136152
volumes:
137153
- name: socket-dir
138154
emptyDir: {}

deploy/v1.22.6/csi-blob-controller.yaml

+16
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,10 @@ spec:
5656
requests:
5757
cpu: 10m
5858
memory: 20Mi
59+
securityContext:
60+
capabilities:
61+
drop:
62+
- ALL
5963
- name: liveness-probe
6064
image: mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.10.0
6165
args:
@@ -71,6 +75,10 @@ spec:
7175
requests:
7276
cpu: 10m
7377
memory: 20Mi
78+
securityContext:
79+
capabilities:
80+
drop:
81+
- ALL
7482
- name: blob
7583
image: mcr.microsoft.com/oss/kubernetes-csi/blob-csi:v1.22.6
7684
imagePullPolicy: IfNotPresent
@@ -114,6 +122,10 @@ spec:
114122
requests:
115123
cpu: 10m
116124
memory: 20Mi
125+
securityContext:
126+
capabilities:
127+
drop:
128+
- ALL
117129
- name: csi-resizer
118130
image: mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.8.0
119131
args:
@@ -134,6 +146,10 @@ spec:
134146
requests:
135147
cpu: 10m
136148
memory: 20Mi
149+
securityContext:
150+
capabilities:
151+
drop:
152+
- ALL
137153
volumes:
138154
- name: socket-dir
139155
emptyDir: {}

deploy/v1.24.1/csi-blob-controller.yaml

+16
Original file line numberDiff line numberDiff line change
@@ -57,6 +57,10 @@ spec:
5757
requests:
5858
cpu: 10m
5959
memory: 20Mi
60+
securityContext:
61+
capabilities:
62+
drop:
63+
- ALL
6064
- name: liveness-probe
6165
image: mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.12.0
6266
args:
@@ -72,6 +76,10 @@ spec:
7276
requests:
7377
cpu: 10m
7478
memory: 20Mi
79+
securityContext:
80+
capabilities:
81+
drop:
82+
- ALL
7583
- name: blob
7684
image: mcr.microsoft.com/oss/kubernetes-csi/blob-csi:v1.24.1
7785
imagePullPolicy: IfNotPresent
@@ -113,6 +121,10 @@ spec:
113121
requests:
114122
cpu: 10m
115123
memory: 20Mi
124+
securityContext:
125+
capabilities:
126+
drop:
127+
- ALL
116128
- name: csi-resizer
117129
image: mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.10.1
118130
args:
@@ -133,6 +145,10 @@ spec:
133145
requests:
134146
cpu: 10m
135147
memory: 20Mi
148+
securityContext:
149+
capabilities:
150+
drop:
151+
- ALL
136152
volumes:
137153
- name: socket-dir
138154
emptyDir: {}

0 commit comments

Comments
 (0)