Skip to content

Commit 8523487

Browse files
feat(cf-common): no podSecurityContext if enabled=false (#36)
1 parent 958499d commit 8523487

37 files changed

+258
-213
lines changed

charts/cf-common-test/tests/deployment/spec_test.yaml

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -215,3 +215,40 @@ tests:
215215
volumeMounts:
216216
- name: var-logs
217217
mountPath: /var/log
218+
219+
- it: Test pod security context
220+
values:
221+
- values.yaml
222+
asserts:
223+
- equal:
224+
path: spec.template.spec.securityContext
225+
value:
226+
runAsGroup: 0
227+
runAsNonRoot: true
228+
runAsUser: 1000
229+
fsGroup: 0
230+
231+
- it: Test disabled pod security context
232+
values:
233+
- values.yaml
234+
set:
235+
podSecurityContext:
236+
enabled: false
237+
asserts:
238+
- isNull:
239+
path: spec.template.spec.securityContext
240+
241+
- it: Test pod security context (omit enabled)
242+
values:
243+
- values.yaml
244+
set:
245+
podSecurityContext:
246+
enabled: true
247+
asserts:
248+
- equal:
249+
path: spec.template.spec.securityContext
250+
value:
251+
runAsGroup: 0
252+
runAsNonRoot: true
253+
runAsUser: 1000
254+
fsGroup: 0

charts/cf-common-test/tests/deployment/values.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,12 @@ controller:
1919
maxSurge: "50%"
2020
revisionHistoryLimit: 5
2121

22+
podSecurityContext:
23+
runAsGroup: 0
24+
runAsNonRoot: true
25+
runAsUser: 1000
26+
fsGroup: 0
27+
2228
container:
2329
image:
2430
registry: 839151377425.dkr.ecr.us-east-1.amazonaws.com/codefresh-inc

charts/cf-common/Chart.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ apiVersion: v2
22
appVersion: v0.0.0
33
description: Codefresh library chart
44
name: cf-common
5-
version: 0.5.2
5+
version: 0.6.0
66
type: library
77
keywords:
88
- codefresh

charts/cf-common/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
Codefresh library chart
44

5-
![Version: 0.5.2](https://img.shields.io/badge/Version-0.5.2-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: v0.0.0](https://img.shields.io/badge/AppVersion-v0.0.0-informational?style=flat-square)
5+
![Version: 0.6.0](https://img.shields.io/badge/Version-0.6.0-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: v0.0.0](https://img.shields.io/badge/AppVersion-v0.0.0-informational?style=flat-square)
66

77
## Installing the Chart
88

@@ -18,7 +18,7 @@ Include this chart as a dependency in your `Chart.yaml` e.g.
1818
# Chart.yaml
1919
dependencies:
2020
- name: cf-common
21-
version: 0.5.2
21+
version: 0.6.0
2222
repository: https://chartmuseum.codefresh.io/cf-common
2323
```
2424

charts/cf-common/templates/classic/_helpers.tpl

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
Calculate RabbitMQ URI (for On-Prem)
33
Must me called from chart root context.
44
Usage:
5-
{{ include "cf-common-0.5.2.classic.calculateRabbitMqUri" . }}
5+
{{ include "cf-common-0.6.0.classic.calculateRabbitMqUri" . }}
66
*/}}
77

8-
{{- define "cf-common-0.5.2.classic.calculateRabbitMqUri" }}
8+
{{- define "cf-common-0.6.0.classic.calculateRabbitMqUri" }}
99

1010
{{- $rabbitmqProtocol := .Values.global.rabbitmqProtocol | default "amqp" -}}
1111
{{- $rabbitmqUsername := .Values.global.rabbitmqUsername -}}
@@ -23,9 +23,9 @@ coalesce here for backward compatibility
2323
{{/*
2424
Calculate Mongo Uri (for On-Prem)
2525
Usage:
26-
{{ include "cf.common-0.5.2.classic.calculateMongoUri" (dict "dbName" $.Values.global.pipelineManagerService "mongoURI" $.Values.global.mongoURI) }}
26+
{{ include "cf.common-0.6.0.classic.calculateMongoUri" (dict "dbName" $.Values.global.pipelineManagerService "mongoURI" $.Values.global.mongoURI) }}
2727
*/}}
28-
{{- define "cf-common-0.5.2.classic.calculateMongoUri" -}}
28+
{{- define "cf-common-0.6.0.classic.calculateMongoUri" -}}
2929
{{- if contains "?" .mongoURI -}}
3030
{{- $mongoURI := (splitList "?" .mongoURI) -}}
3131
{{- printf "%s%s?%s" (first $mongoURI) .dbName (last $mongoURI) }}

charts/cf-common/templates/common/_annotations.tpl

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,19 +2,19 @@
22
Render checksum annotation
33
Must be called from chart root context.
44
Usage:
5-
annotations: {{ include "cf-common-0.5.2.annotations.podAnnotations" . | nindent }}
5+
annotations: {{ include "cf-common-0.6.0.annotations.podAnnotations" . | nindent }}
66
*/}}
7-
{{- define "cf-common-0.5.2.annotations.podAnnotations" -}}
7+
{{- define "cf-common-0.6.0.annotations.podAnnotations" -}}
88

99
{{- if .Values.podAnnotations -}}
10-
{{- include "cf-common-0.5.2.tplrender" (dict "Values" .Values.podAnnotations "context" $) | nindent 0 }}
10+
{{- include "cf-common-0.6.0.tplrender" (dict "Values" .Values.podAnnotations "context" $) | nindent 0 }}
1111
{{- end -}}
1212

1313
{{- $configMapFound := dict -}}
1414
{{- range $configMapIndex, $configMapItem := .Values.configMaps -}}
1515

1616
{{- if $configMapItem.enabled -}}
17-
{{- $_ := set $configMapFound $configMapIndex ( include "cf-common-0.5.2.tplrender" (dict "Values" $configMapItem.data "context" $) | sha256sum) -}}
17+
{{- $_ := set $configMapFound $configMapIndex ( include "cf-common-0.6.0.tplrender" (dict "Values" $configMapItem.data "context" $) | sha256sum) -}}
1818
{{- end -}}
1919

2020
{{- if $configMapFound -}}
@@ -27,7 +27,7 @@ annotations: {{ include "cf-common-0.5.2.annotations.podAnnotations" . | nindent
2727
{{- range $secretIndex, $secretItem := .Values.secrets -}}
2828

2929
{{- if $secretItem.enabled -}}
30-
{{- $_ := set $secretFound $secretIndex ( include "cf-common-0.5.2.tplrender" (dict "Values" $secretItem.stringData "context" $) | sha256sum) -}}
30+
{{- $_ := set $secretFound $secretIndex ( include "cf-common-0.6.0.tplrender" (dict "Values" $secretItem.stringData "context" $) | sha256sum) -}}
3131
{{- end -}}
3232

3333
{{- if $secretFound -}}

charts/cf-common/templates/common/_labels.tpl

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,28 +1,28 @@
11
{{/*
22
Kubernetes standard labels
33
*/}}
4-
{{- define "cf-common-0.5.2.labels.standard" -}}
5-
app.kubernetes.io/name: {{ include "cf-common-0.5.2.names.name" . }}
6-
helm.sh/chart: {{ include "cf-common-0.5.2.names.chart" . }}
4+
{{- define "cf-common-0.6.0.labels.standard" -}}
5+
app.kubernetes.io/name: {{ include "cf-common-0.6.0.names.name" . }}
6+
helm.sh/chart: {{ include "cf-common-0.6.0.names.chart" . }}
77
app.kubernetes.io/instance: {{ .Release.Name }}
88
app.kubernetes.io/managed-by: {{ .Release.Service }}
99
{{- end -}}
1010

1111
{{/*
1212
Labels to use on deploy.spec.selector.matchLabels and svc.spec.selector
1313
*/}}
14-
{{- define "cf-common-0.5.2.labels.matchLabels" -}}
15-
app.kubernetes.io/name: {{ include "cf-common-0.5.2.names.name" . }}
14+
{{- define "cf-common-0.6.0.labels.matchLabels" -}}
15+
app.kubernetes.io/name: {{ include "cf-common-0.6.0.names.name" . }}
1616
app.kubernetes.io/instance: {{ .Release.Name }}
1717
{{- end -}}
1818

1919

2020
{{/*
2121
Extra labels
2222
Usage:
23-
{{ include "cf-common-0.5.2.labels.extraLabels" ( dict "Values" .Values.path.to.the.labels "context" $) }}
23+
{{ include "cf-common-0.6.0.labels.extraLabels" ( dict "Values" .Values.path.to.the.labels "context" $) }}
2424
*/}}
25-
{{- define "cf-common-0.5.2.labels.extraLabels" -}}
25+
{{- define "cf-common-0.6.0.labels.extraLabels" -}}
2626
{{- if not (kindIs "map" .Values) -}}
2727
{{- fail "ERROR: labels block must be a map" -}}
2828
{{- end -}}
@@ -34,9 +34,9 @@ Usage:
3434
{{/*
3535
Annotations
3636
Usage:
37-
{{ include "cf-common-0.5.2.annotations" ( dict "Values" .Values.path.to.the.annotations "context" $) }}
37+
{{ include "cf-common-0.6.0.annotations" ( dict "Values" .Values.path.to.the.annotations "context" $) }}
3838
*/}}
39-
{{- define "cf-common-0.5.2.annotations" -}}
39+
{{- define "cf-common-0.6.0.annotations" -}}
4040
{{- if not (kindIs "map" .Values) -}}
4141
{{- fail "ERROR: annotations block must be a map" -}}
4242
{{- end -}}

charts/cf-common/templates/common/_names.tpl

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
{{/*
22
Expand the name of the chart.
33
*/}}
4-
{{- define "cf-common-0.5.2.names.name" -}}
4+
{{- define "cf-common-0.6.0.names.name" -}}
55
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
66
{{- end -}}
77

88
{{/*
99
Create chart name and version as used by the chart label.
1010
*/}}
11-
{{- define "cf-common-0.5.2.names.chart" -}}
11+
{{- define "cf-common-0.6.0.names.chart" -}}
1212
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
1313
{{- end -}}
1414

@@ -17,7 +17,7 @@ Create a default fully qualified app name.
1717
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
1818
If release name contains chart name it will be used as a full name.
1919
*/}}
20-
{{- define "cf-common-0.5.2.names.fullname" -}}
20+
{{- define "cf-common-0.6.0.names.fullname" -}}
2121
{{- if .Values.fullnameOverride -}}
2222
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
2323
{{- else -}}
@@ -33,10 +33,10 @@ If release name contains chart name it will be used as a full name.
3333
{{/*
3434
ServiceAccount Name
3535
*/}}
36-
{{- define "cf-common-0.5.2.names.serviceAccountName" -}}
36+
{{- define "cf-common-0.6.0.names.serviceAccountName" -}}
3737
{{- if .Values.serviceAccount -}}
3838
{{- if .Values.serviceAccount.enabled -}}
39-
{{- .Values.serviceAccount.nameOverride | default (include "cf-common-0.5.2.names.fullname" .) -}}
39+
{{- .Values.serviceAccount.nameOverride | default (include "cf-common-0.6.0.names.fullname" .) -}}
4040
{{- else -}}
4141
{{- print "default" -}}
4242
{{- end -}}

charts/cf-common/templates/common/_tpl.tpl

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
{{/*
22
Renders a value that contains template.
33
Usage:
4-
{{ include "cf-common-0.5.2.tplrender" ( dict "Values" .Values.path.to.the.Value "context" $) }}
4+
{{ include "cf-common-0.6.0.tplrender" ( dict "Values" .Values.path.to.the.Value "context" $) }}
55
*/}}
6-
{{- define "cf-common-0.5.2.tplrender" -}}
6+
{{- define "cf-common-0.6.0.tplrender" -}}
77
{{- $tpl := .Values -}}
88
{{- if not (typeIs "string" $tpl) -}}
99
{{- $tpl = toYaml $tpl -}}

charts/cf-common/templates/container/_container.tpl

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2,28 +2,28 @@
22
Renders main container in pod template.
33
Called from pod template.
44
Usage:
5-
{{ include "cf-common-0.5.2.container" (dict "Values" .Values.container "context" $) }}
5+
{{ include "cf-common-0.6.0.container" (dict "Values" .Values.container "context" $) }}
66
*/}}
7-
{{- define "cf-common-0.5.2.container" -}}
7+
{{- define "cf-common-0.6.0.container" -}}
88

99
{{/* Restoring root $ context */}}
1010
{{- $ := .context -}}
1111

12-
{{- $containerName := include "cf-common-0.5.2.names.fullname" $ -}}
12+
{{- $containerName := include "cf-common-0.6.0.names.fullname" $ -}}
1313
{{- if and (hasKey .Values "nameOverride") .Values.nameOverride }}
14-
{{- $containerName = include "cf-common-0.5.2.tplrender" (dict "Values" .Values.nameOverride "context" $) -}}
14+
{{- $containerName = include "cf-common-0.6.0.tplrender" (dict "Values" .Values.nameOverride "context" $) -}}
1515
{{- end }}
1616

1717

1818
- name: {{ $containerName }}
19-
image: {{ include "cf-common-0.5.2.image.name" (dict "image" .Values.image "context" $) }}
19+
image: {{ include "cf-common-0.6.0.image.name" (dict "image" .Values.image "context" $) }}
2020
imagePullPolicy: {{ .Values.image.pullPolicy | default "Always" }}
2121

2222
{{- with .Values.command }}
2323
{{- if not (kindIs "slice" .) }}
2424
{{- fail "ERROR: container.command block must be a list!" }}
2525
{{- end }}
26-
command: {{- include "cf-common-0.5.2.tplrender" (dict "Values" . "context" $) | nindent 2 }}
26+
command: {{- include "cf-common-0.6.0.tplrender" (dict "Values" . "context" $) | nindent 2 }}
2727
{{- end }}
2828

2929
{{- with .Values.args }}
@@ -53,12 +53,12 @@ Usage:
5353
{{- if not (kindIs "slice" .) }}
5454
{{ fail "ERROR: container.envFrom block must be a list!"}}
5555
{{- end }}
56-
{{- include "cf-common-0.5.2.tplrender" (dict "Values" . "context" $) | trim | nindent 4 }}
56+
{{- include "cf-common-0.6.0.tplrender" (dict "Values" . "context" $) | trim | nindent 4 }}
5757
{{- end }}
5858
{{- range $secretName, $secretItem := $.Values.secrets }}
5959
{{- if $secretItem.enabled }}
6060
- secretRef:
61-
name: {{ printf "%s-%s" (include "cf-common-0.5.2.names.fullname" $) $secretName }}
61+
name: {{ printf "%s-%s" (include "cf-common-0.6.0.names.fullname" $) $secretName }}
6262
{{- end }}
6363
{{- end }}
6464
{{- end }}
@@ -75,18 +75,18 @@ For backward compatibility (.Values.env takes precedence over .Values.container.
7575
{{- $mergedEnv = merge $mergedEnv $.Values.global.env }}
7676
{{- end }}
7777
env:
78-
{{- include "cf-common-0.5.2.env-vars" (dict "Values" $mergedEnv "context" $) | trim | nindent 2 }}
78+
{{- include "cf-common-0.6.0.env-vars" (dict "Values" $mergedEnv "context" $) | trim | nindent 2 }}
7979
{{- end }}
8080

81-
{{- include "cf-common-0.5.2.ports" $ | trim | nindent 2 }}
81+
{{- include "cf-common-0.6.0.ports" $ | trim | nindent 2 }}
8282

8383
{{- with .Values.volumeMounts }}
8484
volumeMounts:
85-
{{- include "cf-common-0.5.2.volumeMounts" (dict "Values" . "context" $) | trim | nindent 2 }}
85+
{{- include "cf-common-0.6.0.volumeMounts" (dict "Values" . "context" $) | trim | nindent 2 }}
8686
{{- end }}
8787

8888
{{- with .Values.probes }}
89-
{{- include "cf-common-0.5.2.probes" . | trim | nindent 2 }}
89+
{{- include "cf-common-0.6.0.probes" . | trim | nindent 2 }}
9090
{{- end }}
9191

9292
{{- with .Values.resources }}

0 commit comments

Comments
 (0)