Merge pull request #65 from blurpy/filesys_and_role

Fix issue with readOnlyRootFilesystem and statefulsets permissions
This commit is contained in:
Ali Kahoot
2019-06-11 12:13:13 +05:00
committed by GitHub
7 changed files with 62 additions and 12 deletions
@@ -15,7 +15,7 @@ metadata:
rules:
- apiGroups:
- ""
resources:
resources:
- secrets
- configmaps
verbs:
@@ -23,7 +23,6 @@ rules:
- get
- watch
- apiGroups:
- "extensions"
- "apps"
resources:
- deployments
@@ -34,4 +33,14 @@ rules:
- get
- update
- patch
- apiGroups:
- "extensions"
resources:
- deployments
- daemonsets
verbs:
- list
- get
- update
- patch
{{- end }}
@@ -70,6 +70,11 @@ spec:
image: "{{ .Values.reloader.deployment.image.name }}:{{ .Values.reloader.deployment.image.tag }}"
imagePullPolicy: {{ .Values.reloader.deployment.image.pullPolicy }}
name: {{ template "reloader-name" . }}
{{- if eq .Values.reloader.readOnlyRootFileSystem true }}
volumeMounts:
- mountPath: /tmp/
name: tmp-volume
{{- end }}
{{- if .Values.reloader.custom_annotations }}
args:
{{- if .Values.reloader.custom_annotations.configmap }}
@@ -86,3 +91,8 @@ spec:
{{- end }}
{{- end }}
serviceAccountName: {{ template "reloader-serviceAccountName" . }}
{{- if eq .Values.reloader.readOnlyRootFileSystem true }}
volumes:
- emptyDir: {}
name: tmp-volume
{{- end }}
@@ -15,7 +15,7 @@ metadata:
rules:
- apiGroups:
- ""
resources:
resources:
- secrets
- configmaps
verbs:
@@ -23,7 +23,6 @@ rules:
- get
- watch
- apiGroups:
- "extensions"
- "apps"
resources:
- deployments
@@ -34,4 +33,14 @@ rules:
- get
- update
- patch
- apiGroups:
- "extensions"
resources:
- deployments
- daemonsets
verbs:
- list
- get
- update
- patch
{{- end }}
@@ -5,6 +5,8 @@ kubernetes:
reloader:
watchGlobally: true
# Set to true if you have a pod security policy that enforces readOnlyRootFilesystem
readOnlyRootFileSystem: false
matchLabels: {}
deployment:
annotations: {}
@@ -40,4 +42,4 @@ reloader:
# custom_annotations:
# configmap: "my.company.com/configmap"
# secret: "my.company.com/secret"
custom_annotations: {}
custom_annotations: {}
@@ -14,7 +14,7 @@ metadata:
rules:
- apiGroups:
- ""
resources:
resources:
- secrets
- configmaps
verbs:
@@ -22,7 +22,6 @@ rules:
- get
- watch
- apiGroups:
- "extensions"
- "apps"
resources:
- deployments
@@ -33,4 +32,14 @@ rules:
- get
- update
- patch
- apiGroups:
- "extensions"
resources:
- deployments
- daemonsets
verbs:
- list
- get
- update
- patch
+13 -4
View File
@@ -15,7 +15,7 @@ metadata:
group: com.stakater.platform
provider: stakater
version: v0.0.29
name: reloader
spec:
replicas: 1
@@ -34,7 +34,7 @@ spec:
group: com.stakater.platform
provider: stakater
version: v0.0.29
spec:
containers:
- env:
@@ -59,7 +59,7 @@ metadata:
rules:
- apiGroups:
- ""
resources:
resources:
- secrets
- configmaps
verbs:
@@ -67,7 +67,6 @@ rules:
- get
- watch
- apiGroups:
- "extensions"
- "apps"
resources:
- deployments
@@ -78,6 +77,16 @@ rules:
- get
- update
- patch
- apiGroups:
- "extensions"
resources:
- deployments
- daemonsets
verbs:
- list
- get
- update
- patch
---
# Source: reloader/templates/rolebinding.yaml
@@ -5,6 +5,8 @@ kubernetes:
reloader:
watchGlobally: true
# Set to true if you have a pod security policy that enforces readOnlyRootFilesystem
readOnlyRootFileSystem: false
matchLabels: {}
deployment:
annotations: {}
@@ -40,4 +42,4 @@ reloader:
# custom_annotations:
# configmap: "my.company.com/configmap"
# secret: "my.company.com/secret"
custom_annotations: {}
custom_annotations: {}