Fix placement of privilege escalation in Glance.
In a previous patch set (https://review.openstack.org/#/c/629300/), the "allowPrivilegeEscalation" flag was set to false for one of the init containers, but it was intended to be used for the glance-api container. Change-Id: If2d83d82a720d7a1a39729bbf3bddc226af3ba20
This commit is contained in:
parent
00fff1d274
commit
d0a93d3370
@ -71,8 +71,6 @@ spec:
|
||||
{{ if eq .Values.storage "rbd" }}
|
||||
- name: ceph-keyring-placement
|
||||
{{ tuple $envAll "glance_api" | include "helm-toolkit.snippets.image" | indent 10 }}
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
env:
|
||||
- name: RBD_STORE_USER
|
||||
value: {{ .Values.conf.glance.glance_store.rbd_store_user | quote }}
|
||||
@ -94,6 +92,8 @@ spec:
|
||||
- name: glance-api
|
||||
{{ tuple $envAll "glance_api" | include "helm-toolkit.snippets.image" | indent 10 }}
|
||||
{{ tuple $envAll $envAll.Values.pod.resources.api | include "helm-toolkit.snippets.kubernetes_resources" | indent 10 }}
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
command:
|
||||
- /tmp/glance-api.sh
|
||||
- start
|
||||
|
Loading…
Reference in New Issue
Block a user