Merge "Add missing flags to nginx container in neutron chart"

This commit is contained in:
Zuul 2020-11-23 20:50:05 +00:00 committed by Gerrit Code Review
commit 0319e9192a
3 changed files with 7 additions and 2 deletions

View File

@ -14,7 +14,7 @@ apiVersion: v1
appVersion: v1.0.0 appVersion: v1.0.0
description: OpenStack-Helm Neutron description: OpenStack-Helm Neutron
name: neutron name: neutron
version: 0.1.4 version: 0.1.5
home: https://docs.openstack.org/neutron/latest/ home: https://docs.openstack.org/neutron/latest/
icon: https://www.openstack.org/themes/openstack/images/project-mascots/Neutron/OpenStack_Project_Neutron_vertical.png icon: https://www.openstack.org/themes/openstack/images/project-mascots/Neutron/OpenStack_Project_Neutron_vertical.png
sources: sources:

View File

@ -103,7 +103,7 @@ spec:
- name: nginx - name: nginx
{{ tuple $envAll "nginx" | include "helm-toolkit.snippets.image" | indent 10 }} {{ tuple $envAll "nginx" | include "helm-toolkit.snippets.image" | indent 10 }}
{{ tuple $envAll $envAll.Values.pod.resources.nginx | include "helm-toolkit.snippets.kubernetes_resources" | indent 10 }} {{ tuple $envAll $envAll.Values.pod.resources.nginx | include "helm-toolkit.snippets.kubernetes_resources" | indent 10 }}
{{ dict "envAll" $envAll "application" "neutron" "container" "nginx" | include "helm-toolkit.snippets.kubernetes_container_security_context" | indent 10 }} {{ dict "envAll" $envAll "application" "neutron_server" "container" "nginx" | include "helm-toolkit.snippets.kubernetes_container_security_context" | indent 10 }}
ports: ports:
- name: q-api - name: q-api
containerPort: {{ tuple "network" "internal" "api" . | include "helm-toolkit.endpoints.endpoint_port_lookup" }} containerPort: {{ tuple "network" "internal" "api" . | include "helm-toolkit.endpoints.endpoint_port_lookup" }}
@ -129,6 +129,8 @@ spec:
- /tmp/nginx.sh - /tmp/nginx.sh
- stop - stop
volumeMounts: volumeMounts:
- name: pod-tmp
mountPath: /tmp
- name: neutron-bin - name: neutron-bin
mountPath: /tmp/nginx.sh mountPath: /tmp/nginx.sh
subPath: nginx.sh subPath: nginx.sh

View File

@ -516,6 +516,9 @@ pod:
pod: pod:
runAsUser: 42424 runAsUser: 42424
container: container:
nginx:
runAsUser: 0
readOnlyRootFilesystem: false
neutron_server: neutron_server:
allowPrivilegeEscalation: false allowPrivilegeEscalation: false
readOnlyRootFilesystem: true readOnlyRootFilesystem: true