Skip to content

Commit 03d89f7

Browse files
committed
Run as non-root for kubernetes on VPA
1 parent 36d2237 commit 03d89f7

File tree

4 files changed

+12
-0
lines changed

4 files changed

+12
-0
lines changed

vertical-pod-autoscaler/deploy/admission-controller-deployment.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,9 @@ spec:
1515
app: vpa-admission-controller
1616
spec:
1717
serviceAccountName: vpa-admission-controller
18+
securityContext:
19+
runAsNonRoot: true
20+
runAsUser: 65534 # nobody
1821
containers:
1922
- name: admission-controller
2023
image: k8s.gcr.io/vpa-admission-controller:0.6.3

vertical-pod-autoscaler/deploy/recommender-deployment.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,9 @@ spec:
2121
app: vpa-recommender
2222
spec:
2323
serviceAccountName: vpa-recommender
24+
securityContext:
25+
runAsNonRoot: true
26+
runAsUser: 65534 # nobody
2427
containers:
2528
- name: recommender
2629
image: k8s.gcr.io/vpa-recommender:0.6.3

vertical-pod-autoscaler/deploy/updater-deployment.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,9 @@ spec:
2121
app: vpa-updater
2222
spec:
2323
serviceAccountName: vpa-updater
24+
securityContext:
25+
runAsNonRoot: true
26+
runAsUser: 65534 # nobody
2427
containers:
2528
- name: updater
2629
image: k8s.gcr.io/vpa-updater:0.6.3

vertical-pod-autoscaler/examples/hamster.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,9 @@ spec:
2929
labels:
3030
app: hamster
3131
spec:
32+
securityContext:
33+
runAsNonRoot: true
34+
runAsUser: 65534 # nobody
3235
containers:
3336
- name: hamster
3437
image: k8s.gcr.io/ubuntu-slim:0.1

0 commit comments

Comments
 (0)