Skip to content

Commit 7afd248

Browse files
Merge pull request #1073 from javanthropus/add-security-context
Lock down package server runtime environment
2 parents a7ba0e7 + 06faf2d commit 7afd248

File tree

3 files changed

+19
-1
lines changed

3 files changed

+19
-1
lines changed

deploy/chart/templates/_packageserver.deployment-spec.yaml

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,5 +60,15 @@ spec:
6060
{{- if .Values.package.resources }}
6161
resources:
6262
{{ toYaml .Values.package.resources | indent 10 }}
63-
{{- end}}
63+
{{- end }}
64+
{{- if .Values.package.securityContext }}
65+
securityContext:
66+
runAsUser: {{ .Values.package.securityContext.runAsUser }}
67+
{{- end }}
68+
volumeMounts:
69+
- name: tmpfs
70+
mountPath: /tmp
71+
volumes:
72+
- name: tmpfs
73+
emptyDir: {}
6474
{{- end -}}

deploy/upstream/values.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,5 +27,7 @@ package:
2727
pullPolicy: Always
2828
service:
2929
internalPort: 5443
30+
securityContext:
31+
runAsUser: 1000
3032
catalog_sources:
3133
- rh-operators

manifests/0000_50_olm_15-packageserver.clusterserviceversion.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -123,6 +123,12 @@ spec:
123123
requests:
124124
cpu: 10m
125125
memory: 50Mi
126+
volumeMounts:
127+
- name: tmpfs
128+
mountPath: /tmp
129+
volumes:
130+
- name: tmpfs
131+
emptyDir: {}
126132
maturity: alpha
127133
version: 0.14.1
128134
apiservicedefinitions:

0 commit comments

Comments
 (0)