diff --git a/kubernetes-node-problem-detector/templates/bin/_node-problem-detector.sh.tpl b/kubernetes-node-problem-detector/templates/bin/_node-problem-detector.sh.tpl index 86b4ac08f..d0e4e27bc 100644 --- a/kubernetes-node-problem-detector/templates/bin/_node-problem-detector.sh.tpl +++ b/kubernetes-node-problem-detector/templates/bin/_node-problem-detector.sh.tpl @@ -15,7 +15,7 @@ limitations under the License. set -ex -exec /node-problem-detector \ +exec /opt/node-problem-detector/bin/node-problem-detector \ {{- range $monitor, $monitorConfig := .Values.conf.monitors }} {{- if $monitorConfig.enabled }} --config.{{$monitor}}={{ include "helm-toolkit.utils.joinListWithComma" $monitorConfig.enabled }} \ diff --git a/kubernetes-node-problem-detector/values.yaml b/kubernetes-node-problem-detector/values.yaml index 7ddb81eda..898edec3a 100644 --- a/kubernetes-node-problem-detector/values.yaml +++ b/kubernetes-node-problem-detector/values.yaml @@ -17,7 +17,7 @@ --- images: tags: - node_problem_detector: k8s.gcr.io/node-problem-detector:v0.7.0 + node_problem_detector: docker.io/openstackhelm/node-problem-detector:ubuntu_bionic-20200714 dep_check: quay.io/airshipit/kubernetes-entrypoint:v1.0.0 image_repo_sync: docker.io/docker:17.07.0 pull_policy: IfNotPresent diff --git a/kubernetes-node-problem-detector/values_overrides/apparmor.yaml b/kubernetes-node-problem-detector/values_overrides/apparmor.yaml new file mode 100644 index 000000000..fc134e69c --- /dev/null +++ b/kubernetes-node-problem-detector/values_overrides/apparmor.yaml @@ -0,0 +1,8 @@ +--- +pod: + mandatory_access_control: + type: apparmor + node-problem-detector: + node-problem-detector: runtime/default + init: runrtime/default +... diff --git a/tools/deployment/apparmor/115-node-problem-detector.sh b/tools/deployment/apparmor/115-node-problem-detector.sh new file mode 100644 index 000000000..885a5b468 --- /dev/null +++ b/tools/deployment/apparmor/115-node-problem-detector.sh @@ -0,0 +1 @@ +../osh-infra-monitoring/075-node-problem-detector.sh \ No newline at end of file