Skip to content
Snippets Groups Projects
Verified Commit c724d5ca authored by Martin Weise's avatar Martin Weise
Browse files

Fixed privilege escalation policies and shared volume storage class

parent 5a3da104
No related branches found
No related tags found
No related merge requests found
......@@ -31,6 +31,11 @@ spec:
- name: analyse-service
image: {{ .Values.analyseService.image.name }}
imagePullPolicy: {{ .Values.analyseService.image.pullPolicy | default "IfNotPresent" }}
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 5000
protocol: TCP
......
......@@ -3,7 +3,9 @@ kind: PersistentVolumeClaim
metadata:
name: data-db-shared
spec:
{{- if .Values.dataDbSidecar.persistence.storageClass }}
storageClassName: {{ .Values.dataDbSidecar.persistence.storageClass }}
{{- end }}
accessModes:
- ReadWriteMany
resources:
......
......@@ -34,6 +34,10 @@ spec:
securityContext:
runAsUser: 1000
runAsGroup: 1000
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 9099
protocol: TCP
......
......@@ -31,6 +31,11 @@ spec:
- name: search-service
image: {{ .Values.searchService.image.name }}
imagePullPolicy: {{ .Values.searchService.image.pullPolicy | default "IfNotPresent" }}
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 4000
protocol: TCP
......
......@@ -31,6 +31,11 @@ spec:
- name: ui
image: {{ .Values.ui.image.name }}
imagePullPolicy: {{ .Values.ui.image.pullPolicy | default "IfNotPresent" }}
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 3000
protocol: TCP
......
......@@ -31,6 +31,11 @@ spec:
- name: upload-service
image: {{ printf "%s/%s:%s" .Values.uploadService.image.registry .Values.uploadService.image.repository .Values.uploadService.image.tag }}
imagePullPolicy: {{ .Values.uploadService.image.pullPolicy | default "IfNotPresent" }}
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
env:
- name: AWS_ACCESS_KEY_ID
valueFrom:
......
......@@ -154,7 +154,7 @@ dataDb:
dataDbSidecar:
persistence:
storageClass: ""
storageClass:
searchdb:
fullnameOverride: search-db
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment